CrowdStrike CCIS Practice Test Questions and Exam Dumps Part15 Q281-300

View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.

 

Question 281

Which approach is most effective for identifying suspicious identity behavior across a large environment?

  1. Reviewing only administrator accounts
  2. Disabling authentication alerts
  3. Using behavioral analytics with identity and contextual telemetry
  4. Checking passwords manually once a year

Correct Answer: 3

Explanation

Behavioral analytics can identify deviations from normal identity activity by examining authentication patterns, device usage, locations, resource access, and other contextual signals. This approach is especially useful in large environments where manually reviewing every event is impractical. An unusual event does not automatically prove compromise because legitimate changes can produce similar patterns. Analysts should correlate behavioral anomalies with endpoint activity, privileges, authentication methods, and resource sensitivity. A mature identity security program uses behavioral analytics as one component of a broader detection strategy. This provides security teams with useful signals for prioritizing investigations and identifying potentially compromised identities.

Question 282

What is the primary purpose of periodically reviewing privileged access?

  1. To identify and remove privileges that are no longer justified
  2. To provide administrators with permanent access
  3. To eliminate authentication requirements
  4. To increase the number of privileged identities

Correct Answer: 1

Explanation

Periodic privileged-access reviews help ensure that administrative permissions remain aligned with current business responsibilities. Users may change roles, projects may end, or administrative responsibilities may be transferred, leaving unnecessary privileges in place. Reviewing privileged access helps identify these situations and supports least privilege. Organizations can examine ownership, permissions, role requirements, recent activity, and approval records during the review. Removing unnecessary privileges reduces the potential impact of compromised administrative identities. Regular reviews should complement strong authentication, privileged access management, monitoring, and lifecycle processes rather than being treated as a replacement for those controls.

Question 283

Which activity can indicate potential abuse of a compromised service identity?

  1. Performing its documented scheduled operation
  2. Accessing an unrelated sensitive system outside its expected behavior
  3. Connecting to its normal application
  4. Authenticating during its approved maintenance window

Correct Answer: 2

Explanation

Service identities generally have predictable purposes and access requirements. Unexpected access to unrelated sensitive systems can therefore be a useful indicator of potential misuse. Analysts should determine whether a legitimate application change, migration, or configuration update explains the activity. If no approved reason exists, investigators can examine authentication sources, permissions, associated workloads, and subsequent actions. Service accounts may have persistent access and can operate without direct human interaction, making monitoring particularly important. Clear ownership, documented purpose, least privilege, and behavioral monitoring help security teams identify abnormal service-identity activity and respond before unauthorized access expands.

Question 284

Why should identity events be correlated with network telemetry?

  1. Network telemetry can provide additional context about destinations and communication associated with an identity.
  2. Network data automatically identifies every compromised identity.
  3. Identity monitoring makes network visibility unnecessary.
  4. Network telemetry prevents all credential theft.

Correct Answer: 1

Explanation

Identity events show authentication and access activity, while network telemetry can provide information about connections, destinations, and communication patterns associated with that activity. Correlating these sources can help analysts determine whether an identity was used to communicate with unusual systems or destinations. For example, an unfamiliar authentication followed by connections to sensitive infrastructure may warrant additional investigation. Network information should not be treated as definitive proof of compromise because legitimate applications and remote-access technologies can produce unusual traffic. Combining identity and network context improves investigation quality and can help establish relationships between authentication events and broader attack activity.

Question 285

Which principle limits an identity to only the access required for its responsibilities?

  1. Open authorization
  2. Permanent access
  3. Least privilege
  4. Shared administration

Correct Answer: 3

Explanation

Least privilege limits an identity’s permissions to what is necessary for legitimate responsibilities. This reduces unnecessary exposure and can limit the impact of a compromised account. Least privilege applies to human users as well as service accounts, applications, workloads, and privileged identities. Organizations can implement it through role-based access, access reviews, privileged access management, and appropriate approval processes. Permissions should be reassessed when users change roles or when applications and business requirements change. While least privilege does not prevent credential compromise, it can significantly reduce the actions an attacker may perform after gaining control of an identity.

