Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
CompTIA Cybersecurity Analyst (CySA+) (CS0-003) Cert Prep (2024)

CompTIA Cybersecurity Analyst (CySA+) (CS0-003) Cert Prep (2024)

12h 57mAdvanced2024-07-30

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Earning the CompTIA Cybersecurity Analyst+ (CySA+) certification demonstrates that you know how to address cybersecurity threats using an analytics-based approach. This course serves as a comprehensive, all-in-one resource for anyone preparing for the CS0-003 exam. Join University of Notre Dame professor and cybersecurity expert Mike Chapple as he shows you the skills you need to know to tackle the official exam. Mike starts with an overview and general information about the exam, and then goes into detail through each domain of the certification test.

Skills covered

Vulnerability ManagementNetwork SecurityIncident ResponseCybersecurityCert Prep

Concepts

0. Introduction

  • 01 - About the CySA+ exam
  • 02 - What's new in CS0-003

1. The CySA+ Exam

  • 03 - Careers in information security
  • 04 - Value of certification
  • 05 - Stackable certifications

2. Inside the CySA+ Exam

  • 06 - The CySA+ exam
  • 07 - The CySA+ in-person exam environment
  • 08 - At-home testing
  • 09 - CySA+ question types
  • 10 - Passing the CySA+ exam

3. Preparing for the CySA+ Exam

  • 11 - Study resources
  • 12 - Exam tips
  • 13 - Continuing education requirements

4. Domain 1 - Security Operations

  • 14 - Security Operations

5. Operating System Security

  • 15 - The goals of information security
  • 16 - Role of the cybersecurity analyst
  • 17 - Operating system security
  • 18 - Windows Registry
  • 19 - Configuration files
  • 20 - System processes
  • 21 - Hardware architecture

6. Logging

  • 22 - Logging security information
  • 23 - Security information and event management
  • 24 - Tuning and configuring SIEMs
  • 25 - Continuous security monitoring

7. Infrastructure Concepts

  • 26 - Virtualization
  • 27 - Cloud infrastructure components
  • 28 - Containers

8. Network Security

  • 29 - Network architecture
  • 30 - Security zones
  • 31 - VLANs and network segmentation
  • 32 - Zero-trust networking
  • 33 - Secure access service edge (SASE)
  • 34 - Software-defined networking (SDN)

9. Identity and Access Management

  • 35 - Identification, authentication, authorization, and accounting
  • 36 - Usernames and access cards
  • 37 - Biometrics
  • 38 - Authentication factors
  • 39 - Multifactor authentication
  • 40 - Something you have
  • 41 - Password authentication protocols
  • 42 - Single sign-on and federation
  • 43 - Passwordless authentication
  • 44 - Privileged access management
  • 45 - Cloud access security brokers

10. Encryption

  • 46 - Understanding encryption
  • 47 - Symmetric and asymmetric cryptography
  • 48 - Goals of cryptography
  • 49 - Trust models
  • 50 - PKI and digital certificates
  • 51 - TLS and SSL

11. Sensitive Data Protection

  • 52 - Data classification
  • 53 - Data loss prevention

12. Indicators of Malicious Activity

  • 54 - Network symptoms
  • 55 - Rogue access points and evil twins
  • 56 - Endpoint symptoms
  • 57 - Application symptoms
  • 58 - Obfuscated links
  • 59 - Social engineering

13. Tools and Techniques

  • 60 - Protocol analyzers
  • 61 - DNS and IP reputation
  • 62 - Endpoint monitoring
  • 63 - Malware prevention
  • 64 - Executable analysis
  • 65 - Cuckoo and Joe Sandbox
  • 66 - User account monitoring

14. Email Analysis

  • 67 - Malicious email content
  • 68 - Digital signatures
  • 69 - DKIM, DMARC, and SPF
  • 70 - Analyzing email headers

15. Programming and Scripting

  • 71 - Shell and script environments
  • 72 - APIs
  • 73 - Querying logs

16. Understanding the Cybersecurity Threat

  • 74 - Threat actors
  • 75 - Zero-days and the APT
  • 76 - Supply chain vulnerabilities
  • 77 - Threat classification

17. Threat Intelligence

  • 78 - Threat intelligence
  • 79 - Managing threat indicators
  • 80 - Intelligence sharing
  • 81 - Threat research
  • 82 - Identifying threats
  • 83 - Automating threat intelligence
  • 84 - Threat hunting
  • 85 - Deception technologies

18. Efficiency and Process Improvement

  • 86 - Standardizing processes and streamlining operations
  • 87 - Technology and tool integration

19. Domain 2 - Vulnerability Management

  • 88 - Vulnerability Management

20. Creating a Vulnerability Management Program

  • 89 - What is vulnerability management
  • 90 - Identify scan targets
  • 91 - Scan frequency

21. Network Mapping

  • 92 - Network scanning
  • 93 - Install Nmap on Windows
  • 94 - Install Nmap on macOS
  • 95 - Run and interpret a simple Nmap scan
  • 96 - Host discovery with Nmap
  • 97 - Operate system fingerprinting
  • 98 - Service version detection

22. Configuring and Executing Vulnerability Scans

  • 99 - Security baseline scanning
  • 100 - Scan configuration
  • 101 - Scan perspective
  • 102 - Scanner maintenance
  • 103 - Vulnerability scanning tools
  • 104 - Passive vulnerability scanning

23. Analyzing Scan Results

  • 105 - SCAP
  • 106 - CVSS
  • 107 - Interpret CVSS scores
  • 108 - Analyze scan reports
  • 109 - Correlate scan results

24. Common Vulnerabilities

  • 110 - Server vulnerabilities
  • 111 - Endpoint vulnerabilities
  • 112 - Network vulnerabilities

25. Software Security Issues

  • 113 - OWASP Top 10
  • 114 - Prevent SQL injection
  • 115 - Understand cross-site scripting
  • 116 - Request forgery
  • 117 - Privilege escalation
  • 118 - Directory traversal
  • 119 - File inclusion
  • 120 - Overflow attacks
  • 121 - Cookies and attachments
  • 122 - Session hijacking
  • 123 - Race conditions
  • 124 - Memory vulnerabilities
  • 125 - Code execution attacks
  • 126 - Data poisoning
  • 127 - Third-party code
  • 128 - Interception proxies

26. Specialized Technology Vulnerabilities

  • 129 - Industrial control systems
  • 130 - Internet of Things
  • 131 - Embedded systems

27. More Cybersecurity Tools

  • 132 - Exploitation frameworks
  • 133 - Cloud auditing tools
  • 134 - Debuggers
  • 135 - Open-source reconnaissance
  • 136 - Control frameworks

28. Software Development Lifecycle

  • 137 - Software platforms
  • 138 - Development methodologies
  • 139 - Maturity models
  • 140 - Change management

29. Secure Coding Practices

  • 141 - Input validation
  • 142 - Parameterized queries
  • 143 - Authentication and session management issues
  • 144 - Output encoding
  • 145 - Error and exception handling
  • 146 - Code signing
  • 147 - Database security
  • 148 - Data de-identification
  • 149 - Data obfuscation

30. Software Quality Assurance

  • 150 - Software testing
  • 151 - Code security tests
  • 152 - Fuzzing
  • 153 - Reverse engineering software
  • 154 - Reverse engineering hardware

31. Threat Modeling

  • 155 - Threat research
  • 156 - Identify threats
  • 157 - Understand attacks
  • 158 - Threat modeling
  • 159 - Attack surface management
  • 160 - Bug bounty

32. Security Governance

  • 161 - Align security with the business
  • 162 - Organizational processes
  • 163 - Security roles and responsibilities
  • 164 - Security control selection

33. Risk Management

  • 165 - Risk assessment
  • 166 - Quantitative risk assessment
  • 167 - Risk treatment options
  • 168 - Risk management frameworks
  • 169 - Risk visibility and reporting

34. Domain 3 - Incident Response and Management

  • 170 - Incident Response and Management

35. Incident Response Programs

  • 171 - Build an incident response program
  • 172 - Creating an incident response team
  • 173 - Incident communications plan
  • 174 - Incident identification
  • 175 - Escalation and notification
  • 176 - Mitigation
  • 177 - Containment techniques
  • 178 - Incident eradication and recovery
  • 179 - Validation
  • 180 - Post-incident activities
  • 181 - Incident response exercises

36. Attack Frameworks

  • 182 - MITRE ATT&CK
  • 183 - Diamond model of intrusion analysis
  • 184 - Cyber kill chain analysis
  • 185 - Testing guides

37. Incident Investigation

  • 186 - Logging security information
  • 187 - Security information and event management
  • 188 - Cloud audits and investigations

38. Forensic Techniques

  • 189 - Conducting investigations
  • 190 - Evidence types
  • 191 - Introduction to forensics
  • 192 - System and file forensics
  • 193 - File carving
  • 194 - Creating forensic images
  • 195 - Digital forensics toolkit
  • 196 - Operating system analysis
  • 197 - Password forensics
  • 198 - Network forensics
  • 199 - Software forensics
  • 200 - Mobile device forensics
  • 201 - Embedded device forensics
  • 202 - Chain of custody
  • 203 - Ediscovery and evidence production

39. Business Continuity

  • 204 - Business continuity planning
  • 205 - Business continuity controls
  • 206 - High availability and fault tolerance

40. Disaster Recovery

  • 207 - Disaster recovery
  • 208 - Backups
  • 209 - Restoring backups
  • 210 - Disaster recovery sites
  • 211 - Testing BC DR plans
  • 212 - After-action reports

41. Domain 4 - Reporting and Communication

  • 213 - Reporting and Communication

42. Vulnerability Reporting and Communication

  • 214 - Vulnerability communication
  • 215 - Report scan results
  • 216 - Prioritize remediation
  • 217 - Create a remediation workflow
  • 218 - Barriers to vulnerability remediation
  • 219 - Vulnerability metrics

43. Incident Reporting and Communication

  • 220 - Incident communications plan
  • 221 - Incident identification
  • 222 - Escalation and notification
  • 223 - Post-incident activities
  • 224 - Incident response reports
  • 225 - Incident metrics and KPIs

Conclusion

  • 226 - Continuing your studies

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal