Searching CertSprout…
Searching CertSprout…
A little curiosity goes a long way
Search certifications, learning topics, career paths, public profiles and help across CertSprout.
Showing 20 results · Page 2 for “iac”. More results are available below.
CySA+ · Security Operations
The Cyber Kill Chain lays out seven sequential stages from reconnaissance through weaponization, delivery, exploitation, installation, command and control, and actions on objectives, which i…
CySA+ · Security Operations
A security information and event management platform collects logs from across the environment, normalizes them into common fields, correlates events across sources, and raises alerts throug…
CySA+ · Security Operations
Shannon entropy measures how unpredictable the bytes in a file are, on a scale from zero to eight bits per byte. Plain text sits around four to five, compiled code around six, and compressed…
CySA+ · Vulnerability Management
An unauthenticated scan probes a host from the network, fingerprinting services and banners the way an external attacker would. It is quick and needs no access, but it guesses at versions an…
CySA+ · Vulnerability Management
The Common Vulnerability Scoring System base score combines exploitability metrics, attack vector, attack complexity, privileges required and user interaction, with impact metrics for confid…
CySA+ · Vulnerability Management
Every scanner finding or alert falls into one of four boxes. A true positive is a real issue correctly reported. A false positive is a report of something that is not actually there, wasting…
CySA+ · Vulnerability Management
Some systems cannot be fixed on schedule, whether an unsupported medical device, an industrial controller or an application whose vendor is gone. Compensating controls reduce the exploitabil…
CySA+ · Vulnerability Management
Static application security testing analyzes source code or compiled binaries without running them, catching insecure functions, hard-coded secrets and taint flows from input to dangerous si…
CySA+ · Vulnerability Management
Cross-site scripting appears as script tags or event handlers in parameters and is fixed by output encoding and content security policy. SQL injection shows single quotes, OR 1=1, UNION SELE…
CySA+ · Vulnerability Management
A zero-day vulnerability is one the vendor has had zero days to fix, either because it is being exploited before disclosure or because it was published without warning. The exposure window c…
CySA+ · Incident Response and Management
NIST SP 800-61 organizes response into four phases that the exam breaks into six steps. Preparation builds the plan, the team, the tooling and the playbooks before anything happens. Detectio…
CySA+ · Incident Response and Management
Evidence disappears at different speeds, so collect the most fragile first. CPU registers and cache go in nanoseconds, then RAM contents, running processes, network connections and routing t…
CySA+ · Incident Response and Management
Any evidence that might reach a courtroom, a regulator or a disciplinary hearing needs a documented, unbroken history. Record who collected it, when, where and how, compute a hash of every i…
CySA+ · Incident Response and Management
Once an incident is confirmed, the pressure is to pull the plug, but containment decisions have costs. Isolating a host stops lateral movement but may alert the attacker, destroy volatile ev…
CySA+ · Incident Response and Management
After containment, eradication hunts down every foothold: deleting malware, disabling compromised accounts, resetting credentials including service accounts and Kerberos keys, removing persi…
CySA+ · Reporting and Communication
A vulnerability or incident report fails when it hands the board a list of CVEs or hands an administrator a paragraph about brand impact. Executive summaries state what happened or was found…
CySA+ · Reporting and Communication
Mean time to detect measures how long a threat or vulnerability exists before the organization notices it. Mean time to remediate measures how long from discovery to fix, usually reported pe…
CySA+ · Reporting and Communication
Preparation includes deciding who must be told about an incident, in what order and how quickly. Internal escalation reaches management, legal, human resources and public relations. External…
CySA+ · Reporting and Communication
When a confirmed finding cannot be remediated because of legacy dependencies, unacceptable downtime or degraded functionality, the analyst's job is to make the decision explicit rather than …
FIRST-AID · Basic life support concepts
…reted? It is not normal breathing and may occur in cardiac arrest Agonal gasps are not normal breathing. Recognition should trigger the trained emergency response and resuscitation sequence.
People search uses public names, handles and headlines. Private and unlisted profiles are excluded. Your goals are visible only to you in search.