Exam objective

SY0-701 2.5: Enterprise Mitigation Techniques

Security+ Topic

Enterprise Mitigation Techniques for Security+

This Security+ topic covers why enterprise mitigation techniques are used and which broad risk-reduction purpose each technique serves. It teaches segmentation, access control, ACLs, permissions, application allow lists, isolation, patching, encryption, monitoring, least privilege, configuration enforcement, decommissioning, and hardening techniques.

Start first lesson

4 lessons in this topic

Common mistakes to avoid

1

Learners often answer with the technology used to implement the restriction instead of the purpose. A firewall, IAM tool, file system, or router may implement the control, but the mitigation concept is segmentation, access control, ACLs, permissions, or least...

2

Learners often treat patching and configuration enforcement as the same. Patching changes software to fix known defects. Configuration enforcement maintains approved settings.

3

Learners often confuse monitoring with an indicator. Monitoring is the control that observes. An indicator is the suspicious event observed.

4

Learners often confuse lifecycle monitoring with attack indicators. Monitoring is the control used to observe state and events. Missing logs, impossible travel, account lockout, and resource inaccessibility are indicators analyzed under SY0-701 2.4.