Thursday, July 9, 2020

About CompTIA Security+

security exam objectives

Information security definition

Information security, sometimes abbreviated to infosec, is a set of practices intended to keep data secure from unauthorized access or alterations, both when it's being stored and when it's being transmitted from one machine or physical location to another. You might sometimes see it referred to as data security. As knowledge has become one of the 21st century's most important assets, efforts to keep information secure have correspondingly become increasingly important.

Information security vs. cybersecurity

Because information technology has become the accepted corporate buzzphrase that means, basically, "computers and related stuff," you will sometimes see information security and cybersecurity used interchangeably. Strictly speaking, cybersecurity is the broader practice of defending IT assets from attack, and information security is a specific discipline under the cybersecurity umbrella. Network security and application security are sister practices to infosec, focusing on networks and app code, respectively.
Obviously, there's some overlap here. You can't secure data transmitted across an insecure network or manipulated by a leaky application. As well, there is plenty of information that isn't stored electronically that also needs to be protected. Thus, the infosec pro's remit is necessarily broad.

Information security principles

The basic components of information security are most often summed up by the so-called CIA triad: confidentiality, integrity, and availability.
  • Confidentiality is perhaps the element of the triad that most immediately comes to mind when you think of information security. Data is confidential when only those people who are authorized to access it can do so; to ensure confidentiality, you need to be able to identify who is trying to access data and block attempts by those without authorization. Passwords, encryption, authentication, and defense against penetration attacks are all techniques designed to ensure confidentiality.
  • Integrity means maintaining data in its correct state and preventing it from being improperly modified, either by accident or maliciously. Many of the techniques that ensure confidentiality will also protect data integrity—after all, a hacker can't change data they can't access—but there are other tools that help provide a defense of integrity in depth: checksums can help you verify data integrity, for instance, and version control software and frequent backups can help you restore data to a correct state if need be. Integrity also covers the concept of non-repudiation: you must be able to prove that you've maintained the integrity of your data, especially in legal contexts.
  • Availability is the mirror image of confidentiality: while you need to make sure that your data can't be accessed by unauthorized users, you also need to ensure that it can be accessed by those who have the proper permissions. Ensuring data availability means matching network and computing resources to the volume of data access you expect and implementing a good backup policy for disaster recovery purposes.
In an ideal world, your data should always be kept confidential, in its correct state, and available; in practice, of course, you often need to make choices about which information security principles to emphasize, and that requires assessing your data. If you're storing sensitive medical information, for instance, you'll focus on confidentiality, whereas a financial institution might emphasize data integrity to ensure that nobody's bank account is credited or debited incorrectly.

Information security policy

The means by which these principles are applied to an organization take the form of a security policy. This isn't a piece of security hardware or software; rather, it's a document that an enterprise draws up, based on its own specific needs and quirks, to establish what data needs to be protected and in what ways. These policies guide the organization's decisions around procuring cybersecurity tools, and also mandate employee behavior and responsibilities.
Among other things, your company's information security policy should include:
  • A statement describing the purpose of the infosec program and your overall objectives
  • Definitions of key terms used in the document to ensure shared understanding
  • An access control policy, determining who has access to what data and how they can establish their rights
  • password policy
  • data support and operations plan to ensure that data is always available to those who need it
  • Employee roles and responsibilities when it comes to safeguarding data, including who is ultimately responsible for information security
One important thing to keep in mind is that, in a world where many companies outsource some computer services or store data in the cloud, your security policy needs to cover more than just the assets you own. You need to know how you'll deal with everything from personally identifying information stored on AWS instances to third-party contractors who need to be able to authenticate to access sensitive corporate info.

Wednesday, July 8, 2020

How can I control my WiFi at home?

wi fi security

Use the access control feature to block devices from connecting to your router’s Internet connection.
Note: Blocking devices with access control only blocks them from accessing the Internet. Devices can still access your router’s local network and communicate with your connected devices.
To set up access control:
  1. Launch a web browser from a computer or mobile device that is connected to your router’s network.
  2. Enter
    A login window opens.
  3. Enter the router user name and password.
    The user name is admin and the default password is password. The user name and password are case-sensitive.
    The BASIC Home page displays.
  4. Select ADVANCED > Security > Access Control.
  5. Select the Turn on Access Control check box.
    You must select this check box before you can specify an access rule and use the Allow and Block buttons. When this check box is cleared, all devices are allowed to connect, even if a device is in the blocked list.
  6. To specify an access rule, select one of the following radio buttons:
    • Allow all new devices to connect. With this setting, a new device can access your network. You don't need to enter its MAC address in this screen. NETGEAR recommends that you leave this radio button selected.
    • Block all new devices from connecting. With this setting, a new device cannot access your router’s Internet connection, but can still access your router’s local network. Before a device accesses your router’s Internet connection, you must enter its MAC address for an Ethernet connection and its MAC address for a WiFi connection in the allowed list.
      The access rule does not affect previously blocked or allowed devices. It applies only to devices joining your network in the future after you apply these settings.
  7. To view allowed or blocked devices that are not connected, click one of the following links:
    • View list of allowed devices not currently connected to the network
    • View list of blocked devices not currently connected to the network
      The list displays.
  8. To allow the computer or device you’re currently using to continue to access your network, select the check box next to your computer or device, and click the Allow button.
  9. Click the Apply button.
    Your settings are saved.

Tuesday, July 7, 2020

Certified Wireless Security Professional (CWSP)

cwsp


Requirements
  • The students registering for this course are required to have studied the Certified Wireless Network Administrator (CWNA) course or passed the CWNA certification exam.  
Description
The Certified Wireless Security Professional (CWSP) course is designed on the CWSP certification exam curriculum recommended by CWNP. The course teaches the latest enterprise wireless LAN security and auditing techniques to the students. The course also covers the most up-to-date WLAN intrusion and DoS tools and techniques. The students are enabled on the functionality of the 802.11i amendment to the 802.11 standard, the inner-workings of each authentication method used with wireless LANs, and every class and type of WLAN security solution available. This includes a detailed coverage of the wireless intrusion prevention systems and wireless network management systems.
The Certified Wireless Security Professional (CWSP) course will help the students to acquire the necessary skills for implementing and managing wireless security in the enterprise by creating layer2 and layer3 hardware and software solutions with tools from the industry’s leading manufacturers. The course also serves as an excellent preparatory course for the CWSP certification offered by CWNP.
Who this course is for:
  • The course is intended for the professionals working with the wireless network and looking to enhance their knowledge by learning the cutting-edge wireless security tools and techniques and earn the CWSP certification by CWNP.
What it takes to become a CWSP:
The CWSP certification is a professional level wireless LAN certification for the CWNP Program. To earn a CWSP certification, you must hold a current and valid CWNA credential. You must take the CWSP exam at a Pearson Vue Testing Center and pass with a 70% or higher. Instructors must pass with a 80% or higher. However you choose to prepare for the CWSP exam, you should start with the exam objectives, which cover the full list of skills tested on the exam.  The CWSP certification is valid for three (3) years. To recertify, you must have a current CWNA credential and pass the current CWSP exam.  By passing the CWSP exam, your CWNA certificate will be renewed for another three years.
Main areas covered by CWSP
  • WLAN Discovery Techniques
  • Intrusion and Attack Techniques
  • 802.11 Protocol Analysis
  • Wireless Intrusion Prevention Systems (WIPS) Implementation
  • Layer 2 and 3 VPNs used over 802.11 networks
  • Enterprise/SMB/SOHO/Public-Network Security design models
  • Managed Endpoint Security Systems802.11 Authentication and Key
  • 205 Exam Objectives
  • CWSP-206 Exam Objectives 2019 (CWSP-206 Exam will replace CWSP-205 in September of 2019)

