
Discover why cybersecurity protects sensitive information and safeguards business continuity in the digital world, and gain a solid baseline of skills through enterprise cybersecurity and best practices.
Master cybersecurity fundamentals for cloud and virtualization, covering NIST, CISA, data life cycle, and IAM. Prepare for the certification via domains: security principles, access controls, network security, and incident response.
ISC2 certified in cybersecurity crash course offers a vendor-neutral, entry-level overview of the free, two-hour, 100-question exam, plus logistics, scoring, and post-certification steps.
Explore the ISC2 cybersecurity crash course exam domains and objectives. Learn key concepts such as information assurance, CIA triad, ethics, governance, continuity, access controls, networking, and security operations.
Meet instructor Joe Holbrook, CEO of Tech Commanders in Jacksonville with 20+ years in IT, Navy veteran, and certifications including ISC2 Certified in Cybersecurity, CCSP, CompTIA, and Google Cloud security.
download the free course materials, including the presentation, ebooks, and graphics, then proceed to the next lesson.
Explore domain 1 overview of security principles, covering information assurance concepts, authentication and authorization, CIA triad, risk management, controls, identity and access management, code of conduct, and governance policies.
Explore information assurance concepts through the CIA triad, authentication and authorization, non-repudiation and privacy, and password security with multifactor authentication.
Master the CIA triad: confidentiality, integrity, and availability, and see how encryption, authentication methods, hashing checksums, disaster recovery, and redundancy secure a well-documented IT security posture.
Explore authentication, authorization, and accountability—the triple A—including passwords, OTP, and MFA, using the concepts of something you know, have, or are, with logging and least privilege.
Explore non-repudiation and privacy in cybersecurity, linking digital signatures and key pairs to user verification, while examining privacy rights, data risks, and compliance considerations.
Enforce password security with a policy, password management, and multi-factor authentication, following NIST guidance on composition and management, hashing and salting, and biometrics or access cards with a chip.
Explore multifactor authentication for cloud and on-prem deployments, with a focus on AWS MFA best practices. Learn about OTPs, text messages, Google Authenticator, FIDO keys, virtual authenticators, and hardware tokens.
Understand the risk management process by defining risk management and identifying concerns about handling risk, then explore risk identification, assessment, and treatment.
Master risk management fundamentals by applying the risk formula—likelihood times vulnerability scoring times the impact—and examining how assets, threats, and vulnerabilities shape RMF decisions.
Learn risk identification, assessment, and treatment in cybersecurity, exploring risk registers, four response options—accept, avoid, reduce, transfer—and qualitative and quantitative prioritization.
Explore the three security control types—technical, administrative, and physical—and learn how to implement them to manage access in cloud and IT environments, with an AWS IAM demonstration.
Explore technical and logical controls, including encryption, salting passwords, and access methods, and learn how preventive, detective, corrective, deterrent, and compensating measures reduce organizational risk.
Administrative controls, or paperwork-style workflows, mitigate risk through policies and training, including acceptable use policies, advisories, guidelines, security policies, and BYOD and password policies.
Explore physical controls as the third type of security controls, featuring gates, fences, guards, cameras, and proximity readers, and understand their preventive and deterrent roles in the data center.
Explore AWS access controls across regions and zones, and apply IAM, bastion hosts, NAT, and VPNs to enforce secure access and governance with acceptable use policies.
Demonstrates how to manage AWS access controls with IAM, user groups, policies, and MFA options, then apply permission sets and identity center for least-privilege security.
Explore the ISC2 code of ethics in section 1.4, identifying its core principles and applying ethical guidelines to cybersecurity practice.
Explore the Isc2 code of ethics, its preamble and four canons, and how certified information security professionals must protect society, serve principals, and report misconduct.
Explore governance processes by defining policies, procedures, standards, and regulations, and apply security policy best practices, reinforced with a module review and practice questions.
Explore how governance shapes an organization’s approach with multiple frameworks, then distinguish policies, procedures, standards, and regulations and how they drive compliance across industries.
Identify that security policy is an umbrella comprising multiple policies, such as data privacy, acceptable use, and bring your own device, guiding governance and encryption-focused controls for CIA triad compliance.
Domain one review covers the CIA triad and core concepts—authentication, authorization, accountability—plus access control models, non-repudiation, encryption, risk identification and treatment, and governance frameworks.
Explore domain one review questions on authentication methods, something you know, something you have, and something about you, along with security controls, risk treatment, governance elements, and non-repudiation.
Explore business continuity, disaster recovery, and incident response concepts, with emphasis on their importance and high-level application in real environments.
Explore business continuity, define a business continuity plan and its components, and dive into a lesson on business continuity and doctor planning.
Learn how to sustain operations during outages through business continuity planning. A business impact analysis defines scope, schedule, success criteria, and acceptance requirements to understand outage costs and recovery timelines.
Identify the components of a business continuity plan, perform a business impact analysis to assess critical processes, and align with RTO/RPO targets, contingency planning, and recovery resources.
Understand what disaster recovery is and learn the main terminology used in disaster recovery. Examine important metrics, including RTO and RPO.
Learn disaster recovery concepts and planning to keep critical services available after outages, covering DRP, fault tolerance, failover, geo clustering, spof, and KPIs like RTO and MTTR.
Learn how RPO and RTO set data loss tolerance and outage recovery targets. Understand how to balance impact, cost, and bandwidth between primary and secondary sites using BIA.
Explore business response and incident response, and how organizations handle a specific incident, with a module review summary and review questions.
Explore incident response per the NIST guide, covering preparation, detection and analysis, containment, eradication and recovery, and post-incident activity with policy and an IR team.
Review post-incident activity to identify what happened, how to prevent it, and what lessons learned to implement with forensics, legal hold, chain of custody, and NIST remediation practices.
Review disaster recovery, DRP planning, and continuity of operations, including business continuity, BIA, and NIST incident handling lifecycle with evidence handling and chain of custody.
Explore key cyber resilience concepts through module two review questions, identifying BIA, RTO, RPO, DRP, and lessons learned in incident response and business continuity.
Explore module three access control concepts, contrasting physical and logical access controls and their real-world examples to reinforce cybersecurity fundamentals.
Explore physical access controls, define defense in depth, and examine physical control types and monitoring controls.
implement defense in depth through layered physical, administrative, and technical controls. apply this to data centers and cloud iam with doors, swipe access, logbooks, and cameras.
Compare physical control types to design defense-in-depth security. Use cameras with motion sensors, guards or dogs, and biometrics such as fingerprints.
Discuss monitoring controls in data centers using logbooks and electronic records, entry logging with swipes, proximity fobs, biometrics, and anomaly logging with two-year retention.
Describe logical access controls, including the principle of least privilege and separation of duties, and review key concepts through a module summary and practice questions.
Explore logical access controls, defining subjects, objects, and rules, and examine models such as DAC, MAC, RBAC, and ABAC, plus practical examples of policy-driven permissions.
The principle of least privilege guides provisioning the right permissions for each user or service. It reduces security risks, scope creep, data leaks, and compliance concerns.
Segregation of duties requires two or more people to oversee key tasks, reducing fraud and identifying breaches in financial and government environments, with Sarbanes-Oxley and GLBA guidance.
Explore how row level security and column level security enforce fine-grained access in data warehouses, using RBAC policies to restrict student data by region or role.
Watch a practical demonstration of cloud identity and access management in aws, provisioning users, groups, and policies for amazon redshift access, with attention to secure permissions and governance.
Explain defense in depth as a strategy. Identify physical, technical, and administrative controls with examples like guards, data policies, and access policies, including discretionary access control and role-based access control.
Apply defense in depth with physical, technical, and administrative controls, and enforce separation of duties and least privilege while using role-based access controls for privileged vs regular accounts.
After you pass the ISC2 exam, pay a $50 annual maintenance fee, complete 45 continuing education hours, then accept and download your Credly badge to share on LinkedIn.
Explore security principles and information assurance concepts, including authentication, authorization, and the CIA triad. Examine risk management, controls, identity and access management, code of conduct, and governance policies.
Explore information assurance concepts by focusing on the CIA triad, authentication and authorization, non-repudiation and privacy, and password security with multifactor authentication.
Develop secure network designs through structured planning, segmentation, DMZs, vulnerability scanning, defense in depth, and careful hardware, software, and cloud tool selection.
Explore network security in hybrid environments, linking on premise systems to cloud services via VPN, NAT, and bastion hosts, with zero trust and defense in depth.
Explore network protocols and ports, defining a port as a virtual connection point and focusing on well-known ports like 22 for SSH, 25 for SMTP, and 23 for Telnet.
Demonstrates Amazon virtual private cloud concepts, navigates the VPC dashboard and wizard, and configures private isolated networks with subnets, gateways, and security groups for security and compliance.
Explore section 4.2 on network threats, covering threat types, threat actors, and tools to identify and prevent them, plus a whiteboard discussion of DDoS attacks.
Identify ddos, beaconing malware, rogue devices, and irregular p2p threats, and learn to mitigate with load balancing, traffic blocking, malware protection, and hids/nids plus port controls.
Identify threat actors such as script kiddies, insiders, and nation states, and risks they pose. Mitigate with data loss prevention, multi factor authentication, role based access, auditing and zero trust.
Identify and prevent threats by using packet capture, log analysis, endpoint security, DNS tools, file analysis, and sandboxing; understand IDS/IPS types: signature-based, behavior-based, and anomaly-based.
Discusses how distributed denial of service attacks occur through infected machines, and how autoscaling can mitigate DDoS by adding more nodes to keep web services accessible.
Design network security infrastructure for on-premise and cloud. Cover data center design, cloud service and deployment models, managed service providers, the shared security model, zero trust, and secure network design.
Explore on premise architecture and how virtualization enables private data centers with virtual machines and a hypervisor, integrated with the enterprise network.
Explore data center design with a focus on Google Cloud's approach to efficiency, hot and cold rows, color-coded cabling, fire protection, and robust monitoring, HVAC, and power distribution.
Explore cloud architecture across major providers such as Google Cloud, Azure, and Salesforce, and how on-demand self-service, resource sharing, and elasticity enable SaaS, PaaS, and IaaS deployments.
Managed service providers offer tailored IT support for small to midsize businesses, enabling core focus by outsourcing infrastructure. They provide direct support, project management, and upgrades with compliant professionals.
Explore SLAs between cloud customers and providers, detailing uptime, support, and maintenance responsibilities. See how AWS EC2 compute SLAs set region-based metrics and credits, plus how to claim them.
Explore the shared responsibility model in cloud security, showing how providers like AWS handle compute and infrastructure, while customers manage IAM, provisioning, and password policies.
Explore the zero trust security model, focusing on continuous verification and reauthentication to limit blast radius, automate authentication, and protect networks and data.
Explore virtualization basics, hypervisors, and how software layers enable many virtual machines on a single host, then cover SaaS, IaaS, PaaS, public/private/hybrid/community deployment models, MSPs, SLAs, and zero trust.
This module review covers network security concepts, including hacktivist motives, cloud service models (IaaS, PaaS, SaaS), elasticity versus scalability, and defense tools like IPS to mitigate DDoS threats.
Explore module five security operations, where you learn data security, system hardening, best practices, and security awareness training to strengthen cybersecurity fundamentals.
Understand data security fundamentals, including handling and deleting data, encryption implementation, and security compliance across regulations and frameworks, with a demonstration of logging and monitoring.
Explore data security fundamentals, including interoperability, portability, SaaS data, and data roles; learn the cloud data lifecycle from create to destroy, with encryption, access control, IRM, and DLP.
Explore data retention and deletion for cloud services, aligning retention with governance and archive policies, applying encryption and deletion methods such as random data overwrites and cryptographic shredding.
Explore how encryption converts plaintext to ciphertext using symmetric and asymmetric keys, and see how disk encryption differs from public key cryptography in secure messaging via PKI.
Acquire practical understanding of data security compliance across major frameworks such as Bazel two, Glba, Hipaa, Fisma, Pci, and Gdpr, and learn to consult counsel to avoid penalties for non-compliance.
Explore system hardening, its importance, and practical application, and examine how configuration management supports secure system posture.
Explore system hardening to reduce the footprint by applying patches and updates to operating systems, virtual machines, and software, then secure file systems with permissions, encryption, and file integrity monitoring.
Learn how configuration management, with five steps—plan and identify, version control and baseline, change control (change management), configuration status accounting, and audits and reviews—ensures a consistent information technology environment.
Explore best practices for security policy, examine common security policies, and demonstrate an AUP and a privacy policy to reinforce understanding.
Explore common security policies designed to minimize risk, including acceptable use, data handling, password, privacy, change management, and bring your own device policies, vital for ISC2 cybersecurity exam prep.
Demonstrate how an acceptable use policy defines purpose and acceptable information technology usage, detailing templates, data security, social media, privacy, and BYoD, plus access management and password requirements.
Review how privacy policies declare data handling, including what is collected, how it’s stored, cookies and analytics, and user rights to access or delete information.
Explore security awareness training and social engineering, then detail the certification process, exam signup, and how to obtain your certificate and badge along with the course summary review.
Explore security awareness training (SAT) and its role in clarifying acceptable use, safeguarding information, and building skills through education, training, and awareness activities within a formal program.
Explore social engineering tactics like phishing, pretexting, and baiting, spot red flags, avoid clicking links, and protect accounts with up-to-date software, strong passwords, and a password manager.
Review functional security requirements and the owner, custodian, steward, and processor data roles across the cloud data life cycle from create to destroy, including OS hardening and Eskom risk management.
Test your knowledge on data lifecycle phases, BYOD policies, system hardening to reduce attack surface, GDPR personal data, and disk encryption with symmetric keys.
After passing the exam, pay a $50 annual maintenance fee, complete 45 hours of continuing education, then accept and share your Credly badge to finalize ISC2 certification.
The demand for IT security professionals has been exponentially growing year over year and becoming an IT Security Professional can really elevate your potential career opportunities.
Obtaining a certification in Cybersecurity from ISC2, CompTIA or other vendor can be a valuable investment in your career, providing you with the skills, knowledge, and recognition needed to succeed in this rapidly growing field.
Did you know in Oct 2023, the average salary for a Security Analyst was $84,753 dollars per year in United States according to Glassdoor?
Once you complete this cybersecurity course you will be on the way to planning your own specific IT security career path to follow as well as preparing for cybersecurity certifications.
Let us help you get enabled as an IT security professional, so what are you waiting for?
Let us get started!
Join this Digital Crest Institute cyber security course now and elevate your career opportunities!
Certified in Cybersecurity Certification Crash Course
Course Overview
Want to obtain a Cybersecurity Certification for your job or you want to land a job in Cybersecurity? Then join in on this course today.
Demonstrate your foundational knowledge of cybersecurity essentials and gain a competitive edge in the industry.
This industry leading cybersecurity certification validates your understanding of network security, industry terminology, and essential security operations.
As an entry-level or junior-level professional, you'll be equipped with the skills to implement best practices, policies, and procedures. Join the ranks of cybersecurity professionals and embark on a rewarding career path.
The demand for security professionals is growing and the areas of expertise companies are looking to hire security professionals in is also changing.
Learning about enterprise cybersecurity and best practices is not just important for IT professionals or security specialists. It is a valuable skill for anyone who wants to protect sensitive information, safeguard business continuity, build trust, and navigate the increasingly digital world safely.
Cybersecurity is a rapidly growing field with a high demand for skilled professionals. Learning about enterprise cybersecurity and best practices can enhance your resume and increase your job prospects in various industries
The Certified in Cybersecurity Certification Crash Course has been designed to provide you with the knowledge needed to prepare and pass the certification exam from ISC2
What is covered in the course?
In Domain 1: Security Principles are covered:
1.1 Understand the security concepts of information assurance
1.2 Understand the risk management process
1.3 Understand security controls
1.4 Understand ISC2 Code of Ethics
1.5 Understand governance processes
In Domain 2: Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts are covered:
2.1 Understand business continuity (BC)
2.2 Understand disaster recovery (DR)
2.3 Understand incident response
In Domain 3: Access Controls Concepts are covered:
3.1 Understand physical access controls
3.2 Understand logical access controls
Course includes a free study guide with practice questions to help you prepare and pass the certification.
Who is the target audience?
The course is for anyone looking to understand the fundamentals of enterprise cybersecurity practices.
Anyone preparing to take the Certified in Cybersecurity Certification
What You'll Learn in the course:
We cover all the domains and objectives that are covered in the certification exam.
What are the top areas of concern for enterprises around cyber security?
Identify the risks with potential vulnerabilities
What are the risks that enterprise can face from a cyber security perspective.
How to prepare for the ISC Certified in Cybersecurity certification exam.