Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

IDP Exam Questions & Answers

CrowdStrike Certified Identity Specialist  •  CrowdStrike

58 Questions Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample IDP Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

Which of the following are minimum requirements for showing the Falcon Identity Verification Dialog on the end user's machine?

Correct Answer: A
Explanation:

The Falcon Identity Verification Dialog is used to prompt users for identity verification during conditional access enforcement. According to the CCIS curriculum, Internet Explorer 9 and Windows Server 2008 represent the minimum supported requirements for rendering the Identity Verification Dialog on an end user's system.

This requirement exists because the dialog relies on supported browser and OS components to present authentication challenges reliably during enforcement workflows. Systems that do not meet these minimum requirements may fail to display the dialog correctly, impacting the enforcement of MFA or identity verification actions.

The other options reference runtime frameworks or PowerShell versions that are not directly responsible for rendering the verification dialog. Therefore, Option A is the correct and verified answer.

Q2 MultipleChoice

The Enforce section of Identity Protection is used to:

Correct Answer: B
Explanation:

The Enforce section of Falcon Identity Protection is dedicated to policy-based identity enforcement. According to the CCIS curriculum, this section allows administrators to define and manage Policy Rules and Policy Groups that specify how the platform should respond when identity-related conditions are detected.

These rules evaluate triggers such as risky authentication behavior, privilege misuse, compromised credentials, or elevated risk scores, and then execute actions like blocking access, enforcing MFA, or initiating Falcon Fusion workflows. Enforce is therefore the execution layer of Falcon's identity security model.

The other options correspond to different sections of the platform:

Configuration tasks are handled in Configure.

Detections and incidents are reviewed in Monitor or Explore.

Domain posture overviews are displayed in Domain Security Overview.

Because Enforce directly controls what actions are taken in response to identity risk, Option B is the correct and verified answer.

Q3 MultipleChoice

How should a user be classified if one requires observation for potential risk to the business?

Correct Answer: C
Explanation:

Within Falcon Identity Protection, a Watched User is a user explicitly designated for heightened monitoring due to potential business risk. According to the CCIS curriculum, watchlists are designed to provide additional visibility into users whose behavior, access level, or role may warrant closer observation, even if they have not yet exhibited confirmed malicious activity.

Watched Users may include executives, administrators, users with access to sensitive systems, or accounts suspected of being targeted. Placing a user on a watchlist does not imply compromise; instead, it ensures their activity is prioritized in investigations, detections, and dashboards.

The other options are incorrect:

Honeytoken Accounts are decoy accounts designed to detect malicious usage.

High Risk is a calculated risk state, not a monitoring classification.

Marked User is not a valid Falcon Identity Protection classification.

Because the CCIS material explicitly identifies Watched Users as accounts requiring observation for potential risk, Option C is the correct and verified answer.

Q4 MultipleChoice

By using compromised credentials, threat actors are able to bypass the Execution phase of the MITRE ATT&CK framework and move directly into:

Correct Answer: C
Explanation:

The CCIS curriculum highlights a critical identity-security concept: when attackers use compromised credentials, they often bypass traditional malware-based attack phases, including the Execution phase of the MITRE ATT&CK framework. Because no malicious code needs to be executed, attackers can immediately begin interacting with the environment as a legitimate user.

As a result, threat actors move directly into the Discovery phase. During Discovery, attackers enumerate users, groups, privileges, systems, domain relationships, and trust paths to understand the environment and plan further actions. This behavior is commonly observed in identity-based attacks and living-off-the-land techniques.

Falcon Identity Protection is specifically designed to detect this behavior by monitoring authentication traffic, privilege usage, and anomalous identity activity---areas where traditional EDR tools may have limited visibility.

The other options are incorrect:

Initial Access has already occurred via credential compromise.

Weaponization and Execution are not required.

Lateral Movement typically follows Discovery.

Because compromised credentials allow attackers to jump straight into Discovery, Option C is the correct and verified answer.

Q5 MultipleChoice

What basic configuration fields are typically required for cloud Multi-Factor Authentication (MFA) connectors?

Correct Answer: D
Explanation:

Cloud-based MFA connectors integrate Falcon Identity Protection with third-party MFA providers using application-based authentication, not user credentials. As outlined in the CCIS curriculum, these connectors require an application identifier (Client/Application ID) and secret keys to securely authenticate API communications.

This approach follows modern security best practices by avoiding the use of privileged user credentials and instead leveraging scoped, revocable application secrets. The connector uses these credentials to trigger MFA challenges and exchange authentication context securely.

Options involving usernames, passwords, or domain controller details are incorrect, as Falcon Identity Protection does not store or require privileged account credentials for MFA integrations. Therefore, Option D is the correct answer.

Get access to all 58 verified questions with detailed answers.

Unlock All IDP Questions

Frequently Asked Questions

The CrowdStrike Certified Identity Specialist (CCIS) is a professional certification exam that validates expertise in identity and access management security using CrowdStrike's Identity Protection solutions. The certification demonstrates proficiency in securing identity infrastructure and protecting against identity-based threats in modern environments.

While CrowdStrike doesn't enforce strict prerequisites, candidates should have foundational knowledge of identity and access management concepts, cybersecurity principles, and preferably hands-on experience with CrowdStrike Identity Protection products. Prior experience with IAM solutions and security fundamentals is highly recommended to succeed on the exam.

The CCIS exam typically consists of multiple-choice questions and lasts approximately 90 minutes, though specific duration may vary. Candidates generally need to achieve a passing score of around 70-75%, depending on CrowdStrike's current scoring standards for this certification level.

The exam covers identity protection strategies, CrowdStrike's identity solutions architecture, threat detection and response related to identity compromise, policy configuration, and best practices for securing identity infrastructure. It also includes questions on integration with existing security tools and managing identity risk in enterprise environments.

Preparation should include studying CrowdStrike's official training materials, documentation, and hands-on practice with the Identity Protection platform. Many candidates also benefit from taking official CrowdStrike training courses, reviewing practice exams, and gaining practical experience with identity protection use cases in real or lab environments.
Exam Details
  • Exam CodeIDP
  • VendorCrowdStrike
  • Total Questions58
  • LanguageEnglish
  • Last UpdatedSep 5, 2026
4.9/5

Pass IDP First Time

Get all 58 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals