
Access a 35-page companion study guide in downloadable PDF form to accompany the course, and share an honest Udemy review when ready to help future students.
Define authorization and accountability in identity and access management, enforce least privileges and need-to-know, curb privilege creep, and use network, database, application, and system logs to ensure non-repudiation.
Examine how policies, standards, procedures, and guidelines shape security governance, defining organization-wide responsibilities, concrete rules, and step-by-step actions to ensure consistent security posture.
Explore GDPR, HIPAA, PCI-DSS and intellectual property protections, including PII and PHI handling, data minimization, breach reporting, encryption, access controls, and IP basics like trademarks, copyright, and patents.
After completing the lecture, please download the practice activity in the next lecture.
Practice Activity: Please try the lab first then try the Practice Activity in the next lecture.
Explore the OSI and TCP/IP protocol stacks, from application to physical layers, and learn how protocols like HTTP, TCP, IP, UDP, and TLS/SSL secure communications.
Understand how the application layer handles web pages and objects via HTTP, and how the transport layer ensures reliable TCP delivery or fast UDP.
Understand how the domain name system maps human readable names to IP addresses using a hierarchical DNS structure, UDP transmission, and globally distributed root, top level domain, and authoritative servers.
Explore the link layer, responsible for hop-to-hop delivery, and compare Mac addresses to IP addresses while seeing how transport, network, and link headers enable end-to-end routing.
Learn to use nmap to scan the 1000 common ports, identify open ports and their services, and perform stealth scans and os detection.
Set up lab and perform nmap scans to discover ports, fingerprint the operating system and kernel, and locate a secret service on a port in the 40,000 to 60,000 range.
Run the lab script to set up the environment, then use nmap to scan localhost's 1000 ports, revealing ports 22, 80, and 3006, and fingerprinting the os with -O.
Explore how NAT uses a single public IP to support thousands of internal systems, hides private addresses, and employs port address translation to differentiate connections.
Learn how firewalls defend networks as the first line of defense, using access control lists to block or allow traffic. Compare stateless and stateful designs with next-generation deep packet inspection.
Explore DNS attacks such as poisoning and spoofing, how DNSSEC uses public key cryptography to authenticate messages, and the threat of DNS reflection.
Explore social engineering and phishing, explaining how attackers exploit human psychology, employ prompts like urgency and impersonation, and how to detect and prevent these attacks through training, policies, and reporting.
Explore how web applications are architected from front end to database, and learn core security practices and the OWASP top ten vulnerabilities.
Demonstrate sql injection techniques in a lab with a lamp stack vulnerable web app, using the login page, database queries, and union-based data extraction on Kali Linux.
Explore cross-site scripting, including persistent and reflected variants, and learn how input sanitization, input validation, and secure coding practices mitigate these attacks.
learn vulnerability management as a continuous cycle of asset discovery, scanning, assessment, prioritization by business impact and exploitability, and mitigation through patching and disabling unused services.
Learn how spyware gathers data through browser hijackers, cookies, and keyloggers; see how adware injects ads; understand ransomware encryption and prevention with indicators of compromise and decryption resources.
Discover how anti malware detects and removes malware using on-demand and real-time scanning, signature and anomaly based detection, and remediation steps like isolation, patching, and backups.
Explore the cyber kill chain and how attackers progress from reconnaissance to objective. Learn passive and active reconnaissance, weaponization, delivery via phishing and USB drops, exploitation, backdoors, and command-and-control.
Trace the cyber kill chain in a real world Target incident by examining reconnaissance, weaponization, delivery, exploitation, installation, command and control, and exfiltration.
Discover snort, an open source intrusion detection and prevention system (IDPS) that inspects real-time network traffic, uses a rule-based engine, and logs and alerts for incident response.
Learn to configure snort in a Kali Linux VM and an nginx Docker container, and write alert rules for SSH port scans and ICMP ping traffic.
Explore packet and protocol analysis across the application, transport, network, and link layers, tracing how headers, ports, and addresses including DNS, TCP/UDP, and MAC addresses enable end-to-end communication.
Explore Wireshark, a free open source network packet analyzer used to detect threats, investigate incidents, and analyze traffic packet by packet; learn the UI and capture options.
Use wireshark to investigate a credentials breach by loading the credentials breach pcap ng, tracing access from Kali Linux VM to the nginx server, and confirming exfiltration via tcp stream.
Explore a realistic Acme corporate data breach with Wireshark to perform forensic investigation of network traffic, identify attack vectors, malware activity, and data exfiltration.
Compare discretionary access control (DAC) and mandatory access control (MAC), explaining owner-based versus centralized decision making. Describe how subjects and objects receive clearance levels and labels to govern access.
Define cyber security risk as the chance a threat exploits a vulnerability to cause harm. Learn how risk management prioritizes assets to focus protection.
Monitor risks with risk monitoring to test security controls, detect anomalies, and stay ahead of evolving threats through log analysis, vulnerability scanning, patch and configuration management, IDS/IPS, and endpoint security.
Apply risk management concepts to a case study by identifying five explicit IT risks, evaluating them with likelihood and impact scores, and completing a risk register and risk matrix.
Explore security controls across administrative or managerial, technical or logical, and physical categories with examples like biometric authentication and security cameras; learn preventive, detective, corrective, deterrent, compensating, and recovery types.
Explore how generative ai creates new content from massive data, mimics human learning, and transforms cybersecurity through risk analysis, threat modeling, and detection rule generation.
This course contains the use of artificial intelligence.
A beginner level comprehensive course that includes step-by-step explanations of core security concepts along with follow-up quizzes and hands on labs to ensure a solid learning for the course taker.
Designed by a Cybersecurity expert with a PhD degree and premium Cybersecurity certifications, this course has been designed to make it extremely simple to learn complex Cyber Security concepts. Designed for beginner Cyber Security professionals, this course will help you master the major domains and launch a successful career in the Cyber Security industry. It is also a good starting point for students targeting Cyber Security certifications like CompTIA Security+ and CEH.
Please check out our free samples videos to see how complex concepts have been explained in an easy way!
Salient features include:
Step by step and easy to follow videos that don't assume any prior knowledge
Hands on labs to develop practical skills required in jobs
Quizzes at the end of each section to test knowledge about each area
PhD instructor with 10+ years of industry experience as well as teaching experience
Sample interview questions and tips
CISSP certified instructor
30 day money-back guarantee
Domains covered:
Foundations of Cybersecurity (CIA, Security Governance, Identity Federation, Cryptography, Hashing, Digital Signatures, Data Security)
Network Security (Primer on Computer Networks, Protocols, HTTPs, TLS/SSL, VPNs, IPSec, SSH, Firewalls, NAT, Port Scans)
Cyber Attacks (Man-in-the-Middle Attack, DoS/DDoS, Password Attacks, Social Engineering, Network Attacks)
Web Application Security (Web App Architecture, SQL Injections, Blind SQL Injections, Cross-Site Scripting)
Malware (Viruses, Worms, Trojans, Spyware, Adware, Ransomware, Logic Bombs and Root kits, Anti-malware)
Incident Response and Intrusion Detection (Cyber Kill Chain, Incident Response Lifecycle, IDS/IPS, SNORT)
Network Forensics (Packet and Protocol Analysis, Wireshark, tcpdump)
Identity and Access Management Deep Dive (Access Control Models, RBAC, ABAC)
Governance, Risk and Compliance Deep Dive (Security Policies, Change Management, the 5-Step Risk Management Process)
Generative AI for Cyber Security (Using AI for Ransomware Identification)
Unlike other courses, this is a comprehensive course that covers both theory and practice.
Our 15+ hands-on labs will teach you skills which you can directly use in your job:
Practice cryptography by generating public-private keys using RSA, encrypt data using public key and decrypt using private key
Employ hashing to verify the integrity of received data by leveraging MD5 hashing algorithm
Spot phishing emails, investigate whether the links or attachments are malicious and if you should block the domain
Carry out port scanning and discover which services are running on your web server
Carry out an actual SQL injection attack on a website and learn how to prevent these attacks
Carry out a blind SQL injection attack on a website by leveraging boolean and time-base inference techniques
Write and deploy SNORT rules to monitor sensitive web access and detect intrusions
Investigate real data breaches using Wireshark, including a full corporate breach investigation
Perform network forensic investigation using tcpdump
Apply Generative AI tools to identify and analyze ransomware
This course contains promotional materials.