Course Details
Course Details
What You'll Learn
This course prepares you for the CAS-005 certification exam, covering all official exam domains and their approximate weightings:
Domain 1 Governance, Risk, and Compliance (20%)
- Implement governance components (security program documentation, GRC tools, change/configuration management, data governance)
- Perform risk management activities (risk assessment frameworks, third-party/supply chain risk, confidentiality/integrity/availability/privacy risk considerations)
- Explain how compliance affects security strategy (industry standards e.g. PCI DSS, ISO/IEC 27000, NIST CSF; privacy regulations e.g. GDPR/CCPA; audits vs assessments vs certifications)
- Perform threat-modeling activities (actor characteristics, ATT&CK/CAPEC/STRIDE/Cyber Kill Chain frameworks, attack surface determination)
- Summarize information security challenges of AI adoption (prompt injection, model theft/inversion, AI-enabled attacks, AI-enabled assistants/digital workers)
Domain 2 Security Architecture (27%)
- Analyze requirements to design resilient systems (component placement, availability/integrity design, recoverability, scaling)
- Implement security throughout the systems life cycle (security requirements, SAST/DAST/IAST/RASP, SCA, SBOM, CI/CD, supply chain and hardware assurance)
- Integrate appropriate controls into secure architecture design (attack surface management, detection/threat-hunting enablers, DLP, hybrid infrastructures)
- Apply security concepts to access, authentication, and authorization system design (provisioning/deprovisioning, federation, SSO, PKI, access control models)
- Securely implement cloud capabilities in an enterprise environment (CASB, shared responsibility model, IaC via Terraform/Ansible, container/serverless security)
- Integrate Zero Trust concepts into system architecture design (continuous authorization, microsegmentation, deperimeterization via SASE/SD-WAN)
Domain 3 Security Engineering (31%)
- Troubleshoot IAM components in an enterprise environment (subject access control, MFA, PAM, federation protocols SAML/OAuth/OpenID)
- Analyze requirements to enhance endpoint and server security (EDR, HIPS/HIDS, application control, MDM, threat-actor TTPs)
- Troubleshoot complex network infrastructure security issues (DNS security, email security DKIM/SPF/DMARC, TLS/PKI issues, DDoS, ACL issues)
- Implement hardware security technologies and techniques (roots of trust, TPM/HSM, secure boot, tamper detection, firmware attacks)
- Secure specialized and legacy systems against threats (OT/SCADA/ICS, IoT, embedded systems, industry-specific challenges)
- Use automation to secure the enterprise (scripting, IaC, SOAR, generative AI, SCAP/CVE/CVSS) and apply advanced cryptographic concepts and use cases (post-quantum cryptography, homomorphic encryption, tokenization, digital signatures)
Domain 4 Security Operations (22%)
- Analyze data to enable monitoring and response activities (SIEM, aggregate data analysis, behavior baselines, reporting/dashboards)
- Analyze vulnerabilities and attacks to recommend mitigations reducing the attack surface (injection, XSS, deserialization, input validation, patching)
- Apply threat-hunting and threat intelligence concepts (OSINT, TIPs, STIX/TAXII, Sigma/YARA rule languages, indicators of attack)
- Analyze data and artifacts in support of incident response activities (malware analysis, reverse engineering, network/host/metadata analysis, root cause analysis, insider threat)
Course Info
Promotion Code
Your will get 10% discount voucher for 2nd course onwards if you write us a Google review.
Minimum Entry Requirement
Knowledge and Skills
- Able to operate using computer functions
- Minimum 3 GCE ‘O’ Levels Passes including English or WPL Level 5 (Average of Reading, Listening, Speaking & Writing Scores)
Attitude
- Positive Learning Attitude
- Enthusiastic Learner
Experience
- Minimum of 1 year of working experience.
Target Age Group: 21-65 years old
Minimum Software/Hardware Requirement
Software:
You can download and install the following software:
Hardware: Windows and Mac Laptops
Job Roles
Job Roles
- Cybersecurity Analyst
- Information Security Officer
- Security Operations Center (SOC) Analyst
- IT Security Consultant
- Network Security Engineer
- Cyber Risk Analyst
- Governance, Risk, and Compliance (GRC) Specialist
- Security Architect
- IT Security Administrator
- Cloud Security Engineer
- Security Incident Response Specialist
- Penetration Tester
- Ethical Hacker
- Threat Intelligence Analyst
- Systems Security Engineer
- DevSecOps Engineer
- Security Compliance Manager
Trainers
Trainers
Saeid is co-founder of Skymics Sdn Bhd. He has 8 years of experience in the field of IoT (Internet of Things) and Information Technology. He is a certified IBM IoT Practitioner and instructor, and a Certified Citizen Data Scientist Train-The-Trainer. He has been co-inventor of 3 inventions during the last 4 years.
Review
Customer Reviews (7)
- Highly recommended Review by Course Participant/Trainee
-
The training was very practical and hands-on. I could apply what I learned to my work immediately. (Posted on 29/12/2024)1. Do you find the course meet your expectation? 2. Do you find the trainer knowledgeable in this subject? 3. How do you find the training environment - Fantastic experience Review by Course Participant/Trainee
-
Great course materials and well-paced lessons. The exercises really helped me understand the topic. (Posted on 18/05/2024)1. Do you find the course meet your expectation? 2. Do you find the trainer knowledgeable in this subject? 3. How do you find the training environment
Write Your Own Review
- Recommended Courses