The objective of
this chapter is to provide the reader with an understanding of:
Domain 2.0: Communication Security
- 20%
2.1 Recognize and understand the
administration of the following types of remote access technologies:
- 802.1x; VPN (Virtual Private Network)
- RADIUS (Remote Authentication Dial-In User Service)
- TACACS (Terminal Access Controller Access Control
System)
- L2TP / PPTP (Layer Two Tunneling Protocol / Point
to Point Tunneling Protocol)
- SSH (Secure Shell); IPSEC (Internet Protocol
Security); Vulnerabilities
2.2 Recognize and understand the
administration of these email security concepts:
- S/MIME (Secure Multipurpose Internet Mail Extensions)
- PGP (Pretty Good Privacy) like technologies
- Vulnerabilities; SPAM; Hoaxes
2.3 Recognize and understand the
administration of these Internet security concepts:
- SSL / TLS (Secure Sockets Layer / Transport Layer
Security)
- HTTP/S (Hypertext Transfer Protocol / HTTP over
Secure Sockets Layer)
- Instant Messaging (Vulnerabilities; Packet Sniffing;
Privacy)
- Vulnerabilities (Java Script; ActiveX; Buffer
Overflows; Cookies; Signed Applets; CGI; SMTP Relay)
2.4 Recognize and understand the
administration of these directory security concepts:
- SSL / TLS; LDAP (Lightweight Directory Access
Protocol)
2.5 Recognize and understand the
administration of the following file transfer protocols and concepts:
- S/FTP (File Transfer Protocol); Blind FTP (File
Transfer Protocol) / Anonymous
- File Sharing; Vulnerabilities (Packet Sniffing;
8.3 Naming Conventions)
2.6 Recognize and understand the
administration of these wireless technologies and concepts:
- WTLS (Wireless Transport Layer Security)
- 802.11 and 802.11x; WEP / WAP; Vulnerabilities;
Site Surveys
|