Friday, August 9, 2024

Week 10 Posting - Cloud Automation

For the final week of class, we learned about cloud automation and using common terminology that are used in automation services and techniques. Refining documents and logs are important to keeping the network and system consistent and effective. It’s a good habit to update the number of resources being used and being contributed over time. That’s when managing the life cycle plays a crucial role in evolving the system and implement appropriate processes.

            During our reading, I learned five concepts of lifecycle management: roadmaps, version control, updates and upgrades, migrations, and deprecations (West, 2022, pp. 401-402). The roadmap provides a visual perspective of the resource’s life cycle. It outlines all significant phases and goes into detail of each stage. Version control leans more towards monitoring and keeping a look out on any level of changes done in the system. Updates and upgrades are related to patching, which eliminates any errors and add necessary features. Migration happens during growth. If the system grows, it will need to move to another location and hope that environment provides the nourishment it needs. Lastly, deprecations relate to resources that are out of date and are no longer available. It’s the professional’s job to evaluate the area and create a plan to proceed with new features.

            Blogging helps improve my writing skills and language usage. It allows me to be expressive and improve my craft. In addition, it helps build my brand of work and allow myself to be known to many professional companies. Blogging helps me in my current job by applying everything I learned from this class and properly implement topics from different weeks. After school, I will consider blogging when important topics that I’m knowledgeable of cross my path.

 

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology. 

Monday, July 29, 2024

Week 9 Posting - Managing Cloud Capacity and Performance

This week, the class and I learned how to manage cloud capacity and performance. One of our weekly objectives is to describe the relevance of events and data in monitoring cloud resources. During my readings, I want to point out the importance of utilizing a syslog and its priority on data gathering.

            Whether it’s on site or in the cloud, Syslog is the protocol for managing event data logs and sending them to their respected storage location. This protocol collects and stores logging transactions and history information. Event message format, transmission, and handling are three main components to the syslog infrastructure (West, 2022, pp. 361-362). The format is structured with types of data to allow syslog to be used in a variety of environments. The transmission is majority focused on data movement across networks. The handling aspect is for creating and analyzing the event messages.

            Two servers the Syslog uses for logging events are the generator and collector. The generator creates syslog messages and transactions from a file and moves them to the collector that gathers these messages (West, 2022, p. 362).

 

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology.

Friday, July 26, 2024

Week 8 Posting - Cloud Storage

This week, the class and I went over the topic of cloud storage and identifying multiple types of data types stored in the cloud. In the realm of cloud security, it’s essential to classify data in a form of different axes. I want to argue that prioritizing different organizational methods will increase security that store these data. During our reading, I learned about 4 types of data classification axis: sensitivity, compliance, lifecycle, and visibility (West, 2022, p. 337). Sensitivity controls who can access the data and whether it can be accessed remotely or strictly on-premises. Compliance proposes the standards and regulations of data storage and movement. Encryption is one of the main topics in this axis. Lifecycle is focused on the duration of data in the specific storage. Lastly, visibility is centered on monitoring data and tracking any sort of movement and transactions.

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology.

Friday, July 19, 2024

Week 7 Posting - Identity and Access Management

 

This week, the class and I learned about identity and access management. We learned how to evaluate account manage requirements and other technical concerns. During my studies, I learned about common identity and access management (IAM) issues that may hinder and negatively impact performance and productivity. When it comes to issues related to authentication, there are three common areas of impact: expired certificates, misconfigured certificate, and federation /single sign-on issues (West, 2022, p. 288). When certificates expire, it’s common for the system to send a friendly reminder to the user that they’ll expire within a certain duration. In some cases, the certificates will need to be renewed manually. Checking the expiration date of a certificate can help the users to acknowledge when it’ll be time to renew it. In some cases, users attempt the wrong certificate to access or perform a command in the system. If that’s the case, go to the root and configure it correctly. Lastly, mistyping is a common problem when signing to a system. Ensure the credentials are correct and there’s no blockage between the SSO service and service provider’s app (West, 2022, p. 288).

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology.

Friday, July 12, 2024

Week 6 Posting - Securing Cloud Resources

 

This week, the class and I learned about securing cloud resources and identifying different types of threats to cloud security. System misconfiguration occurs when an application is configured improperly or are missing certain settings or guidelines. This creates a ripple effect that exposes weak spots in the system for threat actors to take advantage of. There are common security weak spots that IT professionals should consider when a security issue arrives: unencrypted data and communications, obsolete security technologies, incorrect hardening settings, security device failure, insufficient security controls and processes, and unauthorized physical access (West, 2022, p. 249). To fix these misconfigurations, the team must consider identifying the root of the problem, evaluate the severity, implement correction, and document the situation. The reason for documenting is for future reference, meaning if this situation occurs again, the team will be prepared.

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology.

Friday, July 5, 2024

Week 5 Posting - Cloud Connectivity and Troubleshooting

This week, the class went out cloud connectivity and troubleshooting. We learned how VLANs and common network connectivity tools work. I want to shed to light a recent technology that addresses the weaknesses of VLANs in a cloud computing atmosphere called VXLAN or virtual extensible LAN).

This overlay technology creates an “extended” virtual network on top of the current infrastructure. In terms of the OSI model, it is adding a layer 2 overlay structure above layer 3 (West, 2022, p. 183). The VXLAN header is inserted between the outer UDP header and original layer 2 frame. The header itself consist of the VXLAN flags and VXLAN network ID. An optimal time to use VXLAN is when the users need to accomplish any type of network segmentation that goes beyond what the original can deliver since VXLAN enables up to 16 million virtual networks.

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology.

Saturday, June 29, 2024

Week 4 Posting - Cloud Networking

This week, the class covered cloud networking, which involves appropriating IP address spaces in cloud networks, identifying cloud stacks, and configuring network interfaces in the cloud. For me, I found incorporating the OSI model to the Cloud Stack Theoretical model benefits me by learning how to manage and organize the information. Layer 1 is the physical layer. This layer includes servers, cables, hardware, etc. Layer 2 is the virtualization layer. This layer emphasizes the virtualization software and hardware. Layer 3 is the network layer. This layer focuses on managing resources, costs, security, and other services. Layer 4 is the OS layer. This layer is centered around data storage, data processing and workloads. Lastly, layer 5 is the application layer. This layer is for the traditional lower-layer functions. The cloud service provider is responsible for monitoring the physical and virtualization layer (West, 2022, p. 132).

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology.

Friday, June 21, 2024

Week 3 Posting - Migration to the Cloud

 

            Data transfer is the procedure of migrating data from location A to location B. In the case for cloud computing, it’s the motion of moving data to and from a storage environment. This week, we learned about cloud migration and its functionalities. One terminology I want to bring up is the methodologies of transferring data and the different types of data transfer: public internet, private connection, and offline transfer.

Public internet enables minimal and slow data migrations. Private connections low latency, high availability and increased bandwidth since the user is not competing for connections. One drawback I learned is a private connection often requires a long-term dedicated contract with a specific ISP. Lastly, offline transfer is transferring encrypted data onto a storage device and physically migrating it to the cloud service provider. This could mean package delivery (West, 2022, pp.90-92).

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology.

Sunday, June 16, 2024

Week 2 Posting - Virtual Hardware

Virtual network interface controllers or vNICs physically and virtually connect the virtual machine to other neighboring machines (West, 2022, p. 46). These are the links that enables the host to connect to VMs. Throughout my research, I learned about three common network configurations: bridged, NAT (network address translation), and Host-only mode.

Bridged mode is known to be the easiest route regarding accessibility for VM to connect to a network since it uses the host’s physical network adapters. NAT mode is useful if the user needs to keep their virtual machines private and away from the public eye. NAT is best suited for testing the waters. Lastly, the host-only mode is basically a one-way road. WMs can share data with each other but they cannot communicate with other nodes beyond the host (West, 2022, p. 47).

 

References:

West, J. (2022b). CompTIA Cloud+ Guide to Cloud Computing. Course Technology.


Sunday, June 9, 2024

Week 1 Posting - Introduction to Cloud Computing

Hello friends! I’ve had this blog for a long time, and I am excited to starting blogging about my experiences with BSIT 400 Cloud Computing and Governance class. When it comes to cloud computing, I have no experience on the professional field (yet) but I am willing to learn more about the functionalities and backbone of a cloud infrastructure and how businesses and organizations benefit from utilizing its features. When it comes to the daily and casual lifestyle, there are several cloud services we use that we don’t realize. After reading researching about cloud services, I came across an article from MarcoNet that listed a good amount of cloud services that we use daily. One thing I want to point out is file-sharing. This feature can be used in both professional and casual settings. Google Drive is an example of a well-known file-sharing service where the user can share their personal photos to their loved ones. To add to that, Google Drive can be used in a business setting where associates can exchange and share documents on specific projects and sensitive files. Cloud computing is an excellent concept that helps individuals and organizations with daily activities.

Marco. (2023, November 27). 7 cloud services you use every day without even realizing

it. Marcohttps://www.marconet.com/blog/cloud-based-services-you-use-every-day-without-even-realizing-it

Saturday, August 5, 2023

Week 9 Posting - Incident Response Process and Procedures, Indicators of Compromise, and Basic Digital Forensics Techniques

 Regarding independent contractors, I am in the gray area. Hiring experienced contractors to deal with IR activities hold a lot of benefits. They’ve had experienced dealing and handling certain incidents. It saves money as well since it’s the contractor’s responsibility to use their own equipment and taxes. However, it’s game over not necessarily) when a contractor is injured during the job. Liability is a hot topic whenever they’re injured on site and the employers has to deal with the situation. Another thing is that Each company should have their own incident response worker(s) to combat any dire situations that pose as a threat to company reputation or productivity. It’s good to involve outside power to intervene and help with the situation. But it is better off to have someone in the company who has access to all related applications and tools to fix and augment the issue.

Friday, July 28, 2023

Week 8 Posting - Automation Concepts and Technologies

 Cyber Security automation has a massive upside, improving accuracy and efficiency while reducing the amount of redundancy and incidence.  However, I am leaning more to disagreeing with cyber security automation “leveling” the playing field. We still need sys and network admins to monitor and maintain said programs. The amount of risk and consequences still persist. Attackers are always on the clock and they won’t be waiting for the automated security to keep up with them. Matter of fact, I wouldn’t be surprised if they manipulate the defenses. How do we, as users, know if we’re under attack when the automated security doesn’t react or report any breach? Lastly, I want to point out is the “human error” into utilizing an AI focused defense system, which the automated system itself depends on the sys admin’s configuration ability. One misstep or mistake can be catastrophic (not too dramatic).

Saturday, July 22, 2023

Week 7 Posting - The Importance of Proactive Threat Hunting

Attack vectors

A feared and respected general does not necessarily rush into the battlefield with no plans in their arsenal. In order for a successful attack against their enemies, they need to plan ahead, optimize their current resources and understand the playground. Likewise, most attackers usually have an attack vector in their bag. This is a method of obtaining access to a network or system illegally. These attackers have different ways to approach them, whether it’s through malware, vulnerability exploitation, social engineering or insiders (Chapman & Maymi, p.339, 2020). Malware now days are becoming more polymorphic, meaning they adapt to their environments while on the move to infecting the system. Regarding vulnerability exploitation, zero-day attacks prove to be a massive blow to defenders and threat hunters since no one will be aware or notice any breach that occurs. Social engineering is tricking users and targets into revealing their personal and sensitive information. Because of this manipulative act, attackers will plant their malware into the network. Lastly, an insider can be anyone, which is one of the trickiest assignments for a threat hunter to exploit. This could be a former or current employee. They are literally in the network and it’s hard to figure out whether they’re doing suspicious activities or not.

 

References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Saturday, July 15, 2023

Week 6 Posting - Data Analysis in Security Monitoring Activities and Implement Configuration Changes to Existing Controls to Improve Security

            You can learn a lot from experimenting different subjects to further enhance the knowledge of the scholar. In other words, you gain a lot of data from proving or disproving hypotheses or ideas by providing evidence or lack of. Sandboxing is one of the many examples of experimentation. It’s an effective cyber security practice that allows security specialists to operate codes by observing / analyzing them in an isolated, virtual environment on a network that mirrors regular user’s OS environments. Basically, it’s a practice that inspect unknown and untested code. It’s a helpful area to test out malware without worrying about it attacking neighboring networks since nothing is directly attach to the isolated environment. Often times, security specialists execute software in the sandboxes and report / examine the effects that occurs. With enough data, counter measurements will take place that would benefit the company (Chapman & Maymi, p322, 2020). Some drawbacks with sandboxing are that it is heavily resources reliant, meaning that it can be costly. On top of that, the infrastructure of the sandboxes can be complex and consist of a steep learning curve.

 

References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Saturday, July 8, 2023

Week 5 Posting - Software and Hardware Assurance Best Practices

 

          Most businesses have their software development department, quality assurance, cyber security team, and IT operations team. Somewhere down the line, there would be hiccups that would negatively affect one department that was created by its neighboring department. For example, assignments from QA could indirectly affect the IT operation team’s incentive and productivity. According to Chapman and Maymi, a solution to solve the friction between teams and department is collaborating them into one multifunctional team called DevOps or DevSecOps. This practice will align all department’s incentives and goals to ultimately enable more efficient and consistent performance (Chapman & Maymi, p.225, 2020).

Personally, communication is key. By having everyone collaborate to further prevent anymore hiccups and speed bumps on the way will definitely improve the company’s production. The only flaw I can think of in this multifunctional team that it’ll get more complicated and more complex. It’ll be hard to manage and monitor multiple resources and programs within the team. On top of that, it might be required for all team players to learn new programs which could be timely.

References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Online, O. E. (2023). 10 Advantages and Disadvantages of DevOps. Open Education Onlinehttps://openeducationonline.com/magazine/advantages-and-disadvantages-of-devops/

Week 4 Posting - Security Solutions for Infrastructure Management

 

Honeypots and Honeynets are every cyber security worker’s best friends. These tools are ultimately designed to attract cyber attackers by intentionally exposing a vulnerable hardware or system. One of my favorite features about these tools is that it’s being monitored and will send out alters and messages to any suspicious activities.

 Honeypots target attackers that are attempting to sabotage a hardware whereas honeynet target attackers that are attempting to sabotage an entire network. One of the flaws with utilizing these tools are experienced attackers will bypass them and will attack other areas. The thing is, these tools are isolated away from other networks, which makes it obvious to experienced attackers. Another flaw is that they can only collect a limited amount of data.

 

References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Lutkevich, B., Clark, C., & Cobb, M. (2021). honeypot (computing). Securityhttps://www.techtarget.com/searchsecurity/definition/honey-pot

Sunday, June 25, 2023

Week 3 Posting - Threats and Vulnerabilities Associated with Specialized Technology and Operating in the Cloud; Mitigating Controls for Attacks and Software Vulnerabilities

 

Vulnerabilities

            According to Fortinet, four IoT threats to devices include limited hardware, a mix of transmission technology, vulnerable components, and user security awareness (Fortinet, 2023). In most cases, consumers of any IoT products have limited amount of security and security awareness since some of these devices lack built-in security to combat cyber threats. For example, Chapman and Maymi explains the functionality of the Mirai botnet, a malware that attacks IoT devices (Chapman & Maymi, p.130, 2020). To put things into perspective, the attacker attacks the control server which initially attacks the compromised hosts and ultimately affects the victim by attacking traffic. Another vulnerability to consider are weak or defaulted passwords or passcodes. Users settle for easy and fast passwords to access their devices and ignoring the risks of implementing harder passwords, which should include special characters, numbers, and extended character requirement. For example, “R3ign0ver!37” a solid password should be around 12-15 characters added with special characters and capital or lower-case sensitivity. 


References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Top IoT Device Vulnerabilities: How To Secure IoT Devices | Fortinet. (n.d.). Fortinet. https://www.fortinet.com/resources/cyberglossary/iot-device-vulnerabilities

Sunday, June 18, 2023

Week 2 Posting - Vulnerability Management Activities and Vulnerability Assessment Tools

 Active scanning and passive scanning have their advantages and disadvantages. When it comes to active scanning, I will have an ongoing overview of the health and processes of my home network. In addition, this method of scanning collects basic and detailed profile and configuration information. However, due to fast data collection and active operation, the consequences of endpoint malfunction could be lethal in the long run. Although it’s great to be on top of my game and actively running tests and scans, overloading the signals and causing network traffic could be tedious. On the flip side, passive scanning operates in silence. Unlike its counterpart, passive scanning scans my systems and applications without any direct interaction with the network. The good thing about this is that it does not clog up the network traffic while identifying the traffic patterns and conditions of every endpoint. The downside of passive scanning is it takes forever to collect important data since it has to wait for each asset to finish its operation. Since I’m not running a business and this is more towards personal use, I’m leaning more towards passive scanning since it still gets the job done without excessive manual scanning (Sherry, 2020).


References:

Chapman, B., & Maymi, F. (2020). CompTIA CySA+ Cybersecurity Analyst Certification All-in-One Exam Guide, Second Edition (Exam CS0-002). McGraw Hill Professional.

Sherry, C. (2020, April 21). Advantages and Disadvantages of Active vs. Passive Scanning in IT and OT Environments. Infosecurity Magazine. https://www.infosecurity-magazine.com/opinions/active-passive-scanning/

Sunday, June 11, 2023

Week 1 Posting - Introduction

Hello IT World,

My name is Genesis Perez, and I am an Information Technology student attending Bellevue University. I've always found technology extremely fascinating and spectacular. I enjoy utilizing technology daily, whether it's at the comfort of my own home or working in my office at work. Technology is much more accessible and affordable now. New gadgets like the Apple Vision Pro and advanced artificial intelligence are on the rise and will continue to structure the future. That being said, with the rise of technology comes with the rise of threats and cyber-attacks. It is crucial to be well equipped and prepared for any threats that could potentially damage your device, documents, and reputation. I am a firm believer of cyber security and its role in the defense against hackers and malicious tools. I am excited to learn more about cyber security and proper procedures to handling security power and monitoring your respected network / systemic area.


Saturday, March 5, 2022

Week 12 Posting - Genesis Perez

 Threats to the Computer

No one likes viruses. Everyone wants to keep their files and privacy intact and not on the risk of being exposed or destroyed. Back in the days when I wasn’t familiar with security programs and software, there were times where I’d encounter a virus and it would either slow down my computer or corrupt my files. However, after reading an article from Vangie Beal called “Computer Virus vs Worm vs Trojan Horse,” it changed my perspective on the different types of threats to an individual’s device. At first, I thought a worm or trojan horse was related to a virus but they’re simply not. It’s a common mistake today and there should be more of an awareness and differentiating the three threats. What is common knowledge is that these three damages and corrupts the computer in different angles.

A computer virus hangs onto a file or program and spreads itself to another, infecting computer to an extend unless treating it quickly. This may come in a form of emails and visiting NSFW websites. A worm is like a virus, but it spreads and travel without the user interacting with the device at all. Matter of fact, it sends copies or replicate of itself to the user’s entire network. A worm will consume a lot of bandwidth in a web server that it will stop responding. Lastly, a trojan horse is like a fake software that from the outside, it looks harmless, but once installed, it can either annoy the user by changing the users’ desktop interface or even deleting files off their system. Out of the three threats, the trojan horse is the trickiest and the most deceptive threat for the user’s device.

            According to Beal, a few useful tips are keeping the user’s operating system updated and to utilize a firewall (Beal, V., 2004).

References

Beal, V. (2004, October 28). Computer Virus Vs Worm Vs Trojan Horse. Webopedia. https://www.webopedia.com/insights/virus-vs-worm-trojan/

  • What did you find enjoyable or not about this assignment?
    • What I don’t find enjoyable is that I should’ve learned the differences between the threats in middle school or something. I feel like this is like beyond basic information that sadly, only know I learned this. I am not upset but it’s kind of funny.
  • Was it helpful to you in your current job?
    • It will be very helpful for me.
  • Can you see yourself Blogging in the future when it isn't required for an assignment?
    • I enjoy sharing ideas and personal experiences with topics that I admire and that I find interesting. Whether it’s gaming or technology, I will find time to blog in the future.
  • Can you see this ability as desirable for a company, giving you more weapons in your arsenal and making you a more attractive hire?
    • Cyber security is an important and useful career. I believe any company would love to hire a cyber security professional to keep their company safe and running smoothly.

 

Week 10 Posting - Cloud Automation

For the final week of class, we learned about cloud automation and using common terminology that are used in automation services and techniq...