View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.
Question 321
What is the primary security benefit of applying least privilege to user identities?
- It eliminates the need for authentication.
- It allows every user to access all resources.
- It limits the potential impact if an identity is compromised.
- It prevents all security incidents.
Correct Answer: 3
Explanation
Least privilege limits an identity’s access to only the resources and actions required for legitimate responsibilities. If credentials are compromised, the attacker may therefore have fewer opportunities to access sensitive systems or perform damaging actions. Least privilege should be applied to both human and non-human identities and reviewed periodically as responsibilities change. Organizations can combine role-based access controls, access reviews, privileged access management, and monitoring to maintain appropriate permissions. Least privilege does not eliminate compromise or guarantee that an attacker cannot cause damage, but it can reduce the available attack surface and limit the potential consequences of unauthorized identity use.
Question 322
Which identity event should generally receive additional investigation when it occurs unexpectedly?
- A routine approved login
- An unauthorized addition of administrative privileges
- A scheduled password rotation
- A documented role change
Correct Answer: 2
Explanation
An unexpected addition of administrative privileges can significantly increase the capabilities of an identity and therefore deserves investigation. Analysts should determine which identity performed the change, who approved it, what permissions were added, and whether the change corresponds to a legitimate business requirement. Related authentication, endpoint, and resource-access activity can provide additional context. If the change was unauthorized, security teams may need to contain the affected identity and review other potentially affected accounts or systems. Monitoring privilege modifications helps organizations detect potential privilege escalation and maintain stronger control over administrative access.
Question 323
Why is identity inventory important for security operations?
- It helps identify accounts, owners, privileges, and relationships that require monitoring.
- It prevents every possible authentication failure.
- It removes the need for access reviews.
- It guarantees that all identities are trustworthy.
Correct Answer: 1
Explanation
A current identity inventory gives security teams visibility into the identities operating within an environment. This can include human users, administrators, service accounts, applications, and other machine identities. Knowing ownership, purpose, privileges, and associated resources makes suspicious activity easier to investigate. An inventory can also reveal orphaned accounts, excessive privileges, and identities that no longer have a valid business purpose. Because environments change continuously, inventories should be maintained through appropriate lifecycle processes. Identity inventory is not a guarantee of security, but it provides foundational information needed for monitoring, governance, investigation, and incident response.
Question 324
Which behavior may indicate possible credential misuse?
- Access from the user’s normal managed device
- A scheduled authentication event
- Repeated authentication attempts followed by access from an unusual location
- An approved application login
Correct Answer: 3
Explanation
Repeated authentication attempts followed by successful access from an unusual location can indicate possible credential misuse. Analysts should examine the authentication method, device information, timing, historical behavior, and resources accessed after authentication. Such activity may have legitimate explanations, including travel or approved remote work, so investigators should validate the context rather than automatically treating it as malicious. Correlating authentication events with endpoint and resource-access telemetry can provide stronger evidence. Monitoring authentication anomalies can help security teams identify potentially compromised credentials before an attacker progresses to privilege escalation, lateral movement, or access to sensitive resources.
Question 325
What is a key purpose of conducting periodic access reviews?
- To increase permissions for every identity
- To identify and remove unnecessary or outdated access
- To disable all user accounts
- To eliminate authentication requirements
Correct Answer: 2
Explanation
Periodic access reviews help organizations determine whether identities still require their assigned permissions. Employees may change roles, projects may end, and applications or resources may change over time. Without regular review, users and service identities can accumulate access that is no longer necessary. Reviewing permissions can identify excessive, outdated, or orphaned access and support least privilege. Reviews should consider business ownership, resource sensitivity, identity type, and current responsibilities. They should also produce an auditable record of decisions. Regular access governance reduces unnecessary exposure and helps organizations maintain better control over identity-related risk.
Question 326
Which type of telemetry is particularly useful when investigating suspicious authentication activity?
- Authentication events combined with device and resource-access information
- Printer configuration information only
- Desktop wallpaper changes
- Unrelated application preferences
Correct Answer: 1
Explanation
Authentication telemetry becomes more useful when combined with device and resource-access information. Authentication records can show when and how an identity accessed an environment, while device information can help determine whether the endpoint was known or managed. Resource-access records can show what happened after authentication. Together, these signals can help investigators identify unusual patterns and reconstruct an activity timeline. Security teams should also consider privilege changes, location, timing, and endpoint behavior when appropriate. No single telemetry source is always sufficient, so correlation across identity and security data can improve detection and investigation quality.
Question 327
What is one security concern associated with dormant accounts?
- They may provide unnecessary access that can be abused if compromised.
- They automatically improve identity security.
- They cannot authenticate under any circumstances.
- They remove the need for account lifecycle management.
Correct Answer: 1
Explanation
Dormant accounts may represent unnecessary access if they remain enabled after an identity no longer requires them. Attackers can potentially exploit forgotten or inactive accounts when appropriate credentials become available. Organizations should establish lifecycle processes that identify inactive accounts and determine whether they should be disabled or removed. Exceptions may exist for specific service or operational requirements, but those identities should have documented ownership and purpose. Monitoring account activity can also help identify unexpected use of dormant identities. Removing unnecessary accounts reduces the number of available authentication paths and supports better identity hygiene.
Question 328
Which control can help protect privileged identities from unauthorized access?
- Shared administrator passwords
- Unrestricted administrative sessions
- Strong authentication combined with privileged access controls
- Disabling administrative logging
Correct Answer: 3
Explanation
Privileged identities should receive stronger protection because they can perform high-impact actions. Strong authentication, privileged access controls, session monitoring, and least privilege can reduce the risk associated with administrative accounts. Organizations may also limit privileged sessions, require approval for sensitive actions, and maintain detailed audit records. Shared administrator credentials should generally be avoided because they reduce accountability and make investigations more difficult. Privileged access controls should be integrated with identity lifecycle processes so that access is granted only when needed and removed when no longer required. These controls provide multiple layers of protection around high-value identities.
Question 329
Why should service accounts have clearly defined ownership?
- Ownership helps establish accountability for the account’s purpose, permissions, and activity.
- Ownership prevents the account from authenticating.
- Ownership automatically grants administrative privileges.
- Ownership makes monitoring unnecessary.
Correct Answer: 1
Explanation
Service accounts can operate continuously and may have access to important applications or resources. Clearly defined ownership establishes accountability for their purpose, permissions, credentials, and lifecycle. Without ownership, unnecessary accounts may remain active, permissions may become excessive, and suspicious activity can be difficult to validate. Organizations should document the business purpose, responsible team, associated applications, and required access. Service-account activity should also be monitored for deviations from expected behavior. When an application or service is retired, its associated identity should be reviewed and disabled or removed as appropriate. Good ownership practices strengthen machine-identity governance.
Question 330
Which activity could represent possible lateral movement using a compromised identity?
- Accessing a resource normally used by the identity
- Accessing several previously unrelated systems shortly after an unusual authentication
- Completing a scheduled maintenance task
- Performing an approved application update
Correct Answer: 2
Explanation
Access to several previously unrelated systems shortly after an unusual authentication can be a potential indicator of lateral movement. Attackers may use compromised credentials to move from an initially accessed system to additional resources. Analysts should examine the identity involved, authentication sequence, devices, privileges, and resources accessed. Legitimate administrators or technical staff may also access multiple systems as part of normal duties, so context and authorization are important. Correlating identity and endpoint telemetry can help determine whether the activity fits expected behavior. Detecting unusual access patterns early can help security teams investigate before the compromise expands further.
Question 331
What is an important characteristic of effective identity detection rules?
- They should use relevant context to reduce unnecessary alerts.
- They should generate alerts for every normal login.
- They should ignore identity privileges.
- They should operate without any available telemetry.
Correct Answer: 1
Explanation
Effective identity detections should identify meaningful deviations or suspicious combinations of activity while minimizing unnecessary noise. Useful context can include identity type, privilege level, device status, location, authentication method, resource sensitivity, and historical behavior. For example, an administrative identity accessing an unusual sensitive resource may warrant more attention than a normal user accessing a routine application. Detection logic should be tested and refined because environments change and legitimate activity can evolve. Well-designed detections help analysts focus on higher-value events while maintaining sufficient visibility for emerging identity-based attack techniques.
Question 332
Which action can help reduce the risk from excessive application permissions?
- Granting all applications administrator access
- Periodically reviewing permissions against documented application requirements
- Disabling application logging
- Sharing application credentials between teams
Correct Answer: 2
Explanation
Application permissions should correspond to the application’s legitimate functions. Periodic reviews can identify permissions that are no longer necessary because applications evolve, integrations change, and business requirements are updated. Security teams should work with application owners to determine which resources and actions are actually required. Unnecessary permissions can then be removed while maintaining application functionality. Monitoring application identity activity provides another layer of protection by helping detect unexpected resource access. Applying least privilege to applications reduces the potential impact of stolen tokens, credentials, or compromised workloads and strengthens the overall identity security posture.
Question 333
What should analysts examine when an identity suddenly accesses a highly sensitive resource?
- Only the user’s display name
- Only the resource’s file size
- Authentication context, privileges, device, timing, and business justification
- Only the user’s email signature
Correct Answer: 3
Explanation
Unexpected access to a highly sensitive resource should be investigated using multiple contextual signals. Analysts can examine the identity’s privileges, authentication method, device, location, timing, previous behavior, and business justification. It is also useful to determine whether the access followed another suspicious event, such as a new login or privilege change. A single unusual access does not automatically establish malicious activity because legitimate business requirements can change. Contextual analysis helps investigators distinguish authorized activity from potential misuse. Combining identity telemetry with endpoint and resource-access information can produce a more complete picture of the event.
Question 334
What is the benefit of terminating active sessions after confirmed identity compromise?
- It can help prevent continued use of existing authenticated sessions.
- It permanently fixes every security weakness.
- It guarantees that the attacker never had access.
