100+ Free SBT CJDE Practice Questions
Prepare for the Security Blue Team Certified Junior Detection Engineer exam with instant access — no signup required.
Loading practice questions...
Explore More Security Blue Team Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: SBT CJDE Exam
£399
Course + Exam Fee
Security Blue Team
15 modules
Course Structure
Security Blue Team
120+ hours
Available Lab Hours
Security Blue Team
Intermediate
Difficulty Level
Security Blue Team
40-60 hrs
Avg. Completion Time
Security Blue Team
2025
Year Launched
Security Blue Team
The SBT CJDE (Certified Junior Detection Engineer) certifies entry-to-intermediate detection engineering skills through a practical scenario-based exam. Core domains include Sigma & YARA rule writing, SIEM operations (Splunk, Elastic, Graylog), Zeek network log analysis, threat intelligence integration (MISP, STIX/TAXII, MITRE ATT&CK), and CI/CD detection pipelines with Git and GitHub Actions. The £399 course includes 15 modules, 120+ labs, and the practical exam. This 100-question knowledge-prep bank covers all CJDE domains to build the conceptual foundation for the hands-on exam.
Sample SBT CJDE Practice Questions
Try these sample questions to test your SBT CJDE exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1Which Sigma rule field specifies the log source technology, product, and service to ensure the rule targets the correct event stream?
2A YARA rule must match a file that contains the string 'MZ' at offset 0 AND has a PE section named '.text'. Which YARA condition correctly expresses this?
3In Zeek, which log file records metadata about every TCP, UDP, and ICMP connection observed on the network, including duration, bytes transferred, and connection state?
4Which Splunk SPL command transforms raw events into a statistical table, making it essential for building detection dashboards and alert conditions?
5A detection engineer wants to create a Git branch for a new Sigma rule, make changes, and merge via pull request so automated YARA/Sigma linting runs in CI. What is the correct sequence of Git commands to start this workflow?
6Which MITRE ATT&CK technique ID corresponds to the use of PowerShell for execution, commonly detected by enabling PowerShell Script Block Logging?
7In Elastic SIEM, which query language is optimized for event sequence detection across multiple documents and is specifically designed for temporal correlation of attack chains?
8A detection engineer receives a threat intelligence report containing a list of malicious IP addresses in STIX 2.1 format. Which tool is specifically designed to ingest, store, and share STIX/TAXII threat intelligence feeds?
9Which Sigma rule modifier changes a keyword match to be case-sensitive and requires the field value to end with the specified string?
10When writing a YARA rule to detect a specific malware family, why is it generally better to use unique internal strings (e.g., mutex names, error messages) rather than file hashes as the primary detection mechanism?
About the SBT CJDE Exam
The CJDE (Certified Junior Detection Engineer) is Security Blue Team's practical certification for detection engineering professionals. Launched in 2025, it covers the full detection engineering lifecycle: writing and converting Sigma rules for Splunk and Elastic, building YARA rules for malware detection, analyzing network telemetry with Zeek, integrating threat intelligence via MISP and STIX/TAXII, and managing detection rules through Git CI/CD pipelines. This practice test covers the knowledge domains tested in the CJDE exam.
Assessment
Performance-based assessment
Time Limit
Practical scenario-based (time not disclosed)
Passing Score
Not published
Exam Fee
£399 (~$500 USD) (Security Blue Team (Centri))
SBT CJDE Exam Content Outline
Sigma & YARA Detection Rule Writing
Sigma rule structure (logsource, detection, condition, modifiers, status, tags), pySigma/sigma-cli conversion, YARA strings/conditions/modules, false positive management, and rule tuning
SIEM Operations
Splunk SPL (stats, timechart, rex, eval, iplocation, macros, webhooks), Elastic KQL/EQL (sequence detection, threshold rules, alert suppression, ML rules), and Graylog Lucene query syntax
Zeek Network Detection
Zeek log ecosystem (conn.log, dns.log, ssl.log, x509.log, files.log, smb_files.log, notice.log), Intel framework, Zeek scripting language, and network threat hunting patterns
Threat Intelligence Integration
STIX 2.1 object model, TAXII, MISP (to_ids flag, attributes, galaxy clusters), threat intel lifecycle, MITRE ATT&CK technique mapping, IOC operationalization, and behavioral analytics/UEBA
CI/CD with Git & Alert Triage
Git branching/blame/rebase, GitHub Actions workflows, Detection-as-Code practices, detection unit testing, AI-assisted detection engineering, and SOC alert triage methodology
How to Pass the SBT CJDE Exam
What You Need to Know
- Passing score: Not published
- Assessment: Performance-based assessment
- Time limit: Practical scenario-based (time not disclosed)
- Exam fee: £399 (~$500 USD)
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
SBT CJDE Study Tips from Top Performers
Frequently Asked Questions
What is the SBT CJDE exam format?
The CJDE exam is a practical, scenario-based assessment that replicates real SOC detection engineering tasks. Unlike multiple-choice exams, it tests applied skills including writing Sigma and YARA rules, analyzing Zeek and SIEM logs, and working with detection pipelines. The course includes 15 modules and 120+ hands-on labs. Security Blue Team does not publicly disclose the specific exam duration or passing score threshold.
What tools and platforms does the CJDE cover?
The CJDE curriculum covers: Sigma rules (with sigma-cli and pySigma conversion to Splunk, Elastic, and Graylog); YARA rules for file and memory scanning; Zeek network analysis framework; Splunk (SPL queries, alerts, dashboards); Elastic SIEM (KQL, EQL, detection rules); Graylog (Lucene syntax); MISP for threat intel; Git and GitHub Actions for Detection-as-Code; Python basics for scripting; and AI tools for detection assistance.
How much does the CJDE cost?
The CJDE course and exam package costs £399 GBP (approximately $500 USD at current exchange rates). This includes 4-month access to the full self-paced course (15 modules, 400+ lessons, 120+ labs) and the practical exam. Achieving 90%+ on the first attempt earns a gold challenge coin instead of the standard silver.
How hard is the SBT CJDE?
The CJDE is rated as an intermediate-level certification. It requires practical skills across multiple tool sets — candidates who can write working Sigma rules, query Splunk and Elastic with real log data, and understand Zeek log structure are best positioned to pass. The 40-60 hour course estimate assumes 1-3 years of prior cybersecurity experience. Candidates without SOC experience should budget extra time for the 120+ available lab hours.
What jobs does CJDE qualify me for?
The CJDE demonstrates detection engineering skills valued in: SOC Analyst Tier 2 ($75,000-$110,000), Detection Engineer ($90,000-$140,000), Threat Hunter ($95,000-$135,000), Security Operations Engineer ($85,000-$130,000), and SIEM Administrator ($70,000-$105,000) roles. It complements broader certifications (CompTIA Security+, BTL1) and demonstrates hands-on detection capability.
Is this practice exam like the real CJDE?
No — this is a knowledge-based multiple-choice practice exam. The real CJDE is a practical scenario-based exam where you perform actual detection engineering tasks (writing rules, analyzing logs, building pipelines) in a lab environment. This practice exam tests the conceptual knowledge underlying those practical skills. To pass the real CJDE, you need extensive hands-on lab practice with Sigma, YARA, Zeek, Splunk, and Elastic.