NetApp writes the questions as scenarios, which means you are handed a situation and asked what to do about it. This guide walks through all eight domains in weighting order, what each one genuinely asks you to configure, what the netapp cyber resiliency certification costs, how long it stays valid, and a preparation sequence built around where the marks actually are.
What Is the NetApp Cyber Resiliency Certification?
NS0-950 leads to the NetApp Certified Cyber Resiliency Expert credential, known as NCCRE. It tests whether you can protect ONTAP data against attack and get it back afterwards, across eight domains covering ransomware protection, disaster recovery, backup, governance, encryption, identity, zero trust and day-to-day troubleshooting. The paper runs 60 questions in 90 minutes and costs $250.
NetApp aims it at people with roughly six to twelve months of real cyber resilience work behind them. That is a deliberately narrow band. It rules out someone who has only read about immutable snapshots, and it does not demand a decade either. What it assumes is that you have configured this material on a live cluster, argued about retention policy with somebody, and had at least one recovery go sideways.
The credential sits alongside the NetApp Certified AI Expert as one of the two expert level exams in the programme. Both carry a higher fee than the associate and professional tiers for that reason.
“The exam consists of scenario-based questions that require architectural knowledge, as well as creating preventive measures and action plans for attacks to the IT infrastructure.”
That sentence is the whole exam in one line. Scenario-based, architectural, and action-oriented. If your preparation consists of memorising which command creates a SnapMirror relationship, you have prepared for a different paper.
Where Do the 60 Marks Actually Sit?
The eight NS0-950 domains are weighted 18, 7, 9, 12, 18, 13, 13 and 10 percent. Ransomware protection and detection and Cyber security: Common issues tie for the largest at 18 percent each, which puts 36 percent of the paper in those two alone. Disaster recovery is the smallest at 7 percent. That spread should drive your study calendar more than any other single fact about this exam.
| Domain | Weight | Roughly how many of the 60 questions |
|---|---|---|
| Ransomware protection and detection | 18% | 11 |
| Cyber security: Common issues | 18% | 11 |
| Cybersecurity: Encryption | 13% | 8 |
| Cybersecurity: Identity and Access Management | 13% | 8 |
| Governance and compliance | 12% | 7 |
| Cybersecurity: Zero Trust | 10% | 6 |
| Backup | 9% | 5 |
| Disaster recovery | 7% | 4 |
Read that table sideways and a different shape appears. Four of the eight domain titles begin with the word cyber or cybersecurity, and together those four are worth 54 percent. The three classic data protection domains, backup, disaster recovery and governance, come to 28 percent between them. This is a security exam that happens to run on storage, not a storage exam with a security chapter bolted on.
There is a practical consequence for anyone coming from a pure ONTAP administration background. The parts you already know well are the parts worth least.
What Does the Ransomware Domain Ask You to Configure?
Domain 1 is worth 18 percent and covers six things: recovering from a ransomware attack, configuring immutable or indelible backups, configuring autonomous ransomware protection, configuring and monitoring ransomware detection alerts, configuring tamperproof snapshots, and configuring Data Infrastructure Insights SWS. Every one is a configuration task, not a definition.
Notice how the objectives are ordered. Recovery comes first, before any of the preventive controls. That is not accidental. NetApp is signalling that the credential is about what happens after the alert fires, and the scenarios reflect it.
Immutability is the concept the domain keeps returning to
Immutable backups and tamperproof snapshots are separate objectives, but they answer the same question: can an attacker who has already reached your storage layer delete the copy you plan to restore from. Understand the retention mechanics well enough to explain what an administrator with full privileges can and cannot remove, because that distinction is where the scenarios get interesting.
Autonomous ransomware protection sits on the detection side. It is worth knowing not just how to turn it on, but what it watches for, what it does when it sees it, and what a false positive costs you operationally. A scenario that describes unusual entropy in a volume is asking whether you can tell a legitimate workload change from an encryption event.
Detection alerts and Data Infrastructure Insights SWS round out the domain. Both are monitoring objectives, and both tend to be underprepared, because they sit in a console many candidates only open when something is already wrong.
Why Is Common Issues Worth as Much as Ransomware?
Domain 5, Cyber security: Common issues, is also worth 18 percent and is the broadest domain on the paper. It spans seven objectives: identifying replication failures to a DR or vault destination, remediating IAM authentication failures, using Active IQ to find and fix CVEs, monitoring syslog and audit logs, hardening the storage system, deploying encryption at rest and in flight, and monitoring capacity and SnapMirror relationships.
It is essentially a troubleshooting domain, and it deliberately overlaps the others. An authentication failure question could sit in the identity domain. An encryption deployment question could sit in the encryption domain. Here they are framed as things that have broken.
That reframing is why the domain is hard. Knowing how to configure something and knowing why it stopped working are different skills, and the second one is much harder to fake. Storage hardening in particular rewards candidates who have worked through a real baseline rather than read a checklist. The NIST storage security guidelines are a useful frame of reference for what hardening a storage estate is supposed to achieve, even though the exam tests it in NetApp’s own terms.
