Vulnerability Assessment Training: Protecting Your Organization

Learning Tree International AB, i Stockholm (+3 orter)
Längd
4 dagar
Längd
4 dagar
Få mer information om utbildningen, arrangörerna svarar oftast inom 48h 👍

Beskrivning av: Vulnerability Assessment Training: Protecting Your Organization

In this Vulnerability Assessment training course, you learn how to create a network security vulnerability assessment checklist by exposing infrastructure, server, and desktop vulnerabilities, create and interpret reports, configure vulnerability scanners, detect points of exposure, and ultimately prevent network exploitation.

To minimise costly security breaches, organisations need to evaluate the risk in their enterprise from an array of vulnerabilities. Attend this 4-day course and learn to minimise your organization's exposure to security breaches.

  • Basic understanding of network security and security issues at the level of:
    • System and Network Security Training • course 468
  • You should have an understand of:
    • TCP/IP networking
    • Network security goals and concerns
    • The roles of firewalls and intrusion detection systems

  • This course covers multiple domains on the (ISC)2 CISSP certification exam
  • If you are interested in achieving the CISSP certification, see CISSP® Training and Certification Prep Course • course 2058

Vulnerability Assessment Training: Protecting Your Organization Delivery Methods

  • After-course instructor coaching benefit
  • Learning Tree end-of-course exam included

Vulnerability Assessment Training: Protecting Your Organization Course Benefits

  • Detect and respond to vulnerabilities, and minimise exposure to security breaches
  • Employ real-world exploits and evaluate their effect on your systems
  • Configure vulnerability scanners to identify weaknesses
  • Analyse the results of vulnerability scans
  • Establish an efficient strategy for vulnerability management

Vulnerability Assessment Course Outline

Fundamentals

Introduction

  • Defining vulnerability, exploit, threat and risk
  • Creating a vulnerability report
  • Conducting an initial scan
  • Common Vulnerabilities and Exposure (CVE) list

Scanning and exploits

  • Vulnerability detection methods
  • Types of scanners
  • Port scanning and OS fingerprinting
  • Enumerating targets to test information leakage
  • Types of exploits: worm, spyware, backdoor, rootkits, Denial of Service (DoS)
  • Deploying exploit frameworks

Analysing Vulnerabilities and Exploits

Uncovering infrastructure vulnerabilities

  • Uncovering switch weaknesses
  • Vulnerabilities in infrastructure support servers
  • Network management tool attacks

Attacks against analyzers and IDS

  • Identifying Snort IDS bypass attacks
  • Corrupting memory and causing Denial of Service

Exposing server vulnerabilities

  • Scanning servers: assessing vulnerabilities on your network
  • Uploading rogue scripts and file inclusion
  • Catching input validation errors
  • Performing buffer overflow attacks
  • SQL injection
  • Cross–Site Scripting (XSS) and cookie theft

Revealing desktop vulnerabilities

  • Scanning for desktop vulnerabilities
  • Client buffer overflows
  • Silent downloading: spyware and adware
  • Identifying design errors

Configuring Scanners and Generating Reports

Implementing scanner operations and configuration

  • Choosing credentials, ports and dangerous tests
  • Preventing false negatives
  • Creating custom vulnerability tests
  • Customising Nessus scans
  • Handling false positives

Creating and interpreting reports

  • Filtering and customising reports
  • Interpreting complex reports
  • Contrasting the results of different scanners

Assessing Risks in a Changing Environment

Researching alert information

  • Using the National Vulnerability Database (NVD) to find relevant vulnerability and patch information
  • Evaluating and investigating security alerts and advisories
  • Employing the Common Vulnerability Scoring System (CVSS)

Identifying factors that affect risk

  • Evaluating the impact of a successful attack
  • Determining vulnerability frequency
  • Calculating vulnerability severity
  • Weighing important risk factors
  • Performing a risk assessment

Managing Vulnerabilities

The vulnerability management cycle

  • Standardising scanning with Open Vulnerability Assessment Language (OVAL)
  • Patch and configuration management
  • Analysing the vulnerability management process

Vulnerability controversies

  • Rewards for vulnerability discovery
  • Markets for bugs and exploits
  • Challenge programs

Intresseanmälan

Beställ information

Fyll i formuläret för att få mer information om Vulnerability Assessment Training: Protecting Your Organization, direkt från arrangören. Det är gratis och inte bindande!

reCAPTCHA logo Den här hemsidan är skyddad av reCAPTCHA och Googles Integritetspolicy och Användarvillkor tillämapas.
Learning Tree International AB
Fleminggatan 7
112 26 Stockholm

Learning Tree International

Learning Tree är ett internationellt utbildningsföretag med över 40 års erfarenhet av att leverera utbildning till yrkesverksamma IT-proffs, projektledare, verksamhetsutvecklare och chefer. Vi erbjuder allt från enstaka kurser till globala utbildningsprogram, och vi hjälper våra kunder att införa hållbara processer som fungerar idag och förbereder...

Läs mer om Learning Tree International AB och visa alla utbildningar.

Highlights