Sec Guy

Sec Guy

Download on the App Store

Sec Guy episodes

  • Network Architecture: OSI Model, TCP/IP Model, PEP/PDP VLANS Explained

    If you can't map an attack to its layer, you can't defend against it. Is a DDoS attack Layer 4 or Layer 7? Is ARP Poisoning Layer 2 or Layer 3? In this video, Sec Guy breaks down the OSI Model vs. TCP/IP, explains the critical difference between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP) in Zero Trust, and shows you how to stop VLAN Hopping attacks.

    πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 3.1: Secure Network Architecture (OSI Model, TCP/IP, VLANs)

    [ ] Domain 3.3: Network Designs (Zero Trust: PDP & PEP)

    CISSP

    [ ] Domain 4: Communication & Network Security (OSI Layers & Secure Design)

    [ ] Domain 3: Security Architecture (Zero Trust Principles)

    CISM

    [ ] Domain 3: Information Security Program (Network Infrastructure Security)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Network Vulnerabilities & Architecture Risks)

    CCSP

    [ ] Domain 3: Cloud Infrastructure Security (Virtual Networking & VLANs)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Network Segmentation & Zero Trust)

    GIAC GSEC (SANS)

    [ ] Network Security Essentials: OSI, TCP/IP, & Defense in Depth

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Infrastructure Security (VPC Design, Direct Connect vs. VPN)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (VLAN Hopping & ARP Poisoning)

    CEH (Certified Ethical Hacker)

    [ ] Domain 3: Scanning Networks (Mapping Attacks to OSI Layers)

    SecAI+

    [ ] AI Security: AI-Driven Network Segmentation & Anomaly Detection

    [Timestamps]

    0:00 - Intro: The Battlefield of Architecture

    0:36 - The OSI Model (7 Layers): "Please Do Not Throw Sausage Pizza Away"

    1:01 - The TCP/IP Model (4 Layers): "All The Internet Needs"

    1:25 - Mapping Attacks: DDoS (L7) vs. ARP Poisoning (L2)

    1:50 - Hybrid Cloud: Site-to-Site VPN vs. Direct Connect

    2:40 - The Death of the Flat Network: VLANs & 802.1Q

    2:58 - Zero Trust Brain: Policy Decision Point (PDP) vs. Enforcement Point (PEP)

    3:33 - Attack Vector: VLAN Hopping & Auto-Trunking

    4:00 - Defense: Deception Technology (Honeynets)

    4:16 - The Future: AI-Driven Dynamic Segmentation

    4:52 - Summary: Segment Ruthlessly

    5:08 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=i-jwtB3puxY

    6 min
  • Infrastructure Attack Surfaces: Spectre, VM Escape, & Memory Mastery

    Software updates are great, but you can't patch a physics problem. In this video, Sec Guy explores the Infrastructure Attack Surface, explaining why Spectre and Meltdown exploit the CPU itself, how VM Escape can bring down an entire cloud provider, and the critical difference between a Buffer Overflow (Execution Attack) and a Memory Leak (Availability Attack).

    πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 3.2: Virtualization and Cloud Computing (VM Escape, VM Sprawl)

    [ ] Domain 4.2: Embedded and Specialized Systems (TPM, HSM)

    [ ] Domain 2.2: Vulnerabilities (Buffer Overflow, Memory Leak, DLL Injection)

    [ ] Domain 3.4: Mobile Device Management (Jailbreaking, Rooting, Sideloading)

    CISSP

    [ ] Domain 3: Security Architecture (Side-Channel Attacks, Trusted Foundry, Ring Protection)

    [ ] Domain 8: Software Development Security (Buffer Overflows & Memory Safety)

    CISM

    [ ] Domain 3: Information Security Program (Infrastructure Protection & Supply Chain)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Hardware & Virtualization Risks)

    CCSP

    [ ] Domain 1: Cloud Concepts (Hypervisor Security & Guest Escape)

    [ ] Domain 3: Cloud Infrastructure Security (Virtualization Risks)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Hardware Root of Trust & Secure Boot)

    GIAC GSEC (SANS)

    [ ] Virtualization & Cloud Security: VM Escape & Hypervisor Attacks

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Infrastructure Security (Host Isolation & Nitro Enclaves)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Exploiting Buffer Overflows & Mobile Devices)

    CEH (Certified Ethical Hacker)

    [ ] Domain 6: System Hacking (Privilege Escalation & DLL Injection)

    [ ] Domain 12: Mobile Platform Hacking (Jailbreaking & Rooting)

    SecAI+

    [ ] AI Security: Hardware Security (Protecting AI Model Weights on GPUs)

    [Timestamps]

    0:00 - Intro: You Can't Patch Physics

    0:45 - Hardware Roots of Trust: UEFI, TPM vs. HSM

    1:38 - Side-Channel Attacks: Spectre & Meltdown (Speculative Execution)

    2:07 - Supply Chain Interdiction

    2:25 - Virtualization Attacks: VM Sprawl vs. VM Escape (Hyperjacking)

    3:20 - Physical Memory Attacks: Rowhammer (Bit Flipping)

    3:45 - Memory Vulnerabilities: Buffer Overflow vs. Memory Leak

    4:40 - DLL Injection & Privilege Escalation

    5:05 - Mobile Security: Jailbreaking, Rooting, & Sideloading

    5:48 - Defense: MDM & Containerization (Samsung Knox)

    6:18 - Summary: Prioritizing Infrastructure Risk

    6:48 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=eu_viSkgSRU

    8 min
  • Threat Vectors & Attack Surfaces Explained

    A "Threat Vector" is the path; an "Attack Surface" is the target. If you can't distinguish between a message-based attack (Smishing) and a file-based attack (Malicious Macro), you will lose points on your exam and miss threats in your SOC. In this video, Sec Guy maps out the 7 critical threat vectors you need to know, from Supply Chain compromises to Voice-based social engineering.

    πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 2.1: Threat Actors, Vectors, and Intelligence Sources (Message, Image, File, Voice, Supply Chain)

    [ ] Domain 2.4: Social Engineering (Phishing, Vishing, Smishing)

    CISSP

    [ ] Domain 1: Security and Risk Management (Threat Modeling & Attack Surface Analysis)

    CISM

    [ ] Domain 2: Information Risk Management (Vulnerability & Threat Identification)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Threat Vectors & Emerging Risks)

    CCSP

    [ ] Domain 1: Cloud Concepts (Supply Chain Risk in Cloud Services)

    SecurityX (CompTIA)

    [ ] Domain 3.0: Security Operations (Analyzing Attack Vectors)

    GIAC GSEC (SANS)

    [ ] Incident Handling & Threat Intelligence: Attack Vectors

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 1: Threat Detection (Identifying Compromise Vectors)

    Pentest+ (CompTIA)

    [ ] Domain 1: Planning and Scoping (Attack Surface Mapping)

    CEH (Certified Ethical Hacker)

    [ ] Domain 1: Information Security Overview (Attack Vectors & Surfaces)

    SecAI+

    [ ] AI Security: Prompt Injection as a "Message-Based" Vector

    [Timestamps]

    0:00 - Intro: Vectors vs. Surfaces

    0:50 - Vector 1: Message-Based (Phishing, Smishing, BEC)

    1:36 - Vector 2: Unsecure Networks (Rogue AP, Evil Twin)

    2:17 - Vector 3: Social Engineering (Psychological Manipulation)

    2:52 - Vector 4: File-Based (Macros, PDF Payloads)

    3:28 - Vector 5: Voice Call (Vishing, MFA Fatigue)

    4:03 - Vector 6: Supply Chain (Compromised Vendors/Updates)

    4:43 - Vector 7: Vulnerable Software (Zero Days, Unpatched Systems)

    5:14 - Summary: Identifying the Path to the Asset

    5:40 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=gl3wbHTC7TY

    6 min
  • Security+ Domain 1: Question Walkthrough

    Join Sec Guy for an in-depth review of Domain 1 for the CompTIA Security+ (SY0-701) exam. This 10-question practice test covers everything from security principles and controls to governance and threat actors. Perfect for on-the-go studying!

    πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯

    0:00: Introduction to Domain 1: General Security Concepts.

    0:06: Overview of the exam weight (12% of total score)

    0:21: Q1

    1:05: Q2

    1:48: Q3

    2:26: Q4

    3:03: Q5

    3:49: Q6

    4:29: Q7

    5:03: Q8

    5:51: Q9

    6:31: Q10

    7:18: secguy.org

    7:27: secguy.org/exam-simulators

    7:36: secguy.org/discord

    Topic Categories: Information Technology, Cybersecurity, Education

    Key Topics Covered:

    CIA Triad: Confidentiality, Integrity, Availability

    AAA Framework: Authentication, Authorization, Accounting

    Security Control Types: Physical, Technical, Managerial, Operational

    Security Models: Zero Trust, Defense in Depth

    Processes: Change Management, Hashing, Digital Signatures

    #comptiasecurityplus #Security+ #cybersecurity #training #itcertification #Certifications #Sec Guy

    Original Sec Guy video: https://www.youtube.com/watch?v=_ajWLFMzxS0

    8 min
  • Threat Actors & Motivations

    If you don't know who is attacking you, you are just chasing ghosts. In this video, Sec Guy maps the adversary landscapeβ€”from highly funded Nation States (APTs) like Salt Typhoon to financially motivated Organized Crime groups like Scattered Spider. We also reveal why the "Insider Threat" and "Shadow IT" might be more dangerous to your organization than any elite foreign hacker.

    πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+ (SY0-701)

    [ ] Domain 2.1: Threat Actors, Vectors, and Intelligence Sources (Attributes & Motivations)

    CISSP

    [ ] Domain 1: Security and Risk Management (Threat Modeling & Risk Assessment)

    CISM

    [ ] Domain 1: Information Security Governance (Threat Landscape Analysis)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Threat Identification & Insider Risk)

    CCSP

    [ ] Domain 1: Cloud Concepts (Shadow IT Risks)

    SecurityX (CompTIA)

    [ ] Domain 3.0: Security Operations (Threat Hunting & Attribution)

    GIAC GSEC (SANS)

    [ ] Incident Handling & Threat Intelligence: Threat Actors

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 1: Threat Detection (Identifying Unauthorized Access/Shadow IT)

    Pentest+ (CompTIA)

    [ ] Domain 1: Planning and Scoping (Adversary Emulation)

    CEH (Certified Ethical Hacker)

    [ ] Domain 1: Information Security Overview (Cyber Kill Chain & Threat Concepts)

    SecAI+

    [ ] AI Security: Adversarial Machine Learning (Nation State AI Threats)

    [Timestamps]

    0:00 - Intro: Mapping the Adversary

    0:23 - Nation States (APTs): Espionage & Long Dwell Time (Salt Typhoon)

    1:03 - Organized Crime: Financial Motivation (Scattered Spider)

    1:27 - Hacktivists: Political Disruption (Belarusian Cyber Partisans)

    1:51 - Script Kiddies: Unskilled but Noisy

    2:09 - Insider Threats: Malicious vs. Negligent (The "Clicker")

    2:38 - Shadow IT: The Silent Killer of Compliance

    3:32 - Interview Challenge: Who is the Biggest Risk? (Elite Hacker vs. Admin)

    4:09 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=5Q00hR5OFBw

    5 min
  • Digital Signatures Explained: Non-repudiation, Hashing, Private Keys

    A digital signature is NOT just an image of your name on a PDF. It is a mathematical proof that guarantees three things: Authentication, Integrity, and Non-Repudiation. In this video, Sec Guy explains the exact workflow of signing a document (Hash - Encrypt with Private Key) and why this process makes it legally impossible for a sender to say "It wasn't me."

    πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 1.1: Cryptographic Concepts (Digital Signatures, Non-Repudiation)

    [ ] Domain 1.3: Identity and Access Management (Authentication Proof)

    CISSP

    [ ] Domain 3: Security Architecture (Digital Signatures & Message Digests)

    [ ] Domain 4: Communication & Network Security (Secure Email Standards - S/MIME)

    CISM

    [ ] Domain 2: Information Risk Management (Data Integrity & Non-Repudiation Controls)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Risks of Repudiation)

    CCSP

    [ ] Domain 2: Cloud Data Security (Data Integrity & Origin Authentication)

    SecurityX (CompTIA)

    [ ] Domain 2.0: Security Architecture (Implementing PKI & Digital Signatures)

    GIAC GSEC (SANS)

    [ ] Cryptography: Digital Signatures & Non-Repudiation

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Data Protection (Code Signing & Data Integrity)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Forging Signatures / Hash Collisions)

    CEH (Certified Ethical Hacker)

    [ ] Domain 4: Cryptography (Public Key Infrastructure & Signing)

    SecAI+

    [ ] AI Security: Model Signing (Verifying the Origin of AI Models)

    [Timestamps]

    0:00 - Intro: Digital Signatures vs. Wet Ink

    0:32 - The 3 Guarantees: Authentication, Integrity, Non-Repudiation

    0:46 - Step 1: Hashing the Data (Creating the Fingerprint)

    1:16 - Step 2: Encrypting the Hash with the PRIVATE Key

    1:38 - Step 3: Verification with the PUBLIC Key

    2:07 - Non-Repudiation: Why You Can't Deny It in Court

    2:34 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=49wx9ENRRo4

    4 min
  • Why Blockchain is Replacing Your Social Security Number

    Your Social Security Number is a password you can never changeβ€”and that is a security nightmare. In this video, Sec Guy explains why the future of identity isn't a static number in a database, but a cryptographic key in your wallet. We break down how Blockchain creates an immutable "Distributed Ledger" and how Self-Sovereign Identity (SSI) eliminates the single point of failure that hackers love.

    πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 1.1: Cryptographic Concepts (Blockchain, Distributed Ledger)

    [ ] Domain 1.3: Identity and Access Management (Decentralized Identity)

    CISSP

    [ ] Domain 3: Security Architecture (Distributed Systems & Consensus Models)

    [ ] Domain 5: Identity and Access Management (Federated Identity & SSI)

    CISM

    [ ] Domain 2: Information Risk Management (Emerging Technologies Risk)

    CRISC

    [ ] Domain 2: IT Risk Assessment (Risks of Centralized vs. Decentralized Data)

    CCSP

    [ ] Domain 1: Cloud Concepts (Blockchain as a Service - BaaS)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Implementing Blockchain for Integrity)

    GIAC GSEC (SANS)

    [ ] Cryptography: Blockchain Applications & Integrity

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Data Protection (Immutable Storage & Ledger Databases)

    Pentest+ (CompTIA)

    [ ] Domain 1: Planning and Scoping (Blockchain Attack Surfaces - 51% Attack)

    CEH (Certified Ethical Hacker)

    [ ] Domain 4: Cryptography (Blockchain Fundamentals)

    SecAI+

    [ ] AI Security: Proving Content Authenticity via Blockchain (C2PA)

    [Timestamps]

    0:00 - Intro: Bitcoin is an App, Blockchain is the OS

    0:35 - The Problem: SSNs are Static Passwords

    1:12 - Distributed Ledger Technology (DLT) & Immutability

    1:33 - Consensus Models: Why You Can't Hack the Chain

    1:53 - Decentralized Identity (DID) & Self-Sovereign Identity (SSI)

    2:20 - The Shift: From Database World to Wallet World

    2:42 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=MQNNVN_4AYc

    4 min
  • Zero Trust Architecture Explained (CompTIA Security+, CISSP, CEH, SecAI+, GIAC)

    "Trust but Verify" is a failed strategy. In today's cloud-native world, the only safe assumption is "Never Trust, Always Verify." In this deep dive, Sec Guy unpacks the NIST 800-207 Zero Trust Architecture, explains the critical difference between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP), and shows you how to stop lateral movement dead in its tracks.

    πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+

    [ ] Domain 1.2: Security Concepts (Zero Trust Control Plane/Data Plane)

    CISSP

    [ ] Domain 3: Security Architecture (Zero Trust Principles)

    [ ] Domain 5: Identity & Access Management (Just-in-Time Access)

    CISM

    [ ] Domain 2: Information Risk Management (Reducing Attack Surface)

    CRISC

    [ ] Domain 1: Governance (Zero Trust Strategy Implementation)

    CCSP

    [ ] Domain 1: Cloud Concepts (Zero Trust in Cloud Architecture)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Implementing ZTNA & SASE)

    GIAC GSEC (SANS)

    [ ] Access Control & Password Management: Zero Trust Network Access

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Infrastructure Security (Micro-segmentation & Least Privilege)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Lateral Movement in Zero Trust)

    CEH (Certified Ethical Hacker)

    [ ] Domain 6: System Hacking (Bypassing Micro-segmentation)

    SecAI+

    [ ] AI Security Fundamentals: Behavioral Biometrics & AI-Driven Trust Algorithms

    [Timestamps]

    0:00 - Intro: The Death of the Perimeter

    1:00 - The Core Principle: Never Trust, Always Verify (NIST 800-207)

    1:26 - Pillar 1: Assume Breach & Micro-segmentation

    2:20 - Pillar 2: Verify Explicitly (Context, Health, & Biometrics)

    3:05 - Pillar 3: Least Privilege Access (JIT Access)

    4:00 - Architecture Deep Dive: Control Plane vs. Data Plane

    4:40 - The Logical Components: Policy Engine (PDP) & Enforcement (PEP)

    6:45 - Continuous Adaptive Risk & Trust Assessment (CARTA) & AI

    7:33 - Technologies: ZTNA, SDP, & SASE

    8:44 - Non-Human Identities: Securing AI Agents & APIs

    10:00 - Summary: Strategy Over Products

    11:15 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=EWcfkEC4z8Y

    12 min
  • Mastering Access Control: RBAC, MAC, DAC & The AAA Framework

    If you can't prove who you are, what you're allowed to do, and track what you didβ€”you have no security. In this video, Sec Guy breaks down the AAA Framework (Authentication, Authorization, Accounting) and explains the critical differences between RBAC, MAC, and DAC that you must know for your exam and your career.

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+ (SY0-701)

    [ ] Domain 1.3: Identity and Access Management (Authentication Factors, MFA, AAA)

    [ ] Domain 1.4: Access Control Schemes (RBAC, MAC, DAC)

    CISSP

    [ ] Domain 5: Identity and Access Management (IAM Lifecycle, Access Control Models)

    CISM

    [ ] Domain 3: Information Security Program (Identity Management & Access Control)

    CRISC

    [ ] Domain 2: IT Risk Assessment (IAM Vulnerabilities)

    CCSP

    [ ] Domain 4: Cloud Application Security (Identity & Access Management in Cloud)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Enterprise IAM Strategies)

    GIAC GSEC (SANS)

    [ ] Access Control & Password Management: AAA, MFA, & Access Models

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 3: Infrastructure Security (IAM Policies & Roles)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Attacking Authentication & Authorization)

    CEH (Certified Ethical Hacker)

    [ ] Domain 6: System Hacking (Privilege Escalation & Password Cracking)

    SecAI+

    [ ] AI Security Fundamentals: Biometric Authentication & AI-Driven IAM

    [Timestamps]

    0:00 - Intro: The 3 Pillars of Access Control

    0:35 - The Airport Analogy: Understanding AAA

    1:00 - Authentication: Proving Who You Are (MFA vs. 2FA)

    2:52 - Authorization: What Are You Allowed To Do?

    3:15 - Access Control Models: RBAC vs. DAC vs. MAC

    4:50 - Principle of Least Privilege & Separation of Duties

    6:02 - Accounting: Logging & Non-Repudiation (SIEM)

    8:06 - Digital Signatures: Integrity & Authenticity

    9:08 - Summary: AAA Sec Guy Style

    9:55 - Outro: Stay Safe, Stay Secure.

    Original Sec Guy video: https://www.youtube.com/watch?v=eJm-Na32ljE

    11 min
  • Mastering Security Controls: Preventive, Detective, & Corrective

    Firewalls aren't enough. To build a true defense-in-depth strategy, you need to understand the three pillars of security controls: Preventive, Detective, and Corrective. In this video, Sec Guy breaks down how these controls work together to secure your network, using real-world analogies to make the concepts stick for your exam and your career.

    [Exam Ready Route - FREE]

    Pass your certification for $0.

    βœ… Training Videos & Practice Tests

    βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice)

    βœ… Discord Access (Study sessions & Industry networking)

    πŸ‘‰ Start Here: https://secguy.org

    [Job Ready Route - MEMBERSHIP]

    Stop studying and start working. Get the hands-on experience hiring managers are asking for.

    πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs

    πŸ”₯ Salary Negotiator Workshop

    πŸ”₯ Experience Builder: Real-world projects to fill your resume

    πŸ‘‰ Get Hired: https://secguy.org

    [Exam Domain Checklist]

    This video covers critical objectives for the following exams:

    Security+ (SY0-701)

    [ ] Domain 1.2: Types of Security Controls (Preventive, Detective, Corrective)

    CISSP

    [ ] Domain 3: Security Architecture (Control Selection)

    [ ] Domain 7: Security Operations (Foundational Concepts)

    CISM

    [ ] Domain 3: Information Security Program (Control Design & Implementation)

    CRISC

    [ ] Domain 3: Risk Response and Reporting (Control Design)

    CCSP

    [ ] Domain 1: Cloud Concepts & Architecture (Control Frameworks)

    SecurityX (CompTIA)

    [ ] Domain 1.0: Security Architecture (Enterprise Security Controls)

    GIAC GSEC (SANS)

    [ ] Network Security Essentials: Defense in Depth & Access Controls

    AWS CSS (Certified Security – Specialty)

    [ ] Domain 2: Infrastructure Security (Security Groups/NACLs as Preventive Controls)

    Pentest+ (CompTIA)

    [ ] Domain 3: Attacks and Exploits (Understanding Defenses to Bypass Them)

    CEH (Certified Ethical Hacker)

    [ ] Domain 1: Information Security Overview (Defense in Depth Fundamentals)

    SecAI+

    [ ] AI Security Fundamentals: Implementing Guardrails (Preventive Controls)

    [Timestamps]

    0:00 - Intro: The 3 Types of Security Controls

    0:58 - Preventive Controls: The Frontline Defenders (Firewalls, MFA)

    2:27 - Detective Controls: Spotting the Suspicious (IDS, Logs)

    3:42 - Corrective Controls: Fixing the Damage (Backups, Patching)

    4:42 - Summary: Building Defense in Depth

    5:32 - Outro: Stay Safe, Stay Secure.

    #CompTIASecurityPlus #CISSP #CISM #CyberSecurity #InfoSec #SecurityControls #SecGuy #SY0701 #NetworkDefense #CRISC #CCSP #ITTraining

    Original Sec Guy video: https://www.youtube.com/watch?v=cjMqzX1Vs0Q

    6 min

About Sec Guy

From the publisher's feed

Real cybersecurity training for the real world. We take the complex theories of CompTIA Security+ and SecAI+ and translate them into actionable skills. Whether…