SSCP Cert Prep: 7 Systems and Application Security

SSCP Cert Prep: 7 Systems and Application Security

4h 8mIntermediate2022-03-28

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

The Systems Security Certified Practitioner (SSCP) certification is an excellent entry point to a career in IT security. To help you prepare for the SSCP exam, instructor Mike Chapple has designed a series of courses covering each domain. In this installment, Mike covers the objectives of the seventh and final domain, Systems and Application Security. Join Mike to learn about malicious code and cyberattacks, as well as the endpoint device security controls used to protect against them. He also covers topics like the controls you can use to secure mobile devices, cloud computing environments, and virtualized environments.

Skills covered

Incident ResponseCert PrepCybersecurity

Concepts

Introduction

  • Securing systems and applications
  • What you need to know
  • Study resources

Malware

  • Comparing viruses, worms, and trojans
  • Malware payloads
  • Understanding backdoors and logic bombs
  • Looking at advanced malware
  • Understanding botnets
  • Code signing

Understanding Attackers

  • Cybersecurity adversaries
  • Preventing insider threats
  • Attack vectors
  • Zero-days and the Advanced Persistent Threat

Social Engineering Attacks

  • Social engineering
  • Impersonation attacks
  • Identity fraud and pretexting
  • Watering hole attacks
  • Physical social engineering

Web Application Attacks

  • OWASP Top Ten
  • Application security
  • Preventing SQL injection
  • Understanding cross-site scripting
  • Request forgery
  • Defending against directory traversal
  • Overflow attacks
  • Explaining cookies and attachments
  • Session hijacking
  • Code execution attacks

Host Security

  • Operating system security
  • Malware prevention
  • Application management
  • Host-based network security controls
  • File integrity monitoring
  • Data loss prevention
  • Endpoint monitoring

Hardware Security

  • Data encryption
  • Hardware and firmware security
  • Peripheral security

Mobile Device Security

  • Mobile connection methods
  • Mobile device security
  • Mobile device management
  • Mobile device tracking
  • Mobile application management
  • Mobile security enforcement
  • Bring Your Own Device (BYOD)
  • Mobile deployment models

Embedded Systems Security

  • Industrial control systems
  • Internet of Things
  • Securing smart devices
  • Secure networking for smart devices

Cloud Computing

  • What is the cloud
  • Cloud activities and the Cloud Reference Architecture
  • Cloud deployment models
  • Cloud service categories
  • Virtualization
  • Cloud compute resources
  • Cloud storage
  • Containers

Cloud Issues

  • Security and privacy concerns in the cloud
  • Data sovereignty
  • Operational concerns in the cloud

What's Next

  • Continuing your studies
100,000 Toman