iSecPrep https://www.isecprep.com/ Your Guide to IT Certification Success Wed, 30 Sep 2026 12:41:36 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.9 OCI Data Science Professional: More Platform Than Model https://www.isecprep.com/2026/09/30/oci-data-science-professional-more-platform-than-model/ Wed, 30 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88437 Training a good model is the part of this exam you are least tested on. Five domains send most of 1Z0-1110-26 at the platform around the model: environments, secrets, jobs, pipelines and deployment.

The post OCI Data Science Professional: More Platform Than Model appeared first on iSecPrep.

]]>

A strong data scientist can fail this exam without getting a single modelling question wrong. The Oracle Cloud Infrastructure 2026 Data Science Professional exam, code 1Z0-1110-26 from Oracle, spends 55 percent of its 50 questions on the platform around the notebook: configuring a tenancy, conda environments, OCI Vault, Git repositories, jobs, pipelines, autoscaling, and the Spark, Open Data and Data Labeling services next door.

Even the 45 percent domain that carries the words machine learning lifecycle is not mainly about fitting models. Of its 14 objectives, training is one line. The others cover data sources, profiling, AutoML, evaluation, model explanations, the Model Catalog, deployment, and four generative AI topics Oracle has added: ADS with OCI Generative AI, LangChain deployment, Operators and AI Quick Actions.

That is the assumption to drop before you book. Knowing pandas and scikit-learn gets you into the room. Knowing how OCI Data Science runs a model in production is what earns the OCI Data Science Professional credential. This article goes domain by domain through what the syllabus asks, what the weightings mean on a 50 question paper, and how to prepare when the platform, not the maths, is the obstacle.

Table of Contents

  1. What does the 1Z0-1110-26 exam look like on paper?
  2. Which five domains does the OCI Data Science Professional syllabus weight?
  3. Why is the workspace domain about conda, Vault and Git rather than models?
  4. What does the 45 percent machine learning lifecycle domain actually ask?
  5. How does MLOps show up in the exam?
  6. Which related OCI services make up the last 10 percent?
  7. Who is the OCI Data Science Professional credential written for?
  8. How should you prepare for 1Z0-1110-26?
  9. Frequently Asked Questions
  10. Conclusion

What does the 1Z0-1110-26 exam look like on paper?

The 1Z0-1110-26 exam has 50 multiple choice questions, a 90 minute time limit, a 68 percent passing score and a price of USD 245, which may vary by country. It is the 2026 release of the Oracle Cloud Infrastructure Data Science Professional exam and replaces the 1Z0-1110-25 code. The 1Z0-1110-24 and 1Z0-1110-23 codes are earlier releases of the same credential.

Field Value
Exam name Oracle Cloud Infrastructure Data Science Professional
Exam code 1Z0-1110-26
Questions 50
Duration 90 minutes
Passing score 68 percent
Price USD 245, may vary by country or currency
Format Multiple choice
Recommended training Become an OCI Data Science Professional

The arithmetic is worth doing once. Sixty eight percent of 50 is 34, so you can miss 16 questions and still pass. Ninety minutes across 50 questions gives you 108 seconds each, which is generous for a recall item and tight for a scenario that describes a pipeline and asks what breaks it.

If you searched for 1Z0-1110-25 or 1Z0-1110-24 and landed here, you are in the right place. Oracle reissues the code every year, and the syllabus published for the current release is the one to study. The platform itself is described in Oracle’s Data Science service documentation as a fully managed, serverless platform for building, training and managing machine learning models, and that word managed is the key to how the exam is written.

Which five domains does the OCI Data Science Professional syllabus weight?

The OCI Data Science Professional syllabus has five domains. Implement end-to-end Machine Learning Lifecycle carries 45 percent, Apply MLOps Practices 20 percent, Design and set up Data Science Workspace 15 percent, and both OCI Data Science Introduction and Configuration and Use related OCI Services carry 10 percent. On a 50 question paper that is roughly 22 or 23, 10, 7 or 8, 5 and 5 questions.

Domain Weight Approximate questions What it asks you to do
OCI Data Science – Introduction & Configuration 10% 5 Explain the service and the ADS SDK, configure a tenancy for Data Science
Design and set up Data Science Workspace 15% 7 or 8 Projects, notebook sessions, conda environments, OCI Vault, Git code repositories
Implement end-to-end Machine Learning Lifecycle 45% 22 or 23 Data to model, AutoML, evaluation, explanations, Model Catalog, deployment, generative AI integrations
Apply MLOps Practices 20% 10 MLOps architecture, Jobs, scaling, autoscaled deployments, monitoring and logging, Pipelines
Use related OCI Services 10% 5 Data Flow Spark applications, Open Data Service, Data Labeling

The question counts are arithmetic from the published weights rather than a published split, so treat them as a planning guide. The shape is what matters. Add up everything that is not the lifecycle domain and you get 55 percent of the paper on configuration, workspace, operations and neighbouring services. A candidate who skips those because they feel like admin work has thrown away more than half the marks before the first modelling question.

The published sample questions show what that looks like in practice. One asks which autoscaling policy type uses CPU utilisation. Another asks the difference between a job and a job run. A third asks which algorithm OCI Vault does not support. Work through a set of 1Z0-1110-26 sample questions before you study anything, and you will see how few of them ask you to reason about a model.

Why is the workspace domain about conda, Vault and Git rather than models?

Design and set up Data Science Workspace is 15 percent of 1Z0-1110-26. It covers four things: creating and managing projects and notebook sessions, creating and managing conda environments, using OCI Vault to store credentials, and configuring source code in Code Repositories with Git. None of them involves a model, and all of them decide whether a model can be built at all.

The four setup tasks in the 1Z0-1110-26 workspace domain: projects, conda environments, OCI Vault and Git code repositories

Projects, notebook sessions and conda environments

A project is the container, and a notebook session is the compute you work in. Oracle describes the session as a JupyterLab based environment, so the interface will be familiar to anyone who has used notebooks elsewhere. If JupyterLab itself is new to you, the Project Jupyter site is the place to learn what a kernel, a cell and a notebook server are before you meet them inside OCI.

Conda environments are how a session gets its Python libraries. The exam expects you to know how to create one, activate it in a session and manage it over time, rather than installing packages ad hoc. The Accelerated Data Science SDK documentation has a whole section on working with conda packs, which tells you how central they are to the way Oracle expects the platform to be used.

Vault and Git are tested on fundamentals

The Vault objective is about keeping credentials out of notebooks. One published sample question asks which of SHA-256, RSA, AES and ECDSA is not a supported encryption algorithm in OCI Vault. The answer is SHA-256, because it is a hash function, not an encryption algorithm. That is the level of the question: understand what the service protects and what the algorithms are for.

The Git objective works the same way. A sample question describes a slow internet connection and asks which two operations would be delayed. Pushing to a remote and pulling from it are the network operations, so they slow down. Committing, staging and turning a local folder into a repository all happen on the notebook’s own storage. If you already use Git daily, this domain is a quick win.

What does the 45 percent machine learning lifecycle domain actually ask?

Implement end-to-end Machine Learning Lifecycle is the largest domain of the OCI Data Science Professional exam at 45 percent, about 22 or 23 questions. Its 14 objectives run from fetching data and profiling it, through training, AutoML, evaluation and explanations, to the Model Catalog and deployment, and finish with four generative AI topics: ADS with OCI Generative AI, LangChain, Operators and AI Quick Actions.

From data source to trained model

The first five objectives are the part a working data scientist already knows: use different data sources to fetch data, explore and prepare it, visualise and profile it, and create and train models with OCI and open source libraries. What the exam adds is the Oracle layer. The ADS SDK documentation covers authentication, conda packs, and running jobs, pipelines and model deployments locally, and those are the mechanics you are expected to recognise.

AutoML, evaluation and explanations

Three objectives sit here: create and use automated machine learning from Oracle AutoML, evaluate models, and obtain global and local model explanations. Global explanations tell you which features drive a model across all its predictions. Local explanations tell you why one particular prediction came out the way it did. Expect to be asked which kind answers which question, not to compute one.

The Model Catalog and deployment

Manage models using the Model Catalog, then deploy and invoke a cataloged model. This is the hinge of the whole exam, because everything in the MLOps domain assumes a model is already in the catalog. The sample questions probe the surrounding details: a model deployed through AI Quick Actions can be invoked through both the API and the CLI, and the outputs of a fine-tuning job land in an OCI Object Storage bucket, not in the catalog and not in the training instance’s local disk.

The generative AI edge

The last four objectives are discussion level: ADS and OCI Generative AI integration, LangChain application deployment to Data Science, Operators, and AI Quick Actions. Generative AI has its own Oracle exam, 1Z0-1127-26, so here the point is to know what each tool does and where its outputs go, not to engineer prompts. Oracle’s documentation defines AI Quick Actions as a set of actions for deploying, evaluating and fine-tuning foundation models from inside a Data Science notebook, starting from an explorer of models Oracle has tested and left unmodified.

“Today, we’re announcing the release of OCI Data Science AI Quick Actions, designed to enable anyone to easily deploy, fine-tune, and evaluate foundation models.”

Wendy Yip, Senior Product Manager, AI/ML Platform, Oracle

The AI Quick Actions announcement is worth reading in full for exam purposes. It names the first supported models, recommends at least 100 records for a fine-tuning dataset, and explains that evaluation uses ROUGE and BERTScore. Operators, meanwhile, are the low code side of ADS: forecasting and anomaly detection driven by a configuration file rather than a training script.

How does MLOps show up in the exam?

Apply MLOps Practices is 20 percent of 1Z0-1110-26, about 10 questions. The objectives are the OCI MLOps architecture, creating and managing Jobs for custom tasks, scaling with OCI Data Science, autoscaling model deployments for inference, monitoring and logging with MLOps practices, and using Pipelines to automate the machine learning workflow. This is where a model stops being a notebook and becomes a service.

Jobs and job runs

The distinction the exam likes is simple once stated. A job is a template that describes a task, its code and its compute. A job run is a single execution of that template. You can run the same job many times with different arguments, which is how a training script becomes something scheduled rather than something a person clicks.

Pipelines and step dependencies

Oracle’s documentation describes a pipeline as a resource that defines a workflow of steps, where steps can depend on other steps and can run in sequence or in parallel as long as they form a directed acyclic graph. Each step is discrete, so one pipeline can mix different environments and even different languages. A sample question asks how to make sure data processing happens before training, and the answer is to set a dependency between the steps. The Pipelines documentation lays out the typical sequence of import, transform, train and evaluate.

Autoscaling, monitoring and logging

Autoscaling a model deployment means the inference endpoint adds or removes capacity on a metric. The sample question on this objective asks which policy type a team should configure to scale on CPU utilisation, and the answer is a predefined metric policy rather than a custom one. Know the difference between the two and when you would write your own metric.

Monitoring and logging are a discipline of their own in OCI, and the overlap with this objective is real. The OCI Observability Professional exam article on this site goes deep on the Logging and Monitoring services that a deployed model reports into. For this exam, you need the MLOps view: what to log from a job or a deployment, and how to notice that a model in production has drifted.

Who is the OCI Data Science Professional credential written for?

The OCI Data Science Professional credential is written for people who build and run machine learning on Oracle Cloud Infrastructure: data scientists working in Python and open source libraries, machine learning engineers who deploy and monitor models, and OCI engineers asked to configure a tenancy for a data science team. The syllabus says it expects some experience or exposure to OCI, not just to data science.

That last group is easy to overlook. The 10 percent Introduction and Configuration domain covers the service overview, the capabilities of the ADS SDK, and configuring a tenancy for Data Science. One sample question asks which resource types the default matching rules of the Data Science service template include, and the answer names model deployments, notebook sessions and job runs. That is an identity and policy question, and it lands on the person who owns the tenancy.

Oracle’s own description of the OCI Data Science platform sets the scope well: teams of data scientists using Python and open source tools, a JupyterLab environment, NVIDIA GPUs and distributed training for scale, and MLOps capabilities such as automated pipelines, model deployments and model monitoring. Every phrase in that sentence maps to a domain above.

The credential has been reissued every year since at least the 2023 release. This site’s earlier 1Z0-1110-23 preparation guide describes that release as a 55 question paper, and the generative AI objectives did not exist in it. The current 50 question syllabus is the one to work from, and anything written for an older code should be read with that in mind.

How should you prepare for 1Z0-1110-26?

Prepare for 1Z0-1110-26 by spending your time in proportion to the weights: close to half on the machine learning lifecycle, a fifth on MLOps, and the remaining third on workspace setup, tenancy configuration and the related services. Do all of it inside a real OCI tenancy, because the exam asks what the platform does, and that is learned by using it rather than reading about it.

Study order for 1Z0-1110-26: conda environments first, OCI Vault next, models last
  1. Read the five domains and write the question arithmetic next to each, so you plan for roughly 22 lifecycle questions against 5 on tenancy configuration.
  2. Configure a tenancy for Data Science, then create a project, a notebook session and a conda environment, because the workspace and configuration domains are 25 percent of the paper and cannot be learned from a slide.
  3. Take one small dataset through the whole lifecycle in a notebook: fetch it, profile it, train with an open source library and with AutoML, evaluate it, generate global and local explanations, and save the model to the Model Catalog.
  4. Deploy that cataloged model and invoke it, then rebuild the same work as a Job and as a Pipeline with a dependency between the processing step and the training step.
  5. Visit the edges: connect a notebook to Data Flow, open a dataset from Open Data, label a handful of documents in Data Labeling, and open AI Quick Actions to see what a deployed foundation model looks like.
  6. Finish with timed sets of 50 questions in 90 minutes, and book the exam when you are comfortably above 34 correct.

Two habits pay off during that sequence. Keep a note of every OCI resource name you meet, because the exam uses the platform’s vocabulary and expects you to match it. And read the answer options as a systems engineer would, asking where an output is stored, which service is doing the work and which policy allows it, since that is how most of the platform questions are built.

Frequently Asked Questions

How many questions are on the 1Z0-1110-26 exam?

The 1Z0-1110-26 exam has 50 multiple choice questions with a 90 minute time limit, which works out at 108 seconds per question.

What is the passing score for the OCI Data Science Professional exam?

The passing score is 68 percent. On a 50 question paper that means 34 correct answers, so you can miss 16 questions and still pass.

How much does the 1Z0-1110-26 exam cost?

The exam costs USD 245. Oracle notes that the price may vary by country or by localised currency, so check the figure shown at booking.

Is 1Z0-1110-26 the same exam as 1Z0-1110-25?

They are annual releases of the same credential. 1Z0-1110-26 is the 2026 release and replaces the 1Z0-1110-25 code, with 1Z0-1110-24 and 1Z0-1110-23 before it. Study the syllabus published for the current code.

Which domain is the largest on the OCI Data Science Professional exam?

Implement end-to-end Machine Learning Lifecycle is the largest domain at 45 percent, about 22 or 23 of the 50 questions. Apply MLOps Practices is next at 20 percent.

Does the OCI Data Science Professional exam cover generative AI?

Yes, as four objectives inside the lifecycle domain: ADS and OCI Generative AI integration, LangChain application deployment, Operators, and AI Quick Actions. They are discussion level topics, not prompt engineering.

What is the difference between a job and a job run in OCI Data Science?

A job is a template that defines a task, its code and its compute. A job run is a single execution of that template, and one job can have many runs.

Where can I find OCI Data Science Professional sample questions?

DBExam publishes a free set of ten sample questions with answers for 1Z0-1110-26, covering Open Data, autoscaling, Vault, pipelines, Git, jobs, tenancy templates, Data Labeling and AI Quick Actions.

How long is the OCI Data Science Professional certification valid?

The syllabus published for 1Z0-1110-26 does not state a validity period. Confirm the current renewal terms on Oracle’s certification portal before you plan a recertification date, rather than relying on a third party figure.

Conclusion

The wrong assumption is the expensive one. Candidates who treat 1Z0-1110-26 as a modelling exam revise the part they already know and leave 55 percent of the paper to chance. The syllabus is clear that the OCI Data Science Professional credential measures whether you can set up, run and operate machine learning on the platform: tenancy, workspace, catalog, deployment, jobs, pipelines and the services at the edges.

The numbers give you the plan. Fifty questions, 90 minutes, 34 to pass, with 45 percent on the lifecycle and 20 percent on MLOps. Build one model end to end inside a real tenancy, deploy it, automate it, and visit Data Flow, Open Data and Data Labeling before exam day. Then sit the sample questions on DBExam, and book when your timed scores sit well above the pass mark.

Rating: 0 / 5 (0 votes)

The post OCI Data Science Professional: More Platform Than Model appeared first on iSecPrep.

]]>
NetApp Certified Hybrid Cloud Architect: Earn One Cert First https://www.isecprep.com/2026/09/30/netapp-certified-hybrid-cloud-architect-earn-one-cert-first/ Wed, 30 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88434 Four hyperscaler certifications stand between you and NS0-604, and you need only one of them. Here is how the eight unweighted domains, the 80 percent bar and NetApp's price list fit together.

The post NetApp Certified Hybrid Cloud Architect: Earn One Cert First appeared first on iSecPrep.

]]>

Before NetApp lets you register for NS0-604, it asks for proof that you have already passed somebody else’s exam. The NetApp Certified Hybrid Cloud Architect credential requires at least one of four hyperscaler certifications, AWS SAA-C03, Azure AZ-104, Azure AZ-305 or the Google Associate Cloud Engineer, and no NetApp exam of its own is compulsory beforehand. That single rule says more about the exam than the topic list does.

NS0-604 is not a storage exam with a cloud chapter. It is a design exam that assumes you already speak one public cloud fluently and then tests whether you can place NetApp storage and data services inside it, protect the data across zones and regions, connect it privately, and explain the result to a customer. This article covers the prerequisite, the 60 question format, the eight domains NetApp publishes without weightings, and a preparation order that fits a paper of this shape.

Table of Contents

  1. Why does NS0-604 require a hyperscaler certification first?
  2. What does the NetApp Certified Hybrid Cloud Architect exam look like?
  3. Which eight domains does NS0-604 test, and why are there no weightings?
  4. How does the NetApp Console change the architecture questions?
  5. Designing for availability and durability: what NS0-604 expects
  6. How do networking and private connectivity show up on the exam?
  7. Where does NS0-604 sit in NetApp’s Hybrid Cloud path?
  8. How should you prepare for the NetApp Certified Hybrid Cloud Architect exam?
  9. Frequently Asked Questions
  10. Conclusion

Why does NS0-604 require a hyperscaler certification first?

NetApp requires proof of at least one hyperscaler certification before you can take NS0-604, the NetApp Certified Hybrid Cloud Architect exam. The accepted exams are AWS SAA-C03, Microsoft AZ-104, Microsoft AZ-305 and the Google Associate Cloud Engineer. The exam tests your ability to analyze, position and design NetApp hybrid cloud solutions on one of those three public clouds, so NetApp wants the cloud half proven in advance.

The four hyperscaler certifications NetApp accepts before NS0-604: AWS SAA-C03, Microsoft AZ-104, Microsoft AZ-305 and the Google Associate Cloud Engineer
Accepted prerequisite Vendor Level
AWS Certified Solutions Architect – Associate (SAA-C03) Amazon Web Services Associate
Microsoft Certified: Azure Administrator Associate (AZ-104) Microsoft Associate
Microsoft Certified: Azure Solutions Architect Expert (AZ-305) Microsoft Expert
Google Associate Cloud Engineer (ACE) Google Cloud Associate

You need one of the four, not all of them. Pick the cloud your employer actually runs, because the design scenarios on the exam let you reason from any of the three providers and your answers will be sharper on the one you know.

What NetApp recommends but does not require

The official credential page also lists the NetApp Hybrid Cloud Administrator exam, NS0-305, as highly recommended, along with fundamental NetApp knowledge and NetApp courses. Two low cost accreditation exams, NetApp Cloud Native Associate and NetApp Hybrid Cloud Associate, are suggested as warm ups. None of these is a gate. The hyperscaler certification is.

The task list on the NetApp credential page reads like an architect’s job description rather than an administrator’s: determine business requirements, architect and position a solution, document it, run a proof of concept, support customer success and future proof the design. That is the person NS0-604 is written for, and it explains why the questions are scenarios rather than command syntax.

What does the NetApp Certified Hybrid Cloud Architect exam look like?

NS0-604 has 60 questions in 120 minutes with an 80 percent passing score, delivered through Pearson VUE. NetApp’s price list since 1 May 2025 sets certification exams at 200 USD and Expert level exams at 250 USD, and NetApp places Hybrid Cloud Architect at the Expert level of its Hybrid Cloud path. The credential stays active for 24 months once earned.

Field Value
Exam name NetApp Hybrid Cloud Architect (NCHC Architect)
Exam code NS0-604
Questions 60
Duration 120 minutes
Passing score 80 percent
Fee 200 USD standard tier or 250 USD Expert tier under NetApp’s 1 May 2025 price list; the fee shown at registration applies
Delivery Pearson VUE, with OnVUE online testing available
Prerequisite At least one of SAA-C03, AZ-104, AZ-305 or Google ACE
Validity 24 months

Do the arithmetic before you book. Eighty percent of 60 is 48 correct answers, which leaves you 12 misses. Two hours across 60 questions is two minutes each, which is generous for a fact and tight for a scenario that asks you to compare three placement options. Most candidates find the time is fine and the 80 percent bar is the real obstacle.

Retakes and the account you need first

NetApp’s retake rules are stated on its certification policies page. A first failure can be retaken straight away. After further failures you wait 14 days. After a pass you wait 12 months before sitting the same exam again. One practical detail catches people out: every NetApp exam needs a NetApp account, and a new account takes between 4 and 24 hours to create, so set it up before you try to schedule.

Which eight domains does NS0-604 test, and why are there no weightings?

NS0-604 covers eight domains: Customer Requirements, NetApp Hybrid Cloud Solutions, Hybrid Cloud Architecture, Business Continuity and Data Protection, Networking, Sizing and Scale, Security, and Monitoring. Neither NetApp nor the NWExam syllabus page publishes a percentage for any of them. You plan by objective, not by weight, and there are only 15 objectives in total.

Domain Objectives as published What a scenario tends to ask
Customer Requirements Cloud solutions; Cloud cost management considerations; NetApp Cloud solutions Which NetApp service fits a stated business need and budget
NetApp Hybrid Cloud Solutions NetApp Cloud Storage portfolio; NetApp Cloud Services portfolio; NetApp Cloud Controls portfolio Which control service answers an observability or governance need
Hybrid Cloud Architecture Architectural components Where the control plane and its agent sit
Business Continuity and Data Protection Designing for availability; Designing for durability Zones, regions, replication topology, immutable copies
Networking Networking requirements for NetApp Hybrid Cloud solutions; Hybrid cloud network topologies Peering behaviour, private circuits
Sizing and Scale Workload characteristics for different business requirements; NetApp Hybrid Cloud storage solutions Matching a workload profile to a storage option
Security NetApp Hybrid Cloud control planes; Security considerations for a NetApp Hybrid Cloud environment Permission scope, control plane separation
Monitoring NetApp Hybrid Cloud solutions Which service correlates telemetry across environments

Without weightings, the only safe assumption is that every domain can appear and none can be skipped. If you lose half the marks in any two domains, you have probably spent your 12 misses. The third column above is not published by NetApp. It comes from reading the objectives against the shape of the questions, and the quickest way to calibrate that yourself is to work through a set of NS0-604 sample questions before you study, so you can see which objective each scenario is really testing.

Notice what the objectives do not say. There is no ONTAP command line, no SnapMirror configuration syntax, no cluster setup. Those belong to the administrator and implementation exams lower in the path. Here the verbs are position, design and consider.

How does the NetApp Console change the architecture questions?

The Hybrid Cloud Architecture and Security domains of NS0-604 revolve around the NetApp Console, the control plane NetApp formerly called BlueXP, and the agent it deploys into each environment. NetApp’s documentation now calls that agent the Console agent; older material, including the sample questions, still calls it the Connector. Both names refer to the same component, and the exam expects you to know what it does and does not touch.

Control plane and data path are separate

The design point that keeps recurring is separation. The Console orchestrates provisioning and lifecycle actions. Client reads and writes go directly to the storage service and never pass through the Console or its agent. A candidate who believes the agent proxies application traffic will get the placement, the security and the availability questions wrong in one go, because all three follow from that separation.

