CompTIA Security+ SY0-801 Lessons

Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.

  1. Security controls: the four categories and the six typesObjective 1.1Audio
  2. A lab you can break safely, and why your laptop is not itAudio
  3. Defence in depth: CIA, AAA and non-repudiation, stated precisely enough to be usefulObjective 1.1Audio
  4. Zero trust and least privilege, as principles rather than productsObjective 1.1Audio
  5. Change management, which is a security control and is examined as oneObjective 1.2Audio
  6. PKI and certificates, and the key management that decides whether any of it worksObjective 1.3Audio
  7. Encryption: algorithms, key length, key exchange, and where to apply itObjective 1.3Audio
  8. Hashing, salting, digital signatures and obfuscationObjective 1.3Audio
  9. Characterising threats and vulnerabilities: intelligence, scoring and what to fix firstObjective 2.1Audio
  10. Threat actors and their motivations, sorted by what they can affordObjective 2.2
  11. Threat vectors: messages, attachments, networks, remote access and the supply chainObjective 2.3
  12. Threat vectors: browsers, endpoints, people, IoT and OT, physical access and radioObjective 2.3
  13. Application, code and operating-system vulnerabilitiesObjective 2.4
  14. Attack surfaces: systems, credentials, devices, identity providers and exposed dataObjective 2.4
  15. Social engineering: phishing in all its forms, impersonation and deepfakesObjective 2.5
  16. Recognising malware, and the indicators of compromise it leavesObjective 2.5
  17. Credential attacks, and the controls that end themObjective 2.5
  18. Network, application and physical attack indicatorsObjective 2.5
  19. AI threats and vulnerabilities, from the defender's sideObjective 2.6
  20. Cloud and on-premises architecture, compared by where the risk landsObjective 3.1
  21. Operational technology, air gaps, segmentation and infrastructure as codeObjective 3.1
  22. Device placement, security zones, diversity and failure modesObjective 3.2
  23. Secure communication and access: VPNs, tunnels, SSE and out-of-band managementObjective 3.2
  24. Zero trust architecture and identity infrastructureObjective 3.2
  25. Data types, states, classification and the methods that protect themObjective 3.3
  26. Data roles, handling, the data life cycle and compliance categoriesObjective 3.3
  27. High availability, site resilience and powerObjective 3.4
  28. Backups, recovery testing, continuity and recovery metricsObjective 3.4
  29. Secure baselines, hardening, segmentation and access controlObjective 4.1
  30. Mobile device management, application security, sandboxing and deceptionObjective 4.1
  31. Firewalls, intrusion detection and prevention, and choosing the network controlObjective 4.1
  32. Content filtering, DLP, NAC, EDR/XDR and email securityObjective 4.1
  33. Asset management, from purchase order to certificate of destructionObjective 4.2
  34. Vulnerability management, end to endObjective 4.3
  35. Alerting and monitoring, and the tools that do itObjective 4.4
  36. Provisioning identity, account types, single sign-on and federationObjective 4.5
  37. Multifactor authentication, passwords and passkeysObjective 4.5
  38. Automation and orchestration, AI assistance, and when not to automateObjective 4.6
  39. The incident response process, and the preparation that decides the outcomeObjective 4.7
  40. Threat hunting, digital forensics, root cause and the post-incident reportObjective 4.7
  41. Reading logs, images and other sources to support an investigationObjective 4.8
  42. Policies, standards, procedures, plans and guidelines, and the difference between themObjective 5.1
  43. Risk management: identification, analysis, the register and treatmentObjective 5.2
  44. Third-party risk: selecting a vendor, the agreement, and monitoring after the ink driesObjective 5.3
  45. Compliance, privacy, and the cost of getting it wrongObjective 5.4
  46. Audits, assessments, gap analysis and where penetration testing fitsObjective 5.5
  47. Security awareness that changes behaviour rather than completion ratesObjective 5.6