Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
CompTIA CySA+ (CS0-002) Cert Prep: 2 Vulnerability Management (2020)

CompTIA CySA+ (CS0-002) Cert Prep: 2 Vulnerability Management (2020)

2h 43mAdvanced2020-11-13

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Earning the CompTIA Cybersecurity Analyst (CySA+) certification shows potential employers that you understand how to tackle cybersecurity threats using a behavioral analytics-based approach. This course—the second installment in the CySA+ (CS0-002) Cert Prep series—will provide you with a foundational understanding of key vulnerability management tools and processes, and prepare you to tackle the Threat and Vulnerability Management domain of exam CS0-002. Instructor Mike Chapple covers how to design a vulnerability management program, execute vulnerability scans, and report and analyze scan results. He wraps up by detailing the vulnerabilities associated with different types of technologies, as well as common software security issues to watch out for.

Learning objectives
Configuring vulnerability scans
Reporting scan results
Barriers to vulnerability remediation
Analyzing scan reports
Common server, endpoint, and network vulnerabilities
Software security issues, such as SQL injection
Access control vulnerabilities

Skills covered

Vulnerability ManagementCybersecurityCert Prep

Concepts

0. Introduction

  • 01 - Vulnerability management
  • 02 - What you need to know
  • 03 - Study resources

1. Creating a Vulnerability Management Program

  • 04 - What is vulnerability management
  • 05 - Identify scan targets
  • 06 - Scan frequency

2. Configuring and Executing Vulnerability Scans

  • 07 - Scan configuration
  • 08 - Scan perspective
  • 09 - Scanner maintenance
  • 10 - Vulnerability scanning tools
  • 11 - Passive vulnerability scanning

3. Remediating Vulnerabilities

  • 12 - Report scan results
  • 13 - Prioritize remediation
  • 14 - Create a remediation workflow
  • 15 - Barriers to vulnerability remediation

4. Analyzing Scan Results

  • 16 - SCAP (Security Content Automation Protocol)
  • 17 - CVSS (Common Vulnerability Scoring System)
  • 18 - Interpreting CVSS scores
  • 19 - Analyzing scan reports
  • 20 - Correlating scan results

5. Common Vulnerabilities

  • 21 - Server vulnerabilities
  • 22 - Endpoint vulnerabilities
  • 23 - Network vulnerabilities
  • 24 - Virutalization vulnerabilities

6. Software Security Issues

  • 25 - OWASP (Open Web Application Security Project)
  • 26 - Preventing SQL injection
  • 27 - Understanding cross-site scripting
  • 28 - Privilege escalation
  • 29 - Directory traversal
  • 30 - Race conditions
  • 31 - Dereferencing NULL pointers
  • 32 - Third-party code
  • 33 - Interception proxies

7. Specialized Technology Vulnerabilities

  • 34 - Industrial control systems
  • 35 - Internet of Things
  • 36 - Embedded systems

8. Access Control Vulnerabilities

  • 37 - Password attacks
  • 38 - Password spraying and credential stuffing
  • 39 - Impersonation attacks
  • 40 - Session hijacking
  • 41 - Eavesdropping attacks

Conclusion

  • 42 - Next steps

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal