About this Course
5.0
3 ratings
1 reviews
100% online

100% online

Start instantly and learn at your own schedule.
Flexible deadlines

Flexible deadlines

Reset deadlines in accordance to your schedule.
Beginner Level

Beginner Level

Hours to complete

Approx. 14 hours to complete

Suggested: 5 hours/week...
Available languages

English

Subtitles: English...
100% online

100% online

Start instantly and learn at your own schedule.
Flexible deadlines

Flexible deadlines

Reset deadlines in accordance to your schedule.
Beginner Level

Beginner Level

Hours to complete

Approx. 14 hours to complete

Suggested: 5 hours/week...
Available languages

English

Subtitles: English...

Syllabus - What you will learn from this course

Week
1
Hours to complete
5 hours to complete

Identify and Analyze Malicious Code and Activity

Module Topics: Malicious Code, Malicious Code Countermeasures, Exploitation, Insider Threats, Spoofing, Phishing, Spam, and Botnet, Malicious Web Activity, Payloads, Malicious Activity Countermeasures, Malcode Mitigation, and Common Mistakes. Malicious Code includes topics like Key concepts, Example Worms, Polymorphic Viruses, Software Exploitation Methods, Scanners, Generations of Antivirus Scanning Software, Generic Decryption (GD) Technology, Behavior-Blocking Software, Antivirus Software on the Firewall and IDS, Code signing, Code Signing Certificates, Sandboxing, Virtual Machine (VM), Social Engineering, Additional Examples of Social Engineering Attacks, and Security Awareness Training. Under the topic of Exploitation, you will learn about Long File Extensions, Fake Icon, Hostile Codecs, and E-mail. In Insider Threats, you will learn about Indicators of Malicious Threat Activity, Countermeasures, Direction, Prevention, and Deterrence Methods, Continual Training, and Insider Hardware Threats. In Spoofing, Phishing, Spam, and Botnets, you will learn about Spoofing, Examples of Spoofing, Phishing, Common Characteristics of Forged E-Mail Messages, Techniques, How Phishing Works, Impact of Phishing, How to Recognize a Phishing E-Mail, Spam, Spam Distribution Channels, How Does Spam Work?, Spam Techniques, Protecting users From Spam, Botnets, How Are Botnets Created?, Botnet-Led Exploits, Botnet Detection and Mitigation, Common Botnet Detection and Mitigation Techniques. In Malicious Web Activity, you will go through topics like Mobomarket Attack, Cross-site Scripting (XSS) Attacks, The Theory of XSS, XSS Attack Vectors, Is the Organization's Site Vulnerable to Cross-Site Scripting? Example of a Cross-Site Scripting Attack, How to check for Cross-Site Scripting Vulnerabilities, Zero-Day Exploits and Advanced Persistent Threats (APTS), Unknown Vulnerabilities management Process, Five Phases of APT, Brute-Force Attacks, Instant Messaging, Infected Factory Builds and Media, man-in-the-Middle Malcode, Malicious Activity Countermeasures, Network Layer, Application Layer, Modified Hosts File and DNS Changes, Inspection of Process, Rootkit, Rootkit Classifications, Behavioral Analysis of Malcode, and Static File Analysis....
Reading
18 videos (Total 109 min), 18 readings, 1 quiz
Video18 videos
Malicious Code and Activity: Key Concepts6m
Malicious Code and Activity: Malicious Code Countermeasures4m
Malicious Code and Activity: Software Exploitation Methods6m
Malicious Code and Activity: Software Exploitation Methods5m
Malicious Code and Activity: Code Signing5m
Malicious Code and Activity: Social Engineering6m
Malicious Code and Activity: Security Awareness Training6m
Malicious Code and Activity: Long File Extensions5m
Malicious Code and Activity: E-mail7m
Malicious Code and Activity: Countermeasures5m
Malicious Code and Activity: Examples of Spoofing5m
Malicious Code and Activity: Techniques5m
Malicious Code and Activity: Botnet-Led Exploits6m
Malicious Code and Activity: Malicious Web Activity6m
Malicious Code and Activity: Zero-Day Exploits4m
Malicious Code and Activity: Infected Factory Builds and Media4m
Malicious Code and Activity: Inspection of Processes7m
Reading18 readings
Systems and Application Security10m
Malicious Code and Activity: Key Concepts10m
Malicious Code and Activity: Malicious Code Countermeasures10m
Malicious Code and Activity: Software Exploitation Methods10m
Malicious Code and Activity: Software Exploitation Methods10m
Malicious Code and Activity: Code Signing10m
Malicious Code and Activity: Social Engineering10m
Malicious Code and Activity: Security Awareness Training10m
Malicious Code and Activity: Long File Extensions10m
Malicious Code and Activity: E-mail10m
Malicious Code and Activity: Countermeasures10m
Malicious Code and Activity: Examples of Spoofing10m
Malicious Code and Activity: Techniques10m
Malicious Code and Activity: Botnet-Led Exploits10m
Malicious Code and Activity: Malicious Web Activity10m
Malicious Code and Activity: Zero-Day Exploits10m
Malicious Code and Activity: Infected Factory Builds and Media10m
Malicious Code and Activity: Inspection of Processes10m
Quiz1 practice exercise
Quiz 120m
Week
2
Hours to complete
1 hour to complete

Implement and Operate Endpoint Device Security

Module Topics: Host-Based Intrusion Detection Systems (HIDS), Host-Based Firewalls, Application Whitelisting, Endpoint Encryption, Trusted Platform Module (TPM), Mobile Device Management (MDM), Secure Browsing. In Host-Based Intrusion Detection Systems (HIDS), you will learn about Advantages and Disadvantages of HIDS. In Application Whitelisting, you will learn about software Restriction Policies (SRP), Trusted Platform Module (TPM). In Mobile Device Management (MDM), you will learn about Bring your Own Device (BYOD), Security, BYOD Policy Considerations, BYOD Policy Considerations, Corporate Owned, Personally Enabled (COPE), and Secure Browsing....
Reading
3 videos (Total 15 min), 3 readings, 1 quiz
Video3 videos
Endpoint Device Security: Trusted Platform Module (TPM)6m
Endpoint Device Security: BYOD Policy Considerations2m
Reading3 readings
Endpoint Device Security: HIDS10m
Endpoint Device Security: Trusted Platform Module (TPM)10m
Endpoint Device Security: BYOD Policy Considerations10m
Quiz1 practice exercise
Quiz 210m
Week
3
Hours to complete
5 hours to complete

Operate and Configure Cloud Security

Module Topics: Introduction, Deployment Models, Service Models, Virtualization, Legal and Privacy Concerns, Classification of Discovered Sensitive Data, Mapping and Definition of Controls, Application of Defined Controls for Personally Identifiable Information (PII), Data Storage and Transmission, Encryption, Key Management, Masking/Obfuscation and Anonymization, Tokenization, Data Deletion Procedures and Mechanisms, Event Sources, Data Event Logging and Event Attributes, and Storage and Analysis of Data Events. Introduction covers the Five Essential Characteristics of Clouds. Deployment Models cover topics like Public, Private, Hybrid and Community Cloud, Service Models, SaaS, PaaS, and IaaS. Virtualization includes Hypervisor, and Types of Virtualization. In Legal and Privacy Concerns, you will learn about Key P&DP Questions, Country-Specific Legal Considerations, Jurisdiction and Applicable Law, Essential Requirements in P&DP Laws, Typical Meaning for Common Privacy Terms, Privacy Roles for Customer and Service Provider, Data Discovery, and Privacy Level Agreement (PLA). In Application of Defined Controls for Personally Identifiable Information (PII), you will learn about Cloud security Alliance Cloud Controls Matrix (CCM), CCM Security Domains, Data Dispersion in Cloud Storage, Threat to storage Types, Technologies Available to Address Threats, Data Loss Prevention (DLP), DLP Components, DLP Architecture, Cloud-Based DLP Considerations, and Best Practices. In Encryption, you will learn about Sample Use cases for Encryption, Cloud Encryption Challenges, Key Management, Key Storage in the Cloud, and Key Management in Software environments. In Masking/Obfuscation and Anonymization, you will learn about Data Masking/Obfuscation, Common Approaches for Data Masking, Primary Methods of Masking Data, and Data Anonymization. Tockenization covers topics like Tokenization and Cloud, Data Retention Policies, Data Deletion Procedures and Mechanisms, Disposal Options, Crypto-shredding, Data Archiving Policy, Security and Information Event Management (SIEM). Data Event Logging and Event Attributes covers topics like OWASP Recommendations, SIEM Capabilities, and SIEM Challenges. ...
Reading
16 videos (Total 105 min), 16 readings, 1 quiz
Video16 videos
Cloud Security: Hybrid5m
Cloud Security: Virtualization7m
Cloud Security: Hypervisor4m
Cloud Security: Country-Specific Legal Considerations6m
Cloud Security: P&DP Laws6m
Cloud Security:Application of Defined Controls for Personally Identifiable Information (PII)8m
Cloud Security: Data Dispersion5m
Cloud Security: Threat to Storage Types9m
Cloud Security: Technologies to Address Threats4m
Cloud Security: DLP Architecture7m
Cloud Security: Review Activity6m
Cloud Security: Key Storage in the Cloud4m
Cloud Security: Common Approaches for Data Masking4m
Cloud Security: Data Retention Policies7m
Cloud Security: Disposal Options8m
Reading16 readings
Cloud Security: Five Essential Characteristics of Clouds10m
Cloud Security: Hybrid10m
Cloud Security: Virtualization10m
Cloud Security: Hypervisor10m
Cloud Security: Country-Specific Legal Considerations10m
Cloud Security: P&DP Laws10m
Cloud Security: Application of Defined Controls for Personally Identifiable Information (PII)10m
Cloud Security: Data Dispersion10m
Cloud Security: Threat to Storage Types10m
Cloud Security: Technologies to Address Threats10m
Cloud Security: DLP Architecture10m
Cloud Security: Review Activity10m
Cloud Security: Key Storage in the Cloud10m
Cloud Security: Common Approaches for Data Masking10m
Cloud Security: Data Retention Policies10m
Cloud Security: Disposal Options10m
Quiz1 practice exercise
Quiz 320m
Week
4
Hours to complete
3 hours to complete

Secure Big Data Systems & Operate and Secure Virtual Environments

Module Topics for Secure Big Data Systems: Application Vulnerabilities and Architecture or Design Environments. Application Vulnerabilities include topics like Data Growth, Big Data, Interpreting Big, Data, Big Data Issues, and Challenges with 'Free' Analytic Tools. Architectural or Design Environments include topics like Distributed Computing Architectures, Key Challenges, Securing the Organization's Big Data, and Deploying Big Data for Security. Module Topics for Operate and Secure Virtual Environments: Software-Defined Network (SDN), Virtual Appliances, Continuity and Resilience, Attacks and Countermeasures, Common Virtualization Attacks, Recommendations and Best Practices for Secure Virtualization, and Shared Storage. In Software-Defined network (SDN), you will learn about How SDN Works. Virtual Appliances talks about Virtual Appliances Compared to Virtual Machines. In Continuity and Resilience you will learn about Host Clustering Concepts, VMware Distributed Resource Scheduling (DRS), Scalability and Reliability, windows Failover Clustering. In Common Virtualization Attacks, you will learn about Mitigation Strategies. In Recommendations and Best Practices for Secure Virtualization you will learn about Desktop Virtualization and Security, Network Security, Storage Networks, Auditing and Logging, Virtual Machine Security, Management Systems, Hypervisor Security, Time Synchronization, Remote Access, Backups, and Configuration and Change Management. ...
Reading
9 videos (Total 70 min), 9 readings, 1 quiz
Video9 videos
Secure Big Data Systems: Interpreting Big Data4m
Secure Big data Systems: Key Challenges5m
Operate and Secure Virtual Environments: SDN5m
Operate and Secure Virtual Environments: Virtual Appliances8m
Operate and Secure Virtual Environments: DRS10m
Operate and Secure Virtual Environments: Common Attacks6m
Operate and Secure Virtual Environments: Network Security5m
Operate and Secure Virtual Environments: Virtual Machine Security16m
Reading9 readings
Secure Big Data Systems: Big Data10m
Secure Big Data Systems: Interpreting Big Data10m
Secure Big data Systems: Key Challenges10m
Operate and Secure Virtual Environments: SDN10m
Operate and Secure Virtual Environments: Virtual Appliances10m
Operate and Secure Virtual Environments: DRS10m
Operate and Secure Virtual Environments: Common Attacks10m
Operate and Secure Virtual Environments: Network Security10m
Operate and Secure Virtual Environments: Virtual Machine Security10m
Quiz1 practice exercise
Quiz 412m
5.0

Top Reviews

By GBJul 5th 2018

Thank you. Great course. The instructor breaks everything down, and makes it easy to learn.

Instructor

Avatar

(ISC)² Education & Training

Education & Training

About (ISC)²

(ISC)² is an international nonprofit membership association focused on inspiring a safe and secure cyber world. Best known for the acclaimed Certified Information Systems Security Professional (CISSP®) certification, (ISC)2 offers a portfolio of credentials that are part of a holistic, programmatic approach to security. www.isc2.org ...

About the (ISC)² Systems Security Certified Practitioner (SSCP) Specialization

Pursue better IT security job opportunities and prove knowledge with confidence. The SSCP Professional Training Certificate shows employers you have the IT security foundation to defend against cyber attacks – and puts you on a clear path to earning SSCP certification. Learn on your own schedule with 120-day access to content aligned with the latest (ISC)2 SSCP exam domains. We’re offering the complete online self-paced program for only $1,000 – a $200 savings when you get all domains bundled together. 3 Steps to Career Advancement 1. Register for the course 2. Gain access for 120 days 3. Register and sit for the SSCP certification exam Upon completing the SSCP Professional Certificate, you will: 1. Complete six courses of preparing you to sit for the Systems Security Certified Practitioner (SSCP) certification exam as outlined below. Course 1 - Access Controls Course 2 - Security Operations and Administration Course 3 - Risk Identification, Monitoring, and Analysis/Incident Response and Recovery Course 4 - Cryptography Course 5 - Network and Communication Security Course 6 - Systems and Application Security 2. Receive a certificate of program completion. 3. Understand how to implement, monitor and administer an organization’s IT infrastructure in accordance with security policies and procedures that ensure data confidentiality, integrity and availability....
(ISC)² Systems Security Certified Practitioner (SSCP)

Frequently Asked Questions

  • Yes, you can preview the first video and view the syllabus before you enroll. You must purchase the course to access content not included in the preview.

  • If you decide to enroll in the course before the session start date, you will have access to all of the lecture videos and readings for the course. You’ll be able to submit assignments once the session starts.

  • Once you enroll and your session begins, you will have access to all videos and other resources, including reading items and the course discussion forum. You’ll be able to view and submit practice assessments, and complete required graded assignments to earn a grade and a Course Certificate.

  • If you complete the course successfully, your electronic Course Certificate will be added to your Accomplishments page - from there, you can print your Course Certificate or add it to your LinkedIn profile.

  • This course is one of a few offered on Coursera that are currently available only to learners who have paid or received financial aid. If you’d like to take this course, but can’t afford the course fee, we encourage you to submit a financial aid application.

  • The course schedule contains approximately 15 hours of content material covering lectures, reading materials, a case study, and quizzes broken up over the course of 7 weeks.

More questions? Visit the Learner Help Center.