Security Fundamentals, CIA Triad, Hackers, Threat Actors, and Malware Basics

Introduction to Cybersecurity

Cybersecurity is the practice of protecting computers, networks, applications, and data from unauthorized access, attacks, damage, or theft.

Modern organizations depend heavily on information systems. As a result, cybersecurity has become one of the most important areas of information technology.

Security aims to balance:

Completely open systems are convenient but insecure, while overly restrictive systems reduce productivity. Effective security balances both usability and protection.

Why Security Matters

Organizations store valuable information such as:

If attackers gain unauthorized access, the organization may experience:

Information Security Goals

Information security protects three major areas:

Effective security prevents:

The CIA Triad

The CIA Triad is the foundation of information security.

CIA stands for:

Almost every security concept relates to protecting one or more of these three principles.

Confidentiality

Confidentiality ensures that information is accessible only to authorized individuals.

The goal is to prevent unauthorized disclosure of sensitive information.

Examples include:

Without confidentiality, private information could be exposed.

Protecting Confidentiality

Organizations protect confidentiality through:

These controls help ensure that only authorized users can access sensitive information.

Integrity

Integrity ensures that information remains accurate, complete, and unaltered unless modified by an authorized user.

Users must be confident that information has not been changed improperly.

Examples include:

Threats to Integrity

Integrity may be compromised through:

Maintaining integrity is critical for accurate business operations.

Availability

Availability ensures that systems, applications, and data remain accessible when authorized users need them.

Even perfectly protected data has little value if users cannot access it.

Availability depends on:

Threats to Availability

Availability may be affected by:

Organizations improve availability through redundancy, backups, and disaster recovery planning.

Security Terminology

Several important terms are commonly used in cybersecurity.

Asset

An asset is anything valuable that should be protected.

Examples include:

Threat

A threat is any event or circumstance capable of causing harm to an asset.

Threats may originate from:

Vulnerability

A vulnerability is a weakness that could be exploited by an attacker.

Examples include:

Exploit

An exploit is a method or tool used to take advantage of a vulnerability.

Attackers use exploits to:

Keeping systems updated helps reduce exploitable vulnerabilities.

Risk

Risk is the likelihood that a threat will successfully exploit a vulnerability and cause damage.

Organizations reduce risk through:

Hacking

Hacking is the act of gaining unauthorized access to a computer system, network, or data.

Attackers may attempt to:

Some individuals use technical skills ethically for testing security, while malicious hackers use them for criminal purposes.

Common Threat Actors

Organizations face threats from many different sources.

Cybercriminals

Cybercriminals are motivated primarily by financial gain.

Examples include:

Hacktivists

Hacktivists use hacking to promote political or social causes.

They may:

Nation-State Attackers

Government-sponsored attackers often target:

These attacks are typically highly organized and well funded.

Insider Threats

An insider threat originates from someone with authorized access.

Examples include:

Insiders may intentionally or accidentally compromise security.

Malware

Malware is software specifically designed to harm, disrupt, or gain unauthorized access to computer systems.

Malware is one of the most common cybersecurity threats.

Common Types of Malware

You should understand the major malware categories tested on the CompTIA Tech+ exam.

These include:

Virus

A virus attaches itself to another executable file.

When the infected file runs, the virus executes and may spread to other files.

Viruses often:

Viruses typically require user action to spread.

Worm

A worm is self-contained malware that spreads automatically across networks without attaching to another program.

Characteristics include:

Worms may also deliver additional malicious payloads.

Trojan Horse

A Trojan Horse disguises itself as legitimate software.

Users unknowingly install it because it appears trustworthy.

Once installed, it may:

Unlike viruses and worms, Trojans do not self-replicate.

Adware

Adware displays unwanted advertisements on a user’s device.

Some adware is merely annoying, while other versions collect user information or redirect browsers to advertising websites.

Spyware

Spyware secretly monitors user activity.

It may collect:

Spyware often operates without the user’s knowledge.

Ransomware

Ransomware encrypts files or locks a system and demands payment to restore access.

Consequences include:

The best defense includes regular backups, updated security software, and user awareness.

Rootkit

A rootkit hides malicious software by gaining administrative-level access and concealing processes or files from the operating system.

Rootkits are difficult to detect and remove because they are designed to evade security tools.

Backdoor

A backdoor bypasses normal authentication and provides unauthorized access to a system.

Backdoors may be installed by malware or result from insecure default configurations.

Keyloggers

A keylogger (keystroke logger) is a type of malware or monitoring software that records every key pressed on a keyboard. It is commonly used by cybercriminals to steal sensitive information such as usernames, passwords, credit card numbers, and personal messages. Some organizations may also use legitimate keyloggers to monitor company-owned devices with employee knowledge and authorization.

Best Practices

Key Terms

Exam Tips

Social Engineering, Phishing, Password Attacks, Privacy, and Security Awareness

Social Engineering

Social engineering is the practice of manipulating people into revealing confidential information or performing actions that compromise security.

Instead of attacking computers directly, social engineering attacks target human behavior.

Attackers often exploit:

Because humans are often the weakest link in security, social engineering remains one of the most successful attack methods.

Why Social Engineering Works

Attackers understand that many people:

Successful attacks often rely on psychological manipulation rather than technical skills.

Common Social Engineering Attacks

You should recognize these common attack types:

These attacks attempt to steal credentials, financial information, or sensitive business data.

Phishing

Phishing is a fraudulent attempt to obtain sensitive information by pretending to be a trustworthy organization or individual.

Attackers commonly request:

Phishing usually occurs through email but may also use websites, text messages, or phone calls.

Characteristics of Phishing Emails

Warning signs include:

Users should carefully verify messages before responding.

Spear Phishing

Spear phishing is a targeted phishing attack aimed at a specific individual or organization.

Attackers often research the victim beforehand to create convincing messages.

Spear phishing emails may include:

Because they appear legitimate, spear phishing attacks are often more successful than general phishing campaigns.

Whaling

Whaling is a specialized form of spear phishing that targets high-level executives or senior management.

Examples of targets include:

Successful whaling attacks can result in significant financial losses or data breaches.

Smishing

Smishing combines SMS (text messaging) with phishing.

Attackers send fraudulent text messages encouraging victims to:

Always verify unexpected text messages before responding.

Vishing

Vishing (voice phishing) uses telephone calls or voice messages to deceive victims.

Attackers may pretend to be:

The goal is usually to obtain confidential information or persuade victims to transfer money.

Pretexting

Pretexting involves creating a believable false story to convince someone to reveal confidential information.

Examples include pretending to be:

Attackers often prepare detailed scenarios to appear credible.

Impersonation

Impersonation occurs when attackers pretend to be trusted individuals.

Examples include:

Victims may unknowingly provide sensitive information or grant unauthorized access.

Tailgating

Tailgating (also called piggybacking) occurs when an unauthorized person follows an authorized employee into a secure area.

Examples include:

Physical security procedures help prevent tailgating attacks.

Shoulder Surfing

Shoulder surfing involves observing someone entering sensitive information.

Attackers may watch users type:

Privacy screens and awareness help reduce this risk.

Dumpster Diving

Dumpster diving involves searching discarded materials for sensitive information.

Examples include:

Proper document shredding reduces this risk.

Baiting

Baiting uses an enticing offer to encourage victims to install malware or reveal information.

Examples include:

Victims should avoid connecting unknown devices or downloading untrusted files.

Password Attacks

Attackers frequently target passwords because they provide direct access to accounts.

Common password attacks include:

Strong password policies significantly reduce these risks.

Brute-Force Attack

A brute-force attack systematically attempts every possible password combination until the correct one is found.

Long, complex passwords greatly increase the time required for a successful brute-force attack.

Dictionary Attack

A dictionary attack uses lists of commonly used passwords and words instead of testing every possible combination.

Weak passwords are particularly vulnerable.

Examples include:

Credential Stuffing

Credential stuffing occurs when attackers use usernames and passwords stolen from one website to access accounts on other websites.

This attack succeeds because many users reuse passwords across multiple accounts.

Using unique passwords for every account helps prevent credential stuffing.

Password Spraying

Password spraying attempts a small number of commonly used passwords against many different accounts.

Rather than attacking one account repeatedly, attackers avoid account lockouts by spreading attempts across multiple users.

Spam

Spam refers to unwanted, unsolicited electronic messages.

Spam commonly includes:

Spam filters help reduce unwanted email.

Personally Identifiable Information (PII)

Personally Identifiable Information (PII) is information that can identify a specific individual.

Examples include:

Organizations should protect PII from unauthorized access.

Sensitive Personal Information

Some personal information requires additional protection.

Examples include:

Unauthorized disclosure may result in identity theft or financial fraud.

Privacy Regulations

Organizations may be required to comply with privacy regulations depending on the type of information they collect.

Examples include:

General Data Protection Regulation (GDPR)

GDPR protects the personal data and privacy of individuals within the European Union.

Key principles include:

Health Insurance Portability and Accountability Act (HIPAA)

HIPAA protects sensitive healthcare information.