- It removes the need for credential remediation.
Correct Answer: 1
Explanation
Terminating active sessions can help contain a compromised identity by invalidating existing authenticated access where the technology supports session revocation. This can reduce an attacker’s ability to continue using sessions that were established before the compromise was identified. Session termination should normally be combined with other remediation steps, such as credential resets, access reviews, investigation, and removal of unauthorized persistence. Security teams should also examine how the compromise occurred and whether other identities or systems may have been affected. Session revocation is therefore an important containment measure, but it should not be treated as a complete remediation by itself.
Question 335
Which practice improves accountability for privileged actions?
- Using shared administrator credentials
- Maintaining individual identities with appropriate auditing
- Disabling security logs
- Allowing anonymous administrative access
Correct Answer: 2
Explanation
Individual privileged identities improve accountability because administrative actions can be associated with specific users or authorized processes. Appropriate auditing can record authentication, privilege changes, resource access, and administrative actions for later investigation. Shared credentials make it more difficult to determine who performed a particular action and can weaken incident-response efforts. Organizations should combine individual identities with strong authentication, least privilege, privileged access controls, and appropriate monitoring. Administrative activity should also be reviewed according to risk and organizational requirements. These practices make it easier to detect unusual behavior and establish an accurate timeline during investigations.
Question 336
Which identity should generally be included in security monitoring?
- Only executives
- Only external users
- Human users, privileged identities, service accounts, and application identities
- Only accounts that have recently failed authentication
Correct Answer: 3
Explanation
Identity monitoring should cover the different types of identities that can access organizational resources. Human users, privileged administrators, service accounts, application identities, and other machine identities can all become targets or be misused. Limiting monitoring to a single category creates visibility gaps that attackers may exploit. Monitoring should be tailored to identity type because expected behavior differs between humans and automated workloads. Security teams should establish appropriate baselines and detections for each category while maintaining sufficient contextual information. Comprehensive identity visibility supports earlier detection and helps investigators understand how identities interact with systems and resources.
Question 337
What is the purpose of an identity risk score or risk indicator?
- To provide context that can help prioritize investigation and response
- To automatically prove that an identity is malicious
- To replace all security telemetry
- To permanently disable high-risk identities
Correct Answer: 1
Explanation
Identity risk indicators can help security teams prioritize events and investigations by combining relevant signals associated with an identity. These signals may include unusual authentication behavior, suspicious access patterns, privilege changes, or other risk indicators. A risk score should be treated as contextual information rather than automatic proof of malicious activity. Analysts should review supporting evidence and business context before taking significant action. Risk-based prioritization can help security teams focus attention on events with potentially greater significance, especially in environments containing large numbers of identities and authentication events.
Question 338
Which situation may warrant immediate review of a service account?
- It performs its documented scheduled function.
- It accesses a resource outside its normal application scope.
- It authenticates during an expected job window.
- Its owner completes a routine access review.
Correct Answer: 2
Explanation
A service account accessing resources outside its normal application scope can indicate configuration problems, excessive permissions, or possible compromise. Analysts should compare the activity with documented application behavior and investigate the resource being accessed. They should also review authentication details, source devices, associated processes, and recent configuration changes. Legitimate application updates can sometimes change access requirements, so business and technical context should be validated. Service accounts often operate automatically, making deviations from established behavior particularly useful for detection. Continuous monitoring and clearly documented ownership can improve the ability to identify and investigate such anomalies.
Question 339
Why should identity-related incident investigations include timeline reconstruction?
- It helps determine the sequence and relationship of authentication and subsequent actions.
- It removes the need to preserve evidence.
- It automatically identifies the attacker.
- It guarantees complete attribution.
Correct Answer: 1
Explanation
Timeline reconstruction helps investigators understand how an identity-related incident developed. By arranging authentication events, privilege changes, endpoint activity, resource access, and other relevant events chronologically, analysts can identify relationships between actions. A timeline can help determine the initial access point, subsequent activity, possible persistence, and scope of the incident. It does not automatically identify an attacker or provide perfect attribution. Investigators should validate timestamps and account for differences between data sources. Preserving relevant logs and telemetry is therefore essential. A well-constructed timeline provides a structured foundation for containment, remediation, and lessons learned.
Question 340
Which approach best supports continuous improvement of identity security detections?
- Never changing detection rules
- Disabling alerts that generate investigations
- Reviewing detection outcomes and refining rules based on validated findings
- Removing identity telemetry after each incident
Correct Answer: 3
Explanation
Identity detections should evolve as organizations learn from investigations, changes in infrastructure, and new attack behaviors. Reviewing detection outcomes helps security teams identify false positives, missed activity, unnecessary alert volume, and opportunities for improved correlation. Rules can then be refined using validated investigation findings and current environmental context. Changes should be tested carefully so that improvements do not unintentionally reduce important visibility. Detection engineering should also incorporate feedback from incident responders and threat hunters. Continuous refinement helps maintain useful identity monitoring as users, applications, devices, and authentication patterns change over time.