Tuesday, June 16, 2026

AI Training You Can Take To Upskill Yourself

AI is the buzzword today, even in cybersecurity field. As tech professionals need to constantly upskill themselves, it is timely for us to learn AI too.

Don't know where to start? Here are the compilation of AI training courses you can take (will update from time to time):

Microsoft AI Skills Navigator (free) 

AWS Agentic AI Demonstrated (free)

Anthropic Academic (free)

Google Beginner: Introduction to Generative AI (free)

This learning path contains 5 courses:

  • Introduction to Generative AI (45 mins)
  • Introduction to Large Language Models (1 hour)
  • Introduction to Responsible AI (15 mins)
  • Prompt Design in Agent Platform (1 hour)
  • Responsible AI: Applying AI Principles with Google Cloud (2 hours)

Wednesday, December 25, 2024

How You Can Get Started in Cybersecurity Field


As the technology advances, cybersecurity has gained popularity and increased demand in recent years. Many media have reported that there are lack of cybersecurity professionals and many jobs have gone unfilled. If you're interested to join the cybersecurity field, here are the key steps you should do to get started:

1. Understand the Basics of Cybersecurity

Before diving into specialized areas, it’s important to have a solid understanding of what cybersecurity is and its role in protecting digital assets. Focus on these foundational concepts:

  • Confidentiality, Integrity, and Availability (CIA Triad): The core principles of cybersecurity.
  • Types of Cyber Threats: Malware, phishing, ransomware, and social engineering.
  • Basic Networking: Understand IP addresses, TCP/IP, DNS, VPNs, firewalls, and routers.

2. Get Familiar with Key Tools & Technologies

To be effective in the field, you need hands-on experience with the tools that cybersecurity professionals use. Some important tools to explore include:

  • Firewalls and Intrusion Detection Systems (IDS).
  • Encryption tools for data protection.
  • Security Information and Event Management (SIEM) platforms like Splunk or ELK Stack.
  • Vulnerability scanners such as Nessus or OpenVAS.
  • Penetration testing tools like Metasploit, Burp Suite, or Wireshark.

3. Choose a Specialization

Cybersecurity is a vast field, so narrowing down a specific area of interest can help. Some common specializations include:

  • Network Security: Protecting the network infrastructure and preventing unauthorized access.
  • Application Security: Securing software and applications from vulnerabilities.
  • Incident Response: Managing and responding to security breaches and incidents.
  • Threat Intelligence: Analyzing and understanding cyber threats and their origins.
  • Compliance and Risk Management: Ensuring organizations meet legal and regulatory requirements (e.g., GDPR, HIPAA).

4. Obtain Relevant Certifications

Certifications help validate your skills and demonstrate your competence to potential employers. Some well-recognized cybersecurity certifications include:

  • CompTIA Security+: A great entry-level certification that covers the basics of cybersecurity.
  • Certified Information Systems Security Professional (CISSP): For professionals with more experience.
  • Certified Ethical Hacker (CEH): Focuses on penetration testing and ethical hacking.
  • Certified Information Security Manager (CISM): Focuses on managing and governing cybersecurity programs.
  • Cisco Certified CyberOps Associate: Useful for those interested in network security.

5. Hands-On Practice

Cybersecurity is a practical field that requires hands-on skills. Set up a home lab or use online platforms to practice real-world scenarios. Some options include:

  • TryHackMe and Hack The Box: Interactive platforms with labs for practicing penetration testing and other skills.
  • Build a Home Lab: Set up virtual machines and test security tools and configurations in a controlled environment.
  • Open Source Tools: Play with open-source tools like Wireshark, Snort, or Kali Linux to improve your practical knowledge.

