Topic module

Mitigation and Hardening Techniques

Security+ mitigation items ask for the best control to reduce attack surface, patch exposure, credential abuse, insecure services, and lateral movement.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

Hardening removes unnecessary exposure through secure configuration, patching, least functionality, and secure defaults.

Exam cue: Pick the control that directly closes the exposed path.

Concept 2

Mitigation selection should address the root risk rather than only suppressing alerts.

Exam cue: Prefer layered mitigation for high-impact weaknesses.

Concept 3

Network, endpoint, identity, application, and cloud mitigations often work together as layered controls.

Exam cue: Balance availability and risk when deploying patches or blocks.

Risk pitfalls and guardrails

Choosing monitoring when immediate blocking is required.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Leaving default accounts or services active.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Patching without testing or rollback on critical systems.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

System Hardening

System hardening reduces attack surface by disabling unnecessary services and applying secure settings.

Patch Management

Patch management prioritizes, tests, deploys, and verifies updates that reduce known risk.

Secure Baseline

A secure baseline defines approved minimum configuration for a system or service.

Attack Surface

Attack surface is the set of exposed paths an attacker can attempt to use.

Allow List

An allow list permits only approved applications, addresses, or actions.

Block List

A block list denies known unwanted applications, addresses, or actions.

Segmentation

Segmentation separates systems or networks to reduce exposure and lateral movement.

EDR

Endpoint detection and response monitors endpoints and supports investigation and containment.

WAF

A web application firewall filters and monitors HTTP traffic to reduce application attack risk.

Configuration Drift

Configuration drift occurs when systems move away from the approved baseline over time.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A new server image includes unused web services, sample accounts, and open management ports. What should occur before deployment?

A critical patch fixes an actively exploited flaw, but the affected server supports revenue processing. What is the best patch-management approach?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.