# HTB CJCA: Thoughts and Advice

![](https://cdn.hashnode.com/uploads/covers/673c6b60dcfeadc44f6aa79d/ef7227fd-8d52-48e5-b24f-21fb69dc3ad2.png align="center")

I passed the CJCA, Hack The Box's first junior-level cert. If you're new to the field, take it. If you already work in security, skip it unless you can get it free.

I initially didn't plan to take this certification, but due to their new annual plan model, I had to take it so it wouldn't go to waste.

To set some expectations for you, the reader: I already work full-time in offensive security and organize local HTB community meetups, so the CJCA wasn't exactly on my radar.

## Red and blue in one cert

When CJCA came out I assumed it was purely SOC operations. It has a solid penetration testing section too. It's refreshing to see a cert that gets new students touching both sides of the field.

## Is it worth taking?

For newcomers, yes. It's one of the most budget-friendly options out there and the modules cover a lot of necessary fundamentals.

With prior experience, no, unless it's free. The exam is fun, but there's little value in paying for it once you're further along. Take the modules instead and prepare for something more specialized like CPTS, CWES, or CDSA.

## Don't speedrun the modules

I did. As soon as my Silver Annual subscription activated, I burned through the modules on weekends, didn't overthink the material, and sat the exam as soon as I finished. **Don't copy that.**

HTB gives you all the information you need, and they don't test memorization; that's what cheatsheets and notes are for. What they test is whether you caught the small details. You'll dig back through your notes and find the answer sitting in a module where it got no **emphasis** at all.

## How the five days went

The exam gives you five days for two phases: the penetration test, then SIEM alert validation and analysis.

I started on a Sunday night and kicked off some initial scanning. I was exhausted and had work the next day, so I left the exam running and went to sleep. On Day 2 I finished the first phase in under six hours. It was 6 AM when I finally pwned all of the machines.

![](https://cdn.hashnode.com/uploads/covers/673c6b60dcfeadc44f6aa79d/164ae9e3-ca77-4bca-ae9e-1f56eef12aac.png align="center")

Feeling restless, I started drafting the report and exploring the SIEM alerts. Right as I shifted focus, the SIEM returned a 503. The setup wouldn't let me restart that one machine, and I worried that restarting the whole environment would change the flags on the boxes I'd just pwned so my report wouldn't match. I asked around on Discord and decided to finish the entire pentest report before restarting and moving to phase 2.

![](https://cdn.hashnode.com/uploads/covers/673c6b60dcfeadc44f6aa79d/2db966f5-c872-4722-90b5-ad46a1f28744.png align="center")

Day 3 I poked around the SIEM more and validated about 25% of the alerts while wrapping up the report. Day 4 I locked in hard, and the log correlation needed to back every alert with evidence wore me down fast. At around 80% I stopped to clear my head, then powered through the rest, triple-checked everything, and submitted. I passed a week later.

## Tips

*   **Use Sysreptor for the report.** Play with it before the exam and start from an existing template. The templates give you the exact sections a commercial-grade report needs, so you fill in findings instead of fighting formatting.
    
*   **The modules are enough.** Get comfortable with Elastic SIEM, experiment, learn how Sysmon logs are generated, and learn the patterns of normal versus malicious behavior. Outside labs won't hurt, but the Academy practice labs and skills assessments will get you there.
    
*   **Learn to enumerate.** Sometimes people are lazy and leave important information sitting in plain sight. Research what you don't know: knowing what to search for gets you further than knowing the answer, and don't lose situational awareness.
