
Explore design systems that facilitate incident response and outline actions to take during security incidents and emergency response, including recovery.
Design systems to streamline incident response by distinguishing internal and external violations, auditing security and network logs, and guiding rapid, structured responses to incidents.
Explore internal versus external violations, including insider abuse of permissions, contractors bypassing nondisclosure agreements, tailgating, and social engineering that yields stolen passwords and network intrusions.
Examine insider threats and enforce least privilege, job rotation, and mandatory vacations to strengthen access control, while aligning privacy, data handling, cybercrime laws, and evidence collection to meet forensic standards.
Monitor audit logs, including the Microsoft Event Viewer security log, to track applications, processes, networking, and firewall activity, and assess access successes and failures for misconfigurations and information leakage.
Design incident response systems by staying aware of internal and external violations, enforcing least privilege, encrypting data, and using a siem to collect logs for proactive defense.
Develop incident and emergency response practices, covering data breach definitions and e-discovery policies. Learn forensic analysis, chain of custody, co-op, and order of volatility to guide response plans.
Define e-discovery as a legal method to identify, collect, and analyze electronic data for investigations, guided by the 2006 US Supreme Court, with retention standards to avoid fines.
Define what to inventory, including emails and possibly web browsing history, and establish data retention policies. Assign data ownership and ensure legal compliance for e-discovery and recovery.
A data breach occurs when someone gains unauthorized access to data, potentially viewing, copying, selling, deleting, or publishing it, causing financial losses, embarrassment, and penalties for perpetrators.
Detect breaches early with robust security controls and collect logs and audit data. Mitigate impact, recover data from backups, and disclose incidents as required.
Maintain a strict chain of custody for electronic evidence from collection to court, documenting storage, transfer, and custodians; use tamper-evident seals and logs to prove no alteration.
Learn how to preserve evidence in forensics by imaging the system, hashing the original and copies, and maintaining a strict chain of custody while documenting witnesses and hours.
Continuity of operations (co-op) improves disaster recovery and business continuity plans by sustaining mission-critical network operations during major disasters, focusing on key personnel, contacts, and immediate response assets.
Prioritize forensic data collection by the order of volatility, starting with memory (RAM). Then gather from network caches, hard drives, and optical media, while noting the impact of mobile storage.
Implement an e-discovery policy to protect against litigation, govern asset control, data retention, and recovery storage, and practice an incident response playbook with evidence chain of custody and forensic procedures.
Explore incident and emergency response designs and systems that enable instant responses, and outline the steps for conducting incident handling and evidence collection.
Explore legal issues, computer crime laws and regulations, and incident response to crime as part of advanced security practitioner topics.
Explore crime laws and regulations, including common and statutory law, offenses, administrative law, information privacy, and computer crime compliance, with liability and internal and external audits.
Explore how common law blends written principles with unwritten justice concepts shaped by court decisions, including how common law marriage arises in states.
Statutory law refers to laws written by the legislature and governor, existing as criminal acts or civil acts, with criminal acts carrying jail or prison and civil acts awarding damages.
Statutory criminal laws involve government prosecutions and guilty verdicts under varying state jury rules, while civil cases seek monetary penalties and reparations with a typical 51% verdict threshold.
Examine administrative law and how government regulatory agencies set minimum security standards across businesses, with violations pursued in administrative law courts and potential criminal penalties, as seen in Enron.
Explore intellectual property forms, including patents, trademarks, copyrights, and trade secrets. See licensing and privacy protections in action with real-world examples like protected formulas and copyrighted works.
Explore information privacy laws, including Privacy Act of 1974, Family Educational Rights and Privacy Act, ECPA, HIPAA, GLBA, COPPA, USA Patriot Act, and SOX, and how they protect personal data.
Explore computer crime law, including the Computer Fraud and Abuse Act and key amendments, to protect government systems and define risk assessments, controls, and continuous monitoring.
Audits verify compliance with evolving laws and regulations, making it a top management priority to avoid fines; security and legal teams must collaborate to protect information and meet legal requirements.
Identify liability as legal responsibility for damage and reduce it. Follow the prudent person standard with due diligence, training, and staying current on patches to minimize penalties and reparations.
Conduct internal audits under management to review processes, logs, and transactions for compliance. External auditors provide unbiased oversight to verify compliance and uncover security vulnerabilities.
Explore government oversight resources at federal and state levels, including audits and directives from agencies like the NSA and DCI, to ensure compliance and strengthen security.
Explore the computer crime incident response, covering the evidence lifecycle, collection techniques, surveillance and search and seizure issues, types of evidence, chain of evidence, and basic computer forensics.
Define computer crime as a criminal act that uses a computer as source or target, including hacking and stealing restricted information, with laws evolving since the 1970s.
Build an incident response team trained in proper collection and preservation to determine if incidents occurred and protect evidence through containment, chain of custody, and bit-by-bit forensic copies.
Discover how to identify, protect, and preserve evidence throughout its life cycle, then record, collect, and transport it to secure facilities or court, and finally present and return it.
Learn evidence collection techniques for computer forensics, including bit-by-bit forensic copies, slack space recovery, and analyzing deleted files, with professionals handling specialized procedures to avoid damaging evidence.
Explore evidence types in computer forensics, including best, direct, conclusive, and circumstantial evidence, plus opinion evidence, corroborative evidence, and demonstrative evidence.
Maintain the chain of evidence by securing the first responder at the scene's custody, sealing evidence in an evidential bag, and storing it in a locked facility to prevent tampering.
Identify reliable, relevant evidence with proper identification and a clear chain of custody. Ensure admissibility by lawful collection; avoid illegal eavesdropping or searches that poison the root of the tree.
Explore surveillance techniques such as protocol analyzers to sniff and record network traffic; consider privacy, legal review, and CCTV monitoring on private company property.
Consult legal advisers before collecting evidence on company property, such as a car in a company parking lot, and inform employees about privacy policies and signed-off terms.
Analyze forensic copies of drives to extract information with FTK, and analyze network traffic for evidence. Preserve evidence by evaluating whether to shut down systems with professional guidance.
Explore the legal landscape of computer crime laws and regulations, map incident response practices, and gain a ten thousand foot view of computer forensic investigations.
Develop critical thinking skills to identify the root of the problem and apply sound judgment to make informed decisions.
Develop critical thinking skills by focusing on the argument, examining intellectual autonomy, humility, and objectivity, clarifying and defining arguments, assessing them logically, and applying intellectual honesty to avoid logical fallacies.
Think for yourself and scrutinize others' claims using the Socratic method, then research to verify truth, strengthening critical thought and your believability.
Practice humility by knowing your limits, respecting others' expertise; ask questions, research when unsure, verify findings, and learn from humor-filled teaching moments to sharpen intellectual autonomy.
Develop objectivity by analyzing problems from multiple perspectives, balancing competing interests, and exercising intellectual autonomy to make well informed security decisions.
Focus on the argument by evaluating the message rather than the messenger. Set aside personal bias and consider autonomy, then do the research and pay attention to the words.
Achieve clarity by simplifying ideas and knowing your audience across cultures; minimize slang and jargon to overcome language barriers in instructional settings.
Define your argument with clarity by ensuring meanings are clear and eliminating ambiguity. Avoid miscommunication and foot in mouth errors by choosing precise words and considering others' perspectives.
Develop intellectual honesty by recognizing facts, identifying hidden biases, and applying critical thinking to evaluate tests and stat sheets through your own proof of concept.
Identify common logical fallacies such as post hoc, red herrings, straw man, bandwagon, and slippery slope, and examine how they mislead arguments in security discussions.
Assess arguments logically by identifying loaded words and appeals to sentiment. Avoid emotional manipulation that tries to derail reason and cloud your decision when evaluating sales pitches.
Develop intellectual autonomy and humility; apply critical thinking with objectivity, focus on clarity, and provide accurate and relevant data; examine issues in depth and follow the rules of logic.
Apply root cause analysis by examining obstacles and using Occam's Razor techniques, theme analysis, and the four guidelines technique to determine the root of a problem.
Identify obstacles to analysis, including differing perceptions and hidden agendas that distort the problem statement, disguised solutions, and overgeneralized or overly broad problems that hinder practical solutions.
In this part of the CompTIA advanced security practitioner course, apply Occam's razor to break down complex problems by defining the problem clearly and favoring the simplest explanation.
