IT Security/Threats/Testing

< IT Security < Threats

This lesson covers security testing.

Objectives and Skills

Objectives and skills for the security testing portion of Security+ certification include:[1]

Explain the proper use of penetration testing versus vulnerability scanning.
  • Penetration testing
    • Verify a threat exists
    • Bypass security controls
    • Actively test security controls
    • Exploiting vulnerabilities
  • Vulnerability scanning
    • Passively testing security controls
    • Identify vulnerability
    • Identify lack of security controls
    • Identify common misconfigurations
    • Intrusive vs. non-intrusive
    • Credentialed vs. non-credentialed
    • False positive
  • Black box
  • White box
  • Gray box

Multimedia

  1. Watch YouTube: Penetration Testing - CompTIA Security+ SY0-401: 3.8.
  2. Watch YouTube: Vulnerability Scanning - CompTIA Security+ SY0-401: 3.8.

References

This article is issued from Wikiversity - version of the Sunday, December 13, 2015. The text is available under the Creative Commons Attribution/Share Alike but additional terms may apply for the media files.