CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021)

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) provides everything you need to pass your certification test.

David Miller
Contributor
4.9
88
9 months ago
Preview (31 of 821 Pages)
100%
Purchase to unlock

Page 1

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 1 preview image

Loading page image...

Page 2

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 2 preview image

Loading page image...

DownloadedfromStudyXY.com[=Ww+StudyXYoias.Za\Rr'BE\StudyAnythingThisContentHasbeenPostedOnStudyXY.comassupplementarylearningmaterial.StudyXYdoesnotendroseanyuniversity,collegeorpublisher.Allmaterialspostedareundertheliabilityofthecontributors.|8)www.studyxy.com

Page 3

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 3 preview image

Loading page image...

Page 4

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 4 preview image

Loading page image...

Page 5

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 5 preview image

Loading page image...

ABOUTTHEAUTHORSBrentChapman,GCIH,GCFA,GCTI,CISSP,CySA+,isaninformationsecurityengineerwithmorethan15yearsofexperienceininformationtechnologyandcybersecurity.HeisaformercyberoperationsofficerintheUnitedStatesArmyandhasheldanumberofuniqueassignments,includingresearcherattheArmyCyberInstitute,instructorintheDepartmentofElectricalEngineeringandComputerScienceattheUSMilitaryAcademyatWestPoint,andprojectmanagerattheDefenseInnovationUnitinSiliconValley.HeisaprofessionalmemberoftheAssociationofComputingMachinery,FCCAmateurRadiolicenseholder,andcontributortoseveraltechnicalandmaker-themedpublications.FernandoJ.Maymi,PhD,CISSP,isaconsultant,educator,andauthorwithmorethan25yearsofexperienceininformationsecurity.Hecurrentlyleadsteamsofcybersecurityconsultants,analysts,andredteamersinprovidingservicesaroundtheworld.FernandowasthefoundingdeputydirectoroftheArmyCyberInstitute,agovernmentthinktankhehelpedcreatefortheSecretaryoftheArmytosolvefuturecyberspaceoperationsproblemsaffectingthewholecountry.Hehasservedasadvisortocongressionalleaders,corporateexecutives,andforeigngovernmentsoncyberspaceissues.FernandotaughtcomputerscienceandcybersecurityattheUSMilitaryAcademyatWestPointfor12years.Fernandohaswrittenextensivelyandistheco-authoroftheeightheditionofthebestsellingCISSPAll-in-OneExamGuide.AbouttheTechnicalEditorandContributorBobbyE.Rogersisacybersecurityprofessionalwithover30yearsintheinformationtechnologyandcybersecurityfields.HecurrentlyworksforamajorengineeringcompanyinHuntsville,Alabama,asacontractorfor

Page 6

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 6 preview image

Loading page image...

DepartmentofDefenseagencies,helpingtosecure,certify,andaccredittheirinformationsystems.Bobby’sspecialtiesarecybersecurityengineering,securitycompliance,andcyberriskmanagement,buthehasworkedinalmosteveryareaofcybersecurity,includingnetworkdefense,computerforensics,incidentresponse,andpenetrationtesting.HeisaretiredMasterSergeantfromtheUSAirForce,havingservedforover21years.BobbyhasbuiltandsecurednetworksintheUnitedStates,Chad,Uganda,SouthAfrica,Germany,SaudiArabia,Pakistan,Afghanistan,andseveralothercountriesallovertheworld.HeholdsaMasterofSciencedegreeinInformationAssuranceandiscurrentlywritinghisdissertationforadoctoraldegreeincybersecurity.HismanycertificationsincludeCISSP-ISSEP,CRISC,andCySA+.Hehasnarratedandproducedover30computersecuritytrainingvideosforseveraltrainingcompanies,andisalsotheauthorofCompTIAMobility+CertificationAll-In-OneExamGuide(ExamMB0-001),CRISCCertifiedinRiskandInformationSystemsControlAll-In-OneExamGuide,MikeMeyers’CompTIASecurity+CertificationGuide(ExamSY0-401),andcontributingauthor/technicaleditorforthepopularCISSPAll-In-OneExamGuide,EighthEdition,allfromMcGrawHill.

Page 7

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 7 preview image

Loading page image...

Page 8

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 8 preview image

Loading page image...

Page 9

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 9 preview image

Loading page image...

Copyright©2021byMcGrawHill.Allrightsreserved.ExceptaspermittedundertheUnitedStatesCopyrightActof1976,nopartofthispublicationmaybereproducedordistributedinanyformorbyanymeans,orstoredinadatabaseorretrievalsystem,withoutthepriorwrittenpermissionofthepublisher.ISBN:978-1-26-046431-3MHID:~~1-26-046431-8ThematerialinthiseBookalsoappearsintheprintversionofthistitle:ISBN:978-1-26-046430-6,MHID:1-26-046430-X.eBookconversionbycodeMantraVersion1.0Alltrademarksaretrademarksoftheirrespectiveowners.Ratherthanputatrademarksymbolaftereveryoccurrenceofatrademarkedname,weusenamesinaneditorialfashiononly,andtothebenefitofthetrademarkowner,withnointentionofinfringementofthetrademark.Wheresuchdesignationsappearinthisbook,theyhavebeenprintedwithinitialcaps.McGraw-HillEducationeBooksareavailableatspecialquantitydiscountstouseaspremiumsandsalespromotionsorforuseincorporatetrainingprograms.Tocontactarepresentative,pleasevisittheContactUspageatwww.mhprofessional.com.InformationhasbeenobtainedbyMcGrawHillfromsourcesbelievedtobereliable.However,becauseofthepossibilityofhumanormechanicalerrorbyoursources,McGrawHill,orothers,McGrawHilldoesnotguaranteetheaccuracy,adequacy,orcompletenessofanyinformationandisnotresponsibleforanyerrorsoromissionsortheresultsobtainedfromtheuseofsuchinformation.TERMSOFUSEThisisacopyrightedworkandMcGraw-HillEducationanditslicensorsreserveallrightsinandtothework.Useofthisworkissubjecttothese

Page 10

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 10 preview image

Loading page image...

terms.ExceptaspermittedundertheCopyrightActof1976andtherighttostoreandretrieveonecopyofthework,youmaynotdecompile,disassemble,reverseengineer,reproduce,modify,createderivativeworksbasedupon,transmit,distribute,disseminate,sell,publishorsublicensetheworkoranypartofitwithoutMcGraw-HillEducation’spriorconsent.Youmayusetheworkforyourownnoncommercialandpersonaluse;anyotheruseoftheworkisstrictlyprohibited.Yourrighttousetheworkmaybeterminatedifyoufailtocomplywiththeseterms.THEWORKISPROVIDED“ASIS.”McGRAW-HILLEDUCATIONANDITSLICENSORSMAKENOGUARANTEESORWARRANTIESASTOTHEACCURACY,ADEQUACYORCOMPLETENESSOFORRESULTSTOBEOBTAINEDFROMUSINGTHEWORK,INCLUDINGANYINFORMATIONTHATCANBEACCESSEDTHROUGHTHEWORKVIAHYPERLINKOROTHERWISE,ANDEXPRESSLYDISCLAIMANYWARRANTY,EXPRESSORIMPLIED,INCLUDINGBUTNOTLIMITEDTOIMPLIEDWARRANTIESOFMERCHANTABILITYORFITNESSFORAPARTICULARPURPOSE.McGraw-HillEducationanditslicensorsdonotwarrantorguaranteethatthefunctionscontainedintheworkwillmeetyourrequirementsorthatitsoperationwillbeuninterruptedorerrorfree.NeitherMcGraw-HillEducationnoritslicensorsshallbeliabletoyouoranyoneelseforanyinaccuracy,errororomission,regardlessofcause,intheworkorforanydamagesresultingtherefrom.McGraw-HillEducationhasnoresponsibilityforthecontentofanyinformationaccessedthroughthework.UndernocircumstancesshallMcGraw-HillEducationand/oritslicensorsbeliableforanyindirect,incidental,special,punitive,consequentialorsimilardamagesthatresultfromtheuseoforinabilitytousethework,evenifanyofthemhasbeenadvisedofthepossibilityofsuchdamages.Thislimitationofliabilityshallapplytoanyclaimorcausewhatsoeverwhethersuchclaimorcausearisesincontract,tortorotherwise.

Page 11

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 11 preview image

Loading page image...

ToGinaandCarol,forbeingpatient,supportive,andloving,andforremindingusofwhatreallymattersinlife.

Page 12

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 12 preview image

Loading page image...

