Courseiva

CCNA Identity Awareness Questions

35 questions · Identity Awareness topic · All types, answers revealed

1
MCQmedium

What is the primary function of the 'Identity Collector' in a distributed Identity Awareness environment?

A.Encrypting all user traffic.
B.Offloading identity collection from the Gateway.
C.Providing endpoint antivirus protection.
D.Enforcing access policies on the user.
AnswerB

The Identity Collector centralizes the collection process, which reduces the resource consumption on individual security gateways. It connects to various identity sources, gathers event data, and forwards only the relevant identity information to the gateways, ensuring optimal performance and scalability across large, distributed enterprise network deployments.

Why this answer

The Identity Collector is a dedicated software component that offloads the task of querying directory services (like Active Directory) from the Security Gateway. By centralizing the collection of identity events, it reduces the load on the gateway's CPU and allows for the integration of multiple identity sources, such as Cisco ISE or Windows Event Logs, into a single, unified feed for the security gateways.

Exam trap

Candidates often confuse the Identity Collector's offloading function with direct authentication or policy enforcement, incorrectly assuming it performs the actual packet filtering and rule evaluation instead of simply centralizing directory queries.

2
MCQeasy

A company wants users on managed Windows endpoints to be identified by Identity Awareness without requiring them to open a browser or wait for an AD event log poll. The endpoints are domain-joined and already managed by the organization. Which acquisition method meets this requirement most directly?

A.Captive Portal with single sign-on enabled
B.Identity Agent installed on each managed endpoint
C.AD Query configured against the domain controllers
D.RADIUS Accounting configured on the gateway
AnswerB

The Identity Agent runs as a client on the endpoint and authenticates the logged-in user to the Security Gateway automatically, with no browser interaction. It reports identity as soon as the user session starts rather than waiting for an AD polling cycle. For domain-joined, centrally managed Windows machines, this provides immediate and reliable identification, satisfying the no-browser, no-poll requirement.

Why this answer

An endpoint-resident Identity Agent authenticates the logged-in user to the gateway automatically, providing immediate identification with no browser prompt and no dependency on AD event polling. For centrally managed, domain-joined Windows endpoints, this is the most direct way to achieve seamless, prompt-free identity acquisition.

Exam trap

The trap here is treating AD Query as instant, when its polling behavior means it cannot guarantee immediate identification after logon.

3
MCQhard

A security administrator is deploying Identity Awareness using the Identity Collector in an environment with multiple domain controllers. The administrator wants to ensure that user identity information is collected from all domain controllers and that the load is distributed. Which configuration should be implemented?

A.Enable the Identity Awareness blade on each domain controller to push identities directly to the gateway.
B.Use a single Identity Collector and configure it to query all domain controllers simultaneously via LDAP.
C.Deploy multiple Identity Collector instances, each connecting to a different domain controller, and configure them to share data with the Security Gateway.
D.Configure the Identity Collector to connect to each domain controller individually and enable load balancing.
AnswerC

The Identity Collector can be installed on multiple servers, each monitoring a different domain controller. They can all send identity information to the same Security Gateway. This provides redundancy and distributes the load, ensuring that if one collector fails, others continue to provide identities.

Why this answer

To collect identities from multiple domain controllers and distribute load, deploy multiple Identity Collector instances, each assigned to a different domain controller. They all forward data to the Security Gateway, providing redundancy. This is the recommended approach for large environments with multiple domain controllers.

Exam trap

The trap here is assuming that a single Identity Collector can connect to multiple domain controllers with load balancing, when in fact multiple collectors are needed for redundancy and distribution.

4
MCQhard

An administrator is troubleshooting an issue where users are identified as 'Unknown' despite having Identity Awareness enabled. What is the first logical step to investigate?

A.Restart the security gateway.
B.Check 'pdp monitor' output.
C.Review the Access Control policy.
D.Reinstall the Identity Agent.
AnswerB

The 'pdp monitor' command provides an immediate overview of the health of all identity sources. It reveals if the gateway is actively receiving data from AD Query or other sources. If a source is down, this command will explicitly indicate the status, guiding further targeted troubleshooting efforts effectively.

Why this answer

The most effective first step is to check if the gateway is correctly receiving identity information from the sources. Using the command 'pdp monitor' allows the administrator to see the current status of all configured identity sources. If the source shows as 'Disconnected' or 'Failed', the problem lies in the connectivity or credentials used for the identity source, rather than a policy-level filtering issue.

Exam trap

Candidates often jump to checking the policy or user credentials first, ignoring the 'pdp monitor' command which provides an immediate, high-level overview of the Identity Awareness engine's current state.

5
MCQmedium

A security administrator must let contractors on personally owned, non-domain laptops access internal resources. The contractors cannot install endpoint software, and the organization wants them to authenticate through a web page before access is granted. Which Identity Awareness acquisition method fits these constraints?

