CompTIA has released a new certification called the CompTIA Advanced Security Practitioner (CASP). You can view the objectives for this certification here. Looking over the objectives and the documentation about this exam, it’s clear that this is a at least a step above the CompTIA Security+ exam and it looks like a logical next step [...]
CompTIA Advanced Security Practitioner (CASP)
Security+ Cryptography Topics
Cryptography is an important topic related to IT security, especially if you’re studying for Security+, or even other security certifications such as the SSCP. While the basics are straight forward, there is a lot of depth within the concepts. For example, it should be very clear that encryption enforces confidentiality, and hashing enforces integrity. However, how [...]
Disable SSID Broadcast or Not?
Wireless networks are identified by the service set identifier (SSID), used as a network name. However, should SSID broadcast be enabled or disabled? If you’re taking the Security+ exam, that’s an important concept you should understand. More, you can expect to see two different perspectives on whether SSID broadcast should be disabled or not. At [...]
Security+ SY0-301 Study Guide Update (cont)
I just passed another hurdle with the CompTIA Security+ Get Certified Get Ahead SY0-301 Study Guide. This is an update to the CompTIA Security+: Get Certified Get Ahead: SY0-201 Study Guide and includes full coverage of the new exam and over 450 realistic practice test questions. The file copy came back with the index inserted [...]
Systems Security Certified Practitioner (SSCP) Changes
The (ISC)2 Systems Security Certified Practitioner (SSCP) is a logical next step for many people that have passed the CompTIA Security+ exam. If you’re planning on taking it, you should be aware that it is changing. Everything is the same until January 31, 2012. However, effective February 1, 2012, the domains are changing. This article [...]
CISSP Access Control Domain Objectives
The CISSP objectives are changing effective January 1, 2012. I recently analyzed the Access Control domain and noticed several noteworthy changes. It is more direct on rights and permissions, adds more on account management and includes several specifics on access control attacks. First, the introduction is much more direct on accessing and revoking permissions. In [...]
Security+ SY0-301 Study Guide Update
I just passed another hurdle with the CompTIA Security+ Get Certified Get Ahead SY0-301 Study Guide. This is an update to the CompTIA Security+: Get Certified Get Ahead: SY0-201 Study Guide and includes full coverage of the new exam and over 450 realistic practice test questions. The proof came back and I completed the index. [...]
Hot, Cold, and Warm Sites
If you’re planning on taking the Security+, or SSCP ,exam, you should have a basic understanding alternate locations such as hot sites, cold sites, and warm sites. These help an organization ensure they can continue critical business functions in another location even during or after a disaster. Some examples of disasters are fires, hurricanes, tornados, and [...]
Understanding Security+ Ports
Security+ Ports If you’re planning on taking the Security exam you should have a basic understanding of Security+ ports. Questions continue to appear in the Security+ exam. There are 65,536 TCP and 65, 536 UDP ports. The first 1024 (0 to 1023) are well known ports and commonly used with default protocols. For example, the [...]
CompTIA Network+ Certification
The Network+ is an excellent certification to have in today’s marketplace. Even if you don’t have the certification, the knowledge is valuable for just about any technician working on the job. The exam includes 100 questions that you need to complete in 90 minutes giving you just a little than a minute a question. A [...]