A structured, self-directed learning roadmap built on CompTIA certifications, mapped to Los Angeles City College (LACC) coursework and TryHackMe labs.
This roadmap is designed for a working professional transitioning into IT Cybersecurity. It integrates:
- CompTIA certification track — A+ → Network+ → Security+ → CySA+ → PenTest+
- LACC course equivalents — mapped for academic credit alignment
- TryHackMe labs — hands-on practice tied to each topic
- Python fundamentals — as the scripting backbone for all phases
Total estimated study time: 440–650+ hours across all four phases.
| Phase | Certification | Focus | Est. Hours | LACC Courses |
|---|---|---|---|---|
| 1 | Python + CompTIA A+ | Programming & Hardware | 80–120 | CS101, CS119, CIS212/213 |
| 2 | CompTIA Network+ | Networking & Infrastructure | 60–100 | CIS210, CIS214 |
| 3 Core | CompTIA Security+ | Core Security | 80–120 | CIS211 |
| 3 Analyst | CompTIA CySA+ | Advanced Analysis | 120–160 | CIS166, CIS211 |
| 4 | CompTIA PenTest+ | Offensive / Ethical Hacking | 100–150 | CIS170 |
| # | Course | Topic | Time | TryHackMe Lab | LACC Course |
|---|---|---|---|---|---|
| 1 | Novice to Pythonista | Programming Fundamentals | 15–20 hrs | Python Basics room | CS119 |
| 2 | (VIDEO) Using Python's Finally Block | Error Handling | 1–2 hrs | Python Basics room | CS119 |
| 3 | (VIDEO) Python's Built-in Queue | Data Structure | 1–2 hrs | Python Basics room | CS119 |
| 4 | (COURSE) Python: Automation Testing | Automation / Testing | 5–8 hrs | Python for Pentesters room | CS119 |
| 5 | (COURSE) Python Unit Testing | Unit Testing / Bug Finding | 4–6 hrs | Python for Pentesters room | CS119 |
| 6 | (JOURNEY) Pythonista to Python Master | Deep Dive | 20–30 hrs | Python for Pentesters room | CS119 |
| 7 | (VIDEO) Python's Role in Config Management | System Admin | 2–3 hrs | Linux Fundamentals room | CIS112 |
Priority note: Start with Novice to Pythonista. Python underpins automation, scripting, and security tooling across all phases. Skip Migrating from Python 2 to 3 — Python 2 is EOL.
| # | Course | Topic | Time | TryHackMe Lab | LACC Course |
|---|---|---|---|---|---|
| 1 | CPU Architecture | Hardware Fundamentals | 15–30 min | How Computers Work room | CIS212 |
| 2 | Digitizers & Touchscreens | Input/Output | 10–20 min | How Computers Work room | CIS212 |
| 3 | Wireless Adapters / Wi-Fi Antennas | Compared to Maintenance Work | 20–30 min | Networking Fundamentals room | CIS212 |
| 4 | Internet Appliances | Router / Gateway | 15–20 min | Networking Fundamentals room | CIS212 |
| 5 | Subnetting | Network IT — Very Important | 45–60 min | Subnetting room | CIS213 |
| 6 | Wi-Fi Analyzers | Signal Analysis Software | 15–20 min | Networking Fundamentals room | CIS213 |
| 7 | Firewalls | Cybersecurity Basics | 20–30 min | Firewalls room | CIS211 |
| 8 | Threats and Vulnerabilities | Understanding Hackers | 30–45 min | Intro to Offensive Security room | CIS211 |
| 9 | Containers | Modern Technologies | 20–30 min | Intro to Containerisation room | CIS213 |
| # | Course | Topic | Time | TryHackMe Lab | LACC Course |
|---|---|---|---|---|---|
| 1 | Network Types | LAN, WAN, PAN | 1–2 hrs | What is Networking? room | CIS210 |
| 2 | Ethernet Network Routers | Data Transmission / ZIP Code | 1–2 hrs | Intro to LAN room | CIS210 |
| 3 | Common Networking Functions | DNS, DHCP, IP | 1–1.5 hrs | DNS in Detail + DHCP rooms | CIS210 |
| 4 | Network Transceivers | Hardware: SFP, Fiber | 1 hr | Networking Fundamentals room | CIS214 |
| 5 | Modern Network Environments | Cloud / Virtualization | 2–3 hrs | Cloud Security room | CIS214 |
| 6 | Guest Networks | Network Segmentation | 1 hr | Intro to LAN room | CIS214 |
| 7 | Network Implementations | Real-World Systems | 3–4 hrs | Networking Fundamentals room | CIS214 |
| 8 | Network Operations | Uptime / Monitoring | 2–3 hrs | Network Services room | CIS214 |
| 9 | Troubleshooting / Solving Issues | Incident Response | 3–5 hrs | Wireshark: The Basics room | CIS214 |
Key insight: Subnetting fluency is non-negotiable. Every security role requires it. Take the full time and practice beyond the course material.
