
Meet instructor Patrick Lohner, a 20-year security veteran, sharing expertise in CompTIA CySA+ content, cyber defense, firewall management, multifactor authentication, cloud security (Office 365, Azure), and security training across MSPs.
Learn threat and vulnerability management, threat intelligence, and assessment tools across cloud, virtualization, mobile devices, and network infrastructure, then master incident response, monitoring, change management, and compliance for cs0-002 exam.
Explore threats and vulnerabilities, collect and share threat intelligence, and apply vulnerability management and scanning tools to identify and mitigate security risks.
Explore foundations of threat intelligence and common sources, outline the intelligence cycle from collection to use, explain indicators of compromise, and best practices for sharing within organization and cybersecurity community.
Understand how threat data and threat intelligence illuminate the network, identify weaknesses, and anticipate threat actors to prevent breaches and reduce recovery time.
Explore open source intelligence by analyzing publicly available data from search engines, registries, and DNS to identify threat actors and security trends.
Learn to combine open source with proprietary and closed data, plus internal network artifacts, logs, and baselines to identify threats, using the traffic light protocol for secure information sharing.
Explore the three characteristics of intelligence: timeliness, accuracy, and relevancy, and map threat intelligence products to your threat profile, prioritizing relevant data and communicating business impact with confidence levels.
Explore threat intelligence data and subscribe to security notifications from Microsoft, CISA, and other advisories to stay up to date with vulnerabilities, threats, and MITRE ATT&CK framework insights.
Learn how indicators, as context-rich observable artifacts of intrusions and attacks, are managed using Sticks 2.0, which defines 12 domain objects and 2 relation objects to standardize threat data.
Explore how Stix domain objects model attack patterns, campaigns, indicators, identities, and other elements to reveal threat actors and the techniques behind phishing and other campaigns.
Taxii defines how threat data and accompanying messages are shared between partners. It supports hub-and-spoke, source-subscriber, and peer-to-peer models, using collections and channels on a Taxii server.
OpenIoC, designed by Mandiant, organizes attacker TTPs and indicators of compromise into a machine-readable format for sharing and automation, with metadata, references, and definition guiding indexing and boolean logic.
Learn to classify incidents using baselines to distinguish known, signature-based threats from unknown threats, using heuristic analysis and sandboxing to detect zero-day exploits and APT campaigns.
Examine threat actors by sophistication and intent, from nation-state advanced persistent threats to hacktivists, insider threats, and organized crime threats, plus intentional vs unintentional insider threats.
Explore the intelligence cycle as a continuous five- or six-step process. Transform raw signals into actionable intelligence through requirements, collection, analysis, and dissemination.
Explore information sharing communities that standardize threat data and best practices across sectors, enabling collaboration, education, and continuity against cyber and physical threats.
Explore threat intelligence types and their importance for security professionals, examine attack frameworks, and learn threat modeling methodologies and how threat intelligence supports other security functions.
Assess the current environment to understand false positives and alert fatigue in security operations. Learn how integrating threat intelligence adds context to signals, enabling risk-based decisions in operational security.
Explore attack frameworks as analytical tools used by security teams to analyze incidents, actors, timelines, and attacker motivation. Use consistent language to anticipate techniques and make quick decisions, reducing disruption.
Explore the MITRE ATT&CK framework and its three flavors—enterprise, pre, and mobile. See how the enterprise model supports cybersecurity analysts in analyzing attacker tactics, techniques, and common knowledge.
Mitre attack framework offers a free, open model of twelve real-world tactics used by security operations teams worldwide to prioritize behaviors from initial access to exfiltration.
Explore the diamond model of intrusion analysis, an attack framework linking adversary capability, infrastructure, and victim through their connections, and learn its seven axioms for defenders.
Understand the cyber kill chain, a phase-based model of attacker steps from reconnaissance to actions on objectives, as defined by Lockheed Martin for defense in depth.
Explore threat research as a core part of threat intelligence, enriching alerts with reputational data, behavioral analysis, and unknown TTPs to inform scalable defenses.
Threat modeling promotes secure design by adopting an attacker mindset, creating a system abstraction, profiling actors, and mapping the attack surface to identify weaknesses early in the software development lifecycle.
Explore how threat intelligence sharing supports incident response, vulnerability management, risk management, and detection in the security operations center by enriching alerts with domain reputation, passive DNS, and malware associations.
Explore vulnerability management by detailing the process, determining scan frequency to meet organizational needs, identifying vulnerability types across systems, and configuring tools that perform scans.
Explore vulnerability management as a three-part framework of want-to-do, should-do, and have-to-do; identify requirements from external authorities, internal policies, and best practices to show due diligence and protect information.
Identify vulnerabilities through automated vulnerability scanning, assess asset criticality, and distinguish active versus passive scanning to map network topology and guide remediation options.
Review vulnerability scans and automated reports to validate findings and determine policy exceptions, ensuring accurate results and informed security decisions.
Learn how vulnerability scanners provide impact, mitigation, and remediation options, then apply remediation through configuration baselines, patch management, and system hardening, using compensating controls when needed to verify risk mitigation.
Assess how risk appetite drives scan frequency and scope. Compare credentialed versus non-credentialed scans, agent-based versus server-based scanners, and internal versus external approaches.
Identify data to include for vulnerability scans and how it drives what the scan collects, while considering technical constraints, workflows, data sensitivity, regulatory requirements, and network access.
Identify inhibitors to remediation, including a memorandum of understanding, scope and rules of engagement for vulnerability assessments, and how SLAs, governance, and legacy systems impact timely patching.
Explore how to use vulnerability assessment tools, understand their purpose, compare tools, review and interpret results, and apply them in specialized environments for the CSA exam prep.
Explore web application scanners such as ZAP, Burp Suite, Invicto, and NIE that identify vulnerabilities like SQL injection and cross-site scripting, with proxy mode and parallel scans.
Explore infrastructure scanners that assess network devices from outsider and authenticated user perspectives, using Nessus, OpenVAS, and Qualys Guard to perform authenticated and unauthenticated scans with plugins.
Demonstrates infrastructure scanners like Nessus Essentials performing credentialed and advanced scans across a range of IP addresses, identifying hosts, open ports, and vulnerabilities.
Explore software assessments through static code analysis with automated tools for code reviews and identifying defects. Examine dynamic analysis in a sandbox, reverse engineering, and fuzzing to reveal vulnerabilities.
Enumerate networks with horizontal and vertical scans using nmap to identify hosts and ports. Use active and passive methods, including DNS recon and responder, to gather data and credentials.
Learn network enumeration with nmap in Kali Linux, identifying live hosts, MAC addresses, open ports, and services across a subnet using ping scans, traceroute, and ARP scans.
Learn to conduct wireless assessments by capturing data, identifying devices in master and client modes, auditing with aircrack-ng, including rogue access points and injections, and GPU-based password cracking with hashcat.
Examine cloud vulnerability scanners like Scout Suite, Prowler, and Pacu Picchu, revealing cloud asset security posture across AWS, Azure, and Google Cloud, with emphasis on penetration testing and exportable results.
Translate threat data into actionable intelligence by identifying who, what, and context, then use it to shape defensive postures and drive vulnerability management and scanning across networks, devices, and applications.
Explore threats and vulnerabilities tied to specialized technologies, including cloud environments and wireless and mobile clients, and learn about vulnerability assessment tools used to secure them.
Identify threats and vulnerabilities in specialized technologies and learn why they form a distinct category, with scanning tools that apply to both regular and specialized systems.
Identify common vulnerabilities across systems, such as missing patches, misconfigured firewalls, weak passwords, and insecure wireless and VPN practices, and mitigate via patching, secure configurations, and multi-factor authentication.
Discover how rapid app development creates security risks at the application level, highlighting improper platform usage, insecure data storage, weak authentication, authorization gaps, and legacy code vulnerabilities.
Examine security implications of the internet of things and how connected devices expand the enterprise attack surface; learn patching, secure protocols, and disabling unused ports to prevent botnets.
Explore embedded systems with firmware on low-power microprocessors and real-time operating systems. Learn how SoCs and FPGAs raise hardware–software risks and why hardware verification and vulnerability assessments are critical.
Explore vulnerabilities in physical access control, including RFID badges and readers, and assess threat modeling for automotive CAN, drones, and SCADA with broad mitigation strategies.
Identify threats and vulnerabilities in cloud environments and the associated risks, as organizations adopt scalable, cost-efficient cloud solutions and explore vulnerabilities across service and deployment models.
Explain the three cloud service models—IaaS, PaaS, and SaaS—and how the shared responsibility model defines provider vs. customer duties, with examples like Google Apps and Office 365.
Explore software as a service as the leading cloud model and the security concerns it raises, including MFA, DLP, and identity management with Azure AD and partner sharing.
Explore platform as a service, a cloud-based development environment with access to source code and role-based controls, while applying threat modeling to protect cloud-based systems.
Explore how infrastructure as a service offers high visibility and control to manage hardware without overhead, while addressing hypervisor, RAM, CPU, cache, firmware, and hardware-sharing vulnerabilities.
Explore cloud deployment models by comparing public, private, hybrid, and community clouds, and learn how automatic provisioning and virtualization shape on-premises and externally hosted services.
Explore serverless architecture, function as a service, and the shift from traditional infrastructure, with emphasis on event-driven execution, pay-per-use pricing, and declarative versus imperative approaches to infrastructure as code.
Secure api credentials and implement robust object-level authorization, authentication, and precise responses; enforce short-lived tokens, two-factor authentication, strong passwords, and defend against misconfigurations, injection flaws, and poor logging.
Explore cloud vulnerabilities beyond basics, including improper key management, the risks of encryption keys in distributed cloud environments, and unprotected storage, logging, and monitoring under the shared responsibility model.
Demonstrates identifying Azure security vulnerabilities with secure score insights, MFA for admin accounts, and conditional access policies to mitigate threats in the Azure cloud.
Explore threats and vulnerabilities in specialized technologies and cloud environments, noting common risks across mobile devices and virtualized cloud environments, and highlighting unique threats to help you defend.
Analyze attack types and software vulnerabilities to protect organizational operations and brand. Apply proactive and reactive defense, best practices, and mitigating controls against common attacks.
Explore attack types and how threat actors gain access to privileged systems through exploitable flaws. Learn how widely known vulnerabilities and unaware targets enable malicious activity despite best practices.
Explore how injection attacks abuse untrusted input to trigger operations, including remote code execution and XML injections such as XML bombs or XXE, risking data leaks and denial of service.
Explore injection attacks, including SQL injection and cross-site scripting, showing how attackers exploit input parameters and stored, reflected, or DOM-based payloads to access data or execute code.
Examine directory traversal, where attackers view, modify, or execute files on the file system by exploiting misconfigured servers and root-directory exposure, and defend with proper web server configuration and permissions.
Examine buffer overflow attacks across stack, heap, and integer bases, how memory allocation on the stack and heap works, and how excessive data can lead to remote code execution.
Privilege escalation enables tasks beyond normal permissions, with vertical gaining higher privileges and horizontal targeting peers, used to modify files, steal sensitive information, or install malware, including jailbreaking and rooting.
Explore authentication attacks like password spraying and credential stuffing, and apply mitigations such as multifactor authentication and password policies. Examine impersonation, man in the middle, and session hijacking, rootkit threats.
Identify software vulnerabilities and how attackers exploit flaws in rules, implementations, or functions to bypass security policies; learn compensating controls to protect your company's software and network.
Analyze improper error handling and its security implications, highlighting how internal error messages and stack traces can reveal sensitive system details to external users.
Explore how dereferencing a null pointer creates memory access flaws, causing crashes or instability and potential denial of service, despite legitimate uses as a special marker.
Explain insecure object reference vulnerabilities where direct object identifiers reveal backend structures, and show how indirect reference maps with random values prevent disclosure of internal assets.
Explore how race conditions create vulnerabilities from timing variances, where sequential actions run concurrently, risking data integrity through time-of-check to time-of-use attacks and ACL bypass.
Identify sensitive data exposure vulnerabilities by examining how data is handled, transmitted, and encrypted. Enforce encryption, rotate keys, avoid clear-text transmission, and verify server certificates to uphold baseline security.
Explore insecure components in modern software development, including shared code, default configurations, and insecure functions, and learn logging practices to trace root causes and implement compensating controls.
Analyze attack types and software vulnerabilities, and show how attackers exploit systems to extract data. Outline mitigations and the security analyst responsibilities to keep developers and the organization protected.
Explore infrastructure management and the architectural foundations attackers target in modern networks. Study identity and access management, network architectures, and security solutions to identify, authenticate, and authorize users.
Equip cybersecurity analysts and security teams with a practical understanding of network security solutions, the technologies that compose the network, and how implementations and asset changes affect security.
Define network architecture by detailing how nodes connect and subnets route traffic, listing switches, routers, firewalls, and servers. Use prescriptive, hybrid designs to secure physical, software-defined, virtual, and cloud assets.
Analyze how the physical network interconnects devices like workstations, servers, firewalls, and routers, and implement policies on devices to control traffic between network segments using firewall rules and ACLs.
Decouple the control plane from the data plane in software-defined networks. Let software applications decide how to route data and move packets, describing how nodes communicate.
Explore virtual private cloud networks (VPCs) that provide private resources in a public cloud, enabling systems to communicate as if on the network through software defined networking and virtualization.
Explore how a virtual private network creates a secure tunnel between endpoints over the Internet, enabling remote access, site-to-site connectivity, and split tunneling to optimize traffic.
Examine virtualization solutions and serverless architectures, including hypervisors, type one and type two, VDI, and containerization, to secure and optimize cloud resource use.
Explore network segmentation by breaking networks into subnets with physical and virtual controls, VLANs and ACLs, and use jump boxes and system isolation to strengthen access control and auditing.
Explore Azure virtual networks and resource groups to implement virtual network segmentation, using subnets, IP address spaces, firewalls, and network security groups to isolate and monitor honeypots within cloud workloads.
Explore data collector sets and performance monitor in Windows to collect security-relevant metrics for honeypots, establish baselines, schedule data collection, and detect anomalies.
Learn how identity and access management verifies who users claim to be, grants rights and privileges, and tracks user activity for accountability through auditing.
Identify, authenticate, and authorize users and processes through identity access management, and learn how credentials and a security database enable secure access.
Practice privilege management within identity and access management to prevent authorization creep by minimizing privileged accounts, enforcing least privilege, using separate admin accounts with MFA, and auditing actions.
Utilize multifactor authentication to move beyond single-factor logins, using two or three factors such as who you are, what you know, or what you have, to defend against ransomware.
Master multi-factor authentication to defend against unauthorized access and ransomware. Enforce MFA across Microsoft Azure AD and other apps, and explore Duo and conditional access setups.
Explore identity federation, enabling single sign-on across organizational boundaries with protocols like SAML and OpenID, where identity providers authenticate users and service providers grant access via authentication and authorization decisions.
Explains identity and access management and compares role-based, discretionary, and attribute-based access control models. Highlights ABAC's granular policies and MAC's explicit authorization with multilevel security labels.
Explore discretionary, role-based, and mandatory access control across Windows, Active Directory, Exchange Online, and Azure AD, focusing on permissions, inheritance, and auditing.
Learn how a cloud access security broker sits between users and cloud services to enforce policy across multiple apps, enabling visibility, threat protection, compliance, and data security.
Explore a few additional solutions that accompany infrastructure management and security in the final topic.
Explore monitoring and logging to ensure system availability and performance, enable audit logging, set baselines with alerts, use real user monitoring and synthetic checks, and classify events with pattern recognition.
Explore how encryption transforms plaintext into ciphertext and back, using symmetric and asymmetric cryptography. Learn how SSL, digital signatures, and certificate management protect data and identities.
Demonstrates Windows encrypting file system, showing how a symmetric file encryption key is protected by a public key, with optional recovery agents and scenarios with or without a certificate authority.
Review chapter 4 emphasizes network infrastructure security and solutions such as virtual private networks and virtual private cloud. It also covers identity and access management, monitoring and logging, and encryption.
Explore hardware and software assurance best practices within infrastructure management to protect data even if devices are compromised, and learn how to harden systems against threats.
Explore hardware assurance and best practices to build a route of trust, securely update firmware, protect data with hardware-based security, and anti-tamper techniques.
Explore hardware root of trust and trusted execution environments with built-in cryptographic functions, cryptographic keys and digital certificates storage, and TPM-based binding and sealing for system integrity, including BitLocker integration.
Understand the trusted platform module—a secure microcontroller with cryptographic modules for key and hash processing, featuring non-volatile RAM, the endorsement key, and storage root keys, plus pcrs for attestation.
Explore BitLocker drive encryption using the TPM for hardware-backed keys and secure boot, configure startup pins and key storage options, and back up recovery keys on Windows.
Compare hardware security modules as removable devices that generate, store, and manage cryptographic keys, offloading encryption from CPU to improve performance, as an alternative to TPM, with FIPS guiding evaluation.
One-time programmable eFuse memory provides a nonvolatile memory that cannot revert to zero. It enables hardware protection by disabling test circuitry and stores firmware or cryptographic keys to verify updates.
Explore how unified extensible firmware interface (UEFI) replaces BIOS, enabling larger disks and remote boot, and analyze the secure boot process to establish a route of trust.
Measured boot hashes code and stores the results to create an audit trail. Attestation securely sends hashes to a management station; together they support scenarios where secure boot is impractical.
Explore trusted firmware updates with dual firmware storage and rollback for secure boots, then examine self-encrypting drives with full disk encryption, bus encryption, and secure processing.
Bridge the gap between developers and security teams by applying software assurance best practices, secure coding, and a structured software development lifecycle.
Explore software architectures from standalone to distributed systems, including client-server and web applications, mobile and embedded platforms, and key security considerations for data, networks, and updates.
Learn how service-oriented architecture treats software as interconnected, self-contained services that communicate via APIs using SOAP and REST; explore message envelopes, protocols, XML over HTTP, microservices, and SAML-based identity federation.
Explore the software development lifecycle from requirements to retirement, covering functional, nonfunctional, and security requirements, and the security analyst's role in unit, integration, system, and formal acceptance testing.
Explore software assessment methods from user acceptance and stress testing to security regression testing, code review, and both static and dynamic analysis, ensuring confidentiality, integrity, and availability.
Learn secure coding practices that ensure quality by validating inputs with context-specific whitelisting, encoding outputs, safeguarding sessions, and using parameterized queries to prevent injection.
Explore hardware and software assurance best practices, including TPMs, hardware security modules, root of trust, secure boot, EFI interfaces, and security-minded software development.
Develop skills to monitor security options across diverse networks using security data analytics, endpoint and network analysis, and email analysis to prevent malicious behavior and strengthen security operations centers.
Analyze security data, continuously monitor networks, and make security based decisions using accurate and timely data.
Security monitoring collects and normalizes data from routers, switches, firewalls, ids and ips, unified threat management, mdm, and vulnerability scanners to support audits, compliance, and security decisions.
Aggregate security data from diverse sources to inform decisions, using log managers, SIEMs, and dashboards to normalize data, display a timeline, search, and alert on incidents.
Leverage time series data to detect anomalies by comparing points to baselines, and use trend analysis—predictive analytics across internal, temporal, and spatial patterns—to guide security decisions and controls.
Explore endpoint and network analysis to layer security beyond the network level, ensuring traffic is thoroughly inspected and endpoints, the devices connecting to the network, are monitored.
Protect endpoints by detecting malware through fingerprinting and hashing known binaries, using signature-based and behavior-based detection, and leveraging cloud-based platforms and UEBA for anomaly alerts.
Learn to fuse internal and external data sources for network threat detection, using DNS logging, blacklists, DGA, flow and packet analysis, and encryption handling to disrupt malware command and control.
Analyze Windows event logs and syslog formats to correlate events by ID and severity, audit security events using a SIEM, and review firewall, proxy, and IDS/IPS logs.
Explore logging and monitoring capabilities to analyze current and past system activity, identify login attempts and potential attacks, and use event viewer, firewall logs, and netstat outputs to investigate.
Learn how to assess and respond to attacks by analyzing localized and total impact on availability, confidentiality, and integrity, guiding immediate actions and long-term organizational decisions through auditing.
Analyze email traffic to detect malicious messages and understand threats targeting employees, and implement steps to protect this primary means of communication.
Explore social engineering via phishing and malicious payloads using email as the main channel, showing prompts to enter passwords, visit fake sites, or click links for gift cards.
Explain how DKIM, SPF, and DMARC work together to verify sender identity and message integrity, prevent spoofing, and reduce spam by guiding how to handle spoofed emails.
Explore anti-spam options in Exchange Online, including malware and spam filters, quarantine and notification settings, and implement SPF, DMARC, and DKIM to protect against phishing and outbound spam.
Monitor security across the organization by collecting, correlating, and analyzing data with SIEM systems, and protect endpoints and email with SPF, DKIM, and DMARC.
Learn to implement security changes across the enterprise by applying security configuration management, threat hunting, and automated security practices, guided by monitoring insights and scripting technologies.
Master security configuration management by adapting to changing networks, managing user and group policies, enabling application execution controls, and applying whitelisting, blacklisting, filtering, and intrusion detection systems.
Configure identity management by managing user accounts and groups in domain and cloud environments, authenticate users, and enforce access control through permissions and access control lists.
Explore Windows 10 software controls, including application control policies and software restriction policies, and compare blacklisting with whitelisting to reduce malware risk.
Firewalls control traffic between networks with explicit rules, usually denying inbound and permitting outbound connections, across Windows, ufw, network, web application, and proxy systems, offering logging, content filtering, and caching.
Explore intrusion detection systems (ids) that monitor network events to identify suspicious activity, as network or host ids, using rules in Zeek, Snort, or Circrna to alert or block threats.
Practice data loss prevention (DLP) for digital communication by inspecting traffic, classifying data, and enforcing policies to protect data in transit across platforms and devices.
Endpoint detection and response (EDR) solutions monitor and detect threats by logging and aggregating endpoint activity, enabling trend analysis and threat detection, and respond by stopping or removing malicious assets.
The lecture explains network access control (NAC) as policy enforcement checks prior to connecting to the network, including endpoint malware protection and OS checks, with remediation and diverse response options.
Explore additional techniques for security configuration, including dns sinkhole to mitigate malicious traffic, sandboxing to quarantine executables, signature-based malware detection, and port security to disable unnecessary services.
Learn threat hunting as a proactive, iterative defense that treats attackers as already inside the system, reducing assumptions while outlining the process, benefits, and practical tactics.
Threat hunting blends active defense with human analysis to uncover threat actors beyond alerts, cannot be fully automated, and uses ML and UEBA to add context to data, anticipating techniques.
Develop a repeatable four-stage threat hunting cycle by formulating a testable hypothesis with observable signals, leveraging analytics, situation driven, or intelligence driven approaches, and using tools to inform security operations.
Explore analytics-driven, situation-driven, intelligence-driven, and experience-driven hypotheses, using examples like outbound traffic spikes to guide endpoint scans.
Profile threat actors using the attack framework to map adversary tactics and techniques across the attack lifecycle, aiding threat hunting and threat intelligence.
Automate threat hunting with specialized tools and existing security platforms to sift through logs and traffic, revealing attacker TTPs across initial access, persistence, enumeration, and lateral movement.
Reduce the attack surface to boost overall security, enhance threat hunting readiness, and bundle critical assets with shared security controls, complemented by vulnerability scanners for ongoing threat adaptation.
Explore how automation technologies enhance security operations by enabling analysts to focus on complex tasks, with best practices for orchestration, workflows, playbooks, and scalable data enrichment.
Explore how security automation uses standards and protocols to perform common security actions for fixed periods or indefinitely. Improve troubleshooting, accuracy, and auditing by leveraging specifications and standards.
Orchestrate security workflows by connecting tools through apis to automate threat responses across environments, boosting analyst productivity with tool-to-tool communication in security orchestration, automation and response platforms like Splunk Phantom.
Orchestration playbooks define workflows with initiating conditions, process steps, and end states, enabling chaining of outcomes to automate phishing investigations, enrich threat intelligence, and save time across security operations.
Learn scripting for security operations using cron jobs, cron tab, and secure shell to automate tasks, plus Python and PowerShell for incident response, detection, and vulnerability management.
Explore how APIs standardize communication, boost efficiency, and enable secure, scalable access to data, using soap with xml over http or smtp and rest over http.
Explore the REST architectural style for web services, covering six principles—client-server, statelessness, cache, uniform interface, resource identification and representations—plus hypermedia, layering, and optional code on demand.
The security content automation protocol defines 12 component specifications across five categories to standardize vulnerability assessment and reporting, covering languages, asset identification, and scoring, including XCCDF, OVAL, and OCIL.
Incorporate built in security into software engineering with devsecops, using continuous integration, delivery, and deployment for timely releases, automated testing, and security checks.
Explore implementing security configuration and security configuration management to harden systems, practice threat hunting by analyzing in-network attacker activity, and examine how system automation enhances security analytics.
Explore the incident response process to detect and recover from security incidents, and analyze indicators of compromise using digital forensics to understand and prevent future events.
Recognize the importance of incident response and establish clear communication processes within the organization and security team to effectively manage breaches, assess data criticality, and mitigate unauthorized disclosures.
Learn how a well-documented, organization-specific incident response process detects and recovers from security events, guiding efficient investigation, remediation, and timely stakeholder updates.
Establish and execute a secure, regular incident response plan to keep trusted internal stakeholders informed in a war room and manage external communications per regulatory requirements to avoid soundbites.
Coordinate internal communications within the incident response team and across stakeholders—IT security, management, HR, PR, and senior leadership—to ensure everyone knows their role during incidents.
Coordinate with legal counsel, law enforcement, regulatory bodies, and external contractors during incident response, and establish timely reporting procedures to protect data and avoid penalties.
Identify critical data types, including PII, HIPAA data, PCI, intellectual property, corporate confidential and financial data, and understand regulatory safeguards, penalties, and threats like identity theft and ransomware.
