Sec Guy

Sec Guy

by Sec Guy
Season 4

Digital Signatures Explained: Non-repudiation, Hashing, Private Keys

A digital signature is NOT just an image of your name on a PDF. It is a mathematical proof that guarantees three things: Authentication, Integrity, and Non-Repudiation. In this video, Sec Guy explains the exact workflow of signing a document (Hash - Encrypt with Private Key) and why this process makes it legally impossible for a sender to say "It wasn't me." πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 1.1: Cryptographic Concepts (Digital Signatures, Non-Repudiation) [ ] Domain 1.3: Identity and Access Management (Authentication Proof) CISSP [ ] Domain 3: Security Architecture (Digital Signatures & Message Digests) [ ] Domain 4: Communication & Network Security (Secure Email Standards - S/MIME) CISM [ ] Domain 2: Information Risk Management (Data Integrity & Non-Repudiation Controls) CRISC [ ] Domain 2: IT Risk Assessment (Risks of Repudiation) CCSP [ ] Domain 2: Cloud Data Security (Data Integrity & Origin Authentication) SecurityX (CompTIA) [ ] Domain 2.0: Security Architecture (Implementing PKI & Digital Signatures) GIAC GSEC (SANS) [ ] Cryptography: Digital Signatures & Non-Repudiation AWS CSS (Certified Security – Specialty) [ ] Domain 2: Data Protection (Code Signing & Data Integrity) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Forging Signatures / Hash Collisions) CEH (Certified Ethical Hacker) [ ] Domain 4: Cryptography (Public Key Infrastructure & Signing) SecAI+ [ ] AI Security: Model Signing (Verifying the Origin of AI Models) [Timestamps] 0:00 - Intro: Digital Signatures vs. Wet Ink 0:32 - The 3 Guarantees: Authentication, Integrity, Non-Repudiation 0:46 - Step 1: Hashing the Data (Creating the Fingerprint) 1:16 - Step 2: Encrypting the Hash with the PRIVATE Key 1:38 - Step 3: Verification with the PUBLIC Key 2:07 - Non-Repudiation: Why You Can't Deny It in Court 2:34 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=49wx9ENRRo4

Threat Actors & Motivations

If you don't know who is attacking you, you are just chasing ghosts. In this video, Sec Guy maps the adversary landscapeβ€”from highly funded Nation States (APTs) like Salt Typhoon to financially motivated Organized Crime groups like Scattered Spider. We also reveal why the "Insider Threat" and "Shadow IT" might be more dangerous to your organization than any elite foreign hacker. πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ (SY0-701) [ ] Domain 2.1: Threat Actors, Vectors, and Intelligence Sources (Attributes & Motivations) CISSP [ ] Domain 1: Security and Risk Management (Threat Modeling & Risk Assessment) CISM [ ] Domain 1: Information Security Governance (Threat Landscape Analysis) CRISC [ ] Domain 2: IT Risk Assessment (Threat Identification & Insider Risk) CCSP [ ] Domain 1: Cloud Concepts (Shadow IT Risks) SecurityX (CompTIA) [ ] Domain 3.0: Security Operations (Threat Hunting & Attribution) GIAC GSEC (SANS) [ ] Incident Handling & Threat Intelligence: Threat Actors AWS CSS (Certified Security – Specialty) [ ] Domain 1: Threat Detection (Identifying Unauthorized Access/Shadow IT) Pentest+ (CompTIA) [ ] Domain 1: Planning and Scoping (Adversary Emulation) CEH (Certified Ethical Hacker) [ ] Domain 1: Information Security Overview (Cyber Kill Chain & Threat Concepts) SecAI+ [ ] AI Security: Adversarial Machine Learning (Nation State AI Threats) [Timestamps] 0:00 - Intro: Mapping the Adversary 0:23 - Nation States (APTs): Espionage & Long Dwell Time (Salt Typhoon) 1:03 - Organized Crime: Financial Motivation (Scattered Spider) 1:27 - Hacktivists: Political Disruption (Belarusian Cyber Partisans) 1:51 - Script Kiddies: Unskilled but Noisy 2:09 - Insider Threats: Malicious vs. Negligent (The "Clicker") 2:38 - Shadow IT: The Silent Killer of Compliance 3:32 - Interview Challenge: Who is the Biggest Risk? (Elite Hacker vs. Admin) 4:09 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=5Q00hR5OFBw

