Certification Box https://www.certificationbox.com/ Prepared Well With Certification Box Fri, 25 Sep 2026 10:16:40 +0000 en-US hourly 1 https://wordpress.org/?v=7.1.2 https://www.certificationbox.com/wp-content/uploads/2026/04/cropped-CertificationBox-Mini-Logo-32x32.png Certification Box https://www.certificationbox.com/ 32 32 EXIN DevOps Professional Certification: DEVOPSP Exam https://www.certificationbox.com/2026/09/25/exin-devops-professional-certification-devopsp-exam/ Fri, 25 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=31064 No Jenkins, no Kubernetes, no Terraform, no cloud provider. An advanced DevOps exam that names no technology sounds like a contradiction until you read what it does name.

The post EXIN DevOps Professional Certification: DEVOPSP Exam appeared first on Certification Box.

]]>

There is not a single tool in this syllabus. No Jenkins, no Kubernetes, no Terraform, no cloud provider, no pipeline product of any kind. An advanced DevOps exam that names no technology sounds like a contradiction until you read what it does name: flow, feedback, and continual learning, weighted as if the organisation were the system under test.

The EXIN DevOps Professional certification, exam code DEVOPSP, is 40 multiple choice questions in 90 minutes at a 65 percent pass mark, priced at 295 USD and booked through EXIN. Five domains carry it, and the largest of them, at 30 percent, is feedback.

Table of Contents

  1. Why does an advanced DevOps exam name no tools?
  2. What are the DEVOPSP exam facts?
  3. How do the Three Ways shape the blueprint?
  4. What does the First Way of flow cover?
  5. Why is feedback the biggest domain?
  6. Which two domains do candidates skip?
  7. Foundation, Professional or Master?
  8. Who should take this exam?
  9. How should you prepare?
  10. Frequently Asked Questions
  11. Conclusion

Why does an advanced DevOps exam name no tools?

Because EXIN built the blueprint around the Three Ways rather than around a toolchain. The domains are named DevOps adoption, the First Way of flow, the Second Way of feedback, the Third Way of continual learning and experimentation, and information security and change management. Every one describes how work moves through an organisation, not what software moves it.

A tool exam asks you to name the setting, the EXIN DEVOPSP exam asks you to explain the system

That choice has a practical consequence for candidates. A tool-based exam ages the moment a vendor renames a product, and it rewards whoever has used that product most recently. A principle-based exam stays current for years and rewards whoever has watched delivery actually improve or fail somewhere, which is a different kind of experience and harder to cram.

It also changes what a wrong answer looks like. In a tool exam, wrong means you picked the incorrect flag. Here, wrong usually means you optimised the part instead of the whole: speeding up a deployment step while the queue in front of it grows, or adding a control that makes change safer and slower without measuring either.

What are the DEVOPSP exam facts?

DEVOPSP is 40 multiple choice questions in 90 minutes with a 65 percent pass mark, which means 26 correct answers. It costs 295 USD, is booked through EXIN rather than a test centre network, and is classified by EXIN at Advanced level rather than foundation.

Field Value
Credential EXIN DevOps Professional
Exam code DEVOPSP
Questions 40, multiple choice
Duration 90 minutes
Pass mark 65 percent, so 26 of 40
Fee 295 USD
Level Advanced
Open book No
Electronic equipment Not allowed
ECTS credits 3
Languages English, Chinese, Japanese, Portuguese

Every one of those figures except the fee is published by EXIN itself, and the duration, question count and pass mark match the exam catalogue exactly. The closed-book rule is worth noting early: this is a reasoning exam with no reference material, so the vocabulary has to be in your head rather than in a tab.

Two and a quarter minutes per question is comfortable for recall and tight for a scenario you have to reason through, which is what most of these are. Working through items in the exam’s own format is the cheapest way to find out which domains slow you down, and a DEVOPSP practice test will surface that faster than re-reading the syllabus.

How do the Three Ways shape the blueprint?

The Three Ways are the organising idea of modern DevOps literature: improve the flow of work from development to operations, amplify feedback from right to left, and build a culture of continual learning and experimentation. EXIN maps three of its five domains directly onto them, which makes the exam’s priorities unusually legible.

Domain Weight Roughly how many of 40 questions
DevOps adoption 12.5% 5
The First Way: flow 25% 10
The Second Way: feedback 30% 12
The Third Way: continual learning and experimentation 20% 8
Information security and change management 12.5% 5

Notice what that ordering does. Feedback outweighs flow, which is the opposite of how most teams actually invest: pipelines get built first and telemetry arrives later, if at all. The exam treats that sequence as the common mistake rather than the normal path, and weights accordingly.

The framing comes from the body of DevOps literature published by IT Revolution, which is worth knowing because the exam’s vocabulary is that literature’s vocabulary. Terms such as work in progress, technical debt, lead time and kata appear in the first domain and are used precisely.

What does the First Way of flow cover?

Flow is worth about 10 questions and breaks into four sub-areas with published weights: the deployment pipeline at 12.5 percent of the whole exam, automated testing at 5, continuous integration at 5 and low-risk releases at 2.5. The deployment pipeline alone is therefore half this domain and the single heaviest sub-area on the paper.

What the exam wants here is cause and effect rather than configuration. Why does a large batch size lengthen lead time. Why does an unreliable test suite push teams toward manual verification. Why does trunk-based work reduce merge pain while demanding more discipline. Each of those is a question shape, and none of them requires naming a product.

Low-risk releases, at only 2.5 percent, is the smallest sub-area and still worth reading properly, because the techniques it covers are the ones candidates most often know by a different name than EXIN uses.

Why is feedback the biggest domain?

Feedback is 30 percent of the exam, roughly 12 questions, and splits into telemetry at 7.5 percent, feedback itself at 10, hypothesis-driven development and A/B testing at 5, and review and coordination at 7.5. It is the largest domain and the one that separates a passing candidate from a near miss.

Four habits the EXIN DEVOPSP exam rewards: small batches, fast tests, live signals and blameless review

Telemetry questions are about knowing before the customer does: what to instrument, what a useful signal looks like, and why a dashboard nobody reads is not feedback. Review and coordination covers how changes get looked at, which is where peer review, pairing and change advisory processes are compared as feedback mechanisms rather than as governance.

Hypothesis-driven development is the sub-area most often skipped. It asks you to treat a feature as an experiment with a stated expectation and a measurable result, which is a genuinely different habit from shipping and hoping. The delivery research published through the DORA programme is the clearest public grounding for why these measures matter, and it is a useful read even though EXIN does not require it.

Which two domains do candidates skip?

The Third Way, continual learning and experimentation, is 20 percent and divides evenly between learning and discoveries at 10 percent each. It covers blameless retrospectives, the deliberate practice of improvement, and how an organisation turns an incident into something other than blame.

DevOps adoption, at 12.5 percent, is the entry domain: basic concepts including continuous delivery, agile infrastructure, kata, work in progress, technical debt and lead time, then the Three Ways as principles, then how teams and organisations are structured for it. It is five questions of vocabulary and framing, and it is the cheapest domain to secure.

Information security and change management, also 12.5 percent, splits into security at 7.5 percent and change management at 5. Its argument is that security is a shared responsibility built into the pipeline rather than a gate at the end, which is the position set out in the OWASP DevSecOps guideline and codified for software producers in NIST’s secure development framework.

Foundation, Professional or Master?

EXIN runs three DevOps tiers. Foundation introduces the concepts, Professional is this exam at Advanced level, and Master sits above both. Search demand is heaviest on Foundation, which tells you where most candidates start, and the Professional exam assumes the Foundation material rather than repeating it.

The choice is mostly about what you need to do with the credential. Foundation demonstrates literacy and suits people entering the field or adjacent to it. Professional targets people who influence how delivery works: team leads, engineering managers, consultants and senior engineers who are asked why the pipeline is not making things faster.

Anyone weighing this against EXIN’s other credentials will find the scheme consistent in format across its catalogue, and the EXIN Cloud Computing Foundation route shows what the vendor’s foundation tier looks like in practice before you commit to an advanced paper.

Who should take this exam?

DEVOPSP suits engineers and leads who have lived through a delivery transformation, consultants who advise on one, and managers who need a defensible vocabulary for arguing about flow and feedback. EXIN publishes no formal prerequisite, but the Advanced classification is honest about the level.

It is a poor fit for someone looking for a hands-on credential. If your goal is to prove you can build a pipeline, this exam will not test that and a tool-specific certification will. It is equally a poor fit for someone with no exposure to a real delivery organisation, because the scenarios assume you have seen work queue up behind a bottleneck.

For candidates who prefer process credentials generally, the same vendor’s improvement track covers adjacent ground, and the Lean Six Sigma Green Belt shares the measurement mindset that the feedback domain rewards here.

How should you prepare?

Read the Three Ways literature once properly, then study the blueprint’s sub-weightings, because EXIN publishes them and they tell you exactly where the marks are. With 40 questions and a closed book, the goal is fluent vocabulary plus the ability to reason about a delivery system end to end.

  1. Download EXIN’s preparation guide and sample exam, both published on the credential page, and sit the sample before studying so you know your starting point.
  2. Give feedback and flow roughly half your time. Together they are 22 of the 40 questions.
  3. Learn the vocabulary of the adoption domain precisely: work in progress, technical debt, lead time and kata are used in their exact senses.
  4. For each sub-area, write down one real example from somewhere you have worked. Scenario questions are easier when you have a concrete case to map them onto.
  5. Practise explaining why a local optimisation can slow the whole system. That idea underlies more questions than any single technique.
  6. Rehearse under the clock at closed-book conditions, since no reference material is allowed in the exam.

One more thing worth checking before you book: the exam is offered in English, Chinese, Japanese and Portuguese, so a candidate who would rather sit it in one of the latter three does not need to translate the vocabulary twice.

Frequently Asked Questions

How many questions are on the DEVOPSP exam?

Forty multiple choice questions in 90 minutes, confirmed on EXIN’s own page.

What is the pass mark for EXIN DevOps Professional?

Sixty-five percent, which is 26 correct answers out of 40.

How much does the exam cost?

Two hundred and ninety-five US dollars through the exam catalogue. EXIN does not publish a price on the credential page itself, so confirm it when booking.

Is the exam open book?

No. EXIN states plainly that it is closed book and that no electronic equipment is allowed.

What level is this certification?

EXIN classifies it as Advanced, above its Foundation tier and below Master.

Are there prerequisites?

None are published, though the Advanced classification and the blueprint both assume working familiarity with DevOps practice.

Which domain carries the most marks?

The Second Way, feedback, at 30 percent, which is about 12 of the 40 questions.

Does the exam test specific tools?

No. The blueprint names no products at all. It examines flow, feedback, learning, adoption, security and change management as practices.

What languages is the exam available in?

English, Chinese, Japanese and Portuguese.

Does it carry academic credit?

EXIN lists three ECTS credits for this certification.

Conclusion

DEVOPSP is a principles exam wearing an advanced badge. Forty questions, 90 minutes, 65 percent to pass, 295 USD, closed book, and five domains built on the Three Ways rather than on any toolchain.

The weighting is the instruction. Feedback at 30 percent and flow at 25 percent are 22 of the 40 questions, and the exam consistently rewards the candidate who can explain why improving one stage made the whole system slower. Adoption and security are cheap marks by comparison, and worth securing early.

Download EXIN’s preparation guide and sample exam, map each sub-area onto something you have actually watched happen, and rehearse closed book. A syllabus with no tools in it is not an easier exam. It is a different one.

Rating: 0 / 5 (0 votes)

The post EXIN DevOps Professional Certification: DEVOPSP Exam appeared first on Certification Box.

]]>
Cohesity NetBackup Certification: Inside the COH284 Exam https://www.certificationbox.com/2026/09/25/cohesity-netbackup-certification-inside-the-coh284-exam/ Fri, 25 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=31057 A duplication job fails at three in the morning and the catalog backup behind it never starts. Nobody configured anything that night, and that is precisely where this exam puts most of its marks.

The post Cohesity NetBackup Certification: Inside the COH284 Exam appeared first on Certification Box.

]]>

A duplication job fails at three in the morning, the storage lifecycle policy behind it stalls, and the catalog backup that was supposed to run afterwards never starts. Nobody configured anything that night. Somebody has to work out what happened, in what order, and what to restart first.

That night is what the Cohesity NetBackup certification examines. COH284, the Cohesity Certified Protection Professional for NetBackup, gives 36 percent of its marks to monitoring and maintaining an estate and 23 percent to troubleshooting it, against 31 percent for configuring it. Sixty questions, 105 minutes, a 65 percent pass mark and a 200 USD fee, with the credential expiring after two years.

Table of Contents

  1. What does COH284 actually ask you to prove?
  2. What are the COH284 exam facts?
  3. Why does monitoring outweigh configuring?
  4. The storage and deduplication objectives that catch people out
  5. What does a catalog recovery question look like?
  6. The vendor terms almost nobody else publishes
  7. Where does this sit in the Cohesity certification track?
  8. Who should sit this exam?
  9. How should you prepare for 60 questions in 105 minutes?
  10. Frequently Asked Questions
  11. Conclusion

What does COH284 actually ask you to prove?

COH284 verifies that you can configure, manage, administer and troubleshoot a NetBackup environment day to day. Cohesity’s own description names basic NetBackup architecture, configuring backups and restores, configuring storage devices, implementing specialised backup solutions, and troubleshooting failed jobs, device and media connectivity problems and disaster recovery situations including catalog recovery.

Read that list again and notice what is missing. There is no design domain, no capacity planning, no architecture selection. This is an operator’s credential, aimed at the person who keeps an existing estate running rather than the person who specified it.

The product history explains a lot about the credential’s shape. NetBackup is decades old and arrived at Cohesity through the Veritas data protection merger, which is why the vendor name on the certificate is newer than the software, and why the official exam page still sits at a URL carrying the old Veritas exam code. If your NetBackup knowledge predates the rebrand, it has not gone stale.

What are the COH284 exam facts?

COH284 is 60 questions in 105 minutes with a 65 percent pass mark, priced at 200 USD and registered through Cohesity rather than a third-party test centre network. That allows 105 seconds per question, which is generous by certification standards and reflects how much scenario reading the paper contains.

Field Value
Credential Cohesity Certified Protection Professional, NetBackup
Exam code COH284, written COH-284 by the vendor
Questions 60
Duration 105 minutes
Passing score 65 percent
Fee 200 USD
Prerequisites None
Language English
Expiry 2 years
Retake Once every 14 days

One note on sourcing. The duration, fee, pass mark, language, expiry and retake rule all appear on Cohesity’s own exam page and match the exam catalogue exactly. The question count of 60 does not appear in the vendor’s published list, so treat it as the catalogue figure rather than a vendor-confirmed one.

Because the paper is weighted toward running an estate rather than building one, the fastest way to find your real gaps is to answer items in the exam’s own shape, and a COH284 practice test will show whether your monitoring knowledge matches your configuration knowledge.

Why does monitoring outweigh configuring?

Monitor and Maintain NetBackup is worth 36 percent, the single largest domain, while Configure NetBackup is worth 31 percent, Troubleshoot NetBackup 23 percent and Tune NetBackup 10 percent. Nearly three fifths of the paper therefore lands on what happens after the estate is built, which mirrors how the job actually divides.

Domain Weight Roughly how many of 60 questions
Monitor and Maintain NetBackup 36% 22
Configure NetBackup 31% 19
Troubleshoot NetBackup 23% 14
Tune NetBackup 10% 6

The Monitor and Maintain objectives are unusually specific. They name image management through the administration console, verifying, expiring, importing and manually duplicating images, managing disk and cloud storage, interpreting reports, and deciding when to prioritise, cancel, suspend, resume, restart, retry or manually run a job. They also name role-based access control, host ID certificates, applying updates through VxUpdate, and configuring anomaly and malware detection.

That last pair is the clearest signal of where backup software has moved. Detecting ransomware behaviour inside backup data is now an administration task rather than a security team’s problem, and it sits inside the largest domain of an operator exam. The control frameworks agree: data recovery is a top-level control in the CIS Controls precisely because recovery is what an attack tests.

The storage and deduplication objectives that catch people out

The Configure domain reaches much further than policies and schedules. It names synthetic backups, True Image Restore, multiple data streams, checkpoint restart, disk staging, Storage Lifecycle Policies, Auto Image Replication, Isolated Recovery Environment and NetBackup Accelerator, and then a full deduplication list on top of that.

COH284 deduplication and storage choices matched to constraints: client side for a thin link, WORM for locked copies, MSDP cloud for a cloud tier

The deduplication objectives are the ones candidates underestimate. Media server deduplication, client-side deduplication, optimised duplication, KMS options, MSDP cloud storage, WORM storage, Universal Shares, Snapshot Manager and storage servers all appear by name. These are not interchangeable features, and questions turn on which one solves a stated constraint rather than on what each one is.

A worked example makes the pattern obvious. If a remote site has a thin link and a short backup window, client-side deduplication moves less data across it; if the requirement is instead that copies cannot be altered for a retention period, WORM storage is the answer and deduplication is irrelevant. The exam asks that kind of question repeatedly, which is why memorising feature definitions produces a near miss rather than a pass.

Why immutability keeps appearing

WORM storage, KMS-managed encryption and an isolated recovery environment are three objectives pointing at one idea: a backup copy an attacker cannot quietly modify. Federal storage security guidance sets out the same requirement in detail, and NIST SP 800-209 is the reference worth reading once if these controls are new to you, because it explains why they exist rather than merely how to switch them on.

What does a catalog recovery question look like?

Troubleshoot NetBackup is 23 percent of the paper and the objectives name failed jobs, device and media connectivity problems, common disaster recovery situations and catalog recovery specifically. A catalog question tends to describe a loss, give you a partial set of facts, and ask what must be true before a restore can even begin.

NetBackup recovery order for COH284: catalog first, then images, then the restore itself

The catalog is where the pattern is clearest, because it is the one component whose loss changes the order of everything else. If the catalog is gone, the images may still exist on storage but the system cannot find them, so the recovery sequence starts with the catalog backup rather than with the data, and a candidate who has never rehearsed that sequence will pick a plausible wrong answer.

Tune NetBackup, at 10 percent, is the smallest domain and the vaguest: analyse, optimise and tune. In practice that means recognising where a bottleneck sits when a job runs slowly rather than fails, which is a different diagnostic habit from fault finding and worth six questions.

The vendor terms almost nobody else publishes

Cohesity publishes four commercial terms on its exam page that most third-party write-ups omit entirely: there are no prerequisite exams or certifications, the exam is delivered in English, the credential expires after two years, and a failed attempt can be retaken once every 14 days.

The two-year expiry is the one to plan around. A credential with a two-year life is a commitment to revisit the product on a fixed cycle, and for a working NetBackup administrator that is usually reasonable, since the platform changes in that time anyway. For someone certifying to clear a hiring filter rather than to do the work, it is a recurring cost worth knowing about before booking.

The 14-day retake window is mild by industry standards and effectively removes the case for gambling on an early attempt: waiting a fortnight is rarely worse than sitting underprepared, and the second attempt costs the full fee again. Both facts come straight from the official exam page, which is worth checking yourself before you book in case the terms move.

Where does this sit in the Cohesity certification track?

Protection Professional is the working administrator tier of the Cohesity scheme, below the Architect Expert credential and alongside the Security Specialist track. Because it carries no prerequisites, it can be a first Cohesity credential or a later one, and the NetBackup variant is distinct from the Cohesity-platform variant that shares the tier.

That distinction causes real confusion. COH-285 is the Protection Professional exam for the Cohesity data platform itself, while COH284 is the NetBackup one, and search demand for the two codes runs side by side. They are not alternative names for one exam, and material written for one does not prepare you for the other.

If security controls rather than day-to-day operations are your direction, the specialist route is the better next step, and the COH350 security specialist credential goes deep on the areas COH284 touches only through its anomaly detection and RBAC objectives.

Who should sit this exam?

COH284 suits backup administrators running NetBackup daily, infrastructure engineers who inherited it as part of a wider platform, managed service staff supporting multiple NetBackup estates, and Cohesity partners who need a demonstrable product credential. Cohesity recommends roughly three months of hands-on experience, and that is a fair floor rather than a formality.

It is a weak fit for two groups. Anyone who has never operated NetBackup will find the monitoring and troubleshooting domains, 59 percent of the paper between them, almost impossible to prepare for from reading alone. Anyone looking for a vendor-neutral data protection credential will find this deeply product specific, which is its value if you run the product and its limitation if you do not.

For someone earlier in the Cohesity track, the platform-side entry credential is the gentler introduction, and the COH125 career path route makes more sense before taking on an exam weighted this heavily toward operational recall.

How should you prepare for 60 questions in 105 minutes?

Prepare against the objective list, weight your time toward the two operational domains, and rehearse the sequences rather than the definitions. With 105 seconds per question the clock is not the enemy, so the real risk is answering plausibly rather than correctly on scenarios you have never actually performed.

  1. Read the published objectives and mark every feature you have configured yourself. The unmarked ones are your study list.
  2. Spend roughly 60 percent of your time on Monitor and Maintain and Troubleshoot. They are 35 of the 60 questions.
  3. Rehearse a catalog recovery end to end in a lab, because the sequence is what the questions test.
  4. Build a one-page table of the deduplication options with the constraint each one solves.
  5. Work through the job-state verbs deliberately: prioritise, cancel, suspend, resume, restart, retry and manually run are not synonyms, and the exam treats them as distinct.
  6. Sit a full timed set before booking, and treat anything below 70 percent as a signal to go back to the objectives rather than to the calendar.

Anomaly and malware detection deserves a dedicated evening. It is newer than most of the syllabus, it sits in the largest domain, and it is the area where experienced NetBackup administrators are most likely to be out of date.

Frequently Asked Questions

How many questions are on the COH284 exam?

Sixty questions in 105 minutes, which allows about 105 seconds each.

What is the passing score for COH284?

Sixty-five percent, which on a 60 question paper means 39 correct answers.

How much does the Cohesity NetBackup certification cost?

Two hundred US dollars, registered through Cohesity rather than a third-party test centre network.

Does COH284 have prerequisites?

None. Cohesity states plainly that there are no prerequisite exams or certifications, though it recommends about three months of practical experience.

How long is the credential valid?

Two years. Cohesity publishes the expiry on the exam page, so plan for a recertification cycle rather than a one-off.

What happens if I fail COH284?

You may retake it after 14 days, at the full fee. There is no published discount for a second attempt.

What is the difference between COH284 and COH-285?

COH284 is the Protection Professional exam for NetBackup; COH-285 is the Protection Professional exam for the Cohesity data platform. Different products, different objectives, and material for one does not prepare you for the other.

Which domain carries the most marks?

Monitor and Maintain NetBackup at 36 percent, ahead of Configure at 31 percent, Troubleshoot at 23 percent and Tune at 10 percent.

Is this still a Veritas certification?

No. NetBackup came to Cohesity through the Veritas data protection merger, so the credential is issued by Cohesity even though the product and much of the older study material carry Veritas branding.

Is the exam available in languages other than English?

Cohesity lists English only on the exam page.

Conclusion

COH284 is an operator’s credential for people who run NetBackup rather than design it. Sixty questions, 105 minutes, 65 percent to pass, 200 USD, no prerequisites, English only, and a two-year life.

The weighting is the whole story. Monitoring, maintaining and troubleshooting carry 59 percent of the marks between them, so preparation that concentrates on configuration steps will feel productive and score badly. Rehearse the sequences instead: a catalog recovery, a stalled duplication, a job that has to be suspended rather than cancelled.

Read Cohesity’s published terms before booking, give anomaly and malware detection an evening of its own, and sit a timed set first. Fourteen days between attempts is a long time to wait for something a fortnight of targeted preparation would have fixed.

Rating: 0 / 5 (0 votes)

The post Cohesity NetBackup Certification: Inside the COH284 Exam appeared first on Certification Box.

]]>
Genesys Workforce Management Certification: Cloud or Engage https://www.certificationbox.com/2026/09/23/genesys-workforce-management-certification-cloud-or-engage/ Wed, 23 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=31048 Their names differ by three words and they cost exactly the same, so the catalogues give you almost nothing to choose between them. The syllabuses, read side by side, give you everything.

The post Genesys Workforce Management Certification: Cloud or Engage appeared first on Certification Box.

]]>

There are two Genesys workforce management certifications, their names differ by three words, and they cost exactly the same. Book the wrong one and you will spend 580 dollars proving competence in a product your employer does not run. The catalogues list them one under the other and neither name makes the distinction obvious.

The Genesys workforce management certification you want depends on your platform. GCX-WFM covers Genesys Cloud CX and is 60 questions in 120 minutes at a 65 percent pass mark. GEOP-WFM covers Genesys Engage on-premises and is 45 questions in the same 120 minutes at 70 percent.

Table of Contents

  1. GCX-WFM or GEOP-WFM: which one is yours?
  2. What does the GCX-WFM exam look like?
  3. What do the five GCX-WFM sections cover?
  4. Why forecasting is the section that separates candidates
  5. What scheduling and time-off management really asks for
  6. What does the adherence section actually test?
  7. Who should take GCX-WFM?
  8. How should you prepare without published weightings?
  9. Frequently Asked Questions
  10. Conclusion

GCX-WFM or GEOP-WFM: which one is yours?

GCX-WFM is the Genesys Cloud CX workforce management credential and GEOP-WFM is the Genesys Engage on-premises one. They are not tiers of the same qualification and neither is a prerequisite for the other. The right choice is decided entirely by which platform your contact centre runs, not by which exam looks more impressive.

Field GCX-WFM GEOP-WFM
Platform Genesys Cloud CX Genesys Engage on-premises
Questions 60 45
Duration 120 minutes 120 minutes
Passing score 65 percent 70 percent
Price USD 580 USD 580
Delivered by Kryterion Webassessor Kryterion Webassessor
Recommended course Genesys Cloud: WEM – Workforce Management Genesys Engage on-premises Workforce Management – Operation

The syllabuses diverge more than the summary suggests. GEOP-WFM opens with an architecture section covering workforce management servers, the WFM database, web clients and integration with the CIM platform. Nothing equivalent exists in the cloud syllabus, because in Genesys Cloud those components are somebody else’s problem.

That is the real distinction. The on-premises exam asks you to understand and operate a system you host; the cloud exam assumes the system is simply there and asks whether you can run workforce management inside it. Practitioners who have worked through an Engage on-premises credential will recognise how much of that architecture layer the cloud exams drop.

What does the GCX-WFM exam look like?

GCX-WFM is 60 questions in 120 minutes with a 65 percent pass mark, priced at USD 580 and delivered through Kryterion Webassessor. Sixty-five percent of 60 is 39 correct answers, and two minutes a question is among the more generous allowances in the certification field.

Field Value
Exam name Genesys Cloud CX Workforce Management Certification
Exam code GCX-WFM
Questions 60
Duration 120 minutes
Passing score 65 percent, which is 39 correct answers
Price USD 580
Delivered by Kryterion Webassessor
Recommended training Genesys Cloud: WEM – Workforce Management
Sections 5, with no published weightings

One caveat belongs here rather than buried at the end. Genesys publishes its certification catalogue through a portal that renders entirely in the browser and returns no readable specification to anything but a human with a screen, so the figures above come from the money site’s syllabus page rather than from a vendor page that could be checked against it. No validity period or recertification rule is stated in this article, because no readable source publishes one.

If you want the section list alongside the exam terms, the money site’s GCX-WFM certification page sets the two out together.

What do the five GCX-WFM sections cover?

GCX-WFM has five sections and no published percentage weightings: workforce management overview and configuration, work plans and work plan rotations, forecasting, scheduling and time-off management, and real-time and historical adherence. Every objective is written as something you do in the product rather than as a concept you know.

The Genesys workforce management planning cycle running from historical data to forecast, schedule and adherence

That phrasing is the most useful signal available in the absence of weightings. The objective list reads like a task inventory, naming Add a business unit, Manage a management unit, Add a service goal template, Configure activity codes and dozens more in the same shape. These are the titles of articles in the product documentation, which tells you exactly where the questions come from.

Section What it asks you to be able to do
Overview and configuration Set up business units and management units, assign agents to management units and planning groups, configure service goal templates and activity codes, and understand WFM permissions and divisions
Work plans and rotations Build work plans with daily shifts and shift activities, assign agents to plans and rotations, validate configurations, and run work plan bids
Forecasting Import historical data, build and edit forecasts in the Forecast Editor, use continuous forecasting, and export a forecast into scheduling
Scheduling and time off Generate forecast-based and blank schedules, edit and publish them, swap shifts, manage staffing groups, and run time-off limits, plans, requests and trades
Real-time and historical adherence Read the Real-Time Adherence view, monitor agents, interpret historical adherence data, and use intraday monitoring

Read as a whole the five sections describe one continuous cycle rather than five subjects, which is how the exam treats them too. Configuration defines who can be scheduled, forecasting says how many are needed, scheduling produces the roster, and adherence measures whether reality matched it.

Why forecasting is the section that separates candidates

Forecasting is the section where product knowledge stops being enough. Configuring a management unit is a clerical task once you know where the screen is; producing a forecast that survives contact with a real week requires judgement about seasonality, trend, and which historical data deserves to be trusted.

The objectives name the mechanics: importing historical data, managing forecast source data, the Forecast Editor itself, continuous forecasting, and exporting a forecast into the scheduling workflow. What they do not say, and what the exam expects you to understand anyway, is why a forecast built on contaminated history produces a schedule that is confidently wrong.

Continuous forecasting is the modern part

Traditional forecasting produces a number for a period and leaves it there. Continuous forecasting keeps revising as new data arrives, which narrows the gap between what was planned and what actually happened. It is named as its own objective, which is a reliable sign it appears in the question set rather than sitting in the background.

The mathematics underneath

Contact centre staffing sits on a body of queueing theory that long predates any of these products. The Erlang unit of traffic is where the relationship between arrival rate, handling time and required agents comes from, and a WFM specialist who understands it reads a forecast differently from one who only knows which button generates it.

The exam does not test the mathematics directly. It tests decisions that only make sense if you have some grasp of it, which is a more demanding thing to prepare for.

What scheduling and time-off management really asks for

The scheduling section is the largest by objective count, and it splits into two halves that feel quite different. The first half is generating and publishing schedules from a forecast. The second half is the human machinery around them: time-off limits, time-off plans, request approvals, shift trades and staffing groups.

The second half is where candidates from a pure analytics background lose ground. Configuring a time-off limit is not difficult, but knowing what a limit does when three agents request the same week, and how that interacts with a published schedule, requires having watched it happen.

Blank schedules are a real exam topic

The objectives distinguish between forecast-based and blank schedules, and the distinction matters operationally. A blank schedule gives you a structure with no generated assignments, which is what you want when the forecast is not trustworthy or when a period is genuinely exceptional. Knowing when to reach for one is a judgement question.

Genesys Tempo appears by name

The mobile application is named in the objectives for time-off and schedule access, which means it is in scope rather than a footnote. Anyone preparing purely from the desktop administrative interface will meet a question they have no basis for answering. The Genesys Cloud workforce management documentation is the fastest way to close that kind of gap, since the objective names map onto its article titles almost one to one.

What does the adherence section actually test?

Real-time and historical adherence is the shortest section by objective count and the one with the most operational weight behind it. It covers the Real-Time Adherence view, monitoring agents against their schedules, interpreting historical adherence data and its configuration, and using intraday monitoring to react to staffing changes as they happen.

Adherence is the point where workforce management stops being a planning exercise and becomes a supervisory one. A schedule is a prediction; adherence is the measurement of how the day actually went, and intraday monitoring is the mechanism for doing something about it before the day is lost.

Historical adherence needs configuring, not just reading

The objective says configuration explicitly. Historical adherence depends on how activity codes were set up several steps earlier, which is why the first section of the syllabus matters more than its clerical tone suggests. An activity code mapped carelessly produces adherence figures that are precisely wrong, and the exam connects those two ends of the syllabus deliberately.

Who should take GCX-WFM?

GCX-WFM suits a workforce management analyst, a contact centre resource planner, a supervisor with scheduling responsibility, or a Genesys Cloud administrator whose remit has grown to include WFM. It is not a general Genesys Cloud credential and it assumes you already know your way around the platform.

GCX-WFM covers Genesys Cloud CX while GEOP-WFM covers Genesys Engage on premises

The career case is reasonably specific. Workforce management is a recognised speciality with its own job title rather than a task bolted onto an operations role, and published WFM analyst salary data shows a band wide enough that platform-specific proof of competence is worth having.

If you are new to Genesys Cloud entirely

Start elsewhere. The platform-wide professional credential establishes the vocabulary and the navigation this exam takes for granted, and Genesys Cloud CX Professional route is the usual on-ramp. Arriving at GCX-WFM without that grounding means learning two things at once under a 39-mark pass line.

The wider certification picture

Genesys publishes its own WFM certification view, which is worth reading for how the vendor positions the speciality even though it is promotional in tone. It makes clear that workforce management is being treated as a career track rather than a product module, which is the context this credential sits in.

How should you prepare without published weightings?

No weightings are published for GCX-WFM, so there is no marks-based way to prioritise. The alternative is to prepare along the operational cycle, because the syllabus is written as one, and to spend your time where the objectives name the most distinct tasks.

