My review of the Centri BTL1 certification
At the end of last year, my employer offered me the chance to prepare for the Blue Team Level 1 (BTL1) certification run by the company Centri.
It’s not necessarily the one I would have picked on my own, but you should never turn down the opportunity to add a new certification to your CV 🙂
To give you an idea of my level, I made a career switch to become a SOC analyst and I had 18 months of experience in a SOC when I took this certification.
Here’s my feedback.
What is the BTL1?
The BTL1 is a certification aimed at junior blue team analysts, covering six domains:
- Security Fundamentals
- Phishing analysis
- Threat Intelligence
- Digital Forensics
- Security information and event monitoring
- Incident Response
It costs 399 GBP (about 470 €). This gives you access to the course materials, 100 hours of virtual machines for hands-on labs, and two attempts to pass the exam.
From the moment you start the certification, you have access to the course materials for 4 months and 12 months to take the exam. I’d advise you to try the exam as soon as you’ve finished the course materials to take advantage of it while it’s still fresh in your mind.
According to Centri, you should plan for roughly 30 hours to get everything done. I didn’t measure exactly how much time I spent, but the ballpark figure seems about right.
The course materials
The course materials consist of:
- Theory lessons with text and images
- Tool demonstration videos
- Quizzes
- Labs
- Lab walkthroughs
What’s really nice is being able to immediately put the theory into practice through the labs. Centri provides you with virtual machines with the software you’re studying already installed, along with scenarios and questions. You get 100 hours of virtual machines, which is more than enough (I only used about 9 hours doing 17 of the 24 available labs). You access them directly from your browser.

Through the labs, you’ll get to use a wide range of tools. Special attention is given to Splunk, Autopsy, and Wireshark, which you’re very likely to use during the exam.
Some modules are mostly theoretical (Security Fundamentals and Threat Intelligence). If you already have a bit of cybersecurity experience or hold a certification like the CompTIA Security+, you can breeze through them.
The exam
The exam format is quite original; it’s not a multiple-choice test like most certifications.
The BTL1 exam consists of a realistic scenario with 20 questions you need to answer. You get a virtual machine with all the necessary tools installed (exactly the same format as the labs). You have 24 hours to complete the exam and manage your time as you wish.
It’s an open book exam, meaning you can use the notes you took during preparation, do Google searches, etc. The only thing you can’t do is get help from someone else.
As soon as you submit your answers, you get the result instantly. You need a minimum score of 70%. If you fail, you get a second attempt. If you score at least 90% on your first try, you earn the gold coin as a bonus. It’s pretty useless, but it’s a nice touch.
I really appreciated this exam format, because you have to conduct an investigation under conditions close to what you encounter in real life.
I started the exam on a Saturday morning around 8 a.m. I was a bit hesitant at first while I got the hang of it, then everything went smoothly. By noon, I had already completed 19 out of 20 questions. I took a long break for lunch and a short nap. I resumed around 2 p.m. to finalize the last question and take the time to review before submitting around 3:30 p.m. So I spent 7.5 hours on the exam, including about 5.5 hours of actual work.
The 24 hours allotted are therefore very, very generous. I highly recommend taking all the time you need to read the instructions carefully (and even read them twice), as this will save you time and unnecessary stress.
To illustrate, without revealing anything about the exam: from the exam’s virtual machine, I had to connect via RDP to a domain controller and use a script on it. I couldn’t find the script, and since the machine wasn’t connected to the internet, there was no way to download it. It was only by rereading the instructions that I realized the script was on the virtual machine and I just had to copy-paste it via RDP.
I also recommend taking notes so you always have the times of important events in front of you. If a user clicked a phishing link at 2:24 p.m., it’s likely other events will occur in the following minutes.
I’m very happy with the result since I passed the BTL1 with a score of 95%, so I earn the symbolic gold coin !
My opinion
I think the BTL1 is an excellent certification for beginner analysts and those in the middle of a career change. It’s probably the certification that aligns most closely with the skills needed for the SOC analyst role.
The ability to quickly put theoretical knowledge into practice is a huge plus. This hands-on aspect is missing from most certifications. When I prepared for the CompTIA Security+, I spent dozens of hours reading the 1000-page book without any practice. I answered questions about software I had never used. I learned a great deal, but it lacked practical application.
For profiles like mine with some experience, you’ll likely learn things, but you may find the exam level a bit low. Attempting the BTL2 (level 2) would certainly have been more challenging, but my employer didn’t offer it, and it costs five times more than the BTL1…
While the labs are fun to do, I do want to complain about the power of the virtual machines. They are undersized, and overall, it’s quite laggy! I hoped the exam machine would be more powerful, but that wasn’t the case. In comparison, the machines provided on the TryHackMe platform (where I spent a lot of time preparing for my career change) are much more pleasant to use.
Good luck with your preparation, and if you have any questions, feel free to ask!