CompTIA Security+ SY0-801 Lessons
Every lesson is free to read, with three practice questions each. Work through them in order, or jump to the objective you need.
- Security controls: the four categories and the six typesObjective 1.1Audio
- A lab you can break safely, and why your laptop is not itAudio
- Defence in depth: CIA, AAA and non-repudiation, stated precisely enough to be usefulObjective 1.1Audio
- Zero trust and least privilege, as principles rather than productsObjective 1.1Audio
- Change management, which is a security control and is examined as oneObjective 1.2Audio
- PKI and certificates, and the key management that decides whether any of it worksObjective 1.3Audio
- Encryption: algorithms, key length, key exchange, and where to apply itObjective 1.3Audio
- Hashing, salting, digital signatures and obfuscationObjective 1.3Audio
- Characterising threats and vulnerabilities: intelligence, scoring and what to fix firstObjective 2.1Audio
- Threat actors and their motivations, sorted by what they can affordObjective 2.2
- Threat vectors: messages, attachments, networks, remote access and the supply chainObjective 2.3
- Threat vectors: browsers, endpoints, people, IoT and OT, physical access and radioObjective 2.3
- Application, code and operating-system vulnerabilitiesObjective 2.4
- Attack surfaces: systems, credentials, devices, identity providers and exposed dataObjective 2.4
- Social engineering: phishing in all its forms, impersonation and deepfakesObjective 2.5
- Recognising malware, and the indicators of compromise it leavesObjective 2.5
- Credential attacks, and the controls that end themObjective 2.5
- Network, application and physical attack indicatorsObjective 2.5
- AI threats and vulnerabilities, from the defender's sideObjective 2.6
- Cloud and on-premises architecture, compared by where the risk landsObjective 3.1
- Operational technology, air gaps, segmentation and infrastructure as codeObjective 3.1
- Device placement, security zones, diversity and failure modesObjective 3.2
- Secure communication and access: VPNs, tunnels, SSE and out-of-band managementObjective 3.2
- Zero trust architecture and identity infrastructureObjective 3.2
- Data types, states, classification and the methods that protect themObjective 3.3
- Data roles, handling, the data life cycle and compliance categoriesObjective 3.3
- High availability, site resilience and powerObjective 3.4
- Backups, recovery testing, continuity and recovery metricsObjective 3.4
- Secure baselines, hardening, segmentation and access controlObjective 4.1
- Mobile device management, application security, sandboxing and deceptionObjective 4.1
- Firewalls, intrusion detection and prevention, and choosing the network controlObjective 4.1
- Content filtering, DLP, NAC, EDR/XDR and email securityObjective 4.1
- Asset management, from purchase order to certificate of destructionObjective 4.2
- Vulnerability management, end to endObjective 4.3
- Alerting and monitoring, and the tools that do itObjective 4.4
- Provisioning identity, account types, single sign-on and federationObjective 4.5
- Multifactor authentication, passwords and passkeysObjective 4.5
- Automation and orchestration, AI assistance, and when not to automateObjective 4.6
- The incident response process, and the preparation that decides the outcomeObjective 4.7
- Threat hunting, digital forensics, root cause and the post-incident reportObjective 4.7
- Reading logs, images and other sources to support an investigationObjective 4.8
- Policies, standards, procedures, plans and guidelines, and the difference between themObjective 5.1
- Risk management: identification, analysis, the register and treatmentObjective 5.2
- Third-party risk: selecting a vendor, the agreement, and monitoring after the ink driesObjective 5.3
- Compliance, privacy, and the cost of getting it wrongObjective 5.4
- Audits, assessments, gap analysis and where penetration testing fitsObjective 5.5
- Security awareness that changes behaviour rather than completion ratesObjective 5.6