Skip to content

📊 Enrichment Tracker

Last updated: 22 June 2026 Progress: 🎉 124 / 124 certs enriched (100% — PROGRAM COMPLETE; az-305 upgraded from Phase-A-only to full Phase B 250 on 2026-06-22) Phase C progress: 126 / 126 certs through Phase C — COMPLETE (az-305 was the last remaining; shipped 2026-06-22) Total questions: 33,927 (target: ~31,000)

This page is the single source of truth for enrichment progress. The starter prompt reads this to know what's done and what's next. Update this page after every enrichment session.


🔧 Phase A template-artefact cleanup — DONE (12 May 2026)

The original enrich_engine.py injected deterministic template boilerplate into every cert it ran on (option-text suffixes, whyWrong fillers, scenario answer-revealing sentences, phantom-name prefixes, items "essential step" suffix, etc). The engine was patched in two stages and the affected certs were swept clean across 5 batches:

  • Engine fixes9ee6eb0 (option/whyWrong padding + DB-cert bias) and 4846a1a (residual scenario actor injection, "common mistake" explanation prefix, items suffix; refactor for testability + permanent test_engine_clean.py guardrail).
  • Cleanup sweepbc1a2b3 (one-off dy0-001), 7917d53 (batch 1: 3 certs / 1053 artefacts), 5f99866 (batch 2: 10 certs / 9437 artefacts), 90c973e (batch 3: 10 certs / 6993 artefacts), 85ca00b (batch 4: 2 certs / 1178 artefacts), c16777d (batch 5: 20 certs / 663 residuals + new banned-phrase guardrail).
  • Total: ~19,324 template artefacts removed across 25 affected certs (including dy0-001 residual round in batch 5).
  • Permanent guardrails: test_engine_clean.py (synthetic enrichment must produce zero artefacts) + test-banned-phrases.cjs (scans all src/data/questions/*-domain-*.json for the 13 artefact phrase openings; exit 1 on regression).
  • Deferred (SME risk): Mid-scenario role injection (, a {role} at) and stranded , faces a database challenge. suffix — automated regex cannot safely distinguish these from legitimate Phase B hand-written character intros. Address with hand-targeted edits per cert when an SME pass identifies them.
  • Reusable tool: guided/bulk_cleanup.py — idempotent, BOM-preserving, with built-in integrity assertions (question count, IDs, correct, option IDs, whyWrong keys all preserved; no whyWrong becomes empty). Supports --dry-run, --all, --idempotency-check.

🔬 Phase C — Thin-Q Enrichment Progress

What Phase C is: lift every existing Q above a defensible thin floor (300 chars on scenario AND explanation, plus whyWrong present for mcq/multi). Phase A only swept template-engine artefacts and Phase B only added 50 brand-new hard Qs — Phase C closes the loop on the original 200 Qs per cert. Workflow: scan_thin.pyrecalibrate_thin.py → hand-author per-cert patches JSON → patch_in_place.py (sacred-field guards). See guided/files/question-enrichment-starter.md § Phase C.

SME pass: not required for Phase C (we extend existing scenarios/explanations — no new correct answers, no new technical claims). QA gates ARE required per cert: patch_in_place.py + test-banned-phrases.cjs + npm run build + test-guided-qa.cjs (45/45). Same 3-curl SLA smoke post-deploy.

Cert Tier 1 Found Tier 1 Enriched Date Commit
az-305 183 250 2026-06-22 71e89e0 (Phase B FIRST: +50 net-new hard scenario Qs via inject_phase_b.py -> 250, commit faa67d2, with 4 HIGH + 21 MEDIUM cross-model SME fixes applied. THEN Phase C 350-floor: 183 thin = 183 scenario + 17 explanation; all 4 domains (d1:45 d2:39 d3:35 d4:64). Microsoft AZ-305 Azure Solutions Architect Expert (Expert-level design: identity/governance/monitoring, data storage, business continuity, infrastructure). Stakes-only scenario additions via 5 parallel domain agents (d4 split in two). Leak hardening = programmatic leak_check (token-overlap) + 2 cross-model gpt-5.5 SME agents (semantic): 15 token-echo + 17 semantic answer-cue leaks neutralised (incl. T/F truth-value tips, ordering/match sequence hints, a Data Box+AzCopy double-leak). Azure-native architecture cert so Defender/cross-vendor audit n/a; residual leak_check flags are generic-vocabulary FPs. guided-qa ALL CLEAR; banned-phrases 0/617; LIVE-verified thin=0 AND expl-thin=0 on production)
isc2-ccsp 62 250 2026-06-20 2ec1f4b (350-floor re-pass superseding the 2026-05-23 16-thin/300-floor pass d46af58; 62 thin = 46 scenario + 26 explanation + 1 whyWrong; all 6 domains. (ISC)2 CCSP - VENDOR-NEUTRAL cloud-security concept/framework (shared-responsibility/CSPM/CASB/KMS-BYOK/IAM-federation/CSA-CCM/SOC2/secure-SDLC); brand audit 0 across all 6 ext fragments; via 6 parallel domain agents. 15 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
sc-200 14 250 2026-06-22 f49d39d (350-floor re-pass superseding the 2026-06-02 6-thin/300-floor pass d200dac; 14 thin = 5 scenario + 8 explanation + 3 whyWrong; domains 1,2,3 (d3 carried 11). Microsoft SC-200 Security Operations Analyst (Microsoft Defender XDR Advanced Hunting + KQL tables, Defender for Endpoint/Office365/Identity/Cloud Apps, Microsoft Sentinel data connectors/analytics rules/hunting/SOAR, Security Copilot, MITRE ATT&CK); SECURITY cert - Defender/Sentinel product-match gate "qualified, 0 bare" (one bare "In Sentinel" caught + qualified to "Microsoft Sentinel" in leak-fix); via 3 parallel domain agents (WW path ran). 2 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
az-104 71 250 2026-06-19 7efa524 (350-floor re-pass superseding the 2026-06-02 2-thin/300-floor pass dc09994; 71 thin = 57 scenario + 44 explanation + 3 whyWrong; domains 2-5 carried the thin Qs. Microsoft Azure Administrator - VMs/VNets/NSGs/storage/Entra ID RBAC/Policy/Backup/Monitor vocabulary; Defender-gate audit 0 (no Defender in routine admin Qs); via 4 parallel domain agents. 19 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched; LIVE-verified thin=0 on production)
aws-saa-c03 3 250 2026-06-22 ebb1927 (350-floor re-pass superseding the 2026-06-02 2-thin/300-floor pass e24fbba; 3 thin = 3 scenario; domains 1,4. AWS Solutions Architect Associate SAA-C03 (EC2/S3 storage classes/EBS/VPC/RDS-Aurora Reserved Instances/DynamoDB/Lambda/ELB/Auto Scaling/Route 53/Well-Architected); AWS-native, cross-vendor brand audit 0 (no Azure/GCP); pre-C4 probe all-dict + 0 synth-ww -> standard pipeline (NOT string-option); via 2 parallel domain agents. 1 scenario re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
cisco-ccna 36 250 2026-06-20 62fd58e (350-floor re-pass superseding the 2026-06-02 2-thin/300-floor pass e24fbba; 36 thin = 35 scenario + 1 explanation; domains 2,3,5,6. Cisco CCNA 200-301 networking (routing OSPF/EIGRP, switching VLAN/STP/EtherChannel, ACL/NAT, wireless, automation REST/JSON); cross-vendor brand audit 0; via 4 parallel domain agents. 9 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
dp-700 6 250 2026-06-22 ecc03fa (350-floor re-pass superseding the 2026-06-02 2-thin/300-floor pass e24fbba; 6 thin = 6 scenario; domains 1,2,3. Microsoft DP-700 Fabric Data Engineer (OneLake, Lakehouse/Warehouse, Data Factory in Fabric/Dataflows Gen2, Spark notebooks V-Order/OPTIMIZE/AQE, Delta tables, Real-Time Intelligence/KQL, Direct Lake, medallion, Monitoring hub); Defender audit 0; cross-vendor audit 0 (no Databricks/Snowflake); via 3 parallel domain agents. 3 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
isc2-cissp-issmp 9 250 2026-06-22 6420668 (350-floor re-pass superseding the 2026-06-02 2-thin/300-floor pass e24fbba; 9 thin = 5 scenario + 5 explanation; domains 1,3. (ISC)2 CISSP-ISSMP Information Systems Security Management Professional (security program governance, risk management, KPIs/KRIs/board reporting, budget justification, security awareness program, BCP/DRP, program maturity assessment); VENDOR-NEUTRAL management cert - 0 product/brand names in additions (cross-vendor brand audit 0); via 2 parallel domain agents. 4 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
ai-300 12 250 2026-06-22 6402206 (350-floor re-pass superseding the 2026-06-02 3-thin/300-floor pass e24fbba; 12 thin = 12 scenario; domains 1,2,3. Microsoft AI-300 Azure MLOps Engineer Associate (Azure Machine Learning workspaces/compute/data assets/pipelines/components, AML CLI v2 + SDK v2, MLflow, managed online/batch endpoints, CI/CD Azure DevOps + GitHub Actions, Bicep IaC, model monitoring/data drift, Responsible AI dashboard); Defender audit 0; cross-vendor audit 0 (no SageMaker/Vertex); via 3 parallel domain agents (d2 re-authored in main context after its agent dropped without writing). 4 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
dp-420 59 250 2026-06-19 ac6f96f (350-floor re-pass superseding the 2026-06-02 4-thin/300-floor pass e24fbba; 59 thin = 59 scenario; domains 1 & 4 carried the thin Qs. Designing & Implementing Cloud-Native Apps Using Azure Cosmos DB - partition keys/RU-s/consistency levels/change feed/indexing policy/TTL/global distribution vocabulary; Defender audit 0; via 2 parallel domain agents. 7 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; both domains indent=2 + trailing-newline matched; LIVE-verified thin=0 on production)
gcp-cloud-engineer 28 250 2026-06-20 a4b9087 (350-floor re-pass superseding the 2026-06-02 5-thin pass e24fbba; 28 thin = 28 scenario; domains 1,2,3. Google Cloud Associate Cloud Engineer (Compute Engine, GKE, Cloud Run, App Engine, Cloud Storage, Cloud SQL/Spanner, VPC, Cloud IAM, Operations Suite, gcloud/gsutil/kubectl); GCP-native, cross-vendor brand audit 0 across all 3 ext fragments (no Azure/AWS); via 3 parallel domain agents. 9 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
gcp-data-engineer 42 250 2026-06-20 4c6f17a (350-floor re-pass superseding the 2026-06-02 7-thin pass e24fbba; 42 thin = 33 scenario + 1 explanation + 9 whyWrong; all 5 domains. Google Cloud Professional Data Engineer (BigQuery, Dataflow, Pub/Sub, Dataproc, Cloud Storage, Bigtable, Cloud SQL/Spanner, Composer/Airflow, Vertex AI, Cloud DLP); GCP-native, cross-vendor brand audit 0 across all 5 ext fragments (no Azure/AWS); via 5 parallel domain agents. 8 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
ai-103 24 250 2026-06-20 6fc6e0c (350-floor re-pass superseding the 2026-06-02 11-thin pass e24fbba; 24 thin = 24 scenario; domain 2 carried the thin Qs. Microsoft AI-103 Azure AI App & Agent Developer (Azure AI Foundry, Azure OpenAI, Azure AI Services Vision/Language/Speech/Document Intelligence/Content Safety, Azure AI Search vector/RAG, prompt flow, agents, embeddings, responsible AI); Microsoft product-match + Defender gate audit 0 (AI developer cert, no Defender); via 1 domain agent. 11 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
isc2-cissp-issap 35 250 2026-06-20 d8590af (350-floor re-pass superseding the 2026-06-02 11-thin pass e24fbba; 35 thin = 35 scenario; domains 1,2,3,4,6. (ISC)2 CISSP-ISSAP Information Systems Security Architecture - VENDOR-NEUTRAL security-architecture concept/framework (access-control architecture, security zoning/defense-in-depth, crypto/key-mgmt architecture, IAM/federation, comms/network security architecture, BCP/DRP, NIST/ISO/SABSA/TOGAF); brand audit 0 across all 5 ext fragments; via 5 parallel domain agents. 15 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
aws-mla-c01 24 250 2026-06-20 f0debba (350-floor re-pass superseding the 2026-06-02 row; 24 thin = 15 scenario + 10 explanation; domains 1,2,3. AWS Machine Learning Engineer Associate (Amazon SageMaker Processing/Feature Store/Automatic Model Tuning/Pipelines/Model Registry/Batch Transform/Model Monitor, Glue, Kinesis, S3, IAM, canary deploy, PCA, precision/recall/F1); AWS-native, cross-vendor brand audit 0 across all 3 ext fragments (no Azure/GCP/Vertex); pre-C4 probe all-dict + 0 synth-ww -> standard pipeline; via 3 parallel domain agents. 6 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
az-700 8 250 2026-06-22 25c4092 (350-floor re-pass superseding the 2026-06-02 22-thin row 4b4314a; 8 thin = 1 scenario + 6 explanation + 1 whyWrong; domains 3,5 (d5 carried 7). Microsoft AZ-700 Azure Network Engineer Associate (Application Gateway URL path routing + WAF exclusions, Azure Firewall DNAT/forced tunneling/Premium TLS inspection/secured virtual hub, NSG subnet-vs-NIC evaluation order, NSG flow logs + Traffic Analytics pipeline); Defender audit 0 (network cert - Azure Firewall/WAF are network products, not Defender); cross-vendor audit 0; hand-authored in main context (8 Qs, single cert). 0 scen-leaks (only 1 scenario addition, written answer-free). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production + enriched d5-040 scenario confirmed deployed 328->695 chars)
isaca-cdpse 40 250 2026-06-20 a0ffd43 (350-floor re-pass superseding the 2026-06-02 36-thin pass 50d0349; 40 thin = 37 scenario + 4 explanation; all 4 domains. ISACA CDPSE - VENDOR-NEUTRAL privacy-engineering concept/framework (privacy-by-design/DPIA/DSAR/consent/pseudonymization/ROPA/cross-border-SCCs); brand audit 0 across all 4 ext fragments; via 4 parallel domain agents. 10 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
isc2-cissp 61 250 2026-06-19 5f7f8a9 (350-floor re-pass superseding the 2026-06-02 37-thin/300-floor pass ad6ddcb; 61 thin = 60 scenario + 1 explanation; all 8 domains. (ISC)2 CISSP - VENDOR-NEUTRAL concept/framework (NIST/ISO 27001/risk ALE/crypto/access-control models/network security/IAM/sec-ops/secure-SDLC); brand audit 0 across all 8 ext fragments (the lone "Sentinel" hit = "Sentinel Financial" story persona, not the product); via 8 parallel domain agents. 24 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; all 8 domains indent=2 + trailing-newline matched; LIVE-verified thin=0 on production)
ab-731 47 250 2026-06-20 5ee91bc (350-floor re-pass superseding the 2026-06-02 39-thin pass ed2f912; 47 thin = 22 scenario + 29 explanation; domains 2,3. Microsoft AB-731 AI Transformation Leader - business/C-suite AI cert (Microsoft 365 Copilot, Copilot Studio, Azure AI Foundry as capability, AI adoption framework, responsible AI governance, business value/KPIs, Center of Excellence, change management; no coding); Microsoft product-match + Defender gate audit 0; via 2 parallel domain agents. 6 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
isc2-csslp 51 250 2026-06-19 4f9c58b (350-floor re-pass superseding the 2026-06-02 41-thin/300-floor v3.2 pass; 51 thin = 50 scenario + 1 whyWrong; domains 2-8 carried the thin Qs. (ISC)2 CSSLP - VENDOR-NEUTRAL secure-SDLC concept/framework (secure requirements/design threat-modeling/implementation/testing/lifecycle-mgmt/deployment-ops/supply-chain); brand audit 0 across all 7 ext fragments; via 7 parallel domain agents. 15 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; all 7 domains indent=2 + trailing-newline matched; LIVE-verified thin=0 on production)
mb-800 40 248 2026-06-20 1993941 (350-floor re-pass superseding the 2026-06-02 pass 72c2468; 40 thin = 37 scenario + 10 explanation; domains 1,2,4. Microsoft Dynamics 365 Business Central Functional Consultant (GL/dimensions/posting groups/item costing/warehouse/VAT/role centers); Microsoft product-match + Defender gate audit 0; via 3 parallel domain agents. 16 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production, cert total 248)
mb-500 18 250 2026-06-20 965db5e (350-floor re-pass superseding the 2026-06-17 SME-gate row; 18 thin = 15 scenario + 4 explanation; domains 2,3,4,5,6,7 (d4 carried 9). Microsoft MB-500 Dynamics 365 Finance & Operations Apps Developer (X++, data entities composite/standard, DIXF, Chain of Command vs pre/post-event handlers, insert_recordset, DataMemberAttribute/data contracts, SysTest, security duties/privileges, LCS/ALM); Defender gate audit 0 (ERP dev cert); cross-vendor audit 0; via 6 parallel domain agents. Fixed dump_domains.py to handle ordering Qs with correct={'orderedIds':[...]} shape (was crashing the match path). 4 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
ms-102 144 144 2026-06-17 02c8109 (topic-appropriate extensions; SME gate cleaned copy-paste boilerplate from 90+ Qs via v3 patches)
sc-900 81 250 2026-06-20 e555a6a (350-floor re-pass superseding the 2026-06-17 SME-audit pass 2ce9ecd/c77a32f; 81 thin = 28 scenario + 20 explanation + 41 whyWrong; all 4 domains. Microsoft SC-900 Security, Compliance & Identity Fundamentals (d1 concepts/Zero-Trust, d2 Microsoft Entra identity, d3 Microsoft security solutions Defender/Sentinel, d4 Microsoft Purview compliance); Microsoft product-match gate - Defender audit 0 in concepts/identity/compliance domains (d1/d2/d4, avoiding the Entra-identity Defender-boilerplate landmine), Defender legitimately used only in d3 threat-protection whyWrong; via 4 parallel domain agents. 7 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
az-400 147 152 2026-06-17 20293f9 (147 mcq/multi/tf + 5 ordering Qs whose scen/expl fell below the 300 floor; 6 short whyWrong extended. Topic-appropriate per-question authoring, NOT generic boilerplate; leak_check triaged, QA 45/45 green)
aws-dva-c02 180 200 2026-06-17 4bcedb1 (180 mcq/multi/tf + 20 ordering Qs whose scenarios were below the 300 floor; 5 short whyWrong extended. Scenario-heavy cert (median scen 243); topic-appropriate authoring, leak_check triaged, QA 45/45)
aws-soa-c02 180 194 2026-06-18 fa31159 (180 mcq/multi/tf + 14 ordering Qs whose scenarios/explanations were below the 350 floor; 2 short whyWrong replaced. Topic-appropriate per-question authoring via 6 parallel domain passes, NOT generic boilerplate; 3 ordering scenarios softened to remove step-order hints; leak_check triaged, QA 45/45 green)
comptia-220-1201 171 192 2026-06-18 1b833e2 (171 mcq/multi/tf + 21 ordering Qs below the 350 floor; 2 short whyWrong replaced. CompTIA A+ Core 1; topic-appropriate authoring via 5 parallel domain passes; 9 ordering/multi scenarios softened post-leak-triage to remove sequence/answer hints; QA 45/45 green)
comptia-220-1202 167 186 2026-06-18 7fd75f9 (167 mcq/multi/tf + 19 match/ordering Qs below the 350 floor; 1 short whyWrong replaced. CompTIA A+ Core 2; topic-appropriate authoring via 4 parallel domain passes; 8 scenarios softened post-leak-triage (match category-listing + answer-restate hints) + 4 grammar artifacts fixed; QA 45/45 green)
aws-aif-c01 170 191 2026-06-18 91f17b2 (170 mcq/multi/tf + 21 ordering Qs below the 350 floor. AWS AI Practitioner; topic-appropriate authoring via 5 parallel domain passes; 4 scenarios softened post-leak-triage (answer-set enumeration); QA 45/45 green)
isc2-cc 166 185 2026-06-18 8fb76c0 (166 mcq/multi/tf + 19 ordering Qs below the 350 floor. (ISC)2 Certified in Cybersecurity; topic-appropriate authoring via 5 parallel domain passes; 13 scenarios softened post-leak-triage for ordering sequence-narration, multi answer-category enumeration, mcq answer-restate, and one CCTV deter/evidence paraphrase; QA 45/45 green; banned-phrases clean)
comptia-sy0-701 145 162 2026-06-18 a76fbf5 (145 mcq/multi/tf + 17 match/ordering Qs below the 350 floor. CompTIA Security+, vendor-neutral; topic-appropriate authoring via 5 parallel domain passes; 137 scenario + 97 explanation extensions; 7 scenarios softened post-leak-triage (CA/CRL mechanic-restate, social-eng category enumeration, container/SaaS answer-restate, ordering step-narration, awareness-pillar enumeration, cloud-model shared-resource echo); my additions 100% vendor-neutral (0 product names in 45k added chars); QA 45/45 green; banned-phrases clean)
comptia-n10-009 146 162 2026-06-18 50ba55d (146 mcq/multi/tf + 16 match Qs below the 350 floor. CompTIA Network+, vendor-neutral; topic-appropriate authoring via 5 parallel domain passes; 133 scenario + 108 explanation extensions + 3 short whyWrong replaced; 3 scenarios softened post-leak-triage (SSH credential/traffic restate, DNS mail-flow hint, DR-metric category echo); my additions 100% vendor-neutral (0 product names in 47k added chars); QA 45/45 green; banned-phrases clean)
isc2-sscp 140 158 2026-06-18 b073a6c (140 mcq/multi/tf + 18 ordering Qs below the 350 floor; 1 short whyWrong replaced. ISC2 SSCP (7 domains), vendor-neutral; topic-appropriate authoring via 7 parallel domain passes; 140 scenario + 86 explanation extensions; 4 scenarios softened post-leak-triage (doc-hierarchy 3-answer enumeration, phishing-report restate, EDR investigation/containment restate, DNS resolver/records restate); my additions 100% vendor-neutral (0 product names in 42k added chars); QA 45/45 green; banned-phrases clean)
