EC-Council Certified Network Defender

Size: px
Start display at page:

Download "EC-Council Certified Network Defender"

Transcription

1 EC-Council Certified Network Defender Duration: 5 Days Course Code: CND Version: 1 Overview: Certified Network Defender (CND) is a vendor-neutral, hands-on, instructor-led comprehensive network security certification training program. It is a skills-based, lab intensive program based on a job-task analysis and cybersecurity education framework presented by the National Initiative of Cybersecurity Education (NICE). The course has also been mapped to global job roles and responsibilities and the Department of Defense (DoD) job roles for system/network administrators. The course is designed and developed after extensive market research and surveys. Target Audience: Network AdministratorsNetwork security AdministratorsNetwork Security EngineerNetwork Defense TechniciansCND AnalystSecurity AnalystSecurity OperatorAnyone who involves in network operations Objectives: The program prepares network administrators on network security technologies and operations to attain Defense-in-Depth network security preparedness. It covers the protect, detect and respond approach to network security. The course contains hands-on labs, based on major network security tools and techniques which will provide network administrators real world expertise on current network security technologies and operations. The study-kit provides you with over 10 GB of network security best practices, assessments and protection tools. The kit also contains templates for various network policies and a large number of white papers for additional learning.

2 Content: Module 01: Computer Network and Defense Environmental Controls Best Security Practices for VPN Configuration Fundamentals Recommendations for VPN Connection Heating, Ventilation and Air Conditioning Network Fundamentals Module 10: Wireless Network Defense Electromagnetic Interference (EMI) Shielding Computer Network Wireless Terminologies Hot and Cold Aisles Types of Network Wireless Networks Physical Security: Awareness /Training Major Network Topologies Advantages of Wireless Networks Physical Security Checklists Network Components Disadvantages of Wireless Networks Module 06: Host Security Network Interface Card (NIC) Wireless Standard Host Security Repeater Wireless Topologies Common Threats Specific to Host Security Hub Ad-hoc Standalone Network Architecture (IBSS - Independent Basic Service Set) Where do they come from? Switches Infrastructure Network Topology (Centrally Why Host Security? Coordinated Architecture/ BSS - Basic Router Service Set) Before Configuring Host Security: Identify Bridges purpose of each Host Typical Use of Wireless Networks Gateways Host Security Baselining Extension to a Wired Network TCP/IP Networking Basics OS Security Multiple Access Points Standard Network Models: OSI Model Operating System Security Baselining LAN-to-LAN Wireless Network Standard Network Models: TCP/IP Model Common OS Security Configurations 3G Hotspot Windows Security Baselining: Example Comparing OSI and TCP/IP Microsoft Base Security Analyzer Components of Wireless Network (MBSA) Setting up BIOS Password TCP/IP Protocol Stack Auditing Windows Registry Access Point User and Password Management Disabling Unnecessary User Accounts Domain Name System (DNS) Configuring user authentication Wireless Cards (NIC) Patch Management DNS Packet Format Wireless Modem Configuring an update method for Installing Patches Transmission Control Protocol (TCP) Patch Management Tools Wireless Bridge TCP Header Format Disabling Unused System Services

3 TCP Services Wireless Repeater TCP Operation Three-way handshak Set Appropriate Local Security Policy Settings Wireless Router User Datagram Protocol (UDP) Configuring Windows Firewall UDP Operation Wireless Gateways IP Header Protecting from Viruses Wireless USB Adapter IP Header: Protocol Field Antivirus Software What is Internet Protocol v6 (IPv6)? IPv6 Header Protecting from Spywares Antenna Internet Control Message Protocol (ICMP) Antispywares Directional Antenna Parabolic Grid Antenna Format of an ICMP Message Security: AntiSpammers Dipole Antenna Omnidirectional Antenna Address Resolution Protocol (ARP) Spam Filtering Software Yagi Antenna ARP Packet Format Enabling Pop-up Blockers WEP (Wired Equivalent Privacy) Encryption Fiber Distributed Data Interface (FDDI) Windows Logs Review and Audit WPA (Wi-Fi Protected Access) Encryption Token Ring Log Review Recommendations Event IDs in Windows Event log WPA2 Encryption IP Addressing Configuring Host-based IDS/IPS WEP vs. WPA vs. WPA2 Host based IDS: OSSEC Classful IP Addressing AlienVault Unified Security Management (USM) Wi-Fi Authentication Method Tripwire Address Classes Additional Host Based IDSes Open System Authentication File System Security: Setting Access Controls Reserved IP Address and Permission to Files and Folders Shared Key Authentication Creating and Securing a Windows file Subnet Masking share Wi-Fi Authentication Process Using a Subnetting File and File System Encryption Centralized Authentication Server Supernetting EFS Limitations IPv6 Addressing Data encryption Recommendations Wireless Network Threats DATA Encryption Tools Difference between IPv4 and IPv6 IPv4 compatible IPv6 Address Linux Security War Driving Computer Network Defense (CND) Linux Base Security Checker: Client Mis-association buck-security Computer Fundamental Attributes Unauthorized Association Password Management What CND is NOT HoneySpot Access Point (Evil Twin) Attack Killing unnecessary processes CND Layers Rogue Access Point Attack CND Layer 1: Technologies Linux Patch Management CND Layer 2: Operations CND Layer 3: People Misconfigured Access Point Attack Understanding and checking Linux File Blue Teaming Permissions

4 Ad Hoc Connection Attack Changing File Permissions Network Defense-In-Depth Common File Permission Settings Check and Verify Permissions for AP MAC Spoofing Sensitive Files and Directories Typical Secure Network Design Host-based Firewall Protection with iptables Denial-of-Service Attack CND Triad Linux Log review and Audit WPA-PSK Cracking CND Process Common Linux log files System Log Viewer RADIUS Replay Log Events to Look for CND Actions Securing Network Servers ARP Poisoning Attack CND Approaches Before Hardening Servers WEP Cracking Module 02: Network Security Threats, Vulnerabilities, and Attacks Hardening Web Server Man-in-the-Middle Attack Essential Terminologies Hardening Server: Recommendations Fragmentation Attack Threats Hardening FTP Servers: Recommendations Jamming Signal Attack Vulnerabilities Hardening Routers and Switches Bluetooth Threats Attacks Hardening Routers: Recommendations Leaking Calendars and Address Books Network Security Concerns Hardening Switches Bugging Devices Hardening Switches-Recommendations Why Network Security Concern Arises? Sending SMS Messages Logs Review and Audit: Syslog Fundamental Network Security Threats Causing Financial Losses GFI EventsManager: Syslog Server Types of Network Security Threats Remote Control Application/software Security How does network security breach affects Social Engineering business continuity? Application Security Application Security Phases Malicious Code Network Security Vulnerabilities Application Security: Recommendations Data Security Protocol Vulnerabilities Types of Network Security Vulnerabilities What is Data Loss Prevention (DLP) Wireless Network Security Technological Vulnerabilities Best Practices to Prevent Data Loss List of DLP Solution Vendors Creating Inventory of Wireless Devices Configuration Vulnerabilities Data Leak/Loss Prevention Tools Placement of Wireless Antenna Virtualization Security Security policy Vulnerabilities Disable SSID Broadcasting Virtualization Security Concern

5 Types of Network Security Attacks Virtualization Terminologies Selecting Stronger Wireless Encryption Mode Network Reconnaissance Attacks Introduction to Virtualization Implementing MAC Address Filtering Reconnaissance Attacks Reconnaissance Attacks: ICMP Scanning Characteristics of Virtualization Monitoring Wireless Network Traffic Reconnaissance Attacks: Ping Sweep Reconnaissance Attacks: DNS Footprinting Reconnaissance Attacks: Network Range Benefits of Virtualization Defending Against WPA Cracking Discovery Reconnaissance Attacks: Network Topology Passphrases Identification Virtualization Security Client Settings Reconnaissance Attacks: Network Passphrase Complexity Information Extraction using Nmap Scan Virtualization Security Concern Additional Controls Reconnaissance Attacks: Port Scanning Reconnaissance Attacks : Network Sniffing Securing Hypervisor Detecting Rogue Access Points How an Attacker Hacks the Network Using Sniffers Wireless Scanning: Reconnaissance Attacks : Social Securing Virtual machines Wired-side Network Scanning Engineering Attacks SNMP Polling Implementing Software Firewall Network Access Attacks Deploying Anti-virus Software Wi-Fi Discovery Tools Encrypting the Virtual Machines Password Attacks Secure Virtual Network Management inssider and NetSurveyor Methods to Secure Virtual Environment Password Attack Techniques Virtualization Security Best Practices for Vistumbler and NetStumbler Network Defenders Dictionary Attack Best Practices for Virtual Environment Brute Forcing Attacks Security Locating Rogue Access points Hybrid Attack Birthday Attack Module 07: Secure Firewall Configuration and Rainbow Table Attack Management Protecting from Denial-of-Service Attacks: Interference Man-in-the-Middle Attack Firewalls and Concerns Assessing Wireless Network Security Replay Attack What Firewalls Does? Wi-Fi Security Auditing Tool: AirMagnet WiFi Smurf Attack Analyzer What should you not Ignore?: Firewall Limitations Spam and Spim WPA Security Assessment Tool How Does a Firewall Work? Xmas Attack Elcomsoft Wireless Security Auditor Firewall Rules Pharming Cain ; Abel Types of Firewalls Privilege Escalation Wi-Fi Vulnerability Scanning Tools Hardware Firewall DNS Poisoning Deploying Wireless IDS (WIDS) and Wireless IPS (WIPS) Software Firewall ARP Poisoning Typical Wireless IDS/IPS Deployment Firewall Technologies DHCP Attacks: DHCP Starvation Attacks WIPS Tool

6 DHCP Attacks: DHCP Spoofing Attack Packet Filtering Firewall Switch Port Stealing Adaptive Wireless IPS Circuit Level Gateway Spoofing Attacks AirDefense Application Level Firewall MAC Spoofing/Duplicating Configuring Security on Wireless Routers Denial of Service (DoS) Attacks Stateful Multilayer Inspection Firewall Multilayer Inspection Firewall Additional Wireless Network Security Distributed Denial-of-Service Attack (DDoS) Guides Application Proxy Malware Attacks Module 11: Network Traffic Monitoring and Network Address Translation Analysis Adware Spyware Rootkits Virtual Private Network Network Traffic Monitoring and Backdoors Analysis(Introduction) Logic Bomb Botnets Firewall Topologies Ransomware Advantages of Network Traffic Monitoring and Polymorphic malware Analysis Bastion host Malware Network Monitoring and Analysis: Techniques Types of Malware: Trojan Screened subnet Types of Malware: Virus and Armored Virus Non-Router based Malware Attacks Multi-homed firewall Router Based Monitoring Techniques Adware SNMP Monitoring Spyware Choosing Right Firewall Topology Netflow Monitoring Rootkits Backdoors Non-Router Based Monitoring Techniques Logic Bomb Firewall Rule Set ; Policies Botnets Packet Sniffers Ransomware Network Monitors Polymorphic malware Blacklist vs Whitelist Network Monitoring: Positioning your Machine Module 03: Network Security Controls, at Appropriate Location Protocols, and Devices Example: Packet Filter Firewall Ruleset Connecting Your Machine to Managed Switch Fundamental Elements of Network Security Implement Firewall Policy Network Traffic Signatures Network Security Controls Periodic Review of Firewall Policies Normal Traffic Signature Network Security Protocols Firewall Implementation Transport Layer Attack Signatures Network Layer Before Firewall Implementation and Application Layer Deployment Data Link Layer Baselining Normal Traffic Signatures Network Security Perimeter Appliances Firewall Implementation and Deployment Categories of Suspicious Traffic Signatures Network Security Controls Planning Firewall Implementation Informational Reconnaissance Unauthorized access Access Control Factors to Consider before Purchasing any Denial of service

7 Firewall Solution Access Control Terminology Attack Signature Analysis Techniques Access Control Principles Access Control System: Administrative Configuring Firewall Implementation Content-based Signatures Analysis Access Control Context-based Signatures Analysis Access Control System: Physical Access Atomic Signatures-based Analysis Controls Testing Firewall Implementation Composite Signatures-based Analysis Access Control System: Technical Access Controls Packet Sniffer: Wireshark Deploying Firewall Implementation Types of Access Control Understanding Wireshark Components Discretionary Access Control (DAC) Managing and Maintaining Firewall Role-based Access Implementation Wireshark Capture and Display Filters Network Access Control (NAC) Firewall Administration Monitoring and Analyzing FTP Traffic NAC Solutions Firewall Administration: Deny Unauthorized Public Network Access Monitoring and Analyzing TELNET Traffic User Identification, Authentication, Authorization and Accounting Firewall Administration: Deny Unauthorized Monitoring and Analyzing HTTP Traffic Access Inside the Network Types of Authentication :Password Authentication Detecting OS Fingerprinting Attempts Firewall Administration: Restricting Client s Access to External Host Types of Authentication: Two-factor Detecting Passive OS Fingerprinting Attempts Authentication Firewall Logging and Auditing Detecting Active OS Fingerprinting Attempts Types of Authentication : Biometrics Firewall Logging Detecting ICMP Based OS Fingerprinting Detecting TCP Based OS Fingerprinting Types of Authentication : Smart Card Authentication Firewall Logs Examine Nmap Process for OS Fingerprinting Types of Authentication: Single Sign-on (SSO) Firewall Anti-evasion Techniques Detecting PING Sweep Attempt Types of Authorization Systems Why Firewalls are Bypassed? Detecting TCP Scan Attempt Centralized Authorization Full Data Traffic Normalization TCP Half Open/ Stealth Scan Attempt Implicit Authorization Data Stream-based Inspection TCP Full Connect Scan Decentralized Authorization Vulnerability-based Detection and Blocking TCP Null Scan Attempt Explicit Authorization Firewall Security Recommendations and Best TCP Xmas Scan Attempt Practices Authorization Principles Detecting SYN/FIN DDOS Attempt Secure Firewall Implementation: Best Practices Least privilege Detecting UDP Scan Attempt Secure Firewall Implementation: Separation of duties Recommendations Detecting Password Cracking Attempts

8 Cryptography Secure Firewall Implementation: Do s and Detecting FTP Password Cracking Attempts Don ts Encryption Detecting Sniffing (MITM) Attempts Firewall Security Auditing Tools Symmetric Encryption Asymmetric Encryption Detecting the Mac Flooding Attempt Firewall Analyzer Hashing: Data Integrity Detecting the ARP Poisoning Attempt Firewall Tester: Firewalk Digital Signatures Additional Packet Sniffing Tools FTester Digital Certificates Network Monitoring and Analysis Wingate Public Key Infrastructure (PKI) PRTG Network Monitor Symantec Enterprise Firewall Security Policy Bandwidth Monitoring Hardware Based Firewalls Network Security Policy Bandwidth Monitoring - Best Practices Module 08: Secure IDS Configuration and Key Consideration for Network Security Policy Management Bandwidth Monitoring Tools Types of Network Security Policies Intrusions and IDPS Module 12: Network Risk and Vulnerability Management Network Security Devices Intrusions General Indications of Intrusions What is Risk? Firewalls Intrusion Detection and Prevention Systems (IDPS) Risk Levels DMZ Why do We Need IDPS? Extreme/High Virtual Private Network (VPN) IDS Medium Proxy Server Role of IDS in Network Defense Advantages Of using Proxy Servers Low IDS Functions Honeypot Risk Matrix Advantages of using Honeypots What Events do IDS Examine? Honeypot Tools Risk Management Benefits Intrusion Detection System (IDS) What IDS is NOT? Key Roles and Responsibilities in Risk Intrusion Prevention System (IPS) IDS Activities management IDS/IPS Solutions How IDS Works? Key Risk Indicators(KRI) Network Protocol Analyzer IDS Components Risk Management Phase How it Works Network Sensors

9 Advantages of using Network Protocol Alert Systems Risk Identification Analyzer Command Console Network Protocol Analyzer Tools Response System Establishing Context Attack Signature Database Quantifying Risks Internet Content Filter Intrusion Detection Steps Risk Assessment Advantages of using Internet Content Filters Internet Content Filters Risk Analysis Types of IDS Implementation Risk Prioritization Integrated Network Security Hardware Risk Treatment Approach-based IDS Network Security Protocols Anomaly and Misuse Detection Systems Risk Tracking ; Review Transport Layer Network Layer Behavior-based IDS Application Layer Enterprise Network Risk Management Data Link Layer Protection-based IDS RADIUS Enterprise Risk Management Framework (ERM) Structure-based IDS TACACS+ Goals of ERM Framework Analysis Timing based IDS Kerbros NIST Risk Management Framework Source Data Analysis based IDS Pretty Good Service (PGP) Protocol COSO ERM Framework IDS Deployment Strategies S/MIME Protocol COBIT Framework How it Works Staged IDS Deployment Difference between PGP and S/MIME Risk Management Information Systems Secure HTTP Deploying Network-based IDS (RMIS) Hyper Text Transfer Protocol Secure (HTTPS) Types of IDS Alerts Tools for RMIS Transport Layer Security (TLS) True Positive (Attack - Alert) Enterprise Network Risk Management Policy Internet Protocol Security (IPsec) False Positive (No Attack - Alert) Best Practices for Effective Implementation of Risk Management Module 04: Network Security Policy Design and False Negative(Attack - No Alert) Implementation Vulnerability Management True Negative (No Attack - No Alert) What is Security Policy? Discovery What should be the Acceptable Levels of False Alarms Hierarchy of Security Policy Asset Prioritization Calculating False Positive/False Negative Rate Characteristics of a Good Security Policy Assessment Dealing with False Negative Advantages of Vulnerability Assessment Contents of Security Policy Requirements for Effective Network Vulnerability Assessment Excluding False Positive Alerts with Cisco Types of Vulnerability Assessment Policy Statements Secure IPS Steps for Effective External Vulnerability Assessment

10 Vulnerability Assessment Phases Steps to Create and Implement Security Characteristics of a Good IDS Network Vulnerability Assessment Tools Policies Choosing a Vulnerability Assessment Tool Choosing a Vulnerability Assessment Tool: IDS mistakes that should be avoided Deployment Practices and Precautions Considerations Before Designing a Security Policy Reporting IPS Sample Vulnerability Management Reports Design of Security Policy IPS Technologies Remediation Policy Implementation Checklist Remediation Steps IPS Placement Remediation Plan Types of Information Security Policy Verification IPS Functions Enterprise information security policy(eisp Issue specific security policy(issp) Module 13: Data Backup and Recovery System specific security policy (SSSP) Need of IPS Internet Access Policies Introduction to Data Backup IDS vs IPS Promiscuous Policy Backup Strategy/Plan Types of IPS Permissive Policy Network-Based IPS Identifying Critical Business Data Host-Based IPS Wireless IPS Paranoid Policy Network Behavior Analysis (NBA) Selecting Backup Media System Prudent Policy Network-Based IPS Advantages/Disadvantages of RAID systems Network-Based IPS: Security Capabilities Acceptable-Use Policy Placement of IPS Sensors RAID Storage Architecture Host-Based IPS User-Account Policy RAID Level 0: Disk Striping Host-Based IPS Architecture Remote-Access Policy Wireless IPS RAID Level 1: Disk Mirroring WLAN Components and Architecture Information-Protection Policy Wireless IPS: Network Architecture RAID Level 3: Disk Striping with Parity Security Capabilities Management Firewall-Management Policy RAID Level 5: Block Interleaved Distributed Network Behavior Analysis (NBA) System Parity Special-Access Policy NBA Components and Sensor Locations NBA Security Capabilities RAID Level 10: Blocks Striped and Mirrored Network-Connection Policy IDPS Product Selection Considerations RAID Level 50: Mirroring and Striping across Multiple RAID Levels Business-Partner Policy General Requirements Selecting Appropriate RAID Levels Security Policy Security Capability Requirements Hardware and Software RAIDs Passwords Policy Performance Requirements RAID Usage Best Practices

11 Physical Security Policy Management Requirements Storage Area Network (SAN) Information System Security Policy Life Cycle Costs Advantages of SAN Bring Your Own Devices (BYOD) Policy Complementing IDS SAN Backup Best Practices Software/Application Security Policy Vulnerability Analysis or Assessment Systems SAN Data Storage and Backup Management Data Backup Policy Advantages ; Disadvantages of Tools Vulnerability Analysis Confidential Data Policy File Integrity Checkers Network Attached Storage (NAS) File Integrity Checkers Tools Data Classification Policy Types of NAS Implementation Honey Pot ; Padded Cell Systems Integrated NAS System Internet Usage Policies Honey Pot and Padded Cell System Gateway NAS System Tools Selecting Appropriate Backup Method Server Policy IDS Evaluation: Snort Hot Backup(On) Wireless Network Policy IDS/IPS Solutions Cold Backup(Off) Incidence Response Plan (IRP) IDS Products and Vendors Warm Backup (Near) User Access Control Policy Module 09: Secure VPN Configuration and Management Choosing the Right Location for Backup Switch Security Policy Understanding Virtual Private Network (VPN) Onsite Data Backup Personal Device Usage Policy How VPN works? Offsite Data Backup Encryption Policy Why to Establish VPN? Cloud Data Backup Router Policy VPN Components Backup Types Security Policy Training and Awareness VPN Client Full/Normal Data Backup ISO Information Security Standards Tunnel Terminating Device Differential Data Backup ISO/IEC 27001:2013: Information technology Security Techniques Information security Network Access Server (NAS) Management Systems Requirements Incremental Data Backup VPN Protocol ISO/IEC 27033:Information technology -- Backup Types Advantages and Security techniques -- Network security Disadvantages VPN Concentrators Payment Card Industry Data Security Standard Choosing Right Backup Solution (PCI-DSS) Functions of VPN Concentrator

12 Data Backup Software : AOMEI Backupper Health Insurance Portability and Accountability Types of VPN Act (HIPAA) Data Backup Tools for Windows Data Backup Tools for MAC OS X Client-to-site (Remote-access) VPNs Information Security Acts: Sarbanes Oxley Act Data Recovery (SOX) Site-to-Site VPNs Windows Data Recovery Tool Information Security Acts: Gramm-Leach-Bliley Act (GLBA) Establishing Connections with VPN Recover My Files Information Security Acts: The Digital VPN Categories Millennium Copyright Act (DMCA) and Federal EASEUS Data Recovery Wizard Information Security Management Act (FISMA) Hardware VPNs PC INSPECTOR File Recovery Other Information Security Acts and Laws Hardware VPN Products Software VPNs Data Recovery Tools for MAC OS X Cyber Law in Different Countries Software VPN Products RAID Data Recovery Services Module 05: Physical Security Selecting Appropriate VPN SAN Data Recovery Software Physical Security VPN Core Functions NAS Data Recovery Services Need for Physical Security Encapsulation Module 14: Network Incident Response and Factors Affecting Physical Security Encryption Management Symmetric Encryption Physical Security Controls Asymmetric Encryption Incident Handling and Response Administrative Controls Authentication Physical Controls Incident Response Team Members: Roles Technical Controls and Responsibilities VPN Technologies Physical Security Controls: Location and Architecture Considerations First Responder Hub-and-Spoke VPN Topology Physical Security Controls: Fire Fighting Network Administrators as First Responder Systems Point-to-Point VPN Topology What Should You Know? Physical Security Controls: Physical Barriers Full Mesh VPN Topology First Response Steps by Network Physical Security Controls: Security Personnel Star Topology Administrators Avoid Fear, Uncertainty and Doubt (FUD) Access Control Authentication Techniques Common VPN Flaws Make an Initial Incident Assessment Determining Severity Levels Communicate the Incident Authentication Techniques: Knowledge Factors VPN Fingerprinting Contain the Damage : Avoid Further Harm Control Access to Suspected Devices Collect and Prepare Information about Authentication Techniques: Ownership Factors Insecure Storage of Authentication Suspected Device Credentials by VPN Clients Record Your Actions Restrict Yourself from Doing Investigation Authentication Techniques: Biometric Factors Do Not Change the State of Suspected

13 Username Enumeration Vulnerabilities Device Disable Virus Protection Physical Security Controls Off Password Cracking Incident Handling and Response Process Administrative Controls Physical Controls Technical Controls Man- in- the Middle Attacks Overview of IH;R Process Flow Physical Locks Lack of Account Lockout Preparation for Incident Handling and Response Mechanical locks: Poor Default Configurations Detection and Analysis Combination locks: Poor Guidance and Documentation Classification and Prioritization Electronic /Electric /Electromagnetic locks: VPN Security Incident Prioritization Concealed Weapon/Contraband Detection Devices Firewalls Notification and Planning Mantrap VPN Encryption and Security Protocols Containment Symmetric Encryption Security Labels and Warning Signs Asymmetric Encryption Forensic Investigation Authentication for VPN Access Alarm System Network Forensics Investigation VPN Security: IPsec Server People Involved in Forensics Investigation AAA Server Typical Forensics Investigation Video Surveillance Methodology Connection to VPN: SSH and PPP Eradication and Recovery Physical Security Policies and Procedures Connection to VPN: Concentrator Countermeasures Systems Recovery Other Physical Security Measures VPN Security Radius Post-incident Activities Lighting System Incident Documentation Quality Of Service and Performance in VPNs Incident Damage and Cost Assessment Review and Update the Response Policies Power Supply Improving VPN Speed Training and Awareness Workplace Security Quality of Service (QOS) in VPNs Reception Area SSL VPN Deployment Considerations Server/ Backup Device Security Client security Client integrity scanning Sandbox Critical Assets and Removable Devices Secure logoff and credential wiping Timeouts and re-authentication Virus, malicious code and worm activity Securing Network Cables Audit and Activity awareness Internal Network Security Failings Securing Portable Mobile Devices IP VPN Service Level Management

14 Personnel Security: Managing Staff Hiring and Leaving Process Laptop Security Tool: EXO5 VPN Service Providers Auditing and Testing the VPN Testing VPN File Transfer Laptop Tracking Tools Further Information: For More information, or to book your course, please call us on (0) or training@globalknowledge.com.eg Global Knowledge, 16 Moustafa Refaat St. Block 1137, Sheraton Buildings, Heliopolis, Cairo

EC-Council Certified Network Defender (CND) Duration: 5 Days Method: Instructor-Led

EC-Council Certified Network Defender (CND) Duration: 5 Days Method: Instructor-Led EC-Council Certified Network Defender (CND) Duration: 5 Days Method: Instructor-Led Certification: Certified Network Defender Exam: 312-38 Course Description This course is a vendor-neutral, hands-on,

More information

Course Outline. Module 01: Computer Network and Defense Fundamentals

Course Outline. Module 01: Computer Network and Defense Fundamentals Course Outline Module 01: Computer Network and Defense Fundamentals Network Fundamentals o Computer Network o Types of Network o Major Network Topologies Network Components o Network Interface Card (NIC)

More information

Certified Network Defender v1. Overview

Certified Network Defender v1. Overview Certified Network Defender v1 Overview Certified Network Defender (CND) is a vendor-neutral, hands-on, instructor-led comprehensive network security certification training program. It is a skills-based,

More information

CND Exam Blueprint v2.0

CND Exam Blueprint v2.0 EC-Council C ND Certified Network Defende r CND Exam Blueprint v2.0 CND Exam Blueprint v2.0 1 Domains Objectives Weightage Number of Questions 1. Computer Network and Defense Fundamentals Understanding

More information

Certified Network Defender CND

Certified Network Defender CND Certified Network Defender CND SecureNinja's CND (Certified Network Defender) training and certification boot camp in Alexandria, VA, Dulles, VA and San Diego, CA prepares network administrators on network

More information

CompTIA Security+ (Exam SY0-401)

CompTIA Security+ (Exam SY0-401) CompTIA Security+ (Exam SY0-401) Course Overview This course will prepare students to pass the current CompTIA Security+ SY0-401 certification exam. After taking this course, students will understand the

More information

Security+ SY0-501 Study Guide Table of Contents

Security+ SY0-501 Study Guide Table of Contents Security+ SY0-501 Study Guide Table of Contents Course Introduction Table of Contents About This Course About CompTIA Certifications Module 1 / Threats, Attacks, and Vulnerabilities Module 1 / Unit 1 Indicators

More information

Erasable Programmable Read-Only Memory (EPROM) Electrically Erasable Programmable Read-Only Memory (EEPROM) CMOS 2.2.

Erasable Programmable Read-Only Memory (EPROM) Electrically Erasable Programmable Read-Only Memory (EEPROM) CMOS 2.2. Day - 1 1. INTRODUCTION 1.1 What is Security? 1.2 What is Cyber Security? 1.3 What is Information Security? 1.4 What are the Layers of Security? 1.5 What are the Classification of Security? 1.6 What are

More information

Ethical Hacking and Prevention

Ethical Hacking and Prevention Ethical Hacking and Prevention This course is mapped to the popular Ethical Hacking and Prevention Certification Exam from US-Council. This course is meant for those professionals who are looking for comprehensive

More information

Syllabus: The syllabus is broadly structured as follows:

Syllabus: The syllabus is broadly structured as follows: Syllabus: The syllabus is broadly structured as follows: SR. NO. TOPICS SUBTOPICS 1 Foundations of Network Security Principles of Network Security Network Security Terminologies Network Security and Data

More information

TestOut Network Pro - English 4.1.x COURSE OUTLINE. Modified

TestOut Network Pro - English 4.1.x COURSE OUTLINE. Modified TestOut Network Pro - English 4.1.x COURSE OUTLINE Modified 2017-07-06 TestOut Network Pro Outline - English 4.1.x Videos: 141 (18:42:14) Demonstrations: 81 (10:38:59) Simulations: 92 Fact Sheets: 145

More information

TestOut Network Pro - English 5.0.x COURSE OUTLINE. Modified

TestOut Network Pro - English 5.0.x COURSE OUTLINE. Modified TestOut Network Pro - English 5.0.x COURSE OUTLINE Modified 2018-03-06 TestOut Network Pro Outline - English 5.0.x Videos: 130 (17:10:31) Demonstrations: 78 (8:46:15) Simulations: 88 Fact Sheets: 136 Exams:

More information

CompTIA Security+ Certification

CompTIA Security+ Certification CompTIA Security+ Certification Course Number: SY0-301 Length: 5 Days Certification Exam This course is preparation for the CompTIA Security+ Certification exam. Course Overview This course will prepare

More information

Course overview. CompTIA Security+ Certification (Exam SY0-501) Study Guide (G635eng v107)

Course overview. CompTIA Security+ Certification (Exam SY0-501) Study Guide (G635eng v107) Overview This course is intended for those wishing to qualify with CompTIA Security+. CompTIA's Security+ Certification is a foundation-level certificate designed for IT administrators with 2 years' experience

More information

Chapter 10: Security. 2. What are the two types of general threats to computer security? Give examples of each.

Chapter 10: Security. 2. What are the two types of general threats to computer security? Give examples of each. Name Date Chapter 10: Security After completion of this chapter, students should be able to: Explain why security is important and describe security threats. Explain social engineering, data wiping, hard

More information

This course prepares candidates for the CompTIA Network+ examination (2018 Objectives) N

This course prepares candidates for the CompTIA Network+ examination (2018 Objectives) N CompTIA Network+ (Exam N10-007) Course Description: CompTIA Network+ is the first certification IT professionals specializing in network administration and support should earn. Network+ is aimed at IT

More information

The following chart provides the breakdown of exam as to the weight of each section of the exam.

The following chart provides the breakdown of exam as to the weight of each section of the exam. Introduction The CWSP-205 exam, covering the 2015 objectives, will certify that the successful candidate understands the security weaknesses inherent in WLANs, the solutions available to address those

More information

Curso: Ethical Hacking and Countermeasures

Curso: Ethical Hacking and Countermeasures Curso: Ethical Hacking and Countermeasures Module 1: Introduction to Ethical Hacking Who is a Hacker? Essential Terminologies Effects of Hacking Effects of Hacking on Business Elements of Information Security

More information

FRONT RUNNER DIPLOMA PROGRAM Version 8.0 INFORMATION SECURITY Detailed Course Curriculum Course Duration: 6 months

FRONT RUNNER DIPLOMA PROGRAM Version 8.0 INFORMATION SECURITY Detailed Course Curriculum Course Duration: 6 months FRONT RUNNER DIPLOMA PROGRAM Version 8.0 INFORMATION SECURITY Detailed Course Curriculum Course Duration: 6 months MODULE: INTRODUCTION TO INFORMATION SECURITY INFORMATION SECURITY ESSENTIAL TERMINOLOGIES

More information

CISSP CEH PKI SECURITY + CEHv9: Certified Ethical Hacker. Upcoming Dates. Course Description. Course Outline

CISSP CEH PKI SECURITY + CEHv9: Certified Ethical Hacker. Upcoming Dates. Course Description. Course Outline CISSP CEH PKI SECURITY + CEHv9: Certified Ethical Hacker Learn to find security vulnerabilities before the bad guys do! The Certified Ethical Hacker (CEH) class immerses students in an interactive environment

More information

PROTECTING INFORMATION ASSETS NETWORK SECURITY

PROTECTING INFORMATION ASSETS NETWORK SECURITY PROTECTING INFORMATION ASSETS NETWORK SECURITY PAUL SMITH 20 years of IT experience (desktop, servers, networks, firewalls.) 17 years of engineering in enterprise scaled networks 10+ years in Network Security

More information

CompTIA CSA+ Cybersecurity Analyst

CompTIA CSA+ Cybersecurity Analyst CompTIA CSA+ Cybersecurity Analyst Duration: 5 Days Course Code: Target Audience: The CompTIA Cybersecurity Analyst (CSA+) examination is designed for IT security analysts, vulnerability analysts, or threat

More information

CompTIA Network+ Study Guide Table of Contents

CompTIA Network+ Study Guide Table of Contents CompTIA Network+ Study Guide Table of Contents Course Introduction Table of Contents Getting Started About This Course About CompTIA Certifications Module 1 / Local Area Networks Module 1 / Unit 1 Topologies

More information

ETHICAL HACKING & COMPUTER FORENSIC SECURITY

ETHICAL HACKING & COMPUTER FORENSIC SECURITY ETHICAL HACKING & COMPUTER FORENSIC SECURITY Course Description From forensic computing to network security, the course covers a wide range of subjects. You will learn about web hacking, password cracking,

More information

Securing Information Systems

Securing Information Systems Chapter 7 Securing Information Systems 7.1 2007 by Prentice Hall STUDENT OBJECTIVES Analyze why information systems need special protection from destruction, error, and abuse. Assess the business value

More information

Certified Ethical Hacker (CEH)

Certified Ethical Hacker (CEH) Certified Ethical Hacker (CEH) COURSE OVERVIEW: The most effective cybersecurity professionals are able to predict attacks before they happen. Training in Ethical Hacking provides professionals with the

More information

AURA ACADEMY Training With Expertised Faculty Call Us On For Free Demo

AURA ACADEMY Training With Expertised Faculty Call Us On For Free Demo ETHICAL HACKING (CEH) CURRICULUM Introduction to Ethical Hacking What is Hacking? Who is a Hacker? Skills of a Hacker? Types of Hackers? What are the Ethics and Legality?? Who are at the risk of Hacking

More information

CompTIA Security+(2008 Edition) Exam

CompTIA Security+(2008 Edition) Exam http://www.51- pass.com Exam : SY0-201 Title : CompTIA Security+(2008 Edition) Exam Version : Demo 1 / 7 1.An administrator is explaining the conditions under which penetration testing is preferred over

More information

Hacker Academy Ltd COURSES CATALOGUE. Hacker Academy Ltd. LONDON UK

Hacker Academy Ltd COURSES CATALOGUE. Hacker Academy Ltd. LONDON UK Hacker Academy Ltd COURSES CATALOGUE Hacker Academy Ltd. LONDON UK TABLE OF CONTENTS Basic Level Courses... 3 1. Information Security Awareness for End Users... 3 2. Information Security Awareness for

More information

ACS / Computer Security And Privacy. Fall 2018 Mid-Term Review

ACS / Computer Security And Privacy. Fall 2018 Mid-Term Review ACS-3921-001/4921-001 Computer Security And Privacy Fall 2018 Mid-Term Review ACS-3921/4921-001 Slides Used In The Course A note on the use of these slides: These slides has been adopted and/or modified

More information

Security Assessment Checklist

Security Assessment Checklist Security Assessment Checklist Westcon Security Checklist - Instructions The first step to protecting your business includes a careful and complete assessment of your security posture. Our Security Assessment

More information

Network Security. Thierry Sans

Network Security. Thierry Sans Network Security Thierry Sans HTTP SMTP DNS BGP The Protocol Stack Application TCP UDP Transport IPv4 IPv6 ICMP Network ARP Link Ethernet WiFi The attacker is capable of confidentiality integrity availability

More information

COPYRIGHTED MATERIAL. Contents

COPYRIGHTED MATERIAL. Contents Contents Foreword Introduction xxv xxvii Assessment Test xxxviii Chapter 1 WLAN Security Overview 1 Standards Organizations 3 International Organization for Standardization (ISO) 3 Institute of Electrical

More information

Understanding Cisco Cybersecurity Fundamentals

Understanding Cisco Cybersecurity Fundamentals 210-250 Understanding Cisco Cybersecurity Fundamentals NWExam.com SUCCESS GUIDE TO CISCO CERTIFICATION Exam Summary Syllabus Questions Table of Contents Introduction to 210-250 Exam on Understanding Cisco

More information

Software Development & Education Center Security+ Certification

Software Development & Education Center Security+ Certification Software Development & Education Center Security+ Certification CompTIA Security+ Certification CompTIA Security+ certification designates knowledgeable professionals in the field of security, one of the

More information

Advanced Diploma on Information Security

Advanced Diploma on Information Security Course Name: Course Duration: Prerequisites: Course Fee: Advanced Diploma on Information Security 300 Hours; 12 Months (10 Months Training + 2 Months Project Work) Candidate should be HSC Pass & Basic

More information

Question No: 1 After running a packet analyzer on the network, a security analyst has noticed the following output:

Question No: 1 After running a packet analyzer on the network, a security analyst has noticed the following output: Volume: 75 Questions Question No: 1 After running a packet analyzer on the network, a security analyst has noticed the following output: Which of the following is occurring? A. A ping sweep B. A port scan

More information

Chapter 4. Network Security. Part I

Chapter 4. Network Security. Part I Chapter 4 Network Security Part I CCNA4-1 Chapter 4-1 Introducing Network Security Introduction to Network Security CCNA4-2 Chapter 4-1 Introducing Network Security Why is Network Security important? Rapid

More information

Course 831 Certified Ethical Hacker v9

Course 831 Certified Ethical Hacker v9 Course 831 Certified Ethical Hacker v9 Duration: 5 days What You Get: CEH v9 Certification exam voucher 5 days of high quality classroom training 18 comprehensive modules 40% of class hours dedicated to

More information

Implementing Cisco Network Security (IINS) 3.0

Implementing Cisco Network Security (IINS) 3.0 Implementing Cisco Network Security (IINS) 3.0 COURSE OVERVIEW: Implementing Cisco Network Security (IINS) v3.0 is a 5-day instructor-led course focusing on security principles and technologies, using

More information

Objective Applications, Devices, Protocols Applications, Devices, Protocols Classifying Network Components Objective 1.

Objective Applications, Devices, Protocols Applications, Devices, Protocols Classifying Network Components Objective 1. CompTIA Network+ (Exam N10-005) Course Overview This course is intended for entry-level computer support professionals with basic knowledge of computer hardware, software, and operating systems, who wish

More information

University of Pittsburgh Security Assessment Questionnaire (v1.7)

University of Pittsburgh Security Assessment Questionnaire (v1.7) Technology Help Desk 412 624-HELP [4357] technology.pitt.edu University of Pittsburgh Security Assessment Questionnaire (v1.7) Directions and Instructions for completing this assessment The answers provided

More information

CS System Security 2nd-Half Semester Review

CS System Security 2nd-Half Semester Review CS 356 - System Security 2nd-Half Semester Review Fall 2013 Final Exam Wednesday, 2 PM to 4 PM you may bring one 8-1/2 x 11 sheet of paper with any notes you would like no cellphones, calculators This

More information

ITdumpsFree. Get free valid exam dumps and pass your exam test with confidence

ITdumpsFree.   Get free valid exam dumps and pass your exam test with confidence ITdumpsFree http://www.itdumpsfree.com Get free valid exam dumps and pass your exam test with confidence Exam : 312-50v10 Title : Certified Ethical Hacker Exam (CEH v10) Vendor : EC-COUNCIL Version : DEMO

More information

Fundamentals of Network Security v1.1 Scope and Sequence

Fundamentals of Network Security v1.1 Scope and Sequence Fundamentals of Network Security v1.1 Scope and Sequence Last Updated: September 9, 2003 This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document

More information

Course 831 EC-Council Certified Ethical Hacker v10 (CEH)

Course 831 EC-Council Certified Ethical Hacker v10 (CEH) Course 831 EC-Council Certified Ethical Hacker v10 (CEH) Duration: 5 days What You Get: CEH v10 Certification exam voucher 5 days of high quality classroom training 18 comprehensive modules 40% of class

More information

Wireless Network Security

Wireless Network Security Wireless Network Security Why wireless? Wifi, which is short for wireless fi something, allows your computer to connect to the Internet using magic. -Motel 6 commercial 2 but it comes at a price Wireless

More information

90% 191 Security Best Practices. Blades. 52 Regulatory Requirements. Compliance Report PCI DSS 2.0. related to this regulation

90% 191 Security Best Practices. Blades. 52 Regulatory Requirements. Compliance Report PCI DSS 2.0. related to this regulation Compliance Report PCI DSS 2.0 Generated by Check Point Compliance Blade, on April 16, 2018 15:41 PM O verview 1 90% Compliance About PCI DSS 2.0 PCI-DSS is a legal obligation mandated not by government

More information

Comptia.Certkey.SY0-401.v by.SANFORD.362q. Exam Code: SY Exam Name: CompTIA Security+ Certification Exam

Comptia.Certkey.SY0-401.v by.SANFORD.362q. Exam Code: SY Exam Name: CompTIA Security+ Certification Exam Comptia.Certkey.SY0-401.v2014-09-23.by.SANFORD.362q Number: SY0-401 Passing Score: 800 Time Limit: 120 min File Version: 18.5 Exam Code: SY0-401 Exam Name: CompTIA Security+ Certification Exam Exam A QUESTION

More information

SINGLE COURSE. NH9000 Certified Ethical Hacker 104 Total Hours. COURSE TITLE: Certified Ethical Hacker

SINGLE COURSE. NH9000 Certified Ethical Hacker 104 Total Hours. COURSE TITLE: Certified Ethical Hacker NH9000 Certified Ethical Hacker 104 Total Hours COURSE TITLE: Certified Ethical Hacker COURSE OVERVIEW: This class will immerse the student into an interactive environment where they will be shown how

More information

Cyber Security & Ethical Hacking Training. Introduction to Cyber Security Introduction to Cyber Security. Linux Operating System and Networking: LINUX

Cyber Security & Ethical Hacking Training. Introduction to Cyber Security Introduction to Cyber Security. Linux Operating System and Networking: LINUX Cyber Security & Ethical Hacking Training. Introduction to Cyber Security Introduction to Cyber Security HTML PHP Database Linux Operating System and Networking: LINUX NETWORKING Information Gathering:

More information

Information Security in Corporation

Information Security in Corporation Information Security in Corporation System Vulnerability and Abuse Software Vulnerability Commercial software contains flaws that create security vulnerabilities. Hidden bugs (program code defects) Zero

More information

Chapter 11: It s a Network. Introduction to Networking

Chapter 11: It s a Network. Introduction to Networking Chapter 11: It s a Network Introduction to Networking Small Network Topologies Typical Small Network Topology IT Essentials v5.0 2 Device Selection for a Small Network Factors to be considered when selecting

More information

Cyber Common Technical Core (CCTC) Advance Sheet Windows Operating Systems

Cyber Common Technical Core (CCTC) Advance Sheet Windows Operating Systems Cyber Common Technical Core (CCTC) Advance Sheet Windows Operating Systems Section 1: Command Line Tools Skill 1: Employ commands using command line interface 1.1 Use command line commands to gain situational

More information

GISF. GIAC Information Security Fundamentals.

GISF. GIAC Information Security Fundamentals. GIAC GISF GIAC Information Security Fundamentals TYPE: DEMO http://www.examskey.com/gisf.html Examskey GIAC GISF exam demo product is here for you to test the quality of the product. This GIAC GISF demo

More information

Education Network Security

Education Network Security Education Network Security RECOMMENDATIONS CHECKLIST Learn INSTITUTE Education Network Security Recommendations Checklist This checklist is designed to assist in a quick review of your K-12 district or

More information

Exam : Title : Security Solutions for Systems Engineers. Version : Demo

Exam : Title : Security Solutions for Systems Engineers. Version : Demo Exam : 642-566 Title : Security Solutions for Systems Engineers Version : Demo 1. Which one of the following elements is essential to perform events analysis and correlation? A. implementation of a centralized

More information

Chapter 9. Firewalls

Chapter 9. Firewalls Chapter 9 Firewalls The Need For Firewalls Internet connectivity is essential Effective means of protecting LANs Inserted between the premises network and the Internet to establish a controlled link however

More information

CEH v8 - Certified Ethical Hacker. Course Outline. CEH v8 - Certified Ethical Hacker. 12 May 2018

CEH v8 - Certified Ethical Hacker. Course Outline. CEH v8 - Certified Ethical Hacker.  12 May 2018 Course Outline CEH v8 - Certified Ethical Hacker 12 May 2018 Contents 1. Course Objective 2. Pre-Assessment 3. Exercises, Quizzes, Flashcards & Glossary Number of Questions 4. Expert Instructor-Led Training

More information

V8 - CEH v8 - Certified Ethical Hacker. Course Outline. CEH v8 - Certified Ethical Hacker. 03 Feb 2018

V8 - CEH v8 - Certified Ethical Hacker. Course Outline. CEH v8 - Certified Ethical Hacker.  03 Feb 2018 Course Outline CEH v8 - Certified Ethical Hacker 03 Feb 2018 Contents 1. Course Objective 2. Pre-Assessment 3. Exercises, Quizzes, Flashcards & Glossary Number of Questions 4. Expert Instructor-Led Training

More information

CIH

CIH mitigating at host level, 23 25 at network level, 25 26 Morris worm, characteristics of, 18 Nimda worm, characteristics of, 20 22 replacement login, example of, 17 signatures. See signatures SQL Slammer

More information

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

PASS4TEST. IT Certification Guaranteed, The Easy Way!  We offer free update service for one year PASS4TEST IT Certification Guaranteed, The Easy Way! \ http://www.pass4test.com We offer free update service for one year Exam : GSLC Title : GIAC Security Leadership Certification (GSLC) Vendors : GIAC

More information

CompTIA Cybersecurity Analyst+

CompTIA Cybersecurity Analyst+ CompTIA Cybersecurity Analyst+ Course CT-04 Five days Instructor-Led, Hands-on Introduction This five-day, instructor-led course is intended for those wishing to qualify with CompTIA CSA+ Cybersecurity

More information

CompTIA E2C Security+ (2008 Edition) Exam Exam.

CompTIA E2C Security+ (2008 Edition) Exam Exam. CompTIA JK0-015 CompTIA E2C Security+ (2008 Edition) Exam Exam TYPE: DEMO http://www.examskey.com/jk0-015.html Examskey CompTIA JK0-015 exam demo product is here for you to test the quality of the product.

More information

CHCSS. Certified Hands-on Cyber Security Specialist (510)

CHCSS. Certified Hands-on Cyber Security Specialist (510) CHCSS Certified Hands-on Cyber Security Specialist () SYLLABUS 2018 Certified Hands-on Cyber Security Specialist () 2 Course Description Entry level cyber security course intended for an audience looking

More information

Implementing Cisco Cybersecurity Operations

Implementing Cisco Cybersecurity Operations 210-255 Implementing Cisco Cybersecurity Operations NWExam.com SUCCESS GUIDE TO CISCO CERTIFICATION Exam Summary Syllabus Questions Table of Contents Introduction to 210-255 Exam on Implementing Cisco

More information

Chapter 1 Describing Regulatory Compliance

Chapter 1 Describing Regulatory Compliance [ 2 ] Chapter 1 Describing Regulatory Compliance Failure to secure a WLAN makes it vulnerable to attack. To properly secure your network, you must be able to identify common threats to wireless and know

More information

PracticeDump. Free Practice Dumps - Unlimited Free Access of practice exam

PracticeDump.   Free Practice Dumps - Unlimited Free Access of practice exam PracticeDump http://www.practicedump.com Free Practice Dumps - Unlimited Free Access of practice exam Exam : SY0-501 Title : CompTIA Security+ Certification Exam Vendor : CompTIA Version : DEMO Get Latest

More information

Chapter 11: Networks

Chapter 11: Networks Chapter 11: Networks Devices in a Small Network Small Network A small network can comprise a few users, one router, one switch. A Typical Small Network Topology looks like this: Device Selection Factors

More information

PRODUCT GUIDE Wireless Intrusion Prevention Systems

PRODUCT GUIDE Wireless Intrusion Prevention Systems PRODUCT GUIDE Wireless Intrusion Prevention Systems The Need for Wireless INTRUSION PREVENTION SYSTEMS A Wireless Intrusion Prevention System (WIPS) is designed to address two classes of challenges facing

More information

ECCouncil Exam v9 Certified Ethical Hacker Exam V9 Version: 7.0 [ Total Questions: 125 ]

ECCouncil Exam v9 Certified Ethical Hacker Exam V9 Version: 7.0 [ Total Questions: 125 ] s@lm@n ECCouncil Exam 312-50v9 Certified Ethical Hacker Exam V9 Version: 7.0 [ Total Questions: 125 ] Question No : 1 An Intrusion Detection System(IDS) has alerted the network administrator to a possibly

More information

CCISO Blueprint v1. EC-Council

CCISO Blueprint v1. EC-Council CCISO Blueprint v1 EC-Council Categories Topics Covered Weightage 1. Governance (Policy, Legal, & Compliance) & Risk Management 1.1 Define, implement, manage and maintain an information security governance

More information

SYLLABUS DATE OF LAST REVIEW: 012/2016 CIP CODE: Departmental Syllabus SEMESTER: Information Assurance COURSE TITLE: CIST0225 COURSE NUMBER:

SYLLABUS DATE OF LAST REVIEW: 012/2016 CIP CODE: Departmental Syllabus SEMESTER: Information Assurance COURSE TITLE: CIST0225 COURSE NUMBER: SYLLABUS DATE OF LAST REVIEW: 012/2016 CIP CODE: 24.0101 SEMESTER: COURSE TITLE: COURSE NUMBER: Information Assurance CIST0225 CREDIT HOURS: 4 INSTRUCTOR: OFFICE LOCATION: OFFICE HOURS: TELEPHONE: EMAIL:

More information

CompTIA Network+ N10-005

CompTIA Network+ N10-005 CompTIA Network+ N10-005 Course Number: Network+ N10-005 Length: 7 Day(s) Certification Exam This course is preparation for the CompTIA Network+ N10-005 Certification exam Course Overview The CompTIA Network+

More information

Network Security and Cryptography. December Sample Exam Marking Scheme

Network Security and Cryptography. December Sample Exam Marking Scheme Network Security and Cryptography December 2015 Sample Exam Marking Scheme This marking scheme has been prepared as a guide only to markers. This is not a set of model answers, or the exclusive answers

More information

Table of Contents (CISSP 2012 Edition)

Table of Contents (CISSP 2012 Edition) Table of Contents (CISSP 2012 Edition) CONTENT UPDATES... 6 ABOUT THIS BOOK... 7 NETWORK INFRASTRUCTURE, PROTOCOLS AND TECHNOLOGIES... 8 OPEN SYSTEM INTERCONNECT... 8 LAN NETWORKING...10 ROUTING AND SWITCHING...13

More information

Scanning. Introduction to Hacking. Networking Concepts. Windows Hacking. Linux Hacking. Virus and Worms. Foot Printing.

Scanning. Introduction to Hacking. Networking Concepts. Windows Hacking. Linux Hacking. Virus and Worms. Foot Printing. I Introduction to Hacking Important Terminology Ethical Hacking vs. Hacking Effects of Hacking on Business Why Ethical Hacking Is Necessary Skills of an Ethical Hacker What Is Penetration Testing? Networking

More information

Cisco Exam Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ]

Cisco Exam Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ] s@lm@n Cisco Exam 642-737 Implementing Advanced Cisco Unified Wireless Security v2.0 Version: 9.0 [ Total Questions: 206 ] Cisco 642-737 : Practice Test Question No : 1 RADIUS is set up with multiple servers

More information

ACS-3921/ Computer Security And Privacy. Chapter 9 Firewalls and Intrusion Prevention Systems

ACS-3921/ Computer Security And Privacy. Chapter 9 Firewalls and Intrusion Prevention Systems ACS-3921/4921-001 Computer Security And Privacy Chapter 9 Firewalls and Intrusion Prevention Systems ACS-3921/4921-001 Slides Used In The Course A note on the use of these slides: These slides has been

More information

Training UNIFIED SECURITY. Signature based packet analysis

Training UNIFIED SECURITY. Signature based packet analysis Training UNIFIED SECURITY Signature based packet analysis At the core of its scanning technology, Kerio Control integrates a packet analyzer based on Snort. Snort is an open source IDS/IPS system that

More information

Identify the features of network and client operating systems (Windows, NetWare, Linux, Mac OS)

Identify the features of network and client operating systems (Windows, NetWare, Linux, Mac OS) Course Outline Network+ Duration: 5 days (30 hours) Learning Objectives: Install and configure a network card Define the concepts of network layers Understand and implement the TCP/IP protocol Install

More information

Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy

Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy CHAPTER 9 DEVELOPING NETWORK SECURITY STRATEGIES Expected Outcomes Able to design the network security for the entire network Able to develop and suggest the security plan and policy Network Security Design

More information

Network Security. Kitisak Jirawannakool Electronics Government Agency (public organisation)

Network Security. Kitisak Jirawannakool Electronics Government Agency (public organisation) 1 Network Security Kitisak Jirawannakool Electronics Government Agency (public organisation) A Brief History of the World 2 OSI Model vs TCP/IP suite 3 TFTP & SMTP 4 ICMP 5 NAT/PAT 6 ARP/RARP 7 DHCP 8

More information

PASS4TEST. IT Certification Guaranteed, The Easy Way! We offer free update service for one year

PASS4TEST. IT Certification Guaranteed, The Easy Way!  We offer free update service for one year PASS4TEST IT Certification Guaranteed, The Easy Way! \ http://www.pass4test.com We offer free update service for one year Exam : ECSS Title : EC-Council Certified Security Specialist Practice Test Vendors

More information

CEH: CERTIFIED ETHICAL HACKER v9

CEH: CERTIFIED ETHICAL HACKER v9 CEH: CERTIFIED ETHICAL HACKER v9 SUMMARY The Certified Ethical Hacker (CEH) program is the core of the most desired information security training system any information security professional will ever

More information

CompTIA Security+ E2C (2011 Edition) Exam.

CompTIA Security+ E2C (2011 Edition) Exam. CompTIA JK0-018 CompTIA Security+ E2C (2011 Edition) Exam TYPE: DEMO http://www.examskey.com/jk0-018.html Examskey CompTIA JK0-018 exam demo product is here for you to test the quality of the product.

More information

Course 832 EC-Council Computer Hacking Forensic Investigator (CHFI)

Course 832 EC-Council Computer Hacking Forensic Investigator (CHFI) Course 832 EC-Council Computer Hacking Forensic Investigator (CHFI) Duration: 5 days You Will Learn How To Understand how perimeter defenses work Scan and attack you own networks, without actually harming

More information

ProCurve Network Immunity

ProCurve Network Immunity ProCurve Network Immunity Hans-Jörg Elias Key Account Manager hans-joerg.elias@hp.com 2007 Hewlett-Packard Development Company, L.P. The information contained herein is subject to change without notice.

More information

CTS2134 Introduction to Networking. Module 08: Network Security

CTS2134 Introduction to Networking. Module 08: Network Security CTS2134 Introduction to Networking Module 08: Network Security Denial of Service (DoS) DoS (Denial of Service) attack impacts system availability by flooding the target system with traffic or by exploiting

More information

Fundamentals of Information Systems Security Lesson 8 Mitigation of Risk and Threats to Networks from Attacks and Malicious Code

Fundamentals of Information Systems Security Lesson 8 Mitigation of Risk and Threats to Networks from Attacks and Malicious Code Fundamentals of Information Systems Security Lesson 8 Mitigation of Risk and Threats to Networks from Attacks and Malicious Code Learning Objective Explain the importance of network principles and architecture

More information

CEH v8 - Certified Ethical Hacker. Course Outline. CEH v8 - Certified Ethical Hacker. 15 Jan

CEH v8 - Certified Ethical Hacker. Course Outline. CEH v8 - Certified Ethical Hacker. 15 Jan Course Outline CEH v8 - Certified Ethical Hacker 15 Jan 2019 Contents 1. Course Objective 2. Pre-Assessment 3. Exercises, Quizzes, Flashcards & Glossary Number of Questions 4. Expert Instructor-Led Training

More information

Cisco 1: Networking Fundamentals

Cisco 1: Networking Fundamentals Western Technical College 10150110 Cisco 1: Networking Fundamentals Course Outcome Summary Course Information Description Career Cluster Instructional Level Total Credits 3.00 Total Hours 90.00 This course

More information

Cybersecurity Foundations

Cybersecurity Foundations Cybersecurity Foundations Varighed: 5 Days Kursus Kode: 9701 Beskrivelse: In this cybersecurity course, you will gain a global perspective of the challenges of designing a secure system, touching on all

More information

CIS Controls Measures and Metrics for Version 7

CIS Controls Measures and Metrics for Version 7 Level 1.1 Utilize an Active Discovery Tool 1.2 Use a Passive Asset Discovery Tool 1.3 Use DHCP Logging to Update Asset Inventory 1.4 Maintain Detailed Asset Inventory 1.5 Maintain Asset Inventory Information

More information

Internetwork Expert s CCNA Security Bootcamp. Common Security Threats

Internetwork Expert s CCNA Security Bootcamp. Common Security Threats Internetwork Expert s CCNA Security Bootcamp Common Security Threats http:// Today s s Network Security Challenge The goal of the network is to provide high availability and easy access to data to meet

More information

CIS Controls Measures and Metrics for Version 7

CIS Controls Measures and Metrics for Version 7 Level One Level Two Level Three Level Four Level Five Level Six 1.1 Utilize an Active Discovery Tool Utilize an active discovery tool to identify devices connected to the organization's network and update

More information

CompTIA Security+ (2008 Edition) Exam

CompTIA Security+ (2008 Edition) Exam CompTIA SY0-201 CompTIA Security+ (2008 Edition) Exam Version: 7.20 Topic 1, Volume A QUESTION NO: 1 Which of the following cryptography types provides the same level of security but uses smaller key sizes

More information

Defense-in-Depth Against Malicious Software. Speaker name Title Group Microsoft Corporation

Defense-in-Depth Against Malicious Software. Speaker name Title Group Microsoft Corporation Defense-in-Depth Against Malicious Software Speaker name Title Group Microsoft Corporation Agenda Understanding the Characteristics of Malicious Software Malware Defense-in-Depth Malware Defense for Client

More information

Security+ Practice Questions Exam Cram 2 (Exam SYO-101) Copyright 2004 by Que Publishing. International Standard Book Number:

Security+ Practice Questions Exam Cram 2 (Exam SYO-101) Copyright 2004 by Que Publishing. International Standard Book Number: Security+ Practice Questions Exam Cram 2 (Exam SYO-101) Copyright 2004 by Que Publishing International Standard Book Number: 0789731517 Warning and Disclaimer Every effort has been made to make this book

More information

BOR3307: Intro to Cybersecurity

BOR3307: Intro to Cybersecurity Key Terms for lesson 4 are listed below: It is important that you maintain a copy of these key terms handy as you take this course and complete the readings. Working from a standard lexicon will keep you

More information