1
00:00:06,510 --> 00:00:09,780
- Welcome to lesson 14, deep dive quiz.

2
00:00:09,780 --> 00:00:12,840
Now, lesson 14 was all
about given a scenario,

3
00:00:12,840 --> 00:00:16,500
apply common security techniques
to computing resources.

4
00:00:16,500 --> 00:00:19,080
So we looked at a lot
of different scenarios.

5
00:00:19,080 --> 00:00:22,770
In 14 1, we looked at secure
baseline and hardening targets,

6
00:00:22,770 --> 00:00:25,440
in 14 2, wireless configurations,

7
00:00:25,440 --> 00:00:30,440
in 14 3, wireless design, in
14 4, mobile connectivity,

8
00:00:30,870 --> 00:00:33,870
in 14 5, mobile device management,

9
00:00:33,870 --> 00:00:38,870
in 14 6, application security
and in 14 7, secure coding.

10
00:00:39,570 --> 00:00:41,340
So you ready for 10 questions?

11
00:00:41,340 --> 00:00:43,470
Alright, let's do it.

12
00:00:43,470 --> 00:00:45,300
Oh, do I need to remind
you again to make sure

13
00:00:45,300 --> 00:00:48,390
you have a pencil and a
pen or a piece of paper?

14
00:00:48,390 --> 00:00:49,680
I really want you to do that

15
00:00:49,680 --> 00:00:52,050
'cause I want you to
keep putting me on pause

16
00:00:52,050 --> 00:00:53,943
and answer these questions.

17
00:00:56,430 --> 00:00:57,750
In mobile device management,

18
00:00:57,750 --> 00:01:01,890
what's the primary uses
for geofencing technology?

19
00:01:01,890 --> 00:01:03,780
Choose as many as apply.

20
00:01:03,780 --> 00:01:05,880
To enforce DLP policies,

21
00:01:05,880 --> 00:01:08,550
to require biometric authentication,

22
00:01:08,550 --> 00:01:11,280
to segregate high risk applications,

23
00:01:11,280 --> 00:01:14,850
to identify when a device
enters a secure area

24
00:01:14,850 --> 00:01:18,510
or to define where devices can be used.

25
00:01:18,510 --> 00:01:21,420
So primary uses for geofencing technology.

26
00:01:21,420 --> 00:01:22,270
What do you like?

27
00:01:25,080 --> 00:01:26,280
Are you ready?

28
00:01:26,280 --> 00:01:28,470
I'm gonna choose to identify when a device

29
00:01:28,470 --> 00:01:29,640
enters a secure area

30
00:01:29,640 --> 00:01:32,670
because we could put a
geofence around an area

31
00:01:32,670 --> 00:01:35,403
and maybe that device can't
even be used in that area.

32
00:01:36,240 --> 00:01:40,200
Or define where devices
can or cannot be used.

33
00:01:40,200 --> 00:01:43,500
So that geofence right, just
says, here's a boundary.

34
00:01:43,500 --> 00:01:46,413
So we wanna do things
that are boundary driven.

35
00:01:47,455 --> 00:01:48,720
You like it?

36
00:01:48,720 --> 00:01:50,250
Alright, let's check.

37
00:01:50,250 --> 00:01:51,363
And that's correct.

38
00:01:53,520 --> 00:01:54,690
Alright, wireless protocol

39
00:01:54,690 --> 00:01:57,000
that uses simultaneous authentication

40
00:01:57,000 --> 00:02:00,840
of equals or SAE for authentication.

41
00:02:00,840 --> 00:02:05,400
This is WPA, WEP, WPA3

42
00:02:05,400 --> 00:02:07,293
or WPA2.

43
00:02:08,370 --> 00:02:10,263
This one's also called dragonfly.

44
00:02:11,430 --> 00:02:12,840
I know you're gonna get
this one right away.

45
00:02:12,840 --> 00:02:14,404
What is it?

46
00:02:14,404 --> 00:02:16,770
It is our newest one.

47
00:02:16,770 --> 00:02:18,030
WPA3.

48
00:02:18,030 --> 00:02:19,080
Agree?

49
00:02:19,080 --> 00:02:20,610
Alright, let's try it.

50
00:02:20,610 --> 00:02:21,663
And that's correct.

51
00:02:24,060 --> 00:02:26,490
A collaborative approach
that proactively focuses

52
00:02:26,490 --> 00:02:30,870
on survivability by
providing reliable software

53
00:02:30,870 --> 00:02:34,230
with a reduced attack service
coupled with automated,

54
00:02:34,230 --> 00:02:38,010
continuous and integrated
security testing.

55
00:02:38,010 --> 00:02:42,060
Is this SecDevOps, an
integrated product team,

56
00:02:42,060 --> 00:02:46,050
continuous integration or DevOps.

57
00:02:46,050 --> 00:02:49,650
So keywords here, it's a
collaborative approach, right?

58
00:02:49,650 --> 00:02:53,283
Focuses on survivability,
reliable software.

59
00:02:54,720 --> 00:02:55,683
What do you think?

60
00:02:58,260 --> 00:03:02,670
Well, DevOps would only be
developers and operations folks.

61
00:03:02,670 --> 00:03:04,470
That's a nice collaboration.

62
00:03:04,470 --> 00:03:06,420
But that leaves us out
of the picture, right?

63
00:03:06,420 --> 00:03:07,680
No security.

64
00:03:07,680 --> 00:03:08,850
Continuous integration.

65
00:03:08,850 --> 00:03:10,260
We said that that's when developers

66
00:03:10,260 --> 00:03:13,650
are all putting their code
into a shared mainline.

67
00:03:13,650 --> 00:03:14,550
And if a fault

68
00:03:14,550 --> 00:03:17,430
or a bug or a problem is
found, everything stops.

69
00:03:17,430 --> 00:03:19,920
It gets fixed before we go on.

70
00:03:19,920 --> 00:03:21,600
An integrated product team.

71
00:03:21,600 --> 00:03:24,060
It's again a multidisciplinary team.

72
00:03:24,060 --> 00:03:27,840
But what we were really
looking for here was SecDevOps,

73
00:03:27,840 --> 00:03:30,990
a collaboration between
security, development

74
00:03:30,990 --> 00:03:32,550
and operations.

75
00:03:32,550 --> 00:03:33,630
You like that one?

76
00:03:33,630 --> 00:03:35,190
Alright, let's try it.

77
00:03:35,190 --> 00:03:36,990
And it is correct.

78
00:03:36,990 --> 00:03:40,230
So question four, here we're
gonna match the specifications

79
00:03:40,230 --> 00:03:41,970
and the descriptions.

80
00:03:41,970 --> 00:03:45,120
On the left hand side,
we have Wi-Fi, Bluetooth,

81
00:03:45,120 --> 00:03:49,200
NFC, RFID, and cellular.

82
00:03:49,200 --> 00:03:50,130
On the right hand side

83
00:03:50,130 --> 00:03:52,350
we have radio frequency
distributed network,

84
00:03:52,350 --> 00:03:55,980
short wave network, radio
frequency identification,

85
00:03:55,980 --> 00:03:58,260
radio frequency contained network

86
00:03:58,260 --> 00:04:02,070
and a short range wireless communication.

87
00:04:02,070 --> 00:04:04,050
It's a great time to put me on pause.

88
00:04:04,050 --> 00:04:07,050
Right, take your time, match
these up and then come on back.

89
00:04:08,070 --> 00:04:10,950
Alright, so starting up
here on top with Wi-Fi.

90
00:04:10,950 --> 00:04:14,703
Wi-Fi is a radio frequency
contained network.

91
00:04:16,650 --> 00:04:17,820
So what's cellular?

92
00:04:17,820 --> 00:04:21,603
Cellular is a radio frequency
distributed network.

93
00:04:22,920 --> 00:04:27,270
NFC is going to be our short
range wireless communication.

94
00:04:27,270 --> 00:04:28,950
Remember, it's only very short range,

95
00:04:28,950 --> 00:04:31,410
maybe six eight inches.

96
00:04:31,410 --> 00:04:34,500
Bluetooth is going to
be a shortwave network.

97
00:04:34,500 --> 00:04:36,390
And RFID, well that one's easy.

98
00:04:36,390 --> 00:04:38,820
It stands for radio frequency ID.

99
00:04:38,820 --> 00:04:41,880
So RFID, radio frequency ID.

