Sign-up to receive a free Intro to Virtualization training course.
CompTIA Security+ Training
Industry Recognized Training: 2010, 2009 Editor's Best and Community Choice Award from Windows IT Pro

CompTIA Security+ Training

Take your networking knowledge to the next level and become a Security expert in one of the fastest growing areas of IT. This course offers lessons that will cover everything you need to prepare for your SY0-301 certification exam.

This Course Includes All of the Following:

  • Instant Online Access to Your TrainingInstant Online Access Begin Streaming Your Training Immediately
  • Physical Media Shipped Directly to Your DoorstepPhysical Media Shipped Directly to Your Doorstep For Free, Worldwide
  • Free Award-Winning Practice Exam Transcender Practice Exam Practice For Your Exam With This Award-Winning Exam Preparation
  • $297
  • Paying with Purchase Order?
  • View Outline
  • TrainSignal Exclusive 90 Day Total Experience Guarantee

    Our Total Experience Guarantee is Very Simple

    If you are not satisfied with our training, our service, or our support FOR ANY REASON, return your course within 90 days for a FULL REFUND (up to $397). You have my word.

    Scott Skinger Founder & President of TrainSignal, Inc.

Overview

  • Train Anywhere You Want Mobile On-Demand Training Train Where You Want, When You Want
  • Additional Training Formats Additional Training Formats High Resolution Video, MP3 Audio and PDF of Instructor Notes
  • Watch a Demo

Security issues and concerns are an ever-changing aspect of IT. This latest Security+ course has been designed to meet the expectations of the new CompTIA exam, and to provide networking professionals with the fundamental concepts necessary to anticipate & address security risks.

More and more companies are requiring potential employees to be certified to ensure skill competency for positions such as, security architect, sys admin, information assurance tech, and more.

Highlights of the Course:

  • Network Security with Compliance
  • Operational Security
  • Threats and Vulnerabilities
  • Application, Data and Host Security
  • Access Control and Identity Management
  • Cryptography and Much More!

Break into the IT security field by learning everything you need to know to pass the SY0-301 exam.

Professional Training

  • Nearly 12 Hours (11 Hours, 59 Minutes, 18 Seconds) of CompTIA Security+ Training Videos Jam Packed on 1 DVDs!
  • Multiple File Formats Make it convenient for you to learn anywhere you go! iPod Video, Mp3 Audio, .WMV & high quality .AVI video
  • PDF of Instructor Notes allow you to follow along with the videos and take more organized notes
  • Instant Access Online to the entire training course

Course Outline

CompTIA Security+ Training - Course Outline

Lesson 1 - Getting Started with CompTIA Security+ Training

In this lesson you will meet your instructor and you will find out what you will be doing in the lessons.

  • About Your Instructor
  • About This Course
Lesson 2 - Introduction to IT Security

What is IT Security and why do you need to know about it? This lesson answers those questions and defines basic security terminology that will be used throughout the course.

  • What is IT Security?
  • The Information Security Triad – CIA
  • The AAA Protocol
Lesson 3 - Types of Attacks

As an IT security professional you need to have a firm understanding of all possible threats to your computers and to company infrastructure as a whole. This lesson introduces you to a wide range of attack types, including attacks on data in transit and attacks via email and other communications. You will also get some mitigation tips to help prevent and stop attacks.

  • Spoofing/Poisoning
  • Pharming
  • Man-in-the-Middle
  • Replay Attack
  • Denial of Service (DoS)
  • Distributed Denial of Service (DDoS)
  • Smurf Attack
  • Scanners and Sniffers
  • Spam
  • Phishing
  • Privilege Escalation
  • Transitive Access
  • Client-side Attacks
Lesson 4 - Malware Prevention and Cleanup

Malware has many variations that you will need to keep track of as an IT security professional. This lesson introduces you to each malware type, and then moves on to talk about how to lower the likelihood of malware infections and how to deal with malware after an infection occurs.

  • Malware
  • Viruses
  • Worms
  • Trojans
  • Spyware
  • Adware and Pop-ups
  • Rootkits
  • Backdoors
  • Logic Bombs
  • Botnets
  • Ransomware
  • Malware Mitigation
  • Malware Removal
Lesson 5 - Network Device Security

This lesson discusses what each network device is, what security purpose it serves, some security best practices for it, and if each device is physical or software based. The strengths and weaknesses of different types of firewalls are also detailed. You will also watch a demonstration of using a web browser’s built-in content inspection and filtering.

  • Firewalls
  • Routers
  • Switches
  • Load Balancers
  • Proxies
  • Web Security Gateways
  • VPN Concentrators
  • Network-based Intrusion Detection Systems (NIDS)
  • Network-based Intrusion Prevention Systems (NIPS)
  • Kinds of NIDS and NIPS
  • Other Security Appliances
  • Protocol Analyzers/Sniffers
  • Host-based Filtering Tools
Lesson 6 - Secure Network Administration

This lesson will familiarize you with what is available to manage your network securely. Also, the instructor demonstrates how to configure a rule on a Windows client firewall both from the graphical user interface and the command line.

  • Rule-based Management
  • Access Control Lists (ACLs)
  • Firewall Rules
  • Secure Router Configuration
  • Port Security
  • Flood Guards and Loop Protection
  • Network Separation and Network Bridging
  • Log Analysis
Lesson 7 - Secure Network Design

In this lesson, you will begin thinking about using security zones to help control who can access what from inside and outside your network. Then, you will get an overview of different network design elements that can be used to create and secure these zones.

  • Security Zones
  • DMZ (Demilitarized Zone)
  • Subnetting
  • Virtual Local Area Network (VLAN)
  • Network Address Translation (NAT)
  • Remote Access
  • Virtual Private Network (VPN)
  • Telephony
  • Network Access Control (NAC)
  • Virtualization
  • Cloud Computing
Lesson 8 - TCP/IP Protocols and Port Security

This lesson starts with a quick review of TCP/IP and then moves on to discuss the common protocols that work at the different TCP/IP layers. Each protocol is evaluated for its strength and any important security considerations are listed. There is also a chart of the most common protocols and their port numbers you will use as an IT professional.

  • TCP/IP
  • FTP
  • SSH and SCP
  • Telnet
  • SMTP
  • DNS
  • TFTP
  • HTTP
  • SFTP
  • SNMP
  • HTTPS
  • FTPS
  • SSL and TLS
  • TCP
  • UDP
  • IP
  • ICMP
  • ARP
  • TCP/IP Ports to Remember
  • IPSec
Lesson 9 - Attacks on Wireless Networks

After watching this lesson you should be motivated to add extra security to your wireless networks. You will get definitions of the common attacks on 802.11 and Bluetooth wireless networks along with some tips on how to lower the likelihood of these attacks.

  • Rogue Access Points
  • Evil Twin
  • Wardriving
  • Warchalking
  • IV Attack
  • Packet Sniffing
  • Attacks on Bluetooth
  • Interference
Lesson 10 - Securing Wireless Networks

Now that you know what kind of wireless attacks are out there, learn what you can do about them. This lesson teaches you about ways to secure your wireless network with encryption, authentication, and configuration. Also, learn which encryption protocols are preferred and which should be avoided.

  • IEEE 802.11x Wireless Standards
  • WEP
  • WPA and WPA2
  • TKIP
  • CCMP
  • WAP
  • EAP, PEAP, and LEAP
  • Securing Wireless Routers and Access Points Best Practices
  • Change the SSID and Turn off SSID Broadcast
  • Consider Using MAC Filtering
  • Work with Antenna Placement and Power Level Controls
Lesson 11 - Host Security

Servers and clients have their own set of security vulnerabilities. This lesson teaches you what needs to be done to harden your physical, virtual, and mobile hosts.

  • Antimalware
  • Host-based Firewalls
  • Updates and Patch Management
  • Disabling Unused Services
  • Users and Accounts
  • Virtualization
  • Host Software Baselining
  • Securing Servers
  • Securing Mobile Devices
Lesson 12 - Securing Applications

Every application installed on a host should be considered as a possible security issue. This lesson explains the most common attacks on applications, and how to avoid them. The lesson will then go on to discuss different tasks to strengthen application security.

  • Cookies
  • Session Hijacking
  • Header Manipulation
  • Cross-site Scripting (XSS)
  • Cross-site Request Forgery (XSRF or CSRF)
  • Injection Attacks
  • Preventing Injection Attacks
  • Buffer Overflow
  • Java Applets and JavaScript
  • ActiveX Controls
  • Demo: Internet Explorer Security Settings
  • Malicious Add-ons, Attachments, and Zero Day Exploits
  • Secure Coding Concepts
  • Fuzzing
  • Application Hardening
Lesson 13 - Data Security

Special care needs to be taken to insure data is protected. This lesson covers when and where to use different software-based and hardware-based data encryption methods. Also covered is the use of data loss prevention systems.

  • Data Loss Protection (DLP)
  • Individual Files/Folders Encryption
  • Full Disk/Whole Disk Encryption
  • Database Encryption
  • Removable Media Encryption
  • Mobile Device Encryption
  • Trusted Platform Module (TPM)
  • Hardware Security Module (HSM)
  • USB Encryption
  • Hard Drive Encryption
  • Encryption Key Management
  • Data in the Cloud
Lesson 14 - Authentication, Authorization, and Access Control

The three A’s: authentication, authorization, and access control are fundamental to managing who can interact with what in your environment. Learn the best practices to keep the bad-guys (internal or external) from accessing what they shouldn’t. This is done by using credentials that could be something you know, something you have, or something you are.

  • Identification vs. Authentication
  • Authentication and Authorization
  • Something You Know, Something You Have, and Something You Are
  • Single Factor vs. Multifactor Authentication
  • Types of Access Control
  • Information Models
  • Mandatory Vacations
  • Job Rotation
  • Separation of Duties
  • Trusted OS
Lesson 15 - Physical and Environmental Security

This lesson teaches you what your company should be considering for physical and environmental security. Because all the money and effort spent on technical controls are useless if the servers overheat or if someone walks right in and steals your server.

  • Physical Security
  • Fencing
  • Mantraps
  • Access Lists
  • Proximity Readers
  • Video Surveillance and Monitoring
  • Hardware Locks
  • Environmental Security
  • HVAC Considerations
  • Hot and Cold Aisles
  • Environmental Monitoring and Controls
  • Fire Suppression
  • Power Systems
  • Electromagnetic Emissions: Interference and Shielding
Lesson 16 - Authentication Services

There are several different technologies that handle authentication for the access of resources and data. Watch this lesson to learn about both newer and older authentication service options.

  • Introduction to Authentication Services
  • RADIUS
  • TACACS+
  • TACACS and XTACACS
  • Kerberos
  • LDAP
Lesson 17 - User Account Management

It is important to have user accounts that are secure but allow the users to access what they need for their job. Learn the concepts behind setting up and maintaining well configured user accounts in this lesson.

  • Privilege Management
  • Group Based Privileges
  • User Account Policy
  • Password Policies
Lesson 18 - Risk Management

All organizations small and large need to uncover and then decide how to manage risks. This lesson covers how to assess different risks, calculate their impact, and the options for handling those risks.

  • Risk Management Vocabulary
  • Risk Management Steps
  • Impact Analysis
  • Risk Calculation
  • Options for Handling Risk
  • Control Types
Lesson 19 - Threat and Vulnerability Assessment and Detection

In this lesson you will learn about different assessment types, techniques, and tools for discovering security threats and vulnerabilities.

  • Assessment Types
  • Assessment Techniques
  • Tools
  • Vulnerability Scanning
  • Penetration Testing
  • Black, White, and Gray Box Testing
Lesson 20 - Risk Mitigation and Deterrence

Now that you have discovered and assessed risk, this lesson talks about deterring and mitigating those risks using hardening, policies, technical controls, and more.

  • Security Posture
  • Manual Bypassing of Electronic Controls
  • Change Management
  • Implement Security Controls Based on Risk
  • Detection vs. Prevention Controls
  • Hardening
  • Perform Routine Audits
  • Data Loss or Theft Prevention
  • Security Policies
  • Privacy Policies
  • Acceptable Use Policies (AUP)
  • Other Policies
Lesson 21 - Log Monitoring and Reporting

One way to mitigate risk and help keep an eye on threats in real time is with log monitoring and reporting. In this lesson you will learn about different log file types and how to manage logs in order to gain useful information from them.

  • Reporting
  • Monitoring and Analyzing Logs
  • Log Types
  • Logs Management
Lesson 22 - Business Continuity

Business continuity planning focuses on ensuring continued business operations are available day-to-day, because every minute of system downtime is money lost. This lesson introduces business continuity concepts so you can start planning for expected and unexpected IT failures or attacks that lead to breaks in operation.

  • Business Continuity vs. Disaster Recovery
  • Business Continuity Planning (BCP) and Testing
  • Business Impact Analysis
  • IT Contingency Planning
  • Continuity of Operations
  • Succession Planning
Lesson 23 - Disaster Recovery Planning

Having a well thought out and tested disaster recovery plan allows an organization to get their infrastructure and/or data back up and running in the event of a disaster. This lesson talks about both the physical network elements and the preparation concepts for disaster recovery planning.

  • Disaster Recovery Plan
  • Service Level Agreement (SLA)
  • Utilities
  • Backup Types
  • Backup Plans
  • Backup Storage Options
  • Recovering from Backups
  • Backup and Recovery Considerations
  • Redundancy
  • Fault Tolerance
  • RAID: Redundant Array of Independent Disks
  • Load Balancing
  • Clustering
  • Alternative/Backup Sites
Lesson 24 - Incident Response

Even expensive preparation and planning can’t guarantee an incident won’t happen. Learn about what goes into a good incident response plan in order to control the damage and data loss caused by incidents. This lesson also discusses the basics of computer forensics for investigating and analyzing computer systems that have been attacked.

  • Incident Response Plan
  • Damage and Loss Control
  • Chain of Custody
  • First Responder
  • Basic Forensic Procedures
Lesson 25 - User Education

Users have the ability to greatly help or hinder the security efforts of an organization. The best written policies are useless if users don’t follow them. That is why in this lesson you will learn about security awareness and training that needs to take place at all levels of the company.

  • Security Policy Training and Procedures
  • Threat Awareness
  • Personally Identifiable Information (PII)
  • Regulatory Compliance
  • Social Networking
  • Peer to Peer (P2P) File Sharing
  • User Habits
  • Information Classification
  • Data Labeling, Handling, and Disposal
Lesson 26 - Social Engineering

To attack your organization, social engineering attackers exploit the gullibility, niceness, or even enthusiasm of your staff. In this lesson you will learn about social engineering techniques that all employees need to be aware of and prepared for.

  • Social Engineering Overview
  • Impersonation
  • Tailgating
  • Dumpster Diving
  • Shoulder Surfing
  • Phishing
  • Hoaxes
  • Reverse Social Engineering
Lesson 27 - Cryptography Concepts

In this lesson you will learn the basics of what cryptography is and how it works. The lesson describes symmetric cryptography, asymmetric cryptography, and cryptographic hashing.

  • Cryptography Overview
  • Symmetric vs. Asymmetric Encryption
  • Digital Signatures
  • Non-repudiation
  • Encryption/Decryption Methods
  • Cryptographic Hashing
  • Transport Encryption
  • Steganography
  • Use of Proven Technologies
Lesson 28 - Cryptography Tools

In this lesson you will apply the information from the cryptography concepts lesson to learn about several cryptography algorithms and their comparative strengths.

  • DES
  • 3DES
  • RC4
  • AES
  • Blowfish
  • Twofish
  • Diffie-Hellman
  • RSA
  • ECC
  • Collisions
  • SHA
  • MD5
  • RIPEMD
  • HMAC
  • SSL/TLS and HTTPS
  • SSH
  • IPSec
  • Wi-Fi Authentication
  • PGP/GPG
  • NTLM and NTLMv2
  • One-time Pads (OTP)
  • CHAP and PAP
  • Whole Disk Encryption
  • Comparative Strengths of Algorithms
Lesson 29 - Public Key Infrastructure (PKI) Concepts

This lesson covers the basic concepts of public key infrastructure which is a common way to provide data integrity, non-repudiation, and data confidentiality.

  • Public Key Infrastructure (PKI) Overview
  • Digital Certificates
  • Certificate Authorities (CA)
  • How PKI Works
  • Registration Authorities
  • Certificate Revocation Lists (CRL)
  • Recovery Agents
  • Key Escrow
Lesson 30 - PKI Implementation

Building on what you learned in the PKI concepts lesson this lesson goes into the policies, practices, and management considerations for implementing PKI.

  • Publicly Trusted Certificate Authorities
  • Internal Certificate Authorities
  • Working with Registration Authorities
  • Key Management
  • Certificate Management
  • Trust Models
Lesson 31 - Preparing for Your CompTIA Security+ SY0-301 Certification Exam

Watch this lesson if you are interested in taking the Security+ Test. This lesson gives an overview of the exam and how the exam objectives match up with the lessons in this course.

  • About the Exam
  • Mapping Exam Objectives to this Course
  • Studying for the Exam
  • Test Day Tips
Lesson 32 - Next Steps

You have finished watching the course, now what? In this lesson, we’ll look back at what we covered and discuss additional materials you may want to consult going forward beyond certification.

  • What We Have Covered in This Course
  • My Favorite Supporting Resources
  • Get Certified
  • Continue Learning
  • Join the Community

Certified Instruction

Certified Instructor Lisa Szpnuar

Lisa Szpnuar (CompTIA Security+ SY0-201 and SY0-301, CompTIA A+ 2009, MCTS)

Lisa started her career in education as an elementary school computer teacher and librarian, but as the most technically savvy person in the school she also took over the helpdesk and network administrator roles, concurrently launching her career in IT. Lisa specializes in systems design and security, and holds a Master of Science in Computer Science degree as well as a Bachelor degree in Education. Her fun and engaging teaching style makes learning complex concepts a snap. Working for TrainSignal, Lisa gets to live out both of her passions for technology and education. She gets to keep up with the latest technologies and help her students do the same.

"...I used your training videos to acquire CompTIA Network+ and Linux+ certification within 2 months after receiving the video library..."

Recently I used several of your Microsoft Windows Server 2003 videos for various exam preparation topics.  I used the videos to assist a co-worker with his MCSE training (to which he has passed all 4 core exams).  Our WAN Security instructor has used nearly all of the CCNP videos to further his education and certification levels.

On a personal note, I used your training videos to acquire CompTIA Network+ and Linux+ certification within 2 months after receiving the video library.  Those are the kinds of results my staff and I look for in quality training materials.  We gladly recommend TrainSignal to students, staff, and other IT Professionals.

Darrell Matthews Department Chair, Information Technology and Security,Sampson Community College
"Your way of running business is a rare example..."

There truly is power in a good name and a way of running business. Good impressions and positive experiences with a company definitely affect how people think when they think of your name - in this case, TrainSignal.

All that is to say thank you and that I will truly enjoy the material. I have studied all the other many hours diligently and will continue on my certification path.

You guys are doing it right; it's great to take part in your program and business.

John Archer
"I am on my way to becoming an MCSE and have found your videos very informative. However, your service deserves even more praise."

I inadvertently ordered two of the same course on Routing and Remote Access and when I discovered my mistake, I was very upset.

Internet based companies are often hard to deal with. If you try to return something, they put you off -sometimes indefinitely. I was almost sure that I would encounter problems when I attempted to exchange the video.

I called Ashley on the phone and informed her of my intent to exchange the duplicate video for another. She told me that she would send the other video when I returned mine.

I sent the video back by UPS and within a few days I received a package with the new Active Directory tutorial movie. I was so impressed that your company did not try to hold the movie hostage or to delay sending it. Even though I am an avid supporter of technology, I have to agree with those who say that the age of impersonal commerce has opened doorways to poor service.

I hope your company is successful and that others realize the benefit of doing business with someone they can trust!

Sincerely,

Nancy Ashley Ware
"TrainSignal products not only teach me how to maintain my network, I actually gain understanding that is invaluable for the tests as well..."

I just wanted to send in my thanks. It’s really nice to have a product out there for net admins that really delivers.

Everyone else seems to brag about how you can use their products to pass a test. I've taken and passed several tests, and few contained the content I need on a day-to-day basis.

TrainSignal products not only teach me how to maintain my network, I actually gain understanding that is invaluable for the tests as well. I bought your product at my previous employer and will buy it for my current employer as funds become available.

Though your product is amazing, I would like to make one request that I feel would complete the package. Most admins are clueless when it comes to scripting.

Everyone seems to have tons of advanced scripting, but just like everything else, there are little to no explanations for the beginner. Could you please consider adding something in that area to your training? Keep up the good work.

Thanks

David Morehead www.wcsmiami.org
"The Knowledge learned from the A+ course allowed me to sucessfully pass and update to the new A+ 2006..."

Yes, I have worked in the IT field for over 5 years and this training video was a refresher from the older A+ Cert. I always keep my certifications and training as current as possible. I believe this always gives you a competitive edge in the workplace. My A+ along with several other certifications and a BS Degree always seem to help when it's counts.

Thanks,

Toby Leigh

Looking For Volume User Licensing For CompTIA Security+ Training?

24/7 Instant Access to Individual Courses from TrainSignal

24/7 Access to Training

Online access to all training through My Online Training, with an option for physical media.

Volume Discounts on Individual Courses from TrainSignal

Volume Discounts

Discounts start at quantities as low as 2 licenses per training course.

Scalable Licensing Model from TrainSignal

Scalable Licensing Model

License your team for specific courses that meet their needs to build a custom package of TrainSignal Training.

Call 1.888.229.5055 or Email sales@trainsignal.com

Contact us for a free volume license quote or tell us how many licenses you need and we'll show you the volume license discount immediately in your cart.

Volume Discount Pricing For CompTIA Security+ Training

# of Users% DiscountCost Per User
10%$297.00
220%$237.60
3-425%$222.75
5-930%$207.90
10-1935%$193.05
20-4940%$178.20
50+Call 1.888.229.5055