220-1002 Exam Cram sheets Formatted Outline with Data Four major topic areas make up the CompTIA exam. 1.0 Operating Systems, 2.0 Security, 3.0 Software Troubleshooting, 4.0 Operational Procedures Domain 1.0 1.0 Operating Systems 1.1 Compare and contrast common operating system types and their purposes. 32-bit vs. 64-bit 32-bit limited to 4 GBs of RAM, 64-bit limit on Windows 10 Enterprise is 2 TB of RAM. 64-bit is quicker because of a larger bus. On a 64-bit Windows OS, programs are C:\Program Files. On a 32-bit Windows OS programs are in C:\Program Files(x86) RAM limitations Version Windows 7 Prof/Enterprise/Ultimate Windows 7 Home Premium Windows 8 Prof/Enterprise Windows 8.1 Prof/Enterprise Windows 10 Prof/Education Windows 10 Pro for Workstations/Enterprise Windows 10 Home X86 4GB 16GB 4GB 4GB 4GB 4GB 4GB X64 192GB 128GB 512GB 512GB 2TB 2TB 128GB Windows Software compatibility When installing windows operating system, the device drivers must be 32bit or 64 bit what every you operating system is using. The installation of applications Can be 32bit or 64bit and are loaded in two different places. When you wish to upgrade to another windows operating system then you should download a free program from Microsoft website called upgrade adviser. Linux Software Compatibility It is a good idea to go check the Linux web site read the technical documentation for the version of Linux you plan to install or upgrade to. This is important to make you that the applications you are using currently will function on the new version of Linux. The web site www.linux.org/apps will give you a complete listing of all apps that function on the website. Workstation operating systems. Some of the versions of Windows that are used on the workstation are as follows. For older versions Windows these are used in workstations: Windows 7 Pro/Enterprise. Windows 8 and Windows 8.1 Pro/Enterprise. Windows 10 Pro for Workstations/Enterprise. These versions are normally used in the corporate world. The other versions are used for specialized environments. The professional versions don’t have many multimedia features. Workstation operating systems have limitations as they were made for Desktop use only. Apple Macintosh OS the Mac OS X Lion is the eighth major release of Mac OS X, Apple's desktop and server operating system for Macintosh computers. Linux Ubuntu is used for some desktops. The Suse another complete Linux OS. The Fedora and Red hat are Linux based OS. Cell phone/tablet operating systems Microsoft Windows installed on phones are maintained and had been developed By Microsoft. The phones contain apps like Office suites, web browsers, and media player The newer phones with Windows 10 have digital assistant call Cortana. Android most phones run on android followed by tablets that use Android. IOS only used by Apple devices, such as the iPhone and tablets that are Apple. Chrome OS Google’s Chrome OS and this is Linux based and installed on smartphones and some specialized television sets. Vendor-specific limitations End-of-life the end of the system brings security vulnerabilities to products due to the vendor not supporting the product. This is a major problem no updates for firewalls and the no antivirus updates for the product. This will leave the system extremely Vulnerable to hacker’s malware and bad viruses. Update limitations Once the hardware have reached the end of life you won’t find the model of the motherboard on the Vendor web site which means there would be no bios update that it has reached the end of life. Update limitations on Apple are found on support.apple.com. Microsoft windows go to support. Microsoft.com/lifecycle. Compatibility concerns between operating systems Windows 64-bit versions are not compatible with 32 bits versions of windows. When upgrading you may only upgrade 64bit to 64bit and 32bit to 32bit. Applications that are 32 bits will function on a 32 bits operating system. Device drivers must be loaded to install according to operating system 32bit device driver will only work with 32bit and the 64bit driver will only work with the 64bit operating system. When needing to upgrade the operating system then you need can a program called upgrade advisor which tells you what is compatible with the operating system you planning to upgrade to. 1.2 Compare and contrast features of Microsoft Windows versions. Windows 7 editions were as follows Starter, Home Basic, Home Premium, Professional, Enterprise, and Ultimate. These versions have control panels. Corporate vs. personal needs Domain access there are varies versions and features of windows used in the corporate world. All corporates have domains. So, the windows needs to support the joining of domains. Therefore, all these windows Professional/pro, Enterprise, Ultimate, and education edition support domains. BitLocker allows users to encrypt the whole disk. If the disk is stolen it cannot be cracked. The versions that support this is windows Enterprise, and Ultimate, Windows 8 Pro, and Windows 8 Enterprise, Then Windows 10 Pro, Enterprise, and Educations editions. Media Centre This is portable home entertainment systems that have large screens, storage options with media features like a TV tuner. Video recording with surround sound. BranchCache this is a section where data is stored on the WAN. This is to speed up access from the office and the data does not need to be downloaded individually where everyone has access to the cache. This feature is only supported by Windows 7 Enterprise and Ultimate. Windows 8 Enterprise, Enterprise, and Educations editions. EFS This allows users to apply file and folder encryption and the following operating systems support Windows 10, Windows 8.1, Windows 8, and Windows 7. The home versions did not have bit locker and did not allow you to log on to a Domain. Windows 7 Home Premium, Professional, Enterprise, and Ultimate all have media Centre. Windows 8 and 8.1 was created to support touch screens. You also had to search for items which were not popular. This has charms bar where you swipe from left to right to get the option to shut down. Windows 10 also had Home versions. Professional and Enterprise. Windows has a version called Windows 10 Education created for schools and colleges licensed by the colleges. Desktop styles/user interface the top level of the user interface of windows is always the desktop. That’s where it starts when you boot up the start menu and taskbar which are used to control and launch and control applications. 1.3 Summarize general OS installation considerations and upgrade methods. Boot methods USB boot using solid state/flash drives, or an external/hot-swappable drive works well on ultra-books and netbooks without a DVD drive. Blue-ray can also be used. The ISO file can be mounted in the physical optical drive. Another method installing is External drive. Flash drive and eSATA. PXE/Netbook boots off a PXE server on the network to install an image of the OS and applications. Internal hard drive (partition ) HDD and SSD must be formatted OS installed is the standard way to boot after an OS has been installed. installed. Different operating systems can be installed on different partitions. Upgrade can be a clean installation where you would have needed to back up your data. The second option is when you upgrade the existing the operating system and you retain the data and all the stetting ’s called in place upgrade. Type of installations Unattended Installation uses an answer file as part of the installation process and would decrease the hands-on time it takes to install an operating system on multiple computers. Upgrade works for Windows 7 or 8 to Windows 10. The upgrade is not possible from a 32- bit OS to a 64-bit OS. The upgrade is not possible from a professional/business version to a home version. Clean install essentially deletes the current OS and files on a given computer and performs a fresh installation. Repair installation retains data and apps but resolves OS errors. A repair installation should be attempted first for a computer that will not boot correctly nor has other major issues. Multiboot is when multiple bootable OS installations exist on a single machine. An interface menu allows the user to choose which OS installation to boot. Remote network installation images or reimages computers after a PXE boot. Image deployment installs applications and settings as well as an operating system. Recovery Partition. Allows reinstallation from an image of the OS, drivers, and applications located within this hidden partition. This can significantly reduce reinstallation time and effort. Refresh. All personal files, settings, and apps are retained while the OS is reinstalled. Restore can return system setting and applications to a previous stable state. Partitioning logically divides a hard disk into separate storage space areas. Dynamic Partitions allow the creation of volumes that span multiple disks (spanned and striped volumes) and the ability to create fault-tolerant volumes (mirrored and RAID-5 volumes). Basic disks use primary portions, extended portions, and logical drives to organize data. Basic disks can have either four-primary partitions or three primary and one extended partition. Primary partitions can be set to boot an OS. The Primary partition that is currently set to boot an OS is the active partition. Extended partition can contain up to 128 logical drives. Logical drives can be assigned drive letters but are not bootable. GPT. GUID Par��on Table (GPT) is part of the UEFI specification. It is required for partitions over 2TB. GPT in Windows allows for 128 partitions. File system types/formatting: ExFAT is a Microsoft file system optimized for flash drives. FAT32 allows for partitions up to 2 GBs and file sizes up to 5 GBs. NTFS has file and folder permissions, disk quotas, compression, and encryption. Windows 7 and later requires NTFS for the system partition. The convert command is used to change FAT32 partitions to NTFS partitions. CDFS is used for CDs. UDF is used for DVDs. UDFv2.5 is used on Blu-Ray Disks. NFS allows a user on a client computer to access files over a network in a manner similar to how local storage is accessed. NFS is associated with UNIX, Linux, and NAS. Ext3, Ext4 are UNIX/Linux file systems. Ext4 is backward compatible with ext3. The ext4 filesystem supports volumes up to 1 EB (1024 TBs) and files up to 16 TBs. HFS Hierarchical File System (HFS) is a proprietary file system developed by Apple Inc. HFS supports similar features as NTFS but cannot support encryption. Swap partition this increases the amount of virtual memory available to a host. Quick format