CCFR CertificationGuide
CCFR CertificationGuide
CCFR CertificationGuide
CCFR
Certification
Exam Guide
Last Updated: April, 2024 CCFR-201b © 2024 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
CCFR Certification Guide
Description
The CrowdStrike Certified Falcon Responder (CCFR) exam is the final step toward the
completion of CCFR certification. This exam evaluates a candidate’s knowledge, skills and
abilities to respond to a detection within the CrowdStrike Falcon® console.
A successful CrowdStrike Certified Falcon Responder:
• A successful CrowdStrike Certified Falcon Responder:
• Responds to cyber incidents detected within an enterprise network environment
using the Falcon console
• Manages filtering, grouping, assignment, commenting and status changes of
detections
• Performs basic investigation tasks such as host search, host timeline, process
timeline, user search and other workflows
• Conducts basic proactive hunting across enterprise event data and escalates for
further analysis and resolution when necessary
• Has at least six (6) months of experience working in the Falcon platform
University Subscription
It is strongly suggested that all exam registrants have an active subscription to CrowdStrike
University and have confirmed access to their CrowdStrike University account.
• CrowdStrike certification-aligned courses are available to learners with an active
CrowdStrike University account.
• A unique CrowdStrike Certification ID, training transcripts and printable certification
documents are available through the CrowdStrike University learning management
system.
NOTE: All exam takers can view and print their CrowdStrike certification exam score report
through Pearson VUE.
Last Updated: April, 2024 CCFR-201b © 2024 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
CCFR Certification Guide
Initial Certification
To be eligible for certification, candidates must:
• Achieve a passing score on the CCFR certification exam
• Refrain from any misconduct
In the event of misconduct by the candidate, CrowdStrike may invalidate the score and
consider any suspicious action a violation of the CrowdStrike Certification Exam Agreement.
When a candidate has completed the exam and the candidate's official exam score has been
posted, the certification candidate may view the official exam score through Pearson VUE.
Retake Policy
Candidates who do not pass an exam on their first attempt:
• Must wait 48 hours to retake the exam (wait time begins after the exam).
• Should review the exam objectives, training course materials and associated
recommended reading listed in this document.
After the second attempt, a candidate will need to wait seven (7) days for the third attempt
and any subsequent attempts. Wait time begins the day after the attempt.
Candidates that want to retake the exam should consider retaking the applicable
recommended course(s) and gain additional experience with the CrowdStrike Falcon platform
before trying again.
Retakes beyond the fourth attempt will be considered on a case-by-case basis. CrowdStrike
reserves the right to deny a retake beyond the fourth attempt. If the fourth attempt is a failure
due to a technical issue, the student can reattempt the exam a fifth time.
If the student fails for a fourth time due to personal performance, they must wait 30 days
and retake the recommended training indicated in the exam guide. CrowdStrike will verify
that the candidate has retaken the recommended training in the exam guide and has met with
the CrowdStrike Certification Manager before they are cleared to register for a fifth exam
attempt.
Beta Exams
Candidates will not be permitted to retake beta exams.
Last Updated: April, 2024 CCFR-201b © 2024 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
CCFR Certification Guide
Exam Challenge
If a certification candidate believes there is an error on an exam or that specific questions
on the CCFR exam are invalid, contact certification@crowdstrike.com to request an
evaluation of your claim. The certification candidate must submit a claim within three (3)
days of taking the exam for it to be considered. CrowdStrike will generally respond to
your submission within fifteen (15) business days.
Recertification
All CrowdStrike certifications are valid for three (3) years from the date of successful
completion of an exam. Recertification requires passing the most current version of the
exam upon expiration of certification.
Exam Preparation
Recommended Training
CrowdStrike strongly recommends certification candidates complete the CSU LP- R:
Incident Responder courses in CrowdStrike University to prepare for the CCFR exam. To
learn more about these courses, view the CrowdStrike Training Catalog.
Recommended Reading
CrowdStrike strongly recommends certification candidates review the following
CrowdStrike Falcon Support Documentation titles to prepare for the CCFR exam:
• Falcon Management — Falcon Console User Guide, Dashboards and Reports
section
• Endpoint Security — Start Up and Scale Up, Monitoring, Event Investigation and
Response sections
Exam Scope
The following topics provide a general guideline for the content likely to be included on the
exam; however, other related topics may also appear on any specific delivery of the exam.
• 1.0 MITRE ATT&CK® Framework Application
• 2.0 Detection Analysis
• 3.0 Event Search
• 4.0 Event Investigation
• 5.0 Search Tools
• 6.0 Falcon Real Time Response (RTR)
Last Updated: April, 2024 CCFR-201b © 2024 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
CCFR Certification Guide
Scope Changes
To better reflect the content of the exam and for clarity purposes, the guidelines below may
change at any time without notice. Such changes may include, without limitation, adding or
deleting an available CrowdStrike certification, modifying certification requirements, and
making changes to recommended training courses, testing objectives, outline and exams,
including, without limitation, how and when exam scores are issued. The certification
candidate agrees to meet (and continue to meet) the program requirements, as amended,
as a condition of obtaining and maintaining the certification.
Exam Objectives
The following subtopics and learning objectives provide further guidance on the content
and purpose of the exam:
Last Updated: April, 2024 CCFR-201b © 2024 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
CCFR Certification Guide
Last Updated: April, 2024 CCFR-201b © 2024 CrowdStrike, Inc. All rights reserved.
CrowdStrike University
CCFR Certification Guide
Last Updated: April, 2024 CCFR-201b © 2024 CrowdStrike, Inc. All rights reserved.