Dr. Jason Edwards

Certified: The CompTIA Security+ Audio Course

Certified - Security+ 701 is your completely free audio companion for mastering the CompTIA Security+ SY0-701 certification exam. Developed by BareMetalCyber.com, this immersive Audio Course transforms every domain of the official exam objectives into clear, practical, and exam-ready lessons you can learn anywhere—whether commuting, exercising, or studying at home. Each episode delivers focused explanations, real-world examples, and proven study strategies designed to build confidence and help you pass on your first attempt. Structured for busy professionals and new learners alike, the series...

Author

Dr. Jason Edwards

Category

Technology

Podcast website

baremetalcyber.com

Latest episode

Apr 28, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 48: Supply Chain and Cryptographic Vulnerabilities (Domain 2) 15.06.2025

Modern cybersecurity is deeply interconnected, and vulnerabilities in your vendors, partners, or third-party software can easily become vulnerabilities in your own environment. In this episode, we explore supply chain attacks—like trojanized software updates, compromised developer tools, or backdoors inserted at the firmware level—that undermine trust and introduce malicious code before it even re...

Episode 47: Virtualization and Cloud-Specific Vulnerabilities (Domain 2) 15.06.2025

Virtualization and cloud computing introduce powerful efficiencies—but they also open up new categories of vulnerabilities that traditional security models often fail to address. In this episode, we examine risks like virtual machine (VM) escape, where an attacker breaks out of an isolated VM and interacts directly with the host or other VMs, as well as resource reuse issues that can lead to unint...

Episode 46: Hardware and Firmware Vulnerabilities (Domain 2) 15.06.2025

Cybersecurity doesn’t stop at software—hardware and firmware vulnerabilities can offer attackers deep, long-term access to systems in ways that are difficult to detect and even harder to fix. In this episode, we explore how outdated firmware, hardcoded credentials, unsigned updates, and direct memory access (DMA) features can be exploited to bypass software-level protections. We also discuss the r...

Episode 45: Operating System and Web-Based Vulnerabilities (Domain 2) 15.06.2025

Operating systems and web applications form the backbone of IT infrastructure, and when left unpatched or misconfigured, they present rich targets for exploitation. In this episode, we look at vulnerabilities like privilege escalation, insecure services, and poor access controls in operating systems, along with web-based flaws such as SQL injection and cross-site scripting (XSS). These weaknesses...

Episode 44: Application-Level Vulnerabilities (Domain 2) 15.06.2025

Applications serve as the user-facing layer of most digital environments, and they are frequently targeted by attackers exploiting poor coding practices and flawed design. In this episode, we dive into critical application-level vulnerabilities including memory injection, buffer overflows, and race conditions like time-of-check/time-of-use (TOC/TOU) flaws. These vulnerabilities often allow attacke...

Episode 43: Human Vectors and Social Engineering (Part 2) (Domain 2) 15.06.2025

While basic social engineering relies on message-based deception, more advanced techniques target identity, credibility, and digital presence through impersonation, pretexting, and domain spoofing. In this episode, we examine how attackers craft elaborate backstories or scenarios to manipulate users into granting access, exposing data, or clicking on malicious content. Business Email Compromise (B...

Episode 42: Human Vectors and Social Engineering (Part 1) (Domain 2) 15.06.2025

People are often the weakest link in cybersecurity, and attackers exploit this through carefully crafted manipulation tactics known as social engineering. In this episode, we focus on phishing, vishing, and smishing—three common techniques that deceive users through email, phone, and SMS to trick them into revealing credentials, clicking malicious links, or installing malware. These attacks rely o...

Episode 41: Open Ports, Default Credentials, and Supply Chain Risks (Domain 2) 15.06.2025

Even the best-configured systems can fall victim to the most basic security oversights—like open ports and unchanged default passwords. In this episode, we focus on how these simple but dangerous misconfigurations continue to be exploited, providing easy access points for attackers using automated scanning tools. We also explore the broader risk posed by third-party vendors, suppliers, and managed...

Episode 40: Network-Based Attack Surfaces (Domain 2) 15.06.2025

Your network is the digital highway that connects everything in your organization—and if not properly secured, it becomes the perfect path for attackers. In this episode, we explore the many ways that insecure networks create broad attack surfaces, with a focus on both wired and wireless vulnerabilities. We cover threats such as rogue access points, Wi-Fi spoofing, Bluetooth exploitation, and phys...

Episode 39: Vulnerable Systems, Software, and Devices (Domain 2) 15.06.2025

Many attacks succeed not because of advanced hacking techniques, but because of outdated, misconfigured, or unsupported systems that haven’t been properly maintained. This episode addresses the vulnerabilities introduced by aging operating systems, unpatched applications, and insecure endpoints—including laptops, mobile phones, and IoT devices. We also differentiate between client-based and agentl...

Episode 38: Image, File, and Voice-Based Threats (Domain 2) 15.06.2025

While emails and text messages are well-known vectors, attackers also exploit images, file attachments, and voice communication to bypass traditional security controls. In this episode, we explore steganography—embedding malicious code or data within image files—as well as the risks posed by file-based threats hidden in PDFs, Office documents, and ZIP archives that exploit unpatched applications o...

Episode 37: Message-Based and Communication Threat Vectors (Domain 2) 15.06.2025

Attackers frequently exploit messaging channels—email, SMS, and instant messaging—to deliver payloads, harvest credentials, or manipulate users into making harmful decisions. In this episode, we explore how communication platforms serve as high-risk threat vectors, focusing on phishing, smishing (SMS phishing), and malicious messaging over tools like Slack, Teams, or WhatsApp. These attacks often...

