1
1

00:00:00,240  -->  00:00:02,820
<v Instructor>Training and exercises.</v>
2

2

00:00:02,820  -->  00:00:05,370
Earlier in the course, we talked a little bit about training
3

3

00:00:05,370  -->  00:00:08,250
and exercises, so some of this will be a review.
4

4

00:00:08,250  -->  00:00:10,500
We're going to talk about tabletop exercises,
5

5

00:00:10,500  -->  00:00:14,070
penetration testing, and red, blue, and white exercises
6

6

00:00:14,070  -->  00:00:15,270
in this lesson.
7

7

00:00:15,270  -->  00:00:16,830
We are going to have some new information
8

8

00:00:16,830  -->  00:00:20,250
so please don't just skip ahead and watch this entire video.
9

9

00:00:20,250  -->  00:00:22,170
Now, when we talk about tabletop exercises,
10

10

00:00:22,170  -->  00:00:23,010
we mentioned before
11

11

00:00:23,010  -->  00:00:25,800
that these are exercises that use an incident scenario
12

12

00:00:25,800  -->  00:00:28,560
against a framework of controls or a red team.
13

13

00:00:28,560  -->  00:00:30,450
So what we're going to do here is we are going to
14

14

00:00:30,450  -->  00:00:33,720
carry a discussion of simulated emergency situations
15

15

00:00:33,720  -->  00:00:35,040
and security events.
16

16

00:00:35,040  -->  00:00:37,500
These are great because they're really simple to set up
17

17

00:00:37,500  -->  00:00:39,120
but they tend to be more theoretical
18

18

00:00:39,120  -->  00:00:41,460
in nature and they don't provide practical evidence
19

19

00:00:41,460  -->  00:00:43,800
of what could go wrong during a real event.
20

20

00:00:43,800  -->  00:00:44,633
For example,
21

21

00:00:44,633  -->  00:00:47,220
how long will a particular task take to complete?
22

22

00:00:47,220  -->  00:00:49,410
You really can't gather that from a tabletop,
23

23

00:00:49,410  -->  00:00:50,850
but if you actually go through the actions
24

24

00:00:50,850  -->  00:00:53,280
and motions in something like a penetration test,
25

25

00:00:53,280  -->  00:00:55,110
you'll be able to see that instead.
26

26

00:00:55,110  -->  00:00:55,943
Now, I've seen a lot
27

27

00:00:55,943  -->  00:00:57,990
of times when we're doing tabletop exercises
28

28

00:00:57,990  -->  00:01:00,300
that people start using their magic wands.
29

29

00:01:00,300  -->  00:01:01,920
Now, this is a bad thing to do
30

30

00:01:01,920  -->  00:01:03,430
because you can start getting the effect
31

31

00:01:03,430  -->  00:01:05,520
that something that might take a real team
32

32

00:01:05,520  -->  00:01:08,610
12 hours to do can really be solved in 30 minutes.
33

33

00:01:08,610  -->  00:01:10,440
And so when something really happens,
34

34

00:01:10,440  -->  00:01:12,750
the managers start going, well, in the tabletop,
35

35

00:01:12,750  -->  00:01:14,580
it only took us 30 minutes to solve.
36

36

00:01:14,580  -->  00:01:15,750
Why is it taking you 12 hours?
37

37

00:01:15,750  -->  00:01:17,520
I need this system up right now.
38

38

00:01:17,520  -->  00:01:19,500
And so you start getting this negative training, I call it,
39

39

00:01:19,500  -->  00:01:21,150
where you start training your senior leaders
40

40

00:01:21,150  -->  00:01:22,620
to expect things to happen faster
41

41

00:01:22,620  -->  00:01:24,420
in the real world than they really can.
42

42

00:01:24,420  -->  00:01:25,470
So just be careful about that
43

43

00:01:25,470  -->  00:01:27,930
if you're dealing with a tabletop exercise.
44

44

00:01:27,930  -->  00:01:29,760
Now, when you're dealing with a penetration test,
45

45

00:01:29,760  -->  00:01:31,529
this is a test that uses active tools
46

46

00:01:31,529  -->  00:01:34,470
and security utilities to evaluate security
47

47

00:01:34,470  -->  00:01:36,630
by simulating an attack on a system
48

48

00:01:36,630  -->  00:01:38,760
to verify that a threat really does exist.
49

49

00:01:38,760  -->  00:01:40,980
They actively test that threat and vulnerability.
50

50

00:01:40,980  -->  00:01:43,230
They bypass security controls and then finally
51

51

00:01:43,230  -->  00:01:46,260
exploit those vulnerabilities on a given system.
52

52

00:01:46,260  -->  00:01:48,000
When you're doing a penetration test,
53

53

00:01:48,000  -->  00:01:50,610
you are going to test the system to discover vulnerabilities
54

54

00:01:50,610  -->  00:01:52,710
or prove security controls are actually working
55

55

00:01:52,710  -->  00:01:53,820
as they're supposed to.
56

56

00:01:53,820  -->  00:01:55,380
You're also going to examine the system
57

57

00:01:55,380  -->  00:01:58,170
to identify any logical weaknesses that may be there
58

58

00:01:58,170  -->  00:01:59,970
inside the system architecture.
59

59

00:01:59,970  -->  00:02:02,520
And you're going to interview personnel to gather information
60

60

00:02:02,520  -->  00:02:05,400
and see how prone they are to social engineering attacks.
61

61

00:02:05,400  -->  00:02:06,480
All of these are things you can do
62

62

00:02:06,480  -->  00:02:08,460
as part of a penetration test.
63

63

00:02:08,460  -->  00:02:10,230
Now, when you're dealing with a penetration test,
64

64

00:02:10,230  -->  00:02:12,270
you have to make sure it is properly scoped
65

65

00:02:12,270  -->  00:02:14,700
and resourced before you can begin it.
66

66

00:02:14,700  -->  00:02:16,530
Now, what I mean by this is you have to figure out
67

67

00:02:16,530  -->  00:02:18,180
exactly what is going to be tested
68

68

00:02:18,180  -->  00:02:19,890
as part of the penetration test.
69

69

00:02:19,890  -->  00:02:22,020
If you get a penetration tester to come in
70

70

00:02:22,020  -->  00:02:23,400
and test your organization, you say,
71

71

00:02:23,400  -->  00:02:25,380
just go at the entire organization.
72

72

00:02:25,380  -->  00:02:27,120
That's not going to be very effective.
73

73

00:02:27,120  -->  00:02:29,580
Instead, you should tell them, hey, I'm really concerned
74

74

00:02:29,580  -->  00:02:31,020
about my Windows domain controller.
75

75

00:02:31,020  -->  00:02:33,720
I want you to see if you can get root access on that.
76

76

00:02:33,720  -->  00:02:35,520
And that would allow them to be able to identify
77

77

00:02:35,520  -->  00:02:37,170
exactly what your concerns are
78

78

00:02:37,170  -->  00:02:39,720
and verify your systems are working properly.
79

79

00:02:39,720  -->  00:02:41,700
Now, when you're dealing with a penetration test,
80

80

00:02:41,700  -->  00:02:44,850
you can use either an internal team or an external team.
81

81

00:02:44,850  -->  00:02:47,310
I personally like to use third parties who are external
82

82

00:02:47,310  -->  00:02:50,490
to the organization or a separate internal red team.
83

83

00:02:50,490  -->  00:02:52,350
I don't like to use my system administrators
84

84

00:02:52,350  -->  00:02:54,000
to conduct penetration tests.
85

85

00:02:54,000  -->  00:02:56,130
It's not that they're not smart enough to do it,
86

86

00:02:56,130  -->  00:02:57,930
it's that they're biased in their approach.
87

87

00:02:57,930  -->  00:02:59,070
When you have a system administrator
88

88

00:02:59,070  -->  00:03:00,900
trying to pen test their own system,
89

89

00:03:00,900  -->  00:03:03,180
what ends up happening is they start trying to
90

90

00:03:03,180  -->  00:03:04,950
prove the system is secure
91

91

00:03:04,950  -->  00:03:07,770
instead of trying to prove the system can be attacked.
92

92

00:03:07,770  -->  00:03:11,220
As a penetration tester, our job is to be the bad guy.
93

93

00:03:11,220  -->  00:03:13,260
It's to go in and find all the holes.
94

94

00:03:13,260  -->  00:03:14,910
We want to find all the weaknesses,
95

95

00:03:14,910  -->  00:03:17,700
and the system administrators tend to try to not do that
96

96

00:03:17,700  -->  00:03:19,200
because they're trying to prove that their work
97

97

00:03:19,200  -->  00:03:21,960
that they did securing the system is adequate.
98

98

00:03:21,960  -->  00:03:23,190
And so it's a different perspective,
99

99

00:03:23,190  -->  00:03:25,350
and that's why I much prefer a third party
100

100

00:03:25,350  -->  00:03:27,360
or an internal red team be used
101

101

00:03:27,360  -->  00:03:29,220
instead of system administrators.
102

102

00:03:29,220  -->  00:03:31,110
Now, if you want to learn more about pen testing,
103

103

00:03:31,110  -->  00:03:32,970
as I said before, you should check out
104

104

00:03:32,970  -->  00:03:35,100
the CompTIA Pen Test+ curriculum.
105

105

00:03:35,100  -->  00:03:37,050
In that course, there is a ton of information
106

106

00:03:37,050  -->  00:03:38,160
on how you can become a member
107

107

00:03:38,160  -->  00:03:40,650
of the penetration testing team and learning how
108

108

00:03:40,650  -->  00:03:44,220
to attack these systems from that outsider perspective.
109

109

00:03:44,220  -->  00:03:45,870
Now, the last thing we want to talk about in this lesson
110

110

00:03:45,870  -->  00:03:48,900
is our red teams, our blue teams, and our white teams.
111

111

00:03:48,900  -->  00:03:50,160
When we talk about red teams,
112

112

00:03:50,160  -->  00:03:52,080
these are the hostile or attacking teams
113

113

00:03:52,080  -->  00:03:55,230
in a penetration test or an instant response exercise.
114

114

00:03:55,230  -->  00:03:58,680
If you hire that third party team, that is a red team.
115

115

00:03:58,680  -->  00:04:00,750
They're trying to attack your systems.
116

116

00:04:00,750  -->  00:04:01,950
When we're talking about blue teams,
117

117

00:04:01,950  -->  00:04:03,330
this is our defensive teams
118

118

00:04:03,330  -->  00:04:06,390
in a penetration test or an incident response exercise.
119

119

00:04:06,390  -->  00:04:07,980
This is our system administrators,
120

120

00:04:07,980  -->  00:04:09,690
this is our network defenders,
121

121

00:04:09,690  -->  00:04:12,480
this is our cybersecurity analysts like you.
122

122

00:04:12,480  -->  00:04:14,550
You're going to be part of the blue team.
123

123

00:04:14,550  -->  00:04:15,990
And then we have the white team.
124

124

00:04:15,990  -->  00:04:18,240
This is a staff who administers, evaluates,
125

125

00:04:18,240  -->  00:04:20,310
and supervises a penetration test
126

126

00:04:20,310  -->  00:04:22,140
or instant response exercise.
127

127

00:04:22,140  -->  00:04:24,300
They're also going to be responsible for building the network
128

128

00:04:24,300  -->  00:04:26,280
if you're going to be using a third party network
129

129

00:04:26,280  -->  00:04:27,600
as part of your test.
130

130

00:04:27,600  -->  00:04:30,270
Sometimes organizations don't want to do active testing
131

131

00:04:30,270  -->  00:04:31,830
on their real live networks,
132

132

00:04:31,830  -->  00:04:33,210
so they'll build a training ground
133

133

00:04:33,210  -->  00:04:34,950
and they'll put their red teams and their blue teams
134

134

00:04:34,950  -->  00:04:37,230
if they have internal red teams and internal blue teams
135

135

00:04:37,230  -->  00:04:39,480
against each other in this simulated environment.
136

136

00:04:39,480  -->  00:04:41,220
Well, somebody has to build
137

137

00:04:41,220  -->  00:04:42,990
and support this entire ecosystem,
138

138

00:04:42,990  -->  00:04:44,790
and that's what the white team will do.
139

139

00:04:44,790  -->  00:04:47,160
I like to think about the white team as the referees.
140

140

00:04:47,160  -->  00:04:48,720
They're also going to be the ones who are going to report
141

141

00:04:48,720  -->  00:04:51,570
after the event and say, this is what the red team did well,
142

142

00:04:51,570  -->  00:04:52,890
this is what the blue team did well,
143

143

00:04:52,890  -->  00:04:54,810
and here's what they both did not so well.
144

144

00:04:54,810  -->  00:04:56,510
That's the role of the white team.
