View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.
Question 261
Which capability helps security analysts determine whether an identity’s activity is consistent with its historical behavior?
- Behavioral baseline analysis
- Password expiration alone
- Manual account deletion
- Network cable testing
Correct Answer: 1
Explanation
Behavioral baseline analysis establishes an understanding of normal activity for an identity and helps identify meaningful deviations. Useful baseline information can include typical login times, devices, locations, applications, and resource access. When activity differs significantly from established patterns, analysts can investigate the reason and determine whether the behavior is legitimate or suspicious. Baselines should not be treated as fixed because users, applications, and business processes change over time. Combining behavioral analysis with identity context, endpoint telemetry, privilege information, and authentication data provides stronger evidence for identifying potentially compromised or misused identities.
Question 262
What is an important consideration when investigating an unusual login from a new device?
- The device should automatically be considered malicious.
- The event should be evaluated alongside authentication and device context.
- The user’s account should always be permanently disabled.
- All other identity events should be ignored.
Correct Answer: 2
Explanation
A new device can represent either legitimate activity or potential account compromise. Users may receive replacement equipment, change work locations, or access approved resources from newly enrolled devices. Analysts should therefore examine authentication method, device security posture, location, timing, user behavior, and subsequent resource access. If the new device is combined with other suspicious indicators, investigation may become more urgent. Contextual analysis helps security teams avoid treating every new-device event as malicious while still identifying combinations of signals that may indicate unauthorized access. This approach supports more accurate identity threat detection and prioritization.
Question 263
Which control is most directly associated with reducing persistent administrative privileges?
- Password complexity
- Permanent administrator membership
- Just-in-time privileged access
- Unrestricted account sharing
Correct Answer: 3
Explanation
Just-in-time privileged access reduces the period during which an identity has elevated permissions. Instead of maintaining administrative privileges permanently, access can be granted only when needed and for an approved duration. This reduces the attack surface associated with privileged credentials and limits opportunities for unauthorized use. Additional controls such as strong authentication, approval workflows, session monitoring, and detailed auditing can strengthen privileged access management. Just-in-time access does not eliminate compromise risk, but it supports least privilege by minimizing persistent administrative permissions. Regular reviews should also ensure that privileged access remains aligned with legitimate operational requirements.
Question 264
Why should identity alerts be correlated with endpoint activity?
- Endpoint data is unrelated to identity investigations.
- Endpoint activity can provide evidence about what occurred after an identity was used.
- Endpoint telemetry automatically proves account ownership.
- Identity alerts eliminate the need for endpoint monitoring.
Correct Answer: 2
Explanation
Identity telemetry can show when and where an account was authenticated, but endpoint telemetry can reveal what happened on the associated device. Correlating the two sources can help analysts determine whether an authentication event led to suspicious processes, network connections, file activity, or other actions. This broader context can distinguish a benign authentication anomaly from activity associated with a compromise. For example, an unfamiliar login followed by suspicious process execution may warrant deeper investigation. Correlation also supports timeline reconstruction and can help identify additional systems or identities involved in an incident.
Question 265
Which situation is most likely to require investigation of a service identity?
- The service performs its normal scheduled operation.
- The service accesses an unfamiliar sensitive system without an approved change.
- The service uses its documented application.
- The service authenticates during its normal operating window.
Correct Answer: 2
Explanation
Service identities should normally operate according to clearly defined technical and business requirements. Unexpected access to a sensitive system can therefore be an important signal, especially when no approved change explains the activity. Analysts should review recent application changes, permissions, authentication sources, associated workloads, and subsequent activity. A legitimate infrastructure migration or software update may account for the behavior, so context is essential. If no legitimate explanation exists, the organization should investigate whether credentials were compromised or whether the service identity was misused. Monitoring service accounts helps detect threats that may bypass traditional human-user monitoring.
Question 266
What does the principle of separation of duties help prevent?
- One individual having unnecessary control over conflicting sensitive activities
- All authentication requirements
- Security monitoring across applications
- Normal business operations
Correct Answer: 1
Explanation
Separation of duties reduces the risk associated with concentrating conflicting responsibilities in a single identity or individual. For sensitive processes, one person may be able to request an action while another approves or executes it. This creates additional oversight and makes unauthorized changes more difficult to perform without detection. Separation of duties can be especially valuable for financial systems, privileged administration, access approvals, and other high-impact activities. It should be implemented according to organizational requirements and supported by appropriate identity governance and auditing. The objective is to reduce opportunities for misuse while maintaining practical operational workflows.
Question 267
Which signal can help identify a potentially compromised identity that is being used for lateral movement?
- A routine password expiration
- Access to previously unrelated systems shortly after authentication
- Normal access to an assigned application
- A scheduled training reminder
Correct Answer: 2
Explanation
Access to multiple systems that an identity does not normally use can be an important indicator of lateral movement. Attackers may use compromised credentials to move from an initially accessed system toward additional resources. Analysts should examine authentication relationships, destination systems, privileges, timing, endpoint activity, and subsequent actions. Legitimate administrators or applications may also access multiple systems, so investigators should validate the business context before concluding that activity is malicious. Correlating identity telemetry with endpoint and network data can help establish whether the activity represents routine administration or suspicious movement through the environment.
Question 268
Which practice improves accountability for privileged actions?
- Sharing one administrator password among all administrators
- Using individual privileged identities with detailed auditing
- Disabling administrative logs
- Allowing anonymous administrative access
Correct Answer: 2
Explanation
Individual privileged identities allow administrative actions to be associated with specific users. Detailed auditing can then provide evidence about when privileged access was used, which systems were accessed, and what actions were performed. Shared credentials make attribution more difficult and can complicate incident investigations. Organizations can strengthen accountability through multifactor authentication, privileged access management, approval workflows, session monitoring, and regular access reviews. These controls help establish a clear relationship between an administrator and the actions performed. Strong accountability also supports investigations when suspicious or unauthorized administrative behavior is detected.
Question 269
What is the main purpose of reviewing identity permissions after a role change?
- To ensure access remains appropriate for the user’s new responsibilities
- To automatically grant administrative access
- To preserve every previous permission
- To disable identity monitoring
Correct Answer: 1
Explanation
Role changes can create unnecessary access if previous permissions are not reviewed. A user who moves to a different department or responsibility may no longer require access to resources associated with the previous role. Reviewing permissions after the change supports least privilege and reduces unnecessary exposure. The process should compare current access with documented requirements for the new role and remove permissions that are no longer justified. Automated identity lifecycle workflows can help apply these changes consistently. Periodic access reviews remain valuable because role information and business requirements can change over time.
Question 270
Which activity can indicate an attacker is attempting to discover privileged identities?
- Reviewing approved documentation
- Repeated queries or access attempts targeting administrative resources
- Completing an assigned application task
- Performing a normal password update
Correct Answer: 2
Explanation
Attackers may attempt to identify privileged accounts, administrative systems, or resources that can provide greater access. Repeated queries or access attempts targeting administrative resources can therefore be useful indicators of reconnaissance. Analysts should review the identity involved, source device, timing, destination resources, and related endpoint or network activity. Legitimate administrative work can produce similar patterns, so contextual validation is necessary. If discovery activity is followed by privilege escalation or access to sensitive systems, the sequence may provide stronger evidence of malicious behavior. Monitoring administrative resource discovery can help security teams detect attacks before privileges are abused.
Question 271
What is a benefit of using risk-based access decisions?
- Every user receives identical access regardless of circumstances.
- Access controls can respond to changes in identity and environmental risk.
- Authentication becomes unnecessary.
- Sensitive resources become publicly accessible.
Correct Answer: 2
Explanation
Risk-based access decisions allow security controls to consider current context rather than applying identical treatment to every request. Factors such as identity risk, device posture, authentication strength, location, application, and resource sensitivity can influence the decision. A low-risk request from a trusted device may be handled differently from a high-risk request involving an unfamiliar device or suspicious identity behavior. This approach supports Zero Trust principles and allows organizations to apply stronger controls when circumstances warrant them. Risk-based access should be carefully configured and monitored so that legitimate business activity remains available while suspicious situations receive additional protection.
Question 272
Which action can help contain a confirmed compromised identity?
- Granting the identity additional privileges
- Revoking active sessions and restricting the identity according to response procedures
- Disabling security telemetry
- Ignoring subsequent authentication attempts
Correct Answer: 2
Explanation
Containment aims to prevent a compromised identity from continuing unauthorized activity while investigators determine the scope of the incident. Depending on organizational procedures, this may include revoking active sessions, resetting credentials, removing unauthorized authentication methods, restricting access, or temporarily disabling the identity. Analysts should preserve relevant evidence and examine recent activity to determine which resources were accessed. Containment should be coordinated with incident-response processes because abrupt access removal can affect business operations. After containment, remediation should address the cause of compromise and verify that unauthorized access has been removed before normal privileges are restored.
Question 273
Which identity type is often associated with automated application-to-application communication?
- Service or workload identity
- Guest visitor identity only
- Temporary physical badge
- Human administrator identity only
Correct Answer: 1
Explanation
Service and workload identities are commonly used by applications, services, automation platforms, and other non-human workloads to authenticate and communicate with resources. These identities can have significant permissions and may operate continuously without direct human interaction. As a result, organizations should establish clear ownership, purpose, permissions, and lifecycle controls for them. Monitoring expected communication patterns can help identify abnormal behavior. Applying least privilege to workload identities reduces the potential impact if credentials or authentication tokens are compromised. Security teams should treat non-human identities as an important part of the overall identity attack surface.
Question 274
What should analysts consider when an identity suddenly authenticates at an unusual time?
- Whether the timing is consistent with legitimate work or other contextual factors
- Only the user’s department name
- Whether the user’s account has a profile image
- The color of the login page
Correct Answer: 1
Explanation
An unusual authentication time can be a useful behavioral signal, but it does not automatically indicate compromise. Employees may work different shifts, perform emergency maintenance, travel, or access systems outside normal hours for legitimate reasons. Analysts should consider the identity’s normal behavior, role, device, location, authentication method, and resources accessed after login. Combining unusual timing with other indicators can make the event more significant. A risk-based approach helps avoid unnecessary alerts while still identifying potentially suspicious activity. Organizations should maintain appropriate logging so that analysts can compare current authentication behavior with historical patterns.
Question 275
Why is accurate ownership important for service accounts?
- It identifies who is responsible for validating the account’s purpose and access.
- It guarantees that the account cannot be compromised.
- It eliminates the need for monitoring.
- It gives the service account unrestricted permissions.
Correct Answer: 1
Explanation
Service-account ownership establishes accountability for the account’s purpose, permissions, and lifecycle. Without an identified owner, security teams may have difficulty determining whether unusual activity is legitimate or whether the account is still required. Owners can help validate expected applications, resources, authentication patterns, and access requirements. Ownership also supports periodic reviews and timely decommissioning of obsolete accounts. Service identities should be managed using least privilege and appropriate monitoring regardless of ownership. Clear responsibility makes it easier to investigate suspicious activity and ensures that unnecessary accounts or permissions can be identified and removed.
Question 276
Which scenario best demonstrates excessive privilege?
- A user can access only applications required for their role.
- An identity retains administrative access to systems unrelated to its current responsibilities.
- A service account has documented permissions for its application.
- A user accesses an approved business application.
Correct Answer: 2
Explanation
Excessive privilege occurs when an identity has permissions beyond what is necessary for its current responsibilities. Retaining administrative access to unrelated systems creates unnecessary exposure and may increase the impact of compromise. Access reviews should compare assigned permissions with current business requirements and remove privileges that are no longer justified. Organizations can also use role-based access, privileged access management, and time-limited elevation to reduce persistent exposure. Least privilege should be maintained throughout the identity lifecycle, particularly after role changes, project completion, organizational transfers, or changes to application responsibilities.
Question 277
Which factor can help distinguish a legitimate unusual login from a potentially compromised identity?
- Correlation with approved travel, device changes, and expected business activity
- Ignoring all authentication history
- Assuming every unusual login is malicious
- Disabling the identity immediately without investigation
Correct Answer: 1
Explanation
Unusual authentication events require context. Approved travel, a recently issued device, remote-work arrangements, or a scheduled operational change may explain activity that initially appears suspicious. Analysts can compare the event with identity history, device information, location, authentication method, and subsequent access. If the activity aligns with documented business circumstances, the alert may require less urgent investigation. Conversely, unusual authentication combined with unfamiliar devices, unexpected privilege use, or sensitive-resource access may warrant deeper analysis. Contextual correlation allows security teams to make better-informed decisions without automatically treating every anomaly as malicious.
Question 278
What is the purpose of monitoring authentication failures across identities?
- To identify patterns that may indicate password attacks or other suspicious activity
- To prevent all successful authentication
- To eliminate account lifecycle management
- To grant additional privileges after failures
Correct Answer: 1
Explanation
Authentication failures can provide useful signals about password spraying, credential stuffing, brute-force attempts, user error, or configuration problems. Monitoring patterns across multiple identities can help distinguish isolated mistakes from coordinated activity. Analysts may examine the number of failures, targeted accounts, source information, timing, and whether successful authentication follows the failures. Strong authentication and appropriate account-protection controls can reduce the impact of credential attacks. Authentication failure monitoring should be tuned to the environment because legitimate applications and users can also generate failed attempts. Correlating failures with successful logins and other telemetry can improve detection quality.
Question 279
Which practice supports secure management of temporary elevated access?
- Granting permanent administrative privileges
- Using time-limited access with appropriate approval and monitoring
- Sharing administrator credentials
- Removing audit requirements
Correct Answer: 2
Explanation
Temporary elevated access should be limited to the required task and duration whenever practical. Time-limited privileges reduce the period during which an identity can perform sensitive actions and therefore reduce persistent exposure. Approval workflows can help ensure that elevation has a legitimate business purpose, while logging and monitoring provide visibility into the actions performed. After the approved period, elevated permissions should be removed automatically or according to established procedures. Combining temporary access with strong authentication and least privilege creates a stronger control framework for administrative activities while preserving operational flexibility.
Question 280
Which approach best supports a mature identity threat detection program?
- Relying only on password expiration
- Combining identity telemetry, behavioral analysis, endpoint context, access governance, and response procedures
- Monitoring only executive accounts
- Disabling alerts to reduce workload
Correct Answer: 2
Explanation
A mature identity threat detection program uses multiple complementary capabilities. Identity telemetry provides authentication and authorization visibility, behavioral analysis helps identify deviations from normal activity, and endpoint context can reveal actions performed after an identity is used. Access governance helps ensure that permissions remain appropriate, while response procedures provide a structured method for containment and remediation. No individual control can identify every identity threat. Combining these capabilities gives security teams broader visibility and better investigative context. Continuous tuning is also important because identity behavior, applications, infrastructure, and attack techniques can change over time.