Reviewed 10 October 2026 against the linked published scope. Domain weights: risk 16%, assets 10%, engineering 13%, networks 13%, IAM 13%, assessment 12%, operations 13%, software 10%.
Memory hook: Business risk sets priorities; owners decide; layered controls and evidence provide assurance.
Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.
Risk, assets and engineering
- Governance defines direction/accountability; management implements. Business owners accept residual risk; security advises. Due care is reasonable protective action, while due diligence is continuing investigation and verification. Ethics and human safety can override a convenient technical shortcut.
- Identify assets, threats, vulnerabilities, likelihood and business impact. SLE = asset value × exposure factor; ALE = SLE × annual frequency. Treat by avoiding, mitigating, transferring or accepting through authorized management. Insurance transfers selected financial consequences, not every duty.
- Owners classify data and approve use; custodians implement handling; users follow policy. Apply minimization, retention, legal hold and appropriate sanitization across collection, processing, sharing, storage and disposal. A legal hold can suspend ordinary deletion.
- BIA establishes business priorities and dependencies. RPO targets tolerable data loss; RTO targets recovery duration; maximum tolerable disruption defines the wider business limit. Availability design and backups address different failure modes.
- Bell–LaPadula protects confidentiality: no read up/no write down. Biba protects integrity: no read down/no write up. Clark–Wilson uses controlled transactions and separation of duties. Brewer–Nash constrains conflicts based on previous access.
- A reference monitor must mediate access, resist tampering and be analyzable. Trusted computing base includes components enforcing policy; the security perimeter separates them from other components. Assurance evaluates justified confidence, not an impossible promise of no flaws.
- Symmetric encryption suits bulk data; asymmetric systems support key exchange/signatures. Hashes check integrity; HMAC authenticates with a shared secret; signatures use private-key signing/public-key verification. PKI trust requires chain, name, validity and revocation checks.
- Physical design covers site hazards, zones, power, cooling, fire, cabling and people. Fail-safe/fail-secure choices depend on what must remain safe; a locked emergency exit is not good security.
Networks, identity and assessment
- Separate data, control and management planes; segment east–west as well as north–south traffic. Stateful inspection, proxies, VPNs, IDS/IPS and application controls operate at different boundaries. Encryption does not authenticate an unsafe endpoint by itself.
- Identity proofing precedes enrollment; authentication verifies an enrolled claim; authorization permits an action; accounting records it. MFA uses different factor categories. Federation delegates identity trust; OAuth delegates authorization; OpenID Connect adds identity over OAuth; SAML exchanges assertions.
- RBAC follows roles, ABAC attributes, MAC centrally controlled labels and DAC owner choices. JIT/PAM reduce standing privilege. Separation of duties prevents one identity controlling incompatible steps; access reviews and leaver processes remove stale rights.
- Biometrics trade false acceptance against false rejection; the crossover point compares operating characteristics, not total business suitability. Enrollment, spoof resistance, privacy and recovery matter too.
- Assess scope, independence and evidence before testing. SAST inspects code; DAST tests a running system; SCA inspects dependencies; penetration testing validates exploitable paths within authorization. A vulnerability scan and audit answer different questions.
Operations and software security
- Prepare, detect/analyze, contain, eradicate, recover and improve. Preserve evidence integrity, custody and authorized access. Backup recovery, communications, crisis leadership and technical incident handling must align.
- Job rotation, mandatory absence, least privilege and separation of duties reduce abuse opportunities. Change/configuration control and trusted baselines limit drift. Incident management restores service; problem management addresses underlying causes.
- Build security into requirements, threat models, code review, testing, CI/CD, deployment and retirement. Protect repositories, runners, dependencies, signing keys and release identities. A signed build can still contain vulnerable logic.
- AI introduces untrusted output/code, prompt injection, sensitive-data leakage and delegated-action risk. Apply data provenance, bounded permissions, verification and monitoring; retain accountable human decisions.
Exam traps
- “Think like a manager” means align with business risk and authority, not ignore immediate harm.
- Compliance and outsourcing do not eliminate accountability. More restrictive is not always more appropriate.
- Choose the requested first/best/long-term action; a technical fix may follow rather than precede a necessary scope or risk decision.
Final active recall
1. Who accepts residual risk?
The authorized business owner, with informed treatment choices.
2. Bell–LaPadula versus Biba?
Confidentiality versus integrity; their classic read/write restrictions point in opposite directions.
3. Does OAuth alone prove a user identity to an application?
It delegates authorization; use an appropriate identity layer such as OpenID Connect when that is the requirement.
4. Is a vulnerability scan a penetration test?
No. A penetration test attempts authorized validation of attack paths; scanning primarily identifies potential weaknesses.
5. Why is a backup not a complete continuity plan?
Business operation also depends on people, communications, dependencies, recovery priorities and tested procedures.
Sources and further practice
- Official exam scope
- Objective-to-topic coverage map. Each full topic links to its supporting primary technical documentation.
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Security Principles and Controls
Memory hook: Protect the right property with the right kind of control.
Must remember
Confidentiality prevents unauthorized disclosure; integrity protects against unauthorized alteration; availability keeps a service usable. Authenticity establishes that something is genuine. Non-repudiation supplies evidence of origin or action, subject to trustworthy keys, identities and records.
Authentication establishes an identity, authorization decides permitted actions and accounting records activity. Identify which stage failed: a valid login with excessive database privileges is an authorization problem.
| Classification | Examples |
|---|---|
| Technical | Firewall, encryption, access-control software. |
| Managerial | Policy, risk assessment, oversight. |
| Operational | Human-run procedures, training, guard processes. |
| Physical | Locks, barriers, cameras, environmental protection. |
| Preventive / detective / corrective | Block / discover / repair. |
| Deterrent / directive / compensating | Discourage / instruct / supply an alternative protection. |
One control can have several classifications. A camera detects; a visible camera may also deter. A compensating control addresses the original control's intent when the normal implementation is not feasible; it does not simply mean a cheaper control.
Zero trust evaluates access using identity, device state, resource sensitivity and context rather than trusting network location. A policy engine decides, a policy administrator arranges the session and an enforcement point permits or blocks it. Least privilege and segmentation reduce blast radius; continuous evaluation handles changing conditions.
Honeypots, honeynets, honeyfiles and honeytokens are deception tools. Access to a decoy can be a high-value detection signal, but a decoy needs containment and monitoring.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Prevent disclosure | Access control and encryption appropriate to the data path. |
| Find unauthorized changes | Integrity checks, signatures and audit evidence. |
| Legacy system cannot implement a mandated control | Evaluate an approved compensating control against the same risk. |
Traps
- Encryption alone does not make a service available.
- Zero trust is an architecture and decision process, not one appliance.
02 · Threats, Attacks and Indicators
Memory hook: Actor explains intent; evidence identifies the technique.
Must remember
Actors differ in funding, access and motivation: nation-state espionage, organized financial crime, hacktivism, malicious or careless insiders and opportunistic attackers. Shadow IT is unapproved technology that creates unmanaged exposure; it is not necessarily malicious.
Phishing targets messages; spear phishing targets a person/group; whaling targets senior staff. Smishing uses text messages and vishing voice calls. Pretexting invents a credible story, business email compromise abuses trusted payment workflows, and tailgating exploits physical access. Verify unusual requests through an independent channel, especially when voice or video could be synthesized.
| Indicator | Likely technique / useful response |
|---|---|
| Many passwords against one account | Brute force; rate limits and monitoring. |
| One common password across many users | Password spraying; MFA and password hygiene. |
| Known breached username/password pairs | Credential stuffing; revoke/resecure reused credentials. |
| Browser executes untrusted page content | XSS; contextual output encoding and safe frameworks. |
| Query structure changes through input | Injection; parameterized queries and validation. |
| Server fetches attacker-chosen internal URL | SSRF; destination controls and restricted credentials. |
| Local IP maps to an unexpected MAC | Possible ARP spoofing; inspect trusted bindings and switching controls. |
Ransomware denies access or extorts using stolen data; a worm self-propagates; a Trojan disguises malicious behavior; rootkits hide privileged persistence; spyware captures information. Fileless activity can use legitimate interpreters and memory rather than a conspicuous executable.
Race conditions exploit timing (including time-of-check/time-of-use); buffer overflows corrupt memory; insecure direct object references expose missing object-level authorization. Supply-chain compromise can enter through dependencies, build systems or updates. Downgrade attacks seek weaker protocols; replay reuses captured valid messages without breaking the cipher.
Treat a single indicator as a hypothesis. Correlate identity, endpoint, network and application evidence before concluding cause.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Suspicious urgent transfer request | Independently verify with established contacts. |
| Database query injection | Use parameterized queries; a WAF is supplementary. |
| Large distributed traffic flood | Use upstream capacity and DDoS protections as well as local controls. |
Traps
- A strong password does not prevent phishing of a live session.
- A vulnerability is a weakness; an exploit is a method of using it.
03 · Cryptography, Certificates and Keys
Memory hook: Encrypt for secrecy; sign for origin; hash for comparison.
Must remember
Symmetric encryption uses a shared secret and is efficient for bulk data. Asymmetric cryptography uses a key pair for operations such as signatures or key establishment. TLS combines authenticated negotiation with efficient symmetric protection; it does not encrypt with a certificate as though the certificate were a secret key.
