Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

IDP CrowdStrike Certified Identity Specialist(CCIS) Exam Questions and Answers

Questions 4

An account without a phone number, operating system, or role of CEO would typically be defined as:

Options:

A.

Programmatic

B.

Human

C.

Enterprise

D.

Corporate

Buy Now
Questions 5

What is the recommended action for the "Guest Account Enabled" risk?

Options:

A.

Add related endpoints to a watchlist

B.

Apply a policy rule with an "Access" trigger and "Block" action on the Guest account

C.

Disable Guest accounts on all endpoints

D.

Disable the endpoint in Active Directory

Buy Now
Questions 6

What is the purpose behind creating Policy Rules?

Options:

A.

Policy Rules determine what actions to take in response to certain triggers/conditions observed within the environment

B.

Policy Rules determine what actions an admin in the console can take before making adjustments

C.

Policy Rules determine the scope in which the sensor collects information on the environment

D.

Policy Rules determine how the console tracks and learns behavior for users in the environment

Buy Now
Questions 7

What basic configuration fields are typically required for cloud Multi-Factor Authentication (MFA) connectors?

Options:

A.

Service account user name and password

B.

Domain controller host name and IP address

C.

Domain Administrator user name and password

D.

Connector application identifier and secret keys

Buy Now
Questions 8

Any countries or regions included in the _ will trigger a geolocation detection.

Options:

A.

Blocklist

B.

Allowlist

C.

Dictionary

D.

Exclusion

Buy Now
Questions 9

How should a user be classified if one requires observation for potential risk to the business?

Options:

A.

Honeytoken Account

B.

High Risk

C.

Watched User

D.

Marked User

Buy Now
Questions 10

Which menu option is NOT included in Falcon Identity Threat Detection (ITD)?

Options:

A.

Event Analysis

B.

Settings

C.

Privileged Identities

D.

Policy Rules

Buy Now
Questions 11

How does CrowdStrike Falcon Identity Protection help customers identify different types of accounts in their domain?

Options:

A.

Implements advanced encryption algorithms for account metadata

B.

Assigns a human authorizer to each programmatic account for approval

C.

Analyzes authentication traffic and automatically classifies programmatic and human accounts

D.

Conducts regular vulnerability assessments on programmatic accounts

Buy Now
Questions 12

When creating an API key, which scope should be selected to retrieve Identity Protection detection and incident information?

Options:

A.

Identity Protection Detections

B.

Identity Protection Incidents

C.

Identity Protection Assessment

D.

Identity Protection Data

Buy Now
Questions 13

Which of the following statements is NOT true as it relates to Identity Events, Detections, and Incidents?

Options:

A.

Events related to an incident that occur after the incident is marked In Progress will create a new incident

B.

A detection can become an element of an incident that preceded it in time

C.

An event can become an element of a detection that preceded it in time

D.

Not all events are security events that become elements of detections

Buy Now
Questions 14

Under which CrowdStrike documentation category could you find Identity Protection API information?

Options:

A.

Tools and Reference

B.

Falcon Management

C.

CrowdStrike Store

D.

CrowdStrike APIs

Buy Now
Questions 15

Which of the following actions will NOT help to decrease a domain risk score?

Options:

A.

Upgrading endpoints running end-of-life operating systems

B.

Upgrading endpoints running end-of-life Acrobat Reader

C.

Enabling SMB Signing within Active Directory

D.

Enforcing NTLMv2 responses

Buy Now
Questions 16

Which of the following are NOT included within the three-dot menu on Identity-based Detections?

IDP Question 16

Which of the following are not included within the three-dot menu on Identity-based Detections?

Options:

A.

Edit status

B.

Add to Watchlist

C.

Add exclusion

D.

Add comment

Buy Now
Questions 17

Which of the following would cause an identity-based incident type to change?

Options:

A.

An exclusion added to the incident

B.

A user linked detections to the incident in the console

C.

A user changed the incident type in the console

D.

Detections related to the incident

Buy Now
Exam Code: IDP
Exam Name: CrowdStrike Certified Identity Specialist(CCIS) Exam
Last Update: May 31, 2026
Questions: 58

PDF + Testing Engine

$64.99   $185.69

Testing Engine

$49.99   $142.83

PDF (Q&A)

$54.99   $157.11