156-215.80 · Question #196
When using LDAP as an authentication method for Identity Awareness, the query:
The correct answer is D. Is transparent, requiring no client or server side software, or client intervention. When LDAP is used as the identity source in Check Point Identity Awareness, the gateway queries the directory server transparently with no agent software or user interaction required.
Question
When using LDAP as an authentication method for Identity Awareness, the query:
Options
- ARequires client and server side software.
- BPrompts the user to enter credentials.
- CRequires administrators to specifically allow LDAP traffic to and from the LDAP Server and the
- DIs transparent, requiring no client or server side software, or client intervention.
How the community answered
(15 responses)- C7% (1)
- D93% (14)
Why each option
When LDAP is used as the identity source in Check Point Identity Awareness, the gateway queries the directory server transparently with no agent software or user interaction required.
LDAP queries require no client-side software; the gateway independently contacts the directory server without any endpoint agent.
LDAP identity acquisition does not prompt the user for credentials; it queries the directory using existing session or machine identity data.
While LDAP traffic must be permitted to flow, this option misstates the defining characteristic of LDAP queries in Identity Awareness, which is their transparency and lack of client intervention.
LDAP identity queries in Identity Awareness are fully transparent because the Security Gateway directly queries Active Directory or another LDAP server in the background to resolve user identity. No software needs to be installed on client machines or the LDAP server itself, and users do not receive any prompt or need to take action. This makes LDAP a passive, non-intrusive identity acquisition method.
Concept tested: Transparent LDAP identity acquisition in Identity Awareness
Source: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Default.htm
Topics
Community Discussion
No community discussion yet for this question.