0% found this document useful (0 votes)
14 views26 pages

Study Notes

Study notes for CompTIA

Uploaded by

mapsmahlodi8
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
0% found this document useful (0 votes)
14 views26 pages

Study Notes

Study notes for CompTIA

Uploaded by

mapsmahlodi8
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF or read online on Scribd
‘* Software Defined Networking (SDN): © Abstract model divides network functions into control, data, and management planes. © SDN applications define policy decisions on the control plane. © Implemented through APIs interfacing with network devices. © Manages both physical and virtual network appliances. © Supports rapid deployment of virtual networking using NFV. * Cloud Architecture Features: © Data replication, redundancy, and auto-scaling ensure high availability. © Disaster recovery, SLAs, and ISAs are critical for data protection. © Power efficiency, compute capabilities, and ease of deployment enhance cloud infrastructure. * Cloud Security Considerations: © Data protection, patch management, and secure communication are essential. © SD-WAN and SASE provide enhanced security features for cloud environments. © Zero trust security model and IAM are crucial for secure access. Embedded Systems and Zero Trust Architecture SCADA Overview: © SCADA replaces control servers in large-scale ICSs. © Typically runs as software on ordinary computers. © Gathers data from and manages plant devices with embedded PLCs (field devices). © Uses WAN communications like cellular or satellite to link to field devices. ‘* Applications of ICS/SCADA: © Used in energy (power generation, distribution), industrial (mining, refining), fabrication/manufacturing, logistics, and facilities management. © Historically built without strong IT security, but awareness of security importance is increasing. * Security Concerns in ICS/SCADA: © Vulnerable to cyberattacks. © Example: Stuxnet worm targeting Iran's nuclear program, © NIST Special Publication 800-82 provides security control recommendations, ‘* Priorities in Industrial Systems: ©. Safety is paramount. © Prioritize availability and integrity over confidentiality (AIC triad instead of CIA triad). ‘+ Cybersecurity in ICS/SCADA: © Critical for sectors like energy, manufacturing, transportation, and water treatment. © Robust cybersecurity measures like network segmentation, access controls, intrusion detection, and encryption are essential ‘* Internet of Things (loT): © Refers to networked physical devices with sensors and connectivity. © Used in various sectors like smart homes, smart cities, healthcare, agriculture, etc. © Factors driving adoption include decreased sensor costs, advances in connectivity tech, and the COVID-19 pandemic. ‘* Security Risks Associated with loT: © Many devices lack adequate security measures. © Standardization issues make security implementation challenging. © Large volume of data increases the risk of breaches and cyberattacks. ‘© Best Practices for loT Security: © Recommendations from organizations like loTSF, lIC, CSA, and ETSI Zero Trust Architecture (ZTA): © Assumes nothing is trusted by default. © Requires continuous authentication and verification for alll users, devices, and applications. © NIST SP 800-207 defines ZTA and CISA provides a maturity model. Deperimeterization: © Shifts focus from defending network boundaries to protecting individual resources. © Essential due to trends like cloud adoption, remote work, mobile devices, outsourcing, and wireless networks Key Components of Zero Trust Architecture: © Network and endpoint security, IAM, policy-based enforcement, cloud security, network visibility, network segmentation, data protection, and threat detection/prevention. Zero Trust Security Concepts: © Adaptive identity, threat scope reduction, policy-driven access control, and device posture assessment. Control and Data Planes in Zero Trust Models: © Control plane manages policies, while data plane establishes secure sessions. © Separation allows for flexibility and scalability. Zero Trust Architecture Examples’ © Google BeyondCorp, DoD's JEDI cloud, Cisco Zero Trust Architecture, Palo Alto Networks Prisma Access. Explain Resiliency and Site Security Concepts Asset Management Monitoring and Asset Tracking: ‘* Inventory and enumeration tasks involve creating and maintaining a comprehensive list of all assets within an organization, including hardware, software, data, and network equipment. ‘¢ Regularly updating and verifying asset inventory helps organizations manage assets effectively and ensures accurate information about each asset's location, owner, and status. ‘* Asset monitoring includes tracking performance, security, and usage to detect potential issues, vulnerabilities, or unauthorized access promptly. ‘* Proactive asset monitoring helps mitigate risks, optimize resource utilization, and ensure compliance with regulatory requirements. Ways to Perform Asset Enumeration: ‘© Manual Inventory: Feasible for smaller organizations or specific asset types, involves physically inspecting assets and recording relevant information. ‘* Network Scanning: Tools like Nmap, Nessus, or OpenVAS automatically discover and enumerate networked devices, including open ports and services. ‘* Asset Management Software: Solutions like Lansweeper or ManageEngine automatically discover, track, and catalog various assets, providing a centralized dashboard for management. ‘* Configuration Management Database (CMDB): Centralized repository for IT infrastructure information, managed by tools like ServiceNow or BMC Remedy. ‘* Mobile Device Management (MDM) Solutions: Manage mobile assets like smartphones, and tablets using solutions like Microsoft Intune or VMware Workspace ONE. * Cloud Asset Discovery: Cloud-native or third-party tools like AWS Config or CloudAware help discover and catalog assets deployed in the cloud. Asset Acquisition/Procurement: Select hardware and software solutions with strong security features, prioritize reputable vendors providing ongoing support. Integrate solutions seamlessly with existing security infrastructure like firewalls, intrusion detection systems, or SIEM platforms. ‘Assess total cost of ownership (TCO) considering initial purchase price, ongoing costs, and potential security incidents. Prioritize cybersecurity during acquisition to reduce breach risk, enhance compliance, and protect critical data and systems. Asset Protection Concepts: ‘* Assets include critical resources, information, and infrastructure components that must be protected from threats and unauthorized access. * Identify and prioritize assets based on sensitivity and potential impact on core functions if breached. ‘* Use standard naming conventions and configuration management to ensure consistency and manageability. ‘¢ Implement ITIL framework elements for effective configuration management. Data Backups: Essential for ensuring availability and integrity of critical data and systems. Regularly test and verify backup data to ensure reliability of recovery process. Enterprise backup solutions offer scalability, performance, advanced features like data encryption and ransomware protection, and integration with various environments. ‘Snapshot, Replication, and Journalin ‘* Snapshots capture system state at a specific time, useful for VMs, filesystems, and SANs. Replication creates redundant copies of data for availability and recovery. Journaling tracks changes to data for recovery and consistency, useful for filesystems. ‘Advanced techniques like remote journaling, SAN replication, and VM replication enhance data protection across multiple locations and systems, Encrypting Backups: ‘Adds an extra layer of protection against unauthorized access or theft. Ensures compliance with regulations regarding sensitive data protection. Essential for safeguarding sensitive customer data, intellectual property, or trade secrets, Secure Data Destru n and Asset Disposal: ‘* Sanitization and destruction processes remove sensitive information from storage media to prevent unauthorized access. ‘* Certification provides verification of data destruction process compliance with industry standards and regulations, * Active methods like overwriting or physical destruction ensure irrecoverability of data from storage devices. ‘+ Proper disposal of assets at the end of lifecycle or when no longer needed minimizes security risks and ensures compliance. Redundancy Strategies * Site Considerations © Resiliency Provisioning: Site-level resiliency is common in enterprise environments. © Alternate Processing Site: Provides similar service levels and can be always available. © Recovery Site: Used in emergencies, might take longer to set up. © Failover: Technique ensuring redundancy, quickly taking over functionality from failed asset. © Site Resiliency Levels: = Hot Site: Immediate failover, fully operational and updated. = Warm Site: Similar to hot site but requires loading latest data set. = Cold Site: Longer setup time, may be empty building with lease agreement. © Geographic Dispersion: Distributing recovery sites across different locations to minimize regional disaster impact. * Cloud as Disaster Recovery (DR) © Gost Efficiency: Cloud providers offer affordable redundancy due to economies of scale. © Scalability: Cloud services allow redundant capabilities without over- provisioning, © Faster Deployment: Enables quick setup and deployment of redundant Management: Cloud providers offer tools to reduce