Security+ Certification/Assessments & Audits

From Wikibooks, open books for an open world
< Security+ Certification
Jump to: navigation, search

Contents

[edit] 4.1 Conduct risk assessments and implement risk mitigation

[edit] 4.2 Carry out vulnerability assessment using common tools

  • Port scanners
  • Vulnerability scanners
  • Protocol analyzers
  • OVAL
  • Password crackers
  • Network mappers

[edit] 4.3 Explain the proper use of penetration testing versus vulnerability scanning

[edit] 4.4 Use monitoring tools on systems and networks and detect security-related anomalies

  • Performance monitor
  • Systems monitor
  • Performance baseline
  • Protocol analyzers

[edit] 4.5 Compare and contrast various types of monitoring methodologies

  • Behavior-based
  • Signature-based
  • Anomaly-based

[edit] 4.6 Execute proper logging procedures and evaluate the results

  • Security application
  • DNS
  • System
  • Performance
  • Access
  • Firewall
  • Antivirus

[edit] 4.7 Conduct periodic audits of system security settings

  • User access and rights review
  • Storage and retention policies
  • Group policies
Personal tools
Namespaces
Variants
Actions
Navigation
Community
Toolbox
Sister projects
Print/export