<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: TiltedLunar123</title>
    <description>The latest articles on DEV Community by TiltedLunar123 (@tiltedlunar123).</description>
    <link>https://dev.to/tiltedlunar123</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3847611%2F5372ff69-df32-4335-9ef6-65d8c9504ae5.jpeg</url>
      <title>DEV Community: TiltedLunar123</title>
      <link>https://dev.to/tiltedlunar123</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/tiltedlunar123"/>
    <language>en</language>
    <item>
      <title>Your Gmail is not full. Your Google Account is.</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Sat, 01 Aug 2026 16:13:10 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/your-gmail-is-not-full-your-google-account-is-1k7c</link>
      <guid>https://dev.to/tiltedlunar123/your-gmail-is-not-full-your-google-account-is-1k7c</guid>
      <description>&lt;p&gt;Gmail puts up the banner and tells you storage is full, then offers you a monthly plan. So you open the inbox and start deleting things. Two hours later the number has barely moved.&lt;/p&gt;

&lt;p&gt;So where did the space actually go? Here is the thing nobody tells you. The quota was never a Gmail quota.&lt;/p&gt;

&lt;p&gt;A free Google Account comes with up to 15 GB, and that 15 GB is shared across Gmail, Google Drive, and Google Photos. One pool, three products drinking from it. Gmail is just the one that complains loudest. Plenty of people spend an afternoon clearing email when the actual weight is a phone that has been backing up original quality video to Photos since 2019.&lt;/p&gt;

&lt;h2&gt;
  
  
  Check the split before you delete anything
&lt;/h2&gt;

&lt;p&gt;The Google One storage manager gives you the breakdown by product. Open that first. Which of the three is the big number? That answer takes ten seconds and decides what you work on.&lt;/p&gt;

&lt;p&gt;If Photos is the big number, no amount of email deletion is going to matter. If Drive is the big number, same. Only if Gmail is genuinely the largest slice does an inbox cleanup make sense as the first move.&lt;/p&gt;

&lt;h2&gt;
  
  
  The things that count that people do not expect
&lt;/h2&gt;

&lt;p&gt;This is where the surprises live, and they explain most of the "I deleted everything and nothing happened" stories.&lt;/p&gt;

&lt;p&gt;Spam and Trash still count. Both of them. Deleting a message moves it to Trash, and it keeps occupying your quota until it is permanently cleared. Gmail empties Trash on its own eventually. So people delete 8,000 emails and watch the storage number sit completely still, then decide the cleanup did not work. It worked. It is queued.&lt;/p&gt;

&lt;p&gt;Your Docs and Sheets count now. Files created or edited in the collaborative apps started counting toward quota after June 1, 2021. That includes Slides and Forms as well. Anything older than that got grandfathered. So a Drive full of spreadsheets is not automatically free space.&lt;/p&gt;

&lt;p&gt;Photos changed on the same date. High quality and Storage saver uploads made before June 1, 2021 do not count against you, while everything backed up in those formats after that date does, which is why a phone set up years ago behaves differently from one set up last spring. Original quality has always counted. Always.&lt;/p&gt;

&lt;p&gt;Backups count. Android device backups land in the same pool. So do WhatsApp backups and Meet recordings, and none of those show up anywhere you would normally think to look.&lt;/p&gt;

&lt;p&gt;Shared files do not count against you. A file in a folder somebody shared with you counts against the owner instead. Good news. It also means the team drive stuffed with somebody else's video files is not your problem to solve, however alarming it looks while you are hunting through Drive for the missing gigabytes.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happens if you ignore it
&lt;/h2&gt;

&lt;p&gt;Worth knowing, because the failure mode is worse than most people assume. What actually breaks? Hitting the limit does not just stop you sending mail. You stop receiving it too. Drive uploads fail and Photos quietly stops backing anything up. Mail sent to you while you are over quota can bounce. You will not know what you missed.&lt;/p&gt;

&lt;p&gt;Google also states that being over quota for two years may result in content getting deleted across all three products. That is a long fuse, though a real one.&lt;/p&gt;

&lt;h2&gt;
  
