CompTIA CySA+ (CS0-002) Cert Prep: 3 Identity and Access Management
1h 38mAdvanced2020-02-13
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
Identity and access management systems help organizations accomplish several fundamental tasks: identifying users, authenticating them, and ensuring that they can access only the resources and information that they are privy to. In this course—the third installment in the CySA+ (CS0-002) Cert Prep series—instructor Mike Chapple delves into the identity access management portion of domain two of the CompTIA Cybersecurity Analyst (CySA+) (CS0-002) exam: Software and Systems Security. Mike discusses different means of verifying identity, including biometrics; key authentication techniques, systems, and protocols; authorization and privilege management; the identity management lifecycle; and how to address common security issues in the realm of identity management.
Topics include:
- Provisioning and deprovisioning
- Dealing with identity security issues
- Multifactor authentication
- How password authentication works
- RADIUS and TACACS
- Mandatory access and discretionary access controls
- Account and password policies
Topics include:
- Provisioning and deprovisioning
- Dealing with identity security issues
- Multifactor authentication
- How password authentication works
- RADIUS and TACACS
- Mandatory access and discretionary access controls
- Account and password policies
Skills covered
Identity and Access ManagementCybersecurityCert Prep
Concepts
0. Introduction
- 01 - Identity and access management
- 02 - What you should know
- 03 - Study resources
1. Identity and Access Management
- 04 - Identity and access management
- 05 - Identification, authentication, and authorization
- 06 - Subject object model
- 07 - Provisioning and deprovisioning
- 08 - Identity security issues
2. Identification
- 09 - User names and access cards
- 10 - Biometrics
- 11 - Registration and identity proofing
3. Authentication
- 12 - Authentication factors
- 13 - Multi-factor authentication
- 14 - Something you have
- 15 - Password authentication protocols
- 16 - Single sign-on (SSO) and federation
- 17 - RADIUS and TACACS
- 18 - Kerberos and LDAP
- 19 - SAML
- 20 - IDaaS
- 21 - Advanced authorization concepts
4. Authorization
- 22 - Authorization and privilege management
- 23 - Mandatory access controls
- 24 - Discretionary access controls
- 25 - Access control lists (ACL)
5. Identity Management Life Cycle
- 26 - Account and privilege management
- 27 - Account policies
- 28 - Password policies
- 29 - Role management
- 30 - Account monitoring
Conclusion
- 31 - Next steps