View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.
Question 221
Which practice helps reduce the risk of unauthorized access from inactive user accounts?
- Increasing the session timeout for inactive accounts.
- Granting inactive accounts additional permissions.
- Regularly reviewing and disabling accounts that are no longer required.
- Excluding inactive accounts from identity monitoring.
Correct Answer: 3
Explanation
Regular identity lifecycle management helps organizations reduce unnecessary access. Accounts belonging to former employees, temporary workers, retired applications, or users who no longer require access can become potential attack paths when they remain active. Security teams should periodically review account ownership, business purpose, permissions, and recent activity. Accounts that are no longer required can then be disabled or removed according to organizational procedures. This process also improves visibility because the identity inventory more accurately represents active business requirements. Combining lifecycle management with monitoring and access reviews provides stronger protection against unauthorized use of forgotten or unnecessary identities.
Question 222
What is the main purpose of enforcing conditional access policies?
- To evaluate access requests using contextual security conditions.
- To eliminate all identity authentication.
- To give every identity identical permissions.
- To prevent all users from accessing cloud resources.
Correct Answer: 1
Explanation
Conditional access policies evaluate access requests using contextual information such as identity, device state, authentication strength, location, application, and resource sensitivity. Organizations can use these conditions to apply stronger controls when risk increases. For example, access to a sensitive resource from an unfamiliar device may require additional authentication or may be restricted. Conditional access supports a Zero Trust approach because access decisions can consider current circumstances rather than relying only on a previous successful login. Policies should be carefully designed and regularly reviewed so that legitimate business activity remains available while higher-risk situations receive appropriate controls.
Question 223
Which event would be most concerning when observed immediately after a suspicious authentication?
- The user opens an approved application.
- The user reads a normal internal email.
- The user changes a permitted notification setting.
- The identity accesses sensitive resources that are not normally used.
Correct Answer: 4
Explanation
Access to sensitive resources immediately following suspicious authentication can provide important context for an investigation. If the identity does not normally access those resources, the combination of unusual authentication and unusual resource access may indicate potential account misuse. Analysts should examine the authentication source, device information, privilege level, resource accessed, and actions performed afterward. The activity should not automatically be considered malicious because legitimate operational changes can produce unusual behavior. However, correlated signals provide a stronger reason for investigation than either event considered independently. Monitoring sensitive-resource access is therefore an important component of identity security operations.
Question 224
Which identity-security principle requires access permissions to be limited according to business requirements?
- Network segmentation.
- Least privilege.
- Data duplication.
- Open access.
Correct Answer: 2
Explanation
Least privilege requires identities to receive only the permissions necessary to perform their approved responsibilities. This principle reduces the potential impact of compromised accounts because an attacker inherits fewer capabilities when controlling an identity. Least privilege should apply to employees, administrators, service accounts, applications, and workloads. Access reviews can help identify permissions that are no longer required, while role-based access and privileged access controls can make enforcement easier. Organizations should also review privilege assignments after role changes and departures. Applying least privilege consistently helps reduce unnecessary exposure while maintaining access needed for legitimate business operations.
Question 225
What is an important reason to monitor changes to identity privileges?
- Privilege changes can indicate either legitimate administrative activity or unauthorized escalation.
- Privilege changes never affect security risk.
- Identity permissions cannot be modified after account creation.
- Monitoring privilege changes prevents all credential theft.
Correct Answer: 1
Explanation
Changes to identity privileges can have significant security consequences. A legitimate administrator may grant access as part of an approved role change, but an attacker may also attempt to increase privileges after compromising an account. Monitoring these changes allows analysts to determine who initiated the modification, which identity was affected, what permissions were added, and whether the action was authorized. Correlating privilege changes with authentication and endpoint telemetry can provide additional context. Organizations should maintain approval and change-management processes for sensitive permissions and investigate unexpected modifications promptly to reduce the potential impact of unauthorized privilege escalation.
Question 226
Which factor is particularly useful when determining whether service-account activity is abnormal?
- The user’s personal email preferences.
- The color of the service dashboard.
- The service account’s expected application and resource usage.
- The employee’s vacation schedule.
Correct Answer: 3
Explanation
Service accounts generally perform defined technical functions, so their expected application and resource usage provides useful behavioral context. If a service account normally communicates with a small set of systems but suddenly authenticates to unrelated resources, analysts should investigate the reason. Legitimate software updates, migrations, or configuration changes may explain the behavior, while unexpected access could indicate credential misuse or unauthorized modification. Monitoring should consider normal execution patterns, associated applications, permissions, authentication sources, and resource access. Establishing documented ownership and business purpose for service accounts also makes abnormal behavior easier to recognize and investigate.
Question 227
What is the purpose of maintaining an accurate inventory of organizational identities?
- To increase the number of privileged accounts.
- To understand which identities exist, who owns them, and what access they have.
- To remove the need for authentication.
- To prevent users from changing approved roles.
Correct Answer: 2
Explanation
An accurate identity inventory provides visibility into the accounts and identities that can access organizational resources. It should help identify ownership, identity type, business purpose, permissions, lifecycle status, and relevant applications or systems. Without this information, organizations may overlook dormant accounts, excessive privileges, unmanaged service identities, or accounts belonging to former personnel. Identity inventories also support access reviews and incident investigations because analysts can determine whether an identity is expected and what resources it should legitimately access. Keeping the inventory current requires integration with identity lifecycle processes and regular validation of ownership and access requirements.
Question 228
Which situation can indicate possible credential stuffing activity?
- A single successful login from a normal device.
- A user completing an approved password change.
- Multiple authentication attempts against accounts using previously exposed credential combinations.
- An administrator reviewing access permissions.
Correct Answer: 3
Explanation
Credential stuffing involves attempts to use previously exposed username and password combinations against other services. A pattern of authentication attempts across multiple accounts or services can therefore be an important indicator. Security teams should examine authentication volume, source information, targeted accounts, successful versus failed attempts, and timing. Strong authentication can reduce the effectiveness of stolen passwords, while monitoring can help identify coordinated attempts. Organizations should also educate users about password reuse and encourage secure authentication practices. Detection becomes more effective when identity telemetry is correlated with other security signals and known indicators of credential exposure.
Question 229
Why is phishing-resistant authentication valuable for identity protection?
- It makes stolen passwords completely impossible.
- It provides stronger resistance against attacks designed to capture authentication factors.
- It removes the need to monitor identity activity.
- It allows all users to bypass authorization controls.
Correct Answer: 2
Explanation
Phishing-resistant authentication mechanisms are designed to reduce the ability of attackers to capture and reuse authentication factors through common phishing techniques. This provides stronger protection than password-only authentication and can reduce the effectiveness of credential harvesting attacks. However, authentication remains only one component of identity security. Organizations should continue using authorization controls, endpoint protection, identity monitoring, and incident-response procedures. Strong authentication is especially valuable for privileged accounts and access to sensitive resources. Security teams should select authentication methods appropriate to their environment and ensure users and administrators understand how the selected mechanism works.
Question 230
Which activity can help identify unauthorized use of an administrative identity?
- Comparing privileged activity against expected administrative behavior.
- Disabling all administrator logging.
- Ignoring authentication source information.
- Giving every user administrative permissions.
Correct Answer: 1
Explanation
Administrative identities typically perform predictable activities based on their responsibilities. Comparing privileged actions against expected behavior can help identify unusual use. Analysts may examine authentication sources, access times, target systems, commands or administrative actions, privilege changes, and associated endpoint activity. Unexpected administrative access does not automatically indicate compromise because emergency maintenance or scheduled changes may produce unusual events. Investigators should therefore correlate activity with change records and operational context. Strong monitoring of privileged identities can help organizations detect misuse earlier and determine whether additional containment or investigation is required.
Question 231
What is the primary benefit of correlating multiple identity risk signals?
- It guarantees that every alert is a confirmed attack.
- It eliminates the need for security analysts.
- It provides broader context for evaluating potentially suspicious activity.
- It prevents legitimate users from accessing resources.
Correct Answer: 3
Explanation
Individual identity events can have legitimate explanations, so relying on one signal may produce unnecessary alerts. Correlating multiple signals provides additional context and can reveal relationships between authentication, device activity, privilege changes, resource access, and threat indicators. For example, an unusual login combined with a new device and access to sensitive systems may warrant greater attention than an unusual login alone. Correlation does not prove malicious activity, but it helps analysts prioritize investigations and understand the broader sequence of events. Effective correlation is especially valuable in large environments where security teams must process many identity-related events.
Question 232
What should an organization do when a user changes roles and no longer requires previous privileges?
- Retain all previous privileges permanently.
- Review and adjust the user’s access according to the new role.
- Grant additional unrelated administrative access.
- Disable identity monitoring for the user.
Correct Answer: 2
Explanation
Role changes should trigger an access review because permissions appropriate for one position may not be required for another. Retaining unnecessary privileges can create excessive access and increase risk if the identity is compromised. Organizations should remove permissions that are no longer justified while granting only the access required for the user’s new responsibilities. This process should be supported by identity governance, documented role definitions, approval procedures, and periodic reviews. Promptly adjusting permissions also supports least privilege and reduces the number of accounts with unnecessary access to sensitive applications, systems, and information.
Question 233
Which event is most relevant when investigating possible account takeover?
- A change in the user’s desktop background.
- A routine software update.
- An unexpected password reset followed by unfamiliar authentication activity.
- A scheduled internal meeting.
Correct Answer: 3
Explanation
An unexpected password reset followed by unfamiliar authentication activity can provide meaningful evidence when investigating possible account takeover. Analysts should determine who initiated the reset, whether the request was legitimate, what authentication methods were used afterward, and whether the identity accessed unusual resources. Other relevant evidence can include device information, geographic context, session activity, privilege changes, and endpoint telemetry. The sequence of events is important because attackers may attempt to reset credentials or manipulate authentication methods after obtaining access. Investigating the complete timeline helps determine whether the activity represents compromise or a legitimate account-management event.
Question 234
What is a key objective of identity threat detection?
- Identify suspicious identity activity that may indicate compromise or misuse.
- Increase the number of unused accounts.
- Eliminate authorization controls.
- Allow all identities to access sensitive resources.
Correct Answer: 1
Explanation
Identity threat detection focuses on identifying activity that may indicate compromised credentials, unauthorized access, privilege misuse, or other identity-related threats. Useful signals can include unusual authentication behavior, suspicious privilege changes, abnormal resource access, credential abuse, and anomalous behavior. Detection should be supported by contextual analysis so that legitimate activity is not automatically treated as malicious. Identity threat detection becomes more effective when integrated with endpoint, cloud, network, and application telemetry. Once suspicious activity is identified, security teams can investigate the event, determine scope, and apply appropriate containment or remediation measures based on established procedures.
Question 235
Why should organizations monitor machine and workload identities?
- They are always more secure than human identities.
- They never have permissions.
- They can access resources and may be abused if compromised.
- They cannot authenticate to applications.
Correct Answer: 3
Explanation
Machine and workload identities can authenticate to applications, cloud services, databases, APIs, and other resources. If such an identity is compromised, an attacker may be able to use its permissions without directly controlling a human account. These identities should therefore have clear ownership, defined purposes, appropriate permissions, lifecycle controls, and monitoring. Security teams should understand expected communication patterns and investigate significant deviations. Applying least privilege to workload identities can reduce potential impact. Monitoring machine identities alongside human identities provides a broader view of the organization’s identity attack surface and helps identify misuse that might otherwise remain unnoticed.
Question 236
Which control helps limit the damage caused by a compromised privileged credential?
- Permanent unrestricted administrator access.
- Just-in-time or time-limited privileged access.
- Shared administrator passwords.
- Disabling audit logs.
Correct Answer: 2
Explanation
Just-in-time or time-limited privileged access reduces the amount of time an identity retains elevated permissions. Instead of maintaining permanent administrative privileges, users receive the required access for an approved period or task. This reduces exposure if credentials are compromised and limits opportunities for unauthorized privilege use. Organizations can strengthen this approach with multifactor authentication, approval workflows, session monitoring, and detailed auditing. Time-limited access does not eliminate all risks, but it supports least privilege and reduces persistent administrative exposure. Security teams should align privileged-access controls with operational requirements and emergency procedures.
Question 237
What should analysts examine when an identity accesses a new geographic region unexpectedly?
- Whether the location change is consistent with legitimate user or organizational activity.
- Only the user’s browser theme.
- The number of files in the user’s desktop folder.
- Whether the user has completed a training course.
Correct Answer: 1
Explanation
An unexpected geographic authentication event should be evaluated in context. Analysts can review travel information when available, device identity, authentication method, previous login patterns, network characteristics, and subsequent activity. Legitimate travel, remote work, corporate VPN infrastructure, or other network routing factors can explain apparent location changes. However, an unexpected location combined with unfamiliar devices or suspicious resource access may increase the need for investigation. Geographic information should therefore be treated as one signal rather than definitive evidence of compromise. Correlating location with other identity and endpoint telemetry provides a more reliable assessment.
Question 238
Which approach best supports investigation of an identity alert?
- Immediately delete the identity account.
- Ignore historical events.
- Examine related events before, during, and after the alert.
- Review only the alert title.
Correct Answer: 3
Explanation
Investigating the surrounding timeline provides important context for an identity alert. Analysts should examine events before the alert to identify possible initial access, events during the alert to understand suspicious behavior, and subsequent activity to determine whether the threat continued. Relevant information may include authentication events, devices, IP addresses, privilege changes, resource access, endpoint activity, and administrative actions. This approach helps analysts distinguish isolated anomalies from coordinated attack activity. Preserving evidence while investigating the sequence also supports accurate incident documentation and can help determine appropriate containment and remediation actions.
Question 239
What is an important benefit of separating administrative and standard user identities?
- It reduces the exposure of privileged credentials during routine activities.
- It allows administrators to avoid authentication.
- It guarantees that privileged accounts cannot be compromised.
- It gives standard users administrative access.
Correct Answer: 1
Explanation
Separating administrative and standard identities helps reduce the exposure of privileged credentials. Administrators can use standard accounts for routine activities such as email and web browsing while using privileged identities only when administrative actions are required. This separation reduces opportunities for privileged credentials to be exposed during ordinary tasks. Additional controls such as multifactor authentication, privileged access management, session monitoring, and least privilege can further strengthen protection. Separation does not make privileged accounts immune to compromise, but it provides a clearer security boundary and can reduce the potential impact of attacks targeting everyday user activity.
Question 240
Which action is most appropriate after confirming that an identity has been compromised?
- Continue normal access without monitoring.
- Preserve the compromised credentials for future use.
- Contain the identity, investigate scope, and remediate according to incident procedures.
- Delete all telemetry associated with the identity.
Correct Answer: 3
Explanation
Once an identity compromise is confirmed, response should focus on containment, investigation, and remediation. Depending on organizational procedures, containment may involve revoking sessions, disabling the account temporarily, resetting credentials, removing unauthorized authentication methods, or restricting access. Investigators should determine what systems and resources were accessed and whether other identities or devices were affected. Relevant telemetry should be preserved because it can help establish the timeline and scope of the incident. After containment, remediation should address the underlying cause and verify that unauthorized access has been removed before normal access is restored.