Certified: The CISSP Audio Course

Certified: The CISSP Audio Course

By Dr. Jason EdwardsTechnologyEducationCourses
Download on the App Store

Certified: The CISSP Audio Course episodes

  • Episode 71: Authentication Factors and Methods

    Authentication is the process of verifying identity, and it forms the first line of defense in access control. In this episode, we explore the different authentication factors: something you know (passwords, PINs), something you have (tokens, smart cards), something you are (biometrics), somewhere you are (location), and something you do (behavioral patterns). We also examine common authentication methods, including single-factor, multi-factor, and risk-based authentication. Understanding how these factors work—individually and in combination—is essential for designing secure systems and passing CISSP exam questions that deal with identity assurance.

    17 min
  • Episode 70: DDoS Protection and High Availability Networks

    Distributed Denial of Service (DDoS) attacks are designed to overwhelm systems and take down critical services. In this episode, we explain how these attacks work—volumetric, protocol, and application-layer—and the techniques used to defend against them. You’ll learn about scrubbing centers, rate limiting, traffic shaping, and the role of content delivery networks in mitigation. We also explore how to design high-availability network architectures with redundancy, failover, and load balancing to ensure service continuity even under stress. CISSPs must be equipped to anticipate, prevent, and recover from large-scale disruption events.

    19 min
  • Episode 69: Cloud Network Security (CASB, SASE, Virtual Firewalls)

    As more organizations move to the cloud, network security must evolve. This episode focuses on cloud-native controls including Cloud Access Security Brokers (CASB), Secure Access Service Edge (SASE), and virtual firewalls. You’ll learn how these tools provide visibility, policy enforcement, data loss prevention, and threat protection across hybrid and multi-cloud environments. We also cover identity-based access control, cloud segmentation, and encryption in transit. With cloud services extending beyond traditional boundaries, CISSPs must adopt new strategies to maintain consistent and scalable network protections.

    19 min
  • Episode 68: Content Delivery Networks and Edge Security

    Content Delivery Networks (CDNs) accelerate access to web content by distributing it across global edge nodes, but they also introduce new attack surfaces. In this episode, we discuss how CDNs work, their role in performance optimization, and the security challenges they present, such as cache poisoning, misconfigured access controls, and DDoS targeting. We also explore edge computing security—protecting data and services closer to the end user. CISSPs must understand how to secure the entire content delivery path, from cloud origin to user browser, while balancing speed, scalability, and control.

    19 min
  • Episode 67: Zero Trust and Software-Defined Networking (SDN)

    Zero Trust has emerged as a powerful model for modern cybersecurity, shifting the focus from perimeter defenses to granular, identity-centric control. In this episode, we explain the principles of Zero Trust—never trust, always verify—and how it’s implemented using continuous authentication, microsegmentation, and least privilege access. We also explore Software-Defined Networking (SDN), a framework for dynamically managing and securing network resources through centralized controllers. Together, Zero Trust and SDN provide the flexibility and control needed for cloud-first, hybrid, and highly distributed environments.

    18 min
  • Episode 66: Network Monitoring and Traffic Analysis

    Continuous monitoring and traffic analysis are essential for detecting threats, performance issues, and policy violations. In this episode, we explore tools and techniques used to observe network behavior in real time. Topics include flow monitoring, deep packet inspection, NetFlow, and behavioral analytics. You’ll also learn about the role of Security Information and Event Management (SIEM) in aggregating data and generating actionable alerts. By understanding normal traffic patterns, CISSPs can more effectively detect anomalies, trace intrusions, and support forensic investigations. Monitoring is not optional—it's the pulse of your security operations.

    18 min
  • Episode 65: Network Address Translation and Proxy Usage

    NAT and proxy servers play important roles in hiding internal IP addresses, enforcing access policies, and controlling traffic flow. In this episode, we explore how Network Address Translation (NAT) works to conserve IP space and obscure internal architectures. We also explain how proxies—forward, reverse, and transparent—support web filtering, anonymization, caching, and load balancing. You’ll learn how to implement these technologies securely, monitor their usage, and avoid common pitfalls. CISSPs must understand how to integrate NAT and proxy mechanisms into broader network defense strategies.

    18 min
  • Episode 64: VOIP and Secure Communication Channels

    Voice over IP (VOIP) technologies have replaced traditional telephony in many organizations, but they come with their own set of security concerns. This episode explores the architecture of VOIP systems and the threats they face, including call interception, eavesdropping, spoofing, and denial-of-service attacks. We also cover secure communication protocols such as SRTP, SIPS, and encrypted signaling mechanisms. You’ll learn how to harden VOIP infrastructure, apply access controls, and monitor for anomalies. CISSPs must be prepared to evaluate communication channels not just for functionality, but also for confidentiality and integrity.

    16 min
  • Episode 63: Wireless Network Security (WEP, WPA2/3, 802.1X)

    Wireless networks present a unique set of vulnerabilities due to their reliance on open air transmission. In this episode, we examine wireless security protocols and controls, including WEP, WPA2, WPA3, and 802.1X. We explain how authentication frameworks, encryption standards, and access controls protect against threats like rogue access points, packet sniffing, and brute-force attacks. You’ll also learn about secure SSID broadcasting, segmentation, and signal isolation. Securing wireless environments is a critical task for CISSPs, especially as more enterprise traffic shifts to mobile and remote connections.

    18 min

About Certified: The CISSP Audio Course

From the publisher's feed

Welcome to The Bare Metal Cyber CISSP Audio Course—your comprehensive companion for mastering the Certified Information Systems Security Professional (CISSP) certification. Built for serious cybersecurity professionals and aspiring leaders alike, this Audio Course transforms the eight domains of the CISSP Common Body of Knowledge into clear, structured, and engaging lessons you can learn anytime, anywhere. Each episode blends real-world context, expert insight, and exam-focused explanations to help you understand not just what to study, but how to think like a security professional. Whether you’re commuting, exercising, or studying after work, this series provides the clarity and direction you need to stay motivated and on track.