Courseiva

CCNA Identity Awareness Questions

32 questions · Identity Awareness · All types, answers revealed

1
MCQmedium

An administrator is troubleshooting an Identity Awareness deployment where AD Query fails to resolve user identities for workstations located in a newly added branch office subnet. The Security Gateway can successfully ping the Domain Controllers in the branch office. What is the most likely cause of this communication failure?

A.The Security Gateway lacks the necessary routing table entries to reach the branch office local subnet.
B.Necessary ports such as RPC (135) and SMB (445) are blocked between the Security Gateway and the Domain Controllers.
C.The branch office workstations have not installed the Check Point Identity Agent software.
D.The Captive Portal Web API service on the Security Gateway has been stopped by the administrator.
AnswerB

AD Query requires active RPC and SMB communication to query Windows Security Event logs remotely from Domain Controllers. When intermediate or host firewalls block these administrative ports, the gateway cannot read login events, causing identity resolution to fail completely.

Why this answer

AD Query relies on specific remote procedure call mechanisms and Windows Management Instrumentation protocols to read Security Event logs from Domain Controllers. If required ports like RPC Endpoint Mapper (135), SMB (445), or dynamic RPC ports are blocked by intermediate firewalls or host firewalls, the gateway cannot poll logs, resulting in complete identity resolution failure.

Exam trap

Engineers often assume that successful basic connectivity like pinging the Domain Controller means AD Query will function, overlooking that specific management and log-scraping ports might be blocked.

2
MCQhard

A Security Gateway is configured with Identity Awareness using AD Query, and users authenticate to the domain normally. An administrator notices that identities for users who log on to workstations on a remote subnet are not appearing in the Identity Awareness database, while local subnet users are identified correctly. The domain controllers are reachable and audit logging is enabled. Which configuration item should the administrator verify first?

A.The Captive Portal certificate is trusted by the remote workstations
B.The remote subnet is included in the AD Query configuration's monitored networks
C.The gateway's identity sharing setting is set to 'Sharing to all gateways'
D.The gateway's DNS resolver is configured to query the domain controllers
AnswerB

This is correct because AD Query only tracks logons originating from IP ranges that are explicitly listed as monitored networks in the Identity Awareness configuration. If the remote subnet is missing from that list, the gateway ignores logon events from those addresses, so users there never get mapped even though the domain controllers are functioning properly.

Why this answer

AD Query filters the domain controller logon events it consumes based on the configured monitored networks. A subnet that is not listed produces no identities for its users, even when domain controllers and auditing are healthy. Verifying that the remote subnet appears in the AD Query network list is the direct and most likely fix for this selective failure.

Exam trap

The trap here is blaming domain controller connectivity or DNS for an identity gap, when AD Query silently ignores subnets it is not configured to monitor.

3
MCQmedium

An administrator needs to implement Identity Awareness in a large environment with multiple Active Directory domains. Which method ensures the most efficient identity retrieval without requiring client-side agent installations on every workstation?

A.Identity Agent
B.Browser-Based Authentication
C.Active Directory Query (AD Query)
D.Remote Access VPN
AnswerC

AD Query enables the Security Gateway to identify users by monitoring domain controller security logs for authentication events. This method is completely agentless, highly scalable across multi-domain environments, and provides transparent identity mapping without needing to install any software on the individual workstations within the corporate network.

Why this answer

Active Directory Query (AD Query) is the optimal choice here as it leverages WMI/RPC to monitor domain controller security logs for Kerberos/NTLM authentication events. This agentless approach provides real-time identity mapping across complex domain topologies without the administrative overhead of deploying and maintaining Identity Agents on thousands of endpoints, ensuring seamless scalability and minimal impact on user systems.

Exam trap

Candidates often choose 'Identity Agents' for speed, ignoring the requirement that the solution must not require client-side installations, which immediately disqualifies agents and points to AD Query.

4
MCQmedium

When using the Identity Agent, what is the 'Shared User' feature used for?

A.To allow multiple users to share a single set of credentials.
B.To identify multiple users behind a single IP address.
C.To allow a user to authenticate from multiple devices.
D.To share user identity data between different gateways.
AnswerB

The 'Shared User' feature is specifically designed for environments like Terminal Servers or Citrix, where many users connect from a single server IP. By using this feature, the gateway can identify every individual user session separately, allowing for granular security policy enforcement based on individual identity rather than just the IP.

Why this answer

The 'Shared User' feature in Identity Awareness is specifically designed for terminal environments, such as Citrix or Terminal Servers. It allows the gateway to distinguish between multiple different users who are all sharing the same physical source IP address while connected to a central application server, ensuring that each user is identified and policies are applied individually.

Exam trap

Candidates often confuse 'Shared User' with load balancing or high availability, failing to realize it is a specific solution for terminal server environments where many users share one IP.

5
MCQmedium

An administrator is troubleshooting an Identity Awareness deployment where users authenticated through a Captive Portal are shown as unidentified on a different Security Gateway in the same distributed environment. The portal gateway correctly identifies the users, but the second gateway does not. Which action should the administrator take to allow the identity information to reach the second gateway?

A.Enable AD Query on the second gateway and point it at the same domain controllers
B.Add the second gateway's internal interface to the Captive Portal configuration
C.Configure the second gateway as a Secondary Security Management Server
D.Configure Identity Sharing on the portal gateway to share identities with the second gateway
AnswerD

Identity Sharing is the mechanism that propagates learned identities from the gateway that acquired them to other gateways. Enabling it on the portal gateway so it shares with the second gateway lets the second gateway enforce identity-based rules for the same users without needing its own acquisition method.

Why this answer

Identity Sharing is the feature that lets one gateway publish the identities it has learned so that peer gateways can use them for policy enforcement. When users are identified at the portal gateway but unknown at another gateway, enabling and correctly scoping Identity Sharing from the acquiring gateway to the peer is the direct fix.

Exam trap

The trap here is trying to make the second gateway acquire identities independently, when the real need is to propagate identities already learned elsewhere.

6
Multi-Selecthard

Which THREE parameters must be correctly configured when setting up an Active Directory Query identity source in SmartConsole? (Choose THREE)

Select 3 answers
A.Domain Controller IP addresses or hostnames
B.Active Directory administrator credentials with read access to security event logs
C.LDAP Account Unit integration with write permissions
D.NetBIOS or fully qualified domain name (FQDN)
E.Client SSL certificate for mutual TLS authentication
AnswersA, B, D

Domain Controller IP addresses or hostnames are mandatory because the query identity source must reach each domain controller directly to perform LDAP lookups. Without these endpoints, SmartConsole cannot resolve user and group objects, so the identity source fails to authenticate and collect data, satisfying the stem's requirement for correct configuration.

Why this answer

Configuring AD Query requires specifying the Active Directory domain name, identifying the specific Domain Controllers to poll, and assigning an account with sufficient privileges to read the Windows security event logs. These settings allow the Security Gateway to establish secure RPC connections and query logon events accurately.

Exam trap

Candidates often forget the importance of the NetBIOS or FQDN naming convention, which is critical for the gateway to correctly associate users with the specific domain being queried.

7
MCQmedium

A security administrator is deploying Identity Awareness on a Check Point R81 Security Gateway. The environment uses a Windows Server 2019 domain controller, and the administrator wants the gateway to learn user identities by querying Windows Security Event Logs on the domain controller. The administrator has already configured the Identity Awareness blade and enabled AD Query in SmartConsole. Which additional configuration is required on the domain controller for AD Query to function?

A.Enable the 'Audit Logon Events' and 'Audit Account Logon Events' policies in the Default Domain Controllers Policy.
B.Enable the 'Identity Awareness' Windows Firewall exception on the domain controller.
C.Configure a RADIUS server on the domain controller and point the gateway to it.
D.Install the Check Point Identity Awareness agent on each domain controller.
AnswerA

AD Query relies on reading Windows Security Event Logs, specifically events 4624 and 4768/4769, which record logon activity. Without enabling audit policies for logon events on the domain controller, these events are not generated, and the gateway cannot map IP addresses to users. This is a mandatory prerequisite for AD Query to collect identity data.

Why this answer

AD Query collects user identity by reading Windows Security Event Logs from domain controllers. For the domain controller to generate the necessary logon events, audit policies for logon events must be enabled. Without these audit policies, the gateway cannot receive the events and map users to IP addresses, causing identity awareness to fail.

Exam trap

The trap here is assuming that AD Query requires an agent or RADIUS configuration, when it actually depends on Windows Security Event Log audit policies.

8
MCQmedium

An administrator has deployed Identity Awareness on a Security Gateway in AD Query mode. Users authenticate to the domain and their identities are learned successfully. However, a security policy rule that should permit access to an internal web server for the group 'Sales' is not matching. The administrator verifies that user 'jsmith' is a member of 'Sales' in Active Directory. The gateway's PDP shows the user identity, but the group is missing. What is the most likely cause?

A.The user's identity was learned via a different method (e.g., Captive Portal) and is not associated with AD Query.
B.The Security Gateway's Identity Awareness blade is not licensed for group-based policies.
C.The AD Query account does not have permissions to read group membership attributes.
D.The gateway is not configured to use LDAP over SSL (LDAPS) for group retrieval.
AnswerC

AD Query uses a dedicated service account to query Active Directory for user and group information. If that account lacks read access to group membership attributes (e.g., memberOf), the gateway cannot retrieve the group list, so group-based rules fail even though the user identity is known. Ensuring the account has sufficient privileges resolves the issue.

Why this answer

AD Query relies on a service account to read user and group objects from Active Directory. If the account cannot read the memberOf attribute or group membership, the gateway will not have the group list, causing group-based rules to fail. The other options are either unrelated to the symptom or would cause broader failures.

