Skip to content
Artwork for Certified: The CompTIA Security+ V8 / SY0-801 Audio Course
TechnologyEducationCourses

Certified: The CompTIA Security+ V8 / SY0-801 Audio Course

Jason Edwards

Certified: The CompTIA Security+ V8 / SY0-801 Audio Course is built for learners who want a clear, practical path into modern cybersecurity fundamentals without being tied to a desk. It is designed for entry-level security professionals, IT support staff, help desk technicians, junior system administrators, career changers, and anyone preparing for the Security+ exam. The course assumes you may already understand basic networking and computer systems, but it does not assume deep security experience. Each lesson explains the ideas behind the exam objectives in plain language, then connects them to the kinds of decisions security teams make every day.

You will learn the core areas expected of a Security+ candidate, including threats, vulnerabilities, secure architecture, identity and access management, cryptography, risk, governance, incident response, cloud security, endpoint protection, and operational security practices. The course is taught as an audio-first learning experience, which means each episode is written to be understood while driving, walking, exercising, or reviewing between work and family responsibilities. Instead of reading slides aloud, the lessons explain concepts in a natural sequence, using examples, comparisons, and practical framing so the material is easier to remember.

What makes this course different is its focus on clarity, pacing, and usefulness. The goal is not to overwhelm you with terminology, but to help you build a working understanding of why each topic matters and how it may appear in an exam or real security role. Success means you can explain key concepts, recognize common security scenarios, connect tools to outcomes, and approach practice questions with stronger judgment. By the end, you should feel more prepared, more confident, and better able to continue your Security+ study with purpose.

Play
  • 20 episodes
  • Avg 13 min
  • English
  • April 27 · 1 min

    Welcome to the CompTIA Security+ Audio Course!

    Certified: The CompTIA Security+ V8 / SY0-801 Audio Course is built for learners who want a clear, practical path into modern cybersecurity fundamentals without being tied to a desk. It is designed for entry-level security professionals, IT support staff, help desk technicians, junior system administrators, career changers, and anyone preparing for the Security+ exam. The course assumes you may already understand basic networking and computer systems, but it does not assume deep security experience. Each lesson explains the ideas behind the exam objectives in plain language, then connects them to the kinds of decisions security teams make every day. You will learn the core areas expected of a Security+ candidate, including threats, vulnerabilities, secure architecture, identity and access management, cryptography, risk, governance, incident response, cloud security, endpoint protection, and operational security practices. The course is taught as an audio-first learning experience, which means each episode is written to be understood while driving, walking, exercising, or reviewing between work and family responsibilities. Instead of reading slides aloud, the lessons explain concepts in a natural sequence, using examples, comparisons, and practical framing so the material is easier to remember. What makes this course different is its focus on clarity, pacing, and usefulness. The goal is not to overwhelm you with terminology, but to help you build a working understanding of why each topic matters and how it may appear in an exam or real security role. Success means you can explain key concepts, recognize common security scenarios, connect tools to outcomes, and approach practice questions with stronger judgment. By the end, you should feel more prepared, more confident, and better able to continue your Security+ study with purpose.

    • Transcript
  • #118
    April 27 · 14 min

    Episode 118 — Final Objectives Update: What Changed When CompTIA Finalized SY0-801 (Update)

    This episode is reserved for final updates after CompTIA finalizes the SY0-801 exam objectives. Its purpose is to identify what changed from the draft objectives, including added topics, removed topics, renamed terms, reorganized objectives, weight changes, or clarified wording that affects study priorities. Students should use this episode as a fast alignment check so earlier preparation remains current and exam-focused. For real study planning, the key is to compare the finalized objectives against the course structure, revisit any changed areas, and avoid overstudying draft-only material that no longer appears in the final outline. This update helps students protect their time and keep their preparation aligned with the actual exam blueprint. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #117
    April 27 · 16 min

    Episode 117 — Full-Course Review: The SY0-801 Memory Map (Review)

    This episode provides a guided review of the major relationships students should remember across the SY0-801 course. The five-domain structure can be understood as a connected security model: threats and vulnerabilities create risk, risk drives control selection, controls support secure architecture, operations generate evidence, and governance guides repeatable decisions. Students should review core models such as CIA, AAA, defense in depth, Zero Trust, risk treatment, identity lifecycle, incident response, data protection, resilience, and third-party oversight. For the exam, the goal is to see how topics connect rather than treating each objective as a separate vocabulary list. Strong performance comes from recognizing the situation, choosing the right principle, and applying the correct control or process. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #116
    April 27 · 15 min

