, CompTIAoSecurity1oSY0-601oCertificationoExamoObjectives
Bloom’soTaxon
Security1o Examo Domain/Objectives Module Section omy
1.0oThreats,oAttacks,oandoVulnerabilities
1.1 Compareoandocontrastodifferentotypesoofosocialo
engineeringotechniques.
1 Vulnerabilitieso ando Attacks Understanding
● Phishing
● Smishing
● Vishing
● Spam
● SpamooveroInternetomessagingo(SPIM)
● Spearophishing
● Dumpstero diving
● Shoulderosurfing
● Pharming
● Tailgating
● Elicitingoinformation
● Whaling
● Prepending
● Identityo fraud
● Invoiceo scams
● Credentialo harvesting
● Reconnaissance
● Hoax
● Impersonation
● Wateringoholeoattack
● Typoosquatting
● Influenceo campaigns
❍ Hybrido warfare
❍ Socialomedia
● Principleso(reasonsoforoeffectiveness)
❍ Authority
❍ Intimidation
❍ Consensus
❍ Scarcity
❍ Familiarity
❍ Trust
❍ Urgency
1.2oGivenoaoscenario,oanalyzeopotentialoindicatorsotoodetermi
neotheotypeoofoattack.
● Malware 3 AttacksoUsingoMalware Analyzing
❍ Ransomware
❍ Trojans
❍ Worms
❍ Potentially o unwantedo programs o (PUPs)
❍ Filelessovirus
❍ Command o ando control
❍ Bots
❍ Cryptomalware
❍ Logicobombs
❍ Spyware
❍ Keyloggers
❍ RemoteoaccessoTrojano(RAT)
❍ Rootkit
❍ Backdoor
Copyrighto2022oCengageoLearning.oAlloRightsoReserved.oMayonotobeocopied,oscanned,ooroduplicated,oinowholeooroinopart.oDueotooelectronicorights,osomeothirdopartyocontentomayobeosuppressedofromotheoeBookoand/oroe
Chapter(s).
Editorialoreviewohasodeemedothatoanyosuppressedocontentodoesonotomateriallyoaffectotheooverallolearningoexperience.oCengageoLearningoreservesotheorightotooremoveoadditionalocontentoatoanyotimeoifosubsequentorightsores
, Bloom’soTaxon
Securityo+oExamoDomain/Objectives Module Section omy
● Passwordo attacks 12 TypesoofoAuthenticationoCred Creating
❍ Spraying entials
❍ Dictionary
❍ Bruteo force
■ Offline
■ Online
❍ Rainbow o tables
❍ Plaintext/unencrypted
● Physicaloattacks 5 SecuringoMobileo Devices Applying
❍ Malicious ouniversal oserialobuso(USB)ocable
❍ Malicious o flash o drive
❍ Cardocloning
❍ Skimming
● Adversarial o artificialo intelligence o (AI) 3 AdversarialoArtificialoIntelligen Understanding
❍ Taintedotrainingodataofor omachineolearning ceo Attacks
o(ML)
❍ Security oofomachine olearningoalgorithms
● Supply-chain oattacks
● Cloud-basedovs.oon-premises oattacks
● Cryptographic oattacks 6 CryptographicoAttacksoandoDe Applying
❍ Birthday fenses
❍ Collision
❍ Downgrade
1.3oGivenoaoscenario,oanalyzeopotentialoindicatorsoassocia
tedowithoapplicationoattacks. 3
● Privilegeoescalation SegmentingotheoNetwork Understanding
● Cross-siteoscripting
● Injections
❍ Structuredoqueryolanguage o(SQL) CreatingoNetworkoDeceptionoI ApplyingoApplyin
❍ Dynamicolinkolibrary o(DLL) mplementingoEndpointoSecuri g
❍ Lightweight odirectory oaccessoprotocol ty
o(LDAP)
❍ Extensible omarkupolanguageo (XML)
● Pointer/objecto dereference
● Directoryotraversal Hardeningo theo Network Analyzing
● Bufferooverflows
● Raceoconditions
❍ Timeoofocheck/time oofouse
● Errorohandling
● Impropero inputo handling
● Replayoattack
❍ Session oreplays
● Integerooverflow
● Requestoforgeries
❍ Server-side
❍ Client-side
❍ Cross-site
● Applicationoprogrammingointerfaceo(API)
oattacks
● Resourceoexhaustion
● Memoryoleak
● Secureosocketsolayero(SSL)ostripping
● Drivero manipulation
❍ Shimming
❍ Refactoring
● Passotheohash
Copyrighto2022oCengageoLearning.oAlloRightsoReserved.oMayonotobeocopied,oscanned,ooroduplicated,oinowholeooroinopart.oDueotooelectronicorights,osomeothirdopartyocontentomayobeosuppressedofromotheoeBookoand/oroe
Chapter(s).
Editorialoreviewohasodeemedothatoanyosuppressedocontentodoesonotomateriallyoaffectotheooverallolearningoexperience.oCengageoLearningoreservesotheorightotooremoveoadditionalocontentoatoanyotimeoifosubsequentorightsores
, Seventh Edition o
CompTIA o
Security+
Guide to Network o o o
Security Fundam o
entals
MARK CIAMPA, PH.D. o o
INFORMATION
SECURITY
o
Australiao •o Brazilo •o Canadao •o Mexicoo •o Singaporeo •o Unitedo Kingdomo •o Unitedo States
Copyrighto2022oCengageoLearning.oAlloRightsoReserved.oMayonotobeocopied,oscanned,ooroduplicated,oinowholeooroinopart.oDueotooelectronicorights,osomeothirdopartyocontentomayobeosuppressedofromotheoeBookoand/oroeChapter(s).
Editorialoreviewohasodeemedothatoanyosuppressedocontentodoesonotomateriallyoaffectotheooverallolearningoexperience.oCengageoLearningoreservesotheorightotooremoveoadditionalocontentoatoanyotimeoifosubsequentorightsorestrictionsorequireoit.
Bloom’soTaxon
Security1o Examo Domain/Objectives Module Section omy
1.0oThreats,oAttacks,oandoVulnerabilities
1.1 Compareoandocontrastodifferentotypesoofosocialo
engineeringotechniques.
1 Vulnerabilitieso ando Attacks Understanding
● Phishing
● Smishing
● Vishing
● Spam
● SpamooveroInternetomessagingo(SPIM)
● Spearophishing
● Dumpstero diving
● Shoulderosurfing
● Pharming
● Tailgating
● Elicitingoinformation
● Whaling
● Prepending
● Identityo fraud
● Invoiceo scams
● Credentialo harvesting
● Reconnaissance
● Hoax
● Impersonation
● Wateringoholeoattack
● Typoosquatting
● Influenceo campaigns
❍ Hybrido warfare
❍ Socialomedia
● Principleso(reasonsoforoeffectiveness)
❍ Authority
❍ Intimidation
❍ Consensus
❍ Scarcity
❍ Familiarity
❍ Trust
❍ Urgency
1.2oGivenoaoscenario,oanalyzeopotentialoindicatorsotoodetermi
neotheotypeoofoattack.
● Malware 3 AttacksoUsingoMalware Analyzing
❍ Ransomware
❍ Trojans
❍ Worms
❍ Potentially o unwantedo programs o (PUPs)
❍ Filelessovirus
❍ Command o ando control
❍ Bots
❍ Cryptomalware
❍ Logicobombs
❍ Spyware
❍ Keyloggers
❍ RemoteoaccessoTrojano(RAT)
❍ Rootkit
❍ Backdoor
Copyrighto2022oCengageoLearning.oAlloRightsoReserved.oMayonotobeocopied,oscanned,ooroduplicated,oinowholeooroinopart.oDueotooelectronicorights,osomeothirdopartyocontentomayobeosuppressedofromotheoeBookoand/oroe
Chapter(s).
Editorialoreviewohasodeemedothatoanyosuppressedocontentodoesonotomateriallyoaffectotheooverallolearningoexperience.oCengageoLearningoreservesotheorightotooremoveoadditionalocontentoatoanyotimeoifosubsequentorightsores
, Bloom’soTaxon
Securityo+oExamoDomain/Objectives Module Section omy
● Passwordo attacks 12 TypesoofoAuthenticationoCred Creating
❍ Spraying entials
❍ Dictionary
❍ Bruteo force
■ Offline
■ Online
❍ Rainbow o tables
❍ Plaintext/unencrypted
● Physicaloattacks 5 SecuringoMobileo Devices Applying
❍ Malicious ouniversal oserialobuso(USB)ocable
❍ Malicious o flash o drive
❍ Cardocloning
❍ Skimming
● Adversarial o artificialo intelligence o (AI) 3 AdversarialoArtificialoIntelligen Understanding
❍ Taintedotrainingodataofor omachineolearning ceo Attacks
o(ML)
❍ Security oofomachine olearningoalgorithms
● Supply-chain oattacks
● Cloud-basedovs.oon-premises oattacks
● Cryptographic oattacks 6 CryptographicoAttacksoandoDe Applying
❍ Birthday fenses
❍ Collision
❍ Downgrade
1.3oGivenoaoscenario,oanalyzeopotentialoindicatorsoassocia
tedowithoapplicationoattacks. 3
● Privilegeoescalation SegmentingotheoNetwork Understanding
● Cross-siteoscripting
● Injections
❍ Structuredoqueryolanguage o(SQL) CreatingoNetworkoDeceptionoI ApplyingoApplyin
❍ Dynamicolinkolibrary o(DLL) mplementingoEndpointoSecuri g
❍ Lightweight odirectory oaccessoprotocol ty
o(LDAP)
❍ Extensible omarkupolanguageo (XML)
● Pointer/objecto dereference
● Directoryotraversal Hardeningo theo Network Analyzing
● Bufferooverflows
● Raceoconditions
❍ Timeoofocheck/time oofouse
● Errorohandling
● Impropero inputo handling
● Replayoattack
❍ Session oreplays
● Integerooverflow
● Requestoforgeries
❍ Server-side
❍ Client-side
❍ Cross-site
● Applicationoprogrammingointerfaceo(API)
oattacks
● Resourceoexhaustion
● Memoryoleak
● Secureosocketsolayero(SSL)ostripping
● Drivero manipulation
❍ Shimming
❍ Refactoring
● Passotheohash
Copyrighto2022oCengageoLearning.oAlloRightsoReserved.oMayonotobeocopied,oscanned,ooroduplicated,oinowholeooroinopart.oDueotooelectronicorights,osomeothirdopartyocontentomayobeosuppressedofromotheoeBookoand/oroe
Chapter(s).
Editorialoreviewohasodeemedothatoanyosuppressedocontentodoesonotomateriallyoaffectotheooverallolearningoexperience.oCengageoLearningoreservesotheorightotooremoveoadditionalocontentoatoanyotimeoifosubsequentorightsores
, Seventh Edition o
CompTIA o
Security+
Guide to Network o o o
Security Fundam o
entals
MARK CIAMPA, PH.D. o o
INFORMATION
SECURITY
o
Australiao •o Brazilo •o Canadao •o Mexicoo •o Singaporeo •o Unitedo Kingdomo •o Unitedo States
Copyrighto2022oCengageoLearning.oAlloRightsoReserved.oMayonotobeocopied,oscanned,ooroduplicated,oinowholeooroinopart.oDueotooelectronicorights,osomeothirdopartyocontentomayobeosuppressedofromotheoeBookoand/oroeChapter(s).
Editorialoreviewohasodeemedothatoanyosuppressedocontentodoesonotomateriallyoaffectotheooverallolearningoexperience.oCengageoLearningoreservesotheorightotooremoveoadditionalocontentoatoanyotimeoifosubsequentorightsorestrictionsorequireoit.