
Sign up to save your podcasts
Or


If you are preparing for your CompTIA Security+ SY0-801 certification, throw away the idea of memorizing vocabulary just to pass a test. In the real world, enterprise security is about reasoning through decisions, understanding architectural tradeoffs, and knowing exactly what happens when a control fails.
In this module, Sec Guy breaks down Objective 1.1: Security Concepts and Controls. We dismantle the outdated "castle and moat" strategy and build a modern Defense in Depth architecture. You will learn how to apply the CIA Triad, govern access with the AAA Framework, implement Zero Trust principles, and deploy the exact categories and types of security controls required to defend a modern enterprise.
Rersources:
π Study Guides & Course Materials: https://secguy.org/security-study-guide
π» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org
π¬ Join the Sec Guy Study Discord: https://secguy.org/discord
π» Practice Test: https://secguy.org
In this episode:
00:00 β Introduction: The Perimeter is Dead & Defense in Depth
01:32 β The CIA Triad: Confidentiality, Integrity, and Availability
03:38 β Governing Access: The AAA Framework (Authentication, Authorization, Accounting)
05:53 β Limiting the Blast Radius: Least Privilege & Zero Trust Architecture
07:11 β Security Controls: The 4 Categories (Technical, Managerial, Operational, Physical)
09:01 β Security Controls: The 6 Types (Preventive, Deterring, Detective, Corrective, Compensating, Directive)
Original Sec Guy video: https://www.youtube.com/watch?v=sEKQuOfkKpk
In enterprise security, you cannot defend against an adversary you do not understand. Today, we begin Domain 2 with Lesson S8-006: From Threat Intelligence to Vulnerability Priority for the CompTIA Security+ (SY0-801).
Sec Guy breaks down the definitive difference between a threat (the force that exploits) and a vulnerability (the weakness in the system). You will learn how to consume intelligence across the entire threat lifecycle using Open-Source Intelligence (OSINT), Proprietary Threat Feeds, and Dark Web monitoring to determine an attack's Likelihood and Impact. We also deconstruct the Common Vulnerability Scoring System (CVSS) and explain why relying solely on a Base Score is an operational failure. You will learn how to apply Temporal and Environmental scores to inject actual business context into your patching strategy.
Resources
π Study Guides & Course Materials: https://secguy.org/security-study-guide
π» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org
π¬ Join the Sec Guy Study Discord: https://secguy.org/discord
In this episode:
00:00 β The SWAT Analogy: Prioritizing the Enterprise Response
01:00 β Threat vs. Vulnerability: Defining the Incident
01:50 β Intelligence Sources: OSINT, Proprietary Feeds, and the Dark Web
02:45 β The Math of Risk: Likelihood vs. Impact
04:00 β Quantifying Weaknesses: CVEs and CVSS Mechanics
04:50 β Breaking Down CVSS: Base, Temporal, and Environmental Scores
06:30 β The Junior Analyst Trap: Why You Must Apply Business Context
07:45 β LAB-S8-004: The Threat-Priority Board Workshop
Original Sec Guy video: https://www.youtube.com/watch?v=FfHfyzz71Sc
Theory without execution is useless in enterprise cybersecurity. In this Domain 1 Mastery Workshop for the CompTIA Security+ (SY0-801), you step into the shoes of the Lead Security Architect for a national healthcare processing network facing a critical Friday morning crisis. When infrastructure engineers submit an emergency Change Advisory Board (CAB) request to overhaul the patient billing portal, junior analysts see a standard business request, but an experienced architect spots an architectural minefield.
Sec Guy guides you through dissecting the proposalβs catastrophic failures: missing impact analyses, absent backout plans, bypassed inspection proxies, deprecated MD5 hashing without salt, self-signed wildcard certificates, and unencrypted internal synchronization tunnels. You will learn not only how to reject a reckless deployment, but how to re-engineer the entire system using Enterprise PKI, mutual TLS 1.3, tokenization, Zero Trust identity, and automated rollback triggers, concluding with an executive briefing that proves business value to the CIO and CRO.
Resources
π Study Guides & Course Materials: https://secguy.org/security-study-guide
π» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org
π¬ Join the Sec Guy Study Discord: https://secguy.org/discord
In this episode:
00:00 β Domain 1: From Theory to Execution
00:25 β The Scenario: Lead Security Architect
00:30 β The Emergency Change Request: Three Hidden Risks
01:00 β Don't Approve the Ticket: Analyze the Risk
01:20 β No Impact Analysis, No Approval: Managerial Control Failures
01:43 β Backout Protects Availability: The Missing Rollback Plan
02:11 β No Inspection Means No Visibility: Eliminating Detective Controls
02:41 β Internal Does Not Mean Trusted: Violating Defense in Depth
03:02 β Reject the Risk, Rewrite the Plan
03:17 β Open the Design Packet: Follow the Failure Path
03:32 β One Wildcard Key: Cluster-Wide Risk
03:43 β Never Disable Certificate Validation: On-Path Vulnerabilities
04:15 β Limit the Key's Blast Radius: Enforcing Least Privilege
04:37 β MD5 + No Salt = Credential Failure
05:11 β Slow KDF & Unique Salting Architecture
05:33 β Encrypt Internal Traffic: TLS 1.3 & Forward Secrecy
06:20 β Shared Admin Means No Accountability: AAA Breakdown
06:55 β Repair the Architecture: The Remediated Blueprint
07:13 β One Service, One Certificate: Enterprise PKI & OCSP Stapling
07:33 β Zero Trust Identity: Phishing-Resistant MFA & Jump Hosts
08:05 β Layered Data Protection: AES-256 & Tokenization
08:38 β Governed Pipeline: Test, Snapshot, Verify, Rollback
09:13 β Executive Briefing: Translating Security to the CIO & CRO
10:05 β Outro & Preparing for Domain 2
Original Sec Guy video: https://www.youtube.com/watch?v=twkmTT7nq9U
In modern enterprise security, cryptography is not an academic math drill; it is the trust engine that enforces identity, proves integrity, and secures multi-cloud environments. In this module, Sec Guy breaks down Objective 1.3: Cryptographic Solutions and the Trust Engine for the CompTIA Security+ (SY0-801). We demystify the difference between one-way integrity (hashing, salting, and rainbow table mitigation) and two-way confidentiality (symmetric vs. asymmetric encryption). You will master how Transport Layer Security (TLS) combines the speed of AES with the key-exchange power of RSA and ECC, how digital signatures mathematically enforce non-repudiation, and how enterprise Public Key Infrastructure (PKI) maintains the root of trust across Certificate Authorities (CAs), CRLs, and OCSP stapling. We also detail dedicated hardware root of trust implementations including TPMs, HSMs, and secure enclaves.
Resources
π Study Guides & Course Materials: https://secguy.org/security-study-guide
π» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org
π¬ Join the Sec Guy Study Discord: https://secguy.org/discord
In this episode:
00:00 β Hashing vs. Encryption: Integrity vs. Confidentiality
02:10 β Collision Attacks, SHA-256 & Salting Passwords
04:15 β Obfuscation Techniques: Steganography, Tokenization & Masking
06:40 β Symmetric vs. Asymmetric: AES, RSA, and Elliptic Curve Cryptography (ECC)
09:20 β Hybrid Encryption & The TLS Handshake
11:35 β Public Key Infrastructure (PKI), Root CAs & Certificate Lifecycles
13:50 β Certificate Revocation: CRLs vs. OCSP Stapling
15:40 β Digital Signatures & Non-Repudiation Architecture
Original Sec Guy video: https://www.youtube.com/watch?v=tV1AnMYSBbw
When the network is breached, a technician reacts with panic, but an executive reacts with a playbook.
