
IT Fundamentals Module 5 Unit 1
Presentation
•
Computers
•
Professional Development
•
Practice Problem
•
Hard
willie reynolds
Used 4+ times
FREE Resource
19 Slides • 9 Questions
1
Module 5 / Unit 1 / Security Concerns
The Official CompTIA ITF+
(Exam FC0‑U61) Guide
2
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
Image by racorn © 123rf.com
Objectives
• Distinguish threats to the
confidentiality, integrity, and availability
of information processing systems
• Identify social engineering techniques
• Describe the importance of business
continuity and how to make systems
fault tolerant
• Explain the importance of disaster
recovery plans
2
3
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Controlling access to resources
• Balance security with accessibility
• Properties of secure information—“CIA Triad”
o
Confidentiality
o
Integrity
o
Availability
• Security threats
3
Computer Security Basics
4
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Snooping
• Eavesdropping/wiretapping/sniffing
• Social engineering/dumpster diving
4
Confidentiality Concerns
5
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Man-in-the-Middle (MitM)
• Replay
• Impersonation
5
Integrity Concerns
6
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Denial of Service (DoS)
• Power outage
• Hardware failure
• Destruction
• Serviceoutage
6
Availability Concerns
7
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Access control system
• Authentication
o
Prove that a user is who they say they are
o
Associate that person with a unique computer or network user account
• Authorization
o
Create barriers around the resource such that only authenticated users can gain access
o
Resource permissions lists
• Accounting
o
Recording when and by whom a resource was accessed
7
Authorization, Authentication, and Auditing
8
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Getting people to reveal confidential information
• Attackers often build access with piecemeal steps
• Any information about a company can be helpful in making social engineering
attacks more likely to succeed
8
Social Engineering
9
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
Impersonation, Trust, and Dumpster Diving
• Gain access by pretending to be
someone else
o
Intimidate through false rank or spurious
technical jargon
o
Exploit trust - coax and persuade
• Building trust is easier if you have
information that will convince your target
(or put them off-guard)
o
Department employee lists, job titles,
phone numbers, diary, invoices, or
purchase orders
• “Dumpster diving” for discarded company
information
9
10
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Identity fraud
o
Masquerade as someone else
o
Control accounts that are supposed to be operated by someone else
o
Exploit stolen Personally Identifiable Information (PII)
• “Shoulder surfing” to observe credentials
10
Identity Fraud and Shoulder Surfing
11
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
Defeating Social Engineering Attacks
• Training and education
• Security policies
o
Proper support procedures
o
Account and device protection—e.g.
using screen locks to prevent “lunchtime
attacks”
o
Identity badges, escorted visitors, and
secure doors
11
12
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Outages cost—financially and reputational damage
• Business continuity plans minimize outages or the effect of outages
• Fault tolerance
o
Design systems without single points of failure
o
Develop contingency plans to cope with failures
o
Provision redundant components and systems to allow failover
12
Business Continuity and Fault Tolerance
13
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Redundant Array of Independent Disks (RAID)
• Configurations to allow the storage system to tolerate individual disk unit failures
o
RAID 1—disk mirroring
o
RAID 5—striping with parity
• RAID cannot replace the need for backups
13
Data Redundancy
14
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Multiple adapter cards/ports for individual host
o
Also allows load balancing
• Multiple network paths between nodes
• Routers can detect failed links and choose alternative paths
14
Network Redundancy
15
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Dual power supplies
• Redundant circuits
• Uninterruptible Power Supply (UPS)
• Backup power generator
15
Power Redundancy
16
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Providing redundancy at the site level
• Replication can be used to synchronize data between multiple sites
16
Site Redundancy and Replication
17
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
• Plans for specific scenarios rather than overall business continuity
o
Workflows and resources
o
Wide range of possible major and minor scenarios
• Prioritization
• Data restoration
• Restoring access
17
Disaster Recovery
18
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
Review
Image by Wavebreak Media © 123rf.com
Review
• Distinguish threats to the
confidentiality, integrity, and
availability of information processing
systems
• Identify social engineering
techniques
• Describe the importance of business
continuity and how to make systems
fault tolerant
• Explain the importance of disaster
recovery plans
18
19
Copyright (c) 2018 CompTIA Properties, LLC. All Rights Reserved. | CompTIA.org
Image by racorn © 123rf.com
Examples of Common Threats
19
20
Multiple Choice
When you're sending a private message to a friend, which property of secure information ensures that only your friend can read the message?
