all posts

blog post

earning tryhackme security analyst level 1

my favorite certification so far

i earned the tryhackme security analyst level 1 (sal1) certification to continue building my hands-on defensive cybersecurity skills. after completing certifications like btl1, cysa+, and security+, i wanted to keep getting more practical experience with the types of investigations and tasks that a security analyst might encounter. sal1 focused heavily on applying those skills through realistic, hands-on scenarios rather than simply memorizing concepts.

to prepare for the exam, i worked through tryhackme’s training material and hands-on labs. the platform gave me plenty of opportunities to practice investigating security incidents, analyzing logs, working with security tools, and identifying malicious activity. having the training built around practical exercises made it easier to connect the concepts i was learning with how they would actually be used in real life by a security analyst.

the exam itself continued that hands-on approach. rather than answering traditional multiple-choice questions, i had to investigate simulated security incidents inside a soc environment and use the available evidence and tools to determine what had happened. i enjoyed having to work through the scenarios myself, decide where to look next, and piece together information from different sources instead of simply selecting an answer from a list.

having already completed btl1 was especially helpful because i was familiar with the general process of working through a practical cybersecurity exam. sal1 gave me another opportunity to reinforce those skills while becoming more comfortable analyzing evidence and working through investigations under a time limit.

overall, sal1 is easily the most comprehensive, in-depth, and engaging certification that i’ve earned so far. i liked btl1, but this one covered so much more material and was definitely more challenging. i found the simulated soc environment for the exam too be really unique as well, having me respond to alerts and identify true/false positives and creating reports, like you would as an actual security analyst. for anyone who wants to really know what blue team cybersecurity work looks like, i would strongly recommend sal1.