<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>simeononsecurity</title><link>https://simeononsecurity.com/</link><description>Recent content on simeononsecurity</description><generator>1337 H4X0R Generator</generator><language>en</language><lastBuildDate>Sat, 10 Oct 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://simeononsecurity.com/fulltext.xml" rel="self" type="application/rss"/><item><title>2x RTX 5060 Ti vs GB10: Five-Model Local AI Benchmark at 256K Context</title><link>https://simeononsecurity.com/articles/2x-rtx-5060-ti-vs-gb10-ai-inference/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/2x-rtx-5060-ti-vs-gb10-ai-inference/</guid><description>A five-model comparison of two RTX 5060 Ti cards and an NVIDIA GB10 across 4K to 256K context, including prompt processing, generation speed, and actual prompt lengths.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/nvidia-rtx-5060-ti-vs-gb10-memory-performance-comparison.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/2x-rtx-5060-ti-vs-gb10-ai-inference/">Read the full article at https://simeononsecurity.com/</a>

        <p><strong>Two RTX 5060 Ti 16 GB cards provide 32 GB of aggregate VRAM.</strong> An NVIDIA GB10 system provides 128 GB of coherent unified memory. The new five-model benchmark shows a more balanced result than the earlier Qwen-only test.</p>
<p>The dual-card system leads on generation speed for four of the five models at the 256K setting. The GB10 leads clearly on Qwen3.8 27B and keeps a larger memory reserve for models, context, and runtime allocations. The best choice depends on the model and workload.</p>
<p>The NVIDIA GB10 uses 128 GB of coherent unified memory. NVIDIA lists the GB10 platform with 128 GB of LPDDR5x unified memory and a 140 W chip TDP. The RTX 5060 Ti uses 16 GB of GDDR7 per card, a 128-bit memory interface, and a 180 W total graphics power rating. 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="NVIDIA RTX 5060 Ti specifications">
    <meta itemprop="url" content="https://www.nvidia.com/en-us/geforce/graphics-cards/50-series/rtx-5060-family/">
    <a href="https://www.nvidia.com/en-us/geforce/graphics-cards/50-series/rtx-5060-family/"
    
        
            
                
                    rel="noopener external" target="_blank"
                
            
        
    >NVIDIA RTX 5060 Ti specifications</a>
</span>
 and 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="NVIDIA GB10 specifications">
    <meta itemprop="url" content="https://www.nvidia.com/en-us/products/workstations/dgx-spark/">
    <a href="https://www.nvidia.com/en-us/products/workstations/dgx-spark/"
    
        
            
                
                    rel="noopener external" target="_blank"
                
            
        
    >NVIDIA GB10 specifications</a

        <br>
        <a href="https://simeononsecurity.com/articles/2x-rtx-5060-ti-vs-gb10-ai-inference/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>AI Agent Delegation: Assign Workers and Review Results</title><link>https://simeononsecurity.com/articles/effective-ai-agent-delegation/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/effective-ai-agent-delegation/</guid><description>Decide when a second AI agent helps, give each worker a bounded task, prevent edit conflicts, and integrate evidence in the main session.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/effective-ai-agent-delegation.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-agent-delegation/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Practical AI Workflow Course">
    <meta itemprop="url" content="/effective-ai-course-start/">
    <a href="/effective-ai-course-start/"
    
        rel="follow me"
    >Return to the Practical AI Workflow Course</a>
</span>
</p>
<p><strong>Delegate when an independent question has enough work to justify a separate session.</strong> A worker agent inspects sources, reviews tests, or drafts a bounded change in its own context. The main agent checks and integrates the result. This lesson uses a documentation comparison while your main session keeps the small lab task.</p>
<p><strong>Learning outcome:</strong> you will assign an independent worker review and verify its short evidence report.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>Orchestrator:</strong> the main agent coordinating the task and final review.</li>
<li><strong>Worker:</strong> a separate agent assigned one bounded result.</li>
<li><strong>Independent work:</strong> a subtask whose answer does not depend on another worker&rsquo;s unfinished output.</li>
<li><strong>Ownership:</strong> a named file or question assigned to one worker.</li>
<li><strong>Integration:</strong> the main agent&rsquo;s comparison of worker output with current sources.</li>
</ul>
<h2 id="before-you-begin">
  <a href="#before-you-begin" title="Before You Begin">Before You Begin</a>
  <a href="#before-you-begin" class="h-anchor" aria-hidden="true" title="Before You Begin">#</a>
</h2>
<p><strong>Prerequisites:</strong> your 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-agent-delegation/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>AI Context Window Management: Keep Coding Agents Focused</title><link>https://simeononsecurity.com/articles/effective-ai-context-window-management/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/effective-ai-context-window-management/</guid><description>Control an AI task's active context with selected files, compact handoffs, and small worker outputs while preserving decisions and evidence.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/effective-ai-context-window-management.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-context-window-management/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Practical AI Workflow Course">
    <meta itemprop="url" content="/effective-ai-course-start/">
    <a href="/effective-ai-course-start/"
    
        rel="follow me"
    >Return to the Practical AI Workflow Course</a>
</span>
</p>
<p><strong>A context window is the text and other material a model processes for the current turn.</strong> Prompts, instructions, tool definitions, file excerpts, tool output, and conversation history consume space. This lesson shows how to keep the next task focused and leave a reliable handoff.</p>
<p><strong>Learning outcome:</strong> you will make a compact handoff and test it in a fresh session.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>Tokens</strong> are the units a model uses to process input and output.</li>
<li><strong>Active context</strong> is the material available during one turn, subject to product limits.</li>
<li><strong>Durable sources</strong> live in files or project records outside the chat.</li>
<li><strong>Compaction</strong> summarizes or prunes older context and might omit a needed detail.</li>
<li><strong>A handoff</strong> points a fresh session to current sources and verified work.</li>
</ul>
<h2 id="before-you-begin">
  <a href="#before-you-begin" title="Before You Begin">Before You Begin</a>
  <a href="#before-you-begin" class="h-anchor" aria-hidden="true" title="Before You Begin">#</a>
</h2>
<p><strong>Prerequisites:</strong> your edited lab from the 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="n

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-context-window-management/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>AI Task Packets: Better Prompts and Acceptance Checks</title><link>https://simeononsecurity.com/articles/effective-ai-task-packets/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/effective-ai-task-packets/</guid><description>Turn vague AI requests into task packets with a defined outcome, source, file scope, test, and stop condition.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/effective-ai-task-packets.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-task-packets/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Practical AI Workflow Course">
    <meta itemprop="url" content="/effective-ai-course-start/">
    <a href="/effective-ai-course-start/"
    
        rel="follow me"
    >Return to the Practical AI Workflow Course</a>
</span>
</p>
<p><strong>A useful prompt describes the work and how you will judge it.</strong> More words do not fix missing scope. This lesson turns a vague request into a task packet for the course lab.</p>
<p><strong>Learning outcome:</strong> you will write a bounded task packet with source, file scope, checks, and a stop condition.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>Outcome</strong> names the artifact or behavior you want.</li>
<li><strong>Scope</strong> names allowed files and excluded actions.</li>
<li><strong>Source</strong> identifies the approved requirement.</li>
<li><strong>Acceptance checks</strong> make success observable.</li>
<li><strong>Stop conditions</strong> prevent guessing or unauthorized follow-on work.</li>
</ul>
<h2 id="before-you-begin">
  <a href="#before-you-begin" title="Before You Begin">Before You Begin</a>
  <a href="#before-you-begin" class="h-anchor" aria-hidden="true" title="Before You Begin">#</a>
</h2>
<p><strong>Prerequisites:</strong> the extracted lab, its <code>docs/requirements.md</code>, and the 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="repository context lesson">
    <meta itemprop="url" content="/articles/effective-ai-agents-md-context/">
    <a href="/articles/effective-

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-task-packets/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>AI Workflow Capstone: Build and Verify a JSON Report</title><link>https://simeononsecurity.com/articles/effective-ai-capstone/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/effective-ai-capstone/</guid><description>Build a new JSON task report with project context, a scoped agent request, independent tests, source review, and a fresh-session handoff.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/effective-ai-capstone.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-capstone/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Practical AI Workflow Course">
    <meta itemprop="url" content="/effective-ai-course-start/">
    <a href="/effective-ai-course-start/"
    
        rel="follow me"
    >Return to the Practical AI Workflow Course</a>
</span>
</p>
<p><strong>Build a new output format and prove its behavior.</strong> Earlier you added a status filter. This capstone starts from a fresh lab and adds a JSON report for another program to read. The new requirement tests whether you transfer your workflow to a different feature.</p>
<p><strong>Learning outcome:</strong> you will deliver a checked JSON report, a source and tool evidence record, and a handoff a fresh session understands.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>A separate requirement</strong> controls the capstone feature.</li>
<li><strong>A coding agent&rsquo;s edit</strong> stays within named files.</li>
<li><strong>Independent checks</strong> determine acceptance.</li>
<li><strong>A fresh handoff</strong> lets another session reconstruct the result.</li>
</ul>
<h2 id="before-you-begin">
  <a href="#before-you-begin" title="Before You Begin">Before You Begin</a>
  <a href="#before-you-begin" class="h-anchor" aria-hidden="true" title="Before You Begin">#</a>
</h2>
<p><strong>Prerequisites:</strong> complete lessons 0 through 10, including repository context, the first coding task, MCP or its browser fallback, delegation, and bounded loops. Lesson 11 is optional. Set aside 90 to 120 minutes. Difficulty is intermediate.</p>
<p><strong>Use a fresh extraction</strong> of the 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

 

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-capstone/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>AI Workflow Course Setup: Terminal, Git, and Practice Lab</title><link>https://simeononsecurity.com/articles/effective-ai-course-setup/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/effective-ai-course-setup/</guid><description>Prepare a safe AI practice workspace, learn the terminal and Git terms used in the course, and run the starter lab.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/effective-ai-course-setup.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-course-setup/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Practical AI Workflow Course">
    <meta itemprop="url" content="/effective-ai-course-start/">
    <a href="/effective-ai-course-start/"
    
        rel="follow me"
    >Return to the Practical AI Workflow Course</a>
</span>
</p>
<p><strong>Set up one safe practice space before using an agent.</strong> Lessons 1 and 2 work in a browser without this lab. Return here before lesson 3 if you want the full course. Hands-on coding lessons use Git, Python 3.10 or later, and one coding agent. The study route replaces unavailable agent actions with labeled manual work.</p>
<p><strong>Learning outcome:</strong> you will run the starter lab, save a local baseline, and explain how to reset a disposable copy.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>Browser route:</strong> complete chat, planning, source-checking, and review exercises in ChatGPT or Claude.</li>
<li><strong>Local route:</strong> use a terminal and the supplied Python lab for coding exercises.</li>
<li><strong>Reset route:</strong> extract a new lab copy whenever an exercise goes wrong.</li>
<li><strong>Safety rule:</strong> keep private files, customer records, and credentials outside the lab.</li>
</ul>
<h2 id="choose-your-route">
  <a href="#choose-your-route" title="Choose Your Route">Choose Your Route</a>
  <a href="#choose-your-route" class="h-anchor" aria-hidden="true" title="Choose Your Route">#</a>
</h2>
<table>
	<thead>
			<tr>
					<th>Route</th>
					<th>What you need</th>
					<th>What you practice</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>Browser introduction</strong></td>
					<td>Current browser and a ChatGPT or Claude account</td>
					<td>Lessons 1 and 2, plus the chat task packet in lesson 1</td>
			</tr>
			<tr>
					<td><strong>Local hands-on</strong></td>
					<td>Git, Python 3.10 or later, terminal, one coding agent</td>
					<td>Files, diffs,

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-course-setup/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Bounded AI Agent Loops: Checks, Retries, and Stop Rules</title><link>https://simeononsecurity.com/articles/effective-ai-bounded-agent-loops/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/effective-ai-bounded-agent-loops/</guid><description>Define an AI goal loop with observable state, checks, retry limits, stop conditions, and a clear human handoff.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/effective-ai-bounded-agent-loops.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-bounded-agent-loops/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Practical AI Workflow Course">
    <meta itemprop="url" content="/effective-ai-course-start/">
    <a href="/effective-ai-course-start/"
    
        rel="follow me"
    >Return to the Practical AI Workflow Course</a>
</span>
</p>
<p><strong>A goal loop repeats work until a defined result passes or a stop rule fires.</strong> The useful loop reads current state, takes one bounded action, checks the result, and records what happened. An open-ended “keep trying” instruction has no reliable completion rule.</p>
<p><strong>Learning outcome:</strong> you will run a bounded lab loop with a known failed check and record its stop decision.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>Goal:</strong> a result stated in observable terms.</li>
<li><strong>State:</strong> the current files, outputs, errors, and source revision.</li>
<li><strong>Check:</strong> a test or review tied to the goal.</li>
<li><strong>Retry budget:</strong> the maximum attempts allowed for one failure.</li>
<li><strong>Stop rule:</strong> a condition requiring an end or human decision.</li>
</ul>
<h2 id="before-you-begin">
  <a href="#before-you-begin" title="Before You Begin">Before You Begin</a>
  <a href="#before-you-begin" class="h-anchor" aria-hidden="true" title="Before You Begin">#</a>
</h2>
<p><strong>Prerequisites:</strong> the 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="task packet">
    <meta itemprop="url" content="/articles/effective-ai-task-packets/">
    <a h

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-bounded-agent-loops/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Build a Read-Only Active Directory Inventory With PowerShell</title><link>https://simeononsecurity.com/articles/active-directory-powershell-read-only-inventory/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/active-directory-powershell-read-only-inventory/</guid><description>Inventory Active Directory OUs, users, and computers with scoped PowerShell queries. Export reviewable CSV files without changing directory objects.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/active-directory-powershell-read-only-inventory.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/active-directory-powershell-read-only-inventory/">Read the full article at https://simeononsecurity.com/</a>

        <p>An Active Directory cleanup starts with a trustworthy list of what exists. This <strong>read-only inventory</strong> gathers organizational units, users, and computers from one chosen scope. It exports three CSV files for review without changing directory objects. You still need to protect those files because names and device details reveal part of your environment.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>Choose a scope:</strong> Query one organizational unit before expanding to a whole domain.</li>
<li><strong>Use read commands:</strong> <code>Get-ADOrganizationalUnit</code>, <code>Get-ADUser</code>, and <code>Get-ADComputer</code> retrieve objects.</li>
<li><strong>Select fields:</strong> Export only the properties needed for the task.</li>
<li><strong>Check the output:</strong> Compare counts and sample rows before relying on a report.</li>
</ul>
<h2 id="before-you-begin">
  <a href="#before-you-begin" title="Before You Begin">Before You Begin</a>
  <a href="#before-you-begin" class="h-anchor" aria-hidden="true" title="Before You Begin">#</a>
</h2>
<p>You need a domain-connected Windows administration host with the <strong>ActiveDirectory</strong> PowerShell module, an account approved to read the selected objects, and a protected folder for CSV output. The site&rsquo;s 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Active Directory module guide">
    <meta itemprop="url" content="/articles/active-directory-module-powershell-installation-usage-guide/">
    <a href="/articles/active-directory-module-powershell-installation-usage-guide/"
    
        rel="follow me"
    >Active Directory module guide</a>
</span>
 covers installation. Microsoft lists the module&rsquo;s 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

        <br>
        <a href="https://simeononsecurity.com/articles/active-directory-powershell-read-only-inventory/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Capstone: Plan and Validate a Secure Local AI Server</title><link>https://simeononsecurity.com/local-ai-secure-server-course/07-capstone/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/local-ai-secure-server-course/07-capstone/</guid><description>Produce a deployment package for a measured, access-controlled, monitored, and recoverable local AI server.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/local-ai-secure-server-capstone.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/local-ai-secure-server-course/07-capstone/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Local AI Course">
    <meta itemprop="url" content="/local-ai-secure-server-course-start/">
    <a href="/local-ai-secure-server-course-start/"
    
        rel="follow me"
    >Return to the Local AI Course</a>
</span>
</p>
<p><strong>Your capstone produces a deployment decision, not a running public service.</strong> Use your measured host and model data. Keep tests on loopback or an approved private lab network.</p>
<h2 id="choose-a-track">
  <a href="#choose-a-track" title="Choose a Track">Choose a Track</a>
  <a href="#choose-a-track" class="h-anchor" aria-hidden="true" title="Choose a Track">#</a>
</h2>
<p><strong>Beginner track:</strong> One user on one host. The runtime stays on loopback. The package proves model identity, acceptable task output, measured memory, local API access, and update rollback.</p>
<p><strong>Advanced track:</strong> Several approved users on a private network. The runtime stays on loopback behind an authenticated TLS gateway. The package adds per-user authorization, rate limits, concurrency limits, monitoring, backup, staged updates, and access-denial evidence.</p>
<h2 id="required-package">
  <a href="#required-package" title="Required Package">Required Package</a>
  <a href="#required-package" class="h-anchor" aria-hidden="true" title="Required Package">#</a>
</h2>
<p>Create <strong><code>local-ai-capstone/</code></strong>:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>local-ai-capstone/
</span></span><span style="display:flex;"><span>  workload.md
</span></span><span style="display:flex;"><span>  host-inventory.md
</span></span><span style="display:flex;"><span>  model-record.md
</span></span><span style="display:flex;"><span>  benchmark.md
</span></span><span style="display:flex;"><span>  data-flow.md
</span></span><span style="display:flex;"><span>  access-policy.md
</

        <br>
        <a href="https://simeononsecurity.com/local-ai-secure-server-course/07-capstone/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Capstone: Review a Secure Agent and MCP Design</title><link>https://simeononsecurity.com/secure-ai-agents-mcp-course/06-capstone/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/secure-ai-agents-mcp-course/06-capstone/</guid><description>Produce and evaluate a review-ready security package for an AI agent with MCP tools.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/secure-agent-mcp-capstone.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/secure-ai-agents-mcp-course/06-capstone/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Secure AI Agents and MCP Course">
    <meta itemprop="url" content="/secure-ai-agents-mcp-course-start/">
    <a href="/secure-ai-agents-mcp-course-start/"
    
        rel="follow me"
    >Return to the Secure AI Agents and MCP Course</a>
</span>
</p>
<p><strong>Your capstone is a security decision package for Patch Clerk.</strong> Another reviewer should reach the same deployment decision from your artifacts and evidence.</p>
<h2 id="scenario-change">
  <a href="#scenario-change" title="Scenario Change">Scenario Change</a>
  <a href="#scenario-change" class="h-anchor" aria-hidden="true" title="Scenario Change">#</a>
</h2>
<p>Patch Clerk now reads synthetic issues, reads repository files, proposes a patch, and applies a reviewed patch in a test repository. A product owner requests a new <code>post_comment</code> tool. The tool would publish text to a fictional issue system.</p>
<p>Your job is to decide whether <code>post_comment</code> enters the first release. Treat publication as an external side effect.</p>
<h2 id="required-package">
  <a href="#required-package" title="Required Package">Required Package</a>
  <a href="#required-package" class="h-anchor" aria-hidden="true" title="Required Package">#</a>
</h2>
<p>Create <strong><code>capstone/</code></strong> with these files:</p>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>capstone/
</span></span><span style="display:flex;"><span>  system-map.md
</span></span><span style="display:flex;"><span>  authority-matrix.md
</span></span><span style="display:flex;"><span>  mcp-security-contract.md
</span></span><span style="display:flex;"><span>  event-example.json
</span></span><span style="display:flex;"><span>  detection-plan.md
</span></span><span style="display:flex;"><span>  attack-test.md
</span></span><span style="display:flex;"><span>  deployment-decision

        <br>
        <a href="https://simeononsecurity.com/secure-ai-agents-mcp-course/06-capstone/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>ChatGPT and Claude Projects: Set Up Reusable AI Context</title><link>https://simeononsecurity.com/articles/effective-ai-chat-projects/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/effective-ai-chat-projects/</guid><description>Create ChatGPT and Claude projects with focused instructions, current reference files, and a simple test for reused context.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/effective-ai-chat-projects.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-chat-projects/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Practical AI Workflow Course">
    <meta itemprop="url" content="/effective-ai-course-start/">
    <a href="/effective-ai-course-start/"
    
        rel="follow me"
    >Return to the Practical AI Workflow Course</a>
</span>
</p>
<p><strong>Create a project when several conversations share the same purpose.</strong> Put stable instructions and approved reference files in one place. Keep each conversation focused on one task. This lesson uses a fictional community workshop for practice without private data.</p>
<p><strong>Learning outcome:</strong> you will create a project with two controlled sources and test its facts in a new chat.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>Project instructions</strong> set reusable behavior for related chats.</li>
<li><strong>Project sources</strong> hold reference material you want the assistant to consult.</li>
<li><strong>Conversation history</strong> is a record of one exchange, not a substitute for an approved source.</li>
<li><strong>A fresh-chat test</strong> reveals whether your project setup supplies enough context.</li>
</ul>
<h2 id="before-you-begin">
  <a href="#before-you-begin" title="Before You Begin">Before You Begin</a>
  <a href="#before-you-begin" class="h-anchor" aria-hidden="true" title="Before You Begin">#</a>
</h2>
<p><strong>Prerequisites:</strong> a ChatGPT or Claude account, plus the task packet from 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="lesson 1">
    <meta itemprop="ur

        <br>
        <a href="https://simeononsecurity.com/articles/effective-ai-chat-projects/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM and Zero Trust Capstone</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course/08-capstone-answer-key/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course/08-capstone-answer-key/</guid><description>Review synthetic cloud access, design a least-privilege target state, plan zero trust tests, and compare the result with a full answer key and rubric.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/cloud-iam-zero-trust-capstone.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/08-capstone-answer-key/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Cloud IAM and Zero Trust Lab Course">
    <meta itemprop="url" content="/cloud-iam-zero-trust-course-start/">
    <a href="/cloud-iam-zero-trust-course-start/"
    
        rel="follow me"
    >Return to the Cloud IAM and Zero Trust Lab Course</a>
</span>
</p>
<p><strong>The capstone turns an access review into a tested migration plan.</strong> Finish the submission before reading the reference answer.</p>
<h2 id="scenario">
  <a href="#scenario" title="Scenario">Scenario</a>
  <a href="#scenario" class="h-anchor" aria-hidden="true" title="Scenario">#</a>
</h2>
<p>The payroll reporting environment contains four principals in 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="the synthetic access review">
    <meta itemprop="url" content="/downloads/cloud-iam-zero-trust-course/access-review.csv">
    <a href="/downloads/cloud-iam-zero-trust-course/access-review.csv"
    
        rel="follow me"
    >the synthetic access review</a>
</span>
. Leadership wants narrower access, short-lived sessions, visible policy decisions, and a rollback path.</p>
<h2 id="required-deliverables">
  <a href="#required-deliverables" title="Required Deliverables">Required Deliverables</a>
  <a href="#required-deliverables" class="h-anchor" aria-hidden="true" title="Required Deliverables">#</a>
</h2>
<ol>
<li><strong>Identity map:</strong> principal, type, owner, credential, session, role, scope, and revocation</li>
<li><strong>Effective-access record:</strong> one requested action per principal across applicable policy layers</li>
<li><strong>Review decision:</strong> keep, reduce, remove, or investigate with evidence</li>
<li><stro

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/08-capstone-answer-key/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM and Zero Trust Lab Course</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course-start/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course-start/</guid><description>Design, test, review, and remove cloud identity access across AWS, Azure, and Google Cloud with zero trust principles and disposable labs.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/cloud-iam-zero-trust-lab-course.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course-start/">Read the full article at https://simeononsecurity.com/</a>

        <p><strong>This course treats identity policy as executable security design.</strong> You will model principals, calculate effective access, design human and workload controls, test a disposable provider lab, and prove teardown.</p>
<p>The course compares AWS, Azure, and Google Cloud without hiding their different policy models. Provider terms stay explicit.</p>
<h2 id="audience">
  <a href="#audience" title="Audience">Audience</a>
  <a href="#audience" class="h-anchor" aria-hidden="true" title="Audience">#</a>
</h2>
<p>This course serves cloud administrators, security engineers, DevOps practitioners, and auditors who need practical identity access skills.</p>
<p><strong>You should understand accounts, command-line tools, and JSON.</strong> Prior provider certification is optional.</p>
<h2 id="outcomes">
  <a href="#outcomes" title="Outcomes">Outcomes</a>
  <a href="#outcomes" class="h-anchor" aria-hidden="true" title="Outcomes">#</a>
</h2>
<p>By the end, you will produce:</p>
<ul>
<li>An <strong>identity map</strong> for human and workload principals</li>
<li>An <strong>effective-permissions worksheet</strong> across policy layers</li>
<li>A <strong>human access design</strong> with federation, MFA, session, and emergency controls</li>
<li>A <strong>workload identity design</strong> without long-lived access keys</li>
<li>A <strong>zero trust access policy</strong> using identity, device, resource, context, and telemetry</li>
<li>A <strong>disposable lab record</strong> with preflight checks, grant inspection, AWS policy simulation where selected, teardown, and absence checks</li>
<li>An <strong>access review decision log</strong> and remediation plan</li>
</ul>
<h2 id="course-order">
  <a href="#course-order" title="Course Order">Course Order</a>
  <a href="#course-order" class="h-anchor" aria-hidden="true" title="Course Order">#</a>
</h2>
<table>
	<thead>
			<tr>
					<th>#</th>
					<th>Lesson</th>
					<th>Skill and output</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>1</strong></td>
					<td>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Identi

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course-start/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM and Zero Trust Quiz</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course/07-quiz-answer-key/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course/07-quiz-answer-key/</guid><description>Test cloud identity, effective permissions, human and workload access, zero trust policy, and teardown with a complete answer key.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/cloud-iam-zero-trust-quiz.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/07-quiz-answer-key/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Cloud IAM and Zero Trust Lab Course">
    <meta itemprop="url" content="/cloud-iam-zero-trust-course-start/">
    <a href="/cloud-iam-zero-trust-course-start/"
    
        rel="follow me"
    >Return to the Cloud IAM and Zero Trust Lab Course</a>
</span>
</p>
<p><strong>Answer every question before reading the key.</strong> Add one sentence explaining each choice.</p>
<h2 id="questions">
  <a href="#questions" title="Questions">Questions</a>
  <a href="#questions" class="h-anchor" aria-hidden="true" title="Questions">#</a>
</h2>
<ol>
<li>
<p>Which item answers who receives a temporary session?
A. Permission policy only
B. Trust relationship
C. Audit retention
D. Resource tag only</p>
</li>
<li>
<p>Which design best fits a CI workload?
A. Shared administrator password
B. Long-lived access key in repository secrets
C. OIDC federation with exact issuer, audience, subject, and short session
D. Human emergency account</p>
</li>
<li>
<p>What happens when an applicable AWS explicit deny conflicts with an allow?
A. The newest policy wins
B. The broadest policy wins
C. The request is denied
D. The user chooses</p>
</li>
<li>
<p>Which record establishes effective access?
A. One role name
B. One group membership
C. Principal, session, action, resource, every applicable layer, conditions, and final decision
D. A console screenshot only</p>
</li>
<li>
<p>Which access belongs in an emergency path?
A. Daily deployments
B. Routine report review
C. Recovery from identity or policy failure
D. Every privileged change</p>
</li>
<li>
<p>Which zero trust statement is accurate?
A. A private network grants implicit trust
B. Resource access uses identity, action, context, policy, and telemetry
C. Every request needs a human approval
D. Zero trust is one vendor product</p>
</li>
<li>
<p>Why is service-account impersonation sensitive?
A. Impersonation never creates logs
B. A less privileged principal might obtain a more privileged session
C. Service accounts lack permissions
D. Impersonation requires static keys</p>
</li>
<l

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/07-quiz-answer-key/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM Lesson 1: Identity Model</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course/01-identity-model/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course/01-identity-model/</guid><description>Model human and workload principals, credentials, sessions, policies, roles, resources, and trust relationships across major cloud providers.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/cloud-iam-identity-model.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/01-identity-model/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Cloud IAM and Zero Trust Lab Course">
    <meta itemprop="url" content="/cloud-iam-zero-trust-course-start/">
    <a href="/cloud-iam-zero-trust-course-start/"
    
        rel="follow me"
    >Return to the Cloud IAM and Zero Trust Lab Course</a>
</span>
</p>
<p><strong>Cloud access starts with a principal and ends with a resource action.</strong> Credentials create a session. Policies and trust relationships decide which actions the session receives.</p>
<h2 id="name-the-parts">
  <a href="#name-the-parts" title="Name the Parts">Name the Parts</a>
  <a href="#name-the-parts" class="h-anchor" aria-hidden="true" title="Name the Parts">#</a>
</h2>
<table>
	<thead>
			<tr>
					<th>Part</th>
					<th>Question</th>
					<th>Example</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>Principal</strong></td>
					<td>Who or what asks?</td>
					<td>Person, group, role session, service account, managed identity</td>
			</tr>
			<tr>
					<td><strong>Credential</strong></td>
					<td>How is identity proven?</td>
					<td>Federation token, certificate, workload token</td>
			</tr>
			<tr>
					<td><strong>Session</strong></td>
					<td>Which temporary context acts?</td>
					<td>AWS role session, Azure sign-in session, Google access token</td>
			</tr>
			<tr>
					<td><strong>Role or policy</strong></td>
					<td>Which actions are described?</td>
					<td>S3 list, resource-group reader, logging viewer</td>
			</tr>
			<tr>
					<td><strong>Resource</strong></td>
					<td>What receives the action?</td>
					<td>Bucket, vault, project, secret, application</td>
			</tr>
			<tr>
					<td><strong>Trust relationship</strong></td>
					<td>Who is allowed to obtain the role or identity?</td>
					<td>Federation provider, workload pool, role trust policy</td>
			</tr>
	</tbody>
</table>
<p>Do not merge authentication and authorization. <strong>A valid identity still needs an allowed action on the target resource.</strong></p>
<h2 id="compare-provider-terms">
  <a href="#compare-provider-terms" title="Compare 

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/01-identity-model/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM Lesson 2: Effective Permissions</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course/02-effective-permissions/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course/02-effective-permissions/</guid><description>Evaluate cloud access across identity policies, resource policies, boundaries, hierarchy controls, conditions, inheritance, and explicit denies.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/cloud-effective-permissions.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/02-effective-permissions/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Cloud IAM and Zero Trust Lab Course">
    <meta itemprop="url" content="/cloud-iam-zero-trust-course-start/">
    <a href="/cloud-iam-zero-trust-course-start/"
    
        rel="follow me"
    >Return to the Cloud IAM and Zero Trust Lab Course</a>
</span>
</p>
<p><strong>Effective access is the final result across every applicable policy layer.</strong> Reading one role or binding does not establish the decision.</p>
<h2 id="use-a-decision-record">
  <a href="#use-a-decision-record" title="Use a Decision Record">Use a Decision Record</a>
  <a href="#use-a-decision-record" class="h-anchor" aria-hidden="true" title="Use a Decision Record">#</a>
</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>Principal:
</span></span><span style="display:flex;"><span>Session:
</span></span><span style="display:flex;"><span>Action:
</span></span><span style="display:flex;"><span>Resource:
</span></span><span style="display:flex;"><span>Identity grant:
</span></span><span style="display:flex;"><span>Resource grant:
</span></span><span style="display:flex;"><span>Boundary or session limit:
</span></span><span style="display:flex;"><span>Hierarchy control:
</span></span><span style="display:flex;"><span>Condition:
</span></span><span style="display:flex;"><span>Explicit deny:
</span></span><span style="display:flex;"><span>Final decision:
</span></span><span style="display:flex;"><span>Evidence:
</span></span></code></pre></div><p>Fill every row. Use <code>not applicable</code> where a layer does not exist.</p>
<h2 id="compare-evaluation-models">
  <a href="#compare-evaluation-models" title="Compare Evaluation Models">Compare Evaluation Models</a>
  <a href="#compare-evaluation-models" class="h-anchor" aria-hidden="true" title="Compare Evaluation Models">#</a>
</h2>
<table>
	<thead>
			<tr>
					<th>Provider</th>
					<th>Core mo

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/02-effective-permissions/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM Lesson 3: Human Access</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course/03-human-access/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course/03-human-access/</guid><description>Design federated human access with strong authentication, short sessions, privileged activation, emergency recovery, and continuous review.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/cloud-human-access.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/03-human-access/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Cloud IAM and Zero Trust Lab Course">
    <meta itemprop="url" content="/cloud-iam-zero-trust-course-start/">
    <a href="/cloud-iam-zero-trust-course-start/"
    
        rel="follow me"
    >Return to the Cloud IAM and Zero Trust Lab Course</a>
</span>
</p>
<p><strong>Human cloud access should begin at a central identity provider and end in a short-lived session.</strong> Separate daily work, privileged work, and emergency recovery.</p>
<h2 id="design-the-path">
  <a href="#design-the-path" title="Design the Path">Design the Path</a>
  <a href="#design-the-path" class="h-anchor" aria-hidden="true" title="Design the Path">#</a>
</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>Person
</span></span><span style="display:flex;"><span>  -&gt; central identity provider
</span></span><span style="display:flex;"><span>  -&gt; phishing-resistant authentication
</span></span><span style="display:flex;"><span>  -&gt; device and risk checks
</span></span><span style="display:flex;"><span>  -&gt; group or eligible role
</span></span><span style="display:flex;"><span>  -&gt; short-lived cloud session
</span></span><span style="display:flex;"><span>  -&gt; resource action
</span></span><span style="display:flex;"><span>  -&gt; audit event
</span></span></code></pre></div><p>Each step needs an owner and failure route. A central sign-in without session limits or audit review still leaves excessive access risk.</p>
<h2 id="separate-access-types">
  <a href="#separate-access-types" title="Separate Access Types">Separate Access Types</a>
  <a href="#separate-access-types" class="h-anchor" aria-hidden="true" title="Separate Access Types">#</a>
</h2>
<table>
	<thead>
			<tr>
					<th>Access type</th>
					<th>Use</th>
					<th>Control</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>Daily</strong></td>
					<td>Routin

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/03-human-access/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM Lesson 4: Workload Identity</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course/04-workload-identity/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course/04-workload-identity/</guid><description>Design workload identity with federation, managed identities, service accounts, short-lived tokens, narrow roles, and verified rotation or revocation.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/cloud-workload-identity.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/04-workload-identity/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Cloud IAM and Zero Trust Lab Course">
    <meta itemprop="url" content="/cloud-iam-zero-trust-course-start/">
    <a href="/cloud-iam-zero-trust-course-start/"
    
        rel="follow me"
    >Return to the Cloud IAM and Zero Trust Lab Course</a>
</span>
</p>
<p><strong>A workload needs identity without a stored cloud key.</strong> Prefer platform identity or federation which exchanges trusted workload claims for short-lived access.</p>
<h2 id="choose-the-pattern">
  <a href="#choose-the-pattern" title="Choose the Pattern">Choose the Pattern</a>
  <a href="#choose-the-pattern" class="h-anchor" aria-hidden="true" title="Choose the Pattern">#</a>
</h2>
<table>
	<thead>
			<tr>
					<th>Pattern</th>
					<th>Fit</th>
					<th>Main risk</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>Platform-managed identity</strong></td>
					<td>Workload runs inside one cloud</td>
					<td>Attached identity receives broad resource access</td>
			</tr>
			<tr>
					<td><strong>OIDC workload federation</strong></td>
					<td>CI/CD, Kubernetes, or external workload</td>
					<td>Trust conditions accept unintended repositories, branches, or subjects</td>
			</tr>
			<tr>
					<td><strong>Service account with short-lived impersonation</strong></td>
					<td>Central workload identity model</td>
					<td>Users or workloads impersonate a more privileged account</td>
			</tr>
			<tr>
					<td><strong>Static key or client secret</strong></td>
					<td>Legacy exception</td>
					<td>Copy, leak, unclear owner, weak expiry, and difficult revocation</td>
			</tr>
	</tbody>
</table>
<p>Use static credentials only under a documented exception with owner, storage, rotation, monitoring, and retirement date.</p>
<h2 id="bind-trust-narrowly">
  <a href="#bind-trust-narrowly" title="Bind Trust Narrowly">Bind Trust Narrowly</a>
  <a href="#bind-trust-narrowly" class="h-anchor" aria-hidden="true" title="Bind Trust Narrowly">#</a>
</h2>
<p>Trust policy answers <strong>who gets a session</strong>. Permission policy answers <strong

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/04-workload-identity/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM Lesson 5: Zero Trust Policy</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course/05-zero-trust-policy/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course/05-zero-trust-policy/</guid><description>Turn zero trust principles into explicit cloud access decisions using identity, resource, device, workload, context, policy enforcement, and telemetry.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/cloud-zero-trust-policy.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/05-zero-trust-policy/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Cloud IAM and Zero Trust Lab Course">
    <meta itemprop="url" content="/cloud-iam-zero-trust-course-start/">
    <a href="/cloud-iam-zero-trust-course-start/"
    
        rel="follow me"
    >Return to the Cloud IAM and Zero Trust Lab Course</a>
</span>
</p>
<p><strong>Zero trust removes implicit trust from location, ownership, and prior access.</strong> Policy evaluates a subject, resource, action, and current context before granting a session or request.</p>
<h2 id="build-the-decision">
  <a href="#build-the-decision" title="Build the Decision">Build the Decision</a>
  <a href="#build-the-decision" class="h-anchor" aria-hidden="true" title="Build the Decision">#</a>
</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>Subject: Who or which workload requests access?
</span></span><span style="display:flex;"><span>Credential: How was identity established?
</span></span><span style="display:flex;"><span>Device or runtime: What executes the request?
</span></span><span style="display:flex;"><span>Resource: Which exact asset receives access?
</span></span><span style="display:flex;"><span>Action: Which operation is requested?
</span></span><span style="display:flex;"><span>Context: Time, location, risk, environment, ticket, or branch
</span></span><span style="display:flex;"><span>Policy decision: Allow, block, step up, narrow, or require approval
</span></span><span style="display:flex;"><span>Enforcement point: Where is the decision applied?
</span></span><span style="display:flex;"><span>Telemetry: Which event records decision and use?
</span></span><span style="display:flex;"><span>Revocation: Which signal ends access?
</span></span></code></pre></div><p>This record links architecture to an observable decision.</p>
<h2 id="apply-seven-tenets">
  <a href="#apply-seven-tenets" title="Apply Seven Tenets">Apply 

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/05-zero-trust-policy/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Cloud IAM Lesson 6: Disposable Provider Lab</title><link>https://simeononsecurity.com/cloud-iam-zero-trust-course/06-disposable-cloud-lab/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/cloud-iam-zero-trust-course/06-disposable-cloud-lab/</guid><description>Create a read-only identity in one cloud sandbox, inspect its grant, then remove and verify every lab object. AWS adds policy simulation.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/disposable-cloud-iam-lab.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/06-disposable-cloud-lab/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Cloud IAM and Zero Trust Lab Course">
    <meta itemprop="url" content="/cloud-iam-zero-trust-course-start/">
    <a href="/cloud-iam-zero-trust-course-start/"
    
        rel="follow me"
    >Return to the Cloud IAM and Zero Trust Lab Course</a>
</span>
</p>
<p><strong>Choose one provider track in a dedicated sandbox.</strong> Each track creates read-only identity state, inspects the grant, removes every object created in this run, and checks absence. The AWS track simulates policy decisions. None of the tracks proves a live access denial by the new identity.</p>
<p>Do not use production. Confirm the active provider context before every create command.</p>
<h2 id="lab-record">
  <a href="#lab-record" title="Lab Record">Lab Record</a>
  <a href="#lab-record" class="h-anchor" aria-hidden="true" title="Lab Record">#</a>
</h2>
<div class="highlight"><pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"><code class="language-text" data-lang="text"><span style="display:flex;"><span>Provider:
</span></span><span style="display:flex;"><span>Account, subscription, or project:
</span></span><span style="display:flex;"><span>Operator identity:
</span></span><span style="display:flex;"><span>Start time UTC:
</span></span><span style="display:flex;"><span>Objects created:
</span></span><span style="display:flex;"><span>Object identifiers returned by create commands:
</span></span><span style="display:flex;"><span>Preflight absence result:
</span></span><span style="display:flex;"><span>Expected allow:
</span></span><span style="display:flex;"><span>Expected deny:
</span></span><span style="display:flex;"><span>Test type, live or simulated:
</span></span><span style="display:flex;"><span>Teardown commands:
</span></span><span style="display:flex;"><span>Absence checks:
</span></span><span style="display:flex;"><span>End time UTC:
</span></span><span style="display:flex;"><span>Residual objects:
</span></span></code></pre></div><h

