? Importance of Attack Surface Expansion ?

? Attention cybersecurity professionals! Let's discuss the significance of attack surface expansion and how it plays a crucial role in protecting organizations. ?

Attack surface expansion refers to the process of identifying and assessing the various entry points and vulnerabilities within an organization's network, systems, and applications. By expanding the attack surface, we gain a better understanding of potential attack vectors and can take proactive measures to secure our digital assets.

Here are some key points to consider:

1️⃣ Comprehensive Threat Assessment: Expanding the attack surface allows us to identify potential weak spots and vulnerabilities that might otherwise go unnoticed. By analyzing a wider range of entry points, we gain a more comprehensive understanding of the threats we face.

2️⃣ Proactive Risk Mitigation: By expanding the attack surface, we can proactively address vulnerabilities and implement appropriate security controls. This approach helps us stay one step ahead of potential attackers and reduces the likelihood of successful breaches.

3️⃣ Holistic Security Strategy: A well-rounded security strategy should consider all aspects of an organization's attack surface. Expanding the attack surface enables us to include network infrastructure, cloud services, endpoints, IoT devices, and more. This holistic approach ensures a stronger defense against evolving threats.

4️⃣ Third-Party Risks: Expanding the attack surface also involves evaluating the security posture of third-party vendors and partners. With interconnected systems and supply chains, assessing the vulnerabilities of external entities becomes critical to maintaining a robust security posture.

What are your thoughts? ??

#CyberSecurity #AttackSurface #ThreatAssessment #RiskMitigation #SecurityStrategy #ThirdPartyRisks #DigitalSecurity #InfoSec #DataProtection

Want some free training?

So, one of the things that I've had to do in the change of company directive has been to start learning and integrating our network to FortiNet technology.

So if you go out to https://training.fortinet.com and sign up for a free account, you can latch onto some free training, if you want to expand your horizons when studying for things in the CompTIA security track. Granted it's ALL vendor-driven, however, the way that they present the training is, at least as far as NSE 1-3 is concerned (haven't got that far yet), is conceptual, before rolling out what FortiProduct they have to answer the requirement. I don't know (probably not) if you can use the training in a classroom situation, but I think it's well built. Most of it is SCORM - some of it is more wow-video driven.

And if you're using FortiNet products or plan to in the future, it's probably a foregone conclusion to avail one-self of that training.

I think one can get the images from the FortiNet support site in order to stand up virtual appliances for training purposes - I haven't tried this yet, but it may be a good little exercise for those GNS3 environments we all built last year with @Lee McWhorter.

What free training do you know is out there that might be beneficial for the CIN? Post below!

Back to my FortiTraining. And no, I've not given up on any CompTIA certs I'm working on. But sometimes, things just jump onto one's plate...

/r

CompTIA Linux+ Instructor needed DFW (Hurst) Fall 2023

I'm in need of a Linux+ instructor at Tarrant County College at the Northeast campus in Hurst, TX. This is for a face-to-face credit class (ITSE 1416) that will meet twice weekly August - December. Here is a posting for our generic adjunct pool where you can see more about our jobs: https://jobs.tccd.edu/postings/33030
  • Like
Reactions: Fanuel

CompTIA Certified Instructor for ground-based class in Denver area this summer

We are looking for a Certified Instructor to teach A+ to Denver area high school students this summer. Class would be held Tuesday and Thursday mornings from June 13th to July 27th, from 9-Noon. A stipend will be paid. Please contact Walt Sulmeisters, Director of the Common Good Network, Regis University. My cell # is 303-913-1494. My email is [email protected]
  • Like
Reactions: Fanuel

Training center looks to add trainers to their talent pool

A contact of mine on LinkedIn is attempting to add to her instructor pool so she can offer more courses to her training center. Her name is Kristin Pelletier and she owns Access Computer Training. If you are interested, contact her via LinkedIn.

Access Computer Training - https://www.linkedin.com/school/access-computer-training/

Kristin Pelletier - https://www.linkedin.com/in/kristinpelletiercareercoach/

I have no afiliation with the school and have only spoken with her briefly. Please direct all questions to her directly.

Just Released - Kali Purple - "Leveling the playing field"

Offensive Security released Kali 2023.1 or 'Kali Purple'; a distro aimed at Blue and Purple team members (great Security+ question) with a renewed focus on 'defensive' security. While this is a new release of Kali this 'purple' distro includes new tools specifically for network defenders.

Bleeping Computer has a great article describing the release.

I've yet to download and build an image. I hope to create a VM before the end of next week.

CompTIA Linux+ and Network+ instructors needed ASAP! 100% remote!

Hi all, I have a client searching for multiple CompTIA Linux+ and Network+ instructors. All classes taught online, and students are professionals and active/retired military. We have many dates open - classes are held Monday through Friday from 9 AM - 1 PM CST. Rate of $100hr - can charge for curriculum review and class preparation, hours in class. Please contact me at [email protected] if interested.

  • Question
1100 Series - CompTIA A+ CertMaster Learn Course Pacing Plans for 2, 4, 6, and 8 Weeks - MS Excel Document

Greetings,

I hope this post finds you and your families very well! I am searching for the current A+ CertMaster Learn Course Pacing Plans for 2, 4, 6, and 8 weeks of study in MS Excel format. Can you help?

(I attached an image of the 1000 series pacing plans I used before exam retirement.)

Regards,

Dr. Duane

Attachments

  • CML Course Pacing Plans_220-1102.jpg
    CML Course Pacing Plans_220-1102.jpg
    371.3 KB · Views: 41
  • Like
Reactions: Fanuel

Improving CertMaster for Network+

I manage the Infrastructure Pathways product development at CompTIA, which from a ProdDev standpoint starts with Network+. My team is holding roundtable discussions with instructors, administrators, course coordinators and other decision makers -- anyone who has boots-on-the-ground experience with our existing product offer, training materials for Network+ (N10-008).

I would love to get your feedback on your teaching experiences, what works and what doesn’t, and any wish-list items you might have regarding the Network+ (N10-008) training products. This information will help us tremendously when we begin development of the next version of the product (N10-009).

I'll be hosting discussions during the week of 24-April and the week of 1-May. Please feel free to sign up for a time: https://app.smartsheet.com/b/form/11f05acabd5e47a682f20ea1b76beab5 or email me directly at [email protected]. A member of the Learning team will provide attendees with instructions for joining the call.

Thanks for your interest!

Taught N10-008? Tell me everything!

I manage the Infrastructure Pathways product development at CompTIA, which from a ProdDev standpoint starts with Network+. I'm looking for feedback on our existing product offer, training materials for Network+ (N10-008). This information will help us tremendously when we begin development of the next version of the product (N10-009).

My team is holding roundtable discussions with instructors, administrators, course coordinators and other decision makers -- anyone who has boots-on-the-ground experience with the N10-008 course materials. I would love to get your feedback on your teaching experiences, what works and what doesn’t, and any wishlist items you might have regarding the Network+ (N10-008) training products.

I'm hosting discussions during the week of 24-April and the week of 1-May. Please feel free to sign up for a time: https://app.smartsheet.com/b/form/11f05acabd5e47a682f20ea1b76beab5 or email me directly at [email protected]. A member of the Learning team will provide attendees with instructions for joining the call.

Thanks for your interest!

How long do you take to prepare for exams?

I was reading in an online forum about preparing for exams. I saw several students who mentioned they spent months preparing for certification exams. One student mentioned that he spent three months preparing for the ITF+ exam. Another student mentioned that he averaged six months per exam. Still another stated that he studied for nine months for his first exam.

Granted, I've got 25+ years of experience and have passed four versions of A+, four versions of Net+, four versions of Sec+, and two versions of CySA+ and currently have all but two of the current CompTIA certs. My first CompTIA cert was IT Project+ (now Project+). My supervisor offered me a bonus if I could pass the exam in a week and teach it the following week. I studied like crazy and passed the exam on the first try and did teach it the following week. I don't think I've ever studied for any exam longer than a few weeks. I think I spent three weeks total studying for both the PenTest+ and CASP+ combined. I spent a week studying for my CISM. I passed seven Microsoft exams to get my MCSE in two and a half months. No brain dumps, boot camps, or practice exams either. Just "nose to the grindstone" studying. I don't usually do any labs while preparing because I tend to do lab work all the time anyway.

I know that everyone has different levels of experience and every exam is different. There are a lot of variables that go into preparing for exams.

How long, on average, do you spend preparing for new certifications? How long do you spend preparing for recertifying in certs you've already earned before?

  • Solved
How should I display my certificates in my office?

IMG_0735.jpeg
These are printouts of the certificates as I keep the original framed at home. Should I present them chronologically that I earned them, or by color, or by CompTIA’s pathway? I was thinking to just tape these to my office wall and not need a frame. Should I buy more frames for these copies?
Please share your own Certificate Wall.

  • Question
Security+ and Network+ average time to train in hours

Good afternoon CINers.

Our school is looking to train the Security+ and Network+ plus course to individuals looking to retool their skills.

Looking at related information, I was calculating 80 hours a piece for each course. The participants would be your average computer user. Any thoughts?

-Robert

ComPTIA Virtual Trainer / online Trainer

I completed my last contract the end of February 2023.
I am looking to do Virtual Training again.
Completed contract .
Ready for new contract
Training experience of 20 years which includes on the road experience.
These are ones I am well known for .
At this time I do Exam prep for A+220-1101 and 220-1102 . I help the delegates to pass their exams in the UK and OZ on a Saturday morning for a Training company. I have exam summary guides for core 1 and Core 2 the guys and they love it and they are passing the exams from A+ to Network+. I created the content. I was a Technical editor for a couple publishers. Once a time as well.
So currently I am enjoying good pass marks for the classes Last year Network+ and Security+ 100% pass and A+.
My secret I pre test every one with the content.

ComPTIA 220-1101
ComPTIA 220-1102
ComPTIA network+ 10-008
ComPTIA Security+
IT Fundamentals Fundamentals Exam FC0-U61
ComPTIA Cloud Essentials+
ComPtia Server+

  • Question
Cybersecurity Employability

Hello CINERS,

I would like to train Security+, CySA+, but I'd like to know what is the likelhood of employablity with either one or the other certifications, but not both.

I just want to set the proper expectation of employment opprotunities with my students. Are you finding that individuals certified in either of the aformentioned certifications have been employed and what are the typical job roles. I've looked at the job roles on the CompTIA webpage, but are those realistic?

Thank you.

-Robert

Filter