Topic module

Identity, Access, Automation and Incident Response

Security operations questions combine IAM, MFA, federation, privileged access, automation, orchestration, playbooks, containment, eradication, and recovery.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

IAM controls must authenticate identity, enforce least privilege, monitor privileged use, and remove access when no longer needed.

Exam cue: Remove or reduce access before investigating a compromised account deeply.

Concept 2

Automation and orchestration improve consistency but need approval, testing, logging, and exception handling.

Exam cue: Choose the incident phase that matches the described action.

Concept 3

Incident response follows preparation, detection, analysis, containment, eradication, recovery, and lessons learned.

Exam cue: Use playbooks to standardize high-pressure response.

Risk pitfalls and guardrails

Resetting only one password while active sessions remain valid.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Eradicating before containment preserves evidence and scope.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Automating a destructive action without approval or safeguards.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

MFA

Multi-factor authentication uses different factor types to reduce credential-only compromise risk.

Federation

Federation lets one identity provider authenticate users for another trusted service.

SSO

Single sign-on allows one authenticated session to access multiple approved services.

PAM

Privileged access management controls, monitors, and audits elevated accounts.

JIT Access

Just-in-time access grants elevated privileges only when needed and for a limited time.

Provisioning

Provisioning creates or changes user access based on approved roles and need.

Deprovisioning

Deprovisioning removes access when a person, role, or need changes.

SOAR

SOAR automates and orchestrates security workflows across tools and playbooks.

Containment

Containment limits incident spread while preserving enough evidence for analysis.

Lessons Learned

Lessons learned captures improvements after an incident to reduce future risk.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A user signs in with a password and a fingerprint. Why does this qualify as MFA?

Employees authenticate to a corporate identity provider and then access a partner's application through an established trust. What capability is this?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.