156-315.81.20 Identity Awareness Practice Question
A security administrator is troubleshooting an Identity Awareness issue where users are not being identified on a Security Gateway. The gateway is configured to use AD Query. The administrator runs the command 'pdp monitor all' and sees that no users are listed. Which of the following is the most likely cause?
⚠ Common exam trap
The trap here is overlooking the service account status and jumping to more complex causes like licensing or time sync, when a simple credential issue is often the culprit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The AD Query account password has expired or is incorrect.
AD Query relies on a service account to read user information from Active Directory. If the account credentials are invalid or the password has expired, the gateway cannot connect, resulting in no identities being learned. The other options are less likely given the symptom of zero users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Security Gateway is not licensed for Identity Awareness.
Why it's wrong here
If the gateway were not licensed, the Identity Awareness blade would not function at all, and the administrator would likely see a license error. The scenario implies the blade is configured and the administrator is troubleshooting, so licensing is probably not the issue. The absence of users points to a connectivity or credential problem.
- ✗
The gateway's clock is not synchronized with the Active Directory server.
Why it's wrong here
While time synchronization is important for Kerberos authentication, AD Query typically uses LDAP or a proprietary protocol that is less sensitive to time skew. A clock mismatch might cause authentication failures in some scenarios, but it is less likely to result in zero users being identified. The more direct cause is an account issue.
- ✓
The AD Query account password has expired or is incorrect.
Why this is correct
AD Query requires a valid service account to connect to Active Directory. If the password is incorrect or expired, the gateway cannot authenticate to AD and will fail to retrieve any user information. Checking the account status and updating the password in the Identity Awareness configuration is a primary troubleshooting step.
- ✗
The AD Query is configured to query a domain controller that is offline.
Why it's wrong here
If the specified domain controller were offline, AD Query might fail to retrieve users, but Check Point typically allows configuring multiple domain controllers or uses DNS to find available ones. While possible, an expired password is a more common cause. The administrator should first verify account credentials before investigating domain controller availability.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.