Google Cybersecurity Certificate, Course 1: Foundations of Cybersecurity (Study Notes)
Plain-English notes for the first course: security roles, the CIA triad, threat actors, the 8 CISSP domains, ethics and laws, and a first look at SIEM tools and playbooks. Includes practice questions with explanations.
Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations and questions are original. Confirm current course content on the official Coursera page.
1. Course overview
Course 1 gives you the vocabulary and mindset for everything that follows. You learn what a security analyst actually does, why organisations need one, and which kinds of attackers and attacks they face. You also get a first taste of the tools (SIEM, packet sniffers) and of how security work is documented (playbooks).
Who it suits
Complete beginners, career changers, IT support staff moving toward security.
Prior knowledge
None needed beyond basic computer use.
Study tip
Explain each term aloud in one sentence. If you can’t, reread it.
2. Weekly breakdown (study plan)
This is a suggested five-part plan grouped by topic. Your course’s week titles may differ slightly, so follow the official order for graded work.
Part 1: What security is and what analysts do
- Cybersecurity means protecting networks, devices, people and data from unauthorised access or criminal use.
- Security analyst role: watch for suspicious activity, investigate alerts, respond to incidents, and help reduce risk. Related jobs: SOC analyst, vulnerability analyst, GRC analyst.
- Why it matters: a breach can cost money, trust, legal standing and sometimes safety.
- Transferable skills: communication, curiosity, attention to detail, problem solving.
Part 2: Threats, actors and attacks
A threat actor is whoever might cause harm. Their motive often tells you what they will target.
| Actor | Typical motive | Example |
|---|---|---|
| Cybercriminal | Money | Ransomware gang |
| Hacktivist | Political or social cause | Defacing a website |
| Nation-state / APT | Spying, disruption | Long-term quiet intrusion |
| Insider | Grievance, greed or carelessness | Employee copies client files |
| Script kiddie | Curiosity, bragging | Runs a downloaded tool |
Common attack types: phishing, malware (virus, worm, trojan, ransomware), social engineering, password attacks, supply chain attacks, web-based attacks such as SQL injection.
Part 3: The CIA triad and the 8 CISSP domains
CIA triad: Confidentiality (only the right people see data), Integrity (data is correct and unchanged), Availability (systems work when needed).
| # | Domain | Plain-English meaning |
|---|---|---|
| 1 | Security and Risk Management | Set goals, policies, laws and risk rules |
| 2 | Asset Security | Know what data you have and protect it through its life |
| 3 | Security Architecture and Engineering | Build systems securely from the start |
| 4 | Communication and Network Security | Protect data as it moves across networks |
| 5 | Identity and Access Management | Control who can get to what |
| 6 | Security Assessment and Testing | Check regularly that controls actually work |
| 7 | Security Operations | Monitor, investigate and respond day to day |
| 8 | Software Development Security | Write and review code safely |
Memory trick: “Really Awesome Analysts Can Identify Suspicious Odd Software” (Risk, Asset, Architecture, Communication, Identity, Assessment, Operations, Software).
Part 4: Ethics, privacy and laws
- Ethics: analysts see sensitive data, so they are expected to keep it confidential, respect privacy, act honestly, and use access only for approved work.
- Privacy protection: keeping personal information safe and using it only for its stated purpose.
- PII identifies a person (name, email). SPII is more sensitive (government ID numbers, financial account numbers). PHI is health information.
- Laws and standards to recognise: GDPR (EU privacy), HIPAA (US health data), PCI DSS (card payments), plus frameworks such as NIST CSF and ISO 27001.
- Security controls can be physical, technical or administrative; frameworks organise them into a plan.
Part 5: Tools, SIEM and playbooks
- SIEM: a tool that collects logs from many systems, correlates them and raises alerts. Think of it as a central dashboard for “what is happening across the company”.
- Playbook: a step-by-step guide for handling a type of situation, such as a phishing report. It keeps responses consistent and fast.
- Other tools: packet sniffers (e.g. Wireshark), intrusion detection systems, the Linux command line, SQL, Python.
- Frameworks help: they give analysts a shared structure so each incident is not handled from scratch.
3. 15 must-know terms
| Term | Plain meaning |
|---|---|
| Threat | Anything that could harm an asset |
| Vulnerability | A weakness a threat can use |
| Risk | Chance of loss when a threat meets a vulnerability |
| Asset | Anything valuable: data, devices, people |
| CIA triad | Confidentiality, integrity, availability |
| Threat actor | Person or group behind an attack |
| Social engineering | Tricking people instead of breaking systems |
| Phishing | Fake messages that lure you to share data or click |
| Malware | Software built to cause harm |
| Ransomware | Malware that locks data until payment |
| PII / SPII | Personal / especially sensitive personal data |
| Security control | A safeguard that reduces risk |
| SIEM | Central log collection and alerting tool |
| Playbook | Documented response steps for a scenario |
| Incident | An event that threatens security |
4. Three worked examples
Example 1: Map a scenario to the CIA triad
Scenario: A clinic’s appointment system is down for six hours after an attack.
Step 1: Ask what was affected: patients cannot reach their schedule. Step 2: That is access, so availability. Step 3: If attackers had also read records, add confidentiality. Answer: availability primarily; check confidentiality too.
Example 2: Identify the threat actor
Scenario: A contractor with valid login exports customer lists the day before leaving for a rival.
Reasoning: The person already has legitimate access and a personal motive. Answer: insider threat. Useful controls: least privilege, activity logging, off-boarding checks.
Example 3: Choose the right domain
Scenario: A company writes a rule that every new laptop must be encrypted before use.
Reasoning: Is it about who gets in (5), how code is written (8), or about building security into systems (3)? Encryption is a design requirement. Answer: Security Architecture and Engineering, with a link to Risk Management because it is also a policy.
5. Common mistakes
- Mixing up threat, vulnerability and risk. The threat is the danger, the vulnerability is the gap, the risk is the likelihood and impact of the two meeting.
- Thinking security is only technical. People and policy matter as much as tools; many breaches begin with a convincing email.
- Assuming all hackers are criminals. Ethical (authorised) testers exist; the difference is permission.
- Memorising domain names without examples. Attach one real task to each domain.
- Treating a SIEM alert as proof. An alert is a lead; analysts verify before escalating.
- Ignoring insiders. Not every threat comes from outside.
6. 10 practice questions (tap to reveal)
Q1. Which CIA element does hashing a file most directly support?
Integrity. Comparing a file’s hash before and after reveals whether it changed.
Q2. A thief steals an unencrypted laptop holding client records. Which CIA element is most at risk?
Confidentiality. Unauthorised people could read the data. Encryption is the key control.
Q3. Define a vulnerability and give one example.
A weakness that could be exploited, such as unpatched software or a reused password.
Q4. Which threat actor is typically motivated by a political cause?
Hacktivist. They aim for visibility or disruption rather than profit.
Q5. An email claims to be from IT and asks you to confirm your password via a link. What is this and what should you do?
Phishing. Do not click; report it through the official channel. Real IT teams rarely ask for passwords.
Q6. Which CISSP domain covers classifying and retaining data?
Asset Security (Domain 2). It deals with labelling, storing and disposing of data correctly.
Q7. Why might an organisation limit staff to the minimum access they need?
Least privilege reduces the damage from mistakes, stolen accounts and insiders.
Q8. Is a customer’s home address PII or SPII? What about a government ID number?
Home address is PII. A government ID number is SPII because misuse can cause serious harm.
Q9. What does a SIEM do that checking individual servers cannot?
It gathers logs from many sources into one place and correlates them, so patterns across systems become visible and alerts are raised.
Q10. Why are playbooks useful during an incident?
They give consistent, tested steps, so responders spend less time deciding what to do and make fewer errors under pressure.
7. YouTube search links
- Cybersecurity foundations for beginners
- CIA triad explained
- Types of threat actors
- CISSP 8 domains explained
- SIEM and playbooks in a SOC
8. One-screen revision summary
- Analyst job: monitor, detect, investigate, respond, reduce risk.
- CIA: Confidentiality (secret), Integrity (correct), Availability (accessible).
- Risk = threat meeting a vulnerability, weighed by impact.
- Actors: criminals, hacktivists, nation-states, insiders, novices.
- Attacks: phishing, malware, ransomware, social engineering, web attacks.
- 8 domains: Risk Mgmt, Asset, Architecture, Network, IAM, Assessment, Operations, Software Dev.
- Data: PII, SPII, PHI; laws such as GDPR and HIPAA.
- Ethics: confidentiality, privacy, honesty, authorised use only.
- Tools: SIEM collects and correlates logs; playbooks standardise response.
9. What you should be able to do
Related pages
Educational summary for learners; not affiliated with Google or Coursera. Verify details against official course materials. Last reviewed: October 2026.
