156-315.81.20 Identity Awareness Practice Question
Exhibit
[expert@security-gw:]# pdp test access 10.100.20.15 192.168.1.50 80 Matching Access Role: 'Finance_Users' Identity Source: AD Query Action: Accept
Refer to the exhibit. An administrator runs a CLI command to test policy evaluation for a specific client IP address. What does the output indicate about the gateway's evaluation process?
⚠ Common exam trap
Candidates often misinterpret simulation outputs as live packet logs rather than recognizing that 'pdp test access' only tests how the policy decision point evaluates hypothetical traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The PDP successfully resolved the source IP address to a user matching the 'Finance_Users' access role and evaluated the rule action.
The 'pdp test access' command simulates how the Policy Decision Point evaluates traffic against defined access roles and Identity Awareness rules. The output confirms that traffic from 10.100.20.15 matches the 'Finance_Users' access role via AD Query and would be permitted, verifying policy logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The gateway successfully authenticated the user via Captive Portal and applied the firewall rule.
Why it's wrong here
The test output explicitly identifies AD Query as the identity source rather than Captive Portal. This confirms the user mapping was acquired passively via domain controller event logs instead of an interactive web portal session.
- ✓
The PDP successfully resolved the source IP address to a user matching the 'Finance_Users' access role and evaluated the rule action.
Why this is correct
The command tests policy rules against the PDP database. The output demonstrates that the given IP address maps to an identity associated with the 'Finance_Users' access role, resulting in an 'Accept' decision based on the active security policy.
- ✗
The firewall dropped the packet because the destination port 80 is restricted for Finance department users.
Why it's wrong here
Policy evaluation output shows which rule matched and the resulting action for the tested IP; it does not indicate a port-80 drop tied to Finance users unless that rule is explicitly shown. This tempts because port and user-group restrictions are common rule criteria, but the exhibit reports evaluation logic, not an actual dropped packet.
- ✗
The Policy Enforcement Point rejected the connection because the user credentials expired in Active Directory.
Why it's wrong here
The CLI policy-evaluation output reports rule matching and install-on decisions; it does not query Active Directory credential expiry, and the gateway is not the Policy Enforcement Point performing user authentication. This tempts because identity awareness does integrate with Active Directory, but that occurs during authentication, not policy evaluation for a client IP.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.