Group Purchasing
Group Purchasing

SEC530: Defensible Security Architecture and Engineering: Implementing Zero Trust for the Hybrid Enterprise

SEC530Cyber Defense
  • 6 Days (Instructor-Led)
  • 36 Hours (Self-Paced)
Course authored by:
Ismael Valenzuela
Ismael Valenzuela
SEC530: Defensible Security Architecture and Engineering: Implementing Zero Trust for the Hybrid Enterprise
Course authored by:
Ismael Valenzuela
Ismael Valenzuela
  • GIAC Defensible Security Architecture (GDSA)
  • 36 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

  • 24 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Achieve a holistic approach to defensible security architecture for the AI era. Engineer Zero Trust architectures across networks, applications, data, identity, and AI-assisted enforcement.

Course Overview

SEC530 teaches practical security architecture and engineering for the AI era, helping you design and build stronger prevention, detection, and response capabilities by leveraging your existing infrastructure like next-gen firewalls, SIEM, identity platforms, cloud controls, routers, switches, IDS/IPS, WAF, proxies, encryption, PKI, and Microsoft Entra ID, among others.

You will learn to assess, reconfigure, and validate technologies to reduce attack surfaces, augment visibility, anticipate threats, and showcase practical Zero Trust implementations across hybrid enterprise environments.

SEC530 is a practical class designed by highly experienced practitioners to teach tactics and tools for building and hardening security architectures against today’s most sophisticated adversaries. The course focuses on layering prevention, detection, and response controls across network, endpoint, identity, application, data, and cloud planes by leveraging existing investments common in modern organizations.

The course also covers the key technologies shaping defensible architecture today, including Zero Trust Network Access (ZTNA), Secure Access Service Edge (SASE), Network Detection and Response (NDR), Web Application and API Protection (WAAP), Data Security Posture Management (DSPM), Cloud Access Security Broker (CASB), Data Loss Prevention (DLP), Mobile Device Management (MDM), Identity Threat Detection and Response (ITDR), Conditional Access, OAuth, FIDO2, OCSF, Sigma, agentic AI, AI-assisted analytics, and post-quantum cryptography (PQC).

While this is not a monitoring course, it dovetails nicely with continuous security monitoring by ensuring that your security architecture supports prevention and provides the critical logs, telemetry, and engineered signals that can feed behavioral detection and analytics systems, including modern UEBA, SIEM, and SOC workflows.

Multiple hands-on labs conducted daily reinforce key points in the course and provide actionable skills that students can leverage as soon as they return to work. SEC530 is a truly unique course created by all-around defenders for all-around defenders, offering vendor-neutral expertise, real-world application, hands-on labs, and practical Zero Trust implementation guidance for the hybrid enterprise.

Author Statement

In my many years of experience assessing the security posture of organizations, responding to incidents, and ramping up security operations, I have seen the futility of trying to monitor and defend against modern adversaries when the architecture in place has not been designed with security in mind. That challenge is even more urgent in the AI era, where automation and agentic AI can accelerate both legitimate business workflows and adversary operations. Likewise, I have continually seen that organizations that suffer massive breaches and business disruption often focused their emphasis prior to the breach on perimeter protection and prevention mechanisms but lacked defensible security architecture.

I designed this course to address that gap and help defenders regain the advantage. In six days filled with case studies, winning techniques, instructor-led demos, and plenty of hands-on labs, including a thrilling Secure-the-Flag challenge, students will learn how to design, build, and harden networks, infrastructure, applications, and data planes that can truly be called defensible.

As practitioners, we know that theory is not enough, so I have made sure this class is focused on real-world implementations of network-centric, data-centric, and Zero Trust security architecture mapped to best practices and standards, while also grounded in many years of experience with what works and what does not. The course keeps my Think Red, Act Blue philosophy throughout: understand how attackers adapt, then engineer architectures, telemetry, and response paths that give defenders time, context, and control. You will find that this makes the content appropriate and relevant for the reality of a wide variety of organizations and roles.

- Ismael Valenzuela

What You’ll Learn

  • Design defensible security architectures using the DARIOM, MITRE ATT&CK, and ZT principles
  • Harden routers, switches, IPv6, segmentation boundaries, NAC, and identity-based access
  • Engineer network visibility using NGFWs, NDR/NSM, Zeek, Suricata, flow data, and cloud telemetry
  • Design secure access strategies with ZTNA, SASE, TLS inspection, and encryption tradeoffs
  • Protect applications, APIs, and data with WAAP, WAF, DSPM, DLP, and workload identity
  • Defend against OAuth abuse, token theft, PRT abuse, MFA bypass, and cloud lateral movement
  • Connect ITDR risk signals to Conditional Access enforcement with OCSF-normalized telemetry

Business Takeaways

  • Identify security architecture gaps across networks, identity, and visibility pipelines
  • Use existing infrastructure more effectively while moving toward Zero Trust outcomes
  • Prioritize controls by business impact, adversary behavior, and implementation cost
  • Prepare security architecture for AI-driven business workflows and AI-enabled adversaries
  • Reduce attack surface with segmentation, ZTNA, least privilege, and context-aware access
  • Strengthen identity defense against OAuth abuse, MFA fatigue, and credential theft
  • Connect engineered security signals to enforcement through risk scoring and Conditional Access

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC530: Defensible Security Architecture and Engineering: Implementing Zero Trust for the Hybrid Enterprise.

Section 1A Journey Toward Zero Trust: Defensible Security Strategies for the AI Era

Section 1 establishes the architecture method used throughout SEC530. It introduces defensible security architecture, the DARIOM lifecycle, Time-Based Security, MITRE ATT&CK threat modeling, and the Zero Trust journey grounded in NSA ZIG. Hands-on work covers Layer 2 controls, flow data, OCSF normalization, & behavioral baselining for AI-era visibility.

Topics covered

  • Defensible security architecture, DARIOM, and Time-Based Security
  • Threat modeling with MITRE ATT&CK, ATT&CK Navigator, DeTT&CT, and MITRE ATLAS
  • Zero Trust strategy, NIST SP 800-207, CISA ZTMM, and NSA ZIG pillars
  • Physical, wireless, and Layer 2 security: VLANs, PVLANs, ARP spoofing, switch controls
  • Flow data with NetFlow, IPFIX, sFlow, Suricata, OCSF normalization, baselining

Labs

  • Practical Threat Modeling with MITRE ATT&CK
  • Egress Analysis
  • Layer 2 Attacks
  • Architecting for Flow Data

Overview

This first section describes the principles of designing and building defensible systems and networks. Students begin with the fundamentals of security architecture and the journey toward Zero Trust, including a vendor-neutral and realistic view of Zero Trust based on US and international guidance, maturity models, and design principles. The section compares traditional security architecture with defensible security architecture and introduces the DARIOM lifecycle: Discover, Assess, Re-Design, Implement, Operate, and Monitor.

The main emphasis is practical threat modeling and architecture decision-making. Students use MITRE ATT&CK, ATT&CK Navigator, DeTT&CT, and MITRE ATLAS awareness to prioritize countermeasures, identify attack paths, and understand how AI-assisted reconnaissance and machine-speed adversary workflows change defensive design. The section also introduces Time-Based Security and shows how prevention, detection, response, and resilience are shaped by architecture choices.

The section then builds from the bottom up, starting with physical security, wireless security, Layer 2 controls, VLANs, PVLANs, flow data, and egress analysis. Students learn how to baseline normal network activity with NetFlow, IPFIX, sFlow, VPC Flow Logs, Suricata flows, endpoint flow data, and cloud flow telemetry, then normalize and reason about those signals using OCSF-aware design patterns that support AI-era visibility and decision support.

Full Lab Details

  • Practical Threat Modeling with MITRE ATT&CK: Students learn practical threat modeling with MITRE ATT&CK and apply it as an architecture prioritization model throughout the course. The lab helps all-around defenders become threat-focused instead of vulnerability-focused, identifying the most important risks and designing controls that disrupt realistic adversary behavior.
  • Egress Analysis: Students examine common exfiltration paths, including DNS tunneling and other outbound channels, then layer defenses to increase protection time while increasing the chance that engineered telemetry will expose unauthorized movement.
  • Layer 2 Attacks: Students identify relevant Layer 2 attacks that still affect modern organizations, including ARP spoofing, DHCP attacks, VLAN misuse, and client-to-client pivoting risks that can be reduced through secure architecture.
  • Architecting for Flow Data: Students compare flow data sources and learn where to position and how to use NetFlow, IPFIX, sFlow, cloud flows, Suricata flows, and endpoint telemetry to identify unauthorized or anomalous activity across hybrid environments.

Full Topic Details

  • Security architecture, security architects, and the Tyrell Corporation case study
  • Defensible security architecture, presumption of compromise, de-perimeterization, and Think Red, Act Blue
  • Risk-driven and business outcome-focused architecture, cyber resiliency, ruthless prioritization, and disrupting attacker ROI
  • Practical threat modeling, purple teaming, MITRE ATT&CK, MITRE ATLAS awareness, Cyber Kill Chain, Time-Based Security, and AI-assisted attack-path analysis
  • Zero Trust strategy, NIST SP 800-207, CISA ZTMM, UK NCSC guidance, NSA ZIG pillars, and realistic Zero Trust design principles
  • DARIOM: discovery, assessment, redesign, implementation, operation, monitoring, threat vector analysis, ingress mapping, egress mapping, data flow analysis, and attack surface analysis
  • Layer 1 and Layer 2 architecture, physical security, penetration testing dropboxes, USB keyboard attacks, wireless, Zigbee, RFID badges, WPA3 Enterprise, station isolation, and private 5G architecture
  • VLANs, PVLANs, switch hardening, ARP spoofing defenses, DHCP attack mitigation, NetFlow, IPFIX, sFlow, JFlow, VPC Flow Logs, Suricata flows, endpoint flow, cloud flows, OCSF normalization, and flow design

Section 2Network Architecture: Edge, Segmentation, and Identity-Based Access Control

Section 2 focuses on the network architecture layer: hardened edge devices, router and switch security, IPv6, segmentation, NAC, and identity-based access control. Drawing on Volt Typhoon & Salt Typhoon threat models, students engineer Zero Trust enforcement points and connect traditional network engineering to SD-WAN, SSE, ZTNA, SASE, and microsegmentation.

Topics covered

  • Router, switch, and SD-WAN hardening with AAA, TACACS+, RADIUS, and logging
  • SNMP security, NTP/NTS, bogon filtering, blackholes, darknets, and edge visibility
  • IPv6 security, rogue router advertisements, Neighbor Discovery attacks, and tunnels
  • Macro- and micro-segmentation, OT/ICS segmentation, data diodes, and zone design
  • NAC, 802.1X, OpenZiti, Software-Defined Perimeter, and identity-based segmentation

Labs

  • Router Security
  • IPv6
  • Identity-Based Segmentation with OpenZiti

Overview

This section continues the discussion of hardening critical infrastructure in hybrid environments. Routers, switches, firewalls, SD-WAN devices, cloud routing controls, and segmentation points remain high-value targets for adversaries because they shape trust boundaries, traffic paths, visibility, and enforcement. Students learn how to harden edge infrastructure, validate configuration baselines, and engineer network devices as Zero Trust enforcement points.

The section provides actionable examples for router and switch hardening, including secure administration, AAA, TACACS+, RADIUS, logging, configuration review, SNMPv3, NTP/NTS, bogon filtering, blackholes, darknets, and secure routing practices. It also covers IPv6 in depth, emphasizing common mistakes such as applying an IPv4 mindset to IPv6, missing rogue router advertisement risks, and overlooking unauthorized transition tunnels.

The section then moves into segmentation, one of the most important Zero Trust architecture topics. Students compare macro-segmentation, micro-segmentation, network segmentation, access segmentation, OT/ICS segmentation, data diodes, and identity-based segmentation. They connect traditional network engineering to current industry concepts such as SD-WAN, SSE, ZTNA, SASE, NAC, OpenZiti, Software-Defined Perimeter (SDP), and AI-era lateral movement reduction.

Full Lab Details

  • Router Security: Students identify and mitigate security issues in routers by reviewing configuration weaknesses, management-plane exposure, logging gaps, and hardening opportunities. In a live cloud-based router lab, students perform attacks against SNMP, understand the risk of weak community strings and configuration exposure, and remove the threat through secure SNMP design.
  • IPv6: Students interact with IPv4 and IPv6 to understand differences in addressing, discovery, tunneling, extension headers, router advertisements, and firewall/security control assumptions.
  • Identity-Based Segmentation with OpenZiti: Students compare traditional Layer 3/4 segmentation with identity-based policies, then enforce departmental segmentation using ZTNA concepts emulated with OpenZiti.

Full Topic Details

  • Layer 3 attacks and mitigation, IP source routing, ICMP attacks, unauthorized routing updates, unauthorized tunneling, and securing routing protocols
  • Switch, router, firewall, and SD-WAN best practices, Cisco IOS hardening examples, CIS Benchmarks, DISA STIGs, Nipper-ng, Cisco AutoSecure, and configuration validation
  • AAA, TACACS+, RADIUS, secure administration, logging, banners, management-plane exposure, and secure services
  • SNMP community string guessing, Cisco IOS configuration download through SNMP, SNMPv3, NTP authentication, NTP amplification, and NTS
  • Bogon filtering, fullbogons, blackholes, darknets, darknet traffic monitoring, and IP blackhole packet vacuums
  • IPv6 addressing, address assignment, extension headers, firewall support, scanning, discovery, tunneling, rogue router advertisements, Neighbor Discovery attacks, and protocol 41 visibility
  • Segmentation principles, firewall architecture, DMZ design, beyond-DMZ zone design, OT reference architecture, data diodes, network vs. access segmentation, and security-operations-aware architecture
  • Traditional segmentation, identity-based segmentation, NAC, 802.1X, OpenZiti architecture and components, SDP, ZTNA, SASE, SSE, microsegmentation, and AI-era lateral movement reduction

Section 3Network Detection, Secure Access, and Encrypted Traffic

Section 3 builds network-centric visibility & secure access architecture. It covers NGFW design, NDR/NSM placement, Security Onion, Zeek, Suricata, proxies, email security, ZTNA, SASE, mTLS, PKI, TLS inspection, and post-quantum encryption. The section emphasizes control placement, signal collection, & visibility as traffic encrypts across AI-era workflows.

Topics covered

  • NGFW architecture, application control, DNS security, sinkholing, and GenAI exfiltration
  • Network visibility with NSM, NDR, Security Onion, Zeek, Suricata, and cloud telemetry
  • Web and SMTP proxies, SWG, remote browser isolation, SPF, DKIM, DMARC, sandboxing
  • Secure remote access with VPN, ZTNA, SASE, SSE, OpenZiti, and cloud-routed access
  • Encryption architecture: mTLS, PKI, IPsec, ZTDNS, TLS inspection, and PQC readiness

Labs

  • Architecting for NSM
  • Network Security Monitoring
  • Encryption Considerations

Overview

Organizations own or have access to many network-based security technologies, including NGFWs, IDS/IPS, NDR, NSM sensors, proxies, VPNs, ZTNA, SASE, SSE, cloud firewalls, and email security gateways. These controls are often deployed on-premises and in the cloud, but their effectiveness depends heavily on architecture, placement, configuration, and integration. This section focuses on engineering network-centric visibility and secure access with a Zero Trust mindset.

Students examine how over-reliance on built-in automatic capabilities such as application control, antivirus, intrusion prevention, data loss prevention, and deep packet inspection can leave significant gaps. This section of SEC530 teach students how architecture choices improve prevention, engineered visibility, detection support, and response options. This includes understanding SPAN versus TAP design, sensor placement, cloud telemetry, Zeek, Suricata, JA3/JA4/JA4S, Security Onion, and SIEM integration.

The section also covers secure access and encryption tradeoffs. Students compare VPNs, ZTNA, SASE, SSE, OpenZiti, remote browser isolation, Apache Guacamole, proxies, SWG, email controls, mTLS, PKI, IPsec, ZTDNS, TLS inspection, QUIC/HTTP/3, Encrypted Client Hello, certificate transparency, and post-quantum cryptography readiness. The section emphasizes how to preserve useful visibility as traffic becomes encrypted and as AI-enabled data theft blends into normal-looking web, API, SaaS, GenAI, and agentic AI workflows.

Full Lab Details

  • Architecting for NSM: Students learn how to place and implement NSM technologies for visibility and application/protocol awareness, then use Zeek and correlation techniques to reason about tunnels, C2, beaconing, and AI-era exfiltration paths.
  • Network Security Monitoring: Students use intrusion detection alerts and network metadata to understand unauthorized network activity. The lab emphasizes what telemetry the architecture must produce so tools such as Suricata and Security Onion can support analysis and validation.
  • Encryption Considerations: Students explore how TLS and encryption protect data from attackers and defenders alike, then evaluate how proxies, NGFWs, NSM, TLS inspection, mTLS, PKI, and certificate transparency affect architecture choices.

Full Topic Details

  • NGFW architecture, application filtering, implementation strategies, external dynamic lists, DNS security, DNS filtering, sinkholing, infrastructure as code, Terraform, cloud NGFWs, scripting, and APIs
  • NDR and NSM architecture, alert-driven versus data-driven workflows, architecting for network visibility, network metadata, know-thy-network principles, SPAN ports, TAPs, sensor placement, and cloud telemetry
  • Zeek with a Zero Trust mindset, JA3, JA4, JA4S, RITA, beaconing with machine learning, Kubernetes visibility with Zeek, Security Onion, Suricata, Snort, IDS/IPS rule writing, SIEM integration, and protocol analysis
  • Web proxies, explicit versus transparent proxy design, delegated DNS, ICAP, forward and reverse proxies, Secure Web Gateway, remote browser isolation, malware detonation sandboxes, and proxy-based data control
  • SMTP proxies, phishing protection, Bayesian analysis, SPF, DKIM, DMARC, ARC, BIMI, typosquatting detection, dnstwist, and combating open-source intelligence abuse
  • Secure remote access, TLS VPN, SSH VPNs, Always On VPN, WAN optimization, rethinking VPN strategies, ZTNA, SASE, SSE, OpenZiti overlay networks, HTML5 remote desktop with Guacamole, and hybrid architecture access paths
  • Encryption architecture, encrypt-everything mindset, HSTS preloading, certificate transparency monitoring, crypto suite support, PFS, TLS 1.2 versus TLS 1.3, TLS interception tradeoffs, QUIC/HTTP/3, Encrypted Client Hello, mTLS, ZTDNS, and PQC readiness

Section 4Data-Centric Security: Protecting Data, APIs, and Workloads

Section 4 shifts the architecture toward applications, APIs, data, and workloads. It covers WAAP, WAFs, API gateways, RASP, database security, data discovery, encryption, DLP, DSPM, MDM, and privileged access. The section connects data controls to Zero Trust enforcement and addresses AI data security and exfiltration challenges from generative AI.

Topics covered

  • WAAP, WAF, API gateways, OWASP API Security Top 10, ModSecurity, and RASP
  • Database security, data discovery, credential abuse, masking, and activity visibility
  • Data encryption at rest and in use, confidential computing, HSM/KMS, and PQC awareness
  • Data governance, Microsoft Purview, DSPM, CASB, DLP, and GenAI exfiltration controls
  • Privileged access, PAWs, JIT, PIM/PAM, MDM, Kubernetes, SBOM, and runtime visibility

Labs

  • Securing Web Applications
  • Discovering Sensitive Data
  • Secure Visualization

Overview

The journey continues with data-centric security, a strategy central to Zero Trust architecture and AI-era security. Organizations cannot protect what they do not know exists, yet sensitive data often lives behind reverse proxies, web applications, APIs, application servers, database servers, microservices, cloud services, SaaS platforms, hypervisors, private clouds, containers, and developer pipelines. This section focuses on identifying, classifying, governing, and protecting important data wherever it resides.

Students learn how to prioritize security controls around critical data rather than trying to protect everything equally. The section covers WAAP, WAFs, API gateways, OWASP Top 10, OWASP API Security Top 10, RASP, database security, database activity monitoring, data discovery, data masking, encryption at rest, encryption in use, confidential computing, post-quantum-aware encryption, HSM/KMS design, Microsoft Purview, DSPM, CASB, DLP, insider risk management, AI data provenance, shadow AI governance, and GenAI exfiltration controls.

The section also covers privileged access, identity defense, and workload security. Students learn how to apply the Clean Source Principle, Microsoft’s Tiered Administration Model, Privileged Access Workstations (PAWs), Just-in-Time access, PIM/PAM, context-aware access, workload identities, BYOD, MDM, Intune, private cloud hardening, hypervisor security, Docker, Kubernetes, SBOMs, secrets management, image supply chain protection, and CNAPP/CSPM/CWPP/CIEM concepts.

Full Lab Details

  • Securing Web Applications: Students identify the prevention, visibility, and validation capabilities of web application firewalls, then examine where WAFs can be evaded and how to apply changes that block and detect evasion techniques.
  • Discovering Sensitive Data: Students walk step-by-step through writing a PowerShell script to crawl a file system for sensitive data. The lab reinforces why data discovery, classification, DSPM, DLP, and AI data governance depend on knowing where sensitive information resides.
  • Secure Virtualization: Students examine the implications of attackers gaining host access to a hypervisor or container system and apply hardening and response-oriented architecture steps for virtualization and container platforms.

Full Topic Details

  • Data-centric security, reverse proxies, full-stack security, monolithic applications, web servers, app servers, database servers, microservices, APIs, and cloud-native application architecture
  • Web application firewalls, OWASP Top 10, OWASP API Security Top 10, DDoS scrubbing, reverse proxy plus PAM, TLS offloading, ModSecurity, WAF bypass, normalization, dynamic content routing, WebLabyrinth, WAAP, open-appsec, RASP, and Zero Trust for cloud-native applications
  • API gateways, API security, NIST SP 800-207A, OpenZiti SDKs, workload identity, service-to-service access, and AI-enabled application risk
  • Database firewalls, database activity monitoring, data masking, advanced access controls, authenticated scanning, Snowflake-style credential abuse, database logging architecture, and exfiltration monitoring
  • Data encryption at rest, encryption in use, confidential computing, HSM/KMS design, post-quantum-aware encryption, BitLocker, TPM, network unlock, breach disclosure reduction, and crypto architecture decisions
  • File classification, data discovery, scripts versus software solutions, OCR scanning, Microsoft Purview Information Protection, sensitivity labels, DSPM, CASB, DLP, insider risk management, AI data provenance, shadow AI governance, and GenAI exfiltration controls
  • Entra ID and RBAC, time restrictions, MDM, MAM, BYOD, Intune MAM versus MDM, Conditional Access with Intune, and mobile/application enforcement patterns
  • Privileged access and identity defense, BloodHound, PingCastle, Clean Source Principle, Tiered Administration Model, PAWs, JIT, PIM/PAM, jump boxes, bastion hosts, private cloud security, vSphere, Xen, Hyper-V, VMware NSX, VM escape, hypervisor-based endpoint protection, Docker, Kubernetes security, SBOM, secrets, CNAPP, CSPM, CWPP, CIEM, image supply chain, and runtime visibility

Section 5Zero Trust in Action: Identity, Deception, and Agentic Orchestration

Section 5 brings the architecture together through identity-centered design, telemetry, and enforcement. It covers NSA ZIG, OAuth and token abuse, Silk Typhoon-style identity attacks, ITDR, OCSF normalization, LangGraph agentic orchestration, and deception. Students learn to use AI responsibly while controlling agent identity and human-in-the-loop gates.

Topics covered

  • Variable trust, NSA ZIG activity levels, and identity enforcement
  • IAM, IdP federation, FIDO2, passkeys, OAuth 2.0, OIDC, and Entra ID controls
  • Silk Typhoon, token theft, PRT abuse, MFA fatigue, AiTM phishing, ITDR, and UEBA
  • Agentic AI security, NHI, OWASP LLM risks, MITRE ATLAS, LangGraph, and risk scoring
  • Log architecture, Sysmon, Sigma, deception, honeytokens, and AI-resilient defense

Labs

  • ITDR Part 1: Identity Attacks in the Cloud
  • ITDR Part 2: Agentic AI Orchestration, Risk Scoring, and Conditional Access Response
  • Sigma Generic Signatures
  • Advanced Defense Strategies

Overview

Trust but verify is no longer enough. Section 5 shifts the architecture toward dynamic trust, applying context, identity, device state, telemetry, risk, and continuous assurance before granting access. Students bring together the architecture built throughout the course, from network segmentation and microsegmentation to control-plane and data-plane separation, to implement variable-trust architectures that adapt dynamically to risk.

The section revisits Zero Trust through NSA ZIG, NIST guidance, federal strategy, and practical implementation patterns. It then focuses on identity as a perimeter, including Entra ID, IAM, IdP federation, RBAC, SSO, SAML, OAuth 2.0, OIDC, MFA, FIDO2, passkeys, passwordless authentication, credential rotation, NIST 800-63B, service accounts, managed service accounts, token theft, PRT abuse, OAuth consent phishing, AiTM phishing, MFA fatigue, cross-tenant movement, and Conditional Access.

Students then design ITDR architecture and AI-augmented enforcement. The section covers identity telemetry, UEBA, behavioral baselining, OCSF normalization, agentic AI security, non-human identities, OWASP Agentic AI risks, OWASP Top 10 for LLM Applications, MITRE ATLAS, LangGraph orchestration, risk scoring, human-in-the-loop gates, SOAR integration patterns, Conditional Access enforcement, Sigma, Sysmon, auditd, MITRE mappings, deception, red herrings, honeytokens, identity deception, canary tokens, and AI-resilient defense.

Full Lab Details

  • ITDR Part 1: Identity Attacks in the Cloud: Students investigate modern cloud identity attacks, including token theft, OAuth abuse, consent phishing, PRT abuse, cross-tenant movement, and Conditional Access gaps, then reason about the telemetry and control architecture required to reduce identity risk.
  • ITDR Part 2: Agentic AI Orchestration, Risk Scoring, and Conditional Access Response: Students use OCSF-style signals, risk scoring, and agentic AI orchestration patterns to connect identity findings to enforcement decisions while preserving human-in-the-loop accountability.
  • Sigma Generic Signatures: Students use Sigma rules and conversion workflows to express portable detection logic, map coverage to MITRE ATT&CK, and validate that the architecture produces useful signals across SIEM and analytics platforms.
  • Advanced Defense Strategies: Students configure deception and adversary-disruption techniques that allow internal systems to keep functioning while attack tools fail or reveal themselves, including honeytokens, identity deception, red-herring defenses, and cloned-site detection concepts.

Full Topic Details

  • Zero Trust architecture, variable trust, control-plane and data-plane separation, NIST SP 1800-35, federal Zero Trust strategy, NSA ZIG activity levels, Conditional Access, SASE, microsegmentation, and realistic Zero Trust auditing
  • Identity as a perimeter, IAM, Entra ID, RBAC, identity federation, SaaS applications, federated SSO, SAML, OAuth, OIDC, modern versus legacy authentication, MFA, FIDO2, passkeys, passwordless, and credential rotation
  • Adversary-in-the-Middle phishing, MFA fatigue, MFA bypass, OAuth consent phishing, MSGraph risk, token theft, PRT abuse, CAE, cross-tenant movement, Silk Typhoon-style identity attacks, ITDR architecture, UEBA, identity telemetry, behavioral baselining, and enforcement thresholds
  • Securing traffic with mTLS, mutual TLS for API security, ZTDNS plus mTLS, single-packet authorization, 802.1X, client certificates, PKI, endpoint firewalls, Microsoft Attack Surface Reduction, application control, and endpoint privilege reduction
  • Dynamic authorization, adaptive trust, device compliance, Microsoft Intune and NAC, quarantine, automated digital response, and Conditional Access enforcement
  • AI in Zero Trust, AI versus ML, GenAI for cybersecurity, human-machine teaming, agentic AI security, non-human identities, OWASP Agentic AI risks, OWASP Top 10 for LLM Applications, MITRE ATLAS, LangGraph, OCSF, risk scoring, SOAR integration, and human-in-the-loop gates
  • Log collection architecture, SIEM in the cloud era, logs that matter, Windows auditing, Linux auditing, Sysmon, auditd, hybrid and cross-cloud logging strategy, designing for analysis rather than log collection, and MITRE ATT&CK content engineering
  • Sigma, Sigma conversion, Sigma2Attack, anomaly identification versus real-time alerts, MITRE Engage, deception architecture, tripwires, red herrings, honeynets, honeypots, honeytokens, identity deception, canary tokens, HALO, and proactive defenses that change attacker tool behavior

Section 6Hands-On Secure the Flag Challenge

Section 6 is the capstone challenge. Apply SEC530 architecture and engineering techniques in an immersive Secure the Flag environment. Assess, design, harden, validate, and defend Tyrell Corporation systems using controls and thinking patterns built throughout the course, including Zero Trust, visibility, identity, and enforcement concepts.

Topics covered

  • Defensible security architecture under pressure
  • Architecture assessment, attack-path analysis, and weakness identification
  • Tool- and script-based validation of the initial state
  • Defensive design changes, validation evidence, and challenge strategy
  • Practical application of Zero Trust, network, data, identity, and enforcement controls

Labs

  • Capstone - Design, Detect, Defend

Overview

The course concludes with an immersive team-based Secure the Flag challenge powered by SANS Cyber Ranges. Students apply the principles built throughout SEC530 in a full-day hands-on architecture challenge. Teams assess, design, harden, validate, and defend Tyrell Corporation systems using network, application, data, identity, telemetry, encryption, segmentation, and enforcement concepts from the entire course.

The capstone emphasizes architecture and engineering under pressure. Students must identify weaknesses in a provided environment, understand what changed, decide which controls matter most, and apply practical changes that improve resilience. The challenge reinforces Zero Trust thinking, AI-era visibility, data protection, identity defense, ITDR, secure access, deception, and defensible design.

Full Lab Details

  • Capstone - Design, Detect, Defend: Students work through a realistic Secure the Flag environment in which they must assess the initial state, identify weaknesses, prioritize architecture improvements, apply defensive changes, validate their impact, and defend Tyrell Corporation systems from a replicant attack scenario.

Full Topic Details

  • Defensible security architecture under pressure
  • Architecture assessment, attack-path analysis, and weakness identification
  • Tool- and script-based validation of the initial state
  • Quickly and thoroughly identifying configuration and architecture changes
  • Defensive design changes, validation evidence, and challenge strategy
  • Practical application of Zero Trust, identity defense, encryption, telemetry, visibility, deception, and enforcement controls

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 8GB of RAM or more is required.
  • 60GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration And Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer.
  • Fully update your host operating system prior to the class to ensure you have the right drivers and patches installed.
  • Linux hosts are not supported in the classroom due to their numerous variations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and/or VMs.
  • Administrative access to disable any AV, endpoint security software or host-based firewall (Yes, this is absolutely required. Don't let your IT team tell you otherwise.) If your company will not permit this access for the duration of the course, then you should make arrangements to bring a different laptop.
  • Ability to disable your enterprise VPN client temporarily for some exercises. Any filtering of egress traffic may prevent accomplishing the labs in your course. Firewalls should be disabled or you must have the administrative privileges to disable it.
  • Download and install VMware Workstation Pro 16.2.X+ or VMware Player 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ or VMware Player 17.0.0+ (for Windows 11 hosts), or VMWare Fusion Pro 12.2+ or VMware Fusion Player 11.5+ (for macOS hosts) prior to class beginning. If you do not own a licensed copy of VMware Workstation Pro or VMware Fusion Pro, you can download a free 30-day trial copy from VMware. VMware will send you a time-limited serial number if you register for the trial at their website. Also note that VMware Workstation Player offers fewer features than VMware Workstation Pro. For those with Windows host systems, Workstation Pro is recommended for a more seamless student experience.
  • On Windows hosts, VMware products might not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine. This may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are contained in the setup documentation that accompanies your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

If you have additional questions about the laptop specifications, please contact customer service.

SEC530 training is recommended for a diverse range of individuals, including:

  • Security Architects
  • Network Architects
  • Network Engineers
  • Security Analysts
  • Senior Security Engineers
  • System Administrators
  • Technical Security Managers
  • CND Analysts
  • Security Monitoring Specialists
  • Cyber Threat Investigators

The GIAC Defensible Security Architect (GDSA) certification validates a practitioner's ability to design and implement a strategic combination of network-centric and data-centric controls to balance prevention, detection, and response capabilities.

