
prepare for the 2014 security plus objectives and pass the SY0-401 exam by exploring the latest objective list step by step with instructor Mark Long.
Learn how risk assessment, policy standards, and risk management underpin security. Then implement authentication, authorization, and access controls while exploring network devices, DMZs, and cloud security.
Learn the CompTIA Security+ exam format: 100 short, multiple-choice questions in 90 minutes, with a timer; stay calm, move through questions, and mark and revisit uncertain items.
Learn to access and manage your working files for the infinite skills course by downloading, extracting, and organizing them on your desktop.
Identify threats, vulnerabilities, and the impact of data loss across networks. Prioritize risks by cost and likelihood using quantitative and qualitative assessments.
Compute annual loss expectancy by multiplying single loss expectancy by the annualized rate of occurrence, using asset value and exposure factor to quantify risk.
Explore how clear policies, standards, and guidelines shape risk management and secure networks by defining scope, accountability, and compliance, while enabling enterprise-wide buy-in and consistent configurations.
Explore the three main control types—management, operational, and technical—driven by risk assessment, with ongoing reviews and concrete controls for access, audit, incident response, and protection.
Identify critical functions, determine downtime windows, and conduct a business impact analysis to assess tangible and intangible impacts for risk management and business continuity.
Explore the three A's—authentication, authorization, and access control—as the foundation of modern security, detailing how identities are verified, permissions are granted, and access to resources is managed.
Explore how authentication verifies user identity through methods like username and password, smart cards, biometrics, and location, and compare single factor, mutual, and multi-factor approaches.
Explore how access control uses ACLs and security tokens to govern user access to network resources, domains, and devices, and learn best practices for authentication, permissions, and password hygiene.
Explore four main access control methods—mandatory, discretionary, role-based, and rule-based—and how groups, permissions, and allow lists shape secure resource access.
Balance strong authentication with usability by examining common pitfalls and applying best practices such as passphrases, avoiding dictionary words or sports team names, and using identity proofing.
Explore how authentication protocols securely verify user credentials with a server, focusing on pap, chap, totp, hotp, and hmac-based one-time password.
Explore authentication services that secure credentials across networks, focusing on Radius, TACACS+, XTACACS, and Kerberos. Learn how these services provide centralized management, authentication, authorization, and logging.
Explore LDAP, LDAPS, and SAML for authentication and single sign-on, and examine Kerberos with its KDC, TGTs around 10 hours, and short-lived service tickets.
Apply industry best practices for access control, including least privilege and separation of duties. Implement time-of-day restrictions, regular user access reviews, and log auditing to detect anomalies.
Explore trusted operating systems that meet government security requirements via the Common Criteria, where commercial systems are evaluated to EAL 4 or 5, with assurance levels 1 through 7.
Illustrates setting domain-level permissions on Windows Server 2012 using ACLs and NTFS, assigning read rights to the sales group for the infinite skills folder via the sharing and security tabs.
Explore the four tcp/ip layers—application, transport, internet, and network access—and how data moves from applications through tcp or udp, ip addressing, routing, fragmentation, and reassembly, with security implications.
Discover how TCP/IP powers networks and how ports act as loading docks to manage traffic. Close unused ports with firewalls to reduce intruder access, noting port 80 for HTTP.
Explore protocols and ports, such as ftp (20/21), telnet (23), smtp (25), http (80), https (443), pop3 (110), imap (143), ldap (389), with well-known 0–1024, registered 1024–49151, dynamic 49152–65535.
Define firewalls as devices that isolate networks and filter traffic between trusted and untrusted networks. Learn three firewall types: packet filtering, proxy, and stateful inspection, and their impact on security.
Connect two networks using routers, which act as traffic cops. Create networks on each side with switches by linking devices, and understand routers' role for security design.
Load balancing distributes traffic across multiple web and database servers to prevent a single point of failure and improve performance, using round robin or other algorithms.
Discover how proxy servers act as intermediaries between clients and servers to improve efficiency, enable caching, filtering, and load balancing, and configure a browser to use a proxy.
Discover how intrusion detection systems monitor network traffic to detect intrusions and alert, while intrusion prevention systems block malicious traffic, with behavior-based, signature-based, and anomaly-based approaches.
Explore unified threat management (UTM) devices that consolidate firewall, intrusion prevention, gateway antivirus, anti-spam, VPN, content filtering, load balancing, and reporting into one box.
Explore how protocol analyzers, or packet sniffers, capture and log network traffic, reveal headers and data, and how encryption, SSL, VPNs, and encrypted archives protect against eavesdropping.
Learn to use a Windows network monitor to capture live traffic, view ARP and DNS requests, ping echoes, and inspect source and destination addresses to diagnose network activity.
Explore layered security and defense in depth across physical, data, and network layers, including dmz, lan, and nat, with authentication and authorization, encryption, and tunneling.
Learn about the DMZ, a demilitarized or perimeter network that isolates web servers from the internal network. Firewalls separate internet, DMZ, and internal networks to limit traffic and reduce intrusions.
Explore virtual local area networks and software-based segmentation that divide a LAN into subnets. VLANs reduce broadcast traffic and enhance security by isolating hosts on separate segments.
Identify common malware types—spyware, adware, rootkits, trojan horses, logic bombs, backdoors, botnets, and ransomware—and how malicious software exploits browser, firewall, and software weaknesses.
Viruses are code designed to infect computers and spread via infected DVDs, USB drives, email attachments, and downloads, causing slow performance and unusual files until antivirus eradicates them.
Explore eight common virus types—armored, companion, macro, multi partite, phage, polymorphic, retro, and stealth—and how they interrupt, destroy data, or capture information. Armored and macro viruses hide fingerprints.
Examine virus types like phage, polymorphic, retrovirus, and stealth viruses, how they mutate, encrypt, or move to boot sectors to evade detection, and update antivirus databases daily.
Antivirus software remains the main method to prevent virus infections by detecting and eradicating malware via signatures, fingerprint scanning, and regular updates across gateways, servers, and desktops.
Explore ten common attack types, from denial of service to privilege escalation, including spoofing, phishing, spearfishing, pharming, Christmas attack, man-in-the-middle, replay, and password attacks.
Explore the ten most common attack types, including man-in-the-middle with rogue routers, replay and smurf attacks, privilege escalation, and password attacks like brute force and rainbow table attack.
Identify common attacks, including malicious insiders, client-side threats, typo squatting, watering hole, and transitive access. Understand how insiders pose the greatest risk and how these attacks manifest across networks.
Examine common application attacks, including XSS and SQL injection, and learn how insecure input handling leads to directory traversal, command injection, and buffer overflows.
Explore common application attacks, including exit mail injection, SQL injection, directory traversal, OS command injection, buffer and integer overflows, zero-day exploits, and cookies and attachments risks.
Explore wireless network security, from easy setup to evolving protections, and prepare for the security plus exam by mastering the ATO 11 wireless protocols and common encryption techniques.
Explore the evolution of wireless protocols, covering 802.11a, 802.11b, 802.11g, and 802.11n, their frequencies, speeds, ranges, and MIMO (multiple input multiple output) boosting throughput and compatibility.
Learn about wireless encryption options, including WEP, WPA, and WPA2. Understand why WPA2 with AES is the current secure choice for protecting data on wireless networks.
Learn the basics of the wireless application protocol (wap), including the wireless markup language and wmlscript, device constraints, encryption, and end-to-end web transfer improvements.
Explain how extensible authentication protocol secures wireless access via an authentication server, and compare LEAP and PEAP as secure options with Windows support and encrypted channels.
Identify and mitigate wireless vulnerabilities by recognizing rogue access points, evil twin attacks, and replay attacks, plus jamming and interference, to protect wireless networks and prevent man-in-the-middle threats.
Apply the concept of application hardening by securely configuring server-side, web, and client applications, updating patches, and balancing interoperability with functionality.
Explore how databases store, manipulate, and retrieve data using relational database management systems and SQL, and compare one-tier, two-tier, and three-tier architectures for security and scalability.
Patches and updates close security holes as software grows more complex, covering service packs, patches, and hotfixes, with urgent hotfixes requiring prompt application and ongoing management of application patches.
Secure coding integrates security into the design and development process to prevent sql injection and other application-level attacks, with input validation and data verification taught via owasp and cert resources.
establish host security by enforcing up-to-date malware protection and a rigorous security baseline, then deploy antivirus, antispyware, spam filters, host-based firewall and ids to balance security and usability.
Understand how access control lists and permissions enforce least privilege by granting read, write, modify, read and execute, or full control on files and folders through ACLs.
Define and apply a security baseline across all computers to balance security and usability, using Microsoft Baseline Security Analyzer to scan hosts and enforce uniform settings across the network.
Hardening email and web servers with patches, updated security, minimal permissions, and ACLs while deploying virus scanners and spam filters to block attackers and reduce risk.
Secure dhcp by limiting server access, enabling audit logging of addresses and leases, and detecting rogue servers with Active Directory authorization and the dhcp loc tool.
Explore DNS security concepts, including DNSSEC and domain name system security extensions, to harden DNS servers against DNS denial of service, poisoning, and footprinting attacks.
Authorize a DHCP server in Windows Server 2012 using the DHCP manager to prevent rogue servers from handing out addresses, then activate the scope to start serving clients.
Learn how fault tolerance protects data by allowing systems to continue operating after a failure. Evaluate recovery time, data backups, RAID, clustering, and load balancing to maintain availability.
learn how raid uses multiple disks to protect data and fault tolerance, with striping, mirroring, and parity across raid 0, 1, and 5, plus hardware and software implementations.
Explore how clustering combines two or more computers into a single virtual server to provide fault tolerance and seamless failover, with active and passive cluster modes and heartbeat monitoring.
Construct a comprehensive backup plan by understanding full, differential, and incremental backups, and use archive bits and recovery testing to ensure rapid data restoration after a failure.
Explore full, differential, and incremental backups, how archive bits guide changes, and the recovery trade-offs between fast backups and longer restores.
This CompTIA Security+ training course from Infinite Skills will teach you everything you need to know to prepare for a career in IT security, and successfully complete the CompTIA Security+ certification.
You will start by learning to understand the risks, such as risk assessment, calculation, and management, and then move on to learning about network devices. This course will teach you about network design elements and wireless networks. This video tutorial also covers security threats, including viruses, antivirus software, and application attacks. You will also cover topics such as application security, data security, security in the cloud, and social engineering and physical security. Finally, you will learn the basics of monitoring networks, cryptography basics, security administration, and disaster recovery.
Once you have completed this computer based training course, you will have developed the knowledge necessary to successfully earn your CompTIA Security+ certification. Working files are included, allowing you to follow along with the author throughout the lessons.