All certifications / SecurityX / Lessons
SecurityX CAS-005 lessons
Study SecurityX for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SecurityX study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Governance, risk and compliance
- Security governance components: policies, standards, procedures, guidelines and governance frameworks
- Security program management: roles and responsibilities (RACI), awareness training, metrics and reporting to leadership
- Change, configuration and asset management governance, including CMDB and data inventory
- Risk management activities: impact analysis, risk assessment, risk appetite and tolerance, risk treatment and risk registers
- Third-party and supply chain risk management: vendor assessments, SBOMs, contracts and right to audit
- Business continuity and disaster recovery planning: BIA, RTO, RPO and plan testing
- Compliance and regulatory impacts: GDPR, HIPAA, PCI DSS, SOX, data sovereignty and industry frameworks
- Security frameworks and standards: NIST CSF, NIST SP 800-53, ISO/IEC 27001, CIS Controls and CSA CCM
- Legal and privacy considerations: data subject rights, breach notification, e-discovery and legal holds
- Threat modeling methods: STRIDE, PASTA, attack trees, MITRE ATT&CK and attack surface analysis
- AI adoption challenges: AI governance, data privacy, prompt injection, model poisoning and acceptable use
Domain 2: Security architecture
- Resilient system design: high availability, redundancy, load balancing, geographic dispersion and graceful degradation
- Secure network architecture: segmentation, microsegmentation, screened subnets, NAC and software-defined networking
- Zero trust architecture: policy decision and enforcement points, continuous verification and least privilege
- Security in the software development life cycle: requirements, secure design reviews, SAST, DAST, SCA and CI/CD pipeline security
- Integrating security controls and troubleshooting: firewalls, WAF, proxies, IDS/IPS, SIEM and log collection
- Data security architecture: classification, labeling, DLP, data lifecycle, tokenization and masking
- Identity and access architecture: federation (SAML, OIDC, OAuth 2.0), SSO, conditional access and privileged access management
- Cloud security architecture: shared responsibility, CASB, SASE, cloud workload protection and CSPM
- Container and serverless security: image scanning, orchestration hardening, secrets management and API gateways
- Hybrid and multicloud design: connectivity, key management, consistent policy and cloud-to-on-premises integration
- Secure architecture for remote access and collaboration: VPN, ZTNA, VDI and secure email gateways
Domain 3: Security engineering
- Troubleshooting IAM: authentication failures, federation trust issues, certificate-based auth and MFA problems
- Endpoint and server hardening: secure baselines, application allow lists, EDR, host firewalls and patching
- Hardware security: TPM, HSM, secure boot, measured boot, secure enclaves and firmware integrity
- Specialized and legacy systems: OT/ICS/SCADA, IoT, embedded systems and compensating controls
- Security automation: scripting (PowerShell, Python, Bash), SOAR playbooks, infrastructure as code and configuration drift
- Advanced cryptographic concepts: post-quantum cryptography, key stretching, forward secrecy, homomorphic encryption and envelope encryption
- Cryptographic use cases: data at rest, in transit and in use, code signing, digital signatures and secure key exchange
- PKI engineering: certificate lifecycle, CA hierarchy, OCSP and CRLs, certificate pinning and mutual TLS
- Email and DNS security engineering: SPF, DKIM, DMARC, DNSSEC and S/MIME
- Mobile and endpoint management: MDM/UEM, containerization, device attestation and BYOD controls
- Secrets and key management: vaults, key rotation, KMS, hardware-backed keys and separation of duties
- Secure configuration of network infrastructure: SNMPv3, SSH, management plane protection and secure routing
Domain 4: Security operations
- Monitoring and response data: SIEM correlation, log aggregation, event parsing, baselines and alert tuning
- Threat intelligence: sources, STIX/TAXII, indicators of compromise, TTPs and intelligence sharing
- Threat hunting: hypothesis-driven hunts, behavioral analytics, UEBA and hunting in endpoint telemetry
- Vulnerability management: scanning, CVSS and EPSS prioritization, false positives and remediation tracking
- Analyzing vulnerabilities and attacks: injection, deserialization, race conditions, memory safety and misconfigurations
- Malware and indicator analysis: static vs dynamic analysis, sandboxing, YARA rules and file hashing
- Incident response process: preparation, detection, containment, eradication, recovery and lessons learned
- Digital forensics: order of volatility, chain of custody, memory and disk acquisition, and timeline analysis
- Attack surface management and exposure reduction: asset discovery, external scanning and penetration test findings
- Detection engineering: writing and testing detection rules, Sigma, MITRE ATT&CK coverage mapping and deception technologies