Exam trap

The trap here is assuming that successful user identification automatically includes group information, but AD Query requires explicit permissions to read group memberships.

9
MCQmedium

A security administrator is deploying Identity Awareness on a Check Point R81 Security Gateway using the Identity Agents method. The organization wants to avoid installing additional client software on user workstations. Which Check Point component must be deployed to collect identities from the Active Directory domain controllers without requiring a full Identity Agent on each endpoint?

A.Endpoint Security Client with Identity Awareness blade enabled
B.Identity Collector
C.Captive Portal with AD Query
D.SmartConsole Identity Awareness extension
AnswerB

Identity Collector is a Check Point component that receives identity information directly from Active Directory domain controllers via the Check Point Identity Collector API or WMI, without installing software on user endpoints. It is designed for large environments and supports multiple domain controllers. In this scenario, it eliminates the need for a full Identity Agent on each workstation while still providing transparent user identification.

Why this answer

Identity Collector is specifically designed to gather user identities from Active Directory domain controllers without installing software on user endpoints. It communicates with domain controllers using WMI or the Check Point Identity Collector API, making it suitable for large environments. The other options either require endpoint installation, rely on user interaction, or are management tools that do not collect identities at runtime.

Exam trap

The trap here is assuming that any Check Point component with 'Identity' in its name can collect identities from domain controllers without endpoint agents, when actually only Identity Collector is purpose-built for that role.

10
MCQmedium

An administrator notices that users connecting through a Citrix XenApp published application server are all appearing as a single user in Identity Awareness access logs. What is the appropriate solution to resolve this limitation?

A.Increase the AD Query timeout value in SmartConsole to prevent session caching conflicts.
B.Deploy the Terminal Server Identity Agent on the Citrix XenApp server.
C.Configure Captive Portal to prompt users for credentials every time they launch a published application.
D.Enable Identity Agent in browser-only mode on all client endpoints connecting to Citrix.
AnswerB

The Terminal Server Identity Agent reports each individual session's user identity from the Citrix XenApp server to the gateway, so Identity Awareness logs distinguish users instead of collapsing them into one. This resolves the single-user limitation caused by NAT-style session sharing.

Why this answer

Standard Identity Awareness mechanisms map IP addresses to users. In multi-user server environments like Citrix or Terminal Services, multiple concurrent users share the exact same server IP address. Deploying the Terminal Server Identity Agent allows the gateway to differentiate users based on dynamic port allocations assigned to each individual session.

Exam trap

Candidates often suggest installing standard Identity Agents on the server. However, standard agents cannot distinguish between multiple users sharing one IP, leading to the need for the specialized Terminal Server Identity Agent.

11
MCQhard

A Check Point Security Gateway uses Identity Awareness with AD Query. An administrator notices that user identities are not being recognized in firewall rules that reference Active Directory groups. The gateway can identify individual users, but group-based rules do not match. What is the most likely cause?

A.The Security Gateway's Identity Awareness blade is not licensed for group-based identification.
B.The AD Query account lacks permissions to read group membership information from Active Directory.
C.The gateway is not configured to synchronize user groups from Active Directory, or the groups are not included in the Identity Awareness configuration.
D.The firewall rules are using the wrong source object type; they should reference users instead of groups.
AnswerC

For firewall rules to match AD groups, Identity Awareness must be configured to retrieve group information. This often involves enabling group synchronization or ensuring that the relevant groups are selected in the Identity Awareness settings. If groups are not synchronized, the gateway only knows individual users and cannot map them to groups, causing group-based rules to fail. This is the most likely cause given that users are identified but groups are not.

Why this answer

Identity Awareness must be configured to synchronize group information from Active Directory for group-based rules to work. If only user identification is enabled, the gateway lacks the group membership data needed to evaluate rules referencing AD groups. Ensuring group synchronization is the key step to resolve the issue.

Exam trap

The trap here is assuming that identifying users automatically includes their group memberships, when in fact group synchronization must be explicitly configured.

12
MCQeasy

Which Identity Awareness source is best suited for identifying users connecting from non-Windows devices like mobile phones or tablets?

A.AD Query
B.Identity Agent
C.Captive Portal
D.Terminal Servers (Identity Agent)
AnswerC

Captive Portal is platform-independent because it uses standard web technologies like HTTP/HTTPS. Any device with a modern web browser can authenticate via the captive portal, making it the ideal solution for identifying mobile devices, tablets, and other non-Windows platforms that cannot support more specialized identification methods.

Why this answer

For non-Windows devices that cannot use AD Query or Identity Agents, Captive Portal is the most effective solution. It provides a web-based authentication interface that works across all platforms, ensuring that users on mobile devices are correctly identified and authenticated before being granted access to network resources. This platform-agnostic approach is essential for supporting modern Bring Your Own Device (BYOD) policies.

Exam trap

Candidates frequently select 'Identity Agents' because it is a common method, forgetting that mobile devices and non-Windows platforms do not support the installation of the Check Point Identity Agent software.

