Complete Guide to Cybersecurity: A Practical Approach
14h 21mBeginner2024-10-16
Authors

Pearson

Omar Santos
Course details
Looking to jumpstart your journey as a cybersecurity professional? This course was designed for you. Join instructor and cybersecurity expert Omar Santos as he takes you on a deep dive into the fundamentals of cybersecurity with practical demos and real-world examples that allow you to test out your new skills as you go. There’s never been a better time to pursue a career in cybersecurity, so why not get started today? A great fit for anyone looking to learn more about industry prospects, this course equips you with the core concepts and technical skills required to start working toward becoming a cybersecurity professional.
Skills covered
Security TestingIncident ResponseCybersecurityOne-Off
Concepts
Introduction
- Practical cybersecurity fundamentals - Introduction
Lesson 1 - Security Principles
- Module 1 - Cybersecurity fundamentals introduction
- Learning objectives
- Understanding the security concepts of information assurance
- Understanding the risk management process
- Understanding security controls
- Understanding governance processes
- Building your cybersecurity lab
Lesson 2 - Business Continuity (BC), Disaster Recovery (DR), and Incident Response Concepts
- Learning objectives
- Understanding business continuity (BC)
- Understanding disaster recovery (DR)
- Understanding incident response
Lesson 3 - Access Control Concepts
- Learning objectives
- Understanding physical access controls
- Exploring the principle of least privilege
- Understanding the concept of segregation of duties
- Introducing discretionary access control (DAC)
- Understanding mandatory access control (MAC)
- Understanding role-based access control (RBAC)
Lesson 4 - Network Security
- Learning objectives
- Understanding computer networking
- Understanding network threats and attacks
- Understanding network security infrastructure
- Introducing network segmentation
- Introducing cloud security
Lesson 5 - Security Operations
- Learning objectives
- Understanding data security
- Understanding hashing
- Understanding system hardening
- Understanding best practice security policies
- Understanding security awareness training
Lesson 6 - Software Defined Networking and Infrastructure as Code
- Learning objectives
- Software defined networking security
- Understanding the threats against SDN solutions
- Introducing network programmability
- Introducing SD-WAN and modern architectures
- Surveying the OWASP Top 10
Lesson 7 - Cryptography
- Learning objectives
- Introducing cryptography and cryptanalysis
- Understanding encryption protocols
- Describing hashing algorithms
- Introducing public key infrastructure (PKI)
- Introducing certificate authorities (CAs) and certificate enrollment
- Surveying SSL and TLS implementations
- Surveying IPsec implementations and modern VPN implementations
Lesson 8 - AAA, Identity Management, Network Visibility, and Segmentation
- Learning objectives
- Introducing AAA and identity management
- Implementing zero trust and multifactor authentication
- Understanding identity management in the cloud
- Surveying single-sign on (SSO) implementations
Lesson 9 - Incident Response Fundamentals
- Module 2 - Incident response, digital forensics, and threat hunting introduction
- Learning objectives
- Exploring how to get started in incident response
- Understanding the incident response process
- Defining playbooks and run book automation (RBA)
- Understanding cyber threat intelligence (CTI)
- Understanding data normalization
- Deconstructing universal data formats and 5-tuple correlation
- Understanding security monitoring fundamentals
- Surveying security monitoring tools
Lesson 10 - Threat Hunting Fundamentals
- Learning objectives
- Introducing the threat hunting process
- MITRE s adversarial tactics, techniques, and common knowledge (ATT&CK )
- Understanding automated adversarial emulation
Lesson 11 - Digital Forensics
- Learning objectives
- Introducing digital forensics
- Introducing reverse engineering
- Understanding evidence preservation and chain of custody
- Collecting evidence from endpoints and servers
- Collecting evidence from mobile and IoT devices
- Exploring memory analysis with Volatility
Lesson 12 - Introduction to Security Penetration Testing and Bug Hunting
- Module 3 - Ethical hacking, penetration testing, and bug hunting introduction
- Learning objectives
- How to start a career in ethical hacking
- Understanding the difference between traditional pen testing, bug bounties, and red team assessments
- Exploring bug bounty programs
- Understanding the ethical hacking and bug hunting methodology
- Planning and scoping a penetration testing assessment
Lesson 13 - Passive Reconnaissance and OSINT
- Learning objectives
- Understanding information gathering and vulnerability identification
- Introducing open source intelligence (OSINT) techniques
- Performing DNS-based passive recon
- Identifying cloud vs. self-hosted assets
- Introducing Shodan, Maltego, AMass, Recon-NG, and other recon tools
- Surveying password dumps, file metadata, and public source-code repositories
- Introduction to Google hacking and search engine reconnaissance
Lesson 14 - Active Reconnaissance, Enumeration, and Scanning
- Learning objectives
- Introduction to host and service enumeration
- Mastering Nmap
- Performing website and web application reconnaissance
- Discovering cloud assets
- Crafting packets with Scapy to perform reconnaissance
Lesson 15 - Exploiting Systems and Applications
- Learning objectives
- Performing on-path attacks
- Exploring the OWASP Top 10 risks in web applications
- Exploiting cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities
- Understanding server-side request forgery (SSRF) vulnerabilities
- Hacking databases
- Exploiting wireless vulnerabilities
- Exploiting buffer overflows and creating payloads
Lesson 16 - Post Exploitation Techniques and Reporting
- Learning objectives
- Avoiding detection and evading security tools
- Introduction to lateral movement and exfiltration
- Exploring command and control (C2) techniques
- Understanding living-off-the-land and fileless malware
- Best practices when creating pen testing and bug bounty reports
- Understanding post-engagement cleanup
Lesson 17 - Cloud Security Concepts
- Module 4 - Cloud, DevOps, and IoT security introduction
- Learning objectives
- Introducing the different cloud deployment and service models
- Surveying patch management in the cloud
- Performing security assessments in cloud environments
- Exploring cloud logging and monitoring methodologies
Lesson 18 - DevSecOps
- Learning objectives
- Introducing DevSecOps
- Securing code, applications, and building DevSecOps pipelines
Lesson 19 - IoT Security
- Learning objectives
- Introducing IoT concepts
- Surveying IoT hacking methodologies and IoT hacking tools
- Introducing OT, ICS, and SCADA concepts and attacks
Lesson 20 - Introduction to AI Security
- Module 5 - AI security, ethics, and privacy - Balancing innovation with protection introduction
- Learning objectives
- Surveying the AI landscape and use cases
- Exploring LLMs, ChatGPT, Co-pilot and more
- Understanding the importance of AI security
- Exploring the OWASP Top 10 for LLMs
Lesson 21 - A Deep Dive into the Different Types of AI Threats
- Learning objectives
- Exploring data poisoning attacks
- Understanding model inversion attacks
- Discussing membership inference attacks
- Explaining the model theft attack
- Introducing MITRE s ATLAS
Lesson 22 - Principles of Secure AI Development
- Learning objectives
- Exploring the secure AI development lifecycle
- Understanding privacy-preserving AI techniques
- Understanding robustness and resilience in AI models
- Surveying AI security best practices
- Exploring AI security tools and frameworks
- Understanding the legal landscape and potential new regulations
- Investigating ethical implications of artificial intelligence
Summary
- Practical cybersecurity fundamentals - Summary