FOR CLASS TRAINING SCHEDULES CLICK ON A MENU ITEM ABOVE
Course Description
Security+™A CompTIA Certification is the primary course you will need to take if your job responsibilities include securing network services, network devices, and network traffic. It is also the main course you will take to prepare for the CompTIA Security+ examination (exam number SY0-
201). In this course, you'll build on your knowledge and professional experience with computer hardware, operating systems, and networks as you acquire the specific skills required to implement basic security services on any type of computer network. 5 day course.
Course Prerequisites
CompTIA A+ and Network+ certifications,
or equivalent knowledge, and six to nine months experience in networking,
including experience configuring and managing TCP/IP.
Days: 5
Unit 1 : Mitigating threats
Topic A: 0 Core system maintenance
A-1: Identifying common security threats
A-2: Updating the operating system
A-3: Managing software patches
A-4: Installing service packs
A-5: Determining whether you need to update your computer’s BIOS
A-6: Configuring Windows Firewall
Topic B: 0 Virus and spyware management
B-1: Installing antivirus software
B-2: Scanning your system for spyware
B-3: Configuring Windows Mail to prevent spam
Topic C: 0 Browser security
C-1: Managing pop-ups
C-2: Managing cookies
C-3: Managing scripting, Java, and ActiveX components
C-4: Examining input validation, buffer overflows, and XSS
Topic D: 0 Social engineering threats
D-1: Discussing social engineering
D-2: Examining phishing
Unit 2 : Cryptography
Topic A: 0 Symmetric cryptography
A-1: Encrypting and decrypting data
A-2: Calculating hashes
A-3: Sharing a secret message with steganography
Topic B: 0 Public key cryptography
B-1: Exploring public key cryptography
B-2: Examining certificates
B-3: Examining certificate trusts
B-4: Comparing single- and dual-sided certificates
B-5: Mapping algorithms to applications
Unit 3 : Authentication systems
Topic A: 0 Authentication
A-1: Identifying the components of authentication
A-2: Comparing one, two, and three-factor authentication
A-3: Capturing passwords with a protocol analyzer
A-4: Installing Active Directory Services
A-5: Joining a domain
Topic B: 0 Hashing
B-1: Hashing data
B-2: Cracking passwords
Topic C: 0 Authentication systems
C-1: Identifying the requirements of a secure authentication system
C-2: Examining the components of Kerberos
C-4: Comparing authentication systems
Unit 4 : Messaging security
Topic A: 0 E-mail security
A-1: Identifying the security risks of an e-mail system
A-2: Configuring security on an e-mail server
A-3: Digitally signing a message
A-4: Sending an encrypted message
Topic B: 0 Messaging and peer-to-peer security
B-1: Identifying the security risks of messaging systems
B-2: Configuring security on an IM server
B-3: Configuring IM client security
Unit 5 : User and role based security
Topic A: 0 Security policies
A-1: Creating a console to manage local security policies
A-2: Using the GPMC
A-3: Implementing domain GPOs
A-4: Analyzing a Windows Vista computer’s security
Topic B: 0 Securing file and print resources
B-1: Creating users and groups based on security needs
B-2: Securing file resources
B-3: Securing printer resources
Unit 6 : Public key infrastructure
Topic A: 0 Key management and life cycle
A-1: Understanding certificate life cycle and management
Topic B: 0 Setting up a certificate server
B-1: Installing a standalone root certificate authority
B-2: Installing an enterprise subordinate CA
B-3: Implementing a file-based certificate request
B-4: Managing your certificate server
B-5: Side trip: granting the log on locally right
B-6: Requesting a user certificate
B-7: Revoking a certificate
B-8: Enabling the EFS recovery agent template
B-9: Enrolling for a recovery agent certificate
B-10: Enabling key archival
B-11: Re-enrolling all certificates
Topic C: 0 Web server security with PKI
C-1: Requesting and installing a Web server certificate
C-2: Enabling SSL for the certificate server Web site
C-3: Making a secure connection
C-4: Requesting a client certificate via the Web
Unit 7 : Access security
Topic A: 0 Biometric systems
A-1: Identifying biometric authentication systems
A-2: Installing a fingerprint reader
Topic B: 0 Physical access security
B-1: Identifying the risks associated with physical access to systems
B-2: Examining logging and surveillance best practices
Topic C: 0 Peripheral and component security
C-1: Identifying the risks associated with common peripherals
C-2: Mitigating security risks of peripherals
Topic D: 0 Storage device security
D-1: Enabling file-based encryption
D-2: Enabling whole disk encryption systems (optional)
Unit 8 : Ports and protocols
Topic A: 0 TCP/IP review
A-1: Examining protocols in the TCP/IP suite
A-2: Comparing IPv4 and IPv6 packets
Topic B: 0 Protocol-based attacks
B-1: Preventing common protocol-based attacks
B-2: Assessing your vulnerability to DDoS attacks
B-3: Port scanning
B-4: Checking ARP cache
B-5: Examining spoofing attacks
B-6: Examining replay and hijacking attacks
B-7: Examining antiquated protocols
Unit 9 : Network security
Topic A: 0 Common network devices
A-1: Examining switches and bridges
A-2: Examining routers
A-3: Examining NAT/PAT devices
A-4: Examining firewalls and proxy servers
A-5: Identifying inherent weaknesses in network devices
A-6: Examining the ways to overcome device threats
Topic B: 0 Secure network topologies
B-1: Comparing firewall-based secure topologies
B-2: Identifying the benefits of NAC
B-3: Examining the security enabled by VPNs
Topic C: 0 Browser-related network security
C-1: Configuring the Phishing Filter
C-2: Setting security zones
C-3: Setting privacy options
Topic D: 0 Virtualization
D-1: Exploring the benefits of virtualization technologies
Unit 10 : Wireless security
Topic A: 0 Wi-Fi network security
A-1: Identifying wireless networking vulnerabilities
A-2: Scanning for insecure access points
A-3: Installing third-party router firmware
A-4: Configuring basic router security
A-5: Enabling transmission encryption
Topic B: 0 Non-PC wireless devices
B-1: Identifying cell phone and PDA related threats
Unit 11 : Remote access security
Topic A: 0 Remote access
A-1: Examining RADIUS and Diameter authentication
A-2: Examining the role of LDAP in a remote access environment
A-3: Examining TACACS+ authentication
A-4: Examining how 802.1x adds security to your network
A-5: Installing Network Policy and Access Services
A-6: Configuring an NPS network policy
A-7: Configuring NPS accounting
Topic B: 0 Virtual private networks
B-2: Installing Routing and Remote Access Services
B-3: Enabling a VPN
B-4: Configuring NPS to provide RADIUS authentication for your VPN
B-5: Making a VPN connection
Unit
12
:
Auditing, logging, and monitoring
Topic
A:
0
System logging
A-1:
Viewing event logs
A-2:
Discussing device and application logging
Topic
B:
0
Server monitoring
B-1:
Monitoring with Performance Monitor
B-2:
Running a Data Collector Set
B-3:
Viewing a Data Collector Set report
B-4:
Considering auditing policies and
practices
Unit
13
:
Vulnerability testing
Topic
A:
0
Risk and vulnerability assessment
A-1:
Analyzing risks
A-2:
Installing the MBSA
A-3:
Analyzing your system with the MBSA
A-4:
Downloading and installing OVAL
A-5:
Downloading an OVAL XML file
A-6:
Scanning with OVAL
A-7:
Downloading and installing Nessus
A-8:
Scanning with Nessus
Topic
B:
0
IDS and IPS
B-1:
Discussing IDS characteristics
B-2:
Installing and monitoring with the Snort
IDS
B-3: Comparing HIDS and NIDS
B-4:
Examining the role and use of honeypots
Topic
C:
0
Forensics
C-1:
Examining the forensics process
Unit 14 : Organizational security
Topic A: 0 Organizational policies
A-1: Creating a security policy
A-2: Creating a human resources policy
A-3: Creating an incidence response and reporting policy
A-4: Implementing change management
Topic B: 0 Education and training
B-1: Identifying the need for user education and training
B-2: Identifying education opportunities and methods
Topic C: 0 Disposal and destruction
C-1: Deciding whether to destroy or dispose of IT equipment
Unit 15 : Business continuity
Topic A: 0 Redundancy planning
A-1: Identifying the need for and appropriate use of redundancy
A-2: Creating a disaster recovery plan
Topic B: 0 Backups
B-1: Selecting backup schemes
B-2: Backing up data
B-3: Restoring data
B-4: Identifying appropriate media rotation and storage plans
Topic
C:
0
Environmental controls
C-1: Examining environmental controls
Appendix A : CompTIA Security+ objectives map
Topic A: 0 Objective map
Appendix B : CompTIA Security+ acronyms
Topic A: 0 Acronym list