aws-sap-c02 104 123 2026-06-18 75460f7 (104 mcq/multi/tf + 19 ordering Qs below the 350 floor. AWS Solutions Architect Professional, AWS-specific (vendor service names expected, vendor-neutral rule N/A); topic-appropriate authoring via 4 parallel domain passes; 104 scenario + 37 explanation extensions; 6 scenarios softened post-leak-triage (2 ordering phase-order enumerations d1-051/d4-031, 2 ordering step-category echoes d1-020/d1-045, 2 answer-category namings d1-038/d4-026); leak_check triaged (residual 54 = generic-vocab FPs / stem-vocabulary / by-design explanation overlap); QA 45/45 green; banned-phrases clean. Also fixed leak_check/dump_domains/review_leaks to handle ordering string-options)
cncf-kcna 200 200 2026-06-18 78e18a1 (all 200 Qs thin — every scenario below the 350 floor. CNCF KCNA (Kubernetes & Cloud Native Associate, 4 domains); CNCF/Kubernetes subject vocabulary expected, vendor-neutral rule N/A; topic-appropriate authoring via 6 parallel domain passes (d1=88 and d2=56 split for load balance); 200 scenario + 60 explanation extensions + 1 short whyWrong replaced; 16 scenarios softened post-leak-triage (match category-enumerations for workload/networking/storage/config/RBAC-security/service-mesh + mcq/multi answer-restatements: Ingress HTTP-routing, DaemonSet option-listing, cloud-controller responsibility hints, FinOps definition echo, 4Cs layer enumeration); residual 44 leak flags = generic K8s-vocab FPs / by-design explanation overlap; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617)
aws-scs-c02 185 250 2026-06-18 a95b628 (185 thin = 109 mcq + 28 tf + 27 multi + 21 ordering, all scenarios below the 350 floor. AWS Certified Security - Specialty, AWS-specific (service names expected, vendor-neutral rule N/A); topic-appropriate authoring via 6 parallel domain passes (one per domain); 181 scenario + 67 explanation extensions + 1 short whyWrong replaced; 10 scenarios softened post-leak-triage (OU-order enumeration d4-026, ordering tier/sequence hints d2-035/d3-032, multi answer-source/component enumerations d2-033/d3-033, DNSSEC/Gateway-endpoint mechanism restates d3-011/d3-019, SCP-inheritance restate d4-030, Object-Lock mode hint d5-034, FM compliance-status hint d6-028); residual 54 leak flags = generic AWS-vocab FPs / by-design explanation overlap; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617; mixed HEAD trailing-newline + CRLF handled per file)
cncf-kcsa 199 250 2026-06-18 13dfcac (199 thin = 118 mcq + 31 tf + 31 multi + 19 ordering, all scenarios below the 350 floor. CNCF Kubernetes and Cloud Native Security Associate (6 domains); K8s-security subject vocabulary expected, vendor-neutral rule N/A; topic-appropriate authoring via 6 parallel domain passes; 199 scenario + 51 explanation extensions + 2 short whyWrong replaced; 26 scenarios softened post-leak-triage (4Cs layer-order enumeration + multi answer-category enumerations for threat-model inputs / defence-in-depth controls / Secret-security measures / kernel-isolation features / kubelet-hardening settings + mcq answer-restates for scheduler-placement / container-runtime / NodeRestriction / default-SA / hostPath-threats / dashboard-exposure + ordering sequence-reveals for network-isolation / audit-policy / threat-modelling); residual 60 leak flags = generic K8s-vocab FPs / by-design explanation overlap; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617; mixed HEAD trailing-newline handled per file)
hashicorp-terraform-associate 200 250 2026-06-18 b9a6d47 (200 thin = 133 mcq + 38 multi-select + 19 tf + 10 ordering, all scenarios below the 350 floor. HashiCorp Terraform Associate 003 (8 domains); HashiCorp/Terraform subject vocabulary expected, vendor-neutral rule N/A; topic-appropriate authoring via 8 parallel domain passes; 200 scenario + 91 explanation extensions + 8 whyWrong; 3 scenarios softened post-leak-triage (validation-mechanism 3-way enumeration d4-038, workflow-order review-placement hint d3-017, sensitive-data backend-surface echo d4-019); residual leak flags = generic Terraform-vocab FPs / by-design explanation overlap; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617)
juniper-jncia-junos 200 250 2026-06-18 7f20db3 (200 thin = 183 mcq + 15 tf + 1 multi + 1 ordering, all scenarios below the 350 floor; whyWrong-heavy — 160 mcq distractor-explanations authored. Juniper JNCIA-Junos JN0-105 (7 domains); Juniper/Junos subject vocabulary expected, vendor-neutral rule N/A; topic-appropriate authoring via 7 parallel domain passes; 200 scenario + 107 explanation + 160 whyWrong extensions; 21 definitional scenarios softened post-leak-triage (concept-restatement removed for RE-responsibilities / loopback / out-of-band-mgmt / ECMP / routing-policy / OSPF-area / BGP-community / route-filter / transit-vs-exception / GRES-vs-NSR / IPv4-statement / RIB-vs-FIB / route-scale / filter-term-order / system-login-hierarchy / BGP-convergence + 4 softens); residual leak flags = generic networking-vocab FPs / by-design explanation overlap; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617; all 7 HEAD trailing-newlines restored)
hashicorp-consul-associate 199 250 2026-06-19 e0bfaf8 (199 thin = 130 mcq + 39 multi + 20 tf + 10 ordering, all scenarios below the 350 floor. HashiCorp Consul Associate (10 domains); HashiCorp/Consul subject vocabulary expected, vendor-neutral rule N/A; topic-appropriate authoring via 10 parallel domain agents; 199 scenario + 77 explanation extensions + 0 whyWrong; 13 scenarios softened post-leak-triage (answer-category enumerations for defense-in-depth layers d6-014 / server-metrics d9-014 / snapshot-data-types d10-013 / connect-security-layers d1-006 / server-vs-client responsibilities d2-006 / client-agent functions d2-010 / helm-component characteristics d3-010 + answer-restates for security-model d6-013 / dataplane-required-component d2-015 / mesh data-plane d5-018 / gateway-purpose mapping d8-004 / mesh-gateway no-direct-path d8-012 + ordering sequence-reveal d4-018); residual 46 leak flags = generic Consul-vocab FPs / by-design explanation overlap; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617; mixed HEAD trailing-newline handled per file. Also made patch_in_place.py string-option-safe (opt_id helper) for 'a. text' option certs)
cisco-dccor 202 250 2026-06-19 08a7668 (202 thin = 122 mcq + 27 multi + 33 tf + 20 ordering, all scenarios below the 350 floor. Cisco Data Center Core DCCOR 350-601 (5 domains); Cisco DC subject vocabulary expected (Nexus/NX-OS, vPC, VXLAN/EVPN, ACI, UCS, MDS/SAN, OSPF/BGP, automation), vendor-neutral rule N/A; topic-appropriate authoring via 5 parallel domain agents; 198 scenario + 71 explanation + 5 whyWrong extensions; 18 scenarios softened post-leak-triage (answer-category enumerations for vNIC-config-elements d2-019 / Intersight-advisory-types d2-046 / enhanced-zoning-benefits d3-016 / MDT-advantages d4-018 / DCNM-NDFC-migration d4-025 + answer-restates for consistency-status d1-016 / EVPN-type2 d1-023 / ingress-replication-VTEP-load d1-024 / ACI-forwarding d1-040 / VSAN-purpose d3-019 / HTTP-409 d4-006 / SGT-propagation d5-018 / encryption-match d5-029 + ordering sequence-reveals for service-profile-build d2-021 / blade-troubleshoot d2-050 / NPV-deploy d3-027 / slow-drain d3-039 / RoCE-diagnose d4-030); residual 55 leak flags = generic Cisco-DC-vocab FPs / by-design explanation overlap; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617; mixed HEAD trailing-newline (d4 none) handled per file)
sc-300 195 200 2026-06-19 363c6f3 (195 thin = 116 mcq + 29 multi + 30 tf + 20 ordering, all scenarios below the 350 floor. Microsoft SC-300 Identity and Access Administrator (4 domains, 200-Q cert); Microsoft Entra/identity vocabulary expected, vendor-neutral rule N/A; topic-appropriate authoring via 4 parallel domain agents; 195 scenario + 58 explanation + 5 whyWrong extensions, plus 1 pre-existing 59-char whyWrong lengthened (d2-036). DEFENDER-LANDMINE CLEAR: 0 Defender in additions (verified HEAD-has-Defender=True for all 8 Defender-topic Qs in d3). 21 scenarios softened post-leak-triage (answer-category enumerations for reviewer-types d4-022 / access-review-targets d4-026 / diagnostic-destinations d4-054 / ToU-capabilities d4-013 / consent-controls d3-021 / cross-tenant-sync-caps d1-029 / CBA-MFA d2-002 / token-revocation d2-014 + ordering sequence-reveals for CA-safe-rollout d2-032 / tenant-restrictions d2-055 / CA-app-control d3-044 / KQL-retention d4-052 + 9 softer softens d1-032/d1-041/d2-029/d2-042/d2-044/d2-051/d3-010/d3-011/d4-006); residual 54 leak flags = generic identity-vocab FPs / by-design explanation overlap; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617; mixed HEAD indent (d1/d2=2, d3/d4=1) + trailing-newline handled per file)
gcp-workspace-admin 195 250 2026-06-19 2271105 (195 thin = 122 mcq + 31 multi + 25 tf + 17 ordering, all scenarios below the 350 floor. Google Workspace Administrator Professional (4 domains); Google Workspace subject vocabulary expected (Admin console, OUs, GCDS, Gmail/Drive/Vault, Context-Aware Access, MDM), vendor-neutral rule N/A; topic-appropriate authoring via 4 parallel domain agents; 195 scenario + 63 explanation + 30 whyWrong (52 option fixes, all in d1) extensions, plus 1 pre-existing 58-char whyWrong lengthened (d1-029). 18 scenarios softened post-leak-triage (answer-restates for GCDS-host d1-030 / GCDS-schedule d1-032 / GCDS-exclusion d1-034 / super-admin-count d1-016 / archive-licence-cost d2-013 / CSE-keys d4-017 / Vault-matter d4-022 / Vault-retention d4-033 + answer-category enumerations for billing-plans d1-050 / preservation-methods d2-015 / access-troubleshoot d2-049 / SPF-DKIM-DMARC d3-013 / Drive-restrictions d3-027 / Android-MDM d3-058 + ordering sequence-reveals for GCDS-deploy d1-035 / offboarding d2-010 / Vault-eDiscovery d3-048 / Context-Aware-Access d4-012); residual 56 leak flags = generic Workspace-vocab FPs / by-design explanation overlap / IR stakes-framing; QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline restored)
gcp-security-engineer 193 250 2026-06-19 b14d65e (193 thin = 117 mcq + 30 multi + 28 tf + 18 match, all scenarios below the 350 floor. Google Cloud Professional Cloud Security Engineer (5 domains); GCP-security subject vocabulary expected (Cloud IAM, Cloud KMS/CMEK, VPC Service Controls, Security Command Center, Cloud Armor, Workload Identity Federation, org policy, DLP), vendor-neutral rule N/A; topic-appropriate authoring via 5 parallel domain agents; 192 scenario + 29 explanation extensions + 0 whyWrong (existing whyWrong all >=60). LEAK-HEAVY (security cert dominated by "which THREE"/match Qs): 54 scenarios re-authored post-leak-triage to pure stakes-only via a dedicated leak-fix agent (answer-category enumerations + 1:1 option restates eliminated — e.g. IAM-Condition-attributes d1-041, colocation-facility d2-028, Shared-VPC-controls d2-034, control-type match d4-032); residual 2 leak flags = by-design explanation overlap only (0 scen-leaks). QA 45/45 green (guided-qa ALL CLEAR); banned-phrases clean 0/617; all 5 domains indent=1 + no-trailing-newline matched per file)
comptia-fc0-u71 194 200 2026-06-19 979d4b1 (194 thin = 118 mcq + 29 multi + 30 tf + 17 match, all scenarios below the 350 floor. CompTIA Tech+ FC0-U71 (6 domains: IT Concepts, Infrastructure, Applications/Software, Software Development, Data/Databases, Security). VENDOR-NEUTRAL — 0 vendor/product brand names in additions (regex-audited across all 6 ext fragments AND across all 42 leak-fix additions); topic-appropriate authoring via 6 parallel domain agents; 190 scenario + 64 explanation extensions + 0 whyWrong. 42 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 6 leak flags = by-design explanation overlap only (0 scen-leaks). QA 45/45 green; banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file)
hashicorp-vault-associate 188 250 2026-06-19 b80d32b (188 thin = 126 mcq + 36 multi + 16 tf + 10 ordering, all scenarios below the 350 floor. HashiCorp Vault Associate (9 domains: Auth Methods, Policies, Tokens, Leases, Secrets Engines, Encryption-as-a-Service, Architecture Fundamentals, Deployment Architecture, Access Management); HashiCorp/Vault subject vocabulary expected, vendor-neutral rule N/A; topic-appropriate authoring via 9 parallel domain agents; 188 scenario + 26 explanation extensions + 0 whyWrong. 39 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 1 leak flag = by-design explanation overlap (0 scen-leaks). PRE-EXISTING MALFORMED-Q CLASS: 10 string-option mcq Qs (d1-025/d2-017/d3-024/d4-015/d5-029/d6-011/d7-011/d8-012/d8-022/d9-012) carry synthetic common1/2/3 whyWrong keys that do not map to option ids, tripping patch_in_place's whyWrong validator; handled by splitting them out and applying scenario/explanation directly (new files/apply_scen_expl_direct.py) without touching options/whyWrong. QA 45/45 green; banned-phrases clean 0/617; all 9 domains indent=2 + trailing-newline matched per file)
gcp-network-engineer 185 250 2026-06-19 56dec7b (185 thin = 112 mcq + 28 multi-select + 25 tf + 20 ordering, all scenarios below the 350 floor. Google Cloud Professional Cloud Network Engineer (5 domains: Design/Plan/Prototype, Implement VPC, Managed Network Services, Hybrid/Multi-Cloud Interconnect, Manage/Monitor/Optimize); GCP-networking subject vocabulary expected (VPC, subnets, firewall, Cloud Load Balancing, Cloud NAT/VPN/Interconnect, Cloud Router/BGP, Cloud DNS, Network Connectivity Center, VPC Flow Logs), vendor-neutral rule N/A; topic-appropriate authoring via 5 parallel domain agents; 185 scenario + 35 explanation extensions + 0 whyWrong. 41 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 4 leak flags = by-design explanation overlap only (0 scen-leaks). Note: transient Windows file-lock (dev-server watcher) during patch_in_place apply on d4 — reset to HEAD + retried clean. QA 45/45 green; banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file)
cncf-cks 196 250 2026-06-19 a5c0164 (196 thin = 169 mcq + 27 multi, all scenarios below the 350 floor. Certified Kubernetes Security Specialist / CKS (6 domains: Cluster Setup, Cluster Hardening, System Hardening, Minimize Microservice Vulnerabilities, Supply Chain Security, Monitoring/Logging/Runtime Security); K8s-security subject vocabulary expected (Pod Security Standards, NetworkPolicy, RBAC, seccomp/AppArmor, OPA Gatekeeper/Kyverno, Falco, Trivy, cosign/SBOM, kube-bench/CIS, secrets encryption at rest, gVisor/Kata), vendor-neutral rule N/A; topic-appropriate authoring via 6 parallel domain agents; 184 scenario + 67 explanation + 17 whyWrong extensions. 66 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file)
gcp-cloud-digital-leader 186 200 2026-06-19 48ab4d0 (186 thin = 107 mcq + 28 tf + 28 multi + 12 ordering + 11 match, all scenarios below the 350 floor. Google Cloud Digital Leader (6 domains: business/concepts exam — digital transformation, GCP product categories, infra/app modernization, data/ML value, security & operations); GCP business-value vocabulary expected (Compute Engine/GKE/Cloud Run, BigQuery, Vertex AI/Gemini, committed/sustained-use discounts, IAM resource hierarchy, shared responsibility), vendor-neutral rule N/A; topic-appropriate authoring via 6 parallel domain agents; 183 scenario + 40 explanation + 0 whyWrong extensions. 47 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 6 domains indent=1 + no-trailing-newline matched per file)
comptia-da0-002 187 200 2026-06-19 c3a838e (187 thin = 107 mcq + 31 multi-select + 29 tf + 20 ordering, all scenarios below the 350 floor. CompTIA Data+ DA0-002 (5 domains: Data Concepts/Environments, Data Acquisition/Preparation, Data Analysis, Visualization, Data Governance/Quality/Security). VENDOR-NEUTRAL — 0 vendor/product brand names in additions (case-sensitive word-boundary regex-audited across all 5 ext fragments AND all 48 leak-fix additions; 1 explanation "(like AWS, Azure, or Google Cloud)" neutralized to generic "(such as a major public cloud platform)"); topic-appropriate authoring via 5 parallel domain agents; ~181 scenario + ~65 explanation extensions + 0 whyWrong. 48 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 5 domains indent + trailing-newline matched per file)
comptia-sk0-005 183 250 2026-06-19 b8cfbee (183 thin = 107 mcq + 28 multi-select + 27 tf + 11 ordering + 10 match, all scenarios below the 350 floor. CompTIA Server+ SK0-005 (4 domains: Server Hardware/Install/Management, Server Administration, Security/Disaster Recovery, Troubleshooting). VENDOR-NEUTRAL — 0 vendor/product brand names in additions (case-sensitive word-boundary regex-audited across all 4 ext fragments AND all 50 leak-fix additions; lowercase "windows"/"entra" matches were substring FPs = maintenance-windows / central, verified clean); topic-appropriate authoring via 4 parallel domain agents; 180 scenario + 52 explanation + 2 whyWrong extensions. 50 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 4 domains indent + trailing-newline matched per file)
cisco-scor 182 250 2026-06-19 e3aaa48 (182 thin = 109 mcq + 30 tf + 28 multi + 15 ordering, all scenarios below the 350 floor. Cisco SCOR 350-701 Implementing and Operating Cisco Security Core Technologies (6 domains: Security Concepts, Network Security, Securing the Cloud, Content Security, Endpoint Protection/Detection, Secure Network Access/Visibility/Enforcement); Cisco security subject vocabulary expected (NGFW/FTD, ISE, TrustSec/SGT/SGACL, Stealthwatch/Secure Network Analytics, AMP/Secure Endpoint, Umbrella, IPsec/IKEv2, 802.1X, NetFlow), vendor-neutral rule N/A; topic-appropriate authoring via 6 parallel domain agents; 177 scenario + 41 explanation + 4 whyWrong extensions. 36 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 4 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file)
comptia-cy0-001 179 250 2026-06-19 6fb82cd (179 thin = 100 mcq + 30 multi-select + 29 tf + 20 ordering, all scenarios below the 350 floor. CompTIA CySA+ CY0-001 / Cybersecurity Analyst (4 domains: Security Operations incl. AI/ML & prompt-engineering for security, Vulnerability Management, Incident Response & Management, Reporting & Communication). VENDOR-NEUTRAL — 0 vendor/product brand names in additions (case-sensitive word-boundary regex-audited across all 4 ext fragments AND all 33 leak-fix additions; the 56 diff Sentinel hits were the pre-existing "Sentinel Analytics" story-persona company name, not the Microsoft Sentinel product — verified clean); topic-appropriate authoring via 4 parallel domain agents; 179 scenario + 43 explanation + 1 whyWrong extensions. 33 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 3 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file)
cncf-ckad 184 250 2026-06-19 e23a56f (184 thin = 124 mcq + 31 multi + 29 ordering, all scenarios below the 350 floor. CNCF Certified Kubernetes Application Developer / CKAD (5 domains: Application Design & Build, Deployment, Observability & Maintenance, Environment/Configuration/Security, Services & Networking); Kubernetes app-developer subject vocabulary expected (Pods/Deployments/Jobs/CronJobs, Services/Ingress/NetworkPolicy, ConfigMaps/Secrets, probes, resource requests/limits, labels/selectors, kubectl, manifests/Helm/Kustomize), vendor-neutral rule N/A; topic-appropriate authoring via 5 parallel domain agents; 176 scenario + 94 explanation + 1 whyWrong extensions. 56 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 8 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file)
fortinet-nse4 177 250 2026-06-19 e56b325 (177 thin = 160 mcq + 17 multi-select, all scenarios below the 350 floor. Fortinet NSE4 FortiGate Security (5 domains: System Configuration & Administration, Firewall Policies & NAT, Security Profiles/UTM, VPN/IPsec/SSL-VPN, Routing/SD-WAN/HA); FortiGate/FortiOS subject vocabulary expected (config system/firewall policy, security profiles, FortiGuard, VDOM, SD-WAN, IPsec/SSL-VPN, FSSO, web filtering, application control), vendor-neutral rule N/A; topic-appropriate authoring via 5 parallel domain agents; 177 scenario + 58 explanation + 29 whyWrong extensions. 66 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 11 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file)
aws-das-c01 177 250 2026-06-19 58ba81d (177 thin = 104 mcq + 28 tf + 25 multi + 20 ordering, all scenarios below the 350 floor. AWS Certified Data Analytics - Specialty / DAS-C01 (5 domains: Collection, Storage & Data Management, Processing, Analysis & Visualization, Security); AWS data-analytics subject vocabulary expected (Kinesis Data Streams/Firehose, Glue, Redshift/Spectrum, EMR, Athena, QuickSight, Lake Formation, OpenSearch, MSK, Parquet/ORC partitioning), vendor-neutral rule N/A; topic-appropriate authoring via 5 parallel domain agents; 175 scenario + 40 explanation + 0 whyWrong extensions. 46 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 10 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file)
aws-pas-c01 177 250 2026-06-19 d3c3991 (177 thin = 100 mcq + 29 multi + 28 tf + 20 ordering, all scenarios below the 350 floor. AWS Certified: SAP on AWS - Specialty / PAS-C01 (4 domains: Design, Implementation, Migration, Operation & Maintenance of SAP workloads on AWS); AWS-SAP subject vocabulary expected (SAP HANA/NetWeaver/S4HANA on EC2, Backint backups to S3, Launch Wizard for SAP, pacemaker/overlay-IP HA, AWS Data Provider for SAP, CloudWatch agent), vendor-neutral rule N/A; topic-appropriate authoring via 4 parallel domain agents; 176 scenario + 31 explanation + 0 whyWrong extensions. 76 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 2 leak flags = by-design explanation overlap only (0 scen-leaks). NOTE: aws-pas-c01 + aws-das-c01 were flagged string-option certs but had 0 malformed whyWrong-key Qs (no synthetic common1/2/3 keys), so standard patch_in_place applied cleanly - no apply_scen_expl_direct fallback needed. guided-qa ALL CLEAR; banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file)
fortinet-nse5-fmg 179 250 2026-06-19 7f23915 (179 thin = 179 mcq, all scenarios below the 350 floor. Fortinet NSE 5 - FortiManager (5 domains covering ADOMs, device registration/management, policy packages, global vs ADOM databases, provisioning/CLI templates & scripts, config revisions, workspace/workflow mode, FortiGuard distribution, SD-WAN central management); FortiManager subject vocabulary expected, vendor-neutral rule N/A; topic-appropriate authoring via 5 parallel domain agents; 175 scenario + 77 explanation + 2 whyWrong extensions. 46 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 6 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file)
cisco-clcor 175 250 2026-06-19 1435c97 (175 thin = 105 mcq + 27 tf + 26 multi + 17 ordering, all scenarios below the 350 floor. Cisco CLCOR 350-801 Implementing Cisco Collaboration Core Technologies (6 domains: Infrastructure & Design, Protocols/Codecs/Endpoints, IOS XE Gateways & Media Resources, Call Control, QoS, Collaboration Applications); Cisco collaboration subject vocabulary expected (CUCM dial plans/route patterns/partitions/CSS, SIP/H.323/MGCP, CUBE/SBC, MTP/transcoder/conference bridge, Unity Connection, IM&Presence, Expressway/MRA, DSCP QoS), vendor-neutral rule N/A; topic-appropriate authoring via 6 parallel domain agents; 173 scenario + 59 explanation + 4 whyWrong extensions. 69 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 10 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file)
ms-700 174 250 2026-06-19 4dd694f (174 thin = 106 mcq + 27 multi + 23 tf + 10 ordering + 8 match, all scenarios below the 350 floor. Microsoft Teams Administrator Associate / MS-700 (4 domains: plan & configure Teams environment; manage chat/teams/channels & app policies; manage meetings, calling & Teams Phone; monitor/troubleshoot & manage lifecycle); Microsoft Teams admin vocabulary expected (Teams admin center, Teams PowerShell, meeting/messaging/calling/live-events/app-setup policies, Teams Rooms, Teams Phone/direct routing/calling plans/dial plans/emergency calling, guest vs external access, sensitivity labels & DLP, CQD/Network Planner) - Microsoft product names OK, NOT vendor-neutral. Defender-boilerplate landmine audited across all 4 ext fragments: 0 mismatched product injections (Entra/SharePoint/Exchange refs all contextually correct Teams-admin usage). Topic-appropriate authoring via 4 parallel domain agents; 173 scenario + 62 explanation + 0 whyWrong extensions. 45 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 8 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
gcp-ml-engineer 168 250 2026-06-19 e302319 (168 thin = 94 mcq + 30 multi + 28 tf + 16 ordering, all scenarios below the 350 floor. Google Cloud Professional Machine Learning Engineer (7 domains: ML problem framing/low-code ML, data & model collaboration, prototype-to-model scaling, model serving & scaling, ML pipeline automation/orchestration, ML solution monitoring); GCP ML vocabulary expected (Vertex AI custom training/AutoML/Pipelines/Feature Store/Model Registry/endpoints/Workbench/Vizier/Model Monitoring/Explainable AI, BigQuery ML, TensorFlow/Keras, TPUs/GPUs, Dataflow/Dataproc), vendor-neutral rule N/A; topic-appropriate authoring via 7 parallel domain agents; 167 scenario + 49 explanation + 1 whyWrong extensions. 50 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 5 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 7 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
comptia-pt0-003 166 250 2026-06-19 19fddc5 (166 thin = 91 mcq + 30 tf + 25 multi-select + 11 match + 9 ordering, all scenarios below the 350 floor. CompTIA PenTest+ / PT0-003 (5 domains: Engagement Management, Reconnaissance & Enumeration, Vulnerability Discovery & Analysis, Attacks & Exploits, Post-exploitation & Lateral Movement / Reporting). VENDOR-NEUTRAL — 0 vendor/product brand names in additions (word-boundary regex-audited across all 5 ext fragments AND all 54 leak-fix additions; tools referenced generically e.g. "a port scanner", "a vulnerability scanner"); topic-appropriate authoring via 5 parallel domain agents; 165 scenario + 64 explanation + 0 whyWrong extensions. 54 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual 4 leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
isc2-hcispp 167 250 2026-06-19 e01fa9d (167 thin = 97 mcq + 26 multi-select + 26 tf + 18 ordering, all scenarios below the 350 floor. ISC2 HCISPP / HealthCare Information Security and Privacy Practitioner (7 domains: Healthcare Industry, Information Governance, Information Technologies in Healthcare, Privacy & Security in Healthcare, Regulatory & Legal Requirements, Risk Management & Assessment, Third-Party Risk Management); healthcare security/privacy vocabulary expected (HIPAA Privacy/Security/Breach rules, HITECH, GDPR, PHI/ePHI minimum-necessary, administrative/physical/technical safeguards, NIST/ISO frameworks, business-associate/vendor risk, breach notification) - concept-based, 0 commercial product brand names injected (audited across all 7 ext fragments); topic-appropriate authoring via 7 parallel domain agents; 165 scenario + 53 explanation + 0 whyWrong extensions. 55 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 7 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
comptia-ds0-001 176 250 2026-06-19 95244c7 (176 thin = 101 mcq + 30 tf + 27 multi + 11 match + 7 ordering, all scenarios below the 350 floor. CompTIA DataSys+ / DS0-001 (5 domains: Database Fundamentals, Database Deployment, Database Management & Maintenance, Data & Database Security, Business Continuity). VENDOR-NEUTRAL — 0 DBMS/vendor product brand names in additions (word-boundary regex-audited across all 5 ext fragments AND all 55 leak-fix additions; generic "the DBMS"/"a relational database"/"a NoSQL store" references); topic-appropriate authoring via 5 parallel domain agents; 162 scenario + 84 explanation + 0 whyWrong extensions. 55 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
cisco-encor 175 250 2026-06-19 f9d419a (175 thin = 98 mcq + 30 tf + 27 multi + 20 ordering, all scenarios below the 350 floor. Cisco ENCOR 350-401 / Implementing Cisco Enterprise Network Core Technologies (6 domains: Architecture, Virtualization, Infrastructure, Network Assurance, Security, Automation); Cisco enterprise-network vocabulary expected (OSPF/BGP/EIGRP/redistribution, STP/RSTP/MST/EtherChannel, VRF/GRE/IPsec/LISP/VXLAN, HSRP/VRRP/GLBP, WLC/AP modes/RF, SNMP/syslog/NetFlow/SPAN/IP SLA/DNA Center, ACLs/CoPP/AAA/802.1X/MACsec, Python/JSON/REST/NETCONF/RESTCONF/EEM), vendor-neutral rule N/A; topic-appropriate authoring via 6 parallel domain agents; 161 scenario + 67 explanation + 4 whyWrong extensions. 45 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
aws-mls-c01 161 250 2026-06-19 8d0f6ec (161 thin = 100 mcq + 25 multi + 19 tf + 17 ordering, all scenarios below the 350 floor. AWS Certified Machine Learning - Specialty (4 domains: Data Engineering, Exploratory Data Analysis, Modeling, ML Implementation & Operations); AWS ML/SageMaker vocabulary expected (SageMaker training/endpoints/Ground Truth/Feature Store, Glue, Kinesis, Athena), vendor-neutral rule N/A; cross-vendor audit 0 Azure/GCP/Defender injections; topic-appropriate authoring via 4 parallel domain agents; 160 scenario + 8 explanation + 1 whyWrong extensions. 43 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
eccouncil-ceh-v13 155 250 2026-06-19 b6f9205 (155 thin = 84 mcq + 28 tf + 25 multi + 18 ordering, all scenarios below the 350 floor. EC-Council Certified Ethical Hacker v13 (5 domains: recon/footprinting, scanning & enumeration, system hacking & malware, network/web/wireless attacks, cloud/IoT/cryptography); authorized ethical-hacking tool/technique vocabulary expected (Nmap, Metasploit, Wireshark, Burp Suite, Hydra, Aircrack-ng), vendor-neutral rule N/A; cross-vendor audit 0 Defender/Sentinel injections; topic-appropriate authoring via 5 parallel domain agents; 154 scenario + 23 explanation + 1 whyWrong extensions. 33 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
paloalto-netsec-professional 156 250 2026-06-19 9db8242 (156 thin = 103 mcq + 25 multi + 15 tf + 13 ordering, all scenarios below the 350 floor. Palo Alto Networks Network Security Professional (4 domains: PAN-OS NGFW config, App-ID/User-ID/Content-ID, security/NAT/decryption policies, GlobalProtect/Panorama/threat prevention); Palo Alto vocabulary expected (PAN-OS, App-ID, WildFire, GlobalProtect, Panorama), vendor-neutral rule N/A; cross-vendor audit 0 Cisco/Fortinet/Defender injections; topic-appropriate authoring via 4 parallel domain agents; 154 scenario + 19 explanation + 1 whyWrong extensions. 54 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
gcp-devops-engineer 157 250 2026-06-19 722acf7 (157 thin = 95 mcq + 23 tf + 21 multi-select + 10 ordering + 8 match, all scenarios below the 350 floor. Google Cloud Professional Cloud DevOps Engineer (5 domains: SRE/bootstrapping, CI/CD pipelines, monitoring/SLOs/error-budgets, optimizing service performance, incident response); GCP DevOps vocabulary expected (Cloud Build, GKE, Cloud Monitoring/Logging, Cloud Deploy, Artifact Registry, Terraform), vendor-neutral rule N/A; cross-vendor audit 0 AWS/Azure injections; topic-appropriate authoring via 5 parallel domain agents; 153 scenario + 30 explanation + 2 whyWrong extensions. 37 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
aws-dea-c01 172 250 2026-06-19 91dd07e (172 thin = 112 mcq + 24 tf + 24 multi + 12 ordering, all scenarios below the 350 floor. AWS Certified Data Engineer Associate (4 domains: data ingestion & transformation, data store management, data operations & support, data security & governance); AWS data vocabulary expected (Glue, Kinesis, EMR, Redshift, Athena, Lake Formation, Step Functions/MWAA), vendor-neutral rule N/A; cross-vendor audit 0 Azure/GCP injections; topic-appropriate authoring via 4 parallel domain agents; 152 scenario + 67 explanation + 1 whyWrong extensions. 55 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). NOTE: flagged string-option cert but 0 malformed whyWrong-key Qs (no synthetic common1/2/3 keys), standard patch_in_place applied cleanly. guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
juniper-jncis-ent 159 249 2026-06-19 c7a62b1 (159 thin = 159 mcq, all scenarios below the 350 floor; whyWrong-heavy — 93 mcq distractor-explanation sets authored. Juniper JNCIS-ENT (9 domains: enterprise routing OSPF/IS-IS/BGP, switching VLANs/STP/RSTP/MSTP, LACP/link aggregation, Layer 2/3, Junos routing policy & firewall filters, class of service, high availability); Junos/Juniper vocabulary expected, vendor-neutral rule N/A; cross-vendor audit 0 wrong-vendor injections (2 Cisco mentions = legitimate PVST+ interop teaching in explanations, not contamination); topic-appropriate authoring via 9 parallel domain agents; 152 scenario + 60 explanation + 93 whyWrong extensions (3 scen already >=360 skipped). 38 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 9 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
az-120 156 250 2026-06-19 34dc221 (156 thin = 121 mcq + 15 multi-select + 12 tf + 5 match + 3 ordering, all scenarios below the 350 floor. Microsoft Azure for SAP Workloads / AZ-120 (4 domains: migration planning, Azure infrastructure for SAP, SAP HANA on Azure HA/DR, monitoring & operations); Azure + SAP vocabulary expected (SAP HANA on Azure VMs, Azure NetApp Files, proximity placement groups, Azure Site Recovery, scale-up/scale-out HANA), vendor-neutral rule N/A; cross-vendor audit 0 AWS/GCP injections; topic-appropriate authoring via 4 parallel domain agents; 151 scenario + 18 explanation + 8 whyWrong extensions. 32 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
cisco-spcor 154 250 2026-06-19 1766b96 (154 thin = 86 mcq + 24 multi + 28 tf + 16 ordering, all scenarios below the 350 floor. Cisco SPCOR 350-501 / Implementing and Operating Cisco Service Provider Network Core Technologies (5 domains: architecture, core routing IS-IS/OSPF/BGP, MPLS/segment-routing & VPN services, multicast/QoS, automation/assurance); Cisco IOS XR/XE service-provider vocabulary expected (MPLS LDP/TE, SR/SRv6, L3VPN/EVPN, NETCONF/YANG, model-driven telemetry), vendor-neutral rule N/A; cross-vendor audit 0 Juniper/Arista/Nokia injections; topic-appropriate authoring via 5 parallel domain agents; 150 scenario + 55 explanation + 2 whyWrong extensions. 55 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
