Transcription of Security+401 Course Introduction - USALearning
1 Security+401 Course Introduction Table of Contents CompTIA security + (SY0-401) Introduction .. 2 Notices .. 3 security + SY0-401 Course Objectives .. 4 Gap Area .. 7 A security + Certified 8 About the security + SY0-401 Exam -1 .. 10 About the security + Sy0-401 Exam -2 .. 12 Get the most from this Course .. 13 Page 1 of 15 CompTIA security + (SY0-401) Introduction 2014 Carnegie Mellon UniversityCompTIA security + (SY0-401) Introduction **001 Instructor: Hi, I'm Dean Bushmiller, and we're going to talk about security + version 4. This Page 2 of 15 Notices 2 Notices 2014 Carnegie Mellon UniversityThis material is distributed by the Software Engineering Institute (SEI) only to Course attendees for their own individual for the government purposes described below, this material SHALL NOT be reproduced or used in any other manner without requesting formal permission from the Software Engineering Institute at This material was created in the performance of Federal Government Contract Number FA8721-05-C-0003 with Carnegie Mellon University for the operation of the Software Engineering Institute, a federally funded research and development center.
2 The government's rights to use, modify, reproduce, release, perform, display, or disclose this material are restricted by the Rights in Technical Data-Noncommercial Items clauses (DFAR and DFAR Alternate I) contained in the above identified reproduction of this material or portions thereof marked with this legend must also reproduce the disclaimers contained on this slide. Although the rights granted by contract do not require Course attendance to use this material for government purposes, the SEI recommends attendance to ensure proper MATERIAL IS PROVIDED ON AN AS IS BASIS, AND CARNEGIE MELLON DISCLAIMS ANY AND ALL WARRANTIES, IMPLIED OR OTHERWISE (INCLUDING, BUT NOT LIMITED TO, WARRANTY OF FITNESS FOR A PARTICULAR PURPOSE, RESULTS OBTAINED FROM USE OF THE MATERIAL, MERCHANTABILITY, AND/OR NON-INFRINGEMENT).
3 CERT is a registered mark owned by Carnegie Mellon University. **002 is an Introduction to the Course . Page 3 of 15 security + SY0-401 Course Objectives 4 security + SY0-401 Course ObjectivesIntent Provide a review of the security + Domains . Supplement preparation for the security + certification + Domains (and percentage of questions on exam) network Security20% Compliance and Operational Security18% Threats and Vulnerabilities20% Application, Data, and Host Security15% Access Control and Identity Management15% Cryptography12% **004 What you want to be able to do is to understand these six major sections of the technology and security in a way that you're not confused when you get to the exam.
4 Now, one of the nice things is you may have taken a Networking+ Course , so you have some of that basic background information. If you don't have the network +, a lot of times you're going to come upon topics where I'm going to assume that knowledge is there. The nice thing is, is you can pause, take a minute, and say, "Okay, I need to look up this. I need to understand Page 4 of 15this protocol. I need to know how this service works." I'm going to focus in primarily on the security aspects of each one of these protocols when we talk about network security . When we talk about compliance and operations security , I'm going to talk about how to actually achieve compliance, maybe even audit and be prepared for auditing concepts and be prepared in your job for that.
5 I really like to play the game that I call Threats and Controls, which here we're going to talk about threats and vulnerabilities. Those threats and vulnerabilities to your organization-- how do you deal with them? How do you put controls in place that make the organization secure, or how do you recognize that these particular threats and vulnerabilities are present within your organization? And then we'll dig into the application data and the host security -- how do we actually protect and defend the host-- whether that's locally on the box with antivirus, or whether that's through a network standpoint when we do intrusion detection or intrusion prevention.
6 Then we'll talk about one of my favorite topics. If I had to pick one thing that I could clearly say that I'm an expert in, it would be access control and identity management. And then finally, something near and dear to my heart is cryptography, and we're going to talk about Page 5 of 15cryptography and we're going to talk about the code talkers and the Enigma machine, and then how do you apply cryptography in your environment. Now, notice the percentages here. One of the things that I worry about for people who are coming into this class is that they focus on network security , they focus on threats and vulnerabilities, and they ignore cryptography, and then when they get to the cryptography section, they totally bomb that section.
7 And you probably could bomb one section and still pass the exam, but you need to have a balanced understanding of security in order to get past the test and actually make it out there in the real world. Page 6 of 15 Gap Area 5 Gap AreaYou should consider and use other sources in preparation for the security + exam!Scope of the security + DomainsScope of the this review courseScope of the examThe knowledge gap other sources can fill **005 Now, when we look at the scope of this Course and we look at the scope of the exam, there is going to be a gap there, and you've got to fill that gap up with your knowledge. If you're new to this, if you've never been in security before and you say, "Well, I've got plenty of years of networking experience, but I don't have any security experience," then what I'm going to say to you is: Go out and practice and play.
8 But remember, you don't have to know everything in the exam, but you have to know enough of the concepts and have them very Page 7 of 15ingrained in what you do. Because as soon as you're finished the test, well then, the test is over with; you've got the security + certification. That may have fulfilled some sort of requirement in order for you to keep your job, but now it's time for you to be opened up to all of the security that's out there. A security + Certified Professional 6A security + Certified ProfessionalSecurity+ This is an introductory security certification. A first (or second) step in your security certification path After network + security + Certified Professionals Participate in risk identification and mitigation Provide security in infrastructure, application, information, and operational contexts Apply security controls to maintain confidentiality, integrity, and availability Informed of policies, laws, and regulationsThis is a technical certification 2 years of day-to-day technical security experience **006 As a security + certified professional, remember, this is an Introduction to security .
9 So this should spark your interest in a whole bunch of different areas. You should-- when you're a professional, after this-- you should participate in Page 8 of 15risk identification and risk mitigation. Maybe you do risk assessments for your organization. Even in your little tiny scope that you have, I think that you can become more as far as security is concerned. You're going to apply security controls that protect the confidentiality, the integrity, the availability and the nonrepudiation of your organization. And you need to know about the regulations and the laws. I don't think you have to know about all the regulations and the laws; I think you have to look at the ones that are relevant to your organization and to the jurisdiction that you're in.
10 Now, when you go to take this test. Either you know it or you don't know it. Now the answers may be long and complex and require you to go through a line of logic to actually get the answer, but there's always one right answer, and it's the technical answer. Page 9 of 15 About the security + SY0-401 Exam -1 7 About the security + SY0-401 Exam -190 Minutes90 Questions Multiple choice Performance-based Near the beginning of the test Simulated environment Perform a task or solve a problem Watch your time, part of the 90 minutes Can be saved and returned to laterSome questions are being tested , and not score 750 out of 900 **007 Now let's talk about the exam.