Showing posts with label Training Kit. Show all posts
Showing posts with label Training Kit. Show all posts

Tuesday, August 9, 2011

Cloud Computing Virtualization Specialist Complete






Contents
FOREWORD____________________________ 1
1 INTRODUCTION______________________ 8
1.1 WHAT IS VIRTUALIZATION? 8
1.2 OBJECTIVES OF VIRTUALIZATION 9
1.3 HISTORY OF VIRTUALIZATION 11
1.4 BENEFITS OF VIRTUALIZED TECHNOLOGY 12
1.5 THE VIRTUAL SERVICE DESK 15
1.6 WHAT CAN BE VIRTUALIZED? 15
1.7 RELATED FORMS OF COMPUTING 17
1.7.1 CLOUD COMPUTING 17
1.7.2 SOFTWARE AS A SERVICE - SAAS 18
1.7.3 GRID COMPUTING 18
1.7.4 UTILITY COMPUTING 19
1.8 VIRTUALIZATION PROCESSES 19
1.9 INTRODUCTION REVIEW QUESTIONS 20
2 COMMON TERMINOLOGY 21
3 VIRTUALIZATION TECHNOLOGIES 26
3.1 UBUNTU (SERVER EDITION) 26
3.2 ALTIRIS 27
3.3 WINDOWS SERVER 28
3.4 SOFTWARE VIRTUALIZATION 29
3.5 VMWARE 30
3.6 INTEL VIRTUALIZATION 31
3.7 RED HAT VIRTUALIZATION 32
3.8 SOFTGRID APPLICATION 33
3.9 LINUX VIRTUALIZATION 35
3.10 DESKTOP VIRTUALIZATION 37
3.11 HARDWARE VIRTUALIZATION 38
3.12 RESOURCE VIRTUALIZATION 39
3.13 PROCESSOR VIRTUALIZATION 40
3.14 APPLICATION VIRTUALIZATION 41
3.15 STORAGE VIRTUALIZATION 42
3.16 VIRTUALIZATION DENSITY 43
3.17 PARA-VIRTUALIZATION 44
3.18 OS VIRTUALIZATION 44
3.19 VIRTUALIZATION SOFTWARE 46
3.20 DATA STORAGE VIRTUALIZATION 58
3.21 INTEL VIRTUALIZATION TECHNOLOGY 60
3.22 THINSTALL VIRTUALIZATION SUITE 62
3.23 NET FRAMEWORK VIRTUALIZATION 64
3.24 WINDOWS VIRTUALIZATION ON FEDORA 66
3.25 STORAGE VIRTUALIZATION TECHNOLOGIES 67
3.26 VIRTUALIZATION LEVEL 69
3.27 SECURITY MONITORING AND VIRTUALIZATION 70
3.28 ORACLE VIRTUALIZATION 74
3.29 VIRTUALIZATION TECHNOLOGIES REVIEW QUESTIONS 75
4 ACCOMPLISHING VIRTUALIZATION 76
4.1 MIGRATING TO A VIRTUALIZED ENVIRONMENT 76
4.1.1 THINGS TO DO AND CONSIDER BEFORE MIGRATION 76
4.2 THINGS TO DO AFTER MIGRATION 79
4.2.1 A SIMPLE HOW-TO GUIDE 80
4.2.2 FURTHER MIGRATION CONSIDERATIONS 83
4.2.3 RISKS ASSOCIATED WITH VIRTUALIZATION 90
4.2.4 PROBLEMS ASSOCIATED WITH VIRTUALIZATION 95
5 MANAGING A VIRTUALIZED ENVIRONMENT 97
5.1 SUPPORT ISSUES 97
5.2 MEASURING CAPACITY AND PERFORMANCE 99
5.3 CONTRACTS AND AGREEMENTS SUCH AS LICENSING 101
5.4 ORGANIZATIONAL CONSIDERATIONS 103
SERVICE MANAGEMENT PROCESSES 105
IT FINANCIAL MANAGEMENT 105
5.4.1 IT FINANCIAL MANAGEMENT AND VIRTUALIZATION 106
INFORMATION SECURITY MANAGEMENT 107
5.4.2 INFORMATION SECURITY MANAGEMENT AND VIRTUALIZATION 107
5.5 RELEASE & DEPLOYMENT MANAGEMENT 107
5.5.1 GOALS AND OBJECTIVES 108
5.5.2 SCOPE 108
5.5.3 BENEFITS 108
5.5.4 TERMINOLOGY 109
5.5.5 TRIGGERS AND INTERFACES 112
5.5.6 RELEASE DESIGN OPTIONS AND CONSIDERATIONS 113
5.5.7 RELEASE POLICY 115
5.5.8 RELEASE AND DEPLOYMENT ACTIVITIES 115
KNOWLEDGE MANAGEMENT 125
5.5.9 POLICIES AND PRINCIPLES OF KNOWLEDGE MANAGEMENT 126
5.5.10 THE SERVICE KNOWLEDGE MANAGEMENT SYSTEM (SKMS) 127
INCIDENT MANAGEMENT 128
5.5.11 INCIDENT MANAGEMENT AND VIRTUALIZATION 128
5.6 CHANGE MANAGEMENT 129
5.6.1 GOALS AND OBJECTIVES 130
5.6.2 SCOPE 130
5.6.3 DESIGNING AND PLANNING 131
5.6.4 CHANGE MANAGEMENT POLICIES 132
5.6.5 CHANGE MODELS 132
5.6.6 TRIGGERS AND INTERFACES 134
5.6.7 CHANGE MANAGEMENT ACTIVITIES 136
5.6.8 ROLES AND RESPONSIBILITIES WITHIN CHANGE MANAGEMENT 141
5.6.9 KEY PERFORMANCE INDICATORS (KPIS) OF CHANGE MANAGEMENT 142
5.6.10 CHALLENGES AFFECTING CHANGE MANAGEMENT 143
5.6.11 RELATIONSHIP WITH PROJECT MANAGEMENT 144
5.6.12 TYPICAL CONTENTS OF CHANGE DOCUMENTATION 145
5.7 SERVICE DESK 149
5.7.1 GOAL AND OBJECTIVES 149
5.7.2 BENEFITS 150
5.7.3 SERVICE DESK ORGANIZATIONAL STRUCTURES 150
5.7.4 SERVICE DESK TYPES (SKILL LEVELS) 155
5.7.5 SERVICE DESK STAFFING 155
5.7.6 KEY PERFORMANCE INDICATORS (KPIS) FOR THE SERVICE DESK 157
5.7.7 OUTSOURCING THE SERVICE DESK 157
6 VIRTUALIZATION AND STORAGE MANAGEMENT 158
6.1 THE HEART OF CLOUD COMPUTING: VIRTUALIZATION 158
6.2 DEFINING VIRTUALIZATION 159
6.3 WHY VIRTUALIZE? 159
6.4 WHAT CAN BE VIRTUALIZED? 160
6.5 WHERE DOES VIRTUALIZATION HAPPEN? 161
6.6 HOW DOES VIRTUALIZATION HAPPEN? 162
6.7 ON THE ROAD TO STORAGE VIRTUALIZATION 163
6.8 IMPROVING AVAILABILITY USING VIRTUALIZATION 164
6.9 IMPROVING PERFORMANCE THROUGH VIRTUALIZATION 164
6.10 IMPROVING CAPACITY THROUGH VIRTUALIZATION 165
6.11 BUSINESS VALUE FOR VIRTUALIZATION 166
7 APPLYING CLOUD COMPUTING TO PROJECT MANAGEMENT 167
7.1 BENEFITING FROM CLOUD COMPUTING 167
7.2 THE EASE OF LINKING (HYPERLINKS) 168
7.3 SUBSCRIBING TO SUCCESS (BLOGGING) 169
7.3.1 EVERYONE IS A PROJECT MANAGER (OPEN SOURCE) 171
7.4 TREATING THE PROJECT AS PARTS, NOT THE WHOLE (REUSE) 173
7.5 TESTING THE LIMITS (PORTABILITY) 174
7.6 PROCESS REVIEW QUESTIONS 175
ANSWERS 177
7.6 PROCESS REVIEW 177
CERTIFICATION 177

