Topic module

Security Controls and Core Security Fundamentals

Security+ questions often begin with the purpose of a control, the CIA triad, nonrepudiation, authentication, authorization, and accountability.

Long-form learning
Concept to Risk to Memory to Check-up

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

Core concepts

Concept 1

Security controls are selected by function and purpose, including preventive, detective, corrective, deterrent, compensating, and directive controls.

Exam cue: Name the control objective before naming a product.

Concept 2

The CIA triad frames confidentiality, integrity, and availability tradeoffs in almost every security design.

Exam cue: Separate confidentiality, integrity, and availability.

Concept 3

AAA and nonrepudiation connect identities, permissions, logs, and evidence to defensible security operations.

Exam cue: Tie accountability to identity, logging, and evidence.

Risk pitfalls and guardrails

Choosing a detective control when prevention is required.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Treating authentication and authorization as the same step.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Ignoring availability when a control blocks legitimate operations.

Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Preventive Control

A preventive control blocks or reduces the chance of an unwanted event before it happens.

Detective Control

A detective control identifies events, anomalies, or violations after or while they occur.

Corrective Control

A corrective control restores a system or process after an incident or error.

Deterrent Control

A deterrent control discourages a threat actor by increasing perceived risk or effort.

CIA Triad

Confidentiality protects data exposure, integrity protects correctness, and availability protects access when needed.

Authentication

Authentication verifies that an identity claim belongs to the entity presenting it.

Authorization

Authorization decides what an authenticated identity is allowed to access or perform.

Accounting

Accounting records activity so actions can be reviewed, attributed, and audited.

Nonrepudiation

Nonrepudiation provides evidence that a party cannot credibly deny an action.

Least Privilege

Least privilege grants only the access needed for the approved task and no more.

Checkpoint rule

Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.

Knowledge Check (after reading)

Short check-up to confirm understanding of this module.

Check-up Questions

1-2 question checkpoint

A company configures its email gateway to reject executable attachments before they reach user inboxes. Which control type is this?

Security staff review badge logs each morning to identify attempts to enter a restricted laboratory overnight. Which control type best describes the log review?

Answer all questions to submit.

Next step personalized recommendations

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.