The official comptia cysa self-paced study guide (exam cs0-002)What you'll learn Take and pass the CompTIA CySA (CS0-001 or CS0-002) certification examUnderstand threat and vulnerability management conceptsUnderstand how to conduct a cyber incident responseUnderstand how to setup a strong security architecture for your networksKnow what different types of cybersecurity tools are on the marketand which to use in different scenarios Requirements Basic understanding of network and network securityUnderstand the concepts covered by the Network and Security examsThis course aligns directly to the CompTIA CySA CS0-002 Certification Study Guide Description ** Taught by a Best Selling IT Certification Instructor ** This courseprovides everything you need in order to study for the CompTIA Cybersecurity Analyst (CySA ) (CS0-002) exam, including a downloadable Study Guide (PDF), quizzes to check your knowledge as you progress through the videos, and a full-length practice exam to test your knowledge before test day! Taught by an expert in information technologyand cybersecurity with over 20 years of experience, this course is a fun way to learn what you need to know to pass the CompTIA Cybersecurity Analyst (CySA ) (CS0-002) exam or to better prepare yourself to serve on your organization's cyber defense team.The CompTIA CySA (Cybersecurity Analyst ) (CS0-002) certification is a vendorneutral certification that validates your knowledge and ability to conduct intermediate-level cybersecurity skills. This certification fills the gap between the entry-level CompTIA Security exam (for those with about 1 year in the field) and the advanced-level CompTIA Advanced Security Practitioner (for those with at least 5 years in the field). Taught by an expert in information technology and cybersecurity with over 20 years of experience, this course is a fun way to learn what you need to know to pass the CompTIA Cybersecurity Analyst (CySA+) (CS0-002) exam or to better prepare yourself to serve on your organization's cyber defense team. The CompTIA CySA+ (Cybersecurity Analyst+) (CS0-002) certification is a vendor-neutral certification that validates your knowledge and ability to conduct intermediate-level cybersecurity skills. This certification fills the gap between the entry-level CompTIA Security+ exam (for those with about 1 year in the field) and the advanced-level CompTIA Advanced Security Practitioner (for those with at least 5 years in the field). The CompTIA CySA+ exam is focused on the technical, hands-on details of the cybersecurity field, including not only cyber threats, secure network architecture, and risk management, but also the ability to perform log analysis, configuration assessments, and more. This CySA+ (CS0-002) course is designed for IT Security analysts, vulnerability analysts, threat intelligence analysts, or anyone who is trying to get a better understanding of the concepts involved in conducting cybersecurity analysis, to include threat management, vulnerability management, cyber incident response, security architecture, and the toolsets associated with these cybersecurity efforts. To help you practice for the CompTIA CySA+ (CS0-002) exam, this course even comes with a realistic practice exam containing 90 multiple-choice questions spread across the five domains tested by the CompTIA CySA+ (CS0-002) certification exam! This course will provide you with full coverage of the five domains of the CySA+ (CS0-002) exam: Threat and Vulnerability Management (22%) Software and Systems Security (18%) Security Operations and Monitoring (25%) Incident Response (25%) Compliance and Assessment (13%) Who this course is for: Students preparing for the CompTIA CySA+ (CS0-001 or CS0-002) Certification Exam Threat analysts Vulnerability analysts Risk management professionals Entry-level incident response professionals About the Authors Mike Chapple, Ph.D., CSA , is author of the best-selling CISSP (ISC)2 Certified Information Systems Security Professional Official Study Guide (Sybex, 2015) and the CISSP (ISC)2 Official Practice Tests (Sybex 2016). He is an information security professional with two decades of experience in higher education, the privatesector, and government. Mike currently serves as senior director for IT Service Delivery at the University of Notre Dame. In this role, he oversees the information security, data governance, IT architecture, project management, strategic planning, and product management functions for Notre Dame. Mike also serves as Associate Teaching Professor inthe university’s IT, Analytics, and Operations department, where he teaches undergraduate and graduate courses on cybersecurity, data management, and business analytics. Before returning to Notre Dame, Mike served as executive vice president and chief information officer of the Brand Institute, a Miami-based marketing consultancy. Mike alsospent four years in the information security research group at the National Security Agency and served as an active duty intelligence officer in the U.S. Air Force. Mike is technical editor for Information Security Magazine and has written more than 25 books. He earned both his B.S. and Ph.D. degrees from Notre Dame in computer science andengineering. Mike also holds an M.S. in computer science from the University of Idaho and an MBA from Auburn University. Mike holds the Cybersecurity Analyst (CSA ), Security , and Certified Information Systems Security Professional (CISSP) certifications. David Seidl is the senior director for Campus Technology Services at the University ofNotre Dame. As the senior director for CTS, David is responsible for central platform and operating system support, database administration and services, identity and access management, application services, email and digital signage, and document management. During his over 20 years in information technology, he has served in a variety ofleadership, technical, and information security roles, including leading Notre Dame’s information security team as Notre Dame’s director of information security. He currently teaches a popular course on networking and security for Notre Dame’s Mendoza College of Business and has written books on security certification and cyberwarfare, includingco-authoring CISSP (ISC)2 Official Practice Tests (Sybex 2016). David holds a bachelor’s degree in communication technology and a master’s degree in information security from Eastern Michigan University, as well as CISSP, GPEN, and GCIH certifications. CONTENTS Acknowledgments About the Authors Introduction What Does This Book Cover?Objectives Map for CompTIA Cybersecurity Analyst (CSA ) Exam CS0-001 Objectives Map Assessment Test Answer to the Assessment Test Chapter 1 Defending Against Cybersecurity Threats Cybersecurity Objectives Evaluating Security Risks Building a Secure Network Secure Endpoint Management Penetration Testing Reverse EngineeringSummary Exam Essentials Lab Exercises Review Questions Chapter 2 Reconnaissance and Intelligence Gathering Footprinting Passive Footprinting Gathering Organizational Intelligence Detecting, Preventing, and Responding to Reconnaissance Summary Exam Essentials Lab Exercises Review Questions Chapter 3 Designing a VulnerabilityManagement Program Identifying Vulnerability Management Requirements Configuring and Executing Vulnerability Scans Developing a Remediation Workflow Overcoming Barriers to Vulnerability Scanning Summary Exam Essentials Lab Exercises Review Questions Chapter 4 Analyzing Vulnerability Scans Reviewing and Interpreting Scan ReportsValidating Scan Results Common Vulnerabilities Summary Exam Essentials Lab Exercises Review Questions Chapter 5 Building an Incident Response Program Security Incidents Phases of Incident Response Building the Foundation for Incident Response Creating an Incident Response Team Coordination and Information Sharing Classifying IncidentsSummary Exam Essentials Lab Exercises Review Questions Chapter 6 Analyzing Symptoms for Incident Response Analyzing Network Events Handling Network Probes and Attacks Investigating Host Issues Investigating Service and Application Issues Summary Exam Essentials Lab Exercises Review Questions Chapter 7 Performing Forensic AnalysisBuilding a Forensics Capability Understanding Forensic Software Conducting a Forensic Investigation Forensic Investigation: An Example Summary Exam Essentials Lab Exercises Review Questions Chapter 8 Recovery and Post-Incident Response Containing the Damage Incident Eradication and Recovery Wrapping Up the Response Summary ExamEssentials Lab Exercises Review Questions Chapter 9 Policy and Compliance Understanding Policy Documents Complying with Laws and Regulations Adopting a Standard Framework Implementing Policy-Based Controls Security Control Verification and Quality Control Summary Exam Essentials Lab Exercises Review Questions Chapter 10 Defensein-Depth Security Architectures Understanding Defense in Depth Implementing Defense in Depth Analyzing Security Architecture Summary Exam Essentials Lab Exercises Review Questions Chapter 11 Identity and Access Management Security Understanding Identity Threats to Identity and Access Identity as a Security Layer UnderstandingFederated Identity and Single Sign-On Review Questions Chapter 12 Software Development Security Understanding the Software Development Life Cycle Designing and Coding for Security Software Security Testing Summary Exam Essentials Lab Exercises Review Questions Chapter 13 Cybersecurity Toolkit Host Security Tools Monitoring andAnalysis Tools Scanning and Testing Tools Network Security Tools Web Application Security Tools Forensics Tools Summary Appendix A Answers to the Review Questions Chapter 1: Defending Against Cybersecurity Threats Chapter 2: Reconnaissance and Intelligence Gathering Chapter 3: Designing a Vulnerability Management Program Chapter 4:Analyzing Vulnerability Scans Chapter 5: Building an Incident Response Program Chapter 6: Analyzing Symptoms for Incident Response Chapter 7: Performing Forensic Analysis Chapter 8: Recovery and Post-Incident Response Chapter 9: Policy and Compliance Chapter 10: Defense-in-Depth Security Architectures Chapter 11: Identity and AccessManagement Security Chapter 12: Software Development Security Appendix B Answers to the Lab Exercises Chapter 1: Defending Against Cybersecurity Threats Chapter 2: Reconnaissance and Intelligence Gathering Chapter 4: Analyzing Vulnerability Scans Chapter 5: Building an Incident Response Program Chapter 6: Analyzing Symptoms forIncident Response Chapter 7: Performing Forensic Analysis Chapter 8: Recovery and Post-Incident Response Chapter 9: Policy and Compliance Chapter 10: Defense-in-Depth Security Architectures Chapter 11: Identity and Access Management Security Chapter 12: Software Development Security Index Advert EULA List of Illustrations Chapter 1Figure 1.1 The three key objectives of cybersecurity programs are confidentiality, integrity, and availability. Figure 13.24 Configuring a web proxy Figure 13.25 public anonymizing proxy Figure 13.26 ModSecurity firewall log entry Figure 13.27 Zed Attack Proxy (ZAP)Figure 13.28 Burp Proxy Figure 13.29 shasum Figure 13.30 FTK email viewer Introduction CompTIA Cybersecurity Analyst (CSA ) Study Guide provides accessible explanations and real-world knowledge about the exam objectives that make up the Cybersecurity Analyst certification. This book will help you to assess your knowledge before takingthe exam, as well as provide a stepping-stone to further learning in areas where you may want to expand your skillset or expertise. Before you tackle the CSA , you should already be a security practitioner. CompTIA suggests that test takers have between 3 and 4 years of existing handson information security experience. You should also be familiarwith at least some of the tools and techniques described in this book. You don’t need to know every tool, but understanding how to approach a new scenario, tool, or technology that you may not know using existing experience is critical to passing the CSA exam. For up-to-the-minute updates covering additions or modifications to the CompTIAcertification exams, as well as additional study tools, videos, practice questions, and bonus material, be sure to visit the Sybex website and forum at CompTIA CompTIA is a nonprofit trade organization that offers certification in a variety of IT areas, ranging from the skills that a PC support technical needs, which are covered in theA exam, to advanced certifications like the CompTIA Advanced Security Practitioner, or CASP certification. CompTIA divides its exams into four different categories based on the skill level required for the exam and what topics it covers, as shown in the following table: Foundational Professional IT Fundamentals A Specialty Mastery CDIA CASPCloud with Virtualization CTT CSA Cloud Essentials Linux Healthcare IT Tech Mobility Network Security Project Server CompTIA recommends that practitioners follow a cybersecurity career path as shown here: As you can see, despite the A , Network , and Security falling into the Professional certification category, theCybersecurity Analyst exam is a more advanced exam, intended for professionals with hands-on experience and who possess the knowledge covered by the prior exams. CompTIA certifications are ISO and ANSI accredited, and they are used throughout multiple industries as a measure of technical skill and knowledge. In throughout multipleindustries as a measure of technical skill and knowledge. In addition, CompTIA certifications, including the Security and the CASP, have been approved by the U.S. government as Information Assuance baseline certifications and are included in the State Department’s Skills Incentive Program. The Cybersecurity Analyst Exam The CybersecurityAnalyst exam, which CompTIA refers to as the CSA , is designed to be a vendor-neutral certification for cybersecurity, threat, and vulnerability analysts. The CSA certification is designed for security analysts and engineers as well as Security Operations Center (SOC) staff, vulnerability analysts, and threat intelligence analysts. It focuses onsecurity analytics and practical use of security tools in real-world scenarios. It covers four major domains: Threat Management, Vulnerability Management, Cyber Incident Response, and Security Architecture and Tool Sets. These four areas include a range of topics, from reconnaissance to incident response and forensics, while focusing heavily onscenario-based learning. The CSA exam fits between the entry-level Security exam and the CompTIA Advanced Security Practitioner (CASP) certification, providing a mid-career certification for those who are seeking the next step in their certification and career path. The CSA exam is conducted in a format that CompTIA calls “performancebasedassessment.” This means that the exam uses hands-on simulations using actual security tools and scenarios to perform tasks that match those found in the daily work of a security practitioner. Exam questions may include multiple types of questions such as multiple-choice, fill-in-the-blank, multiple-response, dragand-drop, and image-based problems.CompTIA recommends that test takers have 3–4 years of information security– related experience before taking this exam. The exam costs 320 in the United States, with roughly equivalent prices in other locations around the globe. More details about the CSA exam and how to take it can be found at . Study and Exam Preparation Tips A testpreparation book like this cannot teach you every possible security software package, scenario, or specific technology that may appear on the exam. Instead, you should focus on whether you are familiar with the type or category Instead, you should focus on whether you are familiar with the type or category of technology, tool, process, or scenario asyou read the book. If you identify a gap, you may want to find additional tools to help you learn more about those topics. CompTIA recommends the use of NetWars-style simulations, penetration testing and defensive cybersecurity simulations, and incident response training to prepare for the CSA . Additional resources for hands-on exercises includethe following:

