Domain 1.0 | Exam Weight: 16% | Objectives 1.1–1.3

Introduction

Organizations protect information, systems, networks, and business operations using a combination of security principles, controls, processes, and cryptographic technologies.

Understanding these concepts is fundamental to cybersecurity. Security professionals must recognize which protections are appropriate for different situations, why particular controls are implemented, and how technical or operational decisions affect an organization's security posture.

General Security Concepts accounts for 16% of the CompTIA Security+ SY0-801 examination.

This lesson covers all three objectives in Domain 1.0:

  • 1.1: Explain security concepts and controls.
  • 1.2: Given a scenario, demonstrate the impact of change management processes on security.
  • 1.3: Explain the importance of using appropriate cryptographic solutions.

The objective is to understand the terminology, distinguish similar concepts, interpret scenarios, and identify the most appropriate security response.


1.1 — Explain Security Concepts and Controls

Defense in Depth

Defense in depth is a security strategy that uses multiple independent or complementary protective measures to reduce the likelihood that a single failure will compromise an entire system.

Consider a financial institution protecting customer information. Its security controls may include physical access restrictions, network firewalls, multifactor authentication, application permissions, encryption, and security monitoring.

If an attacker obtains an employee's password, additional controls may still prevent unauthorized access.

Defense in depth recognizes that no individual security mechanism is completely reliable.

Confidentiality, Integrity, and Availability (CIA)

The CIA triad defines three primary objectives of information security.

Confidentiality

Confidentiality ensures information is disclosed only to authorized individuals, processes, or systems.

For example, employee salary records should be available only to personnel who have a legitimate business reason to access them.

Common protections include encryption, access controls, authentication, and data classification.

Integrity

Integrity ensures that information remains accurate, complete, and protected against unauthorized modification.

For example, an unauthorized change to a banking transaction would compromise integrity, even if the transaction remained confidential.

Integrity protections include cryptographic hashes, digital signatures, access controls, and change tracking.

Availability

Availability ensures authorized users can access information and services when they are needed.

A denial-of-service attack that prevents customers from using an online banking application primarily affects availability.

Availability measures include redundancy, failover, backup systems, disaster recovery, and resilient infrastructure.

Recognizing CIA in Examination Questions

ScenarioPrimary principle
Unauthorized employee reads patient recordsConfidentiality
Financial records are secretly modifiedIntegrity
A server outage prevents users from accessing an applicationAvailability
Encrypted confidential documents are stolen but cannot be read without the keyConfidentiality protection
A digital signature reveals a modified documentIntegrity verification

A security incident can affect multiple CIA principles simultaneously. Examination questions may ask for the primary principle involved.

Authentication, Authorization, and Accounting (AAA)

AAA is a framework for controlling access to resources and recording relevant activity.

Authentication

Authentication verifies an identity claim.

Common authentication factors include:

  • Something a person knows, such as a password.
  • Something a person has, such as a hardware security key.
  • Something a person is, such as a fingerprint.

Multifactor authentication combines factors from at least two different categories.

Using two passwords is not multifactor authentication because both are knowledge factors.

Authorization

Authorization determines what an authenticated identity is permitted to access or perform.

An employee might successfully sign in to a corporate system but lack permission to view financial reports.

The identity has been authenticated but not authorized for that resource.

Authorization may be implemented through access control lists, role-based access control, attribute-based access control, and other policies.

Accounting

Accounting records activities associated with users, services, and systems.

Examples include login events, access attempts, administrative actions, and resource usage.

Accounting supports investigations, auditing, accountability, and compliance.

Examination distinction:

Authentication establishes identity. Authorization establishes permissions. Accounting records activity.

Non-repudiation

Non-repudiation provides evidence that an action or communication originated from a particular party, helping prevent credible denial of that action.

Digital signatures are commonly associated with non-repudiation.

Suppose a company executive digitally signs an electronic agreement. A valid signature can help demonstrate that the document was signed using the corresponding private key and has not been modified since signing.

Non-repudiation depends on trustworthy identity verification, key protection, and evidence handling. A valid signature alone does not establish who physically operated a compromised device.

Remember: Encryption protects confidentiality; digital signatures provide evidence of origin and integrity.

Zero Trust Principles

Zero Trust is a security model built around minimizing implicit trust.

A device or user should not be considered trustworthy merely because it is connected to an internal corporate network.

Access decisions consider identity, authorization, device condition, context, and applicable policies.

Core principles include:

Verify explicitly: Evaluate each access request against relevant authentication and authorization requirements.

Use least privilege: Limit access to what is necessary.

Assume breach: Design protections under the assumption that an attacker may already have gained access somewhere in the environment.

Zero Trust commonly uses identity-based access decisions, device assessment, segmentation, continuous evaluation, and strong monitoring.

It is not synonymous with a VPN, firewall, or a single commercial product.

Least Privilege

Least privilege means assigning only the permissions needed for an identity to complete its authorized functions.

For example, an employee responsible for viewing invoices does not normally require permission to delete the company's accounting database.

Least privilege reduces the possible damage from compromised accounts, mistakes, and malicious insiders.

A related principle is separation of duties, in which important responsibilities are divided so that one person cannot independently complete a sensitive process without oversight.

Least privilege concerns the amount of access granted. Separation of duties concerns how responsibilities are distributed.

Security Control Categories

Security controls can be classified by how they are administered or implemented.

Technical/Logical Controls

Technical controls use hardware or software to enforce security requirements.

Examples include firewalls, encryption, multifactor authentication, endpoint protection, and access-control systems.

Managerial/Administrative Controls

Managerial controls provide organizational direction and oversight.

Examples include security policies, risk assessments, governance frameworks, and formal security planning.

Physical/Environmental Controls

Physical controls protect facilities, equipment, and locations.

Examples include door locks, fences, security lighting, equipment enclosures, and controlled access to data centers.

Environmental protections such as fire suppression and water-leak detection help protect physical infrastructure.

Operational Controls

Operational controls govern security through ongoing procedures and activities performed by people and organizational processes.

Examples include incident-handling activities, security awareness training, routine monitoring, and operational procedures.

Some controls overlap categories. The classification depends on the aspect emphasized in the scenario.

Security Control Types

Security control types describe the intended function of a control.

Control typePurposeExample
PreventivePrevent unwanted activityAccess control that blocks unauthorized logins
DeterringDiscourage unwanted behaviorVisible security presence
CorrectiveCorrect conditions after an eventRestoring a damaged system from a clean backup
DetectiveDiscover suspicious or unauthorized activityIntrusion detection alert
CompensatingProvide alternative protection when the preferred control cannot be usedAdditional restrictions and monitoring for an unsupported legacy application
DirectiveEstablish required behaviorA policy requiring approved handling of sensitive information

Understanding the Differences

Preventive versus detective: A preventive control attempts to stop an event. A detective control identifies activity that has occurred or is occurring.

Deterring versus preventive: A warning sign may discourage trespassing but cannot physically block entry. A locked door may prevent entry.

Corrective versus compensating: A corrective control addresses a problem after an event. A compensating control provides alternative risk reduction when a preferred safeguard is unavailable or impractical.

Directive versus technical enforcement: A password policy tells employees what is required. A system that automatically rejects noncompliant passwords enforces a technical restriction.

Exam example: An organization cannot immediately replace a legacy system that lacks modern authentication. It isolates the system and adds restrictive access controls.

These additional safeguards are compensating controls.

Objective 1.1 Summary

A candidate should distinguish security objectives, access-control functions, trust models, and control classifications.

When analyzing a question, identify whether it describes a security goal, an identity or permission decision, the implementation category of a control, or the control's intended function.


1.2 — Given a Scenario, Demonstrate the Impact of Change Management Processes on Security

Change management is a structured process for evaluating, authorizing, implementing, documenting, and reviewing changes to systems or business operations.

An improperly managed change may expose information, create vulnerabilities, cause service interruptions, or invalidate existing controls.

CompTIA expects candidates to recognize both the business processes governing changes and their technical security implications.

Business Processes Impacting Security Operations

Change Advisory Board (CAB)

A Change Advisory Board evaluates proposed changes and advises on their potential impacts.

A CAB may include representatives from IT operations, cybersecurity, networking, applications, business management, and other affected groups.

Its responsibilities may include assessing risk, considering dependencies, reviewing readiness, and making recommendations about scheduling or approval.

Not every organization uses a CAB for every change, and the CAB is not necessarily the final approving authority.

Approval Process

Formal approval establishes that a change has been evaluated and authorized by the appropriate people before implementation.

