1. Attack Methods
- Information Gathering
- Unauthorized Access
- Malicious Code
- Miscellaneous Attacks
- Denial of Service
- Security Intelligence
2. Security Assessment
- Risk Assessment
- Who are the Attackers?
- Legal Issues
- Insurance Against Losses
3. Security Policies
- Security Policy Characteristics
- Types of Policies
- General Security Policy Guidelines
4. Vulnerability Assessment and Audit
- Vulnerability Detection and Audit Policy
- Vulnerability Assessment
- Types of Vulnerability Scanners
- Desirable Scanner Features
- Reasons to Audit
5. Intrusion Detection and Incident Response
- Intrusion Detection Systems (IDSs)
- Types of IDS Devices
- Typical IDS Features
- Centralization and Placement
- IDS Issues
- Incident Response
- Incident Response Policy
6. Host Security
- Types of Hosts
- General Configuration Guidelines
- Special Considerations
- Security Baselines
7. Network Components
- Network Media
- General Network Devices
- Firewalls
- Firewall Methods
- Stateful Inspection
- Hybrid Firewalls
8. Access Control Lists and Firewall Configuration
- Access Control Lists
- Firewall Configuration
9. Architecture Integration
- Security Topologies
- The DMZ
- Device Relationships
- Filtering Inbound/Outbound Traffic
- Extenuating Circumstances
- Modifying and Maintaining the Architecture
10. Authentication
- What is Authentication?
- Authenticators
- Authentication Placement
- Issues
- Enhancements
- Centralized Authentication Methods
11. Cryptographic Functions and Applications
- Features of Secure Communications Elements of Cryptosystems
- Certificates and Certificate Authorities
- Key Management and Certificate Life Cycles
- Applications of Cryptography
12. Communications Security
- Virtual Private Networks (VPNs) using IPSec
- Wireless Security
- Telecommunications Security
Appendix A. Network Services Security
- Common Network Services
- Telnet
- SSH
- DNS
- FTP
- SMTP
- POP3
- HTTP
- DHCP
- Other Services
- Instant Messaging
- P2P File Sharing
- SNMP
- ICMP
- NNTP
- TFTP
Appendix B: Router Security
- Router Access
- Disabling General Services
- Disabling Interface Services
- Auditing
Appendix C: Security+ Exam Objectives
Appendix D: Answers to Review Questions
Appendix E: References