Google Cybersecurity Certificate: A Complete Beginner’s Guide to All 8 Courses

    The Google Cybersecurity Certificate is one of the most popular ways to start a security career. This guide gives you one page to keep open while you study. It maps every course to free study notes, practice pages, labs, and videos.

    First, you will see a course map. Next, you will find core concepts, cheat sheets, and a study plan. Finally, you can search a glossary and read answers to common questions. Bookmark this page, and return to it after each course.

    Independent study aid. This page is not affiliated with or endorsed by Google or Coursera. Always confirm current course content on the official Google Cybersecurity Certificate page on Coursera.

    How to use this Google Cybersecurity Certificate guide

    The Google Cybersecurity Certificate has eight courses. Each course builds on the one before it. Therefore, you should study them in order.

    Use this simple loop for every course:

    1. Read the course study notes on this site.
    2. Watch the course lessons on Coursera.
    3. Practice with the linked helper pages and labs.
    4. Finish the graded quizzes and activities.
    5. Test yourself with the practice questions.

    Tip: You can also go the other way. Start with a helper page, then jump to the matching course on Coursera. Every course block below has links in both directions.

    Google Cybersecurity Certificate course map

    This table shows how each course connects to the study notes and helper pages on this site. Use it as your quick index.

    CourseStudy notesBest helper pages
    1. Foundations of CybersecurityCourse 1 notesCore concepts, Glossary
    2. Play It Safe: Manage Security RisksCourse 2 notesCore concepts, Fundamentals
    3. Connect and Protect: NetworksCourse 3 notesWireshark tutorial, Home lab
    4. Tools of the Trade: Linux and SQLCourse 4 notesLinux guide, SQL guide
    5. Assets, Threats, and VulnerabilitiesCourse 5 notesFundamentals, Core concepts
    6. Sound the Alarm: Detection and ResponseCourse 6 notesSIEM practice, Wireshark
    7. Automate Tasks with PythonCourse 7 notesPython guide
    8. Put It to Work: Prepare for JobsCourse 8 notesPractice questions, Home lab

    Course 1: Foundations of Cybersecurity

    Open Course 1 details

    What you learn: what security is, what analysts do, and why the CIA triad matters. You also meet threat actors, the eight security domains, and your first tools.

    • Security versus cybersecurity, and daily analyst tasks
    • Social engineering, malware, and common attack types
    • Ethics, laws, and data types such as PII, SPII, and PHI
    • An intro to SIEM tools, playbooks, and packet sniffers

    Study next: Course 1 study notes · Core concepts explained · Cybersecurity glossary

    Watch: Foundations · CIA triad · Analyst day in the life

    Start Course 1 on Coursera

    Course 2: Play It Safe: Manage Security Risks

    Open Course 2 details

    What you learn: how organizations manage risk. You study the eight CISSP domains in depth, plus frameworks, controls, and security audits.

    • Risk steps: identify, assess, mitigate, and monitor
    • NIST CSF, NIST RMF, CIS Controls, and ISO 27001
    • Least privilege, defense in depth, and threat modeling with STRIDE and PASTA

    Study next: Course 2 study notes · CIA triad, CISSP, NIST and OWASP · Fundamentals explained

    Watch: NIST CSF · Risk management · STRIDE

    Continue on Coursera

    Course 3: Connect and Protect: Networks and Network Security

    Open Course 3 details

    What you learn: how networks work and how attackers abuse them. You also learn how to harden systems.

    • TCP/IP, the OSI model, ports, DNS, DHCP, and ARP
    • DoS, DDoS, spoofing, and on-path attacks
    • Firewalls, VPNs, proxies, IDS/IPS, and network segmentation

    Study next: Course 3 study notes · Wireshark tutorial · Home lab setup

    Watch: OSI model · TCP/IP · Firewall, IDS and IPS

    Continue on Coursera

    Course 4: Tools of the Trade: Linux and SQL

    Open Course 4 details

    What you learn: the Linux command line, file permissions, and users. You also write SQL queries to investigate security data.

