Jason Edwards

Certified: The ISACA CCOA Audio Course

Welcome to Certified: The ISACA CCOA Audio Course, a focused, audio-first program designed to help you build confidence in cybersecurity audit and assurance. If you’ve ever struggled to interpret an audit request, map security work to a control expectation, or explain evidence in a way that satisfies reviewers, you’re in the right place. I’ll guide you through the concepts that show up again and again in assurance work: how audit scope gets defined, how controls are evaluated, what strong evidence looks like, and how findings are framed. Expect clear explanations, practical language, and a ste...

Author

Jason Edwards

Category

Technology

Latest episode

Feb 15, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Episode 21 — Spaced Retrieval Review: Technology Essentials Across Networks, Systems, and Applications (Task 18) 14.02.2026

This episode consolidates technology essentials into an integrated review that strengthens recall by connecting concepts across networks, operating systems, and applications. You will revisit key definitions like routing and DNS behavior, identity boundaries, segmentation intent, logging sources, and common failure patterns in cloud and automation, but the focus is on using those concepts to answe...

Episode 20 — Scripting and Coding for Analysts: Read, Tweak, and Automate Repeatable Checks (Task 6) 14.02.2026

This episode explains scripting and coding as an analyst skill for repeatability, accuracy, and speed, not as a requirement to become a software engineer. You will learn how small scripts support triage, enrichment, and data parsing, and how to safely modify existing code to match an investigation need without introducing errors. We will cover practical examples like extracting indicators from log...

Episode 19 — Cloud Applications Explained: Shared Responsibility, Identity Boundaries, and Visibility Gaps (Task 2) 14.02.2026

This episode explains cloud applications using the shared responsibility model so you can correctly assign accountability for controls, evidence, and incident response actions. You will learn how identity boundaries define what users, services, and admins can do, and how misconfigurations often become the real “vulnerability” in cloud incidents. We will explore visibility gaps such as missing logs...

Episode 18 — Harden Automated Deployment Thinking: CI/CD Risks, Secrets, and Supply Chains (Task 2) 14.02.2026

This episode explains why automated deployment pipelines are both a productivity advantage and a high-impact attack surface, especially when secrets and third-party dependencies are involved. You will learn how CI/CD systems manage code, build artifacts, credentials, and environment promotion, then identify where attackers target weak points such as token theft, build server compromise, or depende...

Episode 17 — API Basics for Security Analysts: Requests, Authentication, and Common Failures (Task 2) 14.02.2026

This episode teaches API basics in security terms so you can evaluate risk, investigate incidents, and answer exam questions that assume modern application architecture. You will define core API request structure, authentication patterns, authorization enforcement, and why “working authentication” does not guarantee safe access. We will cover common failures such as broken object level authorizati...

Episode 16 — Operating Systems Essentials: Permissions, Services, Memory, and Persistence Paths (Task 2) 14.02.2026

This episode reviews operating system essentials with a defender’s perspective, emphasizing the concepts most likely to appear in questions about access control, malware behavior, and incident investigation. You will define permissions models, service management, memory concepts, and common persistence paths that attackers use to survive reboots and maintain control. We will connect these fundamen...

Episode 15 — Make Middleware Make Sense: Queues, App Servers, APIs, and Hidden Trust (Task 2) 14.02.2026

This episode clarifies middleware components that often become invisible trust zones in modern applications, creating security gaps when they are not explicitly monitored and controlled. You will define message queues, application servers, service buses, and API gateways, then connect them to typical security issues like weak authentication between services, message tampering, replay risks, and ex...

Episode 14 — Containerization and Virtualization Demystified: Isolation, Images, and Escape Risks (Task 2) 14.02.2026

This episode explains containers and virtualization in security terms, focusing on how isolation works, where it fails, and what evidence proves controls are correctly configured. You will define container images, registries, runtime permissions, and virtualization boundaries, then connect those concepts to risks such as supply chain tampering, secret exposure, and container escape or host comprom...

Episode 13 — Command Line for Triage: Fast Evidence Collection Without Breaking Systems (Task 10) 14.02.2026

This episode focuses on triage behavior at the command line, where speed matters but evidence quality and system stability must not be sacrificed. You will learn what “safe collection” looks like, including capturing volatile data, preserving key logs, and documenting context so your results remain credible if escalated to forensics or audit review. We will discuss practical constraints such as no...

Episode 12 — Command Line Fundamentals: Navigate Systems, Inspect Processes, and Read Logs (Task 10) 14.02.2026

This episode builds command line fundamentals as a practical skill set for incident response, triage, and verification tasks commonly tested by the exam. You will learn how analysts use command line navigation, process inspection, and log reading to answer time-critical questions like “what changed,” “what is running,” and “what evidence is reliable.” We will explain why command output must be int...

