Google Cybersecurity Certificate: A Complete Beginner’s Guide to All 8 Courses
The Google Cybersecurity Certificate is one of the most popular ways to start a security career. This guide gives you one page to keep open while you study. It maps every course to free study notes, practice pages, labs, and videos.
First, you will see a course map. Next, you will find core concepts, cheat sheets, and a study plan. Finally, you can search a glossary and read answers to common questions. Bookmark this page, and return to it after each course.
Independent study aid. This page is not affiliated with or endorsed by Google or Coursera. Always confirm current course content on the official Google Cybersecurity Certificate page on Coursera.
How to use this Google Cybersecurity Certificate guide
The Google Cybersecurity Certificate has eight courses. Each course builds on the one before it. Therefore, you should study them in order.
Use this simple loop for every course:
- Read the course study notes on this site.
- Watch the course lessons on Coursera.
- Practice with the linked helper pages and labs.
- Finish the graded quizzes and activities.
- Test yourself with the practice questions.
Tip: You can also go the other way. Start with a helper page, then jump to the matching course on Coursera. Every course block below has links in both directions.
Google Cybersecurity Certificate course map
This table shows how each course connects to the study notes and helper pages on this site. Use it as your quick index.
| Course | Study notes | Best helper pages |
|---|---|---|
| 1. Foundations of Cybersecurity | Course 1 notes | Core concepts, Glossary |
| 2. Play It Safe: Manage Security Risks | Course 2 notes | Core concepts, Fundamentals |
| 3. Connect and Protect: Networks | Course 3 notes | Wireshark tutorial, Home lab |
| 4. Tools of the Trade: Linux and SQL | Course 4 notes | Linux guide, SQL guide |
| 5. Assets, Threats, and Vulnerabilities | Course 5 notes | Fundamentals, Core concepts |
| 6. Sound the Alarm: Detection and Response | Course 6 notes | SIEM practice, Wireshark |
| 7. Automate Tasks with Python | Course 7 notes | Python guide |
| 8. Put It to Work: Prepare for Jobs | Course 8 notes | Practice questions, Home lab |
Course 1: Foundations of Cybersecurity
Open Course 1 details
What you learn: what security is, what analysts do, and why the CIA triad matters. You also meet threat actors, the eight security domains, and your first tools.
- Security versus cybersecurity, and daily analyst tasks
- Social engineering, malware, and common attack types
- Ethics, laws, and data types such as PII, SPII, and PHI
- An intro to SIEM tools, playbooks, and packet sniffers
Study next: Course 1 study notes · Core concepts explained · Cybersecurity glossary
Watch: Foundations · CIA triad · Analyst day in the life
Course 2: Play It Safe: Manage Security Risks
Open Course 2 details
What you learn: how organizations manage risk. You study the eight CISSP domains in depth, plus frameworks, controls, and security audits.
- Risk steps: identify, assess, mitigate, and monitor
- NIST CSF, NIST RMF, CIS Controls, and ISO 27001
- Least privilege, defense in depth, and threat modeling with STRIDE and PASTA
Study next: Course 2 study notes · CIA triad, CISSP, NIST and OWASP · Fundamentals explained
Watch: NIST CSF · Risk management · STRIDE
Course 3: Connect and Protect: Networks and Network Security
Open Course 3 details
What you learn: how networks work and how attackers abuse them. You also learn how to harden systems.
- TCP/IP, the OSI model, ports, DNS, DHCP, and ARP
- DoS, DDoS, spoofing, and on-path attacks
- Firewalls, VPNs, proxies, IDS/IPS, and network segmentation
Study next: Course 3 study notes · Wireshark tutorial · Home lab setup
Watch: OSI model · TCP/IP · Firewall, IDS and IPS
Course 4: Tools of the Trade: Linux and SQL
Open Course 4 details
What you learn: the Linux command line, file permissions, and users. You also write SQL queries to investigate security data.
Study next: Course 4 study notes · Linux for beginners · SQL for analysts · Cheat sheets hub
Watch: Linux CLI · chmod · SQL for security
Quick commands are in the Linux and SQL section below.
Course 5: Assets, Threats, and Vulnerabilities
Open Course 5 details
What you learn: how to find, classify, and protect assets. You also study vulnerabilities, cryptography, and access control.
- Asset classes: restricted, confidential, internal-only, and public
- CVE, CVSS, OWASP Top 10, and zero-day flaws
- Symmetric and asymmetric encryption, hashing, PKI, SSO, and MFA
Study next: Course 5 study notes · Attacks, encryption, zero trust and risk · OWASP Top 10 explained
Watch: OWASP Top 10 · Encryption · CVSS
Course 6: Sound the Alarm: Detection and Response
Open Course 6 details
What you learn: how teams detect and handle incidents. You read logs, use IDS and SIEM tools, and analyze network traffic.
Study next: Course 6 study notes · SIEM and incident response practice · Wireshark tutorial
Watch: IR lifecycle · Splunk · Suricata
Course 7: Automate Cybersecurity Tasks with Python
Open Course 7 details
What you learn: Python basics, loops, functions, strings, lists, regular expressions, and file handling. Then you use them to automate log analysis.
Study next: Course 7 study notes · Python for beginners with 6 mini projects
Watch: Python basics · Regex · Python for security
Course 8: Put It to Work: Prepare for Cybersecurity Jobs
Open Course 8 details
What you learn: how to escalate incidents and talk to stakeholders. You also build a resume, practice interviews, and finish your capstone.
Study next: Course 8 study notes · 80 practice questions · 5 realistic scenarios
Watch: Resume · SOC interview · Portfolio
Core cybersecurity concepts: the CIA triad and beyond
The CIA triad is the base of every security decision. It appears in almost every course, so learn it first. For a deeper walkthrough, read core cybersecurity concepts explained.
Confidentiality
Only authorized people see data. Tools include encryption, access control, and MFA. A data breach is a typical attack.
Integrity
Data stays accurate and unaltered. Tools include hashing and digital signatures. Tampering is a typical attack.
Availability
Systems work when people need them. Tools include backups and redundancy. DoS and ransomware are typical attacks.
Related ideas to know
- Non-repudiation: a party cannot deny an action. Digital signatures and logs provide it.
- AAA: authentication (who are you), authorization (what may you do), and accounting (what did you do).
- Security principles: least privilege, separation of duties, defense in depth, and zero trust.
- Control types: preventive, detective, corrective, and deterrent.
- Data types: PII, SPII, and PHI. Data also has three states: at rest, in transit, and in use.
To go deeper, read cybersecurity fundamentals explained. It covers attacks, encryption, zero trust, authentication, and risk.
The 8 CISSP domains in the Google Cybersecurity Certificate
The certificate uses the eight CISSP domains as a map of the security field. Courses 1 and 2 teach them most directly.
| # | Domain | What it covers | Example |
|---|---|---|---|
| 1 | Security and Risk Management | Policies, compliance, ethics, risk | Writing a security policy |
| 2 | Asset Security | Classifying, storing, and disposing of data | Labeling data confidential |
| 3 | Security Architecture and Engineering | Secure design and cryptography | Configuring a firewall |
| 4 | Communication and Network Security | Securing networks and traffic | VPN, segmentation |
| 5 | Identity and Access Management | Who accesses what | SSO, MFA, RBAC |
| 6 | Security Assessment and Testing | Audits, scans, pen tests | Vulnerability scan |
| 7 | Security Operations | Monitoring, response, forensics | SIEM triage |
| 8 | Software Development Security | Secure coding and code review | Fixing SQL injection |
The full CISSP covers the same domains in more depth. See ISC2 CISSP for details. Note that it requires professional experience.
