CompTIA Security+ (SY0-701) Cert Prep: 4 Security Operations
6h 7mIntermediate2024-02-15
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
In this course, security and information technology expert Mike Chapple guides you through security operations principles to help you prepare for the Security+ exam. This course, part of a series of courses, covers the topics and skills from the Security Operation exam domain. Find out how to apply common security techniques to computing resources. Explore the security implications of proper hardware, software, and data asset management. Plus, learn about vulnerability management activities, as well as the concepts and tools you will use in security alerting and monitoring.
Skills covered
Incident ResponseCert PrepCybersecurity
Concepts
Introduction
- Security operations
- Study resources
Data Security Controls
- Developing security baselines
- Leveraging industry standards
- Customizing security standards
Host Security
- Operating system security
- Malware prevention
- Application management
- Host-based network security controls
- File integrity monitoring
- Data loss prevention
- Data encryption
- Hardware and firmware security
- Linux file permissions
- Web content filtering
Configuration Enforcement
- Change management
- Configuration management
- Physical asset management
- Disposal and decommissioning
Mobile Device Security
- Mobile connection methods
- Mobile device security
- Mobile device management
- Mobile device tracking
- Mobile application security
- Mobile security enforcement
- Bring your own device (BYOD)
- Mobile deployment models
Wireless Networking
- Understanding wireless networking
- Wireless encryption
- Wireless authentication
- RADIUS
- Wireless signal propagation
- Wireless networking equipment
Code Security
- Code review
- Software testing
- Code security tests
- Fuzz testing
- Acquired software
- Package monitoring
Threat Intelligence
- Threat intelligence
- Intelligence sharing
- Threat hunting
Vulnerability Management
- What is vulnerability management
- Identify scan targets
- Scan configuration
- Scan perspective
- Security Content Automation Protocol (SCAP)
- Common Vulnerability Scoring System (CVSS )
- Analyzing scan reports
- Correlating scan results
- Vulnerability response and remediation
Penetration Testing and Exercises
- Penetration testing
- Responsible disclosure
- Bug bounty
Security Alerting, Monitoring, and Automation
- Logging security information
- Security information and event management
- Monitoring activities
- Endpoint monitoring
- Automation and orchestration
Secure Protocols
- TLS and SSL
- IPSec
- Securing common protocols
- DKIM, DMARC, and SPF
- Email gateways
Identification
- Identification, authentication, authorization, and accounting
- Usernames and access cards
- Biometrics
- Registration and identity proofing
Authentication
- Authentication factors
- Multifactor authentication
- Something you have
- Password policy
- Password managers
- Passwordless authentication
- Single sign-on and federation
- Kerberos and LDAP
- SAML
- OAUTH and OpenID Connect
- Certificate-based authentication
Authorization
- Understanding authorization
- Mandatory access controls
- Discretionary access controls
- Access control lists
- Advanced authorization concepts
Account Management
- Understanding account and privilege management
- Privileged access management
- Provisioning and deprovisioning
Incident Response
- Build an incident response program
- Incident identification
- Escalation and notification
- Mitigation
- Containment techniques
- Incident eradication and recovery
- Post-incident activities
- Incident response training and testing
Digital Forensics
- Introduction to forensics
- System and file forensics
- Chain of custody
- E-discovery and evidence production
- Investigation data sources
Conclusion
- Continuing your studies