CrowdStrike · CCFA
Validates skills in administering the CrowdStrike Falcon platform, including sensor deployment, policy configuration, host management, and security operations. Designed for administrators and analysts with hands-on experience managing the Falcon environment.
Practice Questions
600
≈ 9 practice exams
Duration
90 minutes
Passing Score
80%
Difficulty
AssociateLast Updated
Aug 2026
Use this CCFA practice exam to prepare for CrowdStrike Certified Falcon Administrator (CCFA) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 600 questions for CrowdStrike CCFA, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to recurring topics such as User Management and Role-Based Access Control, Sensor Deployment (Windows, Linux, macOS), Host Management and Endpoint Monitoring, Prevention Policies and Custom IOA Rules, and IOC Management and Containment Policies. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The CrowdStrike Certified Falcon Administrator (CCFA) is an associate-level certification that validates an individual's competency in managing and administering the CrowdStrike Falcon platform. The credential demonstrates proficiency across the full administrative lifecycle of Falcon, including deploying and managing sensors across Windows, Linux, and macOS endpoints, configuring prevention and containment policies, managing indicators of compromise (IOCs), building custom IOA rules, and leveraging Real-Time Response for live endpoint interaction.
Issued by CrowdStrike University and delivered through Pearson VUE, the CCFA is a vendor-specific credential that maps directly to hands-on platform skills rather than abstract security theory. It covers 15 distinct administrative domains—from user management and role-based access control to API client configuration and notification workflows—making it a comprehensive validation of day-to-day Falcon administration. The certification is valid for approximately two years, after which recertification is required to reflect platform updates.
The CCFA is specifically designed for administrators, security analysts, and IT professionals who work with the administrative side of the CrowdStrike Falcon platform. This includes SOC analysts who manage endpoint telemetry and detections, security operations administrators responsible for sensor deployment and policy governance, and IT staff who handle endpoint protection at the organizational level.
The certification is best suited for professionals already working in environments where Falcon is deployed, particularly those in roles such as endpoint security administrator, security operations analyst, or managed security service provider (MSSP) technician. It is also valuable for security engineers at organizations that have standardized on CrowdStrike for endpoint detection and response (EDR).
CrowdStrike does not mandate formal prerequisites for the CCFA exam, but strongly recommends that candidates have a minimum of six months of hands-on experience administering the Falcon platform in a production environment. This practical experience is considered essential, as the exam focuses on real-world administrative scenarios rather than conceptual knowledge.
Candidates are also encouraged to complete relevant training through CrowdStrike University before attempting the exam. A working understanding of endpoint security concepts, operating system administration across Windows, Linux, and macOS, and familiarity with security operations workflows will provide meaningful preparation. English language proficiency sufficient to comprehend technical security content is also expected.
The CCFA exam (code CCFA-200) consists of 60 multiple-choice questions and must be completed within a 90-minute time limit. The exam is scored on a pass/fail basis with a passing threshold of 80%. Questions are designed around real-world administrative scenarios encountered when managing the Falcon platform, emphasizing practical decision-making over rote memorization.
The exam is administered through Pearson VUE and is available via two delivery options: online proctored (OnVUE), which allows candidates to test from a home or office environment after completing a system compatibility check, or in-person at an authorized Pearson VUE Testing Center (PVTC). The exam fee is $250 USD. Candidates must ensure the name on their registration matches a government-issued ID.
The CCFA credential signals verified, platform-specific expertise in the market's leading endpoint detection and response solution — CrowdStrike protects over 70% of Fortune 100 companies, which means CCFA-certified professionals are in demand across enterprise, government, financial services, and managed security service provider sectors. Roles commonly held by CCFA-certified professionals include Falcon Administrator, SOC Analyst, Endpoint Security Engineer, and Security Operations Manager. Salary ranges for CrowdStrike-certified professionals broadly span from approximately $95,000 to over $130,000 annually at the administrator level, with senior and specialist roles commanding significantly higher compensation.
Beyond immediate job market value, the CCFA serves as a foundation for the broader CrowdStrike certification track, with more advanced credentials such as the CrowdStrike Certified Falcon Responder (CCFR) and CrowdStrike Certified Falcon Hunter (CCFH) building on the administrative knowledge validated by this exam. Organizations increasingly require vendor-specific certifications when hiring for Falcon-centric roles, making the CCFA a practical differentiator in competitive SOC and endpoint security hiring processes.
5 sample questions with answers and explanations. The full bank has 600 questions, enough for 9 full-length practice exams.
Preview — answers shown1. A compliance officer at Adatum Financial requests an audit trail showing every administrative change made to Falcon prevention policies over the past 30 days. The report must identify which administrator account made each change, what specific action was taken, and the exact timestamp of each change. Which resource in the Falcon console provides this information? (Select one!)
