
Access a 35-page companion study guide in downloadable PDF form to accompany the course, and share an honest Udemy review when ready to help future students.
Explore identity and access management (IAM) concepts, including identification, authentication, authorization, and accountability, plus lifecycle practices like provisioning, revocation, periodic account reviews, and privilege creep, with MFA.
Define authorization and accountability in identity and access management, enforce least privileges and need-to-know, curb privilege creep, and use network, database, application, and system logs to ensure non-repudiation.
Examine how policies, standards, procedures, and guidelines shape security governance, defining organization-wide responsibilities, concrete rules, and step-by-step actions to ensure consistent security posture.
Explore GDPR, HIPAA, PCI-DSS and intellectual property protections, including PII and PHI handling, data minimization, breach reporting, encryption, access controls, and IP basics like trademarks, copyright, and patents.
After completing the lecture, please download the practice activity in the next lecture.
Practice Activity: Please try the lab first then try the Practice Activity in the next lecture.
Explore the OSI and TCP/IP protocol stacks, from application to physical layers, and learn how protocols like HTTP, TCP, IP, UDP, and TLS/SSL secure communications.
Understand how the application layer handles web pages and objects via HTTP, and how the transport layer ensures reliable TCP delivery or fast UDP.
Understand how the domain name system maps human readable names to IP addresses using a hierarchical DNS structure, UDP transmission, and globally distributed root, top level domain, and authoritative servers.
Explore the link layer, responsible for hop-to-hop delivery, and compare Mac addresses to IP addresses while seeing how transport, network, and link headers enable end-to-end routing.
Set up a Kali Linux lab on Apple silicon Macs with VirtualBox 7.1.8. Import the VM, launch VirtualBox, and run the main script to fetch labs.
Learn to use nmap to scan the 1000 common ports, identify open ports and their services, and perform stealth scans and os detection.
Set up lab and perform nmap scans to discover ports, fingerprint the operating system and kernel, and locate a secret service on a port in the 40,000 to 60,000 range.
Run the lab script to set up the environment, then use nmap to scan localhost's 1000 ports, revealing ports 22, 80, and 3006, and fingerprinting the os with -O.
Explore how NAT uses a single public IP to support thousands of internal systems, hides private addresses, and employs port address translation to differentiate connections.
Learn how firewalls defend networks as the first line of defense, using access control lists to block or allow traffic. Compare stateless and stateful designs with next-generation deep packet inspection.
Explore wireless LAN architectures and security challenges, including rogue access points, MAC spoofing, and man-in-the-middle risks, and compare WEP, WPA-Tkip, and WPA2 encryption.
Explore DNS attacks such as poisoning and spoofing, how DNSSEC uses public key cryptography to authenticate messages, and the threat of DNS reflection.
Analyze network attacks, including the Smurf, DNS reflection, and teardrop attacks, where spoofed IP addresses trigger ICMP floods and fragmentation to overwhelm victims and reveal network-layer denial-of-service risks.
Explore man-in-the-middle attacks, including passive eavesdropping and active traffic manipulation, and examine spoofing techniques like IP and DNS spoofing. Learn defenses using HTTPS, VPNs, WPA2, and public key cryptography.
Explore social engineering and phishing, explaining how attackers exploit human psychology, employ prompts like urgency and impersonation, and how to detect and prevent these attacks through training, policies, and reporting.
Explore how web applications are architected from front end to database, and learn core security practices and the OWASP top ten vulnerabilities.
Demonstrate sql injection techniques in a lab with a lamp stack vulnerable web app, using the login page, database queries, and union-based data extraction on Kali Linux.
Learn to mitigate sql injection attacks by sanitizing user input and using prepared or parameterized sql statements, separating code from data, and leveraging layer seven web application firewalls.
Explore cross-site scripting, including persistent and reflected variants, and learn how input sanitization, input validation, and secure coding practices mitigate these attacks.
learn vulnerability management as a continuous cycle of asset discovery, scanning, assessment, prioritization by business impact and exploitability, and mitigation through patching and disabling unused services.
Explore how viruses infect files and boot processes, replicate exponentially, and cause damage through data corruption, ransomware, or denial of service, alongside worms that auto propagate via networks.
Trojans masquerade as legitimate software to trick users, with remote access trojans enabling full system control, keylogging, and data manipulation; prevent them by avoiding untrusted sources and keeping defenses updated.
