Introduction
Practical cybersecurity fundamentals: Introduction
()
Lesson 1: Security Principles
Module 1: Cybersecurity fundamentals introduction
()
Learning objectives
()
Understanding the security concepts of information assurance
()
Understanding the risk management process
()
Understanding security controls
()
Understanding governance processes
()
Building your cybersecurity lab
()
Lesson 2: Business Continuity (BC), Disaster Recovery (DR), and Incident Response Concepts
Understanding business continuity (BC)
()
Understanding disaster recovery (DR)
()
Understanding incident response
()
Lesson 3: Access Control Concepts
Learning objectives
()
Understanding physical access controls
()
Exploring the principle of least privilege
()
Understanding the concept of segregation of duties
()
Introducing discretionary access control (DAC)
()
Understanding mandatory access control (MAC)
()
Understanding role-based access control (RBAC)
()
Lesson 4: Network Security
Learning objectives
()
Understanding computer networking
()
Understanding network threats and attacks
()
Understanding network security infrastructure
()
Introducing network segmentation
()
Introducing cloud security
()
Lesson 5: Security Operations
Understanding data security
()
Understanding hashing
()
Understanding system hardening
()
Understanding best practice security policies
()
Understanding security awareness training
()
Lesson 6: Software Defined Networking and Infrastructure as Code
Software defined networking security
()
Understanding the threats against SDN solutions
()
Introducing network programmability
()
Introducing SD-WAN and modern architectures
()
Surveying the OWASP Top 10
()
Lesson 7: Cryptography
Learning objectives
()
Introducing cryptography and cryptanalysis
()
Understanding encryption protocols
()
Describing hashing algorithms
()
Introducing public key infrastructure (PKI)
()
Introducing certificate authorities (CAs) and certificate enrollment
()
Surveying SSL and TLS implementations
()
Surveying IPsec implementations and modern VPN implementations
()
Lesson 8: AAA, Identity Management, Network Visibility, and Segmentation
Introducing AAA and identity management
()
Implementing zero trust and multifactor authentication
()
Understanding identity management in the cloud
()
Surveying single-sign on (SSO) implementations
()
Lesson 9: Incident Response Fundamentals
Module 2: Incident response, digital forensics, and threat hunting introduction
()
Learning objectives
()
Exploring how to get started in incident response
()
Understanding the incident response process
()
Defining playbooks and run book automation (RBA)
()
Understanding cyber threat intelligence (CTI)
()
Understanding data normalization
()
Deconstructing universal data formats and 5-tuple correlation
()
Understanding security monitoring fundamentals
()
Surveying security monitoring tools
()
Lesson 10: Threat Hunting Fundamentals
Learning objectives
()
Introducing the threat hunting process
()
MITRE’s adversarial tactics, techniques, and common knowledge (ATT&CK®)
()
Understanding automated adversarial emulation
()
Lesson 11: Digital Forensics
Learning objectives
()
Introducing digital forensics
()
Introducing reverse engineering
()
Understanding evidence preservation and chain of custody
()
Collecting evidence from endpoints and servers
()
Collecting evidence from mobile and IoT devices
()
Exploring memory analysis with Volatility
()
Lesson 12: Introduction to Security Penetration Testing and Bug Hunting
Module 3: Ethical hacking, penetration testing, and bug hunting introduction
()
How to start a career in ethical hacking
()
Understanding the difference between traditional pen testing, bug bounties, and red team assessments
()
Exploring bug bounty programs
()
Understanding the ethical hacking and bug hunting methodology
()
Planning and scoping a penetration testing assessment
()
Lesson 13: Passive Reconnaissance and OSINT
Learning objectives
()
Understanding information gathering and vulnerability identification
()
Introducing open source intelligence (OSINT) techniques
()
Performing DNS-based passive recon
()
Identifying cloud vs. self-hosted assets
()
Introducing Shodan, Maltego, AMass, Recon-NG, and other recon tools
()
Surveying password dumps, file metadata, and public source-code repositories
()
Introduction to Google hacking and search engine reconnaissance
()
Lesson 14: Active Reconnaissance, Enumeration, and Scanning
Learning objectives
()
Introduction to host and service enumeration
()
Mastering Nmap
()
Performing website and web application reconnaissance
()
Discovering cloud assets
()
Crafting packets with Scapy to perform reconnaissance
()
Lesson 15: Exploiting Systems and Applications
Learning objectives
()
Performing on-path attacks
()
Exploring the OWASP Top 10 risks in web applications
()
Exploiting cross-site scripting (XSS) and cross-site request forgery (CSRF) vulnerabilities
()
Understanding server-side request forgery (SSRF) vulnerabilities
()
Hacking databases
()
Exploiting wireless vulnerabilities
()
Exploiting buffer overflows and creating payloads
()
Lesson 16: Post Exploitation Techniques and Reporting
Learning objectives
()
Avoiding detection and evading security tools
()
Introduction to lateral movement and exfiltration
()
Exploring command and control (C2) techniques
()
Understanding living-off-the-land and fileless malware
()
Best practices when creating pen testing and bug bounty reports
()
Understanding post-engagement cleanup
()
Lesson 17: Cloud Security Concepts
Module 4: Cloud, DevOps, and IoT security introduction
()
Learning objectives
()
Introducing the different cloud deployment and service models
()
Surveying patch management in the cloud
()
Performing security assessments in cloud environments
()
Exploring cloud logging and monitoring methodologies
()
Lesson 18: DevSecOps
Learning objectives
()
Introducing DevSecOps
()
Securing code, applications, and building DevSecOps pipelines
()
Lesson 19: IoT Security
Learning objectives
()
Introducing IoT concepts
()
Surveying IoT hacking methodologies and IoT hacking tools
()
Introducing OT, ICS, and SCADA concepts and attacks
()
Lesson 20: Introduction to AI Security
Module 5: AI security, ethics, and privacy: Balancing innovation with protection introduction
()
Learning objectives
()
Surveying the AI landscape and use cases
()
Exploring LLMs, ChatGPT, Co-pilot and more
()
Understanding the importance of AI security
()
Exploring the OWASP Top 10 for LLMs
()
Lesson 21: A Deep Dive into the Different Types of AI Threats
Learning objectives
()
Exploring data poisoning attacks
()
Understanding model inversion attacks
()
Discussing membership inference attacks
()
Explaining the model theft attack
()
Introducing MITRE’s ATLAS
()
Lesson 22: Principles of Secure AI Development
Learning objectives
()
Exploring the secure AI development lifecycle
()
Understanding privacy-preserving AI techniques
()
Understanding robustness and resilience in AI models
()
Surveying AI security best practices
()
Exploring AI security tools and frameworks
()
Understanding the legal landscape and potential new regulations
()
Investigating ethical implications of artificial intelligence
()
Summary
Practical cybersecurity fundamentals: Summary
()