Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, individual lessons, and BMC Cyber Challenge activities.

CompTIA · Free, ad-free audio course

CompTIA CySA+

A structured, audio-first learning route for CompTIA CySA+, designed for focused review and practical understanding.

Every Bare Metal Cyber audio course is free and 100% ad-free.

PUT IT INTO PRACTICE

Practice CompTIA CySA+ concepts

Try 50 original BMC questions, review every explanation, and return to the lessons behind the answer. No login is required. Earn Challenge achievements and share your progress as you go.

50 original questionsExplanation after every answerAchievements and sharing

Independent BMC learning practice—not official exam items, a full mock exam, or an exam-readiness score.

Certification practice in the BMC Cyber Challenge

Companion Books

Study with the audio course, then reinforce it in print.

The study guide helps you organize and revisit the material. The flashcards book adds active recall and rapid review across the course objectives.

Complete Lesson Directory

Choose the exact subject you want to study.

Search by topic or narrow the directory by exam domain. Courses with multiple editions are organized below so every season remains easy to find. Each lesson includes its own audio player, full description, transcript when available, and previous-or-next navigation.

130 lessons available

S01E01Transcript

Getting Started and Exam Review

Welcome to the CySA+: Who It’s For and Why It Matters

In this inaugural episode of the CySA+ PrepCast, we begin our journey by exploring what the CompTIA Cybersecurity Analyst certification actually is—and why it's more relevant than ever in today’s threat-driven world.…

Transcript availableJuly 15, 2025
S01E03Transcript

Getting Started and Exam Review

CySA+ vs Other Security Certifications: Where It Fits

With so many cybersecurity certifications on the market, it’s natural to wonder how the CySA+ stacks up against others like Security+, CISA, CEH, and CISSP.…

Transcript availableJuly 15, 2025
S01E04Transcript

Getting Started and Exam Review

How to Study for the CYSA Plus — Tools, Labs, and Habits

Studying for the CySA+ requires more than reading books—it requires strategic repetition, practice, and the right mix of tools. In this episode, we go beyond generic study tips and focus on what really works when preparing for a hands-on, analysis-heavy certification.…

Transcript availableJuly 15, 2025
S01E05Transcript

Getting Started and Exam Review

What to Expect on Exam Day: Questions, Time, and Tips

The exam day experience can make or break your performance—not because of your knowledge, but because of anxiety, confusion, or poor time management. In this episode, we walk you through exactly what to expect when it’s time to take the CySA+ certification exam.…

Transcript availableJuly 15, 2025
S01E06Transcript

Getting Started and Exam Review

Core Cybersecurity Foundations You Need Before You Start

Before we dive into tools, techniques, and frameworks, it’s important to make sure your foundational knowledge is solid. In this episode, we review the essential cybersecurity concepts that every CySA+ candidate should understand before tackling more advanced material.…

Transcript availableJuly 15, 2025
S01E07Transcript

Getting Started and Exam Review

Example Performance-Based Questions (PBQs) Walkthrough

Performance-based questions can catch even well-prepared test takers off guard. Unlike traditional multiple-choice items, these questions ask you to interact with tools, analyze artifacts, or simulate workflows—replicating what you’d actually do in a live security environment.…

Transcript availableJuly 15, 2025
S01E08Transcript

Getting Started and Exam Review

CySA+ Multiple-Choice Question Strategies

The multiple-choice section of the CySA+ exam isn’t just about knowing the right answer—it’s about identifying it under pressure. In this episode, we focus on smart test-taking strategies specifically designed for the CySA+ question format.…

Transcript availableJuly 15, 2025
S01E09Transcript

Getting Started and Exam Review

Building Your Own Cybersecurity Lab Environment

Hands-on practice is essential for CySA+ success, and that means having your own lab environment. In this episode, we help you build one using tools you can install on your own laptop, run in the cloud, or deploy in virtual machines.…

Transcript availableJuly 15, 2025
S01E11Transcript

Getting Started and Exam Review

Communicating Cybersecurity to Non-Technical Stakeholders

Technical knowledge alone isn’t enough. As a cybersecurity analyst, your ability to explain threats, risks, and remediation strategies to non-technical audiences can make or break your effectiveness.…

Transcript availableJuly 15, 2025
S01E12Transcript

Getting Started and Exam Review

Comprehensive Domain 1–2 Review (Pre-Exam Checklist)

In this fast-paced review episode, we recap the most critical concepts from Domain 1 (Security Operations) and Domain 2 (Vulnerability Management).…

Transcript availableJuly 15, 2025
S01E13Transcript

Getting Started and Exam Review

Comprehensive Domain 3–4 Review (Pre-Exam Checklist)

This second review episode brings together the essential content from Domain 3 (Incident Response and Management) and Domain 4 (Reporting and Communication).…

Transcript availableJuly 15, 2025
S01E14Transcript

Getting Started and Exam Review

CySA+ Glossary Episode 1

Before we tackle deeper technical episodes, it's essential to get fluent with the vocabulary used in the exam and in real-world security operations. This first glossary episode focuses on foundational network and infrastructure terms.…

Transcript availableJuly 15, 2025
S01E15Transcript

Getting Started and Exam Review

CySA+ Glossary Episode 2

In this second glossary episode, we focus on the security tools, frameworks, and compliance standards you’ll need to recognize and understand throughout your CySA+ journey.…

Transcript availableJuly 15, 2025
S01E16Transcript

Getting Started and Exam Review

CySA+ Glossary Episode 3

In the final glossary-focused episode, we turn our attention to the specialized language used in incident response, threat detection, and analyst operations.…

Transcript availableJuly 15, 2025
S01E17Transcript

Domain 1 · Security Operations

Domain 1 Overview – Security Operations in the Analyst’s World

Welcome to Domain 1, the largest and most foundational section of the CySA+ exam. In this episode, we preview what you’ll learn across the next several modules and explain how Security Operations serves as the nerve center of a modern cyber defense strategy.…

Transcript availableJuly 15, 2025
S01E18Transcript

Domain 1 · Security Operations

Log Ingestion and Logging Control

Effective cybersecurity starts with visibility—and that begins with logs. In this episode, we explore the basics of log ingestion, including what data is collected, how it's normalized, and where it's stored.…

Transcript availableJuly 15, 2025
S01E19Transcript

Domain 1 · Security Operations

Core OS Concepts Every Analyst Should Know

Understanding the underlying behavior of operating systems is critical for detecting and investigating malicious activity. In this episode, we explore the core OS concepts that every cybersecurity analyst must master.…

Transcript availableJuly 15, 2025
S01E21Transcript

Domain 1 · Security Operations

Infrastructure Concepts in Modern SOCs

Today’s IT environments are complex ecosystems that include virtual machines, containers, and serverless platforms. In this episode, we demystify these infrastructure models from a security analyst’s perspective.…

Transcript availableJuly 15, 2025
S01E22Transcript

Domain 1 · Security Operations

Network Architecture Design and Segmentation

Networks are the circulatory system of any digital environment, and securing them is a fundamental responsibility of the cyber analyst.…

Transcript availableJuly 15, 2025
S01E23Transcript

Domain 1 · Security Operations

Identity and Access Management Models

Authentication and authorization form the frontline of defense in every digital environment. In this episode, we explore key identity and access management (IAM) concepts including multifactor authentication (MFA), single sign-on (SSO), and federated identity systems.…

Transcript availableJuly 15, 2025
S01E24Transcript

Domain 1 · Security Operations

Encryption and Traffic Security Monitoring

Encryption plays a dual role in cybersecurity—protecting data confidentiality and creating blind spots in visibility.…

Transcript availableJuly 15, 2025
S01E25Transcript

Domain 1 · Security Operations

Sensitive Data Handling in the Enterprise

Protecting sensitive data is one of the most urgent and regulated responsibilities in cybersecurity.…

Transcript availableJuly 15, 2025
S01E26Transcript

Domain 1 · Security Operations

Network-Based Indicators of Malicious Activity

Your network is constantly broadcasting signals—some of them benign, some of them suspicious. In this episode, we examine network-level indicators that can reveal malicious activity in progress.…

Transcript availableJuly 15, 2025
S01E27Transcript

Domain 1 · Security Operations

Host-Based Indicators of Malicious Activity

While the network tells you what’s coming and going, the host shows you what’s actually happening. In this episode, we explore host-level indicators of compromise—from CPU spikes and unauthorized software to abnormal OS behavior and registry anomalies.…

Transcript availableJuly 15, 2025
S01E28Transcript

Domain 1 · Security Operations

Application Behavior and Anomaly Detection

Applications are often targeted directly by attackers—or exploited indirectly through user interaction.…

Transcript availableJuly 15, 2025
S01E29Transcript

Domain 1 · Security Operations

Social Engineering and Obfuscation Detection

Not all threats come from code—many come from people. This episode explores how attackers use social engineering tactics to bypass technical defenses, trick users, and gain footholds in environments.…

Transcript availableJuly 15, 2025
S01E30Transcript

Domain 1 · Security Operations

Network Capture and Traffic Inspection Tools

Being a strong analyst means being comfortable working with packets, flows, and raw network data. In this episode, we explore the tools analysts use for network capture and traffic inspection, including Wireshark and tcpdump.…

Transcript availableJuly 15, 2025
S01E33Transcript

Domain 1 · Security Operations

DNS and IP Intelligence Sources

DNS and IP addresses may seem simple at first glance, but they’re powerful resources for cyber defense—if you know how to use them.…

Transcript availableJuly 15, 2025
S01E34Transcript

Domain 1 · Security Operations

Static File Inspection Tools

Some threats are obvious in logs—others hide in files. In this episode, we introduce static file analysis tools and techniques that allow analysts to inspect suspicious files without executing them.…

