Searching CertSprout…
Searching CertSprout…
A little curiosity goes a long way
Search certifications, learning topics, career paths, public profiles and help across CertSprout.
Showing 20 results for “Security+”. More results are available below.
Security+ · General Security Concepts
Security+ groups controls into four categories by how they are implemented. Technical controls are enforced by systems, like firewalls and encryption. Managerial controls are policies and ri…
Security+ · General Security Concepts
In asymmetric cryptography every party has a key pair. Anyone can use your public key to encrypt a message that only your private key can decrypt, which gives confidentiality. Flip it around…
Security+ · General Security Concepts
Zero Trust means no request is trusted because of where it comes from. The architecture separates decisions from enforcement. The control plane holds the Policy Engine, which weighs identity…
Security+ · Threats, Vulnerabilities, and Mitigations
Social engineering attacks are named after the delivery medium. Phishing arrives by email and asks you to click, open or reply. Smishing uses SMS text messages, often with a shortened link a…
Security+ · Threats, Vulnerabilities, and Mitigations
Three password attacks look similar in logs but differ in method. Brute force hammers one account with many guesses and quickly trips lockout. Password spraying tries one or two common passw…
Security+ · Threats, Vulnerabilities, and Mitigations
A zero-day vulnerability is one the vendor does not yet know about, or knows about but has no patch for, while attackers are already exploiting it. The name comes from the vendor having had …
Security+ · Threats, Vulnerabilities, and Mitigations
Both attacks abuse input that an application fails to validate, but they land in different places. SQL injection sends crafted text such as a quote and an always-true clause so the database …
Security+ · Threats, Vulnerabilities, and Mitigations
Embedded, IoT, medical and industrial devices often run old firmware, cannot host an agent, and may be unpatchable for years. The practical mitigation is network segmentation: put them on th…
Security+ · Security Architecture
Recovery sites are graded by how fast you can fail over. A hot site is a running duplicate with live replicated data, ready in minutes but the most expensive to keep. A warm site has power, …
Security+ · Security Architecture
An air-gapped system has no network connection at all to other networks; the only way in is by physically carrying media, which is why USB drives are the classic air-gap threat. It is used f…
Security+ · Security Architecture
Data protection controls depend on where the data is at the moment. Data at rest sits on disks and backups; protect it with full-disk, database or file encryption. Data in transit moves acro…
Security+ · Security Architecture
Rather than let administrators connect to sensitive servers from any workstation, organisations funnel all administrative access through a hardened intermediate host, called a jump server or…
Security+ · Security Operations
A SIEM gathers logs from firewalls, servers, endpoints and identity systems, normalises them, and correlates events into alerts, giving analysts a single console and long-term search. SOAR s…
Security+ · Security Operations
A vulnerability scanner can run two ways. An uncredentialed scan probes the target over the network like an outside attacker would, identifying open ports and banner versions but guessing at…
Security+ · Security Operations
The incident response lifecycle has a fixed sequence. Preparation builds the plan, tools and training. Detection and analysis notice and confirm that something is wrong. Containment stops th…
Security+ · Security Operations
In digital forensics, evidence is worthless in court unless you can prove it was not altered. Chain of custody is the documented record of every person who handled the evidence, when, why, a…
Security+ · Security Operations
Three DNS-based mechanisms defend a domain against spoofed email. SPF publishes which mail servers are permitted to send for the domain, so receivers can check the connecting server. DKIM ad…
Security+ · Security Operations
Discretionary access control lets the owner of a resource decide who may use it, as with file permissions on a workstation. Mandatory access control uses labels such as Secret and Top Secret…
Security+ · Security Operations
Remote Desktop Protocol on TCP 3389 is one of the most attacked services because exposed hosts are easily found and brute forced, and RDP has had critical remote-code-execution flaws. Best p…
Security+ · Security Program Management and Oversight
Quantitative risk analysis produces a yearly number to compare against the cost of controls. Single loss expectancy is asset value multiplied by exposure factor, the fraction of value lost i…
People search uses public names, handles and headlines. Private and unlisted profiles are excluded. Your goals are visible only to you in search.