Courseiva
User and Access Management →mediumMultiple Choice

156-215.81.20 User and Access Management Practice Question

Why is it recommended to use a separate administrative account for policy management versus day-to-day monitoring?

⚠ Common exam trap

Many candidates confuse the principle of least privilege with operational convenience, incorrectly believing that using one account for all tasks simplifies audit logs and troubleshooting processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To implement the principle of least privilege.

Separating administrative duties is a best practice to reduce the impact of account compromise. By using different accounts for different levels of access, an attacker who compromises a monitoring account will not necessarily have the permissions to modify security policies. This enhances the overall security posture and ensures that critical policy changes are performed by accounts with higher levels of scrutiny.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To increase the number of licenses for the management server.

    Why it's wrong here

    Licensing is based on the number of gateways or management objects, not the number of administrator accounts created. Creating additional accounts does not increase licensing costs or requirements, and this is not a valid reason for implementing account separation strategies in a professional environment.

  • ✓

    To implement the principle of least privilege.

    Why this is correct

    The principle of least privilege dictates that users should only have the permissions necessary to perform their job. Using separate accounts allows for granular assignment of roles, ensuring that monitoring accounts have read-only access, while policy-management accounts are restricted to essential personnel for critical configuration changes.

  • ✗

    To bypass the concurrent session limits.

    Why it's wrong here

    Concurrent session limits are managed by the management server configuration and are not affected by the number of accounts used. Creating multiple accounts will not help bypass these limits and may actually lead to session exhaustion if not carefully managed within the system's global policy settings.

  • ✗

    To speed up the policy installation process.

    Why it's wrong here

    Account separation has no impact on policy compilation or installation speed. These processes are determined by the complexity of the policy and the hardware performance of the management server and gateways, and they remain constant regardless of which administrator account initiates the installation request.

About these practice questions

One of 210 original 156-215.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-215.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-215.81.20 exam.