        <br>
        <a href="https://simeononsecurity.com/cloud-iam-zero-trust-course/06-disposable-cloud-lab/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Dependency Review and SBOMs for a Secure Release</title><link>https://simeononsecurity.com/articles/secure-cicd-dependencies-sbom/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/articles/secure-cicd-dependencies-sbom/</guid><description>Review a dependency change, record its risk, and generate a CycloneDX SBOM before releasing software.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/secure-cicd-course.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/articles/secure-cicd-dependencies-sbom/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Secure CI/CD Course">
    <meta itemprop="url" content="/secure-cicd-course-start/">
    <a href="/secure-cicd-course-start/"
    
        rel="follow me"
    >Return to the Secure CI/CD Course</a>
</span>
</p>
<p><strong>A release inherits the code and build inputs it consumes.</strong> Review changed dependencies before merge, then record the components present in the built output. These are related checks with different questions. A pull request review asks what changed. A software bill of materials, or <strong>SBOM</strong>, records what a scanner found in a chosen artifact.</p>
<h2 id="key-takeaways">
  <a href="#key-takeaways" title="Key Takeaways">Key Takeaways</a>
  <a href="#key-takeaways" class="h-anchor" aria-hidden="true" title="Key Takeaways">#</a>
</h2>
<ul>
<li><strong>Dependency review</strong> compares a proposed revision with its base and flags known risk.</li>
<li><strong>An SBOM</strong> lists discovered components. It does not certify their safety or the publisher&rsquo;s identity.</li>
<li><strong>Your decision record</strong> should name the version, source, reason, risk, and owner.</li>
</ul>
<h2 id="prerequisites">
  <a href="#prerequisites" title="Prerequisites">Prerequisites</a>
  <a href="#prerequisites" class="h-anchor" aria-hidden="true" title="Prerequisites">#</a>
</h2>
<p><strong>Download and extract the 











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="lab archive">
    <meta itemprop="url" content="/downloads/secure-cicd-lab.zip">
    <a href="/downloads/secure-cicd-lab.zip"
    
        rel="follow me"
    >lab archive</a>
</span>
.</strong> Enter its <code>secure-cicd-lab<

        <br>
        <a href="https://simeononsecurity.com/articles/secure-cicd-dependencies-sbom/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Detection Engineering and Incident Response Capstone</title><link>https://simeononsecurity.com/detection-engineering-incident-response-course/08-capstone-answer-key/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/detection-engineering-incident-response-course/08-capstone-answer-key/</guid><description>Deliver a complete detection and incident package from the synthetic course data, then compare the result with a detailed answer key and scoring rubric.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/detection-incident-response-capstone.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/detection-engineering-incident-response-course/08-capstone-answer-key/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Detection Engineering and Incident Response Course">
    <meta itemprop="url" content="/detection-engineering-incident-response-course-start/">
    <a href="/detection-engineering-incident-response-course-start/"
    
        rel="follow me"
    >Return to the Detection Engineering and Incident Response Course</a>
</span>
</p>
<p><strong>The capstone joins engineering and response into one review package.</strong> Finish your submission before reading the reference answer.</p>
<h2 id="scenario">
  <a href="#scenario" title="Scenario">Scenario</a>
  <a href="#scenario" class="h-anchor" aria-hidden="true" title="Scenario">#</a>
</h2>
<p>Your security operations lead asks for a detection and incident package based on the three course data files. The package must support analyst review, management decisions, and follow-up engineering work.</p>
<h2 id="required-deliverables">
  <a href="#required-deliverables" title="Required Deliverables">Required Deliverables</a>
  <a href="#required-deliverables" class="h-anchor" aria-hidden="true" title="Required Deliverables">#</a>
</h2>
<ol>
<li><strong>Evidence record:</strong> filenames, hashes, counts, time zone, and source limits</li>
<li><strong>Detection strategy card:</strong> behavior, evidence, correlation, exclusions, escalation, and ATT&amp;CK references</li>
<li><strong>Rule draft:</strong> Sigma-style YAML with status <code>test</code></li>
<li><strong>Test matrix:</strong> two positive, two negative, and one boundary case</li>
<li><strong>Timeline:</strong> at least ten source-linked entries</li>
<li><strong>Scope statement:</strong> confirmed, likely, excluded, unknown, and as-of time</li>
<li><strong>Response plan:</strong> five action cards in order</li>
<li><strong>Recovery gates:</strong> identity, endpoint, mail, monitoring, and business</li>
<li><strong>Improvement backlog:</strong> six owned and testable items</li>
<li><strong>Executive update:</strong> five sentences or fewer</li>
</ol>
<h2 id="constraints">
  <a href="#constraints" title="Co

        <br>
        <a href="https://simeononsecurity.com/detection-engineering-incident-response-course/08-capstone-answer-key/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Detection Engineering and Incident Response Course</title><link>https://simeononsecurity.com/detection-engineering-incident-response-course-start/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/detection-engineering-incident-response-course-start/</guid><description>Build and test detections with synthetic identity, endpoint, and DNS evidence. Investigate an incident and report your findings.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/detection-engineering-incident-response-course.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/detection-engineering-incident-response-course-start/">Read the full article at https://simeononsecurity.com/</a>

        <p><strong>This course joins detection engineering with incident response.</strong> You will define observable behavior, write testable logic, investigate synthetic evidence, choose response actions, and record improvements.</p>
<p>The course uses a fictional compromise across identity, endpoint, and DNS logs. Every conclusion must point to evidence. Every response step must state an owner, approval boundary, and verification check.</p>
<h2 id="audience">
  <a href="#audience" title="Audience">Audience</a>
  <a href="#audience" class="h-anchor" aria-hidden="true" title="Audience">#</a>
</h2>
<p>This course serves junior security analysts, system administrators moving into security operations, and detection engineers who need a repeatable investigation method.</p>
<p><strong>You should know basic command-line navigation and JSON.</strong> Prior SIEM, EDR, or forensic experience is optional.</p>
<h2 id="outcomes">
  <a href="#outcomes" title="Outcomes">Outcomes</a>
  <a href="#outcomes" class="h-anchor" aria-hidden="true" title="Outcomes">#</a>
</h2>
<p>By the end, you will produce:</p>
<ul>
<li>A <strong>telemetry inventory</strong> with fields, retention needs, and trust limits</li>
<li>An <strong>ATT&amp;CK-informed detection hypothesis</strong> tied to current Detection Strategies and Analytics</li>
<li>A <strong>portable rule specification</strong> with test cases and tuning notes</li>
<li>A <strong>full incident timeline</strong> built from three synthetic log sources</li>
<li>A <strong>scope statement</strong> separating confirmed impact, likely impact, and unknowns</li>
<li>A <strong>response plan</strong> with containment, recovery, and improvement checks</li>
</ul>
<h2 id="course-order">
  <a href="#course-order" title="Course Order">Course Order</a>
  <a href="#course-order" class="h-anchor" aria-hidden="true" title="Course Order">#</a>
</h2>
<table>
	<thead>
			<tr>
					<th>#</th>
					<th>Lesson</th>
					<th>Skill and output</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>1</strong></td>
					<td>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" conte

        <br>
        <a href="https://simeononsecurity.com/detection-engineering-incident-response-course-start/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Detection Engineering and Incident Response Quiz</title><link>https://simeononsecurity.com/detection-engineering-incident-response-course/07-quiz-answer-key/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/detection-engineering-incident-response-course/07-quiz-answer-key/</guid><description>Test telemetry, ATT&amp;CK mapping, detection logic, triage, scoping, containment, recovery, and evidence handling with a complete answer key.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/detection-incident-response-quiz.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/detection-engineering-incident-response-course/07-quiz-answer-key/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Detection Engineering and Incident Response Course">
    <meta itemprop="url" content="/detection-engineering-incident-response-course-start/">
    <a href="/detection-engineering-incident-response-course-start/"
    
        rel="follow me"
    >Return to the Detection Engineering and Incident Response Course</a>
</span>
</p>
<p><strong>Answer every question before opening the key.</strong> Write a one-sentence reason for each choice.</p>
<h2 id="questions">
  <a href="#questions" title="Questions">Questions</a>
  <a href="#questions" class="h-anchor" aria-hidden="true" title="Questions">#</a>
</h2>
<ol>
<li>
<p>Which statement best describes a telemetry contract?
A. A list of ATT&amp;CK techniques
B. A record of source, fields, time, retention, transformations, and limits
C. A vendor alert severity table
D. A list of blocked indicators</p>
</li>
<li>
<p>Which ATT&amp;CK object gives platform-specific detection logic in current ATT&amp;CK?
A. Analytic
B. Group
C. Campaign
D. Mitigation</p>
</li>
<li>
<p>What changed in ATT&amp;CK v18?
A. Techniques were removed
B. Data Sources became mandatory
C. Detection Strategies and Analytics replaced technique detection text, and Data Sources were deprecated
D. ATT&amp;CK stopped publishing defensive content</p>
</li>
<li>
<p>Which test is a negative case for the course rule?
A. Word starts PowerShell with <code>-EncodedCommand</code>
B. Excel starts <code>pwsh.exe</code> with <code>-enc</code>
C. Software Center starts an approved inventory script
D. PowerPoint starts encoded PowerShell</p>
</li>
<li>
<p>Why does a successful suspicious sign-in fail to prove actor identity?
A. Sign-in logs never include users
B. The event records credential use, while person or process attribution needs more evidence
C. Every successful sign-in is benign
D. IP addresses identify people</p>
</li>
<li>
<p>Which finding belongs in confirmed scope?
A. Mail content was exported, with no message-access records
B. <code>HR-LT-044</code> launched encoded PowerShell, based on <code>E

        <br>
        <a href="https://simeononsecurity.com/detection-engineering-incident-response-course/07-quiz-answer-key/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item><item><title>Detection Engineering Lesson 1: Telemetry and Evidence</title><link>https://simeononsecurity.com/detection-engineering-incident-response-course/01-telemetry-evidence/</link><pubDate>Sat, 10 Oct 2026 00:00:00 +0000</pubDate><guid>https://simeononsecurity.com/detection-engineering-incident-response-course/01-telemetry-evidence/</guid><description>Inventory identity, endpoint, and DNS telemetry. Normalize timestamps, preserve source events, and document evidence limits before analysis.</description><content:encoded><![CDATA[
        
            <img src="https://simeononsecurity.com/img/cover/detection-engineering-telemetry-evidence.webp">
            
        

        <br>
        <a href="https://simeononsecurity.com/detection-engineering-incident-response-course/01-telemetry-evidence/">Read the full article at https://simeononsecurity.com/</a>

        <p>











    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    

    



    


<span itemscope itemtype="https://schema.org/WebPage">
    <meta itemprop="name" content="Return to the Detection Engineering and Incident Response Course">
    <meta itemprop="url" content="/detection-engineering-incident-response-course-start/">
    <a href="/detection-engineering-incident-response-course-start/"
    
        rel="follow me"
    >Return to the Detection Engineering and Incident Response Course</a>
</span>
</p>
<p><strong>A detection is only as strong as its telemetry contract.</strong> The contract states which system produced an event, which fields exist, how time is recorded, and where collection gaps appear.</p>
<h2 id="build-an-inventory">
  <a href="#build-an-inventory" title="Build an Inventory">Build an Inventory</a>
  <a href="#build-an-inventory" class="h-anchor" aria-hidden="true" title="Build an Inventory">#</a>
</h2>
<p>Create one row per source before opening the investigation files.</p>
<table>
	<thead>
			<tr>
					<th>Source</th>
					<th>Key fields</th>
					<th>Useful question</th>
					<th>Limit</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><strong>Identity</strong></td>
					<td>User, source IP, device, result, authentication protocol, MFA state</td>
					<td>Did a principal authenticate from a new context?</td>
					<td>A successful sign-in does not prove who used the credential</td>
			</tr>
			<tr>
					<td><strong>Endpoint</strong></td>
					<td>Host, user, process, parent, command line, hash</td>
					<td>What executed, and which process launched the child?</td>
					<td>Missing events do not prove missing execution</td>
			</tr>
			<tr>
					<td><strong>DNS</strong></td>
					<td>Host, user, query, response, answer</td>
					<td>Which names did an endpoint resolve?</td>
					<td>A lookup does not prove a later connection</td>
			</tr>
	</tbody>
</table>
<p>Record retention, clock source, ingestion delay, field transformations, and access owner. <strong>Do not merge similarly named fields until their meanings match.</strong> A device name reported by an identity provider might describe registration state rather than the endpoint which sent traffic.</p>
<

        <br>
        <a href="https://simeononsecurity.com/detection-engineering-incident-response-course/01-telemetry-evidence/">Read More at https://simeononsecurity.com/</a>
                            
        

      ]]></content:encoded></item></channel></rss>