Courseiva
Identity Awareness →easyMultiple Choice

156-315.81.20 Identity Awareness Practice Question

An administrator is configuring Identity Awareness on a Check Point Security Gateway. The organization wants to identify users based on their login to the Windows domain without installing any software on user computers. Which Identity Awareness method should be used?

⚠ Common exam trap

It's easy for candidates to confuse AD Query with Identity Agent, or assuming Captive Portal can transparently identify domain logins without user interaction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AD Query

AD Query is a transparent identification method that reads Windows Security Event Logs on domain controllers to track user logons. It requires no software on user computers and integrates with Active Directory. This makes it the ideal choice for identifying users based on domain login without endpoint agents. The other methods either require software installation, user interaction, or additional infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    AD Query

    Why this is correct

    AD Query identifies users by querying domain controllers for logon events, without requiring any software on user computers. It is a transparent method that leverages existing Windows authentication. This meets the requirement of no software installation on user endpoints. It is the correct choice for identifying users based on domain login without additional agents.

  • ✗

    Identity Agent

    Why it's wrong here

    Identity Agent requires installing a client on each user's computer. The scenario explicitly states that no software should be installed on user computers. Therefore, Identity Agent is not suitable. It provides granular control and supports multiple users per machine, but it violates the no-install requirement.

  • ✗

    RADIUS Accounting

    Why it's wrong here

    RADIUS Accounting is used to identify users based on RADIUS accounting packets, often from VPN or wireless controllers. It does not directly leverage Windows domain login and may require additional infrastructure. It is not the primary method for transparent domain login identification and is not suitable here.

  • ✗

    Captive Portal

    Why it's wrong here

    Captive Portal requires users to manually authenticate via a web portal, which is an interactive process and not transparent. It does not rely on domain login and typically requires user action. While it does not require software installation, it is not based on Windows domain login and thus does not meet the requirement of identifying users based on their domain login.

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.