Seminarinformationen

Seminar - Ziel

In diesem 5-tägigen Seminar „Certified Security Specialist (ECSS)“ des EC-Council erwerben Sie umfassendes Wissen in den Bereichen Informations- und Netzwerksicherheit. Sie beschäftigen sich mit grundlegenden Sicherheitskonzepten, den Aufbau und Schutz von Netzwerken sowie typischen Bedrohungen und Schwachstellen.

Im Seminar lernen Sie unter anderem sichere Netzwerkprotokolle, gängige Angriffsarten und Social-Engineering-Methoden kennen. Sie werden mit den Phasen des Hacking-Zyklus vertraut gemacht und erhalten Einblicke in Themen wie Identifikation, Authentifizierung, Autorisierung und Kryptografie. Weitere Inhalte umfassen Firewalls, Intrusion Detection Systeme (IDS), Datensicherung, VPNs, Sicherheit in drahtlosen Netzwerken, Web Security, Ethical Hacking, Incident Response und digitale Forensik. Auch das Sammeln digitaler Beweise und das Erstellen forensischer Berichte sind Bestandteil des Trainings.

Ziel des Seminars ist es, Sie in die Lage zu versetzen, Sicherheitslücken frühzeitig zu erkennen, Angriffen effektiv entgegenzuwirken und geeignete Reaktions- und Schutzmaßnahmen zu ergreifen. Nach Abschluss sind Sie befähigt, Sicherheitslösungen für IT-Umgebungen zu planen und umzusetzen sowie bei Sicherheitsvorfällen professionell zu handeln.

Das Seminar wird von einem zertifizierten EC-Council-Trainer geleitet. Die Prüfungsgebühr ist im Preis inbegriffen.

Teilnehmer - Zielgruppe

  • Schüler und Studierende
  • Berufs- oder Quereinsteiger
  • IT-Mitarbeiter
  • Cybersecurity-Einsteiger
  • IT-Fachkräfte
  • Karrierewechsler

Kurs - Voraussetzungen

Für diesen Kurs sind keine Voraussetzungen nötig.

Seminardauer

  • 5 Tage
  • 09:00 Uhr bis 17:00 Uhr

Schulungsunterlagen

  • nach Absprache

Seminar-Inhalt / Agenda

Module 01: Network Security Fundamentals

  • Fundamentals of Network Security
  • Essential Network Security Protocols

Module 02: Identification, Authentication, and Authorization

  • Access Control Principles, Terminologies, and Models
  • Identity and Access Management (IAM) Concepts

Module 03: Network Security Controls - Administrative Controls

  • Regulatory Frameworks and Compliance Requirements
  • Design and Develop Security Policies
  • Security and Awareness Training

Module 04: Network Security Controls - Physical Controls

  • Introduction to Physical Security
  • Physical Security Controls
  • Workplace Security
  • Environmental Controls

Module 05: Network Security Controls - Technical Controls

  • Network Segmentation and Perimeter Isolation
  • Firewalls Technologies and Deployment Practices
  • Types of IDS/IPS and Deployment Practices
  • Types of Honeypots
  • Types of Proxy Servers and their Benefits
  • Fundamentals of VPN and its importance in Network Security
  • Security Incident and Event Management (SIEM)
  • User Behavior Analytics (UBA)
  • Various Security Software

Module 06: Virtualization and Cloud Computing

  • Virtualization Essential Concepts and OS Virtualization Security
  • Cloud Computing Fundamentals
  • Cloud Security and Best Practices

Module 07: Wireless Network Security

  • Wireless Network Fundamentals
  • Wireless Network Encryption Mechanisms
  • Different Types of Wireless Network Authentication Methods
  • Implement Wireless Network Security Measures

Module 08: Mobile Device Security

  • Mobile Device Connection Methods
  • Mobile Device Attacks
  • Mobile Device Management Concepts
  • Mobile Usage Policies in Enterprises
  • Security Risks and Guidelines Associated with Enterprises Mobile Usage Policies
  • Implement Enterprise-level Mobile Security Management Solutions
  • Implement General Security Guidelines and Best Practices on Mobile Platforms

Module 09: IoT Device Security

  • IoT Devices, Application Areas, and Communication Models
  • Security in IoT-enabled Environments

Module 10: Cryptography and PKI

  • Cryptographic Techniques
  • Cryptographic Algorithms
  • Cryptography Tools
  • Public Key Infrastructure (PKI)

Module 11: Data Security

  • Data Security and its Importance
  • Security Controls for Data Encryption
  • Data Backup and Retention
  • Data Loss Prevention Concepts

Module 12: Network Traffic Monitoring

  • Network Traffic Monitoring
  • Setting up the Environment for Network Monitoring
  • Baseline Traffic Signatures for Normal and Suspicious Network Traffic
  • Network Monitoring for Suspicious Traffic

Module 13: Information Security Fundamentals

  • Overview of Information Security
  • Overview of Threats and Their Sources
  • Cryptography Fundamentals
  • Information Security Laws, Regulations and Standards

Module 14: Ethical Hacking Fundamentals

  • Hacking Concepts and Hacker Classes
  • Ethical Hacking Concepts, Scope, and Limitations
  • Phases of Hacking Cycle
  • Hacking Methodologies and Frameworks

Module 15: Malware Threats and Countermeasures

  • Introduction to Malware
  • Malware Types
  • Malware Countermeasures

Module 16: Ethical Hacking Phases

  • Reconnaissance
  • Vulnerability Scanning
  • Gaining Access
  • Maintaining Access
  • Covering Tracks

Module 17: Password Cracking Techniques and Countermeasures

  • Password Cracking Techniques
  • Password Cracking Tools
  • Password Cracking Countermeasures

Module 18: Social Engineering Techniques and Countermeasures

  • Social Engineering Concepts
  • Social Engineering Techniques
  • Insider Threats and Identity Theft
  • Social Engineering Countermeasures

Module 19: Network Level Attacks and Countermeasures

  • Packet Sniffing Concepts
  • Sniffing Techniques
  • Sniffing Tools
  • Sniffing Countermeasures
  • Overview of DoS and DDoS Attacks
  • DoS/DDoS Attack Techniques
  • DoS/DDoS Attack Countermeasures
  • Overview of Session Hijacking
  • Session Hijacking Methods
  • Session Hijacking Attack Countermeasures

Module 20: Web Application Attacks and Countermeasures

  • Introduction to Web Server Attacks
  • Types of Web Server Attacks
  • Web Server Attacks Countermeasures
  • Web Application Architecture
  • Web Application Threats and Attacks
  • Web Application Attack Countermeasures
  • Overview of SQL Injection Attacks
  • Types of SQL Injection Attack
  • SQL Injection Attack Countermeasures

Module 21: Wireless Attacks and Countermeasures

  • Introduction to Wireless Networks
  • Wireless Network Security Fundamentals
  • Common Wireless Attack Techniques
  • Bluetooth Attack and Security
  • Wireless Attack Countermeasures

Module 22: Mobile, IoT, and OT Attacks and Countermeasures

  • Introduction to Mobile Attack Anatomy
  • Mobile Platform Attack Vectors and Vulnerabilities
  • Mobile Device Management (MDM)
  • Mobile Attack Countermeasures
  • Introduction to IoT
  • IoT Threats and Attacks
  • IoT Attack Countermeasures
  • OT Fundamental Concepts
  • OT Threats and Attacks
  • OT Attack Countermeasures

Module 23: Cloud Computing Threats and Countermeasures

  • Introduction to Cloud Computing Concepts
  • Introduction to Container Technology
  • Cloud Computing Threats
  • Cloud Attack Countermeasures

Module 24: Penetration Testing Fundamentals

  • Introduction to Penetration Testing
  • Penetration Testing Concepts
  • Guidelines and Recommendations for Penetration Testing

Module 25: Computer Forensics Fundamentals

  • Introduction to Computer Forensics
  • Digital Evidence
  • Forensic Readiness
  • Role of a Forensic Investigator
  • Legal Compliance in Computer Forensics

Module 26: Computer Forensics Investigation Process

  • Forensic Investigation Process and its Importance
  • Forensic Investigation Process: Pre-investigation Phase
  • Forensic Investigation Process: Investigation Phase
  • Forensic Investigation Process: Post-investigation Phase

Module 27: Hard Disks and File Systems

  • Different Types of Disk Drives and Their Characteristics
  • Logical Structure of a Disk
  • The Booting Process of Windows, Linux, and macOS
  • File Systems in Windows, Linux, and macOS
  • Examine the File System

Module 28: Data Acquisition and Duplication

  • Data Acquisition Fundamentals
  • Types of Data Acquisition
  • Data Acquisition Methods
  • Data Acquisition Formats
  • Data Acquisition Methodology

Module 29: Defeating Anti-forensics Techniques

  • Introduction to Anti-forensics and its Techniques
  • Anti-forensics Countermeasures

Module 30: Windows Forensics

  • Introduction to Windows Forensics
  • Collect Volatile and Non-Volatile Information
  • Perform Windows Memory Analysis
  • Windows Artifacts
  • Web Browser Forensics
  • Examine Windows Files and Metadata

Module 31: Linux and Mac Forensics

  • Volatile and Non-Volatile Data in Linux
  • Analyze Filesystem Images Using The Sleuth Kit
  • Linux Memory Forensics
  • Mac Forensics

Module 32: Network Forensics

  • Network Forensics Fundamentals
  • Event Correlation Concepts and Types
  • Identify Indicators of Compromise (IoCs) from Network Logs
  • Investigate Network Traffic

Module 33: Investigating Web Attacks

  • Web Application Forensics
  • IIS and Apache Web Server Logs
  • Web Attacks on Windows-based Servers
  • Detect and Investigate Various Attacks on Web Applications

Module 34: Dark Web Forensics

  • Introduction to the Dark Web
  • Dark Web Forensics
  • Tor Browser Forensics

Module 35: Investigating Email Crimes

  • Email Basics
  • Email Crime Investigation

Module 36: Malware Forensics

  • Malware Components and Distribution
  • Malware Forensics Fundamentals
  • Static Malware Analysis
  • Suspicious Word Documents Analysis
  • Dynamic Malware Analysis
  • System Behavior Analysis
  • Network Behavior Analysis

Weitere Schulungen zu Thema EC-Council

Certified Incident Handler (ECIH)

- u.a. in Nürnberg, Berlin, Stuttgart, München, Köln

In diesem 3-tägigen Seminar „Certified Incident Handler (ECIH)“ erhalten Sie umfassendes Wissen zum Incident-Handling und zur Reaktion auf Sicherheitsvorfälle im Bereich der Informationssicherheit. Das Seminar vermittelt nicht nur theoretische Grundlagen, sondern legt ...

Certified Network Defender (CND)

- u.a. in Nürnberg, Berlin, Stuttgart, München, Köln

In diesem 5-tägigen Seminar „Certified Network Defender (CND)“ erwerben Sie die wichtigen Fähigkeiten, um als Netzwerkadministrator gezielt auf potenzielle Bedrohungen zu reagieren. Angesichts der zunehmenden Cyberkriminalität ist es entscheidend, über das nötige ...

Certified SOC-Analyst (CSA)

- u.a. in Frankfurt am Main, Köln, Düsseldorf, Mannheim, Virtual Classroom

In diesem 3-tägigen Seminar „Certified SOC-Analyst (CSA)” erhalten Sie ein intensives Trainings- und Qualifizierungsprogramm, das von erfahrenen Experten aus der Branche geleitet wird. Ziel des Seminars ist es, Ihnen gefragte technische Fähigkeiten zu vermitteln, die Sie ...

Computer Hacking Forensic Investigator (CHFI)

- u.a. in Stuttgart, München, Wien, Dresden, Erfurt

In diesem 5-tägigen Seminar „Computer Hacking Forensic Investigator (CHFI)“ erwerben Sie fundiertes Basiswissen zu den wichtigsten Konzepten und Methoden der digitalen Forensik, die für moderne Unternehmen relevant sind. Digitale Forensik beschäftigt sich mit dem Sammeln ...