gcp-cloud-developer 150 250 2026-06-19 31b5928 (150 thin = 85 mcq + 22 multi + 31 tf + 12 ordering, all scenarios below the 350 floor. Google Cloud Professional Cloud Developer (thin Qs across 3 domains: building, deploying, and integrating cloud-native apps); GCP app-dev vocabulary expected (Cloud Run, GKE, App Engine, Cloud Functions, Pub/Sub, Firestore, Cloud SQL, Spanner, Cloud Build, Apigee), vendor-neutral rule N/A; cross-vendor audit 0 AWS/Azure injections; topic-appropriate authoring via 3 parallel domain agents; 150 scenario + 116 explanation + 0 whyWrong extensions. 45 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 3 edited domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
aws-dbs-c01 148 250 2026-06-19 b794bde (148 thin = 100 mcq + 16 multi-select + 21 tf + 11 ordering, all scenarios below the 350 floor. AWS Certified Database - Specialty (thin Qs across 4 domains: workload-specific DB design, deployment & migration, management & operations, monitoring/security/optimization); AWS database vocabulary expected (RDS, Aurora, DynamoDB, ElastiCache, Redshift, DocumentDB, Neptune, DMS/SCT), vendor-neutral rule N/A; cross-vendor audit 0 Azure/GCP injections; topic-appropriate authoring via 4 parallel domain agents; 148 scenario + 121 explanation + 0 whyWrong extensions (7 scen already >=360 skipped). 50 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). NOTE: 29 string-option Qs but 0 whyWrong needs -> no malformed-key risk; standard patch_in_place applied cleanly. guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 edited domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
dp-300 158 250 2026-06-19 605d0e7 (158 thin = 86 mcq + 27 tf + 26 multi + 10 match + 9 ordering, all scenarios below the 350 floor. Microsoft Azure Database Administrator Associate / DP-300 (5 domains: deploy/configure, security, HA/DR, performance monitoring & optimization, automation of tasks); Azure SQL + SQL Server vocabulary expected (Azure SQL DB/MI, failover groups, Always On AGs, Query Store, automatic tuning, TDE/Always Encrypted, Microsoft Entra auth), vendor-neutral rule N/A; cross-vendor audit 0 AWS/GCP injections AND 0 Defender-boilerplate landmine; topic-appropriate authoring via 5 parallel domain agents; 148 scenario + 33 explanation + 0 whyWrong extensions. 51 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
juniper-jncip-sec 159 250 2026-06-19 9182a52 (159 thin = 159 mcq, all scenarios below the 350 floor; whyWrong-heavy — 80 mcq distractor-explanation sets authored. Juniper JNCIP-SEC / Security Professional (8 domains: security policies & zones, NAT, IPsec VPNs, chassis-cluster HA, AppSecure, UTM, IPS/IDP, ATP & troubleshooting); Junos SRX security vocabulary expected (security zones/policies, source/destination/static NAT, site-to-site/ADVPN IPsec, redundancy groups/RETH, AppFW/AppID, ATP Cloud), vendor-neutral rule N/A; cross-vendor audit 0 Cisco/Palo Alto/Fortinet injections; topic-appropriate authoring via 8 parallel domain agents; 148 scenario + 18 explanation + 80 whyWrong extensions. 58 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent; residual leak flags = by-design explanation overlap only (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 8 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
aws-ans-c01 161 250 2026-06-19 4604ca2 (161 thin = 95 mcq + 26 tf + 24 multi + 16 ordering, all scenarios below the 350 floor. AWS Certified Advanced Networking - Specialty (4 domains: network design, connectivity/hybrid, management/operation, network security); AWS networking vocabulary expected (VPC, Transit Gateway, Direct Connect, Route 53, Network Firewall, Security Groups/NACLs, PrivateLink), vendor-neutral rule N/A; cross-vendor audit 0 Azure/GCP injections; pre-C4 probe = all-dict options + 0 synthetic-ww keys so standard pipeline (no string-option risk); topic-appropriate authoring via 4 parallel domain agents; 146 scenario + 109 explanation + 4 whyWrong extensions. 37 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
comptia-dy0-001 145 250 2026-06-19 a1032eb (145 thin = 80 mcq + 24 tf + 22 multi-select + 10 match + 9 ordering, all scenarios below the 350 floor. CompTIA DataAI (5 domains: mathematics & statistics, modeling/methods, ML operations, analysis, governance) - VENDOR-NEUTRAL: no-brand rule applied to author + leak-fix briefs; brand audit across all 5 ext fragments = 0 hits (no AWS/Azure/GCP/Databricks/Snowflake/etc.); 145 scenario + 3 explanation + 0 whyWrong extensions. NOTE: 30 string-option Qs but 0 whyWrong needs -> no malformed-key risk; standard patch_in_place applied cleanly. 46 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
isaca-cism 151 250 2026-06-19 7e1604a (151 thin = 79 mcq + 22 tf + 30 multi + 20 ordering, all scenarios below the 350 floor. ISACA Certified Information Security Manager (4 domains: information security governance, information risk management, security program development & management, incident management); management/concept-based (governance, risk appetite, board/steering-committee dynamics, business alignment - not deep technical configs); 145 scenario + 28 explanation + 0 whyWrong extensions. 60 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
isc2-cgrc 162 250 2026-06-19 b3f432c (162 thin = 92 mcq + 27 tf + 23 multi + 20 ordering, all scenarios below the 350 floor. (ISC)2 Certified in Governance, Risk and Compliance / CGRC (7 domains across the NIST RMF lifecycle: security/privacy governance, categorization, control selection/implementation/assessment, authorization/ATO, continuous monitoring); framework/process-oriented (RMF steps, authorization decisions, risk/compliance stakes); 144 scenario + 95 explanation + 0 whyWrong extensions. 44 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 7 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
paloalto-netsec-analyst 161 250 2026-06-19 0fa8b34 (161 thin = 104 mcq + 27 multi + 14 tf + 16 ordering, all scenarios below the 350 floor. Palo Alto Networks Certified Network Security Analyst (4 domains: object configuration, policy/NAT, App-ID/User-ID/Content-ID, monitoring); PAN-OS vocabulary expected (security/NAT policy, App-ID, User-ID, security profiles, Panorama, address/service objects); 144 scenario + 36 explanation + 11 whyWrong extensions (whyWrong short-not-missing -> symmetric diff). 70 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
cisco-devasc 162 250 2026-06-19 43e9cb5 (162 thin = 88 mcq + 28 tf + 28 multi + 18 ordering, all scenarios below the 350 floor. Cisco Certified DevNet Associate / DEVASC 200-901 (6 domains: software development & design, understanding/using APIs, Cisco platforms & development, application deployment & security, infrastructure & automation, network fundamentals); developer/automation vocabulary expected (REST APIs, Python, data formats, Git, CI/CD, Docker, NETCONF/RESTCONF/YANG, Webex/Meraki/DNA Center SDKs); 142 scenario + 75 explanation + 0 whyWrong extensions. 41 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (one qid needed a second pass for length; 0 scen-leaks final). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
pl-400 154 250 2026-06-19 cf608a3 (154 thin = 91 mcq + 27 tf + 19 multi + 9 match + 8 ordering, all scenarios below the 350 floor. Microsoft Power Platform Developer Associate / PL-400 (6 domains: Dataverse data modeling, app & automation UX, plug-ins/custom code, integration/custom connectors, testing & ALM, security & deployment); Power Platform developer vocabulary expected (Dataverse, plug-ins/IPlugin pipeline, custom connectors, PCF code components, Power Automate cloud flows, Power Pages, managed solutions/ALM), vendor-neutral rule N/A; pre-C4 probe = 9 string-option Qs but 0 synthetic-ww keys -> standard patch_in_place (no malformed-key risk); cross-vendor audit 0 + 0 Defender-boilerplate landmine; 141 scenario + 78 explanation + 4 whyWrong extensions via 6 parallel domain agents. 41 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 6 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
isaca-cgeit 163 250 2026-06-19 7b29dde (163 thin = 97 mcq + 26 tf + 26 multi + 14 ordering, all scenarios below the 350 floor. ISACA Certified in the Governance of Enterprise IT / CGEIT (4 domains: governance of enterprise IT, IT resources, benefits realization, risk optimization); governance concept-based vocabulary (COBIT, EGIT, portfolio/investment management, value delivery, RACI, board/executive oversight - not technical configs); no cloud-vendor product names (brand audit 0 across all 4 ext fragments); 135 scenario + 89 explanation + 0 whyWrong extensions via 4 parallel domain agents. 58 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
ai-901 154 265 2026-06-19 3ecb016 (154 thin = 123 mcq + 12 tf + 11 match + 8 multi-select, all scenarios below the 350 floor; whyWrong-heavy - 61 distractor-explanation sets authored. Microsoft Azure AI fundamentals / AI-901 (2 domains: AI workloads & responsible AI, Azure AI services & generative AI); Azure AI vocabulary expected (AI Foundry portal/SDK/playground/agent builder, AI Vision/ImageAnalysisClient, AI Language, AI Speech, Content Understanding, Azure OpenAI), vendor-neutral rule N/A; 0 Defender-boilerplate landmine; 134 scenario + 9 explanation + 61 whyWrong extensions via 2 parallel domain agents. 20 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; both domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production - 265 total Qs)
comptia-cs0-003 154 250 2026-06-19 f982c7f (154 thin = 90 mcq + 26 multi-select + 24 tf + 14 ordering, all scenarios below the 350 floor. CompTIA CySA+ / CS0-003 (4 domains: security operations, vulnerability management, incident response & management, reporting & communication) - VENDOR-NEUTRAL: favored generic security tool CATEGORIES (SIEM, EDR/XDR, IDS/IPS, SOAR, MITRE ATT&CK, CVSS, IoC/TTP); cloud-vendor brand audit across all 4 ext fragments = 0 hits (no Azure/AWS/GCP/Defender/Sentinel); 133 scenario + 88 explanation + 0 whyWrong extensions via 4 parallel domain agents. 58 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
isaca-cisa 125 250 2026-06-19 05e0c6f (125 thin = 62 mcq + 25 multi-select + 19 tf + 19 ordering, all scenarios below the 350 floor. ISACA Certified Information Systems Auditor / CISA (5 domains: IS audit process, governance & management of IT, acquisition/development/implementation, operations/maintenance & service management, protection of information assets); IS-audit concept vocabulary (risk-based audit, COBIT, controls preventive/detective/corrective, evidence/sampling, SoD, BCP/DRP); no cloud-vendor product names (brand audit 0 across all 5 ext fragments); 125 scenario + 2 explanation + 0 whyWrong extensions via 5 parallel domain agents. 49 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
cisco-cct 136 250 2026-06-19 69c4d04 (136 thin = 81 mcq + 22 tf + 20 multi-select + 13 ordering, all scenarios below the 350 floor. Cisco Certified Technician / CCT (4 domains: networking fundamentals, Cisco device hardware/identification, IOS software operation, RMA/support & troubleshooting); Cisco field-technician vocabulary expected (IOS/IOS-XE CLI, show commands, ISR/Catalyst/Nexus, FRU/RMA, console/AUX/SFP, ROMMON/boot sequence), vendor-neutral rule N/A; cross-vendor audit 0 (no Azure/AWS/GCP injections); 123 scenario + 81 explanation + 0 whyWrong extensions via 4 parallel domain agents. 31 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
comptia-pk0-005 143 250 2026-06-19 7f72827 (143 thin = 76 mcq + 27 tf + 24 multi-select + 9 match + 7 ordering, all scenarios below the 350 floor. CompTIA Project+ / PK0-005 (4 domains: project management concepts, project life cycle phases, tools/documentation/IT & governance, basics of IT/project change) - VENDOR-NEUTRAL: project-management vocabulary only (Agile/Waterfall/hybrid, PMI process groups, RACI, risk register, Gantt/critical path, change control, scope/schedule/cost/quality constraints); no cloud-vendor product names (brand audit 0 across all 4 ext fragments); pre-C4 probe = all-dict options + 0 synthetic-ww keys -> standard patch_in_place; 122 scenario + 73 explanation + 0 whyWrong extensions via 4 parallel domain agents. 32 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
isaca-crisc 147 250 2026-06-19 a79d204 (147 thin = 75 mcq + 27 multi-select + 26 tf + 19 ordering, all scenarios below the 350 floor. ISACA CRISC / Certified in Risk and Information Systems Control (4 domains: governance, IT risk assessment, risk response & reporting, information technology & security); concept/framework level (COBIT, NIST RMF/CSF, ISO 27001/27005, FAIR, risk register, KRIs/KCIs, risk appetite/tolerance, inherent vs residual risk, three lines of defense); no vendor product names (brand audit 0 across all 4 ext fragments); 122 scenario + 67 explanation + 0 whyWrong extensions via 4 parallel domain agents. 44 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
sc-100 134 250 2026-06-19 4a4abc2 (134 thin = 74 mcq + 26 tf + 19 multi + 8 match + 7 ordering, all scenarios below the 350 floor. Microsoft Cybersecurity Architect / SC-100 (4 domains: security best practices & priorities/Zero Trust, security operations/identity/compliance, infrastructure security, application & data security); Azure security vocabulary expected (Zero Trust pillars, MCRA, Microsoft Entra ID for identity, Microsoft Sentinel for SIEM/SOC, Microsoft Defender for Cloud for posture, Microsoft Purview for data), vendor-neutral rule N/A; Defender-boilerplate gate applied - audit of all 4 ext fragments = 0 bare "Microsoft Defender" injections (all 28 Defender mentions are qualified product names in EXPLANATION fields only, correctly mapped to topic: Defender for Cloud/IoT/Containers/Endpoint/Databases/EASM; 0 Defender leaking into identity content); 122 scenario + 73 explanation + 0 whyWrong extensions via 4 parallel domain agents. 38 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
cisco-devcor 146 250 2026-06-19 02f9e1c (146 thin = 73 mcq + 31 multi + 23 ordering + 19 tf, all scenarios below the 350 floor. Cisco Certified DevNet Professional / DEVCOR 350-901 (5 domains: software development & design, using APIs, Cisco platforms & development, application deployment & security, infrastructure & automation); developer vocabulary expected (REST/RESTCONF/NETCONF, YANG, OAuth2, Git, Docker, CI/CD, webhooks, rate limiting, Webex/Meraki/Catalyst Center/Intersight APIs), vendor-neutral rule N/A; cross-vendor audit 0 (no Azure/AWS/GCP injections); pre-C4 probe = all-dict options + 0 synthetic-ww keys -> standard pipeline; 120 scenario + 82 explanation + 1 whyWrong extensions via 5 parallel domain agents. 65 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
comptia-cnx-001 128 250 2026-06-19 2bce161 (128 thin = 71 mcq + 26 tf + 14 multi + 11 match + 6 ordering, all scenarios below the 350 floor. CompTIA CloudNetX / CNX-001 (4 domains: network architecture/design, modern network deployments, operations & automation, security & compliance) - VENDOR-NEUTRAL: generic networking concepts/protocols only (NTP/DNS/DHCP/DNSSEC, BGP/OSPF, VLAN/VXLAN, SDN, SD-WAN, zero trust network, segmentation, IPsec/TLS); no cloud-vendor product names (brand audit 0 across all 4 ext fragments); 118 scenario + 58 explanation + 4 whyWrong extensions via 4 parallel domain agents. 46 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
comptia-cv0-004 123 250 2026-06-19 d194a5b (123 thin = 67 mcq + 21 tf + 18 multi + 12 match + 5 ordering, all scenarios below the 350 floor. CompTIA Cloud+ / CV0-004 (6 domains: cloud architecture, deployment, operations & support, security, DevOps fundamentals, troubleshooting) - VENDOR-NEUTRAL: generic cloud concepts only (IaaS/PaaS/SaaS/FaaS, shared responsibility, autoscaling, IaC, HA/DR, containers/orchestration, FinOps); no cloud-vendor product names (brand audit 0 across all 6 ext fragments); 114 scenario + 44 explanation + 0 whyWrong extensions via 6 parallel domain agents. 43 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
aws-dop-c02 128 250 2026-06-19 6a89739 (128 thin = 67 mcq + 28 tf + 17 ordering + 16 multi, all scenarios below the 350 floor. AWS Certified DevOps Engineer Professional / DOP-C02 (6 domains: SDLC automation, configuration management & IaC, resilient cloud solutions, monitoring & logging, incident & event response, security & compliance); AWS service vocabulary expected (CodePipeline/CodeBuild/CodeDeploy, CloudFormation, CloudWatch, Systems Manager, ECS/EKS, Lambda, X-Ray, Config, EventBridge), vendor-neutral rule N/A; cross-vendor audit 0 (no non-AWS cloud-brand injections); pre-C4 probe = all-dict options + 0 synthetic-ww keys -> standard pipeline; 112 scenario + 45 explanation + 0 whyWrong extensions via 6 parallel domain agents. 35 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 6 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
md-102 150 250 2026-06-19 956e307 (150 thin = 95 mcq + 21 tf + 18 multi-select + 16 ordering, all scenarios below the 350 floor. Microsoft 365 Endpoint Administrator / MD-102 (4 domains: deploy Windows client, manage identity & compliance, manage & protect devices, manage applications); Microsoft endpoint vocabulary expected (Intune, Entra ID, Configuration Manager, Windows Autopilot, Windows Update for Business, Defender for Endpoint), vendor-neutral rule N/A; Defender-boilerplate gate applied - audit of all 4 ext fragments = 1 qualified "Defender for Endpoint" mention in an EXPLANATION (domain 4 protect-devices, correctly mapped to threat telemetry / onboarding / sensor health), 0 bare/blanket Defender injections, 0 leaking into identity/conditional-access content; 109 scenario + 104 explanation + 1 whyWrong extensions via 4 parallel domain agents. 28 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
isc2-cissp-issep 106 250 2026-06-19 9668e28 (106 thin = 53 mcq + 18 tf + 18 multi + 17 ordering, all scenarios below the 350 floor. ISC2 CISSP-ISSEP / Information Systems Security Engineering Professional (5 domains: systems-security engineering foundations, risk management, security planning & design, systems implementation/V&V, secure operations/maintenance/disposal); concept-only & vendor-neutral (NIST SP 800-160 / 800-37 RMF / 800-53 / 800-137, ISO/IEC 15288, systems-engineering lifecycle, DoD/FedRAMP/OT-ICS framing); no cloud-vendor product names (brand audit 0 across all 5 ext fragments); 105 scenario + 17 explanation + 0 whyWrong extensions via 5 parallel domain agents. 49 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
cisco-cyberops 126 250 2026-06-19 6f63957 (126 thin = 63 mcq + 24 tf + 24 multi + 15 ordering, all scenarios below the 350 floor. Cisco CyberOps Associate / 200-201 CBROPS (5 domains: security concepts, security monitoring, host-based analysis, network intrusion analysis, security policies & procedures); SOC-analyst category vocabulary expected (SIEM, IDS/IPS, EDR, NetFlow, full packet capture, NIST IR lifecycle, CVSS, Cyber Kill Chain, Diamond Model), generic tool categories favored; cross-vendor audit 0 (the only "defender" hit was the generic blue-team term "defender value", not the product); 103 scenario + 60 explanation + 2 whyWrong extensions via 5 parallel domain agents. 30 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 5 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
comptia-cas-005 124 250 2026-06-19 5591adb (124 thin = 73 mcq + 21 tf + 16 ordering + 14 multi-select, all scenarios below the 350 floor. CompTIA SecurityX / CAS-005 (4 domains: governance/risk/compliance, security architecture, security engineering, security operations) - VENDOR-NEUTRAL: generic enterprise-security concepts only (Zero Trust, PKI, IAM, SIEM/SOAR categories, threat modelling, risk frameworks, cryptographic concepts, secure architecture); no cloud-vendor product names (brand audit 0 across all 4 ext fragments); domain 3 was the heaviest at 64 thin Qs; 96 scenario + 57 explanation + 14 whyWrong extensions via 4 parallel domain agents. 37 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
comptia-xk0-005 150 250 2026-06-19 fa22cf3 (150 thin = 79 mcq + 29 multi-select + 26 tf + 12 match + 4 ordering, all scenarios below the 350 floor. CompTIA Linux+ / XK0-005 (4 domains: system management, security, scripting/containers/automation, troubleshooting); Linux administration vocabulary expected (shell commands, systemd, package managers, filesystems, permissions, SELinux/AppArmor, distros RHEL/Debian/Ubuntu/SUSE) - VENDOR-NEUTRAL on cloud (no AWS/Azure/GCP product names; Linux distros are not cloud vendors); brand audit 0 across all 4 ext fragments; 94 scenario + 106 explanation + 1 whyWrong extensions via 4 parallel domain agents. 14 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR (45/45); banned-phrases clean 0/617; all 4 domains indent + trailing-newline matched per file; LIVE-verified thin=0 on production)
sc-401 168 250 2026-06-19 3ff2d10 (168 thin, all scenarios below the 350 floor. Microsoft Information Security Administrator / SC-401 (3 domains: Microsoft Purview information protection - sensitivity labels, DLP, Insider Risk Management, Communication Compliance, eDiscovery, data lifecycle/records, encryption, classification); Microsoft Purview vocabulary expected, vendor-neutral rule N/A; Defender product-match gate applied - audit of all 3 ext fragments = 12 Defender mentions, ALL qualified product names in explanation/whyWrong fields correctly teaching the Purview-vs-Defender boundary (Defender for Cloud Apps / for Endpoint / XDR), 0 bare/blanket injections, 0 leaking into identity content; 92 scenario + 152 explanation + 5 whyWrong extensions via 3 parallel domain agents. 30 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 3 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
eccouncil-chfi-v11 91 250 2026-06-19 cb3b34f (91 thin, all scenarios below the 350 floor. EC-Council Computer Hacking Forensic Investigator v11 (6 domains: chain of custody, forensic imaging/write-blockers, file systems & carving, OS artifacts, memory/network forensics, anti-forensics, mobile/cloud/malware forensics, Locard's principle, evidence handling/reporting) - VENDOR-NEUTRAL: concept-only; generic forensic tools (FTK/EnCase/Autopsy/Volatility/Wireshark) and standards (NIST/ISO/ACPO) only; no cloud-vendor product names (case-sensitive brand audit 0 across all 6 ext fragments); 91 scenario + 6 explanation + 0 whyWrong extensions via 6 parallel domain agents. 26 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
eccouncil-cnd-v3 91 250 2026-06-19 142fcee (91 thin, all scenarios below the 350 floor. EC-Council Certified Network Defender v3 (6 domains: defense-in-depth, security controls/policies, IDS/IPS, firewalls, VPNs, segmentation/zero-trust, endpoint/app security, data protection, SIEM/log monitoring, IR, threat intel, traffic monitoring, wireless/IoT/cloud) - VENDOR-NEUTRAL/cross-vendor: generic categories (next-gen firewall, IDS/IPS, SIEM, NAC) and standards (NIST/ISO 27001/MITRE ATT&CK) only; no cloud-vendor product names (case-sensitive brand audit 0 across all 6 ext fragments); 90 scenario + 5 explanation + 0 whyWrong extensions via 6 parallel domain agents. 33 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 6 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
az-140 86 250 2026-06-19 0eccfd5 (86 thin, all scenarios below the 350 floor. Microsoft Azure Virtual Desktop Specialty / AZ-140 (domains 1 & 4 carried the thin Qs: AVD host pools, session hosts, workspaces, application groups, FSLogix, Azure Files/NetApp, MSIX App Attach, Compute Gallery, RDP Shortpath, autoscale, Conditional Access, monitoring, DR/backup); Azure AVD vocabulary expected, vendor-neutral rule N/A; Defender-boilerplate gate clean (0 Defender mentions in ext fragments); 86 scenario + 0 explanation + 0 whyWrong extensions via 2 parallel domain agents. 32 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; both domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
ab-620 98 250 2026-06-19 a835d4b (98 thin, all scenarios below the 350 floor. Microsoft Copilot Studio / AB-620 (domains 2 & 3 carried the thin Qs: topics, trigger phrases, entities/slot filling, nodes, generative answers, knowledge sources, actions/plugins, connectors, Power Automate, agents, Dataverse, publishing/channels, authentication, analytics, ALM); Copilot Studio / Power Platform vocabulary expected, vendor-neutral rule N/A; Defender-boilerplate gate clean (0 Defender mentions in ext fragments); 85 scenario + 74 explanation + 0 whyWrong extensions via 2 parallel domain agents. 46 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; both domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
cisco-ccie-ei 95 250 2026-06-19 0f54d39 (95 thin, all scenarios below the 350 floor. Cisco CCIE Enterprise Infrastructure (4 domains: L2 STP/MST/VTP/EtherChannel, L3 OSPF/EIGRP/BGP/redistribution, VRF/MPLS L3VPN/DMVPN/IPsec, SD-WAN/SD-Access/Catalyst Center, VXLAN/EVPN, QoS, multicast, NETCONF/RESTCONF/YANG); Cisco protocol/product vocabulary expected, vendor-neutral rule N/A; cross-vendor audit 0 (no non-Cisco cloud-brand injections, case-sensitive); 82 scenario + 28 explanation + 4 whyWrong extensions via 4 parallel domain agents. 62 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR; banned-phrases clean 0/617; all 4 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
cncf-cka 139 250 2026-06-19 bd84bde (139 thin = 70 scenario + 109 explanation + 5 whyWrong below the 350 floor. CNCF Certified Kubernetes Administrator (5 domains: cluster architecture/install/config, workloads & scheduling, services & networking, storage, troubleshooting); PURE UPSTREAM KUBERNETES / CLOUD-NEUTRAL - kubectl/kubelet/etcd/CNI/RBAC/PV-PVC/taints/QoS/crictl/kubeadm vocabulary; cross-vendor brand audit 0 (no Azure/AWS/GCP/AKS/EKS/GKE) across all 5 ext fragments; pre-C4 probe = all-dict options + 0 synthetic-ww keys -> standard pipeline; via 5 parallel domain agents. 29 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; all 5 domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
dp-800 61 250 2026-06-19 7c7d34d (61 thin = 60 scenario + 53 explanation below the 350 floor; domains 2 & 3 carried the thin Qs. Developing AI-Enabled Database Solutions (Microsoft Azure data+AI: Azure SQL, Cosmos DB, PostgreSQL pgvector/DiskANN, Azure AI Search vector/hybrid/semantic, Azure OpenAI embeddings, RAG/chunking, HNSW/IVF indexes); Azure vocabulary expected, vendor-neutral rule N/A; Microsoft product-match gate applied - Defender audit 0 (no Defender boilerplate in data Qs); via 2 parallel domain agents. 12 scenarios re-authored post-leak-triage to pure stakes-only via leak-fix agent (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; both domains indent=2 + trailing-newline matched per file; LIVE-verified thin=0 on production)
gcp-database-engineer 86 248 2026-06-20 2305cee (NET-NEW Phase C row - first thin-pass; 86 thin = 17 scenario + 79 explanation + 3 whyWrong; all 4 domains. Google Cloud Professional Cloud Database Engineer (Cloud SQL MySQL/PostgreSQL/SQL Server, Cloud Spanner, AlloyDB, Bigtable, Firestore, Memorystore, BigQuery, Database Migration Service, Datastream, PITR, read replicas, HA/failover, IAM/CMEK); GCP-native, cross-vendor brand audit 0 across all 4 ext fragments (no AWS/Azure); via 4 parallel domain agents. 8 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production, cert total 248)
ab-100 13 250 2026-06-20 38889aa (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 13 thin = 13 scenario; domain 1. Microsoft AB-100 Agentic AI Business Solutions Architect (expert) (Microsoft Foundry/Azure AI Foundry PaaS, Copilot Studio SaaS, IaaS GPUs+Containers build paths, M365 Copilot, generative orchestration, knowledge sources/grounding/RAG, SLM vs LLM, Cloud Adoption Framework for AI, AI Center of Excellence, responsible AI, ROI); Defender gate audit 0 (architecture/strategy cert); cross-vendor audit 0; via 1 domain agent. 6 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
ab-730 0 (verified clean) 2026-06-02
ab-900 15 250 2026-06-20 f231766 (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 15 thin = 15 scenario; domain 3. Microsoft AB-900 Copilot & Agent Admin Fundamentals (Microsoft 365 Copilot per-user vs pay-as-you-go/metered consumption, Copilot Studio, M365 admin center license + agent management, Copilot Analytics/adoption/readiness, Microsoft Agent 365, declarative vs custom-engine agents, agent discovery in Teams/Outlook/Word/BizChat); Defender gate audit 0 (admin cert, no Defender/Sentinel); via 1 domain agent. 5 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
ai-200 28 262 2026-06-20 eacb554 (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 28 thin = 28 scenario; domains 1,2,3,4. Microsoft AI-200 Developing AI Cloud Solutions on Azure (Azure OpenAI, Azure AI Services/Cognitive Services, Azure AI Search, Functions, Service Bus, Event Grid, Container Apps, Key Vault, managed identities, RAG/prompt flow); Microsoft product-match + Defender gate audit 0 (developer cert, no Defender); via 4 parallel domain agents. 5 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production, cert total 262)
aws-clf-c02 0 (verified clean) 2026-06-02
az-900 17 250 2026-06-20 f0a2ff7 (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 17 thin = 17 scenario; domains 1,2,3 (d3 carried 14). Microsoft AZ-900 Azure Fundamentals (cloud concepts IaaS/PaaS/SaaS/shared-responsibility/CapEx-OpEx; Azure architecture regions/AZ/resource-groups/ARM/compute/networking/storage; management & governance Cost Management/Advisor/Policy/Monitor/Log Analytics/Cloud Shell/Arc); Microsoft product-match + Defender gate audit 0 (fundamentals, no Defender); cross-vendor audit 0; via 3 parallel domain agents. 5 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production. NOTE: now a FREE cert (price_practice=0))
dp-600 0 (verified clean) 2026-06-02
dp-750 2 250 2026-06-22 5e6b06c (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 2 thin = 2 scenario; domain 1. Microsoft DP-750 Azure Databricks Data Engineer (Azure Databricks, Delta Lake managed/external tables/OPTIMIZE/Z-ORDER/time travel, Unity Catalog metastore/catalogs/governance/lineage, clusters/Photon, Delta Live Tables, Auto Loader, ADLS Gen2); Defender audit 0; cross-vendor audit 0 (no AWS/GCP); via 1 domain agent. 1 scenario re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
dp-900 30 250 2026-06-20 7b981cf (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 30 thin = 29 scenario + 1 explanation; domains 1,2,4. Microsoft Azure Data Fundamentals (Azure SQL, Cosmos DB, Synapse, Data Factory, Data Lake Storage, Blob, Databricks, Stream Analytics, Power BI; relational/non-relational, OLTP/OLAP, ETL/ELT); Microsoft product-match + Defender gate audit 0 (data fundamentals, no Defender); via 3 parallel domain agents. 12 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
fortinet-nse7-efw 47 250 2026-06-20 0f6de88 (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 47 thin = 40 scenario + 7 whyWrong; all 5 domains. Fortinet NSE7 Enterprise Firewall (FortiGate/FortiOS 7.x: IPsec/IKEv2, SSL-VPN, ADVPN, SD-WAN, HA FGCP/FGSP, UTM/NGFW profiles); cross-vendor brand audit 0 across all 5 ext fragments; via 5 parallel domain agents. 16 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
gcp-cloud-architect 19 250 2026-06-20 c40413d (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 19 thin = 19 scenario; domains 1,2,4,5. Google Cloud Professional Cloud Architect (Compute Engine, GKE, Cloud Run, Cloud Storage, Cloud SQL/Spanner, BigQuery, VPC/Shared VPC, Cloud Load Balancing, Cloud Armor, Cloud IAM/KMS, Pub/Sub, Dataflow, Anthos, Operations suite, resource hierarchy); GCP-native, cross-vendor brand audit 0 across all 4 ext fragments (no Azure/AWS); via 4 parallel domain agents. 6 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
paloalto-cybersec-apprentice 30 250 2026-06-20 e7d9460 (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 30 thin = 30 scenario; domains 2,3. Palo Alto Networks Cybersecurity Apprentice (PAN-OS, NGFW PA/VM/CN-Series, Panorama, Cortex XDR/XSIAM/XSOAR, Prisma Cloud/Access, WildFire, App-ID/User-ID/Content-ID, GlobalProtect, Zero Trust + security fundamentals); cross-vendor brand audit 0 across both ext fragments (no competing security vendors); via 2 parallel domain agents. 17 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
pl-300 13 250 2026-06-20 a3f9c77 (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 13 thin = 13 scenario; domains 2,3,4. Microsoft PL-300 Power BI Data Analyst (DAX measures/time-intelligence/CALCULATE, Power Query/M, data modeling/star schema/display folders, Performance Analyzer, slicers/sync-slicers/forecasting/accessibility/personalization, workspaces & roles Admin/Member/Contributor/Viewer, Power BI apps + audiences, RLS, data alerts); Defender gate audit 0; cross-vendor audit 0 (no Tableau/Looker/Qlik); via 3 parallel domain agents. 5 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
pl-900 40 250 2026-06-20 a57634c (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 40 thin = 40 scenario; domains 1,3,4,5. Microsoft Power Platform Fundamentals (Power Apps canvas/model-driven, Power Automate, Power BI, Power Pages, Copilot Studio, Dataverse, connectors, AI Builder); Microsoft product-match + Defender gate audit 0; via 4 parallel domain agents. 20 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)
sc-500 19 250 2026-06-20 f7cc967 (350-floor re-pass superseding the 2026-06-02 verified-clean/300-floor entry; 19 thin = 19 scenario; domains 1,2,4. Microsoft SC-500 Cloud & AI Security Engineer (beta, replaces AZ-500: Microsoft Entra/Conditional Access/PIM, Defender for Cloud/Servers/Storage/SQL/Containers, Microsoft Sentinel analytics/SOAR, Microsoft Purview DSPM for AI/DLP, Azure platform security NSG/Firewall/Key Vault, Defender for AI Service, Foundry AI Gateway, Security Copilot); security cert - Defender/Sentinel/Purview product-match gate "qualified, 0 bare"; via 3 parallel domain agents. 5 scenarios re-authored post-leak-triage to pure stakes-only (0 scen-leaks). guided-qa ALL CLEAR 45/45; banned-phrases clean 0/617; LIVE-verified thin=0 on production)

Running total: 126 / 126 certs through Phase C (123 with edits, 3 verified clean — no edits needed). Note: "through Phase C" = present in this ship-log. 🎉 As of 2026-06-22 the ENTIRE portfolio is thin-clean: a fresh files/portfolio_thin_scan.py sweep shows EVERY cert at 0 scenario-thin with NO exceptions. The final cert, az-305, completed BOTH Phase B (200->250, +50 hard scenario Qs, commit faa67d2) and the Phase C thin-pass (183 thin scenarios + 17 explanations enriched, commit 71e89e0) on 2026-06-22, and is LIVE-verified thin=0 on production. No remaining Phase C work items.

Suggested next targets (the seventeenth pass — a 2026-06-22 single-cert top-up: az-700 (Azure Network Engineer Associate) shipped 2026-06-22 and LIVE-verified thin=0 on production (CF deploy live at live-verify cycle 7, ~7 min post-push). 8 thin = 1 scenario + 6 explanation + 1 whyWrong across domains 3,5; hand-authored in main context (single cert, too small to warrant parallel agents); Defender audit 0 (network cert), cross-vendor 0; 0 scen-leaks. RE-PASS of the 2026-06-02 22-thin row, running total unchanged at 125/125. 🎉 PHASE C IS NOW 100% COMPLETE — the eighteenth pass (2026-06-22) shipped the final cert az-305. A fresh python files/portfolio_thin_scan.py sweep (2026-06-22) shows EVERY cert at 0 scenario-thin with NO exceptions. az-305 required a Phase B pass first (Phase-A-only at 200 Qs -> authored 50 net-new hard Qs to 250 via inject_phase_b, commit faa67d2), THEN the standard thin-pass (183 thin: 183 scenario + 17 explanation, via 5 parallel domain agents + 2 cross-model SME agents, commit 71e89e0). Both LIVE-verified thin=0 on production. The thin-enrichment program is complete.

