
Your First Definitive Guide and Review on HackTheBox CJCA Certification Exam
Hello everyone! Chicken0248 here again, and this time, I've successfully passed a newly released certification: the HTB Certified Junior Cybersecurity Associate (HTB CJCA), released on 23rd July 2025. It's now the entry-level certification for people interested in both Pentesting and SOC. Yes, that means you'll need to conduct penetration testing and triage alerts with a SIEM. So without further ado, let's talk about this certification, the job-role path you need to complete before taking the exam, exam preparation, and my experience!

The current state of HackTheBox certifications: I'm still waiting for a Specialized Role certification on the blue team side!

For those already familiar with HackTheBox Academy and its certifications, you'll know that every certificate has a "job-role" path associated with it: you must complete all modules in the path before you can use your exam voucher. HTB CJCA follows that same pattern, aligning with the Junior Cybersecurity Analyst job-role path. No new modules were released specifically for this path or certification: it's made up of 20 already-existing modules, which we'll cover in this section.

Now let's talk about the knowledge domains that are claimed to be evaluated. Looking at these might make some of you nervous, but don't worry. This is a "Junior" / "Associate" certification, which means they expect you to know some of these topics, not master them in depth. I can confirm that all of these areas were thoughtfully represented on the exam after passing it.

The job-role path consists of 20 modules, as shown in the image above (made by HackTheBox themselves), requiring a total of 810 Cubes to unlock, less when you factor in the completion rewards:
- 11 Tier 0 modules (110 Cubes)
- 4 Tier I modules (200 Cubes)
- 5 Tier II modules (500 Cubes)
The path combines a bit of Offensive (Red) and Defensive (Blue) content, along with 9 fundamental modules. Don't underestimate those fundamentals: some of them offer a genuinely different perspective on things you may already know. That said, I did use the word "some," because there are other modules that can be tedious, so I hope you have enough patience to clear them all. 😄
I've calculated the actual cube cost to unlock the full path: 560 Cubes net, after deducting the completion rewards.

That's right: Tier 0 modules give you all your Cubes back, Tier I modules give back 10 Cubes, and Tier II modules give back 20 Cubes, bringing the net total cube cost to 560.


If you have an educational email, you don't need to worry about any of this: just subscribe to the "Student" monthly tier for $8 and you can access all these modules. Add $125 (VAT included) for the exam voucher, and your total cost is just $132. But for those without a student email, here's what I recommend.

If you're going to invest in this certification, invest wisely. In my honest opinion, the CJCA isn't the most cost-efficient standalone purchase: I'd recommend aiming for intermediate-level certifications like CPTS, CBBH, or CDSA instead. HackTheBox seems to understand this too, which is why the CJCA exam voucher is included in the Silver Annual subscription. It's essentially the same deal as before, but with the CJCA voucher bundled in. So if your employer is covering the cost, go for it. If you're spending your own money, the annual subscription is a far smarter investment for the value you get.

Now let's talk cube spending for those who want to see exactly how it plays out. Assuming you're starting with a fresh account (30 Cubes by default) and have at least 10 Cubes to spare, here's the strategy:
- Complete the Tier 0 modules one at a time. Since each costs 10 Cubes and gives 10 back on completion, you only ever need 10 Cubes available at once. After finishing all Tier 0 modules, you'll need 550 more Cubes to unlock everything else.
- Charge $38 to get 500 Cubes and unlock all Tier II modules. Clear them, and you'll unlock 2 Tier I modules, with 2 remaining Tier I modules still locked.

- At this point, you can either wait for your next monthly Cube allocation from your subscription, or purchase an additional 100 Cubes ($12 including VAT).

Total cost including the exam voucher (assuming no Silver Annual subscription and no student pricing) would be: $125 (exam voucher) + $38 (one month of Gold to unlock content) + $12 (100 Cubes) = $175 USD. Surprisingly affordable for a well-known cybersecurity platform. The decision is yours.
One more thing worth mentioning: once you've completed this path, you'll have already finished 2 modules of the CPTS job-role path (out of 28) and 5 modules of the CDSA job-role path (out of 15). So if blue teaming is your goal, just 10 more modules stand between you and the CDSA exam.
Key takeaways from this section:
- You need to complete the Junior Cybersecurity Analyst job-role path before taking the CJCA exam.
- The path consists of 20 modules covering Tier 0, Tier I, and Tier II levels.
- The most budget-friendly way to unlock the full path and purchase the exam voucher is $175 USD (including VAT).
- The Silver Annual subscription includes the CJCA exam voucher and unlocks all modules: no extra Cube purchases needed.
- 5 out of the 20 modules in this path overlap with the CDSA job-role path, giving you a head start if you plan to continue down the blue team route.
As mentioned earlier, some modules in the path are just tedious, so here are the ones I recommend spending focused time on. These will equip you with enough knowledge to pass the exam:
- Pentest in a Nutshell: strongly recommended; spend time here and take detailed notes
- Footprinting: great module that teaches you to enumerate and find vulnerabilities across various network protocols
- Windows Event Logs & Finding Evil: your introduction to the world of Windows Event Logs
- Security Monitoring & SIEM Fundamentals: learn about SIEM and build dashboards in Elastic
- Introduction to Threat Hunting & Hunting With Elastic: simulated threat hunting with Elastic SIEM
For those with a penetration testing or red teaming background: the path doesn't fully prepare you for the SIEM portion of the exam. You'll likely get stuck at some point. Even having already passed CDSA, I'll admit the SIEM section in this exam is tough: probably more advanced than what's expected of a typical SOC L1 analyst in some countries. But if you're motivated, you can pick up the key concepts during the exam itself and apply them on the fly. If you already have the voucher: take the shot. It's completely okay to fail on the first try. You'll walk away knowing exactly what to improve, and that knowledge will carry you through on your second attempt.
People will ask: "Are there any extra resources that'll help prepare for the exam?", and the answer is yes, specifically for the SIEM side. The offensive modules are more than enough to build the right mindset for the pentest section. But for the SIEM part? Even completing all the CDSA job-role path modules may not be sufficient.
My advice: get comfortable with Elastic SIEM. The modules will teach you to build dashboards, but practicing with varied scenarios across different log sources will deepen your understanding significantly. To that end, here's a GitHub repository I created that collects SIEM practice labs for both Splunk and Elastic:
That's all I can share on preparation due to the ToS, and remember, this is still a "Junior" certification.
I was eager to be the first Thai to take and pass this exam, but a tight schedule and overwhelming workload pushed the earliest possible date to August 1st, 2025. Unfortunately, someone I know (who had already passed HTB CBBH and HTB CPTS) bought the voucher and took the exam before me. So I gave up on that particular goal.
Then I realized something: HackTheBox grades and announces certification results in batches. So if he and I took the exam in the same batch window, we'd technically both be the first Thais to pass it simultaneously.
The exam was released on July 23rd, 2025, and it typically takes around 20 business days to be graded (though usually much sooner). Even starting on August 1st, there was still plenty of time before the first batch would be graded and announced.

Since August 1st was a Friday and I was managing two projects simultaneously, I was completely exhausted by the end of the day. I ended up hitting "Enter Exam" around 2 AM on August 2nd, 2025 (local time). Later than planned, but the show must go on.

The exam opens with its terms and conditions, which you must accept to begin. Once you do, the clock starts. All the relevant information is laid out immediately: engagement details, requirements, objectives, scope, and a report template, so you won't need to source a template separately.

I had a different plan for reporting, though. I knew SysReptor already had a template for the CJCA exam, so I created the project beforehand and pre-filled basic info (like my name) before the exam even started. Using SysReptor means zero formatting headaches when you're putting the final touches on your report. I really liked it. Highly recommended.
The exam also provides an OpenVPN configuration file to connect from your own machine, or you can use HTB's "AttackBox" directly in the browser. That means you could technically connect to the exam environment from anywhere, even your workplace. (Assuming, of course, you don't tell anyone about it: that would violate the ToS.)

