Security Blue Team · Examen BTL1

Preguntas de práctica de BTL1 creadas en torno a las decisiones que evalúa el examen.

Train across the hands-on blue-team lifecycle, from phishing and SIEM analysis to digital forensics, threat intelligence, and reporting.

Sin tarjeta para empezar · pago único · acceso permanente
Contenido revisado en septiembre de 2026
Visión general de la certificación

Proveedor independiente. CertSprint is an independent practice-question provider. We are not affiliated with, partnered with, endorsed by or accredited by Centri or Security Blue Team, and we neither sell nor administer the BTL1 exam. The certification is named here only to identify what these questions prepare you for. Everything factual below comes from Centri’s own published pages, linked at the end of this section.

Qué es Blue Team Level 1 y a quién va dirigida

Blue Team Level 1, almost always written BTL1, is a defensive-security certification from Centri — the company that published it as Security Blue Team, whose securityblue.team address now redirects to centri.org. It is sold as one package rather than as a bare exam: an on-demand course plus a single practical exam.

Centri aims it at entry-level and junior roles, and names the people it has in mind: students, IT staff moving sideways into security, and anyone heading for a first job as a SOC analyst, incident responder, threat intelligence analyst or forensics analyst. The certification is mapped to one NICE framework work role, Cyber Defense Analyst. There is no entry requirement to sit the exam; Centri’s recommended profile is zero to two years of experience.

A pass does not expire. Centri describes BTL1 as certification for life, with a digital certificate, a printed certificate, a Credly badge and a challenge coin on completion.

Qué te pide el examen de Blue Team Level 1

The Blue Team Level 1 exam is an investigation, not a question paper. Centri gives you browser access to a compromised corporate network and 24 hours with it, and inside that window you work through 20 task-based questions. Answering them means going and finding the evidence in the environment — mail artifacts, log data, disk and memory images, threat-intelligence sources — and identifying attack vectors against the MITRE ATT&CK framework.

It is not proctored and you can sit it from home or from work. It is also open book: Centri permits course material, your own notes and search engines during the exam, and prohibits AI assistants outright, treating their use as cheating. The exam is graded the moment you submit it and you are given feedback on the questions you got wrong. If you want a submission re-checked afterwards, Centri offers a manual review that can raise a score but never lowers it.

70% passes. 90% on a first attempt earns the gold challenge coin instead of the silver. Every purchase includes two attempts, and a failed attempt carries a 10-day wait before the resit.

Los dominios de Blue Team Level 1

Centri publishes six domains for Blue Team Level 1. They are taught with the tools the work is actually done with, which is most of the point of the certification.

Security Fundamentals
Core security and networking concepts, security management, and the soft skills the rest of the course assumes.
Phishing Analysis
Identifying, categorising and analysing phishing email, retrieving artifacts from it, and choosing the right response and mitigation.
Threat Intelligence
What operational, strategic and tactical intelligence each mean, and hands-on work in MISP.
Digital Forensics
Windows and Linux investigations across both disk and memory, using tools including Autopsy and Volatility.
SIEM
Aggregating and analysing security events in a SIEM — Splunk in the course material — to detect and respond to incidents.
Incident Response
Writing and running an incident response plan: containment, eradication, recovery and improving what you do next time.

Note that CertSprint groups its own practice questions into seven categories rather than six, splitting network security monitoring out as its own set. That is our editorial choice about how to practise, not a claim about Centri’s syllabus.

Blue Team Level 1 frente a CompTIA CySA+ y Security+

The two certifications people weigh Blue Team Level 1 against are CompTIA CySA+ and CompTIA Security+, and the honest answer is that they are not really substitutes. CySA+ and Security+ are timed, proctored sittings of mostly multiple-choice questions with some performance-based items mixed in. BTL1 is one long open-book investigation scored on what you actually found. They reward different abilities.