- Replication that silently stops is a recurring scenario shape, so know what breaks a SnapMirror relationship and what the monitoring shows before it fails outright
- Active IQ is the named tool for CVE remediation, so treat it as examinable rather than optional
- Syslog and audit log monitoring appears here and again in the zero trust domain, which makes it one of the better returns on study time
How Much of NS0-950 Is Encryption, IAM and Zero Trust?
Encryption at 13 percent, identity and access management at 13 percent, and zero trust at 10 percent add up to 36 percent of NS0-950. Together they are worth exactly as much as ransomware and common issues combined, which makes them the second major block of the paper and far too large to treat as a supporting topic.

Encryption is about key management as much as ciphers
The encryption objectives are practical: set up an onboard or external key manager, configure NAE, NVE and NSE self-encrypting drives for encryption at rest, configure data-at-rest encryption, decide when to use encryption with FabricPool, and use cluster peering encryption. The recurring decision is which mechanism fits which situation, so build a mental table of aggregate level, volume level and drive level protection and what each one actually defends against.
Identity work is mostly multifactor and directory integration
The IAM domain asks for multifactor authentication on SSH and the service processor, multifactor for System Manager using SAML or WebAuthn, local accounts under role-based access control, a domain access tunnel for Active Directory accounts, IAM and MFA deployed for management access, and LDAP configuration. Two different multifactor objectives on two different access paths is a strong hint that the scenarios will ask you to pick the right one.
Zero trust is small but very specific
Only three objectives sit under zero trust: multi-admin verification groups and rules, native file auditing or auditing through an external FPolicy server, and sending all audit logs to a remote syslog server. Multi-admin verification is the standout, because it is the control that answers the insider threat question directly. It is a small domain with a low chance of surprises, so it is a reasonable place to earn easy marks late in your preparation.
What Do Backup, Disaster Recovery and Compliance Cover?
Backup is 9 percent, disaster recovery 7 percent and governance and compliance 12 percent, so the three traditional data protection domains carry 28 percent of NS0-950 between them. These are the areas an experienced ONTAP administrator will find most familiar, which makes them the fastest to revise and the easiest to over-study.
Backup covers Snapshot schedules, testing and verifying backup data, SnapMirror and SnapVault configuration and policies, and one very specific objective about the monitoring differences between a SnapMirror mirror policy and a SnapMirror vault policy. That last one is the kind of detail that separates people who have read the documentation from people who have watched both run.
Disaster recovery is the smallest domain on the paper and has just three objectives: architecting and configuring replication for DR, configuring a cyber vault, and recovering data from Snapshot copies. The cyber vault objective is the interesting one, because it is where disaster recovery and ransomware response meet.
Governance and compliance asks you to find unprotected data, configure encryption, classify data, and use Secure Purge to shred data securely. Data classification and secure destruction are the two objectives that most often catch out candidates from an operations background, since they are compliance driven rather than availability driven. If you want a wider view of how the NetApp protection credentials interlock, the NS0-528 data protection track covers much of the same ground at implementation level.
What Does NS0-950 Cost and What Score Do You Need?
NS0-950 costs $250 and requires 75 percent to pass, which is 45 correct answers out of 60. It runs for 90 minutes through Pearson VUE, giving you an average of 90 seconds per question. The resulting NCCRE credential is valid for two years from the date it is granted.
| Detail | Value |
|---|---|
| Exam code | NS0-950 |
| Credential | NetApp Certified Cyber Resiliency Expert (NCCRE) |
| Questions | 60 |
| Duration | 90 minutes |
| Passing score | 75% |
| Cost | $250 USD |
| Delivery | Pearson VUE |
| Validity | 2 years |
The $250 fee is worth understanding in context. Most NetApp exams are priced at $200, with the FlexPod exams at $300 and the expert level exams at $250. NS0-950 sits in that top tier alongside the AI Expert exam, so the fee reflects the level rather than the subject.
The two-year validity is set out in NetApp’s certification programme policies, and it applies to the whole programme rather than to this exam specifically. Miss the renewal window and the certification expires rather than lapsing into a grace period, so put the date somewhere you will see it.
On the 90 second average: that is comfortable for a recall question and tight for a scenario that describes a broken replication relationship across three paragraphs. Pacing matters more here than the raw time budget suggests.
Where Does NCCRE Sit in the NetApp Certification Path?
NCCRE is one of two expert level NetApp credentials, the other being the NetApp Certified AI Expert. NetApp states no prerequisite certification for NS0-950, so you can sit it without holding NCDA or an NCIE credential first. What it does assume is six to twelve months of hands-on cyber resilience experience, which is a practical prerequisite rather than a paper one.
In practice most candidates arrive from one of two directions. Storage administrators come up through data administration and implementation engineering, and find the security half of the syllabus unfamiliar. Security engineers arrive with the threat model already in their heads and have to learn ONTAP’s specific mechanics. The first group usually needs longer.
The credential’s closest neighbour is the implementation engineer data protection specialist track, which shares the SnapMirror, SnapVault and recovery material but stops short of the encryption, identity and zero trust content. If you already hold that one, roughly a quarter of NS0-950 will feel like revision. Detail on what the expert level assumes is set out on NetApp’s own cyber resiliency exam overview.
On the career side, cyber resilience responsibility is increasingly attached to existing storage roles rather than split into a separate job title, and pay for those roles varies widely by region and seniority. Current benchmarks for storage engineer compensation give a reasonable floor to reason from, with security responsibility generally sitting above it.
How Should You Prepare for a Scenario-Based Expert Exam?
Prepare in weighting order, not syllabus order. Ransomware protection and common issues are worth 36 percent between them and take the longest to make automatic, so they go first. Encryption, identity and zero trust follow at 36 percent combined. Backup, disaster recovery and governance come last, because they are both the smallest block and the most familiar.

- Start with ransomware protection and detection, working through immutable backups, tamperproof snapshots and autonomous ransomware protection on a real cluster rather than on paper, because 18 percent of the paper depends on knowing how these behave rather than what they are called.
- Move straight to cyber security common issues while the same systems are still in front of you, deliberately breaking a replication relationship and an authentication path so you have seen what the failure actually looks like.
- Take encryption next, building a clear mental map of NAE, NVE and NSE and of when each one is the right answer, since the scenarios turn on choosing between them rather than on configuring any single one.
- Cover identity and access management immediately after encryption, because the key manager work and the multifactor work share the same access paths and revising them together saves time.
- Add zero trust as a short focused block, concentrating on multi-admin verification, native file auditing and remote syslog, which is only three objectives and the cheapest 10 percent on the paper.
- Finish with backup, disaster recovery and governance and compliance, treating them as revision rather than new learning if you already administer ONTAP day to day.
- Sit at least two full timed papers at 60 questions in 90 minutes, capping any single scenario at three minutes so one long question cannot take the ending away from you.
One habit is worth more than any resource here. When you read an objective that begins “given a scenario”, stop and write down the scenario yourself before you study the answer. The exam is testing whether you can recognise a situation, and you cannot practise recognition by reading conclusions.
A run through a realistic NCCRE practice exam is the cheapest way to find out whether your pacing survives contact with a three-paragraph question. For a broader look at how candidates approach this credential, the NS0-950 preparation overview is a useful companion.
Frequently Asked Questions
How many questions are on the NS0-950 exam?
NS0-950 contains 60 questions and runs for 90 minutes. NetApp notes that the format is subject to change, so confirm the current figures when you book. The average pace works out at 90 seconds per question, which is tight for longer scenarios.
What score do you need to pass NS0-950?
The passing score is 75 percent, which means 45 correct answers out of 60. There is no partial credit structure published, so treat every domain as capable of costing you the pass on its own.
How much does the NetApp cyber resiliency certification cost?
The exam costs $250 USD. That is the expert level price in NetApp’s programme, above the $200 standard rate and below the $300 charged for the FlexPod exams. Regional pricing and taxes may differ.
Is there a prerequisite certification for NCCRE?
No certification is required beforehand. NetApp recommends six to twelve months of technical experience in cyber resilience, including architectural work and hands-on management of secure environments, but that is guidance rather than a gate.
Which NS0-950 domain is worth the most?
Two domains tie at 18 percent: ransomware protection and detection, and cyber security common issues. Between them they carry 36 percent of the paper, so they deserve the first and largest share of study time.
How long is the NCCRE credential valid?
Two years from the date it is granted. NetApp Learning Services applies the same two-year window across its certification programme, and a credential that is not renewed inside that period expires rather than entering a grace period.
Are the NS0-950 questions hands-on or multiple choice?
They are scenario-based questions rather than a live lab. You are given a situation and asked for architectural judgement, preventive measures or a remediation action, which is closer to a design review than to a command syntax test.
Does NS0-950 cover more security or more storage?
Security, clearly. The four domains carrying cyber or cybersecurity in their titles are worth 54 percent, while backup, disaster recovery and governance together account for 28 percent.
How long does preparation usually take?
It depends on where you start. Storage administrators without a security background generally need longer than security engineers learning ONTAP mechanics, because the exam’s largest domains sit on the security side of the syllabus.
Is NCCRE worth it for a storage administrator?
It is worth it if ransomware resilience has become part of your remit, since the syllabus maps closely onto that work. If your role is purely capacity and performance, the security-heavy weighting will not reflect what you do daily.
Conclusion
NS0-950 is not a storage exam with a security section. Fifty four percent of it carries a cybersecurity label, two domains take 36 percent between them, and every objective is written as something you configure or diagnose rather than something you recall. Prepare in weighting order, spend your longest block on ransomware protection and on the troubleshooting domain, and treat the familiar backup and recovery material as revision rather than a starting point. Sixty questions in 90 minutes leaves no room to think slowly about a scenario you have never seen. Work the eight domains against a real cluster, time yourself against realistic scenario questions, and book the exam once your pacing holds.
