You Can Pass This Exam For Free
Choose Your Study Path
Limited or no hands-on Falcon experience. You need to build foundational knowledge of the platform before tackling admin-level topics.
Exam Overview
Format
60 multiple-choice questions, 90 minutes. Proctored through Pearson VUE testing centers or online.
Scoring
Percentage-based scoring. Passing: 70%. No penalty for wrong answers — always answer every question.
Domains & Weights
- User and Access Management15%
- Sensor Deployment and Management20%
- Platform Navigation and Core Functionality15%
- Policy Configuration and Management25%
- Detection and Prevention15%
- Reporting and Administration10%
Registration
$250 USD. Available at Pearson VUE testing centers or online proctored. Exam fee is $250 USD. Requires a CrowdStrike University account.
Topic Priority Table
Not all topics are tested equally. Focus your study time on Tier 1 first, then Tier 2. Tier 3 topics rarely appear — just recognize what they do.
User and Access Management
This domain covers user account creation, role-based access control (RBAC), SSO/SAML configuration, and API client management. You need to understand predefined roles, custom role creation, and how to manage programmatic access to the Falcon platform.
Key Topics
Must-Know Concepts
- Predefined roles and their permissions: Falcon Administrator (full console access), Falcon Analyst (investigate and triage), Falcon Investigator (deep investigation), RTR Active Responder, RTR Administrator
- How to create local user accounts and assign roles. Know that a user can have multiple roles and permissions are additive
- SSO/SAML configuration basics: setting up an identity provider, metadata exchange, and attribute mapping
- API client creation: OAuth2 client credentials, scope assignment, and the principle of least privilege for API access
- Multi-factor authentication (MFA) enforcement options for console access
- Difference between read and write API scopes and which operations require which scope level
- How to manage API client lifecycle: creation, rotation, and revocation of credentials
Common Exam Traps
Sensor Deployment and Management
This domain covers sensor installation across Windows, macOS, and Linux, including prerequisites, deployment methods, proxy configuration, troubleshooting, and sensor lifecycle management. You need to know OS-specific requirements and best practices for large-scale deployments.
Key Topics
Must-Know Concepts
- Pre-installation requirements per OS: Windows (admin rights, .NET not required), macOS (system extensions approval, MDM profile), Linux (kernel compatibility check)
- Customer ID (CID) is required during installation to register the sensor with your Falcon tenant. The CID includes a checksum
- Sensor installation command-line switches: CID, proxy settings, tagging, and quiet install options
- Sensor update policies: N (latest), N-1 (one version back), N-2 (two versions back). Use N-1/N-2 for staged rollouts in production
- Proxy configuration for environments where endpoints cannot directly reach the CrowdStrike cloud
- Sensor uninstallation: requires an uninstall token (anti-tamper protection) that is generated from the Falcon console
- How to verify sensor health: sensor status in console, RFM (Reduced Functionality Mode) indicators, and connectivity checks
- Deployment at scale using GPO, SCCM, Intune, Jamf, or configuration management tools (Ansible, Puppet, Chef)
Common Exam Traps
Policy Configuration and Management
The heaviest domain at 25%. Covers all policy types: prevention, sensor update, device control, firewall, response, and containment. You must understand each policy type, its settings, and how policies are assigned to host groups with proper precedence.
Key Topics
Must-Know Concepts
- Prevention policy settings in detail: cloud ML slider (disabled, cautious, moderate, aggressive, extra aggressive), sensor ML slider (same options), exploit mitigation, script-based execution monitoring, behavioral IOA prevention
- Prevention policy additional settings: adware/PUP detection, intelligence-sourced signatures, MalQuery detection, and file attribute check
- Sensor update policy options: auto-update (N), N-1, N-2, or specific build pinning. Maintenance windows for update scheduling
- Device control policy: USB mass storage blocking, read-only mode, specific device exceptions by vendor/product ID
- Falcon Firewall Management: rule creation, rule ordering (top-down, first match wins), platform-specific rules, and rule group management
- Response policy settings: RTR enablement, RTR custom script enablement, and remote script execution controls
- Containment: network isolating a host while maintaining CrowdStrike cloud connectivity. IP exclusions for maintaining access to critical services
- Policy assignment to host groups: how policies are linked to host groups and what happens when multiple policies could apply
- Policy precedence: when a host is in multiple host groups with different policies, how CrowdStrike determines which policy applies
- Default policies: every policy type has a default that applies to hosts not assigned to any specific host group
Common Exam Traps
Detection and Prevention
This domain covers how the Falcon platform detects and prevents threats, including alert triage, custom IOA rules, detection tuning, and response actions. You need to understand the detection pipeline and how to manage alerts effectively.
Key Topics
Must-Know Concepts
- Detection pipeline: how events flow from sensor telemetry through cloud analysis to generate detections and prevention actions
- Indicators of Attack (IOAs): behavioral-based detections that identify malicious patterns regardless of the specific malware involved
- Indicators of Compromise (IOCs): hash-based, domain-based, or IP-based indicators uploaded to Falcon for matching against endpoint activity
- Custom IOA rules: creating organization-specific detection rules based on process behavior, file writes, registry modifications, or DNS requests
- Detection severity levels: informational, low, medium, high, critical. Understanding what triggers each level
- Alert triage workflow: reviewing detections, assigning to analysts, setting status (new, in progress, true positive, false positive), and closing
- Quarantine management: viewing quarantined files, releasing false positives, and understanding automatic quarantine behavior
- Custom IOC management: uploading hash-based IOCs (SHA256), setting action (detect or prevent), and applying severity and expiration
Common Exam Traps
Reporting and Administration
This domain covers Falcon reporting capabilities, scheduled reports, dashboard customization, sensor health monitoring, and general administrative tasks. While the smallest domain by weight, it tests practical admin knowledge.
Key Topics
Must-Know Concepts
- Dashboard customization: creating custom dashboards with widgets showing detection trends, sensor health, host coverage, and security posture
- Scheduled reports: configuring recurring reports delivered via email. Options for frequency, content, and recipients
- Sensor health monitoring: identifying offline sensors, RFM hosts, sensors needing updates, and coverage gaps
- Audit log review: tracking administrative actions performed in the Falcon console (policy changes, user creation, exclusion modifications)
- Notification settings: configuring email and webhook notifications for detections, sensor events, and platform alerts
- Host activity data: understanding what telemetry the sensor collects and how long data is retained
Common Exam Traps
Concepts You Must Not Confuse
These pairs appear on nearly every exam. Learn the difference and you'll avoid the most common traps.
Top Mistakes to Avoid
Exam-Ready Checklist
Recommended Resources
Free & Official Resources
Paid Courses & Practice Exams
These are recommended if you prefer a structured learning path. They can save time but are not required to pass.