SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions!
The SEC510 course labs contain lab exercises for AWS, Azure, and GCP. Most labs can be completed with any one of these providers. However, we strongly recommend completing the labs for all three providers to learn how the services in each differ in small, yet critical ways. Experiencing this nuance in these interactive labs will help you better defend each platform and prepare for the GPCS certification.
The majority of SEC510's labs teach how to perform cloud security engineering tasks using tried-and-true techniques. This is important to ensure you understand how these processes work. However, some of these processes can be optimized using AI. For this reason, the labs provide many optional instructions demonstrating how you can leverage Agentic AI, specifically OpenAI’s Codex, to perform these cloud security engineering tasks quicker and more easily. We highly recommend trying these AI instruction paths.
SANS will provide students with the AWS accounts, Azure subscription, and Google Cloud project required to complete the labs for those providers.
OnDemand students:
Live events (In Person or Live Online)
Mandatory Laptop Requirement:
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
Bring Your Own Laptop Configured Using The Following Directions:
A properly configured system is required for each student participating in this course. Before starting your course, carefully read and follow these instructions exactly:
In Summary
Before beginning the course, you should:
SANS will be providing access to the following cloud environments: AWS, Azure, and Google Cloud. Unfortunately, due to some cloud security controls we cannot control, sometimes the login you receive requires verification with a valid phone number where you can receive text messages (virtual numbers will not work). Please ensure you have and are willing to provide your phone number to the cloud provider should this situation occur.
After you have completed those steps, access the SANS provider cloud accounts to connect to the SANS Cloud Security Flight Simulator. The SEC510 Flight Simulator server hosts an electronic workbook, terminal, and other services that can be accessed through the Firefox browser.
You must access the "Setup Instructions" document in the Course Material Downloads section of your SANS portal and follow its instructions before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
If you have additional questions about the laptop specifications, please contact customer service.
SEC510 training is recommended for a diverse range of individuals, including:
The GIAC Public Cloud Security (GPCS) certification validates a practitioner's ability to secure the cloud in both public and multi cloud environments. GPCS-certified professionals are familiar with the nuances of AWS, Azure, GCP and have the skills needed to defend each of these platforms.
No, the bonus challenges are optional. Most use the AWS, Azure, and Google Cloud accounts SANS provides. One requires an Oracle Cloud Infrastructure (OCI) account, which SANS does not provide. Students who choose that challenge will need to set up their own OCI account and are responsible for any charges, though OCI's Free Tier credit is usually enough to finish it.
Although SEC510 uses Terraform Infrastructure-as-Code to deploy and configure services in each cloud for the labs, students will not need in-depth knowledge of Terraform or need to understand any of the syntax used. However, students will be introduced at a high level to what this code accomplishes.
The following are courses or equivalent experiences that are prerequisites for SEC510:
NOTE: This is not an application security course, and it will not teach you how to fix vulnerable application code. Instead, it will teach you practical controls and mitigations that you can use to prevent AppSec incidents from becoming breaches. While knowing how to code is helpful, it is not strictly required for this course.
The SEC510 course is part of the Cloud Security Engineer Journey. Security practitioners use these skills to build multicloud controls, mitigate risk, and detect attacks. The other two courses in the Journey are:
Depending on your current or desired future role, other courses that are great next steps in your cybersecurity journey are:
Cloud security controls are techniques and settings provided by cloud service providers (CSPs) that help protect cloud-based assets from unauthorized access, data breaches, and other cyber threats. While each CSP offers default controls, these are often generic and insufficient because they do not account for the unique needs of individual organizations.
Effective cloud security requires configuring these controls based on the organization’s specific business goals, risk tolerance, and operational requirements. This means going beyond defaults and tailoring protections—like access restrictions, encryption, and network segmentation—to fit real-world threats. When implemented thoughtfully by professionals who understand the nuances of different CSPs, cloud security controls play a critical role in reducing risk and securing sensitive data in an increasingly complex multicloud environment. AI can help manage this complexity, but only when used by multicloud engineering experts.
SEC510: Cloud Security Engineering and Controls will deepen your expertise in securing multicloud environments, an increasingly vital skill in today’s cybersecurity world. You will gain hands-on experience with real-world attacks, learn to apply cloud-native tools across AWS, Azure, and Google Cloud, and master topics like IAM, secure configuration, data protection, and privilege escalation prevention. SEC510 focuses on practical, attack-driven controls rather than just compliance, equipping you to proactively defend cloud assets and reduce risk. These skills are in high demand and will set you apart in roles involving cloud security architecture, incident response, or DevSecOps.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources