<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: TiltedLunar123</title>
    <description>The latest articles on DEV Community by TiltedLunar123 (@tiltedlunar123).</description>
    <link>https://dev.to/tiltedlunar123</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3847611%2F5372ff69-df32-4335-9ef6-65d8c9504ae5.jpeg</url>
      <title>DEV Community: TiltedLunar123</title>
      <link>https://dev.to/tiltedlunar123</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/tiltedlunar123"/>
    <language>en</language>
    <item>
      <title>Security+ Port Questions Want the Secure Swap</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Thu, 24 Sep 2026 09:32:44 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/security-port-questions-want-the-secure-swap-4e7p</link>
      <guid>https://dev.to/tiltedlunar123/security-port-questions-want-the-secure-swap-4e7p</guid>
      <description>&lt;p&gt;Plenty of people create a deck of forty port numbers to memorize and still struggle with the port questions on the SY0-701 exam. The deck works well for its purpose, but the test doesn't usually ask just for the number. Instead, it might mention a protocol that transmits data in plain text and ask what should be used instead, or show a firewall rule and ask what's wrong with it.&lt;/p&gt;

&lt;p&gt;That's objective 4.5, where secure protocol selection sits right next to firewall rules. So the thing worth learning is the swap: the insecure protocol, the secure counterpart that replaces it, and which port each one uses.&lt;/p&gt;

&lt;h2&gt;
  
  
  Learn the pairs, not the list
&lt;/h2&gt;

&lt;p&gt;A simple list treats all numbers equally, which can make them hard to remember. With pairs, each number has a partner that helps explain it. You should know these swaps well.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Telnet uses port 23 and switches to SSH on port 22.&lt;/li&gt;
&lt;li&gt;HTTP runs on port 80 and changes to HTTPS on port 443.&lt;/li&gt;
&lt;li&gt;FTP operates on ports 20 and 21, and can switch to SFTP on port 22 or FTPS on ports 989 and 990.&lt;/li&gt;
&lt;li&gt;LDAP works on port 389 and moves to LDAPS on port 636.&lt;/li&gt;
&lt;li&gt;POP3 uses port 110 and changes to POP3S on port 995; similarly, IMAP on port 143 becomes IMAPS on port 993.&lt;/li&gt;
&lt;li&gt;SMTP runs on port 25 and can switch to submission on port 587 with STARTTLS, or to SMTPS on port 465 with TLS from the start.&lt;/li&gt;
&lt;li&gt;Syslog sends on port 514 and moves to syslog over TLS on port 6514.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Once the pair is the unit, many questions become clear. An admin handling switch management via Telnet should use SSH. A directory lookup that travels across the network in plain text should use LDAPS. You're finishing a pair you already know half of, which is much easier than trying to find one number out of forty.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two traps where the fix isn't a new port
&lt;/h2&gt;

&lt;p&gt;Most swaps lead to another port, making it simple to think they all do. However, two of the most tested ones don't, and the incorrect answers are built on that misunderstanding.&lt;/p&gt;

&lt;p&gt;The first is SNMP. In versions 1 and 2c, community strings travel in plain text over UDP ports 161 and 162. SNMPv3 remedies this by incorporating authentication and encryption, still using those same two ports. So an option to switch SNMP to a secure port is incorrect. The solution lies in upgrading the version.&lt;/p&gt;

&lt;p&gt;The second is DNS, with a twist. Traditional DNS on port 53 lacks encryption, meaning anyone along the route can see your queries. DNSSEC, which sounds like it might help, only signs DNS records to detect fake responses; it doesn't encrypt anything, so lookups remain visible. Encrypting the actual query is done by DNS over TLS (DoT) on port 853 or DNS over HTTPS (DoH) on port 443. If a question asks how to prevent others from seeing which sites a user looks up, DoT or DoH is the answer. To stop fake responses, DNSSEC is the solution. Both are part of DNS security but address different issues.&lt;/p&gt;

&lt;h2&gt;
  
  
  SFTP and FTPS are not the same thing
&lt;/h2&gt;

&lt;p&gt;Both are known as secure FTP, and the exam leans on that confusion. SFTP works within SSH for file transfer and isn't related to the FTP protocol, so it uses port 22, which is also used by SSH and SCP. FTPS is standard FTP encrypted with TLS, and it operates on ports 989 and 990.&lt;/p&gt;

&lt;p&gt;That difference raises a real question. In a scenario where the firewall only allows port 22 outbound, SFTP will function but FTPS won't. If the organization desires one open port for remote shell and file transfer, the choice is SSH, as SFTP and SCP use that port too.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where ports show up in a firewall rule
&lt;/h2&gt;

&lt;p&gt;You'll find port numbers in rule tables, often in a performance-based question. The task here is to look at each rule and figure out if that particular traffic should pass through.&lt;/p&gt;

&lt;p&gt;A few rules stand out. An inbound Telnet allow on port 23 from any source is a problem because it's unencrypted. Allowing Remote Desktop Protocol (RDP) on port 3389 from the internet is an issue too, and this one often catches people out. Even though RDP is encrypted, RDP exposed to the internet is a leading entry point for ransomware. Just being encrypted doesn't mean it's safe to expose. The rule table is testing exposure, not only encryption.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to drill it
&lt;/h2&gt;

&lt;p&gt;Write down the insecure part of each pair first, then add the secure counterpart and its port number. Next, reverse the order. Begin with the secure protocol and explain what it replaced. Finally, say out loud what each secure version adds, whether that's encryption, authentication, or integrity, because that detail is what separates DNSSEC from DoT.&lt;/p&gt;

&lt;p&gt;Once that's solid, read ports inside real rules instead of on their own. A &lt;a href="https://secplusmastery.com/r/ch-devto" rel="noopener noreferrer"&gt;free firewall rule question&lt;/a&gt; will tell you quickly if the pairs hold up when mixed with source addresses and directions. The &lt;a href="https://secplusmastery.com/r/ch-devto?to=/security-plus-ports" rel="noopener noreferrer"&gt;full port table&lt;/a&gt;, including less common ports, is worth a single pass once the pairs are solid. CompTIA's wording for objective 4.5 is listed in the &lt;a href="https://secplusmastery.com/r/ch-devto?to=/security-plus-objectives" rel="noopener noreferrer"&gt;objectives&lt;/a&gt; as well.&lt;/p&gt;

&lt;p&gt;When a question mentions a cleartext protocol, start by looking for its paired protocol first. If the question names SNMP or DNS, pause and verify whether the solution involves a newer version of the protocol or an alternative one before proceeding.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>The Security+ Log Question Has One Right Source</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Tue, 22 Sep 2026 09:33:41 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/the-security-log-question-has-one-right-source-2of</link>
      <guid>https://dev.to/tiltedlunar123/the-security-log-question-has-one-right-source-2of</guid>
      <description>&lt;p&gt;Domain 4 is the largest part of SY0-701, and a fair portion of it is one type of question dressed up differently. A short scenario outlines what an analyst needs to figure out, and then four data sources are listed below it, and you pick one. Firewall logs. Endpoint logs. DNS query logs. Vulnerability scan results.&lt;/p&gt;

&lt;p&gt;Most study material prepares you for the wrong version of that question. It teaches the log types as a list, detailing the fields each one contains, and quizzes you on what a firewall log includes. The exam rarely tests that. Instead, it asks &lt;strong&gt;which source answers the question in the scenario&lt;/strong&gt;, and the best way to prepare is to learn the mapping from the question to the source rather than the contents of each source.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three layers, three questions
&lt;/h2&gt;

&lt;p&gt;The layer a source resides at tells you what it can prove, and that's really the key.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The boundary proves reachability.&lt;/strong&gt; Firewall logs list source and destination IP addresses. They also include port, protocol, and the allow or deny decision, making them quick for spotting denied inbound traffic, port scans, and failed egress. A wall of denies from one internal host is a scanning or beaconing signature. What can a firewall log not tell you? What ran on the machine.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The host proves execution.&lt;/strong&gt; Endpoint and EDR logs record process creation with the parent-child relationship intact, which is how you see that Word spawned PowerShell. They also track file system and registry changes and link an outbound connection to the exact binary that opened it. When the scenario asks about what ran, or asks you to confirm a parent process, you're dealing with the host.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The application proves what was touched.&lt;/strong&gt; Application logs connect activity to a user ID and a session ID and a request ID and an API endpoint. That follows one actor's path through the software and shows which records got queried. Nothing at the network boundary can answer that.&lt;/p&gt;

&lt;h2&gt;
  
  
  The distractor is always the source that might have a clue
&lt;/h2&gt;

