Final Exam: OWASP Top 10 Mitigations - 2021
OWASP
| Intermediate
- 1 video | 32s
- Includes Assessment
- Earns a Badge
Final Exam: OWASP Top 10 Mitigations - 2021 will test your knowledge and application of the topics presented throughout the Skillsoft Aspire Web App Vulnerability Analyst - 2022 Update Journey.
WHAT YOU WILL LEARN
-
Identify components related to developing and running a web applicationrecognize how to write code securelydistinguish web application firewalls (wafs) from other types of firewallsdifferentiate web application firewalls (wafs) from other types of firewallsoutline a plan for various types of security testingrecall the purpose of the open web application security project (owasp)differentiate between mandatory, discretionary, role-based, and attribute-based access controlidentify how broken access control attacks occuridentify how http requests and responses interact with web applicationsmanage windows file system permissionsunderstand linux file system permissionsmanage linux file system permissionslist methods by which malicious actors can gain access to sensitive dataoutline the pki hierarchyidentify what personally identifiable information (pii) is and how it relates to data classification and securityname common data privacy standardsencrypt files in windows using encrypting file system (efs)encrypt files using bitlockerencrypt files in windows using bitlockercapture clear-text http credentials using wiresharkrecognize types of injection attacksdescribe how to mitigate injection attacks using fuzzing, input validation, and sanitizationoutline how to mitigate injection attacks using fuzzing, input validation, and sanitizationexecute a command injection attack against a web application using freely available toolsidentify how java and javascript are used in web applicationsrecognize how cross-site scripting (xss) attacks occuroutline how confidentiality, integrity, and availability (cia) apply to web app developmentname various types of software testinglist the benefits of using a secure api when writing web app codestate how security applies to each phase of the software development life cycle (sdlc)
-
recall examples of security misconfigurationsoutline how application containers workmanage docker containers on a linux computerconfigure azure policy to check for the security compliance of azure resourcessearch and understand the common vulnerabilities and exposures (cve) databaserecall how the heartbleed bug compromises older versions of opensslrecognize how security must be integrated into all aspects of continuous integration and continuous delivery (ci/cd)browse vulnerable devices using the shodan websitedistinguish between authentication and authorizationdifferentiate between authentication and authorizationrecognize how weak authentication configurations can lead to system compromisehash user credentialsanalyze plain text credential transmissions using wiresharkcrack web form passwords using the hydra toolcrack rdp passwords using hydracrack linux passwords using john the ripperconfigure a windows server update services (wsus) serverconfigure and deploy a windows server update services (wsus) serverdigitally sign a microsoft powershell scriptrecognize how to deploy security controls to mitigate deserialization attacksidentify how deserialization attacks occurhash files using windows commandsdifferentiate between siem and soar monitoring and incident response solutionsdistinguish between siem and soar monitoring and incident response solutionsidentify how intrusion detection and prevention can be deployed and usedinstall the snort idsconfigure and test snort ids rulesidentify active network hosts and services using nmaprun a denial of service (dos) attack against a vulnerable web applicationimplement controls to reduce the potential for server-side request forgery (ssrf) attacks
EARN A DIGITAL BADGE WHEN YOU COMPLETE THIS COURSE
Skillsoft is providing you the opportunity to earn a digital badge upon successful completion on some of our courses, which can be shared on any social network or business platform.
Digital badges are yours to keep, forever.