endpoint security Archives - Certification Box https://www.certificationbox.com/tag/endpoint-security/ Prepared Well With Certification Box Tue, 08 Sep 2026 02:52:41 +0000 en-US hourly 1 https://wordpress.org/?v=7.1 https://www.certificationbox.com/wp-content/uploads/2026/04/cropped-CertificationBox-Mini-Logo-32x32.png endpoint security Archives - Certification Box https://www.certificationbox.com/tag/endpoint-security/ 32 32 The CrowdStrike Falcon Administrator Certification Is a Console Exam https://www.certificationbox.com/2026/09/08/crowdstrike-falcon-administrator-certification-ccfa/ Tue, 08 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=30810 Responder asks what you would do about the alert. Administrator asks how the platform that raised it was configured. CCFA-200b covers roles, sensors, host groups, prevention and containment policy, custom rules and workflows, and it wants 48 of 60 right.

The post The CrowdStrike Falcon Administrator Certification Is a Console Exam appeared first on Certification Box.

]]>

Two CrowdStrike credentials get mixed up more than any others, and they ask opposite questions about the same alert. The Responder exam asks what you would do about it. The Administrator exam asks how the platform that raised it was set up, which policy allowed the behaviour through, and who had the console permission to change that.

CCFA-200b is the second one. Its eight sections cover roles and API keys, sensor installation and troubleshooting, host groups, prevention and containment policies, custom detection rules, dashboards and automated workflows. Nothing on it asks you to investigate an incident. This walkthrough covers what the CrowdStrike Falcon Administrator certification tests, how it is scored, and where it sits among the eight credentials CrowdStrike publishes.

What Is the CrowdStrike Falcon Administrator Certification?

The CrowdStrike Falcon Administrator certification, exam code CCFA-200b, validates the ability to run the Falcon platform rather than to investigate what it finds. It covers eight areas: user management, sensor deployment, host management and setup, group creation, policy application, rules configuration, dashboards and reports, and workflows. CrowdStrike aims it at administrators and at analysts who hold administrative console access.

Every section describes something you do inside the Falcon console. There is no malware analysis on this paper, no memory forensics, no scripting language to learn. What there is instead is a long list of configuration decisions and their consequences, which is a different kind of difficulty and one that rewards having administered a real tenant.

CrowdStrike recommends at least six months of experience with the platform in a production environment before attempting it. That recommendation reads as genuine rather than promotional once you look at the objectives, several of which are about predicting the effect of a setting rather than knowing where the setting lives.

Where Does CCFA Sit Among the CrowdStrike Certifications?

CrowdStrike publishes eight certifications: six platform credentials covering Practitioner, Administrator, Responder, Hunter, SIEM Analyst and SIEM Engineer, and two specialist credentials for Identity and Cloud. CCFA is the administration credential in that set, and it is the one concerned with configuring the platform rather than working the alerts it produces.

The questions the CrowdStrike Falcon Administrator exam asks compared with the Responder exam

The distinction matters when choosing. Responder and Hunter are analyst credentials: they assume the platform is already configured and ask what you make of what it shows you. Administrator assumes the alerts will arrive and asks whether the tenant is set up so that the right ones do. Two people in the same SOC can reasonably sit different exams.

The full map is published on CrowdStrike’s own Falcon certification programme page, which also names the recommended learning path for each credential. None of the eight is marked retired, so the whole set is currently attainable.

For a candidate already holding an analyst credential, CCFA is genuinely additive rather than a step down. The two skill sets overlap less than the shared platform suggests, and the objectives here are the ones most likely to be missing from an analyst’s day to day.

What Are the CCFA-200b Exam Details?

CCFA-200b carries 60 questions in 90 minutes, costs 250 US dollars, and requires 80 percent to pass. It is booked through Pearson VUE. That combination, a high bar over a moderate number of items, means there is very little room to be uncertain across the eight sections.

Field Value
Exam name CrowdStrike Falcon Administrator
Exam code CCFA-200b
Number of questions 60
Duration 90 minutes
Passing score 80 percent
Price 250 US dollars
Scheduling Pearson VUE

Ninety minutes for 60 questions gives ninety seconds an item, which is workable. The pressure on this paper does not come from the clock. It comes from the mark you have to reach, and from the fact that CrowdStrike publishes no weightings, so there is no small section you can afford to leave alone.

Because the margin is narrow, timed rehearsal is worth more here than on most papers. Working through CCFA-200b sample questions against the 80 percent bar rather than a comfortable 70 tells you whether you are actually ready.

Why Is the Pass Mark Set at 80 Percent?

Eighty percent of 60 questions is 48 correct answers, leaving a margin of twelve. Spread across eight sections that works out at roughly one and a half questions per section, so a single topic you have skipped entirely can put the result out of reach before the clock is even a factor.

