0% found this document useful (0 votes)
9 views10 pages

Security+ Overview: Controls & Threats

The document covers various aspects of cybersecurity, including types and categories of security controls (technical, managerial, operational, and physical), foundational security concepts such as CIA, non-repudiation, and zero-trust, as well as the importance of change management and encryption methods. It also discusses different threat actors, their motivations, and the significance of classifying threats to enhance security measures. Additionally, it highlights the role of vulnerability research in maintaining robust cybersecurity practices.

Uploaded by

khanmazen739
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
9 views10 pages

Security+ Overview: Controls & Threats

The document covers various aspects of cybersecurity, including types and categories of security controls (technical, managerial, operational, and physical), foundational security concepts such as CIA, non-repudiation, and zero-trust, as well as the importance of change management and encryption methods. It also discusses different threat actors, their motivations, and the significance of classifying threats to enhance security measures. Additionally, it highlights the role of vulnerability research in maintaining robust cybersecurity practices.

Uploaded by

khanmazen739
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CompTIA Security+ (SY0-701)

Identify Types and Categories of Security Controls

Security Controls Overview


Security controls can be loosely grouped by category (how the control is implemented) and
by type (why the control is implemented). In this video, we take a closer look at both.

Security Control Category: Technical Controls


Let's look at the types of controls that may fall into the category of technical controls.

Security Control Category: Managerial Controls


Managerial controls are primarily the policies and procedures that are used to implement
security.

Security Control Category: Operational Controls


Operational controls are implemented by humans in their day-to-day operations.

Security Control Category: Physical Controls


Physical controls are physical, and depending on why they are implemented, they would
fall into the different "types" of physical controls.

Que : list the 5 types of security controls for each category.


Summarize Foundation of Security Concepts

CIA
Acronyms can help us remember words, phrases, and or concepts. CIA is one of those
acronyms. In this video, we look at what that means in the security world.

Non-repudiation
Non-repudiation verifies authenticity and establishes accountability. Digital signatures are
one way to achieve non-repudiation.

AAA
This acronym can help us remember essential components regarding security, specifically
authentication, identifying who an individual or system is; authorization, what they are
permitted to do; and accounting, what they did.

Zero-Trust and Gap Analysis


Ideally, every user and system should be verified, with appropriate access controls for
providing access. That is an example of zero-trust.

Physical Security
Physical security has been, and continues to be, one of the essential elements for
protecting our systems, users, and other assets.

Deception and Disruption Technologies


Using a trap, such as a honeypot, can help identify an attacker or hacker attempting to
compromise our security.
Maintain Security With Change Management

Change Management Overview


In this video, we take a big-picture look at the world of Change Management/Change
Control with an eye toward security.

Business Processes Impacting Security Operation


Having a list of items to consider can help us ensure success in change control.

Technical Implications and Documentation


Some changes may need to be made due to technical implications. In this video, we look
closely at some of those implications

Practical Example for Change Control


In this video, we look at change control using a practical example.
Use Symmetrical Encryption

Symmetric Encryption Overview


Symmetric encryption algorithms, such as AES and the older DES and 3DES, use a single
key to encrypt and decrypt data. The key holder can make sense of the encrypted data,
while individuals or systems without the key are kept from seeing the plain text data.

Use Asymmetrical Encryption

Using Digital Signatures


Use Certificates and PKI

PKI and Certs Overview


A Certificate Authority (CA) is a trusted entity that issues digital certificates. The CA
verifies the identity of an entity requesting a certificate and then issues the certificate to
confirm that identity.
Digital Certificates are electronic credentials that confirm the identity of entities such as
individuals, organizations, or websites. In the digital world, they can be compared to
driver's licenses or passports. A digital certificate issued and digitally signed by a trusted
CA can be verified by any other device that also trusts the issuing CA.
PKI uses two cryptographic keys: a public key and a private key. The public key is shared
with any device needing it, while the owner keeps the private key secret. These keys are
used in encryption and decryption processes.
Sometimes, revoking a certificate (such as when a private key is compromised) may be
necessary. PKI provides mechanisms for revoking certificates.

Self Signed Certs


Self-signed certificates are commonly used with newly deployed devices until a CA-issued
(Internal CA or Public CA) certificate is issued.
Most web browsers and operating systems do not inherently trust self-signed certificates,
so users will receive a warning message when they encounter one.

Adding an Internal CA to as a Trusted CA


When using a private or internal CA service within the company that will issue certificates
to devices, it is important that the devices in that company also trust the Internal CA so
that those same clients can verify the signature and trust the certificates issued by the
internal CA.
Using a CSR for Requesting a Certificate
A CSR, or Certificate Signing Request, is used to obtain a digital certificate from a
Certificate Authority (CA). It's a formal request sent to a CA for the issuance of a digital
certificate.
The CSR can include the organization's name, domain name, locality, country, and other
related details. This information forms part of the digital certificate, helping others identify
the certificate's owner.
The CSR includes the public key that will be contained in the digital certificate. The CA
does not receive the private key; it only gets the public key.
Threat Actors and Motivations

Let's compare common themes in cybersecurity threats


Being a security technician for our organization requires us to have a full understanding of
what goes into an attack or cybersecurity threat. But we don't know what we don't know,
you know?
In this skill, we take a look at the general cybersecurity threat and what goes behind it as
we make our way into more details concerning prevention.

Who are the attackers?

Script Kiddies
• Lack of Technical Expertise: Script kiddies are individuals with limited or no
programming skills who rely on pre-written scripts or tools developed by more
skilled hackers.
• Motivated by Mischief: They are often motivated by a desire for mischief or to
prove their abilities, rather than having specific goals or objectives.
• Minimal Understanding of Cybersecurity: Script kiddies typically have a limited
understanding of cybersecurity principles and often engage in hacking activities
without a deep comprehension of the underlying technologies or systems.
Hacktivists
• Hacktivists are individuals or groups who engage in hacking activities for the
purpose of promoting social or political causes. The term is a combination of
"hacking" and "activism."
• Motivations: The primary motivation of hacktivists is to advance a specific social or
political agenda. They often target organizations or entities that they perceive as
opposing their beliefs, using digital means to raise awareness or protest against
issues they find objectionable.
• Methods: Hacktivists use various hacking techniques to gain unauthorized access to
computer systems, networks, or websites. They may deface websites, leak sensitive
information, or disrupt online services to draw attention to their cause.
Organized Crime hackers
• Organized crime hackers operate within criminal organizations or networks,
leveraging sophisticated techniques to carry out cybercrimes for financial gain.
• They often target individuals, businesses, or institutions to steal sensitive
information, commit fraud, or engage in other illicit activities such as ransomware
attacks.
• These hackers may collaborate with other criminal elements, using advanced tools
and methods to exploit vulnerabilities in computer systems and networks for their
criminal pursuits.
Nation State Actors
• Nation-state hackers are individuals or groups who operate with the support,
sponsorship, or direction of a specific nation-state or government.
• Their primary objectives often include conducting cyber espionage to gather
intelligence, steal sensitive information, or engage in activities that serve the
strategic interests of their sponsoring nation.
• Nation-state hackers are known for employing sophisticated and advanced hacking
techniques, tools, and strategies to achieve their goals. They may target government
agencies, critical infrastructure, businesses, or individuals to fulfill their mission.

What information do we use to classify threats?


Classifying cybersecurity threats provides a strategic advantage in safeguarding digital
landscapes by offering a systematic approach to understanding and addressing potential
risks. By categorizing threats, organizations can tailor their defense mechanisms to specific
types of attacks, allowing for more efficient allocation of resources.
This classification aids in the identification of patterns and trends, enabling proactive
measures to be implemented against emerging threats. Additionally, it facilitates
information sharing within the cybersecurity community, fostering collaboration and
collective defense.
Zero-day vulnerabilities are unknown weaknesses in software or hardware. Developers
are unaware, so there's no official solution or patch. Cyber attackers use these flaws for
precise and often advanced attacks.
Known vulnerabilities are recognized flaws in software or hardware. Developers are
aware, and solutions or patches are available. As the vulnerabilities are known, security
measures can be implemented, reducing the risk of exploitation.
Where do we gain information on target systems?
Any IT system within our organization is a target. And for the purposes of this skill, we
need to assume that every system is on some sort of "hacker hit list". The attacker is going
to work their best to retrieve information about our systems. This information is then used
to find possible vulnerabilities that may be open to exploitation.
This is where the practice of Active Defense comes into play. We're going to be looking
for the same information on all of our systems in an effort to patch or block these
vulnerabilities from being exploited.

With all this information, what do we do with it?


Incorporating vulnerability research information is crucial for establishing robust
cybersecurity practices. By staying informed about identified vulnerabilities in software,
systems, or networks, organizations can proactively address potential weaknesses before
they are exploited by malicious actors.
This proactive approach allows for the timely application of patches, updates, and security
measures, minimizing the risk of cyber attacks and unauthorized access. Continuous
monitoring and integration of vulnerability research insights enable organizations to
enhance their overall security posture, protect sensitive data, and maintain the trust of
users and stakeholders.
Vulnerability research information involves collaboration with different categories of
attackers: black hat, gray hat, and white hat.
• Unauthorized attackers or Black hat identify vulnerabilities for malicious
purposes, emphasizing the urgency for organizations to stay ahead in securing their
systems.
• Semi-authorized attackers or Gray hat may discover vulnerabilities and disclose
them responsibly, offering valuable insights for improvement.
• Authorized attackers or White hat, often security professionals, play a critical
role by actively seeking and fixing vulnerabilities to enhance overall cybersecurity.
Ultimately, leveraging this information is instrumental in creating a resilient cybersecurity
framework that adapts to emerging threats and ensures the ongoing integrity and
confidentiality of digital assets.

Common questions

Powered by AI

Symmetrical encryption uses a single key for both encrypting and decrypting data, making it efficient for bulk data encryption due to its lower computational requirements. It is commonly used for securing data at rest and in transit in environments where both parties can securely share the same key . In contrast, asymmetrical encryption requires a pair of cryptographic keys (public and private) for encryption and decryption. This method excels in situations where secure key exchange is needed over unsecured channels, like digital certificates and SSL/TLS communications, providing mechanisms for secure identity verification and digital signatures .

Non-repudiation is crucial in cybersecurity as it verifies the authenticity of communications and actions, ensuring accountability by preventing entities from denying previous commitments or actions. Digital signatures play a key role in achieving non-repudiation by providing a verifiable and secure means of verifying the identity of the sender and ensuring that the message transmitted has not been altered. They use asymmetrical encryption, wherein a private key generates the signature, and a public key is used for verification, providing assurance of the sender's identity and the message's integrity .

Classifying threat actors, such as script kiddies, hacktivists, organized crime groups, and nation-state actors, allows organizations to tailor and prioritize their security measures based on the specific types of threats they face. Recognizing the capabilities and motivations of each threat actor type enables organizations to allocate resources efficiently, emphasizing higher security investments on protecting against sophisticated threats like nation-state actors or organized crime, which employ advanced tools and methods . Tailored defenses help in mitigating specific risks, enhancing resilience against potential attacks, and conserving resources by focusing on the most critical and plausible threats .

A Certificate Signing Request (CSR) is a formal request sent to a Certificate Authority (CA) for the issuance of a digital certificate. It includes crucial information such as the organization's name, domain name, locality, and public key, which will be included in the digital certificate to authenticate the certificate owner . The CSR is critical to ensure the certificate is appropriately linked to the correct entity, and only the public key is provided to the CA to protect the private key while allowing others to verify the identity and integrity of signed communications .

Hacktivists are motivated primarily by the desire to promote social or political causes. They use hacking as a form of activism to target organizations or entities they believe oppose their beliefs, often employing methods such as website defacement or data leaks to raise awareness and protest against issues they find objectionable . In contrast, nation-state hackers operate under the sponsorship or direction of a government and focus on strategic objectives such as cyber espionage to gather intelligence or steal sensitive information to serve national interests. Nation-state actors are known for using sophisticated techniques and may target government agencies, businesses, or critical infrastructure .

The zero-trust model assumes that threats can come from both inside and outside the network, unlike traditional models which often rely on trusted network zones. In zero-trust, every user and system must be validated and authenticated regardless of their location within the network . This model enhances security by limiting access to resources strictly to verified and authorized users, thereby reducing the risk of internal and external breaches. However, challenges include increased complexity in managing and maintaining constant authentication and authorization processes, as well as potential impacts on user experience and system performance due to continuous validation .

Deception technologies like honeypots are employed as decoy systems to attract attackers, providing early detection of unauthorized access attempts and insights into attacker behavior and tactics . By identifying attackers, honeypots can help in formulating defensive strategies and preventing attacks on actual systems by diverting them. However, risks include potential exposure of false vulnerabilities to attackers, which may reveal network configurations or vulnerabilities if not adequately isolated. There's also a risk of attackers using honeypots to practice or develop more advanced techniques that could be applied elsewhere .

A Certificate Authority (CA) is a trusted entity in PKI responsible for issuing digital certificates that authenticate the identity of entities such as individuals or websites. The CA verifies the identity of the entity requesting a certificate and then issues the certificate, which contains the public key and other identity-related information, ensuring trust in digital communications . By digitally signing the certificates, CAs provide a tamper-proof means of establishing and maintaining trust between parties in electronic transactions, as other systems and users can verify this signature .

Self-signed certificates can be beneficial in environments requiring immediate deployment without waiting for a CA-issued certificate, offering cost savings as no third-party verification is required. Moreover, they are handy for internal communications within controlled environments . However, the downsides include a lack of inherent trust from browsers and operating systems, which often show warning messages when self-signed certificates are used. This can lead to security risks, as users may not trust the connection, and attackers could potentially exploit these warnings to conduct man-in-the-middle attacks. CA-issued certificates provide a higher trust level as they are verified by a trusted entity, thus enhancing security in web communications .

The CIA triad is a cornerstone of cybersecurity principles. Confidentiality ensures that sensitive information is accessible only to authorized users, thus protecting against unauthorized access . Integrity involves maintaining the accuracy and reliability of data over its lifecycle, protecting it from unauthorized alterations. Availability ensures that information and critical resources are accessible to authorized users when needed, preventing disruptions in service availability. These principles guide the design and implementation of security measures by highlighting the need to protect data from unauthorized access, tampering, or loss, shaping policies and technologies that maintain security and business continuity .

You might also like