Another Cloud Computing Books
Another Training Kit Books
Download

Saturday, February 5, 2011

The CISSP Prep Guide







Table of Contents

The CISSP Prep Guide—Mastering the Ten Domains of
Computer Security
Foreword
Introduction
Chapter 1 - Security Management Practices
Chapter 2 - Access Control Systems
Chapter 3 - Telecommunications and Network Security
Chapter 4 - Cryptography
Chapter 5 - Security Architecture and Models
Chapter 6 - Operations Security
Chapter 7 - Applications and Systems Development
Chapter 8 -
Business Continuity Planning and Disaster
Recovery Planning
Chapter 9 - Law, Investigation, and Ethics
Chapter 10 - Physical Security
Appendix A - Glossary of Terms and Acronyms
Appendix B -
The RAINBOW Series—Minimum Security
Requirements for Multi-user Operating
Systems NISTIR 5153
Appendix C - Answers to Sample Questions
Appendix D -
A Process Approach to HIPAA Compliance
Through a HIPAA-CMM
Appendix E - The NSA InfoSec Assessment Methodology
Appendix F - The Case for Ethical Hacking
Appendix G - The Common Criteria
Appendix H - References for Further Study
Appendix I - British Standard 7799
Index
List of Figures
List of Tables
List of Sidebars


