100+ Free BTL1 Practice Questions
Prepare for the Blue Team Level 1 (BTL1) exam with instant access — no signup required.
Loading practice questions...
Explore More Security Blue Team Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: BTL1 Exam
24 hours
Exam Window
Security Blue Team
20 tasks
Exam Challenges
Security Blue Team
70%
Passing Score
Security Blue Team
90%+
Gold Coin Threshold
Security Blue Team
$490
Course + Exam Fee
Security Blue Team
6 domains
Content Areas
BTL1 Syllabus
The BTL1 is a 24-hour, browser-based, open-book practical exam comprising 20 task-based challenges mapped to the MITRE ATT&CK framework. Candidates investigate a simulated corporate breach using Splunk (SIEM), Wireshark (network analysis), and Autopsy (digital forensics). A 70% score (14/20 tasks) earns certification; 90%+ on the first attempt earns a rare physical gold challenge coin. The $490 package includes 330+ lessons, 23 browser labs, one exam, and one free resit. This practice bank covers all six domains to prepare candidates for the knowledge required during the practical investigation.
Sample BTL1 Practice Questions
Try these sample questions to test your BTL1 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which component of the CIA triad ensures that data is accessible to authorized users when needed?
2At which OSI layer does IP addressing and routing occur?
3Which type of malware disguises itself as legitimate software while secretly performing malicious actions in the background?
4A security analyst needs to verify whether a suspicious file has been modified since it was last reviewed. Which approach is most reliable?
5Which port is used by SMTP (Simple Mail Transfer Protocol) for server-to-server email transmission by default?
6During phishing email analysis, an analyst checks the Authentication-Results header and finds 'spf=pass; dmarc=fail'. What is the most likely explanation?
7An analyst is examining a suspicious email and wants to identify the originating IP address. Which header should they examine first?
8A phishing email contains an attachment with a .exe extension renamed to 'invoice.pdf.exe'. Without executing the file, which technique should an analyst use to safely determine what the file actually is?
9Which email authentication protocol adds a cryptographic digital signature to the email header to verify the message has not been tampered with in transit?
10An analyst uses a sandbox to analyze a URL found in a phishing email. The sandbox report shows the page redirects through three different domains before reaching a credential harvesting page. What is this technique called?
About the BTL1 Exam
The BTL1 (Blue Team Level 1) is a hands-on defensive security certification from Security Blue Team designed for aspiring SOC analysts and incident responders. The 24-hour open-book practical exam simulates a real corporate breach investigation using Splunk, Wireshark, and Autopsy. This practice bank tests the theoretical knowledge across all six BTL1 domains.
Assessment
Performance-based assessment
Time Limit
24 hours
Passing Score
70% (14/20 tasks)
Exam Fee
$490 USD (Security Blue Team)
BTL1 Exam Content Outline
Security Fundamentals
CIA triad, OSI model, malware types, common protocols and ports, hashing for integrity, and core defensive security principles
Phishing Analysis
Email header analysis, SPF/DKIM/DMARC authentication, URL and attachment investigation, sandbox tools (VirusTotal, urlscan.io), and IOC extraction
Threat Intelligence
Pyramid of Pain, Diamond Model, MITRE ATT&CK tactics and techniques, Cyber Kill Chain, STIX/TAXII, MISP, and threat actor types
Digital Forensics (Autopsy)
Disk image analysis, NTFS MFT, Windows artifacts (prefetch, ShellBags, UserAssist, Recycle Bin $I/$R files, event logs), timeline analysis, and write-blocker use
SIEM (Splunk)
SPL query fundamentals (stats, eval, timechart, top, lookup), index/sourcetype, Windows event log investigation, brute-force and exfiltration detection
Incident Response & Network Analysis
NIST SP 800-61 IR phases, containment/eradication/recovery, Wireshark display filters, TCP stream analysis, C2 beaconing detection, and HTTP object extraction
How to Pass the BTL1 Exam
What You Need to Know
- Passing score: 70% (14/20 tasks)
- Assessment: Performance-based assessment
- Time limit: 24 hours
- Exam fee: $490 USD
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
BTL1 Study Tips from Top Performers
Frequently Asked Questions
What is the BTL1 exam format?
The BTL1 is a 24-hour, open-book, browser-based practical exam. Candidates are given access to a simulated corporate environment that has experienced a security incident. The exam comprises 20 task-based challenges requiring investigation using Splunk, Wireshark, Autopsy, and other tools. There is no proctor — candidates can use notes, the internet, and their BTL1 course materials. A 70% score (14/20 tasks correct) earns the BTL1 certification.
What tools are used in the BTL1 exam?
The BTL1 exam primarily uses three core tools: Splunk for SIEM log analysis and SPL queries, Autopsy for digital forensics and disk image analysis, and Wireshark for network traffic analysis. Additional tools such as VirusTotal, urlscan.io, CyberChef, and MISP knowledge may be required for phishing and threat intelligence tasks.
What is the BTL1 gold coin?
Security Blue Team awards a physical gold challenge coin to candidates who score 90% or higher (18/20 tasks) on their first attempt at the BTL1 exam. All passing candidates receive a silver challenge coin, digital badge, and printed certificate. The gold coin is a rare, prestigious recognition of exceptional first-attempt performance — only a small percentage of candidates achieve it.
How should I prepare for BTL1?
Complete all 330+ BTL1 course lessons and spend significant time in the 23 browser labs provided with your purchase. Focus heavily on Splunk SPL query practice, Wireshark display filtering, and Autopsy workflows. Build a personal notes document with commonly used SPL queries, Wireshark filters, and phishing investigation checklists — the exam is open-book, so organized notes save critical time during the 24-hour window.
How long does BTL1 preparation take?
Most candidates spend 100-150 hours on BTL1 preparation including working through all course material and labs. At 10-15 hours per week, this translates to 6-10 weeks. Candidates with existing SOC experience often prepare faster. The BTL1 purchase includes 4 months of course access and 12 months to activate the exam.
Is this practice test like the real BTL1 exam?
No — this is a knowledge-prep multiple-choice practice bank. The real BTL1 is a hands-on 24-hour practical exam where you investigate an actual simulated breach environment using real tools. This practice bank tests the underlying knowledge (SPL syntax, Wireshark filters, Windows forensic artifacts, threat intelligence frameworks) that you need to succeed in the practical investigation. Use it alongside hands-on lab practice.