- CompTIA Security+ Certification Exam Objectives
Download (https://www.comptia.jp/pdf/Security%2B%20SY0-501%20Exam%20Objectives.pdf) - CIA Triad
- AAA of Security (OBJ 2.4)
- Security Threats (OBJ 1.1 & 1.2)
- Mitigating Threats (OBJ 5.1)
- Hackers (OBJ 1.5)
- Threat Actors (1.5)
- Threat Intelligence and Sources (OBJ 1.5)
- Threat Hunting (OBJ 1.7)
- Attack Frameworks (OBJ 4.2)
● CIA Triad
o Confidentiality
▪ Information has not been disclosed to unauthorized people
o Integrity
▪ Information has not been modified or altered without proper
authorization
o Availability
▪ Information is able to be stored, accessed, or protected at all times
● AAA of Security
o Authentication
▪ When a person’s identity is established with proof and confirmed by a
system
● Something you know
● Something you are
● Something you have
● Something you do
● Somewhere you are
o Authorization
▪ Occurs when a user is given access to a certain piece of data or certain
areas of a building
o Accounting
▪ Tracking of data, computer usage, and network resources
▪ Non-repudiation occurs when you have proof that someone has taken an
action
● Security Threats
o Malware
▪ Short-hand term for malicious software
o Unauthorized Access
▪ Occurs when access to computer resources and data occurs without the
consent of the owner
o System Failure
▪ Occurs when a computer crashes or an individual application fails
o Social Engineering
▪ Act of manipulating users into revealing confidential information or
performing other detrimental actions
● Mitigating Threats
o Physical Controls
▪ Alarm systems, locks, surveillance cameras, identification cards, and
security guards
o Technical Controls
▪ Smart cards, encryption, access control lists (ACLs), intrusion detection
systems, and network authentication
o Administrative Controls
▪ Policies, procedures, security awareness training, contingency planning,
and disaster recovery plans
▪ User training is the most cost-effective security control to use
● Hackers
o Five Types of Hackers
▪ White Hats
● Non-malicious hackers who attempt to break into a company’s
systems at their request
▪ Black Hats
● Malicious hackers who break into computer systems and
networks without authorization or permission
▪ Gray Hats
● Hackers without any affiliation to a company who attempt to
break into a company’s network but risk the law by doing so
▪ Blue Hats
● Hackers who attempt to hack into a network with permission of
the company but are not employed by the company
▪ Elite
● Hackers who find and exploit vulnerabilities before anyone else
does
● 1 in 10,000 are elite
o Script kiddies have limited skill and only run other people’s exploits and tools
● Threat Actors
o Script Kiddies
▪ Hackers with little to no skill who only use the tools and exploits written
by others
o Hacktivists
▪ Hackers who are driven by a cause like social change, political agendas, or
terrorism
o Organized Crime
▪ Hackers who are part of a crime group that is well-funded and highly
sophisticated
o Advanced Persistent Threats
▪ Highly trained and funded groups of hackers (often by nation states) with
covert and open-source intelligence at their disposal
沒有留言:
張貼留言