Exam objective
SY0-701 4.5: Enterprise Security Capabilities
Enterprise Security Capabilities for Security+
This Security+ topic covers operational modification of enterprise security capabilities when a scenario gives a risk, exposure, or business change and asks what capability should be adjusted; Firewall capability changes: rules, access lists, ports/protocols, screened subnets, allow/deny logic, and reducing overly broad network access; Detection and filtering capability changes: IDS/IPS signatures and trends, web filter deployment models, URL scanning, content categorization, block rules, and reputation; OS, protocol, DNS, and email security changes: Group Policy, SELinux, secure protocol selection, port selectio...
Start first lesson4 lessons in this topic
Common mistakes to avoid
Learners often choose a new tool when the scenario asks for a rule change. If the problem is that the firewall already exists but allows too much or blocks a needed service, the answer is usually to modify rules, access lists, ports/protocols, or screened subn...
Learners often treat IDS/IPS and web filters as interchangeable because both can block bad activity. IDS/IPS focuses on intrusion patterns and network or host activity. Web filtering focuses on web destinations, categories, URLs, and reputation.
Learners often answer every email problem with an email gateway. A gateway filters mail content and attachments, but DMARC, DKIM, and SPF specifically address sender authentication and spoofing signals.
Learners often confuse DLP with EDR because both can run on endpoints. DLP follows sensitive data movement. EDR follows endpoint behavior and supports response to suspicious host activity.