Skip to content
Your First Definitive Guide and Review on HackTheBox CJCA Certification Exam

Your First Definitive Guide and Review on HackTheBox CJCA Certification Exam

August 2025HackTheBoxPassed
Certification
CJCA
Provider
HackTheBox
Difficulty
Beginner
Rating
★★★★½4.5/5.0
Introduction

Hello everyone! Chicken0248 here again, and this time, I've successfully passed a newly released certification: the HTB Certified Junior Cybersecurity Associate (HTB CJCA), released on 23rd July 2025. It's now the entry-level certification for people interested in both Pentesting and SOC. Yes, that means you'll need to conduct penetration testing and triage alerts with a SIEM. So without further ado, let's talk about this certification, the job-role path you need to complete before taking the exam, exam preparation, and my experience!

HackTheBox certification ladder — current state
Figure 1

The current state of HackTheBox certifications: I'm still waiting for a Specialized Role certification on the blue team side!

Exam Prerequisite & Path Unlocking Strategy
Junior Cybersecurity Analyst job-role path overview
Figure 2

For those already familiar with HackTheBox Academy and its certifications, you'll know that every certificate has a "job-role" path associated with it: you must complete all modules in the path before you can use your exam voucher. HTB CJCA follows that same pattern, aligning with the Junior Cybersecurity Analyst job-role path. No new modules were released specifically for this path or certification: it's made up of 20 already-existing modules, which we'll cover in this section.

CJCA exam knowledge domains
Figure 3

Now let's talk about the knowledge domains that are claimed to be evaluated. Looking at these might make some of you nervous, but don't worry. This is a "Junior" / "Associate" certification, which means they expect you to know some of these topics, not master them in depth. I can confirm that all of these areas were thoughtfully represented on the exam after passing it.

Junior Cybersecurity Analyst path — 20 modules breakdown
Figure 4

The job-role path consists of 20 modules, as shown in the image above (made by HackTheBox themselves), requiring a total of 810 Cubes to unlock, less when you factor in the completion rewards:

  • 11 Tier 0 modules (110 Cubes)
  • 4 Tier I modules (200 Cubes)
  • 5 Tier II modules (500 Cubes)

The path combines a bit of Offensive (Red) and Defensive (Blue) content, along with 9 fundamental modules. Don't underestimate those fundamentals: some of them offer a genuinely different perspective on things you may already know. That said, I did use the word "some," because there are other modules that can be tedious, so I hope you have enough patience to clear them all. 😄

I've calculated the actual cube cost to unlock the full path: 560 Cubes net, after deducting the completion rewards.

Cube reward breakdown per tier
Figure 5

That's right: Tier 0 modules give you all your Cubes back, Tier I modules give back 10 Cubes, and Tier II modules give back 20 Cubes, bringing the net total cube cost to 560.

Student subscription pricing details
Figure 6
Student monthly subscription — best value option
Figure 7

If you have an educational email, you don't need to worry about any of this: just subscribe to the "Student" monthly tier for $8 and you can access all these modules. Add $125 (VAT included) for the exam voucher, and your total cost is just $132. But for those without a student email, here's what I recommend.

HTB Silver Annual subscription — includes CJCA voucher
Figure 8

If you're going to invest in this certification, invest wisely. In my honest opinion, the CJCA isn't the most cost-efficient standalone purchase: I'd recommend aiming for intermediate-level certifications like CPTS, CBBH, or CDSA instead. HackTheBox seems to understand this too, which is why the CJCA exam voucher is included in the Silver Annual subscription. It's essentially the same deal as before, but with the CJCA voucher bundled in. So if your employer is covering the cost, go for it. If you're spending your own money, the annual subscription is a far smarter investment for the value you get.

Cube spending strategy overview
Figure 9

Now let's talk cube spending for those who want to see exactly how it plays out. Assuming you're starting with a fresh account (30 Cubes by default) and have at least 10 Cubes to spare, here's the strategy:

  • Complete the Tier 0 modules one at a time. Since each costs 10 Cubes and gives 10 back on completion, you only ever need 10 Cubes available at once. After finishing all Tier 0 modules, you'll need 550 more Cubes to unlock everything else.
  • Charge $38 to get 500 Cubes and unlock all Tier II modules. Clear them, and you'll unlock 2 Tier I modules, with 2 remaining Tier I modules still locked.
Gold subscription — 500 cube purchase
Figure 10
  • At this point, you can either wait for your next monthly Cube allocation from your subscription, or purchase an additional 100 Cubes ($12 including VAT).
100 Cubes additional purchase — $12 including VAT
Figure 11

Total cost including the exam voucher (assuming no Silver Annual subscription and no student pricing) would be: $125 (exam voucher) + $38 (one month of Gold to unlock content) + $12 (100 Cubes) = $175 USD. Surprisingly affordable for a well-known cybersecurity platform. The decision is yours.