Transcript availableJuly 15, 2025
S01E35Transcript

Domain 1 · Security Operations

Dynamic Malware Analysis Platforms (Sandboxing)

When static analysis doesn’t provide clear answers, analysts turn to sandboxing—isolated environments where suspicious files can be safely executed and observed.…

Transcript availableJuly 15, 2025
S01E36Transcript

Domain 1 · Security Operations

Common Detection Techniques in the SOC

Detecting threats isn’t just about having the right tools—it’s about applying the right techniques.…

Transcript availableJuly 15, 2025
S01E37Transcript

Domain 1 · Security Operations

Pattern Recognition and Command Analysis

Threat actors often reuse specific commands, tactics, and patterns of behavior—and analysts learn to recognize those patterns quickly.…

Transcript availableJuly 15, 2025
S01E38Transcript

Domain 1 · Security Operations

Suspicious Command Interpretation

Sometimes a single command is all it takes to compromise a system—but recognizing the danger isn’t always easy. This episode focuses on how to interpret suspicious command-line activity and identify intent from syntax.…

Transcript availableJuly 15, 2025
S01E39Transcript

Domain 1 · Security Operations

Email Analysis for Phishing and Spoofing

Phishing remains one of the most common and effective attack vectors—and analysts are often the last line of defense. In this episode, we walk through how to analyze suspicious emails, focusing on headers, sender behavior, and embedded links.…

Transcript availableJuly 15, 2025
S01E40Transcript

Domain 1 · Security Operations

Hashing and File Integrity Techniques

When a file changes unexpectedly, something important may have happened—and hashing is one of the best tools we have to track it.…

Transcript availableJuly 15, 2025
S01E41Transcript

Domain 1 · Security Operations

Detecting Abnormal User Behavior

Attackers often succeed not because they're invisible, but because they mimic normal user behavior—until they don’t. In this episode, we explore how user and entity behavior analytics (UEBA) help security analysts detect when users start acting outside of their established patterns.…

Transcript availableJuly 15, 2025
S01E42Transcript

Domain 1 · Security Operations

Security Scripting and Automation Basics

Not all threats require a human response—and not all analysis can scale without scripting. In this episode, we dive into the scripting and automation fundamentals analysts need to understand for CySA+ and real-world workflows.…

Transcript availableJuly 15, 2025
S01E43Transcript

Domain 1 · Security Operations

Threat Actor Categories and Profiles

Understanding the adversary is the first step to anticipating their next move.…

Transcript availableJuly 15, 2025
S01E44Transcript

Domain 1 · Security Operations

Insider Threats and Supply Chain Risks

Some of the most damaging threats come from within—or through trusted partners. In this episode, we explore the two primary forms of insider threats: intentional actors who sabotage or steal for personal gain, and unintentional insiders whose negligence leads to exposure.…

Transcript availableJuly 15, 2025
S01E45Transcript

Domain 1 · Security Operations

Threat Intelligence Confidence Levels and TTPs

All threat intelligence is not created equal. In this episode, we explore how analysts evaluate the reliability of threat intelligence based on confidence levels—specifically timeliness, relevancy, and accuracy.…

Transcript availableJuly 15, 2025
S01E46Transcript

Domain 1 · Security Operations

Open Source Threat Intelligence Collection

Not all threat intelligence comes with a price tag. In this episode, we explore the value and limitations of open source intelligence (OSINT) in cybersecurity operations.…

Transcript availableJuly 15, 2025
S01E47Transcript

Domain 1 · Security Operations

Closed Source Threat Intel and Information Sharing

Some of the most actionable threat intelligence is found behind closed doors. In this episode, we examine closed source threat intel—feeds and services provided by vendors, threat intelligence platforms, and information-sharing communities like ISACs.…

Transcript availableJuly 15, 2025
S01E48Transcript

Domain 2 · Vulnerability Management

How Threat Intelligence Powers Security Functions

Threat intelligence is more than just information—it’s fuel for proactive defense. In this episode, we show how threat intel informs and enhances nearly every security function: from incident response and vulnerability management to engineering, detection, and monitoring.…

Transcript availableJuly 15, 2025
S01E49Transcript

Domain 2 · Vulnerability Management

Indicators of Compromise and Threat Hunting

Threat hunting begins where automation ends. In this episode, we break down the lifecycle of Indicators of Compromise (IoCs)—how they are discovered, validated, and applied across tools and teams.…

Transcript availableJuly 15, 2025
S01E50Transcript

Domain 2 · Vulnerability Management

Threat Hunting Focus Areas and Active Defense

Hunting threats means knowing where to look—and what to expect. In this episode, we identify the key focus areas for threat hunting operations, including misconfigured systems, isolated or high-value network segments, and business-critical applications.…

Transcript availableJuly 15, 2025
S01E51Transcript

Domain 2 · Vulnerability Management

Standardizing and Automating Security Processes

Consistency is key in security operations, especially when teams are responding to high volumes of alerts under time pressure. In this episode, we dive into the benefits of standardizing and automating security processes.…

Transcript availableJuly 15, 2025
S01E52Transcript

Domain 2 · Vulnerability Management

Streamlining with SOAR and Threat Feed Enrichment

Security Orchestration, Automation, and Response (SOAR) platforms help security teams move faster and more intelligently.…

Transcript availableJuly 15, 2025
S01E53Transcript

Domain 2 · Vulnerability Management

Integrating APIs and Plugins for Efficiency

Modern security platforms rarely operate in silos. In this episode, we explore how APIs, webhooks, and plugins allow your tools to communicate—enabling integrations that speed up investigation, automate response, and support real-time correlation.…

Transcript availableJuly 15, 2025
S01E54Transcript

Domain 2 · Vulnerability Management

Single Pane of Glass: Visibility in the SOC

In complex environments, visibility is everything. But when your tools are spread across different dashboards and platforms, critical context can be lost.…

Transcript availableJuly 15, 2025
S01E55Transcript

Domain 2 · Vulnerability Management

Domain 2 Overview – Vulnerability Management in Practice

Welcome to Domain 2: Vulnerability Management. In this foundational episode, we set the stage for everything you’ll learn in the coming sessions—from scanning tools and techniques to validation, prioritization, and secure development practices.…

Transcript availableJuly 15, 2025
S01E56Transcript

Domain 2 · Vulnerability Management

Asset Discovery in the Wild

Before you can scan for vulnerabilities, you need to know what assets you’re protecting. In this episode, we focus on the first step of the vulnerability management lifecycle: asset discovery.…

Transcript availableJuly 15, 2025
S01E57Transcript

Domain 2 · Vulnerability Management

Vulnerability Scanning – Special Considerations

Not all scans are created equal. In this episode, we explore the many considerations that go into planning and executing a vulnerability scan without disrupting business operations.…

Transcript availableJuly 15, 2025
S01E58Transcript

Domain 2 · Vulnerability Management

Internal vs. External Scanning Strategies

Where you scan from is just as important as what you’re scanning. This episode breaks down the difference between internal and external vulnerability scans—what each one reveals, why both are necessary, and how attackers exploit gaps between them.…

Transcript availableJuly 15, 2025
S01E59Transcript

Domain 2 · Vulnerability Management

Agent-Based vs. Agentless Scanning

Should you deploy agents on every device, or scan remotely without them? In this episode, we compare agent-based and agentless vulnerability scanning approaches and explore their respective strengths, limitations, and use cases.…

Transcript availableJuly 15, 2025
S01E60Transcript

Domain 2 · Vulnerability Management

Credentialed vs. Non-Credentialed Scans

Credentials can change everything. In this episode, we explore the differences between credentialed and non-credentialed scans—and why access matters when identifying vulnerabilities accurately.…

Transcript availableJuly 15, 2025
S01E61Transcript

Domain 2 · Vulnerability Management

Passive vs. Active Vulnerability Detection

Not all scanning involves direct interaction. In this episode, we explore the differences between passive and active vulnerability detection techniques.…

Transcript availableJuly 15, 2025
S01E62Transcript

Domain 2 · Vulnerability Management

Static vs. Dynamic Analysis Techniques

Some vulnerabilities are embedded in code—others appear only at runtime. In this episode, we unpack the distinction between static and dynamic vulnerability analysis.…

Transcript availableJuly 15, 2025
S01E63Transcript

Domain 2 · Vulnerability Management

Scanning Critical Infrastructure Systems (OT/ICS/SCADA)

Operational technology (OT) environments—such as industrial control systems (ICS) and SCADA platforms—pose unique challenges for vulnerability management.…

Transcript availableJuly 15, 2025
S01E64Transcript

Domain 2 · Vulnerability Management

Security Baseline Scanning Techniques

Before you can identify deviations, you need a baseline. This episode focuses on how security baseline scans compare systems and configurations against established security policies and industry benchmarks.…

Transcript availableJuly 15, 2025
S01E65Transcript

Domain 2 · Vulnerability Management

Industry Frameworks for Vulnerability Management

Many vulnerability scanning strategies are guided by established frameworks. In this episode, we break down the most widely recognized standards referenced throughout the CySA+ exam and in real-world practice.…

Transcript availableJuly 15, 2025
S01E66Transcript

Domain 2 · Vulnerability Management

Network Scanning and Mapping Tools

Understanding your network begins with visibility—and that visibility is powered by scanning and mapping tools. In this episode, we introduce key network discovery tools such as Angry IP Scanner and Maltego.…

Transcript availableJuly 15, 2025
S01E67Transcript

Domain 2 · Vulnerability Management

Web Application Scanning Tools

Web applications are among the most targeted assets in modern enterprises—and automated scanning tools are the first line of defense.…

Transcript availableJuly 15, 2025
S01E68Transcript

Domain 2 · Vulnerability Management

Vulnerability Scanners Explained (Nessus, OpenVAS)

At the heart of vulnerability management lies automated vulnerability scanners—and few are more widely used than Nessus and OpenVAS. In this episode, we break down how these scanners work, what they look for, and how analysts interpret their output.…

Transcript availableJuly 15, 2025
S01E69Transcript

Domain 2 · Vulnerability Management

Debugging Tools for Vulnerability Analysts

Not every vulnerability is easy to spot—some require stepping into the execution environment itself.…

Transcript availableJuly 15, 2025
S01E73Transcript

Domain 2 · Vulnerability Management

Validating Scanner Results – Reducing False Positives and Negatives

Automated scanners are powerful—but they’re not perfect. In this episode, we explore the analyst’s role in validating scan results, filtering out false positives, and identifying dangerous false negatives.…

Transcript availableJuly 15, 2025
S01E74Transcript

Domain 2 · Vulnerability Management

Context-Aware Vulnerability Analysis

Sometimes the same vulnerability poses very different risks depending on the environment. This episode teaches you how to analyze vulnerabilities in context—a crucial CySA+ concept and a daily responsibility in the SOC.…

Transcript availableJuly 15, 2025
S01E75Transcript

Domain 2 · Vulnerability Management

Weaponization and Exploitability Considerations

A vulnerability doesn’t become a threat until someone weaponizes it—and that’s when it becomes truly urgent. In this episode, we explore the concepts of exploitability and weaponization in depth.…

Transcript availableJuly 15, 2025
S01E76Transcript

Domain 2 · Vulnerability Management

Asset Value and Business Impact

Every vulnerability exists in the context of what it could damage—and that’s where asset valuation comes in. In this episode, we explore how security analysts assess the value of an asset and how that valuation affects how quickly a vulnerability must be addressed.…

Transcript availableJuly 15, 2025
S01E77Transcript

Domain 2 · Vulnerability Management

Cross-Site Scripting Vulnerabilities (XSS)

Cross-site scripting, or XSS, is one of the most common and dangerous web application vulnerabilities.…

Transcript availableJuly 15, 2025
S01E78Transcript

Domain 2 · Vulnerability Management

Overflow Vulnerabilities

When a program doesn’t control how much data it processes, memory can be overwritten—and attackers can take control. In this episode, we explore the mechanics and consequences of overflow vulnerabilities: buffer, heap, stack, and integer overflows.…

Transcript availableJuly 15, 2025
S01E79Transcript

Domain 2 · Vulnerability Management

Data Poisoning Risks

When attackers manipulate training data or trusted inputs, they can corrupt the very systems meant to defend against them.…

Transcript availableJuly 15, 2025
S01E80Transcript

Domain 2 · Vulnerability Management

Broken Access Control Flaws

Access control determines who can do what—and when it breaks, attackers often find a clear path in. In this episode, we take a deep dive into broken access control vulnerabilities, one of the most serious and widespread categories in application security.…

Transcript availableJuly 15, 2025
S01E81Transcript

Domain 3 · Incident Response Management

Cryptographic Failures

When encryption fails, the consequences can be catastrophic. In this episode, we explore cryptographic failures—formerly called "Sensitive Data Exposure" in the OWASP Top Ten—and why they continue to affect even high-profile organizations.…

Transcript availableJuly 15, 2025
S01E82Transcript

Domain 3 · Incident Response Management

Injection Flaws Explained

Injection vulnerabilities have been on the OWASP Top Ten for years—and for good reason. In this episode, we explain how SQL, command-line, and LDAP injection flaws allow attackers to manipulate input to execute unintended commands or access unauthorized data.…

Transcript availableJuly 15, 2025
S01E83Transcript

Domain 3 · Incident Response Management

Cross-Site Request Forgery (CSRF)

In this episode, we examine Cross-Site Request Forgery, or CSRF—a vulnerability that tricks authenticated users into executing unwanted actions on a web application.…

Transcript availableJuly 15, 2025
S01E84Transcript

Domain 3 · Incident Response Management

Directory Traversal Vulnerabilities

When input isn’t properly restricted, users can end up accessing far more than intended. In this episode, we break down directory traversal vulnerabilities—flaws that allow attackers to manipulate file paths and access sensitive files or directories outside of the intended web root.…

Transcript availableJuly 15, 2025
S01E85Transcript

Domain 3 · Incident Response Management

Insecure Design Patterns

Not all vulnerabilities are bugs—some are architectural. In this episode, we explore the concept of insecure design, a growing concern recognized in recent OWASP rankings.…

Transcript availableJuly 15, 2025
S01E86Transcript

Domain 3 · Incident Response Management

Security Misconfiguration Issues

Even the strongest tools can be rendered useless by poor configuration.…

Transcript availableJuly 15, 2025
S01E87Transcript

Domain 3 · Incident Response Management

End-of-Life and Legacy Component Risk

Running outdated software isn't just inconvenient—it’s dangerous. In this episode, we explore the risks posed by end-of-life (EOL) systems and unsupported components, which often lack vendor patches, security updates, or compatibility with modern security tools.…

Transcript availableJuly 15, 2025
S01E88Transcript

Domain 3 · Incident Response Management

Identification and Authentication Failures

If attackers can bypass your login system, the rest of your defenses may not matter. In this episode, we explore identification and authentication failures such as broken login flows, weak password policies, exposed session tokens, and improper use of multifactor authentication (MFA).…

Transcript availableJuly 15, 2025
S01E89Transcript

Domain 3 · Incident Response Management

Server-Side Request Forgery (SSRF)

Some of the most dangerous requests come from inside the house. In this episode, we unpack Server-Side Request Forgery (SSRF), a vulnerability that allows attackers to trick a server into sending requests to internal services, external endpoints, or cloud metadata APIs.…

Transcript availableJuly 15, 2025
S01E90Transcript

Domain 3 · Incident Response Management

Remote Code Execution (RCE) Threats

Few vulnerabilities are as critical—or as devastating—as remote code execution. In this episode, we explore how RCE vulnerabilities allow attackers to run arbitrary code on target systems, often with high privileges and zero user interaction.…

Transcript availableJuly 15, 2025
S01E91Transcript

Domain 3 · Incident Response Management

Privilege Escalation Techniques and Dangers

Attackers often start with limited access—but they rarely stay there. In this episode, we break down privilege escalation vulnerabilities, which allow attackers to move from low-level accounts to administrative or root-level control.…

Transcript availableJuly 15, 2025
S01E92Transcript

Domain 3 · Incident Response Management

Local/Remote File Inclusion (LFI/RFI)

Sometimes attackers don’t need to upload malicious files—they just need to include them.…

Transcript availableJuly 15, 2025
S01E93Transcript

Domain 3 · Incident Response Management

Compensating Controls in Vulnerability Management

What happens when you can’t fix a vulnerability directly? In this episode, we introduce the concept of compensating controls—alternative safeguards put in place to reduce risk when a vulnerability cannot be immediately remediated.…

Transcript availableJuly 15, 2025
S01E94Transcript

Domain 3 · Incident Response Management

Control Types and Their Purposes

Not all security controls serve the same function. In this episode, we explain the various types of controls used across cybersecurity programs and why it’s important to understand their classification.…

Transcript availableJuly 15, 2025
S01E95Transcript

Domain 3 · Incident Response Management

Patch and Configuration Management Lifecycle

Vulnerabilities don’t just exist—they persist, especially when patch and configuration management processes are weak.…

Transcript availableJuly 15, 2025
S01E96Transcript

Domain 3 · Incident Response Management

Maintenance Windows and Update Timing

Security teams can’t just apply patches whenever they want—especially in enterprise environments where uptime and availability are critical.…

Transcript availableJuly 15, 2025
S01E97Transcript

Domain 3 · Incident Response Management

Documenting and Handling Exceptions

Sometimes a vulnerability can’t be fixed—at least, not right away. In this episode, we explain how analysts and risk managers document and process exceptions: formal records of accepted risk where vulnerabilities are not remediated within standard timelines.…

Transcript availableJuly 15, 2025
S01E98Transcript

Domain 3 · Incident Response Management

Risk Management Principles for Vulnerability Response

Effective vulnerability management is built on sound risk management principles. In this episode, we explore the four classic risk response strategies—accept, avoid, transfer, and mitigate—and how they apply to real-world cybersecurity scenarios.…

Transcript availableJuly 15, 2025
S01E99Transcript

Domain 3 · Incident Response Management

Policy, Governance, and SLO Integration

Cybersecurity doesn’t happen in a vacuum—it happens under governance. In this episode, we explain how policies, governance structures, and service-level objectives (SLOs) shape the work of the security analyst.…

Transcript availableJuly 15, 2025
S01E100Transcript

Domain 3 · Incident Response Management

Vulnerability Prioritization and Escalation

In a world where thousands of vulnerabilities exist, how do you decide which to address first? In this episode, we break down the art and science of vulnerability prioritization—how analysts combine CVSS scores, asset value, exploitability, and business context to triage effectively.…

Transcript availableJuly 15, 2025
S01E101Transcript

Domain 3 · Incident Response Management

Attack Surface Management in Action

You can't protect what you can't see. In this episode, we explore the evolving discipline of attack surface management (ASM)—a proactive process that helps security teams identify, map, and reduce the ways in which an attacker could compromise an organization.…

Transcript availableJuly 15, 2025
S01E102Transcript

Domain 3 · Incident Response Management

Secure Coding Best Practices for Analysts

You don’t need to be a developer to influence secure code—but you do need to understand what secure coding looks like.…

Transcript availableJuly 15, 2025
S01E104Transcript

Domain 3 · Incident Response Management

Threat Modeling for Analysts

What if you could anticipate the attacker’s plan before they even launch it? In this episode, we introduce threat modeling as a method for identifying and prioritizing potential threats based on how applications and systems are designed.…

Transcript availableJuly 15, 2025
S01E105Transcript

Domain 3 · Incident Response Management

Domain 2 Review – From Scanning to Secure Development

Before moving forward, it’s time to reflect. In this comprehensive recap, we walk through the critical knowledge areas covered in Domain 2: Vulnerability Management.…

Transcript availableJuly 15, 2025
S01E106Transcript

Domain 4 · Reporting and Communication

Domain 3 Overview – Mastering Incident Response and Management

Welcome to Domain 3 of the CySA+ PrepCast, where we move from prevention and vulnerability management into response and containment. In this episode, we provide an overview of what incident response means in modern organizations and how it’s structured in the CySA+ exam.…

Transcript availableJuly 15, 2025
S01E107Transcript

Domain 4 · Reporting and Communication

Cyber Kill Chains – From Recon to Exploitation

To stop an attack, you must understand its progression. In this episode, we explore the Lockheed Martin Cyber Kill Chain—a widely used framework that maps the stages of a cyberattack from initial reconnaissance through delivery, exploitation, command and control, and beyond.…

Transcript availableJuly 15, 2025
S01E108Transcript

Domain 4 · Reporting and Communication

The Diamond Model of Intrusion Analysis

What happens when we move beyond events and look at the relationships between adversaries, capabilities, victims, and infrastructure?…

Transcript availableJuly 15, 2025
S01E109Transcript

Domain 4 · Reporting and Communication

MITRE ATT&CK Framework for Analysts

In this episode, we explore the MITRE ATT&CK Framework—a living matrix of adversary behaviors that has transformed how cybersecurity professionals track and respond to attacks.…

Transcript availableJuly 15, 2025
S01E110Transcript

Domain 4 · Reporting and Communication

Open Source Security Testing Methodology Manual (OSSTMM)

The OSSTMM is often overlooked—but it provides a rigorous, standards-based approach to security testing that aligns with the goals of CySA+ and many compliance frameworks.…

Transcript availableJuly 15, 2025
S01E111Transcript

Domain 4 · Reporting and Communication

Indicators of Compromise (IoCs) – Detection Foundations

Detecting an attack starts with recognizing the signs. In this episode, we explore Indicators of Compromise (IoCs)—artifacts that suggest an organization may have been breached or is under active threat.…

Transcript availableJuly 15, 2025
S01E112Transcript

Domain 4 · Reporting and Communication

Evidence Acquisition and Chain of Custody

Once an incident is detected, preserving evidence becomes a top priority. In this episode, we walk through the evidence acquisition process—from initial identification to collection, storage, and transfer.…

Transcript availableJuly 15, 2025
S01E114Transcript

Domain 4 · Reporting and Communication

Containment, Eradication, and Recovery Phases

Detecting an incident is only the beginning. In this episode, we examine the containment, eradication, and recovery phases of incident response—what they are, how they differ, and how they build upon one another to restore a secure state.…

Transcript availableJuly 15, 2025
S01E115Transcript

Domain 4 · Reporting and Communication

Incident Preparation – Building a Response Program

The best incident response doesn’t start with detection—it starts with preparation. In this episode, we walk through the preparation phase of the incident response lifecycle, focusing on how organizations create, document, and test their response plans.…

Transcript availableJuly 15, 2025
S01E116Transcript

Domain 4 · Reporting and Communication

Post-Incident Activity and Organizational Learning

Once the smoke clears, the real improvement begins. In this episode, we explore the post-incident phase of the incident response lifecycle.…

Transcript availableJuly 15, 2025
S01E117Transcript

Domain 4 · Reporting and Communication

Domain 4 Overview – Reporting and Communication in Cybersecurity

Welcome to Domain 4 of the CySA+ PrepCast. In this episode, we introduce the principles of reporting and communication—critical soft skills that define how technical findings are translated into business decisions.…

Transcript availableJuly 15, 2025
S01E118Transcript

Domain 4 · Reporting and Communication

Vulnerability Management Reporting Essentials

In this episode, we break down the core components of a vulnerability management report. You’ll learn how to organize and present data on discovered vulnerabilities, affected assets, associated risk scores, remediation efforts, recurrence frequency, and mitigation timelines.…

Transcript availableJuly 15, 2025
S01E119Transcript

Domain 4 · Reporting and Communication

Creating and Understanding Compliance Reports

Security isn't just about stopping threats—it's also about proving due diligence. In this episode, we explore how security teams create and interpret compliance reports aligned with frameworks like PCI DSS, HIPAA, NIST 800-53, and ISO 27001.…

Transcript availableJuly 15, 2025
S01E120Transcript

Domain 4 · Reporting and Communication

Action Plans and Remediation Communication

Once vulnerabilities are identified, the work isn’t done—it’s just beginning. In this episode, we explore how analysts develop and communicate action plans for addressing discovered risks.…

Transcript availableJuly 15, 2025
S01E121Transcript

Domain 4 · Reporting and Communication

Inhibitors to Remediation

Even when vulnerabilities are known and documented, remediation doesn’t always move forward. In this episode, we examine the most common inhibitors to remediation—technical, procedural, and political obstacles that delay or prevent action.…

Transcript availableJuly 15, 2025
S01E122Transcript

Domain 4 · Reporting and Communication

Metrics and KPIs in Vulnerability Management

You can’t improve what you don’t measure. In this episode, we focus on key performance indicators (KPIs) and metrics used to evaluate the effectiveness of vulnerability management programs.…

Transcript availableJuly 15, 2025
S01E123Transcript

Domain 4 · Reporting and Communication

Identifying Stakeholders for Vulnerability Reporting

Not all stakeholders need the same level of technical detail—but all of them need accurate, timely, and actionable reporting. In this episode, we explore how analysts identify and tailor communication for different stakeholder groups during the vulnerability management process.…

Transcript availableJuly 15, 2025
S01E124Transcript

Domain 4 · Reporting and Communication

Stakeholder Communication for Incident Response

During an incident, clear and timely communication becomes a matter of urgency—not just best practice. In this episode, we cover how security analysts coordinate communication across teams and leadership tiers when responding to security events.…

Transcript availableJuly 15, 2025
S01E125Transcript

Domain 4 · Reporting and Communication

Incident Declaration and Escalation Procedures

Not every alert becomes an incident—but when one does, it needs to be declared formally and escalated swiftly.…

Transcript availableJuly 15, 2025
S01E126Transcript

Domain 4 · Reporting and Communication

Writing Effective Incident Response Reports

When the incident is over, the reporting begins. In this episode, we explore how security analysts write effective incident response reports that document what happened, how it was discovered, what actions were taken, and what outcomes resulted.…

Transcript availableJuly 15, 2025
S01E127Transcript

Domain 4 · Reporting and Communication

Legal and PR Communications During an Incident

Communication during a security incident isn't just internal—it can affect your company’s reputation, legal standing, and customer trust.…

Transcript availableJuly 15, 2025
S01E128Transcript

Domain 4 · Reporting and Communication

Customer and Media Communications

Sometimes the most difficult part of a security incident isn’t stopping the threat—it’s explaining what happened to the people affected. In this episode, we explore how organizations communicate with customers, partners, and the media during and after an incident.…

Transcript availableJuly 15, 2025
S01E129Transcript

Domain 4 · Reporting and Communication

Regulatory and Law Enforcement Reporting

When a breach crosses a legal threshold, reporting to regulators or law enforcement may be required. In this episode, we examine the processes and obligations associated with regulatory reporting under frameworks like GDPR, HIPAA, PCI DSS, and state-level data breach laws.…

Transcript availableJuly 15, 2025

A Practical Study Routine

Listen, read, and review in the order that works for you.

01

Listen

Use the free audio course during a commute, walk, workout, or focused study session.

02

Read

Use the study guide to organize the material, annotate key ideas, and build a reference you can return to.

03

Review

Use the flashcards book to practice active recall and quickly revisit weak areas.

Related Cyber Wiki

Continue with the concepts behind the course.

ATT&CK Campaign Analysis

2015 Ukraine Electric Power Attack (C0028)

A defensive guide to the Enterprise ATT&CK campaign record C0028, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2015 campaign that disrupted Ukrainian electric-power substations using BlackEnergy and KillDisk.

ATT&CK Campaign Analysis

2016 Ukraine Electric Power Attack (C0025)

A defensive guide to the Enterprise ATT&CK campaign record C0025, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2016 campaign that disrupted Ukrainian electric-power distribution using Industroyer.

ATT&CK Campaign Analysis

2022 Ukraine Electric Power Attack (C0034)

A defensive guide to the Enterprise ATT&CK campaign record C0034, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2022 campaign against a Ukrainian electric utility that combined malware and living-off-the-land behavior to issue unauthorized SCADA commands.

ATT&CK Campaign Analysis

2025 Poland Wiper Attacks (C0063)

A defensive guide to the Enterprise ATT&CK campaign record C0063, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing destructive December 2025 attacks against Polish energy infrastructure involving Windows and PowerShell wipers.

ATT&CK Campaign Analysis

3CX Supply Chain Attack (C0057)

A defensive guide to the Enterprise ATT&CK campaign record C0057, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a cascading supply-chain compromise that moved from a trojanized trading application into 3CX build environments.

ATT&CK Software Analysis

AADInternals (S0677)

A defensive guide to the Enterprise ATT&CK software record S0677, including identification, dual-use context, behavior analytics, and investigation. The official record summarizes public reporting describing a PowerShell framework used to administer, enumerate, and test Azure Active Directory environments.