CrowdStrike CCIS Practice Test Questions and Exam Dumps Part18 Q341-360

View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.

 

Question 341

What is a primary objective of identity threat detection?

  1. To identify suspicious identity behavior that may indicate unauthorized activity
  2. To eliminate all user accounts
  3. To prevent employees from using applications
  4. To replace endpoint security controls

Correct Answer: 1

Explanation

Identity threat detection focuses on identifying unusual or suspicious behavior involving identities. This may include unexpected authentication patterns, privilege changes, abnormal resource access, unusual use of service accounts, or other activity that differs from established behavior. Effective detection combines identity telemetry with contextual information such as device, location, privileges, and resource sensitivity. Identity detections should support investigation rather than automatically assume that every anomaly represents an attack. Security teams can improve detection quality by continuously reviewing alerts, validating findings, and tuning rules based on legitimate organizational behavior. This approach helps identify potential identity compromise while reducing unnecessary alert volume.

Question 342

Which control is most useful for reducing the risk of unauthorized access after credentials are stolen?

  1. Increasing account inactivity periods
  2. Multi-factor authentication
  3. Disabling security monitoring
  4. Sharing credentials between administrators

Correct Answer: 2

Explanation

Multi-factor authentication adds another verification requirement beyond a password or other single credential. If an attacker obtains a user’s password, an additional authentication factor may prevent or complicate unauthorized access. Strong authentication should be applied especially to privileged accounts and sensitive resources. Organizations should also monitor authentication events and investigate suspicious MFA activity, because attackers may attempt techniques such as repeated authentication requests or session abuse. MFA is an important defensive layer, but it does not eliminate all identity threats. Combining MFA with least privilege, device controls, monitoring, and appropriate access governance provides broader protection.

Question 343

Why is context important when investigating an unusual login?

  1. Every unusual login is automatically malicious.
  2. Context can help distinguish legitimate unusual activity from potential compromise.
  3. Login investigations should ignore device information.
  4. Authentication logs are never useful during investigations.

Correct Answer: 2

Explanation

An unusual login does not automatically mean that an account has been compromised. Users may legitimately travel, work remotely, change devices, or access resources at unusual times. Investigators should examine contextual signals such as device identity, authentication method, location, time, previous behavior, privileges, and resources accessed afterward. Correlating these signals can help determine whether the event fits expected business activity or presents stronger indicators of compromise. Context reduces the risk of unnecessary response actions while helping analysts identify genuinely suspicious activity. Effective identity investigations therefore rely on multiple related signals rather than treating a single authentication event as conclusive evidence.

Question 344

What is an important security consideration for non-human identities?

  1. They should never be monitored.
  2. They should always have unrestricted privileges.
  3. Their credentials and permissions should be managed throughout their lifecycle.
  4. They cannot be compromised.

Correct Answer: 3

Explanation

Non-human identities such as service accounts, application identities, and workload identities can have significant access to organizational resources. Their security therefore requires lifecycle management similar to human accounts. Organizations should establish ownership, document purpose, limit permissions, protect credentials or tokens, and remove identities when they are no longer required. Monitoring is also important because automated identities may normally generate predictable activity, making deviations easier to identify. Unmanaged machine identities can become persistent access paths for attackers. Proper lifecycle governance helps ensure that non-human identities remain necessary, appropriately privileged, and accountable throughout their operational lifespan.

Question 345

Which event may indicate privilege escalation?

  1. An identity receives administrative permissions that were not previously assigned
  2. A user completes a routine password change
  3. A scheduled backup runs successfully
  4. An approved application starts normally

Correct Answer: 1

Explanation

An unexpected assignment of administrative permissions can indicate possible privilege escalation. Investigators should determine who initiated the change, which permissions were granted, when the change occurred, and whether an approved business requirement existed. Additional context such as authentication events, device activity, and subsequent resource access can help determine whether the change was legitimate. Privilege modifications are important security events because elevated permissions can provide access to sensitive systems and administrative functions. Organizations should monitor privilege changes and maintain appropriate approval and review processes. Unexpected privilege increases should receive appropriate investigation based on organizational risk and context.

Question 346

What is the main purpose of identity lifecycle management?

  1. To keep every account active indefinitely
  2. To manage identities from creation through modification and eventual removal
  3. To eliminate access reviews
  4. To provide identical permissions to every user

Correct Answer: 2

Explanation

Identity lifecycle management governs identities throughout their existence. It includes account creation, assignment of appropriate access, changes resulting from role or responsibility changes, periodic reviews, and eventual disabling or removal. Effective lifecycle management reduces risks associated with orphaned accounts, outdated privileges, and unnecessary access. It should cover both human and non-human identities where appropriate. Organizations can use automated provisioning and deprovisioning processes to improve consistency and reduce manual errors. Lifecycle management is an important part of identity governance because access should reflect current business requirements rather than permissions accumulated over time.

Question 347

Which activity can help identify compromised credentials?

  1. Comparing authentication behavior against known normal patterns
  2. Ignoring failed authentication attempts
  3. Disabling identity monitoring
  4. Removing historical authentication records

Correct Answer: 1

Explanation

Comparing authentication activity against established patterns can help identify potentially compromised credentials. Analysts can examine factors such as login timing, device usage, geographic context, authentication methods, and resource access. A significant deviation may warrant investigation, especially when combined with other suspicious signals. However, behavioral differences can also have legitimate explanations, so detections should provide context rather than automatically declaring compromise. Historical authentication records are valuable for establishing baselines and reconstructing incidents. Maintaining reliable identity telemetry allows security teams to identify anomalies, investigate suspicious activity, and determine whether additional containment or remediation actions are appropriate.

Question 348

What should organizations do with an identity that no longer has a valid business purpose?

  1. Grant it additional privileges.
  2. Keep it permanently active.
  3. Disable or remove it according to lifecycle procedures.
  4. Share it with another employee.

Correct Answer: 3

Explanation

An identity without a valid business purpose generally represents unnecessary access and should be addressed through established lifecycle procedures. Depending on organizational requirements, the identity may be disabled, removed, or retained temporarily for a documented reason. Keeping unnecessary accounts active increases the number of potential authentication paths that could be abused. Before removal, organizations should consider dependencies, ownership, data retention, and application requirements. Proper deprovisioning should also include associated permissions, credentials, tokens, and access relationships where appropriate. Maintaining accurate identity inventories and ownership information makes it easier to identify accounts that should no longer remain active.

Question 349

Which factor can make a privileged identity particularly attractive to attackers?

  1. It has no access to important resources.
  2. It can perform high-impact administrative actions.
  3. It is always automatically protected.
  4. It cannot authenticate remotely.

Correct Answer: 2

Explanation

Privileged identities can perform administrative actions that affect systems, applications, configurations, and sensitive data. This makes them valuable targets for attackers seeking to expand access or modify security controls. Organizations should protect privileged identities with strong authentication, least privilege, controlled administrative sessions, monitoring, and appropriate access governance. Administrative permissions should be granted only when justified and should be reviewed regularly. Security teams should also monitor unusual privileged activity and unexpected privilege changes. Protecting privileged identities is important because misuse of a highly privileged account can potentially have a broader impact than compromise of a standard user identity.

Question 350

What is the purpose of establishing behavioral baselines for identities?

  1. To understand expected activity and identify meaningful deviations
  2. To prevent all authentication
  3. To assign administrative rights automatically
  4. To remove the need for security analysts

Correct Answer: 1

Explanation

Behavioral baselines describe patterns that are considered normal for a particular identity, identity group, or application. These patterns may include common login times, devices, locations, applications, and resources. Once established, baselines can help identify deviations that deserve further investigation. Baselines should not be treated as permanent because organizational behavior changes over time. Security teams should periodically review and update them while considering legitimate changes in work patterns. Effective baselining provides useful context for detection and investigation and can help distinguish routine identity activity from potentially suspicious behavior without relying on a single isolated event.

