LPI Security Essentials

From Thomas-Krenn-Wiki
Jump to navigation Jump to search

LPI Security Essentials is the entry-level certification in the security field offered by the Linux Professional Institute (LPI). In this wiki article, we outline the detailed learning objectives for the LPI Security Essentials exam (Version 1.0, Exam Code 020-100).[1]

Topic 1: Security Concepts

Subject Area Weight Key Knowledge Areas Partial list of the used files, terms, and utilities
1.1 Goals, Roles and Actors 1
  • Importance of IT security
  • Common security goals
  • Common roles in security
  • Common goals of attacks against IT systems and devices
  • Concept of attribution and related issues
  • Confidentiality, integrity, availability, non-repudiation
  • Hackers, crackers, script kiddies
  • Black hat and white hat hackers
  • Accessing, manipulating or deleting data
  • Interrupting services, extorting ransom
  • Industrial espionage
1.2 Risk Assessment and Management 2
  • Know common sources for security information
  • Security incident classification schema and important types of security vulnerabilities
  • Concepts of security assessments and IT forensics
  • Awareness of Information Security Management Systems (ISMS) and Information Security Incident Response Plans and Teams
  • Common Vulnerabilities and Exposures (CVE)
  • CVE ID
  • Computer Emergency Response Team (CERT)
  • Penetration testing
  • Untargeted attacks and Advanced Persistent Threats (APT)
  • Zero-day security vulnerabilities
  • Remote execution and explication of security vulnerabilities
  • Privilege escalation due to security vulnerabilities
1.3 Ethical Behavior 2
  • Implications for others of actions taken related to security
  • Handling information about security vulnerabilities responsibly
  • Handling confidential information responsibly
  • Awareness of personal, financial, ecological, and social implication of errors and outages in information technology services
  • Awareness of legal implications of security scans, assessments, and attacks
  • Responsible Disclosure and Full Disclosure
  • Bug Bounty programs
  • Public and private law
  • Penal law, privacy law, copyright law
  • Liability, financial compensation claims

Topic 2: Encryption

Subject Area Weight Key Knowledge Areas Partial list of the used files, terms, and utilities
2.1 Cryptography and Public Key Infrastructure 3
  • Concepts of symmetric, asymmetric, and hybrid cryptography
  • Concept of Perfect Forward Secrecy
  • Concepts of hash functions, ciphers, and key exchange algorithms
  • Differences between end-to-end encryption and transport encryption
  • Concepts of Public Key Infrastructures (PKI), Certificate Authorities, and Trusted Root-CAs
  • Concepts X.509 certificates
  • How X.509 certificates are requested and issued
  • Awareness of certificate revocation
  • Awareness of Let’s Encrypt
  • Awareness of important cryptographic algorithms
  • Public Key Infrastructures (PKI)
  • Certificate Authorities
  • Trusted Root-CAs
  • Certificate Signing Requests (CSR) and certificates
  • X.509 certificate fields: Subject, Issuer, Validity
  • RSA, AES, MD5, SHA-256, Diffie–Hellman key exchange, Elliptic Curve Cryptography
2.2 Web Encryption 2
  • Major differences between plain text protocols and transport encryption
  • Concepts of HTTPS
  • Important fields in X.509 certificates for the use with HTTPS
  • How X.509 certificates are associated with a specific web site
  • Validity checks web browsers perform on X.509 certificates
  • Determining whether or not a website is encrypted, including common browser messages
  • HTTPS, TLS, SSL
  • X.509 certificate fields: subject, Validity, subjectAltName
2.3 Email Encryption 2
  • Email encryption and email signatures
  • OpenPGP
  • S/MIME
  • Role of OpenPGP key servers
  • Role of certificates for S/MIME
  • How PGP keys and S/MIME certificates are associated with an email address
  • Using Mozilla Thunderbird to send and receive encrypted email using OpenPGP and S/MIME
  • GnuPGP, GPG keys, key servers
  • S/MIME and S/MIME certificates
2.4 Data Storage Encryption 2
  • Concepts of data, file, and storage device encryption
  • Using VeraCrypt to store data in an encrypted container or an encrypted storage devices
  • Core features of BitLocker
  • Using Cryptomator to encrypt files stored in file storage cloud services
  • VeraCrypt
  • BitLocker
  • Cryptomator

Topic 3: Device and Storage Security

Subject Area Weight Key Knowledge Areas Partial list of the used files, terms, and utilities
3.1 Hardware Security 2
  • Major components of a computer
  • Smart devices and the Internet of Things (IoT)
  • Security implications of physical access to a computer
  • USB devices devices types, connections, and security aspects
  • Bluetooth devices types, connections, and security aspects
  • RFID devices types, connections, and security aspects
  • Awareness of Trusted Computing
  • Processors, memory, storage, network adapters
  • Tablets, smartphones, smart tvs, routers, printers smart home, alarm, IoT devices (e.g. light bulbs, thermostats, TVs)
  • USB
  • Bluetooth
  • RFID
3.2 Application Security 2
  • Common types of software
  • Various sources for applications and ways to securely procure and install software
  • Updates for firmware, operating systems, and applications
  • Sources for mobile applications
  • Common security vulnerabilities in software
  • Concepts of local protective software
  • Firmware, operating systems, applications
  • App stores
  • Local packet filters, endpoint firewalls, application layer firewalls
  • Buffer overflows, SQL injections
3.3 Malware 3
  • Common types of malware
  • Concepts of rootkit and remote access
  • Cirus and malware scanners
  • Awareness of the risk of malware used for spying, data exfiltration, and address books copies
  • Viruses, ransomware, trojan malware, adware, cryptominers
  • Backdoors and remote access
  • File copying, keylogging, camera, microphone hijacking
3.4 Data Availability 2
  • Importance of backups
  • Common backup types and strategies
  • Security implications of backups
  • Creating and securely storing backups
  • Data storage, access, and sharing in cloud services
  • Security implications of cloud storage and shared access in the cloud
  • Awareness of the dependence on Internet connection and the synchronization of data between cloud services and local storage
  • Full, differential and incremental backups
  • Backup retention
  • File sharing cloud services

Topic 4: Network and Service Security

Subject Area Weight Key Knowledge Areas Partial list of the used files, terms, and utilities
4.1 Networks, Network Services and the Internet 4
  • Various types of network media and network devices
  • Concepts of IP networks and the Internet
  • Concepts of routing and Internet Service Providers (ISPs)
  • Concepts of MAC and link-layer addresses, IP addresses, TCP and UDP ports, and DNS
  • Concepts of cloud computing
  • Wired networks, WiFi networks, cellular networks
  • Switches, Routers, Access Points
  • Default Router
  • Internet Service Provider
  • IPv4, IPv6
  • TCP, UDP, ICMP, DHCP
  • DNS, DNS host names, forward DNS, reverse DNS
  • Cloud computing
  • Infrastructure as a Service (IaaS)
  • Platform as a Service (PaaS)
  • Software as a Service (SaaS)
4.2 Network and Internet Security 3
  • Implications of link layer access
  • Risks and secure use of WiFi networks
  • Concepts of traffic interception
  • Common security threats in the Internet along with approaches of mitigation
  • Link layer
  • Unencrypted and public WiFi
  • WiFi security and encryption
  • WEP, WPA, WPA2
  • Traffic interception
  • Man in the Middle attacks
  • DoS and DDoS attacks
  • Botnets
  • Packet filters
4.3 Network Encryption and Anonymity 3
  • Virtual private networks (VPN)
  • Concepts of end-to-end encryption
  • Anonymity and recognition in the Internet
  • Identification due to link layer addresses and IP addresses
  • Concepts of proxy servers
  • Concepts of TOR
  • Awareness of the Darknet
  • Awareness of cryptocurrencies and their anonymity aspects
  • Virtual Private Network (VPN)
  • Public VPN providers
  • Organization-specific VPN (e.g. company or university VPNs)
  • End-to-end encryption
  • Transfer encryption
  • Anonymity
  • Proxy servers
  • TOR
  • Hidden service
  • .onion
  • Blockchain

Topic 5: Identity and Privacy

Subject Area Weight Key Knowledge Areas Partial list of the used files, terms, and utilities
5.1 Identity and Authentication 3
  • Concepts of digital identities.
  • Concepts of authentication, authorization, and accounting
  • Characteristics of secure password (e.g. length, special characters, change frequencies, complexity)
  • Using a password manager
  • Concepts of security questions and account recovery tools
  • Concepts of multi-factor authentication (MFA), including common factors
  • Concepts of single sign-on (SSO) and social media logins
  • Role of email accounts for IT security
  • How passwords are stored in online services
  • Common attacks against passwords
  • Monitoring personal accounts for password leaks (e.g. search engine alerts for usernames and password leak checkers)
  • Understanding of the security aspects of online banking and credit cards
  • Online and offline password managers
  • keepass2
  • Single sign-on (SSO)
  • Two-factor authentication (2FA) and multi-factor authentication (MFA)
  • One-time passwords (OTP), time-based one-time passwords (TOTP)
  • Authenticator applications
  • Password hashing and salting
  • Brute force attacks, directory attacks, rainbow table attacks
5.2 Information Confidentiality and Secure Communication 2
  • Implications and risks of data leaks and intercepted communication
  • Phishing and social engineering and scamming
  • Concepts of email spam filters
  • Securely handling of received email attachments
  • Sharing information securely and responsibly using email cloud shares and messaging services
  • Using encrypted instant messaging
  • Phishing and social engineering
  • Identity theft
  • Scamming and scareware
  • Email spam, email spam filtering
  • Non-disclosure agreements (NDA)
  • Information classification
5.3 Privacy Protection 2
  • Importance of personal information
  • How personal information can be used for a malicious purpose
  • Concepts of information gathering, profiling, and user tracking
  • Managing profile privacy settings on social media platforms and online services
  • Risk of publishing personal information
  • Rights regarding personal information (e.g. GDPR)
  • Stalking and cybermobbing
  • HTTP cookies, browser fingerprinting, user tracking
  • Script blockers and ad blockers in web browsers
  • Profiles in online services and social media
  • Contacts and privacy settings in social media

Einzelnachweise


Author: Werner Fischer

Werner Fischer, working in the Knowledge Transfer team at Thomas-Krenn, completed his studies of Computer and Media Security at FH Hagenberg in Austria. He is a regular speaker at many conferences like LinuxTag, OSMC, OSDC, LinuxCon, and author for various IT magazines. In his spare time he enjoys playing the piano and training for a good result at the annual Linz marathon relay.