To pass the CrowdStrike Certified Falcon Administrator (CCFA) exam, build a three-to-five week study plan anchored on the two highest-weighted domains — Policy Configuration and Management (25%) and Sensor Deployment and Management (20%) — and back it with hands-on time in a Falcon console. Together those two areas are nearly half the exam, so that is where your hours should go first.
This is a free, structured study plan for the CCFA, mapped to the official domain weights. Most free CCFA guidance online comes from question-dump sites; this plan focuses on understanding the platform so you can answer scenario questions you have never seen before.
The Exam at a Glance
The CCFA validates your ability to deploy, configure, manage, and troubleshoot the CrowdStrike Falcon platform. Based on our exam profile:
| Detail | Value | |--------|-------| | Exam code | CCFA-200b | | Questions | 60 | | Duration | 90 minutes | | Passing score | 70% | | Exam fee | $250 USD | | Delivery | Proctored |
With 60 questions in 90 minutes, you have about 90 seconds per question. That is plenty if you know where settings live in the Falcon console and why each policy behaves the way it does.
See the full CCFA exam overview for registration and scoring details.
The Six Domains and Their Weights
Spend your time in proportion to how the exam is weighted:
- Policy Configuration and Management — 25%
- Sensor Deployment and Management — 20%
- User and Access Management — 15%
- Platform Navigation and Core Functionality — 15%
- Detection and Prevention — 15%
- Reporting and Administration — 10%
Policy Configuration is the single largest domain and the heart of the CCFA. This is an administrator exam, not a threat-hunting exam — CrowdStrike separates hunting and response into the CCFH and CCFR credentials. Keep your focus on configuration, deployment, and platform operations.
Our full CCFA study guide breaks down each domain objective in detail.
Who Should Take This Exam (and What to Know First)
The CCFA is CrowdStrike's foundational administrator credential. It fits:
- SOC and security analysts who manage endpoints day to day.
- Endpoint / systems administrators rolling out and maintaining the Falcon sensor.
- Consultants and MSSP staff who configure Falcon for clients.
You don't need to be a malware reverse engineer — CrowdStrike separates deep hunting and incident response into the CCFH (Falcon Hunter) and CCFR (Falcon Responder) exams. For CCFA, you should be comfortable with general endpoint security concepts (EDR, prevention vs. detection), basic operating-system administration across Windows/macOS/Linux, and the idea of role-based access control. The single best preparation is time in an actual Falcon console — most successful candidates administer Falcon at work or use CrowdStrike University lab access.
The 4-Week Study Plan
This plan assumes 5–7 hours per week. Compress to 3 weeks if you already administer Falcon at work, or stretch to 5–6 weeks if you are new to the console. Wherever possible, follow along in a live or trial Falcon environment — CCFA questions are practical.
Week 1 — Platform Navigation + Sensor Deployment
- Learn the Falcon console layout: menus, Host Management, and where core settings live.
- Sensor deployment: installation methods across Windows, macOS, and Linux; sensor update policies; host groups; and sensor tags.
- Understand sensor states, uninstall protection, and maintenance tokens.
- Hands-on: install a sensor, assign it to a host group, and configure a sensor update policy.
Week 2 — Policy Configuration and Management (the big one)
- Prevention policies: how detection and prevention toggles map to behavior, and the difference between detect-only and prevent.
- Sensor update, USB device control, firewall, and response policies — know what each policy type controls.
- Policy precedence and how host groups inherit policies.
- Hands-on: build a prevention policy from scratch and apply it to a host group; test how changing a toggle changes behavior.
Week 3 — User/Access Management + Detection and Prevention
- User and Access Management: roles and role-based access control (RBAC), default roles, and least-privilege assignment. Flag any Falcon Flight Control / multi-CID concepts if relevant to your version.
- Detection and Prevention: how detections surface, severity levels, allowlisting/exclusions, and Machine Learning sliders in prevention policies.
- Hands-on: create a custom role; add an ML exclusion and observe the effect on detections.
Week 4 — Reporting, Administration, and Full Review
- Reporting and Administration: audit logs, scheduled reports, dashboards, and API client basics.
- Take timed, full-length practice tests and review every miss.
- Re-drill Policy Configuration and Sensor Deployment — your two heaviest domains.