Explanation
The Audit Log in the Falcon console records all administrative configuration changes performed within the platform, including modifications to prevention policies, sensor update policies, user management actions, API client changes, role assignments, and other administrative events. Each entry captures the specific user account that performed the action, a description of what was changed, and the precise timestamp — exactly the information required for compliance auditing of prevention policy changes over a defined time period. The Incident Activity log tracks detection and incident response events such as new detections, alert status changes, and response actions taken by analysts, not administrative configuration changes made by administrators. The Sensor Health Dashboard displays sensor telemetry metrics and health status information, not a history of administrative configuration changes. Host Management Policy Assignments shows the current state of which policies are assigned to which host groups but does not provide a historical change record of which administrator modified a policy and when.
2. A threat intelligence team at Harrington Defense has confirmed a new malware executable associated with an active threat campaign. The indicator is a SHA-256 file hash that must be blocked from executing on Windows servers only, and each prevention event must generate a detection alert for the SOC. A Falcon administrator is creating the IOC in the platform. Which two settings must be applied when configuring this indicator? (Select two!)
Multiple correct answersExplanation
The Prevent action instructs the IOC evaluation engine to block the matched file from executing and simultaneously generates a detection alert for the SOC, satisfying both the blocking and alerting requirements with a single action setting. The Detect action generates a detection alert without blocking execution and would not satisfy the prevention requirement in this scenario. The Allow action explicitly whitelists the file, which is the opposite of the desired behavior. Scoping the IOC to the Windows platform ensures the indicator is evaluated exclusively on Windows endpoints, precisely matching the requirement to block the hash on Windows servers only. Scoping to All Platforms would cause the IOC to be evaluated on Linux and macOS endpoints as well, potentially disrupting legitimate use of files that share the same hash on non-Windows systems and falling outside the stated operational scope. IOC platform scoping is enforced independently per platform — an IOC scoped to Windows has no effect on Linux or macOS hosts regardless of other configuration settings.
3. A Falcon administrator at Northgate Publishing is deploying the CrowdStrike Falcon sensor to a fleet of macOS endpoints managed through Apple Business Manager. After completing package installation on several MacBook Pros, the administrator notices the sensor status displays as Limited in the Falcon Console. Installation tokens were provided and the CID was correctly configured during deployment. What step must be completed to bring the sensors to full operational status? (Select one!)
Explanation
macOS requires explicit system extension approval before the Falcon sensor can load its protective components and operate at full capacity. Without this approval, the sensor installs but cannot access the kernel interfaces it needs, resulting in a Limited status. In a fleet managed through Apple Business Manager, the correct method is to push the system extension approval via MDM policy, which applies the approval silently to all managed devices without requiring user interaction. Re-running falconctl to set the CID would only matter if CID registration had failed — the Limited status here specifically indicates a system extension approval issue, not a connectivity or registration problem. Proxy configuration affects network connectivity but not the sensor's ability to load its kernel components. Rebooting is not required for Falcon sensor installation on any supported platform; the missing system extension approval is the root cause.
4. A compliance manager at Adatum Healthcare requires a weekly automated report showing all Falcon sensors running versions older than the current release, organized by operating system platform. The report must be emailed to a security distribution list every Monday morning without any manual steps from the administrator after initial configuration. Which approach should the Falcon administrator use? (Select one!)
Explanation
The Falcon console provides native scheduled report functionality that supports sensor and host data with filtering by agent version and operating system platform. Once configured, the report is generated and emailed automatically to the specified recipients on the defined schedule, requiring no ongoing administrator involvement. This is the simplest, most maintainable, and fully native solution for recurring compliance reporting within the Falcon platform. A Falcon Fusion SOAR workflow with a scheduled trigger could technically accomplish this task but introduces unnecessary complexity when the built-in scheduled report feature covers the requirement directly. External cron jobs and API scripts create additional infrastructure dependencies, operational overhead, and maintenance burden outside the Falcon platform. Manual exports require administrator action on each cycle, are not automated, and fail the stated requirement of no manual steps after initial setup.
5. During an active security incident at Adatum Corporation, a Falcon administrator places a compromised Windows host into network containment. The remediation team immediately reports they can no longer reach the internal DNS server at 10.0.1.5 or the patch management system on the 10.0.2.0/24 subnet, both of which are required for the cleanup process. What is the correct way to restore these specific connections while keeping the host contained? (Select one!)
Explanation
Containment policy IP/subnet exclusions allow specific internal IP addresses or subnets to remain accessible while a host is in network containment. This enables remediation workflows by permitting connections to trusted internal systems such as DNS servers and patch management infrastructure without releasing the host from isolation entirely. The CrowdStrike Cloud connection is always maintained during containment and does not need to be added as an exclusion. Releasing the host to configure firewall exceptions would expose it to network threats during the gap and adds unnecessary steps when exclusions achieve the same result while containment remains active. IOC allowlists control how the platform handles file hashes and behavioral indicators of compromise, not network traffic during containment. Prevention policies govern endpoint detection and blocking behavior and play no role in managing network isolation rules during active containment.
$17.99
One-time access to this exam