Exam objective
Core 2 2.0: Security Controls and Identity
Security Controls and Identity for A+
This A+ topic covers technician-level recognition and matching of physical security controls, physical access mechanisms and biometric methods, logical security models and permission controls, multifactor authentication methods, identity-service terms, and administrative/data-protection controls named in the CompTIA A+ Core 2 security objective. The learner should identify which control addresses a described facility, equipment, access, or data protection problem and choose the best control in support scenarios.
Start first lesson6 lessons in this topic
Common mistakes to avoid
Learners often confuse monitoring with prevention. Video surveillance records events and deters, but does not physically stop a thief. They may also confuse physical door locks with logical access controls for files and systems; these are separate categories.
Learners may call any credential a "badge" without distinguishing mechanical keys from electronic tokens. They may also assume biometrics are foolproof; in practice, biometric methods have different accuracy and operational trade-offs.
Technicians often swap least privilege and ACLs: least privilege is the principle (reduce rights overall), while ACLs are one mechanism to enforce permissions on a resource.
A common issue is treating two knowledge-based factors (two passwords) as MFA; they are not. Also, SMS-based MFA is often treated as equivalent security to hardware tokens or app TOTP, though SMS has practical attack risks.