
Join the CompTIA advanced security practitioner course as instructor Troy McMillan introduces the CASP program, notes his CISSP credential, and previews topics for the CASP 002 exam.
Explore how business operations influence IT risk by examining the processes that introduce risk to IT departments. Identify the risks associated with business processes and how they affect IT departments.
Explore how business model changes, partnerships, outsourcing, and cloud computing create security vulnerabilities, and plan mergers or divestitures with roles, gaps and overlaps, and risk of moving data between networks.
Examine how to integrate companies from diverse industries by evaluating differing regulations, policies, geography, and cultural factors to identify potential risks and compliance requirements.
Ensure third-party providers apply information security to your data and manage downstream liability in contracts. Include due diligence and due care, specify encryption, and plan audits or interconnection security agreements.
Assess internal and external influences on security programs, including competitors, auditors, regulators, and client requirements, and secure management buy-in while using onsite assessments and policy reviews to ensure regulatory compliance.
Explore how de-perimeterisation challenges the traditional edge-based security model, where edge routers and firewalls form a fortress, by embracing cloud storage, public cloud, telecommuting, BYOD, and outsourcing.
Explore risk mitigation planning by understanding how to manage risk through policies and procedures, recognizing that while risk cannot be eliminated, it can be controlled.
Explore risk mitigation, planning, and controls within a security program. The CIA triad, confidentiality, integrity, and availability, guides prioritizing high-risk issues and applying encryption to protect data.
Classify organizational data into public, sensitive, private, and confidential to determine appropriate access controls, contrasting discretionary access control with mandatory access control used in military and government contexts.
Explore the information life cycle from creation to destruction, including classification, data protection levels, retention timing, and stakeholder input shaping controls for confidentiality, integrity, and availability.
Implementing technical controls uses compensative, corrective, detective, deterrent, directive, preventative, and recovery methods across logical, administrative, and physical layers, with a security requirements traceability matrix to map assets to tests.
Calculate the aggregate CIA score by evaluating confidentiality, integrity, and availability for an entity, such as a partner site, and assessing the related risk levels.
Analyze worst-case scenarios by mapping threats and actors, ranking them by skill, and identifying assets, vulnerabilities, and cost-effective countermeasures through qualitative and quantitative risk analysis.
Apply single loss expectancy and annual loss expectancy to quantify risk and guide cost-benefit mitigation, while examining attacker motivations such as theft, damage, embarrassment, and gaining technical advantage.
explain how return on investment measures improvements against costs, highlighting payback and net present value, with examples like productivity loss, data loss, and hardware repair costs.
Assess the total cost of ownership of risk management, using industry benchmarks and software to budget and reduce risk, choosing avoid, transfer, mitigate, or accept strategies with insurance brokers.
Identify assets and value, threats, vulnerabilities, likelihood, and impact to assess risk and determine mitigation spending, while evaluating asset cost factors such as value, maintenance, consequences, market value, and penalties.
Identify common vulnerabilities and threats, including human threats from insiders and outsiders, natural hazards, technical and physical threats, environmental and operational risks, and understand inherent and residual risk after countermeasures.
Explore Sabsa's six-layer framework and the four-domain control objectives for information and related technology, plus nist sp 853's three-class control model.
Learn how senior management and cross-department teams drive a contingency policy, conduct a business impact analysis, develop recovery strategies, and continuously test, train, and maintain the business continuity plan.
Senior management defines the security program scope, asset protection levels, information classification, data lifecycle, and non-compliance consequences, and establishes policies, standards, baselines, guidelines, and procedures within IT governance.
Develop strategic policies that define goals, span organization, systems, and issues, define roles and responsibilities, establish a security framework with management approval, and classify standards, baselines, guidelines, and procedures.
Explore how a security policy ensures consistent network security, and examine what makes up a policy and how it differs from standards, procedures, and guidelines.
Explore security policies within the general policy framework, focusing on sections that relate to security and related privacy policies and procedures to protect personally identifiable information.
Explore how new business models, mergers, and cloud technologies alter security needs, driving a policy process. Apply ISO/IEC 27000 standards, such as 27,001–27,005, to establish an information security management system.
Developing processes and procedures requires reviewing management, configuration, network access, wireless, and database administration procedures whenever environmental or business changes affect security, and ensuring procedures are guided by established policies.
Collaborate with HR, legal, and external partners to understand and implement industry-specific compliance, including Sarbanes-Oxley, HIPAA, Gramm-Leach-Bliley, and related acts.
Examine key privacy and security laws and standards, including the federal privacy act, FISMA, PCI DSS, Basel II, and the Patriot Act, governing publicly identifiable information.
Identify assets, vulnerabilities, and threats through a risk assessment; justify controls via a statement of applicability, and use cost-benefit analysis and business impact analysis to prioritize recovery of critical processes.
Define outage metrics such as maximum tolerable downtime, mean time to repair, mean time between failures, recovery time objective, and recovery point objective, plus service level and non-disclosure agreements.
Protect personally identifiable information (PII) across jurisdictions by applying internal security policies such as separation of duties, job rotation, mandatory vacations, and least privilege to protect against identity theft.
Implement a formal incident response process to detect, report, recover, remediate, and review security incidents, preserving evidence and guiding communication across the organization.
Learn computer forensics through a structured process of identification, preservation, collection, examination, and presentation, including risk assessment and securing volatile evidence and seized systems.
Establish employment and termination procedures within the security policy, including pre-offer screenings, signing acceptable use documents, ending access on termination, and delivering awareness and security training.
Balance auditing to protect network performance and storage while using a baseline to identify abnormal traffic and clipping levels that record repeated user errors.
Explore the incident response process and learn how to properly handle security incidents in your network.
Master e-discovery for incident response, securing electronic evidence within 90 days, maintaining asset inventories, and enforcing data retention policies and device controls to protect sensitive information.
Outline data recovery and backup policy guidelines, including backup frequency, data scope, and storage methods; explain full, incremental, and differential backups, archive bit behavior, restores, and media rotation strategies.
Identify data owner and custodian roles, set classification levels, apply access controls, and track access to media while inventorying backups to prevent loss.
Explore disposal terms and concepts for secure data destruction. Compare data purging with data clearing, note data remanence, and recognize legal holds during archival obligations and data forensics.
Detect, respond to, report, recover, remediate, remove traces of a data breach, using data analytics by forensic investigators or big data analytics experts to reconstruct and document the incident.
Mitigate and isolate affected systems to minimize damage, then recover with backups within defined time parameters. Review incidents to capture lessons learned and implement preventative actions; maintain chain of custody.
Ensure chain of custody to keep evidence admissible, with labeled containers and documented handlers, ensuring authenticity, accuracy, completeness, and admissibility across surveillance, search, and seizure.
Preserve the disk image as evidence and perform slack space, content, steganography, and software analysis to identify data types, encryption, authorship, and risk, then trace network communications and logs.
Understand the order of volatility for digital evidence, starting with memory contents and swap files, then routing tables, ARP cache, kernel statistics, and on-disk data.
Develop a process to stay current with industry trends and continuously update security skills. Strengthen network defenses against evolving threats.
Perform ongoing industry research to stay current on best security practices, new technologies, evolving security systems and services, and evolutions in technology, ensuring your policy adapts to trends.
Harden devices by disabling default accounts and passwords, updating software and firmware, applying firewalls, disabling remote logins, weighing encryption against performance where needed, and scheduling regular auditing.
Stay current with the evolution of technology by reviewing RFCs, including IPv6 (RFC 2460) and DHCPv6 (RFC 3355), and RFCs for SMTP (RFC 2821) and Radius deployment (RFC 2866).
Maintain situational awareness by keeping all client devices updated and performing vulnerability assessments—including personnel, physical, and system testing—along with awareness of advanced persistent threats and zero-day attacks.
Assess security implications of social media and cloud storage, implement layered defenses, and require security awareness training with an explicit acceptable use policy.
Explore global and industry security organizations, including CERT and US-CERT, and key conferences like RSA, Black Hat, and Defcon, to understand threat response and vulnerabilities.
Identify threat actors from organized crime to state-sponsored hackers, terrorists, and hacktivists, and describe crackers and white hat, black hat, and gray hat roles affecting critical infrastructure.
Detail policies, practices, and procedures in contracts, specify training, certification, background investigations, security reviews of devices, physical security, and applicable laws for third-party personnel and devices.
Outline contract documents, including the request for proposal, request for quote, and request for information, and how they solicit bids, prices, and essential details to prepare a contract.
Explore module six's specific steps to secure the enterprise and detail what should be done to ensure network security.
Explore benchmarks and baselines to measure enterprise security and performance, comparing benchmarks to reference baselines, and monitor from a separate system across times of day and days of the week.
Prototype and test solutions in a lab with virtualization to simulate live environment before production. Perform a full backup first and implement changes during low-traffic periods on low-priority network segments.
Perform a cost-benefit analysis of any security solution before deployment to avoid unprofitable tools. Understand return on investment and total cost of operations, including purchasing and operating the solution.
Develop metrics to reveal short- and long-term security trends, including password attacks, using graphing tools. Define who collects metrics, what to collect, when, and thresholds for corrective action.
Reverse engineer security controls to assess usefulness and gaps, then think like a hacker to probe devices, revealing weaknesses in firewalls and intrusion detection systems.
Learn to conduct a lessons learned or after action report after an incident, documenting facts chronologically from occurrence to evidence collection, and weigh each security solution to prevent recurrence.
Learn assessment tools and methods to measure your network's vulnerabilities and close the insecurities, gaining insight into exactly how insecure your network is.
Explore port scanners and vulnerability scanners to identify open ports and security gaps on devices, using Nmap/Zenmap and Nessus to surface high, medium, and low risks, including default credentials.
Demonstrate protocol analyzers like Wireshark capturing and inspecting unencrypted packets, network enumerators mapping devices and credentials, and password crackers like Cain and Abel performing brute-force attacks.
Fuzzers identify application weaknesses by introducing faults with peach's string mutator to reveal crashes, while Http interceptors monitor web traffic and performance timelines for server testing.
Explore exploitation tools and frameworks like Metasploit, Canvas, and Impact to test applications and devices for security holes by selecting exploits and payloads and simulating attacks such as buffer overflow.
Identify passive reconnaissance tools such as social media, whois, and routing tables, plus cdp and lldp disclosures, and learn how rogue routers and untrusted routing updates threaten networks, with chap.
Assess vulnerability goals, including valuing information, identifying threats, and deploying malware strategies, while exploring malware sandboxing with Cuckoo and Elastic Sandbox to analyze zero-day behaviors.
Explore memory dumping techniques with mem dump, k tools, and fat kit, and master penetration testing steps, including black, gray, and white box approaches and retina-based vulnerability assessment.
Explore reconnaissance and fingerprinting as information gathering stages for hackers, detailing ping sweeps, port scans, and active versus passive tools to identify live hosts, services and applications, and open ports.
Perform a code review to identify security and performance issues in in-house software, using formal line-by-line investigations alongside lightweight, pair programming, email, over-the-shoulder, and tool-assisted methods.
Explore how social engineering exploits human skills to steal information, including phishing and farming, along with shoulder surfing, identity theft, and dumpster diving.
Explore basic cryptography concepts and learn techniques to protect data in your network as part of module eight of the CASP exam.
Explore cryptographic concepts and techniques, including encryption benefits and transparency. Learn about key stretching to 128-bit keys and hashing for data integrity across storage and transmission.
Compare hashing algorithms across rounds, hash sizes, and performance, from md2, md4, md5 to the sha-2 and sha-3 families, and learn code signing uses cryptographic hashes to verify code integrity.
Explore message authentication codes to ensure data integrity and authenticity, including hash keyed MAC with a symmetric key, CBC-MAC, and cipher-based MAC using a stronger mathematical function.
Explore pseudo random number generators, perfect forward secrecy, and transport encryption, then distinguish entropy, diffusion, and confusion, and define non-repudiation, confidentiality, and integrity.
Explore transport encryption protocols including ssl and tls, their encryption and authentication features, ipsec’s ah, esp, and sa components that establish secure channels for online card transactions, including 3d secure.
Explore symmetric encryption for data at rest with secret keys, covering DES, Triple DES, and AES (Rijndael), plus lesser-known options like IDEA, Skipjack, Blowfish, Twofish, RC, and CAST.
Explore asymmetric algorithms, including public-private key pairs, key exchange with Diffie-Hellman, encryption, decryption, and digital signatures, with examples like RSA, ElGamal, and elliptic curve cryptosystems.
Discover how hybrid encryption uses fast symmetric keys with asymmetric key exchange to secure messages and digital signatures for authenticity and integrity.
Map public key infrastructure using X.509 certificates, root, subordinate, and issuing CAs to form a chain of trust, and cover wildcard certificates, CRLs, and online certificate status protocol.
Explore the five classes of digital certificates and the differences between string-based and block ciphers, including keystream generation and xoring.
Explore des modes including ecb, cbc, cfb, ofb, ctr, and triple des, detailing 64-bit blocks, iv usage, and keystream generation differences.
Explore cryptographic attacks from ciphertext-only and known plaintext to brute force and side channel methods, including linear, differential, frequency, algebraic, dictionary, and replay strategies.
Assess cryptographic strength and performance by key size; symmetric algorithms remain faster than asymmetric ones and support hybrid systems, alongside digital rights management, watermarking, GPG, SSL, SSH, and secure mime.
Protect data in transit and at rest. Explore enterprise storage types and their security implications.
Explore enterprise storage with virtual storage and san arrays, analyze security implications, manage overhead and snapshots, and assess visibility challenges of the guest operating system and network traffic.
Explore cloud storage types—private, public, hybrid, and community—and service models from IaaS to PaaS to SaaS, highlighting security considerations and access control across cloud environments.
Combine data from multiple sources into a data warehouse to enable analytics, then secure data at extraction, at rest in staging, in transit, and from warehouse to data mart.
Explore data archiving, moving old data to tiered long-term storage (tier one production, tier two disaster recovery, tape retention) while noting risks like weak access controls and inadequate tape protection.
Explore storage area networks (SANs) and VSANs, detailing high capacity storage devices connected by a high-speed private network using Fibre Channel, and the advantages and disadvantages of SANs.
Explore network-attached storage, an IP-based system using NFS, CFS, or HTTP, with advantages like easy access and RAID, and risks like spoofing, sniffing, and complex access controls.
Compare iSCSI and fibre channel over ethernet as storage protocols, detailing SCSI commands carried over IP and ethernet encapsulation, and apply security measures like VLAN separation, ACL, authentication, and encryption.
Explore storage area network file systems by comparing NFS and CIFS/SMB, assess security gaps in older versions, and recommend using NFS version 4 with Kerberos for secure access.
Explore storage deployment with multipathing for fault-tolerant primary and secondary paths, plus round-robin performance. Snapshots enable point-in-time data recovery, and deduplication with dynamic disk pools optimize space and resilience.
Learn how lun masking hides luns from users by controlling access at the host adapter or storage controller level, and how hba allocation and zoning confine ports to security zones.
Explore data replication methods: asynchronous, synchronous, and point-in-time, for backups across multi-site storage, and examine disk, block, and file level encryption with symmetric and public-key techniques.
CompTIA's CASP - CompTIA Advanced Security Practitioner , is a vendor-neutral certification that validates IT professionals with advanced-level security skills and knowledge. This certification course covers the technical knowledge and skills required to conceptualize, design, and engineer secure solutions across complex enterprise environments. It involves applying critical thinking and judgment across a broad spectrum of security disciplines to propose and implement solutions that map to enterprise drivers, while managing risk.
There is no required prerequisite for this course however, the CASP certification is intended to follow CompTIA Security+ or equivalent experience and has a technical, hands-on focus at the enterprise level.
This CASP training course follows the CompTIA authorized objectives, ensuring you receive the training and knowledge needed to succeed.