Domain 1.0 | Exam Weight: 16% | Objectives 1.1–1.3
Introduction
Organizations protect information, systems, networks, and business operations using a combination of security principles, controls, processes, and cryptographic technologies.
Understanding these concepts is fundamental to cybersecurity. Security professionals must recognize which protections are appropriate for different situations, why particular controls are implemented, and how technical or operational decisions affect an organization's security posture.
General Security Concepts accounts for 16% of the CompTIA Security+ SY0-801 examination.
This lesson covers all three objectives in Domain 1.0:
- 1.1: Explain security concepts and controls.
- 1.2: Given a scenario, demonstrate the impact of change management processes on security.
- 1.3: Explain the importance of using appropriate cryptographic solutions.
The objective is to understand the terminology, distinguish similar concepts, interpret scenarios, and identify the most appropriate security response.
1.1 — Explain Security Concepts and Controls
Defense in Depth
Defense in depth is a security strategy that uses multiple independent or complementary protective measures to reduce the likelihood that a single failure will compromise an entire system.
Consider a financial institution protecting customer information. Its security controls may include physical access restrictions, network firewalls, multifactor authentication, application permissions, encryption, and security monitoring.
If an attacker obtains an employee's password, additional controls may still prevent unauthorized access.
Defense in depth recognizes that no individual security mechanism is completely reliable.
Confidentiality, Integrity, and Availability (CIA)
The CIA triad defines three primary objectives of information security.
Confidentiality
Confidentiality ensures information is disclosed only to authorized individuals, processes, or systems.
For example, employee salary records should be available only to personnel who have a legitimate business reason to access them.
Common protections include encryption, access controls, authentication, and data classification.
Integrity
Integrity ensures that information remains accurate, complete, and protected against unauthorized modification.
For example, an unauthorized change to a banking transaction would compromise integrity, even if the transaction remained confidential.
Integrity protections include cryptographic hashes, digital signatures, access controls, and change tracking.
Availability
Availability ensures authorized users can access information and services when they are needed.
A denial-of-service attack that prevents customers from using an online banking application primarily affects availability.
Availability measures include redundancy, failover, backup systems, disaster recovery, and resilient infrastructure.
Recognizing CIA in Examination Questions
| Scenario | Primary principle |
|---|---|
| Unauthorized employee reads patient records | Confidentiality |
| Financial records are secretly modified | Integrity |
| A server outage prevents users from accessing an application | Availability |
| Encrypted confidential documents are stolen but cannot be read without the key | Confidentiality protection |
| A digital signature reveals a modified document | Integrity verification |
A security incident can affect multiple CIA principles simultaneously. Examination questions may ask for the primary principle involved.
Authentication, Authorization, and Accounting (AAA)
AAA is a framework for controlling access to resources and recording relevant activity.
Authentication
Authentication verifies an identity claim.
Common authentication factors include:
- Something a person knows, such as a password.
- Something a person has, such as a hardware security key.
- Something a person is, such as a fingerprint.
Multifactor authentication combines factors from at least two different categories.
Using two passwords is not multifactor authentication because both are knowledge factors.
Authorization
Authorization determines what an authenticated identity is permitted to access or perform.
An employee might successfully sign in to a corporate system but lack permission to view financial reports.
The identity has been authenticated but not authorized for that resource.
Authorization may be implemented through access control lists, role-based access control, attribute-based access control, and other policies.
Accounting
Accounting records activities associated with users, services, and systems.
Examples include login events, access attempts, administrative actions, and resource usage.
Accounting supports investigations, auditing, accountability, and compliance.
Examination distinction:
Authentication establishes identity. Authorization establishes permissions. Accounting records activity.
Non-repudiation
Non-repudiation provides evidence that an action or communication originated from a particular party, helping prevent credible denial of that action.
Digital signatures are commonly associated with non-repudiation.
Suppose a company executive digitally signs an electronic agreement. A valid signature can help demonstrate that the document was signed using the corresponding private key and has not been modified since signing.
Non-repudiation depends on trustworthy identity verification, key protection, and evidence handling. A valid signature alone does not establish who physically operated a compromised device.
Remember: Encryption protects confidentiality; digital signatures provide evidence of origin and integrity.
Zero Trust Principles
Zero Trust is a security model built around minimizing implicit trust.
A device or user should not be considered trustworthy merely because it is connected to an internal corporate network.
Access decisions consider identity, authorization, device condition, context, and applicable policies.
Core principles include:
Verify explicitly: Evaluate each access request against relevant authentication and authorization requirements.
Use least privilege: Limit access to what is necessary.
Assume breach: Design protections under the assumption that an attacker may already have gained access somewhere in the environment.
Zero Trust commonly uses identity-based access decisions, device assessment, segmentation, continuous evaluation, and strong monitoring.
It is not synonymous with a VPN, firewall, or a single commercial product.
Least Privilege
Least privilege means assigning only the permissions needed for an identity to complete its authorized functions.
For example, an employee responsible for viewing invoices does not normally require permission to delete the company's accounting database.
Least privilege reduces the possible damage from compromised accounts, mistakes, and malicious insiders.
A related principle is separation of duties, in which important responsibilities are divided so that one person cannot independently complete a sensitive process without oversight.
Least privilege concerns the amount of access granted. Separation of duties concerns how responsibilities are distributed.
Security Control Categories
Security controls can be classified by how they are administered or implemented.
Technical/Logical Controls
Technical controls use hardware or software to enforce security requirements.
Examples include firewalls, encryption, multifactor authentication, endpoint protection, and access-control systems.
Managerial/Administrative Controls
Managerial controls provide organizational direction and oversight.
Examples include security policies, risk assessments, governance frameworks, and formal security planning.
Physical/Environmental Controls
Physical controls protect facilities, equipment, and locations.
Examples include door locks, fences, security lighting, equipment enclosures, and controlled access to data centers.
Environmental protections such as fire suppression and water-leak detection help protect physical infrastructure.
Operational Controls
Operational controls govern security through ongoing procedures and activities performed by people and organizational processes.
Examples include incident-handling activities, security awareness training, routine monitoring, and operational procedures.
Some controls overlap categories. The classification depends on the aspect emphasized in the scenario.
Security Control Types
Security control types describe the intended function of a control.
| Control type | Purpose | Example |
|---|---|---|
| Preventive | Prevent unwanted activity | Access control that blocks unauthorized logins |
| Deterring | Discourage unwanted behavior | Visible security presence |
| Corrective | Correct conditions after an event | Restoring a damaged system from a clean backup |
| Detective | Discover suspicious or unauthorized activity | Intrusion detection alert |
| Compensating | Provide alternative protection when the preferred control cannot be used | Additional restrictions and monitoring for an unsupported legacy application |
| Directive | Establish required behavior | A policy requiring approved handling of sensitive information |
Understanding the Differences
Preventive versus detective: A preventive control attempts to stop an event. A detective control identifies activity that has occurred or is occurring.
Deterring versus preventive: A warning sign may discourage trespassing but cannot physically block entry. A locked door may prevent entry.
Corrective versus compensating: A corrective control addresses a problem after an event. A compensating control provides alternative risk reduction when a preferred safeguard is unavailable or impractical.
Directive versus technical enforcement: A password policy tells employees what is required. A system that automatically rejects noncompliant passwords enforces a technical restriction.
Exam example: An organization cannot immediately replace a legacy system that lacks modern authentication. It isolates the system and adds restrictive access controls.
These additional safeguards are compensating controls.
Objective 1.1 Summary
A candidate should distinguish security objectives, access-control functions, trust models, and control classifications.
When analyzing a question, identify whether it describes a security goal, an identity or permission decision, the implementation category of a control, or the control's intended function.
1.2 — Given a Scenario, Demonstrate the Impact of Change Management Processes on Security
Change management is a structured process for evaluating, authorizing, implementing, documenting, and reviewing changes to systems or business operations.
An improperly managed change may expose information, create vulnerabilities, cause service interruptions, or invalidate existing controls.
CompTIA expects candidates to recognize both the business processes governing changes and their technical security implications.
Business Processes Impacting Security Operations
Change Advisory Board (CAB)
A Change Advisory Board evaluates proposed changes and advises on their potential impacts.
A CAB may include representatives from IT operations, cybersecurity, networking, applications, business management, and other affected groups.
Its responsibilities may include assessing risk, considering dependencies, reviewing readiness, and making recommendations about scheduling or approval.
Not every organization uses a CAB for every change, and the CAB is not necessarily the final approving authority.
Approval Process
Formal approval establishes that a change has been evaluated and authorized by the appropriate people before implementation.
Approval processes help prevent unreviewed modifications, unauthorized configuration changes, and unexpected business disruption.
Emergency changes may follow expedited procedures, but they still require suitable accountability and subsequent review.
Ownership
Ownership establishes accountability for a system, service, change, or business process.
A change owner or system owner may be responsible for ensuring the correct reviews occur, risks are understood, and results are documented.
Clearly defined ownership reduces the likelihood that important security responsibilities will be overlooked.
Stakeholders
Stakeholders are individuals or groups affected by a proposed change.
They may include business users, security personnel, application owners, system administrators, customers, and external service providers.
For example, changing an authentication service may affect employees, applications, help desk personnel, and business operations.
Stakeholder involvement helps identify consequences that may not be obvious to the team performing the change.
Impact Analysis
Impact analysis examines the expected and potential effects of a change.
It should consider:
- Security risks and possible new exposure.
- Business continuity and availability.
- Dependencies between systems.
- Compatibility with existing applications.
- Required resources and service interruption.
- Compliance, privacy, and operational consequences.
A software update might address a critical vulnerability while disrupting a dependent application. Both effects matter when evaluating the change.
Test Results
Test results provide evidence about how a proposed change performs under evaluated conditions.
Testing may reveal compatibility problems, performance degradation, security-control failures, or unexpected functionality changes.
Successful testing reduces uncertainty but cannot guarantee that production deployment will behave identically.
The examination may present a scenario in which a change was deployed without reviewing test results, leading to an avoidable outage or security failure.
Backout Planning
A backout plan describes how an organization can return a system to its previous acceptable state if a change fails.
A backout plan may involve restoring configurations, reversing a deployment, or using recovery mechanisms.
The essential concept is reversibility.
Not every change is safely reversible. Database migrations and irreversible data transformations are common examples requiring special consideration.
Fail Forward
Fail forward means resolving a failed change through a subsequent corrective change rather than returning to the previous version.
For example, if a database schema migration has already altered production data in a way that makes rollback unsafe, a forward-compatible correction may be preferable.
Exam distinction: Backout restores an earlier state; fail forward advances to a corrected state.
Maintenance Window
A maintenance window is an approved period during which changes can occur with consideration for business activity and service availability.
Maintenance windows reduce the risk of disruption during critical operating periods.
They do not eliminate the need for approval, testing, monitoring, or recovery planning.
Standard Operating Procedures (SOPs)
SOPs are documented instructions governing how routine organizational processes should be performed.
They help establish consistency, accountability, repeatability, and compliance.
In change management, SOPs may define responsibilities, evidence requirements, escalation procedures, implementation standards, and closure criteria.
Technical Implications of Changes
Allow Lists and Deny Lists
An allow list identifies explicitly permitted entities, operations, applications, or connections.
A deny list identifies explicitly prohibited ones.
For example, a firewall configuration may permit selected services and block other traffic.
Changing these lists can either increase or reduce exposure.
Allow-list approaches are commonly associated with default-deny security models, although actual behavior depends on the system's rule-processing logic.
Restricted Activities
Organizations may restrict certain activities during change implementation.
Examples include limiting configuration modifications to authorized personnel, prohibiting unrelated changes during sensitive maintenance, and restricting access to critical infrastructure.
These restrictions reduce interference and help preserve accountability.
Downtime
Downtime is a period when a service is unavailable.
A change can cause planned downtime, unplanned downtime, or partial service degradation.
Security consequences may include unavailable monitoring, authentication failures, disruption of protective services, and impacts on business continuity.
Service Restart
A service restart stops and starts a specific background service or process.
A configuration change may not take effect until a service reload or restart occurs.
Restarting a service can interrupt applications that depend on it.
Application Restart
An application restart restarts an application or its runtime.
An application may consist of multiple services, processes, and dependencies.
The difference matters: restarting one service may be less disruptive than restarting an entire application.
Legacy Applications
Legacy applications are older systems that may depend on obsolete software, protocols, configurations, or unsupported components.
They may be incompatible with current encryption standards, authentication methods, or operating system updates.
Legacy dependencies can complicate security improvements and require additional risk management.
Dependencies
Dependencies are relationships in which one system or function relies on another.
An application may depend on DNS, databases, certificate services, identity providers, network connectivity, or external APIs.
A change to one dependency can affect multiple downstream services.
Scenario: A certificate authority is replaced, and several applications stop authenticating because they do not trust the new issuing authority.
