|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cisco-certified-support-technician-cybersecurity-exam-prep-questions/
课程评论:没有评论
课程名称:思科认证支持技术员网络安全考试准备 课程概述:开始您的网络安全之旅,参加思科认证支持技术员:网络安全课程。本课程非常适合初级技术员、学生和实习生,是思科认证路径的基础,旨在为您获得更高级别的认证,例如思科CyberOps。课程提供450个针对性的练习问题和实践培训,帮助您自信应对认证考试,并在网络安全角色中表现出色。 您将学习的内容: 1. **基本安全原则**:定义漏洞、威胁、攻击以及风险,攻击向量,防御深入,机密性、完整性和可用性(CIA),攻击者类型及其攻击动机,职业道德规范等。 2. **常见威胁和漏洞**:包括恶意软件、勒索软件、拒绝服务攻击、僵尸网络、社会工程攻击(如跟踪、鱼叉式钓鱼、钓鱼攻击等)等。 3. **访问管理原则**:包括认证、授权和计费(AAA);RADIUS;多因素认证(MFA);密码策略等。 4. **加密方法与应用**:加密类型、哈希、证书、公共密钥基础设施(PKI)等。 5. **TCP/IP协议的漏洞**、网络地址对安全的影响、网络基础设施及技术、如何设置安全的无线网络,以及实施安全访问技术(如ACL、防火墙、VPN等)。 6. **操作系统安全概念**:覆盖Windows、macOS和Linux的安全特性,以及如何管理和更新客户端安全策略。 7. **漏洞管理**:识别、管理和缓解漏洞的过程,主动与被动侦察技术。 8. **风险管理**:对风险与漏洞的理解,风险等级划分及应对策略的重要性。 9. **灾难恢复与业务持续性规划**:了解自然和人为灾害的影响,以及灾难恢复和业务连续性计划的重要特点。 10. **监控安全事件**:了解SIEM和SOAR角色,识别安全事件的必要性。 11. **数字取证与攻击归属过程**:掌握反应生命周期阶段和合规框架对事件处理的影响。 该课程为您提供了正式进入网络安全领域所需的基础知识和实用技能,帮助您为未来的职业做好准备。
Begin your cybersecurity journey with the Cisco Certified Support Technician: Cybersecurity course. Perfect for entry-level technicians, students, and interns, this course serves as the foundation in the Cisco certification track, leading to advanced credentials such as Cisco CyberOps. Featuring 450 targeted practice questions and hands-on training, it prepares you to confidently pass the certification exam and perform effectively in cybersecurity roles.What You'll Learn: 1.1. Define essential security principles Vulnerabilities, threats, exploits, and risks; attack vectors; hardening; defense-in-depth; confidentiality, integrity, and availability (CIA); types of attackers; reasons for attacks; code of ethics 1.2. Explain common threats and vulnerabilities Malware, ransomware, denial of service, botnets, social engineering attacks (tailgating, spear phishing, phishing, vishing, smishing, etc.), physical attacks, man in the middle, IoT vulnerabilities, insider threats, Advanced Persistent Threat (APT) 1.3. Explain access management principles Authentication, authorization, and accounting (AAA); RADIUS; multifactor authentication (MFA); password policies 1.4. Explain encryption methods and applications Types of encryption, hashing, certificates, public key infrastructure (PKI); strong vs. weak encryption algorithms; states of data and appropriate encryption (data in transit, data at rest, data in use); protocols that use encryption 2.1. Describe TCP/IP protocol vulnerabilities TCP, UDP, HTTP, ARP, ICMP, DHCP, DNS 2.2. Explain how network addresses impact network security IPv4 and IPv6 addresses, MAC addresses, network segmentation, CIDR notation, NAT, public vs. private networks 2.3. Describe network infrastructure and technologies Network security architecture, DMZ, virtualization, cloud, honeypot, proxy server, IDS, IPS 2.4. Set up a secure wireless SoHo network MAC address filtering, encryption standards and protocols, SSID 2.5. Implement secure access technologies ACL, firewall, VPN, NAC 3.1. Describe operating system security concepts Windows, macOS, and Linux; security features, including Windows Defender and host-based firewalls; CLI and PowerShell; file and directory permissions; privilege escalation 3.2. Demonstrate familiarity with appropriate endpoint tools that gather security assessment information netstat, nslookup, tcpdump 3.3. Verify that endpoint systems meet security policies and standards Hardware inventory (asset management), software inventory, program deployment, data backups, regulatory compliance (PCI DSS, HIPAA, GDPR), BYOD (device management, data encryption, app distribution, configuration management) 3.4. Implement software and hardware updates Windows Update, application updates, device drivers, firmware, patching 3.5. Interpret system logs Event Viewer, audit logs, system and application logs, syslog, identification of anomalies 3.6. Demonstrate familiarity with malware removal Scanning systems, reviewing scan logs, malware remediation 4.1. Explain vulnerability management Vulnerability identification, management, and mitigation; active and passive reconnaissance; testing (port scanning, automation) 4.2. Use threat intelligence techniques to identify potential network vulnerabilities Uses and limitations of vulnerability databases; industry-standard tools used to assess vulnerabilities and make recommendations, policies, and reports; Common Vulnerabilities and Exposures (CVEs), cybersecurity reports, cybersecurity news, subscription services, and collective intelligence; ad hoc and automated threat intelligence; the importance of updating documentation and other forms of communication proactively before, during, and after cybersecurity incidents; how to secure, share and update documentation 4.3. Explain risk management Vulnerability vs. risk, ranking risks, approaches to risk management, risk mitigation strategies, levels of risk (low, medium, high, extremely high), risks associated with specific types of data and data classifications, security assessments of IT systems (information security, change management, computer operations, information assurance) 4.4. Explain the importance of disaster recovery and business continuity planning Natural and human-caused disasters, features of disaster recovery plans (DRP) and business continuity plans (BCP), backup, disaster recovery controls (detective, preventive, and corrective) 5.1. Monitor security events and know when escalation is required Role of SIEM and SOAR, monitoring network data to identify security incidents (packet captures, various log file entries, etc.), identifying suspicious events as they occur 5.2. Explain digital forensics and attack attribution processes Cyber Kill Chain, MITRE ATT & CK Matrix, and Diamond Model; Tactics, Techniques, and Procedures (TTP); sources of evidence (artifacts); evidence handling (preserving digital evidence, chain of custody) 5.3. Explain the impact of compliance frameworks on incident handling Compliance frameworks (GDPR, HIPAA, PCI-DSS, FERPA, FISMA), reporting and notification requirements 5.4. Describe the elements of cybersecurity incident response Policy, plan, and procedure elements; incident response lifecycle stages (NIST Special Publication 800-61 sections 2.3, 3.1-3.4