
Explore risk-based information security using frameworks like nist and ffiec, and map detections with the cyber defense matrix and Mitre att&ck techniques.
Adopt five principles of threat based security using behavioral methodology to detect post-compromise activity and evolving adversaries. Develop accurate threat models, iterate by design, and test in realistic production networks.
Explore how denial-of-service traffic floods overwhelm networks from many sources using TCP/IP, HTTP, and HTTPS, distinguishing legitimate traffic from attacks, with ports 80 and 443 and TLS/SSL protection.
Identify web security techniques within an attack-model framework that links adversary tactics to legitimate system functions, such as remote execution and scheduled tasks, to detect post-compromise behavior.
Explore the OSI reference model and its seven-layer architecture, including how layers, data flow, and protocols enable secure, structured communication and troubleshooting across networks.
Explore the OSI layer network model, focusing on the physical, data link, network, and transport layers, and how data is encapsulated and transmitted to support troubleshooting across the layers.
Examine how OSI layers 5–7 and TCP/IP model handle session management, presentation tasks such as data compression and encryption, and application protocols including file transfer, email, and remote login.
Define cloud computing per NIST as on-demand, network-accessible resources pooled for rapid provisioning with minimal management, covering SaaS, PaaS, IaaS, and deployment models public, private, hybrid, community.
cloud systems meter resources like storage, bandwidth, and active user accounts, providing transparency for providers and consumers; elasticity, virtualization, and pay-per-use models drive scalable, simple, cost-efficient expansion.
Learn how platform as a service (PaaS) enables multi-language development, scalable hosting, and reduced vendor lock-in, while software as a service (SaaS) offers pay-per-use access with minimal infrastructure management.
Explore cloud deployment models private, community, public, and hybrid, plus roles such as cloud administrator and cloud architect, highlighting security, scale, and cost benefits.
Explore cloud risks and risk management, identifying, assessing, mitigating, and monitoring risks to protect assets. Learn to evaluate risk appetite, before migrating, and secure access and data.
Explore cloud risk concerns, including governance loss, negotiated SLAs, uptime commitments, and cost implications, and assess regulatory compliance, audits, transparency, and data protection practices across federated clouds.
Classify data and assign rights, store with access controls and encryption, monitor usage, enforce permissions, and manage archiving, destruction, and auditing cloud APIs to avoid vendor lock-in and ensure portability.
Address malicious insider threats in cloud security by defining roles, background checks, NDAs, separation of duties, and job rotation; tackle legacy apps and hybrid cloud risks.
Identify cloud assurance through regulatory laws and standards, including ISO 27001/27017/27018 and federal security assessment programs, and study the Notorious Nine cloud threats like data breaches and insecure interfaces.
Learn how cloud data loss jeopardizes data integrity and compliance, and apply controls such as data governance, encryption and key management, access policies, two-factor authentication, incident response, and secure interfaces.
Mitigate malicious insider risks by enforcing independent third-party audits, clear ownership, handling and labeling policies, background checks, and strict access controls across cloud and on-premises environments.
Evaluate cloud migration with due diligence through risk assessments and baseline requirements. Implement defense-in-depth across data security, compliance, and multi-tenant vulnerabilities in IaaS, PaaS, and SaaS.
Create policies, set scan targets, launch scans, and read results with vulnerability severities from critical to low, then apply patches in the nessus simulation.
Observe dynamic mac address table entries and ARP behavior, examine who has requests, and learn the three-way handshake while generating traffic and capturing packets with a tcap dump.
Configure and verify a trunk on the designated interface, using show commands to confirm trunk status, then validate gateway reachability between switches, routers, and virtual machines with ping tests.
Analyze network traffic with Wireshark by capturing communications between Windows and Linux VMs, observe pings, UDP traffic, the three-way handshake, and resolve IP and MAC addresses.
The IT Security Gumbo, ties in Web Application Vulnerability Management, The OSI Model and Cloud Security into a delicious course meal. The course gets into detail on the respective subject matter and gives a extensive tie on how they all work together. The course is geared towards all levels of IT Professionals.