ITlearnHub
DoD cyber workforce

Connect your study plan to a DCWF work role.

Explore roles that overlap with Network+ and Security+ knowledge. This is career and learning guidance—not an official determination that a certification qualifies you for a position.

Use the current official matrix for qualification decisions.

DoD 8140 qualifications are defined by work role and proficiency level. Education, training, personnel certifications, or experience may provide foundational qualification options, while resident qualification and continuous professional development can also apply. Components may impose additional requirements.

Role finder

What kind of work interests you?

DCWF 441IT (Cyberspace)

Network Operations Specialist

Plans, implements, and operates network services and systems across hardware and virtual environments.

Learning focusNetwork+ conceptsrouting and switchingsubnettingnetwork monitoringnetwork security
14-day bootcamp alignment
Days 1–4: Establish foundations in Network+ concepts, routing and switching with daily retrieval practice.
Days 5–8: Apply subnetting, network monitoring through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on network security.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Network+
Study track →
Read the official work-role description ↗
DCWF 451IT (Cyberspace)

System Administrator

Installs, configures, troubleshoots, and maintains systems, software, hardware, and accounts.

Learning focusoperating systemsidentity and accesshardeningpatchingrecoverynetworking fundamentals
14-day bootcamp alignment
Days 1–4: Establish foundations in operating systems, identity and access with daily retrieval practice.
Days 5–8: Apply hardening, patching through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on networking fundamentals.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Security+
Study track →
Read the official work-role description ↗
DCWF 511Cybersecurity

Cyber Defense Analyst

Analyzes alerts, firewall data, IDS events, and network traffic to identify and mitigate threats.

Learning focusSecurity+ operationslog analysisnetwork trafficthreats and vulnerabilitiesincident triage
14-day bootcamp alignment
Days 1–4: Establish foundations in Security+ operations, log analysis with daily retrieval practice.
Days 5–8: Apply network traffic, threats and vulnerabilities through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on incident triage.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Security+
Study track →
Read the official work-role description ↗
DCWF 531Cybersecurity

Cyber Defense Incident Responder

Investigates, analyzes, and responds to cyber incidents within networks and enclaves.

Learning focusincident responseforensic collectionintrusion analysisremediationcontinuity and recovery
14-day bootcamp alignment
Days 1–4: Establish foundations in incident response, forensic collection with daily retrieval practice.
Days 5–8: Apply intrusion analysis, remediation through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on continuity and recovery.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Security+
Study track →
Read the official work-role description ↗
DCWF 212Cybersecurity

Cyber Defense Forensics Analyst

Analyzes digital evidence and security incidents to support system and network vulnerability mitigation.

Learning focusevidence integritydigital forensicsincident investigationlogsoperating systems
14-day bootcamp alignment
Days 1–4: Establish foundations in evidence integrity, digital forensics with daily retrieval practice.
Days 5–8: Apply incident investigation, logs through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on operating systems.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Security+
Study track →
Read the official work-role description ↗
DCWF 443Cyberspace Effects

Network Analyst

Analyzes network traffic and packet captures, discovers anomalies, and helps identify and mitigate network intrusions.

Learning focuspacket capture analysistraffic baseliningnetwork protocolsdetection rulesintrusion analysis
14-day bootcamp alignment
Days 1–4: Establish foundations in packet capture analysis, traffic baselining with daily retrieval practice.
Days 5–8: Apply network protocols, detection rules through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on intrusion analysis.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Network+
Study track →
Read the official work-role description ↗
DCWF 541Cybersecurity

Vulnerability Assessment Analyst

Assesses systems and networks for configuration deviations, policy gaps, vulnerabilities, and operational risk.

Learning focusvulnerability scanningsecure configurationrisk analysismitigation planningtechnical reporting
14-day bootcamp alignment
Days 1–4: Establish foundations in vulnerability scanning, secure configuration with daily retrieval practice.
Days 5–8: Apply risk analysis, mitigation planning through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on technical reporting.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Security+
Study track →
Read the official work-role description ↗
DCWF 612Cybersecurity

Security Control Assessor

Independently evaluates management, operational, and technical controls to determine whether they are effective.

Learning focussecurity controlsassessment evidencerisk management frameworkcompliancetechnical documentation
14-day bootcamp alignment
Days 1–4: Establish foundations in security controls, assessment evidence with daily retrieval practice.
Days 5–8: Apply risk management framework, compliance through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on technical documentation.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Security+
Study track →
Read the official work-role description ↗
DCWF 421IT (Cyberspace)

Database Administrator

Administers data platforms and applies availability, access-control, backup, recovery, and system-hardening practices.

Learning focusaccess managementbackup and recoverydata protectionavailabilitysystem hardening
14-day bootcamp alignment
Days 1–4: Establish foundations in access management, backup and recovery with daily retrieval practice.
Days 5–8: Apply data protection, availability through guided labs and scored PBQs.
Days 9–12: Integrate all domains, remediate weak areas, and complete timed mixed practice focused on system hardening.
Day 13: Timed readiness/mock test, detailed review, and targeted final remediation.
Day 14: Final certification test and instructor results review.
Relevant ITLearnHub trackCompTIA Security+
Study track →
Read the official work-role description ↗
How to use this in class

Build evidence beyond the certification exam.

1Choose a target role

Start with the work students want to perform, not only the certification name.

2Compare KSATs

Open the official role page and identify the knowledge, skills, abilities, and tasks that need practice.

3Document capability

Use labs, PBQs, projects, and instructor observations to build evidence of applied capability.

4Verify qualification

Check the current matrix and the student’s Component requirements before making a qualification claim.