vs. full format Quick format only erases the location of files, not files themselves. Full format erases files and scans clusters for bad sectors. It should be used instead of quick format if the partition is experiencing problems. Load alternate third-party drivers when necessary Microsoft's Windows platform is considered universal but cannot read some things like ext3/ext4 partitions. Dynamic disks require the addition of the SCSI disk controller for that particular drive you will need to run and configure it. Normally, we only load approved, digitally-signed drivers approved, but then there comes a time you must use a third-party driver but need to disable the enforcement of digitallysigned drivers for you to install the driver. Workgroup vs. Domain setup Domain setup requires that the clock is synchronized and the primary DNS server on the client points to a DNS server that is authoritative for the domain. Time/date/region/language settings should be set to local time. Driver installation, software, and Windows updates. software and windows updates would complete the installation. Factory recovery partition is generally left undisturbed. This came about because new units don’t come with OS Disks. Properly formatted boot drive with the correct partitions/format with the correct partitions/format is set during installation. There may be a separate drive for documents that will be undisturbed if there is an OS reinstall. Prerequisites/hardware compatibility prerequisites are important you don’t miss the requirements homework should be done. Hardware compatibility needs to be verified that it does not exceed the requirements. Application compatibility Windows has got completed with the UAC. In the event, there is a compatibility issue. Windows has a Compatibility Troubleshooter wizard that could help to find the problem. OS compatibility/upgrade path You must check that the OS you are using is compatible with the path you are upgrading to. You must consider the version you are using, and you are upgrading to a higher version and not a lower version 1.4 Given a scenario, use appropriate Microsoft command line tools. Navigation dir C:\*.txt /s /p finds all the text files in the root of the C: drive and all subdirectories and displays this one page at a time. Star or asterisk is a wild card. Which chooses everything. cd is used to change the working directory. CD \ changes to the root directory. CD .. moves up a directory. CD <directory name> moves down to the directory name. .. moves up directory ipconfig View your IP configuration ping to test connectivity. tracert here you are able to verify the route to a remote host netstat -a shows active ports on a host. Inbound and outbound connections nslookup is used to query DNS servers for resource records. shutdown can be used to shut down or reboot a remote computer. dism Dism.exe /Remount-Image mount and unmount image sfc /scan now requires an installation DVD to check and replace any corrupt system files. It cannot be interrupted. It is an alternative to a reinstallation. chkdsk /f fixes errors on the disk. /r automatically recovers any readable data from the bad sectors that the hard disk drive may have. It includes /f and does a more thorough check. disk part command manages disks, partitions, and volumes directly or by scripts. taskkill can terminate unresponsive processes. gpupdate /force forces update to group policy. gpresult shows the resultant set of group policies applied to a local or remote workstation or user. format is used to erase all data and prepare a disk for use. /q is for a quick format. copy copies single files. Copy *.* copies all the files in a directory. xcopy /s copies folders, subfolders, and files. robocopy extends the functionality of XCOPY. net use Connect to a share net user you can add delete and get information about a user. [command name] /? provides the switches that go with the specified command. Commands available with standard privileges vs. administrative privileges Some commands require administrative privileges. To open an administrative command prompt in Windows 8/10 right click on the command prompt and select Command Prompt (Admin). 1.5 Given a scenario, use Microsoft operating system features and tools. Administrative Computer Management provides a number of utilities. Device Manager allows you to view installed hardware devices and adjust their drivers and configuration. Local Users and Groups To add a new a new user, in Windows 8/10 right click on the Start button>Computer Management>Right click on Local Users and Groups> Select Add Users Local Security Policy can stop users from turning off a computer that has a shared printer and changes the account lockout threshold to 30 minutes. Performance Monitor can send an alert to the administrator when the CPU stays above 90% for a period of time. It also shows pages per second and the queue length for the hard drive. Services. MSC displays the status of the services as either started or stopped. From the right-click context menu, Start, Stop, Pause, Resume, or Restart can be chosen. System Configuration MSCONFIG helps troubleshoot startup problems by allowing selective disabling of individual items that normally are executed at startup. Task Scheduler configures jobs to automatically run at scheduled times. Component Services allows you to deploy, administer, and secure component services. Data Sources configures connectors to databases. Print Management provides a single interface to manage all printers. Windows Memory Diagnostics Included memory module testing utility. It can be run via the mdsched.exe command and provides several configurations and testing options. Windows Firewall Provides security against software attacks. It can be enabled/disabled and configured via the Control Panel and command line. Advanced Security This is an extension of the Windows Firewall. Invoking the NETSH advfirewall command provides access to these options. Additional context and/or switch options are needed for specific functions and configurations. Event Viewer aids in identifying and troubleshooting computer problems. It contains the System, Security and Application logs. User Account Management requires the user's consent to continue with application changes. MSConfig Start>Run>MSCONFIG allows selective startup of programs and services. General Choose the startup type: Normal, Diagnostic, or Selective. Boot menu configures parameters such as the number of seconds the menu should appear before the default option is chosen and whether to go to safe boot. Services can enable, disable, or hide Microsoft services from display. Startup shows and can disable scheduled start-up programs. Tools provide quick access to useful Windows diagnostic tools. Task Manager in Windows includes a number of tabs Applications show application resource use and offer the ability to close them. Processes process resource use and provide the ability to end them. Performance displays CPU, memory, disk and Ethernet statistics. Networking provides Ethernet statistics. Users show connected users. Disk management will show a hard drive's status and can be used to configure RAID. Drive status shows as healthy or unhealthy. It also shows the following partitions: System, Active, Primary, Boot, Page File, Crash Dump, and Recovery. Mounting is mapping a partition to an empty folder on another partition. This requires the drives to be formatted with NTFS. Initializing. Disks must be initialized before they can be formatted and used to store data. Extending partitions can be done using free space on a drive to increase the size of a given partition. Splitting partitions. Before a partition that spans a hard drive is split it must be shrunken. Shrink partitions. To shrink a partition, right click on it and select Shrink Volume. Assigning/changing drive letters – Right click on a partition and select Change Drive Letters and Paths. Adding drives. When non-removable drives are added, they must be mounted and assigned a drive letter. Adding arrays increases fault tolerance using RAID, or performance using striping. Storage spaces provide fault tolerance and capacity expansion, with quicker recovery than RAID. System utilities include the following: regedit is used to edit the registry. The two main hives are HKEY_USERS that contains user settings and HKEY_LOCAL_MACHINE that contains drivers and other computer settings. Command or Cmd starts a command prompt window. Services.msc start the Services console in which services are displayed and can be started, stopped and configured. Mmc starts a Microsoft Management Console to which administrative tools can be added via snap-ins. Mstsc starts a remote desktop connection. Notepad is the basic text document tool in Windows. It can be used to strip away formatting, or even to communicate with a remote user during a remote session. Explorer. This opens Windows Explorer and allows for navigation and interaction with files and folders. Msinfo32 provides comprehensive system information on your computer. Dxdiag provides diagnostics and detailed information about installed DirectX video components and drivers. Defrag is used to organized disk clusters by file for quicker access. Solid state drives should not be defragged as they provide random access to data and defrag reduces their lifetime System Restore can return system setting and applications to a previous stable state. Windows Update automates the process of checking for updates and patches. 1.6 Given a scenario, use Microsoft Windows Control Panel utilities. Internet options allow you to configure the operation and security of Internet Explorer. General sets your home page and can clear your browsing history. Security allows you to set default or custom security for the following zones: Internet, Local intranet, Trusted sites and Restricted Sites. Privacy sets pop-up blocker and other settings. Content tab is used to configure certificates, AutoComplete and feeds such as RSS. Connections allow you to set up an Internet connection, VPN, and LAN settings; including a proxy server. Programs tab allows you to manage add-ons, set programs used by IE, set the HTML editor and set IE as the default browser. Advanced tab allows you to configure, restore and reset Internet Explorer settings. Display/Display Settings allows you to position multiple monitors and change the size of text, apps, and other items. Resolution is configured in Advanced display settings. The native resolution provides the clearest image. Color Depth and refresh rate are configured under Video adapter properties>Adapter tab>List all modes. 32-bit color provides 4 billion colors. Fewer colors are used for Remote Desktop. Refresh Rate that is too slow causes flickering and eye strain. It can also damage the Monitor User accounts are used to create accounts, manage account types and credentials, and change user account control settings. Folder options are used to alter the display of files and folders. Show Hidden Files makes files marked as hidden display in Windows Explorer. Hide extensions truncates the file extension from the end of file names. General options allow you to browse folders in the same or separate folders. View options allow you to show hidden files, folders or drives, hide protected operating system files and hide extensions for known file types. System Properties displays basic information about your computer. Additional options are configured when you click on Change settings. Performance (virtual memory) is configured on the Advanced tab>Performance Settings>Advanced tab> Virtual memory>Change… This allows the size of the paging to be set manually. Remote tab is used to configure and enable/disable Remote Assistance and/or Remote Desktop. System protection enables, disables, or initiates System Restore. Windows firewall configures which applications are allowed to send/receive data over the LAN connection. It provides protection against DDoS attacks. Power options conserve energy and battery life. Hibernate saves the desktop to the hard drive and then shuts down. No power is used. On resume, the desktop, including running apps, is restored. Power Plans adjust power consumption based on idle time and in the case of a laptop, whether it is on battery. Sleep/Suspend does not turn off your computer. It puts the computer and all peripherals into a low power consumption mode. Standby only sends a trickle charge to memory and uses less energy than sleep/suspend. Credential Manager this is an app in windows which stores your passwords for you, so you don’t need to remember all the passwords can use SSO. Programs and Features are used to enable or to uninstall applications and features. Homegroup provides password protected file, printer, and media sharing in Windows7/8/8.1/10. Near Share partly replacing Homegroup option in windows 10 build (1803) Devices and Printers enable management of printers, and devices such as speakers, monitors, mice, keyboards, optical drives, and USB drives. Sound allows you to set defaults, test, and adjust the volume of playback and recording devices. Troubleshooting aids in fixing problems in the following categories: Programs, Hardware and Sound, Network and Internet and System and Security. Network and Sharing Center allows you to view network information, set up connections, change adapter settings, change advanced sharing settings and troubleshoot network problems. Device Manager allows you to view and control the hardware attached to the computer. BitLocker encrypts the whole hard drive typically using a Trusted Platform Module (TPM). Sync Center this allows you to keep information in sync between your computer and Files stored in folders on network servers. 1.7 Summarize application installation and configuration concepts. System requirements when you need to know software and hardware for you to function Drive space Operating systems require large space to run some time 7GB and Microsoft soft office requires about 3GB of space on the drive. RAM Most applications would require 2GB of ram or higher to run. OS requirements Many of the applications were created to run within a specific operating system. So before you get the application you must make sure it fits the requirements of the version of the operating system you are using. Compatibility The software could have unpatched vulnerabilities do to with security of relayed to hardware. Research needs to be done to find cures to the vulnerabilities. Methods of installation and deployment Local (CD/USB) USB boot using solid state/flash drives or an external/hotswappable drive works well on ultra-books and netbooks without a DVD drive. Network-based PXE/Netbook boots off a PXE server on the network to install an image of the OS and Applications. Local user permissions normally on the device Folder/file access for installation to do an installation the user would run a setup file for a deployed application that can run using a service account. Security considerations Impact to device Proper security considerations need to be made in due to the potential impacts to the device if you have malware issues. So, software must only be installed from trusted sources. Impact to network Bad viruses can impact the stability and the performance of the network. 1.8 Given a scenario, configure Microsoft Windows networking on a client/desktop. Home Group vs. Workgroup Public Network Settings Homegroup provides password protected sharing. A workgroup requires a user account to utilize shared resources. Domain setup. Domain setup requires that the clock is synchronized and the primary DNS server on the client points to a DNS server that is authoritative for the domain. Network shares. To share a folder, right click on the folder, select Properties, and the Sharing tab. Click on Advanced sharing and select Share this folder. Administrative Shares are hidden and can be accessed by the administrator. They include C$ for the C:\ drive, D$ for the D:\ drive and Admin$ for the Windows directory. Mapping a drive. Right click on a shared drive and select Map network drive. To view the file and printer shares on a computer, right click on the Start button, select run, and type in \\computer_name and hit enter. Printer Sharing. In Devices and Printers, right click on a printer and select Printer Properties. Click on the sharing tab and put a checkmark in Share this printer. Network Printer Mapping. Connect to the computer with the shared printer using\\computer-name, then right click on the shared printer and select Connect. Establish networking connections includes the following: VPN – Click on Set up a new connection or network, and then select Connect to a workplace, then select Use my Internet connection (VPN). Dialup. Click on Set up a new connection or network, and then select Connect to a workplace, then select Dial directly. Wireless, Wired, WWAN (Cellular). In Network and Sharing Center, click on Change adapter settings to configure you're wired, wireless and cellular network cards. Proxy settings are configured on the Connections tab of Internet Options under LAN settings Remote Desktop Connection allows connection to the desktop of another computer without invitation. Remote actions are not displayed on the receiving end. Remote Assistance requires an invitation by a novice that will see what the expert is doing on the novice's computer. Home vs. Work vs. Public Network Settings go from lesser privacy and sharing to more security and sharing. The default setting is Public. A Homegroup requires the Home setting. Firewall settings. Start>Control Panel>Windows Firewall restricts applications to or from the Internet. Exceptions allow certain ports, protocols, or IP address ranges through the firewall. Configuration. ICMP settings can allow incoming echo requests, router requests, and redirects. Services settings can allow FTP, POP3, and HTTP. Enabling/disabling Windows Firewall Enabling and disabling ports is important that you use only the necessary ones. One must never disable a firewall under any condition. Configuring an alternative IP address in Windows you can now set up two IP address referred to as Alternate configuration settings. The standard IP you set in your IP and all The details IP, subnet and gateway or set it for DHCP under the General Tab. You go to network and sharing, then click on Change adapter settings then go to either wired connection or wireless. You right click on the adapter go to properties then choose IPV4 internet protocol properties and you see the general tab or alternate configuration. IP addressing can be configured using DHCP or with a static IP address. Subnet mask divides an IP address into a network portion and a host portion. DNS resolves a hostname to an IP address. A gateway allows communication with other subnets. Network card properties include the following: Half duplex/full duplex/auto. Full duplex sends and receives data simultaneously. Half duplex is used if there are transmission problems. Auto selects the highest common speed and duplex setting. Manual selection could be used if there were problems with auto. Speed allows you to configure whether the card should run at its highest possible setting or use a lower setting if that is what the switch accommodates. Wake-on-LAN sends a magic packet over the network to turn on a sleeping computer QoS can provide priority to VoIP and network control traffic. BIOS (onboard NIC). Make sure that an integrated NIC is set to Enabled w/PXE boot 1.9 Given a scenario, use features and tools of the Mac OS and Linux client/desktop operating systems. Best practices include the following: Scheduled backups can be performed in Linux and the Mac OS using rsync. Mac also has the Time Machine. Scheduled disk maintenance. Linux's fsck is a file system checker. The Mac OS has the Disk Utility that can verify and repair the hard disk. Linux System updates. Go to the homepage of the Linux OS you are currently using and check the version number of your OS against the current version number. App store in Linux and the Mac OS has the latest application versions and the newest apps. Patch management. Windows System Center Configuration Manager can patch additional systems such as Linux and Mac. Driver/firmware updates vary by Linux distribution from Ubuntu's Personal Package Archive (PPA) to Red Hat's Red Hat Package Manager (RPM). The MAC OS informs users of new updates in minor version releases. Antivirus/Antimalware updates depend on the vendor but typically are released daily. Tools include the following: Backup/Time Machine. While Linux graphical backup tools vary by distribution, the command line utilities of tar and cpio are universally supported. Apple's Time Machine includes hourly, daily, and weekly backups. Restore/snapshot. A snapshot pauses any changes while an image is made. A restore brings everything back to a prior state. Image recovery can restore your computer if the hard disk or entire computer ever stops working. Disk maintenance utilities. Man, e2fsck provides the manual files for the filesystem consistency check command in Linux. Cat /etc/fstab shows the file system table in Linux. Mac OS has the Disk Utility. Shell/Terminal. The command line is the shell because it is the outer layer through which the kernel of the OS is accessed. Screen sharing. The Mac OS includes screen sharing to connect to another Mac while you away solve a problem on someone else's Mac or collaborate with others on a project. Force Quit is used to terminate a hung application. Features in the Mac OS include Spotlight which understands natural language and searches the computer and the Web. Notes work with iCloud, so your notes updated and instantly available on all the Apple devices you own. Multiple desktops/Mission Control gives a bird's-eye view of open windows, desktop spaces, full-screen apps, and Split View spaces, making it easy to toggle between them. Keychain is a password management system for the Mac OS and Linux. Spot Light is a search tool built into Mac systems. One way to Spot Light is to click the magnifying glass icon in the upper-right corner of the menu bar. iCloud is cloud-based storage for all Apple devices. It provides for the automatic synchronization of data across all devices of the user. Gestures on a Mac touchscreen all for multi-touch actions to perform multiple actions. Finder on a Mac is used to search through files by content as well as file name. Remote Disc on a Mac OS is an icon in Devices and also in Computer that shows sharable drives on networked computers. Dock is the set of quick access icons at the bottom of the screen on a Mac. Boot Camp allows supported multiboot into Windows, and unsupported multiboot into Linux. Basic Linux commands ls provides a directory of files. grep searches text files for matching lines or patterns. cd changes the working directory. shutdown notifies all logged in users that the system is going down, disables further logins, and gracefully brings down the system. pwd vs. passwd. Pwd displays the current working directory, while passwd changes user passwords. rm removes files or directories. chmod changes permissions on files or directories. chown changes the ownership of a file. iwconfig/ifconfig display and can change (until a reboot) the configuration or wireless and wired network interfaces respectively. Ps a shows all running processes with their process ID. su/sudo. The su command uses the login as root, while the sudo command is used before a command to run it as root. apt-get is used to install Advanced Packaging Tool (APT) software packages. vi is a text editor. dd can copy a file to a different file format. KILL Used to end the process. Normally used conjunction with ps and kill. Domain 2.0 Security 2.1 Summarize the importance of physical security measures. Mantrap is a series of two doors to which a user must authenticate. It prevents tailgating. Badge reader may be combined with a proximity reader. These are RFID badges when it passes within 5 meters a signal transmits the ID to the management software. Persons without a badge should be challenged. Smart card generates a unique key based on the time. It also requires a pin. Thus, it provides two-factor authentications. A security guard is a visual deterrent and can make decisions based on their training and help to avoid breaches. Armed or unarmed they can be placed in front of the location. Door lock can be in a few forms conventual with use of a key, Deadbolt which is bolt on the frame, Electronic door lock using a keypad with a pin. A token base where you use a swipe card. Biometric locks are the strongest single factor of authentication Hardware tokens are devices that are something a user has to prove their identity. They are often associated with devices that enable the user to generate a one-time password. Cable locks can secure a laptop or the hard drive on a desktop. Server locks Server hardware comes with physical chassis security then stops any from getting to the power switch. USB locks this stops any from removing any device from the USB port unless it's been unlocked with a key. Privacy screen mitigates shoulder surfing. Key fobs such as RSA tokens generate a new code every minute that must be entered along with a pin in order to provide two-factor authentication. Entry control roster requires user authentication by a guard and records who entered a facility, their destination, their escort (if any), and when they left. 2.2 Explain logical security concepts. Active Directory Login script this is when the user signs in to the computer which is part of a Domain. The login script is assigned to the user which is part of the group policy. This will be used to configure all the requirements of the user from environmental variables, mapping drive, printers, and home folder. The login script will make sure the user conforms to the security requires of the network. Domain accounts are created and stored on a Windows Server which is Domain controller and the accounts are kept in the Active Directory. The accounts can be accessed from any computer as long as you are a member of a domain. User accounts have two types and local and domain. This can only be created and is managed by the administrator. Group Policy/Updates group policy is used to configure software deployment, windows settings with administrative templates where settings can be configured as a group. When updates are needed you use gpupdate. Organizational Units they are existing containers and the OUs that store the accounts created in Active Directory. You can create more OUs when you need to have them. OUs store Accounts with security. Home Folder this is a private section of the network storage place for users to store all of the personal files on a shared network server. Folder redirection by default users’ files is stored on the local user’s profile. Some we work on more than one computer, so we need the files to follow us We use folder redirection like roaming profile our log in settings and wallpapers can follow up. Software tokens token-based authentication MDM policies This is a management software used to apply security policies to use of mobile devices in use in the enterprise. This can allow apps or block if there is a security issue. Port security this switch does the IEEE 802.1x standard which does the Portbased network access control. This switch does authentication of the device before it activates the port. MAC address filtering Port security Port security can be enabled on a switch where it will only accept certain connections based on the mac address including IEEE 802.1x port- authentication mechanism which allows communication once authentication was successful. Certificates CA Certificates were created as a means of authentication which issued by a certificate authority for two entities being either clients (users) or servers. Antivirus/Anti-malware Antivirus software is an essential security application that must be updated regularly. The database and the engine should be updated. If the Antivirus identifies there is a virus it may quarantine it to stop it till it is able to deal with it. Anti-malware the antivirus you choose must also work with malware not all antivirus work with malware Firewalls are like security guards who will allow you in based on your credentials. They filter packets based on IP address, ports, and protocols. Firewalls have access control lists to control who comes in. There are two types of firewalls Stateful and Stateless. User authentication/strong passwords This would be a minimum of 8 characters with uppercase and some hash characters as well. Multifactor authentication this is when use items to authenticate like a smart card and the use of a password. Directory permissions Make sure secure form of authentication encryption is used and supported by the network and the authentication servers. Request users to change passwords according to the company’s password policy. Implement a minimum 8 characters or more if need be. VPN concentrator A virtual private network (VPN) concentrator is a hardware device for creating a secure VPN between two sites across the internet. DLP Data loss prevention was created as a system to reduce Data lose with data leakage or theft. When theft is confirmed legal proceedings can be implemented. Access control lists ACL Firewall access control lists (ACLs) are a set of rules that allow traffic through should they meet the criteria set out. Should they not get through the next rule Then the next rule would be tested. They are also called filters. Smart card this is an access card you need a Pin to activate the card and encryption is used to protect the contents. Email filtering this is done before the mail is set on to your inbox and it can be scanned before it I sent out. There can spam filter which is meant to catch the spam but some of it slips through. Trusted/untrusted software sources There are trusted software sources that you know and work with all the time like Microsoft, Adobe and many other registered sites where you have recourse if you run into a problem or you get support. The untrusted software sources don’t have legit updates and most the time the time software is pirated The principle of least privilege users must only have enough permissions and privileges needed so they can do their job. 2. 3 Compare and contrast wireless security protocols and authentication methods. Protocols and encryption WEP has flaw 24 bits with plain text and does not update regularly making it weak. WPA Wi-Fi Protected Access was created to improve over the web and still uses the RC4 and Temporal Key Integrity Protocol TKIP was implemented so it could issue a random encryption key. WPA2 replaced the WPA and the WPA2 is the strongest WPA2 and was defined in IEEE 802.11i. TKIP Temporal Key Integrity Protocol TKIP was implemented into 802.11 wireless created in the beginning to replace WEP without the need to replace wireless hardware. Temporal Key Integrity Protocol (TKIP)—TKIP uses the RC4 encryption algorithm, with a 128-bit encryption key, and a 48bit initialization vector (IV), followed by a message integrity code. AES is a block cipher was created to replace DES this uses 128-bit blocks encryption but depending on the key chosen this will use 256bit. This has never been cracked Authentication prove who you are Single-factor User name and password Multifactor authentication using two or more categories of authentication is stronger than single-factor authentication. Factors include something you know, have, or are. RADIUS A Remote access policy that will enforce rules on how and what the devices access company resources from the remote locations. Normally they will use RADIUS to enforce authentication. TACACS Terminal Access Controller Access Control System is a AAA server that is an open standard that uses TCP. 2.4 Given a scenario, detect, remove, and prevent malware using appropriate tools and methods. Malware Ransomware is malware that extorts users to pay a ransom to decrypt their data, hard drive, or source code. Trojan are seemingly harmless programs with a malicious hidden payload that compromise system security by exploiting system access through a virtual backdoor. Keylogger This will record every key a user types on the Keyboard and send it to a third party the best to keep safe an up to date antivirus will detect it. Rootkit is suspicious system-level kernel module which modifies file system operations. They are characterized by hooking processes and erasing logs. Virus is a malicious software program loaded onto a user's computer without the user's knowledge and performs malicious actions. Antivirus is the way to remove it. botnet. A botnet is a large group of infected computers/bots/zombies that have been taken over by hackers. Worms are self-contained programs. They can spread by network shares with no user interaction. As a result, worms spread faster than viruses. Spyware that goes after banking accounts, credit card details, and VPN passwords. Antispyware removes it. Tools and methods Antivirus The best defense against a virus attack is up-to-date antivirus software Anti-malware Antimalware software gets rid of viruses and other malware. Antivirus software definition files should be continually updated Recovery Console is available if the GUI is busted, or when malware must be manually removed as automated removal has failed. Backup/restore Backup is the best tool to perform a regular archiving of information on a PC System restore is the least disruptive way to remove recently installed files and software. System restore should be disabled before malware removal. Rstrui runs system restore. End-user education so he is less likely to expose his computer to malware, and better able to eliminate malware. Software firewalls an unauthorized port could create major problems when malware gets it to the system it runs with administrative privileges. You need to make sure your policies are set to default and always check for any changes. DNS configuration Can be compromised by a malware infection. This can redirect you to malicious websites. It's important you run malware checks all the time. To ensure a clean system. 2.5 Compare and contrast social engineering, threats, and vulnerabilities. Social engineering Social engineering includes impersonation, pretexting, getting information out of some without the use of technology, manipulating people into giving you information. Phishing The attacker poses an individual of a bank that is a duplication your bank, sends you to mail enticing you up update your account which is set on their server. Spear phishing Sends out mail to groups which include staff and the CEO. The attackers are seeking unauthorized access to sensitive information. This would be an email with an attachment. Impersonation When a person masquerades another person and may have a copy of the other person's credentials. This is done mostly to extort finances out of unsuspecting individuals. Shoulder surfing Privacy screens placed over the monitor will block anyone from the side of you from viewing your screen, however, you need to make sure no one is behind. Tailgating When a person being unauthorized will follow an authorized person very close into an entrance. This also is done entering the car park in a car. Dumpster diving attackers will search in the dumpster through the old printouts due to them not being shredded. This can also be passwords written down on sticky notes. DDoS Distributed denial of service is being considered a devastating attack. This is done by using multiple hosts simultaneously normally Botnets. All the combined efforts can easily bring down a server or complete network. DoS Denial-of-service attacks are when a legit use can’t access that website, the server is being pondered with requests to it can’t respond to normal requests. This DoS attack is to a single target. Zero-day This is a vulnerability or weakness in the software if not patched the attacked will exploit it and gain entrance. Man-in-the-middle the attacker gets between two hosts and hijacks a session where the one host thinks he is chatting to legit host and he is not. It will happen near the end of communication the attacker connects and the legit host who is not aware that his communication is with an attacker. This is fixed by using a time stamp to the communication Brute force attacker attempts to work out all possible character combinations either on the line or offline. The way it works is they use a number of combinations of user name and password repetitively like hitting a fort. Dictionary The art of comparing passwords against a list in the database and then use ciphertext by attempting many different common passwords and possible usernames that the humans do. Rainbow table Rainbow tables are used to discover passwords and by doing precomputed hashes it searches the hashes for the password. Spoofing the attacker changes the source IP address, so it would a pair to come from another network. Since the address is false you can’t locate the attacker. Non-compliant systems can be discovered by a vulnerability scanner. Penetration tests show that a vulnerability can be exploited by an attacker. Zombie A botnet is a large group of infected computers/bots/zombies that have been taken over by hackers. 2.6 Compare and contrast the differences of basic Microsoft Windows OS security settings. User and groups Users should be placed in groups and then the groups are given permissions. The administrator is all powerful. This account should be renamed and heavily audited Power user in Windows 7 and below could install software. Guest has limited privileges and should be disabled. Standard user account should be used for email and Web surfing by the administrator. The runas command should be used to do tasks that require administrative permission. NTFS vs. share permissions Both permissions are required for network access to resources. The one with the least permission is the overall permission. Allow vs. deny the deny permission overwrites the allow permission. Moving vs. copying folders and files Moving files on the same partition does not affect the original permissions. Moving to a different partition or copying changes permissions. File attributes include read-only, hidden and system. They can be viewed or changed on file or folder properties or with the attribute command. Shared files and folders can be set with Folder Properties>Sharing tab, or Computer Management, or the net share command. Administrative shares vs. local shares Administrative shares are created automatically and end in a $, such as C$ and Admin$. Local shares are created by users. Permission propagation to subfolders and files is automatic (but inheritance can be disabled) and indicated by grey checkmarks in the indicated permissions. Inheritance is the default unless a specific setting is created to override this. System files and folders have the System and often the Hidden attribute. User authentication is provided by Kerberos in Active Directory and can be provided by pluggable authentication modules in UNIX and Linux. Single sign-on simplifies assignment and revocation of privileges to multiple resources, simplifying password management. Run as administrator vs. standard user Administrative privileges are needed to install hardware and software; however, the administrator should be logged in as a user and use runas. BitLocker encrypts the whole hard drive typically using a Trusted Platform Module (TPM). BitLocker To Go encrypts removable media. It requires the Enterprise or Ultimate version of Windows 7 or higher. EFS (Encrypting File System) would be used to encrypt a folder within a hard drive. 2.7 Given a scenario, implement security best practices to secure a workstation. Password best practices include the following: Setting strong passwords that are long and complex. Password expiration so passwords are periodically changed. Changing default usernames/passwords so that someone knowing the make of a device or the installed OS or program will not know the current password. Screensaver required password provides security if a user forgets to log off when he leaves a computer unattended. BIOS/UEFI passwords prevent a malicious user from changing the boot order to boot off USB or an optical drive that could be used to hack the system. Requiring passwords for all accounts should be done even on small networks and home computers. Account management includes the following: Restricting user permissions to the minimum required consistent with least privilege. Login time restrictions could be used to restrict users from coming back to work in their off hours to hack the system. Disabling guest account prevents unauthenticated access to the network. Failed attempts lockout would limit password guessing, dictionary, and brute force attacks. Timeout/screen lock could be implemented by a password protected screensaver. This could be enforced on all computers in the domain by group policy. Change default admin user account/password should be done so that someone who knows the router model does not know the username and password. Basic Active Directory functions when a server becomes a domain controller ‑ Account creation the creation is done in the active directory to manage users and is created by the administrator. ‑ Account deletion this account be deleted by right-clicking on the object which is the account and then click delete, this can not be reversed if unsure then use disable and then enable later when you need to do so. ‑ Password reset/unlock account this done by going to the properties dialog where you right click and select reset password. ‑ Disable account this done by going to the properties dialog where you right click and select disable the account. Disable autorun Use the control panel applet to configure auto pay actions. Data encryption this used to protect OS files on the disk from being overwritten. Patch/update management Apply very UpToDate patches top protect against attacks. 2.8 Given a scenario, implement methods for securing mobile devices. Screen locks can prevent someone from using the mobile device if it is stolen. Fingerprint lock ties authentication to a particular user and is stronger than a pin. Face lock is more secure than a passcode or swipe process. Difficult in dim lighting. Swipe lock requires a series of gestures and can be defeated if it is too simple and the attacker is given enough time. Passcode lock is the most common, and easiest to implement the type of screen lock. Remote wipes prevent compromise of sensitive data if a device is lost or stolen. Locator applications can help you find your smartphone if it is lost or stolen. It can also be used by bad guys to track a user's location. Remote Backup applications can be cloud-based and operate without user intervention during slack time. Failed login attempts restrictions can lock a computer and protect against hacking the password with multiple attempts. Antivirus/Anti-malware is available for mobile devices and should be used. Patching/OS updates secure a mobile OS as new exploits are discovered, and the code is updated to thwart these attack vectors. Biometric authentication can be by facial recognition, or by fingerprints. Full device encryption would protect the data on a smartphone if it were lost or stolen. Multifactor authentication is stronger than any single factor of authentication. Authenticator applications including Google Authenticator, McAfee Pledge and SAASPASS facilitate a time-based one-time password (TOTP) on a mobile device. Trusted sources vs. untrusted sources - Trusted sources include Google Play and the Apple Store. An untrusted source would be a torrent or an app that is not digitally signed. Firewalls can protect a mobile device but drain the battery. Policies and procedures are enforced on mobile devices through mobile device management (MDM). Management certificates can be distributed using over-the-air (OTA) technologies. BYOD vs. corporate owned – BYOD devices can use an encrypted container for corporate data that can be wiped without affecting user data. Corporate devices can be completely wiped. Profile security requirements are device security settings that can be can be defined based on user groups or device types. 2.9 Given a scenario, implement appropriate data destruction and disposal methods. Physical destruction can be done by the following means: Shredder turns multiple hard drives to small pieces. Drill/Hammer is a low-tech but effective means of hard drive destruction. Electromagnet (Degaussing) is a quick way to erase hard drives. Incineration is a very effective means to destroy hard drives. Certificate of destruction attests that the data on a hard drive has been rendered unrecoverable. Recycling or repurposing best practices include either low-level factory-level format or multiple random bit-level writes to the hard drive before repurposing it. Low-level format vs. standard format. The low-level format typically writes all zeros to the entire disk drive. A standard format only erases the reference to the data, not the data itself. Overwrite software typically does multiple passes to erase magnetic remnants. Drive wipe is not as secure as physical destruction. 2.10 Given a scenario, configure security on SOHO wireless and wired networks. Wireless specific: Changing default SSID would differentiate a network from other with the default SSID. Setting encryption using WPA2 provides the best wireless security. WPA isn't bad, but Disabling SSID broadcast would provide some wireless security, but a sniffer could discover the SSID. Antenna and access point placement. To limit the war driving the access point antenna placement should be at the center of the coverage area with as li�le bleed over as possible. Radio power levels should also be the lowest that does that covers but not overcover. WPS (WiFi Protected Setup) allows the user to press a button on the wireless router to transmit the encryption key for a short period of time. The desired area to limit wardriving. WEP is very weak and can be sniffed and spoofed Change default user-names and passwords should be done so that someone who knows the router model does not know the username and password. Enable MAC filtering can limit access to trusted groups of individuals, but MAC addresses can be sniffed and spoofed. Assign static IP addresses and limit access to those addresses for higher security. Firewall settings should be enabled and configured on the wireless access point. Port forwarding/mapping would associate an inbound port with the IP address of the target server. Domain 3.0 Disabling ports that are not needed reduces the attack surface. Content filtering/parental controls can be implemented on a proxy server to block access to objectionable websites. Update firmware to take advantage of new capabilities (such as multiple SSIDs) or increase security. Third party WAP firmware includes DD-WRT, Tomato, and OpenWRT. Physical security is important to your wireless infrastructure. Access points should be secured. Software Troubleshooting 3.1 Given a scenario, troubleshoot Microsoft Windows OS problems. Common symptoms Slow performance warrants an anti-malware scan and disabling any unneeded new software or browser add-ons. Cleaning the registry and in extreme cases reinstalling is warranted. Limited connectivity solutions include the following: reconnect, reset TCP/IP stack, disable Wi-Fi adapter napping, enable Metered Connection Downloads, reset TCP/IP Autotuning Failure to boot may mean that a hard drive failed, hard drive array failed, or RAID controller failed. OS not found may mean that the boot sector should be repaired Application crashes Check for malware infection many times cause of the crash. Blue screens BSOD (Blue Screen of Death) is a fatal Microsoft OS problem. Apple has the pinwheel when an application has insufficient resources. Black screens This is a malware infection, or the driver has got corrupted. Printing issues Determine is its network hardware or the drivers have become corrupted. Services fail to start to Check the Event Log. Run services.MSC to check dependencies and startup type. Slow bootup Sometimes check network service or the configuration is out. Slow profile load This could be corrupt profile create an account and copy to the old one. Common solutions Common Solutions Defragment the hard drive organizes clusters on a hard drive by file to speed access. For solid state drives, it is unnecessary and reduces their lifespan. Reboot Continuous reboots - Before the Windows logo comes on, repeatedly press and release F8 until the boot menu appears. Select Safe Mode. Kill tasks You can go to two places Task manager look for the task and then right click on it then click end task. In Command prompt you can also stop services by typing Kill Task you need type the name followed by the extension. Restart Services Services.MSC displays the status of the services as either started or stopped. From the right-click context menu, Start, Stop, Pause, Resume, or Restart can be chosen. Update network settings Use device manager to remove and to update any drivers or roll back if there is a problem. Reimage/reload OS sometimes installations will get corrupted. To reimage you need back to a working source of an image you stored and reimage the machine. Rollback updates when you have a problem use system restore if not, go to view installed updates and click uninstall. Roll back devices drivers you can get a problem with a new driver so all you do is roll back to the old one that was working. Apply updates Windows Update automates the process of checking for updates and patches. Repair application Open Control Panel, open Add or Remove Programs, select the application, click Change, and follow the instructions presented to repair the applications. Update boot order Installing from DVD you need to update the boot order that it will boot from the DVD and not Hard drive choose from the menu. Disable Windows services/applications Windows services can be stopped at services.msc. Applications can be disabled at settings. Go to Privacy and then Background and see the option to disable all apps Disable application startup Go to MSConfig and then untick to disable the application from starting up. Safe boot loads only basic drivers good for troubleshooting. Rebuild Windows profiles This will require you to create a new account and copying the old files to the new account but excluding the following Ntuser.dat, NTuser.dat.log,NTuser.ini 3.2 Given a scenario, troubleshoot and resolve PC security issues. Common symptoms which include the following: Pop-ups can be limited to some extent by pop-up blockers. Sometimes whether you click Yes or No on a popup malware will be installed, so X out of the pop-up, or use Task Manager. Browser redirection is a serious problem. Solutions include disabling new add-ons in the Programs tab or Reset Internet Explorer settings on the Advanced tab of Internet Properties. Security alerts against downloading or executing a file should be followed unless you initiated the download and are confident of the trustworthiness of the source and have scanned the file. Slow performance warrants an anti-malware scan and disabling any unneeded new software or browser add-ons. Cleaning the registry and in extreme cases reinstalling is warranted. Internet connectivity issues may be caused by malware that changes the host file or sets up a false proxy server. Antimalware software should be run. A system restore may be needed. PC/OS lock up. Scan for malware. Investigate and rollback any recent hardware or software changes. Application crash may be caused by malware or corrupted files. Try repairing or reinstalling the application. OS update failures or failure of antivirus software to run or update may indicate malware. Try System Restore. Try booting from removable media and running antivirus from there Rogue antivirus offered by a pop-up or other means should not be installed. This goes for pop-up saying that your media player or codec or Java needs to be updated. Spam from unwanted sources should be designated as such to your spam filter and blocked. Renamed system files indicate a serious infection, possibly a rootkit or Trojan horse. Files disappearing are another symptom or infection or a failing hard drive. File permission changes are yet another indication or malware such as a rootkit or Trojan horse. Hijacked email someone took your mail over. ‑ Might be indicated by returned email or automated responses to email you did not initiate. ‑ You want to change your password to regain control over your email. Access denied could indicate malware or a corrupted file system. Invalid certificate (trusted root CA) – Is generally malware but reset browser settings and download the latest browser updates as the certificate might have been revoked or corrupted System/application log errors You go to event viewer and you get three tabs Security, system and applications. When you wish to view applications, you look at application here it will allow you to see errors. The same system will able to view errors. 3.3 Given a scenario, use best practice procedures for malware removal. Identify malware symptoms using observation, error messages, and Event Viewer. Quarantine infected system so it can be studied and so it does not infect other systems. Disable system restore (in Windows) in case the malware tries to restore itself. Remediate infected systems as follows: Update antimalware software to deal with new threats. Scan and removal techniques (safe mode, pre-installation environment) will allow removal of malware before it becomes resident in memory or locks system files. Schedule scans and run updates on a regular basis, and whenever an infection is suspected. Enable the system to restore and create a restore point (in Windows) after the computer has been scanned for malware and before any major updates. Educate end user so he is less likely to expose his computer to malware, and better able to eliminate malware. Malware messes up with your permissions and gives a Blue screen. 3.4 Given a scenario, troubleshoot mobile OS and application issues. Common symptoms include the following: Dim display on a laptop could be the inverter or the backlight. Check the brightness setting on a smartphone. On a laptop or tablet check power settings. Intermittent wireless connectivity might be loose antenna wires or interference. No wireless connectivity might mean that wireless is disabled in hardware or software, that there is a problem with DHCP or the ISP. No Bluetooth connectivity could indicate that Bluetooth is disabled, or pairing it has to be re-attempted. Cannot broadcast to external monitor might be a driver problem or an incorrect key combination to connect the external monitor. Touchscreen non-responsive can sometimes be resolved by rebooting or reinstalling touchscreen drivers. Cleaning and recalibration can also help. Apps not loading. Check for a conflict with a new app. Look for an update. Redownload and reinstall the app. Ensure you have enough resources for the app. Slow performance can be remedied by freeing storage space and limiting running apps. Unable to decrypt email. Make sure that you have the public key of the sender. Extremely short battery life. A battery should be fully discharged and fully recharged multiple times. If that doesn't work, the battery should be replaced. Overheating. Make sure vents are cleaned, fans are functional, and laptops are not rested on a soft surface. Frozen system. Try restarting the device, uninstalling and reinstalling any offending applications, as well as enabling and disabling airplane mode. No sound from speakers. Make sure that: The device is not muted, the device is not set to vibrate only, the device has its volume sufficiently turned up. Inaccurate touch screen response. Clean and calibrate the touch screen. System lockout may require a factory reset. On an iPhone try the Iforgot option to unlock the phone with your existing password. App log errors Consumer level devices the IOS and Android do not support log viewing tools, you must have root level permissions to view all the logs. 3. 5 Given a scenario, troubleshoot mobile OS and application security issues. Common Symptoms Signal drop/weak signal can be caused by localized poor coverage caused by distance from a cell tower, interference, building materials or obstruction. A cell phone booster may help. Power drain can be minimized by turning off a hot spot, Bluetooth, and unnecessary apps. Slow data speeds can be caused by movement, congestion of users, a weak signal, or malware. Unintended WiFi connection may be caused by a previous open connection to a default SSID. Unintended Bluetooth pairing may be caused by failure to change the default pairing code. Leaked personal files/data may be caused by wardriving, an evil twin, or Bluesnarfing. Data transmission over the limit should be corrected by adjusting your data plan, using Wi-Fi when available, not streaming video, or downloading large files, and by limiting hotspot usage. Unauthorized account access means that you should inform your provider, change your password, scan for spyware, check for Bluesnarfing, and beware of an evil twin. Unauthorized root access is more likely on devices that have been jailbroken/rooted to work with any carrier. This allows side-loading of application, bypassing application security. Unauthorized location tracking can pinpoint a user's movements and become a safety issue. GPS tracking can be turned off along with apps that do location tracking. Unauthorized camera/microphone activation is an indication of a Bluebugging exploit to spy on a user. High resource utilization may be an indication of malware or a hung app. Domain 4.0 Operational Procedures 4.1 Compare and contrast best practices associated with types of documentation. Network topology diagrams Network diagrams (logical/physical). Logical network diagrams display enterprise IP routing policy. Physical network diagrams show the way that devices are connected. Knowledgebase/articles many software and hardware manufacturers maintain pieces of knowledge or articles on the Wikus to share information about common information. Incident documentation could be a simple spreadsheet or maybe a database. It could also be a management tracking application all depends on requirements. Regulatory and compliance policy This is adherence to laws, regulations, and specifications to its business Acceptable use policy AUP Acceptable Use Policy AUP (acceptable use policy) explains to users how they must access a network’s resources and also explains penalties for violations. Password policy A password policy is a set of rules that states the length of the password minimum and the lowercase letters, numbers, and symbols in the password. Inventory management It is critical for any organization to have a welldocumented inventory of all assets and resources. Asset tags Asset tags are identification tags attached to assets, which there are two types of Fixed assets and moving assets this means we can keep track of assets. They use RFI as well. Barcodes became commercially successful when they were used to automate supermarket checkout information is encoded in them and are used for serial numbers. 4.2 Given a scenario, implement basic change management best practices Documented business processes In your organization you need general business processes to be documented of your daily workload. The company that requires FDA or other government approvals so that you may sell goods and services. The last item you can track of all employees joining the company and departing from the company. Then when you require your IT setup to upgraded you have details in place. Purpose of the change to make changes to repair or upgrade Scope the change scope change involves adjusting the cost and budget, Risk analysis is when do a change and then maybe we don’t due to the cost implications Plan for change this is done when we need correct an issue or when need to up out system End-user acceptance Should work if the change was performed to their satisfaction and it was implemented correctly Change board When there may a manager or supervisor who needs to be changed if this considered major then this process must get approval through Change advisory board. Approvals the change is subject to the change advisory board. Backout plan when unforeseen problems occurred when the change is made to document all of the changes Document changes Without you documenting the changes you don’t have an accurate reference to measure if the change was effective. 4.3 Given a scenario, implement basic disaster prevention and recovery methods. Backup and recovery all back and recovery should use role-based access control lists, data encryption for backup and storage. Polices where we use to access, the testing with backup/restore cycles outlined. Image level a snapshot is taken of them on the virtual machine. Here all Air filter mask protects your lungs from toner and solvents. the information is captured for the VM to run. File-level A file-level backup allows you to restore individual files and folders. The data gets cataloged in the backup product the same way as a physical server's file system does. Critical applications network applications depend on database storage before induvial file-based storage. That’s why a specialist back system is important. Backup testing the backup test is very important you need to make a test directory and make sure no data gets overwritten in the process. Most important configure the system to verify as it writes, make it contains all the required files. Test backup media and the hardware device on a regular basis. UPs uninterruptible power supply this will supply power when the mains goes off for a period of time depending on the model of the unit. This runs on batteries and has filters that clean up the mains. The battery is being charged while the mains is on. This uses an inverter to convert DC to AC. It can deal with spikes and brownouts as well. Surge protector This is a device that filters out the effects of spikes and surges. Surge protectors are rated according to national and international standards. Cloud storage vs. local storage backups when you use cloud storage the provider will be responsible to do the backups and when you back up locally you have to do the backups yourself. Account recovery options When a user forgets a password when you have some questions to answer that you set up in the beginning when you created the account. Once you answer a question then a token or message with a code is sent to one of your trusted devices listed or an email account plus it can be an SMS to a smartphone. Compliance with local government regulations protects workers from a hazardous workplace. If employees are injured, you may need to contact OSHA. 4.4 Explain common safety procedures. Equipment grounding helps prevent ESD. Use a grounding strap when handling components Proper component handling and storage includes the use of the following: Antistatic bags include a “Faraday cage” layer that prevents static buildup, and additional layers to guard against charges inside and out. ESD (Electrostatic discharge) straps safely ground a person to sensitive electronic equipment, preventing the buildup of static electricity that would result in electrostatic discharge. ESD mats safely dissipate static electricity and should be grounded. Self-grounding can be accomplished by touching the inside case of a computer before working inside it. Toxic waste handling should be done with care. Potentially toxic waste includes the following items. These items should be recycled and separated from normal trash. Batteries contain toxic materials that should not be put in landfills and the water table. Examples are lead, cadmium lithium, manganese, and mercury. Toner cartridges can usually be recycled back to the office supply store from which they were purchased or to the toner manufacturer. Cell phone contains toxins and mercury. It can contain arsenic. If can be donated for reuse, then use approved waste management recycling plant is the way to get rid of it Tablets need to be disposed of the same way as Cell phones since they carry similar Material. Also, use recycling plant Personal safety items include the following: Disconnect power before repairing PC so you do not shock yourself or damage the equipment. Remove jewelry that might get caught in cables and components as your work. Lifting techniques include lifting with your legs rather than your back. Using a back brace, getting help, and using a cart to move heavy or multiple items. Weight limitations should be enforced. This may mean more trips, or getting help lifting heavier items. Overdoing it may lead to back problems or a hernia. Electrical fire safety. Have Class C fire extinguishers in key locations. Class C extinguishers typically use carbon dioxide or FM-200. Halon use has been deprecated. Cable management prevents tripping hazards and facilitates troubleshooting. Safety goggles protect your eyes from harmful materials. 4.5 Explain environmental impacts and appropriate controls. MSDS (Material Safety Data Sheets) documentation for handling and disposal identifies workplace hazards and recommended first responder actions. The successor form is the Safety Data Sheet. Temperature, humidity level awareness, and proper ventilation help maintain the availability of servers. Monitor with thermostats, humidistats, and air quality sensors. Power surges, brownouts, blackouts can be mitigated by the following: Battery backup handles the loss of power on a short-term basis. Backup generator handles the loss of power on a short-term or longerterm basis. UPS (Uninterruptible Power Supply) handles over or under amperages or voltages. Surge suppressor only handles power spikes. Protection from airborne particles include the following: Enclosures and server rooms that filter the air. Air filters/Mask are useful when working with toner. Dust and debris can be cleared by the following: Compressed air clears dust that acts as an insulator and leads to overheating. Vacuums for items such as excess toner, with filters for fine particulates, can be used. Compliance with local government regulations and industry requirements is mandatory. 4.6 Explain the processes for addressing prohibited content/activity, and privacy, licensing, and policy concepts. Incident Response procedure steps include in order: preparation, identification, containment, eradication, remediation and lessons learned. First response includes the following: ‑ Identify the nature and extent of the incident. ‑ Report through proper channels is facilitated by having report templates. ‑ Data/device preservation would protect evidence. Evidence should be collected in order of volatility to preserve the most perishable evidence first. Use of documentation/ documentation changes would facilitate the presentation of evidence in court. Chain of custody creates a chronological paper trail of the seizure, custody, control, transfer, analysis, and disposition of evidence. ‑ Tracking of evidence/documenting processes are significant parts of the chain of custody Licensing / DRM (Digital Rights Management) / EULA (End User License Agreement) procedures make sure that software is distributed and used legally. DRM can prevent copying and distributing software beyond the original user. Open source vs. commercial license. Open source is free, whereas you pay for a commercial license. Regulated data Personal license vs. enterprise licenses. A personal license is associated with an individual. An enterprise license is associated with a company, often at a volume discount. Personally, Identifiable Information (PII) such as SSNs and credit card numbers should be protected. Generally, PII is encrypted when it is stored and transmitted. PCI Payment card industry data security standard it sets out protection that must be provided for cardholders data that is secure at all time. GDPR General data protection regulatory framework is a process that makes data handlers responsible for the complaint about the storage of personal information. Follow corporate end-user policies and security best practices that are approved by upper management and disseminated to all. 4.7 Given a scenario, use proper communication techniques and professionalism. Use proper language. Avoid jargon, acronyms, slang when applicable. Speak to express rather than to impress. Maintain a positive attitude / Project confidence. Talk about what you can do for a user to solve their problem, versus what you can't do. Actively listen (taking notes) and avoid interrupting the customer even when they drone on. This shows respect and you might learn something that helps solve an issue. Be culturally sensitive. Do not belittle anyone based a physical characteristic, belief, clothing or nationality. Use appropriate professional titles, when applicable to show respect and acknowledge their accomplishments. Be on time, and if late make sure to contact the customer. This is common courtesy and shows that you value their time. Avoid distractions such as the following: Personal calls should go to voicemail. If you anticipate an important call that cannot be avoided, inform the customer beforehand to gain their understanding. Texting/Social media sites should be avoided as the customer is paying for your time. Talking to co-workers while interacting with customers should be avoided unless they are consulting on the problem. Focus on the issues at hand. Personal interruptions should not distract you from solving the customer's issues. Dealing with a difficult customer or situation should be done professionally. Avoid escalating a situation. The goal is to keep a customer and not to win an argument. Do not argue with customers and/or be defensive – Give customers insight into your troubleshooting process and possible outcomes. Put yourself in their shoes. Avoid dismissing customer problems - What is trivial to you may be very important to the customer. Avoid being judgmental as customers have their own areas of expertise. Knowing more about computers does not make you superior to your customers. Clarify customer statements (ask open-ended questions to narrow the scope of the problem restate the issue or question to verify understanding) – This active listening helps avoid miscommunication and shows respect for your customers. Do not disclose experiences via social media outlets as to do so would disrespect your customers and the confidentiality of your work on their behalf. Set and meet expectations/timeline and communicate status with the customer as it is better to under-promise and over-deliver than vice versa. Offer different repair/replacement options if applicable so customers will buy into the solution and be informed of potential outcomes and how they can be influenced. Provide proper documentation on the services provided so you get credit for your work, the customer has a receipt for tax purposes and for future reference. Follow up with customer/user at a later date to verify satisfaction. This shows that you care about the customer and it may help you get additional business. Deal appropriately with the customer's confidential and private materials that may be located on a computer, desktop, printer, etc. This helps build trust with the customer. Follow up with customer/user at a later date to verify satisfaction. This shows that you care about the customer and it may help you get additional business. Deal appropriately with the customer's confidential and private materials that may be located on a computer, desktop, printer, etc. This helps build trust with the customer. 4.8 Identify the basics of scripting. Script file types .bat Windows batch file this is a file with instructions created in it that will execute. .ps1 PowerShell This will allow you to administrate and manage the task in windows. .vbs VBScript is an Active Scripting language developed by Microsoft that is modeled on Visual Basic. .sh Linux shell script Shell is a program used in Linux which interprets user commands. .py Python is a general-purpose scripting language which to create many different applications. .js JavaScript is mainly on websites and where interactive webbased content along with applications is created Environment variables are the storage location within the systems command shell. Comment syntax the comment in the code help the developer with maintaining the code, as the system ignores the comment line. Basic script constructs for a developer to write a script he needs to fully understand the structure and the syntax of the language Basic loops Scripts have more than one statement and get processed from top to bottom. The scripts normally are created for complex tasks thereby running a few loops. Variables a variable is a value that can change, depending on conditions. In Linux, this can be configured using the ser command. Basic data types are important because they will determine what sort of operations can be performed. Integers These are all whole numbers. Integers are a commonly used data type in computer programming. Strings This is a collection of text characters. There is also no limit for space. 4.9 Given a scenario, use remote access technologies. RDP Remote Desktop Protocol (RDP) is a protocol that is used by Administrators who need to connect to users for configuration and repairs and port number 3389. Telnet terminal emulator allows you to connect a computer insecurely. HTTPS/management URL This concept is that administrators will log into a switch securely via the Internet. SSH Secure Shell is a network protocol is used to make connections secure due to the Telnet sending password and username in clear text Third-party tools there is a product VNC virtual Network Computing that can be used. Screen share feature Any client which is VNC can connect to a screen sharing server. File share is complex you need to configure permissions on the share for the client and the server recognize. Security considerations of each access method. These access methods are not sure and should be done via a VPN which is secure.
0
You can add this document to your study collection(s)
Sign in Available only to authorized usersYou can add this document to your saved list
Sign in Available only to authorized users(For complaints, use another form )