ITCertFoundryTechnical training system

Free tool · No account required · No email required

Security+ or CCNA First? Let's Stop Guessing.

CCNA teaches you how networks actually move traffic. Security+ teaches you how organizations protect systems, data, identities, and operations. Neither one hands you a job because you passed a test.

Short answer: if you do not understand IP addresses, ports, DNS, routing, TCP, and basic packet flow, security concepts will be harder than they need to be. If you already support users, systems, networks, or cloud services and want to move toward security, Security+ may be the faster next move.

The blunt answer

Here's the situation.

Choose CCNA first if:

  • You want a NOC, network technician, network administrator, or infrastructure role.
  • You cannot confidently explain packet flow.
  • Subnetting, VLANs, routing, NAT, DNS, DHCP, ports, and TCP/UDP are weak areas.
  • You want hands-on configuration and troubleshooting experience.
  • You want to understand the network before attempting to defend it.
  • You learn best by building, breaking, and repairing things.

Choose Security+ first if:

  • You already understand basic networking.
  • You work in help desk, desktop support, systems administration, Microsoft 365, identity, endpoint management, or cloud support.
  • You want to move toward SOC, IAM, GRC, vulnerability management, or general security operations.
  • You need broader knowledge of threats, controls, identity, risk, cryptography, incident response, and governance.
  • The jobs you are targeting specifically request Security+.

Choose neither first if:

  • You cannot explain what an IP address, port, operating system, process, file permission, or DNS query is.
  • You have never used a command line.
  • You are completely new to IT troubleshooting.
  • You believe Security+ turns someone into a penetration tester.
  • You believe CCNA teaches the entire cybersecurity field.
  • You are choosing a certification because somebody promised a six-figure remote job after a six-week boot camp.

If you are starting at absolute zero, throwing you directly into CCNA or Security+ is like handing someone equipment before explaining which end points downrange. Start with IT foundations. It is not glamorous, but neither is failing an exam because every other term sounds like a Pokémon.

Free interactive assessment

Answer honestly. Get a real answer.

12-15 questions, a mix of self-assessment and a few quick knowledge checks. Wrong answers don't get you shamed — they just tell us what to recommend you shore up first.

QUESTION 1 OF 14

How would you describe your current IT experience?

Side-by-side

The full comparison.

Security+ is broad and terminology-heavy. CCNA goes considerably deeper into networking, configuration, packet forwarding, subnetting, and troubleshooting. The easier exam is usually the one closest to what you already know.

CategoryCCNASecurity+
ProviderCiscoCompTIA
Exam code200-301SY0-701
Current versionv1.1 (Aug 2024)V7 (Nov 2023)
Vendor-specific or neutralVendor-specific (Cisco)Vendor-neutral
Primary subjectHow networks move trafficHow organizations protect systems and data
Intended audienceAspiring network techs, admins, and engineersIT staff moving toward security roles
Recommended experience~1 year hands-on networking (informal)Network+ plus 2 years security/sysadmin (informal)
Exam price$300 (verify at registration)$425 (verify at registration)
Exam duration120 minutes90 minutes
Question formatMCQ, drag-and-drop, CLI simulation, testletsMCQ and performance-based
Hands-on configuration expectedExtensive — real IOS commands, real topologiesMinimal — concepts and scenario judgment, not CLI
Networking depthDeep — this is the whole examShallow — enough to discuss controls, not configure them
Security depthOne domain (15%) — fundamentals onlyDeep and broad — this is the whole exam
Governance & risk coverageEssentially noneA full domain (20%) — policy, risk, compliance, third-party
Cryptography coverageNot coveredSubstantial — PKI, encryption, hashing, certificates
Identity & access coverageAAA concepts, local passwords, basic ACLsDeep — IAM, federation, MFA, provisioning, access models
Cloud coverageIntroductory — on-prem vs. cloud architecture conceptsWoven throughout — cloud-specific threats, controls, architecture
Automation coverageA full domain (10%) — APIs, JSON, Ansible/Terraform awarenessLight — SOAR/automation mentioned conceptually, not configured
Command-line requirementYes — you will configure real Cisco IOSNo — terminology and judgment, not syntax
Troubleshooting depthDeep — packet-level, protocol-level troubleshootingShallow — recognizing indicators, not packet analysis
Typical study time8–16 weeks for most working IT people6–10 weeks for most working IT people
Common job pathsNOC, network tech/admin/engineer, infrastructureSOC, IAM, GRC, vulnerability management, security ops
Difficulty for a complete beginnerHard without networking exposure — deep, technical, configuration-heavyHard without IT exposure — broad, terminology-dense, abstract
Best next certificationCCNP ENCOR, or Security+ for a security-adjacent pivotCySA+, PenTest+, or a cloud-security specialization
What it teaches wellReal packet forwarding, addressing, VLANs, routing, troubleshootingThe full vocabulary and mental model of enterprise security
What it barely coversThreats, incident response, governance, cryptographyNetworking mechanics — addressing, routing, switching
What it does not teachSOC operations, forensics, compliance programs, pentestingSubnetting, IOS configuration, routing-table analysis
Where CCNA knowledge and Security+ knowledge apply along one packet's path, from client through switch, router, firewall, and server