Monday, July 6, 2020

Is the CompTIA A+ hard?

comptia salary


The three primary entry-level CompTIA certifications are the A+, Network+ and Security+, and because so many people start their careers focusing on one or more of these certifications, the question often comes up about which certification to take first and which of these you really need for your career.
Should you take the CompTIA A+ before Network+?  You don’t need to, and probably shouldn’t take the CompTIA A+ before the Network+ certification exam, because if you’re entering into field of cyber security, your focus should be on obtaining the Network+ and Security+ instead.
I’m sure this response brings up quite a few questions in everyone’s mind, so let’s discuss why skipping the A+ is practical and why you should go for the Network+ and Security+ instead.

Friday, July 3, 2020

Can I get a job with just an A+ certification?

a+ certification jobs with no experience


CompTIA A+ validates understanding of the most common hardware and software technologies in business and certifies the skills necessary to support complex IT infrastructures. CompTIA A+ is a powerful credential that helps IT professionals worldwide ignite their IT career.
CompTIA A+ held by over 1​ million IT professionals worldwide, CompTIA A+ is the most essential IT certification for establishing an IT career. If you’re new to the IT industry, this will help you put your best foot forward. And if you’re already an IT professional, the CompTIA A+ certification validates your skills and can boost your career.
Now we know what is CompTIA A+, Let’s see what jobs you can have as a A+ certified and the expected salary.
How much you can gain as a A+ certified?
  1. $67,954 (According to concise-courses)
  2. 40.000~45.000 (According to glassdoor)
  3. 25.000~35.000 (According to so technicians talking on forums)
So you can see it depends on many things, for example:
  • Where do you live?
  • The company you are working for?
  • Soft skills
  • How many hours you work per week?Of course it is possible to get a job with just an A+ certification. It is also possible to get a job with no certification at all. The question you're really asking is if it is possible to get a job with an A+ certification that you wouldn't have gotten without that credential. The answer to that is also 'of course'. There is certainly a job opening out there (probably dozens of them, actually), where the hiring manager would pass on a candidate with no job experience or certifications... but would accept one that had no job experience but that does have an A+ certification.
    Is there a job with those specifications going to be open in a region convenient to you on the day after you earn your A+ credential? Heck if I know. There's also the problem that Colin has already noted in his reply... the pay for people with A+ (and nothing else) isn't spectacular.
    Pull up jobs in your area on an online job site -- Indeed.com is one of my favorites. See if there are companies looking for candidates with A+ credentials in your area and what they pay. If there are some and the jobs interest you, then get the credential. Most likely after you have your A+, a similar se

What are some of the best certifications to have?

best entry level it certifications

Top 10 Certifications You Can Get In 2020

2020 is almost approaching. What is your resolution for 2020??
If you are a career-oriented person then upskill yourself with the best certification to stay relevant and grab new opportunities in the coming years. 
Below are the Top 10 certifications that you can have!
Agile and Scrum are very popular certifications as of today.
Agile methodology is more adaptable to changes as per requirements throughout the course of the project. 
Commonly considered as a framework in agile project management, Scrum outlines a set of meetings, tools, and roles that work in harmony to help team structure and conduct their work.
Through this certification, you will be able to learn the Agile and Scrum framework and gain an understanding of team roles, events, and artifacts, as well as how to guide agile teams through a project successfully.
According to Payscale, in 2019, the average annual pay for a Certified Scrum Master in the United States is $115,700 a year.
It is one of the most popular cloud computing certifications. From storing and sharing files using google drive to watching movies on Netflix, everything is on the cloud. From the user base itself, it’s evident that cloud computing is a necessity today. If you are a person who wants to build a career in the cloud, then AWS certification is the best to start with. You can start with a basic level such as AWS Certified Solutions Architect - Associate and gradually move up the ladder with next step certifications.
That’s because AWS is more popular than its 10 other competitors like Azure, Google Cloud, etc.
The average salary of an AWS solutions architect is $123,700 per year according to  Indeed.Com
According to Enlyft, a marketing intelligence company, 47% of Amazon AWS customers are in the United States and that’s a lot of companies that can bring job opportunities for you. 
However, prior to taking an exam, you should have hands-on experience with AWS services and architecting large-scale distributed systems.
It is one of the globally recognized IT security professional's technical skills. Companies usually look for applicants who have completed the CISSP exam because applicants with the CISSP certifications are sufficiently educated about cybersecurity and have hands-on experience of at least 5 years. 
This experience can be earned in a minimum of two of the eight cybersecurity knowledge domains. 
As per Indeed, there has been a sudden increase in demand for cybersecurity skills by 7% in the US. That’s good news! Isn’t it?
According to Payscale, the salary of a CISSP certified individual ranges from $87,000 to $165,000 depending on the years of experience in the USA as of August 2019.
Within Cisco Certifications, the two very popular and valuable certifications are CCNA (Cisco certified network associate) and CCNP (Cisco certified network professional)
CCNA primarily focuses on developing appropriate skills to meet the speedy deployment of technologies in today’s complex networking environment.
Once you are a CCNA certified you can choose different paths that interest you, such as: 
CCNA Security - It deals in troubleshooting and monitoring network devices.
CCNA Voice - It deals with VoIP, handset, voiceover mail, etc.
CCNA Wireless - It deals with using Cisco equipment in configuring, implementing, and supporting wireless LANs
The majority of MNCs, as well as medium-sized companies, use Cisco products, which means they need people who can help with seamless operations while using those products.
In the US, the average salary of a CCNA certified professional ranges from $72,000 to $100,000 as of August 2019, according to Payscale.
CCNP - One of the most popular certifications in the field of networking. This certification is usually preferred by CCNA as this helps them to scale up one’s career. CCNP will help you to validate your proficiency in planning, implementing, managing and troubleshooting WANs and LANs in business environments. It also helps you make aware of how to work in collaboration with other experts to manage wireless, voice, video and security solutions.
CCNP certified professionals earn $92,000 on an average per year which can go high up to $122,000 depending upon the experience according to payscale in August 2019.
It is one of the most recognized certifications globally in today’s date. It is created and administered by PMI - Project Management Institute. According to recruiters, the certificate adds immense value to your leadership skills and in addition, the PMP® certification brings a 22–25% increase over non-certified peers. 
PMP helps you examine yourself in five criteria; initiating, planning, executing, monitoring and controlling, and closing. The results provide you a clear picture of your capability and also for recruiters to choose you over others.
However, there are prior requirements to become PMP certified. You should have a bachelor’s degree with at least 4500 hours of project management experience and if you don’t have a bachelor's degree then you would need to have 7500 hrs of project management experience. And lastly, you need to have a 35-hour contact certificate to take the exam and you are good to go.
According to a survey done by PMI in 2019, Project managers take-home salary is $112,000 annually in the States and earns 23 percent higher than one without PMP certification.
Project Management includes other certifications such as CAPM, PRINCE 2 Foundation, PRINCE 2 practitioner and PRINCE 2 combo. 
With this particular certification, you will have a complete fundamental knowledge of hardware and software. You’ll also learn about troubleshooting a wide range of devices, from computers to smartphones.
The examination is outlined to certify the capability of entry-level personal computer service professionals in installing, operating, customizing, and maintaining personal computers and other devices.
In the US, a CompTIA A+ certified professional earns about $59,000 on an average per year according to PayScale as of August 2019.
7. ITIL 
ITIL or Information Technology Infrastructure Library is a set of best practices for IT service management. ITIL concentrates on adjusting or arranging on the IT services according to the requirements of the companies.
It includes a list of relevant specializations such as IT operations, capacity management, incident management, and availability management, to name a few. Best practices intend to manage or lessen IT costs, improve IT services, and balance IT resources.
You can start with the ITIL Foundation course which will give a brief understanding of the IT service lifecycle.
According to Ziprecruiter.com the majority of ITIL Foundation salaries as of August 2019, range between $52,000 to $118,500 across the United States.
8. Global Information Assurance Certification (GIAC)
GIAC provides a set of vendor-neutral computer security certifications. It offers 30+ specific information security certifications. The objective of these certifications is to focus on job-based capabilities rather than providing a standard course to all. The certification process approves the specific abilities of security professionals and developers with standards established on the most important benchmarks in the industry.
An increase in the number of devices and networks calls for more threat. It leads to the demand for highly skilled people to manage the threats and eliminate them.
According to PayScale August 2019, a GIAC certified can earn an average of $90,000 per year in the US.
The MCSE certification will help if you are an IT Professional to validate your technical expertise through accurate, industry-proven, and industry-recognized exams.
MCSE certifications show the skills to design and build advanced solutions that integrate multiple Microsoft technologies.
Prior to doing MCSE, you will have to complete MCSA certification which will validate your ability to build and design solutions using core Microsoft technologies.
MCSE has various other certifications under it such as MCSE: Business Application, MCSE: Core Infrastructure, MCSE: Data Management & Analytics, MCSE: Mobility, and MCSE: Productivity.
The demand for skilled cloud specialists has exponentially increased due to a multi-cloud strategy approach taken by most businesses.
According to Payscale the average salary in the US for Microsoft certified solution expert is $92,000 per year as of August 2019.
In today’s date hiring an ethical hacker is not a choice but a necessity. If you wish to become one, you will have the ability to understand and know how to look for vulnerabilities in target systems. 
You will also be able to use the same expertise and means as a hacker but strictly aligned with the law to evaluate the security posture of a target system.
Not only in the US but also in other countries malicious hacking is a strict offense. However, one should have the same technical skills that hackers possess to catch a criminal. 
A Certified Ethical Hacker certification indicates your knowledge in network security, particularly in preventing malicious hacking attacks through pre-emptive countermeasures.
In the US, a Certified Ethical Hacker earns on an average of $90,000 per year according to Payscale as of July 2019.
Conclusion
Up your game this 2020 with relevant certifications! You can either jump into the rapidly growing fields such as cybersecurity and cloud. You can upskill yourself staying in the current area to face new opportunities as well as challenges. Regardless, you can choose a certification that aligns with your career interest. However, these certifications would help you in gaining a position you are aspiring to and would be a differentiator among the others.

