Which of the following is NOT a default insight but can be created with a custom insight?
In Falcon Identity Protection, default insights are prebuilt analytical views provided by CrowdStrike to immediately highlight common and high-impact identity risks across the environment. These default insights are automatically available in the Risk Analysis and Insights areas and are designed to surface well-known identity exposure patterns without requiring customization.
Examples of default insights include Using Unmanaged Endpoints, GPO Exposed Password, and Compromised Password. These insights are natively provided because they represent frequent and high-risk identity attack vectors such as credential exposure, unmanaged authentication sources, and password compromise, all of which directly contribute to elevated identity risk scores.
Poorly Protected Accounts with SPN (Service Principal Name), however, is not provided as a default insight. While Falcon Identity Protection does collect and analyze SPN-related risk signals---such as Kerberoasting exposure and weak service account protections---this specific grouping must be created by administrators using custom insight filters. Custom insights allow teams to define precise conditions, combine attributes (privilege level, SPN presence, password age, MFA status), and tailor risk visibility to their organization's threat model.
This distinction is emphasized in the CCIS curriculum, which explains that custom insights extend beyond default coverage, enabling deeper, organization-specific identity risk analysis. Therefore, Option D is the correct answer.
Within which Identity Protection menu would an administrator enable Authentication Traffic Inspection (ATI) for a domain?
Authentication Traffic Inspection (ATI) is enabled through Identity Configuration Policies, which define how the Falcon sensor captures and inspects identity-related network traffic. According to the CCIS documentation, ATI configuration is performed under Configure > Identity Configuration Policies.
These policies allow administrators to specify which authentication protocols are inspected, which domain controllers are covered, and how identity telemetry is collected. This configuration step is mandatory to enable identity visibility and detection capabilities.
The Enforce menu is used for policy rules and automated actions, not traffic inspection. General settings do not control sensor inspection behavior. Because ATI directly affects sensor data capture, it is managed exclusively through Identity Configuration Policies.
Therefore, Option D is the correct and verified answer.
How does the Falcon sensor for Windows contribute to the enforcement in Falcon Identity Protection?
The Falcon sensor for Windows plays a critical role in Falcon Identity Protection by collecting and validating domain authentication events directly from domain controllers. According to the CCIS curriculum, the sensor inspects authentication protocols such as Kerberos, NTLM, and LDAP through Authentication Traffic Inspection (ATI).
This telemetry enables Falcon Identity Protection to analyze authentication behavior, build identity baselines, detect anomalies, and generate identity-based detections. The sensor does not enforce password policies, manage permissions, or encrypt network traffic---those functions belong to Active Directory and network infrastructure components.
By providing high-fidelity authentication telemetry without relying on log ingestion, the Falcon sensor enables real-time identity threat detection and Zero Trust enforcement. Therefore, Option D is the correct and verified answer.
Where in the Identity Protection module can one view the monitoring status of domain controllers?
In Falcon Identity Protection, the Domains page is where administrators can view the monitoring and health status of domain controllers. The CCIS curriculum explains that this page provides visibility into which domain controllers are actively reporting authentication traffic, their inspection status, and whether Authentication Traffic Inspection (ATI) is enabled.
This view is essential for validating coverage and ensuring that Falcon Identity Protection has sufficient visibility into domain authentication activity. Administrators can quickly identify gaps, such as domain controllers that are not reporting or are misconfigured, and take corrective action.
The other options serve different purposes:
Settings manage general configuration.
System Notifications display alerts and messages.
Connectors manage integrations such as MFA and IDaaS.
Because domain controller visibility and monitoring health are managed at the domain level, Option C (Domains) is the correct and verified answer.
Which of the following would cause an identity-based incident type to change?
In Falcon Identity Protection, identity-based incidents are dynamic and can evolve over time as additional detections are associated with them. According to the CCIS curriculum, an incident's type is automatically recalculated based on the detections related to the incident, not by manual user actions.
As new identity-based detections are generated---such as credential misuse, lateral movement attempts, or abnormal authentication behavior---the platform continuously reassesses the incident. If the newly added detections indicate a different or more severe attack pattern, Falcon may automatically change the incident type to better reflect the observed threat activity.
Manual actions such as adding exclusions or linking detections do not directly change the incident type. Similarly, users cannot manually override an incident's classification. The classification logic is driven entirely by Falcon's analytics engine to ensure consistent, objective threat categorization.
This automated behavior is emphasized in CCIS training to highlight Falcon's ability to adapt incident context as attacks progress, making Option D the correct answer.
Susan Hernandez
5 days agoKevin Garcia
27 days agoDeborah Smith
1 month agoAdam Hill
2 months agoMelissa Miller
2 months agoElizabeth Green
3 months agoFrank Green
3 months agoRachel Scott
3 months agoJessica Taylor
2 months agoBetty Johnson
3 months agoFrank Torres
3 months agoAdam Anderson
2 months agoRikki
4 months agoChau
4 months agoVallie
4 months agoMarvel
5 months agoCorazon
5 months agoMarsha
5 months agoTiffiny
5 months agoMee
6 months agoTheron
6 months agoPearly
6 months agoStevie
6 months agoJess
7 months ago