U.S. Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike IDP Exam - Topic 1 Question 10 Discussion

Which of the following would cause an identity-based incident type to change?
D) Detections related to the incident
A) An exclusion added to the incident
B) A user linked detections to the incident in the console
C) A user changed the incident type in the console

CrowdStrike IDP Exam - Topic 1 Question 10 Discussion

Actual exam question for CrowdStrike's IDP exam
Question #: 10
Topic #: 1
[All IDP Questions]

Which of the following would cause an identity-based incident type to change?

Show Suggested Answer Hide Answer
Suggested Answer: D

In Falcon Identity Protection, identity-based incidents are dynamic and can evolve over time as additional detections are associated with them. According to the CCIS curriculum, an incident's type is automatically recalculated based on the detections related to the incident, not by manual user actions.

As new identity-based detections are generated---such as credential misuse, lateral movement attempts, or abnormal authentication behavior---the platform continuously reassesses the incident. If the newly added detections indicate a different or more severe attack pattern, Falcon may automatically change the incident type to better reflect the observed threat activity.

Manual actions such as adding exclusions or linking detections do not directly change the incident type. Similarly, users cannot manually override an incident's classification. The classification logic is driven entirely by Falcon's analytics engine to ensure consistent, objective threat categorization.

This automated behavior is emphasized in CCIS training to highlight Falcon's ability to adapt incident context as attacks progress, making Option D the correct answer.


Contribute your Thoughts:

0/2000 characters
Kenny
1 month ago
I think the answer might be C, since changing the incident type directly seems like it would definitely cause a change.
upvoted 0 times
...

Save Cancel