Jason Edwards

Certified: SANS GIAC GSEC Audio Course

The **GSEC Audio Course** from **BareMetalCyber.com** is your complete, audio-first companion for mastering the **GIAC Security Essentials (GSEC)** certification. Designed for cybersecurity professionals and motivated learners, this course transforms the full range of exam objectives into clear, structured lessons you can absorb anywhere. Each episode focuses on practical understanding—explaining how core security concepts like networks, encryption, access control, risk management, and incident response work together in real environments. Whether you’re building foundational knowledge or sharp...

Author

Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Oct 22, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 66 — Treat Logging as a Security Control: What to Capture and Why It Matters 22.10.2025

This episode frames logging as an active control that enables detection, investigation, and accountability, not just a compliance checkbox, which is a common GSEC emphasis across monitoring and incident scenarios. You’ll learn how to decide what to log by starting from questions you must be able to answer during an incident, such as who accessed what, from where, using which credential, and what a...

Episode 65 — Preserve Evidence Correctly: Chain of Custody, Volatility, and Documentation Discipline 22.10.2025

This episode explains evidence preservation as the foundation for accurate root cause, reliable remediation, and defensible reporting, and it maps directly to GSEC questions about what to collect and how to handle it. You’ll define chain of custody as documented control over evidence from collection through storage and analysis, then connect it to integrity needs such as hashing, access restrictio...

Episode 64 — Contain and Recover Effectively: Triage, Containment, Eradication, and Lessons Learned 22.10.2025

This episode focuses on the mechanics of getting an incident under control and restoring safe operations, which is a frequent GSEC scenario pattern where multiple actions sound reasonable but only some reduce risk quickly. You’ll define triage as rapid sorting of scope, impact, and urgency, then connect it to containment decisions like isolating hosts, disabling accounts, blocking egress, or segme...

Episode 63 — Operate Incident Handling Correctly: Phases, Roles, Evidence, and Communication 22.10.2025

This episode explains incident handling as an operational discipline with defined phases and responsibilities, a core concept for GSEC questions that ask what to do next during an event. You’ll review phases such as preparation, detection and analysis, containment, eradication, recovery, and post-incident activity, then connect each phase to what decisions must be made and who should make them. We...

Episode 62 — Write Better Findings: Severity, Evidence, Impact, and Actionable Remediation Logic 22.10.2025

This episode teaches how to write findings that drive change, which is important for GSEC because exam scenarios often reward answers that connect technical evidence to risk impact and realistic remediation. You’ll learn how to describe a finding with precise conditions, reproducible steps, and supporting artifacts such as logs, screenshots, configuration excerpts, or packet captures, while avoidi...

Episode 61 — Understand Penetration Testing Concepts: Scope, Ethics, Methods, and Useful Outcomes 22.10.2025

This episode explains penetration testing as a controlled assessment designed to validate security posture under defined rules, and it aligns to GSEC questions that test whether you understand scope, authorization, and how results should be used. You’ll define key concepts like rules of engagement, in-scope versus out-of-scope targets, time windows, and acceptable techniques, then connect them to...

Episode 60 — Understand Risk Language Precisely: Risks, Threats, Vulnerabilities, and Consequences 22.10.2025

This episode sharpens risk vocabulary so you can answer GSEC questions that depend on precise distinctions, especially when distractors use correct-sounding terms incorrectly. You’ll define a threat as a potential cause of harm, a vulnerability as a weakness that can be exploited, and risk as the combination of likelihood and impact when a threat can act on a vulnerability. We’ll connect consequen...

Episode 59 — Build Reconnaissance Awareness: Mapping Networks from Observable Clues and Metadata 22.10.2025

This episode explains reconnaissance as the phase where attackers reduce uncertainty by learning what exists, what is exposed, and what appears poorly defended, which is a frequent GSEC scenario driver for choosing prevention and detection controls. You’ll connect reconnaissance to observable clues such as DNS records, certificate transparency artifacts, exposed services and banners, public code r...

Episode 58 — Handle Vulnerability Scanning Properly: What Scanners Find, Miss, and Mislead 22.10.2025

This episode teaches vulnerability scanning as an evidence-gathering method with limits, which is essential for GSEC questions that ask you to interpret scan results and choose the next step responsibly. You’ll define scanning as identifying known weaknesses and exposures through network and host observations, then explain why findings can be true positives, false positives, or context-dependent i...

Episode 57 — Understand Memory Safety Risks: Exploits, Mitigations, and Why Updates Matter 22.10.2025

This episode explains memory safety risks at a practical level and ties them to the GSEC expectation that you understand why certain vulnerabilities can lead to code execution, privilege escalation, or service crashes. You’ll review how memory corruption issues can occur when programs mishandle bounds, pointers, or input validation, then connect those weaknesses to exploit outcomes like overwritin...

Episode 56 — Mitigate Exploits Systematically: Hardening, Patching, and Reducing Attack Surface 22.10.2025

This episode frames exploit mitigation as a process that reduces attacker options before an incident, which is a recurring GSEC decision pattern when multiple controls sound plausible. You’ll connect vulnerabilities to exploitability by examining exposure, reachable services, privilege context, and whether mitigations are in place, then translate that into practical priorities such as patching cri...

Episode 55 — Spot Malicious Code Behaviors: Infection, Persistence, Evasion, and Lateral Movement 22.10.2025

This episode teaches you to recognize malicious code by behavior patterns rather than relying on labels, which aligns with GSEC questions that describe symptoms and ask what is happening or what control best interrupts it. You’ll define infection as the initial execution path, persistence as mechanisms that survive reboots, evasion as attempts to avoid detection, and lateral movement as expansion...

Episode 54 — Understand Wi-Fi Authentication Choices: WPA2, WPA3, Enterprise Modes, and Pitfalls 22.10.2025

This episode breaks down Wi-Fi authentication and encryption choices in a way that supports both exam questions and real deployments, focusing on what changes between WPA2 and WPA3 and why enterprise modes shift trust to identity systems. You’ll compare personal modes, where a shared secret drives access, with enterprise approaches that rely on per-user authentication and centralized policy, then...

Episode 53 — Lock Down Wireless Networks Confidently: Risks, Configurations, and Safe Defaults 22.10.2025

This episode explains why wireless networks require deliberate configuration because the medium is shared and accessible beyond physical walls, a point often tested by GSEC through scenarios about unauthorized access and weak defaults. You’ll connect wireless risks to practical exposure, including eavesdropping, rogue access points, evil twin attacks, weak pre-shared keys, and misconfigured guest...

Episode 52 — Secure Mobile Devices Wisely: Threats, Hardening Priorities, and Policy Tradeoffs 22.10.2025

This episode focuses on mobile security as a blend of endpoint hardening, identity control, and data handling, which appears in GSEC questions that ask for the highest-impact safeguard under real constraints. You’ll review common mobile threats such as lost or stolen devices, malicious apps, unsafe networks, phishing, and credential reuse, then map those threats to practical controls like strong d...

Episode 51 — Protect Data in Motion and Rest: Storage Controls, Encryption, and Key Ownership 22.10.2025

This episode explains how GSEC expects you to reason about data protection across two states: in motion and at rest, with an emphasis on choosing controls that match the threat and the environment. You’ll connect confidentiality goals to storage protections like access control, segmentation, and backup integrity, then extend that to encryption decisions that reduce exposure when media is lost, sys...

Episode 50 — Build DLP Thinking: Classification, Handling Rules, and Detection Without Noise 22.10.2025

This episode explains data loss prevention as a strategy built on classification, handling rules, and measurable enforcement, and it targets the GSEC expectation that you can choose realistic controls rather than relying on vague “deploy DLP” answers. You’ll define classification as labeling data by sensitivity and required protections, then connect it to handling rules that specify where the data...

Episode 49 — Prevent Data Loss on Purpose: The Real Risks, Impacts, and Control Options 22.10.2025

This episode frames data loss as a predictable outcome of weak governance, poor handling discipline, and inadequate technical enforcement, which aligns to GSEC questions that ask you to prioritize controls based on impact and likelihood. You’ll define data loss broadly to include unauthorized disclosure, accidental exposure, deletion without recovery, and uncontrolled replication into unmanaged sy...

Episode 48 — Recognize Web App Vulnerabilities: Injection, XSS, Access Control, and SSRF 22.10.2025

This episode surveys high-impact web application vulnerabilities in the way the GSEC exam expects, emphasizing how to recognize the weakness from symptoms and choose the control that actually addresses the root cause. You’ll define injection as untrusted input being interpreted as commands, including SQL injection and command injection, then connect it to parameterized queries, input validation, a...

Episode 47 — Understand TLS and SSL Failures: Downgrades, Cert Errors, and Trust Breaks 22.10.2025

This episode explains why TLS failures are often security failures, not just connectivity issues, and how GSEC questions test your ability to spot trust breaks and downgrade conditions. You’ll review what TLS provides in practice, then focus on common failure modes such as accepting invalid certificates, misconfigured server names, missing intermediates, expired certificates, and clients that quie...

Episode 46 — Secure Web Sessions Properly: Cookies, Tokens, CSRF, and Session Fixation 22.10.2025

This episode teaches web session security as the practical control that determines whether authentication stays meaningful after login, which is a frequent GSEC theme in web risk questions. You’ll review cookies and bearer tokens as session carriers, then connect them to threats like theft, replay, and misuse across origins. We’ll define CSRF as forcing a victim’s browser to perform unintended act...

Episode 45 — Use GPG with Purpose: Encryption, Signing, Trust, and Operational Mistakes 22.10.2025

This episode explains how GPG supports confidentiality and authenticity workflows, and it connects the tool’s concepts to the GSEC expectation that you understand encryption versus signing and the trust assumptions behind each. You’ll define how GPG uses asymmetric keys for encrypting data to recipients and for signing artifacts so others can verify origin and integrity, then explore trust models...

Episode 44 — Understand PKI in Practice: Certificates, Chains, Validation, and Revocation Reality 22.10.2025

This episode builds an exam-ready understanding of PKI by focusing on what certificates prove, how trust chains are constructed, and why validation mistakes create silent compromise. You’ll define certificates as identity assertions bound to public keys, then walk through chain building from leaf certificates to intermediates to a trusted root, emphasizing that trust is not “the certificate exists...

Episode 43 — Apply Cryptography to VPNs: What Tunnels Do, What They Don’t, and Why 22.10.2025

This episode explains VPNs as cryptographic tunnels that protect traffic in transit while also introducing new trust and routing assumptions, which is a common GSEC scenario pattern. You’ll define what a tunnel provides, including confidentiality and integrity between endpoints, then clarify what it does not automatically provide, such as endpoint health, authorization correctness, or protection a...

Episode 42 — Choose Crypto Safely: Deprecation, Weak Parameters, and Configuration Pitfalls 22.10.2025

This episode focuses on the exam-relevant reality that cryptography fails most often because teams select deprecated algorithms, weak parameters, or unsafe defaults, not because they misunderstand the high-level goals. You’ll learn how to recognize deprecation signals in practice, why legacy options linger for compatibility, and how attackers exploit weak choices like short keys, outdated hashes,...

Listen to the Certified: SANS GIAC GSEC Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.