This path follows the five Security+ domains and pairs each one with the practical side: how a real attack worked, what to patch first, how to check a domain’s mail and certificate settings, and how to find the lines that matter in a log.
The Advisory steps are real incidents and campaigns written up on this site. Read them for the pattern: how the attacker got in, and which control would have stopped it.