Cybersecurity Professional PenTester - Cybersecurity Analysis
Cybersecurity Professional PenTester - Scripting Foundations
Cybersecurity Professional PenTester - Pentesting and Exploitation
Cybersecurity Core Technical - Information Security
On-the-job training
Assists in developing security policies and protocols; assists in enforcing company compliance with network security policies and protocols
Basic - Locates (in Intranet, employee handbook or security protocols) organizational policies intended to maintain security and minimize risk and explains their use
Advanced - Provides guidance to employees on how to access networks, set passwords, reduce security threats and provide defensive measures associated with searches, software downloads, email, Internet, add-ons, software coding and transferred files
Basic - Ensures that password characteristics are explained and enforced and that updates are required and enforced based on appropriate time intervals
Intermediate - Explains company or organization's policies regarding the storage, use and transfer of sensitive data, including intellectual property and personally identifiable information. Identifies data life cycle, data storage facilities, technologie
Advanced - Assigns individuals to the appropriate permission or access level to control access to certain web IP addresses, information and the ability to download programs and transfer data to various locations
Intermediate - Assists employees in the use of technologies that restrict or allow for remote access to the organization's information technology network
Advanced - Develops security compliance policies and protocols for external services (i.e. Cloud service providers, software services, external data centers)
Advanced - Complies with incident response and handling methodologies
Intermediate - Articulates the business need or mission of the organization as it pertains to the use of IT systems and the storage of sensitive data
Provides technical support to users or customers
Basic - Manages inventory of IT resources
Intermediate - Diagnoses and resolves customer-reported system incidents
Basic - Installs and configures hardware, software and peripheral equipment for system users
Basic - Monitors client-level computer system performance
Basic - Tests computer system performance
Basic - Troubleshoots system hardware and software
Intermediate - Administers accounts, network rights, and access to systems and equipment
Advanced - Implements security measures for uses in system and ensures that system designs incorporate security configuration guidelines
Installs, configures, tests, operates, maintains and manages networks and their firewalls including hardware and software that permit sharing and transmission of information
Intermediate - Collaborates with system developers and users to assist in the selection of appropriate design solutions to ensure the compatibility of system components
Advanced - Installs, replaces, configures and optimizes network hubs, routers and switches
Intermediate - Assists in network backup and recovery procedures
Basic - Diagnoses network connectivity problems
Advanced - Modifies network infrastructure to serve new purposes or improve workflow
Intermediate - Integrates new systems into existing network architecture
Intermediate - Patches network vulnerabilities to ensure information is safeguarded against outside parties
Basic - Repairs network connectivity problems
Basic - Tests and maintains network infrastructure including software and hardware devices
Intermediate - Establishes adequate access controls based on principles of least privilege and need-to- know
Basic - Implements security measures for users in system and ensures that system designs incorporate security configuration guidelines
Installs, configures, troubleshoots and maintains server configurations to ensure their confidentiality, integrity and availability; also manages accounts, firewalls, configuration, patch and vulnerability management. Is responsible for access control, se
Intermediate - Checks system hardware availability, functionality, integrity and efficiency
Basic - Conducts functional and connectivity testing to ensure continuing operability
Basic - Conducts periodic server maintenance including cleaning (physically and electronically), disk checks, system configuration and monitoring, data downloads, backups and testing
Advanced - Assists in the development of group policies and access control lists to ensure compatibility with organizational standards, business rules and needs
Intermediate - Documents compliance with or changes to system administration standard operating procedures
Intermediate - Installs server fixes, updates and enhancements
Intermediate - Maintains baseline system security according to organizational policies
Basic - Manages accounts, network rights and access to systems and equipment
Intermediate - Monitors and maintains server configuration
Basic - Supports network components
Basic - Diagnoses faulty system/server hardware; seeks appropriate support or assistance to perform server repairs
Intermediate - Verifies data redundancy and system recovery procedures
Intermediate - Assists in the coordination or installation of new or modified hardware, operating systems and other baseline software
Intermediate - Provides ongoing optimization and problem-solving support
Basic - Resolves hardware/software interface and interoperability problems
Advanced - Establishes adequate access controls based on principles of least privilege, role based access controls (RBAC) and need- to-know
Configures tools and technologies to detect, mitigate and prevent potential threats
Intermediate - Installs and maintains cyber security detection, monitoring and threat management software
Intermediate - Coordinates with network administrators to administer the updating of rules and signatures for intrusion/detection protection systems, anti-virus and network black and white list
Intermediate - Manages IP addresses based on current threat environment
Basic - Ensures application of security patches for commercial products integrated into system design
Assesses and mitigates system network, business continuity and related security risks and vulnerabilities
Intermediate - Applies security policies to meet security objectives of the system
Intermediate - Performs system administration to ensure current defense applications are in place, including on Virtual Private Network devices
Basic - Ensures that data back up and restoration systems are functional and consistent with company's document retention policy and business continuity needs
Advanced - Identifies potential conflicts with implementation of any computer network defense tools. Performs tool signature testing and optimization
Advanced - Installs, manages and updates intrusion detection system
Advanced - Performs technical and non-technical risk and vulnerability assessments of relevant technology focus areas
Intermediate - Conducts authorized penetration testing (Wi- Fi, network perimeter, application security, cloud, mobile devices) and assesses results
Intermediate -Documents systems security operations and maintenance activities
Advanced - Communicates potential risks or vulnerabilities to manager. Collaborates with others to recommend vulnerability corrections
Advanced - Identifies information technology security program implications of new technologies or technology upgrades
Reviews network utilization data to identify unusual patterns, suspicious activity or signs of potential threats
Basic - Identifies organizational trends with regard to the security posture of systems; identifies unusual patterns or activities
Advanced - Characterizes and analyzes network traffic to identify anomalous activity and potential threats; performs computer network defense trend analysis and reporting
Advanced - Receives and analyzes network alerts from various sources within the enterprise and determines possible causes of such alerts
Advanced - Runs tests to detect real or potential threats, viruses, malware, etc.
Intermediate - Assists in researching cost-effective security controls to mitigate risks
Advanced - Helps perform damage assessments in the event of an attack
Advanced - Monitors network data to identify unusual activity, trends, unauthorized devices or other potential vulnerabilities
Intermediate - Documents and escalates incidents that may cause immediate or long-term impact to the environment
Advanced - Provides timely detection, identification and alerts of possible attacks and intrusions, anomalous activities, and distinguish these incidents and events from normal baseline activities
Advanced - Uses network monitoring tools to capture and analyze network traffic associated with malicious activity
Advanced - Performs intrusion analysis
Intermediate - Sets containment blockers to align with company policy regarding computer use and web access
Responds to cyber intrusions and attacks and provides defensive strategies
Advanced - Assists in the development of appropriate courses of action in response to identified anomalous network activity
Advanced - Triages systems operations impact: malware, worms, man-in-the-middle attack, denial of service, rootkits, keystroke loggers, SQL injection and cross-site scripting
Advanced - Reconstructs a malicious attack or activity based on network traffic
Advanced - Correlates incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation
Advanced - Monitors external data sources to maintain currency of Computer Network Defense threat condition and determines which security issues may have an impact on the enterprise. Performs file signature analysis
Advanced - Performs analysis of log files from a variety of sources to identify threats to network security; performs file signature analysis
Advanced - Performs computer network defense incident triage to include determining scope, urgency and potential impact; identifies the specific vulnerability; provides training recommendations; and makes recommendations that enable expeditious remediatio
Advanced - Receives and analyzes network alerts from various sources within the enterprise and determines possible causes of such alerts
Intermediate - Tracks and documents computer network defense incidents from initial detection through final resolution
Advanced - Collects intrusion artifacts and uses discovered data to enable mitigation of potential computer network defense (CND) incidents
Basic - Performs virus scanning on digital media
Interested in this apprenticeship?
Sign up to receive notifications about changes and updates about Cyber Security Support Technician.