100+ Free SAL1 Practice Questions
Pass your TryHackMe Security Analyst Level 1 (SAL1) exam on the first try — instant access, no signup required.
A SOC analyst observes outbound HTTPS traffic to an IP address that appears in a threat intelligence feed as a known C2 server. The internal host making the connection has no legitimate business reason to contact external IPs directly. Which action should the analyst take FIRST?
Explore More TryHackMe Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: SAL1 Exam
750/1000
Passing Score
TryHackMe
80 MCQ + 2 Simulations
Exam Components
TryHackMe
24 hours
Exam Window
TryHackMe
20% MCQ / 80% Practical
Score Distribution
TryHackMe
Browser-based
Exam Delivery
TryHackMe
Entry–Intermediate
Difficulty Level
TryHackMe
The TryHackMe Security Analyst Level 1 (SAL1) is a practical SOC analyst certification with a 24-hour exam window comprising 80 MCQ (200 pts / 20%) plus two SOC simulator scenarios (400 pts each / 40% each). Candidates need 750/1000 to pass. The exam uses a browser-based SOC environment with Splunk and email analysis tools.
Sample SAL1 Practice Questions
Try these sample questions to test your SAL1 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1A SOC analyst receives an alert classified as 'High' severity in the SIEM. The alert was triggered by a single failed login attempt from an internal IP address. What is the most appropriate first action?
2In the TryHackMe SOC Level 1 path, which framework ranks Indicators of Compromise (IoCs) by the level of difficulty they impose on an attacker when defenders detect and act on them?
3An analyst examines a suspicious email and notes the 'From' display name shows 'IT Support <help@company.com>' but the actual 'Reply-To' header points to 'admin@malicious-domain.xyz'. Which phishing technique is being used?
4What does the SPF (Sender Policy Framework) DNS record do in email authentication?
5A SIEM alert fires for a successful authentication to an admin console from a known-clean internal IP at 2:14 AM on a weekend. The user account belongs to a software developer with no admin privileges. Which verdict is most appropriate?
6In the Cyber Kill Chain model developed by Lockheed Martin, at which stage does the attacker first interact with the target system by sending a malicious email with an infected attachment?
7When analyzing a packet capture in Wireshark, an analyst sees multiple TCP SYN packets sent to different ports on the same destination IP with no corresponding SYN-ACK responses. What activity is most likely occurring?
8A Splunk SPL (Search Processing Language) query needs to count the number of failed login events per source IP in the last 24 hours. Which query structure is correct?
9What is the primary difference between an Indicator of Compromise (IoC) and an Indicator of Attack (IoA)?
10An analyst is reviewing Windows Security Event Log for signs of brute-force activity. Which Event ID indicates a successful Windows logon?
About the SAL1 Exam
The TryHackMe SAL1 certifies entry-level SOC analyst skills across alert triage, SIEM operations, phishing analysis, network traffic analysis, and incident communication — validated through both an 80-question MCQ theory section and two hands-on SOC simulation assessments.
Questions
80 scored questions
Time Limit
24-hour window (60 min MCQ + 2 hr x 2 simulations)
Passing Score
750/1000
Exam Fee
Included with TryHackMe Premium (check tryhackme.com for current pricing) (TryHackMe)
SAL1 Exam Content Outline
Alert Triage & SOC Workflows
Alert classification verdicts, enrichment workflow, SOC tiers and escalation, workbooks, SOC metrics (MTTD/MTTR/MTTA), SOAR automation concepts
SIEM Evidence Interpretation
Splunk SPL (stats, dedup, lookup), Windows Event IDs, Sysmon events, Elastic Stack architecture, log correlation techniques
Phishing & Email Analysis
Email header forensics, SPF/DKIM/DMARC authentication, sender spoofing, typosquatting, URL parsing, double extension attacks
Network Traffic Analysis
OSI model, TCP handshake, port scanning detection, beaconing, DGA/DNS tunneling, ARP spoofing, HTTP analysis, SSL/TLS, Wireshark
Threat Intelligence & Cyber Defence Frameworks
MITRE ATT&CK, Pyramid of Pain, Cyber Kill Chain, Unified Kill Chain, IoC vs IoA, VirusTotal, MISP, CTI lifecycle
Suspicious Activity & Incident Response
Process tree analysis, PowerShell obfuscation, web shells, credential dumping, AD attacks, ransomware containment, incident reporting
How to Pass the SAL1 Exam
What You Need to Know
- Passing score: 750/1000
- Exam length: 80 questions
- Time limit: 24-hour window (60 min MCQ + 2 hr x 2 simulations)
- Exam fee: Included with TryHackMe Premium (check tryhackme.com for current pricing)
Keys to Passing
- Complete 500+ practice questions
- Score 80%+ consistently before scheduling
- Focus on highest-weighted sections
- Use our AI tutor for tough concepts
SAL1 Study Tips from Top Performers
Frequently Asked Questions
What is the TryHackMe SAL1 exam format?
The SAL1 exam has three components within a 24-hour window: 80 multiple-choice questions (200 points, 60 minutes), SOC Simulation 1 (400 points, 2 hours), and SOC Simulation 2 (400 points, 2 hours). The total is 1000 points and candidates need 750 to pass. The simulations use a browser-based SOC environment with Splunk dashboards and email analysis tools.
How hard is the TryHackMe SAL1 exam?
The SAL1 is rated entry-to-intermediate difficulty. Candidates who have completed the TryHackMe SOC Level 1 learning path and practiced the SOC simulator rooms report that the MCQ section tests foundational SOC concepts, while the simulation sections require practical investigation skills — alert triage, log analysis in Splunk, phishing email examination, and written case reporting.
What topics are covered in the SAL1 MCQ section?
The 80-question MCQ section covers: SOC workflows and alert triage concepts, SIEM fundamentals (Splunk and Elastic Stack), phishing and email authentication (SPF/DKIM/DMARC), network traffic analysis (OSI model, TCP, DNS, HTTP), cyber defence frameworks (Pyramid of Pain, Cyber Kill Chain, MITRE ATT&CK), threat intelligence basics, Windows event logs, and cryptography fundamentals.
Do I need a TryHackMe subscription to take the SAL1?
Yes. The SAL1 training content (SOC Level 1 learning path) and exam access require a TryHackMe Premium subscription. The exam voucher is typically included with qualifying subscription plans. Check tryhackme.com/certification/security-analyst-level-1 for current pricing and subscription requirements.
How should I prepare for the SAL1 SOC simulations?
Complete the full TryHackMe SOC Level 1 learning path, paying special attention to the SOC L1 Alert Triage, SOC L1 Alert Reporting, and SOC Simulator rooms. Practice writing case reports with timelines, IoCs, and recommended actions. Develop Splunk SPL query skills and practice analyzing phishing email headers. The simulations reward systematic investigation over speed.
What comes after SAL1 — what certification should I study for next?
TryHackMe's own progression leads to SAL2 (72-hour practical). Other logical next steps include CompTIA CySA+, Hack The Box CDSA (practical SOC lab), or Blue Team Level 1 (BTL1) from Security Blue Team. These certifications build on SAL1 foundations with deeper SIEM operations, threat hunting, and digital forensics skills.