Systems and Application Security
Systems and Application Security
This course is part of ISC2 Systems Security Certified Practitioner (SSCP)
3,256 already enrolled
Ask Coursera
34 reviews
Recommended experience
34 reviews
Recommended experience
Skills you'll gain
- Malware Protection
- Security Controls
- Data Security
- Endpoint Detection and Response
- Virtualization and Virtual Machines
- Human Factors (Security)
- Cloud Deployment
- Cyber Attacks
- Intrusion Detection and Prevention
- Infrastructure Security
- Cybersecurity
- Cloud Security
- Virtualization
- Threat Detection
- Application Security
- Cloud Computing
- Information Systems Security
- Endpoint Security
Tools you'll learn
Details to know
See how employees at top companies are mastering in-demand skills
Build your subject-matter expertise
- Learn new concepts from industry experts
- Gain a foundational understanding of a subject or tool
- Develop job-relevant skills with hands-on projects
- Earn a shareable career certificate
There is 1 module in this course
Course 7 - Systems and Application Security
This is the seventh course under the specialization SSCP. This course discusses two major changes in recent years to how we use our data: going mobile and using the cloud. First, we use our data on the go by means of data services provided to our mobile phones, Wi-Fi, and other devices. Second, so many of the enhanced functions we take for granted in our daily personal and professional lives are made possible by cloud services, where our data is stored or processed. Course 7 Learning Objectives After completing this course, the participant will be able to: - Classify different types of malware. - Determine how to implement malware countermeasures. - Identify various types of malicious activities. - Develop strategies for mitigating malicious activities. - Describe various social engineering methods used by attackers. - Explain the role of behavior analytics technologies in detecting and mitigating threats. - Explain the role and functionality of host-based intrusion prevention system (HIPS), host-based intrusion detection system (HIDS), and host-based firewalls. - Evaluate the benefits of application whitelisting in endpoint device security. - Explain the concept of endpoint encryption and its role in endpoint security. - Describe the role and functionality of Trusted Platform Module (TPM) technology in providing hardware-based security features. - Identify the steps in implementing secure browsing practices using digital certificates and secure communication protocols. - Explain the concept of endpoint detection and response (EDR) and its role in providing real-time monitoring, detection, investigation, and response capabilities to identify and mitigate advanced threats and security incidents on endpoint devices. - Identify provisioning techniques for mobile devices. - Explain the concept of containerization and how it contributes to effective mobile device management. - Explain how encryption contributes to effective mobile device management. - Describe the process of Mobile Application Management (MAM) to effectively manage the life cycle of mobile applications. - Distinguish among public, private, hybrid, and community deployment models in cloud security. - Distinguish among various service models and their impact on cloud security practices. - Describe virtualization technologies and their role in maintaining cloud security. - Identify legal and regulatory concerns related to cloud security. - Determine strategies to implement data storage, processing, and transmission while maintaining cloud security. - Explain the requirements and considerations associated with third-party services and outsourcing in cloud storage. - Explain the concept of the shared responsibility model in cloud storage. - Identify steps to manage and secure hypervisor environments. - Explain how to deploy, configure, and maintain virtual appliances within virtualized environments. - Determine the process for managing containerized environments. - Describe the best practices of storage management in virtualized environments. - Develop strategies for ensuring business continuity and resilience in virtualized environments. - Analyze potential threats and attacks targeting virtual environments. Who Should Take This Course: Beginners Experience Required: No prior experience required
This course discusses two major changes in recent years to how we use our data: going mobile and using the cloud. First, we use our data on the go by means of data services provided to our mobile phones, Wi-Fi, and other devices. Second, so many of the enhanced functions we take for granted in our daily personal and professional lives are made possible by cloud services, where our data is stored or processed. Both of those transformations are complex topics. However, from our perspective as security professionals, we can apply the security fundamentals we learn to help us better secure the data through the technologies, systems, and services we use.
What's included
10 videos55 readings25 assignments
10 videos•Total 73 minutes
- Malware Attackers •5 minutes
- Endpoints•14 minutes
- Security Strategies for Endpoints •8 minutes
- The Five Essential Characteristics of Clouds •7 minutes
- Virtualization •7 minutes
- Essential Requirements in P&DP Laws •4 minutes
- Application of Defined Controls for Personally Identifiable Information •6 minutes
- Virtual Machines •6 minutes
- Threats, Attacks, and Countermeasures •9 minutes
- Virtualization Attacks •7 minutes
55 readings•Total 248 minutes
- Protecting the Viability and Success of the Organization •2 minutes
- The Software Environment: Systems and Application Security •6 minutes
- Development Time vs. the Impact of Errors•2 minutes
- Data Security: The Threat Perspective •6 minutes
- Types of Software and Threat Vectors •5 minutes
- Types of Malware •6 minutes
- Rootkits •6 minutes
- Web Application-Based Vulnerabilities •4 minutes
- All-Source Intelligence •3 minutes
- All-Source Intelligence Considerations •6 minutes
- External Threats from Media •2 minutes
- Fundamental Concepts of Malware •6 minutes
- Antimalware Products and Services •2 minutes
- Types of Malware Countermeasures •5 minutes
- Types of Malicious Activity •3 minutes
- Malicious Activity Countermeasures•4 minutes
- Social Engineering Methods •6 minutes
- Behavior Analytics •5 minutes
- Supervisory Control and Data Acquisition •6 minutes
- Industrial Control Systems (ICS) •6 minutes
- Host-Based Intrusion Prevention, Intrusion Detection, and Firewalls •4 minutes
- Application Allowed and Blocked Listing •6 minutes
- Endpoint Encryption, Detection, and Response •5 minutes
- Trusted Platform Module (TPM)•6 minutes
- Secure Browsing •1 minute
- Mobile Device Use •6 minutes
- Remote Working •5 minutes
- Bring Your Own Device (BYOD) •6 minutes
- Containerization, Encryption, and Mobile Application Management •4 minutes
- The Cloud (Simplified) •5 minutes
- Deployment Models •6 minutes
- Service Models •6 minutes
- Legal and Regulatory Concerns •1 minute
- Legal and Privacy Concerns for Cloud-Hosted Data •1 minute
- Data Protection and Privacy: Regional Considerations •3 minutes
- Global Considerations•8 minutes
- Data Discovery •5 minutes
- Cloud Storage: Data Dispersion and Data Loss Prevention •4 minutes
- Cloud Security Alliance Cloud Control Matrix •4 minutes
- Cloud Encryption Challenges •4 minutes
- Key Management and Storage Considerations•2 minutes
- Third-Party Outsourcing Requirements •1 minute
- Shared Responsibility Model •2 minutes
- Risks to Virtual Machines and Virtualized Environments •2 minutes
- Hypervisors, Virtual Appliances, and Containers •4 minutes
- Storage Management •6 minutes
- Continuity and Resilience•2 minutes
- Host Security Considerations •8 minutes
- Firewall and Router Testing •6 minutes
- Security Monitoring Testing •2 minutes
- Network Strategies •4 minutes
- Virtual Machine Security •4 minutes
- Management Systems and Hypervisor Security •4 minutes
- Key Takeaways•10 minutes
- Systems and Application Security Terms and Definitions•10 minutes
25 assignments•Total 328 minutes
- Types of Malware•2 minutes
- Fundamental Concepts of Malware •2 minutes
- Malicious Activity Countermeasures•2 minutes
- Social Engineering Methods •2 minutes
- Behavior Analytics •2 minutes
- Industrial Control Systems (ICS) •2 minutes
- Host-Based Intrusion Prevention System (HIPS), Host-Based Intrusion Detection System (HIDS), and Host-Based Firewalls •4 minutes
- Application Allowed and Blocked Listing •2 minutes
- Endpoint Encryption, Detection, and Response •4 minutes
- Trusted Platform Module (TPM) •2 minutes
- Secure Browsing •2 minutes
- Mobile Device Use •2 minutes
- Containerization, Encryption, and Mobile Application Management •6 minutes
- Service Models •2 minutes
- Virtualization •2 minutes
- Legal and Regulatory Concerns •2 minutes
- Key Management and Storage Considerations•2 minutes
- Third-Party Outsourcing Requirements •2 minutes
- Shared Responsibility Model •2 minutes
- Hypervisors, Virtual Appliances, and Containers •6 minutes
- Storage Management •2 minutes
- Continuity and Resilience •2 minutes
- Threats, Attacks, and Countermeasures •2 minutes
- End of Course Quiz•20 minutes
- Final Assessment•250 minutes
Earn a career certificate
Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.
Instructor
Explore more from Security
- I
ISC2
Course
Course
Course
Why people choose Coursera for their career
Advance your career with an online degree
Earn a degree from world-class universities - 100% online
Frequently asked questions
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
When you enroll in the course, you get access to all of the courses in the Certificate, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
More questions
Financial aid available,
