
Explore fundamental security concepts and terms in topic a, and examine how domain and objective associations frame these core ideas.
Explain the CIA triad and how confidentiality, integrity, and availability guide security controls. Highlight encryption, file permissions, RBAC, hashing, and digital signatures to protect data and ensure non-repudiation.
Explore security terms like threats, actors, vectors, and vulnerabilities, and review attack types across social engineering, physical, network, and application-based vectors with examples such as key loggers and dns spoofing.
Identify and evaluate threat intelligence sources from vendor sites, vulnerability feeds, conferences, journals, RFCs, social media, and local industry groups, and map attacker TTPs to defend networks.
Explore threat intelligence feeds and vulnerability databases, including Proofpoint's emerging threats intel feed and FBI-backed sources, to classify IPs and domains and receive alerts via RSS or email.
Identify inherent vulnerabilities in systems, assess risk with threats and threat vectors, and apply updates, secure configurations, and third-party evaluations to minimize risk.
Identify how threats exploit vulnerabilities to realize risk, causing data loss, data breaches, financial and reputational impacts, and availability issues; protect with encryption, access controls, and DLP.
Explore third party and supply chain vulnerabilities, outsourced code risks, and data storage challenges, and learn automated patch management with monitoring across firmware, operating systems, and applications.
Explore physical attacks that use malicious USB cables, tainted flash drives, and auto-run weaknesses to compromise systems. Understand card cloning risks, magnetic stripes, NFC, skimming, and gas station vulnerabilities.
Social engineering exploits human behavior to manipulate individuals, preying on willingness to help and organizational culture of collaboration; attackers use authority, intimidation, urgency, and trust to coerce action.
Explore the components of a siem system, including alerts and reports driven by organizational rules, data inputs, packet capture, and log aggregation for monitoring and automated actions.
Explore different types of application attacks and their attributes, and learn to connect indicators to a specific attack type by analyzing a scenario aligned with security+ objective one.
Privilege escalation moves an attacker from a user level to root or admin by exploiting vulnerabilities, stealing credentials with sniffers and Windows/Linux password files, or injecting code into elevated processes.
Examine session attacks, including session replay and replay attacks that recreate prior client-server interactions. Understand integer overflow risks and types of request forgery such as server-side and cross-site forgery.
Identify network attacks at the infrastructure level of routers and switches across wired and wireless networks, using indicators to determine what is happening and the measures to defend against it.
Explore layer 2 attacks such as ARP poisoning, MAC flooding, and MAC cloning, and see how attackers achieve man-in-the-middle and on-path outcomes through malware-based man-in-the-browser techniques.
Explore how domain name system attacks threaten application layer services, including domain hijacking, DNS poisoning, URL redirection, and IP reputation, and defend against DNS-based DDoS and botnet-driven threats.
Explore how DNS poisoning corrupts the DNS server database and client DNS cache, using host file edits and lookups with nslookup or resolve-dns-name to demonstrate redirection and credential harvesting.
Exposes how malicious code targets remote systems through command-line vectors, using PowerShell, Python, Bash, and macros (VBA) to execute unmonitored scripts on Windows and Linux.
Learn security exercise types that mix offense and defense, and understand red (offense, often third-party), blue (in-house defense), white (judging), and purple (combined) team roles.
Examine security assessment tools and techniques, logging alerts, syslog, and SIEM utilities, analyze indicators of application and network attacks, and explore penetration testing as ethical hacking to improve organizational security.
Explore enterprise security architecture and design terminology, including configuration management, site resiliency, cloud, and virtualization concepts. Design authentication and authorization, ensure continuous availability, and secure development and deployment.
Explore site resiliency as part of disaster recovery, focusing on replicating data to a separate dr site in the cloud. Compare hot, warm, and cold sites by readiness and timelines.
Defend against advanced threats by using deception and disruption, deploying honeypots and honeynets, honey files, fake telemetry, and DNA sinkholes to mislead attackers.
Design authentication and authorization by identifying and implementing authentication methods, authentication factors, and attributes, and outlining authorization design concepts and requirements to align with the security plus exam objectives.
Explore how directory services like Active Directory and Azure AD manage accounts and synchronize identities across on-premises and cloud resources. Learn how attestation and multifactor authentication enable federation across platforms.
Explore authentication technologies, including time-based and HMAC-based one-time passwords and smart cards. Understand second factors from SMS, authenticator apps, push notifications, and phone calls.
Explore multifactor authentication by combining two factor authentication with factors and attributes—something you know, have, or are—along with geo fencing, actions, biometrics, and questions from external records.
Explore replication concepts as a form of redundancy, duplicating data through offsite backups, cloud replication, and mirrored storage in SANs and virtual machines to improve high availability.
