Reference Library · Sari Greene, CISSP

SY0-701 Crash Course

Two-day crash course slide notes (337 slides), sourced verbatim from the provided course material.

Day 1

Welcome to Day 1

CompTIA SY0-701 Security+ Crash Course Sari Greene, CISSP, ISSMP, CRISC, CISM, CISA, SEC+ sari@sarigreenegroup.com

Day 1

Why Certify?

e: sari@sarigreenegroup.com t: @sari_greene l: https://www.linkedin.com/in/sarigreene/ w: www.sarigreenegroup.com

Day 1

Where are You in your Certification Journey?

o I’ve just begun studying for the CompTIA Security + exam. o I am in the midst of studying for the CompTIA Security + exam. o I am almost ready to take the CompTIA Security + exam. o I am already CompTIA Security+ certified.

Day 1

Crash Course Objectives

You have just begun studying You are currently studying You are almost ready to take your exam You are already Security+ certified Reinforce your knowledge and fill in some gaps. Enhance your skillset and receive continuing education credits. Immersion into the five examination domains. Assess your strengths and weaknesses and perhaps modify your study plan.

Day 1

Certification Exam Outline

This course is based on the SY0-701 Certification Exam Objectives.

  • The CompTIA Security+ Certification

Exam Objectives document can be found at https://www.comptia.org/training/reso urces/exam-objectives.

  • Course slides are available in the

“Resource List” window. Please respect the copyright.

  • This course is being recorded and will

be available to you within 24-48 hours

Day 1

Comprehensive Study

My CompTIA Security+ SY0-701 27+hr. Video Course covers in detail every exam objective and includes 3 Second Challenges, Security-in-Action case studies, Word Clouds, Deep Dive Quizzes, and Closer Look Labs. Available to you on the O’Reilly Media platform! CompTIA Labs is a remote lab environment that enables hands-on practice and skill development in actual software applications. The virtual lab scenarios are aligned with CompTIA exam objectives and are based on real workplace events.

  • https://www.comptia.org/training/certmaster-labs
Day 1

Exam Objectives (Course Outline)

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 1

Domain 1

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 1

Domain 1.0 General Security Concepts

# Objective 1.1 Compare and contrast various types of security controls. 1.2 Summarize fundamental security concepts. 1.3 Explain the importance of change management processes and the impact to security. 1.4 Explain the importance of using appropriate cryptographic solutions.

Day 1

1.1 Compare and contrast various types of security controls.

Day 1

Cyber Basics

Term Description Vulnerability A vulnerability is a weakness. Threat A threat is a potential danger. Threat Actor A threat actor is an adversary with malicious intent Exploit An exploit is when a threat actor successfully takes advantage of a vulnerability. Controls Controls are tactics, mechanisms, or strategies that proactively minimize risk by either:

  • Reducing or eliminating a vulnerability.
  • Reducing or eliminating the likelihood that a threat actor will be able to exploit a

vulnerability.

  • Reducing or eliminating the impact of an exploit.

Countermeasures• Countermeasures are controls implemented to address a specific threat; they are generally reactive.

Day 1

Control Categories (implementation)

Category Description Technical Technical control mechanisms are implemented using hardware, software, and/or firmware components.

  • Can be native or supplemental.

Managerial Managerial controls support risk management, governance, oversight, strategic alignment, and decision making Operational Operational controls are aligned with a process that are primarily implemented and executed by people. Physical Physical controls are designed to address physical interactions. Generally related to buildings and equipment.

Day 1

Control Classifications (objective)

Control Objective Description Deterrent Deterrent controls discourage a threat agent from acting. Preventative Preventative controls stop a threat agent from being successful. Detective Detective controls identify and report a threat agent or action. Corrective Corrective controls minimize the impact of a threat agent or modify or fix a situation. Directive Directive controls are proactive actions taken to cause or encourage a desirable event or outcome to occur. They are often used to increase the effectiveness of other controls. Compensating Compensating controls are controls implemented in lieu of a recommended control that provides equivalent or comparable protection

Day 1

Security Control Diversity

  • Controls should not be subject to a cascade effect and should maintain

independence.

  • Diversity of type of control and associated vendor should be considered.

Defense-in-Depth (also known as layered security) is the design and implementation of multiple overlapping layers of diverse controls.

Day 1

1.2 Summarize fundamental security concepts.

Day 1

Information Security CIA Triad + Privacy

Confidentiality Integrity Information Security Availability Privacy

Day 1

Fundamental Principles

Confidentiality Integrity is the principle that systems are trustworthy, and work as intended, and the data is complete and accurate. Integrity Availability Confidentiality is the assurance that information is not disclosed to unauthorized persons, processes, or devices. Confidentiality covers data in storage, during processing, and in transit. Availability is the principle that Information, systems, and supporting infrastructure are operating and accessible when needed. Privacy Privacy is the right of an individual to control the use of their personal information. Data privacy controls relate to collection, usage, notification, accuracy, and sharing. .

Day 1

Zero Trust (ZT)

Zero trust (ZT) is a security framework requiring all subjects, assets, and workflows to be authenticated, authorized, and continuously validated before being granted or keeping access to applications and data.

  • The goal is to prevent unauthorized access to data and services coupled with

making the access control enforcement as granular as possible.

  • Zero trust supports the principle of least privilege.
  • Zero trust minimizes the risks associated with standing privilege.
  • Standing privilege refers to 24x7x365 privileged access.
Day 1

Physical Security

Physical security is based upon a layered defense model. The premise of a layered defense model is that if an intruder can bypass one layer of controls, the next layer of controls should provide additional deterrence or detection capabilities.

  • Obstacles (deterrent controls) to frustrate trivial attackers and delay

serious ones.

  • Detective controls make it likely that attacks will be noticed.
  • Response mechanisms to catch or impede attackers.

Physical security is the protection of people, property, and physical assets from actions and events that could cause damage, loss, or unauthorized activity.

Day 1

Site Security Controls

Control Description Lighting Lighting for personnel safety and intruder deterrence.

  • Intruders are less likely to enter well-lit areas.

Signs Signs for personnel safety and intruder deterrence.

  • Warning signs indicate surveillance (“someone is paying attention”).

Barriers Barriers such as walls, fences, gates, bollards, and access control vestibules define the perimeter and can be used to control and divert flow of traffic. Surveillance Surveillance sensors* can be used to monitor and detect suspicious, abnormal, or unwanted behavior. [*infrared, motion, photometric, acoustical, contact, pressure, microwave, ultrasonic] Guards Security guards may be stationed at checkpoints, patrol the area, manage surveillance, and respond to breaches and/or suspicious activity.

Day 1

Environmental Impact

  • Computers, electronic equipment, and transmission media are sensitive to

environmental factors such as heat, humidity, air flow, and power quality.

  • Environmental systems are often provided by and/or managed by

contractors.

  • Environmental system providers should be subject to due diligence

(investigation) and included in vendor management programs.

  • Environmental controls/products should be included in vulnerability

management, patch management, disaster recovery, business continuity, and assessment/audit programs. Environmental imbalance and vulnerabilities can impact stability, availability, and integrity.

Day 1

Environmental Baselines

Control Description Temperature Acceptable temperature for an area containing computing devices is between 18-27 degrees C (64.4-80.6 F).* Humidity High humidity can cause corrosion and low humidity can cause excessive static electricity. Relative humidity between 50-70% is acceptable.* Power Continuous clean (filtered) power - consistent voltage. Fire Fire detection and suppression capabilities. Discharge and Interference Electronic components and cable can be impacted by electrostatic discharge (ESD), Electromagnetic Interference (EMI), and Radio Frequency Interference (RFI). * Source: American Society of Heating, Refrigerating and Air-Conditioning Engineers

Day 1

1.3 Explain the importance of change management processes

and the impact to security.

Day 1

Configuration Management

ITIL defines Service Asset and Configuration Management (SACM) as: “The process responsible for ensuring that the assets required to deliver services are properly Configuration Management (CM) is a set of practices designed to ensure that configuration items are deployed in a consistent state and stay that way through their lifetime. The goal of configuration management is to minimize risk.

  • A Configuration Item (CI) is an aggregation of information system components

and treated as a single entity throughout the configuration management process.

  • A Baseline Configuration (BC) is a set of specifications for a CI, that has been

reviewed and agreed upon and can be changed only through change control procedures.

  • The baseline configuration is used as a basis for future builds and releases.
Day 1

Automated Provisioning

ITIL controlled, and that accurate and reliable information about those assets is available when and where it is needed. This information includes details of how the assets have been configured and the relationships between assets. Automated provisioning is the ability to deploy information technology (IT) or operational technology (OT) systems and services using predefined, automated procedures without requiring human intervention.

  • Automation is used to ensure consistency in provisioning in support of

configuration management.

  • Automation reduces or eliminates manual dependencies and human error.
Day 1

Provisioning Processes

Process Description Demand-generated Resource Allocation Demand –generated resource allocation is the automatic provisioning and deprovisioning of resources based upon demand. Idempotence Idempotence is a principle that every time an automated configuration script is run, the same exact result is produced. Immutable System Immutability is the principle that resources should not be changed, only created and destroyed.

  • Utilizes automation to replace rather than fix.

Infrastructure- asCode Infrastructure-as-code is using code to manage configurations and automate provisioning of infrastructure.

  • Supports the principle of Idempotence.
Day 1

Change Management

  • The change control process establishes standard procedures for

managing change requests in a secure, timely, and efficient manner.

  • Process components include prioritization, impact analysis, testing,

rollback strategies, accountability, documentation, automation and implementation. The objective of change management is to drastically minimize the risk and impact a change can have on business operations.

Day 1

1.4 Explain the importance of using appropriate cryptographic

solutions.

Day 1

Cryptography

  • Modern cryptography has widened the historical definition to include

assurance of integrity and sender identity.

  • Strength of a cryptosystem is a combination of the algorithm, the

algorithmic process, the length of the key, and the secrecy of the key. If one element is weak, the cryptosystem can potentially be compromised.

  • Deprecated means that the use of the algorithm and key length is

allowed, but the user must accept some risk due to inherent weaknesses.

  • Broken means that the algorithm and/or key length is exploitable.

Traditional Cryptography is the conversion of communication into a form that can only be read by the intended recipient.

Day 1

Cryptographic Solutions (Use case)

Solution Use Case Encryption Encryption is the process of encoding information.

  • The use case of encryption is confidentiality.

Hashing Hashing is a one-way function that turns a file or string of text into a unique digest of the message.

  • The use case for hashing is integrity.

Digital Signatures A digital signature is a hash value encrypted using the sender's private key.

  • The use case is sender authenticity and non-repudiation.

Digital Certificates A digital certificate is a digital object that is tied to a cryptographic key pair.

  • The use case for a digital certificate is authentication.
Day 1

Cryptographic Primer

Element Description Cipher A cipher is a technique that transforms plaintext into (encrypted text) ciphertext and back. Algorithm An algorithm is a mathematically complex modern cipher. Key A key (cryptovariable) is a secret value used with an algorithm. The key dictates what parts of the algorithm will be used, in what order, and with what values. Symmetric Key A symmetric key is a single shared key used for both encryption and decryption. Asymmetric Asymmetric keys are two mathematically related keys used for encryption and decryption.

Day 1

Encryption

Clear Text Algorithm & Key Ciphertext Ciphertext Algorithm & Key Plaintext Encryption is commonly used to protect the confidentiality of data in transit and data at rest.

Day 1

Symmetric Encryption

Clear Text Symmetric Algorithm & Key Ciphertext Ciphertext Symmetric Algorithm & Key Plaintext Symmetric encryption uses the same key to encrypt and decrypt. The key may be referred to as a single key, shared key, secret key, or session key.

Day 1

Asymmetric Encryption

Clear Text Asymmetric Algorithm & Key Ciphertext Ciphertext Asymmetric Algorithm & Key Plaintext Asymmetric encryption uses two mathematically related keys to encrypt and decrypt. The keys are referred to as public and private keys. The public key is freely distributed. The private key must be secured.

Day 1

Asymmetric Encryption Message Flow

Plaintext Asymmetric Algorithm & Bob’s Public Key Encrypted Message Encrypted Message Asymmetric Algorithm & Bob’s Private Key Plaintext The challenge is that asymmetric is computationally intensive. Alice sends Bob an asymmetrically encrypted message using public and private keys. The public key is freely distributed. The private key must be secured.

Day 1

Symmetric and Asymmetric Comparison

Feature Symmetric Asymmetric # of Keys Single shared key Key pair Processing Computationally efficient Computationally intensive Block Sizes Large Small Scalability Not scalable Scalable Key Exchange Key exchange is inherently insecure Key exchange distribution system

Day 1

Hybrid Message Flow

Encrypted Session Key Asymmetric Algorithm & Bob’s Private Key Session Key Encrypted Message Symmetric Algorithm & Session Key Plaintext Message Plaintext Message Symmetric Algorithm + Session Key Encrypted Message Session Key Asymmetric Algorithm & Bob’s Public Key Encrypted Session Key

Day 1

Hashing

Hashing can be used to:

  • Validate that a message has not been changed during

transmission.

  • Verify that a file has not been altered.
  • Verify that a forensic clone is the exact same as the original

media The objective of hashing is to prove integrity. Hashing produces a visual representation of a data set that can be used for comparative purposes. The output is known as a message digest, fingerprint, or hash value.

Day 1

The Hashing Process

Variable Length Input Hash Function Unique One-way Fixed Length Output

Day 1

Hash Generation

Source: http://onlinemd5.com/

Day 1

Message Digests in Action

Alice puts message through a hash function and generates a message digest (hash value) Alice sends the message and message digest to Bob Bob receives the message and message digest Bob puts message through a hash function and generates a message digest (hash value) Bob compares both message digests If the message digests are the same – the message was not modified in transmission

Day 1

Digital Signature

The objective of a digital signature is to prove integrity and non-repudiation. Nonrepudiation means that the signer cannot deny sending the message.

  • Digital signatures require two algorithms - a hashing algorithm & a digital

signature algorithm (DSA , RSA). A digital signature is a message digest that has been encrypted using the sender’s private key.

Day 1

Digital Signatures in Action

Alice puts message through a hash function and generates a message digest Alice encrypts the message digest with her private key Alice sends the message and message digest to Bob Bob puts the plaintext message through the same hash function and generates a message digest Bob decrypts the message digest using Alice’s public key proving Authenticity Bob compares both message digests If the message digests are the same – the message was not modified proving Integrity If the message digests are different – the message was modified

Day 1

Digital Certificates

  • The X.509 standard defines the certificate format and fields for public keys.
  • The X.509 standard defines the distribution procedures.
  • The current version of X.509 for certificates is v3.
  • There are a variety of certificate types including personal, machine, domain,

extended validation, code, trusted/intermediate authority. A digital certificate is a digital form of identification. It consists of a cryptographic key pair and information about the entity associated with the keys. A digital certificate can be purchased from a commercial certificate authority or self-generated.

Day 1

• Browsers and devices trust a CA by accepting the Root Certificate into its

root store – essentially a database of approved CAs that come preinstalled with the browser or device.

  • The CA receives certificate requests, validates the applications, issues

the certificates, and publishes the ongoing validity status of issued certificates.

  • A Registration Authority (RA) offloads some of the work from the CA.

The RA can accept and process registration requests and distribute certificates. Digital certificates are issued by commercial trusted parties, called Certificate Authorities (CA). Commercial Certificate Authority

Day 1

Commercial Certificate Request Process

Using a key generation program, applicant generates a publicprivate key pair Applicant submits a certificate signing request (Identifying info + public key) The CA or RA validates the application The CA generates the certificate and signs it with their private key The CA send the certificate to the applicant The applicant installs the certificate The applicant renews or destroys the certificate

Day 1

Certificate Validity

CA-maintained list of certificates that have been revoked

  • Pull model – CRL is downloaded by the user or

organization.

  • Push model – CRL is automatically sent out by the CA at

regular intervals. Process designed to query the status of a certificate in realtime.

  • OCSP stapling is a time-stamped (cached) OCSP

response. Certificate Revocation List (CRL) Online Certificate Status Protocol (OCSP)

Day 1

Emerging Cryptography

Solution Description Homomorphic Encryption Homomorphic encryption allows for encrypted data to be processed.

  • Partially Homomorphic Encryption (PHE)
  • Somewhat Homomorphic Encryption (SHE)
  • Fully Homomorphic Encryption (FHE - in development)

Quantum Encryption Quantum cryptography, also called quantum encryption, applies principles of quantum mechanics to encrypt messages. Quantum computers are machines that exploit quantum mechanical phenomena to solve mathematical problems that are difficult or intractable for conventional computers. Post-Quantum Encryption The goal of post-quantum cryptography is to develop cryptographic systems that are secure against both quantum and classical computers and can interoperate with existing communications protocols and networks.

Day 1

Steganography

  • Steganography consists of a message and a cover image.
  • Message is the secret data.
  • Cover image is the carrier that hides the message. The cover image

can be text, image, audio or video. Steganography is the science of hiding information. The objective of is concealment.

Day 1

Steganography Illustrated

Copy /b image1.jpg+text1.txt final1.jpg

Day 1

Steganography v. Cryptography

Feature Steganography Cryptography Purpose Purpose is to conceal (covered writing). Purpose is confidentiality, integrity, and/or non-repudiation. Communication Channel The existence of the secret communication channel is not known. The existence of the communication channel is known Mathematical Transforms Mathematical transforms are not generally used. Mathematical transforms are used.

Day 1

Assessment Question 1

Which statement about controls and countermeasure is not true? A. Controls are designed to proactively minimize risk. B. Countermeasures are designed to reactively minimize risk. C. Countermeasures are designed to address a specific threat. D. Controls by design are not independent of each other.

Day 1

Assessment Question 2

Which statement best describes the principle of integrity? A. Assurance that information is not disclosed without authorization. B. Data is complete and accurate, and systems work as intended. C. Individuals have the right to control their information. D. Consent to collect and utilize information data.

Day 1

Assessment Question 3

Which action is not supported by Zero Trust? A. Reauthentication B. Least privilege C. Continuous validation D. Standing privilege

Day 1

Assessment Question 4

What is the acceptable relative humidity for Data Center equipment? A. 0% B. Less than 20% C. 50-70% D.Above 80%

Day 1

Assessment Question 5

Mary wants to use asymmetric encryption for a session key exchange with Bob. Which cryptovariable should she use to encrypt the session key? A. Mary’s public key B. Mary’s private key C. Bob’s public key D. Bob’s private key

Day 1

Domain 2

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 1

Domain 2.0 Threats, Vulnerabilities & Mitigations

# Objective 2.1 Compare and contrast common threat actors and motivations. 2.2 Explain common threat vectors and attack surfaces. 2.3 Explain various types of vulnerabilities. 2.4 Given a scenario, analyze indicators of malicious activity. 2.5 Explain the purpose of mitigation techniques used in the enterprise.

Day 1

2.1 Compare and contrast common threat actors and

motivations.

Day 1

Cyber Threat Actors

Lone Skilled | Unskilled Attacker Hacktivist Organized Crime (cyber-criminals) Nation- State Insiders | Shadow IT Competitors

Day 1

Threat Modeling

Threat modeling is a structured process by which potential threats and threat actors can be identified, enumerated, and prioritized. Threat modeling approaches:

  • Asset-centric identifies valued assets and related motivation

[what/why].

  • Architecture-centric identifies system design component strength and

weaknesses [how].

  • Attacker-centric identifies known adversaries [who].
Day 1

Threat Intelligence Sources

Subscription and/or public feeds provided by vendors such as Microsoft, Cisco, or Apple. Government Agencies Technology Vendors Journalists, Researchers & Thought Leaders Cybersecurity Companies Subscription and/or public feeds provided by cybersecurity vendors such as TylerDetect, AlienVault, FireEye, RSA, and Secureworks. Bruce Schneier, Jeremiah Grossman, Brian Krebs, Mark Russinovich, Kim Zetter, Nicole Perlroth, Andy Greenberg, Ellen Nakashima, etc. Data provided by agencies such as NIST, FBI, USCERT, NVD, and the Cybersecurity & Infrastructure Agency (CISA). Threat intelligence is evidence-based knowledge about emerging threats that can be used to inform control decisions OSINT Open-Source Intelligence (OSINT) is a term used to refer to the data collected from publicly available sources to be used in an intelligence context. .

Day 1

2.2 Explain common threat vectors and attack surfaces.

Day 1

Threat Vectors

  • Common threat vectors include default credential, weak permissions, data

exfiltration, open ports, unsupported systems and software, unsecured networks, shadow IT, and vulnerable software.

  • Operational threat vectors manifest in day-to-day activities and are generally

related to weak or non-existent internal controls. A threat is a danger. A threat vector, (also known as attack vector) is a potential pathway, or scenario that can be exploited. An attack surface is the sum of all threat vectors.

Day 1

Third-party Threat Vectors

  • Third-party threat vectors (pathways to exploit) include lack of support,

proprietary configurations, EOL, and supply chain disruption and nonconformance.

  • Consequences can include financial loss, reputational damage, inefficient

operations, data breach | exfiltration, service disruption, and regulatory noncompliance. Third-parties include vendors, managed service providers (MSPs), business partners, consultants, and contractors.

Day 1

Human Threat Vector

  • Social engineering is often considered the path of least resistance.
  • Social Engineers use psychology to take advantage of basic human instincts

and exploit human cognition functions. Pretexting and impersonation are the two primary social engineering tactics.

  • A significant number of security incidents and data breaches have started

with or have included a social engineering component.

  • An emerging trend is the use of synthetic content.
  • Social engineering is a critical training topic across an entire organization.

Social engineering is the action of exploiting human nature rather than technical hacking techniques to gain access to minds, systems, data or buildings.

Day 1

2.3 Explain various types of vulnerabilities.

Day 1

Types of Vulnerabilities

Type Description Network Network vulnerabilities are weaknesses within an organization's hardware or software infrastructure. Operating System Operating system vulnerabilities are code weaknesses (bugs) which can be exploited and/or OS mis-configurations. Process Process vulnerabilities occur when there is a security exposure within the process. People Human vulnerabilities are the result of human error, inattention, unintentional or accidental actions. Zero-day A zero-day vulnerability is a flaw in hardware or software that has been discovered but a fix is not yet available. A zero-day exploit is a method that weaponizes a discovered vulnerability.

Day 1

Vulnerability Management

  • The goal of vulnerability management is to reduce the risk of security

breaches and minimize the potential impact of any vulnerabilities that are identified.

  • Vulnerability management is an ongoing process that requires continuous

monitoring and updating as new vulnerabilities are discovered or new threats emerge. Vulnerability management is the process of identifying, assessing, reporting on, prioritizing, and mitigating vulnerabilities.

Day 1

2.4 Given a scenario, analyze indicators of malicious activity.

Day 1

Cyber Attack Terms to Know

Term Description Targeted Attacker chooses a target for a specific objective. Opportunistic Attacker takes advantage of a vulnerable target (not previously known to them). Amplification Attacker uses an amplification factor to multiply its power. Artifact Information of interest (clues) such as virus signature, IP addresses, malicious URLs, command and control connections, file changes, and “reports from the field”.

Day 1

Attack Indicators

There are two primary types of attack indicators – IoA and IoC. Indicators of Compromise (IoC) are artifacts about an event that has already happened and are used to identify potential security breaches. Typical artifacts left behind by an attacker include new user accounts, file hashes, virus signature, malicious files, command and control connections, modification of system and registry settings, evidence of data exfiltration, and patterns of suspicious behavior Indicators of Attack (IoA) are a set of behaviors or actions (sometimes referred to as tradecraft) that are typically observed during the early stage of an attack although they may be identified throughout the cyber kill chain. These behaviors include network traffic patterns, system events, and user activity.

Day 1

Categories of Attack

Category Description Malware Malware is used by hackers, cybercriminals, hacktivists, and cyber terrorists to either steal information, harm or disrupt operations, extort, and/or weaponize devices. Brute Force A brute force approach to a problem leverages those qualities of a brute (strength and power) while being bound by its limitations of resources and discovery. Digital Infrastructure The objective of a digital infrastructure attack is the disruption, manipulation, or compromise of information technology (IT) or operational technology (OT) systems. Application The objective of an application attack is either to manipulate the input, what is sent to the processor, or the output. Cryptographic A cryptographic attack is the circumvention of a cryptographic system by exploiting a weakness in a code, cipher, cryptographic protocol, key management scheme, or implementation.

Day 1

Digital Infrastructure Attack Techniques

Spoofing Poisoning is manipulating a trusted source of data (e.g., DNS)

  • Enables an

attacker to control the trusted source of data and redirect / manipulate actions. Poisoning Hijacking Denial of Service Spoofing is impersonating an address, system, or person

  • Enables an

attacker to act as the trusted source and redirect or manipulate actions. Hijacking is intercepting communication between two or more systems

  • Enables an

attacker to eavesdrop, capture, manipulate, and/or reuse data packets. Web hijacking is misdirection to a fraudulent website for malicious purposes.

  • Examples

include domain hijacking, URL squatting, and typo squatting Denial of Service is overwhelming system resources

  • Enables an

attacker to make services unavailable for their intended use. Web Hijacking

Day 1

2.5 Explain the purpose of mitigation techniques used to

secure the enterprise.

Day 1

Secure Design Engineering

Category Principle Planning Threat modeling, Keep it simple, Default deny posture, Fail-secure, Open design Configuration Secure the weakest link, Defense-in-depth, Least functionality, Appropriate disclosure, Sanitization Relationship Zero trust, Trust but verify, Separation of duties, Least privilege, Psychological acceptance The goal of secure design engineering is to develop trustworthy and survivable systems.

Day 1

Secure Design Planning Principles

Principle Description Threat Modeling Use threat modeling to anticipate threats. Focus on undesirable consequences. Keep it Simple Security mechanisms should be as simple as possible. Simplicity means fewer possibilities exist for error, and the assessment process is less complex. Default Deny Posture Base access decisions on permission rather than exclusion. This means that, by default, access is denied, and the protection scheme identifies conditions under which access is permitted. Fail-Secure In the event of failure, access is denied. Open Design The security mechanism should not depend upon the secrecy of the design or implementation. Argument against “security through obscurity”.

Day 1

Secure Design Configuration Principles

Principle Description Secure the Weakest Link Identify and strengthen weak links until an acceptable level of risk is achieved. Defense-in-Depth Utilize multiple layers of diverse controls including endpoint protection such as host-based firewall. Least Functionality Systems and devices should be configured to provide only essential capabilities, and specifically prohibit or restrict the use of unnecessary functions, ports, protocols, and services. Appropriate Disclosure Error and system messages should not include unnecessary information that may lead to a compromise of security. Sanitize Data Sent to Other Systems Sanitize all data passed to complex subsystems such as command shells, relational databases, and commercial off-the-shelf (COTS) components.

Day 1

Secure Design Relationship Principles

Principle Description Zero Trust No default trust or privilege. Verification (authentication) is required for access. Trust but Verify Dependencies are not trusted until proven trustworthy. Separation of Duties Breaking a task into segments so that no one subject is in complete control or has complete decision-making power. Least Privilege Giving a subject or process only the rights and permissions needed to complete assigned tasks. Psychological Acceptance Human interface should be designed for ease of use, so that users routinely and automatically apply the protection mechanisms correctly.

Day 1

Segmentation

  • Security zones are divisions of the network based on functional, performance,

and/or security requirements.

  • Security zones are enforced by firewall ingress and egress access control lists

(ACL) - rules. Segmenting an enterprise into security zones is useful for creating and enforcing security policies, controlling information flow, and securing network access.

Day 1

Security Zones

An untrusted network is one which the organization has no control over. Screened Untrusted Subnet Trusted Enclave A screened subnet has connections to both trusted and untrusted networks. A trusted network is one which the organization has complete control over. An enclave is a restricted network within a trusted network. Micro-segment Protect Surface Air Gapped Physically Isolated An air gapped network does not connect to any untrusted network. A physically isolated network does not connect to any other network. Micro-segment is a zone within a data centers to isolate workloads and secure them individually. The protect surface is made up of the network’s most critical and valuable data, assets, applications, and services (DAAS).

Day 1

Isolation

Virtualization technology creates multiple environments from a single physical hardware system

  • Virtual machines (VMs) provide fault and security isolation at the

hardware level including memory and CPU access. A virtual local area network (VLAN) divides a single existing network into multiple logical network segments which can be restricted.

  • Broadcast domains are portioned and isolated at the data link

layer. Virtualization Logical Isolation is when zones, devices, sessions, or even components need to be segregated, so as not to cause harm or to be harmed.

Day 1

Assessment Question 1

This adversary’s primary motivation is to make a political or social statement. A. Insider B. Hacktivist C. Competitor D. Nation-State

Day 1

Assessment Question 2

Which statement best describes an attack surface. A. An attack surface is a danger. B. An attack surface is a scenario that can be exploited. C. An attack surface is the sum of all threat vectors. D. An attack surface is the path of least resistance.

Day 1

Assessment Question 3

This technique now being used in social engineering campaigns involves generating, manipulating and/or altering data. A. Impersonation B. Gaslighting C. Pretexting D. Synthetic content

Day 1

Assessment Question 4

The objective of this type of digital infrastructure attack is to manipulate a trusted source of data such as a routing table. A. Spoofing B. Pretexting C. Hijacking D. Poisoning

Day 1

Assessment Question 5

Basing access decision on permissions rather than exclusion exemplifies this approach. A. Fail-secure B. Default deny C. Least functionality D. Trust but verify

Day 1

Domain 3

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 1

Domain 3.0 Security Architecture

# Objective 3.1 Compare and contrast security implications of different architecture models. 3.2 Given a scenario, apply security principles to secure enterprise architecture. 3.3 Compare and contrast concepts and strategies to protect data. 3.4 Explain the importance of resilience and recovery in security architecture.

Day 1

3.1 Compare and contrast security implications of different

architecture models.

Day 1

Computing Architecture

  • Examples of computing architecture include centralized, decentralized

client/server, industrial control systems, cloud, virtualization, embedded systems, and Internet of Things (IoT). A computing architecture model is a conceptual framework used to describe the design and organization of a network. It provides a high-level view of the components, interfaces, and relationships between different parts of the system.

Day 1

Architecture Primer

Design Description Centralized A processing and data storage are managed and controlled by the central server or mainframe rather than on individual devices. Client-Serer Decentralized computing model in which a client device communicates with a server to request services or data. Industrial Control System Networked devices and software used to monitor and control industrial processes, such as manufacturing, power generation, and water treatment. Cloud Delivery of computing services over the Internet (“the cloud”) that scale to business needs. Virtualized Environment Technology that creates multiple environments from a single, physical hardware system. Embedded Systems A device that contains a microprocessor and software designed to perform a specific task. IoT / IIot A network of physical objects or "things“.

Day 1

Industrial Control Systems

  • Components include hardware devices such as sensors, actuators, and controllers

and customized software applications.

  • ICS (Industrial Control System) architecture can be either centralized or

decentralized depending on the specific design and implementation.

  • Supervisory Control and Data Acquisition (SCADA) is a specialized ICS system that is

designed specifically for monitoring and controlling large-scale industrial processes. Industrial Control Systems (ICS) are networked devices and software used to monitor and control industrial processes, such as manufacturing, power generation, and water treatment.

Day 1

Cloud Computing

  • Cloud characteristics
  • Service models (SaaS, PaaS, and IaaS)
  • Deployment models (private cloud, community cloud,

and public cloud, hybrid cloud)

  • Shared Responsibility Model

Cloud computing is the delivery of computing services—including servers, storage, databases, networking, software, analytics, and intelligence—over the Internet (“the cloud”) that scale to business needs.

Day 1

Defining Cloud Characteristics

Characteristics Description Resource Pooling The provider’s computing resources are pooled to serve multiple consumers using a multi-tenant model, with different physical and virtual resources.

  • Location independence
  • Location abstraction (country, state, data center)

Demand-generated Resource Allocation Ability to a adapt to changing workload demand by auto provisioning and deprovisioning pooled resources to match current demand. Measured Service Metering capability.

Day 1

Cloud Infrastructure

  • The physical layer (e.g., processors, memory, connectivity, and storage) is used

to build the cloud’s resource pools.

  • The virtual/abstracted infrastructure.
  • All clouds utilize some form of virtual networking to abstract the physical

network and create a network resource pool.

  • Typically, the cloud user provisions desired networking resources from this

pool, which can then be configured within the limits of the virtualization technique used. Cloud infrastructure is comprised of two layers – physical and virtual (abstracted).

Day 1

Demand-generated Resource Allocation

Scalability is the ability of the system to automatically accommodate larger loads by adding resources – either making hardware stronger (scale up) or adding additional nodes (scale out). Elasticity is the ability to fit the resources needed to cope with loads dynamically. When the load increases, more resources are added and when demand decreases, resources are removed. Demand-generated resource allocation is the automatic provisioning and deprovisioning of resources. Scalability Elasticity

Day 1

Cloud Service Models

Model Provision Software-as-aServices (SaaS)Computing Resources + Operating System + Application

  • The customer uses the provider’s applications running on the

provider infrastructure. Platform-as-a-Service (PaaS) Computing Resources + Operating System + (optionally, database)

  • The customer deploys onto the provider infrastructure created or

acquired applications. Infrastructure-as-aService (IaaS)Computing Resources (“bare metal”)

  • The customer provisions processing, storage, networks, and

other fundamental computing resources from the provider. Anything-as-aService (XaaS)Anything-as-a-service (XaaS) represents the growing type of services available over the Internet via cloud computing opposed to being provided locally, or on premises.

Day 1

Cloud Deployment Models

Model Description Considerations Public cloud Provisioned for public use. Location Multitenancy Community cloud Provisioned for the exclusive use by a welldefined group. Multitenancy Private cloud Provisioned for the exclusive use of a single organization. Scalability Hybrid cloud Hybrid cloud describes a mixed use of onpremise, private cloud and public cloud platforms with orchestration among the providers.

  • Cloud bursting is the on-demand and

temporary use of the public cloud when demand exceeds resources available in the private cloud or on-premise infrastructure. Security of the connection

Day 1

Cloud Security Options

Option Description CASB Cloud Access Security Brokers (CASBs) are security policy points (software or appliance) placed between “the cloud” and enterprise users.

  • CASBs proxy traffic and use auto discovery to identify cloud applications.

Security policies are interjected as cloud-based resources are accessed. For example, authentication, encryption, visibility, and DLP.

  • Provides control over shadow IT applications. Shadow IT is used to describe the

use of IT solutions that are managed outside of and without the knowledge of the IT department. Secaas Security-as-a-Service (SecaaS) is the delivery of managed security services for public, private, and hybrid cloud environments.

  • SecaaS relieves the burden of relying on the SaaS, PaaS, or IaaS vendor for

security protection and enforcement.

Day 1

Shared Responsibility Matrix

Component SaaS PaaS IaaS Infrastructure Security CSP CSP CSP Platform Security CSP CSP User Application Security inc. APIs CSP User User Data Security User User User User Security User User User Legend:

  • CSP refers to the cloud service provider.
  • User refers to the provisioner of the service.
Day 1

Embedded Systems

  • An embedded system can either be fixed or programmable.
  • Embedded system applications range from digital watches and microwaves

to hybrid vehicles and avionics.

  • It is estimated that 98% of all microprocessors manufactured are used

in embedded systems.

  • Commercial uses of embedded systems include medical devices,

biomedical monitoring, vehicle systems (e.g. adaptive cruise control, emission control systems, collision sensors, ABS), aircraft controls systems and sensors, and smart meters An embedded system is an electronic product that contains a microprocessor and software designed to perform a specific task.

Day 1

Closed Loop

1. System on a chip (SoC) which is microprocessor or microcontroller with advanced peripherals such as Wi-Fi. 2. Real-time Operating System (RTOS) that defines the way the system works. 3. Application software specific to the device. An embedded system generally has three closed loop components.

Day 1

The Internet of Things (IoT)

The Internet of Things (IoT) refers to a network of physical objects or "things" embedded with sensors, software, and connectivity that enable them to exchange data with other connected devices and interact with users over the Internet (smart devices). Industrial Internet of Things (IIoT) refers to the application of IoT technology and principles in industrial settings to improve efficiency, productivity, and safety. It refers to the use of connected sensors, devices, and machines in manufacturing, logistics, and other industrial settings to collect, analyze, and share data in real-time.

Day 1

Edge Computing

Edge computing is the deployment of data-handling activities and operations at or close to the source without having to go through centralized network segments.

  • Depending on the device or equipment being considered, the network edge

can refer to the area where the device communicates with the Internet.

  • For IIoT devices, such as a smart camera, the network edge will be the

processor within the camera.

  • Smart edge devices are devices equipped with features for capturing data

and processing.

Day 1

Virtualization

Virtualization is technology that creates multiple environments from a single, physical hardware system.

Day 1

Virtualization Benefits

Virtualization enables the efficient use of hardware resources by allowing multiple virtual systems to run on a single physical system, which can improve resource utilization and reduce costs. Virtualization provides flexibility and scalability by allowing virtual systems to be easily created, deployed, and managed, without needing to invest in additional physical hardware. Each virtual instance (server, desktop, storage, network) behaves as if it were a physically separate system but is running on a shared physical host. Resource Utilization Flexibility

Day 1

3.2 Given a scenario, apply security principles to secure

enterprise architecture.

Day 1

Network Devices

  • An appliance is a self-contained resource that provides a specific function.
  • A sensor is a device that collects information about the network or host. A

sensor can report and/or act.

  • A collector is a device that performs targeted collection which feeds into an

aggregation or correlation engine. A network device is a piece of hardware or software that is used to enable and manage data communication and report on and/or enforce rules.

Day 1

Decision States

State Description True Positive Positive activity is correctly identified. False Positive Positive activity is incorrectly identified as negative. True Negative Negative activity is correctly identified. False Negative Negative activity is incorrectly identified as positive.

  • Positive state refers to normal or expected (what you’re looking for) activity.
  • Negative state refers to abnormal or unexpected activity.
Day 1

Device Failure Modes

Fail-Open Fail-closed mode means that the network device blocks network traffic even if the device fails. This setting is intended to ensure network security by preventing unauthorized access to network resources in the event of a hardware or software failure. Also referred to as Fail-Secure. Fail-Closed Fail-open mode means that the network device allows network traffic to continue to flow even if the device fails. This setting is intended to prevent disruptions to network connectivity and to minimize the impact of hardware or software failures on network operations. Also referred to as Fail-Safe.

Day 1

Common Network Devices

Device Description Firewall Isolates network segments and controls ingress and egress traffic. IDS/IPS Intrusion Detection System (IDS) can analyze and monitor network traffic. Intrusion Prevention System (IPS) can analyze, monitor, and proactively deny network traffic. Jump Server A jump server, is a hardened computer system or server that provides secure access to other computers or systems within a network. Proxy Server A proxy server is an intermediary machine, between a client and a server, which is used to filter or fetch and cache requests made by the client. NAC Evaluate endpoints for network access using pre- and post admission policies. DLP Detects data movement and prevents data exfiltration.

Day 1

Firewall

The primary objective of a traditional firewall is to isolate network segments and traffic by controlling ingress and egress access.

  • Firewalls are a deterrent control because a hardened appearance can discourage

opportunistic attackers.

  • Firewalls are a preventive control because they can be configured to restrict

ingress and egress network traffic, repel known attacks, manage nonroutable IP addresses, and anonymize internal addresses.

  • Firewalls can be a detective control because they can be configured to log events

and to send alerts.

Day 1

Firewall Devices

Type Description Packet-Filtering (OSI Layer 3) Packet-filtering (stateless) firewalls inspect each packet individually and decides whether a packet is allowed or denied based on the header information. Stateful (OSI Layer 4) Stateful firewalls inspect headers and packet payload and keeps track of the state of the entire connection from start to end. Stateful firewalls filter packets based on the full context of a given network connection. Web-Application (OSI Layer 7) A WAF inspects, protect web applications from malicious attacks such as XSS and SQL injection, It works by analyzing incoming HTTP traffic to a web app and filtering out any malicious traffic before it reaches the application. NextGeneration (OSI Layer 7) Next-gen firewalls inspect the entire transaction; does surface-level and deep packet inspection; and incorporates additional security features and application controls. Virtual FW (OSI Layer 7) Virtual firewalls are designed to protect virtualized environments such as cloud infrastructure and virtual machines.

Day 1

IDS/IPS

Both IDS & IPS monitor for & analyze suspicious traffic action IPS is a control system and can deny access IPS/IDS can be network-based (NIDS/NIPS) or host-based (HIDS/HIPS). IDS is a monitoring tool and cannot take selfdirected action

Day 1

IDS Detection Engines

Engines Description Signature-based Pattern-matching decisions are based on established known signatures.

  • Signatures must be updated frequently.

Rule-based Analyzes behavior for violation of preconfigured rules. Behavior-based Behavior-based anomaly decisions rely on predicted norms and deviations.

  • Can be learned over time and/or start with a set of assumptions and

adapt to local conditions.

  • Requires fine tuning.

Heuristic Continually trains on network behavior and can continually alter detection capabilities based on learned knowledge.

Day 1

Secure Communications

  • The objective of secure communications is confidentiality, integrity,

authentication, non-repudiation, or any combination thereof.

  • Transport Layer Security (TLS), and Internet Protocol Security (IPsec) are widely

used to secure online transactions, email communication, and other sensitive data transmissions. A secure protocol is a set of rules and procedures designed to ensure secure communication between two or more parties over a network or the internet.

Day 1

Secure Socket Layer (443)

Developed in 1995 by Netscape, Secure Sockets Layer (SSL) is used to establish a secure communication channel by negotiation using a stream cipher.

  • In 2015, SSL 3.0 was deprecated by the Internet Engineering Task Force (IETF) due to

numerous security vulnerabilities discovered over the years. New vulnerabilities continue to be discovered. Most browsers no longer support SSL.

  • SSL2.0 and 3.0 should be disabled. When enabled they make a system vulnerable to a

downgrade attack. Connection Request Secure Connection Needed Security Capabilities Encrypted Session Established

Day 1

Transport Layer Security (443)

Transport Layer Security (TLS) is used to establish a secure communication channel between two TCP sessions using a cryptographic key exchange.

  • TLS is the successor and recommended replacement for SSL. TLS uses a block

encryption cipher and includes advanced security features and improved algorithms.

  • The current version is TLS 1.3 should be used (or higher, as released). IETF has

officially declared both TLS 1.0 and TLS 1.1 deprecated (weak and vulnerable) and should not be used. Connection Request Session Establishment Confirmation Cryptographic Key Exchange & Encrypted Session Established

Day 1

IP Security (IPsec)

  • Introduced in the mid-1990’s, IPsec was initially designed to secure host-to-host

communication.

  • IPsec operates at the Network layer (L3) and can be used to encrypt data being

sent between any systems that can be identified by an IP address.

  • IPsec can be implemented in two modes – tunnel (default) and transport.
  • IPsec is now the de facto standard for IP-based VPNs.

IPsec (Internet Protocol Security) is a protocol suite used to secure Internet Protocol (IP) communications by providing authentication, integrity, and confidentiality services.

Day 1

IPsec Modes

  • The entire original IP packet is encapsulated to become the

payload of a new IP packet.

  • A new IP header is added on top of the original IP packet.
  • The payload is encrypted but not the IP header.
  • Transport mode has less overhead.

Tunnel Mode (Default) Transport Mode

Day 1

Virtual Private Network

  • VPNs are a cost-effective alternative to dedicated point-to-point connections.
  • VPNs isolate the network frames from the surrounding networking using a

process known as encapsulation or tunneling.

  • Full tunneling requires all traffic to be routed over the VPN.
  • Split tunneling allows the routing of some traffic over the VPN while letting

other traffic directly access the Internet. A virtual private network (VPN) is designed to facilitate secure remote access communication over a public network.

Day 1

VPN Protocols

  • IPsec VPNs are widely used for site-to-site VPNs and remote access

VPNs.

  • Because IPsec operates at OSI layer 3, IPsec VPNs can support all IP

based applications.

  • TLS VPNs are commonly used for remote access VPN

configurations.

  • Because TLS operates at OSI layer 7, TLS VPNs generally only

support browser-based applications. The two most used protocols for virtual private networks (VPN) are IPsec and TLS. IPsec TLS

Day 1

3.3 Compare and contrast concepts and strategies to protect

data

Day 1

Categories of Data

Category Description Regulated Regulated data is protected by law, or industry standards. Personally Identifiable Personally Identifiable refers to data that can be used to identify a specific individual (PI. PII). Intellectual Property Intellectual property refers to intangible creations. Contractually Protected Contractually protected data refers to data that is specified in a contract or agreement. Organizationally Classified Organizationally classified data refers to data meets classification criteria.

Day 1

Regulated Data

  • Jurisdiction is the power or right of a legal or political agency to exercise its

authority over a person, subject matter, or territory.

  • In relation to information security, jurisdiction pertains to the location of data

and systems (processing, transmission, storage), the type of data, the residence of data owners, and the residence of data subjects.

  • GLBA (financial), HIPAA (medical), and FERPA (educational) regulations

related to data types.

  • GDPR and CCPA relates to data type (PII) and residence of data subjects.

Regulated data refers to data that is subject to specific laws, regulations, or industry standards that govern its collection, use, storage, and disclosure.

Day 1

Intellectual Property (IP) Law

  • The goal of IP law is to encourage innovation and creativity by granting exclusive

rights to creators and owners of IP, while at the same time balancing the interests of the public.

  • While there are international agreements and treaties that provide some

standardization in IP protection there are significant differences in how IP is protected and enforced across different jurisdictions. Intellectual property (IP) law is a branch of law that deals with the protection of intangible creations.

Day 1

Intellectual Property (IP) Protections

Patent A trademark is intended to protect recognizable names, icons, shape, color, and sounds, used to represent a brand, product, service, or company. ® TM SM Trademark © Copyright Trade Secret A patent gives its owner the legal right to exclude others from making, using, or selling an invention for a period of time, in exchange for publishing a public disclosure of the invention. Copyright protections are intended to allow the creator of certain types of original works to benefit from being credited and compensated for their work. Trade secrets refer to proprietary business and technical information, processes, designs, or practices that are confidential and critical to a business.

Day 1

Software End-user Licensing Agreements (EULA)

Freeware Shareware is copyrighted software that is available at no cost for unlimited usage. Users are encouraged to share the software to promote larger distribution and sales. Shareware Open Source Commercial of the Shelf (COTS) Freeware is copyrighted software that is available at no cost for unlimited usage. The developer retains all rights to the program and controls distribution. Open source is when the copyright holder grants users the rights to use, study, change, and distribute the software to anyone and for any purpose. COTS is copyrighted software that a company designs and develops to sell or license. The company retains all rights to the program and controls distribution.

Day 1

Classification

  • Sensitivity is based on the impact of asset exposure.
  • Criticality is based on the impact of asset loss. This criteria is often used for

disaster recovery and business continuity planning.

  • Asset classifications inform risk management decisions, protection strategies,

control decisions, audit scope, and regulatory compliance activities. Classification is the process of organizing assets by criticality and sensitivity.

Day 1

Security Clearance

  • Clearance levels mirror data classifications.
  • Clearance is valid for a specific amount of time and then must be renewed.
  • Clearance officers are responsible for the clearance process.

A security clearance is a determination made by the government that an individual is eligible to access classified information up to a certain level of classification.

Day 1

Labeling

  • Labels can take many forms: electronic, print, audio, or

visual.

  • Labels should be appropriate for the intended audience.
  • Labels transcend institutional knowledge and provide

stability and continuity. Labeling is the vehicle for communicating the assigned classification to custodians, users, and applications.

Day 1

Handling Standards

  • Handling standards dictate by classification level how information must be

stored, transmitted, communicated, accessed, retained, and destroyed.

  • Handling standards extend to automated tools such as DLP (data loss

prevention) solutions.

  • Handling standards may extend to incident management and breach

notification. Handling standards inform custodians and users how to protect the information they use and systems they interact with.

Day 1

Data Management

  • Data protection decisions are generally related to:
  • Data classification
  • Data state (point in time)
  • Data at rest (persistent storage — e.g., disk,

tape)

  • Data in use (CPU processing or in RAM)
  • Data in transit (transmission)

Data management is the planning and execution of policies and practices that protect data confidentiality, integrity, and availability throughout its lifecycle.

Day 1

Roles & Responsibilities

Directors & Executive Management Owners are responsible for oversight and decisions related to classification, access control, and protection. Data Owners Data Custodians Data Users Responsible for governance and oversight. From a legal and regulatory perspective, they are ultimately responsible for the actions (or inaction) of the organization. Custodians are responsible for advising, implementing, managing, and monitoring data protection controls. Users are responsible for treating data and interacting with information systems in accordance with organizational policy and handling standards.

Day 1

3.4 Explain the importance of resilience and recovery in

security architecture.

Day 1

Backup and Recovery

Traditional Online Replication Automation Backup and recovery processes ensure that accurate and reliable copies of data and system configurations are created, maintained, and tested. Traditional backup and recovery generally uses removable media or local disk library. Online backup and recovery preserve data by creating copies of it and storing them in an online or cloud-based environment. Replication is the process of creating and maintaining multiple copies of data across different locations. Automation an approach to automated provisioning and replacement.

Day 1

Traditional Backup Strategies

Type Backup Process Restore Process Full Backup Backs up all files Full backup media Differential Backs up all files created or modified since last full backup

  • Does not reset archive bit

Full backup + most recent differential Incremental Backs up all changed files

  • Does reset archive bit

Full backup + all subsequent incremental Media Options: Disk-Tape, Disk-Disk, Disk-Disk-Tape, Disk-Disk-Cloud

Day 1

Online Backup Strategies

Strategy Description Cloud Backup Services Scheduled backup to an Internet location. Disk Shadowing Data is written to (and read from) two or more independent disks Process is transparent to the user. Electronic Vaulting Files copied as they change and periodically transmitted to a backup location. Remote Journaling Transaction logs copied and periodically transmitted to a backup location.

Day 1

Replication Strategies

Type Process Replication is an automated process that streams copies of data to one or more locations in real time or near-time. Point-in-Time • Periodic snapshots replicated

  • If replicated, snapshots are pointer-based, just changes

transmitted Asynchronous Replication

  • Write is considered complete as soon as local storage commits
  • Remote storage updated with a slight time lag

Synchronous Replication

  • Data written in two locations (local and remote)
  • Both write operations must successfully complete before the

system can proceed

  • Guaranteed zero data loss
Day 1

Cost vs. Complexity vs. Availability

Traditional Recovery

  • Tape backup
  • Low complexity
  • Low cost
  • Recovery

measured in hours to days Enhanced Recovery

  • Automated

solutions

  • Medium

complexity

  • Low cost
  • Recovery

measured in hours to days

  • More recoverable

data Rapid Recovery

  • Asynchronous

replication

  • High complexity
  • Moderate cost
  • Recovery measured

in minutes to hours Continuous Availability

  • Synchronous

replication or automation

  • High complexity
  • High cost
  • Recovery measured

in seconds

Day 1

Resiliency

  • Availability is a measure of a system's uptime — the percentage of time that a system

is operational.

  • For example, “Five-Nines” means the device/environment/process should be

available 99.999% of the time and experience no more than 5.26 minutes of downtime per year.

  • Availability measures are used to inform architecture and investment

requirements. Resiliency is the capability to continue operating even when there has been a disruption or abnormal operating conditions.

Day 1

Resiliency Concepts

Device Description System Resiliency

  • Fault Tolerance
  • High Availability
  • Fault tolerance is the capability of a system to continue to

operate in the event of failure of one or more system components (redundancy)

  • High availability is automatic failover for continued

operation Power Resiliency Alternate sources of power Site Resiliency Alternate processing locations and facilities Supplier Resiliency Multiple diverse supply chain options

Day 1

System Resiliency

State Description Failover Transition to a standby device. High availability Automatic failover. Active / Passive Pair The passive device does not come online unless the primary device fails. Active / Active Pair Two or more components are operational and work as a team In case of a failure, remaining components continue to operate. RAID Disk technology that combines multiple disk drive components into a logical unit for the purposes of data redundancy, performance improvement or both. Fail-secure Principle that a failure will result in a secure or trustworthy state.

Day 1

Power Resiliency

Option Description Redundant Power Supply A redundant power supply is when a single piece of computer equipment operates using two or more physical power supplies. UPS An uninterruptible power supply (UPS) provides backup power when a regular power source fails, or voltage drops to an unacceptable level; a UPS provides filtering and surge protection. Generator A generator is a standby, secondary, limited source of electrical power when the power grid is down or inaccessible Supplier Diversity More than one supplier and/or access to multiple power grids.

Day 1

Site Resiliency

Site Description Cold Site A cold site has basic HVAC infrastructure.

  • No server-related or communications equipment

Warm Site A warm site has HVAC, servers, and communications infrastructure and equipment.

  • Systems might need to be configured
  • Data needs to be restored

Hot Site A hot site has HVAC, servers, and communications infrastructure and equipment

  • Systems are preconfigured
  • Data is generally near-time

Mobile Site A mobile site is a transportable modular unit with pre-ordered hardware and software.

  • The delivery site must provide access roads, water, waste disposal, power, and

connectivity Reciprocal Site A reciprocal site is based on an agreement to have access to/use of another organization’s facilities

Day 1

Continuity of Operations

  • In a business context, disasters are disruptive events that significantly impact

an organizations capability to operate.

  • Adverse conditions can be geological, meteorological, environmental,

public health, loss of service, technical, and/or human-related.

  • The impact could be to people, technology, facilities or any combination

thereof. In its simplest form, continuity of operations is the capability of a business to continue to operate in adverse (disaster) conditions.

Day 1

Continuity of Operations Planning

DRPs focus on the recovery and restoration of technology, physical plant, and personnel. BCPs focuses on the overall strategy for sustaining business activities during a disaster (or smaller interruption) and subsequent recovery period. The objective of continuity of operations planning is to prepare for continued operation. Disaster Recovery Plans (DRP) Business Continuity Plans (BCP)

Day 1

Continuity of Operations Planning Workflow

Project Initiation Business Impact Analysis Strategy / Plan Development & Approval Procedure Development Training Testing Auditing Maintenance & Review

Day 1

Assessment Question 1

In a SaaS model, this security component is the responsibility of the cloud service provider. A. Infrastructure security B. Platform security C. Application security D. All the above

Day 1

Assessment Question 2

The most dangerous of the decision states. A. True positive B. False positive C. True negative D. False negative

Day 1

Assessment Question 3

Type of firewall that operates at OSI Layer 4 and filters packets based on the full context of a given network connection. A. Stateful B. Stateless C. Next-Generation D. Virtual

Day 1

Assessment Question 3

Category of data often referred to as intangible creations. A. Regulated B. Intellectual property C. Classified D. Personally identifiable

Day 1

Assessment Question 3

Term used to describe a disk-disk backup that does not reset the archive bit. A. Full backup B. Differential backup C. Incremental backup D. Synchronous backup

Day 1

Study Strategies

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 1

Study Strategies

Commit Create a study plan that works for you. Put it in your calendar and tape it on your refrigerator! Take breaks whenever you feel overwhelmed. Plan Learn Talk to Yourself, Out Loud Schedule your exam! Let everyone know – your boss, your colleagues, your family. Give them the opportunity to support you. Watch my video – The Complete CompTIA Security + SY0- 701 Certification Video on O’Reilly Media! . Make your own flash cards using 3x5” or 4x6” index cards Use this technique to validate that you know a subject. Stand up and out loud teach it. Create Flash Cards

Day 1

Relax. Breath Deeply. Enjoy.

Day 1

Adopt the Zen of Studying

  • Approach the material with a positive, can-do attitude.
  • Don’t think of preparing for the exam as chore – envision it is an

opportunity to learn and enhance your career.

  • Be proud of yourself.
  • Be kind to yourself. Strive for progress, not perfection.

Remind yourself you can do this.

Day 1

Tomorrow – Day 2 SY0-701 Crash Course

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies Day 1 feedback - I encourage you to send me an email sari@sarigreenegroup.com. Until tomorrow ….. Have a great day/evening.

Day 2

Welcome to Day 2

CompTIA SY0-701 Security+ Crash Course Sari Greene, CISSP, ISSMP, CRISC, CISM, CISA, SEC+ sari@sarigreenegroup.com

Day 2

Welcome to Day 2 – How are You feeling?

o Yikes, I’m overwhelmed! o I’m tentative but okay. Just need a bit more confidence. o I’m feeling pretty good & I have a study plan. o I’m ready to ace this exam.

Day 2

Exam Commitment

o Yes, I scheduled my exam. o No, I didn’t but I plan too soon (I promise).

Day 2

Certification Exam Outline

This course is based on the SY0-701 Certification Exam Objectives.

  • The CompTIA Security+ Certification

Exam Objectives document can be found at https://www.comptia.org/training/reso urces/exam-objectives.

  • Course slides are available in the

“Resource List” window. Please respect the copyright.

  • This course is being recorded and will

be available to you within 24-48 hours

Day 2

Comprehensive Study

My CompTIA Security+ SY0-701 27+hr. Video Course covers in detail every exam objective and includes 3 Second Challenges, Security-in-Action case studies, Word Clouds, Deep Dive Quizzes, and Closer Look Labs. Available to you on the O’Reilly Media platform! CompTIA Labs is a remote lab environment that enables hands-on practice and skill development in actual software applications. The virtual lab scenarios are aligned with CompTIA exam objectives and are based on real workplace events.

  • https://www.comptia.org/training/certmaster-labs
Day 2

Exam Objectives (Course Outline)

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 2

Domain 4 Security Operations

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 2

Domain 4.0 Security Operations

# Objective 4.1 Given a scenario, apply common security techniques to computing resources. 4.2 Explain the security implications of proper hardware, software, and data asset management. 4.3 Explain various activities associated with vulnerability management. 4.4 Explain security alerting and monitoring concepts and tools. 4.5 Given a scenario, modify enterprise capabilities to enhance security. 4.6 Given a scenario, implement and maintain identity access management. 4.7 Explain the importance of automation and orchestration related to secure operations. 4.8 Explain appropriate incident response activities. 4.9 Given a scenario, use data sources to support an investigation

Day 2

Security Operations

  • In larger organizations, this function operates independently and may have

its own physical presence known as a Security Operations Center (SOC).

  • In smaller organizations, this function may be integrated within the

Information Technology or Risk Management departments.

  • Alternately, SOC’s can be an outsourced function.

Security operations refer to the ongoing activities that an organization undertakes to ensure the security and protection of its information systems, assets, and data.

Day 2

4.1 Given a scenario, apply common security techniques to

computing resources.

  • Hardening Targets
  • Wireless Design and Security
  • Mobile Connectivity and Device Management
  • Application Security
  • Secure Coding
Day 2

Secure Baseline

  • The purpose of a secure baseline is to ensure that fundamental security

measures are in place to protect against common threats and vulnerabilities.

  • It serves as a starting point for establishing a secure environment and can be

used as a foundation to build upon. A secure baseline is a predefined set of security configurations and practices that are considered the minimum level of protection for a system or network.

Day 2

Hardening

  • The principle of least functionality is that systems and devices should be

configured to provide only essential capabilities and specifically prohibit or restrict the use of unnecessary functions, ports, protocols, and services. Hardening is the ongoing process of configuring security settings, applying security patches, and implementing least functionality in order to reduce the system footprint, minimize vulnerabilities and exposure to threats, and enhance resilience.

Day 2

Hardening Targets (examples)

Servers & Workstations Applying patches, limiting admin privileges, encrypting data Embedded Systems Restricting physical access, updating firmware, configuring security settings Switches and Routers Changing default settings, disabling unused interfaces, using secure protocols Cloud Infrastructure Configuring security groups, segmentation, encrypting data ICS and SCADA Systems Isolation, securing remote access, limiting EOL/EOS Resources include manufacturer documentation and guidelines, government publications (e.g. NIST SP 800 series), industry (e.g. Cloud Security Alliance (CSA), IoT Security Foundation (IoTSF), forums and community groups. *Wireless, mobile and application security and hardening covered separately in this lesson.

Day 2

Wi-Fi Network Configurations

Type Description IEEE Standard WPAN Wireless Personal Area Network A.K.A. Bluetooth 802.15 standard Interconnects devices within a limited range (e.g., keyboards) WLAN Wireless Local Area Network 802.11 standard WMAN Wireless Metropolitan Area Network 802.16 standard MBWA Mobile Broadband Wireless Access 802.20 standard Wi-Fi is a radio frequency contained network.

Day 2

802.11 IEEE Standards

Specification Data Rate Frequency Distance 802.11 2 Mbps 2.4 GHz 100 m 802.11b 11 Mbps 2.4 GHz 140 m 802.11a 54 Mbps 5 GHz 120 m 802.11g 54 Mbps 2.4 GHz 140 m 802.11n 150 Mbps 2.4 / 5 GHz 250 m 802.11i Security for 802.11 technologies

  • Legacy (WEP, WPA)
  • Current (WPA2, WPA3)

802.11e Quality of Service (QoS) for priority and time sensitive data

Day 2

Current 802.11i Security

Control WPA2 WPA3 Authentication Enterprise RADIUS, Certificate or Personal PSK (PPSK) Enterprise or Personal Simultaneous Authentication of Equals (SAE) Key Separate 128-bit keys Separate 256 / 384-bit keys Encryption AES Block Cipher AES Block Cipher GCMP-256 mode HMAC-SHA384 Status Current standard Vulnerable if using Wi-Fi Protected Setup (WPS) Optional certification Backward compatible (WPA2)

Day 2

Simultaneous Authentication of Equals

  • WPA3 uses the Simultaneous Authentication of Equals (SAE) to replace WPA2’s

Personal Pre-Shared Key (PPSK) exchange protocol.

  • SAE incorporates secure mutual authentication.
  • SAE employs perfect forward secrecy and is resistant to offline decryption

attacks.

  • Perfect Forward Secrecy (PFS) is a protocol property that effectively protects

past sessions against future compromises. Simultaneous Authentication of Equals (SAE) also known as Dragonfly Authentication and Encryption (DAE) is a secure password-based authentication and password-authenticated key agreement method.

Day 2

Wi-Fi Network Security Hardening

Regular Firmware Updates: Keep wireless network devices, including routers and APs, up to date with the latest firmware updates.

  • Is

MAC Address Filtering: Use MAC address filtering to allow only authorized devices to connect to the wireless network. Disable SSID Broadcast: Disable the broadcasting of the network's (SSID) to make the network less visible to unauthorized users. Enable Segmentation: Segment the wireless network into virtual LANs (VLANs). Disable Remote Management: Disable remote management capabilities on the wireless router or APs, unless necessary. Strong Authentication & Encryption: Implement the latest Wi-Fi protocols - WPA3. Default Credentials: Change the default login credentials (username and password) for wireless access points (APs), routers, and other network devices.

Day 2

Mobile Connectivity

  • A mobile device is a generic term for any legacy or emerging device that is

portable and has interactive and connectivity capability – for example, a laptop, a tablet, a smartphone, gaming console, e-reader, wearables.

  • Connectivity can be via Wi-Fi, Bluetooth, cellular, RFID, NFC, or WUSB bus.

Mobile connectivity facilitates portable (mobile) device communication.

Day 2

Mobile Connectivity

Method Description Wi-Fi Radio frequency contained network. Bluetooth Shortwave radio low power technology based on the 802.15 standard.

  • Bluetooth is subject to Bluejacking and Bluesnarfing
  • Bluejacking is injecting an unsolicited message.
  • Bluesnarfing is unauthorized device access through a Bluetooth discovery

connection. Cellular Radio frequency distributed network. 4G uses packet switching technology. 5G uses aggregated frequency bands. RFID Radio frequency identification using low power radio waves. Data is sent and received with a system consisting of RFID tags, an antenna, an RFID reader, and a transceiver NFC Short-range wireless technology that requires proximity and/or device contact.

Day 2

Mobile Device Management

  • Mobile Device Management (MDM) software is used to control deployment,

manage settings (policies), and report on activity and usage.

  • Unified Endpoint Management (UEM) extends the functionality of MDM to IoT

devices and wearables.

  • Mobile Application Management (MAM) focuses on the management of mobile

applications. Mobile Device Management encompasses deploying, securing, monitoring, integrating, and managing mobile devices in the workplace.

Day 2

Mobile Device Security Concerns

Removing software restrictions imposed by the manufacturer. Jailbreaking Rooting Sideloading Camera Access Gaining administrative or root access on an Android device. Installing applications from sources other than authorized distribution channels. Unauthorized video by malicious or unauthorized apps. Microphone Access Hotspots GPS Tagging Device Loss Reveal location, movements, and activities. Exposure of vulnerable or sensitive locations. Unauthorized access to personal data, financial accounts, and sensitive information. Unauthorized recording by malicious or unauthorized apps. Unauthorized access. Data usage and charges.

Day 2

Application Security

  • Application security categories include:
  • Secure development and coding
  • Code security testing
  • Security and privacy controls
  • Logging

Application security is the process of developing, adding, and testing security features within applications to minimize the risk of unauthorized access (confidentiality), modification (integrity), and downtime (unavailability).

Day 2

SecDevOps

  • SecDevOps emphasizes the shared responsibility of integrating security

practices throughout the development process, ensuring that security considerations are incorporated early and continuously.

  • The SecDevOps approach enables developers to learn more about what they are

developing and how it can be exploited.

  • SecDevOps proactively focuses on survivability by providing reliable software

with a reduced attack surface. SecDevOps (short for Security, Development, and Operations) promotes collaboration between development, operations, and security teams.

Day 2

Static Application Security Testing (SAST)

  • SAST can take place very early in the software development lifecycle as it does

not require a working application and can take place without code being executed.

  • SAST scans an application before the code is compiled.
  • SAST tools give developers real-time feedback as they code, helping them fix

issues before they pass the code to the next phase of development. Static application security testing (SAST), is a testing methodology that analyzes source code to find security vulnerabilities.

Day 2

Dynamic Application Security Testing (DAST)

  • DAST works by simulating automated attacks on an application, mimicking

a malicious attacker.

  • The goal is to find outcomes or results that were not expected and could

therefore be used by attackers to compromise an application.

  • DAST tools include web and API scanning, pen testing, fuzzing and

interactive application security testing.

  • Fuzz testing, or fuzzing, is an automated testing technique used to

discover coding errors and security loopholes by inputting invalid, unexpected, or semi-random data, called fuzz, and monitoring the application response. Dynamic application security testing (DAST) is a method of application security testing that examines an application while it’s running.

Day 2

Secure Coding Best Practices

Validate input before passing or processing. Keep it Simple Input Validation Output Validation Heed Security Policy Validate output before retuning. Simplicity means fewer errors and a less complex assessment process. Architect and design for security requirements. Use Effective QA Processes Sanitize Data Sent to Other Code Signing Systems Secure Cookies Trust but verify. When in doubt, sanitize. Use effective (and easy to use) quality assurance testing and evaluation processes. Require cookies to be encrypted in transit (flag with “secure” attribute). Digitally sign executables and scripts to confirm authenticity and integrity.

Day 2

4.2 Explain the security implications of proper hardware,

software, and data asset management.

  • Asset Management
  • Asset Lifecycle
  • Asset Disposal and Destruction
Day 2

Asset

  • Every asset should have an assigned owner and a custodian.
  • Owners are responsible for decisions related to classification, and access

control, as well as oversight of protection mechanisms.

  • Custodians are responsible for implementing, managing, and monitoring

controls. An asset is any data, device, or other component of value to an organization.

  • A lifecycle management plan covers all aspects of product lifecycle from

acquisition to end-date.

  • Preparation for end-date mitigates the risk of serious vulnerabilities and

downtime.

Day 2

End-date Milestones

Notification End-of-Sale is the date when the product, service, or subscription is no longer for sale. End-of-Sale End-of-Life (EOL) End-ofSupport (EOS) The notification date is when the end-of-sale, endof-life, and end of support milestones for a product, service, or subscription is communicated to the general public. End-of-Life (EOL) is the date when a product, or subscription is determined to be obsolete. Once obsolete, the product, or subscription is not sold, improved, or maintained. End-of-Support (EOS) is the last date to receive applicable service and support. After this date, updates are no longer available.

Day 2

EOL/EOS Risks

  • Adversaries will continue to identify and exploit vulnerabilities.
  • Almost every regulation requires that an organization take “reasonable steps

to protect the data and systems under its control”. Not doing so can be considered a compliance violation.

  • Exposure to litigation for not upholding the standard of “due care”.
  • Risk of downtime due to lack of support / service resolution.
  • Incompatibility with newer operating systems, applications, and hardware.

Whenever possible, software/hardware should be refreshed prior to EOL/EOS.

Day 2

Secure Data Disposal & Destruction

Technique Description Result Wiping Overwrites all addressable storage and indexing locations multiple times Clearing Degaussing Using a electromagnetic field to destroy all magnetically recorded data Purging Shredding Physically breaking media into pieces Destruction Pulverizing Reducing media to dust Destruction Pulping Chemical altering media Destruction Burning Incinerating media Destruction

Day 2

Certificate of Destruction

A Certificate of Destruction should at a minimum include:

  • Date of destruction.
  • Description of media (including serial number, if appropriate).
  • Method of destruction (burning, shredding, pulping, pulverizing).
  • Witnesses.
  • Company name, address, and contact information.

A Certificate of Destruction is issued by commercial services upon destruction of media.

Day 2

4.3 Explain various activities associated with vulnerability

management.

  • Vulnerability Identification
  • Vulnerability Management
Day 2

Vulnerabilities and Exposures

A vulnerability is a weakness in a system (hardware or software), process, or person that can be exploited. An exposure is a system or software configuration issue, or lack of a control that could contribute to a successful exploit or compromise.

  • A zero-day vulnerability refers to a vulnerability that is actively being

exploited by attackers before the vendor has had an opportunity to develop and release a patch or fix for it.

Day 2

CVE® Program

  • CVE® is a standardized identifier for a given vulnerability or exposure.
  • The CVE records are maintained in the CVE® Program catalogue.
  • The use of CVEs ensures that two or more parties can confidently refer to a CVE

identifier (ID) when discussing or sharing information about a unique vulnerability.

  • https://www.cve.org

The CVE® Program is an international, community-driven effort to catalog hardware and software vulnerabilities for public access.

Day 2

Common Vulnerability Scoring System

  • There are five ratings – none, low, medium, high, and critical.
  • Two common uses of CVSS are calculating the severity of vulnerabilities

discovered on one's systems and as a factor in prioritization of vulnerability remediation activities.

  • The National Vulnerability Database (NVD) provides CVSS scores for almost all

known vulnerabilities.

  • https://nvd.nist.gov/

The Common Vulnerability Scoring System (CVSS) is an open framework for communicating the characteristics and severity of hardware and software vulnerabilities.

Day 2

Vulnerability Scanning

  • Web application scanners look for common types of web flaws such as crosssite scripting (XSS), SQL injection, command injection, and path traversal.
  • This category of tools is frequently referred to as Dynamic Application Security

Testing (DAST) Tools.

  • FMI: https://owasp.org/www-community/Vulnerability_Scanning_Tools

Vulnerability scanning is an automated activity that relies on a database of known vulnerabilities such as CVE®/NVD -- designed to identify vulnerabilities in the target environment.

Day 2

Patch Management

  • Patch deployment can be manual, automated, or a hybrid combination.
  • Timely deployment of security patches reduces the likelihood of exploitation.
  • The time from when an exploit first becomes active to when the number of

vulnerable systems shrink to an insignificant number is known as the Window of Vulnerability (WoV). Patch management is the process of identifying, acquiring, installing, and verifying patches (updates) to remediate vulnerabilities.

Day 2

Patch Management Challenges

  • Confirmation
  • Prioritization, timing, and testing
  • Patch management approach (automated, manual, hybrid)
  • Access to unmanaged, mobile, or remote devices
  • Unintentional consequences
  • Roll-back issues

There are several challenges inherent in the patch management process. Patch management delays should be evaluated considering organizational risk tolerance and brought to management’s attention.

Day 2

4.4 Explain security alerting and monitoring concepts and

tools.

  • Logging and Analysis
  • Monitoring and Management Tools
Day 2

Audit and Event Logs

Audit and event logs are a chronological record of events and actions.

  • Critical log sources include firewalls, IDS/IPS devices, proxy servers,

authentication servers and devices, operating systems, and key applications.

  • Audit logs are both a near-time and historical detective control.
  • Routine log analysis is beneficial for monitoring access, identifying security

incidents, policy violations, fraudulent activity, and operational issues.

Day 2

Log Analysis Processes

Process Purpose Synchronization The process of synchronizing with an external time source with a time stamp protocol (e.g. NTP). Normalization The process of standardizing the log details into a consistent structure. Aggregation The process of consolidating events from disparate devices and systems. Deduplication The process of filtering out duplicate entries or excessive noise. Correlation The process of tying individual log entries together based on related information. Identification The process of identifying normal and abnormal activity.

Day 2

Log Analysis and Response Tools

SIEM Threat Intelligence Platform (TIP) is an automation tool that combines multiple threat intelligence feeds and integrates with existing SIEM solutions. TIP UEBA SOAR Security Information and Event Management (SIEM) is an automation tool for real-time data capture event correlation analysis, and reporting. User and Entity Behavior Analytics (UEBA) is an automation tool that models the behavior of humans and machines to identify normal and abnormal behavior.

Security Orchestration, Automation, and Response (SOAR) is an automation tool that responds to the alerts, triaging the data, and taking remediation steps.

Day 2

SOAR

Automation is the ability to execute a sequence of tasks without human intervention. Orchestration is the integration of disparate tools and platforms for an automated response. Automation Orchestration Security Orchestration, Automation and Response (SOAR) tools allow an organization to define incident analysis and response procedures in a digital workflow.

Day 2

Monitoring and Management Tools

SNMP NetFlow is a network protocol developed by Cisco Systems that allows the collection and analysis of network traffic data. NetFlow SCAP SNMP provides a standardized framework for collecting information about network devices and their performance. Components include SNMP agents and managers. SCAP is a collection of open standards developed by NIST that provides a standardized approach for expressing and sharing securityrelated information Learn more about the NIST SCAP Project: https://csrc.nist. gov/projects/Se curity-ContentAutomationProtocol

Day 2

SCAP Components

Common identifiers for publicly known security vulnerabilities. Common Configuration Enumeration (CCE) Common Vulnerabilities & Exposures (CVE) Common Platform Enumeration (CPE) Common identifiers for system configurations. A naming convention for identifying software applications, operating systems, and hardware devices. Common Vulnerability Scoring System (CVSS) Open Vulnerability and Assessment Language (OVAL) A framework for assessing the severity of software vulnerabilities. A standardized language for expressing vulnerability assessments and configuration checks.

Day 2

SCAP Vulnerability Management (example)

  • Is

SCAP content, such as security benchmarks and checklists, is used to assess the compliance of system configurations with industry standards and best practices. The scan results are presented in a unified format, allowing administrators to prioritize and remediate vulnerabilities based on their severity. The tools leverage SCAP's standardized vulnerability definitions (CVE) and scoring system (CVSS) to identify vulnerabilities and assign severity levels. An organization uses SCAP-compliant vulnerability scanning tools to periodically scan their network devices and systems.

Day 2

4.5 Given a scenario, modify enterprise capabilities to

enhance security.

  • Network Device Security
  • Internet Protocol (IP)
  • Secure Protocols
  • Email Security
  • Group Policy and SELinux
  • Endpoint Detection and Response (EDR) & Extended Detection and

Response (XDR)

Day 2

Network Device Security Enhancements

Enforce security policy by controlling ingress and egress traffic using rules and ACLs. Firewall IDS/IPS DLP NAC Analyze and monitor for suspicious traffic. IPS can deny traffic access. Enforce restrictions to websites based on pre-defined criteria. Detect and report on changes made to system, application, and configuration files. UEBA Web Filters File Integrity Monitoring EDR/XDR Advanced integrated platforms that monitor, report on, and respond to security threats. Automation tool that models the behavior of humans and machines to identify normal and abnormal behavior. Detect and prevent unauthorized transfer and exfiltration of data. Enforce endpoint access privileges based on preadmission and post-admission policies.

Day 2

Internet Protocol (IP)

Originally designed for basic data connectivity.

  • IP convergence is the use of the Internet Protocol as the standard transport

for transmitting all information (voice, data, music, video, TV, teleconferencing, and so on).

  • Extensibility is additional functionality or the modification of existing

functionality without significantly altering the original structure or data flow.

  • Open standard is a standard that is publicly available and can be freely

adopted and extended. Internet Protocol (IP) is a set of rules for routing and addressing packets of data – it is the language of the Internet.

Day 2

IP Versions

IPv4 IPv6 deployed in 1999 (adoption phase).

  • 128-bit address in hexadecimal format.
  • 2001:0db8:85a3:0000:0000:8a2e:0370:7334
  • 2128 addresses (340 trillion trillion trillion).
  • Integrated IPsec.
  • Stateful and stateless auto configuration

capabilities.

  • Scans less effective because of larger

address space.

  • Sniffing is more difficult because of

mandated IPsec. IPv6 Deployed in 1981, IPv4 was the first publicly used version (1-3 were experimental).

  • 32-bit address in

dotted decimal format

  • IP address scarcity
  • Limited security

options

Day 2

Traditional TCP/IP Model

Day 2

Secure Protocols

The function of a secure protocol is to ensure confidentiality, integrity, authentication, nonrepudiation, or any combination thereof.

  • Secure protocols are commonly used in network management and

communications; often replacing older insecure protocols.

Day 2

Secure Communications and Management Protocols

HTTP+TLS HTTPS (80) FTPS (989,990) Secure Shell (22) SFTP (22) FTP+TLS Secure channel between a local and remote device. Telnet replacement. Secure file transport packaged with SSH. SRTP (5601) S/MIME DNSSec (53) DNSSec is an extension to the DNS protocol that enables origin authentication, authenticated denial of existence, and data integrity. Used for securely delivering audio and video messages over IP networks. Used to send digitally signed and encrypted email messages.

Day 2

Secure Email Communications

  • Secure email communications require both server-side (SPF, DKIM, and DMARC)

and client-side configuration (TLS, S/MIME). Secure email communication refers to the use of various measures and protocols to protect the confidentiality, integrity, and authenticity of email messages exchanged between parties.

Day 2

Server-side Email Configuration

SPF DKIM (DomainKeys Identified Mail) is an email authentication method designed to verify the authenticity and integrity of email messages. DKIM DMARC SPF (Sender Policy Framework) is an email authentication method designed to prevent email spoofing and protect against forged or unauthorized use of domain names in email messages. DMARC (Domainbased Message Authentication, Reporting, and Conformance) is an email authentication protocol that helps protect against email spoofing and phishing attacks.

Day 2

Email Encryption

  • Server-to-server encryption establishes an encrypted connection to protect the

email data in transit between the sender's and recipient's servers.

  • End-to-end encryption ensures that the email message is encrypted on the

sender's device and can only be decrypted by the intended recipient. This means that not even the email service provider has access to the decrypted content.

  • Transport Layer Security (TLS) is a cryptographic protocol used to encrypt

communication between email servers during transmission.

  • Secure/Multipurpose Internet Mail Extensions (S/MIME) is a standard for secure

email messaging that provides encryption and digital signatures. The goal of email encryption is that only the intended recipient can read the email message.

Day 2

Windows Group Policy

  • A Group Policy Object (GPO) is a group of settings.
  • GPOs can be associated with single or numerous Active Directory containers,

including sites, domains, or organizational units (OUs).

  • Group Policy Management Console (GPMC) snap-in provides a single

administrative tool for managing Group Policy across the enterprise. Windows Group Policy provides centralized management and configuration of operating systems, applications, and users' settings in a Microsoft Window’s Active Directory environment.

Day 2

Security-Enhanced Linux (SELinux)

  • Created by the United States National Security Agency (NSA) and Red Hat. This

security module is available for most Linux distributions but is mainly used on RHEL and Fedora.

  • SELinux operates on the principle of least-privilege. By default, everything is

denied and then a policy is written that gives each element of the system (a process, a user, and so on) only the permissions it needs to function.

  • SELinux security policies are a set of rules that instruct SELinux who has access

to which system resource. There are two types of policies.

  • Targeted - The most common type of policy is targeted policy where only

selected processes are protected.

  • Strict - The more stringent policy where all processes are protected.

SELinux (Security-Enhanced Linux) is Linux kernel access control security module.

Day 2

EDR/XDR

EDR (Endpoint Detection and Response) and XDR (Extended Detection and Response) are solutions designed to detect and respond to security incidents.

  • EDR focuses on monitoring and responding to security threats on individual

endpoints, such as computers, servers, laptops, and other devices.

  • XDR builds upon the concept of EDR but extends its scope beyond endpoints.
  • The goal of XDR is to provide a more holistic and integrated approach to

threat detection and response by analyzing and correlating data from various security tools and platforms. This broader perspective allows security teams to detect and respond to threats that might span multiple vectors and stages of an attack.

Day 2

4.6 Given a scenario, implement and maintain identity and

access management.

  • Identity and Access Management
  • Federated Identity
  • Authentication
  • Access Control and Authorization
  • Privileged Access Management
Day 2

Identity Primer

Concept Description Identification Who you are (unique record) Identification Schema An identification schema is used to identify unique records in a set. Authentication Method An authentication method is how identification is proven to be genuine. Authorization Model An authorization model defines how access rights and permissions are granted. Identity Management The technical management of user identity including authentication and authorization.

Day 2

Identity and Access Management

  • IAM functions including provisioning, educating, auditing, and deprovisioning.
  • Provisioning is the process of creating and managing digital identities.
  • Deprovisioning is the process of removing and deleting digital identities.
  • IAM functions take place throughout the employee lifecycle.
  • IAM functions are a shared responsibility – managers, owners, HR, IT, physical

security, information security, and audit. Identity and Access Management (IAM) is a business process of enabling the right individuals to access the right resources at the right times and for the right reasons.

Day 2

Identity Management (IdM)

Technology Description Directory Services Centralized collection of subjects and objects Enterprise Single Sign-on (SSO) Authentication system that allows a subject to authenticate to multiple related, yet independent, software systems Federated Identity Management (FIM) Authentication systems that support “portable identity” among multiple enterprises Just-in-Time (JIT) Privileged Access Management Methodology to grant real-time privileged access in order to minimize standing privilege.

  • Standing privilege refers to administrator accounts with “always

on” 24x7x365 privileged access. Identity Management (IdM) describes the technical management of user identity, including authentication and authorization.

Day 2

Federated Identity Management

  • FIM includes identity provisioning, authentication, authorization, and attribute

sharing between participating systems.

  • Technologies used to implement FIM include Security Assertion Markup

Language (SAML) and OAuth 2.0. Federated Identity Management (FIM) refers to the processes and technologies involved in managing user identities, access rights, and permissions across independent federated systems (trust domains).

Day 2

SAML

SAML is an XML-based open standard for exchanging authentication and authorization data between a SP and an IdP.

  • User
  • The subject who needs to access multiple systems or services with a

single set of credentials (portable identity).

  • Identity Provider (IdP)
  • The system responsible for authenticating the user's identity.
  • Service Provider (SP)
  • The system or application that the user wants to access. It relies on the

identity provider's assertion to trust the user's identity and grant access to its resources.

Day 2

SAML Illustrated

Identity Provider (IdP) SAML-compliant authentication service Service Provider (SP) SAML-compliant web application End-user (Principal) Commonly used by businesses that offer subscription/pay services – e.g., Salesforce, Box.

Day 2

OAuth 2.0

OAuth 2.0 is an open standard protocol and framework designed to provide secure, delegated access to resources without sharing credentials.

  • Authorization Server API / Resource
  • The server that authenticated the user and issues an access token to

the resource server.

  • Client Application
  • The application or website that wants access to the protected resource.
  • Resource Owner
  • The user who owns the protected resource.
Day 2

OAuth 2.0 Illustrated

Requesting Client Application Resource Owner Resource/ Authorization Server API Commonly used by consumer apps and services.

Day 2

Authentication Controls

Factor Description Example Knowledge Something a user knows Password/Passphrase/PIN/Cognitive Challenge Question/Out-of-Wallet Challenge Question Possession Something a user has Token, Smartcard Biometric Something a user is Something a user does Physiological Behavioral Location Somewhere a user is GeoIP, Lat/Long Authentication is the process of proving an identity to an authentication system.

  • The proof is referred to as a factor.
  • The combination of a username and factor is referred to as credentials.
Day 2

Factor Requirements

Only one factor is required for authentication. Single-factor Multi-layer Multi-factor (2FA) 2-Step Verification Two or more of the same type of factor required for authentication. Two or more different types of factors are required for authentication. Two-step verification confirms a user's identity by requiring a response. An example of a second step is the user repeating back a code sent to a mobile number or email address. Passwordless refers to a method of authentication that eliminates the need for traditional passwords as the primary means of verifying user identity. Instead of relying on passwords, passwordless authentication relies on alternative methods or factors to authenticate users.

Day 2

Password Vaults (Password Managers)

  • Password vaults store passwords in a secure location accessible only to

authorized individuals or systems.

  • Passwords stored in the vault are encrypted using robust encryption

algorithms.

  • Access to the password vault is typically protected by strong authentication

such as biometric verification or two-factor authentication (2FA).

  • Password vaults often provide the capability to generate strong, complex

passwords automatically. The vault securely stores these generated passwords, eliminating the need for users to remember them. Password vaulting is a technology used to securely store and manage passwords and other sensitive credentials.

Day 2

Possession OPT & Smartcards

Smart Card

  • A smart card is a card / badge that is in the user’s possession. A smartcard has an

embedded chip and one or more certificates. One-time Password (OTP) An OTP is either generated by something you have or sent to something you have.

  • Time OPT (TOPT)
  • A hardware or software token that generates an OTP using a secret shared with the

authentication server and the current time.

  • Hash OPT (HOPT)
  • A hardware or software token that generates an OTP using a secret key and a

cryptographic hash function.

  • SMS | Voice OPT
  • A numeric or alphanumeric code is sent to a phone number either via voice or text.
Day 2

Biometrics

  • Biometric options are physiological markers (what you are) or behavioral traits

(what you do). Biometrics are physical or behavioral human characteristics that can be used to digitally identify a person.

Day 2

Biometric Advantages

  • Biometric markers and traits are unique to each individual and difficult to forge,

it provides a higher level of security and helps prevent identity theft or unauthorized access.

  • Biometric authentication is convenient for users as they don't need to

remember or carry additional credentials. Biometric authentication offers several advantages over traditional authentication methods.

Day 2

Authentication Decisioning

Decisions regarding the type and number of factors should always be commensurate with the business value of what is being protected, regulatory requirements, and contractual obligations!

Day 2

Authorization

Authorization is the process of granting subjects access to objects.

  • Subjects are active entities, generally in the form of a person, process, or

device that causes information to flow among objects, or changes the system state.

  • Objects are passive entities (resource) that contain or receive

information or instructions.

  • Authorization can be static (hard-coded) or dynamic (influenced by

situational factors).

Day 2

Access Control Models

Model Description Mandatory (MAC) Access is based on the relationship between subject clearance and need-to-know, and the object classification level. Discretionary (DAC) Data owners decide subject access. Role-based (RBAC) Access is based on the subject’s assigned roles. Rule-based Access is based on compliance with established rules. Attribute-based Access is determined by a combination of subject, object, environmental and operational attributes. Risk-based Access is determined by a combination of risk-focused behavioral and contextual data analytics.

Day 2

Attribute-based Access Control

Attribute-based access control (ABAC) is a logical access control model that controls access to objects by evaluating rules against the attributes of entities (both subject and object), operations, and the environment relevant to a request.

  • ABAC supports a complex Boolean ruleset that can evaluate many different

attributes.

  • The policies that can be implemented in an ABAC model are limited only to

the degree imposed by the computational language and the richness of the available attributes.

  • An example of an access control framework that is consistent with ABAC is

the Extensible Access Control Markup Language (XACML).

Day 2

ABAC Illustrated

Source: http://nvlpubs.nist.gov/nistpubs/specialpublications/NIST.sp.800-162.pdf

Day 2

Risk-based Access Control

Activity Description Anonymous IP Address Risk trigger indicates sign-ins from an anonymous IP address. Unfamiliar Sign-in Properties Risk trigger considers past sign-in history to identify nonfamiliar system properties. Atypical Travel Risk trigger identifies two sign-ins originating from geographically distant locations, where at least one of the locations is atypical, given past behavior. Impossible Travel Risk trigger identifies two user activities originating from geographically distant locations within a time period shorter than it would take to travel between the locations.

Day 2

Privileged Accounts

  • Standing privilege is defined as accounts that have persistent privileged access

24x7x365.

  • Privileged accounts are rich targets for cyber attacks.
  • Zero-standing privilege (ZSP) aims to minimize the standing privileges granted to

users or accounts within a system.

  • In practice, ZSP means continuous reauthentication (explicit validation), and

granting to authorized users the privileged access they need for the minimum time and only the minimum rights that they need (least privilege). A privileged account is any account that provides rights and permissions above and beyond those of non-privileged (standard) accounts.

Day 2

Privileged Access Management (PAM)

  • The primary goal of PAM is to minimize the risks associated with privileged

accounts.

  • PAM can be applied on-premises and in the cloud.
  • PAM solutions assist in meeting regulatory and compliance requirements by

providing detailed audit logs, reports, and visibility into privileged account activities. Privileged Access Management (PAM) is a set of practices, technologies, and policies designed to manage and secure privileged accounts and access to critical systems and sensitive data within an organization.

Day 2

4.6 Explain the importance of automation and orchestration

related to secure operations.

  • Scripting
  • Automation
  • Orchestration
Day 2

Scripting

  • Scripts are usually written in a scripting language, a type of programming

language designed for integrating and communicating with other programming languages.

  • Scripting languages are typically easier to learn and write than lower-level

programming languages.

  • Scripts are often interpreted opposed to compiled. This means that scripts are

read and executed line-by-line by the processor at runtime.

  • Scripting can be interactive or non-interactive.
  • Scripting tools include Python, PowerShell, Bash, and VBA
  • Scripts are often used by adversaries in attack scenarios.

A script is a set of instructions used to automate a sequence of repetitive tasks.

Day 2

Scripting Attack

Attacker hides a PowerShell script in an MS-Office macro written in VBA Victim receives a phishing email with an attached document The victim opens the document Macro executes and launches a PowerShell script The victim's system is potentially compromised.

Day 2

Automation

  • The goal of automation is to improve quality of service, increase agility, and

reduce risk.

  • Automation reduces or eliminates manual dependencies and human error.
  • Automation can be a workforce multiplier.
  • Automation techniques include scripting, robotics, specialized software, and

artificial intelligence (AI).

  • Automation often requires a significant investment. Organizations should

consider cost, complexity, and maintenance. Automation is the ability to execute a sequence of tasks without human intervention.

Day 2

Orchestration

  • Network orchestration is the automation and coordination of networking tasks

like configuration, management, and optimization of network services and devices. It is often used in SDN (Software Defined Networking).

  • Security Orchestration, Automation, and Response (SOAR) is an automation tool

that reduces response times, improves consistency, and amplifies the productivity of incident response teams.

  • SOAR response playbooks allow an organization to define incident analysis

and response procedures in an automated digital workflow. Orchestration is the integration of disparate tools and platforms (often using bi-directional APIs) for an automated response.

Day 2

SOAR Response Playbook Example

** Single click automated response: 1. Pulls in all emails received by a user at the time of their infection (e.g., from an email server). 2. Parses the emails to extract URLs and attachments. 3. Detonates the attachments in a sandbox (e.g., Cisco Threatgrid). 4. Obtains the URL reputations with a reputation service (e.g., Cisco Umbrella). 5. Geo-locates any network connections being made by the attachments in the Sandbox with a geolocation service (e.g., Maxmind). 6. Uses machine learning to determine if any of the emails are phishing emails based on the info from steps 1 to 5 above. 7. Searches a SIEM for other users that have received the same emails. Source: https://www.exabeam.com/siem/uba-ueba-siem-security-management-terms-defined-exabeam/

Day 2

4.8 Explain appropriate incident response activities.

  • Incident Management
  • Incident Response
  • Evidence Handling
  • Forensic Examination
  • Disclosure and Notification
Day 2

An incident playbook is a set of instructions for responding to a specific type of event,

attack or scenario. Generally, playbooks are developed for high-risk events (measured in terms of likelihood and impact). For example, malware, DDOS attacks, ransomware extortion and payment card compromise. Incident Management Plan and Playbook An incident management plan includes roles and responsibilities, strategies and procedures for preparing for, responding to, and managing incidents.

Day 2

Incident Management Plan Components

Component Description Threat Modeling Anticipated threats and associated controls Incident Types & Categorization Based on severity and used to determine response times, resource assignments, and preparation requirements Roles Organization role assignments inclusive of internal team and external resources Reporting & Escalation Requirements How incidents are internally reported, documented, and reviewed as well as when escalation thresholds are triggered Training & Study Requirements Training each participant of their role as well as maintaining ongoing attack-related situation awareness (attack frameworks) Exercise Requirements Exercising the plan to evaluate readiness and effectiveness.

Day 2

Incident Response Exercises

Incident response exercises should be conducted on a periodic basis to assure readiness. Participants should include the IRT team, external resources, and as applicable, executive management. Exercise Description Walkthrough Personnel or departments review (walkthrough) their plans and procedures for completeness

  • Objective: accuracy

Tabletop Scenario-based group workshop focuses on the application of plans and procedures as well as participant readiness

  • Objective: familiarity, coordination, accuracy

Simulation Localized scenario that simulates an actual event

  • Preplanned – scheduled and attendees invited
  • Surprise – attendees are notified “in the moment”
  • Objective: readiness
Day 2

Incident Response Flow Chart

Incident Detected Incident Reported Incident Assigned Validation and Prioritization Containment Eradication & RCA Recovery Lessons Learned

Day 2

Cyber Investigations

  • There are three types of investigations: criminal, civil, and internal (also referred

to as administrative).

  • In practice, it is difficult for organizations to identify the type of, and the

impact of, a cyber incident until they have carried out an investigation.

  • Evidence collection is the first step in an investigation.
  • Digital evidence is any information or data of value to an investigation that is

stored on, received by, or transmitted by an electronic device.

  • It is critical that first responders are knowledgeable about forensicallysound evidence collection and handling so that they don’t compromise the

investigation. Cyber-related investigations can be triggered by a variety of incidents (e.g., intrusion, insider activity, extortion).

Day 2

Evidence Collection

  • Evidence collection is governed by two main rules.
  • Admissibility of evidence – whether the evidence can be used in court.
  • Weight of evidence – the quality and completeness of the evidence.
  • There are two type of evidence.
  • Direct evidence supports the truth of an assertion directly.
  • Circumstantial evidence relies on an inference to connect it to a

conclusion of fact.

  • Invariably there is tension between response (find and fix) teams and

evidence collectors. Collection of digital evidence is the first step of a forensic investigation.

Day 2

Evidence Collection Rules

  • Preservation is key.
  • Do not allow the evidence to become contaminated.
  • Act in order of volatility.
  • Maintain an evidentiary chain (chain of custody) for all evidence collected

during the investigation.

  • Be aware evidence may become public record, and company confidential

information should not be included unless necessary. Assume evidence will be used in a court of law and act accordingly.

Day 2

Volatility

Order of Volatility refers to the acquisition of evidence before it disappears, is overwritten, or is no longer useful. There are two types of data - persistent data and volatile data.

  • Persistent data is data that does not change and is preserved when the device

is turned off.

  • Volatile data is data which is easily degradable and can be lost when the device

is turned off.

  • Example order of collection:

1. Dynamic data (RAM) 2. Dump files 3. Temp files 4. Log files 5. Static data (media)

Day 2

Evidentiary Chain

  • Evidentiary chain documentation demonstrates trust to the courts that the

evidence has not been subject to mishandling, or evidence spoliation. An evidentiary chain (chain of custody) is chronological documentation that records the collection, control, storage, transfer, analysis, and disposition of evidence.

Day 2

Digital Forensics

  • Forensics work is complex and should be conducted only by trained investigators

and digital forensic professionals.

  • Security operations personnel are not expected to be forensics specialists, but they

should be familiar with terminology and the basic operation as they may be expected to manage and/or participate in an investigation. Digital forensics is the application of science to the identification, collection, examination, and analysis of data (evidence) while preserving the integrity of the information.

Day 2

Digital Forensics Process

Evidence Collection Data Acquisition Examination Analysis and Reporting Testifying (if necessary) Archiving

Day 2

Retention and Archiving

  • Evidence retention parameters are required to ensure that the evidence is

available when it is needed, but they should also consider the costs involved so evidence is not retained indefinitely. Consult legal counsel.

  • At end-of-life, all evidence and findings must be securely disposed of.

Throughout the investigation and during the post-investigation retention period original data, acquired data, and all related media, documents, and ancillary items should be stored securely strict access controls.

Day 2

Jurisdiction, Disclosure and Notification

  • Disclosure is the requirement to reveal a situation.
  • Notification is the act of informing affected parties
  • The purpose of disclosure and notification is to inform others of potential risks

so they can make informed decisions and take appropriate action.

  • Jurisdictional requirements may necessitate disclosure and notification

Jurisdiction is an area of legal authority. In relation to cyber, jurisdiction pertains to the location of data and systems (processing, transmission, storage), the residence of data owners, the type of data, and the residence of data subjects.

Day 2

Data Breach Regulatory Compliance

  • In the U.S., all states and territories have enacted data breach notification

legislation (many conflict with each other).

  • U.S. federal, sector-specific, security legislation (e.g., GLBA and HIPAA) have risk

assessment and breach notification requirements.

  • The EU/EEA General Data Protection Regulation (GDPR) has very stringent breach

disclosure and notification requirements.

  • The Payment Card Industry Data Security Standard (PCI-DSS) has breach

notification requirements.

  • Contractual obligations may have notification requirements.

Organizations have an obligation to comply with regulatory and contractual requirements.

Day 2

Information Sharing

  • An Information Sharing and Analysis Center (ISAC) is a trusted, sector-specific entity

that facilitates sector-specific and/or geographic-specific information sharing about vulnerabilities, threats, and incidents.

  • The 20+ ISACs range from the Aviation ISAC to the Water ISAC.

https://www.nationalisacs.org/

  • ISACS, government agencies, and industry use STIX™ and TAXII ™ to facilitate

the exchange and sharing of threat intelligence information.

  • STIX ™ is a standardized language for describing threat Information.
  • TAXII ™ defines how STIX ™ threat information can be shared.

Information sharing describes a means of conveying information or experience from one trusted party to another.

Day 2

4.9 Given a scenario, use data sources to support an

investigation

  • Data sources
Day 2

Data Sources

  • Vulnerability scan output to identify weakness and potential attack vectors.
  • Log files for device, application, and user specific activity and/or anomalies.
  • SIEM dashboards for broad overview, trend analysis, alerts, and correlation.
  • Metadata for supporting details.
  • Packet capture for network traffic.

Incident investigation often requires analysis of several data sources in order to draw a defensible conclusion.

Day 2

Metadata

Metadata is data about data; it is machine-readable and searchable.

  • Example: The content of the photo is the data. Where the picture was taken, date,

time, direction, camera setting, editing, and copyright are metadata extracts.

Day 2

Packet Capture

  • A protocol analyzer (sniffer) is a tool used to capture and analyze network

packets (data can also be imported for analysis).

  • Packet capture modes:
  • Normal – the NIC only captures frames intended for the interface

(filtering by MAC address).

  • Promiscuous – the NIC is instructed to accept any frames it captures.
  • Filtered – packet capture limited to specific data elements.

Packet capture is the process of intercepting and logging traffic for analysis.

Day 2

Packet Capture Illustration

Source: Wireshark screen capture

Day 2

Assessment Question 4.1

This protocol is a cryptographic replacement for Telnet, includes SFTP, and uses port 22. A. Transport Layer Security B. Secure Real-time Transport Protocol C. Secure Shell D. Lightweight Directory Access Protocol

Day 2

Assessment Question 4.2

This wireless security configuration relies on Enterprise or Personal/ SAE (Simultaneous Authentication of Equals) for authentication. A. WEP B. WPA C. WPA-2 D. WPA-3

Day 2

Assessment Question 4.3

Scenario-based group workshop that focuses on the application of incident response plans as well as participant readiness A. Tabletop B. Walkthrough C. Surprise Simulation D. Planned Simulation

Day 2

Assessment Question 4.4

A FIM authentication system supports this feature among multiple enterprises . A. Portable identity B. File sharing C. Cryptographic exchange D. Complex rule-sets

Day 2

Assessment Question 4.5

The date when a product, or subscription is determined to be obsolete. A. Notification B. End-of-Sale C. End-of-Life D. End-of Support

Day 2

Assessment Question 4.6

This automation tool responds to the alerts and initiates a digital workflow. A. UEBA B. TIP C. SIEM D. SOAR

Day 2

Assessment Question 4.7

A standardized language for describing threat Information. A. STIX™ B. TAXII ™ C. SCAP D. SNMP

Day 2

Assessment Question 4.8

Logical access control model that controls access to objects by evaluating rules against the attributes of entities (both subject and object), operations, and the environment relevant to a request. A. MAC B. DAC C. RBAC D. ABAC

Day 2

Domain 5 Security Program Management & Oversight

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 2

5.1 Summarize elements of effective security governance.

Day 2

Security Leadership & Governance

  • Subsequently, they are also responsible for:
  • Providing the strategic direction, resources, funding, and support to

ensure that the desired state of security can be achieved and sustained.

  • Codify the organizations commitment in policy.
  • Risk management.
  • Oversight.
  • Governance structures and principles identify roles and responsibilities.

As applied to information/cybersecurity, governance is the responsibility of leadership to determine and articulate the organization's desired (future) state of security.

Day 2

Governance Ecosystem

BOD: Strategy, Due Care, Fiduciary, Oversight EXEC MGT: Strategic alignment, risk management, value delivery, assurance, compliance, prioritization (Steering Committee) ORG Roles: CISO/ISO, Privacy Officer, Compliance Officer, Physical Security Officer, Internal Audit Functional Roles: Owners, Custodians, Users

Day 2

Governance Strategy

  • Governance documents are derived from the information security strategy

and are used to communicate direction, expectations, and rules The governance strategy is derived from the desired (future) state. Desired or future state refers to a vision or goal that an organization aspires to achieve in the future.

Day 2

Governance Communication

Policy Standard Procedure Simple Step Hierarchical Graphic Flow Chart Guideline Agreement

Day 2

Standards, Baselines & Guidelines

Standards Baselines are the aggregate of standards for a specific category or grouping such as a platform, device type, ownership, or location. Baselines Guidelines Standards serve as precise specifications for the implementation of policy and dictate mandatory requirements.

  • Standards

must be unambiguous. Guidelines help people understand and conform to a standard. Guidelines are customized to the intended audience and are not mandatory.

  • Information

security policies codify the highlevel requirements for protecting information and information assets, and ensuring confidentiality, integrity, and availability Policies & Agreements Policies codify and communicate the high-level requirements. Agreements are used to legally enforce policies and related governance documents.

Day 2

Procedures

Simple Step Hierarchical Graphic Flowchart Procedures are instructions for how to carry out an action. Procedures focus on discrete actions or steps, with a specific starting and ending point. Simple step lists sequential actions. There is no decision making. Hierarchical organizes the instructions in a hierarchical structure, where each level is nested within the one above it. Graphic presents in pictorial or symbol form. Flowchart is used to communicate a process and/or when decision making is required.

Day 2

User Agreements

Agreement Objective Confidentiality / Non-disclosure (NDA) An NDA is a precursor to sharing information. It includes clauses designed to:

  • Protect data from unauthorized disclosure
  • Establish data ownership
  • Define handling standards including disposal
  • Post-relationship requirements

Acceptable Use Policy (AUP) and Agreement Sets forth proper use of information systems, handling standards, monitoring and privacy expectations, as well as violation consequences.

  • An AUP should be written in language that can be easily and

unequivocally understood.

  • By signing the associated agreement, the user acknowledges that they

understand and agree to the stated rules and obligations. An agreement is a legally enforceable mutual understanding between two or more parties regarding their rights and obligations.

Day 2

5.2 Explain elements of the risk management process.

Day 2

Risk

  • The outcome could be positive or negative.
  • Generally, risk is studied from the perspective of a negative outcome or

consequences.

  • Negative risk is a function of likelihood and impact.
  • Likelihood is the probability or chance of a particular risk event occurring.
  • Impact is a measure of the magnitude of harm.
  • Cascading risk is the principle that, often, risks are linked, and failing to address

one risk could cause a chain reaction. Risk is broadly defined as uncertainty of outcome.

Day 2

Risk Volatility and Velocity

  • Low-risk volatility means that the level of risk is relatively stable and predictable

over time. High-risk volatility means that the level of risk is likely to fluctuate significantly over time.

  • Risk velocity is the time that passes between the occurrence of an event and

the point at which the organization first feels its effects.

  • When the velocity is low, there is time to detect and respond.
  • If the velocity is very high, detection and response are much more

challenging. Risk volatility describes the extent to which the level of risk is likely to change over time. Risk velocity measures how fast an exposure can impact an organization.

Day 2

Risk Appetite

  • There are multiple categories of business risk including strategic, reputational,

operational, financial, compliance, legal, ESG, capital, and resilience.

  • The Board of Directors (or equivalent) determines their risk appetite on a per

category basis and publishes a risk appetite statement for use by the organization. Risk appetite is the level of risk that an organization is comfortable engaging in. For example, expansive, neutral, conservative.

Day 2

Risk Management

  • Every organization needs to take action to manage risk in alignment with their

strategic objectives, compliance and legal requirements, and risk appetite.

  • Risk tolerance is acceptable variation in outcomes related to specific

performance measures. Risk management implies that actions are being taken to either mitigate the impact of an unfavorable outcome and/or enhance the likelihood of a positive outcome.

Day 2

Risk Assessment Process

Identification Process by which the likelihood, impact and level of risk are determined. Analysis Evaluation Response Process of determining and documenting the risk scenarios the organization faces considering exposure, threats, vulnerabilities, controls, and consequences. Process of comparing the results of the risk analysis with the organizations risk appetite and risk tolerance. Process of determining a recommended course of action. Also referred to as risk treatment. A risk assessment is a structured method of understanding risk. There are four distinct processes within a risk assessment.

Day 2

Risk Analysis Approaches

Type Description Qualitative Qualitative risk assessments use descriptive terminology such as high, medium, and low or normal, elevated, and severe. Quantitative Quantitative risk assessments assign numeric and monetary values to all elements of the assessment. Key elements of both are likelihood of occurrence and impact.

Day 2

Qualitative Risk Analysis

  • The qualitative risk analysis approach is appropriate in situations where nontangible elements of risk (e.g., reputation) need to be considered and/or when

there is a lack of meaningful numeric data.

  • Results are generally presented in a risk range map.

Qualitative risk analysis uses well-defined descriptive terminology to indicate likelihood, impact, and residual risk.

Day 2

Quantitative Risk Analysis

Quantitative risk analysis assign either numeric and monetary values to all elements.

  • Quantitative risk analysis elements include:
  • Asset Value (AV) expressed in $.
  • Exposure Factor (EF) expressed as a %.
  • Single Loss Expectancy (SLE) expressed in $.
  • Annualized Rate of Occurrence (ARO) expressed as a #.
  • Annualized Loss Expectancy (ALE) expressed in $.
Day 2

Quantitative Formulas Illustrated

SLE ($) = AV ($) x EF (%) Single Loss Expectancy = Asset Value x Exposure Factor Revenue from one hour of e-commerce is $20,000 (AV) A DDoS attack could disrupt 85% (EF) of online activity $20,000 (AV) x .85 (EF) = $17,000 (SLE) ALE ($) = SLE ($) x ARO (#) Annualized Loss Expectancy = Single Loss Expectancy x Annualized Rate of Occurrence Single Loss Expectancy (for an hour of DDoS disruption) is $17,000 Based on the current threat and controls environment, it is expected that there will be 5 hours of DDoS disruption per year $17,000 (SLE) x 5 (ARO) = $85,000 (ALE) Alternate scenario: it is expected that there will be 30 minutes of DDoS disruption per year. $17,000 (SLE) x .5 (ARO) = $8,500 (ALE)

Day 2

Risk Treatment Options

Risk response is the responsibility to determine how to respond to the outcome of a risk analysis. Risk treatment is to select one or more options for addressing an identified risk. Option Description Ignore Act as if the risk doesn’t exist Avoid Eliminate the cause or terminate the associated activity Mitigate Reduce the impact or likelihood by implementing controls or safeguards Transfer Assign the risk to another party via insurance or contractual agreement (subject to legal and regulatory constraints) Accept Acknowledge and accept the level of risk, monitor, and report to stakeholders.

  • Tools include risk register, heat maps, dashboards and metrics.
Day 2

Risk Exception and Exemption

  • A risk exception is a formal acknowledgment that a risk has been identified, but it

is not feasible or practical to implement standard risk treatment or control measures. Workarounds may be implemented.

  • Exception handling is the process of approving an exception on either a

temporary or permanent basis.

  • A risk exemption is a formal decision not to address a risk at all. Generally

implemented when the potential impact of a risk is low, and the cost and effort required to mitigate the risk are disproportionate to the potential impact. It is not always possible to avoid, transfer or mitigate a risk to an acceptable level.

Day 2

Business Continuity

In its simplest form, business continuity is the capability of a business to operate in adverse conditions.

  • The objective of business continuity planning is to prepare for the continued

operation of essential functions and services during disruption of normal operating conditions.

  • To support this objective:
  • Essential services and processes are identified.
  • Threat scenarios are evaluated.
  • Response, recovery, and contingency plans are developed.
  • Strategies, plans, and procedures are tested.
Day 2

Business Impact Analysis

The objective of a Business Impact Analysis (BIA) is to identify essential services, systems, and infrastructure.

  • Essential means that the absence of or disruption of services would result in

significant, irrecoverable, or irreparable harm to the organization, employees, business partners, constituents, community, or country.

  • The outcome of BIA is a prioritized matrix of services, systems, and

infrastructure.

  • A Business Impact Analysis (BIA) is used by management to:
  • make investment decisions.
  • prioritize resources.
  • guide the development of incident response, disaster recovery, and

business contingency (continuity) plans

Day 2

Business Impact Metrics

Abbr. Metric Definition MTD MTO Maximum Tolerable Downtime Maximum Tolerable Outage Maximum time a process/service can be unavailable without causing significant harm to the business. RTO Recovery Time Objective Amount of time allocated for system recovery. RPO Recovery Point Objective Acceptable data loss ⁻ The point in time, prior to a disruption or system outage that data can be recovered. MTTR Mean Time to Repair Average time to repair a failed component or device. MTBF Mean Time Between Failures Measure of reliability (usage stated in hours).

Day 2

RPO | RTO Timeline

Recovery Point Objective Failure Recovery Time Objective Weeks Days Hours Minutes Minutes Hours Days Weeks

Day 2

5.3 Explain the processes associated with third-party risk

assessment and management

Day 2

Third-Party Risk Management

  • Third-party oversight activities include:
  • Conducting a due diligence investigation related to service provider

selection and subsequent business activities.

  • Codifying relationships.
  • Coordinating incident response protocols and contractual notification.
  • Monitoring the service provider through appropriate audits and

testing. Third-party Risk Management is a composite of activities used to research and source third parties, negotiate contracts, manage relationships, and evaluate performance.

Day 2

Information Security Due Diligence Criteria

Criteria Description Controls Ability to implement required security and privacy controls. Compliance Ability to comply with regulatory requirements. Vulnerability Mgmt. Disclosure of vulnerabilities and frequency of patch releases. EOL/EOS EOL/EOS cycle, notification, and support. Assessment Proof of independent security testing. Right to Audit Agreement to allow independent audits or provide equivalent Incident Mgmt. Detection and response capabilities as well as security breach protocols Business Continuity Ability to continue to provide services and operate in adverse conditions

Day 2

Third-Party Strategic Agreements

Agreement Type Objective Confidentiality / Non-disclosure (NDA) Protects data from unauthorized disclosure during and post-relationship Memorandum of Understanding (MOU) Non-binding document that outlines the intentions and areas of cooperation between parties Memorandum of Agreement (MOA) Legally enforceable document that establishes a contractual relationship between parties Business Partner Agreement (BPA) Comprehensive legal document that outlines the terms and conditions of a relationship between two or more businesses or entities

Day 2

Third-Party Tactical Agreements

Agreement Type Objective Service Level Agreement (SLA) Codifies service and support requirements – may include incentives and/or penalties Interconnection Security Agreement (ISA) Documents technical requirements, ownership and management of equipment and supporting infrastructure Master Services Agreement (MSA) Outlines general terms and conditions. It serves as a framework for future agreements or projects between the parties. Statement of Work (SOW) Defines tasks, deliverables, timelines, and performance expectations for a particular project or engagement between a client and a service provider. Work Order (WO) Transactional documentation used for individual service requests, often within the context of ongoing business relationships.

Day 2

5.4 Summarize elements of effective security compliance

Day 2

Compliance Monitoring

  • Compliance monitoring is used to identify areas for improvement and enables

early detection of non-compliance.

  • Monitoring activities include manual inspections, audits, data analysis,

automated systems, or specialized tools. Compliance means acting in accordance with applicable rules, laws, policies, and/or obligations. Compliance monitoring is the active process of evaluating activities, practices, and behaviors to verify compliance and identify any deviations or non-compliant actions.

Day 2

Automated Compliance Monitoring

  • Automated systems can analyze large volumes of data in real-time to identify

patterns, anomalies, or potential compliance breaches.

  • Automated systems can be programmed to generate alerts or notifications

when specific conditions or thresholds are met.

  • Automation can help maintain comprehensive audit trails and documentation

for compliance purposes.

  • Automated tools can monitor regulatory changes and updates in real-time.

Automated compliance monitoring utilizes automated tools to monitor and assess compliance.

Day 2

Defining Privacy

  • Individuals expect their privacy to be respected and their personal

information to be protected by the organizations with which they do business.

  • Data minimization approach limits data collection to only what is required to

fulfill a specific purpose.

  • Consequences of non-compliance with privacy regulations and/or privacy

breaches include reputational damage, loss of stakeholder trust, fines, and litigation. Privacy is the right of an individual to control the use of their personal information.

Day 2

Privacy Specific Regulations

GDPR The California Consumer Privacy Act (CCPA) objective is to protect California residents The CCPA draws the scope of “personal information” broadly to mean any information that “identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household.” CCPA General Data Protection Regulation (GDPR) objective is to protect people in the European Union (EU) and European Economic Area (EEA) from unlawful data collection or processing and works to increase consent requirements and to provide enhanced user rights. *Canada, Mexico, Brazil, Japan, among others all have privacy regulations modeled on the OECD privacy principles

Day 2

Privacy Statement

  • Best practices (and in some cases, legal and regulatory requirements) dictate

that whenever personal information is being collected there should be a corresponding privacy statement.

  • The statement should indicate a mechanism for opting out as well as reporting

real or perceived breach of privacy. A privacy statement describes how an organization collects, uses, shares, and protects personal information collected from individuals.

Day 2

5.5 Explain types and purposes of audits and assessments

Day 2

Information Security Assessment

  • Two approaches:
  • Examination is the process of interviewing, reviewing, inspecting, studying,

and observing to facilitate understanding, comparing to standards or baselines, or to obtain evidence (e.g., Audit).

  • The objective of an audit is to provide independent assurance based on

evidence.

  • Testing is the process of exercising objects under specified conditions to

compare actual and expected behaviors (e.g., Penetration Testing). An information security assessment is the process of determining how effectively the entity being evaluated meets specific security and/or regulatory criteria.

Day 2

Audit Framework

ISACA COBIT® 5 https://www.isaca.org/resources/cobit AICPA Statement on Standards for Attestation Engagements No. 18 (SSAE18) **Defacto technology company audit** ISACA AICPA An audit framework is a structured and systematic approach used by auditors to plan, execute, and report on an audit engagement. Audit frameworks are typically developed by auditing standards-setting bodies.

Day 2

SSAE18 SOC Versions & Types

SOC 1 Report of controls relevant to user entities financial statements

  • Agreed upon scope

SOC 2 Based upon Trust Services Principles (TSP) SOC 2, reports on controls intended to mitigate risk related to security, availability, processing integrity, confidentiality, and privacy

  • Organization chooses categories; not controls
  • Controls criteria provided by the AICPA

SOC 3 Same as SOC2 but does not detail testing performed and is designed for public distribution Type 1 Reports on controls place in operation as of a point in time

  • Evaluation of design and implementation; not operating effectiveness
  • Cover of report will show as “As of” date (e.g., June 30, 2020)

Type 2 Reports on the design, implementation and operating effectiveness over a period of time Includes tests of operating effectiveness and results

  • Cover of report will show a time period (e.g., Jan 1, 2020-Dec 31,2020)
Day 2

Penetration Testing

  • Penetration testing generally involves exploiting combinations of vulnerabilities

on one or more systems. Pivoting is the act of using weakness on one system to access a better protected system.

  • Testing can originate from within a target environment or external to the target

environment.

  • Penetration testing can be useful for determining incident detection and

response capabilities. The objective of penetration testing is to evaluate the security of a target by identifying and attempting to exploit vulnerabilities, improper configurations, and hidden points of entry (ethical hacking).

Day 2

Penetration Testing Approaches

Approach Description Unknown Environment

  • No information is provided to the testers.
  • The testers need to discover vulnerabilities, conduct reconnaissance,

identify potential entry points, and perform exploitation attempts. Partially Known Environment

  • The organization provides restricted or selective information to the

testers.

  • This approach can simulate scenarios where an attacker gains partial

information through reconnaissance or social engineering Known Environment

  • The testers have comprehensive knowledge about the target system

or network.

  • With this level of knowledge, the testing team can conduct in-depth

analysis, targeted assessments, and explore potential attack vectors.

Day 2

Penetration Test Phases

Passive Reconnaissance Active Reconnaissance Exploitation Additional Research* Continued Exploitation Reporting * Research and exploitation are iterative processes.

Day 2

Offensive / Defensive Penetration Testing

Offensive / Defensive penetration testing is designed to simulate an attack and evaluate preventative and deterrent controls, detection, and response capability.

Day 2

Physical Penetration Testing

  • Physical penetration testing aims to assess the physical security measures in

place, such as access control systems, locks, alarms, surveillance systems, perimeter security, and employee awareness.

  • Physical penetration testers simulate the techniques and tactics that malicious

actors might use to gain unauthorized access (e.g., social engineering, tailgating (following authorized personnel into secured areas), lock picking, badge cloning). Physical penetration testing focuses on evaluating the effectiveness of an organization's physical security controls and measures.

Day 2

5.6 Given a scenario, implement security awareness practices.

Day 2

Shared Responsibility

  • A critical component of a successful information security program is

knowledge and awareness.

  • On-going education, training, and awareness programs are essential.
  • Programs should always be customized for the target audience.
  • Programs should be adaptable to changing circumstances (e.g., remote work

from home). Information security is a shared responsibility throughout an enterprise.

Day 2

NIST SETA Model [SP800-50]

Security Education Training Awareness Attribute Why How What Level Insight Knowledge Information Objective Understanding Skill Behavior Method Discussion, seminar, reading Lecture, case study, hands-on Interactive, video, posters, games Measure Essay Problem solving True or false, multiple choice Impact Long-term Intermediate Short-term

Day 2

SETA Maturity Model

Nonexistent Ad Hoc Compliance Driven Integrated Measurable and Reportable (Metrics Driven)

Day 2

Security Awareness Programs

  • Onboarding and post-boarding programs should focus on policies (e.g.,

Acceptable Use Policy), best practices, social engineering, duress, and reporting suspicious activity.

  • Annual compliance, hot topic, and refresher program (instructor-led, recorded,

online).

  • On-going awareness program which includes posters, games, contests, prizes,

and surveys.

  • As needed, situational awareness communications.

Security awareness programs should be inclusive of all levels of the organization and extend to third-parties. The objective is to influence behavior.

Day 2

Secrets of Impactful Training

Get everyone to believe in a shared outcome.

  • Is

Be concise; don’t wander. Engage your audience – interactive activities, games, songs. Begin with an unexpected opening line. Start on time. Create a comfortable and welcoming environment. Invite everyone.

Day 2

Assessment Question 5.1

Policies are high level governance documents. What is the relationship between policies and standards? A. Standards restate the policy in technical terms. B. Standards are mandatory implementation requirements. C. Standards create awareness. D. Standards influence procurement decisions.

Day 2

Assessment Question 5.2

The Customer Service Team has informed management that if the Online Banking application is unavailable for more than 10 minutes, their phones start ringing off the hook with calls from unhappy customers. How would this be expressed in a BIA metric? A. RTO=10 B. MTD=10 C. MTBF=10 D. RPO=10

Day 2

Assessment Question 5.3

Choose the correct formula for calculating an annualized loss expectancy. A. ALE=AV*EF B. ALE=SLE*ARO C. ALE=ARO*EF D. ALE=EF*SLE

Day 2

Assessment Question 5.4

Type of penetration test that is designed to simulate an attack and evaluate preventative and deterrent controls, detection, and response capability. A. Offensive/defensive B. Open source C. Physical D. Unknown environment

Day 2

Assessment Question 5.5

This privacy regulation is based on the OECD privacy principles and is designed to protect European Union (EU) and European Economic Area (EEA) residents from unlawful data collection or processing. A. GLBA B. COPPA C. CCPA D. GDPR

Day 2

Preparing for the Exam

Domain 1 General Security Concepts 12% Domain 2 Threats, Vulnerabilities & Mitigations 22% Domain 3 Security Architecture 18% Domain 4 Security Operations 28% Security Program Management & Oversight 20% Preparing for the Exam Study Strategies

Day 2

Test Taking Tips

  • Be prepared for a variety of question formats include multiple choice,

multiple response, fill-in-the-blank, drag and drop, scenarios, exhibits (graphic or video), and performance-based.

  • Pace yourself. Don’t rush, you will have enough time.
  • Read the questions carefully.
  • Choose your answer deliberately.
  • Don't argue with the answers.
  • Don’t panic if you are unsure about a question or the answer. Remind

yourself you can do this.

  • If necessary, use the process of elimination.
  • Post-exam, treat yourself to an indulgence.
Day 2

Let’s study together

Stay in touch: e: Sari@sarigreenegroup.com t: @sari_greene l: https://www.linkedin.com/in/sarigreene/ Please complete the online evaluation and thank you for your participation. -All the best, Sari