New Year Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the CrowdStrike CCIS IDP Questions and answers with CertsForce

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

How many days will an identity-based incident be suppressed if new events related to the same incident occur?

Options:

A.

30 days


B.

7 days


C.

14 days


D.

5 days


Expert Solution
Questions # 2:

Which of the following demonstrates a detection is enabled?

Options:

A.

The toggle next to the Detection Enabled is marked in gray


B.

The toggle next to the Detection Enabled is marked in green


C.

The detection has a Disabled tag next to it


D.

The detection has an Enabled tag next to it


Expert Solution
Questions # 3:

Which of the following actions under the Investigate menu will pivot to Falcon Identity Protection from an identity-based detection?

Options:

A.

Investigate involved users


B.

Search for involved entities in Threat Hunter


C.

Search for events in Threat Hunter


D.

Investigate involved endpoints


Expert Solution
Questions # 4:

What trigger will cause a Falcon Fusion Workflow to activate from Falcon Identity Protection?

Options:

A.

New endpoint detection


B.

New incident


C.

Alert > Identity detection


D.

Spotlight user action > Host


Expert Solution
Questions # 5:

For false positives, the Detection details can be set to new“Actions”using:

Options:

A.

exits


B.

remediations


C.

exceptions


D.

recommendations


Expert Solution
Questions # 6:

Which of the following Falcon rolesCANNOTenable and disable policy rules?

Options:

A.

Identity Protection Domain Administrator


B.

Identity Protection Administrator


C.

Identity Protection Policy Manager


D.

Falcon Administrator


Expert Solution
Questions # 7:

Which entity tab will show an administrator how to lower the account's risk score?

Options:

A.

Timeline


B.

Activity


C.

Asset


D.

Risk


Expert Solution
Questions # 8:

How should an organization address the domain risk score found in the Domain Security Overview page?

Options:

A.

Address the risks on the list from top to bottom as risks are presented in a descending order


B.

Prioritizing the risks by severity, addressing the Medium (Yellow) risks first


C.

Prioritizing the detections by severity, addressing the High (Red) detections first


D.

Prioritizing the risks by severity, addressing the Low (Green) risks first


Expert Solution
Questions # 9:

Where would a Falcon administrator enable authentication traffic inspection (ATI) for Domain Controllers?

Options:

A.

Identity configuration policies


B.

Identity management settings


C.

Identity detection configuration


D.

Identity protection settings


Expert Solution
Questions # 10:

Within Domain Security Overview, whatGoalincorporates all risks into one security assessment report?

Options:

A.

Pen Testing


B.

AD Hygiene


C.

Reduce Attack Surface


D.

Privileged User Management


Expert Solution
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions