Back to blog
Study Tips13 min read

How to Pass the TryHackMe SAL1 Exam in 2026: A Study Plan for the SOC Simulator Scenarios

The TryHackMe SAL1 exam is scored out of 1000 points and you need 750 to pass, with 800 of those points coming from two live SOC Simulator scenarios. Here is an eight-week study plan and the exam-day tactics that decide whether you certify.

Tom Ashford

Tom Ashford · Security Certifications Lead

25 July 2026

Most people who fail the TryHackMe SAL1 exam do not fail because they lack knowledge. They fail because they treat the SOC Simulator like a capture the flag room instead of a shift in a security operations centre. If you want to know how to pass the TryHackMe SAL1 exam, the short answer is this: the 80-question quiz is the easy part, and the two live simulator scenarios carry 800 of the 1000 available points.

SAL1 (Security Analyst Level 1) is TryHackMe's entry-level blue team certification, built in collaboration with Accenture, Salesforce and a panel of working analysts. It sits in the same practical bracket as BTL1 and the HTB CDSA, but it is cheaper than both and it puts you in front of a live alert queue rather than a static forensic image.

This guide covers exactly how the exam is scored, an eight-week study plan you can run alongside a full-time job, and the reporting tactics that separate a 780 from a 710.

What the TryHackMe SAL1 Exam Actually Is

SAL1 validates that you can work a SOC alert queue: triage what lands in front of you, classify it correctly, escalate the things that matter and write a case report a colleague can act on. There are no formal prerequisites, but the exam assumes you have worked through TryHackMe's SOC Level 1 path or have equivalent hands-on experience.

DetailSAL1 specification
Full nameSecurity Analyst Level 1
ProviderTryHackMe
Cost349 USD standard, 297 USD for existing Premium subscribers (15% discount)
IncludedExam voucher, three months TryHackMe Premium, one free retake
Total score1000 points
Pass mark750 points
SectionsThree (one multiple choice, two SOC Simulator scenarios)
Active testing timeApproximately five hours
Completion window24 hours from starting
Certificate validityThree years from the date you pass
Attempt window12 months from purchase

Exam Tip: Your exam attempts expire 12 months after purchase, not 12 months after you start studying. Buy the voucher when your study plan starts, not when you first hear about the certification.

The 24-hour window is more generous than it looks. You are not sitting five straight hours at a desk. You can complete the quiz, take a break, then sit each simulator scenario when you are sharp. Use that. Fatigue is a real scoring factor in the second scenario.

How SAL1 Is Scored: Where the 750 Points Come From

This is the single most useful thing to understand before you book. The scoring is heavily weighted towards practical work, and knowing the internal breakdown tells you exactly what to practise.

SectionFormatTimePointsShare of total
Section 180 multiple choice questions1 hour20020%
Section 2SOC Simulator scenario I2 hours40040%
Section 3SOC Simulator scenario II2 hours40040%

Each SOC Simulator scenario is then broken down further:

Simulator componentPoints per scenarioPoints across both scenarios
Classification (true positive or false positive)150300
Escalation (raising the right alerts)150300
Case reports (written findings)100200

That gives you three clear conclusions.

First, classification and escalation together are worth 600 points, which is 60% of the exam and 80% of your pass mark. Getting the verdict right on each alert matters more than writing beautiful prose.

Second, case reports are worth 200 points, exactly the same as the entire multiple choice section. Analysts who skip reports to save time throw away a fifth of the exam.

Third, the score is combined across all three sections. You can have a weak section and still certify, provided the other two carry you past 750. A perfect quiz plus solid classification and escalation gets you to the line even if your reports are only average.

Exam Tip: 750 out of 1000 means you can afford to lose 250 points. Losing all 200 case report points leaves you needing 750 from 800 available elsewhere, which is a near-perfect run. Write the reports.

Section 1: The 80-Question Multiple Choice Quiz

You get one hour for 80 questions, which is 45 seconds each. That sounds tight, but the questions are pitched at genuine entry level and most are answerable in ten seconds if you know the material.

The quiz tests core knowledge across five broad areas:

  • Computing and networking fundamentals (ports, protocols, the OSI model, DNS, HTTP, Windows and Linux basics)
  • Common security tooling (SIEM, EDR, SOAR, IDS and IPS, firewalls, sandboxes)
  • Common malicious behaviour (phishing, credential access, persistence, lateral movement, exfiltration, common malware families)
  • Cyber security frameworks (MITRE ATT&CK, the cyber kill chain, the Diamond Model, NIST incident response phases)
  • SOC workflows and activities (alert triage, severity assignment, escalation paths, shift handover, documentation standards)

The two areas that catch people out are networking fundamentals and framework specifics. If you cannot name the MITRE ATT&CK tactic that a technique belongs to, or you hesitate over which port a service runs on, you will bleed time and marks here.

Flag anything you are unsure about and move on. Finishing all 80 with fifteen minutes to review beats agonising over question nine.

Sections 2 and 3: Inside the SOC Simulator

This is where SAL1 earns its reputation. Each scenario drops you into a simulated organisation with an alert dashboard that fires in real time. You have four browser workspaces to manage:

  1. The alert dashboard, where alerts arrive continuously across the two hours
  2. The SIEM, where you query event logs to confirm or dismiss what an alert claims
  3. The Analyst VM, for deeper analysis such as file inspection and hash lookups
  4. The company information pages, which tell you the asset inventory, naming conventions and who owns what

For each alert you must do three things: mark it as a true positive or a false positive, decide whether to escalate it, and write a case report describing what you found.

The alerts range from single obvious events to multi-stage attack chains that only make sense once you correlate three or four separate alerts. That correlation requirement is the core skill being tested.

Exam Tip: Open the alert dashboard, SIEM, Analyst VM and company information in four separate browser tabs before the timer starts. Navigating away from a half-written case report can lose your work.

The single biggest tactical mistake

New analysts triage alerts the moment they appear, one at a time, in the order they arrive. That is the wrong approach for SAL1.

Let the queue build for the first ten to fifteen minutes. Attack chains generate multiple related alerts, and an alert that looks like an isolated false positive in isolation is often step two of a chain whose step one has not fired yet. If you close it early, you lose the classification points and the escalation points, and your case report describes the wrong incident.

Batch related alerts and write one detailed report covering the chain rather than four thin reports covering fragments of it.

Closing out the queue

You must close all true positive alerts before the two-hour timer expires. Track your remaining queue against the clock. If you are 90 minutes in with a large backlog, start prioritising alerts with clear indicators of compromise and clear the obvious false positives quickly to buy yourself time.

The Eight-Week SAL1 Study Plan

TryHackMe estimates the SOC Level 1 path takes 40 hours. Realistically, if the material is new to you, budget 50 to 80 hours. This plan assumes eight to ten hours a week.

Weeks 1 and 2: Foundations and tooling

Work through the Cyber Security 101 material if networking or operating system fundamentals are shaky. Do not skip this if you cannot confidently read a packet capture or explain what a DNS query looks like in logs.

Then start the SOC Level 1 path proper: what a SOC does, how analysts fit into it, and an introduction to SIEM, EDR and SOAR concepts.

Daily habit from week one: fifteen minutes of multiple choice practice. The quiz section is pure recall and spaced repetition beats cramming. Our practice question banks cover the same networking, tooling and framework ground the SAL1 quiz draws on.

Weeks 3 and 4: Log analysis and SIEM fluency

This is where most of your marks are won. Get genuinely comfortable querying logs. You need to be able to pivot from an alert to the underlying events without hunting through documentation.

Focus on:

  • Writing precise queries that filter noise rather than returning thousands of rows
  • Pivoting on an IP address, a username, a hostname and a process name
  • Reading Windows event logs (process creation, logon events, service installation)
  • Reading web and proxy logs for suspicious requests and data transfer volumes

Practise until querying is muscle memory. In the exam, time spent remembering query syntax is time not spent triaging.

Weeks 5 and 6: Frameworks and attack chains

Learn MITRE ATT&CK properly, not just by name. You should be able to look at an alert and say which tactic it maps to and what typically comes next in a chain.

Study the standard chains end to end:

  • Phishing, then credential access, then lateral movement, then exfiltration
  • External exploitation, then persistence, then privilege escalation, then command and control
  • Insider misuse and data staging

Recognising the shape of a chain in progress is what lets you correlate alerts under time pressure. Read our CySA+ study plan if you want a deeper structured tour of detection and response theory.

Week 7: SOC Simulator practice under timed conditions

Run the SOC Simulator scenarios in the learning path, but run them properly. Set a two-hour timer. Do not pause. Do not look up answers mid-scenario. Write full case reports for every alert even though it is only practice.

Then review what you got wrong. Every misclassification tells you something specific about a gap in your log-reading or your framework knowledge.

Do at least three timed runs this week.

Week 8: Report templating and revision

Build and rehearse your case report template until writing one takes four minutes rather than twelve. Do a final pass over frameworks and networking for the quiz, run one last timed simulator scenario, then book the exam.

Do not extend past week eight. The SOC Simulator rewards fluency and pattern recognition, and both decay if you keep studying theory instead of sitting the exam.

The Case Report Template That Scores

Case reports are graded by an AI scoring engine that rewards technical detail and specificity. Vague reports score poorly even when your classification is correct. Analysts who pass consistently describe writing five to six paragraph reports packed with concrete artefacts.

Build a template covering these elements and reuse it for every alert:

  1. What happened: a one-line summary of the activity in plain terms
  2. When: exact timestamps, including the first and last observed event
  3. Who and where: usernames, source and destination IP addresses, hostnames, affected assets
  4. How: the observed behaviour, including process names, command lines, URLs, file names and hashes
  5. Indicators of compromise: every artefact listed explicitly, not buried in prose
  6. MITRE ATT&CK mapping: the tactics and techniques the activity corresponds to
  7. Verdict and reasoning: why this is a true positive or false positive, stated with evidence
  8. Recommended remediation: containment and next steps, such as isolating a host or resetting credentials

Exam Tip: Include exact values, never approximations. "The user account svc_backup authenticated from 10.14.2.87 at 03:42:11" scores. "A service account logged in from an internal IP early in the morning" does not.

SAL1 vs BTL1 vs CySA+: Which Blue Team Cert First?

SAL1 is new enough that employer recognition lags behind its technical quality. That is the honest trade-off, and it should shape how you sequence your certifications.

FactorTryHackMe SAL1Security Blue Team BTL1CompTIA CySA+
Cost349 USDHigherHigher
Format80 MCQs plus two live SOC simulations24-hour practical investigationMultiple choice plus performance-based questions
Hands-on realismVery high, live alert queueVery high, full investigationModerate
Employer recognitionGrowing but limitedEstablished in blue team circlesWidest, appears in job adverts and DoD 8140
Best forProving you can work a real alert queueProving end-to-end investigation skillGetting past HR filters and compliance requirements

The pragmatic sequence for someone targeting a first SOC role is CySA+ or Security+ for the name recognition that gets your CV read, plus SAL1 for the hands-on evidence that gets you through the technical interview. They solve different problems.

If you are choosing between the two practical options, our BTL1 study plan and HTB CDSA study plan break down how those exams differ in format and depth.

Why People Fail SAL1

Five failure patterns account for most unsuccessful attempts.

Triaging alerts individually as they arrive. You break attack chains into fragments and lose classification, escalation and report points on the same incident.

Skipping case reports to save time. That is 200 points, a fifth of the exam, gone by choice.

Writing vague reports. Correct verdict, poor detail, low score. The scoring engine cannot reward evidence you did not write down.

Weak SIEM query skills. If you spend three minutes per alert working out how to filter logs, you will not clear the queue inside two hours.

Fatigue in scenario two. People sit both scenarios back to back on the same evening after the quiz. You have 24 hours. Sleep between sections if you need to.

None of these are knowledge problems. They are process problems, which means they are fixable in week seven of the plan above if you practise under real timed conditions.

Ready to Start Practising?

SAL1 is one of the better-value entry-level blue team certifications on the market in 2026, and the SOC Simulator is genuinely the closest thing to a real shift you will find in an exam. But 800 of the 1000 points come from performance under a clock, and no amount of passive video watching prepares you for that.

Build the knowledge base first, then drill the process until triage, classification and reporting are automatic.

CertCrush gives you the recall layer that underpins the whole exam: networking fundamentals, security tooling, malicious behaviour patterns and framework mappings, delivered as exam-style practice questions with full explanations so you know why an answer is right rather than just that it is.

Create your free CertCrush account and start practising today, or browse our full course catalogue to build out the rest of your blue team certification path.

TryHackMe SAL1SOC AnalystBlue TeamSOC SimulatorStudy PlanEntry Level CybersecuritySplunk
Tom Ashford

Written by

Tom Ashford · Security Certifications Lead

Tom spent over a decade in security operations and consulting before turning to full-time exam-prep writing. He covers the big security certifications — CISSP, CISM, CISA, Security+ and the rest of the alphabet — with a soft spot for the questions everyone gets wrong. His rule for every article: if it doesn’t help you score marks, it doesn’t go in.

All articles by Tom

Want a TryHackMe SAL1 practice course?

We don’t cover this exam yet — we build the most-requested courses first. One click tells us you want it.

Practising for something nearby?

Try real exam-style questions free — no account needed, full explanations included.