Tan115 commited on
Commit
94eae43
·
verified ·
1 Parent(s): 071a1df

Add files using upload-large-folder tool

Browse files
This view is limited to 50 files because it contains too many changes.   See raw diff
Files changed (50) hide show
  1. .gitattributes +32 -0
  2. 01 - Introduction/001 Course Layout.mp4 +3 -0
  3. 01 - Introduction/001 Course Layout_en.srt +660 -0
  4. 01 - Introduction/002 30 Day Study Plan.mp4 +3 -0
  5. 01 - Introduction/002 30 Day Study Plan_en.srt +704 -0
  6. 01 - Introduction/003 Exam Information.mp4 +3 -0
  7. 01 - Introduction/003 Exam Information_en.srt +568 -0
  8. 01 - Introduction/004 Exam Domains.mp4 +3 -0
  9. 01 - Introduction/004 Exam Domains_en.srt +456 -0
  10. 01 - Introduction/005 30-Day-study-Plan.pdf +3 -0
  11. 01 - Introduction/005 Course Objectives, Notes and Cram Guide Download.html +69 -0
  12. 01 - Introduction/005 Course-Notes.pdf +3 -0
  13. 01 - Introduction/005 Security-Last-Minute-Cram-Guide.pdf +3 -0
  14. 01 - Introduction/005 comptia-security-sy0-701-exam-objectives-5-0.pdf +3 -0
  15. 02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2.mp4 +3 -0
  16. 02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2_en.srt +44 -0
  17. 02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2.mp4 +3 -0
  18. 02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2_en.srt +136 -0
  19. 02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2.mp4 +3 -0
  20. 02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2_en.srt +296 -0
  21. 02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2.mp4 +3 -0
  22. 02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2_en.srt +192 -0
  23. 02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2.mp4 +3 -0
  24. 02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2_en.srt +232 -0
  25. 02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2.mp4 +3 -0
  26. 02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2_en.srt +136 -0
  27. 02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2.mp4 +3 -0
  28. 02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2_en.srt +616 -0
  29. 02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2.mp4 +3 -0
  30. 02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2_en.srt +192 -0
  31. 02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2.mp4 +3 -0
  32. 02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2_en.srt +164 -0
  33. 02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2.mp4 +3 -0
  34. 02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2_en.srt +268 -0
  35. 02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2.mp4 +3 -0
  36. 02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2_en.srt +144 -0
  37. 02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2.mp4 +3 -0
  38. 02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2_en.srt +240 -0
  39. 02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2.mp4 +3 -0
  40. 02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2_en.srt +188 -0
  41. 02 - Lesson 1 IT Security Fundamentals/014 Quick Quiz.html +479 -0
  42. 03 - Security Controls Categories and Types/001 Control Categories OB 1.1.mp4 +3 -0
  43. 03 - Security Controls Categories and Types/001 Control Categories OB 1.1_en.srt +320 -0
  44. 03 - Security Controls Categories and Types/002 Control Types OB 1.1.mp4 +3 -0
  45. 03 - Security Controls Categories and Types/002 Control Types OB 1.1_en.srt +400 -0
  46. 03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1.mp4 +3 -0
  47. 03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1_en.srt +236 -0
  48. 03 - Security Controls Categories and Types/004 Quick Quiz.html +479 -0
  49. 04 - Threats/001 Threats Motivation OB 2.1.mp4 +3 -0
  50. 04 - Threats/001 Threats Motivation OB 2.1_en.srt +384 -0
.gitattributes CHANGED
@@ -33,3 +33,35 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
33
  *.zip filter=lfs diff=lfs merge=lfs -text
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
33
  *.zip filter=lfs diff=lfs merge=lfs -text
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
36
+ 01[[:space:]]-[[:space:]]Introduction/001[[:space:]]Course[[:space:]]Layout.mp4 filter=lfs diff=lfs merge=lfs -text
37
+ 01[[:space:]]-[[:space:]]Introduction/002[[:space:]]30[[:space:]]Day[[:space:]]Study[[:space:]]Plan.mp4 filter=lfs diff=lfs merge=lfs -text
38
+ 01[[:space:]]-[[:space:]]Introduction/003[[:space:]]Exam[[:space:]]Information.mp4 filter=lfs diff=lfs merge=lfs -text
39
+ 01[[:space:]]-[[:space:]]Introduction/005[[:space:]]30-Day-study-Plan.pdf filter=lfs diff=lfs merge=lfs -text
40
+ 01[[:space:]]-[[:space:]]Introduction/004[[:space:]]Exam[[:space:]]Domains.mp4 filter=lfs diff=lfs merge=lfs -text
41
+ 01[[:space:]]-[[:space:]]Introduction/005[[:space:]]Course-Notes.pdf filter=lfs diff=lfs merge=lfs -text
42
+ 01[[:space:]]-[[:space:]]Introduction/005[[:space:]]Security-Last-Minute-Cram-Guide.pdf filter=lfs diff=lfs merge=lfs -text
43
+ 01[[:space:]]-[[:space:]]Introduction/005[[:space:]]comptia-security-sy0-701-exam-objectives-5-0.pdf filter=lfs diff=lfs merge=lfs -text
44
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/001[[:space:]]Introduction[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
45
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/002[[:space:]]CIA[[:space:]]Triad[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
46
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/003[[:space:]]Confidentiality[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
47
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/004[[:space:]]Integrity[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
48
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/006[[:space:]]DAD[[:space:]]Triade[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
49
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/005[[:space:]]Availability[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
50
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/008[[:space:]]Non-Repudiation[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
51
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/007[[:space:]]Zero[[:space:]]Trust[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
52
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/009[[:space:]]Authentication[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
53
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/010[[:space:]]Authorization[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
54
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/012[[:space:]]Accountability[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
55
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/011[[:space:]]Accounting[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
56
+ 02[[:space:]]-[[:space:]]Lesson[[:space:]]1[[:space:]]IT[[:space:]]Security[[:space:]]Fundamentals/013[[:space:]]Gap[[:space:]]analysis[[:space:]]OB[[:space:]]1.2.mp4 filter=lfs diff=lfs merge=lfs -text
57
+ 03[[:space:]]-[[:space:]]Security[[:space:]]Controls[[:space:]]Categories[[:space:]]and[[:space:]]Types/002[[:space:]]Control[[:space:]]Types[[:space:]]OB[[:space:]]1.1.mp4 filter=lfs diff=lfs merge=lfs -text
58
+ 03[[:space:]]-[[:space:]]Security[[:space:]]Controls[[:space:]]Categories[[:space:]]and[[:space:]]Types/001[[:space:]]Control[[:space:]]Categories[[:space:]]OB[[:space:]]1.1.mp4 filter=lfs diff=lfs merge=lfs -text
59
+ 03[[:space:]]-[[:space:]]Security[[:space:]]Controls[[:space:]]Categories[[:space:]]and[[:space:]]Types/003[[:space:]]Defense[[:space:]]in[[:space:]]Depth[[:space:]]OB[[:space:]]1.1.mp4 filter=lfs diff=lfs merge=lfs -text
60
+ 04[[:space:]]-[[:space:]]Threats/002[[:space:]]Threats[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
61
+ 04[[:space:]]-[[:space:]]Threats/001[[:space:]]Threats[[:space:]]Motivation[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
62
+ 04[[:space:]]-[[:space:]]Threats/003[[:space:]]Attributes[[:space:]]of[[:space:]]Actors[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
63
+ 04[[:space:]]-[[:space:]]Threats/005[[:space:]]Unskilled[[:space:]]Attacker[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
64
+ 04[[:space:]]-[[:space:]]Threats/004[[:space:]]Nation-state[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
65
+ 04[[:space:]]-[[:space:]]Threats/006[[:space:]]Hacktivist[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
66
+ 04[[:space:]]-[[:space:]]Threats/007[[:space:]]Organized[[:space:]]Crime[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
67
+ 04[[:space:]]-[[:space:]]Threats/008[[:space:]]Shadow[[:space:]]IT[[:space:]]OB[[:space:]]2.1.mp4 filter=lfs diff=lfs merge=lfs -text
01 - Introduction/001 Course Layout.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:40ca94e4c14019c5944b32c20151709a537d7010d2fe6498f765fe9261e30d31
3
+ size 175684496
01 - Introduction/001 Course Layout_en.srt ADDED
@@ -0,0 +1,660 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ Okay, before we dive into the material, I want to go over the actual interface that you're going to
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:10,000
7
+ be using to navigate this course, how the courses laid out, what should you be expecting at the end
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:14,000
11
+ of every lecture and all the resources that's available to you?
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:15,000
15
+ Let's get started.
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:18,000
19
+ Now the first thing I want to mention is the layout of this course.
20
+
21
+ 6
22
+ 00:00:18,000 --> 00:00:24,000
23
+ So if you're watching this on the Udemy platform, you're very, very familiar with the layout of this
24
+
25
+ 7
26
+ 00:00:24,000 --> 00:00:27,000
27
+ particular class or the Udemy interface.
28
+
29
+ 8
30
+ 00:00:27,000 --> 00:00:35,000
31
+ In other words, so what it is is that the course is separated into 27 sections sections, the first
32
+
33
+ 9
34
+ 00:00:35,000 --> 00:00:41,000
35
+ one being the introduction all the way to section 25 covers all the exam topics.
36
+
37
+ 10
38
+ 00:00:41,000 --> 00:00:43,000
39
+ Section 26 is called labs.
40
+
41
+ 11
42
+ 00:00:43,000 --> 00:00:48,000
43
+ Labs are going to allow you to practice what I have been talking about for 25 sections or.
44
+
45
+ 12
46
+ 00:00:48,000 --> 00:00:52,000
47
+ And then finally the last one at the bottom says Mock exam.
48
+
49
+ 13
50
+ 00:00:52,000 --> 00:00:55,000
51
+ I know I'm blocking my camera here, seems to be blocking it.
52
+
53
+ 14
54
+ 00:00:55,000 --> 00:01:01,000
55
+ Um, there's one mock exam in this course that you guys should be taking when you finish the entire
56
+
57
+ 15
58
+ 00:01:01,000 --> 00:01:02,000
59
+ course.
60
+
61
+ 16
62
+ 00:01:02,000 --> 00:01:04,000
63
+ Now let's take a look at one of these sections.
64
+
65
+ 17
66
+ 00:01:04,000 --> 00:01:11,000
67
+ So these sections are basically labeled with some kind of security topics like section nine is secure
68
+
69
+ 18
70
+ 00:01:11,000 --> 00:01:11,000
71
+ and IT assets.
72
+
73
+ 19
74
+ 00:01:11,000 --> 00:01:13,000
75
+ Section 11 security principles.
76
+
77
+ 20
78
+ 00:01:13,000 --> 00:01:15,000
79
+ Section 12 data protection.
80
+
81
+ 21
82
+ 00:01:15,000 --> 00:01:20,000
83
+ Every time you open a section, you're going to find a series of lectures next to the name of every
84
+
85
+ 22
86
+ 00:01:20,000 --> 00:01:21,000
87
+ lecture.
88
+
89
+ 23
90
+ 00:01:21,000 --> 00:01:23,000
91
+ You're going to see something that says OB and then a number.
92
+
93
+ 24
94
+ 00:01:24,000 --> 00:01:28,000
95
+ This refers to the exam objectives that is coming from.
96
+
97
+ 25
98
+ 00:01:28,000 --> 00:01:33,000
99
+ And I'll explain to you guys in a few minutes what exactly are those exam objectives?
100
+
101
+ 26
102
+ 00:01:34,000 --> 00:01:38,000
103
+ At the end of every single one of the sections, you're going to have what's called a quick quiz.
104
+
105
+ 27
106
+ 00:01:38,000 --> 00:01:44,000
107
+ This is five questions that basically tested your knowledge on those particular topics that you just
108
+
109
+ 28
110
+ 00:01:44,000 --> 00:01:45,000
111
+ learned about in the section.
112
+
113
+ 29
114
+ 00:01:45,000 --> 00:01:49,000
115
+ So every one of the sections have a quick quiz located there.
116
+
117
+ 30
118
+ 00:01:50,000 --> 00:01:52,000
119
+ Um, so keep that in mind.
120
+
121
+ 31
122
+ 00:01:52,000 --> 00:01:57,000
123
+ Every single lecture has a number that comes after it.
124
+
125
+ 32
126
+ 00:01:57,000 --> 00:01:59,000
127
+ That number is the exam objectives.
128
+
129
+ 33
130
+ 00:01:59,000 --> 00:02:02,000
131
+ For example cryptography is objective 1.4.
132
+
133
+ 34
134
+ 00:02:02,000 --> 00:02:04,000
135
+ So that's how this is laid out.
136
+
137
+ 35
138
+ 00:02:04,000 --> 00:02:07,000
139
+ And you just basically click on it and it plays a video for you and you just watch it.
140
+
141
+ 36
142
+ 00:02:08,000 --> 00:02:10,000
143
+ Now what are the resources that comes with it?
144
+
145
+ 37
146
+ 00:02:10,000 --> 00:02:15,000
147
+ If there's one thing I did in this course is that I'm going to be giving you guys tons of resources
148
+
149
+ 38
150
+ 00:02:15,000 --> 00:02:16,000
151
+ that comes with it.
152
+
153
+ 39
154
+ 00:02:16,000 --> 00:02:19,000
155
+ So let's go to the resource section and see what they are.
156
+
157
+ 40
158
+ 00:02:19,000 --> 00:02:23,000
159
+ So in it it's in the introduction.
160
+
161
+ 41
162
+ 00:02:23,000 --> 00:02:27,000
163
+ And number three says course objectives notes and Cram Guide download.
164
+
165
+ 42
166
+ 00:02:27,000 --> 00:02:29,000
167
+ Now you just got to click on this.
168
+
169
+ 43
170
+ 00:02:29,000 --> 00:02:30,000
171
+ Click on every one of them.
172
+
173
+ 44
174
+ 00:02:30,000 --> 00:02:32,000
175
+ There's four things to download and just download it.
176
+
177
+ 45
178
+ 00:02:32,000 --> 00:02:35,000
179
+ They're all PDFs and let's go through what they are.
180
+
181
+ 46
182
+ 00:02:36,000 --> 00:02:41,000
183
+ So the first one up that you should be getting is this CompTIA Security+ exam objectives now.
184
+
185
+ 47
186
+ 00:02:42,000 --> 00:02:44,000
187
+ This CompTIA Security+.
188
+
189
+ 48
190
+ 00:02:44,000 --> 00:02:46,000
191
+ I've already downloaded it.
192
+
193
+ 49
194
+ 00:02:46,000 --> 00:02:50,000
195
+ This is the exam objectives that this entire course is based on.
196
+
197
+ 50
198
+ 00:02:50,000 --> 00:02:59,000
199
+ You guys are studying for Sio 701 or the 701 series of exam, and all the topics that I cover in this
200
+
201
+ 51
202
+ 00:02:59,000 --> 00:02:59,000
203
+ course.
204
+
205
+ 52
206
+ 00:02:59,000 --> 00:03:00,000
207
+ This is where I got it from.
208
+
209
+ 53
210
+ 00:03:00,000 --> 00:03:05,000
211
+ CompTIA publishers publishes this document absolutely free.
212
+
213
+ 54
214
+ 00:03:05,000 --> 00:03:06,000
215
+ You don't have to download it here.
216
+
217
+ 55
218
+ 00:03:06,000 --> 00:03:08,000
219
+ You could download it from Comptia's website.
220
+
221
+ 56
222
+ 00:03:08,000 --> 00:03:10,000
223
+ If you notice I covered some of this already.
224
+
225
+ 57
226
+ 00:03:11,000 --> 00:03:13,000
227
+ We talked about the exam stats.
228
+
229
+ 58
230
+ 00:03:13,000 --> 00:03:15,000
231
+ We talked about the domains that it has.
232
+
233
+ 59
234
+ 00:03:15,000 --> 00:03:20,000
235
+ But if I scroll down, you'll notice that it covers a lot more stuff.
236
+
237
+ 60
238
+ 00:03:20,000 --> 00:03:27,000
239
+ For example, in domain 1.0, general security concepts, it's that itself is broken down into four
240
+
241
+ 61
242
+ 00:03:27,000 --> 00:03:33,000
243
+ sections into 1.1, 1.2, 1.3 and 1.4.
244
+
245
+ 62
246
+ 00:03:33,000 --> 00:03:36,000
247
+ If you remember when we looked at cryptography.
248
+
249
+ 63
250
+ 00:03:38,000 --> 00:03:45,000
251
+ This is a three hour and 35 minute lesson, and in this one you have a 30 lectures actually.
252
+
253
+ 64
254
+ 00:03:45,000 --> 00:03:49,000
255
+ And you notice this is all objective 1.4, 1.41.4.
256
+
257
+ 65
258
+ 00:03:49,000 --> 00:03:50,000
259
+ What am I referring to these things?
260
+
261
+ 66
262
+ 00:03:50,000 --> 00:03:56,000
263
+ 1.4 if I look at the next section social engineering.
264
+
265
+ 67
266
+ 00:03:56,000 --> 00:03:59,000
267
+ Social engineering is objective 2.2.
268
+
269
+ 68
270
+ 00:03:59,000 --> 00:04:04,000
271
+ So if I look back here and I look at 2.2, here it is social engineering.
272
+
273
+ 69
274
+ 00:04:04,000 --> 00:04:10,000
275
+ So when you look at every lecture those numbers refers to this document, these things.
276
+
277
+ 70
278
+ 00:04:10,000 --> 00:04:12,000
279
+ This is the exam objective.
280
+
281
+ 71
282
+ 00:04:12,000 --> 00:04:18,000
283
+ Now what's good about the exam objective is that every single one of your questions will come from these
284
+
285
+ 72
286
+ 00:04:18,000 --> 00:04:19,000
287
+ exam objectives.
288
+
289
+ 73
290
+ 00:04:19,000 --> 00:04:26,000
291
+ No question should or would actually come from something outside of these objectives.
292
+
293
+ 74
294
+ 00:04:26,000 --> 00:04:31,000
295
+ If you want to test something that is foreign all right.
296
+
297
+ 75
298
+ 00:04:31,000 --> 00:04:33,000
299
+ They wouldn't put it on this exam.
300
+
301
+ 76
302
+ 00:04:33,000 --> 00:04:35,000
303
+ They wouldn't put it on this security+ test.
304
+
305
+ 77
306
+ 00:04:35,000 --> 00:04:38,000
307
+ Because technically speaking, they could only test you.
308
+
309
+ 78
310
+ 00:04:38,000 --> 00:04:40,000
311
+ What's on this exam objectives.
312
+
313
+ 79
314
+ 00:04:40,000 --> 00:04:43,000
315
+ Now it's from this objective that I create the other guides.
316
+
317
+ 80
318
+ 00:04:43,000 --> 00:04:43,000
319
+ All right.
320
+
321
+ 81
322
+ 00:04:43,000 --> 00:04:44,000
323
+ And I'll show you what I mean.
324
+
325
+ 82
326
+ 00:04:45,000 --> 00:04:48,000
327
+ So make sure you download this and just give a quick review to this.
328
+
329
+ 83
330
+ 00:04:49,000 --> 00:04:52,000
331
+ The other one here I have is going to be.
332
+
333
+ 84
334
+ 00:04:53,000 --> 00:04:54,000
335
+ Course notes.
336
+
337
+ 85
338
+ 00:04:54,000 --> 00:04:55,000
339
+ Now this is really good.
340
+
341
+ 86
342
+ 00:04:55,000 --> 00:04:57,000
343
+ You guys are going to love this one.
344
+
345
+ 87
346
+ 00:04:57,000 --> 00:04:58,000
347
+ Course notes.
348
+
349
+ 88
350
+ 00:04:58,000 --> 00:05:02,000
351
+ Course notes are every single text.
352
+
353
+ 89
354
+ 00:05:02,000 --> 00:05:06,000
355
+ So when I'm presenting you see me point on this section over here.
356
+
357
+ 90
358
+ 00:05:06,000 --> 00:05:08,000
359
+ And you notice that they're text that appears here.
360
+
361
+ 91
362
+ 00:05:08,000 --> 00:05:10,000
363
+ And I explained the text and we talk about it.
364
+
365
+ 92
366
+ 00:05:10,000 --> 00:05:13,000
367
+ And I tell you what you need to know for your exam and so on and so on.
368
+
369
+ 93
370
+ 00:05:13,000 --> 00:05:15,000
371
+ Those texts is this course notes.
372
+
373
+ 94
374
+ 00:05:15,000 --> 00:05:17,000
375
+ Now it is a lot.
376
+
377
+ 95
378
+ 00:05:17,000 --> 00:05:21,000
379
+ It is 850 pages of notes.
380
+
381
+ 96
382
+ 00:05:21,000 --> 00:05:28,000
383
+ As you can see, this is a great set of tools that or I should say content that you can use just to
384
+
385
+ 97
386
+ 00:05:28,000 --> 00:05:28,000
387
+ study.
388
+
389
+ 98
390
+ 00:05:28,000 --> 00:05:32,000
391
+ If you don't like me, you don't like the way I sound is Andrew, you're too ugly.
392
+
393
+ 99
394
+ 00:05:32,000 --> 00:05:34,000
395
+ You need to get some hair on your head.
396
+
397
+ 100
398
+ 00:05:34,000 --> 00:05:35,000
399
+ Basically, you can read this.
400
+
401
+ 101
402
+ 00:05:35,000 --> 00:05:39,000
403
+ I mean, whatever I'm covering is going to be here, so make sure to review this.
404
+
405
+ 102
406
+ 00:05:39,000 --> 00:05:40,000
407
+ This is a great thing.
408
+
409
+ 103
410
+ 00:05:40,000 --> 00:05:41,000
411
+ It's 850.
412
+
413
+ 104
414
+ 00:05:41,000 --> 00:05:47,000
415
+ And every single text that I'm going to be covering, every single text that you see on the right side
416
+
417
+ 105
418
+ 00:05:47,000 --> 00:05:50,000
419
+ of me as I'm teaching is in that PDF.
420
+
421
+ 106
422
+ 00:05:50,000 --> 00:05:55,000
423
+ If you think that's pretty cool, I got something even cooler for you that I'm really proud about because
424
+
425
+ 107
426
+ 00:05:55,000 --> 00:05:56,000
427
+ I think it's pretty cool.
428
+
429
+ 108
430
+ 00:05:58,000 --> 00:06:02,000
431
+ That's going to be this thing, the security plus the last minute cram guide.
432
+
433
+ 109
434
+ 00:06:02,000 --> 00:06:09,000
435
+ So the last minute cram guide is actually a book that I sell on Amazon.
436
+
437
+ 110
438
+ 00:06:10,000 --> 00:06:18,000
439
+ Um, and this particular book, basically it's 84 pages and it explains every single one of the exam
440
+
441
+ 111
442
+ 00:06:18,000 --> 00:06:19,000
443
+ objectives for you.
444
+
445
+ 112
446
+ 00:06:20,000 --> 00:06:23,000
447
+ So here's what I did I took the exam objectives.
448
+
449
+ 113
450
+ 00:06:24,000 --> 00:06:24,000
451
+ All right.
452
+
453
+ 114
454
+ 00:06:24,000 --> 00:06:30,000
455
+ If you remember, there's five domains and I explained every single one.
456
+
457
+ 115
458
+ 00:06:30,000 --> 00:06:31,000
459
+ So here's objective 1.1.
460
+
461
+ 116
462
+ 00:06:32,000 --> 00:06:37,000
463
+ And technical security controls managerial security controls operations security physical security controls.
464
+
465
+ 117
466
+ 00:06:37,000 --> 00:06:39,000
467
+ And I explained every single one there.
468
+
469
+ 118
470
+ 00:06:39,000 --> 00:06:42,000
471
+ So if you look at the exam objectives.
472
+
473
+ 119
474
+ 00:06:44,000 --> 00:06:45,000
475
+ Where is it.
476
+
477
+ 120
478
+ 00:06:45,000 --> 00:06:51,000
479
+ Let's say one okay so 1.1 categories technical managerial operational physical.
480
+
481
+ 121
482
+ 00:06:51,000 --> 00:06:54,000
483
+ If you notice in my cram guide.
484
+
485
+ 122
486
+ 00:06:56,000 --> 00:06:57,000
487
+ Where is my gram guide?
488
+
489
+ 123
490
+ 00:06:58,000 --> 00:07:00,000
491
+ Here we go in my gram guide.
492
+
493
+ 124
494
+ 00:07:00,000 --> 00:07:02,000
495
+ I explain it to you just like that.
496
+
497
+ 125
498
+ 00:07:03,000 --> 00:07:04,000
499
+ You see this?
500
+
501
+ 126
502
+ 00:07:04,000 --> 00:07:09,000
503
+ Technical, managerial, physical, operational.
504
+
505
+ 127
506
+ 00:07:09,000 --> 00:07:10,000
507
+ All explained there.
508
+
509
+ 128
510
+ 00:07:10,000 --> 00:07:11,000
511
+ All right.
512
+
513
+ 129
514
+ 00:07:11,000 --> 00:07:15,000
515
+ Preventative deterrent, detective corrective.
516
+
517
+ 130
518
+ 00:07:15,000 --> 00:07:17,000
519
+ I just explained that.
520
+
521
+ 131
522
+ 00:07:17,000 --> 00:07:19,000
523
+ And if you look in your exam objectives, that's the way you see it.
524
+
525
+ 132
526
+ 00:07:19,000 --> 00:07:21,000
527
+ So this guide is absolutely amazing.
528
+
529
+ 133
530
+ 00:07:21,000 --> 00:07:25,000
531
+ This guide explains every single thing you need to know to pass your test.
532
+
533
+ 134
534
+ 00:07:25,000 --> 00:07:27,000
535
+ Now, I took this exam.
536
+
537
+ 135
538
+ 00:07:27,000 --> 00:07:30,000
539
+ I'm one of the few teachers that actually takes the test that they teach.
540
+
541
+ 136
542
+ 00:07:30,000 --> 00:07:31,000
543
+ Oddly enough.
544
+
545
+ 137
546
+ 00:07:31,000 --> 00:07:37,000
547
+ Now on this particular exam, they're going to acronym you to death.
548
+
549
+ 138
550
+ 00:07:37,000 --> 00:07:42,000
551
+ There's tons of acronym on the Security Plus exam, and they don't explain them on the test.
552
+
553
+ 139
554
+ 00:07:42,000 --> 00:07:43,000
555
+ They'll just say SLA.
556
+
557
+ 140
558
+ 00:07:43,000 --> 00:07:44,000
559
+ You better know what it means.
560
+
561
+ 141
562
+ 00:07:44,000 --> 00:07:49,000
563
+ So what I did was I went to the exam objectives and they actually give you a list of the acronyms.
564
+
565
+ 142
566
+ 00:07:49,000 --> 00:07:53,000
567
+ And I put it into my document and I explained every one for you.
568
+
569
+ 143
570
+ 00:07:53,000 --> 00:07:55,000
571
+ So at the end of this cram guide.
572
+
573
+ 144
574
+ 00:07:56,000 --> 00:07:59,000
575
+ You have all these acronyms and you're probably saying, oh my God, that is a lot.
576
+
577
+ 145
578
+ 00:07:59,000 --> 00:08:02,000
579
+ Yeah, I didn't even realize there were so many acronyms.
580
+
581
+ 146
582
+ 00:08:03,000 --> 00:08:03,000
583
+ It's a lot.
584
+
585
+ 147
586
+ 00:08:04,000 --> 00:08:04,000
587
+ It's a lot.
588
+
589
+ 148
590
+ 00:08:04,000 --> 00:08:06,000
591
+ So you got you want to make sure you review this.
592
+
593
+ 149
594
+ 00:08:06,000 --> 00:08:07,000
595
+ You know what these acronyms are.
596
+
597
+ 150
598
+ 00:08:07,000 --> 00:08:09,000
599
+ Because these acronyms could pop up on your exam.
600
+
601
+ 151
602
+ 00:08:09,000 --> 00:08:11,000
603
+ And if you don't know what they mean, you're not going to get the question right.
604
+
605
+ 152
606
+ 00:08:11,000 --> 00:08:13,000
607
+ So it's quite a lot.
608
+
609
+ 153
610
+ 00:08:13,000 --> 00:08:16,000
611
+ And trust me, as you go through the course I'm basically going to cover all of them.
612
+
613
+ 154
614
+ 00:08:16,000 --> 00:08:19,000
615
+ So by the time you come to the cram guide, you're probably going to know it.
616
+
617
+ 155
618
+ 00:08:19,000 --> 00:08:22,000
619
+ So this is absolutely free of charge for you guys.
620
+
621
+ 156
622
+ 00:08:22,000 --> 00:08:26,000
623
+ I do charge a price on Amazon for this free of charge just for taking my course.
624
+
625
+ 157
626
+ 00:08:26,000 --> 00:08:29,000
627
+ Now the last thing is going to be the study plan.
628
+
629
+ 158
630
+ 00:08:29,000 --> 00:08:31,000
631
+ Now I'm going to do another video on the study plan.
632
+
633
+ 159
634
+ 00:08:32,000 --> 00:08:34,000
635
+ How do you pass your exam in 30 days?
636
+
637
+ 160
638
+ 00:08:34,000 --> 00:08:35,000
639
+ This is the plan for it.
640
+
641
+ 161
642
+ 00:08:35,000 --> 00:08:38,000
643
+ I'm going to do a whole video on it, uh, right after this.
644
+
645
+ 162
646
+ 00:08:39,000 --> 00:08:39,000
647
+ Okay.
648
+
649
+ 163
650
+ 00:08:39,000 --> 00:08:41,000
651
+ So that is everything you need to know.
652
+
653
+ 164
654
+ 00:08:41,000 --> 00:08:43,000
655
+ How is the course laid out?
656
+
657
+ 165
658
+ 00:08:43,000 --> 00:08:48,000
659
+ And of course, all the amazing resources that I'm going to be giving you to pass your test.
660
+
01 - Introduction/002 30 Day Study Plan.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:46213b5af735d10f09bf5b8ec1fd92c5e832ed74fabfb214a4f1b8f8e550e689
3
+ size 296593312
01 - Introduction/002 30 Day Study Plan_en.srt ADDED
@@ -0,0 +1,704 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:01,000
3
+ Let me ask you guys a question.
4
+
5
+ 2
6
+ 00:00:02,000 --> 00:00:09,000
7
+ If I told you that if you study for just two hours a day, you can be security+ certified in less than
8
+
9
+ 3
10
+ 00:00:09,000 --> 00:00:10,000
11
+ 30 days.
12
+
13
+ 4
14
+ 00:00:10,000 --> 00:00:11,000
15
+ Would you believe me?
16
+
17
+ 5
18
+ 00:00:11,000 --> 00:00:16,000
19
+ Well, what if I give you an actual document that gives you the layout for that and tell you what you
20
+
21
+ 6
22
+ 00:00:16,000 --> 00:00:20,000
23
+ need to study every single day for 30 days?
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:23,000
27
+ You just got to put in about two hours of work.
28
+
29
+ 8
30
+ 00:00:23,000 --> 00:00:29,000
31
+ If you can put in two hours of work for 30 days, actually more like 28 days, you're going to actually
32
+
33
+ 9
34
+ 00:00:29,000 --> 00:00:31,000
35
+ pass your security plus exam.
36
+
37
+ 10
38
+ 00:00:31,000 --> 00:00:35,000
39
+ My study plan has helped thousands of students pass their exam on the first try.
40
+
41
+ 11
42
+ 00:00:35,000 --> 00:00:38,000
43
+ And in this course, I'm going to give you that study plan free of charge.
44
+
45
+ 12
46
+ 00:00:38,000 --> 00:00:42,000
47
+ All you got to do is just follow it, follow it and actually apply it.
48
+
49
+ 13
50
+ 00:00:42,000 --> 00:00:43,000
51
+ And you're going to pass your exam.
52
+
53
+ 14
54
+ 00:00:43,000 --> 00:00:47,000
55
+ Let's take a look at what it is now in the course.
56
+
57
+ 15
58
+ 00:00:47,000 --> 00:00:49,000
59
+ Go to the introduction section of the course.
60
+
61
+ 16
62
+ 00:00:49,000 --> 00:00:54,000
63
+ And in one of those you're going to find course objectives notes and Cram Guide download.
64
+
65
+ 17
66
+ 00:00:54,000 --> 00:00:57,000
67
+ One of the download is called a 30 day study plan.
68
+
69
+ 18
70
+ 00:00:57,000 --> 00:01:01,000
71
+ So I want to review that study plan with you now when you download this.
72
+
73
+ 19
74
+ 00:01:03,000 --> 00:01:04,000
75
+ It should open this up.
76
+
77
+ 20
78
+ 00:01:04,000 --> 00:01:05,000
79
+ So here it is.
80
+
81
+ 21
82
+ 00:01:05,000 --> 00:01:10,000
83
+ So this 30 day study plan is what I wrote that helps my students to pass.
84
+
85
+ 22
86
+ 00:01:10,000 --> 00:01:18,000
87
+ And you should be studying about two hours a day to actually get it done within 30 days.
88
+
89
+ 23
90
+ 00:01:18,000 --> 00:01:21,000
91
+ Now this plan is designed to take 1 to 2 months.
92
+
93
+ 24
94
+ 00:01:21,000 --> 00:01:21,000
95
+ You're saying.
96
+
97
+ 25
98
+ 00:01:21,000 --> 00:01:22,000
99
+ But you just said 30 days.
100
+
101
+ 26
102
+ 00:01:22,000 --> 00:01:25,000
103
+ Well, you you may not study every day.
104
+
105
+ 27
106
+ 00:01:25,000 --> 00:01:28,000
107
+ You may study for six days a week, six days a week.
108
+
109
+ 28
110
+ 00:01:29,000 --> 00:01:31,000
111
+ Over 30 days, about five weeks or so.
112
+
113
+ 29
114
+ 00:01:31,000 --> 00:01:32,000
115
+ So keep that in mind.
116
+
117
+ 30
118
+ 00:01:32,000 --> 00:01:34,000
119
+ You may not study every single day.
120
+
121
+ 31
122
+ 00:01:34,000 --> 00:01:36,000
123
+ So that's why I didn't name it Monday through Friday.
124
+
125
+ 32
126
+ 00:01:36,000 --> 00:01:38,000
127
+ I just put day one, day two, day three.
128
+
129
+ 33
130
+ 00:01:38,000 --> 00:01:42,000
131
+ Now, if you're good and you're really into it, you can get this done in less than a month.
132
+
133
+ 34
134
+ 00:01:42,000 --> 00:01:48,000
135
+ But if your schedule doesn't allow it, and sometimes you just need time to just relax a little bit,
136
+
137
+ 35
138
+ 00:01:48,000 --> 00:01:52,000
139
+ maybe study for six days a week or five days at a minimum and just get it over with.
140
+
141
+ 36
142
+ 00:01:52,000 --> 00:01:53,000
143
+ Let me tell you guys something.
144
+
145
+ 37
146
+ 00:01:54,000 --> 00:01:58,000
147
+ I believe in six weeks you better be certified fully.
148
+
149
+ 38
150
+ 00:01:58,000 --> 00:02:00,000
151
+ Most of you should do this in less than a month.
152
+
153
+ 39
154
+ 00:02:00,000 --> 00:02:02,000
155
+ Okay, keep that in mind.
156
+
157
+ 40
158
+ 00:02:02,000 --> 00:02:05,000
159
+ So let's go back here.
160
+
161
+ 41
162
+ 00:02:05,000 --> 00:02:07,000
163
+ You notice the first day of studying.
164
+
165
+ 42
166
+ 00:02:07,000 --> 00:02:09,000
167
+ What are you doing on the first day of studying?
168
+
169
+ 43
170
+ 00:02:09,000 --> 00:02:12,000
171
+ You're registering for the actual test.
172
+
173
+ 44
174
+ 00:02:12,000 --> 00:02:14,000
175
+ In 30 days from now.
176
+
177
+ 45
178
+ 00:02:14,000 --> 00:02:15,000
179
+ This is a must do.
180
+
181
+ 46
182
+ 00:02:15,000 --> 00:02:16,000
183
+ I put it as a must do.
184
+
185
+ 47
186
+ 00:02:16,000 --> 00:02:17,000
187
+ What do you mean by that?
188
+
189
+ 48
190
+ 00:02:18,000 --> 00:02:19,000
191
+ Let me tell you guys something.
192
+
193
+ 49
194
+ 00:02:19,000 --> 00:02:20,000
195
+ I'm a slacker.
196
+
197
+ 50
198
+ 00:02:20,000 --> 00:02:22,000
199
+ But I got 66 certifications.
200
+
201
+ 51
202
+ 00:02:22,000 --> 00:02:24,000
203
+ I've taken over 100 exams.
204
+
205
+ 52
206
+ 00:02:24,000 --> 00:02:25,000
207
+ No, I didn't fail a lot.
208
+
209
+ 53
210
+ 00:02:25,000 --> 00:02:28,000
211
+ It's just that some exams needs multiple.
212
+
213
+ 54
214
+ 00:02:28,000 --> 00:02:30,000
215
+ Some certifications needs multiple exams.
216
+
217
+ 55
218
+ 00:02:30,000 --> 00:02:32,000
219
+ Like the Omcs needed seven exams.
220
+
221
+ 56
222
+ 00:02:32,000 --> 00:02:36,000
223
+ Now here's what I believe.
224
+
225
+ 57
226
+ 00:02:36,000 --> 00:02:38,000
227
+ I don't trust myself.
228
+
229
+ 58
230
+ 00:02:38,000 --> 00:02:39,000
231
+ Do you trust yourself?
232
+
233
+ 59
234
+ 00:02:39,000 --> 00:02:40,000
235
+ I don't trust myself.
236
+
237
+ 60
238
+ 00:02:40,000 --> 00:02:42,000
239
+ I work better when I'm under pressure.
240
+
241
+ 61
242
+ 00:02:42,000 --> 00:02:44,000
243
+ So here's what I'm going to do.
244
+
245
+ 62
246
+ 00:02:44,000 --> 00:02:50,000
247
+ Anytime I want to take a certification exam, I actually go and schedule it before I actually study
248
+
249
+ 63
250
+ 00:02:50,000 --> 00:02:51,000
251
+ for it.
252
+
253
+ 64
254
+ 00:02:51,000 --> 00:02:53,000
255
+ Yeah, it sounds crazy, but it's true.
256
+
257
+ 65
258
+ 00:02:53,000 --> 00:02:55,000
259
+ And I want you guys to do the same.
260
+
261
+ 66
262
+ 00:02:55,000 --> 00:02:56,000
263
+ Here's what I want you guys to do.
264
+
265
+ 67
266
+ 00:02:56,000 --> 00:02:59,000
267
+ If you're watching this video, you're already enrolled in the course.
268
+
269
+ 68
270
+ 00:02:59,000 --> 00:03:00,000
271
+ Here's what here's what you're going to do.
272
+
273
+ 69
274
+ 00:03:00,000 --> 00:03:06,000
275
+ Go right now to Pearson Vue Vue e.com okay here's what you do.
276
+
277
+ 70
278
+ 00:03:06,000 --> 00:03:11,000
279
+ You go to view vue.com and what you're going to do.
280
+
281
+ 71
282
+ 00:03:11,000 --> 00:03:12,000
283
+ You're going to search for CompTIA.
284
+
285
+ 72
286
+ 00:03:13,000 --> 00:03:15,000
287
+ And you're going to have to pay the fee for the exam here.
288
+
289
+ 73
290
+ 00:03:15,000 --> 00:03:17,000
291
+ Because this is where it gets serious.
292
+
293
+ 74
294
+ 00:03:18,000 --> 00:03:22,000
295
+ If you have a login, if you've taken a previous CompTIA go ahead and log in.
296
+
297
+ 75
298
+ 00:03:23,000 --> 00:03:25,000
299
+ Uh, if not just click log in anyhow.
300
+
301
+ 76
302
+ 00:03:25,000 --> 00:03:27,000
303
+ And uh you can go ahead and sign up.
304
+
305
+ 77
306
+ 00:03:27,000 --> 00:03:29,000
307
+ Now make make an account with them.
308
+
309
+ 78
310
+ 00:03:29,000 --> 00:03:32,000
311
+ Follow your on screen directions from here.
312
+
313
+ 79
314
+ 00:03:32,000 --> 00:03:36,000
315
+ And you can then select the 701 when you're doing the 701 exam.
316
+
317
+ 80
318
+ 00:03:36,000 --> 00:03:38,000
319
+ And I want you guys to do this.
320
+
321
+ 81
322
+ 00:03:38,000 --> 00:03:41,000
323
+ Ask yourself how many days can you commit.
324
+
325
+ 82
326
+ 00:03:41,000 --> 00:03:44,000
327
+ Can you commit six days a week?
328
+
329
+ 83
330
+ 00:03:44,000 --> 00:03:47,000
331
+ Well, Andrew said it's going to take me about 30 days.
332
+
333
+ 84
334
+ 00:03:47,000 --> 00:03:49,000
335
+ The study plan is actually 28 days.
336
+
337
+ 85
338
+ 00:03:49,000 --> 00:03:49,000
339
+ All right.
340
+
341
+ 86
342
+ 00:03:49,000 --> 00:03:54,000
343
+ I say 30 days because maybe you're not going to commit every day.
344
+
345
+ 87
346
+ 00:03:54,000 --> 00:03:58,000
347
+ So I actually lay it out over 28 day period.
348
+
349
+ 88
350
+ 00:03:58,000 --> 00:04:00,000
351
+ So maybe you want to schedule it from four weeks from now.
352
+
353
+ 89
354
+ 00:04:00,000 --> 00:04:03,000
355
+ Or if your schedule is really busy, schedule it for five weeks from now.
356
+
357
+ 90
358
+ 00:04:03,000 --> 00:04:06,000
359
+ But I want you to schedule it.
360
+
361
+ 91
362
+ 00:04:06,000 --> 00:04:13,000
363
+ If you don't schedule this exam right now, you are not going to study as much as you want.
364
+
365
+ 92
366
+ 00:04:13,000 --> 00:04:16,000
367
+ The exam is not reality until you actually pay for it.
368
+
369
+ 93
370
+ 00:04:17,000 --> 00:04:18,000
371
+ Go and pay for it and schedule it.
372
+
373
+ 94
374
+ 00:04:18,000 --> 00:04:22,000
375
+ The worst case scenario, I promise you, is you're not going to fail.
376
+
377
+ 95
378
+ 00:04:22,000 --> 00:04:25,000
379
+ Worst case scenario is if you can't stick to my study plan.
380
+
381
+ 96
382
+ 00:04:25,000 --> 00:04:27,000
383
+ Because things happen in life.
384
+
385
+ 97
386
+ 00:04:27,000 --> 00:04:28,000
387
+ You lose your job.
388
+
389
+ 98
390
+ 00:04:28,000 --> 00:04:35,000
391
+ Something bad happened with the family, you know, whatever it is, uh, you can just reschedule it,
392
+
393
+ 99
394
+ 00:04:35,000 --> 00:04:35,000
395
+ all right?
396
+
397
+ 100
398
+ 00:04:35,000 --> 00:04:36,000
399
+ You can just reschedule it.
400
+
401
+ 101
402
+ 00:04:36,000 --> 00:04:39,000
403
+ They're going to charge you a fee of about 20, $30, I believe.
404
+
405
+ 102
406
+ 00:04:39,000 --> 00:04:40,000
407
+ It's not a lot.
408
+
409
+ 103
410
+ 00:04:40,000 --> 00:04:41,000
411
+ They're going to charge you a little fee.
412
+
413
+ 104
414
+ 00:04:41,000 --> 00:04:46,000
415
+ Consider it the tax you have to pay because you don't want to take it right away because you were slacking
416
+
417
+ 105
418
+ 00:04:46,000 --> 00:04:47,000
419
+ off or whatever it was.
420
+
421
+ 106
422
+ 00:04:47,000 --> 00:04:49,000
423
+ So schedule it.
424
+
425
+ 107
426
+ 00:04:49,000 --> 00:04:50,000
427
+ This will force you to study.
428
+
429
+ 108
430
+ 00:04:50,000 --> 00:04:54,000
431
+ This will push you to study, because then you're always going to say to yourself.
432
+
433
+ 109
434
+ 00:04:55,000 --> 00:04:55,000
435
+ I'm going to start.
436
+
437
+ 110
438
+ 00:04:55,000 --> 00:04:56,000
439
+ I'm tired today.
440
+
441
+ 111
442
+ 00:04:56,000 --> 00:04:59,000
443
+ I'm going to study tomorrow and I'm going to study four hours tomorrow, Andrew said.
444
+
445
+ 112
446
+ 00:04:59,000 --> 00:05:03,000
447
+ Study two, I'm gonna study four hours and the tomorrow comes on study six hours.
448
+
449
+ 113
450
+ 00:05:03,000 --> 00:05:04,000
451
+ And then you know what?
452
+
453
+ 114
454
+ 00:05:04,000 --> 00:05:05,000
455
+ On this weekend I'm going to put extra time.
456
+
457
+ 115
458
+ 00:05:05,000 --> 00:05:08,000
459
+ You never get around to it before, you know, two months, three months go by.
460
+
461
+ 116
462
+ 00:05:08,000 --> 00:05:09,000
463
+ You're not certified this way.
464
+
465
+ 117
466
+ 00:05:09,000 --> 00:05:11,000
467
+ I guarantee you're going to take your test.
468
+
469
+ 118
470
+ 00:05:11,000 --> 00:05:12,000
471
+ So please schedule your exam.
472
+
473
+ 119
474
+ 00:05:12,000 --> 00:05:14,000
475
+ I always do it.
476
+
477
+ 120
478
+ 00:05:14,000 --> 00:05:16,000
479
+ Quick tip or quick thing about me.
480
+
481
+ 121
482
+ 00:05:16,000 --> 00:05:17,000
483
+ What?
484
+
485
+ 122
486
+ 00:05:17,000 --> 00:05:18,000
487
+ I want to take an exam.
488
+
489
+ 123
490
+ 00:05:18,000 --> 00:05:23,000
491
+ I would schedule the exam before I even buy the book or before I even before I buy the book, or before
492
+
493
+ 124
494
+ 00:05:23,000 --> 00:05:25,000
495
+ I even know what what is on that test.
496
+
497
+ 125
498
+ 00:05:25,000 --> 00:05:27,000
499
+ I go ahead and I schedule it that way.
500
+
501
+ 126
502
+ 00:05:27,000 --> 00:05:29,000
503
+ I'm forced to actually do it.
504
+
505
+ 127
506
+ 00:05:30,000 --> 00:05:32,000
507
+ And then you just follow the study plan.
508
+
509
+ 128
510
+ 00:05:32,000 --> 00:05:34,000
511
+ So here we go.
512
+
513
+ 129
514
+ 00:05:34,000 --> 00:05:35,000
515
+ Section two.
516
+
517
+ 130
518
+ 00:05:35,000 --> 00:05:39,000
519
+ So day one every day is about two hours of work.
520
+
521
+ 131
522
+ 00:05:39,000 --> 00:05:43,000
523
+ So you notice they want I got you doing section two, three and four.
524
+
525
+ 132
526
+ 00:05:43,000 --> 00:05:44,000
527
+ So let's take a look at that.
528
+
529
+ 133
530
+ 00:05:44,000 --> 00:05:49,000
531
+ So section two 41 minutes three 14 minutes for 40 minutes.
532
+
533
+ 134
534
+ 00:05:49,000 --> 00:05:52,000
535
+ So combined these are about two hours.
536
+
537
+ 135
538
+ 00:05:53,000 --> 00:05:57,000
539
+ Uh section one day two you're doing two sections.
540
+
541
+ 136
542
+ 00:05:57,000 --> 00:06:00,000
543
+ Sections five and six vulnerabilities and signs of attacks.
544
+
545
+ 137
546
+ 00:06:00,000 --> 00:06:03,000
547
+ So vulnerabilities uh signs of attack.
548
+
549
+ 138
550
+ 00:06:04,000 --> 00:06:06,000
551
+ So this one's going to be a little bit longer, right.
552
+
553
+ 139
554
+ 00:06:06,000 --> 00:06:10,000
555
+ It's going to come out to close to 2.5 hours I believe.
556
+
557
+ 140
558
+ 00:06:11,000 --> 00:06:13,000
559
+ And then section day three and four.
560
+
561
+ 141
562
+ 00:06:13,000 --> 00:06:16,000
563
+ Cryptography is tough, so I actually broke it into two days for you.
564
+
565
+ 142
566
+ 00:06:16,000 --> 00:06:18,000
567
+ Uh, and then this this keeps on going.
568
+
569
+ 143
570
+ 00:06:18,000 --> 00:06:20,000
571
+ You just follow the entire.
572
+
573
+ 144
574
+ 00:06:20,000 --> 00:06:23,000
575
+ Just keep following this, keep on going through with it.
576
+
577
+ 145
578
+ 00:06:23,000 --> 00:06:29,000
579
+ And now coming down towards the end of it, you'll notice the 19.
580
+
581
+ 146
582
+ 00:06:29,000 --> 00:06:31,000
583
+ I got the mock exam in the course.
584
+
585
+ 147
586
+ 00:06:32,000 --> 00:06:32,000
587
+ All right.
588
+
589
+ 148
590
+ 00:06:32,000 --> 00:06:35,000
591
+ Now the mock exam I'm talking about is in this course.
592
+
593
+ 149
594
+ 00:06:35,000 --> 00:06:36,000
595
+ It's at the bottom here.
596
+
597
+ 150
598
+ 00:06:36,000 --> 00:06:37,000
599
+ Mock exam.
600
+
601
+ 151
602
+ 00:06:37,000 --> 00:06:39,000
603
+ In this particular course.
604
+
605
+ 152
606
+ 00:06:39,000 --> 00:06:41,000
607
+ So you do this one.
608
+
609
+ 153
610
+ 00:06:41,000 --> 00:06:45,000
611
+ Now remember there is another course on Udemy that is mock exams.
612
+
613
+ 154
614
+ 00:06:45,000 --> 00:06:47,000
615
+ Get that course from me.
616
+
617
+ 155
618
+ 00:06:47,000 --> 00:06:48,000
619
+ That's also my course.
620
+
621
+ 156
622
+ 00:06:48,000 --> 00:06:49,000
623
+ Make sure it comes from me.
624
+
625
+ 157
626
+ 00:06:49,000 --> 00:06:52,000
627
+ It's the um security plus practice and there's six of them there.
628
+
629
+ 158
630
+ 00:06:52,000 --> 00:06:53,000
631
+ Notice I have one.
632
+
633
+ 159
634
+ 00:06:53,000 --> 00:06:54,000
635
+ You doing one every day.
636
+
637
+ 160
638
+ 00:06:55,000 --> 00:06:58,000
639
+ Because they take 90 minutes and you're going to want to review what you get wrong.
640
+
641
+ 161
642
+ 00:06:58,000 --> 00:07:00,000
643
+ So there you go with the two hours.
644
+
645
+ 162
646
+ 00:07:00,000 --> 00:07:04,000
647
+ And then day 2627 you're reviewing the cramped the last minute guide.
648
+
649
+ 163
650
+ 00:07:05,000 --> 00:07:07,000
651
+ Now I just spoke about the last minute guide.
652
+
653
+ 164
654
+ 00:07:08,000 --> 00:07:11,000
655
+ The last minute guide, if you forgot was this download.
656
+
657
+ 165
658
+ 00:07:11,000 --> 00:07:19,000
659
+ And inside of this download you have every single one of the exam objectives that's covered.
660
+
661
+ 166
662
+ 00:07:19,000 --> 00:07:22,000
663
+ And you have the acronym list that you want to do a quick review on.
664
+
665
+ 167
666
+ 00:07:22,000 --> 00:07:25,000
667
+ So all the exam objectives and the acronym list.
668
+
669
+ 168
670
+ 00:07:27,000 --> 00:07:31,000
671
+ I give you two days to review this, to do maybe 40 page, 40 pages, and then day 28, take the test
672
+
673
+ 169
674
+ 00:07:31,000 --> 00:07:32,000
675
+ and get it over with.
676
+
677
+ 170
678
+ 00:07:33,000 --> 00:07:36,000
679
+ So this is follow the study plan the way you see it.
680
+
681
+ 171
682
+ 00:07:36,000 --> 00:07:41,000
683
+ And if you can do that you're going to ace your exam I promise you.
684
+
685
+ 172
686
+ 00:07:41,000 --> 00:07:41,000
687
+ All right.
688
+
689
+ 173
690
+ 00:07:41,000 --> 00:07:46,000
691
+ Tons of my students, thousands of my students have used this study plan from my previous one.
692
+
693
+ 174
694
+ 00:07:46,000 --> 00:07:48,000
695
+ When I teach the live class, I give them all this.
696
+
697
+ 175
698
+ 00:07:48,000 --> 00:07:51,000
699
+ I didn't use to do it before my e-learning class, but now it's here.
700
+
701
+ 176
702
+ 00:07:51,000 --> 00:07:57,000
703
+ So do this and I guarantee you you are going to ace your exam on the first try.
704
+
01 - Introduction/003 Exam Information.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:ad2492a214f6c9acd6fe654f163609569083986724d8f6219cab527675a298ea
3
+ size 174300628
01 - Introduction/003 Exam Information_en.srt ADDED
@@ -0,0 +1,568 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ The Security+ certification is offered by a company called CompTIA, which stands for Comp.
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:10,000
7
+ It stands for the Computer to Technology Industry Association.
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:14,000
11
+ Now CompTIA has been around for about, I think three decades now.
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:18,000
15
+ And their most famous certification is the A+ certification.
16
+
17
+ 5
18
+ 00:00:18,000 --> 00:00:22,000
19
+ Now, their second most famous is probably going to be Network+ or Security+.
20
+
21
+ 6
22
+ 00:00:22,000 --> 00:00:25,000
23
+ And I think Security+ is more famous now.
24
+
25
+ 7
26
+ 00:00:25,000 --> 00:00:29,000
27
+ So if you want to become Security+ certified, I'm going to walk you through some of the things you
28
+
29
+ 8
30
+ 00:00:29,000 --> 00:00:30,000
31
+ have to do in this video.
32
+
33
+ 9
34
+ 00:00:30,000 --> 00:00:35,000
35
+ And one good thing is that you only have to take one exam in order to be certified.
36
+
37
+ 10
38
+ 00:00:35,000 --> 00:00:39,000
39
+ You just got to pass one certification exam.
40
+
41
+ 11
42
+ 00:00:39,000 --> 00:00:42,000
43
+ And let's take a look at the stats on this exam.
44
+
45
+ 12
46
+ 00:00:42,000 --> 00:00:47,000
47
+ Now, this particular course is designed to help you pass the CIO 701.
48
+
49
+ 13
50
+ 00:00:47,000 --> 00:00:52,000
51
+ You want to make sure that you know this particular number as that's the exam you're taking.
52
+
53
+ 14
54
+ 00:00:52,000 --> 00:00:55,000
55
+ Depending on when you're watching this video and when you're taking this course.
56
+
57
+ 15
58
+ 00:00:55,000 --> 00:00:59,000
59
+ As this video is being made, there is a 601 exam or the older exam.
60
+
61
+ 16
62
+ 00:00:59,000 --> 00:01:04,000
63
+ So this course is for this current, this newer exam I should say 701.
64
+
65
+ 17
66
+ 00:01:04,000 --> 00:01:06,000
67
+ So remember that's the exam you're taking.
68
+
69
+ 18
70
+ 00:01:06,000 --> 00:01:06,000
71
+ Why.
72
+
73
+ 19
74
+ 00:01:06,000 --> 00:01:11,000
75
+ Because when you go to register and at the end of this video I'll talk about where to register for the
76
+
77
+ 20
78
+ 00:01:11,000 --> 00:01:12,000
79
+ exam.
80
+
81
+ 21
82
+ 00:01:12,000 --> 00:01:17,000
83
+ Now when you're ready to register for the exam you're going to make sure you select this exam.
84
+
85
+ 22
86
+ 00:01:17,000 --> 00:01:23,000
87
+ Now the exam is 90 minutes in duration, as you can see here with a maximum of 90 questions.
88
+
89
+ 23
90
+ 00:01:23,000 --> 00:01:26,000
91
+ Now, I did take this exam a few days after it came out.
92
+
93
+ 24
94
+ 00:01:26,000 --> 00:01:29,000
95
+ I think it came out like November 6th, 2023.
96
+
97
+ 25
98
+ 00:01:29,000 --> 00:01:32,000
99
+ I took it like November 8th or November 9th I did.
100
+
101
+ 26
102
+ 00:01:32,000 --> 00:01:36,000
103
+ I'm going to do a video on that on the YouTube channel that talks about my experience.
104
+
105
+ 27
106
+ 00:01:36,000 --> 00:01:38,000
107
+ Now in my exam, I got 77 questions.
108
+
109
+ 28
110
+ 00:01:38,000 --> 00:01:43,000
111
+ So some of you guys may get less than 90 questions or up to 90 questions.
112
+
113
+ 29
114
+ 00:01:43,000 --> 00:01:46,000
115
+ So keep that in mind maximum of 90 questions.
116
+
117
+ 30
118
+ 00:01:46,000 --> 00:01:50,000
119
+ Now keep in mind that you're probably going to get a lot less, maybe 80 something questions or the
120
+
121
+ 31
122
+ 00:01:50,000 --> 00:01:52,000
123
+ late 70 questions.
124
+
125
+ 32
126
+ 00:01:52,000 --> 00:01:54,000
127
+ Now your exam have three types of question.
128
+
129
+ 33
130
+ 00:01:54,000 --> 00:01:59,000
131
+ What's called multiple choice drag and drop, and performance based or simulation based questions.
132
+
133
+ 34
134
+ 00:01:59,000 --> 00:02:02,000
135
+ These here are pretty simple multiple choice questions.
136
+
137
+ 35
138
+ 00:02:02,000 --> 00:02:05,000
139
+ You're just going to choose one of those choices that is there.
140
+
141
+ 36
142
+ 00:02:05,000 --> 00:02:07,000
143
+ Some of the questions is going to have you choose MultiChoice.
144
+
145
+ 37
146
+ 00:02:07,000 --> 00:02:10,000
147
+ So it's going to say choose two or choose three.
148
+
149
+ 38
150
+ 00:02:10,000 --> 00:02:12,000
151
+ They never do choose all or choose many.
152
+
153
+ 39
154
+ 00:02:12,000 --> 00:02:15,000
155
+ They'll just say uh, choose two or choose three.
156
+
157
+ 40
158
+ 00:02:15,000 --> 00:02:16,000
159
+ You're not going to get a lot of those.
160
+
161
+ 41
162
+ 00:02:16,000 --> 00:02:18,000
163
+ So let's say the test had 90 questions.
164
+
165
+ 42
166
+ 00:02:19,000 --> 00:02:22,000
167
+ I'm telling you guys, 80 of them is going to be choose one answer.
168
+
169
+ 43
170
+ 00:02:22,000 --> 00:02:25,000
171
+ Maybe three, 4 or 5 of them is going to be multi choice.
172
+
173
+ 44
174
+ 00:02:25,000 --> 00:02:30,000
175
+ And you're probably going to get as soon as the exam begins, you're going to get a drag and drop or
176
+
177
+ 45
178
+ 00:02:30,000 --> 00:02:31,000
179
+ a performance based simulator.
180
+
181
+ 46
182
+ 00:02:31,000 --> 00:02:37,000
183
+ Now again it depends when you're watching this video I did get a drag and drop questions where you had
184
+
185
+ 47
186
+ 00:02:37,000 --> 00:02:40,000
187
+ to match attacks to how to mitigate this attack.
188
+
189
+ 48
190
+ 00:02:40,000 --> 00:02:41,000
191
+ So to give you a scenario.
192
+
193
+ 49
194
+ 00:02:41,000 --> 00:02:42,000
195
+ And they said, what attack is this?
196
+
197
+ 50
198
+ 00:02:42,000 --> 00:02:44,000
199
+ And you had to match it to that.
200
+
201
+ 51
202
+ 00:02:44,000 --> 00:02:45,000
203
+ And then how would you fix that attack.
204
+
205
+ 52
206
+ 00:02:45,000 --> 00:02:47,000
207
+ That's basically a drag and drop.
208
+
209
+ 53
210
+ 00:02:47,000 --> 00:02:51,000
211
+ The other one you're going to have is sometimes you get a performance based simulator where you may
212
+
213
+ 54
214
+ 00:02:51,000 --> 00:02:57,000
215
+ have to read some kind of text file and decode what that says.
216
+
217
+ 55
218
+ 00:02:57,000 --> 00:02:58,000
219
+ Is this machine hacked?
220
+
221
+ 56
222
+ 00:02:58,000 --> 00:02:59,000
223
+ Is it good?
224
+
225
+ 57
226
+ 00:02:59,000 --> 00:03:01,000
227
+ Here is the log files that go with that.
228
+
229
+ 58
230
+ 00:03:01,000 --> 00:03:03,000
231
+ So that's what this is.
232
+
233
+ 59
234
+ 00:03:03,000 --> 00:03:05,000
235
+ Now these are pretty they're pretty simple in my opinion.
236
+
237
+ 60
238
+ 00:03:05,000 --> 00:03:07,000
239
+ Especially if you do some of the labs.
240
+
241
+ 61
242
+ 00:03:07,000 --> 00:03:08,000
243
+ They're pretty simple.
244
+
245
+ 62
246
+ 00:03:08,000 --> 00:03:14,000
247
+ The drag and drop to me is even more simple that you just have to know, uh, know how to fix problems
248
+
249
+ 63
250
+ 00:03:14,000 --> 00:03:16,000
251
+ or know how to resolve a particular attack.
252
+
253
+ 64
254
+ 00:03:16,000 --> 00:03:20,000
255
+ Now, this exam is pretty scary because of this right here.
256
+
257
+ 65
258
+ 00:03:20,000 --> 00:03:26,000
259
+ You see, right here you need 750 out of 900 points.
260
+
261
+ 66
262
+ 00:03:26,000 --> 00:03:32,000
263
+ Now that basically comes out to 83% is what you have to score on it.
264
+
265
+ 67
266
+ 00:03:32,000 --> 00:03:35,000
267
+ Now, when I took this exam, I didn't find it difficult.
268
+
269
+ 68
270
+ 00:03:35,000 --> 00:03:38,000
271
+ It was mostly just terminologies.
272
+
273
+ 69
274
+ 00:03:38,000 --> 00:03:39,000
275
+ If you know the terminology.
276
+
277
+ 70
278
+ 00:03:39,000 --> 00:03:41,000
279
+ This course comes with a study guide.
280
+
281
+ 71
282
+ 00:03:41,000 --> 00:03:43,000
283
+ So make sure to review that study guide.
284
+
285
+ 72
286
+ 00:03:43,000 --> 00:03:47,000
287
+ And I think you're going to be just fine as the course as the exam is basically just terminology off
288
+
289
+ 73
290
+ 00:03:47,000 --> 00:03:48,000
291
+ of the objectives.
292
+
293
+ 74
294
+ 00:03:48,000 --> 00:03:52,000
295
+ So if you know that I think you can accomplish this score pretty quick.
296
+
297
+ 75
298
+ 00:03:52,000 --> 00:03:56,000
299
+ Now the question is where do you take this exam.
300
+
301
+ 76
302
+ 00:03:56,000 --> 00:04:00,000
303
+ Now this exam is given at a company called Pearson Vue.
304
+
305
+ 77
306
+ 00:04:00,000 --> 00:04:04,000
307
+ Now Pearson Vue administers the exam for CompTIA.
308
+
309
+ 78
310
+ 00:04:04,000 --> 00:04:08,000
311
+ So I want you to hear these two terms CompTIA and Vue.
312
+
313
+ 79
314
+ 00:04:08,000 --> 00:04:10,000
315
+ Vue Aecom I'm going to show you the website in a minute.
316
+
317
+ 80
318
+ 00:04:10,000 --> 00:04:11,000
319
+ So.
320
+
321
+ 81
322
+ 00:04:12,000 --> 00:04:17,000
323
+ CompTIA is the person, the company that's going to certify you okay.
324
+
325
+ 82
326
+ 00:04:17,000 --> 00:04:22,000
327
+ They're the one that created the exam, the objectives and all that good stuff.
328
+
329
+ 83
330
+ 00:04:22,000 --> 00:04:25,000
331
+ Pearson Vue is the people that administers the exam.
332
+
333
+ 84
334
+ 00:04:25,000 --> 00:04:29,000
335
+ So when you're ready to take the test, you're going to want to go to Pearson Vue and take the test
336
+
337
+ 85
338
+ 00:04:29,000 --> 00:04:29,000
339
+ with them.
340
+
341
+ 86
342
+ 00:04:29,000 --> 00:04:31,000
343
+ How do you do that?
344
+
345
+ 87
346
+ 00:04:31,000 --> 00:04:32,000
347
+ Well let's go.
348
+
349
+ 88
350
+ 00:04:32,000 --> 00:04:34,000
351
+ I'm going to show you guys my desktop.
352
+
353
+ 89
354
+ 00:04:34,000 --> 00:04:35,000
355
+ Here we are at my desktop.
356
+
357
+ 90
358
+ 00:04:35,000 --> 00:04:42,000
359
+ I am going to go to Pearson Vue as soon as my browser opens up here at some point in the future.
360
+
361
+ 91
362
+ 00:04:43,000 --> 00:04:44,000
363
+ All right.
364
+
365
+ 92
366
+ 00:04:45,000 --> 00:04:45,000
367
+ Okay.
368
+
369
+ 93
370
+ 00:04:45,000 --> 00:04:47,000
371
+ I'll open up on the other screen.
372
+
373
+ 94
374
+ 00:04:47,000 --> 00:04:47,000
375
+ Okay.
376
+
377
+ 95
378
+ 00:04:47,000 --> 00:04:48,000
379
+ So here we are at Pearson Vue.
380
+
381
+ 96
382
+ 00:04:48,000 --> 00:04:51,000
383
+ So the website is just vue.com.
384
+
385
+ 97
386
+ 00:04:51,000 --> 00:04:56,000
387
+ So we're going to go here and we're going to say let's type in CompTIA.
388
+
389
+ 98
390
+ 00:04:57,000 --> 00:05:00,000
391
+ And this is how you're going to register for the test by the way.
392
+
393
+ 99
394
+ 00:05:00,000 --> 00:05:01,000
395
+ You just go to CompTIA.
396
+
397
+ 100
398
+ 00:05:01,000 --> 00:05:07,000
399
+ Now if you have taken a previous CompTIA exam you would say login okay.
400
+
401
+ 101
402
+ 00:05:07,000 --> 00:05:13,000
403
+ If you have never, ever taken a comp t exam, you follow the on screen prompts here and you're going
404
+
405
+ 102
406
+ 00:05:13,000 --> 00:05:17,000
407
+ to create an account on this website in order to.
408
+
409
+ 103
410
+ 00:05:17,000 --> 00:05:19,000
411
+ So you you could just basically click login.
412
+
413
+ 104
414
+ 00:05:19,000 --> 00:05:21,000
415
+ And then it's going to say, hey, don't have an account.
416
+
417
+ 105
418
+ 00:05:21,000 --> 00:05:22,000
419
+ You can sign up.
420
+
421
+ 106
422
+ 00:05:22,000 --> 00:05:25,000
423
+ If you don't have one, you can sign up for one right on their website.
424
+
425
+ 107
426
+ 00:05:25,000 --> 00:05:27,000
427
+ Now where do you take the test?
428
+
429
+ 108
430
+ 00:05:27,000 --> 00:05:33,000
431
+ Well, this exam is going to be given online at your home.
432
+
433
+ 109
434
+ 00:05:33,000 --> 00:05:36,000
435
+ That's where I tell most people to take the test.
436
+
437
+ 110
438
+ 00:05:36,000 --> 00:05:40,000
439
+ I don't recommend for you to take this exam at a testing center.
440
+
441
+ 111
442
+ 00:05:40,000 --> 00:05:44,000
443
+ So when you register, you're going to have the chance to go to a Pearson Vue testing center in your
444
+
445
+ 112
446
+ 00:05:44,000 --> 00:05:47,000
447
+ local neighborhood, and you can take the test there.
448
+
449
+ 113
450
+ 00:05:47,000 --> 00:05:48,000
451
+ I'm not a fan of that.
452
+
453
+ 114
454
+ 00:05:48,000 --> 00:05:56,000
455
+ The reason is because going to a testing center to take the exam is going to require you to travel to
456
+
457
+ 115
458
+ 00:05:56,000 --> 00:05:57,000
459
+ the testing center.
460
+
461
+ 116
462
+ 00:05:57,000 --> 00:06:00,000
463
+ You're going to have to make sure that you don't be late.
464
+
465
+ 117
466
+ 00:06:00,000 --> 00:06:02,000
467
+ If not, you're going to forfeit the exam.
468
+
469
+ 118
470
+ 00:06:02,000 --> 00:06:04,000
471
+ It's a pretty stressful environment.
472
+
473
+ 119
474
+ 00:06:04,000 --> 00:06:09,000
475
+ Their chairs are uncomfortable, their computer sucks, their keyboard is nasty, their screen is too
476
+
477
+ 120
478
+ 00:06:09,000 --> 00:06:10,000
479
+ small.
