Reader small image

You're reading from  CompTIA Security+: SY0-601 Certification Guide - Second Edition

Product typeBook
Published inDec 2020
PublisherPackt
ISBN-139781800564244
Edition2nd Edition
Right arrow
Author (1)
Ian Neil
Ian Neil
author image
Ian Neil

Ian Neil is one of the world's top trainers of Security+. He is able to break down information into manageable chunks so that people with no background knowledge can gain the skills required to become certified. He has recently worked for the US Army in Europe and designed a Security+ course that catered to people from all backgrounds (not just IT professionals), with an extremely successful pass rate. He is an MCT, MCSE, A+, Network+, Security+, CASP, and RESILIA practitioner that has worked with high-end training providers over the past 23 years and was one of the first technical trainers to train Microsoft internal staff when they opened their Bucharest Office in 2006.
Read more about Ian Neil

Right arrow

Utilizing Data Sources to Support Investigations

There are many different types of data sources that cybersecurity teams can utilize to gain more knowledge and a clear understanding of how much damage has been done and the extent of the incident. Let’s look at the different types of data sources that we can search to support investigations, starting with a vulnerability scan output.

Vulnerability Scan Output

The vulnerability scanner can identify various vulnerabilities, such as software flaws, missing patches, open ports, services that should not be running, and weak passwords. This will help you avoid attacks such as SQL injection, buffer overflows, denial of service, and other type of malicious attacks. A credentialed vulnerability scan is the most effective as it provides more information than any other vulnerability scan.

SIEM Dashboards

Security Information Event Management (SIEM) dashboards are very useful to the security operations centers as they provide...

lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
CompTIA Security+: SY0-601 Certification Guide - Second Edition
Published in: Dec 2020Publisher: PacktISBN-13: 9781800564244

Author (1)

author image
Ian Neil

Ian Neil is one of the world's top trainers of Security+. He is able to break down information into manageable chunks so that people with no background knowledge can gain the skills required to become certified. He has recently worked for the US Army in Europe and designed a Security+ course that catered to people from all backgrounds (not just IT professionals), with an extremely successful pass rate. He is an MCT, MCSE, A+, Network+, Security+, CASP, and RESILIA practitioner that has worked with high-end training providers over the past 23 years and was one of the first technical trainers to train Microsoft internal staff when they opened their Bucharest Office in 2006.
Read more about Ian Neil