The reason for the height of the bar is visible in the objectives themselves. Almost every one of them describes a change that affects a live security posture: disabling detections for a host, adjusting prevention policy settings, configuring containment exclusions, releasing a quarantined file. A partially informed administrator making those changes is a genuine risk, which is not true of every certification subject.

Practically, it changes how you should treat your weakest section. On a 62 or 70 percent exam you can accept one soft area and pass on the strength of the rest. At 80 percent that arithmetic stops working, because the twelve questions you can lose are the entire budget for careless errors, ambiguous wording and genuine gaps combined.

There is one consolation. Sixty questions is a small enough set that the sections cannot be sampled deeply, so breadth beats depth here. Knowing something about every objective is a better strategy than knowing three sections thoroughly.

What Does the Sensor Deployment Section Expect?

The sensor deployment section covers four things: determining the prerequisites for a successful Falcon sensor installation across supported operating systems, analysing default policies and preparing workloads, uninstalling a sensor, and troubleshooting one. It is the section closest to traditional endpoint administration and the one most likely to appear as a scenario.

Prerequisites carry more weight than they sound like they should. Sensor installation depends on operating system version, on connectivity to the cloud, and on the customer identifier being supplied correctly, and a question describing a failed rollout is usually testing which of those was missed.

Uninstallation is a named objective in its own right, which is unusual and worth noticing. Removing a sensor is not simply the install in reverse, and the exam expects you to know the controls that stop it happening accidentally.

Reduced Functionality Mode is the sleeper topic

The host management section names Reduced Functionality Mode three separate times: explaining its impact, explaining its causes, and locating hosts that are in it. Three references to one concept in a blueprint that names most things once is the clearest weighting signal this exam gives you. A sensor in RFM is still installed and still reporting, but is not doing the job you think it is doing, which is exactly the sort of state an administrator is expected to find and fix.

How Much of the Exam Is Policy Configuration?

Policy application is the largest section by objective count, with six named items covering prevention policy settings and their effect on security posture, sensor update policy, applying roles and policies alongside Falcon RTR audit logs, containment policy behaviour, containment exclusions for IP addresses and subnets, and quarantined file management.

Prevention policy is the heart of it. These settings decide what the sensor blocks rather than merely reports, so a question about them is usually framed as a consequence: given this configuration, what happens when this behaviour occurs. Knowing where the toggles are is not enough, because the exam asks what turning them on does to the estate.

Containment is the pair to it and is frequently misread. Containing a host cuts its network communication while leaving it reachable by the platform, and the exclusion list for IP addresses and subnets is what keeps essential connectivity alive during that period. Configuring the exclusions is a named objective, which tells you the exam expects the operational detail and not just the concept.

Sensor update policy is the quiet one, and it is the objective most likely to be under prepared. It governs how and when sensors move between versions, which is an availability decision as much as a security one, and administrators who inherited a working tenant often never touch it.

What Do You Need to Know About IOA and IOC Rules?

The rules configuration section asks you to create custom indicator of attack rules for monitoring non malicious behaviour, to interpret business requirements so that trusted activity is allowed and false positives are resolved, to assess indicator of compromise settings for a customised security posture, and to understand management configurations that apply across the whole customer identifier.

The distinction between the two indicator types is the concept the section turns on. An indicator of compromise is an artefact: a hash, a domain, an address that has been seen before. An indicator of attack describes behaviour, a sequence of actions that looks like an attack whether or not anything on the list has appeared. The behavioural taxonomy behind that idea is maintained independently by MITRE ATT&CK, and reading a few technique entries there is the fastest way to make custom rule writing feel less arbitrary.

The false positive objective is the one that reads like real work, because it is. Interpreting a business requirement means someone in the organisation needs a piece of software to do something that looks suspicious, and your job is to allow exactly that without opening a hole. Exam questions of this shape give you the requirement and ask which mechanism fits.

Customer identifier wide configuration closes the section. Some settings apply to a single host group and some apply to the entire tenant, and knowing which is which prevents an answer that is right in scope but wrong in reach.

Which Console Pages Should You Have Actually Used?

Several CCFA objectives name a specific console page and expect operational familiarity with it rather than knowledge of what it is for. Host Management appears with its filtering behaviour named explicitly. Roles and permissions appear as a creation task. API key management appears as its own objective, as do sensor reports, audit log types and workflow triggers.

Four Falcon console areas named in the CCFA-200b blueprint: roles, sensors, host groups and policies

Filtering on the Host Management page is the clearest example of the pattern. The objective is not to know that filtering exists; it is to understand how it is used, which in practice means finding inactive sensors, finding hosts in a degraded state, and knowing the retention period after which an inactive sensor disappears from view. All three are separately named objectives that resolve on the same screen.

Workflows are the newest part of the blueprint and the shortest, with a single objective about configuring a workflow to respond to a defined trigger. Short does not mean absent, and on a paper with a twelve question margin a single unfamiliar objective is a real cost. The wider platform context is set out on CrowdStrike’s Falcon platform overview.

If you have never worked in an endpoint detection and response product at all, the category background is worth an hour before the exam material, and the neutral EDR overview covers what these tools are for without a vendor frame. For how the neighbouring credential reads by comparison, our walkthrough of the CCFH Falcon Hunter exam shows the analyst side of the same platform.

How Should You Prepare for the CCFA Exam?

Preparation for CCFA works best inside a real or trial Falcon tenant, because most objectives describe a configuration change and its consequence rather than a fact. Cover all eight sections before going deep on any of them, since the 80 percent bar punishes a missing topic far more than it punishes a shallow one.

  1. Read all eight sections of the blueprint first and mark every objective you have never performed, because at a twelve question margin those are the ones that decide the result.
  2. Work through roles and permissions in the console, creating a role, assigning a user to it, and generating an API key, so user management is muscle memory rather than theory.
  3. Install a sensor on each supported operating system you can reach, then uninstall one and deliberately break another so that troubleshooting and Reduced Functionality Mode are things you have seen.
  4. Build host groups and attach different prevention and sensor update policies to them, then predict and check what each setting changes about the security posture.
  5. Configure a containment policy with an IP or subnet exclusion, contain a test host, and confirm what still communicates while it is contained.
  6. Write a custom indicator of attack rule for a benign behaviour, then resolve the false positives it produces, since that loop is exactly what the rules objectives describe.
  7. Finish on dashboards, audit logs and a single workflow trigger, then rehearse against the 80 percent bar rather than a comfortable score.

The recommended course path sits in CrowdStrike University, and the wider set of credentials is mapped on our CrowdStrike certification hub for anyone still deciding which one to sit.

Frequently Asked Questions

How many questions are on the CCFA-200b exam?

Sixty questions in 90 minutes, which is ninety seconds per item. The time is comfortable; the pass mark is what makes the paper hard.

What is the passing score for the CrowdStrike Falcon Administrator exam?

Eighty percent, which is 48 correct answers out of 60. That leaves a margin of twelve questions across eight sections.

How much does the CCFA certification cost?

250 US dollars, booked through Pearson VUE.

What is the difference between CCFA and CCFR?

CCFA is the administrator credential and covers configuring the Falcon platform: roles, sensors, host groups, policies and rules. CCFR is the responder credential and covers working the detections the platform produces. They test opposite halves of the same alert.

How much Falcon experience is recommended before CCFA?

CrowdStrike suggests at least six months with the platform in a production environment. Several objectives ask you to predict the effect of a setting, which is difficult to answer from reading alone.

Are the CCFA domains weighted?

No percentages are published for the eight sections. The nearest weighting signal is that Reduced Functionality Mode is named three separate times and policy application carries six objectives, more than any other section.

Does the exam cover custom detection rules?

Yes. Creating custom indicator of attack rules, assessing indicator of compromise settings, and resolving false positives against a business requirement are all named objectives in the rules configuration section.

What is Reduced Functionality Mode?

A state in which a Falcon sensor is installed and reporting but not operating with full capability. The blueprint asks you to explain its impact, explain its causes, and locate hosts that are in it.

How many CrowdStrike certifications are there?

Eight: six platform credentials covering Practitioner, Administrator, Responder, Hunter, SIEM Analyst and SIEM Engineer, plus two specialist credentials for Identity and Cloud.

Is CCFA worth taking if you already hold an analyst credential?

The overlap is smaller than the shared platform suggests. An analyst credential assumes the tenant is configured; CCFA is about the configuration itself, including policy design, containment exclusions and sensor update control, which many analysts never touch.

Conclusion

The CrowdStrike Falcon Administrator certification is a console exam with a high bar. Sixty questions in 90 minutes, 250 US dollars, 80 percent to pass, and eight unweighted sections running from roles and API keys through sensor deployment, host groups, prevention and containment policy, custom rules, reporting and workflows.

Prepare it inside a tenant rather than a book. Break a sensor so you have met Reduced Functionality Mode, contain a host so you understand what an exclusion protects, and write a rule that produces false positives so you have had to resolve them. Then rehearse against 48 out of 60 rather than a comfortable score, because on this paper twelve wrong answers is the entire budget.

Rating: 0 / 5 (0 votes)

The post The CrowdStrike Falcon Administrator Certification Is a Console Exam appeared first on Certification Box.

]]>