Hashing produces a digest without a decryption operation. Password storage needs a suitable salted password-hashing/key-derivation function with work cost; a fast unsalted hash is unsuitable. A salt is unique nonsecret input preventing identical passwords from sharing the same stored result. An HMAC uses a secret key to authenticate a message; a plain hash alone does not prove origin.
Digital signatures use a private signing key and public verification key. Encryption for a recipient and signing as a sender are different operations. PKI binds public keys to identities through certificates and trusted issuers. Validate chain, hostname/SAN, dates, intended use and revocation information such as CRLs/OCSP. A CSR requests issuance; a CA signs the certificate.
Key management includes generation, distribution, storage, access, rotation, revocation, backup and destruction. HSMs protect key operations; TPMs support device-bound measurements and key protection. Losing an encryption key without recovery can make intact backups unusable.
Tokenization replaces sensitive values with references, often using a protected mapping service. Masking obscures displayed data. Steganography hides the existence of a message; encryption hides meaning. Blockchain links records using cryptography and consensus but does not guarantee that input data was true.
Protect data in transit, at rest and in use with controls suited to each state. Cryptographic erase depends on effective key destruction and the absence of surviving usable key copies.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Protect bulk stored data | Symmetric encryption with controlled keys. |
| Verify a publisher | A valid digital signature and trusted identity/key binding. |
| Reduce exposure in test datasets | Approved masking, tokenization or synthetic data. |
Traps
- Base64 is encoding, not encryption.
- A valid certificate does not prove the business behind a site is honest.
04 · Secure Architecture and Network Defences
Memory hook: Reduce exposure; separate trust; inspect the right layer.
Must remember
Security responsibility changes across IaaS, PaaS and SaaS. Customers retain responsibilities for their data, identities and configuration even when infrastructure is managed. Virtual machines share a hypervisor; containers normally share the host kernel. Isolation, patching and image provenance remain important.
Segment systems by sensitivity and function: user networks, guests, servers, management, IoT and operational technology. A screened subnet/DMZ hosts externally reachable services while restricting movement inward. Air gaps and logical isolation differ; removable media and maintenance paths can still introduce risk. Industrial systems prioritize safety and availability, so patching may require controlled maintenance and compensating safeguards.
| Control | Deciding role |
|---|---|
| Stateful firewall / ACL | Permit or deny network flows at the relevant enforcement point. |
| WAF | Inspect web application requests; supplement secure application code. |
| IDS / IPS | Detect / potentially block suspicious traffic. |
| Proxy / secure web gateway | Mediate outbound web access and policy. |
| NAC | Assess/authorize device network admission. |
| VPN | Protect a tunnel; endpoint compromise remains possible. |
| DLP | Discover and restrict sensitive-data movement. |
| EDR / XDR | Endpoint detection/response / correlation across broader sources. |
Choose fail-open versus fail-closed behavior according to safety and availability requirements. A load balancer improves distribution/availability; it is not a substitute for authentication. Secure management interfaces separately from application traffic, prefer encrypted protocols and restrict administrative access.
Wireless protection includes WPA3 or appropriate enterprise authentication, secure onboarding, guest isolation and removal of legacy protocols. An evil twin imitates a legitimate network; validate the authentication server certificate in enterprise Wi-Fi rather than accepting any certificate prompt.
IaC makes configuration repeatable but also makes a bad template repeatable. Review plans, scan configurations, protect state and control deployment credentials.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Block common web-request attacks | WAF plus application-layer fixes. |
| Untrusted guest devices | Separate network and restricted routing/access. |
| Legacy industrial controller cannot be patched now | Approved segmentation, monitoring and maintenance planning. |
Traps
- A VPN does not make the endpoint trustworthy.
- Containers are not equivalent to separate hardware trust boundaries.
05 · Hardening and Vulnerability Management
Memory hook: Inventory, prioritize, fix, verify.
Must remember
You cannot secure unknown assets. Maintain ownership, location, purpose, classification, versions and support status. Apply secure baselines: remove unused software/services, disable default accounts, restrict administration, patch, configure logging and enforce appropriate endpoint protection.
Mobile management can enforce encryption, screen lock, application policy and remote wipe. BYOD raises ownership/privacy boundaries; choose whole-device management versus application/container controls deliberately. Rooted/jailbroken devices weaken assumptions. Wireless, browser, email and document settings can expose different attack surfaces.
Vulnerability scanning identifies potential weaknesses; penetration testing attempts to demonstrate exploitability within authorization and rules of engagement. Credentialed scans can inspect more internal configuration. SAST examines code without running the application; DAST tests running behavior; software composition analysis identifies dependencies and known component issues.
