| Unit 1 |
IT Security Overview and CIA Triad |
| Unit 2 |
Compare Security Deployments - Security Deployment Overview |
| Unit 3 |
Compare Security Deployments - Network, Endpoint, and Application Security Systems |
| Unit 4 |
Compare Security Deployments - Agentless and Agent-Based Protections |
| Unit 5 |
Compare Security Deployments - Legacy Antivirus and Antimalware |
| Unit 6 |
Compare Security Deployments - SIEM, SOAR and Log Management |
| Unit 7 |
Container and Virtual Environments |
| Unit 8 |
Cloud-Security-Deployments |
| Unit 9 |
Describe Security Terms - Threat Intelligence |
| Unit 10 |
Describe Security Terms - Threat Hunting |
| Unit 11 |
Describe Security Terms - Malware Analysis |
| Unit 12 |
Describe Security Terms - Threat Actor |
| Unit 13 |
Describe Security Terms - Run Book Automation (RBA) |
| Unit 14 |
Describe Security Terms - Reverse Engineering |
| Unit 15 |
Describe Security Terms - Sliding Window Anomaly Detection |
| Unit 16 |
Threat-Modeling-for-Security-Operations |
| Unit 17 |
DevSec Ops Security in the Development Pipeline |
| Unit 18 |
Compare Security Concepts - Risk , Threat, Vulnerability and Exploit |
| Unit 19 |
Describe the Principles of the Defense-in-Depth Strategy - Defense-in-Depth Strategy |
| Unit 20 |
Compare Access Control Models - Access Control Modes |
| Unit 21 |
Attribute-Based-Access-Control ABAC |
| Unit 22 |
Describe terms as defined in CVSS - CVSS Metrics and Calculation |
| Unit 23 |
CVSS Temporal Metrics |
| Unit 24 |
CVSS Environmental Metrics |
| Unit 25 |
Identify the Challenges of Data Visibility (network, host, and cloud) in Detection - Cloud Data Visibility |
| Unit 26 |
Identify the Challenges of Data Visibility (network, host, and cloud) in Detection - Network Data Visibility |
| Unit 27 |
Identify the Challenges of Data Visibility (network, host, and cloud) in Detection - Endpoint Data Visibility |
| Unit 28 |
Identify Potential Data Loss from Provided Traffic Profiles - Data Loss Prevention (DLP) |
| Unit 29 |
Interpret the 5-Tuple Approach to Isolate a Compromised Host in a Grouped Set of Logs - Identify Compromised Host Using 5-Tuple |
| Unit 30 |
Compare Rule-based Detection vs. Behavioral and Statistical Detection - Signature-based vs Behavior-based Detection |
| Unit 31 |
Exam |
| Unit 1 |
Compare Attack Surface and Vulnerability - Attack Surface |
| Unit 2 |
Compare Attack Surface and Vulnerability - Vulnerabilities |
| Unit 3 |
Identify the Types of Data Provided by These Technologies - TCP Dump |
| Unit 4 |
Identify the Types of Data Provided by These Technologies - Netflow |
| Unit 5 |
Identify the Types of Data Provided by These Technologies - Next Gen Firewall |
| Unit 6 |
Identify the Types of Data Provided by These Technologies - Traditional Stateful Firewall |
| Unit 7 |
Identify the Types of Data Provided by These Technologies - Application Visibility and Control |
| Unit 8 |
Identify the Types of Data Provided by These Technologies - Web Content Filtering |
| Unit 9 |
Compare Attack Surface and Vulnerability - Attack Surface Identify the Types of Data Provided by These Technologies - Email Content Filtering |
| Unit 10 |
Describe the Impact of These Technologies on Data Visibility - Access Control List |
| Unit 11 |
Describe the Impact of These Technologies on Data Visibility - NAT/PAT |
| Unit 12 |
Describe the Impact of These Technologies on Data Visibility - Tunneling and Encapsulation |
| Unit 13 |
Describe the Impact of These Technologies on Data Visibility - TOR |
| Unit 14 |
Describe the Impact of These Technologies on Data Visibility - Encryption |
| Unit 15 |
Describe the Impact of These Technologies on Data Visibility - P2P |
| Unit 16 |
Describe the Impact of These Technologies on Data Visibility - Load Balancing |
| Unit 17 |
Describe the Uses of These Data Types in Security Monitoring - Full Packet Capture |
| Unit 18 |
Describe the Uses of These Data Types in Security Monitoring - Session Data |
| Unit 19 |
Describe the Uses of These Data Types in Security Monitoring - Transaction Data |
| Unit 20 |
Describe the Uses of These Data Types in Security Monitoring - Statistical Data |
| Unit 21 |
Describe the Uses of These Data Types in Security Monitoring - Metadata |
| Unit 22 |
Describe the Uses of These Data Types in Security Monitoring - Alert Data |
| Unit 23 |
Describe Network Attacks - Denial of Service and Distributed Denial of Service Attack |
| Unit 24 |
Describe Network Attacks - Man-in-the-Middle |
| Unit 25 |
Describe Web Application Attacks - SQL Injection |
| Unit 26 |
Describe Web Application Attacks - Command Injection |
| Unit 27 |
Describe Web Application Attacks - Cross-site Scripting |
| Unit 28 |
Security Monitoring for Social Engineering Attacks |
| Unit 29 |
Security Monitoring for Generative AI Attacks |
| Unit 30 |
Describe Endpoint-based Attacks - Buffer Overflow |
| Unit 31 |
Describe Endpoint-based Attacks - Command and Control |
| Unit 32 |
Describe Endpoint-based Attacks - Malware |
| Unit 33 |
Describe Endpoint-based Attacks - Ransomware |
| Unit 34 |
Describe the Impact of Certificates on Security - Encryption |
| Unit 35 |
Describe the Impact of Certificates on Security - Cryptanalysis |
| Unit 36 |
Describe the Impact of Certificates on Security - Symmetric Encryption & Asymmetric Encryption |
| Unit 37 |
Describe the Impact of Certificates on Security - Public Key Infrastructure (PKI) |
| Unit 38 |
Identify the Certificate Components in a Given Scenario - Certificate Components |
| Unit 39 |
Exam |
| Unit 1 |
Host-based Firewall |
| Unit 2 |
Endpoint Technologies - Host-based Intrusion Prevention System |
| Unit 3 |
Endpoint Technologies - Host-based Antivirus |
| Unit 4 |
Endpoint Technologies - Host-based AntiMalware |
| Unit 5 |
Endpoint Technologies for Host Based Analysis |
| Unit 6 |
Predictive AI in Host Based Analysis |
| Unit 7 |
Components of an Operating System - Windows Processes |
| Unit 8 |
Components of an Operating System - Windows Threads |
| Unit 9 |
Components of an Operating System - Windows Registry Database |
| Unit 10 |
Components of an Operating System - Windows Handles |
| Unit 11 |
Components of an Operating System - Windows Services |
| Unit 12 |
Components of an Operating System - Windows Users, Group and Permissions |
| Unit 13 |
Components of an Operating System - Windows Network Activity from the CLI |
| Unit 14 |
Components of an Operating System - Windows Network Activity from the GUI |
| Unit 15 |
Components of an Operating System - Linux Bash – Bourne Again Shell |
| Unit 16 |
Components of an Operating System - Linux Directory Structure |
| Unit 17 |
Components of an Operating System - Linux Basic File manipulations |
| Unit 18 |
Components of an Operating System - Linux File system permissions |
| Unit 19 |
Components of an Operating System - Linux Piping and redirection of standard I/O |
| Unit 20 |
Components of an Operating System - Linux Grep stream filter |
| Unit 21 |
Components of an Operating System - Linux processes |
| Unit 22 |
Components of an Operating System - Linux Netstat command |
| Unit 23 |
Describe the role of attribution in an investigation - Role of Attribution in an Investigation |
| Unit 24 |
Identify Type of Evidence Used Based on Provided Logs - Types of Evidence |
| Unit 25 |
Interpreting OS Application and Command Line Logs |
| Unit 26 |
Interpret the Output Report of a Malware Analysis Tool |
| Unit 27 |
Interpret Operating System, Application, or Command Line Logs to Identify an Event - Interpret Logs to Identify an Event |
| Unit 28 |
SIEM Platforms for Host Based Analysis |
| Unit 29 |
SOAR Platforms for Security Operations |
| Unit 30 |
Exam |
| Unit 1 |
Map the Provided Events to Source Technologies |
| Unit 2 |
Compare Impact and no Impact for These Items |
| Unit 3 |
Compare Deep Packet Inspection with Packet Filtering and Stateful Firewall Operation |
| Unit 4 |
Compare Inline Traffic Interrogation and Taps or Traffic Monitoring |
| Unit 5 |
Compare the Characteristics of Data obtained from Taps or Traffic Monitoring |
| Unit 6 |
Extract files from a TCP Stream when Given a PCAP File and Wireshark |
| Unit 7 |
Identify Key Elements in an Intrusion from a Given PCAP File |
| Unit 8 |
Interpreting Protocol Header Fields - Ethernet Frame |
| Unit 9 |
Interpreting Protocol Header Fields - IPv4 |
| Unit 10 |
Interpreting Protocol header fields - IPv6 |
| Unit 11 |
Interpreting Protocol Header Fields - TCP |
| Unit 12 |
Interpreting Protocol Header Fields - UDP |
| Unit 13 |
Interpreting Protocol Header Fields - ICMP |
| Unit 14 |
Interpreting Protocol Header Fields - DNS |
| Unit 15 |
Interpreting Protocol Header Fields - ARP |
| Unit 16 |
Interpret Common Artifact Elements from an Event to Identify an Alert |
| Unit 17 |
Interpret Basic Regular Expressions |
| Unit 18 |
Exam |
| Unit 1 |
Describe Management Concepts |
| Unit 2 |
Describe the Elements in an Incident Response Plan as Stated in NIST.SP800-61r2 |
| Unit 3 |
The Cyber Kill Chain (Incident Response Model) |
| Unit 4 |
NIST.SP800-61 - Preparation |
| Unit 5 |
NIST.SP800-61 - Detection and Analysis |
| Unit 6 |
NIST.SP800-61 - Containment, Eradication, and Recovery |
| Unit 7 |
NIST.SP800-61 - Post-incident Activity |
| Unit 8 |
Incident Response Stakeholders |
| Unit 9 |
Describe concepts as documented in NIST.SP800-86 |
| Unit 10 |
Identify these elements used for Network profiling - Throughput |
| Unit 11 |
Identify these elements used for Network profiling - Session Duration |
| Unit 12 |
Identify these elements used for Network profiling - Ports Used |
| Unit 13 |
Identify these elements used for Network profiling - Critical Asset Address Space |
| Unit 14 |
Identify these elements used for Host profiling - Listening Ports |
| Unit 15 |
Identify these elements used for Host profiling - Logged in Users/Services Accounts |
| Unit 16 |
Identify these elements used for Host profiling - Running Processes |
| Unit 17 |
Identify these elements used for Host profiling - Applications |
| Unit 18 |
Identify Protected Data in a Network |
| Unit 19 |
The Diamond Model (Incident Response model) |
| Unit 20 |
SOC Metrics |
| Unit 21 |
Exam |
| Unit 1 |
Bonus Exam 1 |
| Unit 2 |
Bonus Exam 2 |