CompTIA Cybersecurity Analyst (CySA+) (CS0-003) Cert Prep (2024)

CompTIA Cybersecurity Analyst (CySA+) (CS0-003) Cert Prep (2024)

12h 57mAdvanced2024-07-30

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Earning the CompTIA Cybersecurity Analyst+ (CySA+) certification demonstrates that you know how to address cybersecurity threats using an analytics-based approach. This course serves as a comprehensive, all-in-one resource for anyone preparing for the CS0-003 exam. Join University of Notre Dame professor and cybersecurity expert Mike Chapple as he shows you the skills you need to know to tackle the official exam. Mike starts with an overview and general information about the exam, and then goes into detail through each domain of the certification test.

Skills covered

Vulnerability ManagementNetwork SecurityIncident ResponseCert PrepCybersecurity

Concepts

Introduction

  • About the CySA+ exam
  • What's new in CS0-003

The CySA+ Exam

  • Careers in information security
  • Value of certification
  • Stackable certifications

Inside the CySA+ Exam

  • The CySA+ exam
  • The CySA+ in-person exam environment
  • At-home testing
  • CySA+ question types
  • Passing the CySA+ exam

Preparing for the CySA+ Exam

  • Study resources
  • Exam tips
  • Continuing education requirements

Domain 1 - Security Operations

  • Security Operations

Operating System Security

  • The goals of information security
  • Role of the cybersecurity analyst
  • Operating system security
  • Windows Registry
  • Configuration files
  • System processes
  • Hardware architecture

Logging

  • Logging security information
  • Security information and event management
  • Tuning and configuring SIEMs
  • Continuous security monitoring

Infrastructure Concepts

  • Virtualization
  • Cloud infrastructure components
  • Containers

Network Security

  • Network architecture
  • Security zones
  • VLANs and network segmentation
  • Zero-trust networking
  • Secure access service edge (SASE)
  • Software-defined networking (SDN)

Identity and Access Management

  • Identification, authentication, authorization, and accounting
  • Usernames and access cards
  • Biometrics
  • Authentication factors
  • Multifactor authentication
  • Something you have
  • Password authentication protocols
  • Single sign-on and federation
  • Passwordless authentication
  • Privileged access management
  • Cloud access security brokers

Encryption

  • Understanding encryption
  • Symmetric and asymmetric cryptography
  • Goals of cryptography
  • Trust models
  • PKI and digital certificates
  • TLS and SSL

Sensitive Data Protection

  • Data classification
  • Data loss prevention

Indicators of Malicious Activity

  • Network symptoms
  • Rogue access points and evil twins
  • Endpoint symptoms
  • Application symptoms
  • Obfuscated links
  • Social engineering

Tools and Techniques

  • Protocol analyzers
  • DNS and IP reputation
  • Endpoint monitoring
  • Malware prevention
  • Executable analysis
  • Cuckoo and Joe Sandbox
  • User account monitoring

Email Analysis

  • Malicious email content
  • Digital signatures
  • DKIM, DMARC, and SPF
  • Analyzing email headers

Programming and Scripting

  • Shell and script environments
  • APIs
  • Querying logs

Understanding the Cybersecurity Threat

  • Threat actors
  • Zero-days and the APT
  • Supply chain vulnerabilities
  • Threat classification

Threat Intelligence

  • Threat intelligence
  • Managing threat indicators
  • Intelligence sharing
  • Threat research
  • Identifying threats
  • Automating threat intelligence
  • Threat hunting
  • Deception technologies

Efficiency and Process Improvement

  • Standardizing processes and streamlining operations
  • Technology and tool integration

Domain 2 - Vulnerability Management

  • Vulnerability Management

Creating a Vulnerability Management Program

  • What is vulnerability management
  • Identify scan targets
  • Scan frequency

Network Mapping

  • Network scanning
  • Install Nmap on Windows
  • Install Nmap on macOS
  • Run and interpret a simple Nmap scan
  • Host discovery with Nmap
  • Operate system fingerprinting
  • Service version detection

