ITC 2820 - Information Systems Security Pen Testing
3 Credits Learn how information systems including computers, networks, cloud, and mobile devices are attacked and how attackers find and exploit vulnerabilities in the systems relied upon for modern life. By understanding system weaknesses and vulnerabilities, this pen testing course provides insight into the minds of attackers so that you can better prepare to defend against attacks. This course assists students in preparing for the EC-Council CEH industry certification exam.
Pre-Requisites ITC 2430 , ITC 2536 , ITC 2480 , ITC 2530
Major Content Areas Information Security and Ethical Penetration Testing Overview.
Reconnaissance Techniques.
System Penetration Testing Phases and Attack Techniques.
Network and Perimeter Penetration Testing.
Web Application Penetration Testing.
Wireless Network Penetration Testing.
Mobile Platform, IoT, and OT Penetration Testing.
Cloud Computing.Cryptography.
Learning Outcomes Identify and explain Internet of Things and Operational Technology security considerations and vulnerabilities including common attacks, attack tools, attack methodologies, and countermeasures.
Identify and explain cloud computing security considerations and threats including virtual machines, containers, and serverless computing.
Identify, explain, and demonstrate cryptographic concepts including various common algorithms, PKI, email encryption, disk encryption, cryptanalysis, and countermeasures.
Describe the key concepts of malware, APTs, trojans, viruses, worms, and file-less malware and demonstrate malware analysis, countermeasures, and use of anti-malware software.
Describe and demonstrate network perimeter penetration testing including a variety of common sniffing techniques, social engineering, denial-of-service, session hijacking, and IDS/firewall/honeypot detection and evasion.
Explain the basics of information security and ethical penetration testing including information security controls/laws/standards, and the Cyber Kill Chain.
Demonstrate and explain reconnaissance techniques including foot printing, scanning networks, and enumeration using a variety of common techniques for each.
Demonstrate and explain the phases and techniques used by attackers including vulnerability analysis, password cracking, vulnerability exploitation, privilege escalation, and detection voidance.
Demonstrate and describe attacks against web servers, web applications, and SQL servers including client-side control bypass, access control, authentication, authorization, session management, injection, web shell, and API attacks.
Demonstrate and describe threats, vulnerabilities, attacks, and attack countermeasures against wireless networks including 802.11 and Bluetooth networks.
Identify and explain mobile device security considerations including Android and iOS, mobile device management, anattack vectors.
|