    Episode 116 — PBQ Strategy: Turning Objectives into Scenario Decisions (Review)

    This episode teaches students how to approach performance-based questions by turning exam objectives into practical scenario decisions. A strong PBQ approach starts by identifying the task, the environment, the security goal, and the evidence provided. Students should look for clues such as system type, data sensitivity, user role, log entries, network placement, access requirement, or incident stage before choosing controls or actions. Examples may involve IAM decisions, incident response ordering, firewall rule selection, cloud misconfiguration, log interpretation, data protection, or vulnerability prioritization. For Security+ preparation, the focus is not memorizing isolated facts but applying concepts in context, eliminating unsafe choices, and selecting the most appropriate response for the stated goal. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #115
    April 27 · 14 min

    Episode 115 — Awareness Delivery and Effectiveness: LMS, Self-Service, Metrics, Behavior Risk Scoring, BEC, BYOD, and Remote Work (5.6)

    This episode covers how security awareness is delivered, measured, and improved over time. Students should understand learning management systems, self-service training, one-to-one instruction, and one-to-many instruction as different ways to reach users based on scale, role, and need. Effectiveness metrics may include completion rates, phishing simulation results, reporting rates, repeat failures, policy acknowledgements, and behavior risk scoring. Training topics may include social engineering, business email compromise, removable media, bring your own device rules, remote work, and operational security. For Security+ scenarios, the goal is to connect training delivery and measurement to risk reduction, management reporting, and improved user behavior in realistic work environments. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #114
    April 27 · 13 min

    Episode 114 — Security Awareness Training: Onboarding, Ongoing, Targeted, and Corrective Training (5.6)

    This episode explains security awareness as an ongoing program rather than a one-time compliance activity. Students should understand onboarding training as the first introduction to organizational expectations, acceptable use, data handling, reporting procedures, and common threats. Ongoing training reinforces important behaviors over time, while targeted training focuses on specific roles, risks, departments, or emerging threats. Corrective training is used when behavior shows a gap, such as repeated phishing failures, improper data handling, unsafe remote work habits, or policy violations. For Security+ scenarios, awareness training should be matched to the risk and audience, with the goal of improving real behavior rather than simply completing a checkbox requirement. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #113
    April 27 · 14 min

    Episode 113 — Penetration Testing, Reconnaissance, Frameworks, Functional Testing, and Behavioral Testing (5.5)

    This episode explains penetration testing and related assessment methods at a Security+ level. Students should understand the difference between known, unknown, and partially known environments, where testers may have full information, no internal knowledge, or limited details before testing begins. Reconnaissance may be active, involving direct interaction with targets, or passive, relying on publicly available information and indirect observation. Physical, offensive, defensive, and integrated testing can evaluate different parts of the organization’s security posture. Frameworks and standards help structure testing so results are repeatable and understandable. Functional testing checks whether controls work as designed, while behavioral testing examines how people or systems respond under realistic conditions. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #112
    April 27 · 14 min

    Episode 112 — Audit Scope and Engagements: Charters, Gap Analysis, Internal Reviews, External Reviews, and Benchmarking (5.5)

    This episode covers audit scope and engagement planning, including charters, frequency, boundaries, gap analysis, internal reviews, external reviews, regulatory assessments, and benchmarking. Students should understand that an audit charter defines authority, purpose, responsibilities, and scope so the review is properly controlled and understood. Gap analysis compares the current state to a required or desired state, such as a standard, policy, framework, or regulatory expectation. Internal reviews may support self-improvement, while external reviews and regulatory assessments provide independent or required evaluation. Benchmarking compares performance or controls against a known reference. For Security+ scenarios, the key is knowing what is being assessed, why it is being assessed, and what evidence is needed. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #111
    April 27 · 13 min

    Episode 111 — Audit Data Gathering: Sampling, Questionnaires, Interviews, Assertions, and Reference Sources (5.5)

    This episode explains how audits and assessments gather evidence to determine whether controls, processes, and security requirements are working as expected. Students should understand sampling as reviewing a representative portion of records or systems rather than every item, while questionnaires and interviews help collect information from control owners, administrators, users, and stakeholders. Assertions are claims about control design, operation, or compliance that must be supported by evidence. Reference sources such as MITRE ATT&CK, the Cyber Kill Chain, and the Diamond Model help organize attacker behavior, incident analysis, and assessment context. For Security+ scenarios, the focus is on gathering reliable evidence, validating claims, and using structured sources to support defensible conclusions. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #110
    April 27 · 15 min