&lt;p&gt;Question creators often use nearby sources as wrong answers. The cleanest example is packet capture against flow records. Both are network evidence, both would be in the room during an investigation, and they answer different questions.&lt;/p&gt;

&lt;p&gt;Flow records show who talked to whom and how much and for how long. They're cheap to keep and are the backbone of network investigation, which is why they appear safe. Packet capture is the full content of the traffic at one point in the network, and it's the only source that reveals what was actually transferred. So if the scenario asks about data leaving the environment or what a session contained, you want the packet capture, even though the flow record looks relevant.&lt;/p&gt;

&lt;h2&gt;
  
  
  An alert and a block are different pieces of evidence
&lt;/h2&gt;

&lt;p&gt;Intrusion detection and intrusion prevention are often taught together, with a slash in between. On this objective, the slash matters quite a lot. An &lt;strong&gt;IDS log shows an alert.&lt;/strong&gt; An &lt;strong&gt;IPS log shows a block.&lt;/strong&gt; Both provide a signature ID and the offending packets.&lt;/p&gt;

&lt;p&gt;Why does this distinction matter? Because it is evidentiary rather than trivia. If the question is whether the attack hit its target, an IDS entry says the traffic was seen and allowed through, and an IPS entry says the session was stopped. Same signature, opposite conclusion about impact. A question asking about containment would look for the block.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two sources that describe state rather than activity
&lt;/h2&gt;

&lt;p&gt;Vulnerability scan results and configuration and change data are the other reliable distractor pair, and they fail for one reason. They describe what a system looks like rather than what happened on it. A scan says port 3389 is open and unpatched. It doesn't say anyone connected. Configuration and change records show what the device was set to and when someone made changes, which is useful for proving unauthorized changes but not for reconstructing an intrusion.&lt;/p&gt;

&lt;p&gt;Dashboards fit into the same caution. A dashboard summarizes volume so a person can spot patterns, and it's a starting point rather than evidence. Every finding on one gets confirmed against underlying logs before it goes into a report, and an option that offers a dashboard as proof is almost always wrong.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to drill this
&lt;/h2&gt;

&lt;p&gt;Read the stem's verb first before looking at the options. Who logged in? That's authentication, so it goes to the OS security log, which means Windows Security or &lt;code&gt;auth.log&lt;/code&gt; depending on the platform. What ran? That's execution, so it goes to endpoint logging. What was transmitted? That's content, so it's packet capture. What was reachable? That's about the boundary, so it's the firewall. There are only four verbs and they cover a lot.&lt;/p&gt;

&lt;p&gt;Then practice the objective as a block rather than scattered through a mixed set, because the sources only separate when you see them side by side. The &lt;a href="https://secplusmastery.com/security-plus-domain-4-practice" rel="noopener noreferrer"&gt;Domain 4 practice set&lt;/a&gt; is filtered to security operations, and objective 4.9 is listed as Use Data Sources to Support an Investigation in the &lt;a href="https://secplusmastery.com/security-plus-objectives" rel="noopener noreferrer"&gt;full objectives list&lt;/a&gt; if you want CompTIA's own wording. Individual source names sit in the &lt;a href="https://secplusmastery.com/glossary" rel="noopener noreferrer"&gt;glossary&lt;/a&gt; as well.&lt;/p&gt;

&lt;p&gt;One final habit. When two options both look defensible, ask which one directly answers the question and which one just contains a clue. That's the split the question was built on. Once you spot it, the four options stop being four.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>Every Security+ Control Answer Needs Two Labels</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Sun, 20 Sep 2026 09:37:43 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/every-security-control-answer-needs-two-labels-4m99</link>
      <guid>https://dev.to/tiltedlunar123/every-security-control-answer-needs-two-labels-4m99</guid>
      <description>&lt;p&gt;Objective 1.1 seems to focus on vocabulary. There are four categories and six types to memorize, and then you progress. Then, an exam scenario about a badge reader or a written policy asks which control it is, and half the group picks something the other half has already dismissed.&lt;/p&gt;

&lt;p&gt;Why do people disagree on that? Because the question demands two labels, while most study materials present everything as a single list of ten terms.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two axes, not one list
&lt;/h2&gt;

&lt;p&gt;A control belongs to a category and a type. Categories are about who or what enforces it. There are four:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Technical.&lt;/strong&gt; A system does it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Managerial.&lt;/strong&gt; Someone decides and writes it down.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Operational.&lt;/strong&gt; People do it as part of their job.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Physical.&lt;/strong&gt; You can walk into it.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The type is about timing. It's where the control fits relative to the potential problem:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Preventive&lt;/strong&gt; stops it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Deterrent&lt;/strong&gt; makes someone decide not to try.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Detective&lt;/strong&gt; notices it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Corrective&lt;/strong&gt; cleans it up afterward.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Directive&lt;/strong&gt; tells someone what to do.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Compensating&lt;/strong&gt; replaces a control that can't be used.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every control has one label from each side. A fence is physical and deterrent. Encryption at rest is technical and preventive. A quarterly access review is managerial and detective. Practice answering with both words even when the question asks for just one, as the second word often clarifies the first.&lt;/p&gt;

&lt;h2&gt;
  
  
  The same control can move between boxes
&lt;/h2&gt;

&lt;p&gt;This is where it feels unfair. A security guard is always physical. The type changes with whatever the question says the guard is doing.&lt;/p&gt;

&lt;p&gt;A guard standing at the entrance where everyone can see him, in a question about people deciding not to walk in, is a deterrent. A guard checking badges and turning people away is preventive. A guard watching a camera feed and phoning it in is detective.&lt;/p&gt;

&lt;p&gt;Nothing about the guard changes; the surrounding sentence does, and that's what's being tested. Cameras and logging work the same way.&lt;/p&gt;

&lt;h2&gt;
  
  
  Compensating does not mean extra
&lt;/h2&gt;

&lt;p&gt;Compensating is what people grab for when they are unsure, and using it out of uncertainty is usually wrong.&lt;/p&gt;

&lt;p&gt;A compensating control exists when a required control can't be used. The need still stands, though the usual way to meet it is blocked, so something else steps in to cover the same risk. Think of a legacy server that can't handle the current patch; it's isolated on its own network segment with stricter firewall rules and enhanced logging, and that setup compensates for the patch that can't be applied.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;What about an extra layer on something that already works? That's just another control, and calling it compensating gets the question wrong. If you can't name the missing control or explain why it's missing, choose a different answer.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Directive is the one that gets skipped
&lt;/h2&gt;

&lt;p&gt;A directive control tells someone what to do. An acceptable use policy, a documented procedure for handling customer records, and a sign by the door reading "one person at a time" are all directive.&lt;/p&gt;

&lt;p&gt;The key difference is enforcement. A policy saying laptops must be encrypted is directive and managerial, as it's a policy that controls behavior. Full disk encryption pushed by the MDM that users can't disable is preventive, because it's a technical control that stops something before it happens.&lt;/p&gt;

&lt;p&gt;Both aim at the same goal. They are different types though, and the exam will hand you both in the same question set.&lt;/p&gt;

&lt;h2&gt;
  
  
  Reading the question for the right cue
&lt;/h2&gt;

&lt;p&gt;Verbs are key here.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Stops it from happening: &lt;strong&gt;preventive&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Makes someone decide not to try: &lt;strong&gt;deterrent&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Notices or alerts or reviews: &lt;strong&gt;detective&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Restores or rebuilds after the fact: &lt;strong&gt;corrective&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Instructs or requires or trains: &lt;strong&gt;directive&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Covers a requirement that can't be met the intended way: &lt;strong&gt;compensating&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The category is often clear. A device or a firewall rule is technical. A policy or an audit cycle is managerial. Awareness training and a process someone runs by hand are operational. Locks and cameras and fences and guards are physical.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Watch out for the word operational; it trips people up. Does it mean a thing that is being operated? No. Operational means humans running a process. A backup job on a schedule is technical because the system runs it. Someone testing the restore every quarter and signing off is operational.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Practice with pairs
&lt;/h2&gt;

&lt;p&gt;The fix is boring, and it works. When you encounter a control in a practice question or a lesson, say both labels before checking the choices. A badge reader: technical and preventive. A warning banner at login: directive, and technical if the system forces you to click it, managerial if it's just in a handbook.&lt;/p&gt;

&lt;p&gt;Do twenty of these and the question stops feeling like vocabulary. Is that tedious? Very. It is also the whole trick. Go through CompTIA's published exam objectives and work down the list instead of relying on someone else's table.&lt;/p&gt;

&lt;p&gt;The drag and match performance-based questions ask you to put controls in the right buckets, too. There's a free one on &lt;a href="https://secplusmastery.com/r/ch-devto" rel="noopener noreferrer"&gt;my site&lt;/a&gt; if you want to see the format before exam day.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>Your Security+ Expires in Three Years. Here Is What Renews It.</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Fri, 18 Sep 2026 10:35:18 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/your-security-expires-in-three-years-here-is-what-renews-it-4ah5</link>
      <guid>https://dev.to/tiltedlunar123/your-security-expires-in-three-years-here-is-what-renews-it-4ah5</guid>
      <description>&lt;p&gt;Passing Security+ is not the end of paperwork. The certification lasts three years, starting from the day you pass. Renewal costs 50 continuing education units (CEUs) and a fee. Fifty is more than it sounds. Plan for it. Here's what counts toward those 50, what doesn't, and the one route that can finish the whole thing in a single activity.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three ways to renew with no CEUs
&lt;/h2&gt;

&lt;p&gt;CompTIA lists three ways to renew the certification that don't involve submitting any activities. No tallying and no waiting on a reviewer.&lt;/p&gt;

&lt;p&gt;The first is a CertMaster CE course. CompTIA calls it the fastest option, and Security+ is one of only three certifications it covers, alongside A+ and Network+. The course fee includes the CE fee, which is not nothing. Holders of the higher certifications can't use this route, so renewing SecurityX is harder than renewing Security+.&lt;/p&gt;

&lt;p&gt;The second is passing the newest version of the exam. Sitting the current Security+ again renews it on the spot, which is worth knowing before you book anything else.&lt;/p&gt;

&lt;p&gt;The third is earning a higher-level CompTIA certification. It applies to some certifications and not others. Read your own renewal requirements instead of assuming.&lt;/p&gt;

&lt;p&gt;Everything else? That means earning CEUs and uploading proof of every one of them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Fifty units, and the rules that decide them
&lt;/h2&gt;

&lt;p&gt;So what counts? Five kinds of activity:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;training and higher education&lt;/li&gt;
&lt;li&gt;IT industry participation&lt;/li&gt;
&lt;li&gt;non-CompTIA certifications&lt;/li&gt;
&lt;li&gt;publishing&lt;/li&gt;
&lt;li&gt;related work experience&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Three conditions apply to all five. Miss one, and the activity is worthless.&lt;/p&gt;

&lt;p&gt;Timing. The activity has to happen within your three-year cycle. Something you did before you certified is useless here.&lt;/p&gt;

&lt;p&gt;Relevance. At least half the content must relate to the exam objectives you are renewing against. CompTIA is clear that it looks at both topics and the cognitive level of the material. If you can't point at the objective a course maps to, that's your answer.&lt;/p&gt;

&lt;p&gt;Documentation. Every activity needs paper. Paperwork is where most submissions fail, and it fails them at the last step, after the studying and the money are already spent.&lt;/p&gt;

&lt;h2&gt;
  
  
  The caps are the part people miss
&lt;/h2&gt;

&lt;p&gt;Here's the catch. A live webinar earns one CEU per hour, which sounds good until you read the ceiling. So, how far do webinars get you? Not far at all. They are capped at 10 CEUs for Security+, conferences carry the same cap of 10, and sitting through webinars until the number goes up quietly tops out at a fifth of what you actually need.&lt;/p&gt;

&lt;p&gt;There is no such ceiling on a training course. One CEU per hour, up to the full 50, and a college course is worth 10 CEUs for each three to four credit-hour class, so five classes would cover the whole requirement between them. Teaching or mentoring earns one CEU an hour and caps at 20. Creating instructional materials earns two CEUs an hour and also caps at 20. Sitting in a CompTIA exam development workshop as a subject matter expert has no cap and can cover the full 50 on its own.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;There is a shortcut for anyone working under the Department of Defense, and it is the single biggest one on this page for the people it applies to. The DoD Cybersecurity Fundamentals and Cyberspace Operations Fundamentals courses are pre-approved and carry 25 CEUs for Security+. That's half the requirement in one submission. Worth checking before you pay for anything.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  One certification can do the whole job
&lt;/h2&gt;

&lt;p&gt;Were you going to sit another exam anyway? Then a qualifying non-CompTIA certification is the efficient route. CompTIA publishes an approved list per certification, and for Security+, most entries are worth the full 50. These all sit there at 50, which is really the entire renewal in one activity:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;CISSP&lt;/li&gt;
&lt;li&gt;CISA and CISM&lt;/li&gt;
&lt;li&gt;SSCP&lt;/li&gt;
&lt;li&gt;CEH&lt;/li&gt;
&lt;li&gt;AWS Certified Security Specialty&lt;/li&gt;
&lt;li&gt;the CCNP Security exams&lt;/li&gt;
&lt;/ul&gt;

&lt;blockquote&gt;
&lt;p&gt;Read the list. The numbers are not uniform. Microsoft Certified: Security Operations Analyst Associate appears at 38 CEUs, not 50. It is a qualifying certification that still leaves you 12 short.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  What gets rejected
&lt;/h2&gt;

&lt;p&gt;So what does CompTIA actually want to see? It is specific about proof, and specific in a way that catches people who did the work but lost the renewal on the evidence.&lt;/p&gt;

&lt;p&gt;For a certification, submit the certificate or the badge link issued by the certifying body. It has to show your name and the exact name of the certification. The date goes on there too. Training completion certificates, score reports, and emails are not valid submissions for that activity.&lt;/p&gt;

&lt;p&gt;For a webinar or a conference session, you need an outline of the content, plus either a completion certificate or the registration email. Your name and the session name have to appear on it, along with the date and the hours. On-demand webinars and YouTube videos count only if you can show proof of registration or completion, which is not something most YouTube watching produces.&lt;/p&gt;

&lt;h2&gt;
  
  
  The SY0-701 wrinkle
&lt;/h2&gt;

&lt;p&gt;One date changes the arithmetic here. It matters most for anyone certified recently. The English SY0-701 exam retires on June 11, 2027. If your three-year window closes after that, the route of passing the newest version means sitting a different exam from the one you passed, against a different set of exam objectives. Nobody needs to panic about that. It is worth deciding early rather than in the last month, because a retake you planned for is a study project and a retake you didn't is a scramble.&lt;/p&gt;

&lt;p&gt;Whichever route you pick, the CE fee applies unless the course price already covers it, and the submission has to be approved before your expiration date rather than on it. Three years feels very long right up until the final quarter of it.&lt;/p&gt;

&lt;p&gt;If the exam route is the one you are heading for, the format is worth re-meeting early. Try a &lt;a href="https://secplusmastery.com/r/ch-devto" rel="noopener noreferrer"&gt;free performance-based question&lt;/a&gt; before you commit to a date.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>A Practice Exam Score Is Not a Security+ Prediction</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Wed, 16 Sep 2026 09:50:13 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/a-practice-exam-score-is-not-a-security-prediction-28n4</link>
      <guid>https://dev.to/tiltedlunar123/a-practice-exam-score-is-not-a-security-prediction-28n4</guid>
      <description>&lt;p&gt;Every study group has a simple rule: get 85 percent on your practice exams and you'll pass. Some say 90. Others suggest you'll be fine if you score in the 70s or 80s on one vendor's tests. Where does that number come from?&lt;/p&gt;

&lt;p&gt;In August, I took SY0-701 and relied on practice exams, so this isn't against them. The problem is, that rule can't do the job people think it can. The gap between what people think it measures and what it really does measure is where many first-time failures come from.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two kinds of numbers
&lt;/h2&gt;

&lt;p&gt;A practice test gives you a percentage: 68 out of 80 correct, so 85 percent.&lt;/p&gt;

&lt;p&gt;Your Security+ score arrives in a different currency altogether. It's a scaled score, 750 on a scale from 100 to 900, and the lowest score on that scale is well above zero. You can't convert between the two in either direction, because nobody outside CompTIA holds the conversion and there is no fixed one to hold.&lt;/p&gt;

&lt;p&gt;When someone tells you 85 percent means you're ready, they're not giving you a measurement, they're giving you a personal correlation with a sample size of one person.&lt;/p&gt;

&lt;h2&gt;
  
  
  Whose questions were they?
&lt;/h2&gt;

&lt;p&gt;Under that, there's a harder problem. A practice test scores you against a particular set of questions, so what it really shows is how you did on that set.&lt;/p&gt;

&lt;p&gt;Two vendors covering the same objectives can be very different in difficulty, and neither of them is calibrated against the thing you are actually going to sit. One might write items with a clear right answer and three distractors, while another might make you choose between two defensible answers based on a scenario. Score 85 on the first and 65 on the second, and you've found something about the vendors, not yourself.&lt;/p&gt;

&lt;p&gt;The exam has its own difficulty level, set by a process none of those authors are part of.&lt;/p&gt;

&lt;h2&gt;
  
  
  The number that improves for the wrong reason
&lt;/h2&gt;

&lt;p&gt;Here's the one that trips people up. You take a test and score 70. You study. You take it again and score 88, so 18 points better.&lt;/p&gt;

&lt;p&gt;Some of that improvement is real. Some is because you've seen the questions before. That part is not progress.&lt;/p&gt;

&lt;p&gt;Recognizing a question you've seen before is a different skill from working out an answer you have never encountered anywhere, and the exam only ever tests the second of those. A rising score on something you keep retaking is partly about remembering the questions. Each pass shifts more of the score into recall and less into actual competence.&lt;/p&gt;

&lt;p&gt;For the score to matter, the material has to be new every time.&lt;/p&gt;

&lt;h2&gt;
  
  
  The thing most tests leave out
&lt;/h2&gt;

&lt;p&gt;Nearly all practice tests are multiple choice. SY0-701 mixes multiple choice with &lt;a href="https://secplusmastery.com/r/ch-devto" rel="noopener noreferrer"&gt;performance-based questions&lt;/a&gt;, and those are tasks. You're given an interface and asked to do something in it. Drilling with four-option questions doesn't train for that, which is why so many say the multiple choice was fine but the simulations weren't. Ask yourself which half you drilled. Where your preparation is a stack of practice tests, the skill you have drilled least is the one most likely to cost you time on the day.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the score is good for
&lt;/h2&gt;

&lt;p&gt;Practice tests aren't a waste. They're still one of the better things to spend money on. They're a diagnostic tool rather than a crystal ball. Three jobs, all of them useful.&lt;/p&gt;

&lt;p&gt;The per-objective breakdown is the real prize, because a result telling you cryptography is sitting at 50 percent stays useful no matter what the overall score said, and unlike the headline number it points at something you can go and repair.&lt;/p&gt;

&lt;p&gt;Timing is the one people often ignore. If you can't finish a set within the time you gave yourself, you've surfaced a problem that will still be there on exam day, long after the score is forgotten.&lt;/p&gt;

&lt;p&gt;Question shape is the quiet one. Getting comfortable with scenarios where two answers both seem right is real preparation, and it's the main argument for doing practice questions.&lt;/p&gt;

&lt;h2&gt;
  
  
  A better readiness test
&lt;/h2&gt;

&lt;p&gt;Want to replace 85 percent and I'm ready? Try this.&lt;/p&gt;

&lt;p&gt;Download CompTIA's exam objectives from the Security+ page behind an email form, not a payment. Work through them line by line, saying out loud what each one means and where you would actually use it, before you let yourself look anything up or check a single answer.&lt;/p&gt;

&lt;p&gt;The lines where you stall are your study list. That test has no scaling, no vendor difficulty, and no seen-question problem because you're not being scored against someone else's writing. You're checking if you can explain the concepts.&lt;/p&gt;

&lt;p&gt;When the stalls end, book it.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>A scheduled delete is a different program from the one you watch</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Tue, 15 Sep 2026 09:43:41 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/a-scheduled-delete-is-a-different-program-from-the-one-you-watch-3nbn</link>
      <guid>https://dev.to/tiltedlunar123/a-scheduled-delete-is-a-different-program-from-the-one-you-watch-3nbn</guid>
      <description>&lt;p&gt;A cleanup you watch is a different program from a cleanup on a schedule. Same query. Same mailbox. What changes is that nobody is there when the second one runs.&lt;/p&gt;

&lt;p&gt;I added scheduled runs to my Gmail cleaner. Most of that work turned out to have nothing to do with deleting mail.&lt;/p&gt;

&lt;h2&gt;
  
  
  Somebody was catching your bad matches and you never noticed
&lt;/h2&gt;

&lt;p&gt;Run a bulk delete by hand and you watch the count land. Two thousand four hundred, fine. Nineteen thousand, and your hand comes off the mouse before you finish reading the number.&lt;/p&gt;

&lt;p&gt;That pause is a safety control. Nobody wrote it down. It is not in the code anywhere, and it vanishes the moment a run happens at 4am on a Tuesday while the one person who would have flinched at that number is asleep.&lt;/p&gt;

&lt;p&gt;So the first question for a scheduled job is not how to schedule it, it is what the job should do when a result looks wrong. Remember what "looks wrong" used to mean. A human squinting at a number.&lt;/p&gt;

&lt;p&gt;So what replaces the squint?&lt;/p&gt;

&lt;h2&gt;
  
  
  Daily does not mean daily
&lt;/h2&gt;

&lt;p&gt;Browser extensions get no cron daemon. An alarm fires while the browser is running, so your daily job really runs the next time somebody opens Chrome. Work Monday to Friday, shut the laptop on Saturday, and your daily job runs five times a week.&lt;/p&gt;

&lt;p&gt;Now the interesting part. Three runs were missed. Does the job catch up?&lt;/p&gt;

&lt;p&gt;Say it does. A rule that quietly matches a few hundred messages a day now fires against three days at once, and the run that stayed small every time anyone watched it becomes the biggest this mailbox has seen. Say it does not. The mailbox drifts and the tool looks broken.&lt;/p&gt;

&lt;p&gt;Neither answer is free, and picking one is the actual design decision hiding inside a checkbox that says "run this daily". Skipping is the safer default, and it has to be visible, because silent skipping is how somebody ends up believing a cleanup ran all month when it never did.&lt;/p&gt;

&lt;h2&gt;
  
  
  A schedule turns the query into the whole product
&lt;/h2&gt;

&lt;p&gt;An interactive run repairs its own mistakes. You see 19,000, you narrow the filter, you go again. A bad first draft never survives.&lt;/p&gt;

&lt;p&gt;A scheduled run gets no second draft. The query you wrote on Sunday executes against a mailbox that keeps changing under it for months. Somebody subscribes to a newsletter matching your sender pattern. A vendor switches the From address on receipts you meant to keep. The rule did not change. Its blast radius did.&lt;/p&gt;

&lt;p&gt;Which rules survive that? Ones that state their exclusions rather than only their matches. An unattended rule is worth exactly what its exceptions are worth, and those exceptions belong inside the query instead of in the operator's head. At 4am there is no operator.&lt;/p&gt;

&lt;h2&gt;
  
  
  Cap the run, then tell somebody
&lt;/h2&gt;

&lt;p&gt;What makes an unattended delete survivable? Two things.&lt;/p&gt;

&lt;p&gt;First, a per-run ceiling, so a rule that suddenly matches ten times its usual volume hits the ceiling instead of the mailbox. You do not add a cap because you expect the spike, you add it because the entire premise of scheduling is that you are not watching.&lt;/p&gt;

&lt;p&gt;Second, a record you read afterwards: the query, the number of messages actually acted on rather than matched, the time it ran, whatever it skipped and why. A scheduled feature with no report is a rumour that your inbox is being cleaned.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I actually shipped
&lt;/h2&gt;

&lt;p&gt;The extension is Bulk Delete Gmail Emails, also called Gmail One-Click Cleaner: &lt;a href="https://chromewebstore.google.com/detail/bmcfpljakkpcbinhgiahncpcbhmihgpc" rel="noopener noreferrer"&gt;Chrome Web Store listing&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Per that listing it runs scheduled cleanups daily, weekly or monthly. A run can be live. It can also be a review pass, or a dry run that touches nothing.&lt;/p&gt;

&lt;p&gt;Those modes are doing the work described above. A dry run answers the "how wrong is this rule" question before the rule is ever trusted alone. Review keeps a person in the loop for the first few passes, which is where you find the exception you forgot about.&lt;/p&gt;

&lt;p&gt;There is a recovery log too, with one-click restore for roughly thirty days. That is the backstop for a run nobody watched, and it ticks along on the same clock Gmail's own Trash uses.&lt;/p&gt;

&lt;h2&gt;
  
  
  The limit, said plainly
&lt;/h2&gt;

&lt;p&gt;A recovery log is a thirty-day window rather than a backup. If a scheduled rule has been quietly eating something you wanted for five weeks, the log cannot help you. Neither can Gmail.&lt;/p&gt;

&lt;p&gt;Which is the argument for aiming a schedule only at mail you have already decided against. Promotional mail from senders you unsubscribed from months ago. Notifications out of a system you left. Categories where the worst case is a shrug.&lt;/p&gt;

&lt;p&gt;The exciting version of this feature is a rule that learns what you ignore and clears it for you. I did not build that one, and I am not going to. Unattended and clever make a bad pair when the failure mode is somebody's mail.&lt;/p&gt;