    Study next: Course 4 study notes · Linux for beginners · SQL for analysts · Cheat sheets hub

    Watch: Linux CLI · chmod · SQL for security

    Quick commands are in the Linux and SQL section below.

    Continue on Coursera

    Course 5: Assets, Threats, and Vulnerabilities

    Open Course 5 details

    What you learn: how to find, classify, and protect assets. You also study vulnerabilities, cryptography, and access control.

    • Asset classes: restricted, confidential, internal-only, and public
    • CVE, CVSS, OWASP Top 10, and zero-day flaws
    • Symmetric and asymmetric encryption, hashing, PKI, SSO, and MFA

    Study next: Course 5 study notes · Attacks, encryption, zero trust and risk · OWASP Top 10 explained

    Watch: OWASP Top 10 · Encryption · CVSS

    Continue on Coursera

    Course 6: Sound the Alarm: Detection and Response

    Open Course 6 details

    What you learn: how teams detect and handle incidents. You read logs, use IDS and SIEM tools, and analyze network traffic.

    Study next: Course 6 study notes · SIEM and incident response practice · Wireshark tutorial

    Watch: IR lifecycle · Splunk · Suricata

    Continue on Coursera

    Course 7: Automate Cybersecurity Tasks with Python

    Open Course 7 details

    What you learn: Python basics, loops, functions, strings, lists, regular expressions, and file handling. Then you use them to automate log analysis.

    Study next: Course 7 study notes · Python for beginners with 6 mini projects

    Watch: Python basics · Regex · Python for security

    Continue on Coursera

    Course 8: Put It to Work: Prepare for Cybersecurity Jobs

    Open Course 8 details

    What you learn: how to escalate incidents and talk to stakeholders. You also build a resume, practice interviews, and finish your capstone.

    Study next: Course 8 study notes · 80 practice questions · 5 realistic scenarios

    Watch: Resume · SOC interview · Portfolio

    Finish on Coursera

    Core cybersecurity concepts: the CIA triad and beyond

    The CIA triad is the base of every security decision. It appears in almost every course, so learn it first. For a deeper walkthrough, read core cybersecurity concepts explained.

    Confidentiality

    Only authorized people see data. Tools include encryption, access control, and MFA. A data breach is a typical attack.

    Integrity

    Data stays accurate and unaltered. Tools include hashing and digital signatures. Tampering is a typical attack.

    Availability

    Systems work when people need them. Tools include backups and redundancy. DoS and ransomware are typical attacks.

    Related ideas to know

    • Non-repudiation: a party cannot deny an action. Digital signatures and logs provide it.
    • AAA: authentication (who are you), authorization (what may you do), and accounting (what did you do).
    • Security principles: least privilege, separation of duties, defense in depth, and zero trust.
    • Control types: preventive, detective, corrective, and deterrent.
    • Data types: PII, SPII, and PHI. Data also has three states: at rest, in transit, and in use.

    To go deeper, read cybersecurity fundamentals explained. It covers attacks, encryption, zero trust, authentication, and risk.

    The 8 CISSP domains in the Google Cybersecurity Certificate

    The certificate uses the eight CISSP domains as a map of the security field. Courses 1 and 2 teach them most directly.

    #DomainWhat it coversExample
    1Security and Risk ManagementPolicies, compliance, ethics, riskWriting a security policy
    2Asset SecurityClassifying, storing, and disposing of dataLabeling data confidential
    3Security Architecture and EngineeringSecure design and cryptographyConfiguring a firewall
    4Communication and Network SecuritySecuring networks and trafficVPN, segmentation
    5Identity and Access ManagementWho accesses whatSSO, MFA, RBAC
    6Security Assessment and TestingAudits, scans, pen testsVulnerability scan
    7Security OperationsMonitoring, response, forensicsSIEM triage
    8Software Development SecuritySecure coding and code reviewFixing SQL injection

    The full CISSP covers the same domains in more depth. See ISC2 CISSP for details. Note that it requires professional experience.

    Security frameworks, laws, and standards

    Frameworks give teams a shared plan. Because of this, employers expect you to know the main ones. Course 2 covers most of them.

    NamePurposeLink
    NIST CSFGovern, Identify, Protect, Detect, Respond, Recover (v2.0)nist.gov
    NIST RMFRisk management lifecycle for systemscsrc.nist.gov
    CIS ControlsPrioritized defensive actionscisecurity.org
    ISO/IEC 27001International ISMS standardiso.org
    OWASP Top 10Critical web application risksowasp.org
    MITRE ATT&CKAttacker tactics and techniquesattack.mitre.org
    GDPR, HIPAA, PCI DSS, SOX, FERPAEU privacy, US health data, card payments, financial reporting, student recordsSearch each name

    Common threats, attacks, and vulnerabilities

    Courses 1, 3, and 5 cover threats. As a result, this section helps you across the whole certificate.

    Social engineering

    Phishing, spear phishing, whaling, vishing, smishing, baiting, pretexting, and tailgating. Training, MFA, and email filtering help.

    Malware

    Viruses, worms, trojans, ransomware, spyware, rootkits, and botnets.

    Password attacks

    Brute force, dictionary, credential stuffing, and rainbow tables. Salted hashes and MFA reduce the risk.

    Web attacks

    SQL injection, XSS, CSRF, broken access control, and session hijacking.

    Network attacks

    DoS, DDoS, on-path attacks, spoofing, packet sniffing, and SYN floods.

    Threat actors

    Hacktivists, nation-states, cybercriminals, insiders, and advanced persistent threats.

    Watch: attack types · SQL injection · phishing

    Networking quick reference

    Networking is the skill that beginners often find hardest. Therefore, review this table often. Then practice with the Wireshark tutorial for beginners, which shows you how to capture and filter real traffic.

    OSI layerExamples
    7 ApplicationHTTP, DNS, SMTP
    6 PresentationTLS/SSL, encoding
    5 SessionSession management
    4 TransportTCP, UDP
    3 NetworkIP, routers
    2 Data linkMAC, switches, ARP
    1 PhysicalCables, Wi-Fi signals

    Common ports: 20/21 FTP · 22 SSH · 23 Telnet · 25 SMTP · 53 DNS · 80 HTTP · 110 POP3 · 143 IMAP · 443 HTTPS · 445 SMB · 3389 RDP · 3306 MySQL

    Remember: TCP is reliable and uses a three-way handshake (SYN, SYN-ACK, ACK). UDP is fast and connectionless.

    Linux and SQL cheat sheets

    Course 4 teaches both tools. For full lessons, use the Linux for cybersecurity beginners guide and the SQL for cybersecurity analysts guide. More one-page summaries live on the cheat sheets hub.

    Linux commands

    pwd, ls -la, cd /path       # navigate
    cat, less, head, tail -f    # read files / follow logs
    grep -i "failed" auth.log   # search text
    find / -name "*.conf"       # locate files
    chmod 640 file              # permissions (r=4 w=2 x=1)
    chown user:group file       # ownership
    sudo, su, useradd, passwd   # users
    ps aux, top, kill PID       # processes
    ip a, ss -tulpn, ping       # networking
    man command                 # help

    The permission string -rwxr-x--- shows type, owner, group, and others.

    SQL queries

    SELECT * FROM log_in_attempts WHERE success = 0;
    SELECT username, COUNT(*) FROM events GROUP BY username ORDER BY COUNT(*) DESC;
    SELECT * FROM employees WHERE department = 'Sales' AND NOT office = 'East';
    SELECT a.name, b.device FROM employees a JOIN machines b ON a.id = b.emp_id;
    -- operators: AND OR NOT, LIKE '%x%', BETWEEN, IN

    Python for security: starter patterns

    Course 7 uses Python to automate boring checks. For example, this script flags IP addresses that are not on an allow list. For six hands-on exercises, try Python for cybersecurity beginners.

    import re
    allow_list = ["10.0.0.5", "10.0.0.9"]
    with open("log.txt") as f:
        for line in f:
            ips = re.findall(r"\d{1,3}(?:\.\d{1,3}){3}", line)
            for ip in ips:
                if ip not in allow_list:
                    print("Review:", ip)
    
    def is_strong(pw):
        return len(pw) >= 12 and any(c.isdigit() for c in pw)

    Practice: official Python tutorial · regex101

    Detection and incident response

    Course 6 explains how teams respond to attacks. To practice, work through five realistic SIEM and incident response scenarios.

