CrowdStrike Certified Falcon Administrator (CCFA) CCFA-200b
Official details for CrowdStrike Certified Falcon Administrator (CCFA) CCFA-200b as published by the certification body.
The CrowdStrike Certified Falcon Administrator (CCFA) certification validates the knowledge and skills required to administer the CrowdStrike Falcon platform. According to CrowdStrike's current certification information, the CCFA exam consists of 60 multiple-choice, single-correct-response questions, has a 90-minute duration, and requires a passing score of 80%. The exam fee is $250 USD, and the assessment is delivered through Pearson either at a Pearson test center or online through Pearson OnVUE. CrowdStrike recommends that candidates have at least six months of experience with the Falcon platform, while the certification is valid for three years. The current CrowdStrike University FAQ indicates that some certification exams are available in Japanese, while candidates whose first language is not English may request an accommodation for 120 minutes total; candidates should verify language availability and accommodations for their specific exam appointment.
The CCFA-200b exam is designed for professionals who administer the Falcon platform and need to demonstrate practical knowledge of platform management. The certification is particularly relevant to security administrators, Falcon administrators, endpoint security administrators, security analysts, SOC analysts, security engineers, and IT security operations professionals.
Exam Overview
The CrowdStrike Certified Falcon Administrator (CCFA) is a role-focused cybersecurity certification centered on administration of the CrowdStrike Falcon platform.
The certification demonstrates competency in areas such as:
Managing Falcon users and role-based permissions
Deploying and managing Falcon sensors
Creating and managing host groups
Configuring deployment policies
Configuring prevention policies
Managing allowlists and blocklists
Configuring file-path exclusions
Managing endpoint security settings
Monitoring sensor coverage and health
Conducting administrative reporting
Supporting consistent endpoint protection administration
The CCFA-200b exam is relevant to professionals who work with the administrative side of Falcon rather than focusing exclusively on incident response or threat hunting. CrowdStrike describes the certification as appropriate for administrators and analysts with access to Falcon's administrative functions.
Certification Details
Exam Detail | Information |
|---|---|
Exam Name | CrowdStrike Certified Falcon Administrator |
Certification | CCFA |
Exam Code | CCFA-200b |
Provider | CrowdStrike |
Category | Cybersecurity |
Exam Cost | $250 USD |
Duration | 90 minutes |
Passing Score | 80% |
Number of Questions | 60 |
Question Format | Multiple-choice, single-correct response |
Delivery Method | Pearson test center or online Pearson OnVUE |
Exam Type | Proctored, closed-book |
Certification Level | Professional, role-focused cybersecurity certification |
Recommended Experience | At least 6 months of experience with CrowdStrike Falcon |
Certification Validity | 3 years |
Exam Language | Verify current availability when scheduling; English proficiency is required for comprehension, with language accommodations available under CrowdStrike's policies |
CrowdStrike's current FAQ confirms that certification examinations contain 60 multiple-choice, single-correct-response questions and provide 90 minutes for completion. Exams are proctored, and candidates cannot use study aids, notes, or reference materials during the examination.
Why This Certification Matters
The CCFA certification matters because organizations using endpoint security platforms need professionals who can configure and administer those platforms effectively.
The certification can help demonstrate that a candidate understands key administrative responsibilities associated with the Falcon environment, including:
User access administration
Role-based permission management
Sensor deployment
Sensor management
Host grouping
Prevention policy configuration
Deployment policy configuration
Allowlist administration
Blocklist administration
Exclusion configuration
Security coverage reporting
Administrative monitoring
For employers, a role-focused certification can provide an additional way to assess whether a candidate understands the administrative responsibilities associated with a specific security platform.
For professionals, the CCFA can complement broader cybersecurity qualifications by adding specialized knowledge of CrowdStrike Falcon administration.
Skills Measured
The CCFA certification focuses on the ability to manage important aspects of the Falcon platform.
Key skills include:
Understanding Falcon platform administration
Managing users and permissions
Applying role-based access principles
Deploying Falcon sensors
Managing sensor installations
Creating and organizing groups
Configuring deployment policies
Configuring prevention policies
Managing allowlists
Managing blocklists
Configuring file-path exclusions
Reviewing endpoint security coverage
Using administrative reports
Understanding platform documentation
Supporting consistent security policy administration
CrowdStrike's certification guide specifically identifies user management, role-based permissions, sensor deployment and management, group creation, deployment and prevention policy settings, allowlisting and blocklisting, file-path exclusions, and administrative reporting among the expected capabilities.
Detailed Exam Objectives
Candidates preparing for the CCFA-200b exam should build knowledge across the main administrative responsibilities associated with the Falcon platform.
User Management and Permissions
Candidates should understand:
User account administration
Role-based permissions
Access management concepts
Administrative responsibilities
Appropriate privilege assignment
Managing access according to organizational requirements
A strong understanding of user management helps candidates recognize how administrative access is organized within Falcon.
Falcon Sensor Deployment and Management
Candidates should understand:
Falcon sensor deployment concepts
Sensor installation considerations
Sensor management
Sensor health
Sensor coverage
Deployment verification
Operating system-specific deployment considerations
Sensor maintenance concepts
Sensor administration is a fundamental responsibility for Falcon administrators because endpoint protection depends on appropriate sensor deployment and ongoing management.
Host Groups and Organization
Candidates should understand:
Group creation
Host organization
Group hierarchy concepts
Using groups to support policy management
Assigning endpoints to appropriate groups
Maintaining an organized endpoint environment
Well-structured host groups can make policy administration more manageable in larger environments.
Deployment and Prevention Policies
Candidates should understand:
Deployment policy configuration
Prevention policy configuration
Policy assignment
Policy management
Security settings
Policy hierarchy concepts
The relationship between policies and host groups
Candidates should be able to distinguish between administrative tasks related to deployment and those associated with endpoint prevention controls.
Allowlists and Blocklists
Candidates should understand:
Allowlist configuration
Blocklist configuration
Appropriate use cases
Security implications
Managing exceptions
Maintaining appropriate security controls
These concepts require careful understanding because changes to security policies can influence endpoint protection behavior.
File-Path Exclusions
Candidates should understand:
Exclusion configuration
File-path exclusion concepts
Appropriate administrative use
Security considerations
The relationship between exclusions and endpoint protection
Candidates should understand why exclusions require careful management and appropriate administrative controls.
Administrative Reporting
Candidates should understand:
Administrative reporting
Security coverage reporting
Reviewing platform information
Using dashboards and reports
Identifying coverage gaps
Supporting operational visibility
Reporting capabilities help administrators understand the state of the Falcon deployment and communicate relevant information to security and IT stakeholders.
Official Exam Domains Breakdown
CrowdStrike's publicly available CCFA documentation emphasizes role-based Falcon administration rather than presenting a simple percentage-weighted domain table in the available certification guide.
The principal knowledge areas include:
User Management
User administration
Role-based permissions
Administrative access
Sensor Deployment and Management
Sensor installation
Sensor deployment
Sensor management
Sensor coverage
Group Management
Group creation
Host organization
Group-based administration
Policy Administration
Deployment policies
Prevention policies
Policy configuration
Security Exceptions
Allowlists
Blocklists
File-path exclusions
Reporting and Administration
Administrative reporting
Coverage visibility
Platform management
Candidates should use the latest official CCFA exam guide for the authoritative domain structure and objective wording applicable to their scheduled exam version. CrowdStrike recommends using its certification exam guides and documentation as part of the preparation process.
Prerequisites
The CCFA certification does not require completion of a mandatory training course before attempting the examination.
However, CrowdStrike recommends that candidates:
Have at least six months of experience with the CrowdStrike Falcon platform
Understand Falcon administrative functions
Review recommended CrowdStrike documentation
Follow the recommended Falcon Administrator learning path
Have access to the relevant CrowdStrike University resources
Review the current CCFA exam guide
Meet the certification program's eligibility requirements
The certification guide also states that exam registrants must accept the CrowdStrike Certification Exam Agreement and be at least 18 years old.
Recommended Experience
CrowdStrike recommends approximately six months of experience with the Falcon platform in a production environment.
This experience is valuable because the CCFA focuses on administration tasks that are easier to understand when candidates have familiarity with endpoint security operations.
Recommended experience includes:
Managing endpoint security platforms
Working with endpoint security policies
Administering security tools
Managing user permissions
Deploying security agents or sensors
Working with endpoint groups
Reviewing security dashboards
Producing administrative reports
Candidates without extensive Falcon experience may need additional time to become familiar with the platform's terminology, navigation, configuration options, and administrative workflows.
Career Opportunities
The CCFA certification can support career paths involving CrowdStrike Falcon administration and endpoint security operations.
Potentially relevant roles include:
CrowdStrike Falcon Administrator
Security Administrator
Endpoint Security Administrator
Security Analyst
SOC Analyst
Security Engineer
IT Security Operations Manager
Endpoint Security Engineer
Cybersecurity Operations Specialist
Security Operations Engineer
CrowdStrike's certification materials specifically identify security analysts, SOC analysts, security engineers, IT security operations managers, security administrators, Falcon administrators, and endpoint security administrators as roles aligned with the CCFA certification.
Salary Insights
Salary outcomes depend on factors such as:
Job title
Geographic location
Professional experience
Employer size
Industry
Technical specialization
Broader cybersecurity knowledge
Cloud and identity security expertise
Professional certifications
Scope of administrative responsibility
The CCFA should be viewed as a specialized platform certification rather than a guarantee of a specific salary.
Professionals who combine Falcon administration knowledge with broader skills in areas such as endpoint detection and response, security operations, identity security, cloud security, SIEM, incident response, and security engineering may be positioned for a broader range of cybersecurity roles.
Certification Renewal Information
The CCFA certification is valid for three years, according to CrowdStrike's certification guide.
Candidates should monitor official CrowdStrike certification communications for current renewal and recertification requirements because program policies can change.
When planning a certification lifecycle, professionals should:
Track the certification expiration date
Monitor CrowdStrike University announcements
Review current certification policies
Check whether a newer certification exam version is available
Confirm current renewal requirements before expiration
The three-year validity period is documented in CrowdStrike's certification information.
Exam Registration Process
The CCFA exam registration process generally involves the following steps:
Create or maintain the required Pearson account
Obtain an exam voucher or arrange payment
Review the current CCFA exam information
Select a Pearson test center or online Pearson OnVUE appointment
Choose an available examination date and time
Complete any required identification verification
Review Pearson's exam-day requirements
Complete the examination
CrowdStrike states that candidates can register through Pearson and choose either a Pearson test center or online OnVUE delivery. Exam vouchers can be purchased through CrowdStrike or obtained through applicable organizational arrangements, while direct credit-card payment may be available during Pearson scheduling.
Preparation Resources
Recommended preparation resources include:
Official CrowdStrike CCFA Certification Exam Guide
CrowdStrike University
Falcon Administrator learning path
Falcon platform documentation
Falcon Orientation Guides
Falcon Sensor Deployment and Maintenance Guides
Endpoint Security Guides
User Management Guides
SIEM Connector Guide
CrowdStrike certification practice exams where available
CrowdStrike University webinars and eLearning resources
CrowdStrike University provides certification preparation resources, including exam guides, practice exams, webinars, and learning options. CrowdStrike also recommends reviewing relevant Falcon documentation through the platform's Support and Documentation resources.
Study Strategy
An effective CCFA preparation approach can be organized into several stages.
Start With the Exam Guide
Begin by reviewing the current official exam guide.
Identify:
Exam objectives
Knowledge domains
Recommended learning
Required terminology
Documentation references
Build Platform Familiarity
Focus on understanding how the Falcon platform is organized.
Review:
User administration
Roles
Sensor management
Groups
Policies
Exclusions
Allowlisting
Blocklisting
Reporting
Study by Administrative Function
Organize study sessions around administrative tasks rather than memorizing isolated terminology.
For example:
Study user management together with permissions
Study sensor deployment together with sensor health
Study groups together with policy assignment
Study exclusions together with security implications
Study reporting together with coverage monitoring
Review Official Documentation
Use current CrowdStrike documentation to strengthen understanding of platform terminology and administrative concepts.
Practice Question Management
The exam contains 60 questions and provides 90 minutes, giving an average of approximately 90 seconds per question.
Candidates should practice:
Reading the full question
Identifying the administrative objective
Eliminating clearly incorrect choices
Selecting the most appropriate answer
Moving forward when a question takes too long
Review Weak Areas
After practice sessions, identify topics that require additional study.
Prioritize:
User permissions
Sensor deployment
Policy configuration
Host groups
Security exceptions
Reporting
Common Challenges
Candidates may encounter several challenges while preparing for the CCFA-200b exam.
Platform-Specific Terminology
Candidates coming from other endpoint security products may need time to understand CrowdStrike-specific terminology.
Policy Relationships
Understanding how policies, groups, and endpoints relate to one another can require careful study.
Administrative Scope
The certification covers several administrative responsibilities, so preparation should not focus exclusively on sensor deployment or prevention policies.
Security Exceptions
Allowlisting, blocklisting, and exclusions require understanding of both administrative configuration and security implications.
Time Management
With 60 questions in 90 minutes, candidates need to balance careful reading with efficient decision-making.
Changing Platform Features
Cloud-based security platforms evolve continuously. Candidates should prioritize current official documentation and the latest exam guide.
Frequently Tested Topics
Important topics to prioritize include:
User management
Role-based permissions
Falcon sensor deployment
Sensor management
Sensor health
Host groups
Group creation
Deployment policies
Prevention policies
Allowlists
Blocklists
File-path exclusions
Endpoint security administration
Administrative reporting
Security coverage
Falcon platform administration
These areas align with the core administrative capabilities described in CrowdStrike's CCFA certification materials.
Exam-Day Tips
Candidates should consider the following exam-day practices:
Verify the appointment date and time
Confirm identification requirements
Review Pearson's current test-center or OnVUE policies
Complete the OnVUE system check if taking the exam online
Ensure the testing environment meets technical requirements
Arrive early for a test-center appointment
Keep required identification available
Read every question carefully
Pay attention to terms that distinguish administrative functions
Avoid spending excessive time on a single question
Use the full examination time when necessary
Review answers when time permits
CrowdStrike recommends completing a system check before an online OnVUE exam because employer-managed computers may have security settings or firewalls that interfere with the testing environment.
Related Certifications
Professionals interested in the broader CrowdStrike certification portfolio may also explore:
CrowdStrike Certified Falcon Responder (CCFR)
Focuses on responding to detections and security events
CrowdStrike Certified Falcon Hunter (CCFH)
Focuses on deeper detection analysis, investigation, and threat hunting
CrowdStrike Certified SIEM Analyst (CCSA)
Focuses on analyzing data and alerts within CrowdStrike's SIEM environment
CrowdStrike Certified SIEM Engineer (CCSE)
Focuses on implementing and managing CrowdStrike's SIEM capabilities
CrowdStrike Certified Identity Specialist (CCIS)
Focuses on identity-related security analysis and response
CrowdStrike Certified Cloud Specialist (CCCS)
Focuses on cloud security administration and security posture management
CrowdStrike's certification portfolio is designed around different security roles and specialized areas of the Falcon platform.
Latest Exam Updates
The CCFA-200b designation should always be verified against the latest official CrowdStrike certification documentation before registration.
Current published information confirms:
60 multiple-choice, single-correct-response questions
90-minute examination duration
80% passing score
$250 USD exam voucher price
Pearson delivery
Pearson test-center and OnVUE online options
Three-year certification validity
Recommended six months of Falcon experience
CrowdStrike's current training catalog, updated February 20, 2026, continues to list the CCFA examination as 60 questions with a 90-minute duration.
Candidates should verify the exact exam code, current exam guide, price, language availability, delivery options, and renewal policy at the time of registration because certification programs can be updated.
Competitor Gap Sections
Career Roadmap After Certification
A potential career progression for a Falcon-focused cybersecurity professional may include:
IT or security support role
Security analyst
Endpoint security analyst
SOC analyst
Falcon administrator
Endpoint security administrator
Security engineer
Senior security engineer
Security operations leadership
The CCFA can serve as a specialized credential within this progression, particularly when combined with hands-on Falcon administration experience and broader cybersecurity knowledge.
Industry Demand Analysis
Modern organizations increasingly rely on endpoint security platforms to monitor and protect distributed computing environments.
This creates demand for professionals who can:
Deploy endpoint security technologies
Maintain security configurations
Manage endpoint policies
Monitor security coverage
Support security operations teams
Administer user access
Maintain endpoint security posture
The value of a platform certification is generally strongest when it is combined with experience in security operations, endpoint security, identity, cloud, and incident response.
Use Cases
Falcon administration knowledge can support organizational activities such as:
Managing endpoint security deployments
Organizing endpoints into logical groups
Applying security policies
Managing user permissions
Monitoring sensor coverage
Managing security exceptions
Reviewing administrative reports
Supporting endpoint security operations
Maintaining consistent configuration across endpoints
Hiring Trends
Employers hiring for endpoint and security operations positions may look for combinations of:
Endpoint security experience
EDR platform knowledge
Security operations experience
SIEM familiarity
Incident response knowledge
Identity security understanding
Cloud security knowledge
Automation and scripting skills
Vendor-specific certifications
The CCFA is most valuable when it demonstrates specialized Falcon expertise alongside broader cybersecurity capabilities.
Certification Comparison
Certification | Primary Focus | Best Suited For |
|---|---|---|
CCFA | Falcon platform administration | Falcon administrators and security administrators |
CCFR | Detection response | Incident responders and SOC analysts |
CCFH | Investigation and threat hunting | Threat hunters and investigative analysts |
CCSA | SIEM analysis | SIEM analysts |
CCSE | SIEM engineering | SIEM engineers |
CCIS | Identity security | Identity security professionals |
CCCS | Cloud security | Cloud security professionals |
The CCFA is the most directly aligned option for professionals whose responsibilities center on administering the Falcon platform.
Success Stories
A certification success story typically begins with a clear role objective and structured preparation.
A professional working in endpoint security, for example, may use the CCFA certification to formalize knowledge gained through Falcon administration responsibilities. By combining platform experience with the certification, the professional can demonstrate knowledge of user management, sensors, groups, policies, exclusions, and reporting.
Another candidate may use the CCFA as a specialization within a broader cybersecurity career. Experience in SOC operations, endpoint security, or security engineering can provide a foundation for understanding Falcon administration.
The strongest outcomes generally come from combining certification with demonstrable technical experience, continuous learning, and broader cybersecurity capabilities.
Conclusion
The CrowdStrike Certified Falcon Administrator (CCFA) certification is a specialized credential for professionals responsible for administering the CrowdStrike Falcon platform. The CCFA-200b exam currently consists of 60 questions, provides 90 minutes, requires an 80% passing score, and costs $250 USD. The certification is delivered through Pearson and is valid for three years.
For candidates pursuing the CCFA Certification, the strongest preparation strategy is to combine official CrowdStrike University resources, the current CCFA exam guide, relevant Falcon documentation, and practical experience with platform administration. A focused understanding of user management, sensor deployment, groups, policies, exclusions, allowlists, blocklists, and reporting can provide a strong foundation for the CCFA Exam and for professional responsibilities as a CrowdStrike Falcon Administrator.
Frequently Asked Questions
Same exams as Featured on home
Information Systems Audit and Control Association (ISACA)
Certified in Risk and Information Systems Control (CRISC)
Explore exam
Amazon Web Services (AWS)
AWS Certified Solutions Architect – Associate
Explore exam
Google Cloud
Google Cloud Professional Cloud Architect
Explore exam
EC‑Council
Certified Ethical Hacker(CEH)
Explore exam
CompTIA
CompTIA Security+
Explore exam
Microsoft Azure
Microsoft Azure Fundamentals
Explore exam
Provider
French Proficiency Test Intermediaire Avance B2
Explore exam
Servicenow
ServiceNow Certified Application Developer
Explore exam
