Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
GIAC Security Essentials (GSEC)
Rating: 4.2 out of 5(250 ratings)
2,447 students

GIAC Security Essentials (GSEC)

GIAC Security Essentials
Last updated 5/2023
English
EnglishJapanese [Auto],

What you'll learn

  • Understand the fundamental principles of information security and cybersecurity.
  • Develop an in-depth knowledge of security policies, procedures, and controls.
  • Learn the basics of cryptography and how to apply it to secure data.
  • Gain an understanding of different network security architectures and protocols.
  • Understand the principles of access control and its application in security.

Course content

1 section34 lectures10h 44m total length
  • Overview4:31

    Gain a broad view of security with the GSEC overview, covering password policies, monitoring, incident response, defensive and offensive security across Windows and Linux, and DoD 8570 certification prep.

  • Access Control and Password Management20:21

    Explore access control and password management concepts, including brute-force and dictionary attacks, passphrases, password policies, and multi-factor authentication for stronger system security.

  • Active Defense18:40

    Embrace proactive active defense by deploying honeypots and honey nets like OpenCanary, analyzing attacker methods, and applying techniques such as changing defaults, encryption, obfuscation, and deceptive robots.txt.

  • Contingency Plans22:50

    Explore contingency planning by analyzing business continuity and disaster recovery, including risk assessment, business impact analysis, planning, testing, and maintenance to keep critical services running.

  • Critical Controls14:03

    Explore the CIS critical security controls as a practical, prescriptive guide to strengthen cyber defense, focusing on basic, foundational, and organizational measures for any organization.

  • Basic Cryptography21:07

    Discover the basics of cryptography, from substitution and rot ciphers to symmetric and asymmetric encryption, and explore steganography techniques for hiding messages in image files.

  • Cryptography Algorithms and Deployment21:35

    Explore how cryptography uses symmetric and asymmetric encryption, hashing, and key exchange to ensure confidentiality, integrity, and authentication, with algorithms like des, aes, blowfish, rsa, and sha-256.

  • Cryptography Application25:49

    Apply cryptography to real-world scenarios by using vpn encryption to shield web traffic, and by using gpg and pki concepts with x.509 certificates and certificate authorities for secure communications.

  • Defense in Depth16:38

    Adopt a defense in depth, layered strategy that secures both digital and physical presence with multiple countermeasures, from MFA and VPN to badges, locks, CCTV, and robust patching.

  • Defensible Network Architecture18:34

    Design defensible networks from the ground up by identifying assets, conducting risk and vulnerability assessments, implementing physical security, network segmentation, dmz deployment, and continuous monitoring to keep threats at bay.

  • Endpoint Security17:22

    Explore endpoint security as an umbrella that protects laptops, desktops, and mobile devices through centralized management, antivirus, anti-malware, encryption, DLP, and firewalls, with IDS/IPS and agent-based monitoring.

  • Enforcing Windows Security15:15

    Enforce Windows security across an Active Directory by editing and linking group policy objects to OUs, configuring password policies, lockout thresholds, and security settings.

  • Incident Handling and Response17:49

    Differentiate incident handling from incident response: handling focuses on planning and communication, while responders perform the technical investigation, containment, and eradication within a NIST-aligned framework.

  • IT Risk Management20:48

    Learn IT risk management fundamentals: identify assets, classify data, perform qualitative and quantitative risk assessments using ale, sle, and aro, and implement continuous monitoring, change management, and risk appetite decisions.

  • Linux Security: Structure, Permissions, and Access22:29

    Learn the Linux file system layout, key directories, and how permissions, ownership, and access controls govern file security; practice using chmod, chown, and SSH keys to manage authentication and services.

  • Linux Hardening and Securing18:01

    Explore linux hardening and securing, including regular updates, backups, encryption, strong passwords, least privilege, disabling unnecessary services, with firewall, logging, monitoring, antivirus, and using hardening guides for CIS/SANS standards.

  • Linux Monitoring and Attack Detection21:04

    Establish baselines and monitor Linux systems for anomalies by analyzing ports and services, bandwidth, resource usage, and logs with Nmap, Darkstat, Netstat, Htop, and Snort.

  • Linux Security Utilities20:33

    Learn to harden Linux security using antivirus like ClamAV and Sophos, IDS/IPS such as Snort and Suricata, firewalls with iptables or UFW, and vulnerability scanners like OpenVAS and Nessus.

  • Log Management and SIEMs20:21

    Enable comprehensive log management and SIEM analysis to detect breaches, audit access, and troubleshoot issues across Windows event viewer, Linux /var/log, and Apache logs.

  • Common Attack Methods19:14

    Explore common attack methods, including injection attacks (code, command, SQL), denial of service and distributed denial, password attacks, man-in-the-middle, phishing, eavesdropping, ARP spoofing, and malware.

  • Mitigation Strategies19:46

    Learn practical mitigation strategies for injection attacks, denial of service, phishing, and eavesdropping, with secure coding practices, encryption, password policies, MFA, and defense in depth.

  • Network Device Security16:34
  • Network Security Devices20:22

    Learn how network security devices protect environments, focusing on firewalls, ACLs, and stateful inspection, with practical demonstrations of iptables on Linux and Windows firewall, and notes on UTMs, IDS/IPS.

  • Networking and Protocols20:40

    Delve into the OSI and TCP/IP protocol stacks, from physical and data link to application layers, and analyze TCP, UDP, IP, DHCP, DNS and HTTP/HTTPS for network connectivity and addressing.

  • Securing Windows Network Services21:26

    Secure Windows network services by using IPsec with IKEv2 for VPN tunnels, hardening IIS with authentication and SSL, and restricting remote desktop access.

  • Security Policies15:54

    Security policies provide clear guidelines, gain buy-in, align practices with the CIA triad, and define scope, exemptions, and reporting while supporting ongoing revision for evolving environments, including full disc encryption.

  • Virtualization and Cloud Security20:49

    Explore virtualization and cloud security risks, including VM sprawl, golden image misconfigurations, and unauthorized hypervisor access. Learn to strengthen access controls, multi-tenancy risks, and secure data deletion in cloud environments.

  • Web Communication Vulnerabilities17:53

    Explore common web application vulnerabilities, from CGI misconfigurations and command execution to insecure sessions and token weaknesses, and learn secure practices with cookies, JWTs, and encryption.

  • Vulnerability Scanning and Penetration Testing22:21

    Explore vulnerability scanning and penetration testing through recon, asset protection, and CIA triad concepts, learning to assess vulnerabilities, threats, and risks with automated scanners like Nessus and OpenVAS.

  • Windows Access Controls18:49

    Explore Windows access controls by mastering NTFS and share permissions, inheritance, and effective access to secure folders, files, printers, and registry settings.

  • Windows Updates24:37

    Explore how to plan, deploy, and manage Windows updates in large enterprise environments using WSUS, including domain controller setup, group policy, synchronization from Microsoft, and test vs production rollout.

  • Windows Auditing and Forensics13:34

    Audit Windows systems to detect indicators of compromise using file and system auditing, alternate data streams, and recovery tools, then investigate incidents with forensics tools like Autopsy to preserve evidence.

  • Windows Security Infrastructure18:54

    Manage Windows security infrastructure by distinguishing desktop and server editions, implementing local and Active Directory accounts, and organizing permissions with groups and policy controls to enforce least privilege.

  • Wireless Network Security15:28

    Explore wireless network basics, including 802.11 standards, 2.4 GHz and 5 GHz bands, and secure practices like WPA2, WPA, MAC filtering, and guarding against rogue access points and evil twins.

Requirements

  • There are no specific prerequisites for taking the GIAC Security Essentials (GSEC) course, although it is recommended that learners have a basic understanding of information technology concepts, such as networking, operating systems, and databases. Additionally, a basic understanding of cybersecurity principles and practices would be helpful, although it is not required.
  • To be eligible to take the GIAC Security Essentials (GSEC) certification exam, learners must have completed the GSEC course or have equivalent knowledge and experience in information security. GIAC recommends that learners have at least two years of experience in information security or a related field before attempting the certification exam.

Description

GIAC is a registered trademark of the Escal Institute of Advanced Technologies, Inc. SANS is not affiliated with these courses. GIAC has been an industry leader in information security certifications for years. The GIAC Security Essentials (GSEC) is designed for Security Professionals who want to demonstrate that they are qualified for IT systems hands-on roles with respect to security tasks. GSEC is one of the DoDD Approved 8140 / 8570 Baseline Certifications for IAT Level II.

The GIAC Security Essentials (GSEC) Course is designed to provide learners with a comprehensive understanding of information security and the core concepts, principles, and practices of cybersecurity. The course covers a wide range of topics, including network security, access control, cryptography, risk management, and incident response.

The course is aligned with the GIAC Security Essentials (GSEC) certification, which is a widely recognized certification in the cybersecurity industry. The GSEC certification validates the learner's knowledge and skills in information security and demonstrates their ability to identify and mitigate security risks.

Throughout the course, learners will have access to hands-on labs and exercises designed to reinforce the concepts covered in the lectures. They will learn how to use common cybersecurity tools, such as vulnerability scanners and intrusion detection systems, to identify and mitigate security risks.

Other topics covered in the course include security policies, security architecture, network protocols, and secure software development. The course also covers the legal and ethical aspects of cybersecurity, including compliance requirements and privacy regulations.

Upon completion of the course, learners will have a deep understanding of information security and the skills needed to identify and mitigate security risks. They will be prepared to take the GIAC Security Essentials (GSEC) certification exam and pursue a career in cybersecurity.

Who this course is for:

  • IT professionals who want to gain a comprehensive understanding of cybersecurity concepts, principles, and practices.
  • Security professionals who want to expand their knowledge of cybersecurity and gain practical skills in identifying and mitigating security risks.
  • Network administrators who want to learn how to secure networks and systems.
  • System administrators who want to learn how to implement and maintain secure systems.
  • Auditors and compliance professionals who need to understand cybersecurity requirements and regulations.
  • Anyone who is interested in pursuing a career in cybersecurity and wants to gain a solid foundation in information security concepts and principles.