  1. Confirm which platform you are being examined on before anything else, since the cloud and on-premises credentials share a name and a price but not a syllabus.
  2. Build a business unit and a management unit in a practice environment, then assign agents and planning groups to them, because every later section depends on that structure existing.
  3. Configure activity codes deliberately and think about how each one will appear in adherence reporting later, which is the connection the exam draws between the first section and the last.
  4. Create a work plan with real daily shifts and shift activities, then run a work plan bid, as bids are named separately in the objectives and are easy to skip.
  5. Import historical data and build a forecast in the Forecast Editor, then rebuild it after deliberately corrupting part of the history to see what the output does.
  6. Generate both a forecast-based schedule and a blank one, publish them, and work through the difference in what each leaves you to do by hand.
  7. Run the full time-off cycle from limits and plans through requests, approvals and a shift trade, since the human machinery is the half candidates under-prepare.
  8. Spend a working day with the Real-Time Adherence view open and use intraday monitoring against a live schedule, which is the only way the last section becomes intuitive.

Use the recommended course as a checklist

The money site names the Genesys Cloud WEM workforce management course as the recommended training, and its module list is effectively the syllabus in delivery order. Even if you do not take it, the outline is a useful way to check that nothing in your own preparation has been left out.

Frequently Asked Questions

What is the difference between GCX-WFM and GEOP-WFM?

GCX-WFM covers Genesys Cloud CX and GEOP-WFM covers Genesys Engage on-premises. They are separate credentials for separate platforms, not tiers of the same one.

How many questions are on the GCX-WFM exam?

Sixty questions in 120 minutes, which is two minutes each. The on-premises equivalent has 45 in the same time.

What is the passing score for GCX-WFM?

Sixty-five percent, which works out at 39 correct answers out of 60. GEOP-WFM sets a higher bar at 70 percent.

What does GCX-WFM cost?

USD 580, the same as the on-premises credential. It is delivered through Kryterion Webassessor.

Are the GCX-WFM sections weighted?

No percentage weightings are published for any of the five sections, so there is no marks-based way to prioritise. Prepare along the operational cycle instead.

How long is GCX-WFM valid?

No validity period or recertification rule is published on any readable source, so none is asserted here. Confirm it with Genesys before assuming the credential is permanent.

Do you need another Genesys certification first?

No prerequisite is published. In practice the platform-wide professional credential is a sensible starting point, because GCX-WFM assumes familiarity with Genesys Cloud navigation and vocabulary.

Does GCX-WFM cover the Genesys Tempo mobile app?

Yes. It is named in the scheduling and time-off objectives for mobile schedule and time-off access, so desktop-only preparation leaves a gap.

Is forecasting the hardest part of the exam?

For most candidates, yes. Configuration and scheduling are learnable from the product; forecasting rewards judgement about data quality and seasonality that only comes from having built one.

How long does preparation usually take?

Four to eight weeks alongside a job, most of it spent inside a practice environment rather than reading, because every objective is phrased as a task rather than a concept.

Conclusion

The first decision on this credential is not how to study, it is which of two similarly named exams belongs to your platform. GCX-WFM is the Genesys Cloud CX one: 60 questions, 120 minutes, 39 marks to pass, 580 dollars, five sections and no published weightings.

Prepare along the cycle the syllabus describes, from configuration through forecasting and scheduling to adherence, and do it in a practice environment rather than on paper, because every objective is written as a task. Give forecasting more time than its objective count suggests, and do not skip the mobile application or the work plan bids.

And treat the published figures as what they are. The vendor’s own catalogue cannot be read by anything but a person with a browser, so confirm the exam terms with Genesys directly before booking.

Rating: 0 / 5 (0 votes)

The post Genesys Workforce Management Certification: Cloud or Engage appeared first on Certification Box.

]]>
PfMP Certification: Four Hours on Strategy, Not Delivery https://www.certificationbox.com/2026/09/23/pfmp-certification-four-hours-on-strategy-not-delivery/ Wed, 23 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=31041 Schedules, scope, resourcing, execution. None of it appears anywhere in this syllabus, which is the clearest signal available that PfMP belongs to a different discipline rather than a higher rung of the same one.

The post PfMP Certification: Four Hours on Strategy, Not Delivery appeared first on Certification Box.

]]>

Almost every page that ranks for this credential describes it as the summit of a ladder that starts at PMP. It is not on that ladder. Read the five domains in order and something becomes obvious very quickly: not one of them is about delivering anything. Schedules, scope, resourcing, execution, none of it appears.

The PfMP certification is PMI’s Portfolio Management Professional credential, examined in 170 multiple choice questions over 240 minutes and scored in performance bands rather than a percentage. Its five domains are strategic alignment, governance, portfolio performance, portfolio risk management and communications management.

Table of Contents

  1. What is the PfMP certification, and why is it not the top of the PMP ladder?
  2. What does the PfMP exam look like?
  3. How is PfMP scored when there is no pass percentage?
  4. What do the five PfMP domains cover?
  5. Why strategic alignment and portfolio performance carry half the marks
  6. What does PfMP cost, and does membership pay for itself?
  7. Who is PfMP actually for?
  8. How should you prepare for a four-hour paper?
  9. Frequently Asked Questions
  10. Conclusion

What is the PfMP certification, and why is it not the top of the PMP ladder?

PfMP is PMI’s Portfolio Management Professional credential, and it certifies the ability to select and balance a collection of investments against organisational strategy. A project manager delivers a defined outcome. A portfolio manager decides which outcomes should be funded at all, and stops the ones that no longer earn their place.

PMP manages one project, PgMP manages one programme and PfMP manages the whole portfolio

That is a different job, not a more senior version of the same one. The clearest way to see it is to look at what each credential manages. PMP manages a project. PgMP manages a programme, meaning a group of related projects delivering one coordinated benefit. PfMP manages a portfolio, meaning everything the organisation has chosen to invest in, related or not.

Credential What it manages The central question it answers
PMP A single project Are we delivering this on time, on budget and to scope?
PgMP A programme of related projects Are these projects together producing the benefit we set out to get?
PfMP The whole investment portfolio Are these the right things to be doing at all?

The practical consequence for a candidate is that PMP revision transfers poorly. Earned value, critical path, procurement types and change control are the substance of one exam and largely absent from the other. What transfers is the vocabulary and the habit of thinking in governance structures.

Because the credential sits in an unfamiliar discipline, the sensible first step is reading the exam’s own scope rather than a training provider’s summary of it. The money site’s PfMP certification overview sets out the five domains and the exam mechanics together, which is the fastest way to decide whether this is the credential you actually want.

What does the PfMP exam look like?

The PfMP exam is 170 multiple choice questions in 240 minutes, delivered through Pearson VUE, drawing on The Standard for Portfolio Management, Fourth Edition and the PMBOK Guide. Four hours over 170 questions works out at roughly 85 seconds each, which is generous by certification standards and necessary given how much reading each item carries.

Field Value
Exam name PMI Portfolio Management Professional
Exam code PfMP
Questions 170
Duration 240 minutes
Format Multiple choice
Result Above Target, Target, Below Target or Needs Improvement
Exam fee USD 800 for PMI members, USD 1000 full price
Delivered by Pearson VUE
Reference works The Standard for Portfolio Management, Fourth Edition, and the PMBOK Guide
Domains 5, weighted

The length is the part candidates under-rate. Four hours of dense scenario reading is a physical test as much as a knowledge one, and people who have only ever sat 60 or 90 minute papers routinely find their accuracy falling away in the final hour rather than their knowledge.

A note on what is not published here

PMI’s own certification pages could not be read while researching this article, so every figure above comes from the money site’s syllabus page rather than from vendor confirmation. The eligibility rules, which govern how much portfolio experience you need before you may apply, are not published on that page either, and they are not guessed at here. They live in the official PfMP handbook, which is the document to read before paying anything.

How is PfMP scored when there is no pass percentage?

PfMP does not report a percentage. The result is one of four performance bands: Above Target, Target, Below Target or Needs Improvement. Any page quoting a specific pass percentage for this exam has invented it, because no such number is published for the credential at all.

PfMP reports four performance bands, Above Target, Target, Below Target and Needs Work, per domain and overall

This matters more than it first appears, because it changes what a study plan should optimise for. With a numeric cut score you can trade a weak area against a strong one and still clear the line. With band reporting there is no arithmetic to do, and no published rule that lets you convert one domain’s strength into another domain’s weakness.

What the bands describe

The four bands describe performance against the standard expected of a competent portfolio manager, not against other candidates and not against a raw mark. Target means you met that expectation. Above Target means you exceeded it. The two lower bands mean you did not, with Needs Improvement being the further away of the two.

The result report breaks performance down by domain as well as overall, which is the genuinely useful part for anyone who has to retake. A candidate who lands Below Target overall but Target on four domains knows exactly where the work is.

How to prepare for band scoring

Aim for even competence rather than a spiky profile. That sounds like generic advice until you notice how easy the alternative is: a working portfolio manager usually arrives strong on governance and performance because those are the parts of the job with meetings attached, and thin on risk and communications because those are the parts that get delegated.

What do the five PfMP domains cover?

PfMP has five weighted domains: strategic alignment at 25 percent, governance at 20 percent, portfolio performance at 25 percent, portfolio risk management at 15 percent and communications management at 15 percent. Each is expressed as a set of tasks, and each task names both the technique and the purpose it serves.

Domain Weight What it examines
Strategic Alignment 25% Evaluating organisational goals, setting prioritisation criteria, ranking priorities with stakeholders, building portfolio scenarios and recommending them, and keeping the roadmap aligned when strategy shifts
Governance 20% Establishing the governance model, its structures, policies and decision rights, setting portfolio management standards, and defining the processes that make decisions repeatable
Portfolio Performance 25% Measuring whether the portfolio is delivering the value it promised, and acting on what the measurement shows
Portfolio Risk Management 15% Identifying and managing risk at portfolio level, which includes the risk of the wrong mix rather than only the risk inside each component
Communications Management 15% Keeping stakeholders informed and engaged across a portfolio whose components have different audiences and different reporting rhythms

Read the task lists rather than the domain names. Strategic alignment alone runs to eight tasks, and they describe a sequence: understand the strategy, set the criteria, rank the priorities, identify candidate components, model scenarios, recommend one, absorb strategy changes, publish the roadmap. That sequence is the exam’s spine.

Why strategic alignment and portfolio performance carry half the marks

Strategic alignment and portfolio performance are 25 percent each, so together they account for 50 percent of the exam. That is not an accident of drafting. They are the two ends of the same loop: alignment decides what should be in the portfolio, performance measures whether that decision turned out to be right.

Governance, risk and communications are the machinery that keeps the loop running. They matter, they carry marks, and a candidate who ignores them will not reach Target. But they are supporting disciplines, and the exam’s weighting says so plainly.

The techniques named in the syllabus are the ones to know

The strategic alignment tasks name their methods explicitly rather than leaving them abstract: document review and interviewing for gathering information, qualitative and quantitative analysis for ranking, and what-if scenario modelling using options analysis, risk analysis, SWOT and financial analysis for evaluating options. Those are examinable by name.

The same pattern of naming the technique alongside the purpose shows up across PMI’s credential family. Anyone who has worked through the PMI-RMP risk credential will recognise the style immediately, and the risk vocabulary transfers almost intact into this exam’s fourth domain.

Where candidates lose ground

Portfolio performance is the domain that catches experienced people out, because in practice most organisations measure component delivery and call it portfolio performance. The exam treats them as different things. Whether every project came in on time says nothing about whether the portfolio produced the value that justified funding it.

What does PfMP cost, and does membership pay for itself?

The PfMP exam costs USD 800 for PMI members and USD 1000 at full price. The gap is USD 200, and that single figure decides the membership question for almost everyone: if annual membership costs less than USD 200, joining before booking is cheaper than not joining, and you keep the membership benefits as well.

That arithmetic is worth doing deliberately rather than assuming. It is the same structure PMI uses across its credential range, and it is why the member price is quoted first on almost every summary of the exam.

The costs that are not in the fee

Two reference works sit behind this exam, The Standard for Portfolio Management and the PMBOK Guide, and both are paid publications unless you have access through membership. Budget for them, and budget for the time to read them, because the standard is the source the questions are written from rather than a companion to it.

Retakes are the other line item. Four hours is a long sitting and a resit is not a small commitment of either money or stamina, which is an argument for going in genuinely ready rather than treating the first attempt as reconnaissance.

Who is PfMP actually for?

PfMP suits somebody who already makes or shapes investment decisions: a portfolio manager, a PMO lead with a funding remit, a head of delivery who sits in prioritisation meetings, or a programme manager whose scope has quietly grown into a portfolio. It is a poor fit for somebody who wants a more impressive project management credential.

The career case is genuine but narrower than PMP’s. Portfolio management roles are fewer, more senior and concentrated in organisations large enough to run a formal investment process. Published portfolio manager salary data shows a wide band, which is exactly what you would expect from a title that means something different in financial services than it does in a technology PMO.

The recognition question

Portfolio management as a discipline is considerably older than the credential and considerably broader than PMI’s treatment of it. Reading around project portfolio management is worth an hour before committing, because it makes clear which parts of the exam are PMI’s particular framing and which are the discipline’s common ground.

If you are weighing PfMP against a newer PMI credential in an adjacent space, the cost comparison is a useful reality check. The CPMAI credential pricing sits in similar territory for a very different skill set, and comparing what each actually buys is more informative than comparing badge prestige.

How should you prepare for a four-hour paper?

PfMP preparation is longer than most certification study plans, typically two to four months alongside a senior role, and it divides into learning an unfamiliar discipline and then building the stamina to reason about it for four hours. Skipping the second half is the most common mistake.

  1. Read The Standard for Portfolio Management end to end before touching any question bank, because the exam is written from it rather than from general project management practice.
  2. Work through the strategic alignment tasks as a sequence rather than a list, following it from understanding the strategy to publishing the roadmap.
  3. Learn the named analysis techniques by name, covering options analysis, risk analysis, SWOT and financial analysis, since the syllabus examines them explicitly.
  4. Build a governance model on paper for an imaginary portfolio, defining the boards, the policies and the decision rights, which converts the second domain from theory into something you have actually done.
  5. Separate component performance from portfolio performance deliberately in your own mind, because conflating them is the single most reliable way to lose marks in the highest-weighted pair.
  6. Study risk and communications last and hardest, since they carry 30 percent between them and are the two areas working portfolio managers usually delegate.
  7. Sit at least one full 170 question paper in a single four hour block to find out where your accuracy starts to fall away.

Booking and the day itself

The exam runs through Pearson VUE delivery centres and online proctoring, and the choice between them matters more at four hours than it would at one. A centre removes the risk of a connection failure two hours in; a home sitting removes the commute and lets you control the chair you spend four hours in.

Frequently Asked Questions

How many questions are on the PfMP exam?

One hundred and seventy multiple choice questions, taken over 240 minutes, which works out at roughly 85 seconds each.

What is the passing score for PfMP?

There is no published percentage. The result is reported as Above Target, Target, Below Target or Needs Improvement, with a breakdown by domain. Any source quoting a percentage has invented it.

How long is the PfMP exam?

Four hours. It is one of the longer certification sittings in the field, and stamina is a genuine factor rather than a throwaway concern.

What does PfMP cost?

USD 800 for PMI members and USD 1000 at full price. The USD 200 gap usually makes membership worth taking out before booking.

Is PfMP harder than PMP?

It is not a harder version of PMP, it is a different subject. PMP examines delivering a project; PfMP examines choosing and balancing investments. PMP revision transfers only partly.

What are the PfMP domains and their weightings?

Strategic alignment 25 percent, governance 20 percent, portfolio performance 25 percent, portfolio risk management 15 percent and communications management 15 percent.

What experience do you need to apply for PfMP?

The money-site syllabus page does not publish the eligibility rules, and PMI’s certification pages could not be read while researching this article, so no requirement is asserted here. The official PfMP handbook is where those rules are set out.

Which books does the PfMP exam draw on?

The Standard for Portfolio Management, Fourth Edition, and the PMBOK Guide. The standard is the primary source; the guide is supporting context.

Where is the PfMP exam delivered?

Through Pearson VUE. Over a four hour sitting the choice between a test centre and online proctoring is worth thinking about properly.

How long does preparation usually take?

Two to four months alongside a senior role is typical, with the last few weeks given over to full-length timed practice rather than new material.

Conclusion

PfMP is a credential for people who decide what gets funded, and the syllabus says so in the only way that counts: five domains, none of them about delivery, with alignment and performance carrying half the marks between them. Approaching it as an advanced project management exam is the fastest route to a Below Target report.

Read the standard first, learn the strategic alignment sequence as a sequence, give risk and communications more time than instinct suggests, and sit at least one full four hour paper before the real one. The band scoring rewards even competence, so the goal is a flat profile rather than a spiky one.

And do the membership arithmetic before you book. A USD 200 gap on a single exam fee is the easiest saving available on this credential.

Rating: 0 / 5 (0 votes)

The post PfMP Certification: Four Hours on Strategy, Not Delivery appeared first on Certification Box.

