Description
SEC510: Cloud Security Controls and Mitigations. This advanced course provides actionable strategies to mitigate risk and defend critical cloud assets, focusing on attack-based controls rather than mere compliance. This course prepares professionals to address the complex challenges of multi-cloud environments, where default controls are often inadequate and each cloud provider’s approach is different. This course serves as a prerequisite for the GPCS certification, which demonstrates proficiency in implementing security best practices across AWS, Azure, and GCP platforms. The course’s educational approach is based on the premise that software flaws are inevitable, and as a result, instead of focusing on fixing vulnerable code, it emphasizes configuring the cloud environment securely to effectively mitigate risks. This course demonstrates that relying on default configurations and vendor documentation is not enough, and teaches practical solutions to address even zero-day vulnerabilities by exposing numerous examples of incorrect, incomplete, or inconsistent configurations. While frameworks like the MITRE ATT&CK Cloud Matrix, CIS Standards, and Cyber Defense Matrix are useful, this course goes beyond them and provides essential techniques to protect what is unique to your organization. Finally, this course gives you the confidence to implement cloud security in real-world scenarios by reducing the risk of common errors and minimizing the attack surface by eliminating insecure configurations.
What you will learn
- Make informed choices on AWS, Azure, and GCP platforms: You’ll make better choices by taking an in-depth look at the PaaS (Platform as a Service) and IaaS (Infrastructure as a Service) offerings on these platforms.
- Learn from real-world case studies: Learn from attacks that have impacted even mature cloud security applications.
- Testing and validating security controls: You will learn how to test and validate the actual performance of security controls instead of relying on vendor documentation.
- Build Layered IAM: Build layered IAM (Identity and Access Management) with advanced requirements and integrate identity into network security.
- Automate encryption and compliance checks: You automate encryption and compliance checks at scale.
- Ransomware Countermeasures: You will learn techniques to prevent, mitigate the risk of, and recover from ransomware attacks.
- Securing modern environments: You secure modern environments such as FaaS (Functionality as a Service) architectures, multi-cloud configurations, and IaC (Infrastructure as Code)-based deployments.
This course is suitable for people who:
- Security analysts: People responsible for analyzing security threats and incidents.
- Security engineers, security researchers: People who are involved in the design and implementation of security solutions.
- Cloud Engineers, DevOps Engineers: People responsible for implementing and managing cloud infrastructure.
- Security auditors: Individuals who evaluate organizations’ security controls.
- System administrators, operations personnel: People responsible for the day-to-day management of systems and infrastructure.
- Anyone who has the following responsibilities:
- Evaluate and adopt new cloud offerings.
- Research into new vulnerabilities and advancements in cloud security.
- IAM management.
- Managing a cloud-based virtual network.
- Secure configuration management.
Course Description SEC510: Cloud Security Controls and Mitigations
- Publisher: SANS
- Instructor: Brandon Evans , Eric Johnson
- Training level: Beginner to advanced
- Training duration: 18 hours and 35 minutes
Course topics

SEC510: Cloud Security Controls and Mitigations Course Prerequisites
- Although SEC510 uses Terraform Infrastructure-as-Code to deploy and configure services in each cloud for the labs, students will not need in-depth knowledge of Terraform or need to understand any of the syntax used. However, students will be introduced at a high level to what this code accomplishes.
- The following are courses or equivalent experiences that are prerequisites for SEC510:
- SANS SEC488: Cloud Security Essentials or hands-on experience using the AWS and Azure Cloud.
- Students must have basic familiarity with the high-level concepts of cloud IAM and networking.
- Students must be comfortable working with the Bash commands.
- NOTE: This is not an application security course, and it will not teach you how to fix vulnerable application code. Instead, it will teach you practical controls and mitigations that you can use to prevent AppSec incidents from becoming breaches. While knowing how to code is helpful, it is not strictly required for this course.
Course images

Sample course video
Installation Guide
After Extract, view with your favorite player.
Subtitles: None
Quality: 720p
Download link
File(s) password: www.downloadly.ir
File size
6.8 GB