Sec Guy

Sec Guy

Download on the App Store

Sec Guy episodes

  • CompTIA Security+ SY0-801: 1.1 Security Concepts and Controls

    If you are preparing for your CompTIA Security+ SY0-801 certification, throw away the idea of memorizing vocabulary just to pass a test. In the real world, enterprise security is about reasoning through decisions, understanding architectural tradeoffs, and knowing exactly what happens when a control fails.

    In this module, Sec Guy breaks down Objective 1.1: Security Concepts and Controls. We dismantle the outdated "castle and moat" strategy and build a modern Defense in Depth architecture. You will learn how to apply the CIA Triad, govern access with the AAA Framework, implement Zero Trust principles, and deploy the exact categories and types of security controls required to defend a modern enterprise.

    Rersources:

    πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide

    πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org

    πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord

    πŸ’» Practice Test: https://secguy.org

    In this episode:

    00:00 – Introduction: The Perimeter is Dead & Defense in Depth

    01:32 – The CIA Triad: Confidentiality, Integrity, and Availability

    03:38 – Governing Access: The AAA Framework (Authentication, Authorization, Accounting)

    05:53 – Limiting the Blast Radius: Least Privilege & Zero Trust Architecture

    07:11 – Security Controls: The 4 Categories (Technical, Managerial, Operational, Physical)

    09:01 – Security Controls: The 6 Types (Preventive, Deterring, Detective, Corrective, Compensating, Directive)

    Original Sec Guy video: https://www.youtube.com/watch?v=sEKQuOfkKpk

    12 min
  • CompTIA Security+ SY0-801: 2.1 Threat Intelligence & Vulnerability Priority

    In enterprise security, you cannot defend against an adversary you do not understand. Today, we begin Domain 2 with Lesson S8-006: From Threat Intelligence to Vulnerability Priority for the CompTIA Security+ (SY0-801).

    Sec Guy breaks down the definitive difference between a threat (the force that exploits) and a vulnerability (the weakness in the system). You will learn how to consume intelligence across the entire threat lifecycle using Open-Source Intelligence (OSINT), Proprietary Threat Feeds, and Dark Web monitoring to determine an attack's Likelihood and Impact. We also deconstruct the Common Vulnerability Scoring System (CVSS) and explain why relying solely on a Base Score is an operational failure. You will learn how to apply Temporal and Environmental scores to inject actual business context into your patching strategy.

    Resources

    πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide

    πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org

    πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord

    In this episode:

    00:00 – The SWAT Analogy: Prioritizing the Enterprise Response

    01:00 – Threat vs. Vulnerability: Defining the Incident

    01:50 – Intelligence Sources: OSINT, Proprietary Feeds, and the Dark Web

    02:45 – The Math of Risk: Likelihood vs. Impact

    04:00 – Quantifying Weaknesses: CVEs and CVSS Mechanics

    04:50 – Breaking Down CVSS: Base, Temporal, and Environmental Scores

    06:30 – The Junior Analyst Trap: Why You Must Apply Business Context

    07:45 – LAB-S8-004: The Threat-Priority Board Workshop

    Original Sec Guy video: https://www.youtube.com/watch?v=FfHfyzz71Sc

    8 min
  • CompTIA Security+ SY0-801: Domain 1 Mastery Workshop

    Theory without execution is useless in enterprise cybersecurity. In this Domain 1 Mastery Workshop for the CompTIA Security+ (SY0-801), you step into the shoes of the Lead Security Architect for a national healthcare processing network facing a critical Friday morning crisis. When infrastructure engineers submit an emergency Change Advisory Board (CAB) request to overhaul the patient billing portal, junior analysts see a standard business request, but an experienced architect spots an architectural minefield.

    Sec Guy guides you through dissecting the proposal’s catastrophic failures: missing impact analyses, absent backout plans, bypassed inspection proxies, deprecated MD5 hashing without salt, self-signed wildcard certificates, and unencrypted internal synchronization tunnels. You will learn not only how to reject a reckless deployment, but how to re-engineer the entire system using Enterprise PKI, mutual TLS 1.3, tokenization, Zero Trust identity, and automated rollback triggers, concluding with an executive briefing that proves business value to the CIO and CRO.

    Resources

    πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide

    πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org

    πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord

    In this episode:

    00:00 – Domain 1: From Theory to Execution

    00:25 – The Scenario: Lead Security Architect

    00:30 – The Emergency Change Request: Three Hidden Risks

    01:00 – Don't Approve the Ticket: Analyze the Risk

    01:20 – No Impact Analysis, No Approval: Managerial Control Failures

    01:43 – Backout Protects Availability: The Missing Rollback Plan

    02:11 – No Inspection Means No Visibility: Eliminating Detective Controls

    02:41 – Internal Does Not Mean Trusted: Violating Defense in Depth

    03:02 – Reject the Risk, Rewrite the Plan

    03:17 – Open the Design Packet: Follow the Failure Path

    03:32 – One Wildcard Key: Cluster-Wide Risk

    03:43 – Never Disable Certificate Validation: On-Path Vulnerabilities

    04:15 – Limit the Key's Blast Radius: Enforcing Least Privilege

    04:37 – MD5 + No Salt = Credential Failure

    05:11 – Slow KDF & Unique Salting Architecture

    05:33 – Encrypt Internal Traffic: TLS 1.3 & Forward Secrecy

    06:20 – Shared Admin Means No Accountability: AAA Breakdown

    06:55 – Repair the Architecture: The Remediated Blueprint

    07:13 – One Service, One Certificate: Enterprise PKI & OCSP Stapling

    07:33 – Zero Trust Identity: Phishing-Resistant MFA & Jump Hosts

    08:05 – Layered Data Protection: AES-256 & Tokenization

    08:38 – Governed Pipeline: Test, Snapshot, Verify, Rollback

    09:13 – Executive Briefing: Translating Security to the CIO & CRO

    10:05 – Outro & Preparing for Domain 2

    Original Sec Guy video: https://www.youtube.com/watch?v=twkmTT7nq9U

    11 min
  • CompTIA Security+ SY0-801: 1.3 Cryptographic Solutions & Trust Engine

    In modern enterprise security, cryptography is not an academic math drill; it is the trust engine that enforces identity, proves integrity, and secures multi-cloud environments. In this module, Sec Guy breaks down Objective 1.3: Cryptographic Solutions and the Trust Engine for the CompTIA Security+ (SY0-801). We demystify the difference between one-way integrity (hashing, salting, and rainbow table mitigation) and two-way confidentiality (symmetric vs. asymmetric encryption). You will master how Transport Layer Security (TLS) combines the speed of AES with the key-exchange power of RSA and ECC, how digital signatures mathematically enforce non-repudiation, and how enterprise Public Key Infrastructure (PKI) maintains the root of trust across Certificate Authorities (CAs), CRLs, and OCSP stapling. We also detail dedicated hardware root of trust implementations including TPMs, HSMs, and secure enclaves.

    Resources

    πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide

    πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org

    πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord

    In this episode:

    00:00 – Hashing vs. Encryption: Integrity vs. Confidentiality

    02:10 – Collision Attacks, SHA-256 & Salting Passwords

    04:15 – Obfuscation Techniques: Steganography, Tokenization & Masking

    06:40 – Symmetric vs. Asymmetric: AES, RSA, and Elliptic Curve Cryptography (ECC)

    09:20 – Hybrid Encryption & The TLS Handshake

    11:35 – Public Key Infrastructure (PKI), Root CAs & Certificate Lifecycles

    13:50 – Certificate Revocation: CRLs vs. OCSP Stapling

    15:40 – Digital Signatures & Non-Repudiation Architecture

    Original Sec Guy video: https://www.youtube.com/watch?v=tV1AnMYSBbw

    20 min
  • CompTIA Security+ SY0-801: 2.3 Message, Image, Attachment, Browser, and Human Vectors

    When the network is breached, a technician reacts with panic, but an executive reacts with a playbook.

    In this module, Sec Guy breaks down Objective 4.7: Incident Response and Forensics. Using the Salt Typhoon telecommunications breach as a real-world framework, we cover the entire incident response lifecycle. You will learn how to build a Computer Incident Response Team (CIRT), execute tabletop exercises, perform digital forensics using the order of volatility, and navigate the legal minefield of chain of custody and data sovereignty.

    To map out exactly how to leverage this crisis-management mindset into an executive transition, refer to the SecGuy CompTIA Security+ Career and Certification Strategy Guide.

    Resources:

    πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide

    πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org

    πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord

    In this episode:

    00:00 – The Breach, Preparation, and Salt Typhoon

    01:50 – Detection, Attribution, and Containment

    03:20 – Digital Forensics and the Legal Minefield

    05:30 – Lessons Learned and Real-World Application

    Original Sec Guy video: https://www.youtube.com/watch?v=7i6rLAwrMko

    6 min
  • CompTIA Security+ SY0-801: 2.2 Threat Actors & Motivations

    In cybersecurity, knowing the exploit is only half the battle. If you do not know the hand behind the keyboard, you are just chasing ghosts.In this module, Sec Guy breaks down Objective 2.2 for the CompTIA Security+ (SY0-801) exam: Threat Actors and Motivations. We move beyond textbook definitions to analyze the actual tradecraft, funding, and motivations of modern adversaries. You will learn how Nation-States use dwell time for espionage, how Organized Crime syndicates operate for financial gain, and why Hacktivists seek disruption. We also uncover the most dangerous, yet overlooked, threat vectors inside your own network: malicious insider threats, negligent employees, and Shadow IT.

    Resources

    πŸ“š Study Guides & Course Materials: https://secguy.org/security-study-guide

    πŸ’» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org

    πŸ’¬ Join the Sec Guy Study Discord: https://secguy.org/discord

    In this episode:

    00:00 – Knowing the Hand Behind the Keyboard

    00:45 – Nation-States: Espionage & Dwell Time (Salt Typhoon)

    01:50 – Organized Crime: Extortion & Ransomware (Scattered Spider) 02:40 – Hacktivists: Political Messaging & Disruption

    03:30 – Unskilled Attackers (Script Kiddies)

    04:15 – The Insider Threat: Malicious vs. Accidental

    05:20 – Shadow IT: The Silent Killer of Compliance

    06:10 – Threat Actor Attributes: Location, Resources & Sophistication

    07:05 – The Interview Trap: Who is the Greatest Day-to-Day Risk?

    08:00 – Outro & SecGuy Labs

    Original Sec Guy video: https://www.youtube.com/watch?v=p1nmkjF_X6o

    12 min
  • AI Threat Landscape: Model Poisoning and Prompt Injection

    When you type a password, the computer knows it's data. But when you talk to an AI, your instructions and your data are the exact same thingβ€”just tokens in a stream. That single flaw is the root of every AI attack. In this video, Sec Guy explains the math behind Universal Adversarial Triggers, reveals how Indirect Prompt Injection can turn a resume into a weapon, and shows why Token Smuggling allows malware to slip right past your firewall.

    New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 2.6: Artificial Intelligence (Prompt Injection, Training Data Poisoning)

    [ ] Domain 2.2: Vulnerabilities (Supply Chain Attacks - Poisoned Models)

    CISSP

    [ ] Domain 8: Software Development Security (Input Validation in AI Systems)

    [ ] Domain 1: Security and Risk Management (AI Risk Assessment)

    CISM

    [ ] Domain 2: Information Risk Management (Emerging Tech Risks: AI & ML)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Adversarial AI & Model Theft)

    CCSP

    [ ] Domain 4: Cloud Application Security (Securing AI APIs & Rate Limiting)

    SecurityX (CompTIA)

    [ ] Domain 3.0: Security Operations (Detecting Adversarial ML Attacks)

    GIAC GSEC (SANS)

    [ ] Emerging Threats: AI & LLM Security

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 1: Threat Detection (Anomalous API Usage & Cost Attacks)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Prompt Injection & Jailbreaking LLMs)

    CEH (Certified Ethical Hacker)

    [ ] Domain 10: Web Server & Application Hacking (AI-Specific Injection Vectors)

    SecAI+

    [ ] AI Security: Universal Adversarial Triggers (UAT), Indirect Injection, Token Smuggling, Model Inversion

    [Timestamps]

    0:00 - Intro: Data vs. Instructions (The Core Flaw)

    0:48 - Context Mixing: The "System Prompt" Vulnerability

    1:28 - Type 1: Persona Modification ("Do Anything Now" / DAN)

    1:54 - Type 2: Logical Bypass (Translation & Educational Intent)

    2:25 - Type 3: Universal Adversarial Triggers (The Math of "ZXCVB")

    3:05 - Indirect Prompt Injection: The Resume Scanner Attack (Zero Click)

    3:50 - RAG Poisoning: When the AI Searches a Malicious Site

    4:22 - Token Smuggling: Bypassing Firewalls via Payload Splitting

    4:54 - Availability Attacks: Wallet Exhaustion & Recursive Loops

    5:37 - Defense: Prompt Firewalls & Canary Tokens

    5:56 - Homework: Glitch Tokens

    6:14 - Outro: Train Hard, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=ELWi8OXZoQ0

    7 min
  • Cloud IAM: STS, Roles, SCP, and Policies

    A password can be stolen, but a temporary token expires. In this video, Sec Guy explains why Long-Term Access Keys are a "security smell" and how to replace them with IAM Roles and the STS (Security Token Service). We break down the critical difference between Identity-Based Policies (What I can do) and Resource-Based Policies (Who can access this bucket), and show you how to use SCPs (Service Control Policies) to create an unbreakable ceiling on permissions.

    New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 1.3: Identity and Access Management (Roles vs. Accounts)

    [ ] Domain 3.2: Cloud Computing Concepts (IAM Policies, SCPs)

    [ ] Domain 5.2: Risk Management (Least Privilege & Guardrails)

    CISSP

    [ ] Domain 5: Identity and Access Management (Authorization Mechanisms, Role-Based Access Control)

    [ ] Domain 3: Security Architecture (Cloud Identity Services)

    CISM

    [ ] Domain 3: Information Security Program (Identity Governance & Policy Enforcement)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Cloud Misconfiguration Risks)

    CCSP

    [ ] Domain 4: Cloud Application Security (IAM, STS, & Temporary Credentials)

    [ ] Domain 1: Cloud Concepts (Multi-Tenancy & Resource Policies)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Implementing Service Control Policies)

    GIAC GSEC (SANS)

    [ ] Cloud Security: IAM Roles & Policies

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 3: Infrastructure Security (IAM Policies, SCPs, Permissions Boundaries)

    [ ] Domain 1: Threat Detection (Detecting Principal Misuse)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Cloud Privilege Escalation)

    CEH (Certified Ethical Hacker)

    [ ] Domain 11: Cloud Computing (IAM Misconfigurations & Key Theft)

    SecAI+

    [ ] AI Security: Limiting AI Agent Permissions via SCPs

    [Timestamps]

    0:00 - Intro: Accounts vs. Roles (The "Hat" Analogy)

    0:30 - STS (Security Token Service): The Temporary Badge Office

    0:58 - Identity-Based Policies: "I am allowed to..."

    1:32 - Resource-Based Policies: "This bucket allows..."

    1:42 - Case Study: Imperva Breach (SSRF & Metadata Service)

    2:12 - The Wildcard (*) Danger: Granular Permissions

    2:30 - SCPs (Service Control Policies): The Organization Kill Switch

    2:58 - Permissions Boundaries: Setting the Ceiling for Developers

    3:21 - Summary: Identity is the Perimeter

    3:36 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=4z-v9k5qIWM

    5 min
  • Cloud Architecture Security: CSPM, CASB, Zero Trust

    If your cloud environment is a skyscraper, CSPM is the building inspector checking the foundation, while CASB is the security guard checking everyone who walks through the door. In this video, Sec Guy explains the critical difference between securing infrastructure (IaaS) and securing SaaS applications, breaks down Forward vs. Reverse Proxy deployment modes, and shows how a Zero Trust Policy Decision Point (PDP) can stop an identity attack in real-time.

    New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 3.2: Cloud Computing Concepts (CASB, CSPM)

    [ ] Domain 3.3: Network Designs (Zero Trust: PDP & PEP)

    [ ] Domain 5.2: Risk Management (Shadow IT & Data Loss Prevention)

    CISSP

    [ ] Domain 3: Security Architecture (Cloud Security Tools & Deployment Modes)

    [ ] Domain 4: Communication & Network Security (TLS Inspection & Proxies)

    CISM

    [ ] Domain 2: Information Risk Management (Cloud Misconfigurations)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Shadow IT Risks)

    CCSP

    [ ] Domain 1: Cloud Concepts (NIST 800-207 Zero Trust)

    [ ] Domain 4: Cloud Application Security (CASB Deployment Modes: API, Forward/Reverse Proxy)

    SecurityX (CompTIA)

    [ ] Domain 2.0: Security Architecture (Implementing CNAPP & CASB)

    GIAC GSEC (SANS)

    [ ] Cloud Security: Monitoring & Posture Management

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Infrastructure Security (AWS Config vs. CSPM)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Cloud Misconfigurations & S3 Buckets)

    CEH (Certified Ethical Hacker)

    [ ] Domain 11: Cloud Computing (Shadow IT & Data Exfiltration)

    SecAI+

    [ ] AI Security: Using AI to Automate CSPM Remediation

    [Timestamps]

    0:00 - Intro: Tools of the Trade

    0:16 - CSPM (Cloud Security Posture Management): The Building Inspector

    0:44 - Case Study: Accenture & Twilio (Open S3 Buckets)

    1:08 - Shift Left: Scanning Terraform (IaC) in the Build Pipeline

    1:28 - CASB (Cloud Access Security Broker): The Bouncer for SaaS

    1:50 - CASB Modes: Forward Proxy vs. Reverse Proxy vs. API

    2:17 - The Visibility Gap: TLS Inspection & User Privacy

    2:42 - Zero Trust Architecture (NIST 800-207): Never Trust, Always Verify

    3:00 - The Brain & The Brawn: Policy Decision Point (PDP) vs. Enforcement Point (PEP)

    3:28 - Contextual Access: Blocking Impossible Travel (Seattle to London)

    3:50 - Free Resources: Zero Trust Logic Map & Labs

    4:26 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=GjTDgXsMK60

    5 min
  • Cloud Models: IaaS to Serverless, Shared Responsibility, and Soverignty

    If your data is breached in the cloud, is it Amazon's fault or yours? In this video, Sec Guy breaks down the Shared Responsibility Model, explaining why Capital One was liable for their massive breach (SSRF) despite using a secure cloud provider. We also cover the evolution from IaaS to Serverless (FaaS) and why Data Sovereignty (Microsoft Ireland Case) means your data is subject to the laws of the physical land it sits on.

    New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 3.2: Cloud Computing Concepts (IaaS, PaaS, SaaS, Public/Private/Hybrid)

    [ ] Domain 5.3: Third-Party Risk Management (Shared Responsibility Model)

    [ ] Domain 2.2: Vulnerabilities (SSRF - Server-Side Request Forgery)

    CISSP

    [ ] Domain 3: Security Architecture (Cloud Service Models & Microservices)

    [ ] Domain 1: Security and Risk Management (Legal & Regulatory Issues - Data Sovereignty)

    CISM

    [ ] Domain 2: Information Risk Management (Cloud Risk Assessment)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Outsourcing & Cloud Vendor Risk)

    CCSP

    [ ] Domain 1: Cloud Concepts (IaaS, PaaS, SaaS, FaaS, Shared Responsibility)\

    [ ] Domain 6: Legal, Risk, and Compliance (Cross-Border Data Transfer & GDPR)

    SecurityX (CompTIA)

    [ ] Domain 2.0: Security Architecture (Cloud Native Security Controls - CNAPP, CWPP, CSPM)

    GIAC GSEC (SANS)

    [ ] Cloud Security: Fundamentals & Shared Responsibility

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Infrastructure Security (Shared Responsibility Model)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Cloud Metadata Attacks & SSRF)

    CEH (Certified Ethical Hacker)

    [ ] Domain 11: Cloud Computing (Cloud Attacks & Misconfigurations)

    SecAI+

    [ ] AI Security: Securing AI Models on Serverless Infrastructure (FaaS)

    [Timestamps]

    0:00 - Intro: The Cloud is Just Someone Else's Computer?

    0:37 - IaaS (Infrastructure as a Service): Renting the House (AWS EC2)

    1:00 - PaaS (Platform as a Service): Staying in a Hotel (Google App Engine)

    1:23 - SaaS (Software as a Service): Dining Out (Salesforce, Gmail)

    1:38 - FaaS (Serverless): The Ultimate Abstraction (AWS Lambda)

    2:10 - The Shared Responsibility Model: Security "OF" vs. Security "IN"

    2:45 - Case Study: Capital One Breach (SSRF & Misconfiguration)

    3:30 - Data Sovereignty: The Microsoft Ireland Case & GDPR

    4:20 - The Cloud Security Stack: CSPM, CWPP, CASB, & CNAPP

    5:20 - Summary: Control vs. Convenience

    5:40 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=oxDZf-7dzVQ

    7 min

About Sec Guy

From the publisher's feed

Real cybersecurity training for the real world. We take the complex theories of CompTIA Security+ and SecAI+ and translate them into actionable skills. Whether…