View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.
Question 361
What is the main purpose of implementing just-in-time access for privileged identities?
- To provide permanent administrative access
- To eliminate identity monitoring
- To provide elevated privileges only when they are needed
- To allow shared administrator credentials
Correct Answer: 3
Explanation
Just-in-time access reduces the period during which an identity has elevated privileges. Instead of maintaining permanent administrative permissions, an authorized user receives the required access for a defined period or specific task. This can reduce the opportunity for attackers to abuse privileged credentials if an account is compromised. Organizations can combine just-in-time access with approval workflows, strong authentication, logging, and session monitoring. The approach should also account for legitimate operational requirements and emergency procedures. Limiting privileged access to appropriate time windows supports least privilege and can reduce the exposure associated with continuously active administrative permissions.
Question 362
Which activity is most useful for identifying an orphaned identity?
- Reviewing accounts that have no active owner or valid business purpose
- Increasing permissions for inactive accounts
- Disabling all security alerts
- Creating duplicate administrator accounts
Correct Answer: 1
Explanation
An orphaned identity is generally an account that lacks a valid owner, business purpose, or responsible administrator. Organizations can identify such accounts by comparing identity inventories with employment records, application ownership information, service-account documentation, and access reviews. Accounts that remain active without clear ownership may create unnecessary security exposure. After identification, the organization should determine whether the account has dependencies or legitimate requirements before disabling or removing it. Establishing clear ownership during account creation and maintaining lifecycle processes can reduce the number of orphaned identities. Regular reviews are particularly important in large or frequently changing environments.
Question 363
Why should identity alerts include information about the affected resource?
- Resource context can help determine the potential sensitivity and impact of the activity.
- Resource information prevents all false positives.
- Resource information replaces authentication telemetry.
- Resource context is irrelevant to investigations.
Correct Answer: 1
Explanation
Knowing which resource was accessed provides important context when evaluating an identity-related alert. Access to a highly sensitive database or administrative system may require more urgent investigation than access to a routine application. Analysts can combine resource sensitivity with identity privileges, authentication method, device information, timing, and previous behavior. This context helps prioritize investigations and determine potential impact. Resource information does not prove that an event is malicious, but it can help security teams understand why an event matters. Effective identity detection therefore benefits from correlating identity activity with information about the systems and resources involved.
Question 364
What is a potential benefit of enforcing separation of duties?
- It gives every employee administrative privileges.
- It can reduce the risk that one identity can independently perform conflicting high-impact actions.
- It eliminates the need for authentication.
- It prevents all insider threats.
Correct Answer: 2
Explanation
Separation of duties divides sensitive responsibilities among multiple identities or roles so that one person or account cannot independently complete certain conflicting actions. This can reduce opportunities for unauthorized changes, fraud, or misuse of privileged access. For example, an organization may separate the ability to request a sensitive change from the ability to approve or implement it. Separation of duties should be designed around business processes and risk rather than applied identically everywhere. It does not eliminate insider threats or guarantee that unauthorized activity cannot occur. However, when combined with auditing, least privilege, and approval controls, it can strengthen identity governance.
Question 365
Which identity characteristic should be considered when determining whether an authentication event is unusual?
- The identity’s normal authentication behavior
- The user’s preferred screen brightness
- The computer’s wallpaper
- The monitor manufacturer
Correct Answer: 1
Explanation
An identity’s normal authentication behavior provides useful context for identifying unusual events. Analysts can consider common devices, locations, authentication methods, times, and applications associated with the identity. A sudden deviation may warrant investigation, especially when multiple unusual characteristics occur together. However, behavioral baselines can change because users travel, change roles, or adopt new devices. Security teams should therefore validate unusual activity against current business context rather than treating a baseline deviation as automatic proof of compromise. Historical authentication data can support this analysis and help investigators distinguish legitimate changes from potentially suspicious identity behavior.
Question 366
What is an important security requirement for API identities?
- They should receive unlimited permissions.
- Their credentials or tokens should be protected and appropriately scoped.
- Their activity should never be logged.
- They should always use shared credentials.
Correct Answer: 2
Explanation
API identities can provide applications or automated processes with access to organizational resources. Their credentials, tokens, or keys should therefore be protected from unauthorized disclosure and limited to the permissions required for their intended functions. Appropriate expiration or rotation mechanisms can further reduce exposure. Organizations should also monitor API identity activity for unexpected authentication or resource access. Shared credentials make accountability more difficult and can increase exposure when credentials are compromised. Properly scoped and managed API identities support application functionality while reducing unnecessary privileges and helping security teams detect potentially unauthorized programmatic activity.
Question 367
Which event may indicate possible abuse of a compromised privileged account?
- A normal approved administrative task
- A scheduled system update
- Administrative changes performed from an unexpected device
- A documented maintenance activity
Correct Answer: 3
Explanation
Administrative activity from an unexpected device can be an indicator of possible privileged-account abuse, particularly when the device is not normally associated with the administrator. Analysts should examine authentication details, device status, timing, location, commands or changes performed, and whether the activity was authorized. Legitimate emergency work or temporary administrative arrangements can produce unusual behavior, so investigators should validate the business context. Correlating endpoint, identity, and administrative telemetry can help determine whether the event represents misuse. Privileged identities warrant close monitoring because unauthorized administrative activity can potentially affect many systems and security controls.
Question 368
What should happen when an employee changes roles and no longer requires previous permissions?
- Previous permissions should be reviewed and removed when no longer necessary.
- All previous permissions should remain permanently.
- The employee should receive every available privilege.
- Authentication should be disabled permanently.
Correct Answer: 1
Explanation
Role changes should trigger an access review so that permissions reflect the employee’s new responsibilities. Retaining old access can create privilege accumulation, where an identity gradually obtains more permissions than required. Organizations should compare current responsibilities with assigned access and remove permissions that no longer have a valid business justification. Automated identity lifecycle processes can help apply role changes consistently, while periodic access reviews provide additional validation. Sensitive and privileged permissions deserve particular attention. This process supports least privilege and reduces the potential impact if an identity is later compromised or misused.
Question 369
Why is token theft a concern for identity security?
- Stolen tokens may allow an attacker to use an already authenticated identity or session.
- Tokens can never provide access to resources.
- Token theft only affects physical security.
- Token theft automatically disables the associated account.
Correct Answer: 1
Explanation
Authentication tokens can represent an already authenticated identity or session. If an attacker obtains a valid token, they may potentially use it to access resources without directly possessing the original password. Security teams should therefore monitor unusual token usage, authentication patterns, device context, and resource access. Appropriate token lifetimes, secure storage, strong authentication, and session controls can reduce exposure. When token compromise is suspected, organizations may need to revoke sessions or tokens and investigate related activity. Token security is an important part of identity protection because credential security extends beyond traditional passwords.
Question 370
Which practice helps reduce unnecessary exposure of identity data?
- Giving all employees unrestricted access to identity logs
- Applying appropriate access controls to identity and security telemetry
- Publishing authentication records publicly
- Sharing sensitive identity information through unsecured channels
Correct Answer: 2
Explanation
Identity and security telemetry can contain sensitive information about users, devices, authentication activity, and resource access. Appropriate access controls should therefore limit this information to authorized personnel who require it for legitimate security or operational purposes. Organizations should apply suitable permissions, auditing, retention practices, and handling procedures. Restricting access to sensitive telemetry does not mean eliminating security visibility; instead, it ensures that visibility is provided responsibly. Security teams should also consider data protection requirements when collecting and storing identity information. Proper governance helps reduce the risk of secondary misuse while preserving information needed for detection and investigation.
Question 371
What is the purpose of monitoring changes to authentication methods?
- To identify potentially unauthorized modifications that could affect account security
- To eliminate all authentication methods
- To grant every user administrative access
- To prevent legitimate users from changing devices
Correct Answer: 1
Explanation
Changes to authentication methods can affect how an identity gains access to protected resources. An unexpected addition or modification of an authentication method may indicate account takeover, persistence activity, or unauthorized configuration changes. Analysts should determine who made the change, whether it was approved, when it occurred, and what activity followed it. Examples may include unexpected changes to registered authentication factors or other account-access mechanisms. Monitoring these changes provides another layer of identity visibility. Legitimate users may also modify authentication methods, so investigators should validate the event against known requests and organizational processes before taking action.
Question 372
Which approach can help identify excessive permissions across a large identity population?
- Comparing assigned permissions with role and business requirements
- Granting identical privileges to everyone
- Disabling access reviews
- Removing all identity records
Correct Answer: 1
Explanation
Comparing assigned permissions with role and business requirements can help identify excessive access across a large identity population. Organizations can use role-based access models, entitlement reviews, ownership information, and automated analysis to determine whether permissions remain necessary. Particular attention should be given to privileged access and sensitive resources. Removing unnecessary permissions supports least privilege and reduces potential impact if an identity is compromised. Access analysis should be repeated because organizational roles and applications change over time. Effective governance balances security with legitimate business requirements, ensuring that users and applications retain the access necessary to perform authorized functions.
Question 373
Which signal can increase the significance of an unusual authentication event?
- The identity immediately performs sensitive administrative actions afterward.
- The identity logs out normally.
- The identity accesses a routine application as expected.
- The identity performs an approved task.
Correct Answer: 1
Explanation
An unusual authentication event becomes more significant when it is followed by sensitive administrative actions. The combination may indicate that an attacker successfully authenticated and then attempted to use the identity’s privileges. Analysts should investigate the source device, authentication method, timing, privilege level, administrative actions, and affected resources. Legitimate administrators may also perform sensitive actions, so authorization and business context remain important. Correlating authentication telemetry with administrative activity can help security teams determine whether the sequence represents normal work or potential compromise. Multi-signal detection generally provides stronger evidence than relying on an isolated login anomaly.
Question 374
What is an important reason to monitor inactive privileged accounts?
- They may retain powerful access despite limited legitimate use.
- They automatically protect the organization.
- They cannot be targeted by attackers.
- They require no lifecycle management.
