Skip to content
Artwork for Certified: The CompTIA Security+ Audio Course
TechnologyEducationCourses

Certified: The CompTIA Security+ Audio Course

Dr. Jason Edwards

Certified - Security+ is your completely free audio companion for mastering the CompTIA Security+ certification exam. Developed by BareMetalCyber.com, this immersive Audio Course transforms every domain of the official exam objectives into clear, practical, and exam-ready lessons you can learn anywhere—whether commuting, exercising, or studying at home. Each episode delivers focused explanations, real-world examples, and proven study strategies designed to build confidence and help you pass on your first attempt. Structured for busy professionals and new learners alike, the series provides a complete, flexible way to prepare for certification success without relying on slides or handouts.

The CompTIA Security+ certification is the global benchmark for validating essential cybersecurity knowledge and hands-on skills. It covers critical areas including threat identification, risk management, network security, identity and access control, incident response, and cryptography. Designed to meet the latest industry and Department of Defense (DoD) requirements, Security+ ensures you can assess environments, implement controls, and secure systems in real-world settings. It serves as the perfect foundation for cybersecurity careers and advanced credentials like CySA+, CASP+, and C I S S P. Recognized by employers worldwide, Security+ demonstrates your readiness to protect data, defend networks, and operate confidently in modern cyber defense roles.

For a deeper study experience, pair this Audio Course with the companion textbook Achieve CompTIA Security+ SY0-701 Exam Success—the concise and complete guide designed for busy professionals preparing to earn their certification. Together, they form a powerful toolkit to help you understand, retain, and apply cybersecurity principles from day one through exam day.

Play
  • 20 episodes
  • Avg 14 min
  • English
  • S2 · E118
    July 15 · 14 min

    Final Objectives Update: What Changed When CompTIA Finalized SY0-801 (Update)

    This episode is reserved for final updates after CompTIA finalizes the SY0-801 exam objectives. Its purpose is to identify what changed from the draft objectives, including added topics, removed topics, renamed terms, reorganized objectives, weight changes, or clarified wording that affects study priorities. Students should use this episode as a fast alignment check so earlier preparation remains current and exam-focused. For real study planning, the key is to compare the finalized objectives against the course structure, revisit any changed areas, and avoid overstudying draft-only material that no longer appears in the final outline. This update helps students protect their time and keep their preparation aligned with the actual exam blueprint. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E117
    July 15 · 16 min

    Full-Course Review: The SY0-801 Memory Map (Review)

    This episode provides a guided review of the major relationships students should remember across the SY0-801 course. The five-domain structure can be understood as a connected security model: threats and vulnerabilities create risk, risk drives control selection, controls support secure architecture, operations generate evidence, and governance guides repeatable decisions. Students should review core models such as CIA, AAA, defense in depth, Zero Trust, risk treatment, identity lifecycle, incident response, data protection, resilience, and third-party oversight. For the exam, the goal is to see how topics connect rather than treating each objective as a separate vocabulary list. Strong performance comes from recognizing the situation, choosing the right principle, and applying the correct control or process. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E116
    July 15 · 15 min

    PBQ Strategy: Turning Objectives into Scenario Decisions (Review)

    This episode teaches students how to approach performance-based questions by turning exam objectives into practical scenario decisions. A strong PBQ approach starts by identifying the task, the environment, the security goal, and the evidence provided. Students should look for clues such as system type, data sensitivity, user role, log entries, network placement, access requirement, or incident stage before choosing controls or actions. Examples may involve IAM decisions, incident response ordering, firewall rule selection, cloud misconfiguration, log interpretation, data protection, or vulnerability prioritization. For Security+ preparation, the focus is not memorizing isolated facts but applying concepts in context, eliminating unsafe choices, and selecting the most appropriate response for the stated goal. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E115
    July 15 · 14 min

    Awareness Delivery and Effectiveness: LMS, Self-Service, Metrics, Behavior Risk Scoring, BEC, BYOD, and Remote Work (5.6)

    This episode covers how security awareness is delivered, measured, and improved over time. Students should understand learning management systems, self-service training, one-to-one instruction, and one-to-many instruction as different ways to reach users based on scale, role, and need. Effectiveness metrics may include completion rates, phishing simulation results, reporting rates, repeat failures, policy acknowledgements, and behavior risk scoring. Training topics may include social engineering, business email compromise, removable media, bring your own device rules, remote work, and operational security. For Security+ scenarios, the goal is to connect training delivery and measurement to risk reduction, management reporting, and improved user behavior in realistic work environments. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E114
    July 15 · 13 min

    Security Awareness Training: Onboarding, Ongoing, Targeted, and Corrective Training (5.6)

    This episode explains security awareness as an ongoing program rather than a one-time compliance activity. Students should understand onboarding training as the first introduction to organizational expectations, acceptable use, data handling, reporting procedures, and common threats. Ongoing training reinforces important behaviors over time, while targeted training focuses on specific roles, risks, departments, or emerging threats. Corrective training is used when behavior shows a gap, such as repeated phishing failures, improper data handling, unsafe remote work habits, or policy violations. For Security+ scenarios, awareness training should be matched to the risk and audience, with the goal of improving real behavior rather than simply completing a checkbox requirement. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E113
    July 15 · 14 min

    Penetration Testing, Reconnaissance, Frameworks, Functional Testing, and Behavioral Testing (5.5)

    This episode explains penetration testing and related assessment methods at a Security+ level. Students should understand the difference between known, unknown, and partially known environments, where testers may have full information, no internal knowledge, or limited details before testing begins. Reconnaissance may be active, involving direct interaction with targets, or passive, relying on publicly available information and indirect observation. Physical, offensive, defensive, and integrated testing can evaluate different parts of the organization’s security posture. Frameworks and standards help structure testing so results are repeatable and understandable. Functional testing checks whether controls work as designed, while behavioral testing examines how people or systems respond under realistic conditions. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E112
    July 15 · 14 min

    Audit Scope and Engagements: Charters, Gap Analysis, Internal Reviews, External Reviews, and Benchmarking (5.5)

    This episode covers audit scope and engagement planning, including charters, frequency, boundaries, gap analysis, internal reviews, external reviews, regulatory assessments, and benchmarking. Students should understand that an audit charter defines authority, purpose, responsibilities, and scope so the review is properly controlled and understood. Gap analysis compares the current state to a required or desired state, such as a standard, policy, framework, or regulatory expectation. Internal reviews may support self-improvement, while external reviews and regulatory assessments provide independent or required evaluation. Benchmarking compares performance or controls against a known reference. For Security+ scenarios, the key is knowing what is being assessed, why it is being assessed, and what evidence is needed. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E111
    July 15 · 13 min

    Audit Data Gathering: Sampling, Questionnaires, Interviews, Assertions, and Reference Sources (5.5)

    This episode explains how audits and assessments gather evidence to determine whether controls, processes, and security requirements are working as expected. Students should understand sampling as reviewing a representative portion of records or systems rather than every item, while questionnaires and interviews help collect information from control owners, administrators, users, and stakeholders. Assertions are claims about control design, operation, or compliance that must be supported by evidence. Reference sources such as MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model help organize attacker behavior, incident analysis, and assessment context. For Security+ scenarios, the focus is on gathering reliable evidence, validating claims, and using structured sources to support defensible conclusions. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E110
    July 15 · 15 min

    Non-Compliance, Privacy Rights, Legal Holds, Legal Orders, and Retention (5.4)

    This episode covers the consequences of non-compliance and the legal and privacy concepts that shape data handling decisions. Students should understand that non-compliance can lead to reputational damage, financial penalties, legal action, contract violations, license loss, operational disruption, and loss of customer trust. Privacy rights may include opt-in and opt-out choices, access to personal data, correction of inaccurate data, processing restrictions, and deletion requests where applicable. Controller and processor roles affect who determines the purpose of processing and who acts on instructions. Legal holds preserve relevant information when litigation or investigation is expected, while legal orders may require action or disclosure. For Security+ scenarios, retention requirements must be balanced against disposal, privacy, ownership, and evidence preservation duties. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E109
    July 15 · 14 min

    Compliance Training and Monitoring: Data Handling, AML/CTF, Anti-Bribery, and Attestations (5.4)

    This episode explains compliance as the need to meet laws, regulations, contracts, internal policies, and industry standards. Students should understand that compliance training helps employees know what is required for data handling, privacy, reporting, acceptable behavior, and regulated business activity. Anti-money laundering and counter-terrorist financing controls focus on detecting and preventing misuse of financial systems, while anti-bribery requirements address improper payments, gifts, influence, and conflicts. Monitoring helps verify that required controls are followed, and attestations or acknowledgements create evidence that users, vendors, or employees have received, understood, or accepted obligations. For Security+ scenarios, compliance is not just paperwork; it is a control system that supports accountability and reduces legal, financial, and reputational risk. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E108
    July 15 · 13 min

    Vendor Constraints and Rules of Engagement: Jurisdiction, ROI, Lock-In, and Assurance Mechanisms (5.3)

    This episode explains vendor constraints and assurance mechanisms that affect third-party risk decisions. Students should understand that staffing, resources, geography, jurisdiction, return on investment, and vendor lock-in can influence whether a third-party relationship is practical, secure, and sustainable. Jurisdiction matters because laws, privacy requirements, and legal remedies may differ across locations. Vendor lock-in can make it difficult or expensive to leave a provider, especially when data, integrations, or proprietary services are involved. Assurance mechanisms such as vendor assessments, compliance attestations, audit reports, penetration testing, and rules of engagement help define and verify expectations. For Security+ scenarios, students should evaluate both the benefits of outsourcing and the risks created by dependency, access, and limited visibility. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E107
    July 15 · 14 min

    Agreements and Monitoring: SLA, SLO, MOU, MOA, NDA, MSA, SOW, and Right to Audit (5.3)

    This episode covers common third-party agreements and monitoring terms that define expectations between organizations. Service-level agreements establish required service commitments, while service-level objectives define measurable targets that support those commitments. Memorandums of understanding and memorandums of agreement document shared expectations, responsibilities, or cooperation. Nondisclosure agreements protect confidential information, master service agreements define broad legal and business terms, and statements of work describe specific tasks, deliverables, timelines, and responsibilities. Right-to-audit clauses allow an organization to verify whether a provider is meeting required obligations. For Security+ scenarios, students should match each agreement to the type of risk, service relationship, confidentiality need, or oversight requirement being tested. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E106
    July 15 · 13 min

    Third-Party Risk: Vendor Selection, RFP, RFI, RFQ, EOI, Due Diligence, and Conflicts (5.3)

    This episode explains third-party risk and why vendors, partners, suppliers, service providers, and contractors can extend an organization’s attack surface and compliance obligations. Students should understand vendor selection as a security-relevant process that evaluates capability, reliability, controls, cost, and fit. Requests for information gather general details, requests for proposal ask vendors to explain how they would meet a need, requests for quote focus on pricing, and expressions of interest help identify potential participants. Due diligence reviews security posture, financial stability, compliance history, and operational risk before relying on a third party. For Security+ scenarios, students should also consider conflicts of interest that could weaken trust, fairness, or objectivity. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E105
    July 15 · 13 min

    Risk Treatment and Business Impact: Transfer, Accept, Avoid, Mitigate, BIA, Appetite, Residual Risk, SLE, ALE, and ARO (5.2)

    This episode covers risk treatment and business impact concepts that help organizations decide what to do after a risk is assessed. Students should understand that risk can be transferred through insurance or contracts, accepted when leadership chooses to live with it, avoided by stopping the risky activity, or mitigated by applying controls. A business impact analysis identifies critical processes, dependencies, and consequences of disruption. Risk appetite defines how much risk leadership is willing to tolerate, while residual risk remains after controls are applied. Single loss expectancy, annualized rate of occurrence, and annualized loss expectancy help estimate financial risk. For Security+ scenarios, these concepts connect security decisions to business impact and management oversight. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E104
    July 15 · 13 min

    Risk Analysis and Registers: Impact, Likelihood, Owners, Current Mitigations, and Qualitative vs. Quantitative Risk (5.2)

    This episode explains risk analysis and the role of the risk register in tracking organizational risk. Students should understand impact as the amount of harm a risk could cause and likelihood as the chance that the risk may occur. Risk owners are responsible for tracking, reporting, and supporting treatment decisions, while current mitigations show what controls already reduce exposure. A risk register records details such as description, category, owner, likelihood, impact, status, treatment plan, and residual risk. Qualitative analysis uses categories such as low, medium, and high, while quantitative analysis uses numeric values to estimate loss or probability. For the exam, students should know how these methods support clear risk communication. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E103
    July 15 · 13 min

    Risk Identification and Assessment: Assets, Stakeholders, Scoring, and Categorization (5.2)

    This episode introduces risk identification and assessment as the process of finding what could go wrong, what assets could be affected, and who needs to be involved in the decision. Students should understand that assets may include systems, data, facilities, services, people, vendors, applications, and business processes. Stakeholders help define business value, ownership, acceptable impact, and operational constraints. Risk scoring and categorization help organize risks so leaders can compare them and choose priorities. For Security+ scenarios, students should connect assessment to decision-making, such as whether to remediate, accept, transfer, avoid, or mitigate a risk based on likelihood, impact, asset value, and business context. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E102
    July 15 · 14 min

    Plans and Policies: BCP, DRP, BYOD, AUP, Clean Desk, Incident Response, Data Retention, Access Control, and Privacy (5.1)

    This episode covers major security plans and policies students are expected to recognize for the Security+ exam. Business continuity plans focus on keeping essential functions operating, while disaster recovery plans focus on restoring systems and data after disruption. BYOD policies define rules for personally owned devices, acceptable use policies explain proper technology behavior, and clean desk policies reduce exposure of sensitive information in physical work areas. Incident response, data classification, retention, access control, disposal, vulnerability disclosure, and privacy policies all define expectations before problems occur. For exam scenarios, students should match the policy or plan to the business need, legal requirement, or operational risk being addressed. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E101
    July 15 · 14 min

    Standards and Procedures: Baselines, Passwords, Physical Security, RFCs, Encryption, SOPs, and Runbooks (5.1)

    This episode explains how standards and procedures turn broad security policy into repeatable action. Students should understand that baselines define approved configuration settings, password standards establish expectations for authentication strength, physical security standards guide facility and equipment protection, and encryption standards define approved methods for protecting data. RFCs can document technical protocol behavior, while standard operating procedures explain how tasks should be performed consistently. Runbooks provide step-by-step operational guidance for routine actions or incident response activities. For Security+ scenarios, these documents reduce confusion, support audits, improve consistency, and help teams prove that security practices are defined rather than improvised. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E100
    July 15 · 14 min

    GRC Artifacts: Guidelines, Benchmarks, Advisories, Implementation Guides, and Reference Architectures (5.1)

    This episode introduces governance, risk, and compliance artifacts that help organizations build consistent security programs. Guidelines provide recommended practices, benchmarks define measurable configuration expectations, advisories warn about risks or required action, implementation guides explain how to apply controls, and reference architectures show approved patterns for secure design. For Security+ scenarios, students should understand that these artifacts translate security goals into repeatable decisions across systems, teams, and environments. They also support audits, risk assessments, control selection, secure architecture, and operational consistency. The practical lesson is that security programs depend on documented guidance so teams are not inventing different approaches every time they configure, deploy, assess, or troubleshoot a system. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • S2 · E99
    July 15 · 14 min

    Evidence and Stakeholders: File Integrity, Memory Dumps, Bit Copies, Snapshots, HR, Legal, and Log Parsing (4.8)

    This episode explains evidence handling and stakeholder involvement during security investigations. File integrity checks help confirm whether files were changed, while log integrity helps determine whether records can be trusted. Memory dumps may capture volatile evidence such as running processes, active connections, encryption keys, or malware artifacts. Bit-level copies preserve storage for forensic analysis, and snapshots can capture system state for investigation or recovery. Log parsing helps analysts extract useful patterns from large volumes of records. Students should also understand why HR, legal, accounting, compliance, and leadership may become involved when incidents affect employees, contracts, finances, privacy, or reporting duties. For the exam, evidence must be collected, preserved, analyzed, and communicated carefully. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
Showing 1–20 of 20 episodes