SEC536: Adversarial AI - Penetration Testing AI Systems

Important! Bring your own system configured according to these instructions!
The SEC510 course labs contain lab exercises for AWS, Azure, and GCP. Most labs can be completed with any one of these providers. However, we strongly recommend completing the labs for all three providers to learn how the services in each differ in small, yet critical ways. Experiencing this nuance in these interactive labs will help you better defend each platform and prepare for the GPCS certification.
SANS will provide students with the AWS accounts, Azure subscription, and Google Cloud project required to complete the labs for those providers.
OnDemand students:
Live events (In Person or Live Online)
Mandatory Laptop Requirement:
A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will likely leave the class unsatisfied because you will not be able to participate in hands-on exercises that are essential to this course. Therefore, we strongly urge you to arrive with a system meeting all the requirements specified for the course.
Students must be in full control of their system's network configuration. The system will need to communicate with the cloud-hosted lab environment using a combination of HTTPS, SSH, and SOCKS5 traffic on non-standard ports. Running VPN, intercepting proxy, or egress firewall filters may cause connection issues communicating with the lab environment. Students must be able to configure or disable these services.
Bring Your Own Laptop Configured Using The Following Directions:
A properly configured system is required for each student participating in this course. Before starting your course, carefully read and follow these instructions exactly:
In Summary
Before beginning the course, you should:
SANS will be providing access to the following cloud environments: AWS, Azure, and Google Cloud. Unfortunately, due to some cloud security controls we cannot control, sometimes the login you receive requires verification with a valid phone number where you can receive text messages (virtual numbers will not work). Please ensure you have and are willing to provide your phone number to the cloud provider should this situation occur.
After you have completed those steps, access the SANS provider cloud accounts to connect to the SANS Cloud Security Flight Simulator. The SEC510 Flight Simulator server hosts an electronic workbook, terminal, and other services that can be accessed through the Firefox browser.
must access the "Setup Instructions" document in the Course Material Downloads section of your SANS portal and follow its instructions before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.
Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.
This course provides many optional bonus challenges. One module in these bonus challenges requires an Oracle Cloud Infrastructure (OCI) account. This is not provided by SANS. Students who opt into completing this challenge will be responsible for any OCI charges incurred. However, OCI’s Free Tier has a monetary credit, and it is possible to complete these challenges without using the entire credit.
If you have additional questions about the laptop specifications, please contact customer service.
SEC510 training is recommended for a diverse range of individuals, including:
The GIAC Public Cloud Security (GPCS) certification validates a practitioner's ability to secure the cloud in both public and multi cloud environments. GPCS-certified professionals are familiar with the nuances of AWS, Azure, GCP and have the skills needed to defend each of these platforms.
Although SEC510 uses Terraform Infrastructure-as-Code to deploy and configure services in each cloud for the labs, students will not need in-depth knowledge of Terraform or need to understand any of the syntax used. However, students will be introduced at a high level to what this code accomplishes.
The following are courses or equivalent experiences that are prerequisites for SEC510:
NOTE: This is not an application security course, and it will not teach you how to fix vulnerable application code. Instead, it will teach you practical controls and mitigations that you can use to prevent AppSec incidents from becoming breaches. While knowing how to code is helpful, it is not strictly required for this course.
The SEC510 course is part of the Cloud Security Analyst and Cloud Security Engineer Journeys. Security practitioners use cloud security solutions to enable multicloud controls and mitigations to defenses and detect attacks.
Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:
Cloud security controls are techniques and settings provided by cloud service providers (CSPs) that help protect cloud-based assets from unauthorized access, data breaches, and other cyber threats. While each CSP offers default controls, these are often generic and insufficient because they do not account for the unique needs of individual organizations.
Effective cloud security requires configuring these controls based on the organization’s specific business goals, risk tolerance, and operational requirements. This means going beyond defaults and tailoring protections—like access restrictions, encryption, and network segmentation—to fit real-world threats. When implemented thoughtfully by professionals who understand the nuances of different CSPs, cloud security controls play a critical role in reducing risk and securing sensitive data in an increasingly complex multicloud environment.
SEC510: Cloud Security Engineering and Controls will deepen your expertise in securing multicloud environments, an increasingly vital skill in today’s cybersecurity world. You will gain hands-on experience with real-world attacks, learn to apply cloud-native tools across AWS, Azure, and Google Cloud, and master topics like IAM, secure configuration, data protection, and privilege escalation prevention. SEC510 focuses on practical, attack-driven controls rather than just compliance, equipping you to proactively defend cloud assets and reduce risk. These skills are in high demand and will set you apart in roles involving cloud security architecture, incident response, or DevSecOps.

Get feedback from the world’s best cybersecurity experts and instructors

Choose how you want to learn - online, on demand, or at our live in-person training events

Get access to our range of industry-leading courses and resources