A.Captive Portal configured on the Security Gateway
B.AD Query against the corporate domain controllers
C.Identity Agent installed by each contractor
D.RADIUS Accounting from a third-party network access server
AnswerA

Captive Portal redirects unauthenticated users to a web page where they can log in before access is permitted. It requires no endpoint software and works for non-domain devices, matching both constraints. Contractors authenticate through the browser, and the gateway creates an identity session tied to their source address, enabling identity-based policy for their traffic.

Why this answer

Captive Portal is designed for users who cannot run endpoint agents and are not in the domain. It presents a browser-based login before granting access, satisfying both the no-install and web-authentication requirements. The gateway then maps the authenticated user to the source address for identity-based enforcement.

Exam trap

The trap here is assuming domain-based methods can serve non-domain contractors, when those methods require domain authentication events or endpoint agents.

6
MCQmedium

A security administrator manages a Check Point R81.20 environment with a Security Gateway and a separate Identity Collector. Users authenticate through Microsoft Active Directory, and the administrator wants to minimize the number of AD queries sent from the gateway. Which configuration should the administrator use to achieve this?

A.Configure the Security Gateway to use RADIUS accounting to receive user identity information.
B.Deploy Identity Collector to receive identity events from AD and forward them to the Security Gateway.
C.Configure Identity Awareness with AD Query and enable caching on the Security Gateway.
D.Enable Identity Awareness with Terminal Server Agent on all domain controllers.
AnswerB

Identity Collector subscribes to AD security event logs and pushes user logon and logoff events to the Security Gateway, so the gateway does not need to query AD itself. This push model dramatically reduces the number of queries against domain controllers while keeping identity data current. It is the recommended method when AD load must be minimized in larger environments.

Why this answer

Identity Collector is specifically designed to reduce load on Active Directory by having a dedicated collector receive security event log data and push identity updates to the Security Gateway. This eliminates the need for the gateway to poll AD, which is the behavior of AD Query. The other methods either still query AD or are intended for different authentication scenarios.

Exam trap

The trap here is assuming that enabling caching with AD Query eliminates the need for the gateway to query Active Directory, when in fact AD Query continues to poll domain controllers regardless of caching.

7
MCQmedium

Which of the following describes the function of the 'Identity Awareness Gateway' in a load-sharing cluster?

A.It only synchronizes identity data during a failover event.
B.It synchronizes identity tables across all cluster members.
C.Each member maintains its own independent identity table.
D.It forces traffic to only one node for identity processing.
AnswerB

Identity table synchronization is essential for cluster stability and policy consistency. By keeping the identity mapping consistent across all members, the cluster can maintain a uniform view of the network users, ensuring that security policies are applied reliably, regardless of which specific cluster member processes the individual network packet.

Why this answer

In a load-sharing cluster, identity information must be synchronized across all cluster members to maintain consistent policy enforcement. If a member receives a packet, it must know the identity of the source IP address immediately. By synchronizing the identity table, the cluster ensures that whichever member handles the traffic, it can apply the same user-based access rules without requiring the user to re-authenticate or re-map their identity.

Exam trap

Students often think identity information remains static on a single member or requires manual replication, missing that load-sharing clusters actively synchronize identity tables automatically.

8
Multi-Selectmedium

Which TWO settings are required when configuring the 'Active Directory Query' method in the Identity Awareness blade?

Select 2 answers
A.The IP address of the Domain Controller.
B.A service account with permissions to read security logs.
C.A list of all users in the Active Directory.
D.The public DNS server IP address.
E.An installed Identity Agent on the Domain Controller.
AnswersA, B

The gateway needs to know exactly which server to query for security log events. Providing the IP address of the Domain Controller allows the gateway to establish the necessary WMI or RPC connection to monitor login events and map users to their corresponding IP addresses in real-time.

Why this answer

To configure AD Query, the administrator must provide the gateway with the necessary credentials to read security logs and identify the target domain controller. These two components—the specific Domain Controller and the service account with adequate permissions—are fundamental. Without them, the gateway lacks the administrative authorization required to query the remote logs, and it would be unable to map IP addresses to user accounts.

Exam trap

Candidates often select 'Domain Admin credentials' as a requirement. Providing Domain Admin access is unnecessary and a security risk; only specific read-only access to logs is required.

9
MCQeasy

An administrator is configuring Identity Awareness on a Security Gateway and wants to enable users to authenticate via a web portal before accessing network resources. The administrator wants to minimize user disruption and avoid installing additional software. Which Identity Awareness method should be used?

A.AD Query
B.Terminal Server Agent
C.Identity Collector
D.Browser-Based Authentication
AnswerD

Browser-Based Authentication presents a web portal where users enter credentials. It requires no client software and works on any device with a browser. It is ideal for environments where users need to authenticate without domain integration or additional installations.

Why this answer

Browser-Based Authentication provides a web portal for user login, requiring only a browser. It avoids software installation and domain integration. This method is suitable when users need to authenticate before accessing resources, and it minimizes disruption by leveraging familiar browser interfaces.

Exam trap

The trap here is confusing Browser-Based Authentication with transparent methods like AD Query, which do not provide a web portal and require domain integration.

