CompTIA Security+ Study Guide başlıklı kaynağın profesyonel teknik özetidir. Aşağıda belgenin ana başlık ve içerik yapısı Türkçe açıklamalarla sunulmuştur.
SYO - 701 Exam Study Guide + Table of Contents Section 1 - Summarize Fundamental Security Concepts 1.1 - Introduction To Information Security 1.2 - Cybersecurity Framework 1.3 - Gap Analysis 1.4 - Control Objectives 1.5 - Security Control Categories 1.6 - Security Control Functional Types 1.7 - Security Roles & Responsibilities Section 3 - Explain Cryptographic Solutions 3.1 - Introduction To Cryptography And Hashing 3.2 - Encryption 3.3 - Cryptographic Modes Of Operation & Cipher Suites 3.4 - Cryptographic Use Cases 3.5 - Longevity, Salting , Stretching & Other Types Of Cryptographic Technolo...
gies 3.6 - Certificates, Pkis, Ras & Csrs 3.7 - Digital Certificates 3.8 - Key Management 3.9 - Certificate Management Section 2 - Explaining Threat Actors And Threat Vectors 2.1 - Vulnerability, Threat And Risk 2.2 - Attributes Of Threat Actors 2.3 - Threat Actors 2.4 - Attack Surface & Attack Vectors 2.5 - Vulnerable Software & Network Vectors 2.6 - Lure-Based & Message-Based Vectors 2.7 - Third Party Risks 2.8 - Intro To Social Engineering 7 8 8 9 11 11 12 13 14 15 15 18 18 19 21 22 25 26 27 28 30 31 32 14 Section 6 - Secure Cloud Network Architecture 6.1 - Cloud Deployment Models 6.2 - Res...
ponsibility Matrix 6.3 - Cloud Security Solutions 6.4 - Infrastructure As Code Concepts 6.5 - Zero Trust 6.6 - Embedded Systems 6.7 - Industrial Control Systems & Internet Of Things Section 4 - Implement Identity and Access Management 4.1 - Identity Access Management 4.2 - Authentication Factors, Design And Attributes 4.3 - Biometric Authentication 4.4 - Password Concepts 4.5 - Authorization Solutions - Part 1 4.6 - Authorization Solutions - Part 2 4.7 - Account Attributes & Access Policies 4.8 - Privileged Access Management To protect privileged account credentials, it is important not to sig...
n in on untrusted workstations. A secure administrative workstation (SAW) is a computer with a very low attack surface running the minimum possible apps. 4.9 - Local, Network & Remote Authentication 4.10 - Kerberos Authentication & Authorization 33 34 35 36 37 38 39 41 41 42 42 Section 5 - Secure Enterprise Network Architecture 5.1 - Secure Network Designs 5.2 - Network Segmentation, Topology & Dmzs 5.3 - Device Placement & Attributes 5.4 - Secure Switching And Routing 5.5 - Routing & Switching Protocols 5.6 - Using Secure Protocols 5.7 - Attack Surface 5.8 - Firewalls 5.9 - Firewall Implement...
ation 5.10 - Remote Access Architecture 43 44 46 48 51 52 54 55 57 58 61 62 63 66 68 70 72 Section 7 - Explain Resiliency and Site Security Concepts 7.1 - Backup Strategies & Storage 7.2 - Implementing Redundancy Strategies 7.3 - Cyber Security Resilient Strategies 7.4 - Physical Security Controls 7.5 - physical host security controls 73 75 77 80 83 Section 8 - Explain Vulnerability Management 8.1 - Vulnerability Discover 8.2 - Weak host & Network configurations 8.3 - Evaluation Scope 8.4 - Overflows, Resource Exhaustion, Memory Leaks & Race Conditions 8.5 - Sideloading, Rooting & Jailbreaking...
8.6 - Threat Research Sources 8.7 - Threat Intelligence Providers 8.8 - Threat Data Feeds 8.9 - Vulnerability Response & Remediation 85 86 87 87 89 90 90 91 92 Section 9 - Evaluate Network Security Capabilities 8.1 - Bench Marks & Secure Configuration Guides 8.2 - Hardening Concepts 8.3 - Wi-Fi Authentication Methods 8.4 - Network Access Control 8.5 - Network Security Monitoring 8.6 - Web Filtering 95 96 97 99 100 Section 10 - Assess Endpoint Security Capabilities 10.1 - Endpoint Security 10.2 - Segmentation 10.3 - Mobile Device Management 10.4 - Secure Mobile Device Connections 104 105 106 1...
09 102 Section 11 - Enhance Application Security Capabilities 11.1 - Dns Security, Directory Services & Snmp 11.2 - Secure Application Operations Protocols 11.3 - File Transfer, Email & Video Services 11.4 - Email Security 11.5 - Secure Coding Techniques 111 112 113 115 117 Section 12 - Explain Incident Response and Monitoring Concepts 12.1 - Incident Response Process 12.2 - Cyber Incident Response Team 12.3 - Incident Response Plan 12.4 - Incident Response Exercises, Recovery And Retention Policy 12.5 - Incident Identification 12.6 - Digital Forensics Documentation 12.7 - Digital Forensics Ev...
idence Acquisition 12.8 - Data Sources 119 120 120 123 124 127 130 132 Section 13 - Section 13 - Analyze Indicators of Malicious Activity 13.1 - Malware Classification 13.2 - Computer Viruses 13.3 - Computer Worms & Fileless Malware 13.4 - Spyware, Keyloggers, Rootkits, Backdoors, Ransomware & Logic Bombs 13.5 - Malware Indicators & Process Analysis 13.6 - Password Attacks 13.7 - Tactics, Techniques & Procedures 13.8 - Privilege Escalation & Error Handling 13.9 - Uniform Resource Locator Analysis & Percent Encoding 13.10 - Api & Replay Attacks, Cross-Site Request Forgery, Clickjacking & Ssl St...
rip Attacks 13.11 - Injection Attacks 134 135 136 137 138 138 139 140 141 143 146 Section 14 - Summarize Security Governance Concepts 14.1 - Regulations, Standards & Legislation 14.2 - ISO and Cloud Frameworks 14.3 - Governance Structure 14.4 - Governance Documents 14.5 - Change Management 14.6 - Configuration Management 14.7 - Scripting, Automation & Orchestration 147 148 150 152 154 155 156 Section 15 - Explain Risk Management 15.1 - Risk management process 15.2 - Risk Controls 15.3 - Business Impact Analysis 15.4 - Third-Party Risk Management & Security Agreements 15.5 - Audit & Assurance 1...
5.6 - PenTest Attack Life Cycle 157 159 160 162 163 165 Section 16 - Summarize Data Protection and Compliance Concepts 16.1 - Privacy & Sensitive Data Concepts 16.2 - Data Sovereignty, Privacy Breaches & Data Sharing 16.3 - Privacy And Data Controls 16.4 - Privacy Principles 16.5 - Compliance Monitoring 16.6 - Education, Training & Awareness 16.7 - Personnel Policies 166 168 170 172 174 175 176 SECTION 1 - SUMMARIZE FUNDAMENTAL SECURITY CONCEPTS 1.1 Introduction To Information Security Information security is based on the CIA and DAD triads. Information and cyber security professionals strive ...
to accomplish the CIA triad. Confidentiality - Data is accessed by only those with the right permit and can be achieved with the use of encryption, passwords, biometrics, 2fa and so on. Integrity - This ensures that data has not been tampered or altered in any way with the use of hashing, checksums etc Availability - Data and resources are available to be accessed or shared at all times. This can be achieved with network access, server and data availability. Black hat hackers and cyber criminals aim for the DAD triad. Disclosure - Hwwwwere data is accessed by non-authorized users with ...
the use of trojans, brute force attacks and theft Alteration - This means data has been compromised or tampered with. This can be attained by malware , viruses and attacks like sql injection. Deniability - This means data is not made available to those who need it with the use of attacks like dos and ddos as well as ransomware. Non-repudiation - means a subject cannot deny something such as creating, modifying or sending a resource. 7 Information security and cyber tasks can be classified as five functions following the framework developed by the national institute of standards and technol...
Belge toplam 15 paragraf içermektedir; tam metin /root/pdf klasöründeki kaynak dosyasında mevcuttur.