Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

CrowdStrike IDP Exam - Topic 5 Question 14 Discussion

Which of the following is NOT a default insight but can be created with a custom insight?
D) Poorly Protected Accounts with SPN
A) Using Unmanaged Endpoints
B) GPO Exposed Password
C) Compromised Password

CrowdStrike IDP Exam - Topic 5 Question 14 Discussion

Actual exam question for CrowdStrike's IDP exam
Question #: 14
Topic #: 5
[All IDP Questions]

Which of the following is NOT a default insight but can be created with a custom insight?

Show Suggested Answer Hide Answer
Suggested Answer: D

In Falcon Identity Protection, default insights are prebuilt analytical views provided by CrowdStrike to immediately highlight common and high-impact identity risks across the environment. These default insights are automatically available in the Risk Analysis and Insights areas and are designed to surface well-known identity exposure patterns without requiring customization.

Examples of default insights include Using Unmanaged Endpoints, GPO Exposed Password, and Compromised Password. These insights are natively provided because they represent frequent and high-risk identity attack vectors such as credential exposure, unmanaged authentication sources, and password compromise, all of which directly contribute to elevated identity risk scores.

Poorly Protected Accounts with SPN (Service Principal Name), however, is not provided as a default insight. While Falcon Identity Protection does collect and analyze SPN-related risk signals---such as Kerberoasting exposure and weak service account protections---this specific grouping must be created by administrators using custom insight filters. Custom insights allow teams to define precise conditions, combine attributes (privilege level, SPN presence, password age, MFA status), and tailor risk visibility to their organization's threat model.

This distinction is emphasized in the CCIS curriculum, which explains that custom insights extend beyond default coverage, enabling deeper, organization-specific identity risk analysis. Therefore, Option D is the correct answer.


Contribute your Thoughts:

0/2000 characters
Gerald
4 days ago
Wait, are we sure about D? That sounds like a default to me!
upvoted 0 times
...
Margery
9 days ago
I agree with D, seems like the odd one out.
upvoted 0 times
...
Luisa
14 days ago
A is also a custom one, right?
upvoted 0 times
...
Joni
19 days ago
I thought GPO Exposed Password was custom too?
upvoted 0 times
...
Dick
24 days ago
Definitely D, that's a custom insight for sure.
upvoted 0 times
...
Lawanda
30 days ago
Using Unmanaged Endpoints sounds familiar, but I can't remember if it's a default or custom insight.
upvoted 0 times
...
Johnetta
1 month ago
I practiced a question similar to this, and I think Compromised Password is definitely a default insight.
upvoted 0 times
...
Ronald
1 month ago
I feel like Poorly Protected Accounts with SPN might be a custom insight, but I can't recall the specifics.
upvoted 0 times
...
Andrew
2 months ago
I think I remember something about GPO Exposed Password being a default insight, but I'm not entirely sure.
upvoted 0 times
...

Save Cancel