Leak-fix pipeline (added 2026-06-19): for leak-heavy certs, the per-cert leak triage was automated with files/make_fix_brief.py (lists every scen-leak Q with HEAD scenario + correct answer to avoid) -> a dedicated leak-fix agent re-authors pure stakes-only additions -> files/check_leakfix.py (re-leak guard + length + coverage) -> files/apply_leakfix.py (rebuild scenario = HEAD + clean addition) -> files/hygiene_indent.py (match HEAD indent/newline). This dropped scen-leaks to 0 on all 4 certs in one pass each. files/apply_scen_expl_direct.py handles pre-existing malformed string-option Qs whose inherited whyWrong trips patch_in_place's validator.

Note: az-305 was the only Phase-A-only cert in the portfolio (200 Qs, no Phase B); on 2026-06-22 it received both Phase B (200->250, 50 hard scenario Qs) and the Phase C thin-pass (183 thin), completing the portfolio.


How to Update This Page

After each enrichment session: 1. Change the cert's status from ⬜ Pending to ✅ Done 2. Update the After column with the actual question count 3. Update the New Hard column with the count of new scenario questions 4. Update the Date column 5. Update the progress summary at the top 6. Commit + push the learning-docs repo


Progress by Vendor

Microsoft (37 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
ab-100 ✅ Done 200 250 50 450 520 2026-04-25
ab-620 ⬜ Pending 200 208 225
ab-730 ✅ Done 200 250 50 380 480 2026-04-25
ab-731 ✅ Done 200 250 50 644 879 2026-04-29
ab-900 ✅ Done 200 250 50 500 540 2026-04-25
ai-103 ✅ Done 200 250 50 540 700 2026-04-27
ai-200 ✅ Done 0 250 50 424 860 2026-05-08
ai-300 ✅ Done 200 250 50 420 530 2026-04-25
ai-901 ✅ Done 200 250 50 340 450 2026-04-25
az-104 ✅ Done 200 250 50 380 480 27 Apr 2026
az-120 ✅ Done 200 250 50 350 400 2026-04-26
az-140 ✅ Done 200 250 50 415 608 2026-04-25
az-305 ✅ Done 200 250 50 626 525 2026-06-22
az-400 ✅ Done 200 250 50 453 527 2026-04-28
az-700 ✅ Done 200 250 50 465 590 2026-04-28
az-900 ✅ Done 200 250 50 436 627 2026-04-25
dp-300 ✅ Done 250 50 10/domain 448 560 02 May 2026
dp-420 ✅ Done 200 250 50 457 659 2026-04-26
dp-600 ✅ Done 200 250 50 460 620 2026-04-25
dp-700 ✅ Done 200 250 50 430 490 2026-04-29
dp-750 ✅ Done 200 250 50 471 625 2026-04-26
dp-800 ✅ Done 200 250 50 380 420 2026-04-26
dp-900 ✅ Done 200 250 50 450 550 2026-04-30
mb-500 ✅ Done 200 250 50 380 480 2026-04-25
mb-800 ✅ Done 200 250 50 420 650 2026-04-27
md-102 ✅ Done 200 250 50 405 504 2026-04-28
ms-102 ✅ Done 200 250 50 425 621 2026-05-11
ms-700 ✅ Done 250 50 452 574 2026-05-01
pl-300 ✅ Done 200 250 50 418 608 2026-04-28
pl-400 ✅ Done 200 250 50 376 471 2026-05-15
pl-900 ✅ Done 200 250 50 450 600 2026-04-25
sc-100 ✅ Done 200 250 50 367 458 2026-05-14
sc-200 ✅ Done 200 250 50 469 736 2026-04-30
sc-300 🔶 Phase A 200 200 0 395 516 2026-05-01
sc-401 ✅ Done 200 250 50 350 400 2026-04-28
sc-900 ✅ Done 200 250 50 376 527 2026-05-19

AWS (15 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
aws-aif-c01 ✅ Done 200 250 50 294 415 2026-05-14
aws-ans-c01 ✅ Done 200 250 50 357 408 2026-05-13
aws-clf-c02 ✅ Done 200 250 50 640 812 2026-04-28
aws-das-c01 ✅ Done 200 250 50 382 539 2026-05-01
aws-dbs-c01 ✅ Done 200 250 40 377 470 2026-05-20
aws-dea-c01 ✅ Done 200 250 50 306 397 2026-05-13
aws-dop-c02 ✅ Done 200 250 50 375 479 2026-05-19
aws-dva-c02 ✅ Done 200 250 50 312 502 2026-05-23
aws-mla-c01 ✅ Done 200 250 50 420 480 2026-04-29
aws-mls-c01 ✅ Done 200 250 50 331 515 29 May 2026
aws-pas-c01 ✅ Done 250 50 450 530 02 May 2026
aws-saa-c03 ✅ Done 200 250 50 380 480 27 Apr 2026
aws-sap-c02 ✅ Done 250 50 17 May 2026 320 464 7917d53 / 8d478fe
aws-scs-c02 ✅ Done 200 250 50 319 436 2026-05-15
aws-soa-c02 ✅ Done 200 250 50 285 404 2026-05-14

Cisco (11 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
cisco-ccie-ei ✅ Done 200 250 50 467 499 2026-05-24
cisco-ccna ✅ Done 200 250 50 380 450 2026-04-30
cisco-cct ✅ Done 250 50 250 380 450 2026-04-29
cisco-clcor ✅ Done 200 250 50 313 511 2026-05-23
cisco-cyberops ✅ Done 200 250 50 410 471 2026-05-19
cisco-dccor ✅ Done 200 250 50 278 475 2026-05-15
cisco-devasc ✅ Done 200 250 50 371 473 14 May 2026
cisco-devcor ✅ Done 200 250 50 450 479 2026-05-20
cisco-encor ✅ Done 200 250 50 345 471 2026-05-21
cisco-scor ✅ Done 200 250 50 287 440 2026-05-22
cisco-spcor ✅ Done 200 250 50 347 518 2026-05-22

CompTIA (17 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
comptia-220-1201 ✅ Done 200 250 50 447 569 2026-05-02
comptia-220-1202 ✅ Done 200 250 50 326 482 2026-05-15
comptia-cas-005 ✅ Done 200 250 50 392 472 2026-05-16
comptia-cnx-001 ✅ Done 200 250 50 389 465 2026-05-19
comptia-cs0-003 ✅ Done 200 250 50 335 480 2026-05-15
comptia-cv0-004 ✅ Done 200 250 50 385 595 2026-05-31
comptia-cy0-001 ✅ Done 200 250 50 324 480 2026-05-22
comptia-da0-002 ✅ Done 200 200 0 376 538 2026-05-01
comptia-ds0-001 ✅ Done 200 250 50 338 427 2026-05-15
comptia-dy0-001 ✅ Done 200 250 50 399 552 2026-05-12
comptia-fc0-u71 🔶 Phase A 200 200 0 381 515 2026-05-01
comptia-n10-009 ✅ Done 250 50 250 370 420 2026-04-29
comptia-pk0-005 ✅ Done 200 250 50 350 400 2026-04-26
comptia-pt0-003 ✅ Done 200 250 50 320 486 2026-05-16
comptia-sk0-005 ✅ Done 200 250 50 411 567 2026-05-11
comptia-sy0-701 ✅ Done 200 250 50 368 439 2026-05-12
comptia-xk0-005 ✅ Done 200 250 50 350 400 2026-04-28

GCP (11 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
gcp-cloud-architect ✅ Done 200 250 50 420 520 2026-04-29
gcp-cloud-developer ✅ Done 213 250 37 (13+12+12 across d2-d4) 357 479 2026-05-24 (partial-B completion; SME-check 3H/5M/1L fixed pre-commit)
gcp-cloud-digital-leader ✅ Done 200 200 0 375 548 2026-05-01
gcp-cloud-engineer ✅ Done 200 250 50 380 450 2026-04-30
gcp-data-engineer ✅ Done 200 250 50 430 510 2026-04-29
gcp-database-engineer ✅ Done 200 250 50 350 420 2026-04-28
gcp-devops-engineer ✅ Done 200 250 50 393 576 2026-05-12
gcp-ml-engineer ✅ Done 200 250 50 335 458 2026-05-16
gcp-network-engineer ✅ Done 200 250 50 317 480 2026-05-17
gcp-security-engineer ✅ Done 250 50 383 545 2026-05-01
gcp-workspace-admin ✅ Done 250 50 390 514 01 May 2026

ISC² (10 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
isc2-cc ✅ Done 200 250 50 381 507 2026-05-01
isc2-ccsp ✅ Done 200 250 50 403 439 2026-05-22
isc2-cgrc ✅ Done 200 250 50 363 444 2026-05-12
isc2-cissp ✅ Done 200 250 50 406 638 1 Jun 2026
isc2-cissp-issap ✅ Done 200 250 50 644 977 2026-06-02
isc2-cissp-issep ✅ Done 200 250 50 388 492 2026-05-24
isc2-cissp-issmp ✅ Done 200 250 50 573 593 1 Jun 2026
isc2-csslp ✅ Done 200 250 50 405 681 2026-05-31
isc2-hcispp ✅ Done 200 250 50 333 527 24 May 2026
isc2-sscp ✅ Done 200 250 50 355 441 16 May 2026

ISACA (5 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
isaca-cdpse ✅ Done 200 250 50 400 621 2026-06-01
isaca-cgeit ✅ Done 200 250 50 299 488 2026-05-13
isaca-cisa ✅ Done 200 250 50 337 520 30 May 2026
isaca-cism ✅ Done 200 250 50 365 545 29 May 2026
isaca-crisc ✅ Done 200 250 50 374 474 16 May 2026

CNCF (5 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
cncf-cka ✅ Done 200 250 50 400 500 2026-04-30
cncf-ckad ✅ Done 200 250 50 305 423 2026-05-15
cncf-cks ✅ Done 200 250 50 306 445 2026-05-16
cncf-kcna 🔶 Phase A 200 200 0 366 514 2026-05-01
cncf-kcsa ✅ Done 200 250 50 303 465 2026-05-15

HashiCorp (3 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
hashicorp-consul-associate ✅ Done 200 250 50 270 458 2026-05-20
hashicorp-terraform-associate ✅ Done 200 250 50 285 460 2026-05-16
hashicorp-vault-associate ✅ Done 200 250 50 312 494 2026-05-22

EC-Council (3 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
eccouncil-ceh-v13 ✅ Done 200 250 50 347 516 2026-05-23
eccouncil-chfi-v11 ✅ Done 200 250 50 418 599 1 Jun 2026
eccouncil-cnd-v3 ✅ Done 200 250 50 421 634 30 May 2026

Fortinet (3 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
fortinet-nse4 ✅ Done 200 250 50 277 462 2026-05-16
fortinet-nse5-fmg ✅ Done 200 250 50 340 418 2026-05-13
fortinet-nse7-efw ✅ Done 200 250 50 328 459 2026-05-14

Juniper (3 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
juniper-jncia-junos ✅ Done 200 250 50 195 432 13 May 2026
juniper-jncip-sec ✅ Done 200 250 50 470 723 2026-06-01
juniper-jncis-ent ✅ Done 200 250 50 319 581 2026-05-29

Palo Alto (3 certs)

Cert Status Before After New Hard Avg Scen Avg Expl Date
paloalto-cybersec-apprentice ✅ Done 200 250 50 460 540 2026-04-30
paloalto-netsec-analyst ✅ Done 200 250 50 354 458 2026-05-22
paloalto-netsec-professional ✅ Done 200 250 50 422 681 2026-06-01