CompTIA Security+ (SY0-601) Cert Prep: 1 Threats, Attacks, and Vulnerabilities
2h 36mBeginner2020-07-09
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
The CompTIA Security+ exam is an excellent entry point for a career in information security. The latest version, SY0-601, expands coverage of cybersecurity threats, risk management, and IoT threats. This course prepares exam candidates for the first domain of the exam, Threats, Attacks, and Vulnerabilities. By learning about malware, networking and application security exploitations, and social engineering, you'll be prepared to answer questions from the exam—and strengthen your own organization's systems and defenses. Instructor Mike Chapple, an IT leader with over 17 years of experience, also covers the processes for discovering and mitigating threats and attacks, automating threat intelligence, scanning for vulnerabilities, and conducting penetration testing.
Learning objectives
Malware and advanced malware
Comparing viruses, worms, and Trojans
Preventing insider threats
Threat intelligence
Identifying threats
Social engineering
Password attacks
Adversarial AI
Vulnerability types
Vulnerability scanning
Pen testing
Learning objectives
Malware and advanced malware
Comparing viruses, worms, and Trojans
Preventing insider threats
Threat intelligence
Identifying threats
Social engineering
Password attacks
Adversarial AI
Vulnerability types
Vulnerability scanning
Pen testing
Skills covered
Vulnerability ManagementCybersecurityCert Prep
Concepts
0. Introduction
- 01 - Threats, attacks, and vulnerabilities
- 02 - What you need to know
- 03 - Study resources
1. Malware
- 04 - Comparing viruses, worms, and Trojans
- 05 - Malware payloads
- 06 - Understanding backdoors and logic bombs
- 07 - Looking at advanced malware
- 08 - Understanding botnets
- 09 - Malicious script execution
2. Understanding Attackers
- 10 - Cybersecurity adversaries
- 11 - Preventing insider threats
- 12 - Attack vectors
- 13 - Zero days and the advanced persistent threat
3. Threat Intelligence
- 14 - Threat intelligence
- 15 - Managing threat indicators
- 16 - Intelligence sharing
- 17 - Threat research
- 18 - Identifying threats
- 19 - Automating threat intelligence
- 20 - Threat hunting
4. Social Engineering Attacks
- 21 - Social engineering
- 22 - Impersonation attacks
- 23 - Identity fraud and pretexting
- 24 - Watering hole attacks
- 25 - Physical social engineering
5. Common Attacks
- 26 - Password attacks
- 27 - Password spraying and credential stuffing
- 28 - Adversarial artificial intelligence
6. Understanding Vulnerability Types
- 29 - Vulnerability impact
- 30 - Supply chain vulnerabilities
- 31 - Configuration vulnerabilities
- 32 - Architectural vulnerabilities
7. Vulnerability Scanning
- 33 - What is vulnerability management
- 34 - Identify scan targets
- 35 - Scan configuration
- 36 - Scan perspective
- 37 - SCAP (Security Content Automation Protocol)
- 38 - CVSS (Common Vulnerability Scoring System)
- 39 - Analyzing scan reports
- 40 - Correlating scan results
8. Penetration Testing and Exercises
- 41 - Penetration testing
- 42 - Bug bounty
- 43 - Cybersecurity exercises
Conclusion
- 44 - Continuing your studies