Credentials for defenders, testers, analysts and security leaders across every vendor programme.
Security certifications split into three broad groups: vendor-neutral credentials that prove you understand threats and controls, product credentials that prove you can configure a specific firewall or SIEM, and management credentials that prove you can run a programme and speak to risk.
Employers and government frameworks reference these credentials directly, which is why exam codes matter here more than almost anywhere else — a job posting will ask for a specific version.
The software half of A+: operating system installation and configuration, security practices, software troubleshooting, and the operational procedures a technician follows.
Open the exam guideFilter by practice availability, provider, level or exam code to narrow the list.
64 exams
57 with practice · 7 guide only
The most popular AWS exam: designing secure, resilient, high-performing and cost-optimised architectures across compute, storage, networking and database services.
The most widely requested entry-level security certification: general security concepts, threats and mitigations, secure architecture, security operations, and programme governance.
The most widely recognised senior security certification: eight domains spanning risk management, asset and architecture security, networks, identity, testing, operations and software security.
The single exam behind CCNA: IP addressing and routing, switching and wireless access, IP services, security fundamentals, and an introduction to network automation.
Professional-tier architecture: multi-account governance, hybrid connectivity, migration and modernisation strategy, and continuous improvement of workloads already in production.
The Azure architect exam: designing identity and governance, data storage, business continuity and infrastructure that meets stated availability, cost and compliance requirements.
The software half of A+: operating system installation and configuration, security practices, software troubleshooting, and the operational procedures a technician follows.
The CCNP and CCIE Enterprise core exam: dual-stack architecture, virtualisation, campus and WAN infrastructure, network assurance, security and automation.
The benchmark IT audit credential: the audit process itself, IT governance and management, systems acquisition and development, operations and resilience, and protection of information assets.
Securing Azure in practice: identity and access hardening, network security, protecting compute, storage and databases, and running security operations with Defender and Sentinel.
Google’s flagship architecture exam: designing and planning cloud architectures, managing infrastructure, designing for security and compliance, and ensuring operational reliability.
A vendor-specific security primer: zero trust concepts, Microsoft Entra identity capabilities, the Defender product family and Purview compliance tooling.
Security management rather than security engineering: governance, risk management, building and running a security programme, and managing incidents at an organisational level.
The best-known ethical hacking credential: reconnaissance and scanning, system and web application attacks, wireless and mobile, cloud and IoT, and cryptography, framed around the attacker methodology.
Specialty-level cloud security: threat detection and response, logging and monitoring, infrastructure and data protection, identity design, and governance at scale.
The CCNP and CCIE Security core exam: security concepts, network and cloud security, content security, endpoint protection, and secure network access and visibility.
The analyst-tier security exam: security operations and detection engineering, vulnerability management, incident response, and reporting findings to stakeholders.
Vendor-neutral cloud security: cloud architecture and design, data security, platform and infrastructure security, application security, operations, and legal and compliance obligations.
The engineer-level PAN-OS exam: designing and deploying firewalls, Panorama-managed estates, high availability, advanced policy and decryption, and deep troubleshooting.
Security operations with Microsoft Defender XDR and Sentinel: configuring protections and detections, running incident response, and hunting threats with KQL.
Identity administration in Microsoft Entra: managing identities, designing authentication and conditional access, integrating applications, and running identity governance.
The Microsoft security architect exam: designing zero trust strategy, security operations, identity and compliance capabilities, and security for infrastructure, applications and data.
The CyberOps Associate exam: security concepts, monitoring and event analysis, host-based forensics, network intrusion analysis, and the policies a SOC runs on.
The core FortiGate exam: firewall policy and NAT, authentication, SSL and IPsec VPNs, security profiles, routing, high availability, and diagnosing traffic through the device.
Hands-on penetration testing from scoping to reporting: engagement management, reconnaissance, vulnerability analysis, exploitation, and post-exploitation and lateral movement.
Securing Google Cloud environments: access configuration, boundary protection and secure communications, data protection, security operations, and compliance support.
Running a Microsoft 365 tenant end to end: deployment and management, Entra identity and access, threat protection with Defender XDR, and compliance with Purview.
Day-to-day firewall administration on PAN-OS: security and NAT policy, App-ID, User-ID and Content-ID, security profiles, and monitoring traffic through the device.
Managing the Windows endpoint estate with Intune: deployment and provisioning, identity and compliance, device protection and maintenance, and application delivery.
Secrets management with Vault: authentication methods and policies, static and dynamic secrets engines, encryption as a service, and the operational side of running Vault.
Protecting data with Microsoft Purview: sensitivity labelling, data loss prevention, lifecycle management, insider risk and the investigations that follow an alert.
Cloud security posture and workload protection with Prisma Cloud: onboarding cloud accounts, policy and compliance, container and serverless defence, and integrating with CI/CD.
CompTIA’s most advanced security certification, formerly CASP+: enterprise security architecture and engineering, governance and risk, and running security operations at scale.
The Secure Firewall concentration: deployment modes, configuration and management, intrusion and malware policies, and integration and troubleshooting.
The advanced half of the Windows Server hybrid track: hardening servers, clustering and high availability, disaster recovery, migration and troubleshooting.
The Identity Services Engine concentration: architecture and deployment, policy enforcement, web authentication and guest access, profiling, and endpoint compliance.
A practitioner-level credential for hands-on security roles: access controls, risk monitoring, incident response, cryptography, network security and systems and application security.
Network virtualisation with NSX: architecture and deployment, logical switching and routing, distributed firewalling and micro-segmentation, and operating the NSX platform.
Detection and response with Cortex XDR: threat prevention and detection concepts, investigating alerts and incidents, remediation actions, and tuning the platform to reduce noise.
Technical privacy implementation: privacy governance and programme structure, privacy architecture across infrastructure and applications, and managing the data lifecycle.
Digital forensics end to end: the investigation process and legal considerations, acquiring and analysing disk, memory, network and cloud evidence, and producing defensible reports.
The authorisation and risk management credential, formerly CAP: building a risk management programme, selecting and implementing controls, assessment, authorisation and continuous monitoring.
An entry-level, largely vendor-neutral security exam: the threat landscape, network security fundamentals, cloud and SaaS security concepts, and security operations principles.
Associate-level Juniper security: SRX platform basics, security zones and policies, network address translation, IPsec VPNs, and unified threat management features.
The VPN concentration: site-to-site IPsec, DMVPN and FlexVPN designs, remote access VPN with AnyConnect, and troubleshooting secure tunnels end to end.
Advanced Google Workspace administration: planning deployments and migrations, securing the domain, automating administration, and supporting a large user population.
Engineering-level work on PAN-OS next-generation firewalls: deployment and interfaces, security and NAT policy, decryption, threat prevention, and management at scale with Panorama.
A defensive counterpart to the offensive track: network defence fundamentals, perimeter and endpoint protection, secure configuration, monitoring, and incident response and forensics readiness.
Security across the software lifecycle: secure requirements, architecture and design, implementation, testing, deployment and operations, and securing the software supply chain.
Deploying Palo Alto software firewalls in virtual and containerised environments: VM-Series and CN-Series design, cloud deployment, automation and licensing models.
The CyberOps Professional core exam: security fundamentals at depth, detection and hunting techniques, incident response processes, and automating security operations.
Centralised management with FortiManager: device onboarding and ADOMs, policy packages and installs, configuration revisions, provisioning templates and workflow approvals.
Specialist Juniper security: advanced policy and application security, intrusion detection and prevention, Sky ATP integration, chassis clustering and troubleshooting SRX deployments.
An executive security credential: governance and risk, controls and audit management, security programme management, core competencies, and the financial and vendor side of security leadership.
The email security concentration: appliance administration, message and content filtering, anti-spam and anti-malware, plus data loss prevention and encryption.
The forensics concentration for CyberOps Professional: evidence handling, forensic techniques across hosts and networks, and structured incident response processes.
The legacy NSE 4 FortiGate exam, retained for reference while the numbered NSE programme is phased out in favour of the FCP tier.
The hardest of the Kubernetes lab exams: cluster hardening, system hardening, supply chain security, runtime security with behavioural tooling, and minimising microservice vulnerabilities.
An entry-level security certification with no experience requirement: security principles, business continuity and incident response, access control, network security and security operations.
Security fundamentals for Kubernetes: cluster component security, the cloud native threat model, platform security controls, and compliance frameworks for containerised platforms.
An introductory security credential covering the threat landscape, common attack techniques, network security concepts, and the products that make up the Fortinet Security Fabric.
Centralised logging and reporting with FortiAnalyzer: deployment and ADOMs, log ingestion and storage, reports and dashboards, event handlers and incident workflows.
A lab exam for running Vault in production: cluster deployment and high availability, replication and disaster recovery, auto-unseal, monitoring and upgrade operations.
The solution-specialist exam for network security: advanced FortiOS troubleshooting, routing and SD-WAN behaviour, IPsec at scale, security fabric integration and performance analysis.
How many exams each provider contributes here.
Where each exam sits, so you can plan a progression rather than a single jump.
Multi-exam credentials in this category.
Professional-level Cisco security: the SCOR core exam plus one concentration covering firewalls, identity services, email security or VPNs.
Cisco
Microsoft’s senior security credential, earned by holding one associate security certification and passing the SC-100 architecture exam.
Microsoft
A two-exam security operations credential covering advanced detection and response plus digital forensics and incident response.
Cisco
65 exams from 14 vendors are tagged to Cybersecurity. Exams appear in this category when it is either their primary focus or a substantial secondary one.
AWS Certified Solutions Architect – Associate (SAA-C03) is the most common entry point. The most popular AWS exam: designing secure, resilient, high-performing and cost-optimised architectures across compute, storage, networking and database services.
AWS Certified Solutions Architect – Associate (SAA-C03), CompTIA Security+ (SY0-701) and ISC2 Certified Information Systems Security Professional are the most frequently pursued in this category.
Networking
Routing, switching, wireless, SD-WAN and cloud networking exams from vendor and neutral programmes.
Governance, Risk & Compliance
Audit, risk management, privacy and security leadership certifications.
Cloud Computing
Certifications covering public cloud platforms, architecture, migration and cost management.