Skip to content

CompTIA Certification Roadmap

CompTIA certifications can take you from your first understanding of IT to professional roles in networking, cybersecurity, cloud, security operations, penetration testing, and enterprise security. The key is not collecting certificationsβ€”it is building skills in the right sequence.

Welcome to the CompTIA Certification Roadmap.

This roadmap will help you understand:

  • where to begin
  • which certifications are appropriate for your experience
  • which certifications you may be able to skip
  • how certifications connect to cybersecurity careers
  • when to start practical labs
  • how to build job-ready skills
  • how to progress from beginner to advanced security roles

The GoHackersCloud CompTIA path follows:

Tech+
↓
A+
↓
Network+
↓
Security+
↓
Cloud+
↓
Linux+
↓
CySA+
↓
PenTest+
↓
SecurityX

You do not necessarily need every certification.

Your route should depend on:

  • your existing IT knowledge

  • your experience

  • your target role

  • your certification goals

This roadmap is designed for:

You may be entering IT for the first time.

Recommended starting areas:

Tech+
↓
A+
↓
Network+
↓
Security+

If you already understand:

  • operating systems

  • networking

  • troubleshooting

  • enterprise IT

you may begin around:

Network+
↓
Security+

If you already have strong fundamentals:

Security+
↓
CySA+
↓
PenTest+
↓
SecurityX

may be more appropriate.

Consider:

Network+
↓
Security+
↓
Cloud+
↓
Cloud Security

Consider:

Network+
↓
Linux+
↓
Security+
↓
Advanced Security
Stage Certification Primary Focus Typical Level
01 Tech+ IT Fundamentals Beginner
02 A+ IT Support & Systems Beginner
03 Network+ Networking Beginner β†’ Intermediate
04 Security+ Cybersecurity Beginner β†’ Intermediate
05 Cloud+ Cloud Infrastructure Intermediate
06 Linux+ Linux Administration Intermediate
07 CySA+ Security Operations Intermediate
08 PenTest+ Offensive Security Intermediate
09 SecurityX Enterprise Security Advanced

Tech+ provides an introduction to:

  • IT concepts

  • computing

  • hardware

  • software

  • networking

  • databases

  • cybersecurity

  • troubleshooting

Think of Tech+ as:

Understanding the world of IT before specializing in it.

  • students

  • career switchers

  • complete beginners

  • non-technical professionals

Tech+ alone is generally not the end goal for a cybersecurity career.

Instead, it establishes the vocabulary and concepts required for later certifications.

You already understand:

  • computers

  • operating systems

  • IP networking basics

  • applications

  • basic cybersecurity

Then consider starting with:

➑️ A+ or Network+

A+ moves from understanding IT to:

supporting and troubleshooting IT systems.

You develop knowledge around:

  • computer hardware

  • operating systems

  • endpoints

  • troubleshooting

  • networking

  • software

  • security fundamentals

A+ can support entry-level roles such as:

  • IT Support Technician

  • Help Desk Technician

  • Desktop Support Technician

  • Technical Support Specialist

Security professionals investigate:

Endpoints
Operating Systems
Applications
Users
Networks

If you do not understand how systems normally operate, investigating abnormal behavior becomes much harder.

If your immediate target is:

SOC Analyst

you do not necessarily need to spend years working in help desk first.

Build the fundamentals and continue toward:

A+
↓
Network+
↓
Security+
↓
SOC Skills

Network+ is one of the most important foundation certifications for cybersecurity.

You learn concepts around:

  • TCP/IP

  • IP addressing

  • subnetting

  • switching

  • routing

  • DNS

  • DHCP

  • wireless

  • ports

  • protocols

  • network troubleshooting

  • network security

Cyberattacks move across networks.

A security analyst must understand:

Source
↓
Protocol
↓
Port
↓
Network
↓
Security Control
↓
Destination

Without networking knowledge, concepts such as:

  • firewall rules

  • segmentation

  • VPNs

  • packet analysis

  • IDS/IPS

  • lateral movement

become significantly harder.

Network+ supports progression toward:

  • Network Support

  • Network Administrator

  • SOC Analyst

  • Cybersecurity Analyst

  • Network Security Engineer

  • Cloud Security roles

After Network+, circle back to the Network+ Labs.

Practice:

  • IP addressing

  • subnetting

  • DNS

  • routing

  • network troubleshooting

  • traffic analysis

  • segmentation

  • firewall concepts

Security+ is the major transition point from:

IT professional

to:

Cybersecurity professional

You develop knowledge around:

  • threats

  • vulnerabilities

  • security architecture

  • identity

  • authentication

  • cryptography

  • network security

  • endpoint security

  • risk

  • incident response

  • governance

Security+ supports roles such as:

  • SOC Analyst

  • Junior Security Analyst

  • Cybersecurity Analyst

  • Security Administrator

  • Security Engineer

  • Security Consultant

Do not approach Security+ as:

Memorize definitions β†’ pass exam.

Approach it as:

Concept
↓
Architecture
↓
Threat
↓
Security Control
↓
Implementation
↓
Investigation

Practice:

  • IAM

  • MFA

  • firewall analysis

  • vulnerability assessment

  • SIEM

  • security logs

  • incident investigation

  • network security

  • endpoint security

  • risk assessment

Cloud+ expands your infrastructure knowledge into cloud environments.

You develop knowledge around:

  • cloud architecture

  • virtualization

  • compute

  • networking

  • storage

  • cloud security

  • identity

  • operations

  • availability

  • troubleshooting

  • DevOps concepts

Cloud+ supports progression toward:

  • Cloud Administrator

  • Cloud Engineer

  • Infrastructure Engineer

  • Cloud Security Analyst

  • Cloud Security Engineer

Modern security professionals increasingly need to understand:

Identity
+
Cloud Networks
+
Workloads
+
Storage
+
Logging
+
Automation

Circle back to the Cloud+ Labs.

Build practical experience with:

  • cloud identity

  • virtual networks

  • workloads

  • storage

  • logging

  • monitoring

  • security controls

Linux+ develops practical Linux administration skills.

You learn areas such as:

  • Linux architecture

  • command line

  • filesystems

  • permissions

  • users

  • processes

  • networking

  • services

  • scripting

  • security

  • troubleshooting

Linux appears throughout:

Cloud
Servers
Containers
Security Tools
SIEM Platforms
DevOps
Pentesting

A cybersecurity professional should become comfortable working from:

Terminal window
$

rather than relying entirely on graphical interfaces.

Linux+ supports:

  • Linux Administrator

  • Systems Administrator

  • Cloud Engineer

  • DevOps Engineer

  • Security Engineer

  • SOC Analyst

  • Penetration Tester

CySA+ moves deeper into:

Defensive Cybersecurity and Security Operations

You develop skills around:

  • security monitoring

  • vulnerability management

  • threat analysis

  • SIEM

  • incident response

  • threat intelligence

  • log analysis

  • security operations

CySA+ strongly aligns with:

  • SOC Analyst

  • Cybersecurity Analyst

  • Security Operations Analyst

  • Threat Analyst

  • Incident Response Analyst

  • Vulnerability Analyst

Instead of asking:

What does this alert mean?

Learn to ask:

What Happened?
↓
Which Identity?
↓
Which System?
↓
What Evidence?
↓
Is It Malicious?
↓
How Far Did It Spread?
↓
What Should We Do?

Circle back to the CySA+ Labs.

Practice:

  • SIEM investigations

  • log analysis

  • alert triage

  • threat investigation

  • vulnerability analysis

  • incident response

  • attack-path reconstruction

PenTest+ introduces structured offensive-security assessment.

You develop knowledge around:

  • reconnaissance

  • enumeration

  • vulnerability discovery

  • web security

  • network attacks

  • exploitation concepts

  • privilege escalation

  • reporting

  • remediation

PenTest+ supports:

  • Junior Penetration Tester

  • Vulnerability Analyst

  • Security Consultant

  • Offensive Security Analyst

  • Security Engineer

Professional penetration testing is not:

Running tools until something breaks.

It is:

Authorization
↓
Scope
↓
Reconnaissance
↓
Enumeration
↓
Vulnerability Analysis
↓
Controlled Validation
↓
Evidence
↓
Risk
↓
Remediation
↓
Reporting

Circle back to the PenTest+ Labs.

Practice only in authorized lab environments:

  • reconnaissance

  • enumeration

  • vulnerability assessment

  • exploitation concepts

  • privilege escalation concepts

  • evidence collection

  • reporting

SecurityX represents the advanced end of this CompTIA cybersecurity pathway.

This stage focuses much more heavily on:

  • enterprise security

  • architecture

  • engineering

  • risk

  • advanced security operations

  • security integration

  • complex environments

SecurityX is more relevant to experienced roles such as:

  • Senior Security Engineer

  • Security Architect

  • Cybersecurity Architect

  • Security Consultant

  • Enterprise Security Engineer

At beginner level you may be asked:

What is MFA?

At intermediate level:

How would you implement MFA?

At advanced level:

How would you design enterprise authentication that balances identity assurance, privileged access, legacy systems, availability, cloud services, user experience, and operational risk?

That is the transition toward:

architecture-level thinking.

A practical defensive-security route can look like:

Tech+ / A+
↓
Network+
↓
Security+
↓
CySA+
↓
SOC / Security Analyst
↓
Security Engineer
↓
SecurityX
↓
Security Architect

For offensive security:

A+
↓
Network+
↓
Security+
↓
Linux+
↓
PenTest+
↓
Penetration Testing Labs
↓
Junior Pentester
↓
Security Consultant

For cloud security:

Network+
↓
Security+
↓
Cloud+
↓
Linux+
↓
AWS / Azure
↓
Cloud Security Labs
↓
Cloud Security Engineer

For SOC:

Network+
↓
Security+
↓
Linux Fundamentals
↓
CySA+
↓
SIEM
↓
Threat Investigation
↓
Incident Response
↓
SOC Analyst
Network+
↓
Security+
↓
Linux+
↓
Cloud+
↓
CySA+
↓
Security Engineering
↓
SecurityX

No.

This is extremely important.

Do not turn your learning journey into:

Tech+
A+
Network+
Security+
Cloud+
Linux+
CySA+
PenTest+
SecurityX

simply because they appear sequentially.

Instead ask:

What skills does my target role require?

A reasonable progression could be:

Tech+
↓
A+
↓
Network+
↓
Security+

Then specialize.

You might choose:

Network+
↓
Security+
↓
CySA+

You may already possess much of:

A+
Network+

Your focus might therefore become:

Security+
↓
CySA+
↓
SecurityX

You may choose directly:

CySA+
PenTest+
SecurityX

depending on your role.

For every certification, use this cycle:

Learn
↓
Understand
↓
Practice
↓
Review
↓
Practice Questions
↓
Identify Weak Areas
↓
Return to Study
↓
Lab
↓
Mock Exam
↓
Certification Exam

Complete the relevant GoHackersCloud course.

Do not rush through videos simply to mark them complete.

Ask yourself:

Can I explain this concept without looking at the lesson?

For every major technology ask:

What Is It?
↓
Why Does It Exist?
↓
How Does It Work?
↓
Where Is It Used?
↓
How Is It Secured?
↓
How Can It Fail?

This is where the Academy structure becomes important.

After completing the recorded certification course:

Circle back to the corresponding Labs section.

For example:

Network+ Course
↓
Network+ Labs
Cloud+ Course
↓
Cloud+ Labs
CySA+ Course
↓
CySA+ Labs
PenTest+ Course
↓
PenTest+ Labs

The recorded course teaches:

what you need to understand.

The labs teach:

how it behaves in practice.

The runbooks teach:

how professionals approach the task repeatedly.

Do not create hundreds of pages of notes.

Focus on:

  • important concepts

  • architectures

  • commands

  • comparison tables

  • mistakes

  • weak areas

Practice questions should teach you:

how to apply concepts.

For every incorrect answer ask:

Why Was I Wrong?
↓
Which Concept Did I Miss?
↓
Why Is the Correct Answer Better?

CompTIA exams increasingly require applied understanding.

Instead of memorizing:

Port 443 = HTTPS

understand:

Client
↓
DNS
↓
Network
↓
Firewall
↓
TCP/443
↓
TLS
↓
Web Server

and understand where security controls apply.

Do not ignore practical-style questions.

Practice:

  • interpreting logs

  • network diagrams

  • troubleshooting

  • firewall rules

  • security controls

  • architecture scenarios

During final preparation:

Do not repeatedly study what you already know.

Track:

Topic Confidence Action
Networking High Quick Review
IAM Medium Practice
Cryptography Low Deep Review
Incident Response Medium Lab

When answering scenario questions, identify:

Requirement
+
Constraint
+
Risk
+
Best Available Control

Do not simply choose the technology you recognize.

Words such as:

  • BEST

  • FIRST

  • MOST

  • LEAST

  • NEXT

can completely change the expected answer.

This distinction is critical.

Passing:

Security+

does not automatically make someone:

Security Analyst

Job readiness requires:

Knowledge
+
Hands-On Skills
+
Troubleshooting
+
Communication
+
Portfolio
+
Interview Skills

Throughout the CompTIA journey, practise:

  • Windows

  • Linux

  • networking

  • cloud

  • IAM

  • firewalls

  • logs

  • SIEM

  • vulnerability management

  • incident investigation

Create sanitized artifacts from your labs.

Examples:

Network Diagram
Firewall Review
Security Assessment
Incident Timeline
Attack Path
Vulnerability Report
Hardening Checklist
Remediation Plan

These demonstrate:

what you can actually do.

During an interview, you may be asked:

Tell me about a security project you completed.

Use:

Scenario
↓
Objective
↓
Environment
↓
What You Did
↓
What You Found
↓
How You Investigated
↓
Recommendation
↓
What You Learned

As you progress, practise questions such as:

  • What happens when you enter a URL into a browser?

  • What is DNS?

  • What is DHCP?

  • What is a subnet?

  • What is a VLAN?

  • What is a firewall?

  • What is NAT?

  • TCP vs UDP?

  • What is a process?

  • What is a service?

  • What is virtualization?

  • What happens during system boot?

  • How do permissions work?

  • Authentication vs authorization?

  • What is MFA?

  • What is least privilege?

  • What is Zero Trust?

  • What is vulnerability management?

  • IDS vs IPS?

  • Hashing vs encryption?

  • How would you investigate a suspicious login?

  • What logs would you review?

  • What is a false positive?

  • What is lateral movement?

  • How do you investigate malware communication?

  • What is shared responsibility?

  • What is cloud IAM?

  • What is a security group?

  • How would you secure cloud storage?

  • How would you monitor a cloud environment?

  • What is reconnaissance?

  • Vulnerability scanning vs penetration testing?

  • What is enumeration?

  • Why is scope important?

  • What should a penetration-test report contain?

A user reports that their account was accessed from an unknown location. How would you investigate?

Think:

User
↓
Authentication Logs
↓
Source IP
↓
Device
↓
MFA
↓
Session Activity
↓
Other Systems Accessed
↓
Scope
↓
Containment

A server suddenly begins communicating with an unfamiliar external IP.

Think:

Source Host
↓
Destination
↓
Port / Protocol
↓
DNS
↓
Firewall Logs
↓
Endpoint Activity
↓
Historical Behavior
↓
Other Affected Hosts

A vulnerability scanner reports a critical vulnerability.

Do not immediately say:

Patch it.

Think:

Validate
↓
Asset Criticality
↓
Exposure
↓
Exploitability
↓
Existing Controls
↓
Business Impact
↓
Prioritize
↓
Remediate
↓
Verify

Use:

Certification
↓
Knowledge
Labs
↓
Practical Skills
Runbooks
↓
Professional Methodology
Portfolio
↓
Evidence of Skills
Interview Practice
↓
Ability to Communicate Skills
Career

This is why the Academy does not stop at certification preparation.

The complete progression is:

IT Foundations
↓
Tech+
↓
IT Support
↓
A+
↓
Networking
↓
Network+
↓
Cybersecurity
↓
Security+
↓
Cloud Infrastructure
↓
Cloud+
↓
Linux
↓
Linux+
↓
Security Operations
↓
CySA+
↓
Offensive Security
↓
PenTest+
↓
Enterprise Security
↓
SecurityX

But remember:

This is a roadmap, not a mandatory checklist.

Choose certifications based on the career you are building.

Now that you understand the CompTIA certification landscape, the next page will translate these certifications into actual cybersecurity career progression.

You will learn:

  • which certifications align with different cybersecurity roles

  • which certifications beginners should prioritize

  • when to specialize

  • defensive vs offensive security paths

  • cloud security progression

  • SOC Analyst progression

  • security engineering progression

  • which practical skills employers expect

  • how labs and runbooks fit into your career journey

  • how to move from certification-ready to job-ready

➑️ Next: Cybersecurity Career Roadmap