Question 351

Which security practice helps reduce the exposure created by long-lived credentials?

  1. Regularly rotating or replacing credentials according to risk and policy
  2. Sharing credentials among multiple teams
  3. Storing credentials in plain text
  4. Disabling authentication logs

Correct Answer: 1

Explanation

Long-lived credentials can increase exposure because a compromised credential may remain useful for an extended period. Organizations can reduce this risk by using appropriate credential rotation, short-lived tokens, automated secret management, and other controls based on the identity type and application requirements. Rotation should be implemented carefully to avoid disrupting legitimate services. Credentials should also be stored securely and protected from unnecessary exposure. For non-human identities, automated secret-management processes can reduce manual handling. Credential management works best when combined with least privilege, monitoring, strong authentication, and lifecycle governance rather than being treated as a standalone security measure.

Question 352

What should an analyst verify when a user receives unexpected administrative privileges?

  1. Only the user’s job title
  2. Whether the privilege change was authorized and what activity followed it
  3. The user’s email signature
  4. The computer’s screen resolution

Correct Answer: 2

Explanation

An unexpected administrative privilege change should be examined for authorization, source, timing, and subsequent activity. Analysts should determine who initiated the change, whether an approved request existed, what permissions were granted, and which resources the identity accessed afterward. Authentication and endpoint telemetry can help identify whether the privilege change occurred during a suspicious session. If the change was unauthorized, the identity may require containment and remediation. Investigating related activity can also reveal whether the elevated privileges were used to access sensitive systems or modify security controls. This approach helps determine both legitimacy and potential impact.

Question 353

Why is monitoring application identities important?

  1. Applications can possess permissions and access resources without human interaction.
  2. Applications can never be compromised.
  3. Application identities do not require ownership.
  4. Monitoring application identities reduces visibility.

Correct Answer: 1

Explanation

Application identities can authenticate and access resources automatically, sometimes with substantial permissions. Because these identities may operate continuously, compromise or misuse can provide attackers with persistent access without requiring direct interaction from a human user. Monitoring application identities helps establish expected behavior and identify unusual authentication, resource access, or privilege changes. Organizations should document ownership, purpose, permissions, and associated applications. Least privilege should be applied so that an application receives only the access required for its function. Combining lifecycle management with monitoring and secure credential handling strengthens protection for application identities.

Question 354

Which response action can help contain a confirmed compromised user identity?

  1. Granting the identity additional privileges
  2. Ignoring active sessions
  3. Disabling or restricting the compromised identity while investigation proceeds
  4. Sharing its credentials with investigators

Correct Answer: 3

Explanation

When an identity is confirmed to be compromised, restricting or disabling it can help prevent further unauthorized activity while the investigation continues. Depending on the environment, responders may also revoke active sessions, reset credentials, remove unauthorized authentication methods, and review associated permissions. The exact response should follow organizational incident-response procedures and consider business impact. Investigators should preserve relevant evidence before making changes when appropriate. Containment should also consider whether the attacker may have accessed other accounts or systems. A coordinated response helps limit further activity while supporting investigation, remediation, and recovery.

Question 355

What is an advantage of correlating identity telemetry with endpoint telemetry?

  1. It provides additional context about what happened before and after authentication.
  2. It eliminates the need for identity monitoring.
  3. It guarantees accurate attacker attribution.
  4. It prevents all endpoint compromise.

Correct Answer: 1

Explanation

Correlating identity and endpoint telemetry can provide a more complete view of suspicious activity. Identity data can show authentication, privileges, and resource access, while endpoint data can provide information about processes, devices, network connections, and other host activity. Together, these signals can help analysts determine whether an unusual login was followed by suspicious actions on a device. Correlation can also help reconstruct timelines and identify relationships between events that might appear unrelated when viewed separately. Although it does not guarantee attribution or prevent compromise, combining telemetry improves investigation context and can strengthen identity-focused detection and response.

Question 356

Which situation is most relevant when assessing an identity’s access risk?