</description>
      <category>webdev</category>
      <category>productivity</category>
      <category>programming</category>
    </item>
    <item>
      <title>The Security+ PBQs Are a Time Problem First</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Sun, 13 Sep 2026 10:14:58 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/the-security-pbqs-are-a-time-problem-first-3o27</link>
      <guid>https://dev.to/tiltedlunar123/the-security-pbqs-are-a-time-problem-first-3o27</guid>
      <description>&lt;p&gt;Every SY0-701 story has the same shape. Someone walks in prepared, meets a performance-based question early, and then spends the rest of the exam behind the clock. The version I read this week ended in a pass. The line was still in it: ran out of time to re-review anything.&lt;/p&gt;

&lt;p&gt;The issue is arithmetic. The arithmetic is published.&lt;/p&gt;

&lt;h2&gt;
  
  
  The number CompTIA gives you
&lt;/h2&gt;

&lt;p&gt;CompTIA's own exam details page for Security+ says a maximum of 90 questions in 90 minutes, a mix of multiple choice and performance-based, passing at 750 on a scale that runs from 100 to 900.&lt;/p&gt;

&lt;p&gt;So, one minute per question. That is an average and not a budget. A performance-based question (PBQ) is a small piece of work with several steps, and one of those steps is reading an interface you may never have seen before.&lt;/p&gt;

&lt;p&gt;Meet one early and treat it like any other question, and six or seven minutes can go by without you noticing. Do that twice, and you have borrowed a quarter of an hour from questions that would have taken only twenty seconds each.&lt;/p&gt;

&lt;h2&gt;
  
  
  A question you never reached scores zero
&lt;/h2&gt;

&lt;p&gt;The scoring is scaled, so you cannot sit there working out how many you need. What you can do is notice that a question you never reached scores zero. So does one you skipped in a panic on the way past.&lt;/p&gt;

&lt;p&gt;That makes the decision very simple.&lt;/p&gt;

&lt;p&gt;The cheap marks go first.&lt;/p&gt;

&lt;h2&gt;
  
  
  Flag it and walk away
&lt;/h2&gt;

&lt;p&gt;Here is the habit worth building before exam day, because you will not invent it under pressure.&lt;/p&gt;

&lt;p&gt;When a PBQ appears, give it one read. Is the shape of the answer obvious? If not, flag it and move on. Work the multiple choice to the end of the exam, banking everything you are sure of. Then come back with two things you did not have on the first pass: the leftover minutes, and an exact count of how many tasks are waiting for them.&lt;/p&gt;

&lt;p&gt;Now you can spend. Ten minutes and one task waiting is a very different problem from ten minutes and three, and only that second pass tells you which one you are in.&lt;/p&gt;

&lt;h2&gt;
  
  
  Most of the delay is the interface
&lt;/h2&gt;

&lt;p&gt;What eats the clock is usually the interface. The dragging and the dropdowns. Working out where this particular question even wants you to click.&lt;/p&gt;

&lt;p&gt;That cost is avoidable, and free. PBQs come in a handful of recognizable shapes, and each one has a rhythm you can pick up in an afternoon at your own desk with nothing riding on it, which is a far better place to meet a new interface than a testing center with a countdown running in the corner of the screen.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Drag one list onto another&lt;/li&gt;
&lt;li&gt;Fill in a configuration&lt;/li&gt;
&lt;li&gt;Sort items into buckets&lt;/li&gt;
&lt;li&gt;Click the right spot on a diagram&lt;/li&gt;
&lt;li&gt;Put a sequence of steps in order&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Never done one? &lt;a href="https://secplusmastery.com/r/ch-devto" rel="noopener noreferrer"&gt;This free firewall PBQ&lt;/a&gt; takes a few minutes and needs no account. It is the same kind of task. Do it badly once at home, where it costs nothing. Full disclosure: I built that one.&lt;/p&gt;

&lt;h2&gt;
  
  
  The firewall task, since that is the one people dread
&lt;/h2&gt;

&lt;p&gt;The configuration PBQ has a reputation it mostly does not deserve, because the rules that decide it are short.&lt;/p&gt;

&lt;p&gt;A firewall rule list is read from the top down and the first matching rule wins. Nothing below a match gets consulted. That is it. Two things follow from that one sentence, and between them they account for most of what a configuration task is actually able to test you on.&lt;/p&gt;

&lt;p&gt;A specific rule has to sit above the general rule that would otherwise swallow it. Permit one host to a port, then deny the whole subnet to that port, and the host still gets through. Reverse the two lines and it does not.&lt;/p&gt;

&lt;p&gt;Anything you did not explicitly permit is denied at the bottom. So what are these tasks really checking? The order of the permits sitting above that line.&lt;/p&gt;

&lt;p&gt;After that it is ports, and the set that turns up is small.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;443 for HTTPS&lt;/li&gt;
&lt;li&gt;22 for SSH&lt;/li&gt;
&lt;li&gt;3389 for RDP&lt;/li&gt;
&lt;li&gt;53 for DNS&lt;/li&gt;
&lt;li&gt;445 for SMB&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;CompTIA's published exam objectives name the protocols that matter under each domain, which is a better list to work from than a printout of every port ever assigned.&lt;/p&gt;

&lt;h2&gt;
  
  
  The last ten minutes
&lt;/h2&gt;

&lt;p&gt;Decide now what you will do with the last ten minutes. Ten minutes is enough to finish one task properly, or to half-finish three.&lt;/p&gt;

&lt;p&gt;Take the flagged PBQ you understood best and complete it. Then the next one. An item you left untouched because you were busy being thorough somewhere else is the most expensive thing on the exam, and it is the one part of the score that is entirely under your control.&lt;/p&gt;

&lt;p&gt;None of this replaces knowing the material. It is what stops you from being unable to show the material you already know, which is a much more annoying way to fail.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>The Security+ Acronyms That Get Confused With Each Other</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Thu, 10 Sep 2026 09:48:36 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/the-security-acronyms-that-get-confused-with-each-other-58ib</link>
      <guid>https://dev.to/tiltedlunar123/the-security-acronyms-that-get-confused-with-each-other-58ib</guid>
      <description>&lt;p&gt;The acronym appendix at the back of the SY0-701 objectives lists more than three hundred entries. People often suggest memorizing it, and every study group has someone printing it out. That advice misreads what the exam does with acronyms.&lt;/p&gt;

&lt;p&gt;SY0-701 rarely tests what an acronym means. Instead, it gives you a short scenario and four options, two of which are acronyms from the same area, and asks which one fits the scenario. Knowing that RPO expands to recovery point objective doesn't help much on that question. Understanding that &lt;strong&gt;RPO measures lost data while RTO measures lost time&lt;/strong&gt; gets you the answer in about four seconds.&lt;/p&gt;

&lt;p&gt;So, the useful way to study is by cluster rather than alphabetically. A cluster is a small group of acronyms sitting close enough together that a question writer can build a believable wrong answer out of one of them. How many are there? Maybe fifteen in the whole exam. Here are five of the most common ones, with the objective each sits under, so you can read the source material.&lt;/p&gt;

&lt;h2&gt;
  
  
  The four recovery numbers
&lt;/h2&gt;

&lt;p&gt;Objective 5.2 covers all four under business impact analysis; RPO and RTO also appear in 3.4 with resilience and recovery. Two of them are business targets. The other two are post-event observations. That split is the whole cluster. Learn it and the four stop blurring.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;RPO looks backward.&lt;/strong&gt; How much data can you afford to lose? That makes it about backup frequency. &lt;strong&gt;RTO looks forward.&lt;/strong&gt; How long can you afford to be down? Which is a claim about recovery capability, not about backups. MTTR is the average repair time. MTBF is the time between failures.&lt;/p&gt;

&lt;p&gt;The stem usually gives it away. Read it twice. A sentence about hourly snapshots points at RPO, and one about a four-hour outage window points at RTO. If the sentence describes something that already happened rather than a business decision, you are in MTTR and MTBF territory.&lt;/p&gt;

&lt;h2&gt;
  
  
  Federation, and why one of these is not authentication
&lt;/h2&gt;

&lt;p&gt;Objective 4.6 puts SAML, OAuth and OIDC on one line with Kerberos, LDAP and RADIUS. The trap is that people learn the first three as single sign-on protocols and then mix them up under pressure. All three are very commonly confused.&lt;/p&gt;

&lt;p&gt;SAML and OIDC both carry identity. They answer who this person is. OAuth on its own does something else. It answers what an application is allowed to reach (authorization), and it was built to let an app touch your data without handing over your password. OIDC sits on top of OAuth 2.0 and adds the identity layer that OAuth left out.&lt;/p&gt;

&lt;p&gt;So, a stem describing a third-party app getting limited access to an account points at OAuth, even when the word login appears somewhere in the sentence. A browser redirected to a corporate identity provider, coming back with an assertion? SAML.&lt;/p&gt;

&lt;h2&gt;
  
  
  The agreement alphabet
&lt;/h2&gt;

&lt;p&gt;Objective 5.3 covers third-party risk, and this might be the least loved cluster; it feels like paperwork rather than security. It is also the one where every option in the question is a real document and only one of them fits the sentence you were given. Read the sentence, not the options.&lt;/p&gt;

&lt;p&gt;An &lt;strong&gt;SLA&lt;/strong&gt; carries numbers: uptime and response time, with a penalty for missing the number. An &lt;strong&gt;MOU&lt;/strong&gt; only records that two parties intend to work together, and it is generally not built to be enforced. An &lt;strong&gt;MSA&lt;/strong&gt; sets the terms of a long relationship, while the &lt;strong&gt;SOW&lt;/strong&gt; underneath it says what this particular job is and when it is due. An &lt;strong&gt;NDA&lt;/strong&gt; is about confidentiality and nothing else. A &lt;strong&gt;BPA&lt;/strong&gt; governs a partnership where both parties carry real risk if it goes wrong.&lt;/p&gt;

&lt;h2&gt;
  
  
  Severity is not priority
&lt;/h2&gt;

&lt;p&gt;CVSS, EPSS and KEV all sit in 4.3. CVSS rates how bad a vulnerability would be if exploited. EPSS estimates how likely exploitation is. KEV is a catalog of vulnerabilities already being exploited in the wild.&lt;/p&gt;

&lt;p&gt;Any question that gives you a patch queue and asks what to fix first checks whether you spotted that a severity score alone doesn't set the order. A high CVSS on something nobody is exploiting can wait. A medium that appears on the KEV list goes first.&lt;/p&gt;

&lt;h2&gt;
  
  
  Four ways to test code
&lt;/h2&gt;

&lt;p&gt;Also in 4.3. This is the cleanest cluster of the five. SAST reads source without running it. DAST attacks the running application and sees nothing of the source. IAST instruments the running application to see both. SCA ignores your code entirely and looks at what it depends on.&lt;/p&gt;

&lt;p&gt;The discriminator is almost always in the first clause of the stem. Third-party library with a known vulnerability? That is SCA. No source available means DAST, and a scan that runs before the build has been deployed anywhere is SAST.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to actually drill this
&lt;/h2&gt;

&lt;p&gt;Reviewing a cluster by reading it is the trap. That is the whole warning. A comparison table feels productive, and what it trains is recognition, an easier skill than the one being tested.&lt;/p&gt;

&lt;p&gt;The version that works is slower and more annoying. For each pair in a cluster, write one sentence that only one of the two can answer. Then cover the labels and read your own sentences back. If you wrote a sentence that both acronyms could satisfy, you found the exact gap the question writer is going to aim at, and you found it at your desk instead of in the testing center.&lt;/p&gt;

&lt;p&gt;A last word on that appendix. Treat it as a scope boundary; some entries appear only once, in one sub-bullet of one objective. The clusters are where the questions live, and the fastest way to find the rest is to read CompTIA's published exam objectives and look for lines where three or four related acronyms are grouped together. If you would rather practice this the way the exam asks it, there is a &lt;a href="https://secplusmastery.com/r/ch-devto" rel="noopener noreferrer"&gt;free performance-based question here&lt;/a&gt; that needs no account. Full disclosure: I built that one.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>Gmail's Trash gives back your emails, not your undo</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Tue, 08 Sep 2026 09:40:10 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/gmails-trash-gives-back-your-emails-not-your-undo-5ce6</link>
      <guid>https://dev.to/tiltedlunar123/gmails-trash-gives-back-your-emails-not-your-undo-5ce6</guid>
      <description>&lt;p&gt;Deleting mail in bulk is easy. You run a search and hit delete on what comes back, over and over; the whole loop is about forty lines of code.&lt;/p&gt;

&lt;p&gt;Undoing this operation turns out to be trickier, and I made a misstep initially because I thought Gmail's Trash folder was already my undo button.&lt;/p&gt;

&lt;p&gt;It isn't.&lt;/p&gt;

&lt;h2&gt;
  
  
  Trash gives back the emails, not the operation
&lt;/h2&gt;

&lt;p&gt;Trash just holds emails for 30 days. So technically nothing is lost, since the messages are still there waiting to be restored.&lt;/p&gt;

&lt;p&gt;The issue lies with what you're trying to restore. If you run a cleanup that touches four thousand conversations through twelve different searches, your Trash ends up holding all of them mixed in with whatever you deleted last Tuesday and the thread you dropped on purpose this morning. Nothing marks where one run ends and another begins.&lt;/p&gt;

&lt;p&gt;You can restore an email. Can you restore that run? No. And users usually want more than one message back; they want their last five minutes undone.&lt;/p&gt;

&lt;p&gt;That gap is the actual feature, because Gmail has no concept of the batch you just ran.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the log needs to record
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The exact search query used&lt;/li&gt;
&lt;li&gt;A list of ids actually acted on, not those matched&lt;/li&gt;
&lt;li&gt;A timestamp for when the run happened&lt;/li&gt;
&lt;li&gt;The point at which restoring stops working&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The third and fourth items might seem redundant, but they're crucial. The timestamp is when it happened; the expiry is when the promise runs out, and those two are only the same thing if you assume the retention window never changes.&lt;/p&gt;

&lt;p&gt;The distinction between "matched" and "acted on" matters because a run that dies mid-way results in different sets of matched and deleted emails. A log based solely on intent could offer to restore mail that wasn't removed, creating confusion or worse, teaching users the undo button is unreliable.&lt;/p&gt;

&lt;h2&gt;
  
  
  It has to live on the machine
&lt;/h2&gt;

&lt;p&gt;The extension makes no network calls; it's a deliberate design choice, and it means there is no server-side place to keep a log. The data is stored locally in browser storage, which comes with its own challenges.&lt;/p&gt;

&lt;p&gt;The first limit is size. Storing ids for tens of thousands of messages across multiple runs isn't free, and there is no point keeping an entry past the window where it can still do something.&lt;/p&gt;

&lt;p&gt;The second one bit me. &lt;code&gt;chrome.storage.local.set&lt;/code&gt; replaces the value at a key instead of merging into it, so writing the log for run two silently loses run one. Testing never caught it, because you almost always test the most recent action and that one is always correct. I found it while checking something else entirely.&lt;/p&gt;

&lt;p&gt;So the write path has to read the key first and merge into it. Obvious, once you have lost data that way.&lt;/p&gt;

&lt;h2&gt;
  
  
  Expiry has to be visible
&lt;/h2&gt;

&lt;p&gt;An undo entry outside the retention window is worse than no entry at all; it advertises a capability that won't work at the exact moment somebody needs it. So the log shows when each entry stops working, and anything past that point comes off the list.&lt;/p&gt;

&lt;p&gt;It reads like a small detail next to the deletion engine. It is the difference between a guarantee and a suggestion.&lt;/p&gt;

&lt;h2&gt;
  
  
  The cheaper half is not deleting
&lt;/h2&gt;

&lt;p&gt;All of this is about recovery. The better move is not needing it.&lt;/p&gt;

&lt;p&gt;Dry runs are the key here: same query, same counts, nothing actually deleted. Most of the value of an undo system is captured by showing someone the number before they commit to it. The classic disaster isn't deleting the right things and changing your mind; it's thinking a search meant something else.&lt;/p&gt;

&lt;p&gt;The same logic applies to protecting starred and important mail automatically. That protection belongs inside the query you count with, not applied as a filter after fetching results. If you exclude items after fetching, the number shown to the user came from a different set than the one the delete call sees, and any retry path can quietly act on the wrong list. The count and the action have to be reading the same thing.&lt;/p&gt;

&lt;h2&gt;
  
  
  The limit, stated plainly
&lt;/h2&gt;

&lt;p&gt;None of this is a backup. Once Gmail's window closes, a recovery log is just a list of ids for mail that no longer exists. It's a 30 day guarantee, and it should be described as exactly that rather than dressed up as safety.&lt;/p&gt;

&lt;p&gt;If you want the tool, it's &lt;a href="https://chromewebstore.google.com/detail/bmcfpljakkpcbinhgiahncpcbhmihgpc" rel="noopener noreferrer"&gt;Gmail One-Click Cleaner&lt;/a&gt; on the Chrome Web Store. It runs locally and its source is on GitHub; bulk cleanup is free.&lt;/p&gt;

&lt;p&gt;The engine took a weekend. The undo took considerably longer, and it's the part I would keep.&lt;/p&gt;

</description>
      <category>productivity</category>
      <category>webdev</category>
      <category>javascript</category>
    </item>
    <item>
      <title>Shadow IT is on the Security+ threat actor list, and there is no attacker in it</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Mon, 07 Sep 2026 09:43:33 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/shadow-it-is-on-the-security-threat-actor-list-and-there-is-no-attacker-in-it-2000</link>
      <guid>https://dev.to/tiltedlunar123/shadow-it-is-on-the-security-threat-actor-list-and-there-is-no-attacker-in-it-2000</guid>
      <description>&lt;p&gt;Shadow IT sits on the Security+ threat actor list, right there next to nation-states and organized crime. There is no attacker in it. Nobody is breaking in. It is the finance team paying for a file sharing tool on a company card because the approved one takes four days to grant access.&lt;/p&gt;

&lt;p&gt;That placement confused me for a while. Once it clicked, a whole category of exam questions got easier, so it is worth explaining.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the objectives actually name
&lt;/h2&gt;

&lt;p&gt;Pull up CompTIA's Security+ page and read objective 2.1. The threat actors it lists are nation-states, unskilled attackers, hacktivists, insider threats, organized crime, and shadow IT. Motivations get named separately, things like data exfiltration, espionage and financial gain among others.&lt;/p&gt;

&lt;p&gt;Two lists. Most people skim straight past that. The exam treats the actor and the motive as separate axes, and most of the questions that feel unfair are questions where you read one and answered the other.&lt;/p&gt;

&lt;h2&gt;
  
  
  The list is sorted by capability, not by villainy
&lt;/h2&gt;

&lt;p&gt;Shadow IT belongs there because the list sorts threats by what they can do to you and how much warning you get, which is a very different job from ranking them by how villainous they are.&lt;/p&gt;

&lt;p&gt;Ask three things about whoever is in the scenario.&lt;/p&gt;

&lt;p&gt;How much money and time do they have? A nation-state has effectively unlimited resources and can wait a year. Organized crime is well funded and impatient, because it needs a return. An unskilled attacker has neither.&lt;/p&gt;

&lt;p&gt;How capable are they? This is not the same question. Resources buy tools; sophistication is whether they can build something new. A nation-state writes its own malware and burns a zero day when it needs to. Somebody unskilled is running a tool that another person wrote, and does not necessarily know what it does.&lt;/p&gt;

&lt;p&gt;Are they inside or outside? Inside changes everything, because internal actors skip the whole first phase. They already have a badge, an account, and a reason to be there.&lt;/p&gt;

&lt;p&gt;Run shadow IT through those three and it makes sense. Internal, no hostile intent, minimal sophistication, and yet there is real exposure sitting behind it: company data in a service nobody vetted, and no logging that your team can reach. A security team cannot protect infrastructure it does not know exists. So the slot is earned on capability grounds rather than on intent.&lt;/p&gt;

&lt;h2&gt;
  
  
  The stem usually hands you the motive
&lt;/h2&gt;

&lt;p&gt;Here is the pattern worth internalizing. Exam questions rarely say "a hacktivist did this." They describe what happened and what the attacker seemed to want, and you work backwards.&lt;/p&gt;

&lt;p&gt;Data quietly copied out over months with no ransom demand and no disruption? Long dwell time and no money motive points at espionage, and espionage points at whoever can afford to be patient. Systems encrypted with a payment demand? That is financial gain, and that is organized crime. A public defacement timed to a news story, where the attacker wants you to know? That is philosophical or political, and it is the loudest actor on the list. Nobody quiet does that.&lt;/p&gt;

&lt;p&gt;So the useful question is what this person wanted, and who tends to want that, rather than which of four labels you happen to recognize.&lt;/p&gt;

&lt;p&gt;There is a corollary that matters just as much. Two actors can run the exact same technique. Phishing is evidence of nobody in particular, because everyone phishes. What separates them is who got targeted and what happened after the attacker got in.&lt;/p&gt;

&lt;h2&gt;
  
  
  One wording check before you trust your notes
&lt;/h2&gt;

&lt;p&gt;The current objectives say unskilled attacker. Plenty of study material still says script kiddie.&lt;/p&gt;

&lt;p&gt;On its own that is harmless, and the terms mean the same thing. It is worth noticing anyway, because it dates the material you are holding. If the wording lines up with an older version of the exam, check the rest of it before you rely on it, since SY0-701 has been the live version since November 2023 and CompTIA now prints a retirement date of June 11 2027 for the English exam.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where reading stops helping
&lt;/h2&gt;

&lt;p&gt;You can learn all of this from an article, mine included. What none of it prepares you for is the format that gives people the most trouble on the day.&lt;/p&gt;

&lt;p&gt;The performance-based questions are not written like this. They drop you into a task and expect you to produce something from a blank state, so you are ordering a rule set or walking a log until the answer falls out. Recognizing a threat actor from a paragraph is a very different skill from operating an interface under time pressure, and studying the first one harder does not do much for the second.&lt;/p&gt;

&lt;p&gt;That is the gap I kept hitting, and it is why I ended up building &lt;a href="https://secplusmastery.com/r/ch-devto" rel="noopener noreferrer"&gt;a firewall PBQ you can just do&lt;/a&gt;, free and without an account, so people can find out how the format feels before exam day rather than during it. Full disclosure, that one is mine.&lt;/p&gt;

&lt;p&gt;For the reading side, Professor Messer's SY0-701 series is free and covers the whole blueprint. Jason Dion's practice exams are the usual next step when you want to be tested rather than taught. And the objectives PDF is free from CompTIA and is the only real checklist, since every question traces back to a numbered line in it.&lt;/p&gt;

&lt;p&gt;Threat actors are cheap points once you stop memorizing six labels and start asking what the person wanted and what they could afford. Two questions. They resolve most of the domain.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>CompTIA replaced the Security+ retirement estimate with a date, and it is June 11 2027</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Sat, 05 Sep 2026 17:01:46 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/comptia-replaced-the-security-retirement-estimate-with-a-date-and-it-is-june-11-2027-2ic0</link>
      <guid>https://dev.to/tiltedlunar123/comptia-replaced-the-security-retirement-estimate-with-a-date-and-it-is-june-11-2027-2ic0</guid>
      <description>&lt;p&gt;Every CompTIA exam page carries a line called Retirement, sitting in the Exam details block under the launch date and the question count. For most exams it reads the same way: "usually three years after launch," followed by an estimated year in brackets. It is a planning figure, not a promise, and CompTIA says so in the wording.&lt;/p&gt;

&lt;p&gt;Security+ does not say that any more.&lt;/p&gt;

&lt;p&gt;The SY0-701 page now reads: &lt;strong&gt;Retirement: English - June 11, 2027; Japanese, Portuguese, Spanish, and Thai - August 13, 2027.&lt;/strong&gt; No "usually," no "estimated," no brackets. A date.&lt;/p&gt;

&lt;p&gt;That is a small edit to one line on one page, and it is worth more than it looks.&lt;/p&gt;

&lt;h2&gt;
  
  
  Estimate versus date
&lt;/h2&gt;

&lt;p&gt;The old wording put SY0-701's estimated retirement at 2026, which is this year. If you read that in the spring you would reasonably have concluded the exam was about to disappear and either rushed a booking or quietly decided it was not worth starting. Neither reaction was warranted, because an estimate derived from "three years after a November 2023 launch" is arithmetic, not scheduling.&lt;/p&gt;

&lt;p&gt;The published date is a different kind of object. You can put it in a calendar. You can build a study plan backwards from it. You can tell a manager who is deciding whether to fund a voucher next quarter exactly how long the current version is good for.&lt;/p&gt;

&lt;p&gt;For comparison, as of today the other two exams in the same family have not changed:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Network+ N10-009&lt;/strong&gt;, launched June 20 2024, still reads "usually three years after launch (estimated 2027)."&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A+ V15&lt;/strong&gt;, series 220-1201 and 220-1202, Core 1 launched March 25 2025, still reads estimated 2028.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;So Security+ is currently the only one of the three you can plan against precisely. If you are sequencing certifications, that is genuinely useful: the one with the firm date is the one whose window you can treat as real.&lt;/p&gt;

&lt;h2&gt;
  
  
  The retirement line is about the exam, not about you
&lt;/h2&gt;

&lt;p&gt;This trips people up constantly, and the wording invites it.&lt;/p&gt;

&lt;p&gt;A retirement date applies to the exam version. It says when you can stop being able to sit SY0-701. It says nothing about a certification you already hold. If you pass SY0-701 tomorrow, you hold Security+ for three years from your pass date, and a new version launching in 2027 does not shorten that by a day. Your renewal clock and the exam's retirement clock are unrelated objects that happen to be measured in the same units.&lt;/p&gt;

