156-315.81.20 Identity Awareness Practice Question
Which THREE parameters must be correctly configured when setting up an Active Directory Query identity source in SmartConsole? (Choose THREE)
⚠ Common exam trap
Candidates often forget the importance of the NetBIOS or FQDN naming convention, which is critical for the gateway to correctly associate users with the specific domain being queried.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Domain Controller IP addresses or hostnames
Configuring AD Query requires specifying the Active Directory domain name, identifying the specific Domain Controllers to poll, and assigning an account with sufficient privileges to read the Windows security event logs. These settings allow the Security Gateway to establish secure RPC connections and query logon events accurately.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Domain Controller IP addresses or hostnames
Why this is correct
Domain Controller IP addresses or hostnames are mandatory because the query identity source must reach each domain controller directly to perform LDAP lookups. Without these endpoints, SmartConsole cannot resolve user and group objects, so the identity source fails to authenticate and collect data, satisfying the stem's requirement for correct configuration.
- ✓
Active Directory administrator credentials with read access to security event logs
Why this is correct
Querying security event logs requires a service account whose credentials SmartConsole stores. Read access to those logs is the specific permission needed to retrieve logon and identity events, satisfying the mandatory credential parameter for the Active Directory Query source.
- ✗
LDAP Account Unit integration with write permissions
Why it's wrong here
AD Query relies on event log monitoring rather than standard LDAP directory manipulation. While an LDAP Account Unit is useful for user and group object resolution, write permissions are entirely unnecessary for passive session tracking.
- ✓
NetBIOS or fully qualified domain name (FQDN)
Why this is correct
SmartConsole needs the directory's network identity to locate and bind to the domain controller. Supplying the NetBIOS name or FQDN lets the Identity Collector resolve the Active Directory domain, satisfying the mandatory domain-identification parameter for the query identity source.
- ✗
Client SSL certificate for mutual TLS authentication
Why it's wrong here
AD Query communication with Windows Domain Controllers utilizes standard RPC and WMI protocols over port 135 and dynamic TCP ports, or WinRM, rather than mutual TLS client certificates. Client certificates are relevant for VPN or Web API integrations instead.
About these practice questions
This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Check Point exam blueprint
This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.