Courseiva
Identity Awareness →easyMultiple Choice

156-315.81.20 Identity Awareness Practice Question

An administrator is deploying Identity Awareness on a Security Gateway and wants to ensure that user identities are shared with other gateways in the same domain. The administrator configures the gateway as a PDP and enables Identity Sharing. Which statement describes the primary benefit of this configuration?

⚠ Common exam trap

Many exam-takers confuse Identity Sharing with authentication or encryption features; it is specifically about distributing identities among gateways.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It allows the gateway to act as a PDP for other gateways, distributing identities to them.

Identity Sharing allows a gateway configured as a PDP to share its learned identities with other gateways, which act as PEPs. This reduces the load on AD servers and ensures consistent identity information across the domain. The other options misrepresent the purpose of Identity Sharing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It allows the gateway to enforce identity-based policies without a local Identity Awareness blade.

    Why it's wrong here

    Even when receiving shared identities, a gateway must have the Identity Awareness blade enabled to enforce identity-based policies. Identity Sharing supplements local identity discovery but does not replace the need for the blade. Without the blade, the gateway cannot process identity information for policy enforcement.

  • ✗

    It enables the gateway to authenticate users directly against Active Directory without additional configuration.

    Why it's wrong here

    Identity Sharing is about distributing identities, not about the authentication mechanism itself. The gateway still needs to be configured with an identity source (e.g., AD Query) to learn identities initially. Sharing does not eliminate the need for AD integration; it only propagates the results to other gateways.

  • ✓

    It allows the gateway to act as a PDP for other gateways, distributing identities to them.

    Why this is correct

    Identity Sharing enables a Security Gateway to act as a Policy Decision Point (PDP) and share learned identities with other Security Gateways (PEPs) in the same domain. This centralizes identity discovery and reduces the need for each gateway to query AD directly. The primary benefit is efficient identity distribution across the environment.

  • ✗

    It encrypts all identity traffic between the gateway and the Active Directory server.

    Why it's wrong here

    Identity Sharing does not encrypt AD traffic; it secures the communication of identity information between Check Point gateways using SIC. AD traffic encryption would be handled separately, such as via LDAPS. The feature focuses on sharing identities among gateways, not on securing AD queries.

About these practice questions

This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.