Acknowledgments |
|
xxix | |
Check-In |
|
xxxi | |
I Mission Assurance |
|
1 | (130) |
|
1 Organizational Security and Compliance |
|
|
3 | (38) |
|
Objective 1.01 Explain Risk Management Processes and Concepts |
|
|
5 | (21) |
|
|
6 | (2) |
|
|
6 | (1) |
|
|
6 | (1) |
|
|
6 | (2) |
|
|
8 | (6) |
|
|
9 | (1) |
|
|
10 | (1) |
|
Risk Likelihood and Impact |
|
|
11 | (1) |
|
Solutions and Countermeasures |
|
|
12 | (2) |
|
|
14 | (1) |
|
|
14 | (1) |
|
False Positives and Negatives |
|
|
15 | (1) |
|
Using Organizational Policies to Reduce Risk |
|
|
16 | (10) |
|
|
16 | (2) |
|
Network Security Policies |
|
|
18 | (5) |
|
|
23 | (3) |
|
Objective 1.02 Implement Appropriate Risk Mitigation Strategies |
|
|
26 | (5) |
|
|
27 | (1) |
|
Incident Management and Response Policy |
|
|
27 | (1) |
|
|
28 | (1) |
|
Develop Standard Operating Procedures |
|
|
28 | (1) |
|
User Rights and Permissions Reviews |
|
|
29 | (1) |
|
Data Loss Prevention and Regulatory Compliance |
|
|
29 | (2) |
|
Objective 1.03 Integrate with Third Parties |
|
|
31 | (4) |
|
Interoperability Agreements |
|
|
32 | (1) |
|
|
32 | (1) |
|
Business Partnership Agreements |
|
|
32 | (1) |
|
Memorandums of Agreement/Understanding |
|
|
33 | (1) |
|
Interconnection Security Agreement |
|
|
33 | (1) |
|
|
33 | (1) |
|
|
34 | (1) |
|
Unauthorized Data Sharing |
|
|
34 | (1) |
|
|
34 | (1) |
|
|
35 | (1) |
|
Verification of Adherence |
|
|
35 | (1) |
|
|
35 | (1) |
|
|
36 | (3) |
|
|
39 | (2) |
|
2 Security Training and Incident Response |
|
|
41 | (44) |
|
Objective 2.01 Explain the Importance of Security-Related Awareness and Training |
|
|
43 | (18) |
|
Effective Security Training and Awareness |
|
|
43 | (8) |
|
|
44 | (1) |
|
|
45 | (1) |
|
|
45 | (3) |
|
|
48 | (1) |
|
|
48 | (2) |
|
|
50 | (1) |
|
|
50 | (1) |
|
Data and Documentation Policies |
|
|
51 | (5) |
|
|
51 | (3) |
|
|
54 | (1) |
|
Hardware Disposal and Data Destruction Policy |
|
|
54 | (1) |
|
|
55 | (1) |
|
Best Practices for User Habits |
|
|
56 | (5) |
|
|
56 | (1) |
|
|
57 | (1) |
|
|
57 | (1) |
|
Workstation Locking and Access Tailgating |
|
|
58 | (1) |
|
|
58 | (1) |
|
|
58 | (1) |
|
|
59 | (1) |
|
|
60 | (1) |
|
Compliance with Laws, Regulations, Best Practices, and Standards |
|
|
60 | (1) |
|
Objective 2.02 Analyze and Differentiate Among Types of Social Engineering Attacks |
|
|
61 | (6) |
|
|
62 | (1) |
|
|
63 | (1) |
|
|
64 | (1) |
|
|
64 | (1) |
|
|
65 | (1) |
|
|
65 | (1) |
|
|
66 | (1) |
|
|
66 | (1) |
|
|
67 | (1) |
|
Objective 2.03 Execute Appropriate Incident Response Procedures |
|
|
67 | (6) |
|
|
68 | (1) |
|
|
68 | (1) |
|
|
68 | (1) |
|
|
69 | (1) |
|
|
69 | (1) |
|
|
70 | (1) |
|
|
70 | (1) |
|
Reporting and Notification |
|
|
71 | (1) |
|
Mitigation and Recovery Steps |
|
|
72 | (1) |
|
|
72 | (1) |
|
Objective 2.04 Implement Basic Forensic Procedures |
|
|
73 | (6) |
|
Data Acquisition and Preservation |
|
|
74 | (13) |
|
|
74 | (1) |
|
|
74 | (1) |
|
|
75 | (1) |
|
|
75 | (1) |
|
Use Hashing to Protect Evidence Integrity |
|
|
75 | (1) |
|
|
76 | (1) |
|
|
76 | (1) |
|
|
77 | (1) |
|
|
77 | (1) |
|
|
78 | (1) |
|
|
78 | (1) |
|
|
79 | (1) |
|
|
80 | (2) |
|
|
82 | (3) |
|
3 Business Continuity and Disaster Recovery |
|
|
85 | (46) |
|
Objective 3.01 Explain Concepts of Business Continuity and Disaster Recovery |
|
|
87 | (10) |
|
Select the Appropriate Control to Meet the Goals of Security |
|
|
87 | (2) |
|
|
89 | (1) |
|
|
89 | (1) |
|
|
89 | (1) |
|
Network and Hacking Attacks |
|
|
90 | (1) |
|
|
90 | (1) |
|
|
90 | (7) |
|
|
91 | (1) |
|
|
92 | (1) |
|
|
92 | (2) |
|
Privacy Impact Assessment |
|
|
94 | (1) |
|
Disaster Recovery and IT Contingency Plans |
|
|
94 | (1) |
|
|
95 | (1) |
|
|
96 | (1) |
|
|
96 | (1) |
|
Objective 3.02 Execute Disaster Recovery and Continuity of Operations Plans and Procedures |
|
|
97 | (18) |
|
High Availability and Redundancy Planning |
|
|
97 | (8) |
|
|
98 | (1) |
|
|
99 | (1) |
|
Spare Equipment Redundancy |
|
|
100 | (3) |
|
Alternate Site Redundancy |
|
|
103 | (1) |
|
Alternate Business Practices |
|
|
104 | (1) |
|
|
105 | (10) |
|
|
106 | (1) |
|
|
107 | (1) |
|
|
108 | (1) |
|
|
108 | (1) |
|
Uninterruptible Power Supply |
|
|
108 | (1) |
|
|
108 | (1) |
|
|
109 | (1) |
|
|
110 | (1) |
|
|
110 | (2) |
|
Media Rotation and Retention |
|
|
112 | (1) |
|
|
113 | (1) |
|
|
113 | (1) |
|
|
114 | (1) |
|
|
114 | (1) |
|
Objective 3.03 Explain the Impact and Proper Use of Environmental Controls |
|
|
115 | (10) |
|
Facility Construction Issues |
|
|
116 | (1) |
|
|
116 | (1) |
|
|
116 | (1) |
|
Computer Room Construction |
|
|
117 | (1) |
|
|
117 | (3) |
|
|
117 | (1) |
|
|
118 | (1) |
|
|
119 | (1) |
|
|
119 | (1) |
|
|
119 | (1) |
|
|
120 | (3) |
|
|
121 | (1) |
|
|
122 | (1) |
|
|
122 | (1) |
|
Wireless Networks and Cells |
|
|
123 | (1) |
|
|
123 | (12) |
|
|
124 | (1) |
|
Chemical-Based Fire Suppression |
|
|
125 | (1) |
|
|
125 | (1) |
|
|
126 | (2) |
|
|
128 | (3) |
II Cryptography and PKI |
|
131 | (62) |
|
4 Cryptography and Encryption Basics |
|
|
133 | (34) |
|
Objective 4.01 Utilize the Concepts of Cryptography |
|
|
135 | (13) |
|
|
135 | (2) |
|
|
135 | (1) |
|
|
135 | (1) |
|
|
135 | (1) |
|
|
136 | (1) |
|
|
136 | (1) |
|
|
137 | (8) |
|
|
139 | (1) |
|
|
140 | (3) |
|
In-Band/Out-of-Band Key Exchange |
|
|
143 | (1) |
|
|
143 | (1) |
|
|
144 | (1) |
|
Random/Pseudo-Random Numbers and Inputs |
|
|
144 | (1) |
|
|
145 | (1) |
|
|
145 | (1) |
|
|
145 | (1) |
|
|
146 | (1) |
|
|
147 | (1) |
|
Secure Hash Algorithm (SHA) |
|
|
147 | (1) |
|
|
148 | (1) |
|
|
148 | (1) |
|
Objective 4.02 Use and Apply Appropriate Cryptographic Tools and Products |
|
|
148 | (13) |
|
Symmetric Encryption Algorithms |
|
|
149 | (2) |
|
|
149 | (1) |
|
|
149 | (1) |
|
|
150 | (1) |
|
|
150 | (1) |
|
|
150 | (1) |
|
|
150 | (1) |
|
Asymmetric Encryption Algorithms |
|
|
151 | (1) |
|
|
151 | (1) |
|
Elliptic Curve Cryptography |
|
|
151 | (1) |
|
|
151 | (1) |
|
|
152 | (1) |
|
|
152 | (1) |
|
|
152 | (1) |
|
Implementing Encryption Protocols |
|
|
152 | (8) |
|
Wireless Encryption Protocol |
|
|
152 | (2) |
|
|
154 | (1) |
|
|
155 | (1) |
|
|
155 | (1) |
|
|
156 | (1) |
|
|
157 | (1) |
|
|
158 | (1) |
|
|
159 | (1) |
|
|
159 | (1) |
|
|
160 | (9) |
|
|
160 | (1) |
|
Choosing and Implementing the Best Method |
|
|
161 | (1) |
|
|
161 | (1) |
|
|
162 | (2) |
|
|
164 | (3) |
|
5 Public Key Infrastructure |
|
|
167 | (26) |
|
Objective 5.01 Explain the Fundamentals of Public Key Infrastructure |
|
|
169 | (12) |
|
|
169 | (1) |
|
|
170 | (2) |
|
|
172 | (3) |
|
|
172 | (1) |
|
Third-Party (Single Authority) Trust |
|
|
172 | (1) |
|
|
173 | (2) |
|
Key Management and Storage |
|
|
175 | (6) |
|
Centralized vs. Decentralized Storage |
|
|
175 | (2) |
|
Key Storage and Protection |
|
|
177 | (1) |
|
|
178 | (1) |
|
|
179 | (1) |
|
|
180 | (1) |
|
|
181 | (1) |
|
Objective 5.02 Implementing PKI Concepts to Promote Trust |
|
|
181 | (6) |
|
|
182 | (4) |
|
Certificate Requested, Issued, Published, and Received |
|
|
183 | (1) |
|
Certificate Suspension and Revocation |
|
|
183 | (2) |
|
|
185 | (1) |
|
|
186 | (1) |
|
|
186 | (1) |
|
|
187 | (1) |
|
|
188 | (2) |
|
|
190 | (3) |
III Identity and Access Management |
|
193 | (62) |
|
|
195 | (34) |
|
Objective 6.01 Explain the Fundamental Concepts and Best Practices Related to Authentication, Authorization, and Access Control |
|
|
197 | (11) |
|
|
197 | (5) |
|
|
198 | (1) |
|
|
199 | (3) |
|
Access Control Best Practices |
|
|
202 | (3) |
|
|
202 | (1) |
|
|
203 | (1) |
|
|
203 | (1) |
|
|
204 | (1) |
|
|
204 | (1) |
|
|
204 | (1) |
|
|
205 | (3) |
|
|
205 | (1) |
|
Discretionary Access Control |
|
|
206 | (1) |
|
Role-Based Access Control |
|
|
206 | (1) |
|
Rule-Based Access Control |
|
|
206 | (1) |
|
Attribute-Based Access Control |
|
|
207 | (1) |
|
Objective 6.02 Implement Appropriate Security Controls When Performing Account Management |
|
|
208 | (9) |
|
|
208 | (3) |
|
Using Appropriate Naming Conventions |
|
|
208 | (1) |
|
|
209 | (1) |
|
Setting Account Expiry Dates |
|
|
209 | (1) |
|
Disabling Unused Accounts |
|
|
209 | (1) |
|
Setting Time Restrictions |
|
|
209 | (1) |
|
Setting Machine Restrictions |
|
|
210 | (1) |
|
|
210 | (1) |
|
Restricting Multiple/Shared/Guest/Generic Accounts |
|
|
210 | (1) |
|
|
211 | (1) |
|
|
211 | (2) |
|
|
212 | (1) |
|
Domain Accounts and Single Sign-On |
|
|
212 | (1) |
|
|
213 | (1) |
|
Security Roles and Privileges |
|
|
213 | (1) |
|
|
213 | (1) |
|
|
214 | (1) |
|
|
214 | (1) |
|
File and Print Security Controls |
|
|
214 | (3) |
|
|
215 | (2) |
|
Objective 6.03 Analyze and Differentiate Among Types of Mitigation and Deterrent Techniques |
|
|
217 | (6) |
|
|
218 | (1) |
|
|
218 | (1) |
|
|
218 | (1) |
|
|
219 | (2) |
|
|
220 | (1) |
|
|
221 | (1) |
|
|
221 | (1) |
|
|
221 | (1) |
|
Personal Identification Verification Card |
|
|
222 | (1) |
|
|
222 | (1) |
|
|
223 | (1) |
|
|
223 | (1) |
|
|
224 | (3) |
|
|
227 | (2) |
|
7 Authentication and Identity Management |
|
|
229 | (26) |
|
Objective 7.01 Explain the Fundamental Concepts and Best Practices Related to Authentication, Authorization, and Access Services |
|
|
230 | (11) |
|
|
231 | (2) |
|
Single-Factor Authentication |
|
|
231 | (1) |
|
Two-Factor Authentication |
|
|
231 | (1) |
|
Multifactor Authentication |
|
|
232 | (1) |
|
|
232 | (1) |
|
|
233 | (8) |
|
Remote Access Authentication |
|
|
233 | (3) |
|
Remote Access Applications |
|
|
236 | (2) |
|
|
238 | (1) |
|
|
239 | (2) |
|
Objective 7.02 Explain the Function and Purpose of Authentication Services |
|
|
241 | (10) |
|
|
242 | (1) |
|
|
242 | (1) |
|
|
243 | (1) |
|
|
243 | (1) |
|
Extensible Authentication Protocol |
|
|
243 | (1) |
|
|
244 | (1) |
|
|
244 | (1) |
|
|
245 | (1) |
|
|
245 | (1) |
|
|
246 | (1) |
|
|
247 | (1) |
|
|
248 | (1) |
|
Certificates (Mutual Authentication) |
|
|
248 | (1) |
|
|
249 | (1) |
|
|
249 | (2) |
|
|
251 | (1) |
|
|
252 | (2) |
|
|
254 | (1) |
IV Network Security |
|
255 | (116) |
|
|
257 | (42) |
|
Objective 8.01 Implement Security Functionality on Network Devices and Other Technologies |
|
|
258 | (19) |
|
|
259 | (2) |
|
|
261 | (1) |
|
|
261 | (2) |
|
|
263 | (1) |
|
|
264 | (1) |
|
All-in-One Security Appliances |
|
|
264 | (4) |
|
|
265 | (1) |
|
|
265 | (1) |
|
|
265 | (2) |
|
|
267 | (1) |
|
|
268 | (1) |
|
Security Information and Event Management |
|
|
268 | (1) |
|
|
269 | (1) |
|
Intrusion Detection and Prevention |
|
|
269 | (6) |
|
|
272 | (1) |
|
|
272 | (1) |
|
|
273 | (2) |
|
Application-Aware Devices |
|
|
275 | (1) |
|
|
276 | (1) |
|
Objective 8.02 Explain Network Design Elements and Compounds |
|
|
277 | (17) |
|
|
277 | (4) |
|
|
278 | (2) |
|
|
280 | (1) |
|
|
280 | (1) |
|
Network Security Techniques |
|
|
281 | (6) |
|
|
281 | (1) |
|
|
282 | (2) |
|
Internal Network Addressing |
|
|
284 | (1) |
|
|
284 | (1) |
|
|
285 | (2) |
|
|
287 | (4) |
|
|
287 | (1) |
|
|
287 | (2) |
|
|
289 | (1) |
|
|
290 | (1) |
|
|
290 | (1) |
|
|
291 | (1) |
|
|
292 | (8) |
|
|
292 | (1) |
|
|
293 | (1) |
|
|
294 | (1) |
|
|
294 | (3) |
|
|
297 | (2) |
|
9 Secure Network Administration |
|
|
299 | (40) |
|
Objective 9.01 Implement and Use Common Protocols |
|
|
300 | (9) |
|
|
301 | (1) |
|
|
301 | (1) |
|
|
302 | (1) |
|
|
302 | (1) |
|
|
303 | (1) |
|
|
303 | (1) |
|
|
304 | (2) |
|
|
304 | (1) |
|
|
305 | (1) |
|
|
305 | (1) |
|
|
306 | (1) |
|
|
306 | (1) |
|
|
307 | (1) |
|
|
308 | (1) |
|
|
308 | (1) |
|
|
308 | (1) |
|
|
309 | (1) |
|
|
309 | (1) |
|
Objective 9.02 Identify Commonly Used Default Network Ports |
|
|
309 | (3) |
|
|
310 | (2) |
|
Objective 9.03 Analyze and Differentiate Among Types of Network Attacks |
|
|
312 | (13) |
|
|
313 | (2) |
|
Distributed Denial of Service |
|
|
313 | (1) |
|
|
313 | (1) |
|
|
314 | (1) |
|
|
314 | (1) |
|
|
315 | (1) |
|
|
315 | (1) |
|
|
316 | (1) |
|
|
316 | (2) |
|
|
318 | (1) |
|
|
318 | (1) |
|
|
318 | (2) |
|
|
320 | (1) |
|
|
320 | (1) |
|
|
321 | (1) |
|
|
322 | (1) |
|
|
322 | (1) |
|
|
323 | (1) |
|
|
323 | (1) |
|
|
324 | (1) |
|
|
324 | (1) |
|
Malicious Insider Threats |
|
|
324 | (1) |
|
Objective 9.04 Apply and Implement Secure Network Administration Principles |
|
|
325 | (9) |
|
Networking Device Configuration |
|
|
325 | (4) |
|
|
325 | (1) |
|
|
326 | (1) |
|
|
327 | (2) |
|
|
329 | (1) |
|
Unified Threat Management |
|
|
329 | (1) |
|
Network Device Threats and Risks |
|
|
329 | (2) |
|
|
330 | (1) |
|
|
330 | (1) |
|
Transitive Access and Privilege Escalation |
|
|
330 | (1) |
|
|
331 | (1) |
|
|
331 | (9) |
|
|
331 | (1) |
|
|
332 | (1) |
|
|
332 | (1) |
|
|
333 | (1) |
|
|
333 | (1) |
|
|
334 | (1) |
|
|
334 | (1) |
|
|
335 | (2) |
|
|
337 | (2) |
|
10 Securing Wireless Networks |
|
|
339 | (32) |
|
Objective 10.01 Implement Wireless Networks in a Secure Manner |
|
|
340 | (18) |
|
Wireless LAN Technologies |
|
|
341 | (1) |
|
|
341 | (1) |
|
Spread-Spectrum Technology |
|
|
341 | (1) |
|
|
342 | (1) |
|
|
342 | (4) |
|
|
343 | (2) |
|
|
345 | (1) |
|
|
346 | (4) |
|
|
347 | (1) |
|
|
347 | (2) |
|
|
349 | (1) |
|
Securing Wireless Networks |
|
|
350 | (1) |
|
|
350 | (1) |
|
|
351 | (1) |
|
|
352 | (1) |
|
|
352 | (1) |
|
|
353 | (1) |
|
|
354 | (1) |
|
|
354 | (1) |
|
Wireless Authentication Protocols |
|
|
355 | (1) |
|
|
355 | (1) |
|
|
356 | (1) |
|
|
356 | (1) |
|
|
356 | (1) |
|
|
357 | (1) |
|
|
358 | (1) |
|
Objective 10.02 Analyze and Differentiate Among Types of Wireless Attacks |
|
|
358 | (7) |
|
|
358 | (1) |
|
|
359 | (1) |
|
Bluetooth Vulnerabilities |
|
|
359 | (1) |
|
|
360 | (1) |
|
|
361 | (1) |
|
Access Points (Evil Twin) |
|
|
361 | (1) |
|
Deauthentication and Disassociation |
|
|
362 | (1) |
|
|
362 | (1) |
|
Packet Sniffing and Eavesdropping |
|
|
363 | (1) |
|
|
363 | (1) |
|
|
363 | (1) |
|
|
364 | (10) |
|
|
364 | (1) |
|
|
364 | (1) |
|
|
364 | (1) |
|
|
365 | (1) |
|
|
366 | (2) |
|
|
368 | (3) |
V Host, Application, and Data Security |
|
371 | (88) |
|
|
373 | (48) |
|
Objective 11.01 Analyze and Differentiate Among Types of Malware |
|
|
374 | (10) |
|
|
375 | (3) |
|
|
375 | (2) |
|
File Types That Commonly Carry Viruses |
|
|
377 | (1) |
|
|
378 | (1) |
|
|
378 | (1) |
|
|
378 | (1) |
|
|
379 | (1) |
|
|
379 | (1) |
|
|
379 | (1) |
|
|
380 | (1) |
|
|
380 | (1) |
|
|
381 | (1) |
|
|
382 | (1) |
|
|
383 | (1) |
|
Objective 11.02 Carry Out Appropriate Procedures to Establish Host Security |
|
|
384 | (22) |
|
Physical Hardware Security |
|
|
384 | (2) |
|
|
385 | (1) |
|
Host Software Security Baseline |
|
|
386 | (1) |
|
Operating System Hardening |
|
|
387 | (8) |
|
|
387 | (1) |
|
|
387 | (1) |
|
|
388 | (1) |
|
|
388 | (1) |
|
Services and OS Configuration |
|
|
389 | (1) |
|
|
390 | (1) |
|
System User Accounts and Password Threats |
|
|
390 | (2) |
|
Management Interface Security |
|
|
392 | (1) |
|
|
393 | (1) |
|
Software Access and Privileges |
|
|
393 | (1) |
|
|
394 | (1) |
|
Host Security Applications |
|
|
395 | (9) |
|
|
395 | (1) |
|
Antivirus and Anti-spyware Software |
|
|
395 | (2) |
|
|
397 | (1) |
|
|
397 | (1) |
|
|
398 | (2) |
|
|
400 | (3) |
|
Host-Based Intrusion Detection System |
|
|
403 | (1) |
|
|
404 | (1) |
|
|
404 | (2) |
|
|
404 | (1) |
|
|
405 | (1) |
|
Objective 11.03 Understand Mobile Security Concepts and Technologies |
|
|
406 | (10) |
|
|
406 | (1) |
|
|
406 | (1) |
|
|
407 | (1) |
|
|
408 | (1) |
|
|
408 | (1) |
|
|
408 | (1) |
|
|
408 | (1) |
|
|
408 | (1) |
|
|
408 | (3) |
|
|
409 | (1) |
|
|
409 | (1) |
|
|
410 | (1) |
|
|
411 | (1) |
|
Password/Screen Lock/Lockout |
|
|
411 | (1) |
|
|
411 | (1) |
|
|
411 | (1) |
|
|
412 | (1) |
|
|
412 | (1) |
|
|
412 | (1) |
|
|
412 | (10) |
|
|
413 | (1) |
|
|
413 | (1) |
|
|
414 | (1) |
|
Push Notification Technologies |
|
|
414 | (1) |
|
|
415 | (1) |
|
|
415 | (1) |
|
|
416 | (1) |
|
|
416 | (3) |
|
|
419 | (2) |
|
12 Securing Applications and Data |
|
|
421 | (38) |
|
Objective 12.01 Analyze and Differentiate Among Types of Attacks and Vulnerabilities |
|
|
422 | (16) |
|
Web Application Vulnerabilities |
|
|
423 | (9) |
|
|
423 | (1) |
|
|
424 | (1) |
|
|
425 | (1) |
|
|
425 | (1) |
|
|
426 | (1) |
|
|
426 | (1) |
|
|
427 | (1) |
|
|
428 | (1) |
|
|
428 | (1) |
|
|
429 | (1) |
|
Cross-Site Request Forgery (XSRF) |
|
|
429 | (1) |
|
|
429 | (1) |
|
|
429 | (1) |
|
|
430 | (1) |
|
|
431 | (1) |
|
|
431 | (1) |
|
|
431 | (1) |
|
Internet Server Vulnerabilities |
|
|
432 | (6) |
|
|
432 | (1) |
|
|
433 | (1) |
|
|
434 | (1) |
|
|
435 | (1) |
|
LDAP and Directory Services |
|
|
436 | (1) |
|
|
436 | (2) |
|
|
438 | (1) |
|
Objective 12.02 Explain the Importance of Application Security |
|
|
438 | (9) |
|
Development Life-Cycle Models |
|
|
439 | (1) |
|
|
439 | (1) |
|
|
439 | (1) |
|
|
439 | (6) |
|
Secure Development Operations |
|
|
440 | (1) |
|
|
440 | (1) |
|
|
441 | (1) |
|
|
441 | (1) |
|
Code Testing and Verification |
|
|
441 | (1) |
|
Error and Exception Handling |
|
|
442 | (1) |
|
|
442 | (1) |
|
Server-Side vs. Client-Side Validation |
|
|
443 | (1) |
|
|
443 | (1) |
|
Cross-Site Request Forgery |
|
|
443 | (1) |
|
Code Reuse and Third-Party Libraries |
|
|
444 | (1) |
|
|
444 | (1) |
|
|
445 | (1) |
|
|
445 | (2) |
|
Application Configuration Baseline |
|
|
446 | (1) |
|
Application Patch Management |
|
|
446 | (1) |
|
Objective 12.03 Explain the Importance of Data Security |
|
|
447 | (7) |
|
|
448 | (1) |
|
|
449 | (3) |
|
|
449 | (1) |
|
|
449 | (1) |
|
|
450 | (1) |
|
|
450 | (1) |
|
Individual File Encryption |
|
|
451 | (1) |
|
Removable Media and Mobile Devices |
|
|
451 | (1) |
|
Data Destruction and Media Sanitization |
|
|
451 | (1) |
|
|
452 | (1) |
|
|
453 | (1) |
|
|
454 | (1) |
|
|
454 | (1) |
|
|
455 | (2) |
|
|
457 | (2) |
VI Threats and Vulnerabilities |
|
459 | (64) |
|
13 Monitoring for Security Threats |
|
|
461 | (34) |
|
Objective 13.01 Analyze, Interpret, and Troubleshoot Different Types of Mitigation and Deterrent Techniques |
|
|
462 | (27) |
|
|
463 | (1) |
|
Detecting Security-Related Anomalies |
|
|
464 | (6) |
|
System and Performance Monitoring |
|
|
464 | (1) |
|
|
465 | (2) |
|
|
467 | (1) |
|
Intrusion Detection and Intrusion Prevention Systems |
|
|
468 | (1) |
|
Bypass of Security Equipment |
|
|
469 | (1) |
|
|
470 | (7) |
|
|
470 | (1) |
|
|
471 | (1) |
|
|
472 | (1) |
|
|
473 | (1) |
|
|
473 | (1) |
|
|
474 | (1) |
|
Security Logging Applications |
|
|
475 | (1) |
|
Reports and Trend Monitoring |
|
|
476 | (1) |
|
|
477 | (1) |
|
|
477 | (5) |
|
|
478 | (1) |
|
|
478 | (2) |
|
User Access Rights Review |
|
|
480 | (1) |
|
Reviewing Audit Information |
|
|
481 | (1) |
|
Auditing the Administrators |
|
|
481 | (1) |
|
Storage and Retention Policies |
|
|
482 | (1) |
|
|
482 | (3) |
|
Disable Unnecessary Services |
|
|
483 | (1) |
|
Protect Management Interfaces and Applications |
|
|
483 | (1) |
|
Utilize Password Protection |
|
|
483 | (1) |
|
Disable Unnecessary Accounts |
|
|
484 | (1) |
|
Improve Baseline Configurations |
|
|
484 | (1) |
|
Ensure Systems Are Up to Date |
|
|
485 | (1) |
|
|
485 | (1) |
|
|
485 | (2) |
|
Limit and Filter MAC Addresses |
|
|
486 | (1) |
|
|
486 | (1) |
|
Disable Unused Interfaces and Ports |
|
|
487 | (1) |
|
|
487 | (1) |
|
Mitigating Threats in Alternative Environments |
|
|
487 | (2) |
|
|
489 | (1) |
|
|
490 | (2) |
|
|
492 | (3) |
|
14 Vulnerability Assessments |
|
|
495 | (28) |
|
Objective 14.01 Implement Assessment Tools and Techniques to Discover Security Threats and Vulnerabilities |
|
|
496 | (16) |
|
Vulnerability Assessment Tools |
|
|
498 | (14) |
|
|
499 | (1) |
|
|
499 | (1) |
|
|
500 | (2) |
|
|
502 | (1) |
|
|
503 | (1) |
|
|
504 | (2) |
|
|
506 | (2) |
|
|
508 | (1) |
|
|
508 | (1) |
|
Application Code Assessments |
|
|
509 | (3) |
|
Objective 14.02 Implement Penetration Tests When Appropriate |
|
|
512 | (5) |
|
White, Black, and Gray Box Testing |
|
|
515 | (14) |
|
|
515 | (1) |
|
|
516 | (1) |
|
|
517 | (1) |
|
|
517 | (1) |
|
|
518 | (2) |
|
|
520 | (3) |
VII Appendixes |
|
523 | (8) |
|
|
525 | (4) |
|
CompTIA Security+ Exam Format |
|
|
526 | (1) |
|
CompTIA Security+ and Beyond |
|
|
526 | (1) |
|
Getting the Latest Information on the CompTIA Security+ Exam |
|
|
527 | (2) |
|
|
529 | (2) |
|
|
529 | (1) |
|
Total Tester Premium Practice Exam Software |
|
|
529 | (1) |
|
Installing and Running Total Tester Premium Practice Exam Software |
|
|
529 | (1) |
|
|
530 | (1) |
|
|
530 | (1) |
Index |
|
531 | |