Jason Edwards
Certified: The CompTIA Security+ V8 / SY0-801 Audio Course
Certified: The CompTIA Security+ V8 / SY0-801 Audio Course is built for learners who want a clear, practical path into modern cybersecurity fundamentals without being tied to a desk. It is designed for entry-level security professionals, IT support staff, help desk technicians, junior system administrators, career changers, and anyone preparing for the Security+ exam. The course assumes you may already understand basic networking and computer systems, but it does not assume deep security experience. Each lesson explains the ideas behind the exam objectives in plain language, then connects them...
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Welcome to the CompTIA Security+ Audio Course! 27.04.2026 1:13
Certified: The CompTIA Security+ V8 / SY0-801 Audio Course is built for learners who want a clear, practical path into modern cybersecurity fundamentals without being tied to a desk. It is designed for entry-level security professionals, IT support staff, help desk technicians, junior system administrators, career changers, and anyone preparing for the Security+ exam. The course assumes you may al...
Episode 118 — Final Objectives Update: What Changed When CompTIA Finalized SY0-801 (Update) 27.04.2026 14:12
This episode is reserved for final updates after CompTIA finalizes the SY0-801 exam objectives. Its purpose is to identify what changed from the draft objectives, including added topics, removed topics, renamed terms, reorganized objectives, weight changes, or clarified wording that affects study priorities. Students should use this episode as a fast alignment check so earlier preparation remains...
Episode 117 — Full-Course Review: The SY0-801 Memory Map (Review) 27.04.2026 16:42
This episode provides a guided review of the major relationships students should remember across the SY0-801 course. The five-domain structure can be understood as a connected security model: threats and vulnerabilities create risk, risk drives control selection, controls support secure architecture, operations generate evidence, and governance guides repeatable decisions. Students should review c...
Episode 116 — PBQ Strategy: Turning Objectives into Scenario Decisions (Review) 27.04.2026 15:18
This episode teaches students how to approach performance-based questions by turning exam objectives into practical scenario decisions. A strong PBQ approach starts by identifying the task, the environment, the security goal, and the evidence provided. Students should look for clues such as system type, data sensitivity, user role, log entries, network placement, access requirement, or incident st...
Episode 115 — Awareness Delivery and Effectiveness: LMS, Self-Service, Metrics, Behavior Risk Scoring, BEC, BYOD, and Remote Work (5.6) 27.04.2026 14:51
This episode covers how security awareness is delivered, measured, and improved over time. Students should understand learning management systems, self-service training, one-to-one instruction, and one-to-many instruction as different ways to reach users based on scale, role, and need. Effectiveness metrics may include completion rates, phishing simulation results, reporting rates, repeat failures...
Episode 114 — Security Awareness Training: Onboarding, Ongoing, Targeted, and Corrective Training (5.6) 27.04.2026 13:12
This episode explains security awareness as an ongoing program rather than a one-time compliance activity. Students should understand onboarding training as the first introduction to organizational expectations, acceptable use, data handling, reporting procedures, and common threats. Ongoing training reinforces important behaviors over time, while targeted training focuses on specific roles, risks...
Episode 113 — Penetration Testing, Reconnaissance, Frameworks, Functional Testing, and Behavioral Testing (5.5) 27.04.2026 14:56
This episode explains penetration testing and related assessment methods at a Security+ level. Students should understand the difference between known, unknown, and partially known environments, where testers may have full information, no internal knowledge, or limited details before testing begins. Reconnaissance may be active, involving direct interaction with targets, or passive, relying on pub...
Episode 112 — Audit Scope and Engagements: Charters, Gap Analysis, Internal Reviews, External Reviews, and Benchmarking (5.5) 27.04.2026 14:41
This episode covers audit scope and engagement planning, including charters, frequency, boundaries, gap analysis, internal reviews, external reviews, regulatory assessments, and benchmarking. Students should understand that an audit charter defines authority, purpose, responsibilities, and scope so the review is properly controlled and understood. Gap analysis compares the current state to a requi...
