Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CompTIA Advanced Security Practitioner (Exam CAS-002) Part 2
Rating: 4.3 out of 5(14 ratings)
274 students

CompTIA Advanced Security Practitioner (Exam CAS-002) Part 2

CompTIA Advanced Security Practitioner (CASP) (Part 2 of 2)
Last updated 9/2018
English
English [Auto],

What you'll learn

  • After successfully completing this course, the students shall be able to:
  • Manage security in an enterprise network
  • Integrate IT with business in an enterprise
  • Conduct research and analysis of the threats to enterprise security
  • Implement cryptographic techniques to secure data
  • Implement security controls and policies for applications, compute and storage
  • Conduct vulnerability assessments
  • Respond effectively to incidents and emergencies
  • Implement advances authentication and authorization techniques

Course content

3 sections81 lectures1h 47m total length
  • Responding to and Recovering from Incidents0:23

    Explore design systems that facilitate incident response and outline actions to take during security incidents and emergency response, including recovery.

  • Topic A: Design Systems to Facilitate Incident Response0:32

    Design systems to streamline incident response by distinguishing internal and external violations, auditing security and network logs, and guiding rapid, structured responses to incidents.

  • Internal and External Violations2:46

    Explore internal versus external violations, including insider abuse of permissions, contractors bypassing nondisclosure agreements, tailgating, and social engineering that yields stolen passwords and network intrusions.

  • Security Violations and System Design5:01

    Examine insider threats and enforce least privilege, job rotation, and mandatory vacations to strengthen access control, while aligning privacy, data handling, cybercrime laws, and evidence collection to meet forensic standards.

  • System, Audit, and Security Logs1:57

    Monitor audit logs, including the Microsoft Event Viewer security log, to track applications, processes, networking, and firewall activity, and assess access successes and failures for misconfigurations and information leakage.

  • Guidelines for Designing Systems to Facilitate Incident Response3:24

    Design incident response systems by staying aware of internal and external violations, enforcing least privilege, encrypting data, and using a siem to collect logs for proactive defense.

  • Topic B: Conduct Incident and Emergency Responses0:36

    Develop incident and emergency response practices, covering data breach definitions and e-discovery policies. Learn forensic analysis, chain of custody, co-op, and order of volatility to guide response plans.

  • E-Discovery1:23

    Define e-discovery as a legal method to identify, collect, and analyze electronic data for investigations, guided by the 2006 US Supreme Court, with retention standards to avoid fines.

  • E-Discovery Policy1:35

    Define what to inventory, including emails and possibly web browsing history, and establish data retention policies. Assign data ownership and ensure legal compliance for e-discovery and recovery.

  • Data Breach1:37

    A data breach occurs when someone gains unauthorized access to data, potentially viewing, copying, selling, deleting, or publishing it, causing financial losses, embarrassment, and penalties for perpetrators.

  • Data Breach Response1:10

    Detect breaches early with robust security controls and collect logs and audit data. Mitigate impact, recover data from backups, and disclose incidents as required.

  • Chain of Custody2:19

    Maintain a strict chain of custody for electronic evidence from collection to court, documenting storage, transfer, and custodians; use tamper-evident seals and logs to prove no alteration.

  • Forensic Analysis of Compromised Systems3:35

    Learn how to preserve evidence in forensics by imaging the system, hashing the original and copies, and maintaining a strict chain of custody while documenting witnesses and hours.

  • COOP - Continuity of Operations3:36

    Continuity of operations (co-op) improves disaster recovery and business continuity plans by sustaining mission-critical network operations during major disasters, focusing on key personnel, contacts, and immediate response assets.

  • Order of Volatility2:18

    Prioritize forensic data collection by the order of volatility, starting with memory (RAM). Then gather from network caches, hard drives, and optical media, while noting the impact of mobile storage.

  • Guidelines for Conducting Incident and Emergency Responses2:21

    Implement an e-discovery policy to protect against litigation, govern asset control, data retention, and recovery storage, and practice an incident response playbook with evidence chain of custody and forensic procedures.

  • Lesson 11 Review0:23

    Explore incident and emergency response designs and systems that enable instant responses, and outline the steps for conducting incident handling and evidence collection.

  • Lesson 11 - Quiz

Requirements

  • The course does not have any formal pre-requisites, however, students are advised to attend a basic and foundation level course regarding basic network technologies such as TCP/IP, routing, and switching.
  • Alternatively, students having one year experience in networking can opt for this course without any preliminary training.

Description

CompTIA Advanced Security Practitioner (CAS-002) is the course that teaches the students on securing complex enterprise environments. In this course, the students will expand their knowledge of IT security and learn about the more advanced tools and techniques to keep any organization safe and secure. 

The CompTIA Advanced Security Practitioner (CAS-002) course will enable the students to meet the growing demands of today’s IT environment. The course helps the students to develop their skills and perform their jobs as advanced security professionals in their organizations. The course is designed for IT security professionals who want to acquire the technical knowledge and skills needed to conceptualize, engineer, integrate, and implement secure solutions across complex enterprise environments.

** This course is in 2 parts. Please purchase Part 1 as well for the complete course.**

Who this course is for:

  • The course is primarily intended for the candidates appearing in the CAS-002: CompTIA Advances Security Practitioner exam.
  • The course will helps the candidates to prepare the exam topics and successfully complete the certification.
  • In addition to this, the IT professionals looking to increase their knowledge of enterprise security can also register.