
Explore the LPI Security Essentials 020-100 exam, its five domains and objectives, to build foundational cybersecurity knowledge for protecting personal devices, data, and privacy.
Please download the following file to use during your studies for the certification exam from this lesson.
Explore the fundamentals of cybersecurity, defining threats, vulnerabilities, and risk while comparing information security with information systems security, and introduce CIA triad, the three A's, threat actors, and basic controls.
Explore the three a's of security, authentication, authorization, and accounting, and learn how identity verification, access control, and activity logging protect digital systems.
Master risk mitigation by exploring physical, technical, and administrative controls and their defense-in-depth approach, including access control, encryption, IDS, and regulatory requirements like HIPAA and GDPR.
Identify threat actors across seven types—script kiddies, insider threats, competitors, organized crime, hacktivists, nation-state actors, and supply chain threats—using social engineering, phishing, fingerprinting, service discovery, lateral movement, and data theft.
Explore the diverse roles in cybersecurity, from technicians to the chief information security officer, and learn how teams handle incidents, attribution, and defense.
Explore the MITRE ATT&CK framework, a knowledge base of tactics and techniques used by APTs like APT 28, and learn how threat intelligence informs detection, mitigation, and incident response.
Identify and manage cybersecurity risks by examining risk assessment methodologies, including qualitative and quantitative approaches, and implementing security controls, vulnerability assessments, and incident response processes.
Explore how security assessments—vulnerability assessments, penetration testing, audits, self-assessments, and password analysis—evaluate an organization's security posture within risk analysis and PCIDSS/FSMA contexts, using active and passive methodologies.
Explore security control types: physical, technical, and administrative—and their management, operational, and technical categories, plus preventive, detective, and compensating controls.
Identify vulnerabilities via a vulnerability assessment to understand risk and guide accept, mitigate, transfer, or avoid, using automated tools and three-step process: collect target attributes, analyze differences, and report results.
Learn to validate vulnerability reports by identifying findings as true positives, false positives, true negatives, or false negatives, and manage exceptions via reconciliation, correlation with logs, and best-practice comparisons.
Explore zero-day vulnerabilities and exploits, how attackers exploit unknown flaws before patches, why antivirus often misses them, and the high-stakes use in espionage and crime.
Explain privacy versus security within the CIA triad, highlighting encryption, hashing. Summarize GDPR, SOX, GLBA, FISMA, HIPAA, and COSO ERM and their roles in consent and breach notification.
Discover how bug bounty programs crowdsource security testing for software, services, and applications by rewarding ethical hackers to identify and report vulnerabilities within defined scope.
Understand copyright law and intellectual property to protect data in cybersecurity, including open-source licenses, trade secrets, and landmark cases like Waymo v. Uber and Oracle v. Google.
Define data ownership roles—data owner, data steward, data custodian, and privacy officer—and emphasize stakeholder input for data classification. Protect confidential information with controls, encryption, backups, and data handling policies.
Learn how ransomware locks files and demands payment, why experts advise against paying, and how backups and security measures prevent costly attacks, illustrated by the 2018 Atlanta case.
Explore how backdoors, logic bombs, and remote access trojans threaten secure coding and network integrity. Learn how Easter eggs introduce vulnerabilities and why patching keeps systems secure.
Identify malware symptoms, scan to verify infection, and back up the system before cleanup. Quarantine the device, disable system restore, remediate with safe-mode scans, and schedule updates and end-user training.
Block viruses, worms, trojans, ransomware, spyware, and rootkits with current antivirus and anti-malware tools; patch the operating systems and apps regularly; educate users on safe, encrypted internet surfing.
Demonstrates creating and delivering a simple virus and a remote access trojan, using social engineering, binding techniques, and RAT features to monitor and control a victim machine.
Learn how spam filters detect and block unwanted emails using content-based filtering, blacklisting, whitelisting, and Bayesian methods, and secure handling of email attachments through virus scans and encryption.
Explore how impersonation leverages uniforms and trusted identities to gain access during physical and remote assessments, and master elicitation to elicit staff information and actions.
Explore social engineering attacks, including tailgating, piggybacking, shoulder surfing, eavesdropping, and dumpster diving, and learn how to train users to guard against human vulnerabilities.
Identify frauds, scams, and hoaxes as social engineering, including identity theft and invoice scams. Learn to recognize prepending and scareware, verify software legitimacy, and avoid clicking suspicious links.
Train users in security awareness to avoid sharing credentials, shield PINs, apply a clean desk policy, encrypt emails and data, log suspicious events, and follow disposal and web usage guidelines.
Use Phish Insights, a free tool from Trend Micro, to create phishing campaigns that test users and deliver remedial training while analyzing results.
Implement trusted computing to strengthen hardware security using TPM and Secure Boot, store keys securely, and ensure devices boot from trusted software while combining antivirus and firewalls.
Explore USB interfaces, types, and connections—from USB-A, USB-B, to USB-C—while learning security best practices to prevent malware, data theft, and network access risks.
Explore RFID devices, active and passive, NFC, LF, HF, and UHF connections, relay attacks, and encryption and authentication to prevent data theft and unauthorized access.
Install applications from legitimate sources, understand licensing, and verify downloads with hash checks for firmware, OS, desktop, mobile, and server software.
Download apps only from official app stores, where hashes verify integrity and security reviews ensure safe software; avoid third-party stores and jailbreaking to reduce malware and security risks.
Explain how a buffer overflow occurs when memory is overrun, spilling data from the stack, and highlight concepts like smashing the stack, nop slide, and ASLR.
Explore security applications like endpoint security, endpoint firewalls, packet filtering firewalls, application layer firewalls, antivirus, anti-malware, and host-based intrusion detection or prevention systems to build defense in depth.
Demonstrates a buffer overflow attack in the C program narnia0.c, overflowing a 20 character buffer to 0xdeadbeef and triggering a shell through crafted input.
Explore how SQL injections exploit user input to run malicious SQL against a database, including login forms, and how input validation and sanitizing data prevent these attacks.
Explore the fundamentals of computer networks, including osi and tcp/ip models, tcp and udp transport, switches and routers, ipv4/ipv6 addressing, dns, routing, and isp roles, with emphasis on security.
Explore essential networking hardware—nics, hubs, switches, wireless access points, routers, firewalls, patch panels, poe, cable and dsl modems, onts, and sdn—and learn how they enable secure data transmission.
Compare the tcp/ip model with the osi model, detailing four layers—network interface, internet, transport, and application—and how the top osi layers form the application layer.
Explore IPv4 addressing, including dotted decimal notation, octets, 32-bit space, subnet masks, classful and CIDR subnetting, private vs public IPs, NAT, and essential IPv4 concepts like loopback and APIPA.
Assign IPv4 addresses by comparing static and dynamic methods, including DHCP, BOOTP, APIPA, and zero config, and configure IP, subnet mask, gateway, and DNS.
Explore how data transfers use ip addresses and ports to route traffic. Compare tcp and udp headers, well-known and ephemeral ports, and how a client-server session uses port 80.
Understand the domain name system (dns) concepts, including fully-qualified domain names (fqdn), top-level and second-level domains, internal and external dns, dns records, ttl, and recursive versus iterative lookups.
Identify how internet service providers deliver connectivity using cable and fiber modems, satellite and cellular options, and media converters, with Cat6 and a wireless access point.
Explore wired and wireless network security concepts, threat mitigation, and secure connections. Learn about firewalls, ids/ips, nac, wireless encryption (wpa2/3, aes), and configuring small office networks.
Explore wired network security by examining switches, CAM tables, and MAC filtering to prevent MAC flooding, ARP poisoning, and VLAN exploits while implementing 802.1x, STP, and DHCP snooping.
Protect networks by scanning devices before granting access, quarantining those that fail, and enabling remediation to meet security requirements. Explore persistent, non-persistent, and volatile agent-based NAC approaches.
Configure a non-personal ssid and enable strongest encryption (prefer WPA3 or WPA2 with AES/CCMP), disable guest access, and use 1,6,11 on 2.4 gigahertz with auto on 5 and 6 gigahertz.
Configure a secure small office wireless network by using WPA2 with AES, a strong pre-shared key, disable SSID broadcast, use channels 1, 6, and 11, and turn off WPS.
** Taught by a Best Selling IT Certification Instructor **
Taught by an expert in information technology and cybersecurity with over 20 years of experience, this course is a fun way to master the fundamentals of cloud computing.
My name is Jason Dion, and I have personally helped over 1,000,000 students earn their IT certifications, and now I can help you, too!
Along with my co-instructor, Kip Boyle, we are going to teach you the fundamentals of cybersecurity and how to stay safe while online!
In today's digital age, IT security is vital for both individuals and organizations. Protecting data, devices, and networks is crucial in responsible information technology use. The Linux Professional Institute Security Essentials certificate provides an opportunity to learn and demonstrate expertise in the field. The exam covers essential IT security fields, making it suitable for students, staff, and organizations seeking to improve their security. It's also ideal for individuals looking to gain basic competence in secure information technology use.
In this course, you will get access to all of our lessons, lectures, and video demonstrations to teach you everything you need to know to pass the LPI Security Essentials exam.
LPI Security Essentials (020-100) is the best way to gain a fundamental understanding of cybersecurity and is designed for both IT and non-technical professionals who need to make informed security choices while using the Internet so they don't fall victim to cyber attacks and data breaches.
This course is designed to help prepare you for the LPI Security Essentials (020-100) certification exam and covers all five domains of the LPI Security Essentials (020-100)certification exam:
1. Security Concepts (12.5%)
2. Encryption (22.5%)
3. Device and Storage Security (22.5%)
4. Network and Service Security (25%)
5. Identity and Privacy (17.5%)
What You Will Receive In The Course:
· Video lectures with the essential information needed to pass the LPI Security Essentials (020-100) exam
· A complete downloadable study guide in PDF format based on the lessons
· Practice quizzes to ensure mastery of each section of the course
· A full-length practice exam with multiple choice and mock simulations
This course stays current and up-to-date with the latest release of the LPI Security Essentials exam (020-100), and also provides a 30-day money-back guarantee if you are not satisfied with the quality of this course for any reason!
What Other Students Are Saying About Our Other Certification Courses:
· I passed the Security+ exam. This course was absolutely essential to passing that exam. Only the Dion Security+ covered the topics comprehensively and thoroughly enough. No other resource I used came close. (Kolya, 5 stars)
· I have just completed watching two different instructor courses on the same subject. I must say, Dion's has more information in a better constructed manner. This course is not easy, it is heavy with information and having you sit through shorter videos was the best part. Having watched more than just Dion's, I can say he goes over the content much better. Very glad I chose to watch a second course! (Rutger, 5 stars)
· I love taking this wonderful course. It's full of important tips and amazing steps in order to pass CompTIA Security+. Thank you, Jason Dion, for making this incredible course! (Paul, 5 stars)
Upon completion of this course, you will earn 18 CEUs towards the renewal of your CompTIA A+, Network+, Security+, Linux+, Cloud+, PenTest+, CySA+, or CASP+ certifications.