All Exam Questions

CrowdStrike Certified Falcon Administrator (CCFA) CCFA-200b

Official details for CrowdStrike Certified Falcon Administrator (CCFA) CCFA-200b as published by the certification body.

Exam code
CCFA-200b
Duration
90 minutes
Number of questions
60 according to publicly available CCFA-200b exam information
Cost
$250 according to the published CrowdStrike certification guide; verify current pricing
Certification body
CrowdStrike
Validity
3 Years

The CrowdStrike Certified Falcon Administrator (CCFA) certification validates the knowledge and skills required to administer the CrowdStrike Falcon platform. According to CrowdStrike's current certification information, the CCFA exam consists of 60 multiple-choice, single-correct-response questions, has a 90-minute duration, and requires a passing score of 80%. The exam fee is $250 USD, and the assessment is delivered through Pearson either at a Pearson test center or online through Pearson OnVUE. CrowdStrike recommends that candidates have at least six months of experience with the Falcon platform, while the certification is valid for three years. The current CrowdStrike University FAQ indicates that some certification exams are available in Japanese, while candidates whose first language is not English may request an accommodation for 120 minutes total; candidates should verify language availability and accommodations for their specific exam appointment.

The CCFA-200b exam is designed for professionals who administer the Falcon platform and need to demonstrate practical knowledge of platform management. The certification is particularly relevant to security administrators, Falcon administrators, endpoint security administrators, security analysts, SOC analysts, security engineers, and IT security operations professionals.

Exam Overview

The CrowdStrike Certified Falcon Administrator (CCFA) is a role-focused cybersecurity certification centered on administration of the CrowdStrike Falcon platform.

The certification demonstrates competency in areas such as:

  • Managing Falcon users and role-based permissions

  • Deploying and managing Falcon sensors

  • Creating and managing host groups

  • Configuring deployment policies

  • Configuring prevention policies

  • Managing allowlists and blocklists

  • Configuring file-path exclusions

  • Managing endpoint security settings

  • Monitoring sensor coverage and health

  • Conducting administrative reporting

  • Supporting consistent endpoint protection administration

The CCFA-200b exam is relevant to professionals who work with the administrative side of Falcon rather than focusing exclusively on incident response or threat hunting. CrowdStrike describes the certification as appropriate for administrators and analysts with access to Falcon's administrative functions.

Certification Details

Exam Detail

Information

Exam Name

CrowdStrike Certified Falcon Administrator

Certification

CCFA

Exam Code

CCFA-200b

Provider

CrowdStrike

Category

Cybersecurity

Exam Cost

$250 USD

Duration

90 minutes

Passing Score

80%

Number of Questions

60

Question Format

Multiple-choice, single-correct response

Delivery Method

Pearson test center or online Pearson OnVUE

Exam Type

Proctored, closed-book

Certification Level

Professional, role-focused cybersecurity certification

Recommended Experience

At least 6 months of experience with CrowdStrike Falcon

Certification Validity

3 years

Exam Language

Verify current availability when scheduling; English proficiency is required for comprehension, with language accommodations available under CrowdStrike's policies

CrowdStrike's current FAQ confirms that certification examinations contain 60 multiple-choice, single-correct-response questions and provide 90 minutes for completion. Exams are proctored, and candidates cannot use study aids, notes, or reference materials during the examination.

Why This Certification Matters

The CCFA certification matters because organizations using endpoint security platforms need professionals who can configure and administer those platforms effectively.

The certification can help demonstrate that a candidate understands key administrative responsibilities associated with the Falcon environment, including:

  • User access administration

  • Role-based permission management

  • Sensor deployment

  • Sensor management

  • Host grouping

  • Prevention policy configuration

  • Deployment policy configuration

  • Allowlist administration

  • Blocklist administration

  • Exclusion configuration

  • Security coverage reporting

  • Administrative monitoring

For employers, a role-focused certification can provide an additional way to assess whether a candidate understands the administrative responsibilities associated with a specific security platform.

For professionals, the CCFA can complement broader cybersecurity qualifications by adding specialized knowledge of CrowdStrike Falcon administration.

Skills Measured

The CCFA certification focuses on the ability to manage important aspects of the Falcon platform.

Key skills include:

  • Understanding Falcon platform administration

  • Managing users and permissions

  • Applying role-based access principles

  • Deploying Falcon sensors

  • Managing sensor installations

  • Creating and organizing groups

  • Configuring deployment policies

  • Configuring prevention policies

  • Managing allowlists

  • Managing blocklists

  • Configuring file-path exclusions

  • Reviewing endpoint security coverage

  • Using administrative reports

  • Understanding platform documentation

  • Supporting consistent security policy administration

CrowdStrike's certification guide specifically identifies user management, role-based permissions, sensor deployment and management, group creation, deployment and prevention policy settings, allowlisting and blocklisting, file-path exclusions, and administrative reporting among the expected capabilities.

Detailed Exam Objectives

Candidates preparing for the CCFA-200b exam should build knowledge across the main administrative responsibilities associated with the Falcon platform.

User Management and Permissions

Candidates should understand:

  • User account administration

  • Role-based permissions

  • Access management concepts

  • Administrative responsibilities

  • Appropriate privilege assignment

  • Managing access according to organizational requirements

A strong understanding of user management helps candidates recognize how administrative access is organized within Falcon.

Falcon Sensor Deployment and Management

Candidates should understand:

  • Falcon sensor deployment concepts

  • Sensor installation considerations

  • Sensor management

  • Sensor health

  • Sensor coverage

  • Deployment verification

  • Operating system-specific deployment considerations

  • Sensor maintenance concepts

Sensor administration is a fundamental responsibility for Falcon administrators because endpoint protection depends on appropriate sensor deployment and ongoing management.

Host Groups and Organization

Candidates should understand:

  • Group creation

  • Host organization

  • Group hierarchy concepts

  • Using groups to support policy management

  • Assigning endpoints to appropriate groups

  • Maintaining an organized endpoint environment

Well-structured host groups can make policy administration more manageable in larger environments.

Deployment and Prevention Policies

Candidates should understand:

  • Deployment policy configuration

  • Prevention policy configuration

  • Policy assignment

  • Policy management

  • Security settings

  • Policy hierarchy concepts

  • The relationship between policies and host groups

Candidates should be able to distinguish between administrative tasks related to deployment and those associated with endpoint prevention controls.

Allowlists and Blocklists

Candidates should understand:

  • Allowlist configuration

  • Blocklist configuration

  • Appropriate use cases

  • Security implications

  • Managing exceptions

  • Maintaining appropriate security controls

These concepts require careful understanding because changes to security policies can influence endpoint protection behavior.

File-Path Exclusions

Candidates should understand:

  • Exclusion configuration

  • File-path exclusion concepts

  • Appropriate administrative use

  • Security considerations

  • The relationship between exclusions and endpoint protection

Candidates should understand why exclusions require careful management and appropriate administrative controls.

Administrative Reporting

Candidates should understand:

  • Administrative reporting

  • Security coverage reporting

  • Reviewing platform information

  • Using dashboards and reports

  • Identifying coverage gaps

  • Supporting operational visibility

Reporting capabilities help administrators understand the state of the Falcon deployment and communicate relevant information to security and IT stakeholders.

Official Exam Domains Breakdown

CrowdStrike's publicly available CCFA documentation emphasizes role-based Falcon administration rather than presenting a simple percentage-weighted domain table in the available certification guide.

The principal knowledge areas include:

  • User Management

    • User administration

    • Role-based permissions

    • Administrative access

  • Sensor Deployment and Management

    • Sensor installation

    • Sensor deployment

    • Sensor management

    • Sensor coverage

  • Group Management

    • Group creation

    • Host organization

    • Group-based administration

  • Policy Administration

    • Deployment policies

    • Prevention policies

    • Policy configuration

  • Security Exceptions

    • Allowlists

    • Blocklists

    • File-path exclusions

  • Reporting and Administration

    • Administrative reporting

    • Coverage visibility

    • Platform management

Candidates should use the latest official CCFA exam guide for the authoritative domain structure and objective wording applicable to their scheduled exam version. CrowdStrike recommends using its certification exam guides and documentation as part of the preparation process.

Prerequisites

The CCFA certification does not require completion of a mandatory training course before attempting the examination.

