iSecPrep https://www.isecprep.com/ Your Guide to IT Certification Success Thu, 10 Sep 2026 03:12:03 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 Zscaler Digital Transformation Engineer: Twelve Wrong Answers https://www.isecprep.com/2026/09/10/zscaler-digital-transformation-engineer-zdte-exam-guide/ Thu, 10 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87749 Sixty questions, ninety minutes, and a pass mark of eighty percent. That allowance works out at twelve wrong answers, on a paper where nearly every objective hands you a situation instead of asking you to recall a fact.

The post Zscaler Digital Transformation Engineer: Twelve Wrong Answers appeared first on iSecPrep.

]]>

Read the ZDTE objectives end to end and one phrase appears more than any other. Given a scenario. Given a set of user groups. Given a network topology. Given a sample PAC file.

Almost nothing on this blueprint asks you to recall a fact. The Zscaler Digital Transformation Engineer exam, code ZDTE, hands you a situation and asks what you would do about it, across six weighted domains covering ZIA, ZPA, ZDX and the Client Connector. It runs 60 questions in 90 minutes at 300 US dollars, and the pass mark is 80 percent, which is the highest of any exam covered on this site this month. That combination of scenario phrasing and a high threshold is what makes it an engineer exam rather than an administrator one, and it changes what preparation has to look like.

What Does the Zscaler Digital Transformation Engineer Exam Test?

ZDTE tests advanced configuration of the Zscaler zero trust platform across six domains: architecture and design, implementation and deployment, operations and monitoring, troubleshooting and support, security and compliance, and automation and optimisation. Zscaler frames it around platform services, security services, data protection and the management and logging layer.

The underlying design question runs through every domain. Traffic that used to be inspected at a perimeter now has to reach a cloud service instead, and the exam is largely about how you get it there and prove it arrived.

“Legacy SASE was built in the post-pandemic rush, based on a firewall and VPN model for a network perimeter that no longer exists.”

Jay Chaudhry, Founder, Chairman and CEO of Zscaler

That framing is not vendor-specific. The architecture it describes is set out in the NIST publication on zero trust architecture, and the Cloud Security Alliance maintains a broader body of zero trust research covering the same principles the Zscaler platform implements. Reading one of them first makes several ZDTE objectives read as consequences rather than as product trivia.

What Are the ZDTE Exam Details?

ZDTE is 60 questions in 90 minutes with an 80 percent passing score, priced at 300 US dollars per attempt and scheduled through Pearson VUE as an online proctored exam. Zscaler sets no strict prerequisites but recommends a minimum of one year on the platform, with hands-on time across ZIA, ZPA and ZDX.

The four Zscaler services on the ZDTE blueprint: ZIA for internet traffic and policy, ZPA for private app access, ZDX for user experience probes and ZCC as the device agent
Field Value
Exam name Zscaler Digital Transformation Engineer
Exam code ZDTE
Questions 60
Duration 90 minutes
Passing score 80%
Price $300 USD, one credit per attempt
Delivery Online proctored, Pearson VUE
Prerequisites None strict; one year of platform experience recommended
Published domains 6, weighted, totalling 100%

An 80 percent threshold on a 60 question paper means 48 correct answers. Twelve wrong is the entire margin, and on an exam where most items are scenarios rather than recall, twelve is not many. That single figure is the strongest argument for lab time over reading.

What Zscaler recommends before booking

There are no mandatory prerequisites, but the vendor is unusually specific about preparation. Zscaler highly recommends completing the Zscaler for Users Engineer eLearning course and its hands-on lab, and it names ZIA, ZPA and ZDX individually when describing the year of experience it expects. Both recommendations are published on the Zscaler Academy page for the credential.

How Are the Six ZDTE Domains Weighted?

Architecture and design and implementation and deployment carry 22 percent each, so together they are 44 percent of the paper. Operations and monitoring takes 16 percent, troubleshooting and support 15 percent, security and compliance 14 percent, and automation and optimisation 11 percent. No domain dominates, and none is small enough to skip.

Domain Weight What it is really about
Architecture and Design 22% Choosing forwarding methods, designing PAC deployments, sizing App Connectors, least privilege policy design
Implementation and Deployment 22% Locations and sublocations, URL and CloudApp filtering, DLP and DNS policies, App Segments, log streaming to a SIEM
Operations and Monitoring 16% Reading ZIA, ZPA and ZDX dashboards, interpreting audit logs, acting on insights and DLP incident reports
Troubleshooting and Support 15% Finding mismatched PAC logic and identifying where a block policy stopped legitimate access
Security and Compliance 14% Policy containment: configuring it, monitoring it, and taking corrective action
Automation and Optimization 11% Optimising PAC file logic, scoping API key permissions minimally, increasing efficiency through automation

The flat distribution is itself informative. On an exam where the largest domain is 22 percent and the smallest is 11, there is no domain you can trade away and still clear 80 percent. Security and compliance is worth noticing for the opposite reason: it carries 14 percent of the paper on a single published objective about policy containment, which makes it unusually dense.

Because the whole blueprint is scenario-shaped, the most efficient calibration is to answer questions in that shape rather than to re-read the domain list. Working ZDTE sample questions shows quickly whether your platform habits match what the exam considers correct.

Why Do So Many ZDTE Objectives Start With a Scenario?

Almost every ZDTE objective is written as a situation plus a task. Given globally dispersed users, design a PAC deployment. Given a user’s location and bandwidth and the sizing chart, identify the right App Connector configuration. Given a critical service outage, identify how machine learning capabilities aid root cause analysis. The phrasing is a deliberate signal about how the questions are built.

Two consequences follow. First, memorising configuration steps will not carry you, because the exam supplies the requirement and expects you to select the design that meets it. Second, several objectives hand you an artefact to interpret: a dashboard graphic, an audit log, a PAC file, a DLP incident report, a script. Reading those under time pressure is a distinct skill from configuring the platform.

The objectives that are not scenarios

A handful begin “Identify the steps”, covering application discovery configuration, ZPA access policies with posture checks and conditional rules, and consolidating application segments into segment groups. These are the closest the exam comes to procedural recall, and they are worth learning precisely because they are the exception.

Which Zscaler Services Does the Exam Cover?

Four services run through the blueprint: Zscaler Internet Access, Zscaler Private Access, Zscaler Digital Experience and the Zscaler Client Connector. The operations domain requires you to interpret a dashboard from each of the first three, and the architecture domain asks you to choose between connectivity methods that span all four.

Service Where it appears in the blueprint Typical exam task
ZIA Architecture, implementation, operations, troubleshooting Choose a forwarding method, build URL, CloudApp, firewall and DLP policy, read the dashboard, resolve an insight
ZPA Architecture, implementation, operations, troubleshooting Build App Segments and Segment Groups, deploy an App Connector, apply posture checks, find where access was blocked
ZDX Architecture, implementation, operations Place probes to isolate a slow application, set alert thresholds, read the dashboard
ZCC Architecture, implementation, operations Configure profile and update management, monitor connectivity and act on what it shows

The ZDX material is the one candidates most often underestimate. Its objectives are about diagnosis rather than security: given a user complaining that an application is slow, work out whether the problem is the user’s own resources, the organisation’s network, or the application itself. That is a different mental model from policy work, and it appears in three of the six domains.

Log streaming sits slightly apart. Two objectives cover choosing which Zscaler log fields to send to a SIEM through the Nanolog Streaming Service and the Log Streaming Service, which is a data-selection question rather than a security one.

What Does ZDTE Expect You to Know About PAC Files?

PAC files appear in four separate places on this blueprint. Design a PAC deployment strategy for globally dispersed users. Identify a correct PAC file for a stated goal. Investigate a PAC file for mismatched logic when some users cannot reach an application. Optimise the logic of a supplied PAC file. Few other topics recur that often.

PAC files appear in four ZDTE objectives: design the rollout, build the file, debug a bad rule and tune the logic

That repetition is the clearest study signal on the exam. A candidate who can read a proxy auto-configuration file line by line, spot an ordering problem, and rewrite it more efficiently has covered material worth marks in the architecture, implementation, troubleshooting and automation domains at once.

The troubleshooting framing matters as much as the syntax. The objective describes specific locations or user types failing to reach some internet applications, which is a symptom pattern rather than an error message. Working backwards from that symptom to a condition in the file is what the question is testing.

How Should You Prepare for the ZDTE Exam?

An 80 percent pass mark on a scenario-based paper rewards platform time rather than reading time. Zscaler recommends a year of hands-on experience and its own engineer-level eLearning with a lab, and the preparation order below follows the weightings while front-loading the topics that recur across several domains.

  1. Start with the two 22 percent domains together, because architecture decisions and the deployments that implement them are examined as the same skill in different words.
  2. Work PAC files until you can read one line by line, spot an ordering fault and rewrite it more efficiently, since they appear in four separate objectives.
  3. Build and break an App Segment, then a Segment Group, then an access policy with device posture checks, so the ZPA objectives that ask for steps are muscle memory.
  4. Spend real time in the ZDX dashboards, practising the diagnosis of whether a slow application is the user, the network or the application itself.
  5. Configure a DLP policy and a DNS security policy end to end, then read the resulting incident report as the operations domain expects.
  6. Decide which log fields you would stream to a SIEM for a given investigation, covering both the Nanolog Streaming Service and the Log Streaming Service.
  7. Scope an API key to the minimum permissions a specific script needs, which is the automation domain’s most concrete objective.
  8. Sit timed practice at 90 seconds a question and track how many you get wrong, because 12 is the entire margin at 80 percent.

Registration, the proctoring requirements and the recommended learning path all sit on the Zscaler exam registration page, and it is worth reading the notes there before booking a slot.

If you are mapping out more than one exam, the Zscaler certification track collects the platform’s credentials in one place.

Is ZDTE the Right Exam to Take After ZDTA?

For most engineers, yes, but not immediately. ZDTA covers administration of the platform and ZDTE covers advanced configuration and design of it. Zscaler sets no formal prerequisite between them, so the honest gate is the year of hands-on experience it recommends rather than the earlier certificate.

The difference shows up in the verbs. An administrator exam asks how to configure something. This one gives you a requirement and asks which configuration meets it, then asks you to find the fault when it does not. Someone who has passed the administrator exam but only ever worked in ZIA will find the ZPA and ZDX domains genuinely unfamiliar.

A useful self-test before booking: can you size an App Connector from a user’s location and bandwidth, and can you tell from a ZDX probe whether a slow application is the network’s fault? If either answer is no, more platform time is a better investment than an exam booking. Our ZDTA administrator exam guide covers the tier below in the same detail.

Frequently Asked Questions

How many questions are on the ZDTE exam?

60 questions in 90 minutes, which is 90 seconds each. Most items are scenario-based rather than recall, so the artefact-reading questions take longer and the straightforward ones have to be quicker.

What is the passing score for the Zscaler Digital Transformation Engineer exam?

80 percent, which on a 60 question paper means 48 correct answers. Twelve wrong is the whole margin, and that is the highest threshold of any exam covered here this month.

How much does ZDTE cost?

300 US dollars per attempt, priced by Zscaler as one credit. The exam is delivered online with a proctor rather than requiring a test centre appointment.

Are there prerequisites for ZDTE?

No strict prerequisites. Zscaler highly recommends completing its engineer-level eLearning courses and hands-on lab first, and expects a minimum of one year of experience across ZIA, ZPA and ZDX.

Which ZDTE domain carries the most weight?

Architecture and design and implementation and deployment tie at 22 percent each, so together they are 44 percent of the paper. Automation and optimisation is the smallest at 11 percent.

Does ZDTE cover ZDX as well as ZIA and ZPA?

Yes. ZDX appears in three of the six domains, covering probe placement, alert thresholds and dashboard interpretation, and it is the area administrators who work mainly in ZIA tend to underestimate.

How important are PAC files on the exam?

Very. PAC files appear in four separate objectives spanning design, implementation, troubleshooting and optimisation, which makes them the single highest-value topic on the blueprint.

What is the difference between ZDTA and ZDTE?

ZDTA covers platform administration. ZDTE covers advanced configuration and design, including sizing, least privilege policy design, log streaming and automation. There is no formal prerequisite between them.

Is the ZDTE exam proctored online?

Yes. Zscaler describes it as an online proctored exam and recommends the same year of platform experience regardless of where a candidate sits it.

Does the exam test automation and scripting?

Automation and optimisation is 11 percent of the paper. Its objectives cover optimising PAC file logic, scoping an API key to the minimum permissions a script needs, and identifying where automation improves efficiency.

Conclusion

Two numbers should shape how you approach this exam. Eighty percent, which allows twelve wrong answers out of sixty. And four, the number of separate objectives that involve a PAC file.

Everything else follows from the scenario phrasing. The blueprint hands you requirements and artefacts and asks for a decision, so preparation that consists of reading the objectives will leave you fluent in the vocabulary and unpractised at the task. Spend the time in the platform instead: design a forwarding strategy for dispersed users, size an App Connector from real numbers, build a segment and an access policy with posture checks, and use ZDX to decide whether a slow application is the network’s fault. Then work timed questions in the same shape and count the ones you get wrong, because twelve is the entire allowance and finding that out in practice is much cheaper than finding it out on the day.

Rating: 0 / 5 (0 votes)

The post Zscaler Digital Transformation Engineer: Twelve Wrong Answers appeared first on iSecPrep.

]]>
Cohesity Multicloud Certification: Where the 60 Questions Go https://www.isecprep.com/2026/09/10/cohesity-multicloud-certification-coh150-exam-weights/ Thu, 10 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87741 The COH150 weightings look like odd numbers until you multiply them by 60. Every domain lands on a whole count of questions, and two of the six hold 28 of them. That arithmetic decides where the study time should go long before CloudArchive or CloudSpin do.

The post Cohesity Multicloud Certification: Where the 60 Questions Go appeared first on iSecPrep.

]]>

21.67 percent. 8.33 percent. Those are two of the six domain weightings Cohesity publishes for COH150, and they are not rounded marketing figures.

They are fractions of a 60 question paper. Multiply them out and every domain lands on a whole number of questions: 13, 12, 6, 9, 5 and 15. That arithmetic turns a vague list of percentages into a study plan, because it tells you that cloud migration is worth five questions and deployment considerations is worth fifteen. The Cohesity Protection Associate Multicloud exam, code COH150, is a 90 minute sitting with a 58 percent pass mark, and it is the associate credential for running Cohesity across AWS, Azure and Google Cloud rather than inside your own racks. This walkthrough sets out where the questions sit, what separates CloudArchive from CloudTier and CloudSpin, and how the Cohesity multicloud certification differs from the DataProtect exam most people meet first.

What Does the Cohesity Multicloud Certification Test?

COH150 tests whether you can deploy, operate and monitor the Cohesity Data Cloud platform in and with public cloud environments. Six published domains cover cloud concepts, archiving, tiering, cloud-native backup, workload migration and deployment prerequisites. The scope is cloud behaviour specifically, not general backup administration, which the DataProtect exam handles.

Cohesity exam map showing COH100 core backup, COH125 file services, COH150 cloud and archive, and COH350 security exams

The distinction matters because the two exams share a vendor and a tier but almost no content. An engineer who protects virtual machines competently in a data centre still has to learn how a Cohesity cluster changes when it runs natively in a cloud provider, which external targets CloudArchive supports, and what has to exist in a subscription before any of it works.

Cohesity positions the credential inside the cloud resilience story it now sells against, and its own product leadership describes that estate in the same terms the syllabus uses.

“Our partnership with Google Cloud has delivered critical innovation for customers modernizing backup, disaster recovery, and cyber resilience across hybrid multi-cloud environments.”

Vasu Murthy, chief product officer, Cohesity

Two of the six domains, cloud concepts and deployment considerations, are about judgement rather than clicks. They ask which delivery model suits a requirement, when archiving beats tiering, and what a public cloud subscription must already provide. The federal guidance on recovering from destructive events is a useful frame for that half of the paper, because clean recovery is the outcome every cloud feature in the syllabus exists to support.

What Are the COH150 Exam Details?

COH150 is 60 questions in 90 minutes with a 58 percent passing score and a 200 US dollar fee. There are no prerequisite exams. Registration runs through Cohesity, the exam is delivered in English, and the credential carries the full title Cohesity Certified Protection Associate Multicloud on the Cohesity Certified Associate track.

Field Value
Exam name Cohesity Protection Associate Multicloud
Exam number COH150
Questions 60
Duration 90 minutes
Passing score 58%
Fee $200 USD
Prerequisites None
Registration Cohesity
Published domains 6, weighted, totalling 100%

Ninety minutes for 60 questions gives you 90 seconds each, which is comfortable for recall and tight for anything that needs working out. Several objectives are explicitly scenario-shaped, including one that hands you a graphic and asks how Self-Service completes pre-provisioning steps and another that asks you to infer whether a policy will apply to a virtual machine. Those cost more than 90 seconds, so the recall questions have to cost less.

What happens after you pass

Cohesity issues a digital badge and the certification stays valid for two years. A failed attempt can be retaken once every 14 days, so a near miss is a fortnight of focused revision rather than a lost year. Cohesity asks for no coursework before booking but recommends six to nine months of hands-on time, and it is worth reading that recommendation as a warning about the scenario questions rather than a formality. All of this is published on the Cohesity Academy exam page.

How Many Questions Does Each COH150 Domain Carry?

Cohesity publishes six weightings that sum to 100 percent, and because the paper is exactly 60 questions each weighting converts to a whole number of items. Deployment considerations is the largest at 15 questions, cloud concepts follows at 13, and cloud migration is the smallest at 5. Those counts are arithmetic from the published percentages, not a separate Cohesity statement.

Domain Published weight Questions out of 60
Deployment Considerations 25% 15
Cohesity Cloud Concepts 21.67% 13
Archiving with Cohesity 20% 12
Cloud-native backups with Cohesity 15% 9
Tiering with Cohesity 10% 6
Cloud migration with Cohesity 8.33% 5

Read the table as a budget. Deployment considerations and cloud concepts together account for 28 of the 60 questions, so almost half the paper is decided before you touch archiving, tiering or migration. A candidate who studies the features and skips the prerequisites has capped their score at roughly 53 percent, which is below the pass mark.

The bottom two rows are the ones to keep in proportion. Tiering and migration are 11 questions between them, and they are the topics engineers find most interesting, which is exactly why they absorb study time out of all proportion to their value. Working through COH150 scenario questions in the exam’s own format is the quickest way to see whether your effort is landing where the marks are.

Why Is Deployment Considerations the Largest Domain?

Deployment considerations carries 25 percent, or 15 questions, because it holds everything that has to be true before a cloud feature works at all. Its objectives cover the storage classes CloudArchive supports, the prerequisites for configuring CloudArchive with each public cloud provider, the requirements for running Cohesity natively in AWS, Azure and Google Cloud, cloud source registration, and which SaaS applications the platform can protect.

That is a deliberately unglamorous list, and it is the biggest single block of marks on the exam.

The hybrid question hiding in this domain

One objective asks you to identify the additional features available when Cohesity is deployed both on premises and in the cloud. It is easy to skim, and it is the domain’s most examinable idea. Several capabilities only exist once both halves are present, so a candidate who has only ever seen one deployment shape has a genuine blind spot rather than a gap in recall.

Registration is not configuration

Registering a cloud source and configuring an external target are separate operations with separate prerequisites, and the syllabus lists them separately. Confusing the two is the fastest way to lose marks in this domain, because the questions are precise about which one a given requirement calls for.

CloudArchive, CloudTier and CloudSpin: What Is the Difference?

The three features solve different problems. CloudArchive copies data to cloud storage for long term retention and recovery. CloudTier moves cold blocks off the cluster to free local capacity while keeping the data addressable. CloudSpin clones or moves virtual machines into a public cloud so they can run there. Together they account for 23 of the 60 questions.

Feature What it does Why you would use it Domain weight
CloudArchive Writes copies to an external cloud target for retention Long term retention and disaster recovery, with CloudRetrieve for the recovery path and CloudArchive Direct as a configuration option 20%
CloudTier Moves cold data blocks off local storage Reclaiming cluster capacity without deleting anything or losing addressability 10%
CloudSpin Clones or moves virtual machines into a public cloud Running a workload in the cloud, and spinning up development or test clones from a backup 8.33%

The examinable line runs between archiving and tiering, and the syllabus names it directly: one objective asks you to identify the difference. Archiving produces an additional copy for retention. Tiering relocates the only copy of cold blocks to reclaim space. Answer a tiering question with archiving logic and you will pick a plausible wrong option every time.

CloudSpin is the odd one out because it is not really a protection feature. It uses a backup as the source for a running machine, which is why the same objective set covers both disaster recovery and development clones. Cohesity’s own CloudArchive documentation is worth reading alongside the syllabus, because the external target options it lists are exactly what the deployment domain expects you to recognise.

All three sit on top of assumptions the exam does not stop to teach. Recovery point and recovery time objectives, the vocabulary of disaster recovery planning, run underneath every question about which feature suits a requirement.

How Does Cohesity Run Natively in AWS, Azure and Google Cloud?

The cloud-native backups domain carries 15 percent, or nine questions, and it treats a cloud-resident cluster as a different animal from an on premises one. Its objectives cover configuring Cohesity for native operation in AWS, Azure or Google Cloud, the ways cloud networking differs from data centre networking for that cluster, and which cloud-native backup operations are supported.

The networking objective is stated as a difference rather than as a topic, which is a hint about how it will be asked. You are not being tested on cloud networking in general. You are being tested on what changes for a Cohesity cluster when its network is defined by a provider rather than by your switches.

Supported operations matter just as much as configuration. Cloud-native protection is not simply the on premises feature set pointed at a different location, and questions in this domain reward knowing where the boundary sits. SaaS application protection is scoped in the deployment domain instead, which is worth noting because candidates often expect it here.

How Should You Prepare for the COH150 Exam?

Preparation should follow the weightings rather than the interest curve. Two domains hold 28 of the 60 questions and neither is feature-led, so the study order that matches the exam starts with prerequisites and concepts and reaches CloudSpin last. Cohesity recommends six to nine months of hands-on experience and sets no mandatory coursework.

COH150 study order in four steps: cloud setup first, then concepts, then archive targets and recovery, then tiering and cloning last
  1. Convert the six published weightings into question counts before planning anything, so you know deployment considerations is worth 15 questions and cloud migration is worth 5.
  2. Start with deployment considerations, learning the cloud storage classes CloudArchive supports and the prerequisites each public cloud provider imposes.
  3. Work through cloud concepts next, focusing on the delivery models, the archiving against tiering distinction, and the features that only appear in a hybrid deployment.
  4. Study archiving as a workflow rather than a feature, covering external targets, CloudRetrieve recovery, CloudArchive Direct configuration and the recovery options available to an organisation that relies on it.
  5. Separate tiering from archiving deliberately, because one relocates cold blocks to reclaim capacity and the other writes an extra copy for retention.
  6. Practise a cloud-native deployment in at least one provider, paying attention to how the cluster’s networking differs from an on premises install.
  7. Leave CloudSpin until last and treat it as two use cases, moving a workload to the cloud and cloning it for development or test.
  8. Sit timed practice at 90 seconds a question so the scenario items do not run you out of clock.

The Cohesity certification track is a useful map if you are planning more than one exam, because the associate tier feeds the specialist and expert credentials above it.

Should You Sit COH100 or COH150 First?

Neither exam requires the other, so the honest answer is that it depends on your estate. COH100 covers Cohesity DataProtect and the core backup and recovery workflow. COH150 covers cloud behaviour: archiving, tiering, cloud-native deployment and migration. Both sit at associate level on the same track and both carry no prerequisites.

Pick COH150 first if your Cohesity footprint already reaches into a public cloud, or if the work in front of you is an archive target, a capacity problem or a migration. Pick COH100 first if you are learning the platform itself, because the cloud exam assumes you already know what a protection job and a recovery look like even though it does not test them.

There is a practical argument for taking both in one study cycle. The two syllabi barely overlap, so the second exam adds new material rather than revision, and the shared platform knowledge carries across. Our COH100 exam breakdown sets out the DataProtect side in the same detail as this article covers the multicloud side.

Frequently Asked Questions

How many questions are on the COH150 exam?

COH150 has 60 questions and a 90 minute time limit, which works out at 90 seconds per question. Several objectives are scenario-shaped and will take longer, so the recall items need to be answered quickly.

What is the passing score for the Cohesity multicloud certification?

58 percent. Cohesity publishes the same figure on its own academy page as the NWExam syllabus page carries, and it applies to the single 90 minute sitting with no separately scored sections.

How much does COH150 cost?

200 US dollars per attempt. Registration goes through Cohesity rather than a third-party storefront, and a retake is permitted once every 14 days if the first attempt falls short.