NetApp’s own description of the Console agent architecture makes the boundaries explicit: the agent is a lightweight component installed in your network, it initiates every connection to the Console rather than the other way round, it uses TLS 1.3, and it acts on cloud resources using only the permissions it has been granted.

One agent per environment

Placement follows from permissions. When a design spans two public clouds, the expected answer is an agent aligned to each cloud, holding locally scoped permissions and the network reachability that cloud needs. Routing every cloud’s control operations through one central agent, or embedding the agent inside a volume, are the distractors, and they read as plausible until you remember the permission boundary.

The Monitoring domain sits on the same platform. When a scenario asks for one service that ingests telemetry from on-premises systems and several public clouds and correlates resource relationships across all of them, it is describing the observability service in the Cloud Controls portfolio rather than the health and risk telemetry of the support tooling, and the difference between those two is exactly what the question is checking.

Designing for availability and durability: what NS0-604 expects

The Business Continuity and Data Protection domain of NS0-604 has two objectives, designing for availability and designing for durability, and the exam treats them as different problems. Availability is about surviving the loss of a zone or a region while still serving. Durability is about keeping a restorable copy that survives an attacker with administrative credentials. A single mechanism rarely covers both.

Zones for local resilience, replication for the region

The canonical availability design is a file service deployed across availability zones in the primary region, replicated with SnapMirror to a second region. Two instances in the same zone do not survive a zone loss. Two regions with no replication relationship do not survive anything, because nothing moves the data. Expect the wrong answers to be built from exactly those two mistakes.

Cascade or fan-out

When one dataset must feed a disaster recovery replica in a second region and a reporting copy in a third, the choice is between a fan-out, where the primary sends to both destinations over separate wide-area links, and a cascade, where the primary replicates once to the second region and that copy forwards to the third. If the requirement is to carry the source across the wide-area link only once, the cascade is the answer. Fan-out is not wrong in general, it is wrong for that requirement, and reading the requirement is the skill.

Three requirements, three mechanisms

A favourite question shape gives you three needs for one volume and asks you to map a mechanism to each:

  • Same-day rollback of accidental edits: local snapshots on the source.
  • A cross-region copy for site loss: SnapMirror replication.
  • Restorable copies kept for ninety days on independent storage: backup and recovery to an object store.

The trap is the answer that uses one mechanism for all three, or swaps the roles around. Snapshots on the same storage do not survive a site loss, and a replica is not a ninety day retention policy.

Ransomware changes the durability question

Following a ransomware tabletop exercise, the design has to guarantee a clean copy even when the attacker holds primary administrator credentials. Three design choices meaningfully improve recoverability: enough historical restore points to go back to before the encryption started, an independent backup copy in an object store whose deletion authority is separated from the primary administrators, and at least one immutable copy that cannot be altered or deleted during its retention period. Anything that consolidates copies or widens delete rights makes the position worse.

How do networking and private connectivity show up on the exam?

The Networking domain of NS0-604 tests two things: the network requirements NetApp hybrid cloud services impose, and the topologies used to connect on-premises systems to the cloud. In practice that means hub and spoke behaviour inside a cloud and the choice between a VPN over the internet and a dedicated private circuit between sites.

The hub and spoke question is the one most people get wrong on first sight. Spoke A is peered to a hub, spoke B is peered to the same hub, both peerings are healthy, and hosts in A still cannot reach hosts in B. The reason is that peering is non-transitive. Traffic from A to B does not flow through the hub by default, and the fix is a transit gateway or hub transit rather than a security group change or a public-facing hub.

The private connectivity question is about predictability. A financial customer replicating continuously from on-premises ONTAP to a cloud file service wants low, consistent latency and dedicated throughput unaffected by internet congestion, and accepts the lead time of a physical circuit. A site-to-site VPN encrypts the traffic but still rides the public internet. A private endpoint keeps the address private but not the path. The dedicated circuit, Direct Connect on AWS or ExpressRoute on Azure, is what the requirement describes.

Why the definition matters

Every one of those scenarios is a hybrid cloud in the sense the NIST definition uses, and the wording is worth having in your head because the Customer Requirements domain asks you to talk about cloud solutions in general before it asks about NetApp’s. NIST’s definition of cloud computing puts it this way:

“The cloud infrastructure is a composition of two or more distinct cloud infrastructures (private, community, or public) that remain unique entities, but are bound together by standardized or proprietary technology that enables data and application portability (e.g., cloud bursting for load balancing between clouds).”

Peter Mell and Tim Grance, National Institute of Standards and Technology

The phrase to hold on to is bound together by technology that enables portability. On this exam, SnapMirror, the Console agent and the private circuit are that technology, and the questions are about choosing the right one for the requirement in front of you.

Where does NS0-604 sit in NetApp’s Hybrid Cloud path?

NetApp’s certification catalogue places the Hybrid Cloud Architect at the Expert level, the top of a Hybrid Cloud path that runs through Technology Solutions Professional, Data Administrator ONTAP, Hybrid Cloud Administrator, StorageGRID Administration and Hybrid Cloud Implementation Engineer. NS0-604 is the only exam in that path with a prerequisite from another vendor, and the only one at the Expert tier.

The three verbs NS0-604 tests: analyze the estate, position the fit and design the answer

The path is a recommendation, not a ladder you must climb rung by rung. NetApp does not require the Administrator or Implementation Engineer credentials before the Architect exam. It does say the Administrator exam is highly recommended, and there is a good reason: the Administrator syllabus is where you learn what the services do, while the Architect syllabus assumes you know and asks where to put them. If you are weighing the two, this site’s guide to the NS0-305 Administrator exam shows how much lower the design content sits at that level.

Why the architect role is in demand now

NetApp is a Leader in the 2026 Gartner Magic Quadrant for Enterprise Storage Platforms and ranked first for the Hybrid Cloud Storage use case in the 2026 Gartner Critical Capabilities report, a position NetApp attributes to native storage services across all three major public clouds. Writing about that result on the NetApp Platform blog, the head of NetApp’s platform engineering organisation described what customers are asking for:

“customers today want their hybrid, often multicloud storage to function as one unified platform, with a consistent operating model across data infrastructure, managed and protected via a single interface”

Bret Hull, Senior Vice President and Global Head of Platform Engineering, NetApp

That sentence is the Architect exam in miniature. One platform across clouds is Domain 2. A consistent operating model is Domain 3. Managed and protected through a single interface is the Console and the Security and Monitoring domains. The person who can design that is the person NS0-604 certifies.

How should you prepare for the NetApp Certified Hybrid Cloud Architect exam?

Prepare for NS0-604 in the order NetApp’s own requirements imply: secure the hyperscaler prerequisite first, learn the NetApp services as an administrator would, then practise design decisions by objective across all eight domains until you can defend a placement, a replication topology and a connectivity choice from the requirement alone. Book when timed practice sits comfortably above 48 out of 60.

  1. Confirm you hold one of SAA-C03, AZ-104, AZ-305 or Google ACE, and pass it first if you do not, because NetApp will not register you for NS0-604 without it.
  2. Work through the Hybrid Cloud Administrator material, or sit NS0-305, so that every service in the Cloud Storage, Cloud Services and Cloud Controls portfolios is familiar before you are asked to position one.
  3. Write the 15 objectives down and rate yourself on each, since NetApp publishes no weightings and any of them can carry a question.
  4. Study the NetApp Console and its agent until the control plane and data path separation is second nature, and learn the current names alongside the older BlueXP and Connector terms.
  5. Practise the protection designs on paper: zones plus a replicated region, cascade against fan-out, snapshot against SnapMirror against backup, and the three ransomware safeguards.
  6. Sit timed sets of 60 questions in 120 minutes and stop booking only when you are consistently above 48 correct.

The older resource pages on this site are still useful for the topic map. The NS0-604 essential topics page lists the same eight domains and links out to practice material, and it makes a reasonable checklist to work down once you have the prerequisite and the administrator knowledge in place.

Two things not to spend time on: memorising ONTAP command syntax, which this exam does not test, and hunting for domain percentages, which do not exist. Every hour spent there is an hour not spent on the design decisions the paper is actually made of.

Frequently Asked Questions

How many questions are on the NS0-604 exam?

NS0-604 has 60 questions and a 120 minute time limit, which works out at two minutes per question.

What is the passing score for the NetApp Certified Hybrid Cloud Architect exam?

The passing score is 80 percent. On 60 questions that means 48 correct answers, so you can miss 12.

Do I need another certification before NS0-604?

Yes. NetApp requires proof of at least one of AWS SAA-C03, Microsoft AZ-104, Microsoft AZ-305 or the Google Associate Cloud Engineer before you can take the exam. The NetApp Hybrid Cloud Administrator exam, NS0-305, is highly recommended but not required.

How much does the NS0-604 exam cost?

NetApp’s price list since 1 May 2025 sets certification exams at 200 USD and Expert level exams at 250 USD, and NetApp lists Hybrid Cloud Architect at the Expert level of its Hybrid Cloud path. The fee shown when you register at Pearson VUE is the one that applies.

Does NetApp publish weightings for the NS0-604 domains?

No. Both NetApp and the NWExam syllabus page list eight domains with their objectives and no percentages. Plan by objective and treat every domain as examinable.

How long is the NetApp Certified Hybrid Cloud Architect certification valid?

NetApp certifications are active for 24 months once earned. After a pass you must wait 12 months before retaking the same exam.

What is the retake policy if I fail NS0-604?

A first failure can be retaken immediately. After multiple failures you must wait 14 days between attempts.

Is NS0-604 the current NetApp Hybrid Cloud Architect exam?

Yes. NS0-604 replaced the earlier NS0-603, and NetApp’s catalogue lists the Hybrid Cloud Architect credential as active at the Expert level with no retirement notice.

What is the difference between the NetApp Console and BlueXP?

They are the same product. NetApp renamed BlueXP to NetApp Console, and the Connector component is now called the Console agent. Older study material and sample questions still use the earlier names.

Conclusion

The prerequisite is the point. NetApp Certified Hybrid Cloud Architect is the one NetApp credential that starts with another vendor’s exam, because the paper assumes the cloud and tests the design: where the Console agent sits, how a file service survives a zone and then a region, when a cascade beats a fan-out, and why a private circuit rather than a VPN answers a latency requirement.

The numbers are simple. NS0-604 is 60 questions in 120 minutes at an 80 percent bar, eight domains with no weightings, 24 months of validity, and a fee set by NetApp’s Expert tier price list rather than the older figure still circulating.

Hold the hyperscaler certification, learn the services as an administrator, then practise the design decisions until you can name the objective behind every scenario. When your timed scores stay above 48, schedule the exam.

Rating: 0 / 5 (0 votes)

The post NetApp Certified Hybrid Cloud Architect: Earn One Cert First appeared first on iSecPrep.

]]>
Agentic Automation Professional Certification: What Changes https://www.isecprep.com/2026/09/29/agentic-automation-professional-certification-what-changes/ Tue, 29 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88414 UiAAP keeps the Associate's 60 questions and 70 percent pass mark, then adds five topics and 52 more objectives. Most of the new material is testing, orchestration and governance.

The post Agentic Automation Professional Certification: What Changes appeared first on iSecPrep.

]]>

It is easy to read Agentic Automation Professional as the Associate exam with the difficulty turned up. The syllabus for UiAAP, the UiPath Certified Professional Agentic Automation Professional exam, says otherwise.

Building an agent and writing its prompt are the smaller part of the paper. Of the 84 objectives UiPath lists across 14 topics, 30 sit in just two: agentic evaluations and orchestration with UiPath Maestro. Five topics do not appear at Associate level at all, including agent management, the AI Trust Layer and coded agents. Put plainly, the agentic automation professional certification asks whether you can prove an agent works, place it inside a governed process, and keep it under control once it runs.

This article sets out the exam facts, shows exactly where the Professional tier departs from the Associate, and explains the five new topics. It also covers the question many candidates now ask, which is where the newer Builder Professional credential fits, and it ends with a preparation sequence built around the official resources.

Table of Contents

  1. What are the UiAAP exam facts?
  2. How is the Professional tier different from the Associate?
  3. Which topics are new at Professional level?
  4. Why do evaluations and Maestro carry so many objectives?
  5. Where does the Builder Professional certification fit?
  6. How should you prepare for UiAAP?
  7. Frequently Asked Questions
  8. Conclusion

What are the UiAAP exam facts?

The UiAAP exam has 60 questions in 120 minutes, a 70 percent passing score and a fee of 300 USD. Pearson VUE delivers it at a test centre or online with a proctor. UiPath registers it under the exam number UiPath-AAPv1, and the credential stays valid for 3 years from the date you earn it.

Field Value
Credential UiPath Certified Professional Agentic Automation Professional
Exam code UiAAP (listed by UiPath and Pearson VUE as UiPath-AAPv1)
Certification track Agentic Automation
Questions 60
Duration 120 minutes
Passing score 70 percent
Fee 300 USD
Format Multiple choice, plus drag and drop or sequencing items
Delivery Pearson VUE, test centre or online proctored
Languages English and Japanese
Product version UiPath 2025.10 and later
Validity 3 years
Topics 14, with no published weightings

Two pieces of arithmetic follow from those figures. First, 70 percent of 60 is 42, so you can miss 18 questions and still pass. Second, 120 minutes across 60 questions gives you 2 minutes each. That is a comfortable pace for a recall question and a tight one for a scenario that asks you to read a process, a prompt and an evaluation result before you answer.

The format line matters as well. Sequencing items ask you to put steps in the right order, which rewards people who have actually configured an index or an escalation. Reading about the steps is rarely enough to order them correctly.

UiPath does not weight the 14 topics, so you cannot plan by percentage. The only reliable guide to depth is the objective list itself, which UiPath publishes in the official exam description. The rest of this article uses that list, because it is where the two tiers visibly separate.

How is the Professional tier different from the Associate?

UiAAP doubles the Associate fee, adds 30 minutes, and keeps the same 60 questions and 70 percent pass mark. The larger change is scope. The Associate syllabus lists 32 objectives across 10 topics, while the Professional syllabus lists 84 across 14, and UiPath aims it at the people who deliver agentic solutions.

Field Associate (UiAAA) Professional (UiAAP)
UiPath exam number UiPath-AAAv1 UiPath-AAPv1
Fee 150 USD 300 USD
Duration 90 minutes 120 minutes
Questions 60 60
Time per question 90 seconds 2 minutes
Passing score 70 percent 70 percent
Topics 10 14
Objectives listed 32 84
Validity 3 years 3 years

Same topics, different verbs

Nine topic names carry over from one tier to the next, which is why the two exams look alike at first glance. The objectives under them do not. Associate objectives mostly ask you to define, describe and differentiate. Professional objectives ask you to configure, implement, monitor and troubleshoot. Context Grounding shows the shift clearly: 2 objectives at Associate level, 8 at Professional, including index update strategy and threshold tuning.

A narrower audience

UiPath describes the Associate as suited to both technical and non-technical roles, from business analysts to project managers. The Professional exam names four groups only: automation developers, solution architects, technical leads, and Center of Excellence members who deliver agentic automation. The candidate UiPath has in mind can design, build, orchestrate and govern a solution independently.

Do you need the Associate first?

The Associate exam description states that it has no prerequisite. The Professional exam description names no prerequisite exam either. Even so, the Professional syllabus assumes everything the Associate teaches, so most candidates will want that ground covered before they book.

The quickest way to feel the difference is to read a set of UiAAP sample questions next to the syllabus. They ask how to find the root cause of a failed evaluation, what a low trajectory score means when the final answer looks fine, and what an inclusive gateway does in a Maestro flow. None of those can be answered from a definition.

Which topics are new at Professional level?

Five topics appear on the UiAAP syllabus that the Associate syllabus does not list: Agent management, AI Trust Layer, Coded Agents, Conversational Agents and UI Agent. Together they hold 13 objectives. They move the exam past building a single agent and into governing, monitoring and extending agents across a whole tenant.

The three AI Trust Layer controls on the UiAAP exam: LLM gateway, audit summary and data masking

Agent management

This is the largest of the five, with 7 objectives. You apply governance policies that enable, disable or control agent functionality, and you assign them at tenant, group or user level. You also use agent scores to track performance, analyse trace data, and monitor usage, unit consumption and incidents. Simulations of agent tools and Context Grounding sit here too.

AI Trust Layer

Three objectives cover the controls that sit between an agent and a language model:

  • Bringing your own model through the LLM gateway
  • Using the audit and usage summary
  • Masking personal data in flight before it reaches a model

Coded, conversational and UI agents

Each of these three topics has a single objective, and the syllabus gives no more detail than the name. Coded Agents covers agents written in code. Conversational Agents covers chat based agents. UI Agent refers to ScreenPlay. With so little published, the UiPath Agents documentation is the safest place to learn what each one does.

New objectives inside familiar topics

Some of the sharpest additions hide under topic names you already know. UiPath Platform components and integrations grows from 4 objectives to 11. The new ones include building API workflows as reusable agent tools, exposing existing agents for reuse inside new agents, using agent tool guardrails, and integrating MCP assets as tools. MCP is an open standard for connecting models to tools and data, and the Model Context Protocol specification explains the client and server roles behind it.

Why do evaluations and Maestro carry so many objectives?

Agentic evaluations and agentic orchestration with UiPath Maestro hold 14 and 16 objectives on the UiAAP syllabus, 30 of 84 in total. UiPath publishes no topic weightings, so these counts show breadth of content and not a share of questions. Even so, no other pair of topics asks you to know as much.

The agent test loop for UiAAP: build cases, run tests, read traces and fix the prompt
Topic Associate objectives Professional objectives
Agentic AI and agentic automation concepts 6 3
Agentic discovery and blueprint design 8, split over two topics 8
Context Grounding 2 8
Escalations 2 3
Agentic evaluations 2 14
Agent management Not listed 7
Prompt engineering 4 6
UiPath Platform components and integrations 4 11
Agentic orchestration with UiPath Maestro 3 16
AI Trust Layer Not listed 3
Autopilot for everyone 1 2
Coded Agents Not listed 1
Conversational Agents Not listed 1
UI Agent Not listed 1

Notice the first row. The concepts topic shrinks from 6 objectives to 3, because the Professional exam stops asking what machine learning and large language models are. It assumes you know.

What the evaluation objectives cover

At Associate level you define evaluations and tell deterministic ones from model graded ones. At Professional level you run the whole cycle. You design datasets that reflect real complexity, write input and output pairs, add edge cases and failure scenarios, and choose between strict and flexible assertions. Then you execute the set, interpret the scores, read execution traces for the failures, and improve the prompt.

UiPath has been open about why this matters to it.

“We are targeting 95%+ agent accuracy with every launch.”

Raghu Malpani, Chief Technology Officer, UiPath

Developers share the concern behind that target. In the Stack Overflow Developer Survey for 2025, 87 percent of respondents agreed that they are concerned about the accuracy of information from AI agents, and 81 percent agreed that they have security and privacy concerns. Evaluations, guardrails and escalations are the practical answer, which explains their place on the syllabus.

What the Maestro objectives cover

The Associate touches Maestro in 3 objectives: model a process in BPMN and configure service tasks. The Professional list runs to 16. It adds send and receive tasks for connectors and webhooks, global, local and task level variables, and input and output mapping between tasks and agents. It also covers chaining several agents in one process, asynchronous completion events, user tasks with assignees, SLAs and expiry rules, control flow, and instance management.

Where does the Builder Professional certification fit?

Agentic Automation Builder Professional is a separate UiPath credential that launched on 22 September 2026 under the exam number UiPath-AABPv1. It sits in the same Agentic Automation track as UiAAP, runs 120 minutes with a 70 percent pass mark, and costs 150 USD. UiPath has published no statement that it replaces Agentic Automation Professional.

Field Agentic Automation Professional Builder Professional
UiPath exam number UiPath-AAPv1 UiPath-AABPv1
Available since 1 April 2026 22 September 2026
Fee 300 USD 150 USD
Duration 120 minutes 120 minutes
Passing score 70 percent 70 percent
Validity 3 years 3 years
Structure 14 topics 7 numbered domains
Product version 2025.10 and later Latest versions

What Builder Professional adds

The Builder exam reaches into areas UiAAP does not name. It has a full domain on deterministic automation, which covers variables, control flow, UI automation and exception handling. It has another on UiPath for Coding Agents. Its agent domain includes building Python agents, and its orchestration domain includes case management. UiPath also states an experience level for it: at least 6 months of building automations on the platform.

That deterministic domain overlaps with the developer track. If classic workflow skills are your weak point, this site’s UiADP preparation guide covers the same foundations in more depth.

What UiAAP keeps to itself

UiAAP stays closer to the agent itself. Its objectives go deeper on Context Grounding indexes, on evaluation datasets and assertions, and on the detail of Maestro tasks. Both credentials are currently listed side by side on the UiPath Academy certification page. Because the Builder exam is so new, check that listing on the day you book. If UiPath changes the status of either exam, that page is where it will show first.

How should you prepare for UiAAP?

Prepare for UiAAP by working outward from the official exam description. UiPath names three resources: the Agentic Automation Training learning plan on UiPath Academy, the product documentation, and a free practice test. Candidates on the UiPath forum report that the learning plan covers Associate level material, so the documentation has to fill the gap.

  1. Download the exam description, and mark every objective you cannot already carry out in a tenant.
  2. Complete the Agentic Automation Training learning plan, and treat it as the base layer.
  3. Read the product documentation for the five topics the Associate syllabus does not list.
  4. Build one agent in Studio Web with a tool, a Context Grounding index and an escalation.
  5. Write an evaluation set for that agent, run it, and trace every failure back to its cause.
  6. Model a small Maestro process that calls the agent, routes a user task to a person, and returns the data.
  7. Take the free practice test, and review each missed question against the objective it came from.

Steps 4 to 6 are where the exam is won. Sequencing questions and scenario questions both reward people who have watched an evaluation fail and worked out why. One forum member who passed in the first week after launch described a shorter version of the same order: the Associate training, then the exam description, then the practice test.

Booking and retakes

You schedule through the Pearson VUE UiPath page, and you choose between a test centre and an online appointment. If you fail the first attempt, UiPath asks you to wait two weeks before the second. After that, the wait is one month between attempts, and each attempt carries the full fee.

If you are still deciding which UiPath credential suits your role, the overview of UiPath certification paths on this site sets the agentic exams beside the developer, analyst and architect tracks.

Frequently Asked Questions

How many questions are on the UiAAP exam?

The UiAAP exam has 60 questions to answer in 120 minutes, which works out at 2 minutes per question. The format is multiple choice with drag and drop or sequencing items.

What is the passing score for UiAAP?

The passing score is 70 percent. On 60 questions that means 42 correct answers, so you can miss 18 and still pass.

How much does the Agentic Automation Professional exam cost?

The exam fee is 300 USD, which is double the 150 USD fee for the Agentic Automation Associate exam. Each retake carries the full fee again.

Is UiAAP the same exam as UiPath-AAPv1?

Yes. UiAAP is the short code used for the credential, while UiPath and Pearson VUE list the exam as UiPath-AAPv1, the UiPath Agentic Automation Professional Exam. Look for that number when you book.

Do I need the Associate certification before UiAAP?

The Professional exam description names no prerequisite exam. The syllabus does assume Associate level knowledge, so covering that material first is sensible even though UiPath does not list it as a requirement.

Which topics are new in the Professional exam?

Five topics are not on the Associate syllabus: Agent management, AI Trust Layer, Coded Agents, Conversational Agents and UI Agent. Together they list 13 objectives.

How long is the UiAAP certification valid?

The credential is valid for 3 years from the date you earn it. UiPath expects certified professionals to recertify every three years to keep pace with platform changes.

In which languages can I take the UiAAP exam?

UiPath offers the Agentic Automation Professional exam in English and in Japanese. You can sit it at a Pearson VUE test centre or online with a proctor.

Has Builder Professional replaced Agentic Automation Professional?

UiPath has published no statement saying so. Builder Professional launched on 22 September 2026 as a separate credential in the same track, and both are listed on the UiPath Academy certification page. Check that page before you book.

Conclusion

UiAAP is 60 questions in 120 minutes at a 70 percent pass mark, for a fee of 300 USD. Those numbers look close to the Associate exam, and that closeness is what misleads people.

The real distance is in the objective list: 84 against 32, five topics the Associate never mentions, and 30 objectives on evaluations and Maestro alone. The exam is about proving, orchestrating and governing agents, with building them as the starting point.