Another Computer Security Books
Another Training Kit Books
Download

Sunday, January 30, 2011

The SSCP Prep Guide Mastering the Seven Key Areas of Security






Introduction xiii
Acknowledgments xvii
About the Authors xviii
Chapter 1 The Journey Toward Information Security: An Overview 1
Five Essentials for Making the Journey 2
Roadmap for Information System Security 2
Security Objectives 4
Security Services 6
Security Mechanisms 6
Strategy for Achieving Information Security 10
Navigational Tools for Achieving Information Security 13
Computer Security 14
Data/Information Security 14
Communications/Network Security 14
Administrative/Management Security 15
Personnel Security 15
Operations Security 16
Resources for Achieving Information Security 16
People 16
Technology 17
Processes 17
Time 18
How the System Security Certified Practitioner Participates 18
Conclusion 18
Chapter 2 Domain 1: Access Controls 19
Our Goals 19
Domain Definition 20
Why Control Access? 21
Protection of Assets and Resources 22
Assurance of Accountability 23
Prevention of Unauthorized Access 23
DoS/DDoS Attacks 24
Spamming 26
Brute Force Attacks 27
Masquerade Attacks 27
Man-in-the-Middle Attacks 28
Self-Inflicted DoS 28
Types of Access Controls 29
Physical Controls 29
Logical Controls 30
Access Control Mechanisms 31
Token-Based Access Controls 32
Characteristics-Based Access Controls 32
System Level Access Controls 33
Account-Level Access Controls 35
Privileged Accounts 35
Individual and Group I&A Controls 35
Password Management and Policy 36
Role-Based Access Controls 39
Session-Level Access Controls 39
Data-Level Access Controls 40
Handling and Storing Output and Media 41
Sample Questions 45
Chapter 3 Domain 2: Administration 51
Our Goals 51
What Is Security Administration? 52
Security Administration Concepts and Principles 53
Security Equation 54
System Life Cycle 54
Security Development Life Cycle 56
Data/Information Storage 59
Primary Storage 60
Secondary Storage 60
Real (Physical) Memory 60
Volatile Memory 60
Virtual Memory 61
Storage Access Methods 62
Policies and Practices 63
Employment Policies 63
Security Policies 65
Standards 67
Guidelines 68
Procedures 68
Information Classification 69
Security Modes of Operation 72
Dedicated Mode 72
System High Mode 72
Compartmented Mode 73
Partitioned Security Mode 73
Multilevel Mode 73
Trusted Computing Base (TCB) 73
Security Kernel 73
Reference Monitor 74
Process Isolation 74
Traffic Analysis 74
OSI 7 Layer Model 74
Configuration Management 76
Building Your Roadmap 77
Starting with Policy 78
Defining Specific Requirements 80
Implementing Security Mechanisms 80
Common Technology-Based Security Mechanisms 81
Administering Security in an Operational System
or Enterprise 88
Access to the Firewall Platform 88
Firewall Platform Operating System Builds 89
Logging Functionality 90
Firewall Selection 91
Firewall Environment 91
Firewall Policy 93
Recommendations for Firewall Administration 98
Placement of VPN Servers 98
Security Awareness Training 99
Users 99
Management 100
Executives 101
Sample Questions 102
Chapter 4 Domain 3: Auditing and Monitoring 109
Our Goals 109
Domain Definition 110
Auditing 111
Audit Characteristics 111
Components to Audit 112
External/Internal Network Boundary Auditing 112
Internal/Subnet Boundary Auditing 118
Server Audit 119
User Workstations 120
Data to Collect During an Audit 126
Making Sense of Data 127
Data/Information Management 127
Conducting a Security Review (Audit) 128
Planning Stage 128
The Policies 129
Reporting Requirements 130
Implementation Stage 132
Monitoring 132
Monitoring Characteristics 133
Components to Monitor 133
Network Monitoring 133
Security Monitoring 133
Keystroke Monitoring 134
Intrusion Detection Systems (IDSs) 134
Types of IDSs 134
Data to Collect during Monitoring 135
Computer Forensics 140
Sample Questions 144
Chapter 5 Domain 4: Risk, Response, and Recovery 151
Goal of Chapter 151
Domain Definition 151
Risk 152
What Is Risk? 152
Major System Elements at Risk 153
Assets 153
Threats 155
Vulnerability 155
Controls 156
Safeguards 156
Countermeasures 156
Exposure 157
Risk Analysis 157
Risk Assessment 157
Threats versus Vulnerabilities 158
Analyzing Risk 159
Quantitative Risk Analysis 159
Qualitative Risk Analysis 161
Automated Risk Assessment 161
What to Do with Risk? 162
Why Assess Risk? 163
What Is Risk Management? 163
An Effective Risk-Assessment Methodology 163
Step 1: System Characterization 164
Step 2: Threat Identification 168
Step 3: Vulnerability Identification 173
Step 4: Control Analysis 178
Step 5: Likelihood Determination 180
Step 6: Impact Analysis 180
Step 7: Risk Determination 183
Step 8: Control Recommendations 185
Step 9: Results Documentation 186
Response 188
What Is a Response? 188
Incident Response Steps 191
How Do You Plan? 191
Recovery 198
What Is Contingency Planning? 198
Emergency Response 199
Restoration and Recovery 203
CP Testing 204
Sample Questions 208
Chapter 6 Domain 5: Cryptography 215
Our Goals 216
Domain Definition 216
Definitions of Cryptographic Terms 217
The History of Cryptology: An Overview 221
Caesar Shift Cipher (Mono-Alphabetic Substitution) 222
Vigenère Square (Polyalphabetic Substitution) 225
Vernam Cipher 226
Rotor Machines 229
Code Talkers 232
DES 232
Public Key Cryptography 232
Clipper Chip 232
Security and Cryptography 233
Confidentiality 234
Integrity 234
Encryption Techniques 235
How Encryption Is Used 236
How the Plaintext Is Processed 237
Number of Keys 239
Common Cryptographic Systems 242
Data Encryption Standard (DES) 243
Triple DES 243
RSA 244
Elliptic Curve Cryptography (ECC) 245
Advanced Encryption Standard (AES) 245
IDEA 245
Kerberos 245
Cryptography in Networks 246
Internet Protocol Security (IPSec) 246
Authentication Header (AH) 246
Encapsulating Security Payload (ESP) 246
Secure Socket Layer (SSL) 246
Secure HyperText Transport Protocol (S-HTTP) 246
Cryptography for Email 247
Secure Multipurpose Internet Mail Extensions (s/MIME) 247
Pretty Good Privacy (PGP) 247
Privacy Enhanced Mail (PEM) 247
Cryptography for E-Commerce 247
Secure Electronic Transaction (SET) 248
Transaction Layer Security (TLS) 248
What Is a Public Key Infrastructure (PKI)? 248
Steganography 250
Watermarks 251
Cryptanalysis 251
Known Plain-Text Approach 251
Ciphertext-Only Approach 252
Chosen Plain-Text Approach 252
Cryptography and the Federal Government 253
Sample Questions 254
Chapter 7 Domain 6: Data Communications 261
Our Goals 261
Domain Definition 262
Data Communication Fundamentals 262
Physical Aspects of Data Communications 263
Analog Signals 263
Digital Signals 264
Conducted Media 265
Copper Wire 265
Coaxial Cable 266
Fiber Optics 266
Radiated Media 266
Radio Waves 267
Microwave 267
Satellites 267
Infrared 269
Transmission Approaches 270
Bandwidth 270
Broadband versus Narrowband 270
Spread Spectrum 271
Networks 271
Local Area Networks (LANs) 272
Metropolitan Area Networks (MANs) 272
Intranets 273
The Internet 273
Extranets 274
Virtual Private Networks (VPNs) 275
VPN Security 275
VPN Modes of Operation 276
Peer Authentication 276
Public Key Certificate 276
One-Time Password 277
Password 277
Policy Configuration 277
VPN Operation 278
Physical Topologies 279
Star Topology 279
Bus Topology 280
Ring Topology 280
Logical Topologies 281
Bus 281
Ring 282
Standards 282
IEEE Standards 282
802.X Standards 282
Ethernet 282
Fast Ethernet 283
Gigabit Ethernet 283
International Organization for Standardization (ISO) 283
American National Standards Institute (ANSI) 284
International Telecommunication Union (ITU) 284
Protocols 284
The X Protocols 284
X.400 284
X.500 285
X.509 285
X.25 285
Transmission Control Protocol/Internet Protocol (TCP/IP) 285
User Datagram Protocol (UDP) 285
NetBEUI 285
Wireless Access Protocol (WAP) 286
Remote Access Protocols 286
Remote Access Services (RAS) 286
Remote Authentication Dial-In User Service (RADIUS) 286
Internet Protocol Security (IPSec) 286
Secure Sockets Layer (SSL) or Transport Layer Security (TLS) 287
Layer 2 Tunneling Protocol (L2TP) 287
Point-to-Point Tunneling Protocol (PPTP) 288
Models for Network Communication 288
OSI Seven-Layer Model 288
Physical Layer 288
Data Link Layer 289
Network Layer 289
Transport Layer 289
Session Layer 290
Presentation Layer 290
Application Layer 290
Security Services and Mechanisms 290
TCP/IP Network Model 291
Network Testing Techniques 291
Reasons for Testing a System 291
Security Testing and the System Development Life Cycle 292
Documentation 294
Security Management Staff 294
Senior IT Management/Chief Information Officer (CIO) 294
Information Systems Security Program Managers 295
Information Systems Security Officers 295
System and Network Administrators 295
Managers and Owners 296
Types of Security Testing 296
Network Mapping (Discovery) 297
Vulnerability Scanning 299
Penetration Testing 301
Security Testing and Evaluation 307
Password Cracking 308
Reviewing Logs 310
Checking File Integrity 311
Using Virus Detectors 312
War Dialing 313
Summary Comparisons of Network Testing Techniques 314
Prioritizing Security Testing 317
Minimum versus Comprehensive Testing 317
Prioritization Process 321
Sample Questions 324
Chapter 8 Domain 7: Malicious Code 331
Our Goals 333
Domain Definition (Subject Overview) 333
What Is Malicious Code? 333
Types and Characteristics of Malicious Code 336
Viruses 336
Virus Lifecycle 337
Macro Viruses 338
Macro Viruses 339
Polymorphic Viruses 339
Stealth Viruses 340
Multipartite Virus 340
Attack Scripts 340
Viruses and Email 340
Virus Creation 341
Virus Hoaxes 341
Worms 342
Trojan Horses 342
Trojan Horses 343
Logic Bombs 343
Malicious Code Protection 344
Malicious Code Detection System Requirements 345
Configuration Management Requirements 346
Potential Attack Mechanisms 347
Network Attacks 347
Trapdoors 347
Insider Attacks 348
Connection/Password Sniffing 348
Mobile Code 348
Potential Countermeasures 351
Malicious Code Scanning Products 351
Electronic Security 351
Trapdoor Access/Distribution 352
Network Security 352
Connection and Password Sniffing Countermeasures 352
Physical Security 353
An Overall Approach to Counter Malicious Code 353
Detection Mechanism 353
Administrative Countermeasures 356
System Backup 356
Workstation Strategy 356
Network Strategy 357
Types of Malicious Code Detection Products 357
Updates 357
Pre-Infection Prevention Products 358
Infection Prevention Products 358
Short-Term Infection Detection Products 359
Long-Term Infection Detection Products 359
Interoperability Concerns 360
Products Offering Protection at the Workstation 361
Products Offering Protection at the Network Gateway 362
Criteria for Selecting Protection Products 362
Example Cases 363
Case 1: Macro Virus Attack 363
Problem 363
Solution 363
Case 2: Polymorphic Virus Attack 365
Problem 365
Solution 366
Case 3: Trojan Horse Attack 368
Problem 368
Solution 368
Sample Questions 370
Appendix A Glossary 377
Appendix B Testing Tools 387
File Integrity Checkers 387
Network Sniffers 388
Password Crackers 389
Privilege Escalation and Back Door Tools 389
Scanning and Enumeration Tools 390
Vulnerability Scanning Tools 391
War Dialing Tools 392
Port Scanning: Nmap 392
L0pht Crack 398
LANguard File Integrity Checker 399
Using Tripwire 400
Snort 406
Appendix C References for Further Study 413
Books and Other Printed Materials 413
Web Sites 415
Web Sites of Interest to Security Administrators 416
Appendix D Answers to Sample Questions 417
Chapter 2—Domain 1: Access Controls 417
Chapter 3—Domain 2: Administration 427
Chapter 4—Auditing and Monitoring 436
Chapter 5—Domain 4: Risk, Response, and Recovery 446
Chapter 6—Domain 5: Cryptography 458
Chapter 7—Domain 6: Data Communications 467
Chapter 8—Domain 7: Malicious Code 477
What’s on the CD-ROM 489
Index 493

Another Training Kit Books
Another Computer Security Books
Download

Thursday, January 27, 2011

The CISA Prep Guide






Contents
Introduction xi
Chapter 1 The Information System Audit Process 1
IS Auditing Standards 2
Risk-Based Approach 6
Know Your Business 7
Controls 9
Preventive Controls 9
Detective Controls 9
Corrective Controls 9
Types of Audit Engagements 11
SAS 70 12
The Audit Organization 13
Audit Planning 15
Materiality 16
Irregularities 16
Scheduling 18
Self-Assessment Audits 19
Audit Staffing 19
Planning the Individual Audit 20
IS Audit Types 21
Risk Assessment 22
CobiT 24
Audit Objectives and Scope 28
Using the Work of Other Auditors 29
Impact of Outsourcing on IS Audits 30
Independence of an Auditor 30
Audit Engagement 31
Creating and Maintaining Work Papers 32
Due Care 33
Cover Sheet 33
Key Documents 34
Background 34
Planning and Risk Assessment 35
Audit Program 35
Test Work and Evidence 36
Post-Audit Checklist 37
Fieldwork 37
Control Objectives and Audit Approach 37
Referencing 38
Obtaining Evidence to Achieve the Audit Objectives 38
Flowcharts 39
Documentation Reviews 39
Narratives 40
Interview 40
Observation 40
Inspection 41
Confirmation 41
Reperformance 41
Monitoring 42
Test Work 42
CAATs 43
Management Control Reports 44
Sampling 44
Preparing Exhibits 47
Identifying Conditions and Defining Reportable Findings 47
Conclusions 48
Identification of Control Weaknesses 49
Summarizing Identified Weaknesses into Findings 49
Root Cause Analysis 50
Value-Added Recommendations 50
Reasonable Assurance through a Review of Work 51
The AIC and the Next Level Review of the Work Performed 51
Peer Review 52
Communicating Audit Results and Facilitating Change 52
Report Layout 53
Findings 54
Responses 55
56
Follow-Up
Resources 56
56
Publication
Web Sites 56
Sample Questions 57

