All certifications / Security+ / Lessons
Security+ SY0-701 lessons
Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: General security concepts
- Control categories: technical, managerial, operational, physical
- Control types: preventive, deterrent, detective, corrective, compensating, directive
- CIA triad, AAA, non-repudiation
- Zero trust: control plane vs data plane, policy engine, PEP
- Physical security and deception tech (honeypots, honeynets, honeytokens)
- Change management: approval, CAB, impact analysis, backout plan, maintenance window
- Symmetric vs asymmetric encryption, key exchange
- Hashing, salting, key stretching
- Encryption levels: full disk, partition, file, database, record
- Obfuscation: steganography, tokenization, data masking
- Public/private keys, key escrow
- Certificates: CA, CSR, root of trust, self-signed, wildcard, SAN
- Revocation: CRL vs OCSP, OCSP stapling
- Digital signatures
- TPM, HSM, secure enclave, key management system
- OSI layers and where attacks happen
- Secure vs insecure protocols: SSH/Telnet, SFTP/FTP, LDAPS/LDAP, HTTPS/HTTP, SNMPv3
- Key ports: 22, 25, 53, 80, 443, 389, 636, 3389
- ARP, DNS, DHCP and their attacks
Domain 2: Threats, vulnerabilities & mitigations
- Actors: nation-state, organized crime, hacktivist, insider, unskilled attacker, shadow IT
- Motivations: espionage, financial, disruption, ideology
- Threat vectors: email, SMS, voice, removable media, supply chain, open ports
- Social engineering: phishing, vishing, smishing, pretexting, BEC, watering hole, typosquatting
- OWASP Top 10: broken access control, injection, misconfiguration, integrity failures, SSRF
- SQL injection, XSS (stored/reflected), CSRF
- Buffer overflow, race conditions (TOCTOU), memory injection
- Threat modeling
- Malware: ransomware, trojan, worm, spyware, rootkit, logic bomb, keylogger, fileless
- Password attacks: spraying, brute force, credential stuffing
- Crypto attacks: downgrade, collision, birthday
- Indicators: impossible travel, account lockout, resource consumption, missing logs
- Segmentation and isolation
- Least privilege, access control lists
- Application allow listing
- Patching, encryption, monitoring
- Hardening: disable ports/services, change defaults, remove unused software
Domain 3: Security architecture
- Cloud: IaaS/PaaS/SaaS and shared responsibility
- IaC, serverless, microservices, containers
- Virtualization risks: VM escape, sprawl
- ICS/SCADA, IoT, embedded, RTOS
- On-prem vs cloud vs hybrid trade-offs
- Firewalls (L4/L7, NGFW), WAF, UTM
- IDS vs IPS, inline vs tap
- Fail-open vs fail-closed
- 802.1X, NAC, port security
- VPN, IPsec, TLS, SD-WAN, SASE, jump servers, proxies
- Data types and classifications
- Data states: at rest, in transit, in use
- Protection: encryption, hashing, masking, tokenization, DLP
- Resilience: HA, clustering, load balancing, RAID
- Backups, sites (hot/warm/cold), RPO/RTO
Domain 4: Security operations
- Secure baselines, mobile (MDM, BYOD, COPE, CYOD)
- Wireless: WPA3, SAE, RADIUS, EAP
- Asset management and disposal (sanitize, destroy, certify)
- Vulnerability scanning: credentialed, false positives, CVSS, CVE
- Pen testing and recon: passive vs active
- Logs, SIEM correlation, alerting, SCAP, NetFlow
- Email security: SPF, DKIM, DMARC
- EDR/XDR, DLP, UEBA
- IAM: provisioning, SSO, SAML, OAuth, OpenID Connect, LDAP
- MFA factors, PAM, just-in-time access
- IR process: preparation, detection, analysis, containment, eradication, recovery, lessons learned
- Tabletop exercises and simulations
- Forensics: order of volatility, chain of custody, legal hold, acquisition
- Automation and SOAR playbooks
- Investigation data sources