Complete Guide to Cybersecurity: A Practical Approach

Complete Guide to Cybersecurity: A Practical Approach

14h 21mBeginner2024-10-16

Authors

Pearson

Pearson

Omar Santos

Omar Santos

Course details

Looking to jumpstart your journey as a cybersecurity professional? This course was designed for you. Join instructor and cybersecurity expert Omar Santos as he takes you on a deep dive into the fundamentals of cybersecurity with practical demos and real-world examples that allow you to test out your new skills as you go. There’s never been a better time to pursue a career in cybersecurity, so why not get started today? A great fit for anyone looking to learn more about industry prospects, this course equips you with the core concepts and technical skills required to start working toward becoming a cybersecurity professional.

Skills covered

Security TestingIncident ResponseCybersecurityOne-Off

Concepts

Introduction

  • Practical cybersecurity fundamentals - Introduction

Lesson 1 - Security Principles

  • Module 1 - Cybersecurity fundamentals introduction
  • Learning objectives
  • Understanding the security concepts of information assurance
  • Understanding the risk management process
  • Understanding security controls
  • Understanding governance processes
  • Building your cybersecurity lab

Lesson 2 - Business Continuity (BC), Disaster Recovery (DR), and Incident Response Concepts

  • Learning objectives
  • Understanding business continuity (BC)
  • Understanding disaster recovery (DR)
  • Understanding incident response

Lesson 3 - Access Control Concepts

  • Learning objectives
  • Understanding physical access controls
  • Exploring the principle of least privilege
  • Understanding the concept of segregation of duties
  • Introducing discretionary access control (DAC)
  • Understanding mandatory access control (MAC)
  • Understanding role-based access control (RBAC)

Lesson 4 - Network Security

  • Learning objectives
  • Understanding computer networking
  • Understanding network threats and attacks
  • Understanding network security infrastructure
  • Introducing network segmentation
  • Introducing cloud security

Lesson 5 - Security Operations

  • Learning objectives
  • Understanding data security
  • Understanding hashing
  • Understanding system hardening
  • Understanding best practice security policies
  • Understanding security awareness training

Lesson 6 - Software Defined Networking and Infrastructure as Code

  • Learning objectives
  • Software defined networking security
  • Understanding the threats against SDN solutions
  • Introducing network programmability
  • Introducing SD-WAN and modern architectures
  • Surveying the OWASP Top 10

Lesson 7 - Cryptography

  • Learning objectives
  • Introducing cryptography and cryptanalysis
  • Understanding encryption protocols
  • Describing hashing algorithms
  • Introducing public key infrastructure (PKI)
  • Introducing certificate authorities (CAs) and certificate enrollment
  • Surveying SSL and TLS implementations
  • Surveying IPsec implementations and modern VPN implementations

Lesson 8 - AAA, Identity Management, Network Visibility, and Segmentation

  • Learning objectives
  • Introducing AAA and identity management
  • Implementing zero trust and multifactor authentication
  • Understanding identity management in the cloud
  • Surveying single-sign on (SSO) implementations

Lesson 9 - Incident Response Fundamentals

  • Module 2 - Incident response, digital forensics, and threat hunting introduction
  • Learning objectives
  • Exploring how to get started in incident response
  • Understanding the incident response process
  • Defining playbooks and run book automation (RBA)
  • Understanding cyber threat intelligence (CTI)
  • Understanding data normalization
  • Deconstructing universal data formats and 5-tuple correlation
  • Understanding security monitoring fundamentals
  • Surveying security monitoring tools

Lesson 10 - Threat Hunting Fundamentals

  • Learning objectives
  • Introducing the threat hunting process
  • MITRE s adversarial tactics, techniques, and common knowledge (ATT&CK )
  • Understanding automated adversarial emulation