The primary planning issue is an overlooked trust dependency.
Documentation
Documentation preserves the information required to understand, operate, secure, and maintain systems.
Updating Diagrams
Architecture and network diagrams should accurately represent the operational environment.
Changes to firewalls, network segments, connections, infrastructure components, or trust relationships may make older diagrams inaccurate.
Incorrect diagrams can hinder troubleshooting, incident response, and security reviews.
Updating Policies and Procedures
Security policies and procedures should reflect the organization's approved operating requirements.
When systems or processes change, associated documentation may also require updates.
Otherwise, personnel may follow outdated instructions or misunderstand the current security requirements.
Version Control
Version control maintains a history of changes to documents, software, configurations, and other managed artifacts.
It supports:
- Identifying what changed.
- Tracking who made a change.
- Comparing versions.
- Supporting authorized review.
- Recovering earlier versions when feasible.
- Preserving evidence for troubleshooting and audits.
Version control is not the same as backup. A version history may support recovery, but it does not replace a properly designed backup and disaster-recovery strategy.
Objective 1.2 Scenario Review
Scenario A: A security update causes a critical legacy application to stop working.
Likely issue: Insufficient compatibility and dependency analysis.
Scenario B: A new network configuration interrupts customers during peak business hours.
Likely issue: Inadequate maintenance-window planning and impact analysis.
Scenario C: A failed deployment needs to be reversed to restore service.
Relevant concept: Backout planning.
Scenario D: A corrective migration is necessary because the previous database format cannot safely be restored.
Relevant concept: Fail forward.
Scenario E: Engineers cannot determine who changed an application configuration last week.
Relevant concept: Version control, change records, and accountability.
Objective 1.2 Summary
Change management is an essential part of cybersecurity because technically valid changes can still create unacceptable risks.
The examination emphasizes recognition of authorization, ownership, stakeholder communication, impact analysis, testing, recovery strategies, operational consequences, documentation, and version control.
1.3 — Explain the Importance of Using Appropriate Cryptographic Solutions
Cryptography uses mathematical techniques to protect information and support security functions such as confidentiality, integrity, authentication, and digital signatures.
Different cryptographic solutions solve different problems.
The exam expects candidates to understand how these technologies differ and recognize which are appropriate for particular scenarios.
Public Key Infrastructure (PKI)
Public Key Infrastructure is the collection of technologies, policies, processes, and trusted entities used to manage public-key certificates and associated cryptographic operations.
PKI helps establish trust between parties that may not have previously communicated.
Public Key
A public key is part of an asymmetric cryptographic key pair.
It can be distributed to other parties.
Depending on the algorithm, it may be used to encrypt information for the private-key holder, verify a digital signature, or participate in key establishment.
Private Key
A private key is the secret component of an asymmetric key pair.
It may be used to decrypt information, produce digital signatures, or participate in key agreement, depending on the algorithm.
Private keys require strong protection because compromise can undermine the associated cryptographic trust.
Key distinction: Public keys are intended to be shared. Private keys must remain protected.
Key Escrow
Key escrow is an arrangement in which encryption keys or recovery material are securely held by an authorized third party or designated organization.
Its purpose is to support authorized recovery when normal key access is unavailable.
For example, an organization might maintain protected recovery keys for encrypted corporate storage.
Key escrow introduces security and governance concerns because escrowed material must be protected from unauthorized access.
Signing private keys generally should not be escrowed for routine recovery because this can undermine accountability and non-repudiation.
Digital Certificates
Digital certificates bind public keys to identifying information and support authentication and trust validation.
Certificates are fundamental to many secure communications systems.
Certificate Authorities (CAs)
A certificate authority issues and digitally signs certificates.
A trusted CA provides a basis for determining whether a certificate's asserted identity and public key can be accepted under a particular trust policy.
A certificate being issued by a CA does not, by itself, guarantee that every device trusts it.
Certificate Revocation Lists (CRLs)
A Certificate Revocation List identifies certificates revoked by an issuing CA before their scheduled expiration.
Possible reasons include private-key compromise, incorrect issuance, or an organizational decision to invalidate a certificate.
CRLs allow relying parties to assess whether listed certificates remain valid.
Online Certificate Status Protocol (OCSP)
OCSP provides a mechanism for obtaining revocation-status information about a certificate.
It is an alternative to downloading a full CRL in supported environments.
CRL versus OCSP: CRLs provide lists of revoked certificates; OCSP supports certificate-specific status queries.
Actual revocation checking depends on the application, certificate configuration, and trust-validation policy.
Self-Signed Certificates
A self-signed certificate is signed using its own corresponding private key.
A self-signed certificate is not necessarily insecure. Its trust must be established through an independent, appropriate mechanism.
Self-signed certificates are commonly associated with private trust configurations, internal services, and root certificate authorities.
Third-Party Certificates
A third-party certificate is issued and signed by an external CA rather than being self-signed by the requesting entity.
Certificates issued by publicly trusted CAs are widely used for public-facing websites.
Third-party issuance does not automatically establish trust; the certificate chain, identity, validity, and other requirements must still be evaluated.
Root of Trust
A root of trust is a trusted foundation from which other trust decisions are derived.
Within PKI, a trusted root CA certificate may anchor a chain containing one or more intermediate CA certificates and an end-entity certificate.
Trust-chain validation helps determine whether a certificate is linked to an acceptable trust anchor.
Certificate Signing Request (CSR) Generation
A Certificate Signing Request contains information submitted when requesting issuance of a certificate.
A CSR typically includes a public key, identifying information, and a signature demonstrating control of the corresponding private key.
The private key is not normally included in the CSR.
A CA evaluates the request according to its issuance requirements before producing a certificate.
Wildcard Certificates
A wildcard certificate covers multiple names matching a defined wildcard pattern.
For example, a certificate for *.example.com may cover portal.example.com and mail.example.com.
It does not automatically cover example.com or deeper names such as secure.portal.example.com unless those names are otherwise included.
Wildcard certificates simplify certificate coverage but can increase the consequences of private-key compromise when the same key is used across multiple services.
Encryption
Encryption transforms plaintext into ciphertext using a cryptographic algorithm and key.
Authorized decryption restores the original information.
Encryption primarily protects confidentiality, although authenticated encryption schemes can also provide integrity and authenticity protections.
Encryption Protocols
Cryptographic protocols define how security mechanisms operate during communications or other cryptographic exchanges.
Common examples include:
| Protocol | Typical purpose |
|---|---|
| TLS | Protecting network communications such as HTTPS |
| IPsec | Securing IP network communications |
| SSH | Securing remote command sessions and related communications |
Protocols are not identical to encryption algorithms.
For example, TLS is a security protocol that can use different cryptographic algorithms and key-establishment mechanisms.
Symmetric Encryption
Symmetric encryption uses the same secret key, or closely related secret-key material, for encryption and decryption.
Its major advantage is computational efficiency.
The Advanced Encryption Standard (AES) is a widely used symmetric algorithm.
Symmetric encryption is suitable for bulk data protection such as encrypted storage and application traffic.
The principal challenge is securely distributing and managing shared secret keys.
Asymmetric Encryption
Asymmetric cryptography uses a mathematically related public/private key pair.
In public-key encryption, the public key can be used to encrypt information while the corresponding private key is required for decryption.
Asymmetric cryptography also supports digital signatures and key establishment.
RSA and elliptic-curve cryptographic systems are important examples, although particular algorithms have distinct functions.
| Characteristic | Symmetric encryption | Asymmetric cryptography |
|---|---|---|
| Key structure | Shared secret key | Public/private key pair |
| Bulk-data efficiency | Generally high | Generally lower |
| Main challenge | Secure sharing and protection of secret keys | Authenticating public keys and protecting private keys |
| Common uses | File and communication encryption | Digital signatures, key establishment, some encryption |
| Example | AES | RSA |
Many secure systems combine asymmetric techniques for authentication or key establishment with symmetric encryption for actual data transfer.
Encryption Levels
Encryption can be applied at different levels.
Full-Disk Encryption
Full-disk encryption protects data across an entire disk or the relevant protected disk area.
It is useful for reducing exposure when devices or storage media are lost or stolen.
It does not automatically prevent an authenticated user or malware operating within an unlocked system from accessing data.
Partition Encryption
Partition encryption protects a selected partition rather than necessarily encrypting an entire physical disk.
It provides a more specific encryption boundary.
File Encryption
File encryption protects individual files.
This allows selected information to receive cryptographic protection without necessarily encrypting all storage on a device.
Volume Encryption
Volume encryption protects a logical storage volume.
A logical volume may span storage structures that do not correspond directly to a single physical disk or partition.
Database Encryption
Database encryption protects information within a database system or its storage structures.
Different designs may encrypt database files, tables, columns, or other components.
The protection provided depends on the database architecture, key management, and encryption method.
Record Encryption
Record-level encryption protects individual records, allowing more granular security for selected information.
A financial application might encrypt particularly sensitive customer records independently of broader storage encryption.
Selecting an Encryption Level
| Requirement | Relevant solution |
|---|---|
| Protect an entire lost laptop's stored data | Full-disk encryption |
| Protect a selected storage partition | Partition encryption |
| Protect specific documents | File encryption |
| Protect an entire logical storage volume | Volume encryption |
| Protect stored database information | Database encryption |
| Protect selected individual records | Record-level encryption |
The correct choice depends on the scope of information requiring protection.
Transport and Communication Encryption
Transport encryption protects data while it moves across a communication channel.
HTTPS commonly uses TLS to protect communications between a browser and a web server.
Transport encryption differs from storage encryption: protecting traffic in transit does not automatically encrypt the information once it is stored.
Transport encryption also does not necessarily provide end-to-end secrecy against every intermediary. Its protection boundary depends on where the encrypted connection terminates.
Key Exchange
Key exchange and key-establishment mechanisms allow communicating parties to establish cryptographic key material.
Diffie-Hellman and Elliptic Curve Diffie-Hellman are important examples of key-agreement mechanisms.
Authenticated ephemeral key agreement can provide forward secrecy, meaning later compromise of a long-term authentication key does not automatically reveal previously established session keys.
Key agreement does not inherently authenticate the parties. Authentication must be appropriately incorporated to resist impersonation and on-path attacks.
Exam distinction: Key exchange establishes key material; encryption uses keys to protect information.
Cryptographic Algorithms
Cryptographic algorithms define the mathematical operations used for cryptographic protection.
Important categories include symmetric algorithms, asymmetric algorithms, and hash functions.
| Algorithm | Category | Main use |
|---|---|---|
| AES | Symmetric encryption | Data encryption |
| RSA | Asymmetric | Encryption or digital signatures with appropriate schemes |
| ECDSA | Asymmetric signature | Digital signatures |
| ECDH | Key agreement | Establishing shared secret material |
| SHA-256 | Cryptographic hash | Integrity-related hashing |
| SHA-3 | Cryptographic hash family | Hashing and related cryptographic constructions |
Some older algorithms, including DES, 3DES, MD5, and SHA-1, have significant security limitations in modern applications.
An algorithm's suitability depends on its design, configuration, intended purpose, implementation, and current security guidance.
Key Length
Key length describes the size of a cryptographic key.
Longer keys can increase resistance to exhaustive key-search attacks when comparing keys within the same algorithm and security model.
However, key lengths across different algorithms are not directly comparable.
For example, a 256-bit AES key and a 256-bit elliptic-curve key do not imply identical security properties.
AES-128, AES-192, and AES-256 are standardized AES key sizes.
Modern RSA deployments commonly use keys of at least 2048 bits under applicable security guidance.
The exam may test the relationship between key length, security strength, performance, and cryptographic algorithm selection.
Key principle: Appropriate key strength depends on the algorithm, not merely the largest numerical key length.
Digital Signatures
A digital signature is a cryptographic mechanism used to verify the integrity and asserted origin of signed information.
A signing algorithm uses a private key to generate a signature, and a verification algorithm uses the corresponding public key.
Digital signatures can support authentication, integrity, and non-repudiation.
They do not ordinarily provide confidentiality because signed information is not necessarily encrypted.
A certificate-based signing system additionally depends on trust in the certificate and the associated identity.
Salting
Salting introduces a value, usually unique to each stored password, into the password-hashing process.
Its purpose is to make precomputed password-hash attacks less effective and prevent identical passwords from automatically producing identical stored password-hash outputs.
A salt is not the same as an encryption key, and it does not need to be secret.
Secure password storage also requires a suitable, deliberately expensive password-hashing function, such as Argon2id, scrypt, bcrypt, or PBKDF2, configured appropriately.
Exam distinction: Salting helps protect password hashes. Encryption provides reversible protection for data when the appropriate key is available.
Cryptographic Tools
Cryptographic tools are technologies used to generate, store, protect, apply, or manage cryptographic keys and operations.
Examples include:
Hardware Security Module (HSM): A specialized device designed to protect cryptographic keys and perform sensitive cryptographic operations under controlled conditions.
Trusted Platform Module (TPM): A hardware-based or firmware-supported security component providing protected cryptographic capabilities, such as key operations, measurements, and device-related security functions.
Key Management System (KMS): A service or system that manages cryptographic keys through processes such as creation, access control, lifecycle management, and rotation.
Certificate management tools: Systems that support certificate issuance, inventory, renewal, revocation, and lifecycle management.
Encryption software: Applications or platform capabilities that protect stored information or communications using cryptographic algorithms.
A TPM, HSM, and KMS are not interchangeable.
For example, an HSM emphasizes protected cryptographic key operations; a KMS emphasizes management of keys across their lifecycle and may use HSMs for underlying protection.
Obfuscation
Obfuscation makes information harder to interpret or understand.
It is not necessarily cryptographic protection.
Examples include disguising program logic, replacing recognizable identifiers, or representing information in a less-readable format.
Base64 encoding is not encryption. It changes data representation without requiring a secret decryption key.
Exam distinction:
- Encoding changes representation.
- Obfuscation obscures understanding.
- Encryption protects data using cryptographic algorithms and keys.
- Hashing produces a fixed-length digest used for purposes such as integrity checking.
Hashing Algorithms
A cryptographic hash function transforms arbitrary-length input into a fixed-length digest.
A secure cryptographic hash function is designed to make it computationally difficult to reverse the digest to recover the original input, find a second input matching an existing input's hash, or find any two distinct inputs with the same digest.
Common Hashing Concepts
One-way property: Hashing is not intended to be reversed through decryption.
Deterministic output: The same input produces the same hash with the same algorithm.
Avalanche effect: A small change in input generally produces a substantially different output.
Collision resistance: It should be computationally difficult to find two different inputs with the same hash.
Collisions are mathematically possible because infinitely many potential inputs map to a finite set of digest values.
Common Hashing Algorithms
SHA-256: A widely used SHA-2 family algorithm producing a 256-bit digest.
SHA-512: A SHA-2 family algorithm producing a 512-bit digest.
SHA-3: A separate standardized cryptographic hash family using a design different from SHA-2.
MD5: A legacy 128-bit hash algorithm with known collision weaknesses, unsuitable for applications requiring collision resistance.
SHA-1: A legacy hash algorithm with known collision weaknesses, unsuitable for modern collision-resistant signature applications.
Hashing Versus Encryption
| Property | Hashing | Encryption |
|---|---|---|
| Reversible through a decryption operation | No | Yes, with the appropriate key |
| Primary application | Integrity and related functions | Confidentiality |
| Uses a decryption key | No | Yes |
| Example | SHA-256 | AES |
Hashing by itself does not authenticate the source of data. Authentication may require a keyed message authentication code (MAC), such as HMAC, or a digital signature.
Objective 1.3 Summary
Cryptographic technologies must be selected according to the security problem.
Encryption protects confidentiality. Hashing supports integrity-related operations. Digital signatures provide integrity and origin verification. PKI supports certificate-based trust. Key-management technologies protect and administer the cryptographic material on which these systems depend.
The examination emphasizes selecting appropriate solutions rather than treating every cryptographic technology as interchangeable.
Domain 1.0 — Examination Preparation
The following questions are original practice questions based on the concepts covered in this lesson. They are not actual CompTIA examination questions.
Questions
1. An organization uses multiple independent security controls so that compromising one protection does not automatically expose critical systems. What does this illustrate?
A. Accounting
B. Defense in depth
C. Non-repudiation
D. Certificate revocation
2. A user successfully signs into a corporate application but cannot access the payroll database. Which AAA function restricts the user's access?
A. Accounting
B. Authentication
C. Authorization
D. Availability
3. A security team implements a system that alerts when unusual administrative activity occurs. What type of control is primarily represented?
A. Detective
B. Directive
C. Deterring
D. Corrective
4. An organization is unable to install a required security update on a legacy system and implements network isolation as an alternative safeguard. What type of control is this?
A. Directive
B. Compensating
C. Deterring
D. Managerial
5. A security policy requires formal approval before modifications to production firewall configurations. Which process primarily supports this requirement?
A. Certificate validation
B. Key exchange
C. Change management
D. Data obfuscation
6. A software deployment has altered a database in a way that makes returning to its original format unsafe. Which recovery approach may be appropriate?
A. Backout
B. Fail forward
C. Certificate revocation
D. Key escrow
7. A security engineer discovers that a network architecture diagram does not reflect a recent approved infrastructure change. Which change management activity was incomplete?
A. Updating documentation
B. Encrypting data
C. Password salting
D. Certificate issuance
8. Which cryptographic method generally uses the same secret key to encrypt and decrypt information?
A. Hashing
B. Symmetric encryption
C. Digital signatures
D. Asymmetric encryption
9. A company needs to protect stored information on a lost laptop. Which encryption level most directly matches the requirement?
A. Transport encryption
B. Full-disk encryption
C. Digital signatures
D. Hashing
10. Which technology provides certificate-specific revocation-status information?
A. OCSP
B. AES
C. ECDH
D. TPM
11. A company wants customers to verify that downloaded software originated from its authorized publisher and has not been altered. Which mechanism best supports this objective?
A. Obfuscation
B. Salting
C. Digital signature
D. Full-disk encryption
12. An organization uses unique random salts for stored passwords. What security benefit does this primarily provide?
A. Password decryption
B. Protection against precomputed hash attacks
C. Increased network bandwidth
D. Automatic certificate renewal
13. Which technology is designed to protect cryptographic keys and perform sensitive cryptographic operations within a specialized security device?
A. HSM
B. CRL
C. CAB
D. SOP
14. A certificate covers *.example.com. Which name would typically match its wildcard pattern?
A. example.com
B. mail.example.com
C. secure.mail.example.com
D. anotherexample.com
15. A company needs a mechanism that allows two communicating parties to establish shared secret material without previously sharing that secret. Which technology is relevant?
A. Diffie-Hellman key agreement
B. Base64 encoding
C. MD5 hashing
D. Certificate revocation
Answer Key and Explanations
| Question | Answer | Explanation |
|---|---|---|
| 1 | B | Defense in depth uses multiple layers of protection. |
| 2 | C | Authorization determines which resources an identity may access. |
| 3 | A | Detective controls identify suspicious or unauthorized activity. |
| 4 | B | Compensating controls provide alternative safeguards. |
| 5 | C | Change management governs review and authorization of modifications. |
| 6 | B | Fail forward resolves an unsuccessful change through a subsequent corrective change. |
| 7 | A | Technical changes must be reflected in associated documentation. |
| 8 | B | Symmetric encryption uses shared secret-key material. |
| 9 | B | Full-disk encryption protects stored information across the protected disk area. |
| 10 | A | OCSP provides certificate revocation-status information. |
| 11 | C | Digital signatures support integrity and origin verification. |
| 12 | B | Unique salts reduce the effectiveness of precomputed hash attacks. |
| 13 | A | HSMs provide specialized protection for sensitive cryptographic operations. |
| 14 | B | The wildcard matches a single subdomain label in this example. |
| 15 | A | Diffie-Hellman supports establishment of shared secret material. |
Final Review — Domain 1.0
| Objective | Required knowledge |
|---|---|
| 1.1 | Defense in depth, CIA, AAA, non-repudiation, Zero Trust, least privilege, all four control categories, and all six control types |
| 1.2 | CAB, approval, ownership, stakeholders, impact analysis, test results, backout, fail forward, maintenance windows, SOPs, allow/deny lists, restricted activities, downtime, restarts, legacy systems, dependencies, documentation, and version control |
| 1.3 | PKI, public/private keys, key escrow, all certificate concepts, encryption methods and levels, communication security, key exchange, algorithms, key lengths, digital signatures, salting, cryptographic tools, obfuscation, and hashing |
Preparing for the Examination
Understanding definitions is only the beginning. Security+ also requires candidates to interpret scenarios and distinguish between technologies that may appear similar.
For General Security Concepts, the most important examination skills are recognizing the purpose of security controls, identifying change-related risks, and selecting cryptographic mechanisms appropriate to particular security objectives.
Next Lesson: Part 3 — Threats, Vulnerabilities, and Attacks (Domain 2.0)
Official reference: CompTIA Security+ SY0-801 V8 Certification Exam Objectives, Version 2.0, Domain 1.0, pages 4–5.
https://lecbyo.files.cmp.optimizely.com/download/77f3bd3223ac11f180820e495f189928
*Tech Little Brawta is an independent educational resource and is not affiliated with or endorsed by CompTIA. Security+ and CompTIA are trademarks of CompTIA, Inc.*
