CompTIA CySA+ (CS0-002) Cert Prep: 3 Identity and Access Management
1h 38mAdvanced2020-02-13
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
Identity and access management systems help organizations accomplish several fundamental tasks: identifying users, authenticating them, and ensuring that they can access only the resources and information that they are privy to. In this course—the third installment in the CySA+ (CS0-002) Cert Prep series—instructor Mike Chapple delves into the identity access management portion of domain two of the CompTIA Cybersecurity Analyst (CySA+) (CS0-002) exam: Software and Systems Security. Mike discusses different means of verifying identity, including biometrics; key authentication techniques, systems, and protocols; authorization and privilege management; the identity management lifecycle; and how to address common security issues in the realm of identity management.
Topics include:
- Provisioning and deprovisioning
- Dealing with identity security issues
- Multifactor authentication
- How password authentication works
- RADIUS and TACACS
- Mandatory access and discretionary access controls
- Account and password policies
Topics include:
- Provisioning and deprovisioning
- Dealing with identity security issues
- Multifactor authentication
- How password authentication works
- RADIUS and TACACS
- Mandatory access and discretionary access controls
- Account and password policies
Skills covered
Identity and Access ManagementCert PrepCybersecurity
Concepts
Introduction
- Identity and access management
- What you should know
- Study resources
Identity and Access Management
- Identity and access management
- Identification, authentication, and authorization
- Subject_object model
- Provisioning and deprovisioning
- Identity security issues
Identification
- User names and access cards
- Biometrics
- Registration and identity proofing
Authentication
- Authentication factors
- Multi-factor authentication
- Something you have
- Password authentication protocols
- Single sign-on (SSO) and federation
- RADIUS and TACACS
- Kerberos and LDAP
- SAML
- IDaaS
- Advanced authorization concepts
Authorization
- Authorization and privilege management
- Mandatory access controls
- Discretionary access controls
- Access control lists (ACL)
Identity Management Life Cycle
- Account and privilege management
- Account policies
- Password policies
- Role management
- Account monitoring
Conclusion
- Next steps