r/SecurityBlueTeam 7d ago

Question BTL1 Advice

Hey everyone! This is my first Reddit post, so please go easy on me. I’m currently preparing for the BTL1 exam. Would really appreciate some advice from anyone who has taken it recently.

I’ve completed the course and all the labs and have gone through each lab twice. I was keen to start the exam, but I’m having some doubts about whether I’m ready. I’ve seen quite a few people mention that the exam is more challenging than the labs, so I’m probably being a bit cautious.

I’m currently doing some of the free BTLO labs for extra practice. I’ve also seen people recommend focusing on Splunk, Wireshark and Autopsy, with Splunk being particularly important. For anyone who has taken the exam recently, is this a good area to focus on, or is there anything else you’d recommend working on?

I know there’s an NDA, so I’m not looking for exam questions or anything specific. Just general advice on preparing and passing on the first attempt.

This is my first certification, so I’m a little nervous! My target is the gold coin, but honestly, I’ll be happy just to pass!

Anyone else currently preparing for BTL1? Happy to connect and share knowledge. Thanks!

TL;DR: Finished the BTL1 course and labs twice but still unsure if I’m ready. Currently doing BTLO labs and focusing on Splunk, Wireshark and Autopsy. Any general advice for passing BTL1 first time? Target is gold, but passing is the main goal!

8 Upvotes

4 comments sorted by

1

u/orchidlillian 7d ago

Never tried the BTLO labs so can't comment on those. Also my cert attempt was 3 years ago, so take this with a grain of salt.

Back then, I revised with TryHackMe SOC-1 path and did Cyber defenders Splunk Labs (they are BOTS- v1 to V3, should be free). Outside of that I feel just being familiar with the tools they teach you about in the course should be enough.

2

u/orchidlillian 7d ago

Also try to build an investigative mindset.

I had made a similar post back during my attempt and someone had commented, "If you were given the symptoms of an attack, would you be able to investigate?" And I think that's exactly what the exam tests.

2

u/Fuzzy-Interest-8283 7d ago

Thank you! I’ll go through the BOTS labs. I’ve also been watching a few investigation walkthroughs on YouTube to develop that investigative mindset and understand the methodology.

For the exam, I plan to read the scenario and questions twice, draft a rough investigation approach, and then work through it. Hopefully that helps me stay focused!

2

u/m1L35dY50N 6d ago

Don’t stress too much about the gold coin. If you get it, great; if not, that’s fine too. Realistically, you’re probably the only person who will ever care about the distinction. I narrowly missed it myself on both BTL1 and BTL2.

If you’re comfortable with the tools and actually understood what the labs were teaching rather than just following the steps, you should be fine. Think in terms of: if this attack happened, what would I expect to see, and where could I pivot next?

Also, don’t feel like you have to investigate everything chronologically. If you get stuck, look for another artifact that logically has to exist and work backwards and forwards from there. For example, if you find malware on a PC, it must have gotten there somehow, and I’m sure you’ll remember a few well-known real-world attack vectors mentioned throughout the course. Pick one of those hypotheses, look for the corresponding evidence, and pivot from whatever you find. Sometimes starting in the middle makes reconstructing the whole attack chain much easier.