
Master the latest cybersecurity technologies and prepare for the 701 exam with a hands-on security mastery course featuring labs and exams, not a scripted lecture.
Francois B. Arthanas shares practical cybersecurity expertise from 10+ years across roles from help desk to information security officer, emphasizing hands-on teaching and targeted certifications like CISSP, CISA, and CISM.
Aim to pass the Security+ exam while gaining a broad view of the cybersecurity landscape. Learn to articulate cybersecurity concepts in interviews and commit to finishing the course.
Set a concrete exam date and register for the security+ exam to stay motivated and on track. Read questions thoroughly and choose the best answer within the CompTIA world.
Keep your Security Plus in good standing by completing CertMaster continuing education. Renew via upper level certifications or accumulating CPEs through conferences, courses, and chapters.
Register for the security+ exam via pearsonvue, create and log in to your account, verify your name, and schedule for online or home testing with date and time options.
Take notes to reinforce memory using Joplin or pen and paper; access course resources like quizzes, labs, exams, PBQs, and podcasts; export PDFs and sync with cloud.
Udemy does NOT allow us to add any external links. Please download the contain zip file with workstation and use google to find link to register for VMware license.
Download Kali Linux from their website.... Metasploitable 2 is attached as a zip file.
Only do this if you are going to go over the Windows Lab in this section... You can also use your physical machine for the Windows Essential Lab. So feel free to skip this.
Explore domain 1 of the CompTIA Security+ mastery course to learn the NIST cybersecurity framework, CIA concepts, zero trust, cryptography, and exam prep with PBQs and case studies.
Explore domain two by identifying threat actors, their motivations, and data exfiltration, then assess vulnerabilities and attack surfaces across apps, OS, and cloud, and apply mitigation like patching and segmentation.
Analyze security architecture for cloud and on-prem networks, emphasizing infrastructure as code, serverless, and zero-trust design. Examine data protection, resilience, backups, and ransomware defenses across IoT, SCADA, and virtualization.
Define secure baselines and harden systems from ISO images, and manage assets. Prioritize vulnerabilities for SOC and apply vulnerability management with identity and access controls like firewalls and IDS.
Explore governance, risk, and compliance (GRC) and learn how policies, standards, and procedures guide security program leadership, third-party risk, audits, and security awareness training, with case studies and pbqs.
Identify where valuable data and critical assets reside, and who can access them, using the CIS top 18 controls to inventory hardware and software and guide secure deployment.
Learn the NIST CSF 2.0, identify critical assets, implement protect and detect controls, and execute respond and recovery with governance and SIEM/IDS/EDR for rapid incident response.
Explore the csf 2.0 categories and their functions, including identify, protect, detect, respond, and recover, with governance, asset management, risk assessment, security awareness, and CIEM.
Explore the CIA triad—confidentiality, integrity, and availability—and learn how encryption, access control, hashing, and redundancy protect data from disclosure, tampering, and outages.
Master authentication, authorization, and accounting (AAA) fundamentals—identifying, verifying identity, and granting access by role-based (RBAC) or attributes—along with cloud IAM and auditing to track activity and prevent insider threats.
Explore defense in depth, using multiple layers of security—encryption, access controls, DLP, secure coding, input validation, and endpoint protection—to ensure resilience even if one layer fails.
Enforce the principle of least privilege and need-to-know by granting only the minimum permissions needed, enabling effective access control and reducing breach impact through proper identity management.
Separation of duties enforces least privilege by ensuring two people handle a critical function, reducing risk and deterring fraud through checks, approvals, and periodic vacations.
Identify, assess, treat, and monitor risks to assets, focusing on controllable vulnerabilities and threats to reduce risk to a manageable level.
Explore the risk management lifecycle from risk appetite and identification to qualitative and quantitative assessment, focusing on monetary values, likelihood, impact, and leadership buy-in.
Mitigate risk by balancing security and functionality, implementing controls to reduce likelihood and impact, and bringing risk to a manageable level through risk transference, avoidance, acceptance, and ongoing monitoring.
