
CrowdStrike Certified Falcon Administrator (CCFA)
The CrowdStrike Certified Falcon Administrator (CCFA) certification validates your ability to configure, manage, and optimize the CrowdStrike Falcon platform. It is designed for administrators and analysts who work on the administrative side of Falcon, proving they can handle day-to-day platform operations and maintain a strong security posture. Earning the CCFA demonstrates you have the hands-on skills to keep your organization's Falcon deployment running effectively.
529 practice questions · Updated 2026-08-04
8Domains
30Objectives
139Concepts
529Questions
CCFA Curriculum
Every domain, objective, and concept the CCFA exam measures.
- Role-based access control (RBAC) in Falcon
- Built-in Falcon roles
- Custom roles
- Role assignment to users
- Feature-to-role mapping
- Role creation
- Permission assignment
- User assignment to roles
- Role management
- API Key Creation
- API Key Permissions
- API Key Rotation
- API Key Revocation
- API Key Monitoring
- Operating System Compatibility
- Hardware Requirements
- Software Dependencies
- Network and Connectivity Prerequisites
- System Configuration Prerequisites
- Permission and Administrative Rights
- Antivirus and Security Software Conflicts
- Installation Method Selection
- Default Falcon sensor policies
- Best practices for workload preparation
- Analyzing policy impact on sensor deployment
- Uninstall process overview
- Uninstall on Windows
- Uninstall on macOS
- Uninstall on Linux
- Maintenance token requirement
- Verifying uninstallation
- Sensor troubleshooting overview
- Diagnosing sensor connectivity issues
- Resolving sensor installation and registration failures
- Handling sensor update and version mismatches
- Interpreting sensor status and health indicators
- Collecting and analyzing sensor logs
- Applying sensor troubleshooting commands
- Escalating unresolved sensor issues
- Purpose of filtering
- Filter types
- Applying filters
- Combining filters
- Saving and managing filter views
- Clearing filters
- Disable detections for a host
- Access host management settings
- Disable detections procedure
- Re-enable detections
- Impact and considerations
- Disabling detections
- Impact on detection visibility
- Impact on prevention and response
- Re-enabling detections
- Definition of Reduced Functionality Mode (RFM)
- Causes of RFM
- Impact of RFM on Host Protection
- Impact of RFM on Sensor Operations
- Recovery from RFM
- Understanding RFM (Reduced Functionality Mode)
- Locating hosts in RFM
- Interpreting RFM host details
- Taking action on RFM hosts
- Identify inactive sensors
- Locate inactive sensors in the console
- Interpret inactive sensor status
- Take action on inactive sensors
- Inactive sensor retention period
- Factors affecting retention
- Administrative actions on inactive sensors
- Identify host management reports
- Access and generate host reports
- Interpret report data
- Export and share reports
- Group assignment criteria
- Policy inheritance and precedence
- Impact of group changes on policy application
- Host Group Naming Conventions
- Host Group Hierarchy Design
- Policy Inheritance and Override
- Host Group Membership Rules
- Host Group Lifecycle Management
- Host Group Permissions and Access Control
- Host Group Monitoring and Auditing
- Prevention policy settings
- Impact on security posture
- Policy configuration best practices
- Sensor update policy settings
- Update control mechanisms
- Policy application to endpoints
- Update process management
- Apply roles
- Apply policy settings
- Track RTR audit logs
- Review RTR audit logs
- Containment Policy Purpose
- Containment Actions
- Policy Configuration
- Policy Application
- Policy Monitoring and Adjustment
- Identify containment policy settings
- Understand IP address and subnet exclusions
- Configure IP address exclusions
- Configure subnet exclusions
- Apply exclusions based on security workflow
- Verify exclusion configuration
- Quarantine Overview
- Quarantine Requirements
- Quarantine Management Options
- Quarantine Workflow
- Custom IOA Rule Fundamentals
- Rule Creation Workflow
- Rule Conditions Configuration
- Rule Logic and Filtering
- Rule Testing and Validation
- Rule Deployment and Management
- Interpret business requirements
- Allow trusted activity
- Resolve false positives
- Fix performance issues
- IOC Settings Overview
- Customizing IOC Rules
- Managing False Positives
- Assessing IOC Impact
- CID-wide management overview
- General Settings navigation
- Configuring CID-wide settings
- Impact of CID-wide settings
- Identify sensor report types
- Describe use cases for each sensor report
- Differentiate between sensor report types
- Identify Falcon audit logs
- Audit log use cases
- Access audit logs
- Interpret audit log entries
- Workflow trigger types
- Trigger configuration
- Trigger conditions
- Trigger testing and validation
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.
Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for CCFA, so none is invented.