Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

27h 41mAdvanced2024-07-29

Authors

Jason Dion

Jason Dion

Cybersecurity Trainer at Dion Training Solutions

Dion Training Solutions LLC

Dion Training Solutions LLC

Course details

The CASP+ (CompTIA Advanced Security Practitioner+) (CAS-004) certification is a vendor-neutral certification that validates your knowledge and ability to conduct advanced-level cybersecurity skills. This certification tests your ability to implement solutions within cybersecurity policies and frameworks. CASP+ (CAS-004) is an advanced-level cybersecurity certification covering technical skills in security architecture and senior security engineering. The CompTIA Advanced Security Practitioner+ exam focuses on security architecture and engineering, to validate a technical leader's ability to assess cyber readiness and design and implement the proper solutions. In this comprehensive course, expert cybersecurity trainer Jason Dion helps you prepare to earn this certification, covering in depth each topic you will need to understand for the exam.

Skills covered

Network SecurityIncident ResponseCybersecurityCert Prep

Concepts

0. Introduction

  • 01 - Welcome
  • 02 - About the exam

1. Securing Networks

  • 03 - Securing networks
  • 04 - Switches
  • 05 - Routers
  • 06 - Wireless and mesh
  • 07 - Firewalls
  • 08 - Proxies
  • 09 - Gateways
  • 10 - IDS and IPS
  • 11 - Network access control
  • 12 - Remote access
  • 13 - Unified communication
  • 14 - Cloud vs. on-premises
  • 15 - DNSSEC
  • 16 - Load balancer

2. Securing Architectures

  • 17 - Securing architectures
  • 18 - Traffic mirroring
  • 19 - Network sensors
  • 20 - Host sensors
  • 21 - Layer 2 segmentation
  • 22 - Network segmentation
  • 23 - Server segmentation
  • 24 - Zero trust
  • 25 - Merging networks
  • 26 - Software-defined networking

3. Infrastructure Design

  • 27 - Infrastructure design
  • 28 - Scalability
  • 29 - Resiliency issues
  • 30 - Automation
  • 31 - Performance design
  • 32 - Virtualization
  • 33 - Containerization

4. Cloud and Virtualization

  • 34 - Cloud and virtualization
  • 35 - Cloud deployment models
  • 36 - Cloud service models
  • 37 - Deployment considerations
  • 38 - Provider limitations
  • 39 - Extending controls
  • 40 - Provisioning and deprovision
  • 41 - Storage models
  • 42 - Virtualization

5. Software Applications

  • 43 - Software applications
  • 44 - Systems development lifecycle
  • 45 - Software development lifecycle
  • 46 - Development approaches
  • 47 - Software assurance
  • 48 - Baselines and templates
  • 49 - Best practices
  • 50 - Integrating applications

6. Data Security

  • 51 - Data security
  • 52 - Data lifecycle
  • 53 - Data classification
  • 54 - Labeling and tagging
  • 55 - Deidentification
  • 56 - Data encryption
  • 57 - Data loss prevention (DLP)
  • 58 - DLP detection
  • 59 - Data loss detection

7. Authentication and Authorization

  • 60 - Authentication and authorization
  • 61 - Access control
  • 62 - Credential management
  • 63 - Password policies
  • 64 - Multifactor authentication
  • 65 - Authentication protocols
  • 66 - Federation
  • 67 - Root of trust
  • 68 - Attestation
  • 69 - Identity proofing

8. Cryptography

  • 70 - Cryptography
  • 71 - Privacy and confidentiality
  • 72 - Integrity
  • 73 - Compliance and policy
  • 74 - Data states
  • 75 - Cryptographic use cases
  • 76 - PKI use cases

9. Emerging Technology

  • 77 - Emerging technology
  • 78 - Artificial intelligence and machine learning
  • 79 - Deep learning
  • 80 - Big data
  • 81 - Blockchain distributed consensus
  • 82 - Passwordless authentication
  • 83 - Homomorphic encryption
  • 84 - Virtual and augmented reality
  • 85 - 3D printing
  • 86 - Quantum computing

10. Threat and Vulnerability Management

  • 87 - Threat and vulnerability management
  • 88 - Threat intelligence
  • 89 - Threat hunting
  • 90 - Intelligence collection
  • 91 - Threat actors
  • 92 - Threat management frameworks
  • 93 - Vulnerability management activities
  • 94 - Security Content Automation Protocol

11. Vulnerability Assessments

  • 95 - Vulnerability assessments
  • 96 - Penetration test
  • 97 - Pen test steps
  • 98 - Pen test requirements
  • 99 - Code analysis
  • 100 - Protocol analysis
  • 101 - Analysis utilities

12. Risk Reduction

  • 102 - Risk reduction
  • 103 - Deceptive technologies
  • 104 - Security data analytics
  • 105 - Preventative controls
  • 106 - Application controls
  • 107 - Security automation
  • 108 - Physical security

13. Analyzing Vulnerabilities

  • 109 - Analyzing vulnerabilities
  • 110 - Race conditions
  • 111 - Buffer overflows
  • 112 - Authentication and references
  • 113 - Ciphers and certificates
  • 114 - Improper headers
  • 115 - Software composition
  • 116 - Vulnerable web applications

14. Attacking Vulnerabilities

  • 117 - Attacking vulnerabilities
  • 118 - Directory traversals
  • 119 - Cross-Site Scripting (XSS)
  • 120 - Cross-site request forgery (CSRF)
  • 121 - SQL injections
  • 122 - XML injections
  • 123 - Other injection attacks
  • 124 - Authentication bypass
  • 125 - VM attacks
  • 126 - Network Attacks
  • 127 - Social engineering

15. Indicators of Compromise

  • 128 - Indicators of compromise
  • 129 - Types of IoCs
  • 130 - PCAP files
  • 131 - NetFlow
  • 132 - Logs
  • 133 - IoC notifications
  • 134 - Response to IoCs

16. Incident Response

  • 135 - Incident response
  • 136 - Triage
  • 137 - Communication plan
  • 138 - Stakeholder management
  • 139 - Incident response process
  • 140 - Playbooks

17. Digital Forensics

  • 141 - Digital forensics
  • 142 - Forensic process
  • 143 - Chain of custody
  • 144 - Order of volatility
  • 145 - Forensic analysis

18. Digital Forensic Tools

  • 146 - Digital forensic tools
  • 147 - Forensic workstations
  • 148 - File carving tools
  • 149 - Binary analysis tools
  • 150 - Forensic analysis tools
  • 151 - Imaging tools
  • 152 - Collection tools

19. Enterprise Mobility

  • 153 - Enterprise mobility
  • 154 - Enterprise mobility management
  • 155 - WPA3
  • 156 - Connectivity options
  • 157 - Security configurations
  • 158 - DNS protection
  • 159 - Deployment options
  • 160 - Reconnaissance concerns
  • 161 - Mobile security

20. Endpoint Security Controls

  • 162 - Endpoint security controls
  • 163 - Device hardening
  • 164 - Patching
  • 165 - Security settings
  • 166 - Mandatory access controls (MAC)
  • 167 - Secure boot
  • 168 - Hardware encryption
  • 169 - Endpoint protections
  • 170 - Logging and monitoring
  • 171 - Resiliency

21. Cloud Technologies

  • 172 - Cloud technologies
  • 173 - Business continuity and disaster recovery
  • 174 - Cloud encryption
  • 175 - Serverless computing
  • 176 - Software-defined networking (SDN)
  • 177 - Log collection and analysis
  • 178 - Cloud application security broker
  • 179 - Cloud misconfigurations

22. Operational Technologies

  • 180 - Operational technologies
  • 181 - Embedded systems
  • 182 - ICS and SCADA
  • 183 - ICS protocols
  • 184 - Industries and sectors

23. Hashing and Symmetric Algorithms

  • 185 - Hashing and symmetric algorithms
  • 186 - Hashing
  • 187 - Message authentication
  • 188 - Symmetric algorithms
  • 189 - Stream ciphers
  • 190 - Block ciphers

24. Asymmetric Algorithms

  • 191 - Asymmetric algorithms
  • 192 - Using asymmetric algorithms
  • 193 - SSL, TLS, and cipher suites
  • 194 - S MIME and SSH
  • 195 - EAP
  • 196 - IPSec
  • 197 - Elliptic curve cryptography (ECC)
  • 198 - Forward secrecy
  • 199 - Authenticated encryption with associated data (AEAD)
  • 200 - Key stretching

25. Public Key Infrastructure

  • 201 - Public key infrastructure
  • 202 - PKI components
  • 203 - Digital certificates
  • 204 - Using digital certificates
  • 205 - Trust models
  • 206 - Certificate management
  • 207 - Certificate validity - CRL and OCSP
  • 208 - Protecting web traffic
  • 209 - Troubleshooting certificates
  • 210 - Troubleshooting keys

26. Data Considerations

  • 211 - Data considerations
  • 212 - Data security
  • 213 - Data classification
  • 214 - Data types
  • 215 - Data retention
  • 216 - Data destruction
  • 217 - Data ownership
  • 218 - Data sovereignty

27. Risk Management

  • 219 - Risk management
  • 220 - Risk strategies
  • 221 - Risk management lifecycle
  • 222 - Risk types
  • 223 - Risk handling
  • 224 - Risk tracking
  • 225 - Risk assessment
  • 226 - When risk management fails

28. Policies and Frameworks

  • 227 - Policies and frameworks
  • 228 - Policies
  • 229 - Frameworks
  • 230 - Regulations
  • 231 - Standards
  • 232 - Contracts and agreements
  • 233 - Legal considerations
  • 234 - Integrating industries

29. Business Continuity

  • 235 - Business continuity
  • 236 - Business continuity plan
  • 237 - Business impact analysis
  • 238 - Privacy impact analysis
  • 239 - Incident response plan
  • 240 - Testing plans

30. Risk Strategies

  • 241 - Risk strategies
  • 242 - Asset value
  • 243 - Access control
  • 244 - Aggregating risk
  • 245 - Scenario planning
  • 246 - Security controls
  • 247 - Security solutions
  • 248 - Cost of a data breach

31. Vendor Risk

  • 249 - Vendor risk
  • 250 - Business models
  • 251 - Influences
  • 252 - Organizational changes
  • 253 - Shared responsibility model
  • 254 - Viability and support
  • 255 - Dependencies
  • 256 - Considerations
  • 257 - Supply chain

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal