⏳
Loading cheatsheet...
Career-focused certification planning guide with framework for selecting the right cert path.
| Domain | Weight | Key Topics |
|---|---|---|
| People | 42% | Team management, leadership styles, conflict resolution, stakeholder engagement, communication, emotional intelligence, servant leadership, power & influence |
| Process | 50% | Predictive (Waterfall) vs Adaptive (Agile), hybrid approaches, planning, scope/schedule/cost management, risk management, quality, change management, procurement |
| Business Environment | 8% | Compliance, organizational structure, benefits realization, business value, governance, external factors |
Q1: A project manager discovers a stakeholder is unhappy with a
deliverable. What is the BEST approach?
A) Ignore it — the deliverable meets specifications
B) Meet with the stakeholder to understand concerns, then assess impact
C) Escalate to the project sponsor immediately
D) Replan the entire project to accommodate the stakeholder
→ Answer: B (Engage stakeholder first, then assess)
Q2: Your team is using an Agile approach and a user story is taking
longer than estimated. What should you do FIRST?
A) Add more developers to the story
B) Discuss in daily standup, consider splitting the story
C) Extend the sprint to accommodate
D) Escalate to the product owner
→ Answer: B (Collaborate with team, break down work)
Q3: Which process group involves formally authorizing a project?
A) Planning B) Executing C) Initiating D) Monitoring
→ Answer: C (Initiating — develop project charter)
Q4: A project has a CPI of 0.85 and SPI of 1.1. What does this mean?
A) Over budget, ahead of schedule
B) Under budget, behind schedule
C) Over budget, behind schedule
D) Under budget, ahead of schedule
→ Answer: A (CPI < 1 = over budget, SPI > 1 = ahead of schedule)| Formula | Meaning | Example |
|---|---|---|
| PV = Planned Value | Budgeted cost of work scheduled | If $100K planned by now, PV = $100K |
| EV = Earned Value | Budgeted cost of work actually completed | If 80% done, EV = $80K |
| AC = Actual Cost | Actual money spent | If spent $90K, AC = $90K |
| CPI = EV / AC | Cost Performance Index (< 1 = over budget) | CPI = 80/90 = 0.89 (over budget) |
| SPI = EV / PV | Schedule Performance Index (< 1 = behind) | SPI = 80/100 = 0.80 (behind) |
| CV = EV - AC | Cost Variance (< 0 = over budget) | CV = 80-90 = -$10K |
| SV = EV - PV | Schedule Variance (< 0 = behind) | SV = 80-100 = -$20K |
| EAC = BAC / CPI | Estimate At Completion (if CPI stays same) | EAC = 100K / 0.89 = $112.4K |
| ETC = EAC - AC | Estimate To Complete | ETC = 112.4K - 90K = $22.4K |
| TCPI = (BAC-EV) / (BAC-AC) | To-Complete Performance Index | Efficiency needed to finish on budget |
| PERT: Expected = (O+4M+P)/6 | Weighted average estimate | (O=10, M=20, P=40) → (10+80+40)/6 = 21.67 |
| Process Group | Knowledge Areas (Selected) |
|---|---|
| Initiating | Integration (charter), Stakeholder (register) |
| Planning | Scope (WBS), Schedule (CPM), Cost (estimate), Quality, Resource, Risk, Procurement |
| Executing | Quality (manage), Resource (develop team), Communications, Risk (responses), Procurement |
| Monitoring & Controlling | All knowledge areas — validate, monitor, control changes |
| Closing | Integration (close project/phase), Procurement (close contracts) |
| Certification | Provider | Cost | Duration | Validity |
|---|---|---|---|---|
| PSM I (Professional Scrum Master I) | Scrum.org | $150 | 60 min, 80 Qs | Lifetime |
| PSM II (Advanced) | Scrum.org | $250 | 90 min, 30 Qs (hard) | Lifetime |
| PSM III (Expert) | Scrum.org | $500 | 150 min, 24 Qs (essay) | Lifetime |
| CSM (Certified ScrumMaster) | Scrum Alliance | $400-1000 (course + exam) | 60 min, 50 Qs | 2 years |
| A-CSM (Advanced) | Scrum Alliance | $400-500 (course) | N/A | 2 years |
| SAFe Scrum Master (SSM) | Scaled Agile | $995 (course) | 90 min, 45 Qs | 1 year |
| Topic | Weight | Key Concepts |
|---|---|---|
| Scrum Theory | ~10% | Empiricism (inspect-adapt), Lean thinking, values (commitment, focus, openness, respect, courage) |
| Scrum Events | ~25% | Sprint, Sprint Planning, Daily Scrum, Sprint Review, Sprint Retrospective, timeboxes |
| Scrum Artifacts | ~20% | Product Backlog, Sprint Backlog, Increment, Definition of Done, commitment to each artifact |
| Scrum Roles | ~20% | Scrum Master (servant leader, impediment remover), Product Owner (value maximization), Developers (self-managing) |
| Sprint Execution | ~15% | Daily Scrum format, tracking progress, Sprint Goal, Done vs Done-Done |
| Scrum Master Accountability | ~10% | Coaching, facilitation, removing impediments, organizational change |
╔═════════════════════════════════════════════════════════════════╗
║ SCRUM GUIDE 2020 — QUICK REFERENCE ║
╠═════════════════════════════════════════════════════════════════╣
║ ║
║ THREE ACCOUNTABILITIES (formerly "roles"): ║
║ ┌─────────────┬─────────────────────────────────────────────┐ ║
║ │ Scrum Master│ Servant leader, coaches team, removes │ ║
║ │ │ impediments, promotes Scrum values │ ║
║ ├─────────────┼─────────────────────────────────────────────┤ ║
║ │ Product │ Maximizes value of product, manages │ ║
║ │ Owner │ Product Backlog, makes decisions │ ║
║ ├─────────────┼─────────────────────────────────────────────┤ ║
║ │ Developers │ Self-managing, creates Increment, │ ║
║ │ │ cross-functional, no sub-teams │ ║
║ └─────────────┴─────────────────────────────────────────────┘ ║
║ ║
║ FIVE EVENTS (timeboxed): ║
║ Sprint (1-4 weeks) → Sprint Planning → Daily Scrum (15 min) ║
║ → Sprint Review → Sprint Retrospective ║
║ ║
║ THREE ARTIFACTS (with commitments): ║
║ Product Backlog (commitment: Product Goal) ║
║ Sprint Backlog (commitment: Sprint Goal) ║
║ Increment (commitment: Definition of Done) ║
║ ║
║ SCRUM VALUES: Commitment, Focus, Openness, Respect, Courage ║
╚═════════════════════════════════════════════════════════════════╝| Domain | Weight | Key Topics |
|---|---|---|
| Mobile Devices | 15% | Laptop hardware, displays, connectors, mobile OS (iOS/Android), synchronization, mobile accessories |
| Networking | 20% | OSI model, TCP/IP, WiFi standards (802.11a/b/g/n/ac/ax), Ethernet, IPv4/IPv6, DNS, DHCP, VPN, firewalls |
| Hardware | 25% | Motherboards, CPU, RAM, storage (HDD/SSD/NVMe), power supplies, cooling, peripherals, troubleshooting POST |
| Virtualization & Cloud | 11% | Hypervisors (Type 1/2), VM configuration, cloud concepts (IaaS/PaaS/SaaS), container basics |
| Hardware & Network Troubleshooting | 29% | Diagnostic tools, common symptoms, troubleshooting methodology, safety procedures, environmental factors |
| Domain | Weight | Key Topics |
|---|---|---|
| Operating Systems | 31% | Windows 10/11, macOS, Linux, boot process, command line tools, system utilities, user management |
| Security | 25% | Authentication, encryption, malware, physical security, wireless security, best practices, incident response |
| Software Troubleshooting | 22% | OS troubleshooting, application issues, security troubleshooting, common errors |
| Operational Procedures | 22% | Documentation, change management, disaster recovery, safety, compliance, remote support |
# ── Windows CMD / PowerShell ──
ipconfig /all # Network configuration
ping google.com # Test connectivity
tracert google.com # Trace route
netstat -ano # Active connections + PIDs
tasklist # Running processes
systeminfo # System information
sfc /scannow # System file checker
dism /online /cleanup-image /restorehealth # Repair Windows image
# ── Linux ──
lsblk # List block devices
fdisk -l # Partition info
top / htop # Process monitor
df -h # Disk usage
free -h # Memory usage
systemctl status sshd # Service status
journalctl -u sshd -f # Follow service logs| Domain | Weight | Key Topics |
|---|---|---|
| General Security Concepts | 12% | CIA triad, security controls (preventive/detective/corrective), security frameworks (NIST, ISO 27001), risk management |
| Threats, Vulnerabilities & Mitigations | 22% | Attack types (phishing, MITM, DDoS, XSS, SQLi, ransomware), threat actors, vulnerability assessment, penetration testing |
| Security Architecture | 18% | Enterprise security architecture, zero trust, defense in depth, cloud security, IAM, physical security |
| Security Operations | 28% | Incident response (NIST 800-61), SIEM, log management, BCDR, monitoring, automation, forensics basics |
| Security Program Management | 20% | Risk management process, BIA, policies/standards/procedures, compliance (GDPR, HIPAA, PCI-DSS), governance, security awareness training |
Q1: Which type of control is a firewall classified as?
A) Detective B) Preventive C) Corrective D) Compensating
→ Answer: B (Firewall prevents unauthorized traffic — preventive)
Q2: An employee clicks a link in a phishing email and enters
credentials on a fake login page. What type of attack?
A) Spear phishing B) Whaling C) Credential harvesting
D) Pharming
→ Answer: C (Credential harvesting via phishing page)
Q3: Which security framework provides a risk management methodology
for federal information systems?
A) ISO 27001 B) NIST RMF (SP 800-37) C) COBIT D) ITIL
→ Answer: B (NIST Risk Management Framework)
Q4: What is the BEST way to protect data at rest?
A) TLS/SSL B) VPN C) Full disk encryption D) Firewall
→ Answer: C (Encryption at rest = full disk encryption like BitLocker/LUKS)| Phase | Actions |
|---|---|
| 1. Preparation | Policies, tools, training, incident response team, playbooks |
| 2. Detection & Analysis | SIEM alerts, log review, determine scope, severity classification |
| 3. Containment | Isolate affected systems, short-term + long-term containment strategies |
| 4. Eradication | Remove malware, patch vulnerabilities, remove compromised accounts |
| 5. Recovery | Restore systems, monitor for recurrence, validate fixes |
| 6. Post-Incident | Lessons learned, update procedures, improve detections, report |
| Acronym | Meaning |
|---|---|
| CIA | Confidentiality, Integrity, Availability |
| AAA | Authentication, Authorization, Accounting |
| MFA | Multi-Factor Authentication |
| PKI | Public Key Infrastructure |
| SIEM | Security Information & Event Management |
| SOAR | Security Orchestration, Automation & Response |
| XDR | Extended Detection & Response |
| ZTA | Zero Trust Architecture |
| BIA | Business Impact Analysis |
| RPO/RTO | Recovery Point / Recovery Time Objective |
| SSO | Single Sign-On |
| RBAC | Role-Based Access Control |
| Domain | Weight | Key Topics |
|---|---|---|
| Network Fundamentals | 20% | OSI & TCP/IP models, IPv4/IPv6 addressing, subnetting, VLANs, wireless basics, virtualization, network topologies |
| Network Access | 20% | VLANs, trunking (802.1Q), STP, EtherChannel, switch security (port security), wireless LAN (WLC, AP, SSID) |
| IP Connectivity | 25% | IPv4/IPv6 routing, static/dynamic routing, OSPFv2, routing tables, CEF, first hop redundancy (HSRP, VRRP) |
| IP Services | 10% | NAT, NTP, DHCP, DNS, SNMP, Syslog, NetFlow, SSH, device management, device hardening |
| Security Fundamentals | 15% | Port security, ACLs, VPN basics, wireless security (WPA2/3), 802.1X, port security, device access control |
| Automation & Programmability | 10% | Network automation, SDN, REST APIs, JSON, Puppet/Chef/Ansible basics, device configuration using APIs |
# ── CCNA — Essential Cisco IOS Commands ──
# ── Basic Configuration ──
enable # Enter privileged EXEC mode
configure terminal # Enter global config
hostname Switch1 # Set hostname
enable secret mypass # Set encrypted enable password
username admin secret pass # Create local user
service password-encryption # Encrypt all passwords
# ── VLAN Configuration ──
vlan 10 # Create VLAN 10
name Marketing # Name the VLAN
interface range gig0/1-5 # Configure ports
switchport mode access # Set as access port
switchport access vlan 10 # Assign to VLAN 10
interface gig0/1
switchport mode trunk # Set as trunk port
switchport trunk allowed vlan 10,20,30
# ── Routing (OSPF) ──
router ospf 1 # Enable OSPF process 1
network 192.168.1.0 0.0.0.255 area 0 # Advertise network in area 0
network 10.0.0.0 0.0.0.3 area 0 # Advertise point-to-point link
# Static route
ip route 0.0.0.0 0.0.0.0 192.168.1.1 # Default route
# ── Access Control Lists ──
access-list 10 deny 192.168.2.0 0.0.0.255 # Deny subnet
access-list 10 permit any # Permit everything else
interface gig0/1
ip access-group 10 in # Apply ACL inbound
# ── NAT ──
access-list 1 permit 192.168.1.0 0.0.0.255
ip nat inside source list 1 interface gig0/0 overload # PAT
interface gig0/0
ip nat outside
interface gig0/1
ip nat inside
# ── Verification ──
show ip interface brief # Interface status
show running-config # Current config
show ip route # Routing table
show vlan brief # VLAN summary
show ip ospf neighbor # OSPF neighbors
show access-lists # ACL summary╔═══════════════════════════════════════════════════════════════╗
║ CCNA SUBNETTING QUICK REFERENCE ║
╠═══════════════════════════════════════════════════════════════╣
║ CIDR Subnet Mask Hosts Subnets (Class C) ║
╠═══════════════════════════════════════════════════════════════╣
║ /24 255.255.255.0 254 1 subnet ║
║ /25 255.255.255.128 126 2 subnets ║
║ /26 255.255.255.192 62 4 subnets ║
║ /27 255.255.255.224 30 8 subnets ║
║ /28 255.255.255.240 14 16 subnets ║
║ /29 255.255.255.248 6 32 subnets ║
║ /30 255.255.255.252 2 64 subnets (point-to-pt)║
║ /32 255.255.255.255 1 Host route ║
╠═══════════════════════════════════════════════════════════════╣
║ Power of 2: 1 2 4 8 16 32 64 128 256 ║
║ Block sizes: 128 64 32 16 8 4 2 1 ║
╚═══════════════════════════════════════════════════════════════╝| Domain | Weight | Key Topics |
|---|---|---|
| Describe Cloud Concepts | 25-30% | Cloud vs on-prem, IaaS/PaaS/SaaS, public/private/hybrid cloud, shared responsibility model, consumption-based model, CAPEX vs OPEX |
| Describe Azure Architecture & Services | 35-40% | Azure regions, availability zones, resource groups, subscriptions, Azure Portal/CLI/PowerShell/ARM/Bicep, core services (VMs, App Service, AKS, Azure SQL, Storage) |
| Describe Azure Management & Governance | 30-35% | Cost management, Azure Advisor, Azure Policy, RBAC, Locks, Tags, Azure Monitor, Azure Service Health, SLA |
Q1: Which Azure service provides a managed Kubernetes environment?
A) Azure App Service B) Azure Kubernetes Service (AKS)
C) Azure Container Instances D) Azure Functions
→ Answer: B (AKS is managed Kubernetes; ACI is serverless containers)
Q2: What is the shared responsibility model in Azure IaaS?
A) Microsoft manages everything
B) Customer manages everything
C) Microsoft manages hardware/host; customer manages OS, data, apps
D) Microsoft manages security patches; customer manages data only
→ Answer: C (IaaS splits responsibility at the OS layer)
Q3: You need to estimate costs before deploying Azure resources.
Which tool should you use?
A) Azure Cost Management B) Azure Pricing Calculator
C) Azure Advisor D) Azure Monitor
→ Answer: B (Pricing Calculator for estimation before deployment)
Q4: Which Azure service provides a serverless compute option that
automatically scales and you pay only for execution time?
A) Azure VMs B) Azure Functions C) Azure Batch D) Azure SQL
→ Answer: B (Azure Functions = serverless, consumption-based pricing)| AWS | Azure | GCP |
|---|---|---|
| EC2 | Virtual Machines | Compute Engine |
| Lambda | Azure Functions | Cloud Functions |
| S3 | Blob Storage | Cloud Storage |
| RDS | Azure SQL / Cosmos DB | Cloud SQL / Spanner |
| VPC | Virtual Network (VNet) | VPC |
| CloudWatch | Azure Monitor | Cloud Monitoring |
| IAM | Azure RBAC / Entra ID | Cloud IAM |
| CloudFormation | ARM Templates / Bicep | Deployment Mgr / Terraform |
| Route 53 | Azure DNS | Cloud DNS |
| ALB | Application Gateway | HTTP(S) Load Balancer |
| EKS | AKS (Azure Kubernetes Service) | GKE |
| Elastic Beanstalk | App Service | App Engine |
# ── Azure CLI — Essential Commands ──
az login # Authenticate
az account list # List subscriptions
az account set --subscription "My Sub" # Set active subscription
# Create resource group
az group create --name myRG --location eastus
# Create VM
az vm create --resource-group myRG --name myVM --image Ubuntu2204 --admin-username azureuser --generate-ssh-keys
# Create Storage Account
az storage account create --name mystorageacct123 --resource-group myRG --location eastus --sku Standard_LRS
# Create App Service
az webapp create --resource-group myRG --plan myAppPlan --name my-web-app-123 --runtime "NODE:18-lts"
# List resources
az group list --output table
az vm list --resource-group myRG| Certification | Recommended Resources | Estimated Cost |
|---|---|---|
| PMP | PMI PMBOK Guide 7th Ed, Joseph Phillips (Udemy), PM PrepCast ($299), Pocket Prep app | $50-400 |
| PSM I | Scrum Guide 2020 (free), Scrum.org Open Assessment, Mikhail Lapshin (Udemy) | $0-15 |
| CompTIA A+ | Professor Messer (free videos), CompTIA CertMaster, Jason Dion (Udemy) | $0-300 |
| CompTIA Security+ | Professor Messer, Dion Training, TryHackMe rooms, Cybrary | $0-400 |
| CCNA | Jeremy's IT Lab (free), Wendell Odom OCG books, Packet Tracer, Boson Exams | $50-400 |
| AZ-900 | Microsoft Learn (free), John Savill YouTube, free Azure account | $0-99 |
| Career Path | Recommended Certifications | Timeline |
|---|---|---|
| IT Support / Helpdesk | CompTIA A+ → CompTIA Network+ → AZ-900 | 6-9 months |
| Cybersecurity Analyst | CompTIA Security+ → CCNA → CySA+ → CISSP | 12-18 months |
| Network Engineer | CCNA → CCNP ENCOR → AWS/Azure networking | 12-18 months |
| Cloud Engineer | AZ-900 → AZ-104 / AWS SAA → AZ-305 / AWS SAP | 12-18 months |
| Project Manager (IT) | CAPM → PMP → SAFe Agilist | 6-12 months |
| DevOps Engineer | LFCS → CKA → Terraform → AWS SAA/DOP | 12-18 months |
| Data Engineer | AZ-900 → AZ-204 → GCP PDE → AWS Data Specialty | 12-18 months |
╔═══════════════════════════════════════════════════════════════╗
║ PROFESSIONAL CERTIFICATION COST SUMMARY ║
╠═══════════════════════════════════════════════════════════════╣
║ ║
║ PROJECT MANAGEMENT: ║
║ PMP (PMI member) $405 ║
║ PMP (non-member) $555 ║
║ CAPM $300 ║
║ PSM I (Scrum.org) $150 ║
║ ║
║ IT FUNDAMENTALS: ║
║ CompTIA A+ (2 exams) $718 ║
║ CompTIA Network+ $359 ║
║ CompTIA Security+ $404 ║
║ ║
║ NETWORKING: ║
║ CCNA 200-301 $300 ║
║ CCNP (2 exams) $600 ║
║ ║
║ CLOUD: ║
║ AZ-900 (Azure Fundamentals) $99 ║
║ AZ-104 (Azure Admin) $165 ║
║ AWS Cloud Practitioner $150 ║
║ AWS SAA-C03 $150 ║
║ GCP Cloud Engineer $125 ║
║ ║
║ COMPLETE CAREER PATHS: ║
║ IT Support: A+ + Network+ + Security+ ≈ $1,481 ║
║ Cloud Engineer: AZ-900 + AZ-104 + SAA ≈ $480 ║
║ Network Eng: CCNA + CCNP ≈ $900 ║
║ PM: CAPM + PMP + PSM I ≈ $905 ║
╚═══════════════════════════════════════════════════════════════╝| Strategy | Details |
|---|---|
| Set a deadline | Book the exam date BEFORE you start studying. Accountability drives results. |
| Use spaced repetition | Review weak topics at increasing intervals (1 day, 3 days, 1 week, 2 weeks). |
| Take practice exams early | Take one practice exam at the START to identify gaps, not just at the end. |
| Active recall over passive reading | Flashcards, practice questions, and teaching others beat re-reading notes. |
| Study in 25-min blocks | Pomodoro technique: 25 min focus + 5 min break. Prevents burnout. |
| Join communities | Reddit (r/PMP, r/CompTIA, r/ccna), Discord, LinkedIn groups for tips and support. |
| Understand, don't memorize | All these exams test understanding and application, not rote memorization. |
| Rest before exam | Sleep 7-8 hours the night before. Brain performance drops 30%+ with sleep deprivation. |
| Cert | Top Tip |
|---|---|
| PMP | Study Agile AND predictive — exam is 50/50. Know Scrum artifacts and events cold. |
| PSM I | Read Scrum Guide 2020 at least 3 times. Take the free Open Assessment until you score 100%. |
| CompTIA A+ | Focus on Core 1 hardware/networking first. PBQs require hands-on practice — use virtual labs. |
| CompTIA Security+ | NIST frameworks and incident response are heavily weighted. Know your acronyms. |
| CCNA | Master subnetting, OSPF, VLANs, ACLs, and NAT. Practice on Packet Tracer or GNS3 daily. |
| AZ-900 | Easiest cert here. Complete Microsoft Learn paths (free) and you will pass in 2 weeks. |
| PMP EVM | Memorize the EVM formulas (CPI, SPI, EAC, ETC, VAC). They are guaranteed to appear. |
| CCNA | Lab, lab, lab. You cannot pass CCNA without hands-on practice with Cisco IOS commands. |
| Resource | Covers | Cost |
|---|---|---|
| Professor Messer (YouTube) | CompTIA A+, Network+, Security+ | Free |
| Microsoft Learn | AZ-900, AZ-104, all Azure certs | Free |
| Google Cloud Skills Boost | GCP ACE, PCE, PDE | Free tier / $29/mo |
| AWS Skill Builder | AWS CLF, SAA, DVA, SOA | Free tier / $29/mo |
| Jeremy's IT Lab (YouTube) | CCNA 200-301 | Free |
| Scrum.org Open Assessment | PSM I prep | Free |
| KodeKloud | CKA, CKAD, Docker, LFCS | Free tier / $15/mo |
| TryHackMe | Security+, CySA+, ethical hacking | Free tier |
| Cisco Networking Academy | CCNA, CCNP (student discount) | Free (academic) |
| Certification | Avg Salary (US) | Premium vs Uncertified |
|---|---|---|
| PMP | $115,000 | +$12,000-20,000 |
| CompTIA Security+ | $85,000 | +$8,000-15,000 |
| CCNA | $80,000 | +$8,000-12,000 |
| AZ-900 + AZ-104 | $95,000 | +$10,000-15,000 |
| AWS SAA-C03 | $125,000 | +$15,000-25,000 |
| CKA | $130,000 | +$15,000-20,000 |
| Terraform Associate | $120,000 | +$10,000-15,000 |
| CISSP | $140,000 | +$20,000-30,000 |