Dr. Jason Edwards
Certified: The CompTIA Security+ Audio Course
Certified - Security+ 701 is your completely free audio companion for mastering the CompTIA Security+ SY0-701 certification exam. Developed by BareMetalCyber.com, this immersive Audio Course transforms every domain of the official exam objectives into clear, practical, and exam-ready lessons you can learn anywhere—whether commuting, exercising, or studying at home. Each episode delivers focused explanations, real-world examples, and proven study strategies designed to build confidence and help you pass on your first attempt. Structured for busy professionals and new learners alike, the series...
Author
Dr. Jason Edwards
Category
Podcast website
Latest episode
Apr 28, 2026
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Episode 123: Vulnerability Analysis and Prioritization (Part 1) (Domain 4) 15.06.2025 17:41
Once vulnerabilities are identified, the next challenge is determining which ones require immediate action—and that’s where vulnerability analysis and prioritization come in. In this episode, we explore how to confirm whether a vulnerability is real (not a false positive), determine its potential impact, and assess exploitability in the context of your specific environment. Not every high-severity...
Episode 122: System and Process Auditing (Domain 4) 15.06.2025 17:44
Auditing is how security teams verify that controls are working, policies are being followed, and no one is operating outside expected behavior—and in this episode, we explore both system and process auditing in depth. System audits focus on configurations, permissions, and change logs—ensuring that operating systems, devices, and applications remain in a secure, known state. Process audits, on th...
Episode 121: Vulnerability Identification Methods (Part 2) (Domain 4) 15.06.2025 17:40
Continuing our exploration of how vulnerabilities are identified, this episode focuses on external and community-driven methods, including penetration testing, bug bounty programs, responsible disclosure, and open-source intelligence (OSINT). Penetration testing simulates real-world attack scenarios—often with limited knowledge—to uncover exploitable weaknesses that automated scanners might miss,...
Episode 120: Vulnerability Identification Methods (Part 1) (Domain 4) 15.06.2025 18:25
Finding vulnerabilities before attackers do is a core function of modern cybersecurity, and this episode explores the technical methods used to identify them early and accurately. We begin with vulnerability scanning—automated tools that assess systems for known weaknesses, configuration flaws, and missing patches, often using regularly updated databases and scoring systems like CVSS. We also disc...
Episode 119: Data Retention and Secure Management Practices (Domain 4) 15.06.2025 18:15
Data retention policies define what data must be kept, for how long, and under what security controls—and when they’re done right, they strike a balance between legal obligations, operational needs, and security. In this episode, we explore how organizations develop and enforce data retention practices that comply with regulations like GDPR, HIPAA, or PCI-DSS while also avoiding unnecessary data h...
Episode 118: Secure Asset Disposal and Decommissioning (Domain 4) 15.06.2025 17:09
When assets reach the end of their lifecycle, they don’t just disappear—they become potential liabilities if not securely decommissioned. In this episode, we explore the processes and tools used for secure asset disposal, including data sanitization, cryptographic wiping, degaussing, and physical destruction. We also discuss how improperly retired systems—like old servers, network devices, or hard...
Episode 117: Asset Monitoring and Tracking (Domain 4) 15.06.2025 17:28
Security begins with visibility, and that means knowing what devices, systems, and software exist within your environment at all times. In this episode, we dive into asset monitoring and tracking, emphasizing the importance of real-time discovery tools, agent-based scanning, and centralized asset inventories that support security monitoring, patch management, and incident response. We also explore...
Episode 116: Assignment, Ownership, and Classification (Domain 4) 15.06.2025 18:01
To manage risk effectively, organizations must know what they own, who is responsible for it, and how critical it is—this is the basis of asset assignment, ownership, and classification. In this episode, we discuss the importance of tagging and tracking assets, designating accountable owners, and classifying systems and data based on sensitivity and function. Ownership enforces accountability: eve...
Episode 115: Acquisition and Procurement Security (Domain 4) 15.06.2025 17:53
Security doesn’t start when a system is installed—it begins during the procurement process. In this episode, we examine how secure acquisition strategies reduce long-term risk by vetting vendors, establishing supply chain transparency, and embedding cybersecurity requirements in contracts and service-level agreements (SLAs). We discuss how organizations should assess the security posture of suppli...
Episode 114: Isolation and Monitoring Techniques (Domain 4) 15.06.2025 17:38
Isolation and monitoring form a defensive pairing that not only limits the spread of threats but enables rapid detection and response. In this episode, we discuss isolation technologies like sandboxing, virtualization, and containerization, which allow untrusted or risky code to run without impacting the host system. We then move into monitoring practices at both the host and network levels, empha...
Episode 113: Application Security Essentials (Domain 4) 15.06.2025 18:19
Applications are often the most exposed layer of an organization’s attack surface, and defending them requires both proactive development practices and reactive protection mechanisms. In this episode, we review essential application security concepts including input validation, secure cookie handling, and session management to prevent injection attacks, cross-site scripting (XSS), and session hija...
Episode 112: Advanced Wireless Security Techniques (Domain 4) 15.06.2025 18:49
As wireless threats become more sophisticated, organizations must move beyond basic security measures and implement advanced techniques to protect access points and users. In this episode, we cover the use of WPA3 for stronger encryption and resistance to brute-force attacks, along with 802.1X authentication backed by RADIUS servers for identity-based access control. We explore the use of digital...
Episode 111: Securing Mobile Connectivity (Domain 4) 15.06.2025 19:37
Mobile devices connect through a variety of channels—cellular networks, Wi-Fi, and Bluetooth—each with its own risks and requirements for secure operation. In this episode, we examine the vulnerabilities introduced by unsecured public Wi-Fi, rogue access points, and Bluetooth pairing, and how attackers can exploit these to conduct man-in-the-middle (MitM) attacks, spoofing, or data interception. W...
Episode 110: Securing Mobile Solutions (Domain 4) 15.06.2025 18:38
Mobile devices have become indispensable for productivity, but they also introduce unique security challenges due to their portability, connectivity, and often personal ownership. In this episode, we explore how mobile device management (MDM) platforms enable organizations to enforce policies on corporate-owned and bring-your-own-device (BYOD) endpoints alike, controlling app installation, encrypt...
Episode 109: Securing Wireless Networks (Part 1) (Domain 4) 15.06.2025 18:28
Wireless networks offer convenience, but they also expand the attack surface by broadcasting connectivity beyond physical boundaries, making them inherently riskier than wired alternatives. In this episode, we focus on securing wireless environments beginning with proper access point placement, signal strength tuning, and site surveys that help prevent signal bleed and rogue AP exposure. We also c...
Episode 108: Hardening Embedded Systems and IoT Devices (Domain 4) 15.06.2025 18:16
Embedded systems and IoT devices often operate in environments where security is either underprioritized or extremely difficult to implement, making them prime targets for persistent threats. In this episode, we dive into the unique challenges of hardening these devices, including limited processing power, minimal user interfaces, and inconsistent update mechanisms. Many come with hardcoded creden...
Episode 107: Hardening Computing Resources (Part 2) (Domain 4) 15.06.2025 18:07
Continuing our discussion on hardening, this episode shifts focus to cloud infrastructure, servers, and industrial systems—each of which requires a tailored approach based on operational roles, architecture, and threat exposure. For cloud systems, hardening includes enforcing role-based access control, disabling unused services, encrypting storage, and monitoring resource usage across accounts and...
Episode 106: Hardening Computing Resources (Part 1) (Domain 4) 15.06.2025 18:51
Hardening is the practice of stripping down systems to only what they need to function securely, and this episode focuses on doing just that for mobile devices, workstations, switches, and routers. These devices often serve as entry points for attackers, especially when defaults are left in place, unnecessary services are running, or updates are neglected. We cover basic but essential steps such a...
Episode 105: Secure Baselines and System Management (Domain 4) 15.06.2025 22:33
Establishing a secure baseline is one of the most fundamental—and often overlooked—steps in managing system security. In this episode, we explain how baselines define the minimum acceptable security configuration for a given system, including settings for password policies, logging, services, ports, user rights, and installed software. These baselines serve as both a reference point for compliance...
Episode 104: Introduction to Domain Four — Security Operations 15.06.2025 17:29
If Domains One through Three are about understanding the principles and design of cybersecurity, then Domain Four is about the actual day-to-day work that keeps systems secure. This is where cybersecurity gets real. Welcome to Security Operations. Domain Four is the largest domain on the Security Plus exam. It makes up 28 percent of the test—that’s nearly one-third of the total questions. That alo...
Episode 103: Power Resilience and Continuity (Domain 3) 15.06.2025 17:06
Without reliable power, even the most secure systems are at risk of failure—and in many environments, loss of power is both a security and safety issue. In this episode, we explore how power resilience contributes to business continuity, starting with uninterruptible power supplies (UPS) that bridge short outages and allow graceful shutdowns. We cover the role of backup generators for longer-term...
Episode 102: Data Recovery Techniques (Domain 3) 15.06.2025 27:17
Backups are only half of the story—the other half is how effectively you can recover from them. In this episode, we focus on data recovery techniques that turn dormant backups into operational systems, covering strategies such as replication, journaling, point-in-time recovery, and bare-metal restoration. We define and differentiate between Recovery Time Objective (RTO)—how quickly you need to be...
Episode 101: Backup Strategies and Best Practices (Part 2) (Domain 3) 15.06.2025 16:24
Continuing our discussion on backups, this episode explores encryption, snapshots, and backup lifecycle management—three critical components of a secure, efficient, and resilient backup system. Encrypting backups is essential to protect sensitive data in the event of theft or unauthorized access to storage media, whether local or cloud-based. We explain how key management, access controls, and enc...
Episode 100: Backup Strategies and Best Practices (Part 1) (Domain 3) 15.06.2025 16:34
Backups form the last line of defense when everything else fails, and a good strategy turns potential disaster into a recoverable event. In this episode, we discuss core backup principles and best practices, including the 3-2-1 rule—keep three copies of your data, on two different media types, with one stored offsite. We cover the strengths and trade-offs between full, differential, and incrementa...
Episode 99: Comprehensive Testing for Resilience (Domain 3) 15.06.2025 16:49
Preparation is only as good as its ability to withstand the unexpected, and resilience testing is how you find out whether your systems, processes, and people are truly ready. In this episode, we explore the value of comprehensive testing methods such as tabletop exercises, simulated failovers, load tests, and real-world attack scenarios. Tabletop exercises walk teams through incident response ste...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.