However, CrowdStrike recommends that candidates:

  • Have at least six months of experience with the CrowdStrike Falcon platform

  • Understand Falcon administrative functions

  • Review recommended CrowdStrike documentation

  • Follow the recommended Falcon Administrator learning path

  • Have access to the relevant CrowdStrike University resources

  • Review the current CCFA exam guide

  • Meet the certification program's eligibility requirements

The certification guide also states that exam registrants must accept the CrowdStrike Certification Exam Agreement and be at least 18 years old.

Recommended Experience

CrowdStrike recommends approximately six months of experience with the Falcon platform in a production environment.

This experience is valuable because the CCFA focuses on administration tasks that are easier to understand when candidates have familiarity with endpoint security operations.

Recommended experience includes:

  • Managing endpoint security platforms

  • Working with endpoint security policies

  • Administering security tools

  • Managing user permissions

  • Deploying security agents or sensors

  • Working with endpoint groups

  • Reviewing security dashboards

  • Producing administrative reports

Candidates without extensive Falcon experience may need additional time to become familiar with the platform's terminology, navigation, configuration options, and administrative workflows.

Career Opportunities

The CCFA certification can support career paths involving CrowdStrike Falcon administration and endpoint security operations.

Potentially relevant roles include:

  • CrowdStrike Falcon Administrator

  • Security Administrator

  • Endpoint Security Administrator

  • Security Analyst

  • SOC Analyst

  • Security Engineer

  • IT Security Operations Manager

  • Endpoint Security Engineer

  • Cybersecurity Operations Specialist

  • Security Operations Engineer

CrowdStrike's certification materials specifically identify security analysts, SOC analysts, security engineers, IT security operations managers, security administrators, Falcon administrators, and endpoint security administrators as roles aligned with the CCFA certification.

Salary Insights

Salary outcomes depend on factors such as:

  • Job title

  • Geographic location

  • Professional experience

  • Employer size

  • Industry

  • Technical specialization

  • Broader cybersecurity knowledge

  • Cloud and identity security expertise

  • Professional certifications

  • Scope of administrative responsibility

The CCFA should be viewed as a specialized platform certification rather than a guarantee of a specific salary.

Professionals who combine Falcon administration knowledge with broader skills in areas such as endpoint detection and response, security operations, identity security, cloud security, SIEM, incident response, and security engineering may be positioned for a broader range of cybersecurity roles.

Certification Renewal Information

The CCFA certification is valid for three years, according to CrowdStrike's certification guide.

Candidates should monitor official CrowdStrike certification communications for current renewal and recertification requirements because program policies can change.

When planning a certification lifecycle, professionals should:

  • Track the certification expiration date

  • Monitor CrowdStrike University announcements

  • Review current certification policies

  • Check whether a newer certification exam version is available

  • Confirm current renewal requirements before expiration

The three-year validity period is documented in CrowdStrike's certification information.

Exam Registration Process

The CCFA exam registration process generally involves the following steps:

  • Create or maintain the required Pearson account

  • Obtain an exam voucher or arrange payment

  • Review the current CCFA exam information

  • Select a Pearson test center or online Pearson OnVUE appointment

  • Choose an available examination date and time

  • Complete any required identification verification

  • Review Pearson's exam-day requirements

  • Complete the examination

CrowdStrike states that candidates can register through Pearson and choose either a Pearson test center or online OnVUE delivery. Exam vouchers can be purchased through CrowdStrike or obtained through applicable organizational arrangements, while direct credit-card payment may be available during Pearson scheduling.

Preparation Resources

Recommended preparation resources include:

  • Official CrowdStrike CCFA Certification Exam Guide

  • CrowdStrike University

  • Falcon Administrator learning path

  • Falcon platform documentation

  • Falcon Orientation Guides

  • Falcon Sensor Deployment and Maintenance Guides

  • Endpoint Security Guides

  • User Management Guides

  • SIEM Connector Guide

  • CrowdStrike certification practice exams where available

  • CrowdStrike University webinars and eLearning resources

CrowdStrike University provides certification preparation resources, including exam guides, practice exams, webinars, and learning options. CrowdStrike also recommends reviewing relevant Falcon documentation through the platform's Support and Documentation resources.

Study Strategy

An effective CCFA preparation approach can be organized into several stages.

Start With the Exam Guide

Begin by reviewing the current official exam guide.

