IDP Exam Questions & Answers
CrowdStrike Certified Identity Specialist • CrowdStrike
100% money-back guarantee
Sample IDP Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
Which of the following are minimum requirements for showing the Falcon Identity Verification Dialog on the end user's machine?
The Falcon Identity Verification Dialog is used to prompt users for identity verification during conditional access enforcement. According to the CCIS curriculum, Internet Explorer 9 and Windows Server 2008 represent the minimum supported requirements for rendering the Identity Verification Dialog on an end user's system.
This requirement exists because the dialog relies on supported browser and OS components to present authentication challenges reliably during enforcement workflows. Systems that do not meet these minimum requirements may fail to display the dialog correctly, impacting the enforcement of MFA or identity verification actions.
The other options reference runtime frameworks or PowerShell versions that are not directly responsible for rendering the verification dialog. Therefore, Option A is the correct and verified answer.
The Enforce section of Identity Protection is used to:
The Enforce section of Falcon Identity Protection is dedicated to policy-based identity enforcement. According to the CCIS curriculum, this section allows administrators to define and manage Policy Rules and Policy Groups that specify how the platform should respond when identity-related conditions are detected.
These rules evaluate triggers such as risky authentication behavior, privilege misuse, compromised credentials, or elevated risk scores, and then execute actions like blocking access, enforcing MFA, or initiating Falcon Fusion workflows. Enforce is therefore the execution layer of Falcon's identity security model.
The other options correspond to different sections of the platform:
Configuration tasks are handled in Configure.
Detections and incidents are reviewed in Monitor or Explore.
Domain posture overviews are displayed in Domain Security Overview.
Because Enforce directly controls what actions are taken in response to identity risk, Option B is the correct and verified answer.
How should a user be classified if one requires observation for potential risk to the business?
Within Falcon Identity Protection, a Watched User is a user explicitly designated for heightened monitoring due to potential business risk. According to the CCIS curriculum, watchlists are designed to provide additional visibility into users whose behavior, access level, or role may warrant closer observation, even if they have not yet exhibited confirmed malicious activity.
Watched Users may include executives, administrators, users with access to sensitive systems, or accounts suspected of being targeted. Placing a user on a watchlist does not imply compromise; instead, it ensures their activity is prioritized in investigations, detections, and dashboards.
The other options are incorrect:
Honeytoken Accounts are decoy accounts designed to detect malicious usage.
High Risk is a calculated risk state, not a monitoring classification.
Marked User is not a valid Falcon Identity Protection classification.
Because the CCIS material explicitly identifies Watched Users as accounts requiring observation for potential risk, Option C is the correct and verified answer.
By using compromised credentials, threat actors are able to bypass the Execution phase of the MITRE ATT&CK framework and move directly into:
The CCIS curriculum highlights a critical identity-security concept: when attackers use compromised credentials, they often bypass traditional malware-based attack phases, including the Execution phase of the MITRE ATT&CK framework. Because no malicious code needs to be executed, attackers can immediately begin interacting with the environment as a legitimate user.
As a result, threat actors move directly into the Discovery phase. During Discovery, attackers enumerate users, groups, privileges, systems, domain relationships, and trust paths to understand the environment and plan further actions. This behavior is commonly observed in identity-based attacks and living-off-the-land techniques.
Falcon Identity Protection is specifically designed to detect this behavior by monitoring authentication traffic, privilege usage, and anomalous identity activity---areas where traditional EDR tools may have limited visibility.
The other options are incorrect:
Initial Access has already occurred via credential compromise.
Weaponization and Execution are not required.
Lateral Movement typically follows Discovery.
Because compromised credentials allow attackers to jump straight into Discovery, Option C is the correct and verified answer.
What basic configuration fields are typically required for cloud Multi-Factor Authentication (MFA) connectors?
Cloud-based MFA connectors integrate Falcon Identity Protection with third-party MFA providers using application-based authentication, not user credentials. As outlined in the CCIS curriculum, these connectors require an application identifier (Client/Application ID) and secret keys to securely authenticate API communications.
This approach follows modern security best practices by avoiding the use of privileged user credentials and instead leveraging scoped, revocable application secrets. The connector uses these credentials to trigger MFA challenges and exchange authentication context securely.
Options involving usernames, passwords, or domain controller details are incorrect, as Falcon Identity Protection does not store or require privileged account credentials for MFA integrations. Therefore, Option D is the correct answer.
Get access to all 58 verified questions with detailed answers.
Unlock All IDP Questions