So prepare in that order. Build one agent, test it until you understand its failures, and place it in a Maestro process with a person in the loop. Then check which agentic credentials UiPath lists on the day you book, and choose the one that matches the work you do.

Rating: 0 / 5 (0 votes)

The post Agentic Automation Professional Certification: What Changes appeared first on iSecPrep.

]]>
SCS-C02 vs SCS-C03: What Changed in AWS Security Specialty https://www.isecprep.com/2026/09/29/scs-c02-vs-scs-c03-what-changed-in-aws-security-specialty/ Tue, 29 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88411 AWS rebuilt two domains, moved four points of weight to identity and wrote seven new tasks into the Security Specialty blueprint. Here is what an SCS-C02 candidate keeps, drops and adds.

The post SCS-C02 vs SCS-C03: What Changed in AWS Security Specialty appeared first on iSecPrep.

]]>

On 2 December 2025, AWS replaced SCS-C02 with SCS-C03 as the live version of the AWS Certified Security – Specialty exam, and more than the code moved. Identity and Access Management rose from 16 to 20 percent of scored content, Infrastructure Security fell from 20 to 18, and the two older domains that mixed threat detection, logging and response were rebuilt as Detection and Incident Response.

AWS also wrote seven new pieces of content into the blueprint, including guardrails for generative AI applications, and took out a long list of fundamentals such as TCP/IP basics and host-based firewalls. If you studied for the old version, or you are reading notes written for it, this SCS-C02 vs SCS-C03 comparison shows what still counts, what is gone and where to spend the hours you have left. Every change listed here comes from the comparison AWS publishes in its own exam guide.

Table of Contents

  1. What changed between SCS-C02 and SCS-C03?
  2. What does the SCS-C03 exam look like on the day?
  3. Which topics are new in SCS-C03?
  4. What did AWS remove from the exam?
  5. Where do the six SCS-C03 domains put their weight?
  6. Who is the SCS-C03 exam written for?
  7. How should an SCS-C02 candidate adjust a study plan?
  8. How long does the certification last, and which languages are ending?
  9. Frequently Asked Questions
  10. Conclusion

What changed between SCS-C02 and SCS-C03?

SCS-C03 keeps six domains but reshapes them. AWS split the old threat detection, incident response, logging and monitoring material into two cleaner domains called Detection and Incident Response, raised Identity and Access Management from 16 to 20 percent, cut Infrastructure Security from 20 to 18 percent, and renamed the governance domain Security Foundations and Governance.

AWS sets the two blueprints side by side in its SCS-C02 and SCS-C03 comparison, which states that SCS-C02 was in use until 1 December 2025 and SCS-C03 from the following day.

Position SCS-C02 domain SCS-C02 weight SCS-C03 domain SCS-C03 weight
1 Threat Detection and Incident Response 14% Detection 16%
2 Security Logging and Monitoring 18% Incident Response 14%
3 Infrastructure Security 20% Infrastructure Security 18%
4 Identity and Access Management 16% Identity and Access Management 20%
5 Data Protection 18% Data Protection 18%
6 Management and Security Governance 14% Security Foundations and Governance 14%

The first two domains were rebuilt, not renamed

Do not read the first two rows as a simple swap. Under SCS-C02, logging sat in its own domain and detection shared a domain with response. Under SCS-C03, monitoring, alerting and logging all live in Detection, while planning for and responding to an event live in Incident Response. Together the pair still carries 30 percent. The old pair carried 32.

Identity is now the heaviest domain

Infrastructure Security used to lead at 20 percent. Identity and Access Management now holds that position, and it is the only domain that gained four points. Data Protection and governance kept their weights exactly.

“To better serve security professionals, we’ve restructured the exam domains, creating distinct sections for Detection and Incident Response capabilities.”

Tim Trsar, AWS Training and Certification Blog

What does the SCS-C03 exam look like on the day?

The SCS-C03 exam has 65 questions and lasts 170 minutes. It costs 300 USD and the minimum passing score is 750 on a scale of 100 to 1,000. Only 50 of the 65 questions affect your score. The other 15 are unscored items that AWS is trialling, and they are not identified on the exam.

Field Value
Exam name AWS Certified Security – Specialty
Exam code SCS-C03
Questions 65 (50 scored, 15 unscored)
Duration 170 minutes
Passing score 750 on a scale of 100 to 1,000
Price 300 USD
Delivery Pearson VUE testing center or online proctored exam
Category Specialty

How the score works

AWS uses a compensatory scoring model. That means you do not need to pass each domain separately, only the exam as a whole, so a strong identity score can cover a weaker incident response score. Unanswered questions count as incorrect and there is no penalty for guessing. Never leave a question blank.

Question types

The exam guide lists four response types:

  • Multiple choice, with one correct response and three distractors.
  • Multiple response, with two or more correct responses out of five or more options.
  • Ordering, where you pick 3 to 5 responses and place them in the correct order.
  • Matching, where you pair responses with a list of 3 to 7 prompts.

Ordering and matching give no partial credit. Every position or pair must be right. On pacing, 170 minutes across 65 questions is a little over two and a half minutes each, which sounds generous until you meet a question built around an IAM policy document. Working a set of SCS-C03 sample questions early shows you how long those scenario items really take to read.

Which topics are new in SCS-C03?

AWS added seven items to SCS-C03. They cover validating findings during an incident, integrating edge services with third-party tools, guardrails for generative AI applications, encryption in transit between resources, imported key material, masking sensitive data, and managing keys and certificates across Regions. Four of the seven sit in the Data Protection domain.

Task Domain What was added
2.2.3 Incident Response Validate findings from AWS security services to assess the scope and impact of an event
3.1.4 Infrastructure Security Configure integrations with AWS edge services and third-party services
3.2.7 Infrastructure Security Implement protections and guardrails for generative AI applications
5.1.3 Data Protection Design and configure inter-resource encryption in transit
5.3.3 Data Protection Describe the differences between imported key material and AWS generated key material
5.3.4 Data Protection Mask sensitive data
5.3.5 Data Protection Create and manage encryption keys and certificates across a single Region or multiple Regions

Generative AI guardrails

This is the addition that gets the attention. The blueprint gives one example for it: applying the protections in the OWASP LLM Top 10. The 2025 edition of that list opens with prompt injection and sensitive information disclosure, and also covers supply chain risk and excessive agency. Keep it in proportion, though. It is one task inside an 18 percent domain, and training machine learning models is explicitly out of scope for the target candidate.

OCSF and third-party edge tools

Task 3.1.4 names the Open Cybersecurity Schema Framework as its example, alongside third-party WAF rules. OCSF is an open, vendor-neutral format for security events, and the OCSF schema project publishes it in the open. Amazon Security Lake, which the Detection domain also names, is the service where candidates usually meet it.

Keys, masking and multi-Region

The Data Protection additions are practical. You should be able to explain how imported key material differs from key material that AWS KMS generates, mask sensitive values with CloudWatch Logs data protection policies or Amazon SNS message data protection, and manage customer managed keys and AWS Private Certificate Authority across Regions. Inter-node encryption for Amazon EMR, Amazon EKS and SageMaker AI is named as well.

What did AWS remove from the exam?

AWS removed a set of fundamentals and older references from SCS-C03. The published deletions include TCP/IP networking concepts, host-based security, the components of an IAM policy, TLS concepts, the AWS Security Finding Format, the AWS Security Incident Response Guide, log format and components, and configuring S3 static website hosting.

SCS-C03 study triage showing what to keep, what to drop and what to add after SCS-C02

The full list of published deletions, grouped by the SCS-C02 task each one came from:

  • Task 1.1: AWS Security Finding Format (ASFF).
  • Task 1.3: the AWS Security Incident Response Guide.
  • Task 2.5: log format and components, such as CloudTrail logs.
  • Task 3.3: host-based security and activating host-based firewalls.
  • Task 3.4: analysing reachability, fundamental TCP/IP networking concepts, and prioritising problems in network connectivity.
  • Task 4.2: the components and impact of a policy, such as Principal, Action, Resource and Condition.
  • Task 5.1: TLS concepts, and cross-Region networking with private and public VIFs.
  • Task 5.2: configuring S3 static website hosting.
  • Task 6.4: identifying security gaps through architectural reviews and cost analysis.

Removed from the list is not the same as safe to skip

Read the pattern before you delete your notes. Most of what left is knowledge a working engineer already has. The exam no longer asks you to describe the parts of a policy, yet it still asks you to design, interpret and implement IAM policies and to analyse authorization failures. You cannot do that without knowing what a Condition block does.

The same holds for networking. OSI layers are gone as a topic, while security groups, network ACLs, AWS Network Firewall and segmentation remain. Treat the deletions as AWS raising the floor, not shrinking the syllabus.

Where do the six SCS-C03 domains put their weight?

The six SCS-C03 domains are Detection at 16 percent, Incident Response at 14, Infrastructure Security at 18, Identity and Access Management at 20, Data Protection at 18, and Security Foundations and Governance at 14. The weights apply to scored content, so they describe the 50 scored questions and not all 65.

Domain Weight Task statements
Detection 16% Monitoring and alerting solutions; logging solutions; troubleshooting monitoring, logging and alerting
Incident Response 14% Design and test an incident response plan; respond to security events
Infrastructure Security 18% Network edge services; compute workloads; network security controls
Identity and Access Management 20% Authentication strategies; authorization strategies
Data Protection 18% Data in transit; data at rest; confidential data, credentials, secrets and cryptographic key materials
Security Foundations and Governance 14% Centrally deploy and manage AWS accounts; consistent deployment strategy; evaluate compliance

Two task statements carry a fifth of the exam

Identity and Access Management has only two task statements, authentication and authorization, yet it holds the largest share. That makes it the densest domain on the blueprint. Expect IAM Identity Center, Amazon Cognito, AWS STS, permission boundaries, session policies, IAM Roles Anywhere and IAM Access Analyzer to appear in scenario form.

Governance is about many accounts, not one

Security Foundations and Governance assumes an organization, not a single account. Its examples include AWS Organizations, AWS Control Tower, service control policies, resource control policies, AI service opt-out policies and centralised root access for member accounts. If your experience is limited to one account, this is the domain to practise in a sandbox organization.

Who is the SCS-C03 exam written for?

The SCS-C03 exam guide describes a target candidate with the equivalent of 3 to 5 years of experience securing cloud solutions. AWS requires no earlier certification before you sit the exam. Its certification page adds that candidates commonly hold AWS Certified Solutions Architect – Associate or Professional first.

AWS words the experience in a second way on the certification page: five years of IT security experience designing and implementing security solutions, plus two or more years of hands-on work securing AWS workloads. Both descriptions point at the same person, someone who has already run security in production.

What AWS expects you to know already

  • The shared responsibility model and how it applies.
  • Managing identity at scale and multi-account governance.
  • Software supply chain risk and vulnerability management in the cloud.
  • Firewall rules at scale for layers 3 to 7.
  • Incident root cause analysis and responding to an audit.
  • Encryption at rest and in transit, plus backup and disaster recovery controls.

What is out of scope

The guide also lists job tasks the candidate is not expected to perform: designing cryptographic algorithms, analysing traffic at packet level, architecting overall cloud deployments, managing end-user compute resources and training machine learning models. That list is useful when a study resource drifts into packet captures or model training. You can stop reading.

If you want the older blueprint for reference, this site’s earlier SCS-C02 exam walkthrough shows how the previous version was organised, which makes the changes above easier to see.

How should an SCS-C02 candidate adjust a study plan?

An SCS-C02 candidate moving to SCS-C03 should keep most existing notes and re-sort them. Start by mapping old material to the six new domains, then add the seven new tasks, give Identity and Access Management the most time, and practise ordering and matching questions, since both need every part correct to score.

A four phase move from SCS-C02 to SCS-C03: sort notes into six domains, add seven new tasks, focus on IAM at 20 percent, then test 65 questions in 170 minutes
  1. Re-file your notes under the six SCS-C03 domain names, moving all logging and monitoring material into Detection and all response material into Incident Response.
  2. Write one page for each of the seven added tasks, using the example services AWS names for each.
  3. Give Identity and Access Management the largest block of study time, because it now holds 20 percent of scored content.
  4. Build a multi-account sandbox with AWS Organizations and practise service control policies, delegated administrators and centralised root access.
  5. Practise ordering and matching questions until you can sequence an incident response without hesitating.
  6. Sit a full timed set of 65 questions in 170 minutes and review every miss by domain.

What carries over unchanged

Data Protection kept its 18 percent and governance kept its 14. Encryption at rest, S3 Object Lock, AWS Secrets Manager, AWS Config, AWS Audit Manager and AWS Firewall Manager all remain. Work you did on those topics for SCS-C02 still pays.

A caution on old material

Search results still surface plenty of SCS-C02 and even SCS-C01 content. Before trusting a resource, check that it names Detection and Incident Response as separate domains. If it lists Security Logging and Monitoring as a domain, it was written for the retired blueprint.

How long does the certification last, and which languages are ending?

AWS Certified Security – Specialty is valid for 3 years, and you recertify by passing the latest version of the exam. AWS offers SCS-C03 in six languages today, but the Simplified Chinese, Spanish (Latin America) and Portuguese (Brazil) versions will be retired after 31 December 2026. English, Japanese and Korean are not part of that notice.

Both facts come from the AWS certification page. If you planned to sit the exam in one of the three retiring languages, the practical deadline is the end of December 2026. After that date you would need to take it in one of the remaining languages.

Cost of the next exam

AWS states that once you hold one AWS Certification, you receive a 50 percent discount on your next AWS Certification exam, claimed through your AWS Certification Account. For a holder of an Associate credential, that halves the 300 USD fee.

Where the credential leads

AWS names AWS Certified DevOps Engineer – Professional and AWS Certified Advanced Networking – Specialty as certifications that professionals earn afterwards, on the way to roles such as DevSecOps Engineer or Networking Engineer. For a wider view of how AWS credentials fit a career, see this site’s piece on AWS certification career value.

Frequently Asked Questions

Is SCS-C02 still available?

No. AWS states that SCS-C02 was in use until 1 December 2025 and that SCS-C03 has been in use since 2 December 2025. Anyone booking the exam now sits SCS-C03.

How many questions are on the SCS-C03 exam?

There are 65 questions. Fifty affect your score and 15 are unscored questions that AWS is evaluating for future use. The unscored questions are not identified, so answer all 65 with equal care.

What is the passing score for SCS-C03?

The minimum passing score is 750 on a scaled range of 100 to 1,000. Scoring is compensatory, so you need to pass the exam overall and not each domain separately.

How much does the AWS Security Specialty exam cost?

The exam costs 300 USD. AWS gives holders of an active AWS Certification a 50 percent discount on their next exam, claimed through the AWS Certification Account.

Which domain has the highest weight in SCS-C03?

Identity and Access Management, at 20 percent of scored content. It was 16 percent under SCS-C02. Infrastructure Security and Data Protection follow at 18 percent each.

Does SCS-C03 test generative AI?

Yes, in one task. Task 3.2.7 asks you to implement protections and guardrails for generative AI applications, with the OWASP Top 10 for LLM Applications as the example. Training machine learning models is out of scope.

Do I need another AWS certification before SCS-C03?

No. AWS requires no specific certification first. It notes that candidates commonly earn AWS Certified Solutions Architect – Associate or Professional before attempting the Security Specialty exam.

How long is AWS Certified Security – Specialty valid?

The certification is valid for 3 years. Before it expires, you can recertify by passing the latest version of the exam.

Which SCS-C03 exam languages are being retired?

AWS will retire the Simplified Chinese, Spanish (Latin America) and Portuguese (Brazil) versions after 31 December 2026. The exam is also offered in English, Japanese and Korean.

Conclusion

SCS-C03 is the same size as the exam it replaced: 65 questions, 170 minutes, 750 to pass. What changed is where the marks sit. Identity and Access Management is now the largest domain at 20 percent, detection and response each have a domain of their own, and seven new tasks bring in generative AI guardrails, OCSF, imported key material and data masking.

For anyone holding SCS-C02 notes, that is good news. Most of the material survives, and the published deletions are fundamentals you still use every day. Re-sort what you have, add the seven new tasks, and put your extra hours into identity and multi-account governance. Then test the plan against timed scenario questions before you book.

Rating: 0 / 5 (0 votes)

The post SCS-C02 vs SCS-C03: What Changed in AWS Security Specialty appeared first on iSecPrep.

]]>
What Does the PSM-AI Essentials Exam Actually Test? https://www.isecprep.com/2026/09/28/what-does-the-psm-ai-essentials-exam-actually-test/ Mon, 28 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88380 Scrum Masters who prepare for a technology exam get a surprise. Three of the four syllabus topics cover how you use AI with a team, and 40 questions leave room for six misses.

The post What Does the PSM-AI Essentials Exam Actually Test? appeared first on iSecPrep.

]]>

Most Scrum Masters who book PSM-AI Essentials revise the wrong thing. They expect Scrum.org’s Professional Scrum Master AI Essentials assessment to quiz them on neural networks, model training and the vocabulary of machine learning, so they spend their evenings on how the technology works.

Only one of the four syllabus topics is AI theory. The other three ask whether you can use a generative AI tool inside a Scrum Team without leaking data, trusting a confident wrong answer, or quietly taking a decision away from the people who own it. That is a judgement test, and at an 85 percent pass mark on 40 questions, you can afford only six mistakes.

Table of Contents

  1. What does the PSM-AI Essentials exam look like on the day?
  2. Which four topics does the syllabus name?
  3. Why is most of the paper about judgement?
  4. What does AI Security and Ethics expect you to know?
  5. How is effective prompting tested?
  6. PSM-AI Essentials, PSM I or PSPO-AI Essentials?
  7. How should you prepare for PSM-AI Essentials?
  8. Frequently Asked Questions
  9. Conclusion

What does the PSM-AI Essentials exam look like on the day?

The PSM-AI Essentials exam is 40 multiple choice questions in 60 minutes, with an 85 percent passing score and a fee of 200 USD. The syllabus lists four topics and publishes no weightings for any of them, so you cannot plan by percentage. You plan by topic, and you plan for a very small error budget.

Field Value
Exam name Scrum.org Professional Scrum Master AI Essentials
Exam code PSM-AI Essentials (also written PSM-AIE)
Questions 40
Duration 60 minutes
Passing score 85 percent
Fee 200 USD
Format Multiple choice
Topics 4, with no published weightings

Two numbers in that table matter more than the rest. First, 85 percent of 40 is 34, so the whole attempt tolerates six wrong answers. Second, 60 minutes for 40 questions gives you 90 seconds each, which is generous. Time is rarely what beats a candidate here. Accuracy is.

That combination changes how you should use the clock. With 90 seconds per question you can read every option twice, and you should, because the wrong answers on this paper tend to sound reasonable. A careless pick costs you a sixth of your allowance.

Which four topics does the syllabus name?

The PSM-AI Essentials syllabus names four topics: AI Theory and Primer, AI Security and Ethics, AI for Scrum Masters, and Effective AI Prompting. None is weighted. Only the first is about how AI works; the other three are about how a Scrum Master uses it responsibly with a team.

AI Theory and Primer

This is the foundation layer: what generative AI is, what a large language model does with a prompt, and why its output is a prediction rather than a looked-up fact. You need enough to explain the tool to a team, not enough to build one.

AI Security and Ethics

Data handling, privacy, bias and transparency. This topic asks what can go wrong when a team starts pasting work into an AI tool, and what a Scrum Master should do before it does.

AI for Scrum Masters

The accountability topic. It covers where AI can genuinely help a Scrum Master, such as summarising retrospective input or drafting options, and where using it would undermine self-management or transparency.

Effective AI Prompting

Writing prompts that return something useful. It is also the only topic on the Scrum Master paper with no counterpart on the Product Owner equivalent, which makes it the clearest difference between the two AI Essentials exams.

The fastest way to see how these topics turn into questions is to work a set of PSM-AI Essentials sample questions before you study anything else. Almost every item is a short scenario with a Scrum Master in it, followed by four plausible responses.

Why is most of the paper about judgement?

Because the credential is about the Scrum Master accountability, not about AI engineering. Published sample questions for PSM-AI Essentials almost all describe a Scrum Master facing a choice with an AI tool, and the correct answer is usually the one that keeps people in charge of decisions, data and quality.

PSM-AI Essentials exam infographic of four judgement calls: guard the data, check the output, team owns it, ask policy first

That framing is older than any AI tool. The first value of the Agile Manifesto, written in 2001, is individuals and interactions over processes and tools. An AI assistant is a tool, and the exam keeps asking whether you remember that.

The patterns repeat across the sample items:

  • Anything typed into a public AI tool may be stored, logged or reused, so treat it as shared.
  • Personal identifiers should be stripped or pseudonymised before data leaves the team.
  • A generative model can produce output that is plausible and wrong, so someone must check it.
  • AI may draft a Definition of Done, but the Developers agree on it and own it.
  • A new tool gets checked against the organisation’s acceptable use and data policies first.

Each of those answers protects something the Scrum Guide already assigns to a person. Self-management belongs to the team, the Definition of Done belongs to the Developers, and transparency belongs to everyone. The Scrum Master’s job is to keep it that way while the tools change.

“The Scrum Master is accountable for the Scrum Team’s effectiveness. They do this by enabling the Scrum Team to improve its practices, within the Scrum framework.”

Ken Schwaber and Jeff Sutherland, authors of The Scrum Guide

Read the wrong options in any sample item and you will see the same shortcut offered again and again: let the tool decide, adopt its output as-is, or skip the team. Spotting that shortcut is most of the skill.

What does AI Security and Ethics expect you to know?

AI Security and Ethics expects a PSM-AI Essentials candidate to recognise the everyday risks of using generative AI at work: sensitive data leaving the organisation, output that is confidently wrong, recommendations nobody can explain, and tools adopted without checking policy. It is practical awareness, not security engineering.

The risks worth naming

The security community has already catalogued these. The OWASP LLM Top 10 for 2025 lists prompt injection first, sensitive information disclosure second and misinformation ninth. You will not be asked to defend against prompt injection in code, but you should recognise why confidential sprint data should not go into a public chatbot, and why a polished answer still needs checking.

Ethics is mostly transparency

One sample item asks what concern arises when an AI tool ranks backlog risks and gives no reasoning. The answer is transparency and explainability. In Scrum terms, a decision nobody can inspect cannot be adapted, so an unexplained AI recommendation is a transparency problem before it is anything else.

Frameworks behind the topic

For organisational context, the NIST AI framework is a useful reference. It was released on 26 January 2023 for voluntary use, and NIST added a Generative AI Profile, NIST AI 600-1, on 26 July 2024. You do not need to memorise it; it simply shows that the risks this topic names are the same ones organisations are formally managing.

How is effective prompting tested?

Effective prompting in PSM-AI Essentials is tested through short before-and-after scenarios. A vague prompt returns a generic answer, and you choose the revision that fixes it. The winning revision nearly always adds context, a clear goal, a specific task or an explicit output format, never a louder request or a bigger model.

PSM-AI Essentials exam infographic showing four parts of a better prompt: situation, goal, task and format

The sample items make the principle concrete. “Give me some retrospective ideas” is too vague to help. “Help with the team” is worse. The better option in each case states the situation and names the task, such as asking for three ways to help a team surface impediments in the Daily Scrum.

A useful prompt for this exam has four parts, and each one fixes a different failure:

  1. Situation, so the tool knows the team, the event and the problem.
  2. Goal, so it knows what a good result would achieve.
  3. Task, so it knows exactly what to produce and how much of it.
  4. Format, so the answer arrives as five bullet points rather than dense prose.

Watch for the distractors. Answers that repeat the same prompt until something better appears, ask for the longest possible response, or simply demand a better model are the traps. None of them clarifies the task, which is the only thing that reliably improves the output.

PSM-AI Essentials, PSM I or PSPO-AI Essentials?

PSM-AI Essentials, PSM I and PSPO-AI Essentials share the same 200 USD fee, the same 60 minutes and the same 85 percent bar. They differ in length and focus: PSM I tests the Scrum framework across 80 questions, while the two AI Essentials exams each have 40 questions on applying AI within one accountability.

Exam Questions Time per question Topics Focus
PSM I 80 45 seconds Scrum framework, people and teams, managing products How Scrum works
PSM-AI Essentials 40 90 seconds AI Theory and Primer, AI Security and Ethics, AI for Scrum Masters, Effective AI Prompting AI in the Scrum Master accountability
PSPO-AI Essentials 40 90 seconds AI Theory and Primer, AI Security and Ethics, AI Product Ownership AI in the Product Owner accountability

The practical difference is pace. PSM I gives you 45 seconds a question, so it rewards fast recall of the Scrum Guide. PSM-AI Essentials doubles that time and spends it on scenarios where two answers look sensible, so it rewards careful reading.

If you are choosing between the two AI Essentials exams, pick by accountability. The Scrum Master version is the only one with a prompting topic, while the Product Owner version replaces it with product ownership. A Scrum Master who still wants to strengthen the framework basics first can start with this site’s guide to PSM I preparation, since the AI questions assume you already know who owns what in Scrum.

How should you prepare for PSM-AI Essentials?

Prepare for PSM-AI Essentials by using AI tools on real Scrum Master work and checking every result, not by studying machine learning. Refresh the Scrum Guide accountabilities, practise rewriting weak prompts, learn the common data and accuracy risks, then work scenario questions until the tempting shortcut answers stop tempting you.

  1. Reread the Scrum Guide sections on accountabilities, the Definition of Done and transparency, because most correct answers defend one of them.
  2. Spend one short session on AI theory so you can explain why a model can sound certain and still be wrong.
  3. Use an approved AI tool on a real task, such as grouping retrospective notes into themes, and check the output yourself before sharing it.
  4. Rewrite three vague prompts from your own work by adding situation, goal, task and format, and compare the answers.
  5. Read your organisation’s acceptable use and data policies so the policy questions feel familiar.
  6. Work scenario questions and, for every miss, name the shortcut the wrong answer offered.

The prompting and retrospective work overlaps heavily with facilitation. If that is a weak area, the site’s PSF Skills guide covers the facilitation side of the Scrum Master role in more depth.

Book the attempt when you are consistently above 34 out of 40 in practice, not when you first scrape past it. With only six misses allowed, a comfortable margin matters more than speed.

Frequently Asked Questions

How many questions are on the PSM-AI Essentials exam?

Forty multiple choice questions in 60 minutes, which works out at 90 seconds per question.

What is the passing score for PSM-AI Essentials?

Eighty five percent. On 40 questions that means 34 correct answers, so you can miss six.

How much does PSM-AI Essentials cost?

The listed fee is 200 USD, the same as PSM I and PSPO-AI Essentials.

What are the four PSM-AI Essentials topics?

AI Theory and Primer, AI Security and Ethics, AI for Scrum Masters, and Effective AI Prompting. No weightings are published for any of them.

Is PSM-AI Essentials a technical AI exam?

No. Only one topic covers AI theory. The rest test how a Scrum Master uses AI tools with a team while protecting data, quality and ownership.

Do I need PSM I before PSM-AI Essentials?

The syllabus page lists no prerequisite. Check the current rules on Scrum.org before booking, and note that the questions assume you already know Scrum accountabilities well.

How is PSM-AI Essentials different from PSPO-AI Essentials?

Both have 40 questions, 60 minutes and an 85 percent pass mark. The Scrum Master exam includes Effective AI Prompting, while the Product Owner exam has an AI Product Ownership topic instead.

Does PSM-AI Essentials expire?

The syllabus page publishes no validity period or renewal rule, so confirm it on Scrum.org rather than relying on second-hand claims.

What is the best way to practise for PSM-AI Essentials?

Use AI on real Scrum Master tasks, check every output, practise rewriting vague prompts, and work scenario questions until you can name why each wrong option is wrong.

Conclusion

PSM-AI Essentials is 40 questions in 60 minutes at an 85 percent pass mark, and the pass mark is the real difficulty. Six misses is not much room on a paper built from reasonable-sounding options.

The candidates who struggle are usually the ones who prepared for a technology exam. The syllabus spends one topic on how AI works and three on how a Scrum Master uses it: keeping data safe, checking output, protecting team ownership and writing prompts that ask for something specific.

Prepare in that proportion. Use the tools on real work, verify what they give you, and practise on scenarios until the shortcut answers stand out. When your practice scores sit comfortably above 34, you are ready to book.

Rating: 0 / 5 (0 votes)

The post What Does the PSM-AI Essentials Exam Actually Test? appeared first on iSecPrep.

]]>
Qlik Sense Data Architect Certification: The Script Layer https://www.isecprep.com/2026/09/28/qlik-sense-data-architect-certification-the-script-layer/ Mon, 28 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88362 Most candidates revise connectors and skim the load script. The published weightings say connectors are eight percent and the script is nearly two fifths of the paper.

The post Qlik Sense Data Architect Certification: The Script Layer appeared first on iSecPrep.

]]>

This is not the dashboard exam. Nothing in it asks you to build a sheet, choose a chart or lay out an application, and a developer who has spent two years making front ends will find surprisingly little of their daily work on the paper. Qlik has a separate credential for that.

The Qlik Sense Data Architect certification sits a layer underneath, in the load script and the model it produces, and the published weightings make the point without ambiguity: data transformations and data model design take 66 percent of the exam between them. Connectivity and validation, which most candidates assume will matter, take 14.

Table of Contents

  1. QSDA or QSBA, which exam is yours?
  2. What are the QSDA exam facts?
  3. Where does the exam weight actually sit?
  4. What does the 38 percent transformations topic cover?
  5. What does data model design ask for?
  6. The three light topics, and why light is not skippable
  7. What does Qlik expect you to have built already?
  8. How should you prepare?
  9. Frequently Asked Questions
  10. Conclusion

QSDA or QSBA, which exam is yours?

QSDA is the data architect exam and QSBA is the business analyst one. The first tests how you get data into Qlik Sense and shape it; the second tests what you build on top once it is there. They are separate credentials for separate jobs, and picking the wrong one is the most expensive mistake available here.

QSDA covers the Qlik data layer of load scripts and data models, while QSBA covers the application layer of sheets and charts for business users

The clean test is where your work happens. If you spend your time in the data load editor, writing scripts, joining tables, deciding what the model should look like and why a chart is slow, QSDA is the exam that describes you. If you spend it in the app, choosing visualisations, building sheets and working with business users on what they want to see, the business analyst route fits better.

There is overlap in one place, and the blueprint puts it first. Twenty percent of QSDA is identifying requirements, which includes working out what business users actually need, who the stakeholders are, and what granularity the numbers should sit at. A data architect who cannot do that builds technically sound models that answer nobody’s question, so Qlik tests it before it tests any script.

Qlik lists both credentials, and several others, on its certifications overview. Read the role description rather than the title before booking anything.

What are the QSDA exam facts?

QSDA is 50 questions in 90 minutes at a 62 percent pass mark, priced at 250 USD, delivered as a proctored multiple choice exam you sit remotely. Five topics are published, all of them weighted, and the exam is platform-neutral across client-managed Qlik Sense and Qlik Cloud.

Field Value
Exam name Qlik Sense Data Architect
Exam code QSDA
Questions 50
Duration 90 minutes
Passing score 62 percent
Price 250 USD
Delivery Proctored, remote, machine locked down with webcam supervision
Platform scope Client-managed Qlik Sense and Qlik Cloud
Topics 5, weighted 20, 8, 28, 38 and 6 percent

One number in that table is worth stating carefully. Some exam catalogues list this paper at 120 minutes. Qlik’s own exam details page gives 90, and that is the figure used throughout here. The difference is not academic: 50 questions in 90 minutes is 108 seconds each rather than 144, which is enough to change how you pace a scenario-heavy paper.

Qlik is also unusually open about how the pass mark works. It states that exam content is updated periodically, that the number and difficulty of questions may change, and that the passing score is adjusted to maintain a consistent standard. So 62 percent is not a fixed bar you can calibrate against forever; it is the current expression of a constant standard, and the standard is what you are actually preparing for.

Price is the one field Qlik does not publish on that page, so treat 250 USD as the catalogue figure and confirm it when you book.

Where does the exam weight actually sit?

In the script and the model. Data transformations is 38 percent and data model design is 28, which is 66 percent of the paper in two topics. Identify requirements takes 20 percent, data connectivity 8 and validation 6. The distribution is published by both the exam catalogue and Qlik, and the two agree exactly.

Topic Weight What it is
Identify Requirements 20% Business needs, stakeholders, granularity, dimensionality, security level
Data Connectivity 8% Which sources and connectors, and how to create the connections
Data Model Design 28% Measures and attributes, model type, optimisation, efficient structures
Data Transformations 38% Building content, nulls, documentation, dates, script organisation, incremental loading
Validation 6% Testing scripts and testing data

Read those numbers against how people usually prepare and the mismatch is obvious. Candidates tend to revise connectors, because connectors are concrete and easy to list. Connectivity is 8 percent, roughly four questions. Meanwhile the load script, which is harder to revise because it is a skill rather than a list, is nearly two fifths of the paper.

The practical instruction is to spend your time in proportion. If you have ten study sessions, six or seven belong in the script and the model, two in requirements, and the remaining one across connectivity and validation together.

What does the 38 percent transformations topic cover?

Everything that happens between a raw source and a usable model. Six objectives: building data content to requirements, handling nulls and blanks so filtering behaves, documenting load scripts, date handling, script organisation and cleansing, and the variables needed for incremental loading in the extract layer.

Incremental loading is the one to take seriously. It is named explicitly, it sits in the extract layer, and it is production work rather than exam theory: you are being asked how to load only what has changed since the last run, which means understanding what drives the decision and which variables carry the state. Anyone who has only ever done full reloads on small datasets will find this unfamiliar.

Null and blank handling earns its place for a subtler reason. The objective ties it to filtering, not to correctness, and that connection is the insight. A null that is technically harmless in the data can make a selection behave in a way a user reads as a bug, so the exam wants you to reason about the consequence in the application rather than about the value in the field.

Two objectives are about discipline rather than technique: documenting load scripts, and script organisation and cleansing. They look like filler and are not. A script nobody can follow is a maintenance liability, and Qlik has chosen to examine that directly. Qlik’s load script documentation is the reference if your habits were learned on the job rather than from the manual.

What does data model design ask for?

Four objectives across 28 percent: determining measures and attributes from each source, identifying the appropriate type of data model, optimising the model for Qlik Sense specifically, and implementing data structures efficiently. It is the judgement half of the exam, where transformations is the execution half.

The phrase doing the work is “appropriate type of data model”. You are expected to choose, with reasons, rather than to apply one shape everywhere. That means recognising when a star schema is right, when a snowflake is acceptable, when to denormalise for speed, and when the answer is to split a model rather than stretch one.

“Optimised for Qlik Sense” is deliberate too. Generic warehouse modelling instincts do not transfer cleanly, because Qlik’s associative engine rewards different choices from a relational query engine: synthetic keys and circular references are problems here that would be unremarkable elsewhere, and column cardinality affects memory in ways that matter at load time.

Requirements feed straight into this, which is why the blueprint puts them first. Granularity, aggregation level and the need for slowly changing dimensions are all named in the 20 percent requirements topic, and each is a decision that constrains the model before you write a line of script. Recognising that need early is exactly what the exam is testing.

The three light topics, and why light is not skippable

Requirements at 20 percent, connectivity at 8 and validation at 6 make up the remaining third. Only two of them are genuinely small, and treating any of them as optional is how a candidate with strong scripting skills still fails.

Requirements is not light at all, despite sitting outside the two heavy topics. Twenty percent is roughly ten questions, and its objectives are the ones least improved by technical practice: identifying stakeholders from a scenario, settling metrics and levels of granularity, and determining the appropriate level of security. These are consulting questions, and they reward having sat in the meeting rather than having read about it.

Connectivity at 8 percent is genuinely small, and it is also the easiest topic to secure. Two objectives, both concrete: which sources and connectors a situation needs, and the right way to create those connections. A single focused session covers it, and it would be careless to lose four questions to something that finite.

Validation at 6 percent is the smallest topic on the paper and the one most often left to chance. Two objectives, testing scripts and testing data, and they are worth understanding as separate activities: a script can run perfectly and still produce a model that is wrong. Three questions is not many, but at a 62 percent pass mark the margin is thin enough that three is worth having.

What does Qlik expect you to have built already?

Production applications, not practice ones. Qlik publishes a recommended experience list, and it reads as a description of a working data architect rather than a study prerequisite, which tells you how the questions will be framed.

The experience Qlik recommends before sitting QSDA: shipped production applications, load scripts written by you, understanding of the QVD layer, and SQL basics
  • Practical experience developing multiple production-quality Qlik Sense applications
  • Ability to write Qlik Sense load scripts and validate data
  • A basic understanding of extract, transform and load as a discipline
  • Creating and using connectors to various data sources
  • Understanding the QVD layer and the architecture of the Qlik platform
  • Ability to architect data to provide optimal performance
  • Familiarity with SQL and relational databases

The QVD layer entry is the one to check yourself against honestly. QVD files are Qlik’s own storage format and the layered extract, transform and load pattern built on them is how serious Qlik estates are organised. If you have never worked in a layered architecture, the incremental loading material in the transformations topic will feel abstract, because it exists to serve exactly that pattern.

The SQL entry matters for a different reason. Much of what a Qlik data architect does is decide what to push back to the source and what to do in the script, and that decision needs enough SQL to know which is cheaper. The exam is platform-neutral across client-managed and cloud deployments, so nothing here depends on where your Qlik sits. A related view of how Qlik frames a specialist credential appears in the QAIS specialist guide.

How should you prepare?

Work in the script, in proportion to the weightings, on a model you did not build. Reading about transformations does not prepare you for a paper where nearly two fifths of the questions describe a situation and ask which method is correct.

  1. Split your study time to match the weights, with roughly two thirds of it in transformations and model design.
  2. Build one layered extract, transform and load setup with a QVD layer, even a small one, so the architecture is something you have assembled.
  3. Implement incremental loading end to end and work out for yourself which variables carry the state between runs.
  4. Take a model somebody else built and find its synthetic keys and circular references, because diagnosing is closer to the exam than designing.
  5. Practise the requirements objectives out loud: given a scenario, name the stakeholders, the granularity and the security level.
  6. Spend one session on connectivity and one on validation, which is enough for 14 percent of the paper.
  7. Work a set of QSDA sample questions to calibrate how the script material is actually asked.

If you are coming from the application side, invert the emphasis and expect the adjustment to take longer than you plan. The front-end instincts that make a good sheet designer do not help with a slow model, and the exam is almost entirely about the second problem. An older look at the same credential is available in the site’s earlier data architect overview, useful for the role framing rather than the current figures.

Frequently Asked Questions

How many questions are on the QSDA exam?

Fifty questions in 90 minutes, which is about 108 seconds each.

What is the passing score for QSDA?

Sixty two percent. Qlik states that it adjusts the passing score as content and question difficulty change, so that the standard stays consistent.

How long is the exam, 90 or 120 minutes?

Ninety minutes. Some catalogues list 120, but Qlik’s own exam details page gives 90, and that is the figure to plan against.

What is the difference between QSDA and QSBA?

QSDA is the data architect exam, covering the load script and the data model. QSBA is the business analyst exam, covering what gets built in the application once the data is there.

What are the five topics and their weightings?

Identify requirements at 20 percent, data connectivity at 8, data model design at 28, data transformations at 38, and validation at 6.

Does the exam cover Qlik Cloud or client-managed Qlik Sense?

Both. Qlik states the exam is platform-neutral, so the content applies to either deployment.

How much does QSDA cost?

Two hundred and fifty US dollars as listed. Qlik does not publish a price on its exam details page, so confirm the figure when you book.

Is the exam proctored?

Yes. It is sat remotely with the machine locked down and webcam supervision throughout.

Do I need SQL for this exam?

Qlik lists familiarity with SQL and relational databases as recommended experience. You are not tested on writing SQL, but the modelling decisions assume you understand what the source can do.

What do I get for passing?

The Qlik Sense Data Architect certification and a digital badge issued through Credly.

Conclusion

QSDA is the script and model exam. Fifty questions in 90 minutes, 62 percent to pass, 250 USD, and five topics in which transformations and model design take 66 percent between them.

Prepare in that proportion. Incremental loading, null handling for filtering, script discipline and choosing a model type for Qlik’s engine rather than for a relational one are where the questions live, and none of them yields to revision without a keyboard. Requirements at 20 percent is the topic experience helps with most and study helps with least.

Check the duration before you plan your pacing, since the catalogue figure and Qlik’s own differ, and remember that the 62 percent bar moves with the paper by design. Then work the two heavy topics until the script is something you write rather than something you recognise.

Rating: 0 / 5 (0 votes)

The post Qlik Sense Data Architect Certification: The Script Layer appeared first on iSecPrep.

]]>
CompTIA SecAI+ Certification: Forty Percent Is One Domain https://www.isecprep.com/2026/09/26/comptia-secai-plus-certification-forty-percent-is-one-domain/ Sat, 26 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88354 Most readers meet this credential expecting a course in using AI tools faster. The weightings tell a different story, and the largest domain covers controls that appear on no other CompTIA exam.

The post CompTIA SecAI+ Certification: Forty Percent Is One Domain appeared first on iSecPrep.

]]>

Read the name and you assume the exam is about using artificial intelligence to do security work faster. Automated triage, AI-assisted code review, a chatbot that summarises an incident. That material is on the paper, and it is 24 percent of it.

The largest domain, at 40 percent, goes the other way. It is about securing the AI systems themselves: threat modelling a model, putting a firewall in front of a prompt, deciding who can reach the training data. The CompTIA SecAI+ certification is mostly a defending-AI credential, and the published weightings say so plainly.

Table of Contents

  1. What does SecAI+ actually examine?
  2. What are the CY0-001 exam facts?
  3. Domain 1: how much AI theory do you need?
  4. Domain 2: what does securing an AI system involve?
  5. Domain 3: where does AI help the defender?
  6. Domain 4: what does the governance domain expect?
  7. Who should take this exam?
  8. How should you prepare?
  9. Frequently Asked Questions
  10. Conclusion

What does SecAI+ actually examine?

Four domains, weighted, and the weighting is the answer. Securing AI systems takes 40 percent. AI-assisted security, the domain most people expect to dominate, takes 24 percent. Basic AI concepts take 17 percent and governance, risk and compliance take 19 percent. Defending AI outweighs using it by a clear margin.

Domain Weight What it is
Basic AI concepts related to cybersecurity 17% The vocabulary and mechanics of models, training and prompts
Securing AI systems 40% Threat modelling, guardrails, gateway controls, access to models and data
AI-assisted security 24% Using AI tooling for defence, and how attackers use it too
AI governance, risk and compliance 19% Structures, roles, responsible AI, regulation

That single number reorganises how you should prepare. Two fifths of the questions concern a class of asset most security teams did not own two years ago, and the controls involved have no equivalent on the exams you have already passed. An experienced defender will recognise most of domain 3 on sight and very little of domain 2.

It also explains who the credential is aimed at. This is not a course in prompt writing. It assumes your organisation now runs models in production, exposes them to users, and has to answer for what they do, and it tests whether you can secure and govern that. The full SecAI+ exam syllabus sets out every objective under those four headings.

What are the CY0-001 exam facts?

CY0-001 runs 60 minutes with up to 60 questions, a mix of multiple choice and performance-based items, scored on a scale of 100 to 900 with 600 required to pass. It costs 298 USD, is delivered through Pearson VUE, and is available in English and Japanese.

Field Value
Exam code CY0-001
Exam name CompTIA SecAI+
Questions Maximum of 60, multiple choice and performance-based
Duration 60 minutes
Passing score 600 on a scale of 100 to 900
Price 298 USD
Delivery Pearson VUE
Languages English and Japanese
Launched 17 February 2026
Domains 4, weighted 17, 40, 24 and 19 percent

Two details in that table are worth drawing out. The question count is a maximum rather than a fixed number, and the paper mixes performance-based items with multiple choice, which CompTIA states on its official SecAI+ page. Sixty minutes for up to 60 questions is already tight at a minute each, and performance-based items take several minutes, so the practical arithmetic is worse than it looks.

The second is the launch date. SecAI+ went live on 17 February 2026, which means the beta period is over. Searches for a SecAI beta exam still circulate; there is nothing to wait for. CompTIA estimates retirement roughly three years after launch, so the credential has a normal useful life ahead of it rather than a short one.

Domain 1: how much AI theory do you need?

Enough to hold a precise conversation, and no more. Seventeen percent covers the vocabulary: the types of AI, how models are trained, how prompts are constructed, and how data is prepared. It is a grounding domain rather than a mathematical one, and nothing in it requires you to build a model.

Three groups make up the bulk of it. The first is model types, which spans generative AI, machine learning, statistical learning, transformers, deep learning, generative adversarial networks, natural language processing, and both large and small language models. The distinction between a large and a small language model matters more than it first appears, because it drives where a model runs and therefore what you can control about it.

The second is training technique: supervised, unsupervised, reinforcement and federated learning, plus model validation, fine-tuning, epochs, pruning and quantization. The third is prompt engineering, covering system and user prompts, zero-shot, one-shot and multi-shot prompting, system roles and templates. Prompt structure returns in domain 2 as a control, so learning it properly here pays twice.

Data security closes the domain: cleansing, verification, lineage, integrity, provenance, augmentation and balancing. Data lineage and provenance are the two to know cold, because both reappear in the governance domain as audit and compliance obligations.

Domain 2: what does securing an AI system involve?

Threat modelling it, wrapping it in guardrails, and controlling access to the model and its data. At 40 percent this is the largest block on the exam by a wide margin, and it is built on named public frameworks rather than on abstractions, which makes it unusually studiable from primary sources.

The gateway controls SecAI+ expects in front of an AI model: prompt firewall, rate limits, token limits and modality limits

Threat modelling with named frameworks

The syllabus names six: the OWASP Top 10, the OWASP LLM Top 10, the OWASP Machine Learning Security Top 10, the MIT AI Risk Repository, MITRE ATLAS, and the CVE AI Working Group. Knowing which one applies to a described scenario is the examinable skill. ATLAS catalogues adversary tactics against AI systems; the OWASP lists enumerate the vulnerability classes.

Model and gateway controls

This is the material with no equivalent anywhere on Security+ or CySA+, and it is where preparation time should concentrate. Model controls cover model evaluation, guardrails and prompt templates. Gateway controls sit in front of the model and are the newer idea:

  • Prompt firewalls, which inspect what is sent to a model rather than what is sent to a network
  • Rate limits and token limits, which cap how much a caller can consume
  • Input quotas covering data size and quantity
  • Modality limits, restricting whether a caller may send images or audio as well as text
  • Endpoint access controls on the interface itself

Guardrail testing and validation is examinable separately from building guardrails, and the distinction is deliberate. A guardrail nobody has tried to defeat is an assumption, not a control, so expect scenarios that ask how you would prove one works.

Access control

The domain closes on access to the model and access to the data behind it, treated as two separate problems. That separation is the point. Someone may legitimately query a model while having no business reaching the training data, and the exam expects you to control each independently.

Domain 3: where does AI help the defender?

In tooling and automation, and it helps the attacker in the same breath. Twenty-four percent splits three ways: using AI-enabled tools for security tasks, understanding how AI enables or enhances attack vectors, and automating security work. Most experienced defenders will find this the familiar half of the paper.

The tooling list covers plug-ins for development environments, browsers and the command line, plus chatbots, personal assistants and Model Context Protocol servers. The use cases run from signature matching, code quality and linting, and vulnerability analysis through to automated penetration testing, anomaly detection, pattern recognition, incident management, threat modelling, fraud detection, translation and summarisation.

The offensive half deserves equal study and usually gets less. It covers AI-generated content and deepfakes used for impersonation, misinformation and disinformation, adversarial networks, reconnaissance, social engineering, obfuscation, and automated data correlation for generating attacks, discovering attack vectors, and producing payloads, malware, honeypots and distributed denial of service traffic.

Automation closes the domain: low-code and no-code scripting, document synthesis and summarisation, incident response ticket management, change management with AI-assisted approvals and automated deployment or rollback, AI agents, and a continuous integration pipeline covering code scanning, software composition analysis, and unit, regression and model testing. Model testing inside a pipeline is the item most likely to catch out someone who prepared only on traditional application security.

Domain 4: what does the governance domain expect?

That you can describe how an organisation governs AI, name the risks that come with it, and identify which regulation applies. Nineteen percent, and it is more concrete than governance domains usually are, because the syllabus names actual instruments rather than talking about policy in general terms.

Structures come first: an AI Center of Excellence, and the policies and procedures around it. Then roles, and the list is long enough to be examinable in its own right, spanning data scientist, AI architect, machine learning engineer, platform engineer, MLOps engineer, AI security architect, AI governance engineer, AI risk analyst, AI auditor and data engineer. Learn which ones own risk decisions rather than trying to memorise every description.

Responsible AI covers fairness, reliability and safety, transparency, privacy and security, differential privacy, explainability, inclusiveness, accountability, consistency and awareness training. The risk list is more practical: introduced bias, accidental data leakage, reputational loss, model accuracy and performance, intellectual property exposure, autonomous systems, and shadow AI, which is shadow IT for people quietly using unsanctioned models.

Compliance names four external instruments: the EU AI Act, OECD standards, ISO AI standards and the NIST AI Risk Management Framework. Alongside them sit corporate policy questions: sanctioned against unsanctioned use, private against public models, sensitive data governance, third-party compliance evaluations and data sovereignty. You are not expected to recite the EU AI Act, but you are expected to know what each instrument is for.

Who should take this exam?

Working security practitioners whose organisations have started running AI in production. CompTIA recommends three to four years in IT and at least two years of hands-on cybersecurity, with Security+, CySA+ or PenTest+ already held or equivalent experience in place. This is not an entry point into the field.

The experience CompTIA recommends before sitting SecAI+: three to four years in IT, two or more years hands-on security, and a core credential such as CySA+ or PenTest+

It fits most cleanly where someone already owns defensive work and has been handed AI systems to protect: security analysts whose estate now includes model endpoints, security architects designing controls around them, and engineers asked to put a gateway in front of a model that is already live. The governance domain also makes it genuinely useful to risk and compliance staff who need the vocabulary rather than the implementation.

It fits less well if your interest is using AI tools to work faster. That is domain 3, it is a quarter of the exam, and a shorter course would serve you better. It is also a poor first certification, for the reason CompTIA states: the paper assumes the security fundamentals rather than teaching them, and the CySA+ analyst credential is one of the routes it expects you to have taken first.

One honest caveat about newness. The exam launched in February 2026, so there is little community material, few study guides and no long track record of employer recognition. That is the trade for being early, and it cuts both ways.

How should you prepare?

Spend your time in proportion to the weightings, and study domain 2 from the primary sources it names rather than from summaries of them. Forty percent of the paper sits in one domain built on public frameworks that are free to read, which is an unusually direct route from syllabus to preparation.

  1. Read the four domain weightings and plan your hours against them, because 40 percent in one domain is not a hint you can ignore.
  2. Work through the OWASP LLM Top 10 and the OWASP Machine Learning Security Top 10 directly, since the syllabus names both by title.
  3. Read MITRE ATLAS as a tactics catalogue and practise mapping a described attack onto it.
  4. Learn the gateway controls as a set, prompt firewalls, rate and token limits, input quotas and modality limits, because none of them appear on the exams you have already passed.
  5. Build or borrow one model endpoint and put a control in front of it, so guardrail testing is something you have done rather than read about.
  6. Skim the NIST AI Risk Management Framework and note what the EU AI Act, OECD and ISO standards each cover, at the level of purpose rather than clause.
  7. Practise performance-based items under time, since up to 60 questions in 60 minutes leaves no room to think slowly.

If your background is AI rather than security, invert that plan. Domain 1 will already be familiar and domains 2 and 4 will not, and the security reasoning behind a control is what the questions actually test. A related view of how CompTIA frames AI content appears in the DataAI exam material, which approaches the same technology from the data side.

Frequently Asked Questions

How many questions are on the CY0-001 exam?

A maximum of 60, mixing multiple choice and performance-based items, in 60 minutes.

What is the passing score for SecAI+?

Six hundred on a scale of 100 to 900. It is a scaled score, not a percentage.

How much does SecAI+ cost?

Two hundred and ninety eight US dollars. CompTIA does not publish a price on its own exam page, so confirm the current figure when you book through Pearson VUE.

Is SecAI+ about using AI or about securing AI?

Mostly securing it. The securing AI systems domain is 40 percent of the exam, while the AI-assisted security domain, which covers using AI for defensive work, is 24 percent.

Is the exam still in beta?

No. SecAI+ launched on 17 February 2026, so the beta period is over and the live exam is available.

What experience does CompTIA recommend?

Three to four years in IT and at least two years of hands-on cybersecurity, with Security+, CySA+ or PenTest+ recommended beforehand.

What are the four domains and their weightings?

Basic AI concepts related to cybersecurity at 17 percent, securing AI systems at 40 percent, AI-assisted security at 24 percent, and AI governance, risk and compliance at 19 percent.

What languages is the exam available in?

English and Japanese.

When will SecAI+ retire?

CompTIA estimates retirement about three years after launch, which places it around early 2029, though that is an estimate rather than a fixed date.

Do I need to know how to build machine learning models?

No. Domain 1 covers model types, training techniques and prompt engineering as vocabulary and mechanics, not as a development skill.

Conclusion

SecAI+ is a defending-AI credential wearing a name that suggests otherwise. Up to 60 questions in 60 minutes, 600 to pass on a 100 to 900 scale, 298 USD, and four domains in which securing AI systems alone takes 40 percent.

Plan against that number. The gateway controls, guardrail validation and model access material in domain 2 have no equivalent on the security exams you have already passed, while most of domain 3 will be recognisable from work you already do. Study the named frameworks directly, because the syllabus points at them by title and they are free to read.

Check the current price when you book, since CompTIA publishes none on its exam page, and go in expecting performance-based items rather than a pure multiple choice paper. Then work the domains in proportion to their weight, which is the clearest instruction this syllabus gives.

Rating: 0 / 5 (0 votes)

The post CompTIA SecAI+ Certification: Forty Percent Is One Domain appeared first on iSecPrep.

]]>
Oracle Linux 8 System Administrator Certification: 1Z0-106 https://www.isecprep.com/2026/09/26/oracle-linux-8-system-administrator-certification-1z0-106/ Sat, 26 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88345 Every enterprise Linux certification covers boot, storage and SELinux. Only one expects you to patch a running kernel without rebooting, because the vendor behind it sells the technology that does it.

The post Oracle Linux 8 System Administrator Certification: 1Z0-106 appeared first on iSecPrep.

]]>

Every enterprise Linux certification covers the same ground: boot, packages, storage, networking, SELinux, logging. One of them also expects you to patch a running kernel without rebooting the machine, because the vendor behind it sells the technology that does it. That single topic is the clearest signal that this exam is not interchangeable with the others.

The Oracle Linux 8 system administrator certification is earned by passing 1Z0-106, a 90 minute multiple choice paper of 60 questions at a 60 percent pass mark, priced at 245 USD. Twenty one topic areas run from the boot process to the Linux auditing system, and Oracle publishes no weighting for any of them.

Table of Contents

  1. What makes this exam different from other Linux credentials?
  2. What are the 1Z0-106 exam facts?
  3. How do you plan for a syllabus with no weightings?
  4. What do the core administration topics cover?
  5. Why does Ksplice have its own topic area?
  6. How much security does the syllabus expect?
  7. Control groups and container services
  8. Who should take this exam?
  9. How should you prepare?
  10. Frequently Asked Questions
  11. Conclusion

What makes this exam different from other Linux credentials?

Two things: the syllabus includes Oracle Ksplice, which no other vendor’s Linux exam covers, and the format is multiple choice rather than performance based. Everything else on the topic list would be recognisable to anyone who has prepared for a general enterprise Linux credential.

That combination produces a specific kind of paper. A performance based exam proves you can complete tasks under time pressure on a live system. A multiple choice exam at this level proves something narrower and still useful: that you know which mechanism applies, what a configuration does, and where the system keeps the answer when something breaks.

The distinction matters when you are choosing between credentials rather than collecting them. If your estate runs Oracle Linux, this exam covers the distribution you actually administer, including the parts Oracle adds on top of the common base. If it does not, a vendor neutral credential will serve you better, and the performance based Red Hat route is the obvious comparison at a similar level.

What are the 1Z0-106 exam facts?

1Z0-106 runs 90 minutes with 60 multiple choice questions and a 60 percent pass mark, which is 36 correct answers. It costs 245 USD, though Oracle prices vary by country, and passing grants the Oracle Certified Professional, Oracle Linux 8 System Administrator credential.

Field Value
Exam Oracle Linux 8 Advanced System Administration
Code 1Z0-106
Questions 60
Duration 90 minutes
Passing score 60 percent, so 36 of 60
Format Multiple choice
Price 245 USD, varies by country
Credential earned Oracle Certified Professional, Oracle Linux 8 System Administrator
Topic areas 21, with no published weightings

A word on where those figures come from. Oracle’s certification portal returns an error to anything but a browser, and its learning site serves an application shell with no readable specification inside it, so none of this can be checked against the vendor the way a CompTIA or Cisco figure can. These are the exam catalogue’s numbers, they are internally consistent, and you should confirm the price at registration since Oracle localises it.

For the same reason this guide states no validity period and no retake rule: Oracle publishes neither where it can be read. Ninety seconds per question is comfortable, so the practical constraint is breadth rather than speed, and a 1Z0-106 practice test is the quickest way to find which of the 21 areas you have never touched.

How do you plan for a syllabus with no weightings?

You plan by objective count and by how much of the working day each area occupies, because Oracle publishes no percentages for this exam. Twenty one areas across 60 questions averages under three questions each, which tells you immediately that depth in one favourite area cannot carry the paper.

That average is the most useful planning number available. It means no single area can be worth revising exhaustively, and it means an area you skip entirely costs you roughly three questions, or five percent of the mark, which is most of the margin between 60 percent and a fail.

The sensible approach is coverage first, depth second. Work the whole list once, mark every area where you could not explain the mechanism to a colleague, and spend your remaining time only on those. Candidates who fail this paper usually do so by knowing six areas extremely well and four not at all.

What do the core administration topics cover?

The first half of the syllabus is conventional enterprise Linux administration: the boot process and GRUB 2, kernel boot parameters, systemd, system configuration through /etc/sysconfig, the /proc and /sys filesystems, sysctl, time synchronisation with chrony, NTP and PTP, package management, task automation, users and groups, filesystems and swap, storage devices, networking and OpenSSH.

Two details in that list are worth pausing on, because they are where multiple choice questions tend to live. The first is the difference between a runtime kernel parameter set through sysctl and a boot parameter set in GRUB, which is a distinction the exam can test cleanly without a lab. The second is time: chrony, NTP and PTP are named separately, and the exam expects you to know which one a situation calls for rather than merely that time synchronisation exists.

The behaviour of systemd runs underneath much of this material. Units, targets, dependencies and the journal appear across the boot, service, logging and troubleshooting areas, so a candidate fluent in systemd picks up marks in four separate topic areas rather than one. The kernel side of the same material is documented at the kernel project, which is worth reading once for boot parameters if that ground is unfamiliar.

Why does Ksplice have its own topic area?

Because it solves a problem every other distribution answers with a reboot. Ksplice applies kernel and userspace patches to a running system, so a security fix can be applied without a maintenance window, and it is Oracle technology rather than part of the common Linux base.

What Ksplice changes for Oracle Linux 8 administrators: patch then reboot becomes patch it live

That is why it earns a topic area of its own on this syllabus and appears on no competing vendor’s Linux exam. If you administer Oracle Linux in an environment with uptime commitments, it is also the feature most likely to justify the certification to a manager, because the operational saving is concrete.

For the exam, the examinable ground is what Ksplice does, when it applies, how it is managed, and what its limits are. The vendor documents the service on the Ksplice site, and it is one of the few areas where a candidate cannot fall back on general Linux experience, because there is no general equivalent to fall back on.

How much security does the syllabus expect?

Three of the 21 areas are security mechanisms that administrators commonly work around rather than with: Security Enhanced Linux, pluggable authentication modules, and the Linux auditing system. Each gets its own heading, which is a fair signal of how the exam treats them.

SELinux is the one candidates most often under-prepare, because in practice many estates run it permissive and move on. The exam is not interested in that pragmatism. It expects the modes, contexts, booleans and the relationship between a denial and a policy, which is knowledge you can only fake for about two questions. The project’s own material at the SELinux project repository is the authoritative reference.

PAM rewards a different habit. It is a stack, and almost every PAM question is really about order and control flags, so drawing one real stack out and tracing a login through it converts the whole area from memorisation into something you can reason about. The audit system rounds the group off: what it records, where it writes, and how to ask it a question after the fact.

Control groups and container services

Control groups and container services appear as two separate areas late in the syllabus, and together they are the part of the list that dates the exam most clearly to a modern estate. Cgroups govern how resources are allocated and capped; container services cover running containers on the host rather than orchestrating them across a cluster.

Keep the scope in mind while revising. This is host level container administration, not orchestration: nothing here is asking about clusters, schedulers or service meshes. The examinable material is what the host provides, how a container consumes it, and how cgroups bound that consumption.

Advanced storage administration and file sharing sit alongside them and follow the same pattern. The topics are broad, the depth is moderate, and the questions reward someone who has configured the thing once rather than someone who has read about it twice.

Who should take this exam?

It suits administrators running Oracle Linux in production, engineers supporting Oracle Database or Exadata estates where the operating system is part of the stack they own, and sysadmins whose employer is an Oracle shop and wants a credential that matches. Oracle publishes no prerequisite, though the word advanced in the title is accurate.

It is a weak fit for two groups. Anyone whose estate is Red Hat, Ubuntu or SUSE gains little from a distribution specific paper, especially one covering a feature they do not run. And anyone who wants to prove practical ability under exam conditions will find a multiple choice format less persuasive to a technical interviewer than a performance based one.

There is one more group worth naming: candidates who already hold an Oracle credential on the database side and want the operating system underneath it. That is a coherent pairing, and the Oracle Database SQL route covers the other half of the same estate.

How should you prepare?

Cover all 21 areas before deepening any of them, get hands on an Oracle Linux 8 system, and treat Ksplice and SELinux as the two areas where general Linux experience will not carry you. With roughly three questions per area, the exam punishes gaps far more than it rewards specialism.

Four preparation moves for 1Z0-106: rate all 21 areas, build a VM, drill Ksplice and trace one SELinux denial
  1. List the 21 topic areas and rate your confidence in each one honestly. The list itself is the study plan.
  2. Build an Oracle Linux 8 virtual machine and work through the areas you rated lowest, in order.
  3. Spend a dedicated session on Ksplice, which is the one area with no equivalent elsewhere.
  4. Trace one real PAM stack and one real SELinux denial end to end, rather than reading about either.
  5. Practise distinguishing the mechanisms that look alike: sysctl against boot parameters, chrony against NTP and PTP, cgroups against container limits.
  6. Sit a full timed set and use the result to find the areas you skipped rather than to confirm the ones you enjoy.

An earlier walkthrough of this same paper is still useful on tactics rather than content, and that 1Z0-106 preparation guide predates the current catalogue figures, so read it for method and take the numbers from here.

One practical note on the format: because the paper is multiple choice, elimination is a legitimate technique in a way it never is on a performance based exam. Knowing that two of four answers are impossible is worth a mark, and at a 60 percent threshold those marks decide results.

Frequently Asked Questions

How many questions are on the 1Z0-106 exam?

Sixty multiple choice questions in 90 minutes, which is about 90 seconds each.

What is the passing score for 1Z0-106?

Sixty percent, which works out at 36 correct answers from 60.

How much does the exam cost?

Two hundred and forty five US dollars, and Oracle varies pricing by country, so confirm the local figure when you book.

What credential does passing it earn?

Oracle Certified Professional, Oracle Linux 8 System Administrator.

Are the topic areas weighted?

No. Oracle publishes no weightings for this exam, so plan by objective rather than by percentage. Twenty one areas across 60 questions averages just under three questions each.

Is the exam hands on?

No. It is multiple choice, which is the main format difference between this credential and the performance based Red Hat route at a similar level.

What is Ksplice and why is it on the syllabus?

Ksplice applies kernel patches to a running system without a reboot. It is Oracle technology, it has its own topic area, and no competing vendor’s Linux exam covers it.

Are there prerequisites?

None are published, although the syllabus assumes real administration experience rather than first exposure to Linux.

How long is the certification valid?

Oracle does not publish a validity period where it can be read, so this guide does not state one. Check your certification record after passing.

Does it cover Oracle Linux 9?

No. The release is named in the exam title, and this paper covers Oracle Linux 8.

Conclusion

1Z0-106 is a breadth exam for people who run Oracle Linux specifically. Sixty multiple choice questions, 90 minutes, 60 percent to pass, 245 USD, and 21 topic areas that Oracle declines to weight.

Plan for coverage rather than depth, because under three questions per area means a skipped topic costs about as much as the margin you have to spare. Give Ksplice and SELinux their own sessions, since neither yields to general Linux experience, and build the virtual machine rather than reading about the commands.

Treat the published figures as the catalogue’s rather than the vendor’s, because Oracle’s own pages cannot be read from outside a browser, and confirm the price when you book. Then work the topic list in order of your own weakness, which is the only prioritisation this syllabus offers.

Rating: 0 / 5 (0 votes)

The post Oracle Linux 8 System Administrator Certification: 1Z0-106 appeared first on iSecPrep.

]]>
HCIA-AI Certification: Inside Huawei’s H13-311 Exam https://www.isecprep.com/2026/09/25/hcia-ai-certification-inside-huaweis-h13-311-exam/ Fri, 25 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88288 Most entry level AI certifications still teach the subject as it looked in 2019. This one names DeepSeek in its first domain and puts nearly a third of the paper on foundation models.

The post HCIA-AI Certification: Inside Huawei’s H13-311 Exam appeared first on iSecPrep.

]]>

Most entry-level AI certifications still teach the subject as it looked in 2019: regression, classification, a neural network diagram and a closing slide about ethics. Huawei’s associate paper names DeepSeek in its first domain and gives its largest block of marks to foundation models. That is not where an associate syllabus usually goes.

The HCIA-AI certification, exam code H13-311, is 60 questions in 90 minutes with a 600 out of 1000 pass mark and a 200 USD fee, scheduled through Pearson VUE. Six domains run from an AI overview to cutting-edge applications, and deep learning with foundation models carries 30 percent of them.

Table of Contents

  1. What does the HCIA-AI credential cover?
  2. What are the H13-311 exam facts?
  3. What does the V4.0 syllabus signal?
  4. How are the six domains weighted?
  5. Inside the 30 percent domain
  6. What does the development framework domain expect?
  7. HCIA-AI or HCIA-AI Solution?
  8. Who should take this exam?
  9. How should you prepare?
  10. Frequently Asked Questions
  11. Conclusion

What does the HCIA-AI credential cover?

HCIA-AI is the associate tier of Huawei’s artificial intelligence track, and it certifies conceptual breadth rather than engineering depth. The syllabus moves from what AI is and where it is used, through machine learning and deep learning, into the frameworks used to build models, the business process around an AI project, and the applications at the edge of the field.

The emphasis is unusual for an entry-level paper. Rather than spending most of its weight on classical algorithms, it puts 30 percent on deep learning and foundation models and another 20 percent on development frameworks, which means half the exam is about how modern models are built and trained rather than about statistics.

What it does not do is make you an AI engineer, and it does not pretend to. Associate credentials across every vendor certify that you can hold a technically literate conversation and follow an implementation, and this one is honest about sitting at that level while choosing unusually current material to do it with.

What are the H13-311 exam facts?

H13-311 is 60 questions in 90 minutes, scored out of 1000 with 600 required to pass, at a fee of 200 USD and scheduled through Pearson VUE. That works out at 90 seconds per question, and the scaled scoring means the raw number of correct answers needed is not published.

Field Value
Credential Huawei Certified ICT Associate, AI
Exam code H13-311
Questions 60
Duration 90 minutes
Passing score 600 out of 1000
Fee 200 USD
Scheduling Pearson VUE
Training version HCIA-AI V4.0

A word about where those numbers come from, because it matters. Huawei’s certification portal is a JavaScript application that serves no readable specification to anything but a browser, so none of these figures can be confirmed against the vendor in the way a Cisco or CompTIA figure can. They are the exam catalogue’s, they are internally consistent with the published syllabus, and you should confirm the fee and the booking terms at registration.

For the same reason, this guide states no validity period, no prerequisite and no retake rule: Huawei publishes none that can be read, and a figure nobody publishes is not one worth repeating. The most reliable readiness check is the paper itself, and an H13-311 practice test will tell you more about your gaps than any specification table.

What does the V4.0 syllabus signal?

The current blueprint is keyed to HCIA-AI V4.0 training material, and its content dates it precisely. The AI Overview domain includes an overview of DeepSeek and its influence on AI development, and the largest domain is titled Basics of Deep Learning and Foundation Models rather than simply deep learning.

Both choices tell you the syllabus was rewritten after large language models became the centre of the field rather than a specialism within it. An associate paper that names a specific recent model is taking a deliberate risk: model names age badly, and Huawei has accepted that in exchange for currency.

The practical consequence is about study material rather than about theory. Older HCIA-AI guides, and there are many, describe a version where deep learning was one domain among several and foundation models were not mentioned. They will teach you most of the machine learning content correctly and leave you short exactly where the weighting is heaviest.

How to tell which version you are reading

Check whether the material mentions foundation models at all. If the deep learning section stops at convolutional and recurrent networks and never reaches transformers or pretraining, it predates this blueprint. The transformer architecture those models are built on was set out in the 2017 attention paper, and any current AI syllabus has to reach it.

How are the six domains weighted?

The six domains are AI Overview at 10 percent, Machine Learning Overview at 20 percent, Basics of Deep Learning and Foundation Models at 30 percent, AI Development Framework at 20 percent, AI Business Process Overview at 15 percent and Cutting-edge AI applications at 5 percent. One domain carries nearly a third of the paper and one carries a twentieth.

Domain Weight Roughly how many of 60 questions
AI Overview 10% 6
Machine Learning Overview 20% 12
Basics of Deep Learning and Foundation Models 30% 18
AI Development Framework 20% 12
AI Business Process Overview 15% 9
Cutting-edge AI applications 5% 3

Read the bottom row before the top one. Cutting-edge AI applications is worth about three questions, which is the clearest signal in the whole blueprint that the exam is not testing novelty for its own sake. The marks are in the middle: models, frameworks and the process of getting a model into a business.

Inside the 30 percent domain

Basics of Deep Learning and Foundation Models is the domain to organise your preparation around. It starts from the perceptron and works up through network architectures to the pretrained models that dominate current practice, which means it asks you to understand both the mechanics underneath and the vocabulary on top.

The four things done to a model in the HCIA-AI foundation models domain: pretrain, tune, prompt and infer

The conceptual chain is what carries the marks. A perceptron makes one linear decision; layers of them make a network that can represent non-linear relationships; training adjusts weights by propagating error backwards; and a foundation model is that idea scaled up and pretrained on enough data that it can be adapted to tasks it was never specifically trained for. Candidates who can trace that chain answer most of this domain correctly.

Where people lose marks is the vocabulary of adaptation rather than the architecture itself. Pretraining, fine-tuning, prompting and inference describe different activities at different costs, and an exam question that asks which one fits a described situation is really asking whether you know what each stage does to a model.

What does the development framework domain expect?

AI Development Framework is 20 percent of the paper and covers how models are actually built in code: computational graphs, tensors, the training loop and the libraries that provide them. Huawei’s own MindSpore framework features here, as you would expect from a vendor exam, alongside the general concepts that transfer to any framework.

The good news for anyone arriving from another ecosystem is that the concepts move across intact. A tensor is a tensor, automatic differentiation works the same way, and a training loop looks familiar whether it is written against the PyTorch project or against Huawei’s MindSpore. What you need is the ability to recognise the same idea under a different name.

AI Business Process Overview, at 15 percent, is the domain that surprises engineers. It covers how an AI project runs, from problem definition and data collection through model deployment and monitoring, and its questions are about sequence and responsibility rather than about code. It is also the easiest domain to gain marks in quickly, because the material is short and rarely revised.

HCIA-AI or HCIA-AI Solution?

Huawei runs two associate AI credentials, and they are not tiers of each other. HCIA-AI is H13-311 and HCIA-AI Solution is H13-313. Both are 60 questions in 90 minutes, both score 600 out of 1000, and both cost 200 USD, so the choice is entirely about content rather than about difficulty or commitment.

