Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
CompTIA Security+ (SY0-701) Cert Prep: 2 Threats, Vulnerabilities, and Mitigations

CompTIA Security+ (SY0-701) Cert Prep: 2 Threats, Vulnerabilities, and Mitigations

2h 49mIntermediate2024-01-05

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

The CompTIA Security+ exam is an excellent entry point for a career in information security. The latest version, SY0-701, expands coverage on cloud security, security automation and orchestration, cryptography, threat modeling, and security assessment and testing. Instructor Mike Chapple, an IT leader with 20 years of experience, provides you with the detailed information you need to prepare for the SY0-701 Security+ exam.

This second course in the multi-part series covers topics needed to prepare for the Threats, Vulnerabilities, and Mitigations domain of the SY0-701 Security+ exam. Learn about the major risks facing cybersecurity professionals and about common threat actors and motivations, threat vectors, attack surfaces, and various types of vulnerabilities. Discover how to analyze indicators of malicious activity and be able to explain the purpose of mitigation techniques used to secure the enterprise.

Skills covered

Vulnerability ManagementIncident ResponseCybersecurityCert Prep

Concepts

0. Introduction

  • 01 - Threats, vulnerabilities, and mitigations

1. Understanding Vulnerability Types

  • 02 - Vulnerability impact
  • 03 - Supply chain vulnerabilities
  • 04 - Configuration vulnerabilities
  • 05 - Architectural vulnerabilities

2. Malware

  • 06 - Comparing viruses, worms, and trojans
  • 07 - Malware payloads
  • 08 - Understanding backdoors and logic bombs
  • 09 - Looking at advanced malware
  • 10 - Understanding botnets
  • 11 - Malicious script execution

3. Understanding Attackers

  • 12 - Cybersecurity adversaries
  • 13 - Attacker motivations
  • 14 - Preventing insider threats
  • 15 - Attack vectors
  • 16 - Zero-day attacks

4. Social Engineering Attacks

  • 17 - Social engineering
  • 18 - Impersonation attacks
  • 19 - Identity fraud and pretexting
  • 20 - Watering hole attacks
  • 21 - Physical social engineering
  • 22 - Business email compromise
  • 23 - Misinformation and disinformation

5. Password Attacks

  • 24 - Password attacks
  • 25 - Password spraying and credential stuffing

6. Application Attacks

  • 26 - Preventing SQL injection
  • 27 - Understanding cross-site scripting
  • 28 - Request forgery
  • 29 - Overflow attacks
  • 30 - Explaining cookies and attachments
  • 31 - Session hijacking
  • 32 - Code execution attacks
  • 33 - Privilege escalation
  • 34 - OWASP Top Ten
  • 35 - Application security
  • 36 - Defending against directory traversal
  • 37 - Race condition vulnerabilities

7. Cryptanalytic Attacks

  • 38 - Brute force attacks
  • 39 - Knowledge-based attacks
  • 40 - Limitations of encryption algorithms

8. Network Attacks

  • 41 - Denial-of-service attacks
  • 42 - Eavesdropping attacks
  • 43 - DNS attacks
  • 44 - Wireless attacks
  • 45 - Propagation attacks
  • 46 - Preventing rogues and evil twins
  • 47 - Disassociation attacks
  • 48 - Understanding Bluetooth attacks
  • 49 - RFID security

9. Attack Indicators

  • 50 - Attack indicators

Conclusion

  • 51 - Continuing your studies

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal