5 Day Course
Introduction
This course is the official courseware for the Security Certified Program
SC0-471 certification exam. The Strategic Infrastructure Security (SIS) course
is designed to follow the hands-on skills utilized in the Tactical Perimeter
Defense (TPD) course. The SIS course continues with hardening of strategic
elements of your infrastructure, such as your Windows and Linux servers, and goes
into detail on one of the most critical areas to understand in security,
Cryptography.
Prerequisites
To ensure your success, we recommend that you have completed the SCP
Tactical Perimeter Defense (TPD) course. The TPD course will ensure you have the
core security concepts and skills in developing a secure perimeter for your
organization.
Delivery Method
Instructor-led, group-paced, classroom-delivery learning model with
structured hands-on activities
At Course Completion
Upon successful course completion students should be able to:
•
Detail the core issues of cryptography,
including public and private key
•
Harden SuSe Linux 10 Server computers
•
Harden Windows Server 2003 computers
•
Utilize ethical hacking attack techniques
•
Secure DNS and web servers, and examine Internet
and WWW security
•
Perform a risk analysis
•
Create a security policy
•
Analyze packet signatures
Course Outline
Lesson 1: Cryptography and Data Security
•
History
of Cryptography
•
Math and
Algorithms
•
Private
Key Exchange
•
Public
Key Exchange
•
Message
Authentication
Lesson 2: Hardening Linux Computers
•
Linux
Filesystem and Navigation
•
General
Secure System Management
•
User and
Filesystem Security Administration
•
Network
Interface Configuration
•
Security
Scripting
•
Useful
Linux Security Tools
Lesson 3: Hardening Windows Server 2003
•
Windows
2003 Infrastructure Security
•
Windows
2003 Authentication
•
Windows
2003 Security Configuration Tools
•
Windows
2003 Resource Security
•
Windows
2003 Auditing and Logging
•
Windows
2003 EFS
•
Windows
2003 Network Security
Lesson 4: Attack Techniques
•
Network
Reconnaissance
•
Mapping
the Network
•
Sweeping
the Network
•
Scanning
the Network
•
Vulnerability
Scanning
•
Viruses,
Worms, and Trojan Horses
•
Gaining
Control over the System
•
Recording
Keystrokes
•
Cracking
Encrypted Passwords
•
Revealing
Hidden Passwords
•
Social
Engineering
•
Gaining
Unauthorized Access
•
Hiding
Evidence of an Attack
•
Performing
a Denial of Service
Lesson 5: Security on the Internet and the WWW
•
Describing
the Major Components of the Internet
•
Securing
DNS Services
•
Describing
Web Hacking Techniques
•
Describing
Methods Used to Attack Users
Lesson 6: Performing a Risk Analysis
•
Concepts
of Risk Analysis
•
Methods
of Risk Analysis
•
The
Process of Risk Analysis
•
Techniques
to Minimize Risk
•
Continuous
Risk Assessment
Lesson 7: Creating a Security Policy
•
Concepts
of Security Policies
•
Policy
Design
•
Policy
Contents
•
An
Example Policy
•
Incident
Handling and Escalation Procedures
•
Partner
Policies
Lesson 8: Analyzing Packet Signatures
•
Signature
Analysis
•
Common
Vulnerabilities and Exposures (CVE)
•
Signatures
•
Normal
Traffic Signatures