156-315.81.20 Identity Awareness Practice Question
An administrator is configuring Identity Awareness on a Check Point Security Gateway. The organization wants to identify users based on their login to the Windows domain without installing any software on user computers. Which Identity Awareness method should be used?
⚠ Common exam trap
It's easy for candidates to confuse AD Query with Identity Agent, or assuming Captive Portal can transparently identify domain logins without user interaction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AD Query
AD Query is a transparent identification method that reads Windows Security Event Logs on domain controllers to track user logons. It requires no software on user computers and integrates with Active Directory. This makes it the ideal choice for identifying users based on domain login without endpoint agents. The other methods either require software installation, user interaction, or additional infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
AD Query
Why this is correct
AD Query identifies users by querying domain controllers for logon events, without requiring any software on user computers. It is a transparent method that leverages existing Windows authentication. This meets the requirement of no software installation on user endpoints. It is the correct choice for identifying users based on domain login without additional agents.
- ✗
Identity Agent
Why it's wrong here
Identity Agent requires installing a client on each user's computer. The scenario explicitly states that no software should be installed on user computers. Therefore, Identity Agent is not suitable. It provides granular control and supports multiple users per machine, but it violates the no-install requirement.
- ✗
RADIUS Accounting
Why it's wrong here
RADIUS Accounting is used to identify users based on RADIUS accounting packets, often from VPN or wireless controllers. It does not directly leverage Windows domain login and may require additional infrastructure. It is not the primary method for transparent domain login identification and is not suitable here.
- ✗
Captive Portal
Why it's wrong here
Captive Portal requires users to manually authenticate via a web portal, which is an interactive process and not transparent. It does not rely on domain login and typically requires user action. While it does not require software installation, it is not based on Windows domain login and thus does not meet the requirement of identifying users based on their domain login.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.