Group Purchasing
Group Purchasing

SEC401: Security Essentials

SEC401Cyber Defense
  • 6 Days (Instructor-Led)
  • 46 Hours (Self-Paced)
Course authored by:
Bryan Simon
Bryan Simon
Course authored by:
Bryan Simon
Bryan Simon
  • GIAC Security Essentials (GSEC)
  • 46 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Essential Skill Level

    Course material is for individuals with an understanding of IT or cyber security concepts

  • 20 Hands-On Lab(s)

    Apply what you learn with hands-on exercises and labs

Essentials are not basics. They are the foundation every specialization is built upon—and without them, the specialization itself is unstable.

Course Overview

SEC401: Security Essentials covers more than 30 topical areas of information security—not because breadth is a goal in itself, but because the industry demands it. You cannot effectively defend what you do not understand; and what you do not understand, in an industry this large and this interconnected, will eventually become the gap that matters most.

The course is structured around a deliberate distinction: the difference between knowing the 'what' of a proper security posture, and knowing the 'how' of implementing one. The first four sections of SEC401 address the 'what'—the concepts, frameworks, and principles that form the foundation of any defensible security program. The last two sections address the 'how'—the practical application of those concepts across the platforms where security actually lives: Windows, UNIX, Linux, macOS and cloud.

SEC401 is designed for both managers and technical professionals. Not as a compromise between two audiences—but because both audiences share the same foundational gaps, expressed differently. The manager who cannot articulate why a control matters cannot defend the budget that funds it. The technical professional who implements controls without understanding their foundational purpose is building on ground they have never tested.

Modern cyber defense practices are woven throughout—not as a standalone topic bolted onto existing content, but as the lens through which every concept is examined. The threat landscape that exists today is the context for everything taught here.

Hands-on labs reinforce this directly. Rather than isolated exercises, the SEC401 labs follow a continuous compromise scenario at a fictitious global organization—Alpha Incorporated. Across four separate scenarios (an AWS server compromise, a USB device containing sensitive documents, a phishing victim, and a development environment pushed prematurely to production), you will apply what you learn in the context of real consequences. Select labs incorporate AI assistance—not as a novelty, but as a reflection of how security work is actually performed today. This is the SANS promise, stated plainly: what you learn in SEC401 will be immediately applicable when you return to work.

Enhanced Labs Overview

SEC401 features 20 hands-on labs spanning the full breadth of the course—from network traffic analysis and cryptographic validation to intrusion detection, container security, and Windows and Linux security. Select labs now incorporate AI assistance, reflecting the reality that AI tools are already part of the modern security practitioner's workflow. The lab environment is built around real tools, real scenarios, and real decisions—because proficiency developed in an artificial environment does not transfer.

Lab Highlights:

  • Network Security and Cloud Essentials: tcpdump, Wireshark, and AWS VPC Flow Logs (AI Assisted Lab) — packet analysis, protocol examination, and cloud network flow visibility.
  • Defense-in-Depth: Password Auditing, Data Loss Prevention, and Mobile Device Backup Recovery—identity, data protection, and mobile security applied directly.
  • Vulnerability Management and Response: Network Discovery, Binary File Analysis (AI Assisted Lab), Web Application Exploitation, and SIEM Log Analysis — system discovery, analyzing threats, and detecting adversarial activity.
  • Data Security Technologies: Hashing and Cryptographic Validation, Encryption and Decryption, and Intrusion Detection and Network Security Monitoring with Snort3 and Zeek (AI Assisted Lab).
  • Windows and Azure Security: Windows Process Exploration, Windows Filesystem Permissions, Applying Windows System Security Policies, and PowerShell for Speed and Scale.
  • Containers, Linux, and Mac Security: Linux Permissions, Linux Containers, and Linux Logging and Auditing.

Author Statement

"From observing the world around us, we are living in an era of never-ending compromise. At first glance, the rise in compromises could be attributed to the sheer increase in systems being connected to more networks than ever before. Upon reflection, however, poor security practices might also bear much of the blame.

If more systems being connected to more networks directly leads to more compromises, we face a significant problem. The number of interconnected systems will only continue to grow in an increasingly connected world. With more security tools and technologies available today than at any other time in computing history, surely poor security practices alone can't explain the rise in compromises. Or can they?

The reality is complex. It's possible we live in a world of ever-expanding security capabilities and, simultaneously, ever-increasing compromises. As unsettling as this is, the key takeaway lies in the simple idea that 'Offense informs Defense.' In that spirit, SEC401 offers real-world, immediately actionable knowledge that will empower you and your organization to better defend against modern adversaries. Join us to learn how to fight—and how to win."

— Bryan Simon

What You’ll Learn

  • Master foundational principles: network architecture, cryptography, identity, and hardening
  • Analyze real traffic, interpret logs, and identify indicators of compromise
  • Evaluate defensive strategies across on-premises, cloud, and hybrid environments
  • Recognize and respond to the full attack lifecycle: compromise through exfiltration
  • Implement security controls across Windows, Linux, and macOS with consistency
  • Apply vulnerability management practices that prioritize risk intelligently, not reactively
  • Map adversarial tactics to defensive countermeasures—and understand why it matters

Business Takeaways

  • Build a security program grounded in defensible architecture—explainable and measurable
  • Develop a vulnerability management approach that prioritizes by actual organizational risk
  • Reduce risk through systematic hardening across every major platform: Windows, Linux, macOS
  • Connect foundational security controls to the adversarial tactics they're designed to defeat
  • Return to work day one with skills and tools immediately applicable to your environment

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in SEC401: Security Essentials.

Section 1 Network Security and Cloud Essentials

Every organization operates under the same uncomfortable reality: not every attack will be prevented. The question is never "how do we stop everything?" because everything cannot be stopped. The more important question is "how quickly can we detect, understand, and respond when something gets through?" Section 1 builds that answer, starting with the network itself.

Topics covered

  • Defensible Network Architecture
  • Protocols and Packet Analysis
  • Virtualization, Cloud, and AI Essentials
  • Securing Wireless Networks

Labs

  • Tcpdump
  • Wireshark
  • AI Assisted Lab: AWS VPC Flow Logs

Overview

Within any organization, not all data holds equal value. Some information is routine; other data is so sensitive that its loss causes irreparable damage—to the organization, to its customers, or to both. Understanding that distinction is not an abstract exercise. It directly determines where your defenses are focused, where your monitoring is concentrated, and where the consequences of a gap are most severe. That understanding begins with knowing how modern network communication protocols behave—and where they are vulnerable.

Cloud computing is not a separate conversation from network security. It is a continuation of it. No discussion of defensible networking is complete without addressing the cloud—its security capabilities, its architectural differences from traditional infrastructure, and the new attack surface it introduces. Artificial intelligence enters this conversation here as well, deliberately—not as a standalone topic, but because AI-driven solutions increasingly operate within cloud environments, and because the gap between what AI actually is and what most people assume it to be has direct security implications.

Adversaries rely on our networks as much as we do. They move laterally, they pivot relentlessly from system to system, and they exploit the infrastructure we built for our own purposes to reach their objectives. Understanding how your network functions—its design, its communication flows, its protocols—is what makes adversarial movement visible. You cannot see what you do not understand.

Wireless networking closes this section for a specific reason: it is simultaneously the most pervasive and the least understood component of most organizations' network infrastructure. That combination—ubiquity and misunderstanding—is precisely where risk lives.

Full Lab Details

  • Sniffing and analysis of network traffic using tcpdump
  • Sniffing, protocol decoding, and extraction of network traffic using Wireshark
  • AI Assisted Lab: Examination and interpretation of Amazon Web Services (AWS) VPC Flow Logs

Full Topic Details

Module: Defensible Network Architecture

A network you do not fully understand is a network you cannot fully defend. This module establishes the logical and physical components of network architecture as the prerequisite for everything that follows—and then immediately challenges that foundation by examining how adversaries see and abuse the same infrastructure you are trying to protect. Defense and offense are not separate conversations. They begin here, together.

  • Network Architecture
  • Attacks Against Network Devices
  • Network Topologies
  • Network Design

Module: Protocols and Packet Analysis

Understanding how networks actually communicate—at the protocol level, at the packet level—is what separates a security professional who can only respond to known attacks from one who can recognize something they have never seen before. This module builds that understanding from the ground up: the core concepts of computer networking and the protocols that govern how data moves, where it can be intercepted, and what it looks like when something is wrong.

  • Network Protocols Overview
  • Internet Protocol (IP)
  • Internet Control Message Protocol (ICMP)
  • Transmission Control Protocol (TCP)
  • User Datagram Protocol (UDP)
  • tcpdump

Module: Virtualization, Cloud, and AI Essentials

Every technology in this module is, at its core, an abstraction. Virtualization abstracts hardware—separating the logical from the physical, enabling isolation, containment, and recovery capabilities. Cloud computing abstracts infrastructure and services—removing the boundary of physical ownership and replacing it with on-demand capability, shared responsibility, and an attack surface that extends well beyond the traditional network perimeter. Artificial intelligence abstracts analysis and decision-making itself—and with that abstraction comes a set of risks that most organizations have not yet fully internalized: hallucination, overreliance, prompt injection, and data exposure among them.

These are not three separate topics. They are three successive stages of the same evolution—each one building on the last, each one carrying the security implications of everything that preceded it. Understanding them that way is what this module is designed to accomplish.

  • Virtualization Overview
  • Virtualization Security
  • Cloud Overview
  • Cloud Security
  • AI Overview
  • AI Security

Module: Securing Wireless Networks

Wireless communication is everywhere—and that ubiquity is precisely the problem. Most organizations deploy and rely on wireless technologies they do not fully understand, which means most organizations carry risk they cannot accurately measure. This module addresses that gap directly: the differences between wireless communication technologies, the insecurities inherent to each, and the practical approaches to reducing that risk to a level that is not just acceptable—but defensible.

  • The Pervasiveness of Wireless Communications
  • Traditional Wireless: IEEE 802.11 and its Continual Evolution
  • Personal Area Networks: Bluetooth, Bluetooth Low Energy, Zigbee, Thread/Matter, Z-Wave, UWB
  • 5G Cellular (Mobile) Communications
  • The Internet of Things

Section 2Defense in Depth

No single control stops every threat. That is not a failure of security—it is the reality defense-in-depth is designed to address. Section 2 builds the layered strategy every organization needs but few implement fully: from information assurance principles through identity, authentication, and security frameworks, to data protection and mobile security.

Topics covered

  • Defense-In-Depth
  • IAM, Authentication, and Password Security
  • Security Frameworks
  • Data Loss Prevention
  • Mobile Device Security

Labs

  • Password Auditing
  • Data Loss Prevention
  • Mobile Device Backup Recovery

Overview

The section opens where every serious security discussion must: with information assurance—the foundational commitment to protecting the confidentiality, integrity, and availability of organizational systems. These are not abstract principles. They are the measurable properties that adversaries specifically target, and understanding how large-scale threats attack each one is what makes the rest of this section's content actionable rather than theoretical.

Identity and access management follows directly, because IAM is not about simply an access control mechanism—it is increasingly the security perimeter for cloud-based systems. Passwords remain the dominant authentication factor despite decades of effort to move beyond them, and credential theft remains one of the most common entry points for attackers. This module addresses that reality directly: modern authentication methods, password security, passkeys, and the role of IAM in a cloud-first environment where the traditional network perimeter no longer exists.

From there, the section turns to the frameworks that give structure to defensive decision-making: the CIS Controls, the NIST Cybersecurity Framework, and the MITRE ATT&CK knowledge base. These are not compliance checkboxes—they are the organized intelligence of the security community, distilled into actionable guidance. Understanding how they work, where they complement each other, and how they map to real adversarial behavior is what separates a reactive security program from a deliberate one.

Next, network defensibility returns to focus—specifically, the additional architectural and data protection controls that reinforce what Section 1 established. Data loss prevention is examined in depth: how sensitive data moves, where it is most at risk, and what controls meaningfully reduce that risk both in transit and at rest.

Mobile devices close the section—not as an afterthought, but as a deliberate final statement about the scope of modern defense-in-depth. The mobile device is simultaneously the most personal and the most organizationally significant technology most employees carry. BYOD (Bring Your Own Device) and MDM (Mobile Device Management) are examined not just as policy topics, but as the practical intersection of individual convenience and organizational risk—which is, in many ways, what defense-in-depth is ultimately about.

Full Lab Details

  • Password Auditing
  • Investigative techniques using Data Loss Prevention capabilities
  • Investigation of artifacts found in mobile device backups

Full Topic Details

Module: Defense-in-Depth

Defense-in-depth begins with an honest acknowledgment: no single control is sufficient. Threats to confidentiality, integrity, and availability are too varied, too persistent, and too adaptive for any organization to rely on a single layer of protection. This module examines those threats at scale—and builds the case for layered defense as the only rational response to them. Related principles, including Zero Trust, are examined here not as alternatives to defense-in-depth, but as frameworks that reinforce and extend it.

  • Defense-in-Depth Overview
  • Constituents of Risk: Confidentiality, Integrity and Availability
  • Strategies for Defense-in-Depth
  • Core Security Strategies
  • Defense-in-Depth in the Cloud
  • Zero Trust Methodology
  • Variable Trust

Module: IAM, Authentication, and Password Security

Identity is the new perimeter—and access control is how that perimeter is enforced. This module establishes the principles of identity management and access control, examining the varying models through which organizations grant, restrict, and revoke access, and the strengths and weaknesses each approach carries. Authentication and authorization protocols are examined in that context, leading naturally to the three factors of authentication: something you know, something you have, and something you are. The module closes where the most persistent problem lives—the password. Despite decades of alternatives, the password remains the dominant authentication factor, and credential theft remains one of the most reliable tools in an attacker's arsenal. Understanding why is as important as understanding what to do about it.

  • IAAA: Identification, Authentication, Authorization, Accountability
  • Single Sign On (SSO): Traditional On-Premise and Cloud
  • Password Management
  • Password Techniques
  • Password (Passphrase) Policies
  • Password Storage
  • Key Derivation Functions
  • How Password Assessment Works
  • Password Attack Tools (Hashcat and Mimikatz)
  • Multi-Factor Authentication
  • Adaptive Authentication
  • Passkeys
  • Privileged Access Management: On-Premise and Cloud

Module: Security Frameworks

You cannot manage what you cannot measure—and you cannot measure what you have not defined. This module establishes three frameworks that together provide the structure, prioritization, and adversarial intelligence a modern security program requires. The CIS Controls identify and prioritize the most critical risks organizations face. The NIST Cybersecurity Framework provides the broader context for managing overall cybersecurity risk across an organization. The MITRE ATT&CK knowledge base maps real adversarial tactics and techniques to defensive countermeasures. Individually, each framework is valuable. Combined—prioritized action informed by comprehensive risk management, tested against actual adversarial behavior—they form the analytical foundation of a security program that can defend against the modern adversary with intention rather than assumption.

  • Introduction to the CIS Controls
  • CIS Controls Guiding Principles
  • Case Study: Sample CIS Control
  • NIST Cybersecurity Framework
  • MITRE ATT&CK (TTP and Mapping to Known Adversaries)

Module: Data Loss Prevention

Loss or leakage?

The distinction matters more than most organizations realize. Data loss describes any condition that results in data being corrupted, deleted, or rendered unreadable—an availability and integrity problem. A data breach is an incident that can lead to unintentional information disclosure and data leakage—a confidentiality problem. These are not the same condition, they do not carry the same consequences, and they do not respond to the same controls. This module establishes that distinction precisely, then examines the methodologies for implementing a data loss prevention capability that addresses both.

  • Loss or Leakage
  • Data Loss
  • Data Leakage
  • Ransomware
  • Preventative Strategies
  • Redundancy (On-Premise and Cloud)
  • Data Recovery
  • Related Regulatory Requirements (GDPR and CCPA)
  • Data Loss Prevention Tools
  • User Activity Monitoring

Module: Mobile Device Security

Mobile devices are the most personal technology most employees carry—and increasingly, the most organizationally significant. The security decisions made at the operating system level have direct consequences for the organizations those devices connect to, which makes understanding the architectural differences between Android and iOS not an academic exercise but a practical one. A common assumption in the industry is that Android is inherently less secure than iOS. This module examines that assumption directly—the architectural realities behind it, the contexts in which it holds, and the contexts in which it does not. Security features, platform limitations, and the real risks introduced by mobile malware are examined for both platforms, without the oversimplification that assumption encourages. The module then addresses the organizational challenge directly: how BYOD policies and Mobile Device Management frameworks attempt to reconcile individual convenience with the security requirements of the enterprise—and where that reconciliation succeeds and where it falls short.

  • Android versus iOS
  • Android Security
  • Android Security Features
  • What You Need to Know About Android
  • Android Fragmentation
  • Android Security Fix Process
  • iOS Security
  • iOS Security Features
  • What to Know About iOS
  • iOS Updates
  • Mobile Problems and Opportunities
  • Mobile Device Management
  • Rooting and Jailbreaking
  • Mitigating Mobile Malware
  • Android Malware
  • iOS Malware

Section 3Vulnerability Management and Response

Every compromise begins somewhere. Section 3 covers the full arc—from vulnerabilities that give adversaries a foothold, through attack methods, to logging and detection that expose post-compromise activity, and the incident response discipline that shapes effective recovery. Understanding each stage isn’t optional; the adversary already does.

Topics covered

  • Vulnerability Assessments and Penetration Testing
  • Attacks and Malicious Software
  • Web Application Security
  • Security Operations and Log Management
  • Digital Forensics and Incident Response

Labs

  • Network Discovery
  • AI Assisted Lab: Binary File Analysis and Characterization
  • Web App Exploitation
  • SIEM Log Analysis

Overview

The section opens with vulnerability management—not as an abstract concept, but as a measurable condition that exists in every environment. Defining what constitutes a vulnerability precisely, and establishing a vulnerability assessment program that identifies and prioritizes them systematically, is the foundation this section builds on. Without that foundation, security investment is reactive at best and misdirected at worst.

Because vulnerabilities are the weaknesses adversaries exploit, understanding them requires understanding how adversaries actually use them. Modern attack methodologies are examined in depth here—with real-world examples of compromise that connect technical concepts to actual consequences. Among all potential attack surfaces, web applications consistently represent some of the greatest organizational risk, producing some of the most severe outcomes when exploited. The breadth and severity of web application vulnerabilities warrants—and receives—an entire dedicated module.

Compromise, however, is rarely the end of the story. Adversaries who gain access to a system do not stop moving—they pivot, they persist, and they pursue their objectives through actions that, critically, can often be detected. The logging capabilities built into hardware and software are not compliance artifacts. They are detection infrastructure—and leveraging them effectively is what separates an organization that discovers a breach weeks later from one that identifies adversarial activity while it is still in progress. Security Operations and Log Management addresses exactly that capability.

The section closes with incident response—because detection without a structured response plan is incomplete. When a compromise occurs, the quality of the organization's response determines the scope of the damage. The methodology for an effective incident response is not improvised. It is built, tested, and maintained long before it is needed.

Full Lab Details

  • System Discovery with Nmap
  • AI Assisted Lab: Malware Analysis
  • Abusing Web Application Vulnerabilities for Exploitation
  • Leveraging SIEM Logs for Incident Response and Investigation

Full Topic Details

Module: Vulnerability Assessments

Knowing that vulnerabilities exist in your environment is not the same as knowing which ones matter most. This module establishes the techniques and frameworks for mapping networks and scanning for vulnerabilities systematically—not to produce an exhaustive list, but to produce an actionable one. A vulnerability assessment without prioritization is noise. This module addresses both the capability and the discipline required to turn that noise into a defensible, risk-informed program.

  • Introduction to Vulnerability Assessments
  • Steps to Perform a Vulnerability Assessment
  • Criticality and Risks

Module: Penetration Testing

Penetration testing is one of the most frequently misunderstood capabilities in security—not because organizations are unfamiliar with the term, but because they often misunderstand what it can and cannot tell them. Traditional penetration testing, constrained by scope and time, rarely replicates the full behavior of a real adversary. That limitation gave rise to red teaming and adversary emulation—methodologies specifically designed to do what penetration testing alone cannot: simulate the persistence, creativity, and objectives of an actual threat actor. This module examines all three, the distinctions between them, and the disciplined, methodical approach required to make any of them genuinely valuable to an organization rather than simply reassuring.

  • The What and Why of Penetration Testing
  • Red Team
  • Adversary Emulation
  • Purple Team
  • External and Internal Penetration Testing
  • Web Application Penetration Testing
  • Social Engineering
  • Penetration Testing Process
  • Penetration Testing Tools (Nmap, Metasploit, Meterpreter)
  • Password Compromise, Reuse, Stuffing, and Spraying

Module: Attacks and Malicious Software

The most efficient path to understanding how to defend against attacks is to understand how those attacks actually work. This module examines well-known breaches and ransomware—not for the sake of cataloguing failure, but to identify the conditions that made them possible and the controls that could have interrupted them at each stage. Ransomware alone continues to affect hundreds of thousands of systems across every industry, and its persistence is not a mystery—it exploits conditions that are identifiable, measurable, and addressable. Offense informs Defense. This module is where that principle is most directly applied.

  • High-Profile Breaches and Ransomware
  • Ransomware as a Service
  • Common Attack Techniques
  • Malware and Analysis

Module: Web Application Security

Web applications are among the most targeted and most successfully exploited components of any organization's attack surface—which is precisely why this module exists as a standalone topic rather than a subsection of something broader. Understanding web application security begins with understanding how web communications actually work: HTTP and HTTPS, cookies, authentication mechanisms, and the challenge of maintaining state across stateless protocols. That foundation makes the vulnerability discussion that follows meaningful rather than abstract—because knowing how web applications are built is what makes it possible to understand how they are broken, and what it takes to fix them.

  • Web Communication Fundamentals
  • Cookies
  • HTTPS
  • Developing Secure Web Apps
  • OWASP Top Ten
  • Basics of Secure Coding
  • Web Application Vulnerabilities
  • Web Application Monitoring
  • Web Application Firewall (WAF)

Module: Security Operations and Log Management

Logging is not a compliance requirement dressed up as a security control. It is detection infrastructure—and the difference between an organization that discovers a breach weeks after the fact and one that identifies adversarial activity while it is still in progress is often not the sophistication of their tools. It is the discipline of their logging. This module establishes the essential components of an effective logging program, how to manage log data at scale, and how to leverage that data during incident response—turning what most organizations treat as an audit trail into an active, operational capability for detecting and responding to threats in real time.

  • Logging Overview
  • Log Collection Architecture
  • Log Filtering
  • Problems with Logging Standards
  • Setting Up and Configuring Logging
  • Log Analysis Tools
  • Log Aggregation and SIEM
  • Key Logging Activities

Module: Digital Forensics and Incident Response

When a compromise occurs, the quality of the response determines the scope of the damage—and the quality of the forensic process determines whether anything learned from that compromise can be trusted, repeated, or defended. This module establishes the fundamentals of incident handling and response: a structured, multi-step methodology for building procedures and response plans that work under pressure, not just in theory. Digital forensic methodologies are examined as the discipline that makes incident response verifiable—ensuring that the evidence collected is forensically sound, the processes followed are repeatable, and the conclusions reached are defensible. Improvised incident response produces inconsistent results. This module is the alternative.

  • Introduction to Digital Forensics
  • What is Digital Forensics?
  • Digital Forensics in Practice
  • The Investigative Process
  • Remaining Forensically Sound
  • Examples of Examining Forensics Artifacts
  • DFIR (Digital Forensics and Incident Response) Subdisciplines
  • Digital Forensics Tools
  • Incident Handling Fundamentals
  • Multi-Step Process for Handling an Incident
  • Threat Hunting

Section 4Data Security Technologies

Section 4 examines technologies at the core of defensive security—starting with the most misunderstood: cryptography. It then covers prevention and detection at network and endpoint levels. Awareness isn’t enough; understanding how they work, where they fail, and how they complement each other is what makes them truly defensible choices in practice.

Topics covered

  • Cryptography
  • Cryptography Algorithms and Deployment
  • Applying Cryptography
  • Network Security Devices
  • Endpoint Security

Labs

  • Hashing and Cryptographic Validation
  • Encryption and Decryption
  • AI Assisted Lab: Intrusion Detection and Network Security Monitoring

Overview

There is no single solution that guarantees complete security, but one technology that can address many security challenges—though often improperly deployed—is cryptography. In the first half of this section, we will delve into various cryptographic concepts and explore how they can be effectively used to safeguard an organization's assets.

In the second half, our focus shifts to prevention technologies that can stop adversaries from gaining access to your organization. This includes the use of firewalls and intrusion prevention systems. We will also examine detection technologies, such as intrusion detection systems, which can identify the presence of an adversary. These prevention and detection methods can be deployed at both the network and endpoint levels, and we will discuss the similarities and differences in their implementation.

Full Lab Details

  • Hashing and Cryptographic Validation
  • Encryption, Decryption, and Digital Signature Techniques
  • AI Assisted Lab: Incident Detection Leveraging the Snort and Zeek Intrusion Detection Systems

Full Topic Details

Module: Cryptography

Cryptography is the mechanism by which confidentiality, integrity, authentication, and non-repudiation are technically achieved—four properties that, together, form the foundation of trustworthy communication and data protection. Three fundamental cryptographic systems make this possible: symmetric, asymmetric, and hashing. Each is distinguished by the number of keys it employs and the specific security properties it is designed to deliver. Understanding the differences between them—not just conceptually, but in terms of when each is appropriate and what each cannot do—is what separates a practitioner who deploys cryptography correctly from one who deploys it with confidence but without precision, and thereby leading to great security weakness.

  • Cryptosystem Fundamentals
  • Cryptography
  • Cryptanalysis
  • General Types of Cryptosystems (Symmetric, Asymmetric, Hashing)
  • Digital Signatures

Module: Cryptography Algorithms and Deployment

Understanding why certain cryptographic algorithms are trusted—and why others have been deprecated or broken—requires enough mathematical grounding to evaluate them honestly. This module builds that grounding: the mathematical concepts that underpin modern cryptographic systems, examined at a level of depth that makes algorithm selection and deployment decisions informed rather than arbitrary. Equally important are the attacks designed to subvert those systems—because cryptographic history is, in no small part, a history of algorithms that were once considered secure until they were not. That history is still being written. Quantum computing introduces a threat to contemporary cryptographic standards that is no longer just a theoretical—it must be considered a reality that the industry must prepare for through Post-Quantum Cryptography. Both the threat and the response are examined here, because the cryptographic decisions organizations make today will determine their security posture in a post-quantum world.

  • Mathematical Features of Strong Cryptography
  • AES
  • RSA
  • ECC
  • Cryptography Attacks (Cryptanalysis)
  • Quantum Computing and PQC (Post-Quantum Cryptography)

Module: Applying Cryptography

The previous two modules establish what cryptography is and how it works. This module is where that knowledge meets operational reality. Data in transit and data at rest represent two distinct protection challenges—each requiring specific cryptographic mechanisms, each carrying specific deployment considerations, and each failing in specific ways when those considerations are ignored. The module then addresses Public Key Infrastructure: the framework through which public key cryptography is deployed and managed at organizational scale. PKI is one of the most consequential and most frequently mismanaged cryptographic systems in enterprise environments. Understanding PKI—not just conceptually, but operationally—opens the door to numerous and powerful security capabilities.

  • Data in Transit
  • Virtual Private Networks (VPN), IPsec and SSL-based
  • Data at Rest
  • File/Folder Level Encryption
  • Full Disk Encryption
  • GNU Privacy Guard (GPG)
  • Key Management
  • Public Key Infrastructure (PKI)
  • Digital Certificates
  • Certificate Authorities
  • PKI Use Cases

Module: Network Security Devices

Firewalls, Network Intrusion Detection Systems, and Network Intrusion Prevention Systems are among the most widely deployed security controls in enterprise environments—and the differences between them matter more than most deployments reflect. A firewall enforces policy; it is only as effective as the rules it enforces. The distinction between detection and prevention is not a marketing distinction—it is an architectural one with direct operational consequences. Deploying a prevention system where a detection system is needed, or relying on a firewall ruleset that has never been audited, does not produce security. It produces the appearance of security. This module examines all three technologies in depth: what each one does, what each one cannot do, and how they function together as a complementary set of network-level controls.

  • Overview of Firewalls
  • Types of Firewalls
  • Firewall Configuration and Deployment Considerations
  • NIDS
  • Types of NIDS
  • Snort as a NIDS
  • NIPS
  • Methods for NIPS Deployment
  • NIPS Security and Productivity Risk Considerations

Module: Endpoint Security

Network-level controls establish boundaries. Endpoint security is what exists beyond them—and it is where most attacks ultimately land. This module examines security from the endpoint perspective specifically: the strategies, controls, and solutions that protect individual systems rather than the network they connect to. Baselining is examined as a foundational capability—because detecting anomalous behavior requires first defining what normal looks like, and most organizations have never done that work systematically. Host-based Intrusion Detection and Prevention Systems are examined in direct relation to their network-level counterparts from the previous module: same principles, different deployment context, different visibility, different operational considerations. The section that began with cryptography ends here—at the endpoint where data is ultimately created, and most directly at risk.

  • Endpoint Security Overview
  • Core Components of Endpoint Security
  • Enhancing Endpoint Security
  • Endpoint Security Solutions
  • Anti-malware
  • Endpoint Firewalls
  • Integrity Checking
  • HIDS, HIPS, and EDR

Section 5Windows and Azure Security

Windows remains the most widely used—and most targeted—desktop OS; those facts are linked. Section 5 examines Windows security in today’s ecosystem: Active Directory, Azure, PowerShell, PKI, BitLocker, Microsoft 365, Hyper-V, and more. The simple desktop model no longer applies; this section focuses on the Windows organizations actually defend today.

Topics covered

  • Windows Security Infrastructure
  • Windows as a Service
  • Windows Access Controls
  • Enforcing Security Configurations
  • Microsoft Cloud, Automation, Logging and Auditing

Labs

  • Windows Process Exploration
  • Windows Filesystem Permissions
  • Applying Windows System Security Policies
  • Using PowerShell for Speed and Scale

Overview

The Windows ecosystem has expanded dramatically—and the security surface has expanded with it. What was once a relatively contained environment of desktop workstations in small workgroups is now a complex, hybrid infrastructure spanning on-premises Active Directory, cloud-based Azure environments, virtual desktop infrastructure, and the full breadth of the Microsoft 365 platform. Each addition to that ecosystem introduced new capabilities. Each also introduced new attack surface—and new security requirements that the previous generation of Windows administration was never designed to address.

Windows security in this context is not a single discipline. It is the intersection of identity management, access control, endpoint hardening, automation, and cloud security—all operating within a single vendor ecosystem that is simultaneously one of the most mature and one of the most actively targeted in enterprise computing. Active Directory remains one of the most targeted components in modern attacks; PKI underpins certificate-based trust across the environment; BitLocker addresses data protection at the endpoint level; and PowerShell has become both the most powerful administrative tool and one of the most frequently abused by adversaries.

This section works through all of it—methodically, with direct attention to both the on-premises and Azure dimensions of modern Windows security. Automation and auditing are fundamental, because the scale of the modern Windows environment makes manual administration not just inefficient but genuinely insufficient as a security practice.

Full Lab Details

  • Process Observation and Analysis
  • NTFS File System Permissions Analysis as a Part of Incident Response
  • Auditing and Enforcement of System Baseline Configurations with Security Templates
  • PowerShell Scripting and Automation Techniques for Speed and Scale

Full Topic Details

Module: Windows Security Infrastructure

Every subsequent module in this section depends on what is established here. The Windows security model is not background material. It is the foundation that makes Active Directory, PKI, BitLocker, and every other Windows security mechanism intelligible rather than merely operational. This module builds that foundation deliberately, because understanding why Windows security works the way it does is what separates a security administrator who can configure controls from one who can evaluate them.

  • Windows Family of Products
  • Windows Workgroups and Accounts
  • Windows Active Directory and Group Policy

Module: Windows as a Service

Windows is no longer a static platform that organizations deploy, configure, and maintain on their own schedule. Windows as a Service means continuous updates, continuous change, and a security posture that must be actively managed rather than periodically revisited. This module addresses what that means in practice: patch and update management in an environment where the pace of change is determined by Microsoft as much as by the organization, and cloud-based deployment methodologies—Windows Autopilot, Windows Virtual Desktop, and Windows 365—that have fundamentally changed how Windows environments are provisioned and secured. Understanding these mechanisms is not optional for anyone responsible for securing a modern Windows environment.

  • End of Support
  • Servicing Channels
  • Windows Update
  • Windows Server Update Services
  • Windows Autopilot
  • Windows Virtual Desktop
  • Windows 365

Module: Windows Access Controls

Access controls are only effective when they are correctly understood, correctly configured, and correctly maintained—and in Windows environments, misconfigured permissions in NTFS, Shared Folders, and Active Directory lead to exploitable conditions. This module establishes how permissions and privileges function: what they protect, how they interact, and where they fail when implementation doesn't match intent. BitLocker extends the access control discussion into encryption. When pairing a system with a Trusted Platform Module, the system protects the boot process itself, ensuring that critical operating system executables have not been tampered with.

NTFS Permissions

  • Shared Folder Permissions
  • Active Directory
  • Permissions
  • Privileges
  • BitLocker Drive Encryption
  • Personal Data Encryption (PDE)
  • Hardware-based security (Microsoft Pluton)

Module: Enforcing Security Configurations

Enforcing security configurations consistently across a Windows environment requires tools that can automate what manual administration cannot scale to address. This module covers SecEdit.exe—the command-line implementation of Microsoft's Security Configuration and Analysis tool—including the password and auditing policy changes it enables. Group Policy Objects are examined as the mechanism for enforcing security configuration changes at domain scale, ensuring that controls applied in one place are applied consistently everywhere they need to be.

  • Applying Security Templates
  • Employing the Security Configuration and Analysis Snap-in
  • Understanding Local Group Policy Objects
  • Understanding Domain Group Policy Objects
  • Administrative Users
  • Privileged Account Management
  • Reduction of Administrative Privileges
  • AppLocker
  • User Account Control
  • Windows Firewall
  • IPsec Authentication and Encryption
  • Remote Desktop Services
  • Recommended GPO Settings

Module: Microsoft Cloud Computing

Microsoft's cloud platform—Azure—need not be considered a separate environment from the Windows infrastructure most organizations already manage. Windows 11 is designed for Azure integration, which means Windows security now extends beyond the local environment into the cloud by default. What makes this module particularly important is not just what Azure introduces—it is what Azure changes. Many of the security concepts familiar from on-premises Windows environments have direct Azure equivalents, but those equivalents behave differently, are configured differently, and carry different security implications.

  • Microsoft’s All-In Bet on Cloud Computing
  • Microsoft Cloud Types: IaaS, PaaS, SaaS, and DaaS
  • Microsoft Azure
  • Entra ID (Azure Active Directory)
  • Entra ID Single Sign-On
  • Multi-Factor Authentication
  • Administrative Role Reduction
  • Endpoint Security Enforcement
  • Microsoft Intune
  • Azure Conditional Access
  • Azure Monitor
  • Azure Sentinel (SIEM and SOAR)
  • Azure Policy
  • Azure Security Center

Module: Automation, Logging, and Auditing

Automation, logging, and auditing are grouped together in this module for a specific reason: without automation, auditing doesn't happen consistently—and without consistent auditing, security at scale is not achievable. Manual processes work on a small number of machines. They do not work across an enterprise. PowerShell is the mechanism that changes that equation. This module covers PowerShell as a security tool—not just for administrative efficiency, but for deployment consistency, detection of change, system remediation, and threat hunting.

  • What Is Windows PowerShell?
  • Windows PowerShell versus PowerShell Core
  • Windows Subsystem for Linux (WSL)
  • Automation and Command-Line Capability in Azure (PowerShell Az Module and Azure CLI)
  • Azure Cloud Shell

Section 6Containers, Linux, and Mac Security

The final section of SEC401 addresses the operating systems and deployment models that complete our discussion of the modern enterprise environment — Linux, containers, and macOS. Each presents its own security model, its own strengths, and its own commonly misunderstood limitations.

Topics covered

  • Linux Fundamentals
  • Containerized Security
  • Linux Security Enhancements and Infrastructure
  • macOS Security

Labs

  • Linux Permissions
  • Linux Containers
  • Linux Logging and Auditing

Overview

Linux systems are often fewer in number than Windows systems in a given environment—but they are frequently the most critical. Database servers, web servers, and cloud infrastructure components disproportionately run on Linux, which means the consequences of a Linux compromise are disproportionately severe. This section addresses Linux security practically and deliberately: foundational concepts for those newer to the platform, and advanced security guidance for administrators who manage it daily. Both audiences will find content that challenges what they think they already know.

Containers enter the discussion here because Linux is where they were born. Built on the principle of minimization—running only what is necessary and nothing more—containers offer deployment flexibility that has made them central to modern cloud computing. That same minimization principle aligns naturally with defense-in-depth, but containers introduce their own security considerations that are frequently overlooked in organizations that adopt them primarily for operational convenience. This module examines what containers represent for information security, what they do not, and how to manage them with the security discipline their criticality demands.

macOS closes the section—and the course—for a specific reason. Apple's operating system carries a reputation for security that is partly deserved and partly myth. Built on a UNIX foundation, macOS includes robust hardware and software security features that are genuinely significant. It also has limitations that are genuinely significant. This module separates the reality from the reputation, giving security professionals an accurate basis for the decisions they make about macOS in their environments.

Full Lab Details

  • Linux Permissions
  • Containers and Logging Concepts
  • Linux Logging and Auditing Capabilities

Full Topic Details

Module: Linux Fundamentals

Securing a Linux system requires understanding how it is built before addressing how it is hardened. This module establishes the foundational knowledge necessary for both: how Linux is structured as an operating system, how it manages users, permissions, filesystems, and services, and where its intrinsic security capabilities begin and where they require deliberate configuration to be effective. The module addresses both the conceptual grounding that informed Linux security administration depends on.

  • Operating System Comparison
  • Linux Vulnerabilities
  • Linux Operating System
  • Shells
  • Linux Kernel
  • Linux Filesystem and Intrinsic Security Capabilities
  • Permissions
  • User Accounts
  • PAM Subsystem
  • Service Hardening
  • Package Management

Module: Containerized Security

Isolation is a security principle before it is a technology—and this module examines two technologies that implement it differently: virtualization and containers. Containers—while an addition to the information security toolkit—the security benefits they provide are frequently overstated. This module establishes what containers actually are, how they differ from virtual machines, how they are orchestrated and managed at scale, and what securing them requires in practice. The topic list for this module reflects the operational reality of container deployments, and each is addressed with direct attention to its security implications.

  • Virtualization
  • Containers versus VMs
  • Containers and Orchestration
  • LXC
  • Cgroups and Namespaces
  • Docker
  • Docker Images
  • Kubernetes
  • Container Security
  • Docker and Kubernetes Best Practices
  • Vulnerability Management and Secure Configuration Baselines

Module: Linux Security Enhancements and Infrastructure

Linux provides a strong security foundation—but that foundation requires deliberate enhancement to meet the demands of a modern threat environment. This module covers the security utilities and hardening capabilities that extend what Linux provides by default: access control enhancements, kernel-level protections, and configuration hardening across the system. Logging receives dedicated attention here, as it does throughout the course—because detection depends on it. Linux's Syslog standard and its capabilities are examined directly, along with its limitations as logging demands continue to evolve, and the enhancements—including Auditd—that address those limitations, especially from a security logging perspective.

  • Operating System Enhancements
  • SELinux
  • AppArmor
  • Linux Hardening
  • Kernel Module Security
  • SSH Hardening
  • Logging
  • Log Rotation
  • Auditd
  • Firewalls: Network and Endpoint

Module: macOS Security

macOS is built on a UNIX foundation and includes a substantial set of native security features—privacy controls, encryption, application verification, sandboxing, and hardware-level security among them. This module examines those features directly and practically: what each one does, how it is configured, and what it protects against. macOS is a genuinely capable security platform. It is also an operating system with its own vulnerabilities and its own malware—and this module addresses both realities with equal weight.

  • What is macOS?
  • Privacy Controls
  • Keychain
  • Gatekeeper
  • Anti-Phishing and Download Protection
  • XProtect
  • Firewall Capabilities
  • FileVault
  • Sandboxing and Runtime Protection
  • Security Enclaves
  • macOS Vulnerabilities and Malware

Things You Need To Know

Important! Bring your own system configured according to these instructions.

A properly configured system is required to fully participate in this course. If you do not carefully read and follow these instructions, you will not be able to fully participate in hands-on exercises in your course. Therefore, please arrive with a system meeting all of the specified requirements.

Back up your system before class. Better yet, use a system without any sensitive/critical data. SANS is not responsible for your system or data.

Mandatory System Hardware Requirements

  • CPU: 64-bit Intel i5/i7 (8th generation or newer), or AMD equivalent. A x64 bit, 2.0+ GHz or newer processor is mandatory for this class.
  • CRITICAL: Apple Silicon devices cannot perform the necessary virtualization and therefore cannot in any way be used for this course.
  • BIOS settings must be set to enable virtualization technology, such as "Intel-VTx" or "AMD-V" extensions. Be absolutely certain you can access your BIOS if it is password protected, in case changes are necessary.
  • 16GB of RAM or more is required.
  • 100GB of free storage space or more is required.
  • At least one available USB 3.0 Type-A port. A Type-C to Type-A adapter may be necessary for newer laptops. Some endpoint protection software prevents the use of USB devices, so test your system with a USB drive before class.
  • Wireless networking (802.11 standard) is required. There is no wired Internet access in the classroom.

Mandatory Host Configuration and Software Requirements

  • Your host operating system must be the latest version of Windows 10, Windows 11, or macOS 10.15.x or newer (Intel-based Macs only).
  • Linux hosts are not supported in the classroom due to the variability of Linux configurations. If you choose to use Linux as your host, you are solely responsible for configuring it to work with the course materials and virtual machines.
  • Fully update your host operating system prior to class to ensure you have the correct drivers and patches installed.
  • Local Administrator access is required. If your organization will not permit this access for the duration of the course, arrange to bring a different laptop.
  • Ensure that antivirus or endpoint protection software can be disabled or fully removed, and that you have the administrative privileges to do so. These products can prevent successful lab completion.
  • Any filtering of egress traffic may prevent successful lab completion. Firewalls may need to be disabled—ensure you have the administrative privileges to do so.
  • Download and install VMware Workstation Pro 16.2.X+ (for Windows 10 hosts), VMware Workstation Pro 17.0.0+ (for Windows 11 hosts), or VMware Fusion Pro 12.2+ (for Intel-based macOS hosts) prior to class.
  • On Windows hosts, VMware products may not coexist with the Hyper-V hypervisor. For the best experience, ensure VMware can boot a virtual machine before class — this may require disabling Hyper-V. Instructions for disabling Hyper-V, Device Guard, and Credential Guard are included in the setup documentation accompanying your course materials.
  • Download and install 7-Zip (for Windows Hosts) or Keka (for macOS hosts). These tools are also included in your downloaded course materials.

Your course media is delivered via download. The media files for class can be large. Many are in the 40-50GB range, with some over 100GB. You need to allow plenty of time for the download to complete. Internet connections and speed vary greatly and are dependent on many different factors. Therefore, it is not possible to give an estimate of the length of time it will take to download your materials. Please start your course media downloads as soon as you get the link. You will need your course media immediately on the first day of class. Do not wait until the night before class to start downloading these files.

Your course materials include a "Setup Instructions" document that details important steps you must take before you travel to a live class event or start an online class. It may take 30 minutes or more to complete these instructions.

Your class uses an electronic workbook for its lab instructions. In this new environment, a second monitor and/or a tablet device can be useful for keeping class materials visible while you are working on your course's labs.

If you have additional questions about the laptop specifications, please contact customer service.

SEC401 is designed for security professionals at every stage of their career—not because the content is adjusted for different audiences, but because the foundational gaps this course addresses are not exclusive to any single experience level or job title.

