|
A CIW
Security Professional implements security policy, identifies security
threats, and develops countermeasures using firewall systems and
attack-recognition technologies. This individual is responsible for managing
the deployment of e-business transaction and payment security solutions.
Skills measured in the 1D0-470 exam include but are not limited to:
o
Network
perimeter security and elements of an effective security policy.
o
Encryption,
including the three main encryption methods used in internetworking.
o
Universal
guidelines and principles for effective network security, as well as
guidelines to create effective specific solutions.
o
Security
principles and security attack identification.
o
Firewall
types and common firewall terminology.
o
Firewall
system planning including levels of protection.
o
Network
firewall deployment.
o
Network
security including industry security evaluation criteria and guidelines used
to determine three security levels.
o
Mechanisms
used to implement security systems, tools to evaluate key security
parameters, techniques for security accounts, and threats to Windows 2000
and UNIX systems.
o
Permissions
identification, assignment and usage, system defaults, and security
commands.
o
System
patches and fixes including application of system patches.
o
Windows 2000
Registry modifications, including lockdown and removal of services for
effective security in Windows 2000 and Linux.
o
Security
auditing principles, security auditor's chief duties and network risk factor
assessment.
o
Security
auditing and discovery processes, audit plans, and network-based and
host-based discovery software.
o
Penetration
strategies and methods, including identification of potential attacks.
o
User
activities baseline, log analysis, and auditing of various activities.
o
Security
policy compliance and assessment reports.
o
Operating
system add-ons, including personal firewalls and native auditing.
|