Episode 11 — Understand Databases for Analysts: Data Models, Queries, and Audit Trails (Task 10) 14.02.2026

This episode gives analysts the database literacy needed to investigate incidents, validate suspicious activity, and interpret audit trails without being a full-time database administrator. You will define core database concepts such as tables, relationships, transactions, and query logic, then connect those concepts to security outcomes like authorization boundaries, data integrity, and traceabil...

Episode 10 — Apply Segmentation With Purpose to Reduce Blast Radius and Exposure (Task 4) 14.02.2026

This episode explains segmentation as a risk control that must be designed with clear intent, tested with evidence, and maintained over time to remain meaningful. You will learn how segmentation reduces blast radius, limits lateral movement, and supports incident containment, but only if boundaries reflect real trust differences and are enforced consistently. We will define common segmentation app...

Episode 9 — Master Network Technology Concepts: Wireless, SDN, WAN, and Virtualization (Task 5) 14.02.2026

This episode covers modern network technology concepts that commonly appear in exam questions because they change how controls, visibility, and attack paths work. You will define wireless security considerations, software-defined networking principles, WAN connectivity realities, and how virtualization shifts trust boundaries and monitoring placement. We will connect these technologies to risks su...

Episode 8 — Use Network Tools Confidently: Testing Reachability, Name Resolution, and Paths (Task 10) 14.02.2026

This episode teaches how to use foundational network testing concepts to validate what is truly happening during outages, suspicious behavior, or containment actions. You will learn how reachability tests differ from service availability, why name resolution issues can masquerade as application failures, and how path visibility helps confirm segmentation and routing assumptions. We will discuss ty...

Episode 7 — Secure Network Access Paths: VPNs, NAC, Identity, and Remote Entry (Task 2) 14.02.2026

This episode explains how remote access and network admission controls shape enterprise exposure, and how to evaluate whether these controls are actually enforcing policy rather than creating a false sense of safety. You will define VPN models, network access control concepts, identity-driven access decisions, and common remote entry points such as administrative gateways and cloud consoles. We wi...

Episode 6 — Decode Devices, Ports, and Protocols Quickly Like a Threat Hunter (Task 5) 14.02.2026

This episode trains you to interpret what devices, ports, and protocols suggest about intent, risk, and investigative next steps, which is a frequent requirement in exam scenarios. You will learn how to treat ports and protocols as hypotheses rather than conclusions, using context such as timing, directionality, and known asset roles to decide what is likely benign versus suspicious. We will cover...

Episode 5 — Strengthen Computer Networking Fundamentals: Packets, Sessions, and Trust Boundaries (Task 5) 14.02.2026

This episode reinforces core networking fundamentals that appear in detection, incident questions, and control design across the exam. You will define packets, flows, sessions, and common protocol behaviors, then use those definitions to explain why some attacks are visible in one telemetry source and invisible in another. We will connect networking fundamentals to trust boundaries, showing how au...

Episode 4 — Build Cloud Networking Intuition for Security: Virtual Networks, Routing, and DNS (Task 5) 14.02.2026

This episode explains cloud networking concepts the way security analysts need to understand them: as pathways that shape exposure, logging, and containment options. You will define virtual networks, subnets, route tables, security groups, and DNS resolution, then connect each component to typical failure modes like unintended internet reachability, lateral movement opportunities, and blind spots...

Episode 3 — Exam Acronyms: High-Yield Audio Reference for Fast Recognition (Task 5) 14.02.2026

This episode builds fast acronym recognition so you can decode exam questions without losing time or misreading what a control or tool actually implies. You will learn to translate common security and operations acronyms into their functional meaning, focusing on what each term does, what problem it solves, and where it typically fits in incident detection, response, or governance. We will cover h...

Episode 2 — Map the 21 Supporting Tasks Into Your Everyday SOC Workflow (Task 4) 14.02.2026

This episode shows you how to take the supporting tasks tested by the exam and map them to a realistic SOC workflow so you can study by anchoring concepts to actions you already perform. You will learn to organize work into phases such as intake, triage, investigation, containment coordination, recovery support, and lessons learned, then identify where tasks like risk framing, evidence handling, d...

Episode 1 — CCOA Exam Orientation: Format, Scoring, Policies, and Spoken Study Plan (Task 19) 14.02.2026

This episode sets expectations for how the CCOA exam is structured, what the questions tend to test, and how to translate the blueprint into an audio-first study routine that holds up under real work schedules. You will learn how to pace your preparation by linking each task area to repeatable job actions, then converting those actions into quick mental checklists you can recall under time pressur...

Listen to the Certified: The ISACA CCOA Audio Course podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.