Certified Junior Cybersecurity Analyst

Certified Junior Cybersecurity Analyst (CJCA) by HackTheBox (HTB).


Certification Link/Proof


Introduction

The CJCA tests a broad range of cybersecurity concepts. This means that it covers both red team and blue team. It also encourages thinking about the business side like methodology and scope. The material starts off with foundational concepts like networking to serve as an entry point into cybersecurity. The exam experience concludes like all the other HTB exams with a professional-grade report.

Corporatese translation: We realized that we don't have a cybersecurity team. Take an introductory, all-encompassing class so you can do everything!


Why I Took It

Cybersecurity is increasingly important in the world today as we are becoming even more connected online. The trend is likely to continue to increase too as smart devices, IoT, and AI continue to see mass adoption. To meet this increasing demand, there has to be an entry point in the cybersecurity field for career changers who might want to work in this field.


Now, Why I Actually Took It

I received a free exam voucher when I signed up for the silver package in Hack The Box Academy. Then, I discovered something about myself. Free is my absolutely favorite price for just about anything. It is the perfect amount for the checking account. Additionally, my partner had also started taking the learning path too, “To get an idea of what I do.” To the best of my knowledge, they are still in the networking modules and I steamrolled it into the exam. Thrilled to be halfway through the HTB certification stack.


Skills Gained

You start off by getting a wide overview of Information Security. You then complete two different modules on both Networks and Networking as that is kind of central to the whole thing, unless you’re a physical pentester. This is followed with two modules covering Linux and Bash covering the basics of script writing. Then, of course, you obligatorily have to learn the Windows Fundamentals and scripting to complement the Linux teachings. After this, be prepared for a crash course in web apps, requests, and WordPress. You will have to go through lessons covering Pentesting and its methodology, in a nutshell. After this, switch over to the blue team section of the course. This will cover SIEM operations, log analysis, and the Incident Response process. Of course, you have to finish the entire path before you are eligible to take the exam.


Tools & Technologies Used.

  • Burp Suite
  • Ffuf
  • Wpscan (and other common CMS scanners)
  • Elastic/Kibana
  • KQL


  • Coming soon!


Tips & Lessons Learned

  • Post-exploitation Enumeration is Important: The loot you find on one machine might just be the way into another machine.
  • Track All Usernames and Passwords: It makes it easy to test password/credential reuse.
  • Enumerate When Stuck: If you ever get stuck, enumerate some more. You probably missed something.
  • Don’t Overcomplicate It: It is a junior level exam. You don’t have to write a zero-day.
  • Know the Requirement: Make sure you submit enough alerts to clear their requirement.


Outcome/Status