Availability
Integrity
Confidentiality
Redundancy
21
Multiple Choice
Your favorite online game is suddenly inaccessible due to a high number of requests to the server. This is an example of an attack on which property of secure information?
Confidentiality
Integrity
Availability
Redundancy
22
Multiple Choice
You receive an email from a "friend" asking for your password to a shared streaming service. This is an example of what type of security threat?
Social engineering
Malware
Phishing
Virus
23
Multiple Choice
You attend a workshop at work about how to identify suspicious emails. This is an example of which strategy to enhance the effectiveness of security technologies?
Redundancy
User education and training
Disaster recovery planning
Encryption
24
Multiple Choice
Your computer is set up to automatically back up your files to an external hard drive every night. This is an example of your system being:
Fault tolerant
Confidential
Available
Integrated
25
Multiple Choice
Your office building has multiple internet connections to ensure that if one goes down, the others will keep the network online. This is an example of:
Confidentiality
Redundancy
Integrity
Social engineering
26
Multiple Choice
After a power outage at work, a plan is activated to switch operations to another location. This is an example of:
Redundancy
Social engineering
Disaster recovery planning
User education and training
27
Multiple Choice
You receive an email from your bank asking you to confirm your account details. You're suspicious because the email address doesn't look right. This is an example of which strategy to identify security threats?
Disaster recovery planning
User education and training
Redundancy
Social engineering
28
Dropdown
Module 5 / Unit 1 / Security Concerns
The Official CompTIA ITF+
(Exam FC0‑U61) Guide
Show answer
Auto Play
Slide 1 / 28
SLIDE
Similar Resources on Wayground
23 questions
1 Samuel 9-10
Presentation
•
Professional Development
21 questions
Comparison with as ... as
Presentation
•
University
21 questions
FAB Tính năng và lợi ích
Presentation
•
KG
22 questions
Contrações
Presentation
•
Professional Development
21 questions
Seminario: Estructura del trabajo de investigación
Presentation
•
Professional Development
21 questions
PEMANTIK Kelas Penggerak Sleman
Presentation
•
KG
24 questions
MOORE ENGAGED Presentation
Presentation
•
Professional Development
20 questions
Compañeros 1 - La Familia
Presentation
•
Professional Development
Popular Resources on Wayground
20 questions
Math Review
Quiz
•
3rd Grade
15 questions
Fast food
Quiz
•
7th Grade
20 questions
Context Clues
Quiz
•
6th Grade
20 questions
Inferences
Quiz
•
4th Grade
19 questions
Classifying Quadrilaterals
Quiz
•
3rd Grade
20 questions
Figurative Language Review
Quiz
•
6th Grade
20 questions
Equivalent Fractions
Quiz
•
3rd Grade
10 questions
Identify Fractions, Mixed Numbers & Improper Fractions
Quiz
•
3rd - 4th Grade
Discover more resources for Computers
20 questions
Guess The App
Quiz
•
KG - Professional Dev...
10 questions
Food Quiz
Quiz
•
Professional Development
11 questions
NFL Football logos
Quiz
•
KG - Professional Dev...
19 questions
Minecraft
Quiz
•
6th Grade - Professio...
20 questions
Block Buster Movies
Quiz
•
10th Grade - Professi...
40 questions
Flags of the World
Quiz
•
KG - Professional Dev...
23 questions
super heros
Quiz
•
KG - Professional Dev...
11 questions
SOCCER PLAYERS AND TEAMS
Quiz
•
KG - Professional Dev...