Introduction |
|
xxii | |
Chapter 1 Introduction to Security |
|
2 | (10) |
|
|
3 | (1) |
|
|
3 | (3) |
|
The CIA of Computer Security |
|
|
3 | (1) |
|
The Basics of Information Security |
|
|
4 | (2) |
|
|
6 | (1) |
|
Threat Actor Types and Attributes |
|
|
7 | (5) |
|
Chapter Review Activities |
|
|
9 | (1) |
|
|
9 | (1) |
|
|
9 | (1) |
|
|
9 | (3) |
Chapter 2 Computer Systems Security Part I |
|
12 | (22) |
|
|
13 | (1) |
|
|
13 | (4) |
|
|
13 | (1) |
|
|
14 | (1) |
|
|
14 | (1) |
|
|
15 | (1) |
|
|
15 | (1) |
|
|
16 | (1) |
|
|
16 | (1) |
|
Summary of Malware Threats |
|
|
17 | (1) |
|
|
17 | (3) |
|
Via Software, Messaging, and Media |
|
|
18 | (1) |
|
|
19 | (1) |
|
|
19 | (1) |
|
|
19 | (1) |
|
|
19 | (1) |
|
|
20 | (1) |
|
Preventing and Troubleshooting Malware |
|
|
20 | (9) |
|
Preventing and Troubleshooting Viruses |
|
|
20 | (3) |
|
Preventing and Troubleshooting Worms and Trojans |
|
|
23 | (1) |
|
Preventing and Troubleshooting Spyware |
|
|
24 | (1) |
|
Preventing and Troubleshooting Rootkits |
|
|
25 | (1) |
|
Preventing and Troubleshooting Spam |
|
|
26 | (1) |
|
You Can't Save Every Computer from Malware! |
|
|
27 | (1) |
|
Summary of Malware Prevention Techniques |
|
|
27 | (2) |
|
Chapter Review Activities |
|
|
29 | (5) |
|
|
29 | (1) |
|
|
29 | (1) |
|
|
29 | (1) |
|
Complete the Real-World Scenarios |
|
|
29 | (1) |
|
|
30 | (4) |
Chapter 3 Computer Systems Security Part II |
|
34 | (24) |
|
|
35 | (1) |
|
Implementing Security Applications |
|
|
35 | (4) |
|
Personal Software Firewalls |
|
|
35 | (1) |
|
Host-Based Intrusion Detection Systems |
|
|
36 | (2) |
|
|
38 | (1) |
|
Data Loss Prevention Systems |
|
|
38 | (1) |
|
Securing Computer Hardware and Peripherals |
|
|
39 | (5) |
|
|
39 | (2) |
|
|
41 | (1) |
|
|
41 | (1) |
|
|
41 | (1) |
|
|
42 | (1) |
|
Hardware Security Modules |
|
|
43 | (1) |
|
Securing Wireless Peripherals |
|
|
43 | (1) |
|
|
44 | (9) |
|
|
44 | (1) |
|
|
45 | (1) |
|
SIM Cloning and Carrier Unlocking |
|
|
45 | (1) |
|
|
46 | (1) |
|
|
46 | (1) |
|
|
47 | (2) |
|
|
49 | (4) |
|
Chapter Review Activities |
|
|
53 | (5) |
|
|
53 | (1) |
|
|
53 | (1) |
|
|
54 | (1) |
|
Complete the Real-World Scenarios |
|
|
54 | (1) |
|
|
54 | (4) |
Chapter 4 OS Hardening and Virtualization |
|
58 | (28) |
|
|
59 | (1) |
|
Hardening Operating Systems |
|
|
59 | (15) |
|
Removing Unnecessary Applications and Services |
|
|
59 | (6) |
|
Windows Update, Patches, and Hotfixes |
|
|
65 | (1) |
|
|
66 | (2) |
|
|
68 | (1) |
|
Group Policies, Security Templates, and Configuration Baselines |
|
|
69 | (2) |
|
Hardening File Systems and Hard Drives |
|
|
71 | (3) |
|
Virtualization Technology |
|
|
74 | (5) |
|
Types of Virtualization and Their Purposes |
|
|
74 | (1) |
|
|
75 | (1) |
|
Securing Virtual Machines |
|
|
76 | (3) |
|
Chapter Review Activities |
|
|
79 | (7) |
|
|
79 | (1) |
|
|
80 | (1) |
|
|
80 | (1) |
|
Complete the Real-World Scenarios |
|
|
80 | (1) |
|
|
81 | (5) |
Chapter 5 Application Security |
|
86 | (32) |
|
|
87 | (1) |
|
|
87 | (8) |
|
General Browser Security Procedures |
|
|
88 | (1) |
|
|
88 | (2) |
|
|
90 | (1) |
|
Use a Proxy and Content Filter |
|
|
91 | (1) |
|
Secure Against Malicious Code |
|
|
92 | (1) |
|
Web Browser Concerns and Security Methods |
|
|
92 | (1) |
|
|
92 | (1) |
|
|
92 | (1) |
|
|
93 | (1) |
|
|
94 | (1) |
|
Advanced Browser Security |
|
|
94 | (1) |
|
Securing Other Applications |
|
|
95 | (4) |
|
|
99 | (12) |
|
Software Development Life Cycle |
|
|
99 | (1) |
|
Core SDLC and DevOps Principles |
|
|
100 | (2) |
|
Programming Testing Methods |
|
|
102 | (1) |
|
White-box and Black-box Testing |
|
|
102 | (1) |
|
Compile-Time Errors Versus Runtime Errors |
|
|
102 | (1) |
|
|
103 | (1) |
|
Static and Dynamic Code Analysis |
|
|
104 | (1) |
|
|
104 | (1) |
|
Programming Vulnerabilities and Attacks |
|
|
104 | (1) |
|
|
105 | (1) |
|
Memory/Buffer Vulnerabilities |
|
|
105 | (1) |
|
Arbitrary Code Execution/Remote Code Execution |
|
|
106 | (1) |
|
|
107 | (1) |
|
More Code Injection Examples |
|
|
107 | (2) |
|
|
109 | (1) |
|
|
109 | (2) |
|
Chapter Review Activities |
|
|
111 | (7) |
|
|
111 | (1) |
|
|
112 | (1) |
|
|
112 | (1) |
|
Complete the Real-World Scenarios |
|
|
112 | (1) |
|
|
112 | (6) |
Chapter 6 Network Design Elements |
|
118 | (30) |
|
|
119 | (1) |
|
|
119 | (14) |
|
|
119 | (1) |
|
|
120 | (1) |
|
|
120 | (2) |
|
|
122 | (1) |
|
|
122 | (1) |
|
Network Address Translation, and Private Versus Public IP |
|
|
123 | (2) |
|
Network Zones and Interconnections |
|
|
125 | (1) |
|
|
125 | (1) |
|
|
126 | (1) |
|
|
126 | (1) |
|
|
127 | (1) |
|
Network Access Control (NAC) |
|
|
128 | (1) |
|
|
128 | (2) |
|
Virtual Local Area Network (VLAN) |
|
|
130 | (1) |
|
|
131 | (1) |
|
|
131 | (1) |
|
|
132 | (1) |
|
|
132 | (1) |
|
Cloud Security and Server Defense |
|
|
133 | (9) |
|
|
133 | (2) |
|
|
135 | (2) |
|
|
137 | (1) |
|
|
137 | (1) |
|
|
137 | (1) |
|
|
138 | (1) |
|
|
139 | (1) |
|
|
140 | (2) |
|
Chapter Review Activities |
|
|
142 | (6) |
|
|
142 | (1) |
|
|
143 | (1) |
|
|
143 | (1) |
|
Complete the Real-World Scenarios |
|
|
143 | (1) |
|
|
143 | (5) |
Chapter 7 Networking Protocols and Threats |
|
148 | (26) |
|
|
149 | (1) |
|
|
149 | (6) |
|
Port Ranges, Inbound Versus Outbound, and Common Ports |
|
|
149 | (6) |
|
Protocols That Can Cause Anxiety on the Exam |
|
|
155 | (1) |
|
|
155 | (12) |
|
|
155 | (3) |
|
|
158 | (1) |
|
|
158 | (1) |
|
|
159 | (1) |
|
|
159 | (2) |
|
|
161 | (1) |
|
|
161 | (1) |
|
Transitive Access and Client-Side Attacks |
|
|
162 | (1) |
|
DNS Poisoning and Other DNS Attacks |
|
|
162 | (2) |
|
|
164 | (1) |
|
Summary of Network Attacks |
|
|
164 | (3) |
|
Chapter Review Activities |
|
|
167 | (7) |
|
|
167 | (1) |
|
|
168 | (1) |
|
|
168 | (1) |
|
Complete the Real-World Scenarios |
|
|
168 | (1) |
|
|
168 | (6) |
Chapter 8 Network Perimeter Security |
|
174 | (20) |
|
|
175 | (1) |
|
Firewalls and Network Security |
|
|
175 | (8) |
|
|
175 | (4) |
|
|
179 | (2) |
|
|
181 | (1) |
|
Data Loss Prevention (DLP) |
|
|
182 | (1) |
|
|
183 | (4) |
|
|
183 | (1) |
|
|
184 | (1) |
|
Summary of NIDS Versus NIPS |
|
|
185 | (1) |
|
The Protocol Analyzer's Role in NIDS and NIPS |
|
|
185 | (1) |
|
Unified Threat Management |
|
|
186 | (1) |
|
Chapter Review Activities |
|
|
187 | (7) |
|
|
187 | (1) |
|
|
188 | (1) |
|
|
188 | (1) |
|
Complete the Real-World Scenarios |
|
|
188 | (1) |
|
|
188 | (6) |
Chapter 9 Securing Network Media and Devices |
|
194 | (24) |
|
|
195 | (1) |
|
Securing Wired Networks and Devices |
|
|
195 | (6) |
|
Network Device Vulnerabilities |
|
|
195 | (1) |
|
|
195 | (1) |
|
|
195 | (1) |
|
|
196 | (1) |
|
|
197 | (1) |
|
|
197 | (1) |
|
Other Network Device Considerations |
|
|
197 | (1) |
|
Cable Media Vulnerabilities |
|
|
198 | (1) |
|
|
198 | (1) |
|
|
199 | (1) |
|
|
199 | (1) |
|
Tapping into Data and Conversations |
|
|
200 | (1) |
|
Securing Wireless Networks |
|
|
201 | (11) |
|
Wireless Access Point Vulnerabilities |
|
|
202 | (1) |
|
The Administration Interface |
|
|
202 | (1) |
|
|
202 | (1) |
|
|
202 | (1) |
|
|
203 | (1) |
|
|
203 | (2) |
|
|
205 | (1) |
|
|
205 | (1) |
|
|
205 | (1) |
|
Wireless Access Point Security Strategies |
|
|
205 | (3) |
|
Wireless Transmission Vulnerabilities |
|
|
208 | (1) |
|
Bluetooth and Other Wireless Technology Vulnerabilities |
|
|
209 | (1) |
|
|
209 | (1) |
|
|
210 | (1) |
|
|
210 | (1) |
|
More Wireless Technologies |
|
|
210 | (2) |
|
Chapter Review Activities |
|
|
212 | (6) |
|
|
212 | (2) |
|
|
214 | (1) |
|
|
214 | (1) |
|
Complete the Real-World Scenarios |
|
|
214 | (1) |
|
|
214 | (4) |
Chapter 10 Physical Security and Authentication Models |
|
218 | (26) |
|
|
219 | (1) |
|
|
219 | (3) |
|
General Building and Server Room Security |
|
|
219 | (1) |
|
|
220 | (1) |
|
|
221 | (1) |
|
Authentication Models and Components |
|
|
222 | (1) |
|
|
222 | (14) |
|
Localized Authentication Technologies |
|
|
224 | (1) |
|
|
224 | (2) |
|
|
226 | (1) |
|
Kerberos and Mutual Authentication |
|
|
227 | (2) |
|
|
229 | (1) |
|
Remote Authentication Technologies |
|
|
230 | (1) |
|
|
230 | (1) |
|
|
231 | (3) |
|
|
234 | (2) |
|
Chapter Review Activities |
|
|
236 | (8) |
|
|
236 | (1) |
|
|
236 | (1) |
|
|
237 | (1) |
|
Complete the Real-World Scenarios |
|
|
237 | (1) |
|
|
237 | (7) |
Chapter 11 Access Control Methods and Models |
|
244 | (26) |
|
|
245 | (1) |
|
Access Control Models Defined |
|
|
245 | (5) |
|
Discretionary Access Control |
|
|
245 | (1) |
|
|
246 | (1) |
|
Role-Based Access Control (RBAC) |
|
|
247 | (1) |
|
Attribute-based Access Control (ABAC) |
|
|
248 | (1) |
|
Access Control Wise Practices |
|
|
249 | (1) |
|
Rights, Permissions, and Policies |
|
|
250 | (12) |
|
Users, Groups, and Permissions |
|
|
251 | (4) |
|
Permission Inheritance and Propagation |
|
|
255 | (1) |
|
Moving and Copying Folders and Files |
|
|
256 | (1) |
|
|
256 | (2) |
|
|
258 | (3) |
|
User Account Control (UAC) |
|
|
261 | (1) |
|
Chapter Review Activities |
|
|
262 | (8) |
|
|
262 | (1) |
|
|
262 | (1) |
|
|
263 | (1) |
|
Complete the Real-World Scenarios |
|
|
263 | (1) |
|
|
263 | (7) |
Chapter 12 Vulnerability and Risk Assessment |
|
270 | (24) |
|
|
271 | (1) |
|
Conducting Risk Assessments |
|
|
271 | (9) |
|
Qualitative Risk Assessment |
|
|
272 | (1) |
|
Quantitative Risk Assessment |
|
|
273 | (1) |
|
Security Analysis Methodologies |
|
|
274 | (1) |
|
|
275 | (1) |
|
|
276 | (1) |
|
|
277 | (2) |
|
|
279 | (1) |
|
Additional Vulnerabilities |
|
|
279 | (1) |
|
Assessing Vulnerability with Security Tools |
|
|
280 | (7) |
|
|
280 | (2) |
|
|
282 | (1) |
|
|
283 | (1) |
|
|
284 | (3) |
|
Chapter Review Activities |
|
|
287 | (7) |
|
|
287 | (1) |
|
|
287 | (1) |
|
|
288 | (1) |
|
Complete the Real-World Scenarios |
|
|
288 | (1) |
|
|
288 | (6) |
Chapter 13 Monitoring and Auditing |
|
294 | (28) |
|
|
295 | (1) |
|
|
295 | (1) |
|
Signature-Based Monitoring |
|
|
295 | (1) |
|
|
295 | (1) |
|
Behavior-Based Monitoring |
|
|
296 | (1) |
|
Using Tools to Monitor Systems and Networks |
|
|
296 | (8) |
|
|
297 | (2) |
|
|
299 | (1) |
|
|
299 | (2) |
|
|
301 | (1) |
|
|
302 | (2) |
|
Use Static and Dynamic Tools |
|
|
304 | (1) |
|
|
304 | (11) |
|
|
305 | (1) |
|
|
306 | (4) |
|
Log File Maintenance and Security |
|
|
310 | (1) |
|
Auditing System Security Settings |
|
|
311 | (3) |
|
|
314 | (1) |
|
Chapter Review Activities |
|
|
315 | (7) |
|
|
315 | (1) |
|
|
316 | (1) |
|
|
316 | (1) |
|
Complete the Real-World Scenarios |
|
|
316 | (1) |
|
|
316 | (6) |
Chapter 14 Encryption and Hashing Concepts |
|
322 | (28) |
|
|
323 | (1) |
|
|
323 | (6) |
|
Symmetric Versus Asymmetric Key Algorithms |
|
|
326 | (1) |
|
|
326 | (1) |
|
Asymmetric Key Algorithms |
|
|
327 | (1) |
|
|
327 | (1) |
|
|
328 | (1) |
|
|
328 | (1) |
|
|
329 | (7) |
|
|
329 | (1) |
|
|
329 | (1) |
|
|
330 | (1) |
|
|
331 | (1) |
|
Summary of Symmetric Algorithms |
|
|
331 | (1) |
|
|
331 | (2) |
|
|
333 | (1) |
|
|
333 | (1) |
|
|
334 | (1) |
|
|
334 | (1) |
|
|
335 | (1) |
|
Pseudorandom Number Generators |
|
|
336 | (1) |
|
|
336 | (7) |
|
Cryptographic Hash Functions |
|
|
337 | (1) |
|
|
338 | (1) |
|
|
338 | (1) |
|
|
338 | (1) |
|
|
339 | (1) |
|
|
339 | (1) |
|
|
340 | (1) |
|
|
341 | (1) |
|
|
341 | (1) |
|
|
341 | (1) |
|
Additional Password Hashing Concepts |
|
|
342 | (1) |
|
Chapter Review Activities |
|
|
343 | (1) |
|
|
343 | (7) |
|
|
344 | (1) |
|
|
344 | (1) |
|
Complete the Real-World Scenarios |
|
|
344 | (1) |
|
|
345 | (5) |
Chapter 15 PKI and Encryption Protocols |
|
350 | (18) |
|
|
351 | (1) |
|
Public Key Infrastructure |
|
|
351 | (5) |
|
|
351 | (1) |
|
|
352 | (1) |
|
Single-Sided and Dual-Sided Certificates |
|
|
352 | (1) |
|
Certificate Chain of Trust |
|
|
352 | (1) |
|
|
352 | (1) |
|
|
353 | (3) |
|
|
356 | (1) |
|
|
356 | (5) |
|
|
357 | (1) |
|
|
357 | (2) |
|
|
359 | (1) |
|
|
359 | (1) |
|
|
359 | (1) |
|
|
359 | (1) |
|
|
360 | (1) |
|
Chapter Review Activities |
|
|
361 | (7) |
|
|
361 | (1) |
|
|
361 | (1) |
|
|
362 | (1) |
|
Complete the Real-World Scenarios |
|
|
362 | (1) |
|
|
362 | (6) |
Chapter 16 Redundancy and Disaster Recovery |
|
368 | (22) |
|
|
369 | (1) |
|
|
369 | (10) |
|
|
370 | (1) |
|
|
371 | (1) |
|
Uninterruptible Power Supplies |
|
|
371 | (1) |
|
|
372 | (2) |
|
|
374 | (2) |
|
|
376 | (1) |
|
|
377 | (1) |
|
|
378 | (1) |
|
|
379 | (1) |
|
Disaster Recovery Planning and Procedures |
|
|
379 | (6) |
|
|
379 | (3) |
|
|
382 | (3) |
|
Chapter Review Activities |
|
|
385 | (5) |
|
|
385 | (1) |
|
|
385 | (1) |
|
|
386 | (1) |
|
Complete the Real-World Scenarios |
|
|
386 | (1) |
|
|
386 | (4) |
Chapter 17 Social Engineering, User Education, and Facilities Security |
|
390 | (20) |
|
|
391 | (1) |
|
|
391 | (5) |
|
|
391 | (1) |
|
|
391 | (1) |
|
|
392 | (1) |
|
|
392 | (1) |
|
|
393 | (1) |
|
|
394 | (1) |
|
|
394 | (1) |
|
|
394 | (1) |
|
|
394 | (1) |
|
|
394 | (1) |
|
|
395 | (1) |
|
Summary of Social Engineering Types |
|
|
395 | (1) |
|
|
396 | (2) |
|
|
398 | (6) |
|
|
398 | (1) |
|
|
398 | (1) |
|
|
399 | (1) |
|
Special Hazard Protection Systems |
|
|
399 | (1) |
|
|
400 | (1) |
|
|
401 | (1) |
|
|
402 | (2) |
|
Chapter Review Activities |
|
|
404 | (6) |
|
|
404 | (1) |
|
|
404 | (1) |
|
|
405 | (1) |
|
Complete the Real-World Scenarios |
|
|
405 | (1) |
|
|
405 | (5) |
Chapter 18 Policies and Procedures |
|
410 | (22) |
|
|
411 | (1) |
|
Legislative and Organizational Policies |
|
|
411 | (9) |
|
Data Sensitivity and Classification of Information |
|
|
411 | (2) |
|
Personnel Security Policies |
|
|
413 | (1) |
|
|
414 | (1) |
|
|
414 | (1) |
|
|
414 | (1) |
|
Separation of Duties/job Rotation |
|
|
415 | (1) |
|
|
415 | (1) |
|
Onboarding and Offloarding |
|
|
415 | (1) |
|
|
416 | (1) |
|
|
416 | (1) |
|
|
416 | (1) |
|
User Education and Awareness Training |
|
|
416 | (1) |
|
Summary of Personnel Security Policies |
|
|
417 | (1) |
|
|
417 | (2) |
|
How to Dispose of Computers and Other IT Equipment Securely |
|
|
419 | (1) |
|
Incident Response Procedures |
|
|
420 | (4) |
|
|
424 | (2) |
|
Chapter Review Activities |
|
|
426 | (6) |
|
|
426 | (1) |
|
|
426 | (1) |
|
|
427 | (1) |
|
Complete the Real-World Scenarios |
|
|
427 | (1) |
|
|
427 | (5) |
Chapter 19 Taking the Real Exam |
|
432 | (8) |
|
Getting Ready and the Exam Preparation Checklist |
|
|
432 | (3) |
|
Tips for Taking the Real Exam |
|
|
435 | (3) |
|
Beyond the CompTIA Security+ Certification |
|
|
438 | (2) |
Practice Exam 1: SY0-501 |
|
440 | (18) |
Glossary |
|
458 | (22) |
Index |
|
480 | |