Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
CompTIA Security+ (SY0-701) Cert Prep (2024)

CompTIA Security+ (SY0-701) Cert Prep (2024)

17h 33mIntermediate2024-07-26

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

CompTIA Security+ is an entry-level certification that requires a thorough understanding of network and device security, risk mitigation strategies, compliance, and more. This course provides CompTIA Security+ candidates with essential information they need to prepare for the qualifying exam. Cybersecurity expert Mike Chapple first goes over some of the basics of the exam, then covers the six domains for the latest version of the exam, SY0-701. He shares study tips that can help you feel prepared to take and pass the test on your first try. Plus, learn where to find practice tests to get hands-on experience and how to keep your certification current by continuing your studies.

Skills covered

Software Quality AssuranceVulnerability ManagementGovernance, Risk, and ComplianceNetwork SecurityCybersecurityCert PrepSoftware Development

Concepts

0. Introduction

  • 01 - About the Security+ exam
  • 02 - What's new in SY0-701

1. The Security+ Exam

  • 03 - The Security+ exam
  • 04 - Careers in information security
  • 05 - The value of certification
  • 06 - Stackable certifications
  • 07 - Study resources

2. Inside the Security+ Exam

  • 08 - In-person exam environment
  • 09 - At-home testing
  • 10 - Security+ question types
  • 11 - Passing the Security+ exam

3. Preparing for the Exam

  • 12 - Exam tips
  • 13 - Practice tests
  • 14 - Continuing education requirements

4. Domain 1 - General Security Concepts

  • 15 - General security concepts

5. Fundamental Security Concepts

  • 16 - The goals of information security
  • 17 - Authentication, authorization, and accounting (AAA)
  • 18 - Categorizing security controls
  • 19 - Conducting a gap analysis
  • 20 - Zero Trust
  • 21 - Physical access control
  • 22 - Physical security personnel
  • 23 - Deception technologies
  • 24 - Change management

6. Cryptography

  • 25 - Understanding encryption
  • 26 - Symmetric and asymmetric cryptography
  • 27 - Goals of cryptography
  • 28 - Choosing encryption algorithms
  • 29 - The cryptographic lifecycle
  • 30 - Data de-identification
  • 31 - Data obfuscation

7. Symmetric Cryptography

  • 32 - Data Encryption Standard (DES)
  • 33 - 3DES
  • 34 - AES, Blowfish, and Twofish
  • 35 - Steganography

8. Asymmetric Cryptography

  • 36 - Rivest, Shamir, Adleman (RSA)
  • 37 - PGP and GnuPG
  • 38 - Elliptic-curve and quantum cryptography
  • 39 - Tor and perfect forward secrecy

9. Key Management

  • 40 - Key exchange
  • 41 - Diffie-Hellman
  • 42 - Key escrow
  • 43 - Key stretching
  • 44 - Hardware security modules

10. Public Key Infrastructure

  • 45 - Trust models
  • 46 - PKI and digital certificates
  • 47 - Hash functions
  • 48 - Digital signatures
  • 49 - Digital signature standard
  • 50 - Create a digital certificate
  • 51 - Revoke a digital certificate
  • 52 - Certificate stapling
  • 53 - Certificate authorities
  • 54 - Certificate subjects
  • 55 - Certificate types
  • 56 - Certificate formats

11. Cryptographic Applications

  • 57 - TLS and SSL
  • 58 - Blockchain

12. Domain 2 - Threats, Vulnerabilities, and Mitigations

  • 59 - Threats, vulnerabilities, and mitigations

13. Understanding Vulnerability Types

  • 60 - Vulnerability impact
  • 61 - Supply chain vulnerabilities
  • 62 - Configuration vulnerabilities
  • 63 - Architectural vulnerabilities

14. Malware

  • 64 - Comparing viruses, worms, and trojans
  • 65 - Malware payloads
  • 66 - Understanding backdoors and logic bombs
  • 67 - Looking at advanced malware
  • 68 - Understanding botnets
  • 69 - Malicious script execution

15. Understanding Attackers

  • 70 - Cybersecurity adversaries
  • 71 - Attacker motivations
  • 72 - Preventing insider threats
  • 73 - Attack vectors
  • 74 - Zero-day attacks

16. Social Engineering Attacks

  • 75 - Social engineering
  • 76 - Impersonation attacks
  • 77 - Identity fraud and pretexting
  • 78 - Watering hole attacks
  • 79 - Physical social engineering
  • 80 - Business email compromise
  • 81 - Misinformation and disinformation

17. Password Attacks

  • 82 - Password attacks
  • 83 - Password spraying and credential stuffing

18. Application Attacks

  • 84 - Preventing SQL injection
  • 85 - Understanding cross-site scripting
  • 86 - Request forgery
  • 87 - Overflow attacks
  • 88 - Explaining cookies and attachments
  • 89 - Session hijacking
  • 90 - Code execution attacks
  • 91 - Privilege escalation
  • 92 - OWASP Top Ten
  • 93 - Application security
  • 94 - Defending against directory traversal
  • 95 - Race condition vulnerabilities

19. Cryptanalytic Attacks

  • 96 - Brute force attacks
  • 97 - Knowledge-based attacks
  • 98 - Limitations of encryption algorithms

20. Network Attacks

  • 99 - Denial-of-service attacks
  • 100 - Eavesdropping attacks
  • 101 - DNS attacks
  • 102 - Wireless attacks
  • 103 - Propagation attacks
  • 104 - Preventing rogues and evil twins
  • 105 - Disassociation attacks
  • 106 - Understanding Bluetooth attacks
  • 107 - RFID security

21. Attack Indicators

  • 108 - Attack indicators

22. Domain 3 - Security Architecture

  • 109 - Security architecture

23. Cloud Computing

  • 110 - What is the cloud
  • 111 - Cloud computing roles
  • 112 - Drivers for cloud computing
  • 113 - Multitenant computing
  • 114 - Cloud considerations
  • 115 - Security service providers

24. Virtualization

  • 116 - Virtualization
  • 117 - Desktop and application virtualization

25. Cloud Building Blocks

  • 118 - Cloud compute resources
  • 119 - Cloud storage
  • 120 - Cloud networking
  • 121 - Cloud databases
  • 122 - Cloud orchestration
  • 123 - Containers
  • 124 - SOA and microservices

26. Cloud Activities

  • 125 - Cloud activities and the cloud reference architecture
  • 126 - Cloud deployment models
  • 127 - Cloud service categories
  • 128 - Security and privacy concerns in the cloud
  • 129 - Data sovereignty
  • 130 - Operational concerns in the cloud

27. Cloud Security Controls

  • 131 - Cloud firewall considerations
  • 132 - Cloud application security
  • 133 - Cloud provider security controls

28. TCP IP Networking

  • 134 - Introducing TCP IP
  • 135 - IP addresses and DHCP
  • 136 - Domain Name System (DNS)
  • 137 - Network ports
  • 138 - ICMP

29. Secure Network Design

  • 139 - Security zones
  • 140 - VLANs and network segmentation
  • 141 - Security device placement
  • 142 - Software-defined networking (SDN)

30. Network Security Devices

  • 143 - Routers, switches, and bridges
  • 144 - Firewalls
  • 145 - Web application firewalls
  • 146 - Proxy servers
  • 147 - Load balancers
  • 148 - VPNs and VPN concentrators
  • 149 - Network intrusion detection and prevention
  • 150 - Protocol analyzers
  • 151 - Unified threat management
  • 152 - Failure modes

31. Network Security Techniques

  • 153 - Restricting network access
  • 154 - Network access control
  • 155 - Router configuration security
  • 156 - Switch configuration security
  • 157 - Maintaining network availability
  • 158 - Network monitoring
  • 159 - SNMP
  • 160 - Isolating sensitive systems
  • 161 - Zero trust networking
  • 162 - Secure access service edge (SASE)

32. Embedded Systems Security

  • 163 - Industrial control systems
  • 164 - Internet of Things
  • 165 - Securing smart devices
  • 166 - Secure networking for smart devices
  • 167 - Embedded systems

33. Data Protection

  • 168 - Understanding data security
  • 169 - Data types
  • 170 - Data anonymization
  • 171 - Data obfuscation
  • 172 - Information classification

34. Resilience and Recovery

  • 173 - Business continuity planning
  • 174 - Business continuity controls
  • 175 - High availability and fault tolerance
  • 176 - Disaster recovery
  • 177 - Backups
  • 178 - Restoring backups
  • 179 - Disaster recovery sites
  • 180 - Testing BC DR plans
  • 181 - Capacity planning

35. Domain 4 - Security Operations

  • 182 - Security operations

36. Data Security Controls

  • 183 - Developing security baselines
  • 184 - Leveraging industry standards
  • 185 - Customizing security standards

37. Host Security

  • 186 - Operating system security
  • 187 - Malware prevention
  • 188 - Application management
  • 189 - Host-based network security controls
  • 190 - File integrity monitoring
  • 191 - Data loss prevention
  • 192 - Data encryption
  • 193 - Hardware and firmware security
  • 194 - Linux file permissions
  • 195 - Web content filtering

38. Configuration Enforcement

  • 196 - Change management
  • 197 - Configuration management
  • 198 - Physical asset management
  • 199 - Disposal and decommissioning

39. Mobile Device Security

  • 200 - Mobile connection methods
  • 201 - Mobile device security
  • 202 - Mobile device management
  • 203 - Mobile device tracking
  • 204 - Mobile application security
  • 205 - Mobile security enforcement
  • 206 - Bring your own device (BYOD)
  • 207 - Mobile deployment models

40. Wireless Networking

  • 208 - Understanding wireless networking
  • 209 - Wireless encryption
  • 210 - Wireless authentication
  • 211 - RADIUS
  • 212 - Wireless signal propagation
  • 213 - Wireless networking equipment

41. Code Security

  • 214 - Code review
  • 215 - Software testing
  • 216 - Code security tests
  • 217 - Fuzz testing
  • 218 - Acquired software
  • 219 - Package monitoring

42. Threat Intelligence

  • 220 - Threat intelligence
  • 221 - Intelligence sharing
  • 222 - Threat hunting

43. Vulnerability Management

  • 223 - What is vulnerability management
  • 224 - Identify scan targets
  • 225 - Scan configuration
  • 226 - Scan perspective
  • 227 - Security Content Automation Protocol (SCAP)
  • 228 - Common Vulnerability Scoring System (CVSS )
  • 229 - Analyzing scan reports
  • 230 - Correlating scan results
  • 231 - Vulnerability response and remediation

44. Penetration Testing and Exercises

  • 232 - Penetration testing
  • 233 - Responsible disclosure
  • 234 - Bug bounty

45. Security Alerting, Monitoring, and Automation

  • 235 - Logging security information
  • 236 - Security information and event management
  • 237 - Monitoring activities
  • 238 - Endpoint monitoring
  • 239 - Automation and orchestration

46. Secure Protocols

  • 240 - TLS and SSL
  • 241 - IPSec
  • 242 - Securing common protocols
  • 243 - DKIM, DMARC, and SPF
  • 244 - Email gateways

47. Identification

  • 245 - Identification, authentication, authorization, and accounting
  • 246 - Usernames and access cards
  • 247 - Biometrics
  • 248 - Registration and identity proofing

48. Authentication

  • 249 - Authentication factors
  • 250 - Multifactor authentication
  • 251 - Something you have
  • 252 - Password policy
  • 253 - Password managers
  • 254 - Passwordless authentication
  • 255 - Single sign-on and federation
  • 256 - Kerberos and LDAP
  • 257 - SAML
  • 258 - OAUTH and OpenID Connect
  • 259 - Certificate-based authentication

49. Authorization

  • 260 - Understanding authorization
  • 261 - Mandatory access controls
  • 262 - Discretionary access controls
  • 263 - Access control lists
  • 264 - Advanced authorization concepts

50. Account Management

  • 265 - Understanding account and privilege management
  • 266 - Privileged access management
  • 267 - Provisioning and deprovisioning

51. Incident Response

  • 268 - Build an incident response program
  • 269 - Incident identification
  • 270 - Escalation and notification
  • 271 - Mitigation
  • 272 - Containment techniques
  • 273 - Incident eradication and recovery
  • 274 - Post-incident activities
  • 275 - Incident response training and testing

52. Digital Forensics

  • 276 - Introduction to forensics
  • 277 - System and file forensics
  • 278 - Chain of custody
  • 279 - E-discovery and evidence production
  • 280 - Investigation data sources

53. Domain 5 - Security Program Management and Oversight

  • 281 - Security program management and oversight

54. Security Policies

  • 282 - Security policy framework
  • 283 - Security policies
  • 284 - Security standards
  • 285 - Security procedures
  • 286 - Policy monitoring and revision
  • 287 - Policy considerations

55. Security Governance

  • 288 - Security governance structures
  • 289 - Data security roles

56. Risk Analysis

  • 290 - Risk assessment
  • 291 - Quantitative risk assessment
  • 292 - Business impact analysis
  • 293 - Risk treatment options
  • 294 - Risk visibility and reporting
  • 295 - Ongoing risk assessment
  • 296 - Security metrics

57. Supply Chain Risk

  • 297 - Managing vendor relationships
  • 298 - Vendor agreements
  • 299 - Vendor information management

58. Privacy and Compliance

  • 300 - Legal and compliance risks
  • 301 - Compliance monitoring and reporting

59. Auditing

  • 302 - Audits and assessments

60. Conclusion

  • 303 - Continuing Your Studies

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal