🛡 Security+ 1.1–1.4 — Summarized Notes
1.1 — Fundamental Security Concepts 🔴 HIGH
CIA Triad
The CIA Triad is the foundation of information security.
Concept | Meaning | Think |
|---|---|---|
Confidentiality | Only authorized subjects can access information | Who can see it? |
Integrity | Information cannot be modified without authorization | Can I trust it? |
Availability | Authorized users can access information when needed | Can I get to it? |
🧠 Memory trick: CIA = Keep it Secret, Correct, and Available
Non-repudiation 🔴
Non-repudiation prevents someone from denying that they performed an action.
Examples:
Sending a message
Modifying data
Deleting information
Think: "You can't say you didn't do it."
2. InfoSec Roles 🟡
Know the basic responsibilities:
CSO — Senior security leader
CIO — IT leadership, compliance, overall information systems
CTO — Technology leadership and aligning IT with business goals
ISSO — Maintains the day-to-day security posture of a system
SOC — Continuously monitors and defends systems/networks
CIRT/CSIRT — Responds to security incidents
SOC vs. CIRT 🔴
SOC = Detect/Monitor
CIRT = Respond
🧠 Think:
SOC sees the fire → CIRT responds to the fire.
3. AAA + Identification 🔴 HIGH
Access control uses AAA:
Identification
"Who are you?"
Usually a username/account name.
Authentication
"Prove it."
You provide credentials/factors such as a password.
Authorization
"What are you allowed to do?"
Determines permissions to:
Files
Applications
Databases
Networks
Servers
Printers
Accounting
"What did you do?"
Records access and activity, including successful and unsuccessful attempts.
Also called auditing.
🧠 Easy sequence:
Identification → Authentication → Authorization → Accounting
Who are you? → Prove it → What can you do? → What did you do?
⚠ Exam trap: Authentication does not determine what you're allowed to access. That's authorization.
Also remember that devices can be subjects, not just people. A laptop may need to authenticate before joining a secured Wi-Fi network.
4. Security Posture & Gap Analysis 🔴
Security Posture
An organization's overall cybersecurity strength and ability to:
Prevent threats
Detect threats
Correct threats
Security Framework
A framework provides organized:
Best practices
Guidelines
Standards
It helps an organization understand its current security status and determine where it needs to improve.
Gap Analysis
Gap analysis = Current state vs. Desired state
It identifies the difference between an organization's current security posture and its desired security goals.
🧠 Think:
"Where am I now?" → "Where do I need to be?" → "What's the gap?"
⚠ Exam trap: A framework helps an organization work toward compliance, but using a framework alone does not automatically make an organization compliant.
5. Zero Trust 🔴 HIGH
Core idea
Never implicitly trust anything.
Zero Trust assumes:
Users may be compromised
Devices may be compromised
Internal networks aren't automatically safe
A breach is always possible
Therefore, users, devices, applications, and connections are continuously evaluated and authorized.
Key Zero Trust concepts
Least privilege
Give a subject only the access they actually need.
Adaptive authentication
Access decisions consider context such as:
Who is requesting?
Where are they coming from?
What are they requesting?
What is the risk?
Threat scope reduction
Reduce the attack surface by limiting:
Points of access
Threat vectors
Available resources
Policy-driven access control
Access decisions are enforced using policies and rules.
6. Zero Trust Components 🟡/🔴
Policy Engine
Makes the access decision.
Allow, deny, or revoke access.
It can use information such as:
Policies
Logs
Threat intelligence
Compliance information
SIEM data
Policy Administrator
Carries out the decision.
It communicates with the enforcement point and can establish or terminate sessions.
Policy Enforcement Point (PEP)
Controls the actual connection.
It establishes, monitors, and terminates connections between the subject and resource.
🧠 Memory trick:
Engine = Decide
Administrator = Tell
PEP = Enforce
7. Control Plane vs. Data Plane 🟡
Control Plane
Decides how traffic should move.
Responsible for things such as:
Routing
Routing protocols
NAT tables
Network topology
Policies/rules
Data Plane
Actually moves the traffic.
🧠 Control = Think
Data = Do
⚠ Don't confuse this with physical network components. These are logical concepts describing network processes.
8. Deception Technologies 🔴
Deception technologies use decoys to attract attackers and gather intelligence.
Honeypot
One decoy system/resource.
Designed to look attractive to attackers.
Honeynet
Multiple interconnected honeypots.
Simulates a network.
Honeyfile
Fake file.
Made to look like it contains sensitive information.
Useful for detecting data theft.
Honeytoken
Fake resource that triggers an alert when accessed.
Could be:
User account
API key
Access token
Document
Database record
🧠 Memory trick:
Pot = one
Net = network
File = file
Token = credential/resource
9. Security Control Categories 🔴 HIGH
There are 4 categories based on how the control is deployed.
Technical
Implemented using:
Hardware
Software
Firmware
Examples:
Firewall
Encryption
Antivirus
ACL
Managerial
Management oversight.
Examples:
Security evaluations
Risk identification
Control effectiveness reviews
Operational
People are primarily responsible for implementing/managing it.
Examples:
Security guards
Security awareness training
Physical
Protects physical areas/assets.
Examples:
Locks
Cameras
Fences
Alarms
Lighting
🧠 Memory trick:
Technical = Technology
Managerial = Management
Operational = People
Physical = Physical environment
10. Security Control Types 🔴 HIGH
There are 6 functional types.
Preventative
Stops the incident before it happens.
Examples:
Firewall
ACL
Encryption
Antivirus
System hardening
Deterrent
Discourages someone from attacking.
Examples:
Warning signs
Security awareness
Policies
Visible security controls
Detective
Detects an attack/incident.
Examples:
Audit logs
IDS
Corrective
Fixes/reduces damage after an incident.
Examples:
Backups/recovery
Disaster recovery
Patch management
Compensating
Alternative control when the primary control isn't viable.
Example:
Primary control can't reasonably be implemented → use another control that provides equivalent or greater protection.
Directive
Tells/guides people what they should do.
Examples:
Policies
Training
SOPs
Regulations
🔥 Control Types — Quick Recognition
If the question says... | Think... |
|---|---|
Stop/prevent | Preventative |
Discourage | Deterrent |
Detect/identify | Detective |
Fix/recover | Corrective |
Alternative/substitute | Compensating |
Guide/direct employees | Directive |
⚠ Big exam trap:
Category ≠ Type
For example:
A firewall is a technical control and usually preventative.
One describes how it's implemented; the other describes what it does.
11. Physical Security 🔴/🟡
Physical security protects:
Buildings
Servers
Networking equipment
Cabling
Infrastructure
Other physical assets
It can also enforce AAA.
Common physical controls
Bollards
Prevent vehicles from entering protected areas.
Mantrap / Access Control Vestibule
Two interlocking doors.
First door must close before second opens.
Helps prevent unauthorized physical entry.
Access badge
Physical authentication credential.
Can use RFID, NFC, QR codes, or magnetic stripe.
Fencing
Prevents or restricts physical access.
Lighting
Improves visibility and can deter intrusion.
Video surveillance
Monitors/records physical activity.
Can provide evidence.
Security guards
Deter and respond to physical threats.
12. Security Sensors 🟡
Motion
Detects movement.
Audio/noise
Detects sound or vibration.
Example: breaking glass
Circuit
Detects an open/closed state.
Example: door or window
PIR — Passive Infrared
Detects heat energy emitted by objects.
Pressure
Detects weight/pressure.
Example: floor mat.
Microwave
Uses microwave signals to detect movement.
Ultrasonic
Uses ultrasonic sound waves to detect movement.
13. Change Management 🔴 HIGH
Change management = controlled process for making changes while minimizing disruption and security risk.
Examples:
Software updates
OS/firmware upgrades
Security control installation
Hardware upgrades
Network configuration changes
Cloud migrations
Change Management Process
Know the important concepts:
Change Request / RFC
Formally proposes what needs to change.
Impact Analysis
Determines how the change could affect:
Users
Business processes
Systems
Security
Downtime
CAB — Change Advisory Board
Reviews complex/high-risk changes and helps:
Assess
Prioritize
Authorize
Schedule
Test Environment
Test the change before deploying it fully.
Backout Plan 🔴
Defines how to return to the previous/original state if the change fails.
🧠 Exam clue:
"The update caused problems. How do we restore the previous configuration?"
Backout plan.
14. Other Change Management Concepts 🟡
SOP
Standard Operating Procedure
Detailed step-by-step instructions for performing a task consistently.
Maintenance Window
Scheduled period when maintenance/change can occur with minimal business disruption.
Downtime
Period when a system or business process is unavailable.
Legacy Application
Older software that may be:
Outdated
Specialized
Unsupported
Business-critical
Legacy applications require careful research before making changes.
Dependency
One application/service relies on another.
Example:
Application A requires Service B to work.
If B goes down, A may also stop working.
15. Allow Lists vs. Deny Lists 🟡
Allow List
Only approved items are allowed.
More restrictive.
Deny List
Specified items are blocked.
Everything not on the list is generally allowed.
🧠 Memory trick:
Allow = "Only these."
Deny = "Not these."
⭐ What I'd Focus on First
If you were studying this chapter tonight, I'd prioritize:
🔴 Must Know
CIA Triad
Non-repudiation
Identification vs Authentication vs Authorization vs Accounting
Security posture + gap analysis
Zero Trust
Policy Engine / Administrator / PEP
Honeypot / Honeynet / Honeyfile / Honeytoken
4 security control categories
6 security control types
Preventative / Detective / Corrective / Compensating
Change request / impact analysis / CAB / backout plan
Allow list vs deny list
🟡 Know Well
InfoSec roles
Control plane vs data plane
Physical security controls
Security sensors
SOP
Maintenance windows
Legacy applications
Dependencies
The big picture of this chapter is basically:
CIA → AAA → Zero Trust → Security Controls → Physical Security → Change Management