redundant infrastructure complexity. © Improved Security and Compliance: Cloud providers invest heavily in security and compliance. ‘* Testing Redundancy and High Availability © Load Testing: Validates system performance under expected or peak loads. ©. Failover Testing: Validates seamless transition between primary and secondary infrastructure. © Monitoring Systems Testing: Validates effective detection and response to failures and performance issues. Clustering © Load Balancing vs. Clustering: Load balancing distributes traffic, while clustering allows redundant processing nodes to accept connections. © Active/Passive vs. Active/Active Clustering: Active/passive ensures no performance impact during failover, while active/active utilizes maximum capacity but may degrade performance during failover. Power Redundancy © Dual Power Supplies: Provide redundancy, can be replaced without system shutdown. © Managed Power Distribution Units (PDUs): Support remote power monitoring and integrate with UPSs. © Battery Backups and UPSs: Provide temporary power source during outages. © Generators: Provide backup power for extended periods. Diversity and Defense in Depth © Platform Diversity: Reduces risk by using multiple technologies and platforms, © Defense in Depth: Implements multiple layers of protection against cyber threats. Vendor Diversity © Cybersecurity Benefits: Reduces single point of failure and promotes healthy competition. © Business Ret disruptions. © Innovation and Competition: Encourages innovation and ensures better value for investment ‘Multi-Cloud Strate: © Cybersecurity Benefits: Diversifies risk, improves security posture, and promotes vendor independence. © Business Benefits: Enhances flexibility, agility, and cost efficiency. Deception Technologies © Honeypots, Honeynets, Honeyfiles, and Honeytokens: Cybersecurity tools to detect and defend against attacks by diverting attackers’ attention and gathering intelligence. Disruption Strategies © Active Defense: Uses tactics like bogus DNS entries, web server decoys, and fake telemetry to raise attack cost and tie up adversary's resources. Testing Resiliency © Method of Testing: Tabletop exercises, failover tests, simulations, and parallel processing tests. © Importance of Testing: Identifies vulnerabilities, evaluates recovery strategies, and improves preparedness for real-life incidents. Documentation nce: Mitigates risk associated with vendor lock-in and © Business Continuity Documentation: Covers planning, implementation, and evaluation ©. Test Plans, Scripts, and Results: Provide structure for testing process and communication with stakeholders. © Third-Party Assessments and Certifications: Offer objective evaluation, compliance verification, and recommendations for improvement. Physical Security 1, Fundamental Security Concepts: © Physical security is integral to cybersecurity, protecting physical assets like servers and data centers. Measures include access control, surveillance, and environmental controls. Effective physical security reduces the risk of unauthorized access and insider threats. 2. Physical Security Controls: © Access control mechanisms include biometric scanners, smart cards, and key fobs. © Surveillance systems involve video cameras, motion sensors, and alarms. © Environmental controls like backup power and fire suppression are crucial for data centers, 3. Zone Implementatior © Zones use barriers and security mechanisms to control entry and exit points. © Each zone should have increasingly restrictive access. © Entry points to secure zones should be discreet to prevent inspection by intruders. 4. Physical Security through Environmental Des © Enhances security using non-obvious features in physical spaces. © Promotes safety and deters criminal activity in various settings. 5. Barricades, Fencing, and Lighting: © Barricades channel people through defined entry and exit points. © Security fencing needs to be transparent, robust, and secure against climbing. © Security lighting improves safety and acts as a deterrent at night. 6. Bollards and Existing Structures: © Bollards prevent vehicular access to restricted areas. © Existing structures can be adjusted for improved site layout and security. 7. Gateways, Locks, and Access Control: © Gateways require secure locks, which can be physical, electronic, or biometric. © Access control vestibules regulate entry to secure areas, preventing tailgating. © Access badges replace physical keys and provide access through card readers. 