  1. The color of the user’s desktop theme
  2. The sensitivity of resources combined with the identity’s privileges
  3. The user’s preferred browser appearance
  4. The computer’s wallpaper

Correct Answer: 2

Explanation

Access risk depends partly on what an identity can reach and what actions it can perform. An identity with broad privileges over highly sensitive resources represents a different level of risk from an identity with limited access to routine resources. Security teams should therefore consider resource sensitivity, privilege level, identity type, authentication strength, and expected usage patterns when assessing risk. Access reviews can help determine whether permissions remain necessary. Reducing unnecessary privileges and separating sensitive administrative functions can limit potential impact if an identity is compromised. Risk assessment should focus on security-relevant relationships rather than irrelevant device or user preferences.

Question 357

Why should security teams investigate repeated failed authentication followed by a successful login?

  1. The pattern may indicate password guessing or other suspicious authentication activity.
  2. The successful login automatically proves the account is compromised.
  3. Failed authentication events are never useful.
  4. The pattern should always be ignored.

Correct Answer: 1

Explanation

Repeated failed authentication attempts followed by a successful login can indicate several possibilities, including a user entering an incorrect password, password guessing, credential stuffing, or another authentication-related attack. Analysts should examine the source device, location, timing, authentication method, and subsequent activity to determine whether the pattern is suspicious. A successful login alone does not prove compromise. Correlating authentication events with endpoint and resource-access telemetry can provide additional evidence. Organizations should establish appropriate authentication monitoring and response procedures so that repeated suspicious attempts can be investigated without unnecessarily disrupting legitimate users.

Question 358

What is an important benefit of removing unnecessary identity permissions?

  1. It increases the number of available attack paths.
  2. It reduces the potential impact of identity compromise.
  3. It eliminates the need for authentication.
  4. It guarantees that credentials cannot be stolen.

Correct Answer: 2

Explanation

Removing unnecessary permissions supports least privilege and reduces what a compromised identity can potentially access or modify. If an attacker obtains valid credentials, excessive permissions may allow broader access and increase the potential impact of the compromise. Regular access reviews can identify permissions that no longer match an identity’s responsibilities. Organizations should prioritize sensitive resources and privileged access when conducting reviews. Permission reduction does not prevent credential theft or guarantee that compromise cannot occur, but it limits the capabilities available after compromise. This makes access governance an important component of identity-focused risk reduction.

Question 359

Which information is especially useful for determining whether a service account’s activity is legitimate?

  1. Its documented purpose and expected application behavior
  2. The employee’s desktop wallpaper
  3. The monitor’s screen size
  4. The office furniture used by the owner

Correct Answer: 1

Explanation

A service account’s documented purpose and expected application behavior provide important context during an investigation. Analysts can compare observed authentication and resource access with the account’s intended function. If the account normally interacts with a defined application but suddenly accesses unrelated systems, the deviation may warrant investigation. Ownership information, source devices, timestamps, and recent application changes can provide additional context. Legitimate changes should be validated with the responsible team rather than automatically classified as malicious. Maintaining accurate documentation makes service-account monitoring more effective because analysts have a reliable reference for distinguishing expected automated behavior from unusual activity.

Question 360

Which practice best supports effective identity incident response?

  1. Waiting until all evidence disappears
  2. Disabling all identity monitoring during an incident
  3. Combining containment, evidence preservation, investigation, and remediation
  4. Granting compromised accounts additional access

Correct Answer: 3

Explanation

Effective identity incident response combines several activities rather than relying on a single action. Containment can limit ongoing unauthorized access, while evidence preservation helps investigators understand what occurred. Investigation should determine the affected identities, systems, resources, and likely attack path. Remediation can include credential changes, permission corrections, session revocation, removal of unauthorized access, and addressing the original security weakness. Recovery and post-incident review can then improve controls and detection capabilities. Response actions should follow established procedures and consider business impact. A coordinated approach helps reduce further risk while preserving information needed to understand and prevent similar incidents.