Posts

Acquisition in Digital Forensics: The Step You Can't Redo

 Acquisition in Digital Forensics:  Security+ and CySA+ Exam Prep Security+ SY0-701 Domain 4.8 · CySA+ CS0-004 Incident Response & Management Acquisition is the moment digital forensics either succeeds or quietly fails. It's the step where an analyst captures evidence from a live or compromised system — and if that capture is done sloppily, every conclusion built on top of it is worthless, no matter how good the later analysis is. Security+ tests whether you know what proper acquisition looks like. CySA+ tests whether you can make the right acquisition call under the pressure of an active incident. This article covers both. What acquisition actually means In the forensic process, acquisition is the step where data is copied from its original source — a hard drive, RAM, a network device, a cloud service — into a form that can be preserved and analyzed without altering the original. It sits right after evidence is identified and before it's formally analyzed, and it's...

Security+ Question Keywords: What the Wording Is Telling You

Security+ questions are written to a pattern, and recognising the pattern is worth several marks. This is not a substitute for knowing the material — it is how to convert what you know into the right answer when three options look plausible. Read the last line first Scenario questions front-load context and put the actual question at the end. Reading the final sentence first tells you what to look for, so the scenario is read purposefully rather than absorbed and then re-read. Then identify the qualifier , because it is doing more work than anything else in the question. BEST , MOST likely , FIRST , MOST cost-effective and LEAST each change which of several correct answers is the one wanted. Several options are frequently valid; the qualifier decides. FIRST is the one most often missed. It asks about sequence, not about the most important action — and the answer is usually the least dramatic option, because you verify or contain before you eradicate. Keywords that ...

Transparent vs. Non-Transparent Proxies for CompTIA Security+ Exam Prep

The Two Faces of a Proxy Transparent vs. Non-Transparent Proxies for Security+: Does the Client Know You're There? SECURITY+ FIELD NOTES · Secure Network Architecture · SY0-701 Every proxy in this series so far has been sorted by direction — forward vs. reverse, client-facing vs. server-facing. This one is sorted by something else entirely: whether the client on the other end even knows the proxy exists. A transparent proxy and a non-transparent (explicit) proxy can do the exact same job — filtering, caching, logging — and still be tested as two completely different answers, because the exam isn't asking what the proxy does. It's asking whether the client had to agree to it. That single distinction — client awareness — is the whole article. Once it clicks, "transparent" stops sounding like a vague adjective and starts sounding like the literal answer key. Transparent vs. non-transparent, at a glance Two modes, one distinguishing question: does the clien...

Reverse Proxies for CompTIA Security+ Exam Prep

  The Reverse Proxy Playbook Reverse Proxies for Security+: One Face, Many Servers Behind It SECURITY+ FIELD NOTES · Secure Network Architecture · SY0-701 A reverse proxy is the mirror image of the appliance most people learn first. Where a forward proxy stands in front of internal clients and hides them from the internet, a reverse proxy stands in front of internal servers and hides them from everyone reaching in from outside. Same word, opposite job — and the exam knows that similarity is exactly where candidates trip. Reverse proxies also share real estate with load balancers and web application firewalls, since a single production appliance often does all three jobs at once. Security+ still expects you to name the primary function a scenario is describing, even when the real-world box in front of you would happily do all of them. The server-facing appliance lineup, quickly Four appliances, one distinguishing question: what layer does it work at, and what's its one jo...

Caching Proxies for CompTIA Security+ Exam Prep

  The Caching Proxy Playbook Caching Proxies for Security+: The Appliance That Remembers What It Fetched SECURITY+ FIELD NOTES · Secure Network Architecture · SY0-701 Network appliance questions on the Security+ exam almost always hinge on two things: which direction traffic is flowing, and what the appliance does with a copy of it. Get those two answers right and an intimidating lineup of boxes — proxies, load balancers, IDS sensors — sorts itself out fast. Get them wrong, and a caching proxy starts looking suspiciously like a reverse proxy , a load balancer, or even an IDS. That confusion is exactly why caching proxies show up so often in practice questions. The name gives away half the answer, but the exam still wants you to place it correctly against its closest look-alikes before it counts the point. The network appliance lineup, quickly Four appliances, one distinguishing question: which direction does it face, and does it keep a copy of what passes through? Appl...

True Negatives for CompTIA CySA+ Exam Prep

 True Negatives for CySA+:  When "Nothing Found" Isn't Proof Vulnerability Management & Security Operations · CS0-004 Of the four boxes in the detection-accuracy grid, true negative feels the safest: the tool looked, found nothing, and nothing was there. No harm, no story. Security+ tests it as a definition. CySA+ tests it as a trap, because the analyst-level question isn't "what is a true negative" — it's "how do you know it actually is one, and not something that only looks like one." That distinction is where this article spends most of its time. The confusion matrix, quickly Every detection decision — a vulnerability scan, a SIEM correlation rule, an EDR verdict — lands in one of four outcomes: Verdict vs. reality Threat/finding is real Threat/finding is not real Tool says "match" True positive False positive Tool says "clean" False negative True negative A true negative is the bottom-righ...

True Positives for CompTIA CySA+ Exam Prep

 True Positives for CySA+:  Confirming the Alert Is Real Vulnerability Management & Security Operations · CS0-004 Security+ candidates learn true positive as one box in a simple four-box grid: the tool said "threat," and a threat was actually there. CySA+ expects more than that. As an analyst-level exam, it tests whether you can act on a true positive correctly — validate it, prioritize it, and know that "true positive" doesn't automatically mean "incident." That last point trips up more candidates than the definition itself. The confusion matrix, quickly Every detection decision — a SIEM alert, a vulnerability scan finding, an EDR verdict — lands in one of four outcomes: Verdict vs. reality Threat/finding is real Threat/finding is not real Tool says "match" True positive False positive Tool says "clean" False negative True negative A true positive is the tool correctly identifying something that'...

False Negatives for CompTIA CySA+ / Security+ Exam Prep

 False Negatives for Security+:  The Alert That Never Fires Security Operations · SY0-701 Domain 4.3 Of all the detection-accuracy terms Security+ tests, false negatives are the most likely to get glossed over, probably because a false negative, by definition, doesn't announce itself. A false positive is loud and annoying: an analyst gets paged for nothing, and everyone notices. A false negative is silent. The attack happened, the tool said nothing, and nobody finds out until much later, if ever. That asymmetry is exactly what CompTIA wants you to understand, and it's the thread running through every exam question on the topic. The four outcomes of any detection decision Every security control that makes a yes/no call — an IDS flagging traffic, an antivirus engine scanning a file, a vulnerability scanner grading a host — produces one of four outcomes, usually taught as a simple grid: Verdict vs. reality      Threat is actually present     Th...

802.11a to 802.11be: A Network+ Guide to Wi-Fi Standards, Frequencies, and Data Rates

 Wireless Frequencies A Network+ (N10-009) study guide to the 802.11 standards table, IEEE designation, Wi-Fi generation, frequency, and maximum data rate Why this table is worth memorizing cold Network+ loves to hand you a scenario, "a client device only supports 5 GHz and needs at least 1 Gbps throughput", and expect you to know, instantly, which 802.11 standard(s) qualify. That means you need more than a vague sense that "newer Wi-Fi is faster." You need the actual mapping between the IEEE standard name , the marketing generation number , the frequency band(s) it uses, and its maximum data rate , cold, without a lookup. The one sentence to memorize: Every jump in Wi-Fi generation brought either a new frequency band, a new modulation/channel technique, or both, and the exam tests whether you know which standard unlocked which capability, not just the numbers in isolation. The master reference table IEEE Standard Wi-Fi Generation Frequency Maximum ...

CVE vs. CVSS: What Security+ and CySA+ Candidates Must Know

 CVE vs. CVSS What every Security+ (SY0-701) and CySA+ (CS0-003) candidate needs to know about identifying vulnerabilities versus scoring them Why this pair of acronyms trips people up Ask a room full of Security+ or CySA+ candidates to define CVE and CVSS separately, and most will mix them up. Put both terms in the same exam question — "A scan returns CVE-2024-3094 with a CVSS score of 10.0; what should the analyst do first?" — and the wheels start to wobble. That's because CVE and CVSS aren't competing concepts you choose between. They're two different layers of the same vulnerability management stack, and CompTIA loves to test whether you know which layer does what. Here's the one-sentence version, which is worth memorizing before anything else in this article: CVE tells you what the vulnerability is. CVSS tells you how bad it is. Everything below unpacks that sentence — first CVE alone, then CVSS alone, then how the two work together, and finall...