156-315.81.20 Identity Awareness Practice Question
An administrator has configured Identity Awareness with AD Query. Users are identified correctly during the day, but every morning many users appear unidentified until they generate new domain logon events. The administrator wants to reduce this morning gap without switching acquisition methods. Which configuration should the administrator adjust?
⚠ Common exam trap
The trap here is treating the symptom by changing timeouts or adding a fallback, instead of ensuring AD Query actually reads the logon events that occurred overnight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the AD Query to read events from all relevant domain controllers and verify event log retention.
The morning gap indicates that AD Query is not capturing overnight or early-morning logon events. Common causes are querying an incomplete set of domain controllers or security logs rolling over before the gateway reads them. Verifying that all relevant controllers are queried and that event log retention covers the gap allows AD Query to learn the identities. Adjusting timeouts or adding Captive Portal does not address the missing events.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Captive Portal as an additional acquisition method for unidentified users.
Why it's wrong here
Captive Portal would prompt unidentified users to authenticate manually, which changes the user experience and does not fix the underlying AD Query event collection problem. The administrator wants to reduce the gap without switching methods, and adding an interactive method does not address why events are missed.
- ✓
Configure the AD Query to read events from all relevant domain controllers and verify event log retention.
Why this is correct
If the gateway queries only some domain controllers, or if security logs roll over before events are read, morning logons may be missed. Ensuring all controllers are queried and logs retain enough history lets AD Query process the overnight and early-morning events, closing the identification gap without changing methods.
- ✗
Increase the identity acquisition timeout value for AD Query.
Why it's wrong here
Increasing the timeout keeps learned identities valid longer, but the problem occurs because identities are not yet learned in the morning. A longer timeout does not cause the gateway to read new events faster and could keep stale mappings after users leave, so it does not solve the morning identification gap.
- ✗
Reduce the identity acquisition timeout so stale entries are removed faster.
Why it's wrong here
Shortening the timeout causes identities to expire sooner, which would make the morning gap worse because users would be forgotten even faster overnight. It does not improve the gateway's ability to read domain logon events and would likely increase the number of unidentified users.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.