1
1

00:00:00,000  -->  00:00:01,410
<v ->In this section of the course</v>
2

2

00:00:01,410  -->  00:00:03,900
we're going to cover mitigating vulnerabilities.
3

3

00:00:03,900  -->  00:00:06,210
Again, we're going to stay here in Domain 2,
4

4

00:00:06,210  -->  00:00:08,250
Vulnerability Management and Domain 4,
5

5

00:00:08,250  -->  00:00:09,600
Reporting and Communication
6

6

00:00:09,600  -->  00:00:11,160
during this section of the course
7

7

00:00:11,160  -->  00:00:15,480
it'll be focused on objectives 2.1, 2.5, and 4.1.
8

8

00:00:15,480  -->  00:00:17,100
Now, objective 2.1 states
9

9

00:00:17,100  -->  00:00:19,530
that given a scenario you must be able to implement
10

10

00:00:19,530  -->  00:00:22,110
vulnerability scanning methods and concepts.
11

11

00:00:22,110  -->  00:00:24,690
Objective, 2.5 states that you must be able to explain
12

12

00:00:24,690  -->  00:00:26,880
concepts related to vulnerability response,
13

13

00:00:26,880  -->  00:00:28,410
handling, and management.
14

14

00:00:28,410  -->  00:00:30,030
And objective 4.1 states
15

15

00:00:30,030  -->  00:00:31,740
that you must be able to explain the importance
16

16

00:00:31,740  -->  00:00:34,890
of vulnerability management, reporting, and communication.
17

17

00:00:34,890  -->  00:00:36,580
Now, as we begin to move through this section
18

18

00:00:36,580  -->  00:00:38,820
we're going to start out by discussing the remediation
19

19

00:00:38,820  -->  00:00:41,160
and mitigation plans for a given network
20

20

00:00:41,160  -->  00:00:42,840
and the concept of risk acceptance
21

21

00:00:42,840  -->  00:00:44,850
within your own organization.
22

22

00:00:44,850  -->  00:00:47,580
Then we'll discuss how to create a baseline configuration
23

23

00:00:47,580  -->  00:00:49,650
for your systems and your networks.
24

24

00:00:49,650  -->  00:00:52,050
Next, once we have that baseline created,
25

25

00:00:52,050  -->  00:00:53,580
we're also going to discuss the concept
26

26

00:00:53,580  -->  00:00:55,380
of system hardening and patching
27

27

00:00:55,380  -->  00:00:57,300
so that we can better understand how this applies
28

28

00:00:57,300  -->  00:00:59,010
to our networks as a whole.
29

29

00:00:59,010  -->  00:01:01,800
Then we'll describe the various inhibitors to remediation
30

30

00:01:01,800  -->  00:01:04,410
that you may be faced with inside of your organization
31

31

00:01:04,410  -->  00:01:05,850
whether those are technically based
32

32

00:01:05,850  -->  00:01:07,476
or organizational cultural issues
33

33

00:01:07,476  -->  00:01:09,570
that you're going to have to work through.
34

34

00:01:09,570  -->  00:01:11,490
We're also going to talk about the different outside forces
35

35

00:01:11,490  -->  00:01:13,920
that may impact you, such as regulations,
36

36

00:01:13,920  -->  00:01:15,990
because these may force you to remediate issues
37

37

00:01:15,990  -->  00:01:17,970
and vulnerabilities in certain ways
38

38

00:01:17,970  -->  00:01:20,610
due to the laws in your country or your region.
39

39

00:01:20,610  -->  00:01:22,410
Finally, we're going to take a short quiz
40

40

00:01:22,410  -->  00:01:24,510
to see what you learned during the section of the course
41

41

00:01:24,510  -->  00:01:26,550
and review each of those quiz questions fully
42

42

00:01:26,550  -->  00:01:27,450
to ensure you can explain
43

43

00:01:27,450  -->  00:01:29,490
why the correct answers were correct.
44

44

00:01:29,490  -->  00:01:32,250
So let's go ahead and get started mitigating vulnerabilities
45

45

00:01:32,250  -->  00:01:33,750
in this section of the course.
