Posts

True Negatives for CompTIA CySA+ Exam Prep

 True Negatives for CySA+:  When "Nothing Found" Isn't Proof Vulnerability Management & Security Operations · CS0-004 Of the four boxes in the detection-accuracy grid, true negative feels the safest: the tool looked, found nothing, and nothing was there. No harm, no story. Security+ tests it as a definition. CySA+ tests it as a trap, because the analyst-level question isn't "what is a true negative" — it's "how do you know it actually is one, and not something that only looks like one." That distinction is where this article spends most of its time. The confusion matrix, quickly Every detection decision — a vulnerability scan, a SIEM correlation rule, an EDR verdict — lands in one of four outcomes: Verdict vs. reality Threat/finding is real Threat/finding is not real Tool says "match" True positive False positive Tool says "clean" False negative True negative A true negative is the bottom-right...

True Positives for CompTIA CySA+ Exam Prep

 True Positives for CySA+:  Confirming the Alert Is Real Vulnerability Management & Security Operations · CS0-004 Security+ candidates learn true positive as one box in a simple four-box grid: the tool said "threat," and a threat was actually there. CySA+ expects more than that. As an analyst-level exam, it tests whether you can act on a true positive correctly — validate it, prioritize it, and know that "true positive" doesn't automatically mean "incident." That last point trips up more candidates than the definition itself. The confusion matrix, quickly Every detection decision — a SIEM alert, a vulnerability scan finding, an EDR verdict — lands in one of four outcomes: Verdict vs. reality Threat/finding is real Threat/finding is not real Tool says "match" True positive False positive Tool says "clean" False negative True negative A true positive is the tool correctly identifying something that's...

False Negatives for CompTIA CySA+ / Security+ Exam Prep

 False Negatives for Security+:  The Alert That Never Fires Security Operations · SY0-701 Domain 4.3 Of all the detection-accuracy terms Security+ tests, false negatives are the most likely to get glossed over, probably because a false negative, by definition, doesn't announce itself. A false positive is loud and annoying: an analyst gets paged for nothing, and everyone notices. A false negative is silent. The attack happened, the tool said nothing, and nobody finds out until much later, if ever. That asymmetry is exactly what CompTIA wants you to understand, and it's the thread running through every exam question on the topic. The four outcomes of any detection decision Every security control that makes a yes/no call — an IDS flagging traffic, an antivirus engine scanning a file, a vulnerability scanner grading a host — produces one of four outcomes, usually taught as a simple grid: Verdict vs. reality      Threat is actually present     Thr...

802.11a to 802.11be: A Network+ Guide to Wi-Fi Standards, Frequencies, and Data Rates

 Wireless Frequencies A Network+ (N10-009) study guide to the 802.11 standards table, IEEE designation, Wi-Fi generation, frequency, and maximum data rate Why this table is worth memorizing cold Network+ loves to hand you a scenario, "a client device only supports 5 GHz and needs at least 1 Gbps throughput", and expect you to know, instantly, which 802.11 standard(s) qualify. That means you need more than a vague sense that "newer Wi-Fi is faster." You need the actual mapping between the IEEE standard name , the marketing generation number , the frequency band(s) it uses, and its maximum data rate , cold, without a lookup. The one sentence to memorize: Every jump in Wi-Fi generation brought either a new frequency band, a new modulation/channel technique, or both, and the exam tests whether you know which standard unlocked which capability, not just the numbers in isolation. The master reference table IEEE Standard Wi-Fi Generation Frequency Maximum D...

CVE vs. CVSS: What Security+ and CySA+ Candidates Must Know

 CVE vs. CVSS What every Security+ (SY0-701) and CySA+ (CS0-003) candidate needs to know about identifying vulnerabilities versus scoring them Why this pair of acronyms trips people up Ask a room full of Security+ or CySA+ candidates to define CVE and CVSS separately, and most will mix them up. Put both terms in the same exam question — "A scan returns CVE-2024-3094 with a CVSS score of 10.0; what should the analyst do first?" — and the wheels start to wobble. That's because CVE and CVSS aren't competing concepts you choose between. They're two different layers of the same vulnerability management stack, and CompTIA loves to test whether you know which layer does what. Here's the one-sentence version, which is worth memorizing before anything else in this article: CVE tells you what the vulnerability is. CVSS tells you how bad it is. Everything below unpacks that sentence — first CVE alone, then CVSS alone, then how the two work together, and finally...

CompTIA Security+ SY0-701 practice questions

CompTIA Security+ SY0-701 practice questions               The questions are fairly easy but the explanations will help people understand what CompTIA as an answer. If this experiment goes well we will start adding multiple questions to this quiz. Plus we will consider adding questions for the Tech+, A+, Network+, and CySA+ exams. ProProfs Online Assessment software

Cryptographic Vulnerabilities Explained for Security+ and CySA+

Cryptographic Vulnerabilities Explained: A  Security+, CySA+, PenTest+, and SecurityX Guide Sep 27, 2026 · @Ken What Counts as a Cryptographic Vulnerability Almost nobody breaks the math. Modern algorithms like AES-256 don't fall to clever cryptanalysis, and exam questions rarely ask you to attack a cipher directly. What fails is everything around the math. A cryptographic vulnerability is any weakness that lets an attacker defeat the confidentiality, integrity, or authenticity that encryption was supposed to provide — and in practice those weaknesses cluster into four categories: Algorithm weakness — the primitive itself is broken or too small. MD5 collisions, 56-bit DES keys. Implementation flaws — a sound algorithm used incorrectly. ECB mode, a reused nonce, a predictable random number generator. Key management failures — the algorithm and the code are fine, but the key is hardcoded, shared, never rotated, or stored next to the data it protects. Protocol weakness — the nego...

Beaconing Explained for CySA+, Security+, and PenTest+

Beaconing Explained: Detecting Command-and- Control Traffic for CySA+, Security+, PenTest+,  and SecAI+ Sep 27, 2026 · @Ken What Beaconing Is Once malware lands on a host, it has a problem: it needs instructions and can't accept inbound connections through a firewall. So it calls out instead. At intervals, it contacts the attacker's command-and-control server, asks whether there is anything to do, and goes quiet again. That repeated callback is beaconing , and it is the heartbeat of a compromise. It begins after initial access and persists through every later stage — privilege escalation, lateral movement, exfiltration. If an intrusion is ongoing, something is almost certainly beaconing. Here is the idea the whole topic turns on: Beaconing is detected by the rhythm of the traffic, not its content. Modern C2 is encrypted. You cannot read the payload, and you generally cannot tell a beacon from ordinary web traffic by inspecting any single connection — it looks like a browser fe...