13
MCQeasy

An administrator is deploying Identity Awareness on a Security Gateway and wants to ensure that user identities are shared with other gateways in the same domain. The administrator configures the gateway as a PDP and enables Identity Sharing. Which statement describes the primary benefit of this configuration?

A.It allows the gateway to enforce identity-based policies without a local Identity Awareness blade.
B.It enables the gateway to authenticate users directly against Active Directory without additional configuration.
C.It allows the gateway to act as a PDP for other gateways, distributing identities to them.
D.It encrypts all identity traffic between the gateway and the Active Directory server.
AnswerC

Identity Sharing enables a Security Gateway to act as a Policy Decision Point (PDP) and share learned identities with other Security Gateways (PEPs) in the same domain. This centralizes identity discovery and reduces the need for each gateway to query AD directly. The primary benefit is efficient identity distribution across the environment.

Why this answer

Identity Sharing allows a gateway configured as a PDP to share its learned identities with other gateways, which act as PEPs. This reduces the load on AD servers and ensures consistent identity information across the domain. The other options misrepresent the purpose of Identity Sharing.

Exam trap

The trap here is confusing Identity Sharing with authentication or encryption features; it is specifically about distributing identities among gateways.

14
MCQeasy

An administrator is configuring Identity Awareness on a Check Point Security Gateway. The organization wants to identify users based on their login to the Windows domain without installing any software on user computers. Which Identity Awareness method should be used?

A.AD Query
B.Identity Agent
C.RADIUS Accounting
D.Captive Portal
AnswerA

AD Query identifies users by querying domain controllers for logon events, without requiring any software on user computers. It is a transparent method that leverages existing Windows authentication. This meets the requirement of no software installation on user endpoints. It is the correct choice for identifying users based on domain login without additional agents.

Why this answer

AD Query is a transparent identification method that reads Windows Security Event Logs on domain controllers to track user logons. It requires no software on user computers and integrates with Active Directory. This makes it the ideal choice for identifying users based on domain login without endpoint agents.

The other methods either require software installation, user interaction, or additional infrastructure.

Exam trap

The trap here is confusing AD Query with Identity Agent, or assuming Captive Portal can transparently identify domain logins without user interaction.

15
MCQhard

Refer to the exhibit. An administrator runs a CLI command to test policy evaluation for a specific client IP address. What does the output indicate about the gateway's evaluation process?

A.The gateway successfully authenticated the user via Captive Portal and applied the firewall rule.
B.The PDP successfully resolved the source IP address to a user matching the 'Finance_Users' access role and evaluated the rule action.
C.The firewall dropped the packet because the destination port 80 is restricted for Finance department users.
D.The Policy Enforcement Point rejected the connection because the user credentials expired in Active Directory.
AnswerB

The command tests policy rules against the PDP database. The output demonstrates that the given IP address maps to an identity associated with the 'Finance_Users' access role, resulting in an 'Accept' decision based on the active security policy.

Why this answer

The 'pdp test access' command simulates how the Policy Decision Point evaluates traffic against defined access roles and Identity Awareness rules. The output confirms that traffic from 10.100.20.15 matches the 'Finance_Users' access role via AD Query and would be permitted, verifying policy logic.

Exam trap

Candidates often misinterpret simulation outputs as live packet logs rather than recognizing that 'pdp test access' only tests how the policy decision point evaluates hypothetical traffic.

16
MCQhard

When utilizing Identity Awareness, what is the primary purpose of the 'Identity Logging' feature in the context of compliance and auditing?

A.To increase the throughput of the Security Gateway
B.To enable automatic user account lockout upon detecting suspicious traffic
C.To provide accurate user-based attribution in security logs for auditing
D.To allow the gateway to perform local user authentication without AD
AnswerC

Identity Logging transforms logs from generic IP-based entries into user-aware entries. This is essential for compliance audits, as it allows security teams to trace network actions back to a specific individual, providing an undeniable audit trail that IP addresses alone cannot offer in dynamic DHCP environments.

Why this answer

Identity Logging maps IP addresses to specific usernames within the SmartView Tracker and SmartConsole logs. This visibility is critical for compliance, as it allows administrators to perform forensic analysis, verifying exactly which user accessed which resource at a given time. By replacing ambiguous IP-based logs with identity-rich logs, organizations can meet regulatory requirements and accurately attribute network activities to human users rather than just transient internal IP addresses.

Exam trap

Candidates often confuse Identity Logging with 'Traffic Logging', thinking it is purely for bandwidth monitoring, rather than its primary purpose of providing human-readable user attribution for compliance and auditing.

17
MCQeasy

A network administrator is configuring Identity Awareness on a Security Gateway using AD Query. The administrator wants to ensure that user identities are correctly associated with IP addresses and that the gateway can resolve user group memberships for policy enforcement. Which component must be installed and configured on the Security Gateway to enable AD Query?

