Jason Edwards

Certified: The GIAC GPCS Audio Course

The podcast delivers practical cloud security guidance for professionals who have to ship real systems on real timelines. Episodes focus on the moves that prevent costly incidents: reducing accidental exposure, tightening identity and permissions, hardening serverless triggers, securing managed platforms, and building durable defaults that survive updates and team changes. The approach is technical and operational, with clear explanations that translate directly into repeatable patterns. Each topic is designed to help you think like both a defender and an architect: what attackers exploit firs...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 10, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 11 — Define cloud IAM fundamentals with least privilege as a living system 10.02.2026

This episode establishes the IAM concepts the GPCS exam expects you to apply across cloud providers: principals (users, groups, roles, service identities), authentication versus authorization, policies as explicit statements of allowed actions, and the difference between identity-based and resource-based controls. You’ll treat least privilege as a living system rather than a one-time configuration...

Episode 10 — Identify credential exposure paths from workloads, images, and build pipelines 10.02.2026

This episode surveys how credentials leak in cloud-native delivery, because many real incidents start with “temporary” secrets that quietly became permanent. You’ll define common exposure paths across runtime workloads (environment variables, local files, debug endpoints), machine images (baked-in keys, leftover tokens, unsafe defaults), and build pipelines (logs, artifacts, mis-scoped CI permissi...

Episode 9 — Build metadata-safe compute patterns that survive real attacker pressure 10.02.2026

This episode shifts from point fixes to resilient patterns: how to design compute deployments that remain secure even when an application layer fails. You’ll learn what “metadata-safe” means as an architectural objective, then apply it to common compute models like virtual machines, containers, and managed runtimes. We’ll cover best practices such as isolating sensitive workloads, minimizing outbo...

Episode 8 — Detect and prevent metadata-driven privilege escalation across cloud workloads 10.02.2026

This episode ties metadata abuse to privilege escalation outcomes so you can reason through exam questions that ask, “How does this become account compromise?” You’ll define escalation in cloud terms: pivoting from a workload identity to broader permissions, expanding access through overly powerful roles, and using newly gained credentials to enumerate, modify, or exfiltrate resources. We’ll empha...

Episode 7 — Assess metadata service hardening to block credential harvesting paths 10.02.2026

This episode focuses on practical defenses for metadata attacks, emphasizing how to evaluate whether hardening is real or merely assumed. You’ll connect hardening controls to the attack paths from the prior episode, including SSRF-to-metadata, compromised host-to-metadata, and misconfigured routing that unintentionally exposes metadata. We’ll cover design choices such as requiring stronger request...

Episode 6 — Understand instance metadata APIs and why attackers love them 10.02.2026

This episode explains instance metadata services as a high-value target in cloud environments, because they can expose identity tokens, configuration data, and privileged context to workloads that should not have it. You’ll define what metadata APIs are, why they exist, and how applications and agents legitimately use them for bootstrapping and discovery. Then we pivot to attacker thinking: how se...

Episode 5 — Spot shared responsibility gaps that quietly create real cloud exposure 10.02.2026

This episode clarifies shared responsibility in the way that prevents real incidents: not as a slogan, but as a control ownership model you can apply to any service. You’ll define where the provider stops and where the customer must configure, monitor, and govern, then connect that split to exam questions that test “who is accountable for what.” We’ll cover common gaps, like assuming managed servi...

Episode 4 — Compare AWS, Azure, and GCP security strengths and weak defaults 10.02.2026

This episode compares the big three cloud providers through the lens the exam cares about: what each does well, what defaults can betray you, and how the same security objectives show up in different product shapes. You’ll translate core domains—identity, network controls, logging, key management, and storage security—into cross-cloud equivalencies so you can reason from first principles when a qu...

Episode 3 — Map today’s public cloud landscape risks without vendor blind spots 10.02.2026

This episode builds a vendor-neutral threat and risk map for public cloud so you can answer exam questions that test principles, not brand trivia. You’ll frame the cloud as a set of shared control planes, identity systems, network abstractions, and managed services that shift failure modes compared to on-prem. We’ll define common risk categories—misconfiguration, identity over-permissioning, expos...

Episode 2 — Master GIAC testing rules, open-book boundaries, and proctoring realities 10.02.2026

This episode focuses on the operational rules that shape your risk on exam day, because a correct answer doesn’t help if you trigger a policy issue or lose time to preventable friction. You’ll define what “open book” really means for GIAC exams, how to keep reference materials usable without becoming a distraction, and what boundaries matter around notes, devices, and workspace setup. We’ll cover...

Episode 1 — Decode the GPCS exam format, timing, and scoring with calm precision 10.02.2026

This episode explains how the GIAC GPCS exam is structured so you can plan your study and test-day execution like an engineering problem instead of a stress event. You’ll connect question style and pacing to how you build and use an index, how you decide when to move on, and how you avoid spending minutes “almost knowing” something. We’ll clarify what scoring means in practice, how to interpret co...

Listen to the Certified: The GIAC GPCS Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.