100
00:04:41,880 --> 00:04:45,420
So Wi-Fi, a radio frequency
contained network, Bluetooth,

101
00:04:45,420 --> 00:04:48,870
a shortwave network, NFC
or nearfield communication,

102
00:04:48,870 --> 00:04:51,690
a short range wireless communication,

103
00:04:51,690 --> 00:04:55,650
RFID, radio frequency
identification and cellular

104
00:04:55,650 --> 00:04:58,440
which is a radio frequency
distributed network.

105
00:04:58,440 --> 00:04:59,700
You agree?

106
00:04:59,700 --> 00:05:01,770
Alright, let's check it out.

107
00:05:01,770 --> 00:05:03,660
Yay. We're correct, good work.

108
00:05:03,660 --> 00:05:05,400
Let's move on.

109
00:05:05,400 --> 00:05:07,170
Alright, number five.

110
00:05:07,170 --> 00:05:09,570
This is the environment
that should mirror PROD.

111
00:05:09,570 --> 00:05:13,830
POST-PROD, DEV, TEST or STAGE.

112
00:05:13,830 --> 00:05:14,910
Remember, this is the environment

113
00:05:14,910 --> 00:05:16,500
where we're gonna do risk assessments,

114
00:05:16,500 --> 00:05:19,320
penetration testing,
vulnerability assessments.

115
00:05:19,320 --> 00:05:21,243
It should mirror the PROD environment.

116
00:05:22,080 --> 00:05:25,260
POST-PROD, DEV, TEST or STAGE.

117
00:05:25,260 --> 00:05:26,110
What do you like?

118
00:05:27,840 --> 00:05:30,120
I'm gonna choose stage because staging

119
00:05:30,120 --> 00:05:33,120
is the environment that should
mirror the prod environment.

120
00:05:33,120 --> 00:05:35,400
Post-prod, that's just
a made up term, right?

121
00:05:35,400 --> 00:05:38,220
Dev is really the first
in our four stages.

122
00:05:38,220 --> 00:05:41,160
That's development
followed by test, right?

123
00:05:41,160 --> 00:05:42,360
So the staging environment

124
00:05:42,360 --> 00:05:44,250
should mirror the prod environment.

125
00:05:44,250 --> 00:05:46,503
Let's check and that's correct.

126
00:05:48,900 --> 00:05:53,900
Question six, which statement
is not true about DAST?

127
00:05:54,120 --> 00:05:55,320
Again, not right.

128
00:05:55,320 --> 00:05:58,380
So three of these statements
are true, one is not.

129
00:05:58,380 --> 00:06:00,060
DAST examines running code.

130
00:06:00,060 --> 00:06:03,990
DAST scans pre-compiled code.

131
00:06:03,990 --> 00:06:07,620
DAST tools include
fuzzing and API scanning

132
00:06:07,620 --> 00:06:11,310
or DAST simulates automated attacks.

133
00:06:11,310 --> 00:06:13,590
Again, three of those are true statements

134
00:06:13,590 --> 00:06:15,480
but one of those is not.

135
00:06:15,480 --> 00:06:16,950
Take your time, read through them.

136
00:06:16,950 --> 00:06:18,500
Put me on pause if you need to.

137
00:06:22,290 --> 00:06:27,290
I'm gonna choose DAST
scans pre-compiled code.

138
00:06:27,810 --> 00:06:30,990
Because DAST, our dynamic security testing

139
00:06:30,990 --> 00:06:33,120
doesn't look at pre-compiled code.

140
00:06:33,120 --> 00:06:35,040
It looks like code after it's been piled.

141
00:06:35,040 --> 00:06:37,800
It looks like it looks at
running application code.

142
00:06:37,800 --> 00:06:40,440
So it's true that examines running code.

143
00:06:40,440 --> 00:06:44,700
It's true that DAST tools
include fuzzing and API scanning.

144
00:06:44,700 --> 00:06:48,840
And it is true that DAST
simulates automated attacks

145
00:06:48,840 --> 00:06:52,680
but it's not true that it
scans our pre-compiled code.

146
00:06:52,680 --> 00:06:54,030
Let's double check.

147
00:06:54,030 --> 00:06:56,583
See if you agree and that's correct.

148
00:06:57,870 --> 00:06:59,520
Alright, number seven.

149
00:06:59,520 --> 00:07:01,080
This is an authentication service

150
00:07:01,080 --> 00:07:05,340
that can provide centralized
authentication, authorization

151
00:07:05,340 --> 00:07:07,833
and accounting for wireless clients.

152
00:07:08,820 --> 00:07:13,813
So all three AAA, radius,
EAP, NTLM, or MS-CHAP.

153
00:07:18,360 --> 00:07:22,770
Now all of them are authentication
protocols, but only one

154
00:07:22,770 --> 00:07:25,020
of them is actually an
authentication service

155
00:07:25,020 --> 00:07:27,750
that can provide the AAA authentication,

156
00:07:27,750 --> 00:07:30,180
authorization and accounting.

157
00:07:30,180 --> 00:07:31,530
Which one is it?

158
00:07:31,530 --> 00:07:32,490
Take your time.

159
00:07:32,490 --> 00:07:34,040
Put me on pause if you need to.

160
00:07:35,370 --> 00:07:38,310
I'm gonna choose radius.

161
00:07:38,310 --> 00:07:39,143
You agree?

162
00:07:39,143 --> 00:07:40,500
Alright, let's check it out.

163
00:07:40,500 --> 00:07:42,270
And that is correct.

164
00:07:42,270 --> 00:07:44,010
EAP is a protocol.

165
00:07:44,010 --> 00:07:46,260
Matter of fact, there's
about 43 versions right now

166
00:07:46,260 --> 00:07:48,840
of EAP, extensible authentication protocol

167
00:07:48,840 --> 00:07:50,850
that's often used in
the wireless environment

168
00:07:50,850 --> 00:07:53,400
but it's only an authentication protocol.

169
00:07:53,400 --> 00:07:57,543
NTLM is an authentication
protocol as is MS-CHAP.

170
00:07:59,790 --> 00:08:02,190
A component of WPA3 that ensures

171
00:08:02,190 --> 00:08:04,440
that if a private key is compromised,

172
00:08:04,440 --> 00:08:07,980
all previous uses of
the key remains secure.

173
00:08:07,980 --> 00:08:12,030
It says SAE, simultaneous
authentication of equals,

174
00:08:12,030 --> 00:08:15,840
forward secrecy, the
dragonfly key exchange

175
00:08:15,840 --> 00:08:18,213
or Wi-Fi protected setup.

176
00:08:20,130 --> 00:08:23,010
So we're saying here that if
a private key is compromised,

177
00:08:23,010 --> 00:08:26,310
all previous uses of
the key remains secure.

178
00:08:26,310 --> 00:08:30,090
SAE, simultaneous authentication
of equals, forward secrecy,

179
00:08:30,090 --> 00:08:33,030
sometimes referred to as
perfect forward secrecy,

180
00:08:33,030 --> 00:08:36,933
the dragonfly key exchange
or Wi-Fi protected setup.

181
00:08:38,250 --> 00:08:41,313
Take your time, put me
on pause if you need to.

182
00:08:42,720 --> 00:08:44,880
I'm gonna choose forward secrecy.

183
00:08:44,880 --> 00:08:47,310
That's a component of WPA3 that ensures

184
00:08:47,310 --> 00:08:49,290
that if a private key is compromised,

185
00:08:49,290 --> 00:08:52,500
all previous uses of
the key remain secure.

186
00:08:52,500 --> 00:08:54,390
SAE, simultaneous authentication

187
00:08:54,390 --> 00:08:58,500
of equals is the authentication
method often referred to

188
00:08:58,500 --> 00:09:00,810
as dragonfly because it has what's known

189
00:09:00,810 --> 00:09:02,580
as the dragonfly key exchange.

190
00:09:02,580 --> 00:09:05,970
And WPS, Wi-Fi protected
setup is just what allows us

191
00:09:05,970 --> 00:09:08,160
to connect to a wireless network

192
00:09:08,160 --> 00:09:12,063
by being in close proximity
to the wireless router.

193
00:09:12,930 --> 00:09:15,993
So let's double check and it is correct.

194
00:09:18,000 --> 00:09:21,630
Number nine, it's the principle
that unnecessary services

195
00:09:21,630 --> 00:09:25,320
and applications should
be removed or disabled.

196
00:09:25,320 --> 00:09:30,120
Is this hardening, least
functionality, least privilege

197
00:09:30,120 --> 00:09:32,580
or zero trust?

198
00:09:32,580 --> 00:09:33,420
Hmm.

199
00:09:33,420 --> 00:09:36,330
So it may look like there's
more than one answer

200
00:09:36,330 --> 00:09:37,950
but we're trying to be
really specific here.

