View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.
Question 301
Which approach best helps identify identity-based threats that occur across multiple systems?
- Reviewing only one application’s authentication logs
- Disabling centralized monitoring
- Correlating identity activity across systems and services
- Ignoring events from cloud applications
Correct Answer: 3
Explanation
Identity-based attacks can span multiple systems, applications, and services, making centralized correlation important. By connecting authentication events, privilege changes, resource access, endpoint activity, and cloud events, analysts can identify relationships that may not be visible in individual systems. For example, an unusual authentication followed by access to several unrelated systems may provide stronger evidence of suspicious behavior than a single login event. Correlation also helps reconstruct attack timelines and identify additional affected resources. Security teams should combine centralized telemetry with appropriate detection rules and investigation processes to improve visibility across the identity environment.
Question 302
What is the primary purpose of reviewing authentication methods used by privileged identities?
- To ensure strong and appropriate authentication controls are applied
- To remove all administrative permissions
- To allow password sharing
- To prevent administrators from using approved systems
Correct Answer: 1
Explanation
Privileged identities can have significant control over systems and resources, so their authentication methods deserve careful review. Organizations should ensure that strong authentication is required and that weaker methods are restricted where appropriate. Reviewing authentication methods can also identify legacy configurations, unnecessary exceptions, or privileged accounts that do not meet current security requirements. Strong authentication should be combined with least privilege, privileged access management, logging, and monitoring. The goal is not simply to make authentication more complicated but to reduce the likelihood that stolen or misused credentials can provide unauthorized access to high-impact resources.
Question 303
Which event can provide evidence of possible unauthorized identity manipulation?
- A documented password rotation
- An approved role assignment
- A scheduled application update
- An unexpected change to authentication settings
Correct Answer: 4
Explanation
Unexpected changes to authentication settings can be important because attackers may attempt to weaken authentication controls or establish alternative access methods after compromising an identity. Analysts should determine who made the change, when it occurred, what settings were modified, and whether there was an approved administrative reason. Related authentication events and endpoint activity can provide additional context. Examples may include changes to authentication factors, recovery settings, or other identity configurations. Not every unexpected change is malicious, but changes involving security controls should be validated promptly because they can affect an organization’s ability to protect and monitor identities.
Question 304
Why should organizations monitor newly created privileged identities?
- They can introduce significant access and may require additional validation.
- Newly created identities cannot be compromised.
- Privileged accounts never require approval.
- New accounts automatically have appropriate permissions.
Correct Answer: 1
Explanation
New privileged identities can introduce significant access to critical systems, so their creation should be properly authorized and monitored. Security teams should verify the business justification, owner, assigned permissions, authentication requirements, and approval process. Unexpected creation of a privileged identity may indicate unauthorized administrative activity or an attempt to establish persistence. Correlating account creation with authentication and endpoint events can provide additional evidence. Organizations should also review privileged identities periodically and remove those that are no longer required. Strong governance around privileged-account creation reduces unnecessary administrative exposure and improves accountability.
Question 305
Which condition can increase concern about an otherwise unusual login?
- The login occurs from an approved managed device.
- The login is followed by access to sensitive resources that the identity rarely uses.
- The login matches the user’s normal location.
- The login uses an approved authentication method.
Correct Answer: 2
Explanation
An unusual login becomes more significant when it is followed by unexpected access to sensitive resources. Analysts should consider the identity’s normal behavior, resource sensitivity, device context, authentication method, location, and timing. Access to unfamiliar resources may be legitimate if the user’s responsibilities recently changed, so investigators should validate the business context. However, the combination of an unusual authentication event and sensitive-resource access can provide stronger evidence of potential misuse. Correlating identity telemetry with endpoint and network events can help determine whether the activity represents an isolated anomaly or part of a broader attack sequence.
Question 306
What is an important purpose of monitoring identity privilege changes?
- To identify potentially unauthorized escalation or access modifications
- To permanently increase user privileges
- To eliminate access governance
- To disable administrative auditing
Correct Answer: 1
Explanation
Privilege changes can significantly alter what an identity is capable of doing. Monitoring these changes allows security teams to identify unexpected additions, removals, or modifications to permissions. Analysts can compare changes against approved role assignments and change-management records. A suspicious privilege modification may indicate account compromise, insider misuse, or unauthorized administrative activity. Correlating privilege changes with authentication and endpoint events can provide additional context. Organizations should also conduct periodic access reviews to identify privileges that remain unnecessarily assigned. Monitoring and governance together help maintain least privilege and reduce the potential impact of compromised identities.
Question 307
Which characteristic makes a machine identity different from a typical human identity?
- It may authenticate automatically as part of an application or workload.
- It always has administrator permissions.
- It cannot access sensitive resources.
- It never requires monitoring.
Correct Answer: 1
Explanation
Machine identities can authenticate automatically as part of applications, services, workloads, automation processes, or APIs. Unlike human users, they may operate continuously without direct interaction. This makes their expected behavior and access patterns particularly important for security monitoring. Organizations should document the purpose and ownership of machine identities, apply least privilege, manage credentials securely, and establish lifecycle processes. Unexpected authentication or resource access can indicate compromise or configuration problems. Monitoring machine identities alongside human accounts provides a more complete view of the organization’s identity environment and helps identify threats that may otherwise remain outside traditional user monitoring.
Question 308
Which activity could indicate that a compromised identity is attempting persistence?
- Accessing an approved business application
- Creating or modifying authentication mechanisms without authorization
- Completing a normal password change
- Performing a scheduled task
Correct Answer: 2
Explanation
Attackers may attempt to establish persistence by creating additional accounts, modifying authentication mechanisms, adding credentials, or changing access settings. Unauthorized changes to identity configuration can therefore be an important investigation signal. Analysts should determine who initiated the change, whether it was approved, and whether other suspicious activity occurred around the same time. Reviewing authentication logs, privilege changes, endpoint activity, and account modifications can help establish whether the event is part of a broader compromise. Strong identity governance and monitoring can make unauthorized persistence attempts easier to detect and contain.
Question 309
What is the purpose of defining normal behavior for an identity?
- To establish a baseline against which unusual activity can be detected
- To permanently restrict the user to one device
- To eliminate all authentication alerts
- To grant the identity administrative privileges
Correct Answer: 1
Explanation
A behavioral baseline describes activity that is normally expected for an identity. It can include common authentication locations, devices, applications, times, and resources. Once established, significant deviations can be identified for further investigation. Baselines should remain flexible because legitimate business activities change over time. Analysts should also avoid treating every deviation as malicious because travel, role changes, new projects, and infrastructure changes can affect behavior. Combining baseline analysis with identity risk, privilege information, endpoint telemetry, and resource sensitivity provides stronger context and helps security teams prioritize events that may represent genuine threats.
Question 310
Which action supports secure handling of a suspected compromised account?
- Continuing to grant the account additional permissions
- Preserving relevant evidence while applying appropriate containment procedures
- Deleting all authentication logs
- Sharing the account credentials with investigators
Correct Answer: 2
Explanation
A suspected compromised account should be handled through established incident-response procedures. Security teams may need to contain the identity by revoking sessions, restricting access, resetting credentials, or temporarily disabling the account, depending on the circumstances. At the same time, relevant logs and telemetry should be preserved because they can help determine the timeline and scope of the incident. Investigators should examine authentication activity, resource access, privilege changes, endpoint behavior, and other relevant evidence. Proper containment reduces the opportunity for continued misuse while evidence preservation supports accurate investigation and remediation.
Question 311
Which practice can help reduce risk from long-lived authentication credentials?
- Ignoring credential age
- Using appropriate credential rotation and lifecycle controls
- Sharing credentials among administrators
- Disabling authentication monitoring
Correct Answer: 2
Explanation
Long-lived credentials can increase exposure because they may remain valid after being leaked or otherwise compromised. Appropriate credential lifecycle controls can reduce this risk by ensuring credentials are managed according to organizational requirements. Depending on the identity type and authentication system, organizations may use rotation, short-lived tokens, managed secrets, or other mechanisms. Credential changes should be implemented carefully so that legitimate applications and users continue to operate correctly. Credential lifecycle controls should complement strong authentication, least privilege, monitoring, and secure secret storage. The appropriate approach depends on the technology and organizational risk requirements.
Question 312
Which event is most useful for determining whether a privilege change was authorized?
- A matching approved change or access request
- The user’s desktop wallpaper
- The application’s font setting
- The user’s browser history
Correct Answer: 1
Explanation
Approved change records can provide important context when investigating privilege modifications. If a privilege change matches a documented request, authorized role change, or approved maintenance activity, the event may have a legitimate explanation. Analysts should still consider timing, identity, scope, and related activity. When a privilege change has no corresponding authorization, it may warrant further investigation. Combining change-management records with identity telemetry helps security teams distinguish expected administrative actions from potentially unauthorized modifications. This process also supports accountability by establishing who requested, approved, and performed sensitive access changes.
Question 313
What is a potential risk of excessive permissions assigned to an application identity?
- A compromise could allow unauthorized access to more resources than required.
- The application will always become unavailable.
- Authentication will no longer be required.
- Excessive permissions automatically improve security.
Correct Answer: 1
Explanation
Application identities with excessive permissions can expose multiple resources if their credentials or tokens are compromised. Least privilege should therefore apply to applications and workloads just as it applies to human users. Organizations should identify the application’s legitimate functions and assign only the permissions necessary to perform them. Access should be reviewed when application functionality changes, and unnecessary permissions should be removed. Monitoring application identity activity can also help identify unexpected resource access. Limiting application permissions reduces the potential impact of compromise and supports a broader defense-in-depth strategy for identity security.
Question 314
Which signal may help identify suspicious use of an identity from an unfamiliar endpoint?
- Device identity combined with authentication and access information
- Employee job title alone
- Password length alone
- The number of applications installed on another user’s device
Correct Answer: 1
Explanation
Device identity provides valuable context when investigating authentication events. Analysts can determine whether the device is known, managed, compliant, and historically associated with the identity. Additional authentication information such as location, timing, method, and resource access can strengthen the investigation. An unfamiliar endpoint may be legitimate because of device replacement or approved remote access, so it should not automatically be treated as malicious. Endpoint telemetry can provide additional evidence about processes, network connections, and other activity. Combining these signals helps security teams distinguish legitimate new-device activity from potential account compromise.
Question 315
What should happen to access when an employee leaves an organization?
- Access should be reviewed and revoked according to the organization’s offboarding procedures.
- All privileges should remain permanently active.
- Administrative permissions should be transferred automatically to another user.
- Authentication logs should be deleted.
Correct Answer: 1
Explanation
Offboarding is a critical component of identity lifecycle management. When an employee leaves, their access should be reviewed and revoked according to established procedures. This can include disabling the identity, terminating active sessions, removing application access, recovering organizational credentials or devices, and reviewing privileged permissions. Timing is important because leaving accounts active after departure can create unnecessary security exposure. Organizations should also consider service dependencies and ownership transfers before completing the process. Automated identity lifecycle workflows can help ensure that access changes occur consistently and reduce the risk of forgotten accounts.
Question 316
Which technique can help analysts understand whether multiple suspicious events belong to the same incident?
- Correlating timestamps, identities, devices, and related activities
- Reviewing each event without context
- Ignoring device information
- Deleting duplicate alerts immediately
Correct Answer: 1
Explanation
Incident correlation connects related events using common attributes such as timestamps, identities, devices, resources, and activity patterns. This can help analysts determine whether multiple alerts represent separate issues or different stages of the same incident. For example, an unusual login, privilege change, and access to a sensitive system may be connected when they occur close together and involve the same identity. Correlation supports timeline reconstruction and can help identify the scope of an incident. Analysts should preserve relevant evidence and validate relationships rather than assuming that every event sharing one attribute belongs to the same attack.
Question 317
What is an important security consideration for emergency privileged access?
- It should be controlled, monitored, and reviewed after use.
- It should remain permanently enabled.
- It should use shared credentials without logging.
- It should bypass all security policies.
Correct Answer: 1
Explanation
Emergency privileged access may be necessary during outages or critical incidents, but it can create significant security exposure if not controlled. Organizations should define when emergency access can be used, who can approve it, what permissions are granted, and how activity is monitored. Access should generally be limited to the required duration and reviewed afterward. Detailed auditing can help confirm what actions were performed and whether they were appropriate. Emergency procedures should provide operational flexibility without creating an uncontrolled administrative pathway. Regular testing and review can help ensure that emergency access remains available while maintaining appropriate security safeguards.
Question 318
Which condition can make an identity alert more significant?
- The identity has elevated privileges and the activity targets sensitive resources.
- The identity has no access permissions.
- The identity is disabled.
- The event occurs during a documented maintenance window.
Correct Answer: 1
Explanation
An alert involving an identity with elevated privileges and access to sensitive resources may deserve greater attention because misuse could have a larger impact. Analysts should consider privilege level, resource sensitivity, authentication context, device, location, timing, and subsequent actions. A privileged identity performing unexpected activity can indicate compromise, misuse, or an unauthorized administrative action. However, legitimate maintenance can produce similar events, so investigators should validate the activity against approved changes and operational context. Risk-based prioritization allows security teams to focus resources on events where the potential consequences of unauthorized activity are greatest.
Question 319
Which practice can improve visibility into identity-related attack paths?
- Maintaining accurate relationships between identities, devices, applications, and resources
- Removing identity ownership information
- Disabling access logging
- Ignoring service accounts
Correct Answer: 1
Explanation
Understanding relationships between identities, devices, applications, and resources helps analysts identify potential attack paths and investigate suspicious activity. For example, knowing which service account belongs to an application and which resources that application normally accesses makes abnormal behavior easier to recognize. Accurate relationships also help determine the potential scope of a compromised identity. Identity inventories, access governance, endpoint management, and application records can contribute to this visibility. Keeping these relationships current is important because infrastructure and business responsibilities change. Better visibility allows security teams to investigate identity events with more complete context.
Question 320
Which combination most effectively supports identity threat response?
- Authentication alone
- Strong authentication, monitoring, access controls, investigation, and defined response procedures
- Password changes without logging
- Unrestricted access with no auditing
Correct Answer: 2
Explanation
Identity threat response requires multiple complementary controls. Strong authentication reduces the likelihood of unauthorized credential use, while access controls limit what an identity can do if compromised. Monitoring provides visibility into suspicious behavior, and investigation helps determine the scope and cause of an event. Defined response procedures allow teams to contain affected identities, preserve evidence, remediate the underlying issue, and restore appropriate access. No single control provides complete protection against identity threats. A layered approach combines prevention, detection, investigation, and response so that organizations have multiple opportunities to identify and contain identity-based attacks.