View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.
Question 121
Which capability helps security analysts investigate suspicious identity behavior by providing relevant identity context?
- Identity visibility
- Printer management
- Disk cleanup
- Software packaging
Correct Answer: 1
Explanation
Identity visibility gives security analysts information needed to understand activity associated with users, service accounts, and other identities. During an investigation, analysts may need to review authentication activity, identity attributes, associated systems, detections, and risk information. Having this context makes it easier to determine whether activity is expected or requires additional investigation. CrowdStrike identity security capabilities can provide identity-focused visibility that supports security operations. CCIS candidates should understand that visibility is a foundation for identity protection because security teams cannot effectively investigate identity threats without sufficient information about the identities involved and their observed behavior.
Question 122
What is a primary purpose of least-privilege access?
- To give users unrestricted access
- To reduce unnecessary permissions
- To eliminate authentication
- To share administrative accounts
Correct Answer: 2
Explanation
Least privilege means providing identities with only the permissions required to perform their legitimate responsibilities. Reducing unnecessary access can limit the potential impact of compromised credentials or misuse of an account. Organizations should regularly review permissions because roles and business requirements can change over time. Least privilege is an important principle within Zero Trust and identity security strategies. CCIS candidates should understand that access should be based on legitimate requirements rather than broad default permissions. Combining least privilege with strong authentication, monitoring, risk assessment, and periodic access reviews can help organizations reduce unnecessary identity exposure and improve overall security posture.
Question 123
Which event could indicate that a normally non-interactive identity requires investigation?
- Expected automated activity
- Normal scheduled processing
- Unexpected interactive authentication
- Routine service communication
Correct Answer: 3
Explanation
Unexpected interactive authentication by a normally non-interactive identity can be an investigation indicator. Programmatic identities are commonly used by applications, services, or automated processes and may have predictable activity patterns. If such an identity suddenly performs interactive authentication, analysts should determine whether the behavior is legitimate or potentially suspicious. This does not automatically prove compromise, because administrative or maintenance activities may sometimes explain the event. CCIS candidates should understand the importance of identity classification and behavioral context. Reviewing related authentication events, detections, and system activity can help analysts determine whether the unusual behavior represents a legitimate change or a potential security incident.
Question 124
What is an important function of identity threat detection?
- Identifying potentially suspicious identity activity
- Managing employee payroll
- Monitoring office temperature
- Controlling printer supplies
Correct Answer: 1
Explanation
Identity threat detection helps security teams identify activity that may indicate suspicious or malicious behavior involving identities. Detection signals can provide analysts with a starting point for investigation and may reveal unusual authentication, access, or behavioral patterns. Analysts should not assume that every detection represents confirmed compromise. Instead, detections should be evaluated using available identity context and related security information. CCIS candidates should understand how identity detections fit into a broader security workflow that includes investigation, threat hunting, risk assessment, and response. Effective detection allows security teams to identify potentially harmful activity earlier and determine whether additional action is required.
Question 125
Why is identity context important when investigating an authentication event?
- It helps determine whether the activity is expected
- It automatically proves malicious intent
- It removes the need for authentication
- It prevents all account compromise
Correct Answer: 1
Explanation
Identity context helps analysts determine whether an authentication event is consistent with the identity’s normal behavior and responsibilities. Relevant context can include the identity type, historical activity, authentication method, source information, associated systems, and current risk signals. Without this context, an isolated authentication event can be difficult to interpret accurately. CCIS candidates should understand that security investigations should consider multiple pieces of evidence rather than relying on one event. Identity security platforms can help provide the contextual information required for analysis. Proper context allows analysts to distinguish routine activity from events that may warrant deeper investigation or response.
Question 126
Which security principle assumes that authentication alone should not establish permanent trust?
- Zero Trust
- Open access
- Shared access
- Perimeter-only security
Correct Answer: 1
Explanation
Zero Trust is based on the principle that successful authentication should not automatically create permanent trust. Access decisions should consider relevant identity, device, resource, and security context and may need to be evaluated continuously. This approach can reduce the potential impact of compromised credentials and unnecessary access. CCIS candidates should understand how identity security supports Zero Trust by providing visibility into authentication, identity behavior, and risk. Zero Trust does not mean that users are never trusted; instead, it emphasizes verification and appropriate authorization based on current context. Organizations can combine these principles with least privilege, strong authentication, monitoring, and risk-based controls.
Question 127
What can periodic identity reviews help organizations discover?
- Outdated or unnecessary access
- New office furniture
- Printer maintenance schedules
- Employee lunch preferences
Correct Answer: 1
Explanation
Periodic identity reviews can help organizations discover outdated accounts, unnecessary permissions, inactive identities, and access that no longer matches business requirements. Identity environments change continuously as employees change roles, applications are introduced, and services are retired. Regular reviews help ensure that identity access remains appropriate. These reviews are particularly important for privileged identities and programmatic accounts that may retain access after their original purpose changes. CCIS candidates should understand how identity governance supports least privilege and overall security posture. Periodic reviews should complement authentication controls, identity monitoring, and risk assessment to provide a more complete approach to managing identity-related security risks.
