Description
SEC549: Cloud Security Architecture. This course teaches participants how to design scalable, enterprise-class cloud security solutions. Using a comprehensive case study, this course explores real-world challenges such as identity and access management (IAM), network security, data protection, and log collection through threat modeling and architectural analysis. The focus is on creating secure environments from the ground up that meet practical needs. By learning the architectural frameworks of major cloud providers, students will learn how to design centralized security controls while helping to accelerate and facilitate secure migration to the cloud. This course covers the changing threat models in the cloud with new and distributed trust boundaries and emphasizes designing strategies for strengthening identity, conditional access, policy controls, network security, and logging in multi-cloud environments. Throughout the course, students will work with a hypothetical company on a cloud migration journey, conducting threat modeling and conducting in-depth security assessments by identifying the strengths and weaknesses of cloud architectures. At the end of each module, they will be tasked with designing an architecture for a startup integration, which includes studying cloud resources, interviewing employees, and developing a migration plan. Working in teams, students will develop migration plans, architectural diagrams, and technical documentation, and ultimately present their designs in a final competition. This hands-on, technical training course provides excellent preparation for professionals seeking cloud security architecture certifications.
What you will learn
- Cloud Architecture Design: You will learn how to design secure, enterprise-ready cloud architectures that support business goals.
- Build a scalable identity infrastructure: You build a scalable identity infrastructure that centralizes workforce identity with conditional access and emergency access policies.
- Implementing a Zero-Trust Model: Learn how the cloud enables Zero-Trust for workforce, customer, and workload identities with identity-based and network-based security controls.
- Create network segmentation: You create small network segmentation using hub-and-spoke models and centralized inspection firewalls.
- Protect cloud data: Protect cloud data with strong boundaries, data lakes, shared Key Management Service (KMS), and disaster recovery designs.
- Enable cloud incident response: Enable cloud incident response and telemetry using centralized intra-cloud and inter-cloud logging designs.
This course is suitable for people who:
- They seek to mitigate cloud risks with strategic and phased adoption plans.
- They seek to prevent identity expansion and technical debt through centralization.
- They seek to support organizational growth with high-level protections and secure architecture.
- Seek to avoid cost-prohibitive patterns with thoughtful cloud design.
- They are looking to move towards a Zero-Trust model using proven access control patterns.
- They seek to create effective conditional access and manage policy exceptions.
Course Description SEC549: Cloud Security Architecture
- Publisher: SANS
- Instructor: Eric Johnson , David Hazar , Gregory Leonard
- Training level: Beginner to advanced
- Training duration: 16 hours and 37 minutes
- Number of lessons: 2
Course headings

Course Prerequisites SEC549: Cloud Security Architecture
- The following experience is a prerequisite for SEC549:
- Familiarity with AWS, Azure, and Google Management Consoles and common services in these cloud providers
- Experience or willingness to learn how to use cloud architecture diagram tools such as draw.io
- Ability or willingness to learn to run basic Linux commands for SSH connections, testing network connectivity, and looking up domain names
- Familiarity with or willingness to learn identity federation technologies such as SAML, Open ID Connect (OIDC), and JSON Web Tokens (JWT)
- Preparing for SEC549
- Students taking SEC549 will have the opportunity to learn many different architecture patterns across the AWS, Azure, and Google clouds. Basic familiarity with cloud concepts like IAM, role-based access control, identity federation, VPC networks, and storage services management is helpful.
- Additionally, students will delve into cloud-native tools for securing deployments at the network layer. Having a basic understanding of network concepts such as firewalls, network access control lists and IP addressing is also very helpful.
Course images

Sample course video
Installation Guide
After Extract, view with your favorite player.
Subtitles: None
Quality: 720p
Download link
Downloadly
Rapidgator
Password File(s): www.downloadly.ir
File size
1.04 GB