Secure Baselines and Asset Management
Operations questions often start with inventory, approved baselines, configuration monitoring, change tracking, secure deployment, and asset lifecycle control.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
You cannot secure what you cannot identify, classify, own, and monitor.
Exam cue: Look for inventory and ownership gaps.
Concept 2
Baselines make secure configuration measurable and repeatable across endpoints, servers, cloud, network, and applications.
Exam cue: Compare observed configuration to the approved baseline.
Concept 3
Asset management connects ownership, location, sensitivity, patching, lifecycle, and disposal.
Exam cue: Track asset lifecycle from procurement through disposal.
Risk pitfalls and guardrails
Deploying tools before knowing which assets exist.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Accepting drift without exception approval.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Disposing devices without data sanitization.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Asset Inventory
Asset inventory records systems, software, owners, locations, versions, and business purpose.
Asset Classification
Asset classification assigns sensitivity and criticality to guide protection.
Baseline Enforcement
Baseline enforcement keeps configurations aligned with approved security settings.
Secure Build
A secure build applies hardened images, patches, identity controls, and logging before release.
Golden Image
A golden image is a trusted standard system image used for consistent deployment.
Configuration Monitoring
Configuration monitoring detects unauthorized or risky changes from the baseline.
Exception Process
An exception process documents approved deviations, risk acceptance, and review dates.
Lifecycle Management
Lifecycle management tracks assets from acquisition through use, transfer, retirement, and disposal.
Data Sanitization
Data sanitization removes data so retired or reused media does not expose information.
CMDB
A configuration management database records configuration items and their relationships.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
Incident responders find an unknown server address in logs. Which record should identify its owner, purpose, location, and software?
Two servers have the same software but one processes payroll and the other hosts public brochures. What should asset classification capture?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
