0% found this document useful (0 votes)
2 views19 pages

CybersecurityNotes

The document provides a comprehensive overview of cybersecurity, covering fundamental concepts such as the CIA triad, networking basics, threats, vulnerabilities, and common cyber attacks. It emphasizes the importance of protecting systems, networks, and data from unauthorized access while detailing various security principles and controls. Additionally, it discusses authentication methods and access control models to ensure secure access to information and resources.

Uploaded by

wafaek693
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
0% found this document useful (0 votes)
2 views19 pages

CybersecurityNotes

The document provides a comprehensive overview of cybersecurity, covering fundamental concepts such as the CIA triad, networking basics, threats, vulnerabilities, and common cyber attacks. It emphasizes the importance of protecting systems, networks, and data from unauthorized access while detailing various security principles and controls. Additionally, it discusses authentication methods and access control models to ensure secure access to information and resources.

Uploaded by

wafaek693
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
@qa_insights N - CYBERSECURITY OMPLETE NOTES > (Cybersecurity) = de ® Be Network Ethical Firewalls & | Malware Threat Security Hacking Defense Analysis Protection =| BEGINNER TO ADVANCED | < SWIPE _TO_NEXT —> < Se o> @ UUUUUU UU eee ae ee eee > Qa_insights better careers = @ qa_ insights 01. Cybersecurity Fundamentals ® What is Cybersecurity? @® Cybersecurity vs Information Security Cybersecurity is the practice of protecting systems, networks, applications and data from unauthorized Se cisa dae oy aoe i Tk ensures the confidentiality, integrity and availability | of information onl eyteme i @® Why Security Matters? + Protects sensitive data and user privacy + Prevents financial loss ond fraud Aspect Cybersecurity Information Security Focus | Protects aystons, neboorks | Protects all types of and. digital assets information Scope | Technology, netuorks, | People, process and applications, devices fechooiogy “Threats | Hockers, malaare, DDS, | Tnternal mizue, leaks, Phishing, exploits physical threats Goal | Prevent cyber attacks | Protect information and system compromise | in any form + Ensures business continty and trast ‘Helps meet legal, regulatory and compliance requirements * Protects reputation and brand value People é ASS = Epes * Sener + Maile Dees * Ist Devices Aaplcstions hb Arps Hobie pee + APs + Seabee Threats &, © Attack Surface The foal peter of pts whe an entire sir Eos tata enemy eral Trades + Open ports, series, APTS 2 We cepts User touts perisins Devies, endpints, ld etree Third-party inegrtions + Phishing GA Tate Tat + Does ® Cybersecurity Ecosystem © Threat Landscape Tans + Notin-State Actors {Engines Natorks Aavonced print tres, “i Partie ction —| poe epber unrfae Si 1 Inert Franc gin, cxsonnact, data the. + Hacktivits Date ie Lgl moins, eile tee reas defacement, DDSS. Bices | 6 Trcidere Goal Sige! acs o relent Ss Secrty Conroe ae eA + Scxiph Kies oo Lonel tacks wing ae rengade tse + Racer ® Basic Security Controls By Prevert = Frnt, acess tl, enti, ptcing Detect = 105/175, monitoring, logs, thas intligene QA Respond = Incident response plan, alerts, containment 1 Recover — Backups, disaster recovery, business continuity and Security controle Remember 1 Common Mistake ZX RF Interview Tip Sanu 9 it «prot, Thinking secuity is only TT tans jb. | Exlin CIA Tod, Theat types, its proces Realty Evergne & respetle ‘itack surface People + Process + Tehnlegy rate erly wth amples. ‘Strong. Security J @qa_insights | Quality Insights, Better Careers | @ qp_insights 2 02. CIA Triad & Security Principles @® What is CIA Triad? Confidentiality CCA Tad is the foundation of Information Security. Tk ensures that systems and data remain Confidential, Integrity and Available to cuthorized users when needed. Ensures data is rae & ons Ensures systems and ‘accurate, complete =~ ~~ serv data. are available sid rok alter me g han rad be ate, thyeileieivg @ How They Work Together ? Security is not just one control, it's the combination of all principles working together to protect data, systems and users Ensures data is accessible - only to authorized ® Security Principles Dp ‘Authentication | Verifies the identity of ers or geome | Determines what an authenticated | % ase cates =y Renrrepuction |e tudo Cae oma tr Users ond eystims have only the minima access required to perform their tasks @ moist @ Why These Principles Matter ? Protects sensitive data from unauthorized access or leaks. 9: Important Note + Prevents data tampering and maintains trust. No system can be 100% secure, + Ensures business continuity ond uptime. tat falling theca. pincples redaces Helps meet compliance and legal requirements raicrand ball i raubese ard * Builds user trust and orgeniation reputation fy Remember ZX Common Mistake © Interview Tip CIA Tid pete WHAT, bile Ain re CIN Ft Security Principles protect HOW. or vot enforcing least prvlge arity Piniples in your anevers with examples @qp_insights | Quality Insights, Better Careers | @qa_insights 03. Networking Fundamentals for Security ® Key Concepts © IP Address (Logical Address): Identifies « device on a network, ~ IPv4 (32-bit) e.g., [Link], IPv6 (128-bit) MAC Address (Physical Address): Unique hardware address aigned to network interface. = gu, 00:1A:2B:3C:4D:5E Ports: Logical endpoints used by protcels to identify pplication /servies. Range: 0 ~ 65535 DNS (Domain Name System): Translates domain names (Gerd ell ap tet HTTP vs HTTPS: HTTP is unencrypted (Port 80), HITPS is encrypted using TLS/SSL (Port 443) Network Flow (High Level) aan) Example Comection | Client Coe Chartres | bitpe://example..om => — <—_— | Geert 44) = +-0NS rests doin $[Link] [Link] | TEP cmcton stabs Poi fet bod ee | + TLS handshake (HTTPS) WAC: MM-B8:CC-DD:EE FF on rales (OR it, Poti) MAC 11:22:38:48:55:66 a TCP/IP Layers (4 Layers) \ raiser Kauledge Matters Fate 1? wr] | © Aepliton ayer ao : i (HTTR, DNS, SiTP) Sane Ri Neeslin niece Ea Comstin | Comdine ntl | Grtiotas _| | Rite ae erate Pasi | aia (Ace, | Unione |! Transpart Lager ated msc, | Y Exel fr Frew rae, SE | frsadacatat) | Oy Sern pt, sereiton 1D5/TPS, and segmentation ae [Seed eel Gy se dg | he bn Tb, End, Fe Tank | DS, i, Sang | | od ring (OP) secstty tome, Use Cases | ss TIPS rural! =e Reid fr prin it eur Aacess Pagel nmin | testing ad incident response maleem le] OPmr bas | oe ‘r Remember IP = Where 0 device i MAC = he a davice ie LA Common Mistake Allowing unnecestary parts Kou well-knsun ports, oF applications and services WE Quick Analogy Netuork is Uke a city TCP ve UDP differences IP = Address Parts = What service on fireull exposes systems TCP = Reliable yl cand the role of DNS, Parts = Department UDP = Fast HTTP & HTTPS: Protocols = Rules of communication yainsights | Quality Insights, qa—insigl cs Better Careers! @qa_insights 4 04. Threats, Vulnerabilities & Risks ® Key Terms ‘© Threat: Anything with the potential to cause harm @ Attack Concepts to systems, data or users. Attack Vector © Vulnerability: A weakness or flan that con be The path or method used |The toll aren of bry points ‘exploited by 0 threat. bay an attacker to deliver here an unauthorized cer @ Exploit: A technique or code that takes cdvantage | can attempt to access of a valnerability. Impact: The damage or effect on confidentiality, integrity or availabilty + Risk: The possibility thet a threat sill exploit vulnerability ond cause impact + Threat Actor: An individual, group or orgeizaton that initiates threats & @ The Risk Chain j Threat Vulnerability Exploit Impact Risk a O & x res lle ee alee elec ere ee eee eo oo a ores le eee [aera | a ise ae ® Threat Actors + Cyber Criminals: Seek financial gain through theft, fraud, roncomoare, ee Risk = Likelihood x Impact ] cis Ota ty lao poi 1 agendas Tee + Confidentiaty Loss | IE * Neto Sate Atos: Conduct ong, saiage ‘ ity Liathood + Integrity Damage or cyber uerfare. Tl