
Sign up to save your podcasts
Or


"Security through Obscurity" is a delay tactic, not a defense strategy. In this video, Sec Guy explains why Obfuscation is different from Encryption, how hackers use Steganography to hide malware inside innocent JPEGs, and why Tokenization is the secret weapon for passing your PCI-DSS audits.
🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥
[Exam Ready Route - FREE]
Pass your certification for $0.
✅ Training Videos & Practice Tests
✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)
✅ Discord Access (Study sessions & Industry networking)
👉 Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
🔥 Salary Negotiator Workshop
🔥 Experience Builder: Real-world projects to fill your resume
👉 Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
[ ] Domain 1.2: Security Concepts (Obfuscation vs. Encryption)
[ ] Domain 2.3: Indicators of Malicious Activity (Steganography as an IOC)
CISSP
[ ] Domain 3: Security Architecture (Steganography & Covert Channels)
[ ] Domain 8: Software Development Security (Code Obfuscation)
CISM
[ ] Domain 2: Information Risk Management (Data Masking & Privacy Controls)
CRISC
[ ] Domain 2: IT Risk Assessment (Data Leakage via Covert Channels)
CCSP
[ ] Domain 2: Cloud Data Security (Tokenization & Masking)
SecurityX (CompTIA)
[ ] Domain 2.0: Security Architecture (Data Privacy Techniques)
GIAC GSEC (SANS)
[ ] Cryptography: Steganography & Obfuscation Techniques
AWS CSS (Certified Security – Specialty)
[ ] Domain 2: Data Protection (Tokenization for Compliance)
Pentest+ (CompTIA)
[ ] Domain 3: Attacks and Exploits (Evasion via Obfuscation)
CEH (Certified Ethical Hacker)
[ ] Domain 6: System Hacking (Steganography Tools & Detection)
SecAI+
[ ] AI Security: Obfuscating Training Data (Privacy Preserving AI)
[Timestamps]
0:00 - Intro: Security through Obscurity?
0:38 - The Golden Rule: Obfuscation is NOT Encryption
1:04 - Technique 1: Steganography (Hiding Data in Images/Audio)
1:29 - Technique 2: Tokenization (PCI-DSS & Compliance)
1:53 - Technique 3: Data Masking (Privacy & Usability)
2:10 - Technique 4: Code Obfuscation (Protecting IP)
2:30 - The Attack: Weaponizing Obfuscation (PowerShell & DNS)
3:08 - How to Practice: The Sec Guy Steganography Lab
3:35 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=BLXbe7vz6Sw
If you can't explain the difference between a "Private Key" and a "Public Key," you will fail your exam. In this video, Sec Guy breaks down the two main families of encryption, explains why we use Symmetric for speed (AES) and Asymmetric for security (RSA/ECC), and gives you the "23 BRAIDS" mnemonic to memorize every algorithm instantly.
🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥
[Exam Ready Route - FREE]
Pass your certification for $0.
✅ Training Videos & Practice Tests
✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)
✅ Discord Access (Study sessions & Industry networking)
👉 Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
🔥 Salary Negotiator Workshop
🔥 Experience Builder: Real-world projects to fill your resume
👉 Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
[ ] Domain 1.1: Cryptographic Concepts (Symmetric, Asymmetric, Key Exchange)
[ ] Domain 5.4: Data Protection (Data at Rest, In Transit, In Use)
CISSP
[ ] Domain 3: Security Architecture (Cryptographic Systems: AES, RSA, ECC)
CISM
[ ] Domain 2: Information Risk Management (Encryption Controls)
CRISC
[ ] Domain 2: IT Risk Assessment (Data Leakage Risks)
CCSP
[ ] Domain 2: Cloud Data Security (Encryption Strategies for Cloud Storage)
SecurityX (CompTIA)
[ ] Domain 2.0: Security Architecture (Implementing Cryptography)
GIAC GSEC (SANS)
[ ] Cryptography: Algorithms & Deployment
AWS CSS (Certified Security – Specialty)
[ ] Domain 2: Data Protection (KMS, S3 Encryption, TLS)
Pentest+ (CompTIA)
[ ] Domain 3: Attacks and Exploits (Weak Encryption & Downgrade Attacks)
CEH (Certified Ethical Hacker)
[ ] Domain 4: Cryptography (Cryptanalysis & PKI)
SecAI+
[ ] AI Security: Encrypting Model Weights & Training Data (Data at Rest)
[Timestamps]
0:00 - Intro: The Vault (Confidentiality)
0:30 - Symmetric Encryption: The "House Key" (Fast & Simple)
1:00 - The Key Exchange Problem (Out-of-Band)
1:18 - Mnemonic: "23 BRAIDS" (Symmetric Algos: Twofish, Blowfish, AES, DES)
1:40 - Mnemonic: "DEREK Q" (Asymmetric Algos: Diffie-Hellman, RSA, ECC, Quantum)
1:49 - AES: The Gold Standard for Hard Drives
2:17 - Asymmetric Encryption: The "Mailbox" (Public/Private Keys)
3:02 - RSA vs. ECC (Why Mobile Phones use ECC)
3:46 - Hybrid Encryption: How HTTPS Works (Best of Both Worlds)
4:08 - Data States: At Rest, In Transit, In Use
4:39 - Summary: AES for Bulk, RSA/ECC for Exchange
4:56 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=cA3vvpmWeI0
Hashing is NOT encryption—it's a one-way "meat grinder." In this video, Sec Guy explains the "Avalanche Effect," why MD5 and SHA-1 are dead, and how hackers use Rainbow Tables to crack unsalted passwords in milliseconds. If you don't understand the difference between a collision and a salt, you are not ready for your exam.
🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥
[Exam Ready Route - FREE]
Pass your certification for $0.
✅ Training Videos & Practice Tests
✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)
✅ Discord Access (Study sessions & Industry networking)
👉 Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
🔥 Salary Negotiator Workshop
🔥 Experience Builder: Real-world projects to fill your resume
👉 Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
[ ] Domain 1.1: Cryptographic Concepts (Hashing, Salting, Key Stretching)
[ ] Domain 4.1: Monitoring (File Integrity Monitoring / FIM)
CISSP
[ ] Domain 3: Security Architecture (One-Way Functions, Integrity, Message Digests)
[ ] Domain 5: Identity & Access Management (Secure Password Storage)
CISM
[ ] Domain 2: Information Risk Management (Data Integrity Controls)
CRISC
[ ] Domain 2: IT Risk Assessment (Compromise of Data Integrity)
CCSP
[ ] Domain 2: Cloud Data Security (Encryption & Hashing Standards)
SecurityX (CompTIA)
[ ] Domain 2.0: Security Architecture (Cryptographic Implementations & Algorithms)
GIAC GSEC (SANS)
[ ] Cryptography: Hash Functions, Integrity, & Rainbow Tables
AWS CSS (Certified Security – Specialty)
[ ] Domain 2: Data Protection (Data Integrity & Storage Security)
Pentest+ (CompTIA)
[ ] Domain 3: Attacks and Exploits (Password Cracking, Hash Collisions, Rainbow Tables)
CEH (Certified Ethical Hacker)
[ ] Domain 4: Cryptography (Hash Algorithms & Cryptanalysis Tools)
SecAI+
[ ] AI Security: Data Integrity (Hashing Training Data to Prevent Poisoning)
[Timestamps]
0:00 - Intro: Hashing = Integrity
0:28 - The Golden Rule: One-Way Function (The "Meat Grinder")
0:50 - The Avalanche Effect (Changing 1 Bit changes Everything)
1:21 - Algorithms: MD5 vs. SHA-1 vs. SHA-256 (The Gold Standard)
1:56 - Collisions: When Two Files Have the Same Hash
2:20 - Password Security: How Rainbow Tables Work
2:50 - The Solution: Salting Passwords
3:15 - Summary: One-Way, Integrity, & Salt
3:44 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=YjHTBFe7R14
We spend millions on firewalls, but if an insider can walk out the front door with your AI models in a backpack, your security program has failed. In this video, Sec Guy breaks down the Google AI theft case, explains why "Degaussing" destroys hard drives but fails on SSDs, and covers the critical exam concepts of CPTED, Man Traps, and Faraday Cages.
🔥🔥New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide 🔥🔥
[Exam Ready Route - FREE]
Pass your certification for $0.
✅ Training Videos & Practice Tests
✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)
✅ Discord Access (Study sessions & Industry networking)
👉 Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
🔥 Salary Negotiator Workshop
🔥 Experience Builder: Real-world projects to fill your resume
👉 Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+
[ ] Domain 2.4: Physical Security Controls (Man Traps, Faraday Cages, Air Gaps)
[ ] Domain 3.3: Data Destruction and Disposal (Degaussing vs. Shredding)
CISSP
[ ] Domain 3: Security Architecture (CPTED, Fire Suppression Classes)
[ ] Domain 7: Security Operations (Personnel Safety & Physical Access)
CISM
[ ] Domain 2: Information Risk Management (Physical Threats to Availability)
CRISC
[ ] Domain 2: IT Risk Assessment (Environmental Controls & Power Failure)
CCSP
[ ] Domain 2: Cloud Data Security (Data Center Physical Security Layers)
SecurityX (CompTIA)
[ ] Domain 3.0: Security Operations (Physical Breach Response)
GIAC GSEC (SANS)
[ ] Physical Security: Access Control, Lighting (Lux), & Perimeter Defense
AWS CSS (Certified Security – Specialty)
[ ] Domain 2: Infrastructure Security (Shared Responsibility: Physical Layer)
Pentest+ (CompTIA)
[ ] Domain 3: Attacks and Exploits (RFID Cloning, Tailgating, Badge Cloning)
CEH (Certified Ethical Hacker)
[ ] Domain 2: Footprinting (Physical Reconnaissance)
SecAI+
[ ] AI Security Fundamentals: Protecting AI Hardware (GPUs) & Model Weights
[Timestamps]
0:00 - Intro: The Google AI Theft (Insider Threat)
1:04 - Perimeter Security: CPTED & Lighting (Lux Levels)
2:20 - Authentication: Badge Cloning (Flipper Zero) & Man Traps
3:06 - Critical Exam Question: Fail Safe vs. Fail Secure (Human Safety)
3:30 - Securing AI Hardware: Caged Racks & Hot/Cold Aisles
4:30 - Environmental Controls: Fire Suppression (FM-200) & UPS
5:25 - High Security: Air Gaps & Faraday Cages
6:00 - Data Destruction: Degaussing (HDD) vs. Shredding (SSD)
6:42 - Summary: Physical Security is the Foundation
7:02 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=Kc9uIjwQDPU
Confidentiality, Integrity, and Availability aren't just buzzwords—they are the backbone of every security strategy you will ever build. In this video, Sec Guy breaks down the "CIA Triad" with real-world examples (like hospital outages and bank hacks) to show you exactly how these three principles keep systems secure and why they are the first thing tested on your exam.
[Exam Ready Route - FREE]
Pass your certification for $0.
✅ Training Videos & Practice Tests
✅ Sec Guy Mobile Lab (On-the-go training powered by AI voice)
✅ Discord Access (Study sessions & Industry networking)
👉 Start Here: https://secguy.org
[Job Ready Route - MEMBERSHIP]
Stop studying and start working. Get the hands-on experience hiring managers are asking for.
🔥 Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs
🔥 Salary Negotiator Workshop
🔥 Experience Builder: Real-world projects to fill your resume
👉 Get Hired: https://secguy.org
[Exam Domain Checklist]
This video covers critical objectives for the following exams:
Security+ (SY0-701)
[ ] Domain 1.1: General Security Concepts (CIA Triad)
CISSP
[ ] Domain 1: Security and Risk Management (Security Concepts)
CISM
[ ] Domain 1: Information Security Governance (Information Security Concepts)
CRISC
[ ] Domain 1: Governance (Organizational Goals & Objectives)
CCSP
[ ] Domain 1: Cloud Concepts & Architecture (CIA in the Cloud)
SecurityX (CompTIA)
[ ] Domain 1.0: Security Architecture (Foundational Principles)
GIAC GSEC (SANS)
[ ] Information Security Fundamentals: The CIA Triad
AWS CSS (Certified Security – Specialty)
[ ] Domain 1: Threat Detection and Incident Response (Impact on CIA)
Pentest+ (CompTIA)
[ ] Domain 1: Planning and Scoping (Confidentiality & Integrity Impact)
CEH (Certified Ethical Hacker)
[ ] Domain 1: Information Security Overview (Essential Terminology)
SecAI+
[ ] AI Security Fundamentals: Protecting Model Confidentiality & Integrity
[Timestamps]
0:00 - Intro: The Backbone of Security
0:32 - Real-World Example: The Hospital Hack
1:52 - Confidentiality: Keeping Secrets Secret (Encryption, MFA)
2:34 - Integrity: Trusting the Data (Hashing, Digital Signatures)
3:18 - Availability: Keeping Systems Running (Backups, Redundancy)
4:06 - Summary: The Foundation of Every Control
4:17 - Outro: Stay Safe, Stay Secure.
