ITCertFoundryTechnical training system

CompTIA Security+ guided activity library

Practice Applied Reasoning, Not Just Definitions.

Every activity is a scored, step-by-step guide using real (fictional or sanitized) logs, scan output, headers, and scenarios — reading authentication logs, triaging a vulnerability scan, sequencing an incident response, and more. Nothing here targets, evades, or attacks a real system.

General Security Concepts

🔒 Locked

Inspecting a Certificate Chain

Real troubleshooting and security reviews constantly involve reading certificate details — expired certificates and broken chains are among the most common real-world causes of 'why won't this connection work' tickets.

Preview →
🔒 Locked

Comparing File Hashes to Verify Integrity

Verifying a download's hash against the vendor's published value is one of the simplest, most direct real-world applications of hashing — and a skill most IT professionals never actually practice.

Preview →
🔒 Locked

Classifying Security Controls at a Regional Retailer

The exam constantly asks you to classify a NEW, never-seen-before control on two independent axes at once — this only works if you can apply the definitions to unfamiliar examples, not recall a memorized list.

Preview →
🔒 Locked

Diagnosing CIA and AAA Failures at a Financial Company

Nearly every scenario question on this exam is secretly asking which leg of CIA or which AAA function is actually in play — practicing this diagnosis on realistic incidents is exactly the applied skill being tested.

Preview →
🔒 Locked

Reviewing a Change Ticket for Missing Controls at a School District

Recognizing exactly which element of change management is missing from a real ticket — not just knowing the checklist exists — is the applied skill the exam's scenario questions test.

Preview →

Threats, Vulnerabilities, and Mitigations

🔒 Locked

Reading Authentication Logs to Spot an Attack Pattern

Recognizing an attack pattern from raw log evidence — not just a term definition — is exactly the applied-reasoning skill the exam's scenario questions test, and the exact skill a real SOC analyst uses every shift.

Preview →
🔒 Locked

Recognizing Phishing Indicators in a Raw Email

Most real-world compromises still start with a human clicking something — reliably recognizing phishing indicators is one of the highest-leverage individual skills anyone in IT or security can have.

Preview →
🔒 Locked

Profiling the Threat Actor Behind a Government Contractor Intrusion

The exam almost never tells you the actor type outright — it describes behavior and expects you to infer the profile, exactly the skill a real analyst uses when triaging an incident with an unknown source.

Preview →
🔒 Locked

Categorizing Vulnerabilities Found in a Manufacturing Company's Security Audit

Correctly categorizing a vulnerability points directly at how to fix it — a misconfiguration and a zero-day require completely different responses, even though both might show up as 'a finding' on the same scan.

Preview →
🔒 Locked

Choosing Mitigations for a Hybrid Cloud Organization's Risk Register

The exam tests choosing the RIGHT mitigation for a specific described problem, not reciting the whole toolbox — this is exactly the applied decision a security analyst makes when prioritizing remediation work.

Preview →

Security Architecture

🔒 Locked

Building Firewall Rule Logic for a Small Retailer

Firewall rules are evaluated top-to-bottom with first-match-wins logic, and a rule set that looks correct at a glance can still have a dangerous ordering mistake — this is a genuinely common, genuinely serious real-world error.

Preview →
🔒 Locked

Designing a Segmented Network for a Small Medical Clinic

Designing segmentation from scratch — not just recognizing a diagram — is exactly the kind of applied, decision-making skill Security+ scenario questions test, and a genuinely common real consulting task.

Preview →
🔒 Locked

Classifying a Small Business's Data Inventory

You can't protect data you haven't first classified — this exercise builds the practical judgment behind an activity every real data-protection program depends on.

Preview →
🔒 Locked

Building a Recovery Plan for an MSP's Client Portal

RTO and RPO numbers only matter if you can actually evaluate whether a real backup/recovery plan satisfies them — the exam tests this evaluation directly, not just the definitions.

Preview →

Security Operations

🔒 Locked

Triaging a Vulnerability Scan Report

Real vulnerability management teams face far more findings than they can fix at once — prioritizing correctly (not just by raw score) is a genuinely high-stakes, frequently tested judgment call.

Preview →
🔒 Locked

Sequencing an Incident Response for a Ransomware Outbreak

Getting the SEQUENCE right during a real incident is often more important than any single technical action — reconnecting a still-infected system too early can undo hours of correct work.

Preview →
🔒 Locked

Building an Access-Control Matrix by Role

Building an access-control matrix from scratch — deciding what each role actually needs, not just what's convenient to grant — is a genuinely common real IAM task and a direct, practical application of least privilege.

Preview →
🔒 Locked

Evaluating HTTP Security Headers on a Web Response

Security headers are a fast, free, and commonly-overlooked application-hardening layer — this is a genuinely practical skill for reviewing any web application's basic security posture in minutes.

Preview →
🔒 Locked

Auditing Asset Disposal at a Manufacturing Company

A huge share of real-world data breaches trace back to improperly disposed hardware — recognizing exactly which lifecycle step failed is the applied skill that prevents the next one.

Preview →
🔒 Locked

Triaging SIEM Alerts at an MSP's Security Operations Center

SIEM and SOAR are tested together constantly, and confusing 'detects and alerts' with 'automatically responds' is one of the most common mix-ups on the exam — and in real SOC operations.

Preview →
🔒 Locked

Hardening Email Security for a Remote Workforce Organization

SPF, DKIM, and DMARC are tested together constantly, and business email compromise remains one of the costliest, most common real-world attack categories — getting this exactly right matters far beyond the exam.

Preview →
🔒 Locked

Designing Automation Guard Rails for a Managed Service Provider

The exam tests an honest, two-sided view of automation — real benefits AND real costs — and this is exactly the judgment call a security team makes before automating any sensitive process.

Preview →
🔒 Locked

Building a Defensible Investigation from Multiple Data Sources

The exam consistently presents a single data source and asks whether it's enough to prove a conclusion — recognizing the limit of one source, and what additional source would close the gap, is exactly the applied skill being tested.

Preview →

Security Program Management and Oversight

🔒 Locked

Performing a Basic Risk Assessment

Turning 'this seems risky' into an actual quantified business case is the exact skill that lets a security recommendation survive a conversation with finance leadership.

Preview →
🔒 Locked

Building a Governance Hierarchy for a Government Contractor

An auditor asking 'show me evidence this is followed' is exactly why the governance hierarchy exists — a policy alone, with nothing measurable or executable beneath it, gives an auditor nothing concrete to check.

Preview →
🔒 Locked

Building a Vendor Risk Questionnaire for a Retailer

Your security posture is only as strong as your weakest connected vendor — this is a leading real-world source of major breaches, and this exercise mirrors the real due-diligence work that prevents it.

Preview →
🔒 Locked

Diagnosing a Compliance-Versus-Security Gap at a Medical Clinic

Passing a compliance audit and being fully secure are related but genuinely different claims — conflating them is one of the most consequential, common misunderstandings in real security programs.

Preview →
🔒 Locked

Choosing the Right Audit or Assessment for a Financial Company

Audits, internal self-assessments, and penetration tests answer genuinely different questions — choosing the wrong one for a stated goal wastes real budget and gives leadership false confidence.

Preview →
🔒 Locked

Redesigning a Security Awareness Program at a School District

Security awareness is one of the highest-leverage, most consistently under-invested parts of a security program — recognizing WHY a training program isn't working is the applied skill that actually fixes it.

Preview →