Ccfa Certification Exam Guide: Crowdstrike University
Ccfa Certification Exam Guide: Crowdstrike University
CCFA CERTIFICATION
EXAM GUIDE
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
DESCRIPTION
The CrowdStrike Certified Falcon Administrator (CCFA) exam is the final step toward the completion of CCFA
certification. This exam evaluates a candidate’s knowledge, skills and abilities to manage various components of the
CrowdStrike Falcon® platform on a daily basis, including sensor installation.
Contact your CrowdStrike Account Executive to request a quote or purchase a CrowdStrike exam voucher through
Pearson VUE.
UNIVERSITY SUBSCRIPTION
It is strongly suggested that all exam registrants have an active subscription to CrowdStrike University and have
confirmed access to their CrowdStrike University account.
CrowdStrike certification-aligned courses are available to learners with an active CrowdStrike University account.
A unique CrowdStrike Certification ID, training transcripts and printable certification documents are available
through CrowdStrike University learning management system.
NOTE: All exam takers can view and print their CrowdStrike certification exam score report through Pearson VUE.
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
INITIAL CERTIFICATION
To be eligible for certification, candidates must:
In the event of misconduct by the candidate, CrowdStrike may invalidate the score and consider any suspicious action
a violation of the CrowdStrike Certification Exam Agreement.
When a candidate has completed the exam and the candidate's official exam score has been posted, the certification
candidate may view the official exam score at Pearson VUE.
RETAKE POLICY
Candidates who do not pass an exam on their first (1st) attempt:
Must wait 48 hours to retake the exam (wait time begins after the exam)
Should review the exam objectives, training course materials and associated recommended reading listed in this
document.
After the second (2nd) attempt, a candidate will need to wait seven (7) days for the third (3rd) attempt and any
subsequent attempts. Wait time begins the day after the attempt.
Candidates that want to retake the exam should consider re-sitting the applicable recommended course(s) and gain
additional experience with CrowdStrike Falcon before trying again.
Retakes beyond the fourth (4th) attempt will be considered on a case-by-case basis. CrowdStrike reserves the right to
deny a retake beyond the 4th attempt. If the 4th attempt is a failure due to a technical issue the student can reattempt
for a 5th time.
If the student fails for a 4th time due to personal performance, they must wait 30 days and retake the recommended
training indicated in the exam guide. CrowdStrike will verify that the candidate has retaken the recommended training
in the exam guide and has met with the CS Certification Manager before clearing him or her to register for a 5th exam
attempt.
Beta Exams
Candidates will not be permitted to retake beta exams.
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
EXAM CHALLENGE
If a certification candidate believes there is an error on an exam or that specific questions on the CCFA exam are
invalid, contact [email protected] to request an evaluation of your claim. The certification candidate must
submit a claim within three (3) days of taking the exam for it to be considered. CrowdStrike will generally respond to
your submission within fifteen (15) business days.
RECERTIFICATION
Certification exams are not tied to product versions. The following lifecycle will apply to recertification moving forward,
beginning with the date the certification was issued:
EXAM PREPARATION
RECOMMENDED TRAINING
CrowdStrike strongly recommends that certification candidates complete these CSU LP-A: Falcon Administrator
Courses in CrowdStrike University AND attain six months practical experience to prepare for the CCFA exam. The
courses listed below reflect the current learning path for the CrowdStrike Administration certification:
C
rowdStrike University Orientation
FHT 100: Falcon Platform Architecture Overview
FHT 101: Falcon Platform Technical Fundamentals
FHT 102: Falcon Platform Onboarding Configuration
F
HT 104: Activity App Fundamentals
F
HT 105: Sensor Installation, Configuration and Troubleshooting
FHT 106: Custom Dashboards
FHT 107: Falcon Firewall Management
F
HT 121: Falcon Spotlight Fundamentals
FHT 122: Falcon Discover Fundamentals
F
HT 160: Falcon for Mobile
FHT 200: Falcon Platform For Administrators
To learn more about these courses, view the CrowdStrike Training Catalog. CrowdStrike also recommends that
candidates physically access the Falcon console and perform the exam objectives listed below to prepare for the
exam.
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
RECOMMENDED READING
CrowdStrike strongly recommends certification candidates review the following CrowdStrike Falcon Support
Documentation titles to prepare for the CCFA exam:
EXAM SCOPE
The following topics provide a general guideline for the content likely to be included on the exam; however, other
related topics may also appear on any specific delivery of the exam.
1. User Management
2. Sensor Deployment
3. Host Management
4. Group Creation
5. Prevention Policies
6. Custom IOA Rules
7. Sensor Update Policies
8. Quarantine Files
9. IOC Management
10. Containment Policies
11. Exclusions
12. Firewall Policies
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
SCOPE CHANGES
In order to better reflect the content of the exam and for clarity purposes, the guidelines below may change at any time
without notice. Such changes may include, without limitation, adding or deleting an available CrowdStrike certification,
modifying certification requirements, and making changes to recommended training courses, testing objectives,
outline and exams, including, without limitation, how and when exam scores are issued. The certification candidate
agrees to meet (and continue to meet) the program requirements, as amended, as a condition of obtaining and
maintaining the certification.
EXAM OBJECTIVES
The following subtopics and learning objectives provide further guidance on the content and purpose of the exam:
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
11.0 EXCLUSIONS
11.1 Interpret business requirement in order to allow trusted activity and resolve false positives and performance
issues
11.1.1 Write an effective file exclusion rule using glob syntax
11.1.2 Apply File Pattern Exclusions to groups
11.1.3 Demonstrate how to manage exclusion rules
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
Last Updated: Sept. 9, 2021 2021 CrowdStrike, Inc. All rights reserved.