Security+ Domain 1: Question Walkthrough

Join Sec Guy for an in-depth review of Domain 1 for the CompTIA Security+ (SY0-701) exam. This 10-question practice test covers everything from security principles and controls to governance and threat actors. Perfect for on-the-go studying! πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ 0:00: Introduction to Domain 1: General Security Concepts. 0:06: Overview of the exam weight (12% of total score) 0:21: Q1 1:05: Q2 1:48: Q3 2:26: Q4 3:03: Q5 3:49: Q6 4:29: Q7 5:03: Q8 5:51: Q9 6:31: Q10 7:18: secguy.org 7:27: secguy.org/exam-simulators 7:36: secguy.org/discord Topic Categories: Information Technology, Cybersecurity, Education Key Topics Covered: CIA Triad: Confidentiality, Integrity, Availability AAA Framework: Authentication, Authorization, Accounting Security Control Types: Physical, Technical, Managerial, Operational Security Models: Zero Trust, Defense in Depth Processes: Change Management, Hashing, Digital Signatures #comptiasecurityplus #Security+ #cybersecurity #training #itcertification #Certifications #Sec Guy Original Sec Guy video: https://www.youtube.com/watch?v=_ajWLFMzxS0

Threat Vectors & Attack Surfaces Explained

A "Threat Vector" is the path; an "Attack Surface" is the target. If you can't distinguish between a message-based attack (Smishing) and a file-based attack (Malicious Macro), you will lose points on your exam and miss threats in your SOC. In this video, Sec Guy maps out the 7 critical threat vectors you need to know, from Supply Chain compromises to Voice-based social engineering. πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 2.1: Threat Actors, Vectors, and Intelligence Sources (Message, Image, File, Voice, Supply Chain) [ ] Domain 2.4: Social Engineering (Phishing, Vishing, Smishing) CISSP [ ] Domain 1: Security and Risk Management (Threat Modeling & Attack Surface Analysis) CISM [ ] Domain 2: Information Risk Management (Vulnerability & Threat Identification) CRISC [ ] Domain 2: IT Risk Assessment (Threat Vectors & Emerging Risks) CCSP [ ] Domain 1: Cloud Concepts (Supply Chain Risk in Cloud Services) SecurityX (CompTIA) [ ] Domain 3.0: Security Operations (Analyzing Attack Vectors) GIAC GSEC (SANS) [ ] Incident Handling & Threat Intelligence: Attack Vectors AWS CSS (Certified Security – Specialty) [ ] Domain 1: Threat Detection (Identifying Compromise Vectors) Pentest+ (CompTIA) [ ] Domain 1: Planning and Scoping (Attack Surface Mapping) CEH (Certified Ethical Hacker) [ ] Domain 1: Information Security Overview (Attack Vectors & Surfaces) SecAI+ [ ] AI Security: Prompt Injection as a "Message-Based" Vector [Timestamps] 0:00 - Intro: Vectors vs. Surfaces 0:50 - Vector 1: Message-Based (Phishing, Smishing, BEC) 1:36 - Vector 2: Unsecure Networks (Rogue AP, Evil Twin) 2:17 - Vector 3: Social Engineering (Psychological Manipulation) 2:52 - Vector 4: File-Based (Macros, PDF Payloads) 3:28 - Vector 5: Voice Call (Vishing, MFA Fatigue) 4:03 - Vector 6: Supply Chain (Compromised Vendors/Updates) 4:43 - Vector 7: Vulnerable Software (Zero Days, Unpatched Systems) 5:14 - Summary: Identifying the Path to the Asset 5:40 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=gl3wbHTC7TY