Question 286

What should an analyst examine when a user suddenly accesses a large number of sensitive resources?

  1. Only the user’s profile information
  2. The user’s historical behavior, authentication context, and resource activity
  3. The user’s preferred application theme
  4. The number of emails in the mailbox

Correct Answer: 2

Explanation

A sudden increase in access to sensitive resources may be legitimate, but it can also indicate compromised credentials or unauthorized data discovery. Analysts should compare the activity with the user’s historical behavior and documented responsibilities. Authentication source, device, location, privilege level, timing, and the types of resources accessed can provide additional context. Investigators should also examine whether the activity followed a suspicious login or privilege change. Correlating identity activity with endpoint and network telemetry can help establish whether the behavior represents normal business activity or part of a broader security incident.

Question 287

Which control helps prevent stolen passwords from being sufficient for accessing protected resources?

  1. Strong multifactor authentication
  2. Password reuse
  3. Shared credentials
  4. Anonymous access

Correct Answer: 1

Explanation

Multifactor authentication adds an additional authentication requirement beyond the password. As a result, possession of a stolen password alone may not be sufficient to access the protected resource. Stronger authentication methods can provide greater resistance against credential theft and phishing attacks. Organizations should prioritize stronger authentication for privileged identities and sensitive applications. Authentication controls should still be combined with authorization, identity monitoring, endpoint protection, and incident response because no authentication method eliminates every attack. Monitoring for suspicious behavior remains important even when multifactor authentication is enabled because attackers may attempt other methods of obtaining or abusing access.

Question 288

What is an important security benefit of separating standard and privileged accounts?

  1. It makes privileged credentials less exposed during routine activities.
  2. It eliminates the need for administrative logging.
  3. It allows users to keep permanent administrative rights.
  4. It guarantees privileged accounts cannot be compromised.

Correct Answer: 1

Explanation

Separating standard and privileged accounts reduces the need to use administrative credentials during routine activities such as email, browsing, or general productivity work. This can reduce opportunities for privileged credentials to be exposed or misused. Administrators can use standard accounts for everyday activities and elevate privileges only when administrative actions are required. Additional protections such as multifactor authentication, privileged access management, session monitoring, and detailed logging can further strengthen this separation. The practice does not make privileged accounts immune to compromise, but it reduces unnecessary exposure and creates clearer boundaries between ordinary activity and sensitive administrative operations.

Question 289

Which event may indicate an identity has been targeted by password spraying?

  1. Many authentication attempts using one password pattern across multiple accounts
  2. One successful login from a known device
  3. A scheduled password change
  4. A normal application authentication

Correct Answer: 1

Explanation

Password spraying involves attempting a small number of commonly used or compromised passwords against many accounts rather than repeatedly attacking one account. This can help attackers avoid triggering account-specific lockout thresholds. Security teams can monitor authentication failures across multiple identities and examine source information, timing, targeted accounts, and authentication methods. A pattern affecting many accounts may indicate coordinated activity rather than individual user error. Strong authentication can reduce the effectiveness of password spraying, while monitoring and appropriate account-protection controls can help identify attempts. Analysts should also consider legitimate applications that may generate multiple authentication failures.

Question 290

What is the main purpose of identity governance?

  1. To provide every user with maximum access
  2. To manage and control who should have access to organizational resources
  3. To remove all identity monitoring
  4. To eliminate access reviews

Correct Answer: 2

Explanation

Identity governance provides processes and controls for managing access throughout the identity lifecycle. It helps organizations determine which identities should access particular resources, who approves that access, how permissions are reviewed, and when access should be removed. Governance supports least privilege, separation of duties, lifecycle management, and accountability. It is especially important for sensitive applications and privileged identities. Effective governance requires accurate identity information, defined ownership, documented responsibilities, and regular reviews. Technical controls enforce many of these decisions, while governance establishes the policies and processes that determine what access should be allowed.

