Missiora
A+ Domain: Security Fundamentals

IT & Cyber Certifications

A+ Domain: Security Fundamentals

2 min readPublished 22 Jul 2026

A+ security covers the essentials every technician must apply daily and forms the natural bridge to Security+. You protect devices, data and users against everyday threats.

Beginner: the basics

  • Malware types: viruses, worms, trojans, ransomware and spyware.
  • Authentication: passwords, MFA, and why length and uniqueness matter.
  • Physical security: locks, cable locks, screen privacy and badge access.

Intermediate concepts

  • Logical controls: least privilege, account lockout and permissions.
  • Social engineering: phishing, tailgating and shoulder surfing.
  • Data destruction: wiping, degaussing and physical destruction.

Advanced considerations

  • Encryption at rest (BitLocker/FileVault) and in transit (HTTPS/VPN).
  • Securing SOHO routers: change defaults, WPA2/WPA3, firmware updates.
  • Incident basics: isolate, report, and preserve evidence.

Practical examples

  • Removing malware using the CompTIA malware-removal steps.
  • Enabling disk encryption and configuring MFA for a user.

Common mistakes

  • Reusing passwords or disabling MFA for convenience.
  • Leaving default router credentials in place.
  • Skipping backups before malware remediation.

Best practices

  • Apply least privilege and strong, unique authentication.
  • Patch promptly and use reputable endpoint protection.
  • Educate users — most breaches start with a person.

What employers expect

You can apply everyday security controls, recognise social engineering, remove malware methodically, and explain why each control matters.

Technical interview questions

  1. What is the difference between a virus and a worm?
  2. What are the CompTIA malware-removal steps?
  3. Why is MFA more secure than a password alone?
  4. How would you secure a home/office router?

Behavioural interview questions

  1. Describe a time you helped a user recover from a phishing attack.
  2. Tell me about enforcing a security policy a user disliked.

Practice questions

  1. Which malware encrypts files for a ransom? (Ransomware)
  2. What adds a second factor to a password? (MFA)
  3. Which encrypts a Windows disk? (BitLocker)

Where this fits in your A+ pathway

This is one part of the CompTIA A+ study hub. When you're confident here, review Operating Systems and move on to Hardware Troubleshooting.

Practise with Missiora

Interview Intelligence

How this topic actually shows up in interviews — and how to demonstrate you understand it.

Why employers ask about this

Support techs are the first line of defence; interviewers check security awareness and safe habits.

Technical questions
What are the main malware types?+

Viruses, worms, trojans, ransomware and spyware — know how each spreads and its impact.

What is the principle of least privilege?+

Give users only the access they need to do their job — no more — to limit damage if an account is misused.

Behavioural questions
Describe handling a suspected malware incident calmly.+

Isolate the device, report it, and follow the process rather than panicking.

Real-world scenarios
“A user clicked a suspicious link and now sees pop-ups.”+

Expected answer: Disconnect the device, scan for malware, report the incident and check whether credentials need resetting.

Common candidate mistakes
  • Granting admin rights 'to save time'.
  • Not recognising phishing/social engineering.

Employability Intelligence

Where this knowledge takes you — the jobs, skills and certifications it feeds into.

Relevant roles
IT Support TechnicianIT Security TechnicianSOC Analyst
Skills you're proving
Malware awarenessLeast privilegePhysical securitySafe practices
Recommended certifications
Career progression

IT Support → IT Security Technician → SOC Analyst (via Security+).

What employers expect

That you follow secure practices and recognise common threats.

Frequently asked questions

How does A+ security relate to Security+?

A+ teaches the everyday security controls a technician applies, while Security+ goes far deeper into threats, cryptography and architecture. A+ security is the natural stepping stone into Security+.

What are the CompTIA malware-removal steps?

Identify and verify the symptoms, quarantine the system, disable System Restore, remediate (update and scan), schedule scans and enable protection, re-enable System Restore, and educate the user — in that order.

Why is user education part of security?

Most breaches begin with a person clicking a link or revealing credentials. Teaching users to spot phishing and follow policy is one of the most effective controls a technician can apply.

Related guides

Practise what you've learned

Turn this guide into real, evidenced progress

Missiora helps you measure, improve and evidence the capabilities employers actually value — start with the tools best suited to this topic.

M
Published by
Missiora

Missiora is an AI Employability Intelligence platform. Our resources are researched and reviewed by the Missiora team to help you measure, improve and prove your career readiness.