Identify:

  • Exam objectives

  • Knowledge domains

  • Recommended learning

  • Required terminology

  • Documentation references

Build Platform Familiarity

Focus on understanding how the Falcon platform is organized.

Review:

  • User administration

  • Roles

  • Sensor management

  • Groups

  • Policies

  • Exclusions

  • Allowlisting

  • Blocklisting

  • Reporting

Study by Administrative Function

Organize study sessions around administrative tasks rather than memorizing isolated terminology.

For example:

  • Study user management together with permissions

  • Study sensor deployment together with sensor health

  • Study groups together with policy assignment

  • Study exclusions together with security implications

  • Study reporting together with coverage monitoring

Review Official Documentation

Use current CrowdStrike documentation to strengthen understanding of platform terminology and administrative concepts.

Practice Question Management

The exam contains 60 questions and provides 90 minutes, giving an average of approximately 90 seconds per question.

Candidates should practice:

  • Reading the full question

  • Identifying the administrative objective

  • Eliminating clearly incorrect choices

  • Selecting the most appropriate answer

  • Moving forward when a question takes too long

Review Weak Areas

After practice sessions, identify topics that require additional study.

Prioritize:

  • User permissions

  • Sensor deployment

  • Policy configuration

  • Host groups

  • Security exceptions

  • Reporting

Common Challenges

Candidates may encounter several challenges while preparing for the CCFA-200b exam.

Platform-Specific Terminology

Candidates coming from other endpoint security products may need time to understand CrowdStrike-specific terminology.

Policy Relationships

Understanding how policies, groups, and endpoints relate to one another can require careful study.

Administrative Scope

The certification covers several administrative responsibilities, so preparation should not focus exclusively on sensor deployment or prevention policies.

Security Exceptions

Allowlisting, blocklisting, and exclusions require understanding of both administrative configuration and security implications.

Time Management

With 60 questions in 90 minutes, candidates need to balance careful reading with efficient decision-making.

Changing Platform Features

Cloud-based security platforms evolve continuously. Candidates should prioritize current official documentation and the latest exam guide.

Frequently Tested Topics

Important topics to prioritize include:

  • User management

  • Role-based permissions

  • Falcon sensor deployment

  • Sensor management

  • Sensor health

  • Host groups

  • Group creation

  • Deployment policies

  • Prevention policies

  • Allowlists

  • Blocklists

  • File-path exclusions

  • Endpoint security administration

  • Administrative reporting

  • Security coverage

  • Falcon platform administration

These areas align with the core administrative capabilities described in CrowdStrike's CCFA certification materials.

Exam-Day Tips

Candidates should consider the following exam-day practices:

  • Verify the appointment date and time

  • Confirm identification requirements

  • Review Pearson's current test-center or OnVUE policies

  • Complete the OnVUE system check if taking the exam online

  • Ensure the testing environment meets technical requirements

  • Arrive early for a test-center appointment

  • Keep required identification available

  • Read every question carefully

  • Pay attention to terms that distinguish administrative functions

  • Avoid spending excessive time on a single question

  • Use the full examination time when necessary

  • Review answers when time permits

CrowdStrike recommends completing a system check before an online OnVUE exam because employer-managed computers may have security settings or firewalls that interfere with the testing environment.

Related Certifications

Professionals interested in the broader CrowdStrike certification portfolio may also explore:

  • CrowdStrike Certified Falcon Responder (CCFR)

    • Focuses on responding to detections and security events

  • CrowdStrike Certified Falcon Hunter (CCFH)

    • Focuses on deeper detection analysis, investigation, and threat hunting

  • CrowdStrike Certified SIEM Analyst (CCSA)

    • Focuses on analyzing data and alerts within CrowdStrike's SIEM environment

  • CrowdStrike Certified SIEM Engineer (CCSE)

    • Focuses on implementing and managing CrowdStrike's SIEM capabilities

  • CrowdStrike Certified Identity Specialist (CCIS)

    • Focuses on identity-related security analysis and response

  • CrowdStrike Certified Cloud Specialist (CCCS)

    • Focuses on cloud security administration and security posture management

CrowdStrike's certification portfolio is designed around different security roles and specialized areas of the Falcon platform.

Latest Exam Updates

The CCFA-200b designation should always be verified against the latest official CrowdStrike certification documentation before registration.