6. Stay Current with Threats and Trends

Cybersecurity is a constantly evolving field, with new threats emerging every day. To stay ahead:

  • Follow Cybersecurity Blogs and News Sites: Sources like Krebs on Security, Dark Reading, and Threatpost will help you stay informed.
  • Participate in Forums: Join cybersecurity communities like Reddit’s r/cybersecurity, or specialized forums like StackExchange or InfoSec World.
  • Attend Conferences & Webinars: Look for events like Black Hat, DEF CON, RSA, or local meetups to network and learn.

7. Build a Network

Building relationships with other professionals in the industry is vital for your growth:

  • LinkedIn: Engage with cybersecurity professionals on LinkedIn to learn from their experiences.
  • Local Meetups: Join local groups to meet people in person and exchange ideas.
  • Mentorship: Find a mentor in the field who can offer advice and help you grow.

8. Understand Cybersecurity Governance & Risk

As a leader, it's crucial to understand how to align cybersecurity strategies with business goals:

  • Cybersecurity Frameworks: Familiarize yourself with standards like NIST, ISO 27001, and the CIS Controls.
  • Risk Management: Understand how to assess, mitigate, and manage cybersecurity risks in an organization.
  • Compliance: Learn about laws and regulations like GDPR, HIPAA, and PCI-DSS.

9. Consider the Soft Skills

While technical skills are vital, soft skills are equally important for a successful cybersecurity career:

  • Communication Skills: You’ll need to explain complex technical issues to non-technical stakeholders.
  • Problem-Solving: Cybersecurity is about solving puzzles and identifying vulnerabilities.
  • Teamwork: Collaboration with other IT professionals, executives, and departments is key.
  • Attention to Detail: Cybersecurity requires a keen eye for identifying even the smallest security gaps.

10. Seek Entry-Level Opportunities

Start with entry-level roles to build experience. Some possible starting positions include:

  • Security Analyst: Monitoring and analyzing security systems.
  • Network Administrator: Managing and securing network infrastructure.
  • Incident Responder: Responding to and investigating security incidents.
  • SOC Analyst: Working in a Security Operations Center to monitor for threats.

11. Invest in Continuous Learning

The cybersecurity landscape is always changing, so continuous education is essential. Regularly take courses, read books, and participate in webinars to enhance your skills and stay relevant.

Conclusion

Cybersecurity is a dynamic, high-demand field, and getting started involves both acquiring the necessary technical expertise and developing a broader understanding of security concepts. It requires dedication, a continuous learning mindset, and the ability to adapt to new challenges. By following these steps, newcomers can lay a solid foundation and eventually build a successful career in cybersecurity.

Monday, December 23, 2024

Books I Used to Get My Cybersecurity Certifications

Disclaimer: I'm a big fan of Mike Chapple books and I've been using his books to prepare for all my three cybersecurity certifications CISSP, CCSP, CISM. I read the whole official study guide books and usually start to do the practice questions from the practice tests books 1 month before the actual exam day.


You can find the link to get the books from Amazon on each link.


 CISSP Official Study Guide (link included)



Read on how I prepared for my CISSP exam here


CISSP Official Practice Tests (link included)

I recommend to do practice tests around 1 month before the exam day.



CCSP Official Study Guide (link included)


Read on how I prepared for my CCSP here


CCSP Official Practice Tests (link included)




CISM Official Study Guide (link included)


My other post:

Things I do to stay relevant in tech/cybersecurity industry

Saturday, August 12, 2023

Things I Do to Stay Relevant in the Tech/Cybersecurity Industry

 I have been working in tech industry for more than 10 years and the past few years in Cybersecurity space. It's been a great journey so far. But tech and cybersecurity industries are like our galaxy. There are so many categories inside them and so much things to learn (this what excites me actually, everyday is learning day).


It's undeniable, the industry is so fast evolving everyday. There's always new innovations appear on the market. That's why, we, tech/cybersecurity workers, need to stay relevant as well. Here are few ways that I do to stay relevant in the fast-moving tech and cybersecurity industry.


1. Connect with people and follow relevant organisations/groups on LinkedIn

I got so much benefits from my circle on LinkedIn. I got to know about new vulnerabilities or new features update or relevant events from posts that my circle member posted or liked or shared. You'll be surprised by how information-rich your LinkedIn feed can be. 


2. Join relevant physical events and network with fellow professionals

I personally joined my professional body's local chapter and I've learned a lot from other experts. I got so much other opportunities as well which I wouldn't get if I never join the chapter, like hosting relevant events locally and regionally, both physically and virtually. And, it has expanded my network too, which I am grateful for. When I was affected by layoff last year, there were so many people reached out to me and extended their help.


3. Keep checking on job vacancies although you're not looking for a change

I always do this until now. Not only I get the glimpse of the salary market, but also what are the skills needed in the market for my current role or my next target role. This will help me to prepare on what skills to polish for the next 1-2 years time. By then, when I'm in the lookout for new job/opportunity, I know that I'm ready for my jump.


Hope my above two cents are useful for you. I'm interested to know what other ways you do to stay relevant in your industry. Feel free to share!

Sunday, September 18, 2022

The importance of cybersecurity awareness programs and it can be your first defense against cyber attacks

 Cyber attacks are getting sophisticated and growing in numbers everyday. Small medium businesses and healthcare are the new target of the cyber threat actors. Big companies are not escaping from attacks as well. A lot of cyber attacks in form of phishing and social engineering have been the main concern in the industry. This is why it's important that all staffs in your company are well-equipped with knowledge of various cyber attacks and how to protect themselves and the company. Cybersecurity awareness programs, if done in consistent and right way, can provide the company with strong defense against various cyber attacks.

There are few things that company can start doing in boosting the cybersecurity posture, such as having effective phishing campaigns, launching periodic cybersecurity awareness newsletter, reviewing and socializing company's security policies, and holding targeted cybersecurity training for specific groups of staff.

Effective Phishing Campaigns

In order to have effective phishing campaigns, they must take recent trending topics and are designed as close as possible to the actual email so staffs would naturally think that they are legitimate and "fall" for the suggested actions, such as clicking links, opening attachments or providing their credentials. Once the campaign ends, you can then send campaign closure email to all staffs and put some "hints" to help them identify phishing emails.

Cybersecurity Awareness Newsletter

It's good to have periodic newsletter about various domains in cybersecurity and remind all staffs on company's acceptable use policy. With these newsletters, all staffs will be reminded on what can and what can't be done when they are under your company's employment period and handling company's data.

Company's Security Policies

Policies are important to be established within the company as operational guidelines to safeguard the company's business continuity. Policies usually contain general clauses and standard or procedure documents can be created to have more detailed information related to the policies.

Targeted Cybersecurity Training Programs

Various training programs can be set with relevant content for different groups of people in the company. For example, you can setup secure coding practice workshop for developer team or third-party risk assessment workshop for procurement or sourcing team.

Cybersecurity awareness programs can be your first defense method in countering cyber threats. You can always start small by creating few basic policies, publishing some security related newsletters or posters, or launching a few simple phishing campaigns. Once you have done the first steps, you can review the results and consider improvements for next steps. 

Sunday, September 11, 2022

How Small Medium Businesses Can Improve Their Cybersecurity Posture

 


As a small business, you may not realize just how vulnerable your organization is to cyberattacks. A cyberattack can damage your business' reputation, disrupt operations and even lead to financial losses.

To protect your business, follow these tips:

1. Train your employees on best practices. A lack of cybersecurity awareness among employees can lead to compromised accounts and stolen data. Ensure that all employees understand your organization's security policies. You should also train your employees to recognize phishing emails and other forms of social engineering attacks.

2. Invest in tools that limit information loss, monitor your third-party risk and fourth-party risk exposure, and help you respond to incidents effectively. A comprehensive incident response plan can also help you minimize business disruption if an attack occurs. Theses tools and plans can also help you better manage compliance requirements and meet other industry regulations.

3. Develop an incident response plan. Incident response plans should address how your organization will respond to a cybersecurity incident. Incident response plans should address not only technical responses, but also legal, public relations, and executive communications. The plan should include appropriate communication steps for informing employees, customers, and third parties about the status of incident and how the organization is responding.

4. Implement secure systems. You should ensure that all of your critical IT systems are properly secured to reduce the risk of data breaches and other attacks. End-user systems should be at least protected by anti-virus. Servers should be behind a strong firewall and it should be updated regularly with the latest security patches and firmware. Password should be complex and changed regularly. Backups should be regularly tested to ensure data can be restored quickly in the event of an attack. 

5. Conduct regular risk assessments. Conducting regular risk assessments can help you identify potential risks and secure your sensitive data. You should conduct risk assessments on all of your systems, including computer system, wireless networks, physical systems and mobile devices.

6. Implement multi-factor authentication where possible as additional layer of protection, including for remote access, privileged users and critical assets. Most passwords can be easily cracked using password cracking tools or brute force attacks. Using multi-factor authentication can help protect your accounts from being hacked. In addition, it can also help reduce your risk of data breach by limiting access to systems and data from unauthorized users.

Thursday, September 8, 2022

Quiet Quitting in Cybersecurity May Not Work for Women


Quiet quitting has become a trend recently. Basically, people are just doing their bare minimum at work because they've been having burn out as a result of COVID's work from home culture which blur the work and life boundaries. 

To be honest, this is not something new. I've encountered some people doing this quiet quitting attitude in my previous workplace. They don't bother to pick up new projects to showcase their leadership or skills. They're not after the career advancement and they're content with where they are now.

But, can we do quiet quitting if we work in cybersecurity field, especially women? Firstly, women in cybersecurity has been outnumbered by men and they're treated unequally. Women are often assigned with non-meaningful tasks which don't contribute to their performance review nor career advancement. 

What I'm saying is women are already in unfair place, to begin with. I know women are in general burnt out because they need to take care both career and house chores. And joining the trend of quiet quitting seems to be tempting. But I believe it'll pose higher consequences to women if they're quiet quitting compare to men.

When women do quiet quitting, they will be labelled as slackers or under performer. There's bias that weighs towards bad impression once women stop doing extra. Unfortunately, this won't do women any good for their career advancement. Women will get pushed away from promotion although they're actually more capable than other men coworkers. 

What women can do?

I won't suggest women to take up more work when they're already burnt out and barely surviving. I suggest that women to continue working smarter, not harder. As much as possible, advocate for your work and yourself at work. Speak up when you have better ideas and don't afraid to be wrong (this is how you increase your visibility). Have growth mindset and think challenges as improvement opportunities.



Preparing for CISSP Exam

 I'm currently in the midst of preparing for the CISSP exam. I have been contemplating since last year whether I should go for CISSP exam (in the end I did my CCSP and I passed - read my post on the preparation here). This year I decided to prepare and take the CISSP exam.


Why I want to take the CISSP exam?

1. High Paying Jobs

I read many articles which mentioned that CISSP is always in the top 5 cybersecurity certifications to have high paying jobs.

2. Improving my cybersecurity knowledge

As a beginner in cybersecurity field, I definitely have a lot to catch up. My another intention is as I  prepare for CISSP, I can actually brush up my cybersecurity knowledge and fill the gaps that I have as much as possible.


What materials I use to prepare for the CISSP exam?

1. (ISC)2 CISSP Certified Information Systems Security Professional Official Study Guide

I bought the book and have been reading it since the beginning of my preparation. I think the book has good structure and there's definitely a lot of information on it. I think this book can be considered as the holy grail book when people are preparing for CISSP.


Buy CISSP Official Study Guide Bundle here at Amazon

2. LinkedIn Learning

I'm fortunate that my company provides LinkedIn Learning subscription to staffs so I actually watch the CISSP course by the same book author, Mike Chapple.


Saturday, September 3, 2022

How to earn extra CPEs to maintain your (ISC)2 certification



Once you get certified, it doesn't mean that you can sit back and relax.

There is requirement of 90 CPEs within 3 years to maintain your (ISC)2 certification.

Of course there are various ways to earn your CPEs. In this post, I would like to introduce you to free CPEs which you can earn at spare time.

(ISC)2 Immersive Course

(ISC)2 provides various immersive courses on their website. It's free for members and there are some courses in other languages too.


I did take one of them and it took me around 6 hours to complete. I got 4 CPEs from this one immersive course.

So it's worth to take these immersive courses if you need extra CPEs.

Sunday, August 28, 2022

My experience transferring money internationally using Wise

I want to share my experience with everyone on transferring money internationally using Wise. I've been away from my home country for a while now and often need to send money back to my parents occasionally. It's been quite a painful process before Wise (previously TransferWise. Yes, I've been their customer before they changed name).

Remitting money via banks or remittance service in Singapore are very tedious for me. And another point, the rates are not that good. Often they'll charge additional service fee that may eat up to the amount of money that you're going to send.

When Wise came up, I was originally skeptical on the service and whether they can be trusted. Anyway I did try out Wise with small amount of money first as a trial to understand their process and to check out their rates.

Few features that I like from Wise:

1. You can check the rate real-time and it's guaranteed for certain period of time.

2. You know how much you pay for the transfer fee and it's quite low compare to the banks.

3. You can see the fluctuation of the exchange rate in graph.

4. You know when the money will arrive to recipient's bank account.

5. When there's issue with your transaction, Wise will return your money fully, except the any fee incurred for transferring between your bank account to Wise account, if any.

6. There's a flowchart shown for your transaction as well so you know the current status of your transaction.




And, Wise is regulated by Monetary Authority of Singapore (MAS) and many other countries' authorities. 

I've transferred big amount of money to Indonesia and Canada so far and the experience is easy and fast.

If you want fuss free cross border transfer experience, try Wise




Saturday, August 27, 2022

My cybersecurity journey just started

 Last year, I decided to move to cybersecurity role after my maternity leave ended and joined a local bank in Singapore.

I was lucky that I had ex-colleague who refer me to the position of cyber solutioning as my stepping stone into the field.

It was a steep learning curve, definitely. A lot of new cybersecurity terms that I didn't know before and I needed to spend extra time to research on them. 

I would say it's not an easy beginning, added with postpartum depression that might kick in. 

I stumbled upon mentorship program organized by (ISC)2 Singapore Chapter and immediately registered for it. My mentor was great and smart. He provided me with information that I needed when I just started my cybersecurity job. He also encouraged me to take CCSP exam because I have recent background in cloud. I was so inspired that I signed up to be the chapter's volunteer. Check out the (ISC)2 Singapore Chapter website for more details on our activities.

If you want to know how I prepared for my CCSP exam, I wrote a short post about it. 

I decided to leave the bank after 10 months to joined a tech company as IT GRC (Governance Risk Compliance) analyst. Here I get exposure to different role in cybersecurity. It's been 5 months now, there's still a lot to learn for me. But I enjoy this part of cybersecurity for now.

I'll sure update more on this cybersecurity journey here at my blog. Stay tune! :) 



My CCSP Exam Preparation




 Hi folks,


I've passed my CCSP exam on Dec 2021 (few days before new year 2022) and I would like to share how I prepared for it.

First, I would like to recommend the bundle book by Ben Malisow. They greatly helped to prepare me for the CCSP exam.

1. Certified Cloud Security Professional (CCSP) Official Study Guide

I read this book for around 2 months to fill the gaps of my foundational knowledge, which I feel is important to do. I don't want to pass the exam just for the sake of passing, but instead, I want to master the knowledge.

2. Certified Cloud Security Professional (CCSP) Practice Tests

I focused doing the questions on this book for the last 1 month of my preparation. I would flip back and forth between the question page and answer page to confirm if my answer was correct. The explanation at the answer pages helped me to confirm my doubts or provided me necessary refresher.


Get 30% off if you're buying the bundle books here


Buy the CCSP Official Study Guide Bundle at Amazon

Is there a way to make my preparation cheaper?

If you're based in Singapore, good news, Singapore's National Library has comprehensive list of ebooks, and these books are available there. You can borrow each ebook for 21 days and renew them once for another 21 days.



Friday, March 12, 2021

Setting Up HTTP(S) Load Balancer in GCP

Disclaimer: This is note from my self learning in GCP and may not be correct or complete. Qwiklabs https://google.qwiklabs.com/focuses/10258?parent=catalog

 

In general these are the steps:

  • Create an instance template.
  • Create a target pool.
  • Create a managed instance group.
  • Create a firewall rule to allow traffic (80/tcp).
  • Create a health check.
  • Create a backend service, and attach the managed instance group.
  • Create a URL map, and target the HTTP proxy to route requests to your URL map.
  • Create a forwarding rule.
#create startup.sh script
cat << EOF > startup.sh
#! /bin/bash
apt-get update
apt-get install -y nginx
service nginx start
sed -i -- 's/nginx/Google Cloud Platform - '"\$HOSTNAME"'/' /var/www/html/index.nginx-debian.html
EOF




#create instance template
gcloud compute instance-templates create nginx-template \
   --metadata-from-file startup-script=startup.sh

#create a target pool
gcloud compute target-pools create nginx-pool 

#create a managed instance group
gcloud compute instance-groups managed create nginx-group \
   --template=nginx-template --size=2 --target-pool nginx-pool

#Create a firewall rule to allow traffic (80/tcp)
gcloud compute firewall-rules create www-firewall \
  --allow tcp:80

#Create a forwarding rule
gcloud compute forwarding-rules create nginx-fwd-rule \
        --ports=80 \
        --target-pool nginx-pool

gcloud compute forwarding-rules list

#Create a health check
gcloud compute http-health-checks create basic-check

gcloud compute instance-groups managed set-named-ports nginx-group --named-ports http:80

#Create a backend service, and attach the managed instance group
gcloud compute backend-services create web-backend-service \
        --protocol=HTTP \
        --port-name=http \
        --http-health-checks=basic-check \
        --global

gcloud compute backend-services add-backend web-backend-service \
        --instance-group=nginx-group \
        --instance-group-zone=us-east1-b \
        --global

#Create a URL map, and target the HTTP proxy to route requests to your URL map
gcloud compute url-maps create web-map-http \
        --default-service web-backend-service

gcloud compute target-http-proxies create http-lb-proxy \
        --url-map web-map-http

gcloud compute forwarding-rules create http-content-rule \
--global --target-http-proxy http-lb-proxy --ports 80


Deploying Kubernetes in GCP

 This is note of my self learning in GCP via Qwiklabs https://google.qwiklabs.com/focuses/10258?parent=catalog


#change zone

gcloud config set compute/zone us-east1-b


#to create a cluster (this step takes few minutes to complete)

gcloud container clusters create nucleus-cluster




#authentication

gcloud container clusters get-credentials nucleus-cluster



#deployment

kubectl create deployment nucleus-server --image=gcr.io/google-samples/hello-app:1.0


#service

kubectl expose deployment nucleus-server --type=LoadBalancer --port 8080


Tuesday, March 9, 2021

VPC Peering in AWS and GCP



The steps to do VPC peering in AWS and GCP are quite similar. You need to have these info:

In AWS

  • Account ID
  • Source and Target VPC ID
  • Permission
In GCP
  • Project ID
  • Source and Target VPC name
  • Permission

The below steps assume that the VPC peering are done on 2 different accounts (on AWS) or projects (on GCP) and both source and target VPC have been created prior.

How to do VPC peering in AWS:
You'll do configure the VPC peering in the source account first then followed with target account with similar steps.

1. Login to the source account.
2. Go to VPC > Peering Connections > Create Peering Connections.


3. Fill up the required information and click "Create Peering Connection" button. You'll see the review page. If the information is correct, proceed with the creation. 
4. You'll see your newly created peering status is "Pending Acceptance". Now login to the target account to accept the peering.
5. In the target account, go to VPC > Peering Connections. 
6. You'll see there's pending peering connection request. Choose on that entry and click button "Actions" > Accept Request.
7. The status should turn Active now.

*You may need to update the route table and security group entries if it's necessary.


How to do VPC peering in GCP:
You'll configure the VPC peering in the source project first then move on to the target project with the similar steps. 

  1. Go to the first/source project
  2. Go to VPC Networking > VPC Network Peering
  3. Click "Create Connection" > Continue
  4. Fill up the info and click button Create



You'll see the status is "Inactive" as you need to do the same steps on Target project.




You'll see the status is "Active" now.


You can confirm the peering by running this command in Cloud Shell:

gcloud compute routes list --project <target_project_id>

You should see entry with name starts with "peering-route" in the result.


Sunday, October 18, 2020

My Study Plan in Passing AWS Solutions Architect Associate (SAA-C02) Exam

 Hi Folks,


I'm happy to share that I've passed my AWS Solutions Architect Associate (SAA-C02) certification exam beginning of this month. At first I was prepared to fail as I thought I didn't put enough effort to prepare. If I'm allowed to have an excuse, it'll be due to my pregnancy. I'm currently 7 months pregnant and the struggles are getting real everyday. I keep feeling tired everyday and I can't seem to sit or walk too long, which I heard is common issues during pregnancies. While still working full-time (luckily at home), preparing to be first-time mother,  I took few hours after work everyday preparing for my AWS SAA-C02 exam. 

In this post, I would like to share with you what are the learning materials I used for the past few months studying for the AWS SAA-C02 exam. Hopefully it'll be useful for you.

1. [Book] AWS Certified Solutions Architect Study Guide by Ben Piper, David Clinton



Although this version is not the latest SAA-C02 materials, I did read this book to refresh some of the AWS cloud computing concepts. And I think it does help in a way, as there are some valid contents in the book. I borrowed this ebook from Singapore's National Library and read it after work until before sleep around 1-2 hours almost every weekdays for 1.5 months (if I don't remember wrongly).

2. [Online Course] Stephane Maarek's Ultimate AWS Certified Solutions Architect Associate 2020

I bought this course on Udemy when they're having sale. I watched the tutorial videos for 1-1.5 months everyday after work until before sleep and most weekends. I quite enjoyed this course as the explanation by Stephane was quite clear and not confusing. This course also have some hands-on demo so you know how actually to do it on AWS console. There are 2 practice exams included as well at the end of the course.



3. [Practice Exams] Jon Bonso's AWS Certified Solutions Architect Associate Practice Exams

I bought this practice exam from Udemy and used this for the last 1 month before my exam to gauge my readiness. There are total 6 practice exams, 65 questions each. And good thing is they're actually being updated regularly. I went through the practice exam 2 times each and make sure I have at least 80% passing grade. After every practice exam, I read through all questions explanation (whether I answered them correctly or not), just to make sure I got the concept correctly (means no guessing).


I hope my study plans above help you to prepare for the AWS SAA-C02 exam. 



Sunday, August 30, 2020

My New Journey As Cloud Engineer

 Hi all, 


It’s been a long time since I post on this blog. So much things happened and professionally I’ve grown so much. So I decided to write again to share with you my exciting new journey as cloud engineer.

Some background story

I quitted my job as network engineer (cum project manager) in a bank after 6 years with them. For the past 2 years I’ve been interested with learning cloud technology, especially AWS. I took up course on my own expense and went to take my AWS Solutions Architect Associate certification exam. I was fortunate that my hardwork in studying intensely for few months paid off. I passed the exam! I thought with this I would be able to convince my boss to start taking a look at cloud adoption. Little did I know it’s tough for a small employee like me (I was only promoted to AVP that time) to make influence. For the last half a year I stayed there, there’s slowly progress in cloud adoption but it’s not fast enough. I couldn’t focus on the cloud area because I still need to give my 110% for my main tasks in network team. And it’s exhausting. So I decided it was time for me to move to another company and pursued what I want.


The journey starts

I found my current job through a friend recommmendation. The role is cloud operations engineer. I’ve been in this position for 8 months now and I didn’t regret my decision to move here. In the beginning, it was a steep learning process for me. In previous company I used to handle projects with not much dynamics as what I find here. I did a lot of project budget, plan, schedule and vendor selection last time. but now I do more troubleshooting and analyzing logs. My previous company was more on preserved Asian culture, while here it’s fast moving global culture. I was scared that I couldn’t fit in, but luckily I got help from some colleagues. Another good thing, I got to learn so many AWS features which are hard to come by.


I do believe the cloud technology will be the main focus for the next 5 years and as IT professional we need to always keep up. Now I’m preparing to renew my AWS Solutions Architect Associate certificate. And I noticed so much have changed (or new features have been added) from the materials from 2 years ago.


Wish me luck in my study and I’ll write more on how I prepare for the exam in another post!


Saturday, December 3, 2016

Privacy Policy

This blog does not share personal information with third parties nor do we store any information about your visit to this blog other than to analyze and optimize your content and reading experience through the use of cookies.
You can turn off the use of cookies at anytime by changing your specific browser settings.
We are not responsible for republished content from this blog on other blogs or websites without our permission.
This privacy policy is subject to change without notice and was last updated on Dec 3, 2016. If you have any question, please contact me here.

Wednesday, July 27, 2016

Being "Learning Animals" or "Hungry Brains" Can Boost Your Career


Learning ability can boost your career 

I read an article on Inc.com by J.T. O'Donnell about one skill (I like to call it a trait) that could fast track your career in the next 10 years time. Currently, big companies observe that there is one specific important trait that successful employees have in common. Google and Ernst & Young call it "Learning Animals" skill and put this into criteria in recruiting new hires. People with "Learning Animals" or "Hungry Brains" skill constantly learn about new things. They are proactive in acquiring new knowledge and they have faster professional growth rate.


In a fast pace field like IT, I feel this skill is important to have. In technology, people can not acquire new knowledge today and expect this knowledge will keep them afloat in their career forever. Technology is a dynamic field. There is always new technology being developed everyday which makes the current technology obsolete in maybe three to five years time. That is why the IT certifications expire in three years in average and require you to renew or refresh with new ones. In order for you to be competitive in IT, you need to keep learning. For me, I aim for at least one certification or new skill every year.


There are few methods to upgrade your skills in IT:

1. Take course or certification exam in the field of your interest
This is one of the standard method in upgrading yourself in IT but this may be the most costly method of all.

2. Join the professional community, forum or interest group

3. Take online course in your spare time
Today online courses have emerged into one of the popular method of learning. You can get new knowledge with minimum cost, at your own place and most of the time, at your own pace. Some sites even offer online programs from prestigious school with certificate. What a deal!







Saturday, June 11, 2016

TS 15066 Technical Guideline on How Human Works with Robot

I remember watching science fiction movie by Will Smith I, Robot on how artificial intelligence can think itself and plot harmful things to human beings. It's such a terrifying situation but I believe it could happen in the future, when robots are growing in numbers and smarter than us.

Apparently, the robotic industries are not taking this into serious matter to protect human's safety. I read this article from Tech Republic about new guideline TS15066 on how human can work together with the collaborative robots.

Source: http://www.techrepublic.com/article/robotic-industries-association-manual-shows-how-robots-avoid-harm-to-humans-obeying-asimovs-law/