One more thing worth mentioning: once you've completed this path, you'll have already finished 2 modules of the CPTS job-role path (out of 28) and 5 modules of the CDSA job-role path (out of 15). So if blue teaming is your goal, just 10 more modules stand between you and the CDSA exam.

Key takeaways from this section:

  • You need to complete the Junior Cybersecurity Analyst job-role path before taking the CJCA exam.
  • The path consists of 20 modules covering Tier 0, Tier I, and Tier II levels.
  • The most budget-friendly way to unlock the full path and purchase the exam voucher is $175 USD (including VAT).
  • The Silver Annual subscription includes the CJCA exam voucher and unlocks all modules: no extra Cube purchases needed.
  • 5 out of the 20 modules in this path overlap with the CDSA job-role path, giving you a head start if you plan to continue down the blue team route.
Exam Preparation

As mentioned earlier, some modules in the path are just tedious, so here are the ones I recommend spending focused time on. These will equip you with enough knowledge to pass the exam:

  • Pentest in a Nutshell: strongly recommended; spend time here and take detailed notes
  • Footprinting: great module that teaches you to enumerate and find vulnerabilities across various network protocols
  • Windows Event Logs & Finding Evil: your introduction to the world of Windows Event Logs
  • Security Monitoring & SIEM Fundamentals: learn about SIEM and build dashboards in Elastic
  • Introduction to Threat Hunting & Hunting With Elastic: simulated threat hunting with Elastic SIEM

For those with a penetration testing or red teaming background: the path doesn't fully prepare you for the SIEM portion of the exam. You'll likely get stuck at some point. Even having already passed CDSA, I'll admit the SIEM section in this exam is tough: probably more advanced than what's expected of a typical SOC L1 analyst in some countries. But if you're motivated, you can pick up the key concepts during the exam itself and apply them on the fly. If you already have the voucher: take the shot. It's completely okay to fail on the first try. You'll walk away knowing exactly what to improve, and that knowledge will carry you through on your second attempt.

People will ask: "Are there any extra resources that'll help prepare for the exam?", and the answer is yes, specifically for the SIEM side. The offensive modules are more than enough to build the right mindset for the pentest section. But for the SIEM part? Even completing all the CDSA job-role path modules may not be sufficient.

My advice: get comfortable with Elastic SIEM. The modules will teach you to build dashboards, but practicing with varied scenarios across different log sources will deepen your understanding significantly. To that end, here's a GitHub repository I created that collects SIEM practice labs for both Splunk and Elastic:

That's all I can share on preparation due to the ToS, and remember, this is still a "Junior" certification.

Exam Experience

I was eager to be the first Thai to take and pass this exam, but a tight schedule and overwhelming workload pushed the earliest possible date to August 1st, 2025. Unfortunately, someone I know (who had already passed HTB CBBH and HTB CPTS) bought the voucher and took the exam before me. So I gave up on that particular goal.

Then I realized something: HackTheBox grades and announces certification results in batches. So if he and I took the exam in the same batch window, we'd technically both be the first Thais to pass it simultaneously.

The exam was released on July 23rd, 2025, and it typically takes around 20 business days to be graded (though usually much sooner). Even starting on August 1st, there was still plenty of time before the first batch would be graded and announced.

CJCA exam start — August 2025
Figure 12

Since August 1st was a Friday and I was managing two projects simultaneously, I was completely exhausted by the end of the day. I ended up hitting "Enter Exam" around 2 AM on August 2nd, 2025 (local time). Later than planned, but the show must go on.

CJCA exam terms and conditions screen
Figure 13

The exam opens with its terms and conditions, which you must accept to begin. Once you do, the clock starts. All the relevant information is laid out immediately: engagement details, requirements, objectives, scope, and a report template, so you won't need to source a template separately.

SysReptor — CJCA exam report project
Figure 14

I had a different plan for reporting, though. I knew SysReptor already had a template for the CJCA exam, so I created the project beforehand and pre-filled basic info (like my name) before the exam even started. Using SysReptor means zero formatting headaches when you're putting the final touches on your report. I really liked it. Highly recommended.

The exam also provides an OpenVPN configuration file to connect from your own machine, or you can use HTB's "AttackBox" directly in the browser. That means you could technically connect to the exam environment from anywhere, even your workplace. (Assuming, of course, you don't tell anyone about it: that would violate the ToS.)

CJCA exam environment — connected via OpenVPN
Figure 15

I went with OpenVPN since I already have all the tools I need on my Kali VM. I started with the penetration testing portion, which took me around 13 hours (including sleep) to capture all the flags, leaving me with 4 days and 11 hours to triage SIEM alerts and complete the exam report.