  • Using network-centric and data-centric security strategies to architect a layered defense
  • Assessing existing technology implementations to improve prevention, detection, and response
  • Understanding and applying Zero Trust principles

More Certification Details

  • Printed and electronic courseware
  • A virtual machine, an open-sourced, linux-based distribution with utilities to start and stop the containerized labs
  • An electronic workbook including detailed and visually rich step by step instructions, and an independent study guide with challenges, hints and instructional videos
  • Bonus labs that are regularly updated
  • MP3 audio files of the complete course lecture
  • Ongoing access to course authors and instructors via a private Slack channel

  • Foundational understanding of security principles and familiarity with general security technologies used in IT.
  • Knowledge of networking concepts and infrastructure components like switches, routers, and firewalls.
  • Some experience in IT security practices and operating systems (Linux and Windows) from the command line.
  • Experience using VMware and virtual machines.

The SEC530 course is part of the “Design, Detection, and Defensive Controls” Learning Path, which prepares security professionals to identify security anomalies, deploy detection and monitoring tools, and interpret their output.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Zero Trust implementation is a security model that operates on the principle of "never trust, always verify." It assumes that threats can originate from both inside and outside the network, requiring continuous authentication and authorization for every user and device attempting to access resources. Instead of relying on traditional perimeter-based security, Zero Trust focuses on securing individual resources and data, regardless of their location. This involves strict identity verification, device health checks, and least-privilege access, ensuring that only authorized entities can access specific resources.

The importance of Zero Trust stems from the changing nature of modern threats and the increasingly distributed nature of work. As organizations embrace cloud computing, remote work, and bring-your-own-device (BYOD) policies, traditional perimeter security becomes less effective. Zero Trust addresses these challenges by minimizing the attack surface, limiting the impact of breaches, and enhancing visibility into identity, devices, application, network, and data-plane activity . It reduces lateral movement within the network, meaning that even if an attacker gains initial access, their ability to move deeper into the system is severely restricted. This proactive approach significantly strengthens an organization's overall security posture in the face of sophisticated and persistent threats.

SEC530: Defensible Security Architecture and Engineering – Implementing Zero Trust for the Hybrid Enterprise can significantly boost your career by equipping you with highly sought-after skills in today's security landscape. Here's how:

  • Demand and Relevance: Zero Trust is rapidly becoming the industry standard, driven by the rise of cloud computing, remote work, and sophisticated cyberattacks. Demonstrating expertise in Zero Trust principles and implementation makes you a valuable asset to organizations seeking to enhance their security posture.
  • Enhanced Skillset: You will learn to design, implement, and manage Zero Trust architectures, including identity and access management, network segmentation, micro-segmentation, device security, and data protection. These skills are crucial for preventing and mitigating modern cyber threats.  
  • Career Advancement: Zero Trust expertise opens doors to various cybersecurity roles, such as security architect, network security engineer, cloud security specialist, and security consultant. You will be qualified for positions that require a deep understanding of modern security principles and practices.
  • Improved Problem-Solving: SEC530 will teach you to think critically about security, analyze risks, and implement effective controls. You will gain practical experience in applying Zero Trust principles to real-world scenarios, improving your ability to solve complex security challenges.  
  • Modern Security Practices: You will learn how to implement modern authentication, and authorization practices, and how to improve security monitoring, which are all skills that are highly valued by security teams.

Relevant Job Roles

Protection

SCyWF: Protection And Defense

This role uses cybersecurity tools to protect information, systems and networks from cyber threats. Find the SANS courses that map to the Protection SCyWF Work Role.

Explore learning path

Cybersecurity Research & Development

SCyWF: Cybersecurity Architecture, Research And Development

This role conducts conducts cybersecurity research and development. Find the SANS courses that map to the Cybersecurity Research & Development SCyWF Work Role.

Explore learning path

Cybersecurity Architect

European Cybersecurity Skills Framework

Plans and designs security-by-design solutions (infrastructures, systems, assets, software, hardware and services) and cybersecurity controls.

Explore learning path

Security Architect Training, Salary, and Career Path

Cyber Defense

Design, implement, and tune an effective combination of network-centric and data-centric controls to balance prevention, detection, and response. Security architects and engineers are capable of looking at an enterprise defense holistically and building security at every layer. They can balance business and technical requirements along with various security policies and procedures to implement defensible security architectures.

Explore learning path

Cybersecurity Architecture (OPM 652)

NICE: Design and Development

Responsible for ensuring that security requirements are adequately addressed in all aspects of enterprise architecture, including reference models, segment and solution architectures, and the resulting systems that protect and support organizational mission and business processes.

Explore learning path

Infrastructure Design (IFDN)

Skills Framework for the Information Age

Planning and design of secure, scalable, and resilient infrastructure across on-premise, cloud, and hybrid environments. Design outputs meet both current and future business needs.

Explore learning path

Cyber Defense Infrastructure Support Specialist (DCWF 521)

DoD 8140: Cybersecurity

Deploys, configures, maintains infrastructure software and hardware to support secure and effective IT operations across organizational systems.

Explore learning path

Network Operations Specialist (DCWF 441)

DoD 8140: Cyber IT

Implements and maintains network services, including hardware and virtual systems, ensuring operational support for infrastructure platforms.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 21

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources