Comptia Security+ SY0-301 Authorized Exam Cram, Third Edition
Total Page:16
File Type:pdf, Size:1020Kb
ptg999 CompTIA® Security+™ SY0-301 ptg999 Third Edition Diane Barrett, Kalani K. Hausman, and Martin Weiss CompTIA Security+™ SY0-301 Authorized Exam Cram, Third Edition Associate Copyright © 2012 by Pearson Education, Inc. Publisher All rights reserved. No part of this book shall be reproduced, stored in a David Dusthimer retrieval system, or transmitted by any means, electronic, mechanical, pho- Acquisitions tocopying, recording, or otherwise, without written permission from the pub- Editor lisher. No patent liability is assumed with respect to the use of the informa- tion contained herein. Although every precaution has been taken in the Betsy Brown preparation of this book, the publisher and author assume no responsibility Development for errors or omissions. Nor is any liability assumed for damages resulting Editor from the use of the information contained herein. Andrew Cupp ISBN-13: 978-0-7897-4829-4 ISBN-10: 0-7897-4829-0 Managing Editor Library of Congress Cataloging-in-Publication data is on file. Sandra Schroeder Project Editor Printed in the United States of America Mandie Frank First Printing: December 2011 Copy Editor 14 13 12 11 4 3 2 1 Charlotte Kughen, Trademarks The Wordsmithery All terms mentioned in this book that are known to be trademarks or service LLC marks have been appropriately capitalized. Que Publishing All terms men- tioned in this book that are known to be trademarks or service marks have Indexer been appropriately capitalized. Pearson IT Certification cannot attest to the Tim Wright accuracy of this information. Use of a term in this book should not be regarded as affecting the validity of any trademark or service mark. Proofreader Megan Wade Warning and Disclaimer Every effort has been made to make this book as complete and as accurate Technical Editor as possible, but no warranty or fitness is implied. The information provided is Chris Crayton on an “as is” basis. The author and the publisher shall have neither liability nor responsibility to any person or entity with respect to any loss or dam- Publishing ages arising from the information contained in this book or from the use of Coordinator ptg999 the CD or programs accompanying it. Vanessa Evans Bulk Sales Multimedia Pearson IT Certification offers excellent discounts on this book when ordered Developer in quantity for bulk purchases or special sales. For more –information, please Tim Warner contact U.S. Corporate and Government Sales Book Designer 1-800-382-3419 Gary Adair [email protected] Composition For sales outside of the U.S., please contact TnT Design, Inc. International Sales [email protected] Contents at a Glance Introduction xix Part I: Network Security CHAPTER 1 Network Design 1 CHAPTER 2 Network Implementation 41 Part II: Compliance and Operational Security CHAPTER 3 Risk Management 69 CHAPTER 4 Response and Recovery 103 Part III: Threats and Vulnerabilities CHAPTER 5 Attacks 143 CHAPTER 6 Deterrents 183 Part IV: Application, Data, and Host Security ptg999 CHAPTER 7 Application Security 213 CHAPTER 8 Host Security 231 CHAPTER 9 Data Security 255 Part V: Access Control and Identity Management CHAPTER 10 Authentication and Authorization 277 CHAPTER 11 Access Control and Account Management 295 Part VI: Cryptography CHAPTER 12 Cryptography Tools and Techniques 313 CHAPTER 13 Public Key Infrastructure 339 Part VII: Practice Exams and Answers Practice Exam 1 359 Answers to Practice Exam 1 379 Practice Exam 2 405 Answers to Practice Exam 2 425 Glossary 451 Index 473 Table of Contents Introduction . xix Part I: Network Security CHAPTER 1: Network Design . 1 Explain the Security Function and Purpose of Network Devices and Te c h n o l o g i e s . 2 Firewalls . 3 Routers . 4 Switches. 5 Load Balancers . 5 Proxies . 6 Web Security Gateways . 7 VPN Concentrators . 7 NIDS and NIPS (Behavior Based, Signature Based, ptg999 Anomaly Based, Heuristic). 8 Protocol Analyzers . 10 Sniffers . 10 Spam Filter, All-in-one Security Appliances . 11 Web Application Firewall versus Network Firewall . 11 URL Filtering, Content Inspection, Malware Inspection . 13 Apply and Implement Secure Network Administration Principles . 16 Rule-based Management . 17 Firewall Rules . 17 VLAN Management . 18 Secure Router Configuration . 19 Access Control Lists . 20 Port Security . 20 802.1X . 20 Flood Guards . 21 Loop Protection. 21 Implicit Deny . 22 Prevent Network Bridging by Network Separation . 22 Log Analysis . 23 Distinguish and Differentiate Network Design Elements and Compounds. 25 DMZ. 26 Intranet . 27 Extranet . 27 Subnetting . 28 VLAN . 30 NAT . 31 Remote Access. 32 Te l e p h o n y . 32 NAC . 34 Virtualization . 35 Cloud Computing . 36 CHAPTER 2: Network Implementation . 41 Implement and Use Common Protocols . 42 Internet Protocol Security . 43 SNMP . 45 Secure Shell Connections. 46 Domain Name Service . 47 Transport Layer Security . 48 ptg999 Secure Sockets Layer . 48 TCP/IP . 49 FTPS. 50 Hypertext Transport Protocol over Secure Sockets Layer . 50 Secure FTP . 51 Secure Copy Protocol . 51 Internet Control Message Protocol . 52 IPv4 versus IPv6 . 53 Identify Commonly Used Default Network Ports . 56 Implement Wireless Networks in a Secure Manner. 60 Wi-Fi Protected Access (WPA) . 61 WPA2 . 61 Wired Equivalent Privacy . 61 Extensible Authentication Protocol . 62 Protected EAP. 63 LEAP . 64 Media Access Control Filter . 64 Service Set Identifier Broadcast. 64 Temporal Key Integrity Protocol . 65 CCMP. 65 Antenna Placement. 66 Power Level Controls . 67 vi CompTIA Security+ SY0-301 Authorized Exam Cram, Third Edition Part II: Compliance and Operational Security CHAPTER 3: Risk Management. 69 Exemplify the Concepts of Confidentiality, Integrity, and Availability . 70 Confidentiality. 70 Integrity . 71 Availability . 71 Explain Risk-Related Concepts . 73 Risk Responses . 73 Ty p e s o f C o n t r o l s . 74 Identifying Vulnerabilities . 75 Identifying Risk . 76 Measuring Risk . 76 Qualitative versus Quantitative Measures . 80 Risk Reduction Policies . 81 Carry Out Appropriate Risk-Mitigation Strategies . 90 Change Management . 91 Incident Management . 91 ptg999 Regular Audits. ..