Security+ Syllabus
Security+ Syllabus
CHEAT SHEET
Follow policy & procedures
Life first
Loss of life
Disgruntled employee
Resource = has IP Address
Hashing is not reversible, Encryption is reversible
How are password stores in system? Hash
8 bits = 1 byte = 1 octet
Hash = Integrity
HMAC = Auth + I (Non-R) - FAST (Both need password)
DIG SIG = Auth + I - SLOW (Don't need password)
What is the only cipher that is deemed unbreakable? OTP (One-time pad)
What does BitLocker use for encryption? Requires a TPM (Trusted Platform Module)
Is TPM better than HSM? HSM (Hardware Security Module) you can take with you and TPM is on your m
What does TPM hold? Storage Root Key
There is a signature in your certificate.
What does PKI gives you? Confidentiality, Integrity, Authentication
What does SSH give you? Confidentiality, Integrity, Authentication
What does HTTPS give you? Confidentiality, Integrity, Authentication
What is a wildcard certificate? *.
What is the last step in the process?
Lesson Learned, Documentation, Follow ups
What is a SOC Report?
Who needs them?
Most detailed, least detailed, public report?
SE = Social Engineering
How to stop all attacks? Input validation (Character sanitization)
EAP is an authentication framework
Vulnerability = Exploit
Threats = Human Commucation
Exception - Temporary deviation
Exemption - Permanent deviation
Saying ...
Following policy & procedures
Firewalls have rules, routers have ACL's
ACL = Access Control List. Administrator config file
Flaring = Blinding a camera with a laser
Pop Quiz
BBQ sauce product recipe - Trade secret
Your name and address - PII
Company logo - TM
Binary data with health records - PHI
Radius
certs
AAA
Diameter
European improvement of Radius
FRR
FAR
CER
SYMMETRIC
Static key, same
Super fast
Key = password
Problem: Key Distribution
Confid
Private key only
32braids
2DES
2FISH
blowfish
RC4
IDEA
AES, Rijndael, block 128, Ket 128/192/256
DES
Serpent
IV (initialization Vector)
FIREWALL
Filter > decisions > rules
WAF (input validaton)
Stateless packet inspection - current
Stateful packet inspection - previous and current
Application Proxy - Best firewall
ASYMMETRIC
Public key (public/private)
Very slow
Solves sym key exchange problem
Problem: MITM
Deer
Diffie Hellman
El-Gamal
ECC - smart cards, low overhead
RSA - 2 large prime numbers
IV (initialization Vector)
Security Controls
Technical
Administrative (mgmt)
Operational
Categories:
Detective: lights,
Preventive: Firewall, door access control
Corrective: Backups, redundant servers, Crossing training, patching
Deterrent: Clean desk policy, guards, warning signs
Compensating: Fire extinguishers
Directive: policy
Key Exchange
DEERIODE
Diffie Hellman
El-Gamal
ECC - smarrt cards, low overhead
RSA - 2 prime numbers
IKE = IP sec
OOB
DHE
ECDHE
Salt
PII
PCI-DSS = Credit card
PHI = Personal Health
HIPAA = US Medical
GLBA = Financial
GDPR = Strict of all, EU
PIPEDA - Canadian
Hash
Integrity
Detects changes
Passwords = hash
Rainbow Tables = Precomputed table for hashing
Collision
Mr Sh or shrm
MD5
Ripemd
Havel
SHA-0
SHA-1
SHA-2
SHA-3
IDS
WIPS
NIDS
HIDS
PKI
Manages public key & certificates
CA = Certificate Authority - root. CA = a trusted third party
RA = Registration Authority
RA = Recovery Agent
Key Escrow = back door = the password to everything
What is the world standard? x.509v3
CRL = Certification Revocation List
OCSP = Online Certificate Status Protocol
Whos sig is in your cert? CA or the creator (ie. Go Daddy, Verisign..)
sig = encrypted hash
sig = nonrepudiation = Authentication + integrity
Non-repudiation = cant deny.
PROTOTCOL/SERVICE
See page 5-45, 310
Study tonight
FTP
Radius
DNS
HTTP
HTTPS
SMB
LDAP
RDP
SSH
SFTP
SCP
DHCP
TFTP
FTPS
Telnet
IKE (Key exch IP sec)
IP sec in ESP (Encapsulated Security Payload)
IP sec in AH
IMAP
POP
POP3
SMTP
Microsoft SQL Server
NetBIOS
Syslog
SNMP
NTP
LDAPS
LEGAL/CONTRACTS
Due care = careful
Due diligence + demonstrate doing due care
PORT#
21/20
1812
TCP & UDP/53
80
443
135,139,445
389
3389
22
22
22
UDP/67 & UDP/68
UPD/69
TCP/990
23
UPD/500
50
51
993
110
995
25
1433/1434
137/138
514
161/162(trap)
123
636
UDP
UDP
(139 UDP)
UDP
UDP
UDP
UDP
UDP
(v1/v2 UDP)
IEEE 802 7 layer OSI
CONT.
Solution
Encrypt
Hashing, digital signature
Redundant, resiliant, patching
FORENSICS
Stego = Hiding a message in a picture
Chain of custody
OOV - Order of Volitility
Evidence use write blocker
ACCESS CONTROL
RISK MITIGATION/RESPONSE
- maatd
make An Assessed Timely Decision
Mitigate
accept
avoid
Transfer - Insurance
Deterr
RISK/BC/DR VULN TEST PEN TEST
BIA Safe NOT SAFE
AV Full access = root no access
EF Internal External
ALE = SLE * ARO (SLEARO) Due care Due Diligence (Audit)
SLE = AV * EF (SLEAVE +F)
Qual = L/M/H or simple scale 1-10
Quant = 4.2 mil
DR TESTING
tabletop
failover
simul
parallel
ALTERNATE SITES
Hot site - most expensive
Warm site
Cold site
Type 1 = 12-31-2023
Type 2 = 1-1 to 12-31-24
WEB SERVER ATTACKS COMMANDS
XSS (CSS) - Cookie stealing HO 2! Put them here
XSRF - Advanced Cookie stealing
XSRF - Advanced Cookie stealing (XS > RF) ../
Buffer Overflowing = Giving too much memory netstat
SQL-Injection (1=1) ping
traceroute
STOP? Input validation
V2 = WPA
TKIP
PSK or ENT
V3 = WPA/2
AES-CCMP
PSK or ENT
V4 = WPA/3
CLOUD TYPES Infrastructure
Private P282
Public
Community
Hybrid
IPV4 IPV6
8-bits=octet = BYTE 128 bits
32 bits
Unicast Unicast
Multicast Multicast
Broadcast Anycast
SEC = OFF SEC = ON
IP sec IP sec
Backup Types
Imaging
Snapshot
Full - Slowest to backup, fastest to restore
Incremental - Fastest to back up, slowesy to restore
Differential
Full
C/D
Increm
Deployment Models
BYOD = Bring your own device
CYOD = Choose your own device
COPE = Corporate Owned, Personally Enabled
VDI = Virtual Desktop Infrastructure
FRAUD REDUCTION Capability Maturity Model
Least priv Initial
Job Rotation managed
separation of duties Defined
Mandatory Vacations Quantitatively managed
Optimized
BIO
Type 1 = FRR - False Rejection Rate
Type 2 = FAR - Far Acceptance Rate
CER - Cross Error Rate
ATTACK FRAMEWORK SSO Outside SSO INTRANET
Kill Chain SAML Kerberos
RWDEICA Oauth
WEBSITE SNMP
cve.MITRE.org remote management
nvd Trap is a predefined threshold
Community string = Password
owasp.org V1, V2 broken
SOO INTERNET
SAML
Authen and Author
Oauth
Authorization