10
MCQmedium

An administrator is deploying Identity Awareness on a Check Point R81.20 Security Gateway. Users authenticate to a captive portal hosted by the gateway itself, without any external directory service. Which Identity Awareness method is being used?

A.RADIUS Accounting
B.Identity Collector
C.Active Directory Query
D.Browser-Based Authentication
AnswerD

Browser-Based Authentication lets the Security Gateway present a web portal where users enter credentials directly, with no external directory required. The gateway maintains its own local user database, so this matches the scenario exactly. It is the only Identity Awareness acquisition method that relies solely on the gateway's internal authentication rather than an external source such as AD or RADIUS.

Why this answer

Browser-Based Authentication is the only Identity Awareness method that operates entirely on the Security Gateway without any external directory or identity source. It presents a captive portal, validates credentials against the gateway's local user database, and then maps the source IP to the authenticated user for policy enforcement. All other methods depend on external infrastructure, which the scenario explicitly excludes.

Exam trap

The trap here is assuming that any portal-based login automatically implies a separate identity server, when Browser-Based Authentication actually runs entirely on the gateway.

11
MCQmedium

Refer to the exhibit. An administrator reviews the Identity Awareness status of a user workstation using CLI commands on the Security Gateway. What does the 'Identity Source: Identity Agent' field specifically indicate about how this user's identity was acquired?

A.The gateway queried the Active Directory Domain Controller security event logs using WMI.
B.A client application installed on the user workstation actively authenticated to the Security Gateway.
C.The user successfully completed a web-based Captive Portal challenge in their browser.
D.The gateway intercepted a Kerberos ticket exchange via passive network sniffing.
AnswerB

An Identity Agent runs directly on the endpoint operating system, establishing a secure communication channel with the gateway. This confirms the user's identity through direct application reporting rather than indirect log parsing or network sniffing.

Why this answer

The Identity Agent source indicates that a lightweight client is installed on the endpoint device, actively communicating user credentials and state directly to the Security Gateway. This method offers high reliability and supports advanced features like post-connection accounting and explicit sign-out.

Exam trap

Candidates frequently confuse the Identity Agent source with passive methods like AD Query or Browser-Based Authentication, ignoring the fact that an agent requires installation on the actual workstation.

12
MCQmedium

An administrator configures Identity Awareness with Active Directory Query on an R81.20 Security Gateway. Users are authenticated via Kerberos, and the gateway has been joined to the domain. However, after login, some users are not being identified. The administrator notices that the gateway's AD Query service account password has expired. What is the most likely cause of the identification failure?

A.The AD Query service account password must be updated in the Identity Awareness configuration, and the service restarted.
B.The Security Gateway must be rebooted to re-establish the Kerberos trust with the domain controller.
C.The users must log in again because their Kerberos tickets have expired due to the service account issue.
D.The Identity Awareness blade must be reinstalled because the expired password corrupted its database.
AnswerA

When the AD Query service account password expires, the gateway cannot query Active Directory for user login events. Updating the password in the Identity Awareness configuration and restarting the service restores the connection. This is a common operational issue in AD Query deployments.

Why this answer

The AD Query method relies on a service account to read login events from Active Directory. If that account's password expires or is changed, the gateway loses access and cannot identify users. The fix is to update the password in the Identity Awareness configuration and restart the service.

This ensures continuous identification.

Exam trap

The trap here is assuming that a gateway reboot or reinstallation resolves authentication issues, when the real cause is an expired service account password that must be updated.

13
MCQmedium

An administrator configures Identity Awareness in a Check Point environment using Active Directory Query. Users report that access policies based on user groups fail intermittently for workstations after users lock their screens. Which underlying mechanism causes this authentication loss?

A.The Identity Awareness daemon purges user entries immediately when the workstation screensaver activates.
B.Kerberos ticket-granting service renewal failures occur during idle periods, forcing the Security Gateway to drop user mappings.
C.AD Query relies on periodic polling of domain controller security logs and may miss rapid logon state transitions or idle timeouts.
D.The Security Management Server revokes the user's identity certificate when network traffic ceases for more than sixty seconds.
AnswerC

Active Directory Query operates by polling domain controllers at configured intervals for security event IDs. If a session undergoes rapid state changes or prolonged inactivity without generating new authentication events, the cache may temporarily become desynchronized.

Why this answer

Active Directory Query relies on polling Windows security event logs to track user logon sessions through Kerberos and NTLM ticket activity. When a workstation locks or goes idle, specific session events might not immediately refresh the gateway cache, causing temporary identity loss. Understanding this limitation helps administrators combine AD Query with browser-based Captive Portal or terminal servers to ensure robust identity persistence across all network segments.

Exam trap

Candidates often assume the issue is a firewall rule timeout. They fail to recognize that AD Query is fundamentally limited by the timing of Windows log generation and polling.

14
MCQhard

A security administrator has deployed Identity Awareness with Terminal Server Agent on a Check Point R81.20 gateway. Users report that their identities are correctly identified when they log in, but after disconnecting and reconnecting to a different session on the same terminal server, they are still associated with the old session. What is the most likely cause?

A.The gateway's identity database is full and cannot accept new entries.
B.The Terminal Server Agent is not configured to monitor session changes.
C.The gateway is not licensed for Identity Awareness with Terminal Server Agent.
D.The Terminal Server Agent service is not running on the terminal server.
AnswerB

The Terminal Server Agent must be configured to track session events, including logon, logoff, and session changes. If it only monitors initial logons and not reconnections or session switches, the gateway will retain the old session mapping. This leads to stale identity information when users move between sessions on the same terminal server.

Why this answer

The Terminal Server Agent must be configured to monitor all session events, including logoff and reconnection, to keep the identity database current. If it only tracks initial logons, the gateway will not update the mapping when a user switches sessions, resulting in stale associations. Ensuring that session change monitoring is enabled resolves the issue.

Exam trap

The trap here is assuming that because initial identification works, the service or license must be fine, overlooking that session change events require separate configuration.

15
MCQhard

An administrator is configuring Identity Awareness on a Check Point R81.20 gateway using the Identity Collector. Users are authenticated via multiple Active Directory domains in a forest. The administrator notices that users from one domain are not being identified. What is the most likely cause?

A.The Identity Collector does not support multiple domains in a single forest.
B.The gateway is not configured with a DNS server that can resolve the domain controllers in that domain.
C.The Identity Collector service account does not have sufficient permissions to read the Event Log on domain controllers in that domain.
D.The users in that domain are not members of any groups that are used in Identity Awareness rules.
AnswerC

The Identity Collector requires a service account with read access to the security event logs on all domain controllers it monitors. If the account lacks permissions on domain controllers in one domain, it cannot collect login events from that domain, resulting in unidentified users. This is a common configuration oversight when multiple domains are involved, as permissions must be granted in each domain.

Why this answer

The Identity Collector relies on reading security event logs from domain controllers. When multiple domains exist, the service account must have read permissions on each domain controller. If permissions are missing for one domain, the collector cannot retrieve login events, leaving users unidentified.

Ensuring the account has appropriate rights in every domain is essential for full coverage.

Exam trap

The trap here is assuming that a single service account with permissions in one domain automatically has rights in all domains of the forest, but permissions must be explicitly granted per domain.

16
MCQmedium

An administrator is configuring Identity Awareness on a Check Point R81.20 Security Gateway. The company uses a single Active Directory domain and wants to identify users without installing any software on client machines. Which Identity Awareness method should the administrator choose?

A.Identity Agent
B.Browser-Based Authentication
C.Terminal Server Agent
D.AD Query
AnswerD

AD Query retrieves user logon information directly from Active Directory domain controllers without any client software. It works with domain-joined machines and requires only that the Security Gateway can communicate with the domain controllers. This makes it the ideal choice for identifying users in a single AD domain without deploying agents, satisfying the administrator's requirement.

Why this answer

AD Query is the only method that automatically identifies users in an Active Directory domain without installing any software on client machines. It leverages the existing domain infrastructure and the Security Gateway's ability to query domain controllers, making it the correct choice for this scenario. Other methods either require client software or manual authentication.

Exam trap

The trap here is assuming that Browser-Based Authentication is a no-client-software solution, but it requires user interaction and is not automatic, unlike AD Query which seamlessly identifies domain users.

17
MCQmedium

An administrator needs to implement Identity Awareness to control access based on user groups. Which authentication method should be configured to ensure seamless transparency for users already logged into a Windows domain without requiring manual credentials input?

A.Captive Portal
B.Identity Agent
C.AD Query
D.Browser-Based Authentication
AnswerC

AD Query uses WMI or RPC to read security event logs from Domain Controllers. This provides a completely transparent experience because the Security Gateway passively observes authentication events, ensuring users do not need to perform any actions to be identified by the firewall policies.

Why this answer

Active Directory Query (AD Query) is the ideal mechanism for seamless transparent authentication. By querying the AD Security Event Logs, the Security Gateway identifies user logons without requiring agents on endpoints. This method is crucial for modern enterprise environments where user productivity is high and manual login prompts would cause significant friction, while still maintaining granular access control policies based on user group memberships.

Exam trap

Candidates often confuse AD Query with Identity Agents or Captive Portal, selecting agent-based methods when the question explicitly demands seamless transparency without requiring software installations or user interaction.

18
MCQmedium

An administrator configures Identity Awareness using Active Directory Query to authenticate domain users. After deployment, users report intermittent authentication failures, and logs show that the Security Gateway fails to query the Domain Controllers due to insufficient privileges. Which account permission must be granted to resolve this issue without granting Domain Administrator rights?

A.Membership in the Domain Admins group and full control over the root domain partition.
B.Membership in the Enterprise Admins group and Schema Admins group.
C.Read permissions on user objects and membership in the Event Log Readers security group.
D.Full administrative control over the Built-in Administrators local group on the gateway.
AnswerC

Event Log Readers group membership allows the Identity Awareness daemon to query security logs effectively. Combining this with standard read permissions on user and computer objects fulfills all functional requirements while strictly maintaining least-privilege security standards.

Why this answer

Identity Awareness Active Directory Query requires specific read permissions on the Active Directory container objects and membership in the Event Log Readers group to parse security event logs successfully. Granting full domain admin privileges violates security best practices, making targeted permission delegation essential for enterprise compliance and least-privilege enforcement.

Exam trap

Candidates often recommend full Domain Administrator rights to fix permission issues, ignoring security best practices and the specific requirement for least-privilege delegation.

19
MCQhard

An administrator has configured Identity Awareness with Terminal Server Agent on a Terminal Server. Users report that after disconnecting from a Remote Desktop session and reconnecting, they are sometimes identified as the previous user. What is the most likely cause of this issue?

A.The Terminal Server Agent is not configured to monitor session state changes.
B.The Security Gateway is not receiving updates from the Terminal Server Agent due to a network issue.
C.The Identity Awareness blade is not enabled on the Security Gateway.
D.The Terminal Server Agent maps users to session IDs, and when a session ID is reused without a proper logoff event, the previous user's identity can persist.
AnswerD

The Terminal Server Agent tracks user sessions by their session ID. If a user disconnects without properly logging off, the session remains in a disconnected state. When the same session ID is later reused by a different user, the agent may not have received a logoff event for the previous user, leading to the old identity being associated with the new session. This is a known behavior that can cause incorrect user identification.

Why this answer

The correct answer is that the Terminal Server Agent maps users to session IDs, and if a session ID is reused without a proper logoff event, the previous user's identity can persist. This can happen when users disconnect instead of logging off, leaving the session in a disconnected state. When the session ID is later assigned to a new user, the agent may not have processed a logoff for the old user, causing misidentification.

Exam trap

The trap here is assuming that a network or configuration error is the cause, when the issue is actually due to how session IDs are reused and how logoff events are processed.

20
MCQhard

A security administrator manages a Check Point R81.20 environment with Identity Awareness using Active Directory Query. Users on domain-joined machines are identified correctly, but users who connect through a NAT device are consistently shown as unknown. What is the most likely cause?

A.The AD Query method cannot resolve identities when the source IP is translated by NAT.
B.The gateway is missing a license for Identity Awareness.
C.The AD Query account password has expired.
D.The Security Gateway is not configured to read the correct AD security log.
AnswerA

Active Directory Query learns identities by correlating AD security event logs with the source IP seen by the gateway. When a NAT device translates the source IP, the IP observed by the gateway no longer matches the IP recorded in the AD logs, so the correlation fails and the user remains unknown. This is a fundamental limitation of the passive AD Query method.

Why this answer

Active Directory Query relies on matching the source IP of traffic to the IP recorded in AD security events. NAT rewrites the source IP, so the gateway sees a different address than the one in the AD logs, and the identity lookup fails. To support NATed users, the administrator must use a method that carries identity in the traffic itself, such as Identity Collector or RADIUS Accounting.

Exam trap

The trap here is blaming a global failure such as a license or account issue when the symptom is clearly limited to a specific network topology.

21
Multi-Selecthard

An administrator is troubleshooting an Identity Awareness deployment where some users are intermittently shown as unidentified on the Security Gateway. The environment uses AD Query. Which TWO conditions would cause AD Query to fail to identify a logged-in user? (Choose two.)

Select 2 answers
A.The Security Gateway cannot reach the domain controller on the required ports for event log retrieval.
B.The Captive Portal certificate has expired on the gateway.
C.The user logged in before the Security Gateway was configured as a monitored source in the AD Query settings.
D.The gateway's identity session timeout is shorter than the users' typical work session.
E.The endpoint has the Identity Agent installed but the service is set to manual start.
AnswersA, C

AD Query depends on connecting to domain controllers to read security event logs. If the required ports, such as those for WMI/DCOM or the event log service, are blocked between the gateway and the DC, the gateway cannot retrieve logon events. Users then remain unidentified even though they successfully logged into the domain, making connectivity a direct cause of the symptom.

Why this answer

AD Query relies on reaching domain controllers to read security event logs, and it only sees logons generated after monitoring is enabled for those controllers. Blocked connectivity or logons predating configuration both leave users unidentified. Endpoint agent state, portal certificates, and session timeout length do not govern whether AD Query can read domain login events.

Exam trap

The trap here is attributing AD Query gaps to endpoint agent or portal issues, which belong to entirely different acquisition methods.

22
MCQmedium

What is the primary benefit of using 'Identity Sharing' between multiple Check Point Security Gateways?

A.To reduce the load on the Security Management Server.
B.To allow users to roam between gateways without re-authenticating.
C.To enforce user access restrictions at the Management Server level.
D.To replace the need for AD Query on all gateways.
AnswerB

Identity Sharing ensures that once a user is authenticated at one gateway, that information is propagated to others. When the user moves to a segment protected by another gateway, the new gateway already knows the user's identity, eliminating the need for further authentication and providing a seamless network transition.

Why this answer

Identity Sharing allows gateways to exchange user-to-IP mapping information, effectively creating a unified identity awareness environment. This is critical in large networks where a user might roam between different gateway segments. By sharing this data, the security policy remains consistent for the user regardless of which gateway they connect through, preventing the need for redundant authentication processes and improving the overall security posture and user experience.

Exam trap

Candidates often mistake Identity Sharing for clustering high-availability sync or global policy distribution rather than user-to-IP mapping synchronization.

23
MCQhard

A security administrator is using Identity Awareness with Identity Agents in 'Browser-Based' mode. Users report they are prompted for authentication twice. What is the most likely cause?

A.The Identity Agent is misconfigured.
B.Captive Portal is enabled for the same traffic.
C.The Domain Controller is slow to respond.
D.Active Directory replication delay.
AnswerB

When Captive Portal is enabled for the same traffic as Identity Agents, the gateway may challenge the user via the agent and then immediately via the browser if the initial agent-based authentication is not recognized as sufficient for the specific security rule matching the user's current session or application.

Why this answer

When using browser-based authentication alongside Identity Agents, the gateway might trigger a Captive Portal authentication if the Identity Agent hasn't fully communicated the user's identity, or if there is a conflict in policy enforcement. This double-prompting often indicates that the browser-based authentication policy overlaps with the agent-based authentication method, causing the system to challenge the user through both mechanisms consecutively.

Exam trap

Candidates mistakenly attribute double authentication prompts to expired passwords or browser cookie settings, missing the configuration overlap between browser-based modes and Captive Portal.

24
MCQhard

A security administrator has configured Identity Awareness with AD Query on a Check Point R81.20 Security Gateway. Users report that they can access resources immediately after logging in, but after a password change, some users are still identified with their old group memberships for an extended period. What is the most likely cause of this behavior?

A.The Identity Awareness blade is not configured to synchronize group memberships.
B.The user's session on the Security Gateway has not been refreshed, and the old session is still active.
C.The Security Gateway is not receiving real-time login events from the domain controllers.
D.The AD Query cache has not expired, and the gateway is using cached group information.
AnswerD

AD Query periodically queries Active Directory for user and group information and caches the results. When a user's group membership changes, such as after a password change that triggers a group update, the gateway may continue to use the cached information until the cache expires or is refreshed. This can cause a delay in reflecting the new group memberships, leading to the observed behavior.

Why this answer

The correct answer is that the AD Query cache has not expired, and the gateway is using cached group information. AD Query periodically queries Active Directory and caches the results to reduce load. When group memberships change, the gateway may not reflect the changes until the cache is refreshed, causing users to retain old group memberships for an extended period.

Exam trap

The trap here is assuming that AD Query provides real-time updates, when in fact it relies on periodic queries and caching.

25
MCQmedium

Which of the following is a recommended best practice when using Identity Awareness for internal network security?

A.Enable all Identity Awareness sources on all gateways.
B.Create rules based on user groups rather than IP addresses.
C.Only use Captive Portal for all users.
D.Disable logging to improve gateway performance.
AnswerB

Rules based on user groups are far more flexible and sustainable than IP-based rules. As users move between machines or IPs, the identity policy automatically applies the correct security settings to them. This approach is the cornerstone of modern, robust, and scalable identity-aware access control within an enterprise network.

Why this answer

The most effective way to secure an internal network using Identity Awareness is to implement a 'least privilege' approach combined with granular user-group rules. By defining policies that only allow specific users access to the resources they need to perform their job functions, administrators significantly reduce the internal attack surface. This prevents lateral movement by attackers who might compromise a single machine, as their access remains limited to the authorized user's permissions.

Exam trap

Many candidates mistakenly choose IP-based rules for internal segmentation, overlooking the core security principle that Identity Awareness enables granular, user-group-based access control.

26
MCQeasy

Which of the following is the primary purpose of the Identity Awareness 'Captive Portal' feature?

A.To hide the identity of the user from internal logging servers.
B.To provide authentication for users not identified by transparent methods.
C.To automatically install Identity Agents on client machines.
D.To encrypt traffic between the user and the internal file servers.
AnswerB

The Captive Portal is the primary fallback method for Identity Awareness. It ensures that when transparent methods (like AD Query) fail or are unavailable for certain users or devices, the firewall can still enforce security policies by requiring explicit authentication via a web browser before allowing network traffic.

Why this answer

The Captive Portal serves as a fallback authentication mechanism for users who are not automatically identified by transparent methods like AD Query or Identity Agents. It presents a web page to the user, forcing them to authenticate before granting access to network resources. This ensures that even unmanaged devices or users who cannot be identified through automated means can still have their traffic logged and controlled by the gateway.

Exam trap

Candidates mistakenly believe the Captive Portal is the primary identification method for all users, failing to understand it is a fallback mechanism used only when transparent methods fail.

27
MCQhard

Refer to the exhibit. An administrator is configuring RADIUS authentication for Identity Awareness. What is the cause of this error log?

A.The RADIUS server is down.
B.The firewall policy is blocking RADIUS traffic.
C.The RADIUS server and gateway have mismatched encryption keys.
D.The user password is incorrect.
AnswerC

The shared secret is the cryptographic key used to secure the communication between the RADIUS client and server. A mismatch causes the server to drop the request because it cannot verify the integrity of the incoming packets, which is exactly what the logged error message indicates to the administrator.

Why this answer

The 'shared secret mismatch' error explicitly indicates that the RADIUS client (the Security Gateway) and the RADIUS server are using different keys to encrypt their communications. This is a common configuration error in AAA setups. Both the gateway and the server must have an identical, correctly typed shared secret string, or the authentication handshake will be rejected by the server for security reasons.

Exam trap

Candidates often suspect a RADIUS server service outage or network connectivity issue, failing to check the shared secret, which is the most common cause of authentication handshake failure.

28
Multi-Selectmedium

An administrator is configuring Identity Awareness on a Check Point R81.20 Security Gateway using the Identity Collector. The administrator wants to ensure that the Identity Collector can retrieve user identity information from Active Directory. Which two components are required for the Identity Collector to function? (Choose two.)

Select 2 answers
A.The Terminal Server Agent installed on all domain controllers
B.A dedicated server or virtual machine to run the Identity Collector
C.A user account with read permissions to Active Directory
D.The Security Gateway must be a member of the Active Directory domain
E.A RADIUS server configured for accounting
AnswersB, C

The Identity Collector is a separate component that must be installed on a dedicated server or virtual machine. It cannot run on the Security Gateway itself. This server requires network connectivity to both the Active Directory domain controllers and the Security Gateway. Therefore, a dedicated server or VM is a required component for the Identity Collector to function.

Why this answer

The two required components are a user account with read permissions to Active Directory and a dedicated server or virtual machine to run the Identity Collector. The Identity Collector uses the account to authenticate and retrieve identity events from domain controllers, and it must run on a separate server that has network connectivity to both Active Directory and the Security Gateway.

Exam trap

The trap here is assuming that the Security Gateway must be a domain member or that additional services like RADIUS are needed, when the Identity Collector operates independently.

29
MCQmedium

Refer to the exhibit. An administrator is troubleshooting an issue where 'bob' is unable to access resources. Based on the CLI output, what is the most likely cause for the connectivity failure?

A.The AD Query source is failing to communicate.
B.The security policy is blocking the traffic.
C.The user session has timed out.
D.The Identity Awareness blade is disabled.
AnswerB

Since the identity mapping is verified as active in the gateway's cache, the gateway correctly identifies the user. If the user still cannot access the resource, the traffic is likely being dropped or rejected by a specific rule in the Security Policy base, not due to identity acquisition.

Why this answer

The CLI output confirms that 'bob' is actively mapped to IP 10.0.0.5 via AD Query with a timeout remaining. Since the identity mapping is confirmed, the issue is not with the Identity Awareness blade itself but rather with the security policy rules. The gateway correctly identifies the user, so the administrator should focus on firewall policy rule matching and the specific network permissions defined for bob's group.

Exam trap

Candidates often blame the Identity Awareness blade for the failure, failing to notice that the user was successfully identified, meaning the issue must be in the security policy rules.

30
MCQmedium

When configuring Access Control policies based on Identity Awareness roles, an administrator places an identity-based rule above a traditional IP-based rule. A user authenticated via Identity Awareness attempts to access a blocked server. The rule base evaluates the connection and matches the user against the identity rule. What happens to the connection?

A.The connection is evaluated against the lower IP-based rule if the identity role contains conflicting parameters.
B.The action specified in the matched identity-based rule is immediately enforced.
C.The gateway drops the packet because IP-based rules always take precedence over identity rules.
D.The user is forced to re-authenticate via Captive Portal to confirm their authorization.
AnswerB

Because the rule base is processed sequentially from top to bottom, matching the identity-based rule triggers its defined action (Accept or Drop) instantly. Subsequent rules lower in the policy are ignored for that connection flow.

Why this answer

Check Point Security Gateways evaluate Access Control rules in a top-down manner. Once a packet matches the criteria of an upper rule—including user identity attributes—action is immediately enforced, and lower rules are bypassed. Proper rule ordering is critical to prevent unintended access permissions.

Exam trap

Candidates mistakenly assume traditional IP rules take precedence over identity rules, or believe the gateway evaluates all matching rules before taking action.

31
MCQhard

Refer to the exhibit. Why are users on non-domain machines labeled as 'unknown'?

A.The firewall policy is too restrictive.
B.AD Query cannot identify non-domain machines.
C.The Identity Awareness blade is malfunctioning.
D.The network is using NAT.
AnswerB

AD Query is limited by design to machines that authenticate against an Active Directory domain controller. Non-domain machines do not trigger the necessary security events on the domain controller, which is the only place AD Query looks for identity information. Consequently, these machines will always show as 'unknown' in this setup.