Chapter 2 Management, Planning, and Organization
of Information Systems 65
Evaluate the IS Strategy and Alignment
with the Business Objectives 66
Systems Architecture 68
Evaluate the IS Organizational Structure 69
Roles and Responsibilities 69
Qualification and Training of the IS Staff 73
Evaluating IS Policies, Standards, and Procedures 75
Policy 75
Standards 78
Procedures 78
Evaluating Third-Party Services Selection and Management 79
Contract Management 81
Service Level Agreements 82
Evaluating Project Management 83
Evaluating Change Management 85
Evaluating Problem Management 87
Evaluating Quality Management 88
System Development Life Cycle (SDLC) 89
Quality Assurance Standards and Procedures 93
Evaluating Performance Management 94
Key Performance Indicators (KPIs) 94
Performance Measurement Techniques 95
Evaluating Capacity Management 97
Economic Performance Practices 97
Evaluating Information Security Management 100
Evaluating Business Continuity Management 103
Evaluating IS Management Practices and Policy Compliance 106
Resources 107
Sample Questions 108
Chapter 3 Technical Infrastructure and Operational Practices 115
Evaluating Systems Software 116
Operating Systems 116
Database Management Systems 120
Multi-Tier Client/Server Configuration Implications 123
Security Packages 125
Operations Management Consoles 128
Evaluating Hardware Acquisition, Installation,
and Maintenance 131
Installation 134
135
Maintenance
137
Evaluating Network Infrastructure
Voice Networks 137
141
Data Networks
Evaluating IS Operational Practices 147
Computer Operations 148
Printer Operators 150
Media Library Management 151
Physical Access to Operations Areas 154
Help Desk and User Support 155
Job Scheduling 156
Configuration Management 158
Asset Management 159
Change Management 160
Evaluating System Performance 164
Monitoring Techniques, Processes, and Tools 164
Capacity Planning 166
Problem Management 168
Service Level Agreements (SLAs) 169
Resources 171
Sample Questions 172
Chapter 4 Protection of Information Assets 179
Security Risks and Review Objectives 181
The Security Officer’s Role 183
Privacy Risk 186
The Security Program 187
Policy and Standards 189
Periodic Security Assessments and Planning 195
Designing Security from the Start 197
Identification, Authentication, and Authorization 198
Need to Know 200
Security Controls Economics 201
Role-Based Access 202
Evaluating Account Administration 204
User Account Management 205
Single Sign-On Solutions 208
Application Design Security 209
Application and Data Access 210
Information Ownership and Custodianship 212
Evaluating Logical Access Controls 215
Good Passwords 215
Strong Authentication 218
PKI and Digital Signatures 219
Biometric Access Controls 222
Network User Access 223
Information Security Architecture 224
Security Plans and Compliance 225
Host-Based Security 230
Evaluating Network Infrastructure Security 238
Firewalls 240
Demilitarized Zones (DMZs) 244
Proxies 246
Evaluating Encryption Techniques 247
Virtual Private Networks (VPNs) 249
Web Access Controls 251
Email Security 255
Virus Protection 256
Logging and Monitoring 259
Network Intrusion Detection 261
Incident Response 263
Security Testing Tools 265
Third-Party Connections 267
Evaluating Security Awareness 270
Social Engineering 271
Evaluating Environmental Controls 274
Electrical Power 275
278
Temperature
Fire Suppression 279
Humidity 281
Maintenance 282
Evaluating Physical Access Controls and Procedures 282
Visitor and Vendor Access 284
The Physical Location, Security Measures, and Visibility Profile 285
Personnel Safety 286
Hard Copy Information Protection 287
Resources 288
Sample Questions 289
Chapter 5 Disaster Recovery and Business Continuity 301
The Business Case for Continuity Planning 303
The Process of Planning for Adequate Recovery
and Continuity 305
Evaluating Business Impact Analysis and the
Requirements-Definition Processes 310
Evaluating Media and Documentation Back Up
Procedures 313
Evaluating Recovery Plans, Documentation,
and Maintenance 317
Evaluating Alternative Business Processing Plans
and Associated Training 324
Business Processing Alternatives 327
Training Evaluation 329
Evaluating Testing Methods, Results Reporting,
and Follow-Up Processes 331
Reporting Evaluation 334
Follow-Up 335
Resources 336
Sample Questions 337
Chapter 6 Business Application Systems Development,
Acquisition, Implementation, and Maintenance 345
Evaluation Approach 347
Systems Development Approaches and Management 349
Project Management 350
Functional Requirements 351
Requirements Definitions 352
Feasibility Analysis 353
System Specifications 356
System Design 359
Quality Assurance Planning and Review Processes 363
System Development 365
Change Control Methodologies 366
Third-Party Participation 367
Documentation and Standards 368
Data Management, Security, and Audit Functionality 370
Testing and Code Promotion 379
Training 385
Concluding on the Development Process 386
Acquisition 388
Evaluate the Application System Acquisition
and Implementation Process 389
Vendor Management and Escrow 392
Implementation 395
Conversion 396
Problem Management and Escalation 397
Emergency Change Management 398
Post-Implementation 399
Acceptance and Post-Implementation Review 399
Evaluating the Maintenance and Enhancement Processes 400
Versioning and Release Packaging 401
Resources 402
Sample Questions 403
Chapter 7 Business Process Evaluation and Risk Management 411
Corporate Governance 413
Evaluating the Effectiveness of the Information Systems
in Supporting the Business Process 417
Best Practice Business Process Design 418
Management Controls 420
Key Performance Indicators (KPIs) 421
Evaluating Business Process Reengineering Projects 423
Assessing Performance and Customer Satisfaction 426
E-Business Applications in Support of Business 428
Evaluating the Design and Implementation of Risk Controls 431
Preventive Controls 433
Detective Controls 435
Corrective Controls 435
Automated or Programmed Controls 436
Manual Controls 436
Cost-Benefit Analysis of Control Efforts 438
Evaluating Risk Management and Governance
Implementation 438
Risk Analysis 440
Control Identification 442
Gap Analysis and Reporting 443
Independent Assurance 445
Provisions for Independent Audits 450
Resources 456
Sample Questions 457
Appendix A Answers to Sample Exam Questions 465
Chapter 1—The IS Audit Process 465
Chapter 2—Management, Planning, and Organization
of Information Systems 477
Chapter 3—Technical Infrastructure and Operational
Practices 488
Chapter 4—Protection of Information Assets 499
Chapter 5—Disaster Recovery and Business Continuity 519
Chapter 6—Business Application Systems Development,
Acquisition, Implementation, and Maintenance 530
Chapter 7— Business Process Evaluation and
Risk Management 542
Appendix B What’s on the CD-ROM 555
Index 559

