Learn the detailed information you need to prepare for the Vulnerability Management domain of the Cybersecurity Analyst+ (CySA+) exam.
Overview
Syllabus
Introduction
- Vulnerability management
- What you need to know
- Study resources
- What is vulnerability management?
- Identify scan targets
- Scan frequency
- Network scanning
- Install Nmap on Windows
- Install Nmap on macOS
- Run and interpret a simple Nmap scan
- Host discovery with Nmap
- Operate system fingerprinting
- Service version detection
- Security baseline scanning
- Scan configuration
- Scan perspective
- Scanner maintenance
- Vulnerability scanning tools
- Passive vulnerability scanning
- SCAP
- CVSS
- Interpret CVSS scores
- Analyze scan reports
- Correlate scan results
- Server vulnerabilities
- Endpoint vulnerabilities
- Network vulnerabilities
- OWASP Top 10
- Prevent SQL injection
- Understand cross-site scripting
- Request forgery
- Privilege escalation
- Directory traversal
- File inclusion
- Overflow attacks
- Cookies and attachments
- Session hijacking
- Race conditions
- Memory vulnerabilities
- Code execution attacks
- Data poisoning
- Third-party code
- Interception proxies
- Industrial control systems
- Internet of Things
- Embedded systems
- Exploitation frameworks
- Cloud auditing tools
- Debuggers
- Open-source reconnaissance
- Control frameworks
- Software platforms
- Development methodologies
- Maturity models
- Change management
- Input validation
- Parameterized queries
- Authentication and session management issues
- Output encoding
- Error and exception handling
- Code signing
- Database security
- Data de-identification
- Data obfuscation
- Software testing
- Code security tests
- Fuzzing
- Reverse engineering software
- Reverse engineering hardware
- Threat research
- Identify threats
- Understand attacks
- Threat modeling
- Attack surface management
- Bug bounty
- Align security with the business
- Organizational processes
- Security roles and responsibilities
- Security control selection
- Risk assessment
- Quantitative risk assessment
- Risk treatment options
- Risk management frameworks
- Risk visibility and reporting
- Continue your studies
Taught by
Mike Chapple