all modules module 01 · beginner

Security Fundamentals

The mental models everything else builds on. If you can explain these four lessons to a friend, you’re ahead of most people who “want to get into cyber”.

01The CIA triad~4 min

Every security decision balances three properties:

  • Confidentiality — only the right eyes see the data. Broken by leaks, weak passwords, exposed buckets.
  • Integrity — data isn’t tampered with. Broken by unauthorized edits, man-in-the-middle changes, defacements.
  • Availability — the system works when needed. Broken by DDoS, ransomware, deleting prod at 5pm Friday.

Attackers do the opposite: D-A-D (Disclosure, Alteration, Destruction). When you assess any system, ask how each property could fail here. A smart doorbell? Confidentiality of camera feeds. A hospital? Availability is life-or-death. This triad is also the backbone of many Security+ questions — know which property each scenario damages.

02Attack surface & attack vectors~4 min

Your attack surface is every point where an attacker could try to get in: websites, APIs, email staff open, USB ports, ex-employees’ accounts, that forgotten Jenkins box from 2021. Bigger surface = more doors to guard.

An attack vector is the specific route: a phishing email with a macro-laced invoice, SQL injection through a search box, default credentials on a router.

Defenders shrink surfaces: close unused ports, disable unneeded features, patch software, remove stale accounts. Attackers map surfaces: run subdomain scans, port scans, Google dorks. Both jobs start with the same question — what exists? — which is why recon is always step one, whether you’re breaking or building.

03Threat modelling in plain English~5 min

Threat modelling = asking four questions before bad things happen:

  1. What are we building? Data flows matter more than boxes.
  2. What can go wrong? Use STRIDE as a checklist: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
  3. What will we do about it? Mitigate, accept, transfer (insurance), or avoid (don’t build it).
  4. Did we do a good job? Test, review, repeat after changes.

Example: a login form. Spoofing? Weak passwords → require MFA. Info disclosure? Verbose errors reveal valid usernames → generic messages. You just threat-modelled. Security+ loves asking you to pick the right mitigation for a STRIDE category.

04The vocabulary that makes you sound hireable~5 min
  • CVE — public ID for a known vulnerability. CVSS — its 0–10 severity score.
  • 0-day — a flaw with no patch yet. N-day — patched but still exploited everywhere.
  • PoC — proof of concept, minimal demo that a bug is real.
  • Pentest — authorized, scoped, time-boxed attack with a report at the end. Bug bounty — continuous, crowdsourced, paid per valid finding.
  • Red team attacks like a persistent adversary, blue team defends and detects, purple team makes both better together.
  • Threat actor categories: script kiddies, hacktivists, insiders, organized crime (money), nation-states (espionage/sabotage).

You now speak enough security to survive any intro call. Time to make it practical: hit the challenge arena.