Courseiva
Identity Awareness →mediumMultiple Choice

156-315.81.20 Identity Awareness Practice Question

An administrator is troubleshooting an Identity Awareness deployment where users authenticated through a Captive Portal are shown as unidentified on a different Security Gateway in the same distributed environment. The portal gateway correctly identifies the users, but the second gateway does not. Which action should the administrator take to allow the identity information to reach the second gateway?

⚠ Common exam trap

The trap here is trying to make the second gateway acquire identities independently, when the real need is to propagate identities already learned elsewhere.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Identity Sharing on the portal gateway to share identities with the second gateway

Identity Sharing is the feature that lets one gateway publish the identities it has learned so that peer gateways can use them for policy enforcement. When users are identified at the portal gateway but unknown at another gateway, enabling and correctly scoping Identity Sharing from the acquiring gateway to the peer is the direct fix.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable AD Query on the second gateway and point it at the same domain controllers

    Why it's wrong here

    AD Query is an alternative acquisition method and is not appropriate when users authenticate through Captive Portal. It would not learn portal-based identities, and deploying it on the second gateway does not address the missing propagation of identities already known to the portal gateway.

  • ✗

    Add the second gateway's internal interface to the Captive Portal configuration

    Why it's wrong here

    Captive Portal configuration is local to the gateway that redirects users to the portal. Adding an interface on the second gateway does not transfer already-learned identities to it and could cause users to be prompted again, which is not the goal of sharing existing identity data.

  • ✗

    Configure the second gateway as a Secondary Security Management Server

    Why it's wrong here

    A Secondary Security Management Server provides management high availability and policy redundancy, not identity propagation. It has no role in sharing learned identities between gateways, so it would not resolve the issue of the second gateway lacking user-to-IP mappings.

  • ✓

    Configure Identity Sharing on the portal gateway to share identities with the second gateway

    Why this is correct

    Identity Sharing is the mechanism that propagates learned identities from the gateway that acquired them to other gateways. Enabling it on the portal gateway so it shares with the second gateway lets the second gateway enforce identity-based rules for the same users without needing its own acquisition method.

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.