The mental models everything else builds on. If you can explain these four lessons to a friend, you’re ahead of most people who “want to get into cyber”.
Every security decision balances three properties:
Attackers do the opposite: D-A-D (Disclosure, Alteration, Destruction). When you assess any system, ask how each property could fail here. A smart doorbell? Confidentiality of camera feeds. A hospital? Availability is life-or-death. This triad is also the backbone of many Security+ questions — know which property each scenario damages.
Your attack surface is every point where an attacker could try to get in: websites, APIs, email staff open, USB ports, ex-employees’ accounts, that forgotten Jenkins box from 2021. Bigger surface = more doors to guard.
An attack vector is the specific route: a phishing email with a macro-laced invoice, SQL injection through a search box, default credentials on a router.
Defenders shrink surfaces: close unused ports, disable unneeded features, patch software, remove stale accounts. Attackers map surfaces: run subdomain scans, port scans, Google dorks. Both jobs start with the same question — what exists? — which is why recon is always step one, whether you’re breaking or building.
Threat modelling = asking four questions before bad things happen:
Example: a login form. Spoofing? Weak passwords → require MFA. Info disclosure? Verbose errors reveal valid usernames → generic messages. You just threat-modelled. Security+ loves asking you to pick the right mitigation for a STRIDE category.
You now speak enough security to survive any intro call. Time to make it practical: hit the challenge arena.