u/identity-stack

Once you've finished a cloud-security lab, how do you practice the same skill again without following the exact same walkthrough

This is something I've been checking out for how others approach it

A tutorial can show you how to configure stuff, set up Conditional Access, Azure RBAC, Sentinel rules, Defender, etc. But after you've followed it once, what's your method for actually getting good at investigating problems involving those things?

Do you create your own scenarios afterwards, or just move on to the next topic?

Curious what people actually do?

reddit.com
u/identity-stack — 5 days ago

What do you do after finishing a cloud security tutorial?

This is something I've been struggling with.

A tutorial or a guide shows you how to configure Conditional Access, RBAC, Sentinel rules, Defender, etc. But after you've followed it and practised the configuration, what's your method for actually getting good at investigating problems involving those things?

Do you create your own scenarios afterwards, or just move on to the next topic?

Curious what people actually do, not what the ideal learning process is supposed to be.

reddit.com
u/identity-stack — 9 days ago
▲ 0 r/entra

How do you actually practice security in entra?

I'm curious about how people go beyond courses and documentation. Apart from the courses on YouTube, Udemy, labs, etc.

When you're learning something like MITRE ATT&CK, IAM, RBAC, etc., what do you actually do to practice it? I am not asking about the configuration of conditional access policies or app registrations etc.

Do you:

  • build things in your own cloud tenant?
  • use dedicated labs?
  • use CTFs?
  • follow attack/detection walkthroughs?
  • create your own scenarios?

You can build tenant, create policies, setup mfa, phishing resistant, etc. but how do you get to practice with what happens in real world? Because in testing, everything is controlled.

reddit.com
u/identity-stack — 10 days ago
▲ 23 r/AZURE

How are you learning and practicing cloud?

I'm curious about how people go beyond courses and documentation. Apart from the courses on YouTube, Udemy, labs, etc., deploying resources using IaC or via a portal, on the job or at work.

When you're learning something like IAM, RBAC, Sentinel, Monitoring, Defender for Cloud, etc., what do you actually do to practice it?

Do you:

  • use dedicated labs?
  • follow attack/detection walkthroughs?
  • create your own scenarios?
reddit.com
u/identity-stack — 13 days ago

How do you actually practice cloud security?

I'm curious about how people go beyond courses and documentation. Apart from the courses on YouTube, Udemy, labs, etc.

When you're learning something like MITRE ATT&CK, IAM, RBAC, Sentinel, Defender for Cloud, etc., what do you actually do to practice it?

Do you:

  • build things in your own cloud tenant?
  • use dedicated labs?
  • use CTFs?
  • follow attack/detection walkthroughs?
  • create your own scenarios?
reddit.com
u/identity-stack — 13 days ago