CASP/1.0 Enterprise Security 40%

Distinguish which cryptographic tools and techniques are appropriate for a given situation.Edit

Cryptographic applications and proper implementationEdit

Advanced PKI conceptsEdit

Wild cardEdit

OCSP—Online Certificate Status Protocol VS CRL – Certification Revocation ListEdit

Issuance to entitiesEdit

Implications of cryptographic methods and designEdit

Strength vs. performance vs. feasibility to implement vs. interoperabilityEdit

Transport encryptionEdit

Digital signatureEdit


Code signingEdit



Pseudo random number generationEdit

Perfect forward secrecyEdit

Confusion and DiffusionEdit

Distinguish and select among different types of virtualized, distributed and shared computingEdit

Advantages and disadvantages of virtualizing servers and minimizing physical space requirementsEdit

VLAN – Virtual Local Area NetworkEdit

Securing virtual environments, appliances and equipmentEdit

Vulnerabilities associated with a single physical server hosting multiple companies’ virtual machinesEdit

Vulnerabilities associated with a single platform hosting multiple companies’ virtual machinesEdit

Secure use of on-demand / elastic cloud computingEdit

Provisioning and De-provisioningEdit

Data remnantsEdit

Vulnerabilities associated with co-mingling of hosts with different security requirementsEdit

Virtual Machine EscapeEdit

Privilege elevationEdit

Virtual Desktop Infrastructure (VDI)Edit

Terminal servicesEdit

Explain the security implications of enterprise storageEdit

Virtual storageEdit

NAS- Network Attached StorageEdit

SAN – Storage Area NetworkEdit

vSAN – Virtual Storage Area NetworkEdit

iSCSI - internet Small Computer System InterfaceEdit

FCOE – Fiber Channel Over EthernetEdit

LUN – Logical Unit NumberEdit

HBA- Host Based Adapter allocationEdit

Redundancy (location)Edit

Secure storage managementEdit




Integrate hosts, networks, infrastructures, applications and storage into secure comprehensive solutionsEdit

Advanced network designEdit

Remote accessEdit

Placement of security devicesEdit

Critical infrastructure / Supervisory Control and Data Acquisition (SCADA)Edit

VoIP - Voice over IPEdit


Complex network, Network security, solutions for data flowEdit

Unified Threat ManagementEdit

Secure data flows to meet changing business needsEdit

Secure DNS – Domain Name Service (Server)Edit

Securing zone transferEdit

TSIG- Transaction Signature Interoperability GroupEdit

Secure directory servicesEdit

LDAP – Lightweight Directory Access ProtocolEdit

AD—Active DirectoryEdit

Federated IDEdit

Single sign onEdit

Network design considerationEdit

Building layoutsEdit

Facilities managementEdit

Multitier networking data design considerationsEdit

Logical deployment diagram and corresponding physical deployment diagram of all relevant devicesEdit

Distinguish among security controls for hostsEdit

Host-based firewallsEdit

Trusted OS – Operating System (e.g. how and when to use it)Edit

End point security softwareEdit




Spam filtersEdit

Host hardeningEdit

Standard operating environmentEdit

Security Policy / group policy implementationEdit

Command shell restrictionsEdit

Warning bannersEdit

Restricted interfacesEdit

Asset management (inventory control)Edit

Data exfiltrationEdit

HIDS – Host Based Intrusion Detection System/HIPS – Host Based Intrusion Prevention SystemEdit

NIDS – Network Based Intrusion Detection System/NIPS – Network Based Intrusion Prevention SystemEdit

Explain the importance of application securityEdit

Web application security design considerationsEdit

Secure: by design, by default, by deploymentEdit

Specific application issuesEdit

XSS - Cross-Site ScriptingEdit


Session managementEdit

Input validationEdit

SQL injectionEdit

Application sandboxingEdit

Application security frameworksEdit

Standard librariesEdit

Industry accepted approachesEdit

Secure coding standardsEdit

Exploits resulting from improper error and exception handlingEdit

Privilege escalationEdit

Improper storage of sensitive dataEdit

Fuzzing/false injectionEdit

Secure cookie storage and transmissionEdit

Client-side processing vs. server-side processingEdit


State managementEdit


Buffer overflowEdit

Memory leaksEdit

Integer overflowsEdit

Race conditionsEdit

Time of check to time of useEdit

Resource exhaustionEdit

Resource Management

Given a scenario, distinguish and select the method or tool that is appropriate to conduct an assessmentEdit

Tool typeEdit

Port scannersEdit

Vulnerability scannersEdit

Protocol analyzerEdit

Switchport analyzerEdit

Network enumeratorEdit

Password crackerEdit


HTTP – Hypertext Transfer Protocol interceptorEdit

Attacking tools/frameworksEdit

Vulnerability assessmentEdit

Penetration testingEdit

Black boxEdit

White boxEdit

Grey BoxEdit


Code reviewEdit

Social engineeringEdit