Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
CompTIA Security+ (SY0-601) Cert Prep: 2 Secure Code Design and Implementation

CompTIA Security+ (SY0-601) Cert Prep: 2 Secure Code Design and Implementation

2h 9mBeginner2022-02-28

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Application vulnerabilities can open the floodgates to all manner of malicious attacks. Cybersecurity professionals must be equipped with a robust understanding of the risks associated with application vulnerabilities, as well as the coding practices that can help developers create truly secure applications. In this course, the second installment in the CompTIA Security+ (SY0-601) Cert Prep series, dive into the topic of secure coding design and implementation as you prepare for the Security+ exam. Instructor Mike Chapple goes over the software development lifecycle, covering different software development methodologies, change management processes, and the security implications of the DevOps movement. He also goes over software quality assurance, top web security vulnerabilities to watch out for, and key coding practices that developers can leverage to protect data.

Skills covered

Software Development SecurityCybersecurityCert Prep

Concepts

0. Introduction

  • 01 - Secure code design and implementation
  • 02 - What you need to know
  • 03 - Study resources

1. Software Development Lifecycle

  • 04 - Software platforms
  • 05 - Development methodologies
  • 06 - Maturity models
  • 07 - Change management
  • 08 - Automation and DevOps

2. Software Quality Assurance

  • 09 - Code review
  • 10 - Software testing
  • 11 - Code security tests
  • 12 - Fuzz testing
  • 13 - Code repositories
  • 14 - Application management
  • 15 - Third-party code

3. Application Attacks

  • 16 - OWASP Top 10
  • 17 - Application security
  • 18 - Prevent SQL injection
  • 19 - Cross-site scripting
  • 20 - Request forgery
  • 21 - Defend against directory traversal
  • 22 - Overflow attacks
  • 23 - Cookies and attachments
  • 24 - Session hijacking
  • 25 - Code execution attacks
  • 26 - Privilege escalation
  • 27 - Driver manipulation
  • 28 - Memory vulnerabilities
  • 29 - Race condition vulnerabilities

4. Secure Coding Practices

  • 30 - Input validation
  • 31 - Parameterized queries
  • 32 - Authentication and session management issues
  • 33 - Output encoding
  • 34 - Error and exception handling
  • 35 - Code signing
  • 36 - Database security
  • 37 - Data deidentification
  • 38 - Data obfuscation

Conclusion

  • 39 - Continue your studies

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal