Book description
Master architecting and implementing advanced security strategies across complex enterprise networks with this hands-on guide
Key Features
- Learn how to apply industry best practices and earn the CASP+ certification
- Explore over 400 CASP+ questions to test your understanding of key concepts and help you prepare for the exam
- Discover over 300 illustrations and diagrams that will assist you in understanding advanced CASP+ concepts
Book Description
CompTIA Advanced Security Practitioner (CASP+) ensures that security practitioners stay on top of the ever-changing security landscape. The CompTIA CASP+ CAS-004 Certification Guide offers complete, up-to-date coverage of the CompTIA CAS-004 exam so you can take it with confidence, fully equipped to pass on the first attempt.
Written in a clear, succinct way with self-assessment questions, exam tips, and mock exams with detailed explanations, this book covers security architecture, security operations, security engineering, cryptography, governance, risk, and compliance. You'll begin by developing the skills to architect, engineer, integrate, and implement secure solutions across complex environments to support a resilient enterprise. Moving on, you'll discover how to monitor and detect security incidents, implement incident response, and use automation to proactively support ongoing security operations. The book also shows you how to apply security practices in the cloud, on-premises, to endpoints, and to mobile infrastructure. Finally, you'll understand the impact of governance, risk, and compliance requirements throughout the enterprise.
By the end of this CASP study guide, you'll have covered everything you need to pass the CompTIA CASP+ CAS-004 certification exam and have a handy reference guide.
What you will learn
- Understand Cloud Security Alliance (CSA) and the FedRAMP programs
- Respond to Advanced Persistent Threats (APT) by deploying hunt teams
- Understand the Cyber Kill Chain framework as well as MITRE ATT&CK and Diamond Models
- Deploy advanced cryptographic solutions using the latest FIPS standards
- Understand compliance requirements for GDPR, PCI, DSS, and COPPA
- Secure Internet of Things (IoT), Industrial control systems (ICS), and SCADA
- Plan for incident response and digital forensics using advanced tools
Who this book is for
This CompTIA book is for CASP+ CAS-004 exam candidates who want to achieve CASP+ certification to advance their career. Security architects, senior security engineers, SOC managers, security analysts, IT cybersecurity specialists/INFOSEC specialists, and cyber risk analysts will benefit from this book. Experience in an IT technical role or CompTIA Security+ certification or equivalent is assumed.
Table of contents
- CompTIA CASP+ CAS-004 Certification Guide
- Contributors
- About the author
- About the reviewers
- Preface
- Section 1: Security Architecture
- Chapter 1: Designing a Secure Network Architecture
- Chapter 2: Integrating Software Applications into the Enterprise
- Chapter 3: Enterprise Data Security, Including Secure Cloud and Virtualization Solutions
- Chapter 4: Deploying Enterprise Authentication and Authorization Controls
- Section 2: Security Operations
-
Chapter 5: Threat and Vulnerability Management
- Intelligence types
- Actor types
- Threat actor properties
- Intelligence collection methods
- Frameworks
-
Indicators of compromise
- Packet capture
- Logs
- Network logs
- Vulnerability logs
- Operating system logs
- Access logs
- NetFlow logs
- Notifications
- File integrity monitoring alerts
- SIEM alerts
- Data loss prevention alerts
- Intrusion detection system and intrusion prevention system alerts
- Antivirus alerts
- Notification severity and priorities
- Responses
- Summary
- Questions
- Answers
-
Chapter 6: Vulnerability Assessment and Penetration Testing Methods and Tools
- Vulnerability scans
-
Security Content Automation Protocol (SCAP)
- Extensible Configuration Checklist Description Format (XCCDF)
- Open Vulnerability and Assessment Language (OVAL)
- Common Platform Enumeration (CPE)
- Common Vulnerabilities and Exposures (CVE)
- Common Vulnerability Scoring System (CVSS)
- Common Configuration Enumeration (CCE)
- Asset Reporting Format (ARF)
- Self-assessment versus third-party vendor assessment
- Patch management
- Information sources
- Testing methods
- Penetration testing
- Security tools
- Summary
- Questions
- Answers
- Chapter 7: Risk Mitigation Controls
- Chapter 8: Implementing Incident Response and Forensics Procedures
- Section 3: Security Engineering and Cryptography
-
Chapter 9: Enterprise Mobility and Endpoint Security Controls
- Implementing enterprise mobility management
-
Security considerations for mobility management
- The unauthorized remote activation and deactivation of devices or features
- Encrypted and unencrypted communication concerns
- Physical reconnaissance
- Personal data theft
- Health privacy
- The implications of wearable devices
- The digital forensics of collected data
- Unauthorized application stores
- Containerization
- Original equipment manufacturer (OEM) and carrier differences
- Supply chain issues
- The use of an eFuse
- Implementing endpoint security controls
- Summary
- Questions
- Answers
- Chapter 10: Security Considerations Impacting Specific Sectors and Operational Technologies
- Chapter 11: Implementing Cryptographic Protocols and Algorithms
- Chapter 12: Implementing Appropriate PKI Solutions, Cryptographic Protocols, and Algorithms for Business Needs
- Section 4: Governance, Risk, and Compliance
- Chapter 13: Applying Appropriate Risk Strategies
- Chapter 14: Compliance Frameworks, Legal Considerations, and Their Organizational Impact
- Chapter 15: Business Continuity and Disaster Recovery Concepts
- Chapter 16: Mock Exam 1
- Chapter 17: Mock Exam 2
- Other Books You May Enjoy
Product information
- Title: CompTIA CASP+ CAS-004 Certification Guide
- Author(s):
- Release date: March 2022
- Publisher(s): Packt Publishing
- ISBN: 9781801816779
You might also like
audiobook
CompTIA CASP+ CAS-004 Certification Guide
Architect, engineer, integrate, and implement security across increasingly complex, hybrid enterprise networks About This Audiobook Learn …
book
CompTIA Network+ N10-008 Cert Guide
Trust the best selling Cert Guide series from Pearson IT Certification to help you learn, prepare, …
book
CCNP and CCIE Enterprise Core ENCOR 350-401 Official Cert Guide
Trust the best-selling Official Cert Guide series from Cisco Press to help you learn, prepare, and …
video
CompTIA Network+ Certification (N10-008): The Total Course
In this course, you will learn networking fundamentals, implementation, operations, security, and lastly, troubleshooting. This exam …