CCFA-200 CrowdStrike Certified Falcon
Administrator Exam | Study Guide and Practice
Review
CCFA-200 CROWDSTRIKE CERTIFIED FALCON ADMINISTRATOR EXAM
COMPLETE STUDY GUIDE & PRACTICE REVIEW
Based on Official CrowdStrike Certification Guide
Answers + Detailed Explanations
SECTION 1: EXAM OVERVIEW & REQUIREMENTS
QUESTION 1
What is the format of the CCFA-200 exam?
A) 60 questions, 90 minutes, multiple-choice
B) 100 questions, 120 minutes, hands-on lab
C) 50 questions, 60 minutes, multiple-choice
D) 75 questions, 90 minutes, scenario-based
1
,Correct Answer: A
Rationale: The CCFA exam is a 90-minute, 60-question assessment. Questions are
multiple-choice and are written to eliminate tricky wording, double negatives, and
fill-in-the-blank type questions [citation:1][citation:10].
QUESTION 2
How long must a candidate wait to retake the CCFA exam after a failed first
attempt?
A) 24 hours
B) 48 hours
C) 7 days
D) 30 days
Correct Answer: B
Rationale: Candidates who do not pass the exam on their first attempt must wait 48
hours to retake the exam. After the second attempt, a candidate must wait seven
days for the third attempt and any subsequent attempts [citation:1].
2
,QUESTION 3
How long is the CCFA certification valid?
A) 1 year
B) 2 years
C) 3 years
D) 5 years
Correct Answer: C
Rationale: All CrowdStrike certifications are valid for three years from the date of
successful completion. Recertification requires passing the most current version of
the exam upon expiration [citation:1].
QUESTION 4
Which of the following is NOT a recommended skill for a successful CrowdStrike
Certified Falcon Administrator?
A) Understanding user management and role-based permissions
B) Configuring allowlists and blocklists
3
, C) Writing custom exploit code
D) Configuring file-path exclusions
Correct Answer: C
Rationale: A successful CrowdStrike Certified Falcon Administrator understands
user management and role-based permissions, deploys and manages Falcon
sensors, configures deployment and prevention policy settings, configures
allowlists and blocklists, configures file-path exclusions, and conducts
administrative reporting. Writing custom exploit code is not a required skill for this
certification [citation:1][citation:10].
QUESTION 5
What is the recommended minimum experience for candidates taking the CCFA
exam?
A) 3 months in a production environment
B) 6 months in a production environment
C) 12 months in a production environment
D) No experience required
Correct Answer: B
4
Administrator Exam | Study Guide and Practice
Review
CCFA-200 CROWDSTRIKE CERTIFIED FALCON ADMINISTRATOR EXAM
COMPLETE STUDY GUIDE & PRACTICE REVIEW
Based on Official CrowdStrike Certification Guide
Answers + Detailed Explanations
SECTION 1: EXAM OVERVIEW & REQUIREMENTS
QUESTION 1
What is the format of the CCFA-200 exam?
A) 60 questions, 90 minutes, multiple-choice
B) 100 questions, 120 minutes, hands-on lab
C) 50 questions, 60 minutes, multiple-choice
D) 75 questions, 90 minutes, scenario-based
1
,Correct Answer: A
Rationale: The CCFA exam is a 90-minute, 60-question assessment. Questions are
multiple-choice and are written to eliminate tricky wording, double negatives, and
fill-in-the-blank type questions [citation:1][citation:10].
QUESTION 2
How long must a candidate wait to retake the CCFA exam after a failed first
attempt?
A) 24 hours
B) 48 hours
C) 7 days
D) 30 days
Correct Answer: B
Rationale: Candidates who do not pass the exam on their first attempt must wait 48
hours to retake the exam. After the second attempt, a candidate must wait seven
days for the third attempt and any subsequent attempts [citation:1].
2
,QUESTION 3
How long is the CCFA certification valid?
A) 1 year
B) 2 years
C) 3 years
D) 5 years
Correct Answer: C
Rationale: All CrowdStrike certifications are valid for three years from the date of
successful completion. Recertification requires passing the most current version of
the exam upon expiration [citation:1].
QUESTION 4
Which of the following is NOT a recommended skill for a successful CrowdStrike
Certified Falcon Administrator?
A) Understanding user management and role-based permissions
B) Configuring allowlists and blocklists
3
, C) Writing custom exploit code
D) Configuring file-path exclusions
Correct Answer: C
Rationale: A successful CrowdStrike Certified Falcon Administrator understands
user management and role-based permissions, deploys and manages Falcon
sensors, configures deployment and prevention policy settings, configures
allowlists and blocklists, configures file-path exclusions, and conducts
administrative reporting. Writing custom exploit code is not a required skill for this
certification [citation:1][citation:10].
QUESTION 5
What is the recommended minimum experience for candidates taking the CCFA
exam?
A) 3 months in a production environment
B) 6 months in a production environment
C) 12 months in a production environment
D) No experience required
Correct Answer: B
4