156-315.81.20 Identity Awareness Practice Question
A company wants users on managed Windows laptops to be identified by the Security Gateway without deploying any additional endpoint software and without prompting for credentials. Users already authenticate to the Active Directory domain at logon. Which Identity Awareness component is required on the Security Gateway to achieve this?
⚠ Common exam trap
The trap here is reaching for an endpoint agent or portal because they also provide identity, while overlooking that both conflict with the no-software and no-prompt requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Identity Awareness Software Blade enabled with AD Query configured against the domain controllers
For transparent identification of domain users without endpoint agents or prompts, the gateway needs the Identity Awareness blade with AD Query pointed at the domain controllers. This reads existing domain logon events and builds user-to-IP mappings, which is exactly the behavior the scenario requires.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Captive Portal configured on the gateway's internal interface
Why it's wrong here
Captive Portal identifies users by prompting them through a web page, which violates the requirement of no credential prompts. It is intended for users who are not already known to the gateway, whereas these users already authenticate to Active Directory at logon.
- ✗
A Remote Access VPN blade configured with SecuRemote
Why it's wrong here
Remote Access VPN with SecuRemote is for connecting remote users to the corporate network, not for identifying internal workstation users. It would not identify users who are already on the local network and would add VPN client software that the scenario explicitly wants to avoid.
- ✗
An Identity Agent installed on each managed laptop
Why it's wrong here
An Identity Agent would identify users, but it contradicts the requirement of deploying no additional endpoint software. The scenario explicitly asks for a solution without endpoint agents, so this approach fails the stated constraint even though it can provide identity information.
- ✓
The Identity Awareness Software Blade enabled with AD Query configured against the domain controllers
Why this is correct
This is correct because enabling the Identity Awareness blade and configuring AD Query lets the gateway read domain logon events from the domain controllers, mapping users to workstation IPs. It requires no endpoint agent and no extra credential prompt, satisfying the requirement for transparent identification of domain-authenticated users.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.