156-315.81.20 Identity Awareness Practice Question
An enterprise environment utilizes Identity Awareness with both AD Query and Browser-Based Authentication. Security administrators notice that contractor devices, which are not joined to the Active Directory domain, fail to acquire identity roles and are blocked by internal firewall rules. Which TWO methods can be implemented to correctly identify and authenticate these non-domain-joined contractor machines? (Choose TWO)
⚠ Common exam trap
Test-takers often assume AD Query can identify non-domain-joined machines, forgetting that unmanaged devices lack Active Directory credentials and require alternative mechanisms like Captive Portals or Identity Agents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure identity collection using Browser-Based Authentication (Captive Portal) to prompt unauthenticated users for credentials when accessing web resources.
Non-domain-joined machines lack Active Directory credentials and cannot participate in Kerberos authentication or AD Query log scraping. Captive portal authentication intercepts HTTP traffic to present a login prompt, while Identity Agent provides transparent identification once deployed. Both mechanisms bridge the identification gap for external or unmanaged assets effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure identity collection using Browser-Based Authentication (Captive Portal) to prompt unauthenticated users for credentials when accessing web resources.
Why this is correct
Captive portal authentication intercepts HTTP and HTTPS traffic from unmapped IP addresses and presents a web login page. This allows contractor accounts to authenticate successfully regardless of whether their workstations belong to the corporate Active Directory domain infrastructure.
- ✓
Enable Identity Agent in browser-based mode or deploy the Lightweight Identity Agent on contractor laptops to report user sessions directly to the gateway.
Why this is correct
Identity Agent in browser-based mode or the Lightweight Identity Agent authenticates users directly against the gateway, capturing identity without domain membership. This satisfies the stem's constraint that contractor devices are not joined to Active Directory, so AD Query cannot resolve their identities for firewall rules.
- ✗
Increase the AD Query polling frequency to target the local workgroups of the contractor laptops directly via WMI queries.
Why it's wrong here
AD Query relies on querying Windows Security Event logs from Domain Controllers using WMI or RPC. Since contractor laptops do not register security events on corporate domain controllers, increasing polling frequency yields no identity information for unmanaged devices.
- ✗
Configure Identity Awareness to map user identities statically based on the physical switch port numbers of the access layer switches.
Why it's wrong here
Identity Awareness binds user identities to IP addresses and directory groups, not physical switch ports. While port-based security exists in network layer solutions, Check Point identity blades operate at Layer 3 and above using IP addresses and user credentials.
- ✗
Implement RADIUS Accounting synchronization with the corporate DHCP server to capture dynamic IP leases of contractor endpoints.
Why it's wrong here
DHCP lease logs track IP address allocations but do not contain authenticated user identity information. Without a mechanism to bind specific usernames to those DHCP leases, RADIUS accounting alone cannot establish granular user-based firewall rules for contractors.
About these practice questions
One of 210 original 156-315.81.20 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.