CompTIA Security+ (SY0-701) Cert Prep: 4 Security Operations

CompTIA Security+ (SY0-701) Cert Prep: 4 Security Operations

6h 7mIntermediate2024-02-15

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

In this course, security and information technology expert Mike Chapple guides you through security operations principles to help you prepare for the Security+ exam. This course, part of a series of courses, covers the topics and skills from the Security Operation exam domain. Find out how to apply common security techniques to computing resources. Explore the security implications of proper hardware, software, and data asset management. Plus, learn about vulnerability management activities, as well as the concepts and tools you will use in security alerting and monitoring.

Skills covered

Incident ResponseCert PrepCybersecurity

Concepts

Introduction

  • Security operations
  • Study resources

Data Security Controls

  • Developing security baselines
  • Leveraging industry standards
  • Customizing security standards

Host Security

  • Operating system security
  • Malware prevention
  • Application management
  • Host-based network security controls
  • File integrity monitoring
  • Data loss prevention
  • Data encryption
  • Hardware and firmware security
  • Linux file permissions
  • Web content filtering

Configuration Enforcement

  • Change management
  • Configuration management
  • Physical asset management
  • Disposal and decommissioning

Mobile Device Security

  • Mobile connection methods
  • Mobile device security
  • Mobile device management
  • Mobile device tracking
  • Mobile application security
  • Mobile security enforcement
  • Bring your own device (BYOD)
  • Mobile deployment models

Wireless Networking

  • Understanding wireless networking
  • Wireless encryption
  • Wireless authentication
  • RADIUS
  • Wireless signal propagation
  • Wireless networking equipment

Code Security

  • Code review
  • Software testing
  • Code security tests
  • Fuzz testing
  • Acquired software
  • Package monitoring

Threat Intelligence

  • Threat intelligence
  • Intelligence sharing
  • Threat hunting

Vulnerability Management

  • What is vulnerability management
  • Identify scan targets
  • Scan configuration
  • Scan perspective
  • Security Content Automation Protocol (SCAP)
  • Common Vulnerability Scoring System (CVSS )
  • Analyzing scan reports
  • Correlating scan results
  • Vulnerability response and remediation

Penetration Testing and Exercises

  • Penetration testing
  • Responsible disclosure
  • Bug bounty

Security Alerting, Monitoring, and Automation

  • Logging security information
  • Security information and event management
  • Monitoring activities
  • Endpoint monitoring
  • Automation and orchestration

Secure Protocols

  • TLS and SSL
  • IPSec
  • Securing common protocols
  • DKIM, DMARC, and SPF
  • Email gateways

Identification

  • Identification, authentication, authorization, and accounting
  • Usernames and access cards
  • Biometrics
  • Registration and identity proofing

Authentication

  • Authentication factors
  • Multifactor authentication
  • Something you have
  • Password policy
  • Password managers
  • Passwordless authentication
  • Single sign-on and federation
  • Kerberos and LDAP
  • SAML
  • OAUTH and OpenID Connect
  • Certificate-based authentication

Authorization

  • Understanding authorization
  • Mandatory access controls
  • Discretionary access controls
  • Access control lists
  • Advanced authorization concepts

Account Management

  • Understanding account and privilege management
  • Privileged access management
  • Provisioning and deprovisioning

Incident Response

  • Build an incident response program
  • Incident identification
  • Escalation and notification
  • Mitigation
  • Containment techniques
  • Incident eradication and recovery
  • Post-incident activities
  • Incident response training and testing

Digital Forensics

  • Introduction to forensics
  • System and file forensics
  • Chain of custody
  • E-discovery and evidence production
  • Investigation data sources

Conclusion

  • Continuing your studies
120,000 Toman