Over 71,000 students

EXIN Cyber & IT Security Foundation – CISEF

Official EXIN

  • Duration: 16 hours
  • Portuguese and English
5.0 · PeopleCert Pass Rate 99%

Corporate training clients

About the course

About the Course

Please note that the CISEF (Cyber & IT Security Foundation) course and exam will be discontinued on our platform as of 31/12/2026, as EXIN is retiring this certification from its product portfolio.

The course will no longer be available to new students.

The CISEF exam will no longer be offered by EXIN.

The Cyber & IT Security Foundation preparatory training, delivered live from 31/07/2021 to 03/08/2021, covers the core content for the certification, including the CISEF book, and aims to explain:

How computer architecture and operating systems work;

How security works in a computer's systems;

The structure of the IT security policy;

How to explain data classification standards;

Why the user is the weakest point in the security of an IT infrastructure.

Basic training book on Ethical Hacking Fundamentals

ITIL Foundation course dashboard
71k+ Certified students
99% Exam pass rate
15+ Years of excellence
500+ Corporates served

Who should attend

Target Audience

Exam language: Portuguese and English

Number of questions: 40 questions

Test duration: 1 hour

Passing grade: 65% (26/40)

Difficulty level: Easy

Prerequisites: EXIN strongly recommends the CISEF preparatory course

Open-book exam: No

Exam format: Online

Certification & exam

Exam and Certification

This course prepares you for the official EXIN CISEF certification exam.

Exam language
Portuguese and English
Number of questions
40 questions
Test duration
1 hour
Passing grade
65% (26/40)
Difficulty level
Easy
Prerequisites
EXIN strongly recommends the CISEF preparatory course
Open-book exam
No
Exam format
Online
  • 99

    Pass rate among PMG Academy students

    Our students consistently outperform global averages. The content is developed by the official translator of the PeopleCert exam itself.

  • 1y

    Exam voucher validity

    Your included PeopleCert exam voucher is valid for 12 months, giving you full flexibility to schedule when you’re ready.

  • T2

    Take2 re-sit option available

    Optional Take2 re-sit and PeopleCert Plus Membership are available at checkout for complete peace of mind.

Adriano Martins Antonio, ITIL Master and course instructor

About the instructor

About the Instructor

15 years of training excellence with over 71,000 students who have passed.

Adriano is an ITIL Master, consultant and author of 6 books, bringing 25 years of experience and more than 50 certifications in IT Management, Security and Governance. As the leader of the largest ITSM and DPSM community (over 220,000 YouTube subscribers), he combines his MBA from FGV — one of the world's leading business schools — with a specialization in Neuroscience to guide a global network of more than 71,000 students. His mission is clear: to demystify complex management and turn technical knowledge into tangible value and market impact.

Official translator of the ITIL Foundation Guide (Version 5)

71k+
Students trained
220k
YouTube subscribers
25y
Years of experience

Curriculum

What you will learn

  • Duration: 16 hours
  • 10 modules
  • Knowledge test per module
  • Official PeopleCert aligned
  • 00 Module 0 - Course introduction 8 lessons
    • About the course
    • About the instructor
    • About EXIN
    • About the certification
    • About the exam
    • Literature
    • Security study path
    • Cybersecurity: a matter of survival
  • 01 Module 1 - Introduction to Cyber Security / Computer Systems 19 lessons
    • Objectives
    • Computer architecture and operating systems
    • Components of a computing system
    • The evolution of operating systems
    • How does an operating system work?
    • Main operating systems
    • Security in computer systems
    • Risks, Threats, and Vulnerabilities
    • Examples of computer system security measures
    • Examples of computer system security measures
    • Principles of the A-I-C triad in IT infrastructures
    • Integrity
    • Confidentiality
    • Security controls that ensure confidentiality
    • Availability
    • Availability metrics
    • IT security policy structure
    • Data Classification Standards
    • User – The Weakest Link in the Security of an IT Infrastructure!
  • 02 Module 2 - Security in IT Infrastructures | The 7 Domains 37 lessons
    • Objectives
    • User Domain
    • How does the user domain work?
    • Responsibilities in the user domain
    • Relationship: risks, threats, vulnerabilities vs. mitigation strategies in the user domain
    • Workstation domain
    • How does the workstation domain work?
    • Responsibilities in the workstation domain
    • Relationship: risks, threats, vulnerabilities vs. Mitigation strategies in the workstation domain
    • LAN Domain
    • The physical components of the LAN domain
    • Logical elements of the LAN domain
    • How the LAN domain works
    • Responsibilities in the LAN domain
    • Relationship: risks, threats, vulnerabilities vs. mitigation strategies in the LAN domain
    • Lan-to-Wan Domain
    • Lan-to-Wan domain – examples of TCP and UDP ports
    • How does the Lan-to-Wan domain work?
    • Responsibilities in the Lan-to-Wan domain
    • Relationship: risks, threats, vulnerabilities vs. Mitigation strategies for the LAN-to-WAN domain
    • WAN Domain
    • How does the Wan domain work?
    • Responsibilities in the Wan domain
    • Relationship: risks, threats, vulnerabilities vs. WAN domain mitigation strategies
    • WAN domain – security issues with Internet providers
    • Security issues in the connectivity provided by the provider for the WAN domain
    • Remote access domain
    • How does the remote access domain work?
    • Responsibilities in the remote access domain
    • Security controls in the remote access domain
    • Relationship: risks, threats, vulnerabilities vs. Remote Access Domain Mitigation Strategies
    • System/application domain
    • How does the system/application domain work?
    • Responsibilities in the system/application domain
    • Data – the treasure stored in the System/Application Domain
    • Relationship: risks, threats, vulnerabilities vs. Mitigation strategies for the system/application domain
    • The importance of security controls
  • 03 Module 3 - Applications and Databases / Security Issues and Countermeasures 25 lessons
    • Objectives
    • About Application Development
    • Types of applications
    • Types of system architectures
    • Systems development lifecycle methods
    • System Lifecycle (SLC)
    • Systems Development Life Cycle (SDLC)
    • Phases of Systems Development Life Cycles
    • A little more about equipment disposal
    • About system testing
    • Certification and accreditation
    • Certification
    • Accreditation
    • Waterfall Model
    • Traditional (waterfall) model vs. Agile methods
    • Security issues in the systems development lifecycle
    • Database
    • SQL language types
    • Database Management System (DBMS)
    • OWASP Top 10 Vulnerabilities
    • Top 10 countermeasures for OWASP vulnerabilities
    • Still on vulnerabilities…
    • SQL Injection
    • Examples of SQL Injection
    • Relevant aspects of security in the software development lifecycle
  • 04 Module 4 - TCP/IP Networks 42 lessons
    • Objectives
    • The evolution of telecommunications
    • Protocol
    • TCP and IP
    • Other Types of Protocols – IPv4 and IPv6
    • Other Types of Protocols – HTTP
    • Other Types of Protocols – IPSec
    • Other Types of Protocols – SSH and SSL
    • Other Types of Protocols – TLS, DNS, VNC, and S/MIME
    • Other Types of Protocols – VOIP, SNMP, SMTP, and POP3
    • Other Types of Protocols – UDP, FTP, ARP, and Challenge and Response
    • Other Types of Protocols – ETHERNET
    • Addressing – IP
    • ICMP, Ping, and Traceroute
    • ICMP – Smurf Attack
    • Nodes
    • Hubs and Switches
    • Routers
    • Configuring a router
    • Node connection
    • Elements of the star topology
    • OSI Model
    • Layers of the OSI model and their functions
    • How protocols work in the layers
    • Network security risk categories
    • Risk category – network reconnaissance
    • Risk category – network sniffing
    • Risk category – network denial of service
    • Firewall – rules
    • Firewall
    • Firewall deployment techniques – Edge firewalls
    • Firewall deployment techniques – Filtered subnet (DMZ) firewalls
    • Firewall deployment techniques – Multilayer firewalls
    • VPN
    • VPN Technology
    • Network Access Control (NAC)
    • Wireless networks
    • Wireless networks – Wireless Access Points (WAP)
    • Wireless networks – the danger is in the air…
    • Wireless network security controls – wireless encryption
    • Beacon SSID
    • MAC Address Filtering
  • 05 Module 5 - Cloud Computing 21 lessons
    • Objectives
    • Characteristics of cloud computing
    • Cloud deployment models – Private cloud
    • Cloud deployment model – Community cloud
    • Cloud deployment model – Public cloud
    • Hybrid cloud model
    • Cloud service models/types
    • SaaS (Software as a Service)
    • PaaS (Platform as a Service)
    • Usability and advantages of PaaS
    • IaaS (Infrastructure as a Service)
    • PaaS ≠ IaaS
    • SECaas (Security as a Service)
    • IDaaS (Identity as a Service)
    • Baas (Backup as a Service)
    • The risks of cloud computing – encryption
    • The risks of cloud computing – data storage and archiving and APIs
    • The risks of cloud computing – customer vs. Provider relationship and provider assurance
    • The risks of cloud computing – vendor lock-in
    • Managing risks
    • Risk = Threats vs. Vulnerabilities
  • 06 Module 6 - Cryptography 35 lessons
    • Objectives
    • A bit of the history of Cryptography
    • Kerckhoffs Principle
    • Basic Concepts and Definitions in the Cryptographic Process
    • Basic concepts and definitions in the cryptographic process
    • Types of ciphers
    • Transposition ciphers
    • Substitution ciphers
    • Substitution ciphers – Vigenère Cipher and Vernam Cipher
    • Substitution ciphers – One-way function
    • Encryption methodologies – Symmetric cryptography vs. Asymmetric cryptography
    • Symmetric Encryption – Symmetric Confidentiality Process
    • Examples of symmetric cryptography
    • Asymmetric cryptography – Confidentiality
    • Asymmetric cryptography – Authenticity
    • Advantages and disadvantages of asymmetric cryptography
    • Examples of asymmetric cryptography
    • Cryptography in information security – Confidentiality
    • Cryptography in information security – Integrity
    • Cryptography in information security – Authentication
    • Cryptography in information security – Non-repudiation
    • Business and Security Requirements for Cryptography
    • Cryptanalysis
    • Cryptanalysis – Objectives and Tools
    • How do digital signatures provide authenticity and non-repudiation?
    • About non-repudiation
    • How hashing can provide the integrity of digital information
    • The main hash standards
    • Public Key Infrastructure (PKI)
    • Public Key Infrastructure (PKI) – processes
    • Digital certificates
    • Digital certificates – x.509v3 standard
    • SSL/TLS technologies and practical examples
    • IPsec technologies and practical examples
    • What can we conclude about cryptography in information security?
  • 07 Module 7 - Identity and Access Management 17 lessons
    • Objectives
    • Identity and Access Management – Concept
    • Identification vs. Authentication
    • Identification vs. Authentication
    • Main Authentication technologies and two-factor authentication
    • Biometrics
    • Single Sign-On (SSO)
    • Advantages of SSO
    • Disadvantage of SSO
    • Password Management
    • Authorization in Access Management and Identity
    • Usability principles
    • Usability principles vs. Authorization
    • Access controls
    • Physical access controls
    • Logical Access Controls
    • OPENID CONNECT and OAUTH Specifications and Functionality
  • 08 Module 8 - Exploiting Vulnerabilities 37 lessons
    • Objectives
    • Vulnerability – You need to know to mitigate
    • Malware
    • Examples of malware
    • Types of threats
    • Categories and types of attacks
    • Full Penetration – Trojan Horse
    • Full penetration – Backdoor and Spoofing
    • Full Penetration – Unicode Attack and Bypass Attack
    • Denial-of-service (DoS) attack
    • Not everything is an attack by...
    • Distributed Denial of Service (DDoS) attack
    • Theft or disclosure of information
    • Social engineering
    • Social engineering – Phishing
    • Social engineering – clues to identify phishing
    • Social engineering – Pharming
    • Other examples of attacks – Brute Force, Dictionary, and Repetition
    • Other examples of attacks – Masquerading, Espionage, and Smurf
    • Other examples of Hijacking attacks
    • White Hat Hacker = Ethical Hacker
    • Types of pentests – White Box (with full knowledge)
    • Types of pentests – Black Box (no knowledge)
    • Types of pentests – Grey Box (with limited knowledge)
    • Tools for pentests
    • Black Hat Hacker
    • (Black Hat Hacker) = “Cracker” Hacker
    • Grey Hat Hacker
    • Script Kiddies
    • Hacktivists
    • Tools used for cybercrime
    • Tools used for cybercrime – Vulnerability and port scanners
    • Tools used
    • For cybercrimes – Sniffers, wardialers, and keyloggers
    • How cybercriminals exploit vulnerabilities
    • Eight general preventive steps
    • Conclusion
  • 09 Module 9 - Preparatory Practice Exams 9 lessons
    • CISEF Practice Exam 1: 40 Questions
    • CISEF Mock Exam 2: 40 Questions
    • CISEF Mock Exam 3: 40 Questions
    • CISEF Mock Exam 4: 40 Questions
    • CISEF Mock Exam 5: 40 Questions
    • CISEF Mock Exam 6: 40 Questions
    • CISEF Mock Exam 7: 40 Questions
    • CISEF Practice Exam 8: 40 Questions
    • CISEF 9 Practice Exam: 40 Questions

Student reviews

Trusted by professionals at leading organizations

5.0 Based on 200+ reviews
  • 5★ 92%
  • 4★ 6%
  • 3★ 2%
  • 2★ 0%
  • 1★ 0%
  • Harry Feistauer

    Sicredi

    Curso extenso com muita informação, mas que na didática e metodologia do Adriano, torna a aprendizagem muito mais fácil. Recomendo sempre que tenho a oportunidade a PMG.

    13 de abril de 2026

  • Fellipe Baptista Teixeira de Lima

    Grupo IT.Demand Soluções

    Conteúdo bem completo. Parece que o curso foi ministrado a alguns anos atrás mas boa parte deste conteúdo ainda está bem atualizado.

    18 de fevereiro de 2026

Join professionals from these organizations

Impact

Training teams of 5 or more?

PMG Academy offers corporate licensing, team dashboards, progress tracking, and dedicated support — built around your organization’s schedule and compliance requirements.

local