You should attend if:

  • You work in information security—as a practitioner, engineer, administrator, or analyst—and want a comprehensive, current understanding of the concepts your daily work depends on.
  • You manage security teams or security budgets and need the technical grounding to make defensible decisions, not just informed ones.
  • You specialize in a specific security discipline—forensics, penetration testing, cloud security, incident response—and recognize that specialization built without foundational grounding has limits.
  • You are newer to information security and want to build the foundation that every subsequent course, certification, and career decision will rest upon.
  • You are an IT professional—engineer, administrator, or supervisor—whose responsibilities increasingly intersect with security and who needs a structured, rigorous path into the discipline.

The GIAC Security Essentials (GSEC) certification validates a practitioner's knowledge of information security beyond simple terminology and concepts. GSEC certification holders are demonstrating that they are qualified for hands-on IT systems roles with respect to security tasks.

  • Defense in depth, access control and password management
  • Cryptography: basic concepts, algorithms and deployment, and application
  • Cloud: AWS and Azure operations
  • Defensible network architecture, networking and protocols, and network security
  • Incident handling and response, data loss prevention, mobile device security, vulnerability scanning and penetration testing
  • Linux: Fundamentals, hardening and securing
  • SIEM, critical controls, and exploit mitigation
  • Web communication security, virtualization and cloud security, and endpoint security
  • Windows: access controls, automation, auditing, forensics, security infrastructure, and services

More Certification Details

  • Coursebooks and lab workbook with over 500 pages of exercises
  • Virtual machines pre-installed with essential tools
  • TCP/IP reference guides
  • MP3 audio files of complete course lectures

The SEC401 course covers all the core areas of security and assumes a basic understanding of technology, networks, and security. For those who are new to the field and have no background knowledge, SEC275: Foundations - Computers, Technology and Security or SEC301: Introduction to Cyber Security would be the recommended starting point. While these courses are not a prerequisite for this course, they do provide the introductory knowledge to help maximize the experience with SEC401 training.

The SEC401 course is a part of the “Core Techniques” Learning Path, which aims to equip security professionals with crucial information, skills, and strategies for protecting, maintaining, and securing systems.

Depending on your current or desired future role, one of these courses is a great next step in your cybersecurity journey:

Cybersecurity Essentials that are addressed in SEC401 training encompass fundamental principles and skills needed to secure networks, endpoints, and cloud environments against modern cyber threats. Key aspects covered in the course include:

  • Defensible Network Architecture: Understanding network security helps you design resilient systems capable of identifying and thwarting network-based attacks, which is crucial for protecting critical data.
  • Layered Security or Defense in Depth: This concept applies multiple layers of security controls to mitigate risks, especially focusing on Identity and Access Management (IAM) to control and protect user access.
  • Vulnerability Management: Essential to maintaining cybersecurity, it involves identifying, assessing, and mitigating vulnerabilities across all networked systems, thus reducing the likelihood of exploitation by threat actors.
  • Cloud Security and Virtualization: SEC401 training emphasizes understanding cloud computing risks and defending cloud-based assets, which is vital as more organizations shift to cloud environments.

These cybersecurity essentials are critical because they establish a strong foundation to prevent, detect, and respond to cyber threats effectively. Without these foundational elements, advanced security measures can be undermined, leading to potential breaches that exploit fundamental security gaps.

A career in cybersecurity is built in layers—and the strength of every layer above depends on the integrity of the foundation below. SEC401 is that foundation. Here is what that means practically:

  • Breadth that makes specialization more effective: SEC401 covers more than 30 information security topic areas—not to make you a generalist, but to ensure that whatever you specialize in, you understand the broader context it operates within. That contextual understanding is what separates practitioners who can solve the problem in front of them from those who can anticipate the one around the corner.
  • Skills you can use immediately: The hands-on labs in SEC401 follow a set of real-world compromise scenarios across a fictitious global organization. Web application attacks, phishing, insider threats, cloud compromises — you will work through all of them. The SANS promise applies here directly: what you learn will be applicable when you return to work.
  • Relevance at every experience level: SEC401 is not an entry-level course that experienced professionals outgrow. The foundational gaps this course addresses exist at every career stage—in specialists who built expertise without first building foundations, in managers who make security decisions without sufficient technical grounding, and in practitioners who learned by doing without ever learning why.
  • A credential that signals foundational competence: SEC401 prepares you for the GIAC Security Essentials (GSEC) certification—a globally recognized credential that validates broad, foundational security knowledge. For employers, GSEC signals that a practitioner's knowledge has been tested, not assumed.
  • Modern content in a foundational framework: Cloud security, AI, current adversarial tactics, and even topics such as post-quantum cryptography are woven throughout—because the foundation this course builds is the current one, not the one that existed a decade ago.

Relevant Job Roles

Data Analysis (OPM 422)

NICE: Implementation and Operation

Responsible for analyzing data from multiple disparate sources to provide cybersecurity and privacy insight. Designs and implements custom algorithms, workflow processes, and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes.

Explore learning path

Systems Security Analyst (DCWF 461)

DoD 8140: Software Engineering

Ensures systems and software security from development to maintenance by analyzing and improving security across all lifecycle phases.

Explore learning path

Database Administrator (DCWF 421)

DoD 8140: Cyber IT

Manages and maintains databases or data systems for efficient storage, querying, and access to organizational data assets and records.

Explore learning path

Cyber Instructional Curriculum Developer (DCWF 711)

DoD 8140: Cyber Enablers

Develops and evaluates cyber training content and methods to ensure relevance, effectiveness, and alignment with organizational needs.

Explore learning path

Technical Support Specialist (DCWF 411)

DoD 8140: Cyber IT

Delivers technical support to users, helping them resolve issues with client hardware/software according to organizational service processes.

Explore learning path

Systems Administration (OPM 451)

NICE: Implementation and Operation

Responsible for setting up and maintaining a system or specific components of a system in adherence with organizational security policies and procedures. Includes hardware and software installation, configuration, and updates; user account management; backup and recovery management; and security control implementation.

Explore learning path

Systems Developer (DCWF 632)

DoD 8140: Cyber IT

Oversees full lifecycle of information systems from design through evaluation, ensuring alignment with functional and operational goals.

Explore learning path

Technology Portfolio Management (OPM 804)

NICE: Oversight and Governance

Responsible for managing a portfolio of technology investments that align with the overall needs of mission and enterprise priorities.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
Showing 10 of 33

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources