diff --git a/.gitattributes b/.gitattributes
index 4cf99daff613be2e80703175abf0bd9c6c09859f..a9cb3b780fb844055d21226e33ae90f48f149b2a 100644
--- a/.gitattributes
+++ b/.gitattributes
@@ -133,3 +133,36 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/003[[:space:]]Vishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/002[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/006[[:space:]]Misinformation[[:space:]]and[[:space:]]Disinformation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/005[[:space:]]Spear[[:space:]]Phishing[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/007[[:space:]]Impersonation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/008[[:space:]]Business[[:space:]]Email[[:space:]]Compromise[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/010[[:space:]]Watering[[:space:]]Hole[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/009[[:space:]]Pretexting[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/011[[:space:]]Brand[[:space:]]Impersonation[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/012[[:space:]]Typosquatting[[:space:]]OB[[:space:]]2.2.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/013[[:space:]]Training[[:space:]]against[[:space:]]Phishing[[:space:]]OB[[:space:]]5.6.mp4 filter=lfs diff=lfs merge=lfs -text
+08[[:space:]]-[[:space:]]Social[[:space:]]Engineering/014[[:space:]]Security[[:space:]]Awareness[[:space:]]Program[[:space:]]OB[[:space:]]5.6.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/001[[:space:]]Segmentation[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/002[[:space:]]Isolation[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/003[[:space:]]Access[[:space:]]Control[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/005[[:space:]]Access[[:space:]]Control[[:space:]]List[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/004[[:space:]]Principles[[:space:]]of[[:space:]]Least[[:space:]]Privilege[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/007[[:space:]]Application[[:space:]]Allow[[:space:]]List[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/006[[:space:]]Filesystem[[:space:]]Permissions[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/009[[:space:]]Configuration[[:space:]]Enforcement[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/008[[:space:]]Patching[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/010[[:space:]]Decommissioning[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/011[[:space:]]Monitoring[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+09[[:space:]]-[[:space:]]Securing[[:space:]]IT[[:space:]]Assets/012[[:space:]]Hardening[[:space:]]Techniques[[:space:]]OB[[:space:]]2.5.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/001[[:space:]]Cloud[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/003[[:space:]]Serverless[[:space:]]Architecture[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/002[[:space:]]Infrastructure[[:space:]]as[[:space:]]Code[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/004[[:space:]]Microservices[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/005[[:space:]]Air[[:space:]]Gapped[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/007[[:space:]]On-Premises[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/006[[:space:]]Software-Defined[[:space:]]Networking[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/008[[:space:]]Centralized[[:space:]]vs.[[:space:]]Decentralized[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/009[[:space:]]Virtualization[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/010[[:space:]]Containerization[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/011[[:space:]]High[[:space:]]Availability[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
+10[[:space:]]-[[:space:]]Security[[:space:]]Architecture/013[[:space:]]ICS[[:space:]]OB[[:space:]]3.1.mp4 filter=lfs diff=lfs merge=lfs -text
diff --git a/08 - Social Engineering/005 Spear Phishing OB 2.2.mp4 b/08 - Social Engineering/005 Spear Phishing OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..3ea49f174458f4b55633c18a5275bfeafd6c9730
--- /dev/null
+++ b/08 - Social Engineering/005 Spear Phishing OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:33817e9440664590d364c3a5ac0457d1cf3d4344e5d8cc06bfe9310c469ff374
+size 243728707
diff --git a/08 - Social Engineering/007 Impersonation OB 2.2.mp4 b/08 - Social Engineering/007 Impersonation OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..3de53dc07713ee5bff9d152aed44f055703966b6
--- /dev/null
+++ b/08 - Social Engineering/007 Impersonation OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:84500dfa8248e7c3a4520c043defab68eb4ba9fb0f53b426dedf291d087224ab
+size 146609459
diff --git a/08 - Social Engineering/008 Business Email Compromise OB 2.2.mp4 b/08 - Social Engineering/008 Business Email Compromise OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..a91e8e294fa8c8d42b51bcf855bed66e8dae2375
--- /dev/null
+++ b/08 - Social Engineering/008 Business Email Compromise OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:86ba65fdbf0c8c98c8ff6bf7198c06b7b1de50bffc997dd4807b93094894a639
+size 146064157
diff --git a/08 - Social Engineering/009 Pretexting OB 2.2.mp4 b/08 - Social Engineering/009 Pretexting OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..b6c4c4f6110abd2262d5b93a5ae71626db8b26f2
--- /dev/null
+++ b/08 - Social Engineering/009 Pretexting OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:06d638ed3ad9abd537b9848a1a0a28b8c3d9ec3ada49703b4e22f4bc823e7eab
+size 208963164
diff --git a/08 - Social Engineering/010 Watering Hole OB 2.2.mp4 b/08 - Social Engineering/010 Watering Hole OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..f5ee8b186bcd39a7824841b65c5d3dbb4e9d49fb
--- /dev/null
+++ b/08 - Social Engineering/010 Watering Hole OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:74a70cafc05e7560b7fc660c19784f49e64de7a38f4df7bc959a67eb334d07ee
+size 191350680
diff --git a/08 - Social Engineering/011 Brand Impersonation OB 2.2.mp4 b/08 - Social Engineering/011 Brand Impersonation OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..958789dd8023e25a7e39cac98b08960a05c9502c
--- /dev/null
+++ b/08 - Social Engineering/011 Brand Impersonation OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:fd07516b14d370c2fbd49d8d1cb75f02149b2359c549c644cb2e3c6a568cf1cc
+size 120682958
diff --git a/08 - Social Engineering/012 Typosquatting OB 2.2.mp4 b/08 - Social Engineering/012 Typosquatting OB 2.2.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..8282f103bd8053b78b84a952b697616a081ae19f
--- /dev/null
+++ b/08 - Social Engineering/012 Typosquatting OB 2.2.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:b7e3c1ab4603f980f199544225b39aacf69b307452b72162828d0e81cae5e353
+size 226674750
diff --git a/08 - Social Engineering/013 Training against Phishing OB 5.6.mp4 b/08 - Social Engineering/013 Training against Phishing OB 5.6.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..c7e42d8f3228132a8c977bc57938baf3aa9cf842
--- /dev/null
+++ b/08 - Social Engineering/013 Training against Phishing OB 5.6.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:174997c17366cbd07ceae687d00d495cfd0f5b81187086e9b01a8859e3ed3f7b
+size 213174958
diff --git a/08 - Social Engineering/014 Security Awareness Program OB 5.6.mp4 b/08 - Social Engineering/014 Security Awareness Program OB 5.6.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..66a905eb6232af0a7fc7d95879a653ba17c8115e
--- /dev/null
+++ b/08 - Social Engineering/014 Security Awareness Program OB 5.6.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:22641fc1822b5ba9c357ec85938ff4031ad8cfc2952f5852a0a031d277de0cfe
+size 223183545
diff --git a/09 - Securing IT Assets/001 Segmentation OB 2.5.mp4 b/09 - Securing IT Assets/001 Segmentation OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..665df658ee2a6ad4f2d12ff4bac945a1125f3809
--- /dev/null
+++ b/09 - Securing IT Assets/001 Segmentation OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:0c4f0f6b27eb1c75c27b8d0cf7bd392a00150adec3217b880431c14906a8adc1
+size 229078501
diff --git a/09 - Securing IT Assets/002 Isolation OB 2.5.mp4 b/09 - Securing IT Assets/002 Isolation OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..9535eaf0a0c5455a69bfc6bfc2c0d6e3c738fb7a
--- /dev/null
+++ b/09 - Securing IT Assets/002 Isolation OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:32dd560740f2a381ee6807c0ed3e8463e651f003f6ee16539f6bc847d92494df
+size 255600569
diff --git a/09 - Securing IT Assets/003 Access Control OB 2.5.mp4 b/09 - Securing IT Assets/003 Access Control OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..33718b90481cf7eee68a297bed960759281ceef1
--- /dev/null
+++ b/09 - Securing IT Assets/003 Access Control OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:a634e9b68f524e2eabc5361ca815d4032ea3098ef22c2a734b40cca6bead6c74
+size 130346468
diff --git a/09 - Securing IT Assets/004 Principles of Least Privilege OB 2.5.mp4 b/09 - Securing IT Assets/004 Principles of Least Privilege OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..f867e75cc2516b1b7071c52dd02763557b86b94d
--- /dev/null
+++ b/09 - Securing IT Assets/004 Principles of Least Privilege OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:451cfb0122fcb168220044a2b8dd37ff06aefba2d4a156502c82b654fea2e6b7
+size 140483198
diff --git a/09 - Securing IT Assets/005 Access Control List OB 2.5.mp4 b/09 - Securing IT Assets/005 Access Control List OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..6040494dae5c2fdb92ea2442afd7cfee0262f745
--- /dev/null
+++ b/09 - Securing IT Assets/005 Access Control List OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:1f46f459cecf28e2209ae38d75ab9673c356e21034aa5a0b11e56af3ccb62748
+size 80763470
diff --git a/09 - Securing IT Assets/006 Filesystem Permissions OB 2.5.mp4 b/09 - Securing IT Assets/006 Filesystem Permissions OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..5d6ccaa0632e101c1011c4dfa6c4ad73a417e1c5
--- /dev/null
+++ b/09 - Securing IT Assets/006 Filesystem Permissions OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:6dd5822f232a8da329ab4e45723fc5425a5df7d9e114a5c04a322dd959f0ab5e
+size 207582053
diff --git a/09 - Securing IT Assets/007 Application Allow List OB 2.5.mp4 b/09 - Securing IT Assets/007 Application Allow List OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..a8c264a618748e193ae83b4d5f0073d69dc1a686
--- /dev/null
+++ b/09 - Securing IT Assets/007 Application Allow List OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:ef792351b3328095cb67971f74195f7b0326bde581213dc6f68df24318ac8418
+size 77594987
diff --git a/09 - Securing IT Assets/008 Patching OB 2.5.mp4 b/09 - Securing IT Assets/008 Patching OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..10c25da00407aa2c45e6679f0eb0a180c9c1cc86
--- /dev/null
+++ b/09 - Securing IT Assets/008 Patching OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:ff10141ae450dd7e6237aebfc8658aedfb2ec596420bee9e5069d696ee59f5fe
+size 164696270
diff --git a/09 - Securing IT Assets/009 Configuration Enforcement OB 2.5.mp4 b/09 - Securing IT Assets/009 Configuration Enforcement OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..52c173bf173c34ed1e38ef3e331d1dc3ed03004e
--- /dev/null
+++ b/09 - Securing IT Assets/009 Configuration Enforcement OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:0efce9153d54b004f221be25bc49323bc299d2708ef090b3c75ae3586a2692d0
+size 101018118
diff --git a/09 - Securing IT Assets/010 Decommissioning OB 2.5.mp4 b/09 - Securing IT Assets/010 Decommissioning OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..c1c199f4a63a1aacbf51278430cee1fa9969ce00
--- /dev/null
+++ b/09 - Securing IT Assets/010 Decommissioning OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:c1c63c118e4b9e3c876fcf1647d8ba6cb101f2721a3d09bd7f6512d84f28642d
+size 166973644
diff --git a/09 - Securing IT Assets/011 Monitoring OB 2.5.mp4 b/09 - Securing IT Assets/011 Monitoring OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..4865527b43e6add6ab35f7c74114c735da6f06f8
--- /dev/null
+++ b/09 - Securing IT Assets/011 Monitoring OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:9feb3619ba2c6ee323898656074bd5dd441f7d72d1498b0ae89a10df24ad856b
+size 129115103
diff --git a/09 - Securing IT Assets/012 Hardening Techniques OB 2.5.mp4 b/09 - Securing IT Assets/012 Hardening Techniques OB 2.5.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..03a92a74825f11195cd514f3a373087a9c53bfff
--- /dev/null
+++ b/09 - Securing IT Assets/012 Hardening Techniques OB 2.5.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:c9e1777edb1557bcbfe8732868839e0326f403154a2950c2f022f6ba12bafe1d
+size 440558615
diff --git a/10 - Security Architecture/001 Cloud OB 3.1.mp4 b/10 - Security Architecture/001 Cloud OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..8b59b0ddfbe547cb6727a5af727b3b1236ea5c75
--- /dev/null
+++ b/10 - Security Architecture/001 Cloud OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:d97d150bda22e1f679687878dcc9dbd8d5e575ca6e2b92e5c2f0c032b3728abb
+size 511591304
diff --git a/10 - Security Architecture/002 Infrastructure as Code OB 3.1.mp4 b/10 - Security Architecture/002 Infrastructure as Code OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..cfc9d63668729d7df240dbd346d6b5a4d878a65b
--- /dev/null
+++ b/10 - Security Architecture/002 Infrastructure as Code OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:976a3b50ba018c8bb63c1f35b400aa4597909971dc359f0370bd1471e098419d
+size 153103708
diff --git a/10 - Security Architecture/003 Serverless Architecture OB 3.1.mp4 b/10 - Security Architecture/003 Serverless Architecture OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..512cbef1c26ddf4c55ac3bb05ae2155b51e02723
--- /dev/null
+++ b/10 - Security Architecture/003 Serverless Architecture OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:7f753ffd503baecf5d5073246ceeaf302dcf73709cb234a7f40cfed362ace493
+size 97395474
diff --git a/10 - Security Architecture/004 Microservices OB 3.1.mp4 b/10 - Security Architecture/004 Microservices OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..728ba6607448aa3bf634ba471de4154f38b040a1
--- /dev/null
+++ b/10 - Security Architecture/004 Microservices OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:eb69f2536bc8a9a6b9e54e4de52291302518639303028f4c3b69b3e179891df6
+size 135693215
diff --git a/10 - Security Architecture/005 Air Gapped OB 3.1.mp4 b/10 - Security Architecture/005 Air Gapped OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..0cc4b3363ebe3b35cd8145f174075918358b49cd
--- /dev/null
+++ b/10 - Security Architecture/005 Air Gapped OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:ab7b3f8ae4af31020d8dee0752882f7e2140201c0f6ea3d2b7001dc0d34f8e0b
+size 99208855
diff --git a/10 - Security Architecture/006 Software-Defined Networking OB 3.1.mp4 b/10 - Security Architecture/006 Software-Defined Networking OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..3fb767d06ceec85a21ac12c826a716f6ab78d615
--- /dev/null
+++ b/10 - Security Architecture/006 Software-Defined Networking OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:38ff5c09641718366c45565821aaf767dbae05488e80840b8c16befcfc129f5d
+size 219936591
diff --git a/10 - Security Architecture/007 On-Premises OB 3.1.mp4 b/10 - Security Architecture/007 On-Premises OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..32769bfd0542def53e9d4388102fc0b79893ac64
--- /dev/null
+++ b/10 - Security Architecture/007 On-Premises OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:b4e92596402ff78bdb273f7e3f3d752bc1e859ab7348c6ee0c4a98942328afd9
+size 53459965
diff --git a/10 - Security Architecture/008 Centralized vs. Decentralized OB 3.1.mp4 b/10 - Security Architecture/008 Centralized vs. Decentralized OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..206ebab2250c2283261fb2f3f422088d99c59324
--- /dev/null
+++ b/10 - Security Architecture/008 Centralized vs. Decentralized OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:7b69fff1ae23a2ae3f0de9286cf3ffd92fa111b02a2b82084f8234a8a5a18658
+size 178712004
diff --git a/10 - Security Architecture/009 Virtualization OB 3.1.mp4 b/10 - Security Architecture/009 Virtualization OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..0d9c93b545d180ca632b6f41f1b8267cd6d6804a
--- /dev/null
+++ b/10 - Security Architecture/009 Virtualization OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:8bb61d45846d6513739bbeb3ace86ac2a86f1980a437e56e77ec08cd887c8993
+size 301783477
diff --git a/10 - Security Architecture/010 Containerization OB 3.1.mp4 b/10 - Security Architecture/010 Containerization OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..5a336d78efe0637728a47cd45922368e8a1e3477
--- /dev/null
+++ b/10 - Security Architecture/010 Containerization OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:894f74391eee91494c903790eeae243fea3068ce0840cb08bc3c69e71de019cc
+size 220510089
diff --git a/10 - Security Architecture/011 High Availability OB 3.1.mp4 b/10 - Security Architecture/011 High Availability OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..8faf59b8b054fea9cc862e93ba664fc76d8f458a
--- /dev/null
+++ b/10 - Security Architecture/011 High Availability OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:5a93f0a1eb6b93a13f3b7bb16a8c12bb8c9372b74b956a5453ac0544cfa99ed7
+size 186692724
diff --git a/10 - Security Architecture/013 ICS OB 3.1.mp4 b/10 - Security Architecture/013 ICS OB 3.1.mp4
new file mode 100644
index 0000000000000000000000000000000000000000..277c65766a7b7b92391444f337d649f9382cc3d9
--- /dev/null
+++ b/10 - Security Architecture/013 ICS OB 3.1.mp4
@@ -0,0 +1,3 @@
+version https://git-lfs.github.com/spec/v1
+oid sha256:5305d91a5764667386e2f0cdc270b3bbc5d8a5609e1200f1de342c1180bd1b90
+size 204975036
diff --git a/20 - Security Governance and Privacy/006 Privacy OB 5.4_en.srt b/20 - Security Governance and Privacy/006 Privacy OB 5.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..0f0f8883305090b358df095edec14fa405b978f6
--- /dev/null
+++ b/20 - Security Governance and Privacy/006 Privacy OB 5.4_en.srt
@@ -0,0 +1,552 @@
+1
+00:00:00,000 --> 00:00:04,000
+The hottest topic in the world of cybersecurity right now is privacy.
+
+2
+00:00:04,000 --> 00:00:07,000
+Did you guess that privacy is a big thing nowadays?
+
+3
+00:00:08,000 --> 00:00:13,000
+Almost anytime you hear malware gets into an organization and steals the data, or hackers steals the
+
+4
+00:00:13,000 --> 00:00:18,000
+data, or disgruntled employee steals the data, it's always about the loss of private data.
+
+5
+00:00:19,000 --> 00:00:22,000
+So in this video, let's take a look at privacy.
+
+6
+00:00:22,000 --> 00:00:25,000
+Just the entire topic of privacy.
+
+7
+00:00:25,000 --> 00:00:28,000
+And there's a couple of terms that I want you guys to be familiar with.
+
+8
+00:00:28,000 --> 00:00:30,000
+So if you see on your exam you're familiar with it.
+
+9
+00:00:30,000 --> 00:00:37,000
+Privacy refers to the practices, policies, and legal requirements surrounding the protection of personal
+
+10
+00:00:37,000 --> 00:00:38,000
+and sensitive data.
+
+11
+00:00:38,000 --> 00:00:40,000
+Now, what data are we talking about?
+
+12
+00:00:40,000 --> 00:00:41,000
+What is it that we're secure?
+
+13
+00:00:41,000 --> 00:00:45,000
+Well, privacy information falls into two things.
+
+14
+00:00:45,000 --> 00:00:47,000
+What's known as PII information.
+
+15
+00:00:49,000 --> 00:00:55,000
+Are known as personal identifiable info and protected health, also known as personal health info.
+
+16
+00:00:55,000 --> 00:00:57,000
+So PII and Phi.
+
+17
+00:00:57,000 --> 00:00:59,000
+So what exactly is PII?
+
+18
+00:00:59,000 --> 00:01:05,000
+Well, it's information that when used alone or with other relevant data, can identify the individual.
+
+19
+00:01:06,000 --> 00:01:08,000
+And then there's Phi.
+
+20
+00:01:08,000 --> 00:01:15,000
+Now this is the demographic information, medical history, tests and laboratory results, mental health
+
+21
+00:01:15,000 --> 00:01:22,000
+conditions, insurance information or other information is generally collected to care for a person.
+
+22
+00:01:22,000 --> 00:01:25,000
+Let me give you a couple of examples of what PII and Phi.
+
+23
+00:01:25,000 --> 00:01:26,000
+So.
+
+24
+00:01:27,000 --> 00:01:34,000
+Your address, your, uh, your email address, physical address, email, your phone number, your
+
+25
+00:01:34,000 --> 00:01:35,000
+credit card information.
+
+26
+00:01:35,000 --> 00:01:41,000
+That's going to be PII, what medication you're taking, what illnesses you have, what what was your
+
+27
+00:01:41,000 --> 00:01:43,000
+recent blood tests and things like that.
+
+28
+00:01:43,000 --> 00:01:44,000
+That would be Fi.
+
+29
+00:01:44,000 --> 00:01:49,000
+These are both considered private information that falls under the terms of privacy, and they need
+
+30
+00:01:49,000 --> 00:01:50,000
+to be protected.
+
+31
+00:01:50,000 --> 00:01:54,000
+Privacy is a critical thing when it comes to the world of security.
+
+32
+00:01:54,000 --> 00:02:01,000
+Now, if there's one thing we know about privacy is that it's heavily regulated, not just locally.
+
+33
+00:02:02,000 --> 00:02:05,000
+But sometimes regionally, nationally and globally.
+
+34
+00:02:05,000 --> 00:02:11,000
+Laws like GDPR in Europe, CcpA, which is done in California, which is similar to GDPR.
+
+35
+00:02:11,000 --> 00:02:18,000
+Basically, these are privacy laws that is out there to secure people's private information PII and
+
+36
+00:02:19,000 --> 00:02:20,000
+Phi.
+
+37
+00:02:20,000 --> 00:02:25,000
+Now, the first thing we want to talk about is that you're going to have local or regional laws that
+
+38
+00:02:25,000 --> 00:02:27,000
+you have to follow.
+
+39
+00:02:27,000 --> 00:02:31,000
+These are going to address specific things in a smaller geographic community.
+
+40
+00:02:31,000 --> 00:02:34,000
+These laws can be very detailed or stricter.
+
+41
+00:02:34,000 --> 00:02:40,000
+For example, in a town they may have a certain way that private data should be stored.
+
+42
+00:02:40,000 --> 00:02:44,000
+Or if you want to do business in this town, you have to secure the private data.
+
+43
+00:02:44,000 --> 00:02:47,000
+This is where you have to store it in a certain pattern.
+
+44
+00:02:47,000 --> 00:02:53,000
+Now, you know that's local legal ramifications or local legal laws.
+
+45
+00:02:53,000 --> 00:02:58,000
+Then you have national laws that are broader in scope that the entire country has to follow.
+
+46
+00:02:59,000 --> 00:03:02,000
+This is how organizations across an entire country is going to have to follow.
+
+47
+00:03:02,000 --> 00:03:08,000
+Things like this is going to include like HIPAA compliance, which is every single clinic and hospital
+
+48
+00:03:08,000 --> 00:03:10,000
+within the United States have to follow.
+
+49
+00:03:12,000 --> 00:03:18,000
+Then you can have global laws that anybody wants to do business in this country.
+
+50
+00:03:18,000 --> 00:03:19,000
+They got to follow it.
+
+51
+00:03:19,000 --> 00:03:25,000
+Now this is especially organizations that falls into operating internationally.
+
+52
+00:03:25,000 --> 00:03:28,000
+You're dealing with data across national borders.
+
+53
+00:03:28,000 --> 00:03:34,000
+So for example with with GDPR which is a general data protection.
+
+54
+00:03:34,000 --> 00:03:43,000
+This particular regulation is done to protect the privacy data of the EU citizens, now EU citizens.
+
+55
+00:03:44,000 --> 00:03:49,000
+Doesn't matter what country they're in, their data needs to be protected by GDPR.
+
+56
+00:03:49,000 --> 00:03:53,000
+Doesn't matter what country your organization is in, you need to follow GDPR.
+
+57
+00:03:53,000 --> 00:04:01,000
+So if you work in a company that follows or works in multiple countries, that company needs to follow
+
+58
+00:04:01,000 --> 00:04:03,000
+all these laws across all these different countries.
+
+59
+00:04:03,000 --> 00:04:07,000
+And that, of course, is very complex to do.
+
+60
+00:04:07,000 --> 00:04:11,000
+Now, there are some terms when it comes to processing private data.
+
+61
+00:04:12,000 --> 00:04:13,000
+A couple of terms.
+
+62
+00:04:13,000 --> 00:04:14,000
+What's called the data subject.
+
+63
+00:04:15,000 --> 00:04:18,000
+Data controllers and data processor.
+
+64
+00:04:18,000 --> 00:04:19,000
+So let's go through this.
+
+65
+00:04:19,000 --> 00:04:24,000
+A data subject is an individual whose personal data is processed by an organization.
+
+66
+00:04:24,000 --> 00:04:28,000
+You have to protect the rights and privacy of the data subjects.
+
+67
+00:04:28,000 --> 00:04:36,000
+This includes ensuring consistent, uh, consistency for the data, uh, making sure you get consent
+
+68
+00:04:36,000 --> 00:04:41,000
+for the data and processing and allowing the data to be processed correctly.
+
+69
+00:04:41,000 --> 00:04:46,000
+Now, keep in mind the data subject is just a user to the website.
+
+70
+00:04:46,000 --> 00:04:51,000
+If you're going to Facebook right now, you're the data subject on a website.
+
+71
+00:04:51,000 --> 00:04:54,000
+You're going to have what's called a controller and a processor.
+
+72
+00:04:54,000 --> 00:05:00,000
+In privacy terms, a controller is an entity that determines the purpose and means of person processing.
+
+73
+00:05:00,000 --> 00:05:09,000
+Personal data A processor is an entity that the that processes the data on behalf of the controller.
+
+74
+00:05:09,000 --> 00:05:09,000
+Let me explain.
+
+75
+00:05:09,000 --> 00:05:11,000
+I'll give you guys a couple of examples of this.
+
+76
+00:05:11,000 --> 00:05:14,000
+So you have a data subject a controller and a processor.
+
+77
+00:05:14,000 --> 00:05:16,000
+Let's say you have a website.
+
+78
+00:05:17,000 --> 00:05:23,000
+And you own a website, you're going to determine what data we collect.
+
+79
+00:05:23,000 --> 00:05:29,000
+You're going to then determine how you're going to store that data, why you need to collect the data.
+
+80
+00:05:29,000 --> 00:05:30,000
+Then you have a website user.
+
+81
+00:05:30,000 --> 00:05:34,000
+So the website user is just coming to browse what you have on your website.
+
+82
+00:05:34,000 --> 00:05:36,000
+Then you have something like Google Analytics.
+
+83
+00:05:36,000 --> 00:05:38,000
+Now Google Analytics is just Google.
+
+84
+00:05:38,000 --> 00:05:43,000
+And all they're doing is they're processing all the data on your website to see how many visitors you
+
+85
+00:05:43,000 --> 00:05:45,000
+had and how long they stayed on your website.
+
+86
+00:05:46,000 --> 00:05:52,000
+So let's go through the three, the three terms the data subject, controller and processor.
+
+87
+00:05:52,000 --> 00:05:55,000
+So the data subject is just users.
+
+88
+00:05:55,000 --> 00:06:01,000
+The data controller is you, the data controller is who's going to determine, okay, why do we need
+
+89
+00:06:01,000 --> 00:06:02,000
+this data.
+
+90
+00:06:02,000 --> 00:06:04,000
+Why where are we going to store this data.
+
+91
+00:06:06,000 --> 00:06:07,000
+What are we going to do with this data.
+
+92
+00:06:08,000 --> 00:06:16,000
+Now who's getting the data are processing the data and coming out with specific outputs.
+
+93
+00:06:16,000 --> 00:06:17,000
+Google analytics.
+
+94
+00:06:17,000 --> 00:06:20,000
+So Google is going to be the processor.
+
+95
+00:06:20,000 --> 00:06:22,000
+You are the data controller.
+
+96
+00:06:22,000 --> 00:06:25,000
+And then the person using a website is the subject.
+
+97
+00:06:26,000 --> 00:06:30,000
+Another time you want to be, uh, familiar with is what's called ownership.
+
+98
+00:06:30,000 --> 00:06:33,000
+Data ownership refers to the rights and control of the data.
+
+99
+00:06:33,000 --> 00:06:38,000
+Like who owns the data, who's controlling the data, what they determine what you should do with the
+
+100
+00:06:38,000 --> 00:06:39,000
+data.
+
+101
+00:06:40,000 --> 00:06:46,000
+It relates to the ownership of personal data by data subjects and the organizations responsibility.
+
+102
+00:06:46,000 --> 00:06:47,000
+Now.
+
+103
+00:06:47,000 --> 00:06:52,000
+One thing an organization should always do is have data inventory.
+
+104
+00:06:52,000 --> 00:06:54,000
+What exactly is that?
+
+105
+00:06:54,000 --> 00:07:00,000
+Well, an organization, and I believe every company should do this, is to go and make an inventory
+
+106
+00:07:00,000 --> 00:07:03,000
+of all the different data that they have collected.
+
+107
+00:07:03,000 --> 00:07:08,000
+Sometimes organizations are very surprised to see what they have collected.
+
+108
+00:07:08,000 --> 00:07:10,000
+What exactly have they hold?
+
+109
+00:07:10,000 --> 00:07:11,000
+Where is it stored?
+
+110
+00:07:11,000 --> 00:07:14,000
+How long have they had it?
+
+111
+00:07:15,000 --> 00:07:17,000
+How is it being used?
+
+112
+00:07:17,000 --> 00:07:22,000
+So you want to make sure that you do this data inventory to see basically what data do you have.
+
+113
+00:07:22,000 --> 00:07:28,000
+And then the other thing is certain regulations will dictate how long you can hold certain data for.
+
+114
+00:07:28,000 --> 00:07:32,000
+So data retention policies must align with legal requirements.
+
+115
+00:07:32,000 --> 00:07:36,000
+For example, one law may specify that you need to hold the data for eight years.
+
+116
+00:07:36,000 --> 00:07:38,000
+Another law may say you need to hold it for 20 years.
+
+117
+00:07:38,000 --> 00:07:40,000
+So make sure you know the laws.
+
+118
+00:07:41,000 --> 00:07:44,000
+Here's a firm you're probably going to see on your exam.
+
+119
+00:07:44,000 --> 00:07:50,000
+It's called right to be forgotten and this is something that you're probably familiar with right now.
+
+120
+00:07:50,000 --> 00:07:56,000
+Do you guys know you can go and tell Facebook to delete your data and your profile and Google also.
+
+121
+00:07:57,000 --> 00:08:01,000
+Just Google the steps of how to do that, but that's a right to be forgotten.
+
+122
+00:08:01,000 --> 00:08:08,000
+We now have to give this right, and GDPR makes it pretty much mandatory that there is a right to be
+
+123
+00:08:08,000 --> 00:08:09,000
+forgotten.
+
+124
+00:08:09,000 --> 00:08:17,000
+Now, it's also known the right to erasure is a principle that allows individuals to request a deletion
+
+125
+00:08:17,000 --> 00:08:21,000
+of their personal data when there's no compelling reason for it to be continued processing.
+
+126
+00:08:22,000 --> 00:08:25,000
+For example, maybe you don't use Facebook anymore.
+
+127
+00:08:25,000 --> 00:08:28,000
+Maybe you never logged in in the last two years and you don't plan to.
+
+128
+00:08:28,000 --> 00:08:31,000
+So you can go to Facebook and you could say, well, you know what?
+
+129
+00:08:31,000 --> 00:08:33,000
+I don't want my data stored here anymore.
+
+130
+00:08:34,000 --> 00:08:37,000
+So that's known as a right to be forgotten.
+
+131
+00:08:37,000 --> 00:08:40,000
+And what they're going to do is they're going to delete your profile and all of your data that they
+
+132
+00:08:40,000 --> 00:08:43,000
+have on their systems that have they ever hacked or anything like that.
+
+133
+00:08:43,000 --> 00:08:45,000
+They can't get your data.
+
+134
+00:08:45,000 --> 00:08:45,000
+Okay.
+
+135
+00:08:45,000 --> 00:08:48,000
+Make sure you understand that privacy is a very serious subject.
+
+136
+00:08:48,000 --> 00:08:55,000
+And although most of the time what we do with privacy and how we manage privacy is going to be managed
+
+137
+00:08:55,000 --> 00:09:02,000
+by regulations or dictated by different regulations, keep in mind that even if it's not, it's something
+
+138
+00:09:02,000 --> 00:09:07,000
+that you have to follow all the time because it is super important to protect our customers information.
+
diff --git a/20 - Security Governance and Privacy/007 Quick Quiz.html b/20 - Security Governance and Privacy/007 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..13db4a6f23088c249643fa5539aa3be8005990f6
--- /dev/null
+++ b/20 - Security Governance and Privacy/007 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/21 - Risk Management/001 Risk Terms OB 5.2_en.srt b/21 - Risk Management/001 Risk Terms OB 5.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..05fbe84db4d0127b9783b589810f5212728af0b9
--- /dev/null
+++ b/21 - Risk Management/001 Risk Terms OB 5.2_en.srt
@@ -0,0 +1,416 @@
+1
+00:00:00,000 --> 00:00:03,000
+Everything we do in life has risks.
+
+2
+00:00:03,000 --> 00:00:05,000
+Now, what exactly is risk?
+
+3
+00:00:05,000 --> 00:00:08,000
+Well, in this section I want to define risk.
+
+4
+00:00:08,000 --> 00:00:12,000
+And I want to go through some terms with you guys that you should be familiar with.
+
+5
+00:00:12,000 --> 00:00:14,000
+So first of all, what exactly is risk.
+
+6
+00:00:14,000 --> 00:00:19,000
+Well, risk is the probability of a threat exploiting a vulnerability.
+
+7
+00:00:19,000 --> 00:00:22,000
+That's a generic definition of risk.
+
+8
+00:00:22,000 --> 00:00:28,000
+The first thing we want to talk about is risk is is probable risk is not guaranteed to happen if something
+
+9
+00:00:28,000 --> 00:00:29,000
+is considered to be a risk.
+
+10
+00:00:29,000 --> 00:00:34,000
+We're basically we're saying that this thing might or might not happen.
+
+11
+00:00:34,000 --> 00:00:37,000
+If it's 100% sure it's going to happen, it's not considered a risk.
+
+12
+00:00:37,000 --> 00:00:40,000
+Now, if it's probable, it's going to be a risk.
+
+13
+00:00:40,000 --> 00:00:41,000
+But what exactly is a risk?
+
+14
+00:00:41,000 --> 00:00:46,000
+Well, basically a risk is basically a threat exploiting a vulnerability.
+
+15
+00:00:47,000 --> 00:00:49,000
+This looks like a formula.
+
+16
+00:00:49,000 --> 00:00:53,000
+And it is, but it's not really a numerical formula.
+
+17
+00:00:53,000 --> 00:00:56,000
+It's just more of a formula that tells you how to calculate risk.
+
+18
+00:00:56,000 --> 00:01:03,000
+For example, if there is a particular threat like a hacker and there is a vulnerability because you
+
+19
+00:01:03,000 --> 00:01:08,000
+don't have firewalls on your network and there's a hacker that wants to exploit your network, well,
+
+20
+00:01:08,000 --> 00:01:10,000
+that's a high threat.
+
+21
+00:01:10,000 --> 00:01:11,000
+That's a big vulnerability.
+
+22
+00:01:11,000 --> 00:01:13,000
+There's a very high risk.
+
+23
+00:01:13,000 --> 00:01:19,000
+But what if the hacker exploits a particular hole on your network and you patch up that particular hole?
+
+24
+00:01:20,000 --> 00:01:22,000
+Well, the hacker still exists.
+
+25
+00:01:22,000 --> 00:01:25,000
+There's still a threat, but there's no vulnerability.
+
+26
+00:01:25,000 --> 00:01:27,000
+And anything times zero is basically zero.
+
+27
+00:01:27,000 --> 00:01:29,000
+So basically this risk may not exist.
+
+28
+00:01:29,000 --> 00:01:36,000
+In other words, the risk of him coming through port 21 is no more because you put a firewall on it,
+
+29
+00:01:36,000 --> 00:01:37,000
+blocked that particular port.
+
+30
+00:01:37,000 --> 00:01:44,000
+So when it comes to risk management, we have to ensure that we manage the threats and the vulnerabilities
+
+31
+00:01:44,000 --> 00:01:46,000
+in order to reduce or eliminate risks.
+
+32
+00:01:46,000 --> 00:01:50,000
+Now security is known to be risk based.
+
+33
+00:01:50,000 --> 00:01:57,000
+You see, all the actions we take in security should be done from a risk based approach.
+
+34
+00:01:57,000 --> 00:01:58,000
+What does that mean?
+
+35
+00:01:58,000 --> 00:02:05,000
+You see a risk based approach to security is that the controls we implement is going to be selected
+
+36
+00:02:05,000 --> 00:02:06,000
+based on a risk assessment.
+
+37
+00:02:06,000 --> 00:02:08,000
+Let me just tell you guys something.
+
+38
+00:02:08,000 --> 00:02:12,000
+You can't spend $10 protecting $5.
+
+39
+00:02:12,000 --> 00:02:17,000
+Every control that we implement in IT security is probably going to cost money.
+
+40
+00:02:17,000 --> 00:02:22,000
+And we have to ensure that what we're spending is protecting the asset, that it's actually worth it.
+
+41
+00:02:22,000 --> 00:02:26,000
+In other words, is the $10 that we're spending worth protecting $5?
+
+42
+00:02:26,000 --> 00:02:28,000
+How do we even come up with the value of the asset?
+
+43
+00:02:28,000 --> 00:02:32,000
+So risks of itself, risk assessment can get complex.
+
+44
+00:02:32,000 --> 00:02:34,000
+That's what this whole section is about.
+
+45
+00:02:34,000 --> 00:02:41,000
+Now, before we get into all the different risk assessments and how to respond to it, I want to cover
+
+46
+00:02:41,000 --> 00:02:43,000
+some terms that we're going to be using later.
+
+47
+00:02:43,000 --> 00:02:44,000
+The first thing up we have is an asset.
+
+48
+00:02:44,000 --> 00:02:47,000
+This is anything an environment that needs to be protected.
+
+49
+00:02:47,000 --> 00:02:49,000
+It's anything in the environment that generally has a value.
+
+50
+00:02:49,000 --> 00:02:53,000
+Of course, the most important asset in it is human life.
+
+51
+00:02:53,000 --> 00:02:54,000
+That's correct.
+
+52
+00:02:54,000 --> 00:02:58,000
+If you said that second most important is probably going to be data, then you have things like physical
+
+53
+00:02:58,000 --> 00:03:02,000
+structures like servers, computers, physical buildings and so on.
+
+54
+00:03:02,000 --> 00:03:06,000
+The asset valuation, this is something that you have to calculate.
+
+55
+00:03:06,000 --> 00:03:10,000
+Well, you can't really do a risk assessment if you don't know the value of the asset.
+
+56
+00:03:10,000 --> 00:03:17,000
+Once again, if you don't know the asset is worth $5, how are you doing an assessment to then go and
+
+57
+00:03:17,000 --> 00:03:20,000
+spend $1,020 protecting this $5 asset.
+
+58
+00:03:20,000 --> 00:03:22,000
+So you have to know the value of the asset.
+
+59
+00:03:22,000 --> 00:03:28,000
+This is a dollar value assigned to an asset based on the actual cost and non-monetary expenses.
+
+60
+00:03:28,000 --> 00:03:32,000
+In the world of risk, you have to know your threats.
+
+61
+00:03:32,000 --> 00:03:35,000
+Any potential occurrence that may harm the asset.
+
+62
+00:03:35,000 --> 00:03:42,000
+Threats can be not just people think hackers and viruses, but threats can also be things like physical
+
+63
+00:03:42,000 --> 00:03:46,000
+things, physical threats like a hurricane or a flood.
+
+64
+00:03:47,000 --> 00:03:49,000
+Threat agents and threat actors.
+
+65
+00:03:49,000 --> 00:03:53,000
+Those are people programs, hardware systems that uses threats to cause harm.
+
+66
+00:03:53,000 --> 00:03:57,000
+So a threat agent or an actor is basically a hacker.
+
+67
+00:03:57,000 --> 00:04:01,000
+The threat event are occurrences that lead to the exploitation.
+
+68
+00:04:01,000 --> 00:04:05,000
+So them hacking your system is considered a threat event.
+
+69
+00:04:05,000 --> 00:04:06,000
+What's a threat vector?
+
+70
+00:04:06,000 --> 00:04:08,000
+Well, how did they hack your system?
+
+71
+00:04:08,000 --> 00:04:10,000
+What vector did they use?
+
+72
+00:04:10,000 --> 00:04:14,000
+Well, that's the path or means by which the attacker can gain access.
+
+73
+00:04:14,000 --> 00:04:18,000
+So a threat vector for example is going to be like an internet line.
+
+74
+00:04:20,000 --> 00:04:24,000
+Vulnerability is a weakness in the asset or the absence of the weakness.
+
+75
+00:04:25,000 --> 00:04:29,000
+Uh, or the absent or the weakness of a safeguard or countermeasure.
+
+76
+00:04:29,000 --> 00:04:30,000
+So what is the vulnerability?
+
+77
+00:04:30,000 --> 00:04:31,000
+It's a hole in your system.
+
+78
+00:04:31,000 --> 00:04:33,000
+It's a weakness in your system.
+
+79
+00:04:33,000 --> 00:04:35,000
+It's the absence of a safeguard in your system.
+
+80
+00:04:35,000 --> 00:04:41,000
+For example, not have an antivirus, not having a firewall, uh, not training your users.
+
+81
+00:04:41,000 --> 00:04:45,000
+Those are going to be absence of a particular safeguard.
+
+82
+00:04:46,000 --> 00:04:50,000
+Exposure that is the actual or anticipated damage.
+
+83
+00:04:50,000 --> 00:04:54,000
+So, for example, when the threat exploits the vulnerability, when a hacker comes in, when the malware
+
+84
+00:04:54,000 --> 00:04:56,000
+comes in, how much is lost?
+
+85
+00:04:56,000 --> 00:04:58,000
+That's your exposure.
+
+86
+00:04:58,000 --> 00:05:01,000
+Safeguard is what we put in place to reduce the risk or eliminate the risk.
+
+87
+00:05:01,000 --> 00:05:05,000
+This is going to be like putting an antivirus or training your user.
+
+88
+00:05:05,000 --> 00:05:10,000
+The attack is when the threat attempts to exploit the vulnerability and if they're successful, it's
+
+89
+00:05:10,000 --> 00:05:11,000
+called a breach.
+
+90
+00:05:11,000 --> 00:05:17,000
+Now I want you guys to know the difference breach is the occurrence of a security mechanism being bypassed.
+
+91
+00:05:17,000 --> 00:05:24,000
+So if an attacker, a hacker, tries to break into your network, that's called the attack where they
+
+92
+00:05:24,000 --> 00:05:25,000
+successful.
+
+93
+00:05:25,000 --> 00:05:26,000
+Maybe.
+
+94
+00:05:26,000 --> 00:05:27,000
+Maybe not.
+
+95
+00:05:27,000 --> 00:05:28,000
+If they are, it's considered a breach.
+
+96
+00:05:28,000 --> 00:05:32,000
+So when we say security breach, that is generally a successful attack.
+
+97
+00:05:32,000 --> 00:05:38,000
+Now keep in mind once again guys, everything we do in IT security is a risk based thing.
+
+98
+00:05:38,000 --> 00:05:40,000
+We should not be doing anything in IT security.
+
+99
+00:05:40,000 --> 00:05:43,000
+If we haven't done a risk assessment, we can't.
+
+100
+00:05:43,000 --> 00:05:45,000
+We shouldn't select controls.
+
+101
+00:05:45,000 --> 00:05:47,000
+If we haven't done a risk assessment.
+
+102
+00:05:47,000 --> 00:05:51,000
+Without the risk assessment, we may be spending money protecting things that just don't need it or
+
+103
+00:05:51,000 --> 00:05:53,000
+it just doesn't have any value.
+
+104
+00:05:53,000 --> 00:05:55,000
+So let's get started with these risk assessments.
+
diff --git a/21 - Risk Management/002 Risk Identification and Assessment Times OB 5.2_en.srt b/21 - Risk Management/002 Risk Identification and Assessment Times OB 5.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..e45ab33c03b7c302d2de6d08842c377b99cbda39
--- /dev/null
+++ b/21 - Risk Management/002 Risk Identification and Assessment Times OB 5.2_en.srt
@@ -0,0 +1,340 @@
+1
+00:00:00,000 --> 00:00:04,000
+When it comes to risk management, one of the first things you're going to be doing is, of course,
+
+2
+00:00:04,000 --> 00:00:07,000
+identifying the risks that can affect your network.
+
+3
+00:00:07,000 --> 00:00:14,000
+Now, risk identification is understanding the initial phase of risk management where the potential
+
+4
+00:00:14,000 --> 00:00:17,000
+security risks are recognized and described.
+
+5
+00:00:17,000 --> 00:00:18,000
+Now I want to just point out something.
+
+6
+00:00:18,000 --> 00:00:22,000
+Risk identification is not something that's a solo activity.
+
+7
+00:00:22,000 --> 00:00:27,000
+Risk identification should be done by all members of the IT department, or most members of the IT department
+
+8
+00:00:27,000 --> 00:00:29,000
+and other departments.
+
+9
+00:00:29,000 --> 00:00:34,000
+The more people involved in it, the more perspectives you get.
+
+10
+00:00:34,000 --> 00:00:40,000
+Generally speaking, IT folks may be able to identify risks related to the IT department, but they're
+
+11
+00:00:40,000 --> 00:00:45,000
+probably not going to be able to identify certain risks that can affect the accounting department or
+
+12
+00:00:45,000 --> 00:00:47,000
+the sales department.
+
+13
+00:00:47,000 --> 00:00:47,000
+Why?
+
+14
+00:00:47,000 --> 00:00:49,000
+Because the IT folks generally don't work there.
+
+15
+00:00:49,000 --> 00:00:55,000
+So the more people that gets involved, the more likely your risk identification is going to be more
+
+16
+00:00:55,000 --> 00:00:56,000
+comprehensive.
+
+17
+00:00:56,000 --> 00:01:02,000
+So the whole point of risk identification is just coming up with a list of risks that can affect us.
+
+18
+00:01:02,000 --> 00:01:03,000
+Like what?
+
+19
+00:01:03,000 --> 00:01:08,000
+Well, we can already think of most risks, such as hackers hacking into the network and stealing our
+
+20
+00:01:08,000 --> 00:01:08,000
+data.
+
+21
+00:01:08,000 --> 00:01:13,000
+Ransomware, uh, modifying and encrypting the data.
+
+22
+00:01:13,000 --> 00:01:16,000
+But what about regulatory risks, like being out of compliance?
+
+23
+00:01:16,000 --> 00:01:18,000
+The risk of being out of compliance?
+
+24
+00:01:18,000 --> 00:01:24,000
+What about risks to the supply chain of a of a vendor going away or a vendor going down?
+
+25
+00:01:24,000 --> 00:01:29,000
+What about physical security risks such as the drop of infrastructure such as not having power?
+
+26
+00:01:29,000 --> 00:01:34,000
+Those are all different kinds of risks that needs to identify needs to be identified.
+
+27
+00:01:34,000 --> 00:01:39,000
+This is critical for establishing a baseline from which risk analysis, assessment and strategies are
+
+28
+00:01:39,000 --> 00:01:39,000
+done.
+
+29
+00:01:40,000 --> 00:01:46,000
+Now, when it comes to risk assessment themselves, there are a few different ways of doing it.
+
+30
+00:01:46,000 --> 00:01:51,000
+One kind of risk assessment is called an ad hoc risk assessment.
+
+31
+00:01:51,000 --> 00:01:53,000
+This is performed as needed.
+
+32
+00:01:53,000 --> 00:01:57,000
+Generally responds to a specific event or change in the environment.
+
+33
+00:01:57,000 --> 00:02:03,000
+For example, it might be conducted after a major security breach, or it could be conducted after a
+
+34
+00:02:03,000 --> 00:02:05,000
+natural disaster that no one thought about.
+
+35
+00:02:05,000 --> 00:02:10,000
+For example, there was a major flood next to a data center or a particular office that no one ever
+
+36
+00:02:10,000 --> 00:02:12,000
+taught, that that area ever gets flooded.
+
+37
+00:02:12,000 --> 00:02:14,000
+So you could come out and just do an ad hoc assessment.
+
+38
+00:02:14,000 --> 00:02:16,000
+Basically, there's no plan for it.
+
+39
+00:02:16,000 --> 00:02:18,000
+You just do it when it's needed.
+
+40
+00:02:19,000 --> 00:02:24,000
+Now, most companies have what's called reoccurring risk assessments.
+
+41
+00:02:24,000 --> 00:02:29,000
+This is the kind of assessment is conducted at regular intervals, for example, monthly or quarterly
+
+42
+00:02:29,000 --> 00:02:30,000
+or annually.
+
+43
+00:02:30,000 --> 00:02:35,000
+At a minimum, risk assessment should be done once a year at a minimum.
+
+44
+00:02:35,000 --> 00:02:41,000
+Reoccurring risk assessment are generally part of a good systematic approach to managing risks.
+
+45
+00:02:41,000 --> 00:02:44,000
+Now this one here is a good way of doing it.
+
+46
+00:02:45,000 --> 00:02:46,000
+Yearly, at a minimum.
+
+47
+00:02:46,000 --> 00:02:47,000
+Quarterly.
+
+48
+00:02:47,000 --> 00:02:49,000
+Monthly sounds better.
+
+49
+00:02:49,000 --> 00:02:53,000
+There are times when you're just going to do a one time risk assessment.
+
+50
+00:02:53,000 --> 00:02:58,000
+This is generally conducted for specific scenarios, such as if you're launching like a brand new IT
+
+51
+00:02:58,000 --> 00:03:02,000
+product, you may just do this one time thing because you're not going to launch that product again
+
+52
+00:03:02,000 --> 00:03:04,000
+because it's just going to stay in the marketplace.
+
+53
+00:03:04,000 --> 00:03:08,000
+So for example, when implementing a new system or releasing a new product.
+
+54
+00:03:08,000 --> 00:03:13,000
+Now this is one thing we got to keep in mind is that risk assessment is continuous.
+
+55
+00:03:13,000 --> 00:03:15,000
+It's never something you stop.
+
+56
+00:03:15,000 --> 00:03:17,000
+You continuously do it over and over.
+
+57
+00:03:17,000 --> 00:03:18,000
+Why?
+
+58
+00:03:18,000 --> 00:03:21,000
+Because the world changes and there's new risk every day.
+
+59
+00:03:21,000 --> 00:03:25,000
+Every single day you wake up, there's a new risk that can take your life away.
+
+60
+00:03:25,000 --> 00:03:28,000
+There's a new risk that can bring your company down.
+
+61
+00:03:28,000 --> 00:03:31,000
+So we have to consistently keep doing risk assessment.
+
+62
+00:03:31,000 --> 00:03:35,000
+So remember the first step in that assessment is going to be identifying those risks.
+
+63
+00:03:35,000 --> 00:03:40,000
+Then we have to analyze those risks which will take a look at in the next video.
+
+64
+00:03:41,000 --> 00:03:45,000
+So ongoing monitoring and analysis and analysis of risks.
+
+65
+00:03:45,000 --> 00:03:46,000
+This approach.
+
+66
+00:03:46,000 --> 00:03:49,000
+This approach will use real time data and automated tools.
+
+67
+00:03:49,000 --> 00:03:52,000
+Continuous assessment are becoming increasingly important.
+
+68
+00:03:52,000 --> 00:03:52,000
+Why?
+
+69
+00:03:52,000 --> 00:03:53,000
+Because.
+
+70
+00:03:54,000 --> 00:03:54,000
+It.
+
+71
+00:03:54,000 --> 00:03:56,000
+Security is dynamic.
+
+72
+00:03:56,000 --> 00:03:56,000
+All right.
+
+73
+00:03:56,000 --> 00:03:58,000
+What we do in this world is dynamic.
+
+74
+00:03:58,000 --> 00:03:59,000
+Everything changes.
+
+75
+00:03:59,000 --> 00:04:06,000
+New threats, new technology, new management, new people, new laws, new governments on a consistent
+
+76
+00:04:06,000 --> 00:04:07,000
+basis.
+
+77
+00:04:07,000 --> 00:04:09,000
+The world is not static.
+
+78
+00:04:09,000 --> 00:04:12,000
+So your assessment can't be static.
+
+79
+00:04:12,000 --> 00:04:13,000
+All right, keep that in mind.
+
+80
+00:04:14,000 --> 00:04:18,000
+Keep that in mind that you're going to be doing risk assessment on a continuous basis.
+
+81
+00:04:18,000 --> 00:04:22,000
+There are times when you might do a one time assessment for a particular launch of a new product.
+
+82
+00:04:22,000 --> 00:04:27,000
+Keep in mind that it's continuous and it probably should be done every quarterly in my opinion, or
+
+83
+00:04:27,000 --> 00:04:30,000
+monthly, but at least do it every yearly.
+
+84
+00:04:31,000 --> 00:04:32,000
+Uh, you know why?
+
+85
+00:04:32,000 --> 00:04:35,000
+Because risk is something that changes all the time.
+
diff --git a/21 - Risk Management/003 Quantitative and Qualitive Risk Assessment OB 5.2_en.srt b/21 - Risk Management/003 Quantitative and Qualitive Risk Assessment OB 5.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..aabc205fdf5a21bf437e2c6b5da4d4dc851d8d7c
--- /dev/null
+++ b/21 - Risk Management/003 Quantitative and Qualitive Risk Assessment OB 5.2_en.srt
@@ -0,0 +1,784 @@
+1
+00:00:00,000 --> 00:00:05,000
+When you conduct a risk assessment, you're either going to be doing what's called a quantitative assessment
+
+2
+00:00:05,000 --> 00:00:07,000
+or a qualitative assessment.
+
+3
+00:00:07,000 --> 00:00:13,000
+Quantitative assessment is when you numerically analyze risk and you run a series of formulas for that
+
+4
+00:00:13,000 --> 00:00:18,000
+versus quantitative assessment is a more subjective kind of a risk assessment, in which case you're
+
+5
+00:00:18,000 --> 00:00:23,000
+going to be using things such as high, medium, low or verbally describing risks.
+
+6
+00:00:23,000 --> 00:00:30,000
+So quantitative assessment is when you're going to use numbers, actual hard numbers in order to do
+
+7
+00:00:30,000 --> 00:00:32,000
+your risk assessment.
+
+8
+00:00:32,000 --> 00:00:33,000
+Let me give you an example.
+
+9
+00:00:33,000 --> 00:00:37,000
+In the world of risk assessment, an earthquake in New York City, what's the probability?
+
+10
+00:00:37,000 --> 00:00:43,000
+Well, for quantitative, you might say the probability of an earthquake or a major earthquake in New
+
+11
+00:00:43,000 --> 00:00:49,000
+York City is low versus in a quantitative assessment, you're going to say, well, it's a 1% every
+
+12
+00:00:49,000 --> 00:00:50,000
+year.
+
+13
+00:00:50,000 --> 00:00:54,000
+If you actually look it up, it's actually one out of a one out of 100 chance.
+
+14
+00:00:54,000 --> 00:00:56,000
+You get an earthquake every year.
+
+15
+00:00:56,000 --> 00:00:57,000
+Major earthquake in New York City.
+
+16
+00:00:57,000 --> 00:01:01,000
+If you say, well, what's the impact of a major earthquake in New York City?
+
+17
+00:01:01,000 --> 00:01:06,000
+Qualitative assessment is going to say something like, well, it's a high impact versus quantitative
+
+18
+00:01:06,000 --> 00:01:12,000
+assessment is going to be, well, it's going to cost $50 billion in damages.
+
+19
+00:01:12,000 --> 00:01:15,000
+You notice one is more objective based.
+
+20
+00:01:15,000 --> 00:01:20,000
+That's going to be the quantitative assessment versus one is very subjective based.
+
+21
+00:01:20,000 --> 00:01:22,000
+That's going to be the qualitative assessment.
+
+22
+00:01:22,000 --> 00:01:27,000
+One needs massive amounts of data and computation and calculations.
+
+23
+00:01:27,000 --> 00:01:30,000
+That's going to be quantitative assessment because of the numbers.
+
+24
+00:01:30,000 --> 00:01:33,000
+You're going to have to go and grab data from all kinds of sources.
+
+25
+00:01:33,000 --> 00:01:41,000
+And that makes it very, very objective versus something where we just use people's opinion and their
+
+26
+00:01:41,000 --> 00:01:41,000
+experience.
+
+27
+00:01:41,000 --> 00:01:45,000
+That's going to be more subjective, like qualitative assessment.
+
+28
+00:01:45,000 --> 00:01:50,000
+Now, I do recommend to watch this video twice because when it comes to quantitative assessment, there's
+
+29
+00:01:50,000 --> 00:01:53,000
+a series of formulas that you're going to need to know for your exam.
+
+30
+00:01:53,000 --> 00:01:54,000
+So let's take a look.
+
+31
+00:01:54,000 --> 00:01:57,000
+So here is a series of formulas.
+
+32
+00:01:57,000 --> 00:02:03,000
+And it's basically only two formulas Excel and Ali I'll come to this one value to safeguard coming up
+
+33
+00:02:03,000 --> 00:02:03,000
+later.
+
+34
+00:02:04,000 --> 00:02:11,000
+But I want to point out something before I get started with this, uh, asset value exposure factor.
+
+35
+00:02:11,000 --> 00:02:16,000
+An annual rate of occurrence of the Aro are not numbers that you can calculate.
+
+36
+00:02:16,000 --> 00:02:19,000
+This has to be given to you in a question.
+
+37
+00:02:19,000 --> 00:02:23,000
+And then you can calculate the SL and the Ala.
+
+38
+00:02:24,000 --> 00:02:24,000
+All right.
+
+39
+00:02:24,000 --> 00:02:25,000
+So keep that in mind.
+
+40
+00:02:26,000 --> 00:02:27,000
+Okay.
+
+41
+00:02:27,000 --> 00:02:28,000
+So let's go through this.
+
+42
+00:02:28,000 --> 00:02:30,000
+I'm going to come up with a scenario.
+
+43
+00:02:30,000 --> 00:02:32,000
+Now don't worry too much about the numbers in this scenario.
+
+44
+00:02:32,000 --> 00:02:36,000
+All I need you to do is to be able to calculate the formulas for your exam.
+
+45
+00:02:36,000 --> 00:02:37,000
+So let's get started.
+
+46
+00:02:37,000 --> 00:02:42,000
+So remember quantitative analysis is all about numerical analysis.
+
+47
+00:02:42,000 --> 00:02:44,000
+It's all about numerically analyzing risk.
+
+48
+00:02:44,000 --> 00:02:47,000
+It's about putting a dollar value on the risk.
+
+49
+00:02:47,000 --> 00:02:48,000
+So let's get started.
+
+50
+00:02:48,000 --> 00:02:52,000
+So let's say you have an asset and that asset has to have a value.
+
+51
+00:02:52,000 --> 00:02:56,000
+So your first thing you have to do in risk assessment is you have to know the value of the asset.
+
+52
+00:02:56,000 --> 00:02:58,000
+Let's say the asset is data.
+
+53
+00:02:58,000 --> 00:03:03,000
+And your data is worth, uh, $1 million.
+
+54
+00:03:03,000 --> 00:03:04,000
+All right.
+
+55
+00:03:04,000 --> 00:03:05,000
+So $1 million.
+
+56
+00:03:06,000 --> 00:03:06,000
+All right.
+
+57
+00:03:06,000 --> 00:03:08,000
+Don't ask me where I get the number from.
+
+58
+00:03:08,000 --> 00:03:10,000
+Remember, this number has to be given to you on the exam.
+
+59
+00:03:10,000 --> 00:03:12,000
+You can't make it up.
+
+60
+00:03:12,000 --> 00:03:14,000
+So it's it's $1 million asset.
+
+61
+00:03:14,000 --> 00:03:16,000
+Now the exposure factor.
+
+62
+00:03:16,000 --> 00:03:17,000
+Notice terme.
+
+63
+00:03:17,000 --> 00:03:24,000
+The exposure factor is a percentage of loss that an organization would experience if a specific asset
+
+64
+00:03:24,000 --> 00:03:26,000
+were violated by a risk.
+
+65
+00:03:26,000 --> 00:03:28,000
+So it's a percentage.
+
+66
+00:03:28,000 --> 00:03:32,000
+If I come in here and I put 100%.
+
+67
+00:03:33,000 --> 00:03:41,000
+What that means is that if this risk, know, the risk we're talking about is malware to data.
+
+68
+00:03:41,000 --> 00:03:43,000
+So malware infecting data is the risk.
+
+69
+00:03:43,000 --> 00:03:51,000
+So if the malware infects your data, how much of or percentage of the data would be lost?
+
+70
+00:03:51,000 --> 00:03:53,000
+I'm saying it's 100%.
+
+71
+00:03:53,000 --> 00:03:57,000
+In other words, if you get infected with malware, all your data is gone.
+
+72
+00:03:57,000 --> 00:04:01,000
+This exposure factor can change though.
+
+73
+00:04:01,000 --> 00:04:08,000
+For example, if you had a data center that's worth or a build and worth $1 million and a category five
+
+74
+00:04:08,000 --> 00:04:16,000
+hurricane would destroy 50% of it, so then a 50% loss so your exposure factor wouldn't be 150%.
+
+75
+00:04:16,000 --> 00:04:18,000
+And then how much of the building would you lose?
+
+76
+00:04:18,000 --> 00:04:23,000
+Well, if it's worth $1 million and you and you're going to lose 50%, then it's worth 500,000.
+
+77
+00:04:23,000 --> 00:04:24,000
+And that's called the SLA.
+
+78
+00:04:25,000 --> 00:04:32,000
+The SLA is the cost associated with every single realized risk against an asset.
+
+79
+00:04:32,000 --> 00:04:41,000
+So the SLA is equal to the asset value, which we have is 1 million times the actual 100%.
+
+80
+00:04:41,000 --> 00:04:48,000
+So if we know 1 million times, 100% is basically 100% is one, so it would be equal to 1 million.
+
+81
+00:04:48,000 --> 00:04:56,000
+We're saying is that every single, every single time you get hit with malware, you're going to lose
+
+82
+00:04:56,000 --> 00:04:57,000
+$1 million.
+
+83
+00:04:57,000 --> 00:05:04,000
+You're going to lose all your data versus if you had a build in that was worth a million and a hurricane
+
+84
+00:05:04,000 --> 00:05:07,000
+is going to destroy 50%, it'll be 500 for you.
+
+85
+00:05:07,000 --> 00:05:13,000
+Now, the next thing is, how often is this going to happen, right?
+
+86
+00:05:13,000 --> 00:05:20,000
+How many times every single year are you going to get hit with a particular virus?
+
+87
+00:05:20,000 --> 00:05:25,000
+Now, technically, you should do this before the virus protection is implemented.
+
+88
+00:05:25,000 --> 00:05:28,000
+And after, let's say you have no virus protection.
+
+89
+00:05:28,000 --> 00:05:35,000
+Let's say you don't have any antivirus, no user training, anti-malware, firewall, nothing.
+
+90
+00:05:35,000 --> 00:05:37,000
+You don't have anything.
+
+91
+00:05:37,000 --> 00:05:39,000
+How many times a year are you going to get a virus?
+
+92
+00:05:40,000 --> 00:05:45,000
+Let's say you get a virus at least once a week, 50 times a year.
+
+93
+00:05:45,000 --> 00:05:45,000
+All right.
+
+94
+00:05:45,000 --> 00:05:47,000
+Because you don't have any protection you're going to get.
+
+95
+00:05:47,000 --> 00:05:49,000
+At least I'm going to go with a minimum.
+
+96
+00:05:49,000 --> 00:05:50,000
+I'm going to say 50.
+
+97
+00:05:50,000 --> 00:05:54,000
+You guys are probably saying, well, it's like every day, let's just go with 50 for now.
+
+98
+00:05:54,000 --> 00:05:54,000
+Okay.
+
+99
+00:05:54,000 --> 00:06:00,000
+So we're saying that, hey, you're going to get at least 50 infection a year.
+
+100
+00:06:00,000 --> 00:06:02,000
+So how much are you going to lose every year.
+
+101
+00:06:02,000 --> 00:06:04,000
+Well that's the annualized loss expectancy.
+
+102
+00:06:04,000 --> 00:06:12,000
+This is a formula is equal to the SLA which is 1 million times the R0.
+
+103
+00:06:12,000 --> 00:06:14,000
+So the R0 is 50 right.
+
+104
+00:06:14,000 --> 00:06:15,000
+So 1 million times 50.
+
+105
+00:06:16,000 --> 00:06:18,000
+This is $50 million.
+
+106
+00:06:18,000 --> 00:06:22,000
+So we know that we're going to lose 50 million every year.
+
+107
+00:06:22,000 --> 00:06:28,000
+Another way to calculate the SLA is basically you know SLA is equal to AV times F.
+
+108
+00:06:28,000 --> 00:06:33,000
+So they're just uh uh, spelling that out for you.
+
+109
+00:06:33,000 --> 00:06:38,000
+You can say AV times F times R0, but the real form is SLA, times R0 gives you the same thing.
+
+110
+00:06:38,000 --> 00:06:39,000
+So it's $50 million.
+
+111
+00:06:39,000 --> 00:06:41,000
+What is this number mean.
+
+112
+00:06:41,000 --> 00:06:51,000
+Well that $50 million means that every single year you're going to lose $50 million, right?
+
+113
+00:06:52,000 --> 00:06:54,000
+You're going to lose 50 million bucks.
+
+114
+00:06:54,000 --> 00:06:55,000
+Why?
+
+115
+00:06:55,000 --> 00:06:57,000
+Because you have no anti-virus protection.
+
+116
+00:06:57,000 --> 00:07:00,000
+Now, this are the formulas.
+
+117
+00:07:00,000 --> 00:07:01,000
+So the asset.
+
+118
+00:07:01,000 --> 00:07:02,000
+Let's do a quick review.
+
+119
+00:07:02,000 --> 00:07:04,000
+The asset value is a number that's given to you.
+
+120
+00:07:04,000 --> 00:07:05,000
+You can't calculate it.
+
+121
+00:07:05,000 --> 00:07:12,000
+So whatever the asset is worth to the business the exposure factor is a percentage of loss when or and
+
+122
+00:07:12,000 --> 00:07:17,000
+when if a risk materializes, how much of the asset is lost in percentage.
+
+123
+00:07:17,000 --> 00:07:23,000
+Single loss expectancy is the asset value times the exposure factor.
+
+124
+00:07:23,000 --> 00:07:26,000
+Then how many times a year would a potential thing occur?
+
+125
+00:07:26,000 --> 00:07:28,000
+That's going to be the R0.
+
+126
+00:07:28,000 --> 00:07:30,000
+So in our ones we have 50.
+
+127
+00:07:30,000 --> 00:07:33,000
+Then the annualized loss expectancy is the asset times the R0.
+
+128
+00:07:34,000 --> 00:07:38,000
+Now I have something at the bottom the annual cost of the safeguard.
+
+129
+00:07:38,000 --> 00:07:40,000
+We have to calculate.
+
+130
+00:07:40,000 --> 00:07:45,000
+Well you go to management and you tell management well we're going to lose $50 million a year.
+
+131
+00:07:45,000 --> 00:07:47,000
+And management says, oh that's a lot of money.
+
+132
+00:07:47,000 --> 00:07:53,000
+Okay, let's go and spend some money and protect our protect those data.
+
+133
+00:07:53,000 --> 00:07:59,000
+So management we come out and we need antivirus user training and firewall.
+
+134
+00:07:59,000 --> 00:08:03,000
+So the annual cost of the safeguard is not a number you can calculate.
+
+135
+00:08:03,000 --> 00:08:05,000
+This is going to be let's say 10 million.
+
+136
+00:08:05,000 --> 00:08:08,000
+So 10 million.
+
+137
+00:08:08,000 --> 00:08:16,000
+Now, when you get the actual, uh, value of the safeguard, now you can recalculate your ale.
+
+138
+00:08:16,000 --> 00:08:19,000
+You see, if you recalculate.
+
+139
+00:08:19,000 --> 00:08:24,000
+Remember when we did this, we said we had no protection in place.
+
+140
+00:08:24,000 --> 00:08:28,000
+Remember that with no protection, you're getting 50 infections.
+
+141
+00:08:28,000 --> 00:08:30,000
+Now, what happens if you do protection?
+
+142
+00:08:30,000 --> 00:08:30,000
+Well.
+
+143
+00:08:31,000 --> 00:08:35,000
+Let's recalculate all these numbers because now we have a protection.
+
+144
+00:08:35,000 --> 00:08:37,000
+Now we have antivirus user training.
+
+145
+00:08:37,000 --> 00:08:38,000
+Now what is it going to be.
+
+146
+00:08:38,000 --> 00:08:42,000
+Well by putting an antivirus doesn't change the value of the data does it.
+
+147
+00:08:42,000 --> 00:08:45,000
+It's still a million bucks if you get infected.
+
+148
+00:08:45,000 --> 00:08:50,000
+Even if you have antivirus and you get infected and it bypasses your antivirus, you're still going
+
+149
+00:08:50,000 --> 00:08:51,000
+to lose 100%.
+
+150
+00:08:52,000 --> 00:08:58,000
+So in this one, I'm going to leave the cell as 1 million because it's AV 1 million.
+
+151
+00:08:59,000 --> 00:09:02,000
+Times the single loss expectancy of 100.
+
+152
+00:09:02,000 --> 00:09:07,000
+So it's going to be there's 100% 1 million.
+
+153
+00:09:07,000 --> 00:09:09,000
+Now here's the thing.
+
+154
+00:09:09,000 --> 00:09:13,000
+By implementing all the how many infections are you going to have a year that's going to take out all
+
+155
+00:09:13,000 --> 00:09:14,000
+the data.
+
+156
+00:09:14,000 --> 00:09:19,000
+Let's say you bring that number down to, let's say, two infections a year.
+
+157
+00:09:19,000 --> 00:09:25,000
+That means that your L is equal to 1 million times two.
+
+158
+00:09:25,000 --> 00:09:29,000
+So you only losing $2 million every single year.
+
+159
+00:09:30,000 --> 00:09:34,000
+So by you implementing the safeguard, what is it worth to you?
+
+160
+00:09:35,000 --> 00:09:35,000
+Right.
+
+161
+00:09:35,000 --> 00:09:38,000
+What is what is the value the organization is getting out of this.
+
+162
+00:09:38,000 --> 00:09:39,000
+And that's this last number.
+
+163
+00:09:40,000 --> 00:09:44,000
+So the value is equal to the al before the safeguard we know is 50 million.
+
+164
+00:09:45,000 --> 00:09:48,000
+After minus the L after the safeguard.
+
+165
+00:09:48,000 --> 00:09:50,000
+So we know we're losing 2 million.
+
+166
+00:09:50,000 --> 00:09:52,000
+Even though you put in a safeguard guide, you're still losing 2 million.
+
+167
+00:09:52,000 --> 00:09:54,000
+So -2 million.
+
+168
+00:09:54,000 --> 00:09:57,000
+And then the actual cost of the safeguard is 10 million.
+
+169
+00:09:58,000 --> 00:10:01,000
+So let's do 50 minus two is 48.
+
+170
+00:10:01,000 --> 00:10:04,000
+Minus ten is 38 million.
+
+171
+00:10:05,000 --> 00:10:07,000
+This is what the organization is gaining.
+
+172
+00:10:07,000 --> 00:10:14,000
+This is like their value that they're gaining because of the antivirus protection or the malware protection.
+
+173
+00:10:14,000 --> 00:10:16,000
+You see guys, that's what you need.
+
+174
+00:10:16,000 --> 00:10:17,000
+Antivirus.
+
+175
+00:10:17,000 --> 00:10:18,000
+Okay.
+
+176
+00:10:18,000 --> 00:10:20,000
+Replay this video a couple of times.
+
+177
+00:10:20,000 --> 00:10:22,000
+Make sure you really understand these formulas.
+
+178
+00:10:22,000 --> 00:10:27,000
+Now the last thing I want to mention uh is going to be uh qualitative assessment.
+
+179
+00:10:27,000 --> 00:10:34,000
+So qualitative assessment is assessing risk based on subjective criteria such as expert opinions uh
+
+180
+00:10:34,000 --> 00:10:39,000
+scenario analysis and generally all kinds of industry best practices.
+
+181
+00:10:39,000 --> 00:10:41,000
+It'll categorize risk into high, medium or low.
+
+182
+00:10:42,000 --> 00:10:44,000
+It just it does not use numbers.
+
+183
+00:10:44,000 --> 00:10:49,000
+You see in order to do this you got to go out and you got to grab numbers, man.
+
+184
+00:10:49,000 --> 00:10:51,000
+You got to go and do all the research.
+
+185
+00:10:51,000 --> 00:10:57,000
+For example, when I told you guys that there is a 1% chance of getting an earthquake in New York City,
+
+186
+00:10:57,000 --> 00:10:58,000
+that is an actual number.
+
+187
+00:10:58,000 --> 00:11:02,000
+I had to research that for a project that was working on a while back.
+
+188
+00:11:02,000 --> 00:11:07,000
+Now, this approach is useful for understanding the general magnitude of risks.
+
+189
+00:11:07,000 --> 00:11:12,000
+So keep in mind qualitative analysis is very subjective.
+
+190
+00:11:12,000 --> 00:11:13,000
+All right.
+
+191
+00:11:13,000 --> 00:11:15,000
+It's done by people's opinion.
+
+192
+00:11:15,000 --> 00:11:18,000
+It uses rankings such as high, medium or low.
+
+193
+00:11:18,000 --> 00:11:22,000
+It's quick and it's easy to do and it doesn't require a ton of data.
+
+194
+00:11:23,000 --> 00:11:28,000
+Quantitative assessment is more objective, requires a ton of data, takes a lot of time.
+
+195
+00:11:28,000 --> 00:11:32,000
+And of course it's going to be more expensive because it does require a lot more time.
+
+196
+00:11:32,000 --> 00:11:35,000
+So keep that in mind when taking your exam.
+
diff --git a/21 - Risk Management/004 Risk Register OB 5.2_en.srt b/21 - Risk Management/004 Risk Register OB 5.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..29d65a7668caf2c4444c551d4cba4dad8f4a0de8
--- /dev/null
+++ b/21 - Risk Management/004 Risk Register OB 5.2_en.srt
@@ -0,0 +1,424 @@
+1
+00:00:00,000 --> 00:00:05,000
+When you do your risk assessment, such as your qualitative and quantitative, and you identify your
+
+2
+00:00:05,000 --> 00:00:07,000
+risks, you have to store this somewhere.
+
+3
+00:00:07,000 --> 00:00:09,000
+You have to store this in a particular document.
+
+4
+00:00:09,000 --> 00:00:11,000
+We're going to call the risk register.
+
+5
+00:00:11,000 --> 00:00:17,000
+So the risk register is basically a component of good risk management because it serves as the central
+
+6
+00:00:17,000 --> 00:00:21,000
+repository for all the risk in it.
+
+7
+00:00:21,000 --> 00:00:23,000
+Now I do have a sample of it here.
+
+8
+00:00:23,000 --> 00:00:26,000
+Every risk register can be different in every organization.
+
+9
+00:00:26,000 --> 00:00:30,000
+This is a sample that I got from a risk register template here on this website.
+
+10
+00:00:30,000 --> 00:00:33,000
+At a minimum it's going to have the identified risks.
+
+11
+00:00:33,000 --> 00:00:39,000
+The assessments on them, such as the description and the potential actions that we want to take against
+
+12
+00:00:39,000 --> 00:00:39,000
+them.
+
+13
+00:00:39,000 --> 00:00:44,000
+Notice in this risk register I know it's hard to see, but you can expand it on the you know, when
+
+14
+00:00:44,000 --> 00:00:45,000
+you see the slide, it'll be easier.
+
+15
+00:00:45,000 --> 00:00:50,000
+Uh the description notice they have an impact description, the level, how it's going to impact.
+
+16
+00:00:50,000 --> 00:00:51,000
+It's a high medium or low.
+
+17
+00:00:51,000 --> 00:00:53,000
+Um, they have a priority.
+
+18
+00:00:53,000 --> 00:00:56,000
+They also have a mitigation note like what are we going to do to reduce this risk.
+
+19
+00:00:56,000 --> 00:01:00,000
+So at a minimum, a risk register should have a description of the risk.
+
+20
+00:01:00,000 --> 00:01:03,000
+Like what exactly is the risk in the world of it.
+
+21
+00:01:04,000 --> 00:01:06,000
+We can have ransomware.
+
+22
+00:01:06,000 --> 00:01:07,000
+That's a risk.
+
+23
+00:01:07,000 --> 00:01:08,000
+What's the description of it.
+
+24
+00:01:08,000 --> 00:01:13,000
+Well ransomware can encrypt the data and then hold us hostage by making us want to pay to get the data
+
+25
+00:01:13,000 --> 00:01:14,000
+back.
+
+26
+00:01:14,000 --> 00:01:21,000
+So we want a nice detail risk register with a nice detailed description of each individual risk.
+
+27
+00:01:21,000 --> 00:01:26,000
+If you have a risk with hurricane floods, power outages describe how you know how is that going to
+
+28
+00:01:26,000 --> 00:01:28,000
+affect the actual business.
+
+29
+00:01:28,000 --> 00:01:33,000
+So describe the risks, the assets that are affected, the consequences.
+
+30
+00:01:33,000 --> 00:01:38,000
+For example, if there's a power outage at a major data center, you can see that this can bring the
+
+31
+00:01:38,000 --> 00:01:41,000
+data center down for extended periods of time, causing the organization a lot of money.
+
+32
+00:01:43,000 --> 00:01:49,000
+Another thing here you're going to want to have on your risk register is what's called your Chris or
+
+33
+00:01:49,000 --> 00:01:51,000
+your key risk indicators.
+
+34
+00:01:51,000 --> 00:01:56,000
+These are metrics you're going to use to measure and monitor the likelihood and impact of a risk.
+
+35
+00:01:56,000 --> 00:02:00,000
+They provide early warnings that a risk may be increasing or decreasing.
+
+36
+00:02:00,000 --> 00:02:05,000
+For example, in a high number of failed login this may be a cry for unauthorized access.
+
+37
+00:02:05,000 --> 00:02:07,000
+So think about this.
+
+38
+00:02:07,000 --> 00:02:15,000
+At what point do you look at and say, well, this risk is most likely to happen, right?
+
+39
+00:02:15,000 --> 00:02:16,000
+Like what's that?
+
+40
+00:02:16,000 --> 00:02:18,000
+What's that number?
+
+41
+00:02:18,000 --> 00:02:24,000
+Like, what does that look like to you when you say, well, okay, this is risk is probably going to
+
+42
+00:02:24,000 --> 00:02:24,000
+take place.
+
+43
+00:02:24,000 --> 00:02:26,000
+For example, like they're saying here.
+
+44
+00:02:26,000 --> 00:02:31,000
+Well there's going to be a high this ten failed logins.
+
+45
+00:02:31,000 --> 00:02:33,000
+Is that is that a good number for you.
+
+46
+00:02:33,000 --> 00:02:34,000
+But you see ten fail.
+
+47
+00:02:34,000 --> 00:02:35,000
+Log on from that.
+
+48
+00:02:35,000 --> 00:02:37,000
+Users did this user account is under attack.
+
+49
+00:02:37,000 --> 00:02:40,000
+The risk is starting to materialize itself.
+
+50
+00:02:41,000 --> 00:02:48,000
+So you have to come up with KPIs that can give you basically early warning signs that a risk is happening.
+
+51
+00:02:48,000 --> 00:02:57,000
+Another example, let's say a system has generated, uh, ten different error that the operating system
+
+52
+00:02:57,000 --> 00:03:00,000
+is getting corrupted or the operating system stopped responding.
+
+53
+00:03:00,000 --> 00:03:06,000
+How many of those errors do you need to see before you go in and say, okay, let's reinstall the operating
+
+54
+00:03:06,000 --> 00:03:09,000
+system before the whole thing crashes and produces a massive failure.
+
+55
+00:03:09,000 --> 00:03:11,000
+You need to come up with those numbers.
+
+56
+00:03:11,000 --> 00:03:12,000
+Every organization is different.
+
+57
+00:03:13,000 --> 00:03:15,000
+You want to assign a risk owner.
+
+58
+00:03:15,000 --> 00:03:19,000
+A risk owner is someone who's held responsible for managing and mitigating that risk.
+
+59
+00:03:19,000 --> 00:03:23,000
+So you can go through the risk register and say, well, this risk is owned by this person.
+
+60
+00:03:23,000 --> 00:03:28,000
+That way this person takes ownership of it and build a team to help secure against this risk.
+
+61
+00:03:28,000 --> 00:03:33,000
+Now there's generally someone who's going to be in a manager owner management role and has the authority
+
+62
+00:03:33,000 --> 00:03:37,000
+and knowledge to come up with the right responses now.
+
+63
+00:03:38,000 --> 00:03:42,000
+What exactly is the threshold for the level of action?
+
+64
+00:03:42,000 --> 00:03:42,000
+All right.
+
+65
+00:03:42,000 --> 00:03:47,000
+Threshold refers to the level of risk that the organization is willing to accept.
+
+66
+00:03:47,000 --> 00:03:51,000
+Risks that fall below the threshold is probably you're just going to watch it.
+
+67
+00:03:51,000 --> 00:03:52,000
+You're going to accept it.
+
+68
+00:03:52,000 --> 00:03:53,000
+You're going to monitor it.
+
+69
+00:03:53,000 --> 00:03:59,000
+Anything above it will require an activation notice will require activation of mitigation.
+
+70
+00:03:59,000 --> 00:04:02,000
+So let's say you're watching the operating system.
+
+71
+00:04:02,000 --> 00:04:03,000
+You're watching the operating.
+
+72
+00:04:03,000 --> 00:04:08,000
+You're seeing that the hard drive is getting filled very quickly because it's a backup machine.
+
+73
+00:04:09,000 --> 00:04:11,000
+What is the threshold that we increase the storage.
+
+74
+00:04:11,000 --> 00:04:13,000
+We're going to run out of storage.
+
+75
+00:04:13,000 --> 00:04:15,000
+Is it when it's 80% filled?
+
+76
+00:04:15,000 --> 00:04:16,000
+Is it when it's 90% filled.
+
+77
+00:04:16,000 --> 00:04:19,000
+That's something you have to determine.
+
+78
+00:04:19,000 --> 00:04:20,000
+So that's the risk threshold.
+
+79
+00:04:20,000 --> 00:04:21,000
+All right.
+
+80
+00:04:21,000 --> 00:04:25,000
+Don't forget guys make sure you understand what exactly is a risk register.
+
+81
+00:04:25,000 --> 00:04:29,000
+A risk register is a document that you're going to put all your risk on.
+
+82
+00:04:29,000 --> 00:04:30,000
+You're going to describe them.
+
+83
+00:04:30,000 --> 00:04:34,000
+You're going to have risk owners risk thresholds you're going to put on there.
+
+84
+00:04:35,000 --> 00:04:36,000
+And now risk indicators.
+
+85
+00:04:36,000 --> 00:04:40,000
+Also you're going to have if you're wondering, hey Andrew, what's in between that indicator and the
+
+86
+00:04:40,000 --> 00:04:41,000
+threshold?
+
+87
+00:04:41,000 --> 00:04:45,000
+Well, remember indicator is the early warning sign that the risk is happening.
+
+88
+00:04:45,000 --> 00:04:46,000
+The risk threshold is okay.
+
+89
+00:04:46,000 --> 00:04:47,000
+It crossed this.
+
+90
+00:04:47,000 --> 00:04:48,000
+It needs to be fixed.
+
+91
+00:04:48,000 --> 00:04:50,000
+Remember indicators are early warning signs.
+
+92
+00:04:50,000 --> 00:04:53,000
+For example, if you go back to the server backup.
+
+93
+00:04:53,000 --> 00:05:00,000
+Well, if the server backups start to exceed, let's say the maximum, you're willing to lose 80%.
+
+94
+00:05:00,000 --> 00:05:06,000
+If the backup drives are more than 80% filled, you've got to up the storage before you run out of space
+
+95
+00:05:06,000 --> 00:05:08,000
+and then the risk of no backup.
+
+96
+00:05:08,000 --> 00:05:12,000
+So the risk indicators like 70% okay, it's an early warning sign.
+
+97
+00:05:12,000 --> 00:05:12,000
+Okay.
+
+98
+00:05:12,000 --> 00:05:14,000
+This risk is probably going to happen.
+
+99
+00:05:14,000 --> 00:05:16,000
+So you start looking at it looking at it.
+
+100
+00:05:16,000 --> 00:05:19,000
+And then now you have the threshold okay.
+
+101
+00:05:19,000 --> 00:05:20,000
+Now we crossed with 81%.
+
+102
+00:05:20,000 --> 00:05:21,000
+Boom.
+
+103
+00:05:21,000 --> 00:05:25,000
+Implement the mitigation strategy of up in the drive space.
+
+104
+00:05:25,000 --> 00:05:25,000
+All right.
+
+105
+00:05:25,000 --> 00:05:26,000
+Make sure you know these terms.
+
+106
+00:05:26,000 --> 00:05:29,000
+More than likely you'll see some of them on your test.
+
diff --git a/21 - Risk Management/005 Risk Appetite OB 5.2_en.srt b/21 - Risk Management/005 Risk Appetite OB 5.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..dca29f9ae03e708a1e5985b215d1396371fa35f3
--- /dev/null
+++ b/21 - Risk Management/005 Risk Appetite OB 5.2_en.srt
@@ -0,0 +1,324 @@
+1
+00:00:00,000 --> 00:00:04,000
+In order to do something in life, you have to be willing to take risks.
+
+2
+00:00:04,000 --> 00:00:11,000
+You see, every thing that we do in life, every action that we take in life has risks.
+
+3
+00:00:11,000 --> 00:00:14,000
+There is a risk of me standing here.
+
+4
+00:00:14,000 --> 00:00:17,000
+I mean, the ceiling can fall on top of me, the desk can fall over.
+
+5
+00:00:17,000 --> 00:00:19,000
+There's all kinds of risks that can happen.
+
+6
+00:00:19,000 --> 00:00:20,000
+Now.
+
+7
+00:00:20,000 --> 00:00:25,000
+I have to be willing to take a certain number of risks in order to do a particular task.
+
+8
+00:00:25,000 --> 00:00:30,000
+For example, if you go out and you drive to go to the supermarket, one of the most dangerous things
+
+9
+00:00:30,000 --> 00:00:32,000
+a human can ever do is drive.
+
+10
+00:00:32,000 --> 00:00:35,000
+You have to be willing to take those risks.
+
+11
+00:00:35,000 --> 00:00:39,000
+The risk of getting into a car accident or the risk of death in a car accident.
+
+12
+00:00:39,000 --> 00:00:42,000
+Now, this brings me to a particular terme that we want to be familiar with.
+
+13
+00:00:42,000 --> 00:00:44,000
+It's called the risk appetite.
+
+14
+00:00:44,000 --> 00:00:50,000
+This refers to the risk that an organization is prepared to pursue, retain, or take in its operation.
+
+15
+00:00:50,000 --> 00:00:55,000
+So what kind of risk is the organization willing to take?
+
+16
+00:00:55,000 --> 00:00:55,000
+Now?
+
+17
+00:00:56,000 --> 00:01:01,000
+The organization is going to have to know the risk that they're willing to take in order to do, to
+
+18
+00:01:01,000 --> 00:01:04,000
+build a particular product or a particular service.
+
+19
+00:01:04,000 --> 00:01:10,000
+In fact, in businesses today, it's all about risk because they're willing to spend money to create
+
+20
+00:01:10,000 --> 00:01:15,000
+this product or service, and they don't know if it's going to be sold or not, reflects the organization
+
+21
+00:01:15,000 --> 00:01:17,000
+attitude towards its risk.
+
+22
+00:01:17,000 --> 00:01:21,000
+Now, what's going to influence the risk appetite?
+
+23
+00:01:21,000 --> 00:01:26,000
+So the risk appetite is going to be influenced by its culture, the goals, market conditions and so
+
+24
+00:01:26,000 --> 00:01:26,000
+on.
+
+25
+00:01:26,000 --> 00:01:29,000
+Another time you might see is the risk tolerance.
+
+26
+00:01:29,000 --> 00:01:34,000
+This is the amount of the risk that the organization is willing to take or to withstand.
+
+27
+00:01:34,000 --> 00:01:35,000
+Let me explain.
+
+28
+00:01:35,000 --> 00:01:41,000
+So the risk appetite, well, I'm willing to to take this much.
+
+29
+00:01:41,000 --> 00:01:42,000
+You know, I'm willing to take this risk.
+
+30
+00:01:42,000 --> 00:01:44,000
+But how much of that risk are you willing to take?
+
+31
+00:01:44,000 --> 00:01:47,000
+At what point does that risk becomes too much?
+
+32
+00:01:47,000 --> 00:01:52,000
+You know, one of the best examples of appetite versus tolerance is like speed limit.
+
+33
+00:01:53,000 --> 00:01:59,000
+So a highway can have a speed limit of 60 miles an hour, or let's say 65 miles an hour.
+
+34
+00:01:59,000 --> 00:02:01,000
+So that's the risk.
+
+35
+00:02:01,000 --> 00:02:03,000
+You know, that's the maximum speed.
+
+36
+00:02:03,000 --> 00:02:05,000
+So what is the risk of driving on a highway?
+
+37
+00:02:05,000 --> 00:02:10,000
+Well, you know, crashes are dying of course getting injured and so on.
+
+38
+00:02:10,000 --> 00:02:13,000
+So those are all the risks that's there.
+
+39
+00:02:13,000 --> 00:02:15,000
+Now the tolerance.
+
+40
+00:02:15,000 --> 00:02:15,000
+Well.
+
+41
+00:02:16,000 --> 00:02:19,000
+At what point are you not going to drive that highway?
+
+42
+00:02:19,000 --> 00:02:20,000
+At what point are you going to get pulled over?
+
+43
+00:02:20,000 --> 00:02:25,000
+So, for example, the police on the highway is going to say, well, if they drive at 65, they're
+
+44
+00:02:25,000 --> 00:02:26,000
+okay.
+
+45
+00:02:26,000 --> 00:02:27,000
+If they go up to 70, they're fine.
+
+46
+00:02:27,000 --> 00:02:30,000
+But after 70, we're not willing to take that anymore.
+
+47
+00:02:30,000 --> 00:02:33,000
+Anybody that goes over 70 miles, we're going to stop them.
+
+48
+00:02:33,000 --> 00:02:38,000
+So the amount of risk, like how much of that risk are you actually willing to take?
+
+49
+00:02:38,000 --> 00:02:39,000
+That's the risk tolerance.
+
+50
+00:02:39,000 --> 00:02:41,000
+So you have to know that also.
+
+51
+00:02:41,000 --> 00:02:47,000
+Now when it comes to risk appetite there is expansionary risk appetite.
+
+52
+00:02:47,000 --> 00:02:54,000
+In other words, your risk appetite may be expanding over time to accommodate more risk or higher higher
+
+53
+00:02:54,000 --> 00:02:56,000
+levels of risk in pursuit of a greater reward.
+
+54
+00:02:56,000 --> 00:03:01,000
+Generally, the more risk, the bigger the reward in the world of business, right?
+
+55
+00:03:01,000 --> 00:03:07,000
+Generally, people can pursue things that can give them a great payback, but there's a high risk of
+
+56
+00:03:07,000 --> 00:03:07,000
+failure.
+
+57
+00:03:07,000 --> 00:03:11,000
+For example, purchasing a stock in a brand new company that just started.
+
+58
+00:03:11,000 --> 00:03:13,000
+Yeah, the stock price is cheap.
+
+59
+00:03:13,000 --> 00:03:18,000
+And there's a if the company does well and make a ton of money, think of like investing in Tesla when
+
+60
+00:03:18,000 --> 00:03:19,000
+it first started.
+
+61
+00:03:19,000 --> 00:03:20,000
+So.
+
+62
+00:03:21,000 --> 00:03:27,000
+Companies that does this are often in growth phases, seeking competitive advantage and willing to invest
+
+63
+00:03:27,000 --> 00:03:29,000
+in the opportunity of a higher risk.
+
+64
+00:03:29,000 --> 00:03:31,000
+But remember, these things will carry higher risks.
+
+65
+00:03:31,000 --> 00:03:37,000
+Now, some companies are more conservative towards it and implies a preference for lower risk and focus
+
+66
+00:03:37,000 --> 00:03:39,000
+on more stability.
+
+67
+00:03:39,000 --> 00:03:43,000
+Organizations with a conservative appetite, uh, prioritize.
+
+68
+00:03:43,000 --> 00:03:46,000
+Protect an asset and minimizing potential losses.
+
+69
+00:03:46,000 --> 00:03:50,000
+And then the other one here we have is a neutral risk appetite.
+
+70
+00:03:50,000 --> 00:03:51,000
+They just go with the market.
+
+71
+00:03:51,000 --> 00:03:54,000
+Strikes a balance between the two of them.
+
+72
+00:03:54,000 --> 00:03:59,000
+Organizations with a neutral are willing to accept some level of risk for a reasonable return, but
+
+73
+00:03:59,000 --> 00:04:01,000
+not inclined to pursue high level risks.
+
+74
+00:04:01,000 --> 00:04:04,000
+So if your company is right in the middle, in other words, it's not too conservative.
+
+75
+00:04:04,000 --> 00:04:11,000
+It doesn't take a lot of risk versus your your company takes a ton of risk to get higher rewards.
+
+76
+00:04:11,000 --> 00:04:15,000
+Most of us are probably going to be somewhere here.
+
+77
+00:04:15,000 --> 00:04:16,000
+All right.
+
+78
+00:04:16,000 --> 00:04:21,000
+Just remember, uh, when it comes to risk management, remember what risk appetite is.
+
+79
+00:04:21,000 --> 00:04:25,000
+It's all the risk that you're willing to take on in order to pursue a particular goal.
+
+80
+00:04:25,000 --> 00:04:29,000
+And then how much of that risk can you actually withstand is your risk tolerance?
+
+81
+00:04:29,000 --> 00:04:32,000
+Keep that in mind if you see these terms on your exam.
+
diff --git a/21 - Risk Management/006 Risk Response OB 5.2_en.srt b/21 - Risk Management/006 Risk Response OB 5.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..3eea1daaff69ca7ab48b8568927e86dd071fcb19
--- /dev/null
+++ b/21 - Risk Management/006 Risk Response OB 5.2_en.srt
@@ -0,0 +1,424 @@
+1
+00:00:00,000 --> 00:00:05,000
+When you have identified a risk and know how that risk is going to impact your organization, the next
+
+2
+00:00:05,000 --> 00:00:10,000
+step is going to do is to come up with potential ways to respond to that risk.
+
+3
+00:00:10,000 --> 00:00:15,000
+In this video, I want to go through some of the different ways that organizations can respond to resources.
+
+4
+00:00:15,000 --> 00:00:22,000
+In particularly it's known are the responses are avoidance, mitigate, transfer and accept.
+
+5
+00:00:22,000 --> 00:00:24,000
+So let's go into these here.
+
+6
+00:00:24,000 --> 00:00:28,000
+So the first one up that I want to talk about is going to be risk avoidance.
+
+7
+00:00:28,000 --> 00:00:37,000
+Now risk avoidance involves changing plans or procedures to eliminate the risk or to remove the organization's
+
+8
+00:00:37,000 --> 00:00:38,000
+exposure to it.
+
+9
+00:00:38,000 --> 00:00:40,000
+This means not this.
+
+10
+00:00:40,000 --> 00:00:44,000
+This might mean not implementing a certain system or technology.
+
+11
+00:00:44,000 --> 00:00:51,000
+So avoidance is the process of eliminating completely removing the risk.
+
+12
+00:00:51,000 --> 00:00:52,000
+Let me give you an example.
+
+13
+00:00:53,000 --> 00:00:58,000
+Let's say there is a risk that virus A can infect a windows server.
+
+14
+00:00:58,000 --> 00:01:00,000
+How do you avoid this risk.
+
+15
+00:01:00,000 --> 00:01:02,000
+Well don't use windows right?
+
+16
+00:01:02,000 --> 00:01:03,000
+Use a Linux server.
+
+17
+00:01:03,000 --> 00:01:05,000
+Virus A only infects windows.
+
+18
+00:01:05,000 --> 00:01:11,000
+So you have effectively avoided virus a risk to your organization.
+
+19
+00:01:11,000 --> 00:01:17,000
+So risk avoidance is some kind of action that you're going to take that that results in the risk completely
+
+20
+00:01:17,000 --> 00:01:19,000
+being gone 100% gone.
+
+21
+00:01:20,000 --> 00:01:25,000
+Now the other one that confuses folks with avoidance is mitigation.
+
+22
+00:01:25,000 --> 00:01:31,000
+Now, a lot of times when people say mitigation, they they mean all four of the different responses.
+
+23
+00:01:31,000 --> 00:01:33,000
+But mitigation is a very particular thing.
+
+24
+00:01:33,000 --> 00:01:37,000
+It refers to taking steps to reduce the likelihood or impact of a risk.
+
+25
+00:01:37,000 --> 00:01:42,000
+This is going to be things like implementing security controls, updating your software, user training,
+
+26
+00:01:42,000 --> 00:01:46,000
+monitoring systems, even things such as implementing antivirus.
+
+27
+00:01:46,000 --> 00:01:52,000
+Remember something mitigation doesn't remove the risk 100% like it's completely gone.
+
+28
+00:01:52,000 --> 00:01:57,000
+So in the case with virus A in a windows server, what you're going to do is you're going to patch it,
+
+29
+00:01:57,000 --> 00:02:01,000
+you're going to update it, you're going to do user training, you're going to put malware detection
+
+30
+00:02:01,000 --> 00:02:02,000
+and removal software on it.
+
+31
+00:02:02,000 --> 00:02:06,000
+So the risk of getting the virus is still there.
+
+32
+00:02:06,000 --> 00:02:11,000
+It's just that its impact and or probability has been drastically reduced.
+
+33
+00:02:11,000 --> 00:02:18,000
+So remember that for your exam avoidance completely eliminates the risk versus mitigation reduces the
+
+34
+00:02:18,000 --> 00:02:19,000
+risk.
+
+35
+00:02:19,000 --> 00:02:27,000
+Risk transfer is given away to risk to a third party, shifting the impact to a third party.
+
+36
+00:02:27,000 --> 00:02:30,000
+This is generally done by purchasing insurance.
+
+37
+00:02:30,000 --> 00:02:31,000
+All right.
+
+38
+00:02:31,000 --> 00:02:37,000
+So if you buy insurance policies for example, there's a risk that a fire can bring down your entire
+
+39
+00:02:37,000 --> 00:02:38,000
+infrastructure.
+
+40
+00:02:38,000 --> 00:02:43,000
+Well in order to transfer that risk you buy fire insurance.
+
+41
+00:02:43,000 --> 00:02:47,000
+If there is a fire, then the insurance company is going to have to take care of it.
+
+42
+00:02:47,000 --> 00:02:51,000
+So this transfer is a financial risk to the insurance provider through outsourcing the risks.
+
+43
+00:02:51,000 --> 00:02:59,000
+Remember, anytime you see the word insurance, think transfer risk acceptance is when you do absolutely
+
+44
+00:02:59,000 --> 00:02:59,000
+nothing.
+
+45
+00:02:59,000 --> 00:03:04,000
+It's a decision to not take any action against a risk.
+
+46
+00:03:04,000 --> 00:03:06,000
+In other words, you're not eliminating it.
+
+47
+00:03:06,000 --> 00:03:10,000
+You're not giving it away to somebody else like an insurance company, and you're not taking steps to
+
+48
+00:03:10,000 --> 00:03:11,000
+reduce it.
+
+49
+00:03:11,000 --> 00:03:12,000
+You're just leaving it alone.
+
+50
+00:03:12,000 --> 00:03:13,000
+If it happens, it happens.
+
+51
+00:03:13,000 --> 00:03:17,000
+Now you're probably saying, well, why would you do that?
+
+52
+00:03:17,000 --> 00:03:20,000
+Well, a couple of different couple different reasons.
+
+53
+00:03:20,000 --> 00:03:25,000
+Number one, sometimes the cost of mitigating the risk is greater than the potential loss.
+
+54
+00:03:25,000 --> 00:03:33,000
+For example, let's say you bought a car for $500 and the cheapest alarm system is $2,000, the cheapest
+
+55
+00:03:33,000 --> 00:03:34,000
+one.
+
+56
+00:03:34,000 --> 00:03:38,000
+So your car is 500 and the cheapest alarm is 2000.
+
+57
+00:03:38,000 --> 00:03:40,000
+Would you buy it an alarm system?
+
+58
+00:03:40,000 --> 00:03:42,000
+Would you spend $2,000 protecting 500?
+
+59
+00:03:43,000 --> 00:03:46,000
+You'd say, you know what, if the car gets stolen, it gets stolen.
+
+60
+00:03:46,000 --> 00:03:48,000
+I'm just going to leave it alone.
+
+61
+00:03:48,000 --> 00:03:50,000
+Another time is sometimes the risk.
+
+62
+00:03:50,000 --> 00:03:52,000
+Sometimes the likelihood is way too low.
+
+63
+00:03:54,000 --> 00:03:55,000
+Earthquake in New York City.
+
+64
+00:03:55,000 --> 00:03:56,000
+I live in New York City.
+
+65
+00:03:56,000 --> 00:04:03,000
+Do I have earthquake insurance, earthquake proof housing or earthquake response plan?
+
+66
+00:04:03,000 --> 00:04:03,000
+Nope.
+
+67
+00:04:04,000 --> 00:04:05,000
+If it happens, it happens.
+
+68
+00:04:05,000 --> 00:04:07,000
+I haven't made any plan for it.
+
+69
+00:04:07,000 --> 00:04:11,000
+I don't have any insurance for it because its probability is too low for me to worry about it.
+
+70
+00:04:11,000 --> 00:04:15,000
+Now you're probably asking yourself, well, when are times we want to accept the risk?
+
+71
+00:04:15,000 --> 00:04:19,000
+Sometimes it could be an exemption or an exception.
+
+72
+00:04:19,000 --> 00:04:20,000
+So an exemption is specific.
+
+73
+00:04:20,000 --> 00:04:24,000
+Risk might be exempt from mitigation due to the nature.
+
+74
+00:04:24,000 --> 00:04:29,000
+For example, you might decide not to install antivirus on a particular machine.
+
+75
+00:04:29,000 --> 00:04:31,000
+And you can exempt that one from antivirus.
+
+76
+00:04:31,000 --> 00:04:34,000
+And the reason is because the machine will never touch the internet.
+
+77
+00:04:34,000 --> 00:04:38,000
+The machine is only going to be connected to a particular piece of equipment, so it's exempt from a
+
+78
+00:04:38,000 --> 00:04:40,000
+particular strategy of risk.
+
+79
+00:04:40,000 --> 00:04:44,000
+An exception is similar to an exemption.
+
+80
+00:04:45,000 --> 00:04:47,000
+Generally it's going to be a temporary thing.
+
+81
+00:04:47,000 --> 00:04:52,000
+Now the other thing that we want to know is risk exploitation.
+
+82
+00:04:52,000 --> 00:04:54,000
+Not all risk are going to be negative.
+
+83
+00:04:54,000 --> 00:04:56,000
+In fact there is a thing like positive risk.
+
+84
+00:04:56,000 --> 00:04:59,000
+So sometimes you want the risk to happen.
+
+85
+00:04:59,000 --> 00:05:01,000
+See negative risk increases cost.
+
+86
+00:05:01,000 --> 00:05:03,000
+Reduces functionality.
+
+87
+00:05:04,000 --> 00:05:05,000
+Brings your system down.
+
+88
+00:05:05,000 --> 00:05:11,000
+Sometimes you want to take advantage of potential positive impact of certain risks that could produce
+
+89
+00:05:11,000 --> 00:05:13,000
+a positive result.
+
+90
+00:05:13,000 --> 00:05:18,000
+So while this is less common in cybersecurity, it's common in project management, though less common
+
+91
+00:05:18,000 --> 00:05:19,000
+in cybersecurity.
+
+92
+00:05:19,000 --> 00:05:26,000
+Sometimes certain technological or certain technology can increase functionality if happens.
+
+93
+00:05:26,000 --> 00:05:30,000
+Now, when it comes to all of this, you're going to want to make sure you do a good risk reporting.
+
+94
+00:05:31,000 --> 00:05:37,000
+This involves understanding the process of communicating information about risks, their identified
+
+95
+00:05:37,000 --> 00:05:39,000
+risks, their analysis and mitigation to stakeholders.
+
+96
+00:05:39,000 --> 00:05:47,000
+Stakeholders within the organisation should know what you plan to do about certain risks, that potential
+
+97
+00:05:47,000 --> 00:05:47,000
+risk register.
+
+98
+00:05:47,000 --> 00:05:49,000
+This is going to be a critical element.
+
+99
+00:05:49,000 --> 00:05:53,000
+It ensures transparency and ongoing management of risk management.
+
+100
+00:05:53,000 --> 00:05:54,000
+Okay.
+
+101
+00:05:54,000 --> 00:05:57,000
+Be familiar with the four different ways of managing risk.
+
+102
+00:05:57,000 --> 00:06:02,000
+Remember something avoidance is an action taken to completely eliminate the risk.
+
+103
+00:06:03,000 --> 00:06:06,000
+Mitigation is an action taken to reduce the risk.
+
+104
+00:06:06,000 --> 00:06:13,000
+Transfer is to give away the risk to a third party by an insurance, and acceptance means to do absolutely
+
+105
+00:06:13,000 --> 00:06:14,000
+nothing about the risk.
+
+106
+00:06:14,000 --> 00:06:16,000
+Remember those four strategies for your exam?
+
diff --git a/21 - Risk Management/007 Business Impact Assessment OB 5.2_en.srt b/21 - Risk Management/007 Business Impact Assessment OB 5.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..35843e9a66e59ef4f31e1c6021679fb2a34451c2
--- /dev/null
+++ b/21 - Risk Management/007 Business Impact Assessment OB 5.2_en.srt
@@ -0,0 +1,352 @@
+1
+00:00:00,000 --> 00:00:06,000
+When it comes to a disaster, every business has to understand how certain disasters can affect their
+
+2
+00:00:06,000 --> 00:00:07,000
+business.
+
+3
+00:00:07,000 --> 00:00:13,000
+This particular exercise of how you go through how different disasters can affect your business is called
+
+4
+00:00:13,000 --> 00:00:17,000
+a business impact analysis, and it basically is.
+
+5
+00:00:17,000 --> 00:00:24,000
+When it's done in business continuity, it helps identify and evaluate the potential effects of interruptions
+
+6
+00:00:24,000 --> 00:00:27,000
+to critical business operations.
+
+7
+00:00:27,000 --> 00:00:32,000
+For example, let's say there's a disaster like a power outage, or let's say there's a disaster of
+
+8
+00:00:33,000 --> 00:00:36,000
+a hurricane or a DDoS attacks against your server.
+
+9
+00:00:36,000 --> 00:00:40,000
+The question is exactly how does that affect your operations?
+
+10
+00:00:40,000 --> 00:00:46,000
+So a business impact analysis looks in to how is the business going to be affected?
+
+11
+00:00:46,000 --> 00:00:48,000
+How long is it going to bring down systems.
+
+12
+00:00:48,000 --> 00:00:51,000
+How long is the data center going to be offline for example.
+
+13
+00:00:52,000 --> 00:00:59,000
+So BIA is proactive measure that aids in crafting effective business continuity and disaster recovery
+
+14
+00:00:59,000 --> 00:00:59,000
+strategies.
+
+15
+00:00:59,000 --> 00:01:01,000
+Now remember this.
+
+16
+00:01:01,000 --> 00:01:06,000
+The BIA shows how a potential disaster is going to impact a business.
+
+17
+00:01:06,000 --> 00:01:09,000
+Now there are some terms that we want to review.
+
+18
+00:01:11,000 --> 00:01:15,000
+The first thing we want to talk are terms that's going to deal with what's called recovery time.
+
+19
+00:01:15,000 --> 00:01:18,000
+I have three terms here that you need to know for your exam.
+
+20
+00:01:18,000 --> 00:01:21,000
+The first one is called a maximum tolerable downtime.
+
+21
+00:01:21,000 --> 00:01:28,000
+This defines the amount of time a business function can be inoperable without causing keyword, without
+
+22
+00:01:28,000 --> 00:01:31,000
+causing irreparable harm to the business.
+
+23
+00:01:31,000 --> 00:01:34,000
+This is known sometimes as the maximum tolerable outage.
+
+24
+00:01:34,000 --> 00:01:36,000
+Now take for example.
+
+25
+00:01:36,000 --> 00:01:41,000
+Let's say you're running a website and hackers are against you and they want to bring down your website.
+
+26
+00:01:42,000 --> 00:01:50,000
+Well, if your website does go down, how long can it go down before you start to have harm done to
+
+27
+00:01:50,000 --> 00:01:53,000
+your business that you can never recover from?
+
+28
+00:01:53,000 --> 00:01:53,000
+Right.
+
+29
+00:01:53,000 --> 00:02:01,000
+So let's say if your website goes down for up to an hour, anything that you lose, you can always recover
+
+30
+00:02:01,000 --> 00:02:02,000
+the sales.
+
+31
+00:02:02,000 --> 00:02:05,000
+But anything after an hour, let's say you're an e-commerce site.
+
+32
+00:02:05,000 --> 00:02:07,000
+Yeah, that means those sales are gone forever.
+
+33
+00:02:07,000 --> 00:02:11,000
+That's harm that you'll never be able to get back, or those sales.
+
+34
+00:02:11,000 --> 00:02:12,000
+You'll never be able to make that money back.
+
+35
+00:02:13,000 --> 00:02:18,000
+So your maximum tolerable downtime for that website is one hour.
+
+36
+00:02:18,000 --> 00:02:23,000
+The question is, if your website does go down, how long will it take to fix it?
+
+37
+00:02:23,000 --> 00:02:25,000
+That's called the recovery time objectives.
+
+38
+00:02:25,000 --> 00:02:29,000
+It's the amount of time to recover a function in the event of a disaster.
+
+39
+00:02:29,000 --> 00:02:35,000
+So let's say it takes 30 minutes to recover your website up to 45 minutes.
+
+40
+00:02:35,000 --> 00:02:36,000
+Well, you're doing great.
+
+41
+00:02:36,000 --> 00:02:42,000
+In fact, the whole point of disaster recovery is to keep your toes less than your mtdz if your maximum
+
+42
+00:02:42,000 --> 00:02:43,000
+is one hour.
+
+43
+00:02:44,000 --> 00:02:46,000
+And you could bring it back up in war in 30 minutes.
+
+44
+00:02:46,000 --> 00:02:47,000
+Great.
+
+45
+00:02:47,000 --> 00:02:51,000
+You'll never suffer what's called irreparable harm.
+
+46
+00:02:51,000 --> 00:02:54,000
+In other words, you'll never suffer harm that you can't recover from.
+
+47
+00:02:55,000 --> 00:02:57,000
+Another time you want to know is what we call a recovery point.
+
+48
+00:02:57,000 --> 00:02:58,000
+Objectives.
+
+49
+00:02:58,000 --> 00:03:04,000
+You got to listen to this one defines the point in time before data loss during the outage will leave
+
+50
+00:03:04,000 --> 00:03:05,000
+the business function unrecoverable.
+
+51
+00:03:05,000 --> 00:03:07,000
+At what point?
+
+52
+00:03:07,000 --> 00:03:08,000
+Point is a key word?
+
+53
+00:03:08,000 --> 00:03:10,000
+At what point do we lose so much data?
+
+54
+00:03:10,000 --> 00:03:15,000
+Like how much data are we willing to lose before we fix this thing?
+
+55
+00:03:15,000 --> 00:03:18,000
+So this this deals with data loss.
+
+56
+00:03:18,000 --> 00:03:26,000
+Now when it comes to other terms there, when you look at when system fails, every system fails, every
+
+57
+00:03:26,000 --> 00:03:31,000
+router fails, every single server fails, every switch fails, every component will fail.
+
+58
+00:03:31,000 --> 00:03:35,000
+There's a couple of terms we need to know with regard to with regard to failure time.
+
+59
+00:03:35,000 --> 00:03:42,000
+The first thing is mean time to repair is the average time taken to repair a failed component and return
+
+60
+00:03:42,000 --> 00:03:44,000
+it back to operational status.
+
+61
+00:03:44,000 --> 00:03:47,000
+The other one is mean time between failure.
+
+62
+00:03:47,000 --> 00:03:53,000
+It's a measure of reliability and stability, indicating the average time between failure of a system.
+
+63
+00:03:53,000 --> 00:03:54,000
+Let me give you a couple of examples.
+
+64
+00:03:55,000 --> 00:03:59,000
+So let's say my sonicwall once again.
+
+65
+00:04:01,000 --> 00:04:07,000
+Now when this thing fails, let's say it's common for the for the memory chip to fail.
+
+66
+00:04:07,000 --> 00:04:10,000
+If the memory chips fail, how long will it take to repair it?
+
+67
+00:04:10,000 --> 00:04:15,000
+Well, it takes about two hours to take it out, reprogram it, reflash it, put the memory chip back
+
+68
+00:04:15,000 --> 00:04:15,000
+in.
+
+69
+00:04:15,000 --> 00:04:20,000
+So the mean time to repair for this device is two hours.
+
+70
+00:04:20,000 --> 00:04:23,000
+Now, how often does this device fail?
+
+71
+00:04:23,000 --> 00:04:27,000
+Let's say in a normal work environment, it fails every two years.
+
+72
+00:04:27,000 --> 00:04:33,000
+So the mean time between failure would be two years and the mean time to repair would be two hours.
+
+73
+00:04:33,000 --> 00:04:34,000
+All right.
+
+74
+00:04:34,000 --> 00:04:41,000
+So between the failures, how long versus how long does it take to fix it.
+
+75
+00:04:41,000 --> 00:04:42,000
+All right.
+
+76
+00:04:42,000 --> 00:04:45,000
+These were some important terms you want to be familiar with for your exam.
+
+77
+00:04:45,000 --> 00:04:48,000
+They're really famous and asking you these kinds of terms.
+
+78
+00:04:48,000 --> 00:04:53,000
+Just remember that a business impact analysis is about seeing how different disasters can affect your
+
+79
+00:04:53,000 --> 00:04:54,000
+business.
+
+80
+00:04:54,000 --> 00:05:01,000
+How long will a certain disaster take out your business for maximum tolerable outage or maximum tolerable
+
+81
+00:05:01,000 --> 00:05:02,000
+downtime?
+
+82
+00:05:02,000 --> 00:05:07,000
+MTD is how long your business can go down from a particular disaster.
+
+83
+00:05:07,000 --> 00:05:12,000
+How long will it or could it stay down before irreparable harm?
+
+84
+00:05:12,000 --> 00:05:15,000
+Now remember, you don't want to stay down.
+
+85
+00:05:15,000 --> 00:05:17,000
+You want to be able to repair it then.
+
+86
+00:05:17,000 --> 00:05:20,000
+So you want to make sure that.
+
+87
+00:05:20,000 --> 00:05:28,000
+Your RPOs RTO recovery time objective, which is how fast you can fix things, is less than your MTD.
+
+88
+00:05:28,000 --> 00:05:30,000
+Remember those terms for your tests.
+
diff --git a/21 - Risk Management/008 Quick Quiz.html b/21 - Risk Management/008 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..f2a39e0bd48c74b044edf861f34d713857ae7a26
--- /dev/null
+++ b/21 - Risk Management/008 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/22 - Vendor Management/001 Vendor Assessment and Selection OB 5.3_en.srt b/22 - Vendor Management/001 Vendor Assessment and Selection OB 5.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..1cff1692c433106c87b254c958b19924e36ec0af
--- /dev/null
+++ b/22 - Vendor Management/001 Vendor Assessment and Selection OB 5.3_en.srt
@@ -0,0 +1,888 @@
+1
+00:00:00,000 --> 00:00:05,000
+When it comes to working in information technology, you are going to be dealing with a lot of vendors
+
+2
+00:00:05,000 --> 00:00:07,000
+when I mean a ton of vendors, I mean a lot.
+
+3
+00:00:07,000 --> 00:00:12,000
+You see, in the world of it, we really don't make firewalls, right?
+
+4
+00:00:12,000 --> 00:00:18,000
+I've never met an organization that produces their own firewall or their own antivirus software or their
+
+5
+00:00:18,000 --> 00:00:20,000
+own operating system.
+
+6
+00:00:20,000 --> 00:00:22,000
+So we're going to be dealing with a lot of vendors.
+
+7
+00:00:22,000 --> 00:00:24,000
+For example, I have the Sonicwall student on my desk.
+
+8
+00:00:24,000 --> 00:00:29,000
+This was bought from Dell, or now Sonicwall, or I should say Dell owned Sonicwall.
+
+9
+00:00:30,000 --> 00:00:32,000
+So this is a vendor.
+
+10
+00:00:32,000 --> 00:00:35,000
+Our laptops are purchased from Lenovo, for example.
+
+11
+00:00:35,000 --> 00:00:40,000
+So in the world of technology, you're going to be dealing with a lot of vendors, whether that's a
+
+12
+00:00:40,000 --> 00:00:45,000
+third party vendor such as Dell, that you purchase your hardware from Microsoft, where you're going
+
+13
+00:00:45,000 --> 00:00:51,000
+to get your operating systems from, uh, Symantec's or Broadcom, or you're going to get your, your
+
+14
+00:00:51,000 --> 00:00:56,000
+security software from tons and tons of vendors, then you're going to have vendors coming into your
+
+15
+00:00:56,000 --> 00:01:00,000
+organization to repair some of these devices, and of course, to update your software.
+
+16
+00:01:00,000 --> 00:01:06,000
+So in this video, let's take a look at what should we be doing or what should we be looking at when
+
+17
+00:01:06,000 --> 00:01:12,000
+we are going to be assessing a particular vendor, things that we want to look for, how are we going
+
+18
+00:01:12,000 --> 00:01:13,000
+to keep them monitored?
+
+19
+00:01:13,000 --> 00:01:17,000
+And of course, in the end, part of this section will take a look at different agreements that we can
+
+20
+00:01:17,000 --> 00:01:18,000
+have with vendors.
+
+21
+00:01:18,000 --> 00:01:20,000
+Let's go through this pretty quickly.
+
+22
+00:01:20,000 --> 00:01:22,000
+So the first thing up is vendor assessment.
+
+23
+00:01:22,000 --> 00:01:25,000
+What exactly is this concept of assessing vendor.
+
+24
+00:01:26,000 --> 00:01:33,000
+Well, it's about evaluating and monitoring the security risks associated with third party providers
+
+25
+00:01:33,000 --> 00:01:34,000
+in your network.
+
+26
+00:01:34,000 --> 00:01:36,000
+You control all aspects of it.
+
+27
+00:01:36,000 --> 00:01:42,000
+But the moment you go and you introduce a third party device into your network, this device could bring
+
+28
+00:01:42,000 --> 00:01:43,000
+problems.
+
+29
+00:01:43,000 --> 00:01:48,000
+If this device is compromised and shipped to you in a compromised state, it already has malware on
+
+30
+00:01:48,000 --> 00:01:53,000
+it or some kind of monitoring legal software, and you install this into your organization.
+
+31
+00:01:53,000 --> 00:01:56,000
+You just got compromised by bringing in somebody else's software.
+
+32
+00:01:56,000 --> 00:01:58,000
+So obviously you don't want that.
+
+33
+00:01:58,000 --> 00:02:01,000
+So in this particular one, what is the security risk?
+
+34
+00:02:01,000 --> 00:02:06,000
+Well, the security risk is like I mentioned, put in compromised devices in your network.
+
+35
+00:02:06,000 --> 00:02:11,000
+It involves scrutinizing vendors cybersecurity practices, policies and compliance.
+
+36
+00:02:11,000 --> 00:02:17,000
+Listen, when I purchase software, I really don't purchase software and or hardware from small vendors.
+
+37
+00:02:17,000 --> 00:02:19,000
+I like going with the bigger vendors.
+
+38
+00:02:19,000 --> 00:02:26,000
+That's more scrutinized by all kinds of regulations they have to follow, or all kinds of different
+
+39
+00:02:26,000 --> 00:02:27,000
+financial audits that they may have.
+
+40
+00:02:29,000 --> 00:02:34,000
+Bigger vendors, in my opinion, will probably have better practices, more policies, and they're going
+
+41
+00:02:34,000 --> 00:02:36,000
+to have to be more in compliance.
+
+42
+00:02:36,000 --> 00:02:39,000
+Maybe they have things like penetration testing done on their networks.
+
+43
+00:02:39,000 --> 00:02:44,000
+Maybe they have particular audit reports, maybe they have particular way they handle data and maintain
+
+44
+00:02:44,000 --> 00:02:45,000
+privacy.
+
+45
+00:02:45,000 --> 00:02:53,000
+Now the goal here is to ensure that the vendors security posture aligns with your organization's security
+
+46
+00:02:53,000 --> 00:02:58,000
+requirements and that risk management strategies and anything that's going to be done to minimize risks
+
+47
+00:02:58,000 --> 00:03:00,000
+to our systems and data.
+
+48
+00:03:00,000 --> 00:03:08,000
+Now, security posture is this you can't have an amazing security organization with great policies,
+
+49
+00:03:08,000 --> 00:03:11,000
+but then the vendors you deal with actually don't.
+
+50
+00:03:11,000 --> 00:03:14,000
+In other words, they don't follow good security practices.
+
+51
+00:03:14,000 --> 00:03:15,000
+So what happens?
+
+52
+00:03:15,000 --> 00:03:19,000
+You end up bringing in poor security practices into your company.
+
+53
+00:03:19,000 --> 00:03:22,000
+Now there are some things here that we want to review.
+
+54
+00:03:23,000 --> 00:03:26,000
+When you are getting vendors, okay.
+
+55
+00:03:26,000 --> 00:03:32,000
+When it comes to seeing how well their security issues are managed, there is this concept of penetration
+
+56
+00:03:32,000 --> 00:03:33,000
+testing.
+
+57
+00:03:33,000 --> 00:03:38,000
+So did the vendor get a penetration test against their system?
+
+58
+00:03:38,000 --> 00:03:42,000
+Now keep in mind that you can also hire vendors to penetrate your systems.
+
+59
+00:03:42,000 --> 00:03:48,000
+When you hire a third party to get penetration testing done against you, but vendors should have a
+
+60
+00:03:48,000 --> 00:03:50,000
+pen test done against their system.
+
+61
+00:03:50,000 --> 00:03:56,000
+Think about this if this vendor is holding your private data, maybe it's a type of a cloud service
+
+62
+00:03:56,000 --> 00:03:58,000
+that they're going to be storing your information.
+
+63
+00:03:59,000 --> 00:04:03,000
+Uh, maybe it's a company that processes certain medical records because you deal in medical.
+
+64
+00:04:03,000 --> 00:04:05,000
+They're going to have your patient's information.
+
+65
+00:04:05,000 --> 00:04:10,000
+Did they have a pen test done against their system to test their security policy?
+
+66
+00:04:10,000 --> 00:04:15,000
+So this involves simulating cyber attacks against the vendor system to assess the security.
+
+67
+00:04:15,000 --> 00:04:21,000
+This particularly important for vendors handling sensitive or critical data because once again how do
+
+68
+00:04:21,000 --> 00:04:24,000
+we know if they're systems is actually secure.
+
+69
+00:04:24,000 --> 00:04:29,000
+Well, a pen test can tell us if there's any vulnerability and what those vulnerabilities are.
+
+70
+00:04:29,000 --> 00:04:35,000
+Results from this test can reveal any kind of vulnerabilities that poses a risk to that organization.
+
+71
+00:04:35,000 --> 00:04:41,000
+Another thing you may want to ask your vendors about is a right to audit clause.
+
+72
+00:04:41,000 --> 00:04:47,000
+This involves, and you're usually going to put this in your contracts that grants you the organization,
+
+73
+00:04:47,000 --> 00:04:54,000
+the right to conduct or have conducted on its behalf an audit of the vendor security practices.
+
+74
+00:04:54,000 --> 00:04:59,000
+Now, when it comes to large organizations, this is something not easy to get.
+
+75
+00:04:59,000 --> 00:05:05,000
+This is when you have something in a contract that states that you have the ability to audit them or
+
+76
+00:05:05,000 --> 00:05:10,000
+have a third party company, maybe of your choice, audit their security practices.
+
+77
+00:05:10,000 --> 00:05:11,000
+Not so much.
+
+78
+00:05:11,000 --> 00:05:14,000
+So in large organizations like large third party vendors.
+
+79
+00:05:14,000 --> 00:05:21,000
+But for example, I'm not I might not have that on a contract with Dell, but Dell generally gets a
+
+80
+00:05:21,000 --> 00:05:25,000
+lot of different third party and external audits done.
+
+81
+00:05:25,000 --> 00:05:30,000
+This can include reviewing security policies, all their different controls that they have applied.
+
+82
+00:05:30,000 --> 00:05:34,000
+And do they have any type of compliance that they have to stay with now?
+
+83
+00:05:34,000 --> 00:05:36,000
+Evidence of internal audits.
+
+84
+00:05:36,000 --> 00:05:40,000
+Every organization should be doing some kind of internal audit.
+
+85
+00:05:40,000 --> 00:05:45,000
+Internal audits is when their own auditors inside of their organization.
+
+86
+00:05:45,000 --> 00:05:51,000
+Now I spent about a year, I believe, or a little less than a year, being an internal auditor before
+
+87
+00:05:51,000 --> 00:05:52,000
+it became a pentester.
+
+88
+00:05:52,000 --> 00:06:00,000
+And basically you just reviewing the internal security policies, procedures and findings within the
+
+89
+00:06:00,000 --> 00:06:01,000
+organization.
+
+90
+00:06:01,000 --> 00:06:05,000
+For example, if there is a policy that says secure passwords, do we actually have that?
+
+91
+00:06:05,000 --> 00:06:12,000
+So internal audits is something that the company does on a regular basis with their own internal employees.
+
+92
+00:06:12,000 --> 00:06:20,000
+Does the vendor have evidence of these regular internal audits of their security processes and their
+
+93
+00:06:20,000 --> 00:06:20,000
+controls?
+
+94
+00:06:20,000 --> 00:06:23,000
+Maybe they can show you audit reports.
+
+95
+00:06:23,000 --> 00:06:28,000
+Maybe they can do a summary of different findings that they found and how they fixed it.
+
+96
+00:06:28,000 --> 00:06:32,000
+And what what was the remediation against those findings.
+
+97
+00:06:33,000 --> 00:06:39,000
+Now, a lot of times, one of the best things that I believe that we can get is an independent assessment.
+
+98
+00:06:39,000 --> 00:06:44,000
+I don't want the order the third party vendor to come and say, like, Dell is going to tell me, yeah,
+
+99
+00:06:44,000 --> 00:06:45,000
+we are super secure.
+
+100
+00:06:45,000 --> 00:06:48,000
+You telling me that is the same way?
+
+101
+00:06:48,000 --> 00:06:52,000
+Me telling you that I am the smartest man in the world, in my opinion.
+
+102
+00:06:52,000 --> 00:06:53,000
+So.
+
+103
+00:06:53,000 --> 00:06:59,000
+But if you can get a third party evaluator to evaluate you and tell me that you have good security controls,
+
+104
+00:06:59,000 --> 00:07:01,000
+that gives me a good peace of mind.
+
+105
+00:07:01,000 --> 00:07:03,000
+So that's an independent assessment.
+
+106
+00:07:03,000 --> 00:07:07,000
+It's generally done by third party and sometimes it involves a certification.
+
+107
+00:07:07,000 --> 00:07:13,000
+There's what's called ISO certification or ISO 27,000 which produces an information security management
+
+108
+00:07:13,000 --> 00:07:13,000
+system.
+
+109
+00:07:13,000 --> 00:07:15,000
+There's also what's called SoC audits.
+
+110
+00:07:15,000 --> 00:07:20,000
+These are going to be audits to test for different security controls against the CIA.
+
+111
+00:07:20,000 --> 00:07:23,000
+These provides more of an objective evaluation.
+
+112
+00:07:23,000 --> 00:07:27,000
+An objective means something that is very detailed.
+
+113
+00:07:27,000 --> 00:07:30,000
+It's not subjective like you can question it.
+
+114
+00:07:30,000 --> 00:07:35,000
+The critical for verifying that the vendor heeds the good industry practices.
+
+115
+00:07:35,000 --> 00:07:38,000
+So if you want to know, does your vendor follow good security practices?
+
+116
+00:07:38,000 --> 00:07:42,000
+A good third party independent assessment is important.
+
+117
+00:07:42,000 --> 00:07:46,000
+Another thing you're going to want to ask your vendors about is going to be what's called supply chain
+
+118
+00:07:46,000 --> 00:07:47,000
+analysis.
+
+119
+00:07:47,000 --> 00:07:48,000
+Supply chain.
+
+120
+00:07:48,000 --> 00:07:49,000
+What exactly is supply chain.
+
+121
+00:07:49,000 --> 00:07:56,000
+Well, how do we take oil out of the ground and turn it into something like this?
+
+122
+00:07:56,000 --> 00:07:56,000
+Right.
+
+123
+00:07:56,000 --> 00:08:00,000
+How do we get steel out of the ground and oil out of the ground so we can develop silicone.
+
+124
+00:08:00,000 --> 00:08:04,000
+We can develop all the parts that comes together and then ship it to me.
+
+125
+00:08:05,000 --> 00:08:11,000
+So the supply chain is all the things that it goes through, from raw materials to a finished product
+
+126
+00:08:11,000 --> 00:08:14,000
+that we use as consumers of these products.
+
+127
+00:08:14,000 --> 00:08:21,000
+Supply chain could be damaged, for example, if they're using a supplier in a part of the world that
+
+128
+00:08:21,000 --> 00:08:27,000
+is subject to floods or hurricanes and stuff like that, then the supply chain can easily be affected.
+
+129
+00:08:27,000 --> 00:08:32,000
+Does the vendor have multiple supply chains or supply routes that they can get raw materials from?
+
+130
+00:08:32,000 --> 00:08:37,000
+So examining the security of the vendor supply chain has vulnerabilities in the chain can directly impact
+
+131
+00:08:37,000 --> 00:08:39,000
+the security of the products or services.
+
+132
+00:08:39,000 --> 00:08:42,000
+For example, what if they're getting a microchips?
+
+133
+00:08:43,000 --> 00:08:50,000
+From a country that is that doesn't like the United States, that can then embed malware in those microchips
+
+134
+00:08:50,000 --> 00:08:52,000
+and then ship it to me.
+
+135
+00:08:52,000 --> 00:08:57,000
+Like, for example, what if this thing has what if this sonicwall has chips from a country that doesn't
+
+136
+00:08:57,000 --> 00:09:02,000
+like the United States, that has malware embedded to it to spy on United States companies?
+
+137
+00:09:02,000 --> 00:09:08,000
+So the analysis should assess the security practices of not only the primary vendor, but all of their
+
+138
+00:09:08,000 --> 00:09:10,000
+suppliers that they have.
+
+139
+00:09:10,000 --> 00:09:12,000
+Now, another thing you want.
+
+140
+00:09:12,000 --> 00:09:13,000
+How are you going to get this done.
+
+141
+00:09:13,000 --> 00:09:16,000
+But questionnaires you got to question the vendor.
+
+142
+00:09:16,000 --> 00:09:18,000
+This question is a critical tool.
+
+143
+00:09:18,000 --> 00:09:24,000
+You're going to gather information, question them about their practices, their policies and how how
+
+144
+00:09:24,000 --> 00:09:26,000
+are they going to stay in compliance.
+
+145
+00:09:26,000 --> 00:09:26,000
+Right.
+
+146
+00:09:26,000 --> 00:09:33,000
+So the question just literally asking them questions like what practices you follow, what kind of policies
+
+147
+00:09:33,000 --> 00:09:37,000
+you have, this is really going to assess the risks that they may bring to us.
+
+148
+00:09:38,000 --> 00:09:43,000
+Now, another thing you're going to want to talk about with them is the rules of engagement.
+
+149
+00:09:43,000 --> 00:09:46,000
+This is something that you may want to outline in the contract.
+
+150
+00:09:46,000 --> 00:09:51,000
+The rules of engagement refers to the set of guidelines or protocols that outline how an organization's
+
+151
+00:09:51,000 --> 00:09:54,000
+interact and cooperate with third party vendors.
+
+152
+00:09:54,000 --> 00:09:58,000
+So how are we going to deal with that third party vendor?
+
+153
+00:09:58,000 --> 00:10:00,000
+How are we going to onboard them?
+
+154
+00:10:00,000 --> 00:10:01,000
+Can we do this?
+
+155
+00:10:01,000 --> 00:10:02,000
+Can we not do that with them?
+
+156
+00:10:03,000 --> 00:10:09,000
+Um, this is going to set a good baseline of what we should be expecting of them.
+
+157
+00:10:09,000 --> 00:10:12,000
+Maybe they got to have a yearly third party assessment done.
+
+158
+00:10:12,000 --> 00:10:14,000
+What's the responsibilities?
+
+159
+00:10:14,000 --> 00:10:16,000
+What's the boundaries set between them.
+
+160
+00:10:16,000 --> 00:10:20,000
+Now when it comes to assessing them, we went through a few things there.
+
+161
+00:10:20,000 --> 00:10:22,000
+At some point you got to select a vendor.
+
+162
+00:10:22,000 --> 00:10:25,000
+So this is going to be evaluated.
+
+163
+00:10:25,000 --> 00:10:27,000
+And choosing the best third party provider.
+
+164
+00:10:27,000 --> 00:10:36,000
+Like what's or who we should say is the vendor that meets your security posture or that meets the way
+
+165
+00:10:36,000 --> 00:10:43,000
+you want to do security, meets your recommendations or wants in terms of third party assessments.
+
+166
+00:10:43,000 --> 00:10:45,000
+Now, there's a couple of things that we want to mention.
+
+167
+00:10:45,000 --> 00:10:49,000
+The first thing you want to do before selecting any vendor is do your due diligence.
+
+168
+00:10:49,000 --> 00:10:50,000
+What is due diligence?
+
+169
+00:10:50,000 --> 00:10:58,000
+Well, it's basically a really comprehensive appraisal or evaluation of the vendors practices focusing
+
+170
+00:10:58,000 --> 00:11:00,000
+on cybersecurity policies, procedures.
+
+171
+00:11:00,000 --> 00:11:04,000
+So do do your due diligence.
+
+172
+00:11:04,000 --> 00:11:08,000
+Due diligence is doing all your homework, all your background information.
+
+173
+00:11:08,000 --> 00:11:12,000
+Check in things such as did they have some kind of third party compliance?
+
+174
+00:11:13,000 --> 00:11:14,000
+Are they ISO certified?
+
+175
+00:11:14,000 --> 00:11:16,000
+Did they have Soc2 reports.
+
+176
+00:11:16,000 --> 00:11:19,000
+These are going to be audits done by external organizations.
+
+177
+00:11:19,000 --> 00:11:23,000
+Did they get any past cyber cyber breach?
+
+178
+00:11:23,000 --> 00:11:25,000
+Is their reputation any good.
+
+179
+00:11:26,000 --> 00:11:28,000
+Go back ten years.
+
+180
+00:11:28,000 --> 00:11:30,000
+Did they get hacked at any point?
+
+181
+00:11:30,000 --> 00:11:32,000
+What was the what was the remediation?
+
+182
+00:11:32,000 --> 00:11:35,000
+How many times has this organization been hacked?
+
+183
+00:11:35,000 --> 00:11:39,000
+For example, what is the public's perception of this organization?
+
+184
+00:11:39,000 --> 00:11:41,000
+This is going to be your due diligence.
+
+185
+00:11:41,000 --> 00:11:46,000
+Uncover any potential security vulnerabilities and weaknesses before you're selecting them.
+
+186
+00:11:46,000 --> 00:11:51,000
+Now, one thing that you're going to want to keep in mind is this thing called conflict of interest.
+
+187
+00:11:51,000 --> 00:11:52,000
+What is it?
+
+188
+00:11:52,000 --> 00:11:57,000
+Well, this is going to be identifying and managing any conflict of interest.
+
+189
+00:11:57,000 --> 00:12:03,000
+It's arise when a vendor has listened carefully, competing interests that can influence your ability
+
+190
+00:12:03,000 --> 00:12:07,000
+to objectively and securely provide security services.
+
+191
+00:12:07,000 --> 00:12:15,000
+For example, let's say you hire an organization to do pen tests to do a pen test for you.
+
+192
+00:12:15,000 --> 00:12:19,000
+It's a third party vendor that you're going to be using to do a pen test.
+
+193
+00:12:19,000 --> 00:12:28,000
+But then you came to realize that the vendors, the vendor, their CEO, their let's say their owner
+
+194
+00:12:28,000 --> 00:12:35,000
+owns shares or owns a majority shares in a company that directly competes with you.
+
+195
+00:12:35,000 --> 00:12:41,000
+So your competitor is actually owned by the guy that's doing the pen test for you.
+
+196
+00:12:41,000 --> 00:12:47,000
+That's something that you want to know now, it's not illegal for them to own, you know, for anybody
+
+197
+00:12:47,000 --> 00:12:48,000
+to own a business.
+
+198
+00:12:48,000 --> 00:12:54,000
+But that is called a conflict of interest because can they really objectively analyze your organization?
+
+199
+00:12:54,000 --> 00:12:57,000
+Are they going to look for things that are going to steal your information?
+
+200
+00:12:57,000 --> 00:13:05,000
+So keep in mind these kinds of things do occur, and you have to do your due diligence to find out.
+
+201
+00:13:05,000 --> 00:13:12,000
+Is there any kind of conflict of interest you want to ensure transparency in any kind of impartial ability
+
+202
+00:13:12,000 --> 00:13:14,000
+with this now?
+
+203
+00:13:15,000 --> 00:13:20,000
+When you select your vendor, you have to monitor the vendor consistent monitoring of the vendor.
+
+204
+00:13:21,000 --> 00:13:24,000
+Continuous process assessing and overseeing third party.
+
+205
+00:13:24,000 --> 00:13:25,000
+Always keep an eye on the vendor.
+
+206
+00:13:25,000 --> 00:13:26,000
+Look at the news.
+
+207
+00:13:26,000 --> 00:13:29,000
+Look at all the problems and issues that arise with the vendor.
+
+208
+00:13:29,000 --> 00:13:36,000
+This includes regular evaluations of the security practices, incident capabilities, and making sure
+
+209
+00:13:36,000 --> 00:13:40,000
+that they stay relevant on the industry, industry compliance or regulation.
+
+210
+00:13:41,000 --> 00:13:45,000
+Now you want to proactively identify and manage potential security risks.
+
+211
+00:13:45,000 --> 00:13:48,000
+Because remember, the world of technology changes every day.
+
+212
+00:13:48,000 --> 00:13:52,000
+Keep in mind that today there's no problems with the vendor.
+
+213
+00:13:52,000 --> 00:13:55,000
+The vendor has great security practices.
+
+214
+00:13:55,000 --> 00:14:00,000
+He's in compliance right now to different kinds of certifications that they had to get, or different
+
+215
+00:14:00,000 --> 00:14:02,000
+kinds of third party audits.
+
+216
+00:14:02,000 --> 00:14:06,000
+But tomorrow there, they could be a new audit and the guy fails.
+
+217
+00:14:06,000 --> 00:14:10,000
+They could be a new, uh, pen test against them and they fail it.
+
+218
+00:14:10,000 --> 00:14:12,000
+They could be a new hack, and they lost all your data.
+
+219
+00:14:13,000 --> 00:14:18,000
+Remember, security is is basically an -- of, like, right now type thing.
+
+220
+00:14:18,000 --> 00:14:21,000
+You could be secured today and insecure tomorrow.
+
+221
+00:14:21,000 --> 00:14:26,000
+Let's keep that in mind when managing vendors because of the you know, one of the last things we want
+
+222
+00:14:26,000 --> 00:14:30,000
+is to bring security problems to our organization.
+
diff --git a/22 - Vendor Management/002 Vendor Agreements OB 5.3_en.srt b/22 - Vendor Management/002 Vendor Agreements OB 5.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..f25dabd3a6a8645805fefbb4d33b105a4a2739e1
--- /dev/null
+++ b/22 - Vendor Management/002 Vendor Agreements OB 5.3_en.srt
@@ -0,0 +1,484 @@
+1
+00:00:00,000 --> 00:00:06,000
+When it comes to managing the relationship between you and a vendor, you must have some kind of a contract.
+
+2
+00:00:06,000 --> 00:00:13,000
+Never manage a relationship between you and a third party vendor with just a handshake, or just talking
+
+3
+00:00:13,000 --> 00:00:14,000
+over the phone.
+
+4
+00:00:14,000 --> 00:00:17,000
+Just don't do it by words as they say.
+
+5
+00:00:17,000 --> 00:00:18,000
+Put it on paper.
+
+6
+00:00:18,000 --> 00:00:19,000
+Put it in writing.
+
+7
+00:00:19,000 --> 00:00:24,000
+So in this video, let's take a look at some different kinds of contractual agreements that we want
+
+8
+00:00:24,000 --> 00:00:25,000
+to be familiar with for our exam.
+
+9
+00:00:25,000 --> 00:00:27,000
+And what is it that they're going to have in them.
+
+10
+00:00:27,000 --> 00:00:29,000
+So what exactly are we talking about?
+
+11
+00:00:29,000 --> 00:00:35,000
+Well, when you select vendors, you must consider how well you're going to manage these vendors due
+
+12
+00:00:35,000 --> 00:00:39,000
+to contractual terms, such as having an SLA with them, which we'll cover in a minute.
+
+13
+00:00:39,000 --> 00:00:44,000
+Does these SLAs align with the organization's security expectations?
+
+14
+00:00:44,000 --> 00:00:49,000
+Things we're going to want to look for data protection, incident response, security audits, right
+
+15
+00:00:49,000 --> 00:00:57,000
+to audit clauses, all of these things here we can include in our um, in our different types of contracts.
+
+16
+00:00:57,000 --> 00:01:03,000
+So let's go see some different types of contracts that we're going to want to have with our vendors.
+
+17
+00:01:03,000 --> 00:01:07,000
+So the first one up I want to mention is one of the most popular ones you're going to have with a third
+
+18
+00:01:07,000 --> 00:01:08,000
+party vendor.
+
+19
+00:01:08,000 --> 00:01:11,000
+And that's going to be a service level agreement or SLA.
+
+20
+00:01:11,000 --> 00:01:15,000
+Now, this is a contract between a service provider and a client that specifies, quote unquote, the
+
+21
+00:01:15,000 --> 00:01:21,000
+level of service, hence the name service level agreement expected during the terms of the agreement.
+
+22
+00:01:21,000 --> 00:01:27,000
+This generally includes things like system uptime, response time or support requests and security measures.
+
+23
+00:01:27,000 --> 00:01:28,000
+Let me give you a bunch of examples.
+
+24
+00:01:29,000 --> 00:01:31,000
+When you get when you get a vendor.
+
+25
+00:01:31,000 --> 00:01:37,000
+For example, let's say you go to Verizon and you get a Verizon Internet line.
+
+26
+00:01:37,000 --> 00:01:45,000
+They're vendor, they're providing the service of internet, but you need your internet to be up 99.999%
+
+27
+00:01:45,000 --> 00:01:46,000
+of the time.
+
+28
+00:01:46,000 --> 00:01:47,000
+It's called the five nines.
+
+29
+00:01:47,000 --> 00:01:52,000
+99.999% of the time is a very high uptime.
+
+30
+00:01:52,000 --> 00:01:58,000
+So you could put in a contract if Verizon can say, well, our SLA is 99.999%.
+
+31
+00:01:58,000 --> 00:02:01,000
+In other words, their systems go down very little.
+
+32
+00:02:01,000 --> 00:02:03,000
+So you can put that in the SLA.
+
+33
+00:02:03,000 --> 00:02:09,000
+So the SLA is going to be 99.99% of the time, even incident response times, for example, if there
+
+34
+00:02:09,000 --> 00:02:15,000
+is a security incident or for example, if the internet line does go down, Verizon will fix it within
+
+35
+00:02:15,000 --> 00:02:19,000
+four hours, 2 hours or 24 hours, depending on what's in your SLA.
+
+36
+00:02:19,000 --> 00:02:27,000
+So the SLA is generally going to be some kind of level in the name service level that the organization,
+
+37
+00:02:27,000 --> 00:02:31,000
+the vendor in particular has to meet to keep that agreement active.
+
+38
+00:02:31,000 --> 00:02:32,000
+And what if they don't meet it?
+
+39
+00:02:32,000 --> 00:02:37,000
+Like, what if Verizon say they're going to fix all internet issues within four hours, but then it
+
+40
+00:02:37,000 --> 00:02:38,000
+actually took six hours?
+
+41
+00:02:38,000 --> 00:02:43,000
+Well, the SLA can actually specify penalties for the for the particular vendor.
+
+42
+00:02:43,000 --> 00:02:47,000
+The vendor may have to give you back service credits or refunds on future bills.
+
+43
+00:02:47,000 --> 00:02:52,000
+So this is going to be critical because if you're a manager in a server and it's basically managing
+
+44
+00:02:52,000 --> 00:02:57,000
+your own web server and you need a high uptime on on the internet line, make sure that your SLA is
+
+45
+00:02:57,000 --> 00:02:58,000
+a 99 point.
+
+46
+00:02:58,000 --> 00:03:00,000
+You never get 100%.
+
+47
+00:03:01,000 --> 00:03:04,000
+You know, they say the only thing that's 100% in this world is debt.
+
+48
+00:03:04,000 --> 00:03:06,000
+So you're not going to get 100%.
+
+49
+00:03:06,000 --> 00:03:08,000
+But all those nines is close enough.
+
+50
+00:03:08,000 --> 00:03:13,000
+So SLA is a critical for establishing performance benchmarks and consequences.
+
+51
+00:03:13,000 --> 00:03:19,000
+So it will have consequences, like I said, like if they don't meet it, it may they may have to give
+
+52
+00:03:19,000 --> 00:03:21,000
+you back some kind of service credit.
+
+53
+00:03:21,000 --> 00:03:27,000
+Another thing you have is an MOA or memo of agreement.
+
+54
+00:03:27,000 --> 00:03:32,000
+An MOA is a formal document outlining an agreement between two or more parties.
+
+55
+00:03:32,000 --> 00:03:38,000
+It's used to establish some kind of cooperative relationship, detailing the terms and scope of the
+
+56
+00:03:38,000 --> 00:03:38,000
+agreement.
+
+57
+00:03:38,000 --> 00:03:42,000
+Now, when it comes to cyber security, it's basically set out.
+
+58
+00:03:43,000 --> 00:03:48,000
+A joint initiative for information sharing and collaborative development of security protocols.
+
+59
+00:03:48,000 --> 00:03:55,000
+So a lot of times we're going to have memo of agreement with other organizations to sometimes work on
+
+60
+00:03:55,000 --> 00:03:57,000
+a joint project together.
+
+61
+00:03:57,000 --> 00:03:59,000
+That's very common when we do these things.
+
+62
+00:03:59,000 --> 00:04:03,000
+Hey, we're going to have this agreement that says, here's how we're going to share information, here's
+
+63
+00:04:03,000 --> 00:04:06,000
+how we're going to work together to finish a particular project.
+
+64
+00:04:07,000 --> 00:04:13,000
+Take for example, vendor A and vendor B, combining together to develop a new security product.
+
+65
+00:04:13,000 --> 00:04:15,000
+This is how they're going to share information.
+
+66
+00:04:15,000 --> 00:04:18,000
+These are this is what this one should do versus another.
+
+67
+00:04:18,000 --> 00:04:25,000
+Another thing you have is something that's less formal is what we just have a memo of understanding
+
+68
+00:04:25,000 --> 00:04:26,000
+our MOU.
+
+69
+00:04:26,000 --> 00:04:33,000
+Now it's typically used to outline a mutual agreement or a shared goal without keyword legal obligation.
+
+70
+00:04:33,000 --> 00:04:37,000
+So this is going to be more of when they outline, hey, this is how we're going to work together,
+
+71
+00:04:37,000 --> 00:04:41,000
+but they actually don't go in to the specifics.
+
+72
+00:04:41,000 --> 00:04:45,000
+And it's not something that if one wants to walk away from the other, one can take the other one to
+
+73
+00:04:45,000 --> 00:04:46,000
+court.
+
+74
+00:04:46,000 --> 00:04:50,000
+Now, it does facilitate information sharing, research, research, collaboration.
+
+75
+00:04:50,000 --> 00:04:56,000
+So it's really something that's less formal than an MOA.
+
+76
+00:04:57,000 --> 00:05:03,000
+Now, one of the main ones you're going to want to get is what's called a master service agreement.
+
+77
+00:05:03,000 --> 00:05:05,000
+This is a more comprehensive contract.
+
+78
+00:05:05,000 --> 00:05:11,000
+These sets the general terms governing future of transactions in all agreements between you and that
+
+79
+00:05:11,000 --> 00:05:13,000
+vendor can streamline future agreements.
+
+80
+00:05:13,000 --> 00:05:17,000
+And it often will include how are they going to protect the CIA.
+
+81
+00:05:17,000 --> 00:05:22,000
+So confidentiality, integrity and availability, any kind of disputes that may show up or any kind
+
+82
+00:05:22,000 --> 00:05:23,000
+of data security standard.
+
+83
+00:05:23,000 --> 00:05:30,000
+So the Master Service agreement is exactly how it's the big agreement that really dictates how the relationship
+
+84
+00:05:30,000 --> 00:05:33,000
+between you and the vendor will be managed.
+
+85
+00:05:33,000 --> 00:05:35,000
+Now to outline the specific work.
+
+86
+00:05:35,000 --> 00:05:38,000
+This is going to be called a work order or statement of work.
+
+87
+00:05:38,000 --> 00:05:42,000
+This is a document that specific details about the work to be performed.
+
+88
+00:05:42,000 --> 00:05:47,000
+So if you hire a vendor to work on a particular project or get particular task done for you, you're
+
+89
+00:05:47,000 --> 00:05:48,000
+going to want to make sure you add this in.
+
+90
+00:05:48,000 --> 00:05:52,000
+It must be detailed, like what is it that they're going to have to deliver?
+
+91
+00:05:52,000 --> 00:05:56,000
+When are timelines, specific tasks and the responsibilities?
+
+92
+00:05:56,000 --> 00:05:59,000
+For example, let's say you hire somebody to build a website.
+
+93
+00:05:59,000 --> 00:06:01,000
+You should have a statement of work for them.
+
+94
+00:06:01,000 --> 00:06:02,000
+This is what you want.
+
+95
+00:06:02,000 --> 00:06:03,000
+These are the pages.
+
+96
+00:06:03,000 --> 00:06:08,000
+This is what should be on the pages if it's in terms of security.
+
+97
+00:06:08,000 --> 00:06:13,000
+If it's particularly like if it's a security project, what should be configured, how should be configured,
+
+98
+00:06:13,000 --> 00:06:17,000
+what type of audits or tests or implementations we need to get done.
+
+99
+00:06:18,000 --> 00:06:19,000
+A non-disclosure.
+
+100
+00:06:19,000 --> 00:06:24,000
+Any time you work with a vendor, you should always have a non-disclosure agreement.
+
+101
+00:06:24,000 --> 00:06:30,000
+This is a legal binding contract that establishes that confidential relationship now.
+
+102
+00:06:30,000 --> 00:06:39,000
+Basically it's a it's an agreement that says no one is to disclose information covered by the agreement,
+
+103
+00:06:39,000 --> 00:06:40,000
+which is critical.
+
+104
+00:06:40,000 --> 00:06:45,000
+For example, if you're dealing with a vendor and that vendor comes into your organization, they may
+
+105
+00:06:45,000 --> 00:06:45,000
+find.
+
+106
+00:06:46,000 --> 00:06:52,000
+Private information about your customers, maybe even secret projects that you're working on, maybe
+
+107
+00:06:52,000 --> 00:06:55,000
+specific way you deal your business or business secrets.
+
+108
+00:06:56,000 --> 00:07:03,000
+They can technically share that information with anyone, but if they sign an NDA, they're not supposed
+
+109
+00:07:03,000 --> 00:07:04,000
+to disclose that information to anyone.
+
+110
+00:07:04,000 --> 00:07:07,000
+So this becomes a legal contract that says, you know what?
+
+111
+00:07:07,000 --> 00:07:11,000
+Whatever I find in this organization, I can't disclose it.
+
+112
+00:07:11,000 --> 00:07:13,000
+So that's why this is important.
+
+113
+00:07:13,000 --> 00:07:18,000
+So it's critical for protecting sensitive data, especially proprietary information.
+
+114
+00:07:19,000 --> 00:07:23,000
+Now another agreement you may see is a business partners agreement.
+
+115
+00:07:23,000 --> 00:07:28,000
+This is going to be when business people combine together, share resources, joint ventures or work
+
+116
+00:07:28,000 --> 00:07:30,000
+on different types of projects.
+
+117
+00:07:30,000 --> 00:07:35,000
+Together they're going to sign a business partner agreement to say, here, let's combine together to
+
+118
+00:07:35,000 --> 00:07:39,000
+develop certain security products, software, hardware and so on.
+
+119
+00:07:39,000 --> 00:07:42,000
+Okay, just be familiar with some of these agreements.
+
+120
+00:07:42,000 --> 00:07:44,000
+You might see them, they show up on your exam.
+
+121
+00:07:44,000 --> 00:07:51,000
+But keep in mind, never manage a vendor without having the correct agreement or contract in place.
+
diff --git a/22 - Vendor Management/003 Quick Quiz.html b/22 - Vendor Management/003 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..b828803ef835a02444be6be6b53a1cca1a7394d8
--- /dev/null
+++ b/22 - Vendor Management/003 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/23 - Physical Security/001 Physical Security OB 1.2_en.srt b/23 - Physical Security/001 Physical Security OB 1.2_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..2503b2dccb197657416796d8f6a95374e180125a
--- /dev/null
+++ b/23 - Physical Security/001 Physical Security OB 1.2_en.srt
@@ -0,0 +1,640 @@
+1
+00:00:00,000 --> 00:00:08,000
+IT security professionals mostly think about how do we secure our data from technical attacks such as
+
+2
+00:00:08,000 --> 00:00:09,000
+hackers.
+
+3
+00:00:09,000 --> 00:00:16,000
+But reality says this it doesn't matter how much technical controls you put in place, such as you can
+
+4
+00:00:16,000 --> 00:00:22,000
+have great firewalls, encryption, anti-malware, intrusion prevention systems, and all the other
+
+5
+00:00:22,000 --> 00:00:24,000
+things that we're going to talk about later in this course.
+
+6
+00:00:24,000 --> 00:00:29,000
+See, it doesn't matter how much technical security you have, if I have the ability just to walk into
+
+7
+00:00:29,000 --> 00:00:34,000
+your organization, pick up your server and walk back out, you really don't have much security, do
+
+8
+00:00:34,000 --> 00:00:35,000
+you?
+
+9
+00:00:36,000 --> 00:00:39,000
+You see, the topic in this video is called physical security.
+
+10
+00:00:39,000 --> 00:00:46,000
+And when we protect our organization, just don't protect it from theft of digital data, protect it
+
+11
+00:00:46,000 --> 00:00:50,000
+from the theft of the physical server that stores the data.
+
+12
+00:00:50,000 --> 00:00:52,000
+So let's get more into physical security.
+
+13
+00:00:52,000 --> 00:00:57,000
+And also in this video I want to go through some different controls within physical security.
+
+14
+00:00:57,000 --> 00:00:59,000
+You want to be familiar with for your exam.
+
+15
+00:00:59,000 --> 00:01:01,000
+So the first thing up what exactly is this.
+
+16
+00:01:01,000 --> 00:01:06,000
+Well it's a critical aspect that focuses on protecting an organization's assets.
+
+17
+00:01:06,000 --> 00:01:08,000
+And it's mostly going to be physical assets.
+
+18
+00:01:08,000 --> 00:01:14,000
+Think building equipment and personnel from physical actions and events that can cause serious loss
+
+19
+00:01:14,000 --> 00:01:15,000
+or damage.
+
+20
+00:01:15,000 --> 00:01:16,000
+Now I want to point out something.
+
+21
+00:01:17,000 --> 00:01:21,000
+One of the most important assets that you're going to be protecting in physical security is going to
+
+22
+00:01:21,000 --> 00:01:22,000
+be people's lives.
+
+23
+00:01:22,000 --> 00:01:25,000
+Because when you think physical security, don't think of just theft.
+
+24
+00:01:25,000 --> 00:01:29,000
+Most people think, well, it's a thief coming in to steal a server.
+
+25
+00:01:29,000 --> 00:01:30,000
+Not particularly.
+
+26
+00:01:30,000 --> 00:01:34,000
+Remember, physical security protects against a wide variety of things like fire.
+
+27
+00:01:34,000 --> 00:01:40,000
+Not only can that destroy, that can take lives, flood, natural disasters like hurricanes, earthquakes,
+
+28
+00:01:40,000 --> 00:01:42,000
+burglary, theft, vandalism, and even terrorism.
+
+29
+00:01:42,000 --> 00:01:44,000
+Always remember something.
+
+30
+00:01:44,000 --> 00:01:49,000
+It doesn't matter how sophisticated your IT security is or your technical security is.
+
+31
+00:01:49,000 --> 00:01:54,000
+Keep in mind that it could be rendered ineffective if your physical security is compromised.
+
+32
+00:01:54,000 --> 00:01:59,000
+Now I'm going to go through some physical security controls in this video with you.
+
+33
+00:01:59,000 --> 00:02:02,000
+I want you to understand what these things are for your exam.
+
+34
+00:02:02,000 --> 00:02:03,000
+Don't go in depth into them.
+
+35
+00:02:03,000 --> 00:02:06,000
+Your exam won't, but just know what these controls are.
+
+36
+00:02:06,000 --> 00:02:07,000
+So let's get started.
+
+37
+00:02:07,000 --> 00:02:08,000
+Now.
+
+38
+00:02:08,000 --> 00:02:11,000
+They're not in any particular order per se that you need to have this.
+
+39
+00:02:11,000 --> 00:02:14,000
+Just know that these things exist and know what they do.
+
+40
+00:02:14,000 --> 00:02:19,000
+The first one up is something that you've probably seen many times, and these are going to be this
+
+41
+00:02:19,000 --> 00:02:22,000
+big post that you see, like this one here, the silver one.
+
+42
+00:02:22,000 --> 00:02:24,000
+This is going to be like the one in front of a building.
+
+43
+00:02:25,000 --> 00:02:28,000
+This yellow one is going to be like the one that you see in the parking lot.
+
+44
+00:02:28,000 --> 00:02:32,000
+Now what these things are, they're basically called bollards.
+
+45
+00:02:33,000 --> 00:02:38,000
+Now bollards are basically sturdy vertical posts, and they're designed to prevent car based attacks
+
+46
+00:02:38,000 --> 00:02:41,000
+on buildings or to control access to sensitive areas.
+
+47
+00:02:41,000 --> 00:02:47,000
+So basically, if you put this in front of your building, somebody can't run a car directly into your
+
+48
+00:02:47,000 --> 00:02:48,000
+building or a truck.
+
+49
+00:02:48,000 --> 00:02:53,000
+These things will withstand the force of a car going many miles per hour.
+
+50
+00:02:53,000 --> 00:03:00,000
+Another thing here we're going to have is something we call an access control vestibule.
+
+51
+00:03:00,000 --> 00:03:03,000
+Now, depending on what you read in, this thing used to be called a mantrap.
+
+52
+00:03:03,000 --> 00:03:06,000
+If you ever read old security texts used to be called that.
+
+53
+00:03:06,000 --> 00:03:09,000
+Now it's called an access control vestibule.
+
+54
+00:03:09,000 --> 00:03:16,000
+This is a secure area between two sets of doors used to manage and control access into a secure area.
+
+55
+00:03:17,000 --> 00:03:19,000
+Here's how it works, by the way.
+
+56
+00:03:19,000 --> 00:03:20,000
+Here's a picture of it.
+
+57
+00:03:20,000 --> 00:03:21,000
+Here's how it works.
+
+58
+00:03:21,000 --> 00:03:24,000
+Let's say you want to get into and these are famous.
+
+59
+00:03:24,000 --> 00:03:26,000
+You see these in like prison movies.
+
+60
+00:03:26,000 --> 00:03:27,000
+You want to get into a prison.
+
+61
+00:03:27,000 --> 00:03:29,000
+So there's going to be two doors.
+
+62
+00:03:29,000 --> 00:03:29,000
+Okay.
+
+63
+00:03:29,000 --> 00:03:37,000
+So let's say you enter from this door and in, and when you enter from this door, there's a pathway
+
+64
+00:03:37,000 --> 00:03:38,000
+to the next door.
+
+65
+00:03:38,000 --> 00:03:44,000
+And in order for the second door to open, because the second door is what takes you to the secure area,
+
+66
+00:03:44,000 --> 00:03:45,000
+you first have to enter this door.
+
+67
+00:03:45,000 --> 00:03:49,000
+And then there's some kind of authentication between the two doors.
+
+68
+00:03:49,000 --> 00:03:54,000
+For example, in a prison, the authentication between the two doors is generally a security guard or
+
+69
+00:03:54,000 --> 00:03:58,000
+somebody checking your ID, or it could be checking to see if you have any kind of weapons or something.
+
+70
+00:03:59,000 --> 00:04:05,000
+So you open this door, you go in, you're checked to make sure that you're you match the correct identification.
+
+71
+00:04:05,000 --> 00:04:07,000
+Maybe you check to see if you have any kind of weapons.
+
+72
+00:04:07,000 --> 00:04:09,000
+Then the second door opens.
+
+73
+00:04:09,000 --> 00:04:11,000
+Then you can go in to the secure area.
+
+74
+00:04:12,000 --> 00:04:17,000
+Now it's not just used in prison, but they're used in a wide variety of places in it.
+
+75
+00:04:17,000 --> 00:04:19,000
+For example, in data centers.
+
+76
+00:04:19,000 --> 00:04:21,000
+You're going to find this quite often.
+
+77
+00:04:21,000 --> 00:04:27,000
+Now it's generally equipped with some kind of biometric scanners, metal detectors and other security
+
+78
+00:04:27,000 --> 00:04:31,000
+measures that only authorized individuals will gain access to.
+
+79
+00:04:32,000 --> 00:04:34,000
+Now, the other one here you have is FinCEN.
+
+80
+00:04:34,000 --> 00:04:35,000
+Now, you're pretty much familiar with FinCEN.
+
+81
+00:04:35,000 --> 00:04:40,000
+As you can see in this picture here, fences are used to secure perimeters of a property.
+
+82
+00:04:40,000 --> 00:04:45,000
+Now high security fences are going to be topped with barbed wire and other deterrents to prevent unauthorized
+
+83
+00:04:45,000 --> 00:04:45,000
+entry.
+
+84
+00:04:45,000 --> 00:04:51,000
+Remember something a fence is good to secure perimeter and show where where the perimeter of a building
+
+85
+00:04:51,000 --> 00:04:51,000
+is.
+
+86
+00:04:52,000 --> 00:04:53,000
+Video surveillance.
+
+87
+00:04:53,000 --> 00:04:58,000
+Security guards don't have eyes to see an entire space all around.
+
+88
+00:04:58,000 --> 00:04:59,000
+But if you have.
+
+89
+00:04:59,000 --> 00:05:00,000
+Good video surveillance.
+
+90
+00:05:00,000 --> 00:05:02,000
+And I'm talking cameras as we have in this picture.
+
+91
+00:05:03,000 --> 00:05:11,000
+This can allow one basically one guard or one person and nowadays even software to watch large plots
+
+92
+00:05:11,000 --> 00:05:12,000
+of areas.
+
+93
+00:05:12,000 --> 00:05:17,000
+So they're able to monitor activities in and around a facility.
+
+94
+00:05:17,000 --> 00:05:22,000
+Now the good thing about cameras is they act as a good deterrent to prevent unauthorized actions and
+
+95
+00:05:22,000 --> 00:05:27,000
+can provide vulnerable evidence so people are less likely to steal things.
+
+96
+00:05:27,000 --> 00:05:31,000
+Or it might be deter to steal something or break in if they see, oh, look at that.
+
+97
+00:05:31,000 --> 00:05:32,000
+That camera is watching me.
+
+98
+00:05:32,000 --> 00:05:36,000
+So they might say, you know what, I don't want to do that because I don't want to get caught.
+
+99
+00:05:36,000 --> 00:05:40,000
+And if I do get caught, they're going to have the evidence in the camera footage.
+
+100
+00:05:41,000 --> 00:05:45,000
+Now sometimes you just need a person there.
+
+101
+00:05:45,000 --> 00:05:52,000
+If there's any kind of discretionary or discretion that has to be made, something that needs to be
+
+102
+00:05:52,000 --> 00:05:52,000
+checked.
+
+103
+00:05:52,000 --> 00:05:54,000
+Software is generally not the most reliable.
+
+104
+00:05:54,000 --> 00:05:56,000
+Sometimes you need that physical security guard.
+
+105
+00:05:56,000 --> 00:06:01,000
+Unfortunately, we don't have robots that can restrain or physically stop people, but a security guard
+
+106
+00:06:01,000 --> 00:06:02,000
+could.
+
+107
+00:06:02,000 --> 00:06:06,000
+So security guard is that human presence is a critical component of physical security.
+
+108
+00:06:06,000 --> 00:06:13,000
+Remember, we really don't have basically robots that can get up and catch someone running or somebody
+
+109
+00:06:13,000 --> 00:06:16,000
+that can physically stop someone from entering a building.
+
+110
+00:06:16,000 --> 00:06:19,000
+That's what human personnel are for until robots come along.
+
+111
+00:06:19,000 --> 00:06:20,000
+But that's not yet.
+
+112
+00:06:20,000 --> 00:06:25,000
+So guard they can monitor, they conduct patrols, they respond to incidents, and they're going to
+
+113
+00:06:25,000 --> 00:06:26,000
+control access.
+
+114
+00:06:26,000 --> 00:06:28,000
+You're allowed in and you're not allowed in.
+
+115
+00:06:29,000 --> 00:06:34,000
+Generally, it's pretty common within organizations today for people to be given one of these things
+
+116
+00:06:34,000 --> 00:06:37,000
+that shows the company name, your name, and your title.
+
+117
+00:06:37,000 --> 00:06:42,000
+Sometimes they're embedded with what's called an RFID chip or radio frequency ID chips.
+
+118
+00:06:42,000 --> 00:06:47,000
+So what these are badges are going to be used to identify personnel and will contain some kind of magnetic
+
+119
+00:06:47,000 --> 00:06:47,000
+strip.
+
+120
+00:06:47,000 --> 00:06:53,000
+A lot of times these badges are going to be used to enter certain rooms that only these people should
+
+121
+00:06:53,000 --> 00:06:54,000
+have access to.
+
+122
+00:06:55,000 --> 00:06:56,000
+Leiden.
+
+123
+00:06:57,000 --> 00:07:02,000
+Cameras can detect, uh, if it's dark or if it's completely black.
+
+124
+00:07:02,000 --> 00:07:05,000
+You want to make sure that you have adequate lighting.
+
+125
+00:07:05,000 --> 00:07:10,000
+It's going to be important for security, especially in outdoor areas, because when the sun goes down,
+
+126
+00:07:10,000 --> 00:07:13,000
+you're not going to be able to see the entire perimeter.
+
+127
+00:07:13,000 --> 00:07:20,000
+So make sure the perimeter is well lit and enhances visibility, acting as a deterrent to trespassers,
+
+128
+00:07:20,000 --> 00:07:22,000
+aiding in the effectiveness of video surveillance.
+
+129
+00:07:22,000 --> 00:07:27,000
+You see, if it goes dark and the area is completely black, people can just dressed in black and run
+
+130
+00:07:27,000 --> 00:07:32,000
+through the space, run through the yard, run through the big open ground.
+
+131
+00:07:32,000 --> 00:07:40,000
+That's because run through the big open ground, because it's relatively easy for them to go through,
+
+132
+00:07:40,000 --> 00:07:42,000
+and the camera can't detect them because it's all black.
+
+133
+00:07:42,000 --> 00:07:46,000
+Remember, the camera needs light sensors.
+
+134
+00:07:46,000 --> 00:07:50,000
+Now you're going to have a variety of motion detectors.
+
+135
+00:07:50,000 --> 00:07:56,000
+Now these kinds of motion detectors is going to be able to detect motion in around your ground.
+
+136
+00:07:56,000 --> 00:07:57,000
+There's a few different ones.
+
+137
+00:07:57,000 --> 00:07:59,000
+The first one is going to be infrared sensors.
+
+138
+00:07:59,000 --> 00:08:03,000
+These are going to detect heat often used in an intrusion detection system.
+
+139
+00:08:03,000 --> 00:08:05,000
+These are really good because basically.
+
+140
+00:08:06,000 --> 00:08:12,000
+These are going to be really used to detect if there's heat in the space and if there's movement within
+
+141
+00:08:12,000 --> 00:08:13,000
+that space of that heat.
+
+142
+00:08:13,000 --> 00:08:15,000
+Heat signals the infrared sensors.
+
+143
+00:08:15,000 --> 00:08:17,000
+The problem is they're not going to be able to do a white space.
+
+144
+00:08:17,000 --> 00:08:19,000
+The other one you have is a pressure sensor.
+
+145
+00:08:19,000 --> 00:08:22,000
+These detect changes in pressure like weight.
+
+146
+00:08:22,000 --> 00:08:25,000
+These are these are going to put on things like secure flooring or windows.
+
+147
+00:08:25,000 --> 00:08:30,000
+So if anybody like for example steps on the flooring, it's going to know the weight has changed or
+
+148
+00:08:30,000 --> 00:08:32,000
+the pressure has changed and it's going to set off an alarm.
+
+149
+00:08:32,000 --> 00:08:36,000
+Now, if you have something like a big perimeter or a big ground that you want to secure, you're going
+
+150
+00:08:36,000 --> 00:08:37,000
+to use what's called microwave sensors.
+
+151
+00:08:37,000 --> 00:08:40,000
+These are going to be able to detect movement in a much larger area.
+
+152
+00:08:41,000 --> 00:08:46,000
+Now, the other one you have, and some of the later technology is going to be that ultrasonic.
+
+153
+00:08:46,000 --> 00:08:50,000
+These emit ultrasonic wave and measure the reflection off the objects.
+
+154
+00:08:50,000 --> 00:08:55,000
+These are going to basically use in a lot of different motion detection systems that we have out there.
+
+155
+00:08:56,000 --> 00:08:56,000
+Okay.
+
+156
+00:08:56,000 --> 00:08:59,000
+These are going to be some of the things here that you might see on your exam.
+
+157
+00:08:59,000 --> 00:09:04,000
+When it comes to physical security, the best thing is make sure you understand them, understand what
+
+158
+00:09:04,000 --> 00:09:05,000
+these things are when you see them.
+
+159
+00:09:05,000 --> 00:09:13,000
+Now keep in mind, guys, don't forget it doesn't matter how good your technical security is, it's
+
+160
+00:09:13,000 --> 00:09:17,000
+going to be rendered ineffective if you don't have good physical security.
+
diff --git a/23 - Physical Security/002 Quick Quiz.html b/23 - Physical Security/002 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..2aa7ec94ec094a313205f465888d710afaa6d4d6
--- /dev/null
+++ b/23 - Physical Security/002 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/24 - Change Management/001 Change management OB 1.3_en.srt b/24 - Change Management/001 Change management OB 1.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..e2c4de8a42b78d5be3afc4f73d803e6e05cf9af9
--- /dev/null
+++ b/24 - Change Management/001 Change management OB 1.3_en.srt
@@ -0,0 +1,824 @@
+1
+00:00:00,000 --> 00:00:02,000
+As an IT security person.
+
+2
+00:00:02,000 --> 00:00:06,000
+Anytime something breaks within an organization or there's some kind of security incident, the first
+
+3
+00:00:06,000 --> 00:00:09,000
+thing that comes to my mind is what changed?
+
+4
+00:00:09,000 --> 00:00:10,000
+Who changed what?
+
+5
+00:00:10,000 --> 00:00:13,000
+Now I want to point out something to you guys.
+
+6
+00:00:13,000 --> 00:00:17,000
+You could build the greatest and most secure system.
+
+7
+00:00:18,000 --> 00:00:24,000
+Great firewalls, a good configuration on firewalls, just good selection of configuration of switches,
+
+8
+00:00:24,000 --> 00:00:30,000
+routers, access points, anti-malware software, intrusion detection and prevention systems, and so
+
+9
+00:00:30,000 --> 00:00:30,000
+on.
+
+10
+00:00:31,000 --> 00:00:36,000
+And then it just takes somebody to go and do an unauthorized change or change that you didn't authorize
+
+11
+00:00:36,000 --> 00:00:37,000
+or didn't know about.
+
+12
+00:00:37,000 --> 00:00:40,000
+And all your security just goes right down the drain.
+
+13
+00:00:40,000 --> 00:00:44,000
+Maybe because they punch a hole in the firewall, they change the level of authentication that allows
+
+14
+00:00:44,000 --> 00:00:46,000
+easy passwords or something.
+
+15
+00:00:46,000 --> 00:00:50,000
+Change management is critical for IT security.
+
+16
+00:00:50,000 --> 00:00:57,000
+We want to make sure that any changes within the organization is done in a secure way, and it doesn't
+
+17
+00:00:57,000 --> 00:01:01,000
+reduce the security in the organization if it increases it, great.
+
+18
+00:01:01,000 --> 00:01:04,000
+Now you got to keep in mind that change will happen in a company.
+
+19
+00:01:04,000 --> 00:01:08,000
+If a company is around long enough, they're going to change from Windows 10 to Windows 11.
+
+20
+00:01:08,000 --> 00:01:09,000
+They're going to change a router.
+
+21
+00:01:09,000 --> 00:01:10,000
+They're going to change a switch.
+
+22
+00:01:10,000 --> 00:01:12,000
+They're going to change an access point.
+
+23
+00:01:12,000 --> 00:01:14,000
+They're going to change people.
+
+24
+00:01:14,000 --> 00:01:16,000
+Changes will happen.
+
+25
+00:01:16,000 --> 00:01:18,000
+Business processes and procedure changes.
+
+26
+00:01:18,000 --> 00:01:19,000
+So changes will happen.
+
+27
+00:01:20,000 --> 00:01:25,000
+So in this video I want to talk about change management and some of the things we should be expecting
+
+28
+00:01:25,000 --> 00:01:28,000
+when managing changes across the entire company.
+
+29
+00:01:28,000 --> 00:01:35,000
+So in cybersecurity, change management is a structured approach to transitioning individuals, teams
+
+30
+00:01:35,000 --> 00:01:41,000
+and the organization from the current state to a future state or desired future state, while ensuring
+
+31
+00:01:41,000 --> 00:01:45,000
+now keep in mind the security, the confidentiality, integrity and availability of information.
+
+32
+00:01:45,000 --> 00:01:46,000
+So that's important.
+
+33
+00:01:47,000 --> 00:01:48,000
+Remember something.
+
+34
+00:01:49,000 --> 00:01:55,000
+For us to go from where we are right now, our current state to where we want to be a desired state.
+
+35
+00:01:55,000 --> 00:01:57,000
+Something needs to change.
+
+36
+00:01:57,000 --> 00:01:59,000
+I'm £215.
+
+37
+00:01:59,000 --> 00:01:59,000
+All right.
+
+38
+00:01:59,000 --> 00:02:05,000
+The doctor and my wife and everybody keeps telling me, Andrew, you need to be £190.
+
+39
+00:02:05,000 --> 00:02:12,000
+Well, in order for me to go from the current 215 to the desired 190.
+
+40
+00:02:12,000 --> 00:02:15,000
+Well, I got to do what I got to change, right?
+
+41
+00:02:15,000 --> 00:02:19,000
+Maybe I got to give up that eating that Burger King twice a week or that McDonald's a couple of times
+
+42
+00:02:19,000 --> 00:02:20,000
+a week.
+
+43
+00:02:20,000 --> 00:02:21,000
+Maybe I got to give up that couple of beers.
+
+44
+00:02:21,000 --> 00:02:23,000
+In other words, I have to change something.
+
+45
+00:02:23,000 --> 00:02:29,000
+So changes must occur from for an organization to go from a current state to a desired state, your
+
+46
+00:02:29,000 --> 00:02:34,000
+job is going to be to ensure that all the changes that the organization is going to be going through
+
+47
+00:02:34,000 --> 00:02:35,000
+is done in a secure way.
+
+48
+00:02:35,000 --> 00:02:39,000
+Now there are going to be security changes.
+
+49
+00:02:39,000 --> 00:02:41,000
+Now what are security changes?
+
+50
+00:02:41,000 --> 00:02:44,000
+Well, for example, you configure this firewall and it's working all good.
+
+51
+00:02:44,000 --> 00:02:47,000
+Now you want to change a configuration on the firewall.
+
+52
+00:02:47,000 --> 00:02:48,000
+You want to change a rule on it.
+
+53
+00:02:48,000 --> 00:02:50,000
+You want to update a rule.
+
+54
+00:02:50,000 --> 00:02:52,000
+You want to remove a rule on a firewall.
+
+55
+00:02:52,000 --> 00:02:53,000
+Anti-Malware software.
+
+56
+00:02:53,000 --> 00:02:57,000
+Maybe you want to change the anti-malware software or add a new configuration.
+
+57
+00:02:57,000 --> 00:03:01,000
+So let's go through some things that we want to keep in mind when managing changes.
+
+58
+00:03:02,000 --> 00:03:07,000
+Now business process impacting security operation.
+
+59
+00:03:07,000 --> 00:03:09,000
+Now we got to understand something.
+
+60
+00:03:09,000 --> 00:03:14,000
+Business process is what they're going to be doing to produce the deliverables or produce the products
+
+61
+00:03:14,000 --> 00:03:15,000
+and services that they sell.
+
+62
+00:03:15,000 --> 00:03:17,000
+This will have an impact on security.
+
+63
+00:03:17,000 --> 00:03:23,000
+In general, understanding business processes impacting security operations involve knowing how these
+
+64
+00:03:23,000 --> 00:03:28,000
+processes work together to manage changes in a way that minimize risk, and ensuring security and stability
+
+65
+00:03:28,000 --> 00:03:29,000
+of the environment.
+
+66
+00:03:29,000 --> 00:03:33,000
+When you go out and you change something, how is that going to impact?
+
+67
+00:03:34,000 --> 00:03:36,000
+The business processes that's happening.
+
+68
+00:03:36,000 --> 00:03:43,000
+For example, let's say you go and you modify, uh, you implement a new version of windows across everybody's
+
+69
+00:03:43,000 --> 00:03:47,000
+machine, put Windows 11 that you all had, Windows 10, that can have massive disruption to business
+
+70
+00:03:47,000 --> 00:03:51,000
+operation because people may may not know how to use it very well.
+
+71
+00:03:51,000 --> 00:03:56,000
+So you've got to make sure and understand how does these changes impact business operation.
+
+72
+00:03:56,000 --> 00:04:02,000
+Every change management procedure in a business needs to have some kind of an approval process.
+
+73
+00:04:02,000 --> 00:04:04,000
+This is going to be different for every business.
+
+74
+00:04:04,000 --> 00:04:07,000
+Just understand for now that there has to be one.
+
+75
+00:04:07,000 --> 00:04:09,000
+It's a structured approval process.
+
+76
+00:04:10,000 --> 00:04:15,000
+Ensure that any changes, especially those affect on IT systems and security, are reviewed and approved
+
+77
+00:04:15,000 --> 00:04:17,000
+by an authorized personnel.
+
+78
+00:04:17,000 --> 00:04:19,000
+Who is authorized personnel.
+
+79
+00:04:19,000 --> 00:04:26,000
+Depending on the type of change, it may be a lower level IT manager, a higher mid-level IT manager.
+
+80
+00:04:26,000 --> 00:04:30,000
+It may be the CIO that needs to approve of a certain change.
+
+81
+00:04:30,000 --> 00:04:37,000
+For example, a small change to desktop computers may be done by the Helpdesk Help help desk manager,
+
+82
+00:04:37,000 --> 00:04:43,000
+a major change that somebody wants to implement, like, uh, new configuration or firewall may be done
+
+83
+00:04:43,000 --> 00:04:46,000
+by the CISO or the chief information security officer.
+
+84
+00:04:46,000 --> 00:04:52,000
+But change in massive technology, like all the desktops to win for windows uh, 10 to 11 might need
+
+85
+00:04:52,000 --> 00:04:53,000
+the CIO approval.
+
+86
+00:04:53,000 --> 00:04:57,000
+So think of that approval process.
+
+87
+00:04:57,000 --> 00:04:59,000
+It's going to be different for every single organization.
+
+88
+00:04:59,000 --> 00:05:04,000
+This is going to help to mitigate risk associated with unauthorized or poorly planned changes.
+
+89
+00:05:04,000 --> 00:05:06,000
+So you got to have some kind of an approval process.
+
+90
+00:05:06,000 --> 00:05:06,000
+Why?
+
+91
+00:05:06,000 --> 00:05:12,000
+Because then people are going to know, well, I can't implement the change without having the approval.
+
+92
+00:05:12,000 --> 00:05:14,000
+Next thing we want to look at is ownership.
+
+93
+00:05:14,000 --> 00:05:15,000
+Who owns the change?
+
+94
+00:05:16,000 --> 00:05:20,000
+Ownership refers to identify who's responsible for overseeing the change process.
+
+95
+00:05:20,000 --> 00:05:26,000
+So this can go many ways because you can have a person owning the change management process.
+
+96
+00:05:26,000 --> 00:05:32,000
+Or you can have a team doing this, or you can have ownership of the of a specific change itself.
+
+97
+00:05:32,000 --> 00:05:39,000
+When you're when there's ownership of changes, that person or team is going to be responsible for planning,
+
+98
+00:05:39,000 --> 00:05:41,000
+executing and follow up to the change.
+
+99
+00:05:41,000 --> 00:05:48,000
+This ensures accountability and that the appropriate security consideration are integrated into them.
+
+100
+00:05:48,000 --> 00:05:52,000
+The next thing is when we implement the change who's it?
+
+101
+00:05:52,000 --> 00:05:53,000
+Who's this change affected?
+
+102
+00:05:54,000 --> 00:05:59,000
+If you implement a firewall change to allow remote workers, well, then the stakeholders are going
+
+103
+00:05:59,000 --> 00:06:02,000
+to be only people that are working remotely.
+
+104
+00:06:02,000 --> 00:06:06,000
+And of course the IT security department and some infrastructure department.
+
+105
+00:06:06,000 --> 00:06:11,000
+If it's a change like going from Windows 10 to Windows 11, that's a change that's going to impact every
+
+106
+00:06:11,000 --> 00:06:12,000
+single user in the business.
+
+107
+00:06:12,000 --> 00:06:15,000
+These are called stakeholders in change management.
+
+108
+00:06:15,000 --> 00:06:20,000
+Anyone who may be affected or who has influence over the process.
+
+109
+00:06:20,000 --> 00:06:24,000
+So if someone might be affected or is affected, they're going to be considered a stakeholder of the
+
+110
+00:06:24,000 --> 00:06:25,000
+change.
+
+111
+00:06:25,000 --> 00:06:29,000
+This includes IT staff, security teams, management and of course end users.
+
+112
+00:06:29,000 --> 00:06:32,000
+You want to communicate well with them, communicate what the change is.
+
+113
+00:06:32,000 --> 00:06:33,000
+When are they going to get the change?
+
+114
+00:06:33,000 --> 00:06:35,000
+Why is the change needed?
+
+115
+00:06:35,000 --> 00:06:39,000
+So effective communication involves many stakeholders are going to be key for good implementation.
+
+116
+00:06:40,000 --> 00:06:42,000
+I can't emphasize this part enough.
+
+117
+00:06:42,000 --> 00:06:44,000
+You must have good impact analysis.
+
+118
+00:06:45,000 --> 00:06:45,000
+What is that?
+
+119
+00:06:45,000 --> 00:06:54,000
+Well, don't ever implement the change if you don't know how that change is going to affect systems.
+
+120
+00:06:54,000 --> 00:07:00,000
+Way too often there's people implement the change not understanding the impact and it brings system
+
+121
+00:07:00,000 --> 00:07:01,000
+down.
+
+122
+00:07:02,000 --> 00:07:02,000
+Oh man.
+
+123
+00:07:02,000 --> 00:07:03,000
+Why is the server offline?
+
+124
+00:07:03,000 --> 00:07:08,000
+Well Bob put in a change and he didn't realize it would have taken that server off or shut off a particular
+
+125
+00:07:08,000 --> 00:07:09,000
+service.
+
+126
+00:07:09,000 --> 00:07:13,000
+So before implementing the change, it's critical to analyze its potential impact on the organization
+
+127
+00:07:13,000 --> 00:07:14,000
+posture.
+
+128
+00:07:14,000 --> 00:07:20,000
+This includes evaluating the risk and benefits of the change, how it might affect existing security
+
+129
+00:07:20,000 --> 00:07:23,000
+controls, and what new risk it might prevent present to you.
+
+130
+00:07:24,000 --> 00:07:29,000
+Now, understand how it's going to impact and then test your change.
+
+131
+00:07:29,000 --> 00:07:33,000
+Testing changes in a controlled environment for implementation is critical.
+
+132
+00:07:33,000 --> 00:07:39,000
+One of the things I always say, and when something breaks in a change, you're going to say, did you
+
+133
+00:07:39,000 --> 00:07:41,000
+did you test that change?
+
+134
+00:07:41,000 --> 00:07:44,000
+Did you verify that that was going to do what it says?
+
+135
+00:07:44,000 --> 00:07:46,000
+Because that could just brought down the whole system.
+
+136
+00:07:46,000 --> 00:07:49,000
+This helps to identify any unforeseen issues.
+
+137
+00:07:49,000 --> 00:07:56,000
+And then documenting the test, documenting the test results allows the organization to use them to
+
+138
+00:07:56,000 --> 00:08:00,000
+refine if there is any security problems and maybe enhance it in the future.
+
+139
+00:08:01,000 --> 00:08:04,000
+Now you can plan all you want.
+
+140
+00:08:04,000 --> 00:08:09,000
+You can look at the impact you can implement good, uh, good testing environment.
+
+141
+00:08:10,000 --> 00:08:11,000
+And then you go and you implement the change.
+
+142
+00:08:11,000 --> 00:08:14,000
+And before you know it, the old system crashes or the whole place crash.
+
+143
+00:08:16,000 --> 00:08:17,000
+Well, what are you going to do?
+
+144
+00:08:17,000 --> 00:08:19,000
+Well, you got to go back to where you are.
+
+145
+00:08:19,000 --> 00:08:21,000
+This is called a back out plan.
+
+146
+00:08:21,000 --> 00:08:28,000
+It's a contingency plan that can be active if the changes introduces unacceptable risks or causes unforeseen.
+
+147
+00:08:28,000 --> 00:08:33,000
+It outlines the steps to revert the system to their state before the changes minimize the impact.
+
+148
+00:08:33,000 --> 00:08:36,000
+So let's say you send all your users home.
+
+149
+00:08:36,000 --> 00:08:40,000
+You're going to be rolling out a brand new anti-malware software to all the computers.
+
+150
+00:08:40,000 --> 00:08:45,000
+You send them all home, you start rolling it out and you realize.
+
+151
+00:08:46,000 --> 00:08:49,000
+After half the machine's been installed.
+
+152
+00:08:49,000 --> 00:08:50,000
+It's crashing the machine.
+
+153
+00:08:50,000 --> 00:08:51,000
+It's not compatible.
+
+154
+00:08:51,000 --> 00:08:55,000
+You didn't realize some of the Nic cards are not going to function with it.
+
+155
+00:08:55,000 --> 00:08:58,000
+Some of the operating system don't have the right patches and so on to make this thing work.
+
+156
+00:08:58,000 --> 00:09:02,000
+And you only got four hours before the users come back in.
+
+157
+00:09:02,000 --> 00:09:03,000
+But what do you do?
+
+158
+00:09:03,000 --> 00:09:04,000
+Well, the best thing here.
+
+159
+00:09:04,000 --> 00:09:09,000
+Do you have a backup plan, a roll back procedure that we can use to revert the system back quickly
+
+160
+00:09:09,000 --> 00:09:12,000
+to the old one, because we can't have the entire network down.
+
+161
+00:09:12,000 --> 00:09:18,000
+It's always good to have a good backup plan, also known as a roll back plan maintenance window.
+
+162
+00:09:18,000 --> 00:09:22,000
+Well, you got to ask yourself, when are you going to be doing these changes?
+
+163
+00:09:22,000 --> 00:09:25,000
+This is a predetermined period during which changes are implemented.
+
+164
+00:09:25,000 --> 00:09:27,000
+So we have to have a good maintenance window.
+
+165
+00:09:27,000 --> 00:09:34,000
+In other words, we want to be doing it in a time where it is not going to be affecting users.
+
+166
+00:09:34,000 --> 00:09:35,000
+Scheduling changes.
+
+167
+00:09:35,000 --> 00:09:40,000
+The maintenance windows helps in reducing the impact on users, allows for more controlled and secure
+
+168
+00:09:40,000 --> 00:09:43,000
+implementation guys if you want.
+
+169
+00:09:43,000 --> 00:09:47,000
+If you work in it, be prepared to work on weekends.
+
+170
+00:09:47,000 --> 00:09:49,000
+Late, late nights.
+
+171
+00:09:49,000 --> 00:09:54,000
+I'm talking two in the morning, uh, because that's when we roll out many of the changes, especially
+
+172
+00:09:54,000 --> 00:09:59,000
+weekends, Saturday night at 2:00 when all your friends are going to be out at the bar having fun.
+
+173
+00:09:59,000 --> 00:10:03,000
+You're going to be installing some kind of software on a on a desktop.
+
+174
+00:10:03,000 --> 00:10:04,000
+That's your maintenance window.
+
+175
+00:10:04,000 --> 00:10:09,000
+At that time, you have the least amount of users on the network, so the least impact to them.
+
+176
+00:10:10,000 --> 00:10:17,000
+Now keep in mind what SOPs are standard operating procedures are detailed written instructions to achieve
+
+177
+00:10:17,000 --> 00:10:20,000
+something uniformly in the performance of a specific function.
+
+178
+00:10:20,000 --> 00:10:21,000
+So what exactly is this.
+
+179
+00:10:21,000 --> 00:10:24,000
+So company set up standard operating procedures.
+
+180
+00:10:24,000 --> 00:10:30,000
+So standard operating procedure are the SOPs are basically here's a series of steps of how to configure
+
+181
+00:10:30,000 --> 00:10:32,000
+something how to do something.
+
+182
+00:10:32,000 --> 00:10:33,000
+How to produce.
+
+183
+00:10:33,000 --> 00:10:35,000
+So you can have an SOP to configure this firewall.
+
+184
+00:10:35,000 --> 00:10:38,000
+And in it let's say a company has 30 of these things.
+
+185
+00:10:39,000 --> 00:10:40,000
+You have 30 locations.
+
+186
+00:10:40,000 --> 00:10:43,000
+You can have an SOP that says, here's how you take this thing out of the box.
+
+187
+00:10:43,000 --> 00:10:45,000
+Here's how you configure it step by step.
+
+188
+00:10:45,000 --> 00:10:46,000
+Log into the device.
+
+189
+00:10:46,000 --> 00:10:47,000
+Go to this tab.
+
+190
+00:10:47,000 --> 00:10:49,000
+Implement this username configure here.
+
+191
+00:10:49,000 --> 00:10:50,000
+Add this.
+
+192
+00:10:50,000 --> 00:10:51,000
+Update this.
+
+193
+00:10:51,000 --> 00:10:52,000
+Configure this rule.
+
+194
+00:10:52,000 --> 00:10:52,000
+Remove this rule.
+
+195
+00:10:52,000 --> 00:10:53,000
+That's an SOP.
+
+196
+00:10:53,000 --> 00:10:57,000
+Now when you do changes they're going to affect these SOPs.
+
+197
+00:10:57,000 --> 00:11:03,000
+In change management SOPs is kind of a change manager SOPs ensure that changes are implemented consistently
+
+198
+00:11:03,000 --> 00:11:05,000
+and securely and eat into the best practices.
+
+199
+00:11:05,000 --> 00:11:12,000
+Do you have good SOPs for change management or is your changes affecting the SOPs that you already have?
+
+200
+00:11:12,000 --> 00:11:13,000
+You need both.
+
+201
+00:11:13,000 --> 00:11:18,000
+So we're going to have good procedures to manage the changes, and you're going to have and you're going
+
+202
+00:11:18,000 --> 00:11:21,000
+to want to make sure that the changes you implement update existing SOPs.
+
+203
+00:11:23,000 --> 00:11:26,000
+Change management is critical in every organization.
+
+204
+00:11:26,000 --> 00:11:30,000
+Every organization that wants to grow and which one doesn't is going to have to go through some kind
+
+205
+00:11:30,000 --> 00:11:31,000
+of change.
+
+206
+00:11:31,000 --> 00:11:36,000
+And you want to make sure that you allow these changes in a secure manner.
+
diff --git a/24 - Change Management/002 Technical Implications OB 1.3_en.srt b/24 - Change Management/002 Technical Implications OB 1.3_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..9f0377c70f076c7e8fa847d3b130702020f4f490
--- /dev/null
+++ b/24 - Change Management/002 Technical Implications OB 1.3_en.srt
@@ -0,0 +1,676 @@
+1
+00:00:00,000 --> 00:00:06,000
+Any time you implement a change within an organization, I want you to keep in mind what exactly are
+
+2
+00:00:06,000 --> 00:00:09,000
+the technical implications of that change?
+
+3
+00:00:09,000 --> 00:00:10,000
+Well, what exactly is this?
+
+4
+00:00:10,000 --> 00:00:17,000
+Well, this refers to the direct effects that changes in an IT environment can have on system security
+
+5
+00:00:17,000 --> 00:00:18,000
+functionality and performance.
+
+6
+00:00:18,000 --> 00:00:26,000
+So any time we do a change within the actual organization, whether we're changing over a firewall or
+
+7
+00:00:26,000 --> 00:00:33,000
+a switch or manipulating configurations of a particular system, keep in mind that how is this going
+
+8
+00:00:33,000 --> 00:00:36,000
+to technically affect that system and other systems that are out there?
+
+9
+00:00:36,000 --> 00:00:38,000
+So that's what we're talking about in this one.
+
+10
+00:00:38,000 --> 00:00:44,000
+It's essential to recognize how various technical aspects of function are influenced by changes in how
+
+11
+00:00:44,000 --> 00:00:45,000
+to mitigate any potential risks.
+
+12
+00:00:45,000 --> 00:00:49,000
+You never want to put in a change in a system and then break something else.
+
+13
+00:00:49,000 --> 00:00:54,000
+You never want to put in a good security change to secure your system, but you didn't realize that
+
+14
+00:00:54,000 --> 00:00:56,000
+security change opened a hole somewhere else.
+
+15
+00:00:56,000 --> 00:01:02,000
+You always want to keep in mind all the technical problems that can go wrong with changes now.
+
+16
+00:01:03,000 --> 00:01:07,000
+There are two terms I want you guys to be familiar with what's called an allow list and a deny list.
+
+17
+00:01:08,000 --> 00:01:12,000
+Organizations use these terms in a wide variety of sense, and I'm going to go through some different
+
+18
+00:01:12,000 --> 00:01:12,000
+ways with you.
+
+19
+00:01:12,000 --> 00:01:18,000
+So changes in security configurations, such as updating firewall rules especially or access control
+
+20
+00:01:18,000 --> 00:01:21,000
+lists can have very big implications.
+
+21
+00:01:22,000 --> 00:01:26,000
+There's something called an allow list, which is used to be called a whitelist or deny list, which
+
+22
+00:01:26,000 --> 00:01:31,000
+was a blacklist, needs to be carefully managed to ensure that only authorized entities have access
+
+23
+00:01:31,000 --> 00:01:34,000
+while blocking malicious or unwanted traffic.
+
+24
+00:01:34,000 --> 00:01:34,000
+So.
+
+25
+00:01:35,000 --> 00:01:38,000
+There's a few ways we're going to look at allow lists and deny lists.
+
+26
+00:01:38,000 --> 00:01:45,000
+Now on a firewall an allow list, for example, is traffic that's allowed to come through the firewall
+
+27
+00:01:45,000 --> 00:01:46,000
+or traffic.
+
+28
+00:01:46,000 --> 00:01:50,000
+For example, you may have an allow list that says allow web traffic because you're running your own
+
+29
+00:01:50,000 --> 00:01:51,000
+internal web server.
+
+30
+00:01:51,000 --> 00:01:53,000
+But you may have a deny list.
+
+31
+00:01:53,000 --> 00:01:56,000
+In other words, none of these, nothing else is allowed in your denied.
+
+32
+00:01:56,000 --> 00:02:00,000
+All these other traffic organizations also have this with applications.
+
+33
+00:02:00,000 --> 00:02:02,000
+They may have an allow list and a deny list.
+
+34
+00:02:02,000 --> 00:02:04,000
+So you're allowed to have these applications.
+
+35
+00:02:04,000 --> 00:02:08,000
+Or they might say you're denied from having these applications on your machine.
+
+36
+00:02:08,000 --> 00:02:09,000
+The allow list is more restrictive.
+
+37
+00:02:09,000 --> 00:02:16,000
+For example, if you work in a in an organization today and they say, here's a list of applications
+
+38
+00:02:16,000 --> 00:02:19,000
+that you're allowed and everything else is basically denied.
+
+39
+00:02:19,000 --> 00:02:20,000
+In other words, you're restricted.
+
+40
+00:02:20,000 --> 00:02:21,000
+Let's say there's 20 things on there.
+
+41
+00:02:21,000 --> 00:02:23,000
+You're restricted to just those 20 things.
+
+42
+00:02:23,000 --> 00:02:28,000
+But if they have a deny list, they're basically saying, well, don't install these things, but you're
+
+43
+00:02:28,000 --> 00:02:30,000
+allowed to have all the other billion applications out there.
+
+44
+00:02:30,000 --> 00:02:33,000
+So these terms could be used differently.
+
+45
+00:02:33,000 --> 00:02:36,000
+Now keep in mind that any time there's a change it could be a result.
+
+46
+00:02:36,000 --> 00:02:39,000
+And it could affect these allow and deny lists.
+
+47
+00:02:40,000 --> 00:02:43,000
+Another thing is restricted activities.
+
+48
+00:02:43,000 --> 00:02:52,000
+Changes in things such as system configuration or policies might impose new restrictions on users.
+
+49
+00:02:52,000 --> 00:02:56,000
+Security is known for one thing, and one thing in particular that's going to be restrictions.
+
+50
+00:02:56,000 --> 00:02:59,000
+Security restricts security versus functionality.
+
+51
+00:02:59,000 --> 00:03:01,000
+Security restricts functionality.
+
+52
+00:03:01,000 --> 00:03:02,000
+It's how it functions.
+
+53
+00:03:02,000 --> 00:03:03,000
+It's by definition what it does.
+
+54
+00:03:04,000 --> 00:03:06,000
+The more functionality you have, generally less security you have.
+
+55
+00:03:06,000 --> 00:03:10,000
+So we have to know that if we put a new changes, are we restricting certain activities.
+
+56
+00:03:10,000 --> 00:03:15,000
+This can include limited access to certain resources or disabling certain functions that they may want.
+
+57
+00:03:16,000 --> 00:03:21,000
+These restrictions, while they do enhance security, does impact their productivity and need to be
+
+58
+00:03:21,000 --> 00:03:23,000
+communicated effectively.
+
+59
+00:03:25,000 --> 00:03:27,000
+Ah, I can't emphasize this enough.
+
+60
+00:03:27,000 --> 00:03:31,000
+It's way too many times that changes leads to downtime.
+
+61
+00:03:31,000 --> 00:03:32,000
+All right.
+
+62
+00:03:32,000 --> 00:03:36,000
+Managing change, especially significant system updates or hardware replacement can result in downtime.
+
+63
+00:03:36,000 --> 00:03:37,000
+Yes.
+
+64
+00:03:37,000 --> 00:03:40,000
+For example, if you're changing a server hardware replacement.
+
+65
+00:03:40,000 --> 00:03:41,000
+Um.
+
+66
+00:03:41,000 --> 00:03:46,000
+If you're putting in a major update on a router or something, you better best bet you're going to need
+
+67
+00:03:46,000 --> 00:03:48,000
+to take that machine offline.
+
+68
+00:03:48,000 --> 00:03:50,000
+Take that server, take that router, take that firewall offline.
+
+69
+00:03:50,000 --> 00:03:52,000
+That's going to result in downtown.
+
+70
+00:03:52,000 --> 00:03:56,000
+Planning for downtown involves understanding, hey, how is this going to impact the business?
+
+71
+00:03:56,000 --> 00:03:58,000
+When is the best time to do this?
+
+72
+00:03:58,000 --> 00:04:02,000
+So security risk can arise if downtime is not properly managed.
+
+73
+00:04:02,000 --> 00:04:07,000
+So just increase the vulnerability um, during system reboots and updates.
+
+74
+00:04:07,000 --> 00:04:08,000
+So.
+
+75
+00:04:09,000 --> 00:04:14,000
+Keep in mind that these down times can come from things like what's called a service restart.
+
+76
+00:04:14,000 --> 00:04:18,000
+So on a server, on a computer, you're basically going to run all kinds of services.
+
+77
+00:04:18,000 --> 00:04:23,000
+Whether you're running something like an FTP service, you're running a directory access service, like
+
+78
+00:04:23,000 --> 00:04:28,000
+an authentication type service on your machine or a print service because you're running a print server.
+
+79
+00:04:29,000 --> 00:04:32,000
+Uh, services or servers are part of a change.
+
+80
+00:04:32,000 --> 00:04:34,000
+Contemporary exposed security vulnerabilities.
+
+81
+00:04:34,000 --> 00:04:39,000
+So if you're changing it and it's not set up correctly, it could introduce the security vulnerabilities,
+
+82
+00:04:39,000 --> 00:04:42,000
+especially if the servers come back online before security.
+
+83
+00:04:42,000 --> 00:04:46,000
+So you can change a service, implement a new one.
+
+84
+00:04:46,000 --> 00:04:52,000
+But because of the default configs and you try to push the system back up before you know it, it's
+
+85
+00:04:52,000 --> 00:04:54,000
+not secure because all the default configs are there.
+
+86
+00:04:54,000 --> 00:04:59,000
+You got a plan to restart or ensure that security measures are properly reinstated right away.
+
+87
+00:04:59,000 --> 00:05:01,000
+Application restarts.
+
+88
+00:05:01,000 --> 00:05:05,000
+Now, restarting an application is a common thing.
+
+89
+00:05:05,000 --> 00:05:06,000
+Maybe it crashed.
+
+90
+00:05:06,000 --> 00:05:08,000
+Maybe it needs a particular update.
+
+91
+00:05:08,000 --> 00:05:13,000
+Restarting application A part of a change might disrupt the security settings or controls.
+
+92
+00:05:13,000 --> 00:05:16,000
+Ensuring the applications maintain the security is vitally important.
+
+93
+00:05:16,000 --> 00:05:21,000
+Not to mention, if you restart an application, you disrupt the network and nobody has access to that
+
+94
+00:05:21,000 --> 00:05:22,000
+application.
+
+95
+00:05:22,000 --> 00:05:28,000
+Another super important thing we want to keep in mind is legacy applications, because this is big.
+
+96
+00:05:28,000 --> 00:05:34,000
+Organizations today may seem like they're functioning with their newest and greatest applications out
+
+97
+00:05:34,000 --> 00:05:42,000
+there, but a lot of organizations really do use things that was built in the 1990s, early 2000, and
+
+98
+00:05:42,000 --> 00:05:43,000
+even the 1980s.
+
+99
+00:05:43,000 --> 00:05:45,000
+Yes, that does exist in today's world.
+
+100
+00:05:46,000 --> 00:05:50,000
+When we change things in the system, how does it affect those legacy?
+
+101
+00:05:51,000 --> 00:05:55,000
+Changes in the IT department can particularly impact legacy applications.
+
+102
+00:05:55,000 --> 00:06:00,000
+For example, you may go and you may change a server operating system, but that legacy application
+
+103
+00:06:00,000 --> 00:06:01,000
+that we're using can't run on your new server.
+
+104
+00:06:01,000 --> 00:06:03,000
+Now, what do you do?
+
+105
+00:06:03,000 --> 00:06:09,000
+These older apps might not be compatible with new system security protocol and create a security gap.
+
+106
+00:06:09,000 --> 00:06:14,000
+How changes affect legacy systems and planning for this is going to be important.
+
+107
+00:06:14,000 --> 00:06:17,000
+Now it's different for every organization, but it's something to keep in mind.
+
+108
+00:06:19,000 --> 00:06:25,000
+Keep in mind it is a web of dependency.
+
+109
+00:06:25,000 --> 00:06:29,000
+Let me highlight that because if there's one thing we know it nothing.
+
+110
+00:06:29,000 --> 00:06:30,000
+And it stands alone.
+
+111
+00:06:31,000 --> 00:06:35,000
+Everything in it is dependent on something else.
+
+112
+00:06:35,000 --> 00:06:39,000
+An IT system is a web of different technology that allows for you to send an email from your desk.
+
+113
+00:06:39,000 --> 00:06:47,000
+You know how many devices went into play from your workstation to your switch to your, uh, course
+
+114
+00:06:47,000 --> 00:06:54,000
+switches, to your router, to your to your firewall, to your router, to the ISP network, to the
+
+115
+00:06:54,000 --> 00:06:57,000
+SMTp, SMTp servers, uh, in your network.
+
+116
+00:06:57,000 --> 00:06:59,000
+Oh, my God, it's too much.
+
+117
+00:06:59,000 --> 00:07:05,000
+When we make changes in one component, like an update in a software, this can affect that dependency
+
+118
+00:07:05,000 --> 00:07:06,000
+within systems.
+
+119
+00:07:06,000 --> 00:07:09,000
+You change, your server changes.
+
+120
+00:07:10,000 --> 00:07:16,000
+Let's say you change a switch that can change affects the settings on on the computers in the network.
+
+121
+00:07:16,000 --> 00:07:18,000
+It can affect the router, bringing the entire network down.
+
+122
+00:07:19,000 --> 00:07:21,000
+Understanding and managing these dependencies is critical.
+
+123
+00:07:21,000 --> 00:07:25,000
+You don't want to prevent any type of security issues such as even exposing vulnerabilities.
+
+124
+00:07:25,000 --> 00:07:26,000
+Documentation.
+
+125
+00:07:26,000 --> 00:07:33,000
+It is super important to have proper documentation of changes essential for maintaining a clear record
+
+126
+00:07:33,000 --> 00:07:35,000
+of all changes, their reason, and their impact.
+
+127
+00:07:35,000 --> 00:07:40,000
+So anytime you make a change, have good documentation of what happened with these changes.
+
+128
+00:07:40,000 --> 00:07:44,000
+Understand the importance and scope of the documentation is going to be important.
+
+129
+00:07:46,000 --> 00:07:47,000
+Now.
+
+130
+00:07:47,000 --> 00:07:49,000
+When you do changes, please update your diagrams.
+
+131
+00:07:49,000 --> 00:07:52,000
+There's going to be tons of diagrams across your network.
+
+132
+00:07:52,000 --> 00:07:54,000
+I have your network and systems diagram.
+
+133
+00:07:54,000 --> 00:07:57,000
+Changes in IT infrastructure need to be accurately reflected in all kinds of diagrams.
+
+134
+00:07:57,000 --> 00:08:01,000
+These diagrams are critical for assessing the potential impact of changes.
+
+135
+00:08:01,000 --> 00:08:07,000
+Way too often do we have all kinds of network diagrams we have, like the layout of your network, your
+
+136
+00:08:07,000 --> 00:08:12,000
+IP addressing scheme, where devices are located, and then people implement changes and never update
+
+137
+00:08:12,000 --> 00:08:12,000
+the diagram.
+
+138
+00:08:12,000 --> 00:08:17,000
+And then you look at the diagram a few years later to see how to rebuild the system.
+
+139
+00:08:17,000 --> 00:08:20,000
+Maybe because you had some kind of disaster and you can't rebuild it because it's outdated.
+
+140
+00:08:21,000 --> 00:08:23,000
+When you change, you're going to have.
+
+141
+00:08:23,000 --> 00:08:24,000
+When things change.
+
+142
+00:08:24,000 --> 00:08:29,000
+Are you updated all the corresponding security policies, for example, or procedures that needs to
+
+143
+00:08:29,000 --> 00:08:30,000
+get updated?
+
+144
+00:08:30,000 --> 00:08:33,000
+Any change in it might require update to security policies.
+
+145
+00:08:33,000 --> 00:08:35,000
+You may have change management procedure.
+
+146
+00:08:35,000 --> 00:08:38,000
+This is going to document how to manage the change itself.
+
+147
+00:08:38,000 --> 00:08:44,000
+Now if you're doing software, if you're managing software changes within software or configurations
+
+148
+00:08:44,000 --> 00:08:47,000
+on certain devices, you can have what's called version control.
+
+149
+00:08:47,000 --> 00:08:51,000
+So this is going to be like version one, version two, version three, version 1.1, 1.2.
+
+150
+00:08:51,000 --> 00:08:56,000
+And every version comes with a different set of configurations and or quote unquote changes.
+
+151
+00:08:56,000 --> 00:09:02,000
+So version control refers refers to the practice of managing changes to software called configuration.
+
+152
+00:09:02,000 --> 00:09:04,000
+All the data usually in some kind of collaborative thing.
+
+153
+00:09:04,000 --> 00:09:05,000
+So.
+
+154
+00:09:06,000 --> 00:09:10,000
+There are tons of software that allows you to do this.
+
+155
+00:09:10,000 --> 00:09:11,000
+All right.
+
+156
+00:09:11,000 --> 00:09:16,000
+Uh, GitHub, for example, is where they would manage software configuration or actually software development
+
+157
+00:09:16,000 --> 00:09:17,000
+changes.
+
+158
+00:09:17,000 --> 00:09:23,000
+They track changes, manages historical history, and ensure an integrity and security of the software.
+
+159
+00:09:23,000 --> 00:09:23,000
+For example version.
+
+160
+00:09:24,000 --> 00:09:26,000
+Let's say you're managing the configuration of this firewall.
+
+161
+00:09:26,000 --> 00:09:30,000
+So let's say this firewall has version 2.0 uh, on it.
+
+162
+00:09:30,000 --> 00:09:34,000
+So version 2.0 has all these patches and these configs.
+
+163
+00:09:34,000 --> 00:09:39,000
+Then you could say version 2.1 has all these different changes, maybe restricted new things and these
+
+164
+00:09:39,000 --> 00:09:42,000
+patches and it has this particular configuration and so on and so on.
+
+165
+00:09:42,000 --> 00:09:45,000
+So version control is really important.
+
+166
+00:09:46,000 --> 00:09:49,000
+All right once again guys managing changes is super important.
+
+167
+00:09:49,000 --> 00:09:52,000
+Keep in mind that because it is a web.
+
+168
+00:09:53,000 --> 00:10:01,000
+Anytime you make a change, keep in mind all the technical problems that can go wrong with these changes
+
+169
+00:10:01,000 --> 00:10:05,000
+and make sure to manage them well so they don't bring your systems down.
+
diff --git a/24 - Change Management/003 Quick Quiz.html b/24 - Change Management/003 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..011a9d4a387d5f898e31ea111aa2a750c65a36b5
--- /dev/null
+++ b/24 - Change Management/003 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/25 - Resilience and Recovery/001 High Availability OB 3.4_en.srt b/25 - Resilience and Recovery/001 High Availability OB 3.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..4eb3cb74674f0954e1725651192d0653f89e671a
--- /dev/null
+++ b/25 - Resilience and Recovery/001 High Availability OB 3.4_en.srt
@@ -0,0 +1,312 @@
+1
+00:00:00,000 --> 00:00:04,000
+Organizations today all strive for what's called high availability.
+
+2
+00:00:04,000 --> 00:00:08,000
+You see, if you remember the CIA triad confidentiality, integrity.
+
+3
+00:00:08,000 --> 00:00:10,000
+Well, the last eight was availability.
+
+4
+00:00:10,000 --> 00:00:13,000
+So it's one of the core tenets of information security.
+
+5
+00:00:13,000 --> 00:00:15,000
+So availability is about keeping your systems up.
+
+6
+00:00:15,000 --> 00:00:20,000
+It doesn't matter how much good security you have, how much good firewalls and encryptions and intrusion
+
+7
+00:00:20,000 --> 00:00:22,000
+detection and prevention systems you have.
+
+8
+00:00:22,000 --> 00:00:27,000
+If your systems go down, it's kind of your systems are kind of useless because people can't do their
+
+9
+00:00:27,000 --> 00:00:27,000
+work.
+
+10
+00:00:27,000 --> 00:00:32,000
+The organization can't make money if their web servers are offline or if the user software doesn't work.
+
+11
+00:00:32,000 --> 00:00:35,000
+So what we want to do is we want to build high availability.
+
+12
+00:00:35,000 --> 00:00:41,000
+So high availability is about ensuring that systems, applications and services are available to users
+
+13
+00:00:41,000 --> 00:00:46,000
+over a desired period, typically aiming for what's called near continuous availability.
+
+14
+00:00:46,000 --> 00:00:53,000
+Now, near continuous availability is going to be trying to keep a high uptime or a very big uptime.
+
+15
+00:00:53,000 --> 00:01:00,000
+Now, it's probably logically or maybe even physically impossible to have 100% uptime as there's really,
+
+16
+00:01:00,000 --> 00:01:03,000
+you know, the only thing that's 100% in this world is death.
+
+17
+00:01:03,000 --> 00:01:12,000
+So the only thing that you can do to get close to that 100% is probably going to be something like 99.9999999%
+
+18
+00:01:12,000 --> 00:01:12,000
+uptime.
+
+19
+00:01:12,000 --> 00:01:16,000
+You're never going to get that 100%, but you want near continuous availability.
+
+20
+00:01:16,000 --> 00:01:19,000
+And what that means is very low downtime.
+
+21
+00:01:20,000 --> 00:01:27,000
+It involves designing systems that can that can prevent or quickly recover from failures, thereby minimizing
+
+22
+00:01:27,000 --> 00:01:29,000
+or reducing downtime.
+
+23
+00:01:29,000 --> 00:01:30,000
+So what exactly is this?
+
+24
+00:01:30,000 --> 00:01:36,000
+So what we are doing is we're going to build our systems in a way that if they get a hit, if a drive
+
+25
+00:01:36,000 --> 00:01:38,000
+blow, maybe they have a Raid system in place.
+
+26
+00:01:38,000 --> 00:01:42,000
+If a system goes offline or a server goes offline, we can continuously work.
+
+27
+00:01:42,000 --> 00:01:46,000
+Now in this video, I want to talk about two technologies that's going to allow that.
+
+28
+00:01:46,000 --> 00:01:49,000
+The first one is going to be a load balancer.
+
+29
+00:01:49,000 --> 00:01:51,000
+So what exactly is a load balancer?
+
+30
+00:01:51,000 --> 00:01:55,000
+Well as you can imagine balances a load like literally that's what it does.
+
+31
+00:01:55,000 --> 00:01:57,000
+Here's a here's a picture of a hardware load balancer.
+
+32
+00:01:57,000 --> 00:01:59,000
+The our software load balancer.
+
+33
+00:01:59,000 --> 00:02:00,000
+But this is a hardware one.
+
+34
+00:02:00,000 --> 00:02:05,000
+So load balancing is a technique used to distribute workloads across multiple servers.
+
+35
+00:02:06,000 --> 00:02:10,000
+In the event one server becomes unavailable due to hardware failure or some kind of maintenance, the
+
+36
+00:02:10,000 --> 00:02:12,000
+load balancer can redirect traffic to others.
+
+37
+00:02:12,000 --> 00:02:14,000
+So let's say this is the load balancer.
+
+38
+00:02:14,000 --> 00:02:15,000
+All right.
+
+39
+00:02:15,000 --> 00:02:17,000
+Let's just say this is this device for now.
+
+40
+00:02:18,000 --> 00:02:21,000
+In the back of it you're going to plug in three three servers right.
+
+41
+00:02:21,000 --> 00:02:25,000
+Three desktops or three rack servers whatever you have.
+
+42
+00:02:25,000 --> 00:02:30,000
+And basically as traffic comes into the load balancer, the load balancer distributes the load to all
+
+43
+00:02:30,000 --> 00:02:33,000
+the servers, sometimes evenly.
+
+44
+00:02:33,000 --> 00:02:36,000
+And you can even distribute the some gets more than others depending on how you want to configure it.
+
+45
+00:02:36,000 --> 00:02:42,000
+Now what happens is if one of those servers goes offline, then the load balancer is going to send all
+
+46
+00:02:42,000 --> 00:02:44,000
+the traffic to the remaining servers.
+
+47
+00:02:44,000 --> 00:02:48,000
+That way, if a if a machine goes offline, it doesn't affect your entire network.
+
+48
+00:02:48,000 --> 00:02:49,000
+Now I have a picture of this.
+
+49
+00:02:49,000 --> 00:02:53,000
+So let's say you have clients that are using the internet.
+
+50
+00:02:54,000 --> 00:02:58,000
+And here you have this device that we just spoke about, this hardware load balancer.
+
+51
+00:02:58,000 --> 00:03:01,000
+Again it could be a software load balancer.
+
+52
+00:03:01,000 --> 00:03:05,000
+Now all these application servers are connected to basically this load balancer.
+
+53
+00:03:05,000 --> 00:03:06,000
+We're not using the software.
+
+54
+00:03:06,000 --> 00:03:11,000
+What if this load balancer if this server dies then the load balancer will send all traffic here.
+
+55
+00:03:11,000 --> 00:03:16,000
+This is great because if one of these machines goes offline, the other machine gets all the traffic.
+
+56
+00:03:16,000 --> 00:03:21,000
+Now it's going to probably run a little slower, but at least your system doesn't become unavailable.
+
+57
+00:03:21,000 --> 00:03:23,000
+And that's the key here.
+
+58
+00:03:23,000 --> 00:03:26,000
+The other thing you might want to implement is something we call a cluster.
+
+59
+00:03:26,000 --> 00:03:32,000
+So clustering refers to a group of interconnected computers or servers that work together keyword as
+
+60
+00:03:32,000 --> 00:03:33,000
+a single system.
+
+61
+00:03:33,000 --> 00:03:34,000
+So here's a cluster.
+
+62
+00:03:35,000 --> 00:03:38,000
+You see all three of these machines are connected to a central storage.
+
+63
+00:03:38,000 --> 00:03:42,000
+Computers that are connected to these machines don't see three machines.
+
+64
+00:03:42,000 --> 00:03:45,000
+They actually see one computer.
+
+65
+00:03:45,000 --> 00:03:50,000
+So in in a cluster all these machines are working as one computer.
+
+66
+00:03:50,000 --> 00:03:54,000
+So clusters offer high availability as they can provide automatic failover.
+
+67
+00:03:54,000 --> 00:03:57,000
+For example, if one of these machines dies, computer one and two can kick in.
+
+68
+00:03:57,000 --> 00:04:00,000
+If one of the node fails, the other node takes over.
+
+69
+00:04:00,000 --> 00:04:05,000
+Clustering can be used for a variety of purposes, including during storage, computation, and service
+
+70
+00:04:05,000 --> 00:04:06,000
+availability.
+
+71
+00:04:06,000 --> 00:04:07,000
+Here's the thing.
+
+72
+00:04:07,000 --> 00:04:09,000
+The great thing about clustering is that.
+
+73
+00:04:10,000 --> 00:04:16,000
+You can combine the CPU power so a cluster can actually take one large task, and all the CPU power
+
+74
+00:04:16,000 --> 00:04:20,000
+can then be used across three machines to solve that large task.
+
+75
+00:04:20,000 --> 00:04:22,000
+Think of like rendering a giant movie file.
+
+76
+00:04:22,000 --> 00:04:27,000
+You can have a cluster utilize all their CPUs and memory to render a giant movie file.
+
+77
+00:04:28,000 --> 00:04:33,000
+All right, so keep in mind that these two technologies, clustering and load balancing, is one of
+
+78
+00:04:33,000 --> 00:04:35,000
+the best ways to build high available networks.
+
diff --git a/25 - Resilience and Recovery/002 Site Selection OB 3.4_en.srt b/25 - Resilience and Recovery/002 Site Selection OB 3.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..6f4b8fbfbac07fb711f5b3cddf2653e794f25c85
--- /dev/null
+++ b/25 - Resilience and Recovery/002 Site Selection OB 3.4_en.srt
@@ -0,0 +1,636 @@
+1
+00:00:00,000 --> 00:00:05,000
+If you work in a large company, maybe a fortune 1000 company, more than likely that organization is
+
+2
+00:00:05,000 --> 00:00:09,000
+going to have their own data centers, and they're probably not going to have one data center.
+
+3
+00:00:09,000 --> 00:00:11,000
+They're probably going to have multiple data centers.
+
+4
+00:00:11,000 --> 00:00:16,000
+Now, the question is what happens when one of these data centers go offline?
+
+5
+00:00:16,000 --> 00:00:17,000
+Then what do we do?
+
+6
+00:00:17,000 --> 00:00:18,000
+How do we fix that?
+
+7
+00:00:18,000 --> 00:00:18,000
+Right.
+
+8
+00:00:18,000 --> 00:00:21,000
+Do we move everything to other data centers?
+
+9
+00:00:21,000 --> 00:00:23,000
+Is there other data centers available?
+
+10
+00:00:23,000 --> 00:00:28,000
+In this video I want to talk about what can we do if a data center goes offline.
+
+11
+00:00:29,000 --> 00:00:33,000
+What happens if one of the main sites that we process information goes offline?
+
+12
+00:00:33,000 --> 00:00:33,000
+Now?
+
+13
+00:00:33,000 --> 00:00:39,000
+It could be because there's some kind of earthquake, hurricane, flood, power outages across the building
+
+14
+00:00:39,000 --> 00:00:41,000
+that took the entire building out.
+
+15
+00:00:41,000 --> 00:00:42,000
+Now, what do you do?
+
+16
+00:00:42,000 --> 00:00:43,000
+Well, let's get into this.
+
+17
+00:00:43,000 --> 00:00:49,000
+So you're going to now have to move your processing to another site.
+
+18
+00:00:49,000 --> 00:00:51,000
+And we got some options.
+
+19
+00:00:51,000 --> 00:00:54,000
+You're going to be either using a hot or cold or warm site.
+
+20
+00:00:54,000 --> 00:01:00,000
+Think about the geographic dispersion of the data or the different sites that you have.
+
+21
+00:01:00,000 --> 00:01:05,000
+Now I want to get into in this video, I want to talk about these particular sites and how we're going
+
+22
+00:01:05,000 --> 00:01:06,000
+to maintain continuity.
+
+23
+00:01:06,000 --> 00:01:10,000
+When one of our data centers goes down, the first thing we want to talk about is what's called a hot
+
+24
+00:01:10,000 --> 00:01:11,000
+site.
+
+25
+00:01:11,000 --> 00:01:14,000
+Now, for your exam, you want to know the difference between hot, warm and cold sites.
+
+26
+00:01:14,000 --> 00:01:16,000
+So let's let's get through this.
+
+27
+00:01:17,000 --> 00:01:20,000
+So let's say an organization has a data center.
+
+28
+00:01:20,000 --> 00:01:23,000
+Let's say they only have one data center for the entire organization.
+
+29
+00:01:23,000 --> 00:01:30,000
+But that data center has a major electrical problem, and the entire data center lost power could be
+
+30
+00:01:30,000 --> 00:01:33,000
+the power provider lost power also.
+
+31
+00:01:33,000 --> 00:01:36,000
+So now that data center is offline, well, what happens now?
+
+32
+00:01:36,000 --> 00:01:37,000
+Does the organization does everybody just go home?
+
+33
+00:01:37,000 --> 00:01:38,000
+No.
+
+34
+00:01:38,000 --> 00:01:41,000
+The organization can opt for what's called a hot site.
+
+35
+00:01:41,000 --> 00:01:43,000
+Now, a hot site is basically like a backup site.
+
+36
+00:01:43,000 --> 00:01:48,000
+Basically, it's a fully functional equipped data center that can be switched immediately in case the
+
+37
+00:01:48,000 --> 00:01:49,000
+primary ones fail.
+
+38
+00:01:49,000 --> 00:01:54,000
+So basically in the hot side, it basically has all the equipment.
+
+39
+00:01:54,000 --> 00:01:56,000
+It may have the data also.
+
+40
+00:01:56,000 --> 00:02:01,000
+So basically the organization can just switch their processing right over to this hot site.
+
+41
+00:02:01,000 --> 00:02:04,000
+Now it mirrors critical data and application.
+
+42
+00:02:04,000 --> 00:02:06,000
+Hot sites provide immediate failover capability.
+
+43
+00:02:06,000 --> 00:02:07,000
+So this is great.
+
+44
+00:02:07,000 --> 00:02:11,000
+These things the moment something fail they can go right into these hot sites.
+
+45
+00:02:11,000 --> 00:02:14,000
+The problem with hot sites is of course going to be cost.
+
+46
+00:02:14,000 --> 00:02:15,000
+There's going to be a major problem.
+
+47
+00:02:15,000 --> 00:02:20,000
+They ensure minimal or no downtime, making them essential for operations and requiring high availability.
+
+48
+00:02:20,000 --> 00:02:26,000
+So this is all great the moment one thing goes down, the moment your primary site goes down, you can
+
+49
+00:02:26,000 --> 00:02:26,000
+switch to the hot site.
+
+50
+00:02:26,000 --> 00:02:29,000
+Now remember for your exam the major down.
+
+51
+00:02:29,000 --> 00:02:36,000
+The major problem with a hot site is the cost, because a lot of times these sites are rented facility.
+
+52
+00:02:36,000 --> 00:02:42,000
+And what happens is, if you need a facility that has all the equipment, has continuous data, or maybe
+
+53
+00:02:42,000 --> 00:02:45,000
+you're replicating data to it all the time, basically you're using it quite often.
+
+54
+00:02:45,000 --> 00:02:47,000
+You're probably going to spend a whole lot of money.
+
+55
+00:02:47,000 --> 00:02:50,000
+So this is the most expensive site you can have.
+
+56
+00:02:50,000 --> 00:02:53,000
+The other one you're going to have is what's called a cold site.
+
+57
+00:02:53,000 --> 00:02:56,000
+This is going to be the cheapest option when it comes to sites.
+
+58
+00:02:56,000 --> 00:03:02,000
+A cold site is a location equipped with the necessary infrastructure to support IT operations, but
+
+59
+00:03:02,000 --> 00:03:04,000
+without computers, data and application.
+
+60
+00:03:04,000 --> 00:03:06,000
+So it doesn't have those things.
+
+61
+00:03:06,000 --> 00:03:12,000
+You see, cold sites may just be a warehouse that basically has Hvac and electricity.
+
+62
+00:03:12,000 --> 00:03:17,000
+So basically have heating, ventilation and AC so you can build an IT infrastructure, but it doesn't
+
+63
+00:03:17,000 --> 00:03:21,000
+come with routers and switches and computers.
+
+64
+00:03:21,000 --> 00:03:24,000
+It requires time and effort to become operational.
+
+65
+00:03:24,000 --> 00:03:29,000
+Of course cold sites or cost effective for less critical operation.
+
+66
+00:03:29,000 --> 00:03:31,000
+Now your question is why would you want this?
+
+67
+00:03:31,000 --> 00:03:36,000
+And the real reason you want this is maybe the data center that went offline wasn't processing super
+
+68
+00:03:36,000 --> 00:03:37,000
+critical data.
+
+69
+00:03:37,000 --> 00:03:42,000
+Because if you think about this, if you have to go out and you have to get servers and routers and
+
+70
+00:03:42,000 --> 00:03:48,000
+switches and and get all your data loaded up and configure it, it may take weeks so a hot site can
+
+71
+00:03:48,000 --> 00:03:52,000
+become ready in minutes, seconds, or maybe even hours.
+
+72
+00:03:52,000 --> 00:03:53,000
+But a cold site?
+
+73
+00:03:53,000 --> 00:03:55,000
+This can take weeks to get up.
+
+74
+00:03:55,000 --> 00:04:02,000
+They offer backup options for recovery, but no longer restoration times compared to hot sites, so
+
+75
+00:04:02,000 --> 00:04:05,000
+they're not the best option out there.
+
+76
+00:04:06,000 --> 00:04:08,000
+Now warm sites.
+
+77
+00:04:08,000 --> 00:04:11,000
+This is the middle ground between hot and cold sites, obviously.
+
+78
+00:04:11,000 --> 00:04:12,000
+Right.
+
+79
+00:04:12,000 --> 00:04:14,000
+Hot cold hot cold.
+
+80
+00:04:14,000 --> 00:04:14,000
+Obviously warm.
+
+81
+00:04:15,000 --> 00:04:20,000
+It contains some pre-installed and configured equipment requiring less time to become operational than
+
+82
+00:04:20,000 --> 00:04:20,000
+a cold site.
+
+83
+00:04:20,000 --> 00:04:24,000
+Warm site is the balance between the cost and the speed of recovery.
+
+84
+00:04:24,000 --> 00:04:27,000
+They're suitable for applications that can tolerate a short period of downtime.
+
+85
+00:04:27,000 --> 00:04:29,000
+So here's what these have.
+
+86
+00:04:29,000 --> 00:04:31,000
+These may have the routers the switches.
+
+87
+00:04:31,000 --> 00:04:34,000
+Uh it'll have the heat and ventilation and AC.
+
+88
+00:04:34,000 --> 00:04:39,000
+They may have some particular servers, but you may have to bring some specialized equipment and you're
+
+89
+00:04:39,000 --> 00:04:40,000
+going to have to bring your data.
+
+90
+00:04:40,000 --> 00:04:47,000
+So a hot site, you're probably going to be able to start processing there in maybe seconds, minutes,
+
+91
+00:04:47,000 --> 00:04:48,000
+hours.
+
+92
+00:04:48,000 --> 00:04:51,000
+A cold site can take weeks or months.
+
+93
+00:04:51,000 --> 00:04:54,000
+A hot site a warm site should generally take about a week.
+
+94
+00:04:54,000 --> 00:04:56,000
+Time to get your data up and running.
+
+95
+00:04:56,000 --> 00:05:02,000
+It may take a few days now, if you can tolerate just a few days or just a really short downtime, a
+
+96
+00:05:02,000 --> 00:05:08,000
+warm site is probably the best option because it is a lot cheaper than a hot site, but it's more expensive
+
+97
+00:05:08,000 --> 00:05:09,000
+than a warm site.
+
+98
+00:05:09,000 --> 00:05:15,000
+Now, when you're thinking about, uh, your your location of your data center.
+
+99
+00:05:15,000 --> 00:05:23,000
+All right, you want to make sure that you disperse your data centers across different geographic regions,
+
+100
+00:05:24,000 --> 00:05:24,000
+okay?
+
+101
+00:05:24,000 --> 00:05:30,000
+This is distributed IT resources across different geographic locations, because you don't want to have
+
+102
+00:05:30,000 --> 00:05:33,000
+everything located in just New York.
+
+103
+00:05:33,000 --> 00:05:37,000
+What if New York has a major outage of power like we did many years ago?
+
+104
+00:05:37,000 --> 00:05:38,000
+In 2003 or 4?
+
+105
+00:05:38,000 --> 00:05:41,000
+There was a major power outage 2002, 3 or 4, something like that.
+
+106
+00:05:42,000 --> 00:05:44,000
+Well, the entire northeast lost power.
+
+107
+00:05:44,000 --> 00:05:47,000
+So you don't want just everything in the northeast to you.
+
+108
+00:05:47,000 --> 00:05:51,000
+You probably if you're going to put something in northeast, then put something all the way in the southwest,
+
+109
+00:05:51,000 --> 00:05:54,000
+put something that's geographically dispersed that way.
+
+110
+00:05:54,000 --> 00:05:55,000
+You know what?
+
+111
+00:05:55,000 --> 00:05:59,000
+If something affects one section of the country, it isn't going to affect, hopefully not the others.
+
+112
+00:05:59,000 --> 00:06:02,000
+So it's associated with local disasters and threats or spreading out.
+
+113
+00:06:02,000 --> 00:06:09,000
+It ensures that an incident in one location doesn't affect the operation or doesn't bring down the entire
+
+114
+00:06:09,000 --> 00:06:10,000
+operation.
+
+115
+00:06:10,000 --> 00:06:17,000
+Now, another thing we can do when we're building good high availability systems is to have what's called
+
+116
+00:06:17,000 --> 00:06:18,000
+platform diversity.
+
+117
+00:06:18,000 --> 00:06:22,000
+And this is going to be building your systems across many kinds of platforms.
+
+118
+00:06:22,000 --> 00:06:26,000
+So one platform goes down, you'll be able to bring your systems up.
+
+119
+00:06:26,000 --> 00:06:31,000
+So it's balancing the benefits of diverse technology platform and the challenges of managing a complex
+
+120
+00:06:31,000 --> 00:06:31,000
+things.
+
+121
+00:06:31,000 --> 00:06:35,000
+For example, if you build applications that supports different kinds of platforms that you can install,
+
+122
+00:06:35,000 --> 00:06:40,000
+like Linux and Windows and so on, if one goes down, you have issues, you can always move it over
+
+123
+00:06:40,000 --> 00:06:40,000
+to something else.
+
+124
+00:06:40,000 --> 00:06:43,000
+But of course, this is complex to manage and set up.
+
+125
+00:06:44,000 --> 00:06:46,000
+The other one is multi cloud system.
+
+126
+00:06:46,000 --> 00:06:52,000
+Now there's basically three major cloud providers in today's world that we can use whether it's Amazon's
+
+127
+00:06:52,000 --> 00:06:53,000
+AWS Microsoft Azure.
+
+128
+00:06:53,000 --> 00:06:54,000
+So the Google Cloud.
+
+129
+00:06:55,000 --> 00:06:57,000
+What are you using right now at Tia?
+
+130
+00:06:57,000 --> 00:06:59,000
+We use Amazon's AWS.
+
+131
+00:06:59,000 --> 00:07:04,000
+Now we don't use a multi cloud system because that would require us to have multiple providers.
+
+132
+00:07:04,000 --> 00:07:09,000
+In other words, we set up our systems across multiple cloud providers that we have.
+
+133
+00:07:09,000 --> 00:07:11,000
+One providers have an issue like AWS.
+
+134
+00:07:11,000 --> 00:07:12,000
+We'll just switch over.
+
+135
+00:07:12,000 --> 00:07:14,000
+Now our business is not mission critical like that.
+
+136
+00:07:14,000 --> 00:07:17,000
+But major financial institutions may do something like this.
+
+137
+00:07:17,000 --> 00:07:23,000
+So instead of being stuck with one cloud service provider such as Amazon or CSP, they're going to have
+
+138
+00:07:23,000 --> 00:07:24,000
+a mixture of them.
+
+139
+00:07:24,000 --> 00:07:30,000
+Now, one thing you may want to be familiar with for your exam is called Continuity of Operations.
+
+140
+00:07:30,000 --> 00:07:36,000
+This refers to an organization's ability to continue its essential function, even in the face of a
+
+141
+00:07:36,000 --> 00:07:38,000
+major disruption or disaster.
+
+142
+00:07:38,000 --> 00:07:40,000
+Now, I want you guys to think about this.
+
+143
+00:07:40,000 --> 00:07:45,000
+Do you think Amazon has a continuity of operations or co-op?
+
+144
+00:07:45,000 --> 00:07:46,000
+Do you guys think they have that?
+
+145
+00:07:46,000 --> 00:07:52,000
+Yeah, because I'm pretty sure Amazon websites and systems have gone down before, but you haven't noticed
+
+146
+00:07:52,000 --> 00:07:56,000
+it because they have really good continuous continuity of operations.
+
+147
+00:07:56,000 --> 00:08:00,000
+In other words, they continuously function even though some data centers are offline, servers are
+
+148
+00:08:00,000 --> 00:08:03,000
+broken, hard drives are out, some things lost power, and so on.
+
+149
+00:08:04,000 --> 00:08:09,000
+Ensure key business processes IT services remain available and functional during and after cyber incidents.
+
+150
+00:08:09,000 --> 00:08:16,000
+Now the big thing here is to minimize downtime or reduce the impact on business when it comes to selecting
+
+151
+00:08:16,000 --> 00:08:22,000
+sites in an organization or selecting sites to manage your business continuity, keep in mind that it's
+
+152
+00:08:22,000 --> 00:08:23,000
+really specific to a company.
+
+153
+00:08:23,000 --> 00:08:27,000
+Some companies has the budget to go with a hot site versus some companies that can't.
+
+154
+00:08:27,000 --> 00:08:34,000
+But you got to keep in mind, if you go with a cheaper option and you go down, how much money are you
+
+155
+00:08:34,000 --> 00:08:35,000
+actually losing?
+
+156
+00:08:35,000 --> 00:08:38,000
+There's if you're out of business for a day, you lose a couple of million dollars.
+
+157
+00:08:38,000 --> 00:08:41,000
+If that's the case, maybe it's best to go to warm or hot site.
