CompTIA Cybersecurity Analyst (CySA+) CS0-002 Cert Guide

Paperback Engels 2020 9780136747161
€ 66,94
Levertijd ongeveer 9 werkdagen
Gratis verzonden

Samenvatting

CompTIA Cybersecurity Analyst (CySA+) CS0-002 Cert Guide is a best-of-breed exam study guide. Expert technology instructor and certification author Troy McMillan shares preparation hints and test-taking tips, helping you identify areas of weakness and improve both your conceptual knowledge and hands-on skills. Material is presented in a concise manner, focusing on increasing your understanding and retention of exam topics.
The book presents you with an organized test-preparation routine through the use of proven series elements and techniques. Exam topic lists make referencing easy. Chapter-ending Exam Preparation Tasks help you drill on key concepts you must know thoroughly. Review questions help you assess your knowledge, and a final preparation chapter guides you through tools and resources to help you craft your final study plan.
The companion website contains the powerful Pearson Test Prep practice test software, complete with hundreds of exam-realistic questions. The assessment engine offers you a wealth of customization options and reporting features, laying out a complete assessment of your knowledge to help you focus your study where it is needed most.
Well regarded for its level of detail, assessment features, and challenging review questions and exercises, this CompTIA approved study guide helps you master the concepts and techniques that will enable you to succeed on the exam the first time.
The CompTIA approved study guide helps you master all the topics on the CySA+ exam, including:
· Applying environmental reconnaissance · Analyzing results of network reconnaissance · Implementing responses and countermeasures · Implementing vulnerability management processes · Analyzing scan output and identifying common vulnerabilities · Identifying incident impact and assembling a forensic toolkit · Utilizing effective incident response processes · Performing incident recovery and post-incident response · Establishing frameworks, policies, controls, and procedures · Remediating identity- and access-related security issues · Architecting security and implementing compensating controls · Implementing application security best practices · Using cybersecurity tools and technologies

Specificaties

ISBN13:9780136747161
Taal:Engels
Bindwijze:paperback

Lezersrecensies

Wees de eerste die een lezersrecensie schrijft!

Inhoudsopgave

Introduction xxxvii

Chapter 1 The Importance of Threat Data and Intelligence 3

“Do I Know This Already?” Quiz 3

Foundation Topics 6

Intelligence Sources 6

    Open-Source Intelligence6

    Proprietary/Closed-Source Intelligence 6

    Timeliness 7

    Relevancy 7

    Confidence Levels 7

    Accuracy 7

Indicator Management 7

    Structured Threat Information eXpression (STIX) 8

    Trusted Automated eXchange of Indicator Information (TAXII) 8

    OpenIOC 9

Threat Classification 9

    Known Threat vs. Unknown Threat 10

    Zero-day 10

    Advanced Persistent Threat 11

Threat Actors 12

    Nation-state 12

    Organized Crime 12

    Terrorist Groups 12

    Hacktivist 12

    Insider Threat 12

Intelligence Cycle 13

Commodity Malware 14

Information Sharing and Analysis Communities 15

Exam Preparation Tasks 16

Chapter 2 Utilizing Threat Intelligence to Support Organizational Security 19

“Do I Know This Already?” Quiz 19

Foundation Topics 21

Attack Frameworks 21

    MITRE ATT&CK 21

    The Diamond Model of Intrusion Analysis 22

    Kill Chain 23

Threat Research 23

    Reputational 24

    Behavioral 24

    Indicator of Compromise (IoC) 25

    Common Vulnerability Scoring System (CVSS) 25

Threat Modeling Methodologies 29

    Adversary Capability 29

    Total Attack Surface 31

    Attack Vector 31

    Impact 32

    Probability 32

Threat Intelligence Sharing with Supported Functions 33

    Incident Response 33

    Vulnerability Management33

    Risk Management 33

    Security Engineering 33

    Detection and Monitoring34

Exam Preparation Tasks 34

Chapter 3 Vulnerability Management Activities 39

“Do I Know This Already?” Quiz 39

Foundation Topics 41

Vulnerability Identification 41

    Asset Criticality 42

    Active vs. Passive Scanning 43

    Mapping/Enumeration 44

Validation 44

Remediation/Mitigation 45

    Configuration Baseline 45

    Patching 46

    Hardening 46

    Compensating Controls 47

    Risk Acceptance 47

    Verification of Mitigation 47

Scanning Parameters and Criteria 49

    Risks Associated with Scanning Activities 49

    Vulnerability Feed 49

    Scope 49

    Credentialed vs. Non-credentialed 51

    Server-based vs. Agent-based 52

    Internal vs. External 53

    Special Considerations 53

Inhibitors to Remediation 62

Exam Preparation Tasks 63

Chapter 4 Analyzing Assessment Output 67

“Do I Know This Already?” Quiz 67

Foundation Topics 69

Web Application Scanner 69

    Burp Suite 69

    OWASP Zed Attack Proxy (ZAP) 69

    Nikto 70

    Arachni 70

Infrastructure Vulnerability Scanner 71

    Nessus 71

    OpenVAS 71

Software Assessment Tools and Techniques 72

    Static Analysis 73

    Dynamic Analysis 74

    Reverse Engineering 75

    Fuzzing 75

Enumeration 76

    Nmap 76

    Host Scanning 79

    hping 80

    Active vs. Passive 82

    Responder 82

Wireless Assessment Tools 82

    Aircrack-ng 83

    Reaver 84

    oclHashcat 86

Cloud Infrastructure Assessment Tools 86

    ScoutSuite 87

    Prowler 87

    Pacu 87

Exam Preparation Tasks 88

Chapter 5 Threats and Vulnerabilities Associated with Specialized Technology 93

“Do I Know This Already?” Quiz 93

Foundation Topics 97

Mobile 97

    Unsigned Apps/System Apps 98

    Security Implications/Privacy Concerns 99

    Device Loss/Theft 100

    Rooting/Jailbreaking 100

    Push Notification Services 100

    Geotagging 100

    OEM/Carrier Android Fragmentation 101

    Mobile Payment 101

    USB 102

    Malware 102

    Unauthorized Domain Bridging 103

    SMS/MMS/Messaging 103

Internet of Things (IoT) 103

    IoT Examples 104

    Methods of Securing IoT Devices 104

Embedded Systems 105

Real-Time Operating System (RTOS) 105

System-on-Chip (SoC) 105

Field Programmable Gate Array (FPGA) 105

Physical Access Control 106

    Systems 106

    Devices 107

    Facilities 107

Building Automation Systems 109

    IP Video 109

    HVAC Controllers 111

    Sensors 111

Vehicles and Drones 111

    CAN Bus 112

    Drones 113

Workflow and Process Automation Systems 113

Incident Command System (ICS) 114

Supervisory Control and Data Acquisition (SCADA) 114

    Modbus 118

Exam Preparation Tasks 118

Chapter 6 Threats and Vulnerabilities Associated with Operating in the Cloud 123

“Do I Know This Already?” Quiz 123

Foundation Topics 126

Cloud Deployment Models 126

Cloud Service Models 127

Function as a Service (FaaS)/Serverless Architecture 128

Infrastructure as Code (IaC) 130

Insecure Application Programming Interface (API) 131

Improper Key Management 132

    Key Escrow 133

    Key Stretching 134

Unprotected Storage 134

    Transfer/Back Up Data to Uncontrolled Storage 134

    Big Data 135

Logging and Monitoring 136

    Insufficient Logging and Monitoring 136

    Inability to Access 136

Exam Preparation Tasks 137

Chapter 7 Implementing Controls to Mitigate Attack sand Software Vulnerabilities 141

“Do I Know This Already?” Quiz 141

Foundation Topics 143

Attack Types 143

    Extensible Markup Language (XML) Attack 143

    Structured Query Language (SQL) Injection 145

    Overflow Attacks 147

    Remote Code Execution 150

    Directory Traversal 151

    Privilege Escalation 152

    Password Spraying 152

    Credential Stuffing 152

Managementboek Top 100

€ 66,94
Levertijd ongeveer 9 werkdagen
Gratis verzonden

Rubrieken

    Personen

      Trefwoorden

        Artikelen

          CompTIA Cybersecurity Analyst (CySA+) CS0-002 Cert Guide