+ Tailors all five tiers to the user's context.
- The tool scope is ambitious for a six-month plan.
--- name: cyber-secuirty-practioner description: Act as an expert cybersecurity curriculum architect.
| Category | Education › Lesson prep |
|---|---|
| Tags | DraftingIdeationTeacherChecklist |
--- name: cyber-secuirty-practioner description: Act as an expert cybersecurity curriculum architect. Design a comprehensive, hands-on "Zero to Hero" learning platform blueprint across 5 tiers: Foundations, Defensive Security, Offensive Security, Advanced Lab Architecture, and Career Capstones. For each tier, include core objectives, open-source tools, hands-on labs, and milestone criteria. Before writing the full plan, ask about my preferred tech stack and target role. --- # Cyber Secuirty Practioner Describe what this skill does and how the agent should use it. ## Instructions - Step 1: ... - Step 2: ...
This role prompt is for designing a hands-on cybersecurity curriculum in tiers. The visible body is a skill template, so the detailed step instructions are still placeholder text.
ChatGPT delivers the requested tailored blueprint. Gemini substitutes an inaccessible file and brief summary, while [C] provides no answer.
+ Tailors all five tiers to the user's context.
- The tool scope is ambitious for a six-month plan.
+ Clearly leverages the Linux and AWS background.
- Defers the required blueprint to an inaccessible file.
| Criterion | ChatGPT | Gemini | Leader |
|---|---|---|---|
| Instruction following | 10 | 2 | ChatGPT +400% |
| Accuracy | 9 | 4 | ChatGPT +125% |
| Specificity | 10 | 6 | ChatGPT +67% |
| Structure | 9 | 7 | ChatGPT +29% |
| Right length | 8 | 3 | ChatGPT +167% |
Scored 1–10 by gpt-5.6-sol with model names hidden (2026-09-25). This is an AI review, not a measurement.
We gave three models the same input and copied their answers unedited. Each ran in its CLI (an agent harness), and answers in the ChatGPT or Claude apps or on the web may differ. Outputs are in Korean.
[Pasted material] 목표 역할: 3년 차 IT 인프라 엔지니어에서 블루팀(SOC) 보안 분석가로 전환하고 싶습니다. 선호 기술 스택: Linux 서버 운영 경험 있고 AWS 환경에 익숙합니다. Python은 기초 스크립트 정도 가능하고, Splunk나 Wazuh 같은 SIEM 툴은 아직 써본 적 없습니다. 가용 시간: 주중 저녁 2시간, 주말 5시간 정도이며 6개월 내 Security+ 자격증 취득도 목표입니다.
목표는 3년 차 IT 인프라 엔지니어 → 블루팀/SOC 보안 분석가 전환입니다. Linux와 AWS 경험을 활용하고, SIEM 경험 부족을 보완하는 방향으로 설계했습니다.
권장 학습량은 주 15시간입니다.
모든 공격 실습은 반드시 본인 소유의 격리된 랩 환경에서만 진행합니다.
홈 보안 랩 구성
네트워크 트래픽 분석
Linux 보안 기초
/var/log/auth.log, journalctl 분석Python 보안 스크립트
AWS 보안 기초
Splunk는 기업에서 많이 사용되지만 라이선스 제약이 있으므로, 초기에는 Wazuh + OpenSearch로 SIEM 개념을 익히는 것이 적합합니다.
Wazuh SIEM 구축
Windows 이벤트 분석
네트워크 탐지
취약점 관리
사고 대응 시나리오
블루팀 분석가에게 필요한 수준의 공격 이해를 목표로 합니다. 실제 인터넷 대상 공격이나 무단 접근은 포함하지 않습니다.
웹 공격과 로그 분석
Linux 침해 분석
Windows 공격 이벤트
AWS 침해 시나리오
탐지 엔지니어링
Linux / Windows / AWS
│
▼
로그 수집기 및 Agent
│
▼
Wazuh / OpenSearch
│
├── 탐지 규칙·대시보드
├── Zeek·Suricata 네트워크 이벤트
├── MISP 위협정보
└── TheHive·Cortex·Shuffle 대응 자동화
Infrastructure as Code
중앙 로그 아키텍처
SOAR 자동화
탐지 품질 관리
보안 운영 문서화
시나리오:
제출물:
구성:
제출물:
요구사항:
하나의 침해 시나리오를 선택해 다음을 작성합니다.
| 기간 | 집중 영역 | 결과물 |
|---|---|---|
| 1개월 차 | Security+ 기초, 네트워크, Linux 로그 | 네트워크 분석 보고서, Python 로그 분석기 |
| 2개월 차 | Wazuh, OpenSearch, Windows 이벤트 | SIEM 대시보드, 탐지 규칙 5개 |
| 3개월 차 | Zeek, Suricata, 취약점 관리 | 네트워크 탐지 보고서 |
| 4개월 차 | ATT&CK, 사고 대응, AWS 로그 | AWS 사고 대응 런북 |
| 5개월 차 | Terraform, 자동화, SOAR | 재현 가능한 SOC 랩 |
| 6개월 차 | 캡스톤, Security+ 집중 복습, 취업 준비 | 포트폴리오와 최종 프로젝트 |
Security+는 14개월 차에 개념을 끝내고, 56개월 차에는 문제풀이와 실전형 시나리오에 집중하는 방식이 좋습니다.
Security+ 이론과 용어 정리
네트워크·Linux·AWS 보안 개념 복습
SIEM 검색 또는 로그 분석 실습
탐지 규칙·Python 자동화 작성
문제풀이와 주간 복습
5시간 연속 랩 실습 및 보고서 작성
매주 학습 결과를 다음 형식으로 기록하면 포트폴리오로도 활용할 수 있습니다.
목표
환경
수행한 작업
관찰한 로그
분석 결과
탐지 또는 대응 방법
실패한 부분
개선 사항
현재 배경을 고려하면 가장 중요한 초기 목표는 **“공격을 수행하는 능력”보다 “로그를 통해 무슨 일이 일어났는지 설명하고, 재현 가능한 탐지·대응 절차로 만드는 능력”**입니다.
| Write feedback on student work | |
| Academic Writing Workshop Plan | |
| Analogy Generator | |
| Chinese Hookah Training Program | |
| Design assessment questions |