epenre (Atack Sef) + Malay Dostine 7 Ter Tt: Eng or tad er Finacial / Lege Impact | misuse access (intentional or accidental). + Reputation Damage + Script Kiddies: Tnexprinced attackers sing ! I ready-made tots and expats LX Important Note YY Remember © Interview Tip Seerity is ll about reducing Risk by + You camot eliminate Risk ‘Alwags think: What can go wrong? reducing Vulnerabilities, iting Attack Surface | | * You con only reduce it Where joy Cah coatoe 7 What is the impact? and strengthening Controle = Focus on ua malar mod How Ukly is it to happen? @aqa—insights | Quality Insights, Better Careers! 05. Common Cyber Attacks @ What are Cyber Attacks? | @ Attack Taxonomy (High Level) Cyber attacks ore malicious allampts | to access, seal, alter, disable or destrey | CYBER ATTACKS ystems, networks or data t 1 4 t + @® Malware ® Virus ® Worm ® Trojan © Ransomuare Malicious software ‘Attaches to lagitimate | | Self-replicates and Disguised as legitimate. Enerypts files /data. designed to damage, | | files /programs and spreads. over networks software but. performs ‘and demands. payent Ses pepe re | rnabicis ection Tereiede sed cnocthrinad acs Goal: Goal: Goal: Goal : Goal: Darpt, Damage, || Cor fan, Syston | | Cine, rararsas, Sta data, Backdoor Franca gin, Steal data intabity Der loet cess, Expionage Data exertion oe ge 2 ge © Phishing ® Social. Engineering Brute Force © Credential Attacks | | @® DoS / DDoS xsl & | oa : is] Fake emai oats || Marples pole | | ties mang pasnrds | | Use leaked er gusset |] Ovratainsaysame or trick users to renal | | through psychology cor keys until the Credentials to access abverks lth, massive senitve infomation, | | % 366 tirmtin || Creek one is found, || certs Cogn erent | | tre or aque or access. stuffing ) Goa Goa Goal God: Goal Seal. crednics, || Bygess seer Guin womihoriand || Acount tahaover, Rie Francial frau. Haman explaitation access Dota. theft unaveilable © Best Practice Keay sylane & ppt opted Y, Use strong pssurds HFA Ye Tmportant Note Ntaciers con use a combination of mate atacks in a single campaign. aaa eats Example: Phishing email > Malware delivery —> Ransimuore execution | Uh ache ioral Y_Tngloment defense indepth 3 Remember AS Common Mistake @ Interview Tip Tdentify > Detact > Proven Users licking urkroun inks Kou the purpose, impact and “> Respond > Recover cr dounloaingotachnerts prevention for each abiack type Goonies from untrusted sources sith real-world examples @qa_insights | Quality Insights, Better Careers ! @ qa_insights 6 06. Cryptography Fundamentals © Core Concepts | @ The Basics Flow © Encryption: Converts readable data (Phintet) into | Ciphertest. Decryption Plaintext. unreadable data (Cphertet) using a hoy. i apt aA = © Encoding: Converts data from one format to another | aB7E 4F90|—> [ ¢ | >] Hello ([Link], Bose6) ~ NOT for security i £4 a Wid '® Hashing: Converts data into fixed-length output i u (Hash). One-way process, comet be reversed. | © i Secret key Secret Key ! el eee (Same key) ' £ (A) Symmetric. Eneryption (Shared. Key) «Some secret kay is used for bth enerypton end. decryption Faster, suitable for lage data (B) Asymmetric Encryption (Public Key) © Uns pa of typ: Rabe Key onl Pate Key. © bic kay encrypts, Pinata hay decrypts © Sat, sed fr sre bay exchange dial siete Cpt phere Pitt sae 02 @ | 7a 9020 a mail |: 170|—> i sere sr90|—> L# J—> | — aa taxn i cz Deigt! |= | * « Lneg: eps & Shared Secret Key ' Public Key Private Key @® Hash Functions © Digital Signatures © PKI Basics © One-way function. Oriel dala [© Enures othentity, integrity and 4 Pabe Key Infrastructure (PKL) manages cont be reonard reer | ays and digital corti 7 Eras ty Change pct |) Sige eed pole y t | Uses Certfeate Authorities (CA) to proces «comely diferent bash | Anyone con verify sing puble key. | ei enkty Input Hash (SHA-256) | lie pe SHR256)_ | Data (ita) Sure (MSD ss | ae CSR CA Creda Tred Hello | 185FeD832273Fe25. hello | s6Fcecez0867095F Helle! _| #FRSSERC2AOBIFFE Ye Remember LX Important Note @ Best Practice Q: Interview Tip Encryption = Secwrity | | Never hardcode hays. Use TLS/SSL fr data in tranit.