CISSP Cert Prep (2021): 5 Identity and Access Management

CISSP Cert Prep (2021): 5 Identity and Access Management

2h 17mAdvanced2021-03-12

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Are you getting ready for the Certified Information Systems Security Professional (CISSP) exam, or perhaps an experienced information security professional who wants to learn more about identity and access management? In this course, instructor Mike Chapple provides you with the detailed information you need to prepare for the Identify and Access Management domain of the 2021 CISSP exam. Mike begins by explaining identification, including usernames, access cards, biometrics, and more. He explains authentication factors, multifactor authentication, and password authentication protocols, then goes into access control systems and authentication services. Mike covers how to manage sessions and a variety of account types and roles. He helps you understand authorization and the controls you may use to manage authorizations. In closing, Mike goes over different access control attacks you may encounter and how these attacks work.

Skills covered

Identity and Access ManagementCert PrepCybersecurity

Concepts

Introduction

  • Identity and access management
  • What you need to know
  • Study resources

Identification

  • Identification, authentication, and authorization
  • Usernames and access cards
  • Biometrics
  • Registration and identity proofing

Authentication

  • Authentication factors
  • Multifactor authentication
  • Something you have
  • Password authentication protocols
  • Single sign-on and federation
  • RADIUS and TACACS
  • Kerberos and LDAP
  • SAML
  • Identity as a service IDaaS
  • OAuth and OpenID Connect
  • Certificate-based authentication

Accountability

  • Accountability
  • Session management

Account Management

  • Understand account and privilege management
  • Account types
  • Account policies
  • Password policies
  • Manage roles
  • Account monitoring
  • Privileged access management
  • Provisioning and deprovisioning

Authorization

  • Understand authorization
  • Mandatory access controls
  • Discretionary access controls
  • Access control lists
  • Database access control
  • Advanced authorization concepts

Access Control Attacks

  • Social engineering
  • Impersonation attacks
  • Identity fraud and pretexting
  • Watering hole attacks
  • Physical social engineering

Conclusion

  • Continuing your preparation
80,000 Toman