Security frameworks, laws, and standards
Frameworks give teams a shared plan. Because of this, employers expect you to know the main ones. Course 2 covers most of them.
| Name | Purpose | Link |
|---|---|---|
| NIST CSF | Govern, Identify, Protect, Detect, Respond, Recover (v2.0) | nist.gov |
| NIST RMF | Risk management lifecycle for systems | csrc.nist.gov |
| CIS Controls | Prioritized defensive actions | cisecurity.org |
| ISO/IEC 27001 | International ISMS standard | iso.org |
| OWASP Top 10 | Critical web application risks | owasp.org |
| MITRE ATT&CK | Attacker tactics and techniques | attack.mitre.org |
| GDPR, HIPAA, PCI DSS, SOX, FERPA | EU privacy, US health data, card payments, financial reporting, student records | Search each name |
Common threats, attacks, and vulnerabilities
Courses 1, 3, and 5 cover threats. As a result, this section helps you across the whole certificate.
Social engineering
Phishing, spear phishing, whaling, vishing, smishing, baiting, pretexting, and tailgating. Training, MFA, and email filtering help.
Malware
Viruses, worms, trojans, ransomware, spyware, rootkits, and botnets.
Password attacks
Brute force, dictionary, credential stuffing, and rainbow tables. Salted hashes and MFA reduce the risk.
Web attacks
SQL injection, XSS, CSRF, broken access control, and session hijacking.
Network attacks
DoS, DDoS, on-path attacks, spoofing, packet sniffing, and SYN floods.
Threat actors
Hacktivists, nation-states, cybercriminals, insiders, and advanced persistent threats.
Watch: attack types · SQL injection · phishing
Networking quick reference
Networking is the skill that beginners often find hardest. Therefore, review this table often. Then practice with the Wireshark tutorial for beginners, which shows you how to capture and filter real traffic.
| OSI layer | Examples |
|---|---|
| 7 Application | HTTP, DNS, SMTP |
| 6 Presentation | TLS/SSL, encoding |
| 5 Session | Session management |
| 4 Transport | TCP, UDP |
| 3 Network | IP, routers |
| 2 Data link | MAC, switches, ARP |
| 1 Physical | Cables, Wi-Fi signals |
Common ports: 20/21 FTP · 22 SSH · 23 Telnet · 25 SMTP · 53 DNS · 80 HTTP · 110 POP3 · 143 IMAP · 443 HTTPS · 445 SMB · 3389 RDP · 3306 MySQL
Remember: TCP is reliable and uses a three-way handshake (SYN, SYN-ACK, ACK). UDP is fast and connectionless.
Linux and SQL cheat sheets
Course 4 teaches both tools. For full lessons, use the Linux for cybersecurity beginners guide and the SQL for cybersecurity analysts guide. More one-page summaries live on the cheat sheets hub.
Linux commands
pwd, ls -la, cd /path # navigate
cat, less, head, tail -f # read files / follow logs
grep -i "failed" auth.log # search text
find / -name "*.conf" # locate files
chmod 640 file # permissions (r=4 w=2 x=1)
chown user:group file # ownership
sudo, su, useradd, passwd # users
ps aux, top, kill PID # processes
ip a, ss -tulpn, ping # networking
man command # help
The permission string -rwxr-x--- shows type, owner, group, and others.
SQL queries
SELECT * FROM log_in_attempts WHERE success = 0;
SELECT username, COUNT(*) FROM events GROUP BY username ORDER BY COUNT(*) DESC;
SELECT * FROM employees WHERE department = 'Sales' AND NOT office = 'East';
SELECT a.name, b.device FROM employees a JOIN machines b ON a.id = b.emp_id;
-- operators: AND OR NOT, LIKE '%x%', BETWEEN, IN
Python for security: starter patterns
Course 7 uses Python to automate boring checks. For example, this script flags IP addresses that are not on an allow list. For six hands-on exercises, try Python for cybersecurity beginners.
import re
allow_list = ["10.0.0.5", "10.0.0.9"]
with open("log.txt") as f:
for line in f:
ips = re.findall(r"\d{1,3}(?:\.\d{1,3}){3}", line)
for ip in ips:
if ip not in allow_list:
print("Review:", ip)
def is_strong(pw):
return len(pw) >= 12 and any(c.isdigit() for c in pw)
Practice: official Python tutorial · regex101
Detection and incident response
Course 6 explains how teams respond to attacks. To practice, work through five realistic SIEM and incident response scenarios.
NIST incident response lifecycle:
- Preparation
- Detection and analysis
- Containment, eradication, and recovery
- Post-incident activity (lessons learned)
- Tools: SIEM (Splunk, Chronicle, Elastic), IDS/IPS (Snort, Suricata), Wireshark, and EDR.
- Indicators: an IoC is evidence of a compromise. An IoA is evidence of an attack in progress.
- Key terms: triage, escalation, playbook, chain of custody, and root cause analysis.
- Good escalation note: what happened, when, which systems, the evidence, actions taken, and next steps.
Free labs, tools, and reading
Hands-on practice makes the theory stick. Start with the cybersecurity home lab setup guide. After that, try the platforms below.
Tools to install
- Wireshark
- Nmap
- VirtualBox with Kali or Ubuntu
- Splunk free trial
News and learning
YouTube channels
Professor Messer, NetworkChuck, John Hammond, The Cyber Mentor, David Bombal, and Google Career Certificates.
An 8-week study plan for the Google Cybersecurity Certificate
Every learner moves at a different speed. However, this plan gives you a steady rhythm. Adjust it to your schedule.
| Week | Focus | Do this |
|---|---|---|
| 1 | Course 1 | Read the notes and learn the CIA triad |
| 2 | Course 2 | Study risk and frameworks, then review the glossary |
| 3 | Course 3 | Build your home lab and capture traffic |
| 4 | Course 4 | Practice Linux and SQL daily |
| 5 | Course 5 | Learn encryption, access control, and OWASP |
| 6 | Course 6 | Solve the SIEM scenarios |
| 7 | Course 7 | Finish the Python mini projects |
| 8 | Course 8 | Polish your resume and take the 80 practice questions |
What to do after the Google Cybersecurity Certificate
- Entry roles: SOC analyst, security analyst, IT support with a security focus, vulnerability analyst, and GRC analyst.
- Next certifications: CompTIA Security+, then CySA+. Pursue CISSP after you gain the required experience.
- Portfolio: publish your capstone, lab write-ups, and a home lab. Also write a short blog post for each concept you learn.
- Study habit: learn one concept a day, and explain it aloud. Repeat quizzes until you score 90% or more.
Google Cybersecurity Certificate FAQ
How long does the Google Cybersecurity Certificate take?
Google suggests about six months at under ten hours a week. However, your pace depends on your background. Check the Coursera page for current estimates.
Do I need experience before I start?
No. The program is built for beginners. Still, basic computer skills help a lot.
Which course is the hardest?
Many learners struggle with Course 3 (networking) and Course 7 (Python). Therefore, give those courses extra time. The Wireshark tutorial and Python guide can help.
Is the certificate enough to get a job?
It is a strong start, but it is not a guarantee. Employers also want hands-on proof. For that reason, build a home lab and a portfolio.
How can I test my knowledge?
Use our 80 Google Cybersecurity Certificate practice questions. Then review weak topics in the matching course notes.
Cybersecurity glossary: search key terms
Type a term below to filter the list. For a longer list, open the full cybersecurity glossary for beginners.
- Access control
- Restricting who or what can view or use resources.
- APT
- Advanced persistent threat: a long-term, stealthy, targeted intrusion.
- Asset
- Anything of value to an organization: data, devices, people, systems.
- Attack surface
- All the points where an attacker could try to get in.
- Authentication
- Verifying identity (password, token, biometric).
- Authorization
- Granting permissions to an authenticated identity.
- Backdoor
- Hidden way to bypass normal authentication.
- Baiting
- Social engineering that lures victims with something tempting.
- Botnet
- Network of infected devices controlled remotely.
- Brute force
- Trying many credentials or keys until one works.
- Business continuity
- Keeping critical operations running during a disruption.
- CIA triad
- Confidentiality, Integrity, Availability.
- Cipher
- Algorithm for encrypting and decrypting.
- Cloud security
- Protecting data and services hosted in cloud environments.
- Compliance
- Meeting legal, regulatory, or standards requirements.
- Cryptography
- Science of securing information with math-based techniques.
- CSRF
- Cross-site request forgery: tricking a user’s browser into unwanted actions.
- CVE
- Common Vulnerabilities and Exposures: public ID list of known flaws.
- CVSS
- Scoring system (0 to 10) for vulnerability severity.
- Defense in depth
- Multiple layers of security controls.
- DDoS
- Distributed denial of service: a flood from many sources that knocks a service offline.
- DLP
- Data loss prevention: tools that stop sensitive data from leaving.
- DNS
- Domain Name System: translates names to IP addresses.
- EDR
- Endpoint detection and response: monitors and responds on devices.
- Encryption
- Converting data into an unreadable form without a key.
- Exploit
- Code or technique that takes advantage of a vulnerability.
- Firewall
- Filters network traffic by rules.
- Forensics
- Collecting and analyzing evidence after an incident.
- GRC
- Governance, risk, and compliance.
- Hash
- One-way fixed-length digest of data (SHA-256, MD5). Used for integrity checks.
- Hardening
- Reducing vulnerabilities by tightening configurations.
- IAM
- Identity and access management.
- IDS / IPS
- Intrusion detection (alerts) or prevention (blocks) systems.
- Incident
- An event that threatens the security of information or systems.
- IoC
- Indicator of compromise: evidence a breach occurred.
- Insider threat
- Risk from employees, contractors, or partners with access.
- Least privilege
- Give only the minimum access needed.
- Log
- Record of events on a system.
- Malware
- Malicious software.
- MFA
- Multi-factor authentication: two or more factor types.
- MITRE ATT&CK
- Catalog of real-world adversary tactics and techniques.
- NIST
- US National Institute of Standards and Technology.
- On-path attack
- Attacker intercepts communication between two parties (formerly MITM).
- OSINT
- Open-source intelligence from public information.
- OWASP
- Open Worldwide Application Security Project.
- Packet
- Unit of data sent over a network.
- Patch
- Software update that fixes vulnerabilities.
- Penetration test
- Authorized simulated attack to find weaknesses.
- PHI
- Protected health information.
- Phishing
- Deceptive messages that trick users into revealing data or clicking links.
- PII / SPII
- Personally identifiable information, and its sensitive form (such as a bank number).
- Playbook
- Documented steps for handling a specific scenario.
- PKI
- Public key infrastructure: certificates and keys for trust.
- Ransomware
- Malware that encrypts data and demands payment.
- RBAC
- Role-based access control.
- Risk
- Potential for loss when a threat exploits a vulnerability.
- Rootkit
- Malware that hides deep in a system with elevated privileges.
- Salting
- Adding random data to a password before hashing.
- SIEM
- Security information and event management: collects and analyzes logs.
- SOAR
- Security orchestration, automation, and response.
- SOC
- Security operations center.
- Social engineering
- Manipulating people into giving access or information.
- SQL injection
- Inserting malicious SQL through input to manipulate a database.
- SSO
- Single sign-on: one login for many apps.
- STRIDE
- Threat model: Spoofing, Tampering, Repudiation, Information disclosure, DoS, Elevation of privilege.
- Threat
- Anything that can harm an asset.
- Threat actor
- Person or group behind an attack.
- TLS
- Transport Layer Security: encrypts web traffic (HTTPS).
- Trojan
- Malware disguised as legitimate software.
- VPN
- Encrypted tunnel across an untrusted network.
- Vulnerability
- Weakness that can be exploited.
- Worm
- Self-replicating malware that spreads without user action.
- XSS
- Cross-site scripting: injecting scripts into pages viewed by others.
- Zero-day
- Vulnerability unknown to the vendor, with no patch yet.
- Zero trust
- Model that verifies every request and never assumes trust by location.
Keep learning
You now have a full roadmap for the Google Cybersecurity Certificate. Next, pick your current course in the course map, open its study notes, and start. When you finish, test yourself with the practice questions. Then return to the Google Cybersecurity Certificate on Coursera for the next course.
Educational summary for learners. Verify details against official course materials. Last reviewed: October 2026.
