CompTIA Security+ Lessons

Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.

  1. Security controls: the four categories and the six typesObjective 1.1
  2. A lab you can break safely, and why your laptop is not it
  3. CIA, AAA and non-repudiation, stated precisely enough to be usefulObjective 1.2
  4. Zero trust, and the deception technology that sits beside itObjective 1.2
  5. Change management, which is a security control and is examined as oneObjective 1.3
  6. PKI, encryption and the key management that decides whether any of it worksObjective 1.4
  7. Hashing, digital signatures, obfuscation and blockchainObjective 1.4
  8. Threat actors, sorted by what they can afford rather than by how scary they soundObjective 2.1
  9. Motivations, shadow IT, and the threat that already has a badgeObjective 2.1
  10. Message, voice and file-based vectors, and the social engineering behind themObjective 2.2
  11. Unsecure networks, supply chain, and the software you did not writeObjective 2.2
  12. Application, web and operating-system vulnerabilitiesObjective 2.3
  13. Hardware, mobile, virtualisation, cloud and supply-chain vulnerabilitiesObjective 2.3
  14. Recognising malware by the evidence it leavesObjective 2.4
  15. Password and cryptographic attacks, and the controls that end themObjective 2.4
  16. Network, application and physical attack indicatorsObjective 2.4
  17. Mitigation techniques, chosen for the vulnerability in front of youObjective 2.5
  18. On-premises, cloud and virtualisation, compared by where the risk landsObjective 3.1
  19. IoT, ICS/SCADA, embedded systems and infrastructure as codeObjective 3.1
  20. Device placement, security zones and attack surfaceObjective 3.2
  21. Firewalls, appliances and selecting the control that fitsObjective 3.2
  22. Secure communication and access: VPN, tunnelling and remote workObjective 3.2
  23. Data types, classification, and the protection each class earnsObjective 3.3
  24. High availability, site resilience and powerObjective 3.4
  25. Backups, testing, and continuity of operationsObjective 3.4
  26. Secure baselines, and hardening the targets that appear on the examObjective 4.1
  27. Wireless, mobile deployment, application security and sandboxingObjective 4.1
  28. Asset management, from purchase order to certificate of destructionObjective 4.2
  29. Vulnerability management, end to endObjective 4.3
  30. Alerting and monitoring, and the tools CompTIA namesObjective 4.4
  31. Modifying firewalls, IDS/IPS and the filtering layersObjective 4.5
  32. DLP, NAC, EDR/XDR and email securityObjective 4.5
  33. Provisioning identity, single sign-on and federationObjective 4.6
  34. Multifactor authentication, password concepts and privileged accessObjective 4.6
  35. Automation and orchestration, and when not to automateObjective 4.7
  36. The incident response process, and the preparation that decides the outcomeObjective 4.8
  37. Root cause analysis, threat hunting and digital forensicsObjective 4.8
  38. Reading log data and other sources to support an investigationObjective 4.9
  39. Governance structures, and who is allowed to decideObjective 5.1
  40. Policies, standards, procedures and guidelines, and the difference between themObjective 5.1
  41. Risk identification, assessment and analysisObjective 5.2
  42. The risk register, appetite, response strategies and business impactObjective 5.2
  43. Third-party risk: assessing and selecting a vendorObjective 5.3
  44. Agreements, and monitoring a vendor after the ink driesObjective 5.3
  45. Compliance, privacy, and the cost of getting it wrongObjective 5.4
  46. Audits, assessments and where penetration testing fitsObjective 5.5
  47. Security awareness that changes behaviour rather than completion ratesObjective 5.6