Exam objective

SY0-701 4.5: Enterprise Security Capabilities

Security+ Topic

Enterprise Security Capabilities for Security+

This Security+ topic covers operational modification of enterprise security capabilities when a scenario gives a risk, exposure, or business change and asks what capability should be adjusted; Firewall capability changes: rules, access lists, ports/protocols, screened subnets, allow/deny logic, and reducing overly broad network access; Detection and filtering capability changes: IDS/IPS signatures and trends, web filter deployment models, URL scanning, content categorization, block rules, and reputation; OS, protocol, DNS, and email security changes: Group Policy, SELinux, secure protocol selection, port selectio...

Start first lesson

4 lessons in this topic

Common mistakes to avoid

1

Learners often choose a new tool when the scenario asks for a rule change. If the problem is that the firewall already exists but allows too much or blocks a needed service, the answer is usually to modify rules, access lists, ports/protocols, or screened subn...

2

Learners often treat IDS/IPS and web filters as interchangeable because both can block bad activity. IDS/IPS focuses on intrusion patterns and network or host activity. Web filtering focuses on web destinations, categories, URLs, and reputation.

3

Learners often answer every email problem with an email gateway. A gateway filters mail content and attachments, but DMARC, DKIM, and SPF specifically address sender authentication and spoofing signals.

4

Learners often confuse DLP with EDR because both can run on endpoints. DLP follows sensitive data movement. EDR follows endpoint behavior and supports response to suspicious host activity.