| TCP/IP, port, protocol, packet, routing, subnet, CIDR, OSI | Network Fundamentals |
| firewall, iptables, UFW, Security Group, ACL, ingress, egress | Firewall & Access Control |
| VPN, WireGuard, OpenVPN, tunnel, IPsec, remote access | VPN & Tunneling |
| DNS, DNSSEC, DoH, DoT, zone, record, nameserver, domain | DNS Security |
| SSL, TLS, certificate, HTTPS, Let's Encrypt, CA, chain, OCSP | SSL/TLS & Certificates |
| SSH, Linux hardening, permissions, users, PAM, sudo, audit | Infrastructure Hardening |
| Vault, KMS, secret, key rotation, credential, token | Secret Management |
| Docker security, container scan, K8s RBAC, Pod Security | Container Security |
| AWS IAM, Security Group, VPC, Azure AD, GCP IAM, cloud | Cloud Security |
| OWASP, CVE, vulnerability, exploit, injection, XSS deep | OWASP & Vulnerabilities |
| pentest, penetration testing, recon, enumeration, exploit | Penetration Testing |
| Nmap, Nessus, ZAP, Burp Suite, scanning, vulnerability scan | Vulnerability Scanning |
| incident, breach, forensics, response, containment, recovery | Incident Response |
| SIEM, ELK, Splunk, log analysis, correlation, alert | SIEM & Log Analysis |
| STRIDE, DREAD, threat model, attack tree, risk assessment | Threat Modeling |
| encryption, AES, RSA, hashing, bcrypt, argon2, SHA | Cryptography |
| PKI, X.509, digital signature, key pair, certificate authority | PKI & Certificates |
| SAST, DAST, SCA, dependency scan, code scan, security CI | DevSecOps |
| ISO 27001, SOC 2, GDPR, PCI-DSS, compliance, audit | Compliance |
| zero trust, microsegmentation, identity-aware proxy | Zero Trust |
| DDoS, rate limiting, WAF, CDN protection, traffic scrubbing | DDoS Mitigation |
| IDS, IPS, Snort, Suricata, intrusion detection | IDS/IPS |
| supply chain, dependency, SBom, package integrity | Supply Chain Security |