COURSE OBJECTIVE:
After completing this courses you should be able to:
• Hack, test and secure your SQL Server Infrastructure
TARGET AUDIENCE:
Database administrators, infrastructure architects, security professionals, system engineers, advanced database developer, IT professionals, security consultants and other people responsible for implementing databases security.
COURSE PREREQUISITES:
Attendees should meet the following prerequisites:
• Good hands-on experience in administering Microsoft SQL Server infrastructure. At least 5 years in the field is recommended.
COURSE CONTENT:
Module 1: Hacking SQL Server Infrastructure
• Discovering SQL Server instances
• SQL injection using men in the middle
• Capturing SQL credentials using men in the middle
• Decrypting SQL Logins passwords
• Gaining access to SQL Server on compromised Windows Server
Module 2: SQL Server security baseline concepts
• Defining security objectives
• Configuring service accounts
• Auditing database permissions
• Implementing physical protection
• Configuring firewall
• Securing client-server communication
Module 3: SQL Server Instance security
• Limiting permissions
• Securing CLR
• Implementing protection for extended procedures
• Protecting linked servers (OPENROWSET)
• Securing by using policies
• Hiding instance metadata
Module 4: Managing Logins and Passwords
• Authentication options
• Implementing password policies
• Securing connection strings
• Customizing login / user authorization
Module 5: Encryption in SQL Server
• Key management
• Code and data encryption
• Managing certificates
• Transparent database encryption
• Encryption in HA and Disaster Recovery
Module 6: Protecting database backups
• Securing backup files
• Setting backup file passwords and encryption
• Handling keys and certificate backups
• Security considerations while restoring to another SQL Server instance
Module 7: Monitoring and auditing
• Login auditing options
• Data access auditing
• Data Manipulation Language custom auditing
• Policy-based management
• Forensics case study
Module 8: Securing other SQL Server services
• SQL Server Agent
• SQL Server Analysis Services
• SQL Server Reporting Services
• Azure SQL Database
FOLLOW ON COURSES:
Not available. Please contact.