Courseiva
Identity Awareness →mediumMultiple Choice

156-215.81.20 Identity Awareness Practice Question

What is the primary function of the 'Identity Collector' in a distributed Identity Awareness environment?

⚠ Common exam trap

Candidates often confuse the Identity Collector's offloading function with direct authentication or policy enforcement, incorrectly assuming it performs the actual packet filtering and rule evaluation instead of simply centralizing directory queries.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Offloading identity collection from the Gateway.

The Identity Collector is a dedicated software component that offloads the task of querying directory services (like Active Directory) from the Security Gateway. By centralizing the collection of identity events, it reduces the load on the gateway's CPU and allows for the integration of multiple identity sources, such as Cisco ISE or Windows Event Logs, into a single, unified feed for the security gateways.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Encrypting all user traffic.

    Why it's wrong here

    Encryption of user traffic is handled by the firewall's policy and VPN modules. The Identity Collector is solely focused on the retrieval and consolidation of identity metadata, not the encryption or inspection of the actual data packets passing through the security gateway's data plane.

  • ✓

    Offloading identity collection from the Gateway.

    Why this is correct

    The Identity Collector centralizes the collection process, which reduces the resource consumption on individual security gateways. It connects to various identity sources, gathers event data, and forwards only the relevant identity information to the gateways, ensuring optimal performance and scalability across large, distributed enterprise network deployments.

  • ✗

    Providing endpoint antivirus protection.

    Why it's wrong here

    Antivirus protection is handled by the Threat Prevention blade and the endpoint security agents. The Identity Collector is an infrastructure component used specifically for identity mapping, and it has no capability or responsibility for scanning files or network traffic for malicious content or malware threats.

  • ✗

    Enforcing access policies on the user.

    Why it's wrong here

    Access policies are enforced by the Security Gateway based on the identity information provided. The Identity Collector's role is purely to gather and distribute identity information; it does not perform any traffic filtering or policy enforcement, as that responsibility remains strictly with the Security Gateway's inspection engine.

About these practice questions

Courseiva writes every 156-215.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.