Courseiva
Identity Awareness →hardMultiple Select

156-315.81.20 Identity Awareness Practice Question

Which THREE parameters must be correctly configured when setting up an Active Directory Query identity source in SmartConsole? (Choose THREE)

⚠ Common exam trap

Candidates often forget the importance of the NetBIOS or FQDN naming convention, which is critical for the gateway to correctly associate users with the specific domain being queried.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Domain Controller IP addresses or hostnames

Configuring AD Query requires specifying the Active Directory domain name, identifying the specific Domain Controllers to poll, and assigning an account with sufficient privileges to read the Windows security event logs. These settings allow the Security Gateway to establish secure RPC connections and query logon events accurately.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Domain Controller IP addresses or hostnames

    Why this is correct

    Domain Controller IP addresses or hostnames are mandatory because the query identity source must reach each domain controller directly to perform LDAP lookups. Without these endpoints, SmartConsole cannot resolve user and group objects, so the identity source fails to authenticate and collect data, satisfying the stem's requirement for correct configuration.

  • ✓

    Active Directory administrator credentials with read access to security event logs

    Why this is correct

    Querying security event logs requires a service account whose credentials SmartConsole stores. Read access to those logs is the specific permission needed to retrieve logon and identity events, satisfying the mandatory credential parameter for the Active Directory Query source.

  • ✗

    LDAP Account Unit integration with write permissions

    Why it's wrong here

    AD Query relies on event log monitoring rather than standard LDAP directory manipulation. While an LDAP Account Unit is useful for user and group object resolution, write permissions are entirely unnecessary for passive session tracking.

  • ✓

    NetBIOS or fully qualified domain name (FQDN)

    Why this is correct

    SmartConsole needs the directory's network identity to locate and bind to the domain controller. Supplying the NetBIOS name or FQDN lets the Identity Collector resolve the Active Directory domain, satisfying the mandatory domain-identification parameter for the query identity source.

  • ✗

    Client SSL certificate for mutual TLS authentication

    Why it's wrong here

    AD Query communication with Windows Domain Controllers utilizes standard RPC and WMI protocols over port 135 and dynamic TCP ports, or WinRM, rather than mutual TLS client certificates. Client certificates are relevant for VPN or Web API integrations instead.

About these practice questions

This 156-315.81.20 question is part of Courseiva's 210-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.