CompTIA Certification Roadmap
CompTIA certifications can take you from your first understanding of IT to professional roles in networking, cybersecurity, cloud, security operations, penetration testing, and enterprise security. The key is not collecting certificationsβit is building skills in the right sequence.
Welcome to the CompTIA Certification Roadmap.
This roadmap will help you understand:
- where to begin
- which certifications are appropriate for your experience
- which certifications you may be able to skip
- how certifications connect to cybersecurity careers
- when to start practical labs
- how to build job-ready skills
- how to progress from beginner to advanced security roles
The GoHackersCloud CompTIA path follows:
Tech+ βA+ βNetwork+ βSecurity+ βCloud+ βLinux+ βCySA+ βPenTest+ βSecurityXYou do not necessarily need every certification.
Your route should depend on:
-
your existing IT knowledge
-
your experience
-
your target role
-
your certification goals
π― Who Is This Roadmap For?
Section titled βπ― Who Is This Roadmap For?βThis roadmap is designed for:
Complete Beginners
Section titled βComplete BeginnersβYou may be entering IT for the first time.
Recommended starting areas:
Tech+ βA+ βNetwork+ βSecurity+IT Professionals Moving Into Cybersecurity
Section titled βIT Professionals Moving Into CybersecurityβIf you already understand:
-
operating systems
-
networking
-
troubleshooting
-
enterprise IT
you may begin around:
Network+ βSecurity+Existing Cybersecurity Professionals
Section titled βExisting Cybersecurity ProfessionalsβIf you already have strong fundamentals:
Security+ βCySA+ βPenTest+ βSecurityXmay be more appropriate.
Cloud Professionals
Section titled βCloud ProfessionalsβConsider:
Network+ βSecurity+ βCloud+ βCloud SecurityLinux / Infrastructure Professionals
Section titled βLinux / Infrastructure ProfessionalsβConsider:
Network+ βLinux+ βSecurity+ βAdvanced Securityπ§ Complete CompTIA Roadmap
Section titled βπ§ Complete CompTIA Roadmapβ| Stage | Certification | Primary Focus | Typical Level |
|---|---|---|---|
| 01 | Tech+ | IT Fundamentals | Beginner |
| 02 | A+ | IT Support & Systems | Beginner |
| 03 | Network+ | Networking | Beginner β Intermediate |
| 04 | Security+ | Cybersecurity | Beginner β Intermediate |
| 05 | Cloud+ | Cloud Infrastructure | Intermediate |
| 06 | Linux+ | Linux Administration | Intermediate |
| 07 | CySA+ | Security Operations | Intermediate |
| 08 | PenTest+ | Offensive Security | Intermediate |
| 09 | SecurityX | Enterprise Security | Advanced |
π’ Stage 01 β CompTIA Tech+
Section titled βπ’ Stage 01 β CompTIA Tech+βPurpose
Section titled βPurposeβTech+ provides an introduction to:
-
IT concepts
-
computing
-
hardware
-
software
-
networking
-
databases
-
cybersecurity
-
troubleshooting
Think of Tech+ as:
Understanding the world of IT before specializing in it.
Best For
Section titled βBest Forβ-
students
-
career switchers
-
complete beginners
-
non-technical professionals
Career Value
Section titled βCareer ValueβTech+ alone is generally not the end goal for a cybersecurity career.
Instead, it establishes the vocabulary and concepts required for later certifications.
You May Skip Tech+ If
Section titled βYou May Skip Tech+ IfβYou already understand:
-
computers
-
operating systems
-
IP networking basics
-
applications
-
basic cybersecurity
Then consider starting with:
β‘οΈ A+ or Network+
π’ Stage 02 β CompTIA A+
Section titled βπ’ Stage 02 β CompTIA A+βA+ moves from understanding IT to:
supporting and troubleshooting IT systems.
You develop knowledge around:
-
computer hardware
-
operating systems
-
endpoints
-
troubleshooting
-
networking
-
software
-
security fundamentals
Career Alignment
Section titled βCareer AlignmentβA+ can support entry-level roles such as:
-
IT Support Technician
-
Help Desk Technician
-
Desktop Support Technician
-
Technical Support Specialist
π§ Why A+ Matters for Cybersecurity
Section titled βπ§ Why A+ Matters for CybersecurityβSecurity professionals investigate:
EndpointsOperating SystemsApplicationsUsersNetworksIf you do not understand how systems normally operate, investigating abnormal behavior becomes much harder.
π‘ Career Advice
Section titled βπ‘ Career AdviceβIf your immediate target is:
SOC Analyst
you do not necessarily need to spend years working in help desk first.
Build the fundamentals and continue toward:
A+ βNetwork+ βSecurity+ βSOC Skillsπ’ Stage 03 β CompTIA Network+
Section titled βπ’ Stage 03 β CompTIA Network+βNetwork+ is one of the most important foundation certifications for cybersecurity.
You learn concepts around:
-
TCP/IP
-
IP addressing
-
subnetting
-
switching
-
routing
-
DNS
-
DHCP
-
wireless
-
ports
-
protocols
-
network troubleshooting
-
network security
π§ Why Networking Matters
Section titled βπ§ Why Networking MattersβCyberattacks move across networks.
A security analyst must understand:
Source βProtocol βPort βNetwork βSecurity Control βDestinationWithout networking knowledge, concepts such as:
-
firewall rules
-
segmentation
-
VPNs
-
packet analysis
-
IDS/IPS
-
lateral movement
become significantly harder.
π― Career Alignment
Section titled βπ― Career AlignmentβNetwork+ supports progression toward:
-
Network Support
-
Network Administrator
-
SOC Analyst
-
Cybersecurity Analyst
-
Network Security Engineer
-
Cloud Security roles
π§ͺ Practical Skills
Section titled βπ§ͺ Practical SkillsβAfter Network+, circle back to the Network+ Labs.
Practice:
-
IP addressing
-
subnetting
-
DNS
-
routing
-
network troubleshooting
-
traffic analysis
-
segmentation
-
firewall concepts
π’ Stage 04 β CompTIA Security+
Section titled βπ’ Stage 04 β CompTIA Security+βSecurity+ is the major transition point from:
IT professional
to:
Cybersecurity professional
You develop knowledge around:
-
threats
-
vulnerabilities
-
security architecture
-
identity
-
authentication
-
cryptography
-
network security
-
endpoint security
-
risk
-
incident response
-
governance
π― Career Alignment
Section titled βπ― Career AlignmentβSecurity+ supports roles such as:
-
SOC Analyst
-
Junior Security Analyst
-
Cybersecurity Analyst
-
Security Administrator
-
Security Engineer
-
Security Consultant
π§ Security+ Career Principle
Section titled βπ§ Security+ Career PrincipleβDo not approach Security+ as:
Memorize definitions β pass exam.
Approach it as:
Concept βArchitecture βThreat βSecurity Control βImplementation βInvestigationπ§ͺ Practical Skills After Security+
Section titled βπ§ͺ Practical Skills After Security+βPractice:
-
IAM
-
MFA
-
firewall analysis
-
vulnerability assessment
-
SIEM
-
security logs
-
incident investigation
-
network security
-
endpoint security
-
risk assessment
π’ Stage 05 β CompTIA Cloud+
Section titled βπ’ Stage 05 β CompTIA Cloud+βCloud+ expands your infrastructure knowledge into cloud environments.
You develop knowledge around:
-
cloud architecture
-
virtualization
-
compute
-
networking
-
storage
-
cloud security
-
identity
-
operations
-
availability
-
troubleshooting
-
DevOps concepts
π― Career Alignment
Section titled βπ― Career AlignmentβCloud+ supports progression toward:
-
Cloud Administrator
-
Cloud Engineer
-
Infrastructure Engineer
-
Cloud Security Analyst
-
Cloud Security Engineer
π§ Cloud Security Connection
Section titled βπ§ Cloud Security ConnectionβModern security professionals increasingly need to understand:
Identity+Cloud Networks+Workloads+Storage+Logging+Automationπ§ͺ After Cloud+
Section titled βπ§ͺ After Cloud+βCircle back to the Cloud+ Labs.
Build practical experience with:
-
cloud identity
-
virtual networks
-
workloads
-
storage
-
logging
-
monitoring
-
security controls
π’ Stage 06 β CompTIA Linux+
Section titled βπ’ Stage 06 β CompTIA Linux+βLinux+ develops practical Linux administration skills.
You learn areas such as:
-
Linux architecture
-
command line
-
filesystems
-
permissions
-
users
-
processes
-
networking
-
services
-
scripting
-
security
-
troubleshooting
π§ Why Linux Matters for Cybersecurity
Section titled βπ§ Why Linux Matters for CybersecurityβLinux appears throughout:
CloudServersContainersSecurity ToolsSIEM PlatformsDevOpsPentestingA cybersecurity professional should become comfortable working from:
$rather than relying entirely on graphical interfaces.
π― Career Alignment
Section titled βπ― Career AlignmentβLinux+ supports:
-
Linux Administrator
-
Systems Administrator
-
Cloud Engineer
-
DevOps Engineer
-
Security Engineer
-
SOC Analyst
-
Penetration Tester
π Stage 07 β CompTIA CySA+
Section titled βπ Stage 07 β CompTIA CySA+βCySA+ moves deeper into:
Defensive Cybersecurity and Security Operations
You develop skills around:
-
security monitoring
-
vulnerability management
-
threat analysis
-
SIEM
-
incident response
-
threat intelligence
-
log analysis
-
security operations
π― Career Alignment
Section titled βπ― Career AlignmentβCySA+ strongly aligns with:
-
SOC Analyst
-
Cybersecurity Analyst
-
Security Operations Analyst
-
Threat Analyst
-
Incident Response Analyst
-
Vulnerability Analyst
π§ SOC Analyst Thinking
Section titled βπ§ SOC Analyst ThinkingβInstead of asking:
What does this alert mean?
Learn to ask:
What Happened? βWhich Identity? βWhich System? βWhat Evidence? βIs It Malicious? βHow Far Did It Spread? βWhat Should We Do?π§ͺ After CySA+
Section titled βπ§ͺ After CySA+βCircle back to the CySA+ Labs.
Practice:
-
SIEM investigations
-
log analysis
-
alert triage
-
threat investigation
-
vulnerability analysis
-
incident response
-
attack-path reconstruction
π Stage 08 β CompTIA PenTest+
Section titled βπ Stage 08 β CompTIA PenTest+βPenTest+ introduces structured offensive-security assessment.
You develop knowledge around:
-
reconnaissance
-
enumeration
-
vulnerability discovery
-
web security
-
network attacks
-
exploitation concepts
-
privilege escalation
-
reporting
-
remediation
π― Career Alignment
Section titled βπ― Career AlignmentβPenTest+ supports:
-
Junior Penetration Tester
-
Vulnerability Analyst
-
Security Consultant
-
Offensive Security Analyst
-
Security Engineer
π§ Penetration Testing Principle
Section titled βπ§ Penetration Testing PrincipleβProfessional penetration testing is not:
Running tools until something breaks.
It is:
Authorization βScope βReconnaissance βEnumeration βVulnerability Analysis βControlled Validation βEvidence βRisk βRemediation βReportingπ§ͺ After PenTest+
Section titled βπ§ͺ After PenTest+βCircle back to the PenTest+ Labs.
Practice only in authorized lab environments:
-
reconnaissance
-
enumeration
-
vulnerability assessment
-
exploitation concepts
-
privilege escalation concepts
-
evidence collection
-
reporting
π΄ Stage 09 β CompTIA SecurityX
Section titled βπ΄ Stage 09 β CompTIA SecurityXβSecurityX represents the advanced end of this CompTIA cybersecurity pathway.
This stage focuses much more heavily on:
-
enterprise security
-
architecture
-
engineering
-
risk
-
advanced security operations
-
security integration
-
complex environments
π― Career Alignment
Section titled βπ― Career AlignmentβSecurityX is more relevant to experienced roles such as:
-
Senior Security Engineer
-
Security Architect
-
Cybersecurity Architect
-
Security Consultant
-
Enterprise Security Engineer
π§ Advanced-Level Difference
Section titled βπ§ Advanced-Level DifferenceβAt beginner level you may be asked:
What is MFA?
At intermediate level:
How would you implement MFA?
At advanced level:
How would you design enterprise authentication that balances identity assurance, privileged access, legacy systems, availability, cloud services, user experience, and operational risk?
That is the transition toward:
architecture-level thinking.
πΊοΈ Cybersecurity Career Roadmap
Section titled βπΊοΈ Cybersecurity Career RoadmapβA practical defensive-security route can look like:
Tech+ / A+ βNetwork+ βSecurity+ βCySA+ βSOC / Security Analyst βSecurity Engineer βSecurityX βSecurity Architectπ΄ Offensive Security Roadmap
Section titled βπ΄ Offensive Security RoadmapβFor offensive security:
A+ βNetwork+ βSecurity+ βLinux+ βPenTest+ βPenetration Testing Labs βJunior Pentester βSecurity ConsultantβοΈ Cloud Security Roadmap
Section titled ββοΈ Cloud Security RoadmapβFor cloud security:
Network+ βSecurity+ βCloud+ βLinux+ βAWS / Azure βCloud Security Labs βCloud Security Engineerπ΅ SOC Analyst Roadmap
Section titled βπ΅ SOC Analyst RoadmapβFor SOC:
Network+ βSecurity+ βLinux Fundamentals βCySA+ βSIEM βThreat Investigation βIncident Response βSOC Analystπ£ Security Engineering Roadmap
Section titled βπ£ Security Engineering RoadmapβNetwork+ βSecurity+ βLinux+ βCloud+ βCySA+ βSecurity Engineering βSecurityXπ« Do You Need Every CompTIA Certification?
Section titled βπ« Do You Need Every CompTIA Certification?βNo.
This is extremely important.
Do not turn your learning journey into:
Tech+A+Network+Security+Cloud+Linux+CySA+PenTest+SecurityXsimply because they appear sequentially.
Instead ask:
What skills does my target role require?
Example β Complete Beginner
Section titled βExample β Complete BeginnerβA reasonable progression could be:
Tech+ βA+ βNetwork+ βSecurity+Then specialize.
Example β Existing IT Professional
Section titled βExample β Existing IT ProfessionalβYou might choose:
Network+ βSecurity+ βCySA+Example β Experienced Network Engineer
Section titled βExample β Experienced Network EngineerβYou may already possess much of:
A+Network+Your focus might therefore become:
Security+ βCySA+ βSecurityXExample β Existing Security Professional
Section titled βExample β Existing Security ProfessionalβYou may choose directly:
CySA+PenTest+SecurityXdepending on your role.
π§ Certification Strategy
Section titled βπ§ Certification StrategyβFor every certification, use this cycle:
Learn βUnderstand βPractice βReview βPractice Questions βIdentify Weak Areas βReturn to Study βLab βMock Exam βCertification Examπ Phase 1 β Learn the Concepts
Section titled βπ Phase 1 β Learn the ConceptsβComplete the relevant GoHackersCloud course.
Do not rush through videos simply to mark them complete.
Ask yourself:
Can I explain this concept without looking at the lesson?
π§ Phase 2 β Understand the Technology
Section titled βπ§ Phase 2 β Understand the TechnologyβFor every major technology ask:
What Is It? βWhy Does It Exist? βHow Does It Work? βWhere Is It Used? βHow Is It Secured? βHow Can It Fail?π§ͺ Phase 3 β Complete Practical Labs
Section titled βπ§ͺ Phase 3 β Complete Practical LabsβThis is where the Academy structure becomes important.
After completing the recorded certification course:
Circle back to the corresponding Labs section.
For example:
Network+ Course βNetwork+ Labs
Cloud+ Course βCloud+ Labs
CySA+ Course βCySA+ Labs
PenTest+ Course βPenTest+ Labsπ§ Why Circle Back?
Section titled βπ§ Why Circle Back?βThe recorded course teaches:
what you need to understand.
The labs teach:
how it behaves in practice.
The runbooks teach:
how professionals approach the task repeatedly.
π Phase 4 β Build Notes
Section titled βπ Phase 4 β Build NotesβDo not create hundreds of pages of notes.
Focus on:
-
important concepts
-
architectures
-
commands
-
comparison tables
-
mistakes
-
weak areas
β Phase 5 β Practice Questions
Section titled ββ Phase 5 β Practice QuestionsβPractice questions should teach you:
how to apply concepts.
For every incorrect answer ask:
Why Was I Wrong? βWhich Concept Did I Miss? βWhy Is the Correct Answer Better?π― Phase 6 β Scenario-Based Preparation
Section titled βπ― Phase 6 β Scenario-Based PreparationβCompTIA exams increasingly require applied understanding.
Instead of memorizing:
Port 443 = HTTPS
understand:
Client βDNS βNetwork βFirewall βTCP/443 βTLS βWeb Serverand understand where security controls apply.
π§ͺ Phase 7 β Performance-Based Questions
Section titled βπ§ͺ Phase 7 β Performance-Based QuestionsβDo not ignore practical-style questions.
Practice:
-
interpreting logs
-
network diagrams
-
troubleshooting
-
firewall rules
-
security controls
-
architecture scenarios
β±οΈ Exam Preparation Strategy
Section titled ββ±οΈ Exam Preparation StrategyβDuring final preparation:
Review Strong Areas Quickly
Section titled βReview Strong Areas QuicklyβDo not repeatedly study what you already know.
Spend Time on Weak Areas
Section titled βSpend Time on Weak AreasβTrack:
| Topic | Confidence | Action |
|---|---|---|
| Networking | High | Quick Review |
| IAM | Medium | Practice |
| Cryptography | Low | Deep Review |
| Incident Response | Medium | Lab |
π§ Certification Exam Tip
Section titled βπ§ Certification Exam TipβWhen answering scenario questions, identify:
Requirement+Constraint+Risk+Best Available ControlDo not simply choose the technology you recognize.
π¨ Watch for Keywords
Section titled βπ¨ Watch for KeywordsβWords such as:
-
BEST
-
FIRST
-
MOST
-
LEAST
-
NEXT
can completely change the expected answer.
πΌ Certification β Job Readiness
Section titled βπΌ Certification β Job ReadinessβThis distinction is critical.
Passing:
Security+does not automatically make someone:
Security AnalystJob readiness requires:
Knowledge+Hands-On Skills+Troubleshooting+Communication+Portfolio+Interview Skillsπ οΈ Build Practical Skills
Section titled βπ οΈ Build Practical SkillsβThroughout the CompTIA journey, practise:
-
Windows
-
Linux
-
networking
-
cloud
-
IAM
-
firewalls
-
logs
-
SIEM
-
vulnerability management
-
incident investigation
π Build a Cybersecurity Portfolio
Section titled βπ Build a Cybersecurity PortfolioβCreate sanitized artifacts from your labs.
Examples:
Network DiagramFirewall ReviewSecurity AssessmentIncident TimelineAttack PathVulnerability ReportHardening ChecklistRemediation PlanThese demonstrate:
what you can actually do.
π¬ Learn to Explain Your Labs
Section titled βπ¬ Learn to Explain Your LabsβDuring an interview, you may be asked:
Tell me about a security project you completed.
Use:
Scenario βObjective βEnvironment βWhat You Did βWhat You Found βHow You Investigated βRecommendation βWhat You Learnedπ€ Core CompTIA Interview Questions
Section titled βπ€ Core CompTIA Interview QuestionsβAs you progress, practise questions such as:
Networking
Section titled βNetworkingβ-
What happens when you enter a URL into a browser?
-
What is DNS?
-
What is DHCP?
-
What is a subnet?
-
What is a VLAN?
-
What is a firewall?
-
What is NAT?
-
TCP vs UDP?
Systems
Section titled βSystemsβ-
What is a process?
-
What is a service?
-
What is virtualization?
-
What happens during system boot?
-
How do permissions work?
Security
Section titled βSecurityβ-
Authentication vs authorization?
-
What is MFA?
-
What is least privilege?
-
What is Zero Trust?
-
What is vulnerability management?
-
IDS vs IPS?
-
Hashing vs encryption?
Security Operations
Section titled βSecurity Operationsβ-
How would you investigate a suspicious login?
-
What logs would you review?
-
What is a false positive?
-
What is lateral movement?
-
How do you investigate malware communication?
-
What is shared responsibility?
-
What is cloud IAM?
-
What is a security group?
-
How would you secure cloud storage?
-
How would you monitor a cloud environment?
Penetration Testing
Section titled βPenetration Testingβ-
What is reconnaissance?
-
Vulnerability scanning vs penetration testing?
-
What is enumeration?
-
Why is scope important?
-
What should a penetration-test report contain?
π¨ Interview Scenario
Section titled βπ¨ Interview ScenarioβA user reports that their account was accessed from an unknown location. How would you investigate?
Think:
User βAuthentication Logs βSource IP βDevice βMFA βSession Activity βOther Systems Accessed βScope βContainmentπ¨ Interview Scenario
Section titled βπ¨ Interview ScenarioβA server suddenly begins communicating with an unfamiliar external IP.
Think:
Source Host βDestination βPort / Protocol βDNS βFirewall Logs βEndpoint Activity βHistorical Behavior βOther Affected Hostsπ¨ Interview Scenario
Section titled βπ¨ Interview ScenarioβA vulnerability scanner reports a critical vulnerability.
Do not immediately say:
Patch it.
Think:
Validate βAsset Criticality βExposure βExploitability βExisting Controls βBusiness Impact βPrioritize βRemediate βVerifyβ Recommended Learning Philosophy
Section titled ββ Recommended Learning PhilosophyβUse:
Certification βKnowledge
Labs βPractical Skills
Runbooks βProfessional Methodology
Portfolio βEvidence of Skills
Interview Practice βAbility to Communicate Skills
CareerThis is why the Academy does not stop at certification preparation.
π Your CompTIA Journey
Section titled βπ Your CompTIA JourneyβThe complete progression is:
IT Foundations βTech+ βIT Support βA+ βNetworking βNetwork+ βCybersecurity βSecurity+ βCloud Infrastructure βCloud+ βLinux βLinux+ βSecurity Operations βCySA+ βOffensive Security βPenTest+ βEnterprise Security βSecurityXBut remember:
This is a roadmap, not a mandatory checklist.
Choose certifications based on the career you are building.
π Whatβs Next?
Section titled βπ Whatβs Next?βNow that you understand the CompTIA certification landscape, the next page will translate these certifications into actual cybersecurity career progression.
You will learn:
-
which certifications align with different cybersecurity roles
-
which certifications beginners should prioritize
-
when to specialize
-
defensive vs offensive security paths
-
cloud security progression
-
SOC Analyst progression
-
security engineering progression
-
which practical skills employers expect
-
how labs and runbooks fit into your career journey
-
how to move from certification-ready to job-ready
β‘οΈ Next: Cybersecurity Career Roadmap