Cloud Security

CA304: Cloud Security

Course authored by:

Drinor Selmanaj, Perparim Mjeku, Rinor Shehu, Altin Gashi

29 Hours of Instruction

Includes lectures, guest speakers, and Q&A sessions

Hands-on
labs

18 Labs

Live Online or On-Demand Access

Join weekly synchronous sessions or access all material and recorded lectures anytime

Intermediate Level

Developing practical skills and deepening understanding of core concepts

Prerequisite

  • CA401 Linux Operations
  • CA402 Network Security

Course Overview

The shared responsibility model defines where provider protection ends and yours begins — and most breaches happen in the gap. You cover core concepts including cloud architectures, service models, and that boundary across AWS and Azure. The course focuses on IAM, secure networking, data protection, and real-world risks such as misconfigurations and identity abuse. Monitoring, logging, and incident response are applied in cloud-native scenarios. By the end, you can secure cloud environments under real-world conditions.

What You’ll Learn

* Apply the shared responsibility model and understand cloud service models
* Configure and manage IAM securely across cloud platforms
* Detect and prevent misconfigurations and identity-based attack vectors
* Secure cloud networking using VPCs, segmentation, and access controls
* Implement logging, monitoring, and incident response in cloud-native environments

Business Takeaways

* Reduce risk of data breaches caused by cloud misconfigurations
* Strengthen governance through proper identity and access controls
* Improve compliance with industry regulations and security frameworks
* Protect sensitive data across distributed and scalable cloud systems

Syllabus: 4 Sections to Transformation

The CA304 program drops you into the world of cloud security, where infrastructure, identity, and risk intersect at scale. It spans everything from how cloud systems are built to securing, attacking, and governing them in real environments.

syllabus overview

Justify Training to Your Manager

section 1

FOUNDATIONS + CLOUD ARCHITECTURE

Focuses on cloud computing fundamentals, AWS architecture, IAM, networking, storage services, and serverless technologies to understand how modern cloud environments are built and secured.

TOPICS COVERED

  • Cloud computing models: IaaS, PaaS, SaaS, FaaS
  • Shared Responsibility Model (critical concept)
  • AWS fundamentals (accounts, regions, IAM basics)
  • Core services: S3, EC2, networking basics
  • SaaS architecture design (multi-tenancy, threat modeling)
  • API Gateway & AWS Lambda (serverless entry points)

LABS

  • Billing
  • EC2 instances
  • S3
  • IAM
  • Import VMDK file to AWS

section 2

DEFENSIVE SECURITY + GOVERNANCE

Focuses on cloud monitoring, logging, access control, incident response, and governance practices used to secure, audit, and manage cloud environments.

TOPICS COVERED

  • Cloud logging & telemetry (AWS CloudTrail)
  • Data protection (SSE-S3 vs SSE-KMS)
  • Access control (ACLs vs bucket policies)
  • Incident response in cloud environments
  • Security assurance methodology (CSR model)
  • Policy-as-Code & compliance frameworks

LABS

  • AWS CloudTrail
  • AWS CloudWatch
  • AWS ACLs and Bucket Policies
  • Cloudflare
  • AWS tunnel (Cloudflare tunnel)

section 3

OFFENSIVE SECURITY + CLOUD INFRASTRUCTURE

Focuses on cloud attack surfaces, misconfigurations, reconnaissance, penetration testing methodologies, and secure AWS infrastructure design in multi-account environments.

TOPICS COVERED

  • Cloud penetration testing rules & scope
  • Cloud attack surface & misconfigurations
  • Common vulnerabilities (S3 exposure, IAM abuse)
  • Reconnaissance in cloud environments
  • AWS Organizations & multi-account design
  • Landing zones and security guardrails

LABS

  • AWS CLI
  • SSRF vulnerability on EC2 instance
  • pacu
  • Prowler

section 4

MODERN CLOUD SECURITY + MULTI-CLOUD

Focuses on container, Kubernetes, and multi-cloud security concepts, including runtime risks, privilege escalation, network segmentation, and securing modern cloud-native environments.

TOPICS COVERED

  • Docker security (images, containers, runtime risks)
  • Kubernetes security (RBAC, API server, etcd risks)
  • Container escape & privilege escalation
  • Network segmentation (east-west traffic control)
  • Azure fundamentals (compute, networking, storage)
  • Multi-cloud security principles

LABS

  • Apache with PHP Dockerfile
  • Create a Lambda Function
  • Vulnerable Lambda
  • Containerization with Docker

Course Schedule
& Pricing

Looking for Group Purchase Options? See below

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Next Start Date

March 5, 2026

Duration

14 Weeks Intensive

Format

Live with Zoom Meeting

What's Included

499€

Seats Filling Fast for January 2026

Location

Start Date

Start Time

Prishtina, Kosovo

March 20, 2026

10:30 AM (CEST)

Prishtina, Kosovo

April 15, 2026

4:30 PM (CEST)

Prishtina, Kosovo

May 10, 2026

11:00 AM (CEST)

Frequently Asked Questions

Mission-critical information for prospective operatives

What will I learn in this Cloud Security course?

You will learn how to secure cloud environments by understanding architecture, identity management, networking, and security operations. The course focuses on real-world platforms and teaches how to protect cloud-based systems in practical scenarios.

Basic knowledge of networking or IT is helpful, but the course starts with foundational cloud concepts and gradually introduces security practices, making it accessible for beginners while still valuable for professionals.

Most cloud breaches are caused by misconfigurations, weak identity access controls, and misunderstanding the shared responsibility model. This course teaches how to identify and prevent these common risks.

You will gain hands-on skills in Identity and Access Management (IAM), cloud networking, monitoring, incident response, and vulnerability assessment. The course emphasizes applying security controls in real cloud environments.

Cloud providers secure the infrastructure, but users are responsible for securing their data, access, and configurations. Misunderstanding this model is one of the main causes of cloud security failures, making it a critical concept for any cybersecurity professional.