1.4 MCQ Section Strategy
Key Takeaways
- The SAL1 MCQ section is 80 questions in 60 minutes, about 45 seconds per question on average.
- TryHackMe states that questions get more challenging as they progress, so do not spend the first half of the hour on the early items.
- Read for keywords such as NOT, EXCEPT, and BEST before you look at the options.
- Bookmark a stuck item, move forward, and return if time remains; think like a SOC analyst rather than a trivia contestant.
- Use MITRE ATT&CK and NIST as orientation frameworks, and do not change an answer without a specific reason.
What the MCQ Section Is For
The SAL1 multiple-choice questions (MCQ) section is the first scored part of the sitting. TryHackMe’s format article sets it at 80 questions, 1 hour, covering SOC fundamentals. The dedicated MCQ advice article (30 May 2025) repeats those numbers and adds the pacing fact that drives this whole section: questions get more challenging as you progress.
Eighty items in 60 minutes is 45 seconds per question if you spread time evenly. You will not spread time evenly, because the last third of the paper is where stems get longer, options get closer, and “which is BEST” appears more often. The professional move is to finish the earlier, faster items cleanly, leave a bookmark trail, and arrive at question 60 with minutes still in the bank.
This section teaches exam technique. It does not teach subnetting, phishing-header fields, or MITRE technique IDs in depth. Those topics live in later chapters. If you cannot yet explain what a SOC analyst does with an alert, go study those chapters before you treat this page as a substitute.
Think like a SOC analyst
TryHackMe’s own advice is to apply real-world SOC principles and consider how an analyst would approach the problem in a security operations centre. That is a bias you can practise:
- Prefer answers that contain, detect, or escalate appropriately over answers that “hack back” or wipe production without a ticket
- Prefer answers that use logs, tickets, and severity over answers that rely on a hunch
- Prefer answers that match least privilege and evidence-based triage over theatrical overreaction
- When the stem is about a framework, map the action to the framework’s published language instead of a vendor-blog synonym
You are not taking a trivia night. You are answering as the person who would pick up that alert on a day shift.
Time Budget You Can Actually Run
| Block | Questions | Suggested minutes | Why |
|---|---|---|---|
| Opening pass | 1–20 | about 10–12 | Earlier items should be quicker; do not “warm up” by overthinking |
| Middle pass | 21–50 | about 20–22 | Stems lengthen; still leave a reserve |
| Closing pass | 51–80 | about 18–20 | Published difficulty increase lives here |
| Return pass | bookmarked items | whatever remains (target 6–8) | Only if the first three passes stayed disciplined |
Those bands are a personal runbook, not a TryHackMe-published split. The published constraints are only 80, 60 minutes, and rising difficulty. If you spend 40 minutes on the first 30 questions, the last 50 items — the harder ones — get 20 minutes, which is 24 seconds each. That is how capable candidates fail a knowledge paper they could have passed.
Rules that keep the runbook honest:
- If you hit 45 seconds and still cannot eliminate two options, bookmark and move
- Never negotiate with a single item for three minutes on the opening pass
- Use the return pass for items you actually marked, not for recreational rewriting of answers you already liked
Read the Stem Before the Options
TryHackMe tells you to pay close attention to keywords such as NOT, EXCEPT, or BEST, and to identify the core concept being tested before you look at the answer choices.
NOT and EXCEPT
These stems reverse the hunt. Four options may all look “security flavoured,” but three are true and one is the false statement you must select — or three are in-scope actions and one is the action you would not take. Slow down just enough to circle the word in your head. A correct fact that does not match a NOT stem is a wrong click.
Worked pattern (illustrative, not an exam item): “Which of the following is NOT a reason to escalate this alert to incident response?” Three options will be valid escalation triggers. The distractor will be a routine false-positive handling step. If you skim and pick the most “serious-sounding” option, you fail the stem.
BEST
BEST means more than one option may be defensible. The scored choice is the one that best matches analyst practice: proportionate, evidence-based, and consistent with how a SOC actually works. An option can be possible and still lose to an option that is preferable. This is where “think like a SOC analyst” stops being a poster slogan.
Eliminate before you guess
TryHackMe’s advice is explicit: if unsure, eliminate obviously incorrect answers. On a four-option item, removing one cartoon distractor turns a 25% guess into a 33% guess; removing two turns it into a coin flip you might still return to. Elimination is not a substitute for knowledge, but it is how you stop spending 90 seconds in a fog.
For technical items involving logs or security tools, eliminate answers that fight known good practice. Pay attention to log types, response steps, and SIEM-related concepts — again, as orientation, not as a content dump. If an option claims you should ignore a SIEM alert because dashboards are “always noisy,” that is usually the distractor, not the analyst move.
Frameworks as Orientation, Not as a Syllabus Dump
TryHackMe tells candidates to memorise key concepts and definitions and to focus on important frameworks such as the MITRE ATT&CK matrix and the NIST incident response cycle. Later chapters in this independent OpenExamPrep guide teach those frameworks as full topics, including how SAL1 training content lists NIST Cybersecurity Framework stages. For the MCQ clock, you need a lighter stance:
- MITRE ATT&CK is how many SOCs name adversary behaviour (tactics and techniques). If a stem asks what an attacker is doing, prefer the technique-shaped answer over a random CVE trivia answer that the stem never supported.
- NIST language in MCQ stems often points at a phase of handling (detect versus respond versus recover, or a step in incident response). Match the action to the phase. Do not pick “recover backups” if the stem is still in detection.
You do not need to recite every ATT&CK technique ID in 45 seconds. You need to recognise the shape of the question: behaviour mapping versus control selection versus process order.
Bookmark, Return, and Leave Good Answers Alone
TryHackMe’s time-management advice: don’t spend too long on any single question. If stuck, bookmark it for review and move forward — come back if time permits.
That only works if you actually bookmark and if you actually leave time. A bookmark you never return to is just a slow fail. A return pass that rewrites five confident answers into worse ones is also a fail. The MCQ advice’s final tip is to review if time allows and to avoid changing correct responses unless absolutely necessary.
Change an answer only when you can name the cause:
- You misread NOT/EXCEPT and can now see the reversal
- You confused two definitions and the later item reminded you of the distinction
- You eliminated a remaining option with a concrete fact, not a vibe
Do not change an answer because the last ten items felt harder and you suddenly distrust your earlier self. Difficulty increasing is by design. It is not evidence that question 8 was a trap.
Delivery Habits That Protect the Paper
The MCQ advice repeats the format article’s environment note: ensure a stable internet connection before starting, and stay calm — stress causes misreads. Combine that with section 1.2:
- Chrome or Firefox, already tested
- One exam login, not a phone mirror tab
- No VPN experiments left over from Onfido troubleshooting
- Water and a power cable so you do not jump up during minute 47
You cannot pause the 24-hour exam timer, and you cannot pause the 60-minute MCQ timer either. If you disconnect, your first job is to get back in, not to rebuild a study plan. Technical-issues guidance lives in TryHackMe’s Help Center; do not use a crash as an excuse to open a second device against the multiple-session warning.
A Pre-MCQ Checklist
Use this the morning you start, after Onfido is already approved:
- Confirm you are ready to spend a focused 60 minutes — the first section is short and dense
- Decide your bookmark rule (for example: two options left plus 45 seconds elapsed)
- Remind yourself of the three stem traps: NOT, EXCEPT, BEST
- Remind yourself who you are answering as: a SOC analyst, not a pentest mascot
- Protect a small review reserve for the harder tail of the paper
- Commit to not “fixing” early answers without a named reason
Then sit the paper and leave domain deep-dives for the rest of this study guide. The MCQ is 200 of 1000 marks. It can still drop you if you mismanage the hour, but it cannot carry you if you never learned to investigate. Budget this section accordingly.
Official Starting Points
- MCQ advice (30 May 2025): Multiple Choice Questions: Exam Advice
- Format and timings (23 Feb 2025): Exam Format and Timings
Re-read those two pages the day before you start. Technique fades; the 45-second average does not.
On the SAL1 MCQ section, what is the average time per question if you use the full 60 minutes across all 80 items?
TryHackMe’s MCQ advice says questions get more challenging as they progress. What is the sound pacing response?
A stem reads: “Which of the following is NOT an appropriate first action for a SOC analyst?” What should you do before clicking?