Zero › Module 6 › Lesson 2
SASE Named
Secure Access Service Edge (SASE) literacy — converged network + security cloud — SASE capability map on YOUR $ZT_LAB.
Visual · t40_sase_named
SASE named. $ZT_LAB. Original Cyberlium.
Opening
SASE bundles ZTNA, SWG, CASB, FWaaS, SD-WAN literacy — map capabilities to LAB-ZT-001 hybrid workforce without acronym soup slides only.
Gartner SASE: cloud-delivered secure access combining ZTNA, Secure Web Gateway, Cloud Access Security Broker, firewall-as-a-service, SD-WAN. Single vendor vs best-of-breed literacy tradeoff on checklist row. Write SASE capability map: which functions LAB-ZT-001 needs now vs later — fictional maturity. Next: VPN vs ZTNA.
1. SASE capabilities (named)
ZTNA: private app access. SWG: web filtering/SSL inspect literacy. CASB: SaaS shadow IT visibility. FWaaS: edge firewall cloud. SD-WAN: branch connectivity.
Identity-centric policy ties functions together — not five siloed purchases.
Command guide
Try these commands — SASE capabilities (named)
═══ LINUX / macOS (Terminal Practice) ═══
Check system state and user context
Command — copy this
id whoami uname -a
Inspect network sockets listening for connections
Command — copy this
ss -tuln 2>/dev/null || netstat -tuln
Audit active processes
Command — copy this
ps aux | grep -v "\[" | head -15
═══ WINDOWS (POWERSHELL) ═══ Query user identity and system information
Command — copy this
whoami /all Get-ComputerInfo | Select-Object CsName, OsName, OsVersion
Primary tools to practice this lesson: grep, python3. Reference sites: CISA ZTMM Networks (https://www.cisa.gov/zero-trust-maturity-model); NIST SP 800-207 (https://csrc.nist.gov/publications/detail/sp/800-207/final). Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.
2. Deployment literacy
Branch office: SD-WAN + SWG. Remote user: ZTNA client. SaaS: CASB + IdP SSO. Pick primary pain for LAB-ZT-001 fictional hybrid org.
Document single-vendor vs multi-vendor decision factors — no vendor bash, design tradeoffs.
3. Capability map
Table: Capability | Need now? | Owner | Notes — five SASE rows for lab org.
Ship: SASE capability map. Next: VPN vs ZTNA.
4. What you ship: SASE capability map
Five capability rows with now/later and owner. $ZT_LAB fictional. chmod 600.
5. What you record before the next lesson
Date. SASE map. $ZT_LAB named. File t40-m06-l02-sase-named.txt chmod 600.
6. Wrong vs right: bypass cookbooks vs YOUR ZT design
Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.
Wrong
Label SASE as VPN with marketing rename only. Skip CASB because org is small in lab.
Right
Write SASE capability map with phased now/later rows. Next: VPN vs ZTNA.
Mission: SASE capability map
1) Define five SASE capabilities in your words. 2) Mark now vs later for LAB-ZT-001. 3) Assign fictional owner per row. 4) chmod 600.
Stuck? Ask Cyberlium AI Mentor
SASE is architecture pattern — not one mandatory SKU list.
Knowledge Check
APPLY: SASE converges:
Multiple choice
Knowledge Check
APPLY: True or False: CASB addresses SaaS visibility and control.
True or False
Knowledge Check
APPLY: SASE map on Cyberlium uses:
Multiple choice