Exam objective
SY0-701 1.2: Core Security Concepts
Core Security Concepts for Security+
This Security+ topic covers securityplus.gsc.core.cia1 owns confidentiality, integrity, availability, and non-repudiation as security goals with support-level examples; securityplus.gsc.core.aaa2 owns authentication, authorization, and accounting as conceptual access questions for people and systems; securityplus.gsc.core.zerotrust3 owns Zero Trust concept recognition, including control-plane and data-plane language, reduced implicit trust, adaptive identity, policy-driven access, policy engines, policy administrators, subjects, systems, implicit trust zones, and policy enforcement points; securityplus.gsc.core.p...
Start first lesson5 lessons in this topic
Common mistakes to avoid
Learners often treat every security failure as confidentiality because data is involved. The shortest correction is to ask what happened to the asset: exposed means confidentiality, changed means integrity, unavailable means availability, and denied action mea...
Learners often confuse authentication with authorization. The shortest correction is: authentication proves identity; authorization grants or denies actions after identity is known; accounting records what happened.
Learners often reduce Zero Trust to "never trust anyone." The shortest correction is: Zero Trust means do not rely on implicit trust; verify explicitly, evaluate context, apply policy, and enforce least necessary access.
Learners often confuse deterrence, detection, and prevention. The shortest correction is: barriers such as bollards and fencing slow or block; cameras and sensors detect or record; guards can verify and respond; badges and vestibules control entry.