+
+158
+00:08:41,000 --> 00:08:43,000
+If not, maybe you can go to cold site.
+
+159
+00:08:43,000 --> 00:08:45,000
+So be careful how you select sites.
+
diff --git a/25 - Resilience and Recovery/003 Capacity Planning OB 3.4_en.srt b/25 - Resilience and Recovery/003 Capacity Planning OB 3.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..a52f67232481b35b864b2d06b6e2f7c4f9a39ef5
--- /dev/null
+++ b/25 - Resilience and Recovery/003 Capacity Planning OB 3.4_en.srt
@@ -0,0 +1,284 @@
+1
+00:00:00,000 --> 00:00:06,000
+If you manage information security systems, you have to think about what are the needs right now,
+
+2
+00:00:06,000 --> 00:00:07,000
+how much people do I need?
+
+3
+00:00:07,000 --> 00:00:08,000
+How much technology do I need?
+
+4
+00:00:08,000 --> 00:00:12,000
+How much infrastructure equipment do I need to meet the current needs of the organization?
+
+5
+00:00:12,000 --> 00:00:16,000
+But you should also be thinking about needs in the future.
+
+6
+00:00:16,000 --> 00:00:21,000
+You see, what I'm talking about is called capacity planning, and this involves forecasting and preparing
+
+7
+00:00:21,000 --> 00:00:27,000
+for the future resources needed to manage information information security effectively.
+
+8
+00:00:28,000 --> 00:00:32,000
+This is about do we have adequate staff?
+
+9
+00:00:32,000 --> 00:00:38,000
+I mean, something as simple as do we have adequate staff right now to manage the security function?
+
+10
+00:00:38,000 --> 00:00:42,000
+Right now as this organization grows, how much more staff are we going to need?
+
+11
+00:00:42,000 --> 00:00:45,000
+How much more technology infrastructure are we going to need?
+
+12
+00:00:45,000 --> 00:00:47,000
+So that's what this is all about.
+
+13
+00:00:47,000 --> 00:00:52,000
+It includes the assessment of current capabilities, like what kind of capabilities do we have right
+
+14
+00:00:52,000 --> 00:00:55,000
+now and the anticipation of future needs.
+
+15
+00:00:55,000 --> 00:01:01,000
+Proper capacity ensures that an organization has adequate resources to handle current and future cybersecurity
+
+16
+00:01:01,000 --> 00:01:05,000
+challenges without overextending or underutilizing its assets.
+
+17
+00:01:05,000 --> 00:01:08,000
+So I want to bring this up under utilization.
+
+18
+00:01:08,000 --> 00:01:11,000
+Sometimes an organization is over capacitated.
+
+19
+00:01:11,000 --> 00:01:16,000
+In other words, they have way too many people, way too much technology working there that they're
+
+20
+00:01:16,000 --> 00:01:17,000
+not being utilized effectively.
+
+21
+00:01:17,000 --> 00:01:19,000
+Basically, they're wasting money.
+
+22
+00:01:19,000 --> 00:01:24,000
+And then you have many organizations that have worked way too much for in other words, the resources
+
+23
+00:01:24,000 --> 00:01:25,000
+are basically over utilized.
+
+24
+00:01:25,000 --> 00:01:27,000
+In other words, they're overextended.
+
+25
+00:01:27,000 --> 00:01:32,000
+In other words, somebody's working six doing two person's job every single day or two working basically
+
+26
+00:01:32,000 --> 00:01:33,000
+16 hours.
+
+27
+00:01:33,000 --> 00:01:34,000
+So keep that in mind.
+
+28
+00:01:34,000 --> 00:01:36,000
+Now capacity planning this is planning.
+
+29
+00:01:36,000 --> 00:01:39,000
+So we're planning for capacity in the future.
+
+30
+00:01:39,000 --> 00:01:42,000
+So we have to anticipate well how is this organization growing.
+
+31
+00:01:42,000 --> 00:01:44,000
+How much more locations are they going to add.
+
+32
+00:01:44,000 --> 00:01:46,000
+How many new products are they going to add.
+
+33
+00:01:46,000 --> 00:01:50,000
+What kind of what's going to be the new security problems that they're going to have?
+
+34
+00:01:50,000 --> 00:01:52,000
+How much people should we be adding?
+
+35
+00:01:52,000 --> 00:01:58,000
+What kind of technology should we be getting like when it comes to capacity planning, think of people
+
+36
+00:01:58,000 --> 00:02:02,000
+ensuring an organization have enough skilled cybersecurity to handle various tasks, including incident
+
+37
+00:02:02,000 --> 00:02:04,000
+response, risk assessment, system maintenance.
+
+38
+00:02:04,000 --> 00:02:06,000
+People is important, right?
+
+39
+00:02:06,000 --> 00:02:08,000
+People is what does the security function?
+
+40
+00:02:08,000 --> 00:02:11,000
+Do you have adequate people right now to do the task?
+
+41
+00:02:11,000 --> 00:02:14,000
+And what are you forecasting in the future?
+
+42
+00:02:14,000 --> 00:02:16,000
+How much people are you going to need?
+
+43
+00:02:16,000 --> 00:02:18,000
+The other thing here we have.
+
+44
+00:02:19,000 --> 00:02:24,000
+Is going to be technology implemented, technologies that can scale with the organization, growth and
+
+45
+00:02:24,000 --> 00:02:25,000
+evolving threat.
+
+46
+00:02:25,000 --> 00:02:28,000
+Now I'm going to show you guys something that's probably not a good buy.
+
+47
+00:02:28,000 --> 00:02:31,000
+This device, this device doesn't scale well.
+
+48
+00:02:31,000 --> 00:02:35,000
+If you buy this device that's generally for a single location, you're probably not going to get more
+
+49
+00:02:35,000 --> 00:02:37,000
+than about 50 computers out of it.
+
+50
+00:02:37,000 --> 00:02:42,000
+So if you plan if you think that your organization is going to be growing to 200 computers in this location,
+
+51
+00:02:42,000 --> 00:02:46,000
+this is probably not a good buy for your organization.
+
+52
+00:02:46,000 --> 00:02:51,000
+But if you forecast that you're going to be growing to 200 people in the next two years, it don't make
+
+53
+00:02:51,000 --> 00:02:52,000
+sense to buy this device.
+
+54
+00:02:52,000 --> 00:02:53,000
+Maybe you only got 40 people now.
+
+55
+00:02:53,000 --> 00:02:58,000
+Maybe it's best to spend the extra money and buy the device that can handle your future growth.
+
+56
+00:02:58,000 --> 00:02:59,000
+Keep abreast of.
+
+57
+00:03:01,000 --> 00:03:06,000
+Keep abreast of and invested in emerging technologies as such, such as AI and machine learning.
+
+58
+00:03:06,000 --> 00:03:12,000
+When when you could or if you could, you want to make sure that you get the latest technology.
+
+59
+00:03:12,000 --> 00:03:16,000
+You don't want to buy outdated technology because outdated technology can't protect against new hacks.
+
+60
+00:03:16,000 --> 00:03:20,000
+Anyhow, the last thing we'll talk about is infrastructure.
+
+61
+00:03:20,000 --> 00:03:23,000
+Is your infrastructure capable?
+
+62
+00:03:23,000 --> 00:03:29,000
+Can it support current and future security needs or anticipated security needs?
+
+63
+00:03:29,000 --> 00:03:35,000
+You see, you got to keep in mind, is the infrastructure scalable if the infrastructure is not scalable?
+
+64
+00:03:36,000 --> 00:03:41,000
+Then what happens is you're going to have to rebuild the entire infrastructure when your company grows.
+
+65
+00:03:41,000 --> 00:03:44,000
+No company that I've ever met wants to stay small.
+
+66
+00:03:44,000 --> 00:03:45,000
+Do you all want to grow?
+
+67
+00:03:45,000 --> 00:03:50,000
+So when you build infrastructure, you have to build infrastructure that you could scale up as needed.
+
+68
+00:03:50,000 --> 00:03:51,000
+So keep that in mind.
+
+69
+00:03:51,000 --> 00:03:55,000
+Keep in mind that capacity planning is something that your IT manager is going to do.
+
+70
+00:03:55,000 --> 00:03:58,000
+But as a security professional, you probably want to keep an eye on it.
+
+71
+00:03:58,000 --> 00:04:03,000
+Because remember, without the without resources, we can't perform our security functions.
+
diff --git a/25 - Resilience and Recovery/004 Testing OB 3.4_en.srt b/25 - Resilience and Recovery/004 Testing OB 3.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..559b081a5d8e8d74d957928150c249d2bb221e47
--- /dev/null
+++ b/25 - Resilience and Recovery/004 Testing OB 3.4_en.srt
@@ -0,0 +1,464 @@
+1
+00:00:00,000 --> 00:00:06,000
+Organizations are going to be making what's called business continuity plans and disaster recovery plans.
+
+2
+00:00:06,000 --> 00:00:11,000
+For example, a disaster recovery plan is going to outline well, if this data center goes down, here
+
+3
+00:00:11,000 --> 00:00:14,000
+are the steps that we're going to use to rebuild that particular data center.
+
+4
+00:00:14,000 --> 00:00:17,000
+So that would be like a disaster recovery plan.
+
+5
+00:00:17,000 --> 00:00:21,000
+A business continuity plan is going to outline well when there's a disaster, what steps are we going
+
+6
+00:00:21,000 --> 00:00:24,000
+to take to continuously function.
+
+7
+00:00:24,000 --> 00:00:26,000
+So just maybe okay, this is a disaster.
+
+8
+00:00:26,000 --> 00:00:28,000
+And this site everybody can go work from home.
+
+9
+00:00:29,000 --> 00:00:35,000
+Now organizations builds all kinds of plans to ensure that they have high availability or they can continuously
+
+10
+00:00:35,000 --> 00:00:36,000
+function.
+
+11
+00:00:36,000 --> 00:00:37,000
+Something breaks.
+
+12
+00:00:37,000 --> 00:00:39,000
+Well, here is a plan and what we're going to do.
+
+13
+00:00:39,000 --> 00:00:39,000
+How to fix it.
+
+14
+00:00:39,000 --> 00:00:41,000
+It's great to have plans.
+
+15
+00:00:41,000 --> 00:00:43,000
+The question is did you test the plan?
+
+16
+00:00:44,000 --> 00:00:49,000
+A plan that hasn't been tested is technically not a very good plan, or a plan that you don't know if
+
+17
+00:00:49,000 --> 00:00:50,000
+it's going to work.
+
+18
+00:00:50,000 --> 00:00:53,000
+So that brings me to this video of testing a plan.
+
+19
+00:00:53,000 --> 00:00:58,000
+So testing provides a vital role in ensuring that the organization's security architecture is resilient,
+
+20
+00:00:58,000 --> 00:00:59,000
+capable of recovering.
+
+21
+00:00:59,000 --> 00:01:02,000
+You see, we don't actually test the plan.
+
+22
+00:01:02,000 --> 00:01:09,000
+We may not be able to recover from a disaster because you may go implement your plan and it may not
+
+23
+00:01:09,000 --> 00:01:10,000
+work.
+
+24
+00:01:10,000 --> 00:01:11,000
+So let's take a look.
+
+25
+00:01:12,000 --> 00:01:19,000
+Let's take a look at a few different testing methods that you should know for your exam.
+
+26
+00:01:19,000 --> 00:01:22,000
+The first one up is called a tabletop test.
+
+27
+00:01:22,000 --> 00:01:27,000
+So let's say you build a disaster recovery plan of how to recover a data center because there was a
+
+28
+00:01:27,000 --> 00:01:30,000
+disaster in the whole thing dropped, and now it has to be rebuilt.
+
+29
+00:01:30,000 --> 00:01:34,000
+And the the plan that you have says how to rebuild that.
+
+30
+00:01:34,000 --> 00:01:37,000
+So you can do a tabletop test.
+
+31
+00:01:37,000 --> 00:01:45,000
+A tabletop test basically is an exercise, um, tabletop exercise discussion based sessions where team
+
+32
+00:01:45,000 --> 00:01:49,000
+members gather to walk through various cybersecurity scenarios.
+
+33
+00:01:49,000 --> 00:01:50,000
+So here's what it is.
+
+34
+00:01:50,000 --> 00:01:53,000
+You're basically going to take the the plan that you have.
+
+35
+00:01:54,000 --> 00:01:58,000
+You can distribute it to everyone and they're going to sit down.
+
+36
+00:01:58,000 --> 00:02:04,000
+They're going to put the plan on the table top in the name table top, and they go through various scenarios.
+
+37
+00:02:04,000 --> 00:02:04,000
+Okay.
+
+38
+00:02:04,000 --> 00:02:07,000
+If this was if the data set got flooded, guys.
+
+39
+00:02:08,000 --> 00:02:09,000
+Let's go through the plan.
+
+40
+00:02:09,000 --> 00:02:10,000
+Let's follow the steps.
+
+41
+00:02:10,000 --> 00:02:11,000
+If it's flooded, we're going to do this.
+
+42
+00:02:11,000 --> 00:02:11,000
+Then we're going to do this.
+
+43
+00:02:11,000 --> 00:02:13,000
+And they all go through this.
+
+44
+00:02:13,000 --> 00:02:18,000
+In a scenario based section, the primary goal is to assess the team's understanding and preparedness
+
+45
+00:02:18,000 --> 00:02:21,000
+for handling the different kinds of cybersecurity incidents.
+
+46
+00:02:21,000 --> 00:02:28,000
+These exercises typically involve key personnel discussing our response to a hypothetical security incidents.
+
+47
+00:02:28,000 --> 00:02:34,000
+Maybe a datacenter got flooded okay, if it was hacked and the machines got encrypted with ransomware,
+
+48
+00:02:34,000 --> 00:02:35,000
+what do we do?
+
+49
+00:02:35,000 --> 00:02:36,000
+So you should have, um.
+
+50
+00:02:37,000 --> 00:02:39,000
+Plans of how to respond to that.
+
+51
+00:02:39,000 --> 00:02:42,000
+So remember tabletop test is just going through scenarios.
+
+52
+00:02:42,000 --> 00:02:45,000
+They're just talking about it on top of a table.
+
+53
+00:02:45,000 --> 00:02:48,000
+Now one of the best tests.
+
+54
+00:02:48,000 --> 00:02:52,000
+But the highest risk you can do is a failover test.
+
+55
+00:02:52,000 --> 00:02:55,000
+So if this data center goes offline, well what are you going to do?
+
+56
+00:02:55,000 --> 00:02:58,000
+You're going to move the process into another data center.
+
+57
+00:02:58,000 --> 00:03:01,000
+Well if you're brave enough you can do a failover test.
+
+58
+00:03:02,000 --> 00:03:07,000
+Critical for verifying the reliability and effectiveness of backup systems and processes.
+
+59
+00:03:07,000 --> 00:03:11,000
+In this one, you are going to intentionally create chaos.
+
+60
+00:03:11,000 --> 00:03:13,000
+You're going to intentionally.
+
+61
+00:03:13,000 --> 00:03:18,000
+This involves intentionally causing a system's primary processing to fail to test whether the fail over
+
+62
+00:03:18,000 --> 00:03:23,000
+process to a secondary can occur smoothly and without significant disruption.
+
+63
+00:03:23,000 --> 00:03:25,000
+So I'm going to give you a good scenario of this.
+
+64
+00:03:25,000 --> 00:03:33,000
+Let's say you have a plan in place that if you run out, let's say your power provider, whoever it
+
+65
+00:03:33,000 --> 00:03:38,000
+is, your power grid loses power and there's no power coming to your building.
+
+66
+00:03:38,000 --> 00:03:45,000
+Maybe you guys have a plan in place and procedures in place that if we lose power, we flip over to
+
+67
+00:03:45,000 --> 00:03:48,000
+generators and upss and nothing really happens.
+
+68
+00:03:48,000 --> 00:03:50,000
+We just go on to alternative power.
+
+69
+00:03:51,000 --> 00:03:56,000
+A fail of a test of your alternative power systems is literally going into the basement of the building
+
+70
+00:03:56,000 --> 00:04:03,000
+and pulling the main breaker and shutting off the main power, and then let everything fail over to
+
+71
+00:04:03,000 --> 00:04:06,000
+your alternative power systems and see what happens.
+
+72
+00:04:06,000 --> 00:04:08,000
+This scenario, you're creating your own downtime.
+
+73
+00:04:08,000 --> 00:04:11,000
+You're literally creating your own chaos.
+
+74
+00:04:11,000 --> 00:04:14,000
+But this is one of the only true way to actually know.
+
+75
+00:04:14,000 --> 00:04:19,000
+Does that secondary system turn on smoothly and without disruptions?
+
+76
+00:04:19,000 --> 00:04:23,000
+It ensures business continuity and data integrity during unexpected failures.
+
+77
+00:04:23,000 --> 00:04:29,000
+You see, if you did what I just told you and you were successful and the company didn't really notice
+
+78
+00:04:29,000 --> 00:04:31,000
+any downtime and didn't or no one noticed.
+
+79
+00:04:31,000 --> 00:04:37,000
+Because the moment you lost power, it all flipped over to the to the alternative power with no issues.
+
+80
+00:04:38,000 --> 00:04:40,000
+Then you know your power system works great.
+
+81
+00:04:40,000 --> 00:04:42,000
+It provides good confidence in it.
+
+82
+00:04:43,000 --> 00:04:45,000
+Now a simulation test.
+
+83
+00:04:45,000 --> 00:04:48,000
+This one is going to be the bridge between those two.
+
+84
+00:04:48,000 --> 00:04:55,000
+So in a simulation these are going to be more realistic control tests designed to mimic the condition
+
+85
+00:04:55,000 --> 00:04:56,000
+of a genuine cyberattack.
+
+86
+00:04:56,000 --> 00:05:01,000
+This involves creating an attack scenario and assessing how well the systems and team respond, typically
+
+87
+00:05:01,000 --> 00:05:05,000
+without the knowledge to most of the organizations to gauge response.
+
+88
+00:05:05,000 --> 00:05:10,000
+So you're going to simulate a fake, uh, attack.
+
+89
+00:05:10,000 --> 00:05:10,000
+All right.
+
+90
+00:05:10,000 --> 00:05:12,000
+You're going to create an attack against a network.
+
+91
+00:05:12,000 --> 00:05:16,000
+I'm calling it fake because it's not a, it's not a it's not not done for malicious reasons.
+
+92
+00:05:16,000 --> 00:05:17,000
+And see how people respond.
+
+93
+00:05:17,000 --> 00:05:19,000
+Some people may know.
+
+94
+00:05:19,000 --> 00:05:20,000
+Some people may not.
+
+95
+00:05:20,000 --> 00:05:25,000
+You're not bringing down an entire system like in a failover test to test another one, but you are
+
+96
+00:05:25,000 --> 00:05:26,000
+coming up with different scenarios.
+
+97
+00:05:28,000 --> 00:05:29,000
+Now parallel processing.
+
+98
+00:05:29,000 --> 00:05:33,000
+Now what if you say, Andrew, I can't do the failover, all right?
+
+99
+00:05:33,000 --> 00:05:37,000
+Because if I do that and something fails, I'm going to be in a whole lot of trouble.
+
+100
+00:05:37,000 --> 00:05:40,000
+Then the next thing you can do is call parallel processing.
+
+101
+00:05:40,000 --> 00:05:44,000
+This testability of an organization to handle operations on multiple systems.
+
+102
+00:05:44,000 --> 00:05:49,000
+Basically, instead of shutting off your primary systems, turn on your backup systems and see how they
+
+103
+00:05:49,000 --> 00:05:50,000
+work.
+
+104
+00:05:50,000 --> 00:05:56,000
+Let's say you have a primary site and you have a backup site in the failover, you turn off the primary
+
+105
+00:05:56,000 --> 00:06:00,000
+site and have the backup site take all the take all of the hits or take all the traffic.
+
+106
+00:06:00,000 --> 00:06:05,000
+In this one you turn, you keep your main site on, and you turn on the backup site to see how they
+
+107
+00:06:05,000 --> 00:06:06,000
+function.
+
+108
+00:06:07,000 --> 00:06:10,000
+And to and maybe restore your data and test the backup site really well.
+
+109
+00:06:10,000 --> 00:06:16,000
+So this one here will really tell you that your alternative systems work, or alternative sites work
+
+110
+00:06:16,000 --> 00:06:19,000
+without a lot of the risk that the failover works that the failover has.
+
+111
+00:06:19,000 --> 00:06:21,000
+But remember, the failover is a true test.
+
+112
+00:06:22,000 --> 00:06:24,000
+So it involves running primary system along the Secretary.
+
+113
+00:06:24,000 --> 00:06:26,000
+Ensure that they can operate in parallel without issues.
+
+114
+00:06:26,000 --> 00:06:30,000
+So that's another reason why you would want to do this okay.
+
+115
+00:06:30,000 --> 00:06:31,000
+These are some tests that we can do.
+
+116
+00:06:31,000 --> 00:06:37,000
+Remember if we have a plan to bring systems up and we don't test them, technically we have no plan.
+
diff --git a/25 - Resilience and Recovery/005 Backups OB 3.4_en.srt b/25 - Resilience and Recovery/005 Backups OB 3.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..7d74ffdad3c031ce99574f3bc0d48be05c9a6fad
--- /dev/null
+++ b/25 - Resilience and Recovery/005 Backups OB 3.4_en.srt
@@ -0,0 +1,672 @@
+1
+00:00:00,000 --> 00:00:03,000
+There's an old saying when it comes to managing it.
+
+2
+00:00:03,000 --> 00:00:03,000
+Data.
+
+3
+00:00:03,000 --> 00:00:05,000
+No backup, no restore.
+
+4
+00:00:05,000 --> 00:00:11,000
+Way too often our organization's not backing up their data or not following good practices of having
+
+5
+00:00:11,000 --> 00:00:18,000
+data backup, such as not backing it up often enough, not storing it in offsite, not testing the backup.
+
+6
+00:00:18,000 --> 00:00:20,000
+So in this video let's talk about backup.
+
+7
+00:00:20,000 --> 00:00:26,000
+And then personally to you are you backing up your personal information not just organizational information.
+
+8
+00:00:26,000 --> 00:00:29,000
+I have a I'm not going to get into this in this video too much.
+
+9
+00:00:29,000 --> 00:00:35,000
+But I learned a lesson a long time ago when my daughter was born in 2002.
+
+10
+00:00:35,000 --> 00:00:40,000
+I didn't really I didn't realize that backups was really important because I'm a very stupid person.
+
+11
+00:00:40,000 --> 00:00:44,000
+So we had a digital camera back in those days, 2004, when she was born.
+
+12
+00:00:44,000 --> 00:00:48,000
+We had a digital camera back in those days, and I took a lot of pictures with digital camera stored
+
+13
+00:00:48,000 --> 00:00:49,000
+on a computer.
+
+14
+00:00:49,000 --> 00:00:54,000
+Computer died, and to this day we have no pictures of my daughter from when she was small all the way
+
+15
+00:00:54,000 --> 00:00:56,000
+until she was about 4 or 5.
+
+16
+00:00:56,000 --> 00:00:56,000
+Why?
+
+17
+00:00:56,000 --> 00:00:58,000
+Because no backup.
+
+18
+00:00:58,000 --> 00:00:59,000
+So I learned this the hard way.
+
+19
+00:00:59,000 --> 00:01:02,000
+Remember something outside of the scope of this class?
+
+20
+00:01:02,000 --> 00:01:08,000
+It was one thing you ever learned from this class is you could never, ever recreate a picture until
+
+21
+00:01:08,000 --> 00:01:10,000
+it's a time machine which doesn't exist.
+
+22
+00:01:10,000 --> 00:01:17,000
+So on a personal note, now that I've wasted 45 seconds of your time, please back up your data, including
+
+23
+00:01:17,000 --> 00:01:17,000
+your pictures.
+
+24
+00:01:17,000 --> 00:01:19,000
+You'll never be able to get it back.
+
+25
+00:01:19,000 --> 00:01:23,000
+Now let's talk about data backups inside of your organizations.
+
+26
+00:01:23,000 --> 00:01:24,000
+What exactly is a backup?
+
+27
+00:01:24,000 --> 00:01:28,000
+Well, it's basically copies of data and systems that are stored separately from the original.
+
+28
+00:01:29,000 --> 00:01:32,000
+The design to be used for restoring the original.
+
+29
+00:01:32,000 --> 00:01:36,000
+In case of data loss, corruptions or a disaster, you've got to remember something.
+
+30
+00:01:36,000 --> 00:01:40,000
+It's not if this machine dies, it's when it's not.
+
+31
+00:01:40,000 --> 00:01:42,000
+If your hard drive dies, it's when it's not.
+
+32
+00:01:42,000 --> 00:01:44,000
+If the motherboard dies, it's not.
+
+33
+00:01:44,000 --> 00:01:49,000
+If the system goes offline, it's just a matter of when do you have a backup to restore the data?
+
+34
+00:01:49,000 --> 00:01:54,000
+Now they can be maintained in various forms on site backups, off site backups, cloud backups.
+
+35
+00:01:54,000 --> 00:02:01,000
+But it's going to be super important to make sure that you you manage the CIA of these backups for ensuring
+
+36
+00:02:01,000 --> 00:02:05,000
+that the integrity is maintained in the backups, the availability of the backup is there.
+
+37
+00:02:05,000 --> 00:02:08,000
+And of course, keeping the backup confidential.
+
+38
+00:02:08,000 --> 00:02:11,000
+Now, there are some things here we want to talk about when it comes to backup.
+
+39
+00:02:12,000 --> 00:02:15,000
+The first one up is an on site backup.
+
+40
+00:02:15,000 --> 00:02:20,000
+So most of the time when you backup data in an organization, maybe you have a server, a local server
+
+41
+00:02:20,000 --> 00:02:22,000
+that you have, and you back up the data.
+
+42
+00:02:22,000 --> 00:02:27,000
+You might just keep the drive in the organization where the actual, uh, data is.
+
+43
+00:02:27,000 --> 00:02:31,000
+So you have a backup drive connected to a backup server.
+
+44
+00:02:31,000 --> 00:02:33,000
+You may disconnect the backup drive, but it's still in the organization.
+
+45
+00:02:33,000 --> 00:02:35,000
+It's still in that physical site.
+
+46
+00:02:35,000 --> 00:02:41,000
+Now, it's fine to do this, but what if there's a fire in that building and that building burns?
+
+47
+00:02:41,000 --> 00:02:43,000
+You lose all of the data.
+
+48
+00:02:43,000 --> 00:02:47,000
+The organization basically vanishes if that is the case.
+
+49
+00:02:47,000 --> 00:02:49,000
+So you probably don't want to have that.
+
+50
+00:02:49,000 --> 00:02:53,000
+Alone, so backups are stored in the same physical location quick and easy.
+
+51
+00:02:53,000 --> 00:02:58,000
+But remember, if there's a disaster to that on site, you lose the data.
+
+52
+00:02:58,000 --> 00:03:00,000
+Offsite backups stored at a different location.
+
+53
+00:03:00,000 --> 00:03:05,000
+These backups provide additional safeguards against disasters that could affect the primary sites.
+
+54
+00:03:05,000 --> 00:03:10,000
+If the primary sites got a bit of fire burns down, but you still have a copy of the data.
+
+55
+00:03:10,000 --> 00:03:13,000
+These are essential for comprehensive disaster recovery.
+
+56
+00:03:13,000 --> 00:03:17,000
+Now, another thing here is going to be the frequency.
+
+57
+00:03:17,000 --> 00:03:20,000
+When should you be backing up data?
+
+58
+00:03:20,000 --> 00:03:22,000
+How often should you be backing up data?
+
+59
+00:03:22,000 --> 00:03:28,000
+The frequency of backup should be determined based on how critical of the data is and the rate of changes.
+
+60
+00:03:28,000 --> 00:03:35,000
+So if you have data that changes every day and if those changes are going to lead, uh, cost a lot
+
+61
+00:03:35,000 --> 00:03:35,000
+of money.
+
+62
+00:03:35,000 --> 00:03:39,000
+For example, you have 200 users changing data all day long.
+
+63
+00:03:39,000 --> 00:03:45,000
+Well, if you lose one day of data and you work, you pay your let's say you got everybody works eight
+
+64
+00:03:45,000 --> 00:03:51,000
+hours, you got 2000 users, 200 users, 200 users, eight hours is 16,000 hours.
+
+65
+00:03:51,000 --> 00:03:57,000
+If you paid everybody ten bucks, that's $160,000 worth of payroll to produce data every day and manipulate
+
+66
+00:03:57,000 --> 00:04:02,000
+data one day, a backup for you technically, if you lose your data.
+
+67
+00:04:03,000 --> 00:04:05,000
+Every day that has to be recreated.
+
+68
+00:04:05,000 --> 00:04:07,000
+It's going to cost you $160,000.
+
+69
+00:04:07,000 --> 00:04:09,000
+It's a lot of money now.
+
+70
+00:04:09,000 --> 00:04:11,000
+So how often should you back up?
+
+71
+00:04:11,000 --> 00:04:12,000
+Every day, right?
+
+72
+00:04:12,000 --> 00:04:15,000
+Or maybe you should be backing up every hour.
+
+73
+00:04:15,000 --> 00:04:17,000
+Or maybe you should be backing up every minute.
+
+74
+00:04:17,000 --> 00:04:19,000
+That depends on the organization.
+
+75
+00:04:19,000 --> 00:04:20,000
+That depends on how critical the data is.
+
+76
+00:04:20,000 --> 00:04:23,000
+That depends how expensive it is to recreate the data.
+
+77
+00:04:23,000 --> 00:04:25,000
+Every data set is different.
+
+78
+00:04:25,000 --> 00:04:31,000
+The point is, you must back up your data on a frequent basis, and that frequency depends on how critical
+
+79
+00:04:31,000 --> 00:04:35,000
+the data is, how expensive it is to recreate the data, and many other factors.
+
+80
+00:04:37,000 --> 00:04:38,000
+Encryption.
+
+81
+00:04:38,000 --> 00:04:43,000
+When you have data that you back up onto a tape.
+
+82
+00:04:43,000 --> 00:04:46,000
+Tape because I'm saying tape because I'm all generally use hard drives.
+
+83
+00:04:46,000 --> 00:04:50,000
+Now you back it up to removable hard drive or USB stick of some kind.
+
+84
+00:04:50,000 --> 00:04:52,000
+You have to make sure that that data is encrypted.
+
+85
+00:04:52,000 --> 00:04:57,000
+Now, another popular option that I should go back here, we talked about on site and off site backup.
+
+86
+00:04:57,000 --> 00:05:01,000
+I forgot to mention a good off site backup is backing up into the cloud.
+
+87
+00:05:01,000 --> 00:05:03,000
+There are many cloud providers nowadays.
+
+88
+00:05:03,000 --> 00:05:07,000
+Dropbox, for example, has backup plans that you can use to backup systems.
+
+89
+00:05:07,000 --> 00:05:09,000
+Basically that you're backing up to the cloud.
+
+90
+00:05:10,000 --> 00:05:15,000
+So if you back up something to some, if you back up your data to something like a USB stick or even
+
+91
+00:05:15,000 --> 00:05:19,000
+to the cloud like Dropbox, you want to make sure you encrypt the data.
+
+92
+00:05:19,000 --> 00:05:25,000
+Remember something your data online on your server is secure.
+
+93
+00:05:25,000 --> 00:05:28,000
+It has firewalls on it, it has windows permissions and all this great stuff.
+
+94
+00:05:29,000 --> 00:05:34,000
+But if I can just walk in and pick up your USB, stick with your data and just walk away with it, it's
+
+95
+00:05:34,000 --> 00:05:35,000
+not very useful.
+
+96
+00:05:35,000 --> 00:05:38,000
+What if the USB stick gets lost or the removable hard drive gets lost?
+
+97
+00:05:38,000 --> 00:05:41,000
+What if somebody gets access to your Dropbox, right?
+
+98
+00:05:41,000 --> 00:05:43,000
+It's all these things that can go wrong.
+
+99
+00:05:43,000 --> 00:05:46,000
+You want to make sure that your backup is encrypted.
+
+100
+00:05:46,000 --> 00:05:50,000
+So it's critical for maintaining confidentiality integrity for sensitive data.
+
+101
+00:05:50,000 --> 00:05:55,000
+Now you're going to want to encrypt it both during transmission.
+
+102
+00:05:55,000 --> 00:06:00,000
+Remember the data states the data has three states data at rest and data data at rest.
+
+103
+00:06:00,000 --> 00:06:00,000
+Data in motion.
+
+104
+00:06:00,000 --> 00:06:01,000
+Data in use.
+
+105
+00:06:01,000 --> 00:06:04,000
+You really don't do encryption doesn't work for data in use.
+
+106
+00:06:04,000 --> 00:06:06,000
+But while data is in transmission.
+
+107
+00:06:06,000 --> 00:06:10,000
+So it's the data is transferred from you to your offsite backup or to your cloud.
+
+108
+00:06:10,000 --> 00:06:12,000
+You want to make sure you're encrypted with SSL.
+
+109
+00:06:12,000 --> 00:06:17,000
+And when the data is stored on your machine, you can then use things like AES encryption to encrypt
+
+110
+00:06:17,000 --> 00:06:20,000
+the data at rest or while stored on your machine.
+
+111
+00:06:20,000 --> 00:06:28,000
+Now, one of the great things we can do with systems is a snapshot, a snapshot, or method of capturing
+
+112
+00:06:28,000 --> 00:06:30,000
+the state of a system at a particular point.
+
+113
+00:06:30,000 --> 00:06:34,000
+They're typically used for systems that require regular backups with minimal disruption.
+
+114
+00:06:34,000 --> 00:06:36,000
+There's going to be like a database or virtual machine.
+
+115
+00:06:36,000 --> 00:06:37,000
+Snapshots.
+
+116
+00:06:37,000 --> 00:06:40,000
+I do a lot on virtual machines like Virtual Box.
+
+117
+00:06:40,000 --> 00:06:43,000
+What a snapshot does is that it takes a complete snapshot.
+
+118
+00:06:43,000 --> 00:06:47,000
+Basically, it's it's like a picture of that machine at that time.
+
+119
+00:06:47,000 --> 00:06:49,000
+And I can store different snapshots.
+
+120
+00:06:49,000 --> 00:06:52,000
+So for example, I would do a snapshot of a virtual machine.
+
+121
+00:06:53,000 --> 00:06:56,000
+And then I would install applications, manipulate it or change it.
+
+122
+00:06:56,000 --> 00:06:58,000
+That's what I'm going to do now.
+
+123
+00:06:58,000 --> 00:07:01,000
+If anything changes I can just revert back to the snapshot.
+
+124
+00:07:01,000 --> 00:07:05,000
+So what the snapshot does is that it stores all the configuration and data of that machine in time.
+
+125
+00:07:05,000 --> 00:07:08,000
+It's basically a picture copy of the machine.
+
+126
+00:07:08,000 --> 00:07:10,000
+Now I love using snapshots.
+
+127
+00:07:10,000 --> 00:07:13,000
+Is the best way to restore machine if anything ever goes wrong.
+
+128
+00:07:13,000 --> 00:07:19,000
+Now, when it comes to recovery, recovering from backup is going to be a process.
+
+129
+00:07:19,000 --> 00:07:23,000
+The ability to recover data from backup is a fundamental aspect of all security strategy.
+
+130
+00:07:23,000 --> 00:07:30,000
+It involves processes and plans to restore the data from backups efficiently and effectively, hopefully
+
+131
+00:07:30,000 --> 00:07:33,000
+with no data loss or little data loss.
+
+132
+00:07:33,000 --> 00:07:37,000
+It's great to have backups, but have you ever recovered the data?
+
+133
+00:07:37,000 --> 00:07:41,000
+One of the things we have to do as folks that manage data backups is.
+
+134
+00:07:42,000 --> 00:07:45,000
+Are we restoring that data that way?
+
+135
+00:07:45,000 --> 00:07:50,000
+The day will come when those systems will go down and we will have to recover that data.
+
+136
+00:07:50,000 --> 00:07:56,000
+Do we have the right processes and procedures in place to recover that data now?
+
+137
+00:07:56,000 --> 00:08:02,000
+One thing an organization can do, maybe because they're processing high volume, critical, expensive
+
+138
+00:08:02,000 --> 00:08:05,000
+data is to do what's called data replication.
+
+139
+00:08:05,000 --> 00:08:10,000
+This involves copying data to a secondary location in real time or near real time.
+
+140
+00:08:10,000 --> 00:08:15,000
+Unlike traditional backup, replication aims to merit data which can be quickly switched in case of
+
+141
+00:08:15,000 --> 00:08:16,000
+a primary data failure.
+
+142
+00:08:16,000 --> 00:08:17,000
+So.
+
+143
+00:08:18,000 --> 00:08:24,000
+Let's say you have two major, uh, data centers, and you basically you replicate them.
+
+144
+00:08:24,000 --> 00:08:27,000
+So data is created and manager, it replicates that.
+
+145
+00:08:27,000 --> 00:08:33,000
+And manager replication is a really expensive thing because it's done in real time and just really never
+
+146
+00:08:33,000 --> 00:08:33,000
+data loss.
+
+147
+00:08:33,000 --> 00:08:38,000
+If one data center goes offline, the other data center has all the copy of the data you see.
+
+148
+00:08:38,000 --> 00:08:44,000
+Look at it this way if you do a backup every single night, then technically you can lose 24 hours of
+
+149
+00:08:44,000 --> 00:08:47,000
+data because what if the system fails right before the next backup?
+
+150
+00:08:47,000 --> 00:08:50,000
+Then you lost all the data from the previous backup.
+
+151
+00:08:51,000 --> 00:08:56,000
+With replication, technically you never lose anything, but if you're replicating to a cloud system
+
+152
+00:08:56,000 --> 00:08:59,000
+or to another data center, you need to have the internet lines to support it.
+
+153
+00:08:59,000 --> 00:09:02,000
+You need to have the software licenses, which can be really expensive.
+
+154
+00:09:02,000 --> 00:09:06,000
+And of course, replication needs two of the same systems.
+
+155
+00:09:06,000 --> 00:09:11,000
+So if you if one center costs $1 billion, the other one will also cost $1 billion.
+
+156
+00:09:11,000 --> 00:09:13,000
+Another thing you can do is call journaling.
+
+157
+00:09:13,000 --> 00:09:16,000
+The journaling is a method that keeps track of changes made to a system.
+
+158
+00:09:16,000 --> 00:09:19,000
+Since their last full backup.
+
+159
+00:09:19,000 --> 00:09:22,000
+It's basically used on database to restore to a point in time.
+
+160
+00:09:22,000 --> 00:09:24,000
+So what journaling does.
+
+161
+00:09:24,000 --> 00:09:27,000
+So before data is written to like something like a database, it's written to a journal.
+
+162
+00:09:27,000 --> 00:09:32,000
+Journaling is great because then you can restore data to a certain particular point, especially in
+
+163
+00:09:32,000 --> 00:09:33,000
+a database.
+
+164
+00:09:33,000 --> 00:09:38,000
+It allows for faster recovery by only applying the last changes to the journal.
+
+165
+00:09:38,000 --> 00:09:45,000
+Keep in mind, guys, that when it comes to backup, it is a mandatory thing in any system, even at
+
+166
+00:09:45,000 --> 00:09:45,000
+home.
+
+167
+00:09:45,000 --> 00:09:51,000
+Like I told you with my story of the pictures, always remember the saying when it comes to it no backup,
+
+168
+00:09:51,000 --> 00:09:52,000
+no restore.
+
diff --git a/25 - Resilience and Recovery/006 Power OB 3.4_en.srt b/25 - Resilience and Recovery/006 Power OB 3.4_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..f538fc1ac1371781f8ccbc3a629fe405f8f5de41
--- /dev/null
+++ b/25 - Resilience and Recovery/006 Power OB 3.4_en.srt
@@ -0,0 +1,308 @@
+1
+00:00:00,000 --> 00:00:07,000
+One of the most critical elements when it comes to running a data center or anything in it is power.
+
+2
+00:00:07,000 --> 00:00:07,000
+Yes, we need power.
+
+3
+00:00:07,000 --> 00:00:08,000
+We need electricity.
+
+4
+00:00:08,000 --> 00:00:12,000
+Every single thing in it runs on electricity servers, routers, switches, you name it.
+
+5
+00:00:12,000 --> 00:00:14,000
+Obviously without power nothing works.
+
+6
+00:00:14,000 --> 00:00:20,000
+So what we need to do if we're building redundant systems on high available systems, we need to have
+
+7
+00:00:20,000 --> 00:00:22,000
+good redundant power.
+
+8
+00:00:22,000 --> 00:00:24,000
+So in this video I want to talk about that.
+
+9
+00:00:24,000 --> 00:00:25,000
+You guys know what power is.
+
+10
+00:00:25,000 --> 00:00:30,000
+But we need to ensure that we have consistent and reliable power is vital right.
+
+11
+00:00:30,000 --> 00:00:33,000
+It's vital to the maintenance, availability and functionality of systems.
+
+12
+00:00:33,000 --> 00:00:36,000
+So we need to have consistent and reliable power.
+
+13
+00:00:36,000 --> 00:00:37,000
+Now how are we going to get that?
+
+14
+00:00:37,000 --> 00:00:40,000
+Well, there's two things that we could do.
+
+15
+00:00:40,000 --> 00:00:42,000
+Well, there's basically three things.
+
+16
+00:00:42,000 --> 00:00:45,000
+Number one, you should know getting power from your power provider.
+
+17
+00:00:45,000 --> 00:00:48,000
+But what happens if your power provider goes off?
+
+18
+00:00:48,000 --> 00:00:50,000
+Now, it's not a common thing.
+
+19
+00:00:50,000 --> 00:00:54,000
+I live in New York and it's very uncommon for me not to have power.
+
+20
+00:00:54,000 --> 00:00:58,000
+But in times of like a major snowstorm, I've lost power.
+
+21
+00:00:59,000 --> 00:01:05,000
+Uh, major wind such as potential hurricanes or tropical storms or something like that.
+
+22
+00:01:05,000 --> 00:01:05,000
+Here in New York City.
+
+23
+00:01:05,000 --> 00:01:07,000
+We have lost power before.
+
+24
+00:01:07,000 --> 00:01:09,000
+So what can we do if we lost power?
+
+25
+00:01:09,000 --> 00:01:11,000
+Well, there's two things we can do.
+
+26
+00:01:11,000 --> 00:01:14,000
+Number one, we can get a generator such as this giant box.
+
+27
+00:01:14,000 --> 00:01:19,000
+Now, if you've ever walked to the side of major big buildings and you see something that looks like
+
+28
+00:01:19,000 --> 00:01:21,000
+this outside, that's a generator.
+
+29
+00:01:21,000 --> 00:01:24,000
+These are generators that can power up an entire building.
+
+30
+00:01:24,000 --> 00:01:27,000
+Generators are alternative power source in case of a power outage.
+
+31
+00:01:27,000 --> 00:01:29,000
+They're essential for long.
+
+32
+00:01:29,000 --> 00:01:30,000
+Keyword is a long terme.
+
+33
+00:01:30,000 --> 00:01:35,000
+Power failures when the main power supply is broken or not available.
+
+34
+00:01:36,000 --> 00:01:41,000
+These are things such as servers, uh, servers and data centers remain operational.
+
+35
+00:01:41,000 --> 00:01:46,000
+Now, you've got to keep in mind that these generators is going to work on some kind of fuel, whether
+
+36
+00:01:46,000 --> 00:01:49,000
+it's natural gas, diesel or gasoline.
+
+37
+00:01:49,000 --> 00:01:54,000
+As long as these things generally gets their fuel, they're probably going to continuously work.
+
+38
+00:01:54,000 --> 00:01:58,000
+Now, a lot of them I know, runs on natural gas, which is great because you don't need to go to the
+
+39
+00:01:58,000 --> 00:02:01,000
+you need to get a truck, a diesel truck and keep powering it up.
+
+40
+00:02:02,000 --> 00:02:07,000
+A lot of small generators that we have at home for just a few power outlets may work on something like
+
+41
+00:02:07,000 --> 00:02:10,000
+gasoline, but most of these are going to be natural gas.
+
+42
+00:02:10,000 --> 00:02:15,000
+The other thing here we have is going to be something that I highly recommend you put in your house.
+
+43
+00:02:15,000 --> 00:02:18,000
+This is going to be an uninterruptible power supply.
+
+44
+00:02:18,000 --> 00:02:19,000
+Now I have one on my computer.
+
+45
+00:02:19,000 --> 00:02:21,000
+I have one on my router.
+
+46
+00:02:21,000 --> 00:02:25,000
+Um, I have one connected directly to my wireless router.
+
+47
+00:02:25,000 --> 00:02:30,000
+That way, if we ever lose power in my house, I have one of these big battery things.
+
+48
+00:02:30,000 --> 00:02:32,000
+Cost me about 200 bucks.
+
+49
+00:02:32,000 --> 00:02:38,000
+Quite expensive, but it should give me enough power just to that router for way more than about 3 or
+
+50
+00:02:38,000 --> 00:02:39,000
+4 hours.
+
+51
+00:02:39,000 --> 00:02:42,000
+I'm estimating maybe six seven hours of power I can get.
+
+52
+00:02:42,000 --> 00:02:49,000
+So that means I have internet in my house, wired internet to my router if anything goes wrong.
+
+53
+00:02:49,000 --> 00:02:51,000
+Now, what exactly is this?
+
+54
+00:02:51,000 --> 00:02:54,000
+Well, this is basically a giant battery, so a UPS.
+
+55
+00:02:55,000 --> 00:03:02,000
+Provides immediate power backup in the event of a power failure, allowing for a shutdown of a safe
+
+56
+00:03:02,000 --> 00:03:05,000
+shutdown of systems or bridging a gap until the generator kicks in.
+
+57
+00:03:06,000 --> 00:03:09,000
+A UPS is critical for preventing data loss and system corruption.
+
+58
+00:03:09,000 --> 00:03:11,000
+Here's the thing with generators.
+
+59
+00:03:11,000 --> 00:03:20,000
+Generators generally may not kick in right away the failover from primary power to the actual generator.
+
+60
+00:03:20,000 --> 00:03:26,000
+That flip of power can actually cause all your servers to reboot, causing chaos.
+
+61
+00:03:27,000 --> 00:03:30,000
+Now what you can do is you can put ups on them.
+
+62
+00:03:30,000 --> 00:03:35,000
+So the way a UPS works is that it's basically a giant battery.
+
+63
+00:03:35,000 --> 00:03:40,000
+The power that's being provided to your machine is off of that battery, and the power from the wall
+
+64
+00:03:40,000 --> 00:03:43,000
+that this thing plugs into is basically powering the battery.
+
+65
+00:03:43,000 --> 00:03:47,000
+So if you go and you unplug the ups from the wallet, there's no power.
+
+66
+00:03:47,000 --> 00:03:50,000
+The machine doesn't know because the machine is never running.
+
+67
+00:03:50,000 --> 00:03:53,000
+The server was never actually running on the wall.
+
+68
+00:03:53,000 --> 00:03:54,000
+Power is running on the battery.
+
+69
+00:03:54,000 --> 00:03:58,000
+So until that battery runs out, this thing comes in a wide variety of sizes.
+
+70
+00:03:58,000 --> 00:04:04,000
+You from a really small one, maybe like this big like a little box to this giant device that's probably
+
+71
+00:04:04,000 --> 00:04:07,000
+this big and weighs a whole lot and weighs a whole lot.
+
+72
+00:04:08,000 --> 00:04:11,000
+They are big, big batteries.
+
+73
+00:04:11,000 --> 00:04:12,000
+That's really what these are.
+
+74
+00:04:12,000 --> 00:04:15,000
+Keep in mind, power is really important.
+
+75
+00:04:15,000 --> 00:04:16,000
+You're not going to be able to power up.
+
+76
+00:04:16,000 --> 00:04:18,000
+You're not going be able to run anything in it without power.
+
+77
+00:04:18,000 --> 00:04:22,000
+So make sure you have good, reliable alternative power.
+
diff --git a/25 - Resilience and Recovery/007 Quick Quiz.html b/25 - Resilience and Recovery/007 Quick Quiz.html
new file mode 100644
index 0000000000000000000000000000000000000000..f396fbbe59c20c46f745b7972f09ec578d174aa3
--- /dev/null
+++ b/25 - Resilience and Recovery/007 Quick Quiz.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+
diff --git a/26 - Labs/001 Lab intro_en.srt b/26 - Labs/001 Lab intro_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..e083854075359e8a5358e97a647ae8b22f5887ed
--- /dev/null
+++ b/26 - Labs/001 Lab intro_en.srt
@@ -0,0 +1,664 @@
+1
+00:00:00,000 --> 00:00:01,000
+Okay.
+
+2
+00:00:01,000 --> 00:00:06,000
+In this portion of the course, I'm going to be doing labs with you, hands on labs with you, so you
+
+3
+00:00:06,000 --> 00:00:11,000
+can get a feeling or a touch of what it takes to actually secure systems.
+
+4
+00:00:11,000 --> 00:00:15,000
+Now, I could have gone two ways with these labs and show you how to hack, but I'm going to keep that
+
+5
+00:00:15,000 --> 00:00:18,000
+for my course or Certified Ethical Hacker course.
+
+6
+00:00:18,000 --> 00:00:22,000
+Since this is Security Plus, and all you need to know is how to secure systems.
+
+7
+00:00:22,000 --> 00:00:27,000
+The labs are basically geared towards how to secure systems and not how to hack systems, although I've
+
+8
+00:00:27,000 --> 00:00:30,000
+included a few like password cracking labs.
+
+9
+00:00:30,000 --> 00:00:34,000
+Now, before I get into this, I really want to point out something to you.
+
+10
+00:00:34,000 --> 00:00:37,000
+You do not need to do these labs to pass your exam.
+
+11
+00:00:37,000 --> 00:00:41,000
+If all you're interested in is just to get Security Plus certified.
+
+12
+00:00:41,000 --> 00:00:45,000
+Maybe you've worked in security for many years and you've done most of these labs already.
+
+13
+00:00:45,000 --> 00:00:47,000
+Don't waste your time on this section.
+
+14
+00:00:47,000 --> 00:00:49,000
+Just go and take your exam.
+
+15
+00:00:49,000 --> 00:00:52,000
+I've given you more than enough information for you to pass your test.
+
+16
+00:00:52,000 --> 00:00:57,000
+Just do to do all the videos, do all your practice exams and you're going to be just fine.
+
+17
+00:00:58,000 --> 00:01:03,000
+Now, if you haven't worked in security at all or you just don't have more security experience, then
+
+18
+00:01:03,000 --> 00:01:05,000
+I highly recommend that you do these labs.
+
+19
+00:01:05,000 --> 00:01:11,000
+In this video, I want to show you where I'm getting these labs from and the computer I'm using.
+
+20
+00:01:11,000 --> 00:01:15,000
+I don't believe that you should be buying practice labs.
+
+21
+00:01:15,000 --> 00:01:19,000
+There are these companies that sells these online simulation.
+
+22
+00:01:19,000 --> 00:01:21,000
+That's not the way to do it.
+
+23
+00:01:21,000 --> 00:01:24,000
+The way you should be doing it is to actually build your own lab.
+
+24
+00:01:24,000 --> 00:01:29,000
+You'll learn a lot more from installing virtual machines, which is what I'm going to be doing.
+
+25
+00:01:29,000 --> 00:01:34,000
+And I'll show you all the steps to that, by the way, to actually downloading the software, installing
+
+26
+00:01:34,000 --> 00:01:35,000
+the software.
+
+27
+00:01:35,000 --> 00:01:41,000
+I'm talking all the tools we use and playing around with it, not some BS simulation that you're just
+
+28
+00:01:41,000 --> 00:01:42,000
+going to click step by step.
+
+29
+00:01:42,000 --> 00:01:45,000
+I want you to explore and I want you to try.
+
+30
+00:01:45,000 --> 00:01:50,000
+Security is not an easy thing, and you have to be able to work with different tools, not just with
+
+31
+00:01:50,000 --> 00:01:52,000
+instructions but by yourself.
+
+32
+00:01:52,000 --> 00:01:54,000
+So keep that in mind.
+
+33
+00:01:54,000 --> 00:01:56,000
+Now we're going to take a look at the objectives.
+
+34
+00:01:56,000 --> 00:01:59,000
+And I want to show you how the labs are going to be made.
+
+35
+00:01:59,000 --> 00:02:03,000
+And I'm going to show you the computer I'm using, because a lot of people always want to know, Andrew,
+
+36
+00:02:03,000 --> 00:02:04,000
+what computer are you using?
+
+37
+00:02:04,000 --> 00:02:07,000
+And I'll show you what I'm using and I'll give you some recommendations.
+
+38
+00:02:07,000 --> 00:02:10,000
+So let's go in here and onto my desktop.
+
+39
+00:02:11,000 --> 00:02:15,000
+And the first thing up I have is the exam objectives.
+
+40
+00:02:15,000 --> 00:02:18,000
+So okay this one here.
+
+41
+00:02:18,000 --> 00:02:18,000
+Yeah.
+
+42
+00:02:18,000 --> 00:02:19,000
+Sign in.
+
+43
+00:02:19,000 --> 00:02:25,000
+No you don't want to give anything to first time I'm using this profile here okay.
+
+44
+00:02:25,000 --> 00:02:28,000
+So here we go with the security plus exam objectives.
+
+45
+00:02:28,000 --> 00:02:31,000
+And notice this is for this exam 701.
+
+46
+00:02:31,000 --> 00:02:34,000
+Now some of these things you can't do labs with.
+
+47
+00:02:34,000 --> 00:02:37,000
+And I'll explain to you and some of them you could do labs with.
+
+48
+00:02:37,000 --> 00:02:38,000
+So let's go down here.
+
+49
+00:02:38,000 --> 00:02:40,000
+Let's take a look at exam number one.
+
+50
+00:02:40,000 --> 00:02:41,000
+Things like general security concepts.
+
+51
+00:02:41,000 --> 00:02:45,000
+You can't really do labs with these because this is more this is more discussion.
+
+52
+00:02:45,000 --> 00:02:48,000
+This is more category of controls.
+
+53
+00:02:48,000 --> 00:02:50,000
+These here are more theoretical.
+
+54
+00:02:50,000 --> 00:02:51,000
+You really can't do labs with these things.
+
+55
+00:02:51,000 --> 00:02:56,000
+Obviously I can't do labs with physical security as I can't show you guys how to build a fence.
+
+56
+00:02:56,000 --> 00:02:57,000
+It's technically not IT security.
+
+57
+00:02:57,000 --> 00:03:00,000
+That's physical security.
+
+58
+00:03:00,000 --> 00:03:06,000
+Um, but some of these things in the in the other lessons could I do have some labs we're going to be
+
+59
+00:03:06,000 --> 00:03:09,000
+doing on encryption, such as full disk encryption.
+
+60
+00:03:09,000 --> 00:03:13,000
+I'll show you guys how to do self-signed certificates and all that great stuff.
+
+61
+00:03:13,000 --> 00:03:15,000
+So we are going to be doing some things.
+
+62
+00:03:15,000 --> 00:03:18,000
+We're going to be doing steganography some some of the labs here.
+
+63
+00:03:18,000 --> 00:03:21,000
+We're going to use the TPM chip to do a full disk encryption.
+
+64
+00:03:21,000 --> 00:03:24,000
+Going into lesson number two.
+
+65
+00:03:24,000 --> 00:03:25,000
+These are going to be more threats.
+
+66
+00:03:25,000 --> 00:03:27,000
+Now I really thought about doing threats.
+
+67
+00:03:27,000 --> 00:03:32,000
+If you took a look at my security plus 601 course, I did do a lot of threat labs, but a lot of students
+
+68
+00:03:32,000 --> 00:03:38,000
+felt that it was unnecessary for the simple fact that it's not a course on hacking, it's a course on
+
+69
+00:03:38,000 --> 00:03:40,000
+protection versus hacking.
+
+70
+00:03:40,000 --> 00:03:42,000
+So I'm not going to be wasting your time with that.
+
+71
+00:03:42,000 --> 00:03:47,000
+But we will be talking about things like how to secure a wireless, I'll go through how to secure an
+
+72
+00:03:47,000 --> 00:03:49,000
+entire wireless, and I'll give you guys simulators on how to try that.
+
+73
+00:03:50,000 --> 00:03:53,000
+We'll demo products, how to try that.
+
+74
+00:03:53,000 --> 00:03:56,000
+Um, so good set of labs coming out of number two.
+
+75
+00:03:56,000 --> 00:03:57,000
+Uh, good set of labs.
+
+76
+00:03:57,000 --> 00:04:00,000
+Also we have coming out of number three.
+
+77
+00:04:00,000 --> 00:04:00,000
+All right.
+
+78
+00:04:00,000 --> 00:04:01,000
+I will be showing you this.
+
+79
+00:04:01,000 --> 00:04:04,000
+We'll be showing different kinds of anti-malware software.
+
+80
+00:04:04,000 --> 00:04:07,000
+We'll take a look at engine firewall configuration.
+
+81
+00:04:07,000 --> 00:04:09,000
+So good set of labs with that coming out.
+
+82
+00:04:10,000 --> 00:04:13,000
+Uh, in security number four, I will show you some good labs.
+
+83
+00:04:13,000 --> 00:04:17,000
+We'll do some explorations on things like MDM software.
+
+84
+00:04:17,000 --> 00:04:21,000
+We'll take a look at how to secure, for example, like a workstation.
+
+85
+00:04:21,000 --> 00:04:29,000
+What's what's hardened in a workstation about uh, I did do the CVE and I went over CVE and Cvss in
+
+86
+00:04:29,000 --> 00:04:31,000
+the actual course itself.
+
+87
+00:04:31,000 --> 00:04:35,000
+So I thought about doing a lab, but it was basically going to be the exact same thing we did before.
+
+88
+00:04:35,000 --> 00:04:38,000
+We are going to be doing a vulnerability scan coming up soon.
+
+89
+00:04:38,000 --> 00:04:43,000
+Now I want to point out that lesson number five doesn't really have much labs.
+
+90
+00:04:43,000 --> 00:04:47,000
+And the reason for this is because it's more administrative.
+
+91
+00:04:47,000 --> 00:04:53,000
+It's more like security policies and procedures is all listed here exploring kind of regulatory things
+
+92
+00:04:53,000 --> 00:04:59,000
+that you should be familiar with as, as basically as an IT security professional risk assessment.
+
+93
+00:04:59,000 --> 00:04:59,000
+This is more.
+
+94
+00:04:59,000 --> 00:05:01,000
+Paper base.
+
+95
+00:05:01,000 --> 00:05:03,000
+I saw all these things are basically paper based.
+
+96
+00:05:03,000 --> 00:05:06,000
+Nothing really here to, uh, configure.
+
+97
+00:05:06,000 --> 00:05:15,000
+Now, the other thing I want to mention is the actual computer I'm using now, I just bought this machine.
+
+98
+00:05:15,000 --> 00:05:19,000
+This is a laptop that I bought about four months ago.
+
+99
+00:05:19,000 --> 00:05:23,000
+This laptop cost about 2800 bucks.
+
+100
+00:05:23,000 --> 00:05:26,000
+Now I only buy laptops every 4 to 5 years.
+
+101
+00:05:26,000 --> 00:05:31,000
+So every time I buy one, it's going to be the top of the line one that I'm buying now.
+
+102
+00:05:31,000 --> 00:05:33,000
+I don't recommend for you to do what I did here.
+
+103
+00:05:33,000 --> 00:05:37,000
+What I recommend for you guys to do is to go and get yourself a desktop.
+
+104
+00:05:37,000 --> 00:05:43,000
+You see, laptops are incredibly expensive, and the amount of power that you can get with a desktop
+
+105
+00:05:43,000 --> 00:05:50,000
+will be like half the price of a of half the price of a laptop if you get a desktop with the same equivalent
+
+106
+00:05:50,000 --> 00:05:51,000
+power.
+
+107
+00:05:51,000 --> 00:05:56,000
+So I'm going to show you the laptop, the configurations, basically the this machine runs.
+
+108
+00:05:56,000 --> 00:06:00,000
+So I'm going to right click on my start button and I'm going to go to system.
+
+109
+00:06:01,000 --> 00:06:06,000
+And you can see that the machine has a it's a good Intel i9 processor.
+
+110
+00:06:06,000 --> 00:06:09,000
+You can do an i5, you can do an i7 processor.
+
+111
+00:06:09,000 --> 00:06:10,000
+You're good.
+
+112
+00:06:10,000 --> 00:06:12,000
+I do recommend a lot of Ram.
+
+113
+00:06:12,000 --> 00:06:15,000
+So my machine has 64 gigs of Ram.
+
+114
+00:06:15,000 --> 00:06:16,000
+You don't need this much.
+
+115
+00:06:16,000 --> 00:06:21,000
+What I recommend is just get get uh, 16 gig minimum.
+
+116
+00:06:21,000 --> 00:06:28,000
+You see, the thing is, when you do labs, you have to do a lot of virtual machines, and virtual machines
+
+117
+00:06:28,000 --> 00:06:29,000
+need a lot of Ram.
+
+118
+00:06:29,000 --> 00:06:32,000
+For example, I like to give my virtual machines about six gigs.
+
+119
+00:06:32,000 --> 00:06:39,000
+So if you have only 16 gigs, you can run about maybe two machines, give one for the other one for
+
+120
+00:06:39,000 --> 00:06:41,000
+because you can't leave your base OS with very little.
+
+121
+00:06:41,000 --> 00:06:48,000
+So I would say if you can get your machine to 32 gigs of Ram, it would be ideal 32 gigs.
+
+122
+00:06:48,000 --> 00:06:51,000
+Most of my other computer, except this one.
+
+123
+00:06:51,000 --> 00:06:56,000
+All my other machines, my personal desktop, my other laptop, my other personal desktop.
+
+124
+00:06:56,000 --> 00:06:58,000
+I want to work my one of home.
+
+125
+00:06:58,000 --> 00:07:01,000
+They all have 32 gigs of Ram and I do all my work on them.
+
+126
+00:07:01,000 --> 00:07:04,000
+This is the only one that came with 64 because I maxed out the machine.
+
+127
+00:07:04,000 --> 00:07:10,000
+You don't need that much Ram, so, but you should keep it at 32, okay?
+
+128
+00:07:10,000 --> 00:07:16,000
+When it comes to running virtual machines, the most important things is Ram, CPU, not so much because
+
+129
+00:07:16,000 --> 00:07:23,000
+we're not doing a lot of processor intensive tasks as we're basically just running small tasks on a
+
+130
+00:07:23,000 --> 00:07:27,000
+lot of virtual machines, and a lot of virtual machines needs a lot of Ram.
+
+131
+00:07:27,000 --> 00:07:30,000
+Now that's all you need.
+
+132
+00:07:30,000 --> 00:07:32,000
+Uh, I do recommend windows.
+
+133
+00:07:32,000 --> 00:07:34,000
+I do not recommend Mac.
+
+134
+00:07:34,000 --> 00:07:35,000
+It's not that I'm a mac hater.
+
+135
+00:07:35,000 --> 00:07:37,000
+I have a MacBook air.
+
+136
+00:07:37,000 --> 00:07:43,000
+It's my travel, uh, laptop that I use, and I bought it about two years ago.
+
+137
+00:07:43,000 --> 00:07:44,000
+No, last year I bought.
+
+138
+00:07:44,000 --> 00:07:46,000
+It's an M2 MacBook air.
+
+139
+00:07:46,000 --> 00:07:49,000
+I love my Mac, but I'm not going to use it to do this kind of work.
+
+140
+00:07:49,000 --> 00:07:52,000
+So if you have a mac, you can still follow along in these labs.
+
+141
+00:07:52,000 --> 00:07:53,000
+Okay?
+
+142
+00:07:53,000 --> 00:07:58,000
+You don't have to have windows, but I highly recommend for you to get a windows machine.
+
+143
+00:07:58,000 --> 00:08:02,000
+You see a lot of tools and a lot of utilities don't work on Mac.
+
+144
+00:08:02,000 --> 00:08:07,000
+If you have a mac, you're gonna have to install virtualization and use it on a consistent basis.
+
+145
+00:08:07,000 --> 00:08:12,000
+Mac is great for when browsing personal things, doing personal things, checking email, going on the
+
+146
+00:08:12,000 --> 00:08:13,000
+internet.
+
+147
+00:08:13,000 --> 00:08:19,000
+Mac is amazing, but when it comes to actually doing work, especially in corporate America, you really
+
+148
+00:08:19,000 --> 00:08:20,000
+need a windows box.
+
+149
+00:08:20,000 --> 00:08:22,000
+So I highly recommend you get a windows box.
+
+150
+00:08:22,000 --> 00:08:27,000
+And if you have a mac laptop, go build yourself a windows based machine.
+
+151
+00:08:27,000 --> 00:08:32,000
+I would recommend getting yourself an i7 processor with 32 gigs of Ram.
+
+152
+00:08:32,000 --> 00:08:34,000
+You know, the other thing I forgot to mention is hard drive.
+
+153
+00:08:34,000 --> 00:08:39,000
+Make sure you have an SSD and NVMe SSD drive.
+
+154
+00:08:39,000 --> 00:08:41,000
+Okay, just those is all you need.
+
+155
+00:08:41,000 --> 00:08:47,000
+32 gigs of Ram, any of the i7 processors, uh, the more core, the better.
+
+156
+00:08:47,000 --> 00:08:51,000
+And and at least a one terabyte NVMe SSD drive.
+
+157
+00:08:51,000 --> 00:08:57,000
+So all you need total cost on that will probably run you at about $1,000.
+
+158
+00:08:58,000 --> 00:09:02,000
+Um, you don't you can actually buy a machine for $1,000.
+
+159
+00:09:02,000 --> 00:09:04,000
+You don't have to build one if you don't want to.
+
+160
+00:09:04,000 --> 00:09:05,000
+So keep that in mind.
+
+161
+00:09:05,000 --> 00:09:07,000
+Now let's go ahead and get started with the labs.
+
+162
+00:09:07,000 --> 00:09:09,000
+Once again, I know I'm a broken record.
+
+163
+00:09:09,000 --> 00:09:13,000
+You do not need to do these labs to pass your exam.
+
+164
+00:09:13,000 --> 00:09:14,000
+They're just here.
+
+165
+00:09:14,000 --> 00:09:18,000
+In order to give you a more hands on aspect to the topics you learn.
+
+166
+00:09:18,000 --> 00:09:20,000
+So let's get started in these labs.
+
diff --git a/26 - Labs/002 Installing Windows on VirtualBox_en.srt b/26 - Labs/002 Installing Windows on VirtualBox_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..40329c2a38e2f62f58b87a032cb3720cb67bdfeb
--- /dev/null
+++ b/26 - Labs/002 Installing Windows on VirtualBox_en.srt
@@ -0,0 +1,800 @@
+1
+00:00:00,000 --> 00:00:04,000
+In this video, I'm going to show you how to install Windows 10 on your virtual machine.
+
+2
+00:00:04,000 --> 00:00:09,000
+Now I'm going to assume that you don't have the Windows 10 installation image.
+
+3
+00:00:09,000 --> 00:00:10,000
+I'm going to show you how to get it.
+
+4
+00:00:10,000 --> 00:00:11,000
+Now here's the thing.
+
+5
+00:00:11,000 --> 00:00:17,000
+Microsoft gives away basically the Windows 10 installation image that we can use to run our labs, but
+
+6
+00:00:17,000 --> 00:00:21,000
+it's not going to be registered and we can't activate it unless you actually purchase a copy.
+
+7
+00:00:21,000 --> 00:00:25,000
+But we don't need to do that because we're not going to be using it for very long.
+
+8
+00:00:25,000 --> 00:00:29,000
+And we don't need all the things like the ability to change background and all that.
+
+9
+00:00:29,000 --> 00:00:34,000
+So you can basically use this image for a long time without ever needing to activate it, but it's good
+
+10
+00:00:34,000 --> 00:00:36,000
+enough to do our labs on.
+
+11
+00:00:36,000 --> 00:00:37,000
+So I'm going to show you how to get it.
+
+12
+00:00:37,000 --> 00:00:42,000
+We're going to use what's called the Windows Media Creation Tool to make an ISO.
+
+13
+00:00:42,000 --> 00:00:47,000
+And then we're going to use VirtualBox to use we're basically going to use that ISO in VirtualBox to
+
+14
+00:00:47,000 --> 00:00:49,000
+install windows.
+
+15
+00:00:49,000 --> 00:00:51,000
+Let's go ahead and get started.
+
+16
+00:00:51,000 --> 00:00:56,000
+So here I am at uh good old Google.
+
+17
+00:00:56,000 --> 00:01:01,000
+Here we're going to type Windows 10 ISO download.
+
+18
+00:01:02,000 --> 00:01:05,000
+So here Windows 10 ISO download you're going to use generally download the first one.
+
+19
+00:01:05,000 --> 00:01:07,000
+Download a Windows 10 disk image.
+
+20
+00:01:08,000 --> 00:01:10,000
+Make this easier for you guys to see.
+
+21
+00:01:10,000 --> 00:01:13,000
+And you're supposed to just click download now.
+
+22
+00:01:14,000 --> 00:01:18,000
+And what this does is that it downloads what's called a media creation tool.
+
+23
+00:01:18,000 --> 00:01:20,000
+Go ahead and open that up.
+
+24
+00:01:20,000 --> 00:01:23,000
+Now when you open up, it takes a while to get started.
+
+25
+00:01:23,000 --> 00:01:24,000
+So I've already opened it.
+
+26
+00:01:24,000 --> 00:01:27,000
+It says getting things ready and that takes a while.
+
+27
+00:01:27,000 --> 00:01:28,000
+So I don't want to wait in the video.
+
+28
+00:01:28,000 --> 00:01:30,000
+It's already downloaded I did that.
+
+29
+00:01:30,000 --> 00:01:31,000
+So you're going to accept when?
+
+30
+00:01:31,000 --> 00:01:34,000
+Just open it, click accept.
+
+31
+00:01:34,000 --> 00:01:36,000
+Now we don't want to upgrade this PC.
+
+32
+00:01:36,000 --> 00:01:37,000
+Technically we can't.
+
+33
+00:01:37,000 --> 00:01:38,000
+This is a Windows 11.
+
+34
+00:01:38,000 --> 00:01:41,000
+We're going to say create installation media for another PC.
+
+35
+00:01:41,000 --> 00:01:44,000
+In particularly we want the ISO image.
+
+36
+00:01:44,000 --> 00:01:47,000
+When you're installing a VirtualBox you need an ISO image.
+
+37
+00:01:47,000 --> 00:01:48,000
+So we're going to go and click on next.
+
+38
+00:01:49,000 --> 00:01:52,000
+Windows 10 64 bit more than good enough.
+
+39
+00:01:52,000 --> 00:01:54,000
+We're going to go ahead and click on next.
+
+40
+00:01:54,000 --> 00:02:01,000
+We want the ISO file not a USB stick, because the ISO is what is going to be used as that image file
+
+41
+00:02:01,000 --> 00:02:03,000
+that VirtualBox will use.
+
+42
+00:02:03,000 --> 00:02:05,000
+So we're going to go ahead and click on next.
+
+43
+00:02:05,000 --> 00:02:11,000
+I'm actually going to put this on my desktop with a name called windows.
+
+44
+00:02:15,000 --> 00:02:15,000
+Yeah.
+
+45
+00:02:16,000 --> 00:02:20,000
+Windows installation because I'm actually going to save the entire VM there.
+
+46
+00:02:20,000 --> 00:02:24,000
+So we're going to say Windows 10 ISO.
+
+47
+00:02:25,000 --> 00:02:29,000
+I know it already has the extension ISO, but I always I always do that the way it makes me easier to
+
+48
+00:02:29,000 --> 00:02:30,000
+see.
+
+49
+00:02:30,000 --> 00:02:32,000
+I'm going to go ahead and click on save.
+
+50
+00:02:33,000 --> 00:02:34,000
+Okay.
+
+51
+00:02:34,000 --> 00:02:35,000
+Now it's going to be a while.
+
+52
+00:02:35,000 --> 00:02:43,000
+Because what it has to do is that it has to download that entire ISO from Microsoft, and then it's
+
+53
+00:02:43,000 --> 00:02:45,000
+going to make the actual ISO image.
+
+54
+00:02:45,000 --> 00:02:46,000
+This can take a few minutes.
+
+55
+00:02:46,000 --> 00:02:49,000
+I'll pause the video and I'll see you guys in a second.
+
+56
+00:02:51,000 --> 00:02:52,000
+Okay.
+
+57
+00:02:52,000 --> 00:02:54,000
+Uh, the image has finally finished.
+
+58
+00:02:54,000 --> 00:02:55,000
+Let's go ahead and see.
+
+59
+00:02:55,000 --> 00:02:57,000
+Now, for me, it took about 3 to 4 minutes.
+
+60
+00:02:57,000 --> 00:02:59,000
+So let's go ahead and check this out.
+
+61
+00:02:59,000 --> 00:03:00,000
+All right.
+
+62
+00:03:00,000 --> 00:03:00,000
+So here I am.
+
+63
+00:03:00,000 --> 00:03:02,000
+It says burn the ISO to a DVD.
+
+64
+00:03:02,000 --> 00:03:03,000
+We're not going to do that.
+
+65
+00:03:03,000 --> 00:03:04,000
+We already just want the ISO.
+
+66
+00:03:04,000 --> 00:03:06,000
+So I'm going to go ahead and click on finish.
+
+67
+00:03:07,000 --> 00:03:10,000
+Now it's a setup, is cleaning up a few things and we are done with this.
+
+68
+00:03:10,000 --> 00:03:14,000
+Now I want to see what that looks like on my desktop.
+
+69
+00:03:14,000 --> 00:03:17,000
+Here it is and opened up in the other window.
+
+70
+00:03:17,000 --> 00:03:18,000
+Here it is.
+
+71
+00:03:18,000 --> 00:03:22,000
+So one of the things that I do is I always name files with your extension.
+
+72
+00:03:22,000 --> 00:03:24,000
+It's just a habit that I do.
+
+73
+00:03:24,000 --> 00:03:26,000
+You don't have to, but it's something that I do.
+
+74
+00:03:26,000 --> 00:03:33,000
+Um, if you actually just go to view and you say like details like this one here, like I have it all
+
+75
+00:03:33,000 --> 00:03:36,000
+on default, but if not you can actually see it'll say disk image file.
+
+76
+00:03:36,000 --> 00:03:36,000
+All right.
+
+77
+00:03:36,000 --> 00:03:38,000
+So it's about four gigs.
+
+78
+00:03:38,000 --> 00:03:42,000
+So the rest of this video let's go ahead and make a virtual machine and start installing windows.
+
+79
+00:03:43,000 --> 00:03:44,000
+All right.
+
+80
+00:03:44,000 --> 00:03:44,000
+So we're going to go ahead.
+
+81
+00:03:44,000 --> 00:03:46,000
+And we are going to get started with this.
+
+82
+00:03:46,000 --> 00:03:47,000
+So we're going to go ahead and say new.
+
+83
+00:03:49,000 --> 00:03:51,000
+And it says it here.
+
+84
+00:03:51,000 --> 00:03:51,000
+Let's give it a name.
+
+85
+00:03:51,000 --> 00:03:53,000
+So we're going to say windows.
+
+86
+00:03:55,000 --> 00:03:55,000
+Ten.
+
+87
+00:03:57,000 --> 00:03:59,000
+The folder we want to do this in.
+
+88
+00:03:59,000 --> 00:04:02,000
+Now I'm going to tell you guys I like to store everything together.
+
+89
+00:04:02,000 --> 00:04:04,000
+So I'm going to go ahead and click in there and say other.
+
+90
+00:04:04,000 --> 00:04:07,000
+And I'm going to store it with the ISO image on my desktop.
+
+91
+00:04:07,000 --> 00:04:11,000
+And if you have an additional hard drive on your machine you want to use, that'll be great.
+
+92
+00:04:11,000 --> 00:04:12,000
+Just use that.
+
+93
+00:04:13,000 --> 00:04:15,000
+It's on my desktop windows installation.
+
+94
+00:04:15,000 --> 00:04:16,000
+Select this folder.
+
+95
+00:04:17,000 --> 00:04:19,000
+Uh, Windows 10 64 bit.
+
+96
+00:04:19,000 --> 00:04:19,000
+That's fine.
+
+97
+00:04:21,000 --> 00:04:23,000
+We're going to go ahead and click on next.
+
+98
+00:04:24,000 --> 00:04:28,000
+Now I'm going to give it a lot of Ram because I have a lot of Ram.
+
+99
+00:04:28,000 --> 00:04:31,000
+If you have 16 gigs of Ram, keep it at four gigs.
+
+100
+00:04:31,000 --> 00:04:32,000
+It's its minimum.
+
+101
+00:04:33,000 --> 00:04:33,000
+All right.
+
+102
+00:04:33,000 --> 00:04:34,000
+Give it four gigs.
+
+103
+00:04:34,000 --> 00:04:35,000
+Like right now.
+
+104
+00:04:35,000 --> 00:04:37,000
+By default it came with two gigs.
+
+105
+00:04:37,000 --> 00:04:38,000
+I'm going to.
+
+106
+00:04:38,000 --> 00:04:42,000
+I pushed it up to four gig, but for me, I'm going to push this thing up to.
+
+107
+00:04:43,000 --> 00:04:45,000
+I probably give it 12 gigs or so.
+
+108
+00:04:46,000 --> 00:04:47,000
+Yeah, that's good enough.
+
+109
+00:04:47,000 --> 00:04:49,000
+12 gigs is more than sufficient for this.
+
+110
+00:04:49,000 --> 00:04:55,000
+Now I have 28 cores on my CPU, so I'm going to make it a little faster if you can keep it as one if
+
+111
+00:04:55,000 --> 00:04:58,000
+you don't have a very fast one, I'm just going to keep it as one.
+
+112
+00:04:58,000 --> 00:05:00,000
+But I want it to install quick, so I'll just give it four.
+
+113
+00:05:00,000 --> 00:05:02,000
+Go ahead and click on next.
+
+114
+00:05:03,000 --> 00:05:07,000
+Now the drive is 50 gigs and that is fine.
+
+115
+00:05:07,000 --> 00:05:12,000
+All right, uh, we're going to make a brand new virtual disk 50 gig is fine.
+
+116
+00:05:12,000 --> 00:05:13,000
+Here's the thing.
+
+117
+00:05:13,000 --> 00:05:18,000
+It's not going to take 50 gigs right away as it starts to install and utilize, then it's going to actually
+
+118
+00:05:18,000 --> 00:05:20,000
+start taking away space from your physical machine.
+
+119
+00:05:20,000 --> 00:05:21,000
+All right.
+
+120
+00:05:21,000 --> 00:05:22,000
+We're going to go ahead and click on finish.
+
+121
+00:05:23,000 --> 00:05:28,000
+Now if you actually start this you're going to see it's not going to be happy if you just go ahead and
+
+122
+00:05:28,000 --> 00:05:29,000
+start it.
+
+123
+00:05:29,000 --> 00:05:31,000
+So if we go ahead and click on start.
+
+124
+00:05:35,000 --> 00:05:36,000
+Okay.
+
+125
+00:05:36,000 --> 00:05:37,000
+It's powering up our VM.
+
+126
+00:05:37,000 --> 00:05:37,000
+Now.
+
+127
+00:05:37,000 --> 00:05:40,000
+The first time it's going to take a second it has to create the disk for us.
+
+128
+00:05:40,000 --> 00:05:44,000
+It has to create all the interesting things that it utilizes for us.
+
+129
+00:05:44,000 --> 00:05:51,000
+But it's not going to, uh, it's not going to it's not going to do anything on its first start.
+
+130
+00:05:51,000 --> 00:05:52,000
+And you'll see why.
+
+131
+00:05:54,000 --> 00:05:55,000
+Oops.
+
+132
+00:05:55,000 --> 00:05:56,000
+Minimize this.
+
+133
+00:05:56,000 --> 00:06:02,000
+Now you notice it failed on the startup because it's like this virtual machine failed to boot.
+
+134
+00:06:02,000 --> 00:06:02,000
+Uh.
+
+135
+00:06:02,000 --> 00:06:03,000
+It's missing.
+
+136
+00:06:03,000 --> 00:06:05,000
+Can you tell me where the ISO image is?
+
+137
+00:06:05,000 --> 00:06:08,000
+So we're going to go and get the ISO image where we downloaded it.
+
+138
+00:06:08,000 --> 00:06:13,000
+So we're going to go to other and on the desktop we have windows installation.
+
+139
+00:06:14,000 --> 00:06:18,000
+And there's that ISO that we made okay.
+
+140
+00:06:18,000 --> 00:06:20,000
+We're going to say mount and retry boot.
+
+141
+00:06:26,000 --> 00:06:27,000
+All right, give it a second.
+
+142
+00:06:27,000 --> 00:06:29,000
+As it's doing its business here.
+
+143
+00:06:29,000 --> 00:06:30,000
+And there you go.
+
+144
+00:06:30,000 --> 00:06:31,000
+Windows is starting to install.
+
+145
+00:06:31,000 --> 00:06:32,000
+It's going to make this a full screen.
+
+146
+00:06:32,000 --> 00:06:33,000
+So we can see.
+
+147
+00:06:34,000 --> 00:06:38,000
+Now the thing is that this is a 4K monitor that I'm using.
+
+148
+00:06:38,000 --> 00:06:44,000
+So everything is going to look a little small because this is a 4K monitor that I'm using.
+
+149
+00:06:44,000 --> 00:06:46,000
+That's why everything is like shrunk.
+
+150
+00:06:47,000 --> 00:06:52,000
+Um, smaller resolutions looks very small because it's being recorded in a 4K setting.
+
+151
+00:06:52,000 --> 00:06:57,000
+But if you know how to install windows, which I'm assuming you guys did, hopefully you guys did a
+
+152
+00:06:57,000 --> 00:06:58,000
+plus.
+
+153
+00:06:58,000 --> 00:07:01,000
+Um, then this is pretty straightforward.
+
+154
+00:07:01,000 --> 00:07:06,000
+So I know it's hard to see this, uh, but we got to actually get into windows.
+
+155
+00:07:07,000 --> 00:07:08,000
+Let's see here.
+
+156
+00:07:08,000 --> 00:07:10,000
+We could do a scale mode.
+
+157
+00:07:11,000 --> 00:07:16,000
+Now, by the way, if you open up a bigger mold, it's going to tell you, uh, right.
+
+158
+00:07:16,000 --> 00:07:21,000
+Control and the the home button or seal work.
+
+159
+00:07:23,000 --> 00:07:28,000
+Okay, so with this here we can scale it so we can drag it.
+
+160
+00:07:29,000 --> 00:07:36,000
+So scale mode in VirtualBox basically allows you basically to stretch it and the resolution and windows
+
+161
+00:07:36,000 --> 00:07:38,000
+will adjust to it.
+
+162
+00:07:39,000 --> 00:07:39,000
+All right.
+
+163
+00:07:39,000 --> 00:07:40,000
+So let's go ahead and click on next.
+
+164
+00:07:42,000 --> 00:07:43,000
+We're going to say install now.
+
+165
+00:07:47,000 --> 00:07:48,000
+And give it a second.
+
+166
+00:07:48,000 --> 00:07:50,000
+Of course, windows has to load.
+
+167
+00:07:50,000 --> 00:07:53,000
+This is why you want to give it a good amount of processor in there.
+
+168
+00:07:53,000 --> 00:07:57,000
+Now we're going to say we don't have a product key because we don't actually have a product key.
+
+169
+00:07:59,000 --> 00:08:00,000
+But virgin.
+
+170
+00:08:00,000 --> 00:08:02,000
+Now you want to install the part I wanted to show you.
+
+171
+00:08:02,000 --> 00:08:04,000
+You want to make sure you select Windows Pro.
+
+172
+00:08:04,000 --> 00:08:09,000
+If you don't select Windows Pro and you go with Windows Home, you're not going to have all the options
+
+173
+00:08:09,000 --> 00:08:11,000
+we need in order to do our labs.
+
+174
+00:08:11,000 --> 00:08:16,000
+So things like managing and creating user accounts, doing permissions, for example, it's going to
+
+175
+00:08:16,000 --> 00:08:20,000
+be much more difficult on Windows Home, enabling Remote Desktop and all that.
+
+176
+00:08:20,000 --> 00:08:22,000
+So we want to make sure we get Windows Pro.
+
+177
+00:08:24,000 --> 00:08:26,000
+Now we're just going to use the entire hard drive.
+
+178
+00:08:26,000 --> 00:08:28,000
+The full 50 gigs is fine.
+
+179
+00:08:28,000 --> 00:08:28,000
+Yeah, yeah.
+
+180
+00:08:28,000 --> 00:08:30,000
+We accept your agreement.
+
+181
+00:08:31,000 --> 00:08:31,000
+Now.
+
+182
+00:08:31,000 --> 00:08:34,000
+Notice it says upgrade, install.
+
+183
+00:08:34,000 --> 00:08:39,000
+Now we're just going to do a custom install windows only, uh, 50 gigs next.
+
+184
+00:08:42,000 --> 00:08:43,000
+And that's it.
+
+185
+00:08:43,000 --> 00:08:46,000
+Now you wait for windows to be installed.
+
+186
+00:08:46,000 --> 00:08:50,000
+So let me pause the video and I'll see you guys back in a second.
+
+187
+00:08:52,000 --> 00:08:57,000
+Okay, so it's finished installing it rebooted a few times and this is where I am.
+
+188
+00:08:57,000 --> 00:09:00,000
+So I'm just going to go through the installation very quickly.
+
+189
+00:09:00,000 --> 00:09:02,000
+Yes, we are in the United States.
+
+190
+00:09:03,000 --> 00:09:07,000
+Um, and I'm going to probably stop the video right now because from here, you guys should know it's
+
+191
+00:09:07,000 --> 00:09:14,000
+basically going to ask you to create a user account, select in your keyboard layout, uh, and basically
+
+192
+00:09:14,000 --> 00:09:16,000
+just create any user account that you need.
+
+193
+00:09:16,000 --> 00:09:21,000
+No, we don't want to add another keyboard here because this takes a while to set up as it has to set
+
+194
+00:09:21,000 --> 00:09:22,000
+up the desktop.
+
+195
+00:09:22,000 --> 00:09:25,000
+So I'm just going to create a user called Andy.
+
+196
+00:09:25,000 --> 00:09:31,000
+Uh, it's what I'm going to do while it works its magic as we can see here.
+
+197
+00:09:32,000 --> 00:09:35,000
+Okay, so keep in mind installing windows is not difficult.
+
+198
+00:09:35,000 --> 00:09:43,000
+Just download the windows media creation, create a ISO, create the virtual machine, attach the ISO
+
+199
+00:09:43,000 --> 00:09:45,000
+to it, and let windows do its magic.
+
+200
+00:09:45,000 --> 00:09:48,000
+All right, let's go on to the next lab now of installing Kali Linux.
+
diff --git a/26 - Labs/003 Installing Kali Linux_en.srt b/26 - Labs/003 Installing Kali Linux_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..c53abc8bce1358a40c373f81fd0f42aa193e172b
--- /dev/null
+++ b/26 - Labs/003 Installing Kali Linux_en.srt
@@ -0,0 +1,520 @@
+1
+00:00:00,000 --> 00:00:01,000
+In the world of IT security.
+
+2
+00:00:01,000 --> 00:00:06,000
+You use a lot of tools to secure networks and also to test them or quote unquote, hack them or pen
+
+3
+00:00:06,000 --> 00:00:07,000
+tested.
+
+4
+00:00:07,000 --> 00:00:10,000
+Now there is a ton of tools.
+
+5
+00:00:10,000 --> 00:00:18,000
+Now what some smart, very, very useful folks did was they created a version of Linux that comes with
+
+6
+00:00:18,000 --> 00:00:23,000
+all the tools we're going to need in order to secure a network or test the security of our networks.
+
+7
+00:00:23,000 --> 00:00:24,000
+That's called Kali Linux.
+
+8
+00:00:24,000 --> 00:00:31,000
+Now, Kali Linux is the most famous, the most famous version of Linux that's used by Pentester because
+
+9
+00:00:31,000 --> 00:00:35,000
+it comes with all the tools versus you having to go and look for all the tools.
+
+10
+00:00:35,000 --> 00:00:36,000
+What tools are those?
+
+11
+00:00:36,000 --> 00:00:37,000
+Don't worry about that.
+
+12
+00:00:37,000 --> 00:00:38,000
+I'll show you them later as we get into it.
+
+13
+00:00:38,000 --> 00:00:42,000
+So let's go ahead and get Kali Linux onto our VM.
+
+14
+00:00:42,000 --> 00:00:47,000
+So let's go ahead and go back to the desktop now Windows 10 installed.
+
+15
+00:00:47,000 --> 00:00:52,000
+By the way I want to mention if you're doing Windows 10 and it asks for a username you can just select
+
+16
+00:00:52,000 --> 00:00:52,000
+it.
+
+17
+00:00:52,000 --> 00:00:55,000
+You're going to be doing it from an organization and domain name and just put a local name.
+
+18
+00:00:55,000 --> 00:00:57,000
+I put Andy as the username.
+
+19
+00:00:57,000 --> 00:00:57,000
+Okay.
+
+20
+00:00:57,000 --> 00:01:00,000
+So I have my Windows 10 installed.
+
+21
+00:01:00,000 --> 00:01:04,000
+I am going to now go ahead and get the Kali Linux.
+
+22
+00:01:05,000 --> 00:01:09,000
+So we're going to say Kali Linux is what I'm looking for.
+
+23
+00:01:10,000 --> 00:01:13,000
+Now we're just going to say download Get Kali.
+
+24
+00:01:14,000 --> 00:01:19,000
+Now you notice that you have installation images and you have virtual machines.
+
+25
+00:01:20,000 --> 00:01:21,000
+Get the virtual machines.
+
+26
+00:01:21,000 --> 00:01:28,000
+You see what virtual machines are are basically pre-installed versions of Kali on basically an image.
+
+27
+00:01:28,000 --> 00:01:33,000
+It's basically an image that we're going to import into virtual VirtualBox.
+
+28
+00:01:33,000 --> 00:01:35,000
+So we don't have to do any of the installation.
+
+29
+00:01:35,000 --> 00:01:37,000
+It bypasses the whole installation.
+
+30
+00:01:37,000 --> 00:01:40,000
+So I highly recommend for you to get the virtual machine image.
+
+31
+00:01:40,000 --> 00:01:42,000
+So let's go back to this.
+
+32
+00:01:42,000 --> 00:01:44,000
+So I'm just going to go here.
+
+33
+00:01:45,000 --> 00:01:49,000
+Virtual machine and you notice it has virtual box.
+
+34
+00:01:49,000 --> 00:01:51,000
+Now we are doing a 64 bit.
+
+35
+00:01:51,000 --> 00:01:54,000
+And I'm just going to click on this download button here.
+
+36
+00:01:54,000 --> 00:01:56,000
+If you could get it off of a torrent.
+
+37
+00:01:56,000 --> 00:01:59,000
+But I find that just downloading off of their website its fast enough.
+
+38
+00:01:59,000 --> 00:02:05,000
+So let's go ahead, click on download and we're going to restart the video when it's finished downloading.
+
+39
+00:02:07,000 --> 00:02:08,000
+Okay.
+
+40
+00:02:08,000 --> 00:02:10,000
+Our Kali Linux has finished downloading.
+
+41
+00:02:10,000 --> 00:02:11,000
+Mine is pretty quick.
+
+42
+00:02:11,000 --> 00:02:12,000
+My internet is pretty good.
+
+43
+00:02:12,000 --> 00:02:13,000
+I'm just going to go ahead in here.
+
+44
+00:02:13,000 --> 00:02:16,000
+I'm going to click on this little box here to open up my installation.
+
+45
+00:02:17,000 --> 00:02:18,000
+And here it is.
+
+46
+00:02:18,000 --> 00:02:22,000
+Now the great thing about doing it the way we just do it is just basically we just have to double click
+
+47
+00:02:22,000 --> 00:02:24,000
+and it'll be ready to work.
+
+48
+00:02:24,000 --> 00:02:26,000
+Now this is going to take a couple of seconds.
+
+49
+00:02:26,000 --> 00:02:29,000
+I'm gonna have to pause the video as I drag this onto my desktop.
+
+50
+00:02:29,000 --> 00:02:30,000
+I'm just going to keep it in that folder.
+
+51
+00:02:31,000 --> 00:02:33,000
+This is going to take a couple of seconds.
+
+52
+00:02:34,000 --> 00:02:39,000
+Because it basically has to uncompress the three gig file we download into about 14 gigs.
+
+53
+00:02:39,000 --> 00:02:41,000
+So this is going to take a few minutes.
+
+54
+00:02:41,000 --> 00:02:45,000
+We'll pause the video again until this is all done, and then we'll mount the machine and we'll be done.
+
+55
+00:02:47,000 --> 00:02:48,000
+All right.
+
+56
+00:02:48,000 --> 00:02:51,000
+It's finished copying over, uh, to the desktop.
+
+57
+00:02:51,000 --> 00:02:52,000
+Let's take a look now.
+
+58
+00:02:52,000 --> 00:02:57,000
+And the great thing about what we did there, instead of have to go through the entire installation,
+
+59
+00:02:57,000 --> 00:03:02,000
+is we just have to double click on the image and it's just going to mount Airwatch.
+
+60
+00:03:02,000 --> 00:03:04,000
+So Carly, I'm going to open this up.
+
+61
+00:03:04,000 --> 00:03:07,000
+And you notice just this blue one.
+
+62
+00:03:07,000 --> 00:03:08,000
+Just double click on it.
+
+63
+00:03:10,000 --> 00:03:10,000
+And that's it.
+
+64
+00:03:10,000 --> 00:03:12,000
+Look, it opens it up.
+
+65
+00:03:12,000 --> 00:03:13,000
+You close this out.
+
+66
+00:03:13,000 --> 00:03:14,000
+We don't need this other one.
+
+67
+00:03:14,000 --> 00:03:15,000
+And there it is.
+
+68
+00:03:15,000 --> 00:03:19,000
+Now, what I do recommend for you, by the way, the username is Kali and the password is Kali.
+
+69
+00:03:19,000 --> 00:03:21,000
+What I do recommend.
+
+70
+00:03:22,000 --> 00:03:27,000
+For you guys to do is to actually change the the Ram.
+
+71
+00:03:27,000 --> 00:03:28,000
+It only comes with two gigs.
+
+72
+00:03:28,000 --> 00:03:29,000
+You can give it four gigs.
+
+73
+00:03:29,000 --> 00:03:30,000
+I'm going to give it about eight gigs.
+
+74
+00:03:30,000 --> 00:03:33,000
+Linux doesn't need as much as windows to run.
+
+75
+00:03:33,000 --> 00:03:36,000
+Technically, I can leave it as two gig and it's probably going to be okay.
+
+76
+00:03:36,000 --> 00:03:39,000
+So I'm going to go ahead and click on settings.
+
+77
+00:03:40,000 --> 00:03:44,000
+I'm going to go to system and I'm going to give it eight gigs.
+
+78
+00:03:44,000 --> 00:03:47,000
+That's the only reason I'm doing that is because I have the Ram for it.
+
+79
+00:03:48,000 --> 00:03:49,000
+If not, I probably won't.
+
+80
+00:03:50,000 --> 00:03:53,000
+And just go ahead and click on start.
+
+81
+00:03:54,000 --> 00:03:56,000
+And now it's going to take a few seconds.
+
+82
+00:03:56,000 --> 00:04:01,000
+Of course, the beginning, the first time it boots up, it's going to take a few minutes or a few seconds.
+
+83
+00:04:01,000 --> 00:04:03,000
+So let's restart.
+
+84
+00:04:03,000 --> 00:04:04,000
+Oh, it's already coming up.
+
+85
+00:04:06,000 --> 00:04:06,000
+All right.
+
+86
+00:04:06,000 --> 00:04:08,000
+It looks like it's starting fine.
+
+87
+00:04:09,000 --> 00:04:11,000
+Close that out there.
+
+88
+00:04:11,000 --> 00:04:12,000
+Look at these notifications.
+
+89
+00:04:12,000 --> 00:04:13,000
+We don't want that.
+
+90
+00:04:14,000 --> 00:04:19,000
+Now, once again, because of my 4K screen, uh, it's hard to see.
+
+91
+00:04:19,000 --> 00:04:20,000
+So I'm going to scale it.
+
+92
+00:04:20,000 --> 00:04:20,000
+So scale it.
+
+93
+00:04:20,000 --> 00:04:24,000
+Basically it's like it's stretching it to whatever display I'm going to give it.
+
+94
+00:04:25,000 --> 00:04:26,000
+So we're going to go to view.
+
+95
+00:04:26,000 --> 00:04:27,000
+And I always use scale mode.
+
+96
+00:04:27,000 --> 00:04:29,000
+So that way I can always manipulate the windows as I want.
+
+97
+00:04:29,000 --> 00:04:31,000
+It's just the way I use VirtualBox.
+
+98
+00:04:31,000 --> 00:04:36,000
+Some people like to do like a full screen mode, but I'm a big scale mode person because that way I
+
+99
+00:04:36,000 --> 00:04:36,000
+don't.
+
+100
+00:04:36,000 --> 00:04:41,000
+It doesn't take over my entire screen, and because I'm going to use a lot of VMs, I want to be able
+
+101
+00:04:41,000 --> 00:04:42,000
+to resize them on the fly.
+
+102
+00:04:44,000 --> 00:04:45,000
+Okay.
+
+103
+00:04:51,000 --> 00:04:54,000
+Now the first time it boots up, it's going to.
+
+104
+00:04:54,000 --> 00:05:00,000
+Depending on how fast your machine is, the first time it boots up, it's probably not going to be the
+
+105
+00:05:00,000 --> 00:05:01,000
+fastest thing out there.
+
+106
+00:05:01,000 --> 00:05:02,000
+All right.
+
+107
+00:05:02,000 --> 00:05:05,000
+So you got to remember that dependent again dependent on your machine.
+
+108
+00:05:05,000 --> 00:05:09,000
+So the username the default username is k a l I.
+
+109
+00:05:09,000 --> 00:05:11,000
+And the password is k a Ali.
+
+110
+00:05:11,000 --> 00:05:14,000
+It's the same username same password.
+
+111
+00:05:14,000 --> 00:05:18,000
+And you can see this is going to log me right in.
+
+112
+00:05:18,000 --> 00:05:18,000
+And that's it.
+
+113
+00:05:18,000 --> 00:05:21,000
+We just got our Kali Linux install.
+
+114
+00:05:21,000 --> 00:05:25,000
+And we are ready to rock and roll with our labs now.
+
+115
+00:05:25,000 --> 00:05:27,000
+So these two videos we got our three videos.
+
+116
+00:05:27,000 --> 00:05:29,000
+We got our VirtualBox install.
+
+117
+00:05:29,000 --> 00:05:34,000
+We got our windows install and we have our Kali Linux install.
+
+118
+00:05:35,000 --> 00:05:41,000
+Now what you should be doing is hopefully, you know, before I go on, you guys, hopefully you guys
+
+119
+00:05:41,000 --> 00:05:42,000
+learned a little bit about Linux.
+
+120
+00:05:42,000 --> 00:05:44,000
+I'm going to assume you know a little bit about Linux.
+
+121
+00:05:44,000 --> 00:05:46,000
+If you're saying you never taught us Linux.
+
+122
+00:05:46,000 --> 00:05:48,000
+I did teach that in a plus.
+
+123
+00:05:48,000 --> 00:05:53,000
+If you don't know Linux, I would highly suggest going through just a quick tutorial like what I did
+
+124
+00:05:53,000 --> 00:05:58,000
+in a plus, like how to copy file, how to move files, how to navigate the command prompt, how to
+
+125
+00:05:58,000 --> 00:06:00,000
+use sudo, and all that type of stuff.
+
+126
+00:06:00,000 --> 00:06:06,000
+We're not going to get much in depth into this as I do that more, um, in my course.
+
+127
+00:06:06,000 --> 00:06:08,000
+But we are going to be using some tools.
+
+128
+00:06:08,000 --> 00:06:10,000
+And if you don't know how to use Linux, don't worry about it.
+
+129
+00:06:10,000 --> 00:06:12,000
+I'm going to walk you guys through all the steps.
+
+130
+00:06:12,000 --> 00:06:14,000
+So let's get started on the labs.
+
diff --git a/26 - Labs/004 Using Snapshots_en.srt b/26 - Labs/004 Using Snapshots_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..940dbd519c90b843dd327ea08b52eb8db01f6bd8
--- /dev/null
+++ b/26 - Labs/004 Using Snapshots_en.srt
@@ -0,0 +1,316 @@
+1
+00:00:00,000 --> 00:00:04,000
+In this video, I'm going to be teaching you something from the objective that's called snapshots.
+
+2
+00:00:04,000 --> 00:00:08,000
+So I want to show you guys this in the objectives underneath backups.
+
+3
+00:00:08,000 --> 00:00:10,000
+Uh, objective 3.4.
+
+4
+00:00:10,000 --> 00:00:12,000
+There's something we call snapshots.
+
+5
+00:00:12,000 --> 00:00:14,000
+What exactly is that.
+
+6
+00:00:14,000 --> 00:00:16,000
+Well you see here's what snapshots are.
+
+7
+00:00:16,000 --> 00:00:22,000
+Snapshots are is basically a quote unquote picture of a machine at a certain point in time.
+
+8
+00:00:22,000 --> 00:00:28,000
+So let's say you installed a server, you installed a windows server, you configured it with a bunch
+
+9
+00:00:28,000 --> 00:00:31,000
+of configurations, you put in specialized software.
+
+10
+00:00:31,000 --> 00:00:34,000
+And then what you should do when you're done is take a snapshot of it.
+
+11
+00:00:34,000 --> 00:00:40,000
+And what that does is that it saves the machine exactly the way you configured it at that time.
+
+12
+00:00:40,000 --> 00:00:45,000
+That way, if months from now or even a couple of years from now, the machine ever gets all crazy or
+
+13
+00:00:45,000 --> 00:00:50,000
+it gets corrupted, you can always restore back the snapshot, so you can always go back in time to
+
+14
+00:00:50,000 --> 00:00:52,000
+a particular place.
+
+15
+00:00:52,000 --> 00:00:53,000
+You know, I'm 42 years old.
+
+16
+00:00:53,000 --> 00:00:59,000
+I wish I had the ability to do a snapshot so I can go back to my 25 year old body.
+
+17
+00:00:59,000 --> 00:01:04,000
+When I was much, much more muscular and lifting a lot of weights because now I can't do that, if you
+
+18
+00:01:04,000 --> 00:01:04,000
+know what I mean.
+
+19
+00:01:04,000 --> 00:01:05,000
+That's what snapshot is.
+
+20
+00:01:05,000 --> 00:01:12,000
+It's ability for you to take a picture of, of a, of a machine and a point in time and then restore
+
+21
+00:01:12,000 --> 00:01:12,000
+back that.
+
+22
+00:01:12,000 --> 00:01:13,000
+So let's take a look how to do it.
+
+23
+00:01:13,000 --> 00:01:18,000
+Now we just finished installing our Kali and our windows.
+
+24
+00:01:18,000 --> 00:01:23,000
+And because those are fresh clean installation, one of the first things I do when I'm finished installing
+
+25
+00:01:23,000 --> 00:01:26,000
+something is I do a snapshot of it and I call it original install.
+
+26
+00:01:26,000 --> 00:01:33,000
+That way, anytime something happens, my machine gets corrupted or I played around too much and installed
+
+27
+00:01:33,000 --> 00:01:33,000
+a virus.
+
+28
+00:01:34,000 --> 00:01:35,000
+Very famous doing that one.
+
+29
+00:01:35,000 --> 00:01:38,000
+Uh, then I can just restore back the machine.
+
+30
+00:01:38,000 --> 00:01:41,000
+So make sure you do a snapshot before you do any of the other labs.
+
+31
+00:01:41,000 --> 00:01:44,000
+And this is something in your exam objectives.
+
+32
+00:01:44,000 --> 00:01:47,000
+So let's go back to our virtual machines.
+
+33
+00:01:48,000 --> 00:01:50,000
+And here I am at my virtual machine.
+
+34
+00:01:50,000 --> 00:01:52,000
+Now, what I'm going to do now, I already have it open.
+
+35
+00:01:52,000 --> 00:01:55,000
+So what you're going to do is you're going to click on Windows 10.
+
+36
+00:01:55,000 --> 00:01:58,000
+You're going to click on the little three dots here or boxes.
+
+37
+00:01:58,000 --> 00:01:59,000
+You're going to say snapshot.
+
+38
+00:01:59,000 --> 00:02:02,000
+And then you're going to do take a snapshot.
+
+39
+00:02:02,000 --> 00:02:05,000
+Now depending on how fast your machine is this can take a few minutes.
+
+40
+00:02:05,000 --> 00:02:10,000
+I always call this one the original install.
+
+41
+00:02:11,000 --> 00:02:12,000
+And then I give it a date.
+
+42
+00:02:12,000 --> 00:02:14,000
+So I know that I installed it on this date.
+
+43
+00:02:14,000 --> 00:02:18,000
+So we're going to say December 2023.
+
+44
+00:02:19,000 --> 00:02:20,000
+Okay.
+
+45
+00:02:20,000 --> 00:02:28,000
+And what it's going to do is that it's going to take a snapshot of that machine at a particular point,
+
+46
+00:02:28,000 --> 00:02:30,000
+and notice I have the ability to restore it.
+
+47
+00:02:30,000 --> 00:02:32,000
+So it just took the snapshot.
+
+48
+00:02:33,000 --> 00:02:38,000
+Now what that means is that I can go in and I could mess up the entire Windows 10, add things, delete
+
+49
+00:02:38,000 --> 00:02:42,000
+things, remove things, and then when I'm ready, I'll just come back here to snapshots.
+
+50
+00:02:42,000 --> 00:02:45,000
+Click on the original install and say restore.
+
+51
+00:02:45,000 --> 00:02:50,000
+Now a lot of administrators do snapshots every time they install software before and after.
+
+52
+00:02:50,000 --> 00:02:54,000
+So to have a snapshot before they install the software and a snapshot after they install the software.
+
+53
+00:02:54,000 --> 00:02:58,000
+That way, if they make any changes to their operating system that corrupts something, they can always
+
+54
+00:02:58,000 --> 00:03:02,000
+resort back or restore back to their previous installation.
+
+55
+00:03:02,000 --> 00:03:05,000
+Let's go ahead and do the same thing here for our Kali.
+
+56
+00:03:06,000 --> 00:03:09,000
+Now, I already did the original install for Kali about six minutes ago.
+
+57
+00:03:09,000 --> 00:03:10,000
+So what?
+
+58
+00:03:10,000 --> 00:03:15,000
+So what you guys should do is just say take and then just give it a name like original install.
+
+59
+00:03:15,000 --> 00:03:15,000
+And that's it.
+
+60
+00:03:15,000 --> 00:03:16,000
+That's all there is to it.
+
+61
+00:03:16,000 --> 00:03:22,000
+And when you want to restore back the snapshot you would just go back to snapshots.
+
+62
+00:03:22,000 --> 00:03:24,000
+Click on the one you want to restore.
+
+63
+00:03:24,000 --> 00:03:25,000
+Now you can have multiple.
+
+64
+00:03:25,000 --> 00:03:30,000
+Maybe you change something on Kali Linux like I already have the original and we can go in there and
+
+65
+00:03:30,000 --> 00:03:38,000
+say take and maybe, uh, install new software, maybe we install something.
+
+66
+00:03:39,000 --> 00:03:40,000
+On that.
+
+67
+00:03:41,000 --> 00:03:43,000
+And now I have installed new software.
+
+68
+00:03:43,000 --> 00:03:48,000
+So now I can restore back to that one and go on and on and on and on from there.
+
+69
+00:03:48,000 --> 00:03:52,000
+So always remember, snapshots are absolutely amazing.
+
+70
+00:03:52,000 --> 00:03:57,000
+If you don't need a snapshot, you can always just go in there and delete that particular snapshot.
+
+71
+00:03:57,000 --> 00:03:58,000
+All right.
+
+72
+00:03:58,000 --> 00:03:59,000
+Very good.
+
+73
+00:03:59,000 --> 00:04:04,000
+So keep in mind, guys, the moment you finish doing your installations, especially on your virtual
+
+74
+00:04:04,000 --> 00:04:07,000
+machines, make sure to take a snapshot.
+
+75
+00:04:07,000 --> 00:04:13,000
+In the real world of administration, we use snapshots as a way to go back in time.
+
+76
+00:04:13,000 --> 00:04:16,000
+An administrator makes a change on a virtual machine.
+
+77
+00:04:16,000 --> 00:04:21,000
+And remember, virtual machines are used a lot on servers, not necessarily workstations, but on servers.
+
+78
+00:04:21,000 --> 00:04:25,000
+So anytime they make a change on a server, the best thing you can do is take a snapshot.
+
+79
+00:04:25,000 --> 00:04:26,000
+Take a snapshot.
+
diff --git a/26 - Labs/005 Using an IP Scanner_en.srt b/26 - Labs/005 Using an IP Scanner_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..d5b34bdc8a72aaccaa865e034d6fbea313d21c58
--- /dev/null
+++ b/26 - Labs/005 Using an IP Scanner_en.srt
@@ -0,0 +1,424 @@
+1
+00:00:00,000 --> 00:00:05,000
+As a security administrator, you're going to have to know what are what is on your network, how many
+
+2
+00:00:05,000 --> 00:00:07,000
+hosts are on your network.
+
+3
+00:00:07,000 --> 00:00:13,000
+So in this lab, we're going to take a look at what's called IP scanning our host scanner or host finding.
+
+4
+00:00:13,000 --> 00:00:17,000
+Basically we're going to use a piece of software to scan your entire network.
+
+5
+00:00:17,000 --> 00:00:20,000
+And it's going to tell you things like the host name of that device and a little bit more information
+
+6
+00:00:20,000 --> 00:00:21,000
+about the device.
+
+7
+00:00:21,000 --> 00:00:23,000
+Now I'm doing this in a virtual environment.
+
+8
+00:00:23,000 --> 00:00:27,000
+So we're not going to get much information from the scanner, but it's going to at least tell us what
+
+9
+00:00:27,000 --> 00:00:29,000
+the hosts are on our network.
+
+10
+00:00:29,000 --> 00:00:34,000
+So you could try this on your internal network to see all the devices that you have.
+
+11
+00:00:34,000 --> 00:00:38,000
+Or if you're in a business network, you can try it and see all the different devices that's out there.
+
+12
+00:00:39,000 --> 00:00:43,000
+I'm doing this on my windows box and we're going to use a software called angry IP scanner.
+
+13
+00:00:43,000 --> 00:00:45,000
+This scanner is really angry.
+
+14
+00:00:45,000 --> 00:00:46,000
+It's one of my favorite piece of software to use.
+
+15
+00:00:46,000 --> 00:00:48,000
+It's really simple and really easy to use.
+
+16
+00:00:48,000 --> 00:00:49,000
+Let's get started.
+
+17
+00:00:50,000 --> 00:00:52,000
+So here I am.
+
+18
+00:00:52,000 --> 00:01:00,000
+I'm at my Windows 10 box and I downloaded I install Chrome because I can't stand, uh, fire.
+
+19
+00:01:00,000 --> 00:01:02,000
+I can't stand edge.
+
+20
+00:01:02,000 --> 00:01:06,000
+So I downloaded Chrome and I searched for angry IP scanner.
+
+21
+00:01:06,000 --> 00:01:10,000
+And basically you would just go to this option.
+
+22
+00:01:10,000 --> 00:01:12,000
+It says download for windows.
+
+23
+00:01:12,000 --> 00:01:16,000
+Now I like the standalone standalone executable.
+
+24
+00:01:16,000 --> 00:01:22,000
+That way you can just open it when you want and you're ready to go versus the windows installer that
+
+25
+00:01:22,000 --> 00:01:24,000
+includes the Java runtime.
+
+26
+00:01:24,000 --> 00:01:26,000
+Now it does need Java in order to run.
+
+27
+00:01:26,000 --> 00:01:29,000
+The Java is just a software that allows other applications to run.
+
+28
+00:01:29,000 --> 00:01:34,000
+So if you if you do the Windows installer, it's just one installation, but then it's always on your
+
+29
+00:01:34,000 --> 00:01:35,000
+machine.
+
+30
+00:01:35,000 --> 00:01:38,000
+If you do the standalone, you just have to install this first.
+
+31
+00:01:38,000 --> 00:01:39,000
+So you would just click on this.
+
+32
+00:01:40,000 --> 00:01:40,000
+All right.
+
+33
+00:01:40,000 --> 00:01:41,000
+Just close the add.
+
+34
+00:01:43,000 --> 00:01:46,000
+Except the cookies looking to download Java.
+
+35
+00:01:46,000 --> 00:01:53,000
+And then you just go ahead and download the Java that basically the first one here and download and
+
+36
+00:01:53,000 --> 00:01:55,000
+install it on your machine.
+
+37
+00:01:55,000 --> 00:01:59,000
+So like I have windows, you will just download and you notice it's downloaded there.
+
+38
+00:01:59,000 --> 00:02:00,000
+Now I already downloaded it.
+
+39
+00:02:00,000 --> 00:02:03,000
+You can see it was here and I've already installed it.
+
+40
+00:02:03,000 --> 00:02:07,000
+When you're finished downloading Java, the next thing you're going to do is you're going to download
+
+41
+00:02:07,000 --> 00:02:11,000
+the standalone executable, which I have done already.
+
+42
+00:02:11,000 --> 00:02:12,000
+This one right here.
+
+43
+00:02:14,000 --> 00:02:19,000
+Now I'm going to close this out and I'm going to open up.
+
+44
+00:02:19,000 --> 00:02:20,000
+Here's a quick tip.
+
+45
+00:02:20,000 --> 00:02:25,000
+If you don't know your windows command just do window E to open up your explorer box file Explorer.
+
+46
+00:02:26,000 --> 00:02:28,000
+We're going to then go to downloads.
+
+47
+00:02:30,000 --> 00:02:32,000
+And you can see angry IP scanner is here.
+
+48
+00:02:32,000 --> 00:02:35,000
+Now you remember you have to download and install Java already.
+
+49
+00:02:35,000 --> 00:02:37,000
+So we're going to double click on this.
+
+50
+00:02:38,000 --> 00:02:41,000
+And let this start up now.
+
+51
+00:02:41,000 --> 00:02:44,000
+Basically what this does is you put a range of IP addresses in.
+
+52
+00:02:44,000 --> 00:02:49,000
+So right now this is going to use the entire ten .0.2.
+
+53
+00:02:50,000 --> 00:02:50,000
+Range.
+
+54
+00:02:50,000 --> 00:02:55,000
+The netmask on this is basically a slash 24 if you don't know.
+
+55
+00:02:55,000 --> 00:02:57,000
+IP address and please learn IP addressing.
+
+56
+00:02:58,000 --> 00:02:59,000
+So it's this entire range.
+
+57
+00:02:59,000 --> 00:03:02,000
+Now this is what the virtual machine is based on.
+
+58
+00:03:02,000 --> 00:03:08,000
+So if I do window hold the window key down press R to open up your run command and do cmd.
+
+59
+00:03:08,000 --> 00:03:10,000
+I want to see the IP address of this machine.
+
+60
+00:03:10,000 --> 00:03:13,000
+So we're going to do ipconfig.
+
+61
+00:03:13,000 --> 00:03:19,000
+So you can see that this is a ten .0.2.15 is the IP address on this machine.
+
+62
+00:03:20,000 --> 00:03:25,000
+And let's take a look at Kali because it's going to it should be able to find a Kali box also.
+
+63
+00:03:26,000 --> 00:03:28,000
+So I'm going to log in here and um.
+
+64
+00:03:31,000 --> 00:03:35,000
+You can go ahead and and, uh, just to open your colleague command prompt, let me just do it again
+
+65
+00:03:35,000 --> 00:03:36,000
+for you.
+
+66
+00:03:36,000 --> 00:03:38,000
+Open up your command prompt and Kali and Linux.
+
+67
+00:03:38,000 --> 00:03:40,000
+It's not ipconfig it's ipconfig.
+
+68
+00:03:41,000 --> 00:03:44,000
+And you can see your IP address is there.
+
+69
+00:03:44,000 --> 00:03:48,000
+And basically it's going to find the IP address of these machines.
+
+70
+00:03:48,000 --> 00:03:53,000
+So let's go ahead and close this minimize that and start our scan.
+
+71
+00:03:53,000 --> 00:03:57,000
+So what it's going to do is that it's going to start scanning your entire network.
+
+72
+00:03:57,000 --> 00:03:58,000
+All right.
+
+73
+00:03:58,000 --> 00:03:59,000
+That's what this thing does.
+
+74
+00:03:59,000 --> 00:04:05,000
+It scans all the computers on your network and it finds hey is what host is alive.
+
+75
+00:04:05,000 --> 00:04:08,000
+What host is not alive on your network.
+
+76
+00:04:08,000 --> 00:04:16,000
+So I can see that I got some hosts attend at 2.22.32.42.15.
+
+77
+00:04:16,000 --> 00:04:17,000
+We know it's the Kali box.
+
+78
+00:04:17,000 --> 00:04:19,000
+Uh, and we don't have anything else on this network.
+
+79
+00:04:19,000 --> 00:04:24,000
+This is a really small, just a few, uh, computers that have running on my virtual machines.
+
+80
+00:04:25,000 --> 00:04:29,000
+So that's what this software does, and that's all it does.
+
+81
+00:04:29,000 --> 00:04:31,000
+And then you can, if it finds more information.
+
+82
+00:04:31,000 --> 00:04:33,000
+So it found for host is alive.
+
+83
+00:04:33,000 --> 00:04:36,000
+So if it finds for for hosts you can double click.
+
+84
+00:04:36,000 --> 00:04:43,000
+And if it if it's able to get the host name it'll tell you that host name and ports uh on that machine.
+
+85
+00:04:43,000 --> 00:04:45,000
+And that's all this thing does.
+
+86
+00:04:45,000 --> 00:04:49,000
+It really does not do really anything else that's here.
+
+87
+00:04:49,000 --> 00:04:52,000
+Notice commands is just to rescan or delete IPS.
+
+88
+00:04:52,000 --> 00:04:53,000
+That is all this thing does.
+
+89
+00:04:54,000 --> 00:04:59,000
+So in this lab, this is a this lab, you learned about this really great tool and what this tool is
+
+90
+00:04:59,000 --> 00:05:00,000
+going to do.
+
+91
+00:05:00,000 --> 00:05:01,000
+You're probably wondering, okay, I'm a security person.
+
+92
+00:05:01,000 --> 00:05:02,000
+How does this help me?
+
+93
+00:05:02,000 --> 00:05:05,000
+Well, imagine you're managing a network.
+
+94
+00:05:05,000 --> 00:05:09,000
+And on your network, you know that you should have an inventory of hoses.
+
+95
+00:05:09,000 --> 00:05:10,000
+You should know.
+
+96
+00:05:10,000 --> 00:05:11,000
+Well, on my network right now.
+
+97
+00:05:11,000 --> 00:05:13,000
+Should have 50 hoses.
+
+98
+00:05:13,000 --> 00:05:17,000
+And then you do you run this tool or this scan and you realize, why do I have 60 hoses?
+
+99
+00:05:17,000 --> 00:05:20,000
+Now you got to investigate who has that IP address.
+
+100
+00:05:20,000 --> 00:05:22,000
+Why is that IP address being used?
+
+101
+00:05:22,000 --> 00:05:24,000
+Do we have a rogue computer on the network?
+
+102
+00:05:24,000 --> 00:05:28,000
+Has somebody attached something to the network that didn't have permission to or doesn't meet certain
+
+103
+00:05:28,000 --> 00:05:30,000
+security policies?
+
+104
+00:05:30,000 --> 00:05:31,000
+So keep that in mind.
+
+105
+00:05:31,000 --> 00:05:32,000
+That's what this software does.
+
+106
+00:05:32,000 --> 00:05:36,000
+It's an incredibly useful tool for finding computers on your network.
+
diff --git a/26 - Labs/006 Using the Nessus Vulnerability scanner_en.srt b/26 - Labs/006 Using the Nessus Vulnerability scanner_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..18d5c6b65cb6dfe0c57e331805abb78021a14a09
--- /dev/null
+++ b/26 - Labs/006 Using the Nessus Vulnerability scanner_en.srt
@@ -0,0 +1,1040 @@
+1
+00:00:00,000 --> 00:00:04,000
+In this lab we're going to learn about vulnerability scanners.
+
+2
+00:00:04,000 --> 00:00:06,000
+But before we start, let's go through a scenario.
+
+3
+00:00:06,000 --> 00:00:12,000
+Imagine you're in charge of managing 500 computers as a security administrator.
+
+4
+00:00:12,000 --> 00:00:16,000
+Now, more than likely, a few of those machines are vulnerable.
+
+5
+00:00:16,000 --> 00:00:21,000
+Vulnerable or a vulnerability could be something as the machine is missing an update and could be infected
+
+6
+00:00:21,000 --> 00:00:24,000
+with potential malware because it just doesn't have the right updates.
+
+7
+00:00:24,000 --> 00:00:27,000
+So what you want to do is you want to scan all 500 machines.
+
+8
+00:00:27,000 --> 00:00:30,000
+Now you could do that one at a time.
+
+9
+00:00:30,000 --> 00:00:32,000
+It'll just take you a few billion years to do it.
+
+10
+00:00:33,000 --> 00:00:35,000
+And the more machines you have, the more time it will take.
+
+11
+00:00:35,000 --> 00:00:39,000
+So what you want to do is you want to get an automated scanner.
+
+12
+00:00:39,000 --> 00:00:45,000
+Automated scanners are basically it's a piece of software that scans your entire network and tells you
+
+13
+00:00:45,000 --> 00:00:47,000
+all the vulnerabilities that are on your network.
+
+14
+00:00:47,000 --> 00:00:49,000
+It's going to say, hey, that machine over there, that one needs an update.
+
+15
+00:00:49,000 --> 00:00:51,000
+That one has a default password.
+
+16
+00:00:51,000 --> 00:00:57,000
+So it'll tell you what is, you know, what exactly you need to fix and how critical these vulnerabilities
+
+17
+00:00:57,000 --> 00:00:57,000
+are.
+
+18
+00:00:57,000 --> 00:00:59,000
+So it's a great piece of software.
+
+19
+00:00:59,000 --> 00:01:03,000
+Now, the software we're going to be using in this labs is the Nexus security scanner.
+
+20
+00:01:03,000 --> 00:01:08,000
+It is the world, one of the world's, if not the world's most used vulnerability scanner.
+
+21
+00:01:08,000 --> 00:01:12,000
+Good news for us is that they have a free version called the Nexus Essentials.
+
+22
+00:01:12,000 --> 00:01:14,000
+You can use this to scan up to 16 computers.
+
+23
+00:01:14,000 --> 00:01:18,000
+So if you're managing a small network or if you just want to do this at home.
+
+24
+00:01:19,000 --> 00:01:20,000
+Scan your network at home.
+
+25
+00:01:20,000 --> 00:01:23,000
+You can download and install this because that's what we're going to be doing now.
+
+26
+00:01:23,000 --> 00:01:26,000
+I'm going to be doing this on my Windows 10 VM.
+
+27
+00:01:26,000 --> 00:01:30,000
+If you want to do it and scan your entire home network, you can actually just install this on your
+
+28
+00:01:30,000 --> 00:01:32,000
+base machine and not on your virtual machine.
+
+29
+00:01:32,000 --> 00:01:36,000
+It's a good piece of software to have installed and scanned computers.
+
+30
+00:01:36,000 --> 00:01:41,000
+So again, you could just put this on your laptop and just go around scanning maybe your network or
+
+31
+00:01:41,000 --> 00:01:45,000
+your friends network or something like that to see what exactly is vulnerable.
+
+32
+00:01:45,000 --> 00:01:47,000
+Again, it's up to 16 computers.
+
+33
+00:01:47,000 --> 00:01:48,000
+So you got to remember that.
+
+34
+00:01:49,000 --> 00:01:51,000
+Let me show you how to do it now.
+
+35
+00:01:51,000 --> 00:01:53,000
+I've already downloaded a copy of this a while back.
+
+36
+00:01:53,000 --> 00:01:58,000
+I'm going to show you where to get it, and then I'm going to show you, uh, I'm going to show you
+
+37
+00:01:58,000 --> 00:02:00,000
+where to get it, and then I'll show you what steps to take.
+
+38
+00:02:00,000 --> 00:02:03,000
+But I've already downloaded it on my machine.
+
+39
+00:02:03,000 --> 00:02:06,000
+So I do have a downloaded install and I have an account set up.
+
+40
+00:02:06,000 --> 00:02:07,000
+So you're going to need to set up an account.
+
+41
+00:02:07,000 --> 00:02:09,000
+You will need to provide an email.
+
+42
+00:02:09,000 --> 00:02:10,000
+Again it's a free software.
+
+43
+00:02:10,000 --> 00:02:12,000
+Don't worry about giving them your email.
+
+44
+00:02:12,000 --> 00:02:13,000
+They are a security company.
+
+45
+00:02:13,000 --> 00:02:15,000
+They're not going to spam you.
+
+46
+00:02:15,000 --> 00:02:17,000
+I know a lot of people are scared to do that.
+
+47
+00:02:17,000 --> 00:02:20,000
+Let's go to Google and let's type in the Nexus scanner.
+
+48
+00:02:20,000 --> 00:02:23,000
+Nexus Scanner Essentials is what we're looking for.
+
+49
+00:02:23,000 --> 00:02:25,000
+The essential essentials version.
+
+50
+00:02:25,000 --> 00:02:27,000
+We're going to go down to the first link here.
+
+51
+00:02:27,000 --> 00:02:32,000
+And I have the tenable name of a company that makes it Nexus Essentials Vulnerability Scanner.
+
+52
+00:02:33,000 --> 00:02:38,000
+And it wants you to fill this out and then get started, and then you'll get the download link right
+
+53
+00:02:38,000 --> 00:02:39,000
+after you do this.
+
+54
+00:02:39,000 --> 00:02:41,000
+So go ahead and put your first name.
+
+55
+00:02:41,000 --> 00:02:42,000
+Put your last name in here.
+
+56
+00:02:42,000 --> 00:02:43,000
+Put your.
+
+57
+00:02:43,000 --> 00:02:44,000
+It says business email.
+
+58
+00:02:44,000 --> 00:02:46,000
+But I put a Gmail and it worked fine for me.
+
+59
+00:02:46,000 --> 00:02:49,000
+And then go ahead and click Get Started.
+
+60
+00:02:49,000 --> 00:02:51,000
+Okay I'm going to pause the video here so you guys can do that.
+
+61
+00:02:51,000 --> 00:02:54,000
+And then we'll resume the video once you've downloaded it.
+
+62
+00:02:55,000 --> 00:02:58,000
+Okay, so I have actually put it.
+
+63
+00:02:58,000 --> 00:03:00,000
+I've actually given them my email address.
+
+64
+00:03:00,000 --> 00:03:01,000
+They sent me a link.
+
+65
+00:03:01,000 --> 00:03:05,000
+And then I'm at this particular screen here where it tells me, hey, you have to download the scanner.
+
+66
+00:03:05,000 --> 00:03:07,000
+So we're actually going to go just go and download the scanner.
+
+67
+00:03:07,000 --> 00:03:10,000
+So we'll say view downloads.
+
+68
+00:03:10,000 --> 00:03:12,000
+And then I'm going to go here.
+
+69
+00:03:12,000 --> 00:03:14,000
+So we're just doing just the latest version.
+
+70
+00:03:14,000 --> 00:03:18,000
+We're doing uh, windows x86 64 bit version of windows we have here.
+
+71
+00:03:18,000 --> 00:03:20,000
+And we're just going to say download.
+
+72
+00:03:21,000 --> 00:03:22,000
+I agree.
+
+73
+00:03:22,000 --> 00:03:24,000
+And, uh, that's it.
+
+74
+00:03:24,000 --> 00:03:27,000
+We're just going to let this download and then we're going to install it now.
+
+75
+00:03:27,000 --> 00:03:28,000
+So let's go and install it.
+
+76
+00:03:30,000 --> 00:03:31,000
+All right.
+
+77
+00:03:31,000 --> 00:03:32,000
+We're going to go ahead and click on next.
+
+78
+00:03:33,000 --> 00:03:35,000
+Now we're just going to do a default install, right?
+
+79
+00:03:35,000 --> 00:03:36,000
+Nothing special.
+
+80
+00:03:36,000 --> 00:03:39,000
+We're not going to change any of the options.
+
+81
+00:03:39,000 --> 00:03:40,000
+I'm just going to keep clicking on install.
+
+82
+00:03:40,000 --> 00:03:43,000
+And it should be relatively quick to install.
+
+83
+00:03:43,000 --> 00:03:48,000
+Now the problem with this software is that it's going to have to do a bunch of downloads of plugins
+
+84
+00:03:48,000 --> 00:03:52,000
+and then installing those plugins, and that could take like 30 minutes.
+
+85
+00:03:52,000 --> 00:03:53,000
+So I'll tell you guys.
+
+86
+00:03:54,000 --> 00:04:00,000
+And I'm going to tell you guys it's not something that is very quickly, uh, or easily done, but you're
+
+87
+00:04:00,000 --> 00:04:01,000
+going to have to make sure that you have the key.
+
+88
+00:04:01,000 --> 00:04:03,000
+So let this install.
+
+89
+00:04:03,000 --> 00:04:05,000
+Once this is done, I'll restart the video.
+
+90
+00:04:05,000 --> 00:04:06,000
+Okay.
+
+91
+00:04:06,000 --> 00:04:07,000
+So I'll see you guys in a second.
+
+92
+00:04:08,000 --> 00:04:11,000
+Okay this is our finished installing.
+
+93
+00:04:11,000 --> 00:04:13,000
+So we're just going to going to go ahead and click on finish.
+
+94
+00:04:16,000 --> 00:04:20,000
+Now it's completely finished installing.
+
+95
+00:04:20,000 --> 00:04:24,000
+Now, what you're going to want to do is you're going to want to make sure just to close it.
+
+96
+00:04:24,000 --> 00:04:26,000
+And I want you to keep a note on this.
+
+97
+00:04:26,000 --> 00:04:28,000
+It's installed in a browser.
+
+98
+00:04:28,000 --> 00:04:28,000
+All right.
+
+99
+00:04:28,000 --> 00:04:30,000
+So you have to access it through a browser.
+
+100
+00:04:30,000 --> 00:04:35,000
+It's not like a regular application like you would have like on Microsoft Word or something.
+
+101
+00:04:35,000 --> 00:04:39,000
+So what I like to do is I'm just going to copy this, not the whole thing.
+
+102
+00:04:39,000 --> 00:04:43,000
+I'm just going to copy the local host because it runs on port 80 834.
+
+103
+00:04:43,000 --> 00:04:47,000
+I'm just going to copy this, and I'm going to put it here in a little text file.
+
+104
+00:04:48,000 --> 00:04:53,000
+Now, the reason for that is because you have to remember this every time you want to access it.
+
+105
+00:04:54,000 --> 00:04:56,000
+So we're just going to close this.
+
+106
+00:04:56,000 --> 00:04:57,000
+Give it a quick save.
+
+107
+00:04:58,000 --> 00:05:01,000
+I'm gonna call this Nexus launcher.
+
+108
+00:05:02,000 --> 00:05:04,000
+I that's I probably misspelled that, didn't I?
+
+109
+00:05:05,000 --> 00:05:09,000
+Uh, and you see, look, if I go to it and I just open it.
+
+110
+00:05:10,000 --> 00:05:11,000
+Oops.
+
+111
+00:05:11,000 --> 00:05:11,000
+It wants.
+
+112
+00:05:11,000 --> 00:05:14,000
+It actually has to be installed correctly.
+
+113
+00:05:15,000 --> 00:05:16,000
+All right, here it is.
+
+114
+00:05:16,000 --> 00:05:17,000
+Wrong browser.
+
+115
+00:05:17,000 --> 00:05:18,000
+All right.
+
+116
+00:05:18,000 --> 00:05:19,000
+So it wants me to set it up.
+
+117
+00:05:19,000 --> 00:05:20,000
+Let's set it up.
+
+118
+00:05:20,000 --> 00:05:23,000
+And then we can launch it from from that particular link.
+
+119
+00:05:23,000 --> 00:05:25,000
+So we're going to say connect via SSL.
+
+120
+00:05:25,000 --> 00:05:26,000
+That's fine.
+
+121
+00:05:26,000 --> 00:05:29,000
+Now it is going to tell you that it is not valid.
+
+122
+00:05:29,000 --> 00:05:33,000
+Now what I did wrong here is I forgot to turn Chrome into my default browser, so it didn't work before
+
+123
+00:05:33,000 --> 00:05:37,000
+I realized I'm in, uh, my least favorite browser edge.
+
+124
+00:05:37,000 --> 00:05:40,000
+So let's go ahead and say continue to localhost.
+
+125
+00:05:41,000 --> 00:05:44,000
+And uh, we're going to go ahead and click on continue.
+
+126
+00:05:44,000 --> 00:05:47,000
+We're registering for the next essential.
+
+127
+00:05:47,000 --> 00:05:48,000
+Click continue.
+
+128
+00:05:49,000 --> 00:05:53,000
+And we're going to skip this because we already have the activation code.
+
+129
+00:05:53,000 --> 00:05:55,000
+So we're going to go ahead and put the activation code.
+
+130
+00:05:55,000 --> 00:05:58,000
+And I'm just going to copy paste mine because I have it.
+
+131
+00:05:58,000 --> 00:06:02,000
+You put yours in there and hold on one second and you put mine's one second.
+
+132
+00:06:03,000 --> 00:06:03,000
+Okay.
+
+133
+00:06:03,000 --> 00:06:06,000
+So I've put in my activation code and I'm ready to go.
+
+134
+00:06:06,000 --> 00:06:09,000
+Now it wants me to create a username and password to log in to this thing.
+
+135
+00:06:09,000 --> 00:06:12,000
+So let's go ahead and do that.
+
+136
+00:06:13,000 --> 00:06:19,000
+Put in my I have a default password that I use for everything when I'm studying.
+
+137
+00:06:19,000 --> 00:06:20,000
+You can try this one.
+
+138
+00:06:20,000 --> 00:06:21,000
+It's basically the word password.
+
+139
+00:06:21,000 --> 00:06:26,000
+And it's capital P with an add sign ss w zero rd.
+
+140
+00:06:26,000 --> 00:06:30,000
+This will meet most complexity requirements if your software requires it.
+
+141
+00:06:30,000 --> 00:06:33,000
+Don't use this in the real world, only use it for practicing.
+
+142
+00:06:34,000 --> 00:06:35,000
+All right.
+
+143
+00:06:35,000 --> 00:06:36,000
+Setup is complete.
+
+144
+00:06:36,000 --> 00:06:41,000
+Now, this is the part that's going to take an incredible amount of time, depending on how fast your
+
+145
+00:06:41,000 --> 00:06:46,000
+internet connection is and depending on how fast your VMs are, it can take a very long time.
+
+146
+00:06:46,000 --> 00:06:51,000
+This can take 30 40 minutes again depending on how fast your machine is.
+
+147
+00:06:51,000 --> 00:06:54,000
+For me, it shouldn't take too long, but I'm hoping it doesn't take too long.
+
+148
+00:06:54,000 --> 00:07:00,000
+So I'm going to pause the video here and we'll return when this is done, because it has to download
+
+149
+00:07:00,000 --> 00:07:02,000
+and then it has to install all of these plugins.
+
+150
+00:07:02,000 --> 00:07:04,000
+So let's see how fast this gets done.
+
+151
+00:07:04,000 --> 00:07:06,000
+I'll see you in a few seconds.
+
+152
+00:07:06,000 --> 00:07:06,000
+Okay.
+
+153
+00:07:06,000 --> 00:07:11,000
+So it has actually finished uh, installing and I've logged back in.
+
+154
+00:07:11,000 --> 00:07:16,000
+Now what I did do is that I closed it out from edge because I had my drawer on an edge, and I reopened
+
+155
+00:07:16,000 --> 00:07:18,000
+it in, uh, Chrome.
+
+156
+00:07:18,000 --> 00:07:24,000
+So one thing I forgot to mention when I told you guys to save the the actual URL so you can easily get
+
+157
+00:07:24,000 --> 00:07:27,000
+to it, was that don't forget to put Https on here.
+
+158
+00:07:27,000 --> 00:07:29,000
+And I originally copied it wasn't didn't have the.
+
+159
+00:07:29,000 --> 00:07:35,000
+Yes because it is Https by the way, if you know if you don't know what you're looking at, the localhost
+
+160
+00:07:35,000 --> 00:07:37,000
+means that it's just going to be your machine.
+
+161
+00:07:37,000 --> 00:07:41,000
+So it's run on a web server on your computer and it's actually running it through port eight, eight,
+
+162
+00:07:41,000 --> 00:07:43,000
+three four on your machine.
+
+163
+00:07:44,000 --> 00:07:50,000
+So I've opened it up, uh, on the actual browser on Chrome, which I like.
+
+164
+00:07:50,000 --> 00:07:53,000
+And in this video I want to show you guys how just to run a scan.
+
+165
+00:07:53,000 --> 00:07:58,000
+Now, if it pops up and it acts as for your it acts for your network ID, it may pop up.
+
+166
+00:07:58,000 --> 00:08:02,000
+It did ask me that before, what's the network that is going to be scanned and just go ahead and put
+
+167
+00:08:02,000 --> 00:08:02,000
+it in.
+
+168
+00:08:02,000 --> 00:08:06,000
+But I cancel it because I want to show you in the video how to find your network.
+
+169
+00:08:06,000 --> 00:08:09,000
+So how do you find your network?
+
+170
+00:08:09,000 --> 00:08:13,000
+Well, you have to find the IP address of the machine that you're on to find your entire network.
+
+171
+00:08:13,000 --> 00:08:14,000
+So how do we do that.
+
+172
+00:08:14,000 --> 00:08:15,000
+Well we're just going to use ipconfig.
+
+173
+00:08:15,000 --> 00:08:17,000
+So let's do window key.
+
+174
+00:08:17,000 --> 00:08:18,000
+Hold it down.
+
+175
+00:08:18,000 --> 00:08:20,000
+Press the letter R to open up a run box.
+
+176
+00:08:20,000 --> 00:08:24,000
+We'll type cmd for command and then we'll do ipconfig.
+
+177
+00:08:25,000 --> 00:08:29,000
+And you notice my computer is ten .0.2.15.
+
+178
+00:08:29,000 --> 00:08:31,000
+Let's make this bigger for you guys to see.
+
+179
+00:08:32,000 --> 00:08:36,000
+And the subnet mask is 255 250 5.0.
+
+180
+00:08:36,000 --> 00:08:37,000
+So this is a slash 24.
+
+181
+00:08:37,000 --> 00:08:42,000
+So the network ID here is ten .0.2.0 slash 24.
+
+182
+00:08:42,000 --> 00:08:46,000
+So we need to know that because when we create the scan we got to tell it what we want to scan.
+
+183
+00:08:47,000 --> 00:08:49,000
+So let's go ahead and say create a new scan.
+
+184
+00:08:49,000 --> 00:08:52,000
+I'm going to do a basic network scanner.
+
+185
+00:08:53,000 --> 00:08:58,000
+And we're going to go in here and I'm going to call it my home network.
+
+186
+00:08:59,000 --> 00:09:00,000
+And we'll just do a scan.
+
+187
+00:09:00,000 --> 00:09:01,000
+That's fine.
+
+188
+00:09:01,000 --> 00:09:02,000
+We'll do.
+
+189
+00:09:03,000 --> 00:09:05,000
+Ten .0.2.0.
+
+190
+00:09:05,000 --> 00:09:08,000
+Slash 24.
+
+191
+00:09:08,000 --> 00:09:10,000
+We'll go ahead and save that.
+
+192
+00:09:11,000 --> 00:09:13,000
+And what you're going to do now depending on your network.
+
+193
+00:09:13,000 --> 00:09:15,000
+All right I'm going to click on this.
+
+194
+00:09:15,000 --> 00:09:18,000
+Depending on your network this can take a long time or it could be pretty quick.
+
+195
+00:09:18,000 --> 00:09:20,000
+But this is all done within a virtual environment.
+
+196
+00:09:20,000 --> 00:09:21,000
+So it should go by pretty quickly.
+
+197
+00:09:21,000 --> 00:09:24,000
+So we're going to say launch and that's it.
+
+198
+00:09:24,000 --> 00:09:30,000
+You just go grab yourself some lunch, get yourself some dinner, get yourself a cup of coffee, do
+
+199
+00:09:30,000 --> 00:09:32,000
+something like that and let it scan.
+
+200
+00:09:32,000 --> 00:09:38,000
+Let it find all those vulnerabilities that are going to be on your actual network.
+
+201
+00:09:38,000 --> 00:09:40,000
+And it's going to take a couple of seconds to run.
+
+202
+00:09:41,000 --> 00:09:42,000
+For me, it's going to be really quick.
+
+203
+00:09:42,000 --> 00:09:44,000
+That's why I'm not pausing the video.
+
+204
+00:09:44,000 --> 00:09:48,000
+But for you guys, depending on how big your network is, it could take a long time.
+
+205
+00:09:48,000 --> 00:09:53,000
+Now, I do want to point out that it uses the Cvss version 3.0.
+
+206
+00:09:53,000 --> 00:09:56,000
+Now if you guys remember this, the common vulnerability scoring system.
+
+207
+00:09:56,000 --> 00:09:58,000
+We covered this when we covered the class.
+
+208
+00:09:58,000 --> 00:10:01,000
+So this tells me how severe a particular vulnerability is going to be.
+
+209
+00:10:01,000 --> 00:10:05,000
+So remember that now depending on remember this number.
+
+210
+00:10:05,000 --> 00:10:10,000
+You know you get something like a 2.0 on a vulnerability on a cvss score.
+
+211
+00:10:10,000 --> 00:10:13,000
+Not really worry about, but you get something like a 9.9.
+
+212
+00:10:13,000 --> 00:10:18,000
+You better leave your bed and go fix that right away, as that is drastically bad for your network.
+
+213
+00:10:18,000 --> 00:10:22,000
+So you notice that it found four computers on my network and.
+
+214
+00:10:24,000 --> 00:10:25,000
+Now it's telling me.
+
+215
+00:10:25,000 --> 00:10:27,000
+Now you got to watch this section here.
+
+216
+00:10:27,000 --> 00:10:30,000
+Anything that's informational, not worry about it.
+
+217
+00:10:30,000 --> 00:10:31,000
+Just saying that.
+
+218
+00:10:31,000 --> 00:10:32,000
+Hey, there's something on here.
+
+219
+00:10:32,000 --> 00:10:34,000
+It's doing this.
+
+220
+00:10:34,000 --> 00:10:40,000
+But if you find vulnerabilities that says low, medium or especially high or critical, you're going
+
+221
+00:10:40,000 --> 00:10:41,000
+to want to make sure that you investigate that.
+
+222
+00:10:41,000 --> 00:10:48,000
+It's going to say this particular host has this thing, um, so you can go in here and click on it and
+
+223
+00:10:48,000 --> 00:10:52,000
+it's saying, this machine here, SMB service detection.
+
+224
+00:10:52,000 --> 00:10:53,000
+What is that?
+
+225
+00:10:53,000 --> 00:10:54,000
+Well, it's running.
+
+226
+00:10:54,000 --> 00:10:56,000
+It has the ability to share files.
+
+227
+00:10:56,000 --> 00:10:58,000
+This provides access to files and printers.
+
+228
+00:10:58,000 --> 00:11:01,000
+It's not saying this is bad, it's just an information.
+
+229
+00:11:01,000 --> 00:11:05,000
+You see if you look here it tells you that this is information.
+
+230
+00:11:05,000 --> 00:11:09,000
+If you see something that's a dark red like I have here, you're going to want to fix it.
+
+231
+00:11:09,000 --> 00:11:12,000
+So that's what a vulnerability scanner is all about.
+
+232
+00:11:12,000 --> 00:11:17,000
+It's nothing more than a piece of software that scans your entire network and says, this machine or
+
+233
+00:11:17,000 --> 00:11:20,000
+this machine has critical vulnerabilities, that machine.
+
+234
+00:11:20,000 --> 00:11:23,000
+Here's some information about it like we have on this system.
+
+235
+00:11:23,000 --> 00:11:27,000
+This machine has high vulnerabilities or the vulnerabilities here are pretty high.
+
+236
+00:11:27,000 --> 00:11:29,000
+You need to fix it or medium or low.
+
+237
+00:11:29,000 --> 00:11:36,000
+I say anything that is medium, high or low in the scanner over here is something, you know, these
+
+238
+00:11:36,000 --> 00:11:38,000
+three ones critical, medium and high.
+
+239
+00:11:38,000 --> 00:11:40,000
+You want to take a look at right away.
+
+240
+00:11:40,000 --> 00:11:44,000
+You want to go to that physical machine because you can click on it and it's going to tell you what
+
+241
+00:11:44,000 --> 00:11:45,000
+the machine is.
+
+242
+00:11:45,000 --> 00:11:49,000
+So you would go on you would go to the machine and see, okay, what's wrong with this machine?
+
+243
+00:11:49,000 --> 00:11:50,000
+Maybe it's missing update.
+
+244
+00:11:50,000 --> 00:11:52,000
+Maybe it has a default password.
+
+245
+00:11:52,000 --> 00:11:52,000
+Right.
+
+246
+00:11:52,000 --> 00:11:55,000
+These are things that you're going to want to fix right away.
+
+247
+00:11:55,000 --> 00:11:56,000
+How do we fix it?
+
+248
+00:11:56,000 --> 00:12:00,000
+Well, if you find the machine that is outdated, updated, right.
+
+249
+00:12:00,000 --> 00:12:02,000
+Put on Windows Update and say, hey, update it.
+
+250
+00:12:02,000 --> 00:12:03,000
+So keep that in mind.
+
+251
+00:12:03,000 --> 00:12:04,000
+All right.
+
+252
+00:12:04,000 --> 00:12:05,000
+That's this lab.
+
+253
+00:12:05,000 --> 00:12:06,000
+You can keep this on your machine.
+
+254
+00:12:06,000 --> 00:12:10,000
+By the way, this is 100% free software for up to 16.
+
+255
+00:12:10,000 --> 00:12:12,000
+It's up to 16 computers on your network.
+
+256
+00:12:12,000 --> 00:12:14,000
+You do not need to delete this.
+
+257
+00:12:14,000 --> 00:12:18,000
+It always keeps updating since you've already downloaded and installed it.
+
+258
+00:12:18,000 --> 00:12:25,000
+I have it installed on my main desktop at home, where I scan my network every once in a while.
+
+259
+00:12:25,000 --> 00:12:30,000
+And we do use this in our corporate networks, especially in the smaller offices, to keep a scan of
+
+260
+00:12:30,000 --> 00:12:33,000
+our machines to make sure we are vulnerability free.
+
diff --git a/26 - Labs/007 Cracking a Password with Kali_en.srt b/26 - Labs/007 Cracking a Password with Kali_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..d4d408695c1f254fb04855dc7f7c59db63747372
--- /dev/null
+++ b/26 - Labs/007 Cracking a Password with Kali_en.srt
@@ -0,0 +1,380 @@
+1
+00:00:00,000 --> 00:00:03,000
+In this video, I'm going to show you how to crack a password hash.
+
+2
+00:00:03,000 --> 00:00:09,000
+Now you have to remember from when I covered cryptography, that passwords are hashed and in particularly
+
+3
+00:00:09,000 --> 00:00:16,000
+windows passwords uses a type of a hash called called LM hash or NT hashes or LM hashes.
+
+4
+00:00:16,000 --> 00:00:22,000
+So in this video I want to use a software in Kali Linux called Ophcrack that basically cracks passwords
+
+5
+00:00:22,000 --> 00:00:22,000
+for you.
+
+6
+00:00:22,000 --> 00:00:24,000
+And it does it using a brute force attack.
+
+7
+00:00:24,000 --> 00:00:29,000
+Now I'm going to be using a really simple password just to illustrate that passwords are crackable if
+
+8
+00:00:29,000 --> 00:00:31,000
+you use simple passwords.
+
+9
+00:00:31,000 --> 00:00:37,000
+If you use complex passwords, most password crackers will not be able to crack them, or it may take
+
+10
+00:00:37,000 --> 00:00:38,000
+forever to crack them.
+
+11
+00:00:39,000 --> 00:00:45,000
+So, for example, if you're using a 12 character complex passwords with uppercase lowercase numbers
+
+12
+00:00:45,000 --> 00:00:48,000
+and symbols, a lot of cracking software will not be able to crack it.
+
+13
+00:00:48,000 --> 00:00:51,000
+Let's take a look at the lab and then we'll talk a little bit more.
+
+14
+00:00:51,000 --> 00:00:52,000
+So let's go.
+
+15
+00:00:52,000 --> 00:00:57,000
+And we're using Kali to do this lab because it already comes pre-installed with all the tools we need.
+
+16
+00:00:57,000 --> 00:01:00,000
+So the first thing I want to do is I want to grab a hash.
+
+17
+00:01:00,000 --> 00:01:02,000
+Remember passwords are stored as hashes.
+
+18
+00:01:02,000 --> 00:01:06,000
+So I'm going to go to Google and I'm going to type nt nt hash generator.
+
+19
+00:01:06,000 --> 00:01:15,000
+And there is a website I found t o BTU com and they on their website they have a hash generator.
+
+20
+00:01:15,000 --> 00:01:18,000
+Now we're going to be using an LM hash.
+
+21
+00:01:18,000 --> 00:01:22,000
+So what we're going to do is we're going to put let's say your password is car.
+
+22
+00:01:22,000 --> 00:01:26,000
+Car I'm going to say calculate hash.
+
+23
+00:01:26,000 --> 00:01:27,000
+And this is the hash.
+
+24
+00:01:27,000 --> 00:01:31,000
+So windows would store this particular hash in its database.
+
+25
+00:01:31,000 --> 00:01:33,000
+What database will windows stores them.
+
+26
+00:01:33,000 --> 00:01:35,000
+And what's called the Sam file.
+
+27
+00:01:35,000 --> 00:01:39,000
+Windows Sam file that has all the hashes and all the usernames and the corresponding hashes.
+
+28
+00:01:39,000 --> 00:01:41,000
+So here is the actual hash.
+
+29
+00:01:41,000 --> 00:01:46,000
+So if I give this to my cracking software, it should be able to crack this and turn it back into the
+
+30
+00:01:46,000 --> 00:01:47,000
+password of car.
+
+31
+00:01:47,000 --> 00:01:50,000
+So let's go back here I again I'm on.
+
+32
+00:01:51,000 --> 00:01:52,000
+Among colleagues.
+
+33
+00:01:52,000 --> 00:01:57,000
+I'm going to go back to my little, uh, dragon button there, and I'm going to go here to password
+
+34
+00:01:57,000 --> 00:01:57,000
+attacks.
+
+35
+00:01:57,000 --> 00:01:58,000
+I'll say ophcrack.
+
+36
+00:01:58,000 --> 00:02:00,000
+And again, this comes pre-installed.
+
+37
+00:02:00,000 --> 00:02:03,000
+I didn't change anything in this comes all pre-installed with it.
+
+38
+00:02:03,000 --> 00:02:04,000
+So here I am.
+
+39
+00:02:04,000 --> 00:02:06,000
+So this is the software.
+
+40
+00:02:06,000 --> 00:02:09,000
+And you notice it has a LM hash and NT hashes.
+
+41
+00:02:09,000 --> 00:02:12,000
+So let's go ahead in here and we're going to say we're going to load it.
+
+42
+00:02:12,000 --> 00:02:14,000
+Now you could do it.
+
+43
+00:02:14,000 --> 00:02:18,000
+Uh if you have multiple hashes you can do a dump files and all that.
+
+44
+00:02:18,000 --> 00:02:20,000
+We're just going to say single hash.
+
+45
+00:02:20,000 --> 00:02:22,000
+We're going to paste our hash in here.
+
+46
+00:02:22,000 --> 00:02:23,000
+And we're going to say okay.
+
+47
+00:02:24,000 --> 00:02:29,000
+And right now we're just going to go ahead and we're going to crack this.
+
+48
+00:02:29,000 --> 00:02:30,000
+Now we're not going to change anything.
+
+49
+00:02:30,000 --> 00:02:33,000
+It is set right now as a brute force attack.
+
+50
+00:02:33,000 --> 00:02:36,000
+And you'll see that it's doing that okay.
+
+51
+00:02:36,000 --> 00:02:39,000
+So we're going and notice it cracked it already.
+
+52
+00:02:39,000 --> 00:02:40,000
+All right.
+
+53
+00:02:40,000 --> 00:02:42,000
+So that was pretty quick.
+
+54
+00:02:42,000 --> 00:02:47,000
+So if you use easy passwords and I just want to illustrate something to you.
+
+55
+00:02:49,000 --> 00:02:50,000
+I want to illustrate something to you guys.
+
+56
+00:02:50,000 --> 00:02:51,000
+Oops, we don't want a new one.
+
+57
+00:02:51,000 --> 00:02:52,000
+I actually have it open.
+
+58
+00:02:52,000 --> 00:02:59,000
+You see, if we go in here and we generate a password like van, just another easy one and we say we
+
+59
+00:02:59,000 --> 00:03:02,000
+copy this and we say, can you crack that for us?
+
+60
+00:03:03,000 --> 00:03:04,000
+Let's see.
+
+61
+00:03:04,000 --> 00:03:05,000
+What do you guys think?
+
+62
+00:03:05,000 --> 00:03:06,000
+Is it gonna crack it quick?
+
+63
+00:03:06,000 --> 00:03:10,000
+Well, it's a three digit one, just like the car one.
+
+64
+00:03:10,000 --> 00:03:12,000
+We're going to say crack cracked it already.
+
+65
+00:03:12,000 --> 00:03:14,000
+But what if we use a complex password?
+
+66
+00:03:14,000 --> 00:03:17,000
+So let's go in here and we're going to give it a password.
+
+67
+00:03:18,000 --> 00:03:21,000
+Even if I use this particular one.
+
+68
+00:03:21,000 --> 00:03:25,000
+That's more complex, but it's still very easy right, for us to remember.
+
+69
+00:03:25,000 --> 00:03:28,000
+But for a computer it might not be that difficult.
+
+70
+00:03:28,000 --> 00:03:30,000
+Let's go ahead and calculate a hash here.
+
+71
+00:03:31,000 --> 00:03:32,000
+Copy this.
+
+72
+00:03:32,000 --> 00:03:34,000
+Give it back to my cracking software.
+
+73
+00:03:34,000 --> 00:03:35,000
+Let's load it up.
+
+74
+00:03:37,000 --> 00:03:39,000
+And this one I will say crack.
+
+75
+00:03:41,000 --> 00:03:49,000
+And not found it did find one later though, so you can see that it's it's taken a longer time though
+
+76
+00:03:49,000 --> 00:03:51,000
+it does work with lookup tables.
+
+77
+00:03:51,000 --> 00:03:55,000
+Uh, it you could use lookup tables, but this is a software that does this.
+
+78
+00:03:55,000 --> 00:03:59,000
+Now there are tons of different ways of cracking passwords.
+
+79
+00:03:59,000 --> 00:04:03,000
+I mean, I could crack that using a lookup table very, very quickly.
+
+80
+00:04:03,000 --> 00:04:05,000
+But that's not the point of this video.
+
+81
+00:04:05,000 --> 00:04:11,000
+This point of this video is just to show you that these kinds of software exist, that when you use
+
+82
+00:04:11,000 --> 00:04:14,000
+easy, simple passwords, hackers grabs the hash.
+
+83
+00:04:14,000 --> 00:04:21,000
+Remember, the hash is not a secret when we use when we do a username and a password on unencrypted
+
+84
+00:04:21,000 --> 00:04:27,000
+sessions and we press enter, let's you go to a web page with a form and you press enter that that hash
+
+85
+00:04:27,000 --> 00:04:30,000
+traverses that network in full open text.
+
+86
+00:04:31,000 --> 00:04:31,000
+All right.
+
+87
+00:04:31,000 --> 00:04:33,000
+But it's just a hash.
+
+88
+00:04:33,000 --> 00:04:34,000
+They captured a hash.
+
+89
+00:04:34,000 --> 00:04:36,000
+They put it through a software like this.
+
+90
+00:04:36,000 --> 00:04:40,000
+And if you're using a password, a car or van or any, for example, any three letter or even five,
+
+91
+00:04:40,000 --> 00:04:43,000
+six letters, but it's basically like a dictionary word.
+
+92
+00:04:43,000 --> 00:04:45,000
+It could be cracked very easily.
+
+93
+00:04:45,000 --> 00:04:50,000
+So you can try out this piece of software in this lab just to see, okay, this is how we crack hashes
+
+94
+00:04:50,000 --> 00:04:51,000
+with passwords.
+
+95
+00:04:51,000 --> 00:04:54,000
+And always remember make sure your passwords are complex.
+
diff --git a/26 - Labs/008 Cracking a password with a lookup table_en.srt b/26 - Labs/008 Cracking a password with a lookup table_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..0060aac487ba159d382ee475f00348f411dd3da1
--- /dev/null
+++ b/26 - Labs/008 Cracking a password with a lookup table_en.srt
@@ -0,0 +1,492 @@
+1
+00:00:00,000 --> 00:00:04,000
+In this video, I'm going to show you how to crack a windows hash.
+
+2
+00:00:04,000 --> 00:00:06,000
+Modern windows hashes.
+
+3
+00:00:06,000 --> 00:00:09,000
+So windows uses a hash type called Intel.
+
+4
+00:00:09,000 --> 00:00:12,000
+It stands for New Technology Land Manager.
+
+5
+00:00:12,000 --> 00:00:16,000
+Now this particular hash is what you'll find in things like the windows Sam file.
+
+6
+00:00:16,000 --> 00:00:20,000
+Now the way I'm going to be cracking this is by using what's called a lookup table.
+
+7
+00:00:20,000 --> 00:00:27,000
+A lookup table is basically a it's like an Excel sheet that has a bunch of predefined passwords and
+
+8
+00:00:27,000 --> 00:00:29,000
+hashes already there to it.
+
+9
+00:00:29,000 --> 00:00:32,000
+This thing is the fastest way to crack passwords.
+
+10
+00:00:32,000 --> 00:00:37,000
+It's much more efficient than utilizing something like a brute force attack, which we looked at previously
+
+11
+00:00:37,000 --> 00:00:42,000
+or in one of these labs here, we'll do it where we use Ophcrack to do a type of a brute force.
+
+12
+00:00:42,000 --> 00:00:45,000
+We're going to be doing this on Kali, but you can do this on windows.
+
+13
+00:00:45,000 --> 00:00:47,000
+It's basically all done in your browser.
+
+14
+00:00:47,000 --> 00:00:49,000
+Let's get started on this lab.
+
+15
+00:00:49,000 --> 00:00:53,000
+So the first thing up is we're going to go and we're going to generate an Ntlm hash.
+
+16
+00:00:54,000 --> 00:00:56,000
+And enter the text.
+
+17
+00:00:56,000 --> 00:00:59,000
+So let's say your password is.
+
+18
+00:01:00,000 --> 00:01:03,000
+And if you remember I couldn't crack this particular password.
+
+19
+00:01:03,000 --> 00:01:04,000
+Uh, you know what?
+
+20
+00:01:04,000 --> 00:01:05,000
+Let's make it comp.
+
+21
+00:01:05,000 --> 00:01:05,000
+Let's make it a capital P.
+
+22
+00:01:05,000 --> 00:01:12,000
+I couldn't crack this particular password last time using the brute force because it just took too long.
+
+23
+00:01:12,000 --> 00:01:15,000
+Now I'm going to say generate already generate.
+
+24
+00:01:15,000 --> 00:01:16,000
+This is the hash.
+
+25
+00:01:16,000 --> 00:01:19,000
+So this hash represents this password.
+
+26
+00:01:19,000 --> 00:01:21,000
+So if you're using windows right.
+
+27
+00:01:21,000 --> 00:01:24,000
+And this is your password this would be what windows would store.
+
+28
+00:01:24,000 --> 00:01:26,000
+Now imagine I grabbed this hash.
+
+29
+00:01:26,000 --> 00:01:29,000
+Maybe you would maybe your machine was left unprotected.
+
+30
+00:01:29,000 --> 00:01:31,000
+I was able to get the Sam file.
+
+31
+00:01:31,000 --> 00:01:34,000
+I'm going to copy this and I'm going to give it to a website.
+
+32
+00:01:34,000 --> 00:01:36,000
+We're going to call it crack station.
+
+33
+00:01:36,000 --> 00:01:39,000
+So just Google crack station and crack station.
+
+34
+00:01:39,000 --> 00:01:41,000
+Dot net is the website.
+
+35
+00:01:41,000 --> 00:01:42,000
+Here it is.
+
+36
+00:01:42,000 --> 00:01:45,000
+Now this is a free password hash cracker.
+
+37
+00:01:45,000 --> 00:01:49,000
+And basically what it does is that it has this giant word list.
+
+38
+00:01:50,000 --> 00:01:51,000
+How much words does it have?
+
+39
+00:01:51,000 --> 00:01:59,000
+Well, the word list for, for uh, MD5 and Sha one hash is it's 190 gigs, 15 billion lookup entries.
+
+40
+00:01:59,000 --> 00:02:02,000
+For everything else it's a 1.5 billion lookup entries.
+
+41
+00:02:02,000 --> 00:02:05,000
+So that is a massive amount of entries.
+
+42
+00:02:05,000 --> 00:02:07,000
+So all you do is you just give it a hash.
+
+43
+00:02:08,000 --> 00:02:10,000
+You say, I'm not a robot and I crack this.
+
+44
+00:02:10,000 --> 00:02:11,000
+Can it crack it?
+
+45
+00:02:11,000 --> 00:02:12,000
+Oh, look at that.
+
+46
+00:02:12,000 --> 00:02:14,000
+It found my password right away.
+
+47
+00:02:14,000 --> 00:02:17,000
+It knows that it's an Ntlm hash.
+
+48
+00:02:17,000 --> 00:02:23,000
+So you can try this if you have a password that you're using right now and you want to know, can somebody
+
+49
+00:02:23,000 --> 00:02:24,000
+hack my machine?
+
+50
+00:02:24,000 --> 00:02:26,000
+Well, go into go.
+
+51
+00:02:26,000 --> 00:02:28,000
+Go here go to this website.
+
+52
+00:02:28,000 --> 00:02:31,000
+And again you could just Google Ntlm hash generator.
+
+53
+00:02:31,000 --> 00:02:34,000
+You can go here put your actual password in.
+
+54
+00:02:34,000 --> 00:02:37,000
+And go ahead and put it into crack station.
+
+55
+00:02:37,000 --> 00:02:39,000
+Now let's try a couple of different ones.
+
+56
+00:02:39,000 --> 00:02:43,000
+Let's try capital SW0D1234.
+
+57
+00:02:44,000 --> 00:02:46,000
+Uh, could it crack this particular one.
+
+58
+00:02:46,000 --> 00:02:46,000
+Let's find out.
+
+59
+00:02:46,000 --> 00:02:48,000
+So I'm going to copy this.
+
+60
+00:02:48,000 --> 00:02:49,000
+So this is a password.
+
+61
+00:02:49,000 --> 00:02:51,000
+It's pretty complex but it's still a dictionary word.
+
+62
+00:02:51,000 --> 00:02:53,000
+It's 12 characters in it.
+
+63
+00:02:53,000 --> 00:02:55,000
+So I'm going to go ahead and give it this one.
+
+64
+00:02:57,000 --> 00:02:57,000
+Yep.
+
+65
+00:02:57,000 --> 00:02:58,000
+Correct it.
+
+66
+00:02:58,000 --> 00:02:59,000
+But let's go ahead and give it something else.
+
+67
+00:02:59,000 --> 00:03:01,000
+Let's change this around.
+
+68
+00:03:01,000 --> 00:03:04,000
+Let's do 0156.
+
+69
+00:03:04,000 --> 00:03:04,000
+Oops.
+
+70
+00:03:04,000 --> 00:03:08,000
+Didn't have my num lock on 0156.
+
+71
+00:03:10,000 --> 00:03:11,000
+So okay.
+
+72
+00:03:11,000 --> 00:03:13,000
+So it's generating by itself there as I typed it in.
+
+73
+00:03:14,000 --> 00:03:14,000
+Let's give that one.
+
+74
+00:03:14,000 --> 00:03:16,000
+Can it actually crack this.
+
+75
+00:03:16,000 --> 00:03:16,000
+Let's see.
+
+76
+00:03:17,000 --> 00:03:18,000
+Crack it.
+
+77
+00:03:18,000 --> 00:03:21,000
+Nope, can't do it so it'll crack.
+
+78
+00:03:21,000 --> 00:03:28,000
+Almost all simple password if you have any kind of dictionary word right now.
+
+79
+00:03:28,000 --> 00:03:29,000
+On your machine.
+
+80
+00:03:29,000 --> 00:03:33,000
+If your password is a dictionary, let's say your password is generator.
+
+81
+00:03:33,000 --> 00:03:34,000
+All right.
+
+82
+00:03:34,000 --> 00:03:39,000
+If your password is generator, it will crack it.
+
+83
+00:03:39,000 --> 00:03:40,000
+This is my favorite way.
+
+84
+00:03:40,000 --> 00:03:42,000
+This is the first way I test if I need to crack a password.
+
+85
+00:03:43,000 --> 00:03:44,000
+Bicycle.
+
+86
+00:03:44,000 --> 00:03:45,000
+Bicycle.
+
+87
+00:03:47,000 --> 00:03:49,000
+Uh, boy, did I get it all, I hope so.
+
+88
+00:03:50,000 --> 00:03:51,000
+No, I did not get it all.
+
+89
+00:03:51,000 --> 00:03:52,000
+All right.
+
+90
+00:03:53,000 --> 00:03:54,000
+Does it not want the guy?
+
+91
+00:03:55,000 --> 00:03:56,000
+Nope.
+
+92
+00:03:58,000 --> 00:04:01,000
+You gotta love, uh, all these checks here that we're not robots.
+
+93
+00:04:01,000 --> 00:04:03,000
+All right, let's crack this one.
+
+94
+00:04:04,000 --> 00:04:04,000
+Yep.
+
+95
+00:04:04,000 --> 00:04:10,000
+Told you if your password is anything like a dictionary password, you are in a lot of trouble so you
+
+96
+00:04:10,000 --> 00:04:10,000
+guys can try.
+
+97
+00:04:10,000 --> 00:04:12,000
+You guys can keep trying this.
+
+98
+00:04:12,000 --> 00:04:15,000
+It does more than just Ntlm hashes.
+
+99
+00:04:15,000 --> 00:04:17,000
+You know I saw that.
+
+100
+00:04:17,000 --> 00:04:22,000
+So it does a lot of different if you're using if the software you're using are things like MD5 or Sha
+
+101
+00:04:22,000 --> 00:04:24,000
+one, Sha 256 is also here.
+
+102
+00:04:24,000 --> 00:04:26,000
+That's famous hash today.
+
+103
+00:04:26,000 --> 00:04:28,000
+This thing will try its best to crack it.
+
+104
+00:04:28,000 --> 00:04:30,000
+That's why this alone is proof.
+
+105
+00:04:30,000 --> 00:04:35,000
+Because, you know, I want you guys to remember something that even though.
+
+106
+00:04:35,000 --> 00:04:39,000
+Windows uses NTM a lot of applications.
+
+107
+00:04:39,000 --> 00:04:42,000
+Web applications uses Sha 256.
+
+108
+00:04:42,000 --> 00:04:48,000
+Hopefully they're not using Sha, Sha one or MD5 because these hashes are easily cracked.
+
+109
+00:04:48,000 --> 00:04:49,000
+Something like this.
+
+110
+00:04:49,000 --> 00:04:50,000
+If you're using.
+
+111
+00:04:50,000 --> 00:04:57,000
+If you allow your users to use simple passwords on any web application, we will crack this.
+
+112
+00:04:57,000 --> 00:05:04,000
+Hackers I teach Pentesting remember I keep telling you, but see my course Pentesters hackers will crack
+
+113
+00:05:04,000 --> 00:05:05,000
+your password.
+
+114
+00:05:05,000 --> 00:05:07,000
+You must have complex password.
+
+115
+00:05:07,000 --> 00:05:10,000
+It could be eight digits, but it's got to be complex.
+
+116
+00:05:10,000 --> 00:05:12,000
+Not like a dictionary like I had there.
+
+117
+00:05:12,000 --> 00:05:13,000
+The word pass.
+
+118
+00:05:13,000 --> 00:05:14,000
+That password I use capital p.
+
+119
+00:05:14,000 --> 00:05:17,000
+SS is a very common password, by the way.
+
+120
+00:05:18,000 --> 00:05:19,000
+Make sure it's complex.
+
+121
+00:05:19,000 --> 00:05:20,000
+Make sure it's random.
+
+122
+00:05:20,000 --> 00:05:22,000
+No one can guess it and you're probably going to survive.
+
+123
+00:05:22,000 --> 00:05:28,000
+Try to keep your password at least ten characters to stay secure from things like this cracker.
+
diff --git a/26 - Labs/009 Scanner a website for vulnerabilities_en.srt b/26 - Labs/009 Scanner a website for vulnerabilities_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..95991338738a73480e4bc56bd07ec0062b1c0912
--- /dev/null
+++ b/26 - Labs/009 Scanner a website for vulnerabilities_en.srt
@@ -0,0 +1,452 @@
+1
+00:00:00,000 --> 00:00:02,000
+Websites today are basically applications.
+
+2
+00:00:02,000 --> 00:00:08,000
+Websites today are not really simple web pages with just information on them.
+
+3
+00:00:08,000 --> 00:00:13,000
+So in this video, I want to show you guys how if you're managing a website or you're in charge of securing
+
+4
+00:00:13,000 --> 00:00:17,000
+websites, how you can discover if there's vulnerabilities on those websites.
+
+5
+00:00:17,000 --> 00:00:24,000
+Now, when it comes to this, a single website can have hundreds or thousands of components.
+
+6
+00:00:24,000 --> 00:00:26,000
+They can have millions of lines of codes.
+
+7
+00:00:26,000 --> 00:00:31,000
+Can you actually review that website step by step and see if it's vulnerable to things like cross-site
+
+8
+00:00:31,000 --> 00:00:37,000
+scripting, scripting or injection attacks, buffer overflows, all the different attacks that can affect
+
+9
+00:00:37,000 --> 00:00:37,000
+a website.
+
+10
+00:00:37,000 --> 00:00:39,000
+It's pretty much impossible.
+
+11
+00:00:39,000 --> 00:00:46,000
+So we have paid services or applications that can scan a website and tell you if there's any vulnerability.
+
+12
+00:00:46,000 --> 00:00:51,000
+Now, they're generally always paid, but I do have a free website that's going to give us a scan for
+
+13
+00:00:51,000 --> 00:00:51,000
+free.
+
+14
+00:00:51,000 --> 00:00:55,000
+Now, in this lab, I'm going to be using my website.
+
+15
+00:00:55,000 --> 00:01:01,000
+I cannot tell you to scan a website unless you have permission to scan that site.
+
+16
+00:01:01,000 --> 00:01:05,000
+You know what you call someone that is doing pen testing without permission?
+
+17
+00:01:05,000 --> 00:01:07,000
+Hacking, correct.
+
+18
+00:01:07,000 --> 00:01:10,000
+So I'm going to be scanning my personal website now.
+
+19
+00:01:10,000 --> 00:01:15,000
+I do have a personal website that I was trying to set it up.
+
+20
+00:01:15,000 --> 00:01:15,000
+I never finished it.
+
+21
+00:01:15,000 --> 00:01:18,000
+I'm always trying to finish it, but I never made time to finish it.
+
+22
+00:01:18,000 --> 00:01:20,000
+It just a site that talks about me.
+
+23
+00:01:20,000 --> 00:01:20,000
+All right.
+
+24
+00:01:20,000 --> 00:01:23,000
+It's a ramdayal.com a my first name.
+
+25
+00:01:23,000 --> 00:01:24,000
+Ramdayal my last name.
+
+26
+00:01:24,000 --> 00:01:28,000
+There's nothing on the website, so it doesn't bother me what's there.
+
+27
+00:01:29,000 --> 00:01:36,000
+So I'm going to go and I want to show you this website a ramdayal a ramdayal.com.
+
+28
+00:01:36,000 --> 00:01:39,000
+And I don't think it has a, it doesn't have a certificate.
+
+29
+00:01:39,000 --> 00:01:43,000
+It's just plain old Http man.
+
+30
+00:01:43,000 --> 00:01:46,000
+All right I never finished it doesn't matter what the website is because I just want to show you how
+
+31
+00:01:46,000 --> 00:01:47,000
+to run the scan.
+
+32
+00:01:47,000 --> 00:01:58,000
+Now to run the scan we're going to do pen test and test pen test, dash tools.com pen test dash tools.com.
+
+33
+00:01:58,000 --> 00:01:59,000
+Let's go ahead and press enter.
+
+34
+00:01:59,000 --> 00:02:04,000
+Now I'm just doing this on my base machine by the way I'm not using I'm just using my Windows 10.
+
+35
+00:02:04,000 --> 00:02:05,000
+I'm not using my Kali or anything.
+
+36
+00:02:05,000 --> 00:02:08,000
+You could do it on your base machine too because it's all done on a browser.
+
+37
+00:02:08,000 --> 00:02:14,000
+So we're going to go to free scan and we're going to say website scanner.
+
+38
+00:02:14,000 --> 00:02:16,000
+You also have network vulnerability subdomain.
+
+39
+00:02:16,000 --> 00:02:17,000
+We don't want all.
+
+40
+00:02:17,000 --> 00:02:17,000
+We'll just say.
+
+41
+00:02:17,000 --> 00:02:18,000
+Net website scanner.
+
+42
+00:02:19,000 --> 00:02:20,000
+And we're going to go in here.
+
+43
+00:02:20,000 --> 00:02:27,000
+I'm going to change this to Http, because I noticed that my website does not have a h a, uh, it doesn't
+
+44
+00:02:27,000 --> 00:02:28,000
+have a certificate.
+
+45
+00:02:28,000 --> 00:02:29,000
+If it did, I would just leave it there.
+
+46
+00:02:31,000 --> 00:02:33,000
+And let it scan it.
+
+47
+00:02:34,000 --> 00:02:35,000
+Okay.
+
+48
+00:02:35,000 --> 00:02:37,000
+So scanning progress.
+
+49
+00:02:37,000 --> 00:02:39,000
+Now let the scan here for a second.
+
+50
+00:02:40,000 --> 00:02:42,000
+Now, once again I can't emphasize this enough.
+
+51
+00:02:42,000 --> 00:02:46,000
+You must have permission to scan websites.
+
+52
+00:02:46,000 --> 00:02:46,000
+Right.
+
+53
+00:02:46,000 --> 00:02:53,000
+But, you know, if you go and you scan YouTube or you scan a major website, YouTube or Google, I
+
+54
+00:02:53,000 --> 00:02:54,000
+don't think anything is going to happen.
+
+55
+00:02:54,000 --> 00:03:01,000
+But from a legal perspective, you shouldn't be doing that, uh, unless you have permission to do it.
+
+56
+00:03:01,000 --> 00:03:02,000
+All right.
+
+57
+00:03:02,000 --> 00:03:04,000
+Just some legal things there.
+
+58
+00:03:04,000 --> 00:03:05,000
+Okay.
+
+59
+00:03:05,000 --> 00:03:06,000
+Let's see what it says here.
+
+60
+00:03:06,000 --> 00:03:09,000
+So scan results and this is the like one.
+
+61
+00:03:09,000 --> 00:03:14,000
+They're not going to give us all the information for the website because of course they want us to pay
+
+62
+00:03:14,000 --> 00:03:14,000
+for that.
+
+63
+00:03:14,000 --> 00:03:17,000
+But it'll give you an idea of what you know, what's it all about.
+
+64
+00:03:18,000 --> 00:03:20,000
+So we have no high ratings.
+
+65
+00:03:20,000 --> 00:03:21,000
+Which high would be bad?
+
+66
+00:03:21,000 --> 00:03:24,000
+Like if there is something there that needs to be fixed right away.
+
+67
+00:03:24,000 --> 00:03:27,000
+We do have one medium rate and a bunch of low ratings.
+
+68
+00:03:27,000 --> 00:03:33,000
+So it's is it going to tell us what they find or do they want to make us pay for that?
+
+69
+00:03:33,000 --> 00:03:39,000
+I can tell you, one of the things that is bad about this particular website is that it doesn't have
+
+70
+00:03:39,000 --> 00:03:42,000
+any Https on it.
+
+71
+00:03:42,000 --> 00:03:43,000
+Uh, https on it.
+
+72
+00:03:43,000 --> 00:03:46,000
+So I think that's going to be one of the findings on it.
+
+73
+00:03:47,000 --> 00:03:48,000
+Oops.
+
+74
+00:03:49,000 --> 00:03:50,000
+So I did that.
+
+75
+00:03:50,000 --> 00:03:51,000
+But I don't know why.
+
+76
+00:03:51,000 --> 00:03:54,000
+It's not showing me, uh, what it is.
+
+77
+00:03:54,000 --> 00:03:58,000
+Maybe they want us to pay for it, let it scan it again, and let's see if it's going to.
+
+78
+00:03:58,000 --> 00:03:59,000
+Okay.
+
+79
+00:03:59,000 --> 00:03:59,000
+It did do it.
+
+80
+00:03:59,000 --> 00:04:00,000
+Okay.
+
+81
+00:04:01,000 --> 00:04:02,000
+So.
+
+82
+00:04:02,000 --> 00:04:04,000
+Oh, it's showing me what I have here.
+
+83
+00:04:04,000 --> 00:04:05,000
+So let's see here.
+
+84
+00:04:05,000 --> 00:04:06,000
+Communication is not secure.
+
+85
+00:04:06,000 --> 00:04:09,000
+So that was that yellow one that we saw earlier.
+
+86
+00:04:09,000 --> 00:04:12,000
+It does not notice the kind of server it notes.
+
+87
+00:04:12,000 --> 00:04:14,000
+It gives us good information.
+
+88
+00:04:14,000 --> 00:04:16,000
+It's telling us it's running an Apache web server.
+
+89
+00:04:16,000 --> 00:04:19,000
+It uses this version of PHP.
+
+90
+00:04:19,000 --> 00:04:20,000
+Uh, this version of WordPress.
+
+91
+00:04:20,000 --> 00:04:22,000
+It is a WordPress site.
+
+92
+00:04:22,000 --> 00:04:22,000
+Very good.
+
+93
+00:04:23,000 --> 00:04:25,000
+It uses a MySQL database.
+
+94
+00:04:25,000 --> 00:04:26,000
+It does use jQuery and stuff.
+
+95
+00:04:26,000 --> 00:04:30,000
+So it did give us a bunch of information.
+
+96
+00:04:30,000 --> 00:04:32,000
+As I was scanning it, I saw it.
+
+97
+00:04:33,000 --> 00:04:34,000
+I'm not sure why it doesn't want to show it here.
+
+98
+00:04:35,000 --> 00:04:42,000
+Maybe they want us to pay for it, but this is what a website vulnerability scanner is about.
+
+99
+00:04:42,000 --> 00:04:47,000
+Now, these these companies will make us pay for it.
+
+100
+00:04:47,000 --> 00:04:49,000
+And if you pay for it, this is not an ad, by the way.
+
+101
+00:04:49,000 --> 00:04:51,000
+I don't know this company.
+
+102
+00:04:51,000 --> 00:04:58,000
+If you pay for it, they're going to scan for things like injection attacks, cross-site scripting or
+
+103
+00:04:58,000 --> 00:05:01,000
+their particular server side scripting SQL injection.
+
+104
+00:05:01,000 --> 00:05:01,000
+Here we go.
+
+105
+00:05:01,000 --> 00:05:02,000
+Cross-site scripting.
+
+106
+00:05:03,000 --> 00:05:09,000
+The free test only checked if there was some kind of vulnerability in the versions that we were using.
+
+107
+00:05:10,000 --> 00:05:13,000
+If there was common configuration or misconfiguration of the website.
+
+108
+00:05:13,000 --> 00:05:18,000
+But really, to get all of these things here, you got to pay for that deep scan.
+
+109
+00:05:18,000 --> 00:05:22,000
+So it's not a free software first of all.
+
+110
+00:05:22,000 --> 00:05:23,000
+All right.
+
+111
+00:05:23,000 --> 00:05:24,000
+So let me point that out.
+
+112
+00:05:24,000 --> 00:05:31,000
+But in this lab you saw that when you have a website, you do have particular's scanning software that
+
+113
+00:05:31,000 --> 00:05:33,000
+we can use to find vulnerabilities.
+
diff --git a/26 - Labs/010 Using Wireshark to capture network traffic_en.srt b/26 - Labs/010 Using Wireshark to capture network traffic_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..2bfd12f79d9b21b15e0e43fef4961fda32230fd6
--- /dev/null
+++ b/26 - Labs/010 Using Wireshark to capture network traffic_en.srt
@@ -0,0 +1,696 @@
+1
+00:00:00,000 --> 00:00:05,000
+Throughout your career of launching it, you've probably heard or read way too much.
+
+2
+00:00:05,000 --> 00:00:12,000
+Don't use insecure protocols such as FTP or telnet, or any protocol that just passes data in clear
+
+3
+00:00:12,000 --> 00:00:19,000
+text, because then people utilizing sniffing software can sniff the network and steal your username
+
+4
+00:00:19,000 --> 00:00:20,000
+and password.
+
+5
+00:00:20,000 --> 00:00:23,000
+And in this video, I'm going to show you exactly that.
+
+6
+00:00:23,000 --> 00:00:26,000
+Now, this video does have a quite of a setup because we have to set up a server.
+
+7
+00:00:26,000 --> 00:00:29,000
+We're going to be setting up an FTP server.
+
+8
+00:00:29,000 --> 00:00:31,000
+We're going to create a user on it.
+
+9
+00:00:31,000 --> 00:00:35,000
+Then we're going to connect to it from our Kali Linux.
+
+10
+00:00:35,000 --> 00:00:38,000
+And we're going to use a sniffing software or a protocol analyzer.
+
+11
+00:00:38,000 --> 00:00:39,000
+Sniffing protocol analyzer.
+
+12
+00:00:39,000 --> 00:00:46,000
+Same thing called Wireshark to sniff the network to actually steal the password.
+
+13
+00:00:46,000 --> 00:00:48,000
+Now this lab is designed to do a couple of things.
+
+14
+00:00:48,000 --> 00:00:51,000
+Number one, it's going to show you how to install an FTP server, but it's going to show you how to
+
+15
+00:00:51,000 --> 00:00:53,000
+use Wireshark.
+
+16
+00:00:53,000 --> 00:00:55,000
+And Wireshark is a pretty simple software.
+
+17
+00:00:55,000 --> 00:00:59,000
+I'm not going to get in depth into it, but it'll give you a great introduction to see what it can do,
+
+18
+00:00:59,000 --> 00:01:05,000
+and it'll also teach you why you should never, ever use insecure protocols such as FTP.
+
+19
+00:01:05,000 --> 00:01:06,000
+Let's get started.
+
+20
+00:01:06,000 --> 00:01:10,000
+So we're going to be utilizing an FTP server called FileZilla.
+
+21
+00:01:10,000 --> 00:01:11,000
+It's my most favorite one to use.
+
+22
+00:01:11,000 --> 00:01:12,000
+Let's get to our desktop.
+
+23
+00:01:12,000 --> 00:01:15,000
+So we're going to utilize the FileZilla on Windows 10.
+
+24
+00:01:15,000 --> 00:01:17,000
+And then we're going to use Wireshark.
+
+25
+00:01:17,000 --> 00:01:19,000
+That comes pre-built on Kali Linux.
+
+26
+00:01:19,000 --> 00:01:22,000
+Now you could install Wireshark on Windows also.
+
+27
+00:01:22,000 --> 00:01:25,000
+But why do that when we already have Kali Linux.
+
+28
+00:01:26,000 --> 00:01:33,000
+So you guys are going to go to Google Type File Zilla and you guys are going to go to download File
+
+29
+00:01:33,000 --> 00:01:34,000
+Zilla server.
+
+30
+00:01:35,000 --> 00:01:38,000
+And you're just going to click on the download button, which I already did.
+
+31
+00:01:38,000 --> 00:01:40,000
+And here it is file zilla.
+
+32
+00:01:40,000 --> 00:01:42,000
+And I'm going to install it now.
+
+33
+00:01:42,000 --> 00:01:45,000
+So we're just going to do a default install on File Zilla.
+
+34
+00:01:45,000 --> 00:01:47,000
+Now this is going to be our FTP server.
+
+35
+00:01:50,000 --> 00:01:50,000
+Run it, run it.
+
+36
+00:01:50,000 --> 00:01:51,000
+Yeah that's fine.
+
+37
+00:01:51,000 --> 00:01:52,000
+We're not going to put any administration.
+
+38
+00:01:52,000 --> 00:01:58,000
+This is this password they have here is when you want to administer the FTP server you would need to
+
+39
+00:01:58,000 --> 00:01:59,000
+use this username and password.
+
+40
+00:01:59,000 --> 00:02:03,000
+But this password in particular we're just going to do it without it and install this.
+
+41
+00:02:03,000 --> 00:02:05,000
+Now this should go by really quick.
+
+42
+00:02:05,000 --> 00:02:06,000
+It's really quick install.
+
+43
+00:02:07,000 --> 00:02:11,000
+It will set up a self-signed certificate so you could use ftps.
+
+44
+00:02:11,000 --> 00:02:13,000
+In other words, it encrypts it, but we don't want to encrypt it.
+
+45
+00:02:13,000 --> 00:02:16,000
+We want to see how to sniff it and steal that password.
+
+46
+00:02:16,000 --> 00:02:19,000
+So we're going to click on close and that's it.
+
+47
+00:02:19,000 --> 00:02:20,000
+It's done.
+
+48
+00:02:20,000 --> 00:02:21,000
+So I'm going to close this down.
+
+49
+00:02:21,000 --> 00:02:23,000
+Now you notice it brings this up.
+
+50
+00:02:23,000 --> 00:02:25,000
+And if this doesn't come up for you just go ahead on your desktop.
+
+51
+00:02:25,000 --> 00:02:28,000
+It should say administration of FileZilla.
+
+52
+00:02:28,000 --> 00:02:30,000
+So we're going to go ahead and connect to the server.
+
+53
+00:02:30,000 --> 00:02:31,000
+No password.
+
+54
+00:02:31,000 --> 00:02:34,000
+Remember we didn't put a password when we originally installed it.
+
+55
+00:02:35,000 --> 00:02:39,000
+Now right out of the box it's pretty much ready and willing to go.
+
+56
+00:02:39,000 --> 00:02:40,000
+Now I'm going to go to server.
+
+57
+00:02:42,000 --> 00:02:44,000
+And I'm going to go here to configure.
+
+58
+00:02:45,000 --> 00:02:49,000
+And I got to create a user to to log into it.
+
+59
+00:02:49,000 --> 00:02:52,000
+Now you notice it says it's going to be doing port 21.
+
+60
+00:02:53,000 --> 00:02:57,000
+Uh FTP over SSL and insecure plaintext FTP.
+
+61
+00:02:57,000 --> 00:02:58,000
+That's what we want.
+
+62
+00:02:58,000 --> 00:02:59,000
+So we're going to do so it's doombolt.
+
+63
+00:02:59,000 --> 00:03:00,000
+So we're going to go to user.
+
+64
+00:03:00,000 --> 00:03:01,000
+We're going to create a user called Bob.
+
+65
+00:03:02,000 --> 00:03:04,000
+Actually, I oh, I had one called Bob.
+
+66
+00:03:04,000 --> 00:03:04,000
+Will do.
+
+67
+00:03:04,000 --> 00:03:07,000
+Mary, I already installed this, by the way.
+
+68
+00:03:07,000 --> 00:03:10,000
+I test the labs before I tried them so I don't have to rerecord the video 100 times.
+
+69
+00:03:10,000 --> 00:03:15,000
+So we're going to do Mary, uh, and we're going to say Mary has a password.
+
+70
+00:03:15,000 --> 00:03:18,000
+Call M-a-r-y.
+
+71
+00:03:18,000 --> 00:03:18,000
+Mary.
+
+72
+00:03:18,000 --> 00:03:19,000
+One, two three.
+
+73
+00:03:19,000 --> 00:03:22,000
+Okay, so we got Mary.
+
+74
+00:03:23,000 --> 00:03:26,000
+Now, once you apply that, the password disappears.
+
+75
+00:03:26,000 --> 00:03:27,000
+But it actually did it.
+
+76
+00:03:28,000 --> 00:03:32,000
+So Mary password is Mary one two, three and the username is Mary.
+
+77
+00:03:32,000 --> 00:03:33,000
+So the server is ready to go.
+
+78
+00:03:33,000 --> 00:03:36,000
+Let's go to Carly now and let's steal that password.
+
+79
+00:03:36,000 --> 00:03:39,000
+So here I am back at Carly now.
+
+80
+00:03:39,000 --> 00:03:41,000
+And there's a couple of things I want to do.
+
+81
+00:03:42,000 --> 00:03:43,000
+All right.
+
+82
+00:03:43,000 --> 00:03:47,000
+Uh, I am going to turn on the sniffing software.
+
+83
+00:03:47,000 --> 00:03:49,000
+Now, the sniffing software is Wireshark.
+
+84
+00:03:49,000 --> 00:03:51,000
+Now this is Wireshark.
+
+85
+00:03:51,000 --> 00:03:53,000
+Now I want to point out something.
+
+86
+00:03:53,000 --> 00:03:56,000
+Wireshark is something that you can download and install on windows.
+
+87
+00:03:56,000 --> 00:04:03,000
+You don't have to use it on, on uh, on Kali I use I use it on Kali because it comes pre-installed
+
+88
+00:04:03,000 --> 00:04:04,000
+and I don't need to install it.
+
+89
+00:04:04,000 --> 00:04:08,000
+Whether you use it on Windows or Linux, it's going to give you the exact same thing.
+
+90
+00:04:08,000 --> 00:04:12,000
+So why even bother with windows if it's already pre-installed on your Linux box?
+
+91
+00:04:12,000 --> 00:04:15,000
+So let's go ahead and get started.
+
+92
+00:04:16,000 --> 00:04:19,000
+So welcome to Wireshark.
+
+93
+00:04:19,000 --> 00:04:22,000
+We got this is going to be Ethernet zero that we're listening to.
+
+94
+00:04:22,000 --> 00:04:26,000
+So we want to make sure we know that uh you know what I need the IP address of my windows box that I
+
+95
+00:04:26,000 --> 00:04:27,000
+do need.
+
+96
+00:04:27,000 --> 00:04:29,000
+So let's go back here to windows.
+
+97
+00:04:29,000 --> 00:04:38,000
+I'm going to do cmd, uh, we're going to do ipconfig just to find the IP conf.
+
+98
+00:04:38,000 --> 00:04:41,000
+So this is 1.20.
+
+99
+00:04:41,000 --> 00:04:43,000
+Is the IP address cool.
+
+100
+00:04:44,000 --> 00:04:47,000
+And uh, let's go ahead.
+
+101
+00:04:47,000 --> 00:04:52,000
+And we're just going to click on the little shark fin to start our packet capture.
+
+102
+00:04:54,000 --> 00:04:57,000
+And now what we're going to do is we're going to open up a terminal.
+
+103
+00:04:57,000 --> 00:04:58,000
+All right.
+
+104
+00:04:59,000 --> 00:05:08,000
+And what we're going to do is we're going to type in FTP, FTP, and we're going to say open, and we're
+
+105
+00:05:08,000 --> 00:05:10,000
+going to give it the IP address.
+
+106
+00:05:11,000 --> 00:05:15,000
+What is that one dot 20 and name Mary.
+
+107
+00:05:18,000 --> 00:05:23,000
+Enter password is M-a-r-y 123.
+
+108
+00:05:24,000 --> 00:05:26,000
+Login successfully.
+
+109
+00:05:26,000 --> 00:05:27,000
+Beautiful.
+
+110
+00:05:27,000 --> 00:05:31,000
+We just logged in to our FTP server.
+
+111
+00:05:31,000 --> 00:05:32,000
+It's all ready to go.
+
+112
+00:05:32,000 --> 00:05:38,000
+Now this this lab is not about how to use FTP, but you can browse it and download and transfer files
+
+113
+00:05:38,000 --> 00:05:40,000
+and all that stuff using its command prompt.
+
+114
+00:05:40,000 --> 00:05:43,000
+If you're really interested, just google how to use FTP on a command line.
+
+115
+00:05:44,000 --> 00:05:46,000
+Uh, I'm going to close this out because I'm actually done with that.
+
+116
+00:05:46,000 --> 00:05:51,000
+I've already captured the password in my Wireshark.
+
+117
+00:05:51,000 --> 00:05:53,000
+So we're going to go ahead and stop it here.
+
+118
+00:05:53,000 --> 00:05:54,000
+Stop the packet capture.
+
+119
+00:05:55,000 --> 00:05:58,000
+And this lab is really about Wireshark more than it is FTP.
+
+120
+00:05:59,000 --> 00:06:05,000
+So what I could do in this now is I can actually go in here and sort it by the protocol that I want
+
+121
+00:06:05,000 --> 00:06:06,000
+to see, and this is how I do it.
+
+122
+00:06:06,000 --> 00:06:08,000
+So we want to see FTP.
+
+123
+00:06:08,000 --> 00:06:12,000
+So notice FTP starts here.
+
+124
+00:06:12,000 --> 00:06:17,000
+And let's go ahead make it nice and big so you guys can see also.
+
+125
+00:06:17,000 --> 00:06:20,000
+Oh look at that user was Mary.
+
+126
+00:06:20,000 --> 00:06:22,000
+You guys can see that.
+
+127
+00:06:22,000 --> 00:06:24,000
+And the plain text here.
+
+128
+00:06:24,000 --> 00:06:26,000
+Look at the password is right there Mary.
+
+129
+00:06:26,000 --> 00:06:28,000
+123.
+
+130
+00:06:28,000 --> 00:06:28,000
+Oh look at that.
+
+131
+00:06:28,000 --> 00:06:33,000
+So if we were if we were using things like.
+
+132
+00:06:34,000 --> 00:06:35,000
+FTP we can.
+
+133
+00:06:35,000 --> 00:06:41,000
+They can easily sniff the actual data and steal your password.
+
+134
+00:06:41,000 --> 00:06:43,000
+This is why you don't want to use it now.
+
+135
+00:06:43,000 --> 00:06:44,000
+Moving on.
+
+136
+00:06:45,000 --> 00:06:46,000
+You know, you guys should know.
+
+137
+00:06:46,000 --> 00:06:50,000
+Now you can set up Wireshark to actually not accept.
+
+138
+00:06:50,000 --> 00:06:51,000
+You can actually set up.
+
+139
+00:06:51,000 --> 00:06:53,000
+This is going back to Wireshark.
+
+140
+00:06:53,000 --> 00:07:00,000
+You can actually set up Wireshark to ensure that it it requires FTP, uh, FTP over SSL.
+
+141
+00:07:00,000 --> 00:07:04,000
+And in this particular circumstance it's going to make sure that it encrypts the data.
+
+142
+00:07:04,000 --> 00:07:10,000
+So you're using Ftps not FTP that basically encrypts it so no one can steal the username and password.
+
+143
+00:07:11,000 --> 00:07:16,000
+Now this lab is about it's not about FTP, it's more about Wireshark.
+
+144
+00:07:16,000 --> 00:07:18,000
+And this is what Wireshark does.
+
+145
+00:07:18,000 --> 00:07:21,000
+This is what a sniffing software does.
+
+146
+00:07:21,000 --> 00:07:29,000
+It sniffs the actual data and it gathers all of the packets that has gone through the network.
+
+147
+00:07:29,000 --> 00:07:31,000
+Here are all your ARP requests.
+
+148
+00:07:32,000 --> 00:07:35,000
+Uh, hopefully you guys know what ARP is.
+
+149
+00:07:35,000 --> 00:07:41,000
+Here is all of the different network browsing the Ssdp that are listed there here, here's all your
+
+150
+00:07:41,000 --> 00:07:43,000
+TCP, here's your Syn act and act.
+
+151
+00:07:44,000 --> 00:07:49,000
+So if you guys remember from your network, plus if you were studying networking, you were you would
+
+152
+00:07:49,000 --> 00:07:51,000
+have learned about since and act and act.
+
+153
+00:07:51,000 --> 00:07:55,000
+Well here are those handshakes actually being shown to you.
+
+154
+00:07:55,000 --> 00:08:00,000
+Now if you're interested more in learning about, you know, what is Tftp, you know, what is UDP,
+
+155
+00:08:00,000 --> 00:08:02,000
+what is TCP, what's the difference?
+
+156
+00:08:02,000 --> 00:08:03,000
+What is ssdp?
+
+157
+00:08:03,000 --> 00:08:06,000
+You know, what is all these things that you got to take your network.
+
+158
+00:08:06,000 --> 00:08:08,000
+Plus hopefully you guys took your network plus.
+
+159
+00:08:09,000 --> 00:08:15,000
+But in this lab you saw how we were able to use Wireshark in order to steal.
+
+160
+00:08:15,000 --> 00:08:18,000
+Let's not say steal, let's say sniff.
+
+161
+00:08:18,000 --> 00:08:20,000
+Or we should say monitor is a better word.
+
+162
+00:08:20,000 --> 00:08:22,000
+Monitor our traffic.
+
+163
+00:08:22,000 --> 00:08:29,000
+And if anybody is utilizing plain text data on a computer in a network, depending on how your network
+
+164
+00:08:29,000 --> 00:08:34,000
+is configured, if you have like a merritt port on a switch and you're capturing all the network traffic,
+
+165
+00:08:34,000 --> 00:08:43,000
+you could literally steal any password utilizing Cleartext protocol such as FTP, Http if it's not encrypted,
+
+166
+00:08:44,000 --> 00:08:52,000
+uh, SNMp, early versions of that, uh, and even emails, SMTp, emails, Pop3, all those things
+
+167
+00:08:52,000 --> 00:08:54,000
+are not encrypted, so you don't want to use them.
+
+168
+00:08:54,000 --> 00:08:54,000
+Okay.
+
+169
+00:08:54,000 --> 00:08:56,000
+Hopefully you guys have some fun with this lab.
+
+170
+00:08:56,000 --> 00:08:58,000
+You guys can practice this.
+
+171
+00:08:58,000 --> 00:09:00,000
+Uh, don't forget FileZilla is absolutely free.
+
+172
+00:09:00,000 --> 00:09:02,000
+And of course Kali comes with Wireshark built into it.
+
+173
+00:09:02,000 --> 00:09:08,000
+Or you can install on windows if you're not, if you're not, uh, fan of utilizing Linux.
+
+174
+00:09:08,000 --> 00:09:09,000
+So do the lab have some fun?
+
diff --git a/26 - Labs/011 Installing and Using SSH_en.srt b/26 - Labs/011 Installing and Using SSH_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..3198b70b82a485fcbeae134bfb528f7c24a8e5a4
--- /dev/null
+++ b/26 - Labs/011 Installing and Using SSH_en.srt
@@ -0,0 +1,580 @@
+1
+00:00:00,000 --> 00:00:05,000
+As a security professional, you're going to be logging into many, many devices on your network.
+
+2
+00:00:05,000 --> 00:00:07,000
+Whether it's a router, it's a switch.
+
+3
+00:00:07,000 --> 00:00:09,000
+It's some kind of a server.
+
+4
+00:00:09,000 --> 00:00:13,000
+Now, one of the most common ways to log into non-windows boxes.
+
+5
+00:00:13,000 --> 00:00:16,000
+And when it comes to windows box, you just use Remote Desktop.
+
+6
+00:00:16,000 --> 00:00:22,000
+But when it comes to administering many Linux boxes, Cisco routers, all types of firewalls, we do
+
+7
+00:00:22,000 --> 00:00:23,000
+use the command prompt.
+
+8
+00:00:23,000 --> 00:00:25,000
+You do not ever want to use telnet.
+
+9
+00:00:25,000 --> 00:00:26,000
+All right.
+
+10
+00:00:26,000 --> 00:00:34,000
+You have to ensure that all the devices that you're connecting to Linux Cisco devices all support SSH.
+
+11
+00:00:34,000 --> 00:00:41,000
+Now I did we did we did a lab earlier where I was able to sniff traffic and capture an FTP username
+
+12
+00:00:41,000 --> 00:00:41,000
+and password.
+
+13
+00:00:41,000 --> 00:00:47,000
+So if you're using something like telnet, they're going to sniff your traffic and steal your username
+
+14
+00:00:47,000 --> 00:00:47,000
+and password.
+
+15
+00:00:47,000 --> 00:00:48,000
+So you don't want that.
+
+16
+00:00:48,000 --> 00:00:53,000
+So you want to make sure that you have SSH up and running on your computer.
+
+17
+00:00:53,000 --> 00:00:57,000
+So let's go ahead and actually get that done.
+
+18
+00:00:57,000 --> 00:01:00,000
+So what we're going to be doing is we're going to install SSH on our Kali Linux.
+
+19
+00:01:00,000 --> 00:01:04,000
+And then we're going to utilize a client in windows to connect to it.
+
+20
+00:01:04,000 --> 00:01:05,000
+And we're going to verify it.
+
+21
+00:01:06,000 --> 00:01:08,000
+Uh so let's go ahead in here and do that.
+
+22
+00:01:08,000 --> 00:01:09,000
+So let's go in here.
+
+23
+00:01:09,000 --> 00:01:17,000
+So we're going to be installing we're going to be installing the ssh ssh on our Kali in the first in
+
+24
+00:01:17,000 --> 00:01:19,000
+the first lab first part of the lab.
+
+25
+00:01:19,000 --> 00:01:20,000
+So let's go here.
+
+26
+00:01:20,000 --> 00:01:21,000
+We're going to open up a terminal.
+
+27
+00:01:21,000 --> 00:01:24,000
+And uh let's make this big so you guys can see.
+
+28
+00:01:24,000 --> 00:01:26,000
+And we're going to use a command sudo.
+
+29
+00:01:26,000 --> 00:01:29,000
+And we are going to say apt.
+
+30
+00:01:29,000 --> 00:01:33,000
+Now, I already did this because I always test my lab before I do the video.
+
+31
+00:01:33,000 --> 00:01:38,000
+And it's basically install open SSH server.
+
+32
+00:01:38,000 --> 00:01:43,000
+We don't want the client because we want to we want to connect into this particular box.
+
+33
+00:01:43,000 --> 00:01:47,000
+So apt install open SSH server.
+
+34
+00:01:47,000 --> 00:01:52,000
+We're going to press enter once the the uh root password which is Kali.
+
+35
+00:01:52,000 --> 00:01:54,000
+It's remember this is all default.
+
+36
+00:01:54,000 --> 00:01:59,000
+The next thing you want to do now is once you have installed the SSH you want to make sure to start
+
+37
+00:01:59,000 --> 00:01:59,000
+it.
+
+38
+00:01:59,000 --> 00:02:05,000
+So for this one we're going to do sudo service ssh start is the command.
+
+39
+00:02:05,000 --> 00:02:08,000
+We're doing okay.
+
+40
+00:02:08,000 --> 00:02:09,000
+Now.
+
+41
+00:02:09,000 --> 00:02:10,000
+That's it.
+
+42
+00:02:10,000 --> 00:02:11,000
+It's there.
+
+43
+00:02:11,000 --> 00:02:13,000
+It's working and it's installed now.
+
+44
+00:02:14,000 --> 00:02:19,000
+I'm going to make a folder on the desktop because I want I want you guys to see that.
+
+45
+00:02:19,000 --> 00:02:22,000
+And we're going to call this folder SSH test.
+
+46
+00:02:24,000 --> 00:02:32,000
+And in this folder you can go in here and we're going to make another folder called test one.
+
+47
+00:02:33,000 --> 00:02:37,000
+I'm doing that because when I connect to the SSH, I want to show you that I'm actually connecting to
+
+48
+00:02:37,000 --> 00:02:38,000
+this box.
+
+49
+00:02:39,000 --> 00:02:39,000
+Okay.
+
+50
+00:02:39,000 --> 00:02:41,000
+So we got that.
+
+51
+00:02:41,000 --> 00:02:42,000
+We're good.
+
+52
+00:02:42,000 --> 00:02:48,000
+You see look, if I'm here and I say ls or list, you can see that I can now see all my desktop because
+
+53
+00:02:48,000 --> 00:02:49,000
+this is on the Kali box.
+
+54
+00:02:49,000 --> 00:02:53,000
+So let's do change directory to desktop.
+
+55
+00:02:53,000 --> 00:02:53,000
+Oops.
+
+56
+00:02:55,000 --> 00:02:58,000
+Change directory to desktop.
+
+57
+00:02:58,000 --> 00:02:58,000
+Yep.
+
+58
+00:03:00,000 --> 00:03:00,000
+CD.
+
+59
+00:03:00,000 --> 00:03:01,000
+No such.
+
+60
+00:03:02,000 --> 00:03:03,000
+Sorry, guys.
+
+61
+00:03:03,000 --> 00:03:03,000
+You know what?
+
+62
+00:03:03,000 --> 00:03:05,000
+I forgot to do its capital on Linux.
+
+63
+00:03:05,000 --> 00:03:06,000
+Remember that?
+
+64
+00:03:06,000 --> 00:03:07,000
+Yes.
+
+65
+00:03:07,000 --> 00:03:08,000
+Here it is.
+
+66
+00:03:08,000 --> 00:03:08,000
+List.
+
+67
+00:03:08,000 --> 00:03:15,000
+And you notice I have, uh, the SSH test folder and then I can even go in there.
+
+68
+00:03:15,000 --> 00:03:19,000
+We can say SSH test and that's it.
+
+69
+00:03:19,000 --> 00:03:22,000
+I can say list and you can see test one.
+
+70
+00:03:22,000 --> 00:03:25,000
+So this is on this box I mean if I do if config.
+
+71
+00:03:26,000 --> 00:03:29,000
+Oops I forgot how to spell.
+
+72
+00:03:30,000 --> 00:03:31,000
+Okay.
+
+73
+00:03:31,000 --> 00:03:34,000
+You notice this IP address is 1921681. 21.
+
+74
+00:03:34,000 --> 00:03:35,000
+Okay.
+
+75
+00:03:35,000 --> 00:03:37,000
+So I just showed you guys that.
+
+76
+00:03:37,000 --> 00:03:41,000
+Now if you don't know this commands I ran the LHS CD and all that stuff.
+
+77
+00:03:41,000 --> 00:03:45,000
+You need to study Linux guys, you should have done your A+ before doing this class.
+
+78
+00:03:46,000 --> 00:03:46,000
+Um.
+
+79
+00:03:47,000 --> 00:03:51,000
+Okay, you notice this is 1.21 on this particular box.
+
+80
+00:03:51,000 --> 00:03:55,000
+Now let's go to windows because we're going to have windows connect to this box.
+
+81
+00:03:56,000 --> 00:04:00,000
+So let's go to windows and we're going to download a client.
+
+82
+00:04:02,000 --> 00:04:04,000
+Call putty.
+
+83
+00:04:04,000 --> 00:04:06,000
+Go to Google type putty.
+
+84
+00:04:06,000 --> 00:04:11,000
+Putty and I want you guys to download.
+
+85
+00:04:11,000 --> 00:04:12,000
+Download putty.
+
+86
+00:04:13,000 --> 00:04:15,000
+Now, Putty is a free software.
+
+87
+00:04:15,000 --> 00:04:19,000
+It's basically a client that allows you to connect to your SSH servers.
+
+88
+00:04:19,000 --> 00:04:24,000
+So I'm going to go in here and we're going to go just to get the executable SSH and telnet.
+
+89
+00:04:24,000 --> 00:04:25,000
+Just get the executable.
+
+90
+00:04:26,000 --> 00:04:28,000
+You're doing an x86, that's fine.
+
+91
+00:04:28,000 --> 00:04:31,000
+Open it up and we're just going to give it the IP address.
+
+92
+00:04:31,000 --> 00:04:34,000
+Remember that IP 1.21 we had.
+
+93
+00:04:34,000 --> 00:04:35,000
+We're going to say open.
+
+94
+00:04:37,000 --> 00:04:38,000
+Log in as Kali.
+
+95
+00:04:39,000 --> 00:04:41,000
+Password is Kali.
+
+96
+00:04:43,000 --> 00:04:44,000
+Look at that.
+
+97
+00:04:44,000 --> 00:04:45,000
+We are logged in.
+
+98
+00:04:45,000 --> 00:04:50,000
+We are now administering that Kali box utilizing full ssh.
+
+99
+00:04:50,000 --> 00:04:51,000
+Now I already logged in.
+
+100
+00:04:51,000 --> 00:04:52,000
+It already created a key.
+
+101
+00:04:52,000 --> 00:04:57,000
+It may ask you to accept, uh, a key creation because it's all encrypted.
+
+102
+00:04:57,000 --> 00:05:00,000
+And watch if I do ls you can see my desktop.
+
+103
+00:05:00,000 --> 00:05:03,000
+So we'll say ls desktop.
+
+104
+00:05:05,000 --> 00:05:06,000
+And there it is.
+
+105
+00:05:06,000 --> 00:05:09,000
+Notice I got my SSH test here.
+
+106
+00:05:09,000 --> 00:05:12,000
+Uh, got my SSH test folder right there.
+
+107
+00:05:12,000 --> 00:05:18,000
+I can even say let's change directory to SSH test.
+
+108
+00:05:20,000 --> 00:05:24,000
+Uh, CD ssh test.
+
+109
+00:05:24,000 --> 00:05:25,000
+Where did I go wrong?
+
+110
+00:05:25,000 --> 00:05:28,000
+What did I not type in?
+
+111
+00:05:28,000 --> 00:05:28,000
+Oh, you know what?
+
+112
+00:05:28,000 --> 00:05:31,000
+I didn't do CD desktop first.
+
+113
+00:05:34,000 --> 00:05:34,000
+All right.
+
+114
+00:05:34,000 --> 00:05:35,000
+Now we are desktop.
+
+115
+00:05:35,000 --> 00:05:40,000
+Now we could do CD, ssh test.
+
+116
+00:05:40,000 --> 00:05:41,000
+There we are.
+
+117
+00:05:41,000 --> 00:05:44,000
+We'll do, uh, list so we can see test one.
+
+118
+00:05:44,000 --> 00:05:45,000
+All right.
+
+119
+00:05:45,000 --> 00:05:45,000
+Very good.
+
+120
+00:05:46,000 --> 00:05:50,000
+Yes, you have to practice your Linux commands, guys.
+
+121
+00:05:50,000 --> 00:05:51,000
+I'm a windows guy.
+
+122
+00:05:52,000 --> 00:05:58,000
+Uh, I am a windows person 90% of the time, but when when Linux calls, I'm really worst at it.
+
+123
+00:05:58,000 --> 00:06:00,000
+I do use it quite a lot.
+
+124
+00:06:00,000 --> 00:06:05,000
+Not as my day to day box when I'm doing specialized pen testing.
+
+125
+00:06:05,000 --> 00:06:09,000
+When I'm doing specialized labs with you guys, I'll use Linux because if the tools are there, I'm
+
+126
+00:06:09,000 --> 00:06:10,000
+not going to go put it on windows.
+
+127
+00:06:10,000 --> 00:06:13,000
+Don't be scared of the command prompt, okay?
+
+128
+00:06:13,000 --> 00:06:14,000
+Don't be scared of it.
+
+129
+00:06:14,000 --> 00:06:16,000
+It's just as good as a graphical interface.
+
+130
+00:06:16,000 --> 00:06:19,000
+Okay, so we just installed SSH.
+
+131
+00:06:19,000 --> 00:06:21,000
+We're able to administer a Kali box.
+
+132
+00:06:21,000 --> 00:06:26,000
+So you guys should be familiar with how to utilize tools like putty.
+
+133
+00:06:26,000 --> 00:06:27,000
+Now going back to putty.
+
+134
+00:06:31,000 --> 00:06:33,000
+Going back to things like putty.
+
+135
+00:06:34,000 --> 00:06:37,000
+It's the windows E to go to open up our explorer.
+
+136
+00:06:37,000 --> 00:06:38,000
+We're going to open up putty here.
+
+137
+00:06:38,000 --> 00:06:39,000
+So this is putty.
+
+138
+00:06:39,000 --> 00:06:42,000
+So this is a SSH client.
+
+139
+00:06:42,000 --> 00:06:46,000
+And this is how we would connect to computers securely.
+
+140
+00:06:46,000 --> 00:06:48,000
+You would just put in the IP address and connect to it.
+
+141
+00:06:48,000 --> 00:06:50,000
+It would need a key generation.
+
+142
+00:06:50,000 --> 00:06:51,000
+It'll generally prompt you for that.
+
+143
+00:06:51,000 --> 00:06:55,000
+So make sure you understand what SSH is and how to utilize it.
+
+144
+00:06:55,000 --> 00:07:00,000
+Now in the last part of this just keep in mind never use clear text protocol.
+
+145
+00:07:00,000 --> 00:07:04,000
+Always make sure to use secure protocols such as SSH.
+
diff --git a/26 - Labs/012 Securing Windows with Password Complexity_en.srt b/26 - Labs/012 Securing Windows with Password Complexity_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..7002dc2a9a8f6a9c7f754121e1dd5a4191a9da46
--- /dev/null
+++ b/26 - Labs/012 Securing Windows with Password Complexity_en.srt
@@ -0,0 +1,560 @@
+1
+00:00:00,000 --> 00:00:06,000
+One of the most fundamental things you should be doing as a security administrator is to have a complex
+
+2
+00:00:06,000 --> 00:00:06,000
+password.
+
+3
+00:00:06,000 --> 00:00:11,000
+And what we want to do is we want all users, not just us, to have complex passwords.
+
+4
+00:00:11,000 --> 00:00:13,000
+Now that's going to be the hard part.
+
+5
+00:00:13,000 --> 00:00:18,000
+If we just tell the users to make their passwords complex, they're probably not going to do it as who
+
+6
+00:00:18,000 --> 00:00:20,000
+the hell wants a complex password?
+
+7
+00:00:20,000 --> 00:00:27,000
+Now, when I say complexity, I'm talking passwords with uppercase, lowercase, numbers, symbols,
+
+8
+00:00:27,000 --> 00:00:32,000
+basically all the letters on the keyboard, and a minimum minimal minimum length of the password.
+
+9
+00:00:32,000 --> 00:00:38,000
+So in this video, I want to show you how we can force people to have complex passwords.
+
+10
+00:00:38,000 --> 00:00:44,000
+By default, operating systems like Windows 10 doesn't have that option enabled.
+
+11
+00:00:44,000 --> 00:00:47,000
+And people can just create three digit passwords like car.
+
+12
+00:00:47,000 --> 00:00:53,000
+But what we can do is we can set the operating system to not accept easy to remember passwords, and
+
+13
+00:00:53,000 --> 00:00:55,000
+they must have complex password.
+
+14
+00:00:55,000 --> 00:00:57,000
+So in this lab that's what we're doing.
+
+15
+00:00:57,000 --> 00:01:02,000
+We're going to configure Windows 10 to support only complex password.
+
+16
+00:01:02,000 --> 00:01:05,000
+Now I'm doing this on a standalone version of windows.
+
+17
+00:01:05,000 --> 00:01:12,000
+You could do this on an actual network in a domain setting where you set the policy once and it throws
+
+18
+00:01:12,000 --> 00:01:14,000
+it out to all the machines on your network.
+
+19
+00:01:14,000 --> 00:01:17,000
+So it's not something you have to set per computer.
+
+20
+00:01:17,000 --> 00:01:19,000
+So let's go and take a look at how to do this.
+
+21
+00:01:19,000 --> 00:01:23,000
+So here I am at my Windows 10 desktop.
+
+22
+00:01:23,000 --> 00:01:24,000
+Now you have to have Windows 10 Pro.
+
+23
+00:01:24,000 --> 00:01:27,000
+Hopefully that's the one you installed on your VM.
+
+24
+00:01:27,000 --> 00:01:29,000
+Now I want to show you guys something.
+
+25
+00:01:29,000 --> 00:01:32,000
+Let's create a user and we're going to do it with a simple password.
+
+26
+00:01:32,000 --> 00:01:34,000
+Then we're going to change the complexity settings.
+
+27
+00:01:34,000 --> 00:01:37,000
+And then we are going to try to create one with a simple password.
+
+28
+00:01:37,000 --> 00:01:38,000
+And it shouldn't accept it.
+
+29
+00:01:38,000 --> 00:01:39,000
+So let's go to it.
+
+30
+00:01:39,000 --> 00:01:41,000
+So we're going to right click on the start menu.
+
+31
+00:01:41,000 --> 00:01:44,000
+And we're going to go to Computer management.
+
+32
+00:01:44,000 --> 00:01:46,000
+This is going to give me my console.
+
+33
+00:01:47,000 --> 00:01:49,000
+Where I can create local users.
+
+34
+00:01:49,000 --> 00:01:50,000
+So look at this.
+
+35
+00:01:50,000 --> 00:01:54,000
+I'm going to go to users and I'm going to make a user named Mary.
+
+36
+00:01:54,000 --> 00:02:00,000
+So Mary password is just car car car.
+
+37
+00:02:00,000 --> 00:02:01,000
+That's it.
+
+38
+00:02:01,000 --> 00:02:03,000
+We just want a simple password.
+
+39
+00:02:03,000 --> 00:02:05,000
+She doesn't have to change it at the next login.
+
+40
+00:02:05,000 --> 00:02:06,000
+That is it.
+
+41
+00:02:06,000 --> 00:02:08,000
+I can say create and look at that.
+
+42
+00:02:08,000 --> 00:02:11,000
+It created it Mary with the password car.
+
+43
+00:02:11,000 --> 00:02:19,000
+Now this of course is a simple password that can easily be cracked by any brute force method, dictionary
+
+44
+00:02:19,000 --> 00:02:20,000
+attack and so on.
+
+45
+00:02:20,000 --> 00:02:21,000
+So we don't want that.
+
+46
+00:02:21,000 --> 00:02:23,000
+Let's delete this account.
+
+47
+00:02:24,000 --> 00:02:30,000
+And then what we're going to do is we are going to change the security settings in windows to support
+
+48
+00:02:30,000 --> 00:02:31,000
+complex passwords.
+
+49
+00:02:31,000 --> 00:02:36,000
+Now, to do that, we're going to open up our run box, hold window key and press the letter R.
+
+50
+00:02:37,000 --> 00:02:41,000
+Or you could just go to start type run and you are going to type in this command.
+
+51
+00:02:41,000 --> 00:02:45,000
+It's called Gpedit.msc.
+
+52
+00:02:45,000 --> 00:02:48,000
+This is group policy editor.
+
+53
+00:02:49,000 --> 00:02:50,000
+Um, that MSC is the console.
+
+54
+00:02:50,000 --> 00:02:52,000
+So this is an MMC console.
+
+55
+00:02:52,000 --> 00:02:54,000
+So if you did a plus you saw me use this quite a lot.
+
+56
+00:02:54,000 --> 00:02:59,000
+Uh, MMC consoles or Microsoft management consoles and the administration of different windows boxes.
+
+57
+00:02:59,000 --> 00:03:02,000
+But for now just do gpedit.msc.
+
+58
+00:03:04,000 --> 00:03:09,000
+And let's maximize this screen here and let's increase the complexity of it.
+
+59
+00:03:09,000 --> 00:03:10,000
+And we're going to do a minimum password.
+
+60
+00:03:10,000 --> 00:03:13,000
+We're going to say you can't have less than eight characters.
+
+61
+00:03:13,000 --> 00:03:19,000
+So we're going to go ahead in here and say to windows settings we're going to say security settings.
+
+62
+00:03:19,000 --> 00:03:21,000
+And we're going to go to account policy.
+
+63
+00:03:21,000 --> 00:03:24,000
+Now in account policy we have password policy.
+
+64
+00:03:24,000 --> 00:03:28,000
+Now in here you have a variety of different things.
+
+65
+00:03:28,000 --> 00:03:31,000
+So the first thing I want to do is password must meet complexity.
+
+66
+00:03:31,000 --> 00:03:34,000
+Notice by default it's disabled.
+
+67
+00:03:34,000 --> 00:03:35,000
+So we're going to double click on this.
+
+68
+00:03:35,000 --> 00:03:36,000
+And we're going to enable that.
+
+69
+00:03:36,000 --> 00:03:39,000
+If you want to see what it does you just click on explain.
+
+70
+00:03:39,000 --> 00:03:43,000
+And it tells you that if this policy is enabled they're going to have to have passwords that are at
+
+71
+00:03:43,000 --> 00:03:45,000
+least six characters.
+
+72
+00:03:45,000 --> 00:03:47,000
+They got to have uppercase lowercase numbers and symbols.
+
+73
+00:03:47,000 --> 00:03:48,000
+That's what this does.
+
+74
+00:03:48,000 --> 00:03:50,000
+So by enabling this.
+
+75
+00:03:51,000 --> 00:03:54,000
+They're going to have to put at least six characters.
+
+76
+00:03:54,000 --> 00:03:55,000
+But let's say you want more than that.
+
+77
+00:03:55,000 --> 00:03:58,000
+You can do minimum password length.
+
+78
+00:03:58,000 --> 00:04:00,000
+So we're going to say eight characters.
+
+79
+00:04:02,000 --> 00:04:05,000
+Now this is all I'm going to be enabling.
+
+80
+00:04:05,000 --> 00:04:07,000
+Some people may do ten characters.
+
+81
+00:04:07,000 --> 00:04:12,000
+You have other options here that we could quickly review, such as enforced password history and maximum
+
+82
+00:04:12,000 --> 00:04:13,000
+and minimum password age.
+
+83
+00:04:13,000 --> 00:04:14,000
+Here's what these are.
+
+84
+00:04:14,000 --> 00:04:20,000
+If you do password history, what this does is that people can't keep reusing the same password over
+
+85
+00:04:20,000 --> 00:04:20,000
+and over.
+
+86
+00:04:20,000 --> 00:04:26,000
+It's always good to remember, like the past, I generally do six passwords so they can't keep reusing
+
+87
+00:04:26,000 --> 00:04:27,000
+the same password.
+
+88
+00:04:27,000 --> 00:04:29,000
+They'd have to wait six password more.
+
+89
+00:04:30,000 --> 00:04:32,000
+You have minimum and maximum.
+
+90
+00:04:32,000 --> 00:04:35,000
+So this is how what's the longest they can keep a password.
+
+91
+00:04:35,000 --> 00:04:38,000
+Like how often do they have to change their password.
+
+92
+00:04:38,000 --> 00:04:42,000
+So for example, if your company has a 60 day policy that you have to change your password every 60
+
+93
+00:04:42,000 --> 00:04:45,000
+days, you do maximum password age of 60 days.
+
+94
+00:04:45,000 --> 00:04:46,000
+So we'll put that in here.
+
+95
+00:04:47,000 --> 00:04:48,000
+We don't want 42 days.
+
+96
+00:04:48,000 --> 00:04:50,000
+That's just the default option.
+
+97
+00:04:51,000 --> 00:04:53,000
+Minimum password age is when they change the password.
+
+98
+00:04:53,000 --> 00:04:55,000
+How fast can they change it back?
+
+99
+00:04:55,000 --> 00:04:58,000
+They can change your password anytime they want or anytime they change it.
+
+100
+00:04:58,000 --> 00:05:00,000
+They have to keep it for a certain amount of days.
+
+101
+00:05:00,000 --> 00:05:01,000
+Right now it's set at zero.
+
+102
+00:05:01,000 --> 00:05:06,000
+So if they change it then they can change it at any time, at any moment immediately.
+
+103
+00:05:06,000 --> 00:05:10,000
+Okay, so we set this I'm just going to minimize this.
+
+104
+00:05:11,000 --> 00:05:13,000
+Let's go back and make another user.
+
+105
+00:05:13,000 --> 00:05:14,000
+Let's recreate the mirror user account.
+
+106
+00:05:14,000 --> 00:05:18,000
+So I'm going to right click and say new user Mary.
+
+107
+00:05:18,000 --> 00:05:21,000
+And we're going to give Mary that same car password.
+
+108
+00:05:21,000 --> 00:05:24,000
+Car car create.
+
+109
+00:05:25,000 --> 00:05:26,000
+Oh you see that message.
+
+110
+00:05:26,000 --> 00:05:30,000
+Now this password does not meet password requirements.
+
+111
+00:05:30,000 --> 00:05:34,000
+Check the password length check complexity and history requirements.
+
+112
+00:05:34,000 --> 00:05:37,000
+So we actually have to put in a nice complex password.
+
+113
+00:05:37,000 --> 00:05:40,000
+Let's do capital P at ss w0 rd.
+
+114
+00:05:41,000 --> 00:05:45,000
+This one actually meets all the complexity even though it's dictionary type word.
+
+115
+00:05:45,000 --> 00:05:45,000
+Uh, you know what.
+
+116
+00:05:45,000 --> 00:05:46,000
+Let's take out that D.
+
+117
+00:05:46,000 --> 00:05:48,000
+Let's just leave it at seven characters.
+
+118
+00:05:49,000 --> 00:05:51,000
+It still doesn't do it.
+
+119
+00:05:51,000 --> 00:05:56,000
+Uh, remember, we had set the thing to eight.
+
+120
+00:05:56,000 --> 00:05:57,000
+So you saw that.
+
+121
+00:05:57,000 --> 00:05:59,000
+That even when it's complex, it must be set to.
+
+122
+00:05:59,000 --> 00:06:01,000
+You gotta have that eight characters in there.
+
+123
+00:06:01,000 --> 00:06:02,000
+And look at that.
+
+124
+00:06:02,000 --> 00:06:06,000
+Now, we got Mary with a nice, complex password.
+
+125
+00:06:07,000 --> 00:06:12,000
+All right, so that is how you would change the windows settings on here.
+
+126
+00:06:12,000 --> 00:06:18,000
+So you would just go into your, your uh, group policy object editor or your group policy editor.
+
+127
+00:06:18,000 --> 00:06:21,000
+Don't forget to go to windows.
+
+128
+00:06:21,000 --> 00:06:23,000
+The settings go to computer configuration.
+
+129
+00:06:23,000 --> 00:06:24,000
+Windows settings.
+
+130
+00:06:24,000 --> 00:06:25,000
+Go to Security Settings.
+
+131
+00:06:25,000 --> 00:06:28,000
+We're going to go down to account policy and password policy.
+
+132
+00:06:28,000 --> 00:06:30,000
+It's all listed here.
+
+133
+00:06:31,000 --> 00:06:31,000
+All right.
+
+134
+00:06:31,000 --> 00:06:32,000
+Very good okay.
+
+135
+00:06:32,000 --> 00:06:39,000
+So that's how you would set windows to actually accept complex password I don't know why this is not
+
+136
+00:06:39,000 --> 00:06:42,000
+on by default but it actually is not on by default.
+
+137
+00:06:42,000 --> 00:06:45,000
+And you can have really simple password to your windows box.
+
+138
+00:06:45,000 --> 00:06:50,000
+But again if you're playing in a domain and you're playing in that large network, this is not a problem
+
+139
+00:06:50,000 --> 00:06:53,000
+because these are generally going to be enabled on the domain.
+
+140
+00:06:53,000 --> 00:06:58,000
+And it's going to all the computers in your network is going to have complex passwords.
+
diff --git a/26 - Labs/013 Using Steganography to hide messages_en.srt b/26 - Labs/013 Using Steganography to hide messages_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..36e2d0f567914e52a7679614bd0d3cc69abd992f
--- /dev/null
+++ b/26 - Labs/013 Using Steganography to hide messages_en.srt
@@ -0,0 +1,412 @@
+1
+00:00:00,000 --> 00:00:05,000
+I'm going to give you a scenario that's pretty scary and happens quite often or more than you think.
+
+2
+00:00:05,000 --> 00:00:08,000
+An organization hires a new person to work for that business.
+
+3
+00:00:08,000 --> 00:00:15,000
+That new person comes into the organization, takes a group photo with everyone in it, including themselves,
+
+4
+00:00:15,000 --> 00:00:17,000
+copies that photos to their desktop.
+
+5
+00:00:17,000 --> 00:00:23,000
+That person then takes some of the company's secret data and embeds that secret data the text, the
+
+6
+00:00:23,000 --> 00:00:29,000
+text that they copied from important files, whether it's credit card information or just company secrets.
+
+7
+00:00:29,000 --> 00:00:33,000
+And they embed that text into the image.
+
+8
+00:00:33,000 --> 00:00:38,000
+They then email the image to themselves at a home email and they email it to everyone also.
+
+9
+00:00:39,000 --> 00:00:46,000
+The person then gets home and then utilizes a special tool to decode the image, to decode the message
+
+10
+00:00:46,000 --> 00:00:48,000
+from the image, taking the text out the image.
+
+11
+00:00:49,000 --> 00:00:52,000
+Now, what I just explained to you is called steganography.
+
+12
+00:00:52,000 --> 00:00:57,000
+Steganography is when you take a message and you embed it into another message.
+
+13
+00:00:57,000 --> 00:01:02,000
+In particularly, you can do it with pictures and you can also do it with movie files and music files.
+
+14
+00:01:02,000 --> 00:01:05,000
+Now in this video I'm going to show you how to do that.
+
+15
+00:01:05,000 --> 00:01:09,000
+It's really simple how to do it, but you must have a picture first.
+
+16
+00:01:09,000 --> 00:01:12,000
+Now I went to Wikipedia and I downloaded a picture of a dog.
+
+17
+00:01:14,000 --> 00:01:16,000
+And I want to show you my dog picture.
+
+18
+00:01:16,000 --> 00:01:19,000
+So this picture, there's something I just took right off of Wikipedia.
+
+19
+00:01:19,000 --> 00:01:21,000
+Just a simple picture of a dog.
+
+20
+00:01:21,000 --> 00:01:29,000
+And what I'm going to do is I want to actually embed a message into this picture using the concept of
+
+21
+00:01:29,000 --> 00:01:30,000
+steganography or the tools.
+
+22
+00:01:30,000 --> 00:01:32,000
+So here's what I want you guys to do.
+
+23
+00:01:32,000 --> 00:01:37,000
+Let's go to Google and let's type steganography online because we want to just use one of the online
+
+24
+00:01:37,000 --> 00:01:38,000
+decoders.
+
+25
+00:01:38,000 --> 00:01:40,000
+There's a variety of different tools that you can download.
+
+26
+00:01:40,000 --> 00:01:45,000
+And Kali Linux even has some command line versions of them built in, but this is generally the easiest
+
+27
+00:01:45,000 --> 00:01:46,000
+one we can do.
+
+28
+00:01:46,000 --> 00:01:50,000
+My first link is style sucks.
+
+29
+00:01:50,000 --> 00:01:51,000
+GitHub.
+
+30
+00:01:51,000 --> 00:01:53,000
+That's the first one I have and I'm just going to use that one.
+
+31
+00:01:54,000 --> 00:01:58,000
+So what I'm going to do is I'm going to select the image, and then I'm going to type a message and
+
+32
+00:01:58,000 --> 00:02:00,000
+I'm going to hide the message within the image.
+
+33
+00:02:00,000 --> 00:02:02,000
+So we're going to say choose file.
+
+34
+00:02:02,000 --> 00:02:05,000
+And I'm going to say on my desktop because I have that dog picture there.
+
+35
+00:02:05,000 --> 00:02:07,000
+So I call it dog no text because I know that I'm not.
+
+36
+00:02:07,000 --> 00:02:09,000
+There's no text in that one.
+
+37
+00:02:10,000 --> 00:02:12,000
+And then what I'm going to do is I'm going to type.
+
+38
+00:02:12,000 --> 00:02:15,000
+This is a secret message.
+
+39
+00:02:16,000 --> 00:02:17,000
+Can't spell the word secret.
+
+40
+00:02:18,000 --> 00:02:23,000
+No one should know this message.
+
+41
+00:02:23,000 --> 00:02:25,000
+You can type whatever you want in there.
+
+42
+00:02:25,000 --> 00:02:26,000
+It doesn't matter.
+
+43
+00:02:26,000 --> 00:02:30,000
+Um, and what I'm going to do now is I'm going to say encode.
+
+44
+00:02:32,000 --> 00:02:38,000
+And notice the binary representation that it's added into the image.
+
+45
+00:02:39,000 --> 00:02:40,000
+Now.
+
+46
+00:02:40,000 --> 00:02:45,000
+This is the original image, the normalized image, and this is the message hidden in the image.
+
+47
+00:02:45,000 --> 00:02:47,000
+Now you look at this.
+
+48
+00:02:47,000 --> 00:02:50,000
+You can't tell the difference between this and the original image.
+
+49
+00:02:50,000 --> 00:02:51,000
+So we're going to right click on this.
+
+50
+00:02:51,000 --> 00:02:53,000
+And we're going to say save as.
+
+51
+00:02:55,000 --> 00:02:58,000
+And we're going to call this one saves it as a PNG.
+
+52
+00:02:58,000 --> 00:03:03,000
+We're going to call this one dog with Tex.
+
+53
+00:03:04,000 --> 00:03:05,000
+Save it on my desktop.
+
+54
+00:03:05,000 --> 00:03:06,000
+That's fine.
+
+55
+00:03:06,000 --> 00:03:07,000
+All right, so we saved it okay.
+
+56
+00:03:07,000 --> 00:03:11,000
+So now what we could do is this particular image dog.
+
+57
+00:03:11,000 --> 00:03:12,000
+So we have dog with text.
+
+58
+00:03:12,000 --> 00:03:14,000
+Dog without text.
+
+59
+00:03:14,000 --> 00:03:17,000
+So this is the one without the actual.
+
+60
+00:03:17,000 --> 00:03:19,000
+And you'll see you can't tell the difference.
+
+61
+00:03:20,000 --> 00:03:20,000
+All right, let's zoom in a little.
+
+62
+00:03:20,000 --> 00:03:21,000
+You can't.
+
+63
+00:03:21,000 --> 00:03:22,000
+Okay, this is the original image.
+
+64
+00:03:22,000 --> 00:03:27,000
+And if I look at the one with the text in it, you can't tell what's the geography does is it uses what's
+
+65
+00:03:27,000 --> 00:03:29,000
+called the least significant bits.
+
+66
+00:03:29,000 --> 00:03:31,000
+A lot of times it's like whitespace in the images.
+
+67
+00:03:31,000 --> 00:03:36,000
+It embeds the messages there and you can't tell the difference at all.
+
+68
+00:03:36,000 --> 00:03:36,000
+I mean, the visual.
+
+69
+00:03:36,000 --> 00:03:39,000
+I cannot tell that there's a message in here.
+
+70
+00:03:39,000 --> 00:03:43,000
+Now, let's say you can then take this, this picture and put it wherever you want.
+
+71
+00:03:43,000 --> 00:03:45,000
+Email it to yourself, do whatever you want with it.
+
+72
+00:03:45,000 --> 00:03:47,000
+Distribute it across the internet.
+
+73
+00:03:47,000 --> 00:03:50,000
+And when you're ready to get the secret message out.
+
+74
+00:03:50,000 --> 00:03:51,000
+Or you can give it to someone.
+
+75
+00:03:51,000 --> 00:03:54,000
+And if they know they have a secret message, what they will do.
+
+76
+00:03:54,000 --> 00:03:55,000
+Let's refresh this page.
+
+77
+00:03:55,000 --> 00:03:57,000
+We're going to go to the code.
+
+78
+00:03:57,000 --> 00:03:59,000
+We're then going to choose file.
+
+79
+00:03:59,000 --> 00:04:01,000
+And we're going to select the dog with the text.
+
+80
+00:04:03,000 --> 00:04:05,000
+And this is the input.
+
+81
+00:04:05,000 --> 00:04:06,000
+And we're going to say decode.
+
+82
+00:04:06,000 --> 00:04:09,000
+Now if there's a message in there it'll decode it and it'll give us the message.
+
+83
+00:04:09,000 --> 00:04:11,000
+Notice this secret message.
+
+84
+00:04:11,000 --> 00:04:12,000
+No one should know this image.
+
+85
+00:04:12,000 --> 00:04:16,000
+So that was the message we put and they were able to read that particular message.
+
+86
+00:04:17,000 --> 00:04:18,000
+And that's the whole app.
+
+87
+00:04:18,000 --> 00:04:21,000
+That's what steganography is.
+
+88
+00:04:21,000 --> 00:04:25,000
+Now, if you're wondering, wow, that's pretty dangerous.
+
+89
+00:04:25,000 --> 00:04:26,000
+How can we stop that?
+
+90
+00:04:26,000 --> 00:04:31,000
+One of the things we have to do as security administrator is we should be blocking the sending of images.
+
+91
+00:04:32,000 --> 00:04:35,000
+Steganography is very complex to stop.
+
+92
+00:04:35,000 --> 00:04:38,000
+The reason is because the message is in the picture.
+
+93
+00:04:38,000 --> 00:04:43,000
+The really only which way to stop, uh, messages from going into the picture.
+
+94
+00:04:43,000 --> 00:04:48,000
+And for the picture to leave the business is just basically don't allow pictures to come out the business
+
+95
+00:04:48,000 --> 00:04:49,000
+or left the business.
+
+96
+00:04:49,000 --> 00:04:56,000
+You can use data, uh, data filtering software, such as a data loss prevention software can really
+
+97
+00:04:56,000 --> 00:04:57,000
+help with that.
+
+98
+00:04:58,000 --> 00:05:03,000
+Another thing you can do is if you suspect the image has some kind of steganography behind it, you
+
+99
+00:05:03,000 --> 00:05:08,000
+would have to have the original image, though, and you can hash the files and see if the hashes are
+
+100
+00:05:08,000 --> 00:05:09,000
+different most times.
+
+101
+00:05:09,000 --> 00:05:15,000
+Also, the file size will change and sometimes the file type would change depending on the steganography
+
+102
+00:05:15,000 --> 00:05:17,000
+software.
+
+103
+00:05:17,000 --> 00:05:21,000
+Okay, but if you enjoyed this, go give it a shot on learn more about steganography.
+
diff --git a/26 - Labs/014 Encrypting a hard drive_en.srt b/26 - Labs/014 Encrypting a hard drive_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..17c5d0ca6c307ebbbc2730e6417d59179aabc460
--- /dev/null
+++ b/26 - Labs/014 Encrypting a hard drive_en.srt
@@ -0,0 +1,296 @@
+1
+00:00:00,000 --> 00:00:01,000
+Imagine this scenario.
+
+2
+00:00:01,000 --> 00:00:04,000
+You have important data on your laptop.
+
+3
+00:00:04,000 --> 00:00:05,000
+I mean, super important data.
+
+4
+00:00:05,000 --> 00:00:10,000
+Maybe you got images, private images of you and your family.
+
+5
+00:00:10,000 --> 00:00:13,000
+Maybe you have a copy of your credit card information on that computer.
+
+6
+00:00:13,000 --> 00:00:17,000
+Maybe you have work applications, your social Security number.
+
+7
+00:00:17,000 --> 00:00:20,000
+In other words, really important information, personal information.
+
+8
+00:00:20,000 --> 00:00:25,000
+Imagine another scenario where that same laptop is your work laptop, and it has secret data about your
+
+9
+00:00:25,000 --> 00:00:27,000
+business and all your emails.
+
+10
+00:00:27,000 --> 00:00:31,000
+What would happen if you leave the laptop in a cafe in the back of a taxi?
+
+11
+00:00:31,000 --> 00:00:32,000
+Or you just lose the laptop?
+
+12
+00:00:32,000 --> 00:00:34,000
+Can somebody get into your laptop?
+
+13
+00:00:35,000 --> 00:00:39,000
+But you might be thinking, well, no, they don't know my password, but they don't need to know your
+
+14
+00:00:39,000 --> 00:00:41,000
+password to get into your laptop.
+
+15
+00:00:41,000 --> 00:00:46,000
+All they have to do is take the hard drive out of the laptop and mount the hard drive on a computer,
+
+16
+00:00:46,000 --> 00:00:51,000
+and then they can just open up the hard drive and have access to every single one of your files without
+
+17
+00:00:51,000 --> 00:00:53,000
+ever needing to know your password.
+
+18
+00:00:53,000 --> 00:00:55,000
+I don't need to know your password to access all your files.
+
+19
+00:00:55,000 --> 00:00:58,000
+I just need access to your actual hard drive.
+
+20
+00:00:59,000 --> 00:01:01,000
+But what if I told you there's a way to stop that?
+
+21
+00:01:01,000 --> 00:01:08,000
+What we could do is we could implement what's known as hard drive level encryption or hard disk level
+
+22
+00:01:08,000 --> 00:01:08,000
+encryption.
+
+23
+00:01:08,000 --> 00:01:13,000
+Basically, what you're going to be doing is you're going to be encrypting your entire hard drive or
+
+24
+00:01:13,000 --> 00:01:16,000
+your solid state drive, which whatever you want to call it.
+
+25
+00:01:17,000 --> 00:01:20,000
+Windows support something we call BitLocker encryption.
+
+26
+00:01:20,000 --> 00:01:26,000
+BitLocker encryption is a piece of software that basically encrypts the entire drive on the computer.
+
+27
+00:01:26,000 --> 00:01:29,000
+So I'm going to be doing that to this desktop.
+
+28
+00:01:29,000 --> 00:01:31,000
+Or by the way, I change machines.
+
+29
+00:01:31,000 --> 00:01:35,000
+I know I said in the beginning I was using a Dell laptop, but unfortunately they had to take it from
+
+30
+00:01:35,000 --> 00:01:37,000
+me because they're doing all the work with it.
+
+31
+00:01:37,000 --> 00:01:38,000
+So they gave me a desktop.
+
+32
+00:01:38,000 --> 00:01:44,000
+So I'm going to be using I'm going to be implementing the BitLocker encryption on my actual computer.
+
+33
+00:01:44,000 --> 00:01:45,000
+Now here's the thing.
+
+34
+00:01:45,000 --> 00:01:51,000
+In order to use BitLocker encryption, you need to have a TPM chip or trusted platform module.
+
+35
+00:01:51,000 --> 00:01:53,000
+The computer does not have a TPM chip.
+
+36
+00:01:53,000 --> 00:01:59,000
+You could use a USB stick in order to store the encryption keys, but most laptop modern laptops nowadays
+
+37
+00:01:59,000 --> 00:02:01,000
+does have a TPM chip.
+
+38
+00:02:01,000 --> 00:02:07,000
+Most modern desktop that came out within the last 12 months also has a TPM chip preceding that.
+
+39
+00:02:07,000 --> 00:02:08,000
+Not necessarily.
+
+40
+00:02:08,000 --> 00:02:15,000
+Let's see how to enable hard drive base level encryption or disk level encryption on a on a particular
+
+41
+00:02:15,000 --> 00:02:16,000
+box.
+
+42
+00:02:16,000 --> 00:02:19,000
+Again, I'm going to be using the base the base computer for this.
+
+43
+00:02:20,000 --> 00:02:25,000
+I can't do it on a VM because the VMs don't have TPM chips on them.
+
+44
+00:02:25,000 --> 00:02:29,000
+So we're going to go to start, and I'm just going to type control to open up my control panel.
+
+45
+00:02:30,000 --> 00:02:36,000
+And, uh, in the control panel, I have BitLocker drive encryption.
+
+46
+00:02:37,000 --> 00:02:41,000
+So what we're going to be doing is we're just going to turn this thing on.
+
+47
+00:02:41,000 --> 00:02:42,000
+It's as easy as that.
+
+48
+00:02:42,000 --> 00:02:46,000
+If you have a laptop now and you haven't turned this on, please do it now.
+
+49
+00:02:48,000 --> 00:02:53,000
+Now it is going to take a few minutes to verify that the machine meets all the requirements.
+
+50
+00:02:53,000 --> 00:02:56,000
+Does it have a TPM chip, for example, in it?
+
+51
+00:02:56,000 --> 00:03:01,000
+And what it's going to do, it's going to be like, okay, we're going to prepare your machine to actually
+
+52
+00:03:01,000 --> 00:03:06,000
+do this, prepare your drive for BitLocker and then encrypt the actual drive.
+
+53
+00:03:06,000 --> 00:03:10,000
+Now I am not going to finish this wizard.
+
+54
+00:03:10,000 --> 00:03:15,000
+The reason is because when you do BitLocker encryption, it generally slows the machine down because
+
+55
+00:03:15,000 --> 00:03:18,000
+this is just a test machine and there's no important data ever on this machine.
+
+56
+00:03:18,000 --> 00:03:21,000
+We don't need BitLocker encryption on.
+
+57
+00:03:21,000 --> 00:03:26,000
+So I would tell you guys, now I have this turned on on my personal laptop that I walk around with.
+
+58
+00:03:26,000 --> 00:03:27,000
+I use a Lenovo.
+
+59
+00:03:27,000 --> 00:03:31,000
+It's a personal laptop that I travel with my travel laptop.
+
+60
+00:03:31,000 --> 00:03:31,000
+You bet.
+
+61
+00:03:31,000 --> 00:03:33,000
+Your best bet it does have this on.
+
+62
+00:03:33,000 --> 00:03:36,000
+So what you would do is just click on next a few times.
+
+63
+00:03:36,000 --> 00:03:39,000
+It's going to encrypt the drive and you're done.
+
+64
+00:03:39,000 --> 00:03:44,000
+Now keep in mind that if you do lose your laptop, what's going to happen is that if somebody takes
+
+65
+00:03:44,000 --> 00:03:48,000
+out the hard drive, they're not going to get anything out of it because the drive is encrypted with
+
+66
+00:03:48,000 --> 00:03:54,000
+the BitLocker encryption, they would need your windows username and password in order to decrypt the
+
+67
+00:03:54,000 --> 00:03:55,000
+data.
+
+68
+00:03:55,000 --> 00:03:58,000
+That's why you need to have a good complex password in windows.
+
+69
+00:03:58,000 --> 00:04:00,000
+Okay, try this lab out.
+
+70
+00:04:00,000 --> 00:04:02,000
+Try it on your machine if you have BitLocker.
+
+71
+00:04:02,000 --> 00:04:06,000
+And if you check your windows settings and you don't have BitLocker, you don't have the right versions
+
+72
+00:04:06,000 --> 00:04:07,000
+of windows.
+
+73
+00:04:07,000 --> 00:04:10,000
+I think you need Windows Pro and above in order to get the BitLocker setting.
+
+74
+00:04:11,000 --> 00:04:14,000
+So go ahead, give it a shot and encrypt your drive.
+
diff --git a/26 - Labs/015 Implementing Role Based Access Control in Windows_en.srt b/26 - Labs/015 Implementing Role Based Access Control in Windows_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..53df5a1543d4704a533fa9d2a5e3f36fac9e4448
--- /dev/null
+++ b/26 - Labs/015 Implementing Role Based Access Control in Windows_en.srt
@@ -0,0 +1,336 @@
+1
+00:00:00,000 --> 00:00:01,000
+Intercourse.
+
+2
+00:00:01,000 --> 00:00:07,000
+I covered what's called role based access control, and I did mention that this is the most famous way
+
+3
+00:00:07,000 --> 00:00:10,000
+that organizations today are grouping users together.
+
+4
+00:00:10,000 --> 00:00:16,000
+So when a user comes into an organization, the things that they have access to the files, the folders,
+
+5
+00:00:16,000 --> 00:00:22,000
+the permissions that the applications, the websites that they have access to is actually dictated by
+
+6
+00:00:22,000 --> 00:00:23,000
+the role they're going to play.
+
+7
+00:00:23,000 --> 00:00:27,000
+Now, roles in windows are basically groups, security groups.
+
+8
+00:00:27,000 --> 00:00:31,000
+So in this video or in this lab, I want to show you how to create users.
+
+9
+00:00:31,000 --> 00:00:37,000
+And I want to show you how to create groups and put those users into groups in another lab.
+
+10
+00:00:37,000 --> 00:00:42,000
+I'll then show you how to assign, how to take those groups and assign them to actual resources.
+
+11
+00:00:42,000 --> 00:00:44,000
+So this lab, that's two labs.
+
+12
+00:00:45,000 --> 00:00:46,000
+But they're basically connected.
+
+13
+00:00:46,000 --> 00:00:48,000
+You have to do one before you do the other.
+
+14
+00:00:48,000 --> 00:00:53,000
+So the first thing that we want to define is what our roles in our organization users perform.
+
+15
+00:00:53,000 --> 00:00:56,000
+Certain roles and roles are basically like job functions.
+
+16
+00:00:56,000 --> 00:01:01,000
+For example, somebody working in the accounting department is going to provide the role of an accountant
+
+17
+00:01:01,000 --> 00:01:06,000
+or somebody doing sales, basically provide a role of sales, somebody doing management and finance,
+
+18
+00:01:06,000 --> 00:01:10,000
+research and development, product development, and so on and so on.
+
+19
+00:01:11,000 --> 00:01:16,000
+So what we want to do is we want to create users, and we want to create groups that represents the
+
+20
+00:01:16,000 --> 00:01:19,000
+roles and then add the users to the groups.
+
+21
+00:01:19,000 --> 00:01:22,000
+Now to do this we're going to be using our Windows 10 box.
+
+22
+00:01:22,000 --> 00:01:23,000
+So let's get started.
+
+23
+00:01:24,000 --> 00:01:26,000
+Now the first thing up I have here.
+
+24
+00:01:27,000 --> 00:01:31,000
+Is my Windows 10 and I'm going to create some users.
+
+25
+00:01:31,000 --> 00:01:35,000
+And then I'm going to create some roles and add them to the roles or particularly to groups.
+
+26
+00:01:35,000 --> 00:01:37,000
+So let's right click on start.
+
+27
+00:01:37,000 --> 00:01:40,000
+And I'm going to say computer management.
+
+28
+00:01:41,000 --> 00:01:44,000
+And I'm going to go here to local maximizes.
+
+29
+00:01:45,000 --> 00:01:47,000
+Let's go to local users and groups.
+
+30
+00:01:47,000 --> 00:01:48,000
+And we're going to go to users.
+
+31
+00:01:48,000 --> 00:01:50,000
+Let's create two users.
+
+32
+00:01:50,000 --> 00:01:52,000
+We're going to create a user called Mary.
+
+33
+00:01:54,000 --> 00:02:01,000
+And I got to give Mary a complex password because in a previous lab we actually made the machine man
+
+34
+00:02:01,000 --> 00:02:04,000
+made password complexity mandatory.
+
+35
+00:02:05,000 --> 00:02:06,000
+So we got Mary.
+
+36
+00:02:08,000 --> 00:02:11,000
+And we're going to create another username Bob.
+
+37
+00:02:16,000 --> 00:02:16,000
+All right.
+
+38
+00:02:16,000 --> 00:02:18,000
+So I created two user.
+
+39
+00:02:19,000 --> 00:02:22,000
+Create and we're going to be done.
+
+40
+00:02:22,000 --> 00:02:22,000
+That's it.
+
+41
+00:02:22,000 --> 00:02:25,000
+So we got Bob and we have Mary.
+
+42
+00:02:25,000 --> 00:02:26,000
+Those are two users.
+
+43
+00:02:26,000 --> 00:02:31,000
+Now, what we're going to do next is we're going to be creating two groups, one for accountant and
+
+44
+00:02:31,000 --> 00:02:32,000
+one for sales.
+
+45
+00:02:32,000 --> 00:02:35,000
+We're going to put Mary an accountant and put Bob in sales.
+
+46
+00:02:35,000 --> 00:02:40,000
+That way, when we're ready to assign permission to resources, we're not going to assign Bob the permission.
+
+47
+00:02:40,000 --> 00:02:43,000
+We're going to assign his entire group sales.
+
+48
+00:02:43,000 --> 00:02:49,000
+We're not going to assign Mary permissions to to different kinds of applications or folders.
+
+49
+00:02:49,000 --> 00:02:51,000
+We're going to assign the group that she's in.
+
+50
+00:02:51,000 --> 00:02:56,000
+So when you use role based access control it makes the administration a lot easier.
+
+51
+00:02:56,000 --> 00:03:01,000
+Take for example you have a folder called accountant and you get 300 people in the accounting department.
+
+52
+00:03:01,000 --> 00:03:03,000
+What are you going to add them all one at a time?
+
+53
+00:03:03,000 --> 00:03:03,000
+No.
+
+54
+00:03:03,000 --> 00:03:08,000
+You basically just add one group called accountant and that'll give them all the permissions.
+
+55
+00:03:08,000 --> 00:03:10,000
+So let's create the groups and then add the users to the groups.
+
+56
+00:03:12,000 --> 00:03:17,000
+So let's go in here to groups and we're going to say new new group.
+
+57
+00:03:17,000 --> 00:03:18,000
+We're going to create a county.
+
+58
+00:03:20,000 --> 00:03:22,000
+And we're going to add in here Mary.
+
+59
+00:03:25,000 --> 00:03:27,000
+So here we go with Mary Create.
+
+60
+00:03:27,000 --> 00:03:30,000
+We're going to create a sales.
+
+61
+00:03:31,000 --> 00:03:33,000
+And we're going to add in here Bob.
+
+62
+00:03:36,000 --> 00:03:38,000
+So we have Bob, we got sales.
+
+63
+00:03:38,000 --> 00:03:38,000
+We're going to say create.
+
+64
+00:03:40,000 --> 00:03:42,000
+And we're going to click on close and here we go.
+
+65
+00:03:42,000 --> 00:03:45,000
+So these are going to be the two groups that we have.
+
+66
+00:03:45,000 --> 00:03:52,000
+If I double click on sales I'll notice that here I have Bob and an accountant I have Mary.
+
+67
+00:03:52,000 --> 00:03:55,000
+Now I only have two users on this machine because I want this lab to be really long.
+
+68
+00:03:55,000 --> 00:03:58,000
+But you can create more users and put them into groups.
+
+69
+00:03:58,000 --> 00:04:02,000
+And this is how you would administer your roles within the organization.
+
+70
+00:04:03,000 --> 00:04:07,000
+Now if you ever want to see like okay, well this I have a user.
+
+71
+00:04:07,000 --> 00:04:07,000
+Mary.
+
+72
+00:04:07,000 --> 00:04:09,000
+What group does Mary belong to?
+
+73
+00:04:09,000 --> 00:04:15,000
+Well, if you just go to the users themselves and you go to Mary and you go to member of, you'll notice
+
+74
+00:04:15,000 --> 00:04:16,000
+it's a member account.
+
+75
+00:04:16,000 --> 00:04:18,000
+If I go to Bob.
+
+76
+00:04:18,000 --> 00:04:20,000
+Well, Bob is a member of sales.
+
+77
+00:04:20,000 --> 00:04:22,000
+And it's as easy as that.
+
+78
+00:04:22,000 --> 00:04:27,000
+Okay, so in this lab we learned of how to create different roles.
+
+79
+00:04:27,000 --> 00:04:31,000
+Now in most organizations, the roles are basically going to be the job function, sales, accounting,
+
+80
+00:04:31,000 --> 00:04:31,000
+finance.
+
+81
+00:04:31,000 --> 00:04:35,000
+So what you do is you make uh, groups for every single one of your roles.
+
+82
+00:04:35,000 --> 00:04:40,000
+And then what you're going to do is then put your users into the groups, and then in the next lab,
+
+83
+00:04:40,000 --> 00:04:49,000
+we're going to be using those same groups to then assign those groups to our, our folders and our applications.
+
+84
+00:04:49,000 --> 00:04:51,000
+So let's do that in the next lab.
+
diff --git a/26 - Labs/016 Assigning Permissions to folders_en.srt b/26 - Labs/016 Assigning Permissions to folders_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..c416196bdda6e0311c864edbae97e9b6c6cebd25
--- /dev/null
+++ b/26 - Labs/016 Assigning Permissions to folders_en.srt
@@ -0,0 +1,588 @@
+1
+00:00:00,000 --> 00:00:00,000
+Okay.
+
+2
+00:00:00,000 --> 00:00:05,000
+So we have actually created two groups Accounting and sales.
+
+3
+00:00:05,000 --> 00:00:10,000
+And in this lab I want to assign permissions utilizing those groups.
+
+4
+00:00:10,000 --> 00:00:15,000
+So instead of assigning permissions to let's say a folder on a computer, uh, to the actual users,
+
+5
+00:00:15,000 --> 00:00:18,000
+we're going to be assigning it to the groups instead of the users.
+
+6
+00:00:18,000 --> 00:00:25,000
+And this is how administrators should be doing it when they administer their network utilizing things
+
+7
+00:00:25,000 --> 00:00:27,000
+like role based access controls.
+
+8
+00:00:27,000 --> 00:00:29,000
+So let's go ahead and get started in this lab.
+
+9
+00:00:29,000 --> 00:00:32,000
+Now we will be utilizing our Windows 10.
+
+10
+00:00:32,000 --> 00:00:34,000
+So I'm going to do windows E here.
+
+11
+00:00:34,000 --> 00:00:35,000
+This whole windows key down press E.
+
+12
+00:00:36,000 --> 00:00:36,000
+Oops.
+
+13
+00:00:37,000 --> 00:00:38,000
+And here I have.
+
+14
+00:00:40,000 --> 00:00:43,000
+Uh, my explorer, I'm going to go I'm going to create a folder on the C drive.
+
+15
+00:00:43,000 --> 00:00:44,000
+So we're going to right click.
+
+16
+00:00:44,000 --> 00:00:46,000
+We're going to say new folder.
+
+17
+00:00:46,000 --> 00:00:48,000
+And we're going to call one accountant.
+
+18
+00:00:51,000 --> 00:00:53,000
+And we're going to create another one.
+
+19
+00:00:53,000 --> 00:00:55,000
+And we're going to call this one sales.
+
+20
+00:00:56,000 --> 00:00:58,000
+Now here's what we want to do.
+
+21
+00:00:58,000 --> 00:01:01,000
+In the previous video we created two groups.
+
+22
+00:01:01,000 --> 00:01:03,000
+One called sales, one called accountant.
+
+23
+00:01:03,000 --> 00:01:09,000
+What I want to do with these two folders that we have here is I want to give accountant the ability
+
+24
+00:01:09,000 --> 00:01:14,000
+people in the accounting department, the ability to add to that folder, delete to that folder, update
+
+25
+00:01:14,000 --> 00:01:15,000
+files.
+
+26
+00:01:15,000 --> 00:01:16,000
+I want to give them the sales people.
+
+27
+00:01:16,000 --> 00:01:20,000
+I want to give people in the sales department the ability to add to that.
+
+28
+00:01:20,000 --> 00:01:20,000
+Delete it.
+
+29
+00:01:21,000 --> 00:01:27,000
+Not the folder, but things in it to add to it, delete from it, update files and so on.
+
+30
+00:01:27,000 --> 00:01:34,000
+But I also want to give people an accountant read access to sales so they can read what's in the sales
+
+31
+00:01:34,000 --> 00:01:35,000
+folder, but they can't modify it.
+
+32
+00:01:35,000 --> 00:01:37,000
+But people in sales can't access account and stuff.
+
+33
+00:01:37,000 --> 00:01:40,000
+So let's go ahead and implement that.
+
+34
+00:01:40,000 --> 00:01:45,000
+Now, before we get started, make sure you have your groups available to do that.
+
+35
+00:01:45,000 --> 00:01:49,000
+If you remember from your last lab, we're going to right click on the start button.
+
+36
+00:01:49,000 --> 00:01:51,000
+We're going to go up to Computer management.
+
+37
+00:01:53,000 --> 00:01:55,000
+And I'm going to go here to local users and groups and groups.
+
+38
+00:01:55,000 --> 00:02:01,000
+Now, we did create this in the last in the last lab, I did notice you have a count in that has Mary
+
+39
+00:02:01,000 --> 00:02:04,000
+in it, and I have sales which has Bob in it.
+
+40
+00:02:04,000 --> 00:02:09,000
+If you haven't done that lab, make sure to do that one before doing this one okay.
+
+41
+00:02:09,000 --> 00:02:11,000
+So let's go ahead and let's edit the accounting folder.
+
+42
+00:02:11,000 --> 00:02:13,000
+So I'm going to right click and I'm gonna say properties.
+
+43
+00:02:13,000 --> 00:02:15,000
+Now by default.
+
+44
+00:02:15,000 --> 00:02:16,000
+What's happening here?
+
+45
+00:02:16,000 --> 00:02:20,000
+You notice this thing already has permissions on it, but we go to the security tab.
+
+46
+00:02:20,000 --> 00:02:22,000
+This already has permissions on it.
+
+47
+00:02:22,000 --> 00:02:26,000
+You see, what's happening is that this folder is pulling the permissions from something higher.
+
+48
+00:02:26,000 --> 00:02:28,000
+The C drive itself.
+
+49
+00:02:28,000 --> 00:02:30,000
+The C drive has its own permissions.
+
+50
+00:02:30,000 --> 00:02:33,000
+So this folder is inheriting that permissions from the C drive.
+
+51
+00:02:33,000 --> 00:02:35,000
+So let's go ahead in here.
+
+52
+00:02:36,000 --> 00:02:37,000
+Oops.
+
+53
+00:02:37,000 --> 00:02:41,000
+Let's go ahead in here and disable the inheritance so we can edit it.
+
+54
+00:02:41,000 --> 00:02:47,000
+You see if we go here, if we click edit and we try to remove some of these permissions like users,
+
+55
+00:02:47,000 --> 00:02:52,000
+it doesn't allow it because it's inheriting the permission from the top object which is the C drive
+
+56
+00:02:52,000 --> 00:02:55,000
+because this is in the C drive.
+
+57
+00:02:56,000 --> 00:02:57,000
+So I'm going to cancel this.
+
+58
+00:02:57,000 --> 00:02:59,000
+I'm going to go here to advance.
+
+59
+00:02:59,000 --> 00:03:01,000
+I'm going to say disable inheritance.
+
+60
+00:03:01,000 --> 00:03:03,000
+And it's going to say.
+
+61
+00:03:04,000 --> 00:03:05,000
+Remove all inheritance.
+
+62
+00:03:05,000 --> 00:03:10,000
+I'm going to do that because that just gives me a nice clean slate, and then I'll add myself back into
+
+63
+00:03:10,000 --> 00:03:11,000
+it so I can administer it.
+
+64
+00:03:13,000 --> 00:03:14,000
+So I'm going to apply that.
+
+65
+00:03:15,000 --> 00:03:15,000
+Yep.
+
+66
+00:03:16,000 --> 00:03:17,000
+We're going to click okay.
+
+67
+00:03:18,000 --> 00:03:21,000
+Now you notice that there's no users or groups here.
+
+68
+00:03:21,000 --> 00:03:23,000
+No one is assigned, not even me, the administrator.
+
+69
+00:03:24,000 --> 00:03:25,000
+So I'm going to click okay.
+
+70
+00:03:25,000 --> 00:03:29,000
+Now, if I try to access this it's going to say you don't have permission.
+
+71
+00:03:29,000 --> 00:03:34,000
+But being that I'm the administrator, I can actually give myself permission because I'm the top dog
+
+72
+00:03:34,000 --> 00:03:34,000
+here.
+
+73
+00:03:34,000 --> 00:03:35,000
+I am the administrator.
+
+74
+00:03:35,000 --> 00:03:37,000
+So I'm just going to say continue.
+
+75
+00:03:37,000 --> 00:03:39,000
+But it does give me access.
+
+76
+00:03:39,000 --> 00:03:40,000
+Now I want to go back.
+
+77
+00:03:42,000 --> 00:03:44,000
+And I want to right click on this accountant folder.
+
+78
+00:03:44,000 --> 00:03:45,000
+And I want to go to properties.
+
+79
+00:03:45,000 --> 00:03:47,000
+And I want I want you guys to see the security.
+
+80
+00:03:47,000 --> 00:03:50,000
+Now notice Andy that's me I'm the person on the desktop.
+
+81
+00:03:50,000 --> 00:03:52,000
+But notice that they gave me full control.
+
+82
+00:03:52,000 --> 00:03:56,000
+Now you do need an account that has full control so you can add and remove permissions.
+
+83
+00:03:56,000 --> 00:03:59,000
+So we're going to go here and we're going to say add.
+
+84
+00:04:02,000 --> 00:04:03,000
+Accounting.
+
+85
+00:04:03,000 --> 00:04:05,000
+This is going to be our group.
+
+86
+00:04:05,000 --> 00:04:08,000
+So we're going to give accounting not full control.
+
+87
+00:04:08,000 --> 00:04:11,000
+We're going to give accountant modify control.
+
+88
+00:04:11,000 --> 00:04:12,000
+Why modify.
+
+89
+00:04:12,000 --> 00:04:17,000
+You see modify allows people in the accounting group to add to that folder or delete from that folder.
+
+90
+00:04:18,000 --> 00:04:23,000
+But they can't change permission on the folder, so they can't go and add another group on there.
+
+91
+00:04:23,000 --> 00:04:24,000
+So that's what we want.
+
+92
+00:04:24,000 --> 00:04:26,000
+We want to give people too much permission.
+
+93
+00:04:26,000 --> 00:04:29,000
+Giving them too much permission would defeat the principles of least privileges.
+
+94
+00:04:29,000 --> 00:04:30,000
+We don't want that.
+
+95
+00:04:30,000 --> 00:04:32,000
+So we're going to apply that.
+
+96
+00:04:32,000 --> 00:04:34,000
+We're going to click okay and that's it.
+
+97
+00:04:34,000 --> 00:04:39,000
+If somebody from the accounting team logs in and tries to access that folder, they'll be able to add
+
+98
+00:04:39,000 --> 00:04:40,000
+and delete anything they want.
+
+99
+00:04:40,000 --> 00:04:41,000
+So we're going to say, okay.
+
+100
+00:04:43,000 --> 00:04:46,000
+Now let's do the same for sales, basically the same process.
+
+101
+00:04:46,000 --> 00:04:47,000
+We're going to right click on it.
+
+102
+00:04:47,000 --> 00:04:48,000
+We're going to go to properties.
+
+103
+00:04:48,000 --> 00:04:50,000
+We're going to go to security.
+
+104
+00:04:50,000 --> 00:04:51,000
+We're going to remove the inheritance.
+
+105
+00:04:53,000 --> 00:04:54,000
+Let me see.
+
+106
+00:04:54,000 --> 00:04:54,000
+Okay.
+
+107
+00:04:55,000 --> 00:04:55,000
+Yep.
+
+108
+00:04:56,000 --> 00:04:59,000
+I'm going to double click on it to add myself back to it.
+
+109
+00:05:00,000 --> 00:05:04,000
+I'm going to go back and what we're going to do, we're going to right click on it.
+
+110
+00:05:04,000 --> 00:05:05,000
+Now this one is going to be a little different.
+
+111
+00:05:07,000 --> 00:05:07,000
+All right.
+
+112
+00:05:07,000 --> 00:05:08,000
+Oops.
+
+113
+00:05:08,000 --> 00:05:09,000
+Where is my tab?
+
+114
+00:05:09,000 --> 00:05:09,000
+Here.
+
+115
+00:05:09,000 --> 00:05:11,000
+This one is going to be a little different.
+
+116
+00:05:11,000 --> 00:05:12,000
+Let me close this.
+
+117
+00:05:14,000 --> 00:05:17,000
+Do it again because I misclicked okay, this one we're going to do a little different.
+
+118
+00:05:17,000 --> 00:05:19,000
+So this one here we're going to give sales.
+
+119
+00:05:21,000 --> 00:05:23,000
+We're going to give sales notice.
+
+120
+00:05:23,000 --> 00:05:24,000
+It's groups to people.
+
+121
+00:05:24,000 --> 00:05:27,000
+They're modify but we're going to give a count in.
+
+122
+00:05:31,000 --> 00:05:36,000
+We're going to give a count and read, notice read and execute so they can open the folder.
+
+123
+00:05:36,000 --> 00:05:37,000
+All right.
+
+124
+00:05:37,000 --> 00:05:41,000
+They can list what's in the folder and they can open up any files on there.
+
+125
+00:05:41,000 --> 00:05:43,000
+That's what these three boxes are.
+
+126
+00:05:43,000 --> 00:05:44,000
+But they can't update files.
+
+127
+00:05:44,000 --> 00:05:48,000
+They can't write to any of the files and they can't add or remove files.
+
+128
+00:05:48,000 --> 00:05:49,000
+It'll be modified.
+
+129
+00:05:50,000 --> 00:05:51,000
+And click okay.
+
+130
+00:05:52,000 --> 00:05:53,000
+And.
+
+131
+00:05:53,000 --> 00:05:54,000
+Okay.
+
+132
+00:05:54,000 --> 00:05:54,000
+That's it.
+
+133
+00:05:55,000 --> 00:05:57,000
+Now you guys can try it.
+
+134
+00:05:57,000 --> 00:05:58,000
+So I tried it.
+
+135
+00:05:58,000 --> 00:06:02,000
+It worked already, so I'm not going to make this any much longer.
+
+136
+00:06:02,000 --> 00:06:07,000
+But what you guys can do is log out of the machine and log in as as Mary and log in as Bob, and you'll
+
+137
+00:06:07,000 --> 00:06:13,000
+see that Bob will be able to access everything in the sales folder.
+
+138
+00:06:13,000 --> 00:06:17,000
+He'll be able to create files, delete files, but he can't access the accountant folder.
+
+139
+00:06:17,000 --> 00:06:23,000
+Mary, on the other hand, will be able to log in and Mary is going to be able to do anything she wants
+
+140
+00:06:23,000 --> 00:06:27,000
+in the accountant folder, and then she can see what's in the sales folder, but she can't update it.
+
+141
+00:06:28,000 --> 00:06:33,000
+The best way to learn is, of course, to try things, create different groups and try different permissions.
+
+142
+00:06:33,000 --> 00:06:39,000
+But when it comes to the world of security, nothing beats giving good old fashioned permissions to
+
+143
+00:06:39,000 --> 00:06:40,000
+files and folders.
+
+144
+00:06:40,000 --> 00:06:46,000
+Now, keep in mind that in the world of role based access control, it's not just about assigning permissions
+
+145
+00:06:46,000 --> 00:06:47,000
+to files and folders.
+
+146
+00:06:47,000 --> 00:06:48,000
+We all.
+
+147
+00:06:48,000 --> 00:06:52,000
+We can also use those groups to assign permissions to websites and applications.
+
diff --git a/26 - Labs/017 Configure Firewall rules_en.srt b/26 - Labs/017 Configure Firewall rules_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..30b4288a5c8ce5882fc19fc35a7efea752c4e800
--- /dev/null
+++ b/26 - Labs/017 Configure Firewall rules_en.srt
@@ -0,0 +1,440 @@
+1
+00:00:00,000 --> 00:00:06,000
+In this video, I'm going to show you how to configure a firewall in particularly Windows Firewall.
+
+2
+00:00:06,000 --> 00:00:09,000
+So windows comes with a firewall built into it.
+
+3
+00:00:09,000 --> 00:00:12,000
+It's basically Windows Defender Firewall.
+
+4
+00:00:12,000 --> 00:00:17,000
+Now one of the things that firewalls that we have to understand is how to turn them off, how to turn
+
+5
+00:00:17,000 --> 00:00:17,000
+them on.
+
+6
+00:00:17,000 --> 00:00:20,000
+How do we open ports by fire.
+
+7
+00:00:20,000 --> 00:00:24,000
+By default, firewalls, blocks, all traffic coming in.
+
+8
+00:00:24,000 --> 00:00:28,000
+But if you have a particular computer that you want to allow traffic in, maybe you're running a particular
+
+9
+00:00:28,000 --> 00:00:34,000
+server, maybe you're running a particular web server, maybe you have to have port 443 open because
+
+10
+00:00:34,000 --> 00:00:36,000
+you're running a web server on that machine.
+
+11
+00:00:36,000 --> 00:00:42,000
+Maybe you're running an FTP server and you need port 21 open, or if you're doing FTP over SSH port
+
+12
+00:00:42,000 --> 00:00:43,000
+22.
+
+13
+00:00:43,000 --> 00:00:46,000
+So in this video let's see how to open ports on a firewall.
+
+14
+00:00:46,000 --> 00:00:48,000
+How to turn on and off firewalls.
+
+15
+00:00:48,000 --> 00:00:50,000
+Let's get started in the lab.
+
+16
+00:00:50,000 --> 00:00:52,000
+Now we're going to be using Windows 10 to do this.
+
+17
+00:00:52,000 --> 00:00:55,000
+So let's go in here and we're going to go and start.
+
+18
+00:00:55,000 --> 00:00:56,000
+And I'm just going to type the word firewall.
+
+19
+00:00:56,000 --> 00:00:59,000
+Just to bring up the firewall from Control Panel.
+
+20
+00:00:59,000 --> 00:01:03,000
+You could have gone to Control Panel and actually just click on Windows Defender Firewall.
+
+21
+00:01:05,000 --> 00:01:10,000
+Now I have mine's currently turned off as I did that earlier to run some of the few the earlier labs.
+
+22
+00:01:10,000 --> 00:01:16,000
+So what I'm going to do here is the first thing you're going to learn in the lab is how to turn on and
+
+23
+00:01:16,000 --> 00:01:17,000
+off Windows Firewall.
+
+24
+00:01:17,000 --> 00:01:23,000
+So right here we have an option that says, uh, turn Windows Defender Firewall on or off.
+
+25
+00:01:23,000 --> 00:01:25,000
+And I'm going to turn mine's on.
+
+26
+00:01:25,000 --> 00:01:26,000
+All right.
+
+27
+00:01:26,000 --> 00:01:27,000
+Now it has two settings.
+
+28
+00:01:27,000 --> 00:01:31,000
+So if you're connected to a public network, these are the settings that you would get.
+
+29
+00:01:31,000 --> 00:01:34,000
+And if you connect it to your private network this would be like inside of your house.
+
+30
+00:01:34,000 --> 00:01:38,000
+You can actually have it turned off inside your house and turned on external.
+
+31
+00:01:38,000 --> 00:01:44,000
+When you leave your house, every time you join a network, you notice that windows access.
+
+32
+00:01:44,000 --> 00:01:46,000
+Is this a public or a private network?
+
+33
+00:01:46,000 --> 00:01:48,000
+Now sometimes you may be joined to a domain.
+
+34
+00:01:48,000 --> 00:01:54,000
+If this computer is located in a type of a business environment that has Windows Server, then you wouldn't
+
+35
+00:01:54,000 --> 00:01:56,000
+have necessarily a private setting.
+
+36
+00:01:56,000 --> 00:01:57,000
+It'll be a domain setting.
+
+37
+00:01:58,000 --> 00:01:58,000
+Okay.
+
+38
+00:01:58,000 --> 00:01:59,000
+Let's go take a look here.
+
+39
+00:01:59,000 --> 00:02:02,000
+So I have my firewall turned on.
+
+40
+00:02:02,000 --> 00:02:05,000
+Now you can see that it's all green and it's ready to go.
+
+41
+00:02:05,000 --> 00:02:08,000
+Now the next thing here that we're going to be doing.
+
+42
+00:02:09,000 --> 00:02:15,000
+Is, I'm going to show you, how are we going to open ports on this particular firewall.
+
+43
+00:02:15,000 --> 00:02:19,000
+So Windows Firewall comes with a ton of configuration.
+
+44
+00:02:19,000 --> 00:02:24,000
+And if you try using apps sometimes they may not work because they don't you haven't open the port.
+
+45
+00:02:24,000 --> 00:02:27,000
+So let's go to Advanced Settings on this section.
+
+46
+00:02:28,000 --> 00:02:33,000
+And now I have access to all of the rules firewalls.
+
+47
+00:02:33,000 --> 00:02:38,000
+And it doesn't matter whether it's Windows Firewall, it's a Sonicwall, it's a Cisco's ASA or whatever
+
+48
+00:02:38,000 --> 00:02:38,000
+it is.
+
+49
+00:02:38,000 --> 00:02:41,000
+All firewalls are managed by rules.
+
+50
+00:02:41,000 --> 00:02:48,000
+You have to understand that by default, firewalls block everything coming in and allow everything going
+
+51
+00:02:48,000 --> 00:02:48,000
+out.
+
+52
+00:02:49,000 --> 00:02:56,000
+So notice you have inbound things that are coming in and then you have outbound things that are basically
+
+53
+00:02:56,000 --> 00:02:57,000
+going out.
+
+54
+00:02:57,000 --> 00:03:05,000
+So if I go to the inbound rules you'll notice these are things that it's going to allow into the machine.
+
+55
+00:03:06,000 --> 00:03:11,000
+And the outbound rules are things that it's going to allow to go out of the machine.
+
+56
+00:03:11,000 --> 00:03:11,000
+Now by default.
+
+57
+00:03:11,000 --> 00:03:15,000
+Basically it allows basically every single thing to go out.
+
+58
+00:03:15,000 --> 00:03:23,000
+Now, what we want to do is let's say you're running an FTP server on your machine.
+
+59
+00:03:23,000 --> 00:03:24,000
+All right.
+
+60
+00:03:24,000 --> 00:03:26,000
+Um, let's say running an FTP server.
+
+61
+00:03:26,000 --> 00:03:34,000
+Now, by default, there is no, uh, profile here or no rule that's going to allow an FTP server to
+
+62
+00:03:34,000 --> 00:03:34,000
+come in.
+
+63
+00:03:34,000 --> 00:03:38,000
+That means FTP traffic coming into the machine, inbound rules.
+
+64
+00:03:38,000 --> 00:03:40,000
+There's nothing like that that's going to be here.
+
+65
+00:03:40,000 --> 00:03:41,000
+You can search all you want.
+
+66
+00:03:41,000 --> 00:03:45,000
+It doesn't exist because generally speaking it doesn't come configured with any of that.
+
+67
+00:03:45,000 --> 00:03:47,000
+So if that's what you want to do, here's how you would do it.
+
+68
+00:03:47,000 --> 00:03:49,000
+And this lab is how to configure an inbound rule.
+
+69
+00:03:49,000 --> 00:03:51,000
+So we're going to click on new rule.
+
+70
+00:03:53,000 --> 00:03:56,000
+And in here notice you can see a program.
+
+71
+00:03:56,000 --> 00:03:58,000
+What what type of rule would you like to create.
+
+72
+00:03:58,000 --> 00:04:01,000
+Will we want to allow in a port?
+
+73
+00:04:01,000 --> 00:04:02,000
+What port are we doing.
+
+74
+00:04:02,000 --> 00:04:05,000
+We're going to be doing port 21 because that's what FTP runs on.
+
+75
+00:04:05,000 --> 00:04:06,000
+So we're going to click on next.
+
+76
+00:04:06,000 --> 00:04:09,000
+TCP does run on port 21.
+
+77
+00:04:12,000 --> 00:04:15,000
+And what action should you take when a connection matches it?
+
+78
+00:04:15,000 --> 00:04:17,000
+Well, we want to allow the connection.
+
+79
+00:04:17,000 --> 00:04:20,000
+This connection, uh, this includes connections that are protected.
+
+80
+00:04:20,000 --> 00:04:21,000
+IPsec or not?
+
+81
+00:04:21,000 --> 00:04:21,000
+Yes.
+
+82
+00:04:21,000 --> 00:04:23,000
+We want to allow the connection.
+
+83
+00:04:23,000 --> 00:04:26,000
+You do have an option to only allow it if it's secure.
+
+84
+00:04:26,000 --> 00:04:30,000
+So for example, if it's used in things like IPsec then only then it's going to allow it.
+
+85
+00:04:30,000 --> 00:04:32,000
+But FTP by default is not secure.
+
+86
+00:04:32,000 --> 00:04:33,000
+So we'll see.
+
+87
+00:04:33,000 --> 00:04:34,000
+Allow that.
+
+88
+00:04:35,000 --> 00:04:39,000
+And we're going to apply this to this no matter where the machine is, whether it's on the domain private
+
+89
+00:04:39,000 --> 00:04:41,000
+network or on your public network.
+
+90
+00:04:41,000 --> 00:04:43,000
+And we're going to call this the FTP server.
+
+91
+00:04:46,000 --> 00:04:47,000
+And finish that.
+
+92
+00:04:48,000 --> 00:04:52,000
+So here is my inbound rule that we just created.
+
+93
+00:04:52,000 --> 00:04:59,000
+So what this rule does is that now I can set up an FTP server on this machine, and then people can
+
+94
+00:04:59,000 --> 00:05:00,000
+connect to it, if not by default.
+
+95
+00:05:00,000 --> 00:05:01,000
+It just doesn't do it.
+
+96
+00:05:01,000 --> 00:05:06,000
+So if you are trying to set up an FTP server earlier in the class and it didn't work, maybe because
+
+97
+00:05:06,000 --> 00:05:08,000
+you didn't have the rule, you didn't have the right rule turned on.
+
+98
+00:05:08,000 --> 00:05:11,000
+So what I did is I just turned the firewall off, right?
+
+99
+00:05:11,000 --> 00:05:12,000
+That's that's not the good thing to do.
+
+100
+00:05:12,000 --> 00:05:13,000
+You should have rules.
+
+101
+00:05:13,000 --> 00:05:15,000
+Don't turn firewalls off.
+
+102
+00:05:16,000 --> 00:05:20,000
+I don't recommend to mess with any of the other rules that are here, because these rules, by default
+
+103
+00:05:20,000 --> 00:05:22,000
+are set up by windows to allow it to work.
+
+104
+00:05:23,000 --> 00:05:28,000
+Um, these are things you're probably not going to want to play with, but now you can see that you
+
+105
+00:05:28,000 --> 00:05:31,000
+can configure rules on a firewall.
+
+106
+00:05:31,000 --> 00:05:34,000
+So keep in mind, guys, all firewalls are managed by rules.
+
+107
+00:05:34,000 --> 00:05:35,000
+That's the point of this lab.
+
+108
+00:05:35,000 --> 00:05:38,000
+Every firewall that's out there is managed by rules.
+
+109
+00:05:38,000 --> 00:05:42,000
+And if you want to allow traffic in, you're going to have to create a rule to allow that particular
+
+110
+00:05:42,000 --> 00:05:42,000
+traffic.
+
diff --git a/26 - Labs/018 Updating a Computer_en.srt b/26 - Labs/018 Updating a Computer_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..e8618d0519db4217169bafc941f79c35b0171544
--- /dev/null
+++ b/26 - Labs/018 Updating a Computer_en.srt
@@ -0,0 +1,300 @@
+1
+00:00:00,000 --> 00:00:06,000
+One of the most basic thing any IT security administrator should be doing is keeping their machine updated.
+
+2
+00:00:06,000 --> 00:00:08,000
+You guys probably already know this labs.
+
+3
+00:00:08,000 --> 00:00:10,000
+If you do, you can just skip it.
+
+4
+00:00:10,000 --> 00:00:13,000
+But the whole point of this lab is to make sure that our machines are updated.
+
+5
+00:00:13,000 --> 00:00:15,000
+How can we check that and where are the settings?
+
+6
+00:00:15,000 --> 00:00:16,000
+Let me show you how.
+
+7
+00:00:16,000 --> 00:00:21,000
+So let's I'm going to do this on my Windows 11 because my Windows 11 is actually connected to the internet
+
+8
+00:00:22,000 --> 00:00:24,000
+and it's receiving valid updates.
+
+9
+00:00:24,000 --> 00:00:28,000
+So I'm going to go to start and I'm just going to type update just to make it easy.
+
+10
+00:00:28,000 --> 00:00:31,000
+You don't have to go to Control Panel and try to look for it and all that.
+
+11
+00:00:31,000 --> 00:00:34,000
+And notice you have check for updates.
+
+12
+00:00:34,000 --> 00:00:35,000
+So I'm just going to click on this.
+
+13
+00:00:37,000 --> 00:00:39,000
+And here we go with Windows Update.
+
+14
+00:00:39,000 --> 00:00:45,000
+Now right now my machine is fully updated because notice that I have this option turned on.
+
+15
+00:00:45,000 --> 00:00:49,000
+Get uh latest latest updates as soon as they as soon as they're available.
+
+16
+00:00:49,000 --> 00:00:50,000
+I have mine turned on.
+
+17
+00:00:50,000 --> 00:00:53,000
+So I make sure that my machine is always getting updated.
+
+18
+00:00:53,000 --> 00:00:59,000
+Now, if you ever come to a machine as a network administrator and you're not sure if this machine has
+
+19
+00:00:59,000 --> 00:01:03,000
+been updated or is getting update, you're going to want to check right here at the top.
+
+20
+00:01:03,000 --> 00:01:05,000
+Notice you're up to date.
+
+21
+00:01:05,000 --> 00:01:07,000
+Last check today at 2:34 p.m..
+
+22
+00:01:08,000 --> 00:01:11,000
+Right now it's 2:54 p.m., so this machine just checked for update.
+
+23
+00:01:11,000 --> 00:01:15,000
+If you're not sure if a machine has been updated, you're probably going to want to click on the button
+
+24
+00:01:15,000 --> 00:01:17,000
+that says check for update.
+
+25
+00:01:17,000 --> 00:01:22,000
+That will ensure that the machine can pulls updates from Microsoft and install the particular update.
+
+26
+00:01:23,000 --> 00:01:30,000
+Now, I do recommend on a home machine to have this option checked to get the updates as soon as they're
+
+27
+00:01:30,000 --> 00:01:31,000
+available.
+
+28
+00:01:31,000 --> 00:01:36,000
+Here's the problem in work environments, that option is probably not a good idea.
+
+29
+00:01:36,000 --> 00:01:43,000
+Updates have a way of breaking enterprises or corporate companies software, especially custom software.
+
+30
+00:01:43,000 --> 00:01:48,000
+So you probably want to check the updates or test the updates against the software before installing
+
+31
+00:01:48,000 --> 00:01:49,000
+those updates.
+
+32
+00:01:49,000 --> 00:01:54,000
+A lot of corporate companies are going to have their own update servers that pushes out updates that
+
+33
+00:01:54,000 --> 00:01:58,000
+they check updates from, or they actually test the updates against their systems.
+
+34
+00:01:58,000 --> 00:01:59,000
+So keep that in mind.
+
+35
+00:01:59,000 --> 00:02:03,000
+But at home, you're going to probably want to make sure that button is checked at all times.
+
+36
+00:02:04,000 --> 00:02:07,000
+Uh, you do have an update history on the next option.
+
+37
+00:02:07,000 --> 00:02:11,000
+And what that does is that's going to that's going to show you all the updates that's been applied to
+
+38
+00:02:11,000 --> 00:02:12,000
+your machine.
+
+39
+00:02:12,000 --> 00:02:15,000
+Now, one of the things I like to do here is where it says advanced options.
+
+40
+00:02:15,000 --> 00:02:19,000
+In here you have a ton of things that you can go ahead and do.
+
+41
+00:02:19,000 --> 00:02:20,000
+All right.
+
+42
+00:02:20,000 --> 00:02:25,000
+You can do things like such as you can turn off get Microsoft Office and other updates.
+
+43
+00:02:25,000 --> 00:02:30,000
+So you're just not receiving windows updates, but updates from other things such as Microsoft Office.
+
+44
+00:02:30,000 --> 00:02:35,000
+One thing I like to do is right here active hours.
+
+45
+00:02:35,000 --> 00:02:39,000
+So right now mines is set to 8 a.m. to 5 p.m., and that's the automatic one.
+
+46
+00:02:39,000 --> 00:02:45,000
+That means that when windows receives an update, it's not going to reset the when it installs it.
+
+47
+00:02:45,000 --> 00:02:48,000
+It's not going to restart the machine between those times.
+
+48
+00:02:48,000 --> 00:02:53,000
+But anything outside of those times like seven in the morning or six in the afternoon, it could restart
+
+49
+00:02:53,000 --> 00:02:53,000
+the machine.
+
+50
+00:02:53,000 --> 00:02:56,000
+So if you want, you're going to have to notice.
+
+51
+00:02:56,000 --> 00:02:57,000
+Mine is set to automatically.
+
+52
+00:02:57,000 --> 00:02:59,000
+You can then go in and manually change it.
+
+53
+00:02:59,000 --> 00:03:03,000
+Maybe you work from let's say seven in the morning.
+
+54
+00:03:05,000 --> 00:03:06,000
+To.
+
+55
+00:03:06,000 --> 00:03:08,000
+Let's say you worked eight at night.
+
+56
+00:03:08,000 --> 00:03:09,000
+You got a long day.
+
+57
+00:03:09,000 --> 00:03:18,000
+Now, the machine will not, uh, take updates and restart within this 13 hour time frame.
+
+58
+00:03:18,000 --> 00:03:21,000
+Notice the max it can be is basically 18 hours.
+
+59
+00:03:21,000 --> 00:03:22,000
+Uh, what?
+
+60
+00:03:22,000 --> 00:03:23,000
+What would you like?
+
+61
+00:03:23,000 --> 00:03:24,000
+Notice optional updates.
+
+62
+00:03:24,000 --> 00:03:25,000
+I have two optional updates.
+
+63
+00:03:25,000 --> 00:03:28,000
+It's going to be like things like device drivers mostly falls in here.
+
+64
+00:03:28,000 --> 00:03:32,000
+You can even optimize your bandwidth or even reset or go back on certain updates.
+
+65
+00:03:32,000 --> 00:03:39,000
+So if an update hits your machine and that update kind of breaks a particular software, you can actually
+
+66
+00:03:39,000 --> 00:03:41,000
+revert back the update.
+
+67
+00:03:41,000 --> 00:03:43,000
+Restart applications.
+
+68
+00:03:43,000 --> 00:03:45,000
+This automatically save any restartable apps.
+
+69
+00:03:45,000 --> 00:03:48,000
+If an app gets restarted on data loss, it can actually try to bring that back.
+
+70
+00:03:49,000 --> 00:03:49,000
+All right.
+
+71
+00:03:50,000 --> 00:03:52,000
+These are just some settings here for updates.
+
+72
+00:03:52,000 --> 00:03:56,000
+The big thing though is this big blue button here where we want to make sure that our machines are set
+
+73
+00:03:56,000 --> 00:03:57,000
+to update.
+
+74
+00:03:57,000 --> 00:04:01,000
+When it comes to security updating is security 101.
+
+75
+00:04:01,000 --> 00:04:03,000
+So make sure your machines stay updated.
+
diff --git a/26 - Labs/019 Hardening a Desktop using group policy_en.srt b/26 - Labs/019 Hardening a Desktop using group policy_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..305a09c97fc70ab3eaa75e0bb96522d53fce9fe0
--- /dev/null
+++ b/26 - Labs/019 Hardening a Desktop using group policy_en.srt
@@ -0,0 +1,324 @@
+1
+00:00:00,000 --> 00:00:05,000
+In this lab, I'm going to show you how to do what's called hardening of a desktop.
+
+2
+00:00:05,000 --> 00:00:10,000
+Basically what what you're going to be doing is you're going to be removing things that users don't
+
+3
+00:00:10,000 --> 00:00:11,000
+need to access.
+
+4
+00:00:11,000 --> 00:00:16,000
+The less options user has on the machine, the more secure the machines is.
+
+5
+00:00:16,000 --> 00:00:21,000
+So in this video, I want to show you guys how to use what's called group policy to restrict access
+
+6
+00:00:21,000 --> 00:00:23,000
+to certain things.
+
+7
+00:00:23,000 --> 00:00:28,000
+In particularly, I'm going to show you how to use group policy to restrict access to things like the
+
+8
+00:00:28,000 --> 00:00:30,000
+control panel on the computer.
+
+9
+00:00:30,000 --> 00:00:32,000
+Now let's see how to do it.
+
+10
+00:00:32,000 --> 00:00:34,000
+And then we'll talk more about it when we're done.
+
+11
+00:00:34,000 --> 00:00:36,000
+And we're going to be using Windows 10 for this.
+
+12
+00:00:36,000 --> 00:00:38,000
+So let's go in here to Windows 10.
+
+13
+00:00:38,000 --> 00:00:45,000
+And uh I am going to go to just do window and do R for run.
+
+14
+00:00:45,000 --> 00:00:53,000
+And we want to do this GP edit dot MSC because we're going to be using the Group Policy Object editor.
+
+15
+00:00:53,000 --> 00:00:55,000
+So it's basically a group policy that allows us.
+
+16
+00:00:55,000 --> 00:00:57,000
+So we're going to click on okay.
+
+17
+00:00:58,000 --> 00:01:02,000
+And in a previous lab I had showed you guys.
+
+18
+00:01:02,000 --> 00:01:07,000
+That group policy allows me to control things like the password policy, but group policy under user
+
+19
+00:01:07,000 --> 00:01:15,000
+configurations also allows me to configure administrative templates, allows me to configure all types
+
+20
+00:01:15,000 --> 00:01:24,000
+of things, such as access to things like the control panel and even certain things like a desktop wallpaper.
+
+21
+00:01:24,000 --> 00:01:27,000
+Now I want to show you guys before we get started, let's go to start.
+
+22
+00:01:28,000 --> 00:01:30,000
+And I'm going to open up my control panel.
+
+23
+00:01:31,000 --> 00:01:34,000
+And you notice I control panel opens up just fine.
+
+24
+00:01:34,000 --> 00:01:36,000
+So I'm going to close this out.
+
+25
+00:01:36,000 --> 00:01:42,000
+Now I'm going to go here to under administrative template you have control panel.
+
+26
+00:01:42,000 --> 00:01:47,000
+And you notice you have this option prohibit access to control panel and PC settings.
+
+27
+00:01:47,000 --> 00:01:48,000
+So you could double click on this.
+
+28
+00:01:49,000 --> 00:01:53,000
+And we're going to enable this now if it says at least windows 2000.
+
+29
+00:01:53,000 --> 00:01:56,000
+This is a really old sentence all the way from back in windows 2000.
+
+30
+00:01:56,000 --> 00:01:58,000
+But that's at a minimum that means anything higher than windows 2000.
+
+31
+00:01:58,000 --> 00:02:01,000
+So obviously we're Windows 10, which is much higher than windows 2000.
+
+32
+00:02:02,000 --> 00:02:03,000
+Uh, we're just going to enable that.
+
+33
+00:02:04,000 --> 00:02:05,000
+Now.
+
+34
+00:02:05,000 --> 00:02:07,000
+It depends on how your computer works.
+
+35
+00:02:07,000 --> 00:02:08,000
+The settings may or may not update right away.
+
+36
+00:02:08,000 --> 00:02:11,000
+You may need to restart the machine, but let's see here if it works for me.
+
+37
+00:02:11,000 --> 00:02:20,000
+And so control panel and notice boom it restricted my entire access to the control panel.
+
+38
+00:02:20,000 --> 00:02:24,000
+Turn off my mic here okay so that's it.
+
+39
+00:02:24,000 --> 00:02:25,000
+That's how you would do that.
+
+40
+00:02:25,000 --> 00:02:33,000
+Now this video for me to go through all the options in group policy in this particular thing would take
+
+41
+00:02:33,000 --> 00:02:33,000
+forever.
+
+42
+00:02:33,000 --> 00:02:38,000
+My suggestion is now that I showed you where to find it, it you should go through it and see what are
+
+43
+00:02:38,000 --> 00:02:41,000
+different options like what can you enable, what can you disable?
+
+44
+00:02:41,000 --> 00:02:46,000
+There are lots of other things I'm just going to go ahead since I my user control panel in other labs,
+
+45
+00:02:46,000 --> 00:02:51,000
+I'm going to put it not configured again that way, just re-enables it.
+
+46
+00:02:51,000 --> 00:02:53,000
+So let's see if it works.
+
+47
+00:02:55,000 --> 00:02:56,000
+Okay.
+
+48
+00:02:56,000 --> 00:02:56,000
+And there it is.
+
+49
+00:02:56,000 --> 00:03:00,000
+It starts to open back up so you guys can play around with this.
+
+50
+00:03:00,000 --> 00:03:04,000
+The whole point of this to show you that this thing is exists, that it exists here.
+
+51
+00:03:04,000 --> 00:03:06,000
+Go and look at all the options.
+
+52
+00:03:06,000 --> 00:03:10,000
+You can go ahead in here and disable like the display.
+
+53
+00:03:10,000 --> 00:03:13,000
+Like they can't click on display in Control Panel.
+
+54
+00:03:13,000 --> 00:03:14,000
+They can't.
+
+55
+00:03:14,000 --> 00:03:18,000
+You can prevent the addition and deletion of printers on a machine.
+
+56
+00:03:18,000 --> 00:03:19,000
+Notice how many options in here.
+
+57
+00:03:19,000 --> 00:03:22,000
+And I mean there is a lot of options.
+
+58
+00:03:22,000 --> 00:03:23,000
+More than I can cover.
+
+59
+00:03:23,000 --> 00:03:26,000
+In this video you have your taskbar and start menu.
+
+60
+00:03:27,000 --> 00:03:30,000
+You can do add a log off to the start menu.
+
+61
+00:03:30,000 --> 00:03:36,000
+There's lots and lots of different options here that that you can definitely use in your day to day
+
+62
+00:03:36,000 --> 00:03:36,000
+work.
+
+63
+00:03:36,000 --> 00:03:41,000
+Uh, no real books or video is going to cover every single one because as you can see, they are tons
+
+64
+00:03:41,000 --> 00:03:45,000
+and tons and tons of settings that is located here.
+
+65
+00:03:45,000 --> 00:03:48,000
+So keep that in mind that these are actually policies that you can apply.
+
+66
+00:03:50,000 --> 00:03:52,000
+Now here's what I do want to point out.
+
+67
+00:03:52,000 --> 00:03:54,000
+I just did this on a local machine.
+
+68
+00:03:54,000 --> 00:03:58,000
+If you work in a corporate, if you work in a corporate environment with a windows server and you're
+
+69
+00:03:58,000 --> 00:04:03,000
+using Active Directory in Active Directory, these policies are set at the Active Directory level or
+
+70
+00:04:03,000 --> 00:04:04,000
+at the domain level.
+
+71
+00:04:04,000 --> 00:04:10,000
+And then it pushes it down to all the workstations within the organization.
+
+72
+00:04:10,000 --> 00:04:15,000
+So you would set up things like such as organizational units, and then push the policies to put the
+
+73
+00:04:15,000 --> 00:04:20,000
+computers and the users into the correct units and then apply the policies there.
+
+74
+00:04:20,000 --> 00:04:23,000
+So keep in mind that if you're working in corporate America, you don't have to do this for every single
+
+75
+00:04:23,000 --> 00:04:24,000
+machine.
+
+76
+00:04:24,000 --> 00:04:30,000
+This task is automated across by using Active Directory across thousands of machines.
+
+77
+00:04:30,000 --> 00:04:31,000
+So keep that in mind.
+
+78
+00:04:31,000 --> 00:04:35,000
+But go ahead, have some fun doing this and don't lock yourself out.
+
+79
+00:04:36,000 --> 00:04:36,000
+Don't forget.
+
+80
+00:04:36,000 --> 00:04:38,000
+But maybe you should.
+
+81
+00:04:38,000 --> 00:04:43,000
+You want to do a snapshot of the VM before doing some of these things, in case you lock yourself out.
+
diff --git a/26 - Labs/020 Securing a wireless network_en.srt b/26 - Labs/020 Securing a wireless network_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..c266a7b42580b2f02db571d14cfe1ca0522382db
--- /dev/null
+++ b/26 - Labs/020 Securing a wireless network_en.srt
@@ -0,0 +1,560 @@
+1
+00:00:00,000 --> 00:00:06,000
+In this lab, I'm going to go through how to set up a wireless connection, basically securing a wireless
+
+2
+00:00:06,000 --> 00:00:08,000
+connection on a wireless router.
+
+3
+00:00:08,000 --> 00:00:11,000
+Now, in order to do this, we'll actually need a wireless router.
+
+4
+00:00:11,000 --> 00:00:13,000
+Now I didn't want to use my sonicwall.
+
+5
+00:00:13,000 --> 00:00:16,000
+And then you just have to watch and you can't practice.
+
+6
+00:00:16,000 --> 00:00:18,000
+So what I'm going to do is I'm going to use a demo.
+
+7
+00:00:18,000 --> 00:00:25,000
+A demo product is basically is the full operating system that you configure, like if you actually purchase
+
+8
+00:00:25,000 --> 00:00:26,000
+the device itself.
+
+9
+00:00:26,000 --> 00:00:33,000
+A lot of manufacturers such as TP-Link, Asus, Linksys, these manufacturers, you can actually go
+
+10
+00:00:33,000 --> 00:00:37,000
+and play around with their operating system and configure their devices basically in like a virtual
+
+11
+00:00:37,000 --> 00:00:38,000
+environment.
+
+12
+00:00:38,000 --> 00:00:39,000
+And that's what we're going to be doing.
+
+13
+00:00:39,000 --> 00:00:43,000
+So I'm going to show you where to find the actual images and how to actually practice this yourself
+
+14
+00:00:43,000 --> 00:00:45,000
+as you follow along with me.
+
+15
+00:00:45,000 --> 00:00:49,000
+That way, if you ever come to configure one of these wireless routers, you'll know exactly how to
+
+16
+00:00:49,000 --> 00:00:49,000
+do it.
+
+17
+00:00:50,000 --> 00:00:51,000
+So let's get started.
+
+18
+00:00:51,000 --> 00:00:53,000
+So I like to use TP-Link.
+
+19
+00:00:53,000 --> 00:00:58,000
+TP-Link is a really like I don't want to say cheap but cost effective brand in wireless routers.
+
+20
+00:00:58,000 --> 00:01:00,000
+And they're really good.
+
+21
+00:01:00,000 --> 00:01:03,000
+I use them in my house quite often and they're just fine.
+
+22
+00:01:03,000 --> 00:01:04,000
+I never had a problem with them.
+
+23
+00:01:04,000 --> 00:01:09,000
+So I want you guys to go to Google, and I want you guys to type TP-Link demo log in.
+
+24
+00:01:09,000 --> 00:01:14,000
+This is going to give me the link to where they have all their demo products.
+
+25
+00:01:14,000 --> 00:01:15,000
+So we're going to go here.
+
+26
+00:01:15,000 --> 00:01:19,000
+And the second link is actually what I want TP-Link emulators.
+
+27
+00:01:19,000 --> 00:01:23,000
+And in here you'll notice I have tons.
+
+28
+00:01:23,000 --> 00:01:30,000
+These are all the routers that they basically have all their Wi-Fi routers that they have that we can
+
+29
+00:01:30,000 --> 00:01:32,000
+actually connect to and configure.
+
+30
+00:01:32,000 --> 00:01:34,000
+Now we're going to go with one of the later models.
+
+31
+00:01:34,000 --> 00:01:35,000
+All right.
+
+32
+00:01:35,000 --> 00:01:42,000
+So any of like the ax which is going to be their later models like let's see here ax 3200.
+
+33
+00:01:42,000 --> 00:01:45,000
+You see if I just highlight that and just click Search Google for this.
+
+34
+00:01:45,000 --> 00:01:47,000
+This is a device.
+
+35
+00:01:48,000 --> 00:01:53,000
+So this device, uh, it seems to be still for sale.
+
+36
+00:01:53,000 --> 00:01:53,000
+It's still current.
+
+37
+00:01:53,000 --> 00:01:55,000
+It's about 100 bucks.
+
+38
+00:01:55,000 --> 00:01:57,000
+This is what the device looks like.
+
+39
+00:01:57,000 --> 00:02:02,000
+And we're basically going to be able to log into it and configure some of its Wi-Fi things on it.
+
+40
+00:02:02,000 --> 00:02:05,000
+So I'm going to click on Ax 3200.
+
+41
+00:02:06,000 --> 00:02:07,000
+And we're just going to use this firmware.
+
+42
+00:02:07,000 --> 00:02:08,000
+It doesn't matter what it is.
+
+43
+00:02:08,000 --> 00:02:09,000
+They all look alike.
+
+44
+00:02:11,000 --> 00:02:12,000
+All right, this is it.
+
+45
+00:02:12,000 --> 00:02:15,000
+I'm actually logged into it right now.
+
+46
+00:02:15,000 --> 00:02:19,000
+This is what it's going to look like when you actually go out and configure the device.
+
+47
+00:02:19,000 --> 00:02:24,000
+Now, what we want to do is I want to go through some of the wireless settings that you need to know
+
+48
+00:02:24,000 --> 00:02:27,000
+when you configure a good secure wireless.
+
+49
+00:02:27,000 --> 00:02:28,000
+So we're going to go to wireless.
+
+50
+00:02:29,000 --> 00:02:33,000
+And you notice it gives you a little bit of configuration.
+
+51
+00:02:34,000 --> 00:02:36,000
+Security protocol and so on.
+
+52
+00:02:36,000 --> 00:02:38,000
+But I don't want just this.
+
+53
+00:02:38,000 --> 00:02:40,000
+I want to use the advanced settings on it.
+
+54
+00:02:40,000 --> 00:02:44,000
+This is going to be like what the normal Non-secure non-security folks use.
+
+55
+00:02:44,000 --> 00:02:46,000
+So we're going to go to advanced.
+
+56
+00:02:46,000 --> 00:02:49,000
+And now we have tons of options.
+
+57
+00:02:49,000 --> 00:02:49,000
+That is here.
+
+58
+00:02:49,000 --> 00:02:52,000
+But in this lab we're concentrating on wireless.
+
+59
+00:02:53,000 --> 00:02:55,000
+Okay, here we go.
+
+60
+00:02:55,000 --> 00:02:56,000
+And we're going to go to wireless.
+
+61
+00:02:58,000 --> 00:03:01,000
+Now in here, you got a little bit more option.
+
+62
+00:03:02,000 --> 00:03:05,000
+You have a variety of different channels that we can use.
+
+63
+00:03:05,000 --> 00:03:12,000
+So let's say you're configuring your two your 2.4GHz channel and then your 2.4GHz channel.
+
+64
+00:03:12,000 --> 00:03:13,000
+You would give it a name.
+
+65
+00:03:13,000 --> 00:03:15,000
+Now I'm not going to change any of the settings here.
+
+66
+00:03:15,000 --> 00:03:16,000
+But you would give this the name.
+
+67
+00:03:16,000 --> 00:03:18,000
+So this would be like the name of your network.
+
+68
+00:03:18,000 --> 00:03:21,000
+So the Ssid represents the name of your network.
+
+69
+00:03:21,000 --> 00:03:26,000
+Some people hide it, but if you hide the Ssid, people would then have to know the name of the network
+
+70
+00:03:26,000 --> 00:03:27,000
+to actually connect to it.
+
+71
+00:03:27,000 --> 00:03:29,000
+What type of security would you use?
+
+72
+00:03:29,000 --> 00:03:35,000
+Notice by default it wants to use WPA two, but WPA three is more secure.
+
+73
+00:03:35,000 --> 00:03:39,000
+So in and in this particular course we talked about WPA three.
+
+74
+00:03:39,000 --> 00:03:45,000
+So we're going to go to Wpa3 the version we want to use WPA three safer.
+
+75
+00:03:45,000 --> 00:03:47,000
+See what is the password.
+
+76
+00:03:47,000 --> 00:03:50,000
+Now I'm not going to change any of the configuration here.
+
+77
+00:03:50,000 --> 00:03:52,000
+But you want to make sure you give this a nice.
+
+78
+00:03:52,000 --> 00:03:55,000
+Complex password.
+
+79
+00:03:55,000 --> 00:03:56,000
+Why is that?
+
+80
+00:03:56,000 --> 00:03:56,000
+Because.
+
+81
+00:03:56,000 --> 00:03:57,000
+Remember something.
+
+82
+00:03:58,000 --> 00:04:00,000
+You can have the greatest encryption in the world.
+
+83
+00:04:00,000 --> 00:04:04,000
+Wpa3 is the latest encryption that we can use.
+
+84
+00:04:04,000 --> 00:04:05,000
+But you've got to remember something.
+
+85
+00:04:05,000 --> 00:04:09,000
+Wpa3 is as secure as the password that you do.
+
+86
+00:04:09,000 --> 00:04:14,000
+If you have a Wi-Fi and your password is password, it's probably not.
+
+87
+00:04:14,000 --> 00:04:18,000
+It's probably not going to be the most secure thing that people can easily guess it and hack it.
+
+88
+00:04:18,000 --> 00:04:19,000
+So you don't want that.
+
+89
+00:04:19,000 --> 00:04:22,000
+Now, generally everything else you're probably going to leave the same.
+
+90
+00:04:22,000 --> 00:04:24,000
+And then what type of mode do you want?
+
+91
+00:04:24,000 --> 00:04:26,000
+Right now it's configured to support.
+
+92
+00:04:28,000 --> 00:04:35,000
+Uh, g n and ax if you just want g and N, or if you just want only ax, because that's what you want.
+
+93
+00:04:35,000 --> 00:04:37,000
+Everything to connect and high speeds, you could do that.
+
+94
+00:04:37,000 --> 00:04:40,000
+This one allows us to also have a five gigahertz spectrum.
+
+95
+00:04:40,000 --> 00:04:42,000
+So if you want you can enable and disable that.
+
+96
+00:04:42,000 --> 00:04:44,000
+And then you would configure it basically the same way.
+
+97
+00:04:44,000 --> 00:04:48,000
+There's also a second five gigahertz spectrum just to remember how many antennas this thing had.
+
+98
+00:04:48,000 --> 00:04:51,000
+If you remember the picture um, in here.
+
+99
+00:04:51,000 --> 00:04:56,000
+Now, the other thing I want to point out when you configure wireless, when when you configure wireless
+
+100
+00:04:56,000 --> 00:05:03,000
+is sometimes in organizations, when you have guests, people coming in, people that is just joining
+
+101
+00:05:03,000 --> 00:05:07,000
+your network, think of like a doctor's office where all the equipment is connected over Wi-Fi.
+
+102
+00:05:07,000 --> 00:05:13,000
+But then sometimes you have patients coming in and you don't want them on the same network as all your
+
+103
+00:05:13,000 --> 00:05:16,000
+your medical equipment on and all your medical workstations on.
+
+104
+00:05:16,000 --> 00:05:16,000
+Right?
+
+105
+00:05:16,000 --> 00:05:17,000
+So you want to give them a guest network.
+
+106
+00:05:17,000 --> 00:05:20,000
+So not all wireless router but this one does.
+
+107
+00:05:20,000 --> 00:05:22,000
+It supports guest network.
+
+108
+00:05:22,000 --> 00:05:23,000
+So let's see what that is.
+
+109
+00:05:23,000 --> 00:05:31,000
+So if I go here you can actually set up let's say you want to do a 2.4GHz guest network.
+
+110
+00:05:31,000 --> 00:05:34,000
+So you would then just put in TP-Link.
+
+111
+00:05:34,000 --> 00:05:36,000
+Guess um.
+
+112
+00:05:36,000 --> 00:05:39,000
+And it doesn't have much options.
+
+113
+00:05:39,000 --> 00:05:39,000
+All right.
+
+114
+00:05:39,000 --> 00:05:42,000
+So you would maybe call it your company's name guest network.
+
+115
+00:05:43,000 --> 00:05:45,000
+You can hide this notice by default it's hidden.
+
+116
+00:05:45,000 --> 00:05:48,000
+If not you can just un just uncheck the box and not hide it.
+
+117
+00:05:48,000 --> 00:05:52,000
+And then what type of security would you want Wpa2 wpa3.
+
+118
+00:05:52,000 --> 00:05:53,000
+And then you can put a password on it.
+
+119
+00:05:53,000 --> 00:06:00,000
+So this is a great option to do when configuring wireless network okay.
+
+120
+00:06:00,000 --> 00:06:02,000
+By the way when you're done here you would just save this.
+
+121
+00:06:02,000 --> 00:06:03,000
+But this is an emulator.
+
+122
+00:06:03,000 --> 00:06:06,000
+It doesn't matter whether it's not really going to do anything.
+
+123
+00:06:07,000 --> 00:06:08,000
+And then when you're done, you just close it out.
+
+124
+00:06:09,000 --> 00:06:14,000
+By the way, you can actually, uh, before I leave this, you can actually go in there and type in
+
+125
+00:06:14,000 --> 00:06:22,000
+lynxes, lions, lynxes live demo and you can do demo emulators of lynxes.
+
+126
+00:06:24,000 --> 00:06:28,000
+Uh lynxes is another router manufacturers if you want to connect to like a Lynx router, notice they
+
+127
+00:06:28,000 --> 00:06:31,000
+have all of their even their Ax 900.
+
+128
+00:06:31,000 --> 00:06:34,000
+So you can connect to this and configure these routers.
+
+129
+00:06:35,000 --> 00:06:35,000
+All right.
+
+130
+00:06:35,000 --> 00:06:37,000
+We're going to enable cookies here to make all this work.
+
+131
+00:06:38,000 --> 00:06:42,000
+So tons of things here that we can go and also need cookies.
+
+132
+00:06:42,000 --> 00:06:42,000
+Okay.
+
+133
+00:06:42,000 --> 00:06:44,000
+So you can see you can configure this one on here.
+
+134
+00:06:45,000 --> 00:06:46,000
+Tons of these things.
+
+135
+00:06:46,000 --> 00:06:50,000
+You can do this with Sonicwall also uh you can do this with Linksys.
+
+136
+00:06:50,000 --> 00:06:52,000
+You can do this with Asus.
+
+137
+00:06:52,000 --> 00:06:58,000
+You guys should be playing around with this and trying out different emulators that you can play around
+
+138
+00:06:58,000 --> 00:06:58,000
+with.
+
+139
+00:06:58,000 --> 00:07:03,000
+That way if you ever play, if you ever go into the work environment and you see these wireless devices,
+
+140
+00:07:03,000 --> 00:07:05,000
+you'll know how to configure them.
+
diff --git a/26 - Labs/021 Using Encrypting File System_en.srt b/26 - Labs/021 Using Encrypting File System_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..58c148e1d5fffd837f6c426e1cf503f1b82fc03c
--- /dev/null
+++ b/26 - Labs/021 Using Encrypting File System_en.srt
@@ -0,0 +1,368 @@
+1
+00:00:00,000 --> 00:00:03,000
+When it comes to security, nothing beats good encryption.
+
+2
+00:00:03,000 --> 00:00:08,000
+In a previous lab, I showed you guys how to encrypt the entire hard drive using things like BitLocker
+
+3
+00:00:08,000 --> 00:00:09,000
+encryption.
+
+4
+00:00:09,000 --> 00:00:13,000
+In this lab, I'm going to show you maybe you just want to encrypt one folder that contains a bunch
+
+5
+00:00:13,000 --> 00:00:15,000
+of files that is really secure to you.
+
+6
+00:00:15,000 --> 00:00:19,000
+That way, if anybody ever takes the hard drive out and doesn't know your username and password and
+
+7
+00:00:19,000 --> 00:00:23,000
+tries to access the data on the hard drive, they're not going to be able to access the contents of
+
+8
+00:00:23,000 --> 00:00:25,000
+that particular folder.
+
+9
+00:00:25,000 --> 00:00:30,000
+What we're going to be using is called encrypted file systems, or EFS that's built into windows.
+
+10
+00:00:30,000 --> 00:00:34,000
+Now in order to do this, you have to make sure that the drive you're using, whether to USB drive or
+
+11
+00:00:34,000 --> 00:00:38,000
+the hard drive on the machine, you have to make sure that it's formatted for windows NTFS.
+
+12
+00:00:38,000 --> 00:00:43,000
+So we're going to check to make sure we have NTFS formatted, which 99.9% of the time generally is going
+
+13
+00:00:43,000 --> 00:00:45,000
+to be, but especially on memory sticks.
+
+14
+00:00:45,000 --> 00:00:47,000
+You can actually do this with a USB drive.
+
+15
+00:00:47,000 --> 00:00:49,000
+You can encrypt data on a USB stick.
+
+16
+00:00:49,000 --> 00:00:53,000
+You just got to make sure the USB stick is formatted as NTFS.
+
+17
+00:00:54,000 --> 00:00:55,000
+So keep in mind, why are we doing this?
+
+18
+00:00:56,000 --> 00:00:57,000
+The scenario says this.
+
+19
+00:00:57,000 --> 00:01:05,000
+Let's say you're walking around with your laptop and you don't have, uh, BitLocker disk based encryption
+
+20
+00:01:05,000 --> 00:01:09,000
+enabled, but you have a few folders on that laptop that contain sensitive data.
+
+21
+00:01:09,000 --> 00:01:14,000
+Maybe you got some sensitive documents, company secrets, and so on in that folder.
+
+22
+00:01:14,000 --> 00:01:18,000
+Keep in mind that if you ever lose your laptop and people just want the data, they just have to.
+
+23
+00:01:18,000 --> 00:01:20,000
+They don't need to know your windows password.
+
+24
+00:01:20,000 --> 00:01:24,000
+They just got to take the hard drive out and mounted on a machine and just open up the drive and they'll
+
+25
+00:01:24,000 --> 00:01:26,000
+see all your data on the hard drive.
+
+26
+00:01:27,000 --> 00:01:31,000
+But if you encrypted it, it's basically encrypted with your password.
+
+27
+00:01:31,000 --> 00:01:36,000
+So unless they have your password and they can log into the machine with your password, they cannot
+
+28
+00:01:36,000 --> 00:01:37,000
+see the data.
+
+29
+00:01:37,000 --> 00:01:39,000
+So let's go see how to do it.
+
+30
+00:01:40,000 --> 00:01:45,000
+Now to do this, the first thing I want to do is I want to make sure that we run in NTFS.
+
+31
+00:01:45,000 --> 00:01:46,000
+Now here's the thing.
+
+32
+00:01:46,000 --> 00:01:49,000
+99% of the time you're probably going to run this.
+
+33
+00:01:49,000 --> 00:01:54,000
+I'm showing this to you just in case you're trying to encrypt data on a USB stick that you have to make
+
+34
+00:01:54,000 --> 00:01:56,000
+sure your format is NTFS.
+
+35
+00:01:56,000 --> 00:01:57,000
+So let's do window E.
+
+36
+00:01:58,000 --> 00:01:58,000
+All right.
+
+37
+00:01:58,000 --> 00:02:01,000
+Let's go to the desktop to window E so we can open up the explorer.
+
+38
+00:02:01,000 --> 00:02:03,000
+We're going to go to this PC.
+
+39
+00:02:04,000 --> 00:02:06,000
+And we're just going to be using the C drive here.
+
+40
+00:02:06,000 --> 00:02:10,000
+Now if it was a USB stick you would just right click on it and go to properties.
+
+41
+00:02:10,000 --> 00:02:13,000
+And you want to make sure that your format is NTFS.
+
+42
+00:02:13,000 --> 00:02:19,000
+Um, if not, if the USB stick is not, just go to format, right click on it format.
+
+43
+00:02:19,000 --> 00:02:23,000
+And it doesn't want me to do this because it's going to actually format and wipe out the drive.
+
+44
+00:02:23,000 --> 00:02:27,000
+And then you would select NTFS as the format type that you want.
+
+45
+00:02:28,000 --> 00:02:34,000
+Keep in mind, if you format something as NTFS, it's probably not going to work on, uh, it wouldn't
+
+46
+00:02:34,000 --> 00:02:35,000
+be able to work on a mac.
+
+47
+00:02:35,000 --> 00:02:38,000
+It's basically only for windows, so keep that in mind.
+
+48
+00:02:39,000 --> 00:02:41,000
+Okay, so we got NTFS.
+
+49
+00:02:41,000 --> 00:02:43,000
+Let's say you have a folder on your desktop.
+
+50
+00:02:43,000 --> 00:02:45,000
+With all your private stuff.
+
+51
+00:02:47,000 --> 00:02:49,000
+Private stuff, we call it.
+
+52
+00:02:49,000 --> 00:02:54,000
+So within this folder, maybe you have some, uh, documents.
+
+53
+00:02:55,000 --> 00:02:57,000
+All right, let's copy paste this a few times.
+
+54
+00:02:57,000 --> 00:02:57,000
+All right.
+
+55
+00:02:57,000 --> 00:02:59,000
+We got a three documents in there.
+
+56
+00:02:59,000 --> 00:03:01,000
+And now I want to encrypt it.
+
+57
+00:03:01,000 --> 00:03:02,000
+So how do I do that.
+
+58
+00:03:02,000 --> 00:03:03,000
+Well it's pretty simple.
+
+59
+00:03:03,000 --> 00:03:05,000
+You would just right click on it.
+
+60
+00:03:05,000 --> 00:03:06,000
+You're going to go to properties.
+
+61
+00:03:07,000 --> 00:03:09,000
+And you're just going to go to advance.
+
+62
+00:03:09,000 --> 00:03:12,000
+And it's as easy as just clicking on this box.
+
+63
+00:03:12,000 --> 00:03:12,000
+Look.
+
+64
+00:03:13,000 --> 00:03:16,000
+Encrypt data, encrypt contents to secure data.
+
+65
+00:03:16,000 --> 00:03:17,000
+That's it.
+
+66
+00:03:17,000 --> 00:03:18,000
+That's all you're doing.
+
+67
+00:03:19,000 --> 00:03:20,000
+Just apply that.
+
+68
+00:03:20,000 --> 00:03:20,000
+Okay.
+
+69
+00:03:20,000 --> 00:03:22,000
+You want to apply this changes to this folder.
+
+70
+00:03:22,000 --> 00:03:23,000
+So on all the files.
+
+71
+00:03:23,000 --> 00:03:24,000
+Yes.
+
+72
+00:03:25,000 --> 00:03:25,000
+That's it.
+
+73
+00:03:26,000 --> 00:03:31,000
+Notice it's making a little backup of my encryption key for the notices efs UI application.
+
+74
+00:03:32,000 --> 00:03:36,000
+Uh, basically what it's doing is just backing up the encryption key there and that's it.
+
+75
+00:03:36,000 --> 00:03:39,000
+Now you can see that it has a little lock on it and it's secure.
+
+76
+00:03:39,000 --> 00:03:41,000
+Now I can open it.
+
+77
+00:03:41,000 --> 00:03:43,000
+I can add things to it.
+
+78
+00:03:43,000 --> 00:03:43,000
+Um.
+
+79
+00:03:46,000 --> 00:03:46,000
+See.
+
+80
+00:03:48,000 --> 00:03:51,000
+I can do whatever I want with this because I am the user.
+
+81
+00:03:51,000 --> 00:03:57,000
+Now, if I lose, let's say this was a physical machine and I lose this computer and somebody takes
+
+82
+00:03:57,000 --> 00:04:00,000
+the hard drive out, they'll be able to see my desktop.
+
+83
+00:04:00,000 --> 00:04:04,000
+They're going to log in and see my desktop, not log in, but they'll they'll be able to get to the
+
+84
+00:04:04,000 --> 00:04:06,000
+desktop folder that we're looking at here.
+
+85
+00:04:07,000 --> 00:04:08,000
+And they're going to see private stuff.
+
+86
+00:04:08,000 --> 00:04:11,000
+And when they double click on it it accesses going to be denied.
+
+87
+00:04:11,000 --> 00:04:13,000
+They're not going to be able to see anything on there.
+
+88
+00:04:13,000 --> 00:04:18,000
+They would actually have to log in as me on the laptop, and they would need to know my password to
+
+89
+00:04:18,000 --> 00:04:20,000
+access all of this private stuff.
+
+90
+00:04:21,000 --> 00:04:28,000
+So this is a great alternative to the to the BitLocker encryption, right?
+
+91
+00:04:28,000 --> 00:04:33,000
+Because in this one, instead of encrypting the entire drive, you just encrypt the folder or the files
+
+92
+00:04:33,000 --> 00:04:34,000
+that you need to be encrypted.
+
diff --git a/26 - Labs/022 Backing up router configuration_en.srt b/26 - Labs/022 Backing up router configuration_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..0ec1d1fa196a22f9e014d7c33b3b390de01bb737
--- /dev/null
+++ b/26 - Labs/022 Backing up router configuration_en.srt
@@ -0,0 +1,264 @@
+1
+00:00:00,000 --> 00:00:05,000
+In this video, I'm going to show you how to back up the configurations and restore the configurations
+
+2
+00:00:05,000 --> 00:00:07,000
+on a router.
+
+3
+00:00:07,000 --> 00:00:10,000
+And you could basically do these with switches also.
+
+4
+00:00:10,000 --> 00:00:14,000
+So in a network today, you're guaranteed to manage some kind of network device.
+
+5
+00:00:14,000 --> 00:00:16,000
+No network works without switches and routers.
+
+6
+00:00:16,000 --> 00:00:17,000
+Without switches and routers.
+
+7
+00:00:17,000 --> 00:00:21,000
+You ain't got no connection and you ain't got no internet.
+
+8
+00:00:21,000 --> 00:00:26,000
+So you got to make sure you have this done right now, when you manage these devices, one of the things
+
+9
+00:00:26,000 --> 00:00:31,000
+you should do when you finish configuring them is back up your configuration by backing up your configuration.
+
+10
+00:00:31,000 --> 00:00:36,000
+If the device ever fails, you can just restart, restart the device, maybe get a brand new device,
+
+11
+00:00:36,000 --> 00:00:41,000
+fix the problem, do a hardware reset in which case it wipes all the configs out and then you could
+
+12
+00:00:41,000 --> 00:00:43,000
+just restore the configuration.
+
+13
+00:00:43,000 --> 00:00:44,000
+It's a quick and easy lab.
+
+14
+00:00:44,000 --> 00:00:47,000
+Let's do it now I will be using the Linksys emulator.
+
+15
+00:00:47,000 --> 00:00:50,000
+This assumes that we're using a Linksys device.
+
+16
+00:00:51,000 --> 00:00:52,000
+All devices.
+
+17
+00:00:52,000 --> 00:00:57,000
+All network devices will support the ability to back up and restore its configuration.
+
+18
+00:00:57,000 --> 00:00:59,000
+These steps are going to be different.
+
+19
+00:00:59,000 --> 00:01:00,000
+So in this one we're using Linksys.
+
+20
+00:01:00,000 --> 00:01:04,000
+So keep in mind the principle is going to be the same on all devices.
+
+21
+00:01:04,000 --> 00:01:08,000
+Is this that the actual steps of doing them is going to be different because every device is configured
+
+22
+00:01:08,000 --> 00:01:09,000
+basically differently.
+
+23
+00:01:09,000 --> 00:01:11,000
+So let's see how to do it.
+
+24
+00:01:12,000 --> 00:01:15,000
+So let's go here to Linksys.
+
+25
+00:01:15,000 --> 00:01:19,000
+Uh just go to Google type Linksys live demo.
+
+26
+00:01:19,000 --> 00:01:22,000
+And the first option says Linksys Simulator.
+
+27
+00:01:24,000 --> 00:01:27,000
+And I'm just going to go to the bottom here.
+
+28
+00:01:28,000 --> 00:01:30,000
+How much do the x 6200.
+
+29
+00:01:30,000 --> 00:01:32,000
+You could use any of these as long as they load up.
+
+30
+00:01:32,000 --> 00:01:35,000
+They all all the interfaces on these devices basically looks the same.
+
+31
+00:01:36,000 --> 00:01:39,000
+And I will do the version 1.0 here.
+
+32
+00:01:39,000 --> 00:01:40,000
+And um.
+
+33
+00:01:41,000 --> 00:01:42,000
+Here we go.
+
+34
+00:01:42,000 --> 00:01:43,000
+So we just logged into it.
+
+35
+00:01:43,000 --> 00:01:48,000
+So what you would do is that you would configure the device as needed.
+
+36
+00:01:48,000 --> 00:01:51,000
+You would configure its wireless, right.
+
+37
+00:01:51,000 --> 00:01:55,000
+You would configure its how how you want the wireless to be configured.
+
+38
+00:01:55,000 --> 00:02:00,000
+You would configure it, maybe you would open specific ports and all that interesting stuff.
+
+39
+00:02:01,000 --> 00:02:02,000
+Um, here we go.
+
+40
+00:02:02,000 --> 00:02:06,000
+Open ports here with these, uh, application and gaming settings on it.
+
+41
+00:02:06,000 --> 00:02:12,000
+Basically do all your configuration on the device and when you're done you would go to administration.
+
+42
+00:02:13,000 --> 00:02:19,000
+And you notice at the bottom there is an option that says backup and restore.
+
+43
+00:02:19,000 --> 00:02:22,000
+So you would say backup configuration.
+
+44
+00:02:22,000 --> 00:02:24,000
+And what it's going to do now.
+
+45
+00:02:24,000 --> 00:02:27,000
+This is a demo, so it's not going to work.
+
+46
+00:02:27,000 --> 00:02:33,000
+Basically it takes you to a config file that you can save or it just tells you to save it and what you
+
+47
+00:02:33,000 --> 00:02:33,000
+should be doing.
+
+48
+00:02:33,000 --> 00:02:35,000
+Now again, this is a demo.
+
+49
+00:02:35,000 --> 00:02:36,000
+It's not going to work because it's not real.
+
+50
+00:02:37,000 --> 00:02:39,000
+Um, and what you would do is you would save that configuration.
+
+51
+00:02:39,000 --> 00:02:41,000
+Generally you should save it with the name.
+
+52
+00:02:41,000 --> 00:02:44,000
+Like right now is December 2023.
+
+53
+00:02:44,000 --> 00:02:46,000
+You should save it as December 2023.
+
+54
+00:02:48,000 --> 00:02:52,000
+And when you, let's say the device breaks, let's say you got to restore that device.
+
+55
+00:02:52,000 --> 00:02:57,000
+So you would log into the device and you would say restore configuration.
+
+56
+00:02:57,000 --> 00:03:02,000
+And then you would select choose the file that, that configuration file that we, that we said that
+
+57
+00:03:02,000 --> 00:03:04,000
+it was actually going to save it.
+
+58
+00:03:04,000 --> 00:03:10,000
+And you would just click okay and you would click restore and it would actually restore that configuration.
+
+59
+00:03:11,000 --> 00:03:17,000
+So this is something that you guys should be doing on all your devices.
+
+60
+00:03:17,000 --> 00:03:21,000
+If you're sitting at home right now and you have a wireless router that you configured your wireless
+
+61
+00:03:21,000 --> 00:03:24,000
+and it's all good and everything is working well, go right now and do this.
+
+62
+00:03:24,000 --> 00:03:25,000
+Back up your configuration.
+
+63
+00:03:25,000 --> 00:03:27,000
+Just save it just in case something goes wrong.
+
+64
+00:03:27,000 --> 00:03:31,000
+Your your wireless router gets rebooted or something and you lose your configuration.
+
+65
+00:03:31,000 --> 00:03:36,000
+If you do this you can just go back, restore it within minutes or seconds.
+
+66
+00:03:36,000 --> 00:03:39,000
+Your wireless device is back functioning.
+
diff --git a/26 - Labs/023 Updating firmware on a router_en.srt b/26 - Labs/023 Updating firmware on a router_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..adda4cd2158c980723ad3111610f5ab2ae4ce6e3
--- /dev/null
+++ b/26 - Labs/023 Updating firmware on a router_en.srt
@@ -0,0 +1,464 @@
+1
+00:00:00,000 --> 00:00:01,000
+In this lab.
+
+2
+00:00:01,000 --> 00:00:06,000
+I'm going to show you how to upgrade the firmware on a router, something like a wireless router.
+
+3
+00:00:06,000 --> 00:00:11,000
+It is really important that you update the firmware, just as we do when we update windows with Windows
+
+4
+00:00:11,000 --> 00:00:19,000
+Update routers, things like your wireless router, your actual Cisco router, your switches, your
+
+5
+00:00:19,000 --> 00:00:20,000
+access points.
+
+6
+00:00:20,000 --> 00:00:24,000
+They also need updates, but they generally don't pull the updates as frequently as windows does.
+
+7
+00:00:24,000 --> 00:00:28,000
+We as administrators have to go and update them.
+
+8
+00:00:28,000 --> 00:00:30,000
+So in this video I'm going to use an emulator.
+
+9
+00:00:30,000 --> 00:00:33,000
+We're going to use one of these Linksys devices.
+
+10
+00:00:33,000 --> 00:00:37,000
+And I'll show you how to get the firmware update and how to actually update the device.
+
+11
+00:00:37,000 --> 00:00:40,000
+Now I'm going to be using this on a Linksys device.
+
+12
+00:00:40,000 --> 00:00:43,000
+Keep in mind this procedure is going to be different.
+
+13
+00:00:43,000 --> 00:00:47,000
+The actual step by step procedure is going to be different for every device you use, but the basic
+
+14
+00:00:47,000 --> 00:00:48,000
+principle stays the same.
+
+15
+00:00:48,000 --> 00:00:53,000
+Log into it, get the firmware from the manufacturer and just upload it into the device.
+
+16
+00:00:53,000 --> 00:00:54,000
+Let's see how to do it.
+
+17
+00:00:55,000 --> 00:01:03,000
+So I am going to just to show you guys how I got here, I'm going to do Lynxs live demo because that's
+
+18
+00:01:03,000 --> 00:01:04,000
+the router I'm going to be using here.
+
+19
+00:01:04,000 --> 00:01:07,000
+So you guys could do this so you could follow along with me.
+
+20
+00:01:07,000 --> 00:01:09,000
+And we're going to go right here to Lynx Emulator.
+
+21
+00:01:09,000 --> 00:01:12,000
+And I want to use one of their latest devices at the top.
+
+22
+00:01:12,000 --> 00:01:14,000
+You're probably gonna have more of these like older devices.
+
+23
+00:01:15,000 --> 00:01:18,000
+Um and I'm going to go down here.
+
+24
+00:01:18,000 --> 00:01:21,000
+Here we go with X 6200 wireless router.
+
+25
+00:01:21,000 --> 00:01:22,000
+That's fine for now.
+
+26
+00:01:22,000 --> 00:01:23,000
+And you could use any one of these here.
+
+27
+00:01:23,000 --> 00:01:26,000
+Anything that basically is going to load up.
+
+28
+00:01:26,000 --> 00:01:27,000
+So I'm gonna use this one.
+
+29
+00:01:28,000 --> 00:01:31,000
+Now, these do come with the latest firmware on here.
+
+30
+00:01:31,000 --> 00:01:32,000
+So we're not actually going to update it.
+
+31
+00:01:32,000 --> 00:01:35,000
+But I'll walk you through the steps because these are demos.
+
+32
+00:01:35,000 --> 00:01:37,000
+We really can't update them because they're pretty much updated already.
+
+33
+00:01:37,000 --> 00:01:39,000
+So we're going to go just to the version.
+
+34
+00:01:39,000 --> 00:01:42,000
+This is going to be the the interface I'm using.
+
+35
+00:01:43,000 --> 00:01:44,000
+So now I'm logged into this device.
+
+36
+00:01:44,000 --> 00:01:51,000
+So if you ever purchased this device the X 6200 uh Linksys device.
+
+37
+00:01:52,000 --> 00:01:52,000
+Uh.
+
+38
+00:01:55,000 --> 00:02:00,000
+If you ever purchased this device, this particular device here, um.
+
+39
+00:02:01,000 --> 00:02:02,000
+When you buy this, you get it.
+
+40
+00:02:02,000 --> 00:02:07,000
+You would need to update the firmware on it because I'm pretty sure it's not going to come updated.
+
+41
+00:02:07,000 --> 00:02:08,000
+So with the latest firmware.
+
+42
+00:02:09,000 --> 00:02:11,000
+Okay, so.
+
+43
+00:02:11,000 --> 00:02:12,000
+That's.
+
+44
+00:02:12,000 --> 00:02:14,000
+I just wanted to show you the picture.
+
+45
+00:02:14,000 --> 00:02:15,000
+The device we're using.
+
+46
+00:02:15,000 --> 00:02:20,000
+Okay, so what we're going to do here in every device, you're going to want to go to administration,
+
+47
+00:02:20,000 --> 00:02:21,000
+this tab.
+
+48
+00:02:21,000 --> 00:02:22,000
+Let's make this bigger.
+
+49
+00:02:23,000 --> 00:02:24,000
+Administration.
+
+50
+00:02:25,000 --> 00:02:29,000
+And you'll notice that if I come down here, you have a few things.
+
+51
+00:02:30,000 --> 00:02:31,000
+Um, where is it?
+
+52
+00:02:31,000 --> 00:02:31,000
+Okay, here we go.
+
+53
+00:02:31,000 --> 00:02:33,000
+Firmware upgrade.
+
+54
+00:02:33,000 --> 00:02:34,000
+So you have to look around for it.
+
+55
+00:02:34,000 --> 00:02:36,000
+So I thought it was going to be somewhere here, but it's not.
+
+56
+00:02:36,000 --> 00:02:39,000
+It's actually at the top firmware upgrade.
+
+57
+00:02:39,000 --> 00:02:40,000
+So we're going to go here.
+
+58
+00:02:40,000 --> 00:02:47,000
+Now the most important thing about a firmware update is to make sure you get the firmware from the right
+
+59
+00:02:47,000 --> 00:02:48,000
+place.
+
+60
+00:02:48,000 --> 00:02:55,000
+Way too often this hackers create fake firmware or firmware that contains vulnerabilities that allows
+
+61
+00:02:55,000 --> 00:02:59,000
+them to log in and control your device, so you want to make sure you get the firmware from the right
+
+62
+00:02:59,000 --> 00:02:59,000
+place.
+
+63
+00:02:59,000 --> 00:03:03,000
+So let's go to Linksys and actually get the right firmware from Linksys.
+
+64
+00:03:04,000 --> 00:03:09,000
+So we're going to do Linux.com I'm all right.
+
+65
+00:03:09,000 --> 00:03:10,000
+I'm not going to click on any link.
+
+66
+00:03:10,000 --> 00:03:13,000
+I just I'm just going to go to it myself.
+
+67
+00:03:13,000 --> 00:03:17,000
+Uh linksys.com.
+
+68
+00:03:18,000 --> 00:03:23,000
+And you're always going to find the firmware like in the support section of their website.
+
+69
+00:03:23,000 --> 00:03:24,000
+What device are we looking for?
+
+70
+00:03:24,000 --> 00:03:28,000
+Well, we were playing around with X 6200.
+
+71
+00:03:29,000 --> 00:03:31,000
+Search for that okay.
+
+72
+00:03:31,000 --> 00:03:33,000
+So they do have the X 6200.
+
+73
+00:03:33,000 --> 00:03:35,000
+We want to go to downloads.
+
+74
+00:03:37,000 --> 00:03:39,000
+And select the hardware version.
+
+75
+00:03:39,000 --> 00:03:40,000
+So here they are.
+
+76
+00:03:40,000 --> 00:03:41,000
+They have a firmware.
+
+77
+00:03:41,000 --> 00:03:45,000
+Now this is a I told you that we logged into version 1.0 because that's all they have.
+
+78
+00:03:45,000 --> 00:03:47,000
+And I told you it's already updated to that.
+
+79
+00:03:47,000 --> 00:03:49,000
+But anyways we'll walk through the steps.
+
+80
+00:03:49,000 --> 00:03:50,000
+So we're going to say download.
+
+81
+00:03:51,000 --> 00:03:52,000
+And you notice it's just done.
+
+82
+00:03:52,000 --> 00:03:54,000
+I did it earlier.
+
+83
+00:03:54,000 --> 00:03:56,000
+I just wanted to make sure to check it, make sure it work before we do the video.
+
+84
+00:03:56,000 --> 00:03:57,000
+So here it is.
+
+85
+00:03:57,000 --> 00:03:58,000
+This is the firmware.
+
+86
+00:03:58,000 --> 00:04:02,000
+Now once again, it's super important to get the firmware from the correct place.
+
+87
+00:04:02,000 --> 00:04:06,000
+Don't get the firmware anywhere else but the manufacturer.
+
+88
+00:04:06,000 --> 00:04:11,000
+So I'm going to now go back to this tab here and we got to choose the firmware.
+
+89
+00:04:11,000 --> 00:04:13,000
+So notice choose file.
+
+90
+00:04:13,000 --> 00:04:15,000
+So we say choose file and our downloads folder.
+
+91
+00:04:15,000 --> 00:04:17,000
+Here's the file I just downloaded.
+
+92
+00:04:17,000 --> 00:04:18,000
+And we're just going to say start upgrade.
+
+93
+00:04:18,000 --> 00:04:22,000
+Now you got to keep in mind that when you do this it's going to disconnect everything.
+
+94
+00:04:23,000 --> 00:04:24,000
+It's going to disconnect everybody.
+
+95
+00:04:24,000 --> 00:04:28,000
+The whole network will go down because this device is being updated.
+
+96
+00:04:29,000 --> 00:04:30,000
+Okay.
+
+97
+00:04:30,000 --> 00:04:32,000
+So make sure you do this.
+
+98
+00:04:32,000 --> 00:04:35,000
+And sometimes it may wipe out the configuration.
+
+99
+00:04:35,000 --> 00:04:40,000
+So make sure when you're doing this you back up the router's configuration and then restore it.
+
+100
+00:04:40,000 --> 00:04:41,000
+All right.
+
+101
+00:04:41,000 --> 00:04:42,000
+So just restarted itself.
+
+102
+00:04:43,000 --> 00:04:43,000
+All right.
+
+103
+00:04:43,000 --> 00:04:44,000
+Make sure you do that.
+
+104
+00:04:44,000 --> 00:04:48,000
+So you back up the configuration before doing the firmware update.
+
+105
+00:04:48,000 --> 00:04:49,000
+All right.
+
+106
+00:04:49,000 --> 00:04:50,000
+So we did that lab earlier.
+
+107
+00:04:50,000 --> 00:04:53,000
+But backing up and restoring configurations on on wireless routers.
+
+108
+00:04:53,000 --> 00:04:56,000
+Just do that before you do this on your actual device.
+
+109
+00:04:56,000 --> 00:04:58,000
+How often should you do this.
+
+110
+00:04:58,000 --> 00:05:05,000
+I would say check every month to every quarter for new firmware updates for different devices.
+
+111
+00:05:05,000 --> 00:05:09,000
+Manufacturers does have a way of releasing these updates and never telling anyone.
+
+112
+00:05:10,000 --> 00:05:14,000
+That's why when you register these devices, when you purchase them, you should register them with
+
+113
+00:05:14,000 --> 00:05:16,000
+a good email that you check consistently.
+
+114
+00:05:16,000 --> 00:05:21,000
+Generally, if there's a new firmware update that fixes a lot of vulnerabilities, they will email you
+
+115
+00:05:21,000 --> 00:05:24,000
+that and says, hey, there's a new firmware update to fix those vulnerabilities.
+
+116
+00:05:24,000 --> 00:05:29,000
+So as soon as they come out, make sure you test the update before deploying them.
+
diff --git a/26 - Labs/024 Configuring a DMZ_en.srt b/26 - Labs/024 Configuring a DMZ_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..0146348a745d1ed85b1071467db0ce7ebe21bfa7
--- /dev/null
+++ b/26 - Labs/024 Configuring a DMZ_en.srt
@@ -0,0 +1,400 @@
+1
+00:00:00,000 --> 00:00:05,000
+One concept you need to know for your exam is called demilitarized zones or DMZ.
+
+2
+00:00:06,000 --> 00:00:10,000
+A DMZ is used to host web servers or mail servers.
+
+3
+00:00:10,000 --> 00:00:17,000
+DMZ allows you to have a server on your network that you're going to allow public traffic into, without
+
+4
+00:00:17,000 --> 00:00:19,000
+affecting internal traffic.
+
+5
+00:00:20,000 --> 00:00:23,000
+This is best illustrated with a diagram.
+
+6
+00:00:23,000 --> 00:00:26,000
+So I want you guys to follow along with me on this diagram.
+
+7
+00:00:26,000 --> 00:00:29,000
+And I'm actually going to show you how to set it up.
+
+8
+00:00:30,000 --> 00:00:35,000
+So I'm going to draw one of my famous, uh, really horrible drawing diagram.
+
+9
+00:00:36,000 --> 00:00:38,000
+Uh, just to illustrate the point to you.
+
+10
+00:00:38,000 --> 00:00:39,000
+Now it's going to be really bad.
+
+11
+00:00:39,000 --> 00:00:41,000
+Please do not make fun of my drawing.
+
+12
+00:00:42,000 --> 00:00:46,000
+Um, okay, so let's say you have the internet, so this is going to be your internet.
+
+13
+00:00:46,000 --> 00:00:46,000
+Uh.
+
+14
+00:00:46,000 --> 00:00:48,000
+That's connected.
+
+15
+00:00:48,000 --> 00:00:51,000
+And you're going to have your wireless router at home.
+
+16
+00:00:52,000 --> 00:00:52,000
+All right.
+
+17
+00:00:52,000 --> 00:00:55,000
+You have your wireless router on that wireless router.
+
+18
+00:00:55,000 --> 00:00:58,000
+You're going to have some Ethernet connections to it.
+
+19
+00:00:58,000 --> 00:01:01,000
+And one of those connections is going to be plugged into the internet.
+
+20
+00:01:01,000 --> 00:01:06,000
+This is basically going to be the ISPs, uh, internet connection device.
+
+21
+00:01:06,000 --> 00:01:07,000
+All right.
+
+22
+00:01:07,000 --> 00:01:11,000
+So this is going to probably be like the the ISPs router now.
+
+23
+00:01:12,000 --> 00:01:13,000
+Let's put ISP here.
+
+24
+00:01:13,000 --> 00:01:18,000
+Now on this, you're going to take one of the ports and you're going to connect it to a big switch.
+
+25
+00:01:18,000 --> 00:01:20,000
+And again there's going to be more in a corporate network.
+
+26
+00:01:20,000 --> 00:01:21,000
+But I'm not going to be doing this at home.
+
+27
+00:01:21,000 --> 00:01:25,000
+So this corporate switch might be 36 port 48 port big switch.
+
+28
+00:01:25,000 --> 00:01:28,000
+And in here you're going to have all the workstations.
+
+29
+00:01:28,000 --> 00:01:32,000
+You're going to have all the servers that you have connected.
+
+30
+00:01:32,000 --> 00:01:34,000
+And then of course these are wireless.
+
+31
+00:01:34,000 --> 00:01:37,000
+So you're going to have all kinds of let's say laptops.
+
+32
+00:01:37,000 --> 00:01:42,000
+You're going to have uh, phones on the network and connected to the wireless.
+
+33
+00:01:42,000 --> 00:01:47,000
+But let's say you have a web server that you want to run.
+
+34
+00:01:48,000 --> 00:01:56,000
+So this web server is basically a device that people on the internet, any weird person on the internet,
+
+35
+00:01:56,000 --> 00:02:00,000
+can come to and access a web page and then go back out.
+
+36
+00:02:00,000 --> 00:02:05,000
+So what you're going to do is you're going to designate this web server to be in the DMZ.
+
+37
+00:02:06,000 --> 00:02:08,000
+Now this is going to be done with an IP address.
+
+38
+00:02:08,000 --> 00:02:13,000
+So you're going to say, let's say the IP address of this machine is 192168.
+
+39
+00:02:13,000 --> 00:02:18,000
+Let's say uh, 0 or 1, let's say dot ten.
+
+40
+00:02:19,000 --> 00:02:19,000
+All right.
+
+41
+00:02:19,000 --> 00:02:23,000
+So whatever the let's say it's a class C 102 1680. ten.
+
+42
+00:02:23,000 --> 00:02:25,000
+That's going to be your DMZ.
+
+43
+00:02:25,000 --> 00:02:29,000
+So the way this actually works is that traffic comes off the internet.
+
+44
+00:02:29,000 --> 00:02:32,000
+Let's say this is me, I'm home and I want to access your web server.
+
+45
+00:02:32,000 --> 00:02:34,000
+I'm going to send traffic to your router.
+
+46
+00:02:34,000 --> 00:02:38,000
+Your router sends it to your other wireless router or your basically it's going to be your firewall
+
+47
+00:02:38,000 --> 00:02:39,000
+at this point.
+
+48
+00:02:39,000 --> 00:02:43,000
+And your it comes into the final fiber is like, where are you going?
+
+49
+00:02:44,000 --> 00:02:49,000
+You want to go to the web server, it sends it to the web server and then it goes back to me.
+
+50
+00:02:49,000 --> 00:02:54,000
+So if you're watching the red diagram, it basically sends it to the web server and back out.
+
+51
+00:02:54,000 --> 00:03:00,000
+So that way the actual public traffic is not on your network.
+
+52
+00:03:00,000 --> 00:03:04,000
+You see, if you don't use the DMZ, if you don't use the DMZ, here's what happens.
+
+53
+00:03:04,000 --> 00:03:08,000
+Then what you end up doing is you end up putting the web server here, and then you follow the port.
+
+54
+00:03:08,000 --> 00:03:13,000
+And now all of a sudden the, the, the, the firewall here that we're using or the router that you're
+
+55
+00:03:13,000 --> 00:03:17,000
+using is going to forward that public traffic in your internal network.
+
+56
+00:03:17,000 --> 00:03:17,000
+You don't want that.
+
+57
+00:03:17,000 --> 00:03:21,000
+You want to keep it outside in the DMZ.
+
+58
+00:03:22,000 --> 00:03:24,000
+And that's that's really why you want a DMZ.
+
+59
+00:03:24,000 --> 00:03:26,000
+So why do you want a DMZ.
+
+60
+00:03:26,000 --> 00:03:32,000
+So you can have public servers on your network, your hosting, public servers.
+
+61
+00:03:32,000 --> 00:03:36,000
+You're hosting your own mail server, your own DNS server, your own web server.
+
+62
+00:03:36,000 --> 00:03:38,000
+So let's go and see how to configure this.
+
+63
+00:03:38,000 --> 00:03:41,000
+Now I'm going to be doing this with a very simple device.
+
+64
+00:03:41,000 --> 00:03:46,000
+Um, let's go into our you could use this on your base machine by the way.
+
+65
+00:03:46,000 --> 00:03:48,000
+It's just a just a browser.
+
+66
+00:03:48,000 --> 00:03:50,000
+Let's go to Linksys live demo.
+
+67
+00:03:50,000 --> 00:03:52,000
+Just go to Google, type that in there.
+
+68
+00:03:52,000 --> 00:03:54,000
+Let's go to Linksys uh emulator.
+
+69
+00:03:56,000 --> 00:04:01,000
+And the one I've been using so far to do most of my labs here has been this x 6200 for no apparent reason.
+
+70
+00:04:01,000 --> 00:04:03,000
+You can use any one of these devices that you like.
+
+71
+00:04:04,000 --> 00:04:08,000
+I'm just going to click on the X 6200 device.
+
+72
+00:04:08,000 --> 00:04:16,000
+And so in here in the setup of the of the device notice you have many many many options.
+
+73
+00:04:16,000 --> 00:04:18,000
+All right we're going to go to the tab here.
+
+74
+00:04:18,000 --> 00:04:19,000
+It says application and game.
+
+75
+00:04:19,000 --> 00:04:21,000
+And this allows us to do all the port forwarding.
+
+76
+00:04:21,000 --> 00:04:24,000
+And you notice you have DMZ Demilitarized zone.
+
+77
+00:04:25,000 --> 00:04:27,000
+So we're going to say enabled.
+
+78
+00:04:27,000 --> 00:04:32,000
+And we're going to say the source that means any, any IP address coming into the router, anybody,
+
+79
+00:04:32,000 --> 00:04:36,000
+any IP address coming into the router, we want to send that.
+
+80
+00:04:37,000 --> 00:04:38,000
+22.68.
+
+81
+00:04:38,000 --> 00:04:42,000
+And remember in our diagram it was ten.
+
+82
+00:04:43,000 --> 00:04:48,000
+So 192168. ten and I'm just going, that's it.
+
+83
+00:04:48,000 --> 00:04:49,000
+That's all there was to it.
+
+84
+00:04:49,000 --> 00:04:52,000
+You can even specify a mac address table if you want.
+
+85
+00:04:52,000 --> 00:04:53,000
+And that is it.
+
+86
+00:04:53,000 --> 00:04:54,000
+You're done.
+
+87
+00:04:54,000 --> 00:04:56,000
+That's how easy it was to configure it on this device.
+
+88
+00:04:56,000 --> 00:05:03,000
+Now depending on the configuration of the device this could get more complex right.
+
+89
+00:05:03,000 --> 00:05:06,000
+Depending on configuration you could do an entire subnet.
+
+90
+00:05:06,000 --> 00:05:10,000
+Uh, you can designate certain ports on the physical device itself, like on my sonicwall.
+
+91
+00:05:10,000 --> 00:05:12,000
+I can do subnets, I can do ports and so on.
+
+92
+00:05:12,000 --> 00:05:14,000
+So it could get complex.
+
+93
+00:05:14,000 --> 00:05:19,000
+But something like this particular, uh, home based device here like this Linksys makes it very simple
+
+94
+00:05:19,000 --> 00:05:20,000
+and very easy.
+
+95
+00:05:20,000 --> 00:05:22,000
+But the concepts are the same.
+
+96
+00:05:22,000 --> 00:05:25,000
+Doesn't matter what you use on Linksys or Sonicwall or Cisco's Eisa.
+
+97
+00:05:25,000 --> 00:05:26,000
+It doesn't matter.
+
+98
+00:05:26,000 --> 00:05:27,000
+The concept comes.
+
+99
+00:05:27,000 --> 00:05:28,000
+Concepts are the same.
+
+100
+00:05:28,000 --> 00:05:32,000
+So remember and know what dms's are for your for your exam.
+
diff --git a/26 - Labs/025 Using tor network_en.srt b/26 - Labs/025 Using tor network_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..50ee53eef382c79267ff8e8e35e3a96162b7c143
--- /dev/null
+++ b/26 - Labs/025 Using tor network_en.srt
@@ -0,0 +1,584 @@
+1
+00:00:00,000 --> 00:00:06,000
+One of the concepts that you should learn as a security administrator is how to become anonymous, basically
+
+2
+00:00:06,000 --> 00:00:07,000
+how to hide yourself.
+
+3
+00:00:07,000 --> 00:00:13,000
+And one of the ways of doing that is basically going to be using what's called a Tor browser.
+
+4
+00:00:13,000 --> 00:00:19,000
+So Tor, which stands for the Onion Router, is basically a browser that you can download and use.
+
+5
+00:00:19,000 --> 00:00:23,000
+And basically when you connect to the internet, it anonymizes you.
+
+6
+00:00:23,000 --> 00:00:25,000
+In other words, no one can know where you're coming from.
+
+7
+00:00:25,000 --> 00:00:29,000
+It uses a series of proxies in order to hide your true identity.
+
+8
+00:00:29,000 --> 00:00:33,000
+So if you want to browse the internet anonymously, this is the way to do it.
+
+9
+00:00:33,000 --> 00:00:35,000
+Now, if you're probably saying, Andrew, doesn't this belong in a hacking class?
+
+10
+00:00:35,000 --> 00:00:37,000
+Well, you see.
+
+11
+00:00:38,000 --> 00:00:42,000
+As a security administrator, you should be doing what's called threat hunting.
+
+12
+00:00:43,000 --> 00:00:48,000
+In threat hunting, you play the role of actually going out and looking for potential threats to your
+
+13
+00:00:48,000 --> 00:00:48,000
+network.
+
+14
+00:00:48,000 --> 00:00:54,000
+So when you're doing threat hunting, you want to anonymize yourself by using something as a Tor browser.
+
+15
+00:00:54,000 --> 00:00:59,000
+That way, when you're actually browsing and looking for different threats that could affect your network,
+
+16
+00:00:59,000 --> 00:01:01,000
+you're not giving away where you're coming from.
+
+17
+00:01:02,000 --> 00:01:08,000
+So in this lab, I want to show you guys how to use the how to use the actual Tor browser.
+
+18
+00:01:08,000 --> 00:01:10,000
+So let's go ahead and get it.
+
+19
+00:01:10,000 --> 00:01:11,000
+Uh, where are we?
+
+20
+00:01:11,000 --> 00:01:11,000
+Okay.
+
+21
+00:01:11,000 --> 00:01:12,000
+So we go to our desktop here.
+
+22
+00:01:12,000 --> 00:01:16,000
+I'm going to just go to Google and type Tor browser.
+
+23
+00:01:17,000 --> 00:01:21,000
+Now it might take a few minutes to download, but we're just going to go ahead and do that.
+
+24
+00:01:23,000 --> 00:01:26,000
+Um, okay, so here we go.
+
+25
+00:01:26,000 --> 00:01:28,000
+Download the Tor browser.
+
+26
+00:01:28,000 --> 00:01:28,000
+All right.
+
+27
+00:01:28,000 --> 00:01:31,000
+We'll download that and let's do windows.
+
+28
+00:01:32,000 --> 00:01:34,000
+I notice you have all the appearances.
+
+29
+00:01:34,000 --> 00:01:36,000
+You can run it on Android.
+
+30
+00:01:37,000 --> 00:01:38,000
+Okay.
+
+31
+00:01:38,000 --> 00:01:41,000
+Now, if you're running on a on an iPhone, don't don't use iPhones.
+
+32
+00:01:41,000 --> 00:01:44,000
+It's not good for our hacking community to do that.
+
+33
+00:01:45,000 --> 00:01:45,000
+All right.
+
+34
+00:01:45,000 --> 00:01:47,000
+So it was pretty quick to download for me.
+
+35
+00:01:47,000 --> 00:01:48,000
+So it was about 100 megs.
+
+36
+00:01:50,000 --> 00:01:53,000
+And so I'm just going to go ahead and open it okay.
+
+37
+00:01:54,000 --> 00:01:57,000
+Now, I must warn you, we're just going to install this with all default settings.
+
+38
+00:01:57,000 --> 00:02:02,000
+I must warn you that when you're using things like the Tor browser to browse the internet, yes, you
+
+39
+00:02:02,000 --> 00:02:04,000
+will be anonymized and basically no one will.
+
+40
+00:02:04,000 --> 00:02:10,000
+No one will be able to track where you're from, but it is ridiculously slow.
+
+41
+00:02:10,000 --> 00:02:15,000
+So if you're using this and you're finding it very slow, it is the way it is because it's connected
+
+42
+00:02:15,000 --> 00:02:18,000
+to a series of proxies in order to hide yourself.
+
+43
+00:02:20,000 --> 00:02:21,000
+All right, so we'll just run it, all right?
+
+44
+00:02:21,000 --> 00:02:22,000
+We'll just keep that option.
+
+45
+00:02:22,000 --> 00:02:24,000
+Now it does add a link.
+
+46
+00:02:24,000 --> 00:02:27,000
+Uh there it is on your on your menu.
+
+47
+00:02:27,000 --> 00:02:28,000
+Now here we go.
+
+48
+00:02:28,000 --> 00:02:30,000
+So this is the Tor browser.
+
+49
+00:02:31,000 --> 00:02:36,000
+And this browser routes traffic over the network over the Tor network which is basically a proxy.
+
+50
+00:02:36,000 --> 00:02:39,000
+And this is run by thousands of volunteers around the world.
+
+51
+00:02:39,000 --> 00:02:41,000
+So basically it'll connect to another proxy, connect to another product.
+
+52
+00:02:41,000 --> 00:02:45,000
+It basically anonymizes you by connecting to a whole bunch of different networks.
+
+53
+00:02:46,000 --> 00:02:48,000
+So that way it's almost impossible to find you.
+
+54
+00:02:48,000 --> 00:02:50,000
+So we're going to say connect.
+
+55
+00:02:50,000 --> 00:02:55,000
+Now, depending on how fast your internet connection is and the time of the data the Tor browser is
+
+56
+00:02:55,000 --> 00:03:00,000
+using, this could be very, very slow.
+
+57
+00:03:00,000 --> 00:03:08,000
+And just using any of the, uh, it just says that was just a language Pas and just using any of the
+
+58
+00:03:08,000 --> 00:03:10,000
+actual components.
+
+59
+00:03:10,000 --> 00:03:14,000
+Uh, just going to any website is going to be very slow.
+
+60
+00:03:14,000 --> 00:03:20,000
+So if you're using the Tor to tour to do something, be prepared to to be there a while and you can
+
+61
+00:03:20,000 --> 00:03:21,000
+see how long it's just taking.
+
+62
+00:03:21,000 --> 00:03:29,000
+Now I have a one gig Fios connection on my machine and you notice, hey, it looks looks good there.
+
+63
+00:03:29,000 --> 00:03:39,000
+We want DuckDuckGo is more secure than Google, but you could still go to Google and depending on what
+
+64
+00:03:39,000 --> 00:03:40,000
+proxy I connect to, look, look at this.
+
+65
+00:03:40,000 --> 00:03:41,000
+It's telling me.
+
+66
+00:03:41,000 --> 00:03:50,000
+So if you notice on Google, on my local machine, I mean this is Google on my local, uh, my, my
+
+67
+00:03:50,000 --> 00:03:54,000
+local machine, I'm going to put where am I.
+
+68
+00:03:57,000 --> 00:03:58,000
+Can't even spell that.
+
+69
+00:03:58,000 --> 00:03:59,000
+Where am I.
+
+70
+00:04:01,000 --> 00:04:09,000
+So I am at the Tia Garden City location today in Garden City, Long Island.
+
+71
+00:04:10,000 --> 00:04:12,000
+And it starts where I am.
+
+72
+00:04:12,000 --> 00:04:14,000
+I'm in North Hempstead right now.
+
+73
+00:04:14,000 --> 00:04:15,000
+Good enough.
+
+74
+00:04:15,000 --> 00:04:16,000
+That's where I'm actually are.
+
+75
+00:04:16,000 --> 00:04:20,000
+But the Tor browser is telling me I'm God knows where this is.
+
+76
+00:04:21,000 --> 00:04:22,000
+I don't even know what language this is.
+
+77
+00:04:22,000 --> 00:04:24,000
+Uh, I guess that one there.
+
+78
+00:04:24,000 --> 00:04:27,000
+And if I say, where am I?
+
+79
+00:04:29,000 --> 00:04:32,000
+Uh, so where am I?
+
+80
+00:04:32,000 --> 00:04:34,000
+It's going to try to find a location.
+
+81
+00:04:34,000 --> 00:04:35,000
+I don't know where I am here.
+
+82
+00:04:36,000 --> 00:04:36,000
+Uh.
+
+83
+00:04:37,000 --> 00:04:42,000
+But once again, you guys can remember that it's going to be very, very slow.
+
+84
+00:04:42,000 --> 00:04:42,000
+All right.
+
+85
+00:04:42,000 --> 00:04:43,000
+I guess allow all.
+
+86
+00:04:45,000 --> 00:04:46,000
+So.
+
+87
+00:04:48,000 --> 00:04:49,000
+Share your location.
+
+88
+00:04:49,000 --> 00:04:53,000
+I'm not sure if I actually put that on or not, but Google knows where I am.
+
+89
+00:04:54,000 --> 00:04:55,000
+Sometime, he tells us at the bottom.
+
+90
+00:04:59,000 --> 00:05:01,000
+Yeah, it's starting to share that location.
+
+91
+00:05:01,000 --> 00:05:04,000
+Yeah, it's very slow to notice this just popped up.
+
+92
+00:05:04,000 --> 00:05:07,000
+So it's a whole different interface.
+
+93
+00:05:07,000 --> 00:05:10,000
+Um, I don't recommend using Google on this.
+
+94
+00:05:10,000 --> 00:05:16,000
+I would just use DuckDuckGo here and see if the location is turned on on the browser.
+
+95
+00:05:17,000 --> 00:05:19,000
+But that's basically what this does.
+
+96
+00:05:19,000 --> 00:05:24,000
+Basically, it anonymizes your, uh, this I'm not going to show you guys how to get to, like, the
+
+97
+00:05:24,000 --> 00:05:30,000
+dark web and all this, because if you're looking to get to the dark web, that'll tell you, that'll
+
+98
+00:05:30,000 --> 00:05:30,000
+be it.
+
+99
+00:05:30,000 --> 00:05:34,000
+This this will tell you, uh, this is how you get to the dark web.
+
+100
+00:05:35,000 --> 00:05:36,000
+And sent.
+
+101
+00:05:40,000 --> 00:05:43,000
+I'm just clicking on random links here to see where the hell am I?
+
+102
+00:05:48,000 --> 00:05:50,000
+My location in real time.
+
+103
+00:05:50,000 --> 00:05:54,000
+Let's use this one here to see the actual finder of itself.
+
+104
+00:05:54,000 --> 00:05:58,000
+And once again, I know this lab here is getting kind of long.
+
+105
+00:05:58,000 --> 00:05:59,000
+Uh.
+
+106
+00:06:01,000 --> 00:06:01,000
+All right.
+
+107
+00:06:01,000 --> 00:06:03,000
+This website looks okay.
+
+108
+00:06:05,000 --> 00:06:08,000
+Ah, it's still having a hard time finding us.
+
+109
+00:06:09,000 --> 00:06:11,000
+His location.
+
+110
+00:06:11,000 --> 00:06:14,000
+Uh, localization is not available, so the browser is hiding it.
+
+111
+00:06:14,000 --> 00:06:15,000
+That's good.
+
+112
+00:06:15,000 --> 00:06:17,000
+And every time you connect.
+
+113
+00:06:17,000 --> 00:06:25,000
+The good thing with Tora is that every time you connect to it, it might give you another place like
+
+114
+00:06:25,000 --> 00:06:26,000
+you can.
+
+115
+00:06:26,000 --> 00:06:32,000
+You might close it, reconnect to it, and it'll give you a whole nother place.
+
+116
+00:06:32,000 --> 00:06:32,000
+Oh, here we go.
+
+117
+00:06:32,000 --> 00:06:33,000
+English.
+
+118
+00:06:33,000 --> 00:06:36,000
+So there is an English version of this thing.
+
+119
+00:06:36,000 --> 00:06:38,000
+Um, and that's.
+
+120
+00:06:38,000 --> 00:06:40,000
+Oh, it says I'm in the Netherlands.
+
+121
+00:06:40,000 --> 00:06:41,000
+Okay, there we go.
+
+122
+00:06:41,000 --> 00:06:42,000
+It was there all the time.
+
+123
+00:06:42,000 --> 00:06:43,000
+So.
+
+124
+00:06:44,000 --> 00:06:49,000
+And every time you connect, you can then disconnect and reconnect in the Tor network.
+
+125
+00:06:49,000 --> 00:06:51,000
+And it might tell you a whole different thing.
+
+126
+00:06:51,000 --> 00:06:54,000
+You might be in a whole nother country another time.
+
+127
+00:06:55,000 --> 00:06:56,000
+So we can connect.
+
+128
+00:06:56,000 --> 00:06:58,000
+Are we still going to be in the Netherlands?
+
+129
+00:06:58,000 --> 00:06:58,000
+Maybe.
+
+130
+00:06:58,000 --> 00:07:00,000
+Or maybe not, but.
+
+131
+00:07:02,000 --> 00:07:03,000
+Let's see.
+
+132
+00:07:05,000 --> 00:07:08,000
+And once again it is very slow.
+
+133
+00:07:08,000 --> 00:07:09,000
+I'm giving you guys a word of warning.
+
+134
+00:07:09,000 --> 00:07:16,000
+It is very, very slow and depending on where you are, sometimes it'll go to some Asian countries,
+
+135
+00:07:16,000 --> 00:07:23,000
+sometimes it'll go to, uh, Netherlands, sometimes it'll go to European countries, sometimes it might
+
+136
+00:07:23,000 --> 00:07:25,000
+be back in the United States.
+
+137
+00:07:25,000 --> 00:07:31,000
+So notice this one here is more this is this one here seems to be more English.
+
+138
+00:07:31,000 --> 00:07:31,000
+All right.
+
+139
+00:07:31,000 --> 00:07:33,000
+You guys play around with this.
+
+140
+00:07:33,000 --> 00:07:35,000
+Search the internet as much as you can.
+
+141
+00:07:35,000 --> 00:07:37,000
+You will be fully anonymized.
+
+142
+00:07:37,000 --> 00:07:40,000
+So just make sure you know what the Tor browser is.
+
+143
+00:07:40,000 --> 00:07:43,000
+You may see this thing show up on your exam as Tor.
+
+144
+00:07:43,000 --> 00:07:44,000
+Tor.
+
+145
+00:07:44,000 --> 00:07:48,000
+Just remember it stands for the Onion Router and that all that means is that it's going through different
+
+146
+00:07:48,000 --> 00:07:50,000
+network to keep you anonymous.
+
diff --git a/26 - Labs/026 Configuring VLAN's_en.srt b/26 - Labs/026 Configuring VLAN's_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..10b02b2892703ae8fd9964c0dd68c5d4389c816b
--- /dev/null
+++ b/26 - Labs/026 Configuring VLAN's_en.srt
@@ -0,0 +1,408 @@
+1
+00:00:00,000 --> 00:00:04,000
+One of the most important things you can do as a network administrator is to segment your network.
+
+2
+00:00:04,000 --> 00:00:10,000
+Segmenting your network is going to be done utilizing switches and VLANs.
+
+3
+00:00:10,000 --> 00:00:13,000
+Basically, what you're going to do is you're basically going to go into the switch and create different
+
+4
+00:00:13,000 --> 00:00:18,000
+VLANs, and then you're going to associate different networks with different VLANs.
+
+5
+00:00:18,000 --> 00:00:22,000
+So let's say you're using a class C network 192168 ten dot zero.
+
+6
+00:00:22,000 --> 00:00:24,000
+Let's say that's one of your networks.
+
+7
+00:00:24,000 --> 00:00:25,000
+Uh 10.0.
+
+8
+00:00:26,000 --> 00:00:28,000
+And let's see, that's in the sales.
+
+9
+00:00:28,000 --> 00:00:31,000
+And then you could do 19268 20 dot zero.
+
+10
+00:00:31,000 --> 00:00:32,000
+That's in finance.
+
+11
+00:00:32,000 --> 00:00:33,000
+And then maybe an accountant.
+
+12
+00:00:33,000 --> 00:00:36,000
+It's 19268 30 dot zero and so on and so on.
+
+13
+00:00:36,000 --> 00:00:40,000
+So what you want to do is you just don't want to separate them by subnet, but you want to separate
+
+14
+00:00:40,000 --> 00:00:41,000
+them by Vlan.
+
+15
+00:00:41,000 --> 00:00:48,000
+That way when the switch detects that this machine 192168 ten, that means this machine can only communicate
+
+16
+00:00:48,000 --> 00:00:52,000
+with other machines that are one nine, two one, six, eight, ten and even if that person goes and
+
+17
+00:00:52,000 --> 00:00:56,000
+changed the IP address to 20, it's still not going to communicate with anything outside.
+
+18
+00:00:56,000 --> 00:00:56,000
+So.
+
+19
+00:00:56,000 --> 00:01:00,000
+So what we want to do is we want to segment the network utilizing VLANs.
+
+20
+00:01:00,000 --> 00:01:03,000
+Now to do this we have to do this within a switch.
+
+21
+00:01:04,000 --> 00:01:07,000
+Depending on the wireless router you're using.
+
+22
+00:01:07,000 --> 00:01:10,000
+If it has a built in switch with Vlan configuration, you could do it there too.
+
+23
+00:01:10,000 --> 00:01:13,000
+And that's what we're going to be doing because we're going to keep it simple.
+
+24
+00:01:13,000 --> 00:01:18,000
+I thought about installing packet tracer and showing you guys how to do that, but that would have been
+
+25
+00:01:18,000 --> 00:01:19,000
+a long lab.
+
+26
+00:01:19,000 --> 00:01:23,000
+You just need to get the general idea of how this is done on a switch.
+
+27
+00:01:23,000 --> 00:01:24,000
+So we are going to use a Cisco switch.
+
+28
+00:01:24,000 --> 00:01:28,000
+We're basically going to use a small small business device Cisco Switch.
+
+29
+00:01:28,000 --> 00:01:29,000
+Let me show you which one.
+
+30
+00:01:30,000 --> 00:01:34,000
+So let's go to Google and let's type Cisco Switch Emulator online.
+
+31
+00:01:35,000 --> 00:01:42,000
+And, uh, one of the, uh, first links here on the sponsor is online device emulators, small business
+
+32
+00:01:42,000 --> 00:01:43,000
+from Cisco.
+
+33
+00:01:44,000 --> 00:01:51,000
+And, uh, one device that I like utilizing because I've had personal experience utilizing this device
+
+34
+00:01:51,000 --> 00:01:52,000
+is the RV.
+
+35
+00:01:53,000 --> 00:01:56,000
+Uh, three, four, five.
+
+36
+00:01:56,000 --> 00:01:57,000
+All right.
+
+37
+00:01:57,000 --> 00:01:57,000
+You don't need to.
+
+38
+00:01:57,000 --> 00:02:03,000
+You don't need the, uh, we had used this to do to with a big switch in our network.
+
+39
+00:02:03,000 --> 00:02:05,000
+You notice it has many ports on it.
+
+40
+00:02:05,000 --> 00:02:09,000
+16 ports in particular, and it actually is a VPN.
+
+41
+00:02:09,000 --> 00:02:11,000
+So we had used this a long time ago.
+
+42
+00:02:11,000 --> 00:02:13,000
+So it's really good device to use.
+
+43
+00:02:13,000 --> 00:02:14,000
+I absolutely love it.
+
+44
+00:02:14,000 --> 00:02:19,000
+Hi I you know it comes with it comes with the ability to do VPN.
+
+45
+00:02:19,000 --> 00:02:26,000
+It's a great firewall and it allows you to do VLANs so we can segment our network utilizing this device.
+
+46
+00:02:26,000 --> 00:02:28,000
+So I'm going to open up the latest.
+
+47
+00:02:29,000 --> 00:02:30,000
+Actually, you know what?
+
+48
+00:02:30,000 --> 00:02:31,000
+I'm going to take the bottom firmer.
+
+49
+00:02:31,000 --> 00:02:31,000
+That's fine.
+
+50
+00:02:31,000 --> 00:02:33,000
+It's not the latest, but it's not the most recent.
+
+51
+00:02:34,000 --> 00:02:36,000
+So that is okay.
+
+52
+00:02:37,000 --> 00:02:37,000
+Um.
+
+53
+00:02:38,000 --> 00:02:39,000
+Our city.
+
+54
+00:02:39,000 --> 00:02:39,000
+Earliest one.
+
+55
+00:02:39,000 --> 00:02:40,000
+All right, that's fine.
+
+56
+00:02:40,000 --> 00:02:42,000
+Okay, so here we are.
+
+57
+00:02:42,000 --> 00:02:45,000
+This is what the interface would look like if you're setting up this device, this is what it would
+
+58
+00:02:45,000 --> 00:02:46,000
+look like.
+
+59
+00:02:46,000 --> 00:02:48,000
+So we're going to go in here.
+
+60
+00:02:50,000 --> 00:02:51,000
+To land.
+
+61
+00:02:51,000 --> 00:02:54,000
+And in this lab we're just looking at Vlan settings.
+
+62
+00:02:54,000 --> 00:02:55,000
+So let's go do that.
+
+63
+00:02:55,000 --> 00:03:01,000
+So by default every single thing on the switch is actually done in Vlan one.
+
+64
+00:03:01,000 --> 00:03:04,000
+And you can see that this is just Vlan one.
+
+65
+00:03:04,000 --> 00:03:09,000
+And that means that all all the devices on the network on this particular switch is going to be A19
+
+66
+00:03:09,000 --> 00:03:12,000
+21681.0 network ID.
+
+67
+00:03:12,000 --> 00:03:16,000
+Now, what I'm going to do here is I'm going to add in a second Vlan.
+
+68
+00:03:16,000 --> 00:03:18,000
+And I'm going to add in, let's say we're going to click on add.
+
+69
+00:03:19,000 --> 00:03:20,000
+And this is going to be villain two.
+
+70
+00:03:21,000 --> 00:03:25,000
+And Vlan two is going to be 192168.
+
+71
+00:03:25,000 --> 00:03:27,000
+So this is what one dot basically zero.
+
+72
+00:03:27,000 --> 00:03:33,000
+We're going to do 2.1921682.1.
+
+73
+00:03:33,000 --> 00:03:38,000
+Oops dot one with a 24 prefix.
+
+74
+00:03:38,000 --> 00:03:42,000
+That's the slash 24 that says 255 255 225.0.
+
+75
+00:03:43,000 --> 00:03:45,000
+We're not going to bother with IPV six.
+
+76
+00:03:46,000 --> 00:03:53,000
+Uh, if you have IPV six and you are using different, uh, different prefix prefixes on it, you could
+
+77
+00:03:53,000 --> 00:03:54,000
+definitely do that too.
+
+78
+00:03:54,000 --> 00:03:56,000
+So we're just going to go ahead and click on add.
+
+79
+00:03:57,000 --> 00:04:00,000
+So you could say that 1921681.1.
+
+80
+00:04:00,000 --> 00:04:04,000
+You could say your management Vlan 1921682.1.
+
+81
+00:04:04,000 --> 00:04:12,000
+Maybe your sales Vlan, uh, Vlan three we could say is 192.168.3.1.
+
+82
+00:04:12,000 --> 00:04:15,000
+This could be maybe your accounting Vlan.
+
+83
+00:04:15,000 --> 00:04:22,000
+Now, that means that any time a computer connects to this switch and it carries one of these IP addresses,
+
+84
+00:04:22,000 --> 00:04:26,000
+such as 1921683.2.4.5.
+
+85
+00:04:26,000 --> 00:04:29,000
+Whatever it is, it's going to know it's in Vlan three, and it's going to communicate with any device
+
+86
+00:04:29,000 --> 00:04:31,000
+in Vlan three.
+
+87
+00:04:31,000 --> 00:04:37,000
+If it's connected, it's going to be, um, IP address two dot something or two dot x, it's going to
+
+88
+00:04:37,000 --> 00:04:39,000
+be in Vlan two, and 1.1 is going to be in Vlan one.
+
+89
+00:04:40,000 --> 00:04:41,000
+And that's all this is.
+
+90
+00:04:41,000 --> 00:04:41,000
+Right.
+
+91
+00:04:41,000 --> 00:04:44,000
+And if you ever want to edit it you just click on it and say edit.
+
+92
+00:04:45,000 --> 00:04:46,000
+And that's it.
+
+93
+00:04:46,000 --> 00:04:48,000
+That's all this is, is not more.
+
+94
+00:04:48,000 --> 00:04:56,000
+It's nothing more, uh, harder than this when you're utilizing a device like this and that's it.
+
+95
+00:04:56,000 --> 00:05:00,000
+Now, it's not going to save any of this because it is a demo of the actual.
+
+96
+00:05:00,000 --> 00:05:02,000
+If you close it and you try to reopen, it's not going to be there.
+
+97
+00:05:02,000 --> 00:05:05,000
+Because again, this is a demo for you to practice, okay.
+
+98
+00:05:05,000 --> 00:05:09,000
+But this is how you would set up and configure VLANs on a switch.
+
+99
+00:05:09,000 --> 00:05:15,000
+An easy way of doing it if you're depending on what switch you're using, if you're using a big managed
+
+100
+00:05:15,000 --> 00:05:19,000
+switch, a big Cisco switch, there are command lines that allows you to do this, but we'll keep that
+
+101
+00:05:19,000 --> 00:05:20,000
+for Cisco class.
+
+102
+00:05:20,000 --> 00:05:24,000
+Try this to make it a lot easy to configure VLANs.
+
diff --git a/26 - Labs/027 Setting up an IPS_en.srt b/26 - Labs/027 Setting up an IPS_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..0baa7af7f68fb835bac19fd48de28de0a85661d9
--- /dev/null
+++ b/26 - Labs/027 Setting up an IPS_en.srt
@@ -0,0 +1,268 @@
+1
+00:00:00,000 --> 00:00:05,000
+Your network is going to be under attack quite frequently, and what you have to do is you have to have
+
+2
+00:00:05,000 --> 00:00:06,000
+an IPS.
+
+3
+00:00:06,000 --> 00:00:11,000
+Intrusion prevention systems can block attack from coming into your network and destroying your network.
+
+4
+00:00:11,000 --> 00:00:18,000
+Not all devices supports IPS, and more than likely an IPS is going to be on your firewall.
+
+5
+00:00:18,000 --> 00:00:22,000
+So in this quick lab, I'm going to show you how to enable it if the device supports it.
+
+6
+00:00:22,000 --> 00:00:25,000
+Now I do have a Cisco device that does support IPS.
+
+7
+00:00:25,000 --> 00:00:27,000
+And I'm going to show you guys how to enable it.
+
+8
+00:00:27,000 --> 00:00:28,000
+It's not hard to configure.
+
+9
+00:00:28,000 --> 00:00:29,000
+You just have to turn it on.
+
+10
+00:00:29,000 --> 00:00:34,000
+Also, when you have an IPS or an intrusion prevention system, you have to keep it updated with the
+
+11
+00:00:34,000 --> 00:00:35,000
+current signatures.
+
+12
+00:00:35,000 --> 00:00:39,000
+That's going to require some kind of subscription to the device manufacturer, which generally means
+
+13
+00:00:39,000 --> 00:00:42,000
+you have to pay them monthly or yearly for it.
+
+14
+00:00:42,000 --> 00:00:43,000
+So let's go see how to do it.
+
+15
+00:00:44,000 --> 00:00:49,000
+To do this, we're going to go to go to Google and we're going to type Cisco Switch Emulator online.
+
+16
+00:00:49,000 --> 00:00:53,000
+And I want to look for the online device emulators.
+
+17
+00:00:54,000 --> 00:00:56,000
+Our link on the Cisco community.
+
+18
+00:00:56,000 --> 00:01:02,000
+And this is going to give us the ability to log in and basically play around and manage Cisco devices.
+
+19
+00:01:02,000 --> 00:01:07,000
+So one of the devices that supports this particular function that we're looking for.
+
+20
+00:01:09,000 --> 00:01:13,000
+Uh, is this RV 340?
+
+21
+00:01:14,000 --> 00:01:18,000
+And I'm just going to use the first online device emulator link here.
+
+22
+00:01:18,000 --> 00:01:19,000
+So this is the RV 340.
+
+23
+00:01:19,000 --> 00:01:21,000
+Now this is a small business device.
+
+24
+00:01:21,000 --> 00:01:25,000
+It doesn't have a lot of ports on it, but it does have an IPS function built in.
+
+25
+00:01:25,000 --> 00:01:29,000
+And I want to show you how to access so online device simulator.
+
+26
+00:01:29,000 --> 00:01:34,000
+And in order to access this particular function of the device we're going to go down here to security.
+
+27
+00:01:35,000 --> 00:01:39,000
+And on here you notice it says thread slash IPS.
+
+28
+00:01:39,000 --> 00:01:42,000
+And I'm going to go here to IPS.
+
+29
+00:01:42,000 --> 00:01:44,000
+And it's a simple now this is an emulator.
+
+30
+00:01:44,000 --> 00:01:49,000
+So we actually can't save it or do anything to we can configure it but we can't save the configuration
+
+31
+00:01:50,000 --> 00:01:50,000
+and all it is.
+
+32
+00:01:50,000 --> 00:01:52,000
+We just have to turn it on.
+
+33
+00:01:52,000 --> 00:01:54,000
+Now this come off by default.
+
+34
+00:01:54,000 --> 00:01:59,000
+And again I'm going to warn you guys, you must have the ability to update the device.
+
+35
+00:01:59,000 --> 00:02:03,000
+That means you generally have to purchase a subscription to Cisco to get the updates.
+
+36
+00:02:03,000 --> 00:02:04,000
+So what happens?
+
+37
+00:02:04,000 --> 00:02:10,000
+Well, the mode is by default, we don't want to just log any attacks against our network.
+
+38
+00:02:10,000 --> 00:02:13,000
+We want to block attacks against our network.
+
+39
+00:02:13,000 --> 00:02:16,000
+Notice an IDs will log things and send you alerts.
+
+40
+00:02:16,000 --> 00:02:19,000
+But in this particular one we're going to block it.
+
+41
+00:02:19,000 --> 00:02:21,000
+The IPS level connectivity.
+
+42
+00:02:21,000 --> 00:02:24,000
+This basically is the least protection.
+
+43
+00:02:24,000 --> 00:02:28,000
+Only high risk attacks it's going to is going to block it.
+
+44
+00:02:28,000 --> 00:02:34,000
+If it detects if you want it to be the most protection, you would do security in this particular one.
+
+45
+00:02:34,000 --> 00:02:37,000
+Basically anything that it sees as a threat, it's going to block it.
+
+46
+00:02:37,000 --> 00:02:39,000
+The problem with this, you might get a lot of false positives.
+
+47
+00:02:39,000 --> 00:02:42,000
+In other words, things that are not really a threat to blocked and doesn't come into your network.
+
+48
+00:02:43,000 --> 00:02:46,000
+Now this here, you have to get the signature.
+
+49
+00:02:46,000 --> 00:02:49,000
+You would have to go and update the signature.
+
+50
+00:02:49,000 --> 00:02:51,000
+Uh, notice the last time this was updated was a very long time ago.
+
+51
+00:02:51,000 --> 00:02:56,000
+So if you do buy this device, you're going to have to make sure you get the signature and keep it updated.
+
+52
+00:02:56,000 --> 00:02:56,000
+And that's it.
+
+53
+00:02:56,000 --> 00:02:59,000
+You would just click apply and it's configured.
+
+54
+00:02:59,000 --> 00:03:04,000
+I know when I covered this in the course, and I spoke a lot about IDs and IPS that made it seem like
+
+55
+00:03:04,000 --> 00:03:05,000
+it's a really complex thing.
+
+56
+00:03:05,000 --> 00:03:09,000
+But as you can see, it's not that complex on this device.
+
+57
+00:03:09,000 --> 00:03:14,000
+Now I'm just going to close this out because really, you really can't save anything or do anything.
+
+58
+00:03:14,000 --> 00:03:16,000
+Notice I clicked applied and the whole thing just went off.
+
+59
+00:03:17,000 --> 00:03:19,000
+Uh, this is an emulator after all.
+
+60
+00:03:19,000 --> 00:03:25,000
+So keep in mind, in this particular device it's easy to do, but in other devices it could get more
+
+61
+00:03:25,000 --> 00:03:26,000
+complex.
+
+62
+00:03:26,000 --> 00:03:32,000
+If you set up IPS such as snort, which is the one I recommended when I taught the class.
+
+63
+00:03:32,000 --> 00:03:34,000
+That's more of a robust system.
+
+64
+00:03:34,000 --> 00:03:38,000
+It does support a lot more options than what this has, but if you're a small business and you just
+
+65
+00:03:38,000 --> 00:03:41,000
+need an IPS, this is the best one to use and for you.
+
+66
+00:03:41,000 --> 00:03:42,000
+Just practice in a lab.
+
+67
+00:03:42,000 --> 00:03:45,000
+This is the easiest way to set up an IPS.
+
diff --git a/26 - Labs/028 Configuring web filters_en.srt b/26 - Labs/028 Configuring web filters_en.srt
new file mode 100644
index 0000000000000000000000000000000000000000..7ae46d86d840e4a6fad75555530834ec77b36426
--- /dev/null
+++ b/26 - Labs/028 Configuring web filters_en.srt
@@ -0,0 +1,324 @@
+1
+00:00:00,000 --> 00:00:03,000
+One of the most important things you have to do is going to be filtering.
+
+2
+00:00:03,000 --> 00:00:10,000
+Filtering web content as your users go on the internet and start utilizing all different kinds of websites,
+
+3
+00:00:10,000 --> 00:00:12,000
+they might be going to sites they shouldn't be going to.
+
+4
+00:00:12,000 --> 00:00:14,000
+That's a good network administrator.
+
+5
+00:00:14,000 --> 00:00:16,000
+You want to limit where they can go.
+
+6
+00:00:16,000 --> 00:00:18,000
+Remember, the more choices, the more mistakes.
+
+7
+00:00:18,000 --> 00:00:21,000
+So what we want to do is we want to do what's called web filtering.
+
+8
+00:00:21,000 --> 00:00:25,000
+So web filtering basically says you're blocked from these particular sites.
+
+9
+00:00:25,000 --> 00:00:27,000
+Now some devices supports this.
+
+10
+00:00:27,000 --> 00:00:29,000
+You would need a device that does support it.
+
+11
+00:00:29,000 --> 00:00:33,000
+I do have a Cisco device that we're going to be using that does support web filtering.
+
+12
+00:00:33,000 --> 00:00:37,000
+It's really easy to configure, and it's just a policy that you have to set up.
+
+13
+00:00:37,000 --> 00:00:42,000
+Now, once again, as with some of the other labs I did utilizing these devices, you're going to have
+
+14
+00:00:42,000 --> 00:00:45,000
+to make sure you keep an updated Cisco license.
+
+15
+00:00:45,000 --> 00:00:47,000
+So you always receive the latest updates from Cisco.
+
+16
+00:00:48,000 --> 00:00:49,000
+So let me show you how to do it.
+
+17
+00:00:49,000 --> 00:00:50,000
+It's really simple.
+
+18
+00:00:50,000 --> 00:00:52,000
+So just go to Google.
+
+19
+00:00:52,000 --> 00:00:54,000
+Let's do Cisco Switch emulator online.
+
+20
+00:00:54,000 --> 00:00:55,000
+It doesn't have to be switch.
+
+21
+00:00:55,000 --> 00:00:58,000
+I mean that's what I put in the Cisco emulator online.
+
+22
+00:00:58,000 --> 00:00:59,000
+It's really what I'm looking for.
+
+23
+00:00:59,000 --> 00:01:02,000
+Uh online device emulator first link here.
+
+24
+00:01:02,000 --> 00:01:04,000
+And the device I want to use.
+
+25
+00:01:05,000 --> 00:01:09,000
+That does support this particular option because you got to find the right device.
+
+26
+00:01:09,000 --> 00:01:10,000
+This one does.
+
+27
+00:01:10,000 --> 00:01:13,000
+RV 340 dual wing router.
+
+28
+00:01:13,000 --> 00:01:14,000
+This one supports.
+
+29
+00:01:14,000 --> 00:01:16,000
+I'm just going to use the first link here.
+
+30
+00:01:17,000 --> 00:01:20,000
+And here we go with the interface that comes on.
+
+31
+00:01:20,000 --> 00:01:23,000
+So what I'm going to do here in order to set up the web filter is I'm going to go to security.
+
+32
+00:01:25,000 --> 00:01:27,000
+And you notice we have web filtering.
+
+33
+00:01:27,000 --> 00:01:29,000
+Now this is pretty cool.
+
+34
+00:01:30,000 --> 00:01:31,000
+So you got to turn it on.
+
+35
+00:01:32,000 --> 00:01:38,000
+Now that it's on, what I want to do is I want to put a message that like, let's say somebody goes
+
+36
+00:01:38,000 --> 00:01:41,000
+to a website that I'm going to be filtering out, what do they see?
+
+37
+00:01:41,000 --> 00:01:50,000
+What I'm going to say this site is blocked by your manager.
+
+38
+00:01:51,000 --> 00:01:58,000
+You know, so that's what they're going to say is just going to get a message on the screen that says
+
+39
+00:01:58,000 --> 00:01:59,000
+that.
+
+40
+00:01:59,000 --> 00:02:01,000
+Now what do you want to block?
+
+41
+00:02:01,000 --> 00:02:03,000
+Well, let's click on add here on web Filter and Policy.
+
+42
+00:02:04,000 --> 00:02:07,000
+And we're going to say website.
+
+43
+00:02:08,000 --> 00:02:10,000
+And want to make sure we enable it.
+
+44
+00:02:10,000 --> 00:02:13,000
+And now we can go and block whatever we need so we can say edit.
+
+45
+00:02:14,000 --> 00:02:16,000
+Right now it's on law.
+
+46
+00:02:16,000 --> 00:02:21,000
+So it's basically just blocking some like dead sites and stuff like that, malware sites, phishing
+
+47
+00:02:21,000 --> 00:02:21,000
+sites.
+
+48
+00:02:22,000 --> 00:02:26,000
+So you can actually go in there and just check the box to check all these things.
+
+49
+00:02:26,000 --> 00:02:28,000
+So you should go through all the options.
+
+50
+00:02:28,000 --> 00:02:29,000
+Adult and mature content.
+
+51
+00:02:29,000 --> 00:02:32,000
+There's no need for -- websites during the day.
+
+52
+00:02:32,000 --> 00:02:34,000
+So let's block all that stuff.
+
+53
+00:02:34,000 --> 00:02:35,000
+Uh, business and investment.
+
+54
+00:02:35,000 --> 00:02:39,000
+And again, this is going to be dependent on who's in your network and who you want to apply this policy
+
+55
+00:02:39,000 --> 00:02:39,000
+to.
+
+56
+00:02:39,000 --> 00:02:41,000
+So maybe maybe we want to leave that.
+
+57
+00:02:42,000 --> 00:02:45,000
+Let's block lifestyle and culture.
+
+58
+00:02:45,000 --> 00:02:47,000
+Let's block illegal, questionable stuff.
+
+59
+00:02:47,000 --> 00:02:49,000
+Obviously that's it.
+
+60
+00:02:49,000 --> 00:02:51,000
+So we want to block.
+
+61
+00:02:51,000 --> 00:02:52,000
+Let's apply that.
+
+62
+00:02:52,000 --> 00:02:54,000
+So that's what we want to block.
+
+63
+00:02:55,000 --> 00:02:58,000
+Uh that's all the things that's listed there applied to group.
+
+64
+00:02:58,000 --> 00:03:01,000
+Now you should go and set up different groups.
+
+65
+00:03:01,000 --> 00:03:04,000
+But IP groups is generally going to be set up within the router.
+
+66
+00:03:04,000 --> 00:03:05,000
+And that's it.
+
+67
+00:03:05,000 --> 00:03:08,000
+You just leave it on, you say okay and that's all it is.
+
+68
+00:03:08,000 --> 00:03:16,000
+So now basically anybody that's connected to this particular router now the RV 340 is a basically it's
+
+69
+00:03:16,000 --> 00:03:20,000
+it's a router that you can purchase and utilize in your network now.
+
+70
+00:03:21,000 --> 00:03:22,000
+Whoever is connected to this.
+
+71
+00:03:22,000 --> 00:03:25,000
+If they try to go to any of those websites that we blocked.
+
+72
+00:03:25,000 --> 00:03:26,000
+Now, I did apply and I didn't save it.
+
+73
+00:03:26,000 --> 00:03:28,000
+Once again, it's an emulator.
+
+74
+00:03:28,000 --> 00:03:28,000
+It doesn't save it.
+
+75
+00:03:28,000 --> 00:03:34,000
+So anybody that tries to connect to these bad websites is going to get that message that I put that
+
+76
+00:03:34,000 --> 00:03:36,000
+says, hey, this is blocked by your manager.
+
+77
+00:03:36,000 --> 00:03:39,000
+So web filtering is really important.
+
+78
+00:03:39,000 --> 00:03:40,000
+Uh, I said this during the class.
+
+79
+00:03:40,000 --> 00:03:43,000
+My mother always told me the more choices, the more mistakes.
+
+80
+00:03:43,000 --> 00:03:45,000
+So it's a good network administrator.
+
+81
+00:03:45,000 --> 00:03:47,000
+Let's remove the choices so they don't make any mistakes.
+
diff --git a/27 - Mock Exam/001 Mock Exam.html b/27 - Mock Exam/001 Mock Exam.html
new file mode 100644
index 0000000000000000000000000000000000000000..4b34574615672d6287f538584e11969e752b4894
--- /dev/null
+++ b/27 - Mock Exam/001 Mock Exam.html
@@ -0,0 +1,479 @@
+
+
+
+
+
+
+ Quiz
+
+
+
+
+
+
+
+
+ Score: 999 of
+ 999%
+
+ Correct: 999
+ Incorrect: 999
+
+
+
+
+
+
+
+
+
+