Configuring and Executing Vulnerability Scans

  • Security baseline scanning
  • Scan configuration
  • Scan perspective
  • Scanner maintenance
  • Vulnerability scanning tools
  • Passive vulnerability scanning

Analyzing Scan Results

  • SCAP
  • CVSS
  • Interpret CVSS scores
  • Analyze scan reports
  • Correlate scan results

Common Vulnerabilities

  • Server vulnerabilities
  • Endpoint vulnerabilities
  • Network vulnerabilities

Software Security Issues

  • OWASP Top 10
  • Prevent SQL injection
  • Understand cross-site scripting
  • Request forgery
  • Privilege escalation
  • Directory traversal
  • File inclusion
  • Overflow attacks
  • Cookies and attachments
  • Session hijacking
  • Race conditions
  • Memory vulnerabilities
  • Code execution attacks
  • Data poisoning
  • Third-party code
  • Interception proxies

Specialized Technology Vulnerabilities

  • Industrial control systems
  • Internet of Things
  • Embedded systems

More Cybersecurity Tools

  • Exploitation frameworks
  • Cloud auditing tools
  • Debuggers
  • Open-source reconnaissance
  • Control frameworks

Software Development Lifecycle

  • Software platforms
  • Development methodologies
  • Maturity models
  • Change management

Secure Coding Practices

  • Input validation
  • Parameterized queries
  • Authentication and session management issues
  • Output encoding
  • Error and exception handling
  • Code signing
  • Database security
  • Data de-identification
  • Data obfuscation

Software Quality Assurance

  • Software testing
  • Code security tests
  • Fuzzing
  • Reverse engineering software
  • Reverse engineering hardware

Threat Modeling

  • Threat research
  • Identify threats
  • Understand attacks
  • Threat modeling
  • Attack surface management
  • Bug bounty

Security Governance

  • Align security with the business
  • Organizational processes
  • Security roles and responsibilities
  • Security control selection

Risk Management

  • Risk assessment
  • Quantitative risk assessment
  • Risk treatment options
  • Risk management frameworks
  • Risk visibility and reporting

Domain 3 - Incident Response and Management

  • Incident Response and Management

Incident Response Programs

  • Build an incident response program
  • Creating an incident response team
  • Incident communications plan
  • Incident identification
  • Escalation and notification
  • Mitigation
  • Containment techniques
  • Incident eradication and recovery
  • Validation
  • Post-incident activities
  • Incident response exercises

Attack Frameworks

  • MITRE ATT&CK
  • Diamond model of intrusion analysis
  • Cyber kill chain analysis
  • Testing guides

Incident Investigation

  • Logging security information
  • Security information and event management
  • Cloud audits and investigations

Forensic Techniques

  • Conducting investigations
  • Evidence types
  • Introduction to forensics
  • System and file forensics
  • File carving
  • Creating forensic images
  • Digital forensics toolkit
  • Operating system analysis
  • Password forensics
  • Network forensics
  • Software forensics
  • Mobile device forensics
  • Embedded device forensics
  • Chain of custody
  • Ediscovery and evidence production

Business Continuity

  • Business continuity planning
  • Business continuity controls
  • High availability and fault tolerance

Disaster Recovery

  • Disaster recovery
  • Backups
  • Restoring backups
  • Disaster recovery sites
  • Testing BC DR plans
  • After-action reports

Domain 4 - Reporting and Communication

  • Reporting and Communication

Vulnerability Reporting and Communication

  • Vulnerability communication
  • Report scan results
  • Prioritize remediation
  • Create a remediation workflow
  • Barriers to vulnerability remediation
  • Vulnerability metrics

Incident Reporting and Communication

  • Incident communications plan
  • Incident identification
  • Escalation and notification
  • Post-incident activities
  • Incident response reports
  • Incident metrics and KPIs

Conclusion

  • Continuing your studies
200,000 Toman