Healthcare organizations must safeguard:

Payment Card Industry Data Security Standard (PCI DSS)

PCI DSS establishes security requirements for organizations that process, store, or transmit payment card information.

Its purpose is to reduce credit card fraud and protect cardholder data.

Cookies and Cookie Consent

A cookie is a small file stored by a website on a user’s device.

Cookies are commonly used to:

Some privacy regulations require websites to obtain user consent before storing certain cookies.

Security Awareness Training

Security awareness training teaches users how to recognize and avoid cybersecurity threats.

Training often covers:

Well-trained employees significantly reduce organizational risk.

Best Practices

Key Terms

Exam Tips

Authentication, Authorization, Access Control, Encryption, Firewalls, VPNs, and Wireless Security

Authentication

Authentication is the process of verifying the identity of a user, device, or application before granting access to a system.

Authentication answers the question:

“Who are you?”

Only authenticated users should be allowed to access protected resources.

Examples of authentication methods include:

Authentication is the first step in protecting information systems.

Authorization

Authorization determines what an authenticated user is allowed to do after successfully logging in.

Authorization answers the question:

“What are you allowed to access?”

Examples include:

Authentication always occurs before authorization.

Authentication vs. Authorization
AuthenticationAuthorization
Verifies identityDetermines permissions
Occurs firstOccurs after authentication
Answers “Who are you?”Answers “What can you access?”
Uses credentialsUses permissions and policies

Understanding this distinction is essential for the CompTIA Tech+ exam.

Access Control

Access control is the process of restricting access to systems, data, and resources so that only authorized users can use them.

Access control helps organizations protect sensitive information and reduce security risks.

Access may be granted based on:

Principle of Least Privilege (PoLP)

The Principle of Least Privilege (PoLP) means users should receive only the minimum permissions necessary to perform their job duties.

Benefits include:

Least privilege is considered one of the most important security best practices.

Account Types

Different user accounts provide different levels of access.

Standard User

Standard users can:

They generally cannot:

Administrator

Administrator accounts have elevated privileges.

Administrators can:

Administrator accounts should be used only when necessary.

Password Security

Passwords remain one of the most common authentication methods.

Strong passwords significantly reduce the likelihood of unauthorized access.

Characteristics of Strong Passwords

Strong passwords should be:

Avoid using:

Password Best Practices

Organizations should encourage users to:

Password Managers

A password manager securely stores usernames and passwords in an encrypted vault.

Benefits include:

Users only need to remember one strong master password.

Multi-Factor Authentication (MFA)

Multi-Factor Authentication (MFA) requires users to provide two or more different authentication factors before access is granted.

MFA significantly reduces the risk of unauthorized access.

Authentication Factors

Authentication factors fall into three major categories.

Something You Know

Examples:

Something You Have

Examples:

Something You Are

Examples:

Using multiple authentication factors provides stronger security than relying on passwords alone.

Biometrics

Biometric authentication verifies identity using unique physical or behavioral characteristics.

Common biometric methods include:

Advantages:

Limitations:

Encryption

Encryption converts readable information (plaintext) into unreadable information (ciphertext) to protect confidentiality.

Only authorized users with the correct decryption key can restore the original data.

Encryption protects:

Symmetric Encryption

Symmetric encryption uses the same key for both encryption and decryption.

Advantages:

Disadvantages:

Asymmetric Encryption

Asymmetric encryption uses two mathematically related keys:

The public key encrypts data.

The private key decrypts data.

Asymmetric encryption supports secure communication over untrusted networks.

Digital Certificates

A digital certificate verifies the identity of a website, server, or organization.

Certificates help users confirm that they are communicating with legitimate systems.

Certificates commonly support:

Digital certificates are issued by trusted Certificate Authorities (CAs).

HTTPS

HTTPS (Hypertext Transfer Protocol Secure) encrypts communication between web browsers and web servers.

Benefits include:

Most secure websites use HTTPS.

Firewalls

A firewall monitors and controls network traffic based on predefined security rules.

Firewalls help prevent unauthorized access while allowing legitimate communication.

Firewalls may protect:

Types of Firewalls

Common firewall types include:

Host-Based Firewall

Installed directly on an individual computer.

Protects a single device.

Network Firewall

Protects an entire network.

Usually positioned between the internal network and the Internet.

Firewall Functions

Firewalls can:

Firewalls are a critical component of layered security.

Virtual Private Network (VPN)

A Virtual Private Network (VPN) creates an encrypted connection across an untrusted network such as the Internet.

VPNs protect data while users:

VPNs improve both privacy and security.

Wireless Security

Wireless networks should always use strong security protocols.

Older protocols are vulnerable to attack.

WPA2

Wi-Fi Protected Access 2 (WPA2) greatly improved wireless security through stronger encryption.

Although still widely used, newer standards provide additional protections.

WPA3

Wi-Fi Protected Access 3 (WPA3) is the current recommended wireless security standard.

Advantages include:

Organizations should use WPA3 whenever possible.

Public Wi-Fi Risks

Public wireless networks present several risks.

Potential threats include:

Users should avoid transmitting sensitive information over unsecured public Wi-Fi unless using a VPN.

Security Best Practices

To improve authentication and access security:

Key Terms

Exam Tips

Physical Security, Backups, Incident Response, Data Disposal, and Security Policies

Physical Security

Cybersecurity is not limited to software and networks. Organizations must also protect their physical assets from theft, damage, and unauthorized access.

Physical security refers to the safeguards used to protect:

Strong physical security helps prevent unauthorized individuals from accessing information systems.

Common Physical Security Controls

Organizations use a variety of physical security measures.

Examples include:

Combining multiple physical controls creates a stronger defense.

Secure Areas

Sensitive equipment is often located in secure areas such as:

Access should be limited to authorized personnel only.

Visitors should be escorted whenever they enter restricted areas.

Environmental Controls

Computers and networking equipment require appropriate environmental conditions to operate reliably.

Environmental controls include:

Proper environmental management helps prevent equipment damage.

Uninterruptible Power Supply (UPS)

A UPS (Uninterruptible Power Supply) provides temporary battery power during electrical outages.

Benefits include:

UPS systems are commonly used for servers and networking equipment.

Surge Protectors

A surge protector protects electronic equipment from voltage spikes.

Power surges may result from:

Surge protection helps extend the life of electronic devices.

Backups

A backup is a copy of important data stored separately from the original.

Backups protect organizations against:

Regular backups are one of the most important security controls.

Backup Types

Full Backup

A full backup copies all selected files every time.

Advantages:

Disadvantages:

Incremental Backup

An incremental backup saves only data changed since the last backup of any type.

Advantages:

Disadvantages:

Differential Backup

A differential backup saves all changes made since the last full backup.

Advantages:

Disadvantages:

Backup Best Practices

Organizations should:

Backups are only useful if they can be successfully restored.

Disaster Recovery

Disaster recovery (DR) focuses on restoring IT systems after major disruptions.

Possible disasters include:

An effective disaster recovery plan minimizes downtime and data loss.

Business Continuity

Business continuity ensures that essential business operations continue during and after disruptive events.

Business continuity planning includes:

Business continuity is broader than disaster recovery because it focuses on keeping the organization operational.

Incident Response

An incident is any event that threatens the confidentiality, integrity, or availability of systems or data.

Examples include:

Organizations should prepare for incidents before they occur.

Incident Response Process

Although organizations may use different frameworks, incident response generally follows these phases:

1. Preparation

Preparation includes:

Good preparation reduces the impact of future incidents.

2. Identification

The organization determines:

Quick identification limits damage.

3. Containment

Containment prevents the incident from spreading.

Examples include:

4. Eradication

During eradication, the organization removes the cause of the incident.

Examples include:

5. Recovery

Recovery restores systems to normal operation.

Activities include:

Systems should be carefully tested before returning to production.

6. Lessons Learned

After recovery, organizations review:

Continuous improvement strengthens future security.

Security Policies

A security policy is a formal document that defines an organization’s security requirements and expectations.

Policies help ensure consistent security practices across the organization.

Common policy topics include:

Employees should understand and follow organizational security policies.

Acceptable Use Policy (AUP)

An Acceptable Use Policy (AUP) defines how organizational computers, networks, and Internet resources may be used.

The policy typically explains:

Data Disposal

When equipment or storage devices are no longer needed, sensitive data must be removed securely.

Simply deleting files is often insufficient because deleted data may still be recoverable.

Secure Data Disposal Methods

Common disposal methods include:

Data Wiping

Overwrites storage media with new data.

Suitable for devices that will be reused.

Degaussing

Uses a strong magnetic field to erase magnetic storage devices.

Commonly used for older hard disk drives.

Physical Destruction

Physically destroys storage devices through:

Physical destruction is often used for highly sensitive information.

User Responsibilities

Every employee plays an important role in organizational security.

Users should:

Security is everyone’s responsibility.

Comprehensive Security Best Practices

Organizations should:

Layered security provides better protection than relying on a single control.

Key Terms

Exam Tips

Security Fundamentals

Malware

Identity and Access Management

Network Security

Disaster Recovery

Security Awareness