I disagree with you both, first and foremost because AD Query is disregarding the principle of least privilege. If it was the only option, as it used to be, I wouldn't start this post, though better alternatives exists.
In my opinion Check Point should train both seasoned and new customers to use the more secure options.
AD Query is also unstable and causes lots of support tickets, why is having the least effective, secure and the most problematic, from a security point of view, option as a default desirable?