My Cert Stack So Far: ISC² CC + SC-900 and What Each One Actually Taught Me
- Jul 24
- 5 min read
Two certs on my entry-level path — one I've gone deep on, one I've previewed hands-on. This is the honest version: what the material revealed, and where it exposed gaps I didn't know I had.
The short version
A cert's real value isn't the badge — it's the precise map of your own blind spots it hands you.
CC's hardest domain wasn't the one I expected. Network security (Domain 4) was the unfamiliar ground, not the areas closest to my analyst work.
The OSI model and the port landscape — DNS on port 53 and the rest — were genuine gaps. You can't reason about network anomalies without them.
SC-900 is a preview, not a post-mortem. I haven't started studying it yet, but a hands-on AI Skills Fest session earned it a spot on the roadmap.
The two fit cleanly: CC is the vendor-neutral vocabulary, SC-900 is where that vocabulary meets a real cloud environment
Cert roadmaps get sold as checklists. Pass this, then that, then you're "ready." What nobody tells you is that the real value of a cert isn't the badge — it's the map of your own blind spots it hands you along the way.
So instead of a which-should-you-take-first listicle, here's a genuine reflection on the two certs anchoring my transition into security: ISC² Certified in Cybersecurity (CC), the one I've studied hardest, and Microsoft SC-900, the one I've had a hands-on taste of and have queued up next. Different gaps exposed, and once I stepped back, a surprisingly clean fit.
ISC² CC — the foundation
What CC actually taught me
CC is broad by design — five domains covering security principles, business continuity, access control, network security, and operations. Coming in as a data analyst, I assumed the domains closest to my existing work would be the hard ones. They weren't. Domain 4 — network security — was where I hit real, unfamiliar ground.
I'd heard of switches and routers. But the OSI model was genuinely new to me — the idea that network communication is layered, and that a problem lives at a specific layer, was a mental model I simply didn't have. I'd worked with FTP before, so that port felt familiar, but the rest of the port landscape was foreign territory. DNS took me a while to sit with before it clicked: it's the system that resolves domain names, and it runs on port 53. Obvious now. Not obvious three months ago.
Here's the thing about that gap: it's the one I'm most glad the cert forced me to close. You can't reason about network anomalies — the whole point of the SOC work I'm aiming at — if you can't picture where traffic lives and which port is doing what. CC didn't just test me on it; it exposed that I needed it.
That's the reframe I keep coming back to. CC's value wasn't confirming what I knew. It was drawing a clear line around what I didn't — vocabulary, protocols, the plumbing underneath the dashboards I'd spent a decade building on top of.
The OSI model gave me a layered way to locate a problem instead of treating the network as one opaque box.
Ports stopped being trivia — FTP I knew, but DNS on port 53 and the rest filled in a map I'll use constantly in detection work.
The scope showed me security is a governance-and-vocabulary discipline first, before it's ever a tooling one.
Most useful of all: it named my blind spots so I could actually study them, instead of not knowing they were there.
SC-900 — the preview
What SC-900 has shown me so far
I'll be straight about where I am with this one: I haven't started studying for SC-900 yet. I'm heads-down on CC first, and SC-900 is next in the queue. I've already had a hands-on preview, and it's the reason this cert earned a spot on my roadmap rather than a random Microsoft badge I picked off a list.
During the AI Skills Fest, I got to actually set up Microsoft's security tools to defend a business — not read about them, configure them. That hands-on hour did something a study guide can't: it made the SC-900 material concrete before I cracked it open. Where CC is vendor-neutral fundamentals, SC-900 is the cloud and Microsoft ecosystem — identity, compliance, and the security tooling that sits inside it.
So this section is a preview, not a post-mortem. I can already see the shape of it: CC taught me the concepts; SC-900 is where I'll learn how one major cloud vendor actually implements them. I'd rather tell you that honestly than pretend I've closed a book I haven't opened.
Hands-on setup during AI Skills Fest turned abstract "cloud security" into something I'd actually touched.
It clarified why SC-900 belongs on my path: the detection roles I'm targeting live in the cloud, not on-prem infrastructure.
It set my expectation — this cert is about a specific ecosystem's implementation, a deliberate complement to CC's neutral foundation
How they fit together
Step back, and the stack isn't two random certs — it's two layers of the same thing. CC gave me the vocabulary and the mental models: OSI, ports, access control, the language security people use. It's the neutral foundation that lets you talk to anyone in the field.
SC-900 is where that vocabulary meets a real environment. Concepts become configurations. The map becomes the territory — specifically the cloud territory where the detection work I'm building toward actually happens. One teaches you the language; the other teaches you to speak it somewhere real.
The cert doesn't just prove what you know. Done right, it hands you a precise map of what you don't — and that map is the actual gift.
If you're mapping your own entry-level security path, that's the reframe I'd offer: don't chase certs to collect badges. Chase them for the blind spots they'll expose. CC found mine in the network layer. SC-900 will find the next batch in the cloud. And every gap named is one you can finally close.
I'm heads-down on the CC retake right now, and I'll write the SC-900 chapter honestly once I've actually lived it. That's the whole point of building in public — you get the real version, gaps and all.
This post is basically me living out Square 24 — Earn Your Certification on the Foundations Bingo board. If you're working your own board, that square isn't about the badge on the wall — it's about the blind spots you close getting there. Go find yours. 💜
The tool changes, the question doesn't 💜



Comments