]]>
Oracle MySQL Developer Certification: 1Z0-909 Beyond SQL https://www.certificationbox.com/2026/09/22/oracle-mysql-developer-certification-1z0-909-beyond-sql/ Tue, 22 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=31022 Seven topic areas, thirty one objectives, and not a single published weighting to tell you where the effort belongs. Two of those areas sit outside what a query-writing developer ever touches, which is why this exam is decided by connectors and collections rather than by SQL.

The post Oracle MySQL Developer Certification: 1Z0-909 Beyond SQL appeared first on Certification Box.

]]>

Read the syllabus in order and the first thing a MySQL database developer is asked about is not a query. It is which connector to choose, how to configure it, and how to keep its credentials safe. The SQL arrives in the second topic area.

The Oracle MySQL developer certification, exam code 1Z0-909, awards the MySQL 8.0 Database Developer Oracle Certified Professional credential. It runs to 65 questions in 90 minutes at a 62 percent pass mark, across seven topic areas and 31 objectives that reach from connector configuration to document-store access.

Table of Contents

  1. What is the Oracle MySQL developer certification?
  2. Why does the syllabus start with connectors rather than SQL?
  3. What do the seven topic areas cover?
  4. How is the 1Z0-909 exam delivered and scored?
  5. The document store is a whole topic area
  6. Transactions and locking are developer work here
  7. Is 1Z0-909 the same as the MySQL administrator exam?
  8. How should an application developer prepare?
  9. Frequently Asked Questions
  10. Conclusion

What is the Oracle MySQL developer certification?

The Oracle MySQL developer certification is the professional-level credential for people who build applications against MySQL rather than operate the server. Exam 1Z0-909 awards the title MySQL 8.0 Database Developer Oracle Certified Professional, and it covers connectors, application data access, schema objects, transactions, query optimisation, stored programs and the document store.

Professional is the level, not associate, and Oracle’s own framing on the syllabus page is that the questions test the ability to apply knowledge gained in hands-on practice or professional experience. That is the standard Oracle language for an exam written around work rather than around reading.

The version matters and is worth stating plainly. This is the 8.0 line, and there is no higher-numbered MySQL developer exam in circulation. Residual search demand still exists for the retired 5.7 administrator credential, which is a reliable sign that the 8.0 pair is the current generation rather than a superseded one.

What the credential is not is a database administration qualification with a developer label on it. There is a separate exam for that, and the difference is covered later in this article.

Why does the syllabus start with connectors rather than SQL?

Connectors and APIs is the first of seven topic areas, and it contains five objectives before a single SQL statement appears on the syllabus. The reason is that this exam is written from the application’s point of view: before you query anything, something in your code has to open a connection, authenticate, and handle what comes back.

Three things the 1Z0-909 connectors and APIs topic area asks before any query runs: choose the connector, configure it and handle odd values, secure the secrets and transport

The five objectives are specific about what that involves. Choosing between connectors for a given application. Demonstrating connector use, management and configuration. Retrieving data through a connector. Handling special values. Securing credentials and connections.

Two of those are easy to under-prepare. Handling special values means knowing what a null, a zero date or an out-of-range value becomes on the way from the server into your language’s type system, which differs between connectors. Securing credentials and connections is about where the secret lives and whether the transport is protected, and it is the kind of objective that reads as obvious and tests as specific.

The ordering is a useful signal for planning. A candidate who has only ever written queries in a client tool has not met the first topic area at all, and the fastest way to establish that is to work items rather than to read the list. The sets on the money site’s 1Z0-909 practice exam span all seven areas, so an unfamiliar area surfaces in the first sitting rather than on exam day.

What do the seven topic areas cover?

The seven areas are Connectors and APIs, Data-driven Applications, MySQL Schema Objects and Data, Transactions, Query Optimization, MySQL Stored Programs, and JSON and Document Store. Oracle publishes no percentage weighting for any of them, so the planning unit is the objective rather than the domain and every area has to be treated as examinable.

Topic area Objectives What it really asks
Connectors and APIs 5 Choosing, configuring and securing the connection your application uses
Data-driven Applications 6 Prepared statements, SQL modes, error and warning handling, aggregation, report generation
MySQL Schema Objects and Data 5 Views, and storing and processing string, numeric, temporal and spatial data
Transactions 4 Transaction control in SQL and in code, isolation levels, locking
Query Optimization 3 Indexes, analysing a query, rewriting a query
MySQL Stored Programs 4 Stored routines, programming constructs, triggers, scheduled operations
JSON and Document Store 5 JSON documents, XDevAPI, NoSQL-style development, MySQL Shell

Counting objectives rather than percentages gives a rough proxy for effort. Data-driven Applications is the largest area at six objectives, and Connectors, Schema Objects and the document store follow at five each. Query Optimization is the smallest at three, which is surprising for a developer exam and worth not over-investing in.

Spatial data deserves a mention because it hides inside a broader objective. The schema area asks you to store and process string, numeric, temporal and spatial data, and spatial types are the one most application developers have never touched. It is one objective among 31, but it is the one most likely to be a complete blank.

How is the 1Z0-909 exam delivered and scored?

1Z0-909 is a 65 question multiple choice exam with a 90 minute limit and a 62 percent pass mark, priced at USD $245 with regional variation. That works out at 83 seconds per question and 41 correct answers to pass, leaving a margin of 24.

Field Value
Credential awarded MySQL 8.0 Database Developer Oracle Certified Professional
Exam code 1Z0-909
Level Professional
Questions 65
Format Multiple choice
Duration 90 minutes
Passing score 62 percent
Price USD $245, varies by country and currency
Topic areas 7, none weighted
Objectives 31
Product version MySQL 8.0

A 62 percent bar with a 24 question margin is one of the more forgiving arrangements in the Oracle catalogue, and it changes the risk calculation. You can be genuinely weak in one topic area and still pass comfortably. You cannot be weak in two, because the smallest areas are three to five objectives each and two of them together can spend most of that margin.

Eighty three seconds a question is brisk for a paper that includes code reading. Questions that show a stored routine, a trigger body or a connector configuration take longer than a definition question, so bank time early rather than assuming the average holds.

One note on sourcing. Every figure above is published on the money site’s syllabus page for this exam. Oracle’s certification portal returns an error to automated retrieval and its learning site renders in the browser rather than serving readable content, so none of these could be re-confirmed against Oracle directly at the time of writing.

The document store is a whole topic area

JSON and Document Store is one of seven topic areas and carries five objectives: creating and storing JSON documents, processing data inside them, explaining application development with NoSQL and XDevAPI, creating and accessing a document store, and using MySQL Shell to reach it. For a candidate who thinks of MySQL as a relational database, this is the least familiar part of the paper.

Two different things sit in one area

The first is the JSON data type, which is relational MySQL storing a document in a column and giving you functions to query inside it. Oracle’s own JSON data type reference covers validation, path expressions and the operators involved, and most developers who have used MySQL recently have met at least part of it.

The second is the document store itself, reached through XDevAPI and MySQL Shell, where collections behave like a document database rather than like tables. That is a genuinely different programming model, and the objective that asks you to explain NoSQL-style development is testing whether you understand the trade-off rather than the syntax.

Why the specification is worth twenty minutes

Questions about JSON storage often turn on what is and is not legal in a document rather than on MySQL’s functions. Reading the JSON interchange format specification is a short job and it settles the edge cases: duplicate keys, number precision, and what counts as a valid top-level value. Those are exactly the details a well-written question hangs on.

MySQL Shell is named explicitly in the objectives, which means the exam expects familiarity with the tool rather than just the concept. Installing it and creating a collection takes an afternoon and removes an entire category of uncertainty.

Transactions and locking are developer work here

The Transactions area has four objectives and two of them describe work many developers assume belongs to a database administrator: resolving consistency problems with isolation levels, and understanding locking mechanisms within MySQL. On this exam they are developer responsibilities, because the application is where a transaction is opened and where a deadlock surfaces.

The four InnoDB transaction isolation levels tested in the 1Z0-909 transactions topic area, from the lowest to the strictest

The isolation level objective is the one to study properly rather than skim. InnoDB offers four levels and the differences between them are only visible when two sessions interleave, which is not something you notice while writing single-threaded code.

  • Read uncommitted, where a session can see another session’s uncommitted changes.
  • Read committed, where each statement sees a fresh snapshot.
  • Repeatable read, InnoDB’s default, where the snapshot is fixed at the first read in the transaction.
  • Serializable, where reads become locking reads and concurrency drops accordingly.

Oracle’s InnoDB isolation level documentation sets out exactly what each level permits, and the anomalies it describes are the raw material for scenario questions in this area.

The split between controlling transactions in SQL and controlling them in an application is a second thing worth rehearsing. A connector’s autocommit behaviour, and whether a framework is opening transactions on your behalf, changes what a given block of code actually does, and the exam asks about both sides.

Is 1Z0-909 the same as the MySQL administrator exam?

No. Oracle publishes two MySQL 8.0 professional credentials: the developer exam, 1Z0-909, and the administrator exam, 1Z0-908. They share the product and very little else. The developer exam is written from inside an application, and the administrator exam is written from inside the server.

Comparison point 1Z0-909 Developer 1Z0-908 Administrator
Point of view The application connecting to MySQL The server MySQL runs on
Opening topic Connectors and APIs Installation and configuration
Typical daily work Writing queries, routines and application data access Backup, replication, security, monitoring, tuning the instance
Document store A full topic area Not a developer-style topic area
Who it suits Application and backend developers Database administrators and platform engineers

Search behaviour shows the confusion is real. Administrator-shaped queries carry far more volume than developer-shaped ones, so a developer searching for MySQL certification information lands on administrator material first and comes away with the wrong picture of what 1Z0-909 asks.

If you already hold an Oracle database developer credential the transfer is partial rather than complete. The PL/SQL developer credential shares the stored-program and optimisation instincts but sits on a different engine with a different procedural language, so the habits carry and the syntax does not.

For a reader deciding between the MySQL line and the Oracle Database line entirely, the Autonomous AI Database exam shows how differently Oracle structures its flagship database credentials, which is a useful contrast before committing to either path.

How should an application developer prepare?

Start with the two topic areas that sit outside normal application work, because they are where a competent MySQL developer is most likely to be genuinely blank. The sequence below moves from unfamiliar to familiar rather than following the syllabus order.

  1. Audit your experience against all 31 objectives and mark each one as done in anger, read about, or never seen, since there are no weightings to prioritise by.
  2. Build a small application against MySQL through a connector you have not used before, configuring it deliberately rather than accepting defaults.
  3. Deliberately return a null, a zero date and an out-of-range value through that connector and see what your language makes of each.
  4. Install MySQL Shell, create a collection, and write and read documents through XDevAPI so the document store stops being theoretical.
  5. Store a JSON column in a relational table as well, and query inside it, so the two halves of that topic area stay separate in your head.
  6. Open two sessions and reproduce a consistency anomaly at each InnoDB isolation level in turn, because reading about them does not stick.
  7. Write a stored routine, a trigger and a scheduled event, since those are three separate objectives and each has its own syntax quirks.
  8. Spend an hour on spatial types, which is one objective and the most common complete blank on this paper.
  9. Finish with timed sets of 65 questions in 90 minutes, checking that no single topic area is dragging you below the 62 percent line.

The audit in step one matters more than its position suggests. With no published weightings there is nothing to optimise against except your own gaps, and the people who fail this exam usually fail it on one area they never opened rather than on a thin understanding spread evenly.

For anyone who wants to look at the engine itself rather than the documentation, the official MySQL Server repository is public, and reading how a feature is implemented is occasionally the fastest way to understand behaviour the manual describes only at a high level.

Frequently Asked Questions

How many questions are on the 1Z0-909 exam?

Sixty five multiple choice questions with a 90 minute limit, which is 83 seconds each. Questions that show routine or connector code take longer than that average, so pace matters.

What is the passing score for the MySQL developer exam?

Sixty two percent, which means 41 correct answers out of 65 and a margin of 24. That is relatively forgiving by Oracle standards, but two weak topic areas will still spend most of it.

How much does 1Z0-909 cost?

USD $245 as published, with pricing varying by country and by localised currency. Training is separate and optional.

Does Oracle publish weightings for the MySQL developer topics?

No. Seven topic areas are published with 31 objectives between them and no percentage attached to any area. Planning has to be built on covering every objective rather than on concentrating where the marks sit.

What is the difference between 1Z0-909 and 1Z0-908?

1Z0-909 is the developer exam and 1Z0-908 is the administrator exam. The developer paper is written from inside an application, covering connectors, application data access and the document store. The administrator paper is written from inside the server.

Do you need to know the MySQL document store?

Yes. JSON and Document Store is one of the seven topic areas and carries five objectives, including XDevAPI and MySQL Shell by name. It cannot be skipped on the grounds that your own applications are purely relational.

How much SQL tuning does the exam cover?

Less than most candidates expect. Query Optimization is the smallest topic area at three objectives, covering indexes, analysing a query and rewriting one. It is worth solid rather than deep preparation.

Is there a MySQL 9 version of this certification?

Not in the current catalogue. The 8.0 developer and administrator exams are the live MySQL pair, and older 5.7 credentials are retired even though search demand for them persists.

Does the exam cover spatial data?

Yes, as part of the schema objects area, alongside string, numeric and temporal data. It is one objective out of 31, and it is the one most application developers have never touched.

Can I verify these figures on Oracle’s own site?

Not readily. Oracle’s certification portal returns an error to automated retrieval and its learning site renders in the browser rather than serving readable content, so published syllabus pages are the practical reference for exam specifications.

Conclusion

The useful way to read 1Z0-909 is by what it assumes rather than by what it lists. It assumes you connect to MySQL from code, that you own the transaction boundaries in that code, and that you have at least looked at the document store. None of those is a given for a developer who writes good SQL.

Everything familiar on this syllabus, the queries, the views, the routines, is the part you will cover fastest. The exam is decided by connectors, the document store and isolation levels, and those are the three to schedule first rather than last.

Once your own gaps are mapped across the 31 objectives, timed practice spanning all seven topic areas is the quickest way to see which of them is still costing you marks.

Rating: 0 / 5 (0 votes)

The post Oracle MySQL Developer Certification: 1Z0-909 Beyond SQL appeared first on Certification Box.

]]>
GitHub Actions Certification: Half of GH-200 Is Admin Work https://www.certificationbox.com/2026/09/22/github-actions-certification-half-of-gh-200-is-admin-work/ Tue, 22 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=31013 The cheapest exam Microsoft sells is also one of the widest, and the mismatch catches out the people most confident about it. Two of the five GH-200 domains are about governing Actions rather than writing them, and together with troubleshooting they account for roughly two thirds of the paper.

The post GitHub Actions Certification: Half of GH-200 Is Admin Work appeared first on Certification Box.

]]>

Ninety nine dollars buys a lot of confidence. It is the cheapest credential in the Microsoft catalogue, and the price quietly encourages people to treat GH-200 as a formality that a few months of writing workflow files will cover.

The GitHub Actions certification, exam code GH-200, is Microsoft’s intermediate credential for automating software delivery with GitHub Actions. It runs to 72 questions in 100 minutes against a 700 out of 1000 pass mark, and its five weighted domains put as much of the paper into administering Actions across an organisation as into writing workflows at all.

Table of Contents

  1. What does the GitHub Actions certification test?
  2. Where do the marks sit across the five domains?
  3. Half of GH-200 is administration, not authoring
  4. How is the GH-200 exam delivered and scored?
  5. Which authoring details does the syllabus name explicitly?
  6. What did the syllabus add on security?
  7. How long does a GitHub certification last?
  8. How should a workflow author prepare for the admin half?
  9. Frequently Asked Questions
  10. Conclusion

What does the GitHub Actions certification test?

The GitHub Actions certification, GH-200, tests whether you can automate software delivery with GitHub Actions at organisational scale. It covers authoring and maintaining workflows, consuming and troubleshooting them, building custom actions, governing Actions across an enterprise, and securing and optimising the whole arrangement. Microsoft positions it at intermediate level for the GitHub product.

Microsoft names five roles for the exam rather than one: administrator, developer, DevOps engineer, solution architect, and student. That list is unusual, and it is the first clue about what the paper actually contains. An exam written only for people who author workflows would not name administrator first.

The subject classification is DevOps and the assumed background is wider than Actions alone. Microsoft expects familiarity with continuous integration and delivery as a practice, with GitHub repositories, with GitHub Packages, and with wiring third-party services into a pipeline. Someone whose entire exposure is a single repository’s build file will find the assumed context missing rather than the syntax hard.

If the underlying practice itself is new to you, the vocabulary of continuous integration and delivery is worth settling before the exam objectives will read cleanly, because the syllabus uses those terms as given rather than defining them.

Where do the marks sit across the five domains?

