The five measured domains
General Security Concepts
CIA, AAA, control types, Zero Trust, change management, and cryptography.
Map CIA and AAA to real assets, classify controls, and explain when to use encryption, hashing, signatures, and PKI.
Threats, Vulnerabilities, and Mitigations
Threat actors, attack vectors, vulnerabilities, malicious activity, and mitigations.
Build threat-vulnerability-impact-control chains and validate each mitigation after deployment.
Security Architecture
Architecture models, enterprise infrastructure, data protection, resilience, and recovery.
Draw trust zones and data flows, assign cloud responsibility, and define tested recovery objectives.
Security Operations
Hardening, asset and vulnerability management, monitoring, IAM, automation, response, and forensics.
Correlate host, network, identity, and data evidence; then write containment that preserves evidence.
Security Program Management and Oversight
Governance, risk, third parties, compliance, audits, privacy, and awareness.
Create one complete risk-register item, vendor clause set, exception workflow, and outcome metric.
How to study across domains
- Start with the security objective and asset, not the product name.
- Separate threat, vulnerability, exposure, impact, and control.
- Connect architecture to operational evidence and response.
- Attach governance, ownership, and review to every sustained control.
Official sources
Links should be rechecked before a high-stakes decision.
Choose your assessment depth
Use Quick for a directional reading or Full when you want broader evidence and a richer report.