Interactive guides built to get you exam-ready
Each cybersecurity guide maps to the real exam objectives, with practice questions you answer right here and a downloadable PDF. Guides start at $14.95, or get All-Access to every guide for $29/month.
Complete Security+ Collection
All five SY0-701 domains: 100% exam coverage in one purchase. 5 guides · 375 practice questions · 460 pages of PDFs, every domain of the SY0-701 exam, one purchase, lifetime access.
- D1.0: General Security Concepts
- D2.0: Threats, Vulnerabilities & Mitigations
- D3.0: Security Architecture
- D4.0: Security Operations
- D5.0: Security Program Management & Oversight
Complete CISSP Collection
All eight CISSP domains: 100% exam coverage in one purchase. 8 guides · 640 practice questions · 967 pages of PDFs, every domain of the CISSP exam, one purchase, lifetime access.
- D1.0: Security and Risk Management
- D2.0: Asset Security
- D3.0: Security Architecture and Engineering
- D4.0: Communication and Network Security
- D5.0: Identity and Access Management (IAM)
- D6.0: Security Assessment and Testing
- D7.0: Security Operations
- D8.0: Software Development Security
Complete CCSP Collection
All six CCSP domains: 100% exam coverage in one purchase. 6 guides · 380 practice questions · 663 pages of PDFs, every domain of the CCSP exam, one purchase, lifetime access.
- D1.0: Cloud Concepts, Architecture and Design
- D2.0: Cloud Data Security
- D3.0: Cloud Platform and Infrastructure Security
- D4.0: Cloud Application Security
- D5.0: Cloud Security Operations
- D6.0: Legal, Risk and Compliance
Complete CySA+ Collection
All four CS0-004 V4 domains: 100% exam coverage in one purchase. 4 guides · 320 practice questions · 478 pages of PDFs, every domain of the CS0-004 exam, one purchase, lifetime access.
- D1.0: Security Operations
- D2.0: Vulnerability Management
- D3.0: Incident Response and Management
- D4.0: Reporting and Communication
Complete SecAI+ Collection
All four CY0-001 domains: 100% exam coverage in one purchase. 4 guides · 270 practice questions · 345 pages of PDFs, every domain of the CY0-001 exam, one purchase, lifetime access.
- D1.0: Basic AI Concepts Related to Cybersecurity
- D2.0: Securing AI Systems
- D3.0: AI-assisted Security
- D4.0: AI Governance, Risk, and Compliance
SecAI+ Domain 1: Basic AI Concepts
Everything Domain 1 of CompTIA's new SecAI+ exam tests, made to actually click: 18 in-depth topics across 3 modules, from how AI models really work to securing the data and the full AI lifecycle. A focused 67-page guide you'll finish, with worked examples and exam tips throughout.
SecAI+ Domain 2: Securing AI Systems
The biggest domain on CompTIA's SecAI+ exam, made to actually click: all 6 objectives (2.1–2.6) across threat modeling, security controls, access controls, data security, monitoring, and attack analysis. Follow security engineer Maya Chen as she secures a live customer-facing AI agent end to end, with hand-built diagrams, worked scenarios, and 90 exam-style questions.
SecAI+ Domain 3: AI-assisted Security
The flip side of the SecAI+ exam: using AI to do security. All 3 objectives (3.1–3.3) across AI-enabled security tools, how attackers weaponize AI, and automating security tasks in the SOC and the pipeline. Follow SOC lead Darius Cole as Northstar Financial puts AI to work defensively, with hand-built diagrams, worked scenarios, and 60 exam-style questions.
SecAI+ Domain 4: AI Governance, Risk & Compliance
The governance domain of the SecAI+ exam, made concrete: all 3 objectives (4.1–4.3) across AI governance structures and roles, responsible AI and risk, and the regulatory landscape from the EU AI Act to the NIST AI RMF. Follow AI governance lead Priya Raman as she charters Northstar's AI Center of Excellence, with hand-built diagrams, worked scenarios, and 60 exam-style questions.
Security+ Domain 1: General Security Concepts
The foundation the rest of Security+ builds on: all 4 objectives (1.1–1.4), from control categories and the CIA triad through change management and every cryptographic solution on the exam. An 82-page guide with worked examples, exam tips, and 60 exam-style practice questions.
Security+ Domain 2: Threats, Vulnerabilities & Mitigations
Know your enemy: all 5 objectives (2.1–2.5) covering threat actors and their motivations, every attack vector and vulnerability type on the exam, the indicators of malicious activity, and the mitigations that stop them. 92 pages with 75 exam-style practice questions.
Security+ Domain 3: Security Architecture
How secure systems are built: all 4 objectives (3.1–3.4) across architecture models from cloud to ICS/IoT, securing enterprise infrastructure, the full data-protection toolkit, and resilience and recovery. 81 pages with 60 exam-style practice questions.
Security+ Domain 4: Security Operations
The biggest domain on the exam: all 9 objectives (4.1–4.9), from hardening and asset management through vulnerability management, monitoring, IAM, automation, incident response, and forensic data sources. 121 pages with 90 exam-style practice questions.
Security+ Domain 5: Security Program Management & Oversight
The governance domain: all 6 objectives (5.1–5.6) across security governance, risk management, third-party risk, compliance, audits and assessments, and security awareness. 84 pages with 90 exam-style practice questions.
CySA+ Domain 1: Security Operations
The largest domain on CompTIA's new CySA+ V4 exam: all 6 objectives (1.1–1.6), from logging architecture and indicator analysis through the analyst toolkit, threat hunting, SOC process improvement, and the brand-new AI objective. Follow analyst Rafael Ortiz through a working hospital SOC, with hand-built diagrams, real tool output, and 120 exam-style questions.
CySA+ Domain 2: Vulnerability Management
The second-largest domain on CySA+ V4: all 4 objectives (2.1–2.4), from asset inventory and scan selection through reading tool output critically, prioritizing on exploitation evidence rather than severity, and the control and risk vocabulary that makes a program defensible. Follow vulnerability lead Dev Sharma as he rebuilds a hospital's program from 61,000 findings down to work that fits.
CySA+ Domain 3: Incident Response & Management
What happens when something gets through: all 3 objectives (3.1–3.3), across the Cyber Kill Chain, Diamond Model and MITRE ATT&CK, the seven-phase response process, and every technique from evidence handling to root cause analysis. Follow a live hospital ransomware incident from the 04:12 alert to the regulator submission, with a full reconstructed timeline.
CySA+ Domain 4: Reporting & Communication
The smallest domain on the exam and the one most candidates under-prepare: both objectives (4.1–4.2), from matching the report to the audience and naming the inhibitors that block remediation, through incident declaration, executive summaries, regulatory notification and the SOC metrics that describe real performance rather than activity.
CISSP Domain 1: Security and Risk Management
The largest domain on the CISSP exam and the conceptual foundation of the whole certification: all 12 objectives (1.1–1.12), from professional ethics and security governance through legal and regulatory obligation, business continuity requirements, personnel security, the risk management vocabulary the rest of the exam assumes, threat modeling, supply chain risk and the awareness program that makes any of it real.
CISSP Domain 2: Asset Security
Everything that follows from knowing what you hold and what it is worth: all 6 objectives (2.1–2.6), from classifying information and assets through handling requirements, secure provisioning, the full data lifecycle including remanence and destruction, asset retention past end of support, and the controls and compliance requirements classification drives.
CISSP Domain 3: Security Architecture and Engineering
The engineering domain: all 10 objectives (3.1–3.10), from the eleven secure design principles and the formal security models through system security capabilities, the vulnerabilities of fifteen architecture types, cryptographic selection and cryptanalytic attack, site and facility design, and the information system lifecycle objective added in 2024.
CISSP Domain 4: Communication and Network Security
Networks designed, built and operated securely: all 3 objectives (4.1–4.3), from the reference models and secure protocols through segmentation at three grades, north-south against east-west traffic, wireless and cellular, software-defined networking and virtual private clouds, then securing the components and the communication channels people actually use.
CISSP Domain 5: Identity and Access Management (IAM)
The control plane of a modern organization: all 6 objectives (5.1–5.6), from controlling physical and logical access through identification and authentication strategy, federated identity with a third party, the six authorization models, the provisioning lifecycle, and the authentication protocols themselves: OAuth and OpenID Connect, SAML, Kerberos, RADIUS and TACACS+.
CISSP Domain 6: Security Assessment and Testing
Proving that controls work: all 5 objectives (6.1–6.5), from designing and validating an assessment strategy through the ten named testing techniques including the two added in 2024, the process data that turns point-in-time findings into a continuous picture, analysis and reporting that changes something, and audits that produce an opinion rather than a suggestion.
CISSP Domain 7: Security Operations
The largest objective count on the exam: all 15 objectives (7.1–7.15), from investigations and digital forensics through logging and monitoring, configuration and change management, incident management, detection and preventative measures, patch and vulnerability management, recovery and disaster recovery, business continuity, physical security and personnel safety.
CISSP Domain 8: Software Development Security
Where governance meets the line of code: all 5 objectives (8.1–8.5), from integrating security into the SDLC and securing the development ecosystem through assessing software security effectiveness, evaluating acquired software, and the secure coding and API practices that decide whether a control exists or does not.
CCSP Domain 1: Cloud Concepts, Architecture and Design
The foundation the whole certification rests on: all six objectives (1.1–1.6), from the NIST SP 800-145 and ISO/IEC 17788 definitions and the roles in a cloud arrangement, through the reference architecture and its deployment models, the security concepts cloud changes, the design principles that make a deployment defensible, evaluating a provider against criteria you set first, and the artificial intelligence objective new in the 2026 outline.
CCSP Domain 2: Cloud Data Security
The heaviest domain on the exam and the one that carries the most marks: all nine objectives (2.1–2.9), covering the cloud data lifecycle and data dispersion, storage architectures and the threats specific to each, encryption, tokenization, hashing, DLP and obfuscation, discovery and classification, information rights management, retention, deletion and legal hold, auditability and non-repudiation, and the new objective on protecting AI and ML data.
CCSP Domain 3: Cloud Platform and Infrastructure Security
The platform your workloads sit on: all five objectives (3.1–3.5), from the infrastructure components and the management plane that creates and controls every one of them, through secure data center design and the redundancy notation that gets misquoted, risk identification, analysis and treatment, the selection and implementation of security controls, and business continuity and disaster recovery planning that is measured rather than assumed.
CCSP Domain 4: Cloud Application Security
Building software that survives contact with a shared platform: all seven objectives (4.1–4.7), from training and the vulnerability catalogs the outline names by title, through the secure SDLC and the four threat modeling methodologies, assurance and validation testing, verifying software you did not write, cloud application architecture, and identity and access management.
CCSP Domain 5: Cloud Security Operations
Running it, every day: all six objectives (5.1–5.6), from building the physical and logical infrastructure and operating it safely, through the twelve service management processes and the standards behind them, digital forensics when the media belongs to somebody else, communication with regulators, customers and providers, and the security operations that hold it all together.
CCSP Domain 6: Legal, Risk and Compliance
The domain that decides whether everything else is enforceable: all five objectives (6.1–6.5), from conflicting international legislation and eDiscovery, through privacy requirements and impact assessments, audit reports and what they actually cover, enterprise risk management and the five data roles, and the contract design that substitutes for the control you no longer hold.
Not sure yet? Start with the one that costs nothing.
Domain 1 is free in full: all 82pages, the same PDF paying customers download. Read it, and you'll know whether the other four are for you.