HTB Certified Junior Cybersecurity Associate (CJCA)
The CJCA is Hack The Box's entry-level, hands-on certification. It covers both offensive (red team) and defensive (blue team) fundamentals. This page is a complete guide to what the exam covers, how to prepare, and how to pass.
Exam Overview
| Attribute | Details |
|---|---|
| Full name | HTB Certified Junior Cybersecurity Associate |
| Prerequisites | Complete the 20-module Junior Cybersecurity Analyst path on HTB Academy |
| Exam format | 100% practical, hands-on. Gray box assessment |
| Exam duration | 5-day practical lab window |
| Passing score | 80 points (out of 100 for red team) + satisfactory blue team triage and report |
| Report review | Approximately 20 days after submission |
| Aligned with | NIST NICE Framework, MITRE ATT&CK |
| Connection | HTB Pwnbox or OpenVPN |
Exam Structure
The exam has two parts that you can work on simultaneously over the 5-day window:
Red Team Section
Compromise 5 machines using exploitation and privilege escalation. Each machine is worth points. You need 80 out of 100 to pass the red team portion.
The machines are gray box - you get some information upfront (like a network diagram or partial credentials), but you still need to enumerate, exploit, and escalate privileges on your own.
Blue Team Section
Triage approximately 40 SIEM alerts in an Elastic Stack (ELK) instance. For each alert, classify it as:
- True Positive (TP) - Real attack. Provide evidence from logs and explain what happened.
- False Positive (FP) - Not an attack. Provide evidence showing why the alert fired and why it is benign.
You must provide evidence and reasoning for every classification. Guessing is not enough.
The Report
The report is what separates a pass from a fail. You can get all flags and still fail with a bad report. The report must include:
- Statement of Confidentiality - NDA and confidentiality notice
- Executive Summary - High-level overview of findings and business impact
- Assessment Overview - Scope, objectives, methodology, timeline
- Technical Findings - Per machine: vulnerability, reproduction steps, evidence (screenshots with captions), impact, remediation
- SIEM Alert Triage - Each alert: name, classification (TP/FP), evidence from logs, reasoning
- Recommendations - Prioritized remediation steps
- Appendix - Full command output, raw data, additional evidence
Passing reports are typically 50-75 pages. Every screenshot must have a descriptive caption explaining both the command and the output.
The 20-Module Academy Path
The Junior Cybersecurity Analyst path on HTB Academy has 20 modules split into three tiers.
Tier 0 - Fundamentals (No Cubes Required)
| Module | Key Topics |
|---|---|
| 1. Introduction to Cybersecurity | Career paths, offensive vs defensive, ethics, legality |
| 2. Introduction to Networking | OSI model, TCP/IP, IP addressing, common protocols |
| 3. Linux Fundamentals | File system, permissions, basic commands, text editing |
| 4. Windows Fundamentals | Desktop, file system, user management, settings |
| 5. Introduction to Web Applications | HTTP, HTML, CSS, JavaScript, web app architecture |
| 6. Introduction to Python | Variables, data types, loops, functions, scripting |
Tier 1 - Core (100 Cubes Total)
| Module | Key Topics |
|---|---|
| 7. Linux Shells and Scripting | Bash scripting, automation, shell types |
| 8. Windows Command Line | CMD, PowerShell basics, batch scripting |
| 9. Windows PowerShell | Cmdlets, pipelines, scripting, remote management |
| 10. Introduction to Cybersecurity Assessments | Pentest in a nutshell, PTES, types of assessments |
| 11. Information Gathering | OSINT, DNS, search engines, social media recon |
| 12. Nmap | Network mapping, discovery, scanning flags, scripting engine |
| 13. Footprinting | SMTP, DNS, HTTP, SMB, SQL, RDP, WinRM, SSH enumeration. Most critical offensive module |
| 14. Information Gathering - Web | WordPress enumeration, Gobuster, web reconnaissance |
| 15. Metasploit | MSF architecture, modules, exploitation, post-exploitation, msfvenom |
Tier 2 - Advanced (500 Cubes Total)
| Module | Key Topics |
|---|---|
| 16. Security Monitoring and SIEM Fundamentals | ELK architecture, Elasticsearch indexing, Logstash pipelines, Kibana dashboards, Beats shippers |
| 17. Windows Event Logs and Finding Evil | Event IDs, log analysis, threat detection, SIEM roadmap |
| 18. Hunting with Elastic | ELK syntax (KQL/Lucene), triage queries, alert analysis |
| 19. Introduction to Threat Hunting | Hypothesis-driven hunting, MITRE ATT&CK, behavioral analysis |
| 20. Documentation and Reporting | Professional report writing, structure, audience, evidence |
Must-Master Modules
- Footprinting - The most critical offensive module. Learn every service enumeration technique.
- Windows Event Logs and Finding Evil - Know your Event IDs by heart.
- Security Monitoring and SIEM Fundamentals - Understand ELK architecture completely.
- Hunting with Elastic - KQL syntax must be second nature.
- Pentest in a Nutshell - The methodology module that ties everything together.
Exam Tips
Red Team Strategy
- Check ELK logs first. The SIEM logs contain traces of previous attacker activity. If you can see what the attacker did, you can reproduce it.
- Enumeration is everything. Miss something during recon and you lose your foothold. Be thorough.
- Stay organized. Track which machines you compromised, which flags you found, and what you tried.
- Try harder. If you are stuck, enumerate more. There is always something you missed.
Blue Team Strategy
- Timeline analysis. Look at when events happened. Does the timing match an attack pattern?
- Behavioral analysis. Is this behavior normal for this user/host? Or is it anomalous?
- Prove FP with evidence. A cron job triggering a noisy rule? Show the cron entry. A sysadmin running a legit command? Show the user's normal activity pattern.
- Work simultaneously. Best approach is to switch between red and blue when you get stuck on one side.
General Tips
- Use VPN TCP if UDP has packet loss
- Take notes and screenshots as you go, not after
- Memorize key Windows Event IDs (4624, 4625, 4688, 4720, 4732)
- Practice KQL syntax before the exam
- Know NIST SP 800-61 incident response phases
- Learn Sysmon Event IDs (1, 3, 7, 11)
- Know ELK Stack architecture (Elasticsearch, Logstash, Kibana, Beats)
- Practice nmap flags: -sS, -sV, -O, -p-, -sC, --script=vuln
Key Windows Event IDs
| Event ID | Meaning | Why It Matters |
|---|---|---|
| 4624 | Successful logon | Track who logged in and how (Type 2 interactive, Type 3 network, Type 10 remote) |
| 4625 | Failed logon | Brute force detection, password spraying |
| 4688 | Process creation | What processes are being launched (needs audit policy enabled) |
| 4720 | User account created | New accounts may indicate attacker persistence |
| 4732 | Member added to group | Privilege escalation via group membership changes |
| 4722 | User account enabled | Re-enabling a disabled account |
| 4726 | User account deleted | Covering tracks |
| 4672 | Special privileges assigned | Admin-level logon, sensitive actions |
Key Sysmon Event IDs
| Event ID | Meaning |
|---|---|
| 1 | Process creation (command line, parent process) |
| 3 | Network connection (source IP, destination IP, port) |
| 7 | Image loaded (DLL loaded - detect DLL hijacking) |
| 11 | File creation (detect malware dropping files) |
After the CJCA
The CJCA is just the beginning. HTB offers more advanced certifications:
- CDSA (Certified Defensive Security Analyst) - Focuses on SOC analyst skills, SIEM, and threat hunting
- CPTS (Certified Penetration Testing Specialist) - Advanced offensive cert, much harder than CJCA
- CBBH (Certified Bug Bounty Hunter) - Web-focused offensive cert, covers OWASP Top 10 and beyond
- CWEE (Certified Web Exploitation Expert) - Advanced web exploitation