
Introduction to the course, key topics to be covered, and call to action.
Introduction to the section, key topics to be covered, and call to action.
Learners will explore foundational cloud service models through real-world examples and plain-language definitions, enabling them to identify what components they must secure in different deployment scenarios across AWS, Azure, and GCP.
A guided tour of AWS, Azure, and GCP consoles where learners will launch common services (VMs, databases, SaaS apps) and compare how each maps to the IaaS, PaaS, or SaaS model, reinforcing shared responsibility understanding.
A comprehensive overview of Zero Trust and Confidential Computing concepts across AWS, Azure, and Google Cloud, exploring theoretical frameworks and architectural principles for secure multi-cloud environments.
An introduction to virtual machines (VMs), explaining compute resources like CPU, memory, and OS images, so learners can choose and configure secure base infrastructure.
Learners will distinguish between structured (RDS) and unstructured (S3/Blob) cloud storage, with a focus on performance, access control, and use cases.
This session covers subnets, IP ranges, and firewalls using real-world analogies, then explains why “0.0.0.0/0” is dangerous and how to scope secure network access.
A fun visual analogy to illustrate which security tasks belong to the cloud provider and which are owned by the user a critical concept in any cloud model.
Learners will create a read-only user using IAM tools, learning how to reduce risk by limiting permissions to only what’s needed for a task.
Learners will strengthen access controls by enabling MFA for IAM users, practicing secure configuration steps using AWS Console.
Introduction to the section, key topics to be covered, and call to action.
Learners will select an official or LTS image (e.g., Ubuntu/CentOS) that aligns with CIS Benchmarks and understand the importance of image provenance.
This video walks learners through activating OS-level updates and basic logging features like CloudWatch or Log Analytics, building a foundation for secure operations.
Learners will generate and apply SSH keys, disable password authentication, and understand deny-overrides to prevent unauthorized VM access.
Explains how inbound and outbound port rules work using a door-and-bouncer analogy, setting learners up to make informed firewall decisions.
Learners will create a security group allowing only HTTP and HTTPS traffic (ports 80/443), simulating a real-world web application firewall.
Demonstrates how to use curl and AWS Reachability Analyzer to confirm the firewall is blocking all but web traffic, reinforcing secure access configuration.
Learners will turn on KMS-backed encryption for RDS and S3 and understand why encrypted data at rest is essential for compliance and security.
Guides learners through enabling S3 public-access blockers, explaining how misconfigured buckets lead to data leaks and compliance issues.
Learners will schedule automated snapshots and backups, ensuring data resilience in case of deletion or breach.
Introduction to the section, key topics to be covered, and call to action.
Learners will activate one or more no-cost security tools in their sandbox account and understand the role of each in detecting suspicious activity.
Learners will explore real alerts (e.g., port scanning, reconnaissance) and learn how to read and react to each alert severity and source.
This session trains learners to differentiate between info-level alerts, medium threats, and false positives, reducing noise in detection systems.
Shows how to activate CloudTrail or its equivalents, ensuring full visibility into all account activity for forensic readiness.
Learners will filter logs for delete or terminate actions using predefined queries, laying the foundation for security monitoring.
Covers how to export logs to S3 or blob storage for long-term retention, compliance, or SIEM ingestion.
Learners will identify and deactivate compromised IAM credentials as part of a rapid containment process.
This session teaches how to preserve VM state by creating an image or volume snapshot before taking further action.
Learners complete a 5-question IR template to analyze the root cause, impact, and remediation steps after a mock incident.
The Advanced Cloud Security for AWS, Azure, & Google Cloud specialization is designed to provide beginners with a practical, security-first understanding of how to deploy, harden, and validate cloud-based environments across AWS, Microsoft Azure, or Google Cloud. Through this program, learners will gain hands-on experience identifying common cloud misconfigurations such as exposed virtual machines, open storage buckets, overly permissive access policies, and unmanaged credentials and understand how these issues can rapidly escalate into real-world breaches.
Following a structured, step-by-step curriculum, each module utilizes free-tier services, simple checklists, and guided walkthroughs to help learners build confidence while securing foundational cloud components. Participants will learn how different cloud service models (IaaS, PaaS, and SaaS) impact security decisions, how the shared-responsibility model defines the division of security responsibilities between the provider and the customer, and which built-in protections can reduce risk significantly.
The specialization emphasizes practical cloud security controls such as identity and access management basics, secure networking defaults, storage access restrictions, logging and monitoring essentials, and baseline hardening for compute instances. Learners will also practice reviewing configurations with an audit mindset, documenting security evidence, and validating improvements through repeatable checks.
By the end of this program, learners will have tested a cloud virtual machine against the CIS Benchmark, collected and exported audit-ready evidence into a structured folder, and created a printable ten-control security checklist for use in future cloud projects. This specialization prepares aspiring cloud practitioners, IT professionals, and security newcomers to secure real environments responsibly, communicate security posture clearly, and develop habits to consistently reduce cloud security risk through repeatable operational practices.