Dr. Jason Edwards

Certified: The CompTIA Security+ Audio Course

Certified - Security+ 701 is your completely free audio companion for mastering the CompTIA Security+ SY0-701 certification exam. Developed by BareMetalCyber.com, this immersive Audio Course transforms every domain of the official exam objectives into clear, practical, and exam-ready lessons you can learn anywhere—whether commuting, exercising, or studying at home. Each episode delivers focused explanations, real-world examples, and proven study strategies designed to build confidence and help you pass on your first attempt. Structured for busy professionals and new learners alike, the series...

Author

Dr. Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Apr 28, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 148: Identity Proofing and Federation (Domain 4) 16.06.2025

Before you can secure access, you have to know who’s requesting it—and identity proofing ensures that the person behind a login is who they claim to be. In this episode, we explore identity proofing methods used during onboarding and remote authentication, including document verification, biometric validation, third-party attestation, and knowledge-based authentication. These techniques form the f...

Episode 147: User Account Provisioning and Permission Management (Domain 4) 16.06.2025

Creating, modifying, and revoking user accounts may sound like routine IT work—but it’s a fundamental part of security control. In this episode, we examine account provisioning processes that align access rights with job functions, enforce least privilege, and prevent accumulation of unnecessary entitlements over time. We also discuss automated provisioning tools that integrate with identity provi...

Episode 146: User Behavior Analytics (Domain 4) 16.06.2025

User Behavior Analytics (UBA) shifts the security paradigm from rules-based alerts to behavioral baselines, allowing defenders to spot anomalies that signal potential insider threats, account compromise, or malicious misuse. In this episode, we discuss how UBA platforms collect data from logs, access patterns, login times, file usage, and application activity to build profiles of “normal” user beh...

Episode 145: Network Access Control and Endpoint Protection (Domain 4) 16.06.2025

Controlling access at the point of connection is one of the most effective ways to prevent unauthorized entry, and in this episode, we explore the implementation of Network Access Control (NAC) and endpoint protection systems. NAC evaluates devices before they’re allowed onto the network, verifying compliance with security policies—such as having up-to-date antivirus, system patches, or correct co...

Episode 144: File Integrity Monitoring and Data Loss Prevention (Domain 4) 16.06.2025

File Integrity Monitoring (FIM) and Data Loss Prevention (DLP) tools are essential for detecting tampering and protecting sensitive data from unauthorized exfiltration. In this episode, we explain how FIM works by taking baseline snapshots of critical system files and configurations, then alerting when unauthorized changes occur—helping detect stealthy malware, insider threats, or administrative e...

Episode 143: DNS Filtering and Email Security Enhancements (Domain 4) 16.06.2025

DNS and email are two of the most commonly exploited services in cyberattacks—and securing them requires layered, policy-driven controls. In this episode, we explore DNS filtering, which allows organizations to block access to malicious domains by intercepting or redirecting outbound queries. We discuss how threat feeds, domain reputation systems, and custom blacklists integrate into DNS resolvers...

Episode 142: Secure Protocol Implementation (Domain 4) 16.06.2025

Not all protocols are created equal—and using the wrong one can open a serious security hole in your environment. In this episode, we examine the implementation of secure communication protocols like TLS, SSH, and IPSec, which provide confidentiality and integrity for data in transit. We explain how these protocols differ from insecure alternatives like Telnet, HTTP, and FTP, and why default confi...

Episode 141: Operating System Security Enhancements (Domain 4) 16.06.2025

The operating system is the beating heart of any computing device—and securing it properly lays the groundwork for all other defenses. In this episode, we focus on OS-level security enhancements like Group Policy Objects (GPOs) for centralized control in Windows environments, and Security-Enhanced Linux (SELinux) for mandatory access control enforcement in Linux systems. We explore features such a...

Episode 140: Web Filtering and Content Security (Domain 4) 16.06.2025

Web filtering and content security are essential for managing user behavior and blocking malicious or inappropriate content before it ever reaches the endpoint. In this episode, we explore how organizations use proxy servers, secure web gateways, DNS filtering, and URL categorization to restrict access to risky websites and enforce browsing policies. We discuss agent-based versus agentless filteri...

Episode 139: Enhancing IDS/IPS Effectiveness (Domain 4) 16.06.2025

Intrusion Detection and Prevention Systems (IDS/IPS) are powerful tools—but their effectiveness depends entirely on tuning, context, and visibility. In this episode, we cover how signature-based detection identifies known threats, while anomaly-based systems flag unusual activity based on historical baselines or heuristic models. We discuss the importance of updating signatures, tuning thresholds...

Episode 138: Enhancing Firewall Capabilities (Domain 4) 16.06.2025

Firewalls are often the first line of defense—but they’re only as effective as the rules, architecture, and tuning behind them. In this episode, we explore advanced firewall configurations, including layered rule sets, port and protocol filtering, application awareness, and geographic blocking. We discuss the use of stateful inspection, deep packet inspection (DPI), and integration with threat int...

Episode 137: Vulnerability Scanning Tools and Practices (Domain 4) 16.06.2025

Proactive security means finding and fixing weaknesses before attackers do, and vulnerability scanning is the tool that makes that possible at scale. In this episode, we break down how vulnerability scanners work, from discovering assets and services to identifying known weaknesses based on CVE data, vendor advisories, and configuration checks. We compare credentialed vs. non-credentialed scans, i...

Episode 136: Network-Based Monitoring Tools (Domain 4) 16.06.2025

The network is where everything intersects—making it one of the most important vantage points for threat detection. In this episode, we examine key tools used for monitoring network activity, including NetFlow analysis, SNMP traps, and traffic mirroring with SPAN ports or network taps. NetFlow provides metadata about who’s talking to whom, when, and how much—useful for spotting unusual behavior li...

Episode 135: Endpoint and Data Security Monitoring Tools (Domain 4) 16.06.2025

Endpoints—laptops, desktops, mobile devices—are where most cyberattacks begin, making endpoint security monitoring a frontline defense. In this episode, we explore tools that specifically monitor these devices, including traditional antivirus, modern Endpoint Detection and Response (EDR), and Extended Detection and Response (XDR) solutions that correlate data across endpoints, email, and identity...

Episode 134: Security Monitoring Tools (Part 2) (Domain 4) 16.06.2025

Building on our previous discussion, this episode explores more advanced and specialized monitoring tools—starting with Security Information and Event Management (SIEM) systems. SIEMs aggregate logs, correlate events, and generate alerts based on patterns, thresholds, or anomalies across networks, endpoints, and applications. We then discuss antivirus solutions, which remain essential for detectin...

Episode 133: Security Monitoring Tools (Part 1) (Domain 4) 16.06.2025

Choosing the right tools shapes how effectively you can detect, understand, and respond to threats. In this episode, we focus on foundational monitoring tools like the Security Content Automation Protocol (SCAP), which standardizes vulnerability reporting and configuration assessment across diverse systems. We explain how benchmarks—such as those from the Center for Internet Security (CIS)—serve a...

Episode 132: Alert Response and Validation (Domain 4) 16.06.2025

Alerts are only effective when they result in meaningful, timely responses—and this episode explores how organizations structure alert triage, validation, and remediation workflows. We start with alert tuning: setting appropriate thresholds to reduce false positives while ensuring true threats are caught early. From there, we move into triage processes, where alerts are evaluated by severity, scop...

Episode 131: Key Security Monitoring Activities (Part 2) (Domain 4) 16.06.2025

Beyond real-time alerting, monitoring supports long-term visibility, compliance, and forensics through disciplined reporting and archiving practices. In this episode, we discuss how monitoring data is structured into actionable reports for various audiences—technical teams, executives, and auditors—highlighting trends, risk areas, and remediation status over time. We also cover the importance of l...

Episode 130: Key Security Monitoring Activities (Part 1) (Domain 4) 16.06.2025

Monitoring is most valuable when it drives action, and in this episode, we explore foundational activities that turn data into defense—starting with log aggregation, alerting, and scanning. Log aggregation involves collecting logs from diverse systems—servers, firewalls, applications, cloud platforms—into a central platform for correlation and analysis. Alerting systems evaluate these logs in real...

Episode 129: Monitoring Computing Resources (Domain 4) 16.06.2025

Monitoring is the heartbeat of any modern security operation, providing real-time visibility into systems, applications, and infrastructure. In this episode, we explore how organizations monitor computing resources for both performance and security, using tools like agents, collectors, log forwarders, and telemetry APIs. We discuss the difference between host-based and network-based monitoring, an...

Episode 128: Effective Vulnerability Reporting (Domain 4) 16.06.2025

Clear, actionable reporting is the bridge between technical discovery and organizational response, and in this episode, we explore what makes vulnerability reports useful and credible. We cover how to structure reports with essential components like risk summaries, technical details, affected systems, recommended actions, and business impact assessments. Reports should be tailored to their audienc...

Episode 127: Validation of Remediation Efforts (Domain 4) 15.06.2025

Fixing a vulnerability doesn’t mean it’s gone—it means it needs to be verified. In this episode, we focus on the importance of validating remediation efforts to ensure that patches, configuration changes, and mitigation controls have actually addressed the issue without introducing new problems. This process includes rescanning affected systems, conducting follow-up audits, performing penetration...

Episode 126: Vulnerability Response and Remediation (Part 2) (Domain 4) 15.06.2025

Not all vulnerabilities can be patched right away, and in these cases, compensating controls, segmentation, and exceptions become essential components of a realistic remediation strategy. In this episode, we discuss how organizations can use host firewalls, access control lists, and network isolation to contain vulnerable systems while planning for a longer-term fix. We also explore how to formall...

Episode 125: Vulnerability Response and Remediation (Part 1) (Domain 4) 15.06.2025

Finding vulnerabilities is only useful if you have a plan to fix them—and this episode dives into the critical processes of response and remediation. We begin with patching, one of the most effective and often underutilized defenses in cybersecurity. Timely and tested patch application is essential for operating systems, applications, firmware, and even cloud services, yet many organizations strug...

Episode 124: Vulnerability Analysis and Prioritization (Part 2) (Domain 4) 15.06.2025

Expanding on the concepts of vulnerability prioritization, this episode introduces industry-standard scoring and classification systems like CVSS (Common Vulnerability Scoring System) and CVE (Common Vulnerabilities and Exposures), which provide a structured way to quantify and compare risks. We explain how CVSS scores are calculated using metrics like attack complexity, required privileges, user...

Listen to the Certified: The CompTIA Security+ Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.