top of page

My Cert Stack So Far: ISC² CC + SC-900 and What Each One Actually Taught Me

  • Jul 24
  • 5 min read

Two certs on my entry-level path — one I've gone deep on, one I've previewed hands-on. This is the honest version: what the material revealed, and where it exposed gaps I didn't know I had.



The short version

  • A cert's real value isn't the badge — it's the precise map of your own blind spots it hands you.

  • CC's hardest domain wasn't the one I expected. Network security (Domain 4) was the unfamiliar ground, not the areas closest to my analyst work.

  • The OSI model and the port landscape — DNS on port 53 and the rest — were genuine gaps. You can't reason about network anomalies without them.

  • SC-900 is a preview, not a post-mortem. I haven't started studying it yet, but a hands-on AI Skills Fest session earned it a spot on the roadmap.

  • The two fit cleanly: CC is the vendor-neutral vocabulary, SC-900 is where that vocabulary meets a real cloud environment


Cert roadmaps get sold as checklists. Pass this, then that, then you're "ready." What nobody tells you is that the real value of a cert isn't the badge — it's the map of your own blind spots it hands you along the way.


So instead of a which-should-you-take-first listicle, here's a genuine reflection on the two certs anchoring my transition into security: ISC² Certified in Cybersecurity (CC), the one I've studied hardest, and Microsoft SC-900, the one I've had a hands-on taste of and have queued up next. Different gaps exposed, and once I stepped back, a surprisingly clean fit.


ISC² CC — the foundation


What CC actually taught me


CC is broad by design — five domains covering security principles, business continuity, access control, network security, and operations. Coming in as a data analyst, I assumed the domains closest to my existing work would be the hard ones. They weren't. Domain 4 — network security — was where I hit real, unfamiliar ground.


I'd heard of switches and routers. But the OSI model was genuinely new to me — the idea that network communication is layered, and that a problem lives at a specific layer, was a mental model I simply didn't have. I'd worked with FTP before, so that port felt familiar, but the rest of the port landscape was foreign territory. DNS took me a while to sit with before it clicked: it's the system that resolves domain names, and it runs on port 53. Obvious now. Not obvious three months ago.


Here's the thing about that gap: it's the one I'm most glad the cert forced me to close. You can't reason about network anomalies — the whole point of the SOC work I'm aiming at — if you can't picture where traffic lives and which port is doing what. CC didn't just test me on it; it exposed that I needed it.


That's the reframe I keep coming back to. CC's value wasn't confirming what I knew. It was drawing a clear line around what I didn't — vocabulary, protocols, the plumbing underneath the dashboards I'd spent a decade building on top of.


  • The OSI model gave me a layered way to locate a problem instead of treating the network as one opaque box.

  • Ports stopped being trivia — FTP I knew, but DNS on port 53 and the rest filled in a map I'll use constantly in detection work.

  • The scope showed me security is a governance-and-vocabulary discipline first, before it's ever a tooling one.

  • Most useful of all: it named my blind spots so I could actually study them, instead of not knowing they were there.

SC-900 — the preview


What SC-900 has shown me so far


I'll be straight about where I am with this one: I haven't started studying for SC-900 yet. I'm heads-down on CC first, and SC-900 is next in the queue. I've already had a hands-on preview, and it's the reason this cert earned a spot on my roadmap rather than a random Microsoft badge I picked off a list.


During the AI Skills Fest, I got to actually set up Microsoft's security tools to defend a business — not read about them, configure them. That hands-on hour did something a study guide can't: it made the SC-900 material concrete before I cracked it open. Where CC is vendor-neutral fundamentals, SC-900 is the cloud and Microsoft ecosystem — identity, compliance, and the security tooling that sits inside it.


So this section is a preview, not a post-mortem. I can already see the shape of it: CC taught me the concepts; SC-900 is where I'll learn how one major cloud vendor actually implements them. I'd rather tell you that honestly than pretend I've closed a book I haven't opened.


  • Hands-on setup during AI Skills Fest turned abstract "cloud security" into something I'd actually touched.

  • It clarified why SC-900 belongs on my path: the detection roles I'm targeting live in the cloud, not on-prem infrastructure.

  • It set my expectation — this cert is about a specific ecosystem's implementation, a deliberate complement to CC's neutral foundation

How they fit together


Step back, and the stack isn't two random certs — it's two layers of the same thing. CC gave me the vocabulary and the mental models: OSI, ports, access control, the language security people use. It's the neutral foundation that lets you talk to anyone in the field.

SC-900 is where that vocabulary meets a real environment. Concepts become configurations. The map becomes the territory — specifically the cloud territory where the detection work I'm building toward actually happens. One teaches you the language; the other teaches you to speak it somewhere real.

The cert doesn't just prove what you know. Done right, it hands you a precise map of what you don't — and that map is the actual gift.

If you're mapping your own entry-level security path, that's the reframe I'd offer: don't chase certs to collect badges. Chase them for the blind spots they'll expose. CC found mine in the network layer. SC-900 will find the next batch in the cloud. And every gap named is one you can finally close.


I'm heads-down on the CC retake right now, and I'll write the SC-900 chapter honestly once I've actually lived it. That's the whole point of building in public — you get the real version, gaps and all.

This post is basically me living out Square 24 — Earn Your Certification on the Foundations Bingo board. If you're working your own board, that square isn't about the badge on the wall — it's about the blind spots you close getting there. Go find yours. 💜

The tool changes, the question doesn't 💜

Comments


Let's learn this together. Have a question, a better query, or just want to say hi? Drop a line below.

© 2026 by DataSec Chronicles. Data-Inspired, Instinct-Driven.    Privacy Policy    Terms & Conditions

bottom of page