CompTIA CySA+ (CS0-002) Cert Prep: 3 Identity and Access Management

CompTIA CySA+ (CS0-002) Cert Prep: 3 Identity and Access Management

1h 38mAdvanced2020-02-13

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Identity and access management systems help organizations accomplish several fundamental tasks: identifying users, authenticating them, and ensuring that they can access only the resources and information that they are privy to. In this course—the third installment in the CySA+ (CS0-002) Cert Prep series—instructor Mike Chapple delves into the identity access management portion of domain two of the CompTIA Cybersecurity Analyst (CySA+) (CS0-002) exam: Software and Systems Security. Mike discusses different means of verifying identity, including biometrics; key authentication techniques, systems, and protocols; authorization and privilege management; the identity management lifecycle; and how to address common security issues in the realm of identity management.

Topics include:
- Provisioning and deprovisioning
- Dealing with identity security issues
- Multifactor authentication
- How password authentication works
- RADIUS and TACACS
- Mandatory access and discretionary access controls
- Account and password policies

Skills covered

Identity and Access ManagementCert PrepCybersecurity

Concepts

Introduction

  • Identity and access management
  • What you should know
  • Study resources

Identity and Access Management

  • Identity and access management
  • Identification, authentication, and authorization
  • Subject_object model
  • Provisioning and deprovisioning
  • Identity security issues

Identification

  • User names and access cards
  • Biometrics
  • Registration and identity proofing

Authentication

  • Authentication factors
  • Multi-factor authentication
  • Something you have
  • Password authentication protocols
  • Single sign-on (SSO) and federation
  • RADIUS and TACACS
  • Kerberos and LDAP
  • SAML
  • IDaaS
  • Advanced authorization concepts

Authorization

  • Authorization and privilege management
  • Mandatory access controls
  • Discretionary access controls
  • Access control lists (ACL)

Identity Management Life Cycle

  • Account and privilege management
  • Account policies
  • Password policies
  • Role management
  • Account monitoring

Conclusion

  • Next steps
40,000 Toman