Domain Security Practitioner
The capstone, worked end to end on one estate: a full posture assessment, the impersonation exposure, the findings nobody can fix cleanly, a 30/90/365 plan with an explicit not-doing list, and delivering it to people who will act on it.
- lessons
- 16
- total
- 3 h
- level
- Advanced
Assumes Domain Trust Architecture.
You will be able to
- Assess a whole estate and produce a finding per domain with evidence
- Quantify an impersonation exposure from public data alone
- Handle a domain whose administrator cannot be contacted
- Sequence remediation around constraints you cannot remove
- Write a 30/90/365 plan with owners and go/no-go criteria
- Defend an explicit list of what you are not doing, and why
- Present the work so that the highest-value items actually get done
Syllabus
1. The Estate
A real-shaped organisation, and what a brief does and does not tell you.
2. The Assessment
Posture per domain, the impersonation exposure, and what the evidence actually supports.
3. The Findings Nobody Can Fix Cleanly
An unreachable agency, a signed zone you do not control, and a CNAME from 2024.
4. The Plan
Thirty, ninety and three hundred and sixty-five days, with owners and criteria.
5. What You Are Not Doing
The section that gets read after an incident, written before there is one.
6. Delivering It
Presenting the work so the highest-value items are the ones that get done.
7. Final assessment
15 scenario questions · 80% to pass · unlimited retakes
What the assessment covers
Domain Security Practitioner
- Complete every lesson in Domain Security Practitioner
- Pass the Domain Security Practitioner assessment with at least 80%
CertaDNS Engineering · last reviewed