Learn the incident response cycle, including preparation, detection and analysis, containment, eradication, recovery, and post-incident actions, and distinguish events from incidents to protect organizational security.
Explore the incident response cycle, from preparation and detection to identification, analysis, containment, eradication, and recovery, and learn techniques that strengthen future defenses.
Prepare for security incidents with a sound methodology to reduce uncertainty, identify assets and priorities, and use training, testing, and documentation to align teams and improve response readiness.
Conduct detection and analysis to classify security events and determine scope of impact, using automated techniques, MTD and RTL, data integrity, and SIEM-driven data correlation to reduce false positives.
Containment stops further damage by denying threat agents ability to spread incident; it can be proactive or reactive, including network disconnection when appropriate, depending on attack category and assets' criticality.
Examine containment types, focusing on segmentation and isolation with gateway controls and VLANs to limit malware spread. Understand removing compromised hosts and preserving forensic evidence within the IRR plan.
Eradicate the incident by capturing evidence, restoring systems to a known good state, mitigating vulnerabilities, sanitizing media, and rebuilding hosts from gold master images to ensure trusted functionality.
Restore data from up-to-date backups and securely dispose media using appropriate methods, then patch gold master images, restore and validate permissions, and verify services and logging for a secure recovery.
Publish a lesson learned report with observations and recommendations. Use change control to update the response plan, produce a summary report, and integrate indicators of compromise into the monitoring plan.
Analyze indicators of compromise to detect hidden attacker activity by examining network, host, and application symptoms, and ignore misleading choices to diagnose incidents effectively.
Identify network-related indicators of compromise by monitoring bandwidth patterns, beaconing, irregular peer-to-peer traffic, and rogue devices, then investigate lateral movement and unusual port usage.
Assess host indicators by tracing resource spikes in CPU, memory, and disk, baseline normal processes, and monitor for unauthorized software and changes, including registry and scheduled tasks.
Identify application-related indicators by monitoring user-level software like browsers and email clients for anomalous activity, unexpected prompts, privilege escalation, new accounts, and outbound communications signaling compromise.
Analyze indicators of compromise through incident response by inspecting event viewer, auditing policies, credential validation, logon events, object access and ACLs, and resource monitoring to detect breaches.
Explore how digital forensics techniques support incident response and learn basic forensic analysis methods, common utilities, and how to assemble a forensics toolkit.
Analyze digital forensics to determine incidents and explain what, where, when, and how, then apply seizure, acquisition, analysis, and reporting to preserve evidence and ensure an unbiased report.
Compare header captures and full packet captures, and explore passive versus active network taps for data collection. Use Wireshark, Tshark, and TCP dump to analyze traffic across platforms.
Explore how to use the free packet analysis tool Wireshark for capturing and filtering network traffic, identifying sources, IOCs, and protocols during incident response, and saving captures for reports.
Avoid powering off a device during a forensic investigation to preserve memory and detect threats. Document the physical environment with photos and analyze Windows registry and event logs for clues.
Take a mobile forensics approach by addressing challenges like Faraday container usage, dedicated tools, and device access, then explore virtualization and cloud evidence with snapshots, VMX files, and memory state.
Build a forensics kit with a jump bag, live response tools, and write blockers for rapid data collection. Include cables, tamper-proof seals, a camera for site photos, and chain-of-custody forms.
Develop incident response procedures and phased communication to manage inevitable breaches. Analyze indicators of compromise by examining operating system, CPU, memory, and network usage, then apply basic digital forensic techniques.
Explore the distinction between privacy and security, key data types and laws, and implement non-technical and technical controls to protect data, plus risk mitigation and policies.
Explore data privacy and protection in topic a, the first topic of the course, focusing on how to protect data.
Privacy is control over how others view or use personal information, while security protects data from unauthorized access. Security can provide privacy but may limit it, for example via monitoring.
Explore data types and how compliance and assessment shape data privacy and protection. Focus on four regulated types: personal data, personal health data, financial data, and copyrighted data.
Navigate local, national, and international data laws governing privacy, including GDPR, HIPAA, PCI DSS, and copyright. Understand GDPR's consent, HIPAA's medical data protections, PCI DSS's penalties, and copyright rights.
Understand non-technical controls, or administrative controls, and how data ownership, classification, and confidentiality guide risk management. Learn how NDAs, data sovereignty, data minimization, purpose limitation, and retention protect information.
Data retention standards define what data to keep, for how long, and where it is stored. Build searchable archives through taxonomy, metadata tagging, and indexing to enable timely retrieval.
Implement technical controls with access control and authentication methods such as username/password, Kerberos, biometrics, PKI certificates, RADIUS, and smart cards, and apply encryption, masking, tokenization, and DRM.
Inventory data and map data flows across devices and clouds to prepare for data loss prevention. Implement policies at rest, in use, and in motion with testing and maintenance.
Demonstrates implementing data loss prevention across Microsoft 365 services, including Exchange Online, SharePoint, OneDrive for Business, and Teams, with templates for U.S. financial data and policy tips.
Explore risk mitigation by applying a business impact analysis to understand how information systems support the organization, then assess risk, implement controls, and periodically evaluate their effectiveness.
Conduct a business impact analysis by gathering data from interviews, surveys, and workshops to classify business functions by criticality and downtime. Identify regulatory responsibilities, reputation impacts, and critical technology assets.
Identify interviewees and data gathering techniques, map critical business functions and resources, set acceptable downtime, assess vulnerabilities and threats, calculate risks by function, and document findings for management.
Identify vulnerabilities and threats through risk assessment to evaluate impact and determine cost-effective and timely controls responsive to threats, and align security with business goals while securing senior management support.
Identify vulnerabilities, assess exploitation likelihood, and gauge business impact through threat intelligence, vulnerability assessments, security operations, and adversary-minded brainstorming; establish a monthly threat working group to sustain risk identification.
Compare quantitative and qualitative risk calculation methods, quantifying elements like impact and frequency or categorizing them into severity levels. Use matrices to assess risk and inform security controls.
Prioritize risks by applying transference, avoidance, mitigation, and acceptance strategies. Recognize that risk elimination is impossible, and use insurance or cost-benefit checks to decide when to accept or mitigate.
Security controls consist of administrative, technical, and physical measures, with ongoing reviews for effectiveness and costs, and compensating controls like VLAN isolation and ACLs.
Explore the training and exercises module as it outlines tabletop, live-fire, and simulated exercises, detailing branches, sequels, and the roles of red, blue, and white teams, plus goals and outcomes.
Explore how policies and procedures implement security frameworks and follow industry guidelines and best practices while examining ethics and codes of conduct.
Explore how a code of conduct guides ethical behavior, detailing policies on acceptable use, password management, data ownership, retention, and continuous monitoring for risk management.
Compare managerial, technical, operational, and physical controls to build a defense-in-depth strategy. Recognize preventive, detective, corrective, deterrent, and compensating controls and the distinction between responsive and corrective functions.
Understand how audits—performed by independent third parties—verify that security frameworks, policies, procedures, and controls meet external regulatory and standards compliance, reducing risk and detailing penalties for noncompliance.
Explore how regulatory requirements shape data privacy and security, assess risk, and select controls using transfer, avoidance, mitigation, or acceptance. Emphasize policies and procedures to keep data secure.
Prepare for the cysa+ exam by reviewing threat data and intelligence, vulnerability management, incident response, and security operations to become a proficient cybersecurity analyst.
The CompTIA Cyber Security Analyst course is an intermediate level certification that assesses both practical performance as well as theoretical knowledge of the candidates in the field of cyber security. Due to the increased exposure of data, applications and critical resources of any organization, cyber security is rapidly taking the center stage in every organization’s vision, mission and roadmap. The CompTIA CySA+ certification prepares the candidates to use artificial intelligence and threat detection techniques, analyze and interpret sensitive and critical data, pinpoint and fix vulnerabilities, suggest preventative measures to effectively respond to and recover from data breach and intrusion incidents. This set of skills helps the candidates to stand out and enhance job prospects in the competitive field of cyber security as well as related fields like information security, network security and systems security.
The CompTIA CySA+ (Cyber Security Analyst) course is an ideal course for information security professionals who are looking for career progression in this ever growing and always changing field. During the last decade, cyber security’s importance has increased exponentially and with this, the job openings have also multiplied several folds. On the other hand, the inflow of trained and certified cyber security professionals has not been able to match the demand, hence resulting in higher salaries for the trained professionals. The CompTIA CySA+ certification, being an intermediate level certification, provides an excellent opportunity to candidates to step foot in the cyber security and information security job market and excel from there. As a starting point for cyber security related certification, the training you will receive in this course, will help you to be prepared for the exam contents and successfully clear the CompTIA CySA+ exam.