Approval processes help prevent unreviewed modifications, unauthorized configuration changes, and unexpected business disruption.

Emergency changes may follow expedited procedures, but they still require suitable accountability and subsequent review.

Ownership

Ownership establishes accountability for a system, service, change, or business process.

A change owner or system owner may be responsible for ensuring the correct reviews occur, risks are understood, and results are documented.

Clearly defined ownership reduces the likelihood that important security responsibilities will be overlooked.

Stakeholders

Stakeholders are individuals or groups affected by a proposed change.

They may include business users, security personnel, application owners, system administrators, customers, and external service providers.

For example, changing an authentication service may affect employees, applications, help desk personnel, and business operations.

Stakeholder involvement helps identify consequences that may not be obvious to the team performing the change.

Impact Analysis

Impact analysis examines the expected and potential effects of a change.

It should consider:

  • Security risks and possible new exposure.
  • Business continuity and availability.
  • Dependencies between systems.
  • Compatibility with existing applications.
  • Required resources and service interruption.
  • Compliance, privacy, and operational consequences.

A software update might address a critical vulnerability while disrupting a dependent application. Both effects matter when evaluating the change.

Test Results

Test results provide evidence about how a proposed change performs under evaluated conditions.

Testing may reveal compatibility problems, performance degradation, security-control failures, or unexpected functionality changes.

Successful testing reduces uncertainty but cannot guarantee that production deployment will behave identically.

The examination may present a scenario in which a change was deployed without reviewing test results, leading to an avoidable outage or security failure.

Backout Planning

A backout plan describes how an organization can return a system to its previous acceptable state if a change fails.

A backout plan may involve restoring configurations, reversing a deployment, or using recovery mechanisms.

The essential concept is reversibility.

Not every change is safely reversible. Database migrations and irreversible data transformations are common examples requiring special consideration.

Fail Forward

Fail forward means resolving a failed change through a subsequent corrective change rather than returning to the previous version.

For example, if a database schema migration has already altered production data in a way that makes rollback unsafe, a forward-compatible correction may be preferable.

Exam distinction: Backout restores an earlier state; fail forward advances to a corrected state.

Maintenance Window

A maintenance window is an approved period during which changes can occur with consideration for business activity and service availability.

Maintenance windows reduce the risk of disruption during critical operating periods.

They do not eliminate the need for approval, testing, monitoring, or recovery planning.

Standard Operating Procedures (SOPs)

SOPs are documented instructions governing how routine organizational processes should be performed.

They help establish consistency, accountability, repeatability, and compliance.

In change management, SOPs may define responsibilities, evidence requirements, escalation procedures, implementation standards, and closure criteria.

Technical Implications of Changes

Allow Lists and Deny Lists

An allow list identifies explicitly permitted entities, operations, applications, or connections.

A deny list identifies explicitly prohibited ones.

For example, a firewall configuration may permit selected services and block other traffic.

Changing these lists can either increase or reduce exposure.

Allow-list approaches are commonly associated with default-deny security models, although actual behavior depends on the system's rule-processing logic.

Restricted Activities

Organizations may restrict certain activities during change implementation.

Examples include limiting configuration modifications to authorized personnel, prohibiting unrelated changes during sensitive maintenance, and restricting access to critical infrastructure.

These restrictions reduce interference and help preserve accountability.

Downtime

Downtime is a period when a service is unavailable.

A change can cause planned downtime, unplanned downtime, or partial service degradation.

Security consequences may include unavailable monitoring, authentication failures, disruption of protective services, and impacts on business continuity.

Service Restart

A service restart stops and starts a specific background service or process.

A configuration change may not take effect until a service reload or restart occurs.

Restarting a service can interrupt applications that depend on it.

Application Restart

An application restart restarts an application or its runtime.

An application may consist of multiple services, processes, and dependencies.

The difference matters: restarting one service may be less disruptive than restarting an entire application.

Legacy Applications

Legacy applications are older systems that may depend on obsolete software, protocols, configurations, or unsupported components.

They may be incompatible with current encryption standards, authentication methods, or operating system updates.

Legacy dependencies can complicate security improvements and require additional risk management.

Dependencies

Dependencies are relationships in which one system or function relies on another.

An application may depend on DNS, databases, certificate services, identity providers, network connectivity, or external APIs.

A change to one dependency can affect multiple downstream services.

Scenario: A certificate authority is replaced, and several applications stop authenticating because they do not trust the new issuing authority.

The primary planning issue is an overlooked trust dependency.

Documentation

Documentation preserves the information required to understand, operate, secure, and maintain systems.

Updating Diagrams

Architecture and network diagrams should accurately represent the operational environment.

Changes to firewalls, network segments, connections, infrastructure components, or trust relationships may make older diagrams inaccurate.

Incorrect diagrams can hinder troubleshooting, incident response, and security reviews.

Updating Policies and Procedures

Security policies and procedures should reflect the organization's approved operating requirements.

When systems or processes change, associated documentation may also require updates.

Otherwise, personnel may follow outdated instructions or misunderstand the current security requirements.

Version Control

Version control maintains a history of changes to documents, software, configurations, and other managed artifacts.

It supports:

  • Identifying what changed.
  • Tracking who made a change.
  • Comparing versions.
  • Supporting authorized review.
  • Recovering earlier versions when feasible.
  • Preserving evidence for troubleshooting and audits.

Version control is not the same as backup. A version history may support recovery, but it does not replace a properly designed backup and disaster-recovery strategy.

Objective 1.2 Scenario Review

Scenario A: A security update causes a critical legacy application to stop working.

Likely issue: Insufficient compatibility and dependency analysis.

Scenario B: A new network configuration interrupts customers during peak business hours.

Likely issue: Inadequate maintenance-window planning and impact analysis.

Scenario C: A failed deployment needs to be reversed to restore service.

Relevant concept: Backout planning.

Scenario D: A corrective migration is necessary because the previous database format cannot safely be restored.

Relevant concept: Fail forward.

Scenario E: Engineers cannot determine who changed an application configuration last week.

Relevant concept: Version control, change records, and accountability.

Objective 1.2 Summary

Change management is an essential part of cybersecurity because technically valid changes can still create unacceptable risks.

The examination emphasizes recognition of authorization, ownership, stakeholder communication, impact analysis, testing, recovery strategies, operational consequences, documentation, and version control.


1.3 — Explain the Importance of Using Appropriate Cryptographic Solutions

Cryptography uses mathematical techniques to protect information and support security functions such as confidentiality, integrity, authentication, and digital signatures.

Different cryptographic solutions solve different problems.

The exam expects candidates to understand how these technologies differ and recognize which are appropriate for particular scenarios.

Public Key Infrastructure (PKI)

Public Key Infrastructure is the collection of technologies, policies, processes, and trusted entities used to manage public-key certificates and associated cryptographic operations.

PKI helps establish trust between parties that may not have previously communicated.

Public Key

A public key is part of an asymmetric cryptographic key pair.

It can be distributed to other parties.

Depending on the algorithm, it may be used to encrypt information for the private-key holder, verify a digital signature, or participate in key establishment.

Private Key

A private key is the secret component of an asymmetric key pair.

It may be used to decrypt information, produce digital signatures, or participate in key agreement, depending on the algorithm.

Private keys require strong protection because compromise can undermine the associated cryptographic trust.

Key distinction: Public keys are intended to be shared. Private keys must remain protected.

Key Escrow

Key escrow is an arrangement in which encryption keys or recovery material are securely held by an authorized third party or designated organization.

Its purpose is to support authorized recovery when normal key access is unavailable.

For example, an organization might maintain protected recovery keys for encrypted corporate storage.

Key escrow introduces security and governance concerns because escrowed material must be protected from unauthorized access.

Signing private keys generally should not be escrowed for routine recovery because this can undermine accountability and non-repudiation.

Digital Certificates

Digital certificates bind public keys to identifying information and support authentication and trust validation.

Certificates are fundamental to many secure communications systems.

Certificate Authorities (CAs)

A certificate authority issues and digitally signs certificates.

A trusted CA provides a basis for determining whether a certificate's asserted identity and public key can be accepted under a particular trust policy.

A certificate being issued by a CA does not, by itself, guarantee that every device trusts it.

Certificate Revocation Lists (CRLs)

A Certificate Revocation List identifies certificates revoked by an issuing CA before their scheduled expiration.

Possible reasons include private-key compromise, incorrect issuance, or an organizational decision to invalidate a certificate.

CRLs allow relying parties to assess whether listed certificates remain valid.

Online Certificate Status Protocol (OCSP)

OCSP provides a mechanism for obtaining revocation-status information about a certificate.

It is an alternative to downloading a full CRL in supported environments.

CRL versus OCSP: CRLs provide lists of revoked certificates; OCSP supports certificate-specific status queries.

Actual revocation checking depends on the application, certificate configuration, and trust-validation policy.

Self-Signed Certificates

A self-signed certificate is signed using its own corresponding private key.

A self-signed certificate is not necessarily insecure. Its trust must be established through an independent, appropriate mechanism.

Self-signed certificates are commonly associated with private trust configurations, internal services, and root certificate authorities.

Third-Party Certificates

A third-party certificate is issued and signed by an external CA rather than being self-signed by the requesting entity.

Certificates issued by publicly trusted CAs are widely used for public-facing websites.

Third-party issuance does not automatically establish trust; the certificate chain, identity, validity, and other requirements must still be evaluated.

Root of Trust

A root of trust is a trusted foundation from which other trust decisions are derived.

Within PKI, a trusted root CA certificate may anchor a chain containing one or more intermediate CA certificates and an end-entity certificate.

Trust-chain validation helps determine whether a certificate is linked to an acceptable trust anchor.

Certificate Signing Request (CSR) Generation

A Certificate Signing Request contains information submitted when requesting issuance of a certificate.

A CSR typically includes a public key, identifying information, and a signature demonstrating control of the corresponding private key.

The private key is not normally included in the CSR.

A CA evaluates the request according to its issuance requirements before producing a certificate.

Wildcard Certificates

A wildcard certificate covers multiple names matching a defined wildcard pattern.

For example, a certificate for *.example.com may cover portal.example.com and mail.example.com.

It does not automatically cover example.com or deeper names such as secure.portal.example.com unless those names are otherwise included.

Wildcard certificates simplify certificate coverage but can increase the consequences of private-key compromise when the same key is used across multiple services.

Encryption

Encryption transforms plaintext into ciphertext using a cryptographic algorithm and key.

Authorized decryption restores the original information.

Encryption primarily protects confidentiality, although authenticated encryption schemes can also provide integrity and authenticity protections.

Encryption Protocols

Cryptographic protocols define how security mechanisms operate during communications or other cryptographic exchanges.

Common examples include:

ProtocolTypical purpose
TLSProtecting network communications such as HTTPS
IPsecSecuring IP network communications
SSHSecuring remote command sessions and related communications

Protocols are not identical to encryption algorithms.

For example, TLS is a security protocol that can use different cryptographic algorithms and key-establishment mechanisms.

Symmetric Encryption

Symmetric encryption uses the same secret key, or closely related secret-key material, for encryption and decryption.

Its major advantage is computational efficiency.

The Advanced Encryption Standard (AES) is a widely used symmetric algorithm.

Symmetric encryption is suitable for bulk data protection such as encrypted storage and application traffic.

The principal challenge is securely distributing and managing shared secret keys.

Asymmetric Encryption

Asymmetric cryptography uses a mathematically related public/private key pair.

In public-key encryption, the public key can be used to encrypt information while the corresponding private key is required for decryption.

Asymmetric cryptography also supports digital signatures and key establishment.

RSA and elliptic-curve cryptographic systems are important examples, although particular algorithms have distinct functions.

CharacteristicSymmetric encryptionAsymmetric cryptography
Key structureShared secret keyPublic/private key pair
Bulk-data efficiencyGenerally highGenerally lower
Main challengeSecure sharing and protection of secret keysAuthenticating public keys and protecting private keys
Common usesFile and communication encryptionDigital signatures, key establishment, some encryption
ExampleAESRSA

Many secure systems combine asymmetric techniques for authentication or key establishment with symmetric encryption for actual data transfer.

Encryption Levels

Encryption can be applied at different levels.

Full-Disk Encryption

Full-disk encryption protects data across an entire disk or the relevant protected disk area.

It is useful for reducing exposure when devices or storage media are lost or stolen.

It does not automatically prevent an authenticated user or malware operating within an unlocked system from accessing data.

Partition Encryption

Partition encryption protects a selected partition rather than necessarily encrypting an entire physical disk.

It provides a more specific encryption boundary.

File Encryption

File encryption protects individual files.

This allows selected information to receive cryptographic protection without necessarily encrypting all storage on a device.

Volume Encryption

Volume encryption protects a logical storage volume.

A logical volume may span storage structures that do not correspond directly to a single physical disk or partition.

Database Encryption

Database encryption protects information within a database system or its storage structures.

Different designs may encrypt database files, tables, columns, or other components.

The protection provided depends on the database architecture, key management, and encryption method.

Record Encryption

Record-level encryption protects individual records, allowing more granular security for selected information.

A financial application might encrypt particularly sensitive customer records independently of broader storage encryption.

Selecting an Encryption Level

RequirementRelevant solution
Protect an entire lost laptop's stored dataFull-disk encryption
Protect a selected storage partitionPartition encryption
Protect specific documentsFile encryption
Protect an entire logical storage volumeVolume encryption
Protect stored database informationDatabase encryption
Protect selected individual recordsRecord-level encryption

The correct choice depends on the scope of information requiring protection.

Transport and Communication Encryption

Transport encryption protects data while it moves across a communication channel.

HTTPS commonly uses TLS to protect communications between a browser and a web server.

Transport encryption differs from storage encryption: protecting traffic in transit does not automatically encrypt the information once it is stored.

Transport encryption also does not necessarily provide end-to-end secrecy against every intermediary. Its protection boundary depends on where the encrypted connection terminates.

Key Exchange

Key exchange and key-establishment mechanisms allow communicating parties to establish cryptographic key material.

Diffie-Hellman and Elliptic Curve Diffie-Hellman are important examples of key-agreement mechanisms.

Authenticated ephemeral key agreement can provide forward secrecy, meaning later compromise of a long-term authentication key does not automatically reveal previously established session keys.

Key agreement does not inherently authenticate the parties. Authentication must be appropriately incorporated to resist impersonation and on-path attacks.

Exam distinction: Key exchange establishes key material; encryption uses keys to protect information.

Cryptographic Algorithms

Cryptographic algorithms define the mathematical operations used for cryptographic protection.

Important categories include symmetric algorithms, asymmetric algorithms, and hash functions.

AlgorithmCategoryMain use
AESSymmetric encryptionData encryption
RSAAsymmetricEncryption or digital signatures with appropriate schemes
ECDSAAsymmetric signatureDigital signatures
ECDHKey agreementEstablishing shared secret material
SHA-256Cryptographic hashIntegrity-related hashing
SHA-3Cryptographic hash familyHashing and related cryptographic constructions

Some older algorithms, including DES, 3DES, MD5, and SHA-1, have significant security limitations in modern applications.

An algorithm's suitability depends on its design, configuration, intended purpose, implementation, and current security guidance.

Key Length

Key length describes the size of a cryptographic key.

Longer keys can increase resistance to exhaustive key-search attacks when comparing keys within the same algorithm and security model.

However, key lengths across different algorithms are not directly comparable.

For example, a 256-bit AES key and a 256-bit elliptic-curve key do not imply identical security properties.

AES-128, AES-192, and AES-256 are standardized AES key sizes.

Modern RSA deployments commonly use keys of at least 2048 bits under applicable security guidance.

The exam may test the relationship between key length, security strength, performance, and cryptographic algorithm selection.

Key principle: Appropriate key strength depends on the algorithm, not merely the largest numerical key length.

Digital Signatures

A digital signature is a cryptographic mechanism used to verify the integrity and asserted origin of signed information.

A signing algorithm uses a private key to generate a signature, and a verification algorithm uses the corresponding public key.

Digital signatures can support authentication, integrity, and non-repudiation.

They do not ordinarily provide confidentiality because signed information is not necessarily encrypted.

A certificate-based signing system additionally depends on trust in the certificate and the associated identity.

Salting

Salting introduces a value, usually unique to each stored password, into the password-hashing process.

Its purpose is to make precomputed password-hash attacks less effective and prevent identical passwords from automatically producing identical stored password-hash outputs.

A salt is not the same as an encryption key, and it does not need to be secret.

Secure password storage also requires a suitable, deliberately expensive password-hashing function, such as Argon2id, scrypt, bcrypt, or PBKDF2, configured appropriately.

Exam distinction: Salting helps protect password hashes. Encryption provides reversible protection for data when the appropriate key is available.

