
Introduce the CompTIA Security+ (SY0-601) exam series and foundational security concepts, outlining objectives, study resources, and the exam structure including attacks and threats.
Learn how social engineering exploits people, with phishing, vishing, smishing, spear phishing, and whaling, and how the CIA triad, threats, and user awareness shape defense.
Explore the spectrum of malware, from viruses and worms to fileless viruses, rootkits, and ransomware, and learn how each type infects, propagates, and evades detection for the security+ exam.
Explore how password attacks exploit authentication systems through brute force, dictionary, rainbow tables, and spraying methods to gain privileged access.
Explore online versus offline password attacks and key tools such as John the Ripper, Hashcat, Hydra, and Burp Suite, including wordlist generation and hash extraction techniques.
Learn how injection-based attacks exploit untrusted input in web apps. Explore sql, ldap, xml (xxe), dll, and command injections and their impacts like data loss and denial of service.
Explore application attacks that drain system resources, including CPU, memory, network, and storage. Learn about memory leaks, buffer and integer overflows, race conditions, TOC TOU, and driver manipulation.
Explain cross site scripting and cross site request forgery, detailing reflected XSS, stored XSS, and DOM-based XSS, and compare server-side versus client-side CSRF risks.
Explore replay attacks and how retransmitted data from packet sniffing enables attackers. Discover defenses such as time stamping, sequencing, and ipsec or tcp/ip safeguards.
Explore how DNS resolves host names to IP addresses using caching, root and TLD lookups, A/AAAA records, and how poisoning, hijacking, or domain hijacking redirects users to malicious sites.
Examine layer 2 attacks—ARP poisoning, MAC cloning, and MAC flooding—and understand how ARP operates with MAC addresses on the data link layer within a local network.
Explains denial of service and distributed denial of service attacks, including reflected, amplified, and coordinated methods, how botnets and spoofed IPs overwhelm targets.
Explore man-in-the-middle and man-in-the-browser attacks, their use of cleartext protocols, session hijacking, and crafted requests, and how secure protocols like ssh mitigate risk.
Explore common wireless network attacks, including rogue access points and evil twins, disassociation and initialization vector vulnerabilities, and Bluetooth and RFID/NFC threats and relay attacks.
Identify common vulnerabilities across systems, from weak configurations and defaults to weak encryption and open permissions. Manage third-party risks and patch management to protect on-premises and cloud environments.
Explore open source intelligence (OSINT) as the practice of gathering and analyzing publicly available data to identify external threats and strengthen defense strategies.
Explore threat maps and feeds to visualize real time threats and identify indicators of compromise. Learn how STIX, TAXII, and automated indicator sharing enable rapid threat intelligence for malware defense.
Explore vulnerability databases and feeds, including MITRE's CVE and the NVD, with SCAP, CPE, and CVSS, to track vulnerabilities and inform patching for security analysts.
Threat actors range from script kiddies to insiders, hacktivists, APTs, state actors, criminal syndicates, and competitors. Understand their access, motivations, and vectors like phishing, insider access, shadow IT, and cloud.
Explore cryptography concepts essential for security professionals and the Security+ exam, including encryption, hashing, confidentiality, integrity, and availability across transit, rest, and use; plus lightweight cryptography, quantum computing, and blockchain.
Learn how encryption converts plain text to ciphertext to protect data in transit, at rest, and in use, and how steganography hides data in plain sight within media.
Explore hashing as a one-way function that converts data of any size into a fixed-length digest to verify integrity, enabling file signing, password hashing, and data authenticity. Review major hashing algorithms like MD5 and SHA-1 and their successors SHA-256, SHA-384, and SHA-512, plus salting and HMAC for stronger security.
Explore secure protocols and key exchanges, including TLS handshake, SSH, LDAP over SSL, SFTP, and HTTPS. Learn how DNSSEC and SNMPv3 secure data on public networks.
Explore symmetric and asymmetric encryption, comparing key exchange, speed, and security; and learn how aes, des, 3des, blowfish, rc4, rsa, diffie-hellman, and digital signatures secure tls cipher suites.
Build and manage a public key infrastructure on Windows using Active Directory Certificate Services, including root and subordinate CAs, certificate issuance, and revocation via OCSP and CRL.
Understand certificates' role in encrypted communications, the PKI hierarchy, and types like self-signed, machine, user, and code signing, plus DV/OV/EV validations and formats such as DER, PEM, and PKCS.
Explore encryption keys, PKI and certificates for server authentication, key length, and exchanges (PSK, RSA, DH, ECC), plus key management and security measures like key renewal and destruction.
Ipsec secures data across public networks by establishing phase one and phase two security associations for site-to-site and remote access vpn, using esp for encryption and ah for authentication.
Explore identity, authentication, authorization, and accounting to control access; learn authentication factors (knowledge, possession, biometrics), multi-factor strategies, and security tools like TPM, HSM, password vaults, and geolocation as a factor.
Explore authentication methods, including directory services, federation and single sign-on, and learn about attestation, identity and service providers, and standards like X.500 with SAML, OpenID, and OAuth.
Explore connected, disconnected, and contactless tokens as authentication methods, including one-time passwords generated by hotp and totp, and understand their use, expiry, and security benefits.
Discover how biometrics authenticate users using fingerprints, voice, facial recognition, iris and retina, hand geometry, gait, and veins, and evaluate system accuracy with FRR, FAR, and CER.
Explore PAP and CHAP as authentication protocols, showing how PAP sends passwords in clear text while CHAP uses a challenge-response to keep credentials off the wire; MS-CHAPv2 enables mutual authentication.
Learn how the extensible authentication protocol enables flexible wireless authentication, including eap-tls and ttls, and how 802.1x uses a supplicant, authenticator, and radius for port-based security.
Explore RADIUS and TACACS+, open-standard authentication protocols powering centralizing authentication, authorization, and accounting. Learn how RADIUS uses udp ports 1812/1813 and TACACS+ uses tcp with full encryption and modular design.
Explore Kerberos, the time-sensitive authentication protocol used by Active Directory, and learn how the AS, KDC, and TGS issue TGTs and service tickets to access resources.
Learn how access control schemes protect resources by mapping subjects to objects using mandatory, discretionary, role-based, rule-based, and attribute-based models, with ACLs, implicit/explicit deny, conditional access, and PAM.
Explore account types, including administrator, standard user, guest, service, and shared accounts. Apply the principle of least privilege and secure management to protect systems.
Establish password policies with complexity rules, history, length, and expiration, and implement them through group policy in Windows Server to secure account management.
Explore account and access policies for user and computer accounts, including time-based logins, IP and geolocation restrictions, geofencing, and centralized management via Active Directory.
Strengthen application security by enforcing input validation with syntactic and semantic checks, adopting whitelisting and prepared statements, and using code signing, secure cookies, and fuzzing to test resilience.
Secure facilities with layered physical controls—from perimeter bollards and mantraps to alarms and closed-circuit television (cctv)—plus locks, guards, visitor logs, and two-person control, protecting air-gapped networks, vaults, and data centers.
Explore wireless security protocols from WEP to WPA3, compare encryption methods like RC4 and CCMP, and learn authentication methods, site surveys, and deployment best practices.
Discover secure data destruction techniques, from paper shredding and pulping to multi-pass overwriting per DoD 5220.22 (P4–P6) and gaussing with magnets, ensuring data cannot be recovered.
Learn endpoint protection fundamentals, including antivirus, behavior monitoring, heuristics and ai, plus edr and data loss prevention, with layered defenses like host firewalls and next-gen firewalls.
Hardening host systems by applying patches, changing defaults, and enforcing least privilege across OS, firmware, and applications. Secure features include UEFI, secure boot, TPM, encryption, firewall, antivirus, and registry protections.
Discover how unified endpoint management centralizes security across mobile devices and traditional workstations, integrating MDM, EMM, and MAM for BYOD, CYOD, and COPE deployment.
Master centralized mobile device management with an endpoint manager, enforcing policies for apps, connectivity, passwords, and compliance across iOS, Android, and Windows devices, including remote wipe.
Learn about mobile device connections, including cellular identifiers like IMEI and IMSI, Wi-Fi standards, NFC, infrared, Bluetooth, USB, GPS, and RFID, and key security concerns such as eavesdropping and spoofing.
Explore specialized systems like SCADA/ICS and embedded IoT devices, including Raspberry Pi, FPGA, and SoC, and assess security risks from weak cryptography, poor authentication, insecure defaults, patching, and physical access.
Learn how network segmentation enhances performance and security through VLANs, ACLs, and DMZs, with intranets, extranets, and a zero-trust mindset guiding secure traffic.
Explore how VPNs secure remote and site-to-site connections over public networks, including remote access and site-to-site setups, split-tunnel and full-tunnel, and encryption options like IPSec and AES.
Discover how forward and reverse proxies and load balancers secure networks by controlling access, caching, and availability, with NAT, DMZ, and virtual IP concepts.
Secure networks by using port security features like the spanning tree protocol and bpdu guard, DHCP snooping, and mac filtering, and employ port mirroring to monitor traffic.
Compare stateless and stateful firewalls, including how they inspect traffic and defend against syn flood attacks, and explore content filtering, url filtering, and nat gateways.
Learn the difference between network intrusion detection and intrusion prevention systems, including inline versus passive deployment. Identify detection methods: signature-based, heuristics, behavior-based, anomaly-based learning, and note false positives and negatives.
Explore virtualization basics, including host and guest machines, and hypervisors type 1 and 2. Learn virtual networking with NICs and switches, containers, and resource allocation for secure, scalable computing.
Learn cloud concepts such as on-demand self-service, broad network access, resource pooling, and rapid elasticity, and how providers like AWS, Azure, and GCP deliver isolated, measured computing services.
Explore cloud service types, focusing on software, platform, and infrastructure as a service, plus anything as a service with containers, desktop, database, and security as a service.
Explore cloud service models and how public, private, community, and hybrid deployments differ, including vendor options, private cloud connections, and transitions between on-premises and cloud infrastructure.
Compare cloud, edge, and fog computing for IoT, including real-time processing and IoT gateways. Understand software-defined networking with its three layers and OpenFlow REST APIs.
Explore cloud security controls, including resource policies, permissions, and least privilege, to protect cloud resources. Understand network segmentation with public and private subnets, secure web gateway, CASB, and VPC endpoints.
Explore hardware redundancy and fault tolerance to maximize availability through RAID levels 0, 1, 5, 10, SAN, multi-pathing, NIC teaming, clustering, load balancing, and power redundancy.
Examine hot, warm, and cold sites for disaster recovery, focusing on cost, restore time, location considerations, and vendor diversity to ensure business continuity.
Learn non persistence concepts such as last known good, known state baselines, system restore, and live boot media to revert configurations and recover boot states.
Explore backup and recovery strategies, contrasting full, differential, and incremental backups, and learn how archive bits, restore times, and media choices shape business continuity and disaster recovery.
Learn network reconnaissance and discovery with key tools such as ping, traceroute, pathping, ipconfig/ifconfig, arp, nslookup, dig, netstat, and nmap for host discovery.
Master packet capture for security using tcpdump and Wireshark to analyze FTP traffic and extract logs. Explore replay attacks with tcpreplay to test defenses.
Learn how vulnerability scans identify weaknesses and prioritize risk. Use credentialed or non-credentialed, intrusive or non-intrusive scans, and interpret false positives and false negatives with CVSS and CVE outputs.
Explore how SIEM and SOAR centralize log data, normalize events, and automate threat detection, incident response, and threat intel to secure complex networks.
Learn how penetration testing reveals exploitable vulnerabilities to test an organization’s resilience, distinguishing it from vulnerability assessments, and using white-box, black-box, and gray-box methods under defined rules of engagement.
Explore pentesting exercise types—red team offensive security, blue team defensive monitoring, purple team integration, and white team refereeing—covering scope, timeline, and post-exercise lessons learned.
Explore digital forensic concepts, including legal holds, order of volatility, data acquisition and preservation, chain of custody, hashing and provenance, and common forensic tools for eDiscovery.
Explore investigational data sources for incident response, including SIEMs, NetFlow/IPFIX, and protocol analyzers. Access Windows and Linux logs, centralize with syslog, and use metadata tools like exiftool.
Follow an incident response process, including preparation, identification, containment, eradication, and recovery. Leverage SIEM, indicators of compromise, alerts, backups, and lessons learned to detect, contain, eradicate, recover, and improve resilience.
Formulate an incident response plan by building an incident response team and defining authority and stakeholders. Outline business continuity, disaster recovery, and communication strategies, plus tabletop, walkthrough, and simulation exercises.
Explore attack frameworks to threat model your organization, including MITRE attack framework, the diamond model of intrusion analysis, and the cyber kill chain, to identify adversaries, tactics, techniques, and defenses.
Define security controls and how they minimize risk across CIA—confidentiality, integrity, availability. Categorize controls into administrative, technical, and physical, and apply seven control types to protect assets.
Explore how regulations, standards, and frameworks guide compliance, risk management, and security controls. Learn about PCI DSS, NIST CSF, RMF, ISO 27001/27002/27701/31000, SOC reports, CSA CCM, and CIS controls.
Explores the GDPR, defines personal data and the roles of data controller, processor, and data protection officer, and covers consent, breach notification, DSAR, and the right to be forgotten.
Explore the personnel-focused elements of organizational policies, including job rotation, mandatory vacation, separation of duties, least privilege, on boarding and off boarding, background checks, NDAs, social media analysis, and training.
Explore third party and supply chain risk, including vendor and business partner management, NDAs, MOUs, SLAs, and BPAs. Learn the PPRR risk model—prevention, preparedness, response, and recovery—for resilient operations.
Understand how data ownership drives classification and categorization, and explore data governance with ISO 38500, data lifecycle, retention policies, and the necessary infrastructure and roles.
Explore credential policies and identity management, including MFA, BYOD, and privilege accounts. Examine change management, change control, and asset management with CMDB and asset lifecycle.
Master foundational risk management concepts, including risk, threat, vulnerability, likelihood, impact, residual risk, and controls, guided by NIST SP800-30R1, for enterprise security.
Learn the risk assessment process, from preparation to communication and maintenance, and explore external and internal risk types, licensing challenges, and risk management strategies like accept, avoid, transfer, and mitigate.
Explore risk management concepts, including risk analysis, risk assessment, risk register, and the risk matrix, and learn to apply quantitative and qualitative methods like ALE, SLE, and ARO.
Explore risk management with business impact analysis to differentiate business continuity and disaster recovery, and apply RPO, RTO, WRT, and MAD/MTD for prioritized recovery.
Explore privacy and data sensitivity by examining breaches, data types, and classification—learn breach consequences, notification requirements, GDPR and HIPAA basics, and risk management.
Balance data protection with usability by applying privacy enhancing techniques such as data minimization, data masking (static, deterministic, on-the-fly, dynamic), and tokenization.
Identify roles and responsibilities for privacy and data sensitivity, from data subject through data owner, controller, processor, custodian, steward, to the data protection officer, including classification, access, and compliance.
Examine the information life cycle for privacy and data sensitivity—from creation to destruction—including storage, use, sharing, archiving, and secure disposal, plus privacy impact assessments.
The CompTIA Security+ certification is a vendor-neutral cybersecurity certification that validates the knowledge and skills of IT professionals in the area of network security, compliance, and operational security. The certification is designed to test the essential security knowledge and skills required to perform core security functions and pursue an IT security career.
The CompTIA Security+ certification is designed for IT professionals who want to specialize in network security, cybersecurity, and IT risk management. The certification validates their knowledge and skills in these areas and demonstrates their ability to secure network infrastructure, identify and mitigate risks, and respond to security incidents.
CompTIA also recommends that candidates have a basic understanding of the following topics:
Network protocols and architecture
Network hardware and operating systems
General security concepts, such as authentication and authorization
Basic cryptography concepts, such as symmetric and asymmetric encryption
Common security threats and vulnerabilities
While these topics are not required to take the Security+ exam, having a basic understanding of them can help candidates prepare for the certification exam and increase their chances of success.
Overall, the CompTIA Security+ certification is suitable for anyone who wants to gain a foundational understanding of cybersecurity concepts and best practices and advance their career in the IT security field.
"This course qualifies for CompTIA continuing education units (CEUs)."
Available CEUs* for this Course Series : 28
By completing this course series, you can earn up to 28 CEUs.
(*CEUs are entirely dependent on the organization you are applying)