| # | Course | Topic | Time | TryHackMe Lab | LACC Course |
|---|---|---|---|---|---|
| 1 | Security Boundaries | Defense-in-Depth Concept | 1–2 hrs | Principles of Security room | CIS211 |
| 2 | Hardware Security | Server / Physical Security | 2–3 hrs | Physical Security room | CIS212 |
| 3 | Data Security | Encryption | 2–3 hrs | Encryption - Crypto 101 room | CIS211 |
| 4 | Security Controls | Controls / Policy | 2–4 hrs | Principles of Security room | CIS211 |
| 5 | Firewall Security | Network+ → Deeper Coverage | 1.5–2 hrs | Firewalls room | CIS211 |
| 6 | Network Security | Intrusion Detection | 4–6 hrs | Network Security room | CIS211 |
| 7 | Email Security | Phishing / Spam | 1–2 hrs | Phishing room | CIS211 |
| 8 | Application Security | Python + CS101 | 3–5 hrs | OWASP Top 10 room | CS101 |
| 9 | API Security | App ↔ App Communication | 2–3 hrs | OWASP API Security room | CIS211 |
| 10 | Security Coprocessors | TPM / Mainboard | 1 hr | Principles of Security room | CIS211 |
| # | Course | Topic | Time | TryHackMe Lab | LACC Course |
|---|---|---|---|---|---|
| 1 | Authentication & Authorization | Auth / Authz Fundamentals | 2–3 hrs | Active Directory Basics room | CIS211 |
| 2 | Threat Monitoring | Log Monitoring / Dashboard | 4–6 hrs | Intro to SIEM room | CIS211 |
| 3 | Malware | Analysis / Defense | 3–5 hrs | Malware Analysis room | CIS211 |
| 4 | Cryptography | Data Encryption | 3–4 hrs | Encryption - Crypto 101 room | CIS211 |
| 5 | Cloud Computing & Cyber | Azure / AWS | 3–5 hrs | Cloud Security room | CIS214 |
| 6 | Managing Risk | Risk Assessment | 2–4 hrs | Governance & Regulation room | CIS211 |
| 7 | Data Privacy | GDPR / Regulations | 2–3 hrs | Governance & Regulation room | CIS211 |
| 8 | Digital Forensics | Evidence Collection / Troubleshoot | 5–8 hrs | Digital Forensics room | CIS166 |
| 9 | (Lab) Cybersecurity Analyst | Hands-On Practice | 10+ hrs | SOC Level 1 Path (full) | CIS166 |
| # | Course | Topic | Time | TryHackMe Lab | LACC Course |
|---|---|---|---|---|---|
| 1 | Information Gathering | Gathering Target Information | 2–3 hrs | Passive Reconnaissance room | CIS170 |
| 2 | Passive Reconnaissance | Non-Intrusive Intelligence Gathering | 1.5–2 hrs | Passive Reconnaissance room | CIS170 |
| 3 | Active Reconnaissance | Direct System Scanning | 3–4 hrs | Active Reconnaissance room | CIS170 |
| 4 | Vulnerability Identification | Finding Vulnerabilities | 4–6 hrs | Vulnerability Research room | CIS170 |
| 5 | Wireless Attacks | Wi-Fi / Bluetooth | 2–3 hrs | Wifi Hacking 101 room | CIS170 |
| 6 | Penetration Testing | Real Exploitation | 5–8 hrs | Metasploit room | CIS170 |
| 7 | Cleanup & Restoration | Covering Tracks | 1–2 hrs | Post-Exploitation Basics room | CIS170 |
| 8 | Reporting & Remediation | Report / Remediation | 3–4 hrs | Pentest+ Reporting room | CIS166 |
| 9 | Reporting & Communication | Team Communication | 1.5–2 hrs | Pentest+ Reporting room | CIS170 |
| 10 | The CompTIA PenTest+ Exam | Exam Preparation | 1 hr | Jr Penetration Tester Path | CIS170 |
Professional note: Cleanup & Restoration is the most overlooked topic. Remediation is the end goal — not exploitation. Reporting skills separate junior testers from senior security engineers.
- A+ before Network+ — Hardware context makes networking concepts concrete, not abstract.
- Python runs through all phases — Automation, scripting, and tool-building depend on it.
- Security+ before CySA+ — CySA+ is defensive analysis; Security+ is the prerequisite mental model.
- PenTest+ last — Offensive work requires deep defensive understanding first. Skipping ahead creates structural gaps.
Most cybersecurity students come from pure software backgrounds and lack intuition for physical security, hardware architecture, and hands-on diagnostics. Industrial maintenance experience maps directly to:
- A+ hardware topics — already familiar territory
- CySA+ threat monitoring — reading system diagnostics is the same discipline as reading machine diagnostics
- PenTest+ reconnaissance — systematic observation before action mirrors equipment fault diagnosis
The A+ → Network+ → Security+ → CySA+ → PenTest+ progression is a coherent dependency chain. Structural gaps from skipping phases surface at the worst possible time — in a job interview or a live incident response.
| Resource | Purpose | Link |
|---|---|---|
| TryHackMe | Hands-on labs for every phase | tryhackme.com |
| HackTheBox | Advanced offensive practice (Phase 4+) | hackthebox.com |
| CompTIA | Official certification portal | comptia.org |
| LACC | Academic course enrollment | lacitycollege.edu |
| Professor Messer | Free CompTIA study materials | professormesser.com |
cybersecurity-roadmap/
├── README.md ← This file (full roadmap)
├── phase1-fundamentals/
│ ├── python-notes.md
│ └── comptia-a-plus.md
├── phase2-networking/
│ └── network-plus.md
├── phase3-security/
│ ├── security-plus.md
│ └── cysa-plus.md
├── phase4-offensive/
│ └── pentest-plus.md
└── labs/
└── tryhackme-progress.md
2026 Q1-Q2 → CompTIA A+ (Core 1 & Core 2)
2026 Q3 → CompTIA Network+
2026 Q4 → CompTIA Security+
2027 Q1-Q2 → CompTIA CySA+
2027 Q3-Q4 → CompTIA PenTest+
Built for a working professional. Structured for execution, not inspiration.