Jason Edwards

Certified: SANS GIAC GSEC Audio Course

The **GSEC Audio Course** from **BareMetalCyber.com** is your complete, audio-first companion for mastering the **GIAC Security Essentials (GSEC)** certification. Designed for cybersecurity professionals and motivated learners, this course transforms the full range of exam objectives into clear, structured lessons you can absorb anywhere. Each episode focuses on practical understanding—explaining how core security concepts like networks, encryption, access control, risk management, and incident response work together in real environments. Whether you’re building foundational knowledge or sharp...

Author

Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Oct 22, 2025

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 16 — Master TCP and UDP Behavior: Sessions, State, Reliability, and Abuse Patterns 22.10.2025

This episode builds a clear comparison of TCP and UDP and explains how their differences shape both troubleshooting and attack opportunities, which shows up frequently in GSEC network questions. You’ll define TCP as connection-oriented with sequencing, acknowledgments, and flow control, then connect that to stateful devices like firewalls that track sessions and can enforce policy based on establi...

Episode 15 — Understand Network Protocol Stacks: How Layers Create Both Function and Risk 22.10.2025

This episode explains why layered networking models matter for security analysis, and how GSEC expects you to diagnose problems by locating where a failure or attack operates. You’ll review how data moves through link, network, transport, and application behaviors, and why different controls align to different layers, such as switching controls at the local segment, routing controls across network...

Episode 14 — Make Authorization Decisions Safer: Entitlements, Groups, Roles, and Access Reviews 22.10.2025

This episode focuses on authorization as the decision of what an authenticated identity is allowed to do, and it targets the way GSEC questions often hide authorization failures inside “it logged in successfully” stories. You’ll define entitlements as the specific permissions granted through groups, roles, policies, or direct assignments, then learn how over-broad groups and direct user grants cre...

Episode 13 — Control Sessions and Re-Authentication: Timeouts, Reuse, Lockouts, and Risk Signals 22.10.2025

This episode explains session control as the bridge between “authentication happened once” and “access stays safe over time,” which is a subtle but common theme in GSEC questions about web apps, VPNs, and administrative consoles. You’ll define session lifetime, idle timeout, absolute timeout, and re-authentication triggers, then connect those ideas to risks like stolen cookies, unattended terminal...

Episode 12 — Run Account Lifecycle Cleanly: Provisioning, Deprovisioning, Reviews, and Drift Control 22.10.2025

This episode covers identity lifecycle as a control system that either keeps access aligned to business reality or slowly turns into a collection of orphaned risk. You’ll connect provisioning and deprovisioning to GSEC exam scenarios involving contractors, job changes, and emergency access, where the best answer often reduces window-of-exposure instead of adding a new tool. We’ll define joiner-mov...

Episode 11 — Reduce Privilege Risk Fast: Least Privilege, Admin Rights, and Separation of Duties 22.10.2025

This episode explains why privilege management is a high-frequency driver of real breaches and a recurring focus in GSEC questions that ask you to pick the control that most reduces impact. You’ll define least privilege as the minimum permissions needed for a task, then connect it to administrative rights, privileged sessions, and the difference between standing access and just-in-time elevation....

Episode 10 — Secure Password Storage Properly: Hashing, Salting, and Safe Verification Logic 22.10.2025

This episode breaks down password storage as a design problem that directly impacts breach impact, and it aligns to GSEC’s expectation that you understand hashing, salting, and verification at a conceptual level. You’ll explain why passwords must not be encrypted for routine verification, why hashes should be one-way with deliberate cost, and how salts prevent attackers from using precomputed tabl...

Episode 9 — Build Strong Authentication: Passwords, MFA, Tokens, and Practical Failure Modes 22.10.2025

This episode explains authentication as proof of identity and shows how GSEC expects you to reason about factors, protocols, and failure modes rather than treating MFA as a magic fix. You’ll review knowledge, possession, and inherence factors, then connect them to real controls like passwords, one-time codes, push approvals, hardware tokens, and certificate-based authentication. We’ll analyze comm...

Episode 8 — Compare Access Control Models: DAC, MAC, RBAC, ABAC, and Real Fit 22.10.2025

This episode compares the major access control models and focuses on how to select the best fit based on governance needs, data sensitivity, and administrative scalability, which is a common GSEC exam angle. You’ll define discretionary access control and why owner-driven permissions can create drift, mandatory access control and how labels enforce centralized rules, role-based access control and h...

Episode 7 — Understand Access Control Purpose: Controlling Who Can Do What, and Why 22.10.2025

This episode establishes access control as a core security function and shows how GSEC tests your ability to connect identity, authorization, and accountability to real operational outcomes. You’ll define subjects, objects, permissions, and entitlements, then tie them to least privilege, auditability, and risk reduction. We’ll explore why “who can do what” is incomplete without “under what conditi...

Episode 6 — Turn Security Principles into Policy: Standards, Exceptions, and Real Accountability 22.10.2025

This episode explains how principles become enforceable policy and why GSEC expects you to understand the difference between policies, standards, procedures, and guidelines. You’ll focus on how specificity increases enforceability, how standards translate intent into measurable requirements, and how procedures make the work repeatable under stress. We’ll cover how to manage exceptions without quie...

Episode 5 — Choose Defense Strategies Wisely: Prevent, Detect, Respond, Recover, and Adapt 22.10.2025

This episode clarifies how to choose the right strategy for a given threat, constraint, or business requirement, which is a frequent GSEC decision pattern. You’ll define each strategy, then learn how exam scenarios signal what is actually being asked: stopping an action, discovering it quickly, limiting impact, restoring service, or improving so it doesn’t repeat. We’ll work through examples like...

Episode 4 — Map the Key Areas of Security: People, Process, Technology, and Governance 22.10.2025

 This episode frames security as an organizational system, not just a technical toolkit, and explains how GSEC questions often probe whether you can connect controls to ownership and decision rights. You’ll define what belongs in people controls, process controls, technical controls, and governance, then learn how to map common topics like access, logging, and incident handling into that structure...

Episode 3 — Internalize Defense in Depth: Why Layers Beat Single “Perfect” Controls 22.10.2025

 This episode builds a practical definition of defense in depth and shows how GSEC expects you to reason about layered safeguards across people, process, and technology. You’ll connect the concept to real attack chains, where a single missed control, misconfiguration, or human error can collapse a “perfect” plan, while layered controls reduce blast radius and increase detection chances. We’ll walk...

Episode 2 — Build Your Audio-Only Study System: Daily Plan, Reviews, and Exam-Day Tactics 22.10.2025

 This episode turns preparation into a system you can execute consistently, with an emphasis on the way GSEC tests breadth, vocabulary precision, and applied reasoning. You’ll learn how to structure daily listening so each session has a clear objective, a short reinforcement loop, and a planned review window that prevents topic decay. We’ll define what “active recall” looks like in an audio-first...

Episode 1 — Decode the GIAC GSEC Exam: Format, Scoring, Rules, and Timing 22.10.2025

 This episode explains how the GIAC GSEC exam is structured and why understanding the mechanics matters for score management and time control. You’ll review how question sets, timing, and navigation constraints shape your approach, including how to pace through mixed-difficulty items without burning minutes on low-value uncertainty. We’ll translate exam rules into practical tactics: how to triage...

Listen to the Certified: SANS GIAC GSEC Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.