
CrowdStrikeCertified Cloud Specialist (CCCS)
Domain 6Objective 3
6.3 Audit User Account Activity and Permissions to Identify Risks CCCS Practice Questions (Page 1)
Part of the Findings and Detection Analysis domain, which makes up ~22% of our current practice bank.
22questions here
5free pages
4concepts
Questions 1–5
- 1
An auditor is reviewing logs and finds that a user with 'Finance Analyst' role has been accessing the 'Accounts Payable' system at unusual hours and from a VPN endpoint. The user's role is documented to have 'Read' access to the system. The activity log shows the user has been downloading large volumes of data. The auditor also notices that the user's account has been granted 'Write' access to the system by a 'Finance Manager' two days ago. What is the most significant risk indicator?
Select an answer first - 2
During an audit of user account activity, an analyst notices a user account has multiple failed login attempts followed by a successful login within a short time. Which behavior does this pattern most likely indicate?
Select an answer first - 3
A security team is reviewing user activity and permissions in a hybrid cloud environment. They find that a 'System Administrator' account has been used to create a new user account with 'Global Administrator' permissions. The System Administrator role is documented to have permission to create user accounts, but not to assign 'Global Administrator' role. The new account has not been used yet. What is the most appropriate immediate action?
Select an answer first - 4
A security analyst at a financial firm reviews the previous day's user activity logs. The analyst notices that a junior accountant, who typically logs in between 8:00 AM and 6:00 PM from the corporate office, authenticated successfully at 2:47 AM from an IP address geolocated to a foreign country. The account then performed a bulk export of client records to a personal cloud storage URL. Which combination of findings should the analyst prioritize as the most significant risk indicators?
Select an answer first - 5
A security analyst is investigating a potential data breach. The analyst reviews the activity logs of a user account and finds that the user logged in from a new device, then immediately attempted to access several internal resources that are not part of their normal job function. The user's role is 'Sales Representative', but they attempted to access the 'HR Payroll' share. What should the analyst do first?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by CrowdStrike. “CCCS” is a trademark of its owner, used for identification only.