Introduction |
|
xix | |
|
|
xxii | |
|
|
xxiv | |
|
CompTIA professional certification program |
|
|
xxvi | |
|
How certification helps your career |
|
|
xxvi | |
|
|
xxvii | |
|
Four steps to getting certified and staying certified |
|
|
xxvii | |
|
How to obtain more information |
|
|
xxviii | |
|
|
xxviii | |
|
|
xxx | |
|
|
xxxi | |
Chapter 1 Risk management and incident response |
|
1 | (38) |
|
|
2 | (2) |
|
Confidentiality and disclosure |
|
|
3 | (1) |
|
|
3 | (1) |
|
|
3 | (1) |
|
Risk assessment and mitigation |
|
|
4 | (8) |
|
|
5 | (4) |
|
|
9 | (3) |
|
|
12 | (2) |
|
|
12 | (1) |
|
|
12 | (1) |
|
|
13 | (1) |
|
|
14 | (20) |
|
|
14 | (5) |
|
Incident response life cycle |
|
|
19 | (6) |
|
|
25 | (1) |
|
|
26 | (2) |
|
|
28 | (6) |
|
|
34 | (1) |
|
|
35 | (2) |
|
|
37 | (2) |
Chapter 2 Network security technologies |
|
39 | (28) |
|
|
40 | (22) |
|
Humongous Insurance: a modern secure network |
|
|
41 | (1) |
|
|
41 | (5) |
|
|
46 | (1) |
|
|
47 | (2) |
|
|
49 | (2) |
|
|
51 | (1) |
|
|
52 | (2) |
|
Network intrusion detection systems (NIDS) and net- work intrusion prevention systems (NIPS) |
|
|
54 | (3) |
|
|
57 | (1) |
|
|
58 | (4) |
|
All-in-one security appliances |
|
|
62 | (1) |
|
|
62 | (1) |
|
|
63 | (2) |
|
|
65 | (2) |
Chapter 3 Secure network design and management |
|
67 | (42) |
|
Network design and implementation |
|
|
69 | (15) |
|
IP: the Internet Protocol |
|
|
69 | (8) |
|
Network and application protocols |
|
|
77 | (6) |
|
|
83 | (1) |
|
Network design and segmentation |
|
|
84 | (11) |
|
|
87 | (2) |
|
|
89 | (1) |
|
|
90 | (5) |
|
Network administration and management |
|
|
95 | (3) |
|
Access control lists (ACLs) |
|
|
95 | (1) |
|
|
96 | (1) |
|
|
96 | (2) |
|
Secure switch and router configuration |
|
|
98 | (3) |
|
|
98 | (1) |
|
|
98 | (1) |
|
|
99 | (1) |
|
|
99 | (1) |
|
|
100 | (1) |
|
Preventing network bridging |
|
|
100 | (1) |
|
Wireless protocols: encryption and authentication |
|
|
101 | (3) |
|
Designing and implementing secure wireless networks |
|
|
103 | (1) |
|
|
104 | (1) |
|
|
105 | (2) |
|
|
107 | (2) |
Chapter 4 Operational and environmental security |
|
109 | (40) |
|
|
111 | (7) |
|
|
113 | (1) |
|
|
113 | (2) |
|
|
115 | (1) |
|
Personnel security best practices |
|
|
115 | (3) |
|
Security awareness and training |
|
|
118 | (6) |
|
|
118 | (1) |
|
|
119 | (1) |
|
|
119 | (4) |
|
|
123 | (1) |
|
Information classification and labeling |
|
|
124 | (4) |
|
Personally identifying information (PII) |
|
|
126 | (2) |
|
|
128 | (4) |
|
Heating, ventilation, and air conditioning (HVAC) |
|
|
128 | (1) |
|
|
129 | (1) |
|
|
130 | (1) |
|
Environmental and video monitoring |
|
|
130 | (2) |
|
Business continuity planning |
|
|
132 | (6) |
|
Business impact assessment (BIA) |
|
|
132 | (1) |
|
Removing single points of failure |
|
|
133 | (2) |
|
Designing and testing the business continuity plan |
|
|
135 | (2) |
|
|
137 | (1) |
|
Disaster recovery planning |
|
|
138 | (6) |
|
Disaster recovery metrics |
|
|
138 | (2) |
|
|
140 | (1) |
|
Building fault-tolerant environments |
|
|
141 | (2) |
|
|
143 | (1) |
|
|
144 | (1) |
|
|
145 | (2) |
|
|
147 | (2) |
Chapter 5 Threats and attacks |
|
149 | (52) |
|
|
151 | (15) |
|
|
151 | (10) |
|
|
161 | (3) |
|
Application vulnerabilities |
|
|
164 | (2) |
|
|
166 | (5) |
|
|
166 | (2) |
|
|
168 | (1) |
|
|
169 | (1) |
|
|
170 | (1) |
|
|
171 | (1) |
|
Injection and modification attacks |
|
|
171 | (4) |
|
|
172 | (1) |
|
|
173 | (1) |
|
|
174 | (1) |
|
|
175 | (7) |
|
|
175 | (1) |
|
|
176 | (1) |
|
|
176 | (1) |
|
|
177 | (1) |
|
|
178 | (1) |
|
Denial of service and distributed denial of service attacks |
|
|
179 | (1) |
|
|
180 | (1) |
|
|
181 | (1) |
|
|
182 | (6) |
|
|
183 | (2) |
|
|
185 | (1) |
|
|
185 | (1) |
|
Packet sniffing and wireless networks |
|
|
186 | (2) |
|
Social engineering and phishing |
|
|
188 | (7) |
|
|
190 | (1) |
|
|
190 | (3) |
|
|
193 | (2) |
|
|
195 | (1) |
|
|
196 | (2) |
|
|
198 | (3) |
Chapter 6 Monitoring, detection, and defense |
|
201 | (52) |
|
Securing and defending systems |
|
|
202 | (21) |
|
|
203 | (6) |
|
Secure system configuration and management |
|
|
209 | (12) |
|
|
221 | (2) |
|
|
223 | (18) |
|
Continuous security monitoring |
|
|
223 | (1) |
|
|
223 | (13) |
|
|
236 | (5) |
|
Physical security design and concepts |
|
|
241 | (7) |
|
|
248 | (1) |
|
|
249 | (2) |
|
|
251 | (2) |
Chapter 7 Vulnerability assessment and management |
|
253 | (34) |
|
Vulnerabilities and vulnerability assessment |
|
|
255 | (6) |
|
Risk-based vulnerability assessments |
|
|
256 | (2) |
|
|
258 | (3) |
|
|
261 | (11) |
|
Vulnerability scanning tools |
|
|
261 | (2) |
|
|
263 | (2) |
|
|
265 | (4) |
|
|
269 | (3) |
|
|
272 | (9) |
|
Types of penetration tests |
|
|
274 | (1) |
|
Conducting a penetration test |
|
|
275 | (6) |
|
|
281 | (1) |
|
|
282 | (2) |
|
|
284 | (3) |
Chapter 8 The importance of application security |
|
287 | (30) |
|
|
287 | (3) |
|
|
290 | (6) |
|
Error handling and exception handling |
|
|
292 | (1) |
|
|
293 | (3) |
|
Cross-site scripting prevention |
|
|
296 | (1) |
|
Cross-site request forgery (XSRF) prevention |
|
|
297 | (4) |
|
Application configuration baseline (proper settings) |
|
|
301 | (2) |
|
|
303 | (3) |
|
Application patch management |
|
|
306 | (3) |
|
|
309 | (2) |
|
|
311 | (2) |
|
|
313 | (4) |
Chapter 9 Establishing host security |
|
317 | (54) |
|
Operating system security and settings |
|
|
318 | (3) |
|
|
321 | (18) |
|
|
324 | (7) |
|
|
331 | (2) |
|
|
333 | (3) |
|
|
336 | (1) |
|
|
337 | (2) |
|
|
339 | (2) |
|
|
341 | (8) |
|
|
343 | (2) |
|
|
345 | (2) |
|
|
347 | (2) |
|
|
349 | (2) |
|
|
351 | (11) |
|
|
354 | (1) |
|
|
355 | (1) |
|
|
356 | (2) |
|
|
358 | (1) |
|
|
359 | (1) |
|
|
359 | (3) |
|
|
362 | (2) |
|
|
364 | (3) |
|
|
367 | (4) |
Chapter 10 Understanding data security |
|
371 | (40) |
|
Data loss prevention (DLP) |
|
|
371 | (2) |
|
|
373 | (20) |
|
|
377 | (7) |
|
|
384 | (1) |
|
Individual file encryption |
|
|
385 | (3) |
|
|
388 | (3) |
|
|
391 | (2) |
|
Hardware-based encryption devices |
|
|
393 | (8) |
|
|
395 | (1) |
|
|
396 | (2) |
|
|
398 | (1) |
|
|
399 | (2) |
|
|
401 | (1) |
|
|
401 | (3) |
|
|
404 | (3) |
|
|
407 | (4) |
Chapter 11 Identity and access control |
|
411 | (38) |
|
Identification and authentication |
|
|
412 | (2) |
|
|
413 | (1) |
|
Authentication and authorization |
|
|
414 | (9) |
|
|
414 | (1) |
|
Single-factor vs. multifactor authentication |
|
|
414 | (2) |
|
|
416 | (4) |
|
|
420 | (3) |
|
|
423 | (8) |
|
|
423 | (1) |
|
|
424 | (1) |
|
|
425 | (1) |
|
|
426 | (2) |
|
Active Directory Domain Services |
|
|
428 | (1) |
|
|
429 | (2) |
|
Access control concepts and models |
|
|
431 | (8) |
|
Trusted operating systems |
|
|
432 | (1) |
|
|
432 | (1) |
|
|
433 | (1) |
|
|
434 | (1) |
|
|
434 | (1) |
|
|
434 | (1) |
|
|
435 | (4) |
|
|
439 | (5) |
|
|
439 | (3) |
|
|
442 | (1) |
|
Centralized and decentralized privilege management |
|
|
443 | (1) |
|
|
444 | (1) |
|
|
445 | (2) |
|
|
447 | (2) |
Chapter 12 Cryptography |
|
449 | (40) |
|
|
451 | (1) |
|
|
452 | (8) |
|
Symmetric vs. asymmetric cryptography |
|
|
454 | (5) |
|
|
459 | (1) |
|
Symmetric encryption algorithms |
|
|
460 | (7) |
|
|
460 | (5) |
|
Advanced Encryption Standard |
|
|
465 | (1) |
|
|
465 | (1) |
|
|
466 | (1) |
|
|
467 | (1) |
|
Asymmetric encryption algorithms |
|
|
467 | (4) |
|
Rivest, Shamir, and Adelman (RSA) |
|
|
468 | (1) |
|
Pretty Good Privacy (PGP) |
|
|
468 | (2) |
|
Elliptic curve cryptography (ECC) |
|
|
470 | (1) |
|
|
471 | (5) |
|
|
471 | (2) |
|
Creating digital signatures |
|
|
473 | (3) |
|
Public-key infrastructure |
|
|
476 | (2) |
|
|
476 | (2) |
|
Key recovery and key escrow |
|
|
478 | (1) |
|
Protecting data with encryption |
|
|
478 | (5) |
|
|
479 | (2) |
|
Encrypting data in motion |
|
|
481 | (2) |
|
|
483 | (1) |
|
|
484 | (1) |
|
|
485 | (2) |
|
|
487 | (2) |
Glossary |
|
489 | (14) |
Index |
|
503 | |