Unlimited courses and practice exams for the old 8570, now 8140.

Study for Security+, CISSP, CySA+, CEH and more. Every module is built from the vendor's own published exam blueprint, and the practice exams score you by domain, so you always know what to study next.

Start free. Pay when it's worth it.

Inside the product

This is what you actually get.

Not a video library. Written lessons that argue a point, labs that put you in a situation, and practice exams weighted to the real blueprint.

The CIA triad in a DoD contextreading · 12 min

Confidentiality, integrity, and availability are not three boxes to tick. They are three pressures that pull against each other, and security engineering is mostly the work of deciding which one wins when they conflict. Full-disk encryption raises confidentiality and costs you a little availability. Aggressive integrity checking on a file transfer raises integrity and costs you throughput. An air gap maximizes confidentiality and destroys availability for anyone who needed the data quickly. There is no configuration that maximizes all three, and an engineer who claims otherwise has simply not found the tradeoff

An actual lesson from the free first module — not a mockup.
Knowledge check

A supply depot's inventory system is encrypted by ransomware. Investigation confirms no data left the network and no records were altered before encryption. Which security objective was harmed?

  • Confidentiality, because the attacker had access to the data
  • Integrity, because the files are no longer in their original form
  • Availability, because authorized users cannot reach the data they need
  • Non-repudiation, because the attacker's actions cannot be attributed
Every question explains why the tempting wrong answer fails.
Hands-on lab22 min

Lab: classify controls and route a change for an enclave

You support a moderate-impact enclave hosting a logistics application for roughly 400 users. Work through the following in order and write your answers down before checking your reasoning against the

  • Classify a mixed set of controls by both category and type.
  • Identify the security-relevant failure in a change proposal.
  • Write a backout condition that an approver can actually test.
A situation with a decision in it — written scenarios, not click-throughs.
Practice exam · by domainSY0-701
General security concepts12% of exam
Threats, vulnerabilities, and mitigations22% of exam
Security architecture18% of exam
Security operations28% of exam
Security program management and oversight20% of exam
Real published domains and weights; scores shown are an example. Your weakest domain is flagged, and you can drill it.

28 paths

Pick your certification

Start with the one your contract names. Every course opens with a free module, so you can read the actual material before deciding.

Professional development

AI for the DoD Technical Workforce

Every AI course teaches you to be productive. This one teaches you to be productive without causing a spill — what never goes in a prompt, using AI on the authorized path, and verifying output you are accountable for. Written for a cleared environment, where the paste-everything habit generic courses build is a reportable incident.

This is professional development, not certification prep. 8140 does not currently require any AI certification, and nothing here is an 8140 qualification — it is included in the same subscription as everything else.

What is inside

  1. 01What this course is, and what it is not5
  2. 02What never goes in a prompt6
  3. 03Using AI the authorized way6
  4. 04Prompting without spilling6
  5. 05Verifying AI output like it matters6
  6. 06AI, your certification, and your renewal5

6 modules · 6 hours in total

Why it is different

Why this beats a video course

Three claims, and the thing that proves each one — rendered from the same data the courses are built from, not a screenshot.

01

Built from the real blueprint

Modules are generated from each vendor's published exam objectives. When a vendor reweights an exam, the course changes with it instead of quietly going stale.

Security+ blueprint → your courseSY0-701
Published by CompTIAWhat we built

General security concepts

12%

General security concepts

6 lessons

Threats, vulnerabilities, and mitigations

22%

Threats, vulnerabilities, and mitigations

8 lessons

Security architecture

18%

Security architecture

7 lessons

Security operations

28%

Security operations

8 lessons

Security program management and oversight

20%

Security program management and oversight

7 lessons

Domains and weights read from CompTIA’s published blueprint. Reweight the exam and the course follows it.
02

Tells you what to study next

Practice exams score you per domain against the published weights, flag your weakest one, and let you drill it. No guessing where the gap is.

After your practice exam

Weakest domain

Security operations64%

Worth 28% of the exam — the heaviest domain on it.

Study these next

  • Hardening baselines and STIGs
  • Identity and access management operations
  • Monitoring, logging, and making a SIEM useful
Real domain weights and real lessons; the score shown is an example.
03

Sourced, and honest about gaps

Every requirement carries a source link and the date we checked it. Where a vendor publishes no weighting, we show none rather than inventing one.

Source record

CompTIA Security+ certification page

Source published2023-11-07
We last checked2026-09-15

What we could not confirm

CompTIA lists SY0-701 retirement as June 11, 2027 (English) and August 13, 2027 (Japanese, Portuguese, Spanish, and Thai). Its successor, Security+ V8 (SY0-801), is in development: CompTIA has posted draft V8 exam objectives but has not published a release date. Re-check when the final V8 objectives are posted.

Every certification carries one of these. Unedited — including the parts that admit a gap.

The reference DoD took offline

Told to get “IAT Level II”?

The DoD 8570 baseline table — IAT, IAM, IASAE and CSSP — left the public web in late 2024, and most sites still link to the page that went dark. We host the last public capture, sourced and dated.

DoD Approved 8570 Baseline CertificationsRemoved from public web
IAT Level I
A+ CECCNA-SecurityCNDNetwork+ CESSCP
IAT Level II
CCNA-SecurityCySA+GICSPGSECSecurity+ CECNDSSCP
IAT Level III
CASP+ CECCNP SecurityCISACISSP (or Associate)GCEDGCIHCCSP
Last public capture, 2024-10-02. Amber marks a certification that has been renamed or retired since DoD last revised the table — the page itself was never corrected.

Every level lists the certifications that satisfy it, and which one is the lightest lift to obtain — so a line in your contract becomes a course you can start today.

Browse the baseline levels

Start free. Pay when it is worth it.

  • The first module of all 28 courses, free
  • A knowledge check in every free module
  • $39 a month, or $390 a year
  • Cancel any time — no contract

For teams

Buying for people you are responsible for?

Per-seat pricing for every course, an admin dashboard that tells you who is on track to qualify by your contract date, and exportable training records for the ones who ask. From $270 per seat a year.

30 courses. 1,565 lessons. 251 labs.

Pick the certification you were told to get and start with the free module. Handed something like “IAT Level II” instead of a certification name? We will show you every certification that satisfies it.