You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The CrowdStrike Certified SIEM Analyst (CCSA) certification validates your ability to investigate detections and analyze data within the CrowdStrike Falcon® Next-Gen SIEM environment. It is designed for security professionals who use Falcon Next-Gen SIEM to hunt threats, respond to incidents, and support security operations. Earning the CCSA demonstrates that you can effectively leverage CrowdStrike's SIEM capabilities to defend your organization.
Content last reviewed 4 August 2026 · Up to date
What this certification covers, who it is written for, and what the exam itself looks like on the day.
What it validates, who it is written for, and the experience it assumes.
The CrowdStrike Certified SIEM Analyst (CCSA) certification validates the knowledge and skills required to investigate detections and analyze data within the CrowdStrike Falcon® Next-Gen SIEM environment. It is designed for security professionals who are responsible for monitoring, hunting, and responding to threats using Falcon Next-Gen SIEM. This role-based certification confirms your ability to use the platform's search, correlation, and visualization capabilities to uncover malicious activity and support incident response.
Earning the CCSA demonstrates that you can effectively navigate the Falcon Next-Gen SIEM interface, build queries, analyze event data, and interpret results to identify and respond to security incidents. The certification is part of the CrowdStrike Falcon Certification Program, which validates proficiency across Falcon user disciplines. By achieving the CCSA, you prove your expertise in using CrowdStrike's SIEM solution to strengthen your organization's security posture.
The CrowdStrike Certified SIEM Analyst (CCSA) certification is directed at security professionals responsible for investigating detections and analyzing data within the CrowdStrike Falcon® Next-Gen SIEM environment. This includes security operations center (SOC) analysts, incident responders, threat hunters, and other security practitioners who use Falcon Next-Gen SIEM to monitor and respond to threats. Ideal candidates are those who work with Falcon Next-Gen SIEM to perform security monitoring, investigate alerts, and support incident response activities. They should have hands-on experience with the platform and a solid understanding of security operations concepts.
CrowdStrike strongly recommends that candidates complete the training courses offered in CrowdStrike University that align to this certification and have at least 6 months' experience working in the Falcon platform, as the exam questions measure knowledge and skills gained through hands-on experience. Complete the recommended training courses in CrowdStrike University, such as SIEM 211: Incident Response and Investigation in Falcon Next-Gen SIEM; Have at least 6 months of hands-on experience working with the CrowdStrike Falcon platform; Familiarity with security operations, incident response, and threat hunting concepts
Everything CrowdStrike publishes about sitting it, and nothing we inferred.
No mandatory prerequisites — this certification has no required predecessor exam or credential.
The path CrowdStrike lays out, how the credential is kept, and where to book.
Step-by-step path to CrowdStrike Certified SIEM Analyst (CCSA)
CrowdStrike certifications are valid for 3 years. Certification holders must renew to maintain their credential. Stay current with the latest technologies and maintain your certification.
Learn more about renewal requirementsThis certification is currently active and available. CrowdStrike maintains this certification to validate current skills and industry relevance.
Register for the exam through Pearson VUE, CrowdStrike’s authorized testing partner.
Schedule your examVisit the official CrowdStrike certification page for exam policies and requirements.
View the official pageYour coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.
See how the coach worksThe CCSA is for security professionals who investigate detections and analyze data within Falcon Next-Gen SIEM, while the CCSE is for security engineers who implement and manage Falcon Next-Gen SIEM. They are separate role-based certifications within the CrowdStrike Falcon Certification Program.
No. CrowdStrike does not require any prerequisite certifications for the CCSA. However, it is strongly recommended that you complete the relevant training courses in CrowdStrike University and have at least 6 months of hands-on experience with the Falcon platform.
You can schedule the CCSA exam by creating or logging in to your Pearson VUE account. During scheduling, you can choose to take the exam online (OnVUE) or at a Pearson VUE test center. You can pay by credit card or redeem an exam voucher.
You must present a valid government-issued photo ID prior to taking the exam. The name on your ID must match the name on your Pearson VUE account.
The official exam guide does not specify a hands-on lab component. The exam focuses on knowledge and skills gained through hands-on experience with the Falcon platform, as recommended by CrowdStrike.
The CCSA is directed at security professionals responsible for investigating detections and analyzing data within the CrowdStrike Falcon Next-Gen SIEM environment, such as SOC analysts, incident responders, and threat hunters.
CrowdStrike certifications are valid for 3 years. The official materials do not specify whether passing a different exam can renew the CCSA. For specific renewal options, contact certification@crowdstrike.com.
Every domain, every objective, and every concept CrowdStrike measures — each one written out.





The objectives below with practice pages open right away, without an account.
The official CrowdStrike exam outline · checked 4 August 2026 · See the source
The curriculum tells you what is on the exam. Proving you know it is a different job — and it is the one the closed-book run does.
The pages shown here come from our AI-900 book — an example of how each concept is written in plain language and, where the idea needs one, drawn as a full page you can take in at a glance.





Three reasons, and each one is a real finding rather than a slogan.
You can see it againUnder pressure people bring back shapes and positions long after the wording has gone.
Picture superiority · Shepard 1967, Standing 1973
The whole idea at onceWhere it starts, what happens in the middle, what comes out, and the mistake to avoid.
Multimedia principle · Mayer
The look-alikes sit togetherThe pairs the exam tests are drawn side by side, so the difference is seen, not told.
Dual coding · PaivioYou are never asked to read a poster here — only to see how one is built. After that, every other page is legible at a glance.

The idea as a sequence, followed with a finger before a word is read.
What it is, how the machine learns it, when it is the right tool.
The distinction the exam tests, given its own box instead of buried in prose.
The sentence to carry into the exam room.
This is the part that teaches. The illustration and the written explanation stay where they are while you work, so a scenario stops being a memory test and becomes something you can simply look at.
A smartphone uses AI to unlock when the owner looks at the camera. Which AI capability is being used?

The same questions come back with the book closed — that run is the one that counts. After it, your coach picks one thing for tonight, sized to the time you have, and brings pages back before you lose them.
Testing effect · Roediger & Karpicke 2006 · spacing effect · Cepeda et al. 2006
Where the exam is defined, scheduled and scored.
We link to them rather than repeat them, so nothing here goes stale behind them.
That is the only question worth answering the night before, and no link answers it. You answer it by taking the questions with the book closed, and seeing what comes back.