
Download file to get access to PART2
Ken Mayer introduces the CompTIA advanced security practitioner course, sharing decades of security experience with vendors like Cisco, Juniper, Palo Alto Networks, and IBM to inform modern security deployments.
Download files here
Explore the basics of enterprise security, including nomenclature, components, and aligning security with business goals. Learn threat intelligence, prioritization, defense in depth, and governance through policies and procedures.
Define a top-down business strategy to secure information, align security with profitability and business needs, and use risk assessments and policy blueprints to implement integrated security solutions.
Master the CIA triad—confidentiality, integrity, and availability—along with least privilege, authentication and authorization, dual control, and separation of duties, illustrated through Active Directory and backups.
Protect data across the storage area network, cloud, web server, and databases using encryption and integrity checks, while enforcing secure access and physical barriers to guard internal and customer data.
Protect networks with a defense-in-depth approach that combines firewalls, intrusion detection and prevention systems, and host-based controls to guard external and internal threats, including BYOD risks.
Programmers design and maintain applications that users interact with, focusing on web programming, languages, algorithms, sql database interactions, security planning, testing, deployment, and ongoing support.
stakeholders, including board members, investors, employees, customers, and suppliers, expect audits and security policy adherence to ensure the company runs smoothly and protects stakeholder interests.
Human resources plays a key role in hiring, background checks, and enforcing acceptable use policies to protect security. They facilitate security training, including awareness of social engineering, and manage terminations.
Learn how to safeguard personal identifying information, including PINs, social security numbers, and phone numbers, during transmission and storage, while managing internal and external access.
Explore how vlan integration reduces broadcast storms, creates dedicated broadcast domains, and strengthens security through private vlans, dmz configurations, and protected management ports.
Explore how network intrusion prevention systems inspect traffic at the switch, block malware, and balance security with slower throughput, as IPX devices offer higher speeds at greater cost.
Explore the esb process: a consumer sends a request to a bus that translates to a logical service address, delivering and monitoring messages to the correct endpoint.
Explore how a database activity monitor enforces access policies, tracks user, administrator, and third-party activities, and uses views and stored procedures to safeguard data integrity.
Explore unified communications components like web-based and video conferencing, desktop sharing, presence information, remote assistance, and email integration, including smartphones enabling push-button video conferences over 4G.
implement training on external communications security, including social engineering awareness and vpn policy controls, audit connections and failures, and terminate vpn at the firewall to decrypt and inspect traffic.
Explore enterprise cryptography and the CIA triad: confidentiality with encryption, integrity with hashing, and availability (or authentication), plus non repudiation via digital signatures proving who sent a message.
Explore where to encrypt in the enterprise, balancing security with resources, and plan host-to-host, site-to-site, and edge-router to edge-firewall encryption across multiple locations.
Explore how pseudo random number generation strengthens security by using a random seed to produce session ids that are hard to guess, protecting user sessions in online shopping.
Explore how encryption uses confusion to hide patterns and diffusion to spread changes, illustrated by DES chaining where each block's key derives from the previous encryption.
Explore advanced authentication within the enterprise, covering multi-location networks and systems outside Active Directory, and learn frameworks to securely exchange credentials without piling up logins.
Review lesson 02 in the CompTIA Advanced Security Practitioner (Part 1 of 2) course to recap the covered content and reinforce learning.
Treat nas as a networked file server; encrypt data on drives and backups, monitor traffic for attacks, and enforce enterprise access control to prevent unauthorized data and personal use.
Implement strict access control for data warehousing with read-only data access where needed. Evaluate third-party use with NDAs and comply with jurisdictional laws to prevent lawsuits and protect security.
Archive older information by moving it to a separate storage location to reduce breach risk and comply with retention laws, such as seven years for emails.
Focuses on CIA triad in data archiving: encrypt for confidentiality, ensure integrity, and maintain availability across multiple secure locations, with compliance and physical security as baselines.
Explore how iSCSI enables storage area networks to transport storage commands over IP and Ethernet, comparing it with fiber channel while detailing initiators, targets, LUNs, IQNs, and authentication.
Explore the security implications of vSAN, including vm escaping and how unauthorized access to an operating system can expose data stored on the storage area network.
Discover how a storage area network uses logical unit numbers to present virtual machines with individual disks via iSCSI or fibre channel, and how to hide LUN traffic.
Explore redundancy in storage area networks using RAID arrays with mirroring, striping, and parity; learn monitoring alerts and instant recovery after drive failures.
Apply secure storage guidelines to protect confidentiality, integrity, and availability, including multipath access, regular snapshots, deduplication, dynamic disk pools, LUN masking, offsite replication, and encryption at rest and in transit.
Virtualization reduces hardware, maintenance, and costs while boosting resource utilization. It simplifies infrastructure and enables live migration of running virtual machines with no downtime.
Isolate traffic between groups of machines with VLANs on the virtual switch. Route inter-host traffic through an external physical switch to connect VMs, enabling segmentation and security.
Explore virtualization vulnerabilities across host and guest systems, including malware in VMs, hypervisor attacks, VM escape, compromised virtual switches, and privilege escalation risks.
Explore cloud computing by comparing private and public clouds, and learn how enterprises consolidate services, servers, processes, and applications for internal groups or external customers.
Explore security designs and solutions from the network perspective, covering network security design and security assessment, then extend to host and endpoint security.
Explore how copper, radio, and fiber carry ones and zeros across layer 1, then encapsulate them at layer 2 with Ethernet frames and MAC addresses for LANs and WANs.
Explore physical security measures that restrict facility access, from turnstiles and magnetic cards to access controls, and discuss ensuring reliability of critical infrastructure with backup power and data centers.
Discover how a network intrusion detection system monitors activity for anomalies and vulnerabilities, includes antivirus components, mirrors traffic for analysis, and issues alerts alongside routers, firewalls, and a DMZ.
Security information and event management (siem) provides real-time analysis by correlating logs from firewalls, routers, servers, and programs to detect anomalies and speed incident response.
Explore virtual networking and security components by designing virtual LANs to separate voice over IP and data traffic using switches, routers, and guest access controls, improving performance and manageability.
Explore device placement beyond external firewalls, securing perimeters within local area network, private cloud environments, and storage area network to control traffic and protect physical access to servers from malware.
Identify and evaluate network security components and devices, including centralized network attached encryption like HSM, traffic segmentation via virtualization, and monitoring solutions to defend and optimize performance against attacks.
Explore environmental threats such as fire, hurricanes, floods, and extreme temperatures, and how offsite backups and temperature and moisture management keep data centers resilient.
Explore how sensors support physical security, from fire and smoke detection to motion sensors and intrusion concerns, and how device placement protects networks and communications from theft and disruption.
Explore SCADA networks that control critical energy and resource infrastructures, and learn how hardening communications, data collection, and access prevents cyber attacks on utilities.
Analyze network-attached devices beyond traditional computers to manage risks, protect data, and ensure bandwidth and latency support for cameras, printers, and other endpoints in your network.
Cloud-managed networks let you administer your entire network from anywhere with the right credentials using cloud services such as infrastructure as a service and software as a service.
Learn how network access control enforces health policies on devices connecting to switches, checking antivirus status and last scan, and approving or denying access to servers.
Identify critical infrastructure beyond networks, including facilities, people, power backups, water, food production, health services, transportation, communications, and security, and plan policies to sustain operations during outages.
Malware sandboxing uses isolated virtual environments and network-based sandbox servers to safely analyze files, determine harmful behavior, and generate virus signatures to guide firewall decisions.
Learn how memory dumping exposes addresses and contents in memory as programs run, enabling you to spot memory usage changes, potential memory leaks, and possible buffer overflows.
Perform vulnerability assessments to identify security weaknesses across hardware, software, and networks, and use baseline analyzers, configuration wizards, and code reviews to harden systems and prevent sequel injection.
Explore authorized penetration testing from black box, white box, and gray box perspectives, where testers simulate breaches to uncover weaknesses before attackers.
Learn how protocol analyzers capture network traffic with Wireshark to monitor a network interface, spot unusual communications and ports, and identify possible spyware or trojan activity.
Explore fuzzing techniques that send miscellaneous data to provoke errors and reveal buffer overflow risks, and learn how automated scripts can act as beta testers to uncover vulnerabilities.
This lecture highlights implementing a code review method with alpha and beta testing, fuzzing, and tester feedback to verify functionality and enforce server-side validation against broken inputs.
Apply host-based security controls, firewalls, and intrusion detection; harden the host with operating system security and anti-malware, and monitor inbound and outbound communications with packet capture.
Explore how host-based firewalls run on the host and use inbound and outbound rules to block malware like remote access trojans that try to phone home.
Explore Windows advanced firewall rules that explicitly allow inbound traffic and block others, and apply app-based outbound rules to permit browser traffic while blocking botnet control traffic.
Describe a trusted operating system using ring 0 to ring 3, with kernel protection, ring 1 services, ring 2 drivers and user interface, governed by explicit interaction rules.
Operating systems have unique vulnerabilities across Windows 7, Windows 8, and Apple; keep up to date with patches to curb exploits. Research new vulnerabilities to stay secure.
Explore virtual machine vulnerabilities, including vm escape that can compromise the hypervisor, host, or other vms. Understand privilege elevation and vm migration risks, and data remnants on storage during migration.
Use IMA, a TPM method and open source Linux-based solution, to measure files before load; hash measurements and compare with TPM hashes; detected tampering blocks loading or execution.
explores security design across network infrastructure and external communications, reviews assessment tools like vulnerability scanners and packet analyzers, and examines host based security on endpoints to strengthen the network.
Learn to classify risks by base type and source, analyzing how interrelated delays, cost, and quality affect project plans, and differentiate knowns, known unknowns, and unknown unknowns to build buffers.
Examine the cloud model alongside outsourcing, noting automation, contract terms, and how well cloud providers protect your information, including connections to the cloud and auditing considerations.
Assess how to integrate diverse industries by reconciling conflicting policies and laws through risk assessment, considering regulations, baseline security, liability, and international differences in transportation and politics.
De-perimeterization reshapes network boundaries as cloud and outsourcing expand access beyond traditional perimeters. Protect connections beyond firewalls and IPs, accounting for BYOB and remote work.
Classify information by CIA levels to balance confidentiality (encryption), integrity, and availability. Increasing confidentiality and integrity can reduce availability and hinder access when needed.
Identify risk response techniques, including avoidance, insurance transfer, mitigation with controls such as firewalls, and acceptance based on return on investment, to reduce risk exposure.
Engage in continuous monitoring to assess control effectiveness and lower risk across the security lifecycle. Acknowledge devices require updates and patches, making monitoring a recurring process.
Craft a risk management plan that documents your approach to identifying, assessing, mitigating risks, with methodology, tools, budgeting, scheduling, risk categories, and examples like employee theft and park ride injuries.
Organize your project's risk management teams, plan meetings, and craft a risk management plan that includes budget, policy compliance, data sources, and documentation of risk responses.
Identify early warning signs of risk arising from external factors like legislation changes, staff turnover, governance or funding shifts, and strikes that may delay projects.
Master documentation reviews as structured examinations of project plans to improve quality, align with requirements, and identify risks via checklist analysis and assumption analysis.
Analyze risks using qualitative and quantitative methods, assess probability and impact, apply risk matrices and rankings, and review data collection, representation, and basic probability distributions.
Apply Monte Carlo analysis to estimate the most likely outcomes and consequences of project plans. Use this technique to handle large input data and assess risk in complex project management.
Define the business continuity plan as the framework for restoring operations during crises, including servers and data backups, testing solutions, and recovery timelines, methods, procedures, and alternate recovery resource facilities.
Develop and test disaster recovery plans that outline actions before, during, and after disasters, such as earthquakes or floods, to minimize business disruption and achieve a speedy recovery.
Identify and manage the contingency reserve by setting aside a predetermined amount of time, money, or resources in advance to address accepted known risks if they materialize.
Coordinate risk-related contract decisions to plan and transfer or share risk with third parties, assess the risks of third parties failing, and mitigate opportunities or threats to the organization.
Develop a risk response plan by examining each risk, determining causes, choosing effective strategies, and detailing actions and backups, then integrate into project plan and examine trends in analysis results.
Develop a risk management plan by identifying business needs and potential risks, analyze likelihood and causes, and implement controls to mitigate or transfer risk, culminating in a risk response plan.
Explore advanced authentication and authorization techniques using new technologies and how to implement them in your network, with identity management guiding who is allowed access.
Identify how username and password prompts reveal your identity and how this information is sent to a service to verify your identity via authentication.
Explain how the OAuth process authenticates access: the app requests service, end user provides credentials, service provider validates the token, and a token is issued by a trusted third party.
Explore how Active Directory organizes domains, containers, and organizational units, and view how selecting a container reveals the directory services database and the objects it tracks.
Discover how Kerberos, developed by MIT engineers as a single sign-on method and used by Microsoft, uses a domain controller to issue a ticket proving your identity for printing.
Implement advanced identity management by exploring identity propagation and federations. Understand how federations enable centralized management of who you are and review options.
Explore steganography by concealing data in images using the least significant bits of pixels, encoding 8-bit letters across multiple pixels while keeping the picture visually unchanged.
Explore pseudorandom number generation as part of entropy, using salt and nonce to add random output to messages and better conceal data before encryption or hashing.
Explore secure shell (SSH) as it parallels SSL, enabling authenticated connections through certificate exchange, asymmetric keys, and encrypted SSH tunnels for command-line sessions on routers and hosts.
Define goals for cryptographic implementations by weighing copyrights, digital rights, DRM, and trade secrets. Consider protections like watermarking and SSL/TLS for email and attachments.
Explore cryptographic techniques by comparing symmetric, asymmetric, stream, and block ciphers, and examine encryption protocols, email authentication, SSL sessions, and digital rights management with watermarking.
Explore how to implement security standards in the enterprise, define what standards are, examine categories of interoperability issues, cover data flow security, and review related security standard issues.
Explore how standards guide security and interoperability in enterprise settings, and how competing wireless standards and unregulated esm bands influence technology choices.
Demonstrate data flow security using a mesh network of edge routers, showing how traffic shifts with servers and bottlenecks, and how traffic shaping and virtual circuits optimize performance and availability.
Examine deployment models by locating where systems are hosted and how data is secured in storage and transmission, then compare insourcing, outsourcing, and managed services for optimal security.
Explain data isolation through least privilege and role-based access to separate data by user. Clarify read versus write permissions and administrator controls, with cloud Chinese walls to prevent data mixing.
Manage resource provisioning and de-provisioning by assigning group-based user access, handling terminations and promotions, and testing cloud versus on-premises firewall migrations during a maintenance window.
Explore how virtual machines share hardware through a hypervisor, the risks of vm escaping, and how isolation and firewall appliances protect traffic between virtual and real networks.
Design the enterprise infrastructure to meet evolving business needs and anticipate threats and vulnerabilities. Securely connect storage, protocols, and storage area networks with logical and physical diagrams.
Service oriented architecture enables interoperable services to design and develop applications. It encapsulates commands as data requests sent between applications for coordinating ordering, shipping, and supplier interactions.
Learn how domain name systems translate fully qualified domain names to IP addresses, traverse root and authoritative servers, and use digital signatures and certificates to prevent DNS cache poisoning.
Learn to integrate hosted storage, networks, and applications into enterprise architecture by applying security standards, exploring physical and logical deployment models, and securing infrastructure design for special applications and databases.
Explore emerging business tools, including social media and mobile devices, and learn to balance advertising potential with security concerns like encryption, device viruses, and trade secret protection.
Analyze how mobile devices such as iPad, Android smartphones, and Windows Phone serve as emerging business tools for managing information and communications, and outline research and security considerations for networks.
Explore how cloud computing and virtualization consolidate servers and cut costs, shifting maintenance to providers; encryption evolves from des to sha-1 amid social media and smart devices bridging networks.
Explore the global impact analysis industry, uncovering security conferences, trends in threats, hackers and groups, and how infosec information from events and sites informs proactive defense.
Perform an industry trends impact analysis by staying current with vendors and research, assessing threats and technologies to inform contract security requirements and the security plan.
Prototyping and testing model enterprise security by validating hardware and software tools, policies, and processes. Prototype in an enterprise sandbox to prevent production disruption, using virtualization to resemble production networks.
Practice reverse engineering by breaking down a running program into source or assembler to analyze steps, inspect variables for buffer overflows, and assess input handling against injection commands.
CompTIA Advanced Security Practitioner (CAS-002) is the course that teaches the students about securing complex enterprise environments. In this course, the students will expand their knowledge of IT security and learn about the more advanced tools and techniques to keep any organization safe and secure.
The CompTIA Advanced Security Practitioner (CAS-002) course will enable the students to meet the growing demands of today’s IT environment. The course helps the students to develop their skills and perform their jobs as advanced security professionals in their organizations. The course is designed for IT security professionals who want to acquire the technical knowledge and skills needed to conceptualize, engineer, integrate, and implement secure solutions across complex enterprise environments.