CONTENTSATAGLANCEPartIThreatandVulnerabilityManagementChapter1TheImportanceofThreatDataandIntelligenceChapter2ThreatIntelligenceinSupportofOrganizationalSecurityChapter3VulnerabilityManagementActivitiesChapter4VulnerabilityAssessmentToolsChapter5ThreatsandVulnerabilitiesAssociatedwithSpecializedTechnologyChapter6ThreatsandVulnerabilitiesAssociatedwithOperatingintheCloudChapter7MitigatingControlsforAttacksandSoftwareVulnerabilitiesPartIISoftwareandSystemsSecurityChapter8SecuritySolutionsforInfrastructureManagementChapter9SoftwareAssuranceBestPracticesChapter10HardwareAssuranceBestPracticesPartIIISecurityOperationsandMonitoringChapter11DataAnalysisinSecurityMonitoringActivitiesChapter12ImplementConfigurationChangestoExistingControlstoImproveSecurityChapter13TheImportanceofProactiveThreatHuntingChapter14AutomationConceptsandTechnologies

Page 13

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 13 preview image

Loading page image...

PartIVIncidentResponseChapter15TheImportanceoftheIncidentResponseProcessChapter16AppropriateIncidentResponseProceduresChapter17AnalyzePotentialIndicatorsofCompromiseChapter18UtilizeBasicDigitalForensicsTechniquesPartVComplianceandAssessmentChapter19TheImportanceofDataPrivacyandProtectionChapter20SecurityConceptsinSupportofOrganizationalRiskMitigationChapter21TheImportanceofFrameworks,Policies,Procedures,andControlsPartVIAppendixesandGlossaryAppendixAObjectiveMapAppendixBAbouttheOnlineContentGlossaryIndex

Page 14

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 14 preview image

Loading page image...

CONTENTSAcknowledgmentsIntroductionPartIThreatandVulnerabilityManagementChapter1TheImportanceofThreatDataandIntelligenceFoundationsofIntelligenceIntelligenceSourcesOpenSourceIntelligenceProprietary/ClosedSourceIntelligenceCharacteristicsofIntelligenceSourceDataConfidenceLevelsIndicatorManagementIndicatorLifecycleStructuredThreatInformationExpressionTrustedAutomatedExchangeofIndicatorInformationOpenlOCThreatClassificationKnownThreatsvs.UnknownThreatsZeroDayAdvancedPersistentThreatThreatActorsNation-StateThreatActorsHacktivistsOrganizedCrimeInsiderThreatActorsIntelligenceCycle

Page 15

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 15 preview image

Loading page image...

RequirementsCollectionAnalysisDisseminationFeedbackCommodityMalwareInformationSharingandAnalysisCommunitiesChapterReviewQuestionsAnswersChapter2ThreatIntelligenceinSupportofOrganizationalSecurityLevelsofIntelligenceAttackFrameworksMITREATT&CKTheDiamondModelofIntrusionAnalysisKillChainThreatResearchReputationalBehavioralIndicatorofCompromiseCommonVulnerabilityScoringSystemThreatModelingMethodologiesAdversaryCapabilityTotalAttackSurfaceAttackVectorImpactLikelihoodSTRIDEPASTAThreatIntelligenceSharingwithSupportedFunctionsIncidentResponseVulnerabilityManagementRiskManagementSecurityEngineering

Page 16

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 16 preview image

Loading page image...

DetectionandMonitoringChapterReviewQuestionsAnswersChapter3VulnerabilityManagementActivitiesVulnerabilityIdentificationRegulatoryEnvironmentsCorporateSecurityPolicyDataClassificationAssetInventoryActivevs.PassiveScanningScanningParametersandCriteriaRisksAssociatedwithScanningActivitiesRegulatoryRequirementsTechnicalConstraintsWorkflowSensitivityLevelsVulnerabilityFeedScopeNoncredentialedvs.CredentialedServerBasedvs.AgentBasedInternalvs.ExternalTypesofDataToolUpdatesandPlug-InsSCAPSpecialConsiderationsIntrusionPreventionSystem,IntrusionDetectionSystem,andFirewallSettingsGeneratingReportsAutomatedvs.ManualDistributionValidationTruePositivesFalsePositivesTrueNegatives

Page 17

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 17 preview image

Loading page image...

FalseNegativesRemediationPatchingPrioritizingHardeningCompensatingControlsRiskAcceptanceVerificationofMitigationInhibitorstoRemediationMemorandumofUnderstandingServiceLevelAgreementOrganizationalGovernanceBusinessProcessInterruptionDegradingFunctionalityLegacyandProprietarySystemsOngoingScanningandContinuousMonitoringChapterReviewQuestionsAnswersChapter4VulnerabilityAssessmentToolsWebApplicationScannersOWASPZedAttackProxyBurpSuiteNiktoArachniInfrastructureVulnerabilityScannersNessusOpenVASQualysSoftwareAssessmentToolsandTechniquesStaticAnalysisDynamicAnalysisReverseEngineeringFuzzing

Page 18

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 18 preview image

Loading page image...

EnumerationToolsandTechniquesnmaphpingPassivevs.ActiveEnumerationTechniquesresponderWirelessAssessmentToolsAircrack-ngReaveroclHashcatCloudInfrastructureAssessmentToolsScoutSuiteProwlerPacuChapterReviewQuestionsAnswersChapter5ThreatsandVulnerabilitiesAssociatedwithSpecializedTechnologyAccessPointsVirtualPrivateNetworksMobileDevicesNetworkVulnerabilitiesDeviceVulnerabilitiesOperatingSystemVulnerabilitiesAppVulnerabilitiesInternetofThingsTheMiraiBotnetEmbeddedSystemsReal-TimeOperatingSystemsSystemonaChipFieldProgrammableGateArrayPhysicalAccessControlConnectedVehiclesCANBus

Page 19

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 19 preview image

Loading page image...

DronesHardwareSecurityCommunicationsChannelsSecurityWebPortalSecurityIndustrialControlSystemsSCADADevicesModbusProcessAutomationSystemsChapterReviewQuestionsAnswersChapter6ThreatsandVulnerabilitiesAssociatedwithOperatingintheCloudCloudServiceModelsSharedResponsibilityModelSoftwareasaServicePlatformasaServiceInfrastructureasaServiceCloudDeploymentModelsPublicPrivateCommunityHybridServerlessArchitectureFunctionasaServiceInfrastructureasCodeInsecureApplicationProgrammingInterfaceBrokenObjectLevelAuthorizationBrokenUserAuthenticationExcessiveDataExposureLackofResourcesandRateLimitingBrokenFunctionLevelAuthorizationMassAssignmentSecurityMisconfiguration

Page 20

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 20 preview image

Loading page image...

InjectionImproperAssetManagementInsufficientLoggingandMonitoringImproperKeyManagementUnprotectedStorageLoggingandMonitoringChapterReviewQuestionsAnswersChapter7MitigatingControlsforAttacksandSoftwareVulnerabilitiesAttackTypesInjectionAttacksBufferOverflowAttacksPrivilegeEscalationAuthenticationAttacksRootkitsVulnerabilitiesImproperErrorHandlingDereferencingInsecureObjectReferenceRaceConditionSensitiveDataExposureInsecureComponentsInsufficientLoggingandMonitoringWeakorDefaultConfigurationsUseofInsecureFunctionsChapterReviewQuestionsAnswersPartIISoftwareandSystemsSecurityChapter8SecuritySolutionsforInfrastructureManagementCloudvs.On-PremisesSolutionsNetworkArchitecture

Page 21

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 21 preview image

Loading page image...

PhysicalNetworkSoftware-DefinedNetworkVirtualPrivateCloudNetworkVirtualPrivateNetworkServerlessNetworkVirtualizationHypervisorsVirtualDesktopInfrastructureContainerizationNetworkSegmentationVirtualLocalAreaNetworksPhysicalSegmentationJumpBoxesSystemIsolationHoneypotsandHoneynetsAssetManagementAssetInventoryAssetTaggingChangeManagementIdentityandAccessManagementPrivilegeManagementMultifactorAuthenticationSingleSign-OnIdentityFederationRole-BasedAccessControlAttribute-BasedAccessControlMandatoryAccessControlManualReviewCloudAccessSecurityBrokerMonitoringandLoggingEncryptionSymmetricCryptographyAsymmetricCryptographySymmetricvs.AsymmetricCryptography

Page 22

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 22 preview image

Loading page image...

CertificateManagementActiveDefenseChapterReviewQuestionsAnswersChapter9SoftwareAssuranceBestPracticesPlatformsandSoftwareArchitecturesClient/ServerWebApplicationMobileEmbeddedSystemonaChipFirmwareService-OrientedArchitectureSimpleObjectAccessProtocolRepresentationalStateTransferMicroservicesSecurityAssertionsMarkupLanguageTheSoftwareDevelopmentLifecycleRequirementsDevelopmentImplementationOperationandMaintenanceDevOpsandDevSecOpsSoftwareAssessmentMethodsUserAcceptanceTestingStressTestingSecurityRegressionTestingCodeReviewsStaticAnalysisToolsDynamicAnalysisToolsFormalMethodsofVerifyingCriticalSoftwareSecureCodingBestPracticesInputValidation

Page 23

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 23 preview image

Loading page image...

OutputEncodingSessionManagementAuthenticationDataProtectionParameterizedQueriesChapterReviewQuestionsAnswersChapter10HardwareAssuranceBestPracticesHardwareRootofTrustTrustedPlatformModuleHardwareSecurityModuleeFuseFirmwareUnifiedExtensibleFirmwareInterfaceMeasuredBootandAttestationTrustedFirmwareUpdatesSelf-EncryptingDriveBusEncryptionSecureProcessingTrustedExecutionEnvironmentProcessorSecurityExtensionsAtomicExecutionTrustedFoundryAnti-TamperTechniquesChapterReviewQuestionsAnswersPartIIISecurityOperationsandMonitoringChapter11DataAnalysisinSecurityMonitoringActivitiesSecurityDataAnalyticsDataAggregationandCorrelationDataAnalysis

Page 24

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 24 preview image

Loading page image...

TrendAnalysisHistoricalAnalysisBehavioralAnalysisHeuristicsAnomalyAnalysisEndpointSecurityMalwareDetectandBlockFilelessMalwareSandboxCloud-ConnectedProtectionUserandEntityBehaviorAnalyticsNetworkDomainNameSystemAnalysisDomainGenerationAlgorithmsFlowAnalysisPacketAnalysisMalwareLogReviewPacketCapturesSystemLogsFirewallLogsIntrusionDetection/PreventionSystemsAuthenticationLogsImpactAnalysisAvailabilityAnalysisSecurityInformationandEventManagementReviewQueryWritingE-mailAnalysisMaliciousPayloadDomainKeysIdentifiedMailSenderPolicyFrameworkDomain-BasedMessageAuthentication,Reporting,andConformance

Page 25

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 25 preview image

Loading page image...

HeaderPhishingForwardingDigitalSignaturesandEncryptionEmbeddedLinksImpersonationChapterReviewQuestionsAnswersChapter12ImplementConfigurationChangestoExistingControlstoImproveSecurityPermissionsUsersGroupsBlacklistingWhitelistingFirewallsWebProxiesWebApplicationFirewallsOperatingSystemFirewallsIntrusionPreventionSystemRulesSnortRuleBuildingZeekLogsSuricataRule-BuildingHost-BasedIntrusionPreventionSystemsDataLossPreventionEndpointDetectionandResponseNetworkAccessControlTime-BasedSolutionRule-BasedSolutionRole-BasedSolutionLocation-BasedSolutionSinkholingMalwareSignatures

Page 26

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 26 preview image

Loading page image...

SandboxingPortSecurityChapterReviewQuestionsAnswersChapter13TheImportanceofProactiveThreatHuntingEstablishingaHypothesisProfilingThreatActorsandActivitiesThreat-HuntingTacticsHigh-ImpactTTPsDeliveringResultsDocumentingtheProcessReducingtheAttackSurfaceAreaandBundlingCriticalAssetsAttackVectorsIntegratedIntelligenceImprovingDetectionCapabilitiesChapterReviewQuestionsAnswersChapter14AutomationConceptsandTechnologiesWorkflowOrchestrationSecurityOrchestration,Automation,andResponsePlatformsOrchestrationPlaybooksDataEnrichmentScriptingPythonScriptingPowerShellScriptingApplicationProgrammingInterfaceIntegrationRepresentationalStateTransferAutomatingAPICallsAutomatedMalwareSignatureCreationThreatFeedCombination

Page 27

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 27 preview image

Loading page image...

MachineLearningUseofAutomationProtocolsandStandardsSecurityContentAutomationProtocolSoftwareEngineeringContinuousIntegrationContinuousDeliveryContinuousDeploymentChapterReviewQuestionsAnswersPartIVIncidentResponseChapter15TheImportanceoftheIncidentResponseProcessEstablishingaCommunicationProcessInternalCommunicationsExternalCommunicationsResponseCoordinationwithRelevantEntitiesFactorsContributingtoDataCriticalityPersonallyIdentifiableInformationPersonalHealthInformationHigh-ValueAssetsPaymentCardInformationIntellectualPropertyCorporateConfidentialInformationChapterReviewQuestionsAnswersChapter16AppropriateIncidentResponseProceduresPreparationTrainingTestingDocumentationDetectionandAnalysisCharacteristicsofSeverityLevelClassification

Page 28

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 28 preview image

Loading page image...

ReverseEngineeringContainmentSegmentationIsolationRemovalEradicationandRecoveryVulnerabilityMitigationSanitizationReconstructionSecureDisposalPatchingRestorationofPermissionsRestorationofServicesandVerificationofLoggingPost-IncidentActivitiesLessons-LearnedReportChangeControlProcessUpdatestoResponsePlanSummaryReportIndicatorofCompromiseGenerationMonitoringChapterReviewQuestionsAnswersChapter17AnalyzePotentialIndicatorsofCompromiseNetwork-RelatedIndicatorsBandwidthUtilizationBeaconingIrregularPeer-to-PeerCommunicationRogueDevicesontheNetworkScanSweepsCommonProtocoloveraNonstandardPortHost-RelatedIndicatorsCapacityConsumptionUnauthorizedSoftware

Page 29

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 29 preview image

Loading page image...

MaliciousProcessesMemoryContentsUnauthorizedChangesUnauthorizedPrivilegesDataExfiltrationRegistryChangeorAnomalyUnauthorizedScheduledTaskApplication-RelatedIndicatorsAnomalousActivityIntroductionofNewAccountsUnexpectedOutputUnexpectedOutboundCommunicationServiceInterruptionMemoryOverflowsApplicationLogsChapterReviewQuestionsAnswersChapter18UtilizeBasicDigitalForensicsTechniquesPhasesofanInvestigationSeizureDataAcquisitionAnalysisReportingNetworkNetworkTapHubSwitchesWireshark/TSharktcpdumpEndpointsServersOSandProcessAnalysisMobileDeviceForensics

Page 30

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 30 preview image

Loading page image...

VirtualizationandtheCloudProceduresBuildingYourForensicKitCryptographyToolsAcquisitionUtilitiesForensicDuplicatorsPasswordCrackersHashingUtilitiesForensicSuitesFileCarvingChapterReviewQuestionsAnswersPartVComplianceandAssessmentChapter19TheImportanceofDataPrivacyandProtectionPrivacyvs.SecurityTypesofDataLegalRequirementsforDataNontechnicalControlsDataOwnershipDataClassificationDataConfidentialityDataSovereigntyDataMinimizationDataPurposeLimitationDataRetentionTechnicalControlsAccessControlsEncryptionSharingDataWhilePreservingPrivacyDigitalRightsManagementDataLossPreventionChapterReview

Page 31

CompTIA CySA+ Cybersecurity Analyst Certification CS0-002 All-in-One Exam Guide (2021) - Page 31 preview image

Loading page image...

QuestionsAnswersChapter20SecurityConceptsinSupportofOrganizationalRiskMitigationBusinessImpactAnalysisRiskAssessmentRiskIdentificationProcessRiskCalculationCommunicationofRiskFactorsRiskPrioritizationSecurityControlsEngineeringTradeoffsDocumentedCompensatingControlsSystemsAssessmentSupplyChainRiskAssessmentVendorDueDiligenceHardwareSourceAuthenticityTrainingandExercisesTypesofExercisesRedTeamBlueTeamWhiteTeamChapterReviewQuestionsAnswersChapter21TheImportanceofFrameworks,Policies,Procedures,andControlsSecurityFrameworksNISTISO/IEC27000SeriesCenterforInternetSecurityControlsPoliciesandProceduresEthicsandCodesofConductAcceptableUsePolicyPasswordPolicy
Preview Mode

This document has 821 pages. Sign in to access the full document!

Study Now!

XY-Copilot AI
Unlimited Access
Secure Payment
Instant Access
24/7 Support
Document Chat

Document Details

Related Documents

View all