
Explore the CompTIA Security+ SY0-701 course introduction with Jay Cotrone, and learn security fundamentals, CIA triad, IAM, risk, incident response, and cryptography through engaging visuals and quizzes.
Explore the CompTIA Security+ CE 0701 exam details, including question types, timing, and scoring, and examine performance based questions and network scenarios like dmz and acl configurations.
You will learn about fundamental security concepts like the CIA Triad, an overview security awareness, risk and vulnerability management.
Coverage of fundamental secuirty terms that are a foundation for the remainer of the course.
Coverage of Identification, Authentication, Authorization, and Accounting (IAAA) which is the process of recognizing individuals, verifying their identity, granting them appropriate access privileges, and keeping track of their activities.
Coverage of Asset Managment planning and processing.
Explore the asset life cycle from planning and budgeting through acquisition, assignment, use, maintenance, decommissioning, data sanitation, and final disposal.
Explore asset types from physical and data assets to networks and intellectual property, and learn data ownership, access controls, and the benefits of asset management for compliance.
Identify and acquire needed assets and services in alignment with business objectives, evaluate suppliers for security and quality, and manage the procurement process from RFP or RFQ to inspection.
Develop a comprehensive asset inventory and classification by identifying assets, detailing descriptions, locations, acquisition and maintenance data, and including network and software enumeration.
Explore change management by planning, evaluating, and implementing organizational and network changes with a formal process, impact analysis, and a Change Advisory Board, plus documentation and rollback plan.
Explore identity and access management, defining unique identities, authentication, authorization, and single sign-on. Learn provisioning and deprovisioning, access control lists, and identity proofing options like biometric and knowledge-based methods.
Learn how different identity and access management systems interoperate to share data, enable single sign-on, synchronize user provisioning, and enforce role-based access, MFA, and attestation for secure access.
Authenticate devices through 802.1x network access control by validating supplicant identities with EAP via an authenticator and authentication server, enabling dynamic access and preventing unauthorized connections.
Explore password policies that enforce strong credentials through length and complexity, history and age controls, and use password managers to securely store, generate, and autofill unique passwords.
Explore passwordless authentication, using biometrics, security keys, OTP, and push notifications to verify identity without passwords, enabled by FIDO, cryptographic keys, and secure enclaves.
Master privileged access management by implementing just-in-time access, password vaulting, and ephemeral credentials to control and monitor elevated privileges across critical systems and data.
Identify, assess, and mitigate risks related to information security and cyber threats to protect assets, systems, networks, and data through enterprise, financial, operational, and regulatory risk management.
Identify privacy risks that threaten personal information and compliance with privacy laws and regulations, including data breaches, unauthorized access, surveillance, privacy policy violations, and encryption and access controls.
Understand how privacy compliance aligns practices with laws like GDPR and CCPA, covering consent, notices, data minimization, and lawful processing to protect personal data.
Identify risks through risk identification techniques by applying SWOT analysis, vulnerability scanning, and root cause analysis to understand weaknesses, threats, and historical patterns, enabling proactive risk mitigation.
Categorize risks by type and source, grouping technological, operational, strategic, financial, compliance, reputational, and environmental risks for clearer analysis and targeted mitigation.
Differentiate risk analysis from risk assessment, and apply qualitative and quantitative methods to calculate SLE, ALE, asset value, and exposure factor for informed risk management.
Perform risk impact analysis by defining the analysis scope, identifying stakeholders, and assessing magnitude, likelihood, and recovery time objective and maximum tolerable downtime.
Rank risks by severity and likelihood using a business impact analysis to identify critical functions and dependencies, then assign scores with MTBF, MTTR, and MTBSI metrics to guide mitigation.
Identify and assess risks with proactive and reactive strategies to prevent and mitigate threats. Explore risk transfer, acceptance, exemption, avoidance, and mitigation with methods like risk workshops and data analysis.
Monitor identified risks by collecting data from internal and external sources, using quantitative and qualitative indicators, and updating risk registers to align with organizational objectives.
Communicates identified risks to stakeholders, outlines risk nature, impact, likelihood, and mitigations; explains business impact analysis, RTO, RPO, MTTR, MTBF, risk registers, and monitoring to support informed decisions.
Assess third-party risk by identifying vendors, classifying by risk, and evaluating security controls and compliance across the supply chain, including audits and penetration testing.
Assess third-party risks by identifying and categorizing vendors, reviewing security controls, and evaluating compliance; cover supply-chain analysis, vendor assessment, and agreement types such as mou, moa, sla, nda, and bpa.
Learn how a structured incident response process detects, contains, mitigates, and recovers from cybersecurity incidents, supported by a cross-functional team from management to forensics and communications.
Learn how to design and implement an incident response plan that detects, reports, categorizes, contains, investigates, communicates, recovers, and improves security to minimize downtime and regulatory risk.
Organizations prepare an incident response framework, detect and analyze incidents, contain and eradicate threats, recover operations, and apply lessons learned to prevent future breaches.
Enhance incident response readiness through tabletop exercises, simulations, and capture the flag challenges, featuring red, blue, white, and purple teams to minimize impact and protect assets.
Learn to plan and implement disaster recovery with hot, warm, cold, and cloud sites, parallel processing or full cutover, and robust backups, system images, and restoration order to minimize downtime.
Explore how malware attacks use malicious software to compromise systems, including viruses, ransomware, Trojan horses, worms, spyware, keyloggers, rootkits, backdoors, and APTs.
Explore how various network attacks compromise availability, integrity, and confidentiality. Learn about DDoS, DNS amplification, IP spoofing, man-in-the-middle, credential replay, DNS cache poisoning, XSS, and CSRF.
Explore how cryptographic and password attacks threaten encryption and credentials, including downgrade attacks, SSL stripping, and common cracking methods, with mitigations like strong algorithms, key management, and audits.
Uncover how social engineers manipulate trust and fear to obtain sensitive information or access. Explore phishing, spearphishing, pretexting, baiting, misinformation, and deception techniques that exploit authority and emotions.
Identify threat actor types from ethical (white hat) and malicious (black hat) hackers to hacktivists, cyber terrorists, insiders, organized crime, and nation-state actors, and examine their capabilities.
Examine threat actor attributes, from insider threats with privileged access to external actors, their tools, funding, and capabilities, and trace sophistication from low to nation-state levels.
Identify threat actor motivations, including financial gain, espionage, political beliefs, and disruption, driving data exfiltration, blackmail, ransomware, extortion, and denial of service against organizations.
Nation state actors, or state-sponsored hackers, pursue political, economic, or military objectives through espionage, APTs, zero-day exploits, and targeted sabotage, including supply chain and disinformation campaigns.
Identify threat vectors as pathways cyber threats use to exploit vulnerabilities, including message-based phishing, image-based stenography, voice-based robocalls, and web, network, and physical vectors.
Explore web based threat vectors, including malicious websites, phishing, watering hole attacks, typosquatting, drive by downloads, cross-site scripting, SQL injection, man in the middle, and malvertising.
Explore phishing techniques such as pretexting, prepending, spoofing, and urgency, plus variants like vishing, smishing, spearfishing, and whaling, to recognize deceptive emails and protect passwords and personal data.
Advance threat information processing by aggregating and enriching data, analyzing patterns, and interpreting insights to mitigate risks. Leverage sharing organizations and protocols like taxi and sticks to strengthen defenses.
Proactively search logs, network traffic, and data to detect indicators of compromise beyond traditional defenses, then plan, collect data, test hypotheses, remediate, and monitor continuously with a diverse team.
Apply vulnerability management by identifying and categorizing vulnerabilities through assessment, scans, and asset inventory. Prioritize by severity, apply patches, implement mitigations, and monitor continuously to reduce risk and alert stakeholders.
Identify common vulnerabilities in computer systems, software, and networks. Include software bugs, misconfigurations, weak passwords, buffer overflows, insecure protocols, input validation gaps, and supply chain and vendor risks.
Explore software and hardware vulnerabilities, including code injection, DLL infections, unverified code, and firmware risks, and learn defenses like input validation, secure coding, patching, and security controls.
Mitigate cloud service vulnerabilities by enforcing strong authentication, robust access controls, encryption, and regular security assessments to prevent data breaches and service disruptions.
Identify virtualization vulnerabilities such as hypervisor flaws, unsecure VM images, weak authentication, and VM sprawl, and mitigate with updates, hardening, access controls, and continuous monitoring.
Identify and mitigate mobile device vulnerabilities across OS, apps, networks, and hardware by enrolling devices in a mobile device management system, using official app stores, encryption, and secure network practices.
Identify wireless network and Bluetooth vulnerabilities, including rogue access points, eavesdropping, and man-in-the-middle attacks, and Bluetooth threats like Blueborne, Bluejacking, Bluesnarfing, Bluebugging, with weak encryption such as WEP and Tkip.
Identify and assess vulnerabilities across systems, networks, and applications using scanning, audits, penetration testing, fuzz testing, and application security testing; validate results with false positives and negatives and SIEM insights.
Classify vulnerabilities by characteristics, impact, and causes, assigning labels or scores to prioritize risk. SCAP standardizes tool communication and CVE/CVSS identifiers support risk assessment.
Identify vulnerabilities through assessments and automated scans, assess risk, and plan remediation using patches, configuration changes, and security controls to reduce attack exposure.
Explore penetration testing as an active, proactive security assessment that simulates real-world attacks to identify vulnerabilities and evaluate security controls, with offensive red team and defensive blue team perspectives.
Explore the planning, reconnaissance, vulnerability assessment, exploitation, post-exploitation, documentation, and debrief and remediation phases of penetration testing, plus the responsible disclosure program.
Explore virtualization basics, including hypervisors—type one bare metal and type two—virtual networks, network function virtualization, and containerization with Docker and Kubernetes, highlighting security, scalability, and portability.
Explore wireless security measures that protect networks from unauthorized access by evolving encryption from WEP to WPA3, including TKIP, AES-CCMP, 802.1X, and the Dragonfly handshake.
Explore wireless authentication protocols that verify the identities of devices and users connecting to a network, including wps vulnerabilities, easy connect, and eap variants such as eap-tls, peap, and eap-fast.
Explains how microservices break apps into independent services, each with its own code, data, and resources, enabling scalable, agile development and secure isolation with CI or CD pipelines.
Explore internet of things IoT devices, their embedded sensors and connectivity, enabling data exchange, remote monitoring, and automation, while applying patching, authentication, and encryption for security.
Explore industrial control systems and SCADA architectures, including sensors, PLCs, HMIs, and safety features, and learn how real-time monitoring, data logging, and secure networks safeguard critical infrastructure.
Conduct a gap analysis by comparing the current security posture with the desired state, identify gaps and root causes, implement improvements, monitor results, and document outcomes.
Enhance system reliability through redundancy, fault tolerance, and proactive monitoring to maintain high availability. Implement load balancing, failover, clustering, and regular backups to minimize downtime and safeguard data during disruptions.
This lecture explains how redundancy and resilience ensure availability and continuity by duplicating network paths, devices, storage, services, and sites, plus fault-tolerant design, monitoring, and disaster recovery planning.
Discover deception and disruption technology in cybersecurity, including decoys, honeypots, fake data, honey tokens, and active defense with fake telemetry to deter and detect attackers.
Explore control types and how preventative, detective, corrective, compensating, deterrent, recovery, and directive controls mitigate risk before, during, and after incidents, such as access controls, encryption, logs, and incident response.
Apply technical controls such as firewalls, intrusion detection and prevention systems, and NAC to protect assets, detect threats, and enforce access policies.
Learn how managerial controls, from security policies and procedures, drive strategic planning, risk assessment, and security awareness training, with policies on acceptable use, credentials, change management, incident response, remote access.
Physical controls safeguard assets and people by preventing unauthorized access and theft. Learn about access control systems, guards, video surveillance, barriers, alarms, secure storage, lighting, signage, and visitor management.
Deterrent controls use visible signals to discourage attackers, combining cameras, warning signs, alarms, guards, access controls, and lighting to create a layered, proactive security approach.
Identify and implement preventative controls, including access controls with authentication and authorization, encryption, IPS, firewalls, antivirus, and EDR, plus physical measures like secure entryways, fences, bollards, and locks.
Explore corrective controls that address incidents and vulnerabilities, from incident response and patch management to system restoration, data recovery, and user training, to restore security and prevent repeats.
Discover compensating controls as alternative measures that provide equivalent security when primary controls are infeasible, including multifactor authentication, network segmentation, data encryption, and security monitoring.