Are there prerequisites for COH150?

None. Cohesity requires no prior exam or certification and no mandatory coursework, though it recommends six to nine months of on-the-job experience with the platform before booking.

How long does the Cohesity Protection Associate Multicloud certification last?

Two years. Cohesity states the expiration plainly on its certification page, and a digital badge is issued through Credly when you pass.

Which COH150 domain carries the most questions?

Deployment Considerations at 25 percent, which is 15 of the 60 questions. It covers cloud storage classes, provider prerequisites, cloud source registration, hybrid-only features and SaaS application protection.

What is the difference between CloudArchive and CloudTier?

CloudArchive writes an additional copy to an external cloud target for long term retention. CloudTier relocates cold data blocks off the cluster to reclaim local capacity while keeping them addressable. The syllabus asks you to distinguish them directly.

Does COH150 test SaaS application protection?

Yes, but inside the Deployment Considerations domain rather than the cloud-native backups domain. One objective asks you to identify which SaaS applications the Cohesity platform can protect.

Is COH150 harder than COH100?

They are peers rather than tiers, both at associate level with no prerequisites. COH150 is narrower and more cloud-specific, so it feels harder to an engineer who has only worked on premises and easier to one who has not.

In what language is COH150 delivered?

English only. Cohesity lists a single language on the exam page, alongside the 14 day retake window and the two year expiration.

Conclusion

The most useful fact about COH150 is the one hiding in its odd percentages. Six weightings, 60 questions, and every domain landing on a whole number of items: 15, 13, 12, 9, 6 and 5.

That arithmetic should drive the whole study plan. Deployment considerations and cloud concepts hold 28 of the 60 questions between them, and both are about prerequisites and judgement rather than features, so a candidate who starts with CloudSpin because it is the interesting one has already put their effort in the wrong place. Learn what has to exist in a subscription before anything works, get the archiving against tiering distinction clean enough to answer under time pressure, and leave migration until the end where its five questions belong. Cohesity recommends six to nine months of hands-on time, and the scenario objectives are the reason. Once the weightings are mapped, timed practice in the exam’s own question format is what turns a reading list into a pass.

Rating: 0 / 5 (0 votes)

The post Cohesity Multicloud Certification: Where the 60 Questions Go appeared first on iSecPrep.

]]>
CREST Certified Red Team Specialist: Two Exams, Four Sections, One Result https://www.isecprep.com/2026/09/09/crest-certified-red-team-specialist-exam-structure/ Wed, 09 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87683 Almost every summary of this credential quotes sixty questions in sixty minutes. That is one of four marked sections. CCRTS is six hours across two sittings, worth 480 marks, with four separate pass marks and no partial credit for clearing three of them.

The post CREST Certified Red Team Specialist: Two Exams, Four Sections, One Result appeared first on iSecPrep.

]]>

Search for this credential and you will be told, repeatedly, that it is a sixty minute exam with sixty questions and a two thirds pass mark. Those numbers are real. They describe one of four marked sections.

The CREST Certified Red Team Specialist exam is two separate sittings of three hours each. A written exam splits into a one hour multiple-choice test and a two hour written scenario. A practical exam splits into a red team assault course and a section on operational security and tradecraft, the second of which is scored automatically from whether the defenders caught you. Four sections, 480 marks in total, four separate pass marks, and failing one fails the part it sits in. This walkthrough sets out the real structure, the marking, the eight syllabus areas, and what the exam environment actually gives you to work with.

What Does the CREST Certified Red Team Specialist Exam Involve?

The CREST Certified Red Team Specialist exam has two distinct parts. A written exam of three hours, containing a one hour multiple-choice test and a two hour written scenario, and a practical exam of three hours, containing a red team assault course and an operational security and tradecraft section. Candidates may sit them in either order, though CREST suggests starting with the written.

The four CCRTS marked sections with their marks and pass marks across the written and practical exams

Before either sitting, candidates are given a threat intelligence pack. It carries the background of the target, the scenario context, the threat actor being emulated, the goals of the engagement, and usable data such as tactics, techniques and procedures, domains and user names. That pack is not scene setting. It is the brief you are assessed against, because the whole assessment is built on simulating a specific adversary rather than demonstrating generic attack skill.

The practical labs are built per candidate. Each is a unique instance, constructed and verified before it is presented, and every answer is marked automatically. There is no examiner watching you work and no partial credit for an approach that did not land.

What Are the Real CCRTS Exam Details?

CCRTS runs to six hours of assessment across two sittings, with an additional 15 minutes of reading time before the written scenario and another 15 before the practical exam. There are no prerequisites. The exam is listed at 400 US dollars and results are delivered through Pearson VUE, and the syllabus is published as eight areas with no weightings attached to any of them.

Field Value
Exam name CREST Certified Red Team Specialist
Exam code CCRTS
Written exam 3 hours: multiple-choice test 1 hour, written scenario 2 hours
Practical exam 3 hours: assault course and tradecraft sections
Reading time 15 minutes before the written scenario, 15 before the practical
Total marks 480 across four sections
Prerequisites None
Listed price $400
Results platform Pearson VUE

The written exam is closed book, and that applies to both of its components. No books, no notes, no internet access, no electronic devices. Someone used to writing engagement reports with documentation open in a second window should treat the two hour scenario as the harder half of that sitting for exactly this reason.

The practical exam works differently. Files can be pre-uploaded through CRESTDrive ahead of the day and are available inside the environment, so tooling you rely on does not have to be rebuilt under time pressure. Two virtual machines are provided for familiarisation beforehand, one running Kali Linux and one running Windows, and a licensed copy of Proxifier is available in the exam environment. CREST publishes all of this on its own CCRTS certification page, and it is worth reading the notes for candidates in full before booking.

If you want to calibrate against the multiple-choice component specifically, working CCRTS sample questions is the cheapest way to find the gaps in the breadth the syllabus expects.

How Is the Written Exam Marked?

The written exam carries 180 marks. The multiple-choice test is worth 60 and requires at least two thirds, meaning 40 marks. The written scenario is worth 120 and also requires at least two thirds, meaning 80 marks. Passing one component while failing the other results in failure of the written exam overall.

Section Part Marks Pass mark
Multiple-choice test Written 60 40 (two thirds)
Written scenario Written 120 80 (two thirds)
Red team assault course Practical 180 120 (two thirds)
Tactics, tradecraft and operational security Practical 120 60 (one half)

The ordering inside the written exam is fixed even though the ordering between the two exams is not. Candidates must start with the multiple-choice test and then move to the written scenario, though questions can be answered in any order within each component.

What the scenario component is really testing

Two hours and 120 marks is a lot of weight for a written piece, and it sits at twice the value of the multiple-choice test. The syllabus areas that feed it are the ones that have nothing to do with running a tool: scoping, risk, record keeping and reporting, threat intelligence interpretation, and client communications. This is the section that separates a red teamer from an operator.

When you find out

Multiple-choice results appear at the end of the sitting in your Pearson VUE account, with a breakdown by area showing how you performed in each. The written scenario is marked by hand, so that result and the overall written outcome arrive within 20 days. Practical results are usually available within 24 hours and occasionally up to 48 where additional verification is needed.

What Happens in the Practical Exam?

The practical exam runs three hours and carries 300 marks across two sections. The red team assault course is worth 180 and asks the candidate to compromise an enterprise environment along an attack path informed by the threat intelligence pack. The tactics, tradecraft and operational security section is worth 120 and is scored on detection results rather than on completed objectives.

What the CCRTS practical exam environment provides: Kali and Windows familiarisation machines, licensed Proxifier and CRESTDrive uploads

That second sentence is the important one, because it means the two sections can pull against each other. The assault course rewards progress. The tradecraft section rewards not being seen making it. A candidate who kicks doors down efficiently can pass the first and fail the second, and failing one section fails the practical exam overall.

The environment supports a realistic approach rather than a lab one. Each instance is unique and built for that candidate, files can be pre-uploaded, and the familiarisation machines let you confirm your tooling works with the versions available before the clock starts. All marking is automatic, so an approach that was conceptually right but did not produce the artefact scores nothing.

In practice, this means preparation has to include operating quietly under time pressure, not just operating. Rehearsing a full engagement end to end, with throttled traffic and deliberate choices about which detections to trigger, matters more than rehearsing individual techniques.

Why Does the Tradecraft Section Use a Lower Pass Mark?

The tactics, tradecraft and operational security section requires only half its 120 marks to pass, against two thirds on the other three sections. The marks are auto calculated from detection results, so the threshold reflects a reality of adversary simulation: a competent red team is detected sometimes, and the exam is measuring restraint rather than invisibility.

Reading it as a soft option would be a mistake. Half of 120 is still 60 marks earned by not being caught, in an environment instrumented to catch you, while simultaneously making enough progress to clear 120 of 180 on the assault course. The lower threshold acknowledges that the two objectives conflict.

The syllabus is candid about what is being assessed here. It talks about limiting opportunities for detection while also providing detection opportunities in line with the simulation’s threat intelligence, which is a more sophisticated goal than pure stealth. A red team emulating a noisy actor should be noisy in that actor’s way. This is where the syllabus expects fluency in adversary tactics and techniques as a map of behaviour rather than as a checklist of tools, alongside the cyber kill chain phases that structure an engagement.

What Do the Eight Syllabus Areas Cover?

CREST publishes the CCRTS syllabus as eight areas with no weightings: Soft Skills and Assessment Management, Core Technical Skills, Reconnaissance, Implants, Initial Access, Lateral Movement and Privilege Escalation, Evasion, and Egress and Command and Control. The absence of weightings means no area can be treated as optional, and the areas map onto the phases of an engagement rather than onto categories of knowledge.

Syllabus area What it covers
Soft Skills and Assessment Management Law and compliance, scoping, risk, record keeping and reporting, threat intelligence, client communications, operational security, social engineering, physical security, threat modelling
Core Technical Skills Networking, discovery and mapping, cryptography, file system permissions, audit techniques, automation and scripting
Reconnaissance Registration records, DNS, internet reconnaissance, and third party or cloud provider discovery
Implants Implant design and assessment, trojanised file formats, persistence, and physical implants
Initial Access Email and application delivery, supply chain attacks, perimeter attacks, insider threat simulation, remote credential theft
Lateral Movement and Privilege Escalation Active Directory and cloud directory abuse, host and user enumeration, operating system vulnerabilities, software and file enumeration, browser and application exploitation, user interaction
Evasion Host antivirus and endpoint detection evasion, network intrusion detection, perimeter controls, stealth
Egress and Command and Control Reverse communications, tunnelling, attack source obfuscation, secure egress

The first area is the one candidates from a pure testing background tend to underestimate. It is by some distance the largest by sub-topic count, and it is almost entirely non-technical: scoping an engagement properly, measuring the risk of an attack path before taking it, keeping an audit log detailed enough to assist a customer afterwards, and running a communication strategy with defined escalation paths. Those are the skills the two hour written scenario draws on.

The technical areas read as a single engagement in sequence. Reconnaissance produces the target picture, implants and initial access get you in, lateral movement and privilege escalation get you where you need to be, and evasion and egress determine whether any of it survives contact with the defenders.

How Should You Prepare for the CCRTS Exam?

Preparation splits along the same line the exam does. The written exam rewards breadth and the ability to explain a decision in prose without documentation to hand; the practical rewards operating quietly under time pressure in an unfamiliar environment. Preparing for one does very little for the other, so plan two tracks.

  1. Read the eight syllabus areas end to end and mark every sub-topic you have never actually done, because the absence of weightings means no area can be written off as minor.
  2. Start with Soft Skills and Assessment Management, the largest area by sub-topic count and the one that feeds the two hour written scenario, working scoping, risk, reporting and client communications rather than tooling.
  3. Cover the law and compliance material for the regions you work in, including what a letter of authority must contain and when law enforcement notification applies.
  4. Rehearse the technical areas as a single engagement in sequence, from reconnaissance through implants and initial access to lateral movement, rather than as separate techniques.
  5. Practise evasion and egress deliberately against instrumented defences, since the tradecraft section is scored on detection results rather than on objectives completed.
  6. Sit timed written practice closed book, with no notes and no internet, because that is the condition both written components are taken under.
  7. Use the familiarisation virtual machines before exam day to confirm your tooling works with the versions provided, and prepare the files you intend to pre-upload through CRESTDrive.

The iSecPrep CCRTS exam resources page collects the study material for the written half in one place.

Who the Credential Is Aimed At

CCRTS has no prerequisites, which is unusual for an assessment of this shape and does not mean it is an entry point. The exam assumes a candidate who has already compromised enterprise environments professionally, because three hours is not long enough to learn the assault course while sitting it.

The credential fits a specific transition: a penetration tester moving into adversary simulation. Those are different jobs. Testing finds and proves vulnerabilities against a scoped target list. Red teaming emulates a named threat actor to measure whether an organisation’s protective and detective controls actually work, which is why the marking scheme cares as much about whether you were seen as about what you reached.

That difference also explains the weight given to the non-technical area. A red team engagement produces a judgement about an organisation’s defensive posture, and that judgement has to be communicated to people who were not in the room.

Frequently Asked Questions

How long is the CCRTS exam?

Six hours of assessment across two sittings: a three hour written exam and a three hour practical exam, plus 15 minutes of reading time before the written scenario and another 15 before the practical.

Is the CCRTS exam really 60 questions in 60 minutes?

No. That describes the multiple-choice test, which is one of four marked sections and worth 60 of the 480 marks available. The written scenario, assault course and tradecraft sections carry the rest.

What is the pass mark for CCRTS?

Two thirds on the multiple-choice test, the written scenario and the assault course, and one half on the tactics, tradecraft and operational security section. Failing one section fails the part it sits in.

Can I take the practical exam before the written one?

Yes. CREST allows either order and suggests starting with the written exam. Within the written exam the order is fixed: multiple choice first, then the scenario.

Are there prerequisites for CCRTS?

None. CREST states plainly that there are no prerequisites, though the practical exam assumes professional experience compromising enterprise environments rather than lab familiarity.

Is the CCRTS written exam open book?

No. Both written components are closed book, with no books, written notes, internet access or other electronic devices permitted.

How is the tradecraft section scored?

Automatically, from detection results. The marks reflect how visible your activity was to the instrumented defences rather than how many objectives you completed.

How quickly do CCRTS results arrive?

Multiple-choice results appear at the end of that sitting with an area breakdown. The written scenario and overall written result take up to 20 days. Practical results usually arrive within 24 hours and occasionally take 48.

What tooling is available in the practical exam?

Familiarisation machines running Kali Linux and Windows, a licensed copy of Proxifier in the exam environment, and any files you pre-upload through CRESTDrive before the day.

Does CREST publish weightings for the CCRTS syllabus?

No. Eight areas are published with no percentages attached, which means preparation has to cover all of them rather than being ranked by importance.

Conclusion

The most useful thing to know about CCRTS is the thing most summaries leave out: it is six hours across four separately marked sections, and clearing three of them is a fail. The multiple-choice test that dominates search results is the smallest of the four.

That shape should drive preparation. The written scenario carries twice the marks of the multiple-choice test and draws almost entirely on scoping, risk, reporting and communication rather than tooling. The practical exam asks you to make real progress while staying quiet enough to earn 60 marks from detection results. Read the eight syllabus areas honestly, work the non-technical area first because it is the largest, and rehearse full engagements rather than individual techniques. Sample questions in the multiple-choice format are the fastest way to find where the breadth is thin. If you are still deciding where CCRTS sits against the testing and threat intelligence tracks, the CREST certification hub is the place to start.

Rating: 0 / 5 (0 votes)

The post CREST Certified Red Team Specialist: Two Exams, Four Sections, One Result appeared first on iSecPrep.

]]>
What the SAFe Product Owner Product Manager Certification Now Expects https://www.isecprep.com/2026/09/09/safe-product-owner-product-manager-certification-explained/ Wed, 09 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87675 Six weighted domains, one of them entirely about AI, and a pass mark of 82 percent that leaves room to lose eight questions out of 45. This walkthrough takes the POPM blueprint domain by domain and explains why Iteration Execution alone is worth nearly a third of the paper.

The post What the SAFe Product Owner Product Manager Certification Now Expects appeared first on iSecPrep.

]]>

One of the six domains on the current POPM blueprint is about artificial intelligence. Not as a footnote inside another topic, but as a named domain worth 12 to 14 percent of the paper, sitting alongside PI Planning and Iteration Execution as an equal. Almost nothing written about this credential mentions it.

That single change tells you the SAFe Product Owner Product Manager certification has moved. It is still a foundational credential, still 45 questions in 90 minutes, still scored at a demanding 82 percent. What has shifted is the definition of competent. Scaled Agile now expects a product owner to reason about prompting, model risk and where automation belongs in a backlog conversation, and it tests that expectation with the same weight it gives the roles and responsibilities domain. This walkthrough takes all six domains in turn, explains what the weighting pattern is really telling you, and sets out how to revise for a paper where a third of the marks sit in one place.

What Does the SAFe Product Owner Product Manager Certification Actually Test?

The SAFe Product Owner Product Manager certification tests six weighted domains: roles and responsibilities at 12 to 14 percent, PI Planning Preparation at 17 to 19 percent, Leadership for PI Planning at 14 to 16 percent, Iteration Execution at 28 to 30 percent, PI Execution at 10 to 12 percent, and Apply AI to Product Roles at 12 to 14 percent. Passing awards the Certified SAFe Product Owner/Product Manager credential.

Read the six names in order and a shape appears. The first domain establishes who you are inside the framework. The next two prepare and then run the planning event. The fourth covers the fortnightly rhythm that follows it. The fifth covers the quarter as a whole. The sixth cuts across all of them.

That ordering is not decorative. Scaled Agile has built the exam around a single Program Increment, walked through from the moment someone starts drafting a vision to the moment the increment is inspected and adapted. Every objective attaches to a point in that cycle. If you can place yourself in the cycle, you can usually place the question.

Domain Weight What it covers
Understanding Product Owner/Product Management Roles and Responsibilities 12-14% Applying SAFe to the two roles, the Lean-Agile mindset, value streams, and the responsibilities each role carries
PI Planning Preparation 17-19% Summarising PI Planning, the solution vision, forecasting through roadmaps, planning features, managing the ART backlog and Kanban
Leadership for PI Planning 14-16% Communicating the vision in the event, planning PI objectives, organising dependencies, analysing risks
Iteration Execution 28-30% Creating stories, planning an iteration, managing flow with the team Kanban, refining the backlog, the review and retrospective, supporting DevOps and Release on Demand
PI Execution 10-12% The PO Sync, the system demo, innovation through the increment, and Inspect and Adapt
Apply AI to Product Roles 12-14% AI basics and terminology, prompting, risks and responsible use, and augmenting the product roles with AI

The weightings are published as ranges rather than fixed figures, which means the exact split varies between forms of the paper. Treat the midpoint as your planning number and the top of each range as your risk.

What Are the POPM Exam Details?

The POPM exam runs 90 minutes and carries 45 questions with a passing score of 82 percent. Items are either multiple choice with one correct answer or multiple select taking two or three. The first attempt is included in the course registration fee when it is taken within 30 days of course completion; each retake, or any attempt after that window, costs 50 US dollars.

Field Value
Exam name SAFe Product Owner/Product Manager
Exam code POPM
Questions 45
Duration 90 minutes
Passing score 82%
Format Multiple choice (one answer) or multiple select (2-3 answers)
First attempt Included in the course fee within 30 days of course completion
Retake or late attempt $50 each

Two of those numbers deserve more attention than they usually get. The first is the pass mark. At 82 percent you can afford to lose eight questions out of 45 and no more, which is unusually tight for a foundational credential and leaves no room for a domain you decided to skim. The second is the pace. Ninety minutes across 45 items gives you two minutes each, which sounds generous until you meet a multiple select item that asks you to pick two of five plausible options.

Scaled Agile sells the proctored exam separately from the course, and its own POPM credential page states plainly that the training certification course is not required, so an experienced product owner can sit the paper on the strength of practical work. Whether that is wise is a different question, and the weighting pattern below suggests it depends entirely on how much iteration level work you have actually done. Working through POPM sample questions before committing is the cheapest way to find out where you stand.

Why Does Iteration Execution Carry Nearly a Third of the Paper?

Iteration Execution is worth 28 to 30 percent of the POPM exam, more than twice the weight of PI Execution and roughly double any other single domain. It covers creating stories, planning an iteration, managing flow with the team Kanban, refining the team backlog, participating in the review and retrospective, and supporting DevOps and Release on Demand.

The reason is simple arithmetic about how a product owner spends a quarter. PI Planning happens once. The iteration cycle happens five or six times inside the same period, and everything a product owner does between planning events lives there. Scaled Agile has weighted the exam to match the calendar rather than the ceremony.

Story writing carries more marks than it looks

Creating stories is the first objective in the domain and the one candidates most often underestimate, usually because they have written hundreds of stories and assume the topic is settled. The exam is not asking whether you can write one. It is asking whether you can distinguish a story from an enabler, size it in a way that supports forecasting, and recognise when acceptance criteria have quietly become a specification.

Flow management is the technical half

Managing flow with the team Kanban and refining the backlog are the objectives where the domain gets genuinely difficult. You need to know what work in progress limits do to throughput, why a bottleneck moves when you relieve it, and how backlog refinement feeds the next iteration rather than the current one.

DevOps sits inside this domain, not beside it

Supporting DevOps and Release on Demand is the last objective in Iteration Execution, which surprises people who expect release topics to sit with PI Execution. The placement is deliberate. Release on Demand only works if the iteration produces something releasable, so the framework treats it as an iteration level responsibility rather than a quarterly one.

What Does the New AI Domain Actually Ask For?

Apply AI to Product Roles is worth 12 to 14 percent of the POPM exam and carries four objectives: understanding AI basics and terminology, understanding AI prompting, understanding risks and responsible AI use, and augmenting the product roles with AI. It is weighted the same as the roles and responsibilities domain, which makes it a full domain rather than an addendum.

The scope is narrower than the name suggests, and that is good news for anyone worried they need a machine learning background. Nothing in the objectives asks you to build, train or evaluate a model. The domain is about a product owner working alongside these tools competently and safely.

  • Terminology means being able to use the vocabulary correctly in a planning conversation rather than defining it academically.
  • Prompting is treated as a practical skill: framing a request so the output is usable for backlog, roadmap or research work.
  • Risks and responsible use is the objective with the most examinable substance, covering where output cannot be trusted, what must not be pasted into a tool, and who remains accountable for a decision.
  • Augmenting the product roles asks where in the existing responsibilities these tools genuinely help, and by implication where they do not.

Scaled Agile positions the current credential explicitly around integrating AI into product work, so this domain is not a temporary addition that will quietly disappear from the next revision. If your preparation material predates it, the material is out of date rather than merely incomplete.

How Much of the POPM Exam Is PI Planning?

PI Planning accounts for 31 to 35 percent of the POPM exam once its two domains are combined: PI Planning Preparation at 17 to 19 percent and Leadership for PI Planning at 14 to 16 percent. Split across preparation and facilitation, the planning event is the single largest theme on the paper, narrowly ahead of Iteration Execution.

The four stage Program Increment cycle the SAFe POPM exam is built around: prepare, plan, execute and inspect

Splitting one event into two domains is the clearest structural signal in the whole blueprint. Scaled Agile is separating the work you do beforehand from the work you do in the room, and testing them differently.

Preparation is about artefacts

The preparation domain covers summarising PI Planning, explaining the solution vision, forecasting work through roadmaps, planning features, and managing the ART backlog and Kanban. Every one of those produces something tangible before the event starts. A vision that has not been written cannot be communicated, and a backlog that has not been ordered cannot be planned against.

Leadership is about the room

The leadership domain covers communicating the vision during the event, planning PI objectives, organising and managing dependencies, and analysing risks. These are live activities under time pressure with multiple teams present. The exam tests whether you know what a good PI objective looks like, how dependencies get surfaced rather than discovered later, and what actually happens to a risk once it is raised. Scaled Agile documents the full event structure in its own PI Planning guidance, which is worth reading against the objectives rather than instead of them.

PI Execution, by contrast, is only 10 to 12 percent. Four objectives covering the PO Sync, the system demo, innovation and Inspect and Adapt. It is the lightest domain on the paper, which tells you Scaled Agile considers the quarter mostly decided by how well it was planned and how well the iterations ran.

Product Owner or Product Manager: Which Role Does This Credential Serve?

POPM certifies both roles with one exam, which is why the first domain is called Understanding Product Owner/Product Management Roles and Responsibilities. In SAFe the product owner works at team level with the team backlog and stories, while the product manager works at Agile Release Train level with the ART backlog and features. The exam expects you to know which responsibility belongs where.

SAFe product owner and product manager compared by team scope, backlog ownership and planning horizon

This is the distinction candidates most often lose marks on, because outside SAFe the two titles are frequently used interchangeably or merged into one job. Inside the framework they are separate roles operating at different altitudes on different artefacts.

Dimension Product Owner Product Manager
Operates at Agile team Agile Release Train
Owns Team backlog ART backlog
Primary artefact Stories Features
Planning horizon Iteration Program Increment and roadmap
Main forum Iteration planning, review, retrospective PI Planning, system demo

Both roles share the Lean-Agile mindset the first domain tests, and both are ultimately traceable back to the principles set out in the Agile Manifesto. What differs is scope. A question that mentions a team backlog is a product owner question; one that mentions features or a roadmap is usually a product manager question. Reading for that signal first resolves a surprising number of items.

What Does the Weighting Pattern Say About Study Order?

The weighting pattern points to a clear revision order for the POPM exam: Iteration Execution first at 28 to 30 percent, then the two PI Planning domains at a combined 31 to 35 percent, then the AI domain and roles domain at 12 to 14 percent each, and PI Execution last at 10 to 12 percent. Roughly six questions in ten come from Iteration Execution and PI Planning combined.

There is a second, less obvious reading. The three lightest domains, roles, AI and PI Execution, together account for between 34 and 40 percent of the paper, which is more than any single heavy domain. Skipping all three because they are individually small would cost you the exam outright at an 82 percent pass mark.

A more useful way to think about it is confidence per hour. Iteration Execution rewards study time because it is dense and practical. The roles domain rewards it because the distinctions are crisp and testable. The AI domain rewards it disproportionately right now, simply because most candidates arrive with material that does not cover it. PI Execution is the one place where a light pass is defensible, and even then only if you have actually sat through a system demo and an Inspect and Adapt event.

How Should You Prepare for the POPM Exam?

Preparation for the POPM exam works best in the order the framework itself runs, because the blueprint is organised as one Program Increment from vision to Inspect and Adapt. Working the domains in calendar order rather than weighting order builds a mental timeline that makes questions easier to place, then a second pass weighted by marks fixes the gaps.

  1. Read all six domain names and their weightings in one sitting before opening any study material, so you know from the start that Iteration Execution and PI Planning between them decide the result.
  2. Work the roles domain first and write down, in your own words, which artefacts belong to the product owner and which to the product manager, because that distinction reappears inside every later domain.
  3. Walk the two PI Planning domains as a single event, separating what you would prepare beforehand from what you would do in the room, and make sure you can state what a good PI objective looks like.
  4. Spend the largest block of time on Iteration Execution, covering story writing, iteration planning, team Kanban and flow, backlog refinement, the review and retrospective, and how Release on Demand depends on the iteration producing something releasable.
  5. Cover the AI domain deliberately rather than assuming general familiarity is enough, focusing on responsible use and on where these tools genuinely augment product work.
  6. Finish with PI Execution, rehearsing the PO Sync, the system demo and Inspect and Adapt as events you would run rather than definitions you would recite.
  7. Sit timed practice at 45 questions in 90 minutes until you are comfortably above 82 percent, paying attention to multiple select items where partial knowledge scores nothing.

The iSecPrep POPM exam resources collect the practice material for that final timed step in one place.

Where the POPM Credential Leads

POPM sits at the Foundational level of the SAFe programme and is aimed at people new to the framework rather than at experienced SAFe practitioners. It is the credential most organisations ask for when they move a product owner or business analyst onto an Agile Release Train, and it is usually the first SAFe qualification someone earns.

The practical value is less about the certificate than about the shared vocabulary. Once a train is running, the cost of one person using PI objectives to mean something different from everyone else is measured in a whole planning event. That is the problem this credential is bought to solve.

On compensation, the honest position is that the credential rarely moves a salary on its own. Product owner pay tracks seniority, domain and location far more than certification, and reported product owner salaries vary widely for exactly those reasons. What POPM does reliably is qualify you for roles that list it as a requirement, which in SAFe adopting organisations is a large share of them.

Frequently Asked Questions

How many questions are on the POPM exam?

Forty five questions in 90 minutes. That is two minutes per item, which is comfortable for single answer questions and tight for multiple select items asking you to choose two or three options from five.

What is the passing score for the SAFe Product Owner Product Manager certification?

82 percent. At 45 questions that leaves room to lose eight items and no more, which is why skipping a small domain is a poor strategy on this particular paper.

How much does the POPM exam cost?

The first attempt is included in the course registration fee if you sit it within 30 days of finishing the course. Every retake, and any attempt after that 30 day window closes, costs 50 US dollars.

Which domain is worth the most marks?

Iteration Execution, at 28 to 30 percent. It is the only single domain worth more than a quarter of the paper, and it covers story writing, iteration planning, team Kanban, backlog refinement, the review and retrospective, and Release on Demand.

Does the POPM exam really cover artificial intelligence?

Yes. Apply AI to Product Roles is a full domain worth 12 to 14 percent, covering AI basics and terminology, prompting, risks and responsible use, and augmenting the product roles. No model building is required.

Do you have to take the course before sitting the exam?

No. Scaled Agile states on its own credential page that the training certification course is not required, and the proctored exam can be purchased separately. The course does include the first attempt, which is why most candidates take it.

What is the difference between the product owner and product manager roles in SAFe?

The product owner works at team level, owning the team backlog and stories across an iteration. The product manager works at Agile Release Train level, owning the ART backlog and features across a Program Increment and roadmap.

What format are POPM questions in?

Multiple choice with one correct answer, or multiple select requiring two or three correct answers. There is no partial credit on multiple select items, so a half remembered answer scores the same as a wrong one.

Is POPM a beginner credential?

Scaled Agile positions it at Foundational level for people new to SAFe. That describes framework experience rather than product experience, so experienced product owners new to SAFe are exactly the intended audience.

How much of the exam is PI Planning?

Between 31 and 35 percent once both planning domains are counted: PI Planning Preparation at 17 to 19 percent and Leadership for PI Planning at 14 to 16 percent. It is the largest single theme on the paper.

Conclusion

The POPM blueprint is unusually honest about where a product owner’s time actually goes. Iteration Execution takes the largest share because iterations happen five or six times a quarter, the two PI Planning domains take the next largest because everything downstream depends on that event, and the newest domain reflects a role that has genuinely changed.

Two numbers should shape your revision. Eighty two percent means no domain is safe to skip, and 28 to 30 percent means Iteration Execution is where the paper is won. Build your study plan around the Program Increment rather than around a list of topics, then confirm you are clearing the pass mark under real time pressure. Sample questions in the exam’s own format are the fastest way to find out whether the plan is working before you pay for an attempt. If you are still choosing between this credential and the Scrum Master or Practitioner routes, the SAFe certification hub lays those tracks out side by side.

Rating: 0 / 5 (0 votes)

The post What the SAFe Product Owner Product Manager Certification Now Expects appeared first on iSecPrep.

]]>
Most Docker Certified Associate Questions Are Not Multiple Choice https://www.isecprep.com/2026/09/08/docker-certified-associate-dca-exam/ Tue, 08 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87624 Forty two of the 55 items on this paper arrive one option at a time, with no list to compare and no way back. Underneath that format sit six weighted domains, a quarter of them orchestration, and Kubernetes objects named in three of them. Here is what the DCA blueprint really contains.

The post Most Docker Certified Associate Questions Are Not Multiple Choice appeared first on iSecPrep.

]]>

Thirteen. That is how many of the 55 questions on this paper are ordinary multiple choice. The other 42 arrive one option at a time, each one accepted or rejected on its own, with no list to compare and no way back to a choice you have already made.

Almost everything written about the Docker Certified Associate concentrates on that format and stops there. It is genuinely the most unusual thing about the exam, but it is not the only thing worth knowing before booking. Six weighted domains sit underneath it, a quarter of the paper is orchestration, and a surprising amount of the blueprint is not about Docker at all. This walkthrough covers the format, the weighting and what each domain actually expects you to have done.

What Is the Docker Certified Associate?

The Docker Certified Associate is the entry level container platform credential now administered by Mirantis, earned by passing a single 55 question exam in 90 minutes. It covers six weighted domains: orchestration, image creation and registry work, installation and configuration, networking, security, and storage and volumes. Mirantis positions it as the first exam in a multi tiered certification programme.

It is aimed at practitioners rather than beginners. Mirantis states the exam is designed to validate professionals with a minimum of six to twelve months of Docker experience, and the objectives read that way throughout. There is no domain that explains what a container is. The blueprint starts at the point where you already run them and asks whether you can operate a cluster of them.

The credential is valid for two years and must be updated after that, which is worth factoring into the decision. It is not a permanent badge, and the renewal clock starts the day you pass.

Why Is the DCA Question Format So Unusual?

The DCA is delivered as 13 traditional multiple choice questions and 42 discrete option multiple choice questions, a format usually abbreviated to DOMC. In a DOMC item you are shown one candidate answer at a time and asked whether it is correct. Accept or reject it, and the next one appears. You never see the full option list, and you cannot revisit a decision.

Comparison of ordinary multiple choice against the discrete option multiple choice format used by the Docker Certified Associate exam

That removes the technique most candidates rely on without noticing. On a conventional item you can often reach the right answer by discarding the obviously wrong ones, so a partial understanding still scores. DOMC takes that away deliberately. Each option is judged on its own merits, so you either recognise a correct statement as correct or you do not.

The practical consequence is that half remembered knowledge scores much worse here than it does elsewhere. Knowing that one of four answers involves an overlay network is enough on a conventional paper. Being shown a single statement about overlay network behaviour and having to rule on it is a different test entirely, and it is the test you will sit 42 times.

It also changes how you should rehearse. Practising against option lists trains the wrong reflex, so working through DCA practice questions is most useful when you force yourself to judge each option in isolation rather than scanning for the best of four.

What Are the Docker Certified Associate Exam Details?

The DCA carries 55 questions in 90 minutes and costs 199 US dollars, or 200 euro when purchased online. It is remotely proctored on your own Windows or Mac computer, results are delivered immediately, and it is available globally in English. Mirantis does not publish a passing score for it.

Field Value
Exam name Mirantis Docker Certified Associate (DCA)
Number of questions 55, comprising 13 multiple choice and 42 DOMC
Duration 90 minutes
Passing score Not published by Mirantis
Price 199 US dollars or 200 euro
Delivery Remotely proctored on your own computer, results immediate
Language English
Validity Two years, then an update is required

The missing passing score is not an oversight and it is worth reading carefully. Mirantis states on its official DCA exam page that passing scores are not published because questions and scores are both subject to change without notice. Approximate figures circulate widely on prep sites, and none of them come from the vendor.

Fifty five questions in ninety minutes is about ninety eight seconds an item, which sounds generous. It is less generous than it looks, because a DOMC item can present several options in sequence and each one needs its own judgement. Budget your time per question, not per option.

Booking runs through the Mirantis webstore as a voucher purchase rather than through a third party test centre network, which is why there is no Pearson VUE step in the process.

How Is the DCA Weighted Across Six Domains?

The DCA splits into Orchestration at 25 percent, Image Creation, Management and Registry at 20 percent, Installation and Configuration at 15 percent, Networking at 15 percent, Security at 15 percent, and Storage and Volumes at 10 percent. Orchestration alone is a quarter of the paper, and the top two domains together account for 45 percent.

Domain Weight What it is really about
Orchestration 25% Running a cluster, not a container
Image Creation, Management, and Registry 20% Building, tagging, signing and shipping images
Installation and Configuration 15% Standing the platform up and backing it up
Networking 15% How traffic reaches a container
Security 15% Trust, roles, certificates and scanning
Storage and Volumes 10% Persistence and the layers underneath it

The shape of that table tells you the exam’s opinion of the job. Building images is a fifth of it. Everything else, three quarters of the paper, is about operating the platform those images run on: clustering, installing, networking, securing and storing. This is an operations credential wearing a developer tool’s name.

The 10 percent storage domain is the one candidates consistently underweight, and it is also the one with the most unfamiliar vocabulary. Graph drivers, devicemapper, and the relationship between container storage interface drivers and volume objects are not things most engineers touch weekly.

What Does the Orchestration Domain Ask For?

Orchestration is the largest domain at 25 percent, roughly fourteen questions, and it is built around swarm mode. The objectives cover setting up clusters with manager and worker nodes, understanding quorum, converting deployments using YAML compose files, scaling replicas, placing tasks with node labels, and troubleshooting service deployments that fail.

The distinction between a container and a service is examinable in its own right, and it is the concept everything else in the domain depends on. A service is a declaration of desired state that the cluster maintains; a container is one running instance of it. Questions that look like they are about scaling are usually testing whether you hold that distinction cleanly.

Quorum gets a named objective, which tells you the exam expects you to reason about manager node counts rather than just configure them. Why an even number of managers is a bad idea, and what happens to a cluster that loses it, are the shapes those questions take. Docker’s own swarm mode documentation sets out the raft behaviour underneath that.

Replicated against global, and templates

Two smaller objectives are worth targeted revision because they are easy marks. Replicated services run a specified number of tasks across the cluster; global services run exactly one task on every eligible node. The difference decides the answer to any question about how many instances appear after a node joins. Templates used with service creation are similarly narrow: they let a service definition reference runtime values, and questions about them tend to be recognition rather than construction.

Why Does a Docker Exam Test Kubernetes?

Kubernetes objects appear by name in three of the six DCA domains. Orchestration asks you to deploy containerised workloads as Kubernetes pods and deployments and to supply configuration through configMaps and secrets. Networking asks you to route traffic to pods using ClusterIP and NodePort services. Storage asks you to provision persistent storage to pods using persistentVolumes.

Kubernetes objects named in the Docker Certified Associate blueprint: pods, configMaps, ClusterIP and persistent volumes

That is not a token mention. It reflects the platform this credential was built around, where a single control plane could schedule workloads to either orchestrator, so an administrator was expected to be fluent in both. The exam kept that shape.

For a candidate it means the preparation cannot be swarm only. You need working familiarity with the pod as the unit of scheduling, with how a deployment maintains it, and with the two service types named in the blueprint. The Kubernetes pod documentation is the authoritative description of the object the exam keeps referring to.

The storage half is the least forgiving part of it. Provisioning a persistentVolume to a pod means understanding the chain from a container storage interface driver, through a storageClass, to a persistentVolumeClaim, to the volume the pod actually mounts. The blueprint names all four objects in one line, and questions about them test whether you know which one binds to which.

How Deep Does the Image and Registry Domain Go?

Image Creation, Management and Registry is 20 percent of the paper and the only domain that is genuinely about building rather than operating. It covers Dockerfile instructions by name, creating efficient images, managing them from the command line, inspecting them with filters and formatting, tagging, working with layers, and the full set of registry operations from deployment through to signing.

The Dockerfile objective names specific instructions: add, copy, volumes, expose and entry point. Add against copy is the classic examinable pair, because they look interchangeable and are not. Expose and entry point are similar traps, since both are frequently misunderstood as doing more than they do.

Efficient image creation is listed as its own skill, which points at layer behaviour. How instructions become layers, why ordering changes cache reuse, and what actually reduces final image size are all inside scope. The image format itself is standardised by the Open Container Initiative, which is why the same layer model holds across tools.

Registry work goes further than push and pull. Deploying a registry, authenticating against it, searching it, and signing images are all named, and signing connects directly to the security domain through Docker Content Trust. The two domains are best studied together for that reason.

What Security Work Is Examinable?

Security is 15 percent of the DCA and is administrative rather than theoretical. The objectives cover image signing, default engine and swarm security, mutual TLS, roles, the difference between manager and worker nodes from a security standpoint, external certificates, security scanning, enabling Docker Content Trust, configuring role based access control, and integrating the control plane with LDAP or Active Directory.

Mutual TLS is the concept that ties the cluster together. Swarm nodes authenticate to each other with certificates by default, which is why the manager and worker distinction appears in a security domain as well as an orchestration one. Questions here often test whether you know what is secured out of the box versus what you must configure.

Docker Content Trust is the practical half of image signing, and it is a toggle with consequences. Enabling it changes which images the daemon will run, so a question describing an unexpected pull failure is often a Content Trust question wearing a registry costume.

Role based access control and directory integration round the domain out. Both are configuration tasks rather than concepts, and both reward having clicked through them once rather than having read about them.

Is the Docker Certified Associate Still Active?

Yes. The Docker Certified Associate is currently sold by Mirantis at 199 US dollars and has a live exam page describing its format, validity and recommended experience. Claims that the credential was discontinued when Mirantis acquired Docker Enterprise circulate widely and are contradicted by the vendor’s own working purchase page.

The confusion has a traceable cause. Several older Mirantis URLs that used to describe the certification now return 404, including the paths under the main marketing site, so a link followed from an old article or an aggregator lands on a missing page and looks like a retirement notice. The exam moved, it did not stop.

Two details are worth taking from that. First, verify certification claims against a vendor page that transacts, because a store page with a price on it is harder to misread than a marketing page. Second, the two year validity means anyone holding a DCA from the Docker Inc era has long since needed to renew it, which is a separate question from whether new candidates can sit it.

If you want a sense of how the paper has felt to candidates over time, our earlier piece on DCA exam difficulty covers the experience side rather than the blueprint.

How Should You Prepare for the DCA Exam?

Preparation for the Docker Certified Associate should follow the weighting rather than the blueprint order, because orchestration alone is a quarter of the paper and storage is only a tenth. Build a real swarm first, add the Kubernetes objects the blueprint names, then work outward into images, networking, security and storage.

  1. Stand up a multi node swarm with more than one manager, so quorum behaviour is something you have watched rather than something you have read about.
  2. Convert a compose file into a running stack, then scale replicas, place tasks with node labels, and deliberately break a service deployment so you have seen the failure output.
  3. Deploy the same workload as a Kubernetes pod and deployment, supply its configuration through configMaps and secrets, and expose it with both ClusterIP and NodePort.
  4. Build images by hand until add against copy, expose and entry point are automatic, then push, tag, sign and pull them through a registry you deployed yourself.
  5. Enable Docker Content Trust and configure role based access control, because both change platform behaviour in ways the exam asks you to predict.
  6. Finish with storage, working through volumes, graph drivers and the chain from a storage interface driver to a persistentVolumeClaim, since this is the least familiar vocabulary on the paper.
  7. Rehearse every practice item as a single accept or reject decision rather than a choice between options, so the DOMC format is not new on the day.

That last step matters more than any other piece of advice about this exam. Our older walkthrough on mastering the DCA exam collects the study resources for the domain work itself.

Frequently Asked Questions

How many questions are on the Docker Certified Associate exam?

Fifty five in 90 minutes, made up of 13 traditional multiple choice questions and 42 discrete option multiple choice questions.

What is the passing score for the DCA?

Mirantis does not publish one. Its exam page states that passing scores are not published because questions and scores are subject to change without notice, so any percentage you see quoted elsewhere is not a vendor figure.

What does DOMC mean?

Discrete option multiple choice. You are shown one candidate answer at a time and asked to accept or reject it, without seeing the full option list and without being able to go back to a decision you have made.

How much does the Docker Certified Associate cost?

199 US dollars, or 200 euro when purchased online through the Mirantis webstore.

How long is the DCA valid?

Two years. Mirantis requires the certification to be updated every two years, so the renewal clock starts the day you pass.

Which domain carries the most weight?

Orchestration at 25 percent, followed by Image Creation, Management and Registry at 20 percent. Installation and Configuration, Networking and Security carry 15 percent each, and Storage and Volumes carries 10 percent.

Does the DCA exam cover Kubernetes?

Yes, in three of the six domains. Pods, deployments, configMaps, secrets, ClusterIP and NodePort services and persistentVolumes are all named directly in the published objectives.

How much Docker experience is recommended?

Mirantis states the exam is designed to validate professionals with a minimum of six to twelve months of Docker experience. The blueprint assumes you already run containers in earnest.

Where do you sit the exam?

Remotely, proctored on your own Windows or Mac computer, with results delivered immediately. It is available globally in English.

Is the Docker Certified Associate retired?

No. Mirantis sells it at 199 US dollars and publishes a current exam page. Several older Mirantis URLs about the certification now return 404, which is the most likely source of the retirement claims that circulate.

Conclusion

The Docker Certified Associate is an operations exam with a developer tool’s name and an unusual scoring format. Fifty five questions in 90 minutes, only 13 of them conventional, 199 US dollars, remotely proctored, English only, and valid for two years. Orchestration is a quarter of it, images a fifth, and Kubernetes objects run through three separate domains.

Prepare it by weighting rather than by chapter. Build a real swarm, run the same workload as a pod, sign an image you built through a registry you deployed, and leave storage until the vocabulary is the only thing left to learn. Then practise every question as a single accept or reject decision, because that is the one part of this exam no amount of Docker experience prepares you for.

Rating: 0 / 5 (0 votes)

The post Most Docker Certified Associate Questions Are Not Multiple Choice appeared first on iSecPrep.

]]>
How the BIG-IP DNS Specialist Exam Tests Real GSLB Work https://www.isecprep.com/2026/09/08/big-ip-dns-specialist-exam-f5-302/ Tue, 08 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87617 Exam 302 is the only F5 specialist paper that ships without a single published weighting. Four sections, forty odd sub-points, eighty questions in ninety minutes, and a scaled pass mark of 245 out of 350. Here is what each blueprint section is really asking a BIG-IP DNS administrator to have done.

The post How the BIG-IP DNS Specialist Exam Tests Real GSLB Work appeared first on iSecPrep.

]]>

Four sections, and not one percentage between them. F5 publishes the blueprint for the BIG-IP DNS Specialist exam as Design and Architect, Implement, Test and Troubleshoot, and Operations and Support, then stops. There is no weighting table, no domain worth thirty percent, nothing that tells you which quarter of the paper decides the result.

That silence is useful once you read it correctly. It means no section can be treated as filler and none can be revised into a corner. Eighty questions in ninety minutes, scored out of 350 with 245 to pass, drawn from four bodies of work that a real BIG-IP DNS administrator does in sequence: scope the environment, build it, prove it, then keep it alive. This walkthrough takes the blueprint section by section and explains what each one is actually asking you to have done.

What Does the BIG-IP DNS Specialist Exam Actually Cover?

The BIG-IP DNS Specialist exam covers four sections: Design and Architect, Implement, Test and Troubleshoot, and Operations and Support. Passing exam 302 awards the F5 Certified Technology Specialist, BIG-IP DNS credential. The paper spans requirement gathering, global server load balancing configuration, DNS Express and DNS Cache, packet level diagnosis, and the backup, monitoring and upgrade work that follows a deployment.

Read as a set, those four names describe a lifecycle rather than a syllabus. The first section is the conversation with a customer before anything is built. The second is the build. The third is what happens when the build misbehaves. The fourth is everything after handover. F5 has chosen to test the whole arc rather than only the configuration screens, and that choice shapes every objective underneath.

It also sets the audience. This is not an introductory DNS paper. It assumes you already know what a zone transfer is and moves straight to whether you can predict the performance cost of enabling DNSSEC on a topology load balanced pool. F5 sells the credential as evidence that someone can deliver intelligent DNS and global server load balancing across multiple data centres, and the objectives are written at that level throughout.

What Are the F5 302 Exam Details?

Exam 302 runs for 90 minutes, carries 80 questions, and is scored out of 350 with a passing score of 245. It costs 180 US dollars and is booked through Pearson VUE. F5 delivers it as a test centre proctored exam, and passing it awards the F5 Certified Technology Specialist, BIG-IP DNS certification.

Field Value
Exam name F5 Certified Technology Specialist, BIG-IP DNS
Exam code 302
Number of questions 80
Duration 90 minutes
Passing score 245 out of 350
Price 180 US dollars
Scheduling Pearson VUE, test centre proctored

Eighty questions in ninety minutes leaves roughly sixty seven seconds per item. That is not a paper you reason your way through from first principles. Scenario questions in this exam typically hand you a configuration and a symptom and expect you to recognise the shape of the fault immediately, which is a recall speed problem as much as a knowledge problem.

The scoring scale matters too. A mark of 245 out of 350 is exactly 70 percent of the scale, but F5 reports a scaled score rather than a raw count, so you cannot translate it into a fixed number of correct answers in advance. Working out how many you can afford to lose is wasted effort. Rehearsing against F5 302 practice questions under a timer is a better use of the same hour, because it exposes the sections where your recall is slow rather than absent.

One structural detail is worth knowing before you plan a path. On its official 302 exam page F5 lists this certification as a prerequisite for the Cloud Solutions Expert tracks, so 302 is not a terminal badge. It is a gate into the expert tier for anyone heading that way.

Why Does F5 Publish No Weightings for This Exam?

F5 publishes the 302 blueprint as four named sections with objectives underneath and no percentage attached to any of them. Every other detail is stated openly, including the item count, the duration and the exact pass mark, so the absence is deliberate rather than an oversight. Preparation has to be planned without knowing which section carries the most marks.

The four sections of the F5 302 BIG-IP DNS Specialist blueprint shown as a left to right flow

The practical consequence is that the usual weighting strategy does not work here. On a Cisco or CompTIA paper you can look at a thirty percent domain and decide where the study hours go. On 302 there is no such signal, so the only defensible plan is to cover all four sections to a working depth and let the objective count act as a rough proxy for volume.

By that proxy the four sections are unusually even. Design and Architect carries four objective groups, Implement carries four, Test and Troubleshoot carries four, and Operations and Support carries four. The sub-points run to roughly forty across the whole blueprint, distributed without any obvious concentration. An even blueprint is consistent with an even paper, and until F5 says otherwise that is the safest assumption to prepare against.

There is a second reading, and it is the more useful one. The four sections are not independent topics. You cannot troubleshoot iQuery without having configured self IPs, and you cannot predict upgrade impact without understanding sync groups. The lack of weightings quietly signals that the exam treats the four as one continuous body of work.

What Does the Design and Architect Section Ask For?

Design and Architect asks you to turn a customer situation into a BIG-IP DNS deployment decision. Its four objective groups cover identifying customer requirements and constraints, evaluating an existing DNS environment, choosing a deployment and integration strategy, and determining performance requirements. Almost none of it involves touching a configuration screen.

The requirements objective is explicit that you must recognise the functionality and limitations of the DNS protocol, naming hierarchy and roles as examples, and work out what to ask a customer about high availability, security and management. This is the one place in the blueprint where protocol fundamentals are tested directly, and the protocol itself is defined in RFC 1035, which remains the reference for record types, message format and the resolution path.

Evaluating the existing environment brings in something exams rarely test: change control. The objective asks you to identify the change control procedure related to integrating BIG-IP DNS into an existing environment, alongside scoping the scale of the requirement and recognising limitations imposed by the incumbent DNS provider. That is a consulting skill sitting inside a technical blueprint.

The feature recognition objective is the one to drill

Buried in the deployment strategy objective is a single sub-point that names more product features than any other line in the blueprint. Given a customer environment, requirements and constraints, you are expected to recognise the use case for DNS Express, ZoneRunner, DNS64, DNSSEC, DNS Cache, various load balancing algorithms, persistence and health monitors. Eight features, one question stem, and the skill under test is matching each to the situation it solves.

Performance closes the section. You are asked to relate the characteristics of virtual edition against physical hardware to a use case, to use topology load balancing to improve user experience, and to predict the performance implications of key features. DNSSEC is named as an example, and its signing and validation cost is real: the standard is set out in ICANN’s DNSSEC overview, which explains why validation adds work to every response rather than a one off cost at configuration time.

How Much of the Exam Is Really GSLB?

Global server load balancing is the centre of the Implement section and reaches into all three of the others. Two of the four Implement objectives are GSLB specific, covering pool and virtual server selection tiers, load balancing methods and topology parameters, and a third covers the network conditions GSLB needs before it will work at all. In practice GSLB is the through line of the paper.

The selection tier objective is precise and is worth memorising in its exact shape. You are asked to differentiate between, and decide when to use, the two tiers of GSLB pool selection and the three tiers of virtual server selection. Two and three, not two and two. Candidates who half remember this arrive at a scenario question and pick a plausible wrong answer, because the fallback behaviour at each tier is what the question is really testing.

Load balancing methods are grouped by F5 into static, dynamic and fallback, and the objective asks you to recognise the functionality of each rather than to recite the list. That distinction matters. A question is more likely to describe a traffic outcome and ask which method produced it than to ask what round robin means. F5’s own global server load balancing glossary is the shortest correct summary of the model the exam assumes.

Topology load balancing appears twice, once here as configuration parameters and once in Design as a tool for optimising user experience. Anything the blueprint names twice is worth treating as core, and topology is the clearest example in the 302 objectives.

Which Non-GSLB DNS Components Are Examinable?

The blueprint carries a dedicated objective titled identify configuration options for non-GSLB DNS components, and it names three things: determining the listener IP and protocol, configuring DNS Express, and configuring DNS Cache. These are the parts of BIG-IP DNS that answer queries directly rather than steering clients between data centres, and they are examined separately from GSLB.

F5 302 comparison of GSLB client steering against the DNS services that answer queries directly

Listener configuration is the hinge. Until a listener exists on the right IP with the right protocol, no other DNS feature on the box does anything, which is why the objective leads with it. Candidates who only ever built GSLB in a lab frequently skip listeners entirely, because a wide IP configured through a wizard hides the step.

DNS Express and DNS Cache solve different problems and are easy to confuse under time pressure. DNS Express holds authoritative zone data in memory after a zone transfer so the BIG-IP answers rather than proxies. DNS Cache stores resolved answers so repeat lookups do not travel upstream. One is about being authoritative, the other about being fast for recursion, and a scenario question will describe the symptom rather than name the feature.

The wider configuration of these services is documented in F5’s BIG-IP DNS services documentation, which walks the implementations in the same order the blueprint lists them.

The TMOS objective is quietly a prerequisite

Sitting alongside these is the objective on TMOS and sync groups: creating the correct self IP configuration, routes and settings for iQuery communication, ensuring NTP operates on all sync group members, and creating logging profiles for DNS requests and responses. None of that is DNS work in the ordinary sense. It is the platform plumbing that makes a sync group function, and every later troubleshooting objective assumes you can do it.

NTP is the sleeper item. Sync group members that disagree about the time produce iQuery failures that look like network faults, and the blueprint names NTP explicitly rather than leaving it to be inferred.

Why Does a Whole Section Go to Test and Troubleshoot?

Test and Troubleshoot is one of four sections in a blueprint with no weightings, so on an even reading it is worth as much as building the solution. Its four objectives cover choosing the right diagnostic tool, diagnosing BIG-IP DNS issues, analysing system logs and statistics, and applying a configuration change to resolve what the analysis found. It is the only section that names specific command line tools.

Three tools appear by name. You are expected to use openssl to review trusted certificate information, tcpdump to capture and analyse DNS and iQuery traffic on the appropriate VLAN and IP, and dig or nslookup to verify DNS configuration and operation. The VLAN and IP qualifier on the tcpdump objective is not decorative. Capturing on the wrong interface is the single most common reason a candidate cannot explain what a sync group is doing.

Virtual server flapping appears twice, once as a diagnosis objective and once as a remediation objective, where the fix is described as applying a configuration change such as a monitor or prober adjustment. That pairing tells you the exam expects a full loop: observe the flap, find the cause, choose the correct object to change. Recognising the symptom without knowing which knob to turn will not score.

Log analysis is broken into three specific outcomes: verifying pool status from log entries, using statistical data to pinpoint query response time problems, and reading the appropriate log to confirm zone transfer operation. Three different logs, three different questions, and the skill is knowing which one answers which.

What Does Operations and Support Expect You to Have Done Before?

Operations and Support tests the work that happens after a BIG-IP DNS deployment goes live: configuration backup, configuration restoration, monitoring, and software upgrades. Its objectives are written as procedures rather than concepts, and several of them are difficult to answer correctly unless you have performed the task at least once on a real or virtual appliance.

Backup is tested twice over, through the graphical interface and through TMSH commands, followed by verifying the archive was created and moving it to remote storage. Knowing that a UCS archive exists is not enough. The objective wants the steps in both interfaces, which is a deliberate check that you have done it rather than read about it.

Restoration is the harder half and carries the most specific sub-point in the whole blueprint. You must recognise the special requirements for restoring configuration data to a BIG-IP DNS RMA unit, compare configuration objects between a new device and an existing sync group member, and determine when and how to restore the master encryption keys for TSIG and DNSSEC. Those keys are the detail that separates a restore that works from one that leaves a device silently unable to sign or validate.

Monitoring covers SNMP polling and the use of DNS statistics and analytics, and the upgrade objective asks for three things: recognising that a licence must be reactivated before an upgrade, predicting the end user impact of upgrading a sync group member while it is offline, and validating operation after the upgrade completes. The middle one is a scenario question waiting to happen, because the answer depends on how the remaining members handle the load.

If you sat 303 or another specialist paper recently, the operational shape here will feel familiar, and our walkthrough of the F5 303 ASM specialist exam shows how the same lifecycle structure repeats across the specialist tier.

How Should You Prepare for the F5 302 Exam?

Preparation for the BIG-IP DNS Specialist exam works best in the order the blueprint is written, because each section depends on the one before it. Build the platform, build GSLB on top of it, break it deliberately, then practise the operational tasks. Reading the objectives is not enough on its own, since several of them are written as actions performed in two different interfaces.

  1. Read the four blueprint sections end to end before studying any of them, so you know which objectives repeat across sections and which appear only once.
  2. Build a two device lab with correct self IPs, routes and NTP, and confirm iQuery is established between them before configuring anything DNS related.
  3. Configure GSLB with wide IPs, pools and virtual servers, then work through the two tiers of pool selection and the three tiers of virtual server selection until the fallback behaviour is predictable.
  4. Add the non-GSLB components separately, configuring a listener, then DNS Express against a real zone transfer, then DNS Cache, so the difference between them stays clear.
  5. Break each piece on purpose and diagnose it with tcpdump, dig and the relevant log, because the troubleshooting objectives expect the full loop from symptom to configuration change.
  6. Practise the operational tasks last, creating archives in both the interface and TMSH, and rehearsing a restore including the TSIG and DNSSEC master keys.

Time the rehearsal from the start rather than at the end. At roughly sixty seven seconds a question there is no recovery from slow recall, and candidates who only add a timer in the final week discover the problem too late to fix it. Our older F5 302 study tools page collects the practice material for that rehearsal in one place.

Frequently Asked Questions

How many questions are on the F5 302 exam?

Eighty questions in 90 minutes. That works out at roughly sixty seven seconds per item, so recall speed matters as much as depth on this paper.

What is the passing score for the BIG-IP DNS Specialist exam?

245 out of 350. F5 reports a scaled score rather than a raw count of correct answers, so there is no fixed number of questions you can afford to lose.

How much does exam 302 cost?

180 US dollars, booked through Pearson VUE. F5 delivers 302 as a test centre proctored exam.

Which certification do you get for passing 302?

F5 Certified Technology Specialist, BIG-IP DNS. F5 also lists this certification as a prerequisite for its Cloud Solutions Expert tracks, so it opens the expert tier rather than closing a path.

How is the 302 blueprint weighted?

It is not. F5 publishes four sections, Design and Architect, Implement, Test and Troubleshoot, and Operations and Support, with no percentage attached to any of them. The objective counts are even across the four, which is the closest thing to a weighting signal available.

Is GSLB the main topic of the exam?

It is the largest single theme but not the whole paper. Two Implement objectives are GSLB specific and a third covers the network conditions GSLB depends on, while a separate objective covers non-GSLB components including listeners, DNS Express and DNS Cache.

What is the difference between DNS Express and DNS Cache on the exam?

DNS Express holds authoritative zone data in memory after a zone transfer so the BIG-IP answers queries itself. DNS Cache stores previously resolved answers so repeat lookups do not go upstream. Scenario questions describe the symptom rather than naming the feature.

Which command line tools does the exam name?

Three: openssl for reviewing trusted certificate information, tcpdump for capturing DNS and iQuery traffic on the correct VLAN and IP, and dig or nslookup for verifying configuration and operation.

Does the exam cover DNSSEC?

Yes, in two places. It is named among the features you must match to a use case in the design section, and its performance implications are a separate sub-point. Restoring DNSSEC master encryption keys also appears in the operations section.

How much experience does F5 expect before 302?

F5 does not state a prerequisite exam on the 302 exam page, but describes the programme as progressive, with higher certifications building on the skills demonstrated by earlier ones. The objectives assume working familiarity with TMOS platform configuration rather than teaching it.

Conclusion

The BIG-IP DNS Specialist exam is built as a lifecycle rather than a topic list. Design, implement, troubleshoot, operate: four sections, no published weightings, and roughly forty sub-points spread evenly across them. Eighty questions, 90 minutes, 245 out of 350 to pass, at 180 US dollars through Pearson VUE.

Prepare it in the order F5 wrote it. Get the platform and iQuery right before touching GSLB, keep the selection tiers straight at two and three, treat listeners and DNS Express as separate skills from wide IP configuration, and rehearse the backup and restore steps in both interfaces rather than reading them. Then put a timer on everything, because at sixty seven seconds a question the exam tests how fast you recognise a fault as much as whether you can fix one.

Rating: 0 / 5 (0 votes)

The post How the BIG-IP DNS Specialist Exam Tests Real GSLB Work appeared first on iSecPrep.

]]>
HQT-4420 Exam: Hitachi Content Platform From Rack to Running https://www.isecprep.com/2026/09/07/hqt-4420-hitachi-content-platform-installation-exam/ Mon, 07 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87606 Hitachi publishes the six HQT-4420 sections without a single percentage weighting, which removes the option of quietly dropping one. Here is what each section asks, why the network design section decides the installation questions, and who the credential is genuinely aimed at.

The post HQT-4420 Exam: Hitachi Content Platform From Rack to Running appeared first on iSecPrep.

]]>

A pallet arrives at a customer loading bay. Inside are the nodes, the switches and the rails for a Hitachi Content Platform, and somebody has to turn that into a running system on a network they did not design, in a rack they did not build, before the customer’s change window closes. The HQT-4420 exam is written for that person.

Hitachi Vantara calls the credential Content Platform Installation Professional, and the word doing the work is installation. This is not a storage administration paper. It does not test capacity planning, tenant policy or day-to-day operations. It tests whether you can identify the physical components in front of you, configure the network and storage correctly the first time, bring nodes up in the right order, and keep the system healthy afterwards. This guide walks the six syllabus sections as Hitachi publishes them, sets out the exam mechanics, and explains why the absence of percentage weightings tells you something useful about how to prepare.

What Does the HQT-4420 Exam Cover?

HQT-4420 covers installing and configuring Hitachi Content Platform across six published sections: the platform’s functionality and protection concepts, the hardware architecture of HCP nodes, the hardware architecture of S-series nodes, network and storage configuration, installation and virtualization options, and ongoing maintenance including upgrades and node replacement.

Hitachi Content Platform is an object storage system, which is the frame worth holding on to while you study. Objects carry their own metadata and are addressed rather than located, which is why HCP behaves differently from a filer at every layer, from how you size storage to how you replace a failed node. If object storage architecture is unfamiliar territory, that gap will show up repeatedly across the syllabus.

Hitachi lists HQT-4420 in the Installation and Support row of its Qualified Professional programme, alongside the other installation credentials rather than the administration ones. That placement is the clearest statement of scope the vendor makes, and it matches what the sections ask for.

What Are the HQT-4420 Exam Details?

HQT-4420 is 35 questions in 60 minutes with a 65 percent pass mark, priced at 100 US dollars and registered through Kryterion Webassessor rather than Pearson VUE. Thirty-five questions across 60 minutes gives you roughly 103 seconds each, which is comfortable, and the low fee reflects that this is a partner-facing operational credential rather than a flagship one.

Detail Value
Certification name Hitachi Vantara Content Platform Installation Professional
Exam code HQT-4420
Questions 35
Duration 60 minutes
Passing score 65%
Price $100 USD
Registration Kryterion Webassessor
Recommended training TCI2741 Installing and Configuring Hitachi Content Platform, a three day instructor-led course

A 65 percent pass mark on 35 questions means 23 correct answers, so you can afford to lose twelve. That sounds generous until you notice how few questions each section gets: with six sections and 35 items, several sections are carrying only four or five questions, and losing one section entirely is close to losing the exam.

Hitachi names one recommended course, TCI2741, and it runs for three days as instructor-led training. It is a recommendation rather than a requirement, but the fact that the vendor points to a hands-on course rather than a reading list says something about the intended preparation route. Working through HQT-4420 sample questions alongside that course is the quickest way to find which of the six sections you are thin on.

Why Does the Syllabus Carry No Weightings?

Hitachi publishes the six HQT-4420 sections without percentage weightings, which is unusual and worth taking seriously. Most vendors weight their domains so candidates can triage. The absence of weights here means you cannot decide which section to under-prepare, and on a 35-question paper that is a real constraint rather than a formality.

Section What it asks you to do
Hitachi Content Platform overview Describe HCP functionality, protection concepts and configurations
HCP nodes hardware architecture Identify physical components and describe network components
HCP S-nodes hardware architecture Identify the physical components of S-series nodes
Network and storage configuration Describe the HCP network and storage configuration design
Installation and virtualization options Configure a node, install nodes, integrate in virtualized environments, install S-series
Maintenance Hardware maintenance, software upgrades, node replacement, adding SSD, S-series upgrades

Read the table as a sequence rather than a list and the exam’s logic appears. You learn what the platform is, then what the hardware is, then how it connects, then how you bring it up, then how you keep it running. Every section depends on the one before it, which is a strong argument for studying them in published order rather than starting with whatever feels weakest.

What Do the Two Hardware Sections Ask About?

Two of the six sections are hardware identification, and they are deliberately separated because HCP nodes and S-series nodes are different machines with different roles. The first asks you to identify the physical components of HCP nodes and describe their network components. The second asks the same identification question about S-series nodes.

HCP nodes run the platform while S-series nodes provide the dense storage tier

The distinction matters on site. HCP nodes run the platform and hold the access layer. S-series nodes are the dense storage tier the platform writes to, and they are physically and logically different enough that an installer who conflates the two will cable the wrong thing. Splitting them into separate syllabus sections is Hitachi making that point structurally.

Note also that only the HCP node section mentions network components. That asymmetry is a genuine hint about where the questions sit: the network expectations attach to the platform nodes, and the S-series section stays on physical identification.

How Much Network and Storage Configuration Is on It?

One full section is devoted to describing the HCP network and to storage configuration design, which on a six-section paper makes it a substantial share. It sits between hardware identification and installation for a reason: this is the planning work that has to be right before a single node is powered on.

Storage configuration design is the phrase to notice. The syllabus says design, not configure. You are being asked to reason about how a storage layout should be arranged for a given deployment rather than to recall a menu path, which is a different and harder kind of question.

The networking side is described rather than configured too. Understanding how the HCP network is structured, which interfaces carry which traffic, and how the nodes talk to each other and to clients is the knowledge that makes the installation section survivable. Get this section wrong and the installation questions become guesswork, because they assume the network model is already in your head.

What Does the Maintenance Section Actually Test?

Maintenance is the broadest section by objective count, covering hardware maintenance procedures for HCP nodes, software upgrade procedures, node replacement, adding SSD storage to a G11 node, and S-series software upgrades. It is the section most likely to be underestimated, because installers think of their job as ending at handover.

The G11 SSD objective is unusually specific. Where the rest of the syllabus is written in general terms, this one names a hardware generation and a component, which suggests a procedure with enough particular steps to be examinable in its own right. Treat it as a discrete thing to learn rather than as an example of a general skill.

Node replacement is the other objective worth deliberate work. Replacing a node in an object store is not the same as swapping a disk: data placement, protection and cluster membership all have to be re-established, and the sequence matters. Questions in this area tend to be about order of operations rather than about which cable goes where.

Software upgrades appear twice, once for HCP nodes and once for S-series, and that repetition is a signal too. The two upgrade paths are separate procedures, and the syllabus lists them separately rather than folding them together.

How Should You Prepare for HQT-4420?

Preparation for HQT-4420 works best in the syllabus’s own published order, because each section is the foundation of the next. Hardware identification without the platform concepts is memorisation, and installation steps without the network model are a recipe you cannot troubleshoot.

HQT-4420 study order checklist from platform concepts through to node replacement
  1. Start with the platform concepts, making sure you can explain HCP protection and the available configurations in your own words before touching hardware.
  2. Learn the two node families side by side rather than separately, so the differences between HCP nodes and S-series nodes are the thing you remember rather than two isolated component lists.
  3. Work through the network and storage design section next, sketching a deployment layout by hand until you can justify where each interface and each storage decision goes.
  4. Only then take on installation and virtualization, walking the node configuration and installation sequence end to end, including the virtualized deployment path.
  5. Finish on maintenance, rehearsing node replacement and both upgrade paths as ordered procedures, and treat the G11 SSD addition as its own small drill.

Hitachi’s own recommended course, TCI2741, is three days of instructor-led work and covers installing and configuring the platform directly. If you can get on it, it removes most of the guesswork from steps four and five. For a structured view of the objectives before you book anything, the site’s HQT-4420 study guide lays the six sections out in the order Hitachi publishes them.

The step candidates skip is the third one. Sketching the network and storage layout feels like homework rather than study, and it is the single thing that makes the installation questions read as obvious rather than as a memory test.

Who Should Sit This Exam?

HQT-4420 is aimed at Hitachi Vantara employees and partners who install Content Platform systems at customer sites. That is a narrower audience than most certifications address, and it explains both the low fee and the operational focus of every section.

If you work for a Hitachi partner and object storage installations are part of your delivery work, this credential is a direct match. If you administer an HCP estate that somebody else installed, it is the wrong exam: the syllabus never reaches tenant configuration, policy or day-to-day operations, and the parts you would find useful are not on it.

The transferable value sits in the platform knowledge rather than the credential itself. Hitachi describes what HCP is built to do on its own Content Platform product page, and the architecture concepts behind it carry across to any object store you meet later. Infrastructure roles that involve this kind of on-site build work sit in the broader systems administration market, where systems administrator pay data gives a reasonable benchmark for what the surrounding skill set is worth.

Within Hitachi’s own programme, HQT-4420 is a Professional-tier credential. Candidates who already hold an installation credential on another Hitachi platform will find the structure familiar, and our HQT-4180 exam guide covers the equivalent paper on the VSP midrange side, which follows the same identify, configure, install, maintain shape.

Frequently Asked Questions

How many questions are on the HQT-4420 exam?

Thirty-five questions in 60 minutes, which is roughly 103 seconds each. That is a comfortable pace, and the practical difficulty comes from the breadth of the six sections rather than from time pressure.

What is the passing score for HQT-4420?

Sixty-five percent, which works out at 23 correct answers from 35. With six sections sharing 35 questions, being blank in one whole section puts a pass in serious doubt.

How much does the HQT-4420 exam cost?

One hundred US dollars. The fee is low compared with most vendor certifications, which fits its role as a partner-facing operational credential rather than a flagship architecture qualification.

Where do you register for HQT-4420?

Through Kryterion Webassessor, not Pearson VUE. Hitachi Vantara runs its Qualified Professional programme on Kryterion, so candidates used to booking through Pearson need a separate account.

Does the HQT-4420 syllabus have domain weightings?

No. Hitachi publishes the six sections without percentages, so there is no published basis for deciding which area to under-prepare. On a 35-question paper that makes even coverage the safer strategy.

What is the difference between HCP nodes and S-series nodes?

They are different machines with different roles, which is why the syllabus gives each its own section. HCP nodes run the platform and carry the network components; S-series nodes are the dense storage tier the platform writes to.

Is HQT-4420 a storage administration exam?

No. It is an installation credential, listed by Hitachi in the Installation and Support row of its programme. Tenant configuration, policy and daily operations are all outside its scope.

What training does Hitachi recommend for HQT-4420?

TCI2741, Installing and Configuring Hitachi Content Platform, a three day instructor-led course. It is recommended rather than required, but it maps closely to the installation and virtualization section.

Does the exam cover virtualized deployments?

Yes. The installation section explicitly includes integration procedures for Hitachi Content Platform in virtualized environments, alongside the physical node installation and the S-series installation path.

Who is the HQT-4420 exam intended for?

Hitachi Vantara employees and partners who install Content Platform systems at customer sites. Administrators who inherit a running estate rather than building one will find the syllabus points away from their day job.

Conclusion

HQT-4420 is a field engineer’s exam. Thirty-five questions, 60 minutes, a 65 percent pass mark and six sections that run from platform concepts through hardware identification and network design to installation and maintenance. No section carries a published weighting, which removes the option of triaging one away.

Work the sections in Hitachi’s own order, learn the two node families against each other rather than in isolation, and give the network and storage design section the time it looks like it does not need. Get that one right and the installation questions stop being a memory test.

Rating: 0 / 5 (0 votes)

The post HQT-4420 Exam: Hitachi Content Platform From Rack to Running appeared first on iSecPrep.