Lesson 11 - Digital Forensics

  • Learning objectives
  • Introducing digital forensics
  • Introducing reverse engineering
  • Understanding evidence preservation and chain of custody
  • Collecting evidence from endpoints and servers
  • Collecting evidence from mobile and IoT devices
  • Exploring memory analysis with Volatility

Lesson 12 - Introduction to Security Penetration Testing and Bug Hunting

  • Module 3 - Ethical hacking, penetration testing, and bug hunting introduction
  • Learning objectives
  • How to start a career in ethical hacking
  • Understanding the difference between traditional pen testing, bug bounties, and red team assessments
  • Exploring bug bounty programs
  • Understanding the ethical hacking and bug hunting methodology
  • Planning and scoping a penetration testing assessment

Lesson 13 - Passive Reconnaissance and OSINT

  • Learning objectives
  • Understanding information gathering and vulnerability identification
  • Introducing open source intelligence (OSINT) techniques
  • Performing DNS-based passive recon
  • Identifying cloud vs. self-hosted assets
  • Introducing Shodan, Maltego, AMass, Recon-NG, and other recon tools
  • Surveying password dumps, file metadata, and public source-code repositories
  • Introduction to Google hacking and search engine reconnaissance

Lesson 14 - Active Reconnaissance, Enumeration, and Scanning

  • Learning objectives
  • Introduction to host and service enumeration
  • Mastering Nmap
  • Performing website and web application reconnaissance
  • Discovering cloud assets
  • Crafting packets with Scapy to perform reconnaissance

Lesson 15 - Exploiting Systems and Applications

  • Learning objectives
  • Performing on-path attacks
  • Exploring the OWASP Top 10 risks in web applications
  • Exploiting cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities
  • Understanding server-side request forgery (SSRF) vulnerabilities
  • Hacking databases
  • Exploiting wireless vulnerabilities
  • Exploiting buffer overflows and creating payloads

Lesson 16 - Post Exploitation Techniques and Reporting

  • Learning objectives
  • Avoiding detection and evading security tools
  • Introduction to lateral movement and exfiltration
  • Exploring command and control (C2) techniques
  • Understanding living-off-the-land and fileless malware
  • Best practices when creating pen testing and bug bounty reports
  • Understanding post-engagement cleanup

Lesson 17 - Cloud Security Concepts

  • Module 4 - Cloud, DevOps, and IoT security introduction
  • Learning objectives
  • Introducing the different cloud deployment and service models
  • Surveying patch management in the cloud
  • Performing security assessments in cloud environments
  • Exploring cloud logging and monitoring methodologies

Lesson 18 - DevSecOps

  • Learning objectives
  • Introducing DevSecOps
  • Securing code, applications, and building DevSecOps pipelines

Lesson 19 - IoT Security

  • Learning objectives
  • Introducing IoT concepts
  • Surveying IoT hacking methodologies and IoT hacking tools
  • Introducing OT, ICS, and SCADA concepts and attacks

Lesson 20 - Introduction to AI Security

  • Module 5 - AI security, ethics, and privacy - Balancing innovation with protection introduction
  • Learning objectives
  • Surveying the AI landscape and use cases
  • Exploring LLMs, ChatGPT, Co-pilot and more
  • Understanding the importance of AI security
  • Exploring the OWASP Top 10 for LLMs

Lesson 21 - A Deep Dive into the Different Types of AI Threats

  • Learning objectives
  • Exploring data poisoning attacks
  • Understanding model inversion attacks
  • Discussing membership inference attacks
  • Explaining the model theft attack
  • Introducing MITRE s ATLAS

Lesson 22 - Principles of Secure AI Development

  • Learning objectives
  • Exploring the secure AI development lifecycle
  • Understanding privacy-preserving AI techniques
  • Understanding robustness and resilience in AI models
  • Surveying AI security best practices
  • Exploring AI security tools and frameworks
  • Understanding the legal landscape and potential new regulations
  • Investigating ethical implications of artificial intelligence

Summary

  • Practical cybersecurity fundamentals - Summary
200,000 Toman