Explore directive controls that provide clear instructions to enforce security policies and guide behavior. Implement policies and procedures, training, access control, change management, incident response, audits, regulatory frameworks, and standards.
Explore enterprise security mitigation techniques to protect assets and data. Implement risk assessment, access controls, encryption, network segmentation, isolation, ids/ips, security awareness training, incident response, vulnerability management, and continuity planning.
Explore optimal placement of technical control appliances—firewalls, intrusion detection and prevention systems, and VPN gateways—across perimeters, DMZs, and internal segments to enhance security, monitoring, and threat prevention.
Position unified threat management devices at network perimeter and data center junctions to monitor traffic and enforce policies. Enable threat detection, control access, and protect sensitive data through this placement.
Learn logical network security segregation through segmentation, network zones, choke points, and secure gateways to enforce access controls and encrypt inter-segment traffic, reducing attack surface and limiting lateral movement.
Define and enforce configuration baselines with predefined security settings to reduce the attack surface and ensure compliance with security best practices and regulatory standards.
Learn detection methods in cybersecurity, from signature-based and anomaly-based to behavioral and heuristic techniques, plus user behavior analytics, URL scanning, content categorization, and block and reputation rules.
Learn how security monitoring continuously observes systems, networks, and logs, using tools like siem, vulnerability scanners, antivirus, and netflow to detect, prioritize risks, and support compliance.
Automate processes with tools and security information and event management systems to streamline threat detection, incident response, patch management, and log analysis, while enabling threat intelligence sharing and user provisioning.
Learn how orchestration coordinates multiple automated tasks to streamline security operations, contrasting automation with orchestration and highlighting use cases like user and resource provisioning, guardrails, security groups, and automated ticketing.
Implement secure baselines and deploy hardening, access controls, and patch management to protect processes, devices, and networks, while continuously monitoring and educating users to prevent threats.
Explore how SD-WAN and SASE secure and optimize connectivity for remote sites and cloud apps, with centralized policy control, dynamic routing, and cloud-based security services.
Explore cloud security fundamentals across CASBs, containers, serverless, and compliance. Learn to deploy secure configurations, encryption, access controls, and incident response to protect data, apps, and infrastructure in cloud environments.
Explore how boards, committees, and government entities shape information security governance through policies, guidelines, standards, frameworks, risk management, change management, onboarding and offboarding, and incident response playbooks.
Explore how security policies establish guidelines and rules to protect information systems, defining responsibilities, data classification, access control, incident response, disaster recovery, security awareness, and business continuity.
Explore how security audits and assessments identify vulnerabilities and strengthen an organization's security posture. Learn about risk and vulnerability assessments, penetration testing, audit committees, and internal, external, and third-party audits.
Navigate regulatory compliance through audits and assessments across information security, physical security, risk management, and compliance, uncovering gaps before penalties such as fines, sanctions, or reputational damage.
Learn how regulatory compliance monitoring ensures adherence to laws, regulations, and industry standards by monitoring activities, policies, and procedures to protect data privacy and security, minimizing legal and financial risk.
Define and implement managerial security using policies, procedures, and risk management to protect information technology assets, govern access, change management, and incident response and training.
Develop and sustain security awareness training to educate employees on best practices and security behaviors. Use phishing simulations and ongoing assessments to reduce security incidents.
Identify phishing emails by checking sender addresses, generic greetings, grammar, urgency, malicious links, and suspicious attachments. Implement steps to respond: avoid clicking, report to IT, delete, and educate others.
Explore phishing victim behavior across unintentional, risky, and unexpected actions and review tools like EDR, DLP, IDS, IPS, SIEM, and UEBA for detection and prevention.
Explore cryptography fundamentals, including encryption and decryption, symmetric and asymmetric schemes, block and stream ciphers, hashing, and PKI concepts, with examples like AES, DES, RSA, ECC, and post-quantum cryptography.
Explore how digital certificates secure communications and verify identity within a PKI, using public keys, certificate authorities, and trust chains for code signing, web TLS, and email.
Learn how certificate revocation validation protects security by checking revoked certificates via CRLs and real-time OCSP responses, ensuring certificates are current and trusted.
Explore how symmetric encryption uses a shared key to encrypt and decrypt data, emphasizing key management, block and stream ciphers, and AES and DES family.
Learn how storage and transport encryption protect data at rest and in transit, covering file, volume, full disk, and database encryption, TLS, and IPsec.
Explore hashing as a one-way function that yields a fixed-size hash value to verify data integrity, using algorithms such as MD5, SHA-1, SHA-256, SHA-512, SHA-3, and RIPEMD.
Explore private key security and key escrow with a trusted escrow agent within a public key infrastructure, applying M of N threshold cryptography for key availability and recovery.
Enroll in our course today to learn the details you need to get certified!
Our comprehensive cybersecurity CompTIA Security Plus SY0-701 course is taught by Jay Cotrone. Jay has held a cybersecurity professional position for 10 years and has been a technical instructor for over 24 years. Jay has used the knowledge he has gained teaching cyber security to incorporate into this course, proven benefits for official exam success.
Your knowledge of terms, study facts, acronyms and understanding processes will give you an advantage when taking official exams.
In addition to videos, included in each section of the course are Section Reviews and Section Acronym Lists. Terms and study facts are covered in the video lectures and summarized in the Section Reviews. The Acronym Lists can help you remember important acronyms.
There is a Section Quiz at the end of each section to test your retention of the section information.
This course includes multiple modalities utilizing visual and audible learning methods,
including topic details on screen, synchronized with lecture audio to improve retention.
This course also includes on-screen animations that enhance your understanding of processes.
Our complete training course covers the exam objectives and details, essential for passing the official exam.
This course is divided into 12 Sections: Here are a few topics covered in each section.
· Security Fundamentals
o Fundamental security concepts
o CIA Triad
o Fundamental security terms
o Identification, Authentication, Authorization & Accounting
· Asset Management
Asset Management
Asset Types
Asset Acquisition & Procurement
Asset Inventory & Classification
Asset Lifecycle
Change Management
· Identity & Access Management
o Identity & Access Management
o IAM Auditing & Logging
o Federated Authentication
o 802.1x Authentication
o IAM Processes & Protocols
o Multifactor Authentication
o Password Policies & Managers
o Passwordless Authentication
· Risk Management
o Risk Types
o Risk Identification
o Risk Assessment
o Risk Analysis
o Risk Prioritization
o Privacy Compliance
o Risk Monitoring
o Third-Party Risk Assessment
· Incident Response, Business Continuity & Disaster Recovery
o Incident Response Plans
o Incident Response Process
o Digital Forensics
o Business Continuity Planning
o Incident Response Training
o Disaster Recovery
· Attacks, Threats & Vulnerabilities
o Malware Attacks
o Network Attacks
o Application Attacks
o Threat Actor Types, Attributes & Motivations
o Threat Vectors
o Threat Intelligence
o Vulnerability Management
o Software & Hardware Vulnerabilities
· Enterprise Security
o Wireless Security
o Software Defined Networking
o Infrastructure as Code
o Serverless Architecture
o Internet of Things Devices
o ICS & SCADA Systems
o Secure Network Strategies
o Zero Trust
o Control Types
· Security Governance & Security Training
o Security Policies
o Security Audits & Assessments
o Regulatory Compliance
o Security Awareness Training
o Phishing Identification Training
o Phishing Victim Behavior
· Cryptography & PKI
o Cryptography Fundamentals
o Public Key Infrastructure
o Certificate Authorities
o Digital Certificates
o Symmetric & Asymmetric Encryption
o Hashing
o Physical Key Security
· Application & Data Security
o Application Security
o Application Vulnerabilities
o Application Security Analysis
o Data Management
o Data Location Planning
o Data Loss Prevention
o Data Privacy Technologies
o Data Roles & Responsibilities
o Data Lifecycle
· Endpoint Security
o Mobile Device Application Vulnerabilities
o Securing Mobile Devices
o Mobile Device Deployment Models
o Mobile Device Connection Methods
o Securing Hosts
o Endpoint Detection & Response
o Securing Workstations
o Securing Servers
· Physical Security
o Physical Security
o Secure Entry
o Video Surveillance
o Sensors & Alarms
o HVAC Security
o Power Redundancy
The above is just a summary of section topics. This is a very comprehensive corse and there are many more topics covered throughout the course. To see the extent of topics covered, please refer to the course video list.
We know that this cyber security course will give the knowledge of the official exam objectives and details you need to pass the Security+ SY0-701 exam.