Courseiva

156-315.81.20 · topic practice

Identity Awareness practice questions

Identity Awareness on the Check Point Certified Security Expert exam covers how Security Gateways learn user identities and enforce identity-based rules. Questions are scenario-based: diagnosing AD Query failures, choosing acquisition methods for multi-domain environments, and configuring identity sources correctly in SmartConsole. Expect troubleshooting and configuration detail rather than pure theory.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Identity Awareness

What the exam tests

What to know about Identity Awareness

Be able to configure and troubleshoot AD Query and other agentless identity sources in SmartConsole, and select the right acquisition method for multi-domain environments. The most important thing: verify gateway-to-domain-controller connectivity and correct domain/credential settings before assuming policy problems.

AD Query identity source configuration in SmartConsole, including domain, credentials, and gateway association

Identity Acquisition methods: AD Query, Identity Agents, Terminal Servers, and Captive Portal without client agents

Multi-domain Active Directory environments and efficient identity retrieval across trusted domains

Troubleshooting identity resolution failures for branch subnets, LDAP connectivity, and gateway-to-DC reachability

Watch out for

Common Identity Awareness exam traps

  • ▸Assuming AD Query works across subnets without verifying the gateway can reach the domain controller and that the branch subnet is included in the query scope.
  • ▸Confusing agentless methods (AD Query, Captive Portal) with agent-based Identity Agent deployments when the question forbids client-side installation.
  • ▸Mixing up which parameters belong to the AD Query identity source versus gateway object settings, causing misconfigured domain or credentials.

Practice set

Identity Awareness questions

20 questions · select your answer, then reveal the explanation

An administrator configures Identity Awareness in AD Query mode on a Security Gateway. Users report that after logging in from workstations, traffic is occasionally blocked because the firewall associates their IP addresses with previously logged-out users. What is the most effective troubleshooting step to resolve this stale identity mapping issue?

Refer to the exhibit. An administrator runs a status command for Identity Awareness on a Security Gateway member of a High Availability cluster and sees the output shown in the exhibit. What is the immediate impact on identity enforcement for this cluster member?

Exhibit

[Identity Awareness]
Status: Enabled
AD Query Status: Connected
PDp Status: Active
PEp Status: Active
Connected PDP instances: 0
Last Error: Failed to connect to PDP on cluster peer due to SIC failure.

When configuring Identity Awareness with Active Directory integration, an administrator needs to ensure that user group memberships are retrieved accurately and efficiently. Which THREE configuration steps or prerequisites are required for successful AD Query and LDAP integration? (Choose THREE)

When configuring Identity Awareness in SmartConsole, which software blade must be enabled on the Security Gateway object before Identity Awareness options become available?

Refer to the exhibit. An administrator runs the 'pdp monitor all' command on a Security Gateway to troubleshoot an Identity Awareness issue. Based on the output, what conclusion can be made regarding the IP address 10.100.10.55?

Exhibit

[expert@security-gw:]# pdp monitor all
UID: 0-0-0-0-ip-10.100.10.55
IP: 10.100.10.55
Timeout: 3598
State: Connected
Sources: (AD Query)
User: jdoe
Domain: CORP

A Security Gateway is configured with both AD Query and Browser-Based Authentication. A user successfully logs into a workstation and generates network traffic. However, the gateway captures the user identity through Browser-Based Authentication instead of AD Query. Why did this occur?

Which TWO methods can an administrator use to verify active Identity Awareness sessions and troubleshoot user mappings on a Check Point Security Gateway CLI? (Choose TWO)

An enterprise environment implements Identity Awareness with AD Query. Security administrators notice that contractor laptops connected to the internal network are incorrectly acquiring internal user identities belonging to employees who previously used those machines. What is the best method to prevent this stale identity mapping?

Question 9hardmulti select
Read the full VPN explanation →

Which TWO of the following configurations are required to ensure that a Security Gateway can transparently identify users connecting from a remote subnet via a VPN tunnel using AD Query?

Question 10mediummultiple choice
Read the full Identity Awareness explanation →

Refer to the exhibit. An administrator is troubleshooting an issue where 'jdoe' cannot access a restricted server. The policy rule explicitly allows the 'IT_Staff' group. Based on the output, what is the most likely reason the traffic is being blocked?

Exhibit

pdp monitor all
User: jdoe
IP: 10.10.1.50
Session ID: 5218
State: Associated
Source: AD Query
Age: 120s
Groups: CN=IT_Staff,OU=Users,DC=corp,DC=local
Question 11mediummultiple choice
Read the full Identity Awareness explanation →

Which mechanism does the Identity Awareness gateway use to prevent 'Identity Spoofing' when using transparent identification methods like AD Query?

When configuring the Identity Awareness 'Captive Portal', which authentication method is considered the most secure for internal users?

Which THREE components are necessary for the 'Identity Collector' to function correctly in a Check Point environment?

Question 14mediummultiple choice
Read the full Identity Awareness explanation →

A user is authenticated via AD Query, but after 30 minutes, they lose access. The administrator checks the logs and sees 'Session Timeout'. Which setting should be adjusted to keep the user authenticated longer without requiring them to re-authenticate?

Question 15mediummultiple choice
Read the full Identity Awareness explanation →

Which of the following describes the correct order of operations when a user attempts to access a resource protected by an Identity Awareness policy?

Which TWO of the following steps are required to troubleshoot an 'Identity Awareness' user-identification failure when using 'Captive Portal'?

Question 17mediummultiple choice
Read the full Identity Awareness explanation →

An administrator wants to use Identity Awareness for internal traffic, but the gateway must not prompt users for authentication. Which combination is the most suitable?

Question 18mediummultiple choice
Read the full Identity Awareness explanation →

Which of the following describes the function of the 'Identity Awareness' gateway in a cross-domain environment?

Which TWO of the following are prerequisites for configuring Identity Awareness with Active Directory Query in a Check Point environment?

Question 20mediummultiple choice
Read the full Identity Awareness explanation →

A security administrator has deployed Identity Awareness using Terminal Servers Agent on a Citrix XenApp server. Users log in to the XenApp server with their Active Directory credentials, then open a published Internet Explorer session to access internal web applications through the Security Gateway. The administrator notices that all user sessions are attributed to the service account used by the Identity Awareness agent, not the individual users. What is the most likely cause of this issue?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Identity Awareness sessions

Start a Identity Awareness only practice session

Every question in these sessions is drawn from the Identity Awareness domain — nothing else.

Related practice questions

Related 156-315.81.20 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 156-315.81.20 exam test about Identity Awareness?
Be able to configure and troubleshoot AD Query and other agentless identity sources in SmartConsole, and select the right acquisition method for multi-domain environments. The most important thing: verify gateway-to-domain-controller connectivity and correct domain/credential settings before assuming policy problems.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Identity Awareness questions in a focused session?
Yes — the session launcher on this page draws every question from the Identity Awareness domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 156-315.81.20 topics?
Use the topic links above to move to related areas, or go back to the 156-315.81.20 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 156-315.81.20 exam covers. They are not copied from any real exam or dump site.