156-315.81.20 Identity Awareness Practice Question
A company wants to enforce identity-based rules for remote users who connect through a VPN. The administrator needs the Security Gateway to learn the user identity during the VPN authentication process without deploying additional agents. Which Identity Awareness feature should the administrator use?
⚠ Common exam trap
The trap here is overlooking that VPN authentication itself is an identity source, and instead selecting a method that requires domain events, a browser prompt, or endpoint agents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VPN Authentication
Identity Awareness can consume the username from Remote Access VPN authentication and bind it to the VPN-assigned IP address. This gives the gateway identity for remote users as soon as the tunnel is established, with no endpoint agent and no browser prompt. Other acquisition methods either depend on domain logon events, require interactive web authentication, or need endpoint software, none of which fit the stated requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VPN Authentication
Why this is correct
Identity Awareness integrates with Remote Access VPN authentication so that when a user establishes a VPN tunnel, the gateway records the authenticated username and associates it with the assigned VPN IP address. This provides identity without extra agents and applies immediately to identity-based rules for remote users.
- ✗
AD Query
Why it's wrong here
AD Query learns identities from Active Directory security event logs on domain controllers. Remote VPN users may authenticate against the gateway or a RADIUS server rather than generating a domain logon event visible to AD Query. It is not the mechanism that captures identity directly from the VPN authentication.
- ✗
Captive Portal
Why it's wrong here
Captive Portal requires users to open a browser and authenticate to a web page before their identity is known. For VPN users, the tunnel authentication already provides identity, so adding a browser prompt would be redundant and would not be the feature that captures identity during VPN login.
- ✗
Identity Agents
Why it's wrong here
Identity Agents are installed on endpoint computers to report the logged-in user. The requirement explicitly avoids deploying additional agents, and for VPN users the tunnel authentication already supplies identity. Identity Agents would add management overhead without being necessary in this scenario.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.