Episode 36: Introduction to Threat Vectors and Attack Surfaces (Domain 2) 15.06.2025

Cybersecurity is not just about knowing your enemy—it’s about understanding the paths they take to reach you. This episode introduces threat vectors and attack surfaces, two essential concepts for identifying exposure and hardening defenses. A threat vector is the specific method or route used by an attacker to exploit a vulnerability, such as phishing emails, unpatched software, or rogue USB devi...

Episode 35: Motivations Behind Cyber Attacks (Part 3) (Domain 2) 15.06.2025

Not all cyberattacks are launched for money or politics—some are driven by emotion, chaos, or war. In this episode, we examine three additional motivations: revenge, disruption, and warfare. Revenge-driven attacks often originate from disgruntled employees, ex-partners, or individuals with personal grievances, and they may involve sabotage, data deletion, or insider leaks. Disruption for disruptio...

Episode 34: Motivations Behind Cyber Attacks (Part 2) (Domain 2) 15.06.2025

Cyber threats aren’t always driven by stealth or sophistication—sometimes they are fueled by money, ideology, or ethics. In this episode, we continue our exploration of attacker motivations by examining financial gain, political activism, and the blurred lines between ethical and unethical hacking. Financially motivated attackers may use ransomware, banking Trojans, phishing scams, or e-commerce s...

Episode 33: Motivations Behind Cyber Attacks (Part 1) (Domain 2) 15.06.2025

Behind every cyberattack is a motive, and understanding why attackers do what they do is essential for predicting and preventing their behavior. This episode explores some of the most common motivations that drive malicious activity: data exfiltration, cyber espionage, denial of service, and blackmail. Data exfiltration involves stealing sensitive or proprietary data for financial, competitive, or...

Episode 32: Attributes and Capabilities of Threat Actors (Domain 2) 15.06.2025

To effectively model risk and defend systems, cybersecurity professionals must understand not just who the attackers are, but what they are capable of . In this episode, we analyze the key attributes that define threat actors: whether they are internal or external, well-funded or opportunistic, highly skilled or reliant on publicly available tools. These characteristics determine the methods and s...

Episode 31: Insider Threats, Organized Crime, and Shadow IT (Domain 2) 15.06.2025

Some of the most damaging cybersecurity incidents originate not from unknown hackers, but from within—through employees, vendors, or unmanaged systems operating outside official channels. In this episode, we explore insider threats in depth, breaking them into categories like malicious insiders, negligent users, and compromised individuals, each presenting different risks to data confidentiality,...

Episode 30: Understanding Threat Actors (Domain 2) 15.06.2025

Cyber threats come in many forms, and to defend effectively, you must understand the adversaries behind the attacks. This episode explores common categories of threat actors, including nation-state groups, cybercriminal organizations, hacktivists, insiders, and unskilled attackers (often called script kiddies). Each actor type operates with different motivations, levels of funding, technical capab...

Episode 29: Introduction to Domain Two — Threats, Vulnerabilities, and Mitigations 15.06.2025

If Domain One is the foundation of cybersecurity—built on core principles and frameworks—then Domain Two is where we start applying that knowledge to real-world threats. This is the domain where you learn what we’re actually defending against. You’ll explore how attackers operate, what kinds of vulnerabilities they target, and how defenders recognize and respond to malicious activity. If you’re so...

Episode 28: Certificates, Authorities, and Management (Domain 1) 15.06.2025

Digital certificates are the backbone of online trust, providing the mechanism for authenticating websites, users, devices, and software in a secure, scalable manner. In this episode, we examine the lifecycle and infrastructure behind certificates, beginning with the role of Certificate Authorities (CAs) in issuing and signing them. We explain how trust is built through a chain of certificates tha...

Episode 27: Advanced Cryptographic Techniques (Domain 1) 15.06.2025

Modern threats require advanced cryptographic responses, and in this episode, we explore the techniques that strengthen authentication, protect weak credentials, and secure transactional data at scale. We begin with key stretching—methods like bcrypt, PBKDF2, and scrypt that increase the computational time needed to brute-force a password hash, adding layers of defense even when password quality i...

Episode 26: Hashing, Salting, and Digital Signatures (Domain 1) 15.06.2025

Data integrity and authenticity are two foundational pillars of cybersecurity, and in this episode, we explore how hashing, salting, and digital signatures help uphold both. Hashing generates a fixed-length output from variable input, creating a digital fingerprint that can be used to verify whether data has been tampered with. Common algorithms like SHA-256 are used in password storage, file inte...

Episode 25: Obfuscation and Data Protection Techniques (Domain 1) 15.06.2025

While encryption is the gold standard for confidentiality, it’s not the only method for protecting sensitive information—especially in use cases like software development, privacy regulation, or fraud prevention. In this episode, we examine alternative data protection strategies including obfuscation, steganography, tokenization, and data masking. Obfuscation refers to making data or code difficul...

Episode 24: Cryptographic Hardware and Secure Storage (Domain 1) 15.06.2025

Software-based encryption can be effective, but for high-assurance environments, hardware-based cryptography adds critical layers of tamper resistance and performance optimization. This episode explores devices and technologies that provide physical and logical security for cryptographic keys, including Trusted Platform Modules (TPMs), Hardware Security Modules (HSMs), and secure enclaves. We expl...

Listen to the Certified: The CompTIA Security+ Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.