n3cr0 secure shell v2.0.26
initializing encrypted connection...
loading cyber warfare modules...
red team: READY
blue team: READY
purple team: READY
HTB integration: ONLINE
access granted. welcome, operator.

HTB Certified Junior Cybersecurity Associate (CJCA)

The CJCA is Hack The Box's entry-level, hands-on certification. It covers both offensive (red team) and defensive (blue team) fundamentals. This page is a complete guide to what the exam covers, how to prepare, and how to pass.

Exam Overview

Attribute Details
Full name HTB Certified Junior Cybersecurity Associate
Prerequisites Complete the 20-module Junior Cybersecurity Analyst path on HTB Academy
Exam format 100% practical, hands-on. Gray box assessment
Exam duration 5-day practical lab window
Passing score 80 points (out of 100 for red team) + satisfactory blue team triage and report
Report review Approximately 20 days after submission
Aligned with NIST NICE Framework, MITRE ATT&CK
Connection HTB Pwnbox or OpenVPN

Exam Structure

The exam has two parts that you can work on simultaneously over the 5-day window:

Red Team Section

Compromise 5 machines using exploitation and privilege escalation. Each machine is worth points. You need 80 out of 100 to pass the red team portion.

The machines are gray box - you get some information upfront (like a network diagram or partial credentials), but you still need to enumerate, exploit, and escalate privileges on your own.

Blue Team Section

Triage approximately 40 SIEM alerts in an Elastic Stack (ELK) instance. For each alert, classify it as:

You must provide evidence and reasoning for every classification. Guessing is not enough.

The Report

The report is what separates a pass from a fail. You can get all flags and still fail with a bad report. The report must include:

  1. Statement of Confidentiality - NDA and confidentiality notice
  2. Executive Summary - High-level overview of findings and business impact
  3. Assessment Overview - Scope, objectives, methodology, timeline
  4. Technical Findings - Per machine: vulnerability, reproduction steps, evidence (screenshots with captions), impact, remediation
  5. SIEM Alert Triage - Each alert: name, classification (TP/FP), evidence from logs, reasoning
  6. Recommendations - Prioritized remediation steps
  7. Appendix - Full command output, raw data, additional evidence

Passing reports are typically 50-75 pages. Every screenshot must have a descriptive caption explaining both the command and the output.

The 20-Module Academy Path

The Junior Cybersecurity Analyst path on HTB Academy has 20 modules split into three tiers.

Tier 0 - Fundamentals (No Cubes Required)

Module Key Topics
1. Introduction to Cybersecurity Career paths, offensive vs defensive, ethics, legality
2. Introduction to Networking OSI model, TCP/IP, IP addressing, common protocols
3. Linux Fundamentals File system, permissions, basic commands, text editing
4. Windows Fundamentals Desktop, file system, user management, settings
5. Introduction to Web Applications HTTP, HTML, CSS, JavaScript, web app architecture
6. Introduction to Python Variables, data types, loops, functions, scripting

Tier 1 - Core (100 Cubes Total)

Module Key Topics
7. Linux Shells and Scripting Bash scripting, automation, shell types
8. Windows Command Line CMD, PowerShell basics, batch scripting
9. Windows PowerShell Cmdlets, pipelines, scripting, remote management
10. Introduction to Cybersecurity Assessments Pentest in a nutshell, PTES, types of assessments
11. Information Gathering OSINT, DNS, search engines, social media recon
12. Nmap Network mapping, discovery, scanning flags, scripting engine
13. Footprinting SMTP, DNS, HTTP, SMB, SQL, RDP, WinRM, SSH enumeration. Most critical offensive module
14. Information Gathering - Web WordPress enumeration, Gobuster, web reconnaissance
15. Metasploit MSF architecture, modules, exploitation, post-exploitation, msfvenom

Tier 2 - Advanced (500 Cubes Total)

Module Key Topics
16. Security Monitoring and SIEM Fundamentals ELK architecture, Elasticsearch indexing, Logstash pipelines, Kibana dashboards, Beats shippers
17. Windows Event Logs and Finding Evil Event IDs, log analysis, threat detection, SIEM roadmap
18. Hunting with Elastic ELK syntax (KQL/Lucene), triage queries, alert analysis
19. Introduction to Threat Hunting Hypothesis-driven hunting, MITRE ATT&CK, behavioral analysis
20. Documentation and Reporting Professional report writing, structure, audience, evidence

Must-Master Modules

Exam Tips

Red Team Strategy

Blue Team Strategy

General Tips

Key Windows Event IDs

Event ID Meaning Why It Matters
4624 Successful logon Track who logged in and how (Type 2 interactive, Type 3 network, Type 10 remote)
4625 Failed logon Brute force detection, password spraying
4688 Process creation What processes are being launched (needs audit policy enabled)
4720 User account created New accounts may indicate attacker persistence
4732 Member added to group Privilege escalation via group membership changes
4722 User account enabled Re-enabling a disabled account
4726 User account deleted Covering tracks
4672 Special privileges assigned Admin-level logon, sensitive actions

Key Sysmon Event IDs

Event ID Meaning
1 Process creation (command line, parent process)
3 Network connection (source IP, destination IP, port)
7 Image loaded (DLL loaded - detect DLL hijacking)
11 File creation (detect malware dropping files)

After the CJCA

The CJCA is just the beginning. HTB offers more advanced certifications:

Sign up for Hack The Box ->