Courseiva
Identity Awareness →hardMultiple Choice

156-315.81.20 Identity Awareness Practice Question

A Check Point Security Gateway uses Identity Awareness with AD Query. An administrator notices that user identities are not being recognized in firewall rules that reference Active Directory groups. The gateway can identify individual users, but group-based rules do not match. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that identifying users automatically includes their group memberships, when in fact group synchronization must be explicitly configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The gateway is not configured to synchronize user groups from Active Directory, or the groups are not included in the Identity Awareness configuration.

Identity Awareness must be configured to synchronize group information from Active Directory for group-based rules to work. If only user identification is enabled, the gateway lacks the group membership data needed to evaluate rules referencing AD groups. Ensuring group synchronization is the key step to resolve the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The Security Gateway's Identity Awareness blade is not licensed for group-based identification.

    Why it's wrong here

    Check Point Identity Awareness licensing does not typically differentiate between user and group identification; the blade license covers both. There is no specific license restriction that disables group-based identification. Therefore, this is an incorrect assumption and not the cause of the issue.

  • ✗

    The AD Query account lacks permissions to read group membership information from Active Directory.

    Why it's wrong here

    While permissions are important, if the AD Query account lacked permissions to read group membership, the gateway would likely fail to identify users at all or show errors. The scenario states that individual users are identified, so basic query permissions are working. Group membership reading typically requires similar permissions, so this is not the most likely cause for group-only failure.

  • ✓

    The gateway is not configured to synchronize user groups from Active Directory, or the groups are not included in the Identity Awareness configuration.

    Why this is correct

    For firewall rules to match AD groups, Identity Awareness must be configured to retrieve group information. This often involves enabling group synchronization or ensuring that the relevant groups are selected in the Identity Awareness settings. If groups are not synchronized, the gateway only knows individual users and cannot map them to groups, causing group-based rules to fail. This is the most likely cause given that users are identified but groups are not.

  • ✗

    The firewall rules are using the wrong source object type; they should reference users instead of groups.

    Why it's wrong here

    The scenario implies that the administrator intends to use groups, and the issue is that group rules do not match. Changing rules to reference users would be a workaround, not a fix for the underlying problem. The question asks for the most likely cause of group-based rules not matching, so this is not the correct diagnosis.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.