Cryptographic Tools

Cryptographic tools are technologies used to generate, store, protect, apply, or manage cryptographic keys and operations.

Examples include:

Hardware Security Module (HSM): A specialized device designed to protect cryptographic keys and perform sensitive cryptographic operations under controlled conditions.

Trusted Platform Module (TPM): A hardware-based or firmware-supported security component providing protected cryptographic capabilities, such as key operations, measurements, and device-related security functions.

Key Management System (KMS): A service or system that manages cryptographic keys through processes such as creation, access control, lifecycle management, and rotation.

Certificate management tools: Systems that support certificate issuance, inventory, renewal, revocation, and lifecycle management.

Encryption software: Applications or platform capabilities that protect stored information or communications using cryptographic algorithms.

A TPM, HSM, and KMS are not interchangeable.

For example, an HSM emphasizes protected cryptographic key operations; a KMS emphasizes management of keys across their lifecycle and may use HSMs for underlying protection.

Obfuscation

Obfuscation makes information harder to interpret or understand.

It is not necessarily cryptographic protection.

Examples include disguising program logic, replacing recognizable identifiers, or representing information in a less-readable format.

Base64 encoding is not encryption. It changes data representation without requiring a secret decryption key.

Exam distinction:

  • Encoding changes representation.
  • Obfuscation obscures understanding.
  • Encryption protects data using cryptographic algorithms and keys.
  • Hashing produces a fixed-length digest used for purposes such as integrity checking.

Hashing Algorithms

A cryptographic hash function transforms arbitrary-length input into a fixed-length digest.

A secure cryptographic hash function is designed to make it computationally difficult to reverse the digest to recover the original input, find a second input matching an existing input's hash, or find any two distinct inputs with the same digest.

Common Hashing Concepts

One-way property: Hashing is not intended to be reversed through decryption.

Deterministic output: The same input produces the same hash with the same algorithm.

Avalanche effect: A small change in input generally produces a substantially different output.

Collision resistance: It should be computationally difficult to find two different inputs with the same hash.

Collisions are mathematically possible because infinitely many potential inputs map to a finite set of digest values.

Common Hashing Algorithms

SHA-256: A widely used SHA-2 family algorithm producing a 256-bit digest.

SHA-512: A SHA-2 family algorithm producing a 512-bit digest.

SHA-3: A separate standardized cryptographic hash family using a design different from SHA-2.

MD5: A legacy 128-bit hash algorithm with known collision weaknesses, unsuitable for applications requiring collision resistance.

SHA-1: A legacy hash algorithm with known collision weaknesses, unsuitable for modern collision-resistant signature applications.

Hashing Versus Encryption

PropertyHashingEncryption
Reversible through a decryption operationNoYes, with the appropriate key
Primary applicationIntegrity and related functionsConfidentiality
Uses a decryption keyNoYes
ExampleSHA-256AES

Hashing by itself does not authenticate the source of data. Authentication may require a keyed message authentication code (MAC), such as HMAC, or a digital signature.

Objective 1.3 Summary

Cryptographic technologies must be selected according to the security problem.

Encryption protects confidentiality. Hashing supports integrity-related operations. Digital signatures provide integrity and origin verification. PKI supports certificate-based trust. Key-management technologies protect and administer the cryptographic material on which these systems depend.

The examination emphasizes selecting appropriate solutions rather than treating every cryptographic technology as interchangeable.


Domain 1.0 — Examination Preparation

The following questions are original practice questions based on the concepts covered in this lesson. They are not actual CompTIA examination questions.

Questions

1. An organization uses multiple independent security controls so that compromising one protection does not automatically expose critical systems. What does this illustrate?

A. Accounting
B. Defense in depth
C. Non-repudiation
D. Certificate revocation

2. A user successfully signs into a corporate application but cannot access the payroll database. Which AAA function restricts the user's access?

A. Accounting
B. Authentication
C. Authorization
D. Availability

3. A security team implements a system that alerts when unusual administrative activity occurs. What type of control is primarily represented?

A. Detective
B. Directive
C. Deterring
D. Corrective

4. An organization is unable to install a required security update on a legacy system and implements network isolation as an alternative safeguard. What type of control is this?

A. Directive
B. Compensating
C. Deterring
D. Managerial

5. A security policy requires formal approval before modifications to production firewall configurations. Which process primarily supports this requirement?

