View Full CrowdStrike CCIS Exam Dumps and Practice Test Dumps.
Question 161
Which approach can help identify potentially compromised identities?
- Disabling identity monitoring
- Granting unrestricted access
- Reviewing unusual identity and authentication activity
- Sharing administrative credentials
Correct Answer: 3
Explanation
Reviewing unusual identity and authentication activity can help security teams identify potentially compromised identities. Analysts can examine authentication patterns, access behavior, identity risk, related detections, and other contextual information to determine whether activity requires further investigation. An unusual event alone does not confirm compromise because legitimate operational circumstances can also create unexpected behavior. CCIS candidates should understand the importance of combining multiple signals during identity investigations. Identity-focused monitoring can provide useful visibility into user and programmatic identity activity. Security teams should evaluate evidence carefully and follow established procedures when deciding whether an identity requires containment, credential remediation, additional monitoring, or other security actions.
Question 162
What is a primary security benefit of restricting administrative privileges?
- It reduces the potential impact of a compromised privileged identity
- It eliminates all authentication requirements
- It guarantees that credentials cannot be stolen
- It prevents every identity-related attack
Correct Answer: 1
Explanation
Restricting administrative privileges helps reduce the potential impact of a compromised identity. If an account has unnecessary administrative access, an attacker controlling that account may be able to make significant changes or access sensitive resources. Applying least privilege limits permissions to what is required for legitimate responsibilities. CCIS candidates should understand that privilege restriction should be supported by strong authentication, monitoring, access reviews, and appropriate identity policies. Organizations should periodically review privileged identities to ensure that administrative access remains necessary. Reducing unnecessary privileges does not eliminate all threats, but it can limit the scope of actions available to an attacker after an identity compromise.
Question 163
Which information can help determine whether an authentication event is unusual?
- Office furniture inventory
- Historical authentication patterns
- Printer maintenance records
- Employee parking information
Correct Answer: 2
Explanation
Historical authentication patterns provide useful context when determining whether a current authentication event is unusual. Analysts can compare current activity with established patterns involving timing, source information, authentication methods, and other relevant characteristics. A deviation may indicate a need for additional investigation, although it does not automatically prove malicious activity. Legitimate circumstances such as travel, role changes, or administrative work can affect normal behavior. CCIS candidates should understand how historical identity information supports investigations and threat hunting. Combining behavioral history with identity risk, detections, and other security telemetry allows analysts to make better-informed assessments of potentially suspicious authentication activity.
Question 164
What should organizations do to maintain appropriate identity permissions?
- Grant permanent administrator access
- Share credentials among teams
- Disable authorization controls
- Perform regular access reviews
Correct Answer: 4
Explanation
Regular access reviews help organizations ensure that identity permissions remain appropriate for current responsibilities. Employees can change roles, applications can change requirements, and accounts may no longer need permissions that were previously granted. Reviewing access helps identify unnecessary privileges and supports least-privilege principles. CCIS candidates should understand that access reviews should include appropriate attention to privileged identities and programmatic accounts. These reviews work best when combined with identity monitoring, strong authentication, and risk assessment. Organizations should establish processes for removing unnecessary access while preserving legitimate business functionality. Regular reviews help reduce identity exposure and improve overall access governance.
Question 165
Which authentication method provides an additional verification factor beyond a password?
- Multi-factor authentication
- File encryption
- Network segmentation
- Data compression
Correct Answer: 1
Explanation
Multi-factor authentication requires users to provide an additional verification factor beyond a password or another single factor. This provides an additional security layer if a password is stolen or exposed. Depending on the implementation, the additional factor may involve something the user possesses, something they know, or another approved verification mechanism. CCIS candidates should understand that MFA is an important identity protection control but should be combined with monitoring, least privilege, and risk-based security practices. Security teams should also monitor authentication activity for suspicious behavior. Strong authentication reduces the usefulness of stolen passwords but does not eliminate every possible identity attack.
Question 166
What is the purpose of identity threat hunting?
- To manage employee compensation
- To search proactively for suspicious identity activity
- To replace all authentication controls
- To disable security detections
Correct Answer: 2
Explanation
Identity threat hunting allows security analysts to proactively search identity-related telemetry for suspicious activity. Instead of relying exclusively on automated detections, analysts can develop hypotheses and investigate patterns involving authentication, access, identities, and related security events. Hunting can reveal activity that has not generated a clear automated alert. CCIS candidates should understand that threat hunting complements detection and response capabilities. Effective hunting requires knowledge of expected identity behavior, available telemetry, and relevant attack techniques. Analysts should document findings and use them to support appropriate investigation and response. Threat hunting can also provide information that helps improve future detections and identity security controls.
Question 167
Why is identity classification important during security investigations?
- It eliminates the need for security monitoring
- It guarantees that an identity is trusted
- It provides context about expected identity behavior
- It automatically blocks suspicious activity
Correct Answer: 3
Explanation
Identity classification provides context about how an identity is expected to behave. Human users and programmatic identities may have very different authentication and access patterns. A behavior that is normal for a user may be unusual for a service account, and understanding the identity type helps analysts interpret events correctly. CCIS candidates should understand why accurate classification is valuable for detection, threat hunting, risk assessment, and investigation. Identity classification does not automatically determine whether an activity is malicious. Analysts should combine identity type with authentication data, historical behavior, detections, and other relevant evidence to determine whether additional investigation is warranted.
Question 168
Which activity can help detect excessive identity privileges?
- Reviewing permissions against actual job or service requirements
- Disabling all access reviews
- Sharing administrator credentials
- Giving every account full access
Correct Answer: 1
Explanation
Reviewing permissions against actual job or service requirements can help identify excessive identity privileges. Organizations should determine whether each identity still needs its assigned permissions and remove access that is no longer justified. This supports the principle of least privilege and reduces unnecessary exposure. CCIS candidates should understand that permissions should be reviewed as organizational roles, applications, and services change. Privileged identities deserve particular attention because excessive administrative access can increase the potential impact of compromise. Identity monitoring and risk information can provide additional context when reviewing access. Regular permission reviews should form part of a broader identity governance and security program.
Question 169
What can risk information help security analysts do?
- Remove the need for authentication
- Grant unrestricted access
- Identify identities that may require additional investigation
- Disable identity detections
Correct Answer: 3
Explanation
Identity risk information can help analysts identify identities that may require additional investigation or security attention. Risk indicators can provide useful prioritization when security teams are handling many identity-related events. However, risk information should not be treated as definitive proof of malicious behavior. Analysts should review authentication activity, behavioral context, detections, and other available evidence before deciding on an appropriate response. CCIS candidates should understand how risk assessment fits into identity security operations. Risk-based prioritization can help teams focus resources more efficiently while maintaining appropriate investigation procedures and avoiding unnecessary disruption to legitimate users and services.
Question 170
What is an important consideration before enabling automated identity response actions?
- Whether the action could affect legitimate users or systems
- Whether the office has enough printers
- Whether users have identical workstations
- Whether the organization uses paper records
Correct Answer: 1
Explanation
Before enabling automated identity response actions, organizations should consider their potential effect on legitimate users and systems. Automation can accelerate response, but an overly broad condition or inappropriate action could unnecessarily restrict access or disrupt business operations. Security teams should define clear conditions, permissions, response actions, and exception handling. Testing and monitoring can help identify unexpected results. CCIS candidates should understand that automation should be designed carefully and reviewed regularly. Automated workflows should complement investigation and security procedures rather than operate without oversight. Properly designed automation can improve response efficiency while reducing the risk of unnecessary operational impact.
Question 171
Which security principle requires access decisions to consider current context rather than permanent trust?
- Open access
- Zero Trust
- Shared administration
- Perimeter-only security
Correct Answer: 2
Explanation
Zero Trust requires organizations to avoid assuming that an identity remains trusted simply because it previously authenticated successfully. Access decisions can consider identity, authentication, device, resource, risk, and other available security context. This approach supports continuous evaluation and can reduce the potential impact of compromised credentials. CCIS candidates should understand that Zero Trust is closely connected to least privilege and strong authentication. Identity security visibility can help organizations evaluate identity activity and identify changes that may require additional attention. Implementing Zero Trust requires appropriate policies, monitoring, authentication controls, and access management rather than relying on a single security technology.
Question 172
Which type of identity is generally associated with a person accessing organizational resources?
- Programmatic identity
- Service identity
- Human identity
- Application identity
Correct Answer: 3
Explanation
A human identity generally represents an individual person accessing organizational resources. Human identities can authenticate interactively and may access applications, systems, or data according to their roles. Their expected behavior may differ from programmatic or service identities, which commonly perform automated functions. CCIS candidates should understand the distinction between these identity types because classification provides important investigation context. Security teams should apply appropriate authentication, authorization, monitoring, and access controls to human identities. Human accounts can still be compromised or misused, so they should not be considered inherently trustworthy. Identity monitoring and risk assessment can help identify potentially suspicious activity associated with user accounts.
Question 173
What can endpoint context add to an identity investigation?
- Information about the system associated with identity activity
- Employee salary information
- Office seating arrangements
- Printer supply levels
Correct Answer: 1
Explanation
Endpoint context can provide information about the system associated with identity activity. When an analyst knows both which identity performed an action and which endpoint was involved, the investigation can gain additional context. Endpoint information may help establish timelines, identify related activity, and determine whether the identity event is connected to other security signals. CCIS candidates should understand the value of correlating identity and endpoint telemetry during investigations. Correlation does not automatically prove malicious activity, so analysts should continue evaluating the evidence. Combining identity, endpoint, authentication, and risk information can help security teams develop a more complete understanding of potential incidents.
Question 174
What should be done when an identity security policy no longer matches organizational requirements?
- Leave it unchanged indefinitely
- Disable all identity controls
- Review and update the policy appropriately
- Grant unrestricted permissions
Correct Answer: 3
Explanation
When an identity security policy no longer matches organizational requirements, it should be reviewed and updated appropriately. Changes in users, applications, infrastructure, authentication services, and business processes can make existing policies outdated. Security teams should evaluate the impact of proposed changes and use appropriate testing and change-management procedures. CCIS candidates should understand that identity policy management is an ongoing process. Policies should maintain appropriate security controls while supporting legitimate business operations. Regular reviews can help identify outdated permissions, authentication requirements, and response workflows. Maintaining current policies contributes to a stronger identity security posture and helps organizations adapt to changing security risks.
Question 175
Which activity can help identify suspicious use of a privileged identity?
- Comparing privileged activity with expected administrative behavior
- Disabling administrator monitoring
- Sharing privileged credentials
- Granting every user administrative rights
Correct Answer: 1
Explanation
Comparing privileged activity with expected administrative behavior can help identify suspicious use of a privileged identity. Administrators may legitimately perform sensitive actions, so analysts need context to determine whether an event is expected. Useful information can include authentication details, historical behavior, timing, systems accessed, and related detections. CCIS candidates should understand that privileged identity monitoring is important because these accounts can have broad access. Security teams should combine monitoring with strong authentication, least privilege, and periodic access reviews. An unusual administrative action should be investigated using available evidence rather than automatically being treated as malicious or legitimate.
Question 176
What is one purpose of maintaining identity-related telemetry?
- To support detection and investigation
- To eliminate all authentication
- To provide unrestricted access
- To replace security policies
Correct Answer: 1
Explanation
Maintaining identity-related telemetry provides security teams with information that can support detection, investigation, and threat hunting. Authentication events, identity activity, risk signals, and related information can help analysts understand what occurred and establish relationships between events. Without appropriate telemetry, investigators may have limited visibility into identity-based activity. CCIS candidates should understand the importance of collecting and retaining relevant security information according to organizational requirements. Telemetry should be monitored for quality and availability because missing or incomplete data can affect investigations. Identity telemetry works most effectively when it can be correlated with other security information and analyzed in appropriate context.
Question 177
Which practice can help reduce risk from dormant identities?
- Granting them additional privileges
- Regularly reviewing and managing inactive accounts
- Sharing their credentials
- Disabling all account monitoring
Correct Answer: 2
Explanation
Regularly reviewing and managing inactive accounts can reduce risk associated with dormant identities. Accounts that are no longer required may still retain permissions or credentials that could be misused if compromised. Organizations should establish processes for identifying inactive identities and determining whether they should be disabled, removed, or retained for a documented business reason. CCIS candidates should understand that identity lifecycle management is an important part of identity security. Dormant accounts should not be ignored simply because they are not actively used. Combining account reviews with least privilege, monitoring, and appropriate authentication controls can help reduce unnecessary identity exposure.
Question 178
Which factor can help determine whether a detected identity event requires escalation?
- The event’s security context and associated evidence
- The user’s preferred computer brand
- The size of the office
- The number of printers available
Correct Answer: 1
Explanation
The security context and associated evidence can help analysts determine whether an identity event requires escalation. Analysts may consider identity risk, authentication history, related detections, endpoint information, behavioral deviations, and the potential impact of the activity. A single signal may not be enough to justify escalation, so investigators should evaluate the broader context. CCIS candidates should understand that escalation decisions should follow established organizational procedures and incident response criteria. Evidence-based analysis helps security teams distinguish routine activity from events that may require additional investigation or containment. Proper documentation can also support communication between analysts and incident response teams.
Question 179
What is a key advantage of combining identity monitoring with threat hunting?
- It provides both ongoing visibility and proactive investigation
- It removes the need for authentication
- It guarantees that all threats will be discovered
- It eliminates access management
Correct Answer: 1
Explanation
Combining identity monitoring with threat hunting provides both ongoing visibility and proactive investigation capabilities. Monitoring can identify relevant identity events as they occur, while threat hunting allows analysts to search for suspicious patterns that may not have generated automated detections. Together, these approaches provide complementary methods for identifying potential identity threats. CCIS candidates should understand that neither method guarantees detection of every threat. Effective identity security also requires strong authentication, least privilege, risk assessment, appropriate policies, and response processes. Using multiple complementary controls can help security teams improve visibility and investigate identity activity more effectively across users, services, and applications.
Question 180
Which combination best supports a mature identity security program?
- Unrestricted access and shared credentials
- Strong authentication, least privilege, monitoring, risk assessment, and investigation
- Password-only access without monitoring
- Permanent trust for authenticated identities
Correct Answer: 2
Explanation
A mature identity security program combines several complementary security practices. Strong authentication protects access, least privilege limits unnecessary permissions, monitoring provides visibility, risk assessment helps prioritize potential concerns, and investigation provides context for suspicious activity. These capabilities can work together with Zero Trust principles and appropriate response procedures. CCIS candidates should understand that identity security is an ongoing process rather than a single deployment task. Organizations should regularly review identities, permissions, authentication policies, integrations, detections, and response workflows. A layered approach helps security teams manage changing identity environments and respond appropriately when suspicious behavior or potential compromise is identified.