Apply Occam's razor through analysis and brainstorming to identify main themes, organize ideas under theme headings, re-evaluate lists, and use the four guidelines to filter problems.
Identify the main themes with an Ockham's razor approach, group ideas under themes, and rewrite the list to reveal how it all goes together.
Apply the four guidelines technique to assess feasibility, gather data, and decide whether to solve the problem, embracing the idea that a well-stated problem is half solved.
Identify the root of a problem by applying Ockham's Razor to simplify complexity, ask probing questions, clarify perceptions, and analyze hidden expectations.
Develop judgment to make sound decisions by analyzing problems with analytical and creative thinking, using fishbone diagrams, cost-benefit analysis, decision trees, and the ease and effect matrix.
Analyze problems by defining and analyzing the issue, then gather and interpret data with matrices and charts. Identify multiple cost-effective solutions and compare to choose the best.
Explore the contrast between analytical thinking and creative thinking and learn how each approaches problem solving. Analytical thinking follows logical steps; creative thinking yields out-of-the-box ideas and new solutions.
Identify barriers to creative thinking, such as restricted thinking from past experience, assumptions about what's possible, and reflexive judgments that dismiss ideas or insist on one right answer.
Brainstorming generates new ideas to solve problems, often in group settings or via virtual chats, providing a non-threatening environment to foster many different ideas.
Generate ideas freely and document them without criticism, suspend judgment to encourage participation, and work quickly to produce many ideas, about 100 in 20 minutes.
Organize ideas into themes using a structured method, apply Ockham's Razor to trim options, reject impractical choices, and note that some ideas spark new ones while identifying instant winners.
Use the fishbone (cause-and-effect) diagram to analyze a defined problem and generate ideas for solutions, organizing issues such as machine, nonstandard software, format incompatibilities, storyboards, and poor training.
Learn how the Pareto chart applies the 80/20 law to identify the few causes that drive most problems, and how histograms aid visual focus on the main issues.
Explore how a histogram, a kind of chart, reveals patterns in data. See test scores from 75 to 85, 10 times, with some results pointing to the solution.
The cost-benefit analysis examines telecommuting two days per week, weighing tangible benefits such as higher productivity, morale, reduced parking, and costs like setup, equipment, and support per employee.
Identify and assess both tangible and intangible costs, evaluate benefits and monetize them, then compare total costs to total benefits to justify investments.
Use a prioritization matrix with weighted scores to compare alternatives, rank options after an opinion survey, and select the best choice—e.g., increasing profits while maintaining customer costs, via multiplication.
Use the trade-off method to compare alternatives by attributes in a table, assess the degree of variation, and weigh profit versus costs and implementation time.
Explore how a decision tree visually maps alternatives and their strengths and weaknesses, guiding investment decisions such as capacity expansion with a systematic evaluation approach.
Evaluate options using the ease and effect matrix to map ease of implementation against impact under limited resources, highlighting easy, moderate, and difficult to implement choices.
Explore the PMI analysis table to weigh pros and cons, using the interesting column to evaluate telecommuting decisions, mentoring possibilities, and potential effects on face time, visibility, and home life.
Define the problem, generate solutions, apply different tools to analyze those solutions, and perform a cost-benefit analysis to make sound decisions.
Lesson 13 review focuses on methods for developing critical thinking, identifying the root of problems, and using that insight to make sound judgments and decisions.
Wrap up your CompTIA advanced security practitioner Part 2 course through course closure, highlighting your engagement and readiness to complete the program.
CompTIA Advanced Security Practitioner (CAS-002) is the course that teaches the students on securing complex enterprise environments. In this course, the students will expand their knowledge of IT security and learn about the more advanced tools and techniques to keep any organization safe and secure.
The CompTIA Advanced Security Practitioner (CAS-002) course will enable the students to meet the growing demands of today’s IT environment. The course helps the students to develop their skills and perform their jobs as advanced security professionals in their organizations. The course is designed for IT security professionals who want to acquire the technical knowledge and skills needed to conceptualize, engineer, integrate, and implement secure solutions across complex enterprise environments.
** This course is in 2 parts. Please purchase Part 1 as well for the complete course.**