Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
CROWDSTRIKE

CrowdStrike Certified Identity Specialist (CCIS)

CCISCrowdStrike Certified Identity Specialist

The CrowdStrike Certified Identity Specialist (CCIS) certification validates your expertise in securing workforce identities with the CrowdStrike Falcon® platform. It is designed for identity and access management (IAM) professionals, analysts focused on identity-based threats, and policy and access administrators. Earning CCIS demonstrates your ability to defend your organization against sophisticated identity-based cyberattacks.

12Domains
66Objectives
284Concepts
0Questions

CCIS Curriculum

Every domain, objective, and concept the CCIS exam measures.

Describe what the NIST SP 800-207 framework for Zero Trust architecture defines

5 concepts · 0 questions
  1. NIST SP 800-207 Overview
  2. Zero Trust Tenets
  3. Zero Trust Architecture Components
  4. Deployment Models
  5. Trust and Access Decisions

Describe the security need and impetus for the Zero Trust architecture

4 concepts · 0 questions
  1. Define Zero Trust Architecture
  2. Identify Security Drivers for Zero Trust
  3. Explain the Impetus from Evolving Threats
  4. Recognize Zero Trust in Identity-Centric Security

Describe the implementation of the Zero Trust architecture within Falcon Identity Protection

7 concepts · 0 questions
  1. Zero Trust Architecture Fundamentals
  2. Falcon Identity Protection Integration
  3. Identity-Based Policy Enforcement
  4. Continuous Verification Mechanisms
  5. Least Privilege Access Implementation
  6. Zero Trust Segmentation
  7. Monitoring and Response in Zero Trust

Describe the fundamental principles of Zero Trust (continuous validation, etc.)

4 concepts · 0 questions
  1. Zero Trust core principles
  2. Continuous validation
  3. Zero Trust architecture components
  4. Zero Trust vs. traditional security

Describe the difference between a traditional "wall-and-moat" security model and a modern Zero Trust model

4 concepts · 0 questions
  1. Traditional wall-and-moat model
  2. Modern Zero Trust model
  3. Key differences between the models
  4. Implications for identity security

Describe some of the key use cases for Falcon Zero Trust

6 concepts · 0 questions
  1. Identify Falcon Zero Trust use cases
  2. Explain Zero Trust access enforcement
  3. Describe integration with identity providers
  4. Outline use case for unmanaged devices
  5. Summarize use case for third-party and contractor access
  6. Explain use case for adaptive risk-based access

Describe how a Falcon user's Zero Trust Assessment (ZTA) score is calculated

4 concepts · 0 questions
  1. ZTA score definition
  2. Scoring factors
  3. Score calculation logic
  4. Score interpretation

Describe the identity protection architecture employed at CrowdStrike as a part of the Falcon Identity Protection module

6 concepts · 0 questions
  1. Falcon Identity Protection Architecture Overview
  2. Identity Protection Data Flow
  3. Integration with Falcon Platform
  4. Deployment Models
  5. Scalability and Performance
  6. Security and Compliance

Describe how Falcon Identity Protection inspects traffic in the domain

5 concepts · 0 questions
  1. Traffic inspection architecture
  2. Inspection points
  3. Protocols and ports
  4. Traffic analysis techniques
  5. Integration with domain controllers

Describe how Falcon Identity Protection complements traditional EDR solutions

4 concepts · 0 questions
  1. Complementary detection capabilities
  2. Integration with EDR telemetry
  3. Coverage of identity attack surface
  4. Operational synergy

Describe how Falcon Identity Protection helps secure against the human elements of security vulnerability

2 concepts · 0 questions
  1. Human Elements of Security Vulnerability
  2. Falcon Identity Protection's Role in Mitigating Human Risk

Describe how Falcon Identity Protection empowers the team to mitigate and prevent identity-based exploits and attacks

5 concepts · 0 questions
  1. Identity-Based Exploits and Attacks
  2. Falcon Identity Protection Capabilities
  3. Mitigation Strategies
  4. Prevention Mechanisms
  5. Empowering Security Teams

Identify key differences between Falcon Identity Protection log-free detections and traditional EDR solutions

