Topic module

Cryptography, Zero Trust and Change Management

This topic links cryptographic protections, certificates, key use, Zero Trust principles, deception, physical controls, and controlled change.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

Cryptography should match the goal: confidentiality, integrity, authentication, nonrepudiation, or key exchange.

Exam cue: Match the crypto tool to the security property.

Concept 2

Zero Trust assumes no implicit trust and continuously evaluates identity, device posture, and context.

Exam cue: Prefer continuous verification over network-location trust.

Concept 3

Change management reduces production risk through approvals, testing, rollback planning, and documentation.

Exam cue: Look for approval, impact analysis, testing, and rollback.

Risk pitfalls and guardrails

Using hashing when reversible confidentiality is required.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Trusting a device only because it is on an internal network.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Skipping rollback plans for urgent production changes.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Encryption

Encryption protects confidentiality by transforming readable data into ciphertext with a key.

Hashing

Hashing creates a fixed digest used to verify integrity rather than hide data for later recovery.

Digital Signature

A digital signature supports integrity, authentication, and nonrepudiation.

PKI

PKI uses certificates, keys, certificate authorities, and trust paths to bind identities to public keys.

Key Exchange

Key exchange establishes shared secret material without sending the secret directly.

Zero Trust

Zero Trust removes implicit trust and verifies identity, device posture, context, and authorization continuously.

Microsegmentation

Microsegmentation limits lateral movement by separating workloads and applying granular policy.

Deception Technology

Deception technology uses decoys or lures to detect and study unauthorized activity.

Change Approval

Change approval documents business need, risk, testing, communication, and rollback before implementation.

Rollback Plan

A rollback plan defines how to restore service if a change creates unacceptable impact.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A laptop is stolen while powered off. Which control most directly protects readable files on its drive?

An administrator downloads an operating-system image and wants to confirm it exactly matches the publisher's file. What should be compared?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.