
Download files here
Learn to conduct a network vulnerability assessment through data collection, interviews, and hands-on investigation; analyze assets, threats, and risks, prioritize safeguards, and align with risk management standards.
Learn vulnerability assessment essentials, including authorization creep, separation and rotation of duties, and qualitative and quantitative risk analysis with single and annualized loss expectancy.
Quantify risk, justify countermeasures, and compare annual loss expectancy and residual risk for cost-beneficial decisions.
Explore critical vulnerability types, including buffer overflow, directory traversal, format string attacks, and default passwords, and learn best practices to prevent information leaks, denial of service, and system compromise.
Examine backdoors and information leaks that enable attackers to map networks, including memory disclosure, banners, path disclosures, SNMP and ICMP reconnaissance, and botnets-based denial of service threats.
Master a network security assessment platform, performing internet-hosted enumeration, IP scanning, and service checks across Windows, Linux, and Unix. Explore virtualization and exploitation frameworks like Metasploit.
Assess network enumeration techniques using dig for DNS lookups, web crawling with tools like spider foot and Nmap scans, including SMTP probing and SMB null sessions.
Fingerprint web servers and subsystems, assess reverse proxies and authentication, and analyze web applications for vulnerabilities, including SQL injection and brute-force risks.
Assess web servers and applications by examining extended stored procedures, direct attacks, privilege escalation, port configurations, query strings, and cross-site scripting, and apply input validation and encoding defense strategies.
Assess remote information services and vpn options by examining DNS, LDAP, WHO, SNMP, and RPC, plus remote maintenance tools such as FTP, Telnet, Citrix, RDP, IPsec and SSL VPN.
Explore vulnerability scanners such as Nessus, Saint, Retina, GFI Land Guard, and Microsoft Baseline Security Analyzer; understand scanning, reporting, patch management, and how to choose the right tool.
Compare vulnerability tools' report features and output formats. See how Nessus, GFI Land Guard, and MBSA generate executive and technical reports for PCI and HIPA compliance.
The Certified Vulnerability Assessor (CVA) course is a vendor neutral certification preparatory course with the objective to deliver the importance of vulnerability assessments by providing intricate knowledge and skills in the Vulnerability Assessment arena. The CVA course provides foundational knowledge of general VA tools as well as popular exploits an IT engineer should be familiar with.
The Certified Vulnerability Assessor is a fundamental cyber security course that focuses on vulnerability assessments. The CVA course focuses on the basic knowledge of conducting a vulnerability assessment and analyze the outcomes to prevent break-ins to the network infrastructure of an organization. The course teaches the candidates to identify the basic malware and virus patterns and the tools and techniques required to prevent the infiltration of the malware and virus into the network. The graduating students will be able to effectively perform a security vulnerability assessment on a network and secure the organization’s IT infrastructure.
Exam Information
The Certified Vulnerability Assessor exam is taken online through Mile2’s Assessment and Certification System (“MACS”), which is accessible on your mile2.account. The exam will take 2 hours and consist of 100 multiple choice questions.