Courseiva

156-215.81.20 · topic practice

Identity Awareness practice questions

Identity Awareness on Check Point R81 covers how gateways learn user, machine, and group identity and enforce it in Access Control and Threat Prevention rules. Expect exhibits of CLI output, RADIUS and AD Query error logs, and rule-order questions where an identity-based rule interacts with IP-based rules.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Identity Awareness

What the exam tests

What to know about Identity Awareness

Diagnose identity resolution with pdp and Identity Awareness CLI output, then read Access Control rule order correctly. The single most important thing: identity-based rules must sit above broader IP-based rules, or the wrong rule matches and policy never evaluates the user.

Identity Sources: AD Query, Identity Agents, Captive Portal, RADIUS accounting, and Terminal Servers/Session-based identities

Using 'pdp' diagnostics and the Identity Awareness blade CLI to confirm which identity source resolved a user

Building Access Control rules with Access Roles, users, groups, and machines instead of plain IP objects

Configuring RADIUS authentication and accounting, including shared secret and accounting port settings

Watch out for

Common Identity Awareness exam traps

  • ▸Placing an identity-based rule below an IP-based rule, so the IP rule matches first and identity is never evaluated
  • ▸Assuming AD Query alone covers all users when locked workstations or roaming clients need an Identity Agent or Captive Portal
  • ▸Ignoring rule order and implied cleanup rules, then blaming the identity source for a policy that never reaches the identity rule

Practice set

Identity Awareness questions

20 questions · select your answer, then reveal the explanation

Which TWO of the following statements accurately describe the functionality of the Identity Awareness 'Identity Collector'?

Which THREE of the following are valid Identity Awareness 'Identity Sources' that can be used to identify users?

An administrator notices that some users are identified correctly while others show as 'unknown'. What is the most likely reason for this discrepancy in an Identity Awareness environment using AD Query?

Refer to the exhibit. An administrator receives this error on a client machine. Which configuration error on the gateway is the most likely cause?

Exhibit

Error: 'Identity Agent failed to connect to the gateway. Please check the gateway's Identity Awareness configuration.'

When designing an Identity Awareness deployment utilizing Terminal Servers, an administrator must select the appropriate tracking mechanisms to ensure accurate user identification. Which TWO mechanisms are natively supported by Check Point Identity Awareness for Terminal Server environments? (Choose two)

An administrator notices that Active Directory Query is failing to resolve user identities for a newly established subnet of workstations. The Security Gateway and Domain Controllers can communicate via ICMP, but queries fail. Which TWO troubleshooting steps should the administrator perform to resolve this issue? (Choose two)

Which Identity Awareness method is best suited for an environment where users utilize non-domain joined devices and require seamless authentication without client software?

Question 8mediummultiple choice
Review the full subnetting walkthrough →

An administrator notices that Identity Awareness is not correctly identifying users from a specific subnet. The gateway is configured with AD Query. Which log source should the administrator check to verify the gateway is receiving successful login events?

Which TWO of the following are prerequisites for configuring Identity Awareness with AD Query?

Which THREE of the following are valid Identity Awareness sources for identifying users?

Question 11mediummultiple choice
Read the full Identity Awareness explanation →

Which object type should an administrator use in a Firewall rule to restrict access based on Active Directory group membership?

A security administrator has deployed a single Security Gateway running R81.20 with Identity Awareness configured to use the Terminal Server Agent method. Users authenticate to a Citrix XenApp terminal server, which then reports their identities to the Gateway. After several weeks in production, the administrator notices that user-to-IP mappings remain valid long after users disconnect, causing stale identities to be matched against firewall rules. The administrator verifies that the Terminal Server Agent is running and heartbeating normally, and that the Gateway is receiving updates. What is the MOST likely cause of the stale identity mappings?

Question 13mediummultiple choice
Read the full Identity Awareness explanation →

A security administrator manages a Check Point R81.20 Security Gateway that enforces identity-based rules for users in an Active Directory domain. The organization wants to avoid installing any software on user computers and does not want to deploy a separate Identity Collector. Which Identity Awareness method should the administrator configure on the Security Gateway?

Question 14mediummultiple choice
Read the full Identity Awareness explanation →

A security administrator manages a Check Point R81.20 Security Gateway that enforces identity-based rules for users authenticating through a Captive Portal. Users complain that they must log in every morning even though the portal shows a session timeout of 480 minutes. After reviewing the gateway configuration, the administrator notices that the Identity Awareness blade is set to use the 'AD Query' method only. Which action should the administrator take to resolve the frequent re-authentication?

Question 15mediummultiple choice
Read the full Identity Awareness explanation →

A security administrator manages a Security Gateway where Identity Awareness is configured with both AD Query and Identity Agents (Captive Portal). Users who log into their domain-joined laptops via AD Query are also prompted by the Captive Portal, causing duplicate identity records and confusing session logs. Which action resolves this without disabling either acquisition method entirely?

A security administrator is deploying Identity Awareness on a Check Point R81.20 Security Gateway. The organization wants to identify users without installing any software on the user computers and without requiring the gateway to be a domain member. Which Identity Awareness method should the administrator use?

An administrator is deploying Identity Awareness in a Check Point R81.20 environment. The company uses both domain-joined Windows workstations and non-domain-joined Linux servers. The administrator wants to ensure that users on both types of systems are identified. Which two methods should be configured to meet this requirement? (Choose two.)

Question 18mediummultiple choice
Read the full DHCP explanation →

A security administrator manages a Check Point R81.20 Security Gateway that protects a network where users authenticate through a Captive Portal. The administrator wants to prevent users from having to log in again every time their IP address changes due to DHCP lease renewal. Which Identity Awareness configuration should be implemented?

A security administrator has configured Identity Awareness on a Security Gateway using AD Query. Users report that after changing their passwords, they are still identified as the old user in the logs. The administrator verifies that the gateway can reach the domain controllers. What is the most likely cause of this issue?

A security administrator needs to configure Identity Awareness on a Check Point R81.20 Security Gateway so that users are identified by reading security event logs from domain controllers. Which Identity Awareness method should be selected?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Identity Awareness sessions

Start a Identity Awareness only practice session

Every question in these sessions is drawn from the Identity Awareness domain — nothing else.

Related practice questions

Related 156-215.81.20 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 156-215.81.20 exam test about Identity Awareness?
Diagnose identity resolution with pdp and Identity Awareness CLI output, then read Access Control rule order correctly. The single most important thing: identity-based rules must sit above broader IP-based rules, or the wrong rule matches and policy never evaluates the user.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Identity Awareness questions in a focused session?
Yes — the session launcher on this page draws every question from the Identity Awareness domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 156-215.81.20 topics?
Use the topic links above to move to related areas, or go back to the 156-215.81.20 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 156-215.81.20 exam covers. They are not copied from any real exam or dump site.