Most people who fail the TryHackMe SAL1 exam do not fail because they lack knowledge. They fail because they treat the SOC Simulator like a capture the flag room instead of a shift in a security operations centre. If you want to know how to pass the TryHackMe SAL1 exam, the short answer is this: the 80-question quiz is the easy part, and the two live simulator scenarios carry 800 of the 1000 available points.
SAL1 (Security Analyst Level 1) is TryHackMe's entry-level blue team certification, built in collaboration with Accenture, Salesforce and a panel of working analysts. It sits in the same practical bracket as BTL1 and the HTB CDSA, but it is cheaper than both and it puts you in front of a live alert queue rather than a static forensic image.
This guide covers exactly how the exam is scored, an eight-week study plan you can run alongside a full-time job, and the reporting tactics that separate a 780 from a 710.
What the TryHackMe SAL1 Exam Actually Is
SAL1 validates that you can work a SOC alert queue: triage what lands in front of you, classify it correctly, escalate the things that matter and write a case report a colleague can act on. There are no formal prerequisites, but the exam assumes you have worked through TryHackMe's SOC Level 1 path or have equivalent hands-on experience.
| Detail | SAL1 specification |
|---|---|
| Full name | Security Analyst Level 1 |
| Provider | TryHackMe |
| Cost | 349 USD standard, 297 USD for existing Premium subscribers (15% discount) |
| Included | Exam voucher, three months TryHackMe Premium, one free retake |
| Total score | 1000 points |
| Pass mark | 750 points |
| Sections | Three (one multiple choice, two SOC Simulator scenarios) |
| Active testing time | Approximately five hours |
| Completion window | 24 hours from starting |
| Certificate validity | Three years from the date you pass |
| Attempt window | 12 months from purchase |
Exam Tip: Your exam attempts expire 12 months after purchase, not 12 months after you start studying. Buy the voucher when your study plan starts, not when you first hear about the certification.
The 24-hour window is more generous than it looks. You are not sitting five straight hours at a desk. You can complete the quiz, take a break, then sit each simulator scenario when you are sharp. Use that. Fatigue is a real scoring factor in the second scenario.
How SAL1 Is Scored: Where the 750 Points Come From
This is the single most useful thing to understand before you book. The scoring is heavily weighted towards practical work, and knowing the internal breakdown tells you exactly what to practise.
| Section | Format | Time | Points | Share of total |
|---|---|---|---|---|
| Section 1 | 80 multiple choice questions | 1 hour | 200 | 20% |
| Section 2 | SOC Simulator scenario I | 2 hours | 400 | 40% |
| Section 3 | SOC Simulator scenario II | 2 hours | 400 | 40% |
Each SOC Simulator scenario is then broken down further:
| Simulator component | Points per scenario | Points across both scenarios |
|---|---|---|
| Classification (true positive or false positive) | 150 | 300 |
| Escalation (raising the right alerts) | 150 | 300 |
| Case reports (written findings) | 100 | 200 |
That gives you three clear conclusions.
First, classification and escalation together are worth 600 points, which is 60% of the exam and 80% of your pass mark. Getting the verdict right on each alert matters more than writing beautiful prose.
Second, case reports are worth 200 points, exactly the same as the entire multiple choice section. Analysts who skip reports to save time throw away a fifth of the exam.
Third, the score is combined across all three sections. You can have a weak section and still certify, provided the other two carry you past 750. A perfect quiz plus solid classification and escalation gets you to the line even if your reports are only average.
Exam Tip: 750 out of 1000 means you can afford to lose 250 points. Losing all 200 case report points leaves you needing 750 from 800 available elsewhere, which is a near-perfect run. Write the reports.
Section 1: The 80-Question Multiple Choice Quiz
You get one hour for 80 questions, which is 45 seconds each. That sounds tight, but the questions are pitched at genuine entry level and most are answerable in ten seconds if you know the material.
The quiz tests core knowledge across five broad areas:
- Computing and networking fundamentals (ports, protocols, the OSI model, DNS, HTTP, Windows and Linux basics)
- Common security tooling (SIEM, EDR, SOAR, IDS and IPS, firewalls, sandboxes)
- Common malicious behaviour (phishing, credential access, persistence, lateral movement, exfiltration, common malware families)
- Cyber security frameworks (MITRE ATT&CK, the cyber kill chain, the Diamond Model, NIST incident response phases)
- SOC workflows and activities (alert triage, severity assignment, escalation paths, shift handover, documentation standards)
The two areas that catch people out are networking fundamentals and framework specifics. If you cannot name the MITRE ATT&CK tactic that a technique belongs to, or you hesitate over which port a service runs on, you will bleed time and marks here.
Flag anything you are unsure about and move on. Finishing all 80 with fifteen minutes to review beats agonising over question nine.
Sections 2 and 3: Inside the SOC Simulator
This is where SAL1 earns its reputation. Each scenario drops you into a simulated organisation with an alert dashboard that fires in real time. You have four browser workspaces to manage:
- The alert dashboard, where alerts arrive continuously across the two hours
- The SIEM, where you query event logs to confirm or dismiss what an alert claims
- The Analyst VM, for deeper analysis such as file inspection and hash lookups
- The company information pages, which tell you the asset inventory, naming conventions and who owns what
For each alert you must do three things: mark it as a true positive or a false positive, decide whether to escalate it, and write a case report describing what you found.
The alerts range from single obvious events to multi-stage attack chains that only make sense once you correlate three or four separate alerts. That correlation requirement is the core skill being tested.
Exam Tip: Open the alert dashboard, SIEM, Analyst VM and company information in four separate browser tabs before the timer starts. Navigating away from a half-written case report can lose your work.
The single biggest tactical mistake
New analysts triage alerts the moment they appear, one at a time, in the order they arrive. That is the wrong approach for SAL1.
Let the queue build for the first ten to fifteen minutes. Attack chains generate multiple related alerts, and an alert that looks like an isolated false positive in isolation is often step two of a chain whose step one has not fired yet. If you close it early, you lose the classification points and the escalation points, and your case report describes the wrong incident.
Batch related alerts and write one detailed report covering the chain rather than four thin reports covering fragments of it.
Closing out the queue
You must close all true positive alerts before the two-hour timer expires. Track your remaining queue against the clock. If you are 90 minutes in with a large backlog, start prioritising alerts with clear indicators of compromise and clear the obvious false positives quickly to buy yourself time.
The Eight-Week SAL1 Study Plan
TryHackMe estimates the SOC Level 1 path takes 40 hours. Realistically, if the material is new to you, budget 50 to 80 hours. This plan assumes eight to ten hours a week.
Weeks 1 and 2: Foundations and tooling
Work through the Cyber Security 101 material if networking or operating system fundamentals are shaky. Do not skip this if you cannot confidently read a packet capture or explain what a DNS query looks like in logs.
Then start the SOC Level 1 path proper: what a SOC does, how analysts fit into it, and an introduction to SIEM, EDR and SOAR concepts.
Daily habit from week one: fifteen minutes of multiple choice practice. The quiz section is pure recall and spaced repetition beats cramming. Our practice question banks cover the same networking, tooling and framework ground the SAL1 quiz draws on.
Weeks 3 and 4: Log analysis and SIEM fluency
This is where most of your marks are won. Get genuinely comfortable querying logs. You need to be able to pivot from an alert to the underlying events without hunting through documentation.
Focus on:
- Writing precise queries that filter noise rather than returning thousands of rows
- Pivoting on an IP address, a username, a hostname and a process name
- Reading Windows event logs (process creation, logon events, service installation)
- Reading web and proxy logs for suspicious requests and data transfer volumes
Practise until querying is muscle memory. In the exam, time spent remembering query syntax is time not spent triaging.
Weeks 5 and 6: Frameworks and attack chains
Learn MITRE ATT&CK properly, not just by name. You should be able to look at an alert and say which tactic it maps to and what typically comes next in a chain.
Study the standard chains end to end:
- Phishing, then credential access, then lateral movement, then exfiltration
- External exploitation, then persistence, then privilege escalation, then command and control
- Insider misuse and data staging
Recognising the shape of a chain in progress is what lets you correlate alerts under time pressure. Read our CySA+ study plan if you want a deeper structured tour of detection and response theory.
Week 7: SOC Simulator practice under timed conditions
Run the SOC Simulator scenarios in the learning path, but run them properly. Set a two-hour timer. Do not pause. Do not look up answers mid-scenario. Write full case reports for every alert even though it is only practice.
Then review what you got wrong. Every misclassification tells you something specific about a gap in your log-reading or your framework knowledge.
Do at least three timed runs this week.
Week 8: Report templating and revision
Build and rehearse your case report template until writing one takes four minutes rather than twelve. Do a final pass over frameworks and networking for the quiz, run one last timed simulator scenario, then book the exam.
Do not extend past week eight. The SOC Simulator rewards fluency and pattern recognition, and both decay if you keep studying theory instead of sitting the exam.
The Case Report Template That Scores
Case reports are graded by an AI scoring engine that rewards technical detail and specificity. Vague reports score poorly even when your classification is correct. Analysts who pass consistently describe writing five to six paragraph reports packed with concrete artefacts.
Build a template covering these elements and reuse it for every alert:
- What happened: a one-line summary of the activity in plain terms
- When: exact timestamps, including the first and last observed event
- Who and where: usernames, source and destination IP addresses, hostnames, affected assets
- How: the observed behaviour, including process names, command lines, URLs, file names and hashes
- Indicators of compromise: every artefact listed explicitly, not buried in prose
- MITRE ATT&CK mapping: the tactics and techniques the activity corresponds to
- Verdict and reasoning: why this is a true positive or false positive, stated with evidence
- Recommended remediation: containment and next steps, such as isolating a host or resetting credentials
Exam Tip: Include exact values, never approximations. "The user account svc_backup authenticated from 10.14.2.87 at 03:42:11" scores. "A service account logged in from an internal IP early in the morning" does not.
SAL1 vs BTL1 vs CySA+: Which Blue Team Cert First?
SAL1 is new enough that employer recognition lags behind its technical quality. That is the honest trade-off, and it should shape how you sequence your certifications.
| Factor | TryHackMe SAL1 | Security Blue Team BTL1 | CompTIA CySA+ |
|---|---|---|---|
| Cost | 349 USD | Higher | Higher |
| Format | 80 MCQs plus two live SOC simulations | 24-hour practical investigation | Multiple choice plus performance-based questions |
| Hands-on realism | Very high, live alert queue | Very high, full investigation | Moderate |
| Employer recognition | Growing but limited | Established in blue team circles | Widest, appears in job adverts and DoD 8140 |
| Best for | Proving you can work a real alert queue | Proving end-to-end investigation skill | Getting past HR filters and compliance requirements |
The pragmatic sequence for someone targeting a first SOC role is CySA+ or Security+ for the name recognition that gets your CV read, plus SAL1 for the hands-on evidence that gets you through the technical interview. They solve different problems.
If you are choosing between the two practical options, our BTL1 study plan and HTB CDSA study plan break down how those exams differ in format and depth.
Why People Fail SAL1
Five failure patterns account for most unsuccessful attempts.
Triaging alerts individually as they arrive. You break attack chains into fragments and lose classification, escalation and report points on the same incident.
Skipping case reports to save time. That is 200 points, a fifth of the exam, gone by choice.
Writing vague reports. Correct verdict, poor detail, low score. The scoring engine cannot reward evidence you did not write down.
Weak SIEM query skills. If you spend three minutes per alert working out how to filter logs, you will not clear the queue inside two hours.
Fatigue in scenario two. People sit both scenarios back to back on the same evening after the quiz. You have 24 hours. Sleep between sections if you need to.
None of these are knowledge problems. They are process problems, which means they are fixable in week seven of the plan above if you practise under real timed conditions.
Ready to Start Practising?
SAL1 is one of the better-value entry-level blue team certifications on the market in 2026, and the SOC Simulator is genuinely the closest thing to a real shift you will find in an exam. But 800 of the 1000 points come from performance under a clock, and no amount of passive video watching prepares you for that.
Build the knowledge base first, then drill the process until triage, classification and reporting are automatic.
CertCrush gives you the recall layer that underpins the whole exam: networking fundamentals, security tooling, malicious behaviour patterns and framework mappings, delivered as exam-style practice questions with full explanations so you know why an answer is right rather than just that it is.
Create your free CertCrush account and start practising today, or browse our full course catalogue to build out the rest of your blue team certification path.