I went with OpenVPN since I already have all the tools I need on my Kali VM. I started with the penetration testing portion, which took me around 13 hours (including sleep) to capture all the flags, leaving me with 4 days and 11 hours to triage SIEM alerts and complete the exam report.
You might be wondering: is the exam that easy? Well, yes: this is a Junior certification, so it's not as intense as CBBH or CPTS, and I'd expect it's even lighter than the Pro Labs. Proper enumeration is all you need. The phrase keeps repeating itself for a reason: "Enumeration is the key."
Rather than jumping straight into SIEM triage, I spent time organizing my notes first, because those notes would directly feed my exam report. While conducting any engagement, take proper notes that will serve your future self, not just your current self.
After getting my notes in order, I started triaging the SIEM alerts, and I was genuinely surprised. Some of the log sources that appeared weren't ones I'd investigated in a SIEM before. That said, they weren't too different from what I was familiar with, so I knew how to approach them. Still, it took me a full day to triage everything. It wasn't impossibly hard, but Elastic isn't my preferred SIEM: I'd always pick Splunk if I had the choice.
The sheer volume of events aggregated in the SIEM was also significant. Unlike SAL1, which brands itself as a Junior/SOC L1-level exam and keeps data volumes manageable, this one doesn't hold back. You'll need to stay organized and know exactly what you're looking for, just as you would in a real threat hunting scenario.
I finished triaging everything around midnight, then called it a night to let my body decompress. I wanted a fresh mind the next morning for the report.


I spent all of Sunday writing and polishing the report, then submitted it: I had work on Monday and needed to be done. My organized notes made the whole process faster than expected. After that, it was just a matter of waiting for the first batch announcement.

Morning of August 21st. While getting ready for the TB-CERT Annual Security Conference 2025, I checked my inbox and found an email from HackTheBox. I'm now officially a Certified Junior Cybersecurity Associate (CJCA). The news gave me an instant boost and set the perfect tone for the day. I headed straight to HackTheBox Academy to claim my certificate.

The certificate has to be manually claimed from the Academy.

You'll need to specify the name to display on the certificate: it can be anything. I've seen many people use a made-up or "signature" name. If you want to look professional, I'd recommend using your real name.

After clicking "NEXT," your name will appear on a certificate preview. You can still go back and modify it. Once you're happy with how it looks, click "CLAIM CERTIFICATE" to make it official.

You can now download your certificate in PDF format: the only format currently supported. You can convert it to PNG or JPG later if you want to post it on LinkedIn or other platforms.

One thing worth noting: don't skip the examiner's feedback section on the certification page. I won't share mine here, but it was great and constructive, and it'll help me write a better report when I attempt CPTS later. As you can also see, there's no "Print Certificate" option yet, no pins, stickers, or T-shirts for CJCA either. They may add them alongside CAPE, or all at once, but for now, it's digital only.


After claiming your certificate, a separate email will arrive with your badge.

You can find your Certificate ID in the top-right corner of your certificate. Head to the HackTheBox Discord and use the /verifycertification command to claim your role. At the time of writing, CJCA certificate verification hadn't been deployed yet: I'll update this section once it goes live.
- Stay organized: disorganization only complicates everything downstream.
- Stay hydrated. Dehydration will affect your performance and focus in any high-pressure environment.
- Remember, this is a 'Junior' cert: what might seem basic to an experienced penetration tester is still valid and worth doing properly.
- Save all scan results to files so you never have to re-run them.
- Always run network scans more than once on the same host: you may miss something on the first pass.
- Think outside the box and chain multiple vulnerabilities. If one isn't enough, look for a second or even a third.
- This is a real-world enterprise network: keep that in mind and it will serve you well. 😉
- Practice threat hunting with Elastic until you're comfortable correlating multiple log sources and confirming findings with confidence.
- A timeline is crucial for every investigation: build it as you go.
- Keep the SIEM URL for each alert. When you apply filters in Elastic, the URL updates to reflect your current view: bookmark it so you can return to the same perspective later if you need to verify something.
- Don't just close alerts robotically with "This is TP." Explain <em>why</em> a specific alert is a True Positive (TP) or a False Positive (FP).
- Research your FP alerts: you need to understand what's normal in the environment and what isn't.
That's all for this blog. Thank you for your time, and good luck to anyone preparing for the exam!