Thursday, July 2, 2020

How hard is it to pass the CompTIA A+ certification exam?

a+ certification job opportunities

The exam itself is not terribly difficult; so long as you know the content. I would strongly suggest building a small lab that you can test the theories and get some hands-on experience. On top of that here are some resources I strongly recommend:
Study Resources
The internet is loaded with tons of resources for studying to pass the a plus exam. Some of them are great and others will just hinder your studying. Below is a list of resources that I personally find to be helpful for those looking into studying and passing the CompTIA A+ exam.
  • Professor Messer’s free A+ Videos – Most of you probably already know about Messer’s free videos. The videos are a bit dry but the content is great.
  • passtheaplus.com – FREE online resource with CompTIA A+ study notes & study guides. I blog here.
  • CertForums – The forums that I frequent the most often! Great community to ask questions and get feedback. More personable group of professionals than the other forum I frequent.
  • Exam Cram by David L. Prowse – My personal favorite if you prefer reading from an actual book. The content is to the point without boring you to death. A great overview.
  • TechExams.net A+ forum – Huge community of other IT folks like you and me. Great place to participate and ask questions. Great for encouragement in pursuing your IT career.
  • CompTIA subreddit – Surely you know about Reddit. Huge community with 3,500+ other techies.

About the CompTIA A+ certification

 comptia a plus About the CompTIA A+ certification A+ (A Plus) is an entry-level computer certification for PC computer service technicians....