
Bob Salmans
Cybersecurity & Governance, Risk, and Compliance (GRC)
Where teams start
Core security paths for SOC analysts, penetration testers, cloud security engineers, and governance teams.
PEN-100: Network Penetration Testing Essentials is foundational OffSec training for aspiring ethical hackers. Learn Linux and Windows command line, network protocols, scripting with Bash and Python, and explore essential security tools like Nmap, Kali Linux, and Metasploit. Build a strong ethical hacking mindset with hands-on practice in reconnaissance, exploitation, and post-exploitation techniques. Perfect for beginners looking to start a cybersecurity career.
Erik Choron
This Governance, Risk and Compliance training covers how to manage your organization's compliance-related requirements and balance them with operational risks to provide cost-efficient and in-compliance results. For systems administrators and security professionals, compliance is much more than ensuring that the right people are getting the right data — this training shows you how to prove your work, verify data integrity, and more.
Bob Salmans
This CCNA Cybersecurity training prepares you for the Understanding Cisco Cybersecurity Operations Fundamentals (200-201 CCNACBR) v1.2 exam (formerly called Cisco CyberOps). With virtual labs and unlimited practice exams included, you’ll gain experience with SIEM, NetFlow, tcpdump, malware analysis, access control models, and incident response workflows based on NIST.SP800‑61. You'll also learn how to detect network, application, and endpoint threats, investigate attacks like DDoS or man‑in‑the‑middle, and apply defense‑in‑depth. This course is deal for entry‑level security analysts or engineers ready to earn their CCNA Cybersecurity certification and launch an SOC career.
Keith Barker, Bob Salmans, John Munjoma, Kelvin Tran
This CCNP Security training is designed to help you get comfortable with the 300-710 SNCF exam objectives, and earn your CCNP Security certification. Taught by networking expert Keith Barker and cybersecurity professional Bob Salmans, this course focuses on securing networks with Cisco Firewalls, including Firepower Threat Defense and Management Center. This training is ideal for Network Security Engineers and System Administrators seeking rigorous 300-710 SNCF exam prep, as well as IT managers looking for a streamlined onboarding tool or a high-level Cisco training resource for their technical teams.
Keith Barker, Bob Salmans
This Microsoft SC-900 training prepares you to earn your Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) certification. You'll learn the fundamentals of security, compliance, and identity (SCI) within the Microsoft services ecosystem. You'll also explore how to use Microsoft Azure, Microsoft 365, and Microsoft Entra to create a secure cloud environment. This Microsoft SC-900 training is perfect for IT newcomers, students, end users, and enterprise training programs.
John Munjoma, James Conrad, Bob Salmans
This ISACA CRISC training is designed to help you earn your Certified in Risk and Information Systems Control credential. This course helps you learn to identify IT risks, build threat models, and align technology with business goals. Once you've completed this course, you'll know how to design effective control frameworks, manage vendor risk, and handle data lifecycles from start to finish. You'll also gain the skills to analyze risk appetite, report metrics through heatmaps and dashboards, and lead disaster recovery efforts.
Bob Salmans
Capability ladder
The most popular Cybersecurity courses at each certification level — from first credentials for new team members through expert and specialty tracks.
Certification tier
Core role credentials — the level most teams standardize on for day-to-day operations.
This CCNA Cybersecurity training prepares you for the Understanding Cisco Cybersecurity Operations Fundamentals (200-201 CCNACBR) v1.2 exam (formerly called Cisco CyberOps). With virtual labs and unlimited practice exams included, you’ll gain experience with SIEM, NetFlow, tcpdump, malware analysis, access control models, and incident response workflows based on NIST.SP800‑61. You'll also learn how to detect network, application, and endpoint threats, investigate attacks like DDoS or man‑in‑the‑middle, and apply defense‑in‑depth. This course is deal for entry‑level security analysts or engineers ready to earn their CCNA Cybersecurity certification and launch an SOC career.
Keith Barker, Bob Salmans, John Munjoma, Kelvin Tran
This Microsoft Identity and Access Administrator (SC-300) training prepares you to become a Microsoft identity and access admin. Expert-led training will teach you to implement and manage secure identity solutions using Microsoft Entra ID (Azure AD) and hybrid identities. You’ll set up and manage users, groups, devices, and custom roles. You’ll learn to configure passwordless and multifactor sign-in, apply conditional access policies, and use tools like PIM to support a zero-trust strategy. You’ll also manage app access with registrations, service principals, and entitlement controls. Bring on-prem and cloud together using Azure AD Connect and Active Directory Federation Services, and monitor and protect identities using Defender for Cloud Apps, Sentinel, Identity Protection and Identity Secure Score. With practice exams and real‑world scenarios, this course maps to the SC‑300 exam blueprint, giving you the skills and confidence to get certified and secure access to your organization’s cloud resources.
Bob Salmans
Advance your cybersecurity analyst career. This Microsoft SC-200 training prepares you for the Security Operations Analyst Associate certification exam. Validate your ability to detect, investigate, and remediate real threats across cloud and on-prem environments. Using SC-200 practice exams, you’ll prepare for real-world incident response, threat hunting, and risk reduction using Microsoft Defender XDR, Microsoft Sentinel, and Security Copilot. You’ll learn to write KQL queries, configure detections, manage playbooks, and automate investigations so you can move from alert triage to confident remediation.
Bob Salmans
Certification tier
Advanced credentials for the engineers who own design, escalation, and complex environments.
This CCNP Security training is designed to help you get comfortable with the 300-710 SNCF exam objectives, and earn your CCNP Security certification. Taught by networking expert Keith Barker and cybersecurity professional Bob Salmans, this course focuses on securing networks with Cisco Firewalls, including Firepower Threat Defense and Management Center. This training is ideal for Network Security Engineers and System Administrators seeking rigorous 300-710 SNCF exam prep, as well as IT managers looking for a streamlined onboarding tool or a high-level Cisco training resource for their technical teams.
Keith Barker, Bob Salmans
This Microsoft SC-900 training prepares you to earn your Microsoft Certified: Security, Compliance, and Identity Fundamentals (SC-900) certification. You'll learn the fundamentals of security, compliance, and identity (SCI) within the Microsoft services ecosystem. You'll also explore how to use Microsoft Azure, Microsoft 365, and Microsoft Entra to create a secure cloud environment. This Microsoft SC-900 training is perfect for IT newcomers, students, end users, and enterprise training programs.
John Munjoma, James Conrad, Bob Salmans
This ISACA CRISC training is designed to help you earn your Certified in Risk and Information Systems Control credential. This course helps you learn to identify IT risks, build threat models, and align technology with business goals. Once you've completed this course, you'll know how to design effective control frameworks, manage vendor risk, and handle data lifecycles from start to finish. You'll also gain the skills to analyze risk appetite, report metrics through heatmaps and dashboards, and lead disaster recovery efforts.
Bob Salmans
This intermediate-level CySA+ course prepares cybersecurity professionals to pass the CompTIA Cybersecurity Analyst (CySA+) CS0-003 exam. Learn how to proactively monitor systems, detect threats, and respond to incidents with confidence. This hands-on training dives into real-world tools and techniques used in vulnerability management, threat intelligence, and security operations. You’ll practice using SIEM tools, analyzing indicators of compromise (IoCs), performing risk assessments, and strengthening cloud and hybrid environments. Ideal for SOC analysts, security engineers, and IT pros looking to advance their careers, this course aligns with the official CompTIA exam blueprint and industry best practices.
Erik Choron
This CISA online training prepares you for the Certified Information Systems Auditor certification. The course follows ISACA’s exam blueprint: you’ll learn audit standards and risk‑based planning, manage IT governance and strategy, guide systems through acquisition, development and implementation, oversee operations and business resilience, and protect information assets. Build hands‑on skills in evidence collection, analytics and reporting through engaging videos, practice exams, and real‑world scenarios, all while preparing for the CISA exam.
Bob Salmans
Get ready to earn your ISC2 CISSP certification. This course covers all eight CISSP domains in clear, easy-to-follow lessons. Learn governance frameworks, secure design principles, and incident response while sharpening risk analysis, policy writing, and business continuity planning. Along the way, you’ll access unlimited CISSP practice exams and our downloadable CISSP study guide PDF to stay organized and on track. Whether you prefer a structured CISSP bootcamp-style, or flexible self-paced learning, this training helps you prepare smarter, stay focused, and get certified with confidence.
Bob Salmans
Certification tier
Expert tracks and specialty credentials for architects and niche platform owners.
This Microsoft Certified: Cybersecurity Architect Expert (SC-100) training covers how to design a large network's protective security architecture, grounded in the Zero Trust strategy. You'll master the Microsoft Cybersecurity Reference Architecture (MCRA) and Zero Trust principles to design resilient security strategies for SaaS, PaaS, and IaaS environments. As you learn to translate complex requirements into technical safeguards (from Entra Global Secure Access to advanced identity and data protection) you'll gain the high-level skills necessary to secure enterprise infrastructures and pass the SC-100 exam.
Bob Salmans
Fresh from the studio
The latest Cybersecurity training added to the catalog — new courses land here within a day of publication.
Vendor coverage
The vendors behind the cybersecurity catalog — each vendor page maps its full certification landscape.

Hands-on Cybersecurity practice
Human-led training is the point: engineers practice real skills with expert guidance, not just video playback.
Why CBT Nuggets
The platform features IT directors comparing training platforms ask about most often.
Full catalog
Everything else in the Cybersecurity catalog beyond the curated sections above.
Practitioner-led
Built and taught by engineers who have spent decades running production Cybersecurity infrastructure — not crowd-sourced contributors.

Cybersecurity & Governance, Risk, and Compliance (GRC)

Offensive Security & Security Operations

Networking & Network Security
Team outcome
Manager reporting gives IT leaders a clearer view of assigned training, completion progress, and certification coverage.
Best fit for: compliance-sensitive teams that need evidence of progress before a review, renewal, or internal governance checkpoint.
Common questions IT directors ask when evaluating Cybersecurity training for their team.
Start with threats, attacks, vulnerabilities, cryptography, and secure design for shared vocabulary, then split into SOC, cloud security, GRC, or penetration testing by role.
Yes. It includes penetration testing foundations, tools, planning, scanning, Kali, PEN-100, PEN-103, and PEN-200 paths.
Assign SOC/incident response to analysts, pentesting to red-team roles, cloud security to cloud engineers, and GRC/CMMC paths to governance and compliance teams.
Track role coverage for incident response, vulnerability testing, cloud hardening, compliance evidence, and risk ownership.
Yes. Managers can assign paths by security role, track completion, and document readiness for audits and operations.