]]>
IBM QRadar SIEM Analysis Exam: What C1000-162 Really Weighs https://www.isecprep.com/2026/09/07/ibm-qradar-siem-analysis-exam-c1000-162/ Mon, 07 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87591 C1000-162 splits into five weighted domains, and threat hunting takes the largest share at 24 percent. Here is how the marks sit, what the exam expects from an analyst at the console, and how it differs from the QRadar foundations and administration papers.

The post IBM QRadar SIEM Analysis Exam: What C1000-162 Really Weighs appeared first on iSecPrep.

]]>

Twenty-four percent is the largest single share of the IBM QRadar SIEM analysis exam, and it does not belong to offense analysis. It belongs to threat hunting. That one figure tells you more about C1000-162 than the exam title does, because the credential is named IBM Certified Analyst – Security QRadar SIEM V7.5, and most candidates read “analyst” as “the person who works the offense queue”.

The syllabus disagrees. Offense analysis carries 23 percent. Threat hunting carries 24 percent, and searching and reporting carries another 21 percent. Put those two together and 45 percent of the paper is about what you do once you stop trusting the offense list: writing Ariel Query Language searches, reading payloads, and separating a real indicator from a noisy rule. This guide walks the five weighted domains as IBM’s published syllabus names them, sets out the exam mechanics, and settles the question that sends most people to the wrong exam entirely, which is whether you should be sitting the analysis paper at all.

What Does the IBM QRadar SIEM Analysis Exam Test?

C1000-162 tests whether you can work an investigation inside IBM QRadar SIEM V7.5 rather than describe how the product is built. Across 64 questions in 90 minutes, it asks you to triage offenses, read the rules and building blocks that created them, hunt through events and flows with Ariel searches, and turn what you find into dashboards and reports.

That framing matters because QRadar has three separate credentials, and only this one sits in the investigation seat. Deployment questions, appliance sizing and licence management belong elsewhere. Here the console is already running, the log sources are already feeding it, and the question is what you do with the alert in front of you.

QRadar itself is IBM’s threat detection platform, and its central idea is correlation: raw events and network flows are matched against rules, and the matches are collapsed into prioritised offenses so an analyst is not reading a firehose. IBM sets out that architecture on its QRadar SIEM product page. The exam assumes you accept that model and can operate inside it under pressure.

A useful way to read the objective list is to notice what the verbs are. The syllabus asks you to triage, analyse, recognize, distinguish, investigate and recommend. It rarely asks you to define. Questions are written as scenarios with a console state attached, and the correct answer is usually the next investigative step rather than a fact about the product.

How Are the Five C1000-162 Domains Weighted?

The published syllabus splits C1000-162 into five weighted domains: Threat Hunting at 24 percent, Offense Analysis at 23 percent, Searching and Reporting at 21 percent, Rules and Building Block Design at 18 percent, and Dashboard Management at 14 percent. Nothing dominates, which means no single area can be skipped and passed around.

Domain Weight Approximate questions What it is really asking
Threat Hunting 24% 15 Can you find something the rules did not flag
Offense Analysis 23% 15 Can you work the queue the rules did produce
Searching and Reporting 21% 13 Can you evidence and communicate what you found
Rules and Building Block Design 18% 12 Can you read why the console behaved as it did
Dashboard Management 14% 9 Can you build the view a team works from

The question counts are derived from the weightings against a 64-question paper, so treat them as planning figures rather than a guarantee. Their value is in showing how flat the distribution is. Dashboard Management is the smallest domain and still accounts for roughly nine questions, which is more than the six-question margin between a 64 percent pass and a fail.

Working through QRadar analysis sample questions against a live console is the fastest way to find which of the five you are weakest in, because the gap tends to show up as hesitation rather than as a wrong answer.

Why a flat distribution changes your study plan

On an exam with a 40 percent domain, you protect the big one and accept losses elsewhere. C1000-162 does not allow that. With the largest domain at 24 percent, a candidate who is fluent in four areas and blank in the fifth is losing between nine and fifteen marks before answering a single question they know.

What Are the C1000-162 Exam Details?

C1000-162 is a 64-question exam with a 90-minute limit and a 64 percent pass mark, priced at 200 US dollars and delivered through Pearson VUE. Ninety minutes across 64 questions works out at roughly 84 seconds each, which is comfortable for recall items and tight for a scenario that hands you a screenshot of an offense summary.

Detail Value
Certification name IBM Certified Analyst – Security QRadar SIEM V7.5
Exam code C1000-162
Questions 64
Duration 90 minutes
Passing score 64%
Price $200 USD
Delivery Pearson VUE

A 64 percent pass mark on 64 questions means 41 correct answers. That is a wider margin than many security exams allow, and it is the reason a candidate with genuine console experience and one weak domain can still pass. It is not wide enough to survive two weak domains.

Scheduling runs through the standard IBM route at Pearson VUE for IBM exams, with the usual choice between a test centre and online proctoring. The product version in the title is not decoration: the objectives are written against QRadar SIEM V7.5, and console layouts have shifted enough across releases that rehearsing on an older build teaches menu paths you will not be shown.

Which of the Three QRadar Exams Should You Sit?

IBM publishes three QRadar SIEM V7.5 credentials, and they are not a difficulty ladder. C1000-175 covers foundations, C1000-162 covers analysis, and C1000-156 covers administration. They describe three different jobs, so the right choice follows what you are asked to do on a Monday morning rather than how long you have been doing it.

Exam Credential focus Who it fits
C1000-175 Foundations of QRadar SIEM V7.5 Newcomers proving they can navigate the console at all
C1000-162 Analysis Analysts who investigate offenses and hunt through events
C1000-156 Administration Engineers who own log sources, tuning and platform health

The confusion is usually between the first two. If your day is spent in the offense queue and the log activity tab, analysis is your exam. If you are still learning where the offense summary lives, the foundations credential is the honest starting point, and our QRadar security associate guide covers what that tier expects before you commit 200 dollars to the analysis paper.

Administration is the one people sit by accident. Its search demand runs close to the analysis exam, and the titles look similar enough that candidates book on the wrong code. If your responsibilities include adding log sources, managing deployment health or handling licences, that is the correct paper. If they do not, the administration objectives will read as a syllabus for somebody else’s job.

What Does Offense Analysis Look Like in Practice?

Offense analysis is 23 percent of C1000-162, and it covers the whole life of an alert: triaging the initial offense, reading which rules matched fully and which matched only in part, following the associated IP addresses, interpreting magnitude, and closing the offense out through offense management. It is the queue-work half of the analyst role.

Four stages of a QRadar investigation for C1000-162: offense fires, triage, hunt, report

Two objectives in this domain catch experienced people out. The first is the distinction between fully matched and partially matched rules. An offense raised by a partial match is a different investigative problem from one raised by a complete match, and the syllabus expects you to say which you are looking at and what that implies about confidence.

The second is magnitude. It is easy to treat it as a severity score and move on, but it is a composite, and the exam asks you to describe what it is actually made of and why two offenses with the same event count can carry different magnitudes.

MITRE mapping is a named objective

The syllabus lists “recognize MITRE threat groups and actors” as an Offense Analysis objective, which makes threat-actor attribution part of the exam rather than background reading. The MITRE ATT&CK groups index is the reference the industry works from, and it is worth being able to move from a technique seen in an offense to the groups that habitually use it.

Alongside that sit the quieter objectives: identifying stored and unknown events and where they came from, outlining offense naming mechanisms, and creating customized searches from inside an offense. None of them is difficult. All of them are the kind of thing you have clicked through a hundred times without ever articulating.

Why Is Threat Hunting the Heaviest Domain?

Threat hunting is 24 percent of C1000-162 because it is where analysis stops being reactive. The domain covers Ariel Query Language searches, event and flow parameter investigation, time-series searches, indicator analysis, payload inspection, right-click investigations, and the judgement call that separates a probable false positive from something worth escalating.

AQL is the piece most candidates underprepare. The syllabus asks you to perform an AQL query, not to recognise one, and the difference shows in scenario questions that give you a hunting goal and four query fragments. Reading AQL fluently is a different skill from writing it, and only one of them survives exam conditions.

Payload work is the other underweighted objective. Two separate items ask you to investigate the payload for additional detail and to recommend new custom properties based on what the payload contains. That second one is a design decision dressed as an analysis question: you are being asked whether a field you keep extracting by hand should become a property the console extracts for everyone.

IBM’s own QRadar 7.5 documentation is the right reference for query syntax and property behaviour, and it is worth reading the Ariel sections against a console rather than on their own.

Rules and building blocks sit underneath the hunt

Rules and Building Block Design is a smaller domain at 18 percent, but it is the one that explains the other four. Reading a regular expression test, understanding reference sets and how they are populated, recognising when a Content Pack is the answer, and knowing your network hierarchy are all things you need before you can say why an offense fired. Behavioral, anomaly and threshold rules each fail in a characteristic way, and the exam expects you to name which is which.

How Should You Prepare for C1000-162?

Preparation for C1000-162 works best as a four-stage sequence built around a live QRadar console rather than a reading list. The order matters: rules and building blocks explain offenses, offenses generate the hunts, and hunts produce the searches and reports, so studying them out of sequence means learning each one without its context.

  1. Rebuild your console fluency first. Spend a week inside log activity, network activity and the offense tab until you can reach any of them without thinking, and read your own deployment’s network hierarchy end to end.
  2. Work the rules layer next. Open the rules that fire most often in your environment, read their tests, trace the building blocks they depend on, and populate a reference set by hand so the mechanics are yours rather than remembered.
  3. Move to offense work and hunting together. Triage real offenses, follow each one to the rule that raised it, then leave the offense behind and hunt the same activity with AQL from scratch until the query comes without reference.
  4. Finish with searching, reporting and dashboards under a clock. Build a threat report from an offense, export results, schedule a report, and assemble a dashboard in both the classic view and Pulse, then run a timed set of practice items with no console open.

The last stage is the one people skip, and it is the one the weightings argue for hardest. Searching and reporting plus dashboard management together are 35 percent of the paper, which is more than threat hunting and more than offense analysis. They are also the least glamorous parts of the job, which is exactly why they go unrehearsed.

For a checklist of what the exam covers before you start, the site’s C1000-162 exam overview lays the objectives out in the order IBM publishes them, which is a useful audit sheet to score yourself against at the end of each stage.

What Skills Does Passing This Exam Prove?

Passing C1000-162 proves you can take an alert from a QRadar console to a defensible conclusion without help. Concretely, that means triaging an offense against its originating rules, hunting the same activity independently with Ariel searches, judging an indicator against a false positive, and producing a report a manager or an auditor can read.

What passing C1000-162 proves: triage, hunting, judgement and reporting skills

Those are transferable claims. The console is IBM’s, but the reasoning is platform-neutral: correlation rules, reference sets, network hierarchies and query languages exist in every serious SIEM under different names. An analyst who can explain why a partially matched rule raised an offense is describing a way of thinking, not a menu path.

The credential also carries a specific signal about scope. It says you sit on the investigation side rather than the platform side, which is a genuinely useful thing for a hiring manager to know in advance. Roles that split SOC analysis from SIEM engineering read the three QRadar codes precisely for that reason.

One caution worth stating plainly. The certification is versioned to QRadar SIEM V7.5, and IBM’s security portfolio has been moving toward a broader suite. A version-bound credential proves current fluency rather than permanent standing, so treat it as evidence of what you can do now and keep the underlying investigative skill portable.

Frequently Asked Questions

How many questions are on the C1000-162 exam?

Sixty-four questions in 90 minutes. That is roughly 84 seconds per question, which is enough for recall items but tight for the scenario questions that present an offense summary and ask for the next investigative step.

What is the passing score for C1000-162?

Sixty-four percent, which works out at 41 correct answers from 64. The margin is wide enough to absorb one weak domain but not two, and the domains are weighted flatly enough that no single area can be skipped.

How much does the IBM QRadar certification cost?

Two hundred US dollars for C1000-162, scheduled through Pearson VUE. The fee is per attempt, so the practical cost of an unprepared sitting is 400 dollars rather than 200.

What is the difference between C1000-162 and C1000-156?

C1000-162 is the analysis exam and C1000-156 is the administration exam. Analysis covers investigating offenses and hunting through events. Administration covers owning the platform itself, including log sources, tuning and deployment health.

Which QRadar domain carries the most marks?

Threat Hunting, at 24 percent. Offense Analysis follows at 23 percent, then Searching and Reporting at 21, Rules and Building Block Design at 18, and Dashboard Management at 14 percent.

Do I need to write AQL for the C1000-162 exam?

Yes. Performing an AQL query is a named Threat Hunting objective, not an optional extra. Scenario questions give a hunting goal and candidate query fragments, so reading AQL fluently is not sufficient on its own.

Does the QRadar analysis syllabus include MITRE threat groups?

Yes. Recognising MITRE threat groups and actors is listed as an Offense Analysis objective, so being able to move from an observed technique to the groups that commonly use it is inside the exam scope.

What QRadar version does the exam cover?

QRadar SIEM V7.5. Console layouts and property behaviour have shifted across releases, so practising on an older build risks learning navigation paths that will not match what the exam describes.

How long should I spend preparing for C1000-162?

Around four weeks is a realistic block for someone already working in a QRadar console, split across console fluency, the rules layer, offense and hunting work together, and a final timed stage on searching, reporting and dashboards.

Is C1000-162 suitable for a complete QRadar beginner?

Not really. The objectives assume you can already navigate the console and read an offense summary. C1000-175, the foundations credential, is the honest starting point if the offense tab is still unfamiliar territory.

Conclusion

The IBM QRadar SIEM analysis exam is not the offense-queue exam its title suggests. Threat hunting is the heaviest domain at 24 percent, searching and reporting takes another 21, and together with dashboards that is well over half the paper spent away from the alert list. C1000-162 gives you 64 questions, 90 minutes and a 64 percent pass mark to show you can investigate rather than react.

Audit yourself against the five weighted domains, be honest about which of the three QRadar credentials matches the job you actually do, and rehearse AQL and reporting on a live console rather than on paper. The domain table above is worth returning to until none of the five reads as unfamiliar territory.

Rating: 0 / 5 (0 votes)

The post IBM QRadar SIEM Analysis Exam: What C1000-162 Really Weighs appeared first on iSecPrep.

]]>
Open Book Does Not Make This Security Exam Easy https://www.isecprep.com/2026/09/04/dsof-devsecops-foundation-open-book-exam/ Fri, 04 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87557 Forty questions, sixty minutes, and permission to look things up. The format removes recall and leaves comprehension, which is the harder problem on a ninety second clock.

The post Open Book Does Not Make This Security Exam Easy appeared first on iSecPrep.

]]>

If the answers are allowed to be in front of you, what exactly is there to revise? That is the question worth settling before booking the DevSecOps Foundation exam, because DSOF is delivered open book, and almost every piece of study advice written for it ignores that fact entirely. Forty multiple choice questions, 60 minutes, a 65 percent pass mark, and permission to look things up while you answer.

The honest answer is that open book removes recall and leaves comprehension, which is a harder problem on a 90-second-per-question clock than most candidates expect. The DevOps Institute DevSecOps Foundation credential covers eight named topics, from the cyber threat landscape through pipelines and continuous compliance to how learning programmes are run, and the syllabus names the OWASP Top Ten, published CVEs and common software weaknesses outright. This guide sets out what those topics contain, what open-book delivery actually changes, and who the $257 is genuinely worth spending by.

What Is the DevSecOps Foundation Exam?

DSOF is the entry-level credential in the DevOps Institute’s security track. The DevSecOps Foundation exam contains 40 multiple choice questions, runs for 60 minutes, and is passed at 65 percent, which means 26 correct answers. It costs $257 US dollars, is delivered over the web, and carries a three-year validity.

The credential’s ownership matters for anyone planning around it. DevOps Institute is now part of the PeopleCert Group, and application, purchase and delivery all route through the PeopleCert platform. That change is also why the validity period is three years: certifications taken on the PeopleCert platform fall under its Continuing Professional Development programme rather than the older two-year Continuing Education cycle.

Language availability is wider than the foundation tier usually offers, covering English, Brazilian Portuguese, Chinese and Japanese. Preparation can be instructor-led, online, or entirely self-directed, and no formal prerequisite blocks a booking.

Is the DSOF Exam Really Open Book?

Yes. The DevOps Institute lists Open Book: Yes among the certification details for DSOF, alongside the 40 questions, 65 percent pass mark and 60-minute duration. It is a web-based exam, so the reference material is genuinely to hand rather than notionally permitted.

Candidates hear that and relax, which is the mistake. Sixty minutes across 40 questions is 90 seconds each. Looking up a term costs perhaps 30 to 45 seconds by the time you have found it and read enough to be sure, so the format tolerates roughly a dozen lookups across the whole paper before the clock becomes the binding constraint rather than your knowledge.

What that produces is an exam that punishes unfamiliarity rather than imperfect memory. If you recognise every term and merely cannot recall one definition precisely, open book saves you. If half the vocabulary is new, no amount of reference material rescues a 90-second budget.

What Does Open Book Change About Preparation?

It moves the target from memorising to navigating. The useful preparation for a closed-book exam is repetition until recall is automatic; the useful preparation for an open-book one is building a mental index so that you know where an answer lives and can reach it in seconds rather than searching for it.

Four practical differences follow.

  • Flashcards lose most of their value. Recall drills solve a problem the format has already solved for you.
  • Organising your reference material becomes a study activity in its own right, because a well-structured set of notes is faster to search than a well-remembered one is to recall.
  • Reading comprehension under time pressure matters more than content coverage, since the questions are scenario-flavoured rather than definitional.
  • Deciding quickly whether to look something up is a skill. The candidates who run out of time are usually the ones who checked answers they already knew.

Working through the topics against DSOF exam preparation material under a timer is the fastest way to discover which of those two habits you have.

What Topics Does DSOF Cover?

Eight named topics, published without weightings. They move from context to practice to people: the threat landscape first, then how DevSecOps outcomes are realised, the practices and the response model, how to get started, who the stakeholders are, pipelines and continuous compliance, and finally how learning is run.

Topic What sits inside it
Cyber Threat Landscape Tactics, techniques and procedures; threat models identifying objectives and vulnerabilities including the OWASP Top Ten; continuous delivery practices supporting governance, risk management and compliance
Realizing DevSecOps Outcomes Security built into the value stream, empowered teams implementing features securely, shift-left testing, automated feedback tooling, culture improvement rather than policy enforcement
DevSecOps Practices Security integrated into people, process, technology and governance; continuous security in onboarding; data-driven monitoring of security outcomes; lean and value stream thinking so security adds no waste
Responsive DevSecOps Model Continuously adaptive and auditable security, breaking silos between security and other business units, security practices and toolsets as code, observable security KPIs inside the value stream
Getting Started Value stream mapping to locate security activities and bottlenecks; collaborative target-state design covering artifact management, risk management, identity and access, secrets, encryption, governance, monitoring, logging and incident response
DevSecOps Stakeholders Closing the gap between waterfall security culture and DevOps pace through credibility, reliability and empathy; decisions informed by everyone affected; shared metrics and adaptable governance
Pipelines and Continuous Compliance Security testing and scanning integrated into CI/CD to find published CVEs and common software weaknesses; automated configuration and fuzz testing; compliance as code
Learning Using Outcomes Continuous learning programmes through lunch and learns, mentoring, professional education, employee learning plans, structured classes, Dojos, retrospective learning and gamification

The balance is worth noticing. Only two of the eight topics are primarily technical. The rest are about culture, stakeholders, value streams and learning, which tells you what kind of exam this is before you read a single question.

Which Frameworks Does the Syllabus Name Directly?

Three, and all three are open industry references rather than vendor material: the OWASP Top Ten under the threat landscape topic, and published CVEs together with common software weaknesses under pipelines and continuous compliance. That specificity is unusual for a foundation syllabus and makes the reading list short and concrete.

Frameworks the DSOF syllabus names directly: the OWASP Top Ten, CVE, CWE and fuzz testing

The threat side

The syllabus describes threat models as optimising security by identifying objectives and vulnerabilities before counter-measures are defined, and names the OWASP list as the example. The OWASP Top Ten project is the reference of record here, and reading the current list once is worth more than any summary of it.

The pipeline side

For pipelines, the objectives distinguish between known vulnerabilities in shipped components and weaknesses in the code itself, which is the CVE and CWE distinction stated plainly. MITRE’s Common Weakness Enumeration is the catalogue behind the second half of that pairing, and understanding why the two lists exist separately is the point the exam is likely to test.

Alongside those, the syllabus names compliance as code, fuzz testing and value stream mapping as techniques rather than as concepts, so each one needs a working definition rather than a recognition-level one.

What Are the DSOF Exam Details?

DSOF is 40 multiple choice questions in 60 minutes, passed at 65 percent, which is 26 correct answers with 14 to spare. The fee is $257 US dollars, delivery is web-based and open book, and the credential remains valid for three years.

Detail Value
Exam name DevOps Institute DevSecOps Foundation
Exam code DSOF
Questions 40, multiple choice
Duration 60 minutes
Passing score 65 percent, or 26 correct
Fee $257 USD
Delivery Web-based, open book
Languages English, Brazilian Portuguese, Chinese, Japanese
Validity 3 years
Preparation Instructor-led training, online learning, or self-study

Fourteen permitted mistakes across eight topics is a comfortable margin on paper, and the format is what makes it less comfortable than it looks. The full certification details, including the open-book confirmation, sit on the official DevSecOps Foundation page, and the exam itself is now booked and sat through the PeopleCert platform.

For readers who want the study material gathered rather than scattered, our DSOF resource page collects it in one place alongside the topic list above.

What Is the Difference Between DevOps and DevSecOps?

DevOps removes the handoff between building software and running it. DevSecOps removes a second handoff, the one where security reviews the result after it is built. The syllabus frames the difference as culture rather than tooling: security integrated into people, process, technology and governance, with culture improvements replacing policy enforcement.

That framing is why the exam spends so little time on scanners. Two of the eight topics deal with pipelines and threats; the other six deal with outcomes, practices, response models, stakeholders, getting started and learning. A candidate expecting a tools exam will find a change-management exam wearing a security badge.

The stakeholder topic makes the distinction concrete. It describes closing the gap between a traditional waterfall security culture and a fast-moving DevOps culture by building credibility, reliability and empathy while reducing self-interest, with decisions informed by everyone affected. That is organisational work, and it is examinable.

How Should You Prepare for an Open Book Paper?

Build a reference you can navigate rather than a memory you can recall. The goal is that any term in the eight topics is either already familiar or findable in under 30 seconds, because the 90-second question budget will not absorb more than a dozen genuine lookups.

How open book delivery changes the DSOF study plan, replacing memorising with indexing notes and limiting lookups
  1. Read all eight topic descriptions once without taking notes, marking only the terms you could not define aloud to a colleague, because that list is your entire revision scope.
  2. Build a single structured reference document organised by the eight topic names, so that during the exam you know which section to open before you know what you are looking for.
  3. Read the current OWASP Top Ten in full rather than a summary, since it is the one list the syllabus names by name under the threat landscape topic.
  4. Settle the CVE and CWE distinction properly, because the pipelines topic treats known vulnerabilities and common weaknesses as two separate things and a question turning on that difference is easy to lose.
  5. Work the culture topics with the same seriousness as the technical ones, given that six of the eight topics deal with outcomes, stakeholders, practices and learning rather than with tooling.
  6. Rehearse at 90 seconds per question with your reference open, deliberately practising the decision of whether to look something up, because the candidates who run out of time are the ones who checked what they already knew.

Anyone already working in a DevSecOps team will find steps one and six do most of the work. The credential’s difficulty for practitioners is rarely the content; it is the vendor’s specific vocabulary for practices they already run under different names.

Who the Credential Is Actually Aimed At

Broader than the name suggests. The DevOps Institute names compliance and delivery staff, project and product managers, IT managers, security professionals, site reliability engineers, DevOps engineers, software engineers, support staff, managed service providers, quality assurance teams, release managers, scrum masters and testers among the roles this credential suits.

Read that list carefully and the design intent becomes clear: DSOF is built to give a mixed team one shared vocabulary rather than to deepen a specialist’s expertise. It is a reasonable team-wide credential and a thin individual one for anyone already senior in application security.

Practitioners who find the foundation content already familiar should look straight past it. The practitioner tier is the one that adds depth, and our guide to the DSOP practitioner credential covers what changes at that level and whether the step up is worth taking.

Frequently Asked Questions

What is the DevSecOps Foundation exam?

DSOF is the DevOps Institute’s entry-level DevSecOps credential. It contains 40 multiple choice questions, runs 60 minutes, is passed at 65 percent, and covers eight topics spanning threats, practices, pipelines, stakeholders and learning.

Is the DSOF exam open book?

Yes. The DevOps Institute lists Open Book: Yes among the certification details, and the exam is delivered over the web. Reference material is genuinely available while you answer, though the 90-second question budget limits how often you can use it.