Why this answer

The current configuration only enables AD Query, which specifically relies on Windows domain login events. Non-domain machines do not participate in the domain login process, so the domain controller never generates the security logs required for AD Query to function. Because Captive Portal and Identity Agents are disabled, there is no secondary or fallback method available to identify these non-domain users, resulting in an 'unknown' identity status for their traffic.

Exam trap

Candidates often incorrectly assume that AD Query can identify any device on the network, forgetting that it is strictly dependent on Windows domain login logs from the Domain Controller.

32
MCQmedium

Which command is used to clear the user sessions in the Identity Awareness database on a Security Gateway?

A.fw tab -t user_auth -x
B.pdp session revoke all
C.cpstop && cpstart
D.identity_clear
AnswerB

The 'pdp session revoke all' command is the correct and supported method to clear all active user sessions from the Identity Awareness database. This clears the mapping cache, forcing the gateway to re-authenticate users, which is essential for troubleshooting or resetting the environment after significant policy changes.

Why this answer

The 'pdp' (Policy Decision Point) command is the primary CLI utility for managing Identity Awareness. Specifically, 'pdp session revoke' allows administrators to manually terminate individual user sessions or clear the entire database. This is a vital task when testing identity policies or when a user's session appears stuck, preventing them from accessing resources correctly due to an outdated identity mapping in the gateway's active cache.

Exam trap

Candidates often guess general firewall policy commands or database restart scripts instead of the specific 'pdp' utility designed for Identity Awareness sessions.

33
MCQmedium

An administrator wants to ensure that mobile devices are correctly identified. Which method is most appropriate for mobile device identity identification in a Wi-Fi environment?

A.AD Query
B.Captive Portal
C.Identity Agent
D.Browser-based transparent authentication
AnswerB

Captive Portal is a device-agnostic method that works at the application layer. It is the most reliable way to enforce identity on mobile devices, as it forces the user to provide credentials through their web browser, ensuring that the identity is captured regardless of the specific device's operating system.

Why this answer

Captive Portal or integration with an MDM (Mobile Device Management) system is most appropriate for mobile devices. Unlike Windows PCs that can join a domain and use AD Query, mobile devices are typically not domain-joined. Using Captive Portal ensures that regardless of the device type or OS, the user must authenticate, allowing the firewall to associate their mobile session with a known identity for consistent security policy application.

Exam trap

Candidates often try to apply AD Query to mobile devices. Since mobile devices do not join Active Directory, they cannot trigger the necessary Windows security events for AD Query.

34
MCQhard

An administrator configures Identity Awareness to use AD Query and creates an Access Control rule allowing the 'Sales' identity group to reach a CRM server. Users in Sales are identified, yet some still get blocked. Reviewing logs shows their sessions exist but the group membership is missing. Which configuration should the administrator verify first?

A.The AD Query refresh and group synchronization settings that determine how often group membership is updated from Active Directory.
B.The Identity Agent installation package version deployed to Sales laptops.
C.The Captive Portal login page branding and timeout values.
D.The Security Gateway's routing table entries toward the CRM server subnet.
AnswerA

AD Query builds identity sessions from logon events and then resolves the user's group membership from Active Directory. If group synchronization is infrequent or misconfigured, the session can exist while the associated group data is stale or absent, causing the identity-based rule to fail. Verifying these settings directly addresses the missing group membership shown in the logs.

Why this answer

When an identity session exists but group membership is absent, the issue is usually in how group data is resolved and refreshed from Active Directory. AD Query relies on periodic synchronization to map users to their groups, so stale or misconfigured group synchronization settings explain why identified Sales users lack the group needed to match the rule.

Exam trap

The trap here is chasing portal or agent settings for a symptom that is really about how group data is synchronized from Active Directory.

35
MCQmedium

A security administrator is configuring Identity Awareness with Terminal Server Agent on a Citrix server. Users report that after logging off and logging back in, they are still associated with their previous session, causing policy inconsistencies. What is the most likely cause of this issue?

A.The Security Gateway's identity database is full and cannot accept new sessions.
B.The user's credentials are cached by the Citrix server, causing automatic re-authentication with the old identity.
C.The Terminal Server Agent is not configured to monitor session logoff events.
D.The Terminal Server Agent requires a reboot after each user logoff to clear the session.
AnswerC

The Terminal Server Agent must be configured to monitor both logon and logoff events. If logoff events are not monitored, the gateway will not remove the user's identity when they log off, leading to stale sessions. This causes the user to retain their previous identity upon re-login.

Why this answer

The Terminal Server Agent must be configured to monitor both logon and logoff events to accurately track user sessions. If logoff events are missed, the gateway retains the user's identity, causing policy inconsistencies when the user logs back in. Ensuring proper event monitoring resolves the issue.

Exam trap

The trap here is overlooking that Terminal Server Agent needs explicit configuration to monitor logoff events, not just logon events.

Ready to test yourself?

Try a timed practice session using only Identity Awareness questions.