GH-200 publishes five domains with banded weightings rather than fixed percentages. Author and manage workflows and Manage GitHub Actions for the enterprise are jointly the heaviest at 20 to 25 percent each. Consume and troubleshoot workflows and Author and maintain actions follow at 15 to 20 percent, and Secure and optimize automation is the lightest at 10 to 15 percent.

Domain Weight Approximate questions What it is really about
Author and manage workflows 20-25% 14 to 18 Triggers, jobs, matrices, contexts, expressions, caching, artifacts, passing data between jobs
Manage GitHub Actions for the enterprise 20-25% 14 to 18 Runner groups, IP allow lists, org policies, reusable component governance, secret and variable scoping
Consume and troubleshoot workflows 15-20% 11 to 14 Reading logs, diagnosing failures, matrix expansions, starter against reusable workflows
Author and maintain actions 15-20% 11 to 14 JavaScript, Docker and composite actions, metadata, versioning, Marketplace distribution
Secure and optimize automation 10-15% 7 to 11 Token scoping, OIDC federation, SHA pinning, attestations, caching economics

Banded weightings are worth pausing on. The low end of the five bands adds to 80 percent and the high end to 105, which means Microsoft is reserving room to move the mix between exam forms. Planning on the upper figure for each domain is the safe reading.

The quickest way to find out which of the five is your weak one is to work items drawn across all of them rather than to reread the objectives. The sets on the money site’s GH-200 practice exam are spread over the five domains in roughly the published proportions, which makes a lopsided profile visible in one sitting.

Half of GH-200 is administration, not authoring

Add the enterprise domain to the security domain and you get 30 to 40 percent of the paper on governing Actions rather than writing them. Add troubleshooting other people’s workflows and the share of the exam that is not greenfield authoring reaches roughly two thirds. That is the single most useful thing to know before booking.

Four objective groups the GH-200 enterprise administration domain adds: runner groups, organisation policy, secret scoping and reuse control

What the enterprise domain actually asks

Three objective groups sit under it, and none of them appear in a typical developer’s week. Distributing and governing actions covers reusable components, access control within the enterprise, and organisational use policies. Managing runners at scale covers hosted and self-hosted runners, IP allow lists, runner groups, and the preinstalled software and toolcache on hosted images. Managing encrypted secrets and variables covers scoping at organisation, repository and environment level, and doing it programmatically through the REST API.

The runner objectives are the ones that surprise people most. Knowing that a job runs on ubuntu-latest is not the same as knowing which tool versions that image ships, how to install what it does not, or what happens to a queued job when a runner group’s allow list rejects the network it sits on.

Troubleshooting is a separate skill from authoring

Consume and troubleshoot workflows is written entirely from the reader’s side rather than the author’s. It asks you to infer triggers from configuration and logs, to expand YAML anchors and merged mappings when reading someone else’s file, to correlate job names back to matrix axes, and to rerun individual matrix jobs selectively.

Reading a matrix expansion backwards from a failure list is a different mental operation from writing the matrix in the first place, and it is the one the exam tests. Candidates who have only ever authored their own workflows have rarely done it.

How is the GH-200 exam delivered and scored?

GH-200 is a proctored exam of 72 questions with a 100 minute limit, scored on Microsoft’s 1000 point scale with 700 required to pass, and priced at $99 USD. It is scheduled through Pearson VUE and may include interactive components alongside standard question types.

Field Value
Credential name Microsoft GitHub Actions
Exam code GH-200
Level Intermediate
Questions 72
Duration 100 minutes
Passing score 700 out of 1000
Price $99 USD
Domains 5, all weighted as bands
Delivery Pearson VUE, proctored
Languages English, Spanish, Portuguese (Brazil), Korean, Japanese
First retake 24 hours after a failed attempt
Validity 2 years

Seventy two questions in 100 minutes is about 83 seconds each, which is tighter than it looks once interactive items are in the mix. Those take longer than a multiple choice item and cannot be answered on recognition, so banking time on the straightforward questions matters more here than on a slower paper.

One administrative detail is worth more than it sounds. Microsoft advises registering with a personal account rather than a work or school one, because exam records tied to an organisational identity are lost and cannot be recovered if you leave that organisation. People discover this years later, at the worst possible moment.

Microsoft also publishes an interactive sandbox that reproduces the exam interface and question types, reachable from the official credential page. Spending twenty minutes in it removes the whole category of surprise about how interactive items behave under time pressure.

Which authoring details does the syllabus name explicitly?

The authoring domain is unusually specific about mechanisms rather than concepts. It names workflow_dispatch input types and defaults, workflow_call input and secret mapping, service containers with ports and health checks, strategy matrices with include, exclude, fail-fast and max-parallel, YAML anchors and merge keys, and the full list of predefined contexts.

Comparison of starter workflows, reusable workflows and composite actions in the GH-200 GitHub Actions syllabus

That specificity is a gift for planning, because it tells you exactly where recognition will not be enough.

  • Expressions are split into static evaluation at workflow parse time and runtime evaluation, and the objective explicitly pairs that distinction with preventing secret leakage into logs.
  • Data passing is enumerated rather than generalised: artifacts, step outputs, environment files through GITHUB_ENV and GITHUB_OUTPUT, and reusable workflow outputs.
  • GITHUB_STEP_SUMMARY appears as its own objective for generating Markdown job summaries with test results and coverage.
  • Retention policies for logs, artifacts and workflow runs are to be applied through the REST API at organisation and repository level, not through the interface.

There is also a boundary question the syllabus asks in two separate places: the difference between a starter workflow, a reusable workflow and a composite action. A starter workflow is a scaffold that is copied and then lives independently. A reusable workflow is a central versioned definition invoked through workflow_call. A composite action encapsulates step logic. Confusing the three is the most predictable way to lose marks in two domains at once.

Candidates who have prepared a Microsoft DevOps credential before will recognise the pattern of naming mechanisms rather than outcomes. The Azure DevOps Engineer exam is built the same way, and the study habits transfer even though the tooling does not.

What did the syllabus add on security?

The security domain is the lightest by weight at 10 to 15 percent, but it carries the most recently added material on the whole syllabus. Immutable actions, OIDC federation to cloud providers, commit SHA pinning of third-party actions, and artifact attestation with build provenance all appear as named objectives.

Tokens, and getting rid of them

Two objectives deal with credentials and they point in the same direction. The first asks you to understand the GITHUB_TOKEN lifecycle, that it is ephemeral and scoped, how to configure granular permissions on it, and how it contrasts with a personal access token. The second asks you to use OIDC cloud federation with the id-token permission specifically to eliminate long-lived cloud secrets.

Read together, they describe a direction of travel rather than two techniques: short-lived, narrowly scoped, exchanged at run time. Answers that reach for a stored secret are usually the distractor.

Trusting what you did not write

Supply chain material runs through several objectives. Pinning third-party actions to full commit SHAs rather than a floating tag, aligning with immutable actions enforcement on hosted runners, enforcing allow and deny lists at organisation level, requiring reviewers for unverified actions, and generating and verifying artifact attestations that a deployment step then checks.

The attestation objective names provenance formats directly, and the ecosystem work behind them sits with the open source security foundation rather than with GitHub alone. Understanding what an attestation asserts, and what verifying one actually proves, is more useful here than memorising a command.

Script injection rounds the domain out and is the most practical item on it: sanitising inputs, least-privilege permissions, keeping untrusted data out of run steps, correct shell quoting, and preferring vetted actions over inline scripts.

How long does a GitHub certification last?

GitHub certifications are valid for two years, not three. That distinction matters because the three year figure is widely repeated and is one of the more common searches around these exams, and planning a renewal a year late is an expensive mistake to make on a credential you have already paid for.

There is a transitional arrangement in place at the moment. GitHub is moving its certifications onto Microsoft’s recertification process, which will let holders maintain a credential without resitting the full exam. Until that process is available, any GitHub certification that would expire before it launches is extended by six months automatically.

Anyone whose certification has already lapsed is not stuck either. GitHub’s stated position is that expired holders can contact its learning team and be issued a voucher to resit at no cost, which is a more generous arrangement than most vendors offer.

For readers weighing GH-200 against another Microsoft credential on validity and renewal grounds, the comparison of two Azure certification paths works through the same decision for the Azure line, where renewal runs on Microsoft’s annual online assessment instead.

How should a workflow author prepare for the admin half?

Assume your authoring is already close and spend the preparation time on the two thirds of the exam that is not authoring. The sequence below works outward from what a developer already does toward what an organisation administrator does, which is the direction most candidates need to travel.

  1. Audit your own experience against the five domains honestly, marking each objective as done in anger, read about, or never seen.
  2. Read three workflows you did not write and predict their trigger behaviour from the configuration alone before checking the run history.
  3. Force a matrix failure deliberately, then correlate the failed job names back to their matrix axes and rerun only the failing variants.
  4. Build one of each action type, a JavaScript action, a Docker action and a composite action, so the metadata and directory differences stop being abstract.
  5. Scope a secret at organisation level, then at repository level, then at environment level, and observe which workflow can read which.
  6. Register a self-hosted runner, put it in a runner group, and restrict that group, because runner administration is the objective group developers have least exposure to.
  7. Replace a stored cloud credential with OIDC federation using the id-token permission, then pin every third-party action in that workflow to a full commit SHA.
  8. Spend twenty minutes in the published exam sandbox so interactive question types cost you no thinking time on the day.
  9. Finish with timed sets of 72 questions in 100 minutes, tracking your score per domain rather than overall.

The audit in step one is the step people skip and the one that saves the most time. GH-200 is a cheap exam with a wide scope, and the cost of failing it is mostly the fortnight, not the fee.

Frequently Asked Questions

How many questions are on the GH-200 exam?

GH-200 has 72 questions with a 100 minute limit, roughly 83 seconds each. Some items are interactive rather than multiple choice, and those take longer, so pace matters more than the raw average suggests.

What score do you need to pass GH-200?

700 out of 1000 on Microsoft’s scaled scoring. That is not a straight 70 percent of questions, because the scale weights items rather than counting them, but it is the figure the score report is measured against.

How much does the GitHub Actions certification cost?

$99 USD, which makes it one of the cheapest credentials Microsoft offers. The exact charge varies with the country or region the exam is proctored in, and training is a separate optional cost.

Are GitHub certifications valid for three years?

No, they are valid for two years. The three year figure circulates widely and is wrong. GitHub is currently extending certifications that expire before its new recertification process launches by an extra six months.

Which GH-200 domain is the heaviest?

Two domains tie at 20 to 25 percent: authoring and managing workflows, and managing GitHub Actions for the enterprise. The enterprise domain is the one candidates consistently underestimate because it sits outside a typical developer’s daily work.

Do you need self-hosted runner experience for GH-200?

The syllabus names runner administration directly, including runner groups, IP allow lists, hosted image toolcache contents, and troubleshooting. You can pass without production experience, but not without having configured and restricted a runner at least once.

What is the difference between a reusable workflow and a starter workflow?

A starter workflow is a scaffold you copy into a repository, after which it lives independently. A reusable workflow is a central versioned definition invoked through workflow_call. The syllabus asks you to distinguish both from composite actions as well.

Is GH-200 harder than AZ-400?

They are different rather than ranked. AZ-400 spans a wider toolchain across the Azure DevOps platform, while GH-200 goes deeper into one product and names specific mechanisms rather than outcomes. GH-200 is classified intermediate; AZ-400 is expert level.

What languages is the GH-200 exam offered in?

English, Spanish, Portuguese for Brazil, Korean and Japanese. That is a narrower set than most Microsoft role-based exams, which is worth checking before booking if English is not your first language.

Can you retake GH-200 immediately after failing?

Not immediately, but soon. A first retake is allowed 24 hours after the failed attempt. Waiting periods lengthen for subsequent retakes, so the second attempt is the one to prepare properly for.

Conclusion

GH-200 is priced like a fundamentals exam and scoped like a role-based one. The gap between those two facts is where candidates come unstuck: the fee suggests a quick win, while the syllabus quietly asks about runner groups, organisation policies, secret scoping and provenance verification alongside the workflow syntax everyone expects.

Treat the enterprise domain as the centre of your preparation rather than an afterthought, and the rest of the paper follows. Authoring skill you already have; reading someone else’s matrix expansion and restricting a runner group are the things worth practising deliberately before you book.

When your workflow authoring feels solid and the administration half still does not, timed practice across all five domains is the fastest way to see how far apart the two halves really are.

Rating: 0 / 5 (0 votes)

The post GitHub Actions Certification: Half of GH-200 Is Admin Work appeared first on Certification Box.

]]>
Qlik Replicate Certification: Design Is Nearly Half the Exam https://www.certificationbox.com/2026/09/16/qlik-replicate-certification-design-is-nearly-half-the-exam/ Wed, 16 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=30996 Four domains look like four equal parts of a syllabus until you read the percentages: one of them outweighs the other three combined. This is where the QREP marks actually sit, what the smallest domain reveals about the product, and why a low pass mark and a long clock point the same way.

The post Qlik Replicate Certification: Design Is Nearly Half the Exam appeared first on Certification Box.

]]>

Every summary of this exam lists four domains as though they were comparable. They are not. One of them is larger than the other three put together, and a study plan that treats the list as a list rather than as a ranking is aimed at the wrong place from the first evening.

The Qlik Replicate certification, exam code QREP, is 50 questions in 120 minutes at an unusually low 54 percent pass mark, and Design alone carries 47 percent of the marks against 23, 22 and 8 for everything else.

Table of Contents

  1. What is the Qlik Replicate certification?
  2. Why does one domain carry nearly half the marks?
  3. How is the QREP exam delivered and scored?
  4. What sits inside the Design domain?
  5. Administration is almost a quarter of the paper
  6. What does the troubleshooting domain actually ask for?
  7. Why is Operations only 8 percent?
  8. Does Qlik expect you to have used the product first?
  9. How should you prepare for QREP?
  10. Frequently Asked Questions
  11. Conclusion

What is the Qlik Replicate certification?

The Qlik Replicate certification is Qlik’s credential for practitioners who design and run data replication and change data capture pipelines on the Qlik Replicate platform. It carries the exam code QREP, runs to 50 questions across four weighted domains, and is aimed at someone already operating the product rather than someone evaluating it.

Qlik Replicate moves data between systems continuously rather than in scheduled batches. It reads changes at the source, usually from a transaction log, and applies them at the target, which is why the exam’s vocabulary is endpoints, tasks, transformations and exceptions rather than jobs and schedules.

What makes this credential unusually easy to plan for is that Qlik publishes the domain weightings itself. Most vendors leave that to third parties or omit it entirely. Here the vendor and the money site agree on all four figures, which removes the guesswork that normally dominates the first week of study.

Why does one domain carry nearly half the marks?

Design holds 47 percent of the QREP exam, Administration 23 percent, Troubleshooting 22 percent and Operations 8 percent. On a 50 question paper that is roughly 24 questions in Design and about four in Operations, so the four domains are not four equal parts of a syllabus but one dominant subject with three supporting ones.

QREP domain weights showing Design at 47 against Administration 23, Troubleshooting 22 and Operations 8
Domain Weight Approximate questions What it is really about
Design 47% 24 Endpoints, architecture, task type, task settings and transformations
Administration 23% 12 Server settings, user roles, Enterprise Manager, deployment options
Troubleshooting 22% 11 Logs, error handling, diagnostic packages, exception tables
Operations 8% 4 Starting and stopping tasks, and task metadata

The reason for the imbalance is in the nature of the product. Replication is a configuration discipline. Once a task is designed correctly it runs without intervention, which is exactly why day-to-day operation is worth only four questions while the decisions that produced the task are worth twenty four.

That distribution also tells you what kind of questions to expect. A domain worth nearly half the paper cannot be tested by asking where a button is, so Design questions tend to give a requirement and ask which configuration satisfies it. The sample sets on the money site’s QREP practice exam show that shape clearly, which is useful for calibrating early rather than late.

How is the QREP exam delivered and scored?

QREP is 50 questions in 120 minutes with a 54 percent pass mark, priced at $250 USD and registered through Qlik. Qlik publishes the question count, duration, pass mark and all four domain weightings on its own exam-details page, and every figure matches the money site’s syllabus exactly.

Field Value
Credential name Qlik Replicate
Exam code QREP
Questions 50
Duration 120 minutes
Passing score 54 percent
Price $250 USD
Domains 4, all weighted
Registration Qlik
Recommended experience One year minimum with the Replicate platform
Prerequisite certification None

Two of those numbers point in opposite directions and both are worth planning around. A 54 percent pass mark is low, meaning 27 correct answers out of 50 and a margin of 23 questions. That is the most generous allowance of any exam covered here.

The time is generous too. Fifty questions in 120 minutes is 144 seconds each, roughly double what a typical vendor product exam allows. Taken together, a low bar and a long clock usually signal one thing: the questions are expected to take thinking rather than recall. That matches a paper whose largest domain asks which configuration meets a requirement.

What sits inside the Design domain?

Design has four objectives and they escalate. Endpoints, then architecture, then task type and task settings, then transformations. Each one is a decision the person configuring a replication pipeline has to make before anything runs, and together they account for roughly 24 of the 50 questions.

Endpoints and architecture

Endpoints are the source and target definitions, and the objective is specifically about the requirements to create and manage them. Different source systems expose change data differently, which is why the endpoint is not a connection string but a set of decisions about how changes will be read.

The architecture objective sits underneath that. Understanding how the platform captures and applies changes is what makes the endpoint choices comprehensible rather than arbitrary. Qlik’s Replicate introduction documentation is the clearest statement of that model and is worth reading before anything else in this domain.

The underlying mechanism is not proprietary. Reading committed changes out of a database’s own write-ahead log is how most change data capture works, and the PostgreSQL logical replication documentation explains the same idea from the database side. Understanding it there makes the endpoint objective substantially easier, because you stop treating each source system as a special case.

Task type and transformations

The third objective asks you to determine which task type to use and which settings go with it, from a stated requirement. That is the heart of the exam. A full load, an ongoing change capture, or a combination of the two are different task types with different consequences for latency, load and recovery, and the requirement in the question is what decides between them.

The fourth objective does the same for transformations: given a requirement, determine which transformation to use. Transformations in a replication pipeline are deliberately limited compared with a full integration tool, so the skill being tested is knowing what belongs in the pipeline and what does not. A relational target and an event streaming target behave very differently once changes start arriving, which is exactly the kind of consequence the task settings objective expects you to have met.

Administration is almost a quarter of the paper

Administration carries 23 percent, roughly 12 questions, across four objectives: server settings, matching user types to roles, setting up the Enterprise Manager, and listing the deployment options. This is the platform side rather than the pipeline side, and it is where candidates who have only ever configured tasks tend to be thin.

Enterprise Manager deserves particular attention because it is a separate component rather than a screen. It is the layer that gives a single view across multiple Replicate servers, which means it exists for estates rather than for single installations. Anyone who has only worked with one server may never have opened it.

The user types and roles objective is phrased as a matching exercise, which is a hint about question style. Expect items that name a responsibility and ask which role grants it, rather than items that ask you to describe the permission model in the abstract.

Deployment options round it out. Where the product runs, and in what configuration, is a question asked at purchase time and rarely revisited, so it is another objective that experience alone may not have covered.

What does the troubleshooting domain actually ask for?

Troubleshooting is 22 percent, about 11 questions, and it is unusually specific for a domain of that size. Four objectives: getting logs from a task, setting error handling and debug log levels, obtaining a diagnostic package, and debugging errors using the attrep_apply_exceptions table.

The four step troubleshooting route on the QREP syllabus from reading logs to sending a diagnostic package

That last objective is the one worth memorising by name. The exceptions table is where the platform records rows it could not apply at the target, and it is the first place an experienced operator looks when a task is running but data is missing. A question naming it is testing whether you have actually debugged a live pipeline.

The diagnostic package objective is similarly practical. It is the bundle you generate when escalating to support, and knowing what it contains and when to produce it is the difference between a resolved ticket and a week of back and forth.

Error handling settings sit alongside debug logging because they answer the same question from two directions: what should the task do when a row fails, and how much detail should it record while deciding. Twenty two percent is a large share for diagnostics, and it reflects a product whose failures are usually silent rather than loud.

Why is Operations only 8 percent?

Operations carries 8 percent, about four questions, and just two objectives: determining when and why to start or stop a task, and identifying the options for handling task metadata. It is the smallest domain on the syllabus by a wide margin, and that is the most revealing number on the page.

A well designed replication pipeline does not need operating. It runs, and the only genuine operational decisions are when to interrupt it and what happens to its state when you do. Stopping a change capture task is not like stopping a batch job, because the source keeps generating changes while you are stopped, so the decision has consequences that a scheduled job does not have.

Task metadata is the other half of that. What the platform remembers about where a task had reached determines whether restarting resumes or reloads, and that single behaviour is why the objective exists at all.

The planning lesson from an 8 percent domain is not to skip it, since four questions is more than a seventh of the 23 question margin. It is to give it an evening rather than a week, and to spend the time saved in Design.

Does Qlik expect you to have used the product first?

Yes, explicitly. Qlik recommends a minimum of one year of practical experience with the Replicate platform before sitting the exam, alongside expertise in onboarding sources and an understanding of the platform’s components. That is a firmer readiness statement than most vendors publish and it is not on the money site’s syllabus page.

A year is a meaningful bar, and the domain weights explain why. An exam that spends nearly half its marks asking which configuration satisfies a requirement is difficult to pass from documentation, because the answers depend on consequences you have seen rather than rules you have read.

There is no prerequisite certification, so nothing blocks an earlier attempt. The recommendation is about the likelihood of passing rather than about eligibility, and Qlik states it on its Qlik Replicate exam details page alongside the weightings.

For anyone mapping out a wider Qlik profile, the vendor’s credentials differ sharply in how much they publish. The Qlik AI Specialist certification is structured quite differently from this one, which is worth knowing before assuming a single preparation approach covers the portfolio.

How should you prepare for QREP?

Preparation for QREP should follow the weightings rather than the domain order. Roughly half your time belongs in Design, a quarter split between Administration and Troubleshooting each, and a single evening in Operations. The low pass mark means the goal is competence across all four rather than mastery of any one.

  1. Read the Replicate architecture documentation first, because every Design objective assumes you know how changes are captured at the source and applied at the target.
  2. Build endpoints against at least two different source systems, so that the differences in how each exposes change data become concrete rather than theoretical.
  3. Create a full load task and a change capture task against the same endpoint pair, and watch what each does, since the task type objective is the single densest part of the exam.
  4. Apply every transformation type the product offers to a running task, so that determining which transformation a requirement calls for becomes recognition rather than reasoning.
  5. Set up Enterprise Manager even if you only have one server, because it is a separate component that task-level experience never introduces you to.
  6. Break a task deliberately by forcing rows to fail at the target, then read the attrep_apply_exceptions table and generate a diagnostic package from the result.
  7. Stop and restart a change capture task and observe what the retained metadata does to the resume, which is essentially the whole Operations domain in one exercise.
  8. Finish with timed sets of 50 questions, using the full 120 minutes rather than rushing, since the generous clock is there because the questions expect reasoning.

Four to six weeks is realistic for someone already running Replicate in production. Someone with less than Qlik’s recommended year should expect the Design domain to be the constraint, and should spend the extra time building pipelines rather than reading about them.

Practitioners coming from the data quality side of the Qlik portfolio will find the vocabulary familiar but the emphasis different, and the Talend Data Quality Implementer exam is a useful reference point for how differently Qlik weights its data credentials.

Frequently Asked Questions

How many questions are on the QREP exam?

Fifty questions in 120 minutes, which is about 144 seconds each. That is roughly double the per-question time most vendor product exams allow.

What is the passing score for the Qlik Replicate certification?

Fifty four percent, meaning 27 correct answers out of 50 and a margin of 23. Qlik publishes the same figure on its own exam-details page as the money site’s syllabus does.

How much does QREP cost?

$250 USD, registered through Qlik. The price is published on the money site’s syllabus page rather than on Qlik’s exam-details page, which directs candidates to a purchase link instead.

Which QREP domain carries the most marks?

Design, at 47 percent, which is roughly 24 of the 50 questions. Administration follows at 23 percent, Troubleshooting at 22 percent and Operations at 8 percent.

Does Qlik publish the domain weightings itself?

Yes, and all four match the money site’s syllabus exactly. That is unusual. Most vendors publish topic names without percentages, which makes planning a guess rather than a calculation.

How much experience does Qlik recommend before the exam?

A minimum of one year of practical experience with the Replicate platform, plus expertise in onboarding sources and an understanding of the platform’s components.

Is there a prerequisite certification?

None. The one year experience recommendation is guidance on readiness rather than an eligibility condition, so nothing prevents an earlier attempt.

What is the attrep_apply_exceptions table?

It is where the platform records rows it could not apply at the target, and the syllabus names it directly under troubleshooting. It is the first place to look when a task is running but data is missing.

Why is the Operations domain so small?

Because a correctly designed replication task largely runs itself. The only real operational decisions are when to stop or start a task and what happens to its retained metadata, which is exactly what the two objectives cover.

Does the exam cover Enterprise Manager?

Yes, under Administration. Enterprise Manager is a separate component that gives a view across multiple Replicate servers, so anyone who has only worked with a single installation may never have opened it.

Conclusion

QREP is a design exam with three supporting domains attached: 50 questions, 120 minutes, $250, and a 54 percent bar that is the lowest of any credential covered here. Design alone is 47 percent, Administration 23, Troubleshooting 22 and Operations 8, and Qlik publishes every one of those figures itself.

Plan to the weighting rather than the list. Spend half your preparation building and comparing tasks, give Administration and Troubleshooting a genuine block each, and let Operations have a single evening. Then use the full two hours in the exam, because a low pass mark and a long clock together mean the questions were written to be thought about.

Rating: 5 / 5 (1 votes)

The post Qlik Replicate Certification: Design Is Nearly Half the Exam appeared first on Certification Box.

]]>
Symantec ZTNA Certification: 250-583 and Its Eleven Topics https://www.certificationbox.com/2026/09/16/symantec-ztna-certification-250-583-and-its-eleven-topics/ Wed, 16 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=30988 Broadcom lists eleven topic areas for this exam and attaches a percentage to none of them, which removes the one seam candidates normally plan around. Here is what each topic contains, why agentless and agent based publishing get separate treatment, and the experience Broadcom quietly expects before you book.

The post Symantec ZTNA Certification: 250-583 and Its Eleven Topics appeared first on Certification Box.

]]>

Broadcom’s ZTNA exam does not ask what zero trust means. It never defines the model, never compares it with perimeter security, and never asks you to argue for it. Every one of its eleven topics is a place in a console or a decision you make inside one.

The Symantec ZTNA certification is the Technical Specialist credential for Symantec ZTNA Complete, coded 250-583: 75 questions in 90 minutes at a 70 percent bar, with a syllabus that publishes eleven topic names and not a single percentage beside them.

Table of Contents

  1. What is the Symantec ZTNA certification?
  2. Why does Broadcom test the console rather than the concept?
  3. How is the 250-583 exam delivered and scored?
  4. What does the syllabus actually list?
  5. Agentless or agent based, and why the exam splits them
  6. Where ZTNA sits inside the wider SASE stack
  7. What does Broadcom expect you to have done first?
  8. How does the Technical Specialist track work?
  9. How should you prepare for 250-583?
  10. Frequently Asked Questions
  11. Conclusion

What is the Symantec ZTNA certification?

The Symantec ZTNA certification is Broadcom’s intermediate-level credential for administrators of Symantec ZTNA Complete, formally titled Broadcom Symantec ZTNA Complete R1 Technical Specialist and carrying the exam code 250-583. It is a 75 question paper covering eleven topic areas, from the administration portal and authentication through to application publishing, policy, integrations and reporting.

Broadcom classifies the badge as a certification at intermediate level rather than as a foundational or expert one. That placement is honest about the audience: the exam assumes you can already find your way around the product, and spends its questions on what you do once you are there.

The product itself has a second name that turns up constantly in the material. Symantec ZTNA was previously Secure Access Cloud, and Broadcom’s own badge text still uses that older name. Anyone reading around this exam will meet both, and they refer to the same thing.

Why does Broadcom test the console rather than the concept?

Read the eleven topic names in order and the pattern is unmistakable. Symantec ZTNA Portal, Authentication, Network Security Boundary, Agentless Application Configuration, Policy Configuration, Agent Based Application Configuration, Integrations, Role Based Admin Control, Logging and Reporting, Planning. Ten of the eleven describe an administrative task. Only the first, SASE Solution Overview, is conceptual at all.

That design has a consequence worth saying plainly: reading about zero trust will not prepare you for this exam. The architecture is well documented, and the reference most organisations work from is NIST Special Publication 800-207, which sets out the policy engine, policy administrator and policy enforcement point model that products like this one implement. It is genuinely useful background. It will not tell you which screen in the Symantec portal creates a connector. Vendor-neutral practitioner material from the Zero Trust working group is useful for the same reason, because it describes the deployment decisions without assuming any one product.

The productive way to use that document is as a translation layer. When the syllabus says Network Security Boundary, it is talking about enforcement points. When it says Policy Configuration, it is talking about the policy engine. Knowing the abstract model helps you understand why the product is shaped the way it is, but the exam scores you on the shape.

The quickest way to calibrate is to work a set of exam-style items and see how many are locational rather than conceptual. CertFun’s 250-583 practice questions make the difference obvious within the first handful, and that is a cheaper diagnosis than discovering it during the real sitting.

How is the 250-583 exam delivered and scored?

250-583 is 75 questions in 90 minutes, priced at $250 USD, with a 70 percent pass mark, and it is scheduled through Broadcom rather than through a third-party test aggregator. The recommended training is Broadcom’s own Symantec Zero Trust Network Access Administration R1 course. Passing issues a Broadcom Technical Specialist badge through Credly.

Field Value
Credential name Broadcom Symantec ZTNA Complete R1 Technical Specialist
Exam code 250-583
Level Intermediate
Questions 75
Duration 90 minutes
Passing score 70 percent
Price $250 USD
Topic areas 11, with no published weightings
Recommended course Symantec Zero Trust Network Access Administration R1
Scheduling Broadcom

Seventy five questions in 90 minutes is 72 seconds each, which is tight by the standards of vendor product exams. It is roughly a third less time per question than a 50 item, 75 minute paper allows, so the pacing itself is part of the challenge rather than an afterthought.

A 70 percent bar on 75 questions means 53 correct answers and a margin of 22. That sounds generous, and it is the reason the missing weightings matter less than they might: with eleven topics and no published distribution, the safest assumption is that no single topic can be skipped, and a 22 item allowance is enough to absorb one genuinely weak area but not two.

What does the syllabus actually list?

Eleven topic areas, published as names and objectives with no percentage beside any of them. That is unusual and it changes how you should plan. Without weightings there is no way to rank topics by exam value, so the defensible approach is to treat coverage as flat and work through every one rather than gambling on which will dominate.

Topic What the objectives describe
SASE Solution Overview The benefits of the Symantec SASE solution and of ZTNA within it
Symantec ZTNA Portal Navigating the admin portal and administering tenant admins
Authentication Configuring and administering authentication
Network Security Boundary Implementing and administering sites and connectors
Agentless Application Configuration Implementing and administering agentless applications
Policy Configuration Implementing and administering policies on configured applications
Agent Based Application Configuration Agent based applications, plus integrating Cloud SWG and DNS servers
Integrations Integration with Cloud Data Loss Prevention and Threat Intelligence Services
Role Based Admin Control Using RBAC with ZTNA sites and with collections
Logging and Reporting Log shipping, health checks and notifications
Planning Planning and deploying ZTNA in an organisation

Two of these are easy to underestimate. Planning is a single objective and reads like a throwaway, but it is the only topic that asks you to think about a whole deployment rather than a single setting, which makes it the most likely home for scenario-shaped questions. Logging and Reporting looks administrative and covers health checks and notifications, which are the mechanisms by which a broken connector becomes visible.

Role Based Admin Control deserves a second look too, because it is explicitly tested in two different scopes: against sites and against collections. Those are different objects with different inheritance behaviour, and a question that names one when you are thinking of the other is a straightforward way to lose a mark.

Agentless or agent based, and why the exam splits them

The syllabus gives agentless and agent based application configuration two separate topics rather than one, which is the clearest structural signal it offers. They are different publishing models with different capabilities, and the exam wants you to know which one a described requirement calls for.

Comparison of agentless and agent based application publishing in the Symantec ZTNA 250-583 syllabus

Agentless publishing puts the service in front of a web application and brokers the session without anything installed on the user’s device. It is the model that makes third-party and unmanaged-device access workable, because there is nothing to deploy to a machine you do not control.

Agent based publishing installs a client and can therefore reach applications that are not web based, handling protocols a browser cannot broker. The syllabus attaches two integrations to this topic specifically: Cloud Secure Web Gateway and DNS servers. That pairing is not decorative. Once a client is on the device, web traffic and name resolution both become things the platform can influence, which is why those integrations belong here rather than in the general integrations topic.

This is also where the comparison people actually search for gets answered. The practical difference between this model and a traditional remote access tunnel is that a tunnel grants network reachability and this grants application reachability, one published application at a time. A candidate who understands that distinction will find most of the policy questions follow from it.

Where ZTNA sits inside the wider SASE stack

The first topic on the syllabus is the SASE Solution Overview, and it exists because ZTNA Complete is not sold or deployed alone. Broadcom’s Symantec ZTNA product page positions it inside a wider network protection portfolio, and the exam’s integration objectives reflect exactly that.

Three named integrations run through the syllabus. Cloud Secure Web Gateway handles outbound web traffic. Cloud Data Loss Prevention inspects what moves through the sessions ZTNA brokers. Threat Intelligence Services supplies the reputation and threat context that policy decisions can act on.

Understanding those as a set rather than as three unrelated checkboxes is what the overview topic is really testing. A question about why a policy references DLP is answerable from the architecture; it is not answerable by memorising the name of a menu item.

It is worth knowing which parts of the portfolio are separately certified, too. Broadcom runs Technical Specialist exams across the Symantec line, including web protection, endpoint and messaging products, so the ZTNA credential is one node in a set rather than a standalone qualification.

What does Broadcom expect you to have done first?

Broadcom states its expectation on the badge record rather than on the syllabus page, and it is specific: three to six months of experience working with Symantec ZTNA in production or in a lab, alongside completing eLearning and instructor-led training. There is no formal prerequisite certification, but there is a clear experience assumption.

That detail is the most useful thing a candidate can find before booking, and it is easy to miss because it lives on the badge page rather than with the exam specifications. A reader who has been using the product for a fortnight now knows the honest answer to whether they are ready.

There is one administrative step in the same list that catches people out. Earning the badge requires accepting Broadcom’s Software Certification Agreement, which is not an academic requirement at all, but it is part of the process and it is worth doing before results day rather than after. The Broadcom ZTNA badge record lists all four requirements together.

How does the Technical Specialist track work?

Technical Specialist is a tier in Broadcom’s certification programme rather than a single qualification, and it runs across the whole Symantec and CA software portfolio. Each product line has its own exam in the 250 series, each is scoped to that product, and none of them is a prerequisite for another.

That structure explains why the credential is narrow on purpose. It is not trying to establish that you understand network security generally. It is establishing that you can run one named product, which is precisely what a partner or a customer wants to verify before letting someone near a production tenant. Broadcom describes the programme structure on its software certification programme page.

Anyone building a Symantec profile will find the exams share a shape more than they share content. The Symantec Messaging Gateway specialist exam sits in the same tier and follows the same console-first logic, which means preparation habits transfer even though nothing on the syllabus does.

The same numbering scheme runs across the wider portfolio, well beyond the Symantec security line, so a 250 series code on its own tells you the tier rather than the subject.

How should you prepare for 250-583?

Preparation for 250-583 should be flat rather than weighted, because the syllabus publishes no percentages. Cover all eleven topics, spend the extra time on the two application-publishing topics and on policy, and rehearse the pace, because 72 seconds a question is the constraint most candidates underestimate.

The three integrations named in the 250-583 syllabus: Cloud Secure Web Gateway, Cloud Data Loss Prevention and Threat Intelligence Services
  1. Check your experience honestly against Broadcom’s own expectation of three to six months working with Symantec ZTNA, and if you fall short, get lab time before you book rather than after you fail.
  2. Work through the Symantec Zero Trust Network Access Administration R1 course, since Broadcom names it as the recommended training and the syllabus follows its structure.
  3. Publish one application each way, agentless and agent based, so that the two separate topics become two distinct experiences rather than a single blurred memory.
  4. Attach policies to both published applications and change them, because policy configuration is tested against configured applications rather than in isolation.
  5. Configure the three named integrations, Cloud Secure Web Gateway, Cloud Data Loss Prevention and Threat Intelligence Services, so the architecture questions rest on something you have wired rather than read.
  6. Set up role based admin control twice, once scoped to sites and once scoped to collections, since the syllabus explicitly tests both and they behave differently.
  7. Break a connector deliberately and follow it through log shipping, health checks and notifications, which turns the reporting topic into a diagnosis you have actually performed.
  8. Finish with timed sets at 75 questions in 90 minutes until the pace feels routine, and accept the Broadcom Software Certification Agreement before exam day so the badge issues cleanly.

Four to six weeks is a sensible window for an administrator already working with the platform. The breadth is the work here, not the depth, because eleven topics with no weightings leaves nowhere safe to be thin.

The habit of preparing in the console rather than from notes carries across the tier. Broadcom’s workload automation line follows the same pattern, and the AutoSys 250-613 exam is another Technical Specialist paper built entirely around a single product’s administration surface.

Frequently Asked Questions

How many questions are on the 250-583 exam?

Seventy five questions in 90 minutes, which works out at about 72 seconds each. That is tighter than most vendor product exams and the pacing is worth rehearsing.

What is the passing score for the Symantec ZTNA certification?

Seventy percent, which on 75 questions means 53 correct answers and a margin of 22. Broadcom does not publish a scaled score for this exam.

How much does Broadcom 250-583 cost?

$250 USD. Scheduling is through Broadcom rather than a third-party aggregator.

Are the topics weighted?

No. The syllabus publishes eleven topic names with objectives under each and no percentages at all. Without a distribution, the safe plan is to treat coverage as flat rather than guess which topic dominates.

Do I need experience before taking this exam?

Broadcom sets no formal prerequisite certification, but its own badge record expects three to six months of hands-on work with Symantec ZTNA in production or a lab, alongside eLearning and instructor-led training.

What is the difference between agentless and agent based publishing here?

Agentless brokers access to web applications with nothing installed on the device, which is what makes unmanaged-device access workable. Agent based installs a client, reaches non-web applications, and is where the Cloud Secure Web Gateway and DNS integrations attach.

Does the exam test zero trust theory?

Barely. Only the SASE Solution Overview topic is conceptual, and even that is framed around the benefits of Symantec’s own solution. The other ten topics are administration tasks.

Is Symantec ZTNA the same as Secure Access Cloud?

Yes. Secure Access Cloud is the former name, and Broadcom’s badge text still uses it, so both names appear across the documentation and refer to the same product.

Which integrations does the syllabus name?

Three: Cloud Secure Web Gateway and DNS servers under the agent based topic, and Cloud Data Loss Prevention plus Threat Intelligence Services under the integrations topic.

Does the credential expire?

Broadcom states no expiry or validity period on the badge record. Because the exam is tied to release R1 of the product, its practical currency is likely to follow the product rather than a fixed clock.

Conclusion

250-583 is a broad, console-first product exam with an unusually bare syllabus: eleven topics, no weightings, 75 questions in 90 minutes, and a 70 percent bar. The missing percentages are the defining feature, because they remove any safe place to be thin and make even coverage the only defensible plan.

Take Broadcom’s own three to six month experience expectation seriously, publish an application both ways, wire the three named integrations, and practise at the pace the clock actually demands. Then book it, accept the certification agreement in advance, and treat the badge as proof you can run this one product well rather than as a general zero trust qualification.

Rating: 0 / 5 (0 votes)

The post Symantec ZTNA Certification: 250-583 and Its Eleven Topics appeared first on Certification Box.

]]>
Network Security Analyst Certification: NetSec-Analyst https://www.certificationbox.com/2026/09/15/network-security-analyst-certification-netsec-analyst/ Tue, 15 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=30969 Palo Alto puts its Specialist tier above Professional, and NetSec-Analyst is the Specialist credential for the people who configure firewalls rather than deploy them. Sixty percent of the paper is objects and policies, a quarter is Strata Cloud Manager, and the pass mark sits 560 points up a 700 point scale.

The post Network Security Analyst Certification: NetSec-Analyst appeared first on Certification Box.

]]>

A pass mark of 860 out of 1000 sounds brutal until you notice the scale starts at 300, not at zero. That single detail reframes the whole exam, and it is the kind of thing a candidate discovers on results day rather than while planning.

NetSec-Analyst is Palo Alto Networks’ Specialist tier credential for the people who actually build and maintain firewall configuration: 60 questions, 90 minutes, four weighted domains, and a syllabus that puts 60 percent of the marks into object and policy creation before it asks about anything else.

Table of Contents

  1. What is the network security analyst certification?
  2. Specialist sits above Professional in Palo Alto’s scheme
  3. How is the NetSec-Analyst exam delivered and scored?
  4. What does 860 on a 300 to 1000 scale actually mean?
  5. How are the four domains weighted?
  6. Why do objects and policies carry 60 percent between them?
  7. Strata Cloud Manager is a quarter of the exam on its own
  8. What does the troubleshooting domain actually ask?
  9. Who is this certification written for?
  10. How should you prepare for NetSec-Analyst?
  11. Frequently Asked Questions
  12. Conclusion

What is the network security analyst certification?

The network security analyst certification is Palo Alto Networks’ credential for analysts and firewall administrators, formally the Palo Alto Networks Certified Network Security Analyst and coded NetSec-Analyst. It validates object configuration, policy creation, and centralised management through Strata Cloud Manager, and it adds the ability to improve security posture and troubleshoot a configured environment.

What distinguishes it from the engineer level credentials in the same platform is the work it describes. An engineer exam asks how a firewall is deployed and integrated. This one asks what you put into it day after day: which security profile, which decryption policy, which external dynamic list, and which centralised object structure keeps all of that manageable across a fleet.

Palo Alto’s own Network Security Analyst certification page names a wide target audience for it: network security analysts, firewall administrators, network engineers, security engineers, professional services consultants and technical support engineers. That breadth is accurate rather than marketing. The tasks in the syllabus are done by all of those roles.

Specialist sits above Professional in Palo Alto’s scheme

Palo Alto Networks runs four certification levels, and they are not ordered the way most vendors order theirs. The sequence is Foundational, then Professional, then Specialist, then Architect. NetSec-Analyst is a Specialist credential, which puts it above the Network Security Professional exam rather than below it.

The logic behind it is product depth rather than seniority. Palo Alto describes Professional as validating operations and management across a platform, and Specialist as validating the deployment, operation and management of a product. So Specialist is narrower and deeper, not junior.

Within the Network Security platform, the Specialist tier holds four exams: Network Security Analyst, Next-Generation Firewall Engineer, SD-WAN Engineer and Security Service Edge Engineer. They share a tier and test almost entirely different things, so the tier label tells you very little about which one to sit.

How is the NetSec-Analyst exam delivered and scored?

NetSec-Analyst is 60 questions in 90 minutes, priced at $250 USD, delivered through Pearson VUE, and scored on a scale of 300 to 1000 with 860 required to pass. Palo Alto publishes the level, platform, objectives and target audience on its certification page but keeps the numeric specifications in a downloadable datasheet, so the figures here come from the money site’s published syllabus.

Field Value
Credential name Palo Alto Networks Certified Network Security Analyst
Exam code NetSec-Analyst
Level Specialist
Platform Network Security
Questions 60
Duration 90 minutes
Scoring Scaled 300 to 1000, with 860 to pass
Price $250 USD
Delivery Pearson VUE
Domains Four, all weighted

Ninety minutes across 60 questions is 90 seconds each, which is comfortable for a configuration exam. The time pressure on this paper is low; the precision pressure is high, because most wrong answers are plausible configurations that solve a slightly different problem. Running a NetSec-Analyst practice test broken down by domain is the fastest way to see whether your errors are knowledge gaps or reading errors.

What does 860 on a 300 to 1000 scale actually mean?

The scale runs from 300 to 1000, not from 0 to 1000, so the usable range is 700 points wide and 860 sits 560 points into it. That is roughly 80 percent of the way up the usable scale rather than 86 percent of everything, which is a meaningfully different proposition.

Two things follow from a scaled score of this kind. The first is that it does not convert into a fixed number of correct answers, because items are weighted by difficulty and calibrated across forms. Anyone who tells you 860 means exactly 52 of 60 is guessing. The second is that there is no partial credit to plan around and no domain level score to learn from, so an even standard across all four domains is worth more than a peak in one.

Practically, treat it as a demanding bar and prepare to be comfortable rather than borderline. On a 60 item paper there is very little room for the handful of questions everybody gets wrong.

How are the four domains weighted?

NetSec-Analyst has four domains and publishes a weighting against each. Object Configuration Creation and Application and Policy Creation and Application are 30 percent apiece, Management and Operations is 26 percent, and Troubleshooting is 14 percent.

Domain Objectives Weight
Object Configuration Creation and Application Create and apply security profiles and security profile groups; decryption profiles; external dynamic lists; custom objects such as URL categories, signatures and data patterns; Log Forwarding profiles; data security profiles; internet of things security profiles; DoS protection profiles; SD-WAN profiles and templates 30%
Policy Creation and Application Create and apply Security policies using App-ID, User-ID and Content-ID; NAT policies; decryption policies; application override policies; Policy Based Forwarding policies; SD-WAN routing and service-level agreement policies 30%
Management and Operations Use a centralized management system including Strata Cloud Manager, folders and snippets, automations and variables, and Strata Logging Service; use Command Center, Activity Insights and Policy Optimizer to improve security posture; use Log Viewer and the Incidents and Alerts page to remediate incidents and alerts 26%
Troubleshooting Troubleshoot misconfigurations across all management and on-box options; troubleshoot runtime and commit or push errors; troubleshoot device usage and health 14%

On a 60 item paper that is roughly 18, 18, 16 and 8 questions. The distribution is deliberate: three quarters of the exam is about making things, and the remaining quarter is about noticing when they are wrong.

Why do objects and policies carry 60 percent between them?

Objects and policies are 60 percent because on this platform they are the entire mechanism of enforcement. A policy decides what is allowed; an object decides what the policy inspects it with. Neither is useful alone, and the exam tests them as two halves of one skill rather than as separate topics.

A policy decides if traffic passes, a profile inspects what passes and an object defines what counts as a match

The object domain is the broader of the two. Nine distinct object families appear in it, from security profile groups and decryption profiles through external dynamic lists to IoT security profiles, DoS protection profiles and SD-WAN templates. That breadth is the difficulty: each family has its own application rules, and a question typically describes a requirement and asks which object family answers it.

The distinction most candidates get wrong

A recurring question shape gives you a requirement that could plausibly be met by a profile, by a custom object or by a policy, and asks which is correct. The reliable way through it is to ask what is being decided. If the answer is whether traffic is permitted at all, it is a policy. If the answer is how permitted traffic is inspected, it is a profile. If the answer is what counts as a match, it is a custom object.

Application override policies and Policy Based Forwarding are the two policy types that catch out candidates from a pure firewall background, because both change how the platform treats traffic rather than whether it passes. Those two deserve deliberate time.

Strata Cloud Manager is a quarter of the exam on its own

Management and Operations is 26 percent, and it is built almost entirely around Strata Cloud Manager and Strata Logging Service. The objectives name folders and snippets, automations and variables, Command Center, Activity Insights, Policy Optimizer, Log Viewer and the Incidents and Alerts page.

Folders and snippets are the concept to settle first. They are how configuration is organised and reused across a fleet in a cloud managed model, and they behave differently from the device group and template structure that Panorama users will expect. A candidate whose entire experience is on-box or Panorama managed will find this domain unfamiliar in a way the other three are not.

Policy Optimizer and Activity Insights sit under the posture improvement objective, and this is where the exam moves from configuration to judgement. Vendor neutral posture frameworks such as the CIS Benchmarks describe the same underlying idea of measuring a configuration against a known good standard, which makes the platform specific tooling easier to reason about.

What does the troubleshooting domain actually ask?

Troubleshooting is 14 percent, roughly eight questions, and its three objectives are narrower than the name suggests: misconfigurations across management and on-box options, runtime and commit or push errors, and device usage and health.

The commit and push objective is the one to read carefully. In a centrally managed estate a change can be valid locally and fail on push, or succeed on push and behave unexpectedly because of where it sat in the folder hierarchy. Questions in this area usually describe an error at commit or push time and ask what caused it, which is a different skill from diagnosing traffic that is not flowing.

The incident and alert remediation work sits in Management and Operations rather than here, which is worth knowing when you are planning revision. If you are strengthening the detection and response side alongside this, our guide to the XSIAM Analyst certification covers the security operations platform where that work properly lives. Frameworks such as MITRE ATT&CK give the vendor neutral vocabulary for the adversary behaviour those alerts describe.

Who is this certification written for?

Palo Alto names six roles explicitly: network security analysts, firewall administrators, network engineers, security engineers, professional services consultants and technical support engineers. What unites them is responsibility for configuration rather than for design, and that is the honest test of fit.

Two groups should think twice. Architects and designers will find the exam asks for a level of configuration detail their role does not touch, and the Architect tier credential is the better match. Security operations analysts whose work is alerts and investigations rather than firewall policy will recognise perhaps a quarter of the syllabus.

The natural neighbour in the same Specialist tier is the firewall engineering credential, which covers deployment and platform integration where this one covers what you configure once the platform is in place. Our walkthrough of the NGFW Engineer exam domains sets out that division in detail, and the two together cover most of what a firewall team does.

How should you prepare for NetSec-Analyst?

This is a configuration exam, so preparation has to be hands-on in a lab where you can create objects and watch policies take effect. Four to six weeks is realistic for someone administering Palo Alto firewalls already; a candidate new to Strata Cloud Manager should add two weeks for that domain alone.

