Courseiva
Identity Awareness →easyMultiple Choice

156-315.81.20 Identity Awareness Practice Question

A company wants to enforce identity-based rules for remote users who connect through a VPN. The administrator needs the Security Gateway to learn the user identity during the VPN authentication process without deploying additional agents. Which Identity Awareness feature should the administrator use?

⚠ Common exam trap

The trap here is overlooking that VPN authentication itself is an identity source, and instead selecting a method that requires domain events, a browser prompt, or endpoint agents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPN Authentication

Identity Awareness can consume the username from Remote Access VPN authentication and bind it to the VPN-assigned IP address. This gives the gateway identity for remote users as soon as the tunnel is established, with no endpoint agent and no browser prompt. Other acquisition methods either depend on domain logon events, require interactive web authentication, or need endpoint software, none of which fit the stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    VPN Authentication

    Why this is correct

    Identity Awareness integrates with Remote Access VPN authentication so that when a user establishes a VPN tunnel, the gateway records the authenticated username and associates it with the assigned VPN IP address. This provides identity without extra agents and applies immediately to identity-based rules for remote users.

  • ✗

    AD Query

    Why it's wrong here

    AD Query learns identities from Active Directory security event logs on domain controllers. Remote VPN users may authenticate against the gateway or a RADIUS server rather than generating a domain logon event visible to AD Query. It is not the mechanism that captures identity directly from the VPN authentication.

  • ✗

    Captive Portal

    Why it's wrong here

    Captive Portal requires users to open a browser and authenticate to a web page before their identity is known. For VPN users, the tunnel authentication already provides identity, so adding a browser prompt would be redundant and would not be the feature that captures identity during VPN login.

  • ✗

    Identity Agents

    Why it's wrong here

    Identity Agents are installed on endpoint computers to report the logged-in user. The requirement explicitly avoids deploying additional agents, and for VPN users the tunnel authentication already supplies identity. Identity Agents would add management overhead without being necessary in this scenario.

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.