What it actually teaches

CCNA

  • Reading and interpreting network diagrams
  • Understanding how a packet actually moves from source to destination
  • IPv4 and IPv6 addressing, including subnetting by hand
  • VLANs, trunks, and inter-VLAN routing
  • Spanning Tree Protocol and loop prevention
  • EtherChannel and link aggregation
  • Static routing and single-area OSPF
  • NAT and PAT
  • DHCP, DNS, and NTP roles in a network
  • Access control lists (ACLs)
  • Layer 2 protections: DHCP snooping, dynamic ARP inspection, port security
  • Wireless architecture concepts (SSIDs, RF, encryption)
  • Cisco IOS configuration via CLI
  • Verification and systematic troubleshooting
  • Basic REST APIs, JSON, and automation tooling awareness (Ansible, Terraform)

CCNA includes security fundamentals. It is not a complete cybersecurity certification. CCNA teaches you what the network is doing before you accuse it of being hacked. Many "security incidents" begin life as a broken route, bad DNS record, expired certificate, wrong VLAN, or somebody who confidently configured the wrong interface.

CCNA does not deeply teach:

  • SOC operations and alert triage
  • Detailed incident response procedure
  • Malware analysis
  • Digital forensics
  • Enterprise risk frameworks and compliance programs
  • Deep identity architecture (federation, IAM platforms)
  • Full cloud-security operations
  • Penetration testing

What it actually teaches

Security+

  • General security concepts: control types, CIA triad, Zero Trust, AAA
  • Threat actor types, motivations, and attack surfaces
  • Identifying indicators of malware, network, and application attacks
  • Vulnerability types and mitigation techniques across the enterprise
  • Secure architecture: segmentation, cloud responsibility models, resilience
  • Identity and access management: MFA, SSO, federation, provisioning
  • Cryptography and PKI: encryption, hashing, certificates, digital signatures
  • Security operations: hardening, monitoring, alerting, SIEM/SOAR concepts
  • Incident response process, from preparation through lessons learned
  • Vulnerability management lifecycle, from identification to reporting
  • Data classification and protection across its lifecycle
  • Risk management: identification, assessment, registers, treatment strategies
  • Governance: policies, standards, procedures, and organizational roles
  • Third-party/vendor risk assessment and management
  • Business continuity, disaster recovery, and backup strategy

Security+ provides broad security foundations. It does not make someone an experienced SOC analyst, penetration tester, incident responder, or security engineer by itself.

Security+ does not deeply teach:

  • Subnetting
  • Routing protocol configuration (OSPF, static routes)
  • VLAN and trunk configuration
  • Spanning Tree troubleshooting
  • Cisco IOS or any vendor CLI
  • Building or wiring an actual enterprise network
  • Routing-table analysis
  • Packet-level troubleshooting at CCNA depth
  • Advanced offensive-security technique

Neither certification is a complete career. They are foundations. The job begins where the multiple-choice question ends.

By career goal

What should you take, given what you actually want to do?

Help desk technician

Depends on your networking comfort

If you can already explain IP addresses, DNS, and basic connectivity troubleshooting, Security+ is the more direct move. If networking still feels fuzzy, close that gap first — help desk work touches both constantly.

Beyond the certification

  • Ticketing systems
  • Clear written communication
  • Basic Active Directory/M365 administration

Suggested next step

Security+, or CCNA first if networking fundamentals are genuinely shaky

Desktop support technician

Security+ first, if networking is comfortable

Desktop support already lives close to identity, endpoints, and access issues — Security+ formalizes vocabulary you're already using informally.

Beyond the certification

  • Endpoint management (Intune, Jamf, etc.)
  • MFA and conditional access troubleshooting
  • Basic scripting for repetitive tasks

Suggested next step

Security+, then SOC-adjacent hands-on labs

NOC analyst

CCNA first

NOC work is monitoring, escalation, and connectivity triage across a real network — CCNA's depth in interface diagnostics, routing, and VLANs maps directly onto the job.

Beyond the certification

  • Monitoring tools (SolarWinds, PRTG, etc.)
  • Escalation documentation and evidence-gathering
  • Shift-based troubleshooting under time pressure

Suggested next step

CCNA, then Security+ if you want a broader security-adjacent skill set later

Network technician

CCNA first

This is CCNA's home turf — cabling, connectivity, interface diagnostics, and VLAN assignment are exam content, not tangential skills.

Beyond the certification

  • Physical cabling and rack work
  • Vendor hardware beyond Cisco (if your shop is mixed)
  • Change-management discipline

Suggested next step

CCNA, then CCNP ENCOR or Security+ depending on direction

Network administrator

CCNA first

Administering a network you don't deeply understand is how outages happen. CCNA builds the routing, switching, and troubleshooting foundation the role assumes.

Beyond the certification

  • Change management
  • Documentation discipline
  • Vendor and ISP relationship management

Suggested next step

CCNA, then Security+ to strengthen access-control and policy awareness

Network engineer

CCNA first

Engineering-level network design and troubleshooting requires the depth CCNA provides — this isn't a certification you skip on the way to that job.

Beyond the certification

  • Design documentation
  • Capacity planning
  • Vendor-specific advanced features beyond CCNA scope

Suggested next step

CCNA → CCNP ENCOR, with Security+ as a later add-on

SOC analyst

Depends on existing networking ability

A SOC analyst who cannot explain normal traffic will have a rough time deciding what abnormal traffic looks like. If networking is weak, spend real time there — even informally — before or alongside Security+. If it's already solid, go straight to Security+ and hands-on SOC labs.

Beyond the certification

  • Log analysis (SIEM tools)
  • Alert triage under volume
  • Writing clear incident notes

Suggested next step

Security+ (or networking foundations first), then SOC-specific log-analysis practice, then CySA+

IAM analyst

Security+ first

IAM is squarely inside Security+'s identity and access domain — you'll be productive faster building on that than on CCNA's networking-first approach.

Beyond the certification

  • Active Directory and Entra ID administration
  • SSO/federation platforms in practice
  • Access-review and provisioning workflows

Suggested next step

Security+, then hands-on Active Directory/Entra ID labs and real IAM projects

GRC analyst

Security+ first

Security+'s governance, risk, and compliance domain is 20% of the exam — directly relevant. CCNA has essentially nothing to offer this specific role.

Beyond the certification

  • Framework-specific knowledge (NIST, ISO 27001, SOC 2)
  • Policy writing
  • Audit coordination

Suggested next step

Security+, then framework-specific study and real risk-register/policy projects

Vulnerability analyst

Security+ first

Vulnerability management is a named Security+ domain topic — prioritization logic, scanning concepts, and remediation workflows are covered directly.