|_| Know the difernce been Enns data at ret. || Syrmaric ve. Aayrmetric, Encoding = Format oe strong elgzithms Ui i <) 2 ti Ue | 1 7 tet rae bye caefily. | | Hashing, Dig Sgmters Hasting = Tneity | | AES, RSA, SHA-256. | Y pate kage ely Aiea @qa_insights | Quality Insights, Better Careers ! @ qa_ insights 7 OF. Authentication & Access Control @® Key Concepts © Authentication: Verifies the identity of user or system. (Who are you?) © Authorization: Determines what an @® Authentication Methods Possord, PIN, Security B Something yo brow | ee eee OTP, Mobile, Smart card, authenticated user is allowed to do. Hardware token nat can you access?) - Biometrics: Fir int, (iat en yu ec?) GD Saving pu ne | Bat: Fes ‘© Access Control: Policies and mechanisms ‘that enforce authorization decisions © Goal: Ensure the right users have the right access at the right time for the right reasons Factor Authentication) Combines tivo or more factors to verify identity | [aaa cer anes D Access Control Models RBAC (Role-Based ]{ ABAC (Altrbute-Based | DAC (Discretionary MAC. (Mandatory ‘Access Control) | Access Control) Access Control) ‘Access Control) Tip Sert_ | Hh a- i QA > (aa) Secret Confit R22 me beg ed ein [libres aura oe] Access based on security Access is granted bosed on || altribles and policies, cen excess the rescurce Lhe ser oles. Exanle: Mlow acess oly from || Examples Fle comer gies aa | Same: Adin, Ue, Aer | | fer nek: ding wring has] | pein to there Used in govt, military systems 8 Application, Data, ‘YF Remember LY Common Mistake @ Best Practice “Qi Interview Tip Aatertcaton = Verify Uentty | | Gining more acess than | | ¥, Ute MFA fe al ecounts | | Alsays explain the difference Authorization = Check Access rapiredl Ore fdanea yale OS teat Tae between Authentication and ee a ea Teal Sean [A eat ik | le san | | aca @aqa_insights | Quality Insights, Better Careers ! @qp—insights 08. Network Security Key. Concepts @ Layered Network Security Architecture @ 4 Firewall: Controls incoming and antgsing_ neuer traf TDS: Monitors traffic for spins actly and. geerales lets IPS: Actily Wocks or provents rabous raf VPN: Creates enerypled tunel er untrusted. ebors Prony: Ads on intermediary betanen ces end servers NAC: Ensures ony tested & compan devices azcss the nlonk Defense in Depth: Mile lagers of seority controls to vobuce ih Security Components. Explained @ @© Meng Rees Lage © Rests Cntr Lage @ Werk Set age \@ Data / Application Layer WAF, Apatin Security, Sere Coding DNS Sets ogre, from lta Dele, aarts and responds to Urea SIEM, Log rae, SOC, Threat Inligece| Enares oly othrned NAC, IAM, MFA, Zero Trt ee ee Ply Eefercoment Mnitrs and filers DS / TPS, VPN, Prey, eae Bhatti sai pcinbe. Perimeter Secarty Layer Feslls, DM2, Aati-DDsS, Neloork Sogeartatin Lng YUM, Sut, Hemera, ite aie movment it cher. Peles phy infeeractre IDS. Cntraon Freall TPS (hrsin VON (Vira Detection System) Prevention System) Private Network) a \, Oo (R Jee tn endo || ts tte [fet at Bs, |] merged trae ben |] Ce da pt i or et hone) acto lt et ne spine pt || sa ti gti || Ere on may Soca Oe amet da || *Pasie ~ oly lets. |] ents ts in rane |= Typ: Ranta Ae, ||* He tral rch, |] before ec Types: eh Filer, || o Types: NIDS, HIDS || «Types: NOPS, HIS. Sa-Su VI |] a ti || Empl 802.8, Siauincrw | = a ie, ® Netware Segrentation © Defense in Depth ia eta te alee tnt. Rah eke tana cegnants Pg Sealy (Lid, CCTV, Gude) + Permtar Seurty (Fre, DoS Prlectin) Neberk Seaity (IDS/IPS, VPN, Prony) ezas Cntr (WAC, TAM, HFA) = Ent Srey (EDR, Ani, Pig) Apion Serty (WAF, Sere Code) TPS = Promnt Wu soar tn wits | Data Saat (Empl, DUP, Bae) as EGET Rare ak ome ag i, at a ph en | [PCiieewnen Mite © Bat Prelce © Interview Tp os Beedtedgroriptean titty ee eh ie ean Ena legging b mostaring. Segrent nk properly ep dea pth. Fils loa pie wc v v ceed ef ether v (Cafes in Dep): Dra lage v sretacure if posse v ights | Quality Insights, Better Careers ! @qp_insights 09. Web Application Security @ What is Web Application Security? | @) OWASP Top 10 (2021) Web Application Security protects websites and | | 1. Broken Access Control Pac tueb APIs fom attacks that exploit 2. Coptogrghie Fs Lean aie vulnerabilities in code, design, lgic Failures 3. Injection Softuare & Data Tnegrity or configuration Failures 4, Insecure Design See agg # Meng Goal: Protect data, maintain integrity, 5. Searity Misconiguration enore ilblily and preserve teat Server-Side Reus Ferg (SRF) + InpotValdation + AF 1 Secure Headers = HTTPS ® Common Web Abtacks (SQL Tnjection XSS | (Coms-Site Seriging) ater ints a st |e | oe |S are Sie ae serie enna in at's Ue open pots, expen eror Rae rower Fact a igen ser | Ur can ent or modify | mesages, te Prevention Ko pefiemtinomtad, | resources bayou thir Majer Pees ectons | permissions ae yaa Paneer es | Preven + See deft © [Link] ew ys | CSR tans + Enforce autherization “Regier efiguccbon Samet cokes Les pros oan © Best Practices ZX Common Mistakes Ye Remember © Interview Tip Yee s tetng ae || See Dg, | | Beng eae OS Ty 1, PaaS He py + Exposing sent info Secure by Default, | | SOL Inpeion, XSS, CSRF and (1S) and ot rt in ero messages ea es eu proret than’ rel + Hard oF ewe Pag beriernntereal Herdcding vecrets Lue Y. Refem agar sey lig || * Ming ccs cole Defense in. Depth Pre @qa_insights | Quality Insights, Better Coreers ! @qa_insights 10. Cloud Security @® Cloud Security Fundamentals + Cloud Security i the pain of protcng dt, pln, wats frees Peat eee APS [pega cies ella + Goals: Confer, Inert, Aniabity sol Capita. e368 cay @® Shared Responsibility Model 10 = sy Raat ah aterasay QB le) eee eS Hird canara 6) Matsitrottigyprvider Ep Panag enna eC (She oe pe?) e?) Rea + Canralized ‘denity, roles end permissions. 1 Use RBAC / ABAC, Least Privilege and. MFA | © Seerets Management fear seems (eo AWS Secete i Manager, Aare Key | Vat, GP Sent | | anon © Micanfiguain Ris + Ope Sirah Bale Ls: Ooty porin ite ites | YY Remember Cloud shifts responsibilty, not romoves it Security is « Shared Jurray LX Common Mistake Aaseming cll provider cxcures everthing Tyroring configurstions. G Bet Proctice is Lge El Lig & Ming ¥ Enea evrything {YR st rie @ qa_insights | Quality Insights, Better Careers! % Interview Tip eit tania as Resnsiity Moll and vd fac iad @qpinsights 44 11. Endpoint & System Security D Key Concepts | + Endpi Sewily prc det Ibe | ged dena tee Pagid fo Ghalgg elyaaken te pe threats targeting endprnts, © Strong endpoint security reduces risk of malware, data theft and unauthorized @® Key Components Explained 1. 08 2. Secure Hardening | Configuration | Management eT ee Aiabing wuaed | bastinos and | 05 ond eftvare serie, hanging | coniguatin | te fi room dull ating” | standards lorie, snd efing Strong poses. | Esamles: sane: Enangle cS tenbmats | Winews Update + Dine Gust | + Grup gy |» WSUS Sng eamend | 6 Sten Aalte | 6 Theda ‘eg | © rate Tote en | @® Best Practices Y Keep 05, append driers updated Bee eclanialatl va Ena Fr eleudpi prcatin, edit eka eer Morir lage and alerts cntimously Backup impartant data regulary KS488 | 9 Remember DX Conmon Mistakes Strong endpoints = Skrong security posture | Secure endpcints protect data, users and business @qa_insights | Quality a 7, Device Sarty GER (Dain 8 Re) oe Pavias / Aot-malare @® Endpoint Defense Layers (Defense in Depth) Protects devices from lost, the nd ppc ttacs ‘Mew ony trated opps to run. Blacks wnuthorzed pps Detects advanced threats, imestigaten and. responds areca Blocks Koen maluare using Satire ond heuristic onal Kaye 05 srk appeal ap te date to fic vlrerabilties, Enforce security baselines td best practices Minimise oltack curface by Eeabting wrecenary serves ond features San ES ste | cama | te ® Qifa a Ree ee cect monte aera ne oe StS Ss Set ES coaen Se. co pet ea eae Lo Ce eae [Sot eh hee The SE pe EE | aes I Ss poring sytem updates Ung default configurations tifa lee Delegated fo I bl tig 2 Interview Tip Know the endpoint security layers and how each control hele Be ready to explain EDR ws Antivirus and shy Patch Management is critical ‘Nec, understand hardening and pplication contr in real-world use, @qa_insights D7 12. Email & Social Engineering Security © Types of Email-Based Attacks | @ Common Traps in Emails by Phishing: Mass fraudulent emails sent to many users | Malicious Attachments: Files with malware fo steal credentials or deliver maluare (exe, doom, sip, js, ee.) Spear Phishing: Targeled attacks on «specie ‘ele fet fps formato i @ Malicious Links: Links to fake subsites \ eli fle snil wheelers Whaling: Targets high-profile executives (CEOs, | (CPO A el ah ae cet | MM, Soci Enginerng Paghaagy: Machars plait $ Base Email Coproie (BEC): Ninos | Qe tan emis = fer egy ci, rnd Reveal raalis Balen TS or trust to maiplate atone @® Aratony of Phishing Eni {@ Prevention & Best Proctices a nm et ore cory ore fees fel Se ola deere ah oa fe ney at Generic Subjects Urgent: Verify Yur Aco Kou! Check the otal, URL Gog ol Sats Uae Vey (PE tad Fog i ¥ De nat open anepectad Dear Customer, | + tone or ake denn! | tthe pre) a] We detected unusual ctvty on your acount, |! in slr lds alee rather Tht Your ecout il be expended in 24 hours | Ge ting Orr FING we senitive ifemation. 'F you don't verify immediatly FM deka ee Zag hpct , wanl Please dick the bition balms to verify yar acount. |! Supine links Gr to T1/Security team tik CO 1 eck | L] Enable MEA on ll acounts Urea atactnmts || Keep secarity omareess igh ees 1] cn say updated Spling Use na ftring, en pishng cell sathetag lene Fale Lge / Bruning | © 202% Sear Lain AL : [te pm pet Social Engineering Techniques f , hey tick: prple. i Oo eerea carey {Whe Werks? | Shag Aes Th Boe | Co ts gy 5 OD | va itty | You ha! => Quid Po Quo (ofr hin) {2 Urging & Foor saa pas ee oy | + Corialy & Grad ‘car > Tapatin pdand eat) iin | Hye © Best Practice LX Common Mistake 3% Key Takeaway © Inteniew Tip Wri bef yu tra + Clkng witht inking || Emails cr be pmerfal | | Be ready to clin phishing Use PEA erga © Typoring sll rol. flag pe a tapes, re flags and how Kap sglene tds plated. | | + Oreriharing information. | | Aggreness + Verification | | you will handle a rater Eda ear reply + ning emis genine. | = Strongest Defense. | | phishing incident @qa_insights | Quality Insights, Better Careers ! @qp_insights 13 13 Vulnerability Management @ What is Vulnerability Management? | (2) Vulner Velrraity Managiment is the ntinwous ® @ proces of identifing, evaluating, prioritizing, remediating, and veldoting security uleroilten in. asters, oppiotiaord ebuorks ty Management Lifeeyle Goal: Reduce attack surface ond risk by xing wlrerabiities before attackers expat | them. ® Key Concepts | © VSS Severity Rotings (v3.4) Asst: Ary diz, appleain, service, dud rence, | {Scare Range | Severity Description Aation Sree 1] 90-100 | Gritant | Had ris cay to ovat | Fg Tamedately + Vulnerability : Weakness that can be exploited. tL major impact © CVE (Comen Wines ond Egonre): || 70-89 Beha see Fa ASAP Unique 1D for «koa snerab | ra z " cee lames Fa an © CVSS (Common Vulnerability Scoring System): | impae Standard sce (0.0 ~ $00) tht shows sty. | | 04-39 | Low | Lewis wirinal impact | Fi When Rese + Risk = Likelihood of exploit x Inpact iL 00 Nove | Informational Monitor © Risk Prioritization Factors | © Remediation Examples er | | pid inadogtel Y Rrlcatity (Cyst ott) — | 208 Y had Chiey Bais opt) | tiger a, | 7 OS | 7 pin (ara fag Fares)|—P 6 par | "en Rte | GE |_| Dela Santivty Prrty | Frmare Updates | } vCal Cae | © Think-prty Solara Updates | (a Thea tee | | @ Toss Used (eka, Winatlsai fared jee 4 No wali re dere dy Es oO oO > © © Coin an mode ar pins t } shay prot a, apd? Ops AMS per Arne | St ith SIM / Tide / Ah Magurt Rade kin ght Defrder 7 mae TY Best Practices AX Common Mistakes @ Remember Qe Interview Tip YY Scan regularly (weeliy/daiy) ‘+ Scaming wthost remediation Yeu conrat protect Understand the lifecycle, Bon borden ak Figeeg aieaeh ae car ee Cis eal este Aen pts prolly © Me raleboed pin eee Validate and wry fs Ne aidan the fs Direc Se 2a ‘lnerabities in real-world ak mat ad igs Tempe i inary date > Repeat eveoomant. @qa—insights | Quality Insights, Better Careers | @qa_insights 14 14. Security Monitoring & SIEM fifa @® Key Concepts flog taal ohare erally Saag aes + Sealy Eve: Spee scare at ae «Art: Nefetine gard hon ets rn rule a i ey + SIEM (Sealy Tomato and Event Management): Colets, correlates and Q@ Monitoring Flow cee eats sem Eat ews geld = UEBA / ML + Tickets . ace Sf enigma, tiga a Sic lee CSTE toe respond to threat +106 / 108 @® Leg Correlation (Example) @® Detection Rules (Examples) 1 fhe filosing bpp Taper Aer Se led agin lamps fom tae Tin 5 rine Ur ae Fo Tape Fort At Brata Force Alt. 4 Walware detect on | lens | Mae Ae bis Conte | [ese [ett et teed ee lineata © Tweat Intelligence, IOC & IOA © Benefits of SIEM Test Taigece | (10¢ aes Cope) (TOA Can of Aca) | Vela vd of ete ern enon hn inn] | fae Ua dine | | Bon ankle wm in| | 7 Retin Ui dln and lating acon does od TH | | Exams: peg Corio rd ies fle pti. “@x* + Ribion TR nag: ce al een AD P sfiaiieos Orie eal repirenents. Fe Haber Pach enatin S| | V Tree ie rege oped fat Adan 2 Page stn ng Re ees & ze Un ed Tae + 10C/IOA in SIEM to dec B nejing rate.) WY Best Practices LY Common Mistakes YY Remember @ Interview Tip Ya reo ay fon a ses || a ing ech a You can't protect Unlartand lo sures, edn, Yeap tine op (HTP) ss gen Tog et ig tat you can't se. | | OC we TOA, deletion re, 1 egg tk tin te || © Mee yw ri Yh teat pig fr STEM aa perapennen Mort -+ Dee» || and haw SIEM spare SOC Y Nose SEM ah age Ny Ord ip Rarpond > Inpro | | seri @y jights | Quality Insights, Better Careers ! ights 5) 15. Incident Response Incident. Resporse is the structured approach to detect, respond to and recover from security incidents to minimize impact and restore normal. operations. Tncident. Response Lifecycle Se ee ORR eae titan yee | © Setup tool & communication + Training & anurans © Decumart: tinalra 2 ection + Evidene called + Tngot asesmnt + Final ropert & compliance E sthafer imelwecea| Out Detect potential) cadet a Q | ae ify al ek wall? + Gof & dea tint tehat didn't TR Goal: J + Record initial details Update playbooks, contre , Acer mene eRe aid tainmen vi Coa os & Restore Business Se (© Short-term: isolate affected copies Conny pie ghotehs, pees + Long-term: prover sprend, + fate pce & writ Racowry | (@ Erion) ay) preted ans Sree Peete tansy | tate yeaa © Gradual return te normal hs ae we + Verify fetionality af kage aN SR ee # Dalate mare, else backdoors + Patch vulnerabilities LA Common Tncidert Types | ge Key Principles 1+ Malare / Ransomuare TV Act quietly “+ Phishing / BEC | ¥ Prsere evidence ‘© Speed + Accuracy = Effective Response + Unetheriaed Ase |v Committe carly © Good. prepartin reduces respnte tine + Date Breach | Pinos bans pct Dev't dp + DDS Attack Fallow preces & playioks ; Insider Treat f Continous inproveent rea eet ie = erg patty © Best Practices BiGenn item || FE] Remember Interview Tip Keep TR playinks updated + Dulagd tection Prepare Before, Explain each phase of IR Y Erale loging & mooring | | + Por communication Detect Early, ith real-world example ‘Regier dels & simtins Nok. preering evidenee Respond. uc, Menton tools lke SIEM, Backups & tested restoration | | + Incomplete radiation Recover Safely, EDR, SOAR ond Tit lad diet aaa Na pet aveded ot Improve Continaouely systems @ qa_insights | Quality Insights, Better Careers ! @qo_ insights 16 16. Ethical Hacking & Penetration Testing Ethical Hacking is an authorized attempt to find vulnerabilities in systems, applications or networks to help organizations fix them before attackers exploit. @® Penetration Testing Lifecycle © Key Concepts + Eh Meng: Ligh eg wh | permission ts ingen secu j ee eo en SARIN ate 41, Reconnaissance Gate infratinaeat target (OSDNT, DNs, wHors, | a alia, de) @ 2 seaming Ty Uo he, pn Pelt Aone Dene adopt | cater eda © Goal: Ldentiy, expat (in cotelled runner) and report vlrarabiltine to improve defenses. © Scope: Defined sytans, epplications | || ve. Poat-Expltation $= 3. Enumeration or abuerks > = Ose Ethical Hacking oat ake ® pes of Pentesting kes Lifecycle fel Meal 2s Black Box: No infermaton provided. | © Gray Box: Pari information provide. While Bow: Fall formation povided, | 4, Vlreraity 6. Privilege Qe eigen. Assesment (© Internal: From inside the network. antl Es Gain hier rags Ang lel eater es © Web Application / Mobile / APL / (Cay veciin $9 gui rae ate Wireless / Cloud / TsT Ponteting eal velop! xcace oF cnt. ® Common Tools | ® What Are We Looking For? © Ethical. Hocker Mindset ast asters neal tae ti aerate Pewee eee eee eee ee ea Enmertin: Nes, SMBEnm, Gober setae nd Lialiood ack Lhe 0 defender. Winery San Near, Op NAS Default / weak erdenials fy Yarine | Fallow eles of engogemtt Elton’ Malt, Burp Sate Insecure services /pets eee ‘rand Mince: Hydra, Jn th Ripper | 8 Sentine dade pera Poa-Ergaitatin: Meerprtr, Minas a ee ae Yi Protect dale. privacy, Reprting: Brae, Carne Y Reaprk respon © Bet Practices LX Coen, Miles ) oj eae ae oe pee Teed sets wad) ean a oe Piss iia ok Note af fe mebesie ea) | toa weeny | [etal Be Epc | Validate fadings wary. ‘+ Tying aloe positives, Feats hoes del | Minin nga on gta. Na decmentng. properly. Find it > Fix it > BPs | Mrs dar roan tee main Frat it at | @qa—insights | Quolity Insights, Better Careers ! @qa_insights 17 17 DevSecOps & Secure SDLC DevSecOps integrates Security into DevOps and SDLC so that security is built-in, automated and continuous throughout the software lifecycle @ Secure CI/CD Pipeline @ Key Concepts i sere 1 Seat ees Fe dened Ui SHALE. Seely: Fading & fing vrais ely inthe SDLC + DeSecOpe: Pale + ce + each atic «Gel: Da sour efor fir th contin falc Continuous Feedback Loop Sealy Toad in Pipi | © Secure SDLC Phasee | © Benefits of DevSecDpe T, Requronote sch ae compare on AST: Slate cade nays to fad ration tery in vw. cole Eng dita = lute cath to fo verbs, ‘DAST! Dipeapi tatig rong pheno ‘Dee Pg Retest leas rate le preted: te fin tine ioe KB Tet rei sere wetter, || Y tmaed ily = ens SCA: Sofas Conponton Ais to ect ap ncairaat” os leeches epevsence compe i | Sop va stg ¥ Fatr radese wth bil-in sey Secrets, Scanning: Detadis hardcoded sas, SAS APE bey, ttens in cde Darerdoey Seedy aera tele wins re opted & seme Y Tnprove cellaberaion bslaten Daw, See & Ope teas 2%% HO Cordtiner Sctaing: Sout criner image for bnom varies Sceahe irate | Bet pes | Css eee nae wate ele | | ShifL Left ~ Secure Early, Secure Alays! © Best Practices 1 ZX Common Mistakes © Interview Tip ideteedt ect eee CTT: © Aiding wort ly oth wd Be rey be ela Use Tfetre at Code (aC) smi | Tying fled sei scam res J SAST va DAST ve SCA Keep dependencies & base images update. fe erltedie sill crete Shp Left concept YH security file in CI/CD Y Seats management. srlagier Y Container & dapendancy sxcrty + Wing eat dopey li pees aa Fase aioonah cere King party Contnmaly mtr Bela sey mi | * Mitofigved dd J cotinre v v v Store sera val, er in nde a v $y Key Takeaway ‘DevSecOps is about building security into every step of development. and operations Seare Cols —> Sec Bild —» Stare Deploy —> Suare Ran @qa_insights | Quality Insights, Better Careers ! @qa_insights 18 18. Advanced. Cybersecurity + Quick Revision @® Defense in Depth Use matiple layers of mecwity controle @ Zero Trust Model User / Device Never trust, pees Agog a ees | + Nery enpitly é | a To athe Pees + Aan breach I ee + Mare-tegnatation Pay Exe ©) | OES Manone ees | SS Oo 8 QO pea iN eats | | Tf ore ager fale hse eal | @ MITRE ATTACK Overview | Frameerk te undrstand @® Security Architecture = ald soar, alle cael wee + Seare by Design + CIA Tad + Wray os Eat + beat Pree + ve, ovss + QUASP Tip 10 et ee pe 05, nny CEN / OCP Ck / ApS Mar | Pe + SAST we DAST we SCA Spiga Th Ba CISSP RY DIR, CHSO | zee Tat Jaan a 500 1 = er Sol (Fi maya)” Ot Sheet apt Seeear ee ee er © Sra = Pople, Frets and Techoslany mat work tgeher Prevent > Dalact + Resp + Reimar + Dap Sect is ceryoe’s snp, Stag spate, prc labe and bald raver sil, We pee aeN| Tk Ue on aad, ded tn « pe | Response fare Nong Sree | nent omy oll mop a @ qp—insights | Quality Insights, Better Careers !

You might also like