156-315.81.20 Identity Awareness Practice Question
An administrator is troubleshooting Identity Awareness on a Security Gateway. Users authenticated previously, but now the gateway shows them as unidentified and all traffic falls to the default rule. The administrator confirms the gateway can reach the domain controllers and that the Identity Awareness blade is enabled. Which action should the administrator take first to verify whether the gateway is receiving identity information from the PDP?
⚠ Common exam trap
The trap here is reaching for packet capture or system statistics when a single PDP diagnostic command directly shows whether identities are present on the gateway.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run 'pdp monitor all' on the Security Gateway to view currently identified users and their sources.
The pdp monitor command is the native diagnostic for Identity Awareness on a gateway. It shows the identity table populated by the PDP, including which acquisition sources have reported users. If the table lacks expected entries, the administrator can focus on the acquisition method or PDP connectivity. Other commands inspect system health or raw packets but do not directly reveal whether the gateway has current user identities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run 'cpconfig' on the Security Gateway to re-enable the Identity Awareness blade.
Why it's wrong here
cpconfig is used for initial configuration tasks such as licensing and certificate setup, not for enabling blades, which is done through the SmartConsole or Gaia portal. Re-running cpconfig would not display identity status and could risk misconfiguration. It is not a diagnostic step for missing identities.
- ✓
Run 'pdp monitor all' on the Security Gateway to view currently identified users and their sources.
Why this is correct
The pdp monitor command queries the local PDP on the gateway and displays the identity table, including users, machines, and the acquisition source that reported them. If the table is empty or stale, the problem is in acquisition or PDP communication. This directly checks whether identity data is reaching the gateway, making it the correct first diagnostic step.
- ✗
Run 'fw monitor' on the Security Gateway to capture identity traffic on the wire.
Why it's wrong here
fw monitor captures packets traversing the inspection points and can show identity protocol traffic, but interpreting it requires knowing the exact ports and protocols and it does not present the resulting identity table. It is a lower-level tool and not the quickest way to verify whether the PDP has populated identities.
- ✗
Run 'cpstat os -f all' on the Security Gateway to inspect operating system statistics.
Why it's wrong here
cpstat os reports CPU, memory, disk, and other host statistics. It does not display identity mappings, PDP status, or acquisition source information. While useful for general health checks, it cannot confirm whether the gateway is receiving user identities, so it would not answer the troubleshooting question.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.