What is the HTB CJCA?
The HTB Certified Junior Cybersecurity Associate (CJCA) is Hack The Box's entry-level, hands-on certification. Unlike most junior certs it covers both sides: basic offensive work (enumeration, exploitation, privilege escalation) and defensive work (traffic analysis, Windows event logs, SIEM monitoring and alert triage), mapped to MITRE ATT&CK and the NIST/NICE framework.
You earn it by completing the Junior Cybersecurity Analyst Job-Role Path (20 modules, 318 sections, rated Easy) and then passing the exam. HTB estimates the path takes 17 days 3 hours (about 139 hours at 8 hrs/day), and you have to finish 100% of it before the exam unlocks.
The exam
The CJCA exam runs for 5 days in a live lab and has two halves. The red-team half has 5 machines, each with a user and a root flag worth 10 points, and reviewers report a pass mark of 80 of 100. The blue-team half gives you an Elastic SIEM with roughly 40 alerts to triage as true or false positives, with reasoning.
You then submit a professional report in English (HTB provides a SysReptor template and a sample report). The report is graded by HTB staff and can fail you on its own. You get 2 attempts per voucher, and results with feedback arrive within 20 business days. HTB only officially says "a minimum point threshold", so treat the point figures as what reviewers reported.
The 20 modules in order
- Security & Networking Foundations: Introduction to Information Security · Network Foundations · Introduction to Networking
- Linux & Bash: Linux Fundamentals · Introduction to Bash Scripting
- Windows & Command Line: Windows Fundamentals · Introduction to Windows Command Line
- Web Fundamentals: Web Requests · Introduction to Web Applications
- Pentest Process: Introduction to Penetration Testing · Pentest in a Nutshell
- Enumeration & Exploitation: Network Enumeration with Nmap · Footprinting · Hacking WordPress · Using the Metasploit Framework
- Defensive: SOC & Detection: Intro to Network Traffic Analysis · Incident Handling Process · Windows Event Logs & Finding Evil · Security Monitoring & SIEM Fundamentals · Introduction to Threat Hunting & Hunting With Elastic
Top tips from people who passed
- The report is the exam. Screenshots, reproducible steps, and negative findings too. One reviewer failed with 60 pages and passed with 111. (Halil, MANESEC)
- Don't underestimate the blue half. Every TP/FP call needs a reason. Build an attack timeline and check alerts against it. (MANESEC, Chicken0248)
- Work both halves together. The SIEM logs can hint at attack paths, and your attacks show up as alerts. (MANESEC)
- Chain findings. Credentials or access from one host often open the next. Scan each host more than once. (Laziz, Chicken0248)
- Practice on Easy boxes and write them up. Linux and Windows, initial access and privesc, then a real report. (Laziz, Halil)
The full list of tips is at the bottom of the Resource Library tab.
How to use this tracker
- Set your start date at the top. Every day's calendar date and your pace indicator are computed from it.
- Pick a timeline (25/30/45/65/90 days). They all cover the same curriculum, just packed into more or fewer days, and your progress carries across when you switch.
- Tick each task as you finish it. A day is marked complete when all its tasks are done.
- Use the Notes field on each day as a journal for commands that worked, queries worth saving, and things to revisit.
- All progress is saved in your browser. Use Export backup regularly to keep a copy.
Take notes on every module as if you'll be writing a report from them, because you will. Don't coast through the defensive modules at the end: the SIEM half of the exam catches people who spent all their time on the flags.
This is an independent study aid and is not affiliated with or endorsed by Hack The Box. Always confirm current module counts, exam format, and pricing on the official HTB Academy site.
Built on and inspired by mattrfield's coae-study-tracker.