&lt;p&gt;The practical version: passing early does not cost you anything, and waiting does not buy you anything except a longer wait.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to actually do with this
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Check what version your material is written for.&lt;/strong&gt; SY0-601 retired a while ago and its content is still in circulation, sold in bundles and posted in study groups, because nothing forces a seller to take it down. The two versions overlap enough to look interchangeable and diverge in the places that decide marks. If a course, a question bank or a PDF does not say 701 somewhere visible, assume it is not.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Do not confuse the retirement date with the last day to book.&lt;/strong&gt; The outgoing version normally stays bookable for a period after its replacement appears, and CompTIA has published a date rather than a countdown. Treat June 11 2027 as the outside edge of the window, not as a deadline you are racing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Plan against the objectives, not the calendar.&lt;/strong&gt; The exam is a maximum of 90 questions in 90 minutes, the passing score is 750 on a scale that runs from 100 to 900, and the five domains are weighted General security concepts 12%, Threats vulnerabilities and mitigations 22%, Security architecture 18%, Security operations 28%, Security program management and oversight 20%. Security operations is more than a quarter of the exam on its own. If you are short on time, that is where the time goes, and no retirement date changes that arithmetic.&lt;/p&gt;

&lt;h2&gt;
  
  
  The part the date does not help with
&lt;/h2&gt;

&lt;p&gt;Knowing when the exam retires tells you nothing about the thing most people actually lose marks on, which is the performance-based questions.&lt;/p&gt;

&lt;p&gt;They sit near the front, they are slower per mark than anything else on the paper, and they ask you to produce rather than recognise. Multiple choice hands you four options and lets recognition do the work. A PBQ hands you an empty firewall table or a set of tiles with nothing to compare against, and recognition has nothing to grab. That gap does not close by rereading, and it does not close by watching video.&lt;/p&gt;

&lt;p&gt;Professor Messer's SY0-701 series is free and good on the concepts, and Jason Dion's practice exams will find your weak spots. Neither gives you many real simulations, which is the honest gap in the free material. I built one that runs in a browser with no account, for exactly this: &lt;a href="https://secplusmastery.com/r/ch-devto" rel="noopener noreferrer"&gt;a firewall PBQ you can just do&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Full disclosure, that site is mine. I sat SY0-701 on August 22 this year and passed, studying on it. Because of that, both plans are 50% off with the code PASSED50 through September 6.&lt;/p&gt;

&lt;p&gt;All of the exam facts above come from the CompTIA exam pages themselves, which is where I would check again before planning anything on them. Pages move, and this one just did.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>career</category>
      <category>learning</category>
    </item>
    <item>
      <title>Your Gmail cleanup tool found nothing because your mailbox is the wrong shape</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Fri, 04 Sep 2026 09:29:46 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/your-gmail-cleanup-tool-found-nothing-because-your-mailbox-is-the-wrong-shape-27dn</link>
      <guid>https://dev.to/tiltedlunar123/your-gmail-cleanup-tool-found-nothing-because-your-mailbox-is-the-wrong-shape-27dn</guid>
      <description>&lt;p&gt;Most inbox cleanup tools ship with the same three searches: promotions, big attachments, anything older than a year. Run one against a mailbox holding 60,000 messages and you can still get a report that says 142 promotional emails and four large attachments. Nothing is broken. The tool asked three questions your mailbox does not answer.&lt;/p&gt;

&lt;p&gt;I ran into this building a Gmail cleanup extension, and it took me an embarrassingly long time to see it as a design problem instead of a bug.&lt;/p&gt;

&lt;h2&gt;
  
  
  Category searches get written before anyone sees your mail
&lt;/h2&gt;

&lt;p&gt;&lt;code&gt;category:promotions&lt;/code&gt;, &lt;code&gt;larger:10M&lt;/code&gt;, &lt;code&gt;older_than:1y&lt;/code&gt;. Those are guesses about what clutter looks like, made by someone who has never seen your inbox. They are good guesses for one kind of mailbox: shopper, newsletter reader, ten years of Black Friday mail.&lt;/p&gt;

&lt;p&gt;Plenty of mailboxes are not that. A working mailbox is often tens of thousands of small, ordinary, individually reasonable messages from a few dozen automated senders. Build notifications. Ticket updates. Bank alerts. Delivery notices. School portals. None of it is promotional, none of it is large, and a lot of it arrived last month, so it fails all three searches at once.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;category:promotions&lt;/code&gt; has a second problem stacked on top. The Promotions tab is a classifier's opinion, not a property of the message. Gmail decides. Anything it decides wrong is invisible to a rule built on that category, and you never notice the miss, because a miss looks exactly like a clean mailbox.&lt;/p&gt;

&lt;h2&gt;
  
  
  Enumerate senders instead
&lt;/h2&gt;

&lt;p&gt;The question that works on every mailbox shape is not "what category is this" but "who keeps sending me things".&lt;/p&gt;

&lt;p&gt;Sender lists survive the shape problem because they assume nothing. A mailbox of 40,000 build notifications and a mailbox of 40,000 retail promos both reduce to a short list of names, and the list is shorter than people expect. Most mailboxes are dominated by a few dozen senders. You can hold that list in your head. You cannot hold 40,000 messages in your head, which is most of why the pile feels unmanageable.&lt;/p&gt;

&lt;p&gt;Doing it by hand in Gmail:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Sample. Open a few searches that cut across your mail in different directions rather than by category: &lt;code&gt;older_than:2y&lt;/code&gt;, &lt;code&gt;is:unread&lt;/code&gt;, &lt;code&gt;after:2026/01/01&lt;/code&gt;. Read the sender column, not the subjects.&lt;/li&gt;
&lt;li&gt;Count each name that keeps coming up: &lt;code&gt;from:notifications@example.com&lt;/code&gt;. Gmail gives you the real total for that search.&lt;/li&gt;
&lt;li&gt;Sort your list by that number and work top down.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Step 2 is the one that matters and the one tools get wrong. A page of Gmail results is 50 rows. If something counts what it can see on the page, it is reporting a page, not a mailbox. The number has to come from Gmail's own answer to the &lt;code&gt;from:&lt;/code&gt; search.&lt;/p&gt;

&lt;h2&gt;
  
  
  The trap on the way out
&lt;/h2&gt;

&lt;p&gt;Once you have a ranked list you will want to act on it, and this is where a count quietly stops meaning what you think it means.&lt;/p&gt;

&lt;p&gt;Say a row says 4,812 from one sender. You have also, sensibly, told your tool never to touch anything starred, or anything with "invoice" in it. So the run deletes 4,390 and you spend ten minutes wondering where the other 422 went.&lt;/p&gt;

&lt;p&gt;Nothing went wrong. The count and the button were measured through different filters. If a row shows you a number, that number has to be measured through the same filters the button applies, or it is describing a mailbox you are not about to modify. The same rule holds by hand: put your exclusions in the search you count with, not only in the delete you run afterwards. &lt;code&gt;from:x -is:starred -invoice&lt;/code&gt; is the honest count.&lt;/p&gt;

&lt;h2&gt;
  
  
  Two things worth keeping
&lt;/h2&gt;

&lt;p&gt;Deleting is not the end of it. A sender that filled your mailbox once will do it again, so whatever you decide about a sender wants to keep applying rather than being a one-off sweep.&lt;/p&gt;

&lt;p&gt;And check &lt;code&gt;in:spam from:&lt;/code&gt; separately when you audit a sender. Mail that Gmail routed to Spam does not appear in an ordinary &lt;code&gt;from:&lt;/code&gt; search at all, so a sender can look like they stopped when they only moved. Be careful what you delete in there, too. Spam has no 30 day Trash window.&lt;/p&gt;

&lt;p&gt;I built the sampling and the per-sender counting into the extension because doing it by hand across a few dozen senders is tedious and easy to get wrong. The census and the counts are free and read only. Clearing the senders you tick is the paid part, and it only ever touches senders you ticked yourself. Full disclosure, it is mine: &lt;a href="https://chromewebstore.google.com/detail/bmcfpljakkpcbinhgiahncpcbhmihgpc" rel="noopener noreferrer"&gt;https://chromewebstore.google.com/detail/bmcfpljakkpcbinhgiahncpcbhmihgpc&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The by-hand version above works fine without any of that, and it is the part worth taking away either way.&lt;/p&gt;

</description>
      <category>productivity</category>
      <category>opensource</category>
      <category>privacy</category>
      <category>webdev</category>
    </item>
  </channel>
</rss>