Infrastructure Attack Surfaces: Spectre, VM Escape, & Memory Mastery

Software updates are great, but you can't patch a physics problem. In this video, Sec Guy explores the Infrastructure Attack Surface, explaining why Spectre and Meltdown exploit the CPU itself, how VM Escape can bring down an entire cloud provider, and the critical difference between a Buffer Overflow (Execution Attack) and a Memory Leak (Availability Attack). πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 3.2: Virtualization and Cloud Computing (VM Escape, VM Sprawl) [ ] Domain 4.2: Embedded and Specialized Systems (TPM, HSM) [ ] Domain 2.2: Vulnerabilities (Buffer Overflow, Memory Leak, DLL Injection) [ ] Domain 3.4: Mobile Device Management (Jailbreaking, Rooting, Sideloading) CISSP [ ] Domain 3: Security Architecture (Side-Channel Attacks, Trusted Foundry, Ring Protection) [ ] Domain 8: Software Development Security (Buffer Overflows & Memory Safety) CISM [ ] Domain 3: Information Security Program (Infrastructure Protection & Supply Chain) CRISC [ ] Domain 2: IT Risk Assessment (Hardware & Virtualization Risks) CCSP [ ] Domain 1: Cloud Concepts (Hypervisor Security & Guest Escape) [ ] Domain 3: Cloud Infrastructure Security (Virtualization Risks) SecurityX (CompTIA) [ ] Domain 1.0: Security Architecture (Hardware Root of Trust & Secure Boot) GIAC GSEC (SANS) [ ] Virtualization & Cloud Security: VM Escape & Hypervisor Attacks AWS CSS (Certified Security – Specialty) [ ] Domain 2: Infrastructure Security (Host Isolation & Nitro Enclaves) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Exploiting Buffer Overflows & Mobile Devices) CEH (Certified Ethical Hacker) [ ] Domain 6: System Hacking (Privilege Escalation & DLL Injection) [ ] Domain 12: Mobile Platform Hacking (Jailbreaking & Rooting) SecAI+ [ ] AI Security: Hardware Security (Protecting AI Model Weights on GPUs) [Timestamps] 0:00 - Intro: You Can't Patch Physics 0:45 - Hardware Roots of Trust: UEFI, TPM vs. HSM 1:38 - Side-Channel Attacks: Spectre & Meltdown (Speculative Execution) 2:07 - Supply Chain Interdiction 2:25 - Virtualization Attacks: VM Sprawl vs. VM Escape (Hyperjacking) 3:20 - Physical Memory Attacks: Rowhammer (Bit Flipping) 3:45 - Memory Vulnerabilities: Buffer Overflow vs. Memory Leak 4:40 - DLL Injection & Privilege Escalation 5:05 - Mobile Security: Jailbreaking, Rooting, & Sideloading 5:48 - Defense: MDM & Containerization (Samsung Knox) 6:18 - Summary: Prioritizing Infrastructure Risk 6:48 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=eu_viSkgSRU

Network Architecture: OSI Model, TCP/IP Model, PEP/PDP VLANS Explained

If you can't map an attack to its layer, you can't defend against it. Is a DDoS attack Layer 4 or Layer 7? Is ARP Poisoning Layer 2 or Layer 3? In this video, Sec Guy breaks down the OSI Model vs. TCP/IP, explains the critical difference between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP) in Zero Trust, and shows you how to stop VLAN Hopping attacks. πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 3.1: Secure Network Architecture (OSI Model, TCP/IP, VLANs) [ ] Domain 3.3: Network Designs (Zero Trust: PDP & PEP) CISSP [ ] Domain 4: Communication & Network Security (OSI Layers & Secure Design) [ ] Domain 3: Security Architecture (Zero Trust Principles) CISM [ ] Domain 3: Information Security Program (Network Infrastructure Security) CRISC [ ] Domain 2: IT Risk Assessment (Network Vulnerabilities & Architecture Risks) CCSP [ ] Domain 3: Cloud Infrastructure Security (Virtual Networking & VLANs) SecurityX (CompTIA) [ ] Domain 1.0: Security Architecture (Network Segmentation & Zero Trust) GIAC GSEC (SANS) [ ] Network Security Essentials: OSI, TCP/IP, & Defense in Depth AWS CSS (Certified Security – Specialty) [ ] Domain 2: Infrastructure Security (VPC Design, Direct Connect vs. VPN) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (VLAN Hopping & ARP Poisoning) CEH (Certified Ethical Hacker) [ ] Domain 3: Scanning Networks (Mapping Attacks to OSI Layers) SecAI+ [ ] AI Security: AI-Driven Network Segmentation & Anomaly Detection [Timestamps] 0:00 - Intro: The Battlefield of Architecture 0:36 - The OSI Model (7 Layers): "Please Do Not Throw Sausage Pizza Away" 1:01 - The TCP/IP Model (4 Layers): "All The Internet Needs" 1:25 - Mapping Attacks: DDoS (L7) vs. ARP Poisoning (L2) 1:50 - Hybrid Cloud: Site-to-Site VPN vs. Direct Connect 2:40 - The Death of the Flat Network: VLANs & 802.1Q 2:58 - Zero Trust Brain: Policy Decision Point (PDP) vs. Enforcement Point (PEP) 3:33 - Attack Vector: VLAN Hopping & Auto-Trunking 4:00 - Defense: Deception Technology (Honeynets) 4:16 - The Future: AI-Driven Dynamic Segmentation 4:52 - Summary: Segment Ruthlessly 5:08 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=i-jwtB3puxY

