156-315.81.20 Identity Awareness Practice Question
A security administrator is deploying Identity Awareness on a Check Point R81 Security Gateway. The environment uses a Windows Server 2019 domain controller, and the administrator wants the gateway to learn user identities by querying Windows Security Event Logs on the domain controller. The administrator has already configured the Identity Awareness blade and enabled AD Query in SmartConsole. Which additional configuration is required on the domain controller for AD Query to function?
⚠ Common exam trap
The trap here is assuming that AD Query requires an agent or RADIUS configuration, when it actually depends on Windows Security Event Log audit policies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable the 'Audit Logon Events' and 'Audit Account Logon Events' policies in the Default Domain Controllers Policy.
AD Query collects user identity by reading Windows Security Event Logs from domain controllers. For the domain controller to generate the necessary logon events, audit policies for logon events must be enabled. Without these audit policies, the gateway cannot receive the events and map users to IP addresses, causing identity awareness to fail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable the 'Audit Logon Events' and 'Audit Account Logon Events' policies in the Default Domain Controllers Policy.
Why this is correct
AD Query relies on reading Windows Security Event Logs, specifically events 4624 and 4768/4769, which record logon activity. Without enabling audit policies for logon events on the domain controller, these events are not generated, and the gateway cannot map IP addresses to users. This is a mandatory prerequisite for AD Query to collect identity data.
- ✗
Enable the 'Identity Awareness' Windows Firewall exception on the domain controller.
Why it's wrong here
The Windows Firewall exception is not a specific Identity Awareness option. AD Query requires access to WMI and event logs, which typically involves opening specific ports (e.g., RPC, WMI) rather than a named exception. This option is not a recognized configuration step for AD Query.
- ✗
Configure a RADIUS server on the domain controller and point the gateway to it.
Why it's wrong here
RADIUS is used for authentication in some Identity Awareness methods, but AD Query does not use RADIUS. AD Query reads Windows Security Event Logs directly. Configuring RADIUS would not enable AD Query and would not provide the required logon event data for identity mapping.
- ✗
Install the Check Point Identity Awareness agent on each domain controller.
Why it's wrong here
No Check Point agent is installed on domain controllers for AD Query. The gateway communicates directly with the domain controller using native Windows protocols (WMI and event log access). Installing an agent is not part of the AD Query configuration and would be an unnecessary change to the domain controller.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.