Courseiva
Identity Awareness →hardMultiple Choice

156-315.81.20 Identity Awareness Practice Question

When utilizing Identity Awareness, what is the primary purpose of the 'Identity Logging' feature in the context of compliance and auditing?

⚠ Common exam trap

Candidates often confuse Identity Logging with 'Traffic Logging', thinking it is purely for bandwidth monitoring, rather than its primary purpose of providing human-readable user attribution for compliance and auditing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To provide accurate user-based attribution in security logs for auditing

Identity Logging maps IP addresses to specific usernames within the SmartView Tracker and SmartConsole logs. This visibility is critical for compliance, as it allows administrators to perform forensic analysis, verifying exactly which user accessed which resource at a given time. By replacing ambiguous IP-based logs with identity-rich logs, organizations can meet regulatory requirements and accurately attribute network activities to human users rather than just transient internal IP addresses.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To increase the throughput of the Security Gateway

    Why it's wrong here

    Logging actually consumes system resources and can slightly impact performance if configured aggressively. It is used for auditing and visibility, not for hardware acceleration or performance optimization. Suggesting that logging increases gateway throughput is technically incorrect and contradicts the expected overhead associated with packet inspection and log generation.

  • ✗

    To enable automatic user account lockout upon detecting suspicious traffic

    Why it's wrong here

    Identity Logging is strictly for recording activity for administrative and security auditing purposes. It does not perform active enforcement or account management. Automatically locking accounts based on traffic logs would be a function of an IPS or threat prevention system, not the logging component of Identity Awareness.

  • ✓

    To provide accurate user-based attribution in security logs for auditing

    Why this is correct

    Identity Logging transforms logs from generic IP-based entries into user-aware entries. This is essential for compliance audits, as it allows security teams to trace network actions back to a specific individual, providing an undeniable audit trail that IP addresses alone cannot offer in dynamic DHCP environments.

  • ✗

    To allow the gateway to perform local user authentication without AD

    Why it's wrong here

    Logging is an output mechanism for data, not an input mechanism for authentication. Local authentication is handled by the internal user database or an LDAP integration. The logging feature does not provide the logic required to validate credentials or establish sessions, making it irrelevant to the authentication flow.

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.