156-215.81.20 User and Access Management Practice Question
Why is it recommended to use a separate administrative account for policy management versus day-to-day monitoring?
⚠ Common exam trap
Many candidates confuse the principle of least privilege with operational convenience, incorrectly believing that using one account for all tasks simplifies audit logs and troubleshooting processes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To implement the principle of least privilege.
Separating administrative duties is a best practice to reduce the impact of account compromise. By using different accounts for different levels of access, an attacker who compromises a monitoring account will not necessarily have the permissions to modify security policies. This enhances the overall security posture and ensures that critical policy changes are performed by accounts with higher levels of scrutiny.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To increase the number of licenses for the management server.
Why it's wrong here
Licensing is based on the number of gateways or management objects, not the number of administrator accounts created. Creating additional accounts does not increase licensing costs or requirements, and this is not a valid reason for implementing account separation strategies in a professional environment.
- ✓
To implement the principle of least privilege.
Why this is correct
The principle of least privilege dictates that users should only have the permissions necessary to perform their job. Using separate accounts allows for granular assignment of roles, ensuring that monitoring accounts have read-only access, while policy-management accounts are restricted to essential personnel for critical configuration changes.
- ✗
To bypass the concurrent session limits.
Why it's wrong here
Concurrent session limits are managed by the management server configuration and are not affected by the number of accounts used. Creating multiple accounts will not help bypass these limits and may actually lead to session exhaustion if not carefully managed within the system's global policy settings.
- ✗
To speed up the policy installation process.
Why it's wrong here
Account separation has no impact on policy compilation or installation speed. These processes are determined by the complexity of the policy and the hardware performance of the management server and gateways, and they remain constant regardless of which administrator account initiates the installation request.
About these practice questions
One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.