CompTIA Cybersecurity Analyst+ (CySA+) (CS0-003): 2 Vulnerability Management

CompTIA Cybersecurity Analyst+ (CySA+) (CS0-003): 2 Vulnerability Management

4h 50mAdvanced2023-07-12

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

As cybersecurity threats become more sophisticated and pervasive, the need for IT professionals with security analytics expertise has grown exponentially. Earning the CompTIA Cybersecurity Analyst (CySA+) certification demonstrates a proficiency in tackling cybersecurity threats using a behavioral analytics-based approach. In this course—the second installment in the CompTIA Cybersecurity Analyst+ CySA+ (CS0-003) certification prep series, instructor Mike Chapple covers the topics covered in the Vulnerability Management domain of the exam. Mike shows how to design a vulnerability management program and configure and execute vulnerability scans. He also covers vulnerability remediation workflows, overcoming barriers to vulnerability scans, and analyzing the results of scans.

Skills covered

Vulnerability ManagementIncident ResponseCert PrepCybersecurity

Concepts

Introduction

  • Vulnerability management
  • What you need to know
  • Study resources

Creating a Vulnerability Management Program

  • What is vulnerability management
  • Identify scan targets
  • Scan frequency

Network Mapping

  • Network scanning
  • Install Nmap on Windows
  • Install Nmap on macOS
  • Run and interpret a simple Nmap scan
  • Host discovery with Nmap
  • Operate system fingerprinting
  • Service version detection

Configuring and Executing Vulnerability Scans

  • Security baseline scanning
  • Scan configuration
  • Scan perspective
  • Scanner maintenance
  • Vulnerability scanning tools
  • Passive vulnerability scanning

Analyzing Scan Results

  • SCAP
  • CVSS
  • Interpret CVSS scores
  • Analyze scan reports
  • Correlate scan results

Common Vulnerabilities

  • Server vulnerabilities
  • Endpoint vulnerabilities
  • Network vulnerabilities

Software Security Issues

  • OWASP Top 10
  • Prevent SQL injection
  • Understand cross-site scripting
  • Request forgery
  • Privilege escalation
  • Directory traversal
  • File inclusion
  • Overflow attacks
  • Cookies and attachments
  • Session hijacking
  • Race conditions
  • Memory vulnerabilities
  • Code execution attacks
  • Data poisoning
  • Third-party code
  • Interception proxies

Specialized Technology Vulnerabilities

  • Industrial control systems
  • Internet of Things
  • Embedded systems

More Cybersecurity Tools

  • Exploitation frameworks
  • Cloud auditing tools
  • Debuggers
  • Open-source reconnaissance
  • Control frameworks

Software Development Lifecycle

  • Software platforms
  • Development methodologies
  • Maturity models
  • Change management

Secure Coding Practices

  • Input validation
  • Parameterized queries
  • Authentication and session management issues
  • Output encoding
  • Error and exception handling
  • Code signing
  • Database security
  • Data de-identification
  • Data obfuscation

Software Quality Assurance

  • Software testing
  • Code security tests
  • Fuzzing
  • Reverse engineering software
  • Reverse engineering hardware

Threat Modeling

  • Threat research
  • Identify threats
  • Understand attacks
  • Threat modeling
  • Attack surface management
  • Bug bounty

Security Governance

  • Align security with the business
  • Organizational processes
  • Security roles and responsibilities
  • Security control selection

Risk Management

  • Risk assessment
  • Quantitative risk assessment
  • Risk treatment options
  • Risk management frameworks
  • Risk visibility and reporting

Conclusion

  • Continue your studies
100,000 Toman