Learn how spyware gathers data through browser hijackers, cookies, and keyloggers; see how adware injects ads; understand ransomware encryption and prevention with indicators of compromise and decryption resources.
Discover how anti malware detects and removes malware using on-demand and real-time scanning, signature and anomaly based detection, and remediation steps like isolation, patching, and backups.
Explore the cyber kill chain and how attackers progress from reconnaissance to objective. Learn passive and active reconnaissance, weaponization, delivery via phishing and USB drops, exploitation, backdoors, and command-and-control.
Explore the cyber kill chain from reconnaissance to actions on the objective, showing how attackers exploit vulnerabilities with droppers to gain footholds, install backdoors, and establish command and control.
Trace the cyber kill chain in a real world Target incident by examining reconnaissance, weaponization, delivery, exploitation, installation, command and control, and exfiltration.
Understand the incident response lifecycle from preparation to lessons learned, with practical steps for preparation, identification, containment, eradication, and recovery, plus post-incident analysis to prevent recurrence.
Explore intrusion detection systems and intrusion prevention systems as the first line of defense, and compare misuse detection with anomaly detection in network and host based deployments.
Discover snort, an open source intrusion detection and prevention system (IDPS) that inspects real-time network traffic, uses a rule-based engine, and logs and alerts for incident response.
Learn to configure snort in a Kali Linux VM and an nginx Docker container, and write alert rules for SSH port scans and ICMP ping traffic.
Explore packet and protocol analysis across the application, transport, network, and link layers, tracing how headers, ports, and addresses including DNS, TCP/UDP, and MAC addresses enable end-to-end communication.
Master tcpdump fundamentals to monitor traffic on docker zero, apply filters, analyze live icmp, http, and dns traffic, and perform forensic analysis on pcap files.
Explore Wireshark, a free open source network packet analyzer used to detect threats, investigate incidents, and analyze traffic packet by packet; learn the UI and capture options.
Use wireshark to investigate a credentials breach by loading the credentials breach pcap ng, tracing access from Kali Linux VM to the nginx server, and confirming exfiltration via tcp stream.
Explore a realistic Acme corporate data breach with Wireshark to perform forensic investigation of network traffic, identify attack vectors, malware activity, and data exfiltration.
Examine how identity and access management prevents breaches by restricting admin access. Explore IAM concepts from identification to accountability and model access with rbac and abac.
Compare discretionary access control (DAC) and mandatory access control (MAC), explaining owner-based versus centralized decision making. Describe how subjects and objects receive clearance levels and labels to govern access.
Choose the right access control model by combining RBAC and ABAC to enable context-aware break-glass scenarios while preserving policies, security, and audit login.
Explain governance, risk, and compliance (GRC) as the organizational framework for policies, roles, and controls, linking access models, risk management, and regulatory standards like GDPR and HIPAA.
Explore security policies, including acceptable use, data classification, and change management, and learn how these high-level policies translate into practical rules and safe change practices.
Learn how a formal change management process—raising requests, risk analysis, approvals, testing, phased implementation, documentation, and post-change review—prevents breaches like Equifax’s by avoiding unauthorized changes.
Define cyber security risk as the chance a threat exploits a vulnerability to cause harm. Learn how risk management prioritizes assets to focus protection.
Explore the universal five-stage risk management process for cybersecurity: identify risks, analyze with scores, evaluate via a risk matrix, and treat, while maintaining a risk register and monitoring controls.
Identify risks proactively by inventorying assets, assessing historical incidents, and applying audits and compliance insights, then document with a risk register and assign owners for mitigation.
Learn to analyze risks by quantifying likelihood and impact to produce a risk score, prioritizing threats using a 1–5 scale. Apply these concepts to phishing, hackers, and the risk register.
Identify risks and evaluate them with a five-by-five risk matrix that multiplies likelihood by impact to yield scores, then prioritize by category—low, medium, or critical—and adjust brackets as needed.
Treat risks by using four strategies: avoid, mitigate, transfer, and accept; assign risk owners, and implement mitigation plans with controls like RBAC, backups, and endpoint protection.
Monitor risks with risk monitoring to test security controls, detect anomalies, and stay ahead of evolving threats through log analysis, vulnerability scanning, patch and configuration management, IDS/IPS, and endpoint security.
Apply risk management concepts to a case study by identifying five explicit IT risks, evaluating them with likelihood and impact scores, and completing a risk register and risk matrix.
Explains identifying five information technology audit risks, including weak authentication, unencrypted data, insecure backups, no training, and an untested enrollment portal, via a risk register and a five-by-five risk matrix.
Learn how security controls enforce organizational policies by reducing risk through administrative, technical, and physical safeguards, including password policy enforcement, MFA, firewalls, encryption, and access control.
Explore security controls across administrative or managerial, technical or logical, and physical categories with examples like biometric authentication and security cameras; learn preventive, detective, corrective, deterrent, compensating, and recovery types.
Explore how generative ai creates new content from massive data, mimics human learning, and transforms cybersecurity through risk analysis, threat modeling, and detection rule generation.
Explore a three-step workflow using gen AI to identify ransomware: collect indicators of compromise, identify the strain, and act on encrypted files and exfiltration signals.
Practice activity guides learners to investigate a ransomware infection using IOCs, a log file, and ChatGPT prompts to identify the ransomware and possible data exfiltration to a destination IP.
Use GenAI to analyze log files for data exfiltration and identify the IP address, then prompt ChatGPT with indicators of compromise and chain-of-thought reasoning to infer ransomware such as Lockbit.
This course contains the use of artificial intelligence.
A beginner level comprehensive course that includes step-by-step explanations of core security concepts along with follow-up quizzes and hands on labs to ensure a solid learning for the course taker.
Designed by a Cybersecurity expert with a PhD degree and premium Cybersecurity certifications, this course has been designed to make it extremely simple to learn complex Cyber Security concepts. Designed for beginner Cyber Security professionals, this course will help you master the major domains and launch a successful career in the Cyber Security industry. It is also a good starting point for students targeting Cyber Security certifications like CompTIA Security+ and CEH.
Please check out our free samples videos to see how complex concepts have been explained in an easy way!
Salient features include:
Step by step and easy to follow videos that don't assume any prior knowledge
Hands on labs to develop practical skills required in jobs
Quizzes at the end of each section to test knowledge about each area
PhD instructor with 10+ years of industry experience as well as teaching experience
Sample interview questions and tips
CISSP certified instructor
30 day money-back guarantee
Domains covered:
Foundations of Cybersecurity (CIA, Security Governance, Identity Federation, Cryptography, Hashing, Digital Signatures, Data Security)
Network Security (Primer on Computer Networks, Protocols, HTTPs, TLS/SSL, VPNs, IPSec, SSH, Firewalls, NAT, Port Scans)
Cyber Attacks (Man-in-the-Middle Attack, DoS/DDoS, Password Attacks, Social Engineering, Network Attacks)
Web Application Security (Web App Architecture, SQL Injections, Blind SQL Injections, Cross-Site Scripting)
Malware (Viruses, Worms, Trojans, Spyware, Adware, Ransomware, Logic Bombs and Root kits, Anti-malware)
Incident Response and Intrusion Detection (Cyber Kill Chain, Incident Response Lifecycle, IDS/IPS, SNORT)
Network Forensics (Packet and Protocol Analysis, Wireshark, tcpdump)
Identity and Access Management Deep Dive (Access Control Models, RBAC, ABAC)
Governance, Risk and Compliance Deep Dive (Security Policies, Change Management, the 5-Step Risk Management Process)
Generative AI for Cyber Security (Using AI for Ransomware Identification)
Unlike other courses, this is a comprehensive course that covers both theory and practice.
Our 15+ hands-on labs will teach you skills which you can directly use in your job:
Practice cryptography by generating public-private keys using RSA, encrypt data using public key and decrypt using private key
Employ hashing to verify the integrity of received data by leveraging MD5 hashing algorithm
Spot phishing emails, investigate whether the links or attachments are malicious and if you should block the domain
Carry out port scanning and discover which services are running on your web server
Carry out an actual SQL injection attack on a website and learn how to prevent these attacks
Carry out a blind SQL injection attack on a website by leveraging boolean and time-base inference techniques
Write and deploy SNORT rules to monitor sensitive web access and detect intrusions
Investigate real data breaches using Wireshark, including a full corporate breach investigation
Perform network forensic investigation using tcpdump
Apply Generative AI tools to identify and analyze ransomware
This course contains promotional materials.