Oluma makes cybersecurity more accessible for everyone. We connect aspiring professionals and everyday people with trusted resources, learning opportunities, career pathways, and digital safety guidance, helping bridge the gap between the industry and underserved communities..
Community Driven• Digital Safety• Aspiring Professionals
Learn the foundations, protect your self and family, study for a career, practice for the exam, find the job, and land the role every tool below is open, free, and built for people like you.
Well organized resources.
Free practice exams for 40+ certs, scored the moment you answer.
Gamified challenges with XP, ranks, and hands-on practice.
Fresh cybersecurity roles and internships, updated every day.
Plain-English guides to NIST, ISO 27001, CIS Controls and more.
Internships, scholarships and conferences, gathered in one feed.
Build a security resume that gets past the filters and gets read.
Explore every role in the field and what it really does day to day.
Two quick self-checks. Whether you're just cyber-curious or already deep in study, get a personalized read in under two minutes, no signup, no email.
Four quick either-or questions, two at a time. You'll get an honest read on whether the field fits how you're wired — no signup, no email.
Questions 1–2 of 4
Questions 3–4 of 4
🟢 Green light — you're wired for this
The traits cyber actually hires for — curiosity, grit, a love of learning, and initiative — are the hard part to teach, and you already have them. Tools, certifications and technical skills are all learnable from here. Don't wait for permission: pick a foundational track and start this week. Oluma's learning is free, forever. Your move.
🟡 Strong potential — a couple of gaps to close
You've got real raw material. One or two of the traits that keep people in cyber for the long haul are still developing — completely normal, and fully buildable. Start small with a low-stakes intro course, notice which parts light you up versus wear you down, and steer hard toward the ones that light you up. Try a free foundational module and watch how it feels.
🔵 Worth exploring — go in with open eyes
Cyber is wide open to career-changers — there's no gatekeeping here. Just know the day-to-day leans hard on self-directed learning and stubborn problem-solving. Before you commit real time or money, try one free intro module. If it pulls you in more than it tires you out, that's your green light. Start with something small and free — no commitment.
Already studying cyber? Answer six quick either-or questions, two at a time, and get a starting direction based on how you actually think.
Questions 1–2 of 6
Questions 3–4 of 6
Questions 5–6 of 6
Offensive Security
You like getting deep in the tech and thinking like an adversary. You'd rather find the hole than patch it.
Roles: Penetration tester · Red teamer · Bug-bounty hunter · Exploit developer
Start here: Networking + Linux + a scripting language (Python), then hands-on web-app hacking.
Cert path: Security+ → PenTest+ / eJPT → OSCP
Security Engineering & Architecture
Technical to the core, but you'd rather build and defend than break. You like making things secure by design.
Roles: Security engineer · Cloud security · Application security · DevSecOps
Start here: Cloud (AWS/Azure), automation, and secure-coding fundamentals.
Cert path: Security+ → cloud security (AWS/Azure) → CySA+
Threat Intel & Investigations
You love the hunt and the story behind an attack — but you lead with analysis and clear communication over deep coding.
Roles: SOC analyst · Threat hunter · Threat-intel analyst · Incident responder
Start here: Log analysis, the MITRE ATT&CK framework, and sharp report-writing.
Cert path: Security+ → CySA+ → GCIH / GCFA later
Governance, Risk & Compliance
You connect security to the business — people, policy, and risk. You're the translator between the tech team and everyone else.
Roles: GRC analyst · Risk analyst · IT auditor · Security-awareness / program lead
Start here: Frameworks (NIST CSF, ISO 27001), risk assessment, and audit basics.
Cert path: Security+ → CC / CISA → CRISC later
Real careers blend these — this is a compass, not a cage. Wherever you landed, Oluma has a free path to get you moving.
Real-world security scenarios, one decision at a time. Answer, see why it matters, and keep going as long as you like.
Attackers exploit authority, urgency, secrecy, and hierarchy. A fraudulent request can look legitimate when it appears to come from a senior executive.
Never rely solely on the identity or communication channel used for a high-risk request. Verify financial requests through an independent trusted channel.
The attacker repeatedly triggered authentication requests until the victim became fatigued and approved one.
MFA dramatically reduces account compromise, but users should never approve unexpected authentication requests.
The QR code may have redirected the victim to a fraudulent payment website designed to steal financial information.
QR codes can hide malicious destinations. Always inspect the destination before entering credentials or payment information.
The fake login page is designed to capture authentication information.
A login page can look perfect and still be fraudulent. Inspect the actual domain and use trusted bookmarks where possible.
The filename makes the file appear to be a PDF even though the actual file type is a Windows shortcut.
Never trust a file based only on its displayed name. File extensions and actual file types should be verified.
Attackers can compromise a legitimate mailbox and silently join existing conversations, making fraudulent requests appear legitimate.
Never verify a sensitive payment change solely through the same email conversation where the request originated.
The attacker is abusing developer trust in third-party software dependencies.
Third-party packages are part of your attack surface. Verify package names, publishers, versions, and sources.
The application appears to trust an object identifier without verifying whether the requesting user is authorized to access that object.
Authorization must be enforced server-side for every sensitive object request.
Server-side request forgery can sometimes reach cloud metadata services that provide temporary credentials or other sensitive information.
Cloud applications must carefully control outbound requests and access to metadata services.
The attackers combined encryption with data theft and threatened public disclosure.
Backups can restore availability, but they cannot undo data exfiltration.
An attacker can create a wireless network designed to imitate a legitimate network and trick nearby devices into connecting.
Don't automatically trust familiar Wi-Fi names. Verify the network and avoid sensitive activity on untrusted networks.
The attacker is exploiting physical trust to bypass an access-control point.
Physical security is cybersecurity. Don't allow unauthorized people to follow you into restricted areas.
Attackers can abuse legitimate administrative tools already installed on a system rather than deploying obvious malware.
Security teams must monitor behavior and command activity, not simply search for known malicious files.
Automated scanners continuously search public repositories for exposed credentials and secrets.
Secrets should never be embedded in source code. Use secret-management systems and rotate exposed credentials immediately.
The API appears to identify the requested record but fails to verify that the requesting user is authorized to access it.
Every API request for a sensitive object must be authorized against the requesting user's permissions.
Manipulated information entering an AI system's training or retrieval pipeline can influence the system's future behavior.
AI systems require data provenance, validation, monitoring, and controls around what information can influence the model.
You worked through all 16 scenarios. Threats keep evolving — run the set again to sharpen your instincts, or head into the Cert Zone to go deeper.
Making cybersecurity resource:knowledge, skills, and opportunities accessible to everyone, so we can build a safer digital world together.
20+ Framework guides 40+ Certification tracks Daily Job updates Verified Sources