A. Certificate validation
B. Key exchange
C. Change management
D. Data obfuscation

6. A software deployment has altered a database in a way that makes returning to its original format unsafe. Which recovery approach may be appropriate?

A. Backout
B. Fail forward
C. Certificate revocation
D. Key escrow

7. A security engineer discovers that a network architecture diagram does not reflect a recent approved infrastructure change. Which change management activity was incomplete?

A. Updating documentation
B. Encrypting data
C. Password salting
D. Certificate issuance

8. Which cryptographic method generally uses the same secret key to encrypt and decrypt information?

A. Hashing
B. Symmetric encryption
C. Digital signatures
D. Asymmetric encryption

9. A company needs to protect stored information on a lost laptop. Which encryption level most directly matches the requirement?

A. Transport encryption
B. Full-disk encryption
C. Digital signatures
D. Hashing

10. Which technology provides certificate-specific revocation-status information?

A. OCSP
B. AES
C. ECDH
D. TPM

11. A company wants customers to verify that downloaded software originated from its authorized publisher and has not been altered. Which mechanism best supports this objective?

A. Obfuscation
B. Salting
C. Digital signature
D. Full-disk encryption

12. An organization uses unique random salts for stored passwords. What security benefit does this primarily provide?

A. Password decryption
B. Protection against precomputed hash attacks
C. Increased network bandwidth
D. Automatic certificate renewal

13. Which technology is designed to protect cryptographic keys and perform sensitive cryptographic operations within a specialized security device?

A. HSM
B. CRL
C. CAB
D. SOP

14. A certificate covers *.example.com. Which name would typically match its wildcard pattern?

A. example.com
B. mail.example.com
C. secure.mail.example.com
D. anotherexample.com

15. A company needs a mechanism that allows two communicating parties to establish shared secret material without previously sharing that secret. Which technology is relevant?

A. Diffie-Hellman key agreement
B. Base64 encoding
C. MD5 hashing
D. Certificate revocation

Answer Key and Explanations

QuestionAnswerExplanation
1BDefense in depth uses multiple layers of protection.
2CAuthorization determines which resources an identity may access.
3ADetective controls identify suspicious or unauthorized activity.
4BCompensating controls provide alternative safeguards.
5CChange management governs review and authorization of modifications.
6BFail forward resolves an unsuccessful change through a subsequent corrective change.
7ATechnical changes must be reflected in associated documentation.
8BSymmetric encryption uses shared secret-key material.
9BFull-disk encryption protects stored information across the protected disk area.
10AOCSP provides certificate revocation-status information.
11CDigital signatures support integrity and origin verification.
12BUnique salts reduce the effectiveness of precomputed hash attacks.
13AHSMs provide specialized protection for sensitive cryptographic operations.
14BThe wildcard matches a single subdomain label in this example.
15ADiffie-Hellman supports establishment of shared secret material.

Final Review — Domain 1.0

ObjectiveRequired knowledge
1.1Defense in depth, CIA, AAA, non-repudiation, Zero Trust, least privilege, all four control categories, and all six control types
1.2CAB, approval, ownership, stakeholders, impact analysis, test results, backout, fail forward, maintenance windows, SOPs, allow/deny lists, restricted activities, downtime, restarts, legacy systems, dependencies, documentation, and version control
1.3PKI, public/private keys, key escrow, all certificate concepts, encryption methods and levels, communication security, key exchange, algorithms, key lengths, digital signatures, salting, cryptographic tools, obfuscation, and hashing

Preparing for the Examination

Understanding definitions is only the beginning. Security+ also requires candidates to interpret scenarios and distinguish between technologies that may appear similar.

For General Security Concepts, the most important examination skills are recognizing the purpose of security controls, identifying change-related risks, and selecting cryptographic mechanisms appropriate to particular security objectives.

Next Lesson: Part 3 — Threats, Vulnerabilities, and Attacks (Domain 2.0)


Official reference: CompTIA Security+ SY0-801 V8 Certification Exam Objectives, Version 2.0, Domain 1.0, pages 4–5.

https://lecbyo.files.cmp.optimizely.com/download/77f3bd3223ac11f180820e495f189928

*Tech Little Brawta is an independent educational resource and is not affiliated with or endorsed by CompTIA. Security+ and CompTIA are trademarks of CompTIA, Inc.*