Jason Edwards

Certified: The CompTIA Security+ V8 / SY0-801 Audio Course

Certified: The CompTIA Security+ V8 / SY0-801 Audio Course is built for learners who want a clear, practical path into modern cybersecurity fundamentals without being tied to a desk. It is designed for entry-level security professionals, IT support staff, help desk technicians, junior system administrators, career changers, and anyone preparing for the Security+ exam. The course assumes you may already understand basic networking and computer systems, but it does not assume deep security experience. Each lesson explains the ideas behind the exam objectives in plain language, then connects them...

Author

Jason Edwards

Category

Technology

Latest episode

Apr 27, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 69 — Mitigating Controls Overview: Segmentation, Access Control, Hardening, and Sandboxing (4.1) 27.04.2026

This episode introduces mitigating controls as practical actions that reduce risk after threats, vulnerabilities, or exposures are identified. Segmentation limits movement between systems or zones, access control restricts who or what can reach resources, hardening removes unnecessary services and insecure settings, and patching addresses known weaknesses. Isolation and sandboxing contain suspicio...

Episode 68 — Recovery Metrics: RTO, RPO, MTTR, and MTBF (3.4) 27.04.2026

This episode explains four recovery and reliability metrics that frequently appear in Security+ questions. Recovery time objective defines the maximum acceptable time to restore a service after disruption, while recovery point objective defines the maximum acceptable amount of data loss measured in time. Mean time to repair measures the average time needed to restore a failed component or service,...

Episode 67 — Disaster Recovery and Business Continuity: Failover, Simulation, Parallel Processing, and Capacity Planning (3.4) 27.04.2026

This episode explains the relationship between disaster recovery and business continuity. Disaster recovery focuses on restoring technology and data after disruption, while business continuity focuses on keeping essential business functions operating during and after an incident. Students should understand failover testing, simulations, tabletop exercises, parallel processing, and capacity plannin...

Episode 66 — Power, Storage, Backups, Immutability, and Restoration Testing (3.4) 27.04.2026

This episode explains resilience controls related to power, storage, backups, immutability, and recovery validation. Uninterruptible power supplies provide short-term power during interruptions, redundant power supplies reduce hardware failure risk, generators support longer outages, and surge protection helps protect equipment from electrical damage. Storage resilience may involve redundancy, rep...

Episode 65 — Platform Diversity, Load Balancing, Clustering, Autoscaling, and High Availability (3.4) 27.04.2026

This episode covers design methods that improve resilience and reduce single points of failure. Platform diversity can reduce the chance that one common flaw affects every system, though it may increase management complexity. Load balancing distributes traffic across multiple systems to improve performance and availability, while clustering allows systems to work together so one node can fail with...

Episode 64 — Resilience Sites: Hot, Warm, Cold, and Environmental Planning (3.4) 27.04.2026

This episode explains hot, warm, and cold recovery sites and how they support resilience and disaster recovery planning. A hot site is ready for rapid failover with systems, connectivity, and data prepared for use, while a warm site has some infrastructure ready but may require configuration or data restoration. A cold site provides space and basic facilities but requires more setup before operati...

Episode 63 — Data Handling, Geofencing, Lifecycle, Retention, Disposal, and Compliance (3.3) 27.04.2026

This episode explains data handling across the full data lifecycle, from creation and collection through storage, use, sharing, retention, archival, and disposal. Students should understand that data protection is not limited to encryption; it also includes classification, approved storage locations, access rules, handling procedures, transfer methods, and disposal requirements. Geofencing and dat...

Episode 62 — Data Protection Roles: Owner, Custodian, Steward, Operator, Controller, and Subprocessor (3.3) 27.04.2026

This episode covers data protection roles and explains how responsibility is divided across people and organizations. A data owner is accountable for decisions about data use and protection, while a custodian manages storage, systems, and technical safeguards. A steward helps maintain quality, classification, and proper handling, and an operator may process or manage data according to assigned dut...

Episode 61 — Securing Data: Masking, Hashing, Filtering, Tokenization, Encryption, and Obfuscation (3.3) 27.04.2026

This episode explains common methods used to protect data and how each method serves a different security purpose. Masking hides part of a value, such as showing only the last digits of an account number, while hashing creates a fixed integrity value that should not be reversible. Filtering removes or blocks data based on rules, tokenization replaces sensitive values with substitute tokens, and en...

Episode 60 — Data Classification: Public to Top Secret, Sensitive to Restricted (3.3) 27.04.2026

This episode covers data classification labels and how they guide security decisions. Students should recognize common labels such as public, sensitive, confidential, restricted, critical, secret, and top secret, while understanding that exact labels vary by organization and industry. Classification helps determine who can access data, where it may be stored, whether it must be encrypted, how it s...

Episode 59 — Data Types and States: Structured, Unstructured, At Rest, In Use, and In Transit (3.3) 27.04.2026

This episode explains data types and data states, which are central to choosing the correct protection method. Structured data is organized in predictable formats such as databases and spreadsheets, while unstructured data includes documents, emails, images, chat records, and other content without a fixed schema. Data at rest is stored, data in transit is moving across a network, and data in use i...

Episode 58 — Identity Architecture: gMSAs, Least Privilege Accounts, Privilege Creep, and Failure Modes (3.2) 27.04.2026

This episode covers identity architecture as a core part of secure system design, especially where service accounts and administrative access are involved. Group managed service accounts help manage service credentials more safely by reducing manual password handling and supporting automatic credential management in appropriate environments. Least-privilege access accounts limit what users, servic...

