|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/comptia-security-sy0-701-practice-tests/
课程评论:没有评论
Coursera 上的 CompTIA Security+ (SY0-701) 实践测试课程,旨在帮助学习者为 CompTIA Security+ 认证考试做好准备。该课程涵盖了考试的五个主要领域: 1. **通用安全概念 (12%):** 学习各种安全控制的比较与对比,理解基本安全概念,认识变更管理过程及其对安全的影响,以及选择和应用恰当的加密解决方案的重要性。 2. **威胁、漏洞与缓解措施 (22%):** 探讨不同类型的威胁参与者及其动机,了解常见的威胁向量和攻击面,识别各种安全漏洞,分析恶意活动指标,并学习用于保护企业的缓解技术。 3. **安全架构 (18%):** 比较不同架构模型的安全影响,学习如何根据场景安全地应用安全原则来保护企业基础设施,理解保护数据的概念与策略,以及增强安全架构的弹性和恢复能力。 4. **安全运营 (28%):** 掌握将常见安全技术应用于计算资源,了解正确管理硬件、软件和数据资产的安全含义,熟悉漏洞管理的相关活动,理解安全警报和监控的概念及工具,学习如何修改企业能力以增强安全性,实现和维护身份与访问管理,认识自动化与编排在安全运营中的重要性,以及掌握恰当的事件响应活动和利用数据源进行调查。 5. **安全项目管理与监督 (20%):** 总结有效的安全治理要素,解释风险管理过程,理解第三方风险评估与管理的相关流程,总结有效的安全合规要素,熟悉不同类型审计和评估的目的,并学习如何根据场景实施安全意识实践。 该课程通过对这些关键领域的深入讲解和实践练习,帮助学员建立扎实的安全知识基础,为通过 CompTIA Security+ 认证奠定坚实基础。
1.0 General Security Concepts (12 % of the exam)Compare and contrast various types of security controls.Summarize fundamental security concepts.Explain the importance of change management processes and the impact to security.Explain the importance of using appropriate cryptographic solutions.2.0 Threats, Vulnerabilities, and Mitigations (22% of the exam)Compare and contrast common threat actors and motivations.Explain common threat vectors and attack surfaces.Explain various types of vulnerabilities.Given a scenario, analyze indicators of malicious activity.Explain the purpose of mitigation techniques used to secure the enterprise.3.0 Security Architecture (18% of the exam)Compare and contrast security implications of different architecture models.Given a scenario, apply security principles to secure enterprise infrastructure.Compare and contrast concepts and strategies to protect data.Explain the importance of resilience and recovery in security architecture.4.0 Security Operations (28% of the exam)Given a scenario, apply common security techniques to computing resources.Explain the security implications of proper hardware, software, and data asset management.Explain various activities associated with vulnerability management.Explain security alerting and monitoring concepts and tools.Given a scenario, modify enterprise capabilities to enhance security.Given a scenario, implement and maintain identity and access management.Explain the importance of automation and orchestration related to secure operations.Explain appropriate incident response activities.Given a scenario, use data sources to support an investigation.5.0 Security Program Management and Oversight (20% of the exam)Summarize elements of effective security governance.Explain elements of the risk management process.Explain the processes associated with third-party risk assessment and management.Summarize elements of effective security compliance.Explain types and purposes of audits and assessments.Given a scenario, implement security awareness practices.