156-215.81.20 · Question #179
Fill in the blank: With the User Directory Software Blade, you can create user definitions on a(n) ___________ Server.
The correct answer is B. LDAP. See the full explanation below for the reasoning.
Question
Fill in the blank: With the User Directory Software Blade, you can create user definitions on a(n) ___________ Server.
Options
- ASecurID
- BLDAP
- CNT domain
- DSMTP
How the community answered
(30 responses)- A3% (1)
- B83% (25)
- C3% (1)
- D10% (3)
Community Discussion
6The answer is B, LDAP. Think of the User Directory Software Blade like a phone book integration tool, and LDAP is the phone book standard it knows how to read and write, so naturally you define your users on an LDAP Server when that blade is in play.
That phone book analogy is solid, but worth noting that in Check Point environments you will often see Active Directory filling that LDAP server role, so the two concepts are closely tied and knowing that connection helps you answer follow-up questions about identity-based policy too.
Honestly I was eyeing C at first because NT domain still shows up in so many legacy questions and my brain just went there automatically. But then I remembered that the User Directory Blade is literally just Checkpoint's name for LDAP integration, so B is the only one that actually fits.
B is correct, and this maps directly to the Identity Awareness domain on the blueprint. The User Directory Software Blade integrates with an LDAP Server (typically Active Directory) to pull user and group objects into SmartConsole, which is exactly what lets you build access rules based on identity rather than just IP address.
Went back and forth on this one but I keep landing on C, NT domain, because the User Directory blade is specifically about integrating Windows-based user stores, and NT domain authentication is the classic Microsoft directory model that Check Point has supported for years. When I was studying the SmartConsole user management section, every lab example I saw for "creating user definitions" pointed to pulling from an NT domain structure. The other options felt like distractors to me, SMTP is obviously off, SecurID is RSA token auth not a user store, and LDAP felt too broad since the blade itself is more narrowly scoped in the documentation I read.
Good effort working through the distractors, Wesley, but the User Directory blade is built specifically around LDAP as its protocol for querying external directory servers, which is exactly why Check Point renamed the feature from "LDAP Account Unit" in older versions, and that naming history alone is a reliable anchor on the exam.