    NIST incident response lifecycle:

    1. Preparation
    2. Detection and analysis
    3. Containment, eradication, and recovery
    4. Post-incident activity (lessons learned)
    • Tools: SIEM (Splunk, Chronicle, Elastic), IDS/IPS (Snort, Suricata), Wireshark, and EDR.
    • Indicators: an IoC is evidence of a compromise. An IoA is evidence of an attack in progress.
    • Key terms: triage, escalation, playbook, chain of custody, and root cause analysis.
    • Good escalation note: what happened, when, which systems, the evidence, actions taken, and next steps.

    Free labs, tools, and reading

    Hands-on practice makes the theory stick. Start with the cybersecurity home lab setup guide. After that, try the platforms below.

    Tools to install

    YouTube channels

    Professor Messer, NetworkChuck, John Hammond, The Cyber Mentor, David Bombal, and Google Career Certificates.

    An 8-week study plan for the Google Cybersecurity Certificate

    Every learner moves at a different speed. However, this plan gives you a steady rhythm. Adjust it to your schedule.

    WeekFocusDo this
    1Course 1Read the notes and learn the CIA triad
    2Course 2Study risk and frameworks, then review the glossary
    3Course 3Build your home lab and capture traffic
    4Course 4Practice Linux and SQL daily
    5Course 5Learn encryption, access control, and OWASP
    6Course 6Solve the SIEM scenarios
    7Course 7Finish the Python mini projects
    8Course 8Polish your resume and take the 80 practice questions

    What to do after the Google Cybersecurity Certificate

    • Entry roles: SOC analyst, security analyst, IT support with a security focus, vulnerability analyst, and GRC analyst.
    • Next certifications: CompTIA Security+, then CySA+. Pursue CISSP after you gain the required experience.
    • Portfolio: publish your capstone, lab write-ups, and a home lab. Also write a short blog post for each concept you learn.
    • Study habit: learn one concept a day, and explain it aloud. Repeat quizzes until you score 90% or more.

    Google Cybersecurity Certificate FAQ

    How long does the Google Cybersecurity Certificate take?

    Google suggests about six months at under ten hours a week. However, your pace depends on your background. Check the Coursera page for current estimates.

    Do I need experience before I start?

    No. The program is built for beginners. Still, basic computer skills help a lot.

    Which course is the hardest?

    Many learners struggle with Course 3 (networking) and Course 7 (Python). Therefore, give those courses extra time. The Wireshark tutorial and Python guide can help.

    Is the certificate enough to get a job?

    It is a strong start, but it is not a guarantee. Employers also want hands-on proof. For that reason, build a home lab and a portfolio.

    How can I test my knowledge?

    Use our 80 Google Cybersecurity Certificate practice questions. Then review weak topics in the matching course notes.

    Cybersecurity glossary: search key terms

    Type a term below to filter the list. For a longer list, open the full cybersecurity glossary for beginners.

    Access control
    Restricting who or what can view or use resources.
    APT
    Advanced persistent threat: a long-term, stealthy, targeted intrusion.
    Asset
    Anything of value to an organization: data, devices, people, systems.
    Attack surface
    All the points where an attacker could try to get in.
    Authentication
    Verifying identity (password, token, biometric).
    Authorization
    Granting permissions to an authenticated identity.
    Backdoor
    Hidden way to bypass normal authentication.
    Baiting
    Social engineering that lures victims with something tempting.
    Botnet
    Network of infected devices controlled remotely.
    Brute force
    Trying many credentials or keys until one works.
    Business continuity
    Keeping critical operations running during a disruption.
    CIA triad
    Confidentiality, Integrity, Availability.
    Cipher
    Algorithm for encrypting and decrypting.
    Cloud security
    Protecting data and services hosted in cloud environments.
    Compliance
    Meeting legal, regulatory, or standards requirements.
    Cryptography
    Science of securing information with math-based techniques.
    CSRF
    Cross-site request forgery: tricking a user’s browser into unwanted actions.
    CVE
    Common Vulnerabilities and Exposures: public ID list of known flaws.
    CVSS
    Scoring system (0 to 10) for vulnerability severity.
    Defense in depth
    Multiple layers of security controls.
    DDoS
    Distributed denial of service: a flood from many sources that knocks a service offline.
    DLP
    Data loss prevention: tools that stop sensitive data from leaving.
    DNS
    Domain Name System: translates names to IP addresses.
    EDR
    Endpoint detection and response: monitors and responds on devices.
    Encryption
    Converting data into an unreadable form without a key.
    Exploit
    Code or technique that takes advantage of a vulnerability.
    Firewall
    Filters network traffic by rules.
    Forensics
    Collecting and analyzing evidence after an incident.
    GRC
    Governance, risk, and compliance.
    Hash
    One-way fixed-length digest of data (SHA-256, MD5). Used for integrity checks.
    Hardening
    Reducing vulnerabilities by tightening configurations.
    IAM
    Identity and access management.
    IDS / IPS
    Intrusion detection (alerts) or prevention (blocks) systems.
    Incident
    An event that threatens the security of information or systems.
    IoC
    Indicator of compromise: evidence a breach occurred.
    Insider threat
    Risk from employees, contractors, or partners with access.
    Least privilege
    Give only the minimum access needed.
    Log
    Record of events on a system.
    Malware
    Malicious software.
    MFA
    Multi-factor authentication: two or more factor types.
    MITRE ATT&CK
    Catalog of real-world adversary tactics and techniques.
    NIST
    US National Institute of Standards and Technology.
    On-path attack
    Attacker intercepts communication between two parties (formerly MITM).
    OSINT
    Open-source intelligence from public information.
    OWASP
    Open Worldwide Application Security Project.
    Packet
    Unit of data sent over a network.
    Patch
    Software update that fixes vulnerabilities.
    Penetration test
    Authorized simulated attack to find weaknesses.
    PHI
    Protected health information.
    Phishing
    Deceptive messages that trick users into revealing data or clicking links.
    PII / SPII
    Personally identifiable information, and its sensitive form (such as a bank number).
    Playbook
    Documented steps for handling a specific scenario.
    PKI
    Public key infrastructure: certificates and keys for trust.
    Ransomware
    Malware that encrypts data and demands payment.
    RBAC
    Role-based access control.
    Risk
    Potential for loss when a threat exploits a vulnerability.
    Rootkit
    Malware that hides deep in a system with elevated privileges.
    Salting
    Adding random data to a password before hashing.
    SIEM
    Security information and event management: collects and analyzes logs.
    SOAR
    Security orchestration, automation, and response.
    SOC
    Security operations center.
    Social engineering
    Manipulating people into giving access or information.
    SQL injection
    Inserting malicious SQL through input to manipulate a database.
    SSO
    Single sign-on: one login for many apps.
    STRIDE
    Threat model: Spoofing, Tampering, Repudiation, Information disclosure, DoS, Elevation of privilege.
    Threat
    Anything that can harm an asset.
    Threat actor
    Person or group behind an attack.
    TLS
    Transport Layer Security: encrypts web traffic (HTTPS).
    Trojan
    Malware disguised as legitimate software.
    VPN
    Encrypted tunnel across an untrusted network.
    Vulnerability
    Weakness that can be exploited.
    Worm
    Self-replicating malware that spreads without user action.
    XSS
    Cross-site scripting: injecting scripts into pages viewed by others.
    Zero-day
    Vulnerability unknown to the vendor, with no patch yet.
    Zero trust
    Model that verifies every request and never assumes trust by location.

    Keep learning

    You now have a full roadmap for the Google Cybersecurity Certificate. Next, pick your current course in the course map, open its study notes, and start. When you finish, test yourself with the practice questions. Then return to the Google Cybersecurity Certificate on Coursera for the next course.

    ↑ Back to top

    Educational summary for learners. Verify details against official course materials. Last reviewed: October 2026.