Searching CertSprout…
Searching CertSprout…
A little curiosity goes a long way
Search certifications, learning topics, career paths, public profiles and help across CertSprout.
Showing 20 results · Page 4 for “CompTIA”. More results are available below.
CySA+ · Vulnerability Management
Static application security testing analyzes source code or compiled binaries without running them, catching insecure functions, hard-coded secrets and taint flows from input to dangerous si…
CySA+ · Vulnerability Management
Cross-site scripting appears as script tags or event handlers in parameters and is fixed by output encoding and content security policy. SQL injection shows single quotes, OR 1=1, UNION SELE…
CySA+ · Vulnerability Management
A zero-day vulnerability is one the vendor has had zero days to fix, either because it is being exploited before disclosure or because it was published without warning. The exposure window c…
CySA+ · Incident Response and Management
NIST SP 800-61 organizes response into four phases that the exam breaks into six steps. Preparation builds the plan, the team, the tooling and the playbooks before anything happens. Detectio…
CySA+ · Incident Response and Management
Evidence disappears at different speeds, so collect the most fragile first. CPU registers and cache go in nanoseconds, then RAM contents, running processes, network connections and routing t…
CySA+ · Incident Response and Management
Any evidence that might reach a courtroom, a regulator or a disciplinary hearing needs a documented, unbroken history. Record who collected it, when, where and how, compute a hash of every i…
CySA+ · Incident Response and Management
Once an incident is confirmed, the pressure is to pull the plug, but containment decisions have costs. Isolating a host stops lateral movement but may alert the attacker, destroy volatile ev…
CySA+ · Incident Response and Management
After containment, eradication hunts down every foothold: deleting malware, disabling compromised accounts, resetting credentials including service accounts and Kerberos keys, removing persi…
CySA+ · Reporting and Communication
A vulnerability or incident report fails when it hands the board a list of CVEs or hands an administrator a paragraph about brand impact. Executive summaries state what happened or was found…
CySA+ · Reporting and Communication
Mean time to detect measures how long a threat or vulnerability exists before the organization notices it. Mean time to remediate measures how long from discovery to fix, usually reported pe…
CySA+ · Reporting and Communication
Preparation includes deciding who must be told about an incident, in what order and how quickly. Internal escalation reaches management, legal, human resources and public relations. External…
CySA+ · Reporting and Communication
When a confirmed finding cannot be remediated because of legacy dependencies, unacceptable downtime or degraded functionality, the analyst's job is to make the decision explicit rather than …
Data+ · Analytical reasoning
Analysis translates data into an answer to a specific question. Define the population, time period and metric before computing results. A rate depends on its denominator, and a change in who…
Data+ · Data quality
A value can have the right data type and still be wrong for the business. Data quality checks should cover required values, uniqueness, valid ranges and relationships, along with freshness a…
Data+ · Statistics and measurement
A statistic summarizes observed data, while inference uses a sample to reason about a wider population. The sampling process matters as much as sample size: a large biased sample can remain …
DataAI · Data pipeline design
A data pipeline needs defined inputs, transformations, outputs and checkpoints. Failures can leave partial results, so decide how processing resumes without losing or duplicating records. Tr…
DataAI · Data quality
A value can have the right data type and still be wrong for the business. Data quality checks should cover required values, uniqueness, valid ranges and relationships, along with freshness a…
DataAI · Machine-learning engineering
Data leakage occurs when training or model selection uses information that would not be available at prediction time. Split data in a way that respects time and related entities, and fit lea…
DataSys+ · Database administration
Database administration balances availability, integrity, performance and recovery. Investigate workload evidence before changing indexes or resource limits, and understand the impact on wri…
DataSys+ · Backup and recovery
Recovery point objective describes tolerable data loss measured in time; recovery time objective describes tolerable restoration time. Backup frequency influences the first, while restore sp…
People search uses public names, handles and headlines. Private and unlisted profiles are excluded. Your goals are visible only to you in search.