CompTIA Cybersecurity Analyst+ (CySA+) (CS0-003): 3 Incident Response and Management
2h 30mAdvanced2023-07-13
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
Cybersecurity professionals are responsible for responding to security incidents and carrying out other operational tasks. The CompTIA Cybersecurity Analyst+ (CySA+_ (CS0-003) exam can offer valuable training and certification of your skills. In this course, Mike Chapple dives into incident response practices, as needed to complete the CySA+ exam. Learn about classifying threats and assessing the impact of cybersecurity incidents. Go over the importance of communication during a cybersecurity incident response effort, as well as the symptoms of an incident in progress, the use of forensic tools, and the incident recovery process. After completing this course, you will be prepared to answer questions on the CySA+ exam from the Incident Response and Management domain.
Skills covered
Incident ResponseCert PrepCybersecurity
Concepts
Introduction
- Incident response
- What you need to know
- Study resources
Incident Response Programs
- Build an incident response program
- Creating an incident response team
- Incident communications plan
- Incident identification
- Escalation and notification
- Mitigation
- Containment techniques
- Incident eradication and recovery
- Validation
- Post-incident activities
- Incident response exercises
Attack Frameworks
- MITRE ATT&CK
- Diamond model of intrusion analysis
- Cyber kill chain analysis
- Testing guides
Incident Investigation
- Logging security information
- Security information and event management
- Cloud audits and investigations
Forensic Techniques
- Conducting investigations
- Evidence types
- Introduction to forensics
- System and file forensics
- File carving
- Creating forensic images
- Digital forensics toolkit
- Operating system analysis
- Password forensics
- Network forensics
- Software forensics
- Mobile device forensics
- Embedded device forensics
- Chain of custody
- Ediscovery and evidence production
Business Continuity
- Business continuity planning
- Business continuity controls
- High availability and fault tolerance
Disaster Recovery
- Disaster recovery
- Backups
- Restoring backups
- Disaster recovery sites
- Testing BC DR plans
- After-action reports
Conclusion
- Continuing your studies