Beyond the certification

  • Scanner tools (Nessus, Qualys, etc.)
  • CVSS scoring in practice
  • Patch-management coordination

Suggested next step

Security+, then hands-on scanner practice and CVE research

Penetration tester

Networking foundation first, then Security+, then real offensive-security training

Security+ is not a hacking certification, and neither is watching someone run a scanner on YouTube. You need real networking literacy, Linux/Windows fundamentals, and web fundamentals before offensive-security training actually clicks.

Beyond the certification

  • Linux and Windows internals
  • Scripting (Python/Bash)
  • Web application fundamentals
  • A real offensive-security course after this foundation

Suggested next step

Networking foundations (CCNA-level or equivalent) → Security+ → dedicated offensive-security training

Systems administrator

Security+ first, if networking basics are already comfortable

Sysadmin work already touches identity, patching, and access control daily — Security+ formalizes that. If routing/subnetting genuinely trips you up, patch that gap alongside it, not instead of it.

Beyond the certification

  • Server administration (Windows/Linux)
  • Patch management
  • Backup and DR practice

Suggested next step

Security+, then security-operations and cloud/identity labs

Cloud-security engineer

Depends on your infrastructure background

Weak networking background: get CCNA-level fundamentals first — cloud security still runs on the same addressing, routing, and segmentation concepts. Strong infrastructure background already: go straight to Security+, then add a cloud platform's own security specialization.

Beyond the certification

  • A cloud platform (AWS/Azure/GCP) security specialization
  • Infrastructure-as-code security
  • Cloud-native monitoring tools

Suggested next step

CCNA or Security+ depending on background, then a cloud-security specialization

Firewall / network-security engineer

CCNA first, then Security+

You can't secure a network you don't understand. CCNA gives you the routing/switching/addressing foundation; Security+ adds the security-control vocabulary before moving into firewall-specific training.

Beyond the certification

  • Vendor-specific firewall platforms (Palo Alto, Fortinet, etc.)
  • VPN and NAC configuration
  • Change control for security-critical devices

Suggested next step

CCNA → Security+ → firewall-specific vendor training

Same problem, two perspectives

How each certification thinks through the same incident.

A user can't reach an application

CCNA thinking

  • Interface/link state
  • VLAN assignment
  • IP configuration
  • Default gateway
  • DNS resolution
  • Routing table
  • ACL behavior
  • NAT translation
  • Overall packet path

Security+ thinking

  • Authentication failure
  • Account lockout status
  • Access-control policy
  • Certificate validity
  • Firewall restriction
  • Possible malicious activity
  • Logging for evidence
  • Incident escalation criteria
  • Data sensitivity involved

Competent professionals often need both lenses — the CCNA lens tells you what the traffic is actually doing; the Security+ lens tells you whether it should be doing it.

A suspicious outbound connection appears

CCNA thinking

  • Source and destination
  • Port and protocol
  • Route taken
  • NAT translation
  • VLAN of origin
  • Expected ACL behavior
  • Whether this packet path is even expected

Security+ thinking

  • Threat indicators present
  • Possible malware behavior
  • Severity assessment
  • Containment options
  • Evidence preservation
  • Incident-response next actions
  • Reporting requirements

Networking tells you what the traffic is doing. Security helps you decide whether it should be doing it, and what to do next.

Certification roadmap branches from IT foundations toward CCNA and Security+, continuing to CCNP ENCOR, firewall specialization, SOC, IAM, or GRC

Free roadmaps

Six sensible orders, depending on where you're headed.

Complete beginner

  1. IT foundations (OS basics, file systems, command line)
  2. Networking foundations
  3. CCNA or Security+, based on the role you actually want

Networking and network security

  1. CCNA
  2. Security+
  3. CCNP ENCOR or a firewall/network-security specialization

SOC and blue team

  1. Networking foundations
  2. Security+
  3. Log analysis and SOC-style labs
  4. CySA+ or role-specific development

IAM

  1. IT support foundations
  2. Security+
  3. Active Directory and Entra ID labs
  4. Real IAM projects

GRC

  1. Security+
  2. Risk and policy projects
  3. Framework-specific development (NIST, ISO 27001, SOC 2)

Network engineer moving into security

  1. CCNA
  2. Security+
  3. Firewall, VPN, NAC, or network-security specialization

Free readiness checklists

Where do you actually stand?

Beginner readiness checklist

  • I can explain what an IP address is, in my own words
  • I can explain what a port is
  • I can explain what DNS does
  • I've used a command line (any OS) at least a little
  • I know the difference between an operating system and an application
  • I can explain what a file permission is
  • I've never used a command line, and none of the above feel familiar yet → start with IT foundations, not a cert

CCNA readiness checklist

  • I can subnet an IPv4 address by hand, or I'm willing to learn it properly
  • I understand the difference between a switch and a router
  • I know what a VLAN is for
  • I'm comfortable typing commands into a CLI and reading the output
  • I like troubleshooting — building something, breaking it, and fixing it
  • I have 8+ hours a week I can realistically commit for 2-4 months

Security+ readiness checklist

  • I already understand basic networking (IP addresses, DNS, ports)
  • I work in or around IT today (help desk, support, admin, identity, cloud)
  • I can explain the difference between authentication and authorization
  • I'm comfortable with broad conceptual material, not just hands-on configuration
  • I have a specific security-adjacent role in mind, not just "cybersecurity" in the abstract
  • I have 6+ hours a week I can realistically commit for 6-10 weeks

Use your browser's print function (or the buttons above) to save any section of this page as a PDF — no account, no email, no payment.

Myths, addressed directly

Things people repeat that aren't quite true.

"Security+ guarantees a cybersecurity job."

It may help you pass an HR keyword filter and establish real foundational knowledge. It does not replace hands-on experience, projects, troubleshooting ability, communication skills, or a strong interview.

"CCNA is useless because it's vendor-specific."

The CLI commands are Cisco-specific. Routing logic, switching concepts, VLANs, subnetting, packet forwarding, ACL logic, and troubleshooting methodology are not — they transfer to every vendor you'll ever touch.

"CCNA is only useful for network engineers."

It's primarily a networking certification, but networking literacy is directly useful in cloud, security, systems administration, incident response, and support roles — a surprising number of "security incidents" turn out to be a bad route or a broken DNS record.

"Security+ teaches ethical hacking."

It covers attack types and defensive concepts at a conceptual level. It is not a penetration-testing course, and it won't teach you to actually run one.

"I need both certifications before I apply for anything."

Apply when you can demonstrate useful, relevant skills. Don't wait until your resume looks like a certification sticker collection with no projects behind it.

"One certification is always better than the other."

The right certification depends on the job you're trying to do. A wrench isn't better than a multimeter — it's better when the problem actually requires a wrench.

"A certification replaces hands-on experience."

It doesn't. Both certifications are foundations — proof you understand the concepts. The job itself starts where the multiple-choice question ends.

The bottom line

Here is the bottom line: CCNA teaches you how networks work. Security+ teaches you how organizations protect systems and manage security risk. If your networking foundation is weak, fix it. If you already understand the network and want to move into security, take Security+. If your target role needs both, then congratulations—you found the answer nobody on social media wanted to give you: you probably need both, just not at the same time.

Last reviewed: July 21, 2026 · CCNA: 200-301 (CCNA v1.1 (effective since August 20, 2024)) · Security+: SY0-701 (Security+ V7 (launched November 7, 2023))

Sources: Cisco's official CCNA exam topics (PDF) · CompTIA's official Security+ certification page

CompTIA's own page lists Security+ retirement as "usually three years after launch" — SY0-701 launched November 2023, so a successor version could be announced before this page's next review. As of the last-reviewed date above, SY0-701 is still CompTIA's current, active exam.

Exam prices, durations, and formats can change without notice. Verify current details directly with Cisco and CompTIA before registering. This page does not reproduce any proprietary exam questions, official paid training material, or confidential exam content.