Cloud Security Foundations
Secure your side of the cloud, from identity to continuous posture.
Tuition
$349
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
9 hours
Estimated time
What you will be able to do
- You will be able to draw the shared responsibility line for IaaS, PaaS, and SaaS, and name which security controls belong to the provider and which are yours.
- You will be able to map the cloud attack surface (control plane, data plane, identity, and network) and reason about how cloud threats differ from on-premises ones.
- You will be able to design least-privilege cloud access using roles, policies, permission boundaries, and short-lived credentials instead of long-lived keys.
- You will be able to federate workforce and workload identity with single sign-on, OIDC, and SAML so no human or service relies on a static cloud credential.
- You will be able to protect data at rest and in transit with managed encryption, envelope encryption, and a key management service, including customer-managed keys.
- You will be able to manage secrets and shut down the storage misconfigurations that cause most public cloud data leaks.
- You will be able to assess a cloud environment against the CIS Benchmarks using a CSPM or CNAPP tool, then triage the misconfigurations it finds by real risk.
- You will be able to close the loop with guardrails as code, such as service control policies and policy-as-code, so fixed misconfigurations do not come back.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
The Cloud Security Model and Shared Responsibility
Cloud security starts with a question most teams get wrong: which controls are yours and which belong to the provider. This module frames the Cloud Security Engineer role, walks the shared responsibility model across IaaS, PaaS, and SaaS, and maps the cloud attack surface so you can see where your duties begin. You will leave able to draw the responsibility line for any service and reason about how cloud threats differ from the on-premises world.
2 lessons · 5 quiz questions
- 02
Identity and Access Management in the Cloud
In the cloud, identity is the perimeter, and one over-permissioned role can expose an entire account. This module shows how principals, roles, and policies actually grant access, then how to enforce least privilege with permission boundaries, federation, and short-lived credentials so no human or workload has to lean on static keys.
2 lessons · 5 quiz questions · assignment
- 03
Data Protection and Encryption
With identity under control, protection turns to the data itself. This module shows a Cloud Security Engineer how to classify data by sensitivity, then apply encryption in transit and at rest using a cloud key management service, envelope encryption, and customer-managed keys. You will also manage secrets safely and close the storage misconfigurations behind most public cloud data leaks.
2 lessons · 5 quiz questions
- 04
Cloud Security Posture Management
Every account you touch drifts out of a secure state over time, and this module keeps it in check. You will continuously assess environments against the CIS Benchmarks using CSPM and CNAPP tooling, triage misconfigurations by real risk instead of raw finding count, then close the loop with guardrails as code so the same mistakes cannot reappear.
2 lessons · 5 quiz questions · assignment