Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CompTIA CySA+ (CS0-002)
Rating: 4.9 out of 5(2 ratings)
30 students

CompTIA CySA+ (CS0-002)

CompTIA Cyber Security Analyst
Last updated 5/2022
English
English [Auto],

What you'll learn

  • Learn to manage threats and vulnerabilities by understanding attack frameworks like MITRE ATT&CK
  • Learn about attack kill chain and identify vulnerabilities using assessment tools
  • Perform remediation and mitigation of threats and vulnerabilities
  • Learn about threats and vulnerabilities for cloud environments and software
  • Manage security infrastructure and learn about network security solutions
  • Implement identity and access management
  • Get to know advanced techniques like cryptography
  • Ensure hardware security and learn about software assurance methods and best practices
  • Learn the concepts of monitoring, logging, aggregating and analyzing security related data
  • Implement security changes and manage security configuration
  • Understand the importance of incident response and learn about incident response cycle
  • Utilize digital forensic techniques
  • Analyze indicators of compromise (IoCs)
  • Perform compliance checks and assessments
  • Analyze business impact and perform risk assessment

Course content

9 sections218 lectures11h 30m total length
  • Instructor Introduction2:56

    Meet instructor Patrick Lohner, a 20-year security veteran, sharing expertise in CompTIA CySA+ content, cyber defense, firewall management, multifactor authentication, cloud security (Office 365, Azure), and security training across MSPs.

  • Course Introduction3:33

    Learn threat and vulnerability management, threat intelligence, and assessment tools across cloud, virtualization, mobile devices, and network infrastructure, then master incident response, monitoring, change management, and compliance for cs0-002 exam.

  • Managing Threats and Vulnerabilities1:34

    Explore threats and vulnerabilities, collect and share threat intelligence, and apply vulnerability management and scanning tools to identify and mitigate security risks.

  • Topic A: Threat Data and Intelligence0:36

    Explore foundations of threat intelligence and common sources, outline the intelligence cycle from collection to use, explain indicators of compromise, and best practices for sharing within organization and cybersecurity community.

  • Importance of Threat Data2:20

    Understand how threat data and threat intelligence illuminate the network, identify weaknesses, and anticipate threat actors to prevent breaches and reduce recovery time.

  • Open-Source Intelligence9:27

    Explore open source intelligence by analyzing publicly available data from search engines, registries, and DNS to identify threat actors and security trends.

  • Proprietary / Closed Source Intelligence2:51

    Learn to combine open source with proprietary and closed data, plus internal network artifacts, logs, and baselines to identify threats, using the traffic light protocol for secure information sharing.

  • Intelligence Characteristics3:21

    Explore the three characteristics of intelligence: timeliness, accuracy, and relevancy, and map threat intelligence products to your threat profile, prioritizing relevant data and communicating business impact with confidence levels.

  • Demo - Threat Data4:40

    Explore threat intelligence data and subscribe to security notifications from Microsoft, CISA, and other advisories to stay up to date with vulnerabilities, threats, and MITRE ATT&CK framework insights.

  • Indicator Management1:23

    Learn how indicators, as context-rich observable artifacts of intrusions and attacks, are managed using Sticks 2.0, which defines 12 domain objects and 2 relation objects to standardize threat data.

  • STIX Domain Objects7:53

    Explore how Stix domain objects model attack patterns, campaigns, indicators, identities, and other elements to reveal threat actors and the techniques behind phishing and other campaigns.

  • Trusted Automated Exchange of Indicator Information (TAXII)2:38

    Taxii defines how threat data and accompanying messages are shared between partners. It supports hub-and-spoke, source-subscriber, and peer-to-peer models, using collections and channels on a Taxii server.

  • OpenIoC1:36

    OpenIoC, designed by Mandiant, organizes attacker TTPs and indicators of compromise into a machine-readable format for sharing and automation, with metadata, references, and definition guiding indexing and boolean logic.

  • Threat Classification5:03

    Learn to classify incidents using baselines to distinguish known, signature-based threats from unknown threats, using heuristic analysis and sandboxing to detect zero-day exploits and APT campaigns.

  • Threat Classification6:08

    Examine threat actors by sophistication and intent, from nation-state advanced persistent threats to hacktivists, insider threats, and organized crime threats, plus intentional vs unintentional insider threats.

  • Intelligence Cycle4:26

    Explore the intelligence cycle as a continuous five- or six-step process. Transform raw signals into actionable intelligence through requirements, collection, analysis, and dissemination.

  • Information Sharing1:36

    Explore information sharing communities that standardize threat data and best practices across sectors, enabling collaboration, education, and continuity against cyber and physical threats.

  • Topic B: Utilizing Threat Intelligence0:32

    Explore threat intelligence types and their importance for security professionals, examine attack frameworks, and learn threat modeling methodologies and how threat intelligence supports other security functions.

  • Threat Intelligence and Operational Security2:17

    Assess the current environment to understand false positives and alert fatigue in security operations. Learn how integrating threat intelligence adds context to signals, enabling risk-based decisions in operational security.

  • Attack Frameworks0:47

    Explore attack frameworks as analytical tools used by security teams to analyze incidents, actors, timelines, and attacker motivation. Use consistent language to anticipate techniques and make quick decisions, reducing disruption.

  • MITRE ATT&CK1:27

    Explore the MITRE ATT&CK framework and its three flavors—enterprise, pre, and mobile. See how the enterprise model supports cybersecurity analysts in analyzing attacker tactics, techniques, and common knowledge.

  • MITRE ATT&CK (cont.)2:36

    Mitre attack framework offers a free, open model of twelve real-world tactics used by security operations teams worldwide to prioritize behaviors from initial access to exfiltration.

  • The Diamond Model of Intrusion Analysis1:43

    Explore the diamond model of intrusion analysis, an attack framework linking adversary capability, infrastructure, and victim through their connections, and learn its seven axioms for defenders.

  • Kill Chain5:43

    Understand the cyber kill chain, a phase-based model of attacker steps from reconnaissance to actions on objectives, as defined by Lockheed Martin for defense in depth.

  • Threat Research4:25

    Explore threat research as a core part of threat intelligence, enriching alerts with reputational data, behavioral analysis, and unknown TTPs to inform scalable defenses.

  • Threat Modeling4:06

    Threat modeling promotes secure design by adopting an attacker mindset, creating a system abstraction, profiling actors, and mapping the attack surface to identify weaknesses early in the software development lifecycle.

  • Threat Intelligence Sharing with Supported Functions4:26

    Explore how threat intelligence sharing supports incident response, vulnerability management, risk management, and detection in the security operations center by enriching alerts with domain reputation, passive DNS, and malware associations.

  • Topic C: Vulnerability Management0:30

    Explore vulnerability management by detailing the process, determining scan frequency to meet organizational needs, identifying vulnerability types across systems, and configuring tools that perform scans.

  • Introduction to Vulnerability Management1:14

    Explore vulnerability management as a three-part framework of want-to-do, should-do, and have-to-do; identify requirements from external authorities, internal policies, and best practices to show due diligence and protect information.

  • Vulnerability Identification3:38

    Identify vulnerabilities through automated vulnerability scanning, assess asset criticality, and distinguish active versus passive scanning to map network topology and guide remediation options.

  • Validation Options3:25

    Review vulnerability scans and automated reports to validate findings and determine policy exceptions, ensuring accurate results and informed security decisions.

  • Remediation and Mitigation4:00

    Learn how vulnerability scanners provide impact, mitigation, and remediation options, then apply remediation through configuration baselines, patch management, and system hardening, using compensating controls when needed to verify risk mitigation.

  • Understanding Scanning7:01

    Assess how risk appetite drives scan frequency and scope. Compare credentialed versus non-credentialed scans, agent-based versus server-based scanners, and internal versus external approaches.

  • Additional Scanning Considerations3:12

    Identify data to include for vulnerability scans and how it drives what the scan collects, while considering technical constraints, workflows, data sensitivity, regulatory requirements, and network access.

  • Inhibitors to Remediation3:48

    Identify inhibitors to remediation, including a memorandum of understanding, scope and rules of engagement for vulnerability assessments, and how SLAs, governance, and legacy systems impact timely patching.

