Group Purchasing
Group Purchasing
UPDATED

SEC502: Cloud Security Tactical Defense

SEC502Cloud Security
  • 5 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Ryan Nicholson
Ryan Nicholson
SEC502: Cloud Security Tactical Defense
Course authored by:
Ryan Nicholson
Ryan Nicholson
  • GIAC Cloud Security Essentials (GCLD)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 40 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Operate securely in AWS and Azure with hands-on cloud defense skills across identity, networking, data protection, and compliance.

Course Overview

SEC502: Cloud Security Tactical Defense equips practitioners with practical, job-ready experience to secure modern cloud environments against evolving threats. Through live labs in real cloud environments, students will design and enforce tactical controls across identity, data, and network layers, addressing real-world risks like misconfigurations, lateral movement, and privilege escalation, credential theft, data theft, and lateral movement. With 40 immersive, live-fire labs and a competitive Capture the Flag challenge, participants gain the skills to harden cloud infrastructure, assist with incident response efforts, and implement security strategies aligned with enterprise-scale deployments and compliance frameworks.

Imagine becoming the tactical cloud defender your organization relies on. As attackers relentlessly target cloud infrastructure, securing cloud workloads with precision is no longer optional—it's mission-critical. SEC502: Cloud Security Tactical Defense immerses you in real-world challenges across popular cloud vendor offerings, equipping you to implement identity guardrails, secure cloud storage, harden virtual machines, compute assets, and operationalize automation and remote management. Dive into Identity and Access Management (IAM), configuration management, data protection, cloud resource and network visibility, penetration testing, and defense, and much more to confidently mitigate risk during cloud migrations and ongoing operations.

SEC502 goes far beyond theoretical training. You'll engage in 40 hands-on labs using live cloud environments and compete in a capstone Capture the Flag event that validates your skills under pressure. Gain hands-on experience in preventing, detecting, containing, and responding to threats while avoiding costly incidents from service disruptions to privilege escalation and unauthorized access. This course is designed for professionals seeking to enhance their technical expertise, support compliance objectives, and achieve tangible security outcomes across multicloud environments.

What Is Cloud Security?

Cloud security involves adapting traditional security practices to the public cloud environment by leveraging the shared responsibility model. It requires applying vendor-provided controls to protect applications, data, and brand within the cloud environment. Effective cloud security includes Identity and Access Management (IAM), data protection, network security, and continuous monitoring to safeguard cloud resources and maintain a strong security posture. A deep understanding of these domains is critical to effectively securing any cloud deployment at scale.

Hands-On Cloud Security Training

Just like flight simulators for commercial pilots, the SEC502 lab environment immerses students in practical, real-world exercises to apply the theory and skills learned during lectures. With 15 hours dedicated entirely to hands-on keyboard experiences, students gain the ability to "fly the plane" rather than just read the manual. Students rave about the SEC502 exercises because they are effective! Continuously updated to match vendor changes, the SEC502 labs are resilient, and students get extended access to lab content via the course lab workbook.

This multi-cloud, immersive lab environment features a variety of cloud resources such as virtual machines, storage services, and security tools, all configured to simulate real-world scenarios. This setup gives students comprehensive exposure to different cloud service providers. The "choose your own adventure" format allows students to select their preferred cloud vendor for each lab, whether it's AWS or Azure. There is also a gamified capture the flag in Section 6 where it tests the students’ skill in both vendor environments.

Labs offer a vital opportunity to apply theoretical knowledge in a controlled setting, helping students solidify their understanding of cloud security principles. By actively engaging in these repeatable labs, students can practice and hone their skills, ensuring they are well-prepared to tackle cloud security challenges in their organizations from day one back in the office.

Syllabus Summary

  • Section 1: Utilize Identity and Access Management (IAM) to secure cloud accounts and implement least privilege access.
  • Section 2: Focus on securing compute instances and managing configurations within cloud environments.
  • Section 3: Learn to protect data through a variety of stringent protection mechanisms.
  • Section 4: Explore network security controls and logging to monitor and manage cloud data flows.
  • Section 5: Understand compliance requirements, explore cloud-based Artificial Intelligence (AI) platforms, perform penetration testing, respond to incidents in the cloud, and explore how cloud can provide solutions for on-premises chaellenges.
  • Section 6: Apply all learned skills in a comprehensive CloudWars challenge to reinforce cloud security concepts.

What You’ll Learn

  • Identify cloud security weaknesses and risks in CSP offerings.
  • Navigate challenges and choose effective cloud security controls.
  • Protect sensitive data and ensure accountability with cloud logging.
  • Assess CSP trustworthiness using documentation and audits.
  • Secure management access and deploy native network controls.
  • Perform penetration testing and leverage top CSP services.
  • Communicate cloud security concepts with teams and leadership.

Business Takeaways

  • Minimize Your Cloud Risk: Proactively secure your cloud environments to significantly reduce vulnerabilities.
  • Safeguard Computational Resources: Ensure your budget remains intact by protecting your computing power.
  • Enhance Compliance: Elevate your cloud security compliance to meet and exceed regulatory standards.
  • Boost Efficiency: Leverage automation to streamline operations and enhance overall productivity.
  • Strengthen Workforce Retention: Enhance organizational security, leading to increased employee satisfaction and retention.
  • Protect Brand Reputation: Maintain and enhance your organization's brand by securing your cloud operations.
  • Build Customer Trust: Increase customer confidence with robust and reliable cloud security measures.

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC502: Cloud Security Tactical Defense.

Section 1Identity and Access Management (IAM)

The first section of this cloud security course focuses on Identity and Access Management (IAM). Students will quickly understand IAM's critical role in protecting cloud accounts.

Topics covered

  • Separate accounts and groups by workload
  • Apply least-privilege policies
  • Limit breach impact with guardrails and Zero Trust
  • Use temporary creds and manage secrets
  • Control all identities with strong authentication and oversight

Labs

  • User Inventory and Configurations
  • Adventures in Least Privilege
  • Application Credentials
  • Metadata Services

Overview

By the end of this section, students will be able to:

  • Identify security vulnerabilities in their cloud account's IAM service
  • Implement least privilege access in cloud accounts
  • Discover and protect secrets related to cloud service authentication
  • Use cloud vendor IAM tools to automate the detection of security issues

Full Topic Details

  • Course Overview
  • Cloud Accounts and Groups
  • Policies and Permissions
  • Identity Guardrails
  • Temporary Credentials and Secrets Management
  • Cloud Application Account Architecture 
  • Cloud Resource and External Identities
  • Zero Trust

Section 2Compute and Configuration Management

The second section will cover ways to protect the compute elements in cloud providers' Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and other “as a Service” offerings.

Topics covered

  • Secure VM, host, and image configurations
  • Apply application security and threat modeling
  • Understand IaaS/PaaS/SaaS/FaaS security responsibilities
  • Manage containers with secure deployment practices
  • Analyze and secure Infrastructure as Code (IaC)

Labs

  • Secure VM Deployment
  • Automated Image Build
  • Which Reality?
  • Infrastructure as Code Analysis

Overview

  • Students will determine early on that there is much more complexity when launching instances or virtual machines in the cloud as opposed to on-premises. As the section progresses, students will learn to:
  • Securely deploy a compute instance/virtual machine in CSP environments
  • Maintain the running instance throughout its lifecycle
  • Create hardened images for re-use in the organization
  • Understand the various threats that could affect cloud-based applications
  • Leverage Infrastructure as Code (IaC) not only to automate operations, but also automate security configurations

Full Topic Details

  • Secure Instance/ Virtual Machine Deployment
  • Host Configuration Management
  • Image Management
  • Application Security
  • Threat Modeling
  • Beyond IaaS
  • Container Services
  • Infrastructure as Code

Section 3Data Protection

The third section will first focus on the protection of data in cloud environments.

Topics covered

  • Address legal, contractual, and data residency requirements
  • Protect cloud storage with encryption and access controls
  • Ensure availability and resilience of critical cloud apps
  • Manage cloud resources and their lifecycle securely
  • Identify risks in productivity tools and perform data hunting

Labs

  • Public Storage Blunders
  • Sensitive Data Hunting
  • Data in Transit Encryption
  • Cloud Data Lifecycle Management

Overview

All too often, we are reading news articles about breaches that, very frequently, come down to a misconfiguration of a cloud service. Students will learn just what to look out for regarding these misconfigurations as well as:

  • Lock down cloud storage to prevent spillage of sensitive information
  • How to properly identify and classify their organization's data in various cloud services
  • Encrypt data where it resides and as it traverses networks
  • Ensure the data is available when it is required
  • Identify gaps in cloud-based productivity service

Full Topic Details

  • Legal and Contractual Concerns
  • Cloud Storage
  • Availability
  • Data Hunting
  • Data-at-Rest Encryption
  • Data-in-Transit
  • Productivity Services
  • Lifecycle Management

Section 4Networking and Detection

Section 4 is where many network security analysts, engineers, and architects will begin salivating as they will do a deep dive into the ins and outs of cloud networking and log generation, collection, and analysis to set themselves up for success to defend their IaaS workloads.

Topics covered

  • Compare and harden public cloud vs. on-prem networking
  • Secure remote management of IaaS resources
  • Segment networks to isolate and protect assets
  • Use cloud-native protection and detection services
  • Implement logging and visibility for threat detection

Labs

  • Restricting Network Access
  • Web Application Firewall (WAF)
  • Cloud Services Logging
  • IaaS Logging

Overview

Students will learn to:

  • Learn how to control cloud data flows via network controls
  • Add segmentation between compute resources of varying sensitivity levels
  • Generate the proper logs, collect those logs, and process them as a security analyst
  • Increase the effectiveness of their security solutions by gaining more network visibility
  • Detect treats in real time as they occur in the cloud

Full Topic Details

  • Cloud Network Architecture
  • Remote Management of IaaS Systems
  • Cloud Routing, Traffic Management, and Connectivity
  • Threat-Aware Network Security
  • Cloud Account and Service Monitoring
  • Log Generation, Collection, and Analysis
  • Network Visibility
  • Cloud Detection Services

Section 5Compliance, Incident Response, and Penetration Testing

In the fifth section, we'll dive headfirst into compliance frameworks, audit reports, privacy, and eDiscovery to equip you with the information and references to ensure that the right questions are being asked during CSP risk assessments.

Topics covered

  • Extend asset inventory and risk management to the cloud
  • Apply AI and serverless strategies for cloud defense
  • Use CASBs, CSPMs, and CWPPs for visibility and control
  • Conduct and respond to cloud-focused penetration testing
  • Detect and contain cloud breaches early

Labs

  • Cloud-Native Vulnerability Assessment Tools
  • Cloud Custodian
  • Cloud Penetration Testing
  • Tripwires

Overview

In the fifth section, we'll dive headfirst into compliance frameworks, audit reports, privacy, and eDiscovery to equip you with the information and references to ensure that the right questions are being asked during CSP risk assessments. After covering special-use cases for more restricted requirements that may necessitate the AWS GovCloud or Azure's Trusted Computing, we'll delve into penetration testing in the cloud and finish the day with incident response and forensics. Student will learn to:

Learn how Cloud Access Security Broker (CASB), Cloud Workload Protection Platform (CWPP), and Cloud Security Posture Management (CSPM) tools operate and what benefit they may add to the organization

Leverage the Cloud Security Alliance Cloud Controls Matrix to select the appropriate security controls for a given cloud network security architecture and assess a CSP's implementation of those controls using audit reports and the CSP's shared responsibility model

Use logs from cloud services and virtual machines hosted in the cloud to detect a security incident and take appropriate steps as a first responder according to a recommended incident response methodology

Perform a preliminary forensic file system analysis of a compromised virtual machine to identify indicators of compromise and create a file system timeline

Full Topic Details

  • Cloud Asset Discovery and Inventory
  • Governance, Privacy, and Risk Management in Cloud
  • Cloud-Based Artificial Intelligence (AI) Security
  • Cloud-Native Application Protection Platform (CNAPP)
  • Preparing for Cloud Penetration Tests
  • Conducting Cloud Penetration Tests
  • Incident Response and Forensics
  • Serverless for Defenders

Section 6CloudWars

The final section is a multi-hour, self-paced CloudWars challenge completed independently after the course to reinforce key concepts and hands-on skills.

Overview

CloudWars is a self-paced Capture the Flag (CTF) challenge that reinforces the tactical skills from the course. Students secure a vulnerable multicloud environment by identifying misconfigurations and defending against simulated threats.

In-Person and Live Online students have two weeks of post-course access to the CTF. OnDemand students access CloudWars as part of their standard lab provisioning.

It’s a flexible, hands-on way to validate your real-world cloud defense skills.

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • A supported web browser, including:
    • Google Chrome (recent versions)
    • Mozilla Firefox (recent versions)
    • Microsoft Edge (recent versions)
    • Apple Safari (recent versions)
  • Internet access: Your network must allow communication over the WebSocket protocol. If you are behind a strict proxy or firewall, your network administrator may need to configure it to allow WebSockets to avoid connection errors.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

SEC502 training is recommended for a diverse range of individuals, including:

  • Cloud Security Engineers
  • Cloud Security Analysts
  • System Administrators
  • Risk Managers
  • Security Managers
  • Cloud Security Auditors
  • Cloud Security Professionals
  • Cloud Architects
  • IT Professionals
  • Developers working in cloud environments
  • Compliance Officers responsible for cloud security
  • Network Engineers transitioning to cloud security roles

The GIAC Cloud Security Essentials (GCLD) certification validates a practitioner's ability to implement preventive, detective, and reactionary techniques to defend valuable cloud-based workloads.

  • Evaluation of cloud service provider similarities, differences, challenges, and opportunities
  • Planning, deploying, hardening, and securing single and multi-cloud environments
  • Basic cloud resource auditing, security assessment, and incident response

More Certification Details

  • AWS and Azure provisioned accounts
  • MP3 audio files of the complete course lectures
  • Printed and Electronic courseware
  • Extended access to the course's 40+ lab exercises

  • Basic Networking Concepts: Understanding fundamental networking principles, such as IP addressing, subnets, firewalls, and DNS, is essential. Familiarity with network protocols like TCP/IP, HTTP/HTTPS, and DNS resolution will help contextualize cloud network security topics.
  • Operating Systems: A working knowledge of Linux and Windows operating systems is vital, as cloud environments often rely on both. Students should know how to navigate the command line, manage processes, handle file systems, and understand basic permissions.
  • Cloud Fundamentals: Prior exposure to cloud computing concepts is beneficial. Topics like virtualization, the shared responsibility model, and the key services offered by platforms such as AWS, Azure, or Google Cloud can provide valuable context.
  • Security Basics: A foundational understanding of cybersecurity principles, including encryption, authentication, and common attack vectors, is critical. Knowledge of key concepts like confidentiality, integrity, availability (CIA triad), and access control strengthens their grasp of cloud security.

SEC502 is part of the SANS Cloud Security curriculum and aligns with both the Cloud Security Analyst and Cloud Security Architect learning journeys.

In the Cloud Security Analyst journey, SEC502 complements courses including SEC510: Cloud Security Engineering and Controls and SEC541: Cloud Security Threat Detection, which focus on prevention, detection, and response in cloud environments.

In the Cloud Security Architect journey, SEC502 supports broader architectural and strategic objectives alongside courses like SEC549: Cloud Security Architecture and LDR520: Emerging Trends for Cyber Leaders: AI and Cloud.

The course provides hands-on, tactical skills applicable across technical and strategic cloud security roles.

Cloud security tactical defense refers to the practical strategies and controls used to actively protect cloud environments from real-world threats. This includes securing identities, hardening configurations, detecting intrusions, mitigating risk, and maintaining compliance across multicloud platforms like AWS, Azure, GCP, and others.

Tactical cloud defense is critical for reducing the likelihood and impact of breaches, aligning with the shared responsibility model, and enabling secure, scalable operations. It protects critical assets, supports regulatory requirements, and strengthens organizational resilience. SEC502: Cloud Security Tactical Defense™ builds these applied skills through immersive labs and real-world exercises—empowering professionals to secure cloud infrastructure with confidence and precision.

SEC502: Cloud Security Tactical Defense delivers job-ready skills in cloud configuration, identity management, and threat mitigation—making you a more valuable and capable security professional. The course provides hands-on experience in real AWS and Azure environments, enhancing your technical credibility and positioning you for advancement in cloud-focused roles. Backed by SANS and aligned with GIAC certification, it demonstrates your ability to lead tactical cloud defense efforts in high-stakes environments.

Relevant Job Roles

Systems Security Analyst (DCWF 461)

DoD 8140: Software Engineering

Ensures systems and software security from development to maintenance by analyzing and improving security across all lifecycle phases.

Explore learning path

Systems Administration (OPM 451)

NICE: Implementation and Operation

Responsible for setting up and maintaining a system or specific components of a system in adherence with organizational security policies and procedures. Includes hardware and software installation, configuration, and updates; user account management; backup and recovery management; and security control implementation.

Explore learning path

Systems Developer (DCWF 632)

DoD 8140: Cyber IT

Oversees full lifecycle of information systems from design through evaluation, ensuring alignment with functional and operational goals.

Explore learning path

Cloud Security Analyst Training, Salary, and Career Path

Cloud Security

A Cloud Security Analyst monitors and analyzes activity across cloud environments, proactively detects and assesses threats, and implements preventive controls and targeted defenses to protect critical business systems and data.

Explore learning path

Cybersecurity Architecture (OPM 652)

NICE: Design and Development

Responsible for ensuring that security requirements are adequately addressed in all aspects of enterprise architecture, including reference models, segment and solution architectures, and the resulting systems that protect and support organizational mission and business processes.

Explore learning path

Cloud Security Manager

Cloud Security

Developing cloud security roadmaps, plans and procurement models to mature cloud security.

Explore learning path

Systems Security Management (OPM 722)

NICE: Oversight and Governance

Responsible for managing the cybersecurity of a program, organization, system, or enclave.

Explore learning path

Cyber Defense Infrastructure Support Specialist (DCWF 521)

DoD 8140: Cybersecurity

Deploys, configures, maintains infrastructure software and hardware to support secure and effective IT operations across organizational systems.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 15

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources