View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.
Question 201
An organization wants to identify suspicious authentication activity involving a user account. Which activity would be the strongest indicator of potential identity compromise?
- A user changes their password according to policy.
- A successful login is followed by unusual access activity from an unexpected location.
- A user accesses an application during normal working hours.
- A user completes a required security training course.
Correct Answer: 2
Explanation
Unexpected authentication behavior can be an important indicator of identity compromise. A successful login followed by unusual activity, particularly from an unexpected location or context, may indicate that valid credentials have been obtained by an unauthorized party. Security teams should correlate authentication events with other identity and endpoint telemetry rather than treating a single event as conclusive evidence. Additional factors such as device reputation, access patterns, privilege level, and subsequent actions can help determine risk. Monitoring these signals allows analysts to distinguish normal user behavior from suspicious activity and prioritize investigations involving potentially compromised accounts.
Question 202
What is the primary security benefit of applying least privilege to user and service identities?
- It eliminates the need for authentication.
- It prevents all credential theft.
- It allows every identity to access the same resources.
- It limits the potential impact if an identity is compromised.
Correct Answer: 4
Explanation
Least privilege limits an identity’s access to only the resources and actions required for legitimate responsibilities. If an account is compromised, restricting its permissions can significantly reduce what an attacker can access or modify. This principle applies to human users, service accounts, applications, and other identities. Least privilege does not prevent credential theft or eliminate the need for authentication, but it helps contain the consequences of unauthorized access. Security teams can strengthen this approach through regular access reviews, role-based permissions, privileged access controls, and monitoring for abnormal privilege use.
Question 203
When investigating a potentially compromised identity, which information is most useful for establishing a timeline of activity?
- Authentication, endpoint, and related identity events with timestamps.
- The organization’s marketing material.
- The user’s preferred software interface.
- Archived training presentations.
Correct Answer: 1
Explanation
A reliable incident timeline depends on events that contain meaningful timestamps and contextual information. Authentication records can show when and where an identity was used, while endpoint and identity telemetry can reveal actions performed after authentication. Correlating these events helps analysts understand the sequence of activity and identify suspicious transitions. For example, an unusual login followed shortly by privilege use or access to sensitive resources may provide stronger evidence than any single event. Building a timeline also helps investigators identify the initial access point, subsequent activity, and possible containment requirements.
Question 204
Which approach best supports detection of anomalous identity behavior?
- Reviewing only monthly password changes.
- Disabling all remote authentication.
- Establishing normal behavior patterns and detecting significant deviations.
- Allowing all authentication attempts without monitoring.
Correct Answer: 3
Explanation
Behavioral analysis can help identify identity activity that differs significantly from established patterns. Normal behavior may include typical login locations, devices, applications, access times, and resource usage. When activity deviates from those patterns, the event can be investigated using additional context. Anomaly detection should not automatically treat every unusual event as malicious because legitimate travel, role changes, or administrative activity can produce similar signals. Combining behavioral indicators with identity context, endpoint telemetry, authentication strength, and privilege information creates a more useful risk assessment and reduces unnecessary investigation noise.
Question 205
Why should privileged identities receive additional monitoring compared with ordinary user accounts?
- Privileged identities cannot be compromised.
- Privileged accounts are exempt from security policies.
- Privileged identities are always used by administrators.
- Misuse of privileged access can produce a greater security impact.
Correct Answer: 4
Explanation
Privileged identities generally have access to sensitive systems, administrative functions, or high-value resources. If such an identity is compromised or misused, an attacker may be able to change configurations, create accounts, access sensitive information, or disable security controls. Additional monitoring can therefore help detect suspicious privileged activity earlier. Organizations commonly combine strong authentication, just-in-time access, role separation, approval processes, session monitoring, and detailed logging for privileged identities. These controls do not eliminate risk, but they reduce unnecessary exposure and provide investigators with better visibility into potentially harmful administrative actions.
Question 206
What is a key purpose of correlating identity telemetry with endpoint telemetry?
- To replace endpoint protection completely.
- To connect account activity with activity occurring on devices.
- To eliminate the requirement for security logging.
- To prevent users from accessing cloud applications.
Correct Answer: 2
Explanation
Identity telemetry shows how accounts authenticate and interact with resources, while endpoint telemetry provides visibility into activity occurring on devices. Correlating these data sources can provide a more complete picture of an incident. For example, an unusual authentication event can be investigated alongside processes, network connections, or other endpoint activity associated with the device. This correlation can help analysts determine whether an identity event is benign, suspicious, or connected to a broader attack sequence. It also supports faster investigation because analysts can connect identity-based indicators with device-level evidence.
Question 207
Which control most directly reduces the risk associated with stolen passwords?
- Increasing the number of applications available to users.
- Allowing password reuse across applications.
- Using strong authentication mechanisms such as phishing-resistant MFA.
- Removing identity monitoring.
Correct Answer: 3
Explanation
Strong authentication can reduce the usefulness of stolen passwords because possession of a password alone may not be sufficient to complete authentication. Phishing-resistant multifactor authentication provides stronger protection than relying solely on passwords or weaker second factors. Organizations should also combine authentication controls with conditional access, identity monitoring, device trust, and appropriate session management. No authentication control eliminates every form of compromise, so security teams should continue monitoring for suspicious behavior. A layered approach helps detect attempts to misuse legitimate credentials even when attackers obtain valid authentication information.
Question 208
A service account begins accessing resources it has never previously used. What should an analyst consider first?
- Whether the access is consistent with the account’s documented business purpose.
- Whether the account has a human user’s profile picture.
- Whether the account receives security newsletters.
- Whether the account’s password contains special characters.
Correct Answer: 1
Explanation
Service accounts often perform predictable and narrowly defined functions. When a service identity suddenly accesses unfamiliar resources, analysts should determine whether the behavior matches its documented purpose and expected workload. A legitimate application update, infrastructure change, or new integration could explain the activity. However, unexpected resource access can also indicate credential compromise, misuse, or unauthorized modification of the service. Reviewing authentication records, application dependencies, recent changes, permissions, and associated endpoint or workload telemetry can help establish context. Monitoring service identities is particularly important because they may operate without direct human interaction.
Question 209
What is the primary purpose of identity risk scoring in a security operations workflow?
- To permanently classify every user as malicious or benign.
- To replace all security investigations.
- To determine employee performance.
- To help prioritize identities or events that require further investigation.
Correct Answer: 4
Explanation
Identity risk scoring can help security teams prioritize investigation by combining multiple indicators into a contextual assessment. Signals may include unusual authentication behavior, privilege changes, suspicious access patterns, compromised credentials, or other relevant telemetry. A risk score should generally be treated as an analytical aid rather than definitive proof that an identity is compromised. Analysts can investigate high-risk identities by examining supporting evidence and validating whether the activity has a legitimate explanation. Prioritization is especially useful in environments that generate large volumes of identity events and require analysts to focus attention on the most significant signals.
Question 210
Which scenario best represents lateral movement involving a compromised identity?
- A user changes their email signature.
- A user reads an approved internal document.
- An attacker uses compromised credentials to access additional systems.
- A user completes multifactor authentication successfully.
Correct Answer: 3
Explanation
Lateral movement occurs when an attacker uses access obtained from one system or identity to reach additional systems or resources. Compromised credentials can provide a convenient mechanism for this activity because the resulting authentication may appear legitimate. Analysts should therefore monitor unusual authentication relationships, new destination systems, privilege changes, and access patterns that differ from the identity’s normal behavior. Correlating identity and endpoint events can help determine whether additional systems were accessed after an initial compromise. Detecting lateral movement early can help organizations contain an incident before the attacker reaches more sensitive resources.
Question 211
Why is continuous monitoring important in a Zero Trust security model?
- Trust decisions should be evaluated continuously rather than assumed permanently.
- Users should receive permanent unrestricted access after their first login.
- Authentication should occur only once per year.
- Endpoint activity does not need to be monitored.
Correct Answer: 1
Explanation
Zero Trust is based on the principle that access should not be automatically trusted simply because an identity or device was previously authenticated. Continuous monitoring provides security teams with information needed to reassess risk as circumstances change. Factors such as device posture, identity behavior, resource sensitivity, authentication context, and detected threats can influence access decisions. Continuous evaluation does not necessarily mean repeatedly prompting users for passwords. Instead, security controls can use telemetry and policy decisions to detect changing conditions. This approach helps organizations respond when an identity or device becomes suspicious after initial access was granted.
Question 212
Which activity would most likely require an investigation of an identity’s privilege escalation?
- A user opens a previously authorized document.
- An identity suddenly receives administrative permissions outside its normal role.
- A user signs in from their normal workstation.
- A user updates an approved calendar event.
Correct Answer: 2
Explanation
Unexpected privilege changes can indicate either legitimate administrative activity or malicious privilege escalation. Analysts should investigate how the permission was granted, who initiated the change, whether the change was approved, and what actions followed. Sudden administrative access is particularly important because elevated privileges can provide access to sensitive systems and security controls. Identity telemetry, directory events, endpoint data, and change-management records can help establish whether the activity was expected. Monitoring privilege changes allows security teams to identify potentially dangerous access modifications and determine whether containment or remediation actions are necessary.
Question 213
Which type of identity should be included in an organization’s identity security monitoring strategy?
- Only full-time employees.
- Only executives.
- Human users, service accounts, applications, and other relevant identities.
- Only external contractors.
Correct Answer: 3
Explanation
Identity security should extend beyond traditional human user accounts. Service accounts, application identities, workload identities, privileged accounts, contractors, and other machine or non-human identities can all have access to important resources. Each identity type can introduce different risks and monitoring requirements. For example, a service account may generate predictable automated activity, while a human account may show location and device changes. Monitoring diverse identity types provides broader visibility into authentication and authorization behavior. Organizations should establish ownership, appropriate permissions, lifecycle management, and monitoring requirements for every identity that can access protected resources.
Question 214
What is an important advantage of integrating identity security telemetry with a security operations platform?
- It removes the need for identity policies.
- It guarantees that every alert is malicious.
- It prevents every compromised credential.
- It enables analysts to correlate identity signals with broader security events.
Correct Answer: 4
Explanation
Integration allows identity-related events to be analyzed alongside endpoint, network, cloud, and other security telemetry. This broader context can help analysts understand whether an authentication event is part of a larger attack sequence. For example, suspicious login activity followed by unusual endpoint behavior and access to sensitive resources may provide stronger evidence than an isolated authentication event. Security operations platforms can also support alert correlation, investigation workflows, and automated response actions. Effective integration improves visibility and can reduce the time required to move from an individual identity alert to a broader understanding of the incident.
Question 215
An analyst discovers that a user’s credentials were likely exposed. What is an appropriate immediate security objective?
- Preserve unrestricted access until the investigation ends.
- Contain potential misuse while determining the scope of the compromise.
- Delete all available identity logs.
- Disable security monitoring for the affected account.
Correct Answer: 2
Explanation
When credentials are suspected to be compromised, containment should reduce the opportunity for continued unauthorized use while preserving evidence for investigation. Depending on organizational procedures, actions may include revoking sessions, requiring credential changes, increasing authentication requirements, restricting access, or temporarily disabling the identity. Analysts should also examine recent authentication activity and determine whether the credentials were actually used maliciously. Preserving relevant telemetry is important because it can help establish the scope and timeline of the incident. Response actions should follow documented incident-response procedures and consider business requirements to avoid unnecessary disruption.
Question 216
Which indicator can provide useful context when evaluating whether a login is anomalous?
- The relationship between the login’s device, location, time, and normal user behavior.
- The user’s preferred desktop wallpaper.
- The number of documents in the user’s recycle bin.
- The color of the authentication portal.
Correct Answer: 1
Explanation
Authentication anomalies are best evaluated using contextual signals rather than a single attribute. Device identity, geographic location, login time, historical behavior, authentication method, and resource access can help determine whether an event is unusual. For example, a login from a previously unseen device combined with an unusual location and subsequent access to sensitive resources may warrant investigation. However, an unusual login does not automatically indicate compromise because legitimate travel, device replacement, or organizational changes can produce similar signals. Contextual correlation allows analysts to distinguish potentially risky behavior from normal variations in user activity.
Question 217
What is a major security concern when an identity has excessive permissions?
- The identity will always authenticate faster.
- Security logs will automatically become more accurate.
- The identity will require fewer security controls.
- A compromise could provide access to more resources than necessary.
Correct Answer: 4
Explanation
Excessive permissions increase the potential impact of identity compromise because an attacker controlling that identity may inherit its unnecessary access. This can enable unauthorized data access, configuration changes, privilege escalation, or movement to other systems. Least privilege helps reduce this exposure by limiting permissions to legitimate business requirements. Organizations should periodically review access rights, remove unnecessary privileges, monitor privilege changes, and apply stronger controls to sensitive accounts. Reducing excessive permissions also improves governance because access becomes more closely aligned with documented responsibilities and approved business functions.
Question 218
Which investigation technique is most useful for determining whether suspicious identity activity is part of a larger attack?
- Looking only at the user’s password length.
- Reviewing unrelated business documents.
- Correlating the identity events with endpoint, network, and access activity.
- Ignoring events that occurred before the suspicious login.
Correct Answer: 3
Explanation
Attack activity often spans multiple security layers, so identity events should be correlated with other available telemetry. Analysts can examine endpoint processes, network connections, authentication events, privilege changes, and resource access around the same timeframe. This can reveal relationships that are not visible from identity logs alone. For example, suspicious authentication followed by unusual process execution and access to sensitive systems may indicate a broader compromise. Correlation also helps establish the attack timeline and identify additional affected identities or systems. A comprehensive investigation should preserve relevant evidence while continually testing whether observed activity has a legitimate explanation.
Question 219
Why should organizations regularly review dormant or unused identities?
- Unused accounts can still provide an unnecessary attack path if compromised.
- Dormant accounts automatically protect sensitive systems.
- Dormant accounts cannot be targeted by attackers.
- Unused identities never require ownership information.
Correct Answer: 1
Explanation
Dormant identities can represent unnecessary security exposure when they remain enabled and retain access to organizational resources. An attacker who obtains dormant credentials may exploit them without immediately attracting attention because the account normally generates little activity. Regular identity lifecycle reviews can identify accounts that are no longer required, confirm ownership, reduce permissions, or disable them according to policy. This is particularly important for former employees, obsolete service accounts, temporary accounts, and identities associated with retired applications. Maintaining an accurate identity inventory helps security teams understand which accounts exist and why they continue to have access.
Question 220
Which response best demonstrates a risk-based approach to identity security?
- Treating every identity event as equally dangerous.
- Combining identity context, privileges, behavior, and threat signals to prioritize response.
- Ignoring low-volume identities completely.
- Applying the same access decision without considering resource sensitivity.
Correct Answer: 2
Explanation
A risk-based identity security approach considers multiple factors before determining how an event should be handled. Identity type, privilege level, authentication context, behavioral anomalies, resource sensitivity, device posture, and threat intelligence can all contribute to the overall assessment. This allows security teams to prioritize events that present greater potential risk while avoiding unnecessary responses to routine activity. The approach should remain adaptive because risk can change as an identity, device, or environment changes. Combining contextual signals with documented policies and response procedures provides a more effective foundation for identity monitoring and incident investigation.