Episode 57 — Out-of-Band Management, File Transfer, and Security Service Edge (3.2) 27.04.2026

This episode explains out-of-band management, secure file transfer, and Security Service Edge as architecture concepts tied to secure operations and access. Out-of-band management gives administrators a separate path to manage infrastructure when the primary network is unavailable, degraded, or compromised, but it must be strongly protected because it can provide powerful control. Secure file tran...

Episode 56 — Secure Access: VPNs, Remote Access, Tunneling, and Encrypted Messaging (3.2) 27.04.2026

This episode covers secure access technologies used to protect communication and allow users to reach systems from different locations. VPNs create encrypted connections over untrusted networks, while remote access tools support administration, support, and user productivity. Tunneling can carry one type of traffic through another protected channel, and end-to-end encrypted messaging protects mess...

Episode 55 — Zero Trust Architecture: User, Device, and Application Decisions (3.2) 27.04.2026

This episode explains Zero Trust architecture as a practical design approach where access decisions are based on identity, device health, application sensitivity, context, and risk. Students should understand that Zero Trust requires more than a strong login; it also depends on device inventory, posture checks, least privilege, segmentation, application access control, and continuous monitoring. A...

Episode 54 — Infrastructure Protection: Device Placement, Security Zones, Attack Surface, and Diversity (3.2) 27.04.2026

This episode introduces infrastructure protection by focusing on where controls are placed and how environments are divided. Students should understand that device placement affects visibility, enforcement, and risk, such as placing firewalls, sensors, proxies, and gateways where they can inspect the right traffic. Security zones separate systems by trust level, sensitivity, function, or exposure....

Episode 53 — Scalability, Environmental Requirements, Risk, and Recovery Decisions (3.1) 27.04.2026

This episode explains how scalability, environmental needs, risk, and recovery expectations influence secure architecture. Scalability means a system can grow to meet demand, but growth must be planned so security controls, logging, identity, network design, and data protection scale with it. Environmental requirements may include power, cooling, physical location, connectivity, hardware constrain...

Episode 52 — Business Architecture Tradeoffs: Data Sovereignty, Classification, Cost, and Ownership (3.1) 27.04.2026

This episode covers business architecture tradeoffs that influence secure design beyond purely technical preferences. Students should understand how data sovereignty affects where data may be stored, processed, or transferred, especially when laws or contracts require data to remain in certain jurisdictions. Classification drives handling, encryption, access, retention, and monitoring decisions. C...

Episode 51 — Technical Architecture Tradeoffs: Availability, Resilience, Open Source, and Usability (3.1) 27.04.2026

This episode explains how technical architecture decisions create tradeoffs across availability, resilience, responsibility, compute, power, recovery, and usability. For the Security+ exam, students should recognize that a design choice may improve one goal while creating cost, complexity, or operational risk somewhere else. High availability can reduce downtime but may require clustering, redunda...

Episode 50 — OT, Air-Gapped Networks, Microservices, and Segmentation 27.04.2026

This episode covers operational technology, air-gapped networks, microservices, and segmentation as architecture choices that affect isolation, monitoring, and risk. Operational technology supports physical processes such as manufacturing, utilities, building systems, and industrial control, so availability and safety may be more important than rapid patching. Air-gapped networks are separated fro...

Episode 49 — Serverless, Multicloud, and Infrastructure as Code 27.04.2026

This episode explains serverless computing, multicloud environments, and infrastructure as code as modern architecture concepts with important security implications. Serverless shifts operational responsibility for servers to the provider but still requires secure permissions, data protection, dependency management, and event handling. Multicloud can reduce reliance on one provider but may increas...

Episode 48 — Architecture Models: Cloud, On-Premises, Hybrid, Private, Public, and Community Cloud 27.04.2026

This episode compares major architecture and deployment models and the security responsibilities each creates. On-premises environments usually give the organization more direct control over hardware, networks, and physical access, but also more operational responsibility. Public cloud offers scalability and managed services, private cloud provides dedicated resources, hybrid models combine intern...

Episode 47 — AI Abuse: Jailbreaking, Evasion, Privacy, Session Hijacking, and Code Execution 27.04.2026

This episode covers ways AI-enabled systems can be abused when boundaries, permissions, or integrations are weak. Jailbreaking attempts to bypass safety or policy restrictions, while evasion attempts to avoid detection or filtering. Privacy exposure can occur when sensitive prompts, outputs, logs, or connected data sources are mishandled. Session hijacking becomes a concern when an attacker can st...

Episode 46 — AI Failure Risks: Data Loss, Bias, Explainability, Hallucinations, and Ethics 27.04.2026

This episode explains AI risks that can occur even when there is no traditional attacker. Data loss may happen when sensitive information is entered into tools, retained improperly, or exposed through connected systems. Bias can lead to unfair or unreliable outcomes, while poor explainability makes it difficult to understand why a system produced a result. Hallucinations occur when AI generates in...

Episode 45 — AI Threats: Model Manipulation, Poisoning, and Prompt Injection 27.04.2026

This episode introduces AI security threats at a Security+ level, focusing on how attackers may manipulate models, poison data, or use prompt injection to influence outputs. Model manipulation can involve attempts to change behavior, extract sensitive information, or cause unsafe responses. Poisoning can affect training data, reference data, retrieval sources, or business content used by an AI sys...

Listen to the Certified: The CompTIA Security+ V8 / SY0-801 Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.