CompTIA Security+ (SY0-701) Cert Prep: 2 Threats, Vulnerabilities, and Mitigations

CompTIA Security+ (SY0-701) Cert Prep: 2 Threats, Vulnerabilities, and Mitigations

2h 49mIntermediate2024-01-05

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

The CompTIA Security+ exam is an excellent entry point for a career in information security. The latest version, SY0-701, expands coverage on cloud security, security automation and orchestration, cryptography, threat modeling, and security assessment and testing. Instructor Mike Chapple, an IT leader with 20 years of experience, provides you with the detailed information you need to prepare for the SY0-701 Security+ exam.

This second course in the multi-part series covers topics needed to prepare for the Threats, Vulnerabilities, and Mitigations domain of the SY0-701 Security+ exam. Learn about the major risks facing cybersecurity professionals and about common threat actors and motivations, threat vectors, attack surfaces, and various types of vulnerabilities. Discover how to analyze indicators of malicious activity and be able to explain the purpose of mitigation techniques used to secure the enterprise.

Skills covered

Vulnerability ManagementIncident ResponseCert PrepCybersecurity

Concepts

Introduction

  • Threats, vulnerabilities, and mitigations

Understanding Vulnerability Types

  • Vulnerability impact
  • Supply chain vulnerabilities
  • Configuration vulnerabilities
  • Architectural vulnerabilities

Malware

  • Comparing viruses, worms, and trojans
  • Malware payloads
  • Understanding backdoors and logic bombs
  • Looking at advanced malware
  • Understanding botnets
  • Malicious script execution

Understanding Attackers

  • Cybersecurity adversaries
  • Attacker motivations
  • Preventing insider threats
  • Attack vectors
  • Zero-day attacks

Social Engineering Attacks

  • Social engineering
  • Impersonation attacks
  • Identity fraud and pretexting
  • Watering hole attacks
  • Physical social engineering
  • Business email compromise
  • Misinformation and disinformation

Password Attacks

  • Password attacks
  • Password spraying and credential stuffing

Application Attacks

  • Preventing SQL injection
  • Understanding cross-site scripting
  • Request forgery
  • Overflow attacks
  • Explaining cookies and attachments
  • Session hijacking
  • Code execution attacks
  • Privilege escalation
  • OWASP Top Ten
  • Application security
  • Defending against directory traversal
  • Race condition vulnerabilities

Cryptanalytic Attacks

  • Brute force attacks
  • Knowledge-based attacks
  • Limitations of encryption algorithms

Network Attacks

  • Denial-of-service attacks
  • Eavesdropping attacks
  • DNS attacks
  • Wireless attacks
  • Propagation attacks
  • Preventing rogues and evil twins
  • Disassociation attacks
  • Understanding Bluetooth attacks
  • RFID security

Attack Indicators

  • Attack indicators

Conclusion

  • Continuing your studies
80,000 Toman