Posts

Regulations and Standards

  Regulations and Standards to know for the exam      NIST RMF: Supply chain risks ISO 27001: Organization meets the security standards ISO 27002: Classifies security controls ISO 27017 & 27018: Cloud security ISO 27701: Personal data & privacy ISO 31000 / 31K: Risk assessments GDPR: European Union / International Standards ·          Data owners, data controllers, data processors, & data protection officer ·          Data owner: responsible for determining how the data may be used ·          Data controller: responsible for the protection of privacy & website user rights ·          Data Protection Officer: Independent advocate for care & use of customer information, & responsible for ensuring the organization is complying with relevant laws PCI DSS: ·      ...

2-Step verification

 2-Step Verification or Out-of-Band This process is completed by generating a software token on a server and sending it to a user. The token can be sent via: SMS (Short Message Service):  The code is sent to a registered phone number Email: The code is emailed to a registered email account Push Notification: The code is sent to an authenticator app on a smartphone or PC. This is seamless. The user does not have to enter the code; just tap the notification.  Phone call: The code is sent as an automated phone call (voice) to a registered phone number

PROTOCOL / PACKET ANALYZERS

 WIRESHARK / TCPDUMP Wireshark is a free download in GUI format. The sniffer winpcap captures the traffic, and Wireshark analyzes it.  With Wireshark, you can capture specific protocols or IP addresses. It also offers many different options for viewing protocols, flags, and the direction of the data stream.  With Linux, you can use a command-line protocol analyzer, tcpdump . If the capture is saved as a .pcap file, it can be imported into Wireshark, making it easier to read.  Specific ports can be port mirrored to capture that traffic. The NIC (Network Interface card) must have promiscuous mode enabled. On a Linux system, this can be enabled with the following command: "ifconfig eth0 promisc".

International Organization for Standardization (ISO) 27001/27002/27701/31000

ISO 27001/27002/27017/27701/31000 27001 - Provides requirements for an information security system. This lets other organizations know that your company meets security standards. 27002 - Classifies security controls 27017 - Guidelines for information security controls for cloud services 27701 - Focuses on personal data and privacy 31000 - Standards related to risk management, also referred to as ISO 31K

PCI DSS (Payment Card Industry Data Security Standard)

 Requirements for PCI DSS compliance 1. Install and maintain a firewall configuration to protect cardholder data 2. Do not use vendor-supplied defaults for system passwords and other security parameters 3. Protect stored cardholder data 4. Encrypt transmission of cardholder data across open, public networks 5. Use and regularly update anti-virus software or programs 6. Develop and maintain secure systems and applications 7. Restrict access to cardholder data by business need-to-know 8. Assign a unique ID to each person with computer access 9. Restrict physical access to cardholder data 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes 12. Maintain a policy that addresses information security for employees and contractors

GDPR ( General Data Protextion Regulation)

 GDPR - Things to know for the exam The General Data Protection Regulation regulates the protection of personal data for residents of the European Union. The GDPR outlines the roles and responsibilities of data controllers and data processors. The data controller is responsible for protecting privacy & website user rights. The data protection officer (DPO) can advocate for the care and use of customer information. A data protection officer ensures the organization complies with all relevant laws. The data controller (sometimes called the data owner) is responsible for the data's use. A data processor uses and manipulates the data on behalf of the data controller.

Password Policy

PASSWORD POLICY The recommended minimum password length is 14 characters. With the advancement of CPU processing power and RAM, 8-character passwords are no longer recommended.  Avoid using words found in the dictionary or part of the username to make a password strong. Use at least 3 of the following four: Uppercase letters (26 A through Z) Lowercase letters (26 a through z) Numbers (10 numbers 0-9) Special characters (32 characters, like !, @, #, %, &, and *) An 8-character password with only lowercase letters is calculated as 26^8, or  208827064576  (208 billion) possibilities. Making the password 10 lowercase letters changes it to 141 trillion possibilities.  With a desktop computer and a high-end graphics card, password-cracking tools are capable of testing 20 billion passwords per second. An attacker could break the 10-character password in two hours. The combination possibilities of utilizing all four character types will equal 94 characte...

Passwordless Authentication: The Future of Secure and Seamless Logins

  Passwordless Authentication Passwordless authentication replaces traditional passwords with alternative methods for verifying a user's identity, offering enhanced security and a more user-friendly experience. Instead of relying on something the user knows (a password), it utilizes factors like biometrics, possession of a device, or unique digital keys. This approach minimizes the risk of password-related vulnerabilities, such as phishing and theft, while also simplifying the login process.   How Passwordless Authentication Works: Passwordless authentication leverages different methods to verify a user's identity without relying on passwords. Here's a breakdown of common approaches: 1. Biometrics: This method uses unique biological traits like fingerprints, facial recognition, or iris scans to verify identity. Users unlock their devices or access applications by simply scanning their fingerprint or using facial recognition, eliminating the need for passwords. Examples incl...

CompTIA A+ Questions

 Here are CompTIA A+ Questions, more to be added daily Loading…

IPv4 Subnetting Videos

Image
 Video 1.  Intro to IPv4 Subnetting Video 2.   Converting Dotted Decimal to Binary Video 3. Subnetting Rules Video 4. Basic Subnetting Part 1 Video 5. Basic Subnetting Part 2.

Blue, Red, White, Purple & Yellow Teams explained

  Organization Security Exercise Types In the context of cybersecurity, red, blue, white, purple, and yellow teams represent different roles focused on enhancing security. Red teams simulate attacks, blue teams defend against them, and purple teams bridge the gap between the two. Yellow teams focus on building secure systems, while white teams oversee the process and ensure compliance.  Here's a more detailed breakdown: Red Team:  This team acts as the "attacker," simulating real-world cyberattacks to identify vulnerabilities and weaknesses in an organization's systems and defenses. They use techniques like penetration testing and social engineering to assess the effectiveness of security measures.  Blue Team:  This team focuses on defense, protecting the organization's systems and networks from cyberattacks. Their responsibilities include implementing security measures, monitoring for threats, and responding to security incidents.  Purple Team:  This ...

DNS Record Types to know for the exam

 DNS RECORD TYPES Make sure you know the following DNA record types for this exam and how they are used: A: host (IPv4). Maps the name to an IPv4 address. AAAA: host (IPv6)  Maps the name to an IPv6 address. CNAME: (Canonical Name): Alias. Example: Sites that use www as the hostname of a web server might internally call it something else, such as Dallwebserver1. MX : Mail Exchanger. This is used for an email server. NS: Name Server. Provides a list of the authoritative DNS servers responsible for the domain you are trying to query. PTR: Pointer. This is a reverse record; it resolves IPv4 or IPv6 addresses to domain names. SOA: Start of Authority. Keeps track of all of the DNS changes to help with replication. TXT: Text. Stores descriptive information about the domain in a text format.  SPF stands for  Sender Policy Framework. It helps prevent spammers from sending emails from your domain using the email addresses of your email servers.