    Episode 110 — Non-Compliance, Privacy Rights, Legal Holds, Legal Orders, and Retention (5.4)

    This episode covers the consequences of non-compliance and the legal and privacy concepts that shape data handling decisions. Students should understand that non-compliance can lead to reputational damage, financial penalties, legal action, contract violations, license loss, operational disruption, and loss of customer trust. Privacy rights may include opt-in and opt-out choices, access to personal data, correction of inaccurate data, processing restrictions, and deletion requests where applicable. Controller and processor roles affect who determines the purpose of processing and who acts on instructions. Legal holds preserve relevant information when litigation or investigation is expected, while legal orders may require action or disclosure. For Security+ scenarios, retention requirements must be balanced against disposal, privacy, ownership, and evidence preservation duties. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #109
    April 27 · 14 min

    Episode 109 — Compliance Training and Monitoring: Data Handling, AML/CTF, Anti-Bribery, and Attestations (5.4)

    This episode explains compliance as the need to meet laws, regulations, contracts, internal policies, and industry standards. Students should understand that compliance training helps employees know what is required for data handling, privacy, reporting, acceptable behavior, and regulated business activity. Anti-money laundering and counter-terrorist financing controls focus on detecting and preventing misuse of financial systems, while anti-bribery requirements address improper payments, gifts, influence, and conflicts. Monitoring helps verify that required controls are followed, and attestations or acknowledgements create evidence that users, vendors, or employees have received, understood, or accepted obligations. For Security+ scenarios, compliance is not just paperwork; it is a control system that supports accountability and reduces legal, financial, and reputational risk. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #108
    April 27 · 13 min

    Episode 108 — Vendor Constraints and Rules of Engagement: Jurisdiction, ROI, Lock-In, and Assurance Mechanisms (5.3)

    This episode explains vendor constraints and assurance mechanisms that affect third-party risk decisions. Students should understand that staffing, resources, geography, jurisdiction, return on investment, and vendor lock-in can influence whether a third-party relationship is practical, secure, and sustainable. Jurisdiction matters because laws, privacy requirements, and legal remedies may differ across locations. Vendor lock-in can make it difficult or expensive to leave a provider, especially when data, integrations, or proprietary services are involved. Assurance mechanisms such as vendor assessments, compliance attestations, audit reports, penetration testing, and rules of engagement help define and verify expectations. For Security+ scenarios, students should evaluate both the benefits of outsourcing and the risks created by dependency, access, and limited visibility. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #107
    April 27 · 14 min

    Episode 107 — Agreements and Monitoring: SLA, SLO, MOU, MOA, NDA, MSA, SOW, and Right to Audit (5.3)

    This episode covers common third-party agreements and monitoring terms that define expectations between organizations. Service-level agreements establish required service commitments, while service-level objectives define measurable targets that support those commitments. Memorandums of understanding and memorandums of agreement document shared expectations, responsibilities, or cooperation. Nondisclosure agreements protect confidential information, master service agreements define broad legal and business terms, and statements of work describe specific tasks, deliverables, timelines, and responsibilities. Right-to-audit clauses allow an organization to verify whether a provider is meeting required obligations. For Security+ scenarios, students should match each agreement to the type of risk, service relationship, confidentiality need, or oversight requirement being tested. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #106
    April 27 · 13 min

    Episode 106 — Third-Party Risk: Vendor Selection, RFP, RFI, RFQ, EOI, Due Diligence, and Conflicts (5.3)

    This episode explains third-party risk and why vendors, partners, suppliers, service providers, and contractors can extend an organization’s attack surface and compliance obligations. Students should understand vendor selection as a security-relevant process that evaluates capability, reliability, controls, cost, and fit. Requests for information gather general details, requests for proposal ask vendors to explain how they would meet a need, requests for quote focus on pricing, and expressions of interest help identify potential participants. Due diligence reviews security posture, financial stability, compliance history, and operational risk before relying on a third party. For Security+ scenarios, students should also consider conflicts of interest that could weaken trust, fairness, or objectivity. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #105
    April 27 · 13 min

    Episode 105 — Risk Treatment and Business Impact: Transfer, Accept, Avoid, Mitigate, BIA, Appetite, Residual Risk, SLE, ALE, and ARO (5.2)

    This episode covers risk treatment and business impact concepts that help organizations decide what to do after a risk is assessed. Students should understand that risk can be transferred through insurance or contracts, accepted when leadership chooses to live with it, avoided by stopping the risky activity, or mitigated by applying controls. A business impact analysis identifies critical processes, dependencies, and consequences of disruption. Risk appetite defines how much risk leadership is willing to tolerate, while residual risk remains after controls are applied. Single loss expectancy, annualized rate of occurrence, and annualized loss expectancy help estimate financial risk. For Security+ scenarios, these concepts connect security decisions to business impact and management oversight. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #104
    April 27 · 13 min

    Episode 104 — Risk Analysis and Registers: Impact, Likelihood, Owners, Current Mitigations, and Qualitative vs. Quantitative Risk (5.2)

    This episode explains risk analysis and the role of the risk register in tracking organizational risk. Students should understand impact as the amount of harm a risk could cause and likelihood as the chance that the risk may occur. Risk owners are responsible for tracking, reporting, and supporting treatment decisions, while current mitigations show what controls already reduce exposure. A risk register records details such as description, category, owner, likelihood, impact, status, treatment plan, and residual risk. Qualitative analysis uses categories such as low, medium, and high, while quantitative analysis uses numeric values to estimate loss or probability. For the exam, students should know how these methods support clear risk communication. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #103
    April 27 · 13 min

    Episode 103 — Risk Identification and Assessment: Assets, Stakeholders, Scoring, and Categorization (5.2)

    This episode introduces risk identification and assessment as the process of finding what could go wrong, what assets could be affected, and who needs to be involved in the decision. Students should understand that assets may include systems, data, facilities, services, people, vendors, applications, and business processes. Stakeholders help define business value, ownership, acceptable impact, and operational constraints. Risk scoring and categorization help organize risks so leaders can compare them and choose priorities. For Security+ scenarios, students should connect assessment to decision-making, such as whether to remediate, accept, transfer, avoid, or mitigate a risk based on likelihood, impact, asset value, and business context. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #102
    April 27 · 14 min

    Episode 102 — Plans and Policies: BCP, DRP, BYOD, AUP, Clean Desk, Incident Response, Data Retention, Access Control, and Privacy (5.1)

    This episode covers major security plans and policies students are expected to recognize for the Security+ exam. Business continuity plans focus on keeping essential functions operating, while disaster recovery plans focus on restoring systems and data after disruption. BYOD policies define rules for personally owned devices, acceptable use policies explain proper technology behavior, and clean desk policies reduce exposure of sensitive information in physical work areas. Incident response, data classification, retention, access control, disposal, vulnerability disclosure, and privacy policies all define expectations before problems occur. For exam scenarios, students should match the policy or plan to the business need, legal requirement, or operational risk being addressed. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #101
    April 27 · 14 min

    Episode 101 — Standards and Procedures: Baselines, Passwords, Physical Security, RFCs, Encryption, SOPs, and Runbooks (5.1)

    This episode explains how standards and procedures turn broad security policy into repeatable action. Students should understand that baselines define approved configuration settings, password standards establish expectations for authentication strength, physical security standards guide facility and equipment protection, and encryption standards define approved methods for protecting data. RFCs can document technical protocol behavior, while standard operating procedures explain how tasks should be performed consistently. Runbooks provide step-by-step operational guidance for routine actions or incident response activities. For Security+ scenarios, these documents reduce confusion, support audits, improve consistency, and help teams prove that security practices are defined rather than improvised. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
  • #100
    April 27 · 14 min

    Episode 100 — GRC Artifacts: Guidelines, Benchmarks, Advisories, Implementation Guides, and Reference Architectures (5.1)

    This episode introduces governance, risk, and compliance artifacts that help organizations build consistent security programs. Guidelines provide recommended practices, benchmarks define measurable configuration expectations, advisories warn about risks or required action, implementation guides explain how to apply controls, and reference architectures show approved patterns for secure design. For Security+ scenarios, students should understand that these artifacts translate security goals into repeatable decisions across systems, teams, and environments. They also support audits, risk assessments, control selection, secure architecture, and operational consistency. The practical lesson is that security programs depend on documented guidance so teams are not inventing different approaches every time they configure, deploy, assess, or troubleshoot a system. Produced by BareMetalCyber.com, where you’ll find more cyber audio courses, books, and information to strengthen your educational path. Also, if you want to stay up to date with the latest news, visit DailyCyber.News for a newsletter you can use, and a daily podcast you can commute with. And dont forget Cyberauthor.me for the companion study guide and flash cards!

    • Transcript
Showing 1–20 of 20 episodes