Question 291

Which situation is most likely to require investigation of a potentially compromised administrator account?

  1. A scheduled administrative task performed from an approved device
  2. An unexpected administrative login followed by unusual configuration changes
  3. A normal password rotation
  4. An approved maintenance activity

Correct Answer: 2

Explanation

An unexpected administrative login followed by unusual configuration changes can provide multiple indicators of potential account compromise. Analysts should investigate the authentication source, device, timing, privilege use, affected systems, and specific changes performed. Change-management records can help determine whether the activity was authorized. Endpoint and network telemetry may provide additional evidence about what occurred before and after the administrative actions. Because privileged accounts can affect critical systems, suspicious administrative behavior deserves careful attention. However, unusual activity should still be validated against legitimate operational events before conclusions are made or containment actions are taken.

Question 292

What is the purpose of monitoring identity authentication locations?

  1. To prevent legitimate users from traveling
  2. To identify geographic patterns that may provide useful risk context
  3. To eliminate multifactor authentication
  4. To give every identity the same risk level

Correct Answer: 2

Explanation

Authentication location can provide useful context when evaluating identity behavior. A login from a new or unexpected geographic location may be legitimate because of travel, remote work, VPN infrastructure, or other network conditions. However, when geographic anomalies occur alongside unfamiliar devices, unusual timing, or sensitive-resource access, they may warrant investigation. Location should therefore be treated as one signal rather than definitive proof of compromise. Security teams can improve accuracy by correlating geographic information with device identity, authentication method, historical behavior, and other telemetry. This approach helps prioritize suspicious activity without unnecessarily blocking legitimate access.

Question 293

Which practice helps reduce the risk associated with dormant accounts?

  1. Increasing their privileges
  2. Regularly reviewing and disabling accounts that are no longer required
  3. Excluding them from access reviews
  4. Sharing their credentials with administrators

Correct Answer: 2

Explanation

Dormant accounts can represent unnecessary attack paths if they remain enabled with valid permissions. Attackers may target these accounts because their activity can be less noticeable than activity from regularly used identities. Organizations should periodically identify inactive accounts, verify whether they still have a legitimate purpose, and disable or remove them when appropriate. Reviews should include account ownership, permissions, authentication activity, and business justification. Lifecycle automation can help identify accounts that have not been used for defined periods. Reducing unnecessary accounts improves identity hygiene and limits the number of potential credentials available to attackers.

Question 294

Which factor can increase the risk associated with an identity?

  1. Access to highly sensitive resources combined with elevated privileges
  2. Limited access to a single approved application
  3. A regularly reviewed standard account
  4. A disabled account with no permissions

Correct Answer: 1

Explanation

An identity with elevated privileges and access to highly sensitive resources represents a greater potential security impact if compromised. Such identities should generally receive stronger authentication, closer monitoring, more frequent access reviews, and appropriate privileged-access controls. Risk is influenced by several factors, including identity type, privilege level, resource sensitivity, behavior, and authentication context. Elevated access does not mean that an identity is malicious; it simply means that compromise could have broader consequences. A risk-based approach allows organizations to apply stronger protections where the potential impact of unauthorized access is greater.

Question 295

What should happen when a temporary identity is no longer required?

  1. Its permissions should be increased.
  2. It should remain permanently active.
  3. It should be disabled or removed according to lifecycle procedures.
  4. Its credentials should be shared with another user.

Correct Answer: 3

Explanation

Temporary identities should have a defined lifecycle and should be disabled or removed when their approved purpose ends. Leaving temporary accounts active can create unnecessary access that may eventually be forgotten or misused. Organizations should establish expiration dates, ownership, required permissions, and appropriate approval procedures for temporary identities. Automated lifecycle controls can help enforce expiration consistently. Before disabling an account, security and business teams may need to confirm that no legitimate process still depends on it. Proper lifecycle management reduces identity sprawl and ensures that access remains aligned with current business requirements.

Question 296

Which type of telemetry can help determine what actions occurred after a suspicious identity login?

  1. Endpoint activity associated with the authenticated device
  2. Employee vacation records only
  3. Marketing analytics
  4. Office lighting schedules

Correct Answer: 1

Explanation

Endpoint telemetry can provide important evidence about activity that occurred after an identity authenticated to a device. Analysts may examine processes, file activity, network connections, applications, and other endpoint events to determine whether suspicious actions followed the login. Correlating endpoint events with authentication timestamps can help establish a detailed timeline. This is especially useful when investigating potential account takeover or lateral movement. Endpoint evidence should be considered alongside identity, network, cloud, and application telemetry where available. A combined view helps analysts determine whether the authentication was simply unusual or connected to a broader security incident.

Question 297

Which action supports least privilege for application identities?

  1. Granting access to every available API
  2. Assigning only the permissions required for the application’s documented functions
  3. Using shared administrator credentials
  4. Giving applications permanent unrestricted access

Correct Answer: 2

Explanation

Application identities should receive only the permissions required to perform their documented functions. Granting broad access to every available API increases the potential impact if the application’s credentials or tokens are compromised. Organizations should identify required resources, define appropriate scopes or permissions, and review them periodically. Changes to application functionality should trigger an access review so permissions remain aligned with current requirements. Strong authentication, secure credential storage, monitoring, and lifecycle management should complement least privilege. Limiting application permissions reduces unnecessary exposure while allowing legitimate automated workflows to continue operating.

Question 298

Why is maintaining detailed identity audit logs important?

  1. They provide evidence that can support monitoring and incident investigations.
  2. They guarantee that attacks cannot occur.
  3. They eliminate the need for authentication.
  4. They automatically remediate compromised accounts.

Correct Answer: 1

Explanation

Detailed identity audit logs provide evidence about authentication, authorization, privilege changes, account modifications, and other identity-related activity. During an investigation, these records can help analysts reconstruct timelines and determine which identities accessed particular systems or resources. Logs can also support detection by providing the data needed to identify unusual behavior. Retention requirements should be aligned with organizational policies and applicable requirements, while access to logs should itself be protected against unauthorized modification. Audit logs do not prevent attacks by themselves, but they provide essential visibility for detection, investigation, accountability, and response activities.

Question 299

Which behavior may indicate an attacker is attempting privilege escalation?

  1. An identity requests or obtains permissions beyond its normal role without a clear business reason.
  2. A user accesses an approved application.
  3. An administrator performs a documented maintenance task.
  4. A service executes its normal scheduled process.

Correct Answer: 1

Explanation

Unexpected requests or changes that provide an identity with permissions beyond its normal responsibilities may indicate privilege escalation. Analysts should determine who initiated the change, whether it was approved, what permissions were granted, and what activity followed. Endpoint and identity telemetry can help identify whether the privilege change was associated with suspicious processes or access attempts. Legitimate role changes and emergency administration can also produce elevated permissions, so investigators should validate the event against change-management records and business context. Monitoring privilege modifications is important because successful escalation can significantly increase the potential impact of an identity compromise.

Question 300

Which combination provides the strongest contextual basis for investigating a suspicious identity event?

  1. User’s favorite application and desktop background
  2. Authentication data, device context, privileges, resource access, and related endpoint activity
  3. Employee name and department only
  4. Password length without any other information

Correct Answer: 2

Explanation

A comprehensive identity investigation benefits from multiple sources of context. Authentication data can show when and how an identity was used, while device information can identify the endpoint involved. Privilege data reveals the capabilities available to the identity, and resource-access information shows what systems or information were reached. Endpoint telemetry can then provide evidence of actions performed after authentication. Combining these signals allows analysts to reconstruct events and determine whether activity is consistent with normal behavior. No single data source provides complete visibility, so correlation is essential for effective identity threat detection and incident investigation.