From the course: CompTIA Advanced Security Practitioner (CASP+) (CAS-004) Cert Prep

Unlock this course with a free trial

Join today to access over 24,200 courses taught by industry experts.

Security settings

Security settings

- In this lesson, we're going to discuss some security settings that you should be aware of on your endpoint devices in order to best secure and harden those devices. These include local drive encryption, enabling NX and XN bits, disabling CPU virtualization support, secure encrypted enclaves and memory encryption, shell restrictions, and ASLR. First, let's talk about local drive encryption. Local drive encryption is used to protect the contents of the storage device when the operating system is not running. This is also known as "data at rest". This is going to be where BitLocker and other full disc encryption software are going to be used. Now, BitLocker is a full disc encryption software that's included in Microsoft Windows, and it relies on the TPM chip to perform its encryption and decryption functions. If you're using Linux, on the other hand, you can use Cryptsetup. If you're using OS X, you can use FileVault. All of these tools essentially do the same thing. They use AES…

Contents