Exam objective
SY0-701 4.2: Asset Management Security
Asset Management Security for Security+
This Security+ topic covers acquisition and procurement process decisions that affect hardware, software, and data security; Assignment and accounting controls, including ownership and classification; Monitoring and asset tracking, including inventory and enumeration; Disposal and decommissioning, including sanitization, destruction, certification, and data retention.
Start first lesson4 lessons in this topic
Common mistakes to avoid
Procurement security is not the same as supply chain attack analysis. Supply chain threats can matter, but this micro-objective asks how proper asset management during acquisition and procurement affects security outcomes such as supportability, tracking, owne...
Learners often treat ownership as physical possession. The person holding a device may be the assigned user, but the asset owner is the accountable party for decisions. A custodian can operate an asset without owning the business risk.
Inventory and vulnerability scanning are often confused. Inventory answers what assets exist and key facts about them. Vulnerability scanning looks for weaknesses in those assets.
Sanitization and destruction are related but not identical. Sanitization removes data so media can often be reused. Destruction makes the asset or media unusable and is appropriate when reuse is not acceptable or data sensitivity demands stronger assurance.