All Modules FUNDAMENTALS

Security Fundamentals · Complete Guide

Ten chapters covering the core concepts every other domain in H3AD-LEARN builds on: the CIA triad, authentication and access control, cryptography basics, common attack patterns, security frameworks and compliance, risk and vulnerability management, SOC operations basics, identity federation, threat modeling, and how it all maps to a career track. Built for anyone starting a SOC analyst, threat hunting, or detection engineering path with no assumed background.

10 CHAPTERS
~13 HRS CONTENT
BEGINNER to INTERMEDIATE SKILL RANGE
SEP 2026 LAST UPDATED
MODULE PROGRESS 0 / 10 chapters complete
CIA triad AAA MFA cryptography kill chain NIST CSF CVSS SOC tiers

ALL CHAPTERS

/
01
BEGINNER 25 min

Security Fundamentals & the CIA Triad

Confidentiality, integrity, and availability as the core security model, the Parkerian Hexad extension, AAA, and the vocabulary of threat, vulnerability, risk, and attack surface every other chapter assumes.

CIA triad AAA core vocabulary
02
BEGINNER 30 min

Authentication & Access Control

The three authentication factors, MFA mechanics from TOTP to passkeys, RBAC and ABAC authorization models, least privilege, and why Zero Trust replaced the perimeter model.

MFA RBAC Zero Trust
03
BEGINNER 35 min

Cryptography Basics

Symmetric and asymmetric encryption, hashing and integrity, digital signatures, PKI and certificate chains, and how a TLS handshake ties all of it together.

symmetric/asymmetric hashing PKI
04
INTERMEDIATE 35 min

Common Attacks & the Cyber Kill Chain

Malware taxonomy, phishing and social engineering tradecraft, common web and network attack patterns, and the Cyber Kill Chain and ATT&CK as shared vocabulary for describing an intrusion.

malware taxonomy kill chain ATT&CK
05
INTERMEDIATE 30 min

Security Frameworks & Compliance

NIST CSF, ISO 27001, and CIS Controls as prioritization frameworks, plus a practical walkthrough of PCI-DSS, HIPAA, and GDPR obligations analysts actually encounter.

NIST CSF ISO 27001 CIS Controls
06
INTERMEDIATE 35 min

Risk & Vulnerability Management

Risk as likelihood times impact, CVSS scoring mechanics, the full vulnerability management lifecycle, and patch prioritization under real operational constraints.

CVSS vuln lifecycle patch management
07
INTERMEDIATE 30 min

Security Operations Basics

How a SOC is structured across tiers, what SIEM and EDR actually do, the alert triage workflow from ticket to disposition, and escalation and shift realities.

SOC tiers SIEM triage
08
BEGINNER 25 min

Career Paths & Your Learning Roadmap

How these fundamentals map onto SOC analyst, threat hunter, CTI, detection engineer, and IR career tracks, plus a suggested study order through the rest of H3AD-LEARN.

career paths study roadmap
09
INTERMEDIATE 40 min

Identity Federation: SSO, SAML & OAuth/OIDC

SSO, SAML assertions, OAuth 2.0 grant types, OpenID Connect, and JWTs, the identity backbone of real enterprise environments and real federation attacks like Golden SAML.

SSO SAML OAuth/OIDC
10
INTERMEDIATE 35 min

Threat Modeling & Security by Design

STRIDE, attack trees, DREAD, and PASTA, threat modeling as a practice done before code is written, closing the module by tying every prior chapter together.

STRIDE attack trees secure design

PREREQUISITES & OUTCOMES

WHAT YOU SHOULD KNOW

  • No security background required. This module assumes general computer literacy only
  • Basic comfort with how logins, websites, and files work day to day
  • Curiosity about how attackers and defenders think, no prior IT or security job required
  • Nothing else. This is the starting point for the rest of H3AD-LEARN

WHAT YOU WILL KNOW AFTER

  • The CIA triad and the vocabulary (threat, vulnerability, risk, exploit) used throughout every other module
  • How authentication, authorization, and Zero Trust actually work, not just as buzzwords
  • Enough cryptography to understand TLS, hashing, and why certificate errors matter
  • The Cyber Kill Chain and ATT&CK as a shared language for describing an attack
  • Where compliance and frameworks fit into a real security program
  • Which H3AD-LEARN module and which career track to pursue next

RECOMMENDED TOOLS

H3AD-SEC tools that pair directly with this module's content.