|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/comptia-security-701
课程评论:没有评论
课程名称:CompTIA Security+ 701 概述:本课程旨在帮助个人成功通过CompTIA Security+ SY0-701认证考试。课程涵盖了Security+考试中的五个领域:一般安全概念、威胁、漏洞及其缓解措施、安全架构、安全操作以及安全程序管理和监督。每个课程将解释考试中的概念和术语,并提供有助于记忆的类比、记忆辅助工具和材料的实用应用。 课程大纲: 1. **安全基础**:介绍网络安全中使用的一般概念和词汇,并探索用于保护资产的安全控制的类别和类型,讨论物理控制作为保护物理基础设施的方式。 2. **密码学**:讨论如何通过密码学保护敏感数据,包括密码的历史、哈希技术、密码和密钥。 3. **威胁**:回顾可能对组织运营造成影响的各类攻击者及其动机,并讨论不同的攻击方式,以及社会工程攻击的执行方式。 4. **攻击**:概述多种可能的网络攻击,如物理、网络、应用和密码攻击,并描述网络和应用中具体攻击的工作模式。 5. **身份与访问管理**:学习身份与访问管理的核心安全概念,包括身份识别、身份验证、授权和审计,确保正确的用户拥有必要的访问权限。 6. **组织安全**:审查组织如何创建安全的操作环境,包括保护网络和软件以防止数据丢失的方法。 7. **网络安全设备**:深入了解不同的网络设备,帮助保护组织网络免受恶意活动,保护数据机密性并减少潜在的有害入侵。 8. **安全操作**:探讨在实施新技术和发展现有基础设施时,应采取的各种安全运营要求,包括安全管理的概念、政策及技术。 9. **虚拟化**:概述虚拟化和云服务的术语,以及组织如何利用这些技术满足其需求。 10. **移动安全**:探讨移动设备的广泛使用及其对组织数据保护的影响,学习移动设备管理解决方案及相关实施策略。 11. **漏洞与风险管理**:概述安全组织识别漏洞、分析发现及评估应对措施的方法。 12. **事件响应**:解释事件响应计划的目的和主要组成部分,介绍事件响应的各个阶段及创建备份的重要性。 13. **数据保护**:讨论如何保护组织数据免受外部和内部威胁,采用安全数据管理实践、技术和合规性要求。 14. **治理**:回顾法律和行业规定对组织运营的影响,并讨论组织如何创造和实施相应政策以防止数据丢失。 通过本课程的学习,学员将全面掌握CompTIA Security+考试所需的知识和技能,为获得相关认证打下坚实基础。
Name:Security basics
Description:In this module, we explain general concepts and vocabulary used in cybersecurity and explore categories and types of security controls used to protect assets. Physical controls are also considered as ways of protecting physical infrastructure.
Name:Cryptography
Description:In this course, we will discuss protecting sensitive data with cryptography, which is the practice of disguising information in a way that looks random. We will cover the history of cryptography, hashing, passwords, and keys.
Name:Threats
Description:There are a range of groups and individuals who might carry out an attack or impact an organization's operations. In this course, we review various types of threat actors who might seek to harm an organization along with their motivations. Also discussed are the various ways an attack might occur. Ways a social engineering attack might be carried out is also described.
Name:Attacks
Description:A number of cyberattacks are possible including physical, network, application, and cryptographic attacks. In this course, we review the general types of cyber attacks mentioned in the CompTIA Security+ exam. We also describe their general operation of specific examples of attacks both over the network and in applications.
Name:Identity and access management
Description:Identity and access management is all about verifying the right users have the right access to the tools and technologies needed to do their job. Learn about the most important security concepts related to identity and access management: identification, authentication, authorization, and accounting.
Name:Organizational security
Description:There are a number of ways an organization can create a secure operating environment. In this course, we review ways organizations protect their networks and software in order to prevent data loss.
Name:Network security devices
Description:A number of network devices can be used to help secure an organization's networks. In this course, we delve into different network devices used to safeguard networks from malicious activity, protect data confidentiality, and reduce potential harmful intrusions.
Name:Security operations
Description:As an organization implements new technologies and evolves its existing infrastructure, various secure operating requirements should be utilized. In this course, we review the concepts driving security management at an organization including practices, policies, and specific technologies such as a security information and event management system to better monitor a network for security incidents.
Name:Virtualization
Description:Virtualization has given rise to a host of new computing technologies and operations. Most major enterprise solutions utilize virtualization, automation, and cloud services. In this course, we review the terminology used in virtualization and how organizations leverage cloud computing services to meet their needs.
Name:Mobile security
Description:As mobile devices proliferate the modern workplace, various security controls must be implemented to safeguard the organization from data loss. In this course, we explore mobile device management solutions as well as the manner in which organization choose to implement mobile device usage for their employees.
Name:Vulnerability and risk management
Description:Determining if a system or network is impacted by vulnerabilities is the first step toward identifying and correcting security shortcomings. In this section, we outline the methods by which secure organizations identify vulnerabilities, analyze the findings, and determine which vulnerabilties require a response.
Name:Incident response
Description:This course explains the purpose and main components of an incident response plan and walks through the phases of incident response, contingency planning and creating backups. Explore how an incident response plan works and the basic concepts related to digital forensics.
Name:Data protection
Description:Organizations must be on guard to protect their data both from outside threats as well as inside threats. In this course, we disuss the ideas surrounding data protection through the use of secure data management practices, data management technologies, and regulatory requirements involving how an organization's data protection operation is structured.
Name:Governance
Description:Secure, mature organizations thoughtfully consider how individuals at the organization will operate and take proactive steps to safeguard the organization from data loss. In this course, we review legal and industry regulations that might shape how an organization operates and we describe the methods by which an organization creates and implements policies.
This course prepares individuals to successfuly pass the CompTIA Security+ SY0-701 certification exam. It covers each of the five domains in the Security+ exam: General Security Concepts; Threats, Vulnerabilities, and Mitigations; Security Architecture; Security Operations; and Security Program Management and Oversight. Each course will explain the concepts and terminology covered on the exam and include helpful analogies, memory aids, and practical applications of the material to better remembe