Cryptography, Zero Trust and Change Management
This topic links cryptographic protections, certificates, key use, Zero Trust principles, deception, physical controls, and controlled change.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
Cryptography should match the goal: confidentiality, integrity, authentication, nonrepudiation, or key exchange.
Exam cue: Match the crypto tool to the security property.
Concept 2
Zero Trust assumes no implicit trust and continuously evaluates identity, device posture, and context.
Exam cue: Prefer continuous verification over network-location trust.
Concept 3
Change management reduces production risk through approvals, testing, rollback planning, and documentation.
Exam cue: Look for approval, impact analysis, testing, and rollback.
Risk pitfalls and guardrails
Using hashing when reversible confidentiality is required.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Trusting a device only because it is on an internal network.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Skipping rollback plans for urgent production changes.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Encryption
Encryption protects confidentiality by transforming readable data into ciphertext with a key.
Hashing
Hashing creates a fixed digest used to verify integrity rather than hide data for later recovery.
Digital Signature
A digital signature supports integrity, authentication, and nonrepudiation.
PKI
PKI uses certificates, keys, certificate authorities, and trust paths to bind identities to public keys.
Key Exchange
Key exchange establishes shared secret material without sending the secret directly.
Zero Trust
Zero Trust removes implicit trust and verifies identity, device posture, context, and authorization continuously.
Microsegmentation
Microsegmentation limits lateral movement by separating workloads and applying granular policy.
Deception Technology
Deception technology uses decoys or lures to detect and study unauthorized activity.
Change Approval
Change approval documents business need, risk, testing, communication, and rollback before implementation.
Rollback Plan
A rollback plan defines how to restore service if a change creates unacceptable impact.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A laptop is stolen while powered off. Which control most directly protects readable files on its drive?
An administrator downloads an operating-system image and wants to confirm it exactly matches the publisher's file. What should be compared?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