Perform gap analysis to compare current risk with the desired state, identify the gap, and develop an action plan by identifying current state, defining desired state, and analyzing the gap.
Learn how security controls reduce risk by applying technical controls such as firewalls and 2FA, administrative policies, operational daily habits, and physical measures like fences and CCTV.
Understand preventative controls across technical, physical, and administrative categories. Acknowledge that prevention can fail, implement defense in depth, and pair detection with response, such as intrusion prevention systems.
Explains deterrent controls as psychological warnings that discourage trespassers, using examples like warning signs, a warning banner on login pages, and security guards to deter rather than prevent.
Master detective controls such as CCTV surveillance and real-time monitoring that detect incidents and alert responders; SNORT is IDS, while Splunk and Elastic are CIM tools that monitor activity.
Describe how corrective controls activate after an incident to recover, restore, and reconfigure systems; promote backing up, patching, restoring settings, and reconfiguring firewalls to return to normal.
compensating controls provide alternatives when the primary control is unavailable, such as using a security guard for a broken door lock, enhanced monitoring for legacy systems, or multi-factor authentication.
Directive controls, or administrative controls, set company rules with policies guiding behavior. They pair with technical controls to enforce change management and curb shadow IT, forming a defense-in-depth approach.
Examine the NotPetya 2017 case study, showing how EternalBlue and SMB zero days vulnerabilities enabled a global cyber attack, with Mimikatz dumping passwords and massive losses for firms including Maersk.
Explore the top cybersecurity career paths, from engineering and testing to incident response, forensics, and auditing, and learn how cloud, AI, governance, and zero trust shape the field.
learn to balance security with business enablement, practice risk management and acceptable risk, and support threat hunting, incident response, and penetration testing through practical, report-driven defense.
Explore preventive controls in cybersecurity, including firewalls, ACLs, system hardening, patching, change management, and security awareness training, while recognizing that detection and rapid response are essential when prevention falls short.
Learn how deterrent controls psychologically discourage attackers through warning signs and banners, distinguishing deterrence from prevention and outlining consequences for trespassers.
Detective controls reveal security events through monitored alerts from systems like Splunk. Note that CCTV or SIEM require human monitoring to function as detective controls.
Corrective controls jump into action to stop the bleed and restore normal operations after an attack, using measures like intrusion prevention systems, spyware remediation, and recovery controls.
directive controls set security direction through policies, standards, and training, addressing the human factor and shadow it, and reinforcing defense in depth with multi-layer controls and change management.
Identify threat actors as individuals, groups, or organizations with harmful intent, including insiders and unintentional actors. Use MITRE's attack framework and TTPs—tactics, techniques, and procedures—and IOCs to slow attackers.
Analyze threat actors by assessing motivation, capability, and persistence, including financial and political motives, advanced persistence threat groups, their tools, and how defenders use Mendiant and CrowdStrike.
Identify script kiddies, less experienced attackers who rely on pre-built scripts and tools like Metasploit on Kali Linux for automated vulnerability scans.
Identify insider threats: people with legitimate access who can exfiltrate data, including former, current, and contractor staff. Apply a multi-layer defense with data loss prevention and privileged access controls.
Explore organized crime as a structured threat actor using ransomware as a service to target companies for money, highlighting REVO groups, WannaCry, Colonial Pipeline, JBS, and FBI guidance on paying.
State-sponsored advanced persistent threats, or APTs, are well-funded, professional groups pursuing geopolitical espionage and intellectual property theft. They operate long-term, may use zero days, and target governments and critical infrastructure.
State-sponsored advanced persistent threats rely on persistence and deep understanding of target networks, not zero days, as Rob Joyce of the NSA explains; defenders should learn the environment.
Identify terrorist groups as threat actors who use cyber means to threaten governments and citizens with violence, spreading fear, propaganda, disinformation, and disruption.
Identify all potential entry points in the attack surface, distinguish it from attack vectors, and reduce risk by removing unnecessary services, ports, and accounts, and by implementing strong authentication.
A zero-day exploit targets an unknown vulnerability, often used against high-value targets; detectability lacks signatures, so defend with defense in depth, behavior-based anomaly detection, reduced attack surface, and threat intelligence.
Identify legacy systems as out-of-date, end-of-life assets with unpatched vulnerabilities, and mitigate risk through isolation, segmentation, and a web application firewall that whitelists ftp-only access.
Examine the cyber kill chain from recon (osint) to weaponization, delivery, exploitation, installation, command and control, and exfiltration, a framework for attacker steps.
Explore the MITRE ATT&CK framework with Navigator and Detect to map adversary techniques to your logs, prioritize detections, and tailor the approach to your environment.
Generate an asymmetric key pair in Kali Linux with ssh-keygen using RSA, creating a public key for sharing on MIT's public key server and a private key for secure communication.
Cryptography, the practice and study of secure communication in the presence of adversaries, enables encryption and secure protocols, with cryptanalysis testing weaknesses and cryptosystems as algorithms like Blowfish and Toolfish.
Explain how cryptography achieves confidentiality, integrity, authentication, and non-repudiation by using a cipher and a key to transform plaintext into ciphertext and back through encryption and decryption.
Symmetric encryption uses a single secret key for both encryption and decryption, making it fast and ideal for bulk data, but its key distribution and non-repudiation limitations pose challenges.
Explore symmetric algorithms, including AES, DES, 3DES, RC4, Blowfish, and Twofish, with emphasis on AES as the current standard used in Wi‑Fi and the weaknesses of older ciphers.
Explore symmetric encryption use cases such as disk and file encryption, database security, and secure communications, highlighting bulk data protection, key management challenges, and AES vs DES key lengths.
Asymmetric encryption uses a key pair, with a public key shared openly and a private key kept secret, to ensure confidentiality and enable digital signatures for authentication and non-repudiation.
Compare RSA and ECC, examine Diffie-Hellman for key exchange and session key distribution, and review DSA for digital signatures, highlighting key sizes and performance trade-offs.
Explore hashing algorithms and their role in data integrity and password security, showing how hashes protect passwords and how breaches like Rockyou exploit unencrypted credentials.
Discuss hashing algorithms for passwords, detailing md5 and sha, the sha-2 family, sha-3, and hmac, including collision issues and authentication use cases like one-time codes and bitcoin verification.
Explore how PKI creates a root of trust by linking encryption, hashing, and trusted websites through a CA hierarchy and domain, OV, and EV validations for https.
Identify the roles of the registration authority and certificate authority in PKI, and describe certificate signing requests, X.509 digital certificates, and certificate status methods like CRL and OCSP.
Explore key management and exchange between browser and bank servers, detailing how Diffie-Hellman, RSA, or elliptic-curve Diffie-Hellman establish a shared symmetric key over HTTPS with perfect forward secrecy.
Establish secure key exchange between browser and bank server using diffie-hellman or rsa, over https, with perfect forward secrecy and key pinning to prevent man-in-the-middle attacks.
Explore entropy-driven key generation and compare storage options—TPM on the motherboard, removable HSM, and secure enclaves—with self-encrypting drives for full-disk encryption.
Key escrow backups keys with a third party to enable data recovery and compliance, while M of N controls distribute keys among multiple people to prevent a point of failure.
Learn how salting and key stretching strengthen password security by adding random values and extra hashing rounds to resist brute force and rainbow table attacks using bcrypt.
Explore common cryptographic attacks, from brute-force and dictionary attacks to rainbow-table attacks, and learn how salts, cryptographic hashes, MD5/SHA-1 weaknesses, and downgrade attacks strengthen web encryption.
Explore the big picture of cryptography, covering symmetric and asymmetric encryption, stream and block ciphers, public and private keys, hashing, digital signatures, PKI, key management, and Diffie-Hellman.
Explore obfuscation as making code hard to understand, and see how attackers misuse it; also cover steganography, data masking of PII and PHI, tokenization, and de-identification.
Analyze the 2010 Stuxnet case study, a cyber weapon targeting Iran's nuclear program, attributed to the US and Israeli intelligence, using usb delivery, zero-day exploits, and stolen Microsoft keys.
Explore CyberChef, the Swiss army knife for cybersecurity professionals, mastering encoding, decoding, encryption, and decryption with ROT13, XOR, and PGP RSA key pairs.
Explore authentication and authorization, including AAA, MFA, passwords and tokens, SSO. Cover SAML, OAuth, OpenID Connect, DAC, MAC, RBAC, ABAC, rule-based models, and Kerberos, LDAP, RADIUS, TACACS and TACACS+.
Explore identification, authentication, authorization, and accounting (IAAA) and learn how proving who you are enables access control, while authorization defines permissions and accounting logs activities.
Explore the three main authentication factors—something you know, something you have, and something you are—and how location and behavior add depth, with examples like passwords, smart cards, biometrics, and smartphones.
Compare multi-factor authentication with two-factor authentication and learn how MFA uses two or more methods, such as something you know, something you have, and something you are.
Explore how authentication methods verify user identity using passwords, tokens, biometric, digital signatures, and digital certificates. Understand how these methods are applied to authenticate people in various scenarios.
Biometric authentication offers highest security but is costly and enrollment-driven, relying on a biometric database to compare scans; engineers balance false rejection, false acceptance, and crossover error rate.
Examine hardware authentication tokens, including YubiKeys and smart cards, compare one-time passwords and time-based tokens, and explore FIDO standards and passwordless authentication led by Google.
Explore software authentication tokens on smartphones that provide one-time codes via SMS, email, or push notification, with OTPs expiring every 30 seconds and improving security against keyloggers.
Explore passwordless authentication with FIDO standards, passkeys and biometrics to verify identity without passwords, featuring magic links and security tokens for improved security and user experience.
Explore how single sign-on enables a user to sign in once and access multiple applications. Understand federation, where an identity provider enables cross-organization sign-in using SAML, OAuth, and OpenID Connect.
Explore how OpenID Connect uses tokens like JSON web tokens to authenticate users via Google. Learn how SAML uses XML and HTTPS with SOAP for secure data exchange.
Explore discretionary access control (DAC) and its challenges, then compare role-based access control (RBAC) using Active Directory and OUs, attribute-based access control with zero trust, and rule-based RUBAC with ACLs.
Kerberos is a single sign-on authentication protocol that uses tickets; a key distribution center issues tickets via the authentication and ticket-granting servers, for eight-hour validity in Windows environments.
Discover how Kerberos uses an authentication service to issue a ticket-granting ticket, which the client exchanges for a service ticket to enable mutual authentication between client and server.
Implement radius to authenticate, authorize, and account by interfacing with Active Directory, noting UDP usage and incomplete encryption, with diameter offering TLS and IP security.
Explore TACACS+ and its improvements over TACACS and Radius, highlighting TCP-based, fully encrypted conversations for centralized authentication, authorization, and accounting in device management for routers, switches, and firewalls.
Learn hands-on password cracking using John the Reaper and Hashcat in Kali Linux, exploring md5 and YesCrypt hashes, shadow and passwd files, unshadow, and word lists like rockyou.
Explore physical security concepts and deception technologies, covering access control, vestibules and man traps, with insights on lighting, security guards, badges, and sensors.
Explore why physical security is essential to cybersecurity and how access controls protect data center assets and prevent unauthorized entry.
Explore bollards and access control vestibules, including mantraps, to deter tailgating and enforce authentication. Learn how fencing and CCTV deter and detect intrusions in high-security facilities.
Learn how security guards, lighting, and access badges form essential physical security controls to deter, detect, and prevent intrusions, with badge authentication and credential verification.
Explore how various sensors including infrared, pressure, microwave, and ultrasonic detect motion and trigger lighting and alarm systems, powering practical security implementations in real buildings.
Explore deception and disruption technologies, including decoys, honeypots, honey nets, and honey files, to monitor attacker behavior and use intelligence to secure the organization.
Explore change management and security impact, covering business processes, version control with git and GitHub, and the role of documentation in maintaining secure systems.
Master change management to prevent vulnerabilities and outages by testing changes in a controlled environment, rolling back when needed, and integrating security to reduce incidents and ensure compliance.
Approve changes via a manager or change management committee, test in a virtualized environment, announce a maintenance window, ensure ownership and accountability with a back-out plan and sops for compliance.
Explore how version control in security tracks changes, assigns accountability, and enables rollback across CVCS and DVCS. See how Git and GitHub enable collaboration and precise versioning.
Showcases how a faulty CrowdStrike Falcon sensor update tampered with the Windows kernel, triggering a global outage and billions in losses, underscoring the need for rigorous testing and validation.
Explore the module roadmap, outlining malware types such as virus and worm, plus ransomware, Trojan, rootkit, spyware, and other threats, and examine social engineering techniques and mitigations.
Distinguish viruses and worms; explain macros and polymorphic or metamorphic variants, with examples like Morris worm, I love you worm, Code Red, Conficker, Stuxnet.
Explore trojans, remote access trojans, ransomware, spyware, and adware; learn how trojan horses conceal malicious intent and how ransomware encrypts files for ransom.
Explore how rootkits gain administrative privileges and evade detection at user, kernel, firmware, and hypervisor levels, and how keyloggers capture keystrokes and botnets enable denial-of-service attacks.
Learn about logic bombs that trigger by time or event, and fireless malware that stays in RAM to evade detection, using EDR and XDR with behavior analytics.
Explore malware delivery methods, including email, USBs, and network exploits like the WannaCry SMB vulnerability. Learn how supply chain attacks such as SolarWinds demonstrate how attackers reach multiple organizations.
Explore how social engineering uses psychology to trick people, leveraging authority, intimidation, social proof, scarcity, urgency, familiarity, and trust to bypass technical controls.
Phishing uses a broad volume of fraudulent e-mails to exploit social engineering, while spear phishing targets specific individuals. Whaling narrows further to compromise high-value targets like the CEO.
Explore typosquatting, where attackers register look-alike domains to exploit user typos and redirect visitors to attacker pages. See how misspellings like Google with an extra o enable this threat.
Learn about business email compromise (BEC), where attackers impersonate colleagues or brands to target a specific employee, including techniques like watering hole attacks.
Explore vishing and smishing as voice and text social engineering attacks, and farming (pharming) via DNS poisoning and host file manipulation to redirect users.
Learn how tailgating, dumpster diving, and shoulder surfing enable breaches and how to prevent them with badge verification, awareness of trash for sensitive data, and privacy screens.
Explore hoaxes, pretexting, and impersonation, including how deceptive messages claim viruses, use invented scenarios to gain trust, and impersonate trusted entities for unauthorized access.
Implement a multi-layer defense that blends human firewall training with tech controls like email filtering, security gateways, AI tools, EPP, patching, antivirus, and least-privilege policies against phishing.
The Complete CompTIA Security+ (SY0-701) Mastery Course is your ultimate guide to achieving the globally recognized Security+ certification and launching a successful career in cybersecurity.
This course is meticulously designed to help beginners and experienced professionals alike gain the skills and confidence needed to excel in the SY0-701 exam. Covering every objective outlined by CompTIA, you’ll explore the latest tools, techniques, and best practices to protect systems, networks, and data in an ever-evolving threat landscape.
Through engaging video lectures, hands-on exercises, and exam-focused practice tests, you’ll build expertise in areas such as risk management, incident response, cryptography, and network security. Whether you're looking to boost your credentials, break into cybersecurity, or stay ahead of emerging threats, this course is your key to success.
Take the next step in your career and join thousands of students who have transformed their futures with the Security+ certification.
What You'll Learn:
Understand the critical importance of security in today’s digital world, including the principles of confidentiality, integrity, and availability (CIA triad).
Learn to identify and respond to a wide array of threats like malware, ransomware, phishing, and social engineering.
Explore the tools and techniques for implementing secure networks, applications, and devices.
Master the processes for detecting, mitigating, and recovering from cybersecurity incidents.
Dive deep into encryption, hashing, and key management to protect sensitive data.
Familiarize yourself with key regulations, frameworks, and policies that guide organizational security practices.