Prioritize using exploitability, exposure, asset value, business impact and active exploitation, not severity alone. CVE identifies a known vulnerability; CVSS scores technical severity; threat intelligence adds context. A low-scoring flaw on a critical exposed identity system can deserve urgent action.
Remediation may mean patching, reconfiguration, removing a component or applying an approved compensating control. Exceptions need owners, expiration and risk acceptance. Test compatibility, maintain a rollback plan, deploy in controlled stages and rescan to verify the issue is resolved. Suppressing an alert is not remediation.
False positive: a reported issue that is not actually present. False negative: an existing issue missed by the test. Confirm with evidence before tuning detection. Sandboxing isolates suspicious code for analysis; a safe analysis environment should not have production access or usable production credentials.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Find missing updates at scale | Authenticated scanning with appropriate permissions. |
| Prove a finding’s impact | Authorized validation or penetration testing within scope. |
| Cannot immediately patch | Time-bound approved mitigation and tracked risk. |
Traps
- CVSS alone is not business risk.
- An uncredentialed scan may miss issues visible from inside the system.
06 · Identity, Authentication and Privileged Access
Memory hook: Who are you, what may you do, and for how long?
Must remember
Factors are something you know, have or are. Two passwords are not MFA. Hardware-backed phishing-resistant authentication reduces risks that a phishable one-time code does not fully address. Biometrics need fallback and privacy controls; false acceptance and false rejection trade off against each other.
SSO reduces repeated sign-ins; federation lets one identity provider assert identity to another service. SAML carries assertions commonly used in enterprise federation. OAuth delegates authorization; OpenID Connect adds an identity layer. Kerberos uses tickets and depends on appropriate time synchronization. LDAP is a directory-access protocol, not encryption by itself.
RBAC grants access through roles; ABAC evaluates attributes and context; discretionary access lets owners delegate; mandatory access enforces centrally controlled labels. Least privilege restricts permissions; separation of duties prevents one person completing a sensitive workflow alone. Need-to-know narrows access even among sufficiently cleared users.
Provisioning must cover joiners, movers and leavers. Reconcile access after role changes and promptly revoke accounts, sessions, keys and tokens when required. Periodic access reviews find accumulated privilege and dormant accounts. Service accounts need ownership, scoped permissions and credential lifecycle controls too.
PAM manages privileged access with vaulting, approval, session recording and just-in-time elevation. Just-enough access narrows the permitted actions. A break-glass account needs controlled storage, monitoring and periodic tests; it should not become a daily shared login.
RADIUS commonly centralizes network access authentication; TACACS+ is often used for network-device administration with separable AAA functions. Certificates and device posture can supplement user identity. An authenticated user can still be compromised or unauthorized for the requested object.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Temporary production administration | Approved just-in-time privilege with logging. |
| Access depends on classification and device state | Attribute/context-based policy. |
| A user changes department | Reconcile old and new permissions, not only add the new role. |
Traps
- SSO without careful controls can concentrate compromise risk.
- Authentication success does not establish authorization for every resource.
07 · Incident Response and Evidence
Memory hook: Contain harm while preserving what explains it.
Must remember
Preparation establishes contacts, authority, playbooks, logging, tools and exercises. Detection and analysis distinguish an event from an incident and establish scope. Containment limits damage; eradication removes the cause/persistence; recovery restores trustworthy service; lessons learned improve the system. These activities can overlap and repeat.
Use the scenario's authority and safety requirements. Isolate a compromised endpoint when appropriate, but do not automatically power it off: volatile evidence may matter. Human safety and urgent containment can outweigh evidence collection when the situation requires it. Engage legal, privacy and communications owners for reporting obligations and external statements.
Chain of custody records who collected, handled, transferred and stored evidence. Integrity hashes help demonstrate that a copy has not changed; they do not independently establish who collected it or whether collection was lawful. Preserve originals and work on validated copies where practical.
Volatile sources include running processes, memory and active network connections; disks and archived logs are generally less volatile. Collection order depends on the system and investigative purpose. Record synchronized timestamps, time zones, commands and methods. A legal hold suspends normal deletion for relevant material.
Threat hunting starts with a hypothesis and seeks evidence beyond existing alerts. Root-cause analysis asks why the incident was possible, not only which host was infected. Tabletop exercises test decisions and communication; simulations and technical exercises test execution.
Backups used for recovery must be known good, accessible and protected from the same compromise. Rebuilding without revoking stolen credentials or closing the original entry point invites recurrence.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Suspected compromise with ongoing exfiltration | Authorized containment plus scoped evidence preservation. |
| Evidence may be needed in proceedings | Document custody and collection integrity. |
| Validate response coordination | Tabletop exercise with owners and decision points. |
Traps
- Reimaging first can destroy the explanation of a broader breach.
- An incident is not closed merely because alerts stop.
08 · Monitoring, Automation and Investigation
Memory hook: Correlate signals; constrain automated actions.
Must remember
Collect evidence from identity providers, endpoints, applications, DNS, proxies, firewalls, databases and cloud control planes. Normalize timestamps and retain enough context to connect a user, device, request and resource. Central collection improves correlation but needs access control, integrity protection and retention limits.
SIEM aggregates and correlates security events. SOAR orchestrates response workflows and integrations. EDR supplies endpoint evidence and response; XDR combines multiple detection domains. A dashboard without useful detections or responders is not an effective control.
| Data source | What it answers |
|---|---|
| Authentication log | Who attempted access, from where, with which outcome? |
| DNS log | Which names did a host request? |
| Flow record | Which endpoints communicated, when and how much? |
| Packet capture | What protocol details/content are visible at this point? |
| Application audit | Which business action or object was affected? |
| Endpoint telemetry | Which process, parent, file or persistence mechanism was involved? |
Encrypted traffic can still reveal timing, volume and endpoints while hiding application content. Packet capture location and collection permissions matter. Baselines distinguish ordinary patterns from meaningful deviations; tune rules with feedback instead of disabling noisy detection broadly.
Automation can enrich indicators, create tickets, quarantine endpoints, revoke sessions or enforce configurations. Give automation minimal permissions, bounded targets, tested rollback and human approval for actions with substantial impact. Protect integration credentials and validate untrusted input before passing it to scripts.
Track mean time to detect/respond, coverage, false positives and repeat incidents with clear definitions. A falling alert count can mean better security, broken collection or weaker rules; investigate the reason.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Connect login and endpoint evidence | Correlate sources in a SIEM with consistent identifiers/time. |
| Repeat a well-defined response safely | A tested SOAR playbook with scoped credentials. |
| Need packet-level protocol behavior | Capture at an authorized point; consider encryption and privacy. |
Traps
- Logs can contain credentials or personal data.
- Automating a flawed decision makes the mistake faster and broader.
09 · Governance, Risk and Assurance
Memory hook: Business owns risk; controls reduce it; evidence checks it.
Must remember
Policy states management intent; standards set mandatory requirements; procedures describe steps; guidelines advise. Assign data/system owners and accountable decision makers. Security should enable business objectives within legal and risk constraints.
Threats can exploit vulnerabilities and cause impact. Inherent risk exists before controls; residual risk remains afterward. Appetite is the broad willingness to take risk; tolerance defines acceptable variation/bounds. Treat risk by avoiding, mitigating, transferring/sharing or formally accepting it. Insurance transfers some financial consequences, not accountability or every impact.
Quantitative example: an asset worth $100,000 with 20% expected loss per event has SLE = $20,000. At 0.5 events/year, ALE = $10,000/year. Estimates are uncertain; qualitative matrices express relative likelihood/impact without pretending to precise currency.
Change control records purpose, impact, dependencies, approvals, testing, maintenance window, rollback and validation. Emergency changes still need defined authority and retrospective documentation. Version control supports traceability; it does not approve a change by itself.
Supplier assessment covers security evidence, subcontractors, data location, access, continuity, breach notification and exit/deletion terms. SLAs define service commitments; NDAs protect shared confidential information; rules of engagement constrain testing. Review suppliers throughout the relationship.
Audits compare evidence against criteria; assessments evaluate controls; attestation is a formal assertion/report; penetration tests validate selected attack paths. Compliance is a baseline tied to scope, not proof of complete security. Awareness programs need role-specific training, usable reporting channels and measured outcomes, not only annual attendance.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Control costs more than justified risk reduction | Escalate a documented business risk decision. |
| Supplier stores sensitive customer data | Assess contractual, technical and lifecycle controls. |
| Audit finds missing evidence | Correct the evidence/control process, not merely the report wording. |
Traps
- A technical administrator does not unilaterally accept business risk.
- A supplier certification applies to its stated scope and period.
10 · Data Lifecycle, Privacy and Recovery
Memory hook: Know the owner, keep only what you need, test restoration.
Must remember
Classify data by business impact and obligations, then label and protect it consistently. Owners decide use/classification; custodians implement handling. Controllers determine processing purposes while processors act under applicable instructions; exact legal duties depend on jurisdiction and contract.
The lifecycle runs through collection/creation, use, sharing, storage, retention and disposal. Minimize collection, restrict purpose and access, discover misplaced sensitive data and track copies. Data residency describes where data is stored; sovereignty/jurisdiction concerns which laws may apply. Encryption does not automatically resolve every cross-border obligation.