In this module, Sec Guy breaks down Objective 4.7: Incident Response and Forensics. Using the Salt Typhoon telecommunications breach as a real-world framework, we cover the entire incident response lifecycle. You will learn how to build a Computer Incident Response Team (CIRT), execute tabletop exercises, perform digital forensics using the order of volatility, and navigate the legal minefield of chain of custody and data sovereignty.
To map out exactly how to leverage this crisis-management mindset into an executive transition, refer to the SecGuy CompTIA Security+ Career and Certification Strategy Guide.
Resources:
π Study Guides & Course Materials: https://secguy.org/security-study-guide
π» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org
π¬ Join the Sec Guy Study Discord: https://secguy.org/discord
In this episode:
00:00 β The Breach, Preparation, and Salt Typhoon
01:50 β Detection, Attribution, and Containment
03:20 β Digital Forensics and the Legal Minefield
05:30 β Lessons Learned and Real-World Application
Original Sec Guy video: https://www.youtube.com/watch?v=7i6rLAwrMko
In cybersecurity, knowing the exploit is only half the battle. If you do not know the hand behind the keyboard, you are just chasing ghosts.In this module, Sec Guy breaks down Objective 2.2 for the CompTIA Security+ (SY0-801) exam: Threat Actors and Motivations. We move beyond textbook definitions to analyze the actual tradecraft, funding, and motivations of modern adversaries. You will learn how Nation-States use dwell time for espionage, how Organized Crime syndicates operate for financial gain, and why Hacktivists seek disruption. We also uncover the most dangerous, yet overlooked, threat vectors inside your own network: malicious insider threats, negligent employees, and Shadow IT.
Resources
π Study Guides & Course Materials: https://secguy.org/security-study-guide
π» Hands-On AI Skills Labs & Exam Simulator: https://secguy.org
π¬ Join the Sec Guy Study Discord: https://secguy.org/discord
In this episode:
00:00 β Knowing the Hand Behind the Keyboard
00:45 β Nation-States: Espionage & Dwell Time (Salt Typhoon)
01:50 β Organized Crime: Extortion & Ransomware (Scattered Spider) 02:40 β Hacktivists: Political Messaging & Disruption
03:30 β Unskilled Attackers (Script Kiddies)
04:15 β The Insider Threat: Malicious vs. Accidental
05:20 β Shadow IT: The Silent Killer of Compliance
06:10 β Threat Actor Attributes: Location, Resources & Sophistication
07:05 β The Interview Trap: Who is the Greatest Day-to-Day Risk?
08:00 β Outro & SecGuy Labs
Original Sec Guy video: https://www.youtube.com/watch?v=p1nmkjF_X6o
When you type a password, the computer knows it's data. But when you talk to an AI, your instructions and your data are the exact same thingβjust tokens in a stream. That single flaw is the root of every AI attack. In this video, Sec Guy explains the math behind Universal Adversarial Triggers, reveals how Indirect Prompt Injection can turn a resume into a weapon, and shows why Token Smuggling allows malware to slip right past your firewall.
New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide
[Exam Ready Route - FREE]
Pass your certification for $0.
β Training Videos & Practice Tests
β Sec Guy Mobile Lab (On-the-go training powered by AI voice)
β Discord Access (Study sessions & Industry networking)
π Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
π₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
π₯ Salary Negotiator Workshop
π₯ Experience Builder: Real-world projects to fill your resume
π Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
[ ] Domain 2.6: Artificial Intelligence (Prompt Injection, Training Data Poisoning)
[ ] Domain 2.2: Vulnerabilities (Supply Chain Attacks - Poisoned Models)
CISSP
[ ] Domain 8: Software Development Security (Input Validation in AI Systems)
[ ] Domain 1: Security and Risk Management (AI Risk Assessment)
CISM
[ ] Domain 2: Information Risk Management (Emerging Tech Risks: AI & ML)
CRISC
[ ] Domain 2: IT Risk Assessment (Adversarial AI & Model Theft)
CCSP
[ ] Domain 4: Cloud Application Security (Securing AI APIs & Rate Limiting)
SecurityX (CompTIA)
[ ] Domain 3.0: Security Operations (Detecting Adversarial ML Attacks)
GIAC GSEC (SANS)
[ ] Emerging Threats: AI & LLM Security
AWS CSS (Certified Security β Specialty)
[ ] Domain 1: Threat Detection (Anomalous API Usage & Cost Attacks)
Pentest+ (CompTIA)
[ ] Domain 3: Attacks and Exploits (Prompt Injection & Jailbreaking LLMs)
CEH (Certified Ethical Hacker)
[ ] Domain 10: Web Server & Application Hacking (AI-Specific Injection Vectors)
SecAI+
[ ] AI Security: Universal Adversarial Triggers (UAT), Indirect Injection, Token Smuggling, Model Inversion
[Timestamps]
0:00 - Intro: Data vs. Instructions (The Core Flaw)
0:48 - Context Mixing: The "System Prompt" Vulnerability
1:28 - Type 1: Persona Modification ("Do Anything Now" / DAN)
1:54 - Type 2: Logical Bypass (Translation & Educational Intent)
2:25 - Type 3: Universal Adversarial Triggers (The Math of "ZXCVB")
3:05 - Indirect Prompt Injection: The Resume Scanner Attack (Zero Click)
3:50 - RAG Poisoning: When the AI Searches a Malicious Site
4:22 - Token Smuggling: Bypassing Firewalls via Payload Splitting
4:54 - Availability Attacks: Wallet Exhaustion & Recursive Loops
5:37 - Defense: Prompt Firewalls & Canary Tokens
5:56 - Homework: Glitch Tokens
6:14 - Outro: Train Hard, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=ELWi8OXZoQ0
A password can be stolen, but a temporary token expires. In this video, Sec Guy explains why Long-Term Access Keys are a "security smell" and how to replace them with IAM Roles and the STS (Security Token Service). We break down the critical difference between Identity-Based Policies (What I can do) and Resource-Based Policies (Who can access this bucket), and show you how to use SCPs (Service Control Policies) to create an unbreakable ceiling on permissions.
New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide
[Exam Ready Route - FREE]
Pass your certification for $0.
β Training Videos & Practice Tests
β Sec Guy Mobile Lab (On-the-go training powered by AI voice)
β Discord Access (Study sessions & Industry networking)
π Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
π₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
π₯ Salary Negotiator Workshop
π₯ Experience Builder: Real-world projects to fill your resume
π Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
[ ] Domain 1.3: Identity and Access Management (Roles vs. Accounts)
[ ] Domain 3.2: Cloud Computing Concepts (IAM Policies, SCPs)
[ ] Domain 5.2: Risk Management (Least Privilege & Guardrails)
CISSP
[ ] Domain 5: Identity and Access Management (Authorization Mechanisms, Role-Based Access Control)
[ ] Domain 3: Security Architecture (Cloud Identity Services)
CISM
[ ] Domain 3: Information Security Program (Identity Governance & Policy Enforcement)
CRISC
[ ] Domain 2: IT Risk Assessment (Cloud Misconfiguration Risks)
CCSP
[ ] Domain 4: Cloud Application Security (IAM, STS, & Temporary Credentials)
[ ] Domain 1: Cloud Concepts (Multi-Tenancy & Resource Policies)
SecurityX (CompTIA)
[ ] Domain 1.0: Security Architecture (Implementing Service Control Policies)
GIAC GSEC (SANS)
[ ] Cloud Security: IAM Roles & Policies
AWS CSS (Certified Security β Specialty)
[ ] Domain 3: Infrastructure Security (IAM Policies, SCPs, Permissions Boundaries)
[ ] Domain 1: Threat Detection (Detecting Principal Misuse)
Pentest+ (CompTIA)
[ ] Domain 3: Attacks and Exploits (Cloud Privilege Escalation)
CEH (Certified Ethical Hacker)
[ ] Domain 11: Cloud Computing (IAM Misconfigurations & Key Theft)
SecAI+
[ ] AI Security: Limiting AI Agent Permissions via SCPs
[Timestamps]
0:00 - Intro: Accounts vs. Roles (The "Hat" Analogy)
0:30 - STS (Security Token Service): The Temporary Badge Office
0:58 - Identity-Based Policies: "I am allowed to..."
1:32 - Resource-Based Policies: "This bucket allows..."
1:42 - Case Study: Imperva Breach (SSRF & Metadata Service)
2:12 - The Wildcard (*) Danger: Granular Permissions
2:30 - SCPs (Service Control Policies): The Organization Kill Switch
2:58 - Permissions Boundaries: Setting the Ceiling for Developers
3:21 - Summary: Identity is the Perimeter
3:36 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=4z-v9k5qIWM
If your cloud environment is a skyscraper, CSPM is the building inspector checking the foundation, while CASB is the security guard checking everyone who walks through the door. In this video, Sec Guy explains the critical difference between securing infrastructure (IaaS) and securing SaaS applications, breaks down Forward vs. Reverse Proxy deployment modes, and shows how a Zero Trust Policy Decision Point (PDP) can stop an identity attack in real-time.
New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide
[Exam Ready Route - FREE]
Pass your certification for $0.
β Training Videos & Practice Tests
β Sec Guy Mobile Lab (On-the-go training powered by AI voice)
β Discord Access (Study sessions & Industry networking)
π Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
π₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
π₯ Salary Negotiator Workshop
π₯ Experience Builder: Real-world projects to fill your resume
π Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
[ ] Domain 3.2: Cloud Computing Concepts (CASB, CSPM)
[ ] Domain 3.3: Network Designs (Zero Trust: PDP & PEP)
[ ] Domain 5.2: Risk Management (Shadow IT & Data Loss Prevention)
CISSP
[ ] Domain 3: Security Architecture (Cloud Security Tools & Deployment Modes)
[ ] Domain 4: Communication & Network Security (TLS Inspection & Proxies)
CISM
[ ] Domain 2: Information Risk Management (Cloud Misconfigurations)
CRISC
[ ] Domain 2: IT Risk Assessment (Shadow IT Risks)
CCSP
[ ] Domain 1: Cloud Concepts (NIST 800-207 Zero Trust)
[ ] Domain 4: Cloud Application Security (CASB Deployment Modes: API, Forward/Reverse Proxy)
SecurityX (CompTIA)
[ ] Domain 2.0: Security Architecture (Implementing CNAPP & CASB)
GIAC GSEC (SANS)
[ ] Cloud Security: Monitoring & Posture Management
AWS CSS (Certified Security β Specialty)
[ ] Domain 2: Infrastructure Security (AWS Config vs. CSPM)
Pentest+ (CompTIA)
[ ] Domain 3: Attacks and Exploits (Cloud Misconfigurations & S3 Buckets)
CEH (Certified Ethical Hacker)
[ ] Domain 11: Cloud Computing (Shadow IT & Data Exfiltration)
SecAI+
[ ] AI Security: Using AI to Automate CSPM Remediation
[Timestamps]
0:00 - Intro: Tools of the Trade
0:16 - CSPM (Cloud Security Posture Management): The Building Inspector
0:44 - Case Study: Accenture & Twilio (Open S3 Buckets)
1:08 - Shift Left: Scanning Terraform (IaC) in the Build Pipeline
1:28 - CASB (Cloud Access Security Broker): The Bouncer for SaaS
1:50 - CASB Modes: Forward Proxy vs. Reverse Proxy vs. API
2:17 - The Visibility Gap: TLS Inspection & User Privacy
2:42 - Zero Trust Architecture (NIST 800-207): Never Trust, Always Verify
3:00 - The Brain & The Brawn: Policy Decision Point (PDP) vs. Enforcement Point (PEP)
3:28 - Contextual Access: Blocking Impossible Travel (Seattle to London)
3:50 - Free Resources: Zero Trust Logic Map & Labs
4:26 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=GjTDgXsMK60
If your data is breached in the cloud, is it Amazon's fault or yours? In this video, Sec Guy breaks down the Shared Responsibility Model, explaining why Capital One was liable for their massive breach (SSRF) despite using a secure cloud provider. We also cover the evolution from IaaS to Serverless (FaaS) and why Data Sovereignty (Microsoft Ireland Case) means your data is subject to the laws of the physical land it sits on.
New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide
[Exam Ready Route - FREE]
Pass your certification for $0.
β Training Videos & Practice Tests
β Sec Guy Mobile Lab (On-the-go training powered by AI voice)
β Discord Access (Study sessions & Industry networking)
π Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
π₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
π₯ Salary Negotiator Workshop
π₯ Experience Builder: Real-world projects to fill your resume
π Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
[ ] Domain 3.2: Cloud Computing Concepts (IaaS, PaaS, SaaS, Public/Private/Hybrid)
[ ] Domain 5.3: Third-Party Risk Management (Shared Responsibility Model)
[ ] Domain 2.2: Vulnerabilities (SSRF - Server-Side Request Forgery)
CISSP
[ ] Domain 3: Security Architecture (Cloud Service Models & Microservices)
[ ] Domain 1: Security and Risk Management (Legal & Regulatory Issues - Data Sovereignty)
CISM
[ ] Domain 2: Information Risk Management (Cloud Risk Assessment)
CRISC
[ ] Domain 2: IT Risk Assessment (Outsourcing & Cloud Vendor Risk)
CCSP
[ ] Domain 1: Cloud Concepts (IaaS, PaaS, SaaS, FaaS, Shared Responsibility)\
[ ] Domain 6: Legal, Risk, and Compliance (Cross-Border Data Transfer & GDPR)
SecurityX (CompTIA)
[ ] Domain 2.0: Security Architecture (Cloud Native Security Controls - CNAPP, CWPP, CSPM)
GIAC GSEC (SANS)
[ ] Cloud Security: Fundamentals & Shared Responsibility
AWS CSS (Certified Security β Specialty)
[ ] Domain 2: Infrastructure Security (Shared Responsibility Model)
Pentest+ (CompTIA)
[ ] Domain 3: Attacks and Exploits (Cloud Metadata Attacks & SSRF)
CEH (Certified Ethical Hacker)
[ ] Domain 11: Cloud Computing (Cloud Attacks & Misconfigurations)
SecAI+
[ ] AI Security: Securing AI Models on Serverless Infrastructure (FaaS)
[Timestamps]
0:00 - Intro: The Cloud is Just Someone Else's Computer?
0:37 - IaaS (Infrastructure as a Service): Renting the House (AWS EC2)
1:00 - PaaS (Platform as a Service): Staying in a Hotel (Google App Engine)
1:23 - SaaS (Software as a Service): Dining Out (Salesforce, Gmail)
1:38 - FaaS (Serverless): The Ultimate Abstraction (AWS Lambda)
2:10 - The Shared Responsibility Model: Security "OF" vs. Security "IN"
2:45 - Case Study: Capital One Breach (SSRF & Misconfiguration)
3:30 - Data Sovereignty: The Microsoft Ireland Case & GDPR
4:20 - The Cloud Security Stack: CSPM, CWPP, CASB, & CNAPP
5:20 - Summary: Control vs. Convenience
5:40 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=oxDZf-7dzVQ
From the publisher's feed
Real cybersecurity training for the real world. We take the complex theories of CompTIA Security+ and SecAI+ and translate them into actionable skills. Whetherβ¦
Train Hard. Stay Secure.