
Meet your security plus exam prep instructor, Troy McMellon, with a background in security, training, instructional design, and authoring study guides and practice tests for the security plus exam.
Explore general security concepts and the exam structure, reviewing security domains and their percentage weights while defining key security topics you need to know.
Explore Security+ SY0-401 exam domains, including four (application data and host security), with network security 20%, compliance and operational security 18%, threats and vulnerabilities 20%, identity management 15%, cryptography 12%.
Define hackers and hacking, noting cracking and phreaking as related terms. Describe computer security and the CIA triad—confidentiality, integrity, availability—with encryption and access control to ensure data protection.
Explore additional security goals, including authentication with username and password, digital signatures for non-repudiation, and CIA principles, and learn prevention, detection, and response strategies using backups and incident response.
Harden the operating system, enable antivirus, and close unused ports to reduce the attack surface. Deploy bastion hosts in the DMZ, apply host-based IDS, and enforce least privilege.
Discover layered security using patches, firewalls, and multiple access controls. Examine mandatory, role-based, rule-based, and discretionary access control, plus authentication methods—something you know, have, or are—and multi-factor options.
Review the chapter one concepts and revisit them throughout the course to strengthen familiarity. Keep these concepts in mind and strive to become as familiar as you can with them.
Explore organizational security by examining steps to institutionalize security approaches, including security policies, incident response, and proper procedures.
Define a security program as the set of procedures, processes, and technology that address security issues, guided by a policy and supported by standards and guidelines.
Outline the circular operational process for security programs, from planning to implementing, monitoring, evaluating, and adjusting, and examine physical and logical access controls, including access control lists and group policies.
Learn how password policies enforce access controls through time-based restrictions, expiration, length, and complexity, along with password history. Also examine hardware tokens and one-time codes in stronger authentication.
Demonstrate implementing a password policy on a single machine or domain. Remember the last eight passwords, set maximum age to 30 days, and enable complexity requiring three of four criteria.
Explore how social engineering uses non-technical tricks to obtain passwords and access by convincing people, including fishing, shoulder surfing, dumpster diving, and hoaxes.
Explain change management policies that require approvals and track impacts, along with information classification, acceptable use, internet usage, and email usage policies that govern access and behavior.
Understand policies implementing due care, due diligence, due process, separation of duties, least privilege, and need to know to protect data. Include disposal, destruction, privacy, and service level agreements.
Explore human resources policies governing hiring, background checks, promotions, retirement, separation, and terminations, ensuring equal treatment, with mandatory vacations, a code of ethics, and an incident response plan.
Summarizes the module's coverage of security policies and introduces a basic framework to guide enterprises in creating a security program or policy.
Examine privacy, ethics, and legal issues organizations face when handling customer or employee information. Explore how to mitigate these problems, including addressing unethical employee behavior.
Explore cyber crime types, including computer assisted, computer targeted, and computer incidental, plus internet schemes like auction and credit card fraud, and computer trespass under statutory, administrative, and common law.
Explore how global cybercrime prompts legal responses, from the first international convention to national laws like the electronic communications privacy act and the computer fraud and abuse act.
Examine export controls on encryption under the Bureau of Industry and Security and the Wassa arrangement. Discuss electronic signatures, digital rights management, and privacy in commerce law.
Review ethics and privacy, and confirm familiarity with the major laws covered in this module, plus the legal issues and types of laws used in this area.
Explore cryptography as the science of scrambling information to keep data unread, and examine encryption algorithms, encryption keys, and how they work together to protect data.
Explore how cryptography secures communications against third parties. Analyze transposition and shift ciphers, learn their reversibility, and examine how keys and algorithms encrypt and decrypt data.
Explore classic ciphers from the Caesar cipher with offset keys to substitution and block rearrangement methods, and learn how one-time pads offer unbreakable encryption when keys match message length.