Choose disposal by medium and sensitivity: clear, purge or physically destroy using an approved sanitization method. A quick format or ordinary file deletion may leave recoverable data. Track disposal and verify sanitization; retain evidence when required. Legal holds can override routine deletion.
RPO measures tolerable lost data in time; RTO measures target restoration time. A business impact analysis prioritizes services and dependencies. High availability handles component failures; backups recover prior data; disaster recovery restores technology; business continuity sustains critical business operations.
Full backups simplify restoration but copy more data. Incremental backups copy changes since the preceding backup and may require a chain; differential backups copy changes since the full backup. Offline/isolated or suitably immutable copies resist attacks on live systems. Replication can also replicate corruption and deletion.
Hot, warm and cold recovery sites trade readiness for cost. Test restoration, application consistency, key availability, access, DNS and dependent services. Redundant power, UPS/generators, geographic diversity and people/process continuity address different failure modes.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Recover yesterday’s deleted records | A tested point-in-time/backup capability, not only replication. |
| Minimal data loss after disaster | A replication/backup frequency consistent with the RPO. |
| Retire sensitive storage | Approved sanitization with verification and records. |
Traps
- Replication is not a substitute for independent recovery history.
- A backup without usable decryption keys may be worthless.
11 · Security Leadership, Ethics and Business Risk
Memory hook: Protect people; understand the business; assign the risk owner.
Must remember
For management scenarios, establish the business objective, scope, authority and acceptable risk before selecting a product. That does not mean delaying urgent safety or containment actions while conducting a lengthy committee review. Read whether the question asks for the first action, strongest control or long-term program improvement.
Professional ethics prioritize the public interest and trust, lawful and honest conduct, competent service to principals and the profession's development. Conflicting instructions require escalation through appropriate authority; employment does not justify unlawful conduct. Due care is reasonable protective action; due diligence is the continuing investigation and verification supporting that care.
Business owners accept residual risk; security specialists analyze and advise. Governance sets direction and accountability; management implements it. Frameworks serve different purposes: NIST CSF organizes outcomes, ISO 27001 specifies an information-security management system, COBIT addresses enterprise governance of information/technology, and SABSA connects security architecture to business attributes. PCI DSS addresses its defined payment-data environment; FedRAMP concerns assessment/authorization of relevant US federal cloud offerings. Choose by scope and need rather than assuming one framework replaces law.
Personnel controls span lawful screening, agreements, onboarding, transfer, monitoring and termination. Separation of duties reduces single-person abuse; job rotation and mandatory absence can expose concealed activity. Contractors, acquisitions and divestitures require the same deliberate review of inherited identities, data and obligations.
Threat modeling starts with assets, data flows and trust boundaries. STRIDE helps examine spoofing, tampering, repudiation, disclosure, denial of service and privilege escalation; attack trees break a goal into paths. Models guide controls and abuse tests, then evolve with the system.
AI adoption adds data provenance, privacy, output verification and delegated-action risks. Decide who owns model/use-case risk and how outcomes will be monitored, rather than treating a vendor promise as assurance.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Executive asks what security to buy | Clarify business risk and requirements before choosing controls. |
| Residual risk exceeds tolerance | Escalate to the accountable owner with treatment options. |
| New supplier or acquisition | Assess inherited exposure, obligations and integration before trust is extended. |
Traps
- “Think like a manager” does not mean ignore immediate human safety.
- Compliance certification does not transfer the organization’s accountability.
12 · Security Models, Trusted Computing and Cryptanalysis
Memory hook: Confidentiality keeps secrets; integrity protects trustworthy change.
Must remember
Bell–LaPadula addresses confidentiality: no read up and no write down in its classic formulation. Biba addresses integrity: no read down and no write up. Clark–Wilson protects integrity through well-formed transactions, authorized transformation procedures and separation of duties. Brewer–Nash changes access based on prior activity to prevent conflicts of interest. Match the property, not just a memorized phrase.
The reference monitor mediates access, must resist tampering and be small enough to analyze. The trusted computing base includes components whose correct operation is necessary for policy enforcement. Reduce complexity, isolate privileges, fail securely and validate every relevant access; a secure default should not require users to opt into basic protection.
Memory isolation, privilege rings, process boundaries, ASLR and nonexecutable memory address different exploitation paths. A TPM can protect keys and support measured-boot evidence; an HSM protects cryptographic operations. Measured boot reports measurements; secure boot enforces an approved boot chain. Neither guarantees application-level authorization.
Cryptanalytic scenarios differ by attacker knowledge: ciphertext-only, known-plaintext, chosen-plaintext and chosen-ciphertext. Side-channel, timing and fault-injection attacks exploit implementation behavior rather than necessarily defeating the mathematical algorithm. A strong cipher with exposed keys still fails. Pass-the-hash reuses a credential representation; it is not the same as decrypting a password.
Symmetric key length and asymmetric key length are not directly comparable security measures. Plan cryptographic agility so algorithms, protocols and keys can change. Quantum risks affect algorithm families differently; use current approved standards and inventory dependencies rather than guessing that all encryption becomes equally obsolete.
System lifecycle decisions include requirements, design, implementation, integration, verification, validation, operations and secure retirement. Verification checks conformance to specification; validation checks whether the result satisfies the intended need.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Stop lower-integrity input corrupting trusted data | Integrity-oriented controls/model. |
| Prove a boot state to a verifier | Measured boot/attestation with a trustworthy verification process. |
| Unexpected timing reveals key-dependent behavior | Analyze implementation side channels, not only algorithm strength. |
Traps
- A security model is an abstraction, not a complete deployment architecture.
- Secure boot and measured boot are related but different.
13 · Network, Facility and Distributed-System Design
Memory hook: Trace every trust boundary, including the physical one.
Must remember
Separate the data plane carrying traffic, control plane deciding forwarding and management plane administering devices. Protect management with dedicated access paths, strong identity, logging and recovery capability. Out-of-band management can remain reachable when the production network fails, but it needs independent protection.
Layering helps locate controls: physical media, Ethernet switching, IP routing, transport and application protocols solve different problems. VLANs separate broadcast domains; routing/firewall policy controls communication between them. VRFs separate routing tables; overlays encapsulate traffic but do not automatically encrypt it. IPsec can protect IP traffic, TLS application transport and SSH administration. Deprecated SSL should not be treated as a current secure protocol.
North–south traffic enters/leaves an environment; east–west traffic moves within it. Microsegmentation restricts lateral movement. SDN centralizes or programs control; securing its controllers and APIs is crucial. SASE combines networking and security delivery concepts; it does not remove endpoint or identity responsibilities.
Bandwidth is capacity, throughput delivered work, latency delay, jitter variation and loss missing packets. Voice/video suffer from jitter and loss even when aggregate bandwidth is high. Storage/converged networks such as iSCSI carry sensitive traffic too; shared infrastructure needs isolation and capacity planning. CDNs cache/distribute content but require correct origin protection and cache policy.
Distributed systems introduce partial failures, retry duplication, consistency tradeoffs and dependencies. Containers share kernel risk; serverless reduces server administration while preserving code/data/identity risks; edge and IoT add physical exposure and constrained updates. Industrial systems require safety-aware controls.
Facility choices address natural and human hazards, access zoning, secure cabling, evidence/media storage, power, cooling, humidity and appropriate fire protection. Human life and safe egress come first. Redundant power paths sharing one upstream failure point are not truly independent. Test emergency communication and personnel procedures as well as machines.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Voice calls break despite spare bandwidth | Inspect latency, jitter, loss and queueing. |
| Control-plane compromise risk | Restrict and monitor controller/API administration. |
| Disaster affects a shared building | Independent geography, utilities and tested continuity processes. |
Traps
- Two components sharing one power source do not eliminate that source’s failure.
- Encapsulation alone is not confidentiality.
14 · Identity Assurance and Access Models
Memory hook: Proof the identity, bind the credential, limit the session.
Must remember
Identity proofing verifies a claimed real-world identity before enrollment. Authentication later verifies control of its bound authenticator. Strong authentication of a fraudulently enrolled identity does not repair poor proofing. Match identity and authenticator assurance to the transaction's risk.
Federation separates an identity provider from relying parties. Validate issuer, audience, signature, time bounds and replay protections for assertions/tokens. SSO simplifies access but centralizes dependency on the identity provider; design recovery and account protection accordingly. Session expiration, revocation and reauthentication matter after login.
RBAC maps permissions to job functions; ABAC evaluates subject, object and environment attributes; mandatory access applies centrally imposed labels; discretionary access permits owner-controlled delegation. Rule-based access applies defined rules and is not synonymous with role-based access. Risk-based decisions can adjust controls using context, but signals must be trustworthy and explainable.
Separation of duties may be static (never hold both roles) or dynamic (do not perform both actions in one transaction). Privileged access should use named identities, least privilege, just-in-time elevation and audit. Shared credentials weaken attribution unless tightly controlled by a system that records individual use.
For biometrics, false acceptance admits an impostor and false rejection blocks a legitimate user. The crossover/equal-error point is one comparison metric, not the whole deployment decision. Consider spoof resistance, accessibility, privacy and recovery.
Machine identities include workloads, devices and services. Inventory owners, credential issuance, rotation, permissions and decommissioning. Federation or short-lived credentials often reduces distributed secret management, but token issuance itself becomes a critical trust boundary.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| High-risk enrollment | Appropriate identity proofing before authenticator binding. |
| Compromised federation token | Revoke/contain sessions and investigate issuer/validation, not only reset a password. |
| Sensitive payment approval | Separate initiation and approval authorities. |
Traps
- Successful MFA does not prove the enrolled person was correctly identified.
- A validly signed token with the wrong audience must still be rejected.
15 · Security Assessment and Assurance
Memory hook: Test the requirement; report the business consequence.
Must remember
Define scope, criteria, independence, authorization, frequency and reporting before an assessment. Internal reviews provide organizational context; external independent reviews provide another assurance perspective. Sampling reduces effort but limits what conclusions can be drawn.
Testing methods answer different questions. Code review and SAST inspect implementation; DAST exercises a running system; IAST combines runtime observation with instrumentation; composition analysis examines dependencies. Fuzzing explores unexpected inputs. Synthetic transactions test a known business path; misuse cases test forbidden behavior. Coverage metrics reveal what was exercised, not proof that untested behavior is safe.
A red team pursues objectives within authorization; a blue team defends; purple-team collaboration improves detection and response from shared learning. Penetration tests are scoped snapshots and can miss vulnerabilities. Breach simulations validate selected paths without representing every possible adversary.
Gather technical and administrative evidence: access reviews, change approvals, backups/restores, detection performance, training outcomes and continuity exercises. A control can be well designed yet poorly operated; test both. Distinguish key performance indicators (how a process performs) from key risk indicators (signals of increasing exposure).
Findings should state condition, criteria, cause, impact, evidence and recommended treatment. Confirm false positives, prioritize by risk, assign owners and due dates, then retest. Track accepted exceptions and their expiry. Ethical disclosure follows legal authorization and coordinated reporting, not public release of exploitable details without considering affected parties.
Audit reports differ in intended audience, scope and time period. Read exclusions and customer responsibilities before relying on a supplier report. A polished report is only as useful as its criteria, evidence and follow-through.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Prove a control operated over time | Review time-bound evidence and representative samples. |
| Find risky dependency versions | Software composition analysis and provenance review. |
| Improve detection after an exercise | Translate observed gaps into owned changes and retest. |
Traps
- High code coverage does not prove secure behavior.
- An external audit is not a guarantee that every system is secure.
16 · Secure Software Lifecycle and Supply Chains
Memory hook: Build the control into the path that ships code.
Must remember
Security starts in requirements and design, continues through implementation/testing and remains necessary during operation and retirement. Waterfall, Agile and DevSecOps change delivery organization, not the need for risk decisions. Maturity models assess repeatability and capability; they do not certify that a particular application is vulnerability-free.
Define abuse cases and trust boundaries before coding. Use server-side authorization for every protected object/action, parameterized queries, context-appropriate output encoding, bounds checking, safe memory patterns and structured error handling. Client-side validation improves usability but is not a trusted enforcement point. Prevent secrets from entering source code, build logs and artifacts.
Secure the development ecosystem: repositories, branch protections, reviewers, build runners, dependencies, artifact registries, signing keys and deployment identities. Separate build from approval/deployment authority where needed. An SBOM inventories components; provenance records how an artifact was produced; signatures establish integrity and issuer within a trust system. None alone proves the software has no vulnerability.
Use SAST, DAST, SCA and appropriate manual review at complementary stages. Verify fixes with regression and abuse tests. Threat modeling and architecture review catch issues that scanners may miss. Purchased, open-source, SaaS and custom software all require risk assessment, support/patch obligations and exit planning.
AI-enabled development and applications add untrusted generated code, prompt injection, sensitive-data leakage, model supply-chain risks and excessive agent permissions. Treat generated output as untrusted; validate code and data before use. Retrieval authorization must follow the user's permissions, and tool execution needs explicit, narrow authority. Monitor model/application changes as production changes.
Assess software security with meaningful outcomes: escaped defects, time to remediate, verified control coverage and supply-chain integrity. A pipeline that merely runs a scanner without acting on results is not effective assurance.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Prevent a dependency compromise from reaching production | Control sources, versions, provenance, scans and release authority. |
| AI agent can execute business actions | Constrain tools/identity and validate each high-impact action. |
| Purchase a SaaS application | Assess security, data handling, support, contracts and exit capability. |
Traps
- Open source is not automatically safe or unsafe.
- A signed malicious artifact remains malicious.