SEC401: Security Essentials: Network, Endpoint, and Cloud GSEC Security Essentials giac.org/gsec This course will show you the most effective steps to prevent attacks and detect adversaries with actionable techniques that can be used as soon as you get back to work. You’ll learn tips and tricks designed to help you win the battle against the wide range of cyber adversaries that want to harm your environment. Organizations are going to be targeted, so they must be prepared for eventual compromise. Today more than ever before, TIMELY detection and response is critical. The longer an adversary is present in your environment, the more devastating and damaging the impact becomes. The most important question in information security may well be, “How quickly can we detect, respond, and REMEDIATE an adversary?” Information security is all about making sure you focus on the right areas of defense, especially as applied to the uniqueness of YOUR organization. In SEC401 you will learn the language and underlying workings of computer and information security, and how best to apply them to your unique needs. You will gain the essential and effective security knowledge you will need if you are given the responsibility to secure systems and/or organizations. Whether you are new to information security or a seasoned practitioner with a specialized focus, SEC401 will provide the essential information security skills and techniques you need to protect and secure your organization’s critical information and technology assets, whether on-premise or in the cloud. SEC401 will also show you how to directly apply the concepts learned into a winning defensive strategy, all in the terms of the modern adversary. This is how we fight; this is how we win! Is SEC401: Security Essentials: Network, Endpoint, and Cloud the right course for you? Ask yourself the following questions: • Do you fully understand why some organizations become compromised and others do not? • If there were compromised systems on your network, are you confident that you would be able to find them? • Do you understand the effectiveness of each security control and are you certain that they are all configured correctly? • Are the proper security metrics set up and communicated to your executives to help drive the best security decisions? SEC401 provides the information security knowledge necessary to help you answer these questions, delivered in a bootcamp-style format and reinforced with hands-on labs. You Will Be Able To • Understand the core areas of cybersecurity and how to create a security program that is built on a foundation of Detection, Response, and Prevention • Apply practical tips and tricks that focus on addressing high-priority security problems within your organization and doing the right things that lead to security solutions that work • Understand how adversaries adapt tactics and techniques, and importantly how to adapt your defense accordingly • Know what ransomware is and how to better defend against it • Leverage a defensible network architecture (VLANs, NAC, and 802.1x) based on advanced persistent threat indicators of compromise • Understand the Identity and Access Management (IAM) methodology, including aspects of strong authentication (Multi-Factor Authentication) • Leverage the strengths and differences among the top three cloud providers (Amazon, Microsoft, and Google), including the concepts of multi-cloud • Identify visible weaknesses of a system using various tools and, once vulnerabilities are discovered, configure the system to be more secure (realistic and practical application of a capable vulnerability management program) • Sniff network communication protocols to determine the content of network communication (including access credentials) using tools such as tcpdump and Wireshark • Use Windows, Linux, and macOS command line tools to analyze a system looking for high-risk indicators of compromise, as well as the concepts of basic scripting for the automation of continuous monitoring • Build a network visibility map that can be used to validate the attack surface and determine the best methodology to reduce the attack surface through hardening and configuration management • Know why some organizations win and some lose when it comes to security, and most importantly, how to be on the winning side 6 Day Program 46 CPEs Laptop Required sans.org/sec401 • Watch a preview of this course • Discover how to take this course: Online, In-Person “ SEC401 gives you a fantastic knowledge base to build on, and I would say it’s essential for anyone working in cybersecurity.” — Thomas Wilson, Agile Systems