You might be wondering: is the exam that easy? Well, yes: this is a Junior certification, so it's not as intense as CBBH or CPTS, and I'd expect it's even lighter than the Pro Labs. Proper enumeration is all you need. The phrase keeps repeating itself for a reason: "Enumeration is the key."

Rather than jumping straight into SIEM triage, I spent time organizing my notes first, because those notes would directly feed my exam report. While conducting any engagement, take proper notes that will serve your future self, not just your current self.

After getting my notes in order, I started triaging the SIEM alerts, and I was genuinely surprised. Some of the log sources that appeared weren't ones I'd investigated in a SIEM before. That said, they weren't too different from what I was familiar with, so I knew how to approach them. Still, it took me a full day to triage everything. It wasn't impossibly hard, but Elastic isn't my preferred SIEM: I'd always pick Splunk if I had the choice.

The sheer volume of events aggregated in the SIEM was also significant. Unlike SAL1, which brands itself as a Junior/SOC L1-level exam and keeps data volumes manageable, this one doesn't hold back. You'll need to stay organized and know exactly what you're looking for, just as you would in a real threat hunting scenario.

I finished triaging everything around midnight, then called it a night to let my body decompress. I wanted a fresh mind the next morning for the report.

Report writing — organized notes in progress
Figure 16
Report writing — polishing the final document
Figure 17

I spent all of Sunday writing and polishing the report, then submitted it: I had work on Monday and needed to be done. My organized notes made the whole process faster than expected. After that, it was just a matter of waiting for the first batch announcement.

Email from HackTheBox — CJCA result notification
Figure 18

Morning of August 21st. While getting ready for the TB-CERT Annual Security Conference 2025, I checked my inbox and found an email from HackTheBox. I'm now officially a Certified Junior Cybersecurity Associate (CJCA). The news gave me an instant boost and set the perfect tone for the day. I headed straight to HackTheBox Academy to claim my certificate.

HTB Academy — claim certificate page
Figure 19

The certificate has to be manually claimed from the Academy.

HTB Academy — specify name for certificate
Figure 20

You'll need to specify the name to display on the certificate: it can be anything. I've seen many people use a made-up or "signature" name. If you want to look professional, I'd recommend using your real name.

Certificate preview with name
Figure 21

After clicking "NEXT," your name will appear on a certificate preview. You can still go back and modify it. Once you're happy with how it looks, click "CLAIM CERTIFICATE" to make it official.

CJCA certificate — ready to download
Figure 22

You can now download your certificate in PDF format: the only format currently supported. You can convert it to PNG or JPG later if you want to post it on LinkedIn or other platforms.

CJCA certification page — examiner feedback section, no print certificate option yet
Figure 23

One thing worth noting: don't skip the examiner's feedback section on the certification page. I won't share mine here, but it was great and constructive, and it'll help me write a better report when I attempt CPTS later. As you can also see, there's no "Print Certificate" option yet, no pins, stickers, or T-shirts for CJCA either. They may add them alongside CAPE, or all at once, but for now, it's digital only.

CJCA badge on Credly — ready to accept
Figure 24
Badge email from HackTheBox
Figure 25

After claiming your certificate, a separate email will arrive with your badge.

HackTheBox Discord — /verifycertification command
Figure 26

You can find your Certificate ID in the top-right corner of your certificate. Head to the HackTheBox Discord and use the /verifycertification command to claim your role. At the time of writing, CJCA certificate verification hadn't been deployed yet: I'll update this section once it goes live.

Exam Tips & Key Takeaways
  • Stay organized: disorganization only complicates everything downstream.
  • Stay hydrated. Dehydration will affect your performance and focus in any high-pressure environment.
  • Remember, this is a 'Junior' cert: what might seem basic to an experienced penetration tester is still valid and worth doing properly.
  • Save all scan results to files so you never have to re-run them.
  • Always run network scans more than once on the same host: you may miss something on the first pass.
  • Think outside the box and chain multiple vulnerabilities. If one isn't enough, look for a second or even a third.
  • This is a real-world enterprise network: keep that in mind and it will serve you well. 😉
  • Practice threat hunting with Elastic until you're comfortable correlating multiple log sources and confirming findings with confidence.
  • A timeline is crucial for every investigation: build it as you go.
  • Keep the SIEM URL for each alert. When you apply filters in Elastic, the URL updates to reflect your current view: bookmark it so you can return to the same perspective later if you need to verify something.
  • Don't just close alerts robotically with "This is TP." Explain <em>why</em> a specific alert is a True Positive (TP) or a False Positive (FP).
  • Research your FP alerts: you need to understand what's normal in the environment and what isn't.

That's all for this blog. Thank you for your time, and good luck to anyone preparing for the exam!