CASP+ (CAS-004) Cert Prep: 3 Security Engineering and Cryptography

CASP+ (CAS-004) Cert Prep: 3 Security Engineering and Cryptography

6h 18mIntermediate2022-05-10

Authors

Jason Dion

Jason Dion

Cybersecurity Trainer at Dion Training Solutions

Course details

The CASP+ (CompTIA Advanced Security Practitioner+) (CAS-004) certification is a vendor-neutral certification that validates your knowledge and ability to conduct advanced-level cybersecurity skills. Designed for the advanced-level technical cybersecurity professional certification, the certification exam tests your ability to implement solutions within cybersecurity policies and frameworks. This third course in the series from information technology and cybersecurity expert Jason Dion focuses on security engineering and cryptography topics covered in the exam. After a brief review of the prerequisite courses, Jason dives into topics covering enterprise mobility, endpoint security controls, cloud technologies, symmetric and asymmetric algorithms, and public key infrastructure.

Skills covered

CryptographyCert PrepCybersecurity

Concepts

Introduction

  • Welcome
  • About the exam

Enterprise Mobility

  • Enterprise mobility
  • Enterprise mobility management
  • WPA3
  • Connectivity options
  • Security configurations
  • DNS protection
  • Deployment options
  • Reconnaissance concerns
  • Mobile security

Endpoint Security Controls

  • Endpoint security controls
  • Device hardening
  • Patching
  • Security settings
  • Mandatory access controls (MAC)
  • Secure boot
  • Hardware encryption
  • Endpoint protections
  • Logging and monitoring
  • Resiliency

Cloud Technologies

  • Cloud technologies
  • Business continuity and disaster recovery
  • Cloud encryption
  • Serverless computing
  • Software-defined networking (SDN)
  • Log collection and analysis
  • Cloud application security broker
  • Cloud misconfigurations

Operational Technologies

  • Operational technologies
  • Embedded systems
  • ICS and SCADA
  • ICS protocols
  • Industries and sectors

Hashing and Symmetric Algorithms

  • Hashing and symmetric algorithms
  • Hashing
  • Message authentication
  • Symmetric algorithms
  • Stream ciphers
  • Block ciphers

Asymmetric Algorithms

  • Asymmetric algorithms
  • Using asymmetric algorithms
  • SSL, TLS, and cipher suites
  • S MIME and SSH
  • EAP
  • IPSec
  • Elliptic curve cryptography (ECC)
  • Forward secrecy
  • Authenticated encryption with associated data (AEAD)
  • Key stretching

Public Key Infrastructure

  • Public key infrastructure
  • PKI components
  • Digital certificates
  • Using digital certificates
  • Trust models
  • Certificate management
  • Certificate validity - CRL and OCSP
  • Protecting web traffic
  • Troubleshooting certificates
  • Troubleshooting keys

Conclusion

  • Conclusion
120,000 Toman