CompTIA Security+ Lessons
Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.
- Security controls: the four categories and the six typesObjective 1.1
- A lab you can break safely, and why your laptop is not it
- CIA, AAA and non-repudiation, stated precisely enough to be usefulObjective 1.2
- Zero trust, and the deception technology that sits beside itObjective 1.2
- Change management, which is a security control and is examined as oneObjective 1.3
- PKI, encryption and the key management that decides whether any of it worksObjective 1.4
- Hashing, digital signatures, obfuscation and blockchainObjective 1.4
- Threat actors, sorted by what they can afford rather than by how scary they soundObjective 2.1
- Motivations, shadow IT, and the threat that already has a badgeObjective 2.1
- Message, voice and file-based vectors, and the social engineering behind themObjective 2.2
- Unsecure networks, supply chain, and the software you did not writeObjective 2.2
- Application, web and operating-system vulnerabilitiesObjective 2.3
- Hardware, mobile, virtualisation, cloud and supply-chain vulnerabilitiesObjective 2.3
- Recognising malware by the evidence it leavesObjective 2.4
- Password and cryptographic attacks, and the controls that end themObjective 2.4
- Network, application and physical attack indicatorsObjective 2.4
- Mitigation techniques, chosen for the vulnerability in front of youObjective 2.5
- On-premises, cloud and virtualisation, compared by where the risk landsObjective 3.1
- IoT, ICS/SCADA, embedded systems and infrastructure as codeObjective 3.1
- Device placement, security zones and attack surfaceObjective 3.2
- Firewalls, appliances and selecting the control that fitsObjective 3.2
- Secure communication and access: VPN, tunnelling and remote workObjective 3.2
- Data types, classification, and the protection each class earnsObjective 3.3
- High availability, site resilience and powerObjective 3.4
- Backups, testing, and continuity of operationsObjective 3.4
- Secure baselines, and hardening the targets that appear on the examObjective 4.1
- Wireless, mobile deployment, application security and sandboxingObjective 4.1
- Asset management, from purchase order to certificate of destructionObjective 4.2
- Vulnerability management, end to endObjective 4.3
- Alerting and monitoring, and the tools CompTIA namesObjective 4.4
- Modifying firewalls, IDS/IPS and the filtering layersObjective 4.5
- DLP, NAC, EDR/XDR and email securityObjective 4.5
- Provisioning identity, single sign-on and federationObjective 4.6
- Multifactor authentication, password concepts and privileged accessObjective 4.6
- Automation and orchestration, and when not to automateObjective 4.7
- The incident response process, and the preparation that decides the outcomeObjective 4.8
- Root cause analysis, threat hunting and digital forensicsObjective 4.8
- Reading log data and other sources to support an investigationObjective 4.9
- Governance structures, and who is allowed to decideObjective 5.1
- Policies, standards, procedures and guidelines, and the difference between themObjective 5.1
- Risk identification, assessment and analysisObjective 5.2
- The risk register, appetite, response strategies and business impactObjective 5.2
- Third-party risk: assessing and selecting a vendorObjective 5.3
- Agreements, and monitoring a vendor after the ink driesObjective 5.3
- Compliance, privacy, and the cost of getting it wrongObjective 5.4
- Audits, assessments and where penetration testing fitsObjective 5.5
- Security awareness that changes behaviour rather than completion ratesObjective 5.6