Security Controls Quick Reference
Classify technical, managerial, operational, and physical controls, then separate preventive, deterrent, detective, corrective, compensating, and directive functions.
Security+ quick review
Focused comparisons for concepts that are easy to blur together when several answers sound reasonable.
Each guide explains the distinction, works through realistic scenarios, and ends with a rapid-review grid. The pages are designed for both screen review and clean printing.
Classify technical, managerial, operational, and physical controls, then separate preventive, deterrent, detective, corrective, compensating, and directive functions.
Compare RTO, RPO, MTTR, and MTBF with timelines, calculations, recovery-planning distinctions, and common exam traps.
Match confidentiality, integrity, authenticity, and data representation to hashing, encryption, encoding, signatures, HMAC, salts, and key stretching.
Separate encryption, decryption, signing, verification, certificate, and key-establishment roles by identifying whose key pair the scenario uses.
Review identity-to-public-key binding, certificate contents, trust chains, validity, revocation, CRLs, OCSP, and common certificate mistakes.
Follow the chain from weakness and threat source through exploitation to likelihood, impact, mitigation, and business risk.
Follow preparation, detection, analysis, containment, eradication, recovery, and lessons learned while deciding what belongs first or next.
Calculate loss per event, annual occurrence rates, and annualized loss, then separate quantitative estimates from broader risk decisions.
Separate governance documents by authority, detail, and purpose: organizational direction, mandatory requirements, task steps, and recommendations.
Compare detection and response tools by visibility, evidence, enforcement, endpoint context, and cross-domain correlation.
Separate factor categories from authentication methods and authenticators, then identify what actually makes a login multifactor.
Follow data through storage, network movement, and active processing, then match each state to the controls that protect it.
Use the quick references to correct a specific weak spot. When the individual distinctions are mostly solid, use the Final Review to compress the whole exam before a fresh question set.