Question 128
Which type of account commonly performs automated application or service functions?
- Human user account
- Programmatic identity
- Guest visitor account
- Temporary office account
Correct Answer: 2
Explanation
A programmatic identity is commonly used by applications, services, scripts, or other automated processes to perform tasks without requiring continuous interactive user involvement. Because these identities can have access to important systems or resources, they should be monitored and appropriately protected. Their expected behavior may differ significantly from that of human users. CCIS candidates should understand the importance of distinguishing programmatic identities from human identities during investigations. Unexpected activity from a service identity, such as unusual authentication behavior or access to unfamiliar resources, may require additional investigation. Proper classification helps analysts interpret identity activity more accurately and establish useful behavioral expectations.
Question 129
What is a potential benefit of using risk-based identity controls?
- They can help prioritize security attention based on available risk signals
- They eliminate the need for security monitoring
- They guarantee that no account will be compromised
- They provide unrestricted access to every identity
Correct Answer: 1
Explanation
Risk-based identity controls can help security teams prioritize attention based on available risk signals. Instead of treating every identity event identically, analysts can use risk information to determine which identities or activities may require closer examination. Risk information should be considered alongside other evidence because elevated risk does not necessarily prove malicious activity. CCIS candidates should understand how risk-based approaches can support efficient identity security operations. Combining risk information with authentication telemetry, detections, behavioral context, and investigation workflows can help organizations respond more effectively to potential threats while reducing unnecessary disruption to legitimate users and business processes.
Question 130
What should an analyst examine when determining whether an unusual login is suspicious?
- Only the user’s job title
- Only the computer manufacturer
- Authentication context and related activity
- Only the time of day
Correct Answer: 3
Explanation
An unusual login should be evaluated using authentication context and related activity rather than a single attribute. Analysts may examine the identity involved, authentication method, source information, timing, historical behavior, associated endpoints, and related detections. This broader context helps determine whether the event is consistent with legitimate activity or requires investigation. CCIS candidates should understand that unusual behavior is an indicator rather than automatic proof of compromise. Identity security tools can provide relevant context to support investigation. Analysts should follow established procedures and gather sufficient evidence before selecting containment or remediation actions that could affect legitimate access.
Question 131
Which control can reduce the likelihood that a stolen password alone will provide access?
- Multi-factor authentication
- Shared credentials
- Unlimited login attempts
- Permanent administrator access
Correct Answer: 1
Explanation
Multi-factor authentication can reduce the likelihood that a stolen password alone will be sufficient to gain access to a protected resource. By requiring an additional authentication factor, organizations can introduce another security barrier for attackers attempting to use compromised credentials. MFA should be combined with monitoring, appropriate policies, and risk-based identity controls because no single control eliminates every identity threat. CCIS candidates should understand the role of MFA within a broader identity security architecture. Strong authentication controls can help protect user identities while identity monitoring and detection capabilities can help security teams identify suspicious authentication attempts or potential abuse of valid credentials.
Question 132
Which activity is most closely associated with identity threat hunting?
- Searching identity telemetry for suspicious patterns
- Updating office furniture
- Managing printer toner
- Replacing workstation keyboards
Correct Answer: 1
Explanation
Identity threat hunting involves proactively searching identity-related telemetry for suspicious patterns or behaviors. Analysts may develop a hypothesis based on known attack techniques, unusual authentication behavior, or intelligence about emerging threats and then search available data for supporting evidence. Threat hunting can identify activity that may not have triggered an automated detection. CCIS candidates should understand that hunting complements automated security controls and requires knowledge of normal identity behavior and relevant threat techniques. Findings from threat hunts can also contribute to improved detections and security controls. Effective hunting is therefore an important part of a proactive identity protection strategy.
Question 133
What is a major concern when an identity has excessive privileges?
- A compromise could have a broader impact
- Authentication becomes impossible
- Monitoring becomes unnecessary
- The account automatically becomes secure
Correct Answer: 1
Explanation
Excessive privileges increase the potential impact if an identity is compromised or misused. An attacker who gains control of an overprivileged account may be able to access additional systems, modify configurations, or reach sensitive resources. Least-privilege principles help reduce this exposure by limiting permissions to legitimate requirements. CCIS candidates should understand why privilege management is an important part of identity security and Zero Trust. Organizations should regularly review privileged and non-privileged identities to identify unnecessary permissions. Combining access controls with authentication security, monitoring, and risk assessment can further reduce the potential consequences of compromised identities.
Question 134
Why should identity security integrations be monitored after deployment?
