Skip to main content

Your learning journey

The career-changer track is self-paced, takes roughly 80-120 hours, and runs across 14 modules (M0-M13). Everything is mapped to the CompTIA Security+ (SY0-701) exam domains, the ASD Cyber Skills Framework, and what Australian employers actually ask of entry-level candidates.

As you go, every module ends with an interactive self-check (a short scored quiz plus flashcards that come back on a spaced schedule) and your progress is tracked privately on your own device (see your progress page).

The journey at a glance

  • Foundations (M0-M3): work out if cyber is for you, then build the computing, networking and command-line base everything else stands on.
  • Core security (M4-M7): security fundamentals, the Australian frameworks employers expect you to know, identity, and how real attacks actually start.
  • Applied & defensive (M8-M11): life in a SOC, web application security, governance and risk, and cloud, the day-to-day of entry-level roles.
  • Capstone & career (M12-M13): build a portfolio that proves your skills, then turn it into applications, interviews and a job.

Module map

ModuleWhat you'll coverHands-on practice
M0: Orientation: Is cyber for you?Real roles, real salaries, realistic pathways, decide with evidenceNone
M1: Computing & digital foundationsHow computers, operating systems and files actually workBuild a free virtual machine (optional stretch)
M2: Networking fundamentalsTCP/IP, DNS, ports: how data moves between computersFree video course + packet basics
M3: Operating systems & the command lineWindows and Linux essentials every analyst needsPractise Linux in your browser (TryHackMe, OverTheWire Bandit)
M4: Security fundamentalsThe CIA triad, threat types, and crypto basicsNone
M5: The Australian cyber contextEssential Eight, the ISM, the Privacy Act: what local employers expectRun an Essential Eight self-assessment
M6: Identity & access managementAuthentication, MFA, Active Directory and Entra IDNone
M7: Threats & social engineeringHow attacks really start: phishing, scams, manipulationAnalyse a phishing email step by step
M8: Defensive ops & the SOCAlerts, triage, SIEMs and the incident response lifecycleTryHackMe SOC Level 1 path (browser)
M9: Web & application securityThe OWASP Top 10: how web apps get broken and defendedPortSwigger Web Security Academy (browser); local Juice Shop (optional stretch)
M10: Governance, Risk & ComplianceRisk, frameworks, audit: the GRC analyst's toolkitBuild a mock risk register
M11: Cloud security fundamentalsThe shared responsibility model and cloud-native threatsFree-tier cloud walkthrough
M12: Capstone / CTFTurn your skills into portfolio evidencepicoGym challenges + professional write-ups; self-hosted CTF (optional stretch)
M13: Career launchRésumé, applications, interviews, Security+ exam strategyBuild your application pack

Most hands-on practice runs in your browser on free platforms that host the environment for you. Items marked (optional stretch) involve setting up software on your own computer, worth doing, never required.

Security+ SY0-701 alignment

The course covers all five Security+ SY0-701 exam domains. Each module names the domain it maps to at the top of the page, so you can study for the exam alongside the course.

Where this content comes from

We write our own explanations, adapt only openly licensed material (always with attribution), and link you to the best free resources rather than copying them. Credits for the material we adapt are on the attributions page.


Ready to start? Begin with Module 0: Orientation, it's designed to help you decide if this path is for you.