
CrowdStrike Certified Identity Specialist (CCIS)
The CrowdStrike Certified Identity Specialist (CCIS) certification validates your expertise in securing workforce identities with the CrowdStrike Falcon® platform. It is designed for identity and access management (IAM) professionals, analysts focused on identity-based threats, and policy and access administrators. Earning CCIS demonstrates your ability to defend your organization against sophisticated identity-based cyberattacks.
12Domains
66Objectives
284Concepts
0Questions
CCIS Curriculum
Every domain, objective, and concept the CCIS exam measures.
Describe what the NIST SP 800-207 framework for Zero Trust architecture defines
- NIST SP 800-207 Overview
- Zero Trust Tenets
- Zero Trust Architecture Components
- Deployment Models
- Trust and Access Decisions
Describe the security need and impetus for the Zero Trust architecture
- Define Zero Trust Architecture
- Identify Security Drivers for Zero Trust
- Explain the Impetus from Evolving Threats
- Recognize Zero Trust in Identity-Centric Security
Describe the implementation of the Zero Trust architecture within Falcon Identity Protection
- Zero Trust Architecture Fundamentals
- Falcon Identity Protection Integration
- Identity-Based Policy Enforcement
- Continuous Verification Mechanisms
- Least Privilege Access Implementation
- Zero Trust Segmentation
- Monitoring and Response in Zero Trust
Describe the fundamental principles of Zero Trust (continuous validation, etc.)
- Zero Trust core principles
- Continuous validation
- Zero Trust architecture components
- Zero Trust vs. traditional security
Describe the difference between a traditional "wall-and-moat" security model and a modern Zero Trust model
- Traditional wall-and-moat model
- Modern Zero Trust model
- Key differences between the models
- Implications for identity security
Describe some of the key use cases for Falcon Zero Trust
- Identify Falcon Zero Trust use cases
- Explain Zero Trust access enforcement
- Describe integration with identity providers
- Outline use case for unmanaged devices
- Summarize use case for third-party and contractor access
- Explain use case for adaptive risk-based access
Describe how a Falcon user's Zero Trust Assessment (ZTA) score is calculated
- ZTA score definition
- Scoring factors
- Score calculation logic
- Score interpretation
Describe the identity protection architecture employed at CrowdStrike as a part of the Falcon Identity Protection module
- Falcon Identity Protection Architecture Overview
- Identity Protection Data Flow
- Integration with Falcon Platform
- Deployment Models
- Scalability and Performance
- Security and Compliance
Describe how Falcon Identity Protection inspects traffic in the domain
- Traffic inspection architecture
- Inspection points
- Protocols and ports
- Traffic analysis techniques
- Integration with domain controllers
Describe how Falcon Identity Protection complements traditional EDR solutions
- Complementary detection capabilities
- Integration with EDR telemetry
- Coverage of identity attack surface
- Operational synergy
Describe how Falcon Identity Protection helps secure against the human elements of security vulnerability
- Human Elements of Security Vulnerability
- Falcon Identity Protection's Role in Mitigating Human Risk
Describe how Falcon Identity Protection empowers the team to mitigate and prevent identity-based exploits and attacks
- Identity-Based Exploits and Attacks
- Falcon Identity Protection Capabilities
- Mitigation Strategies
- Prevention Mechanisms
- Empowering Security Teams
Identify key differences between Falcon Identity Protection log-free detections and traditional EDR solutions
- Log-free detection mechanism
- Comparison with EDR log-based detection
- Detection sources and data
- Detection scope and coverage
- Deployment and operational impact
Describe the threat landscape and the need for identity-based security solutions
- Identity-based threats
- Evolution of the threat landscape
- Need for identity security
- Identity as the new perimeter
Identify the menu categories (monitor, enforce, explore and configure) of Falcon Identity Protection
- Menu categories overview
- Monitor category
- Enforce category
- Explore category
- Configure category
Describe the contents of each menu category (monitor, enforce, explore and configure) within Falcon Identity Protection
- Monitor menu contents
- Enforce menu contents
- Explore menu contents
- Configure menu contents
Identify the goal of each menu category (monitor, enforce, explore and configure)
- Monitor menu category
- Enforce menu category
- Explore menu category
- Configure menu category
Recognize the availability of specific tools limited by product subscription for Identity Threat Detection vs. Identity Threat Protection (ITD vs. ITP)
- Product Subscription Tiers
- ITD vs ITP Feature Sets
- Tool Availability Mapping
- Subscription Limitations
Describe the purpose of Falcon Identity Protection in general security terms
- Falcon Identity Protection Overview
- Identity Threat Landscape
- Integration with Security Operations
Explain how Falcon Identity Protection works to mitigate threats that bypass traditional MITRE ATT&CK framework vectors
- Threat vectors bypassing traditional MITRE ATT&CK
- Falcon Identity Protection detection mechanisms
- Mitigation techniques for identity-based threats
- Integration with MITRE ATT&CK framework
Describe the Falcon roles working within Falcon Identity Protection and the features available to those roles
- Falcon roles in Identity Protection
- Role-based feature availability
- Identity Protection dashboard access
- Alert and detection management roles
- Administrative roles and configuration
Understanding Domain Risk Scores and Trends
- Definition of Domain Risk Score
- Score Trend Representation
- Factors Influencing Domain Risk Score
- Methods to Lower Domain Risk Score
- Impact of Actions on Score Trend
Interpreting Risk Matrix and Risk Factors
- Risk Matrix Structure
- Risk Representation
- Severity Definition
- Likelihood Definition
- Consequence Definition
- Interpreting Risk Levels
Prioritizing and Addressing Risks
- Risk Prioritization Framework
- Domain Risk Assessment
- Prioritization Criteria
- Addressing High-Priority Risks
Integrating Falcon Identity Protection
- Falcon Identity Protection in the Security Model
Managing Domain Security Goals and Scope
- Domain Security overview goals
- Changing the Goal setting
- Goal-specific focus areas
- Changing the Scope setting
- Scope impact on Overview dashboard
Risk Fundamentals
- Entity Risk Categories
- Risk Score Contributing Elements
Risk Analysis and Dashboards
- Risk Analysis Dashboard Overview
- Event Analysis Dashboard Overview
- Filtering for Targeted Risk Analysis
Custom Insights and Reports
- Custom Insights Generation
- Custom Report Creation
- Insight vs. Report Distinction
- Custom Report Export
- Custom Report Scheduling
Risk Remediation
- Risk Level Transition Workflow
- Risk Reduction Actions
- Verification of Risk Change
User Fundamentals
- User attributes in Falcon Identity Protection
- User vs. endpoint vs. entity
- Human vs. programmatic accounts
- User icons and their meanings
User Risk Assessment
- Default insights in Users view
- Creating custom filters in Users view
- Baselining high-risk users
- Risk baselining process and timelines
- Risky account types and their risks
Risk Mitigation and Special Accounts
- Adding custom lists to Compromised Password directory
- Risks of elevated privilege users
- User watchlist and honeytoken accounts
- Use cases for honeytoken accounts
Identity-Based Detection and Incident Fundamentals
- Identity-Based Detection Definition
- Identity-Based Incident Definition
- Investigation Pivots from Identity-Based Incidents
- Difference Between Incident and Detection
- Types of Identity-Based Detections
- Key Information in Identity-Based Detections
Investigating Identity-Based Incidents
- Pivoting to Related Entities
- Navigating the Incident Tree
- Incident Evolution Over Time
- Filtering and Searching Detections
- Investigating Incident History and Type Changes
Managing Detection Exclusions and Types
- Enabling and disabling detection exclusions
- Adding exceptions to detection exclusions
- Logic behind detection exclusions
- Use cases for enabling detection types
- Use cases for disabling detection types
Understanding Risk in Detection and Analysis
- Detection-based risk definition
- Analysis-based risk definition
- Comparing detection and analysis risk
Describe the purpose of policy rules and policy groups
- Purpose of policy rules
- Purpose of policy groups
- Relationship between policy rules and policy groups
Demonstrate the policy rule creation process
- Policy Rule Creation Workflow
- Policy Rule Configuration Options
- Policy Rule Validation and Testing
Explain the purpose of the various triggers and conditions within a policy rule
- Trigger types in policy rules
- Condition types in policy rules
- Purpose of triggers
- Purpose of conditions
- Relationship between triggers and conditions
Explain how to enable and disable policy rules
- Enable Policy Rules
- Disable Policy Rules
- Impact of Enabling/Disabling
Explain how to group, ungroup and manage groups of rules
- Grouping rules
- Ungrouping rules
- Managing rule groups
Describe how to apply any changes made to policy rules
- Policy Rule Change Workflow
- Impact Assessment of Policy Changes
- Implementation of Policy Updates
- Verification of Applied Changes
Describe the Falcon role(s) necessary to write and manage policy rules
- Falcon roles for policy rule management
Domain Monitoring and Configuration
- DC visibility in Falcon console
- Monitoring DC health and reporting
- Enabling ATI on DCs
- ATI prerequisites and impact
- Falcon Identity Protection policy configuration options
- Sensor data capture settings
Subnet Management and Policy Enforcement
- Subnet Creation
- Subnet Management
- Subnet Policy Enforcement
Risk Configuration and Exceptions
- Risk configuration settings overview
- Risk scoring parameters
- Risk thresholds and policies
- Exception concept and purpose
- Adding exceptions to risk configurations
- Managing and validating exceptions
Connector Types and Setup
- Two connector types
- MFA connector subtypes
- Supported connectors list
- Connector setup documentation
Business Privileges and Country Controls
- Definition of Business Privileges
- Impact of Business Privileges on Entities
- Blocklisted and Allowlisted Countries Configuration
- Effect of Country Lists on Detections
Explain how to access the IDaaS and MFA configuration settings
- Accessing IDaaS configuration settings
- Accessing MFA configuration settings
- Understanding the relationship between IDaaS and MFA settings
Explain the configuration fields associated with the various connectors
- Connector Configuration Fields Overview
- Field-Specific Settings for Each Connector Type
- Authentication and Authorization Fields
- Connectivity and Endpoint Fields
- Synchronization and Mapping Fields
- Troubleshooting and Validation Fields
Describe how to configure the settings for MFA connectors
- MFA connector configuration overview
- Accessing MFA connector settings
- Configuring connector authentication
- Mapping identity provider attributes
- Enabling and disabling MFA connectors
- Testing MFA connector connectivity
- Troubleshooting MFA connector issues
Describe how to enable third-party MFA for Falcon Identity Protection
- Third-party MFA integration overview
- Configuration steps for third-party MFA
- Verification and troubleshooting
Describe how Falcon Identity Protection extends on capabilities of existing MFA providers and does not intend to replace it
- Falcon Identity Protection integration with MFA providers
- Non-replacement principle
- Capability extension
Describe the building blocks of a Falcon Fusion SOAR workflow
- Workflow components
- Trigger types
- Conditions and logic
- Actions and integrations
- Workflow execution and data flow
Explain how to define triggers
- Trigger definition
- Trigger types
- Trigger configuration
- Trigger testing
- Trigger management
Explain how to add conditions
- Identify condition types
- Add a condition node
- Configure condition logic
- Test condition behavior
Explain what various conditions do and how to combine them to limit the scope of a workflow
- Purpose of Conditions
- Types of Conditions
- Combining Conditions
- Limiting Workflow Scope
- Condition Evaluation Order
Describe how to create custom, templated, scheduled and on-demand workflows
- Custom workflow creation
- Templated workflow usage
- Scheduled workflow setup
- On-demand workflow execution
- Workflow lifecycle management
Describe how to create branching workflows and loops
- Branching workflow fundamentals
- Creating conditional branches
- Looping workflow fundamentals
- Implementing loops
- Combining branches and loops
Create workflows in Falcon Fusion SOAR to accomplish specific goals
- Workflow fundamentals
- Trigger configuration
- Action orchestration
- Conditional logic
- Data transformation
- Integration with identity tools
- Testing and debugging
- Deployment and management
Describe where you can find Identity API (GraphQL) documentation
- Identity API Documentation Location
- Accessing GraphQL Documentation
- Documentation Structure
Create an API key specific to Falcon Identity Protection
- API Key Fundamentals
- Falcon Identity Protection API Key Requirements
- Creating an API Key in the Falcon Console
- Managing and Securing API Keys
Describe the differences between the different Falcon Identity Protection API permissions
- Falcon Identity Protection API permission types
- Scope of each permission type
- Differences between permission types
Pivot from a Threat Hunter search into GraphQL
- Threat Hunter search context
- GraphQL query construction
- Mapping search results to GraphQL fields
- Executing GraphQL queries
- Interpreting GraphQL response data
Build a simple query that returns all privileged users with high risk
- GraphQL query structure
- Identifying privileged users
- Filtering by risk level
- Combining filters
- Executing and interpreting results
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCIS, so none is invented.