Huawei H13-311 HCIA-AI compared with H13-313 HCIA-AI Solution, same exam format and different blueprints

The split is roughly technology against application. H13-311 spends its weight on the models and the frameworks; H13-313 is keyed to its own separate training material and distributes its marks differently across a solution-focused blueprint. If your work is understanding how models are built, take the first. If it is positioning and delivering AI solutions, read the second blueprint before choosing.

Huawei’s wider scheme follows the same associate, professional and expert ladder used across its tracks, and the expert-level big data credential shows how much deeper the demands become higher up, which is useful context when deciding whether the associate tier is a destination or a starting point.

Who should take this exam?

HCIA-AI suits ICT professionals adding AI literacy, students and career changers who want a structured syllabus rather than a course list, pre-sales and solution staff who must discuss AI credibly, and engineers inside Huawei-aligned organisations where the certification carries internal weight. No prerequisite is published.

It is a weak fit for two groups. Practising machine learning engineers will find the depth well below their working level, and would be better served by a professional-tier paper. Anyone who needs a credential recognised primarily in North American hiring will find Huawei’s scheme carries more weight in other markets, which is a positioning question rather than a quality one.

If your interest is infrastructure rather than models, the same vendor’s other associate tracks may fit better, and the Huawei storage certification route covers a track where the day-to-day work looks nothing like an AI syllabus.

How should you prepare?

Study from V4.0 material, weight your time toward deep learning and frameworks, and treat the business process domain as free marks. Ninety minutes for 60 questions is comfortable, so the constraint is coverage rather than speed, and the commonest failure is a candidate strong on classical machine learning who never reached foundation models.

  1. Confirm your study material is V4.0 by checking whether it covers foundation models at all.
  2. Give the deep learning domain the largest share of your time, since it alone is 18 of the 60 questions.
  3. Learn the adaptation vocabulary deliberately: pretraining, fine-tuning, prompting and inference.
  4. Build one small model end to end in any framework, so the tensor and training-loop questions describe something you have actually done.
  5. Read the business process domain once and revise it twice. It is 15 percent of the paper for very little study effort.
  6. Sit a full timed set before booking, and use it to find which of the six domains you have skipped rather than to confirm the one you enjoy.

Do not over-invest in the cutting-edge applications domain. At 5 percent it is worth about three questions, and the material moves faster than any exam can track, so a general awareness of current applications is enough.

Frequently Asked Questions

How many questions are on the H13-311 exam?

Sixty questions in 90 minutes, which allows 90 seconds each.

What is the passing score for HCIA-AI?

Six hundred out of 1000. The scoring is scaled, so the number of correct answers that represents is not published.

How much does the HCIA-AI certification cost?

Two hundred US dollars, scheduled through Pearson VUE. Confirm the current fee at registration, since Huawei does not publish it in a form that can be checked independently.

Which version of the syllabus is current?

The blueprint is keyed to HCIA-AI V4.0 training material, and it includes foundation models and an overview of DeepSeek. Material that does not mention foundation models predates it.

Are there prerequisites for HCIA-AI?

None are published. It is an associate-tier credential and is designed as an entry point.

Which domain carries the most marks?

Basics of Deep Learning and Foundation Models at 30 percent, roughly 18 of the 60 questions.

What is the difference between HCIA-AI and HCIA-AI Solution?

They are separate exams, H13-311 and H13-313, with the same format and price but different blueprints. The first concentrates on models and frameworks, the second on solution delivery.

Does the exam require programming?

Not directly. The framework domain expects you to recognise tensors, computational graphs and training loops rather than to write code under exam conditions.

How long is the certification valid?

Huawei does not publish a validity period where it can be read, so this guide does not state one. Check your certification record after passing.

Is MindSpore knowledge essential?

It appears in the framework domain as the vendor’s own framework, but the concepts tested transfer across frameworks, so experience in another library is useful preparation rather than a handicap.

Conclusion

HCIA-AI is a current associate credential wearing a conventional name. Sixty questions, 90 minutes, 600 out of 1000 to pass, 200 USD, and a blueprint that puts nearly a third of its marks on deep learning and foundation models rather than on classical algorithms.

The version question decides most outcomes. Study V4.0 material, confirm it reaches foundation models, and give that domain the time its weighting deserves. The business process domain is the cheapest 15 percent on the paper, and cutting-edge applications is worth three questions and no more.

Treat the published figures as the catalogue’s rather than the vendor’s, because Huawei’s portal cannot be read from outside a browser, and confirm the fee and terms when you book. Then build one small model end to end, so the framework questions describe something your hands have already done.

Rating: 0 / 5 (0 votes)

The post HCIA-AI Certification: Inside Huawei’s H13-311 Exam appeared first on iSecPrep.

]]>
Wireless IoT Solutions Administrator Certification Exam https://www.isecprep.com/2026/09/25/wireless-iot-solutions-administrator-certification-exam/ Fri, 25 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88280 The most searched CWISA code is one nobody can sit any more. CWISA-102 closed on 31 December 2025, yet it still pulls more traffic than the exam that replaced it, so much of the material people find describes a syllabus that no longer exists.

The post Wireless IoT Solutions Administrator Certification Exam appeared first on iSecPrep.

]]>

The most searched CWISA exam code is one nobody can sit any more. CWNP stopped offering CWISA-102 on 31 December 2025, yet it still pulls more search traffic every quarter than the exam that replaced it, which means a large share of the study material people find was written against a syllabus that no longer exists.

The current paper is CWISA-103, released in November 2025. The wireless IoT solutions administrator certification it awards is 60 questions in 90 minutes, scored at 70 percent, delivered through Prometric for 275 USD, and built around five domains in which planning, implementing and supporting a deployment carry 70 percent of the marks between them.

Table of Contents

  1. What does a wireless IoT solutions administrator actually administer?
  2. What are the CWISA-103 exam facts?
  3. Where do the marks really sit across the five domains?
  4. Why is so much CWISA material out of date?
  5. Which wireless protocols does the exam expect you to tell apart?
  6. Planning and implementing decide the result
  7. Where does CWISA sit in the CWNP scheme?
  8. Who should take this exam, and who should not?
  9. How do you prepare for 60 questions in 90 minutes?
  10. Frequently Asked Questions
  11. Conclusion

What does a wireless IoT solutions administrator actually administer?

CWISA-103 certifies that you can plan, install, support and troubleshoot wireless systems that mostly are not Wi-Fi. The syllabus covers Bluetooth and BLE, Zigbee, 802.15.4, LoRaWAN, Sigfox, cellular and location services alongside 802.11, and treats each as one option among several rather than as the default answer.

That scope is unusual, and it is the reason the credential exists. CWNP spent two decades certifying WLAN skills, where the question was almost always which 802.11 feature to use. In a building full of sensors, actuators, asset tags and gateways, the question changes: a battery-powered soil sensor reporting once an hour and a ceiling access point serving laptops are not solved by the same radio, and choosing wrongly is expensive to undo.

So the exam is a breadth paper with an operational bias. It asks what each technology is for, what the standards bodies behind them specify, how to gather requirements before choosing one, how to install and validate the result safely, and how to find the fault when a deployment misbehaves in a hospital, a factory or a farm.

What are the CWISA-103 exam facts?

CWISA-103 runs 90 minutes and contains 60 questions, with a passing score of 70 percent and a fee of 275 USD. It is delivered through Prometric and carries no published prerequisite, so anyone may register. At 90 seconds per question on average, it is a paper that rewards recognition over deliberation.

Field Value
Credential CWNP Wireless IoT Solutions Administrator
Exam code CWISA-103
Questions 60
Duration 90 minutes
Passing score 70 percent
Fee 275 USD
Delivery Prometric
Current version CWISA-103, released November 2025
Next scheduled update CWISA-104, 2028

One figure is deliberately absent from that table. CWNP does not publish a validity period for CWISA on its credential page, and no other source states one clearly, so this guide does not invent a number. Check your certification record after you pass rather than relying on a figure quoted second hand.

Where do the marks really sit across the five domains?

The five CWISA-103 domains are Wireless Technologies at 15 percent, Radio Frequency Communications at 15 percent, Planning Wireless Solutions at 20 percent, Implementing Wireless Solutions at 25 percent and Supporting Wireless Solutions at 25 percent. Implementing and Supporting together carry half the paper, which tells you plainly what the exam is about.

Domain Weight Roughly how many of 60 questions
Wireless Technologies 15% 9
Radio Frequency Communications 15% 9
Planning Wireless Solutions 20% 12
Implementing Wireless Solutions 25% 15
Supporting Wireless Solutions 25% 15

Read the split as a warning about study habits. Candidates from a Wi-Fi background tend to over-prepare the RF domain, because it is familiar and the material is plentiful, and under-prepare the two deployment domains, where the questions are about staging, documentation, handover and fault isolation. Those two domains are worth 30 questions. RF is worth nine.

Working through items in the exam’s own format is the quickest way to find out which side of that line you are on, and a CWISA-103 practice test will expose a Planning or Supporting weakness long before the real paper does.

Why is so much CWISA material out of date?

Because the previous version only died recently and the internet has not caught up. CWNP set 31 December 2025 as the last day to sit CWISA-102, and published CWISA-103 in November 2025. Search demand still runs higher on the retired code than on the live one, so a candidate searching casually will find guides, question sets and blog posts describing an exam that cannot be booked.

The practical risk is not that the old material is wildly wrong. The two versions share a great deal, because the underlying technologies did not change overnight. The risk is at the edges: objectives that were added, terminology that moved, and emphasis that shifted toward edge compute, APIs and programmability. Those edges are exactly where a 70 percent pass mark is won or lost.

Two checks protect you. First, confirm the code on anything you study, and treat a page that never names a code as unverified. Second, read the vendor’s own objective list rather than a summary of it. CWNP publishes the current objectives as a PDF from its official CWISA page, and the 2025 objectives document is the definitive statement of what is examinable.

The good news about timing

CWNP states that the next scheduled update, CWISA-104, is not due until 2028. For a candidate that is an unusually long runway: study material bought now stays current for years, and there is no reason to rush a booking in case the syllabus shifts underneath you.

Which wireless protocols does the exam expect you to tell apart?

CWISA-103 expects working familiarity with traditional 802.11 WLANs, Wi-Fi HaLow, Bluetooth and BLE, Zigbee and other 802.15.4 protocols, LoRaWAN, Sigfox, cellular connectivity and location services such as RTLS, beaconing and geofencing. You are not asked to configure each one, but you are asked to choose correctly between them.

Four wireless IoT radio choices compared for CWISA-103: Wi-Fi for high speed, BLE for short hops, Zigbee for mesh and LoRa for long range

The distinctions that carry marks are practical ones: range against battery life, throughput against device density, licensed spectrum against unlicensed, and mesh against star topology. A question rarely asks what LoRaWAN is. It describes a site, a duty cycle and a power budget, and asks which technology fits.

Behind those choices sit the organisations the syllabus names explicitly, and the exam expects you to know which body governs what. The IEEE 802.11 working group writes the wireless LAN standards, including the 802.11ah amendment marketed as Wi-Fi HaLow, while the LoRa Alliance maintains the LoRaWAN specification. The Wi-Fi Alliance certifies interoperability rather than writing standards, the Bluetooth SIG and the Connectivity Standards Alliance own their own specifications, and regulators such as the FCC decide what you may transmit and at what power.

The data layer counts too

Supporting Wireless Solutions reaches into territory that surprises people arriving from a pure RF background. The objectives name MQTT, RESTful APIs, Webhooks, WebSockets and OpenConfig, and expect recognition of JSON, XML, YAML and YANG as data structures. You are also expected to know what scripting languages are typically used around these systems. None of it requires you to write code, and all of it requires you to recognise the terms in context.

Planning and implementing decide the result

Planning Wireless Solutions is worth 20 percent and Implementing Wireless Solutions 25 percent, and together they describe a project rather than a technology. The planning objectives run through requirements, constraints, technology selection and technical design; the implementing objectives run through pilot testing, configuration, staging, installation, validation and handover.

Planning questions tend to start with a constraint rather than a capability. Budget, regulation, existing infrastructure, business policy and system dependency all appear as explicit objectives, alongside stakeholder identification. The examinable skill is recognising which constraint dominates a scenario, because that is what eliminates the wrong answers.

Implementing questions are more physical than candidates expect. The objectives name mounting equipment to applicable safety requirements and building codes, configuring wired and wireless connectivity, configuring cloud connectivity where appropriate, and implementing authentication, authorisation, encryption, monitoring and onboarding for the chosen system. Then they name the part most engineers skip: documentation, staff training and a final stakeholder meeting.

Supporting Wireless Solutions closes the loop with troubleshooting and vertical context. Interference, signal strength, misconfiguration, security misconfiguration, failing hardware, firmware and driver problems and faulty installation all appear by name, and the exam frames them inside healthcare, industrial, smart city, agricultural, retail, education and large public venue deployments, where the same symptom has different causes and different consequences.

Where does CWISA sit in the CWNP scheme?

CWISA is the entry point of CWNP’s wireless IoT track, which then branches into CWICP for connectivity, CWIIP for integration and CWIDP for design, and culminates in CWISE at expert level. It is a separate ladder from the Wi-Fi track that runs CWTS, CWNA, CWAP, CWDP, CWSP and CWNE.

The CWNP wireless IoT certification ladder from CWISA at administrator level through CWICP, CWIIP and CWIDP to CWISE at expert tier

Knowing which ladder you are on matters more than it sounds. The Wi-Fi track goes deep on 802.11: analysis, design and security of wireless LANs specifically. The IoT track goes wide across the protocols an enterprise actually deploys around those LANs. Someone who wants to specialise in RF analysis should be looking at the Wi-Fi ladder, not this one.

If the connectivity layer is where your work sits, the next rung is the natural follow-on, and the CWICP-202 exam layout shows how much more specific the professional tier becomes once the administrator paper is behind you.

Who should take this exam, and who should not?

CWISA-103 suits network administrators inheriting IoT deployments, integrators and installers who are asked to specify wireless technologies, facilities and operational technology staff whose systems have quietly become networked, and Wi-Fi professionals who keep being handed projects that are not Wi-Fi. It has no prerequisite, so none of those groups needs another credential first.

It is a poor fit for two groups. Anyone whose work is purely 802.11 design or analysis will get more from the Wi-Fi ladder, where the depth is. Anyone looking for a security credential will find the coverage here deliberately broad rather than deep, since security appears as one objective inside implementation rather than as a domain of its own.

That second point is worth separating clearly, because the two subjects are easy to confuse. Securing a wireless network to an examinable standard is a different discipline with its own paper, and the CWSP-208 security professional route covers authentication architecture and attack analysis at a depth CWISA never attempts.

How do you prepare for 60 questions in 90 minutes?

Work outward from the objectives document, weight your time by domain, and rehearse under the clock. Ninety minutes for 60 questions allows 90 seconds each, which is comfortable for recall and tight for reasoning, so the goal of preparation is to convert as much of the syllabus as possible into recognition.

  1. Download the official objectives and turn each bullet into a question you can answer aloud. The list is the exam blueprint, and anything not on it is not examinable.
  2. Spend roughly half your study time on Planning, Implementing and Supporting. They are 70 percent of the paper and the least covered by general wireless material.
  3. Build a one-page comparison of the protocols: range, data rate, power profile, topology and typical use. Most technology questions collapse to that table.
  4. Learn which body owns which standard. It is cheap to memorise and it appears in the first domain.
  5. Read the data and API terms until they are familiar. MQTT, REST, JSON and YANG need recognition, not fluency.
  6. Sit a full timed set before booking, and treat anything below the mid seventies as a signal to go back to the objective list rather than to sit the exam early.

One practical note on the fee: at 275 USD a retake is not trivial, and there is no published discount for a second attempt. Passing first time is worth a fortnight of extra preparation.

Frequently Asked Questions

How many questions are on the CWISA-103 exam?

Sixty questions in 90 minutes, which works out at 90 seconds per question.

What is the passing score for CWISA-103?

Seventy percent. On a 60 question paper that means 42 correct answers.

How much does the CWISA-103 exam cost?

275 USD, delivered through Prometric. CWNP publishes no retake discount for this exam.

Is CWISA-102 still available?

No. CWNP states that the last day to take CWISA-102 was 31 December 2025. Any study material written for it describes a retired version, which is why checking the code on what you read matters.

When will CWISA-103 be replaced?

CWNP lists CWISA-104 as the next scheduled update, due in 2028. That is an unusually long runway for a wireless credential.

Are there prerequisites for the wireless IoT solutions administrator certification?

None are published. CWISA sits at the administrator tier and is designed as the entry point to the CWNP wireless IoT track, so no prior credential is required.

Is CWISA a Wi-Fi certification?

Only partly. It covers 802.11 alongside Bluetooth and BLE, Zigbee, other 802.15.4 protocols, LoRaWAN, Sigfox, cellular and location services. If you want depth in 802.11 specifically, the CWNA and CWAP route is the better fit.

Which domain should I study first?

Implementing and Supporting, at 25 percent each. They carry half the paper between them and are the least well served by general wireless reading.

Does the exam require programming?

No. It expects you to recognise MQTT, REST, Webhooks, WebSockets, OpenConfig, JSON, XML, YAML and YANG, and to know where scripting fits in an IoT deployment, but it does not ask you to write code.

How long is the certification valid?

CWNP does not publish a validity period for CWISA on its credential page, so this guide does not state one. Confirm the expiry on your own certification record once you have passed.

Conclusion

CWISA-103 is a breadth credential for people who look after wireless systems that are not only Wi-Fi. Sixty questions, 90 minutes, a 70 percent pass mark, 275 USD, and five domains in which planning, implementing and supporting a deployment carry 70 percent of the marks.

Two things decide the outcome. Study the current code, because the retired CWISA-102 still dominates search results and the material written for it misses the edges where the pass mark is decided. Then weight your preparation toward the deployment domains rather than the radio theory, however comfortable the theory feels.

Download the official objectives, build the protocol comparison table, and sit a full timed set before you book. With CWISA-104 not due until 2028, the version you prepare for now will still be the current one for a long time.

Rating: 0 / 5 (0 votes)

The post Wireless IoT Solutions Administrator Certification Exam appeared first on iSecPrep.

]]>
Kyverno Certified Associate Exam: Six Domains, One Tool https://www.isecprep.com/2026/09/23/kyverno-certified-associate-exam-six-domains-one-tool/ Wed, 23 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88193 A policy engine read the manifest on the way into the cluster and refused it, and somebody had to write the rule that did the refusing. This credential is for that somebody, and a third of it rests on the writing.

The post Kyverno Certified Associate Exam: Six Domains, One Tool appeared first on iSecPrep.

]]>

A developer pushes a deployment. Three seconds later it comes back rejected, with a message saying the container is missing a resource limit and the image is not signed. Nobody reviewed it. A policy engine read the manifest on the way into the cluster and refused it, and somebody had to write the rule that did the refusing.

The Kyverno Certified Associate exam is the Linux Foundation’s credential for that skill. KCA is 60 multiple choice questions in 90 minutes at a 75 percent pass mark, priced at 250 dollars, across six weighted domains of which writing policies alone carries 32 percent.

Table of Contents

  1. What is Kyverno, and why does it have its own certification?
  2. Is the KCA exam hands on or multiple choice?
  3. What do the six KCA domains cover?
  4. Why writing policies is nearly a third of the exam
  5. What the installation and upgrade domain really asks for
  6. What does KCA cost, and what does the price include?
  7. Where does KCA sit next to CKA and CKS?
  8. How should you prepare for KCA?
  9. Frequently Asked Questions
  10. Conclusion

What is Kyverno, and why does it have its own certification?

Kyverno is a policy engine for Kubernetes that runs as an admission controller, reading every resource on its way into the cluster and deciding whether to allow it, change it or reject it. It has its own credential because policy as code has become a distinct job, and because Kyverno writes its policies in Kubernetes YAML rather than in a separate language.

How a Kyverno policy runs: you apply a deployment, the API server takes the request, the policy reads the manifest and returns a verdict

That last point is the whole reason the project exists. The established alternative expects you to learn a dedicated policy language, which puts a wall between the people who write manifests and the people who write the rules governing them. Kyverno removes the wall, and the consequence is that a platform engineer who already reads YAML can become useful on day one.

The project sits in the CNCF project landscape alongside the rest of the cloud native toolchain, which matters for a credential in a way it would not for a vendor product. A foundation-hosted project has public governance and public roadmaps, so the exam content is anchored to something you can read rather than to a release cycle you cannot see.

What an admission controller actually does

Every request to create or change a resource passes through the Kubernetes API server, and the admission controller stage is where a webhook can intervene before anything is persisted. Kyverno registers itself there. Domain 1 of the exam expects you to know this mechanism, not just the Kyverno syntax that rides on it.

Understanding the sequence explains several things the exam asks about later, including why a policy can mutate a resource before validating it, and why an outage in the webhook can block deployments across a whole cluster if the failure policy is set carelessly.

If you want the credential’s full scope beside the mechanics, the money site’s KCA certification overview sets the six domains and the exam terms out together.

Is the KCA exam hands on or multiple choice?

KCA is an online, proctored, multiple choice exam. This surprises people, because the Linux Foundation’s best-known Kubernetes credentials are performance based and drop you into a live terminal. KCA does not. You answer 60 questions in 90 minutes and need 75 percent, which is 45 correct answers.

The assumption is worth correcting early because it changes how you prepare. A terminal exam rewards muscle memory in the shell; a multiple choice exam at 75 percent rewards precise recall of what each rule type does and what each flag changes. Both need hands-on practice, but for different reasons.

Field Value
Exam name Kyverno Certified Associate
Exam code KCA
Questions 60
Duration 90 minutes
Passing score 75 percent, which is 45 correct answers
Format Online, proctored, multiple choice
Price USD 250 for the exam alone
Prerequisites None
Experience level Beginner
Validity 2 years
Domains 6, weighted

Seventy-five percent is a high bar by certification standards, and it sits oddly next to a beginner label. Ninety seconds a question is comfortable, so the pressure is not time. The pressure is that you can only afford to be wrong 15 times across six domains, three of which carry 10 or 12 percent and therefore only a handful of questions each.

What do the six KCA domains cover?

KCA has six weighted domains: fundamentals of Kyverno at 18 percent, installation configuration and upgrades at 18 percent, the Kyverno CLI at 12 percent, applying policies at 10 percent, writing policies at 32 percent and policy management at 10 percent. The weightings on the money site and on the Linux Foundation’s own page match exactly.

Domain Weight What it names
Fundamentals of Kyverno 18% Policies and rules, YAML manifests, admission controllers, OCI images
Installation, Configuration, and Upgrades 18% Helm installation, custom resource definitions, controller flags, RBAC roles and permissions, high availability, upgrading
Kyverno CLI 12% apply, test, jp, and installing the CLI itself
Applying Policies 10% Applying policy in cluster, resource selection, common rule settings
Writing Policies 32% Validation, preconditions, background scans, mutation, generation, verifyImage, variables and API calls, JSON patches, autogen, cleanup policies, Common Expression Language
Policy Management 10% Policy reports, PolicyExceptions, Kyverno metrics

Read the objective lists rather than the domain names, because the names understate the load. Writing policies is not one topic; it is eleven named capabilities, several of which are independent enough to be their own subject.

Why writing policies is nearly a third of the exam

Writing policies carries 32 percent, which is roughly 19 of the 60 questions and more than the next two domains combined. The reason is straightforward: everything else in Kyverno exists to run the policies, and the policies are where the engineering judgement lives.

The five actions a Kyverno rule can take: reject, change, create, verify and clean up

The objective list names six kinds of rule, and the useful way to hold them is by what each one does to a request rather than by its syntax. Validation rules accept or reject. Mutation rules change a resource on the way through. Generation rules create other resources in response. VerifyImage rules check image signatures and attestations. Cleanup policies remove resources on a schedule.

The parts that sit underneath the rules

Preconditions, variables, API calls and JSON patches are not rule types; they are the machinery that makes a rule conditional or dynamic. Common Expression Language appears here too, which is the newer way of writing those conditions and is the part of the syllabus most likely to be unfamiliar to someone who learned Kyverno two years ago.

Autogen rules are the quiet one. Kyverno can automatically extend a pod-level rule to the controllers that create pods, so a policy written once applies to deployments, jobs and cron jobs without being restated. Candidates who have only written pod policies by hand routinely lose marks here.

Background scans change what a policy means

An admission policy only sees new and changed resources. A background scan applies the same rule to what is already running, which is how you find out that the cluster has been out of compliance since before the policy existed. The distinction between the two modes is a recurring source of exam questions and of production surprises.

The project’s own documentation is effectively this domain written out in prose, and working through it with a cluster open is a better use of study time than any summary.

What the installation and upgrade domain really asks for

Installation, configuration and upgrades carries the same 18 percent as fundamentals, and it is heavier than it sounds. It names Helm-based installation, Kyverno’s custom resource definitions, controller configuration through flags, RBAC roles and permissions, high availability installations, and the upgrade path.

The RBAC half is where security practitioners should pay attention. A policy engine that can mutate and generate resources needs permissions to do so, and those permissions are exactly what an attacker would want. Knowing which service accounts Kyverno runs under, and what each one may touch, is a genuine operational skill rather than exam trivia.

High availability is not optional in practice

Because Kyverno sits in the admission path, its availability is the cluster’s availability for anything that creates resources. The high availability objective exists because a single-replica install in a production cluster is a decision with consequences, and the failure policy that governs what happens when the webhook is unreachable is the setting that decides how bad those consequences are.

Anyone who has worked through the wider Kubernetes security surface on the CKS security specialist exam will recognise the pattern: the control plane component you add for safety becomes something you now have to keep safe and keep running.

What does KCA cost, and what does the price include?

KCA costs USD 250 for the exam on its own. That price includes two attempts, meaning one retake, and 12 months in which to schedule and sit. The certification is valid for two years once earned, and there are no prerequisites to buy first.

The Linux Foundation also sells KCA bundled with its annual subscription at USD 495, which adds access to a large catalogue of courses and skill credentials. Whether that is better value depends entirely on whether you would use the catalogue; as a route to this one credential, the standalone exam is the cheaper path.

The included retake changes the calculation

Two attempts for one price is more generous than it first appears at a 75 percent pass mark. It means a first attempt taken slightly early is a diagnostic rather than a loss, and with a 12 month window there is room to sit, learn what the questions actually look like, and return properly prepared.

That said, the retake is best treated as insurance rather than as a plan. Forty-five correct answers out of 60 is not a bar you clear by accident.

Where does KCA sit next to CKA and CKS?

KCA is narrower than either. The Kubernetes administrator and security specialist credentials cover a whole platform; KCA covers one project inside it, at beginner level, with no prerequisite. The Linux Foundation itself points holders toward the security specialist credential as the natural next step.

The practical question is therefore not which is better but which order makes sense. A platform engineer with no Kubernetes credential at all is usually better served starting with the broad administrator exam, because KCA assumes you already know what a deployment, a service account and a CRD are. A security engineer who already knows Kubernetes and needs policy as code specifically can take KCA directly.

The single-tool credential question

Certifications built around one open source project divide opinion, and the fair criticism is that a tool-specific badge ages with the tool. The counter-argument here is that the underlying skill, expressing governance as code that a cluster enforces automatically, transfers to whatever engine an employer runs, and the concepts in the writing-policies domain map closely onto the alternatives.

It is the same trade-off that runs through the Linux Foundation’s newer associate credentials generally, including the one covered in the PyTorch Associate guide, where a single framework stands in for a whole discipline.

How should you prepare for KCA?

KCA preparation is short by certification standards, usually four to six weeks alongside a job, and almost all of it should happen with a cluster open. A multiple choice format does not change that: the questions ask what a given policy does, and the fastest way to know is to have run it.

  1. Install Kyverno with Helm into a throwaway cluster before reading anything else, since the installation domain carries 18 percent and is the cheapest to learn by doing.
  2. Write one validation rule that rejects a pod without resource limits, then watch it reject a real deployment, which makes the admission controller mechanism concrete.
  3. Work through each rule type in turn, covering validation, mutation, generation, verifyImage and cleanup, and write a small policy for each one rather than reading about it.
  4. Practise preconditions, variables and API calls together, because these are what turn a static rule into a conditional one and they are examined as a group.
  5. Learn Common Expression Language deliberately, as it is the newest part of the syllabus and the part most likely to be missing from older tutorials.
  6. Drill the CLI commands apply, test and jp against your own policies, since the CLI is 12 percent and the commands are few enough to know completely.
  7. Turn on background scans and policy reports on a cluster that already has workloads in it, which shows the difference between admission-time and existing-state enforcement.
  8. Sit a full timed set of 60 questions in 90 minutes to confirm you are clearing 45 rather than hovering near it.

The official resources worth using

The Linux Foundation names two of its own courses as preparation for this exam, and the official KCA page lists the full competency set alongside them. Between that page and the project documentation you have the entire syllabus without paying for anything beyond the exam.

Frequently Asked Questions

Is the KCA exam hands on?

No. It is an online, proctored, multiple choice exam, unlike the Linux Foundation’s performance-based Kubernetes credentials. Hands-on practice still matters, but the sitting itself is not a terminal exam.

How many questions are on the KCA exam?

Sixty questions in 90 minutes, which is roughly 90 seconds each.

What is the passing score for KCA?

Seventy-five percent, which works out at 45 correct answers out of 60. That is a high bar relative to most associate credentials.

What does the KCA exam cost?

USD 250 for the exam alone, which includes two attempts and a 12 month window to sit. A bundle with the annual subscription is sold at USD 495.

Are there prerequisites for KCA?

None. The Linux Foundation lists the experience level as beginner and requires no prior certification, though practical Kubernetes familiarity makes the syllabus far easier to follow.

How long is KCA valid?

Two years from the date it is earned.

What are the KCA domains and weightings?

Fundamentals 18 percent, installation configuration and upgrades 18 percent, the CLI 12 percent, applying policies 10 percent, writing policies 32 percent and policy management 10 percent.

Should you take CKA before KCA?

If you have no Kubernetes credential at all, usually yes, because KCA assumes you already understand deployments, service accounts and custom resources. A practitioner who already has that grounding can take KCA directly.

Does KCA cover Open Policy Agent or Gatekeeper?

No. The syllabus is entirely Kyverno. The concepts transfer, but nothing in the objectives names an alternative engine.

How long does preparation usually take?

Four to six weeks alongside a job is typical, with most of that time spent writing policies against a real cluster rather than reading.

Conclusion

KCA is a narrow credential and it does not pretend otherwise. Six domains, one project, 60 multiple choice questions, and a third of the marks resting on whether you can write a policy that does what you intended. The beginner label describes the assumed starting point, not the 75 percent you need on the day.

Prepare with a cluster open, work through the rule types by what each one does to a request, and give Common Expression Language and autogen more attention than older tutorials will suggest. Then sit a full 60 question set under the clock and check you are clearing 45 comfortably rather than scraping it.

For anyone whose job now includes stopping bad manifests before they land, this is the shortest credible route to proving it.

Rating: 0 / 5 (0 votes)

The post Kyverno Certified Associate Exam: Six Domains, One Tool appeared first on iSecPrep.

]]>
ITIL 4 Foundation Exam Format: 40 Questions, 26 to Pass https://www.isecprep.com/2026/09/23/itil-4-foundation-exam-format-40-questions-26-to-pass/ Wed, 23 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88186 Nine topics, no weightings, and a clock that gives you ninety seconds a question. The specification for this paper is unusually plain, and almost nothing in it matches the gentle impression the word Foundation gives off.

The post ITIL 4 Foundation Exam Format: 40 Questions, 26 to Pass appeared first on iSecPrep.

]]>

Foundation is a comforting word. It suggests a gentle introduction, an open book, and a paper designed to let you through. None of those three things is true here, and candidates who plan around the word rather than the specification are the ones who come out of the test centre surprised.

The ITIL 4 Foundation exam format is 40 multiple choice questions in 60 minutes, closed book, with a 65 percent pass mark. That works out at 26 correct answers and roughly 90 seconds per question, across a syllabus of nine topics that PeopleCert publishes without any percentage weightings at all.

Table of Contents

  1. What does the ITIL 4 Foundation exam actually look like?
  2. How many marks do you need to pass ITIL 4 Foundation?
  3. What does the ITIL 4 Foundation syllabus cover?
  4. Which topics carry the paper when nothing is weighted?
  5. Is ITIL 4 Foundation open book?
  6. What happens after you pass?
  7. How should you prepare for a closed-book hour?
  8. Frequently Asked Questions
  9. Conclusion

What does the ITIL 4 Foundation exam actually look like?

ITIL 4 Foundation is a 60 minute paper of 40 multiple choice questions, scheduled through PeopleCert, with a pass mark of 65 percent and a published fee of USD 463. There is no lab, no scenario simulation and no written response. Every mark on the paper comes from selecting one option out of four, and every question carries the same weight as every other.

That last point is worth pausing on, because it changes how you revise. On an exam with weighted domains you can make a calculated decision to under-prepare a 7 percent area. Here there are no weightings to trade against each other. A question about the service value chain is worth exactly what a question about service level agreements is worth, so the only sensible strategy is even coverage.

Field Value
Exam name PeopleCert ITIL 4 Foundation
Exam code ITIL 4 Foundation
Questions 40
Duration 60 minutes
Passing score 65 percent
Format Multiple choice
Book policy Closed book
Exam fee USD 463
Scheduled through PeopleCert
Syllabus topics 9, with no published weightings

The credential itself has no alphanumeric exam code. Unlike a vendor certification that hides behind something like 1Z0-909 or MLA-C01, this one is booked and referenced by its name, which is why search results for it are crowded with training providers rather than with specification pages.

How many marks do you need to pass ITIL 4 Foundation?

Sixty-five percent of 40 marks is 26. You need 26 correct answers out of 40 to pass ITIL 4 Foundation, which means you can afford to get 14 questions wrong and still walk out certified. Expressed that way the bar sounds generous, and for a well-prepared candidate it is. The constraint is not the mark; it is the clock.

ITIL 4 Foundation exam pacing: 90 seconds per question, 26 marks to pass out of 40 and 14 spare marks

Sixty minutes across 40 questions is 90 seconds each. In practice you want to be faster than that on the recall questions so you can afford to be slower on the ones that describe a situation and ask which guiding principle applies. Those situational items are where the time goes, because they require you to read a short scenario, discard two plausible options and choose between the remaining two.

Where the 14 spare marks actually go

Candidates rarely lose marks evenly. The pattern that shows up again and again is a cluster of losses in one area the candidate skimmed, plus two or three careless errors elsewhere. Fourteen looks like a wide margin until a single under-revised topic takes eight of them on its own.

The defence is not more study hours, it is rehearsal under the clock. Working through the money site’s ITIL 4 Foundation sample questions at exam pace tells you which topic is your weak one far more honestly than rereading a chapter does, and it does it while there is still time to fix it.

There is no partial credit

Multiple choice scoring is binary. A question you half understand scores the same as one you have never seen, which is why the situational items reward a working mental model over memorised definitions. If you can say what the service value chain is for, you can usually reason your way to the right activity even when the wording is unfamiliar.

What does the ITIL 4 Foundation syllabus cover?

The ITIL 4 Foundation syllabus covers nine topics: service management concepts, the service value system, the four dimensions of service management, the guiding principles, the service value chain, ITIL practices, continual improvement, service level agreements, and key metrics and performance indicators. No percentage weighting is published for any of them.

Read as a list it looks like nine separate subjects. Read properly it is one structure described from nine angles, and that is the single most useful thing to understand before you start revising. The service value system is the container. The service value chain sits inside it. The four dimensions describe what you have to keep in balance while the chain runs, the guiding principles describe how to behave while doing it, and the practices are the named capabilities you call on.

Syllabus topic What the exam expects you to do with it
Service management concepts Define a service, name its components, and explain the value it carries to stakeholders
Service value system Describe the framework that creates, delivers and manages services, including governance
Four dimensions of service management Name and apply organisations and people, information and technology, partners and suppliers, and value streams and processes
Guiding principles Recognise which of the seven principles fits a described situation
Service value chain Explain how the chain creates value by optimising activities and resources
ITIL practices Match practices to working methods and to the business strategy they support
Continual improvement Explain how organisations iterate and adapt processes and services
Service level agreements Describe the role of SLAs in defining service quality, and where service level management fits
Key metrics and performance indicators Explain why metrics and KPIs matter to service performance and effectiveness

Two of those nine are narrower than the rest. Service level agreements and key metrics are self-contained subjects you can learn in an evening each. The other seven interlock, and studying them in isolation is the mistake that produces a cluster of lost marks.

Which topics carry the paper when nothing is weighted?

With no published weightings, the honest answer is that PeopleCert does not tell you. What can be said from the syllabus itself is that the guiding principles and the service value system are the two topics the other seven are described in terms of, which makes them the highest-leverage revision targets rather than the highest-scoring ones.

That distinction matters. Nobody can promise you that the guiding principles are worth more marks, and any page that claims a percentage split for this exam has made it up. What is verifiable is structural: the principles appear inside the service value system, the value system frames the value chain, and questions about practices routinely resolve to a judgement about which principle applies.

The seven guiding principles are the reasoning engine

Focus on value, start where you are, progress iteratively with feedback, collaborate and promote visibility, think and work holistically, keep it simple and practical, optimise and automate. Learn those seven well enough to recognise them in a paraphrase and a significant share of the situational questions stop being guesswork, because the correct option is usually the one that names the principle the scenario is quietly describing.

The four dimensions are the most commonly skipped

Organisations and people, information and technology, partners and suppliers, value streams and processes. They are easy to recite and easy to under-revise, because the list is short enough to feel finished. The exam asks you to apply them, typically by describing a failure and expecting you to identify which dimension was neglected, and that is a different skill from listing them.

Anyone approaching ITIL from a project background will recognise the pattern from the PRINCE2 7 Foundation route, which examines its principles the same way: name the rule, then recognise it in a story rather than in a definition.

Is ITIL 4 Foundation open book?

No. PeopleCert states plainly that ITIL 4 Foundation is closed book. You may not bring the official publication, printed notes or a summary sheet into the exam, and nothing is provided in the interface either. This is the detail that catches out candidates who have sat other foundation-level papers where a reference text is permitted.

The consequence is practical rather than dramatic. A closed-book hour rewards recall of names and structures, because you cannot look up which of the four dimensions covers suppliers or how many guiding principles there are. Definitions have to be in your head, not in a file you planned to consult.

Delivery and languages

PeopleCert publishes the exam in twelve languages: English, Chinese, Dutch, French, German, Hungarian, Italian, Japanese, Polish, Brazilian Portuguese, Spanish and Thai. That is an unusually wide list for an IT credential and it reflects ITIL’s reach into public sector and enterprise service desks well outside the English-speaking market.

If English is not your first language, sitting the paper in your own is worth considering even if you work in English daily. Ninety seconds a question leaves very little room for translating a scenario before you can answer it.

What happens after you pass?

The certificate does not last forever. PeopleCert requires renewal every three years, and the standard route is to accumulate 60 CPD points through everyday professional activity and log them against your membership. The alternative route is to complete a different exam from the same product suite before your renewal date falls due.

The two ITIL 4 Foundation renewal routes published by PeopleCert: 60 CPD points over three years, or another exam in the same product suite

This is the part most comparison pages leave out, and it changes the arithmetic of the decision. A credential with a recurring obligation is a different purchase from one you earn once, and it is worth knowing before you book rather than three years afterwards when a renewal notice arrives.

Which route suits which candidate

The CPD route suits somebody already working in service management, because the activities that earn points are largely things they were going to do anyway: reading, attending sessions, contributing to practice. The further-exam route suits somebody who intended to climb the ITIL ladder regardless, since the next credential renews the first one as a side effect.

The route that does not work is ignoring it. A lapsed certification is not a smaller version of a current one on a CV, and the PRINCE2 Agile Foundation credential sits in the same suite, which makes it one of the practical ways to renew while adding something genuinely new.

How should you prepare for a closed-book hour?

Preparation for ITIL 4 Foundation is short by certification standards, usually two to four weeks alongside a job, and it divides cleanly into two halves: learning one connected structure, then rehearsing recall of it at speed. Treating it as nine separate subjects is the most common way to waste that time.

  1. Learn the service value system first as a single diagram, so that every later topic has somewhere to attach rather than floating on its own.
  2. Commit the seven guiding principles to memory by name, then practise recognising each one described in a sentence that never uses its name.
  3. Work through the six activities of the service value chain and be able to say what each one produces, because the exam tests the flow rather than the list.
  4. Memorise the four dimensions and pair each with one concrete failure it would have prevented, which converts a recited list into something you can apply.
  5. Read the ITIL practices in groups rather than alphabetically, since the exam asks which practice fits a situation and grouping makes the distinctions visible.
  6. Study service level agreements and key metrics last, because they are self-contained and will still be fresh on the day.
  7. Sit at least two full timed papers of 40 questions in 60 minutes, closed book, to find out where your 14 marks of headroom are actually going.

What not to spend time on

Historical ITIL versions absorb a surprising amount of candidate effort and earn nothing. The exam examines ITIL 4 as it stands. Background on how the framework evolved is genuinely interesting and the documented history of ITIL explains why so much older material still circulates, but it is context rather than syllabus. The same applies to tooling: no vendor’s service desk product appears on this paper.

For the current framework itself, the ITIL service management home and the official ITIL 4 Foundation page are the two places where the specification and the certification scheme are stated by the bodies that own them.

Frequently Asked Questions

How many questions are on the ITIL 4 Foundation exam?

Forty multiple choice questions, each carrying equal weight. There is no scenario simulation, no written element and no lab component.

What is the passing score for ITIL 4 Foundation?

Sixty-five percent, which is 26 correct answers out of 40. You can lose 14 marks and still pass, though that margin disappears quickly if one topic has been under-revised.

How long is the ITIL 4 Foundation exam?

Sixty minutes, which averages 90 seconds per question. Recall questions should take far less, leaving room for the situational items that describe a scenario and ask which principle or practice applies.

Is ITIL 4 Foundation open book?

No. PeopleCert runs it closed book, so no publication, notes or summary sheet may be used. Definitions and structures have to be memorised rather than looked up.

What does the ITIL 4 Foundation exam cost?

The published exam fee is USD 463. PeopleCert also sells bundles that pair the voucher with official training materials or eLearning, which are priced separately and regionally.

Are the ITIL 4 Foundation syllabus topics weighted?

No. Nine topics are published with no percentage split, and any source claiming one has invented it. Plan for even coverage rather than trying to prioritise by marks.

Which languages is ITIL 4 Foundation available in?

Twelve: English, Chinese, Dutch, French, German, Hungarian, Italian, Japanese, Polish, Brazilian Portuguese, Spanish and Thai.

How long does ITIL 4 Foundation stay valid?

Three years. Renewal is either 60 CPD points logged through PeopleCert membership, or completing a different exam in the same product suite before the renewal date.

How long should preparation take?

Two to four weeks alongside a full-time job is typical. The syllabus is small; the work is in connecting the topics rather than in volume.

Do you need service desk experience to pass?

No, there are no prerequisites. Experience helps with the situational questions because the scenarios describe recognisable workplace problems, but the exam assumes no prior credential.

Conclusion

The specification for this exam is unusually plain, and that is exactly why it is worth reading before booking. Forty questions, 60 minutes, 26 marks to pass, closed book, nine unweighted topics and a three-year renewal obligation. Nothing there is hidden, and nothing there matches the gentle impression the word Foundation gives off.

Prepare for it as one connected structure rather than nine subjects, put disproportionate effort into the guiding principles and the service value system because everything else is described in their terms, and sit at least two full timed papers closed book before the real one. A candidate who has done that will finish inside the hour with marks to spare.

If you take one number away, take 90 seconds. It is the constraint that decides the outcome far more often than the 65 percent does.

Rating: 0 / 5 (0 votes)

The post ITIL 4 Foundation Exam Format: 40 Questions, 26 to Pass appeared first on iSecPrep.

]]>
OCI Observability Professional: 38% of 1Z0-1111-26 Is Logs https://www.isecprep.com/2026/09/22/oci-observability-professional-38-of-1z0-1111-26-is-logs/ Tue, 22 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88148 Six Oracle services hide behind seven domain titles that name outcomes rather than products, and the biggest of them has nothing to do with the three pillars everyone revises. Here is where the fifty questions actually fall, and why two separate domains both deal with logs.

The post OCI Observability Professional: 38% of 1Z0-1111-26 Is Logs appeared first on iSecPrep.

]]>

Defining the pillars of observability is worth 7 percent of this exam. Finding patterns in log data is worth 22. The credential is named after the concept and weighted around the work, and those are two different study plans.

The OCI Observability Professional certification, exam code 1Z0-1111-26, is Oracle’s professional-level credential for monitoring workloads on Oracle Cloud Infrastructure. It runs to 50 questions in 90 minutes at a 68 percent pass mark, and its seven weighted domains put more than a third of the paper into log data alone.

Table of Contents

  1. What does the OCI Observability Professional certification cover?
  2. Where do the marks sit across the seven domains?
  3. Two domains are about logs, and they are not the same skill
  4. How is the 1Z0-1111-26 exam delivered and scored?
  5. What does the APM domain expect you to have done?
  6. Is this 1Z0-1111-25 under a new number?
  7. Who is this exam a fair test for?
  8. How should you prepare for 1Z0-1111-26?
  9. Frequently Asked Questions
  10. Conclusion

What does the OCI Observability Professional certification cover?

The OCI Observability Professional certification validates that an engineer can monitor, trace and troubleshoot workloads running on Oracle Cloud Infrastructure using Oracle’s own Observability and Management services. It spans metrics and alarms, the Events service, Logging, Logging Analytics, Application Performance Monitoring and Stack Monitoring across seven weighted domains.

Those are six distinct products rather than one, and the exam treats them as such. Oracle groups them under a single observability and management platform, but each service has its own concepts, its own ingestion model and its own console experience, and the syllabus tests them separately.

The credential sits at professional level, which in Oracle’s scheme means hands-on rather than foundational. The syllabus says as much directly: Oracle recommends combining courses with practice and real experience, because the questions are written to test applied knowledge rather than recall. Oracle runs several professional level OCI papers on the same pattern, and the OCI data science exam is a good example of how much of each one is platform work.

One thing the exam is not is vendor-neutral observability theory. There is a domain about the pillars, and it is the joint smallest on the paper. Everything else is Oracle’s implementation of them.

Where do the marks sit across the seven domains?

Logging Analytics is the largest domain at 22 percent, followed by Application Performance Monitoring at 20 percent and metrics and alarms at 18 percent. Central log management takes 16 percent, the Events service 10 percent, and both the observability pillars and Stack Monitoring 7 percent each. Seven domains, and a spread of 15 points between the biggest and the smallest.

Domain Weight Approximate questions Service it maps to
Identify log data patterns and create visualizations for advanced analytics 22% 11 Logging Analytics
Monitor applications with deep visibility into end-user experience 20% 10 Application Performance Monitoring
Monitor cloud environments with metrics and alarms 18% 9 Monitoring
Centrally manage and visualize log data 16% 8 Logging
Respond to cloud resource changes in real-time 10% 5 Events
Define the pillars of Observability 7% 4 Platform overview
Monitor distributed components of an application stack 7% 4 Stack Monitoring

With only 50 questions on the paper, a 7 percent domain is about four items and a 22 percent domain is about eleven. That is a real difference in study value, but it also means no domain is safely ignorable: four questions is a third of the 16-question margin a 68 percent pass mark gives you.

The three heaviest domains are all things you configure and read rather than things you define. Logging Analytics, APM and Monitoring together account for 60 percent, and all three reward console time over reading.

Working sample items across all seven is the fastest way to find out which service you have only read about. The sets on the money site’s 1Z0-1111-26 practice questions follow the published weightings, so an uneven profile across the two log domains in particular shows up quickly.

Two domains are about logs, and they are not the same skill

Central log management is 16 percent and log pattern analysis is 22 percent, which puts 38 percent of the exam on log data. They are separate domains because they are separate services with separate jobs: one gets logs into a single place, the other turns what is there into answers.

The OCI log journey across the two log domains of 1Z0-1111-26: collect audit service and custom logs, route them with connectors, then analyse for patterns

Logging, at 16 percent, is about collection and movement

Three objectives sit here. Distinguishing log categories and enabling collection from sources. Managing and searching logs across the whole estate. Creating connectors to move logs somewhere else.

The category distinction is the one people underestimate. OCI separates audit logs, service logs and custom logs, and which one a given signal lands in decides where you look for it and what you can do with it. The connector objective is equally practical: it is about routing, and a question about it is usually really a question about which destination is legitimate for which log type.

Collection from outside OCI is part of this too, and that is where the syslog protocol specification becomes relevant background rather than trivia, because the shape of an incoming record decides how usefully it can be parsed later.

Logging Analytics, at 22 percent, is about interpretation

Four objectives, and the verbs escalate. Distinguish the key concepts. Explore ingestion methods. Analyse search, filter and visualise. Present advanced analytics and features for troubleshooting.

The distinction that matters between the two domains is that Logging lets you find a line and Logging Analytics lets you find a pattern. One answers what happened at 03:14. The other answers whether it has been happening for a fortnight. Oracle’s Logging service documentation is the right starting point for the first, and it will not prepare you for the second.

Candidates who use OCI daily often have the first domain covered by habit and the second barely at all, because reaching for pattern analysis is a deliberate act rather than a reflex. That asymmetry is the single most common gap on this exam.

How is the 1Z0-1111-26 exam delivered and scored?

1Z0-1111-26 is a 50 question multiple choice exam with a 90 minute limit and a 68 percent pass mark, priced at USD $245 with regional variation. That works out at 108 seconds per question and 34 correct answers to pass, leaving a margin of 16.

Field Value
Credential name Oracle Cloud Infrastructure Observability Professional
Exam code 1Z0-1111-26
Previous code 1Z0-1111-25
Level Professional
Questions 50
Format Multiple choice
Duration 90 minutes
Passing score 68 percent
Price USD $245, varies by country and currency
Domains 7, all weighted

Sixty eight percent is a tighter bar than it reads

Most professional cloud exams sit in the low sixties, and each percentage point here is worth half a question on a 50 item paper. Thirty four out of 50 means you can lose the whole of Logging Analytics and one other domain and still fail, which is the arithmetic behind the advice not to leave a weak service unaddressed.

One note on where these figures come from

Every specification above is published on the money site’s syllabus page for this exam. Oracle’s own certification portal returns an error to automated retrieval and its learning site renders entirely in the browser, so none of these figures could be independently re-confirmed against Oracle at the time of writing. They are reproduced as published rather than presented as vendor-confirmed.

What does the APM domain expect you to have done?

Application Performance Monitoring is 20 percent of the paper across three objectives: the key concepts of APM, instrumenting applications for data collection, and visualising and analysing the performance data that comes back. The middle objective is the one that separates candidates, because instrumentation is something you have either done or only read about.

Four stages of the OCI Application Performance Monitoring domain in 1Z0-1111-26: instrument, collect, visualise and explain

Instrumenting an application means deciding what gets traced, attaching an agent or a library, and accepting that some of your latency budget now goes to telemetry. Questions written around that objective tend to be about consequences rather than syntax.

  • Which components need an agent and which can be observed from outside.
  • What a trace actually contains once a request crosses a service boundary.
  • How synthetic monitoring differs from real user data, and when each answers the question you have.
  • Why a dashboard showing healthy infrastructure can sit alongside an application users describe as slow.

The instrumentation model here is the same one the wider industry has settled on, and reading the OpenTelemetry project overview is a useful way to understand the vocabulary of spans, traces and context propagation before mapping it onto Oracle’s implementation.

Stack Monitoring, at 7 percent, is the quiet counterpart. Two objectives, covering the key concepts and discovering resources to monitor with metrics. It is the domain that watches the middleware and database tier underneath the application, and it is small enough that most candidates cover it in an afternoon and large enough that skipping it costs four questions.

Is this 1Z0-1111-25 under a new number?

Broadly yes. Oracle refreshes its cloud exam codes annually, so 1Z0-1111-26 is the current form of the credential that was previously sat as 1Z0-1111-25. The certification name does not change with the code, and the seven domains published for the current version are the ones to plan against.

The practical problem is that search demand has not moved with the code. Almost every recorded query for this exam still carries the 2025 number, which means a candidate searching for study material will find pages written for the previous version sitting above pages written for the current one.

Two habits protect you. Check the code on any breakdown before planning around it, and check the domain list rather than the title, since a page can carry the right code and an older set of weightings. Where the two disagree, the money site’s syllabus page for the current code is the version to trust.

Oracle’s annual roll affects the whole OCI line rather than this exam alone, so the same caution applies to adjacent credentials. The OCI DevOps professional exam moved to its own -26 code in the same cycle, and material for the previous generation is still circulating there too.

Who is this exam a fair test for?

It is a fair test for someone who already operates workloads on OCI and has been asked to explain a production problem after the fact. It is a harder test than it looks for a cloud engineer from another provider, because six named Oracle services have to be learned as products rather than as concepts.

Starting point Usually already comfortable Where the gap tends to sit
OCI operations engineer Monitoring, alarms, Events, reading logs Logging Analytics pattern work, APM instrumentation
Observability engineer from another cloud Pillars, tracing concepts, instrumentation Oracle’s service boundaries, connectors, log categories, console workflows
Application developer APM, traces, what slow means to a user Metrics and alarm definitions, Stack Monitoring, the infrastructure half

The second row is the interesting one. Somebody who has run a mature observability stack elsewhere knows more about the subject than the exam requires, and less about the product than it demands. Their preparation is mostly translation, and it is quicker than they fear once they stop looking for equivalents and start learning the boundaries.

For readers mapping this credential against the rest of the OCI professional track before committing, the OCI multicloud architect credential sits at the same level with a very different scope, which is a useful contrast when deciding which to take first.

How should you prepare for 1Z0-1111-26?

Build the preparation around the two log domains first, because together they are 38 percent and they are the pair most likely to be unevenly covered by real experience. The sequence below moves from what most OCI engineers already do toward what they usually do not.

  1. Map the seven domains onto the six services so you always know which product a question is really about, since the domain titles describe outcomes rather than naming the service.
  2. Enable log collection from a source in each of the three categories, audit, service and custom, and confirm where each one lands.
  3. Build a connector that moves logs to another destination, then check what arrives and what does not.
  4. Ingest a log set into Logging Analytics and work a genuine troubleshooting question through search, filter and visualisation rather than stopping at the first matching line.
  5. Define an alarm from a metric, trigger it deliberately, and read what the notification actually contains.
  6. Write an Events rule and integrate it with another OCI service, since the Events domain is small but entirely practical.
  7. Instrument one application for APM end to end, then compare what synthetic monitoring tells you against what real user data tells you.
  8. Spend an afternoon on Stack Monitoring discovery, which is enough for a 7 percent domain and more than most candidates give it.
  9. Finish with timed sets of 50 questions in 90 minutes, tracking the score for the two log domains separately from everything else.

Step one matters more than its position suggests. Several domain titles on this syllabus describe a goal rather than a product, and a candidate who has not made that mapping loses time in the exam working out which service a question is set in.

Frequently Asked Questions

How many questions are on the 1Z0-1111-26 exam?

Fifty multiple choice questions with a 90 minute limit, which is 108 seconds each. The pass mark of 68 percent means 34 correct answers, leaving a margin of 16.

What is the passing score for the OCI Observability Professional exam?

68 percent. That is higher than most professional level cloud exams, and on a 50 question paper each percentage point is worth roughly half a question, so the margin is tighter than it sounds.

How much does the exam cost?

USD $245 as published, with pricing varying by country and by localised currency. Training is a separate and optional cost.

Which domain is the largest?

Logging Analytics at 22 percent, roughly eleven questions. Application Performance Monitoring follows at 20 percent and metrics and alarms at 18 percent, so the three console-heavy services carry 60 percent between them.

Is 1Z0-1111-26 the same exam as 1Z0-1111-25?

It is the current form of the same credential. Oracle rolls its cloud exam codes annually, so plan against the domains published for the -26 code and treat older breakdowns as a version behind.

How much of the exam is about logs?

Thirty eight percent, split across two domains. Central log management is 16 percent and log pattern analysis is 22 percent, and they test different skills rather than the same one twice.

Do you need to have instrumented an application for APM?

It is strongly advisable. Instrumenting applications for data collection is one of three objectives in a 20 percent domain, and questions about it turn on consequences that are hard to reason about without having done it.

How much of the exam is observability theory?

Very little. The domain that defines the pillars is 7 percent, roughly four questions. Everything else is Oracle’s implementation, so conceptual knowledge from another platform helps less than it might seem.

Is Stack Monitoring worth studying?

Yes, and briefly. At 7 percent it is about four questions across two objectives, which most candidates can cover in an afternoon. Skipping it spends a quarter of your pass margin before you start.

Can I confirm these figures on Oracle’s own site?

Not easily. Oracle’s certification portal returns an error to automated retrieval and its learning site renders in the browser rather than serving readable content, so published third-party syllabus pages are the practical reference for exam specifications.

Conclusion

The useful way to read 1Z0-1111-26 is as an exam about six Oracle services rather than one about observability. The concept itself is worth four questions. Logging Analytics alone is worth eleven, and the two log domains together outweigh anything else on the paper.

That reframing changes the study plan immediately. Time spent rehearsing the three pillars is time not spent in Logging Analytics, and Logging Analytics is where most OCI engineers discover they have been reading logs rather than analysing them.

Once the seven domains are mapped onto the services behind them, timed practice across all of them is the quickest way to see which service is still costing you marks.

Rating: 0 / 5 (0 votes)

The post OCI Observability Professional: 38% of 1Z0-1111-26 Is Logs appeared first on iSecPrep.

]]>
Cloud Security Automation Certification: GCSA Has No Weights https://www.isecprep.com/2026/09/22/cloud-security-automation-certification-gcsa-has-no-weights/ Tue, 22 Sep 2026 00:00:00 +0000 https://www.isecprep.com/?p=88138 Eighteen objectives, seventy five questions, and not one percentage to tell you where the marks are. GIAC leaves GCSA candidates without the arithmetic every other study plan is built on, so here is how the eighteen group into five clusters and which one usually turns out to be the gap.

The post Cloud Security Automation Certification: GCSA Has No Weights appeared first on iSecPrep.

]]>

A deployment pipeline that ships to production several times a day never pauses for a security review, and the GIAC Cloud Security Automation certification is built entirely on that fact. Its answer is not slower releases. Its answer is controls that run at pipeline speed.

The cloud security automation certification, exam code GCSA, is GIAC’s practitioner credential for engineers who secure cloud native systems through automation rather than through gates. It runs to 75 questions in 120 minutes at a 66 percent pass mark, and it publishes eighteen objectives without a single weighting attached to any of them.

Table of Contents

  1. What does the cloud security automation certification cover?
  2. Why does GCSA publish no domain weightings?
  3. How is the GCSA exam delivered and scored?
  4. Container orchestration runs through five of the eighteen objectives
  5. What does the pipeline half of the syllabus expect?
  6. Who is this credential actually for?
  7. Is SEC540 required to pass GCSA?
  8. How should you prepare when nothing is weighted?
  9. Frequently Asked Questions
  10. Conclusion

What does the cloud security automation certification cover?

The cloud security automation certification, GCSA, validates that an engineer can build security into a cloud native delivery pipeline instead of bolting it on afterwards. It spans DevOps and DevSecOps fundamentals, infrastructure as code, container and Kubernetes security, secrets handling, supply chain integrity, policy as code, and continuous compliance across eighteen published objectives. Policy enforcement inside the cluster has its own credential, and the Kyverno policy certification covers the admission control side of that pipeline.

The credential sits in GIAC’s Practitioner tier, which is the band for hands-on role certifications rather than leadership or applied-knowledge credentials. That placement matters when you are reading the objectives, because almost every one of them is written as something the candidate can do rather than something the candidate can define.

Read the objective wording closely and the pattern is consistent. The candidate can construct rules. The candidate can use the kubectl command line interface. The candidate can apply policy as code controls. Only two of the eighteen objectives ask you to explain or summarise anything; the rest describe actions.

GIAC’s own framing of the credential comes from the co-author of the aligned course.

“The GIAC Cloud Security Automation (GCSA) certification covers cloud services and modern DevSecOps practices that are used to build and deploy systems and applications more securely. The certification shows that you not only know how to speak the language of modern cloud and DevSecOps principles but can put them into practice in an automated and repeatable manner.”

Frank Kim, SEC540 Course Co-Author

Why does GCSA publish no domain weightings?

GIAC lists eighteen certification objectives for GCSA and attaches a percentage to none of them. That is a deliberate house style across GIAC credentials rather than an omission on one exam, and it changes how you plan: there is no largest domain to anchor a study schedule on, and no smallest one you can safely under-prepare.

Three step method for planning GCSA study without domain weightings: group the 18 topics, test each cluster, fill the weak one

Most certification study plans are built by arithmetic. You take the weightings, multiply by the question count, and spend your hours in proportion. With GCSA that method has nothing to work with. Eighteen objectives across 75 questions averages roughly four questions each, and the only honest planning assumption is that every objective is examinable.

That sounds harsher than it is. In practice the eighteen objectives cluster into a small number of genuinely different skill areas, and grouping them is the substitute for weighting them.

Cluster Objectives it contains Count
Container orchestration and workloads Architecture and fundamentals, risks and access control, runtime security, workload security, container lifecycle security 5
Pipeline and delivery security Understanding the DevOps workflow, securing the DevOps workflow, software supply chain security, configuration management 4
Policy, compliance and remediation Policy enforcement, cloud compliance as code, automated cloud remediation 3
Microservices and edge Microservices architecture and deployment, microservice API gateways, edge identity and authentication 3
Infrastructure, secrets and visibility Deploying cloud infrastructure as code, managing secrets, cloud native observability 3

Grouped that way, one thing is immediately clear. Container orchestration is the single biggest cluster by objective count, and no reading of the syllabus makes it optional.

Because the syllabus will not tell you where the marks sit, the fastest way to find your own weak cluster is to work items and watch where you hesitate. The GCSA sample questions published on the money site are drawn across the clusters rather than concentrated in one, which makes an uneven profile show up quickly.

How is the GCSA exam delivered and scored?

GCSA is a single proctored exam of 75 questions with a 120 minute limit and a 66 percent minimum passing score, priced at $999 USD. That works out at 96 seconds per question and 50 correct answers to pass, leaving a margin of 25. The exam is web based and must be proctored, either remotely or at a test centre.

Field Value
Credential name GIAC Cloud Security Automation
Exam code GCSA
Tier Practitioner Certification
Questions 75
Duration 120 minutes
Passing score 66 percent
Price $999 USD
Objectives 18, none weighted
Proctoring Remote through ProctorU, or onsite through Pearson VUE
Aligned training SEC540
Renewal 36 CPE credits over four years

Where the 66 percent figure comes from

The pass mark is not a round number somebody chose. GIAC sets it through a psychometric standard-setting study, and 66 percent applies to exam versions released from 29 June 2024 onward. Older material quoting a different figure is describing a retired version, which is worth knowing if you are reading study notes written a few years ago.

The 120 day window most candidates miss

Once your attempt is activated in your GIAC account you have 120 days to complete it. That is generous compared with most vendors, but it is a deadline rather than an open invitation, and it starts at activation rather than at the moment you feel ready. Plan the purchase around the study, not the other way round.

Container orchestration runs through five of the eighteen objectives

Five GCSA objectives are about containers and the platform that schedules them: architecture and fundamentals of container orchestration, risks and access control, runtime security, workload security, and container lifecycle security. No other topic on the syllabus is named five times, which makes Kubernetes the practical centre of gravity of the exam.

These five are not repetitions of one another. They ask for different things, and a candidate who is comfortable with one can be exposed on the next.

  • Architecture and fundamentals expects you to identify core components and drive them with kubectl, which is the only objective on the whole syllabus that names a specific command line tool.
  • Risks, authentication and access control covers the security controls the platform itself provides, role based access control among them, plus the known attack paths against a cluster.
  • Runtime security is narrower than it sounds: it is about admission controllers rejecting misconfigured or malicious workloads before they run.
  • Workload security targets a specific documented weakness, namely how pods authenticate to cloud services, and the OIDC-based workload identity pattern that fixes it.
  • Container lifecycle security steps outside the cluster to image hardening and scanning.

The workload identity objective is the one that catches people. It sits at the join between two identity systems, the cluster’s and the cloud provider’s, and reading the Kubernetes security concepts without also understanding how the provider issues credentials leaves half the picture missing.

There is a useful sibling comparison here. GIAC’s cloud security line also includes a fundamentals-level credential aimed at securing cloud services themselves rather than the delivery pipeline around them, and the cloud security essentials credential covers that ground at a lower technical bar. Candidates who find the Kubernetes cluster is genuinely new territory often take that route first.

What does the pipeline half of the syllabus expect?

Four objectives cover the delivery pipeline itself: understanding the DevOps workflow, securing it, software supply chain security, and configuration management. Together they ask whether you can put controls inside the build and release process rather than in front of it, and whether you can prove what went into a release afterwards.

Controls inside the pipeline, not in front of it

Securing the DevOps workflow names the pre-commit and pre-merge phases specifically, which tells you where GIAC thinks the controls belong. It also names AI-augmented controls as part of workflow hardening, a recent addition that reflects how quickly review tooling has changed.

Configuration management is framed around trusted machine images rather than around any single tool. The objective is the security benefit of building hardened gold images and then having the pipeline consume them, so the reasoning transfers whether your shop uses one image builder or another.

Proving what shipped

Software supply chain security asks for the standard steps that secure a container image supply chain, and names artifact signing and SBOM vulnerability scanning as examples. Frameworks such as the SLSA supply chain levels give that objective a vocabulary, and candidates who have worked through a real signing and attestation setup tend to find this the easiest cluster on the paper.

Policy enforcement rounds the cluster out and is worth reading twice. It is the only objective that names application security posture management platforms, and it is specific about what they do: ingest findings from several pipeline sources, deduplicate them, and gate a deployment on the result.

Who is this credential actually for?

GIAC names a deliberately wide audience for GCSA: developers, software architects, operations engineers, system administrators, security analysts and engineers, consultants, auditors, and risk managers. In practice that breadth means the exam is approached from two very different starting points, and which one you come from decides your study plan more than anything else.

Engineers arriving from the build side usually know pipelines, infrastructure as code and container tooling, and are weakest on the controls: admission policy, compliance as code, posture management and the auditing story. Engineers arriving from the security side know the controls and are weakest on the plumbing that carries them.

Starting point Usually already comfortable Where the gap tends to sit
Platform or DevOps engineer Pipelines, infrastructure as code, Kubernetes operation, image builds Admission control, policy as code, compliance automation, posture management
Cloud or application security engineer Threat models, secrets handling, supply chain risk, identity kubectl fluency, cluster internals, microservice deployment patterns, observability
Auditor or risk manager Compliance frameworks, evidence and reporting Almost the entire hands-on half; this is the hardest route in

For the auditor and risk manager profile, GIAC’s own audience list is more optimistic than the objective wording. Eighteen objectives written as things a candidate can do is a high bar for anyone who does not build systems, and that group should expect a longer runway than the other two.

Is SEC540 required to pass GCSA?

No. GIAC does not require any training course as a condition of sitting GCSA, and the certification can be attempted on the strength of experience alone. SEC540, Cloud Native Security and DevSecOps Automation, is the aligned course and the objectives track it closely, but the requirement is competence rather than attendance.

Comparison of the SEC540 course route and the hands on experience route into the GIAC GCSA certification

That said, the alignment is tight enough to matter when you are budgeting. The eighteen objectives read as a course outline because they largely are one, so a candidate who skips the course is taking on the job of mapping each objective to their own material.

Practical experience is the strongest substitute, and it needs to be the right kind. Running workloads on a managed Kubernetes service is directly relevant; managing a cloud account without any container or pipeline exposure is not. If you can look at the five orchestration objectives and recall doing each of those things, the aligned SANS course becomes an accelerator rather than a prerequisite.

One more piece of context for anyone weighing the price. GIAC operates as an ANAB-accredited ISO/IEC 17024 personnel certification body, which is the accreditation standard that governs how certification bodies run exams and set pass marks. It is part of why the pass mark comes from a standard-setting study rather than from a product decision.

How should you prepare when nothing is weighted?

Replace weighting with coverage. Because GCSA gives you no percentages, the planning unit is the objective rather than the domain, and the goal is to reach a defensible level on all eighteen rather than an excellent level on a few. The sequence below works outward from the biggest cluster.

  1. Work the five container orchestration objectives first, since they are the largest cluster and every later topic assumes you can read a cluster.
  2. Get genuinely fluent with kubectl, because it is the only tool named anywhere in the eighteen objectives and fluency with it shortens every practical question.
  3. Follow one pod’s identity all the way out to a cloud service using OIDC-based workload identity, which turns the workload security objective from a definition into something you have seen fail.
  4. Build a pipeline that produces a signed image and an SBOM, then break the signature deliberately and watch what the gate does.
  5. Write policy as code that rejects a real misconfiguration, then extend the same rule into automated remediation, since policy enforcement and automated cloud remediation are separate objectives that share one skill.
  6. Instrument a microservice for metrics, logs and traces, because cloud native observability is easy to skim and hard to answer from theory.
  7. Put an API gateway and network policy in front of that service so microsegmentation and edge authentication stop being abstractions.
  8. Finish with timed sets of 75 questions in 120 minutes, checking that no single cluster is dragging your score below the 66 percent line.

A candidate coming from the security rather than the build side should reverse the first two blocks and start with the pipeline, since that is the shorter climb from where they already stand. For a sense of how the broader GIAC cloud track fits together before committing, the public cloud security exam covers adjacent ground from a provider-first angle.

Frequently Asked Questions

How many questions are on the GCSA exam?

GCSA has 75 questions and a 120 minute limit, which is roughly 96 seconds per question. It is delivered as a single proctored exam rather than split into parts.

What is the passing score for GCSA?

66 percent, which means 50 correct answers out of 75. GIAC set that figure through a psychometric standard-setting study, and it applies to exam versions released on or after 29 June 2024.

How much does the cloud security automation certification cost?

$999 USD for the certification attempt. Training is a separate cost and is not required, so the exam fee is the only mandatory spend.

Does GCSA publish domain weightings?

No. GIAC publishes eighteen certification objectives for GCSA with no percentage attached to any of them. Planning has to be built on covering every objective rather than on concentrating effort where the marks sit.

How much Kubernetes knowledge does GCSA need?

A working amount. Five of the eighteen objectives name container orchestration or containers directly, covering cluster components, access control, admission controllers, workload identity and image hardening. kubectl is the only tool the syllabus names.

Is SEC540 required before taking GCSA?

No course is required. SEC540 is the aligned training and the objectives track it closely, but GIAC lets candidates sit the exam on experience alone. Relevant experience means containers and pipelines, not general cloud administration.

How long do you have to sit the exam after buying it?

120 days from the date your attempt is activated in your GIAC account. The clock starts at activation rather than at purchase or at the point you feel prepared.

How is GCSA proctored?

Every GIAC exam is web based and must be proctored. There are two routes: remote proctoring through ProctorU, or onsite proctoring at a Pearson VUE test centre.

How long does the certification stay valid?

GIAC certifications are kept active by earning 36 CPE credits over four years. Credits can come from SANS training, conferences, published writing and other approved industry activity.

Is GCSA the same thing as GCSA Guardicore?

No, and the acronym collision causes real confusion. GCSA here is the GIAC Cloud Security Automation certification. The same letters are used elsewhere as a product abbreviation and have nothing to do with this credential.

Conclusion

GCSA is unusual among cloud security credentials in two ways that reinforce each other. It is written almost entirely in the language of doing rather than knowing, and it refuses to tell you where the marks are. Taken together, those mean the exam rewards breadth of genuine practice and punishes the selective revision that carries people through weighted papers.

The practical route in is to stop looking for a shortcut through the eighteen objectives and instead group them, find which of the five clusters you cannot demonstrate, and build that one first. Container orchestration is where most candidates find their gap, and it is also the cluster that makes the rest of the syllabus legible.

When you are ready to test that coverage rather than read about it, working exam-style items across all five clusters is the quickest way to see which one is still costing you marks.

Rating: 0 / 5 (0 votes)

The post Cloud Security Automation Certification: GCSA Has No Weights appeared first on iSecPrep.

]]>