156-315.81.20 Identity Awareness Practice Question
An administrator is configuring Identity Awareness on a Check Point Security Gateway using the Captive Portal method. The organization wants to ensure that users who authenticate via the portal are correctly identified and that their identities are used in security policies. Which two actions are necessary to enable this? (Choose two.)
⚠ Common exam trap
A common mix-up: candidates confuse the requirements of Captive Portal with those of other Identity Awareness methods, leading to the selection of unnecessary components like Identity Agent or Identity Collector.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Captive Portal to use Local Authentication or an external authentication server such as RADIUS.
Captive Portal requires an authentication method (local or external) and network access to the portal interface. These two actions enable users to authenticate and be identified. Installing endpoint agents or using AD Query/Identity Collector are not necessary for the Captive Portal method, as it is designed to work without endpoint software and uses its own authentication flow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the Captive Portal to use Local Authentication or an external authentication server such as RADIUS.
Why this is correct
The Captive Portal requires an authentication method to validate user credentials. Administrators can choose local authentication (using the gateway's internal user database) or integrate with external servers like RADIUS, TACACS+, or Active Directory. Without a configured authentication method, the portal cannot verify identities, and users would not be identified. This action is essential for the portal to function and map users to IP addresses.
- ✗
Configure the gateway to use the Identity Collector for real-time identity updates.
Why it's wrong here
Identity Collector is a component used with the Identity Agents method to gather identities from domain controllers. It is not used with Captive Portal. Captive Portal relies on user authentication through the portal itself, not on an external collector. Therefore, this action is irrelevant and incorrect for the Captive Portal scenario.
- ✗
Enable AD Query to synchronize user groups from Active Directory.
Why it's wrong here
AD Query is a separate identification method that queries Active Directory for user-to-IP mappings. While it can be used alongside Captive Portal for group synchronization, it is not a requirement for basic Captive Portal user identification. The portal authenticates users directly, and group information can be obtained from the authentication server. Thus, enabling AD Query is not necessary for the portal to identify users.
- ✗
Install a Check Point Identity Agent on each user workstation.
Why it's wrong here
The Captive Portal method is specifically designed to identify users without installing endpoint software. It uses a web-based portal to prompt for credentials. Installing an Identity Agent is characteristic of the Identity Agents method, not Captive Portal. Therefore, this action is unnecessary and contradicts the purpose of using Captive Portal for transparent identification without endpoint installation.
- ✓
Ensure that the Security Gateway is configured to allow traffic to the Captive Portal web interface on the appropriate port.
Why this is correct
For users to authenticate via the Captive Portal, they must be able to reach the portal's web interface. The gateway must have a firewall rule allowing HTTP/HTTPS traffic to the portal, typically on port 80 or 443. If this traffic is blocked, users cannot complete authentication, and identities will not be acquired. This is a necessary step to enable the portal's operation.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.