  • Topic D: Using Vulnerability Assessment Tools0:44

    Explore how to use vulnerability assessment tools, understand their purpose, compare tools, review and interpret results, and apply them in specialized environments for the CSA exam prep.

  • Web Application Scanners3:36

    Explore web application scanners such as ZAP, Burp Suite, Invicto, and NIE that identify vulnerabilities like SQL injection and cross-site scripting, with proxy mode and parallel scans.

  • Infrastructure Scanners2:37

    Explore infrastructure scanners that assess network devices from outsider and authenticated user perspectives, using Nessus, OpenVAS, and Qualys Guard to perform authenticated and unauthenticated scans with plugins.

  • Demo - Infrastructure Scanners10:56

    Demonstrates infrastructure scanners like Nessus Essentials performing credentialed and advanced scans across a range of IP addresses, identifying hosts, open ports, and vulnerabilities.

  • Software Assessments3:15

    Explore software assessments through static code analysis with automated tools for code reviews and identifying defects. Examine dynamic analysis in a sandbox, reverse engineering, and fuzzing to reveal vulnerabilities.

  • Enumeration3:43

    Enumerate networks with horizontal and vertical scans using nmap to identify hosts and ports. Use active and passive methods, including DNS recon and responder, to gather data and credentials.

  • Demo - Enumeration8:46

    Learn network enumeration with nmap in Kali Linux, identifying live hosts, MAC addresses, open ports, and services across a subnet using ping scans, traceroute, and ARP scans.

  • Wireless Assessments4:03

    Learn to conduct wireless assessments by capturing data, identifying devices in master and client modes, auditing with aircrack-ng, including rogue access points and injections, and GPU-based password cracking with hashcat.

  • Cloud Assessment2:00

    Examine cloud vulnerability scanners like Scout Suite, Prowler, and Pacu Picchu, revealing cloud asset security posture across AWS, Azure, and Google Cloud, with emphasis on penetration testing and exportable results.

  • Chapter 1 Review0:47

    Translate threat data into actionable intelligence by identifying who, what, and context, then use it to shape defensive postures and drive vulnerability management and scanning across networks, devices, and applications.

  • Chapter 1 Quiz

Requirements

  • The course is ideal for the candidates already having some exposure and basic knowledge of cyber security. The candidates are expected to have a personal computer along with hands-on experience of using multiple operating systems like Windows, Linux and Ubuntu etc.

Description

The CompTIA Cyber Security Analyst course is an intermediate level certification that assesses both practical performance as well as theoretical knowledge of the candidates in the field of cyber security. Due to the increased exposure of data, applications and critical resources of any organization, cyber security is rapidly taking the center stage in every organization’s vision, mission and roadmap. The CompTIA CySA+ certification prepares the candidates to use artificial intelligence and threat detection techniques, analyze and interpret sensitive and critical data, pinpoint and fix vulnerabilities, suggest preventative measures to effectively respond to and recover from data breach and intrusion incidents. This set of skills helps the candidates to stand out and enhance job prospects in the competitive field of cyber security as well as related fields like information security, network security and systems security.

The CompTIA CySA+ (Cyber Security Analyst) course is an ideal course for information security professionals who are looking for career progression in this ever growing and always changing field. During the last decade, cyber security’s importance has increased exponentially and with this, the job openings have also multiplied several folds. On the other hand, the inflow of trained and certified cyber security professionals has not been able to match the demand, hence resulting in higher salaries for the trained professionals. The CompTIA CySA+ certification, being an intermediate level certification, provides an excellent opportunity to candidates to step foot in the cyber security and information security job market and excel from there. As a starting point for cyber security related certification, the training you will receive in this course, will help you to be prepared for the exam contents and successfully clear the CompTIA CySA+ exam.

Who this course is for:

  • Security analysts working in any organization
  • Threat intelligence analysts
  • Information security manager
  • Security engineer
  • Application security analyst
  • Incident responder or handler
  • Compliance analyst
  • Threat hunter
  • Information security officer