Modern Network Security: From Firewalls to Agentic AI Defense

A firewall is no longer just a boxβ€”it's a policy enforcement engine. In this deep dive, Sec Guy explains why WAFs have evolved into WAAPs to stop API attacks, why VPNs are being replaced by ZTNA and SASE, and how to use "Sticky MAC" and 802.1X to lock down your physical ports. If you are prepping for Security+, CISSP, or CCSP, this is your masterclass in network defense. πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ (SY0-701) [ ] Domain 3.3: Network Designs (SASE, ZTNA) [ ] Domain 2.3: Indicators of Malicious Activity (Heuristic vs. Anomaly) [ ] Domain 1.2: Security Controls (NGFW, WAF/WAAP) CISSP [ ] Domain 3: Security Architecture (Radius vs. TACACS+, 802.1X) [ ] Domain 4: Communication & Network Security (Secure Design Principles) CISM [ ] Domain 3: Information Security Program (Infrastructure Protection) CRISC [ ] Domain 2: IT Risk Assessment (Network Vulnerabilities) CCSP [ ] Domain 1: Cloud Concepts (SASE, CASB) [ ] Domain 2: Cloud Data Security (DLP) SecurityX (CompTIA) [ ] Domain 1.0: Security Architecture (Micro-segmentation & eBPF) GIAC GSEC (SANS) [ ] Access Control & Password Management: 802.1X & Port Security AWS CSS (Certified Security – Specialty) [ ] Domain 2: Infrastructure Security (Security Groups vs. NACLs vs. WAF) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Bypassing NAC, VLAN Hopping) CEH (Certified Ethical Hacker) [ ] Domain 6: Evading IDS, Firewalls, and Honeypots SecAI+ [ ] AI Security: Defending Against Agentic AI & Non-Human Identities (NHI) [Timestamps] 0:00 - Intro: Weapons on the Wall 0:30 - Firewalls vs. NGFW: Deep Packet Inspection 0:48 - WAAP: Protecting APIs & Stopping Mass Assignment 1:27 - IDS vs. IPS: Signature, Heuristic, & Anomaly Detection 2:42 - The New Threat: Agentic AI & Low/Slow Recon 2:54 - NDR & DNS Sinkholing: Catching Lateral Movement 3:18 - Bot Management: Behavioral Fingerprinting 3:40 - 802.1X: Supplicant, Authenticator, & Radius Server 4:12 - Port Security: Sticky MAC & Loop Protection 4:28 - RADIUS vs. TACACS+: The CISSP Distinction 5:22 - The Shift: VPN vs. ZTNA (Identity Aware Proxies) 5:48 - SASE: Converging SD-WAN, CASB, & DLP 6:16 - Non-Human Identities (NHI) & Micro-segmentation (eBPF) 7:11 - Summary: Identity is the New Perimeter 7:25 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=T6wtE8hDmw0

Risk Management: BCP, DRP, RTO/RPO & Risk Math

In cybersecurity, we don't plan for ifβ€”we plan for when. In this video, Sec Guy explains why the old "3-2-1 Backup Rule" is no longer enough to stop ransomware, how to calculate the cost of a disaster using SLE, ARO, and ALE, and the critical difference between a Business Continuity Plan (BCP) and a Disaster Recovery Plan (DRP). πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 5.2: Risk Management Processes (SLE, ALE, ARO, Risk Acceptance) [ ] Domain 5.4: Redundancy & Backup (RTO, RPO, MTBF, MTTR, 3-2-1 Rule) CISSP [ ] Domain 1: Security and Risk Management (Quantitative Risk Analysis) [ ] Domain 7: Security Operations (BCP/DRP, Testing Strategies) CISM [ ] Domain 4: Information Security Incident Management (RTO/RPO Definition) CRISC [ ] Domain 4: Risk and Control Monitoring (Reliability Metrics: MTBF/MTTR) CCSP [ ] Domain 1: Cloud Concepts (Cloud-to-Cloud Backup & Immutability) SecurityX (CompTIA) [ ] Domain 5.0: Security Operations (Disaster Recovery Planning) GIAC GSEC (SANS) [ ] Incident Handling: Business Continuity & Disaster Recovery AWS CSS (Certified Security – Specialty) [ ] Domain 4: Incident Response (Automated Backup & Restore) Pentest+ (CompTIA) [ ] Domain 1: Planning and Scoping (Impact Analysis) CEH (Certified Ethical Hacker) [ ] Domain 1: Information Security Overview (Risk Terminology) SecAI+ [ ] AI Security: Immutable Backups (WORM) to Prevent Training Data Corruption [Timestamps] 0:00 - Intro: Planning for "When," Not "If" 0:35 - The Math of Risk: Qualitative vs. Quantitative Analysis 1:13 - Calculating Risk: SLE, ARO, and ALE (The $10,000 Laptop Example) 2:02 - Risk Treatment: Mitigate, Transfer, Avoid, Accept 2:40 - BCP Metrics: Maximum Tolerable Downtime (MTD) vs. RTO 3:28 - Business Impact Analysis (BIA) & Supply Chain Risk 4:00 - Testing the Plan: Tabletop vs. Full Interruption 4:40 - The Golden Metrics: RTO (Time) vs. RPO (Data Loss) 5:25 - Reliability Metrics: MTBF vs. MTTR 6:02 - The New Standard: 3-2-1-1-0 Backup Rule (Air-Gapped & Verified) 7:00 - Recovery Sites: Hot, Warm, Cold & Cloud 7:52 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=7E1qTrSz2LU

Identity Access Management: PAM, JIT, JEA, ABAC, SAML, OAuth

In a cloud-native world, firewalls don't matter if your identity is compromised. "Identity is the New Perimeter." In this video, Sec Guy explains why Permanent Admin Rights are a security failure, how to implement Just-in-Time (JIT) access to stop attackers, and clearly defines the difference between SAML (XML/Enterprise), OAuth (Authorization), and OIDC (Authentication). πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 1.3: Identity and Access Management (SAML, OAuth, OIDC, ABAC vs. RBAC) [ ] Domain 1.4: Access Control Schemes (PAM, JIT, JEA) CISSP [ ] Domain 5: Identity and Access Management (Federated Identity, SAML, OIDC, Authorization vs. Authentication) CISM [ ] Domain 3: Information Security Program (Identity Lifecycle & Access Governance) CRISC [ ] Domain 2: IT Risk Assessment (Privileged Access Risks) CCSP [ ] Domain 4: Cloud Application Security (Federated Identity Management & XML/JSON usage) SecurityX (CompTIA) [ ] Domain 1.0: Security Architecture (Implementing Zero Trust Identity) GIAC GSEC (SANS) [ ] Access Control & Password Management: Federation & OAuth AWS CSS (Certified Security – Specialty) [ ] Domain 3: Infrastructure Security (IAM Roles, Federation, & Temporary Credentials) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Token Theft & Forging SAML Assertions) CEH (Certified Ethical Hacker) [ ] Domain 6: System Hacking (Privilege Escalation via Misconfigured IAM) SecAI+ [ ] AI Security: Workload Identity Federation for AI Agents (Non-Human Identities) [Timestamps] 0:00 - Intro: Identity is the New Perimeter 0:32 - Privileged Access Management (PAM): The Keys to the Kingdom 1:00 - Just-In-Time (JIT) vs. Just-Enough-Administration (JEA) 1:56 - ABAC vs. RBAC: Why Context Matters (Time/Location/Device) 2:32 - Federated Identity: Moving Trust Across the Internet 2:45 - SAML (XML): The Enterprise SSO Standard 3:05 - OAuth 2.0 (Authorization): "What You Can Do" vs. "Who You Are" 3:22 - OIDC (Authentication): The JSON Layer on Top of OAuth 3:42 - The Cryptography of Tokens: Signing & Hashing (JWTs) 4:42 - Non-Human Identities (NHI): Securing AI Agents & Service Accounts 5:14 - Summary: Identity is Proof, Not Just a Username 5:31 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=y_2UfJnrYtM

Cryptography: PKI & Certificates: CA, OSCP, CRL, TLS

Encryption protects your data, but PKI protects your trust. If you don't understand how a Certificate Authority (CA) validates a server, or why OCSP Stapling is faster than a CRL, you don't understand how the internet works. In this video, Sec Guy breaks down the "Trust Anchor" model, explains the difference between the Root CA and Intermediate CA, and walks you through the modern TLS 1.3 Handshake. πŸ”₯πŸ”₯New Security+ SYO-801 Study Guide Available today: secguy.org/security-study-guide πŸ”₯πŸ”₯ [Exam Ready Route - FREE] Pass your certification for $0. βœ… Training Videos & Practice Tests βœ… Sec Guy Mobile Lab (On-the-go training powered by AI voice) βœ… Discord Access (Study sessions & Industry networking) πŸ‘‰ Start Here: https://secguy.org [Job Ready Route - MEMBERSHIP] Stop studying and start working. Get the hands-on experience hiring managers are asking for. πŸ”₯ Hands-On Labs: Python, Encryption, Hashing, AI, & CTFs πŸ”₯ Salary Negotiator Workshop πŸ”₯ Experience Builder: Real-world projects to fill your resume πŸ‘‰ Get Hired: https://secguy.org [Exam Domain Checklist] This video covers critical objectives for the following exams: Security+ [ ] Domain 1.1: Cryptographic Concepts (PKI, CA, RA, CRL, OCSP) [ ] Domain 3.1: Secure Network Architecture (TLS 1.3, SSL Inspection) CISSP [ ] Domain 3: Security Architecture (PKI Trust Models, Key Management Lifecycle) [ ] Domain 4: Communication & Network Security (Secure Protocols - TLS) CISM [ ] Domain 2: Information Risk Management (Managing Trust & Digital Certificates) CRISC [ ] Domain 2: IT Risk Assessment (Risks of Expired Certificates & Weak CAs) CCSP [ ] Domain 2: Cloud Data Security (Key Management Services & BYOK) SecurityX (CompTIA) [ ] Domain 2.0: Security Architecture (Implementing Enterprise PKI) GIAC GSEC (SANS) [ ] Cryptography: Public Key Infrastructure & Certificates AWS CSS (Certified Security – Specialty) [ ] Domain 2: Data Protection (AWS Certificate Manager - ACM & Private CA) Pentest+ (CompTIA) [ ] Domain 3: Attacks and Exploits (Certificate Pinning Bypass & MITM) CEH (Certified Ethical Hacker) [ ] Domain 4: Cryptography (PKI Attacks & Fake Certificates) SecAI+ [ ] AI Security: Signing AI Models with PKI for Integrity [Timestamps] 0:00 - Intro: The Problem with Public Keys (Trust) 0:27 - The Certificate Authority (CA): The Ultimate Trust Anchor 1:04 - Hierarchy of Trust: Root CA (Offline) vs. Intermediate CA 1:36 - The Registration Authority (RA): Verifying Identity vs. Signing 2:08 - Revocation: CRL (Slow List) vs. OCSP (Fast Query) 2:50 - OCSP Stapling: The Efficient Modern Standard 3:07 - TLS 1.3 Handshake: Asymmetric for Key Exchange, Symmetric for Data 3:48 - Certificate Transparency Logs (CT Logs) & Post-Quantum Crypto 4:28 - How to Build Your Own CA (Lab) 4:53 - Outro: Stay Safe, Stay Secure. Original Sec Guy video: https://www.youtube.com/watch?v=HMazc2OpIeo
2 of 7