Correct Answer: 1
Explanation
Inactive privileged accounts can retain powerful permissions even when they are rarely used. Such accounts may become attractive targets because attackers can potentially exploit them without immediately attracting attention. Organizations should regularly review privileged accounts and determine whether inactive access remains necessary. Accounts that are no longer required should be disabled or removed according to lifecycle procedures. If an account must remain available for a specific operational reason, appropriate ownership, monitoring, and controls should be maintained. Reducing unnecessary privileged identities helps minimize the number of high-impact access paths available within an environment.
Question 375
Which practice improves detection of unusual programmatic identity behavior?
- Establishing expected activity patterns for applications and service accounts
- Disabling logs for automated processes
- Giving service accounts unrestricted access
- Treating all automated activity as malicious
Correct Answer: 1
Explanation
Programmatic identities often perform predictable operations, making behavioral expectations useful for detection. Organizations can document which applications, resources, devices, and time periods are normally associated with service accounts or workloads. Deviations from these patterns can then be investigated. For example, an identity normally limited to one application might warrant review if it suddenly accesses unrelated systems. However, application changes and maintenance can legitimately alter behavior, so alerts require contextual validation. Monitoring programmatic identities alongside application and endpoint telemetry can improve visibility into machine-driven activity and help identify potentially compromised credentials or workloads.
Question 376
Why should identity-related detections be tested after major environment changes?
- Changes can alter normal behavior and may affect detection accuracy.
- Detection rules never depend on environmental context.
- Testing automatically disables security controls.
- Environment changes have no relationship to identity activity.
Correct Answer: 1
Explanation
Changes such as new applications, authentication systems, cloud services, network architectures, or organizational roles can alter normal identity behavior. Detection rules based on previous assumptions may therefore produce excessive alerts or miss important activity. Security teams should test detections after significant changes and confirm that required telemetry remains available. Baselines may also need to be updated to reflect legitimate new behavior. Continuous validation helps ensure that detection logic remains useful and relevant. Testing should preserve security coverage while reducing unnecessary noise. This process supports more reliable identity monitoring as the environment evolves.
Question 377
Which response is appropriate when an identity is confirmed to have excessive permissions but no compromise is detected?
- Review and reduce the permissions according to least-privilege requirements.
- Increase the identity’s privileges.
- Disable all identity monitoring.
- Share the identity with another user.
Correct Answer: 1
Explanation
Excessive permissions should be corrected even when there is no evidence of compromise. Least privilege requires identities to have only the access necessary for legitimate responsibilities. Security or identity teams should validate the required permissions with the appropriate business owner and remove unnecessary access. The change should be documented and, where appropriate, included in future access reviews. Reducing permissions lowers potential impact if the identity is compromised later. Organizations should also investigate why excessive access existed and determine whether lifecycle or provisioning processes need improvement. Proactive access governance can address weaknesses before they become security incidents.
Question 378
What is the value of retaining identity event history during an investigation?
- It can help establish a timeline and identify changes or patterns preceding an incident.
- It prevents all future compromises.
- It makes endpoint telemetry unnecessary.
- It guarantees attacker attribution.
Correct Answer: 1
Explanation
Historical identity events can help investigators understand what happened before, during, and after a suspected incident. Authentication records, privilege changes, resource access, and other identity events can establish a timeline and reveal patterns that may not be visible from a single event. Historical information can also help identify when an identity’s behavior changed and whether similar activity occurred previously. Retention requirements should be aligned with organizational policies and applicable obligations. Preserving useful telemetry supports incident investigation, threat hunting, and detection improvement. It does not guarantee attribution, but it provides important evidence for understanding identity-related activity.
Question 379
Which condition can increase the risk associated with a service account?
- The account has broad privileges unrelated to its documented purpose.
- The account has narrowly scoped permissions.
- The account has a documented owner.
- The account’s activity is monitored.
Correct Answer: 1
Explanation
A service account with broad permissions unrelated to its documented purpose presents increased risk because compromise could provide access beyond what the application actually requires. Organizations should review service-account privileges against technical and business requirements and remove unnecessary permissions. Ownership, monitoring, credential protection, and lifecycle controls should also be established. Service accounts should ideally be limited to the resources and actions required for their functions. Narrowly scoped permissions reduce potential impact if credentials or tokens are compromised. Regular reviews are important because application architectures and requirements change over time.
Question 380
What is a key objective of identity threat hunting?
- To proactively search for suspicious identity activity that may not have generated an alert
- To disable all user accounts
- To replace incident response completely
- To eliminate authentication requirements
Correct Answer: 2
Explanation
Identity threat hunting involves proactively examining identity-related telemetry for suspicious patterns that may not have triggered existing detections. Hunters can investigate unusual authentication behavior, privilege changes, abnormal resource access, service-account activity, and other signals associated with identity-based attacks. Hunting can reveal gaps in detection logic and help security teams develop new rules based on validated findings. It complements automated detection and incident response rather than replacing them. Effective hunting requires relevant telemetry, knowledge of normal identity behavior, and a structured approach to hypothesis development and investigation. Findings can contribute to improved identity controls and monitoring.