Courseiva
Identity Awareness →easyMultiple Choice

156-315.81.20 Identity Awareness Practice Question

A network administrator is configuring Identity Awareness on a Security Gateway using AD Query. The administrator wants to ensure that user identities are correctly associated with IP addresses and that the gateway can resolve user group memberships for policy enforcement. Which component must be installed and configured on the Security Gateway to enable AD Query?

⚠ Common exam trap

Candidates often confuse AD Query with agent-based or portal-based identification, assuming that client software or user interaction is always required for Identity Awareness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check Point AD Query configuration in the Identity Awareness blade

AD Query is a transparent identification method where the Security Gateway queries Active Directory domain controllers to learn user logon events and group memberships. It is configured within the Identity Awareness blade on the gateway and does not require any client-side software. The Identity Agent, Captive Portal, and Terminal Server Agent are separate identification methods used in different scenarios. For AD Query, only the gateway configuration and proper permissions to query AD are needed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Check Point Identity Agent

    Why it's wrong here

    The Check Point Identity Agent is a client-side component installed on user endpoints to provide identity information to the gateway. It is used for Identity Agent-based identification, not for AD Query. AD Query does not require any client-side software. This option is incorrect because it refers to a different identification method. The Identity Agent is not needed when using AD Query, which relies on server-side queries to Active Directory.

  • ✓

    Check Point AD Query configuration in the Identity Awareness blade

    Why this is correct

    AD Query is a server-side mechanism where the Security Gateway queries Active Directory domain controllers to obtain user login events and group memberships. It is configured within the Identity Awareness blade on the gateway. No client-side agent is required. This is the correct component because it directly enables the gateway to learn identities from AD without endpoint software, satisfying the requirement for transparent identification.

  • ✗

    Check Point Terminal Server Agent

    Why it's wrong here

    The Terminal Server Agent (Multi-User Host agent) is used in environments like Citrix to identify individual users on a terminal server. It is installed on the terminal server, not on the Security Gateway. AD Query does not require this agent. This option is incorrect because it refers to a specialized component for multi-user hosts, which is unrelated to the standard AD Query configuration for typical user workstations.

  • ✗

    Check Point Captive Portal

    Why it's wrong here

    Captive Portal is a web-based authentication method that prompts users to enter credentials when they attempt to access network resources. It is used when transparent identification methods are not available or desired. AD Query does not use Captive Portal; it operates transparently in the background. This option is incorrect because it describes a different Identity Awareness source. Captive Portal is not required for AD Query and would introduce user interaction.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.