Introduction xxiAssessment Test xxxvDomain I Security Operations 1Chapter 1 Today's Cybersecurity Analyst 3Chapter 2 System and Network Architecture 37Chapter 3 Malicious Activity 77Chapter 4 Threat Intelligence 135Chapter 5 Reconnaissance and Intelligence Gathering 159Domain II Vulnerability Management 201Chapter 6 Designing a Vulnerability Management Program 203Chapter 7 Analyzing Vulnerability Scans 245Chapter 8 Responding to Vulnerabilities 293Domain III Incident Response and Management 341Chapter 9 Building an Incident Response Program 343Chapter 10 Incident Detection and Analysis 377Chapter 11 Containment, Eradication, and Recovery 397Domain IV Reporting and Communication 421Chapter 12 Reporting and Communication 423Chapter 13 Performing Forensic Analysis and Techniques for Incident Response 447Appendix Answers to Review Questions 489Index 513
ABOUT THE AUTHORSMIKE CHAPPLE, PhD, Security+, CySA+, CISSP, is Teaching Professor of Information Technology, Analytics, and Operations at Notre Dame's Mendoza College of Business. He is a bestselling author of over 25 books and serves as the Academic Director of the University's Master of Science in Business Analytics program. He holds multiple additional certifications, including the CISSP (Certified Information Systems Security Professional), CySA+ (CompTIA Cybersecurity Analyst), CIPP/US(Certified Information Privacy Professional), CompTIA PenTest+, and CompTIA Security+. Mike provides cybersecurity certification resources at his website, CertMike.com.DAVID SEIDL, CySA+, CISSP, PenTest+, is Vice President for Information Technology and CIO at Miami University. David co-led Notre Dame's move to the cloud, and has written multiple cybersecurity certification books.