480
+
481
+ 121
482
+ 00:06:10,000 --> 00:06:11,000
483
+ It's a lot of security.
484
+
485
+ 122
486
+ 00:06:11,000 --> 00:06:13,000
487
+ They're going to pat you down.
488
+
489
+ 123
490
+ 00:06:13,000 --> 00:06:15,000
491
+ They're going to put a metal detector against you.
492
+
493
+ 124
494
+ 00:06:15,000 --> 00:06:19,000
495
+ They might hand scan you or take a biometric print of you.
496
+
497
+ 125
498
+ 00:06:19,000 --> 00:06:22,000
499
+ It's pretty much it's pretty stressful environment.
500
+
501
+ 126
502
+ 00:06:22,000 --> 00:06:24,000
503
+ If you do it at home, you're going to need two things.
504
+
505
+ 127
506
+ 00:06:24,000 --> 00:06:27,000
507
+ You're going to microphone and you're going to need a webcam on your computer.
508
+
509
+ 128
510
+ 00:06:28,000 --> 00:06:30,000
511
+ Technically three things because you need a quiet room.
512
+
513
+ 129
514
+ 00:06:30,000 --> 00:06:31,000
515
+ If you got that, you're good.
516
+
517
+ 130
518
+ 00:06:31,000 --> 00:06:35,000
519
+ If you have a laptop that comes with a built in micro camera, you're good.
520
+
521
+ 131
522
+ 00:06:35,000 --> 00:06:41,000
523
+ You can also if you have a all laptops pretty much nowadays have a microphone built in, you're fine.
524
+
525
+ 132
526
+ 00:06:41,000 --> 00:06:46,000
527
+ If not, you can just buy like a $50 webcam and just take the exam at home.
528
+
529
+ 133
530
+ 00:06:46,000 --> 00:06:49,000
531
+ Basically, they're going to install a piece of software on your computer, uh, a couple of minutes
532
+
533
+ 134
534
+ 00:06:49,000 --> 00:06:51,000
535
+ before the exam starts.
536
+
537
+ 135
538
+ 00:06:51,000 --> 00:06:55,000
539
+ They're going to test it, and you just sit and take it at home and you're certified directly from the
540
+
541
+ 136
542
+ 00:06:55,000 --> 00:06:59,000
543
+ comfort of your home, your chair, your computer, and a whole lot less stressful.
544
+
545
+ 137
546
+ 00:06:59,000 --> 00:07:00,000
547
+ All right.
548
+
549
+ 138
550
+ 00:07:00,000 --> 00:07:01,000
551
+ So keep that in mind.
552
+
553
+ 139
554
+ 00:07:01,000 --> 00:07:04,000
555
+ These things I do recommend to take the exam at home.
556
+
557
+ 140
558
+ 00:07:04,000 --> 00:07:05,000
559
+ Remember that.
560
+
561
+ 141
562
+ 00:07:05,000 --> 00:07:08,000
563
+ And then don't forget 90 minutes 90 questions.
564
+
565
+ 142
566
+ 00:07:08,000 --> 00:07:12,000
567
+ And you need 83% to pass to become certified.
568
+
01 - Introduction/004 Exam Domains.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:58c158a7a21ad26e9756520ff56a8f0091449cf0d55e1d770930954844448451
3
+ size 144894608
01 - Introduction/004 Exam Domains_en.srt ADDED
@@ -0,0 +1,456 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ Now, before we get into every single one of the topics in the exam objectives, I want to just give
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:08,000
7
+ you a brief overview of what exactly is covered on this test.
8
+
9
+ 3
10
+ 00:00:08,000 --> 00:00:12,000
11
+ So here I have this document or I should say this table.
12
+
13
+ 4
14
+ 00:00:12,000 --> 00:00:15,000
15
+ Now I got this out of the exam objectives.
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:20,000
19
+ Now you can download the Sy0 701 exam objectives from the CompTIA website.
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:26,000
23
+ Or if it's dependent on the platform that this video is hosted on, you could probably probably just
24
+
25
+ 7
26
+ 00:00:26,000 --> 00:00:27,000
27
+ attach it as a PDF.
28
+
29
+ 8
30
+ 00:00:27,000 --> 00:00:29,000
31
+ Again, it depends where this video is hosted on.
32
+
33
+ 9
34
+ 00:00:29,000 --> 00:00:30,000
35
+ I may or may not be able to do that.
36
+
37
+ 10
38
+ 00:00:30,000 --> 00:00:34,000
39
+ If not, you can get the exam objective from Comptia's website.
40
+
41
+ 11
42
+ 00:00:34,000 --> 00:00:36,000
43
+ So let's go over what exactly is this.
44
+
45
+ 12
46
+ 00:00:36,000 --> 00:00:43,000
47
+ And you can see that we got five domains that makes up all of the exam questions.
48
+
49
+ 13
50
+ 00:00:43,000 --> 00:00:44,000
51
+ So let's go over this.
52
+
53
+ 14
54
+ 00:00:44,000 --> 00:00:47,000
55
+ The first thing up I have is that general security concept.
56
+
57
+ 15
58
+ 00:00:47,000 --> 00:00:48,000
59
+ This is 12%.
60
+
61
+ 16
62
+ 00:00:48,000 --> 00:00:52,000
63
+ This is a domain that you're just going to learn basic terms like what is authentication.
64
+
65
+ 17
66
+ 00:00:52,000 --> 00:00:54,000
67
+ What is identification.
68
+
69
+ 18
70
+ 00:00:54,000 --> 00:00:55,000
71
+ What is confidentiality.
72
+
73
+ 19
74
+ 00:00:56,000 --> 00:01:00,000
75
+ Um, it does talk a little bit about physical security and how to classify different kinds of controls
76
+
77
+ 20
78
+ 00:01:00,000 --> 00:01:01,000
79
+ is going to be here.
80
+
81
+ 21
82
+ 00:01:01,000 --> 00:01:06,000
83
+ Now as a security professional, you're going to have to know all the different threats that affect
84
+
85
+ 22
86
+ 00:01:06,000 --> 00:01:12,000
87
+ your network, such as what's the DDoS attack, what's cross-site scripting, what SQL injections,
88
+
89
+ 23
90
+ 00:01:12,000 --> 00:01:18,000
91
+ what are the different threats, what makes your systems vulnerable, such as outdated or unpatched
92
+
93
+ 24
94
+ 00:01:18,000 --> 00:01:21,000
95
+ machines, and what can we do to fix those things?
96
+
97
+ 25
98
+ 00:01:21,000 --> 00:01:21,000
99
+ Right.
100
+
101
+ 26
102
+ 00:01:21,000 --> 00:01:24,000
103
+ What what can we implement to keep our systems more secure?
104
+
105
+ 27
106
+ 00:01:24,000 --> 00:01:28,000
107
+ Such as, hey, maybe you should at least patch your computers or keep them up to date at least.
108
+
109
+ 28
110
+ 00:01:28,000 --> 00:01:32,000
111
+ How do we design secure systems?
112
+
113
+ 29
114
+ 00:01:32,000 --> 00:01:33,000
115
+ Right?
116
+
117
+ 30
118
+ 00:01:33,000 --> 00:01:39,000
119
+ If we go out and we build a network, what should we be doing as we build secure networks?
120
+
121
+ 31
122
+ 00:01:39,000 --> 00:01:40,000
123
+ Is what number three are.
124
+
125
+ 32
126
+ 00:01:40,000 --> 00:01:44,000
127
+ Cover number four is security operations and day to day things that we should be doing.
128
+
129
+ 33
130
+ 00:01:44,000 --> 00:01:48,000
131
+ Like how do you secure and harden a router or switch for example, is going to be covered here.
132
+
133
+ 34
134
+ 00:01:48,000 --> 00:01:52,000
135
+ Notice this is one of the biggest domain with 28%.
136
+
137
+ 35
138
+ 00:01:52,000 --> 00:01:54,000
139
+ So quite a lot is covered in domain four.
140
+
141
+ 36
142
+ 00:01:54,000 --> 00:01:56,000
143
+ Now domain five is pretty simple.
144
+
145
+ 37
146
+ 00:01:56,000 --> 00:02:01,000
147
+ This is more administrative things such as understanding different types of policies and what security
148
+
149
+ 38
150
+ 00:02:01,000 --> 00:02:04,000
151
+ policies are what guidelines are also risk management.
152
+
153
+ 39
154
+ 00:02:05,000 --> 00:02:10,000
155
+ You're going to learn about how do we deal and manage with risk, how do we respond to certain risks,
156
+
157
+ 40
158
+ 00:02:10,000 --> 00:02:13,000
159
+ how do we deal and manage with vendors, for example?
160
+
161
+ 41
162
+ 00:02:13,000 --> 00:02:19,000
163
+ And finally, we'll take a look at user training in this particular section for a total of 100 points.
164
+
165
+ 42
166
+ 00:02:19,000 --> 00:02:22,000
167
+ Now I want you guys to remember that this is the weight of it.
168
+
169
+ 43
170
+ 00:02:22,000 --> 00:02:27,000
171
+ And in theory, in theory you should get questions by the weights.
172
+
173
+ 44
174
+ 00:02:27,000 --> 00:02:33,000
175
+ If CompTIA, for example, said there is up to 90 questions, technically you should get 18 questions
176
+
177
+ 45
178
+ 00:02:33,000 --> 00:02:35,000
179
+ from this domain.
180
+
181
+ 46
182
+ 00:02:35,000 --> 00:02:37,000
183
+ That's 20% of 90.
184
+
185
+ 47
186
+ 00:02:37,000 --> 00:02:38,000
187
+ And so on and so on.
188
+
189
+ 48
190
+ 00:02:39,000 --> 00:02:44,000
191
+ Um, but keep in mind that CompTIA really doesn't publish those numbers, doesn't say what you're going
192
+
193
+ 49
194
+ 00:02:44,000 --> 00:02:49,000
195
+ to get all these questions, uh, on on this particular topic, it's all scattered out all over the
196
+
197
+ 50
198
+ 00:02:49,000 --> 00:02:50,000
199
+ exam.
200
+
201
+ 51
202
+ 00:02:51,000 --> 00:02:51,000
203
+ Okay.
204
+
205
+ 52
206
+ 00:02:51,000 --> 00:02:57,000
207
+ So one of the things that you should you guys should be doing is going through the exam objectives.
208
+
209
+ 53
210
+ 00:02:57,000 --> 00:03:03,000
211
+ Now I have the exam objectives here that you can download from Comptia's website.
212
+
213
+ 54
214
+ 00:03:03,000 --> 00:03:07,000
215
+ And I want to show you guys what that document looks like.
216
+
217
+ 55
218
+ 00:03:08,000 --> 00:03:08,000
219
+ All right.
220
+
221
+ 56
222
+ 00:03:08,000 --> 00:03:09,000
223
+ So I do have it open.
224
+
225
+ 57
226
+ 00:03:09,000 --> 00:03:10,000
227
+ Let's take a look.
228
+
229
+ 58
230
+ 00:03:10,000 --> 00:03:16,000
231
+ So here's the um here's Comptia's exam objectives.
232
+
233
+ 59
234
+ 00:03:17,000 --> 00:03:18,000
235
+ Let me just make this bigger.
236
+
237
+ 60
238
+ 00:03:18,000 --> 00:03:22,000
239
+ And again, this is for the Sci 0701.
240
+
241
+ 61
242
+ 00:03:23,000 --> 00:03:26,000
243
+ Now you can see that this is the table I just showed you.
244
+
245
+ 62
246
+ 00:03:26,000 --> 00:03:28,000
247
+ We just went over this.
248
+
249
+ 63
250
+ 00:03:28,000 --> 00:03:32,000
251
+ Uh, we also went over this, the 1990 questions, 90 minutes and so on.
252
+
253
+ 64
254
+ 00:03:32,000 --> 00:03:41,000
255
+ But if we go down here, you guys see these, uh, all of these topics like general security, number
256
+
257
+ 65
258
+ 00:03:41,000 --> 00:03:46,000
259
+ 1.1, it goes through categories of controls, control types.
260
+
261
+ 66
262
+ 00:03:46,000 --> 00:03:50,000
263
+ 1.2, you got to know what CIA is, a confidentiality, integrity and availability.
264
+
265
+ 67
266
+ 00:03:50,000 --> 00:03:52,000
267
+ You have to know what zero trust is.
268
+
269
+ 68
270
+ 00:03:52,000 --> 00:03:54,000
271
+ If I go down it goes into more and more.
272
+
273
+ 69
274
+ 00:03:54,000 --> 00:03:58,000
275
+ Now this document is very, very large.
276
+
277
+ 70
278
+ 00:03:58,000 --> 00:04:01,000
279
+ Um, and you can see that it covers quite a lot of topics.
280
+
281
+ 71
282
+ 00:04:01,000 --> 00:04:04,000
283
+ This is why this course is incredibly long.
284
+
285
+ 72
286
+ 00:04:05,000 --> 00:04:08,000
287
+ And you can see it's a lot for me to go over.
288
+
289
+ 73
290
+ 00:04:08,000 --> 00:04:11,000
291
+ Every one of these topics will take a very, very long time.
292
+
293
+ 74
294
+ 00:04:11,000 --> 00:04:15,000
295
+ Now, at the bottom of it, I do want to point out this section.
296
+
297
+ 75
298
+ 00:04:16,000 --> 00:04:19,000
299
+ You see this section here that comes with acronyms.
300
+
301
+ 76
302
+ 00:04:19,000 --> 00:04:22,000
303
+ You guys see that all of these acronyms.
304
+
305
+ 77
306
+ 00:04:23,000 --> 00:04:27,000
307
+ Now throughout the course I will be covering these acronyms.
308
+
309
+ 78
310
+ 00:04:28,000 --> 00:04:30,000
311
+ And you can see it's quite a lot.
312
+
313
+ 79
314
+ 00:04:30,000 --> 00:04:32,000
315
+ And I'm going to give you guys a quick tip here.
316
+
317
+ 80
318
+ 00:04:32,000 --> 00:04:34,000
319
+ So here's a quick tip.
320
+
321
+ 81
322
+ 00:04:34,000 --> 00:04:41,000
323
+ I took this exam and I was stunned to see how many acronyms was on that test.
324
+
325
+ 82
326
+ 00:04:41,000 --> 00:04:45,000
327
+ I'm talking about crazy acronyms and they don't tell you the meaning of them.
328
+
329
+ 83
330
+ 00:04:45,000 --> 00:04:50,000
331
+ So before you take this exam, you want to make sure you review these objectives.
332
+
333
+ 84
334
+ 00:04:50,000 --> 00:04:53,000
335
+ And again you can download this or it might be attached to this video.
336
+
337
+ 85
338
+ 00:04:53,000 --> 00:04:54,000
339
+ Just type.
340
+
341
+ 86
342
+ 00:04:54,000 --> 00:05:00,000
343
+ If you don't know how to use Comptia's website just go to Google Type CompTIA Security+ 701 exam objectives
344
+
345
+ 87
346
+ 00:05:00,000 --> 00:05:01,000
347
+ and you'll get a link to it.
348
+
349
+ 88
350
+ 00:05:01,000 --> 00:05:07,000
351
+ Now these particular acronyms you need to know them before you walk into that exam room.
352
+
353
+ 89
354
+ 00:05:07,000 --> 00:05:09,000
355
+ Make sure you know them.
356
+
357
+ 90
358
+ 00:05:09,000 --> 00:05:15,000
359
+ The other point I want to point out about these exam objectives is that every single thing in the exam
360
+
361
+ 91
362
+ 00:05:15,000 --> 00:05:17,000
363
+ comes from this objective.
364
+
365
+ 92
366
+ 00:05:17,000 --> 00:05:21,000
367
+ Every single question will come from the objectives.
368
+
369
+ 93
370
+ 00:05:21,000 --> 00:05:22,000
371
+ You have to remember that.
372
+
373
+ 94
374
+ 00:05:22,000 --> 00:05:23,000
375
+ All right.
376
+
377
+ 95
378
+ 00:05:23,000 --> 00:05:29,000
379
+ So if you know everything in this exam objectives you will be able not should you will be able to pass
380
+
381
+ 96
382
+ 00:05:29,000 --> 00:05:30,000
383
+ the exam.
384
+
385
+ 97
386
+ 00:05:30,000 --> 00:05:33,000
387
+ But you're saying well how well do I need to know it?
388
+
389
+ 98
390
+ 00:05:33,000 --> 00:05:38,000
391
+ Well, the good thing is in Security+ you don't need to be an expert at the topic.
392
+
393
+ 99
394
+ 00:05:38,000 --> 00:05:40,000
395
+ All I need you to do is be able to explain that.
396
+
397
+ 100
398
+ 00:05:40,000 --> 00:05:42,000
399
+ Be able to tell me what that is.
400
+
401
+ 101
402
+ 00:05:42,000 --> 00:05:44,000
403
+ I don't need you to go configure a firewall.
404
+
405
+ 102
406
+ 00:05:44,000 --> 00:05:46,000
407
+ I just need you to tell me what does a firewall do?
408
+
409
+ 103
410
+ 00:05:46,000 --> 00:05:48,000
411
+ I don't need you to tell me.
412
+
413
+ 104
414
+ 00:05:49,000 --> 00:05:49,000
415
+ I'm sorry.
416
+
417
+ 105
418
+ 00:05:49,000 --> 00:05:54,000
419
+ I don't need you to, uh, set up a different kinds of IDs systems.
420
+
421
+ 106
422
+ 00:05:54,000 --> 00:05:55,000
423
+ I just need you to tell me.
424
+
425
+ 107
426
+ 00:05:55,000 --> 00:05:57,000
427
+ Hey, how does those systems get updated?
428
+
429
+ 108
430
+ 00:05:57,000 --> 00:05:59,000
431
+ What's the point of that?
432
+
433
+ 109
434
+ 00:05:59,000 --> 00:06:00,000
435
+ What's the point of DLP?
436
+
437
+ 110
438
+ 00:06:00,000 --> 00:06:01,000
439
+ Do you know the meaning of that?
440
+
441
+ 111
442
+ 00:06:01,000 --> 00:06:02,000
443
+ Do you even know the purpose it serves?
444
+
445
+ 112
446
+ 00:06:02,000 --> 00:06:06,000
447
+ That's what you need to know for this particular exam.
448
+
449
+ 113
450
+ 00:06:06,000 --> 00:06:10,000
451
+ Now make sure once again, I can't emphasize this enough.
452
+
453
+ 114
454
+ 00:06:10,000 --> 00:06:13,000
455
+ Know your acronyms to pass your exam.
456
+
01 - Introduction/005 30-Day-study-Plan.pdf ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:d66e4361263e47f2f1599f5c079ffe5e794985c72b7ba944856ac205db669b9c
3
+ size 201165
01 - Introduction/005 Course Objectives, Notes and Cram Guide Download.html ADDED
@@ -0,0 +1,69 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ <!DOCTYPE html>
2
+ <html lang="en">
3
+ <head>
4
+ <meta charset="UTF-8" />
5
+ <meta name="viewport" content="width=device-width, initial-scale=1.0" />
6
+ <title>Course Objectives, Notes and Cram Guide Download</title>
7
+
8
+ <style>
9
+ * {
10
+ box-sizing: border-box;
11
+ margin: 0;
12
+ padding: 0;
13
+ }
14
+ body {
15
+ font-family: var(--font-stack-text);
16
+ font-weight: 400;
17
+ line-height: 1.4;
18
+ font-size: 1.6rem;
19
+ color: #2d2f31;
20
+ }
21
+ .container {
22
+ position: relative;
23
+ height: 100%;
24
+ overflow-y: auto;
25
+ }
26
+ .content {
27
+ padding: 3.2rem 4.8rem;
28
+ word-break: break-word;
29
+ max-width: 69.6rem;
30
+ margin: 0 auto;
31
+ }
32
+ .heading {
33
+ margin-bottom: 24px;
34
+ font-family: -apple-system, BlinkMacSystemFont, Roboto, "Segoe UI", Helvetica, Arial, sans-serif,
35
+ "Apple Color Emoji", "Segoe UI Emoji", "Segoe UI Symbol";
36
+ font-weight: 700;
37
+ line-height: 1.2;
38
+ letter-spacing: 0;
39
+ font-size: 32px;
40
+ max-width: 36em;
41
+ }
42
+ .article-asset-container {
43
+ padding: 2.4rem;
44
+ }
45
+ .article-asset-container p {
46
+ font-size: 19px;
47
+ }
48
+ code {
49
+ background-color: #fff;
50
+ border: 1px solid #d1d7dc;
51
+ color: #b4690e;
52
+ font-size: 80%;
53
+ padding: 0.2rem 0.4rem;
54
+ font-family: sfmono-regular, Consolas, liberation mono, Menlo, Courier, monospace;
55
+ }
56
+ p {
57
+ font-weight: 400;
58
+ }
59
+ </style>
60
+ </head>
61
+ <body>
62
+ <div class="container">
63
+ <div class="content">
64
+ <div class="heading">Course Objectives, Notes and Cram Guide Download</div>
65
+ <div class="article-asset-container"><p>Please download all attachment.</p><p>Passing your exam requires doing a lot of practice exams. Get my 6 full-length mock exam course here on Udemy to practice your knowledge gain in this class. If you can score a minimum of 80% on all of the mock exams you will ace your exam. Here is the link:</p><p><a href="https://www.udemy.com/course/securitypluspracticeexams/" rel="noopener noreferrer" target="_blank">https://www.udemy.com/course/securitypluspracticeexams/</a></p><p><br></p><p>-AR</p></div>
66
+ </div>
67
+ </div>
68
+ </body>
69
+ </html>
01 - Introduction/005 Course-Notes.pdf ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:1d34db2b70c0ea7381dd5d3b094c82efe43f684a395b058e3a442f18ce509f64
3
+ size 14673478
01 - Introduction/005 Security-Last-Minute-Cram-Guide.pdf ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:fa966c6b9f54507b6094a771990edabf4c210aad69c3f910b984a9a3e9a12da9
3
+ size 934774
01 - Introduction/005 comptia-security-sy0-701-exam-objectives-5-0.pdf ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:64e5a75df0e6105c724990476b678cf63533d241261538f53d99d2cc73690eba
3
+ size 191074
02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:fca859ed882120f6c1ab557a39e5bbe6a288a5e5ac35a4de44eae4728f3e32e4
3
+ size 17971296
02 - Lesson 1 IT Security Fundamentals/001 Introduction IT Security Fundamentals OB 1.2_en.srt ADDED
@@ -0,0 +1,44 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ Welcome to the first section of the course IT Security Fundamentals.
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:09,000
7
+ Now I want you guys to pay really careful attention in this particular section.
8
+
9
+ 3
10
+ 00:00:09,000 --> 00:00:15,000
11
+ You see in this section I'm going to be reviewing some concepts such as CIA and triple A that you're
12
+
13
+ 4
14
+ 00:00:15,000 --> 00:00:17,000
15
+ going to need for the entire rest of the course.
16
+
17
+ 5
18
+ 00:00:17,000 --> 00:00:23,000
19
+ Terms such as confidentiality, integrity, availability, authentication, authorizations are terms
20
+
21
+ 6
22
+ 00:00:23,000 --> 00:00:28,000
23
+ that we're going to use throughout the entire class to cover all the other lessons.
24
+
25
+ 7
26
+ 00:00:28,000 --> 00:00:30,000
27
+ This section gives you the foundation.
28
+
29
+ 8
30
+ 00:00:30,000 --> 00:00:33,000
31
+ You're going to need to understand the rest of the course.
32
+
33
+ 9
34
+ 00:00:33,000 --> 00:00:39,000
35
+ So my recommendation is to maybe watch this section maybe two times, or at least understand every part
36
+
37
+ 10
38
+ 00:00:39,000 --> 00:00:41,000
39
+ of it so you can be successful in the rest of the class.
40
+
41
+ 11
42
+ 00:00:41,000 --> 00:00:43,000
43
+ So with that in mind, let's get started.
44
+
02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:6172a91d2913d73fec34b2d2bc2e567dc80d574bf722b9a0982f50e3aa4b2bb7
3
+ size 90102008
02 - Lesson 1 IT Security Fundamentals/002 CIA Triad OB 1.2_en.srt ADDED
@@ -0,0 +1,136 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:01,000
3
+ When you think of it.
4
+
5
+ 2
6
+ 00:00:01,000 --> 00:00:03,000
7
+ Security, what comes to mind?
8
+
9
+ 3
10
+ 00:00:03,000 --> 00:00:04,000
11
+ You know what comes to my mind?
12
+
13
+ 4
14
+ 00:00:04,000 --> 00:00:07,000
15
+ Protecting my secret information.
16
+
17
+ 5
18
+ 00:00:07,000 --> 00:00:08,000
19
+ Yeah, I have a lot of secret information.
20
+
21
+ 6
22
+ 00:00:08,000 --> 00:00:09,000
23
+ And so do you.
24
+
25
+ 7
26
+ 00:00:09,000 --> 00:00:16,000
27
+ Credit card information, health care information, passwords to specific website products I buy, and
28
+
29
+ 8
30
+ 00:00:16,000 --> 00:00:17,000
31
+ so on and so on.
32
+
33
+ 9
34
+ 00:00:17,000 --> 00:00:20,000
35
+ All of this private data that I need to keep secret.
36
+
37
+ 10
38
+ 00:00:20,000 --> 00:00:25,000
39
+ You see, protecting your private information from eyes that don't need to see it is a concept we call
40
+
41
+ 11
42
+ 00:00:25,000 --> 00:00:26,000
43
+ confidentiality.
44
+
45
+ 12
46
+ 00:00:26,000 --> 00:00:30,000
47
+ But confidentiality is only one of the three main goals of IT.
48
+
49
+ 13
50
+ 00:00:30,000 --> 00:00:31,000
51
+ Security.
52
+
53
+ 14
54
+ 00:00:31,000 --> 00:00:36,000
55
+ You see it security revolves around three main concepts.
56
+
57
+ 15
58
+ 00:00:36,000 --> 00:00:39,000
59
+ And that concept is right here.
60
+
61
+ 16
62
+ 00:00:39,000 --> 00:00:41,000
63
+ This is called the CIA triad.
64
+
65
+ 17
66
+ 00:00:41,000 --> 00:00:45,000
67
+ The CIA triad tells us that the word CIA is just an acronym.
68
+
69
+ 18
70
+ 00:00:45,000 --> 00:00:50,000
71
+ It's not actually a word that tells us the three main goals of it security.
72
+
73
+ 19
74
+ 00:00:50,000 --> 00:00:52,000
75
+ That's going to be confidentiality.
76
+
77
+ 20
78
+ 00:00:52,000 --> 00:00:54,000
79
+ We just mentioned integrity.
80
+
81
+ 21
82
+ 00:00:54,000 --> 00:00:59,000
83
+ This is ensuring that, hey, unauthorized people don't edit our information or change it.
84
+
85
+ 22
86
+ 00:00:59,000 --> 00:01:01,000
87
+ And then of course we want data to be available.
88
+
89
+ 23
90
+ 00:01:01,000 --> 00:01:02,000
91
+ Availability.
92
+
93
+ 24
94
+ 00:01:02,000 --> 00:01:09,000
95
+ You see all that we're going to be studying throughout this entire course, all your ways to keep your
96
+
97
+ 25
98
+ 00:01:09,000 --> 00:01:16,000
99
+ data secure and to make them available and to keep them from not being altered, such as firewalls and
100
+
101
+ 26
102
+ 00:01:16,000 --> 00:01:22,000
103
+ encryption, intrusion detection system, malware protection, and all the great things that we're going
104
+
105
+ 27
106
+ 00:01:22,000 --> 00:01:28,000
107
+ to be learning to secure our networks, secure our data, secure people is all about revolving against
108
+
109
+ 28
110
+ 00:01:28,000 --> 00:01:30,000
111
+ these three concepts here.
112
+
113
+ 29
114
+ 00:01:30,000 --> 00:01:35,000
115
+ So in the next series of videos, let's get more in depth into these particular three things.
116
+
117
+ 30
118
+ 00:01:35,000 --> 00:01:39,000
119
+ Because on your exam, I want you guys to know this on your exam.
120
+
121
+ 31
122
+ 00:01:39,000 --> 00:01:43,000
123
+ Sometimes they may just say CIA triad, or they might just say CIA.
124
+
125
+ 32
126
+ 00:01:43,000 --> 00:01:47,000
127
+ And you want to make sure, you know, it's not the Central Intelligence Agency, but it's actually
128
+
129
+ 33
130
+ 00:01:47,000 --> 00:01:50,000
131
+ confidentiality, integrity and availability.
132
+
133
+ 34
134
+ 00:01:50,000 --> 00:01:53,000
135
+ So let's keep going to learn more about these particular terms.
136
+
02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:562120d0a9cd657c905f68f5b128491e05b8399bbeec87ad67c408d63fcae534
3
+ size 112277736
02 - Lesson 1 IT Security Fundamentals/003 Confidentiality OB 1.2_en.srt ADDED
@@ -0,0 +1,296 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ When 99% of people think about it security, they're thinking about confidentiality.
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:09,000
7
+ You see, confidentiality is about keeping secret data secret.
8
+
9
+ 3
10
+ 00:00:09,000 --> 00:00:17,000
11
+ It's to ensure that only authorized individuals or systems or entities has access to the right data,
12
+
13
+ 4
14
+ 00:00:17,000 --> 00:00:20,000
15
+ and it keeps away unauthorized folks.
16
+
17
+ 5
18
+ 00:00:20,000 --> 00:00:24,000
19
+ So confidentiality is one of the core tenets of IT security.
20
+
21
+ 6
22
+ 00:00:24,000 --> 00:00:33,000
23
+ In fact, many of the controls, whether it's a firewall, an IDs system, antivirus software, a security
24
+
25
+ 7
26
+ 00:00:33,000 --> 00:00:40,000
27
+ guard badge, access to get into a building, a lot of these controls that we're going to be applying,
28
+
29
+ 8
30
+ 00:00:40,000 --> 00:00:44,000
31
+ we're going to be doing it to keeping our secret data secret.
32
+
33
+ 9
34
+ 00:00:44,000 --> 00:00:48,000
35
+ And only only authorized individuals should have access to it.
36
+
37
+ 10
38
+ 00:00:48,000 --> 00:00:51,000
39
+ Let's take a look here at the definition for confidentiality.
40
+
41
+ 11
42
+ 00:00:51,000 --> 00:00:58,000
43
+ So refers to the refers to the measures taken to ensure that sensitive information is not disclosed
44
+
45
+ 12
46
+ 00:00:58,000 --> 00:01:01,000
47
+ to unauthorized individuals, entities or processes.
48
+
49
+ 13
50
+ 00:01:02,000 --> 00:01:07,000
51
+ It involves preserving, in other words, keeping authorized restrictions.
52
+
53
+ 14
54
+ 00:01:07,000 --> 00:01:11,000
55
+ So we have to place restrictions on our information.
56
+
57
+ 15
58
+ 00:01:11,000 --> 00:01:12,000
59
+ Well, what are those restrictions?
60
+
61
+ 16
62
+ 00:01:12,000 --> 00:01:14,000
63
+ Well, I have some of them listed here.
64
+
65
+ 17
66
+ 00:01:14,000 --> 00:01:15,000
67
+ We'll go through those in a little while.
68
+
69
+ 18
70
+ 00:01:16,000 --> 00:01:20,000
71
+ It involves preserving authorized restrictions on the information.
72
+
73
+ 19
74
+ 00:01:20,000 --> 00:01:27,000
75
+ Access disclosure, and we want to make sure that we keep our personal privacy and proprietary information
76
+
77
+ 20
78
+ 00:01:27,000 --> 00:01:27,000
79
+ secure.
80
+
81
+ 21
82
+ 00:01:27,000 --> 00:01:30,000
83
+ Now, how do we do this in the world of it?
84
+
85
+ 22
86
+ 00:01:30,000 --> 00:01:34,000
87
+ How are we going to keep our secret data secret?
88
+
89
+ 23
90
+ 00:01:34,000 --> 00:01:35,000
91
+ Here are a few ways.
92
+
93
+ 24
94
+ 00:01:35,000 --> 00:01:37,000
95
+ These are not the only ways, but there are a few.
96
+
97
+ 25
98
+ 00:01:37,000 --> 00:01:39,000
99
+ That's pretty pretty popular.
100
+
101
+ 26
102
+ 00:01:39,000 --> 00:01:41,000
103
+ The first thing up we'll talk about is access control.
104
+
105
+ 27
106
+ 00:01:41,000 --> 00:01:43,000
107
+ What exactly is that?
108
+
109
+ 28
110
+ 00:01:43,000 --> 00:01:48,000
111
+ This is a firm you're going to hear about throughout this entire course, or any IT security course.
112
+
113
+ 29
114
+ 00:01:48,000 --> 00:01:49,000
115
+ You're going to take about that.
116
+
117
+ 30
118
+ 00:01:49,000 --> 00:01:50,000
119
+ You're going to be taken.
120
+
121
+ 31
122
+ 00:01:50,000 --> 00:01:54,000
123
+ So in the world of computing, there's two things.
124
+
125
+ 32
126
+ 00:01:54,000 --> 00:01:57,000
127
+ Something called a subject and an object.
128
+
129
+ 33
130
+ 00:01:57,000 --> 00:01:59,000
131
+ Subjects wants to access objects.
132
+
133
+ 34
134
+ 00:01:59,000 --> 00:02:01,000
135
+ Who's a subject.
136
+
137
+ 35
138
+ 00:02:01,000 --> 00:02:06,000
139
+ You're the subject I'm the subject I want to use this computer to make this video.
140
+
141
+ 36
142
+ 00:02:07,000 --> 00:02:08,000
143
+ So there's the subject.
144
+
145
+ 37
146
+ 00:02:08,000 --> 00:02:12,000
147
+ The object is what you want to is is what you want to access.
148
+
149
+ 38
150
+ 00:02:12,000 --> 00:02:16,000
151
+ Maybe a file or a folder, maybe a particular system that you want to access.
152
+
153
+ 39
154
+ 00:02:16,000 --> 00:02:22,000
155
+ How do we control subjects access and objects with access control?
156
+
157
+ 40
158
+ 00:02:22,000 --> 00:02:27,000
159
+ Access controls things such as a password is a type of an access control.
160
+
161
+ 41
162
+ 00:02:27,000 --> 00:02:27,000
163
+ Right.
164
+
165
+ 42
166
+ 00:02:27,000 --> 00:02:31,000
167
+ Because what the password does is that it controls your access to that machine.
168
+
169
+ 43
170
+ 00:02:31,000 --> 00:02:35,000
171
+ If you know the password, you can get into the machine, don't know the password, you can't access
172
+
173
+ 44
174
+ 00:02:35,000 --> 00:02:36,000
175
+ it.
176
+
177
+ 45
178
+ 00:02:36,000 --> 00:02:42,000
179
+ So access control, such as a password or some kind of biometric will stop you from accessing a particular
180
+
181
+ 46
182
+ 00:02:42,000 --> 00:02:43,000
183
+ system.
184
+
185
+ 47
186
+ 00:02:43,000 --> 00:02:47,000
187
+ In other words, if you don't have authorization, you can't see the data on there preserving confidentiality.
188
+
189
+ 48
190
+ 00:02:48,000 --> 00:02:53,000
191
+ Another thing here that we have is going to be that falls in here that you should be familiar with is
192
+
193
+ 49
194
+ 00:02:53,000 --> 00:02:56,000
195
+ something called an ACL, an access control list.
196
+
197
+ 50
198
+ 00:02:56,000 --> 00:03:01,000
199
+ If you work in an organization today and you try to access a file, maybe, or a folder, you double
200
+
201
+ 51
202
+ 00:03:01,000 --> 00:03:04,000
203
+ click on it and it says boom, access denied.
204
+
205
+ 52
206
+ 00:03:04,000 --> 00:03:05,000
207
+ That's an access control list.
208
+
209
+ 53
210
+ 00:03:05,000 --> 00:03:10,000
211
+ Later on in the course, I'm going to show you what access control list looks like on files and folder
212
+
213
+ 54
214
+ 00:03:10,000 --> 00:03:13,000
215
+ here on windows and of course on your different routers and firewalls.
216
+
217
+ 55
218
+ 00:03:14,000 --> 00:03:16,000
219
+ Now encryption.
220
+
221
+ 56
222
+ 00:03:16,000 --> 00:03:20,000
223
+ This is something that plays a huge part of our life.
224
+
225
+ 57
226
+ 00:03:20,000 --> 00:03:25,000
227
+ When you buy on Amazon, you buy the latest gadget, you put your credit card information in, you put
228
+
229
+ 58
230
+ 00:03:25,000 --> 00:03:28,000
231
+ your address, and Amazon ships that product.
232
+
233
+ 59
234
+ 00:03:28,000 --> 00:03:32,000
235
+ Well, when you put your credit card information in, you are sitting at your computer.
236
+
237
+ 60
238
+ 00:03:32,000 --> 00:03:35,000
239
+ So your credit card information went across the internet to Amazon.
240
+
241
+ 61
242
+ 00:03:35,000 --> 00:03:39,000
243
+ Hopefully nobody saw that information from your house to the Amazon web server.
244
+
245
+ 62
246
+ 00:03:39,000 --> 00:03:45,000
247
+ Well, they did see the information, but what they saw was an encrypted session.
248
+
249
+ 63
250
+ 00:03:45,000 --> 00:03:50,000
251
+ And because of encryption, if they when they read it, they're not going to get anything out of it
252
+
253
+ 64
254
+ 00:03:50,000 --> 00:03:52,000
255
+ because the data is fully encrypted.
256
+
257
+ 65
258
+ 00:03:52,000 --> 00:03:59,000
259
+ So encryption is an amazing way to ensure that only authorized party can read the information.
260
+
261
+ 66
262
+ 00:03:59,000 --> 00:04:05,000
263
+ So secure communication combined with encryption, we're going to use protocols or security protocols
264
+
265
+ 67
266
+ 00:04:05,000 --> 00:04:11,000
267
+ such as SSL or TLS, basically the same thing in order to keep our data secure.
268
+
269
+ 68
270
+ 00:04:11,000 --> 00:04:18,000
271
+ So these are some technical ways here that we're going to ensure confidentiality by using things such
272
+
273
+ 69
274
+ 00:04:18,000 --> 00:04:22,000
275
+ as encryption, uh, access control.
276
+
277
+ 70
278
+ 00:04:22,000 --> 00:04:26,000
279
+ And there are a bunch of physical ways to we'll get into those later on okay.
280
+
281
+ 71
282
+ 00:04:26,000 --> 00:04:28,000
283
+ So just remember something about confidentiality.
284
+
285
+ 72
286
+ 00:04:28,000 --> 00:04:34,000
287
+ It's all about keeping secret information secret and how to and how do we do that with a wide variety
288
+
289
+ 73
290
+ 00:04:34,000 --> 00:04:39,000
291
+ of technical things and physical things that we're going to be using, that you're going to be learning
292
+
293
+ 74
294
+ 00:04:39,000 --> 00:04:42,000
295
+ a lot more in the course to keep your secret data secret.
296
+
02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:49aeced5d62772206c3adc5c4d98bb3a2d6baa5a1ba8fbafe0fdfb8bb50b9eb4
3
+ size 68409165
02 - Lesson 1 IT Security Fundamentals/004 Integrity OB 1.2_en.srt ADDED
@@ -0,0 +1,192 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ One of the most important concepts in IT security is to ensure that there is only authorized changes
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:11,000
7
+ to information, basically, accuracy of information you see on systems.
8
+
9
+ 3
10
+ 00:00:11,000 --> 00:00:16,000
11
+ Today, you're going to have tons and tons of data from people, Social Security numbers to secret memos
12
+
13
+ 4
14
+ 00:00:16,000 --> 00:00:18,000
15
+ or business plans on a system.
16
+
17
+ 5
18
+ 00:00:18,000 --> 00:00:23,000
19
+ We want to ensure that only authorized individuals can edit that information.
20
+
21
+ 6
22
+ 00:00:24,000 --> 00:00:29,000
23
+ You see, viewing the information and seeing it, that's confidentiality, but changes and manipulation
24
+
25
+ 7
26
+ 00:00:29,000 --> 00:00:29,000
27
+ of the data.
28
+
29
+ 8
30
+ 00:00:29,000 --> 00:00:32,000
31
+ This is known as integrity.
32
+
33
+ 9
34
+ 00:00:32,000 --> 00:00:37,000
35
+ So integrity is about protecting data from unauthorized changes to ensure it's reliable and correct.
36
+
37
+ 10
38
+ 00:00:37,000 --> 00:00:42,000
39
+ That means that, hey, we want to stop unauthorized people from changing and editing information,
40
+
41
+ 11
42
+ 00:00:42,000 --> 00:00:49,000
43
+ but we also want to make sure that we give authorized people the way or the method to change the data.
44
+
45
+ 12
46
+ 00:00:49,000 --> 00:00:55,000
47
+ Now this really comes back to one core thing in integrity.
48
+
49
+ 13
50
+ 00:00:55,000 --> 00:00:59,000
51
+ When you think integrity for your exam, I want you to think data accuracy.
52
+
53
+ 14
54
+ 00:00:59,000 --> 00:01:04,000
55
+ How do we ensure that the data that you're getting that you're receiving is accurate?
56
+
57
+ 15
58
+ 00:01:04,000 --> 00:01:06,000
59
+ Let me give you an example.
60
+
61
+ 16
62
+ 00:01:06,000 --> 00:01:08,000
63
+ Let's say the CEO writes a memo.
64
+
65
+ 17
66
+ 00:01:08,000 --> 00:01:11,000
67
+ He gives it to the to his assistant.
68
+
69
+ 18
70
+ 00:01:11,000 --> 00:01:13,000
71
+ That memo is then distributed to the company.
72
+
73
+ 19
74
+ 00:01:13,000 --> 00:01:17,000
75
+ But the upcoming goals of the business, let's say it has some secret business plans in there that only
76
+
77
+ 20
78
+ 00:01:17,000 --> 00:01:20,000
79
+ companies I should see when you receive it.
80
+
81
+ 21
82
+ 00:01:20,000 --> 00:01:22,000
83
+ And you're a much lower down the ladder than the CEO here.
84
+
85
+ 22
86
+ 00:01:22,000 --> 00:01:26,000
87
+ So it had to go through many eyes and many hands.
88
+
89
+ 23
90
+ 00:01:26,000 --> 00:01:32,000
91
+ How are you so sure that what's in this memo actually came from the CEO?
92
+
93
+ 24
94
+ 00:01:32,000 --> 00:01:34,000
95
+ How do you ensure that it was never changed or modified?
96
+
97
+ 25
98
+ 00:01:35,000 --> 00:01:36,000
99
+ This is the concept of integrity.
100
+
101
+ 26
102
+ 00:01:36,000 --> 00:01:39,000
103
+ How do you sure that the data that you're receiving is accurate?
104
+
105
+ 27
106
+ 00:01:39,000 --> 00:01:40,000
107
+ Is it consistent.
108
+
109
+ 28
110
+ 00:01:40,000 --> 00:01:45,000
111
+ So consistency with what the CEO wrote and how can you trust it?
112
+
113
+ 29
114
+ 00:01:45,000 --> 00:01:50,000
115
+ Well, one of the ways of doing this in the world of it that we're going to discuss later in this course
116
+
117
+ 30
118
+ 00:01:50,000 --> 00:01:52,000
119
+ is called a digital signature.
120
+
121
+ 31
122
+ 00:01:52,000 --> 00:01:59,000
123
+ If the CEO had used something such as a digital signature, you'll note that the data was never modified
124
+
125
+ 32
126
+ 00:01:59,000 --> 00:02:01,000
127
+ and it actually came from him.
128
+
129
+ 33
130
+ 00:02:01,000 --> 00:02:03,000
131
+ This helps to form integrity.
132
+
133
+ 34
134
+ 00:02:03,000 --> 00:02:09,000
135
+ Another thing that we can use to stop people from changing or manipulating data that they shouldn't
136
+
137
+ 35
138
+ 00:02:09,000 --> 00:02:10,000
139
+ be is access controls.
140
+
141
+ 36
142
+ 00:02:10,000 --> 00:02:16,000
143
+ So access controls is basically controlling the access between subjects and objects.
144
+
145
+ 37
146
+ 00:02:16,000 --> 00:02:21,000
147
+ So I can go in there in my computer and say, Mary, she can write to the data.
148
+
149
+ 38
150
+ 00:02:21,000 --> 00:02:26,000
151
+ She has a, she has the, the, the permission to write to the information.
152
+
153
+ 39
154
+ 00:02:26,000 --> 00:02:30,000
155
+ But Bob, he doesn't have access to write to the data.
156
+
157
+ 40
158
+ 00:02:30,000 --> 00:02:36,000
159
+ He can see it though, so they could both see it, but only one person can write to it this way.
160
+
161
+ 41
162
+ 00:02:36,000 --> 00:02:40,000
163
+ Mary is an authorized, authorized individual for integrity.
164
+
165
+ 42
166
+ 00:02:40,000 --> 00:02:41,000
167
+ Bob is not.
168
+
169
+ 43
170
+ 00:02:41,000 --> 00:02:43,000
171
+ So don't get the concepts confused.
172
+
173
+ 44
174
+ 00:02:43,000 --> 00:02:46,000
175
+ There was two concepts so far confidentiality and integrity.
176
+
177
+ 45
178
+ 00:02:46,000 --> 00:02:49,000
179
+ Confidentiality allows you to view the information.
180
+
181
+ 46
182
+ 00:02:49,000 --> 00:02:53,000
183
+ Integrity allows you to manipulate and change the information.
184
+
185
+ 47
186
+ 00:02:53,000 --> 00:02:54,000
187
+ So keep that in mind.
188
+
189
+ 48
190
+ 00:02:54,000 --> 00:02:57,000
191
+ Confidentiality view it and integrity is about changing it.
192
+
02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:c729741a4cbc53b331814879bd94ceb1083176a0b13ac387a2e05591fe3ba7ca
3
+ size 154740853
02 - Lesson 1 IT Security Fundamentals/005 Availability OB 1.2_en.srt ADDED
@@ -0,0 +1,232 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:03,000
3
+ One concept that's missed a lot when talking about it.
4
+
5
+ 2
6
+ 00:00:03,000 --> 00:00:05,000
7
+ Security is availability.
8
+
9
+ 3
10
+ 00:00:05,000 --> 00:00:09,000
11
+ You see, when most people think it security, they're thinking confidentiality.
12
+
13
+ 4
14
+ 00:00:09,000 --> 00:00:11,000
15
+ And some may even think of about about availability.
16
+
17
+ 5
18
+ 00:00:11,000 --> 00:00:15,000
19
+ But it doesn't matter how secure your information is.
20
+
21
+ 6
22
+ 00:00:15,000 --> 00:00:20,000
23
+ For example, you could secure your information by writing it on a piece of paper.
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:22,000
27
+ Take it off computer, put in a vault, put it inside the earth.
28
+
29
+ 8
30
+ 00:00:23,000 --> 00:00:27,000
31
+ It's going to be super secure, but then not much people can access it.
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:32,000
35
+ It's not very useful if your security is so good that no one can use it when they actually need to use
36
+
37
+ 10
38
+ 00:00:32,000 --> 00:00:35,000
39
+ it to make some money or to grow your organization.
40
+
41
+ 11
42
+ 00:00:35,000 --> 00:00:42,000
43
+ So visibility is really this concept that ensures that data systems and services are accessible to authorized
44
+
45
+ 12
46
+ 00:00:42,000 --> 00:00:44,000
47
+ users when needed.
48
+
49
+ 13
50
+ 00:00:44,000 --> 00:00:51,000
51
+ Now we want to make sure to understand this concept, because there are a lot of attacks against networks
52
+
53
+ 14
54
+ 00:00:51,000 --> 00:00:55,000
55
+ that can bring down an entire system, and then it's not very useful.
56
+
57
+ 15
58
+ 00:00:55,000 --> 00:00:58,000
59
+ For example, what if there is a DDoS attack?
60
+
61
+ 16
62
+ 00:00:58,000 --> 00:01:01,000
63
+ The distributed denial of service that takes out the Amazon website?
64
+
65
+ 17
66
+ 00:01:01,000 --> 00:01:03,000
67
+ If you don't know what this is, don't worry, cover it.
68
+
69
+ 18
70
+ 00:01:04,000 --> 00:01:04,000
71
+ Cover this more later.
72
+
73
+ 19
74
+ 00:01:04,000 --> 00:01:09,000
75
+ Just know it's a type of attack that sends a lot of traffic to a website and takes it offline for malicious
76
+
77
+ 20
78
+ 00:01:09,000 --> 00:01:10,000
79
+ reasons.
80
+
81
+ 21
82
+ 00:01:10,000 --> 00:01:16,000
83
+ Now Amazon can't make money, or maybe your organization can't make money because the website is offline.
84
+
85
+ 22
86
+ 00:01:16,000 --> 00:01:25,000
87
+ We want to protect our systems from unauthorized access, confidentiality, unauthorized changes, integrity,
88
+
89
+ 23
90
+ 00:01:25,000 --> 00:01:29,000
91
+ and we want to make sure that it's available when needed.
92
+
93
+ 24
94
+ 00:01:29,000 --> 00:01:30,000
95
+ How are we going to do that?
96
+
97
+ 25
98
+ 00:01:30,000 --> 00:01:32,000
99
+ Well, here are a couple of ways.
100
+
101
+ 26
102
+ 00:01:32,000 --> 00:01:37,000
103
+ Number one, we could build systems that can take a hit and keep on going.
104
+
105
+ 27
106
+ 00:01:37,000 --> 00:01:37,000
107
+ All right.
108
+
109
+ 28
110
+ 00:01:37,000 --> 00:01:40,000
111
+ They can continuously operate even if something goes wrong.
112
+
113
+ 29
114
+ 00:01:40,000 --> 00:01:44,000
115
+ For example, you may have a server that has a dual power supply.
116
+
117
+ 30
118
+ 00:01:44,000 --> 00:01:47,000
119
+ One of the first things that fails on a computer is the power supply.
120
+
121
+ 31
122
+ 00:01:47,000 --> 00:01:49,000
123
+ So put two power supply.
124
+
125
+ 32
126
+ 00:01:49,000 --> 00:01:51,000
127
+ Another common thing that fails is a hard drive.
128
+
129
+ 33
130
+ 00:01:51,000 --> 00:01:52,000
131
+ Have a Raid system.
132
+
133
+ 34
134
+ 00:01:52,000 --> 00:01:54,000
135
+ If you don't know what those are, talk about those later.
136
+
137
+ 35
138
+ 00:01:55,000 --> 00:01:57,000
139
+ Another thing is you want to make sure you have backup of your information.
140
+
141
+ 36
142
+ 00:01:57,000 --> 00:02:01,000
143
+ So if the system ever dies, you can always restore a backup.
144
+
145
+ 37
146
+ 00:02:02,000 --> 00:02:06,000
147
+ If there's no backup, there's no restoration, and there's no you're going to lose a ton of data.
148
+
149
+ 38
150
+ 00:02:06,000 --> 00:02:08,000
151
+ But if you have a backup, there's going to be no data loss.
152
+
153
+ 39
154
+ 00:02:08,000 --> 00:02:11,000
155
+ So availability is a really important concept.
156
+
157
+ 40
158
+ 00:02:11,000 --> 00:02:15,000
159
+ And there are many things that we're going to talk about later in the course that we're going to be
160
+
161
+ 41
162
+ 00:02:15,000 --> 00:02:18,000
163
+ doing in order to maintain high availability.
164
+
165
+ 42
166
+ 00:02:18,000 --> 00:02:19,000
167
+ All right.
168
+
169
+ 43
170
+ 00:02:19,000 --> 00:02:21,000
171
+ So remember something.
172
+
173
+ 44
174
+ 00:02:21,000 --> 00:02:25,000
175
+ The CIA triad confidentiality keep secret data secret.
176
+
177
+ 45
178
+ 00:02:25,000 --> 00:02:31,000
179
+ Only authorized individuals can access the data, prevents unauthorized access integrity.
180
+
181
+ 46
182
+ 00:02:31,000 --> 00:02:38,000
183
+ Only authorized individuals can edit the information prevents unauthorized changes or manipulation of
184
+
185
+ 47
186
+ 00:02:38,000 --> 00:02:39,000
187
+ data availability.
188
+
189
+ 48
190
+ 00:02:39,000 --> 00:02:46,000
191
+ Keeping systems online ensure there's no unauthorized downtime of information, such as the system failure
192
+
193
+ 49
194
+ 00:02:46,000 --> 00:02:48,000
195
+ or data corruption.
196
+
197
+ 50
198
+ 00:02:48,000 --> 00:02:52,000
199
+ Remember, these are going to be the three main concepts of IT security.
200
+
201
+ 51
202
+ 00:02:52,000 --> 00:02:56,000
203
+ And if you're wondering, well, how is this going to fit in with the rest of the course, are all that
204
+
205
+ 52
206
+ 00:02:56,000 --> 00:02:57,000
207
+ I'm about to learn?
208
+
209
+ 53
210
+ 00:02:58,000 --> 00:03:03,000
211
+ Because believe this or not, every single thing that you're going to be learning.
212
+
213
+ 54
214
+ 00:03:03,000 --> 00:03:06,000
215
+ For the next many, many, many hours.
216
+
217
+ 55
218
+ 00:03:06,000 --> 00:03:09,000
219
+ It's going to be about protecting these three things.
220
+
221
+ 56
222
+ 00:03:09,000 --> 00:03:17,000
223
+ It's going to be about how do we, uh, prevent unauthorized access, manipulation and high uptime on
224
+
225
+ 57
226
+ 00:03:17,000 --> 00:03:18,000
227
+ availability?
228
+
229
+ 58
230
+ 00:03:18,000 --> 00:03:21,000
231
+ This is the core concept of IT security.
232
+
02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:d4b5553ab5e0906328439265fd51cfeaea5389e19db61b4ca3016e20daf1e4cf
3
+ size 48749088
02 - Lesson 1 IT Security Fundamentals/006 DAD Triade OB 1.2_en.srt ADDED
@@ -0,0 +1,136 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:02,000
3
+ I generally consider myself a good person.
4
+
5
+ 2
6
+ 00:00:02,000 --> 00:00:08,000
7
+ I generally work with organizations to prevent unauthorized access, confidentiality, unauthorized
8
+
9
+ 3
10
+ 00:00:08,000 --> 00:00:14,000
11
+ changes, integrity, and ensuring uptimes high uptimes under system availability.
12
+
13
+ 4
14
+ 00:00:14,000 --> 00:00:17,000
15
+ But there are those of us or bad people.
16
+
17
+ 5
18
+ 00:00:17,000 --> 00:00:20,000
19
+ Not a lot, but there are some bad people that we work against.
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:27,000
23
+ Every single thing in this course that we're going to learn about is to preserve the CIA and to stop
24
+
25
+ 7
26
+ 00:00:27,000 --> 00:00:30,000
27
+ the D&D or the D&D triad.
28
+
29
+ 8
30
+ 00:00:30,000 --> 00:00:32,000
31
+ You see, there is the opposite of the CIA.
32
+
33
+ 9
34
+ 00:00:32,000 --> 00:00:36,000
35
+ So if we're working to preserve CIA, then what are we working against this?
36
+
37
+ 10
38
+ 00:00:36,000 --> 00:00:39,000
39
+ If you are a bad person, this is what you do.
40
+
41
+ 11
42
+ 00:00:39,000 --> 00:00:41,000
43
+ If you're a good person, you do CIA.
44
+
45
+ 12
46
+ 00:00:41,000 --> 00:00:42,000
47
+ So what is this?
48
+
49
+ 13
50
+ 00:00:42,000 --> 00:00:43,000
51
+ Well, this is the opposite.
52
+
53
+ 14
54
+ 00:00:43,000 --> 00:00:47,000
55
+ This tells us so we have confidentiality, integrity and availability.
56
+
57
+ 15
58
+ 00:00:47,000 --> 00:00:51,000
59
+ The opposite of those are going to be disclosure alteration and denial.
60
+
61
+ 16
62
+ 00:00:52,000 --> 00:00:59,000
63
+ For example the opposite of confidentiality which is going to be, uh, preventing unauthorized access
64
+
65
+ 17
66
+ 00:00:59,000 --> 00:01:05,000
67
+ is going to be allowing this unauthorized access or exposure of data, the opposite of integrity, which
68
+
69
+ 18
70
+ 00:01:05,000 --> 00:01:11,000
71
+ is going to be something such as unauthorized, preventing unauthorized manipulation or changes.
72
+
73
+ 19
74
+ 00:01:11,000 --> 00:01:13,000
75
+ This is going to allow authorized changes.
76
+
77
+ 20
78
+ 00:01:13,000 --> 00:01:17,000
79
+ Alteration and availability is ensuring that you always have access.
80
+
81
+ 21
82
+ 00:01:17,000 --> 00:01:21,000
83
+ How about if I deny you access to this actual information.
84
+
85
+ 22
86
+ 00:01:21,000 --> 00:01:26,000
87
+ So this gives you just a quick a quick summary of what I just stated.
88
+
89
+ 23
90
+ 00:01:26,000 --> 00:01:27,000
91
+ So what exactly is it.
92
+
93
+ 24
94
+ 00:01:27,000 --> 00:01:28,000
95
+ Disclosure.
96
+
97
+ 25
98
+ 00:01:28,000 --> 00:01:30,000
99
+ This goes against confidentiality.
100
+
101
+ 26
102
+ 00:01:30,000 --> 00:01:32,000
103
+ This allows unauthorized access alteration.
104
+
105
+ 27
106
+ 00:01:32,000 --> 00:01:38,000
107
+ This is against integrity unauthorized changes and denial is when they take your system offline.
108
+
109
+ 28
110
+ 00:01:38,000 --> 00:01:43,000
111
+ By the way, I want to mention that sometimes depending on the book you read, denial may have they
112
+
113
+ 29
114
+ 00:01:43,000 --> 00:01:47,000
115
+ may replace denial with the word destruction because that will also take data offline.
116
+
117
+ 30
118
+ 00:01:47,000 --> 00:01:53,000
119
+ So sometimes you might see that, okay, just be familiar that there is such a thing as the D&D triad.
120
+
121
+ 31
122
+ 00:01:53,000 --> 00:01:56,000
123
+ You may see it on your exam as just D&D triad.
124
+
125
+ 32
126
+ 00:01:56,000 --> 00:01:58,000
127
+ Just remember that is where the bad guy works.
128
+
129
+ 33
130
+ 00:01:58,000 --> 00:02:02,000
131
+ That's everything that we're going to be doing in this course.
132
+
133
+ 34
134
+ 00:02:02,000 --> 00:02:06,000
135
+ That we're going to be working to stop the D&D triad.
136
+
02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:1a77d9929feab6395cbd63db5ee5bbca15560ce0d80dad8bdf24343237e7d10e
3
+ size 320464412
02 - Lesson 1 IT Security Fundamentals/007 Zero Trust OB 1.2_en.srt ADDED
@@ -0,0 +1,616 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ If you make a visit to Tia offices in Midtown Manhattan, and you come to pay us a visit, and you want
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:10,000
7
+ to gain access to some of our network resources, such as maybe internet or some files and folders on
8
+
9
+ 3
10
+ 00:00:10,000 --> 00:00:13,000
11
+ our corporate systems or admin network.
12
+
13
+ 4
14
+ 00:00:13,000 --> 00:00:15,000
15
+ You're going to have to go through a device like this.
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:21,000
19
+ Now, this is a sonic wall, and this sonic wall basically is a firewall, but it does include a switch,
20
+
21
+ 6
22
+ 00:00:21,000 --> 00:00:22,000
23
+ as you can see at the back.
24
+
25
+ 7
26
+ 00:00:22,000 --> 00:00:24,000
27
+ And it does have an access point.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:27,000
31
+ We're going to talk a lot more about this devices as the course.
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:27,000
35
+ Go on.
36
+
37
+ 10
38
+ 00:00:27,000 --> 00:00:31,000
39
+ Let me put this down here for a minute though, because there's something I want to talk to you guys
40
+
41
+ 11
42
+ 00:00:31,000 --> 00:00:33,000
43
+ about, getting access to networks.
44
+
45
+ 12
46
+ 00:00:33,000 --> 00:00:38,000
47
+ You see, in today's world, if you're going to a network and you plug your computer into it, as long
48
+
49
+ 13
50
+ 00:00:38,000 --> 00:00:43,000
51
+ as you're in that particular network, you're probably going to get at least an internet connection.
52
+
53
+ 14
54
+ 00:00:43,000 --> 00:00:48,000
55
+ So you're going to be able to do some kind of work, and you may have access to certain files and folders.
56
+
57
+ 15
58
+ 00:00:48,000 --> 00:00:55,000
59
+ So what what essentially is happening is that you're basically getting access to resources such as the
60
+
61
+ 16
62
+ 00:00:55,000 --> 00:01:00,000
63
+ internet or particular files and folders, without anybody authenticating you or knowing who the hell
64
+
65
+ 17
66
+ 00:01:00,000 --> 00:01:01,000
67
+ you are.
68
+
69
+ 18
70
+ 00:01:01,000 --> 00:01:07,000
71
+ You see, that is the default setup, especially on networks that uses small business devices like this
72
+
73
+ 19
74
+ 00:01:08,000 --> 00:01:10,000
75
+ Sonicwall that I have here.
76
+
77
+ 20
78
+ 00:01:10,000 --> 00:01:12,000
79
+ What we want to do is we want to change that.
80
+
81
+ 21
82
+ 00:01:12,000 --> 00:01:18,000
83
+ What we want to do is have a different mindset, a different method of managing our network.
84
+
85
+ 22
86
+ 00:01:18,000 --> 00:01:22,000
87
+ And that brings me to today's lesson zero trust.
88
+
89
+ 23
90
+ 00:01:22,000 --> 00:01:23,000
91
+ What exactly is this?
92
+
93
+ 24
94
+ 00:01:23,000 --> 00:01:29,000
95
+ Well, it centers on the belief that organizations should not automatically trust anything inside or
96
+
97
+ 25
98
+ 00:01:29,000 --> 00:01:31,000
99
+ outside of their network.
100
+
101
+ 26
102
+ 00:01:31,000 --> 00:01:36,000
103
+ So, for example, if you come into my network and because you're physically standing in it, you plug
104
+
105
+ 27
106
+ 00:01:36,000 --> 00:01:42,000
107
+ your device into it, you're going to gain access to something the internet, internet, certain files
108
+
109
+ 28
110
+ 00:01:42,000 --> 00:01:44,000
111
+ and folders, maybe even access to printers.
112
+
113
+ 29
114
+ 00:01:44,000 --> 00:01:49,000
115
+ But on a zero trust, when you come into my network and you take your computer and you plug it into
116
+
117
+ 30
118
+ 00:01:49,000 --> 00:01:55,000
119
+ the port, or you connect to the access point that that's on this device, you're not going to get anything.
120
+
121
+ 31
122
+ 00:01:55,000 --> 00:02:00,000
123
+ We're going to have to authenticate you, or we're going to have to trust who you are or find out who
124
+
125
+ 32
126
+ 00:02:00,000 --> 00:02:03,000
127
+ are you before this device is going to give you access to the network.
128
+
129
+ 33
130
+ 00:02:03,000 --> 00:02:07,000
131
+ So zero trust is they shouldn't trust anything.
132
+
133
+ 34
134
+ 00:02:07,000 --> 00:02:09,000
135
+ In other words, nothing is trusted.
136
+
137
+ 35
138
+ 00:02:09,000 --> 00:02:11,000
139
+ Let me ask you a question.
140
+
141
+ 36
142
+ 00:02:11,000 --> 00:02:17,000
143
+ As you sit here and you watch this video, if I come to your house and I connect to your network.
144
+
145
+ 37
146
+ 00:02:17,000 --> 00:02:17,000
147
+ All right.
148
+
149
+ 38
150
+ 00:02:17,000 --> 00:02:22,000
151
+ So I take out my laptop and I plug it into the switcher on your network, on your router or your cable
152
+
153
+ 39
154
+ 00:02:22,000 --> 00:02:23,000
155
+ modem or whatever.
156
+
157
+ 40
158
+ 00:02:23,000 --> 00:02:24,000
159
+ Do I get internet access?
160
+
161
+ 41
162
+ 00:02:24,000 --> 00:02:26,000
163
+ Do I get access to things in your house?
164
+
165
+ 42
166
+ 00:02:26,000 --> 00:02:29,000
167
+ If the answer is yes, you don't have zero trust with zero trust.
168
+
169
+ 43
170
+ 00:02:29,000 --> 00:02:31,000
171
+ When people connect, they have nothing.
172
+
173
+ 44
174
+ 00:02:31,000 --> 00:02:35,000
175
+ Not even internet organizations trust no one.
176
+
177
+ 45
178
+ 00:02:35,000 --> 00:02:41,000
179
+ So they instead they verify every anything and everything trying to connect to its system.
180
+
181
+ 46
182
+ 00:02:41,000 --> 00:02:43,000
183
+ Now, how are they going to do that?
184
+
185
+ 47
186
+ 00:02:43,000 --> 00:02:47,000
187
+ Well, they're going to do very strict identity verification.
188
+
189
+ 48
190
+ 00:02:47,000 --> 00:02:51,000
191
+ That's identifying users principles of least privileges.
192
+
193
+ 49
194
+ 00:02:51,000 --> 00:02:55,000
195
+ That way when people connect, they have very little privileges on a network, just what they need to
196
+
197
+ 50
198
+ 00:02:55,000 --> 00:02:58,000
199
+ do, just what they need to do a particular job.
200
+
201
+ 51
202
+ 00:02:58,000 --> 00:03:00,000
203
+ Multi-factor authentication can be used here.
204
+
205
+ 52
206
+ 00:03:00,000 --> 00:03:04,000
207
+ And of course, in Zero Trust, you're going to want to monitor and log all traffic.
208
+
209
+ 53
210
+ 00:03:04,000 --> 00:03:13,000
211
+ Now, to take this a little further, I want to go in to a particular model that was that is given to
212
+
213
+ 54
214
+ 00:03:13,000 --> 00:03:15,000
215
+ us by NIST documentation.
216
+
217
+ 55
218
+ 00:03:15,000 --> 00:03:20,000
219
+ So NIST documentation and particularly NIST SP 800 207.
220
+
221
+ 56
222
+ 00:03:20,000 --> 00:03:21,000
223
+ This is on page nine.
224
+
225
+ 57
226
+ 00:03:21,000 --> 00:03:23,000
227
+ I took this diagram from there.
228
+
229
+ 58
230
+ 00:03:23,000 --> 00:03:30,000
231
+ And this diagram breaks down how we can do a zero trust model using a specific set of components.
232
+
233
+ 59
234
+ 00:03:30,000 --> 00:03:33,000
235
+ Now I'm going to come back to this model here in a minute.
236
+
237
+ 60
238
+ 00:03:33,000 --> 00:03:35,000
239
+ Let me cover some terms first.
240
+
241
+ 61
242
+ 00:03:35,000 --> 00:03:41,000
243
+ So the first thing I want to mention is that you're going to come to understand that you have to break
244
+
245
+ 62
246
+ 00:03:41,000 --> 00:03:48,000
247
+ down your network into two layers, what's called a data layer and a control layer, or what's called
248
+
249
+ 63
250
+ 00:03:48,000 --> 00:03:50,000
251
+ data planes and control planes.
252
+
253
+ 64
254
+ 00:03:50,000 --> 00:03:54,000
255
+ Now I want to go back and I want to look at this particular diagram that we have here.
256
+
257
+ 65
258
+ 00:03:56,000 --> 00:03:58,000
259
+ Let me put on my trusty pen.
260
+
261
+ 66
262
+ 00:03:58,000 --> 00:03:59,000
263
+ Here we go with my trusty pen.
264
+
265
+ 67
266
+ 00:03:59,000 --> 00:04:01,000
267
+ So I want you guys to take a look at this.
268
+
269
+ 68
270
+ 00:04:01,000 --> 00:04:06,000
271
+ So notice you have what's called a data plane and a control plane.
272
+
273
+ 69
274
+ 00:04:06,000 --> 00:04:10,000
275
+ Now as you go through your network and you connect to the network.
276
+
277
+ 70
278
+ 00:04:10,000 --> 00:04:17,000
279
+ So let's say your subjects who are subjects, subjects, um, the subjects comes out of the data plane.
280
+
281
+ 71
282
+ 00:04:17,000 --> 00:04:19,000
283
+ Subjects are entities requesting access.
284
+
285
+ 72
286
+ 00:04:19,000 --> 00:04:23,000
287
+ So this is like you request an access to my particular network.
288
+
289
+ 73
290
+ 00:04:24,000 --> 00:04:26,000
291
+ Now you're going to go on to a system, right?
292
+
293
+ 74
294
+ 00:04:26,000 --> 00:04:29,000
295
+ You're going to be logged in to a laptop.
296
+
297
+ 75
298
+ 00:04:29,000 --> 00:04:32,000
299
+ You're sitting at your laptop, you're sitting at your desktop.
300
+
301
+ 76
302
+ 00:04:32,000 --> 00:04:33,000
303
+ So that's going to be your system.
304
+
305
+ 77
306
+ 00:04:33,000 --> 00:04:36,000
307
+ You're going to be in what's called an untrusted zone.
308
+
309
+ 78
310
+ 00:04:36,000 --> 00:04:41,000
311
+ So you're the subject and the system is untrusted by default on a zero trust.
312
+
313
+ 79
314
+ 00:04:41,000 --> 00:04:45,000
315
+ Remember it's called zero trust, which means you're not trusted to our system.
316
+
317
+ 80
318
+ 00:04:45,000 --> 00:04:49,000
319
+ So you come in and you say, hey, can you give me access to your network?
320
+
321
+ 81
322
+ 00:04:49,000 --> 00:04:57,000
323
+ Well, the request to get access to my network is going to send to send to what we call a policy enforcement
324
+
325
+ 82
326
+ 00:04:57,000 --> 00:04:57,000
327
+ point.
328
+
329
+ 83
330
+ 00:04:57,000 --> 00:04:59,000
331
+ Now, what exactly is a policy enforcement point?
332
+
333
+ 84
334
+ 00:04:59,000 --> 00:05:05,000
335
+ What that is, what's going to be responsible for enabling, monitoring and eventually terminating connections.
336
+
337
+ 85
338
+ 00:05:05,000 --> 00:05:13,000
339
+ So you notice this policy enforcement point sits between you and the resource you want.
340
+
341
+ 86
342
+ 00:05:13,000 --> 00:05:14,000
343
+ Let's say this resource is a printer.
344
+
345
+ 87
346
+ 00:05:16,000 --> 00:05:16,000
347
+ All right.
348
+
349
+ 88
350
+ 00:05:16,000 --> 00:05:18,000
351
+ So you want to access a particular printer.
352
+
353
+ 89
354
+ 00:05:18,000 --> 00:05:23,000
355
+ Well, this policy enforcement point sits between you and accessing that particular resource.
356
+
357
+ 90
358
+ 00:05:23,000 --> 00:05:30,000
359
+ So at the data plane of the network what is there in that data plane is just a subject accessing the
360
+
361
+ 91
362
+ 00:05:30,000 --> 00:05:30,000
363
+ resource.
364
+
365
+ 92
366
+ 00:05:30,000 --> 00:05:34,000
367
+ And there's something in between them that's saying, hey, you know what, you can access this or you
368
+
369
+ 93
370
+ 00:05:34,000 --> 00:05:35,000
371
+ can't.
372
+
373
+ 94
374
+ 00:05:36,000 --> 00:05:40,000
375
+ Now there is something we call an implicit trust.
376
+
377
+ 95
378
+ 00:05:40,000 --> 00:05:48,000
379
+ So an implicit trust is let's say you're already trusted to log into the accounting network, an implicit
380
+
381
+ 96
382
+ 00:05:48,000 --> 00:05:50,000
383
+ trust because you're logged in there.
384
+
385
+ 97
386
+ 00:05:50,000 --> 00:05:55,000
387
+ The company already the company will give you then access to the financial network.
388
+
389
+ 98
390
+ 00:05:55,000 --> 00:05:57,000
391
+ You don't need to re-authenticate it there.
392
+
393
+ 99
394
+ 00:05:57,000 --> 00:06:00,000
395
+ So this has what's called an implicit trust between zones.
396
+
397
+ 100
398
+ 00:06:01,000 --> 00:06:03,000
399
+ Now control plane.
400
+
401
+ 101
402
+ 00:06:03,000 --> 00:06:07,000
403
+ The control plane is where all the magic happens.
404
+
405
+ 102
406
+ 00:06:07,000 --> 00:06:10,000
407
+ You see the control plane has three components.
408
+
409
+ 103
410
+ 00:06:10,000 --> 00:06:12,000
411
+ What's called a policy decision point.
412
+
413
+ 104
414
+ 00:06:12,000 --> 00:06:14,000
415
+ This is what the whole thing is going to be about.
416
+
417
+ 105
418
+ 00:06:14,000 --> 00:06:17,000
419
+ Should we let this guy go or not?
420
+
421
+ 106
422
+ 00:06:17,000 --> 00:06:19,000
423
+ You have a policy engine and a policy administrator.
424
+
425
+ 107
426
+ 00:06:20,000 --> 00:06:25,000
427
+ Now, when you log into a network, there is something we call an adaptive identity.
428
+
429
+ 108
430
+ 00:06:25,000 --> 00:06:27,000
431
+ Adaptive means changing, right.
432
+
433
+ 109
434
+ 00:06:27,000 --> 00:06:31,000
435
+ So we are going to dynamically adjust how we identify you.
436
+
437
+ 110
438
+ 00:06:31,000 --> 00:06:35,000
439
+ Maybe we're going to identify you based on an IP address along with a username.
440
+
441
+ 111
442
+ 00:06:35,000 --> 00:06:39,000
443
+ Maybe we're going to identify you based on where you're located and a particular username.
444
+
445
+ 112
446
+ 00:06:39,000 --> 00:06:44,000
447
+ So I know this username should always log in from the United States or somewhere else.
448
+
449
+ 113
450
+ 00:06:44,000 --> 00:06:50,000
451
+ There are some things this is all going to be done using what's called a policy driven access control.
452
+
453
+ 114
454
+ 00:06:50,000 --> 00:06:54,000
455
+ All the access control that we have that we're going to allow you to access.
456
+
457
+ 115
458
+ 00:06:54,000 --> 00:06:59,000
459
+ This particular printer has to go through a certain policy set up generally by your network administrator.
460
+
461
+ 116
462
+ 00:06:59,000 --> 00:07:03,000
463
+ Now comes the, uh, policy administrator.
464
+
465
+ 117
466
+ 00:07:04,000 --> 00:07:05,000
467
+ Oops.
468
+
469
+ 118
470
+ 00:07:05,000 --> 00:07:07,000
471
+ The policy administrator and the policy engine.
472
+
473
+ 119
474
+ 00:07:07,000 --> 00:07:13,000
475
+ So the policy administrator this is responsible for establishing or shutting down the communication
476
+
477
+ 120
478
+ 00:07:13,000 --> 00:07:16,000
479
+ path between the between you, the subject and the resource.
480
+
481
+ 121
482
+ 00:07:16,000 --> 00:07:22,000
483
+ The printer and the policy engine is responsible for the decision to whether to allow you to grant access
484
+
485
+ 122
486
+ 00:07:22,000 --> 00:07:23,000
487
+ or not.
488
+
489
+ 123
490
+ 00:07:23,000 --> 00:07:25,000
491
+ Now, let me go back to this.
492
+
493
+ 124
494
+ 00:07:25,000 --> 00:07:27,000
495
+ I want to erase.
496
+
497
+ 125
498
+ 00:07:28,000 --> 00:07:29,000
499
+ And I want to put this all together.
500
+
501
+ 126
502
+ 00:07:29,000 --> 00:07:32,000
503
+ I know you're confused right now because this looks complex.
504
+
505
+ 127
506
+ 00:07:32,000 --> 00:07:40,000
507
+ So you log in, you and your system try to gain access to this printer.
508
+
509
+ 128
510
+ 00:07:41,000 --> 00:07:46,000
511
+ So what you do is you send your request to a policy enforcement point.
512
+
513
+ 129
514
+ 00:07:46,000 --> 00:07:49,000
515
+ The policy enforcement point sends it to the administrator.
516
+
517
+ 130
518
+ 00:07:49,000 --> 00:07:56,000
519
+ Now the administrator is responsible for allow for allowing that, uh, communication between you and
520
+
521
+ 131
522
+ 00:07:56,000 --> 00:07:57,000
523
+ the actual printer.
524
+
525
+ 132
526
+ 00:07:57,000 --> 00:08:02,000
527
+ But the policy administrator is not the one making the actual decision.
528
+
529
+ 133
530
+ 00:08:02,000 --> 00:08:04,000
531
+ That's going to be the policy engine.
532
+
533
+ 134
534
+ 00:08:04,000 --> 00:08:10,000
535
+ The policy engine is going to say allow or deny access after verifying the system, knowing who the
536
+
537
+ 135
538
+ 00:08:10,000 --> 00:08:13,000
539
+ system is generally based on some kind of policy.
540
+
541
+ 136
542
+ 00:08:13,000 --> 00:08:17,000
543
+ The policy engine tells the administrator, hey, allow this guy to gain access.
544
+
545
+ 137
546
+ 00:08:17,000 --> 00:08:23,000
547
+ The policy enforcement point says, okay, the policy decision point, the place at the top says, you
548
+
549
+ 138
550
+ 00:08:23,000 --> 00:08:23,000
551
+ know what?
552
+
553
+ 139
554
+ 00:08:23,000 --> 00:08:27,000
555
+ You can gain access and now you gain access to it.
556
+
557
+ 140
558
+ 00:08:27,000 --> 00:08:32,000
559
+ So this is what a zero trust model will look like in full implementation.
560
+
561
+ 141
562
+ 00:08:32,000 --> 00:08:36,000
563
+ Now there is something here we call threat scope reduction.
564
+
565
+ 142
566
+ 00:08:36,000 --> 00:08:38,000
567
+ This is going to be minimizing network attack surfaces.
568
+
569
+ 143
570
+ 00:08:38,000 --> 00:08:41,000
571
+ What you want to do is you know where can you enter a network.
572
+
573
+ 144
574
+ 00:08:41,000 --> 00:08:43,000
575
+ How many entry points do you have in a network.
576
+
577
+ 145
578
+ 00:08:43,000 --> 00:08:45,000
579
+ The less entry points into a network.
580
+
581
+ 146
582
+ 00:08:45,000 --> 00:08:50,000
583
+ For example, if you have no wireless, there's a lot less vulnerabilities or or entry points into a
584
+
585
+ 147
586
+ 00:08:50,000 --> 00:08:51,000
587
+ network.
588
+
589
+ 148
590
+ 00:08:52,000 --> 00:08:52,000
591
+ Okay.
592
+
593
+ 149
594
+ 00:08:53,000 --> 00:08:54,000
595
+ The Zero Trust.
596
+
597
+ 150
598
+ 00:08:54,000 --> 00:08:59,000
599
+ I would suggest for you to review this video one more time to make sure that you understand some of
600
+
601
+ 151
602
+ 00:08:59,000 --> 00:09:02,000
603
+ the terms on it, that some of these terms may or may not appear on your exam.
604
+
605
+ 152
606
+ 00:09:03,000 --> 00:09:10,000
607
+ But what will appear on your exam is probably the concept of zero trust, in which case no one can access
608
+
609
+ 153
610
+ 00:09:10,000 --> 00:09:14,000
611
+ anything on your network without first being authenticated and verified that they should have access
612
+
613
+ 154
614
+ 00:09:14,000 --> 00:09:16,000
615
+ to those particular resources.
616
+
02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:223b6716912eb7ce86f06dc01fc8a700e4ab0c347105d8269c243082c4de95db
3
+ size 63283884
02 - Lesson 1 IT Security Fundamentals/008 Non-Repudiation OB 1.2_en.srt ADDED
@@ -0,0 +1,192 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:01,000
3
+ In the world of security.
4
+
5
+ 2
6
+ 00:00:01,000 --> 00:00:07,000
7
+ When somebody does something and we tell them, hey, you did something wrong, we want to ensure that
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:09,000
11
+ they can't say, it wasn't me.
12
+
13
+ 4
14
+ 00:00:09,000 --> 00:00:14,000
15
+ We want to put so much quote unquote controls, or we want to put so much protection mechanisms.
16
+
17
+ 5
18
+ 00:00:14,000 --> 00:00:18,000
19
+ They don't want to come to you and says, hey, Bob, you stole that pen off the desk.
20
+
21
+ 6
22
+ 00:00:18,000 --> 00:00:20,000
23
+ And Bob is like, was it me?
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:21,000
27
+ And I'm like, well, here's the camera footage.
28
+
29
+ 8
30
+ 00:00:21,000 --> 00:00:22,000
31
+ You did it.
32
+
33
+ 9
34
+ 00:00:22,000 --> 00:00:27,000
35
+ I want Bob to not deny that they did something.
36
+
37
+ 10
38
+ 00:00:27,000 --> 00:00:29,000
39
+ You see, there is a terme in it.
40
+
41
+ 11
42
+ 00:00:29,000 --> 00:00:32,000
43
+ Security we call non-repudiation.
44
+
45
+ 12
46
+ 00:00:32,000 --> 00:00:39,000
47
+ Non-repudiation is when an entity cannot deny that an event has taken place.
48
+
49
+ 13
50
+ 00:00:39,000 --> 00:00:41,000
51
+ They can't repudiate that.
52
+
53
+ 14
54
+ 00:00:41,000 --> 00:00:46,000
55
+ So, for example, let's say I like this tablet.
56
+
57
+ 15
58
+ 00:00:46,000 --> 00:00:46,000
59
+ All right.
60
+
61
+ 16
62
+ 00:00:46,000 --> 00:00:47,000
63
+ There's a camera on this wall.
64
+
65
+ 17
66
+ 00:00:47,000 --> 00:00:48,000
67
+ Camera in front of me.
68
+
69
+ 18
70
+ 00:00:48,000 --> 00:00:51,000
71
+ I pick up this tablet, I put it in my bag, and I run out the room.
72
+
73
+ 19
74
+ 00:00:51,000 --> 00:00:56,000
75
+ All right, I steal it, and I run out of the room, and the police comes after me and the police says,
76
+
77
+ 20
78
+ 00:00:56,000 --> 00:00:58,000
79
+ Andrew, you stole that tablet.
80
+
81
+ 21
82
+ 00:00:58,000 --> 00:01:00,000
83
+ And I'm like, no, I didn't, right?
84
+
85
+ 22
86
+ 00:01:00,000 --> 00:01:01,000
87
+ Because I'm a bad person.
88
+
89
+ 23
90
+ 00:01:01,000 --> 00:01:02,000
91
+ I'm a liar, obviously.
92
+
93
+ 24
94
+ 00:01:02,000 --> 00:01:07,000
95
+ And the police says, well, here's the camera footage of you stealing it.
96
+
97
+ 25
98
+ 00:01:08,000 --> 00:01:11,000
99
+ And I'm going to say, oh, you're right, I did steal that.
100
+
101
+ 26
102
+ 00:01:11,000 --> 00:01:15,000
103
+ I guess I forgot, so I can't deny it anymore.
104
+
105
+ 27
106
+ 00:01:15,000 --> 00:01:20,000
107
+ Okay, so in the world of IT security, this is called non-repudiation.
108
+
109
+ 28
110
+ 00:01:20,000 --> 00:01:27,000
111
+ So non-repudiation is that when a party in a communication cannot, cannot deny the authenticity of
112
+
113
+ 29
114
+ 00:01:27,000 --> 00:01:30,000
115
+ their signature on a document or sending of a message that the originator.
116
+
117
+ 30
118
+ 00:01:30,000 --> 00:01:36,000
119
+ So they can't deny that they send something, they can't deny that this didn't come from them.
120
+
121
+ 31
122
+ 00:01:36,000 --> 00:01:43,000
123
+ Now, this is really important because when you receive messages from places like Amazon, right when
124
+
125
+ 32
126
+ 00:01:43,000 --> 00:01:48,000
127
+ you go to a website and you receive a confirmation from Amazon that, hey, your credit card went through
128
+
129
+ 33
130
+ 00:01:48,000 --> 00:01:54,000
131
+ or you go to a website, how are you so sure that's Amazon, how does your computer know that's Amazon?
132
+
133
+ 34
134
+ 00:01:54,000 --> 00:01:59,000
135
+ You see that's going to fall into the world of non-repudiation because those websites have something
136
+
137
+ 35
138
+ 00:01:59,000 --> 00:02:03,000
139
+ we call certificates, which are digitally signed, a digital signature.
140
+
141
+ 36
142
+ 00:02:03,000 --> 00:02:04,000
143
+ We're going to get more into it.
144
+
145
+ 37
146
+ 00:02:04,000 --> 00:02:06,000
147
+ If you want to skip to this, it's going to be in the cryptography section.
148
+
149
+ 38
150
+ 00:02:06,000 --> 00:02:14,000
151
+ But a digital signature is when you attach something to a document, a certificate that when you send
152
+
153
+ 39
154
+ 00:02:14,000 --> 00:02:17,000
155
+ it, people are 100% sure it came from you.
156
+
157
+ 40
158
+ 00:02:17,000 --> 00:02:18,000
159
+ All right.
160
+
161
+ 41
162
+ 00:02:18,000 --> 00:02:20,000
163
+ That way that person can't deny that it came from them.
164
+
165
+ 42
166
+ 00:02:20,000 --> 00:02:22,000
167
+ And you are sure that it came from them.
168
+
169
+ 43
170
+ 00:02:22,000 --> 00:02:26,000
171
+ So that's one way of providing non-repudiation.
172
+
173
+ 44
174
+ 00:02:26,000 --> 00:02:27,000
175
+ So remember what non-repudiation is.
176
+
177
+ 45
178
+ 00:02:27,000 --> 00:02:36,000
179
+ Non-repudiation is going to be a concept that an entity, a subject cannot deny that a particular event
180
+
181
+ 46
182
+ 00:02:36,000 --> 00:02:37,000
183
+ has taken place.
184
+
185
+ 47
186
+ 00:02:37,000 --> 00:02:42,000
187
+ We do this in IT security most of the time by just using a digital signature.
188
+
189
+ 48
190
+ 00:02:42,000 --> 00:02:43,000
191
+ Know that one for your exam.
192
+
02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:467be145f0cd86815836570a5564fedec1be478b5dbe8248b1294e7b07fa0688
3
+ size 75714389
02 - Lesson 1 IT Security Fundamentals/009 Authentication OB 1.2_en.srt ADDED
@@ -0,0 +1,164 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ When working on a system, you're going to want to make sure that three main concepts are applied to
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:06,000
7
+ that system.
8
+
9
+ 3
10
+ 00:00:06,000 --> 00:00:11,000
11
+ When a user logs into a computer, you want to make sure that they have the right password.
12
+
13
+ 4
14
+ 00:00:11,000 --> 00:00:16,000
15
+ In other words, they're authenticated, they have access to the correct information authorization,
16
+
17
+ 5
18
+ 00:00:16,000 --> 00:00:18,000
19
+ and you're tracking what they're doing.
20
+
21
+ 6
22
+ 00:00:18,000 --> 00:00:22,000
23
+ You see, these concepts is referred to as triple A.
24
+
25
+ 7
26
+ 00:00:22,000 --> 00:00:26,000
27
+ Triple A talks about authentication authorization and accounting.
28
+
29
+ 8
30
+ 00:00:26,000 --> 00:00:28,000
31
+ Now authentication is a really important terms.
32
+
33
+ 9
34
+ 00:00:28,000 --> 00:00:30,000
35
+ We have a whole dedicated video on it.
36
+
37
+ 10
38
+ 00:00:30,000 --> 00:00:31,000
39
+ Coming up next.
40
+
41
+ 11
42
+ 00:00:31,000 --> 00:00:37,000
43
+ This is the process of verifying the identity of a user, device or other entity to a particular system.
44
+
45
+ 12
46
+ 00:00:38,000 --> 00:00:40,000
47
+ Another concept is authorization.
48
+
49
+ 13
50
+ 00:00:40,000 --> 00:00:46,000
51
+ So authorization is really going to be about ensuring that an authorized individual has access to this
52
+
53
+ 14
54
+ 00:00:46,000 --> 00:00:46,000
55
+ data.
56
+
57
+ 15
58
+ 00:00:46,000 --> 00:00:53,000
59
+ For example, let's say you log in to a computer at your workplace and there's a folder on the desktop,
60
+
61
+ 16
62
+ 00:00:53,000 --> 00:00:54,000
63
+ you double click on it.
64
+
65
+ 17
66
+ 00:00:54,000 --> 00:00:56,000
67
+ Do you have access to that data?
68
+
69
+ 18
70
+ 00:00:56,000 --> 00:01:02,000
71
+ The system has to perform some kind of a check to see, well, this user account, Bob, has access
72
+
73
+ 19
74
+ 00:01:02,000 --> 00:01:03,000
75
+ to this particular folder.
76
+
77
+ 20
78
+ 00:01:03,000 --> 00:01:05,000
79
+ Can you read what's in there?
80
+
81
+ 21
82
+ 00:01:05,000 --> 00:01:08,000
83
+ Can you write to what's in there or can you just read.
84
+
85
+ 22
86
+ 00:01:08,000 --> 00:01:10,000
87
+ This is called authorization.
88
+
89
+ 23
90
+ 00:01:10,000 --> 00:01:11,000
91
+ We got to make sure that you have access to that data.
92
+
93
+ 24
94
+ 00:01:11,000 --> 00:01:15,000
95
+ You try to go to a particular website, open up a particular application.
96
+
97
+ 25
98
+ 00:01:15,000 --> 00:01:19,000
99
+ We have to make sure that only authorized people.
100
+
101
+ 26
102
+ 00:01:19,000 --> 00:01:25,000
103
+ Has or is permitted to access certain types of information.
104
+
105
+ 27
106
+ 00:01:25,000 --> 00:01:29,000
107
+ This is done generally using some kind of thing called we call an access control list.
108
+
109
+ 28
110
+ 00:01:29,000 --> 00:01:32,000
111
+ Another thing we want to do is we want to track what you're doing.
112
+
113
+ 29
114
+ 00:01:32,000 --> 00:01:38,000
115
+ We want to see that when you log in to a particular system, everything you do, we're going to know
116
+
117
+ 30
118
+ 00:01:38,000 --> 00:01:45,000
119
+ as IT security professionals, we need to know that Bob logged in at 8:00 in the morning.
120
+
121
+ 31
122
+ 00:01:45,000 --> 00:01:47,000
123
+ He accessed this file at 802.
124
+
125
+ 32
126
+ 00:01:47,000 --> 00:01:49,000
127
+ He changed this one at 803.
128
+
129
+ 33
130
+ 00:01:49,000 --> 00:01:51,000
131
+ He deleted this at 804, and so on and so on.
132
+
133
+ 34
134
+ 00:01:51,000 --> 00:01:54,000
135
+ We want to keep track of every single thing you're doing.
136
+
137
+ 35
138
+ 00:01:54,000 --> 00:02:00,000
139
+ This is going to help lead to keeping you accountable to what is happening on our systems.
140
+
141
+ 36
142
+ 00:02:00,000 --> 00:02:01,000
143
+ So accountability is a big thing.
144
+
145
+ 37
146
+ 00:02:01,000 --> 00:02:03,000
147
+ We'll talk about that later though in the course.
148
+
149
+ 38
150
+ 00:02:03,000 --> 00:02:03,000
151
+ All right.
152
+
153
+ 39
154
+ 00:02:03,000 --> 00:02:05,000
155
+ So remember what exactly is triple A.
156
+
157
+ 40
158
+ 00:02:06,000 --> 00:02:09,000
159
+ Triple A refers to authentication authorization and accounting.
160
+
161
+ 41
162
+ 00:02:09,000 --> 00:02:15,000
163
+ And every system that we have in our network today should have these particular three things.
164
+
02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:f1c4515ebc370ba6b64ba57e77635683f0d7b33ef92a5bf036841f967890e0f4
3
+ size 137044412
02 - Lesson 1 IT Security Fundamentals/010 Authorization OB 1.2_en.srt ADDED
@@ -0,0 +1,268 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ When a user logs into a system, what can they do?
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:05,000
7
+ What can they access?
8
+
9
+ 3
10
+ 00:00:05,000 --> 00:00:07,000
11
+ Can they access a certain application?
12
+
13
+ 4
14
+ 00:00:07,000 --> 00:00:09,000
15
+ Are they denied access to a particular thing?
16
+
17
+ 5
18
+ 00:00:10,000 --> 00:00:12,000
19
+ You see, this is called authorization.
20
+
21
+ 6
22
+ 00:00:12,000 --> 00:00:17,000
23
+ An authorization is all about ensuring that users have access to the right information.
24
+
25
+ 7
26
+ 00:00:17,000 --> 00:00:21,000
27
+ Remember authentication is just about getting them into the system, but what can they access?
28
+
29
+ 8
30
+ 00:00:21,000 --> 00:00:25,000
31
+ I want to show you a quick demonstration of authorization at play.
32
+
33
+ 9
34
+ 00:00:25,000 --> 00:00:27,000
35
+ So here I am at my windows desktop.
36
+
37
+ 10
38
+ 00:00:27,000 --> 00:00:30,000
39
+ I have two folders message and I have homework.
40
+
41
+ 11
42
+ 00:00:30,000 --> 00:00:34,000
43
+ You notice that if I try to double click on messages watch what happens.
44
+
45
+ 12
46
+ 00:00:34,000 --> 00:00:39,000
47
+ It says you don't you you don't currently have permission to access this folder.
48
+
49
+ 13
50
+ 00:00:39,000 --> 00:00:43,000
51
+ That means that the system is denying me access to this particular folder.
52
+
53
+ 14
54
+ 00:00:44,000 --> 00:00:44,000
55
+ All right.
56
+
57
+ 15
58
+ 00:00:44,000 --> 00:00:46,000
59
+ Now you notice homework.
60
+
61
+ 16
62
+ 00:00:46,000 --> 00:00:49,000
63
+ If I double click on this, I have full access to this.
64
+
65
+ 17
66
+ 00:00:49,000 --> 00:00:50,000
67
+ I can access this.
68
+
69
+ 18
70
+ 00:00:50,000 --> 00:00:52,000
71
+ I can go in here.
72
+
73
+ 19
74
+ 00:00:52,000 --> 00:00:54,000
75
+ Maybe I can add a add a text file to this.
76
+
77
+ 20
78
+ 00:00:54,000 --> 00:00:55,000
79
+ Wouldn't the other one.
80
+
81
+ 21
82
+ 00:00:55,000 --> 00:00:56,000
83
+ I couldn't even open it.
84
+
85
+ 22
86
+ 00:00:57,000 --> 00:01:03,000
87
+ The system is doing this by using something files and permissions on a access control list.
88
+
89
+ 23
90
+ 00:01:03,000 --> 00:01:05,000
91
+ I want to show you what that looks like.
92
+
93
+ 24
94
+ 00:01:05,000 --> 00:01:10,000
95
+ You see, if I right click on homework and I go to properties and I go to security.
96
+
97
+ 25
98
+ 00:01:10,000 --> 00:01:15,000
99
+ You'll notice this list here of all the users and what they can do.
100
+
101
+ 26
102
+ 00:01:15,000 --> 00:01:16,000
103
+ You notice I'm listed here.
104
+
105
+ 27
106
+ 00:01:17,000 --> 00:01:20,000
107
+ And it says that I have full control and I can edit this.
108
+
109
+ 28
110
+ 00:01:20,000 --> 00:01:25,000
111
+ Now if you're the administrator of the system like I am, you can actually add and remove permissions
112
+
113
+ 29
114
+ 00:01:25,000 --> 00:01:26,000
115
+ as needed.
116
+
117
+ 30
118
+ 00:01:27,000 --> 00:01:30,000
119
+ If I look at messages though, I right click I go to properties.
120
+
121
+ 31
122
+ 00:01:30,000 --> 00:01:32,000
123
+ You'll notice this one doesn't have anybody.
124
+
125
+ 32
126
+ 00:01:33,000 --> 00:01:33,000
127
+ All right.
128
+
129
+ 33
130
+ 00:01:33,000 --> 00:01:34,000
131
+ Nobody is listed here.
132
+
133
+ 34
134
+ 00:01:34,000 --> 00:01:40,000
135
+ So the administrator of the machine which is me can now go in here and add the permissions or edit permissions
136
+
137
+ 35
138
+ 00:01:40,000 --> 00:01:41,000
139
+ to this.
140
+
141
+ 36
142
+ 00:01:41,000 --> 00:01:47,000
143
+ So to give you a quick demonstration I'm going to show you how we can add a user to a particular system
144
+
145
+ 37
146
+ 00:01:47,000 --> 00:01:49,000
147
+ or add users to a particular folder.
148
+
149
+ 38
150
+ 00:01:49,000 --> 00:01:50,000
151
+ I would just say edit.
152
+
153
+ 39
154
+ 00:01:51,000 --> 00:01:52,000
155
+ Add.
156
+
157
+ 40
158
+ 00:01:53,000 --> 00:01:57,000
159
+ And then I would say advanced because I just want a quick list of users find now.
160
+
161
+ 41
162
+ 00:01:57,000 --> 00:02:01,000
163
+ And you notice all the users in the machine will show up in this list.
164
+
165
+ 42
166
+ 00:02:01,000 --> 00:02:02,000
167
+ I'm looking for myself.
168
+
169
+ 43
170
+ 00:02:02,000 --> 00:02:06,000
171
+ So I'm going to click on me, say okay, okay one more time because it found me.
172
+
173
+ 44
174
+ 00:02:06,000 --> 00:02:12,000
175
+ And then I'm going to give myself full control and say, okay, now when I try to access this, you
176
+
177
+ 45
178
+ 00:02:12,000 --> 00:02:13,000
179
+ notice it opens right up.
180
+
181
+ 46
182
+ 00:02:13,000 --> 00:02:16,000
183
+ And I can now go in there and add another message if I want.
184
+
185
+ 47
186
+ 00:02:16,000 --> 00:02:20,000
187
+ This is the process of what's known as authorization.
188
+
189
+ 48
190
+ 00:02:20,000 --> 00:02:28,000
191
+ So authorization is is going to be that process where we're going to determine what a user is allowed
192
+
193
+ 49
194
+ 00:02:28,000 --> 00:02:30,000
195
+ to do by establishing their rights and privileges.
196
+
197
+ 50
198
+ 00:02:30,000 --> 00:02:31,000
199
+ How are we going to do that?
200
+
201
+ 51
202
+ 00:02:31,000 --> 00:02:34,000
203
+ By using what I just showed you permissions and privileges.
204
+
205
+ 52
206
+ 00:02:34,000 --> 00:02:35,000
207
+ All right.
208
+
209
+ 53
210
+ 00:02:35,000 --> 00:02:41,000
211
+ It involves granting permission to specific folders devices, applications.
212
+
213
+ 54
214
+ 00:02:41,000 --> 00:02:44,000
215
+ And then we can say whether they can read to read to it or write to it.
216
+
217
+ 55
218
+ 00:02:44,000 --> 00:02:49,000
219
+ So you got to remember that now I just showed you a small sample of that.
220
+
221
+ 56
222
+ 00:02:49,000 --> 00:02:54,000
223
+ Rights and permissions are generally going to be done by assigning it to some kind of what's called
224
+
225
+ 57
226
+ 00:02:54,000 --> 00:02:55,000
227
+ an ACL.
228
+
229
+ 58
230
+ 00:02:55,000 --> 00:02:58,000
231
+ Now access control lists are going to be used by firewalls.
232
+
233
+ 59
234
+ 00:02:58,000 --> 00:03:03,000
235
+ It's going to be used by, uh, routers to ensure who can come in and out of your network.
236
+
237
+ 60
238
+ 00:03:04,000 --> 00:03:10,000
239
+ There are something we call an authorized auth authorization model.
240
+
241
+ 61
242
+ 00:03:10,000 --> 00:03:13,000
243
+ And things such as Mac or Dak systems fall into this category.
244
+
245
+ 62
246
+ 00:03:13,000 --> 00:03:19,000
247
+ I'm not going to cover this topic now because I have a whole I have a whole lecture coming up on different
248
+
249
+ 63
250
+ 00:03:19,000 --> 00:03:24,000
251
+ forms of access control models coming up later in the in the course.
252
+
253
+ 64
254
+ 00:03:24,000 --> 00:03:26,000
255
+ So just keep in mind that these do fall in here.
256
+
257
+ 65
258
+ 00:03:26,000 --> 00:03:27,000
259
+ All right.
260
+
261
+ 66
262
+ 00:03:27,000 --> 00:03:33,000
263
+ So remember now for your exam that when it comes to to authorization it's just about ensuring that the
264
+
265
+ 67
266
+ 00:03:33,000 --> 00:03:37,000
267
+ right user has the right access to the correct resources.
268
+
02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:28a0b1152a42a6f3bcb0b80720711c36fbe806dd2b51f3b19b6e7d013ffadf41
3
+ size 67696549
02 - Lesson 1 IT Security Fundamentals/011 Accounting OB 1.2_en.srt ADDED
@@ -0,0 +1,144 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:02,000
3
+ Any time you log into a system.
4
+
5
+ 2
6
+ 00:00:02,000 --> 00:00:05,000
7
+ I'm pretty sure every single thing you do on that system is tracked.
8
+
9
+ 3
10
+ 00:00:05,000 --> 00:00:06,000
11
+ What do I mean by that?
12
+
13
+ 4
14
+ 00:00:06,000 --> 00:00:12,000
15
+ Well, you open a file, you open a folder, you delete a file, you add a file to it.
16
+
17
+ 5
18
+ 00:00:12,000 --> 00:00:17,000
19
+ More than likely, your organization is keeping track of all the activities you're doing in the world
20
+
21
+ 6
22
+ 00:00:17,000 --> 00:00:18,000
23
+ of IT security.
24
+
25
+ 7
26
+ 00:00:18,000 --> 00:00:20,000
27
+ We're going to call this thing accounting.
28
+
29
+ 8
30
+ 00:00:20,000 --> 00:00:27,000
31
+ So accounting refers to tracking of user activity and resources within that system.
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:28,000
35
+ How are we tracking it.
36
+
37
+ 10
38
+ 00:00:28,000 --> 00:00:32,000
39
+ Well in things like windows you have these log files and particularly the security log file.
40
+
41
+ 11
42
+ 00:00:32,000 --> 00:00:37,000
43
+ And in that file depending on how your system is set up, I'm going to be able to see that you logged
44
+
45
+ 12
46
+ 00:00:37,000 --> 00:00:38,000
47
+ in at 8:00.
48
+
49
+ 13
50
+ 00:00:38,000 --> 00:00:40,000
51
+ You access this file at 802.
52
+
53
+ 14
54
+ 00:00:40,000 --> 00:00:42,000
55
+ You change this file at 803.
56
+
57
+ 15
58
+ 00:00:42,000 --> 00:00:46,000
59
+ I'm going to see all the actions you did, including all the things you deleted.
60
+
61
+ 16
62
+ 00:00:46,000 --> 00:00:53,000
63
+ So log in is really important in helping keeping you accountable for the actions you took on the system.
64
+
65
+ 17
66
+ 00:00:53,000 --> 00:01:01,000
67
+ So accounting along with authentication, authorization and identification then leads into this concept
68
+
69
+ 18
70
+ 00:01:01,000 --> 00:01:03,000
71
+ of accountability, which we'll cover next.
72
+
73
+ 19
74
+ 00:01:03,000 --> 00:01:08,000
75
+ So just for now, or I should say just in this video, I need you guys to understand that accounting
76
+
77
+ 20
78
+ 00:01:08,000 --> 00:01:11,000
79
+ is about keeping track of everything you do.
80
+
81
+ 21
82
+ 00:01:11,000 --> 00:01:13,000
83
+ It's on servers like windows.
84
+
85
+ 22
86
+ 00:01:13,000 --> 00:01:18,000
87
+ We'll set up user tracking or auditing on them to see in the security log files.
88
+
89
+ 23
90
+ 00:01:18,000 --> 00:01:24,000
91
+ And then of course, you can set up auditing and log in in many other devices such as firewalls, uh,
92
+
93
+ 24
94
+ 00:01:24,000 --> 00:01:27,000
95
+ access points, routers and others.
96
+
97
+ 25
98
+ 00:01:27,000 --> 00:01:28,000
99
+ So how is this done?
100
+
101
+ 26
102
+ 00:01:28,000 --> 00:01:29,000
103
+ Well, user activity tracking.
104
+
105
+ 27
106
+ 00:01:29,000 --> 00:01:30,000
107
+ When did you log in?
108
+
109
+ 28
110
+ 00:01:30,000 --> 00:01:31,000
111
+ When did you log off?
112
+
113
+ 29
114
+ 00:01:31,000 --> 00:01:33,000
115
+ What application you use?
116
+
117
+ 30
118
+ 00:01:33,000 --> 00:01:34,000
119
+ When did you use it?
120
+
121
+ 31
122
+ 00:01:34,000 --> 00:01:36,000
123
+ We're going to store these things in the system log files.
124
+
125
+ 32
126
+ 00:01:36,000 --> 00:01:39,000
127
+ And particularly like in windows in the security log file.
128
+
129
+ 33
130
+ 00:01:39,000 --> 00:01:43,000
131
+ You see users should be aware of this.
132
+
133
+ 34
134
+ 00:01:43,000 --> 00:01:49,000
135
+ All users on a system should be aware that all actions they take is logged by the system log files,
136
+
137
+ 35
138
+ 00:01:49,000 --> 00:01:54,000
139
+ and can be viewed by the authorized professionals, such as the administrators or senior management.
140
+
141
+ 36
142
+ 00:01:54,000 --> 00:01:58,000
143
+ Because it's with accounting, are we going to be able to hold users accountable?
144
+
02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:22939ae9693ee8d035054da5412de3af3b7cc7d126222a92dea24ac7ee8a8058
3
+ size 72878164
02 - Lesson 1 IT Security Fundamentals/012 Accountability OB 1.2_en.srt ADDED
@@ -0,0 +1,240 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:01,000
3
+ When it comes to it security.
4
+
5
+ 2
6
+ 00:00:01,000 --> 00:00:05,000
7
+ One of the things we have to have is going to be accountability.
8
+
9
+ 3
10
+ 00:00:05,000 --> 00:00:08,000
11
+ So what exactly is accountability?
12
+
13
+ 4
14
+ 00:00:08,000 --> 00:00:14,000
15
+ Well, accountability is when we're going to be able to ensure that individuals or entities are held
16
+
17
+ 5
18
+ 00:00:14,000 --> 00:00:16,000
19
+ responsible for their actions.
20
+
21
+ 6
22
+ 00:00:16,000 --> 00:00:21,000
23
+ The thing is, accountability is not something you're going to get by doing nothing, right.
24
+
25
+ 7
26
+ 00:00:21,000 --> 00:00:26,000
27
+ Accountability has a particular set of steps that must be done.
28
+
29
+ 8
30
+ 00:00:26,000 --> 00:00:29,000
31
+ If it's hard to, it's hard to point out where these things are.
32
+
33
+ 9
34
+ 00:00:29,000 --> 00:00:33,000
35
+ Uh, that must be done in order for us to get right here.
36
+
37
+ 10
38
+ 00:00:33,000 --> 00:00:35,000
39
+ So let's let's take a look at this.
40
+
41
+ 11
42
+ 00:00:35,000 --> 00:00:41,000
43
+ So in order to get accountable or in order to hold you accountable for it, the first thing I need to
44
+
45
+ 12
46
+ 00:00:41,000 --> 00:00:43,000
47
+ do is to identify who are you?
48
+
49
+ 13
50
+ 00:00:43,000 --> 00:00:44,000
51
+ What's your name?
52
+
53
+ 14
54
+ 00:00:44,000 --> 00:00:49,000
55
+ Oh, you're Bob, I need to prove to ensure that you prove that you are Bob.
56
+
57
+ 15
58
+ 00:00:49,000 --> 00:00:50,000
59
+ So that's authentication.
60
+
61
+ 16
62
+ 00:00:50,000 --> 00:00:53,000
63
+ This is going to be done maybe with a password or your thumbprint.
64
+
65
+ 17
66
+ 00:00:53,000 --> 00:00:58,000
67
+ And then I want to make sure that I give you the right access to particular things.
68
+
69
+ 18
70
+ 00:00:58,000 --> 00:00:59,000
71
+ Authorization.
72
+
73
+ 19
74
+ 00:00:59,000 --> 00:01:03,000
75
+ And once I know you have access to it I'm going to track that you did it.
76
+
77
+ 20
78
+ 00:01:03,000 --> 00:01:05,000
79
+ That's going to give me accountability.
80
+
81
+ 21
82
+ 00:01:05,000 --> 00:01:10,000
83
+ Now, here's why all of these things are important to get to accountability.
84
+
85
+ 22
86
+ 00:01:10,000 --> 00:01:11,000
87
+ And the reason is this.
88
+
89
+ 23
90
+ 00:01:12,000 --> 00:01:17,000
91
+ If any of these blue boxes are broken, you're not going to get accountability.
92
+
93
+ 24
94
+ 00:01:17,000 --> 00:01:21,000
95
+ For example, let's say everybody was using the same username.
96
+
97
+ 25
98
+ 00:01:21,000 --> 00:01:23,000
99
+ Then there's no real identification.
100
+
101
+ 26
102
+ 00:01:23,000 --> 00:01:26,000
103
+ There's no real way to say that's Bob and that's Mary, right.
104
+
105
+ 27
106
+ 00:01:26,000 --> 00:01:30,000
107
+ Let's say everybody used the same password, but they had different usernames.
108
+
109
+ 28
110
+ 00:01:30,000 --> 00:01:32,000
111
+ Everybody knew each other password.
112
+
113
+ 29
114
+ 00:01:32,000 --> 00:01:34,000
115
+ So when I say, hey Mary, you are still our data.
116
+
117
+ 30
118
+ 00:01:34,000 --> 00:01:36,000
119
+ Mary is going to be like, honestly, your data.
120
+
121
+ 31
122
+ 00:01:36,000 --> 00:01:37,000
123
+ Everybody knows my password.
124
+
125
+ 32
126
+ 00:01:38,000 --> 00:01:39,000
127
+ I can't hold you accountable.
128
+
129
+ 33
130
+ 00:01:39,000 --> 00:01:41,000
131
+ If you never had access to something you're going to.
132
+
133
+ 34
134
+ 00:01:41,000 --> 00:01:44,000
135
+ I'm going to say, hey man, you stole our data, Bob.
136
+
137
+ 35
138
+ 00:01:44,000 --> 00:01:46,000
139
+ And Bob is going to say, I never had access to the data.
140
+
141
+ 36
142
+ 00:01:46,000 --> 00:01:48,000
143
+ That's authorization.
144
+
145
+ 37
146
+ 00:01:48,000 --> 00:01:53,000
147
+ I'm going to say, hey, Bob, you stole the data, and Bob is going to be like, so prove that I actually
148
+
149
+ 38
150
+ 00:01:53,000 --> 00:01:54,000
151
+ stole the data.
152
+
153
+ 39
154
+ 00:01:54,000 --> 00:01:59,000
155
+ That's accounting account is going to track what they did when they did it, how they did it right with
156
+
157
+ 40
158
+ 00:01:59,000 --> 00:02:00,000
159
+ those log files.
160
+
161
+ 41
162
+ 00:02:00,000 --> 00:02:07,000
163
+ So for us to get here to get accountability, we need to have all of these particular things done.
164
+
165
+ 42
166
+ 00:02:07,000 --> 00:02:13,000
167
+ And if any one of those blue boxes are broken, you can best bet that you're not going to get the black
168
+
169
+ 43
170
+ 00:02:13,000 --> 00:02:13,000
171
+ box.
172
+
173
+ 44
174
+ 00:02:13,000 --> 00:02:15,000
175
+ You're not going to get accountability.
176
+
177
+ 45
178
+ 00:02:15,000 --> 00:02:19,000
179
+ So I want to make sure these things here are absolutely correct.
180
+
181
+ 46
182
+ 00:02:19,000 --> 00:02:20,000
183
+ Now you got to remember something.
184
+
185
+ 47
186
+ 00:02:20,000 --> 00:02:23,000
187
+ Accountability is a core concept of security.
188
+
189
+ 48
190
+ 00:02:23,000 --> 00:02:24,000
191
+ Remember this.
192
+
193
+ 49
194
+ 00:02:24,000 --> 00:02:30,000
195
+ If you know you're going to be held accountable for something, you're less likely to commit that crime
196
+
197
+ 50
198
+ 00:02:30,000 --> 00:02:31,000
199
+ driving down the highway.
200
+
201
+ 51
202
+ 00:02:32,000 --> 00:02:36,000
203
+ Imagine every couple of hundred feet on a highway.
204
+
205
+ 52
206
+ 00:02:36,000 --> 00:02:37,000
207
+ There's a cop.
208
+
209
+ 53
210
+ 00:02:37,000 --> 00:02:38,000
211
+ You'd think anybody would speed, right?
212
+
213
+ 54
214
+ 00:02:38,000 --> 00:02:40,000
215
+ You're going up a highway and there's a cop sitting there.
216
+
217
+ 55
218
+ 00:02:41,000 --> 00:02:45,000
219
+ A whole highway slows down or people goes back to the speed limit because they're going to be held accountable.
220
+
221
+ 56
222
+ 00:02:45,000 --> 00:02:47,000
223
+ If you're speeding, you're more likely to get caught.
224
+
225
+ 57
226
+ 00:02:47,000 --> 00:02:54,000
227
+ If somebody knows that every action you take, you're going to be held accountable to those actions.
228
+
229
+ 58
230
+ 00:02:54,000 --> 00:03:00,000
231
+ You're less likely to take bad actions, illegal actions.
232
+
233
+ 59
234
+ 00:03:00,000 --> 00:03:00,000
235
+ Correct.
236
+
237
+ 60
238
+ 00:03:00,000 --> 00:03:04,000
239
+ That's why accountability is really important.
240
+
02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:8634f2ffc03b7f69b11617fc6e8a4d7c22bc2f27b07d09af4c4a72bfbc625b2c
3
+ size 54590058
02 - Lesson 1 IT Security Fundamentals/013 Gap analysis OB 1.2_en.srt ADDED
@@ -0,0 +1,188 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:01,000
3
+ In today's organizations.
4
+
5
+ 2
6
+ 00:00:01,000 --> 00:00:08,000
7
+ We all want to go from being good to being great, from making 1 million to 2 million, from being not
8
+
9
+ 3
10
+ 00:00:08,000 --> 00:00:10,000
11
+ so secure to being very secure.
12
+
13
+ 4
14
+ 00:00:10,000 --> 00:00:17,000
15
+ You see, in order to go from here currently to our desired state or where we want to be, we have to
16
+
17
+ 5
18
+ 00:00:17,000 --> 00:00:19,000
19
+ perform what's called a gap analysis.
20
+
21
+ 6
22
+ 00:00:19,000 --> 00:00:20,000
23
+ Easy example.
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:24,000
27
+ Well, I'm £210 today and I want to be £180.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:27,000
31
+ Well, we've got a gap of £30.
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:30,000
35
+ You see we have to do a gap analysis.
36
+
37
+ 10
38
+ 00:00:30,000 --> 00:00:35,000
39
+ We have to perform an assessment to see where we are right now and how are we going to get there.
40
+
41
+ 11
42
+ 00:00:36,000 --> 00:00:40,000
43
+ So notice terms for your exam a gap analysis.
44
+
45
+ 12
46
+ 00:00:40,000 --> 00:00:44,000
47
+ It's an assessment that organizations use to compare the current state.
48
+
49
+ 13
50
+ 00:00:44,000 --> 00:00:46,000
51
+ That means where they are currently in terms of security.
52
+
53
+ 14
54
+ 00:00:46,000 --> 00:00:53,000
55
+ Remember we are talking security here with a set of standards best practices or regulatory requirements.
56
+
57
+ 15
58
+ 00:00:53,000 --> 00:00:58,000
59
+ So in terms of gap analysis, when it comes to IT security right now there may be a new regulation that
60
+
61
+ 16
62
+ 00:00:58,000 --> 00:01:01,000
63
+ is out there and your organization is here.
64
+
65
+ 17
66
+ 00:01:01,000 --> 00:01:03,000
67
+ So you've got to see what what do we have to do.
68
+
69
+ 18
70
+ 00:01:03,000 --> 00:01:08,000
71
+ What are the controls and mechanisms and things we have to change to meet the new requirements.
72
+
73
+ 19
74
+ 00:01:08,000 --> 00:01:09,000
75
+ So that's going to be the gap.
76
+
77
+ 20
78
+ 00:01:09,000 --> 00:01:14,000
79
+ So in order to do this, one of the first things you have to know is where you are identification of
80
+
81
+ 21
82
+ 00:01:14,000 --> 00:01:15,000
83
+ that current state.
84
+
85
+ 22
86
+ 00:01:16,000 --> 00:01:19,000
87
+ What is your existing security controls and policies?
88
+
89
+ 23
90
+ 00:01:19,000 --> 00:01:21,000
91
+ Then you have to decide, well, where do you want to be?
92
+
93
+ 24
94
+ 00:01:21,000 --> 00:01:22,000
95
+ Right.
96
+
97
+ 25
98
+ 00:01:22,000 --> 00:01:26,000
99
+ So what exactly is going to be that desired state?
100
+
101
+ 26
102
+ 00:01:26,000 --> 00:01:31,000
103
+ Is it a particular policy you're trying to meet a particular standard, a particular um.
104
+
105
+ 27
106
+ 00:01:32,000 --> 00:01:38,000
107
+ Regulation that you want to meet so you can understand what is that like standard.
108
+
109
+ 28
110
+ 00:01:38,000 --> 00:01:38,000
111
+ Right.
112
+
113
+ 29
114
+ 00:01:38,000 --> 00:01:40,000
115
+ What is that target that you want to be.
116
+
117
+ 30
118
+ 00:01:40,000 --> 00:01:42,000
119
+ Then comes the analysis of the gap.
120
+
121
+ 31
122
+ 00:01:42,000 --> 00:01:44,000
123
+ So how do we get there.
124
+
125
+ 32
126
+ 00:01:44,000 --> 00:01:44,000
127
+ Right.
128
+
129
+ 33
130
+ 00:01:44,000 --> 00:01:45,000
131
+ How are we going to go from here.
132
+
133
+ 34
134
+ 00:01:45,000 --> 00:01:47,000
135
+ How am I going to go from 180?
136
+
137
+ 35
138
+ 00:01:47,000 --> 00:01:50,000
139
+ I'm sorry I wish I was 180 from 210 to 180.
140
+
141
+ 36
142
+ 00:01:50,000 --> 00:01:51,000
143
+ Right.
144
+
145
+ 37
146
+ 00:01:51,000 --> 00:01:52,000
147
+ How am I going to do that?
148
+
149
+ 38
150
+ 00:01:52,000 --> 00:01:55,000
151
+ The core of the gap analysis is identifying the difference between the two.
152
+
153
+ 39
154
+ 00:01:55,000 --> 00:01:56,000
155
+ And how are we going to get there?
156
+
157
+ 40
158
+ 00:01:57,000 --> 00:02:03,000
159
+ So keep in mind, guys, what a gap analysis is, is basically knowing your current state to your desired
160
+
161
+ 41
162
+ 00:02:03,000 --> 00:02:07,000
163
+ state and then looking at hey, what is what is the gap?
164
+
165
+ 42
166
+ 00:02:07,000 --> 00:02:08,000
167
+ How far are we off?
168
+
169
+ 43
170
+ 00:02:08,000 --> 00:02:11,000
171
+ I'm £30 off how far his organization will be.
172
+
173
+ 44
174
+ 00:02:11,000 --> 00:02:17,000
175
+ We're off by these many controls and these many policies that has to get implemented to meet the future
176
+
177
+ 45
178
+ 00:02:17,000 --> 00:02:17,000
179
+ state.
180
+
181
+ 46
182
+ 00:02:17,000 --> 00:02:18,000
183
+ And that is what.
184
+
185
+ 47
186
+ 00:02:18,000 --> 00:02:21,000
187
+ And that is what a gap analysis is.
188
+
02 - Lesson 1 IT Security Fundamentals/014 Quick Quiz.html ADDED
@@ -0,0 +1,479 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ <!DOCTYPE html>
2
+ <html lang="en">
3
+ <head>
4
+ <meta charset="UTF-8" />
5
+ <meta http-equiv="X-UA-Compatible" content="IE=edge" />
6
+ <meta name="viewport" content="width=device-width, initial-scale=1.0" />
7
+ <title>Quiz</title>
8
+ <style>
9
+ * {
10
+ font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, Cantarell,
11
+ "Open Sans", "Helvetica Neue", sans-serif;
12
+ margin: 0;
13
+ padding: 0;
14
+ box-sizing: border-box;
15
+ font-size: 16px;
16
+ }
17
+
18
+ main {
19
+ padding-top: 48px;
20
+ }
21
+
22
+ :root {
23
+ --large-device-width: 850px;
24
+ --primary-color: #0f172a;
25
+ --secondary-color: #020617;
26
+ --primary-text-color: #c7d1dd;
27
+ --secondary-text-color: #061602;
28
+ --success-background: hsl(159, 82%, 24%);
29
+ --success-foreground: hsl(164, 86%, 16%);
30
+ --success: hsl(160, 84%, 39%);
31
+ --danger: #ef4444;
32
+ --warning: #f59e0b;
33
+ --info-background: hsl(218, 81%, 8%);
34
+ --info-foreground: hsl(217, 91%, 85%);
35
+ --border-color: #d1d7dc;
36
+ --check-box-size: 20px;
37
+ /* control the size */
38
+ --check-box-color: var(--info-foreground);
39
+ /* the active color */
40
+ }
41
+
42
+ body {
43
+ position: relative;
44
+ background-color: #020617;
45
+ color: var(--primary-text-color);
46
+ }
47
+
48
+ #score-stats-container {
49
+ position: fixed;
50
+ z-index: 10;
51
+ top: 0;
52
+ height: 40px;
53
+ width: 100%;
54
+ background-color: var(--info-background);
55
+
56
+ padding: 0px 16px;
57
+ color: var(--info-foreground);
58
+ font-weight: 600;
59
+ display: flex;
60
+ align-items: center;
61
+ justify-content: space-between;
62
+ }
63
+
64
+ #quiz-container {
65
+ border-radius: 8px;
66
+ display: flex;
67
+ gap: 16px;
68
+ flex-direction: column;
69
+ }
70
+
71
+ input[type="radio"] {
72
+ height: var(--check-box-size);
73
+ aspect-ratio: 1;
74
+ border: calc(var(--check-box-size) / 8) solid #939393;
75
+ padding: calc(var(--check-box-size) / 8);
76
+ background: radial-gradient(farthest-side, var(--check-box-color) 94%, #0000) 50%/0 0 no-repeat
77
+ content-box;
78
+ border-radius: 50%;
79
+ outline-offset: calc(var(--check-box-size) / 10);
80
+ -webkit-appearance: none;
81
+ -moz-appearance: none;
82
+ appearance: none;
83
+ cursor: pointer;
84
+ font-size: inherit;
85
+ transition: 0.3s;
86
+ }
87
+
88
+ input[type="radio"]:checked {
89
+ border-color: var(--check-box-color);
90
+ background-size: 100% 100%;
91
+ }
92
+
93
+ input[type="radio"]:disabled {
94
+ background: linear-gradient(#939393 0 0) 50%/100% 20% no-repeat content-box;
95
+ opacity: 0.5;
96
+ cursor: not-allowed;
97
+ }
98
+
99
+ label {
100
+ display: inline-flex;
101
+ align-items: center;
102
+ gap: 10px;
103
+ cursor: pointer;
104
+ padding: 4px 6px;
105
+ border-radius: 4px;
106
+ }
107
+
108
+ @media (max-width: 767px) {
109
+ input[type="radio"],
110
+ label {
111
+ cursor: default;
112
+ }
113
+
114
+ #quiz-container {
115
+ margin-left: 8px;
116
+ margin-right: 8px;
117
+ }
118
+ }
119
+
120
+ /* PC (Desktop devices) */
121
+ @media (min-width: 768px) {
122
+ body {
123
+ display: flex;
124
+ justify-content: center;
125
+ }
126
+
127
+ main {
128
+ max-width: var(--large-device-width);
129
+ }
130
+
131
+ #score-stats-container {
132
+ max-width: var(--large-device-width);
133
+ }
134
+
135
+ dialog {
136
+ max-width: var(--large-device-width);
137
+ }
138
+ }
139
+
140
+ @media print {
141
+ input[type="radio"] {
142
+ background: none !important;
143
+ border-color: #939393 !important;
144
+ }
145
+
146
+ input[type="radio"]:checked {
147
+ border-color: #939393 !important;
148
+ }
149
+ }
150
+
151
+ .question-lable {
152
+ display: flex;
153
+ align-items: center;
154
+ gap: 8px;
155
+ }
156
+
157
+ button {
158
+ -webkit-tap-highlight-color: transparent;
159
+ -webkit-touch-callout: none;
160
+ -webkit-user-select: none;
161
+ user-select: none;
162
+ outline: none;
163
+ position: relative;
164
+ overflow: hidden;
165
+ cursor: pointer;
166
+ }
167
+
168
+ .button {
169
+ background-color: var(--success-background);
170
+ border: none;
171
+ color: #f4f5f7;
172
+ opacity: 0.8;
173
+ font-size: 18px;
174
+ flex-grow: 1;
175
+ padding: 8px 16px;
176
+ border-radius: 8px;
177
+ }
178
+
179
+ .button:hover {
180
+ opacity: 1;
181
+ }
182
+
183
+ .explanation-btn {
184
+ border: none;
185
+ color: var(--success);
186
+ background-color: transparent;
187
+ }
188
+
189
+ #submit-button:active::after {
190
+ background-color: #ef4444;
191
+ }
192
+
193
+ .single-question-container {
194
+ background-color: var(--primary-color);
195
+ display: flex;
196
+ flex-direction: column;
197
+ gap: 8px;
198
+ padding: 16px;
199
+ border-radius: 8px;
200
+ }
201
+
202
+ #modal-content {
203
+ padding: 16px;
204
+ line-height: 24px;
205
+ }
206
+
207
+ dialog::backdrop {
208
+ background: rgba(0, 0, 0, 0.5);
209
+ }
210
+
211
+ dialog {
212
+ position: fixed;
213
+ border: 1px solid var(--border-color);
214
+ background-color: var(--primary-color);
215
+ color: rgb(240, 241, 248);
216
+ padding: 16px;
217
+ border-radius: 8px;
218
+ width: 80vw;
219
+ max-height: 80vh;
220
+ overflow: auto;
221
+ top: 50%;
222
+ left: 50%;
223
+ -webkit-transform: translateX(-50%) translateY(-50%);
224
+ -moz-transform: translateX(-50%) translateY(-50%);
225
+ -ms-transform: translateX(-50%) translateY(-50%);
226
+ transform: translateX(-50%) translateY(-50%);
227
+ }
228
+
229
+ #close-modal-btn {
230
+ position: absolute;
231
+ top: 4px;
232
+ right: 4px;
233
+ padding: 2px 8px;
234
+ border-radius: 2px;
235
+ border: none;
236
+ background-color: var(--danger);
237
+ }
238
+
239
+ .correct-answer label {
240
+ border: 2px solid var(--success);
241
+ width: 100%;
242
+ }
243
+
244
+ .incorrect-answer label {
245
+ border: 2px solid var(--danger);
246
+ width: 100%;
247
+ }
248
+
249
+ .options-container {
250
+ display: flex;
251
+ flex-direction: column;
252
+ gap: 4px;
253
+ }
254
+
255
+ #quiz-meta-container {
256
+ border-radius: 8px;
257
+ background-color: var(--primary-color);
258
+ margin-bottom: 12px;
259
+ padding: 8px;
260
+ }
261
+
262
+ #quiz-title {
263
+ text-align: center;
264
+ font-size: 24px;
265
+ margin-bottom: 8px;
266
+ }
267
+
268
+ #quiz-description {
269
+ line-height: 1.5;
270
+ padding: 2px 6px;
271
+ }
272
+ </style>
273
+ </head>
274
+
275
+ <body onload="main()">
276
+ <main>
277
+ <section id="quiz-meta-container">
278
+ <h1 id="quiz-title"></h1>
279
+ <p id="quiz-description"></p>
280
+ </section>
281
+ <section id="score-stats-container">
282
+ <div id="score-card">
283
+ Score: <span id="current-score">999</span> of
284
+ <span id="pass-percent">999%</span>
285
+ </div>
286
+ <div>Correct: <span id="correct-answers">999</span></div>
287
+ <div>Incorrect: <span id="wrong-answers">999</span></div>
288
+ </section>
289
+
290
+ <section id="quiz-container"></section>
291
+
292
+ <dialog id="modal" class="modal-container">
293
+ <div id="modal-content">
294
+ <p id="modal-text"></p>
295
+ </div>
296
+ </dialog>
297
+ </main>
298
+
299
+ <script>
300
+ const quizData = {"quiz_id": 6180068, "quiz_description": null, "quiz_title": "Quick Quiz", "pass_percent": null, "questions": [{"_class": "assessment", "id": 74726732, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A network adopts a security model where it does not automatically trust any entity inside or outside its perimeter until verified. This approach is known as what?</p>", "relatedLectureIds": "", "feedbacks": ["", "The Zero Trust model operates on the principle of \"never trust, always verify,\" not automatically trusting any entity without verification, regardless of their location in relation to the network's perimeter. The Control Plane and Data Plane are components of network architecture, and Policy Administrator is a role in managing security policies.", "", ""], "answers": ["<p>Control Plane</p>", "<p>Zero Trust</p>", "<p>Policy Administrator</p>", "<p>Data Plane</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A network adopts a security model where it does not automatically trust any entity inside or outside its perimeter until verified. This approach is known as what?", "related_lectures": []}, {"_class": "assessment", "id": 74726736, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A company encrypts its sensitive emails to ensure that only the intended recipient can read them. This practice primarily enhances which aspect of security?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "", "Encrypting emails ensures that they cannot be read by unauthorized individuals, which is a direct measure to protect the confidentiality of the information. Integrity refers to safeguarding data from unauthorized modifications, availability focuses on ensuring data is accessible when needed, and authorization is about granting permissions to users."], "answers": ["<p>Integrity</p>", "<p>Availability</p>", "<p>Authorization</p>", "<p>Confidentiality</p>"]}, "correct_response": ["d"], "section": "", "question_plain": "A company encrypts its sensitive emails to ensure that only the intended recipient can read them. This practice primarily enhances which aspect of security?", "related_lectures": []}, {"_class": "assessment", "id": 74728330, "assessment_type": "multiple-choice", "prompt": {"question": "<p>An organization ensures that only specific individuals can modify financial records and tracks these modifications. This is primarily a practice of:</p>", "relatedLectureIds": "", "feedbacks": ["Integrity ensures that data is accurate and unaltered, and accounting involves keeping logs of who performed what actions. Limiting and tracking modifications to financial records ensures data integrity and involves accounting for those changes. Confidentiality is about keeping data secret, non-repudiation is ensuring actions cannot be denied, and availability ensures data is accessible when needed. Gap Analysis is a method for determining the difference between current and desired states.", "", "", ""], "answers": ["<p>Integrity and Accounting</p>", "<p>Confidentiality and Non-repudiation</p>", "<p>Availability and Authentication</p>", "<p>Gap Analysis</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "An organization ensures that only specific individuals can modify financial records and tracks these modifications. This is primarily a practice of:", "related_lectures": []}, {"_class": "assessment", "id": 74728336, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A cybersecurity team conducts an assessment to identify differences between the current security measures and the desired optimal security posture. This assessment is called:</p>", "relatedLectureIds": "", "feedbacks": ["", "", "", "Gap Analysis in cybersecurity is the process of comparing the current security measures (what is) with the desired, optimal security state (what should be). This helps in identifying gaps in the security posture that need to be addressed. Zero Trust Implementation is about establishing a security model based on strict verification, Non-repudiation Audit would involve ensuring actions or communications cannot be denied by the parties involved, and AAA Review would focus on authentication, authorization, and accounting procedures."], "answers": ["<p>Zero Trust Implementation</p>", "<p>Non-repudiation Audit</p>", "<p>AAA Review</p>", "<p>Gap Analysis</p>"]}, "correct_response": ["d"], "section": "", "question_plain": "A cybersecurity team conducts an assessment to identify differences between the current security measures and the desired optimal security posture. This assessment is called:", "related_lectures": []}, {"_class": "assessment", "id": 74728340, "assessment_type": "multiple-choice", "prompt": {"question": "<p>An organization's network automatically logs all user activities, providing a detailed record of who accessed what resources and when. This practice is an example of:</p>", "relatedLectureIds": "", "feedbacks": ["", "", "Accounting in the context of security refers to the tracking of user activities, including what resources they access and when. This is essential for auditing and monitoring purposes, helping in detecting unauthorized access or abnormal activities. Non-repudiation ensures the actions of a user cannot be denied, authentication is about verifying identity, and authorization is granting access to resources based on authenticated identity.", ""], "answers": ["<p>Non-repudiation</p>", "<p>Authentication</p>", "<p>Accounting</p>", "<p>Authorization</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "An organization's network automatically logs all user activities, providing a detailed record of who accessed what resources and when. This practice is an example of:", "related_lectures": []}]};
301
+ let correct = new Set();
302
+ let incorrect = new Set();
303
+ let totalNumberOfQuestions = 0;
304
+ const quizTitle = quizData.quiz_title;
305
+ const quizDescription = quizData.quiz_description;
306
+ const questionData = quizData.questions;
307
+ const passPercent = quizData.pass_percent;
308
+ const modalTextElement = document.getElementById("modal-text");
309
+ const quizContainerElement = document.getElementById("quiz-container");
310
+
311
+ const dialog = document.querySelector("dialog");
312
+ const showButton = document.getElementById("view-explanatin");
313
+ const closeButton = document.getElementById("close-modal-btn");
314
+ const quizTitleElement = document.getElementById("quiz-title");
315
+ const quizDescriptionElement = document.getElementById("quiz-description");
316
+
317
+ function main() {
318
+ // update quiz meta data
319
+ document.title = quizTitle;
320
+ quizTitleElement.innerHTML = quizTitle;
321
+ quizDescriptionElement.innerHTML = quizDescription;
322
+
323
+ const passPercentElement = document.getElementById("pass-percent");
324
+ passPercentElement.innerHTML = passPercent + "%";
325
+ totalNumberOfQuestions = questionData.length;
326
+ // shuffle the questionData to randomize the order of the questions
327
+ for (let i = questionData.length - 1; i > 0; i--) {
328
+ const j = Math.floor(Math.random() * (i + 1));
329
+ [questionData[i], questionData[j]] = [questionData[j], questionData[i]];
330
+ }
331
+
332
+ let formattedQuestions = questionData.map(formatSingleQuestionData);
333
+ updateScore();
334
+ // display the formattedQuestions
335
+ formattedQuestions.forEach((question, idx) => {
336
+ renderSingleQuestion(question, idx + 1);
337
+ });
338
+ }
339
+
340
+ /**
341
+ * Formats the question data from the given QuizData object.
342
+ *
343
+ * @param {Object} singleQuizData - The singleQuizData object containing prompt and correct_response.
344
+ * @return {Object} The formatted question object with the following properties:
345
+ * - id: The ID of the question.
346
+ * - question: The text of the question.
347
+ * - answers: The array of answer options.
348
+ * - correctAnswer: The text of the correct answer.
349
+ * - explanation: The explanation of the correct answer.
350
+ */
351
+ function formatSingleQuestionData(singleQuizData = null) {
352
+ const { prompt, correct_response, id } = singleQuizData;
353
+ const questionText = prompt.question;
354
+ const answers = prompt.answers;
355
+ const correctAnswer = correct_response[0];
356
+ const correctAnswerText = answers[correctAnswer.toLowerCase().charCodeAt(0) - 97];
357
+ const questionObj = {
358
+ id: id,
359
+ question: questionText,
360
+ answers: answers,
361
+ correctAnswer: correctAnswerText,
362
+ explanation: prompt?.explanation || "",
363
+ };
364
+ return questionObj;
365
+ }
366
+
367
+ /**
368
+ * Renders a single question with its options and submit button.
369
+ *
370
+ * @param {Object} singleQuestionData - The data of the question to render.
371
+ * @param {number} rootIndex - The index of the question in the quiz.
372
+ * @return {void} return nothing.
373
+ */
374
+
375
+ const renderSingleQuestion = (singleQuestionData = {}, rootIndex = 1) => {
376
+ const { id, explanation, answers, correctAnswer, question } = singleQuestionData;
377
+ // shuffle the answers to randomize the order of the answers
378
+ for (let i = answers.length - 1; i > 0; i--) {
379
+ const j = Math.floor(Math.random() * (i + 1));
380
+ [answers[i], answers[j]] = [answers[j], answers[i]];
381
+ }
382
+ const optionsHTML = answers
383
+ .map((option, index) => {
384
+ const optionId = `${id}_${index}`;
385
+
386
+ return `
387
+ <div class="question-lable">
388
+ <input type="radio" id="${optionId}" name="${"answer"}" value="${option}" />
389
+ <label for="${optionId}">${option}</label>
390
+ </div>
391
+ `;
392
+ })
393
+
394
+ .join("");
395
+
396
+ const container = document.createElement("div");
397
+ container.innerHTML = `
398
+ <form data-correct-answer="${correctAnswer}" data-question-id="${id}" class="single-question-container" onsubmit="submitButtonListener(event)">
399
+ <div style="display: flex;justify-content: space-between;">
400
+ <p style="font-weight: 600">Question ${rootIndex}:</p>
401
+ <button type="button" onclick="renderExplanation(event)" id="${`explanation-${id}`}" data-explanation="${explanation}" class="explanation-btn">View Explanation</button>
402
+ </div>
403
+ <p style="margin-bottom: 8px;line-height: 1.5">${question}</p>
404
+ <div class="options-container">
405
+ ${optionsHTML}
406
+ </div>
407
+ <div style="display: flex; gap: 8px;">
408
+ <button type="submit" id="submit-button" class="button">Submit</button>
409
+ </div>
410
+ </form>
411
+ `;
412
+ quizContainerElement.appendChild(container);
413
+ };
414
+
415
+ /**
416
+ * Updates the score on the page based on the number of correct and incorrect answers.
417
+ *
418
+ * @return {void} This function does not return a value.
419
+ */
420
+ function updateScore() {
421
+ const currentParcentageElement = document.getElementById("current-score");
422
+ const correctAnswerElement = document.getElementById("correct-answers");
423
+ const wrongAnswerElement = document.getElementById("wrong-answers");
424
+ correctAnswerElement.innerHTML = correct.size;
425
+ wrongAnswerElement.innerHTML = incorrect.size;
426
+ const score = Number((correct.size / totalNumberOfQuestions) * 100).toFixed(2);
427
+ currentParcentageElement.innerHTML = score;
428
+ }
429
+
430
+ /**
431
+ * Handles the event when the submit button is clicked.
432
+ *
433
+ * @param {Event} e - The event object.
434
+ * @return {void} This function does not return anything.
435
+ */
436
+ const submitButtonListener = (e) => {
437
+ e.preventDefault();
438
+ const formData = new FormData(e.target);
439
+ const form = e.target;
440
+ const selectedOption = e.target.querySelector('input[type="radio"]:checked');
441
+ if (!selectedOption) {
442
+ alert("Please select an answer!");
443
+ return;
444
+ }
445
+
446
+ let isCorrect = false;
447
+ const { answer: userAnswer } = Object.fromEntries(formData.entries());
448
+ const correctAnswer = e.target.dataset.correctAnswer;
449
+ const questionId = e.target.dataset.questionId;
450
+ if (userAnswer == correctAnswer) {
451
+ correct.add(questionId);
452
+ incorrect.delete(questionId);
453
+ isCorrect = true;
454
+ } else {
455
+ incorrect.add(e.target.dataset.questionId);
456
+ correct.delete(questionId);
457
+ }
458
+ updateScore();
459
+
460
+ const resultClass = isCorrect ? "correct-answer" : "incorrect-answer";
461
+
462
+ form.querySelectorAll(".question-lable").forEach((label) => {
463
+ label.classList.remove("correct-answer", "incorrect-answer");
464
+ });
465
+ selectedOption.closest(".question-lable").classList.add(resultClass);
466
+ };
467
+
468
+ function renderExplanation(ev) {
469
+ modalTextElement.innerHTML = ev.target.dataset?.explanation || "no explanation found";
470
+ dialog.showModal();
471
+ dialog.addEventListener("click", (event) => {
472
+ if (event.target === dialog) {
473
+ dialog.close();
474
+ }
475
+ });
476
+ }
477
+ </script>
478
+ </body>
479
+ </html>
03 - Security Controls Categories and Types/001 Control Categories OB 1.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:cdf2e7a6c48ee07ed1ff6fc5e4153246b54b1beea7a7bcafdf7816bb41197afa
3
+ size 236173595
03 - Security Controls Categories and Types/001 Control Categories OB 1.1_en.srt ADDED
@@ -0,0 +1,320 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:01,000
3
+ Okay.
4
+
5
+ 2
6
+ 00:00:01,000 --> 00:00:07,000
7
+ What does a security policy, a camera and the firewall have in common?
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:15,000
11
+ Well, all of these things, such as my paper policy, my user access policy that I have that's not
12
+
13
+ 4
14
+ 00:00:15,000 --> 00:00:15,000
15
+ filled out here.
16
+
17
+ 5
18
+ 00:00:15,000 --> 00:00:17,000
19
+ But just keep in mind this is just a policy.
20
+
21
+ 6
22
+ 00:00:17,000 --> 00:00:20,000
23
+ What does all of these things here have in common.
24
+
25
+ 7
26
+ 00:00:20,000 --> 00:00:24,000
27
+ And that is all about protecting our network.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:32,000
31
+ For example, this firewall will protect our network from having worms, having all kinds of viruses
32
+
33
+ 9
34
+ 00:00:32,000 --> 00:00:34,000
35
+ and hackers from breaking into our network.
36
+
37
+ 10
38
+ 00:00:34,000 --> 00:00:40,000
39
+ This policy will tell you what you should be doing on my computer and what you shouldn't be doing.
40
+
41
+ 11
42
+ 00:00:40,000 --> 00:00:47,000
43
+ And this camera is going to keep an eye on you as you walk around my physical facilities that this GoPro
44
+
45
+ 12
46
+ 00:00:47,000 --> 00:00:51,000
47
+ in particular, but more of a CCTV or more of the cameras you see on the walls.
48
+
49
+ 13
50
+ 00:00:51,000 --> 00:00:53,000
51
+ But let's just say that's one of them.
52
+
53
+ 14
54
+ 00:00:53,000 --> 00:00:58,000
55
+ So in this video I want to talk about different categories of control.
56
+
57
+ 15
58
+ 00:00:58,000 --> 00:01:04,000
59
+ And these are three different categories from a technical category from a technical control and administrative
60
+
61
+ 16
62
+ 00:01:04,000 --> 00:01:07,000
63
+ or managerial control and a physical control.
64
+
65
+ 17
66
+ 00:01:07,000 --> 00:01:08,000
67
+ Let's get into this.
68
+
69
+ 18
70
+ 00:01:09,000 --> 00:01:14,000
71
+ So the first category I want to talk about is going to be technical controls.
72
+
73
+ 19
74
+ 00:01:14,000 --> 00:01:21,000
75
+ As IT professionals we are more interested and we think more of technical controls.
76
+
77
+ 20
78
+ 00:01:21,000 --> 00:01:26,000
79
+ But you've got to keep in mind you can have the best technical controls out there such as firewalls,
80
+
81
+ 21
82
+ 00:01:26,000 --> 00:01:28,000
83
+ IDs, systems, encryption, antivirus.
84
+
85
+ 22
86
+ 00:01:28,000 --> 00:01:30,000
87
+ You can have the best technical controls.
88
+
89
+ 23
90
+ 00:01:30,000 --> 00:01:35,000
91
+ And if somebody can walk into the network and pick up your your data or your server and walk back out,
92
+
93
+ 24
94
+ 00:01:35,000 --> 00:01:36,000
95
+ it's not very good.
96
+
97
+ 25
98
+ 00:01:36,000 --> 00:01:40,000
99
+ So technical controls are basically the also known as logical controls.
100
+
101
+ 26
102
+ 00:01:40,000 --> 00:01:45,000
103
+ And they're mechanisms that we use in hardware, software and firmware to help secure our network.
104
+
105
+ 27
106
+ 00:01:45,000 --> 00:01:50,000
107
+ Now this is going to help us to prevent, detect and respond to security threats.
108
+
109
+ 28
110
+ 00:01:50,000 --> 00:01:51,000
111
+ Here's what I tell my students.
112
+
113
+ 29
114
+ 00:01:51,000 --> 00:01:59,000
115
+ If it's something you configure in a hardware and software like this device, it's considered a technical
116
+
117
+ 30
118
+ 00:01:59,000 --> 00:02:01,000
119
+ control or logical control.
120
+
121
+ 31
122
+ 00:02:01,000 --> 00:02:01,000
123
+ Same thing.
124
+
125
+ 32
126
+ 00:02:02,000 --> 00:02:05,000
127
+ The other one I have is going to fall into this category.
128
+
129
+ 33
130
+ 00:02:05,000 --> 00:02:10,000
131
+ This is going to be a managerial control also known as administrative controls.
132
+
133
+ 34
134
+ 00:02:10,000 --> 00:02:16,000
135
+ So administrative controls are generally I tell my students are basically going to be anything on paper
136
+
137
+ 35
138
+ 00:02:16,000 --> 00:02:23,000
139
+ that's going to be some kind of security policy, risk management processes, recovery plans, um,
140
+
141
+ 36
142
+ 00:02:24,000 --> 00:02:27,000
143
+ incident responses and plans and disaster recovery plans.
144
+
145
+ 37
146
+ 00:02:27,000 --> 00:02:33,000
147
+ Anything that you're going to find on a piece of paper is going to fall into this category of managerial
148
+
149
+ 38
150
+ 00:02:33,000 --> 00:02:36,000
151
+ or also known as administrative control.
152
+
153
+ 39
154
+ 00:02:36,000 --> 00:02:40,000
155
+ Another one we have is going to be operational security controls.
156
+
157
+ 40
158
+ 00:02:40,000 --> 00:02:48,000
159
+ Now, operational controls are basically the things that we do to on a day to day to ensure that we
160
+
161
+ 41
162
+ 00:02:48,000 --> 00:02:51,000
163
+ enforce the organization's policies and procedures.
164
+
165
+ 42
166
+ 00:02:51,000 --> 00:02:53,000
167
+ This is going to be done by people.
168
+
169
+ 43
170
+ 00:02:54,000 --> 00:02:57,000
171
+ So we're going to be doing this to maintain the security.
172
+
173
+ 44
174
+ 00:02:57,000 --> 00:03:01,000
175
+ So what are things that people do within the organization generally?
176
+
177
+ 45
178
+ 00:03:01,000 --> 00:03:03,000
179
+ Security awareness training.
180
+
181
+ 46
182
+ 00:03:03,000 --> 00:03:05,000
183
+ That's something that you should have people be doing.
184
+
185
+ 47
186
+ 00:03:05,000 --> 00:03:10,000
187
+ Training the users how to detect phishing links, training the users not to get scammed or click on
188
+
189
+ 48
190
+ 00:03:10,000 --> 00:03:11,000
191
+ bad things.
192
+
193
+ 49
194
+ 00:03:11,000 --> 00:03:15,000
195
+ Physical media protection such as protecting a USB stick, for example.
196
+
197
+ 50
198
+ 00:03:16,000 --> 00:03:18,000
199
+ And then come the physical control.
200
+
201
+ 51
202
+ 00:03:18,000 --> 00:03:24,000
203
+ Now, while I know security guys are pretty good at technical stuff, I know a lot of use.
204
+
205
+ 52
206
+ 00:03:24,000 --> 00:03:28,000
207
+ Security guys, especially experienced security guys are really good at this one.
208
+
209
+ 53
210
+ 00:03:28,000 --> 00:03:30,000
211
+ This firewall configuration thing.
212
+
213
+ 54
214
+ 00:03:31,000 --> 00:03:35,000
215
+ Uh, most of us would be good at that.
216
+
217
+ 55
218
+ 00:03:35,000 --> 00:03:40,000
219
+ A good set of us, not most of us, though, will also have a lot of respect and implement a lot of
220
+
221
+ 56
222
+ 00:03:40,000 --> 00:03:43,000
223
+ managerial controls or administrative controls, such as policies.
224
+
225
+ 57
226
+ 00:03:44,000 --> 00:03:50,000
227
+ And of course, we're all doing the day to day work, but not many of security people nowadays think
228
+
229
+ 58
230
+ 00:03:50,000 --> 00:03:51,000
231
+ of physical controls.
232
+
233
+ 59
234
+ 00:03:51,000 --> 00:03:55,000
235
+ Physical controls are really important, like I mentioned earlier.
236
+
237
+ 60
238
+ 00:03:55,000 --> 00:04:01,000
239
+ You can have the best encryption on on your servers, but if I can just walk into the organization and
240
+
241
+ 61
242
+ 00:04:01,000 --> 00:04:06,000
243
+ pick up a workstation, pick up the data and just walk back out, you don't really have good controls,
244
+
245
+ 62
246
+ 00:04:06,000 --> 00:04:06,000
247
+ do you?
248
+
249
+ 63
250
+ 00:04:07,000 --> 00:04:13,000
251
+ So physical controls are measures taken to protect the actual hardware and facilities that house the
252
+
253
+ 64
254
+ 00:04:13,000 --> 00:04:14,000
255
+ system.
256
+
257
+ 65
258
+ 00:04:14,000 --> 00:04:17,000
259
+ So these are controls we use to protect the actual physical hardware.
260
+
261
+ 66
262
+ 00:04:17,000 --> 00:04:23,000
263
+ Like somebody just can't walk in and pick up my firewall, really expensive device and walk back out
264
+
265
+ 67
266
+ 00:04:23,000 --> 00:04:24,000
267
+ with it.
268
+
269
+ 68
270
+ 00:04:24,000 --> 00:04:26,000
271
+ So that's going to include things like what.
272
+
273
+ 69
274
+ 00:04:26,000 --> 00:04:31,000
275
+ Well, that's going to include things like cameras, security guards, fences, signs, lighting and
276
+
277
+ 70
278
+ 00:04:31,000 --> 00:04:34,000
279
+ so on that we can use in the physical vicinity.
280
+
281
+ 71
282
+ 00:04:34,000 --> 00:04:38,000
283
+ Now, we do have a whole lesson on physical security coming up later.
284
+
285
+ 72
286
+ 00:04:39,000 --> 00:04:39,000
287
+ Okay.
288
+
289
+ 73
290
+ 00:04:39,000 --> 00:04:43,000
291
+ So keep in mind that we have four categories.
292
+
293
+ 74
294
+ 00:04:43,000 --> 00:04:45,000
295
+ Technical things you can figure.
296
+
297
+ 75
298
+ 00:04:46,000 --> 00:04:48,000
299
+ Are manager or administrative.
300
+
301
+ 76
302
+ 00:04:48,000 --> 00:04:48,000
303
+ Same thing.
304
+
305
+ 77
306
+ 00:04:48,000 --> 00:04:50,000
307
+ Those are going to be things on paper.
308
+
309
+ 78
310
+ 00:04:50,000 --> 00:04:56,000
311
+ Operational things you do on a day to day basis and then come physical things you can touch and feel
312
+
313
+ 79
314
+ 00:04:56,000 --> 00:04:59,000
315
+ to protect physical assets within the environment.
316
+
317
+ 80
318
+ 00:04:59,000 --> 00:05:02,000
319
+ Make sure you know what they are and what they're doing to protect you.
320
+
03 - Security Controls Categories and Types/002 Control Types OB 1.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:cc1f860e5998ef88bd6cfe5ce60130f243d176797aecbc16ec1201221e637d92
3
+ size 230762032
03 - Security Controls Categories and Types/002 Control Types OB 1.1_en.srt ADDED
@@ -0,0 +1,400 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:05,000
3
+ When protecting your network, you're going to be using a whole lot of controls and a lot of the controls
4
+
5
+ 2
6
+ 00:00:05,000 --> 00:00:08,000
7
+ that we have falls into multiple types.
8
+
9
+ 3
10
+ 00:00:08,000 --> 00:00:10,000
11
+ So let's see what these types are in this video.
12
+
13
+ 4
14
+ 00:00:10,000 --> 00:00:14,000
15
+ So the first thing that we're going to have is we're going to go through one of the most common types
16
+
17
+ 5
18
+ 00:00:14,000 --> 00:00:18,000
19
+ that most people think about is going to be preventative types or preventative controls.
20
+
21
+ 6
22
+ 00:00:18,000 --> 00:00:21,000
23
+ You see preventative controls will stop.
24
+
25
+ 7
26
+ 00:00:21,000 --> 00:00:24,000
27
+ An intrusion will stop a security incident from arising.
28
+
29
+ 8
30
+ 00:00:24,000 --> 00:00:27,000
31
+ So they'll stop all kinds of incidents.
32
+
33
+ 9
34
+ 00:00:27,000 --> 00:00:31,000
35
+ This is going to include things like firewalls, encryption, access control, and even physical things
36
+
37
+ 10
38
+ 00:00:31,000 --> 00:00:33,000
39
+ that could security guard or a fence.
40
+
41
+ 11
42
+ 00:00:33,000 --> 00:00:40,000
43
+ Now, before I get it more into this, I want to I want to keep remind you guys that a single control
44
+
45
+ 12
46
+ 00:00:40,000 --> 00:00:42,000
47
+ falls into multiple types.
48
+
49
+ 13
50
+ 00:00:42,000 --> 00:00:42,000
51
+ All right.
52
+
53
+ 14
54
+ 00:00:42,000 --> 00:00:48,000
55
+ Some controls may only be one type, but generally a lot of the controls that we use falls into multiple
56
+
57
+ 15
58
+ 00:00:48,000 --> 00:00:48,000
59
+ types.
60
+
61
+ 16
62
+ 00:00:48,000 --> 00:00:51,000
63
+ So I want you guys take a look at this firewall that I have here.
64
+
65
+ 17
66
+ 00:00:51,000 --> 00:00:52,000
67
+ So this is a sonicwall.
68
+
69
+ 18
70
+ 00:00:52,000 --> 00:01:00,000
71
+ And this particular firewall will stop all kinds of malicious traffic from entering my network.
72
+
73
+ 19
74
+ 00:01:00,000 --> 00:01:03,000
75
+ So let's say there's a malicious worm spreading around on the internet.
76
+
77
+ 20
78
+ 00:01:03,000 --> 00:01:07,000
79
+ Well this this one here has the internet port here.
80
+
81
+ 21
82
+ 00:01:07,000 --> 00:01:09,000
83
+ And it has a switch port on this end.
84
+
85
+ 22
86
+ 00:01:10,000 --> 00:01:10,000
87
+ All right.
88
+
89
+ 23
90
+ 00:01:10,000 --> 00:01:12,000
91
+ Actually, uh, the switchboard connected here.
92
+
93
+ 24
94
+ 00:01:12,000 --> 00:01:15,000
95
+ So internet comes in here.
96
+
97
+ 25
98
+ 00:01:15,000 --> 00:01:18,000
99
+ The firewall then assesses the traffic and says, hey, you're a worm.
100
+
101
+ 26
102
+ 00:01:18,000 --> 00:01:18,000
103
+ Boom.
104
+
105
+ 27
106
+ 00:01:18,000 --> 00:01:21,000
107
+ You're not coming in here and stops it from going out to Switchport.
108
+
109
+ 28
110
+ 00:01:21,000 --> 00:01:22,000
111
+ So what happens?
112
+
113
+ 29
114
+ 00:01:22,000 --> 00:01:24,000
115
+ This device stopped an intrusion.
116
+
117
+ 30
118
+ 00:01:24,000 --> 00:01:27,000
119
+ So this is a good preventative device.
120
+
121
+ 31
122
+ 00:01:27,000 --> 00:01:31,000
123
+ Another kind of control we're going to have is going to be called a detective control.
124
+
125
+ 32
126
+ 00:01:31,000 --> 00:01:35,000
127
+ Detective controls can detect intrusions as they're happening.
128
+
129
+ 33
130
+ 00:01:35,000 --> 00:01:39,000
131
+ This is going to be something like an intrusion detection system such as snort.
132
+
133
+ 34
134
+ 00:01:39,000 --> 00:01:46,000
135
+ So snort very popular software that you can download right now and try out snort will actually absorb
136
+
137
+ 35
138
+ 00:01:46,000 --> 00:01:51,000
139
+ all your network traffic and then analyze the traffic and says, hey, that computer over there, that
140
+
141
+ 36
142
+ 00:01:51,000 --> 00:01:52,000
143
+ computer has a worm.
144
+
145
+ 37
146
+ 00:01:52,000 --> 00:01:54,000
147
+ That one there is being hacked.
148
+
149
+ 38
150
+ 00:01:54,000 --> 00:01:59,000
151
+ So this is detecting intrusions also that can happen here in the world of physical is going to be things
152
+
153
+ 39
154
+ 00:01:59,000 --> 00:02:05,000
155
+ like a video surveillance camera watching people, security guards watching them can detect them committing
156
+
157
+ 40
158
+ 00:02:05,000 --> 00:02:06,000
159
+ a crime.
160
+
161
+ 41
162
+ 00:02:06,000 --> 00:02:07,000
163
+ Corrective control.
164
+
165
+ 42
166
+ 00:02:07,000 --> 00:02:12,000
167
+ Well, when there is a security incident and something has gone wrong in your network, you have to
168
+
169
+ 43
170
+ 00:02:12,000 --> 00:02:14,000
171
+ remember that we have to go and fix it.
172
+
173
+ 44
174
+ 00:02:14,000 --> 00:02:17,000
175
+ We just after it's done, we got to go fix it.
176
+
177
+ 45
178
+ 00:02:17,000 --> 00:02:19,000
179
+ Let's say a computer got infected with a virus.
180
+
181
+ 46
182
+ 00:02:19,000 --> 00:02:22,000
183
+ The virus deletes the data, corrupts the entire machine.
184
+
185
+ 47
186
+ 00:02:22,000 --> 00:02:25,000
187
+ Well, somebody needs to go in here and do this control.
188
+
189
+ 48
190
+ 00:02:25,000 --> 00:02:31,000
191
+ Somebody needs to restore those backups and reinstall windows on those particular machines.
192
+
193
+ 49
194
+ 00:02:32,000 --> 00:02:35,000
195
+ Another one we have is what's called a deterrent control.
196
+
197
+ 50
198
+ 00:02:35,000 --> 00:02:37,000
199
+ Deterrent control will scare people off.
200
+
201
+ 51
202
+ 00:02:37,000 --> 00:02:40,000
203
+ Deterrent control will discourage a threat.
204
+
205
+ 52
206
+ 00:02:40,000 --> 00:02:47,000
207
+ So, for example, a camera is a kind of a not only is this a detective as this can detect people coming
208
+
209
+ 53
210
+ 00:02:47,000 --> 00:02:49,000
211
+ to crime, but this can also scare people off.
212
+
213
+ 54
214
+ 00:02:49,000 --> 00:02:52,000
215
+ Now I want you to keep in mind the turn versus preventive.
216
+
217
+ 55
218
+ 00:02:52,000 --> 00:02:53,000
219
+ So watch this.
220
+
221
+ 56
222
+ 00:02:53,000 --> 00:02:54,000
223
+ Here's a camera.
224
+
225
+ 57
226
+ 00:02:54,000 --> 00:02:55,000
227
+ It's watching my desk.
228
+
229
+ 58
230
+ 00:02:55,000 --> 00:03:02,000
231
+ So if we position this camera here to watch this desk, and I'm a bad guy and I go to steal my tablet,
232
+
233
+ 59
234
+ 00:03:02,000 --> 00:03:05,000
235
+ let's say I want to steal my tablet and run off.
236
+
237
+ 60
238
+ 00:03:05,000 --> 00:03:07,000
239
+ Well, this camera doesn't do anything.
240
+
241
+ 61
242
+ 00:03:07,000 --> 00:03:08,000
243
+ It just sits here.
244
+
245
+ 62
246
+ 00:03:08,000 --> 00:03:11,000
247
+ Its hands don't come out the camera and stop me.
248
+
249
+ 63
250
+ 00:03:11,000 --> 00:03:18,000
251
+ This is only here to scare me and detect me, discourage me and detect me from stealing a particular
252
+
253
+ 64
254
+ 00:03:18,000 --> 00:03:19,000
255
+ thing or committing a crime.
256
+
257
+ 65
258
+ 00:03:19,000 --> 00:03:23,000
259
+ You see, this is detective.
260
+
261
+ 66
262
+ 00:03:23,000 --> 00:03:25,000
263
+ This is deterrent.
264
+
265
+ 67
266
+ 00:03:25,000 --> 00:03:27,000
267
+ But this is not preventative.
268
+
269
+ 68
270
+ 00:03:27,000 --> 00:03:29,000
271
+ This doesn't prevent a security guard, though.
272
+
273
+ 69
274
+ 00:03:29,000 --> 00:03:32,000
275
+ Can see they have surveillance.
276
+
277
+ 70
278
+ 00:03:32,000 --> 00:03:35,000
279
+ They can deter because they're standing there.
280
+
281
+ 71
282
+ 00:03:35,000 --> 00:03:36,000
283
+ Maybe they have a gun.
284
+
285
+ 72
286
+ 00:03:36,000 --> 00:03:38,000
287
+ And of course there are.
288
+
289
+ 73
290
+ 00:03:38,000 --> 00:03:42,000
291
+ They're going to detect, prevent and deter me.
292
+
293
+ 74
294
+ 00:03:42,000 --> 00:03:42,000
295
+ All right.
296
+
297
+ 75
298
+ 00:03:42,000 --> 00:03:43,000
299
+ So they can do a lot.
300
+
301
+ 76
302
+ 00:03:43,000 --> 00:03:46,000
303
+ Like I said, one control can fall into multiple.
304
+
305
+ 77
306
+ 00:03:46,000 --> 00:03:49,000
307
+ Another one we have is the directive control.
308
+
309
+ 78
310
+ 00:03:49,000 --> 00:03:52,000
311
+ So a directive control is when we're going to.
312
+
313
+ 79
314
+ 00:03:53,000 --> 00:04:01,000
315
+ Have, uh, all kinds of instructions on how to use a system to prevent a response to security incidents,
316
+
317
+ 80
318
+ 00:04:01,000 --> 00:04:07,000
319
+ and particularly having different kind of policies would tell people how to use our systems, compensate
320
+
321
+ 81
322
+ 00:04:07,000 --> 00:04:09,000
323
+ and control compensating controllers.
324
+
325
+ 82
326
+ 00:04:09,000 --> 00:04:14,000
327
+ When you don't have the best control available, you go well with the second best.
328
+
329
+ 83
330
+ 00:04:14,000 --> 00:04:18,000
331
+ You can say, well, he's compensating because he can't do that particular task.
332
+
333
+ 84
334
+ 00:04:18,000 --> 00:04:19,000
335
+ So.
336
+
337
+ 85
338
+ 00:04:19,000 --> 00:04:26,000
339
+ For example, let's say the best control out there is going to be the highest end firewall, next generation
340
+
341
+ 86
342
+ 00:04:26,000 --> 00:04:27,000
343
+ firewall.
344
+
345
+ 87
346
+ 00:04:27,000 --> 00:04:27,000
347
+ You don't have that one.
348
+
349
+ 88
350
+ 00:04:27,000 --> 00:04:31,000
351
+ You don't have the resources or budget for it, so you get the next best one.
352
+
353
+ 89
354
+ 00:04:31,000 --> 00:04:35,000
355
+ Remember, this one is when you don't have the primary control, you go with the second best one.
356
+
357
+ 90
358
+ 00:04:35,000 --> 00:04:38,000
359
+ That's going to be a compensating control.
360
+
361
+ 91
362
+ 00:04:38,000 --> 00:04:38,000
363
+ Okay.
364
+
365
+ 92
366
+ 00:04:38,000 --> 00:04:44,000
367
+ So once again guys, I really want to point out that if you're sitting here saying, well, if you can
368
+
369
+ 93
370
+ 00:04:44,000 --> 00:04:48,000
371
+ think of a particular control that I haven't mentioned and you're saying, well, hey, that sounds
372
+
373
+ 94
374
+ 00:04:48,000 --> 00:04:52,000
375
+ like a complete compensator, that sounds like a detective, that sounds like a preventative.
376
+
377
+ 95
378
+ 00:04:52,000 --> 00:04:53,000
379
+ It probably is.
380
+
381
+ 96
382
+ 00:04:53,000 --> 00:04:58,000
383
+ Now on your exam, they may give you a particular scenario, and you're going to have to say, well,
384
+
385
+ 97
386
+ 00:04:58,000 --> 00:05:01,000
387
+ that's a detective, that's a deterrent.
388
+
389
+ 98
390
+ 00:05:01,000 --> 00:05:02,000
391
+ Or they may even give it to you.
392
+
393
+ 99
394
+ 00:05:02,000 --> 00:05:04,000
395
+ And you may have to say what category it falls in.
396
+
397
+ 100
398
+ 00:05:04,000 --> 00:05:06,000
399
+ Just make sure you know your types and categories for your test.
400
+
03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:f07f37584be67761f48e45ff75e8985c7917d39aa5d30329262f0a0ab5fae5d9
3
+ size 159103460
03 - Security Controls Categories and Types/003 Defense in Depth OB 1.1_en.srt ADDED
@@ -0,0 +1,236 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:06,000
3
+ A good security professional doesn't secure a network with a single control, or a single type or category
4
+
5
+ 2
6
+ 00:00:06,000 --> 00:00:07,000
7
+ of control.
8
+
9
+ 3
10
+ 00:00:07,000 --> 00:00:11,000
11
+ A security professional secures a network using a multi-layered approach.
12
+
13
+ 4
14
+ 00:00:11,000 --> 00:00:14,000
15
+ So that brings me to this section layered security.
16
+
17
+ 5
18
+ 00:00:14,000 --> 00:00:20,000
19
+ One of the more important concepts you'll ever learn in this entire video series is going to be this
20
+
21
+ 6
22
+ 00:00:20,000 --> 00:00:21,000
23
+ concept of defense in depth.
24
+
25
+ 7
26
+ 00:00:21,000 --> 00:00:29,000
27
+ Defense in depth is using multiple or layers of controls in order to secure a network.
28
+
29
+ 8
30
+ 00:00:29,000 --> 00:00:33,000
31
+ It's not just one layer, it's going to be multiple layers.
32
+
33
+ 9
34
+ 00:00:33,000 --> 00:00:37,000
35
+ And for that, I want to draw you guys a particular diagram.
36
+
37
+ 10
38
+ 00:00:37,000 --> 00:00:37,000
39
+ Where is that pen.
40
+
41
+ 11
42
+ 00:00:38,000 --> 00:00:38,000
43
+ Here we go.
44
+
45
+ 12
46
+ 00:00:39,000 --> 00:00:41,000
47
+ So I want to show you guys something.
48
+
49
+ 13
50
+ 00:00:41,000 --> 00:00:43,000
51
+ Let's say you have a network.
52
+
53
+ 14
54
+ 00:00:43,000 --> 00:00:45,000
55
+ And in the network there's data.
56
+
57
+ 15
58
+ 00:00:45,000 --> 00:00:45,000
59
+ All right.
60
+
61
+ 16
62
+ 00:00:45,000 --> 00:00:48,000
63
+ So data is what you're trying to protect.
64
+
65
+ 17
66
+ 00:00:48,000 --> 00:00:51,000
67
+ Well you're going to secure that data with a firewall.
68
+
69
+ 18
70
+ 00:00:51,000 --> 00:00:52,000
71
+ Well that's just one layer.
72
+
73
+ 19
74
+ 00:00:52,000 --> 00:00:58,000
75
+ Then around that you're going to use procedures or policies to tell people, hey, don't share this
76
+
77
+ 20
78
+ 00:00:58,000 --> 00:00:58,000
79
+ data.
80
+
81
+ 21
82
+ 00:00:58,000 --> 00:01:00,000
83
+ Don't give away this data.
84
+
85
+ 22
86
+ 00:01:00,000 --> 00:01:06,000
87
+ And then around this also, you're going to be using physical things like a security guard or a fence.
88
+
89
+ 23
90
+ 00:01:07,000 --> 00:01:09,000
91
+ You can see why I don't write too much.
92
+
93
+ 24
94
+ 00:01:09,000 --> 00:01:10,000
95
+ Not the best handwriting there.
96
+
97
+ 25
98
+ 00:01:10,000 --> 00:01:16,000
99
+ Okay, so you notice that when we're secure in our data, we're not just securing the data with just
100
+
101
+ 26
102
+ 00:01:16,000 --> 00:01:18,000
103
+ one control.
104
+
105
+ 27
106
+ 00:01:18,000 --> 00:01:23,000
107
+ You're using multiple controls across multiple categories.
108
+
109
+ 28
110
+ 00:01:23,000 --> 00:01:28,000
111
+ For example, you're just not going to use a firewall, but you're going to use firewall and encryption.
112
+
113
+ 29
114
+ 00:01:28,000 --> 00:01:31,000
115
+ That's two technical controls.
116
+
117
+ 30
118
+ 00:01:31,000 --> 00:01:36,000
119
+ You're going to use a policy and a procedure to administrative control.
120
+
121
+ 31
122
+ 00:01:36,000 --> 00:01:39,000
123
+ You're going to use physical media protection.
124
+
125
+ 32
126
+ 00:01:39,000 --> 00:01:44,000
127
+ You're going to use a variety, a whole variety and different kinds of physical controls out there.
128
+
129
+ 33
130
+ 00:01:44,000 --> 00:01:49,000
131
+ So when you think of securing a network, you know, I gave this example, I know I'm sound like a broken
132
+
133
+ 34
134
+ 00:01:49,000 --> 00:01:54,000
135
+ record, but if I can walk into the network and pick up your data and walk back out, you really don't
136
+
137
+ 35
138
+ 00:01:54,000 --> 00:01:56,000
139
+ have much security, right?
140
+
141
+ 36
142
+ 00:01:56,000 --> 00:02:01,000
143
+ I don't care what it is because a hacker, bad people, they're just not going to try to break into
144
+
145
+ 37
146
+ 00:02:01,000 --> 00:02:03,000
147
+ your organization one way.
148
+
149
+ 38
150
+ 00:02:03,000 --> 00:02:05,000
151
+ They're going to use multiple ways.
152
+
153
+ 39
154
+ 00:02:05,000 --> 00:02:10,000
155
+ For example, if I can't break through your firewall because this device is updated.
156
+
157
+ 40
158
+ 00:02:12,000 --> 00:02:15,000
159
+ I'll just try to call a user and ask them for the data.
160
+
161
+ 41
162
+ 00:02:15,000 --> 00:02:18,000
163
+ They already have access to the data, they can email it to me.
164
+
165
+ 42
166
+ 00:02:18,000 --> 00:02:23,000
167
+ I defeated all your security users, or people that are known as some of the weakest link in security.
168
+
169
+ 43
170
+ 00:02:23,000 --> 00:02:24,000
171
+ That's what we have to train them.
172
+
173
+ 44
174
+ 00:02:24,000 --> 00:02:30,000
175
+ Well, if that doesn't, if I can't get to a user, uh, nobody's giving me the data.
176
+
177
+ 45
178
+ 00:02:30,000 --> 00:02:32,000
179
+ I can't get through your firewall.
180
+
181
+ 46
182
+ 00:02:33,000 --> 00:02:37,000
183
+ I'll just wait till the night everybody goes home or break into your office and steal all your data.
184
+
185
+ 47
186
+ 00:02:37,000 --> 00:02:41,000
187
+ That way I'll take up the whole server, just walk back out, you see why you need this multi-layered
188
+
189
+ 48
190
+ 00:02:41,000 --> 00:02:42,000
191
+ approach.
192
+
193
+ 49
194
+ 00:02:42,000 --> 00:02:44,000
195
+ So this is known as defense in depth.
196
+
197
+ 50
198
+ 00:02:45,000 --> 00:02:53,000
199
+ And you want to make sure that all entry points is mitigated or assessed, and make sure that you have
200
+
201
+ 51
202
+ 00:02:53,000 --> 00:02:56,000
203
+ the right control to protect your right data.
204
+
205
+ 52
206
+ 00:02:57,000 --> 00:03:01,000
207
+ And I want to mention that when it comes to IT security, don't be single minded.
208
+
209
+ 53
210
+ 00:03:01,000 --> 00:03:05,000
211
+ Don't be narrow focused way too often in IT security.
212
+
213
+ 54
214
+ 00:03:05,000 --> 00:03:10,000
215
+ Are we focused only on one thing which is logical controls, technical controls.
216
+
217
+ 55
218
+ 00:03:10,000 --> 00:03:10,000
219
+ Right.
220
+
221
+ 56
222
+ 00:03:10,000 --> 00:03:11,000
223
+ Configuring this firewall.
224
+
225
+ 57
226
+ 00:03:11,000 --> 00:03:17,000
227
+ Don't forget guys, it's where we don't see that they see in order to steal our information.
228
+
229
+ 58
230
+ 00:03:17,000 --> 00:03:22,000
231
+ That's why in this course we're going to learn a variety of different ways to protect our network and
232
+
233
+ 59
234
+ 00:03:22,000 --> 00:03:23,000
235
+ keep our data secure.
236
+
03 - Security Controls Categories and Types/004 Quick Quiz.html ADDED
@@ -0,0 +1,479 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ <!DOCTYPE html>
2
+ <html lang="en">
3
+ <head>
4
+ <meta charset="UTF-8" />
5
+ <meta http-equiv="X-UA-Compatible" content="IE=edge" />
6
+ <meta name="viewport" content="width=device-width, initial-scale=1.0" />
7
+ <title>Quiz</title>
8
+ <style>
9
+ * {
10
+ font-family: system-ui, -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, Cantarell,
11
+ "Open Sans", "Helvetica Neue", sans-serif;
12
+ margin: 0;
13
+ padding: 0;
14
+ box-sizing: border-box;
15
+ font-size: 16px;
16
+ }
17
+
18
+ main {
19
+ padding-top: 48px;
20
+ }
21
+
22
+ :root {
23
+ --large-device-width: 850px;
24
+ --primary-color: #0f172a;
25
+ --secondary-color: #020617;
26
+ --primary-text-color: #c7d1dd;
27
+ --secondary-text-color: #061602;
28
+ --success-background: hsl(159, 82%, 24%);
29
+ --success-foreground: hsl(164, 86%, 16%);
30
+ --success: hsl(160, 84%, 39%);
31
+ --danger: #ef4444;
32
+ --warning: #f59e0b;
33
+ --info-background: hsl(218, 81%, 8%);
34
+ --info-foreground: hsl(217, 91%, 85%);
35
+ --border-color: #d1d7dc;
36
+ --check-box-size: 20px;
37
+ /* control the size */
38
+ --check-box-color: var(--info-foreground);
39
+ /* the active color */
40
+ }
41
+
42
+ body {
43
+ position: relative;
44
+ background-color: #020617;
45
+ color: var(--primary-text-color);
46
+ }
47
+
48
+ #score-stats-container {
49
+ position: fixed;
50
+ z-index: 10;
51
+ top: 0;
52
+ height: 40px;
53
+ width: 100%;
54
+ background-color: var(--info-background);
55
+
56
+ padding: 0px 16px;
57
+ color: var(--info-foreground);
58
+ font-weight: 600;
59
+ display: flex;
60
+ align-items: center;
61
+ justify-content: space-between;
62
+ }
63
+
64
+ #quiz-container {
65
+ border-radius: 8px;
66
+ display: flex;
67
+ gap: 16px;
68
+ flex-direction: column;
69
+ }
70
+
71
+ input[type="radio"] {
72
+ height: var(--check-box-size);
73
+ aspect-ratio: 1;
74
+ border: calc(var(--check-box-size) / 8) solid #939393;
75
+ padding: calc(var(--check-box-size) / 8);
76
+ background: radial-gradient(farthest-side, var(--check-box-color) 94%, #0000) 50%/0 0 no-repeat
77
+ content-box;
78
+ border-radius: 50%;
79
+ outline-offset: calc(var(--check-box-size) / 10);
80
+ -webkit-appearance: none;
81
+ -moz-appearance: none;
82
+ appearance: none;
83
+ cursor: pointer;
84
+ font-size: inherit;
85
+ transition: 0.3s;
86
+ }
87
+
88
+ input[type="radio"]:checked {
89
+ border-color: var(--check-box-color);
90
+ background-size: 100% 100%;
91
+ }
92
+
93
+ input[type="radio"]:disabled {
94
+ background: linear-gradient(#939393 0 0) 50%/100% 20% no-repeat content-box;
95
+ opacity: 0.5;
96
+ cursor: not-allowed;
97
+ }
98
+
99
+ label {
100
+ display: inline-flex;
101
+ align-items: center;
102
+ gap: 10px;
103
+ cursor: pointer;
104
+ padding: 4px 6px;
105
+ border-radius: 4px;
106
+ }
107
+
108
+ @media (max-width: 767px) {
109
+ input[type="radio"],
110
+ label {
111
+ cursor: default;
112
+ }
113
+
114
+ #quiz-container {
115
+ margin-left: 8px;
116
+ margin-right: 8px;
117
+ }
118
+ }
119
+
120
+ /* PC (Desktop devices) */
121
+ @media (min-width: 768px) {
122
+ body {
123
+ display: flex;
124
+ justify-content: center;
125
+ }
126
+
127
+ main {
128
+ max-width: var(--large-device-width);
129
+ }
130
+
131
+ #score-stats-container {
132
+ max-width: var(--large-device-width);
133
+ }
134
+
135
+ dialog {
136
+ max-width: var(--large-device-width);
137
+ }
138
+ }
139
+
140
+ @media print {
141
+ input[type="radio"] {
142
+ background: none !important;
143
+ border-color: #939393 !important;
144
+ }
145
+
146
+ input[type="radio"]:checked {
147
+ border-color: #939393 !important;
148
+ }
149
+ }
150
+
151
+ .question-lable {
152
+ display: flex;
153
+ align-items: center;
154
+ gap: 8px;
155
+ }
156
+
157
+ button {
158
+ -webkit-tap-highlight-color: transparent;
159
+ -webkit-touch-callout: none;
160
+ -webkit-user-select: none;
161
+ user-select: none;
162
+ outline: none;
163
+ position: relative;
164
+ overflow: hidden;
165
+ cursor: pointer;
166
+ }
167
+
168
+ .button {
169
+ background-color: var(--success-background);
170
+ border: none;
171
+ color: #f4f5f7;
172
+ opacity: 0.8;
173
+ font-size: 18px;
174
+ flex-grow: 1;
175
+ padding: 8px 16px;
176
+ border-radius: 8px;
177
+ }
178
+
179
+ .button:hover {
180
+ opacity: 1;
181
+ }
182
+
183
+ .explanation-btn {
184
+ border: none;
185
+ color: var(--success);
186
+ background-color: transparent;
187
+ }
188
+
189
+ #submit-button:active::after {
190
+ background-color: #ef4444;
191
+ }
192
+
193
+ .single-question-container {
194
+ background-color: var(--primary-color);
195
+ display: flex;
196
+ flex-direction: column;
197
+ gap: 8px;
198
+ padding: 16px;
199
+ border-radius: 8px;
200
+ }
201
+
202
+ #modal-content {
203
+ padding: 16px;
204
+ line-height: 24px;
205
+ }
206
+
207
+ dialog::backdrop {
208
+ background: rgba(0, 0, 0, 0.5);
209
+ }
210
+
211
+ dialog {
212
+ position: fixed;
213
+ border: 1px solid var(--border-color);
214
+ background-color: var(--primary-color);
215
+ color: rgb(240, 241, 248);
216
+ padding: 16px;
217
+ border-radius: 8px;
218
+ width: 80vw;
219
+ max-height: 80vh;
220
+ overflow: auto;
221
+ top: 50%;
222
+ left: 50%;
223
+ -webkit-transform: translateX(-50%) translateY(-50%);
224
+ -moz-transform: translateX(-50%) translateY(-50%);
225
+ -ms-transform: translateX(-50%) translateY(-50%);
226
+ transform: translateX(-50%) translateY(-50%);
227
+ }
228
+
229
+ #close-modal-btn {
230
+ position: absolute;
231
+ top: 4px;
232
+ right: 4px;
233
+ padding: 2px 8px;
234
+ border-radius: 2px;
235
+ border: none;
236
+ background-color: var(--danger);
237
+ }
238
+
239
+ .correct-answer label {
240
+ border: 2px solid var(--success);
241
+ width: 100%;
242
+ }
243
+
244
+ .incorrect-answer label {
245
+ border: 2px solid var(--danger);
246
+ width: 100%;
247
+ }
248
+
249
+ .options-container {
250
+ display: flex;
251
+ flex-direction: column;
252
+ gap: 4px;
253
+ }
254
+
255
+ #quiz-meta-container {
256
+ border-radius: 8px;
257
+ background-color: var(--primary-color);
258
+ margin-bottom: 12px;
259
+ padding: 8px;
260
+ }
261
+
262
+ #quiz-title {
263
+ text-align: center;
264
+ font-size: 24px;
265
+ margin-bottom: 8px;
266
+ }
267
+
268
+ #quiz-description {
269
+ line-height: 1.5;
270
+ padding: 2px 6px;
271
+ }
272
+ </style>
273
+ </head>
274
+
275
+ <body onload="main()">
276
+ <main>
277
+ <section id="quiz-meta-container">
278
+ <h1 id="quiz-title"></h1>
279
+ <p id="quiz-description"></p>
280
+ </section>
281
+ <section id="score-stats-container">
282
+ <div id="score-card">
283
+ Score: <span id="current-score">999</span> of
284
+ <span id="pass-percent">999%</span>
285
+ </div>
286
+ <div>Correct: <span id="correct-answers">999</span></div>
287
+ <div>Incorrect: <span id="wrong-answers">999</span></div>
288
+ </section>
289
+
290
+ <section id="quiz-container"></section>
291
+
292
+ <dialog id="modal" class="modal-container">
293
+ <div id="modal-content">
294
+ <p id="modal-text"></p>
295
+ </div>
296
+ </dialog>
297
+ </main>
298
+
299
+ <script>
300
+ const quizData = {"quiz_id": 6180064, "quiz_description": null, "quiz_title": "Quick Quiz", "pass_percent": null, "questions": [{"_class": "assessment", "id": 74726560, "assessment_type": "multiple-choice", "prompt": {"question": "<p>A security manager regularly reviews access logs to identify any unauthorized attempts to access the system. This activity is classified under which type of control?</p>", "relatedLectureIds": "", "feedbacks": ["", "Reviewing access logs falls under detective controls as it involves identifying and reporting unauthorized activities post-occurrence. Preventive controls would stop unauthorized access before it happens, compensating controls are backup strategies, and operational controls relate to daily operational security measures.", "", ""], "answers": ["<p>Preventive</p>", "<p>Detective</p>", "<p>Compensating</p>", "<p>Operational</p>"]}, "correct_response": ["b"], "section": "", "question_plain": "A security manager regularly reviews access logs to identify any unauthorized attempts to access the system. This activity is classified under which type of control?", "related_lectures": []}, {"_class": "assessment", "id": 74726566, "assessment_type": "multiple-choice", "prompt": {"question": "<p>In an organization, the policy requires employees to wear visible ID badges. This policy is an example of which type of security control?</p>", "relatedLectureIds": "", "feedbacks": ["Requiring ID badges is a directive control as it involves a policy directing specific behavior. Physical controls involve tangible measures to protect assets, technical controls are implemented via technology, and deterrent controls aim to discourage security violations.", "", ""], "answers": ["<p>Directive</p>", "<p>Physical</p>", "<p>Technical</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "In an organization, the policy requires employees to wear visible ID badges. This policy is an example of which type of security control?", "related_lectures": []}, {"_class": "assessment", "id": 74726570, "assessment_type": "multiple-choice", "prompt": {"question": "<p>he use of CCTV cameras in a facility primarily serves as what type of security control?</p>", "relatedLectureIds": "", "feedbacks": ["CCTV cameras act as a deterrent control by discouraging unauthorized actions due to the fear of being watched and recorded. Detective controls identify issues after they occur, preventive controls stop security incidents before they happen, and corrective controls rectify security breaches.", "", "", ""], "answers": ["<p>Deterrent</p>", "<p>Detective</p>", "<p>Preventive</p>", "<p>Corrective</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "he use of CCTV cameras in a facility primarily serves as what type of security control?", "related_lectures": []}, {"_class": "assessment", "id": 74726574, "assessment_type": "multiple-choice", "prompt": {"question": "<p>An organization conducts regular training for employees on security policies and procedures. This is an example of which category of security controls?</p>", "relatedLectureIds": "", "feedbacks": ["", "", "Operational controls includes security awareness training. ", ""], "answers": ["<p>Managerial</p>", "<p>Technical</p>", "<p>Operational</p>", "<p>Physical</p>"]}, "correct_response": ["c"], "section": "", "question_plain": "An organization conducts regular training for employees on security policies and procedures. This is an example of which category of security controls?", "related_lectures": []}, {"_class": "assessment", "id": 74726584, "assessment_type": "multiple-choice", "prompt": {"question": "<p>Encrypting data stored on a company server is considered which type of security control?</p>", "relatedLectureIds": "", "feedbacks": ["Encrypting data is a technical control, as it uses technology to protect information. Managerial controls involve strategic guidance, operational controls are daily security tasks, and physical controls are tangible measures for protection.", "", "", ""], "answers": ["<p>Technical</p>", "<p>Managerial</p>", "<p>Operational</p>", "<p>Physical</p>"]}, "correct_response": ["a"], "section": "", "question_plain": "Encrypting data stored on a company server is considered which type of security control?", "related_lectures": []}]};
301
+ let correct = new Set();
302
+ let incorrect = new Set();
303
+ let totalNumberOfQuestions = 0;
304
+ const quizTitle = quizData.quiz_title;
305
+ const quizDescription = quizData.quiz_description;
306
+ const questionData = quizData.questions;
307
+ const passPercent = quizData.pass_percent;
308
+ const modalTextElement = document.getElementById("modal-text");
309
+ const quizContainerElement = document.getElementById("quiz-container");
310
+
311
+ const dialog = document.querySelector("dialog");
312
+ const showButton = document.getElementById("view-explanatin");
313
+ const closeButton = document.getElementById("close-modal-btn");
314
+ const quizTitleElement = document.getElementById("quiz-title");
315
+ const quizDescriptionElement = document.getElementById("quiz-description");
316
+
317
+ function main() {
318
+ // update quiz meta data
319
+ document.title = quizTitle;
320
+ quizTitleElement.innerHTML = quizTitle;
321
+ quizDescriptionElement.innerHTML = quizDescription;
322
+
323
+ const passPercentElement = document.getElementById("pass-percent");
324
+ passPercentElement.innerHTML = passPercent + "%";
325
+ totalNumberOfQuestions = questionData.length;
326
+ // shuffle the questionData to randomize the order of the questions
327
+ for (let i = questionData.length - 1; i > 0; i--) {
328
+ const j = Math.floor(Math.random() * (i + 1));
329
+ [questionData[i], questionData[j]] = [questionData[j], questionData[i]];
330
+ }
331
+
332
+ let formattedQuestions = questionData.map(formatSingleQuestionData);
333
+ updateScore();
334
+ // display the formattedQuestions
335
+ formattedQuestions.forEach((question, idx) => {
336
+ renderSingleQuestion(question, idx + 1);
337
+ });
338
+ }
339
+
340
+ /**
341
+ * Formats the question data from the given QuizData object.
342
+ *
343
+ * @param {Object} singleQuizData - The singleQuizData object containing prompt and correct_response.
344
+ * @return {Object} The formatted question object with the following properties:
345
+ * - id: The ID of the question.
346
+ * - question: The text of the question.
347
+ * - answers: The array of answer options.
348
+ * - correctAnswer: The text of the correct answer.
349
+ * - explanation: The explanation of the correct answer.
350
+ */
351
+ function formatSingleQuestionData(singleQuizData = null) {
352
+ const { prompt, correct_response, id } = singleQuizData;
353
+ const questionText = prompt.question;
354
+ const answers = prompt.answers;
355
+ const correctAnswer = correct_response[0];
356
+ const correctAnswerText = answers[correctAnswer.toLowerCase().charCodeAt(0) - 97];
357
+ const questionObj = {
358
+ id: id,
359
+ question: questionText,
360
+ answers: answers,
361
+ correctAnswer: correctAnswerText,
362
+ explanation: prompt?.explanation || "",
363
+ };
364
+ return questionObj;
365
+ }
366
+
367
+ /**
368
+ * Renders a single question with its options and submit button.
369
+ *
370
+ * @param {Object} singleQuestionData - The data of the question to render.
371
+ * @param {number} rootIndex - The index of the question in the quiz.
372
+ * @return {void} return nothing.
373
+ */
374
+
375
+ const renderSingleQuestion = (singleQuestionData = {}, rootIndex = 1) => {
376
+ const { id, explanation, answers, correctAnswer, question } = singleQuestionData;
377
+ // shuffle the answers to randomize the order of the answers
378
+ for (let i = answers.length - 1; i > 0; i--) {
379
+ const j = Math.floor(Math.random() * (i + 1));
380
+ [answers[i], answers[j]] = [answers[j], answers[i]];
381
+ }
382
+ const optionsHTML = answers
383
+ .map((option, index) => {
384
+ const optionId = `${id}_${index}`;
385
+
386
+ return `
387
+ <div class="question-lable">
388
+ <input type="radio" id="${optionId}" name="${"answer"}" value="${option}" />
389
+ <label for="${optionId}">${option}</label>
390
+ </div>
391
+ `;
392
+ })
393
+
394
+ .join("");
395
+
396
+ const container = document.createElement("div");
397
+ container.innerHTML = `
398
+ <form data-correct-answer="${correctAnswer}" data-question-id="${id}" class="single-question-container" onsubmit="submitButtonListener(event)">
399
+ <div style="display: flex;justify-content: space-between;">
400
+ <p style="font-weight: 600">Question ${rootIndex}:</p>
401
+ <button type="button" onclick="renderExplanation(event)" id="${`explanation-${id}`}" data-explanation="${explanation}" class="explanation-btn">View Explanation</button>
402
+ </div>
403
+ <p style="margin-bottom: 8px;line-height: 1.5">${question}</p>
404
+ <div class="options-container">
405
+ ${optionsHTML}
406
+ </div>
407
+ <div style="display: flex; gap: 8px;">
408
+ <button type="submit" id="submit-button" class="button">Submit</button>
409
+ </div>
410
+ </form>
411
+ `;
412
+ quizContainerElement.appendChild(container);
413
+ };
414
+
415
+ /**
416
+ * Updates the score on the page based on the number of correct and incorrect answers.
417
+ *
418
+ * @return {void} This function does not return a value.
419
+ */
420
+ function updateScore() {
421
+ const currentParcentageElement = document.getElementById("current-score");
422
+ const correctAnswerElement = document.getElementById("correct-answers");
423
+ const wrongAnswerElement = document.getElementById("wrong-answers");
424
+ correctAnswerElement.innerHTML = correct.size;
425
+ wrongAnswerElement.innerHTML = incorrect.size;
426
+ const score = Number((correct.size / totalNumberOfQuestions) * 100).toFixed(2);
427
+ currentParcentageElement.innerHTML = score;
428
+ }
429
+
430
+ /**
431
+ * Handles the event when the submit button is clicked.
432
+ *
433
+ * @param {Event} e - The event object.
434
+ * @return {void} This function does not return anything.
435
+ */
436
+ const submitButtonListener = (e) => {
437
+ e.preventDefault();
438
+ const formData = new FormData(e.target);
439
+ const form = e.target;
440
+ const selectedOption = e.target.querySelector('input[type="radio"]:checked');
441
+ if (!selectedOption) {
442
+ alert("Please select an answer!");
443
+ return;
444
+ }
445
+
446
+ let isCorrect = false;
447
+ const { answer: userAnswer } = Object.fromEntries(formData.entries());
448
+ const correctAnswer = e.target.dataset.correctAnswer;
449
+ const questionId = e.target.dataset.questionId;
450
+ if (userAnswer == correctAnswer) {
451
+ correct.add(questionId);
452
+ incorrect.delete(questionId);
453
+ isCorrect = true;
454
+ } else {
455
+ incorrect.add(e.target.dataset.questionId);
456
+ correct.delete(questionId);
457
+ }
458
+ updateScore();
459
+
460
+ const resultClass = isCorrect ? "correct-answer" : "incorrect-answer";
461
+
462
+ form.querySelectorAll(".question-lable").forEach((label) => {
463
+ label.classList.remove("correct-answer", "incorrect-answer");
464
+ });
465
+ selectedOption.closest(".question-lable").classList.add(resultClass);
466
+ };
467
+
468
+ function renderExplanation(ev) {
469
+ modalTextElement.innerHTML = ev.target.dataset?.explanation || "no explanation found";
470
+ dialog.showModal();
471
+ dialog.addEventListener("click", (event) => {
472
+ if (event.target === dialog) {
473
+ dialog.close();
474
+ }
475
+ });
476
+ }
477
+ </script>
478
+ </body>
479
+ </html>
04 - Threats/001 Threats Motivation OB 2.1.mp4 ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:9356fb1da896565f0c255d84da13296f4335204cfa11175e0889fcb7f67e1b72
3
+ size 261867505
04 - Threats/001 Threats Motivation OB 2.1_en.srt ADDED
@@ -0,0 +1,384 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ 1
2
+ 00:00:00,000 --> 00:00:04,000
3
+ One of the questions you really have to ask yourself is, why are they coming after me?
4
+
5
+ 2
6
+ 00:00:04,000 --> 00:00:06,000
7
+ Why are they breaking into my network?
8
+
9
+ 3
10
+ 00:00:06,000 --> 00:00:07,000
11
+ My network is small.
12
+
13
+ 4
14
+ 00:00:07,000 --> 00:00:09,000
15
+ Do I have something that they want?
16
+
17
+ 5
18
+ 00:00:09,000 --> 00:00:15,000
19
+ Many organizations, sometimes even nonprofit organizations, are hit with particular attacks.
20
+
21
+ 6
22
+ 00:00:15,000 --> 00:00:17,000
23
+ And they left themselves asking, well, why are they coming after us?
24
+
25
+ 7
26
+ 00:00:17,000 --> 00:00:19,000
27
+ We don't have much data.
28
+
29
+ 8
30
+ 00:00:19,000 --> 00:00:22,000
31
+ We don't have much money, if any money at all.
32
+
33
+ 9
34
+ 00:00:22,000 --> 00:00:23,000
35
+ Why are we being attacked?
36
+
37
+ 10
38
+ 00:00:23,000 --> 00:00:26,000
39
+ Maybe because they're being attacked for a political gain.
40
+
41
+ 11
42
+ 00:00:26,000 --> 00:00:30,000
43
+ Maybe people just don't like what that nonprofit is doing or what they support.
44
+
45
+ 12
46
+ 00:00:31,000 --> 00:00:38,000
47
+ You see, when you most you see when most people think of a motivation for these particular threats,
48
+
49
+ 13
50
+ 00:00:38,000 --> 00:00:40,000
51
+ they're thinking generally of.
52
+
53
+ 14
54
+ 00:00:40,000 --> 00:00:45,000
55
+ The last thing that I have on my list here in this slide is ten of them, basically is just for financial
56
+
57
+ 15
58
+ 00:00:45,000 --> 00:00:46,000
59
+ gains.
60
+
61
+ 16
62
+ 00:00:46,000 --> 00:00:49,000
63
+ But there's a lot more than just financial gains.
64
+
65
+ 17
66
+ 00:00:49,000 --> 00:00:56,000
67
+ So one of the most common things that people do, one of the most common motivations for attacks against
68
+
69
+ 18
70
+ 00:00:56,000 --> 00:01:02,000
71
+ your company, is basically stealing data from the target, taking taking the data right out of the
72
+
73
+ 19
74
+ 00:01:02,000 --> 00:01:07,000
75
+ organization, maybe by using some kind of ransomware or backdoor attacks.
76
+
77
+ 20
78
+ 00:01:07,000 --> 00:01:11,000
79
+ Another one is going to be espionage, just spying on what you're doing.
80
+
81
+ 21
82
+ 00:01:11,000 --> 00:01:13,000
83
+ They're not manipulating or changing the information.
84
+
85
+ 22
86
+ 00:01:13,000 --> 00:01:16,000
87
+ They're just basically spying on your information.
88
+
89
+ 23
90
+ 00:01:16,000 --> 00:01:21,000
91
+ This is famous for when a nation states do this to each other.
92
+
93
+ 24
94
+ 00:01:21,000 --> 00:01:26,000
95
+ So, for example, North Korea may try to break into the United States government to see what kind of
96
+
97
+ 25
98
+ 00:01:26,000 --> 00:01:28,000
99
+ weapons we are developing, and vice versa.
100
+
101
+ 26
102
+ 00:01:28,000 --> 00:01:31,000
103
+ Other governments will do it to other governments also.
104
+
105
+ 27
106
+ 00:01:31,000 --> 00:01:33,000
107
+ You're also going to have service disruptions.
108
+
109
+ 28
110
+ 00:01:33,000 --> 00:01:38,000
111
+ So for example, DDoS distributed denial of service attacks.
112
+
113
+ 29
114
+ 00:01:38,000 --> 00:01:40,000
115
+ These are going to be attacks that you can.
116
+
117
+ 30
118
+ 00:01:41,000 --> 00:01:49,000
119
+ Spin up all kinds of bots on the internet, and then load up these bots on a particular web server.
120
+
121
+ 31
122
+ 00:01:49,000 --> 00:01:54,000
123
+ In other words, generates so much traffic to a particular web server that the web server goes offline.
124
+
125
+ 32
126
+ 00:01:54,000 --> 00:01:59,000
127
+ This disrupts the service of that website to other particular users.
128
+
129
+ 33
130
+ 00:01:59,000 --> 00:02:03,000
131
+ Hacktivists may do this in order to promote a political agenda.
132
+
133
+ 34
134
+ 00:02:03,000 --> 00:02:11,000
135
+ For example, if hacktivists believes that what this organization is doing is injust to their beliefs,
136
+
137
+ 35
138
+ 00:02:11,000 --> 00:02:15,000
139
+ they may just shut that entire website off by sending it a whole bunch of traffic.
140
+
141
+ 36
142
+ 00:02:15,000 --> 00:02:21,000
143
+ Not unheard of as famous hacker group anonymous has done this quite a lot to different government agencies.
144
+
145
+ 37
146
+ 00:02:21,000 --> 00:02:22,000
147
+ Blackmail.
148
+
149
+ 38
150
+ 00:02:23,000 --> 00:02:25,000
151
+ This is common with ransomware.
152
+
153
+ 39
154
+ 00:02:25,000 --> 00:02:29,000
155
+ So what they do here is that they will steal your data.
156
+
157
+ 40
158
+ 00:02:29,000 --> 00:02:32,000
159
+ They're going to hold on to it unless you pay that demand.
160
+
161
+ 41
162
+ 00:02:33,000 --> 00:02:38,000
163
+ 200,000 300,000 for small people may be a couple hundred bucks, couple thousand dollars.
164
+
165
+ 42
166
+ 00:02:38,000 --> 00:02:42,000
167
+ Unless you pay that demand, they're going to release your data to the public.
168
+
169
+ 43
170
+ 00:02:42,000 --> 00:02:45,000
171
+ So they're holding you ransom.
172
+
173
+ 44
174
+ 00:02:45,000 --> 00:02:46,000
175
+ They're holding you blackmail.
176
+
177
+ 45
178
+ 00:02:46,000 --> 00:02:48,000
179
+ So this is a form of blackmail.
180
+
181
+ 46
182
+ 00:02:49,000 --> 00:02:50,000
183
+ Okay.
184
+
185
+ 47
186
+ 00:02:50,000 --> 00:02:52,000
187
+ The others I have here is some kind of political belief.
188
+
189
+ 48
190
+ 00:02:54,000 --> 00:02:58,000
191
+ Especially hacktivists, has a political belief, has a political agenda.
192
+
193
+ 49
194
+ 00:02:58,000 --> 00:03:01,000
195
+ They don't support what the government is doing here.
196
+
197
+ 50
198
+ 00:03:01,000 --> 00:03:07,000
199
+ They may shut down a government website, uh, they may deface the website, corrupt a particular website,
200
+
201
+ 51
202
+ 00:03:07,000 --> 00:03:11,000
203
+ all going to be with political beliefs, ethical.
204
+
205
+ 52
206
+ 00:03:11,000 --> 00:03:16,000
207
+ Some people believe that what they're doing is ethically correct.
208
+
209
+ 53
210
+ 00:03:16,000 --> 00:03:20,000
211
+ They consider themselves a whistleblower or white hat hacker.
212
+
213
+ 54
214
+ 00:03:20,000 --> 00:03:24,000
215
+ For example, let's say you work in an organization today.
216
+
217
+ 55
218
+ 00:03:25,000 --> 00:03:26,000
219
+ I cannot see you.
220
+
221
+ 56
222
+ 00:03:26,000 --> 00:03:32,000
223
+ Let's say somebody works in an organization today, and they feel that what this organization is doing
224
+
225
+ 57
226
+ 00:03:32,000 --> 00:03:37,000
227
+ is illegal or bad for the public, even though it might be legal in the country's law.
228
+
229
+ 58
230
+ 00:03:37,000 --> 00:03:44,000
231
+ So what you do argue somebody else, what somebody else does is that then they do bad things.
232
+
233
+ 59
234
+ 00:03:44,000 --> 00:03:45,000
235
+ They corrupt the data.
236
+
237
+ 60
238
+ 00:03:45,000 --> 00:03:48,000
239
+ They release the data, they try to punish the organization.
240
+
241
+ 61
242
+ 00:03:48,000 --> 00:03:53,000
243
+ So what they feel is technically, in their mind, ethical revenge.
244
+
245
+ 62
246
+ 00:03:53,000 --> 00:03:57,000
247
+ Okay, disgruntled employees will do this.
248
+
249
+ 63
250
+ 00:03:57,000 --> 00:03:58,000
251
+ So revenge is this.
252
+
253
+ 64
254
+ 00:03:58,000 --> 00:04:03,000
255
+ Let's say you work for an organization and for some reason they treat you bad.
256
+
257
+ 65
258
+ 00:04:03,000 --> 00:04:05,000
259
+ They didn't send you that last paycheck.
260
+
261
+ 66
262
+ 00:04:05,000 --> 00:04:07,000
263
+ They owe you a bunch of money.
264
+
265
+ 67
266
+ 00:04:07,000 --> 00:04:09,000
267
+ They did bad things to you, don't support.
268
+
269
+ 68
270
+ 00:04:09,000 --> 00:04:15,000
271
+ So what you do is because you probably still had logins, or even if you were fired and your login still
272
+
273
+ 69
274
+ 00:04:15,000 --> 00:04:21,000
275
+ worked, you may go and corrupt their data, expose their information would be revenge, disruption
276
+
277
+ 70
278
+ 00:04:21,000 --> 00:04:22,000
279
+ and chaos.
280
+
281
+ 71
282
+ 00:04:22,000 --> 00:04:25,000
283
+ Some people are just motivated.
284
+
285
+ 72
286
+ 00:04:25,000 --> 00:04:31,000
287
+ They don't have really any agenda other than chaos in a.
288
+
289
+ 73
290
+ 00:04:31,000 --> 00:04:34,000
291
+ I'm not sure if you guys ever saw Batman.
292
+
293
+ 74
294
+ 00:04:34,000 --> 00:04:38,000
295
+ Uh, the one with the Joker, the Dark Knight.
296
+
297
+ 75
298
+ 00:04:38,000 --> 00:04:39,000
299
+ Really good movie.
300
+
301
+ 76
302
+ 00:04:39,000 --> 00:04:40,000
303
+ You should watch that.
304
+
305
+ 77
306
+ 00:04:40,000 --> 00:04:44,000
307
+ So in The Dark Knight, Alfred, uh, acts as bad.
308
+
309
+ 78
310
+ 00:04:44,000 --> 00:04:46,000
311
+ Uh, Batman is asking for.
312
+
313
+ 79
314
+ 00:04:46,000 --> 00:04:47,000
315
+ Why is the Joker doing this?
316
+
317
+ 80
318
+ 00:04:47,000 --> 00:04:50,000
319
+ You know, why is he killing people and creating chaos?
320
+
321
+ 81
322
+ 00:04:50,000 --> 00:04:57,000
323
+ And the gist of it is because there are just some people that prefers to watch the world burn.
324
+
325
+ 82
326
+ 00:04:57,000 --> 00:05:05,000
327
+ There are some people out there that their only motivation is the dissatisfaction and unhappiness of
328
+
329
+ 83
330
+ 00:05:05,000 --> 00:05:06,000
331
+ others.
332
+
333
+ 84
334
+ 00:05:06,000 --> 00:05:07,000
335
+ All right.
336
+
337
+ 85
338
+ 00:05:07,000 --> 00:05:08,000
339
+ This is how we secure against.
340
+
341
+ 86
342
+ 00:05:08,000 --> 00:05:13,000
343
+ And there's quite a lot of people and a lot of attackers that you're going to encounter like this.
344
+
345
+ 87
346
+ 00:05:13,000 --> 00:05:18,000
347
+ In other words, there's no real motive other than destruction in their path.
348
+
349
+ 88
350
+ 00:05:18,000 --> 00:05:20,000
351
+ The next one up I have is war.
352
+
353
+ 89
354
+ 00:05:20,000 --> 00:05:24,000
355
+ Now, this is going to be mostly driven by nation states, okay?
356
+
357
+ 90
358
+ 00:05:24,000 --> 00:05:30,000
359
+ Their motivation is to produce all kinds of warfare between organizations.
360
+
361
+ 91
362
+ 00:05:30,000 --> 00:05:31,000
363
+ Okay.
364
+
365
+ 92
366
+ 00:05:31,000 --> 00:05:32,000
367
+ So here we go guys.
368
+
369
+ 93
370
+ 00:05:32,000 --> 00:05:34,000
371
+ Quite a lot of motivations that are out there.
372
+
373
+ 94
374
+ 00:05:34,000 --> 00:05:42,000
375
+ And as you can see there are many, many motivations that these hackers, these bad people will have
376
+
377
+ 95
378
+ 00:05:42,000 --> 00:05:43,000
379
+ towards your organization.
380
+
381
+ 96
382
+ 00:05:43,000 --> 00:05:47,000
383
+ So just keep these motivations in mind so you can secure against them.
384
+