How much does the DevSecOps Foundation certification cost?

Two hundred and fifty seven US dollars for the exam. Training is priced separately, and the vendor supports instructor-led, online and self-study routes, so the fee is the only unavoidable cost.

What is the passing score for DSOF?

Sixty-five percent, which is 26 correct answers from 40. That leaves 14 permitted mistakes, a reasonable margin for a foundation paper delivered under open-book conditions.

How long is the DevSecOps Foundation certification valid?

Three years. The period changed after DevOps Institute joined the PeopleCert Group, since certifications taken on the PeopleCert platform fall under its Continuing Professional Development programme.

What is the difference between DevOps and DevSecOps?

DevOps closes the gap between building and running software. DevSecOps closes a second gap by integrating security into people, process, technology and governance rather than reviewing the finished product after the fact.

Does DSOF cover the OWASP Top Ten?

Yes, by name. The cyber threat landscape topic describes threat models identifying objectives and vulnerabilities such as the OWASP Top Ten before counter-measures are defined, so the current list is required reading.

Is DSOF worth it for an experienced security engineer?

Marginally. Six of the eight topics cover culture, stakeholders and learning rather than tooling, so an experienced practitioner mostly gains shared vocabulary. The practitioner-tier credential is the better fit for depth.

What languages is the DSOF exam available in?

English, Brazilian Portuguese, Chinese and Japanese. That is wider coverage than most foundation-level credentials offer, and all four are available through the same web-based delivery.

Are there prerequisites for the DevSecOps Foundation exam?

None. The vendor recommends training but does not require it, and no prior certification gates a booking. The audience list runs from software engineers to release managers and compliance staff.

Conclusion

The DevSecOps Foundation exam is easier to underestimate than to fail. Open book, 40 questions, 65 percent and 60 minutes describes a paper that rewards familiarity and punishes unfamiliarity, and six of its eight topics are about how organisations work rather than about how scanners work.

Prepare by building a reference you can navigate under time pressure, read the OWASP Top Ten properly, settle the CVE and CWE distinction, and take the culture topics as seriously as the technical ones. If most of that already describes your week, the credential is a vocabulary exercise worth three years of validity rather than a learning one.

Rating: 0 / 5 (0 votes)

The post Open Book Does Not Make This Security Exam Easy appeared first on iSecPrep.

]]>
The RHCSA Exam Objectives Are a Task List, Not a Topic List https://www.isecprep.com/2026/09/04/rhcsa-ex200-exam-objectives-hands-on-tasks/ Fri, 04 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87548 Ten objective groups, twenty tasks, one hundred and fifty minutes, and a machine that gets graded instead of your reasoning. Reading the objectives as topics is where preparation goes wrong.

The post The RHCSA Exam Objectives Are a Task List, Not a Topic List appeared first on iSecPrep.

]]>

Most candidates prepare for EX200 as though questions were waiting for them. They memorise command flags, drill option lists, and arrive expecting a screen of radio buttons. That preparation is aimed at the wrong exam. The Red Hat Certified System Administrator (RHCSA) exam is delivered as a live Red Hat Enterprise Linux system with tasks to complete, and nothing you know counts until the system itself shows it working.

That single fact reshapes what the objective list means. Every line on the RHCSA exam objectives is written as something you do, not something you recall, and Red Hat adds a condition that catches people out: whatever you configure has to survive a reboot on its own. This guide walks the ten objective groups exactly as Red Hat and the published syllabus name them, explains which of them your daily work already covers, and sets out how to rehearse the rest on a system rather than on paper.

What Are the RHCSA Exam Objectives?

The RHCSA exam objectives are ten groups of practical system administration tasks that EX200 asks you to perform on a live Red Hat Enterprise Linux system. They run from shell fundamentals and software management through storage, file systems, networking, users and groups, and finish with SELinux and firewall configuration under the heading Manage security.

The published syllabus lists them without percentage weightings. That is unusual, and it is deliberate: a performance-based exam does not divide neatly into marks per topic the way a question paper does. You are given tasks, and each task may touch two or three objective groups at once. Creating a logical volume, mounting it by UUID at boot, and setting the right SELinux context on it is one piece of work that draws on three separate groups.

Objective group Representative tasks it covers
Understand and use essential tools Shell syntax, input and output redirection, grep and regular expressions, SSH access, tar and gzip archives, file and directory operations, hard and soft links, ugo/rwx permissions, system documentation
Manage software Configuring access to RPM repositories, installing and removing RPM packages, configuring access to Flatpak repositories, installing and removing Flatpak packages
Create simple shell scripts Conditional execution with if and test, looping constructs, processing script inputs, capturing the output of commands inside a script
Operate running systems Booting and rebooting, booting into different targets, interrupting the boot process, identifying and killing intensive processes, adjusting scheduling, tuning profiles, logs and journals, service status, secure file transfer
Configure local storage Partitions on MBR and GPT disks, physical volumes, volume groups, logical volumes, mounting by UUID or label at boot, adding partitions, logical volumes and swap non destructively
Create and configure file systems vfat, ext4 and xfs file systems, NFS mounts, autofs, extending logical volumes, set-GID directories for collaboration, diagnosing permission problems
Deploy, configure, and maintain systems Scheduling with at and cron, enabling services at boot, booting into a specific target automatically, time service clients, installing updates from the Red Hat Content Delivery Network or a local source, modifying the bootloader
Manage basic networking IPv4 and IPv6 addressing, hostname resolution, starting network services at boot, restricting access with firewalld and firewall-cmd
Manage users and groups Creating, deleting and modifying local accounts, passwords and password aging, local groups and memberships, configuring superuser access
Manage security Firewall settings through firewall-cmd, default file permissions, key based SSH authentication, SELinux enforcing and permissive modes, file and process contexts, restoring default contexts, port labels, boolean settings

Read that table as a list of things to be able to do at a prompt, without notes, on an unfamiliar machine. That is the standard the exam applies.

Is the RHCSA a Written Exam or a Practical One?

It is entirely practical. Red Hat describes EX200 as a hands-on exam that requires candidates to undertake real-world tasks, and there is no written component at all. You are given a system, a set of requirements, and a fixed amount of time. Grading is automated against the state of the machine when your session ends.

Three consequences follow, and each one changes how you should revise.

  • Partial knowledge earns nothing. Knowing that a setting exists but not where it lives produces an unconfigured system, which scores the same as an untouched one.
  • Speed matters in a way it does not on a question paper. There is no skipping ahead to easy marks and coming back; every task costs real minutes at a terminal.
  • Verification is part of the work. Since the machine is what gets graded, checking your own result is not optional polish, it is the only way to know you have scored.

Red Hat is also strict about what you may bring. Internet access is not provided, and no hard copy or electronic documentation is permitted, including notes and books. The documentation that ships with the product remains available, which is a meaningful concession: man pages and the files under the shipped documentation tree are on the system and are fair game. Learning to navigate them quickly is itself an exam skill, which is why the first objective group ends with locating and interpreting system documentation.

How Are the Ten Objective Groups Split?

They split cleanly into four themes: working at the shell, putting storage together, running and maintaining the system, and locking it down. No published weighting says how many tasks come from each, so treating the four themes as roughly equal claims on your study time is the safest planning assumption.

Theme Objective groups it contains What the exam is really testing
Shell and software Essential tools, Manage software, Create simple shell scripts Whether you are fluent enough at a prompt to work without hesitation
Storage and file systems Configure local storage, Create and configure file systems Whether you can build a stack from disk to mount point and make it come back after a reboot
Running systems Operate running systems, Deploy configure and maintain systems, Manage basic networking Whether you can control what starts, when it starts, and how the machine reaches the network
Identity and security Manage users and groups, Manage security Whether you can grant access precisely and leave SELinux enforcing rather than switching it off

The storage theme deserves particular respect. It is the one area where a small error compounds: a volume group built on the wrong physical volume, or a mount entry written without a UUID, produces a system that looks correct until it restarts. Rehearsing the whole chain against the objectives on EX200 exam preparation material is a faster way to find those gaps than reading about them.

Which Objectives Does Daily RHEL Work Already Cover?

For most working administrators, roughly half the objective list is already routine and the other half is not. Shell work, package installation, service management and user administration tend to be daily habits. Storage construction, SELinux context repair, autofs and shell scripting are the areas that people either use constantly or have never touched.

Four themes of the RHCSA exam objectives: tools and software, storage and files, running systems, and users and security

Usually already covered

If you administer RHEL for a living, the essential tools group, most of managing software, and the bulk of users and groups will feel like description rather than instruction. Service enablement, log inspection and basic firewall rules usually sit in the same category. Revising these is a matter of confirming syntax under time pressure, not learning anything new.

The reliable weak spots

Three areas catch experienced people out repeatedly.

  1. Logical volume management end to end. Plenty of administrators inherit volumes rather than build them, so creating a physical volume, assigning it to a volume group, carving a logical volume and extending it later is unfamiliar in practice even when it is familiar in theory.
  2. SELinux beyond switching modes. The objectives ask for file and process contexts, restoring default contexts, port labels and boolean settings. Setting the system permissive is not an answer, and on a graded machine it is a visible failure. The upstream SELinux kernel documentation is the clearest reference for what those contexts and booleans actually control.
  3. Shell scripting. The requirement is modest, covering conditionals, loops, positional parameters and command substitution, but administrators who work interactively rather than in scripts often have not written one from scratch in years.

An honest audit against the objective table is worth more than any study plan. Mark each of the ten groups as fluent, rusty or unseen, and the rusty and unseen entries become the entire revision list.

What Does Persistence After Reboot Actually Demand?

Red Hat states that on all of its performance-based exams, configurations must persist after a reboot without intervention. In practice that means a change made only in memory scores zero, however correct it looked at the time. The graded artefact is the system as it comes back up, not the system as you left it.

This rule quietly rewrites several objectives. Setting an IP address with a live command is not the same as configuring it to be there after a restart. Mounting a file system by hand is not the same as writing a persistent entry keyed to a UUID or label, which is exactly why the storage objective specifies mounting at boot by universally unique ID or label rather than simply mounting. Enabling a service for the current session is not the same as configuring it to start at boot, which is why the maintenance group separates starting a service from configuring it to start automatically.

The habit worth building is simple and slightly uncomfortable: reboot during practice, on purpose, before you believe a task is finished. Candidates who only reboot at the end of a practice session discover several broken tasks at once and have no time left to trace which change caused which failure.

Why Does the RHEL 10 Version Matter?

Red Hat states that the current EX200 exam is based on Red Hat Enterprise Linux 10. Version matters here more than on a knowledge exam, because you are working in a real environment: default tools, package behaviour and command availability are whatever the shipped release provides, not whatever your production estate happens to run.

The clearest example sits in the software objective. Alongside configuring access to RPM repositories and installing RPM packages, the syllabus now asks for configuring access to Flatpak repositories and installing and removing Flatpak packages. An administrator whose experience stops at earlier releases may never have handled Flatpak on a server at all, and it is not something you can bluff at a prompt.

The practical instruction is to practise on the release the exam targets. Rehearsing on an older RHEL build, or on a downstream rebuild that lags behind, risks muscle memory that produces the right idea and the wrong command. Where your workplace estate is older, a lab virtual machine on the current release is the difference between recognising an environment and meeting it for the first time under a clock.

What Are the EX200 Exam Details?

EX200 runs for 150 minutes, contains 20 items, and is passed at 210 out of 300. The fee is $400 US dollars and scheduling runs through Pearson VUE. Those numbers reframe the objective list immediately: ten groups of tasks compressed into two and a half hours leaves very little room for hesitation.

Detail Value
Exam name Red Hat Certified System Administrator (RHCSA)
Exam code EX200
Items 20
Duration 150 minutes
Passing score 210 of 300
Price $400 USD
Scheduling Pearson VUE
Format Performance based, tasks completed on a live system
Platform version Red Hat Enterprise Linux 10
Recommended training RH124, RH134, or the RH199 rapid track course

A score of 210 out of 300 is 70 percent, which sounds forgiving until you remember that tasks are graded on outcome. There is no partial credit for the right approach applied to the wrong device. Budget the 150 minutes deliberately: leave a genuine reserve at the end for a reboot and a verification pass, because the alternative is discovering a non persistent change after the session has closed. Red Hat’s own EX200 exam page is the reference of record for format and objectives.

How Should You Work Through the Objectives?

Work them on a live system in the order the machine builds up, not the order the syllabus prints. Storage before file systems, file systems before services that depend on them, networking before anything remote, and security last so that SELinux and firewall rules are applied to a system that already works. Each step ends with a reboot.

Five stage RHCSA preparation sequence from building a lab through storage and services drills to a timed run
  1. Build a lab on Red Hat Enterprise Linux 10 with two spare disks attached, because several storage objectives are impossible to rehearse convincingly on a single disk.
  2. Audit yourself against the ten objective groups honestly, marking each as fluent, rusty or unseen, and treat the rusty and unseen entries as the whole revision list.
  3. Rehearse the storage chain from physical volume to mounted file system in one continuous run, then reboot and confirm every mount returned without intervention.
  4. Practise the running systems and networking objectives next, enabling each service and address so that it survives a restart rather than only working in the current session.
  5. Finish on the security group with SELinux left enforcing throughout, repairing contexts and setting port labels and booleans rather than lowering the mode to make a task pass.
  6. Run a full timed rehearsal of 150 minutes with no notes and no internet, using only the documentation that ships with the system, and reboot before you call it complete.

The sequence matters because the objectives are interdependent. Practising SELinux contexts on a file system you did not build yourself teaches half the lesson, and the half it omits is the half the exam grades.

Where RHCSA Leads Next

RHCSA is the gateway credential in Red Hat’s programme rather than a terminal one. Red Hat requires it before either engineer-level credential: you must hold RHCSA to become a Red Hat Certified Engineer in Enterprise Linux and to become a Red Hat Certified Engineer in Ansible. Red Hat sets all of this out on its own RHCSA credential page. The credential is also cited by administrators certifying under organisational mandates, including the DoD 8570 directive.

Red Hat names the next step directly, pointing candidates toward Red Hat Linux Automation with Ansible and its associated exam. That progression is coherent: RHCSA proves you can configure one system by hand, and the automation credential proves you can do the same work across many without repeating yourself.

The audience Red Hat describes for EX200 is broader than it first appears. It includes experienced administrators seeking validation, students completing the RH124 and RH134 sequence, lapsed engineers recertifying, and DevOps practitioners who want container fundamentals grounded in real system administration. If you already hold the credential and are weighing the engineer track, our RHCE exam guide covers what changes at that level.

It is worth being clear about why a Linux administration credential still carries weight. Linux remains the dominant platform for professional server and development work, a position the independent Stack Overflow developer survey continues to record year after year. A credential that proves you can operate it under time pressure, without notes, is not a paper qualification.

Frequently Asked Questions

What are the RHCSA exam objectives?

Ten groups of practical tasks: essential tools, managing software, simple shell scripts, operating running systems, local storage, file systems, deploying and maintaining systems, basic networking, users and groups, and managing security including SELinux and firewalld.

Is the RHCSA exam multiple choice?

No. EX200 is performance based. You complete real tasks on a live Red Hat Enterprise Linux system and the machine is graded on its final state, so there are no answer options to select at any point.

How long is the RHCSA exam?

One hundred and fifty minutes for 20 items. That is roughly seven and a half minutes per item, and the budget has to include time to reboot and verify that your configurations came back correctly.

What is the passing score for EX200?

Two hundred and ten out of 300, which works out at 70 percent. Because grading is based on the state of the system, there is no partial credit for a correct method applied to the wrong target.

What version of Red Hat Enterprise Linux is the RHCSA based on?

Red Hat states the current exam is based on Red Hat Enterprise Linux 10. Practising on an older release risks learning commands and defaults that differ from the environment you will actually be given.

How much does the RHCSA exam cost?

Four hundred US dollars, scheduled through Pearson VUE. Red Hat also offers the RH199 rapid track course bundled with the exam for candidates who prefer training and testing as a single package.

Can you use documentation during the RHCSA exam?

Only what ships with the product. Internet access is not provided, and no notes, books or electronic documents may be brought in. Man pages and the installed documentation tree remain available on the system.

Do RHCSA configurations need to survive a reboot?

Yes. Red Hat requires that configurations persist after a reboot without intervention on all performance-based exams, so a change that exists only in the running session scores nothing at all.

What are the prerequisites for the RHCSA exam?

Red Hat recommends RH124 and RH134, or the RH199 rapid track course that combines them, or comparable working experience administering Red Hat Enterprise Linux. There is no formal barrier to booking without them.

Is RHCSA required before RHCE?

Yes. Red Hat states you must hold RHCSA to become a Red Hat Certified Engineer in Enterprise Linux and to become a Red Hat Certified Engineer in Ansible, which makes EX200 the entry point to the whole track.

Conclusion

The RHCSA exam objectives are a task list, and reading them as a topic list is the single most common preparation mistake. EX200 gives you 150 minutes, 20 items and a live Red Hat Enterprise Linux 10 system, then grades the machine rather than your reasoning. Everything about that format rewards rehearsal over revision: build the storage stack yourself, leave SELinux enforcing, and reboot before you believe anything is done.

Audit yourself group by group against the ten objectives, turn the rusty and unseen entries into lab work, and finish with one full timed run under exam conditions. The RHCSA certification overview is a useful companion when you are weighing whether the credential fits your current role, and the objective table above is the checklist worth returning to until every line reads as fluent.

Rating: 0 / 5 (0 votes)

The post The RHCSA Exam Objectives Are a Task List, Not a Topic List appeared first on iSecPrep.

]]>
You Can Miss Twelve Questions on the ACP-520 Certification https://www.isecprep.com/2026/09/03/acp-520-atlassian-organization-admin-pass-mark/ Thu, 03 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87507 A pass mark written as a count rather than a percentage turns preparation into budgeting. Twelve wrong answers is the allowance, and two of the four domains decide how it gets spent.

The post You Can Miss Twelve Questions on the ACP-520 Certification appeared first on iSecPrep.

]]>

Twelve. That is how many questions you are allowed to get wrong on ACP-520, because Atlassian publishes the pass mark as a raw count rather than a percentage: 33 out of 45. Most vendors give you a percentage, or worse, a scaled score that hides how many marks are actually in play. Here the arithmetic is done for you before you book.

There is a second structural detail worth knowing before any studying starts. Atlassian says each question on the refreshed exam has one correct answer and two distractors, so every item is a choice between three options rather than four or five. Combined with a 90-minute limit for 45 questions, that shapes both the pace and the guessing maths. This guide covers the four weighted domains behind the ACP-520 certification, converts each weight into questions against that 33-mark target, and shows where the twelve permitted mistakes are cheapest to spend.

Why Does Atlassian Publish the ACP-520 Pass Mark as 33 of 45?

Because a raw count is unambiguous in a way a percentage is not. ACP-520 has 45 questions and a pass mark of 33, which is 73.3 percent, but expressing it as 33 removes any doubt about rounding or about whether unscored items are included. You know exactly how many correct answers you need and exactly how many you can lose.

Three panels showing how the twelve permitted ACP-520 mistakes are used up under different scenarios

That clarity is genuinely useful during preparation. A percentage encourages you to think in proportions; a count encourages you to think in questions, which is how the exam is actually experienced. Twelve wrong answers is a budget, and it can be allocated deliberately across the four domains rather than hoped for.

It also sets expectations honestly. Seventy-three percent is a demanding bar for an administration exam, and dressing it as 33 out of 45 makes that obvious immediately rather than after a calculation. Candidates who plan around a comfortable 60 percent will be caught out.

What Are the Four ACP-520 Domains?

ACP-520 publishes four weighted topics. User management and access control is the largest at 34 percent. Atlassian organizations and App and site management sit level at 25 percent each. Atlassian Guard and advanced administration closes the syllabus at 16 percent.

Topic Weight Roughly what it governs
User management and access control 34% Managed accounts, groups and default groups, product access and the permissions that follow from where a user sits
Atlassian organizations 25% The organization as the container above sites, including how multiple sites, billing and organization-level settings relate to each other
App and site management 25% Managing products and apps across sites, and the administrative work that sits between the organization and an individual product
Atlassian Guard and advanced administration 16% Identity, domain verification, authentication policies and the security controls layered on top of ordinary administration

The interesting shape here is the near-tie in the middle. Two domains at exactly 25 percent means neither organizations nor app and site management can be treated as the main event, and the syllabus refuses to pick a favourite between the container and its contents.

How Many Questions Does Each Domain Carry?

Applying the weights to 45 questions gives roughly 15 on user management and access control, 11 each on Atlassian organizations and on app and site management, and 7 on Atlassian Guard and advanced administration. Against a target of 33 correct, the largest domain alone supplies almost half the marks you need.

Topic Weight Approximate questions of 45
User management and access control 34% 15
Atlassian organizations 25% 11
App and site management 25% 11
Atlassian Guard and advanced administration 16% 7

Set the twelve-mistake budget against that and the strategy writes itself. Losing the whole Guard domain costs seven, leaving five across the other 38 questions, which is survivable but uncomfortable. Losing half of user management costs seven or eight on its own. Working through ACP-520 exam material domain by domain is the quickest way to find out which of those two scenarios you are actually in.

What Is the ACP-520 Exam Format?

ACP-520 delivers 45 questions in 90 minutes at a price of $249 US dollars, with a pass mark of 33 correct answers. Scheduling runs through Certmetrics. Ninety minutes across 45 questions is two minutes each, which is generous, and Atlassian has said the refreshed exam is designed around thinking rather than racing the clock.

Detail Value
Exam name Atlassian Certified Professional: Organization Admin
Exam code ACP-520
Questions 45
Duration 90 minutes
Passing score 33 of 45
Price $249 USD
Scheduling Certmetrics
Delivery Proctored online, and available at test centres
Recommended training Atlassian Cloud Organization Admin

The three-option structure is the detail most guides miss. Atlassian describes each question as having a single correct answer and two distractors, which means a pure guess is a one-in-three shot rather than one in four. Across twelve uncertain questions that difference is material, and it argues for answering everything rather than leaving blanks.

The credential itself dates from May 2023 and was later refreshed with new content, a detail Atlassian set out in its own ACP-520 update announcement. Study material written before that refresh should be treated with care.

Why Is User Management the Largest Domain?

Because at organization level, user management is where almost every real administrative decision lands. The 34 percent domain covers managed accounts, groups including default and special groups, and product access, and roughly 15 of the 45 questions come from it. Nothing else on the exam has that much surface area.

The reason is structural. In Atlassian Cloud, what a person can do is a product of which account they hold, which groups they belong to, and what those groups grant across which products. Change one of the three and the outcome changes, which makes scenario questions natural and makes memorising individual screens useless.

Default groups are the classic trap. Adding a user to a site usually places them in a default group whose permissions the administrator did not consciously choose, and the exam tests whether you understand that consequence rather than whether you can find the setting. The general principle behind these questions, that access should be granted deliberately and least-privilege by default, is set out well in the OWASP access control guidance.

What Does Atlassian Guard Add to the Exam?

The security layer that ordinary administration does not reach. At 16 percent, roughly seven questions, Atlassian Guard and advanced administration is the smallest domain, and it deals with identity: verifying domains, claiming accounts, applying authentication policies and controlling how people prove who they are before any product permission applies.

Small does not mean skippable here. Seven questions is more than half the twelve-mistake budget, so a candidate who ignores Guard entirely has almost no margin left for the other three domains. It is also the domain least likely to be covered by day-to-day experience, because many administrators inherit an identity configuration rather than building one.

Automated user provisioning is the concept that ties this domain together. The industry standard behind it is described in the SCIM protocol specification, and understanding why provisioning exists makes the exam’s questions about lifecycle and deprovisioning considerably easier to reason through.

Organization Level Against Site Level

The single most useful mental model for ACP-520 is the boundary between an organization and a site. An organization contains one or more sites, holds billing, owns managed accounts and applies security policy. A site holds products and their own configuration. Half the exam is really asking which of the two a given setting belongs to.

Two panels separating Atlassian organization level responsibilities from site level ones

Once that boundary is clear, several domains simplify at once. Billing questions belong to the organization. Product access questions straddle both. App management sits at site level but is administered from above. The 25 percent Atlassian organizations domain exists precisely to test whether you hold this model.

It is also where candidates arriving from a single-site background struggle most. Administering one Jira site for years teaches the site layer thoroughly and the organization layer barely at all, which is exactly the gap this credential is designed to expose. The earlier ACP-520 preparation strategies guide is worth reading alongside this one for that reason.

How Useful Is the Free Practice Exam?

More useful than most, because Atlassian provides it free and allows two attempts, and because it runs on Certiverse, the same platform that delivers the real exam. That means it doubles as a rehearsal of the interface as well as a check on knowledge, which removes a genuine source of exam-day friction.

Use both attempts deliberately rather than back to back. The first is best taken early, before serious study, to find which of the four domains is weakest while there is still time to act on it. The second belongs a few days before the real sitting, as a confidence check rather than a learning exercise.

Atlassian also supplies a free certification preparation course alongside it. Between the free course and the free practice attempts, the only unavoidable cost is the $249 exam fee itself, which is worth knowing before paying for third-party material.

How Should You Spend Your Twelve Permitted Mistakes?

Deliberately, and mostly on the two 25 percent domains rather than on the largest or the smallest. User management supplies too many marks to give away, and Guard is small enough that losing all of it eats more than half the budget. The plan below works outward from the boundary model that makes everything else legible.

  1. Start by fixing the organization and site boundary in your head, because roughly half the exam is really asking which of the two layers a given setting belongs to.
  2. Take the free practice exam early, before serious study, so the weakest of the four domains is identified while there is still time to change the plan.
  3. Give user management and access control the largest share of study time, concentrating on managed accounts, default groups and how product access follows from group membership.
  4. Work the Atlassian Guard domain next despite its size, since seven questions is more than half the twelve-mistake budget and it is the material least likely to be covered by daily work.
  5. Cover the two 25 percent domains together, treating organizations as the container and app and site management as its contents, so the overlap between them is learned once.
  6. Use the second free practice attempt a few days before the exam as a confidence check rather than a learning exercise, and answer every question on the day because a guess is one in three.

Three to five weeks suits an administrator already working in Atlassian Cloud, and closer to eight for someone who has only ever administered a single site. Anyone weighing this credential against the wider Atlassian ladder will find the ACP-520 resources roundup a useful companion when deciding what to study from.

Frequently Asked Questions

What is the passing score for ACP-520?

Thirty-three correct answers out of 45, which works out at 73.3 percent. Atlassian publishes it as a raw count rather than a percentage, so you can miss twelve questions and still pass.

How many questions are on the ACP-520 exam?

Forty-five, with a 90-minute limit. That is two minutes per question, and Atlassian has said the refreshed exam is built around thinking rather than racing the clock.

How much does the ACP-520 certification cost?

Two hundred and forty-nine US dollars. Scheduling runs through Certmetrics, and the free preparation course and free practice attempts mean the fee is the only unavoidable cost.

How many answer options does each question have?

Three. Atlassian describes each question as having a single correct answer and two distractors, so a pure guess is a one-in-three chance rather than one in four.

Which ACP-520 domain is the largest?

User management and access control at 34 percent, roughly 15 of the 45 questions. It covers managed accounts, default and special groups, and how product access follows from group membership.

Is the ACP-520 exam proctored?

Yes. It is delivered as a proctored online exam that can be taken from home or an office, and it is also available at testing centres for candidates who prefer that.

Is there a free ACP-520 practice exam?

Yes. Atlassian offers a practice exam on Certiverse that can be taken twice at no cost, alongside a free certification preparation course for the credential.

What is the difference between ACP-520 and a Jira administration certification?

ACP-520 sits at organization level, above individual products. Jira administration credentials cover configuration inside one product, whereas this exam covers sites, billing, managed accounts and security policy across them.

Does Atlassian Guard appear on the exam?

Yes, in its own domain worth 16 percent, roughly seven questions. It covers domain verification, account claiming, authentication policies and the identity layer that sits above product permissions.

How long does preparation usually take?

Three to five weeks for an administrator already working in Atlassian Cloud, and closer to eight weeks for someone whose experience is limited to administering a single site.

Conclusion

ACP-520 is unusually transparent about what it wants. Thirty-three of 45, three options per question, four weighted domains and a free practice route on the real delivery platform. Nothing about the assessment is hidden, which means preparation can be planned as arithmetic rather than guessed at.

Spend the effort where the marks are: the organization and site boundary first because it explains the rest, then user management and access control for the largest single block, then Atlassian Guard despite its size because seven questions is over half the mistake budget. Take the free practice attempt early rather than late, and work through exam material domain by domain until the twelve permitted mistakes look like a comfortable margin instead of a target.

Rating: 0 / 5 (0 votes)

The post You Can Miss Twelve Questions on the ACP-520 Certification appeared first on iSecPrep.

]]>
Eight Methods Carry the Dell Data Science Foundations Certification https://www.isecprep.com/2026/09/03/dell-data-science-foundations-d-ds-fn-23-weightings/ Thu, 03 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87489 Six weighted objectives, and one of them is four times the size of the smallest. Converting the D-DS-FN-23 blueprint into question counts changes where a study week is worth spending.

The post Eight Methods Carry the Dell Data Science Foundations Certification appeared first on iSecPrep.

]]>

Forty percent of one exam, spread across eight methods that the blueprint names out loud: k-means clustering, association rules, linear regression, logistic regression, naive Bayesian classifiers, decision trees, time series analysis and text analytics. That single objective is the Dell Data Science Foundations certification in miniature. D-DS-FN-23 puts 60 questions in front of you over 90 minutes, asks for 60 percent, and costs $230, and almost half of what it asks about is the theory, application and interpretation of those eight techniques.

The rest of the paper is not filler, though. A second domain worth 22 percent covers the big data tooling underneath the methods, and a third worth 15 percent covers the statistics you need before any of the modelling makes sense. Read the weightings as a map and the study plan writes itself. This guide walks all six domains, converts each weight into questions on a 60-item paper, and shows where candidates tend to spend time they cannot afford.

Why Do Eight Methods Carry Forty Percent of D-DS-FN-23?

Because Dell built the Data Science Foundations certification around technique rather than tooling. The largest objective on D-DS-FN-23 is worth 40 percent and asks you to describe the theory, application and interpretation of results for eight specific methods. No other domain comes close. Method fluency is the credential’s definition of a foundation.

Four cards grouping the eight D-DS-FN-23 analytics methods by the question each one answers

That design choice separates this exam from most vendor credentials, which usually reward knowing a product. Here the product barely appears. You are asked whether you can tell when association rules are the right instrument and when a decision tree is, and then whether you can read what the output means once the model has run.

It also sets the bar for what “interpretation” means. The objective does not stop at application. A question can hand you a result and ask what it supports, which is a different skill from knowing how to produce it. Candidates who can run a logistic regression but cannot explain what an odds ratio implies for the business tend to lose marks in exactly this domain.

The Six Domains and What Each Weight Buys You

D-DS-FN-23 publishes six weighted objectives that sum to 100 percent. They run from a 5 percent opener on big data and the data scientist role, through the analytics lifecycle and initial data analysis, into the 40 percent advanced analytics block, then a 22 percent tooling domain and a 10 percent close on communicating and operationalizing the work.

Objective Weight What it actually asks
Big Data, Analytics, and the Data Scientist Role 5% Characteristics of big data, the business drivers behind analytics, and the data scientist role with its related skills
Data Analytics Lifecycle 8% The purpose and sequence of the phases, then Discovery, Data preparation, Model planning and Model building with their activities and roles
Initial Analysis of the Data 15% Basic R commands for exploration, the important statistical measures and effective visualizations, and hypothesis testing used to evaluate a model
Advanced Analytics: theory, application and interpretation for eight methods 40% K-means clustering, association rules, linear regression, logistic regression, naive Bayesian classifiers, decision trees, time series analysis and text analytics
Advanced Analytics for Big Data: technology and tools 22% Big data technology challenges, MapReduce and Apache Hadoop, the Hadoop ecosystem, in-database analytics and SQL essentials, plus window functions, ordered aggregates and MADlib
Operationalizing an Analytics Project and Data Visualization Techniques 10% Communicating findings, building presentations for specific audiences, and planning effective visualizations

Two of the six are worth less than a tenth each. The first objective at 5 percent is the definitional one, and candidates routinely over-study it because it is the first thing they read. It is the smallest domain on the paper.

How Many Questions Does Each Analytics Method Get?

Applying the published weights to a 60-question paper gives roughly 24 questions in the advanced analytics domain, 13 in the big data tooling domain, 9 in initial analysis, 6 in operationalizing, 5 in the lifecycle and 3 in the opening domain. Split those 24 across eight named methods and each one is worth about three questions.

Three questions per method is the number worth carrying into study. It means no single technique can be skipped safely, because dropping one costs roughly 5 percent of the paper when the whole margin above a 60 percent pass is 24 marks. It also means no single technique deserves a week of deep theory either.

Domain Weight Approximate questions of 60
Advanced Analytics, eight methods 40% 24
Advanced Analytics for Big Data 22% 13
Initial Analysis of the Data 15% 9
Operationalizing and Visualization 10% 6
Data Analytics Lifecycle 8% 5
Big Data and the Data Scientist Role 5% 3

Treat those counts as arithmetic on the published weights rather than a guarantee about any one form. The useful conclusion is proportional: the eight methods plus the tooling domain together account for close to two thirds of the exam, so two thirds of preparation belongs there. Working through D-DS-FN-23 sample questions method by method is the quickest way to find which of the eight you cannot yet interpret under time.

What Is the D-DS-FN-23 Exam Format?

D-DS-FN-23 is a 60-question exam with a 90-minute limit, a 60 percent passing score and a $230 price in US dollars. Registration runs through Pearson VUE. Ninety minutes across 60 questions works out at 90 seconds each, which is comfortable for definitional items and tight for anything asking you to read a result.

Detail Value
Exam name Dell Data Science Foundations 2023
Exam code D-DS-FN-23
Questions 60
Duration 90 minutes
Passing score 60%
Price $230 USD
Registration Pearson VUE
Recommended training Data Science Foundations

Sixty percent of 60 questions is 36 correct answers, so the margin is 24. That is a genuinely forgiving threshold by certification standards, and it is why the weighting map matters more than perfection in any one area. You can be weak somewhere. You cannot be weak across the 40 percent domain.

Booking runs through Pearson VUE for Dell, and the exam is offered in English, French and Japanese. The Dell exam listing publishes the same six topic weightings used above.

Big Data Tools the Blueprint Names by Hand

The 22 percent tooling domain is unusually specific for a foundations exam. It names MapReduce and Apache Hadoop directly, then the Hadoop ecosystem and its product use cases, then in-database analytics and SQL essentials, and finally three advanced SQL techniques: window functions, ordered aggregates and MADlib. Nothing there is left to inference.

Hadoop and MapReduce

The objective asks for the nature and use of MapReduce, not for the ability to write a job. Expect questions about what the model is good at, where it breaks down, and which ecosystem component solves which problem. Reading the Apache Hadoop project pages for the component list is a faster route than any summary, because the exam is asking about use cases rather than internals.

SQL that goes past SELECT

Window functions and ordered aggregates are the part candidates underestimate. They are examined as analytics tools, so the question is usually what a window function lets you compute without leaving the database, rather than syntax recall. MADlib sits alongside them as the in-database machine learning library, and the Apache MADlib documentation is the reference of record for what it actually offers.

The common thread across this domain is the argument for moving computation to the data instead of moving data to the computation. If you can articulate why that matters at scale, most of the 13 questions here become straightforward.

How Much Statistics Do You Need Before the Modelling?

Enough to pass a 15 percent domain that covers exploratory analysis with basic R commands, the important statistical measures, effective visualizations, and the theory, process and analysis of results for hypothesis testing. Initial Analysis of the Data is the third-largest objective on D-DS-FN-23 and it functions as the prerequisite for the 40 percent block above it.

Hypothesis testing is the piece to take seriously. The blueprint ties it explicitly to evaluating a model, which is a narrower framing than a statistics course would use. You need to know what a test is telling you about whether a result is worth acting on, and what it is not telling you.

R appears here as an exploration language rather than a development one. The objective asks how basic commands are used to explore and analyse data, so familiarity with reading R output matters more than writing it fluently. Candidates who arrive from Python find this domain the least comfortable, and it is worth a deliberate week rather than an afternoon.

Where Does the Data Analytics Lifecycle Fit?

At 8 percent, or roughly five questions, the Data Analytics Lifecycle is a small domain that pays back quickly. It asks for the purpose and sequence of the phases, then for the detail of four of them: Discovery, Data preparation, Model planning and Model building, each with its activities and the roles associated with it.

The word “roles” is doing real work in that objective. Questions here are as likely to ask who does something as what gets done, which reflects how Dell frames the credential: a data scientist working inside a project team rather than alone. Knowing that the business sponsor belongs in Discovery is examinable content.

Because it is only five questions, the efficient approach is to learn the phase order cold and the four detailed phases properly, then stop. The lifecycle also gives the rest of the syllabus a spine. Initial analysis belongs to Data preparation, the eight methods belong to Model planning and Model building, and the 10 percent operationalizing domain is what happens after.

Who Is This Foundations Credential Actually For?

Dell points the Data Science Foundations certification at systems engineers and technical consultants, and describes it as validating the practical foundation skills a data scientist needs to join big data and analytics projects immediately. It is a starting credential, not a specialist one, and the syllabus is deliberately vendor-neutral in its method coverage.

Four tiles showing what the Dell Data Science Foundations credential proves a holder can do

In practice that suits three groups. Infrastructure people who now support analytics platforms and need the vocabulary. Analysts who want a structured method inventory rather than a tool certificate. And consultants who need something on paper before joining a project team where the modelling is done by someone more senior.

If your goal is the advanced analytics tier rather than the foundation, the natural next step inside Dell’s own track is Dell Data Science Optimize, which goes considerably deeper into method selection and tuning. Foundations first is the sensible order, because the Optimize syllabus assumes the eight methods are already familiar.

One practical note on availability: the exam is published in English, French and Japanese, which is broader than many Dell credentials and matters if English is not your working language for statistical terminology.

How Should You Sequence Preparation for D-DS-FN-23?

Work outward from the lifecycle, because it organises everything else, then spend the bulk of your time on the eight methods and the tooling domain that together carry 62 percent of the paper. The sequence below follows the dependency order rather than the syllabus order, which puts the small domains first for a reason.

  1. Learn the Data Analytics Lifecycle phase order first, along with the activities and roles inside Discovery, Data preparation, Model planning and Model building, because every later domain hangs off one of those phases.
  2. Cover the 15 percent initial analysis domain next, working through basic R exploration output, the core statistical measures and hypothesis testing, since the advanced analytics block assumes all three.
  3. Take the eight methods one at a time and force yourself to write, for each, what it is for, what input it needs and what its output actually means in business terms.
  4. Move to the big data tooling domain, concentrating on MapReduce use cases, the Hadoop ecosystem components, and why window functions, ordered aggregates and MADlib let analytics happen inside the database.
  5. Finish with the 10 percent operationalizing and visualization domain, which is short, concrete and easy to pick up once you know what the models produce.
  6. Test yourself against sample items method by method, and treat any of the eight you cannot interpret under 90 seconds as unfinished work.

Six weeks is a realistic run at this for someone already working around analytics, and closer to ten for a candidate meeting hypothesis testing and Hadoop for the first time. Browsing the wider Dell certification hub is worth doing before you book, because the Proven Professional track has several adjacent credentials and picking the wrong tier wastes a fee.

Frequently Asked Questions

How many questions are on the D-DS-FN-23 exam?

Sixty questions with a 90-minute limit, which is 90 seconds per question. That is generous for definitional items and tight for questions that ask you to read and interpret a model result.

What is the passing score for Dell Data Science Foundations?

Sixty percent, so 36 correct answers out of 60. The margin is 24 marks, which is forgiving by certification standards but not enough to survive skipping the 40 percent advanced analytics domain.

How much does the D-DS-FN-23 exam cost?

Two hundred and thirty US dollars, booked through Pearson VUE. Dell does not publish the price on its own exam listing, so that figure comes from the money-site syllabus page.

Which eight methods does the advanced analytics domain cover?

K-means clustering, association rules, linear regression, logistic regression, naive Bayesian classifiers, decision trees, time series analysis and text analytics. All eight are named individually on the blueprint.

Do you need to write R code for this exam?

No. The objective asks how basic R commands are used to explore and analyse data, which is a reading skill rather than a development one. Being able to interpret R output matters more than writing it.

What programming or SQL knowledge does D-DS-FN-23 assume?

SQL essentials plus three named advanced techniques: window functions, ordered aggregates and MADlib. They are examined as analytics instruments, so expect questions about what they let you compute rather than syntax recall.

Which languages is the exam offered in?

English, French and Japanese, according to Dell’s own exam listing. That is broader coverage than several other Dell credentials offer, which helps if statistical terminology is easier for you in French or Japanese.

Is D-DS-FN-23 tied to Dell products?

Barely. The syllabus is built around methods, the analytics lifecycle and open technology such as Apache Hadoop and MADlib. The credential carries Dell’s name but tests portable data science knowledge.

Who does Dell say this certification is for?

Systems engineers and technical consultants. Dell frames it as validating practical foundation skills so the holder can participate immediately in big data and analytics projects rather than lead them.

How long should preparation take?

Roughly six weeks for someone already working near analytics, and closer to ten weeks for a candidate meeting hypothesis testing, Hadoop and the eight methods for the first time.

Conclusion

The weighting map is the whole story on D-DS-FN-23. Two domains, the eight advanced analytics methods at 40 percent and the big data tooling block at 22 percent, carry 62 percent of a 60-question paper between them. The other four objectives are worth 38 percent combined, and the smallest of them is the definitional opener most candidates read first and study hardest.

Plan around that and the exam becomes a manageable piece of work: learn the lifecycle for structure, get comfortable reading R output and hypothesis tests, then give the eight methods the time their share of the marks deserves. Once each method is something you can explain rather than merely name, sample items covering all eight are the fastest way to confirm you are ready to book.

Rating: 0 / 5 (0 votes)

The post Eight Methods Carry the Dell Data Science Foundations Certification appeared first on iSecPrep.

]]>
H3C Certification Is a Real Ladder You Have Probably Never Climbed https://www.isecprep.com/2026/09/02/h3c-gb0-192-h3cne-rs-exam-sections/ Wed, 02 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87447 Seven of the eight GB0-192 sections describe standards that behave the same on anyone's hardware, so the study load is smaller than the unfamiliar vendor name suggests. Only the Comware layer is genuinely new.

The post H3C Certification Is a Real Ladder You Have Probably Never Climbed appeared first on iSecPrep.

]]>

There is a complete three-tier networking certification ladder that a great many working engineers have never once seen mentioned. H3C, the enterprise networking vendor spun out of the old 3Com joint venture, runs its own engineer, senior engineer and expert credentials, and the entry rung is GB0-192, Routing and Switching Essentials, which awards H3CNE-RS+. In parts of the world it is a hiring requirement. In English-language networking discussion it is almost invisible.

That gap is worth closing, because the exam itself is not obscure at all. GB0-192 asks 50 questions in 60 minutes for $165 USD, needs 600 out of 1000 to pass, and covers eight sections that run from CSMA/CD and MAC addressing all the way to SDN and NFV. This guide works through all eight, what each genuinely tests, how much of it transfers from any other networking background, and how to prepare without a rack of Comware kit.

Why Have Most Network Engineers Never Heard of H3CNE-RS+?

Because H3C’s certification programme is documented mainly for markets where H3C equipment is common, and English-language networking discussion is dominated by vendors with a larger Western install base. The credential is not small or informal. H3C describes H3CNE-RS+ as covering the planning, design, configuration and maintenance of small and medium-sized networks, and it is awarded by New H3C on passing a single exam.

The practical consequence for a reader is that the usual signals are missing. There are few independent study blogs, almost no video walkthroughs in English, and very little forum discussion. What there is instead is an unusually complete official syllabus, which is why this article works from the published sections rather than from community folklore.

H3C is not Huawei, and the distinction matters

The two are frequently conflated because both are large Chinese networking vendors with their own certification programmes. They are separate companies with separate equipment lines, separate operating systems and entirely separate credentials. H3C’s platform is Comware; the exam names it directly. Studying Huawei material for an H3C exam will get the vendor-neutral half right and the device half wrong.

The full certification structure is set out on the official H3CNE-RS+ page, which also confirms that this exam has no advanced certification prerequisites, so it can be sat as a first H3C credential with nothing behind it.

What Are the Eight GB0-192 Exam Sections?

GB0-192 publishes eight sections and no weightings for any of them. They run from computer network fundamentals and H3C device operation, through LAN switching, advanced TCP/IP and IP routing, into secure branch configuration and WAN access, and close with a section on virtualization, SDN and NFV.

Section Core content
Computer Network Fundamentals Network concepts and classification, the OSI and TCP/IP models, LAN and Ethernet fundamentals, CSMA/CD, MAC addressing, IP principles, ARP and proxy ARP, and TCP and UDP behaviour
Getting Started with H3C Network Devices Router and switch components, the Comware system, command line basics, the device file system, configuration and system file management, boot process, ping, tracert and debugging
LAN Switching Switch learning and forwarding logic, VLANs and 802.1Q trunks, STP, RSTP and MSTP, port security with 802.1x, port isolation and binding, link aggregation, and WLAN basics
Advanced TCP/IP Subnetting, VLSM and CIDR, DNS structure and resolution, FTP and TFTP, DHCP and DHCP relay, and IPv6 addressing, Neighbor Discovery and autoconfiguration
IP Routing Routing principles, tables, sources, metrics, priorities and loops, direct and static routes, inter-VLAN routing, routing protocol classification, and OSPF basics including DR election and LSAs
Configuring a Secure Branch Network ACL types and working principles, packet filtering on firewalls, and NAT covering Basic NAT, NAPT, Easy IP, NAT Server and NAT ALG
WAN Access and Interconnection WAN technologies, connection methods and interface standards, PPP with LCP, NCP, PAP and CHAP, and segment routing fundamentals
The Evolution of Network Technologies Virtualization concepts across compute, storage and network, SDN background, architecture and value, and NFV concepts, standards bodies and H3C’s own NFV architecture

With eight sections, 50 questions and no published weightings, the even-distribution assumption gives roughly six questions per section. That is a working planning figure rather than a published one, and the honest position is that no section can be written off as cheap because there is no basis on which to do it. The full objective detail sits on the GB0-192 exam topics listing.

What Is the GB0-192 Exam Format?

GB0-192 is 50 questions in 60 minutes at $165 USD, with a passing score of 600 out of 1000. Registration runs through Prometric rather than Pearson VUE, which is worth noting because it is the less common of the two routes for networking exams. The recommended training is H3C’s own Routing and Switching Essentials V1.0 course.

Specification Detail
Exam number GB0-192
Credential awarded H3CNE-RS+
Questions 50
Duration 60 minutes
Passing score 600 out of 1000
Price $165 USD
Registration Prometric
Prerequisites None
Validity Three years

The clock is tighter than it looks

Fifty questions in 60 minutes is 72 seconds each, which is brisk for a syllabus that includes subnet arithmetic. Subnetting, VLSM and CIDR calculations all appear in the Advanced TCP/IP section, and a subnet question you have to work out on paper eats two or three times the average. The way to protect the clock is to make the arithmetic automatic before exam day rather than to hurry it on the day.

One detail the money-site syllabus page does not carry, and which comes from H3C directly: the credential is valid for three years. Plan the exam with that in mind, because a certification earned early in a job search is a certification that expires early in the role that follows it.

How Much of GB0-192 Is Vendor-Neutral Networking?

Most of it. Of the eight sections, only one is explicitly about H3C equipment, and a second is partly so. Computer Network Fundamentals, Advanced TCP/IP, IP Routing and much of LAN Switching describe standards that behave the same on any vendor’s hardware, which means an engineer arriving from another platform already knows a substantial share of the material.

GB0-192 study transfer split showing seven sections of vendor-neutral standards and concepts against one section of H3C Comware device material

That is genuinely useful for planning. Someone with a solid grounding in the OSI model, subnetting, VLANs, spanning tree and OSPF is not starting this exam from zero; they are starting from the device half. The section that will actually be new is Getting Started with H3C Network Devices, covering Comware, its command line, its file system and its boot process.

Where the standards are the same, the exam still names them

The syllabus does not paraphrase. It names 802.1Q for VLAN tagging and 802.1x for port access control directly, so the specifications are worth reading at source rather than through a vendor’s summary. The IEEE’s own page for 802.1Q virtual LANs is the reference, and the same is true of 802.1X port-based control for the port security objectives.

The reverse warning applies too. Vendor-neutral does not mean identical syntax. Everything you know about how spanning tree behaves transfers; nothing you know about how to configure it on another vendor’s command line does. Keep those two categories separate in your notes and the study load becomes much clearer.

What Does the LAN Switching Section Expect You to Configure?