- Configuration or connectivity problems can affect visibility
- Integrations never require maintenance
- Monitoring automatically disables authentication
- Connectors cannot experience errors
Correct Answer: 1
Explanation
Identity security integrations should be monitored because configuration, authentication, permission, or connectivity problems can affect the availability and quality of identity information. A connector that stops functioning correctly may reduce security visibility and affect investigation workflows. Administrators should periodically verify integration health and investigate errors or unexpected changes. CCIS candidates should understand that integration management is part of maintaining an effective identity security environment. Proper monitoring helps ensure that identity data continues to reach security systems as expected. Organizations should also document important integration configurations and establish processes for troubleshooting and validating changes that could affect identity monitoring or security operations.
Question 135
What is one purpose of identity risk prioritization?
- To help analysts focus attention on potentially higher-risk activity
- To remove all security alerts
- To give every identity administrator privileges
- To disable identity monitoring
Correct Answer: 1
Explanation
Identity risk prioritization helps security teams focus investigation resources on activity or identities that may represent greater security concern. Security operations often receive many events, so risk information can help analysts determine where additional attention may be valuable. Risk should not be interpreted in isolation because elevated risk can have legitimate explanations and does not automatically confirm compromise. CCIS candidates should understand how risk information can support triage and investigation. Analysts should combine risk indicators with authentication activity, detections, behavioral patterns, and other evidence to determine whether an identity requires further investigation, additional controls, or an appropriate response.
Question 136
Which approach supports continuous evaluation of identity access?
- Requiring users to authenticate once and never reviewing access
- Combining authentication, authorization, monitoring, and risk information
- Giving all users permanent administrative access
- Disabling security telemetry
Correct Answer: 2
Explanation
Continuous evaluation of identity access involves considering authentication, authorization, monitoring, and relevant risk information rather than relying on a single successful login. This approach aligns with Zero Trust principles and helps organizations respond when identity context or risk changes. Security teams can use identity telemetry and risk signals to identify activity that may require additional verification or investigation. CCIS candidates should understand that continuous evaluation is designed to reduce unnecessary trust and limit the potential impact of compromised identities. It should be supported by appropriate policies, least privilege, strong authentication, and security monitoring to create a comprehensive identity protection strategy.
Question 137
What can historical authentication data help analysts establish?
- A baseline for normal identity behavior
- The user’s personal preferences
- The physical condition of a server
- The organization’s office layout
Correct Answer: 1
Explanation
Historical authentication data can help analysts establish a baseline for normal identity behavior. Understanding when, where, and how an identity typically authenticates provides useful context when reviewing unusual activity. A deviation from the baseline may warrant additional investigation, although it does not automatically indicate malicious behavior. Legitimate changes such as travel, role changes, or operational requirements can affect authentication patterns. CCIS candidates should understand how historical context supports identity investigations and threat hunting. Combining baseline information with current detections, identity risk, and related events can help analysts determine whether an authentication event is routine, unusual, or potentially part of a security incident.
Question 138
Which identity should generally receive careful monitoring because it may have broad access?
- Privileged identity
- Inactive guest identity
- Temporary visitor account
- Disabled test account
Correct Answer:1
Explanation
Privileged identities generally require careful monitoring because they may have broad permissions over systems, applications, or sensitive resources. If such an identity is compromised, the attacker may be able to perform high-impact actions. Organizations should protect privileged identities with appropriate authentication controls, least privilege, monitoring, and regular access reviews. CCIS candidates should understand that privileged access should be granted only when necessary and should be monitored for unusual behavior. Identity security capabilities can provide useful context for investigating privileged activity and identifying potential risks. Strong controls around privileged identities can help reduce the potential impact of credential compromise or misuse.
Question 139
What is the purpose of correlating multiple identity-related signals during an investigation?
- To provide a more complete view of potentially suspicious activity
- To remove all identity controls
- To guarantee that every event is malicious
- To prevent users from authenticating
Correct Answer: 1
Explanation
Correlating multiple identity-related signals provides analysts with a more complete view of potentially suspicious activity. A single event may not contain enough information to determine its significance, while multiple related events can reveal a broader pattern. Analysts may correlate authentication activity, identity risk, detections, endpoint context, and behavioral information. CCIS candidates should understand that correlation supports evidence-based investigation and can improve the accuracy of security decisions. Correlated information should still be evaluated carefully because legitimate activities can produce unusual patterns. The goal is to provide sufficient context for determining whether additional investigation, containment, remediation, or monitoring is appropriate.
Question 140
Which strategy best supports protection against identity-based threats?
- Combining strong authentication, least privilege, monitoring, and investigation
- Using passwords without monitoring
- Granting unrestricted access to all users
- Disabling identity detections
Correct Answer: 4
Explanation
A comprehensive identity security strategy combines multiple controls rather than relying on one protection mechanism. Strong authentication helps protect credentials, least privilege limits unnecessary access, monitoring provides visibility, and investigation allows analysts to evaluate suspicious activity. Risk assessment and appropriate response can further strengthen the security posture. CCIS candidates should understand that identity protection requires continuous management because threats, users, applications, and access requirements change over time. Combining these controls supports Zero Trust principles and can reduce the potential impact of compromised identities. Organizations should regularly review identity policies, integrations, permissions, and detections to ensure that controls remain aligned with current security requirements.