  
  If Gmail really is the problem
&lt;/h2&gt;

&lt;p&gt;Then the useful question is which senders, not which emails. Which ten addresses own your quota? Storage is concentrated. A handful of senders with attachments. Newsletters carrying heavy images. Some automated report that has been arriving daily for four years. That is most of your gigabytes right there.&lt;/p&gt;

&lt;p&gt;Gmail can get you partway with search. Try larger:10M for the worst offenders, then has:attachment older_than:2y for the long tail. One trap here. Ticking the checkbox at the top only selects the current page, so you also have to click the "select all conversations that match this search" line that appears above the list. Miss it and you are deleting fifty at a time, wondering why this is taking all night.&lt;/p&gt;

&lt;p&gt;For the by-sender view, Gmail has no native equivalent, which is the gap I built a Chrome extension to fill. Its storage scan ranks your senders by how much space they use, so you see the top ten instead of guessing. Full disclosure, that one is mine: &lt;a href="https://chromewebstore.google.com/detail/bulk-delete-gmail-emails/bmcfpljakkpcbinhgiahncpcbhmihgpc" rel="noopener noreferrer"&gt;Gmail One-Click Cleaner&lt;/a&gt;. It is open source, and the search-operator route above costs nothing if you would rather do this by hand.&lt;/p&gt;

&lt;p&gt;Whichever way you go, the order matters more than the tooling. Look at the split first. Pick whichever product is actually heavy. Empty the Trash when you are finished, and stop paying for storage you were never really using.&lt;/p&gt;

</description>
      <category>gmail</category>
      <category>productivity</category>
      <category>email</category>
      <category>webdev</category>
    </item>
    <item>
      <title>Adding a second server is not an answer to a Security+ resilience question</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Sat, 01 Aug 2026 16:03:06 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/adding-a-second-server-is-not-an-answer-to-a-security-resilience-question-boa</link>
      <guid>https://dev.to/tiltedlunar123/adding-a-second-server-is-not-an-answer-to-a-security-resilience-question-boa</guid>
      <description>&lt;p&gt;Objective 3.4 looks like the easiest thing in Domain 3. Hot sites and cold sites. Load balancing. Clustering. Backups. Most people skim that list, decide it is vocabulary, and go spend the evening on cryptography instead.&lt;/p&gt;

&lt;p&gt;Then a scenario shows up about a data center that just went dark, with four answer options that are all genuine resilience controls, and the vocabulary does nothing for you. The question was never asking what the words mean.&lt;/p&gt;

&lt;p&gt;Domain 3 is 18 percent of SY0-701 and resilience is a real slice of it. What follows is the part that turns the objective from a memorization list into something you can reason through on the day.&lt;/p&gt;

&lt;h2&gt;
  
  
  Sort by what the control does to a failure
&lt;/h2&gt;

&lt;p&gt;Every term in 3.4 answers one of three questions.&lt;/p&gt;

&lt;p&gt;Does this keep me running while something breaks? High availability lives here. So do load balancing and clustering. Platform diversity and multi-cloud belong in the same pile.&lt;/p&gt;

&lt;p&gt;Will it get me back after I am already down? Recovery sites and geographic dispersion. Backups too.&lt;/p&gt;

&lt;p&gt;Can I keep serving people while I am still down? That is continuity of operations, and it is the bucket everybody forgets.&lt;/p&gt;

&lt;p&gt;Read the stem, decide which of those three it is describing, then cross off every option sitting in the other two before you compare anything. On a lot of these questions that one step leaves you with two options instead of four.&lt;/p&gt;

&lt;h2&gt;
  
  
  Load balancing and clustering are not the same shape
&lt;/h2&gt;

&lt;p&gt;Here is the pair that quietly costs people points. Both of them put several servers behind one workload, and both of them sound like more servers.&lt;/p&gt;

&lt;p&gt;Load balancing puts one device out front. The load balancer takes incoming requests and distributes them across individual servers that are otherwise doing their own thing. The servers stay separate. Something in front of them is making a choice about traffic.&lt;/p&gt;

