Cybersecurity Learning Roadmap

Saira’s Cybersecurity Bootcamp
⚡ Personal Bootcamp

Cybersecurity
Learning Roadmap

// From Zero → Security+ Ready · Self-Paced

👩‍💻 Saira Ghazi · HND Nutrition → CyberSec
0
Completed
0
Total Tasks
0%
Progress
0
Certs Earned

// Overall Progress

Phase 1: Foundation 0% complete
CC
🏆 ISC2 CC — Do This First! (Free Certification)
Parallel with Phase 1 & 2 · Free exam + free training · No experience required
0%
Go to isc2.org → Create a free account → Register for “Certified in Cybersecurity (CC)” free exam offer
freedo today15 min
Enroll in ISC2’s free self-paced CC training course on their website (included with registration)
freewatch~14 hrs total
Learn CIA Triad — Confidentiality, Integrity, Availability with real life examples (same as Security+ Obj 1.2)
watchimportant~1 hr
Understand Authentication methods and Multi-Factor Authentication (MFA) — what they are and why they matter
watchfree~45 min
Learn Non-repudiation and Privacy concepts — Obj 1.1
watchfree~30 min
Study Risk Management basics: risk identification, risk assessment, risk treatment — Obj 1.2
watchimportant~1 hr
Learn 3 security control types: Technical, Administrative, Physical — Obj 1.3
watchfree~30 min
Read ISC2 Code of Ethics — understand the professional code of conduct — Obj 1.4
readfree~20 min
Learn Governance: difference between Policies, Procedures, Standards, Regulations and Laws — Obj 1.5
watchimportant~45 min
Understand Business Continuity (BC) — purpose, importance and key components — Obj 2.1
watchfree~30 min
Learn Disaster Recovery (DR) — difference between DR and BC, RTO and RPO concepts — Obj 2.2
watchimportant~30 min
Study Incident Response basics — the 6 step process: Prepare→Detect→Analyze→Contain→Eradicate→Recover — Obj 2.3
watchimportant~45 min
Learn Physical Access Controls — badge systems, CCTV, security guards, alarm systems — Obj 3.1
watchfree~30 min
Study Logical Access Controls — Least Privilege, DAC, MAC, RBAC, Segregation of Duties — Obj 3.2
watchimportant~1 hr
Learn OSI Model (7 layers) and TCP/IP Model — understand what happens at each layer — Obj 4.1
watchimportant~1.5 hrs
Understand IPv4, IPv6, WiFi and common ports — Obj 4.1
watchfree~1 hr
Learn network threats — DDoS, virus, worm, trojan, man-in-the-middle attacks — Obj 4.2
watchimportant~1 hr
Study IDS vs IPS — what they detect, how they prevent attacks — Obj 4.2
watchfree~45 min
Learn network design concepts — DMZ, VLAN, VPN, network segmentation, defense in depth — Obj 4.3
watchimportant~1 hr
Understand Cloud basics for security — SaaS, IaaS, PaaS, MSP, SLA — Obj 4.3
watchfree~45 min
Learn encryption types — symmetric vs asymmetric vs hashing — and when each is used — Obj 5.1
watchimportant~1 hr
Understand data handling — classification, labeling, retention, destruction — Obj 5.1
watchfree~30 min
Learn system hardening — baselines, patch management, configuration management — Obj 5.2
watchfree~30 min
Study security policies — AUP, Password Policy, BYOD, Change Management, Privacy Policy — Obj 5.3
readimportant~45 min
Understand security awareness training — social engineering, password protection, why training matters — Obj 5.4
watchfree~30 min
Do ISC2’s official CC practice questions on their website — free with your account
practicefree~3 hrs
Search YouTube for “ISC2 CC practice exam” — Thor Teaches and Inside Cloud and Security have great free videos
watchfree~4 hrs
Score 75%+ consistently on practice questions — exam passing score is 700/1000
milestone
🎉 Book and pass your ISC2 CC exam at Pearson VUE — available online proctored from Pakistan!
final goalfree voucher
P1
Phase 1 — Foundation & Networking Basics
Weeks 1–3 · ~1–2 hrs/day · No prior IT knowledge needed
0%
Watch: “How the Internet Works” — NetworkChuck YouTube (free playlist)
watchfree~2 hrs
Learn what IP addresses, DNS, and ports are — watch Professor Messer’s “Networking Basics” videos
watchfree~3 hrs
Understand TCP vs UDP — why both exist and when each is used
watchfree~1 hr
Learn about firewalls and routers — what they actually do
watchfree~1 hr
Get comfortable with Windows: file system, task manager, user accounts, Event Viewer
practice~2 hrs
Learn basic Linux commands (ls, cd, pwd, cat, grep) — use TryHackMe “Linux Fundamentals” free room
practicefree~4 hrs
Complete TryHackMe “Pre-Security” learning path (free)
practicefreeimportant~40 hrs
Can you explain to someone: what happens when you type google.com in a browser? If yes, move to Phase 2!
checkpoint
P2
Phase 2 — Core Security Concepts
Weeks 4–7 · ~1.5 hrs/day · Follow SY0-701 Objectives PDF
0%
Watch Professor Messer: Security Controls (Technical, Managerial, Operational, Physical) — Obj 1.1
watchfree~45 min
Learn CIA Triad (Confidentiality, Integrity, Availability) — understand with real-life examples
watchimportant~30 min
Study AAA (Authentication, Authorization, Accounting) and Zero Trust model — Obj 1.2
watchfree~1 hr
Learn Cryptography basics: symmetric vs asymmetric, hashing, PKI, certificates — Obj 1.4
watchimportant~3 hrs
Learn all threat actor types (nation-state, insider, hacktivist, etc.) and their motivations — Obj 2.1
watchfree~1 hr
Study all social engineering attacks: phishing, vishing, smishing, pretexting — Obj 2.2
watchimportant~1.5 hrs
Learn malware types: ransomware, trojan, worm, rootkit, keylogger, spyware — Obj 2.4
watchimportant~2 hrs
Study vulnerability types: SQLi, XSS, buffer overflow, zero-day — Obj 2.3
watchfree~2 hrs
Complete TryHackMe “Jr Penetration Tester” intro rooms (free tier)
practicefree~5 hrs
Take a free practice quiz on Domains 1 & 2 — aim for 60%+ before moving on
checkpoint
P3
Phase 3 — Architecture & Operations
Weeks 8–12 · ~2 hrs/day · Heaviest domain (28%)
0%
Learn cloud concepts: IaaS, PaaS, SaaS, shared responsibility model — Obj 3.1
watchfree~2 hrs
Understand network segmentation, VPNs, firewalls, IDS/IPS placement — Obj 3.2
watchimportant~2 hrs
Study data protection methods: encryption at rest/transit/use, tokenization, masking — Obj 3.3
watchfree~1.5 hrs
Learn resilience concepts: backups, RTO/RPO, hot/cold/warm sites, high availability — Obj 3.4
watchimportant~1.5 hrs
Study hardening techniques for mobile, workstations, servers, IoT — Obj 4.1
watchimportant~2 hrs
Learn vulnerability management lifecycle: scan → analyze → patch → verify — Obj 4.3
watchimportant~2 hrs
Study SIEM, DLP, EDR/XDR, monitoring tools — Obj 4.4
watchfree~2 hrs
Learn Identity & Access Management: MFA, SSO, LDAP, SAML, OAuth, PAM — Obj 4.6
watchimportant~3 hrs
Study incident response process: Preparation→Detection→Analysis→Containment→Eradication→Recovery — Obj 4.8
watchimportant~2 hrs
Practice on TryHackMe “SOC Level 1” path — hands-on SIEM and log analysis
practicefree~15 hrs
Practice quiz on Domains 3 & 4 — aim for 65%+ score before continuing
checkpoint
P4
Phase 4 — Governance, Risk & Compliance
Weeks 13–15 · ~1.5 hrs/day · Domain 5 (20%)
0%
Learn security governance: policies, standards, procedures, guidelines — Obj 5.1
watchfree~1.5 hrs
Study risk management: SLE, ALE, ARO, risk appetite, risk register — Obj 5.2
watchimportant~2 hrs
Learn third-party risk: vendor assessments, SLAs, NDAs, due diligence — Obj 5.3
watchfree~1 hr
Understand compliance frameworks: GDPR, PCI-DSS, privacy laws — Obj 5.4
watchfree~1.5 hrs
Study penetration testing types: black/white/grey box, passive vs active recon — Obj 5.5
watchfree~1 hr
Learn security awareness training concepts: phishing campaigns, insider threats — Obj 5.6
watchfree~45 min
Memorize the full acronym list from the objectives PDF (AAA, SIEM, EDR, PKI etc.)
readimportant~2 hrs
Practice quiz on Domain 5 — aim for 65%+ before moving to review phase
checkpoint
P5
Phase 5 — Review, Practice & Exam Ready
Weeks 16–20 · ~2 hrs/day · Polish & solidify everything
0%
Re-watch all Professor Messer videos for topics you found confusing — make notes
watchfree~10 hrs
Do Jason Dion’s Practice Exam set on Udemy (buy when on sale ~$10-15)
practiceimportant~6 hrs
Use Professor Messer’s free practice questions on his website daily
practicefreedaily
Use ExamCompass.com for free Security+ practice questions
practicefree~4 hrs
Complete at least 5 TryHackMe rooms in areas you feel weakest
practicefree~10 hrs
Set up a free home lab: install VirtualBox + Kali Linux + a vulnerable VM (no cost)
practicefree~5 hrs
Score 80%+ consistently on full practice exams before considering the real exam
milestone
Apply for Google Cybersecurity Certificate on Coursera with financial aid (free!)
free w/ aidparallel
Create LinkedIn profile highlighting your learning journey and TryHackMe badges
career
🎉 Book your Security+ exam at Pearson VUE (online proctored from Pakistan!)
final goal

// Saira’s Daily Routine Suggestion

Mon/Wed/Fri: Watch ISC2 CC training + Professor Messer videos following the objectives PDF — 1 objective at a time.

Tue/Thu: Practice questions, Blue Team Labs Online, or Cisco NetAcad hands-on labs.

Weekend: Review your notes, do practice quiz questions, re-read anything confusing.

Remember: Even 1 hour/day consistently beats 5 hours once a week. You’re doing this from a nutrition background — that’s actually a strength because you already know how to study complex material systematically!

🏅
Certificate Tracker — Your LinkedIn Wall
Click a certificate to mark it earned · Ordered by priority
0 earned

⚡ Priority Action — Do This Today!

The ISC2 CC free exam offer includes free training AND a free exam voucher. Go to isc2.org right now and register before this offer changes. It is a real proctored certification from the world’s top cybersecurity organization — completely free for you.

// Level 1 — Beginner · Start Here
🏆
Certified in Cybersecurity (CC)
ISC2 · isc2.org
BeginnerFREE + Free ExamTop Priority
✓ Earned — Add to LinkedIn!
🌐
Google Cybersecurity Certificate
Google / Coursera · coursera.org
BeginnerFree w/ Financial AidTop Priority
✓ Earned — Add to LinkedIn!
🔗
Networking Basics
Cisco NetAcad · netacad.com
BeginnerFREE
✓ Earned — Add to LinkedIn!
🛡️
Network Defense Essentials (NDE)
Cisco NetAcad · netacad.com
BeginnerFREE
✓ Earned — Add to LinkedIn!
⚔️
Cyber Aces — OS, Networking & Security
SANS Institute · cyberaces.org
BeginnerFREE
✓ Earned — Add to LinkedIn!
💻
IBM Cybersecurity Analyst Certificate
IBM / Coursera · coursera.org
BeginnerFree w/ Financial Aid
✓ Earned — Add to LinkedIn!
// Level 2 — Practical Skills · After Basics
📊
Splunk Fundamentals 1
Splunk · education.splunk.com
IntermediateFREESOC Essential
✓ Earned — Add to LinkedIn!
🔒
Network Defense Essentials (NDE)
EC-Council · codered.eccouncil.org
IntermediateFREE
✓ Earned — Add to LinkedIn!
🕵️
Ethical Hacking Essentials (EHE)
EC-Council · codered.eccouncil.org
IntermediateFREE
✓ Earned — Add to LinkedIn!
🔍
Digital Forensics Essentials (DFE)
EC-Council · codered.eccouncil.org
IntermediateFREE
✓ Earned — Add to LinkedIn!
🔎
Vulnerability Management
Qualys · qualys.com/training
IntermediateFREE
✓ Earned — Add to LinkedIn!
🌿
DigiSkills Courses
DigiSkills Pakistan · digiskills.pk
BeginnerFREELocal Recognition
✓ Earned — Add to LinkedIn!
// Level 3 — Vendor Certifications · Boosts LinkedIn
🔥
Fortinet NSE 1 — Information Security Awareness
Fortinet · training.fortinet.com
BeginnerFREE
✓ Earned — Add to LinkedIn!
🔥
Fortinet NSE 2 — The Evolution of Cybersecurity
Fortinet · training.fortinet.com
BeginnerFREE
✓ Earned — Add to LinkedIn!
🔥
Fortinet NSE 3 — Fortinet Portfolio
Fortinet · training.fortinet.com
IntermediateFREE
✓ Earned — Add to LinkedIn!
🦅
Palo Alto Cybersecurity Fundamentals
Palo Alto Networks · beacon.paloaltonetworks.com
BeginnerFREE
✓ Earned — Add to LinkedIn!
☁️
Microsoft SC-900 Security Fundamentals
Microsoft · learn.microsoft.com
Intermediate~$65 or Free Voucher
✓ Earned — Add to LinkedIn!
CompTIA Security+ SY0-701
CompTIA · comptia.org
Intermediate~$392 ExamUltimate Goal
✓ Earned — Congratulations! 🎉