|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cissp-certification-domains-5-6-7-8/
课程评论:没有评论
课程名称:CISSP认证:第5、6、7和8领域视频培训-2021 课程概述:在本课程中,您将获得通过CISSP认证所需的知识、经验和实践技能。该课程重点涵盖CISSP第5、6、7和8领域的内容,同时结合讲师21年的实际经验,讲解CISSP培训要求的现实案例。课程包含各领域的完整视频以及10道练习题,具体包括: - **第5领域**:控制物理和逻辑访问、身份管理、认证机制管理等; - **第6领域**:设计和验证评估、测试和审计策略,进行安全控制测试等; - **第7领域**:支持调查、证据收集与管理、日志监控等; - **第8领域**:分析测试输出,进行安全审计等。 课程的内容覆盖了最新的CISSP考试要求(2021年4月),同时预告2023年将进行的新考试更新。通过学习该课程,学生将掌握不同复杂程度和能力要求的知识点,帮助他们在CISSP考试中获得成功。 重要提醒:通过CISSP考试需要扎实的知识基础和实际经验。考试内容虽为英文编写,但其他语言版本也可获取。解题时需从管理者及风险顾问的角度进行思考,确保能够识别出关键字和指示词。建议学习者多利用多种培训资源,加强对CISSP内容的理解,以提升考试成功率。
In this CISSP Domain 5, 6, 7 and 8 video training course, I will provide you the knowledge, experience and practical skills you need to pass the CISSP certification. In addition, you will get my years of experience (Over 21 years) as I translate CISSP training requirements into real-world examples.Included in this course:CISSP Domain 5 VideosFull CISSP Domain 5 Videos 10 CISSP practice questionsCISSP Domain 6 VideosFull CISSP Domain 6 Videos 10 CISSP practice questionsCISSP Domain 7 VideosFull CISSP Domain 7 Videos 10 CISSP practice questionsCISSP Domain 8 VideosFull CISSP Domain 8 Videos10 CISSP practice questionsThe curriculum in this course covers the content that will be on the most current CISSP exam (April 2021). Each objective that is required for the CISSP exam will be covered in varying degrees of complexity and competency. The next upgrade to the CISSP curriculum/exam will occur in 2023.In Domain 5 we will cover:Control Physical and Logical Access to AssetsInformationSystemsDevicesFacilitiesManage Identification and Authentication of People, Devices, and ServicesIdentity management implementationSingle/multi-factor authenticationAccountabilitySession managementRegistration and proofing of identityFederated Identity Management (FIM)Credential management systemsIntegrate Identity as a Third-party ServiceOn-premiseCloudFederatedImplement and Manage Authorization MechanismsRole Based Access Control (RBAC)Rule-based Access controlMandatory Access Control (MAC)Discretionary Access Control (DAC)Attribute Based Access Control (ABAC)Manage the Identity and Access Provisioning LifecycleUser access reviewSystem account access reviewProvisioning and deprovisioningIn Domain 6 we will cover:Design and Validate Assessment, Test, and Audit StrategiesInternalExternalThird PartyConduct Security Control TestingVulnerability AssessmentPenetration TestingLog ReviewsSynthetic TransactionsCode Review and TestingMisuse Case TestingTest Coverage AnalysisInterface TestingCollect Security Process Data (e.g., Technical and Administrative)Account ManagementManagement Review and ApprovalKey Performance and Risk IndicatorsBackup Verification DataTraining and AwarenessDisaster Recovery (DR) and Business Continuity (BC)Analyze Test Output and Generate ReportConduct or Facilitate Security AuditsInternalExternalThird-PartyIn Domain 7 we will cover:Understand and Support InvestigationsEvidence Collection and HandlingReporting and DocumentationInvestigative TechniquesDigital Forensics Tools, Tactics, and ProceduresUnderstand Requirements for Investigation TypesAdministrativeCriminalCivilRegulatoryIndustry StandardsConduct Logging and Monitoring ActivitiesIntrusion Detection and PreventionSecurity Information and Event ManagementContinuous MonitoringEgress MonitoringSecurely Provisioning ResourcesAsset InventoryAsset ManagementConfiguration ManagementUnderstand and Apply Foundational Security Ops Concepts"Need-To-Know" / Least PrivilegesSeparation of Duties and ResponsibilitiesPrivileged Account ManagementJob RotationInformation LifecycleService Level Agreements (SLA)Apply Resource Protection TechniquesMedia ManagementHardware and Software Asset ManagementConduct Incident ManagementDetectionResponseMitigationReportingRecoveryRemediationLessons LearnedOperate and Maintain Detective and Preventative MeasuresFirewallsIntrusion Detection and Prevention SystemsWhitelisting/BlacklistingThird-Party Provided Security ServicesSandboxingImplement and Support Patch and Vulnerability ManagementUnderstand and Participate in Change Management ProcessesImplement Recovery StrategiesBackup Storage StrategiesRecovery Site StrategiesMultiple Processing SitesSystem Resilience, High Availability, Quality of Service (QOS), and Fault ToleranceImplement Disaster Recovery (DR) ProcessesResponsePersonnelCommunicationsAssessmentRestorationTraining and AwarenessTest Disaster Recovery Plans (DRP)Read-Through/ChecklistStructured Walk-Through (Table-Top)Simulation TestParallel TestFull Interruption TestParticipate in Business Continuity (BC) Planning and ExercisesImplement and Manage Physical SecurityPerimeter Security ControlsInternal Security ControlsAddress Personnel Safety and Security ConcernsTravelSecurity Training and AwarenessEmergency ManagementDuressIn Domain 8 we will cover:Design and Validate Assessment, Test, and Audit StrategiesInternalExternalThird PartyConduct Security Control TestingVulnerability AssessmentPenetration TestingLog ReviewsSynthetic TransactionsCode Review and TestingMisuse Case TestingTest Coverage AnalysisInterface TestingCollect Security Process Data (e.g., Technical and Administrative)Account ManagementManagement Review and ApprovalKey Performance and Risk IndicatorsBackup Verification DataTraining and AwarenessDisaster Recovery (DR) and Business Continuity (BC)Analyze Test Output and Generate ReportConduct or Facilitate Security AuditsInternalExternalThird-PartyNotes / Disclaimers:In order for you to pass the CISSP test you need to have the substantial knowledge through experience and knowledge.The test was originally written in English, but there are other language versions availableAnswering the questions you need to consider the "perfect world" scenario and that work around options may be technically correct, but they may not meet (ISC)2 point of viewYou need to be able to spot the keywords (DR, BCP, Policy, Standards, etc.) as well as the indicators (First, Best, Last, Least, Most)Understand and answer every question from the Manager, CISO, or Risk Advisers Point of View (PoV). Answering the questions from a CIO or technical perspective will place your thinking too high or down in the weeds too far.Understand that you are to answer the questions based on being proactive within your environment. Enable a Vulnerability Management Program before you have vulnerability issues.The English version of the CISSP exam, utilizes the Computerized Adaptive Testing (CAT) format and is 3 hours long with 100-150 questionsMost people studying for CISSP certification will various media sources, test banks, and various books to enhance their test taking experience.Don't rely on one source to teach you all that you need to know for the CISSP….Invest in multiple training opportunities. The future payoff is worth the time and energy.