certslothcertsloth
220-1202/Topic 04

CompTIA / Foundational

Security Principles and Controls

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Protect the right property with the right kind of control.

Must remember

Confidentiality prevents unauthorized disclosure; integrity protects against unauthorized alteration; availability keeps a service usable. Authenticity establishes that something is genuine. Non-repudiation supplies evidence of origin or action, subject to trustworthy keys, identities and records.

Authentication establishes an identity, authorization decides permitted actions and accounting records activity. Identify which stage failed: a valid login with excessive database privileges is an authorization problem.

Classification Examples
Technical Firewall, encryption, access-control software.
Managerial Policy, risk assessment, oversight.
Operational Human-run procedures, training, guard processes.
Physical Locks, barriers, cameras, environmental protection.
Preventive / detective / corrective Block / discover / repair.
Deterrent / directive / compensating Discourage / instruct / supply an alternative protection.

One control can have several classifications. A camera detects; a visible camera may also deter. A compensating control addresses the original control's intent when the normal implementation is not feasible; it does not simply mean a cheaper control.

Zero trust evaluates access using identity, device state, resource sensitivity and context rather than trusting network location. A policy engine decides, a policy administrator arranges the session and an enforcement point permits or blocks it. Least privilege and segmentation reduce blast radius; continuous evaluation handles changing conditions.

Honeypots, honeynets, honeyfiles and honeytokens are deception tools. Access to a decoy can be a high-value detection signal, but a decoy needs containment and monitoring.

Choose under exam pressure

Requirement Choice and reason
Prevent disclosure Access control and encryption appropriate to the data path.
Find unauthorized changes Integrity checks, signatures and audit evidence.
Legacy system cannot implement a mandated control Evaluate an approved compensating control against the same risk.

Traps

  • Encryption alone does not make a service available.
  • Zero trust is an architecture and decision process, not one appliance.

Active recall

1. Integrity or confidentiality for detecting file tampering?

Integrity.

2. A signed policy is which control category?

Primarily managerial and directive.

3. Can one control be detective and deterrent?

Yes; classifications describe different aspects or effects.

4. What is wrong with trusting every internal address?

Location alone does not establish a trustworthy identity, device or request.

5. What makes a honeytoken useful?

It should have no legitimate use, so attempted use can signal suspicious activity.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.