Courseiva
Identity Awareness →hardMultiple Select

156-315.81.20 Identity Awareness Practice Question

Which TWO authentication methods are natively supported by Check Point Identity Awareness for acquiring user identities without requiring a client-side agent installation? (Choose TWO)

⚠ Common exam trap

Candidates often select 'Identity Agent' or 'Browser-Based Authentication' as generic terms, forgetting that the question specifies 'without requiring a client-side agent'. They accidentally choose methods that actually require software installation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Active Directory Query (AD Query)

Active Directory Query and Captive Portal allow the Security Gateway to identify users transparently or interactively without deploying software to endpoints. AD Query reads domain controller events, while Captive Portal prompts users via a browser redirect, making both methods ideal for unmanaged devices or environments where endpoint agent deployment is restricted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Active Directory Query (AD Query)

    Why this is correct

    AD Query reads user-to-IP mappings directly from Active Directory domain controller security logs, requiring no endpoint agent. This satisfies the stem's agentless constraint, unlike Identity Agents or browser-based methods that need software installed on the client.

  • ✗

    Check Point Endpoint Identity Agent

    Why it's wrong here

    The Endpoint Identity Agent requires software installed on the endpoint, so it is not agentless. It is tempting because it reliably collects identities from managed desktops, but the question demands native agentless acquisition, which Identity Awareness provides through portals and directory integrations instead.

  • ✓

    Captive Portal

    Why this is correct

    Captive Portal intercepts HTTP and HTTPS traffic from unauthenticated users and redirects them to a web authentication page. Once the user submits valid credentials, the gateway maps their IP address to their identity without requiring any pre-installed endpoint software.

  • ✗

    Terminal Server Identity Agent

    Why it's wrong here

    The Terminal Server Identity Agent is a specialized software component specifically designed for multi-user Microsoft Terminal Server or Citrix environments. It tracks individual user sessions sharing a single IP address and requires explicit installation on the server host.

  • ✗

    Browser-Based Identity Agent

    Why it's wrong here

    The Browser-Based Identity Agent requires specific configuration and browser extension or plugin interactions on the endpoint device. It does not qualify as a native server-side or network-level identification mechanism that operates entirely free of client interaction.

About these practice questions

Courseiva writes every 156-315.81.20 question from scratch — 210 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Check Point exam blueprint

This 156-315.81.20 practice question is part of Courseiva's free Check Point certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 156-315.81.20 exam.