From Wikibooks, open books for an open world
< Security+ Certification
This page may need to be
reviewed for quality.
[edit] 4.1 Conduct risk assessments and implement risk mitigation
[edit] 4.2 Carry out vulnerability assessment using common tools
- Port scanners
- Vulnerability scanners
- Protocol analyzers
|
- OVAL
- Password crackers
- Network mappers
|
[edit] 4.3 Explain the proper use of penetration testing versus vulnerability scanning
[edit] 4.4 Use monitoring tools on systems and networks and detect security-related anomalies
- Performance monitor
- Systems monitor
- Performance baseline
- Protocol analyzers
[edit] 4.5 Compare and contrast various types of monitoring methodologies
- Behavior-based
- Signature-based
- Anomaly-based
[edit] 4.6 Execute proper logging procedures and evaluate the results
- Security application
- DNS
- System
- Performance
|
- Access
- Firewall
- Antivirus
|
[edit] 4.7 Conduct periodic audits of system security settings
- User access and rights review
- Storage and retention policies
- Group policies