{"product_id":"comptia-security-deluxe-study-guide-w-online-lab-exam-sy0601-5e-9781119812289","title":"CompTIA Security Deluxe Study Guide w Online Lab","description":"\u003cb\u003eBook Synopsis\u003c\/b\u003e\u003cbr\u003eLearn the key objectives and most crucial concepts covered by the Security+ Exam SY0-601with this comprehensive and practical Deluxe Study GuideCovers 100% of exam objectives including threats, attacks, and vulnerabilities; technologies and tools; architecture and design; identity and access management; risk management; cryptography and PKI, and much more... Includes interactive online learning environment and study tools with: 4 custom practice exams100 Electronic FlashcardsSearchable key term glossaryPlus 33 Online Security+ Practice Lab Modules Expert Security+ SY0-601 exam preparation--Now with 33 Online Lab Modules The Fifth edition ofCompTIA Security+ Deluxe Study Guideoffers invaluable preparation for Exam SY0-601. Written by expert authors, Mike Chapple and David Seidl, the book covers 100% of the exam objectives with clear and concise explanations. Discover how to handle threats, attacks, and vulnerabilities using industry-standard tools and technologies, while gaining and understanding the role of architecture and design. Spanning topics from everyday tasks like identity and access management to complex subjects such as risk management and cryptography, this study guide helps you consolidate your knowledge base in preparation for the Security+ exam. Illustrative examples show how these processes play out in real-world scenarios, allowing you to immediately translate essential concepts to on-the-job application.    Coverage of 100% of all exam objectives in this Study Guide means you'll be ready for: Attacks, Threats, and VulnerabilitiesArchitecture and DesignImplementationOperations and Incident ResponseGovernance, Risk, and Compliance Interactive learning environment Take your exam prep to the next level with Sybex's superior interactive online study tools. To access our learning environment, simply visitwww.wiley.com\/go\/sybextestprep,register your book to receive your unique PIN, and instantly gain one year of FREE access after activation to: Interactive test bank with 4 bonus exams. Practice questions help you identify areas where further review is needed.   100 Electronic Flashcards to reinforce learning and last-minute prep before the exam.   Comprehensive glossary in PDF format gives you instant access to the key terms so you are fully prepared.    ABOUT THE PRACTICE LABS SECURITY+ LABS So you can practice with hands-on learning in a real environment, Sybex has bundled Practice Labs virtual labs that run from your browser. The registration code is included with the book and gives you 6 months unlimited access to Practice Labs CompTIA Security+ Exam SY0-601 Labs with 33 unique lab modules to practice your skills.    If you are unable to register your lab PIN code, please contact Wiley customer support for a replacement PIN code.