ExamOpsPractice free

CompTIA Security+ SY0-701 · Free study guide

Objective 4.1 — Secure endpoints, servers, cloud workloads, and mobile resources

A secure baseline defines the approved starting state for a resource. Establish it from workload requirements and credible guidance, test it, deploy it consistently, and monitor for drift. Baselines should cover identity, services, ports, software, logging, encryption, update settings, and recovery—not only a list of disabled features.

Hardening targets differ. A workstation needs user and browser controls; a server needs service-specific exposure and administration paths; a switch or router needs protected management, configuration backups, and routing controls. Cloud workloads add identity policies, security groups, metadata services, images, and provider logging. IoT, embedded, real-time, and industrial systems may have limited patch options and safety constraints, requiring segmentation and compensating monitoring.

Wireless and mobile

A wireless site survey measures coverage, interference, and placement. A heat map visualizes the results; it does not replace secure configuration. Use modern protection such as WPA3 where supported, enterprise authentication through a service such as RADIUS when appropriate, protected management, segmented guest access, and monitoring for unauthorized access points.

Mobile deployment models change ownership and privacy. BYOD uses employee-owned devices, COPE allows personal use on corporate-owned devices, and CYOD lets users choose from an approved list. MDM or unified endpoint management can enforce encryption, screen lock, approved applications, update posture, remote actions, and separation of managed data. Cellular, Wi-Fi, and Bluetooth each introduce connection risks; disable or restrict what the role does not need.

Application safeguards

Input validation checks data against expected type, length, range, and structure on a trusted boundary. Secure cookie attributes reduce exposure to script access or unprotected transport. Static analysis inspects code without running it, while sandboxing limits execution impact. Code signing supports integrity and publisher verification when trust and key custody are valid.

Monitoring closes the baseline loop. Inventory deployed versions, compare settings, collect relevant events, and define response for drift. A baseline that is never measured becomes documentation rather than an operating control.

Decision rule: choose controls that fit the resource’s ownership, exposure, function, and patch constraints, then preserve evidence that the approved baseline remains deployed.

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free