Enterprise Infrastructure and Data Protection
This area covers network zones, secure infrastructure, data states, classification, encryption, tokenization, masking, DLP, and lifecycle controls.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
Infrastructure design should place controls at points where data, identity, and traffic cross trust boundaries.
Exam cue: Name the data state and sensitivity first.
Concept 2
Data protection depends on classification, data state, sensitivity, retention, and approved handling requirements.
Exam cue: Choose the data control that matches the use case.
Concept 3
Encryption, tokenization, masking, hashing, and DLP solve different data-protection problems.
Exam cue: Use zones and segmentation to reduce blast radius.
Risk pitfalls and guardrails
Using masking when strong storage confidentiality is required.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Ignoring data in use because data at rest is encrypted.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Putting public-facing services in the same zone as sensitive databases.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Data at Rest
Data at rest is stored data such as files, databases, backups, or archives.
Data in Transit
Data in transit is moving across a network or between systems.
Data in Use
Data in use is actively processed in memory, applications, or endpoints.
Data Classification
Data classification labels information by sensitivity, value, and handling requirements.
Tokenization
Tokenization replaces sensitive data with a token that maps back through a protected system.
Masking
Masking hides part of a value so users see only what they need.
DLP
Data loss prevention detects or blocks unauthorized movement of sensitive information.
DMZ
A DMZ exposes public services while separating them from internal trusted networks.
Network Segmentation
Network segmentation divides environments to limit exposure, enforce policy, and reduce lateral movement.
Data Retention
Data retention defines how long information is kept and when it should be disposed.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A backup tape contains an encrypted copy of the customer database and sits in a vault. Which data state is being protected?
Customer records travel from an application server to a reporting service. Which control best protects confidentiality in this state?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