Where BTL1 is the stronger choice
It produces evidence that you can do the work: pull artifacts out of a phishing message, search a SIEM, carve a memory image and write up what happened. A multiple-choice score does not show that, and BTL1 is unusual in asking for it at entry level.
Where BTL1 is the weaker choice
Centri publishes no third-party accreditation for BTL1 — the only external mapping on its page is the NICE Cyber Defense Analyst work role. If what stands between you and the job is an advert, a government scheme or a procurement list that names certifications explicitly, a widely listed vendor-neutral certification is the safer bet, and BTL1 is not that.
BTL1 is bundled, not a standalone voucher
Centri sells the course and the exam together — listed at £399 as of September 2026, with the exam attempts included. If you already do this work daily and only want the credential, a share of that price is training you may not need.
Security+ sits earlier in the path
Security+ is broad foundational coverage of security as a subject. BTL1 assumes you have decided to specialise in defence and goes straight at the work. With no security background at all, the vocabulary Security+ drills makes BTL1’s labs considerably easier to follow.

Qué implica realmente preparar Blue Team Level 1

Centri puts the course itself at roughly 30 hours: 330-plus lessons, videos, quizzes and activities, plus 23 browser labs carrying 100 hours of lab access. You get four months of on-demand access to all of it, and the exam has to be used within 12 months.

The one figure Centri publishes about real effort is lab usage — it says most clients spend somewhere between 10 and 30 of those 100 lab hours before passing the exam. It does not publish a recommended number of study weeks, so neither do we; how long this takes depends almost entirely on how much of the Security Fundamentals domain you already know. What Centri does recommend is finishing the labs and activities before booking, on the straightforward grounds that the exam is the same kind of work.

Dónde encaja la práctica de CertSprint

Practice questions cannot rehearse a 24-hour investigation, and we do not pretend otherwise — nothing here reproduces Centri’s exam environment, and a CertSprint percentage is not a BTL1 score or a prediction of one. What questions are good for is the recall the investigation runs on: which Windows event ID matters, what a given ATT&CK technique looks like in a log, which artifact to preserve first, what each class of threat intelligence is for. Those are the things that cost you hours in the lab when you have to look them up, and minutes when you do not.

Use the domain scores below to find the areas where your reasoning is slowest, then spend your lab hours there rather than on the domains you already answer quickly.

Todos los datos de esta sección proceden de las páginas publicadas por el propio proveedor: Centri BTL1 certification page · Centri support: BTL1 exam format · Centri support: is BTL1 right for me?

¿Aún no sabes si BTL1 es para ti?

Haz primero el diagnóstico gratuito de 10 preguntas: sin registro, con puntuación instantánea y desglose por dominio, para saber dónde estás antes de comprometerte.

Diagnóstico gratuito de 10 preguntas
Diseñado para tu próximo intento

Preparación con un propósito.

Entry-level defenders who want practical blue-team preparation across phishing, SIEM, forensics, intelligence, and incident response.

CertSprint combina práctica dirigida, explicaciones, tareas basadas en desempeño y preparación por dominio, para que cada sesión te diga qué estudiar a continuación.

Banco de práctica completo

Ve más allá de la vista previa de 20 preguntas y accede al banco completo enfocado en el examen, organizado según las habilidades y escenarios del temario actual.

Explicaciones que enseñan

Descubre por qué la respuesta correcta encaja con la evidencia y por qué las demás opciones fallan, para desarrollar criterio en lugar de memorizar patrones.

PBQ y escenarios aplicados

Practica tareas de ordenar, emparejar, investigar y configurar, diseñadas para hacer útil el conocimiento bajo la presión del examen.

Preparación por dominio

La precisión se asigna a las áreas del examen, exponiendo los dominios débiles y convirtiendo la fecha del examen en una meta diaria realista.

Lo que practicarás

Cobertura enfocada en BTL1.

La experiencia está diseñada en torno a decisiones y resolución de problemas relevantes, no datos sueltos.

  • Phishing and security operations
  • Digital forensics and threat intelligence
  • SIEM investigations and incident response
Pregunta de ejemplo

Pon a prueba el razonamiento, no la memoria.

Worked example

A suspicious email attachment launches a child process and creates a scheduled task. Which evidence should an analyst preserve first for timeline analysis?

AEndpoint event logsMejor respuesta
BThe user wallpaper
CPrinter queue history
DBrowser bookmarks

El acceso completo incluye una explicación clara después de cada pregunta respondida, incluyendo por qué las demás opciones son menos adecuadas.

Why this is the best answer

Of the choices shown, endpoint event logs provide the strongest starting point for a timeline linking execution and persistence. Preserve relevant records with timestamps and collection context, then correlate them with the original message and attachment. Available detail depends on which events were collected.

Why the other options fit less well

Wallpaper, printer history, and bookmarks do not directly establish the described execution chain. This is a focused question about timeline evidence, not a complete forensic acquisition order; volatile evidence and the response plan can change real-world collection priorities.

Microsoft: endpoint event categories
Cómo funciona el examen

Conoce exactamente cómo será el día del examen.

Formato oficial de Security Blue Team BTL1 (BTL1) — confirma el precio y las políticas vigentes en el sitio del proveedor antes de reservar, ya que pueden cambiar.

Formato1 exam — a practical incident-response investigation, not a multiple-choice paper
Preguntas20 task-based questions answered from evidence you find in a compromised corporate lab
Duración24 hours of in-browser lab access, started whenever you feel ready
Puntaje de aprobación70% to pass, which earns the silver challenge coin; 90% on a first attempt earns the gold one
Tipos de preguntasOpen book and unproctored — course material, personal notes and search engines are allowed, AI assistants are prohibited
ModalidadIn-browser lab from Centri (formerly Security Blue Team), graded on submission with feedback on missed questions
Política de repeticiónTwo attempts included with every purchase, with a 10-day wait after a failed attempt
Plan de estudio

Un plan de 6 semanas ponderado según el banco de preguntas real.

La duración de cada semana es proporcional a cuántas preguntas de práctica de BTL1 tiene realmente ese dominio, no una plantilla genérica. Sigue tu progreso real desde tu panel.

  1. 1

    Security Fundamentals + Phishing Analysis

    Smaller domains grouped together to keep every week substantive.

    ~20 preguntas/día
  2. 2

    SIEM + Digital Forensics

    Smaller domains grouped together to keep every week substantive.

    ~21 preguntas/día
  3. 3

    Network Security Monitoring + Threat Intelligence

    Smaller domains grouped together to keep every week substantive.

    ~19 preguntas/día
  4. 4

    Incident Response

    15% of the full question bank — the single largest block this week.

    ~11 preguntas/día
  5. 5

    Cumulative review

    Mixed practice across every domain, prioritizing whichever ones your readiness tracker shows below 80% accuracy — not a fixed list, but whatever the data says is weakest this week.

  6. 6

    Full practical walkthrough

    Run a complete investigation in an authorized lab under time pressure. Keep evidence-linked notes and check the provider’s current practical-exam instructions before your assessment.

Empieza con evidencia

Encuentra tus dominios débiles antes de que el día del examen lo haga.

Prueba 20 preguntas de BTL1 gratis. Desbloquea el espacio de trabajo completo cuando estés listo.

Empieza BTL1 gratis

Go deeper on BTL1

Practica con perspectiva

Comprende la decisión detrás de la respuesta.

Analiza el escenario, identifica las pruebas relevantes y compara tu razonamiento con la explicación. Usa tus resultados por dominio para elegir la siguiente sesión de estudio. El porcentaje obtenido en la práctica indica qué debes repasar; no predice tu resultado ni equivale a una puntuación oficial.

BTL1 es un examen práctico de investigación. Estas preguntas y tareas de asociación complementan los laboratorios, pero no reproducen el entorno del examen del proveedor.