Which of the following demonstrates a detection is enabled?
Answer : B
In Falcon Identity Protection, detection status is visually indicated using a toggle control within the detection configuration interface. According to the CCIS documentation, when a detection is enabled, the toggle next to Detection Enabled is displayed in green.
A green toggle indicates that the detection logic is active and that Falcon will generate detections when the defined conditions are met. When the toggle is gray, the detection is disabled and will not generate alerts or contribute to incident formation.
Falcon does not rely on textual ''Enabled'' or ''Disabled'' tags to indicate detection status. Instead, the toggle color provides a clear, immediate visual indicator to administrators.
Because a green toggle explicitly represents an enabled detection, Option B is the correct and verified answer.
How does CrowdStrike Falcon Identity Protection help customers identify different types of accounts in their domain?
Answer : C
Falcon Identity Protection automatically differentiates human and programmatic accounts by analyzing authentication traffic patterns. According to the CCIS curriculum, the platform uses behavioral analytics to observe how accounts authenticate, including frequency, protocol usage, timing, and access patterns.
Human users typically authenticate interactively and exhibit variable behavior, while programmatic or service accounts authenticate predictably and non-interactively. Falcon leverages these differences to automatically classify account types without requiring manual tagging or administrative input.
This classification is critical for accurate risk scoring, privilege analysis, and detection logic. Programmatic accounts often carry elevated privileges and long-lived credentials, making them attractive targets for attackers. Automatically identifying them allows Falcon to apply appropriate risk models and detections.
Because Falcon uses authentication traffic analysis to classify account types, Option C is the correct and verified answer.
How should an organization address the domain risk score found in the Domain Security Overview page?
Answer : A
The Domain Security Overview page in Falcon Identity Protection presents domain risks in a prioritized, descending order, based on a combination of severity, likelihood, and consequence. The CCIS curriculum emphasizes that organizations should address risks from top to bottom, as the list is already optimized to reflect the most impactful identity risks first.
This ordering allows security teams to focus remediation efforts where they will produce the greatest reduction in overall domain risk score. Addressing risks sequentially ensures alignment with Falcon's risk modeling and avoids misprioritization that could occur if teams focus only on color-based severity or individual detections.
The incorrect options reflect common misconceptions:
Medium risks should not be prioritized over higher-impact risks.
Detections are different from risks and should not be addressed independently of risk context.
Low risks are intentionally deprioritized by the platform.
By following the descending order provided in the Domain Security Overview, organizations align remediation with Falcon's Zero Trust--driven identity risk scoring methodology, making Option A the correct answer.
How should a user be classified if one requires observation for potential risk to the business?
Answer : C
Within Falcon Identity Protection, a Watched User is a user explicitly designated for heightened monitoring due to potential business risk. According to the CCIS curriculum, watchlists are designed to provide additional visibility into users whose behavior, access level, or role may warrant closer observation, even if they have not yet exhibited confirmed malicious activity.
Watched Users may include executives, administrators, users with access to sensitive systems, or accounts suspected of being targeted. Placing a user on a watchlist does not imply compromise; instead, it ensures their activity is prioritized in investigations, detections, and dashboards.
The other options are incorrect:
Honeytoken Accounts are decoy accounts designed to detect malicious usage.
High Risk is a calculated risk state, not a monitoring classification.
Marked User is not a valid Falcon Identity Protection classification.
Because the CCIS material explicitly identifies Watched Users as accounts requiring observation for potential risk, Option C is the correct and verified answer.
The configuration of the Azure AD (Entra ID) Identity-as-a-Service connector requires which three pieces of information?
Answer : D
To integrate Falcon Identity Protection with Azure AD (Entra ID) as an Identity-as-a-Service (IDaaS) provider, specific application-level credentials are required. According to the CCIS curriculum, the connector configuration requires Tenant Domain, Application (Client) ID, and Application Secret.
These values are generated when registering an application in Azure AD and are used to authenticate Falcon Identity Protection securely via OAuth-based API access. This method ensures least-privilege access and allows the connector to ingest cloud authentication activity and apply SSO-related policy enforcement.
Other options list incomplete or incorrect credential combinations. Therefore, Option D is the correct and verified answer.
Falcon Identity Protection can continuously assess identity events and associate them with potential threats WITHOUT which of the following?
Answer : D
Falcon Identity Protection is architected as a log-free identity security platform, a core tenet emphasized throughout the CCIS curriculum. Unlike traditional SIEM- or log-based solutions, Falcon Identity Protection does not require string-based queries to continuously assess identity events or associate them with threats.
Instead, the platform relies on machine-learning-powered detection rules, real-time authentication traffic inspection, and API-based connectors to collect and analyze identity telemetry directly from domain controllers and identity providers. This approach eliminates the operational complexity of building, tuning, and maintaining query logic.
String-based queries are commonly associated with legacy log aggregation tools and SIEM platforms, where analysts must manually search logs to identify suspicious behavior. Falcon Identity Protection replaces this model with behavioral baselining and automated correlation, enabling continuous identity risk assessment without human-driven query execution.
Because Falcon does not require string-based queries to operate, Option D is the correct and verified answer.
Falcon Identity Protection monitors network traffic to build user behavioral profiles to help identify unusual user behavior. How can this be beneficial to create a Falcon Fusion workflow?
Answer : D
Falcon Identity Protection continuously inspects authentication traffic and network behavior to establish behavioral baselines for users and accounts. These baselines enable the platform to detect deviations that indicate potential compromise, misuse, or insider threat activity. This behavioral intelligence directly enhances the effectiveness of Falcon Fusion workflows.
Falcon Fusion leverages identity and behavioral analytics as decision points within workflows, allowing automated actions to be triggered when abnormal behavior is detected. For example, a workflow can automatically enforce MFA, notify administrators, isolate risky sessions, or initiate remediation when a user deviates from their established baseline.
The CCIS curriculum highlights that Falcon Fusion is designed to integrate identity risk signals with IT policy enforcement, enabling Zero Trust-aligned automation. This capability goes far beyond simple notifications and supports coordinated responses across security and IT teams.
Options A, B, and C are incorrect because Falcon Fusion is fully identity-aware, applies broadly across users and entities, and supports a wide range of actions beyond email notifications. Therefore, Option D accurately describes how behavioral profiling strengthens Falcon Fusion workflows.