A.Check Point Identity Agent
B.Check Point AD Query configuration in the Identity Awareness blade
C.Check Point Terminal Server Agent
D.Check Point Captive Portal
AnswerB

AD Query is a server-side mechanism where the Security Gateway queries Active Directory domain controllers to obtain user login events and group memberships. It is configured within the Identity Awareness blade on the gateway. No client-side agent is required. This is the correct component because it directly enables the gateway to learn identities from AD without endpoint software, satisfying the requirement for transparent identification.

Why this answer

AD Query is a transparent identification method where the Security Gateway queries Active Directory domain controllers to learn user logon events and group memberships. It is configured within the Identity Awareness blade on the gateway and does not require any client-side software. The Identity Agent, Captive Portal, and Terminal Server Agent are separate identification methods used in different scenarios.

For AD Query, only the gateway configuration and proper permissions to query AD are needed.

Exam trap

The trap here is confusing AD Query with agent-based or portal-based identification, assuming that client software or user interaction is always required for Identity Awareness.

18
Multi-Selectmedium

An administrator is configuring Identity Awareness on a Check Point Security Gateway using the Captive Portal method. The organization wants to ensure that users who authenticate via the portal are correctly identified and that their identities are used in security policies. Which two actions are necessary to enable this? (Choose two.)

Select 2 answers
A.Configure the Captive Portal to use Local Authentication or an external authentication server such as RADIUS.
B.Configure the gateway to use the Identity Collector for real-time identity updates.
C.Enable AD Query to synchronize user groups from Active Directory.
D.Install a Check Point Identity Agent on each user workstation.
E.Ensure that the Security Gateway is configured to allow traffic to the Captive Portal web interface on the appropriate port.
AnswersA, E

The Captive Portal requires an authentication method to validate user credentials. Administrators can choose local authentication (using the gateway's internal user database) or integrate with external servers like RADIUS, TACACS+, or Active Directory. Without a configured authentication method, the portal cannot verify identities, and users would not be identified. This action is essential for the portal to function and map users to IP addresses.

Why this answer

Captive Portal requires an authentication method (local or external) and network access to the portal interface. These two actions enable users to authenticate and be identified. Installing endpoint agents or using AD Query/Identity Collector are not necessary for the Captive Portal method, as it is designed to work without endpoint software and uses its own authentication flow.

Exam trap

The trap here is confusing the requirements of Captive Portal with those of other Identity Awareness methods, leading to the selection of unnecessary components like Identity Agent or Identity Collector.

19
MCQeasy

A company wants to enforce identity-based rules for remote users who connect through a VPN. The administrator needs the Security Gateway to learn the user identity during the VPN authentication process without deploying additional agents. Which Identity Awareness feature should the administrator use?

A.VPN Authentication
B.AD Query
C.Captive Portal
D.Identity Agents
AnswerA

Identity Awareness integrates with Remote Access VPN authentication so that when a user establishes a VPN tunnel, the gateway records the authenticated username and associates it with the assigned VPN IP address. This provides identity without extra agents and applies immediately to identity-based rules for remote users.

Why this answer

Identity Awareness can consume the username from Remote Access VPN authentication and bind it to the VPN-assigned IP address. This gives the gateway identity for remote users as soon as the tunnel is established, with no endpoint agent and no browser prompt. Other acquisition methods either depend on domain logon events, require interactive web authentication, or need endpoint software, none of which fit the stated requirement.

Exam trap

The trap here is overlooking that VPN authentication itself is an identity source, and instead selecting a method that requires domain events, a browser prompt, or endpoint agents.

20
MCQmedium

An administrator configures Identity Awareness in a Check Point environment using Active Directory Query as the primary identity source. Users suddenly report that access policies based on user groups are randomly failing. What is the most likely root cause of this behavior?

A.The Identity Awareness Web API service on the Security Gateway stopped responding because port 443 is blocked.
B.The Active Directory Domain Controllers are purging security event logs too quickly, causing the gateway to miss logon events.
C.Check Point Identity Agents must be forcibly reinstalled on every workstation to refresh the Kerberos ticket cache.
D.The LDAP Account Unit configuration is missing the required Read-Write credentials for the domain administrator account.
AnswerB

Active Directory Query actively polls domain controller security event logs for specific logon event IDs. When logs wrap around and overwrite historical data too rapidly, the gateway loses track of active sessions, leading to intermittent policy enforcement failures across the user population.

Why this answer

Active Directory Query relies on tracking user logons via Windows security event logs. If the Security Event log fills up quickly and overwrites old events before the Security Gateway queries them, user identity mapping is lost. Administrators must monitor event log sizes and generation rates carefully to prevent authentication state dropouts in high-traffic enterprise environments.

Exam trap

Candidates often blame the gateway's configuration or SIC, failing to consider that the Active Directory environment itself might be purging the very event logs the gateway relies on for tracking.

21
MCQhard

Refer to the exhibit. An administrator is trying to refresh group membership for a user manually using the CLI. What is the most likely cause of this error?

A.The user does not exist in the local LDAP directory.
B.The LDAP Account Unit configuration is incorrect or unreachable.
C.The user is logged out of the network.
D.Identity Awareness blade is disabled on the management server.
AnswerB

The error message 'Connection to LDAP Account Unit failed' directly identifies the root cause as a failure to communicate with the defined LDAP server. This could be due to wrong IP/hostname, invalid credentials in the LDAP object, or network connectivity issues that prevent the gateway from querying the server.

Why this answer

The error explicitly points to a failure in the communication between the Security Gateway and the LDAP Account Unit. This is typically caused by a misconfigured LDAP server object, incorrect service account credentials, or a network firewall blocking the communication between the gateway and the LDAP server. The gateway cannot resolve the user's group memberships without a successful connection to the LDAP directory.

Exam trap

Students often blame local user permission issues when CLI LDAP commands fail, missing the root cause of misconfigured or unreachable LDAP Account Units.

22
MCQeasy

A company wants users on managed Windows laptops to be identified by the Security Gateway without deploying any additional endpoint software and without prompting for credentials. Users already authenticate to the Active Directory domain at logon. Which Identity Awareness component is required on the Security Gateway to achieve this?

A.A Captive Portal configured on the gateway's internal interface
B.A Remote Access VPN blade configured with SecuRemote
C.An Identity Agent installed on each managed laptop
D.The Identity Awareness Software Blade enabled with AD Query configured against the domain controllers
AnswerD

This is correct because enabling the Identity Awareness blade and configuring AD Query lets the gateway read domain logon events from the domain controllers, mapping users to workstation IPs. It requires no endpoint agent and no extra credential prompt, satisfying the requirement for transparent identification of domain-authenticated users.

Why this answer

For transparent identification of domain users without endpoint agents or prompts, the gateway needs the Identity Awareness blade with AD Query pointed at the domain controllers. This reads existing domain logon events and builds user-to-IP mappings, which is exactly the behavior the scenario requires.

Exam trap

The trap here is reaching for an endpoint agent or portal because they also provide identity, while overlooking that both conflict with the no-software and no-prompt requirements.

23
MCQhard

An administrator is troubleshooting Identity Awareness on a Security Gateway. Users authenticated previously, but now the gateway shows them as unidentified and all traffic falls to the default rule. The administrator confirms the gateway can reach the domain controllers and that the Identity Awareness blade is enabled. Which action should the administrator take first to verify whether the gateway is receiving identity information from the PDP?

A.Run 'cpconfig' on the Security Gateway to re-enable the Identity Awareness blade.
B.Run 'pdp monitor all' on the Security Gateway to view currently identified users and their sources.
C.Run 'fw monitor' on the Security Gateway to capture identity traffic on the wire.
D.Run 'cpstat os -f all' on the Security Gateway to inspect operating system statistics.
AnswerB

The pdp monitor command queries the local PDP on the gateway and displays the identity table, including users, machines, and the acquisition source that reported them. If the table is empty or stale, the problem is in acquisition or PDP communication. This directly checks whether identity data is reaching the gateway, making it the correct first diagnostic step.

Why this answer

The pdp monitor command is the native diagnostic for Identity Awareness on a gateway. It shows the identity table populated by the PDP, including which acquisition sources have reported users. If the table lacks expected entries, the administrator can focus on the acquisition method or PDP connectivity.

Other commands inspect system health or raw packets but do not directly reveal whether the gateway has current user identities.

Exam trap

The trap here is reaching for packet capture or system statistics when a single PDP diagnostic command directly shows whether identities are present on the gateway.

24
MCQhard

An administrator has configured Identity Awareness with AD Query. Users are identified correctly during the day, but every morning many users appear unidentified until they generate new domain logon events. The administrator wants to reduce this morning gap without switching acquisition methods. Which configuration should the administrator adjust?

A.Enable Captive Portal as an additional acquisition method for unidentified users.
B.Configure the AD Query to read events from all relevant domain controllers and verify event log retention.
C.Increase the identity acquisition timeout value for AD Query.
D.Reduce the identity acquisition timeout so stale entries are removed faster.
AnswerB

If the gateway queries only some domain controllers, or if security logs roll over before events are read, morning logons may be missed. Ensuring all controllers are queried and logs retain enough history lets AD Query process the overnight and early-morning events, closing the identification gap without changing methods.

Why this answer

The morning gap indicates that AD Query is not capturing overnight or early-morning logon events. Common causes are querying an incomplete set of domain controllers or security logs rolling over before the gateway reads them. Verifying that all relevant controllers are queried and that event log retention covers the gap allows AD Query to learn the identities.

Adjusting timeouts or adding Captive Portal does not address the missing events.

Exam trap

The trap here is treating the symptom by changing timeouts or adding a fallback, instead of ensuring AD Query actually reads the logon events that occurred overnight.

25
Multi-Selecthard

An enterprise environment utilizes Identity Awareness with both AD Query and Browser-Based Authentication. Security administrators notice that contractor devices, which are not joined to the Active Directory domain, fail to acquire identity roles and are blocked by internal firewall rules. Which TWO methods can be implemented to correctly identify and authenticate these non-domain-joined contractor machines? (Choose TWO)

Select 2 answers
A.Configure identity collection using Browser-Based Authentication (Captive Portal) to prompt unauthenticated users for credentials when accessing web resources.
B.Enable Identity Agent in browser-based mode or deploy the Lightweight Identity Agent on contractor laptops to report user sessions directly to the gateway.
C.Increase the AD Query polling frequency to target the local workgroups of the contractor laptops directly via WMI queries.
D.Configure Identity Awareness to map user identities statically based on the physical switch port numbers of the access layer switches.
E.Implement RADIUS Accounting synchronization with the corporate DHCP server to capture dynamic IP leases of contractor endpoints.
AnswersA, B

Captive portal authentication intercepts HTTP and HTTPS traffic from unmapped IP addresses and presents a web login page. This allows contractor accounts to authenticate successfully regardless of whether their workstations belong to the corporate Active Directory domain infrastructure.

Why this answer

Non-domain-joined machines lack Active Directory credentials and cannot participate in Kerberos authentication or AD Query log scraping. Captive portal authentication intercepts HTTP traffic to present a login prompt, while Identity Agent provides transparent identification once deployed. Both mechanisms bridge the identification gap for external or unmanaged assets effectively.

Exam trap

Test-takers often assume AD Query can identify non-domain-joined machines, forgetting that unmanaged devices lack Active Directory credentials and require alternative mechanisms like Captive Portals or Identity Agents.

26
Multi-Selecthard

Which TWO authentication methods are natively supported by Check Point Identity Awareness for acquiring user identities without requiring a client-side agent installation? (Choose TWO)

Select 2 answers
A.Active Directory Query (AD Query)
B.Check Point Endpoint Identity Agent
C.Captive Portal
D.Terminal Server Identity Agent
E.Browser-Based Identity Agent
AnswersA, C

AD Query reads user-to-IP mappings directly from Active Directory domain controller security logs, requiring no endpoint agent. This satisfies the stem's agentless constraint, unlike Identity Agents or browser-based methods that need software installed on the client.

Why this answer

Active Directory Query and Captive Portal allow the Security Gateway to identify users transparently or interactively without deploying software to endpoints. AD Query reads domain controller events, while Captive Portal prompts users via a browser redirect, making both methods ideal for unmanaged devices or environments where endpoint agent deployment is restricted.

Exam trap

Candidates often select 'Identity Agent' or 'Browser-Based Authentication' as generic terms, forgetting that the question specifies 'without requiring a client-side agent'. They accidentally choose methods that actually require software installation.

27
MCQeasy

Which core software blade must be enabled on a Check Point Security Gateway to allow the creation of access control rules based on Active Directory user groups and computer objects?

A.URL Filtering
B.Identity Awareness
C.Threat Emulation
D.Application Control
AnswerB

Identity Awareness is the blade that acquires user and computer identities from Active Directory and maps them to gateway connections, enabling access control rules keyed on AD user groups and computer objects. Without it, the gateway cannot resolve identities for rule matching.

Why this answer

Identity Awareness is the foundational Check Point software blade responsible for identifying network users and computer objects across various access methods. Enabling this blade enables administrators to write granular security policies incorporating directory attributes, ensuring robust access control aligned with corporate identity management structures.

Exam trap

Candidates frequently mistake specialized blades like Access Control or Mobile Access for the foundational blade required specifically for directory-based user and computer object identification.

28
MCQmedium

A security administrator is troubleshooting an Identity Awareness issue where users are not being identified on a Security Gateway. The gateway is configured to use AD Query. The administrator runs the command 'pdp monitor all' and sees that no users are listed. Which of the following is the most likely cause?

A.The Security Gateway is not licensed for Identity Awareness.
B.The gateway's clock is not synchronized with the Active Directory server.
C.The AD Query account password has expired or is incorrect.
D.The AD Query is configured to query a domain controller that is offline.
AnswerC

AD Query requires a valid service account to connect to Active Directory. If the password is incorrect or expired, the gateway cannot authenticate to AD and will fail to retrieve any user information. Checking the account status and updating the password in the Identity Awareness configuration is a primary troubleshooting step.

Why this answer

AD Query relies on a service account to read user information from Active Directory. If the account credentials are invalid or the password has expired, the gateway cannot connect, resulting in no identities being learned. The other options are less likely given the symptom of zero users.

Exam trap

The trap here is overlooking the service account status and jumping to more complex causes like licensing or time sync, when a simple credential issue is often the culprit.

29
MCQmedium

A security administrator is troubleshooting an Identity Awareness deployment that uses Identity Agents. Users report that they can access resources based on their identity, but sometimes they are prompted to authenticate again even though they are already logged in. The administrator checks the gateway and sees that the Identity Agent is running on the users' computers. What is a possible cause for the re-authentication prompts?

A.The Identity Agent is not configured to start automatically, so it stops when the user logs off and on.
B.The user's IP address has changed, and the Identity Agent has not updated the PDP with the new IP.
C.The gateway is configured to use AD Query in addition to Identity Agents, causing conflicting identity information.
D.The Identity Agent is configured to use a different port than the gateway's Identity Awareness service.
AnswerB

Identity Agents maintain the mapping between the user and their IP address. If the user's IP changes (e.g., due to DHCP lease renewal or switching networks), the agent must send an update to the PDP. If the update is delayed or fails, the gateway may not recognize the new IP as authenticated, prompting re-authentication. This is a common cause of intermittent identity loss.

Why this answer

Identity Agents dynamically update the PDP with the user's current IP address. If the IP changes and the agent fails to update the PDP promptly, the gateway may see traffic from an unknown IP and treat it as unauthenticated, triggering re-authentication. This is a common issue in environments with DHCP or multiple network interfaces.

Ensuring the agent is running and can communicate with the gateway is essential.

Exam trap

The trap here is assuming that once the Identity Agent authenticates a user, the identity persists indefinitely regardless of IP changes.

30
MCQhard

Refer to the exhibit. Rule 5 allows the group 'Admins'. Why is the user 'admin' being blocked?

A.The user is not authenticated.
B.The rule has additional constraints (e.g., source/destination/time) not met.
C.The PDP table is corrupt.
D.The group 'Admins' is not synced to the gateway.
AnswerB

Identity is only one part of a security rule. Even if the user is in the correct group, the rule may have other requirements such as a specific source network, destination, or time-of-day. If any of these secondary criteria are not met, the gateway will block the traffic despite the identity match.

Why this answer

The user is correctly associated with the 'Admins' group. If a rule specifically allowing this group is blocking the traffic, it is highly likely that the rule contains additional restrictions, such as time-based limitations, specific service restrictions, or the rule is being shadowed by a higher-priority block rule. Alternatively, the user might be mapped to the group, but the rule requires an additional factor like a specific machine or device.

Exam trap

Candidates often focus solely on the user-to-group mapping and ignore the rule's other columns, missing that time-based constraints or source network restrictions might be the actual cause of the block.

31
MCQmedium

An administrator is configuring Identity Awareness on a Check Point Security Gateway using the Terminal Server Agent. The environment has multiple users logging into a Citrix terminal server. The administrator wants to ensure that each user's identity is correctly associated with their individual session, not just the terminal server's IP address. Which statement describes how the Terminal Server Agent accomplishes this?

A.It uses RADIUS accounting to track user sessions on the terminal server.
B.It requires each user to authenticate through a Captive Portal when accessing the terminal server.
C.It monitors Windows Security Event Logs on the terminal server to detect user logon and logoff events.
D.It assigns a unique IP address to each user session on the terminal server.
AnswerC

The Terminal Server Agent runs on the terminal server and monitors Windows Security Event Logs for logon and logoff events (e.g., event IDs 4624, 4634). It reports these events to the Security Gateway, which then associates the user with the terminal server's IP address. This allows per-user identity tracking even when multiple users share the same IP.

Why this answer

The Terminal Server Agent is installed on the terminal server and reads Windows Security Event Logs to detect user logon and logoff events. It then sends this information to the Security Gateway, which maps each user to the terminal server's IP address. This enables per-user identity awareness even when multiple users share the same IP.

Exam trap

The trap here is assuming that the Terminal Server Agent uses Captive Portal or RADIUS, when it actually relies on Windows Security Event Logs to track individual sessions.

32
Multi-Selecthard

An administrator is implementing Identity Awareness using AD Query on a Security Gateway. Before identities can be learned from Active Directory, which two actions must be performed? (Choose two.)

Select 2 answers
A.Enable the Captive Portal on the gateway's internal interface
B.Configure the AD Query settings with the domain controller address and credentials
C.Ensure the monitored networks list includes the subnets where users log on
D.Install an Identity Agent on each workstation
E.Configure a RADIUS server object for accounting
AnswersB, C

AD Query needs to authenticate to the domain controllers to read their security event logs, so valid credentials and the DC address must be configured. Without this, the gateway cannot query logon events and no identities will be learned, regardless of other settings.

Why this answer

AD Query requires the gateway to connect to the domain controllers with valid credentials and to know which networks to monitor for logon events. Configuring the DC address and credentials enables the query, while listing the user subnets ensures events from those subnets are actually processed. Both are mandatory for identities to appear.

Exam trap

The trap here is treating endpoint agents or Captive Portal as prerequisites for AD Query, when AD Query is agentless and does not involve portal prompts.

Ready to test yourself?

Try a timed practice session using only Identity Awareness questions.