156-315.81.20 Identity Awareness Practice Question
Exhibit
pdp monitor all User: admin IP: 192.168.1.10 Session ID: 4005 State: Associated Source: Captive Portal Groups: CN=Admins,OU=Groups,DC=local [Gateway Log] Error: Identity Awareness user 'admin' blocked by rule 5.
Refer to the exhibit. Rule 5 allows the group 'Admins'. Why is the user 'admin' being blocked?
⚠ Common exam trap
Candidates often focus solely on the user-to-group mapping and ignore the rule's other columns, missing that time-based constraints or source network restrictions might be the actual cause of the block.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The rule has additional constraints (e.g., source/destination/time) not met.
The user is correctly associated with the 'Admins' group. If a rule specifically allowing this group is blocking the traffic, it is highly likely that the rule contains additional restrictions, such as time-based limitations, specific service restrictions, or the rule is being shadowed by a higher-priority block rule. Alternatively, the user might be mapped to the group, but the rule requires an additional factor like a specific machine or device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user is not authenticated.
Why it's wrong here
The exhibit shows the state is 'Associated' and the source is 'Captive Portal'. This indicates the user has successfully authenticated. If the user were not authenticated, the state would likely show 'Pending' or not be present in the PDP table at all, so this is not the cause.
- ✓
The rule has additional constraints (e.g., source/destination/time) not met.
Why this is correct
Identity is only one part of a security rule. Even if the user is in the correct group, the rule may have other requirements such as a specific source network, destination, or time-of-day. If any of these secondary criteria are not met, the gateway will block the traffic despite the identity match.
- ✗
The PDP table is corrupt.
Why it's wrong here
A corrupt PDP table is extremely rare and usually presents with symptoms far more severe than a single user being blocked. The output shows valid information for the user session, suggesting the Identity Awareness engine is functioning correctly and the issue is a policy-based restriction rather than a system failure.
- ✗
The group 'Admins' is not synced to the gateway.
Why it's wrong here
If the group were not synced, the 'pdp monitor' output would not show the group membership for the user. Since the output explicitly shows 'Groups: CN=Admins...', it confirms the gateway has successfully fetched and associated the user with the correct group, proving sync is working as expected.
About these practice questions
Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.