What is the format of the CCSA exam?
The CrowdStrike Certified SIEM Analyst (CCSA) exam is a 90-minute, 60-question assessment - about 90 seconds per question - and every question is multiple-choice. CrowdStrike's exam guide describes it as the step that earns the CCSA certification, the analyst credential in the role-based Falcon Certification Program directed at security professionals responsible for investigating detections and analyzing data within the Falcon Next-Gen SIEM environment.
CrowdStrike does not publish a numeric passing score. The guide requires candidates to 'achieve a passing score' and leaves it there - any third party quoting an exact CCSA pass percentage is guessing.
Everything on this page comes from CrowdStrike's own exam guide and program guide, so you are reading the format the vendor actually publishes - not a forum's memory of it.
What topics does the CCSA exam cover?
The exam measures Falcon Next-Gen SIEM the way a working analyst uses it. The guide's successful-candidate profile covers investigating detections and analyzing data with CrowdStrike Query Language (CQL), visualizing and summarizing data, correlating events across multiple data sources to identify suspicious or malicious activity, and using first-party and third-party data to detect threats and contribute to incident investigations without detailed procedural guidance.
A foundational understanding of the MITRE ATT&CK framework is expected, along with the ability to differentiate detection types - first-party detections, third-party passthrough detections, and correlation rule detections. CrowdStrike recommends at least six months of Falcon platform experience plus hands-on time in a SOC, threat detection, or incident response role before sitting.
The published scope lands in four areas, and the objectives inside them are concrete: constructing CQL searches with filters, logical operators, and time parameters, applying the CrowdStrike Parsing Standard, judging alert metadata (severity, tactic, confidence), building the chain of events across correlated logs, and documenting investigations through Case Management. The recommended preparation is CrowdStrike's Certified SIEM Analyst courses in CrowdStrike University.
| # | Scope area | What it covers |
|---|---|---|
| 1 | Querying and Analytics | CQL searches, dashboards and prebuilt scripts, interpreting results, correlating related data sets, the CrowdStrike Parsing Standard |
| 2 | Detection Logic and Alert Analytics | Correlation rules, detection types (first-party, third-party passthrough, correlation rule), MITRE ATT&CK components, false positives, alert metadata |
| 3 | Incident Investigation | Chain-of-events construction, lateral movement, persistence and privilege escalation indicators, pivoting between observables, severity and scope, Fusion SOAR response, IOCs |
| 4 | Reporting and Communication | Documenting and summarizing investigation results in Case Management, aggregations and visual summaries for trends and anomalies |
Scroll horizontally to view all columns.
How much does the CCSA exam cost?
$250 USD per exam, per the CrowdStrike Falcon Certification Program guide. The voucher is purchased through your CrowdStrike sales representative or online at Pearson, and every registrant must accept the CrowdStrike Certification Exam Agreement and be at least 18 years old.
Budget for the retake policy, not just the first sitting. A failed attempt is another full $250, plus a mandatory 48-hour wait before attempt two and a seven-day wait before attempt three and beyond. A fourth performance failure triggers a 30-day wait, retaken recommended training, and a review with the CrowdStrike Certification Manager before a fifth attempt is approved.
Can you take the CCSA exam at home?
Yes. Pearson VUE's CrowdStrike program page states the certification programs are 'delivered by Pearson either online (OnVUE) or at a Pearson testing center' - your room or theirs.
At home, OnVUE's published requirements apply: Windows 10 or macOS 14 or higher, a working webcam, microphone, and speaker with no headphones, one display only, at least 6 Mbps down and 2 Mbps up, and the ability to close every application except OnVUE. Virtual machines, phones, tablets, smart devices with recording or AI features, and secondary displays are prohibited. Failing the requirements on exam day can mean immediate cancellation and forfeiture of the exam fee - run the system test on the exact device and network you will use.
How long does the CCSA certification last?
Three years. Every CrowdStrike certification is valid for three years from the date you pass, and recertification requires passing the most current version of the exam when it expires - CrowdStrike publishes no continuing-education shortcut.
You also cannot retake an exam you already passed except for an approved recertification, so the three-year clock is the only scheduled reason to see the exam again.
That three-year clock matters for planning. If your employer needs the credential for a contract or a role requirement, an expiring CCSA means facing the current version of the exam again - on the current format, not the one you originally passed. CrowdStrike's scope-change clause is explicit that exam content can change at any time without notice.
If the Sitting Itself Is the Problem
Format research solves the knowing. It does not solve the doing when your calendar, your test anxiety, or a failed attempt already on the books is the real blocker.
That is the gap Exam Assist fills: your CCSA sitting is handled end to end against the current 60-question, 90-minute format, and the service fee is due only after the agreed pass posts. If that is the outcome you actually need, the CCSA service page has the details.
Either way, you now know the real shape of the exam: 60 questions, 90 minutes, $250, the published scope, at home or at a center. The next move is yours - book the sitting yourself, or hand it to a team whose fee only exists if the pass posts.