201
00:09:37,950 --> 00:09:40,500
It's a principle that unnecessary services

202
00:09:40,500 --> 00:09:42,840
and applications should be removed.

203
00:09:42,840 --> 00:09:43,920
So what do you like?

204
00:09:43,920 --> 00:09:46,170
Hardening, least
functionality, least privilege

205
00:09:46,170 --> 00:09:47,763
or zero trust?

206
00:09:49,770 --> 00:09:52,560
I'm gonna choose least functionality

207
00:09:52,560 --> 00:09:54,480
because least functionality
is our principle

208
00:09:54,480 --> 00:09:56,190
that all unnecessary services

209
00:09:56,190 --> 00:09:58,560
and applications should
be removed or disabled

210
00:09:58,560 --> 00:10:02,250
that we wanna have as small
a footprint as possible.

211
00:10:02,250 --> 00:10:04,170
Now, least functionality is one

212
00:10:04,170 --> 00:10:07,080
of the things that we
do in hardening a system

213
00:10:07,080 --> 00:10:09,780
but hardening is a much more generic term.

214
00:10:09,780 --> 00:10:13,560
It talks about least
functionality and you know,

215
00:10:13,560 --> 00:10:16,440
really it also includes
things like least privilege

216
00:10:16,440 --> 00:10:18,540
and making sure that
we're doing our patches.

217
00:10:18,540 --> 00:10:20,460
So that's a very generic term

218
00:10:20,460 --> 00:10:23,640
where least functionality
is a specific principle.

219
00:10:23,640 --> 00:10:25,950
Least privilege refers to our subject

220
00:10:25,950 --> 00:10:28,590
or user saying that we're
gonna assign the least amount

221
00:10:28,590 --> 00:10:30,990
of rights and permissions
necessary to do a job.

222
00:10:30,990 --> 00:10:34,320
And zero trust means that
there is no trust whatsoever.

223
00:10:34,320 --> 00:10:35,490
That reauthentication

224
00:10:35,490 --> 00:10:38,520
and verification is continually required.

225
00:10:38,520 --> 00:10:42,540
So I'm going with least
functionality and that is correct.

226
00:10:42,540 --> 00:10:44,370
And we are at our 10th question.

227
00:10:44,370 --> 00:10:48,030
An organization issues
company-owned smartphones

228
00:10:48,030 --> 00:10:52,080
that employees can use both
professionally and personally.

229
00:10:52,080 --> 00:10:55,590
Which ownership model best
describes this scenario?

230
00:10:55,590 --> 00:10:58,290
COPE, CYOD,

231
00:10:58,290 --> 00:11:01,713
COBO, C O B O or BYOD.

232
00:11:06,840 --> 00:11:09,963
So which one of these best
describes the scenario?

233
00:11:12,690 --> 00:11:17,100
COPE, CYOD, COBO or BYOD?

234
00:11:17,100 --> 00:11:18,480
I'll help you out.

235
00:11:18,480 --> 00:11:22,020
COPE is company owned, personally enabled.

236
00:11:22,020 --> 00:11:26,550
CYOD is choose your own device

237
00:11:26,550 --> 00:11:29,280
which we didn't even talk about
'cause it's not very common.

238
00:11:29,280 --> 00:11:32,580
COBO is company owned, business only

239
00:11:32,580 --> 00:11:35,850
and BYOD is bring your own device.

240
00:11:35,850 --> 00:11:38,490
So now that you know that,
you must have the answer.

241
00:11:38,490 --> 00:11:39,810
The company owned smartphone

242
00:11:39,810 --> 00:11:42,873
that employees can use both
professionally and personally.

243
00:11:44,640 --> 00:11:49,050
Well, it must be company owned,
personally enabled or COPE.

244
00:11:49,050 --> 00:11:49,883
Agree?

245
00:11:49,883 --> 00:11:51,180
Let's check it if it is right,

246
00:11:51,180 --> 00:11:53,640
we've got a hundred and it is correct.

247
00:11:53,640 --> 00:11:55,470
Great job, congratulations.

248
00:11:55,470 --> 00:11:58,320
Alright, up next we're
gonna go into lesson 15

249
00:11:58,320 --> 00:12:00,270
to explain the security implications

250
00:12:00,270 --> 00:12:04,140
of proper hardware, software,
and data asset management.

251
00:12:04,140 --> 00:12:05,090
I'll see you there.
