Limited-Time Summer Sale 25% Discount Offer - Apply Coupon Code: Save25
Certs Blitz
See all results for ""
Home Exams
CRISC ISACA CISSP ISC2 200-301 Cisco SY0-701 CompTIA AZ-104 Microsoft AI-900 Microsoft AIGP IAPP 1Z0-1067-26 Oracle View All Exams →
Sign in Create account
IDP EXAM PREPARATION

Prepare Smarter for the IDP Exam

Build your exam confidence with flexible preparation resources designed around the latest IDP exam objectives. Practice at your own pace using PDF questions, online exam simulations, or desktop practice software.

Download Exam View Entire Exam
Page: 1 / 1
Question #1 (Topic: Demo Questions)

An account without a phone number, operating system, or role of CEO would typically be defined as:

A.

Programmatic

B.

Human

C.

Enterprise

D.

Corporate

Correct Answer: A
Explanation:

Falcon Identity Protection classifies accounts based on observed authentication behavior and associated identity attributes , not solely on naming conventions. According to the CCIS curriculum, programmatic accounts (such as service accounts or application accounts) typically lack human-centric attributes like a phone number, assigned operating system, job title, or executive role (for example, CEO).

Human accounts generally have enriched identity context sourced from directory services and identity providers, including user profile details, interactive login behavior, and endpoint associations. In contrast, programmatic accounts authenticate non-interactively, often on predictable schedules, and do not require personal attributes to function.

Falcon analyzes authentication traffic to automatically identify these characteristics and classify the account accordingly. An account missing human identity signals—such as a phone number or endpoint ownership—strongly aligns with programmatic behavior.

Because the absence of personal attributes and interactive context is a defining indicator of a programmatic account , Option A is the correct and verified answer.

Question #2 (Topic: Demo Questions)

What basic configuration fields are typically required for cloud Multi-Factor Authentication (MFA) connectors?

A.

Service account user name and password

B.

Domain controller host name and IP address

C.

Domain Administrator user name and password

D.

Connector application identifier and secret keys

Correct Answer: D
Explanation:

Cloud-based MFA connectors integrate Falcon Identity Protection with third-party MFA providers using application-based authentication , not user credentials. As outlined in the CCIS curriculum, these connectors require an application identifier (Client/Application ID) and secret keys to securely authenticate API communications.

This approach follows modern security best practices by avoiding the use of privileged user credentials and instead leveraging scoped, revocable application secrets. The connector uses these credentials to trigger MFA challenges and exchange authentication context securely.

Options involving usernames, passwords, or domain controller details are incorrect, as Falcon Identity Protection does not store or require privileged account credentials for MFA integrations. Therefore, Option D is the correct answer.

Question #3 (Topic: Demo Questions)

Which menu option is NOT included in Falcon Identity Threat Detection (ITD)?

A.

Event Analysis

B.

Settings

C.

Privileged Identities

D.

Policy Rules

Correct Answer: D
Explanation:

Falcon Identity Threat Detection (ITD) provides visibility, analytics, and detection of identity-based threats but does not include enforcement capabilities . According to the CCIS curriculum, ITD customers have access to investigative and analytical features such as Event Analysis , Privileged Identities , and relevant Settings for visibility and monitoring.

Policy Rules , however, are part of Identity Threat Protection (ITP) and reside in the Enforce section of the Falcon console. Policy Rules enable automated responses and enforcement actions, such as blocking access or enforcing MFA, which are not available under ITD-only subscriptions.

This distinction is critical in the CCIS material:

ITD = Detect and analyze identity threats

ITP = Detect + enforce policy actions

Because ITD does not include enforcement functionality, Policy Rules are not available , making Option D the correct answer.

Question #4 (Topic: Demo Questions)

Which of the following statements is NOT true as it relates to Identity Events, Detections, and Incidents?

A.

Events related to an incident that occur after the incident is marked In Progress will create a new incident

B.

A detection can become an element of an incident that preceded it in time

C.

An event can become an element of a detection that preceded it in time

D.

Not all events are security events that become elements of detections

Correct Answer: A
Explanation:

Falcon Identity Protection follows a correlation and enrichment model where events, detections, and incidents are dynamically linked over time. According to the CCIS curriculum, events that occur after an incident is marked In Progress do not automatically create a new incident . Instead, related events and detections are typically added to the existing incident , provided they fall within the incident’s correlation and suppression window.

This behavior allows Falcon to present a single evolving incident , showing the full progression of an identity attack rather than fragmenting activity into multiple incidents. Therefore, statement A is not true .

The other statements are correct:

Detections can be retroactively associated with incidents that occurred earlier if correlation logic determines relevance.

Events can be linked to detections even if the detection is created after the event occurred.

Not all events are security-relevant; many remain informational and never become detections.

This adaptive correlation model is a core concept in CCIS training and supports efficient investigation and incident lifecycle management. Hence, Option A is the correct answer.

Question #5 (Topic: Demo Questions)

Which of the following would cause an identity-based incident type to change?

A.

An exclusion added to the incident

B.

A user linked detections to the incident in the console

C.

A user changed the incident type in the console

D.

Detections related to the incident

Correct Answer: D
Explanation:

In Falcon Identity Protection, identity-based incidents are dynamic and can evolve over time as additional detections are associated with them. According to the CCIS curriculum, an incident’s type is automatically recalculated based on the detections related to the incident , not by manual user actions.

As new identity-based detections are generated—such as credential misuse, lateral movement attempts, or abnormal authentication behavior—the platform continuously reassesses the incident. If the newly added detections indicate a different or more severe attack pattern, Falcon may automatically change the incident type to better reflect the observed threat activity.

Manual actions such as adding exclusions or linking detections do not directly change the incident type. Similarly, users cannot manually override an incident’s classification. The classification logic is driven entirely by Falcon’s analytics engine to ensure consistent, objective threat categorization.

This automated behavior is emphasized in CCIS training to highlight Falcon’s ability to adapt incident context as attacks progress , making Option D the correct answer.

Download Exam
Page: 1 / 1
Next Page