8. Security Guards and Cameras: © Surveillance enhances resilience, with guards providing visual deterrence. © Cameras offer cost-effective monitoring and can use Al for smart security. © Alarms supplement other security controls, detecting and deterring threats effectively. Explain Vulnerability Management Device and OS Vulnerabilities 1, Mobile OS Vulnerabilities: © Android and iOS are primary computing platforms, prone to attacks. © Android's open-source nature leads to similar benefits and problems as Linux. © Fragmentation among manufacturers and versions of Android results in inconsistent patching. © iOS, though not open source, faces significant vulneral 2. Example OS Vulnerabilities: licrosoft Windows: MS08-067 and MS17-010 allowed remote code execution, exploited by Conficker and WannaCry. © _macOS: "Shellshock" vulnerability in Unix-based systems. Android: "Stagefright" vulnerability allowed remote code execution via MMS. iS: Google's Project Zero discovered vulnerabilities used in “watering hole" attacks. © Linux: "Heartbleed” bug compromised OpenSSL cryptographic software. 3. Legacy and End-of-Life Systems: ‘© EOL systems lack vendor support and critical security patches, posing vulnerabilities. © Legacy systems are outdated but may stil receive support. © Notable examples include Windows 7 and Server 2008. 4, Firmware Vulnerabilities: © Meltdown and Spectre vulnerabilities impacted computers and mobile devices. © "LoJax" exploited UEFI firmware. © EOL hardware vulnerabilities arise from discontinued updates, jon Vulneral i © VM escape allows attackers to access host systems. © Examples include "Cloudburst" vulnerability in VMware. © Resource reuse can lead to data leakage between virtual machines. Zero-Day Vulnerabilities: © Previously unknown flaws exploited before developers can fix them © Notable examples include the BEAST and POODLE attacks. © Ethical disclosure aims to limit potential harm, Misconfiguration Vulnerabilities: ‘© Common cause of security vulnerabilities. © Default configurations often prioritize usability over security © Proper configuration and change management are crucial. Cryptographic Vulnerabilities: ‘© Weaknesses in cryptographic systems, algorithms, or protocols. © Examples include MD5, SHA-1, and RSA vulnerabilities. © Proper key generation and protection are essential. 9. Sideloading, Rooting, and Jailbreaking: © Methods to gain elevated privileges on mobile devices. © Introduces security risks, including malware installation and data breaches. © Violates terms of service and voids warranties on some platforms. 10. Mobile Device Vulnerabilities: ‘* Susceptible to common vulnerabilities like insecure Wi-Fi and phishing attacks. ‘* More likely to be lost or stolen, exposing data if unencrypted. 2 st ~ Application and Cloud Vulnerabilities * Malicious Update: © Definition: Update containing harmful code disguised as legitimate. Purpose: Distribution of malware, execution of cyberattacks. Examples: CCleaner compromise (2017), SolarWinds attack (2020). tigation: Secure software supply chain management, digital signature verification. ‘* Evaluation Scops © Definition: Analysis of product, system, or service for vulnerabilities. © Targets: Software application, network, security service, or IT infrastructure. © Goals: Identify weaknesses, ensure compliance with security standards. * TOE Practice Description: © Security Testing: Vulnerability assessments, penetration testing ‘© Documentation Review: Ensure implementation according to secure design principles. ‘Source Code Analysis: Identify security vulnerabilities in code. Configuration Assessment: Evaluate security-related configurations. Cryptographic Analysis: Assess encryption mechanisms and key management. Compliance Verification: Ensure compliance with relevant regulations. © Security Architecture Review: Evaluate security controls and design ‘* Penetration Tester vs. Attacker: © Scope: Defines objectives for penetration tester or attacker. © Penetration Tester: Authorized to evaluate system, report findings, recommend remediation. © Attacker: Aims to exploit vulnerabilities within target for unauthorized access or other malicious objectives. Web Application Attacks: © Definition: Target applications accessible over the Internet. © Characteristics: Exploit poor input validation, misconfigured security settings, outdated software. © Examples: XSS, CSRF, improper session management. Cross-Site Scripting (XSS): © Types: Reflected/nonpersistent, stored/persistent, DOM-based. © Execution: Injects malicious scripts into trusted sites, executed in client's browser. SQL Injection (SQLi): © Exploits: Unsecure handling of SQL queries. © Impact: Unauthorized access to database, data theft, execution of arbitrary code. Cloud-Based Application Attacks: © Targets: Cloud-hosted applications. ‘© Exploits: Misconfigurations, weak authentication, insufficient network segmentation. © Characteristics: Shared responsibility model, scalability attracts attackers. Cloud Access Security Brokers (CASBs): © Definition: Mediate access to cloud services by users. © Functions: Single sign-on authentication, malware scanning, activity monitoring, © Implementation: Forward proxy, reverse proxy, API-based Supply Chain: © Definition: Risks and weaknesses introduced into software products during development, distribution, maintenance. Components: Service providers, hardware suppliers, software providers. Importance: Transparency, visibility, rapid response to vulnerabilities. Tools: OWASP Dependency-Check, SPDX, OWASP CycloneDX standards for SBOM creation. Vulnerability Identification Methods ‘+ Network Vulnerability Scanner © Designed to test network hosts such as client PCs, servers, routers, and switches. © Compares scan results to configuration templates and lists of known vulnerabilities. © Identifies missing patches, deviations from baseline configurations, and related vulnerabilities. © Examples include Tenable Nessus and OpenVAS. ‘* Credentialed vs. Non-Credentialed Scans, © Non-Credentialed Scans: = Test packets directed at hosts without login access. = View obtained is that of an unprivileged user. ‘= Useful for external network perimeter assessment or web application scanning. © Credentialed Scans: = Given user account access with appropriate permissions. = Allows in-depth analysis, especially for detecting misconfigurations. = Mimics insider attacks or compromised user accounts. ion and Web Application Scanners © Specialized for identifying software application weaknesses. © Includes static analysis (reviewing code) and dynamic analysis (testing running applications). © Identifies issues like unvalidated inputs, broken access controls, and SQL injection vulnerabilities. Package Monitoring o Tracks and assesses security of third-party software packages, libraries, and dependencies, © Ensures they are up to date and free from known vulnerabilities. © Associated with software bill of materials (SBOM) and software supply chain risk management. Threat Feeds © Real-time, continuously updated sources of information about potential threats and vulnerabilities. © Integrated into vulnerability management practices for swift response to emerging risks. © Gathered from security vendors, cybersecurity organizations, and open-source intelligence. Open-Source Intelligence (OSINT) © Collects and analyzes publicly available information for decision-making. © Used in cybersecurity to identify vulnerabilities and threat information. © Sources include blogs, forums, social media, and the dark web. Penetration Testing © Aggressive approach to vulnerability management. ©. Involves ethical hacking to breach security and exploit vulnerabil © Identifies complex vulnerabilities that automated tools may miss. Bug Bounties © Incentivizes external security researchers to discover and report vulnerabilities. © Complements penetration testing with a global community of researchers. © Encourages responsible disclosure of verified security issues. Auditing ©. Essential part of vulnerability management. © Includes product audits, system/process audits, and security audits. © Penetration testing is a critical component of technical and compliance audits. Vulnerability Analysis and Remediation Vulnerability Analysis and Remediation ‘* Vulnerability Analysis: © Evaluates vulnerabilities for potential impact and exploitabilty. © Considers factors like ease of exploitation, potential damage, asset value, and current threat landscape. © Helps prioritize remediation efforts by addressing critical vulnerabilities first + Remediation: © Mitigation techniques include patching, configuration changes, software updates, or system replacement. ‘© Compensating controls provide altemative plans when immediate remediation is impossible. © Verification of successful remediation via rescanning affected systems. ‘Common Vulnerabilities and Exposures (CVE) * Vulnerability Feeds: © Updated via SCAP, facilitating sharing of intelligence data. © Consist of common identifiers for vulnerability descriptions. ‘* National Vulnerability Database (NVD) © Maintained by NIST, provides detailed vulnerability information. © Supplements CVE descriptions with additional analysis and CVSS metrics. ‘* CVSS (Common Vulnerability Scoring System) © Generates a score from 0 to 10 based on vulnerability characteristics. © Score bands: 0.1+ (Low), 4.0+ (Medium), 7.0+ (High), 9.0+ (Critical). False Positives, False Negatives, and Log Review «False Positives: © Incorrect identification of vulnerabilities by scanners. © Can lead to unnecessary time and effort if not addressed + False Negatives © Undetected vulnerabilities in scans. © Risk mitigated by periodic rescanning and using scanners from different vendors. * Log Review: © Validates vulnerability reports by examining system and network logs. © Confirms vulnerability alerts and ensures accurate remediation. Vulnerability Analysis © Prioritization: © Identifies critical vulnerabilities for focused remediation efforts, * Classification: © Categorizes vulnerabilities based on characteristics for clarity. Exposure Factor: © Assesses susceptibility of assets to specific vulnerabilities. Impacts: © Evaluates potential organizational impact for informed decision-making. Environmental Variables: © Includes IT infrastructure, extemal threat landscape, regulatory environment, and operational practices. Vulnerability Response and Remediat ‘+ Remediation Practices: © Patching, cybersecurity insurance, segmentation, compensating controls, exceptions, and exemptions. * Validation: © Ensures remediation actions are implemented correctly and do not introduce new vulnerabilities. * Reporting: © Highlights existing vulnerabilities, ranks based on severity, provides recommendations, and emphasizes timely reporting for effective remediation. Evaluate Network Security Capabilities Network Security Baselines Hardening Concepts: ‘* Default settings in network equipment, software, and operating systems balance ease of use with security ‘* Default configurations are often targeted by attackers due to well-documented. credentials, insecure protocols, etc. ‘* Hardening involves changing default settings to enhance security, typically following published secure baselines. Switches and Routers Hardening: Change default credentials to mitigate security risks, Disable unnecessary services like HTTP or Telnet to reduce attack surface. Use secure management protocols like SSH instead of Telnet. Implement Access Control Lists (ACLs) to restrict access. Enable logging and monitoring to identify security issues. Configure port security to limit device connections. Implement strong password policies. Physically secure equipment to prevent unauthorized access. Server Hardware and Operating Systems Hardening: Change default credentials to prevent unauthorized access. Disable unnecessary services to reduce attack surface Apply software security patches and updates regularly. Implement the least privilege principle. Use firewalls and Intrusion Detection Systems (IDS) to block or alert on malicious activity. ‘Secure configurations using baseline configurations like CIS or STIGs. Implement strong access controls like strong password policies, MFA, and PAM Enable logging and monitoring for identifying security issues. Use antivirus and antimalware solutions to detect and quarantine malware. Physically secure server equipment to prevent unauthorized access. Wireless Network Installation Considerations: Ensure good coverage of authorized Wi-Fi access points to prevent rogue and evil twin attacks. Use nonoverlapping channels in the § GHz band for better performance. Conduct site surveys to measure signal strength and interference. Use heat maps to optimize WAP placement and configuration. Configure wireless encryption settings to secure the network. Consider vulnerabilities and limitations of Wi-Fi Protected Setup (WPS). Utilize Wi-Fi Protected Access 3 (WPA3) for improved security \uthentication Methods: Personal, open, and enterprise authentication types. WPA2-PSK and WPA3-SAE for personal authentication WPA3 enhances security over WPA2, particularly with SAE protocol. Enterprise authentication involves 802.1%, EAP methods, and RADIUS. Network Access Control (NAC): Authenticates users and devices, enforces compliance with security policies. Restricts access based on user profile, device type, location, etc. Works with VLANs to automate seourity measures. NAC can be agent-based or agentless, each with its advantages and limitations. Network Security Capability Enhancement Network Security Capability Enhancement: Firewalls, IDS, IPS, and web filters are essential components in network security Firewalls create a barrier between trusted internal networks and untrusted external networks, controlling incoming and outgoing traffic based on rules. IDS monitor network traffic for possible incidents and alert administrators. IPS not only detect but also prevent threats by taking automated actions like blocking traffic. ‘© Web filters control access to Internet content, preventing access to malicious websites and monitoring access to restricted sites. Access Control Lists (ACL): ‘* ACLs control traffic at a network interface level using packet information like source/destination IP addresses, port numbers, and protocols. ‘* Firewall rules dictate how firewalls handle inbound/outbound traffic based on IP addresses, port numbers, protocols, or application traffic patterns. Rules in a firewall's ACL are processed from top to bottom; specific rules are placed at the top, and a default deny rule is typically at the end. Basic principles include blocking internal/private IP addresses, protocols for local network level, penetration testing, and securing hardware. Screened Subnet: ‘Acts as a neutral zone between an organization's internal network and the Internet, separating public-facing servers from sensitive internal resources. Hosts web, email, DNS, or FTP services accessible from the Intemet but isolated from internal systems to limit damage from breaches. Firewalls control traffic to/from the screened subnet, providing an additional layer of protection. Intrusion Detection and Prevention Systems (IDS/IPS): IDS/IPS monitor network traffic for suspicious pattems or activities. Host-based (HIDS/HIPS) installed on individual systems detect insider threats, file changes, and local events. Network-based (NIDS/NIPS) monitor network traffic for known threats and unusual behavior across multiple systems. IDSAPS Tools: Snort and Suricata are well-known IDS/IPS tools. ‘Security Onion provides intrusion detection, network security monitoring, and log management. ‘These tools use signature-based, behavioral/anomaly-based, and trend analysis detection methods. Web Filtering: Web filters block access to malicious or inappropriate websites, preventing malware infections and increasing productivity. Agent-based filtering installs software agents on devices, enforcing filtering policies locally Centralized web filtering uses proxy servers to analyze and control web traffic, implementing block rules, content categorization, and reputation-based filtering Issues include overblocking, underblocking, handling of encrypted traffic, and privacy ‘concerns. Proper configuration and management are essential. Assess Endpoint Security Capabilities Implement Endpoint Security ACLs and File System Permissions: ACLs manage access control policies for files and directories. Each object in the file system has an ACL associated with it. ACLs contain a list of allowed accounts and their permissions. Permissions include Read (r), Write (w), and Execute (x), Permissions are applied based on owner user (u), group (q), and others (0) Commands like chmod modify permissions using symbolic or absolute mode. Application Allow Lists and Block Lists: ‘* Allow lists permit execution only for approved applications. ‘* Block lists prohibit execution of listed processes. ‘* Lists need regular updates based on incidents and threat hunting. ‘* Strategic changes may be necessary based on threat analysis. Monitoring: ‘* Monitoring enforces and maintains security measures on endpoints. ‘* Helps detect changes that weaken security configurations. ‘* Provides data for compliance and auditing purposes. Configuration Enforcement: ‘* Ensures systems adhere to mandatory security configurations. ‘* Involves standardized configuration baselines, automated management tools, continuous monitoring, and change management processes. Group Policy: ‘* Centralized management of Windows OS settings in an Active Directory environment. ‘Applies security settings consistently across systems. ‘* Settings include password policies, firewall settings, software restrictions, etc. SELinux: ‘* Security feature in Linux supporting access control security policies. ‘* Offers granular permission control over processes and system objects. «Limits resource access to prevent harm from malicious or flawed programs. Hardening Techniques: ‘* Protects endpoints against evolving cybersecurity threats. ‘* Strategies include physical port hardening, logical port security, encryption, and host- based firewalls/IPS. Instal 1g Endpoint Protecti ‘* Involves strategic planning, standardized configurations, automated deployments, updates, monitoring, and centralized management. ‘Changing Defaults and Removing Unnecessary Software: ‘* Crucial steps in hardening endpoints. ‘* Changing default passwords and removing unnecessary software reduces vulnerabilities. Decommissioning: ‘* Secure process for retiring devices to prevent data exposure. ‘* Involves data sanitization, resetting to factory settings, and updating inventory records. Hardening Specialized Devices: ‘* Unique hardening strategies for industrial control systems, embedded systems, real-time operating systems, and loT devices. ‘* Involves network segmentation, authentication, secure coding, and compliance with security standards and certifications. Mobile Device Hardening 4, Mobile Device Deployment Models: Corporate owned, business only (COBO): Device owned by organization, strictly for business use. Corporate owned, personally enabled (COPE): Device provided by organization, allows personal use within policy limits. Choose your own device (CYOD): Employees select devices from a predetermined list. Each model balances contol, flexibility, and security differently. COBO offers more control but higher equipment spending; BYOD offers flexibility but security challenges. 2. Mobile Device Management (MDM): © Crucial for managing, securing, and enforcing policies on smartphones and tablets © Maintains device inventory, ensures authorized access, enforces security policies, and enables remote lock or wipe. Manages device updates, patches, app distributions, and other tasks. Various platforms available: Apple's MDM, Android Enterprise, Microsoft Intune, VMware AirWatch, IBM MaaS360. 3. Full Device Encryption and External Media: Most mobile OSes offer full device encryption. © iOS offers multiple encryption levels, including Data Protection for sensitive data. © Android encrypts user data at the file level by default (since Android 10). Care should be taken with external media (MicroSD cards) to apply encryption where necessary. 4. Location Services: © Utilizes GPS or Indoor Positioning System (IPS) for device location. © Privacy concems arise due to tracking potential; apps require user permission. © Geofencing creates virtual boundaries; can be used for context-aware authentication. 5. Connection Methods (Cellular, Wi-Fi, Bluetooth): © Cellular connections bypass enterprise network protections; require endpoint controls. © WiFi risks from open access points or rogue networks; strong WPA3 security recommended. © Bluetooth vulnerabilities include device discovery, authentication issues, malware, and bluejacking/bluesnarfing, © NFC for short-range communication and mobile payments; vulnerable to eavesdropping, interception, and data corruption attacks. Enhance Application Security Capabilities Application Protocol Security Baselines ‘+ Secure Directory Services: © Network directory lists subjects (users, computers, services) and objects (directories, files) with permissions. © Most use Lightweight Directory Access Protocol (LDAP) over port 389. © Authentication methods: ‘= No Authentication: Anonymous access. = Simple Bind: Plaintext DN and password. = SASL: Negotiates supported authentication mechanisms, = LDAPS: Uses digital certificate for secure tunnel on port 636. © Limit access: Disable anonymous and simple authentication if secure access is required. © Access control policy for read-only and read/write access. © Restrict access to private network; block LDAP port from public interface. ‘Simple Network Management Protocol Security (SNMP): © Framework for management and monitoring. © Agent maintains Management Information Base (MIB); communicates over ports, 161 (queries) and 162 (traps). © SNMP Monitor oversees agents, polls them for info, alerts for traps. © Security measures: Disable if not used, use difficull-to-guess community names, restrict management operations, use SNMP v3 for encryption and strong authentication, File Transfer Services: © FTP remains popular despite newer protocols. © FTP lacks security mechanisms, vulnerable to interception. © SSH FTP (SFTP) and FTP Over SSL (FTPS) provide encryption. © SFTP uses SSH over port 22; FTPS uses TLS over ports 21 (explicit) and 990 (implicit). Email Services: © SMTP for sending: mailbox protocol (POP3, IMAP) for storing/accessing. Secure SMTP (SMTPS) and Secure POP (POP3S) use TLS. ‘Secure IMAP (IMAPS) allows permanent connections and folder management. © Email Security = SPF, DKIM, DMARC authenticate senders, prevent phishing and spam. = Email Gateway scrutinizes emails, utiizes anti-spam filters, antivirus scanners, DMARC, SPF, DKIM. = S/MIME encrypts and authenticates email communications. = Email Data Loss Prevention (DLP) prevents unauthorized sharing of sensitive information. DNS Filtering: © Blocks or allows access to specific websites by controlling DNS resolution. © Proactive defense mechanism against phishing sites, malware, and inappropriate content. © Implemented through DNS filtering services, DNS servers, DNS firewalls, or local DNS resolvers. DNS Security: © Configure DNS servers for fault tolerance, restrict recursive queries to local hosts. ©. Patch DNS server software regularly to mitigate vulnerabilities. © Prevent DNS footprinting by applying access control lists to prevent unauthorized zone transfers. © DNSSEC provides validation process for DNS responses, mitigates spoofing and poisoning attacks. Cloud and Web Application Security Concepts Concepts: ‘* Cloud and web application security involve: © Cloud hardening: fortifies cloud infrastructure, reduces attack surface. © Application security: ensures secure design, development, deployment. ‘* Both practices establish a layered defense strategy against various threats. ‘* Secure coding practices include: © Input validation techniques.

You might also like