Introduction |
|
xxvii | |
Chapter 1 Applying Environmental Reconnaissance Techniques |
|
3 | (34) |
|
"Do I Know This Already?" Quiz |
|
|
3 | (2) |
|
|
5 | (1) |
|
|
5 | (6) |
|
|
5 | (1) |
|
|
5 | (1) |
|
|
6 | (1) |
|
|
6 | (1) |
|
|
6 | (1) |
|
Router/Firewall ACLs Review |
|
|
6 | (1) |
|
|
7 | (1) |
|
|
7 | (1) |
|
|
8 | (1) |
|
|
8 | (3) |
|
|
11 | (5) |
|
|
11 | (1) |
|
|
12 | (1) |
|
|
13 | (1) |
|
|
14 | (1) |
|
|
15 | (1) |
|
|
16 | (15) |
|
|
16 | (3) |
|
|
19 | (1) |
|
|
20 | (1) |
|
|
21 | (2) |
|
|
23 | (2) |
|
|
25 | (2) |
|
|
27 | (1) |
|
Firewall Rule-Based and Logs |
|
|
27 | (3) |
|
|
27 | (2) |
|
|
29 | (1) |
|
|
30 | (1) |
|
|
30 | (1) |
|
|
31 | (1) |
|
|
31 | (1) |
|
|
32 | (1) |
|
|
32 | (5) |
Chapter 2 Analyzing the Results of Network Reconnaissance |
|
37 | (32) |
|
"Do I Know This Already?" Quiz |
|
|
37 | (3) |
|
|
40 | (1) |
|
Point-in-Time Data Analysis |
|
|
40 | (5) |
|
|
40 | (1) |
|
|
40 | (1) |
|
|
40 | (1) |
|
|
41 | (2) |
|
|
43 | (2) |
|
|
43 | (2) |
|
Data Correlation and Analytics |
|
|
45 | (2) |
|
|
45 | (1) |
|
|
46 | (1) |
|
|
46 | (1) |
|
|
46 | (1) |
|
|
47 | (1) |
|
|
47 | (10) |
|
|
47 | (2) |
|
|
49 | (3) |
|
|
52 | (1) |
|
|
52 | (1) |
|
|
53 | (2) |
|
|
55 | (1) |
|
|
56 | (1) |
|
|
57 | (5) |
|
|
57 | (2) |
|
|
59 | (1) |
|
|
60 | (1) |
|
|
61 | (1) |
|
|
61 | (1) |
|
|
62 | (1) |
|
|
62 | (1) |
|
|
63 | (1) |
|
|
63 | (6) |
Chapter 3 Recommending and Implementing the Appropriate Response and Countermeasure |
|
69 | (26) |
|
"Do I Know This Already?" Quiz |
|
|
69 | (3) |
|
|
72 | (1) |
|
|
72 | (5) |
|
|
72 | (1) |
|
|
72 | (1) |
|
|
72 | (1) |
|
|
73 | (1) |
|
|
73 | (2) |
|
|
75 | (1) |
|
|
76 | (1) |
|
|
77 | (1) |
|
|
77 | (1) |
|
|
78 | (2) |
|
|
80 | (2) |
|
|
81 | (1) |
|
|
82 | (4) |
|
Mandatory Access Control (MAC) |
|
|
82 | (1) |
|
|
83 | (3) |
|
|
83 | (1) |
|
|
84 | (1) |
|
Administrative (Management) Controls |
|
|
85 | (1) |
|
Logical (Technical) Controls |
|
|
85 | (1) |
|
|
85 | (1) |
|
Blocking Unused Ports/Services |
|
|
86 | (1) |
|
|
86 | (1) |
|
|
86 | (4) |
|
|
88 | (1) |
|
Agent-Based vs. Agentless NAC |
|
|
88 | (1) |
|
|
88 | (2) |
|
|
90 | (1) |
|
|
90 | (1) |
|
|
91 | (1) |
|
|
91 | (4) |
Chapter 4 Practices Used to Secure a Corporate Environment |
|
95 | (18) |
|
"Do I Know This Already?" Quiz |
|
|
95 | (3) |
|
|
98 | (1) |
|
|
98 | (3) |
|
|
100 | (1) |
|
|
101 | (4) |
|
|
101 | (2) |
|
|
103 | (1) |
|
|
104 | (1) |
|
|
105 | (1) |
|
|
106 | (1) |
|
Technical Impact and Likelihood |
|
|
106 | (1) |
|
|
107 | (1) |
|
Operational Control Review |
|
|
107 | (1) |
|
|
107 | (1) |
|
|
108 | (1) |
|
|
108 | (1) |
|
|
108 | (5) |
Chapter 5 Implementing an Information Security Vulnerability Management Process |
|
113 | (28) |
|
"Do I Know This Already?" Quiz |
|
|
113 | (4) |
|
|
117 | (1) |
|
Identification of Requirements |
|
|
117 | (3) |
|
|
117 | (2) |
|
|
119 | (1) |
|
|
119 | (1) |
|
|
120 | (1) |
|
Establish Scanning Frequency |
|
|
120 | (2) |
|
|
120 | (1) |
|
|
121 | (1) |
|
|
121 | (1) |
|
|
121 | (1) |
|
Configure Tools to Perform Scans According to Specification |
|
|
122 | (9) |
|
Determine Scanning Criteria |
|
|
122 | (6) |
|
|
122 | (1) |
|
|
123 | (1) |
|
|
123 | (2) |
|
Credentialed vs. Non-credentialed |
|
|
125 | (1) |
|
|
126 | (1) |
|
Server-Based vs. Agent-Based |
|
|
126 | (2) |
|
|
128 | (3) |
|
|
128 | (3) |
|
|
131 | (1) |
|
|
131 | (2) |
|
|
132 | (1) |
|
Automated vs. Manual Distribution |
|
|
132 | (1) |
|
|
133 | (2) |
|
|
133 | (1) |
|
|
134 | (1) |
|
Difficulty of Implementation |
|
|
134 | (1) |
|
Communication/Change Control |
|
|
134 | (1) |
|
|
134 | (1) |
|
Inhibitors to Remediation |
|
|
134 | (9) |
|
|
134 | (1) |
|
|
135 | (1) |
|
Organizational Governance |
|
|
135 | (1) |
|
Business Process Interruption |
|
|
135 | (1) |
|
|
135 | (1) |
|
Ongoing Scanning and Continuous Monitoring |
|
|
135 | (1) |
|
|
136 | (1) |
|
|
136 | (1) |
|
|
136 | (1) |
|
|
137 | (4) |
Chapter 6 Analyzing Scan Output and Identifying Common Vulnerabilities |
|
141 | (46) |
|
"Do I Know This Already?" Quiz |
|
|
141 | (2) |
|
|
143 | (1) |
|
Analyzing Output Resulting from a Vulnerability Scan |
|
|
143 | (5) |
|
Analyze Reports from a Vulnerability Scan |
|
|
143 | (4) |
|
Review and Interpret Scan Remits |
|
|
145 | (2) |
|
Validate Results and Correlate Other Data Points |
|
|
147 | (1) |
|
Common Vulnerabilities Found in Targets Within an Organization |
|
|
148 | (32) |
|
|
148 | (13) |
|
|
149 | (11) |
|
|
160 | (1) |
|
|
161 | (1) |
|
|
162 | (7) |
|
|
163 | (1) |
|
|
164 | (1) |
|
|
164 | (1) |
|
|
165 | (3) |
|
|
168 | (1) |
|
|
169 | (1) |
|
|
169 | (4) |
|
|
169 | (1) |
|
|
170 | (1) |
|
|
171 | (2) |
|
|
173 | (1) |
|
|
174 | (1) |
|
|
175 | (4) |
|
Industrial Control Systems/SCADA Devices |
|
|
179 | (1) |
|
|
180 | (1) |
|
|
181 | (1) |
|
|
182 | (1) |
|
|
182 | (5) |
Chapter 7 Identifying Incident Impact and Assembling a Forensic Toolkit |
|
187 | (26) |
|
"Do I Know This Already?" Quiz |
|
|
187 | (2) |
|
|
189 | (1) |
|
|
189 | (2) |
|
Known Threats vs. Unknown Threats |
|
|
190 | (1) |
|
|
190 | (1) |
|
Advanced Persistent Threat |
|
|
191 | (1) |
|
Factors Contributing to Incident Severity and Prioritization |
|
|
191 | (10) |
|
|
191 | (3) |
|
Downtime and Recovery Time |
|
|
191 | (2) |
|
|
193 | (1) |
|
|
193 | (1) |
|
System Process Criticality |
|
|
193 | (1) |
|
|
194 | (7) |
|
Personally Identifiable Information (PII) |
|
|
194 | (1) |
|
Personal Health Information (PHI) |
|
|
195 | (1) |
|
|
195 | (2) |
|
|
197 | (2) |
|
|
199 | (2) |
|
|
201 | (5) |
|
Digital Forensics Workstation |
|
|
202 | (4) |
|
Forensic Investigation Suite |
|
|
206 | (2) |
|
|
208 | (1) |
|
|
208 | (1) |
|
|
208 | (1) |
|
|
209 | (4) |
Chapter 8 The Incident Response Process |
|
213 | (24) |
|
"Do I Know This Already?" Quiz |
|
|
213 | (3) |
|
|
216 | (1) |
|
|
216 | (1) |
|
|
216 | (1) |
|
|
217 | (1) |
|
|
217 | (1) |
|
|
217 | (1) |
|
Purpose of Communication Processes |
|
|
217 | (1) |
|
Limit Communication to Trusted Parties |
|
|
218 | (1) |
|
Disclosure Based on Regulatory/Legislative Requirements |
|
|
218 | (1) |
|
Prevent Inadvertent Release of Information |
|
|
218 | (1) |
|
Secure Method of Communication |
|
|
218 | (1) |
|
Role-Based Responsibilities |
|
|
218 | (2) |
|
|
219 | (1) |
|
|
219 | (1) |
|
|
219 | (1) |
|
Retain Incident Response Provider |
|
|
220 | (1) |
|
Using Common Symptoms to Select the Best Course of Action to Support Incident Response |
|
|
220 | (12) |
|
Common Network-Related Symptoms |
|
|
220 | (5) |
|
|
221 | (1) |
|
|
221 | (1) |
|
Irregular Peer-to-Peer Communication |
|
|
222 | (1) |
|
Rogue Devices on the Network |
|
|
223 | (1) |
|
|
224 | (1) |
|
|
225 | (1) |
|
Common Host-Related Symptoms |
|
|
225 | (5) |
|
|
226 | (1) |
|
|
227 | (1) |
|
Drive Capacity Consumption |
|
|
227 | (1) |
|
|
228 | (1) |
|
|
229 | (1) |
|
|
229 | (1) |
|
|
229 | (1) |
|
|
229 | (1) |
|
Common Application-Related Symptoms |
|
|
230 | (10) |
|
|
230 | (1) |
|
Introduction of New Accounts |
|
|
231 | (1) |
|
|
231 | (1) |
|
Unexpected Outbound Communication |
|
|
231 | (1) |
|
|
231 | (1) |
|
|
231 | (1) |
|
|
232 | (1) |
|
|
232 | (1) |
|
|
232 | (1) |
|
|
233 | (4) |
Chapter 9 Incident Recovery and Post-Incident Response |
|
237 | (14) |
|
"Do I Know This Already?" Quiz |
|
|
237 | (3) |
|
|
240 | (1) |
|
|
240 | (2) |
|
|
240 | (1) |
|
|
240 | (1) |
|
|
241 | (1) |
|
|
241 | (1) |
|
|
242 | (1) |
|
|
242 | (1) |
|
|
242 | (1) |
|
|
242 | (1) |
|
|
243 | (2) |
|
|
243 | (1) |
|
|
244 | (1) |
|
|
244 | (1) |
|
Verify Logging/Communication to Security Monitoring |
|
|
244 | (1) |
|
|
245 | (1) |
|
|
245 | (1) |
|
|
245 | (1) |
|
Update Incident Response Plan |
|
|
245 | (1) |
|
|
246 | (1) |
|
|
246 | (1) |
|
|
246 | (1) |
|
|
247 | (1) |
|
|
247 | (4) |
Chapter 10 Frameworks, Policies, Controls, and Procedures |
|
251 | (50) |
|
"Do I Know This Already?" Quiz |
|
|
251 | (3) |
|
|
254 | (1) |
|
|
254 | (4) |
|
|
258 | (10) |
|
National Institute of Standards and Technology (NIST) |
|
|
258 | (2) |
|
Framework for Improving Critical Infrastructure Cybersecurity 259 ISO |
|
|
260 | (3) |
|
Control Objectives for Information and Related Technology (COBIT) |
|
|
263 | (2) |
|
Sherwood Applied Business Security Architecture (SABSA) |
|
|
265 | (1) |
|
The Open Group Architecture Framework (TOGAF) |
|
|
265 | (2) |
|
Information Technology Infrastructure Library (ITIL) |
|
|
267 | (1) |
|
|
268 | (9) |
|
|
268 | (3) |
|
Acceptable Use Policy (AUP) |
|
|
271 | (1) |
|
|
272 | (1) |
|
|
272 | (1) |
|
Account Management Policy |
|
|
273 | (1) |
|
Data Classification Policy |
|
|
274 | (3) |
|
Sensitivity and Criticality |
|
|
275 | (1) |
|
Commercial Business Classifications |
|
|
276 | (1) |
|
Military and Government Classifications |
|
|
276 | (1) |
|
|
277 | (7) |
|
Control Selection Based on Criteria |
|
|
278 | (3) |
|
|
278 | (3) |
|
Organizationally Defined Parameters |
|
|
281 | (1) |
|
|
282 | (2) |
|
|
284 | (4) |
|
|
284 | (1) |
|
|
285 | (1) |
|
|
285 | (1) |
|
Compensating Control Development |
|
|
286 | (1) |
|
Control Testing Procedures |
|
|
286 | (1) |
|
|
287 | (1) |
|
|
287 | (1) |
|
Verifications and Quality Control |
|
|
288 | (13) |
|
|
288 | (2) |
|
|
290 | (1) |
|
|
290 | (1) |
|
|
291 | (1) |
|
|
291 | (1) |
|
|
291 | (1) |
|
|
292 | (1) |
|
|
292 | (2) |
|
|
294 | (1) |
|
|
294 | (1) |
|
|
294 | (1) |
|
|
295 | (1) |
|
|
296 | (5) |
Chapter 11 Remediating Security Issues Related to Identity and Access Management |
|
301 | (42) |
|
"Do I Know This Already?" Quiz |
|
|
301 | (3) |
|
|
304 | (1) |
|
Security Issues Associated with Context-Based Authentication |
|
|
304 | (1) |
|
|
304 | (1) |
|
|
304 | (1) |
|
|
305 | (1) |
|
|
305 | (1) |
|
Security Issues Associated with Identities |
|
|
305 | (14) |
|
|
306 | (4) |
|
Employment Candidate Screening |
|
|
306 | (2) |
|
Employment Agreement and Policies |
|
|
308 | (1) |
|
|
308 | (1) |
|
Proper Credential Management |
|
|
308 | (1) |
|
|
309 | (1) |
|
Maintaining a Secure Provisioning Life Cycle |
|
|
309 | (1) |
|
|
310 | (2) |
|
Social Engineering Threats |
|
|
310 | (1) |
|
|
311 | (1) |
|
|
311 | (1) |
|
|
312 | (1) |
|
|
312 | (1) |
|
|
313 | (2) |
|
|
315 | (1) |
|
|
316 | (3) |
|
|
316 | (1) |
|
Applications as Identities |
|
|
317 | (1) |
|
|
318 | (1) |
|
|
319 | (1) |
|
Security Issues Associated with Identity Repositories |
|
|
319 | (6) |
|
|
319 | (4) |
|
|
319 | (1) |
|
|
320 | (1) |
|
|
321 | (1) |
|
|
322 | (1) |
|
|
323 | (2) |
|
Security Issues Associated with Federation and Single Sign-on |
|
|
325 | (9) |
|
|
326 | (1) |
|
|
327 | (1) |
|
|
327 | (2) |
|
|
329 | (1) |
|
|
330 | (1) |
|
|
331 | (1) |
|
|
332 | (1) |
|
Manual vs. Automatic Provisioning/Deprovisioning |
|
|
333 | (1) |
|
Self-Service Password Reset |
|
|
334 | (1) |
|
|
334 | (2) |
|
|
334 | (1) |
|
|
334 | (1) |
|
|
335 | (1) |
|
|
335 | (1) |
|
|
335 | (1) |
|
|
335 | (1) |
|
|
336 | (1) |
|
|
336 | (1) |
|
|
337 | (1) |
|
|
338 | (5) |
Chapter 12 Security Architecture and Implementing Compensating Controls |
|
343 | (42) |
|
Do I Know This Already?" Quiz |
|
|
343 | (3) |
|
|
346 | (1) |
|
|
346 | (2) |
|
Data Aggregation and Correlation |
|
|
346 | (1) |
|
|
346 | (1) |
|
|
347 | (1) |
|
|
348 | (5) |
|
|
348 | (2) |
|
|
350 | (1) |
|
|
351 | (1) |
|
|
352 | (1) |
|
|
353 | (26) |
|
|
354 | (2) |
|
|
354 | (1) |
|
|
355 | (1) |
|
|
355 | (1) |
|
|
355 | (1) |
|
|
355 | (1) |
|
Cross-Training/Mandatory Vacations |
|
|
356 | (1) |
|
|
356 | (1) |
|
|
356 | (2) |
|
|
356 | (1) |
|
Scheduled Reviews/Retirement of Processes |
|
|
357 | (1) |
|
|
358 | (15) |
|
|
358 | (1) |
|
|
358 | (1) |
|
|
359 | (1) |
|
|
360 | (2) |
|
|
362 | (11) |
|
|
373 | (14) |
|
|
374 | (5) |
|
|
379 | (1) |
|
|
379 | (1) |
|
|
380 | (1) |
|
|
380 | (5) |
Chapter 13 Application Security Best Practices |
|
385 | (18) |
|
"Do I Know This Already?" Quiz |
|
|
385 | (2) |
|
|
387 | (1) |
|
Best Practices During Software Development |
|
|
387 | (9) |
|
|
387 | (1) |
|
Gather Requirements (Security Requirements Definition) |
|
|
388 | (1) |
|
|
388 | (1) |
|
|
389 | (1) |
|
|
389 | (1) |
|
|
390 | (3) |
|
|
390 | (1) |
|
Web App Vulnerability Scanning |
|
|
391 | (1) |
|
|
391 | (1) |
|
Use Interception Proxy to Crawl Application |
|
|
392 | (1) |
|
|
393 | (1) |
|
|
393 | (1) |
|
|
393 | (1) |
|
Security Regression Testing |
|
|
394 | (1) |
|
|
394 | (1) |
|
|
395 | (1) |
|
|
395 | (1) |
|
Change Management and Configuration Management/Replacement |
|
|
395 | (1) |
|
Secure Coding Best Practices |
|
|
396 | (2) |
|
|
396 | (1) |
|
|
396 | (1) |
|
Center for Internet Security |
|
|
397 | (8) |
|
System Design Recommendations |
|
|
397 | (1) |
|
|
398 | (1) |
|
|
398 | (1) |
|
|
398 | (1) |
|
|
399 | (1) |
|
|
399 | (4) |
Chapter 14 Using Cybersecurity Tools and Technologies |
|
403 | (50) |
|
"Do I Know This Already?" Quiz |
|
|
403 | (2) |
|
|
405 | (1) |
|
|
405 | (16) |
|
|
405 | (1) |
|
|
405 | (3) |
|
|
405 | (1) |
|
|
406 | (1) |
|
|
407 | (1) |
|
|
408 | (1) |
|
|
408 | (7) |
|
|
410 | (5) |
|
|
415 | (1) |
|
|
415 | (1) |
|
|
415 | (1) |
|
|
415 | (1) |
|
|
416 | (2) |
|
|
416 | (1) |
|
|
417 | (1) |
|
|
418 | (1) |
|
|
418 | (3) |
|
|
418 | (2) |
|
|
420 | (1) |
|
|
420 | (1) |
|
|
421 | (1) |
|
|
421 | (15) |
|
|
421 | (2) |
|
|
421 | (1) |
|
|
422 | (1) |
|
|
422 | (1) |
|
|
422 | (1) |
|
|
423 | (1) |
|
|
423 | (1) |
|
|
423 | (1) |
|
|
423 | (5) |
|
|
425 | (1) |
|
|
425 | (1) |
|
|
426 | (1) |
|
|
426 | (1) |
|
|
427 | (1) |
|
Microsoft Baseline Security Analyzer |
|
|
427 | (1) |
|
|
428 | (2) |
|
|
428 | (1) |
|
|
429 | (1) |
|
|
429 | (1) |
|
|
429 | (1) |
|
Command Line/IP Utilities |
|
|
430 | (6) |
|
|
430 | (1) |
|
|
431 | (1) |
|
|
432 | (1) |
|
|
433 | (1) |
|
|
434 | (1) |
|
|
435 | (1) |
|
|
436 | (1) |
|
|
436 | (1) |
|
|
436 | (4) |
|
|
437 | (1) |
|
|
437 | (2) |
|
|
437 | (1) |
|
|
438 | (1) |
|
|
438 | (1) |
|
|
439 | (1) |
|
|
439 | (1) |
|
|
439 | (1) |
|
|
440 | (1) |
|
|
440 | (1) |
|
|
440 | (1) |
|
|
440 | (3) |
|
|
440 | (1) |
|
|
441 | (1) |
|
|
441 | (1) |
|
|
442 | (1) |
|
|
442 | (1) |
|
|
442 | (1) |
|
Microsoft SDL File/Regex Fuzzer |
|
|
442 | (1) |
|
|
443 | (4) |
|
|
443 | (2) |
|
|
444 | (1) |
|
|
444 | (1) |
|
|
444 | (1) |
|
|
444 | (1) |
|
|
445 | (1) |
|
|
445 | (1) |
|
|
445 | (1) |
|
|
445 | (1) |
|
|
445 | (2) |
|
|
445 | (1) |
|
|
446 | (1) |
|
|
447 | (6) |
|
|
447 | (1) |
|
|
447 | (1) |
|
|
447 | (1) |
|
|
448 | (1) |
|
|
448 | (5) |
Chapter 15 Final Preparation |
|
453 | (6) |
|
Tools for Final Preparation |
|
|
453 | (4) |
|
Pearson Test Prep Practice Test Software and Questions on the Website |
|
|
453 | (2) |
|
Accessing the Pearson Test Prep Software Online |
|
|
454 | (1) |
|
Accessing the Pearson Test Prep Practice Test Software Offline |
|
|
454 | (1) |
|
|
455 | (1) |
|
|
456 | (1) |
|
|
456 | (1) |
|
Chapter-Ending Review Tools |
|
|
457 | (1) |
|
Suggested Plan for Final Review/Study |
|
|
457 | (1) |
|
|
457 | (2) |
Appendix A Answers to the "Do I Know This Already?" Quizzes and Review Questions |
|
459 | (32) |
Glossary |
|
491 | (35) |
Index |
|
526 | |