Current published information confirms:

  • 60 multiple-choice, single-correct-response questions

  • 90-minute examination duration

  • 80% passing score

  • $250 USD exam voucher price

  • Pearson delivery

  • Pearson test-center and OnVUE online options

  • Three-year certification validity

  • Recommended six months of Falcon experience

CrowdStrike's current training catalog, updated February 20, 2026, continues to list the CCFA examination as 60 questions with a 90-minute duration.

Candidates should verify the exact exam code, current exam guide, price, language availability, delivery options, and renewal policy at the time of registration because certification programs can be updated.

Competitor Gap Sections

Career Roadmap After Certification

A potential career progression for a Falcon-focused cybersecurity professional may include:

  • IT or security support role

  • Security analyst

  • Endpoint security analyst

  • SOC analyst

  • Falcon administrator

  • Endpoint security administrator

  • Security engineer

  • Senior security engineer

  • Security operations leadership

The CCFA can serve as a specialized credential within this progression, particularly when combined with hands-on Falcon administration experience and broader cybersecurity knowledge.

Industry Demand Analysis

Modern organizations increasingly rely on endpoint security platforms to monitor and protect distributed computing environments.

This creates demand for professionals who can:

  • Deploy endpoint security technologies

  • Maintain security configurations

  • Manage endpoint policies

  • Monitor security coverage

  • Support security operations teams

  • Administer user access

  • Maintain endpoint security posture

The value of a platform certification is generally strongest when it is combined with experience in security operations, endpoint security, identity, cloud, and incident response.

Use Cases

Falcon administration knowledge can support organizational activities such as:

  • Managing endpoint security deployments

  • Organizing endpoints into logical groups

  • Applying security policies

  • Managing user permissions

  • Monitoring sensor coverage

  • Managing security exceptions

  • Reviewing administrative reports

  • Supporting endpoint security operations

  • Maintaining consistent configuration across endpoints

Hiring Trends

Employers hiring for endpoint and security operations positions may look for combinations of:

  • Endpoint security experience

  • EDR platform knowledge

  • Security operations experience

  • SIEM familiarity

  • Incident response knowledge

  • Identity security understanding

  • Cloud security knowledge

  • Automation and scripting skills

  • Vendor-specific certifications

The CCFA is most valuable when it demonstrates specialized Falcon expertise alongside broader cybersecurity capabilities.

Certification Comparison

Certification

Primary Focus

Best Suited For

CCFA

Falcon platform administration

Falcon administrators and security administrators

CCFR

Detection response

Incident responders and SOC analysts

CCFH

Investigation and threat hunting

Threat hunters and investigative analysts

CCSA

SIEM analysis

SIEM analysts

CCSE

SIEM engineering

SIEM engineers

CCIS

Identity security

Identity security professionals

CCCS

Cloud security

Cloud security professionals

The CCFA is the most directly aligned option for professionals whose responsibilities center on administering the Falcon platform.

Success Stories

A certification success story typically begins with a clear role objective and structured preparation.

A professional working in endpoint security, for example, may use the CCFA certification to formalize knowledge gained through Falcon administration responsibilities. By combining platform experience with the certification, the professional can demonstrate knowledge of user management, sensors, groups, policies, exclusions, and reporting.

Another candidate may use the CCFA as a specialization within a broader cybersecurity career. Experience in SOC operations, endpoint security, or security engineering can provide a foundation for understanding Falcon administration.

The strongest outcomes generally come from combining certification with demonstrable technical experience, continuous learning, and broader cybersecurity capabilities.

Conclusion

The CrowdStrike Certified Falcon Administrator (CCFA) certification is a specialized credential for professionals responsible for administering the CrowdStrike Falcon platform. The CCFA-200b exam currently consists of 60 questions, provides 90 minutes, requires an 80% passing score, and costs $250 USD. The certification is delivered through Pearson and is valid for three years.

For candidates pursuing the CCFA Certification, the strongest preparation strategy is to combine official CrowdStrike University resources, the current CCFA exam guide, relevant Falcon documentation, and practical experience with platform administration. A focused understanding of user management, sensor deployment, groups, policies, exclusions, allowlists, blocklists, and reporting can provide a strong foundation for the CCFA Exam and for professional responsibilities as a CrowdStrike Falcon Administrator.

Frequently Asked Questions