Original Sec Guy video: https://www.youtube.com/watch?v=hids4CADb6M
Welcome to the Sec Guy Channel and the start of your journey to becoming a cybersecurity professional! 🛡️ This is the first video in our comprehensive training series designed to help you pass the new CompTIA Security+ (SY0-701) exam.
In this foundational video, "Exam Overview," we're breaking down everything you need to know before you start studying the core content. Understanding the exam logistics is the first step to success!
🔑 What We Cover:
Exam Logistics: Format, number of questions, and scoring.
PBQs & Multiple Choice: What to expect from different question types.
Exam Objectives: A high-level look at the six domains you need to master.
Study Tips: Strategies for approaching the exam effectively.
Whether you're new to IT or looking to formalize your security knowledge, this series is for you.
🔔 Don't forget to Like, Comment, and Subscribe for more cybersecurity training! Hit the notification bell so you don't miss the next video in this series.
➡️ Next Video in the Series: [Link to next video when available]
📚 Resources Mentioned:
CompTIA Security+ (SY0-701) Objectives: https://www.comptia.org/en-us/certifications/security/
Recommended Study Materials:
Cheat Sheet: https://mega.nz/file/rVdWnQCL#oL80-0nSlu3_bs35fc52CO8UGCLmkqBC7way0CDKgZM
Practice Test
Domain 1: Test A: https://mega.nz/file/XYNySIYA#IG57yLOhdlD5VvMd1AdHTXaD9fVJg4ISsK7t9LRBIjQ
Domain 1: Test B: https://mega.nz/file/3IsSWQyD#Ak4Y0MOfqzOXBdSjTu0twaDsQqG-5OKQrwo0m8vYFZ4
Domain 1: Test C: https://mega.nz/file/6BVghCYS#vycOnNv3KkRRK0e7MMvSQ0gSFTw05FgmgSOlAMOjGcA
Domain 1: Test D: https://mega.nz/file/jZMkGLII#wc74MYCpBKWkM44mLFKcX4mrTngr-Q1bQ5rE1Xk6Xso
Connect with My Sec Guy Channel:
📘 Facebook: https://www.facebook.com/share/1HGdh1m51U/
#CompTIA #SecurityPlus #SY0701 #CybersecurityTraining #ITCertification #MySecGuy #ExamOverview #CyberSec #ITSecurity
Original Sec Guy video: https://www.youtube.com/watch?v=PjvDwhUA_GA
The Final Objective: Mastering the Law and Frameworks for global AI compliance.
In the finale of our SecAI+ course, we cover Objective 4.3: Compliance and Frameworks. We break down the EU AI Act's risk-based approach, the four core functions of the NIST AI RMF, and the critical ISO standards (42001, 23894, 22989) you need for the exam. Plus, learn about Data Sovereignty and how the OECD Principles impact security architecture.
📝 Pass the Exam: Take the practice quiz and join the Discord study group at: secguy.org
📍 Timestamps (Chapters):
00:00 – Introduction: The Law of AI
00:30 – The EU AI Act: Global Impact
00:44 – The 4 Levels of AI Risk & Regulation
01:43 – NIST AI Risk Management Framework (RMF)
02:13 – ISO 42001: AI Management Systems
02:29 – ISO 23894 & 22989: Risk & Terminology
02:58 – Data Sovereignty & GDPR
03:24 – Course Wrap-up: You're Ready!
#EUAIAct #NIST #ISO42001 #SecAI #CyberSecurityLaw #SecGuy
From the server room to the boardroom: Mastering AI GRC for the SecAI+ Exam.
This episode covers Domain 4: AI Governance, Risk, and Compliance. We explore the AI Center of Excellence (CoE), identify the Builders, Defenders, and Watchers on an AI team, and deep-dive into the dangers of Shadow AI. Learn the essential Responsible AI Principles—Fairness, Transparency, and Accountability—needed to pass objective 4.1.
🎓 Join the Mission: Get free practice tests and the Python for Security module at: secguy.org
📍 Timestamps (Chapters):
00:00 – Introduction to AI GRC (Domain 4)
00:28 – The AI Center of Excellence (CoE)
00:50 – Team Roles: Builders vs. Defenders
01:23 – Team Roles: The Watchers (Auditors & Analysts)
01:40 – Shadow AI vs. Shadow IT
02:17 – Beyond Data: Safety & Reputational Risk
02:35 – Responsible AI Principles: Fairness & Transparency
02:50 – Accountability = Human (Avoiding Bias)
03:13 – Coming Up: EU AI Act & Regulatory Frameworks
#AI #Governance #SecAI #CompTIA #RiskManagement #SecGuy
We have seen the weapons (Video 10). Now, let’s look at the shields. Welcome to Domain 3: AI-Assisted Security. In this video (Objective 3.3), we switch to the Blue Team.
We are breaking down the "AI Co-Pilot" stack, the new hardware you need to know for the exam, and the critical standard that connects AI to your internal data without causing a leak.
In this video, we cover:
The AI Co-Pilot: IDE vs. CLI Plugins (GitHub Copilot vs. Terminal Assistants).
Critical Exam Term: Model Context Protocol (MCP)—The standard for connecting AI to secure internal servers.
Analysis Tools: Vulnerability Analysis, Anomaly Detection, Summarization, and Real-Time Translation.
Hardware: NVIDIA Jetson Nano Orin (Edge AI) and Vector Databases.
Privacy: Using Ollama to run local LLMs and prevent data leaks.
Timecodes:
0:00 - Intro: Switching to the Blue Team
0:25 - The AI Co-Pilot (IDE vs. CLI Plugins)
1:00 - CRITICAL TERM: Model Context Protocol (MCP)
1:30 - Analysis Tools: Vuln Scans & Translation
2:15 - Anomaly Detection & Vector Databases
2:38 - Edge AI Hardware: NVIDIA Jetson Nano Orin
3:02 - Threat Hunting with Neo4j Graph Database
3:22 - Privacy Tools: Ollama & Local LLMs
3:45 - What’s Next: Automation & SOAR (Video 12)
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
#SecAI #CompTIA #BlueTeam #CyberDefense #MCP #ModelContextProtocol #Ollama #JetsonNano #CoPilot #Cybersecurity
🛡️ Domain 3: AI-Assisted Security (Objective 3.1)
We’ve analyzed the weapons in Domain 2—now it’s time to deploy the shields. Welcome to the Blue Team.
In this video, we break down the "AI Co-Pilot" stack and the defensive tools you need to master for the SecAI+ exam. From the hardware powering Edge AI to the critical protocols that secure internal data, this is your crash course in AI-assisted defense.
🚀 What We Cover in This Video:
The AI Co-Pilot Stack: Understanding the difference between IDE plugins (GitHub Copilot) and CLI Terminal Assistants.
CRITICAL Exam Concept: The Model Context Protocol (MCP)—the industry standard for connecting AI models to secure internal servers without risking data leaks.
Defensive Analysis: leveraging AI for vulnerability scanning, anomaly detection, automated summarization, and real-time translation.
Hardware & Architecture: A look at NVIDIA Jetson Nano Orin (Edge AI) and how Vector Databases power modern security tools.
Threat Hunting: visualizing threats with Neo4j Graph Databases.
Data Privacy: How to use Ollama to run local LLMs, ensuring your sensitive data never leaves the network.
⏱️ Timecodes
0:00 - Intro: Switching to the Blue Team
0:25 - The AI Co-Pilot (IDE vs. CLI Plugins)
1:00 - CRITICAL TERM: Model Context Protocol (MCP)
1:30 - Analysis Tools: Vuln Scans & Translation
2:15 - Anomaly Detection & Vector Databases
2:38 - Edge AI Hardware: NVIDIA Jetson Nano Orin
3:02 - Threat Hunting with Neo4j Graph Database
3:22 - Privacy Tools: Ollama & Local LLMs
3:45 - What’s Next: Automation & SOAR (Video 12)
📚 Resources & Support
🎓 FREE Interactive Learning Tools
Don't just watch—practice. Access our new browser-based tools to test your skills live.
AI-Powered Exam Simulators: https://secguy.org/exam-simulators
Python for Security Labs: https://secguy.org/python-practice
Mock Interview Board: https://secguy.org/mock-interview
💬 Join the Squad
Connect with other industry veterans and students in our new dedicated study group.
Official Discord: https://secguy.org/discord-chat
📚 Download Course Materials
Get the SecAI+ Cheat Sheet (including the MCP Architecture Diagram & Jetson specs) and full course slides directly from the academy.
Access Here: https://secguy.org/courses
Next Up: Domain 3.3: The AI Automator (SOAR & Agents)
#SecAI #CompTIA #BlueTeam #CyberDefense #MCP #ModelContextProtocol #Ollama #JetsonNano #CoPilot #Cybersecurity
From the publisher's feed
Real cybersecurity training for the real world. We take the complex theories of CompTIA Security+ and SecAI+ and translate them into actionable skills. Whether…
Train Hard. Stay Secure.