Jason Edwards
Certified - CompTIA Cloud+ Audio Course
Get exam-ready with the CompTIA Cloud+ Audio Course — your complete, on-demand companion for mastering every domain of the CompTIA Cloud+ (CV0-003) certification. Each episode takes you deep into the essentials of cloud architecture, deployment, operations, security, and troubleshooting, breaking down complex topics into clear, practical explanations you can put to use right away. Designed for busy professionals and aspiring cloud specialists alike, this course helps you build true technical confidence—whether you’re listening during your commute, workout, or study time. The CompTIA Cloud+ cer...
Author
Jason Edwards
Category
Podcast website
Latest episode
Oct 14, 2025
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 65 — Encryption Practices — OS, App, Storage, API, Filesystem 24.08.2025 13:57
In this episode, we explore encryption practices across multiple layers of a cloud environment. We explain how to secure operating systems with full disk encryption, protect applications with encrypted communications, safeguard storage through encryption at rest, and secure APIs with TLS or other cryptographic protocols. Filesystem encryption is also discussed for granular data protection within v...
Episode 64 — Security Through Configuration Management and Event Monitoring 24.08.2025 13:05
This episode looks at how configuration management and event monitoring work together to maintain cloud security. Configuration management ensures systems are deployed and maintained according to predefined policies, reducing drift and misconfigurations. Event monitoring collects and analyzes data from system logs, security tools, and applications to detect deviations or suspicious behavior. We al...
Episode 63 — Hardened OS and Application Baselines 24.08.2025 14:02
In this episode, we explain how hardened baselines create secure, standardized configurations for operating systems and applications. We cover the process of removing unnecessary services, disabling unused accounts, applying security patches, and configuring system-level protections. The goal is to reduce vulnerabilities and ensure all deployed systems meet a consistent security standard. We also...
Episode 62 — HIDS and HIPS — Host-Level Detection and Prevention 24.08.2025 14:09
This episode covers Host-based Intrusion Detection Systems (HIDS) and Host-based Intrusion Prevention Systems (HIPS) as part of a layered cloud security approach. HIDS monitors and analyzes system activity, looking for suspicious behavior or policy violations, while HIPS actively blocks identified threats before they can cause harm. We detail how these systems work at the OS and application level,...
Episode 61 — User Permissions, Antivirus, and Endpoint Detection 24.08.2025 14:38
In this episode, we look at three critical layers of endpoint and application security in cloud environments. User permissions define the specific resources and actions a user can access, enforcing the principle of least privilege. Antivirus software is covered as a first line of defense against known malware threats, while endpoint detection and response (EDR) tools add advanced capabilities like...
Episode 60 — OS and Application Security Policies — Passwords, Lockouts, Whitelisting 24.08.2025 15:57
In this episode, we focus on the security policies that protect operating systems and applications in cloud environments. We cover password complexity and expiration requirements, account lockout thresholds, and application whitelisting to prevent unauthorized software execution. The discussion also touches on enforcing these policies through configuration management tools and group policy objects...
Episode 59 — DDoS Protection in the Cloud — Design and Defense 24.08.2025 16:12
This episode explores how to design cloud environments to withstand Distributed Denial of Service (DDoS) attacks. We discuss layered defense strategies, including upstream filtering by cloud providers, traffic scrubbing services, and auto-scaling to absorb surges. The importance of monitoring and anomaly detection is also covered, as well as incident response playbooks for mitigating active attack...
Episode 58 — Traffic Control — Ingress, Egress, Proxies, and Filtering 24.08.2025 16:24
In this episode, we explain the methods used to control and secure inbound (ingress) and outbound (egress) traffic in cloud environments. We detail how firewalls, access control lists, and routing policies enforce these controls, and how proxies can provide content filtering, caching, and malware scanning. The episode also covers advanced filtering techniques, including application-aware firewalls...
Episode 57 — Hardening Network Configurations — Ports, Protocols, Firmware 24.08.2025 16:51
This episode focuses on reducing attack surfaces by hardening network device configurations. We explain the process of closing unused ports, disabling insecure or unnecessary protocols, and applying firmware updates to address vulnerabilities. We also discuss best practices for change control, configuration backups, and testing updates before production rollout. These measures are essential for en...
Episode 56 — Network Flow Analysis and Anomaly Detection 24.08.2025 13:50
In this episode, we explore how network flow analysis provides valuable insights into traffic patterns, bandwidth utilization, and potential security threats in cloud environments. We explain the difference between packet-level analysis and flow-based monitoring, with a focus on using NetFlow, sFlow, or IPFIX to gather aggregated traffic data. This approach allows administrators to identify normal...
Episode 55 — Log and Event Monitoring for Network Security 24.08.2025 16:28
In this episode, we cover the role of log and event monitoring in detecting and responding to security incidents. We explain the types of logs generated by firewalls, IDS/IPS, and network devices, and how to centralize them for analysis. Event correlation is discussed as a method for identifying patterns that may indicate malicious activity or system failure. We also emphasize the importance of re...
Episode 54 — Packet Brokers and DLP Tools in Cloud Monitoring 24.08.2025 13:01
This episode explains how packet brokers and data loss prevention (DLP) tools enhance visibility and control in cloud environments. Packet brokers aggregate and filter traffic from multiple sources, optimizing monitoring tool performance. DLP tools identify, monitor, and protect sensitive information from unauthorized transfer, whether intentional or accidental. We discuss common deployment patter...
Episode 53 — IPS, IDS, NAC, and Advanced Network Protection 24.08.2025 14:22
In this episode, we look at intrusion prevention systems (IPS), intrusion detection systems (IDS), and network access control (NAC) as part of a broader cloud security architecture. IPS actively blocks malicious traffic in real time, IDS alerts administrators to suspicious activity, and NAC enforces device compliance before granting network access. We explain deployment models, detection methods,...
Episode 52 — Cloud Network Services — Stateful/Stateless Firewalls and WAF 24.08.2025 12:26
This episode explains how network security appliances and services operate in cloud environments. We begin with stateful firewalls, which track active sessions and allow or block traffic based on the state of connections, and contrast them with stateless firewalls, which evaluate each packet individually without session context. We also cover web application firewalls (WAFs) that protect applicati...
Episode 51 — Secure Tunneling — SSH, GRE, L2TP, PPTP 24.08.2025 13:08
In this episode, we cover the tunneling protocols that enable secure or encapsulated communications in cloud and hybrid network architectures. Secure Shell (SSH) is explained as both a remote access protocol and a secure tunneling mechanism for other traffic. Generic Routing Encapsulation (GRE) is introduced for transporting multiple protocols over IP networks, with a focus on its flexibility but...
Episode 50 — Network Encryption — IPSec, TLS, HTTPS 24.08.2025 13:02
In this episode, we detail the protocols that protect data in transit across cloud networks. IPSec is covered as a suite for securing IP communications, including its modes, encryption methods, and authentication options. TLS is explained as the protocol securing most application-layer traffic, while HTTPS is presented as the encrypted form of HTTP used for secure web communication. We cover where...
Episode 49 — Time Synchronization and NTP Security 24.08.2025 12:19
This episode discusses the importance of accurate timekeeping for authentication, logging, and system coordination in cloud environments. We explain how the Network Time Protocol (NTP) operates, why time drift can cause authentication failures or log mismatches, and how to configure secure time sources. Topics include Network Time Security (NTS) for protecting NTP communications and redundancy str...
Episode 48 — DNS Security — DNSSEC, DoH, DoT 24.08.2025 13:56
In this episode, we explore how securing the Domain Name System (DNS) protects against spoofing, cache poisoning, and man-in-the-middle attacks. We explain DNSSEC’s role in verifying authenticity through digital signatures, DNS over HTTPS (DoH) for encrypting queries in HTTPS traffic, and DNS over TLS (DoT) for protecting queries at the transport layer. Each method’s operational trade-offs and dep...
Episode 47 — Network Segmentation — VLAN, VXLAN, GENEVE, and Micro-Segmentation 24.08.2025 12:42
This episode explains how network segmentation improves performance, security, and manageability in cloud architectures. We break down traditional VLANs for broadcast domain control, VXLAN for extending Layer 2 networks over Layer 3, and GENEVE as a flexible tunneling protocol for encapsulating network traffic. Micro-segmentation is also discussed, detailing how it enforces granular security polic...
Episode 46 — Secret and Key Management — Secure Credential Handling 24.08.2025 12:06
In this episode, we cover the essential practices for managing sensitive information such as API keys, encryption keys, passwords, and tokens in cloud environments. We explain why storing credentials in plain text or embedding them directly in code creates significant security risks, and how centralized secret management solutions mitigate these risks. Topics include encryption at rest, role-based...
Episode 45 — Public Key Infrastructure — Concepts and Cloud Use Cases 24.08.2025 13:22
In this episode, we explore the architecture and functions of Public Key Infrastructure (PKI), which supports secure communications through encryption, authentication, and digital signatures. We explain the components, including certificate authorities, registration authorities, and key pairs, and how they work together to establish trust in a cloud environment. PKI underpins many critical service...
Episode 44 — Single Sign-On and SAML in Cloud Environments 24.08.2025 12:32
This episode explains how single sign-on (SSO) reduces friction for users by enabling access to multiple applications with a single authentication event. We detail how SAML serves as a widely used protocol for exchanging authentication and authorization data between identity providers and service providers. Benefits include improved user experience, centralized access control, and reduced password...
Episode 43 — Multifactor Authentication — Configurations and Use Cases 24.08.2025 12:46
In this episode, we explore multifactor authentication (MFA) as a core security control in cloud environments. We define the three common factor types—something you know, something you have, and something you are—and explain how combining them strengthens identity verification. Common configurations include password plus SMS code, authenticator apps, or biometric verification, each offering varyin...
Episode 42 — Certificate Management Fundamentals 24.08.2025 7:16
This episode focuses on the role of digital certificates in securing cloud communications and verifying system identities. We cover the components of a certificate, including public and private keys, certificate authorities (CAs), and trust chains. You’ll learn how certificates enable encryption and authentication in protocols like TLS and HTTPS, ensuring data integrity and confidentiality in tran...
Episode 41 — Federation and Identity Trust Relationships 24.08.2025 12:23
In this episode, we examine how federation enables users from one domain to access resources in another without needing separate authentication credentials. We explain how this is achieved through trust relationships between identity providers and service providers, using standards such as SAML, OAuth, and OpenID Connect. Federation allows seamless cross-platform access while maintaining security,...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.