Cybersecurity Fundamentals

Security Goals, Threats, and Controls

Connect security objectives to concrete harm, trace threat paths through weaknesses, and verify layered controls without hiding residual risk.

Beginner14 min read
Cybersecurity Fundamentals lessonCybersecurity foundationsPractice

UNTIMED COACHING

Practice before the pressure

Use feedback to correct the model, not merely memorize an option position.

GUIDED PRACTICE

Practice the lesson questions

Answer normal lesson questions without a timer. Every answer includes an explanation, and incorrect answers can be tried again before continuing.

CONCEPT MODELS

See the lesson as a system

Use these visual guides to connect the key ideas before answering the questions.

Classify the security harmStart with protected information, then separate disclosure, unauthorized change, and service interruption as different harms.
Classify the security harmProtected data branches to an access boundary, an integrity record, and service health to represent confidentiality, integrity, and availability.
Protected dataInformation needed by the mission
Access boundaryLimits unauthorized information disclosure
Integrity recordKeeps values accurate and trusted
Service healthKeeps authorized use timely
Trace the threat pathConnect a possible harmful event to a real weakness, then place a safeguard and inspect the remaining outcome.
Trace the threat pathA threat event reaches vulnerability evidence, a security control reduces the path, and a residual result remains for review.
Threat eventCan cause denied service
Vulnerability evidenceShows an exploitable system weakness
Security controlReduces likelihood or impact
Residual resultRecords remaining risk for review