156-215.81.20 Identity Awareness Practice Question
Which TWO settings are required when configuring the 'Active Directory Query' method in the Identity Awareness blade?
⚠ Common exam trap
Candidates often select 'Domain Admin credentials' as a requirement. Providing Domain Admin access is unnecessary and a security risk; only specific read-only access to logs is required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The IP address of the Domain Controller.
To configure AD Query, the administrator must provide the gateway with the necessary credentials to read security logs and identify the target domain controller. These two components—the specific Domain Controller and the service account with adequate permissions—are fundamental. Without them, the gateway lacks the administrative authorization required to query the remote logs, and it would be unable to map IP addresses to user accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The IP address of the Domain Controller.
Why this is correct
The gateway needs to know exactly which server to query for security log events. Providing the IP address of the Domain Controller allows the gateway to establish the necessary WMI or RPC connection to monitor login events and map users to their corresponding IP addresses in real-time.
- ✓
A service account with permissions to read security logs.
Why this is correct
The gateway requires an account with sufficient privileges on the Domain Controller to read the Windows Security Event logs. Without the correct service account permissions, the connection will be established, but the gateway will be denied access to the actual log data required for successful identity mapping.
- ✗
A list of all users in the Active Directory.
Why it's wrong here
The gateway does not need a pre-loaded list of all users. It dynamically discovers users as they log into the network. Importing a full list of users would be inefficient and difficult to maintain, as it would require constant updates whenever a new user is added to the domain.
- ✗
The public DNS server IP address.
Why it's wrong here
Public DNS servers are irrelevant for internal Active Directory authentication processes. Identity Awareness requires internal infrastructure knowledge, such as the specific internal domain controller's address, to function correctly. Relying on public DNS would lead to connectivity failures, as domain controllers are typically resolved via internal DNS services.
- ✗
An installed Identity Agent on the Domain Controller.
Why it's wrong here
Identity Agents are designed for end-user workstations, not for domain controllers. AD Query is an agentless method, specifically designed to read standard Windows event logs without needing to install any custom software on the domain controllers themselves, keeping the infrastructure as clean and as standard as possible.
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.