A duplication job fails at three in the morning, the storage lifecycle policy behind it stalls, and the catalog backup that was supposed to run afterwards never starts. Nobody configured anything that night. Somebody has to work out what happened, in what order, and what to restart first.
That night is what the Cohesity NetBackup certification examines. COH284, the Cohesity Certified Protection Professional for NetBackup, gives 36 percent of its marks to monitoring and maintaining an estate and 23 percent to troubleshooting it, against 31 percent for configuring it. Sixty questions, 105 minutes, a 65 percent pass mark and a 200 USD fee, with the credential expiring after two years.
Table of Contents
- What does COH284 actually ask you to prove?
- What are the COH284 exam facts?
- Why does monitoring outweigh configuring?
- The storage and deduplication objectives that catch people out
- What does a catalog recovery question look like?
- The vendor terms almost nobody else publishes
- Where does this sit in the Cohesity certification track?
- Who should sit this exam?
- How should you prepare for 60 questions in 105 minutes?
- Frequently Asked Questions
- Conclusion
What does COH284 actually ask you to prove?
COH284 verifies that you can configure, manage, administer and troubleshoot a NetBackup environment day to day. Cohesity’s own description names basic NetBackup architecture, configuring backups and restores, configuring storage devices, implementing specialised backup solutions, and troubleshooting failed jobs, device and media connectivity problems and disaster recovery situations including catalog recovery.
Read that list again and notice what is missing. There is no design domain, no capacity planning, no architecture selection. This is an operator’s credential, aimed at the person who keeps an existing estate running rather than the person who specified it.
The product history explains a lot about the credential’s shape. NetBackup is decades old and arrived at Cohesity through the Veritas data protection merger, which is why the vendor name on the certificate is newer than the software, and why the official exam page still sits at a URL carrying the old Veritas exam code. If your NetBackup knowledge predates the rebrand, it has not gone stale.
What are the COH284 exam facts?
COH284 is 60 questions in 105 minutes with a 65 percent pass mark, priced at 200 USD and registered through Cohesity rather than a third-party test centre network. That allows 105 seconds per question, which is generous by certification standards and reflects how much scenario reading the paper contains.
| Field | Value |
|---|---|
| Credential | Cohesity Certified Protection Professional, NetBackup |
| Exam code | COH284, written COH-284 by the vendor |
| Questions | 60 |
| Duration | 105 minutes |
| Passing score | 65 percent |
| Fee | 200 USD |
| Prerequisites | None |
| Language | English |
| Expiry | 2 years |
| Retake | Once every 14 days |
One note on sourcing. The duration, fee, pass mark, language, expiry and retake rule all appear on Cohesity’s own exam page and match the exam catalogue exactly. The question count of 60 does not appear in the vendor’s published list, so treat it as the catalogue figure rather than a vendor-confirmed one.
Because the paper is weighted toward running an estate rather than building one, the fastest way to find your real gaps is to answer items in the exam’s own shape, and a COH284 practice test will show whether your monitoring knowledge matches your configuration knowledge.
Why does monitoring outweigh configuring?
Monitor and Maintain NetBackup is worth 36 percent, the single largest domain, while Configure NetBackup is worth 31 percent, Troubleshoot NetBackup 23 percent and Tune NetBackup 10 percent. Nearly three fifths of the paper therefore lands on what happens after the estate is built, which mirrors how the job actually divides.
| Domain | Weight | Roughly how many of 60 questions |
|---|---|---|
| Monitor and Maintain NetBackup | 36% | 22 |
| Configure NetBackup | 31% | 19 |
| Troubleshoot NetBackup | 23% | 14 |
| Tune NetBackup | 10% | 6 |
The Monitor and Maintain objectives are unusually specific. They name image management through the administration console, verifying, expiring, importing and manually duplicating images, managing disk and cloud storage, interpreting reports, and deciding when to prioritise, cancel, suspend, resume, restart, retry or manually run a job. They also name role-based access control, host ID certificates, applying updates through VxUpdate, and configuring anomaly and malware detection.
That last pair is the clearest signal of where backup software has moved. Detecting ransomware behaviour inside backup data is now an administration task rather than a security team’s problem, and it sits inside the largest domain of an operator exam. The control frameworks agree: data recovery is a top-level control in the CIS Controls precisely because recovery is what an attack tests.
The storage and deduplication objectives that catch people out
The Configure domain reaches much further than policies and schedules. It names synthetic backups, True Image Restore, multiple data streams, checkpoint restart, disk staging, Storage Lifecycle Policies, Auto Image Replication, Isolated Recovery Environment and NetBackup Accelerator, and then a full deduplication list on top of that.

The deduplication objectives are the ones candidates underestimate. Media server deduplication, client-side deduplication, optimised duplication, KMS options, MSDP cloud storage, WORM storage, Universal Shares, Snapshot Manager and storage servers all appear by name. These are not interchangeable features, and questions turn on which one solves a stated constraint rather than on what each one is.
A worked example makes the pattern obvious. If a remote site has a thin link and a short backup window, client-side deduplication moves less data across it; if the requirement is instead that copies cannot be altered for a retention period, WORM storage is the answer and deduplication is irrelevant. The exam asks that kind of question repeatedly, which is why memorising feature definitions produces a near miss rather than a pass.
Why immutability keeps appearing
WORM storage, KMS-managed encryption and an isolated recovery environment are three objectives pointing at one idea: a backup copy an attacker cannot quietly modify. Federal storage security guidance sets out the same requirement in detail, and NIST SP 800-209 is the reference worth reading once if these controls are new to you, because it explains why they exist rather than merely how to switch them on.
What does a catalog recovery question look like?
Troubleshoot NetBackup is 23 percent of the paper and the objectives name failed jobs, device and media connectivity problems, common disaster recovery situations and catalog recovery specifically. A catalog question tends to describe a loss, give you a partial set of facts, and ask what must be true before a restore can even begin.

The catalog is where the pattern is clearest, because it is the one component whose loss changes the order of everything else. If the catalog is gone, the images may still exist on storage but the system cannot find them, so the recovery sequence starts with the catalog backup rather than with the data, and a candidate who has never rehearsed that sequence will pick a plausible wrong answer.
Tune NetBackup, at 10 percent, is the smallest domain and the vaguest: analyse, optimise and tune. In practice that means recognising where a bottleneck sits when a job runs slowly rather than fails, which is a different diagnostic habit from fault finding and worth six questions.
The vendor terms almost nobody else publishes
Cohesity publishes four commercial terms on its exam page that most third-party write-ups omit entirely: there are no prerequisite exams or certifications, the exam is delivered in English, the credential expires after two years, and a failed attempt can be retaken once every 14 days.
The two-year expiry is the one to plan around. A credential with a two-year life is a commitment to revisit the product on a fixed cycle, and for a working NetBackup administrator that is usually reasonable, since the platform changes in that time anyway. For someone certifying to clear a hiring filter rather than to do the work, it is a recurring cost worth knowing about before booking.
The 14-day retake window is mild by industry standards and effectively removes the case for gambling on an early attempt: waiting a fortnight is rarely worse than sitting underprepared, and the second attempt costs the full fee again. Both facts come straight from the official exam page, which is worth checking yourself before you book in case the terms move.
Where does this sit in the Cohesity certification track?
Protection Professional is the working administrator tier of the Cohesity scheme, below the Architect Expert credential and alongside the Security Specialist track. Because it carries no prerequisites, it can be a first Cohesity credential or a later one, and the NetBackup variant is distinct from the Cohesity-platform variant that shares the tier.
That distinction causes real confusion. COH-285 is the Protection Professional exam for the Cohesity data platform itself, while COH284 is the NetBackup one, and search demand for the two codes runs side by side. They are not alternative names for one exam, and material written for one does not prepare you for the other.
If security controls rather than day-to-day operations are your direction, the specialist route is the better next step, and the COH350 security specialist credential goes deep on the areas COH284 touches only through its anomaly detection and RBAC objectives.
Who should sit this exam?
COH284 suits backup administrators running NetBackup daily, infrastructure engineers who inherited it as part of a wider platform, managed service staff supporting multiple NetBackup estates, and Cohesity partners who need a demonstrable product credential. Cohesity recommends roughly three months of hands-on experience, and that is a fair floor rather than a formality.
It is a weak fit for two groups. Anyone who has never operated NetBackup will find the monitoring and troubleshooting domains, 59 percent of the paper between them, almost impossible to prepare for from reading alone. Anyone looking for a vendor-neutral data protection credential will find this deeply product specific, which is its value if you run the product and its limitation if you do not.
For someone earlier in the Cohesity track, the platform-side entry credential is the gentler introduction, and the COH125 career path route makes more sense before taking on an exam weighted this heavily toward operational recall.
How should you prepare for 60 questions in 105 minutes?
Prepare against the objective list, weight your time toward the two operational domains, and rehearse the sequences rather than the definitions. With 105 seconds per question the clock is not the enemy, so the real risk is answering plausibly rather than correctly on scenarios you have never actually performed.
- Read the published objectives and mark every feature you have configured yourself. The unmarked ones are your study list.
- Spend roughly 60 percent of your time on Monitor and Maintain and Troubleshoot. They are 35 of the 60 questions.
- Rehearse a catalog recovery end to end in a lab, because the sequence is what the questions test.
- Build a one-page table of the deduplication options with the constraint each one solves.
- Work through the job-state verbs deliberately: prioritise, cancel, suspend, resume, restart, retry and manually run are not synonyms, and the exam treats them as distinct.
- Sit a full timed set before booking, and treat anything below 70 percent as a signal to go back to the objectives rather than to the calendar.
Anomaly and malware detection deserves a dedicated evening. It is newer than most of the syllabus, it sits in the largest domain, and it is the area where experienced NetBackup administrators are most likely to be out of date.
Frequently Asked Questions
How many questions are on the COH284 exam?
Sixty questions in 105 minutes, which allows about 105 seconds each.
What is the passing score for COH284?
Sixty-five percent, which on a 60 question paper means 39 correct answers.
How much does the Cohesity NetBackup certification cost?
Two hundred US dollars, registered through Cohesity rather than a third-party test centre network.
Does COH284 have prerequisites?
None. Cohesity states plainly that there are no prerequisite exams or certifications, though it recommends about three months of practical experience.
How long is the credential valid?
Two years. Cohesity publishes the expiry on the exam page, so plan for a recertification cycle rather than a one-off.
What happens if I fail COH284?
You may retake it after 14 days, at the full fee. There is no published discount for a second attempt.
What is the difference between COH284 and COH-285?
COH284 is the Protection Professional exam for NetBackup; COH-285 is the Protection Professional exam for the Cohesity data platform. Different products, different objectives, and material for one does not prepare you for the other.
Which domain carries the most marks?
Monitor and Maintain NetBackup at 36 percent, ahead of Configure at 31 percent, Troubleshoot at 23 percent and Tune at 10 percent.
Is this still a Veritas certification?
No. NetBackup came to Cohesity through the Veritas data protection merger, so the credential is issued by Cohesity even though the product and much of the older study material carry Veritas branding.
Is the exam available in languages other than English?
Cohesity lists English only on the exam page.
Conclusion
COH284 is an operator’s credential for people who run NetBackup rather than design it. Sixty questions, 105 minutes, 65 percent to pass, 200 USD, no prerequisites, English only, and a two-year life.
The weighting is the whole story. Monitoring, maintaining and troubleshooting carry 59 percent of the marks between them, so preparation that concentrates on configuration steps will feel productive and score badly. Rehearse the sequences instead: a catalog recovery, a stalled duplication, a job that has to be suspended rather than cancelled.
Read Cohesity’s published terms before booking, give anomaly and malware detection an evening of its own, and sit a timed set first. Fourteen days between attempts is a long time to wait for something a fortnight of targeted preparation would have fixed.
