6 Real Problems I Solved While Building My SOC Homelab
Root Cause Analysis, Fixes and Lessons Learned During My SOC Homelab Deployment
Hello everyone!
After publishing my previous article on TryHackMe’s SOC Level 1 learning path , which was very well received by readers interested in blue-team and SOC roles , I decided to write a follow-up focused on the Security Analyst Level 1 (SAL1) certification itself.
Surprisingly, there are still very few in-depth articles covering SAL1, despite the fact that it’s becoming increasingly relevant and recognized in the cybersecurity job market, especially for SOC and blue-team roles.
After taking and passing the exam, I wanted to share my first-hand experience, along with practical study tips and expectations for anyone considering it or wondering how to prepare effectively for SAL1 certification.
⚠️ This article is intentionally detailed. Feel free to jump directly to the sections that interest you most. Key takeaways are highlighted in bold for easy skimming.
The Security Analyst Level 1 (SAL1) is a certification issued by TryHackMe that validates a candidate’s ability to operate as a junior SOC / security analyst in a real-world environment.
Unlike many purely theory-based certifications, SAL1 places strong emphasis on:
In short, it evaluates how you think and act as an analyst, not just what you memorize.
The certification is earned by completing a structured exam that lasts a total of 5 hours, broken into three parts:
Each practical exam simulates a real SOC investigation workflow.
This flexible structure allows you to manage fatigue, which is crucial — especially during the investigation phases.
Another review highlights on-exam logistics like identity verification and scoring nuances, which many first-timers overlook. blog.razrsec.uk
If you’re preparing for SAL1, I strongly recommend completing the TryHackMe SOC Level 1 learning path, which is the official and most aligned preparation material for the certification.

TryHackMe’s SOC Level 1 path. All you need to learn is here.
This path has been recently revamped and is now far more focused on:
The exam does not only test tool usage — it evaluates whether you understand why you’re doing something, just like in a real job.
Before starting each room, check the suggested prerequisite rooms. Even if some titles sound basic, they often include:
If you’re completely new to cybersecurity, starting with the Pre-Security learning path is a smart move — it builds a solid foundation for everything that follows.

TryHackMe’s Pre Security and Cyber Security 101 foundational paths, packed with relevant, related material.
Writing short notes — especially for:
…can significantly reinforce your understanding and help during revision.
One recent SOC training guide recommends consistent weekly study instead of weekend cram sessions to solidify learning and mirror real SOC workflows. HackerDNA
For context, before taking SAL1 I had already passed: CompTIA Security+ and Blue Team Level 1 (BTL1).
Because of that, the theory exam felt familiar in structure and difficulty. If you already hold certifications like Security+, CySA+, or BTL1, you’ll notice known concepts and this part may be easier for you.
However, SAL1 still includes:
Also, keep in mind:
Even though the exam is multiple-choice, some questions include very similar answers.
You’ll need real understanding — not guessing — to choose the most accurate one.
All theory covered in the exam comes directly from the SOC Level 1 path. If you complete it thoroughly and understand the content, you are already well prepared.
A good final step before the exam is to revisit rooms you feel less confident about.
One common mistake among TryHackMe learners is getting overwhelmed by the number of tools to learn. My advice:
Slow down. Understand what you’re doing and why. Be patient.
While learning, keep in mind to master the main tools here, essential to your career and more often used in real-world jobs, namely:
Among them, Splunk deserves special attention, as it is the primary investigation tool during the exam.
Some tools may not appear directly in the exam, but they help you develop intuition and investigative thinking.
Understand the intent of each and what you are trying to achieve with them. Then pick up your favorites as your complementary professional tools.
For example, I really enjoyed using NetworkMinner, so even this one won’t appear in the exam, I may remember it for my future practical investigations. Its practice room also helped me by itself to broad my understanding of network investigations.
The practical exam uses TryHackMe’s SOC environment, which is one of the platform’s strongest features. It does an excellent job simulating a real SOC workflow.

TryHackMe’s SOC simulation. The dashboard screen.
You can expect to:
You’ll be required to:
Most investigations revolve around:
TryTestMe is available in a VM and works similarly to VirusTotal, allowing you to:
This helps validate findings during investigations.
To be fully ready:
⏱️ Time is tight during the exam , use it wisely.

TryHackMe’s two free SOC investigation rooms included in SOC Level 1. Essential to understand how the practical exam works.
According to one dedicated SAL1 exam review “The most critical preparation … is doing the free SOC Simulators,” — reinforcing the importance of hands-on simulation practice in this exam. happycamper84
I hope this article gives you a clear and realistic idea of what the SAL1 exam looks like and how to prepare for it effectively.
Key Takeaways:
Please remember to respect TryHackMe’s non-disclosure policies if you decide to share your own experience. As you’ve seen, it’s absolutely possible to help others without revealing exam content.