4.1.C.1Adversaries can develop exploits for known vulnerabilities in software (including operating systems). Devices with unpatched software are vulnerable to these exploits, which could allow an adversary to crash a system, view…Learning objective: Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.
4.2.C.1Authentication mechanisms are technical controls that verify the identity of a user to ensure that only authorized users access a system. The proof the user provides to identify themselves is called a factor. Common…Learning objective: Determine the type of authentication used to verify the identity of a user.
4.3.C.2Ensuring that a computer’s operating system and software applications are updated to the most recent version prevents adversaries from taking advantage of a known vulnerability.Learning objective: Explain why keeping a device’s operating system and software updated makes it more secure.
AP Networking alignment
1.4.B.3To prevent exploitation of known vulnerabilities that can lead to device compromise or data loss, users should keep all software and firmware current. Software refers to applications and operating systems, while firmware is…Learning objective: Implement device- and account-level security practices to prevent phishing, credential compromise, and data loss.
2.5.A.2Unauthorized access to a network can allow an adversary to change network configurations or disable security controls. This can occur when routers and access points use default usernames, passwords, or settings that are widely…Learning objective: Identify impacts of potential security vulnerabilities in a SOHO network.
4.5.A.3Widespread data compromise, service outages, or loss of administrative control can occur when an adversary or malicious software moves laterally across a network. These impacts are more likely in segmented or large networks…Learning objective: Identify the impacts of common threats and vulnerabilities in a managed network.