
Marvel
338 posts

Marvel
@TheCyber_Chic
learning in public - technology & security ✧





When I started in cybersecurity, I did what every beginner does. I tried to learn everything at once. Networking. Linux. Cloud. Hacking tools. Certifications. Months later I realized something frustrating: I still didn't know what interviewers actually expected me to understand. The truth most beginners discover too late? You don't need to know everything. You need to know the right things first. So I created this post to ask you, do you really know what you are doing? How well do you understand - The CIA Triad - Risk Management - Cryptography. Networking - IAM - Incident Response - Cloud Security - Detection Engineering (SIEM/EDR/XDR - Threat Modeling (STRIDE/PASTA) - Attack Surface Mapping - Vulnerability Research & Disclosure Identity Federation (SAML, OIDC, OAuth 2.0) - Role Based Access Control (RBAC) / (ABAC) - Privileged Access Management (PAM) - Multi Factor Authentication (MFA/FIDO2) - Indicators of Compromise (IoC) & Tactics, Techniques, and Procedures (TTPs) - Blast Radius Containment - Post-Mortem Root Cause Analysis (RCA) How well do you think you could defend yourself in an interview?




