CompTIA Cybersecurity Analyst (CySA+) (CS0-003) Cert Prep (2024)
12h 57mAdvanced2024-07-30
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
Earning the CompTIA Cybersecurity Analyst+ (CySA+) certification demonstrates that you know how to address cybersecurity threats using an analytics-based approach. This course serves as a comprehensive, all-in-one resource for anyone preparing for the CS0-003 exam. Join University of Notre Dame professor and cybersecurity expert Mike Chapple as he shows you the skills you need to know to tackle the official exam. Mike starts with an overview and general information about the exam, and then goes into detail through each domain of the certification test.
Skills covered
Vulnerability ManagementNetwork SecurityIncident ResponseCert PrepCybersecurity
Concepts
Introduction
- About the CySA+ exam
- What's new in CS0-003
The CySA+ Exam
- Careers in information security
- Value of certification
- Stackable certifications
Inside the CySA+ Exam
- The CySA+ exam
- The CySA+ in-person exam environment
- At-home testing
- CySA+ question types
- Passing the CySA+ exam
Preparing for the CySA+ Exam
- Study resources
- Exam tips
- Continuing education requirements
Domain 1 - Security Operations
- Security Operations
Operating System Security
- The goals of information security
- Role of the cybersecurity analyst
- Operating system security
- Windows Registry
- Configuration files
- System processes
- Hardware architecture
Logging
- Logging security information
- Security information and event management
- Tuning and configuring SIEMs
- Continuous security monitoring
Infrastructure Concepts
- Virtualization
- Cloud infrastructure components
- Containers
Network Security
- Network architecture
- Security zones
- VLANs and network segmentation
- Zero-trust networking
- Secure access service edge (SASE)
- Software-defined networking (SDN)
Identity and Access Management
- Identification, authentication, authorization, and accounting
- Usernames and access cards
- Biometrics
- Authentication factors
- Multifactor authentication
- Something you have
- Password authentication protocols
- Single sign-on and federation
- Passwordless authentication
- Privileged access management
- Cloud access security brokers
Encryption
- Understanding encryption
- Symmetric and asymmetric cryptography
- Goals of cryptography
- Trust models
- PKI and digital certificates
- TLS and SSL
Sensitive Data Protection
- Data classification
- Data loss prevention
Indicators of Malicious Activity
- Network symptoms
- Rogue access points and evil twins
- Endpoint symptoms
- Application symptoms
- Obfuscated links
- Social engineering
Tools and Techniques
- Protocol analyzers
- DNS and IP reputation
- Endpoint monitoring
- Malware prevention
- Executable analysis
- Cuckoo and Joe Sandbox
- User account monitoring
Email Analysis
- Malicious email content
- Digital signatures
- DKIM, DMARC, and SPF
- Analyzing email headers
Programming and Scripting
- Shell and script environments
- APIs
- Querying logs
Understanding the Cybersecurity Threat
- Threat actors
- Zero-days and the APT
- Supply chain vulnerabilities
- Threat classification
Threat Intelligence
- Threat intelligence
- Managing threat indicators
- Intelligence sharing
- Threat research
- Identifying threats
- Automating threat intelligence
- Threat hunting
- Deception technologies
Efficiency and Process Improvement
- Standardizing processes and streamlining operations
- Technology and tool integration
Domain 2 - Vulnerability Management
- Vulnerability Management
Creating a Vulnerability Management Program
- What is vulnerability management
- Identify scan targets
- Scan frequency
Network Mapping
- Network scanning
- Install Nmap on Windows
- Install Nmap on macOS
- Run and interpret a simple Nmap scan
- Host discovery with Nmap
- Operate system fingerprinting
- Service version detection
Configuring and Executing Vulnerability Scans
- Security baseline scanning
- Scan configuration
- Scan perspective
- Scanner maintenance
- Vulnerability scanning tools
- Passive vulnerability scanning
Analyzing Scan Results
- SCAP
- CVSS
- Interpret CVSS scores
- Analyze scan reports
- Correlate scan results
Common Vulnerabilities
- Server vulnerabilities
- Endpoint vulnerabilities
- Network vulnerabilities
Software Security Issues
- OWASP Top 10
- Prevent SQL injection
- Understand cross-site scripting
- Request forgery
- Privilege escalation
- Directory traversal
- File inclusion
- Overflow attacks
- Cookies and attachments
- Session hijacking
- Race conditions
- Memory vulnerabilities
- Code execution attacks
- Data poisoning
- Third-party code
- Interception proxies
Specialized Technology Vulnerabilities
- Industrial control systems
- Internet of Things
- Embedded systems
More Cybersecurity Tools
- Exploitation frameworks
- Cloud auditing tools
- Debuggers
- Open-source reconnaissance
- Control frameworks
Software Development Lifecycle
- Software platforms
- Development methodologies
- Maturity models
- Change management
Secure Coding Practices
- Input validation
- Parameterized queries
- Authentication and session management issues
- Output encoding
- Error and exception handling
- Code signing
- Database security
- Data de-identification
- Data obfuscation
Software Quality Assurance
- Software testing
- Code security tests
- Fuzzing
- Reverse engineering software
- Reverse engineering hardware
Threat Modeling
- Threat research
- Identify threats
- Understand attacks
- Threat modeling
- Attack surface management
- Bug bounty
Security Governance
- Align security with the business
- Organizational processes
- Security roles and responsibilities
- Security control selection
Risk Management
- Risk assessment
- Quantitative risk assessment
- Risk treatment options
- Risk management frameworks
- Risk visibility and reporting
Domain 3 - Incident Response and Management
- Incident Response and Management
Incident Response Programs
- Build an incident response program
- Creating an incident response team
- Incident communications plan
- Incident identification
- Escalation and notification
- Mitigation
- Containment techniques
- Incident eradication and recovery
- Validation
- Post-incident activities
- Incident response exercises
Attack Frameworks
- MITRE ATT&CK
- Diamond model of intrusion analysis
- Cyber kill chain analysis
- Testing guides
Incident Investigation
- Logging security information
- Security information and event management
- Cloud audits and investigations
Forensic Techniques
- Conducting investigations
- Evidence types
- Introduction to forensics
- System and file forensics
- File carving
- Creating forensic images
- Digital forensics toolkit
- Operating system analysis
- Password forensics
- Network forensics
- Software forensics
- Mobile device forensics
- Embedded device forensics
- Chain of custody
- Ediscovery and evidence production
Business Continuity
- Business continuity planning
- Business continuity controls
- High availability and fault tolerance
Disaster Recovery
- Disaster recovery
- Backups
- Restoring backups
- Disaster recovery sites
- Testing BC DR plans
- After-action reports
Domain 4 - Reporting and Communication
- Reporting and Communication
Vulnerability Reporting and Communication
- Vulnerability communication
- Report scan results
- Prioritize remediation
- Create a remediation workflow
- Barriers to vulnerability remediation
- Vulnerability metrics
Incident Reporting and Communication
- Incident communications plan
- Incident identification
- Escalation and notification
- Post-incident activities
- Incident response reports
- Incident metrics and KPIs
Conclusion
- Continuing your studies