100+ Free HTB CJCA Practice Questions
Prepare for the HTB Certified Junior Cybersecurity Associate exam with instant access — no signup required.
Loading practice questions...
Explore More Hack The Box Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: HTB CJCA Exam
5 days
Practical Exam Window
Hack The Box
100%
Practical (No MCQ Component)
Hack The Box
20 modules
Junior Cybersecurity Analyst Path Length
HTB Academy
50%
Tier 0 Modules Available Free
HTB Academy
~$490/yr
Silver Annual Subscription (includes voucher)
Hack The Box
6 domains
Exam Coverage Areas
HTB CJCA Curriculum
The HTB CJCA is Hack The Box's beginner-friendly hybrid certification (offensive + defensive) mapped to the 20-module Junior Cybersecurity Analyst job-role path. The practical 5-day exam involves compromising machines and analyzing security logs/alerts. Half the preparatory modules are free on HTB Academy. The Silver Annual subscription (~$490/year) includes one exam voucher. This practice bank covers all six domains: Linux/Windows fundamentals, networking/Wireshark, Elastic SIEM/KQL, security monitoring/event logs, intro pentesting, and incident handling.
Sample HTB CJCA Practice Questions
Try these sample questions to test your HTB CJCA exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which layer of the OSI model is responsible for logical addressing and routing packets between networks?
2A Linux file has permissions `-rwxr-x---`. Which group of users can execute this file?
3Which TCP flag combination is used during the TCP three-way handshake to initiate a connection?
4In Wireshark, which display filter would show only HTTP traffic on port 80?
5What does the CIA triad stand for in information security?
6Which Linux command displays the current user's id and group memberships?
7What is the primary purpose of a SIEM (Security Information and Event Management) system?
8In Windows, which Event ID indicates a successful logon?
9Which nmap flag is used to perform a SYN (stealth) scan?
10What does the Elastic KQL query `event.category: "network" AND destination.port: 443` return?
About the HTB CJCA Exam
The HTB CJCA (Certified Junior Cybersecurity Associate) is Hack The Box's entry-level hybrid certification covering both offensive and defensive cybersecurity fundamentals. Unlike purely theoretical exams, CJCA is a 100% practical hands-on assessment across a 5-day window involving machine compromise and blue-team log analysis. This practice exam tests the theoretical knowledge needed: Linux/Windows commands, networking, Wireshark, Elastic KQL, Windows Event IDs, incident handling, and basic pentesting concepts.
Assessment
Performance-based assessment
Time Limit
5-day practical lab window
Passing Score
Practical objectives (threshold not published)
Exam Fee
HTB Academy Silver Annual (~$490/year) or standalone voucher (Hack The Box)
HTB CJCA Exam Content Outline
Linux & Windows Fundamentals
Linux CLI (chmod, find, grep, sudo, cron, /etc/shadow), Windows (registry hives, PowerShell cmdlets, ipconfig, net user, hostname), bash scripting variables, and IT fundamentals
Networking & Traffic Analysis
OSI model, TCP three-way handshake and flags, DNS, DHCP, SMB ports, Wireshark display filters (ip.src, tcp.port, dns.flags.response, http.request.method), tcpdump, ARP spoofing detection
SIEM Fundamentals & Elastic Stack
ELK components (Elasticsearch indexing, Logstash pipelines, Kibana dashboards, Winlogbeat shipping), KQL syntax (field: value, AND/OR/NOT, wildcards, CIDR ranges, ECS fields), detection rules
Security Monitoring & Windows Event Logs
Key Event IDs (4624 logon, 4625 failed logon, 4688/4720/4732 process/account/group changes), Sysmon IDs (1 process, 3 network, 7 DLL, 11 file), True/False Positive triage, SOC Tier 1 role
Intro Penetration Testing & Basic Exploitation
Pentest methodology phases, nmap flags (-sS, -sV, -O, -p-, -sC, --script=vuln), Metasploit (search, RHOST/LHOST, msfvenom), Gobuster, reverse shells, post-exploitation (id, sudo -l, find SUID)
Incident Handling & Threat Hunting
NIST SP 800-61 lifecycle phases (Preparation, Detection, Containment, Eradication, Recovery, Post-Incident), hypothesis-driven hunting, MITRE ATT&CK tactics/techniques, incident report components
How to Pass the HTB CJCA Exam
What You Need to Know
- Passing score: Practical objectives (threshold not published)
- Assessment: Performance-based assessment
- Time limit: 5-day practical lab window
- Exam fee: HTB Academy Silver Annual (~$490/year) or standalone voucher
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
HTB CJCA Study Tips from Top Performers
Frequently Asked Questions
What is the HTB CJCA exam format?
The HTB CJCA is a 100% practical hands-on exam with a 5-day window. It is a hybrid assessment combining offensive tasks (machine compromise) and defensive tasks (log analysis, alert triage). Candidates must analyze approximately 40 security log alerts as True Positive or False Positive, compromise several machines in a realistic lab environment, and submit a professional report documenting their findings.
What topics does the HTB CJCA cover?
CJCA covers six domains: (1) Linux and Windows fundamentals; (2) Networking and traffic analysis with Wireshark; (3) SIEM fundamentals using Elastic Stack and KQL; (4) Security monitoring and Windows Event Log analysis; (5) Introduction to penetration testing with Nmap and Metasploit; and (6) Incident handling using the NIST SP 800-61 framework and threat hunting with Elastic.
How do I prepare for the HTB CJCA?
Complete the Junior Cybersecurity Analyst job-role path on HTB Academy. The path contains 20 modules including Linux Fundamentals, Windows Fundamentals, Network Traffic Analysis, Security Monitoring & SIEM Fundamentals, Windows Event Logs & Finding Evil, and Introduction to Threat Hunting & Hunting with Elastic. Half the modules are free. Take detailed notes, practice each module's hands-on exercises, and use this practice exam to test your conceptual knowledge.
Is the HTB CJCA good for beginners?
Yes — the CJCA is explicitly designed for complete beginners and career changers entering cybersecurity. No prior security experience is required. It covers foundational IT concepts alongside security-specific content, and half the preparatory modules are free. The 5-day exam window is generous compared to other certifications. It is an excellent first cybersecurity certification before advancing to CompTIA Security+, HTB CDSA, or eJPT.
How much does the HTB CJCA cost?
The CJCA exam voucher is included with the HTB Academy Silver Annual subscription (~$490/year), which also provides access to the full Junior Cybersecurity Analyst learning path. Standalone exam vouchers may also be available — check the HTB Academy website for current pricing. Silver Annual subscribers after September 1, 2025 receive an extra CJCA exam voucher.
Is this practice exam like the real HTB CJCA?
No — this is a theoretical multiple-choice practice exam covering the knowledge base behind CJCA topics. The real HTB CJCA is 100% practical: you must actually compromise machines and analyze real security logs in a lab environment. Use this practice exam to test your conceptual understanding of tools, commands, and methodology, then validate hands-on skills through the HTB Academy modules and Hack The Box machines.