|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/security-certification-threats-and-vulnerabilities-domain/
课程评论:没有评论
课程名称:Security+认证 - 威胁与漏洞领域 课程概述:本课程面向初学者和希望获得认证以进入薪资达到六位数的网络安全入门职位的IT专业人士。目前全球有超过一百万的网络安全职位空缺,需求大大超过供应,这为您带来了更多的机会、工作保障和更高的薪资!Security+考试涵盖六个领域,本课程专注于第三个领域,即“威胁与漏洞”领域。 在课程中,您将学习以下内容: - 恶意软件(Malware):定义恶意软件的类别和特征,并讨论防护措施,以确保网络、系统和数据的安全。 - 网络攻击(Cyber Attacks):概述不同类型的网络攻击,包括未在其他部分中讨论的攻击类型。 - DNS安全(DNS Security):了解DNS的漏洞、攻击以及相关的安全协议。 - 社会工程(Social Engineering):理解信息安全中的心理操控技巧,如何诱使人们泄露机密信息。 - 无线攻击(Wireless Attacks):学习现代无线安全协议、漏洞、攻击方式和防御机制。 - 先进的无线攻击(Advanced Wireless Attacks):讨论如何防止这些攻击。 - 跨站脚本攻击(XSS):学习如何测试XSS漏洞、识别利用和防护措施。 - 缓冲区溢出(Buffer Overflows):分析如何利用缓冲区溢出技术执行恶意代码的方式以及缓解措施。 - 安全测试工具(Security Testing Tools):初步了解可用的安全测试工具,分类及其用途。 - 安全信息与事件管理(SIEM):有效管理操作安全日志,并从中提取有用的安全信息。 - 操作系统、数据库和应用的强化(Platform Hardening and Baselining):降低攻击面。 - 蜜罐和蜜网(Honeypots and Honey Nets):引诱攻击者,以研究他们的行为从而保护关键数据。 - 漏洞评估与渗透测试(Vulnerability Scanning and Pen Testing):探讨两者之间的异同。 本课程将为您提供网络安全领域的基础知识和实用技能,使您在求职时具备竞争力。
This course is for beginners and IT pros looking to get certified and land an entry level Cyber Security position paying upwards of six figures! There are currently over a million Cyber Security job openings global and demand is greatly outpacing supply which means more opportunity, job security and higher pay for you! The Security+ exam covers six domains and this course focuses on the third domain which is 'Threats and Vulnerabilities'' domain. MalwareCyber attacksDNS SecuritySocial engineeringWireless attacksAdvanced wireless attacksXSS - Cross-Site Scripting attacksBuffer overflowsSecurity testing toolsSIEM - security information and events managementPlatform hardening and baseliningHoneypots and honey netsVulnerability scanning and pen testingThreat modeling In Malware section we will define Malware categories and characteristics and talk through protective countermeasures to keep networks, systems and data safe from compromise. There are so many different types of attacks sometimes it can be challenging to address them all within the context of our various lessons. So in the Cyber Attacks lesson I've pulled together some attack types that haven't necessarily been covered in the other sections. When the internet was originally architected services such as DNS weren't necessarily designed with security in mind. You will learn about DNS vulnerabilities, attacks and DNS Security protocols as part of the DNS Security lesson Understand social engineering in the context of information security, which refers to psychological manipulation of people into performing actions or divulging confidential information.You will learn the basics of modern wireless security protocols, vulnerabilities, attacks and defense mechanisms in the wireless attacks lesson.Wireless networks represent the softest and most common entry point for hackers. We will talk about advanced wireless attacks and how to prevent them. XSS and Injection are some of the top techniques used by attackers to compromise websites and user data. Learn how to test for XSS vulnerabilities, identify exploits and protect against them. Attack applications using buffer overflow techniques in order to execute arbitrary malicious code and we will also identify ways to mitigate these attacks. There are practically an infinite number of security testing tools available both free and paid. In the security testing tools lesson we will begin to scratch the surface of some of these common tools and identify how we categorize them and their uses. Management of logs are a key component of operational security. These days the velocity, variety and volume of data collected via logs has catapulted log management into the realm of Big Data. You will learn how to effectively manage these logs and derive useful security information from them in the lesson on SIEM. Minimizing the attack surface area of operating systems, databases and applications is a key tenet of operational security. I will show you techniques for OS/DB and App hardening. Luring attackers away from critical data and studying their behavior can help us to protect the data that matters most. You will learn how to use honeypots to tie up attackers and find out what they are up to. Vulnerability Assessment and Pen Testing are often terms that are used interchangeably. In this section we will walk through some of the differences and commonalities between the two.