Book description
Get complete coverage of all objectives included on the latest release of the CompTIA Security+ exam from this comprehensive resource. Cowritten by leading information security experts, this authoritative guide fully addresses the skills required for securing a network and managing risk. You'll find learning objectives at the beginning of each chapter, exam tips, practice exam questions, and in-depth explanations. Designed to help you pass CompTIA Security+ exam SY0-401, this definitive volume also serves as an essential on-the-job reference.
COVERS ALL EXAM DOMAINS, INCLUDING:
Network security
Compliance and operational security
Threats and vulnerabilities
Application, data, and host security
Access control and identity management
Cryptography
ELECTRONIC CONTENT INCLUDES
- 200 practice exam questions
- Test engine that provides practice exams or quizzes that can be customized by chapter or exam objective
Table of contents
- Cover
- Title Page
- Copyright Page
- About the Authors
- Dedication
- Contents at a Glance
- Contents
- Preface
- Acknowledgments
- Introduction
- Part I Network Security
-
Part II Compliance and Operational Security
-
Chapter 5 Risk Concepts
-
An Overview of Risk Management
- Key Terms for Understanding Risk Management
- Control Types
- False Positives
- False Negatives
- Importance of Policies in Reducing Risk
- Qualitative Risk Assessment
- Quantitative Risk Assessment
- Risk Calculation
- Quantitative vs. Qualitative
- Vulnerabilities
- Threat Vectors
- Probability/Threat Likelihood
- Risk Avoidance, Transference, Acceptance, Mitigation, Deterrence
- The Cloud
- Chapter Review
-
An Overview of Risk Management
- Chapter 6 System Integration Processes
- Chapter 7 Risk Management
- Chapter 8 Digital Forensics and Incident Response
- Chapter 9 Security Awareness and Training
- Chapter 10 Physical Security and Environmental Controls
- Chapter 11 Security Controls
-
Chapter 5 Risk Concepts
-
Part III Threats and Vulnerabilities
-
Chapter 12 Attacks and Malware
- Malware
-
Attack Methods
- Man-in-the-Middle
- Denial-of-Service
- Distributed Denial-of-Service
- Replay
- Spoofing
- Spam
- Spim
- Phishing
- Spear Phishing
- Vishing
- Xmas Attack
- Pharming
- Privilege Escalation
- Malicious Insider Threat
- Cache Poisoning
- TCP/IP Hijacking
- Transitive Access
- Client-side Attacks
- Password Attacks
- Typo Squatting/URL Hijacking
- Watering Hole Attack
- Chapter Review
- Chapter 13 Social Engineering
- Chapter 14 Application and Wireless Attacks
- Chapter 15 Mitigation Techniques
- Chapter 16 Threat and Vulnerability Discovery
-
Chapter 12 Attacks and Malware
-
Part IV Application, Data, and Host Security
- Chapter 17 Application Security Controls
- Chapter 18 Mobile Device Security
- Chapter 19 Host-based Security
- Chapter 20 Securing Alternative Environments
- Part V Access Control and Identity Management
-
Part VI Cryptography
- Chapter 23 Cryptographic Concepts
- Chapter 24 Cryptographic Methods
- Part VII Appendixes and Glossary
- Glossary
- Index
Product information
- Title: CompTIA Security+ All-in-One Exam Guide, Fourth Edition (Exam SY0-401), 4th Edition
- Author(s):
- Release date: December 2014
- Publisher(s): McGraw-Hill
- ISBN: 9780071837354
You might also like
book
Improve your speed reading skills
READ FASTER, LEARN MORE, ACHIEVE MORE Improve Your Speed Reading Skills and breeze through books, newspapers, …
video
Full Stack Web Development Mastery Course - Novice to Expert
Full stack development refers to the development of both frontend (client-side) and backend (server-side) portions of …
book
HBR's 10 Must Reads on Communication 2-Volume Collection
If you read nothing else on communicating effectively, read these definitive articles from Harvard Business Review. …
video
Introduction to ChatGPT and OpenAI
OpenAI ChatGPT is a powerful language model that uses advanced ML techniques to generate human-like text …