COMPTIA® Cybersecurity Analyst (CYSA+)
The course introduces tools and tactics to manage cybersecurity risks, identify various types of common threats, evaluate the organization’s security, collect and analyze cybersecurity intelligence, and handle incidents as they occur.
Target audience:
- IT Security Analyst
- Security Operations Center (SOC) Analyst
- Vulnerability Analyst
- Cybersecurity Specialist
- Threat Intelligence Analyst
- Security Engineer
Prerequisites
CompTIA recommends CySA+ certification candidates to have the following requirements prior to attending the CySA+ course:
- 3-4 years of hands-on information security or related experience
- Network+, Security+ or equivalent knowledge
Course outline:
- Threat Management 1:
- Cybersecurity analysts
- Reconnaissance techniques
- Threat Management 2:
- Security appliances
- Logging and analysis
- Vulnerability Management:
- Managing vulnerabilities
- Remediating vulnerabilities
- Secure software development
- Cyber Incident Response:
- Incident response
- Forensics tools
- Incident analysis and recovery
- Security Architecture:
- Secure network design
- Managing identities and access
- Security frameworks and policies
At course completion participants will able to:
- Apply environmental reconnaissance techniques using appropriate tools and processes.
- Analyze the results of a network reconnaissance.
- Given a network-based threat, implement or recommend the appropriate response and countermeasure.
- Explain the purpose of practices used to secure a corporate environment.
- Implement an information security vulnerability management process.
- Analyze the output resulting from a vulnerability scan.
- Compare and contrast common vulnerabilities found in the various targets within an organization.
- Distinguish threat data or behavior to determine the impact of an incident.
- Prepare a toolkit and use appropriate forensics tools during an investigation.
- Explain the importance of communication during the incident response process.
- Analyze common symptoms to select the best course of action to support incident response.
- Summarize the incident recovery and post-incident response process.
- Explain the relationship between frameworks, common policies, controls, and procedures.
- Use data to recommend remediation of security issues related to identity and access management.
- Review security architecture and make recommendations to implement compensating controls.
- Use application security best practices while participating in the Software Development Life Cycle (SDLC).
- Compare and contrast the general purpose and reasons for using various cybersecurity tools and technologies.
The student kit includes a comprehensive workbook and other necessary materials for this class.
Certification exam.
Course helps to prepare for CompTIA exam CompTIA CySA+ (Exam Code CS0-003)
Trainer:
Kirils Solovjovs
Head of security company “Possible Security”, IT policy activist, vulnerability finder and the most visible “good hacker” in Latvia. Kirill specializes in network flow analysis and reverse engineering, as well as social engineering. Experienced in investigating security incidents. Kirill has obtained three higher educations with distinction, incl. Master’s degree in computer science at the University of Latvia, specializing in computer networks specialist and project manager. His professional experience is complemented by an internship at the NATO Cyber Defense Center of Excellence, developing the Crossed Swords red team exercise.
Koolitusfirma tutvustus
BCS Koolitus on Eesti juhtiv IKT valdkonna koolitus-, projektijuhtimis- ja konsultatsiooniettevõte. Loen koolitusfirma kohta veel...