课程信息
5.0
3 个评分
1 个审阅
100% 在线

100% 在线

立即开始,按照自己的计划学习。
可灵活调整截止日期

可灵活调整截止日期

根据您的日程表重置截止日期。
初级

初级

完成时间(小时)

完成时间大约为14 小时

建议:5 hours/week...
可选语言

英语(English)

字幕:英语(English)
100% 在线

100% 在线

立即开始,按照自己的计划学习。
可灵活调整截止日期

可灵活调整截止日期

根据您的日程表重置截止日期。
初级

初级

完成时间(小时)

完成时间大约为14 小时

建议:5 hours/week...
可选语言

英语(English)

字幕:英语(English)

教学大纲 - 您将从这门课程中学到什么

1
完成时间(小时)
完成时间为 5 小时

Identify and Analyze Malicious Code and Activity

Module Topics: Malicious Code, Malicious Code Countermeasures, Exploitation, Insider Threats, Spoofing, Phishing, Spam, and Botnet, Malicious Web Activity, Payloads, Malicious Activity Countermeasures, Malcode Mitigation, and Common Mistakes. Malicious Code includes topics like Key concepts, Example Worms, Polymorphic Viruses, Software Exploitation Methods, Scanners, Generations of Antivirus Scanning Software, Generic Decryption (GD) Technology, Behavior-Blocking Software, Antivirus Software on the Firewall and IDS, Code signing, Code Signing Certificates, Sandboxing, Virtual Machine (VM), Social Engineering, Additional Examples of Social Engineering Attacks, and Security Awareness Training. Under the topic of Exploitation, you will learn about Long File Extensions, Fake Icon, Hostile Codecs, and E-mail. In Insider Threats, you will learn about Indicators of Malicious Threat Activity, Countermeasures, Direction, Prevention, and Deterrence Methods, Continual Training, and Insider Hardware Threats. In Spoofing, Phishing, Spam, and Botnets, you will learn about Spoofing, Examples of Spoofing, Phishing, Common Characteristics of Forged E-Mail Messages, Techniques, How Phishing Works, Impact of Phishing, How to Recognize a Phishing E-Mail, Spam, Spam Distribution Channels, How Does Spam Work?, Spam Techniques, Protecting users From Spam, Botnets, How Are Botnets Created?, Botnet-Led Exploits, Botnet Detection and Mitigation, Common Botnet Detection and Mitigation Techniques. In Malicious Web Activity, you will go through topics like Mobomarket Attack, Cross-site Scripting (XSS) Attacks, The Theory of XSS, XSS Attack Vectors, Is the Organization's Site Vulnerable to Cross-Site Scripting? Example of a Cross-Site Scripting Attack, How to check for Cross-Site Scripting Vulnerabilities, Zero-Day Exploits and Advanced Persistent Threats (APTS), Unknown Vulnerabilities management Process, Five Phases of APT, Brute-Force Attacks, Instant Messaging, Infected Factory Builds and Media, man-in-the-Middle Malcode, Malicious Activity Countermeasures, Network Layer, Application Layer, Modified Hosts File and DNS Changes, Inspection of Process, Rootkit, Rootkit Classifications, Behavioral Analysis of Malcode, and Static File Analysis....
Reading
18 个视频 (总计 109 分钟), 18 个阅读材料, 1 个测验
Video18 个视频
Malicious Code and Activity: Key Concepts6分钟
Malicious Code and Activity: Malicious Code Countermeasures4分钟
Malicious Code and Activity: Software Exploitation Methods6分钟
Malicious Code and Activity: Software Exploitation Methods5分钟
Malicious Code and Activity: Code Signing5分钟
Malicious Code and Activity: Social Engineering6分钟
Malicious Code and Activity: Security Awareness Training6分钟
Malicious Code and Activity: Long File Extensions5分钟
Malicious Code and Activity: E-mail7分钟
Malicious Code and Activity: Countermeasures5分钟
Malicious Code and Activity: Examples of Spoofing5分钟
Malicious Code and Activity: Techniques5分钟
Malicious Code and Activity: Botnet-Led Exploits6分钟
Malicious Code and Activity: Malicious Web Activity6分钟
Malicious Code and Activity: Zero-Day Exploits4分钟
Malicious Code and Activity: Infected Factory Builds and Media4分钟
Malicious Code and Activity: Inspection of Processes7分钟
Reading18 个阅读材料
Systems and Application Security10分钟
Malicious Code and Activity: Key Concepts10分钟
Malicious Code and Activity: Malicious Code Countermeasures10分钟
Malicious Code and Activity: Software Exploitation Methods10分钟
Malicious Code and Activity: Software Exploitation Methods10分钟
Malicious Code and Activity: Code Signing10分钟
Malicious Code and Activity: Social Engineering10分钟
Malicious Code and Activity: Security Awareness Training10分钟
Malicious Code and Activity: Long File Extensions10分钟
Malicious Code and Activity: E-mail10分钟
Malicious Code and Activity: Countermeasures10分钟
Malicious Code and Activity: Examples of Spoofing10分钟
Malicious Code and Activity: Techniques10分钟
Malicious Code and Activity: Botnet-Led Exploits10分钟
Malicious Code and Activity: Malicious Web Activity10分钟
Malicious Code and Activity: Zero-Day Exploits10分钟
Malicious Code and Activity: Infected Factory Builds and Media10分钟
Malicious Code and Activity: Inspection of Processes10分钟
Quiz1 个练习
Quiz 120分钟
2
完成时间(小时)
完成时间为 1 小时

Implement and Operate Endpoint Device Security

Module Topics: Host-Based Intrusion Detection Systems (HIDS), Host-Based Firewalls, Application Whitelisting, Endpoint Encryption, Trusted Platform Module (TPM), Mobile Device Management (MDM), Secure Browsing. In Host-Based Intrusion Detection Systems (HIDS), you will learn about Advantages and Disadvantages of HIDS. In Application Whitelisting, you will learn about software Restriction Policies (SRP), Trusted Platform Module (TPM). In Mobile Device Management (MDM), you will learn about Bring your Own Device (BYOD), Security, BYOD Policy Considerations, BYOD Policy Considerations, Corporate Owned, Personally Enabled (COPE), and Secure Browsing....
Reading
3 个视频 (总计 15 分钟), 3 个阅读材料, 1 个测验
Video3 个视频
Endpoint Device Security: Trusted Platform Module (TPM)6分钟
Endpoint Device Security: BYOD Policy Considerations2分钟
Reading3 个阅读材料
Endpoint Device Security: HIDS10分钟
Endpoint Device Security: Trusted Platform Module (TPM)10分钟
Endpoint Device Security: BYOD Policy Considerations10分钟
Quiz1 个练习
Quiz 210分钟
3
完成时间(小时)
完成时间为 5 小时

Operate and Configure Cloud Security

Module Topics: Introduction, Deployment Models, Service Models, Virtualization, Legal and Privacy Concerns, Classification of Discovered Sensitive Data, Mapping and Definition of Controls, Application of Defined Controls for Personally Identifiable Information (PII), Data Storage and Transmission, Encryption, Key Management, Masking/Obfuscation and Anonymization, Tokenization, Data Deletion Procedures and Mechanisms, Event Sources, Data Event Logging and Event Attributes, and Storage and Analysis of Data Events. Introduction covers the Five Essential Characteristics of Clouds. Deployment Models cover topics like Public, Private, Hybrid and Community Cloud, Service Models, SaaS, PaaS, and IaaS. Virtualization includes Hypervisor, and Types of Virtualization. In Legal and Privacy Concerns, you will learn about Key P&DP Questions, Country-Specific Legal Considerations, Jurisdiction and Applicable Law, Essential Requirements in P&DP Laws, Typical Meaning for Common Privacy Terms, Privacy Roles for Customer and Service Provider, Data Discovery, and Privacy Level Agreement (PLA). In Application of Defined Controls for Personally Identifiable Information (PII), you will learn about Cloud security Alliance Cloud Controls Matrix (CCM), CCM Security Domains, Data Dispersion in Cloud Storage, Threat to storage Types, Technologies Available to Address Threats, Data Loss Prevention (DLP), DLP Components, DLP Architecture, Cloud-Based DLP Considerations, and Best Practices. In Encryption, you will learn about Sample Use cases for Encryption, Cloud Encryption Challenges, Key Management, Key Storage in the Cloud, and Key Management in Software environments. In Masking/Obfuscation and Anonymization, you will learn about Data Masking/Obfuscation, Common Approaches for Data Masking, Primary Methods of Masking Data, and Data Anonymization. Tockenization covers topics like Tokenization and Cloud, Data Retention Policies, Data Deletion Procedures and Mechanisms, Disposal Options, Crypto-shredding, Data Archiving Policy, Security and Information Event Management (SIEM). Data Event Logging and Event Attributes covers topics like OWASP Recommendations, SIEM Capabilities, and SIEM Challenges. ...
Reading
16 个视频 (总计 105 分钟), 16 个阅读材料, 1 个测验
Video16 个视频
Cloud Security: Hybrid5分钟
Cloud Security: Virtualization7分钟
Cloud Security: Hypervisor4分钟
Cloud Security: Country-Specific Legal Considerations6分钟
Cloud Security: P&DP Laws6分钟
Cloud Security:Application of Defined Controls for Personally Identifiable Information (PII)8分钟
Cloud Security: Data Dispersion5分钟
Cloud Security: Threat to Storage Types9分钟
Cloud Security: Technologies to Address Threats4分钟
Cloud Security: DLP Architecture7分钟
Cloud Security: Review Activity6分钟
Cloud Security: Key Storage in the Cloud4分钟
Cloud Security: Common Approaches for Data Masking4分钟
Cloud Security: Data Retention Policies7分钟
Cloud Security: Disposal Options8分钟
Reading16 个阅读材料
Cloud Security: Five Essential Characteristics of Clouds10分钟
Cloud Security: Hybrid10分钟
Cloud Security: Virtualization10分钟
Cloud Security: Hypervisor10分钟
Cloud Security: Country-Specific Legal Considerations10分钟
Cloud Security: P&DP Laws10分钟
Cloud Security: Application of Defined Controls for Personally Identifiable Information (PII)10分钟
Cloud Security: Data Dispersion10分钟
Cloud Security: Threat to Storage Types10分钟
Cloud Security: Technologies to Address Threats10分钟
Cloud Security: DLP Architecture10分钟
Cloud Security: Review Activity10分钟
Cloud Security: Key Storage in the Cloud10分钟
Cloud Security: Common Approaches for Data Masking10分钟
Cloud Security: Data Retention Policies10分钟
Cloud Security: Disposal Options10分钟
Quiz1 个练习
Quiz 320分钟
4
完成时间(小时)
完成时间为 3 小时

Secure Big Data Systems & Operate and Secure Virtual Environments

Module Topics for Secure Big Data Systems: Application Vulnerabilities and Architecture or Design Environments. Application Vulnerabilities include topics like Data Growth, Big Data, Interpreting Big, Data, Big Data Issues, and Challenges with 'Free' Analytic Tools. Architectural or Design Environments include topics like Distributed Computing Architectures, Key Challenges, Securing the Organization's Big Data, and Deploying Big Data for Security. Module Topics for Operate and Secure Virtual Environments: Software-Defined Network (SDN), Virtual Appliances, Continuity and Resilience, Attacks and Countermeasures, Common Virtualization Attacks, Recommendations and Best Practices for Secure Virtualization, and Shared Storage. In Software-Defined network (SDN), you will learn about How SDN Works. Virtual Appliances talks about Virtual Appliances Compared to Virtual Machines. In Continuity and Resilience you will learn about Host Clustering Concepts, VMware Distributed Resource Scheduling (DRS), Scalability and Reliability, windows Failover Clustering. In Common Virtualization Attacks, you will learn about Mitigation Strategies. In Recommendations and Best Practices for Secure Virtualization you will learn about Desktop Virtualization and Security, Network Security, Storage Networks, Auditing and Logging, Virtual Machine Security, Management Systems, Hypervisor Security, Time Synchronization, Remote Access, Backups, and Configuration and Change Management. ...
Reading
9 个视频 (总计 70 分钟), 9 个阅读材料, 1 个测验
Video9 个视频
Secure Big Data Systems: Interpreting Big Data4分钟
Secure Big data Systems: Key Challenges5分钟
Operate and Secure Virtual Environments: SDN5分钟
Operate and Secure Virtual Environments: Virtual Appliances8分钟
Operate and Secure Virtual Environments: DRS10分钟
Operate and Secure Virtual Environments: Common Attacks6分钟
Operate and Secure Virtual Environments: Network Security5分钟
Operate and Secure Virtual Environments: Virtual Machine Security16分钟
Reading9 个阅读材料
Secure Big Data Systems: Big Data10分钟
Secure Big Data Systems: Interpreting Big Data10分钟
Secure Big data Systems: Key Challenges10分钟
Operate and Secure Virtual Environments: SDN10分钟
Operate and Secure Virtual Environments: Virtual Appliances10分钟
Operate and Secure Virtual Environments: DRS10分钟
Operate and Secure Virtual Environments: Common Attacks10分钟
Operate and Secure Virtual Environments: Network Security10分钟
Operate and Secure Virtual Environments: Virtual Machine Security10分钟
Quiz1 个练习
Quiz 412分钟
5.0
1 个审阅Chevron Right

热门审阅

创建者 GBJul 5th 2018

Thank you. Great course. The instructor breaks everything down, and makes it easy to learn.

讲师

Avatar

(ISC)² Education & Training

Education & Training

关于 (ISC)²

(ISC)² is an international nonprofit membership association focused on inspiring a safe and secure cyber world. Best known for the acclaimed Certified Information Systems Security Professional (CISSP®) certification, (ISC)2 offers a portfolio of credentials that are part of a holistic, programmatic approach to security. www.isc2.org ...

关于 (ISC)² Systems Security Certified Practitioner (SSCP) 专项课程

Pursue better IT security job opportunities and prove knowledge with confidence. The SSCP Professional Training Certificate shows employers you have the IT security foundation to defend against cyber attacks – and puts you on a clear path to earning SSCP certification. Learn on your own schedule with 120-day access to content aligned with the latest (ISC)2 SSCP exam domains. We’re offering the complete online self-paced program for only $1,000 – a $200 savings when you get all domains bundled together. 3 Steps to Career Advancement 1. Register for the course 2. Gain access for 120 days 3. Register and sit for the SSCP certification exam Upon completing the SSCP Professional Certificate, you will: 1. Complete six courses of preparing you to sit for the Systems Security Certified Practitioner (SSCP) certification exam as outlined below. Course 1 - Access Controls Course 2 - Security Operations and Administration Course 3 - Risk Identification, Monitoring, and Analysis/Incident Response and Recovery Course 4 - Cryptography Course 5 - Network and Communication Security Course 6 - Systems and Application Security 2. Receive a certificate of program completion. 3. Understand how to implement, monitor and administer an organization’s IT infrastructure in accordance with security policies and procedures that ensure data confidentiality, integrity and availability....
(ISC)² Systems Security Certified Practitioner (SSCP)

常见问题

  • 是的,您可以在注册之前预览第一个视频和查看授课大纲。您必须购买课程,才能访问预览不包括的内容。

  • 如果您决定在班次开始日期之前注册课程,那么您将可以访问课程的所有课程视频和阅读材料。班次开始之后,您便可以提交作业。

  • 在您注册且班次开课之后,您将可以访问所有视频和其他资源,包括阅读材料内容和课程论坛。您将能够查看和提交练习作业,并完成所需的评分作业以获得成绩和课程证书。

  • 如果您成功完成课程,您的电子课程证书将添加到您的成就页中,您可以通过该页打印您的课程证书或将其添加到您的领英档案中。

  • 此课程是 Coursera 上提供的众多课程之一,当前只对已购买课程或已获得助学金的学生开放。如果您要学习此课程,但却承担不起课程费用,我们建议您提交助学金申请。

  • The course schedule contains approximately 15 hours of content material covering lectures, reading materials, a case study, and quizzes broken up over the course of 7 weeks.

还有其他问题吗?请访问 学生帮助中心