How to Get Hands-On Practice
Because the CCFA is practical, console access matters more than any single guide. Options, in rough order of accessibility:
- Your employer's Falcon tenant. If your organization runs Falcon, ask for a read-only or lab role. Even browsing existing policies, host groups, and audit logs builds the pattern recognition the exam tests.
- CrowdStrike University labs. CrowdStrike's official training often includes guided lab environments — the closest match to exam scenarios.
- Documentation walkthroughs. When you can't click, read CrowdStrike's admin documentation while picturing each screen: where the setting lives, what it controls, and what breaks if it's wrong.
Whatever you use, practice doing tasks — create a prevention policy, assign it to a host group, add an exclusion — rather than only reading about them. The exam phrases questions around outcomes ("a host is behaving this way — why?"), and only hands-on reps train that reflex.
Common Mistakes That Cause Failures
- Treating CCFA like a hunting exam. It is administration-focused. Detection and response depth belongs to CCFR/CCFH — do not over-study threat hunting.
- Memorizing dumps instead of the console. ExamTopics-style question banks (last updated March 2026 per ExamTopics) go stale and teach recall, not reasoning. The exam asks where and why, which requires console familiarity.
- Underweighting Policy Configuration. At 25%, it is the most-tested domain. If you are weak here, you are unlikely to pass.
- Ignoring policy precedence and host groups. Many scenario questions hinge on which policy actually applies to a host.
Key Concepts You Must Be Able to Explain
If you can explain each of these clearly, you are ready. Any you can't become your next study session:
- Prevention policy toggles — how detect-only vs. prevent behaves, and how the Machine Learning sliders (detection and prevention) change outcomes.
- Policy types — prevention, sensor update, USB device control, firewall, and response policies, and what each one actually controls.
- Policy precedence — how host groups and policy priority determine which policy applies to a given host.
- Host groups — static vs. dynamic groups and how assignment drives policy inheritance.
- Sensor lifecycle — installation methods per OS, sensor update policies, uninstall protection, and maintenance tokens.
- RBAC — default roles, custom roles, and least-privilege assignment.
- Exclusions — sensor visibility exclusions vs. ML exclusions and when each is appropriate.
- Reporting — audit logs, scheduled reports, and dashboards for administrative oversight.
Exam-Day Tips
- Anchor on Policy Configuration. It is 25% of the exam — if a question is about how a host behaves, think "which policy applies and why."
- Think like an administrator, not a hunter. When two answers look plausible, pick the one a Falcon admin would configure, not the one a threat hunter would investigate.
- Mind policy precedence. Scenario questions often hinge on which of several policies actually takes effect on a host.
- Watch OS-specific details. Deployment and sensor behavior can differ across Windows, macOS, and Linux.
- Pace yourself. ~90 seconds per question across 60 questions — flag the hard ones, bank the easy points, and circle back.
Free Resources to Use
- Our free CrowdStrike CCFA practice questions — scenario-based and mapped to the six domains.
- The CCFA cheat sheet for last-minute review of policy types and sensor concepts.
- The CCFA study guide for domain-by-domain objectives.
- CrowdStrike University courses linked from the official certification page.
Frequently Asked Questions
How long should I study? Three to five weeks for most candidates. If you already administer Falcon at work, three weeks of focused review is enough; if the console is new, budget five to six weeks with plenty of hands-on time.
Do I need CCFA before CCFH or CCFR? CCFA is the administrator foundation and a natural first step, while CCFH (Hunter) and CCFR (Responder) cover threat hunting and incident response. Check CrowdStrike's current certification page for the latest prerequisites, as the program evolves.
Is the CCFA worth it? For SOC analysts and endpoint admins working with Falcon, it is a strong résumé signal in a growing EDR market. See our full breakdown in Is the CrowdStrike CCFA Worth It?.
Can I pass with dumps alone? It's risky. Dump sites teach recall of specific items, but the CCFA asks where a setting lives and why a policy behaves a certain way — that requires real console familiarity.
What score do I need? 70% across 60 questions. There's no guessing penalty, so answer every question.
Final Word
The CCFA rewards administrators who know the Falcon console cold. Put the bulk of your time into Policy Configuration and Sensor Deployment, learn the platform hands-on rather than through dumps, and validate readiness with timed practice.
Ready to check where you stand? Start with our free CrowdStrike CCFA practice questions and aim for 85%+ before booking your exam.