156-215.81.20 Identity Awareness Practice Question
Which of the following is a recommended best practice when using Identity Awareness for internal network security?
⚠ Common exam trap
Many candidates mistakenly choose IP-based rules for internal segmentation, overlooking the core security principle that Identity Awareness enables granular, user-group-based access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create rules based on user groups rather than IP addresses.
The most effective way to secure an internal network using Identity Awareness is to implement a 'least privilege' approach combined with granular user-group rules. By defining policies that only allow specific users access to the resources they need to perform their job functions, administrators significantly reduce the internal attack surface. This prevents lateral movement by attackers who might compromise a single machine, as their access remains limited to the authorized user's permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable all Identity Awareness sources on all gateways.
Why it's wrong here
Enabling all sources is unnecessary and can create excessive traffic and management complexity. Only the sources required for the specific network environment should be enabled. This minimizes the risk of misconfiguration and ensures that the gateway's resources are dedicated to the most relevant identity sources for that segment.
- ✓
Create rules based on user groups rather than IP addresses.
Why this is correct
Rules based on user groups are far more flexible and sustainable than IP-based rules. As users move between machines or IPs, the identity policy automatically applies the correct security settings to them. This approach is the cornerstone of modern, robust, and scalable identity-aware access control within an enterprise network.
- ✗
Only use Captive Portal for all users.
Why it's wrong here
Relying solely on Captive Portal is highly disruptive to user productivity. It ignores the benefits of transparent methods like AD Query and Identity Agents. A mature deployment should prioritize transparent methods for efficiency and only use Captive Portal as a fallback for guest users or non-compliant, unmanaged devices.
- ✗
Disable logging to improve gateway performance.
Why it's wrong here
Disabling logging eliminates visibility, making it impossible to perform audits or incident response. Security is predicated on visibility. Administrators must maintain logs to identify suspicious activity, verify that access policies are working correctly, and ensure compliance with security standards, regardless of the potential minor performance impact on the gateway.
About these practice questions
This 156-215.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.