Episode 111 — Audit Data Gathering: Sampling, Questionnaires, Interviews, Assertions, and Reference Sources (5.5) 27.04.2026 13:11
This episode explains how audits and assessments gather evidence to determine whether controls, processes, and security requirements are working as expected. Students should understand sampling as reviewing a representative portion of records or systems rather than every item, while questionnaires and interviews help collect information from control owners, administrators, users, and stakeholders....
Episode 110 — Non-Compliance, Privacy Rights, Legal Holds, Legal Orders, and Retention (5.4) 27.04.2026 15:47
This episode covers the consequences of non-compliance and the legal and privacy concepts that shape data handling decisions. Students should understand that non-compliance can lead to reputational damage, financial penalties, legal action, contract violations, license loss, operational disruption, and loss of customer trust. Privacy rights may include opt-in and opt-out choices, access to persona...
Episode 109 — Compliance Training and Monitoring: Data Handling, AML/CTF, Anti-Bribery, and Attestations (5.4) 27.04.2026 14:15
This episode explains compliance as the need to meet laws, regulations, contracts, internal policies, and industry standards. Students should understand that compliance training helps employees know what is required for data handling, privacy, reporting, acceptable behavior, and regulated business activity. Anti-money laundering and counter-terrorist financing controls focus on detecting and preve...
Episode 108 — Vendor Constraints and Rules of Engagement: Jurisdiction, ROI, Lock-In, and Assurance Mechanisms (5.3) 27.04.2026 13:58
This episode explains vendor constraints and assurance mechanisms that affect third-party risk decisions. Students should understand that staffing, resources, geography, jurisdiction, return on investment, and vendor lock-in can influence whether a third-party relationship is practical, secure, and sustainable. Jurisdiction matters because laws, privacy requirements, and legal remedies may differ...
Episode 107 — Agreements and Monitoring: SLA, SLO, MOU, MOA, NDA, MSA, SOW, and Right to Audit (5.3) 27.04.2026 14:53
This episode covers common third-party agreements and monitoring terms that define expectations between organizations. Service-level agreements establish required service commitments, while service-level objectives define measurable targets that support those commitments. Memorandums of understanding and memorandums of agreement document shared expectations, responsibilities, or cooperation. Nondi...
Episode 106 — Third-Party Risk: Vendor Selection, RFP, RFI, RFQ, EOI, Due Diligence, and Conflicts (5.3) 27.04.2026 13:03
This episode explains third-party risk and why vendors, partners, suppliers, service providers, and contractors can extend an organization’s attack surface and compliance obligations. Students should understand vendor selection as a security-relevant process that evaluates capability, reliability, controls, cost, and fit. Requests for information gather general details, requests for proposal ask v...
Episode 105 — Risk Treatment and Business Impact: Transfer, Accept, Avoid, Mitigate, BIA, Appetite, Residual Risk, SLE, ALE, and ARO (5.2) 27.04.2026 13:36
This episode covers risk treatment and business impact concepts that help organizations decide what to do after a risk is assessed. Students should understand that risk can be transferred through insurance or contracts, accepted when leadership chooses to live with it, avoided by stopping the risky activity, or mitigated by applying controls. A business impact analysis identifies critical processe...
Episode 104 — Risk Analysis and Registers: Impact, Likelihood, Owners, Current Mitigations, and Qualitative vs. Quantitative Risk (5.2) 27.04.2026 13:17
This episode explains risk analysis and the role of the risk register in tracking organizational risk. Students should understand impact as the amount of harm a risk could cause and likelihood as the chance that the risk may occur. Risk owners are responsible for tracking, reporting, and supporting treatment decisions, while current mitigations show what controls already reduce exposure. A risk re...
Episode 103 — Risk Identification and Assessment: Assets, Stakeholders, Scoring, and Categorization (5.2) 27.04.2026 13:06
This episode introduces risk identification and assessment as the process of finding what could go wrong, what assets could be affected, and who needs to be involved in the decision. Students should understand that assets may include systems, data, facilities, services, people, vendors, applications, and business processes. Stakeholders help define business value, ownership, acceptable impact, and...
Episode 102 — Plans and Policies: BCP, DRP, BYOD, AUP, Clean Desk, Incident Response, Data Retention, Access Control, and Privacy (5.1) 27.04.2026 14:47
This episode covers major security plans and policies students are expected to recognize for the Security+ exam. Business continuity plans focus on keeping essential functions operating, while disaster recovery plans focus on restoring systems and data after disruption. BYOD policies define rules for personally owned devices, acceptable use policies explain proper technology behavior, and clean de...
Episode 101 — Standards and Procedures: Baselines, Passwords, Physical Security, RFCs, Encryption, SOPs, and Runbooks (5.1) 27.04.2026 14:41
This episode explains how standards and procedures turn broad security policy into repeatable action. Students should understand that baselines define approved configuration settings, password standards establish expectations for authentication strength, physical security standards guide facility and equipment protection, and encryption standards define approved methods for protecting data. RFCs c...
Episode 100 — GRC Artifacts: Guidelines, Benchmarks, Advisories, Implementation Guides, and Reference Architectures (5.1) 27.04.2026 14:41
This episode introduces governance, risk, and compliance artifacts that help organizations build consistent security programs. Guidelines provide recommended practices, benchmarks define measurable configuration expectations, advisories warn about risks or required action, implementation guides explain how to apply controls, and reference architectures show approved patterns for secure design. For...
Episode 99 — Evidence and Stakeholders: File Integrity, Memory Dumps, Bit Copies, Snapshots, HR, Legal, and Log Parsing (4.8) 27.04.2026 14:34
This episode explains evidence handling and stakeholder involvement during security investigations. File integrity checks help confirm whether files were changed, while log integrity helps determine whether records can be trusted. Memory dumps may capture volatile evidence such as running processes, active connections, encryption keys, or malware artifacts. Bit-level copies preserve storage for fo...
Episode 98 — Investigation Sources: Vulnerability Scans, Automated Reports, NetFlow/IPFIX, Surveillance, and Packet Captures (4.8) 27.04.2026 15:19
This episode covers investigation sources beyond standard logs, including vulnerability scans, automated reports, NetFlow, IPFIX, surveillance footage, dashboards, and packet captures. Vulnerability scans can show known weaknesses that may explain an entry point, while automated reports can summarize recurring issues, compliance status, or tool findings. NetFlow and IPFIX describe traffic patterns...
Episode 97 — Investigation Data Types: Access, Device, Server, Application, Authentication, Communication, and Audit Logs (4.8) 27.04.2026 15:29
This episode explains the major log categories used during security investigations and how each source contributes part of the incident story. Access logs show who reached a resource and when, device logs reveal endpoint or network device activity, server logs show operating system or service behavior, and application logs provide details about application events, errors, transactions, or suspicio...
Episode 96 — Containment Through Post-Incident: Isolation, Negotiation, Recovery, Reporting, Lessons Learned, and RCA (4.7) 27.04.2026 14:05
This episode covers the incident response path from containment through post-incident activity. Containment limits damage by isolating systems, disabling accounts, blocking traffic, or separating affected environments. Eradication removes the cause of compromise, and recovery restores systems, data, services, and normal operations while monitoring for reoccurrence. Some incidents may involve exter...
Episode 95 — Identification and Investigation: Detection, Advisories, Threat Hunting, Forensics, and Chain of Custody (4.7) 27.04.2026 13:55
This episode explains how teams identify and investigate potential security incidents using alerts, advisories, threat hunting, forensics, and evidence handling. Detection may begin with monitoring tools, user reports, endpoint alerts, network anomalies, or external notifications. Advisories can help teams determine whether a known threat applies to their environment, while threat hunting proactiv...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.