LAN Switching is the broadest single section on GB0-192. It covers shared versus switched Ethernet and the learning, forwarding and filtering logic of a switch, VLAN concepts and allocation modes, 802.1Q tags and trunk links, the full spanning tree family, port security, link aggregation, and WLAN fundamentals with basic configuration.

The spanning tree material is the deepest part and the syllabus is unusually explicit about it. It names STP, RSTP and MSTP, their relationships, Ethernet ring generation, switch roles, port states and BPDUs, then asks separately for the improvements RSTP brings over STP and the improvements MSTP brings over RSTP. That is a comparison question waiting to be asked, and it is answerable if you have learned the three as a progression rather than three protocols.

Port security is four separate topics, not one

The objectives name 802.1x functions, features and system architecture, port access control, port isolation and port binding as distinct items. They solve different problems: 802.1x authenticates a device before it gets a network, isolation stops two ports on the same VLAN talking to each other, and binding ties a port to a specific address. Candidates who treat the four as one topic lose marks on the distinctions between them.

Link aggregation is smaller but reliably examinable, and the split the syllabus draws is between static aggregation groups and dynamic ones. WLAN appears here at introductory depth only, covering key concepts, device types and basic configuration, so it does not need the study time a wireless-specific credential would demand.

How Deep Does GB0-192 Go Into IP Routing?

Deeper than the entry-level label suggests, but only in one direction. The section covers routing principles, the routing table, how routers process packets, route sources, metrics, priorities and loops, then direct and static routes and inter-VLAN routing, a general classification of routing protocols, and OSPF basics. There is no BGP, no EIGRP equivalent, and no route redistribution.

The concentration on OSPF is the point. The objectives name its features, basic working process, DR election, LSAs and the link state database, and domain-based OSPF, which is a real depth of coverage for a single protocol on an entry exam. DR election in particular is a favourite because it has clear rules and a clear failure mode.

Anyone who wants the behaviour from the source rather than a summary can read RFC 2328 on OSPF, which is the specification the vendor implementations follow. It is long, and the sections on the link state database and designated router election are the ones that map onto this syllabus.

The other half of the section is quieter but just as examinable: route priority and metric. Knowing why a router prefers one route over another when two protocols offer a path to the same destination is the kind of question that separates people who have configured routing from people who have read about it, and it appears in the objectives as route sources, metrics and priorities in a single line.

Why Does an Entry-Level Exam Include SDN and NFV?

Because H3C has put its own architectural direction into the blueprint. The eighth section, The Evolution of Network Technologies, covers virtualization fundamentals across compute, storage and network, then SDN background, architecture and value, then NFV background, concepts, standards organisations, and H3C’s own NFV products and architecture. It is conceptual rather than configurational.

That placement is unusual for an entry credential and it tells you something about how the exam is meant to be read. The first seven sections describe a network you can build today; the eighth describes where the vendor believes the discipline is going. Questions here will be definitional, asking what SDN separates from what, or what problem NFV solves, rather than asking you to deploy a controller.

The study effort is correspondingly light, and that is the honest advice: this section rewards a clear conceptual grasp and punishes nothing else. Understand the separation of control and forwarding planes, understand why moving network functions onto general-purpose compute changes the economics, and know that H3C has its own product line in this space. Six questions of conceptual material is not where a pass is won or lost.

Segment routing sits in the WAN section rather than this one, but belongs to the same modernising impulse. The objectives ask for its origin, advantages, principles and application scenarios, which is again a conceptual rather than a configuration expectation.

How Should You Prepare Without Comware Hardware?

Most candidates will not have H3C equipment to practise on, and the blueprint is structured in a way that makes that survivable. Seven of the eight sections are either standards-based or conceptual, and only the device section genuinely needs the platform. The order below reflects that, and it is deliberately sequential because each stage supplies what the next assumes.

Four stage GB0-192 study route without lab hardware, moving from auditing existing knowledge through subnet drills and the Comware device layer to the conceptual sections
  1. Audit what already transfers by working through the fundamentals, TCP/IP and IP routing sections first, since these describe standards that behave identically on any vendor and are where an experienced engineer can move fastest.
  2. Close the arithmetic gap next, drilling subnetting, VLSM and CIDR until the calculations are automatic, because a 72 second average per question leaves no room to work a subnet out on paper.
  3. Learn the Comware device layer deliberately as the one genuinely vendor-specific block, covering the command line, the file system, configuration and system file management and the boot process from the official course material.
  4. Finish with the conceptual sections on secure branch configuration, WAN access and the virtualization, SDN and NFV material, which reward clear definitions rather than hands-on practice.

Where a lab is available, spend it on the switching section rather than anywhere else. Spanning tree behaviour, VLAN trunking and link aggregation are the topics where watching the thing happen genuinely beats reading about it, and they sit in the broadest section on the paper.

Beyond that, treat the official syllabus as the scope boundary rather than a starting point. Because independent English study material is scarce, the temptation is to substitute another vendor’s course and hope the overlap covers it. The overlap is real but partial, and everything in the device section and the NFV architecture material sits outside it.

Where Does H3CNE-RS+ Lead, and How Long Does It Last?

H3CNE-RS+ is the engineer tier of a three-level ladder, and it is valid for three years. Above it sits H3CSE for senior engineers and H3CIE at expert level, with the routing and switching track continuing directly upward. Alongside it, the H3CNE tier itself branches into other specialisms rather than being a single credential.

The direct continuation in this track is the senior routing and switching material, which moves from OSPF basics into the advanced protocol work an enterprise network actually runs on. A walkthrough of that next tier sits in this guide to the H3CSE advanced routing exam, which is the natural follow-on once the essentials credential is in hand.

The sideways moves at the same tier are worth knowing about too, because they are cheaper than climbing and often more relevant to a specific job. H3C runs H3CNE credentials for areas including project management, server platforms, cloud and security, and this look at the H3CNE project management exam shows how different those siblings can be from the routing track.

On the validity question, three years is shorter than some vendors and the same as many. The practical implication is that timing matters: earning the credential at the point where it supports an application is better than earning it speculatively and watching a third of its life expire before anyone asks about it.

Frequently Asked Questions

How many questions are on the GB0-192 exam?

Fifty questions in 60 minutes, which is 72 seconds each. The passing score is 600 out of 1000, and there are no prerequisites of any kind for sitting it.

How much does the H3C GB0-192 exam cost?

One hundred and sixty-five US dollars. Registration runs through Prometric rather than Pearson VUE, which is the less common of the two routes for networking exams.

What certification does GB0-192 award?

H3CNE-RS+, the H3C Certified Network Engineer for Routing and Switching Plus. H3C confirms that passing this single exam is the whole requirement for the credential.

How long is H3CNE-RS+ valid?

Three years. That detail comes from H3C’s own certification page rather than the money-site syllabus page, which does not mention validity at all.

Is H3C certification the same as Huawei certification?

No. They are separate companies with separate equipment, separate operating systems and separate credentials. H3C’s platform is Comware, and the GB0-192 syllabus names it directly.

How many sections does GB0-192 have?

Eight, and none of them carries a published weighting. On a 50 question paper that averages roughly six questions per section if the distribution is even.

Does GB0-192 cover BGP?

No. The IP Routing section covers routing principles, static and direct routes, inter-VLAN routing, a general classification of protocols, and OSPF basics. BGP is not in the objectives.

Do you need H3C hardware to prepare?

Not for most of it. Seven of the eight sections are standards-based or conceptual. Only the device section, covering Comware, its command line and file system, genuinely needs the platform.

Why does an entry-level exam include SDN and NFV?

The eighth section covers virtualization, SDN and NFV conceptually rather than as configuration. It reflects H3C’s own architectural direction, and questions there are definitional.

What comes after H3CNE-RS+?

H3CSE at senior engineer level and H3CIE at expert level. The routing and switching track continues upward directly, and other H3CNE credentials sit alongside it as sideways moves.

Conclusion

GB0-192 is a broader exam than its entry-level position suggests, and a more transferable one than its vendor obscurity implies. Eight sections, 50 questions, 60 minutes, 600 out of 1000, $165, no prerequisites, and a credential valid for three years. Seven of the eight sections describe standards or concepts that behave the same anywhere.

Prepare by auditing what already transfers, closing the subnetting arithmetic gap so the 72 second average holds, then learning the Comware device layer as the one genuinely new block and finishing with the conceptual sections. Treat the published syllabus as the scope boundary, because independent English-language material is scarce and another vendor’s course will cover the standards and miss the platform entirely.

Rating: 5 / 5 (1 votes)

The post H3C Certification Is a Real Ladder You Have Probably Never Climbed appeared first on iSecPrep.

]]>
Your PCEP Certification Study Plan Has a Date on It https://www.isecprep.com/2026/09/02/pcep-30-02-entry-level-python-certification/ Wed, 02 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=87437 Control flow and exceptions carry 57 percent of PCEP between them, while the fundamentals beginners over-study are worth about five questions. A weighting-led read of the entry-level Python paper.

The post Your PCEP Certification Study Plan Has a Date on It appeared first on iSecPrep.

]]>

Every PCEP study plan on the internet now needs a date check. PCEP-30-02 is the current, active version of the Python Institute Certified Entry-Level Python Programmer exam, and the Python Institute has scheduled an updated version for release in the third quarter of 2026. That is a routine refresh rather than a retirement, and it does not shorten the five-year life of a credential already earned, but it does decide whether the study guide you are about to buy is describing your paper.

So the practical question is not whether PCEP is worth taking. It is what PCEP-30-02 actually asks while it is still the live version. The answer is a 30 question paper, 40 minutes long, $69 USD, needing 70 percent to pass, split across four weighted domains that are not weighted the way most beginners assume. This guide works through all four, what each genuinely tests, how the clock changes your preparation, and where the credential leads afterwards.

What Changes About PCEP-30-02 Before the Next Version Lands?

PCEP-30-02 is the active exam version today. The Python Institute has said an updated version is scheduled for the third quarter of 2026, describing it as a routine exam-version update rather than a change to the credential itself. Certifications already earned keep their five-year validity. Nothing about the four domains is being withdrawn.

What that means in practice is a buying decision rather than a panic. Study material written for PCEP-30-02 is correct for the paper being delivered now, and the objectives it covers are the objectives on the current blueprint. Material written for the older PCEP-30-01 numbering is a version behind and should be checked line by line against the current syllabus before you rely on it.

The safest habit is the one the Python Institute itself recommends: confirm the exam version code on your registration before you sit, and match it to the version your study material names. That is a thirty second check that removes the only genuine version risk in this credential. Full details of the current release sit on the official PCEP certification page.

Where Do the Marks Actually Sit on PCEP?

Control Flow is the largest domain at 29 percent, followed closely by Functions and Exceptions at 28 percent. Data Collections takes 25 percent. Computer Programming and Python Fundamentals, the part most beginners spend longest on, is the smallest at 18 percent. The four weightings sum to 100, so nothing on this paper is unweighted.

Domain Weight Approximate questions of 30
Control Flow – Conditional Blocks and Loops 29% 9
Functions and Exceptions 28% 8
Data Collections – Tuples, Dictionaries, Lists, and Strings 25% 7
Computer Programming and Python Fundamentals 18% 5

Read that table as a study budget and the shape of the exam changes. Control Flow and Functions together carry 57 percent of the marks, which is more than half the paper resting on making code decide something and then survive being wrong about it. A candidate who can write a nested loop, reason about a for-else clause and predict which except branch catches a KeyError is already most of the way to 70 percent.

The inverse is the trap. Fundamentals is where the vocabulary lives, so it feels like the foundation and it absorbs study time accordingly. It is worth roughly five questions. Spending three weeks on numeral systems and operator binding while leaving exception hierarchies until the last evening is the most common way to fail a paper you understood.

What Is the PCEP Exam Format?

PCEP-30-02 puts 30 questions in front of you in 40 minutes for $69 USD, and asks for 70 percent to pass. That is 21 correct answers out of 30, and 80 seconds per question. The exam is delivered through the OpenEDG Testing Service using its TestNow platform, and there are no prerequisites of any kind.

Specification Detail
Exam code PCEP-30-02
Full credential name Certified Entry-Level Python Programmer
Questions 30
Duration 40 minutes
Passing score 70 percent
Price $69 USD
Delivery OpenEDG Testing Service, TestNow
Prerequisites None

The question types are wider than most people expect

Calling this a multiple choice exam undersells it. Alongside single and multiple select questions, the Python Institute uses drag and drop, gap fill, sort, code fill, code insertion, and interactive scenario-based items. Several of those require you to assemble working code rather than recognise it, which is a different skill from reading four options and eliminating three.

That matters for the clock. An 80 second average is comfortable for a recall question and tight for a code-insertion item where you have to place a statement into a partly written block. Practising against the real item mix is the only way to find out which of them slow you down, and working through a PCEP practice test under timed conditions is where most candidates discover their pacing problem is one specific format rather than the subject.

One more piece of arithmetic worth knowing before exam day: the 40 minutes covers the exam only. A separate five minute window is allowed for the non-disclosure agreement and the tutorial, so the session is longer than the exam clock suggests, and the tutorial time is not taken out of your 40 minutes.

Why Is Control Flow the Heaviest Domain?

Control Flow carries 29 percent of PCEP because it is where beginners actually break. The domain covers conditional branching with if, if-else, if-elif and if-elif-else, multiple and nested conditionals, the pass instruction, loops built with while, for, range() and in, iteration over sequences, the while-else and for-else clauses, nested loops, and loop control with break and continue.

Two of those objectives are disproportionately examinable. The first is nesting. Reading a loop inside a conditional inside another loop and predicting what it prints is a skill that does not improve by reading about it, and PCEP asks for it directly. The second is the else clause attached to a loop rather than to an if, which is close to unique to Python and therefore a reliable way to separate people who have written Python from people who have written C and guessed.

What a for-else question actually tests

The else block on a loop runs when the loop finishes without hitting a break. Candidates who have never used the construct assume it runs every time, or that it runs when the loop body never executes. Both assumptions produce a wrong answer on a question that takes ten seconds if you know the rule. Learn the rule, then write three short loops that prove it to yourself.

Break and continue land in the same category. The exam does not ask you to define them, it asks you to trace them, usually inside a nested loop where break exits only the inner one. Trace-the-output questions are cheap to write and hard to bluff, which is exactly why this domain is the biggest on the paper.

What Does the Data Collections Domain Expect?

Data Collections is 25 percent of PCEP and covers four structures rather than one: lists, tuples, dictionaries and strings. The objectives run from construction and indexing through slicing, the len() function, list methods such as append(), insert() and index(), the del instruction, membership testing with in and not in, list comprehensions, copying and cloning, and nested lists used as matrices.

The dividing line the exam cares about is mutability. Lists can be changed in place, tuples and strings cannot, and dictionaries can gain and lose keys at will. Almost every question in this domain is testing whether you have internalised that distinction, whether it is phrased as a tuple assignment that raises an error or a string method that returns a new object instead of modifying the original.

Copying and cloning is the objective people skip

The syllabus names copying and cloning explicitly, and it is the objective most self-taught candidates have never thought about. Assigning one list to another name does not create a second list; it creates a second name for the same list, so changing one changes both. Slicing the whole list does create a copy. That single behaviour generates a whole family of trace-the-output questions.

  • Lists are ordered, mutable and indexable, and are the only one of the four with comprehensions in scope
  • Tuples are ordered and immutable, and are examined mainly through what you cannot do to them
  • Dictionaries bring key access, key existence checks, and the keys(), items() and values() methods
  • Strings are immutable and sliceable, with escaping, multi-line forms and the basic method set in scope

Nesting reappears here too. Lists inside tuples and tuples inside lists are named in the objectives, as are lists of lists used to represent matrices and cubes, so the indexing questions can go two levels deep.

How Deep Does PCEP Go Into Functions and Exceptions?

Functions and Exceptions is 28 percent of PCEP, and it is deeper than an entry-level label suggests. It covers defining and invoking functions and generators, the return keyword, None, recursion, the difference between parameters and arguments, positional, keyword and mixed argument passing, default parameter values, name scopes, shadowing, the global keyword, the built-in exception hierarchy, and try-except handling.

Scope is the part that carries the most marks per page of study. The exam expects you to say what a name refers to inside a function, what happens when a local name shadows a global one, and what the global keyword changes. These are short questions with unambiguous answers, which makes them attractive to an examiner and profitable for a candidate who has practised them.

The exception hierarchy is examined as a hierarchy

The syllabus names BaseException, Exception, SystemExit, KeyboardInterrupt, the abstract exceptions, ArithmeticError, LookupError, IndexError, KeyError, TypeError and ValueError. Naming them is not the test. The test is knowing which one catches which, because IndexError and KeyError both sit under LookupError, so an except LookupError branch catches both and an except IndexError branch does not.

That structure drives the other examinable behaviour in this domain: the order of except branches. A broad branch placed before a narrow one swallows the narrow case, and the narrow branch becomes unreachable. The syllabus also names propagating exceptions across function boundaries and delegating responsibility for handling them, so expect at least one question where the handler is not in the function that raised the problem.

Is 18 Percent Enough Reason to Skip the Fundamentals?

No, but 18 percent is a reason to time-box it. Computer Programming and Python Fundamentals is the smallest domain on PCEP-30-02, worth roughly five of the 30 questions. It covers interpreting versus compiling, lexis, syntax and semantics, keywords, indentation, comments, literals and variables, numeral systems, operators, data types, and console input and output.

Two objectives in it repay attention out of proportion to the domain weight. The first is operator priorities and binding, because a single question can hinge on whether you know that exponentiation binds more tightly than unary minus. The second is the accuracy of floating-point numbers, which is a concept question rather than an arithmetic one and is easy marks once you have read it properly.

The domain also names PEP 8 directly, under implementing naming conventions. That is the Python Software Foundation’s own style guide, and the examinable part is the convention set rather than the whole document: lowercase names with underscores for variables and functions, capitals for constants, and the indentation rules. Reading the PEP 8 style guide once is enough for this exam, and it is a habit worth forming anyway.

Bitwise operators sit here too, and they are the single most skippable item on the blueprint for a working programmer, yet they are explicitly listed. If your background is web or data work you may never have used them. One evening on the six of them is a proportionate response.

How Should You Prepare for an 80 Second Paper?

Preparation for PCEP-30-02 should follow the weightings rather than the syllabus order, because the syllabus lists Fundamentals first and it is the smallest domain. The sequence below spends time in proportion to marks, and it is deliberately ordered: each step assumes the one before it, so working through them out of order costs you the benefit.

Four step PCEP-30-02 preparation order showing loops first at 29 percent, functions next at 28 percent, lists and dicts at 25 percent and basics last at 18 percent
  1. Start with Control Flow and write loops until tracing them is automatic, because it is the single heaviest domain at 29 percent and every later topic sits inside a loop or a condition sooner or later.
  2. Move to Functions and Exceptions next, building small functions that raise and catch real errors, so the 28 percent domain rests on code you have debugged rather than a hierarchy you have memorised.
  3. Work through Data Collections by converting between lists, tuples and dictionaries deliberately, and prove the copying and cloning behaviour to yourself rather than reading about it.
  4. Finish with Fundamentals as a single time-boxed pass over operators, numeral systems, PEP 8 naming and floating-point accuracy, since the domain is only worth about five questions.

Layer timed practice over that sequence rather than saving it for the end. The 80 second average is generous for recall and tight for code insertion, and the only way to find out which format slows you down is to sit the mixed item types against a clock. The Python Institute’s own Python Essentials 1 course covers the same ground the syllabus does and is the closest free match to the blueprint.

A realistic budget for someone who already writes a little Python is four to six weeks of steady evenings. For a complete beginner it is longer, and the honest signal that you are ready is not finishing a course but scoring consistently above 80 percent on timed practice, which leaves headroom above the 70 percent cut score for exam-day nerves.

Where Does PCEP Lead in the Python Institute Path?

PCEP is the entry point to a credential family rather than a standalone certificate. The natural next step is PCAP, the Certified Associate Python Programmer, after which the path branches: PCPP1 for professional-level general programming, PCAD for data analysis, and PCAT or PCET for software testing in Python. Each is a separate exam with its own code and fee.

Python Institute credential ladder showing PCEP entry level, PCAP associate level, PCPP1 professional level and PCAD data analyst

The jump from PCEP to PCAP is the one worth understanding before you start, because it is larger than the naming implies. PCEP stops at functions, exceptions and the four built-in collection types. PCAP adds modules and packages, string processing, object-oriented programming, and file handling, which is a genuine step up in scope rather than a harder version of the same paper.

Choosing between the later branches is a question about your job rather than your Python. If you are heading for analysis work the data branch is the relevant one; if you are heading for quality engineering the testing credentials are. A fuller comparison of how the tiers differ is set out in this guide to the Python Institute credential ladder.

One practical note on sequencing: nothing forces you to take PCEP before PCAP. There are no prerequisites on either exam. PCEP is worth taking anyway if you are new to structured study, because it gives you a real exam experience under a real clock at a low fee, and that rehearsal is most of what a first certification is for.

Which Roles Actually Recognise an Entry-Level Python Credential?

PCEP is recognised as a starting signal rather than a hiring requirement. It appears most usefully in junior developer, QA automation, data assistant, IT support and technical apprenticeship applications, and in career-change CVs where the candidate has no commercial Python history and needs something verifiable between a course completion and a portfolio.

The market context behind that is straightforward. Python has been among the most widely used programming languages for years running in the Stack Overflow Developer Survey, which means the language is rarely the differentiator in an application. What a credential does is close the specific gap a self-taught candidate has, which is an external check that the syntax claim on the CV is true.

Be realistic about what it does not do. No entry-level certification substitutes for shipped code, and a hiring manager comparing two juniors will look at the repository before the badge. The honest positioning is that PCEP gets a CV read rather than getting an offer, and it is priced accordingly at $69.

Where it genuinely carries weight is inside organisations that use certification for internal progression, and in regions where formal credentials are weighted more heavily than portfolios in early screening. Candidates who go on to the testing credentials often find the same pattern applies there, as this walkthrough of the PCET and PCAT testing exams sets out in more detail.

Frequently Asked Questions

How many questions are on the PCEP exam?

Thirty questions in 40 minutes, which is 80 seconds each. You need 70 percent to pass, so 21 correct answers out of the 30, leaving room to drop nine.

What is the PCEP passing score?

Seventy percent. That is confirmed on both the money-site syllabus page and the Python Institute’s own certification page, so it is one of the more reliably documented figures on this exam.

How much does the PCEP certification cost?

Sixty-nine US dollars, booked through the OpenEDG Testing Service on its TestNow platform. There are no prerequisites, so there is no earlier exam fee to budget for first.

Which PCEP domain carries the most marks?

Control Flow, covering conditional blocks and loops, at 29 percent. Functions and Exceptions follows at 28 percent, so those two together carry 57 percent of the paper between them.

Is PCEP-30-02 still the current exam version?

Yes. The Python Institute lists PCEP-30-02 as the active version and has scheduled an updated version for the third quarter of 2026, described as a routine version update rather than a retirement.

How long is the PCEP certification valid?

Five years. The Python Institute confirms that the coming exam-version update does not affect the five-year validity of credentials already earned, so a pass now runs its full term.

Is PCEP only a multiple choice exam?

No. Alongside single and multiple select items, the exam uses drag and drop, gap fill, sort, code fill, code insertion, and interactive scenario-based questions, several of which require assembling working code.

How long does it take to prepare for PCEP?

Four to six weeks of steady evenings is realistic for someone already writing a little Python, and longer for a complete beginner. Readiness is scoring above 80 percent on timed practice, not finishing a course.

Should you take PCEP before PCAP?

Neither exam has prerequisites, so it is optional. PCEP is still worth taking first if you are new to formal exams, because it buys a genuine timed rehearsal at a low fee.

Does PCEP cover object-oriented programming?

No. Classes, modules, packages, file handling and string processing all sit in PCAP rather than PCEP. PCEP stops at functions, exceptions and the four built-in collection types.

Conclusion

PCEP-30-02 is a small, cheap, well-documented exam that rewards a study plan built from its weightings rather than its syllabus order. Control Flow and Functions and Exceptions carry 57 percent between them, Data Collections another 25, and the Fundamentals domain that beginners over-study is worth about five questions. Thirty questions, 40 minutes, 70 percent, $69, and no prerequisites.

The one time-sensitive detail is the version. PCEP-30-02 is current now, an updated version is scheduled for the third quarter of 2026, and credentials already earned keep their five-year validity either way. Check the version code on your registration against the version your study material names, work the heavy domains first under a clock, and treat the Fundamentals pass as a time-boxed finish rather than a starting point.

Rating: 5 / 5 (1 votes)

The post Your PCEP Certification Study Plan Has a Date on It appeared first on iSecPrep.

]]>