blog post
earning blue team level 1
my first hands-on certification
i earned the blue team level 1 (btl1) certification in november 2024 to get more hands-on experience with defensive cybersecurity. unlike the other certifications i had completed (cysa+ and security+), btl1 was much more focused on practical skills and applying what i knew in realistic simulated scenarios. the material covered topics such as phishing analysis, digital forensics, security information and event management (siem), threat intelligence, and incident response.
to prepare for the exam, i worked through the training material and labs included with the certification. the hands-on labs were especially useful because they gave me experience using real security tools and investigating scenarios instead of simply reading about the concepts. i found this approach much more engaging and appreciated being able to practice the skills as i learned them.
the exam itself was also a very different experience from the multiple-choice certification exams i had taken previously. instead of answering questions about what i would do in a given situation, i actually had to investigate a simulated security incident, analyze the available evidence, determine what had happened, and create a report, all in a limited amount of time. it made the exam feel much closer to the type of work the certification was designed to prepare me for.
my favorite part of the certification was the phishing analysis section. analyzing email content and headers, then using that information to investigate potentially malicious links or attachments, felt like solving a puzzle or a mystery and gave me that dopamine rush from finding the answer.
for anyone interested in blue team or security operations work, i’d recommend btl1 as a good introduction to the practical side of cybersecurity. the combination of training material, hands-on labs, and a practical exam made it one of the more engaging certifications i’ve completed.