🖥️ Hands-on Lab Exercises — 12 Labs
Lab 01
General Concepts
Implementing Network Security Controls
Explore the full taxonomy of security controls — from management and operational to technical and physical — and apply them to realistic enterprise scenarios.
Learning Objectives
- Distinguish among Managerial, Operational, Technical, and Physical security control categories.
- Classify security controls by functional type: Preventive, Detective, Corrective, Deterrent, Directive, and Compensating.
- Apply the control category and functional-type frameworks to real-world security scenarios.
Lab 02
General Concepts
Basic Encryption
Put cryptographic theory into practice — work with symmetric and asymmetric algorithms, generate MD5 hashes, and match encryption methods to real-world use cases.
Learning Objectives
- Demonstrate the use of symmetric and asymmetric encryption, identifying the correct algorithm for a given security scenario.
- Generate an MD5 cryptographic hash using a hashing calculator.
Lab 03
Threats & Vulns
Social Engineering Tactics
Step into the attacker's mindset — demonstrate social engineering techniques, identify malware families by behavior, and measure password strength under realistic conditions.
Learning Objectives
- Demonstrate the use of social engineering tactics.
- Identify common malware families by their behavior, propagation method, and primary objective.
- Measure and compare the strength of a complex password.
Lab 04
Threats & Vulns
Vulnerability Identification
Use real commands to surface vulnerabilities across OS, application, mobile, cloud, and web platforms — then prioritize remediation using CVSS scores, business impact, and exploitability.
Learning Objectives
- Use common commands to identify vulnerabilities across operating systems, applications, mobile platforms, cloud environments, and web applications.
- Explain how misconfigurations create exploitable vulnerabilities and describe the conditions that allow exploits to succeed.
- Distinguish among patching, hardening, segmentation, isolation, and access control as mitigation strategies, matching each to the vulnerability types it best addresses.
- Justify remediation prioritization decisions using CVSS severity, business impact, and exploitability factors.
Lab 05
Architecture
Secure Operational Technologies Architecture
Examine virtualization, IoT, and ICS/SCADA security challenges through scenario-based tasks — then design a resilience solution addressing business continuity requirements.
Learning Objectives
- Identify the security implications of virtualization, including hypervisor types, VM escape risks, and container isolation challenges.
- Describe the unique security challenges of IoT devices and recommend controls that address their constrained, always-on nature.
- Distinguish ICS/SCADA environments from traditional IT networks and justify why standard IT security practices must be adapted for operational technology.
- Demonstrate the use of redundancy, high availability, and fault tolerance, and design a resilience solution for a described business continuity scenario.
Lab 06
Architecture
Configure a Firewall
Select, configure, and compare network defense tools — firewalls, IDS/IPS, DNS filtering, NAC, DLP, and endpoint controls — mapping each to the threat vectors it is designed to neutralize.
Learning Objectives
- Compare and contrast firewall types — packet filtering, stateful, NGFW, and WAF — and select the appropriate type for a described network scenario.
- Demonstrate the use of IDS and IPS by their detection methods, placement, and response capabilities, explaining when each is the correct choice.
- Demonstrate how DNS filtering, NAC, and DLP each address different threat vectors and data protection requirements in an enterprise environment.
- Demonstrate the use of endpoint security.
- Demonstrate mapping security controls to the threats they are designed to address.
Lab 07
Security Ops
Identity & Access Management
Implement enterprise IAM — configure AAA, evaluate authentication factors, compare access control models, and trace the Joiner-Mover-Leaver lifecycle to uncover identity governance gaps.
Learning Objectives
- Demonstrate the use of Authentication, Authorization, and Accounting to implement access management in enterprise environments.
- Compare the five authentication factor types and identify which combinations constitute true Multi-Factor Authentication versus weak single-category implementations.
- Differentiate DAC and RBAC control models and select the appropriate model for a described organizational context.
- Explain the Joiner-Mover-Leaver lifecycle and describe the security failures — privilege creep and orphaned accounts — that occur when it is poorly managed.
- Apply IAM principles to a real-world scenario, identifying control gaps and recommending appropriate identity governance controls.
Lab 08
Security Ops
Build Asset Inventory
Establish system baselines, build and maintain an asset inventory, then configure SIEM alert thresholds by distinguishing among event, system, security, and application log types.
Learning Objectives
- Create system baselines.
- Build and maintain an asset inventory.
- Distinguish log types (event, system, security, application) and configure SIEM alert thresholds.
Lab 09
Security Ops
Vulnerability Scan & Incident Response
Execute the full vulnerability management lifecycle — scan, analyze, prioritize, and validate — then apply digital forensics and incident response procedures to a realistic security event.
Learning Objectives
- Demonstrate understanding of the vulnerability management lifecycle — scanning, analysis, remediation, and validation.
- Compare credentialed and non-credentialed vulnerability scans.
- Prioritize a list of scan findings using CVSS score, asset criticality, and exploitability to determine remediation order.
- Describe the principles of digital forensics — chain of custody, order of volatility, write blockers, and forensic imaging — and explain why each is essential for evidence admissibility.
- Select appropriate IR actions and forensic procedures for a described security incident scenario.
Lab 10
Program Mgmt
Security Governance & Policy
Navigate the governance document hierarchy, map major compliance frameworks to regulated industries, and apply privacy principles to a real-world compliance scenario.
Learning Objectives
- Distinguish among policies, standards, procedures, and guidelines, correctly classifying each by authority level, specificity, and purpose.
- Identify the security governance roles.
- Map major compliance frameworks (PCI DSS, HIPAA, SOX, GDPR, CMMC, NIST CSF) to the industry sectors and data types they regulate.
- Explain privacy principles.
- Apply governance and compliance knowledge to a real-world scenario, identifying the applicable regulation and the organization's compliance obligations.
Lab 11
Program Mgmt
Risk Management & Analysis
Calculate risk scores, compare treatment strategies, build a risk register, and apply BIA metrics — RTO, RPO, MTTR, and MTBF — to a described organizational risk scenario.
Learning Objectives
- Calculate a risk score using the likelihood × impact formula.
- Compare the four risk treatment strategies — Accept, Avoid, Transfer, and Mitigate — and select the appropriate strategy for a described risk scenario.
- Explain the purpose and structure of a risk register and a Business Impact Analysis (BIA).
- Apply risk management concepts to a scenario to recommend a risk treatment strategy and identify the applicable BIA metrics (RTO, RPO, MTTR, MTBF).
Lab 12
Capstone
Final Project
Bring every domain together in this capstone assessment — identify real threats and vulnerabilities, then complete a full System Security Plan and Security Assessment Report for a defined organization.
Learning Objectives
- Identify vulnerabilities and threats to an organization.
- Complete a System Security Plan.
- Complete a Security Assessment Report.