Identity, Access, Automation and Incident Response
Security operations questions combine IAM, MFA, federation, privileged access, automation, orchestration, playbooks, containment, eradication, and recovery.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
IAM controls must authenticate identity, enforce least privilege, monitor privileged use, and remove access when no longer needed.
Exam cue: Remove or reduce access before investigating a compromised account deeply.
Concept 2
Automation and orchestration improve consistency but need approval, testing, logging, and exception handling.
Exam cue: Choose the incident phase that matches the described action.
Concept 3
Incident response follows preparation, detection, analysis, containment, eradication, recovery, and lessons learned.
Exam cue: Use playbooks to standardize high-pressure response.
Risk pitfalls and guardrails
Resetting only one password while active sessions remain valid.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Eradicating before containment preserves evidence and scope.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Automating a destructive action without approval or safeguards.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
MFA
Multi-factor authentication uses different factor types to reduce credential-only compromise risk.
Federation
Federation lets one identity provider authenticate users for another trusted service.
SSO
Single sign-on allows one authenticated session to access multiple approved services.
PAM
Privileged access management controls, monitors, and audits elevated accounts.
JIT Access
Just-in-time access grants elevated privileges only when needed and for a limited time.
Provisioning
Provisioning creates or changes user access based on approved roles and need.
Deprovisioning
Deprovisioning removes access when a person, role, or need changes.
SOAR
SOAR automates and orchestrates security workflows across tools and playbooks.
Containment
Containment limits incident spread while preserving enough evidence for analysis.
Lessons Learned
Lessons learned captures improvements after an incident to reduce future risk.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A user signs in with a password and a fingerprint. Why does this qualify as MFA?
Employees authenticate to a corporate identity provider and then access a partner's application through an established trust. What capability is this?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