Explore how cryptographic math uses a key with bitwise XOR to encrypt and decrypt binary data, and how hashing provides data integrity with one-way, fixed-length outputs and salt.
Explore encryption and hashing algorithms for confidentiality and integrity, including sha and md families, and analyze des as a symmetric block cipher and its key tradeoffs.
Explore symmetric encryption, including triple encryption with three keys and the reverse process, and note AES-based encryption as the current standard with 128, 192, and 256-bit keys.
Examine block and stream ciphers, including RC4, Blowfish, and IDEA, and understand RSA public-key cryptography for digital signatures; learn PBKDF2 with salt to resist rainbow tables and brute-force attacks.
Use asymmetric key exchange to securely share a symmetric key, then encrypt data with fast symmetric encryption. Diffie-Hellman with elliptic-curve cryptography enables perfect forward secrecy, while El-Gamal provides digital signatures.
Explore how digital signatures verify integrity and non-repudiation by signing a document with a private key, hashing it, and validating with a public key in a public key infrastructure.
Explore how cryptography safeguards confidentiality and integrity within the CIA triad and supports non repudiation.
Explore the hardware, applications, and interfaces that enable a public key infrastructure, and examine the cryptographic algorithms that make PKI work.
Explore how a public key infrastructure uses certificates, keys, and a certificate authority to enable secure document exchange with symmetric and asymmetric encryption and digital signatures.
Explore certificate hierarchies with root certificate authority and subordinate certificate authorities, centralized versus distributed issuance, and class one, class two, and class three certificates, repositories, and distinguished names.
Verify the certificate by matching its signer to the trusted CA list, computing the message digest, decrypting the signature with the CA’s key, and checking validity and revocation.
Examine types of certificates, including user, computer, application, and policy certificates, and how cross certification links PKIs for trust. Learn standard, private, and critical extensions, and the certificate life cycle.
Manage certificate trust by using a certificate revocation list (crl) with delta updates and ocsp for real-time validation, while securely handling key destruction and local private keys.
Implement ephemeral keys to achieve perfect forward secrecy by rotating session keys for each message, and balance key size and lifetime with data sensitivity, secure storage, authentication, and proper destruction.
Implement secure key archival and recovery with dual-control agents and thresholds, and understand key escrow and the roles of public, internal, and outsourced certificate authorities.
Explore how cross certification and trust domains enable PKI to validate and vouch for identities across certificate authorities within a hierarchical root and intermediate structure and path validation.
Explore the components that enable a public Canfor structure to operate. Review certificate types and trust models, and outline issuing and revoking processes for the exam.
Explore the standards and protocols that enable public key infrastructures to communicate using a common method, and examine how these standards are created to make this possible.
Explore PKI standards and protocols, including X.509 and PKCS, defining certificates, authorities, revocation lists, policies, and extensions that support SSL, TLS, and IPsec.
Understand how ssl and tls secure privacy via the handshake and record protocols, while certificates, authorities, and key management enable authentication and encryption across pki-enabled systems.
S/MIME uses public key infrastructure to encrypt and digitally sign email, with CMS triple-encapsulated messages and version 3 specifications for message syntax and certificates.
Explore how IPsec secures network-layer traffic in transport and tunnel modes, using AH and ESP for authentication, integrity, and optional encryption, with FIPS guidelines.
Learn the criteria framework for evaluating software and operating systems, with EAL levels 1–7, thoroughly. Note ISO 27000 security policy standards and that WEP is insecure, with labs evaluating software.
analyze the standards and protocols that underpin a public key infrastructure, review pki standards, explore applications like s/mime and ipsec, and examine business processes enabled by these standards and protocols.
Explore physical security to protect devices from unauthorized physical access and learn how to physically authenticate users, contrasting with logical methods like usernames and passwords.
Learn physical security measures that cover preventative and detective aspects, including access control, locks, server room security, Faraday cages, bios password protection, USB controls, and policies for computers and users.
Explain how access controls and monitoring deter theft through layered protections, including mantraps, video surveillance, and reliable power, while authenticating users with token-based cards and multi-factor authentication.
Biometrics enroll a biometric factor, convert it to a digital value, and authenticate users by comparing scans to data. Discuss false positives, false negatives, privacy, and two factor authentication.
protect devices from theft and damage through robust physical security. authenticate users with biometrics and tokens using multi-factor approaches.
Explore infrastructure security by examining network devices, identifying device-specific vulnerabilities, and implementing targeted measures to mitigate dangers and protect your network.
Focuses on infrastructure security for devices and interconnects, securing printers with non-default passwords and least-privilege print access, and hardening workstations with antivirus, patches, and restricted usb ports.
Harden servers by removing unnecessary protocols and shares, renaming administrator account and password, patching operating system, securing physical access, and reinforcing switch security with mac address tables and secure shell.
Segment networks with VLANs on switches, isolate departments, secure routers with ACLs and authentication, disable unused ports, and deploy firewalls offering NAT, stateless, and stateful filtering plus application-layer protection.
Secure wireless access points by disabling telnet, using encrypted protocols like SSH, changing default admin passwords, and enforcing authentication; encrypt all sensitive wireless traffic to counter eavesdropping.
Learn vpn tunneling with ipsec that encrypts data and headers, and how intrusion detection uses signature or anomaly methods alongside network access protection and Cisco trust agent.
Learn SNMP monitoring version 3 with community strings and secure default changes, assess mobile malware risks, and compare coax, shielded twisted pair, fiber, iscsi, and fiber channel protocols.
Address big data challenges for organizations, where relational databases falter, and secure radio frequency, infrared, and microwave media with encryption; emphasize physical security for removable media and backups.
Segment networks into security zones with a dmz and extranet, use firewalls to block access, and manage vlan trunking and nat to protect internal addresses.
Operate multiple virtual machines on a single physical host with shared resources and hardening, and outline cloud models: infrastructure as a service, platform as a service, software as a service.
Explore infrastructure security and learn how to protect the various devices in your network and the media that connect them. Review related issues such as cloud computing and virtualization.
Explore remote access technologies and authentication methods used to secure connections to the office network and access resources.
Explore how remote access relies on triple-A and Kerberos, with a key distribution center issuing time-stamped tickets to authenticate users and grant service access.
Explore alternatives to passwords, including certificates, tokens, and hardware devices, and study 802.1x port-based authentication using a supplicant, authenticator, and radius server with centralized credentials.
Diameter aims to replace radius as a triple-a protocol suite, offering authentication, authorization, and accounting with encrypted client-server communication via a shared secret, similar to tacacs+.
Federated authentication uses security token services across trust domains to let resource providers access a user's rights, while single sign-on and mutual authentication with certificates securely validate users and servers.
Explore HOTP and TOTP, MAC-based one-time passwords with sequence- and time-based generation, and secure remote access concepts like tunneling, IPsec with AH/ESP, and security associations.
Explore remote authentication protocols such as CHAP, PAP, and EAP, noting CHAP avoids passwords over the network and PAP sends credentials in clear text.
Explore remote access technologies and authentication methods for secure remote connections. Examine secure methods for connecting to and managing infrastructure devices.
CompTIA's Security+ is a vendor-neutral certification that validates the competency of security professionals working in the IT industry. The Security Plus Certification confirms a technician's critical knowledge of communication security, infrastructure security, cryptography, operational security, and general security concepts. Because human error is the number one cause for a network security breach, CompTIA Security+ is recognized by the technology community as a valuable credential that proves competency with information security.
The CompTIA Security+ Certification Training Course measures the necessary competencies for an IT professional with approximately two years networking experience. Students will learn the knowledge and skills needed to protect your business from the theft or destruction of information or disruption of communication.
This Security Plus training course follows the CompTIA authorized curriculum, ensuring you receive the training and knowledge needed to succeed.