1.2 Summarize fundamental security concepts
Domain 1: General Security Concepts
This objective covers the vocabulary the rest of the exam is built on: the CIA triad, non-repudiation, AAA (authentication, authorization, accounting), gap analysis, and Zero Trust. Expect Zero Trust to get real weight — know the split between the control plane (adaptive identity, policy engine, policy administrator) and the data plane (policy enforcement point, implicit trust zones). Physical security appears here too: bollards, access control vestibules, sensor types, and lighting. Deception technology (honeypots, honeynets, honeyfiles, honeytokens) shows up as detective tooling, not prevention. The exam favors scenario questions: which Zero Trust component makes the access decision versus which one enforces it, or which physical control stops tailgating. Study the definitions until you can distinguish authentication from authorization instantly, because distractors deliberately swap them. Also be ready to explain why non-repudiation depends on digital signatures rather than encryption alone.
What you must know
- CIA triad
- Zero Trust planes
- AAA framework
- Non-repudiation
- Physical security controls
- Honeypots and deception
common pitfall · Candidates mix up the Zero Trust policy engine (which decides) with the policy enforcement point (which allows or blocks the connection).
Try a sample question
An architect is designing a zero trust network. When a user requests access to an application, the request is evaluated against the user's identity, device health, and current threat intelligence, and a decision to grant or deny access is produced. Which zero trust component is responsible for making this access decision?
- A Policy enforcement point
- B Implicit trust zone
- C Data plane
- D Policy engine
Show answer & explanations
- A The policy enforcement point sits in the traffic path and carries out the decision by allowing or terminating the connection, but it does not evaluate the request or decide the outcome itself.
- B An implicit trust zone is an area where traffic is trusted without per-request evaluation, something zero trust architecture seeks to minimize; it is a network region, not a decision-making component.
- C The data plane is where subject traffic actually flows to resources once access is granted; decisions about that traffic are made in the control plane, not by the data plane itself.
- D correct ·Correct. In the zero trust control plane, the policy engine weighs identity, device posture, and threat data to render the grant-or-deny decision, which the policy administrator then relays for enforcement.
sample item — the full bank runs 450+ questions at exam difficulty
Is objective 1.2 your weak spot?
The free readiness check finds your weakest objectives in 15 adaptive questions — then full access drills them until the gauge clears the cut line.
Check my readiness — free