CyberJA.
YOUR CERTIFICATION STUDY COMPANION

Learn the concepts.
Practise the decisions.

Choose a certification connected to the work you want to do. Discover how Richea Perry’s CyberJA courses and free tools can strengthen your understanding, then complete the official exam-specific preparation.

17 pathways · 10 linked courses · Guided practical tasks

Step 1 — Choose your goal

Filter by your target role or subject. Beginners can start with CC or SC-900.

Step 2 — Learn and practise

Open a certification card. Follow its course links and complete the suggested business task.

Step 3 — Close your gaps

Compare your knowledge with the issuer’s current outline. Add official study resources, technical labs and practice questions.

Step 4 — Check eligibility

Confirm the current exam, experience, fees, application and renewal rules before booking.

17 pathways

01 / Foundations

CC — Certified in Cybersecurity

ISC2 · New cybersecurity students

How CyberJA supports your preparation: Security principles, access control, network security, operations and incident/continuity concepts. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Apply CIA impact analysis to an asset and explain appropriate controls.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Study the full current CC outline, networking terminology and official practice material.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

02 / Foundations

SC-900 — Security, Compliance, and Identity Fundamentals

Microsoft · Students exploring Microsoft security

How CyberJA supports your preparation: Identity, compliance and cloud security concepts. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Document least privilege, identity lifecycle and cloud responsibilities.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Learn Microsoft Entra, Defender and Purview product capabilities through Microsoft Learn.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

03 / Audit & GRC

CISA — Certified Information Systems Auditor

ISACA · Aspiring IT auditors

How CyberJA supports your preparation: Audit planning, evidence, control testing, governance and business resilience. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Create a scoped audit finding with evidence, business impact and a remediation action.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Cover all five official domains, audit standards, acquisition/development and exam-style audit judgement. Check experience and application requirements.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

04 / Leadership & risk

CISM — Certified Information Security Manager

ISACA · Security managers and future CISOs

How CyberJA supports your preparation: Governance, business-aligned risk, security programme planning and incident management. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Explain a security gap to management and propose an accountable treatment plan.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Study the full official outline and management decision scenarios. Confirm experience, ethics and application requirements.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

05 / Leadership & risk

CRISC — Certified in Risk and Information Systems Control

ISACA · Technology risk practitioners

How CyberJA supports your preparation: Risk scenarios, likelihood/impact, control evaluation, treatment and reporting. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Build a business risk scenario, justify current and residual risk and compare investment assumptions.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Use the full official risk outline, risk metrics and exam-specific practice. Check qualifying experience.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

06 / Audit & GRC

CGRC — Certified in Governance, Risk and Compliance

ISC2 · GRC and control assurance practitioners

How CyberJA supports your preparation: Scope, control selection, assessment evidence and ongoing governance. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Link an obligation to a control, test procedure and dated evidence.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Study the complete CGRC lifecycle and authorisation concepts, official terminology and experience requirements.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

07 / Leadership & risk

CISSP — Certified Information Systems Security Professional

ISC2 · Experienced security practitioners

How CyberJA supports your preparation: Business risk, asset protection, IAM, architecture, operations and assurance. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Connect a business process to systems, data, controls and recovery dependencies.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Cover all eight official domains including technical areas beyond these courses. Check experience, endorsement and Associate options with ISC2.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

08 / Cloud & architecture

CCSP — Certified Cloud Security Professional

ISC2 · Cloud security and risk practitioners

How CyberJA supports your preparation: Cloud responsibilities, data protection, governance and cloud risk assessment. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Review cloud data, identity, logging, backup and supplier responsibilities.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Add hands-on cloud architecture, platform/infrastructure, application and operations study across the full official outline. Check experience requirements.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

09 / Operations & forensics

SC-200 — Security Operations Analyst Associate

Microsoft · Microsoft security operations students

How CyberJA supports your preparation: Incident triage, detection reasoning, evidence and response documentation. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Replay a synthetic detection and document what it can and cannot detect.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Practise Microsoft Sentinel, Defender, KQL and current product-specific objectives in a permitted lab. The website replay is not a live SIEM.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

10 / Operations & forensics

CCOA — Certified Cybersecurity Operations Analyst

ISACA · Aspiring cybersecurity analysts

How CyberJA supports your preparation: Threat and vulnerability analysis, countermeasures and operational assessment. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Validate a vulnerability, prioritise it using business context and record a retest plan.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Study the official CCOA blueprint and add tool-based operational exercises and exam-specific practice.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

11 / Operations & forensics

GCFA — GIAC Certified Forensic Analyst

GIAC · Students progressing to advanced digital forensics

How CyberJA supports your preparation: Initial evidence reasoning, incident timelines and investigation write-ups. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Complete the Practice Lab forensic investigation with evidence references and limitations.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Introductory support only: add substantial disk/memory forensics, artifact analysis, threat hunting and advanced incident response labs from the official objectives.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

12 / AI & privacy

AIGP — Artificial Intelligence Governance Professional

IAPP · AI governance and risk students

How CyberJA supports your preparation: AI risk, accountability, lifecycle governance and implementation strategy. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Document an AI use case, affected people, controls, oversight and adoption gates.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Study the current AIGP Body of Knowledge, jurisdiction-specific laws, lifecycle detail and official preparation resources.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

13 / AI & privacy

CIPM — Certified Information Privacy Manager

IAPP · Privacy programme practitioners

How CyberJA supports your preparation: Governance, ownership, data lifecycle, privacy impact and incident coordination. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Map sensitive data, retention, access and privacy response responsibilities.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Add the complete privacy programme lifecycle, relevant laws, metrics and official CIPM preparation.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

14 / AI & privacy

CDPSE — Certified Data Privacy Solutions Engineer

ISACA · Privacy-focused technology practitioners

How CyberJA supports your preparation: Privacy governance, data lifecycle and access/control assessment. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Record a data flow and propose privacy safeguards with verification evidence.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Add privacy engineering, architecture and full official exam coverage. Check qualifying experience and application requirements.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

15 / Audit & GRC

ISO/IEC 27001 Lead Implementer

PECB · ISMS implementation practitioners

How CyberJA supports your preparation: Risk assessment, compliance, control ownership and improvement planning. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Produce a scoped evidence and action register for a security management programme.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Study the actual standard, ISMS clauses, Statement of Applicability, internal audit and management review; follow PECB training/exam and credential-level requirements. This is a PECB individual credential, not an ISO-issued credential.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

16 / AI & privacy

ISO/IEC 42001 Lead Implementer

PECB · AI management system implementers

How CyberJA supports your preparation: AI risk, governance responsibilities and controlled adoption. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Draft AI governance roles, an adoption roadmap and monitoring/review checkpoints.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Study the actual ISO/IEC 42001 standard, AIMS requirements and PECB methodology and credential criteria. This course alignment is supplementary.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

17 / Continuity & resilience

CBCI — Certificate of the Business Continuity Institute

BCI · Business continuity and recovery students

How CyberJA supports your preparation: Business impact, process dependencies, recovery priorities, RTO/RPO and exercises. These practical examples help you explain and apply the concepts behind scenario questions.

View courses, practice task and study gaps

Step 1 — Learn the relevant concepts

Step 2 — Apply them in a business scenario

Create a business impact analysis, recovery targets and a scheduled tabletop exercise.

Open the practical tool →

Step 3 — Complete exam-specific preparation

Study the complete current BCI Good Practice Guidelines and CBCI syllabus; use official or licensed preparation where required. The credential is named a Certificate.

Official credential / exam guidance ↗

Step 4 — Explain your decisions

Write why the control is appropriate, what evidence supports your conclusion, what remains uncertain and how you would verify improvement. Then practise authorised exam-style questions and review every mistake.

Already taking a CyberJA course?

Find it below to see related certification pathways. Treat these as options to explore, rather than a requirement to pursue every credential.

GRC Analyst to Manager: Exploring Real Job Descriptions

Related pathways: CISM — Certified Information Security Manager.

Explore this course ↗
Practical Compliance Management for GRC Professionals

Related pathways: SC-900 — Security, Compliance, and Identity Fundamentals; CISA — Certified Information Systems Auditor; CGRC — Certified in Governance, Risk and Compliance; AIGP — Artificial Intelligence Governance Professional; CIPM — Certified Information Privacy Manager; CDPSE — Certified Data Privacy Solutions Engineer; ISO/IEC 27001 Lead Implementer; ISO/IEC 42001 Lead Implementer.

Explore this course ↗
“Best Practices” for Cybersecurity & GRC Professionals

Related pathways: CC — Certified in Cybersecurity; CISM — Certified Information Security Manager; CISSP — Certified Information Systems Security Professional; CCOA — Certified Cybersecurity Operations Analyst; ISO/IEC 27001 Lead Implementer; CBCI — Certificate of the Business Continuity Institute.

Explore this course ↗
Practical Assessments for Cybersecurity & GRC Professionals

Related pathways: CISA — Certified Information Systems Auditor; CISM — Certified Information Security Manager; CRISC — Certified in Risk and Information Systems Control; CGRC — Certified in Governance, Risk and Compliance; SC-200 — Security Operations Analyst Associate; CCOA — Certified Cybersecurity Operations Analyst; GCFA — GIAC Certified Forensic Analyst; AIGP — Artificial Intelligence Governance Professional; CIPM — Certified Information Privacy Manager; ISO/IEC 27001 Lead Implementer; CBCI — Certificate of the Business Continuity Institute.

Explore this course ↗
Effective IAM Governance: A Practical Approach

Related pathways: SC-900 — Security, Compliance, and Identity Fundamentals; CISSP — Certified Information Systems Security Professional; CCSP — Certified Cloud Security Professional; CIPM — Certified Information Privacy Manager; CDPSE — Certified Data Privacy Solutions Engineer.

Explore this course ↗
Practical Zero Trust Implementation

Related pathways: CISSP — Certified Information Systems Security Professional; CCSP — Certified Cloud Security Professional.

Explore this course ↗
The Ultimate Cybersecurity Professional

Related pathways: CC — Certified in Cybersecurity; CISSP — Certified Information Systems Security Professional; SC-200 — Security Operations Analyst Associate; CCOA — Certified Cybersecurity Operations Analyst; GCFA — GIAC Certified Forensic Analyst; CBCI — Certificate of the Business Continuity Institute.

Explore this course ↗
Cloud Adoption Risk Assessment

Related pathways: SC-900 — Security, Compliance, and Identity Fundamentals; CRISC — Certified in Risk and Information Systems Control; CCSP — Certified Cloud Security Professional; CDPSE — Certified Data Privacy Solutions Engineer.

Explore this course ↗
Management of AI Risk

Related pathways: CRISC — Certified in Risk and Information Systems Control; AIGP — Artificial Intelligence Governance Professional; ISO/IEC 42001 Lead Implementer.

Explore this course ↗
IT Auditing Fundamentals for the GRC Analyst

Related pathways: CISA — Certified Information Systems Auditor; CGRC — Certified in Governance, Risk and Compliance.

Explore this course ↗