Mitigation and Hardening Techniques
Security+ mitigation items ask for the best control to reduce attack surface, patch exposure, credential abuse, insecure services, and lateral movement.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
Hardening removes unnecessary exposure through secure configuration, patching, least functionality, and secure defaults.
Exam cue: Pick the control that directly closes the exposed path.
Concept 2
Mitigation selection should address the root risk rather than only suppressing alerts.
Exam cue: Prefer layered mitigation for high-impact weaknesses.
Concept 3
Network, endpoint, identity, application, and cloud mitigations often work together as layered controls.
Exam cue: Balance availability and risk when deploying patches or blocks.
Risk pitfalls and guardrails
Choosing monitoring when immediate blocking is required.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Leaving default accounts or services active.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Patching without testing or rollback on critical systems.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
System Hardening
System hardening reduces attack surface by disabling unnecessary services and applying secure settings.
Patch Management
Patch management prioritizes, tests, deploys, and verifies updates that reduce known risk.
Secure Baseline
A secure baseline defines approved minimum configuration for a system or service.
Attack Surface
Attack surface is the set of exposed paths an attacker can attempt to use.
Allow List
An allow list permits only approved applications, addresses, or actions.
Block List
A block list denies known unwanted applications, addresses, or actions.
Segmentation
Segmentation separates systems or networks to reduce exposure and lateral movement.
EDR
Endpoint detection and response monitors endpoints and supports investigation and containment.
WAF
A web application firewall filters and monitors HTTP traffic to reduce application attack risk.
Configuration Drift
Configuration drift occurs when systems move away from the approved baseline over time.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A new server image includes unused web services, sample accounts, and open management ports. What should occur before deployment?
A critical patch fixes an actively exploited flaw, but the affected server supports revenue processing. What is the best patch-management approach?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
