156-315.81.20 Identity Awareness Practice Question
An administrator notices that users connecting through a Citrix XenApp published application server are all appearing as a single user in Identity Awareness access logs. What is the appropriate solution to resolve this limitation?
⚠ Common exam trap
Candidates often suggest installing standard Identity Agents on the server. However, standard agents cannot distinguish between multiple users sharing one IP, leading to the need for the specialized Terminal Server Identity Agent.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the Terminal Server Identity Agent on the Citrix XenApp server.
Standard Identity Awareness mechanisms map IP addresses to users. In multi-user server environments like Citrix or Terminal Services, multiple concurrent users share the exact same server IP address. Deploying the Terminal Server Identity Agent allows the gateway to differentiate users based on dynamic port allocations assigned to each individual session.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the AD Query timeout value in SmartConsole to prevent session caching conflicts.
Why it's wrong here
Adjusting AD Query timeouts does not resolve multi-user IP sharing challenges on Citrix servers. Since AD Query maps IP addresses to users, multiple users sharing one server IP will continuously overwrite each other's identity mapping regardless of timeout settings.
- ✓
Deploy the Terminal Server Identity Agent on the Citrix XenApp server.
Why this is correct
The Terminal Server Identity Agent reports each individual session's user identity from the Citrix XenApp server to the gateway, so Identity Awareness logs distinguish users instead of collapsing them into one. This resolves the single-user limitation caused by NAT-style session sharing.
- ✗
Configure Captive Portal to prompt users for credentials every time they launch a published application.
Why it's wrong here
Captive Portal relies on IP address mapping and browser redirects, which fails in shared Citrix environments where browser traffic from multiple users originates from a single IP. Prompting via captive portal would cause constant session hijacking and incorrect identity assignments.
- ✗
Enable Identity Agent in browser-only mode on all client endpoints connecting to Citrix.
Why it's wrong here
Browser-only Identity Agent cannot identify users behind Citrix because the agent runs on the endpoint, not inside the published session. The Citrix terminal server needs an Identity Agent installed locally, or Identity Awareness Terminal Servers integration, to resolve individual sessions. Browser mode suits direct endpoint browsing.
Visual reference
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.