Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CompTIA Security+ (SY0-601)
Rating: 4.6 out of 5(18 ratings)
139 students

CompTIA Security+ (SY0-601)

Certificate Exam Preparatory Course
Last updated 6/2023
English
English

What you'll learn

  • Threats, Attacks, and Vulnerabilities: Identify and analyze potential security risks, understand various types of attacks, and know how to mitigate and respo
  • Technologies and Tools: Understand the different security technologies and tools used in securing network devices, data, and communication channels.
  • Architecture and Design: Implement secure network architectures and designs, secure systems and applications, and know the different security models.
  • Identity and Access Management: Implement identity and access management, such as authentication and authorization, for users, devices, and applications.
  • Risk Management: Identify, assess, and respond to security risks using risk management frameworks, policies, and procedures.
  • Cryptography and PKI: Understand and apply cryptography and public key infrastructure (PKI) in securing data and communication channels.
  • Cloud and Virtualization: Implement security in cloud and virtualized environments, understand the different cloud models and know how to secure them.
  • Resilience and Incident Response: Implement incident response and recovery procedures, and understand the importance of business continuity and disaster reco
  • Governance, Risk, and Compliance: Understand the legal and regulatory requirements and standards for security, such as GDPR and HIPAA, and know how to comply

Course content

8 sections92 lectures28h 44m total length
  • Overview5:34

    Introduce the CompTIA Security+ (SY0-601) exam series and foundational security concepts, outlining objectives, study resources, and the exam structure including attacks and threats.

  • Social Engineering Techniques20:21

    Learn how social engineering exploits people, with phishing, vishing, smishing, spear phishing, and whaling, and how the CIA triad, threats, and user awareness shape defense.

  • Malware20:00

    Explore the spectrum of malware, from viruses and worms to fileless viruses, rootkits, and ransomware, and learn how each type infects, propagates, and evades detection for the security+ exam.

  • Password Attacks - Types12:34

    Explore how password attacks exploit authentication systems through brute force, dictionary, rainbow tables, and spraying methods to gain privileged access.

  • Password Attacks - Tools14:39

    Explore online versus offline password attacks and key tools such as John the Ripper, Hashcat, Hydra, and Burp Suite, including wordlist generation and hash extraction techniques.

  • Application Attacks - Injections18:47

    Learn how injection-based attacks exploit untrusted input in web apps. Explore sql, ldap, xml (xxe), dll, and command injections and their impacts like data loss and denial of service.

  • Application Attacks - System Resources20:37

    Explore application attacks that drain system resources, including CPU, memory, network, and storage. Learn about memory leaks, buffer and integer overflows, race conditions, TOC TOU, and driver manipulation.

  • Application Attacks - XSS and XSRF11:56

    Explain cross site scripting and cross site request forgery, detailing reflected XSS, stored XSS, and DOM-based XSS, and compare server-side versus client-side CSRF risks.

  • Application Attacks - Replay Attacks12:12

    Explore replay attacks and how retransmitted data from packet sniffing enables attackers. Discover defenses such as time stamping, sequencing, and ipsec or tcp/ip safeguards.

  • Network Attacks - DNS Attacks20:25

    Explore how DNS resolves host names to IP addresses using caching, root and TLD lookups, A/AAAA records, and how poisoning, hijacking, or domain hijacking redirects users to malicious sites.

  • Network Attacks - Layer 2 Attacks19:49

    Examine layer 2 attacks—ARP poisoning, MAC cloning, and MAC flooding—and understand how ARP operates with MAC addresses on the data link layer within a local network.

  • Network Attacks - DoS and DDoS13:13

    Explains denial of service and distributed denial of service attacks, including reflected, amplified, and coordinated methods, how botnets and spoofed IPs overwhelm targets.

  • Network Attacks - MiTM and MiTB11:45

    Explore man-in-the-middle and man-in-the-browser attacks, their use of cleartext protocols, session hijacking, and crafted requests, and how secure protocols like ssh mitigate risk.

  • Network Attacks - Wireless20:31

    Explore common wireless network attacks, including rogue access points and evil twins, disassociation and initialization vector vulnerabilities, and Bluetooth and RFID/NFC threats and relay attacks.

  • Vulnerabilities19:54

    Identify common vulnerabilities across systems, from weak configurations and defaults to weak encryption and open permissions. Manage third-party risks and patch management to protect on-premises and cloud environments.

  • Threat Intelligence - OSINT12:30

    Explore open source intelligence (OSINT) as the practice of gathering and analyzing publicly available data to identify external threats and strengthen defense strategies.

  • Threat Intelligence - Threat Maps and Feeds13:06

    Explore threat maps and feeds to visualize real time threats and identify indicators of compromise. Learn how STIX, TAXII, and automated indicator sharing enable rapid threat intelligence for malware defense.

  • Threat Intelligence Vulnerability Databases Feed18:20

    Explore vulnerability databases and feeds, including MITRE's CVE and the NVD, with SCAP, CPE, and CVSS, to track vulnerabilities and inform patching for security analysts.

  • Threat Actors and Vectors20:30

    Threat actors range from script kiddies to insiders, hacktivists, APTs, state actors, criminal syndicates, and competitors. Understand their access, motivations, and vectors like phishing, insider access, shadow IT, and cloud.

Requirements

  • The CompTIA Security+ certification does not have any formal prerequisites. However, CompTIA recommends that candidates have at least two years of experience in IT administration with a focus on security. This experience should include configuring, installing, and troubleshooting network security devices, such as firewalls, routers, and switches.

Description

The CompTIA Security+ certification is a vendor-neutral cybersecurity certification that validates the knowledge and skills of IT professionals in the area of network security, compliance, and operational security. The certification is designed to test the essential security knowledge and skills required to perform core security functions and pursue an IT security career.

The CompTIA Security+ certification is designed for IT professionals who want to specialize in network security, cybersecurity, and IT risk management. The certification validates their knowledge and skills in these areas and demonstrates their ability to secure network infrastructure, identify and mitigate risks, and respond to security incidents.

CompTIA also recommends that candidates have a basic understanding of the following topics:

  1. Network protocols and architecture

  2. Network hardware and operating systems

  3. General security concepts, such as authentication and authorization

  4. Basic cryptography concepts, such as symmetric and asymmetric encryption

  5. Common security threats and vulnerabilities

While these topics are not required to take the Security+ exam, having a basic understanding of them can help candidates prepare for the certification exam and increase their chances of success.

Overall, the CompTIA Security+ certification is suitable for anyone who wants to gain a foundational understanding of cybersecurity concepts and best practices and advance their career in the IT security field.


"This course qualifies for CompTIA continuing education units (CEUs)."

Available CEUs* for this Course Series : 28

By completing this course series, you can earn up to 28 CEUs.

(*CEUs are entirely dependent on the organization you are applying)

Who this course is for:

  • Security Professionals
  • Network Administrators
  • Systems Administrators
  • IT Managers
  • Security Analysts
  • Compliance Officers
  • Entry-Level IT Professionals