Another Training Kit Books
Another Management Books
Download

Tuesday, January 18, 2011

Windows® Server™ 2003 Network Infrastructure Exam Cram







By Diana Huggins

Publisher : Que
Pub Date : October 30, 2003
ISBN : 0-7897-2947-4
Pages : 384





This Exam Cram 2 helps you pass the 70-291 exam, which is a core exam in both the MCSE 2003 and MCSA 2003 programs. This book assumes that you have a solid foundation of knowledge but could use a refresher on iportant concepts, as well as a guide to exam topics and objectives. The book features test-taking strategies, time-saving study tips, and a special Cram Sheet that includes tips, acronyms, and memory joggers not available anywhere else! The Cram Sheet is especially useful for last-minute review before the test begins.

The best-selling Exam Cram 2 series is supported online at examcram.com. Each book is published under the direction of Series Editor Ed Tittel, the leading authority on IT certification. This book has been subjected to rigorous technical review by a team of industry experts, ensuring content is superior in both coverage and technical accuracy, and has earned the distinction of Cramsession(TM) Approved Study Material.


Copyright
The 70-291 Cram Sheet
DHCP/DNS
NETWORK SECURITY
REMOTE ACCESS
NETWORK MAINTENANCE

A Note from Series Editor Ed Tittel
About the Author
About the Technical Editors

Acknowledgments
We Want to Hear from You!
Introduction
Taking a Certification Exam
Tracking MCP Status
How to Prepare for an Exam
About This Book

Self-Assessment
MCSEs in the Real World
The Ideal MCSE Candidate
Put Yourself to the Test
Assessing Readiness for the 70-291 Exam
What's Next?

Chapter 1. Microsoft Certification Exams
Assessing Exam-Readiness
What to Expect at the Testing Center
Exam Layout and Design
Microsoft's Testing Formats
Strategies for Different Testing Formats
Question-Handling Strategies
Mastering the Inner Game
Additional Resources

Chapter 2. Managing IP Addressing
Configuring TCP/IP on a Server Computer
Managing DHCP
Troubleshooting TCP/IP Addressing
Exam Prep Questions
Need to Know More?

Chapter 3. Managing Name Resolution
Installing and Configuring the DNS Server Service
Managing DNS
Monitoring DNS
Exam Prep Questions
Need to Know More?

Chapter 4. Maintaining Network Security
Implementing Security Baseline Settings
Auditing Security Settings Using Security Templates
Installing and Configuring a Software Update Infrastructure
Monitoring Network Protocol Security
Troubleshooting Network Protocol Security
Exam Prep Questions
Need to Know More?

Chapter 5. Routing and Remote Access
Configuring Remote Access
Configuring Routing and Remote Access User Authentication
Configuring a Virtual Private Network (VPN)
Managing TCP/IP Routing
Managing Remote Access
Implementing Secure Access Between Private Networks
Troubleshooting User Access to Remote Access Services
Exam Prep Questions
Need to Know More?

Chapter 6. Maintaining a Network Infrastructure
Monitoring Network Traffic
Troubleshooting Internet Connectivity
Troubleshooting Server Services
Exam Prep Questions
Need to Know More?

Chapter 7. Practice Exam #1
How to Take the Practice Tests
Exam-taking Tips
Practice Exam

Chapter 8. Answer Key for Practice Exam #1
Chapter 9. Practice Exam #2
Chapter 10. Answer Key for Practice Exam #2
Appendix A. Additional Resources
Web Resources
Magazine Resources
Book Resources

Appendix B. What's on the CD
PrepLogic Practice Tests, Preview Edition

Appendix C. Using the PrepLogic Practice Tests, Preview Edition Software
Exam Simulation
Question Quality
Interface Design
Effective Learning Environment
Software Requirements
Installing PrepLogic Practice Tests, Preview Edition
Removing PrepLogic Practice Tests, Preview Edition from Your Computer
Using PrepLogic Practice Tests, Preview Edition

Glossary
Index


Another Training Kit
Another Network Books
Download

Wednesday, December 29, 2010

MSCE SQL Server 2000 Design Study Guide













Microsoft’s Microsoft Certified Systems Engineer (MCSE) track for Windows 2000 is the premier certification for computer industry professionals. Covering the core technologies around which Microsoft’s future will be built, the MCSE Windows 2000 program is a powerful credential for career advancement.

This book has been developed to give you the critical skills and knowledge you need to prepare for one of the electives for the MCSE certification program: Designing and Implementing Databases with Microsoft® SQL Server™ 2000 Enterprise Edition (Exam 70-229).

This exam is also one of the required exams for the Microsoft Certified Database Administrators (MCDBA). We have chosen to focus on the MCSE track as that is by far the most popular of Microsoft’s certification tracks. As of this printing, there were over 400,000 MCSEs, and roughly 20,000 MCDBAs. We will discuss all of the different tracks below.

Since the inception of its certification program, Microsoft has certified over one million people. As the computer network industry grows in both size and complexity, these numbers are sure to grow—and the need for proven ability will also increase. Companies rely on certifications to verify the skills of prospective employees and contractors.

Microsoft has developed its Microsoft Certified Professional (MCP) program to give you credentials that verify your ability to work with Microsoft products effectively and professionally. Obtaining your MCP certification requires that you pass any one Microsoft certification exam. Several levels of certification are available based on specific suites of exams. Depending on your areas of interest or experience,

Another Training Kit Books
Another Database Books
Another Web Programming Books
Download

Saturday, December 4, 2010

MCSD Training Kit-Analyzing Requirements and Defining Solution Architectures












Course Overview
This self-paced course combines text, graphics, and review questions to teach you about analyzing requirements and defining solutions architecture. The course assumes that you will work through the book from beginning to end, but you can choose a customized track and complete only the sections that interest you.

The book is divided into the following chapters:


Chapter 1, "Enterprise Architecture" This chapter examines the need for application and infrastructure guidance at an enterprise level. It begins by suggesting that systems be implemented with an architecture-first process. Next, the chapter introduces the Microsoft Solutions Framework (MSF). Chapter 1 also examines the MSF Enterprise Architecture Model and its Business, Application, Information, and Technology Perspectives. This chapter additionally points out that the four primary goals of an enterprise architecture are that it be integrated, iterative, actionable, and prioritized. Finally, this chapter discusses how to begin the enterprise architecture process and continue to deliver systems and applications while the architecture process is underway.


Chapter 2, "Enterprise Applications" This chapter examines the features of modern enterprise applications, and issues that should be considered. It discusses designing large-scale, distributed, enterprise applications and the need to reduce their complexity. It also recommends managing this enterprise application complexity through abstraction, which involves grouping similar requirements together into a small number of abstract categories. Various architecture descriptions are discussed, such as the Unified Modeling Language (UML), Design Patterns, and AntiPatterns. Additionally, this chapter out-lines ten principles for delivering successful applications. Chapter 2 finally suggests that organizations use the several perspectives represented by Microsoft's Enterprise Application Model and discusses the application architecture framework provided by the separate MSF Application Model for Development.


Chapter 3, "Project Teams" This chapter discusses who is responsible for doing what so that all the different parts of an application project are managed properly. The chapter also discusses building a project team within the context of the MSF Team Model for Application Development (MSF Development Team Model). The discussion progresses from understanding the six equally vital team roles to finding and enlisting leaders from different parts of the organization. Chapter 3 also pinpoints specific responsibilities that must be fulfilled for a project to be successful, and assigns these responsibilities to specific team members. It looks at ways to analyze project requirements from the perspectives of different team members and also explores ways to scale the project team to fit the needs and size of the project. Finally, this chapter examines team and leadership characteristics that will help make an organization's use of its project resources more effective.


Chapter 4, "Development Process" This chapter is primarily devoted to the MSF Process Model for Application Development, otherwise known as the MSF Development Process Model. Rather than a step-by-step methodology, MSF is a structural framework that an organization can adapt to suit its particular needs. The MSF Development Process Model is the part of this framework that describes the life cycle of a successful software development project. Using a development framework has been successfully proven in the software industry to improve project control, minimize risk, improve product quality, and increase development speed. Also in this chapter, we discuss the Unified Process development framework along with its workflows, stages, and milestones.


Chapter 5, "Project Vision" This chapter describes the dynamics of the MSF Development Process Model's Envisioning Phase. This chapter also discusses what information to gather from the project stakeholders, how to create a product vision, how the MSF Development Team Model's various roles participate in the envisioning process, and what their responsibilities are. In addition, Chapter 5 examines how the envisioning process develops over a period of time. Finally, this chapter presents a detailed discussion of risk management, based on the MSF Risk Management Model.


Chapter 6, "Project Plan" This chapter outlines the process of mapping concepts to actions and explains team roles in the Planning Phase of the MSF Development Process Model. It takes an in-depth look at the MSF Design Process Model and the conceptual, logical, and physical architectures of an application. This chapter also discusses how the MSF Application Model's user, business, and data service layers can be incorporated into the application's physical architecture. The MSF Development Process Model's Functional Specification, Master Project Plan, and Master Project Schedule are all emphasized as key deliverables of the Planning Phase. Finally, Chapter 6 discusses principles of scheduling, as well as the ongoing task of risk management.


Chapter 7, "User Service Layer Technologies" This chapter examines how to create effective and efficient user interface (UI) designs. It also explores legacy, current, and future technologies that affect the user service layer design of the MSF Application Model. Additionally, this chapter discusses the impact of Web technologies on current application design techniques. We complete Chapter 7 with an in-depth look at implementing a Web-based application.


Chapter 8, "Business Service Layer Technologies" This chapter focuses on such issues as using an object context to manage state, using explicitly defined interfaces when possible, composing functionality, maintaining state across transaction boundaries, propagating errors, and programmatically controlling security. In addition, this chapter takes a detailed examination using COM and COM+ within the business service of an application's physical design. This chapter concludes with a detailed look at using COM components with Microsoft Transaction Server.


Chapter 9, "Data Service Layer Technologies" This chapter examines design issues related to data requirements and explores characteristics of different data access technologies. This chapter also discusses best uses for each access technology, and normalization of data and data integrity. In addition, this chapter identifies how business rules can affect application data and where these rules are implemented. Furthermore, Chapter 9 examines technologies that provide data access to legacy data system stores and Enterprise Resource Planning (ERP) applications. Finally, this chapter reviews COM+ In-Memory Database (IMDB) features that can improve data access performance.


Chapter 10, "Testing and the Production Channel" This chapter explains how to build a working environment that supports development, testing, certification, and production. Using real-life examples, this chapter describes the production channel and its goals. Chapter 10 thoroughly examines testing, and recommends several ways to execute and monitor tests. It also discusses ways to scale out an application's production environment by adding servers to the physical implementation. Finally, this chapter examines ways to classify program faults and failures, discuss the larger issue of product bugs, and describe methods of tracking, classifying, and resolving known bug problems.


Chapter 11, "Application Security" This chapter looks at different security-related protocols and the basic security concepts of authentication. It also examines encryption, which stores and passes information from one place to another so that it can't be read by anyone who intercepts it. Additionally, this chapter discusses access control, which determines what users are allowed to accomplish, and auditing, which records what goes on inside the operating system as users request and work with the resources the system makes available to them.


Chapter 12, "Development Deliverables" This chapter examines the creation process, including how the various team roles function during development. This chapter further explores testing, bug tracking, and the "zero-defect mindset," and also shows how the project management team makes effective trade-offs. In addition, this chapter discusses how multi-layer applications are implemented as monolithic or client/server, or distributed in physical form. Finally, Chapter 12 explores the end of the MSF Development Process Model's Developing Phase, when code-complete is reached, and all product features and original code are incorporated into the application.


Chapter 13, "Product Stabilization" This chapter emphasizes the evolutionary cycle the team will progress through to move from the Developing Phase's Scope Complete Milestone to the Stabilizing Phase's Release Milestone. We summarize this phase's effort as four primary steps: Fix the bugs, synchronize all product deliverables, ship the release, and extensively test the release. Leading up to the Release Milestone, the chapter identifies several key interim milestones that are reached by the continual iteration of the phase's steps. This chapter also provides some guidelines for the deployment of an application after the product is released. From the preplanning phases though pilot testing, support, and troubleshooting, we explore efficient ways to deploy the application with as little negative impact as possible on the users and their systems and networks.


Chapter 14, "Project Review" This chapter emphasizes the value of a solid project review, as it both relates to a project just completed and to the ongoing growth and improvement of the organization. The chapter examines the relationship between the project review and the Capability Maturity Model for Software, and also shows the project review's impotance in creating a best practice guide for the organization's development teams. This chapter examines the practical considerations of conducting a project review: when to schedule a project review, who should attend, and the proper physical setting for a project review.

Features of This Book
The following features are designed to enhance the usefulness of this course:

The overall structure reflects the way a development team would progress through the process of creating an application.

Each chapter contains reference material that also serves as additional recommended reading.

Each chapter ends with a short summary of the material presented.

Review questions at the end of each chapter let you test what you have learned in the chapter.

Case studies provide a different and interesting way to learn development and application design by participating in the complete development life cycle of a multi-layer, distributed application. Although the case study events are purely fictional, they provide fresh insight on how people build applications. See the "Case Studies" section for more information.


Conventions Used in This Book
Before you start reading any of the chapters, it is impotant that you understand the following notational conventions used in this book:

Italic is used for emphasis when defining new terms. Italic is also used for book titles.

Names of files and folders appear in Title Caps. Unless otherwise indicated, you can use all lowercase letters when you type a file or folder name in a dialog box or at a command prompt.

File name extensions appear in all lowercase.

Acronyms appear in all uppercase.

Monospace type represents code samples, examples of screen text, or entries that you might type at a command prompt or in initialization files.

Square brackets [ ] are used in syntax statements to enclose optional items. For example, [filename] in command syntax indicates that you can choose to type a file name with the command. Type only the information within the brackets, not the brackets themselves.

Braces { } are used in syntax statements to enclose required items. Type only the information within the braces, not the braces themselves.


Download
Another Training Kit Books
Another Software Engineering Books

MCSA/MCSE Self-Paced Training Kit (Exams 70-292 and 70-296): Upgrading Your Certification to Microsoft Windows Server 2003












Contents at a Glance
Part 1 Learn at Your Own Pace
Introduction to Windows Server 2003 . . . . . . . . . . . . . . . . . . . . . . . . . . . -1
Implementing an Active Directory Infrastructure . . . . . . . . . . . . . . . . . . . -1
Managing and Maintaining an Active Directory Implementation. . . . . . . -1
Managing Users, Groups, and Computers . . . . . . . . . . . . . . . . . . . . . . . . -1
Planning, Implementing, and Troubleshooting Group Policy . . . . . . . . . . -1
Managing the User Environment with Group Policy . . . . . . . . . . . . . . . . . -1
Planning a Host Name Resolution Strategy. . . . . . . . . . . . . . . . . . . . . . . -1
Implementing, Managing, and Maintaining Name Resolution. . . . . . . . . -1
Planning and Implementing Server Roles and Security. . . . . . . . . . . . . . -1
Managing and Maintaining a Server Environment. . . . . . . . . . . . . . . . .10-1
Securing Network Communication. . . . . . . . . . . . . . . . . . . . . . . . . . . . .11-1
Creating and Managing Digital Certificates . . . . . . . . . . . . . . . . . . . . . .12-1
Managing and Implementing Disaster Recovery . . . . . . . . . . . . . . . . . .13-1
Clustering Servers. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .14-1
Part 2 Prepare for the Exam
15 Exam 70-292—Managing Users, Computers, and Groups (1.0) . . . . . .15-1
16 Exam 70-292—Managing and Maintaining Access . . . . . . . . . . . . . . .16-1
to Resources (2.0)
17 Exam 70-292—Managing and Maintaining a . . . . . . . . . . . . . . . . . . . .17-1
Server Environment (3.0)
18 Exam 70-292—Managing and Implementing Disaster . . . . . . . . . . . . .18-1
Recovery (4.0)
19 Exam 70-292—Implementing, Managing, and Maintaining Name . . .19-1
Resolution (5.0)
20 Exam 70-292—Implementing, Managing, and Maintaining . . . . . . . . .20-1
Network Security (6.0)
21 Exam 70-296—Planning and Implementing Server Roles and . . . . . .21-1
Server Security (1.0)
22 Exam 70-296—Planning, Implementing, and Maintaining a . . . . . . . .22-1
Network Infrastructure (2.0)
23 Exam 70-296—Planning, Implementing, and Maintaining . . . . . . . . . 23-1
Server Availability (3.0)
24 Exam 70-296—Planning and Maintaining Network Security (4.0) . . . . 24-1
25 Exam 70-296—Planning, Implementing, and Maintaining . . . . . . . . . 25-1
Security Infrastructure (5.0)
26 Exam 70-296—Planning and Implementing an Active . . . . . . . . . . . . 26-1
Directory Infrastructure (6.0)
27 Exam 70-296—Managing and Maintaining an Active . . . . . . . . . . . . . 27-1
Directory Infrastructure (7.0)
28 Exam 70-296—Planning and Implementing User, Computer, . . . . . . . 28-1
and Group Strategies (8.0)
29 Exam 70-296—Planning and Implementing Group Policy (9.0) . . . . . . 29-1
30 Exam 70-296—Managing and Maintaining Group Policy (10.0) . . . . . . 30-1

Download
Another Web Programming Books
Another Internet Books
Another Training Kit Books
Related Posts with Thumbnails

Put Your Ads Here!