Four NetSec-Analyst lab exercises covering objects, policies, folders and forced push failures
  1. Start with the object families, creating at least one of every type named in the syllabus so that security profiles, decryption profiles, external dynamic lists and custom objects are concrete rather than remembered
  2. Move to policies next, building Security, NAT and decryption policies against the objects you just created, so the dependency between the two domains is experiential
  3. Add the two policy types people skip, application override and Policy Based Forwarding, and observe how each changes the treatment of traffic that would otherwise pass unchanged
  4. Spend a dedicated block on Strata Cloud Manager, building a folder and snippet structure and pushing the same configuration to more than one device
  5. Run Policy Optimizer and Command Center against that estate, so the posture improvement objective is something you have used rather than read about
  6. Finish by breaking things deliberately, forcing commit and push failures and device health issues, then sit timed sets until 60 questions in 90 minutes is routine

The highest value single exercise is step four. Folders and snippets are the concept that separates candidates who have used Strata Cloud Manager from candidates who have read about it, and a quarter of the exam sits on top of it.

Frequently Asked Questions

How many questions are on the NetSec-Analyst exam?

Sixty questions within 90 minutes, according to the money site’s published syllabus. Palo Alto keeps the numeric specifications in a downloadable datasheet rather than on its web page, so this is not an officially rendered figure.

What is the passing score for the network security analyst certification?

Eight hundred and sixty on a scale that runs from 300 to 1000. Because the scale starts at 300 rather than zero, 860 is roughly 80 percent of the way up the usable range, and it does not convert into a fixed number of correct answers.

How much does the NetSec-Analyst exam cost?

$250 USD, with registration through Pearson VUE.

What level is the Network Security Analyst certification?

Specialist. In Palo Alto’s scheme that sits above Professional, because Specialist means narrower and deeper product knowledge rather than a more junior credential.

Which NetSec-Analyst domain carries the most marks?

Two domains tie at 30 percent each: Object Configuration Creation and Application, and Policy Creation and Application. Management and Operations follows at 26 percent and Troubleshooting at 14 percent.

Does the exam require Strata Cloud Manager experience?

Effectively, yes. The Management and Operations domain is 26 percent of the paper and is built around Strata Cloud Manager and Strata Logging Service, including folders, snippets, automations and variables. Panorama experience does not transfer cleanly.

Is there a prerequisite for NetSec-Analyst?

Palo Alto publishes no prerequisite certification for it on its certification page. The recommended route is to review the datasheet topics and then work through the digital learning path.

What is the difference between NetSec-Analyst and the NGFW Engineer exam?

Both are Specialist tier credentials on the Network Security platform, but they test different work. This one covers what you configure once the platform is in place; the engineer credential covers deploying and integrating the platform itself.

Does the exam cover SD-WAN?

Yes, in two places. SD-WAN profiles and templates appear in the object domain, and SD-WAN routing and service-level agreement policies appear in the policy domain.

How much of the exam is troubleshooting?

Fourteen percent, roughly eight questions, covering misconfigurations across management and on-box options, runtime and commit or push errors, and device usage and health. Incident and alert remediation sits in a different domain.

Conclusion

NetSec-Analyst is a configuration exam with an unusually demanding bar: 60 questions, 90 minutes, $250 USD, and 860 on a scale that starts at 300. Four domains weighted 30, 30, 26 and 14 percent put three quarters of the marks on building things correctly and the rest on spotting when they are not.

Prepare in a lab rather than a book, and give Strata Cloud Manager the block of time its 26 percent deserves, because folders and snippets are where Panorama experience stops helping. Build every object family the syllabus names, attach policies to them, then break the estate on purpose. The exam is less about knowing what a feature is than about knowing which of three defensible configurations the described requirement actually calls for.

Rating: 0 / 5 (0 votes)

The post Network Security Analyst Certification: NetSec-Analyst appeared first on Certification Box.

]]>
FinOps Certification: Where the FOCP Marks Actually Sit https://www.certificationbox.com/2026/09/15/finops-certification-where-the-focp-marks-actually-sit/ Tue, 15 Sep 2026 00:00:00 +0000 https://www.certificationbox.com/?p=30962 Revising all six FOCP domains evenly wastes most of the effort. Lifecycle and Capabilities hold 58 percent of the marks between them, the pass bar is a tight 75 percent, and the purchase quietly includes three attempts across a year. Here is what that structure means for how you prepare.

The post FinOps Certification: Where the FOCP Marks Actually Sit appeared first on Certification Box.

]]>

Nobody watches you take this one. The FinOps Certified Practitioner exam is unproctored, and buying it gives you three attempts across twelve months rather than one high stakes hour. That single structural fact reframes the whole preparation question, and almost nobody mentions it.

What it does not do is make the exam soft. Fifty questions, sixty minutes, and a 75 percent bar, with 58 percent of the marks concentrated in just two of the six domains. Knowing which two is the difference between revising evenly and revising usefully.

Table of Contents

  1. What is the FinOps certification, and who actually awards it?
  2. How is the FOCP exam delivered and scored?
  3. Where do the FOCP marks actually sit?
  4. Why do Capabilities and Lifecycle carry 58 percent between them?
  5. What the FOCP exam does not test
  6. Three attempts in twelve months changes how you prepare
  7. How long does the credential last?
  8. How should a cloud engineer prepare for FOCP?
  9. Who actually benefits from a FinOps certification?
  10. Frequently Asked Questions
  11. Conclusion

What is the FinOps certification, and who actually awards it?

The FinOps certification most people mean is the FinOps Certified Practitioner, exam code FOCP, and it is awarded by the FinOps Foundation rather than by a cloud vendor. The FinOps Foundation sits under the Linux Foundation umbrella, which is why the credential is often listed under Linux Foundation cloud and containers certifications, but the exam, the syllabus and the certificate all come from the Foundation itself.

That ownership matters more than it sounds. Because no cloud provider writes the exam, nothing in it is specific to one billing console. FOCP tests a discipline: how an organisation brings engineering, finance and business together to get value out of variable cloud spend. The published FinOps Framework is the source material, and the exam is essentially a check that you can work inside it.

It is a practitioner level credential, not an expert one. The Foundation positions it as the entry point into a career track that continues into more specialised credentials, and it assumes familiarity with cloud rather than deep engineering skill.

How is the FOCP exam delivered and scored?

FOCP is a 50 question exam with a 60 minute limit and a 75 percent pass mark, taken online and unproctored. The FinOps Foundation confirms every one of those figures on its own FOCP certification exam page, and adds that the purchase covers three attempts within twelve months of the purchase date rather than a single sitting.

Field Value
Credential name FinOps Certified Practitioner
Exam code FOCP
Questions 50 multiple choice
Duration 60 minutes
Passing score 75 percent
Price $325 USD for the standalone exam
Proctoring None
Attempts included Three, within 12 months of purchase
Credential validity 24 months
Awarding body FinOps Foundation

Seventy five percent of 50 questions means 38 correct answers, with room for 12 wrong ones. That is a tighter margin than most practitioner level exams, and it is the reason domain weighting matters so much here: losing a whole domain is survivable only if it is one of the small ones. Sitting a FOCP practice test broken down by domain is the quickest way to find out which one would sink you.

The absence of proctoring is a genuine convenience rather than a loophole. The clock is still 60 minutes, the questions still require you to have internalised the Framework, and 72 seconds per question does not leave time to look things up. Treat it as an open environment you will not have time to use.

Where do the FOCP marks actually sit?

The FOCP syllabus divides into six domains, and unlike many practitioner exams it publishes a weighting against every one of them. Two domains, FinOps Lifecycle at 30 percent and FinOps Capabilities at 28 percent, account for 58 percent of the paper between them. The remaining four share the other 42 percent.

Domain Objectives Weight
FinOps Lifecycle Describe the FinOps lifecycle, its phases and purpose; understand the basic processes that FinOps teams enact in the FinOps Lifecycle 30%
FinOps Capabilities Understand the six pillars of FinOps Capabilities; describe the activities associated with each capability 28%
What is FinOps & FinOps Principles Define FinOps; understand each of the FinOps Principles 12%
FinOps Teams & Motivation Describe the skills, roles and responsibilities of a FinOps Team; describe where a FinOps team would be situated; understand what drives a FinOps team’s size, position and makeup 12%
Terminology & the Cloud Bill Understand basic cloud, FinOps, DevOps and Finance terminology; describe the characteristics of the Cloud Bills 10%
Challenge of Cloud Understand the challenges of working with Cloud; recognize the differences between Cloud and Traditional IT 8%

Read as question counts rather than percentages, the picture sharpens. Lifecycle is worth roughly 15 questions and Capabilities roughly 14. Challenge of Cloud is worth about four. A candidate who spends equal evenings on all six domains has given the same attention to a four question topic as to a fifteen question one.

Why do Capabilities and Lifecycle carry 58 percent between them?

Those two domains carry the weight because they are the only ones that describe what a FinOps team does rather than what FinOps is. Principles, terminology and team structure are context. Capabilities and Lifecycle are the operating model, and the exam is built to check you could actually run one.

The FinOps lifecycle loop with three phases: Inform, Optimize and Operate

The Lifecycle domain, at 30 percent

The FinOps Foundation names three phases: Inform, Optimize and Operate. Inform is about visibility into spend, Optimize is about acting on it, and Operate is about running the practice continuously. The exam asks which phase a described situation belongs to, what a team does in each phase, and why a given activity would be premature in one phase and correct in another. Expect scenarios rather than definitions.

The recurring trap is assuming the phases are a project with an end. They are a loop, and a maturing organisation revisits the earliest phase for every new workload. Questions that describe a team declaring the work finished are usually testing exactly that.

The Capabilities domain, at 28 percent

Capabilities are the specific practices a FinOps team performs, grouped under a small number of pillars, and the objective asks you to describe the activities associated with each. This is the domain where memorisation genuinely helps, because the groupings are a published taxonomy rather than something you can derive from first principles.

It also connects to real tooling more than the rest of the syllabus. Cost allocation, showback and chargeback are recognised practices with open implementations behind them, and the vendor neutral OpenCost project is a useful way to see what allocation means in practice if your experience is on the finance side rather than the engineering side.

What the FOCP exam does not test

FOCP does not test any cloud provider’s console, pricing calculator, CLI or billing export format. It does not require you to write a query, build a dashboard or configure a budget alert. Candidates arriving from a hands on cloud role frequently over prepare on exactly those things and under prepare on the Framework taxonomy.

What the FOCP exam tests and what it does not, compared side by side

Three specific things people revise unnecessarily:

  • Provider specific discount mechanisms and their commercial terms, which vary by provider and are not what the questions are about
  • Tagging syntax and policy enforcement mechanics, as opposed to the reason allocation matters
  • Deep unit economics mathematics, when the exam wants you to recognise the concept and where it sits in the lifecycle

The inverse is also true. Engineers routinely underestimate the finance side of the Terminology and the Cloud Bill domain, which is only 10 percent but is also the domain where a technical candidate is most likely to lose every question in it.

Three attempts in twelve months changes how you prepare

The purchase buys three attempts within twelve months, which is unusually generous and worth planning around rather than ignoring. The rational strategy is not to treat attempt one as disposable, but it does mean a genuine first attempt is far cheaper than on an exam where a retake is another full fee.

What that structure supports is a diagnostic first sitting. If you are within reach of the material, sitting the exam early gives you the strongest possible signal about which of the six domains is weak, and you still hold two attempts and most of a year. On a single attempt exam that would be reckless. Here it is a legitimate tactic.

The counterweight is that no score breakdown by domain is promised, so the diagnostic value comes from your own sense of which questions felt unfamiliar. Write down the topics that surprised you the moment you finish, because that recollection fades within an hour.

How long does the credential last?

The FinOps Certified Practitioner certification is valid for 24 months from the date you pass. The Foundation states this alongside the exam details, together with the certificate and Credly badge you receive immediately on passing.

Two years is short by certification standards, and it is deliberate. FinOps as a discipline has changed substantially in that timeframe, with new capability areas and a shifting emphasis toward software and AI spend rather than infrastructure alone. A credential that outlived those changes would not mean much.

Plan the renewal as a genuine refresh rather than an administrative one, and if you are mapping out the wider programme, our earlier FOCP exam preparation resources cover the study material side in more depth than this format guide does.

How should a cloud engineer prepare for FOCP?

A cloud engineer preparing for FOCP needs roughly three weeks of evenings, weighted heavily toward the two large domains and toward the finance vocabulary that engineering roles rarely use. The sequence below front loads the 58 percent and leaves the small domains until the material is familiar.

  1. Read the FinOps Framework end to end first, so the vocabulary is in place before any domain revision begins
  2. Spend the largest block on Capabilities and Lifecycle together, mapping each capability to the lifecycle phase where it is performed
  3. Work through the finance side of Terminology and the Cloud Bill next, because it is the domain where a technical candidate loses whole questions
  4. Cover Principles, Teams and Challenge of Cloud last, since they are context domains worth 32 percent combined and largely comprehension rather than recall
  5. Sit full length timed sets until you finish inside 60 minutes with a margin, then use your first official attempt as a real one

Two practical notes. Map every capability to a lifecycle phase explicitly, on paper, because a large share of the 58 percent sits precisely at that join. And do the reading in the Foundation’s own words, since the exam uses the published taxonomy rather than paraphrases of it.

Who actually benefits from a FinOps certification?

FOCP pays off most clearly for people who sit between two functions and need shared language to work across them. Cloud engineers who keep being asked to justify spend, finance analysts who have inherited a cloud bill nobody can explain, and platform leads standing up a cost practice from nothing all get concrete value from a common taxonomy.

It is a weaker investment for two groups. Deep infrastructure specialists with no organisational remit will find most of the syllabus describes meetings they do not attend. And anyone hoping the credential alone will create a FinOps role in an organisation that has not decided it wants one will be disappointed, because the certification describes a practice rather than a job title.

Where it does land, it lands quickly, because the discipline is young enough that a shared vocabulary is genuinely scarce. If you are assembling a broader cloud and containers credential set around it, the wider Linux Foundation certification programme covers the adjacent engineering credentials that pair naturally with a cost practice.

Frequently Asked Questions

How many questions are on the FOCP exam?

Fifty multiple choice questions within a 60 minute limit. The FinOps Foundation publishes both figures on its own exam page, and the money site syllabus page gives the same numbers.

What is the passing score for the FinOps Certified Practitioner exam?

Seventy five percent, which works out at 38 correct answers from 50. That leaves a margin of 12 wrong answers, which is tighter than most practitioner level credentials.

How much does the FinOps certification cost?

The standalone certification exam is $325 USD. That purchase includes three attempts within twelve months of the purchase date, and bundles that add course materials or further credentials are priced separately.

Is the FOCP exam proctored?

No. The FinOps Foundation states explicitly that you are not proctored while taking the exam. The 60 minute time limit still applies, so there is no practical time to look answers up.

How long is the FinOps Certified Practitioner certification valid?

Twenty four months from the date you pass. The discipline changes quickly enough that the renewal is a genuine refresh rather than an administrative formality.

Which FOCP domain carries the most marks?

FinOps Lifecycle at 30 percent, closely followed by FinOps Capabilities at 28 percent. Together those two domains carry 58 percent of the paper, or roughly 29 of the 50 questions.

Do you need cloud engineering experience to pass FOCP?

No. The exam tests the FinOps Framework rather than any provider’s console or tooling, so finance and business candidates are within reach. What they do need is comfort with basic cloud terminology, which is its own 10 percent domain.

Who awards the FinOps Certified Practitioner credential?

The FinOps Foundation, which sits under the Linux Foundation umbrella. That is why the credential often appears in Linux Foundation cloud and containers listings even though the Foundation writes and delivers the exam itself.

Can you retake the FOCP exam if you fail?

Yes. The purchase includes three attempts, and all three must be used within twelve months of the purchase date. After that window a new purchase is required.

Is FOCP tied to AWS, Azure or Google Cloud?

No. It is deliberately provider neutral. Nothing in the six domains depends on one billing console, one pricing model or one discount mechanism, which is what makes the credential portable across employers.

Conclusion

FOCP is a short, provider neutral exam with an unusually forgiving purchase structure and an unusually demanding pass mark. Fifty questions, 60 minutes, 75 percent, $325 USD for three attempts inside a year, and a credential that expires after 24 months.

The preparation decision is settled by the weighting table rather than by instinct. Lifecycle and Capabilities are 58 percent of the paper and deserve more than half the study time; Challenge of Cloud is 8 percent and deserves an evening. Read the Framework in the Foundation’s own words, map every capability to the lifecycle phase where it happens, give the finance vocabulary genuine attention if you come from engineering, and then use the first of your three attempts as a real one.

Rating: 0 / 5 (0 votes)

The post FinOps Certification: Where the FOCP Marks Actually Sit appeared first on Certification Box.

]]>