Hướng Dẫn Thực Hành Bảo Mật Mạng: Lab Manual cho Security+ Guide

Hướng dẫn thực hành về các nguyên tắc cơ bản của bảo mật mạng, cung cấp kiến thức và kỹ năng cần thiết để bảo vệ hệ thống mạng hiệu quả.

Trường đại học

Cengage Learning

Chuyên ngành

Network Security

Người đăng

Ẩn danh

Thể loại

Lab Manual

2016

286
8
0

Phí lưu trữ

55 Point

Mục lục chi tiết

1. CHAPTER ONE: Introduction to Security Lab

1.1. Online Rescarch—Certifcation Lab

1.2. Online Research—Information Security Careers Lab

1.3. Online Research—SANS Reading Room Lab

1.4. Online Research—Which Is the “Safest™ Operating System? Lab

1.5. Online Research—Information Security Policies

2. CHAPTER TWO: Malware and Social Engineering Attacks

2.1. Eicar Antivirus Test File

2.2. Remote Program Execution

2.3. Checking for Unsigned Programs

2.4. Validating a Downloaded Program

2.5. Acceptable Use Policy

3. CHAPTER THREE: Application and Networking-Based Attacks

3.1. Getting Started with Kali Linux

3.2. IP Spoofing with Hping3

3.3. ARP Poisoning

3.4. Man-in-the-Middle Attack

4. CHAPTER FOUR: Host, Application, and Data Security

4.1. Exploring the Windows Server 2012 R2 Security Configuration Wizard

4.2. Creating a Security Template

4.3. Analyzing Security Configurations

4.4. Applying Security Settings from a Security Template and Verifying System Compliance

4.5. Auditing Object Access

5. CHAPTER FIVE: Basic Cryptography

5.1. Encrypting Files from the Command Prompt

5.2. Demonstrating Encryption Security

5.3. Examining the Relationship Between EFS and NTFS Permissions

5.4. Using EFS Recovery Agent Certificates

5.5. Breaking the Code

6. CHAPTER SIX: Advanced Cryptography

6.1. Installing Certificate Services

6.2. Configuring Secure Sockets Layer

6.3. Using Certificate Services Web Enrollment

6.4. Configuring Certificate Auto- Enrollment

6.5. Acceptable Encryption Policy

7. CHAPTER SEVEN: Network Security

7.1. Verifying the Integrity of the Hosts File

7.2. Installing the FTP Server Service and Wireshark

7.3. Capturing and Analyzing FTP Traffic

7.4. Capturing and Analyzing Telnet Traffic

7.5. Data Loss Prevention

8. CHAPTER EIGHT: Administering a Secure Network

8.1. Configuring Windows Firewall on Windows Server 2012

8.2. Configuring Windows Firewall on Windows 7

8.3. Installing and Configuring an SSH Server

8.4. Installing and Configuring an SSH Client

8.5. Researching IPV6

9. CHAPTER NINE: Wireless Network Security

9.1. Installing a SOHO Wireless Router/Access Point

9.2. Installing and Configuring a Wireless Adapter

9.3. Configuring an Enterprise Wireless Access Point

9.4. Configuring Wireless Security

9.5. Exploring Access Point Settings

10. CHAPTER TEN: Mobile Device Security

10.1. File Transfer Using Bluetooth

10.2. Getting Bluetooth Info with Bluesnarfer

10.3. Kali Linux Mobile Device Security Tools

10.4. Physical Security

10.5. BYOD Policies

11. CHAPTER ELEVEN: Access Control Fundamentals

11.1. Setting NTFS Permissions

11.2. Using NTFS Permissions

11.3. Setting and Testing Share Permissions

11.4. Auditing Permissions

12. CHAPTER TWELVE: Authentication and Account Management

12.1. Setting a Minimum Password Length Policy

12.2. Setting Password History and Minimum Password Age Policy

12.3. Enforcing Password Complexity Requirements

12.4. Setting Policies for Account Lockouts and Log on Hours

12.5. Restricting Access to Programs

13. CHAPTER THIRTEEN: Business Continuity

13.1. Installing VMware Player

13.2. Adding Hard Drives to a Virtual Machine

13.3. Creating RAID

13.4. Creating Fault Tolerant RAID

13.5. Comparing a System's Current State to Its Baseline State

14. CHAPTER FOURTEEN: Risk Mitigation

14.1. Online Research—Ethics in Information Technology

14.2. Online Rescarch—The Cloud

14.3. Creating a Laptop Policy

14.4. The Human Resources Department’ Role in Information Security

14.5. Exploring the ISO/IEC 27002 Standard

15. CHAPTER FIFTEEN: Vulnerability Assessment and Mitigating Attacks

15.3. Web Server Vulnerability Testing with Vega

15.4. Exploitation and Payload Delivery

15.5. Working with Meterpreter

Tóm tắt

I. Hướng dẫn thực hành bảo mật mạng Tổng quan về Security

Bảo mật mạng là một lĩnh vực quan trọng trong công nghệ thông tin, đặc biệt là trong bối cảnh ngày càng gia tăng các mối đe dọa từ tội phạm mạng. Hướng dẫn thực hành bảo mật mạng này sẽ cung cấp cho người học những kiến thức và kỹ năng cần thiết để vượt qua kỳ thi Security+ của CompTIA. Nội dung sẽ bao gồm các bài lab thực hành, giúp người học áp dụng lý thuyết vào thực tế.

1.1. Giới thiệu về Security và tầm quan trọng của nó

Chứng chỉ Security+ là một trong những chứng chỉ được công nhận rộng rãi trong ngành bảo mật thông tin. Nó cung cấp kiến thức cơ bản về bảo mật mạng, giúp người học hiểu rõ hơn về các mối đe dọa và cách phòng chống chúng.

1.2. Cấu trúc của lab manual cho Security

Lab manual cho Security+ được thiết kế để hỗ trợ người học thực hành các kỹ năng bảo mật mạng. Mỗi lab đều có mục tiêu rõ ràng và hướng dẫn chi tiết, giúp người học dễ dàng theo dõi và thực hiện.

II. Các thách thức trong bảo mật mạng hiện nay

Bảo mật mạng đối mặt với nhiều thách thức, từ các cuộc tấn công mạng tinh vi đến việc quản lý rủi ro. Những thách thức này đòi hỏi các chuyên gia bảo mật phải luôn cập nhật kiến thức và kỹ năng mới. Việc hiểu rõ các thách thức này sẽ giúp người học chuẩn bị tốt hơn cho sự nghiệp trong lĩnh vực bảo mật.

2.1. Tăng cường tấn công mạng và các phương pháp phòng chống

Các cuộc tấn công mạng ngày càng trở nên tinh vi hơn, từ tấn công DDoS đến tấn công lừa đảo. Việc nắm vững các phương pháp phòng chống là rất cần thiết để bảo vệ hệ thống thông tin.

2.2. Quản lý rủi ro trong bảo mật thông tin

Quản lý rủi ro là một phần quan trọng trong bảo mật mạng. Các chuyên gia cần phải đánh giá và phân tích các rủi ro tiềm ẩn để đưa ra các biện pháp phòng ngừa hiệu quả.

III. Phương pháp thực hành bảo mật mạng hiệu quả

Để thực hành bảo mật mạng hiệu quả, người học cần áp dụng các phương pháp và công cụ phù hợp. Các lab trong hướng dẫn này sẽ giúp người học làm quen với các công cụ bảo mật phổ biến và cách sử dụng chúng trong thực tế.

3.1. Sử dụng Kali Linux trong bảo mật mạng

Kali Linux là một trong những hệ điều hành phổ biến nhất cho các chuyên gia bảo mật. Nó cung cấp nhiều công cụ hữu ích cho việc kiểm tra bảo mật và phân tích mạng.

3.2. Kiểm tra bảo mật với Wireshark

Wireshark là một công cụ phân tích mạng mạnh mẽ, cho phép người dùng theo dõi và phân tích lưu lượng mạng. Việc sử dụng Wireshark giúp người học hiểu rõ hơn về cách thức hoạt động của mạng và phát hiện các vấn đề bảo mật.

IV. Ứng dụng thực tiễn của bảo mật mạng trong doanh nghiệp

Bảo mật mạng không chỉ là lý thuyết mà còn có ứng dụng thực tiễn trong các doanh nghiệp. Việc áp dụng các biện pháp bảo mật hiệu quả sẽ giúp doanh nghiệp bảo vệ thông tin và duy trì hoạt động kinh doanh.

4.1. Chính sách bảo mật thông tin trong doanh nghiệp

Doanh nghiệp cần xây dựng và thực hiện các chính sách bảo mật thông tin rõ ràng để bảo vệ dữ liệu và tài sản của mình. Các chính sách này cần được cập nhật thường xuyên để phù hợp với các mối đe dọa mới.

4.2. Đào tạo nhân viên về bảo mật mạng

Đào tạo nhân viên về bảo mật mạng là một phần quan trọng trong chiến lược bảo mật của doanh nghiệp. Nhân viên cần được trang bị kiến thức và kỹ năng để nhận diện và ứng phó với các mối đe dọa.

V. Kết luận và tương lai của bảo mật mạng

Bảo mật mạng là một lĩnh vực không ngừng phát triển. Với sự gia tăng của các mối đe dọa, nhu cầu về các chuyên gia bảo mật mạng sẽ tiếp tục tăng cao. Việc nắm vững các kiến thức và kỹ năng trong lĩnh vực này sẽ mở ra nhiều cơ hội nghề nghiệp cho người học.

5.1. Xu hướng mới trong bảo mật mạng

Các xu hướng mới như bảo mật đám mây và bảo mật IoT đang trở thành tâm điểm trong ngành bảo mật mạng. Người học cần theo dõi và cập nhật các xu hướng này để không bị lạc hậu.

5.2. Tương lai của chứng chỉ Security

Chứng chỉ Security+ sẽ tiếp tục giữ vai trò quan trọng trong việc xác nhận kiến thức và kỹ năng của các chuyên gia bảo mật. Việc chuẩn bị cho kỳ thi này sẽ giúp người học tự tin hơn trong sự nghiệp của mình.

10/07/2025
Lab manual for security guide to network security fundamentals compress

Trích đoạn nội dung tài liệu

Hith Edlition »» mm ce Copyright 2016 Cengage Learning, All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Andrew Hurd, Dean Farwood ^ » CENGAGE «© Learning” ‘Australia « Brazil Mexico» Singapore = United Kingdom + United States CENGAGE Learning: Lab Manual for Security+ Guide © 2016, 2012 Cengage Learning to Network Security Fundamentals, WEN: 02-200-202 Fifth Edition ‘Andrew Hurd, Dean Farwood ALL RIGHTS RESERVED. No part of this work covered by the copyright herein may be reproduced, transmitted, stored or used in any form or by SVP, GM Skills & Global Product any means graphic, electronic, or mechanical, including but not limited to ‘Management: Dawn Gerrain photocopying, recording, scanning, digitizing, taping, Web distribution, Product Director: Kathleen McMahon Information networks, or information storage and retrieval systems, except Product Team Manager: Kristin McNary 23s permitted under Section 107 or 108 ofthe 1976 United States Copyright ‘Act, without the prior written permission of the publisher.

Senior Director, Development: Marah cron is arepistere tacemark of he Miro Carportion Bellegarde Security isa regstere trademark of Compra Properties. LC nome Product Development Manager: Leigh For produc information an technology sestance, contact ea ngage Lerning Customer & Sales Support, 800 334:9706 Sel Conterk vlog ch aon For permission ose mater fom ths text product, submit all requests online at wwwcengage. Product Assistant: Abigail Pufpaff Further permissions questions can be e-mailed to Vice President, Marketing Services: Jenifer ermissionrequest@cengage.com ‘Ann Baker Senior Marketing Manager: Eric La Scola brary of Congress Control Number: 2014940611 Senior Production Director: Wendy Troeger |SBN-13:978-1305-09525-0 Production Director: Patty Stephan Cengage Learning Senior Content Project Manager: Brooke 20 Channel Center Street Greenhouse Boston, MA 02210 ‘Managing Art Director: jack Pendleton USA Cover image: sading provider of customized learning solutions in nearly40 different countries and sales in more (© Sergey Nivens/Shutterstock com than 125 countries around the world. Find your local representative at -w0ww cengage.

Cengage Learning products are represented in Canada by Nelson Education, itd. To learn more about Cengage Learning, vist www.com Purchase any of our products at your local college store or at our preferred online store www.com Notice tothe Reader Publisher does not warantor guarantee ay of the products described herein or perform any independent analysis in connection with any ofthe product information contained herein. Publisher does not assume, and expressly disclaims, any obligation to obtain ad include information other than that provided tot by the manufacture.The reader is expressly warned toconsider and adoptll safety precautions that mightbe indicated following the instructions contained herein, thereader wilingly assumes. the activities byall risks describedwith herein in connection ad to avoid Theal potential such instructions.

makes noBy representations publisher hazards or waranties of any kind, including but not limited to, the warranties of fitness fr particular purposeor merchantably, nor are ary such representations implied with respect to the material set forth herein, and the publisher takes noresponsibilty with respectto such materia. The publisher shall not be liable or any special, consequential, or ‘exemplary damages resulting In whole or prt, from the readers use of of reliance upon this materia. ‘Some ofthe product names and company names usd i this book have been used for identification purposes only and may be trademarksor reglsteed trademarks oftheir respective manufacturers and sellers ‘Any fictional data related to persons or companiesor URLS used throughout this books intended for instructional purposes only. At the time this book was printed, any such data was fictional and not belonging to ary real personsor companies.

The programs in this book are fr instructional purposes only. They have been tested with care, but are not guaranted for any particular Intent beyond education purposes. The author andthe pubisher ono oer any warrants or represerttions, or othe accept any ables with respect tothe programs. Printed in the United States of America Print Number: 01 PrintYear:2015 Copyright 2016 Cengage Learning, All Rights Reserved.

May not be copied, scanned, or duplicated, in whole or in part. Table of Contents INTRODUCTION DEDICATION AND ACKNOWLEDGMENTS xix CHAPTER ONE Introduction to Security Lab 1.1 Online Rescarch—Certifcation Lab 1.2 Online Research—Information Security Careers Lab 1.3 Online Research—SANS Reading Room Lab 1.4 Online Research—Which Is the “Safest™ Operating System? Lab 1.5 Online Research—Information Security Policies CHAPTER TWO Malware and Social Engineering Attacks 3 Lab 2.1 Eicar Antivirus Test File 4 Lab 2.2 Remote Program Execution 18 Lab 2.3 Checking for Unsigned Programs 2 Lab 2.4 Validating a Downloaded Program 25 Lab 2.5 Acceptable Use Policy 28 CHAPTER THREE Application and Networking-Based Attacks 31 Lab 3.1 Getting Started with Kali Linux 3 Lab 3.2 IP Spoofing with Hping3 37 Lab 3.3 ARP Poisoning 4 Lab 3.4 Man-in-the-Middle Attack 45 CHAPTER FOUR Host, Application, and Data Security 49 Lab 4.1 Exploring the Windows Server 2012 R2 Security Configuration Wizard s0 Lab 4.2 Creating a Security Template “ Lab 4.3 Analyzing Security Configurations 38 ‘Lab 4.4 Applying Security Settings from a Security Template and Verifying System Compliance Lab 4.5 Auditing Object Access 6s CHAPTER FIVE Basic Cryptography n Lab 5.1 Encrypting Files from the Command Prompt n Lab 5.2 Demonstrating Encryption Security 7s Lab 5.3 Examining the Relationship Between EFS and NTFS Permissions 78 Copyright 2016 Cengage Learning, All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in pest. vi Table of Contents Lab 5.4 Using EFS Recovery Agent Certificates 81 Lab 5.5 Breaking the Code 84 CHAPTER SIX Advanced Cryptography 89 Lab 6.1 Installing Certificate Services 90 Lab 6.2 Configuring Secure Sockets Layer 8 Lab 6.3 Using Certificate Services Web Enrollment 100 Lab 6.4 Configuring Certificate Auto- Enrollment 103 Lab 6.5 Acceptable Encryption Policy 108 CHAPTER SEVEN Network Security 1 Lab 7.1 Verifying the Integrity of the Hosts File tạ Lab 7.2 Installing the FTP Server Service and Wireshark 116 Lab 7.3 Capturing and Analyzing FTP Traffic 120 Lab 7.4 Capturing and Analyzing Telnet Traffic 126 Lab 7.5 Data Loss Prevention 130 CHAPTER EIGHT ‘Administering a Secure Network 183 Lab 8.1 Configuring Windows Firewall on Windows Server 2012 134 Lab 8.2 Configuring Windows Firewall on Windows 7 137 Lab 8.3 Installing and Configuring an SSH Server m1 Lab 8.4 Installing and Configuring an SSH Client 145 Lab 8.5 Researching IPV6 149 CHAPTER NINE Wireless Network Security 151 Lab 9.1 Installing a SOHO Wireless Router/Access Point 152 Lab 9.2 Installing and Configuring a Wireless Adapter 187 Lab 9.3 Configuring an Enterprise Wireless Access Point 162 Lab 9.4 Configuring Wireless Security 168 Lab 9.5 Exploring Access Point Settings 1" CHAPTER TEN Mobile Device Security 7 Lab 10.1 File Transfer Using Bluetooth 178 Lab 10.2 Getting Bluetooth Info with Bluesnarfer 181 Lab 10.3 Kali Linux Mobile Device Security Tools 183 Lab 10.4 Physical Security 185 Lab 10.5 BYOD Policies 187 Copyright 2016 Cengage Learning, All Rights Reserved.

May not be copied, scanned, or duplicated, in whole or in part. Table of Contents vil CHAPTER ELEVEN ‘Access Control Fundamentals 189 Lab 11.1 Setting NTFS Permissions 190 Lab 11.2 Using NTFS Permissions 195 Lab 11.3 Setting and Testing Share Permissions 198 Lab 11.4 Auditing Permissions 202 CHAPTER TWELVE Authentication and Account Management zm Lab 12.1 Setting a Minimum Password Length Policy 212 Lab 12.2 Setting Password History and Minimum Password Age Poli 215 Lab 12.3 Enforcing Password Complexity Requirements 218 Lab 12.4 Setting Policies for Account Lockouts and Log on Hours 220 Lab 12.5 Restricting Access to Programs 226 CHAPTER THIRTEEN Business Continuity 231 Lab 13.1 Installing VMware Player 232 Lab 13.2 Adding Hard Drives to a Virtual Machine 234 Lab 13.3 Creating RAID 236 Lab 13.4 Creating Fault Tolerant RAID 241 Lab 13.5 Comparinga System's Current State to Its Baseline State 244 CHAPTER FOURTEEN Risk Mitigation 251 Lab 14.1 Online Research—Ethics in Information Technology 252 Lab 14.2 Online Rescarch—The Cloud 254 Lab 14.3 Creatinga Laptop Policy 257 Lab 14.4 The Human Resources Department’ Role in Information Security 260 Lab 14.5 Exploring the ISO/IEC 27002 Standard 262 CHAPTER FIFTEEN Vulnerability Assessment and Mitigating Attacks 265 Lab 15.3 Web Server Vulnerability Testing with Vega 273 Lab 15.4 Exploitation and Payload Delivery 275 Lab 15.5 Working with Meterpreter 279 Copyright 2016 Cengage Learning, All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Copyright 2016 Cengage Learning, All Rights Reserved.

May not be copied, scanned, or duplicated, in whole or in part. Introduction Hands-on learning is necessary to master the security skills needed for both CompTIA’s Security+ Exam and for a career in network security. This book contains hands-on exercises that use fundamental networking security concepts as they are applied in the real world. In addition, each chapter offers review questions to reinforce your mastery of network secu- rity topics and to sharpen your critical thinking and problem-solving skills.

The organiza- tion of this book follows that of Course Technology's Security+ Guide to Network Security Fundamentals, Fifth Edition, and using the two together will provide a substantial, effective learning experience. This book is suitable for use in a beginning or intermediate networking security course. As a prerequisite, students should have a fundamental understanding of gen- eral networking concepts and at least one course in network operating systems. This manual is best used when accompanied by Mark Ciampa’s Security+ Guide to Network Security Fundamentals, Fifth Edition.

Features ‘To ensure a successful experience for instructors and students alike, this manual includes the following feature ‘* Maps to CompTIA Objectives: The material in this text covers all of the CompTIA Security + SY0-401 exam objectives. + Lab Objectives: Every lab has an introductory description and list of learning objectives. * Materials Required: Every lab includes information on hardware, software, and other materials you will need to complete the lab. ‘* Completion Times: Every lab has an estimated completion time, so that you can plan your activities more accurately.

* Activity Sections: Labs are presented in manageable sections. Where appropriate, additional activity background information is provided to illustrate the importance of a particular project. ‘* Step-by-Step Instructions: Logical and precise step-by-step instructions guide you through the hands-on activities in each lab. + Review Questions: Questions help reinforce concepts presented in the lab.

New to This Edition + Server operating system updated to Windows 2012 R2 server + Fully maps to the latest CompTIA Security+ exam SY0-401 * All new chapter on mobile device security * Chapters grouped by major domains: Threats and Vulnerabilities; Application, Data and Host Security; Cryptography; Network Security; Access Control and Identity Management; and Compliance and Operational Security Copyright 2016 Cengage Learning, All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. x Introduction * All new chapter on Mobile Security * All new labs centered around Kali Linux * All new labs centered around computer security policies * Cryptography and advanced cryptography are covered earlier in the text Instructor Resources Answers to review questions are available online at the textbook’s website. Please visit login.com and log in to access instructor-specific resources.

To access additional course materials, please visit www. At the CengageBrain.com home page, search for the ISBN of your title (from the back cover of the textbook, Lab Manual for Security+ Guide to Network Security Fundamentals, Fifth Edition) using the search box at the top of the page. This will take you to the product page where these resources can be found. Information Security Community Site Stay secure with the Information Security Community Site! Connect with students, profes- sors, and professionals from around the world, and stay on top of this ever-changing field.comlcommunitylinfosec to: * Download resources such as instructional videos and labs.

* Ask authors, professors, and students the questions that are on your mind in our Dis- cussion Forums. * Sce up-to-date news, videos, and articles. * Read weekly blogs from author Mark Ciampa. * Listen to podcasts on the latest Information Security topics.

Copyright 2016 Cengage Learning, All Rights Reserved. May not be copied, scanned, or duplicated, in whole or in part. Introduction xi Hardware Requirements This section lists the hardware required to complete the labs in the book.

Nội dung được bảo vệ bản quyền — Tải xuống đầy đủ

Tài liệu "Hướng Dẫn Thực Hành Bảo Mật Mạng: Lab Manual cho Security+ Guide" cung cấp một cái nhìn tổng quan và chi tiết về các phương pháp bảo mật mạng, giúp người đọc nắm vững các kỹ thuật và công cụ cần thiết để bảo vệ hệ thống thông tin. Tài liệu này không chỉ hướng dẫn thực hành mà còn giải thích lý thuyết cơ bản, từ đó giúp người học có thể áp dụng kiến thức vào thực tế một cách hiệu quả.

Để mở rộng thêm kiến thức về bảo mật thông tin, bạn có thể tham khảo tài liệu "Luận văn một số giải pháp bảo mật hệ thống thông tin cho công ty cổ phần dịch vụ tất thành", nơi cung cấp các giải pháp cụ thể cho doanh nghiệp. Ngoài ra, tài liệu "Tìm hiểu giải pháp bảo mật cho dịch vụ truy cập từ xa sử dụng mã nguồn mở openssh" sẽ giúp bạn hiểu rõ hơn về bảo mật trong các dịch vụ truy cập từ xa. Cuối cùng, tài liệu "Luận văn an toàn và bảo mật dữ liệu bằng mã hóa ứng dụng trong hệ thống trao đổi văn bản điện tử" sẽ cung cấp cái nhìn sâu sắc về bảo mật dữ liệu trong các hệ thống thông tin.

Mỗi tài liệu này là một cơ hội để bạn khám phá sâu hơn về các khía cạnh khác nhau của bảo mật mạng và nâng cao kiến thức của mình trong lĩnh vực này.