Dr. Jason Edwards
Certified: The CISSP Audio Course
Welcome to The Bare Metal Cyber CISSP Audio Course—your comprehensive companion for mastering the Certified Information Systems Security Professional (CISSP) certification. Built for serious cybersecurity professionals and aspiring leaders alike, this Audio Course transforms the eight domains of the CISSP Common Body of Knowledge into clear, structured, and engaging lessons you can learn anytime, anywhere. Each episode blends real-world context, expert insight, and exam-focused explanations to help you understand not just what to study, but how to think like a security professional. Whether yo...
Author
Dr. Jason Edwards
Category
Podcast website
Latest episode
Jan 17, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 66: Network Monitoring and Traffic Analysis 23.06.2025 17:18
Continuous monitoring and traffic analysis are essential for detecting threats, performance issues, and policy violations. In this episode, we explore tools and techniques used to observe network behavior in real time. Topics include flow monitoring, deep packet inspection, NetFlow, and behavioral analytics. You’ll also learn about the role of Security Information and Event Management (SIEM) in ag...
Episode 65: Network Address Translation and Proxy Usage 23.06.2025 17:22
NAT and proxy servers play important roles in hiding internal IP addresses, enforcing access policies, and controlling traffic flow. In this episode, we explore how Network Address Translation (NAT) works to conserve IP space and obscure internal architectures. We also explain how proxies—forward, reverse, and transparent—support web filtering, anonymization, caching, and load balancing. You’ll le...
Episode 64: VOIP and Secure Communication Channels 23.06.2025 15:30
Voice over IP (VOIP) technologies have replaced traditional telephony in many organizations, but they come with their own set of security concerns. This episode explores the architecture of VOIP systems and the threats they face, including call interception, eavesdropping, spoofing, and denial-of-service attacks. We also cover secure communication protocols such as SRTP, SIPS, and encrypted signal...
Episode 63: Wireless Network Security (WEP, WPA2/3, 802.1X) 23.06.2025 17:48
Wireless networks present a unique set of vulnerabilities due to their reliance on open air transmission. In this episode, we examine wireless security protocols and controls, including WEP, WPA2, WPA3, and 802.1X. We explain how authentication frameworks, encryption standards, and access controls protect against threats like rogue access points, packet sniffing, and brute-force attacks. You’ll al...
Episode 61: Secure Routing and Switching 23.06.2025 14:25
Secure routing and switching are foundational elements of network security. In this episode, we explore how routers and switches operate, and how attackers exploit their misconfigurations or weaknesses to gain access or disrupt communication. Topics include route hijacking, ARP poisoning, MAC flooding, and VLAN hopping. You’ll learn best practices for hardening these devices, including access cont...
Episode 60: Intrusion Detection and Prevention Systems 23.06.2025 13:13
Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are crucial for identifying and stopping threats in real time. This episode explores how these tools work, their deployment strategies, and how they integrate with broader security operations. You’ll learn about signature-based and anomaly-based detection, false positives, evasion techniques, and tuning practices. We also cov...
Episode 59: Defense in Depth with Firewalls and DMZs 23.06.2025 12:44
Layered security—known as defense in depth—is a core concept in cybersecurity architecture. This episode focuses on how firewalls and demilitarized zones (DMZs) serve as essential layers in protecting internal networks. We explore different types of firewalls (packet filtering, stateful, next-gen), the design of DMZs for public-facing services, and how to enforce traffic controls between zones. Yo...
Episode 58: Network Segmentation and Microsegmentation 23.06.2025 14:09
Segmentation limits the spread of attacks and improves control over traffic flows within a network. In this episode, we examine both traditional network segmentation and microsegmentation techniques. You’ll learn how VLANs, firewalls, and subnetting create macro boundaries, while software-defined networking enables granular control over traffic between workloads and devices. We discuss how segment...
Episode 57: Secure Protocols: HTTPS, SSH, SFTP, SNMPv3 23.06.2025 12:59
Secure communication protocols form the backbone of protected digital environments. In this episode, we explore widely used secure protocols like HTTPS, SSH, SFTP, and SNMPv3. You’ll learn how each one provides confidentiality, integrity, and authentication for various types of data exchanges—from web traffic and file transfers to remote administration and device management. We cover protocol stre...
Episode 56: OSI and TCP/IP Models Refresher 23.06.2025 12:29
The OSI and TCP/IP models provide a layered approach to understanding how data is transmitted, received, and managed across networks. In this episode, we refresh your understanding of these models and their significance in network security. We explore the function of each layer—from physical cabling to application-level protocols—and explain how attacks and defenses map to specific layers. You’ll...
Episode 55: Network Architecture: LAN, WAN, Internet 23.06.2025 13:18
Understanding how networks are built and connected is foundational for any security professional. In this episode, we review core network architecture concepts, including the structure and purpose of Local Area Networks (LANs), Wide Area Networks (WANs), and the global Internet. We examine how data moves across these networks and where vulnerabilities may appear, from physical access points to rou...
Episode 54: Fault Tolerance, Redundancy, and High Availability 23.06.2025 12:51
Downtime is not an option for mission-critical systems. In this episode, we dive into fault tolerance, redundancy, and high availability—design strategies that ensure continuity despite component failures or unexpected disruptions. You’ll learn the differences between active-active and active-passive configurations, the role of clustering, load balancing, failover mechanisms, and geographically di...
Episode 53: SCADA and Embedded System Security 23.06.2025 13:05
Supervisory Control and Data Acquisition (SCADA) systems and embedded devices operate some of the most critical infrastructure in the world—from energy grids to transportation systems. This episode explores the unique challenges of securing these environments, including limited resources, outdated firmware, lack of patching, and real-time operational requirements. We cover best practices for acces...
Episode 52: Emerging Technologies and Security Architecture (e.g., IoT, AI) 23.06.2025 13:47
Technological innovation continues to transform the security landscape. In this episode, we examine how emerging technologies such as the Internet of Things (IoT), Artificial Intelligence (AI), and machine learning are impacting security architecture. We discuss the benefits and vulnerabilities of these systems, including expanded attack surfaces, device sprawl, privacy concerns, and autonomous de...
Episode 51: Security Boundaries and Isolation Techniques 23.06.2025 13:48
Security boundaries are essential for creating logical separations between systems, users, and data flows. In this episode, we explore how boundaries are defined and enforced, using both physical and logical mechanisms. You’ll learn about concepts like trust zones, network segmentation, VLANs, virtualization, and sandboxing. We also discuss isolation techniques that prevent lateral movement, conta...
Episode 50: Security Evaluations: Common Criteria, RMF, ISO/IEC 23.06.2025 12:50
Security evaluations provide assurance that systems meet defined security requirements. In this episode, we examine key evaluation frameworks including Common Criteria (CC), the NIST Risk Management Framework (RMF), and the ISO/IEC 27000 series. You'll learn how these models define evaluation assurance levels, categorize controls, and guide secure system development. We also discuss how evaluation...
Episode 49: Cryptanalysis and Attacks Against Crypto 23.06.2025 13:41
No cryptographic system is immune to attack, and CISSPs must understand the methods used to break or weaken them. In this episode, we explore cryptanalysis techniques including brute-force, dictionary attacks, chosen plaintext attacks, and side-channel analysis. We explain how poor implementation, weak keys, and outdated algorithms create vulnerabilities, and how to mitigate those risks through pr...
Episode 48: PKI, Digital Certificates, and Trust Models 23.06.2025 12:57
Public Key Infrastructure (PKI) is essential for enabling secure communication and verifying digital identities. This episode breaks down how PKI works, including the roles of certificate authorities (CAs), registration authorities (RAs), and digital certificates. You’ll learn about certificate chaining, revocation, validation protocols like OCSP and CRL, and how trust is established in both hiera...
Episode 47: Key Management and Key Escrow 23.06.2025 14:46
Cryptographic systems are only as secure as the keys they use—and how those keys are managed. In this episode, we delve into key management principles, including generation, storage, distribution, rotation, and destruction. We also explore key escrow, where a third party securely stores encryption keys for legal or recovery purposes. You’ll learn about hardware security modules (HSMs), key managem...
Episode 46: Hashing and Message Integrity 23.06.2025 12:52
Hashing ensures that data remains unchanged during storage or transmission—a core requirement for integrity. In this episode, we explore how cryptographic hash functions like SHA-256 and SHA-3 are used to detect tampering, generate digital signatures, and verify file authenticity. We discuss key properties such as collision resistance, pre-image resistance, and determinism. You'll also learn the d...
Episode 45: Cryptographic Lifecycle: Algorithms, Strength, Obsolescence 23.06.2025 15:23
Cryptographic tools aren’t set-and-forget solutions—they require lifecycle management. This episode explores how organizations select, deploy, and eventually retire cryptographic algorithms. We examine how algorithm strength is determined, the impact of key length, and the risks posed by deprecated or broken ciphers like MD5 and SHA-1. You’ll learn how to stay ahead of threats by monitoring crypto...
Episode 44: Cryptographic Concepts: Symmetric and Asymmetric 23.06.2025 11:30
Cryptography is the backbone of digital security, and understanding its core principles is essential. In this episode, we explain the difference between symmetric and asymmetric encryption, along with their real-world applications. You’ll learn how symmetric encryption uses a single key for both encryption and decryption, while asymmetric encryption relies on key pairs for secure key exchange, dig...
Episode 43: Common Security Flaws in Architecture 23.06.2025 12:28
Flawed architecture is one of the most serious vulnerabilities in any system. In this episode, we explore common architectural security weaknesses, including insecure defaults, lack of isolation, poor trust boundaries, and insufficient input validation. We explain how these flaws emerge during design and how they can be exploited by attackers. You’ll also learn how to apply secure design principle...
Episode 42: Secure Baseline and Configuration Management 23.06.2025 14:46
Systems don’t stay secure by accident—they stay secure through consistent configuration and control. In this episode, we cover the concepts of secure baselining and configuration management. You’ll learn how to establish security baselines, enforce configuration standards, and use automation tools to detect and remediate drift. We also discuss patching, change control, and the role of configuratio...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.