156-315.81.20 Identity Awareness Practice Question
An administrator has deployed Identity Awareness on a Security Gateway in AD Query mode. Users authenticate to the domain and their identities are learned successfully. However, a security policy rule that should permit access to an internal web server for the group 'Sales' is not matching. The administrator verifies that user 'jsmith' is a member of 'Sales' in Active Directory. The gateway's PDP shows the user identity, but the group is missing. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that successful user identification automatically includes group information, but AD Query requires explicit permissions to read group memberships.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The AD Query account does not have permissions to read group membership attributes.
AD Query relies on a service account to read user and group objects from Active Directory. If the account cannot read the memberOf attribute or group membership, the gateway will not have the group list, causing group-based rules to fail. The other options are either unrelated to the symptom or would cause broader failures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user's identity was learned via a different method (e.g., Captive Portal) and is not associated with AD Query.
Why it's wrong here
The scenario states the gateway is in AD Query mode and the user authenticated to the domain, so the identity is learned via AD Query. If another method were used, the user might still have group information if that method retrieves it. The missing group specifically indicates a problem with AD Query's group retrieval, not a method conflict.
- ✗
The Security Gateway's Identity Awareness blade is not licensed for group-based policies.
Why it's wrong here
Identity Awareness licensing does not restrict group-based policies; all supported features are available with a valid license. The issue is not licensing but the ability to read group data from Active Directory. A licensing problem would typically prevent the blade from functioning at all or show a license error, not just missing groups.
- ✓
The AD Query account does not have permissions to read group membership attributes.
Why this is correct
AD Query uses a dedicated service account to query Active Directory for user and group information. If that account lacks read access to group membership attributes (e.g., memberOf), the gateway cannot retrieve the group list, so group-based rules fail even though the user identity is known. Ensuring the account has sufficient privileges resolves the issue.
- ✗
The gateway is not configured to use LDAP over SSL (LDAPS) for group retrieval.
Why it's wrong here
AD Query does not require LDAPS to retrieve group memberships; it uses its own query mechanism. While LDAPS can be used for secure communication, its absence would not cause group information to be missing if the account has proper permissions. The symptom points to a permissions issue rather than a protocol security setting.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.