\u003cbr\u003e\u003cbr\u003e\u003cb\u003eTable of Contents\u003c\/b\u003e\u003cbr\u003e\u003cp\u003eIntroduction xxv\u003c\/p\u003e \u003cp\u003eAssessment Test xxxvi\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1 Today’s Security Professional 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eCybersecurity Objectives 2\u003c\/p\u003e \u003cp\u003eData Breach Risks 3\u003c\/p\u003e \u003cp\u003eThe DAD Triad 3\u003c\/p\u003e \u003cp\u003eBreach Impact 5\u003c\/p\u003e \u003cp\u003eImplementing Security Controls 7\u003c\/p\u003e \u003cp\u003eSecurity Control Categories 7\u003c\/p\u003e \u003cp\u003eSecurity Control Types 8\u003c\/p\u003e \u003cp\u003eData Protection 9\u003c\/p\u003e \u003cp\u003eSummary 12\u003c\/p\u003e \u003cp\u003eExam Essentials 12\u003c\/p\u003e \u003cp\u003eReview Questions 14\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2 Cybersecurity Threat Landscape 19\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eExploring Cybersecurity Threats 20\u003c\/p\u003e \u003cp\u003eClassifying Cybersecurity Threats 20\u003c\/p\u003e \u003cp\u003eThreat Actors 22\u003c\/p\u003e \u003cp\u003eThreat Vectors 28\u003c\/p\u003e \u003cp\u003eThreat Data and Intelligence 30\u003c\/p\u003e \u003cp\u003eOpen Source Intelligence 31\u003c\/p\u003e \u003cp\u003eProprietary and Closed-Source Intelligence 33\u003c\/p\u003e \u003cp\u003eAssessing Threat Intelligence 35\u003c\/p\u003e \u003cp\u003eThreat Indicator Management and Exchange 36\u003c\/p\u003e \u003cp\u003ePublic and Private Information Sharing Centers 37\u003c\/p\u003e \u003cp\u003eConducting Your Own Research 38\u003c\/p\u003e \u003cp\u003eSummary 38\u003c\/p\u003e \u003cp\u003eExam Essentials 39\u003c\/p\u003e \u003cp\u003eReview Questions 40\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3 Malicious Code 45\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eMalware 46\u003c\/p\u003e \u003cp\u003eRansomware 47\u003c\/p\u003e \u003cp\u003eTrojans 47\u003c\/p\u003e \u003cp\u003eWorms 48\u003c\/p\u003e \u003cp\u003eRootkits 48\u003c\/p\u003e \u003cp\u003eBackdoors 49\u003c\/p\u003e \u003cp\u003eBots 50\u003c\/p\u003e \u003cp\u003eKeyloggers 52\u003c\/p\u003e \u003cp\u003eLogic Bombs 53\u003c\/p\u003e \u003cp\u003eViruses 53\u003c\/p\u003e \u003cp\u003eFileless Viruses 53\u003c\/p\u003e \u003cp\u003eSpyware 54\u003c\/p\u003e \u003cp\u003ePotentially Unwanted Programs (PUPs) 55\u003c\/p\u003e \u003cp\u003eMalicious Code 55\u003c\/p\u003e \u003cp\u003eAdversarial Artificial Intelligence 57\u003c\/p\u003e \u003cp\u003eSummary 58\u003c\/p\u003e \u003cp\u003eExam Essentials 59\u003c\/p\u003e \u003cp\u003eReview Questions 61\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4 Social Engineering, Physical, and Password Attacks 65\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eSocial Engineering 66\u003c\/p\u003e \u003cp\u003eSocial Engineering Techniques 67\u003c\/p\u003e \u003cp\u003eInfluence Campaigns 72\u003c\/p\u003e \u003cp\u003ePassword Attacks 72\u003c\/p\u003e \u003cp\u003ePhysical Attacks 74\u003c\/p\u003e \u003cp\u003eSummary 76\u003c\/p\u003e \u003cp\u003eExam Essentials 76\u003c\/p\u003e \u003cp\u003eReview Questions 78\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 5 Security Assessment and Testing 83\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eVulnerability Management 84\u003c\/p\u003e \u003cp\u003eIdentifying Scan Targets 84\u003c\/p\u003e \u003cp\u003eDetermining Scan Frequency 86\u003c\/p\u003e \u003cp\u003eConfiguring Vulnerability Scans 87\u003c\/p\u003e \u003cp\u003eScanner Maintenance 92\u003c\/p\u003e \u003cp\u003eVulnerability Scanning Tools 95\u003c\/p\u003e \u003cp\u003eReviewing and Interpreting Scan Reports 96\u003c\/p\u003e \u003cp\u003eValidating Scan Results 106\u003c\/p\u003e \u003cp\u003eSecurity Vulnerabilities 107\u003c\/p\u003e \u003cp\u003ePatch Management 107\u003c\/p\u003e \u003cp\u003eLegacy Platforms 108\u003c\/p\u003e \u003cp\u003eWeak Configurations 109\u003c\/p\u003e \u003cp\u003eError Messages 110\u003c\/p\u003e \u003cp\u003eInsecure Protocols 111\u003c\/p\u003e \u003cp\u003eWeak Encryption 112\u003c\/p\u003e \u003cp\u003ePenetration Testing 113\u003c\/p\u003e \u003cp\u003eAdopting the Hacker Mindset 114\u003c\/p\u003e \u003cp\u003eReasons for Penetration Testing 115\u003c\/p\u003e \u003cp\u003eBenefits of Penetration Testing 115\u003c\/p\u003e \u003cp\u003ePenetration Test Types 116\u003c\/p\u003e \u003cp\u003eRules of Engagement 118\u003c\/p\u003e \u003cp\u003eReconnaissance 119\u003c\/p\u003e \u003cp\u003eRunning the Test 120\u003c\/p\u003e \u003cp\u003eCleaning Up 120\u003c\/p\u003e \u003cp\u003eTraining and Exercises 120\u003c\/p\u003e \u003cp\u003eSummary 122\u003c\/p\u003e \u003cp\u003eExam Essentials 122\u003c\/p\u003e \u003cp\u003eReview Questions 124\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 6 Secure Coding 129\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eSoftware Assurance Best Practices 130\u003c\/p\u003e \u003cp\u003eThe Software Development Life Cycle 130\u003c\/p\u003e \u003cp\u003eSoftware Development Phases 131\u003c\/p\u003e \u003cp\u003eSoftware Development Models 133\u003c\/p\u003e \u003cp\u003eDevSecOps and DevOps 136\u003c\/p\u003e \u003cp\u003eDesigning and Coding for Security 138\u003c\/p\u003e \u003cp\u003eSecure Coding Practices 138\u003c\/p\u003e \u003cp\u003eAPI Security 139\u003c\/p\u003e \u003cp\u003eCode Review Models 139\u003c\/p\u003e \u003cp\u003eSoftware Security Testing 143\u003c\/p\u003e \u003cp\u003eAnalyzing and Testing Code 143\u003c\/p\u003e \u003cp\u003eInjection Vulnerabilities 144\u003c\/p\u003e \u003cp\u003eSQL Injection Attacks 145\u003c\/p\u003e \u003cp\u003eCode Injection Attacks 148\u003c\/p\u003e \u003cp\u003eCommand Injection Attacks 149\u003c\/p\u003e \u003cp\u003eExploiting Authentication Vulnerabilities 150\u003c\/p\u003e \u003cp\u003ePassword Authentication 150\u003c\/p\u003e \u003cp\u003eSession Attacks 151\u003c\/p\u003e \u003cp\u003eExploiting Authorization Vulnerabilities 154\u003c\/p\u003e \u003cp\u003eInsecure Direct Object References 154\u003c\/p\u003e \u003cp\u003eDirectory Traversal 155\u003c\/p\u003e \u003cp\u003eFile Inclusion 156\u003c\/p\u003e \u003cp\u003ePrivilege Escalation 157\u003c\/p\u003e \u003cp\u003eExploiting Web Application Vulnerabilities 157\u003c\/p\u003e \u003cp\u003eCross-Site Scripting (XSS) 158\u003c\/p\u003e \u003cp\u003eRequest Forgery 160\u003c\/p\u003e \u003cp\u003eApplication Security Controls 161\u003c\/p\u003e \u003cp\u003eInput Validation 162\u003c\/p\u003e \u003cp\u003eWeb Application Firewalls 163\u003c\/p\u003e \u003cp\u003eDatabase Security 163\u003c\/p\u003e \u003cp\u003eCode Security 166\u003c\/p\u003e \u003cp\u003eSecure Coding Practices 168\u003c\/p\u003e \u003cp\u003eSource Code Comments 168\u003c\/p\u003e \u003cp\u003eError Handling 168\u003c\/p\u003e \u003cp\u003eHard-Coded Credentials 170\u003c\/p\u003e \u003cp\u003eMemory Management 170\u003c\/p\u003e \u003cp\u003eRace Conditions 171\u003c\/p\u003e \u003cp\u003eUnprotected APIs 172\u003c\/p\u003e \u003cp\u003eDriver Manipulation 172\u003c\/p\u003e \u003cp\u003eSummary 173\u003c\/p\u003e \u003cp\u003eExam Essentials 173\u003c\/p\u003e \u003cp\u003eReview Questions 175\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 7 Cryptography and the Public Key Infrastructure 179\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eAn Overview of Cryptography 180\u003c\/p\u003e \u003cp\u003eHistorical Cryptography 181\u003c\/p\u003e \u003cp\u003eGoals of Cryptography 186\u003c\/p\u003e \u003cp\u003eConfidentiality 187\u003c\/p\u003e \u003cp\u003eIntegrity 188\u003c\/p\u003e \u003cp\u003eAuthentication 188\u003c\/p\u003e \u003cp\u003eNonrepudiation 189\u003c\/p\u003e \u003cp\u003eCryptographic Concepts 189\u003c\/p\u003e \u003cp\u003eCryptographic Keys 189\u003c\/p\u003e \u003cp\u003eCiphers 190\u003c\/p\u003e \u003cp\u003eModern Cryptography 191\u003c\/p\u003e \u003cp\u003eCryptographic Secrecy 191\u003c\/p\u003e \u003cp\u003eSymmetric Key Algorithms 192\u003c\/p\u003e \u003cp\u003eAsymmetric Key Algorithms 193\u003c\/p\u003e \u003cp\u003eHashing Algorithms 196\u003c\/p\u003e \u003cp\u003eSymmetric Cryptography 197\u003c\/p\u003e \u003cp\u003eData Encryption Standard 197\u003c\/p\u003e \u003cp\u003eTriple DES 199\u003c\/p\u003e \u003cp\u003eAdvanced Encryption Standard 200\u003c\/p\u003e \u003cp\u003eSymmetric Key Management 200\u003c\/p\u003e \u003cp\u003eAsymmetric Cryptography 203\u003c\/p\u003e \u003cp\u003eRSA 203\u003c\/p\u003e \u003cp\u003eElliptic Curve 204\u003c\/p\u003e \u003cp\u003eHash Functions 205\u003c\/p\u003e \u003cp\u003eSHA 206\u003c\/p\u003e \u003cp\u003eMD 5 207\u003c\/p\u003e \u003cp\u003eDigital Signatures 207\u003c\/p\u003e \u003cp\u003eHMAC 208\u003c\/p\u003e \u003cp\u003eDigital Signature Standard 209\u003c\/p\u003e \u003cp\u003ePublic Key Infrastructure 209\u003c\/p\u003e \u003cp\u003eCertificates 209\u003c\/p\u003e \u003cp\u003eCertificate Authorities 211\u003c\/p\u003e \u003cp\u003eCertificate Generation and Destruction 212\u003c\/p\u003e \u003cp\u003eCertificate Formats 215\u003c\/p\u003e \u003cp\u003eAsymmetric Key Management 216\u003c\/p\u003e \u003cp\u003eCryptographic Attacks 217\u003c\/p\u003e \u003cp\u003eEmerging Issues in Cryptography 220\u003c\/p\u003e \u003cp\u003eTor and the Dark Web 220\u003c\/p\u003e \u003cp\u003eBlockchain 220\u003c\/p\u003e \u003cp\u003eLightweight Cryptography 221\u003c\/p\u003e \u003cp\u003eHomomorphic Encryption 221\u003c\/p\u003e \u003cp\u003eQuantum Computing 222\u003c\/p\u003e \u003cp\u003eSummary 222\u003c\/p\u003e \u003cp\u003eExam Essentials 222\u003c\/p\u003e \u003cp\u003eReview Questions 224\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 8 Identity and Access Management 229\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIdentity 230\u003c\/p\u003e \u003cp\u003eAuthentication and Authorization 231\u003c\/p\u003e \u003cp\u003eAuthentication and Authorization Technologies 232\u003c\/p\u003e \u003cp\u003eDirectory Services 236\u003c\/p\u003e \u003cp\u003eAuthentication Methods 237\u003c\/p\u003e \u003cp\u003eMultifactor Authentication 237\u003c\/p\u003e \u003cp\u003eOne-Time Passwords 239\u003c\/p\u003e \u003cp\u003eBiometrics 241\u003c\/p\u003e \u003cp\u003eKnowledge-Based Authentication 243\u003c\/p\u003e \u003cp\u003eManaging Authentication 244\u003c\/p\u003e \u003cp\u003eAccounts 245\u003c\/p\u003e \u003cp\u003eAccount Types 245\u003c\/p\u003e \u003cp\u003eAccount Policies and Controls 245\u003c\/p\u003e \u003cp\u003eAccess Control Schemes 248\u003c\/p\u003e \u003cp\u003eFilesystem Permissions 249\u003c\/p\u003e \u003cp\u003eSummary 251\u003c\/p\u003e \u003cp\u003eExam Essentials 252\u003c\/p\u003e \u003cp\u003eReview Questions 253\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 9 Resilience and Physical Security 257\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eBuilding Cybersecurity Resilience 258\u003c\/p\u003e \u003cp\u003eStorage Resiliency: Backups and Replication 260\u003c\/p\u003e \u003cp\u003eResponse and Recovery Controls 266\u003c\/p\u003e \u003cp\u003ePhysical Security Controls 269\u003c\/p\u003e \u003cp\u003eSite Security 269\u003c\/p\u003e \u003cp\u003eSummary 278\u003c\/p\u003e \u003cp\u003eExam Essentials 279\u003c\/p\u003e \u003cp\u003eReview Questions 281\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 10 Cloud and Virtualization Security 285\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eExploring the Cloud 286\u003c\/p\u003e \u003cp\u003eBenefits of the Cloud 287\u003c\/p\u003e \u003cp\u003eCloud Roles 289\u003c\/p\u003e \u003cp\u003eCloud Service Models 289\u003c\/p\u003e \u003cp\u003eCloud Deployment Models 293\u003c\/p\u003e \u003cp\u003eShared Responsibility Model 295\u003c\/p\u003e \u003cp\u003eCloud Standards and Guidelines 298\u003c\/p\u003e \u003cp\u003eVirtualization 300\u003c\/p\u003e \u003cp\u003eHypervisors 300\u003c\/p\u003e \u003cp\u003eCloud Infrastructure Components 302\u003c\/p\u003e \u003cp\u003eCloud Compute Resources 302\u003c\/p\u003e \u003cp\u003eCloud Storage Resources 304\u003c\/p\u003e \u003cp\u003eCloud Networking 307\u003c\/p\u003e \u003cp\u003eCloud Security Issues 311\u003c\/p\u003e \u003cp\u003eAvailability 311\u003c\/p\u003e \u003cp\u003eData Sovereignty 311\u003c\/p\u003e \u003cp\u003eVirtualization Security 312\u003c\/p\u003e \u003cp\u003eApplication Security 312\u003c\/p\u003e \u003cp\u003eGovernance and Auditing 313\u003c\/p\u003e \u003cp\u003eCloud Security Controls 313\u003c\/p\u003e \u003cp\u003eCloud Access Security Brokers 314\u003c\/p\u003e \u003cp\u003eResource Policies 314\u003c\/p\u003e \u003cp\u003eSecrets Management 316\u003c\/p\u003e \u003cp\u003eSummary 316\u003c\/p\u003e \u003cp\u003eExam Essentials 316\u003c\/p\u003e \u003cp\u003eReview Questions 318\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 11 Endpoint Security 323\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eProtecting Endpoints 324\u003c\/p\u003e \u003cp\u003ePreserving Boot Integrity 325\u003c\/p\u003e \u003cp\u003eEndpoint Security Tools 326\u003c\/p\u003e \u003cp\u003eHardening Endpoints and Systems 332\u003c\/p\u003e \u003cp\u003eService Hardening 333\u003c\/p\u003e \u003cp\u003eOperating System Hardening 335\u003c\/p\u003e \u003cp\u003eHardening the Windows Registry 336\u003c\/p\u003e \u003cp\u003eConfiguration, Standards, and Schemas 336\u003c\/p\u003e \u003cp\u003eDisk Security and Sanitization 338\u003c\/p\u003e \u003cp\u003eFile Manipulation and Other Useful Command-Line Tools 341\u003c\/p\u003e \u003cp\u003eScripting, Secure Transport, and Shells 343\u003c\/p\u003e \u003cp\u003eSecuring Embedded and Specialized Systems 344\u003c\/p\u003e \u003cp\u003eEmbedded Systems 345\u003c\/p\u003e \u003cp\u003eSCADA and ICS 346\u003c\/p\u003e \u003cp\u003eSecuring the Internet of Things 348\u003c\/p\u003e \u003cp\u003eSpecialized Systems 349\u003c\/p\u003e \u003cp\u003eCommunication Considerations 350\u003c\/p\u003e \u003cp\u003eSecurity Constraints of Embedded Systems 351\u003c\/p\u003e \u003cp\u003eSummary 352\u003c\/p\u003e \u003cp\u003eExam Essentials 354\u003c\/p\u003e \u003cp\u003eReview Questions 356\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 12 Network Security 361\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDesigning Secure Networks 363\u003c\/p\u003e \u003cp\u003eNetwork Segmentation 365\u003c\/p\u003e \u003cp\u003eNetwork Access Control 366\u003c\/p\u003e \u003cp\u003ePort Security and Port-Level Protections 367\u003c\/p\u003e \u003cp\u003ePort Spanning\/Port Mirroring 369\u003c\/p\u003e \u003cp\u003eVirtual Private Network 370\u003c\/p\u003e \u003cp\u003eNetwork Appliances and Security Tools 371\u003c\/p\u003e \u003cp\u003eNetwork Security, Services, and Management 377\u003c\/p\u003e \u003cp\u003eDeception and Disruption 382\u003c\/p\u003e \u003cp\u003eSecure Protocols 383\u003c\/p\u003e \u003cp\u003eUsing Secure Protocols 383\u003c\/p\u003e \u003cp\u003eSecure Protocols 384\u003c\/p\u003e \u003cp\u003eAttacking and Assessing Networks 389\u003c\/p\u003e \u003cp\u003eOn-Path Attacks 389\u003c\/p\u003e \u003cp\u003eDomain Name System Attacks 391\u003c\/p\u003e \u003cp\u003eLayer 2 Attacks 393\u003c\/p\u003e \u003cp\u003eDistributed Denial-of-Service Attacks 394\u003c\/p\u003e \u003cp\u003eNetwork Reconnaissance and Discovery Tools and Techniques 398\u003c\/p\u003e \u003cp\u003eSummary 411\u003c\/p\u003e \u003cp\u003eExam Essentials 412\u003c\/p\u003e \u003cp\u003eReview Questions 414\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 13 Wireless and Mobile Security 419\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eBuilding Secure Wireless Networks 420\u003c\/p\u003e \u003cp\u003eConnectivity Methods 421\u003c\/p\u003e \u003cp\u003eWireless Network Models 425\u003c\/p\u003e \u003cp\u003eAttacks Against Wireless Networks 426\u003c\/p\u003e \u003cp\u003eDesigning a Network 430\u003c\/p\u003e \u003cp\u003eController and Access Point Security 432\u003c\/p\u003e \u003cp\u003eWi-Fi Security Standards 433\u003c\/p\u003e \u003cp\u003eWireless Authentication 434\u003c\/p\u003e \u003cp\u003eManaging Secure Mobile Devices 436\u003c\/p\u003e \u003cp\u003eMobile Device Deployment Methods 436\u003c\/p\u003e \u003cp\u003eMobile Device Management 438\u003c\/p\u003e \u003cp\u003eSpecialized Mobile Device Security Tools 442\u003c\/p\u003e \u003cp\u003eSummary 442\u003c\/p\u003e \u003cp\u003eExam Essentials 443\u003c\/p\u003e \u003cp\u003eReview Questions 445\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 14 Incident Response 449\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eIncident Response 450\u003c\/p\u003e \u003cp\u003eThe Incident Response Process 451\u003c\/p\u003e \u003cp\u003eAttack Frameworks and Identifying Attacks 457\u003c\/p\u003e \u003cp\u003eIncident Response Data and Tools 461\u003c\/p\u003e \u003cp\u003eSecurity Information and Event Management Systems 462\u003c\/p\u003e \u003cp\u003eAlerts and Alarms 464\u003c\/p\u003e \u003cp\u003eCorrelation and Analysis 465\u003c\/p\u003e \u003cp\u003eRules 465\u003c\/p\u003e \u003cp\u003eMitigation and Recovery 473\u003c\/p\u003e \u003cp\u003eSummary 477\u003c\/p\u003e \u003cp\u003eExam Essentials 478\u003c\/p\u003e \u003cp\u003eReview Questions 480\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 15 Digital Forensics 485\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDigital Forensic Concepts 486\u003c\/p\u003e \u003cp\u003eLegal Holds and e-Discovery 487\u003c\/p\u003e \u003cp\u003eConducting Digital Forensics 488\u003c\/p\u003e \u003cp\u003eAcquiring Forensic Data 489\u003c\/p\u003e \u003cp\u003eAcquisition Tools 493\u003c\/p\u003e \u003cp\u003eValidating Forensic Data Integrity 496\u003c\/p\u003e \u003cp\u003eData Recovery 499\u003c\/p\u003e \u003cp\u003eForensic Suites and a Forensic Case Example 499\u003c\/p\u003e \u003cp\u003eReporting 504\u003c\/p\u003e \u003cp\u003eDigital Forensics and Intelligence 504\u003c\/p\u003e \u003cp\u003eSummary 505\u003c\/p\u003e \u003cp\u003eExam Essentials 505\u003c\/p\u003e \u003cp\u003eReview Questions 507\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 16 Security Policies, Standards, and Compliance 511\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eUnderstanding Policy Documents 512\u003c\/p\u003e \u003cp\u003ePolicies 512\u003c\/p\u003e \u003cp\u003eStandards 515\u003c\/p\u003e \u003cp\u003eProcedures 517\u003c\/p\u003e \u003cp\u003eGuidelines 518\u003c\/p\u003e \u003cp\u003eExceptions and Compensating Controls 519\u003c\/p\u003e \u003cp\u003ePersonnel Management 520\u003c\/p\u003e \u003cp\u003eLeast Privilege 520\u003c\/p\u003e \u003cp\u003eSeparation of Duties 521\u003c\/p\u003e \u003cp\u003eJob Rotation and Mandatory Vacations 521\u003c\/p\u003e \u003cp\u003eClean Desk Space 522\u003c\/p\u003e \u003cp\u003eOnboarding and Offboarding 522\u003c\/p\u003e \u003cp\u003eNondisclosure Agreements 522\u003c\/p\u003e \u003cp\u003eSocial Media 522\u003c\/p\u003e \u003cp\u003eUser Training 522\u003c\/p\u003e \u003cp\u003eThird-Party Risk Management 523\u003c\/p\u003e \u003cp\u003eWinding Down Vendor Relationships 524\u003c\/p\u003e \u003cp\u003eComplying with Laws and Regulations 524\u003c\/p\u003e \u003cp\u003eAdopting Standard Frameworks 525\u003c\/p\u003e \u003cp\u003eNIST Cybersecurity Framework 525\u003c\/p\u003e \u003cp\u003eNIST Risk Management Framework 528\u003c\/p\u003e \u003cp\u003eISO Standards 529\u003c\/p\u003e \u003cp\u003eBenchmarks and Secure Configuration Guides 531\u003c\/p\u003e \u003cp\u003eSecurity Control Verification and Quality Control 531\u003c\/p\u003e \u003cp\u003eSummary 533\u003c\/p\u003e \u003cp\u003eExam Essentials 534\u003c\/p\u003e \u003cp\u003eReview Questions 535\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 17 Risk Management and Privacy 539\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eAnalyzing Risk 540\u003c\/p\u003e \u003cp\u003eRisk Identification 541\u003c\/p\u003e \u003cp\u003eRisk Calculation 542\u003c\/p\u003e \u003cp\u003eRisk Assessment 543\u003c\/p\u003e \u003cp\u003eManaging Risk 547\u003c\/p\u003e \u003cp\u003eRisk Mitigation 547\u003c\/p\u003e \u003cp\u003eRisk Avoidance 549\u003c\/p\u003e \u003cp\u003eRisk Transference 549\u003c\/p\u003e \u003cp\u003eRisk Acceptance 549\u003c\/p\u003e \u003cp\u003eRisk Analysis 550\u003c\/p\u003e \u003cp\u003eDisaster Recovery Planning 552\u003c\/p\u003e \u003cp\u003eDisaster Types 552\u003c\/p\u003e \u003cp\u003eBusiness Impact Analysis 553\u003c\/p\u003e \u003cp\u003ePrivacy 553\u003c\/p\u003e \u003cp\u003eSensitive Information Inventory 554\u003c\/p\u003e \u003cp\u003eInformation Classification 554\u003c\/p\u003e \u003cp\u003eData Roles and Responsibilities 556\u003c\/p\u003e \u003cp\u003eInformation Lifecycle 557\u003c\/p\u003e \u003cp\u003ePrivacy Enhancing Technologies 557\u003c\/p\u003e \u003cp\u003ePrivacy and Data Breach Notification 558\u003c\/p\u003e \u003cp\u003eSummary 559\u003c\/p\u003e \u003cp\u003eExam Essentials 559\u003c\/p\u003e \u003cp\u003eReview Questions 560\u003c\/p\u003e \u003cp\u003e\u003cb\u003eAppendix Answers to Review Questions 565\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eChapter 1: Today’s Security Professional 566\u003c\/p\u003e \u003cp\u003eChapter 2: Cybersecurity Threat Landscape 567\u003c\/p\u003e \u003cp\u003eChapter 3: Malicious Code 569\u003c\/p\u003e \u003cp\u003eChapter 4: Social Engineering, Physical, and Password Attacks 572\u003c\/p\u003e \u003cp\u003eChapter 5: Security Assessment and Testing 574\u003c\/p\u003e \u003cp\u003eChapter 6: Secure Coding 576\u003c\/p\u003e \u003cp\u003eChapter 7: Cryptography and the Public Key Infrastructure 578\u003c\/p\u003e \u003cp\u003eChapter 8: Identity and Access Management 579\u003c\/p\u003e \u003cp\u003eChapter 9: Resilience and Physical Security 582\u003c\/p\u003e \u003cp\u003eChapter 10: Cloud and Virtualization Security 584\u003c\/p\u003e \u003cp\u003eChapter 11: Endpoint Security 586\u003c\/p\u003e \u003cp\u003eChapter 12: Network Security 589\u003c\/p\u003e \u003cp\u003eChapter 13: Wireless and Mobile Security 591\u003c\/p\u003e \u003cp\u003eChapter 14: Incident Response 594\u003c\/p\u003e \u003cp\u003eChapter 15: Digital Forensics 596\u003c\/p\u003e \u003cp\u003eChapter 16: Security Policies, Standards, and Compliance 598\u003c\/p\u003e \u003cp\u003eChapter 17: Risk Management and Privacy 600\u003c\/p\u003e \u003cp\u003eIndex 603\u003c\/p\u003e","brand":"John Wiley \u0026 Sons Inc","offers":[{"title":"Default Title","offer_id":49407160156503,"sku":"9781119812289","price":90.0,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0817\/1739\/5799\/files\/9781119812289.jpg?v=1730498382","url":"https:\/\/bookcurl.com\/products\/comptia-security-deluxe-study-guide-w-online-lab-exam-sy0601-5e-9781119812289","provider":"Book Curl","version":"1.0","type":"link"}