
Download file to get access to PART2
Ken Mayer introduces the CompTIA advanced security practitioner course, sharing decades of security experience with vendors like Cisco, Juniper, Palo Alto Networks, and IBM to inform modern security deployments.
Download files here
Explore the basics of enterprise security, including nomenclature, components, and aligning security with business goals. Learn threat intelligence, prioritization, defense in depth, and governance through policies and procedures.
Define a top-down business strategy to secure information, align security with profitability and business needs, and use risk assessments and policy blueprints to implement integrated security solutions.
Master the CIA triad—confidentiality, integrity, and availability—along with least privilege, authentication and authorization, dual control, and separation of duties, illustrated through Active Directory and backups.
Protect data across the storage area network, cloud, web server, and databases using encryption and integrity checks, while enforcing secure access and physical barriers to guard internal and customer data.
Protect networks with a defense-in-depth approach that combines firewalls, intrusion detection and prevention systems, and host-based controls to guard external and internal threats, including BYOD risks.
Explore the network administrator role across routers, switches, firewalls, and LAN/WAN infrastructures, emphasizing cross-team collaboration to avoid the silo effect and ensure security and quality of service.
Programmers design and maintain applications that users interact with, focusing on web programming, languages, algorithms, sql database interactions, security planning, testing, deployment, and ongoing support.
stakeholders, including board members, investors, employees, customers, and suppliers, expect audits and security policy adherence to ensure the company runs smoothly and protects stakeholder interests.
Human resources plays a key role in hiring, background checks, and enforcing acceptable use policies to protect security. They facilitate security training, including awareness of social engineering, and manage terminations.
Identify and implement enterprise security requirements, including legal compliance and privacy issues, while safeguarding personal identifying information and aligning with your organization's security standards.
Learn how to safeguard personal identifying information, including PINs, social security numbers, and phone numbers, during transmission and storage, while managing internal and external access.
Explore enterprise security technologies and common network security components, understand criteria for selecting security devices, examine cryptographic tools and techniques, and review advanced authentication options, including communication and collaboration security.
Explore how vlan integration reduces broadcast storms, creates dedicated broadcast domains, and strengthens security through private vlans, dmz configurations, and protected management ports.
Explore how network intrusion prevention systems inspect traffic at the switch, block malware, and balance security with slower throughput, as IPX devices offer higher speeds at greater cost.
Explore the esb process: a consumer sends a request to a bus that translates to a logical service address, delivering and monitoring messages to the correct endpoint.
Explore how a database activity monitor enforces access policies, tracks user, administrator, and third-party activities, and uses views and stored procedures to safeguard data integrity.
Explore unified communications components like web-based and video conferencing, desktop sharing, presence information, remote assistance, and email integration, including smartphones enabling push-button video conferences over 4G.
Explore how traffic shaping and policing control data flow on routers, setting maximum bandwidth and bursts, and how virtual circuits like MPLS enable selective traffic paths for service providers.
implement training on external communications security, including social engineering awareness and vpn policy controls, audit connections and failures, and terminate vpn at the firewall to decrypt and inspect traffic.
Learn enterprise mobile security methods, including enforcing screen locks and strong passwords, protecting data on lost devices, and using remote lock, remote wipe, and GPS tracking to safeguard data.
Explore enterprise cryptography and the CIA triad: confidentiality with encryption, integrity with hashing, and availability (or authentication), plus non repudiation via digital signatures proving who sent a message.
Explore where to encrypt in the enterprise, balancing security with resources, and plan host-to-host, site-to-site, and edge-router to edge-firewall encryption across multiple locations.
Explore how transport encryption secures data with ssl/tls and ip security, including certificates, public/private keys, symmetric keys, and diffie-hellman key exchange.
Explore how pseudo random number generation strengthens security by using a random seed to produce session ids that are hard to guess, protecting user sessions in online shopping.
Explore how IP security uses IKE to establish a site-to-site VPN between two firewalls, with phase 1 authentication, Diffie-Hellman exchange, phase 2 encryption, and perfect forward secrecy.
Explore how encryption uses confusion to hide patterns and diffusion to spread changes, illustrated by DES chaining where each block's key derives from the previous encryption.
Explore advanced authentication within the enterprise, covering multi-location networks and systems outside Active Directory, and learn frameworks to securely exchange credentials without piling up logins.
Learn SPML, a service provisioning markup language for exchanging resource provisioning data, enabling provisioning of user accounts, and implementing authentication, authorization, and accounting to control what users can do.
Learn XACML, an extensible access control markup language for policy information, enabling centralized or distributed management via policy enforcement points and policy decision points that define access to resources.
Review lesson 02 in the CompTIA Advanced Security Practitioner (Part 1 of 2) course to recap the covered content and reinforce learning.
Explore enterprise resource technology by examining enterprise storage security issues and distributed shared and virtualized computing, then address cloud computing security concerns.
Treat nas as a networked file server; encrypt data on drives and backups, monitor traffic for attacks, and enforce enterprise access control to prevent unauthorized data and personal use.
Explore how storage area networks are less exposed to IP-based attacks, but internal threats can target virtualized storage via Fiber Channel or iSCSI, mitigated by strict access privileges.
Explore how virtual storage is accessed through a host and virtual switch, risks of VM escaping and unauthorized access, and how data remnants on the host can compromise security.
Implement strict access control for data warehousing with read-only data access where needed. Evaluate third-party use with NDAs and comply with jurisdictional laws to prevent lawsuits and protect security.
Archive older information by moving it to a separate storage location to reduce breach risk and comply with retention laws, such as seven years for emails.
Focuses on CIA triad in data archiving: encrypt for confidentiality, ensure integrity, and maintain availability across multiple secure locations, with compliance and physical security as baselines.
Explore how iSCSI enables storage area networks to transport storage commands over IP and Ethernet, comparing it with fiber channel while detailing initiators, targets, LUNs, IQNs, and authentication.
Explore the security implications of vSAN, including vm escaping and how unauthorized access to an operating system can expose data stored on the storage area network.
Discover how a storage area network uses logical unit numbers to present virtual machines with individual disks via iSCSI or fibre channel, and how to hide LUN traffic.
Explore redundancy in storage area networks using RAID arrays with mirroring, striping, and parity; learn monitoring alerts and instant recovery after drive failures.
Apply secure storage guidelines to protect confidentiality, integrity, and availability, including multipath access, regular snapshots, deduplication, dynamic disk pools, LUN masking, offsite replication, and encryption at rest and in transit.
Virtualization reduces hardware, maintenance, and costs while boosting resource utilization. It simplifies infrastructure and enables live migration of running virtual machines with no downtime.
Isolate traffic between groups of machines with VLANs on the virtual switch. Route inter-host traffic through an external physical switch to connect VMs, enabling segmentation and security.
Explore how a physical server hosts virtual machines via the hypervisor, carving CPU and memory, creating virtual hardware and virtual hard drives, often stored on a storage area network.
Explore terminal services as a virtualization tool and remote desktop service. See a window of the virtual machine while keyboard and mouse input travel over the network to that machine.
Explore virtualization vulnerabilities across host and guest systems, including malware in VMs, hypervisor attacks, VM escape, compromised virtual switches, and privilege escalation risks.
Explore cloud computing by comparing private and public clouds, and learn how enterprises consolidate services, servers, processes, and applications for internal groups or external customers.
Review lesson 03 in the CompTIA Advanced Security Practitioner course, part 1 of 2, highlighting core objectives and recapping key concepts from the session.
Explore security designs and solutions from the network perspective, covering network security design and security assessment, then extend to host and endpoint security.
Explore network security design, covering network design types and techniques, data network types, diagrams, media and transmission technologies, and physical security with storage integration.
Document the network as a diagram that captures the physical topology and records IP addresses, subnets, serial numbers, routing protocols, and quality of service considerations for planning new servers.
Explore how copper, radio, and fiber carry ones and zeros across layer 1, then encapsulate them at layer 2 with Ethernet frames and MAC addresses for LANs and WANs.
Explore physical security measures that restrict facility access, from turnstiles and magnetic cards to access controls, and discuss ensuring reliability of critical infrastructure with backup power and data centers.
Facilities management covers service and maintenance planning, security enforcement, and training everyone to report suspicious activity, illustrated by a bank story about unlocked monitors.
Discover how a network intrusion detection system monitors activity for anomalies and vulnerabilities, includes antivirus components, mirrors traffic for analysis, and issues alerts alongside routers, firewalls, and a DMZ.
Security information and event management (siem) provides real-time analysis by correlating logs from firewalls, routers, servers, and programs to detect anomalies and speed incident response.
Explore virtual networking and security components by designing virtual LANs to separate voice over IP and data traffic using switches, routers, and guest access controls, improving performance and manageability.
Explore device placement beyond external firewalls, securing perimeters within local area network, private cloud environments, and storage area network to control traffic and protect physical access to servers from malware.
Identify and evaluate network security components and devices, including centralized network attached encryption like HSM, traffic segmentation via virtualization, and monitoring solutions to defend and optimize performance against attacks.
Explore environmental threats such as fire, hurricanes, floods, and extreme temperatures, and how offsite backups and temperature and moisture management keep data centers resilient.
Explore how sensors support physical security, from fire and smoke detection to motion sensors and intrusion concerns, and how device placement protects networks and communications from theft and disruption.
Identify how scientific and industrial equipment store data on hard drives, leaving data remnants in devices like plotters or copy machines that thieves could exploit.
Explore SCADA networks that control critical energy and resource infrastructures, and learn how hardening communications, data collection, and access prevents cyber attacks on utilities.
Analyze network-attached devices beyond traditional computers to manage risks, protect data, and ensure bandwidth and latency support for cameras, printers, and other endpoints in your network.
Cloud-managed networks let you administer your entire network from anywhere with the right credentials using cloud services such as infrastructure as a service and software as a service.
Discover how availability relies on a load balancer that presents a single ip, distributes traffic across multiple servers, and redirects users when a server fails.
Learn how network access control enforces health policies on devices connecting to switches, checking antivirus status and last scan, and approving or denying access to servers.
Identify critical infrastructure beyond networks, including facilities, people, power backups, water, food production, health services, transportation, communications, and security, and plan policies to sustain operations during outages.
Malware sandboxing uses isolated virtual environments and network-based sandbox servers to safely analyze files, determine harmful behavior, and generate virus signatures to guide firewall decisions.
Learn how memory dumping exposes addresses and contents in memory as programs run, enabling you to spot memory usage changes, potential memory leaks, and possible buffer overflows.
Perform vulnerability assessments to identify security weaknesses across hardware, software, and networks, and use baseline analyzers, configuration wizards, and code reviews to harden systems and prevent sequel injection.
Explore authorized penetration testing from black box, white box, and gray box perspectives, where testers simulate breaches to uncover weaknesses before attackers.
Learn penetration testing techniques by thinking like a hacker, using black box, gray box, and white box tests; perform fingerprinting, scanning, and enumeration to uncover vulnerabilities and guide securing measures.
Learn how protocol analyzers capture network traffic with Wireshark to monitor a network interface, spot unusual communications and ports, and identify possible spyware or trojan activity.
Explore fuzzing techniques that send miscellaneous data to provoke errors and reveal buffer overflow risks, and learn how automated scripts can act as beta testers to uncover vulnerabilities.
Explore passive reconnaissance and intelligence gathering tools, including using Netcraft to identify a web server, its technology, and hosting details from a URL or IP address.
This lecture highlights implementing a code review method with alpha and beta testing, fuzzing, and tester feedback to verify functionality and enforce server-side validation against broken inputs.
Apply host-based security controls, firewalls, and intrusion detection; harden the host with operating system security and anti-malware, and monitor inbound and outbound communications with packet capture.
Explore how host-based firewalls run on the host and use inbound and outbound rules to block malware like remote access trojans that try to phone home.
Explore Windows advanced firewall rules that explicitly allow inbound traffic and block others, and apply app-based outbound rules to permit browser traffic while blocking botnet control traffic.
Explore how peripherals connect to systems through wired and wireless protocols, including USB, firewire, Bluetooth, and Wi-Fi, and assess related security risks like blue jacking.
Describe a trusted operating system using ring 0 to ring 3, with kernel protection, ring 1 services, ring 2 drivers and user interface, governed by explicit interaction rules.
Explore anti-malware software and its role in protecting your data and financial information by scanning emails, files, and web activity for malware, even as it may slow devices and networks.
Operating systems have unique vulnerabilities across Windows 7, Windows 8, and Apple; keep up to date with patches to curb exploits. Research new vulnerabilities to stay secure.
Explore virtualization: run multiple operating systems on a host via a hypervisor and compare hardware and software virtualization, including Hyper-V, ESX, Solaris containers, and workstation or VM player.
Virtualize Office applications on a remote desktop, delivering Word through streaming on an XP desktop while keeping resources hosted and communications secure.
Explore virtual machine vulnerabilities, including vm escape that can compromise the hypervisor, host, or other vms. Understand privilege elevation and vm migration risks, and data remnants on storage during migration.
Weigh in-house versus rented cloud security services, including private clouds, platform, infrastructure, or software as a service, and third-party risks. Use cloud tools to protect assets and enable collaboration.
Explore how BIOS, the basic input/output system, powers startup decisions, hardware information gathering, clock setting updates, and boot order, while noting its limitations with large drives and memory.
Use IMA, a TPM method and open source Linux-based solution, to measure files before load; hash measurements and compare with TPM hashes; detected tampering blocks loading or execution.
explores security design across network infrastructure and external communications, reviews assessment tools like vulnerability scanners and packet analyzers, and examines host based security on endpoints to strengthen the network.
Identify and understand risk and risk management in projects, then create a plan, analyze risks, determine causes, and develop a proactive risk response plan.
Learn to classify risks by base type and source, analyzing how interrelated delays, cost, and quality affect project plans, and differentiate knowns, known unknowns, and unknown unknowns to build buffers.
Explore risk tolerance as the level of risk acceptable to a project manager or stakeholder, illustrated by car insurance deductibles and the trade-off between deductible amount, cost, and potential profit.
Explore the risk breakdown structure by examining sources of risk across management and technology domains. Analyze how corporate culture, finances, labor markets, and technology resources shape risk at multiple levels.
Examine the cloud model alongside outsourcing, noting automation, contract terms, and how well cloud providers protect your information, including connections to the cloud and auditing considerations.
Examine how mergers and divestitures affect risk assessment and security policies as a company evolves. Explore asset sharing between entities and why frequent risk assessments matter during sales or spin-offs.
Assess how to integrate diverse industries by reconciling conflicting policies and laws through risk assessment, considering regulations, baseline security, liability, and international differences in transportation and politics.
De-perimeterization reshapes network boundaries as cloud and outsourcing expand access beyond traditional perimeters. Protect connections beyond firewalls and IPs, accounting for BYOB and remote work.
Classify information by CIA levels to balance confidentiality (encryption), integrity, and availability. Increasing confidentiality and integrity can reduce availability and hinder access when needed.
Analyze how different attacks affect the CIA triad by evaluating denial of service, database intrusions, and their impact on confidentiality, integrity, and availability through aggregate scoring.
Explore extreme scenario planning to identify worst-case risks like denial of service and data destruction, then design risk controls to protect critical assets.
Identify risk response techniques, including avoidance, insurance transfer, mitigation with controls such as firewalls, and acceptance based on return on investment, to reduce risk exposure.
Engage in continuous monitoring to assess control effectiveness and lower risk across the security lifecycle. Acknowledge devices require updates and patches, making monitoring a recurring process.
Craft a risk management plan that documents your approach to identifying, assessing, mitigating risks, with methodology, tools, budgeting, scheduling, risk categories, and examples like employee theft and park ride injuries.
Organize your project's risk management teams, plan meetings, and craft a risk management plan that includes budget, policy compliance, data sources, and documentation of risk responses.
Develop policies and administrative controls to guide risk management; clarify social engineering concepts and help employees reduce their exposure.
Explore process and procedure development by outlining initiation, concept, and planning to guide the development of a process and procedure, emphasizing adherence to a guideline.
Identify early warning signs of risk arising from external factors like legislation changes, staff turnover, governance or funding shifts, and strikes that may delay projects.
Master documentation reviews as structured examinations of project plans to improve quality, align with requirements, and identify risks via checklist analysis and assumption analysis.
Evaluate probability and impact in risk analysis by applying qualitative and quantitative methods, illustrated with flood plain examples to compare opinion based and numbers based approaches.
Analyze risks using qualitative and quantitative methods, assess probability and impact, apply risk matrices and rankings, and review data collection, representation, and basic probability distributions.
Assess qualitative risk analysis by evaluating probability and impact through expert opinion, multiplying to rank risk exposure, and testing scenarios like weather and attendance against break-even thresholds.
Explore risk probability and impact assessment to evaluate likelihood and potential impact, rank risks, and prioritize mitigation using brainstorming, interviews, and historical data.
Explore how probability distributions link the likelihood and impact of risk events, using a distribution graph to show sample-based probabilities bounded by one.
Apply Monte Carlo analysis to estimate the most likely outcomes and consequences of project plans. Use this technique to handle large input data and assess risk in complex project management.
Identify a negative risk as a threat that could harm the project. A competitor introducing a new and improved product may reduce demand for the existing product and impact revenue.
Explore negative risk strategies, including avoidance, risk transference to a third party, risk mitigation through controls, and risk acceptance when we can afford the consequences.
Identify positive risk as events that yield desirable project outcomes and opportunities, illustrated by how marketing strategies can boost market demand and revenue, even when others outperform you.
Define the business continuity plan as the framework for restoring operations during crises, including servers and data backups, testing solutions, and recovery timelines, methods, procedures, and alternate recovery resource facilities.
Develop and test disaster recovery plans that outline actions before, during, and after disasters, such as earthquakes or floods, to minimize business disruption and achieve a speedy recovery.
Identify and manage the contingency reserve by setting aside a predetermined amount of time, money, or resources in advance to address accepted known risks if they materialize.
Coordinate risk-related contract decisions to plan and transfer or share risk with third parties, assess the risks of third parties failing, and mitigate opportunities or threats to the organization.
Develop a risk response plan by examining each risk, determining causes, choosing effective strategies, and detailing actions and backups, then integrate into project plan and examine trends in analysis results.
Develop a risk management plan by identifying business needs and potential risks, analyze likelihood and causes, and implement controls to mitigate or transfer risk, culminating in a risk response plan.
Explore advanced authentication and authorization techniques using new technologies and how to implement them in your network, with identity management guiding who is allowed access.
Identify how username and password prompts reveal your identity and how this information is sent to a service to verify your identity via authentication.
Explain how the OAuth process authenticates access: the app requests service, end user provides credentials, service provider validates the token, and a token is issued by a trusted third party.
Explore how Active Directory organizes domains, containers, and organizational units, and view how selecting a container reveals the directory services database and the objects it tracks.
Discover how Kerberos, developed by MIT engineers as a single sign-on method and used by Microsoft, uses a domain controller to issue a ticket proving your identity for printing.
Implement advanced identity management by exploring identity propagation and federations. Understand how federations enable centralized management of who you are and review options.
Identity federation hinges on trust across separate companies, allowing a single password to access multiple services. Trusted domains manage identity verification and grant permissions across cloud, gaming, and email apps.
Examine identity federation methods and how cross-domain authentication exchanges information with the original identity service, such as Outlook, to verify a valid user on Xbox Live.
Explore confusion, a simple substitution where each plaintext letter shifts three positions to create ciphertext, highlighting its weak key and easy decipherability.
Explore steganography by concealing data in images using the least significant bits of pixels, encoding 8-bit letters across multiple pixels while keeping the picture visually unchanged.
Explore stream cipher basics: encrypt binary plaintext bit by bit with a key using exclusive or, noting that repeating the key can reveal patterns, and contrast with 64-bit block ciphers.
Explore how hash functions prevent easy collisions by enforcing preimage and second preimage resistance, and how password hashing relies on these properties to keep original data from being revealed.
Explore how key stretching enlarges encryption keys to prevent patterns from revealing the key in stream cyphers, creating an enhanced key distinct from the original.
Explore pseudorandom number generation as part of entropy, using salt and nonce to add random output to messages and better conceal data before encryption or hashing.
Explore secure shell (SSH) as it parallels SSL, enabling authenticated connections through certificate exchange, asymmetric keys, and encrypted SSH tunnels for command-line sessions on routers and hosts.
Explore how PGP and GPG use public and private keys without third-party trust, and how you distribute your public key, build a key ring, and encrypt messages for trusted contacts.
Define goals for cryptographic implementations by weighing copyrights, digital rights, DRM, and trade secrets. Consider protections like watermarking and SSL/TLS for email and attachments.
Explore cryptographic techniques by comparing symmetric, asymmetric, stream, and block ciphers, and examine encryption protocols, email authentication, SSL sessions, and digital rights management with watermarking.
Explore how to implement security standards in the enterprise, define what standards are, examine categories of interoperability issues, cover data flow security, and review related security standard issues.
Explore how standards guide security and interoperability in enterprise settings, and how competing wireless standards and unregulated esm bands influence technology choices.
Demonstrate data flow security using a mesh network of edge routers, showing how traffic shifts with servers and bottlenecks, and how traffic shaping and virtual circuits optimize performance and availability.
Examine deployment models by locating where systems are hosted and how data is secured in storage and transmission, then compare insourcing, outsourcing, and managed services for optimal security.
Explain data isolation through least privilege and role-based access to separate data by user. Clarify read versus write permissions and administrator controls, with cloud Chinese walls to prevent data mixing.
Manage resource provisioning and de-provisioning by assigning group-based user access, handling terminations and promotions, and testing cloud versus on-premises firewall migrations during a maintenance window.
Explore how virtual machines share hardware through a hypervisor, the risks of vm escaping, and how isolation and firewall appliances protect traffic between virtual and real networks.
Explore how network segmentation divides enterprise resources into domains or perimeters, using VLANs to isolate traffic and control inter‑VLAN communication to reduce the risk of unauthorized access.
Design the enterprise infrastructure to meet evolving business needs and anticipate threats and vulnerabilities. Securely connect storage, protocols, and storage area networks with logical and physical diagrams.
Explain governance, risk, and compliance (GRC) as a baseline for enterprise security, detecting deviations, evaluating policies, and aligning operational controls with sensors, DLP, and intrusion prevention.
Service oriented architecture enables interoperable services to design and develop applications. It encapsulates commands as data requests sent between applications for coordinating ordering, shipping, and supplier interactions.
Directory services store user and device identities for network authentication and single sign-on; ensure strong access controls to prevent apps from compromising the directory.
Learn how domain name systems translate fully qualified domain names to IP addresses, traverse root and authoritative servers, and use digital signatures and certificates to prevent DNS cache poisoning.
Learn to integrate hosted storage, networks, and applications into enterprise architecture by applying security standards, exploring physical and logical deployment models, and securing infrastructure design for special applications and databases.
Apply policy based and technology based controls with ongoing risk management, strong password policies, training, encryption in motion or at rest, PKI certificates, VPN or SSL, and continuous monitoring.
Conduct ongoing research to stay current with security vulnerabilities by following threat lists and vendor alerts, reading US-CERT updates, and tracking ISO standards; commit to regular updates.
Explore emerging business tools, including social media and mobile devices, and learn to balance advertising potential with security concerns like encryption, device viruses, and trade secret protection.
Analyze how mobile devices such as iPad, Android smartphones, and Windows Phone serve as emerging business tools for managing information and communications, and outline research and security considerations for networks.
Explore how cloud computing and virtualization consolidate servers and cut costs, shifting maintenance to providers; encryption evolves from des to sha-1 amid social media and smart devices bridging networks.
Explore the global impact analysis industry, uncovering security conferences, trends in threats, hackers and groups, and how infosec information from events and sites informs proactive defense.
Perform an industry trends impact analysis by staying current with vendors and research, assessing threats and technologies to inform contract security requirements and the security plan.
Learn to perform an enterprise security analysis with benchmarking, network traffic analysis, return on investment evaluation, and policy comparison, producing after action reports and lessons learned to improve security.
Prototyping and testing model enterprise security by validating hardware and software tools, policies, and processes. Prototype in an enterprise sandbox to prevent production disruption, using virtualization to resemble production networks.
Compare the expected annualized loss from a threat with mitigation costs to determine if an investment, such as sprinklers, yields a positive return on risk reduction.
Perform an enterprise security analysis to identify gaps and gain insight into enhancing security. Evaluate changes implemented to close those gaps and strengthen security based on the analysis.
Practice reverse engineering by breaking down a running program into source or assembler to analyze steps, inspect variables for buffer overflows, and assess input handling against injection commands.
Apply guidelines for analyzing scenarios to secure the enterprise by benchmarking baselines, testing in a lab or POC, assessing ROI, and validating security controls with vulnerability assessments.
CompTIA Advanced Security Practitioner (CAS-002) is the course that teaches the students about securing complex enterprise environments. In this course, the students will expand their knowledge of IT security and learn about the more advanced tools and techniques to keep any organization safe and secure.
The CompTIA Advanced Security Practitioner (CAS-002) course will enable the students to meet the growing demands of today’s IT environment. The course helps the students to develop their skills and perform their jobs as advanced security professionals in their organizations. The course is designed for IT security professionals who want to acquire the technical knowledge and skills needed to conceptualize, engineer, integrate, and implement secure solutions across complex enterprise environments.