Security Controls and Core Security Fundamentals
Security+ questions often begin with the purpose of a control, the CIA triad, nonrepudiation, authentication, authorization, and accountability.
How to study for Security+
Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.
Core concepts
Concept 1
Security controls are selected by function and purpose, including preventive, detective, corrective, deterrent, compensating, and directive controls.
Exam cue: Name the control objective before naming a product.
Concept 2
The CIA triad frames confidentiality, integrity, and availability tradeoffs in almost every security design.
Exam cue: Separate confidentiality, integrity, and availability.
Concept 3
AAA and nonrepudiation connect identities, permissions, logs, and evidence to defensible security operations.
Exam cue: Tie accountability to identity, logging, and evidence.
Risk pitfalls and guardrails
Choosing a detective control when prevention is required.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Treating authentication and authorization as the same step.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Ignoring availability when a control blocks legitimate operations.
Guardrail: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.
Memory anchors
Preventive Control
A preventive control blocks or reduces the chance of an unwanted event before it happens.
Detective Control
A detective control identifies events, anomalies, or violations after or while they occur.
Corrective Control
A corrective control restores a system or process after an incident or error.
Deterrent Control
A deterrent control discourages a threat actor by increasing perceived risk or effort.
CIA Triad
Confidentiality protects data exposure, integrity protects correctness, and availability protects access when needed.
Authentication
Authentication verifies that an identity claim belongs to the entity presenting it.
Authorization
Authorization decides what an authenticated identity is allowed to access or perform.
Accounting
Accounting records activity so actions can be reviewed, attributed, and audited.
Nonrepudiation
Nonrepudiation provides evidence that a party cannot credibly deny an action.
Least Privilege
Least privilege grants only the access needed for the approved task and no more.
Checkpoint rule
Do the check-up only after you can summarize each concept in one sentence and identify one dangerous pitfall from memory.
Knowledge Check (after reading)
Short check-up to confirm understanding of this module.
Check-up Questions
A company configures its email gateway to reject executable attachments before they reach user inboxes. Which control type is this?
Security staff review badge logs each morning to identify attempts to enter a restricted laboratory overnight. Which control type best describes the log review?
Answer all questions to submit.
Next step personalized recommendations
Continue learning
Move forward only after this module is stable.
What is Pass Harbor?
Completely free exam prep for 317 U.S. exams.
- Practice questions
- Flashcards
- Study guides
- Mock exams
- No registration
- No paywall
- Start instantly
“No more expensive exam prep. Quality study tools should be accessible to everyone.”