Explore cloud types: public, private, community, and hybrid, and how multitenant security and shared infrastructure shape each choice. Learn when to reserve resources and apply security based on sensitivity.
Explore cloud computing security with Azure AD identity management, role-based access control, and conditional access policies, covering device compliance, e-discovery, data loss prevention, and governance in Azure and Office 365.
Review how development, test, staging, and production environments isolate code and data, using segregated hardware and access controls to prevent untrusted code from reaching production, while ensuring quality through testing.
Examine elasticity and scalability in cloud environments, including scaling out/in and pay-as-you-go hardware and IoT data, and learn version control, software diversity, secure application development, and binary diversity as defense.
Explore how cameras capture recording evidence and distinguish motion detection from object detection. Learn about CCTV, motion and noise sensors, temperature sensors, proximity readers, and visitor logs.
Explore security personnel categories and deployments—from guards and access control to video surveillance—along with two-person integrity controls, reception buffers, and robots or drones for patrol.
Explore data destruction software and physical destruction practices, including open-source tools and third-party shredding services, to ensure data sanitization, unrecoverable hard drive erasure, and organizational policy development.
Embedded systems integrate into larger systems, from controllers to cars, including devices like Raspberry Pi and Arduino, with security concerns shaped by deployment environments.
Explore additional system types, including voice over IP and real-time operating systems, emphasizing authentication, channel protection, and vulnerabilities from exploits and patches in devices like system on a chip.
Examine communication considerations in embedded systems and secure network choices, from 5G options to narrow band and baseband radios, SIM cards, and Ziggy low-power mesh sensors.
Explore physical security controls, budget considerations, and asset importance, and analyze how security posture affects organizational choices, plus security options for embedded specialized systems.
Explore the fundamentals of cryptography, including encryption and decryption to hide data from unauthorized users, and learn how public key infrastructure and digital certificates enforce enterprise security.
Explore how cryptography protects data by encrypting plain text into cipher text with algorithms and keys, enabling confidentiality, data at rest protection, and integrity verification.
Identify common cryptography use cases across devices and systems, including low power and low latency needs. Learn how confidentiality, integrity, authentication, obfuscation, and non-repudiation arise from cryptographic functions.
Learn how digital signatures use public key cryptography and hashing to verify message integrity, ensuring the sender's identity and that the contents remain unaltered.
Explore the public key infrastructure that enables secure communication through digital signatures and data encryption, detailing its hardware, applications, policy services, algorithms, and protocols.
Public key infrastructure, or PKI, manages key distribution and cryptographic techniques; certificate authorities issue certificates via templates tied to Windows AD users or smart cards, and they revoke as needed.
Verify certificate validity by expiration and revocation status. Learn traditional crl checks by the certificate authority and the efficient ocsp real-time status checks.
Examine online versus offline certificate authorities, root and subordinate CAs, certificate stapling, pinning, and cert chaining to establish a robust trust model.
Implement secure networks by outlining practical steps, secure protocols, and network devices and designs that bolster security. Compare cloud and on-prem implementations and address wireless security and secure mobile solutions.
Explore network segmentation through vlans and screened subnets, including dmz and extranet, and analyze east-west traffic within a zero-trust security model.
Explore secure network appliances, including jump servers, forward and reverse proxies, IDS/IPS, and hardware security modules, and compare signature-based, heuristic, and anomaly detection approaches, including inline and out-of-band deployment.
Compare cloud security controls and security solutions, implement data protection, and assess cloud native versus third-party solutions.
Learn cloud security controls within the shared responsibility model, covering encryption, policy enforcement, identity integration, and auditing across zones and data centers, including SOC 1, SOC 2, high-trust PCI.
Explore cloud network security with software defined networking, public and private subnets, remote access via vpn or jump server, and api content inspection with virtual firewalls.
Explore compute in the cloud, including processor and memory, security groups with firewall and identity access rules, plus dynamic resource allocation, instance awareness, VPC endpoints, and container security.
Explore additional cloud security solutions, including cloud access security brokers, next generation secure web gateways, and cloud native versus third-party controls, with emphasis on policy enforcement, auditing, and segmentation.
Plan wireless installations by site surveys, floor plan mapping, wifi analyzers, and heatmaps to optimize access point placement, coverage, and channel selection for 2.4 ghz and 5 ghz bands.
Explore mobile connection methods and receivers, including cellular, Wi-Fi, Bluetooth, NFC, GPS, RFID, infrared, and USB, and contrast point-to-point and point-to-multipoint architectures with security considerations.
Implement mobile device management by enforcing device locking, encryption, remote wipe, password policies, and app controls through a cloud-based solution like Intune to secure corporate data across devices.
Discusses mobile device security concepts, including microSD hardware security module keys within PKI, MDM and unified endpoint management, mobile application management, and Android's mandatory access control with deny everything.
Explore various additional controls managed via MDM, including cameras, SMS, external media, USB on-the-go, microphone, geotagging, ad hoc Wi-Fi, tethering, and payment methods to protect confidential data.
Explore role-based access control in Office 365 by assigning Azure AD and Exchange roles to a user, then demonstrate how limited rights reveal fewer admin options and PowerShell access.
Explore remote access authentication protocols, including chap, pap, and eap variants, 802.1x, and compare radius and tacacs+ for wireless and vpn access.
Explore identity concepts and practices, review different account types and account policies, and learn to implement identity and account management controls.
Account policies translate password and access rules into enforceable controls via group policy or Intune MDM, covering password complexity, history, reuse, location-based access, time restrictions, and lockout or disable controls.
Explore identity terms like attributes and certificates, and learn how dynamic access control, authentication through digital certificates, and smart cards enable access tokens and single sign-on.
Implement host and application security solutions by deploying endpoint protection and antivirus, securing machines and the applications running on them within the enterprise security program.
Extend the security perimeter to devices joining the network and standardize controls, using antivirus, malware endpoint detection and response, data loss prevention, firewalls, and host-based intrusion detection.
Harden endpoints by reducing vulnerabilities, closing extraneous ports and services, securing registry with policy controls, enabling disk encryption, and enforcing centralized patch management.
Explore authentication and authorization concepts and protocols, implement account management controls with password and account lock-out policies, and secure endpoints across host, operating system, storage, and applications.
Explore operational procedures for security assessment by using Windows and Linux tools to evaluate an organization’s security, use data sources for investigation, and apply mitigation techniques to reduce risk.
Explore using four core tools to assess security, focusing on command-line utilities and building competency in essential security functions for organizational assessments, aligned with the security plus exam objective.
Identify key digital forensics tools such as deedi, meme dump, hex, fta imager, and autopsy, and learn their purposes in data gathering, memory analysis, and disk imaging.
Log files provide a historical record for investigations across operating system, system, application, and security logs, with balanced logging to avoid data overload and enable analysis using syslog-ng and Nextlog.
Bandwidth monitors track utilization and who uses it over time, while protocol analyzers like NetFlow and CE flow capture packet flows for centralized monitoring.
Explore endpoint security solutions, including antivirus and application control policies, and learn whitelist/blacklist methods via Group Policy in Active Directory with quarantine mechanisms.
Learn isolation and segmentation techniques, containment strategies, and secure orchestration, automation, and response to accelerate incident response with runbooks and playbooks.
Explore security tools and procedures that scan networks for faults and attacks using Windows and Linux apps. Use diverse log sources for investigations and apply mitigations through policies and controls.
Learn how incident response planning and digital forensics extend security policies and procedures, equipping you to prepare for breaches and use scientific methods to solve computer-related events.
Explore the mider attack framework, the diamond model, and the cyber kill chain to map attacker actions and prioritize defenses.
Outline how incident response extends into a communications plan, escalation processes, and information flow, prepared in advance. Explain disaster recovery, backups, business continuity planning, and SOPs to sustain essential operations.
Explore evidence categories, identifying direct, real (associative) or physical, documentary, and demonstrative evidence, and see how digital forensics applies these concepts to computer crimes.
Information and network security has become an important topic of discussion in recent times and the focus of almost every organization on information and network security is increasing with each passing day. This is primarily due to increased reliance on digital systems for day-to-day operations. There is a substantial amount of data residing on the digital systems that lures hackers and state actors towards illegally accessing and using it for monetary benefits and other political reasons.
This course prepares the candidates to appear in the CompTIA Security+ (SY0-601) exam. The CompTIA Security+ exam is a foundational exam for aspiring information security professionals and enables them to understand different threats, analyze attacks, learn cryptography, implement secure networks, devise operational procedures, perform forensic analysis and more to ensure integrity and protection of sensitive data.
This course also provides the basis to build on the knowledge gained and advance towards other professional certifications in the field of information and network security. This can be a great career move for young IT professionals to explore the in-demand network and information security arena.
The CompTIA Security+ is the premier vendor-neutral security certification. This preparatory course for the CompTIA Security+ certification exam assures that the students completely learn and understand the exam topics of the latest SY0-601 exam version. The students will be able to demonstrate their knowledge of security concepts, tools, and procedures. It also confirms their ability to react to security incidents, and validates their skills in anticipating security risks and guarding against them.
Overall, the course is very well designed to give a detailed overview of network and information security concepts and practical implications to the students. This helps them to appear in the CompTIA Security+ exam as well as polish their skills to improve their productivity in their jobs.