Topic module

Secure Baselines and Asset Management

Operations questions often start with inventory, approved baselines, configuration monitoring, change tracking, secure deployment, and asset lifecycle control.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

You cannot secure what you cannot identify, classify, own, and monitor.

Exam cue: Look for inventory and ownership gaps.

Concept 2

Baselines make secure configuration measurable and repeatable across endpoints, servers, cloud, network, and applications.

Exam cue: Compare observed configuration to the approved baseline.

Concept 3

Asset management connects ownership, location, sensitivity, patching, lifecycle, and disposal.

Exam cue: Track asset lifecycle from procurement through disposal.

Risk pitfalls and guardrails

Deploying tools before knowing which assets exist.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Accepting drift without exception approval.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Disposing devices without data sanitization.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Asset Inventory

Asset inventory records systems, software, owners, locations, versions, and business purpose.

Asset Classification

Asset classification assigns sensitivity and criticality to guide protection.

Baseline Enforcement

Baseline enforcement keeps configurations aligned with approved security settings.

Secure Build

A secure build applies hardened images, patches, identity controls, and logging before release.

Golden Image

A golden image is a trusted standard system image used for consistent deployment.

Configuration Monitoring

Configuration monitoring detects unauthorized or risky changes from the baseline.

Exception Process

An exception process documents approved deviations, risk acceptance, and review dates.

Lifecycle Management

Lifecycle management tracks assets from acquisition through use, transfer, retirement, and disposal.

Data Sanitization

Data sanitization removes data so retired or reused media does not expose information.

CMDB

A configuration management database records configuration items and their relationships.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

Incident responders find an unknown server address in logs. Which record should identify its owner, purpose, location, and software?

Two servers have the same software but one processes payroll and the other hosts public brochures. What should asset classification capture?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.