5 concepts · 0 questions
  1. Log-free detection mechanism
  2. Comparison with EDR log-based detection
  3. Detection sources and data
  4. Detection scope and coverage
  5. Deployment and operational impact

Describe the threat landscape and the need for identity-based security solutions

4 concepts · 0 questions
  1. Identity-based threats
  2. Evolution of the threat landscape
  3. Need for identity security
  4. Identity as the new perimeter

Identify the menu categories (monitor, enforce, explore and configure) of Falcon Identity Protection

5 concepts · 0 questions
  1. Menu categories overview
  2. Monitor category
  3. Enforce category
  4. Explore category
  5. Configure category

Describe the contents of each menu category (monitor, enforce, explore and configure) within Falcon Identity Protection

4 concepts · 0 questions
  1. Monitor menu contents
  2. Enforce menu contents
  3. Explore menu contents
  4. Configure menu contents

Identify the goal of each menu category (monitor, enforce, explore and configure)

4 concepts · 0 questions
  1. Monitor menu category
  2. Enforce menu category
  3. Explore menu category
  4. Configure menu category

Recognize the availability of specific tools limited by product subscription for Identity Threat Detection vs. Identity Threat Protection (ITD vs. ITP)

4 concepts · 0 questions
  1. Product Subscription Tiers
  2. ITD vs ITP Feature Sets
  3. Tool Availability Mapping
  4. Subscription Limitations

Describe the purpose of Falcon Identity Protection in general security terms

3 concepts · 0 questions
  1. Falcon Identity Protection Overview
  2. Identity Threat Landscape
  3. Integration with Security Operations

Explain how Falcon Identity Protection works to mitigate threats that bypass traditional MITRE ATT&CK framework vectors

4 concepts · 0 questions
  1. Threat vectors bypassing traditional MITRE ATT&CK
  2. Falcon Identity Protection detection mechanisms
  3. Mitigation techniques for identity-based threats
  4. Integration with MITRE ATT&CK framework

Describe the Falcon roles working within Falcon Identity Protection and the features available to those roles

5 concepts · 0 questions
  1. Falcon roles in Identity Protection
  2. Role-based feature availability
  3. Identity Protection dashboard access
  4. Alert and detection management roles
  5. Administrative roles and configuration

Understanding Domain Risk Scores and Trends

5 concepts · 0 questions
  1. Definition of Domain Risk Score
  2. Score Trend Representation
  3. Factors Influencing Domain Risk Score
  4. Methods to Lower Domain Risk Score
  5. Impact of Actions on Score Trend

Interpreting Risk Matrix and Risk Factors

6 concepts · 0 questions
  1. Risk Matrix Structure
  2. Risk Representation
  3. Severity Definition
  4. Likelihood Definition
  5. Consequence Definition
  6. Interpreting Risk Levels

Prioritizing and Addressing Risks

4 concepts · 0 questions
  1. Risk Prioritization Framework
  2. Domain Risk Assessment
  3. Prioritization Criteria
  4. Addressing High-Priority Risks

Integrating Falcon Identity Protection

1 concepts · 0 questions
  1. Falcon Identity Protection in the Security Model

Managing Domain Security Goals and Scope

5 concepts · 0 questions
  1. Domain Security overview goals
  2. Changing the Goal setting
  3. Goal-specific focus areas
  4. Changing the Scope setting
  5. Scope impact on Overview dashboard

Risk Fundamentals

2 concepts · 0 questions
  1. Entity Risk Categories
  2. Risk Score Contributing Elements

Risk Analysis and Dashboards

3 concepts · 0 questions
  1. Risk Analysis Dashboard Overview
  2. Event Analysis Dashboard Overview
  3. Filtering for Targeted Risk Analysis

Custom Insights and Reports

5 concepts · 0 questions
  1. Custom Insights Generation
  2. Custom Report Creation
  3. Insight vs. Report Distinction
  4. Custom Report Export
  5. Custom Report Scheduling

Risk Remediation

3 concepts · 0 questions
  1. Risk Level Transition Workflow
  2. Risk Reduction Actions
  3. Verification of Risk Change

User Fundamentals

4 concepts · 0 questions
  1. User attributes in Falcon Identity Protection
  2. User vs. endpoint vs. entity
  3. Human vs. programmatic accounts
  4. User icons and their meanings

User Risk Assessment

5 concepts · 0 questions
  1. Default insights in Users view
  2. Creating custom filters in Users view
  3. Baselining high-risk users
  4. Risk baselining process and timelines
  5. Risky account types and their risks

Risk Mitigation and Special Accounts

4 concepts · 0 questions
  1. Adding custom lists to Compromised Password directory
  2. Risks of elevated privilege users
  3. User watchlist and honeytoken accounts
  4. Use cases for honeytoken accounts

Identity-Based Detection and Incident Fundamentals

6 concepts · 0 questions
  1. Identity-Based Detection Definition
  2. Identity-Based Incident Definition
  3. Investigation Pivots from Identity-Based Incidents
  4. Difference Between Incident and Detection
  5. Types of Identity-Based Detections
  6. Key Information in Identity-Based Detections

Investigating Identity-Based Incidents

5 concepts · 0 questions
  1. Pivoting to Related Entities
  2. Navigating the Incident Tree
  3. Incident Evolution Over Time
  4. Filtering and Searching Detections
  5. Investigating Incident History and Type Changes

Managing Detection Exclusions and Types

5 concepts · 0 questions
  1. Enabling and disabling detection exclusions
  2. Adding exceptions to detection exclusions
  3. Logic behind detection exclusions
  4. Use cases for enabling detection types
  5. Use cases for disabling detection types

Understanding Risk in Detection and Analysis

3 concepts · 0 questions
  1. Detection-based risk definition
  2. Analysis-based risk definition
  3. Comparing detection and analysis risk

Describe the purpose of policy rules and policy groups

3 concepts · 0 questions
  1. Purpose of policy rules
  2. Purpose of policy groups
  3. Relationship between policy rules and policy groups

Demonstrate the policy rule creation process

3 concepts · 0 questions
  1. Policy Rule Creation Workflow
  2. Policy Rule Configuration Options
  3. Policy Rule Validation and Testing

Explain the purpose of the various triggers and conditions within a policy rule

5 concepts · 0 questions
  1. Trigger types in policy rules
  2. Condition types in policy rules
  3. Purpose of triggers
  4. Purpose of conditions
  5. Relationship between triggers and conditions

Explain how to enable and disable policy rules

3 concepts · 0 questions
  1. Enable Policy Rules
  2. Disable Policy Rules
  3. Impact of Enabling/Disabling

Explain how to group, ungroup and manage groups of rules

3 concepts · 0 questions
  1. Grouping rules
  2. Ungrouping rules
  3. Managing rule groups

Describe how to apply any changes made to policy rules

4 concepts · 0 questions
  1. Policy Rule Change Workflow
  2. Impact Assessment of Policy Changes
  3. Implementation of Policy Updates
  4. Verification of Applied Changes

Describe the Falcon role(s) necessary to write and manage policy rules

1 concepts · 0 questions
  1. Falcon roles for policy rule management

Domain Monitoring and Configuration

6 concepts · 0 questions
  1. DC visibility in Falcon console
  2. Monitoring DC health and reporting
  3. Enabling ATI on DCs
  4. ATI prerequisites and impact
  5. Falcon Identity Protection policy configuration options
  6. Sensor data capture settings

Subnet Management and Policy Enforcement

3 concepts · 0 questions
  1. Subnet Creation
  2. Subnet Management
  3. Subnet Policy Enforcement

Risk Configuration and Exceptions

6 concepts · 0 questions
  1. Risk configuration settings overview
  2. Risk scoring parameters
  3. Risk thresholds and policies
  4. Exception concept and purpose
  5. Adding exceptions to risk configurations
  6. Managing and validating exceptions

Connector Types and Setup

4 concepts · 0 questions
  1. Two connector types
  2. MFA connector subtypes
  3. Supported connectors list
  4. Connector setup documentation

Business Privileges and Country Controls

4 concepts · 0 questions
  1. Definition of Business Privileges
  2. Impact of Business Privileges on Entities
  3. Blocklisted and Allowlisted Countries Configuration
  4. Effect of Country Lists on Detections

Explain how to access the IDaaS and MFA configuration settings

3 concepts · 0 questions
  1. Accessing IDaaS configuration settings
  2. Accessing MFA configuration settings
  3. Understanding the relationship between IDaaS and MFA settings

Explain the configuration fields associated with the various connectors

6 concepts · 0 questions
  1. Connector Configuration Fields Overview
  2. Field-Specific Settings for Each Connector Type
  3. Authentication and Authorization Fields
  4. Connectivity and Endpoint Fields
  5. Synchronization and Mapping Fields
  6. Troubleshooting and Validation Fields

Describe how to configure the settings for MFA connectors

7 concepts · 0 questions
  1. MFA connector configuration overview
  2. Accessing MFA connector settings
  3. Configuring connector authentication
  4. Mapping identity provider attributes
  5. Enabling and disabling MFA connectors
  6. Testing MFA connector connectivity
  7. Troubleshooting MFA connector issues

Describe how to enable third-party MFA for Falcon Identity Protection

3 concepts · 0 questions
  1. Third-party MFA integration overview
  2. Configuration steps for third-party MFA
  3. Verification and troubleshooting

Describe how Falcon Identity Protection extends on capabilities of existing MFA providers and does not intend to replace it

3 concepts · 0 questions
  1. Falcon Identity Protection integration with MFA providers
  2. Non-replacement principle
  3. Capability extension

Describe the building blocks of a Falcon Fusion SOAR workflow

5 concepts · 0 questions
  1. Workflow components
  2. Trigger types
  3. Conditions and logic
  4. Actions and integrations
  5. Workflow execution and data flow

Explain how to define triggers

5 concepts · 0 questions
  1. Trigger definition
  2. Trigger types
  3. Trigger configuration
  4. Trigger testing
  5. Trigger management

Explain how to add conditions

4 concepts · 0 questions
  1. Identify condition types
  2. Add a condition node
  3. Configure condition logic
  4. Test condition behavior

Explain what various conditions do and how to combine them to limit the scope of a workflow

5 concepts · 0 questions
  1. Purpose of Conditions
  2. Types of Conditions
  3. Combining Conditions
  4. Limiting Workflow Scope
  5. Condition Evaluation Order

Describe how to create custom, templated, scheduled and on-demand workflows

5 concepts · 0 questions
  1. Custom workflow creation
  2. Templated workflow usage
  3. Scheduled workflow setup
  4. On-demand workflow execution
  5. Workflow lifecycle management

Describe how to create branching workflows and loops

5 concepts · 0 questions
  1. Branching workflow fundamentals
  2. Creating conditional branches
  3. Looping workflow fundamentals
  4. Implementing loops
  5. Combining branches and loops

Create workflows in Falcon Fusion SOAR to accomplish specific goals

8 concepts · 0 questions
  1. Workflow fundamentals
  2. Trigger configuration
  3. Action orchestration
  4. Conditional logic
  5. Data transformation
  6. Integration with identity tools
  7. Testing and debugging
  8. Deployment and management

Describe where you can find Identity API (GraphQL) documentation

3 concepts · 0 questions
  1. Identity API Documentation Location
  2. Accessing GraphQL Documentation
  3. Documentation Structure

Create an API key specific to Falcon Identity Protection

4 concepts · 0 questions
  1. API Key Fundamentals
  2. Falcon Identity Protection API Key Requirements
  3. Creating an API Key in the Falcon Console
  4. Managing and Securing API Keys

Describe the differences between the different Falcon Identity Protection API permissions

3 concepts · 0 questions
  1. Falcon Identity Protection API permission types
  2. Scope of each permission type
  3. Differences between permission types

Pivot from a Threat Hunter search into GraphQL

5 concepts · 0 questions
  1. Threat Hunter search context
  2. GraphQL query construction
  3. Mapping search results to GraphQL fields
  4. Executing GraphQL queries
  5. Interpreting GraphQL response data

Build a simple query that returns all privileged users with high risk

5 concepts · 0 questions
  1. GraphQL query structure
  2. Identifying privileged users
  3. Filtering by risk level
  4. Combining filters
  5. Executing and interpreting results
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCIS, so none is invented.