Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
CompTIA Cybersecurity Analyst+ (CySA+) (CS0-003): 2 Vulnerability Management

CompTIA Cybersecurity Analyst+ (CySA+) (CS0-003): 2 Vulnerability Management

4h 50mAdvanced2023-07-12

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

As cybersecurity threats become more sophisticated and pervasive, the need for IT professionals with security analytics expertise has grown exponentially. Earning the CompTIA Cybersecurity Analyst (CySA+) certification demonstrates a proficiency in tackling cybersecurity threats using a behavioral analytics-based approach. In this course—the second installment in the CompTIA Cybersecurity Analyst+ CySA+ (CS0-003) certification prep series, instructor Mike Chapple covers the topics covered in the Vulnerability Management domain of the exam. Mike shows how to design a vulnerability management program and configure and execute vulnerability scans. He also covers vulnerability remediation workflows, overcoming barriers to vulnerability scans, and analyzing the results of scans.

Skills covered

Vulnerability ManagementIncident ResponseCybersecurityCert Prep

Concepts

0. Introduction

  • 01 - Vulnerability management
  • 02 - What you need to know
  • 03 - Study resources

1. Creating a Vulnerability Management Program

  • 04 - What is vulnerability management
  • 05 - Identify scan targets
  • 06 - Scan frequency

2. Network Mapping

  • 07 - Network scanning
  • 08 - Install Nmap on Windows
  • 09 - Install Nmap on macOS
  • 10 - Run and interpret a simple Nmap scan
  • 11 - Host discovery with Nmap
  • 12 - Operate system fingerprinting
  • 13 - Service version detection

3. Configuring and Executing Vulnerability Scans

  • 14 - Security baseline scanning
  • 15 - Scan configuration
  • 16 - Scan perspective
  • 17 - Scanner maintenance
  • 18 - Vulnerability scanning tools
  • 19 - Passive vulnerability scanning

4. Analyzing Scan Results

  • 20 - SCAP
  • 21 - CVSS
  • 22 - Interpret CVSS scores
  • 23 - Analyze scan reports
  • 24 - Correlate scan results

5. Common Vulnerabilities

  • 25 - Server vulnerabilities
  • 26 - Endpoint vulnerabilities
  • 27 - Network vulnerabilities

6. Software Security Issues

  • 28 - OWASP Top 10
  • 29 - Prevent SQL injection
  • 30 - Understand cross-site scripting
  • 31 - Request forgery
  • 32 - Privilege escalation
  • 33 - Directory traversal
  • 34 - File inclusion
  • 35 - Overflow attacks
  • 36 - Cookies and attachments
  • 37 - Session hijacking
  • 38 - Race conditions
  • 39 - Memory vulnerabilities
  • 40 - Code execution attacks
  • 41 - Data poisoning
  • 42 - Third-party code
  • 43 - Interception proxies

7. Specialized Technology Vulnerabilities

  • 44 - Industrial control systems
  • 45 - Internet of Things
  • 46 - Embedded systems

8. More Cybersecurity Tools

  • 47 - Exploitation frameworks
  • 48 - Cloud auditing tools
  • 49 - Debuggers
  • 50 - Open-source reconnaissance
  • 51 - Control frameworks

9. Software Development Lifecycle

  • 52 - Software platforms
  • 53 - Development methodologies
  • 54 - Maturity models
  • 55 - Change management

10. Secure Coding Practices

  • 56 - Input validation
  • 57 - Parameterized queries
  • 58 - Authentication and session management issues
  • 59 - Output encoding
  • 60 - Error and exception handling
  • 61 - Code signing
  • 62 - Database security
  • 63 - Data de-identification
  • 64 - Data obfuscation

11. Software Quality Assurance

  • 65 - Software testing
  • 66 - Code security tests
  • 67 - Fuzzing
  • 68 - Reverse engineering software
  • 69 - Reverse engineering hardware

12. Threat Modeling

  • 70 - Threat research
  • 71 - Identify threats
  • 72 - Understand attacks
  • 73 - Threat modeling
  • 74 - Attack surface management
  • 75 - Bug bounty

13. Security Governance

  • 76 - Align security with the business
  • 77 - Organizational processes
  • 78 - Security roles and responsibilities
  • 79 - Security control selection

14. Risk Management

  • 80 - Risk assessment
  • 81 - Quantitative risk assessment
  • 82 - Risk treatment options
  • 83 - Risk management frameworks
  • 84 - Risk visibility and reporting

Conclusion

  • 85 - Continue your studies

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal