Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
When an endpoint that has not been used in the last 90 days becomes active, a detection for Use of Stale Endpoint is reported.
Falcon Identity Protection identifies stale endpoints as systems that have not authenticated or shown activity for an extended period and then suddenly become active. According to the CCIS curriculum, an endpoint that has been inactive for 90 days and then resumes activity will trigger a Use of Stale Endpoint detection.
This detection is important because attackers frequently exploit dormant or forgotten systems to re-enter environments, evade monitoring, or move laterally. A long period of inactivity followed by sudden authentication activity is considered a strong identity risk signal.
The 90-day threshold is used to establish a reliable inactivity baseline while minimizing false positives. Shorter timeframes could incorrectly flag normal usage patterns, while longer timeframes could delay detection of genuine threats.
Because Falcon explicitly defines stale endpoint activity using a 90-day inactivity window, Option B is the correct answer.
Falcon Identity Protection monitors network traffic to build user behavioral profiles to help identify unusual user behavior. How can this be beneficial to create a Falcon Fusion workflow?
Falcon Identity Protection continuously inspects authentication traffic and network behavior to establish behavioral baselines for users and accounts. These baselines enable the platform to detect deviations that indicate potential compromise, misuse, or insider threat activity. This behavioral intelligence directly enhances the effectiveness of Falcon Fusion workflows.
Falcon Fusion leverages identity and behavioral analytics as decision points within workflows, allowing automated actions to be triggered when abnormal behavior is detected. For example, a workflow can automatically enforce MFA, notify administrators, isolate risky sessions, or initiate remediation when a user deviates from their established baseline.
The CCIS curriculum highlights that Falcon Fusion is designed to integrate identity risk signals with IT policy enforcement, enabling Zero Trust-aligned automation. This capability goes far beyond simple notifications and supports coordinated responses across security and IT teams.
Options A, B, and C are incorrect because Falcon Fusion is fully identity-aware, applies broadly across users and entities, and supports a wide range of actions beyond email notifications. Therefore, Option D accurately describes how behavioral profiling strengthens Falcon Fusion workflows.
How long does it typically take Falcon Identity to develop a baseline of a user?
Falcon Identity Protection establishes a user baseline by observing authentication behavior over time, including login frequency, endpoints used, access patterns, and protocol usage. According to the CCIS curriculum, Falcon typically requires approximately one week of consistent activity to develop an initial, reliable baseline for a user.
This baseline allows Falcon to distinguish normal behavior from anomalies and to calculate accurate risk scores. While the baseline continues to mature over time and becomes more precise with additional data, the first usable behavioral model is generally formed within a week.
Longer timeframes such as one or three months are not required to begin detecting abnormal behavior. Conversely, periods shorter than a week may not provide sufficient behavioral data to accurately model normal usage patterns.
Because Falcon can rapidly establish a functional baseline while continuously refining it, Option C (One week) is the correct and verified answer.
When creating an API client, which scope with Write permissions must be enabled prior to using Identity Protection API?
To interact with Falcon Identity Protection using GraphQL, the API client must be created with the appropriate permission scopes. According to the CCIS curriculum, the Identity Protection GraphQL scope with Write permissions must be enabled prior to using the Identity Protection API.
This scope allows the API client to execute GraphQL queries and mutations related to identity detections, incidents, users, and risk data. Even when performing read-only operations, CrowdStrike requires the GraphQL Write scope to authorize GraphQL query execution within the Falcon platform.
The other options are incorrect because:
Identity Protection Assessment and Health are read-only data scopes.
The statement that Write permissions are not required is explicitly false per CCIS documentation.
Because GraphQL access requires the Identity Protection GraphQL (Write) scope, Option D is the correct and verified answer.
Describe the difference between a Human account and a Programmatic account.
Falcon Identity Protection differentiates human accounts and programmatic accounts based on authentication behavior, not naming conventions or assigned roles. According to the CCIS curriculum, human accounts are often used interactively, meaning they authenticate through direct user actions such as workstation logins, VPN access, or application access.
Programmatic accounts (such as service accounts) typically authenticate non-interactively, often on a predictable schedule or in response to automated processes. Falcon analyzes authentication frequency, protocol usage, timing, and access patterns to classify account types automatically.
The incorrect options reflect common misconceptions:
Human accounts are not always administrators.
Programmatic accounts can support MFA in some architectures.
Programmatic accounts are not used interactively.
Because interactive authentication behavior is the defining characteristic of human accounts, Option D is the correct and verified answer.
58 questions covering all exam domains, starting from $20
Exam domains verified against: Official CrowdStrike IDP exam guide, last checked August 2026.
Understand NIST SP 800-207 framework and Zero Trust principles including continuous validation. Learn how Falcon Identity Protection implements Zero Trust architecture and its key use cases, including how to interpret Zero Trust Assessment scores.
Explore the identity protection architecture in Falcon Identity Protection, how it inspects domain traffic, and complements traditional EDR solutions. Understand how it mitigates identity-based exploits and protects against human-element security vulnerabilities.
Identify the four menu categories in Falcon Identity Protection: monitor, enforce, explore, and configure. Understand the availability and features tied to subscription levels, Falcon roles, and how the tool mitigates threats bypassing traditional MITRE ATT&CK vectors.
Learn how risk scores, score trends, and risk matrices represent security posture in your domain. Understand the factors contributing to domain risk scores including severity, likelihood, and consequence, and how to manage goals and scope in the security overview.
Master entity risk categorization, the Risk Analysis and Event Analysis dashboards, and how to generate and export custom reports and insights. Learn to apply filters for targeted analysis and move users from higher to lower risk states.
Distinguish between users, endpoints, and entities, and between human and programmatic accounts. Learn high-risk account types such as stale and compromised password accounts, how risk baselining works, and how to use honeytoken accounts and watchlists.
Differentiate identity-based detections from incidents and master incident investigation pivots. Learn to navigate incident trees, filter detections, manage exclusions, and understand the difference between detection-based and analysis-based risk.
Create and manage policy rules and rule groups with appropriate triggers and conditions. Learn how to enable, disable, and apply changes to policies, and understand which Falcon roles can write and manage rules.
Monitor domain controllers and manage subnets for policy enforcement. Configure MFA and IDaaS connectors, enable authentication traffic inspection, and understand business privileges and country-based blocking rules.
Access and configure MFA and IDaaS connector settings. Enable third-party MFA for Falcon Identity Protection and understand how Falcon extends MFA capabilities rather than replacing them.
Build identity-focused workflows using Falcon Fusion SOAR components including triggers, conditions, branching, and loops. Create custom, templated, scheduled, and on-demand workflows to accomplish specific security goals.
Sample question from this domain above: Q2
Access Identity API documentation and create API keys specific to Falcon Identity Protection. Understand API permissions and pivot from Threat Hunter searches into GraphQL to build queries returning privileged high-risk users.
Sample question from this domain above: Q4
Common questions about the exam itself