100+ Free SEC1 Practice Questions
Prepare for the TryHackMe Cyber Security 101 (SEC1) exam with instant access — no signup required.
Loading practice questions...
Explore More TryHackMe Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
Key Facts: SEC1 Exam
24 hours
Exam Window
TryHackMe
7 sections
Exam Sections
TryHackMe
65%
Passing Score (455/700)
TryHackMe
Beginner
Difficulty Level
TryHackMe
54 rooms
Preparatory Path Length
TryHackMe Cyber Security 101
1 retake
Resit Allowance
TryHackMe
The SEC1 is TryHackMe's entry-level practical certification for learners who complete the 54-room Cyber Security 101 path (~45 hours). The 24-hour exam comprises 7 sections (3 Purple Team, 2 Blue Team, 2 Red Team) with fill-in-the-blank questions answered using real tools in a browser-based VM. Passing score is 455/700 (65%). One retake is available after a cooldown period. The exam is included with a TryHackMe Premium subscription. This practice bank tests the foundational knowledge — Linux/Windows CLI, Nmap, Metasploit, Wireshark, Hydra, Gobuster, CyberChef, SQLi, XSS, log analysis, and incident response — required to succeed in the hands-on sections.
Sample SEC1 Practice Questions
Try these sample questions to test your SEC1 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.
1In the CIA triad, which property ensures that information is accessible only to those with authorized access?
2Which of the following best describes the role of a Security Operations Center (SOC)?
3What is the primary purpose of the Nmap tool in the context of offensive security?
4Which Nmap flag performs a SYN (stealth) scan, sending SYN packets without completing the TCP handshake?
5In the Linux filesystem, which directory stores system-wide configuration files?
6Which Linux command displays the current user's group memberships?
7In Windows, which Event ID is generated when a user successfully logs on interactively?
8What does the Metasploit module type 'exploit' do?
9Which protocol does HTTPS use to encrypt web traffic, replacing the deprecated SSL?
10In the OSI model, at which layer does the TCP protocol operate?
About the SEC1 Exam
The TryHackMe Cyber Security 101 (SEC1) certification is a beginner-level, 100% practical exam designed for learners who complete the Cyber Security 101 learning path. The 24-hour exam presents 7 real-world sections spanning Red Team, Blue Team, and Purple Team scenarios using an analyst VM with actual artifacts. This practice bank tests the foundational knowledge needed to navigate those hands-on challenges.
Assessment
Performance-based assessment
Time Limit
24 hours (7 sections: 3× 45-min + 4× 60-min timers)
Passing Score
455/700 (65%)
Exam Fee
Included with TryHackMe Premium (TryHackMe)
SEC1 Exam Content Outline
Purple Team — OS & Shell Fundamentals
Linux and Windows command-line proficiency, PowerShell scripting, Bash shells, packet capture analysis, and OS security features
Networking & Secure Protocols
OSI model, TCP/IP, DNS, HTTP/HTTPS, TLS, Wireshark basics, tcpdump, Nmap scanning, and foundational network analysis
Cryptography Basics
Symmetric and asymmetric encryption, hashing (MD5, SHA-256), public-key cryptography, digital signatures, password cracking with John the Ripper
Offensive Security & Tooling
Exploitation basics (Metasploit, EternalBlue/Blue room), Hydra brute-forcing, Gobuster directory enumeration, SQLMap, reverse and bind shells, OSINT with theHarvester and WHOIS
Web Application Security
SQL injection, XSS (stored/reflected/DOM), IDOR, command injection, Burp Suite basics, OWASP Top 10 fundamentals, JavaScript security
Defensive Security & SOC
SOC fundamentals, SIEM concepts, digital forensics (hashing, chain of custody), incident response (NIST SP 800-61), log analysis, Windows event IDs, phishing analysis (SPF/DKIM/DMARC)
How to Pass the SEC1 Exam
What You Need to Know
- Passing score: 455/700 (65%)
- Assessment: Performance-based assessment
- Time limit: 24 hours (7 sections: 3× 45-min + 4× 60-min timers)
- Exam fee: Included with TryHackMe Premium
Keys to Passing
- Work through all 100 available questions
- Review every answer and explanation
- Track weak areas and revisit them
- Use our AI tutor for tough concepts
SEC1 Study Tips from Top Performers
Frequently Asked Questions
What is the TryHackMe SEC1 exam format?
The SEC1 is a 24-hour practical exam divided into 7 sections: 3 Purple Team sections (45 minutes each) and 4 Red/Blue Team sections (60 minutes each). Each section has 10 fill-in-the-blank questions. Candidates use a browser-based analyst VM with real tools and artifacts. Total possible score is 700 points; 455 (65%) is required to pass.
What topics are covered in the SEC1 exam?
The SEC1 covers six core areas: (1) OS fundamentals — Windows and Linux architecture, CLI proficiency, filesystem, user management; (2) Network traffic analysis — protocol analysis, Wireshark, packet capture; (3) Web application security — common vulnerabilities, basic penetration testing; (4) Security operations — log analysis, threat detection, SOC workflows; (5) Password attacks and credential security — brute-forcing, dictionary attacks, cracking; (6) Malware analysis fundamentals — identifying malware types, basic static and dynamic analysis.
How should I prepare for the SEC1 exam?
Complete all 54 rooms in the TryHackMe Cyber Security 101 learning path, which covers 13 modules including Linux/Windows fundamentals, networking, cryptography, web hacking, Metasploit, and defensive security tooling. Practice using all tools hands-on: Nmap, Hydra, Gobuster, Burp Suite, Wireshark, CyberChef, and CAPA. Use these 100 practice questions to reinforce conceptual knowledge before the practical exam.
Is the SEC1 exam multiple choice?
No — the SEC1 is 100% practical and hands-on with fill-in-the-blank answers derived from real tool usage. There are no multiple-choice questions on the actual exam. This practice bank provides MCQ-format questions to build the underlying knowledge needed to navigate the practical sections effectively.
What tools are used in the SEC1 exam?
The SEC1 uses real cybersecurity tools in a browser-based VM. Based on the exam sections, expect to use: Linux CLI (bash, grep, find, ss), PowerShell, Wireshark for packet analysis, web application testing tools (Burp Suite, Gobuster), brute-force tools (Hydra), and blue team investigation tools. The Cyber Security 101 learning path covers all required tools.
What jobs can I get with the SEC1 certification?
The SEC1 is an entry-level certification demonstrating foundational red, blue, and purple team knowledge. It supports junior roles such as: SOC Analyst Tier 1 ($45,000-65,000), IT Security Analyst ($50,000-70,000), Cybersecurity Technician ($45,000-65,000), and Junior Penetration Tester ($55,000-75,000). It is a strong stepping stone to more advanced certifications like BTL1, Security+, or eJPT.