&lt;p&gt;Clustering is servers configured to work together as one big server, and you can add and remove members while the cluster is running. There is no traffic cop out front. The systems themselves are the single logical thing.&lt;/p&gt;

&lt;p&gt;So the tell is the noun the stem picks. If the scenario is about distributing requests or sessions, it wants load balancing. If it is about several machines presenting as one system, or about growing capacity without taking that system offline, it wants clustering.&lt;/p&gt;

&lt;p&gt;The same warning covers platform diversity and multi-cloud. Platform diversity is running different operating systems for different purposes, so one OS-specific vulnerability cannot take everything at once. Multi-cloud is running application services across more than one provider, so one provider's outage is not automatically your outage. Both are diversity. One is diversity of software. The other is diversity of vendor.&lt;/p&gt;

&lt;h2&gt;
  
  
  Recovery sites get described, not named
&lt;/h2&gt;

&lt;p&gt;Nobody writes a question that says which of these is a warm site. They write a paragraph about budget and downtime and let you work it out.&lt;/p&gt;

&lt;p&gt;A hot site is an exact replica of your data center, synchronized and ready now. A cold site is an empty building, and you are moving staff and equipment in before anything runs. A warm site sits between them, with some equipment already there.&lt;/p&gt;

&lt;p&gt;What makes the question work is that those labels are a cost curve. Hot costs the most to sit idle and the least when you actually need it. Cold is the reverse. So a stem leaning on a tight recovery window is pointing at hot, while limited budget plus an acceptable multi-day outage is pointing at cold. Neither one will use the word.&lt;/p&gt;

&lt;p&gt;Geographic dispersion rides along with all of this and scores as its own point. Putting the recovery site a significant distance away is what stops the same storm or grid failure from taking both at once. A perfect hot site in the same industrial park as the primary is still one bad afternoon away from nothing.&lt;/p&gt;

&lt;h2&gt;
  
  
  The answer that looks too unserious to pick
&lt;/h2&gt;

&lt;p&gt;Continuity of operations is the option people rule out on instinct.&lt;/p&gt;

&lt;p&gt;It is the nontechnical fallback. The manual process. The paper form. A phone call to the customer. When three options are technical and the fourth is staff switching to paper order forms, the technical ones really do feel more like security answers.&lt;/p&gt;

&lt;p&gt;They are not. Not once the scenario has already told you the systems are down. What that bucket describes is simply what the business does during an outage, and it is a legitimate answer whenever the stem cares about the business continuing rather than the system recovering. Read for which one the question is tracking, the servers or the customers.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to drill this
&lt;/h2&gt;

&lt;p&gt;For every term on the 3.4 list, answer two questions out loud. What failure does this survive? And what does it cost me on an ordinary day when nothing is failing?&lt;/p&gt;

&lt;p&gt;The second question separates them, because that cost is what CompTIA builds the scenario around. Hot sites cost money continuously. Clustering costs complexity. Multi-cloud costs you a second set of everything to administer. Capacity planning sits on the same objective for the same reason, and it starts with people rather than hardware, which is the part that actually catches people out. You can scale servers in an afternoon. Trained staff do not scale in an afternoon.&lt;/p&gt;

&lt;p&gt;Then take one pass over the testing methods, because they are cheap points. A tabletop exercise is the team walking through the recovery plan together around a table. A failover test means actually flipping over to the redundant configuration to see whether it takes the load. A simulation runs a scripted event, something like a phishing test or a password reset process. Parallel processing tends to be the one that throws people, and it refers to multiple processors or processes handling transactions at the same time.&lt;/p&gt;

&lt;p&gt;If you want to know whether this domain is genuinely costing you points or you just feel shaky on it, the free diagnostic at &lt;a href="https://secplusmastery.com/diagnostic" rel="noopener noreferrer"&gt;secplusmastery.com/diagnostic&lt;/a&gt; breaks your result out by domain, and the architecture lessons and labs at &lt;a href="https://secplusmastery.com" rel="noopener noreferrer"&gt;secplusmastery.com&lt;/a&gt; work through the rest of Domain 3 the same way.&lt;/p&gt;

&lt;p&gt;Resilience questions reward one habit over everything else. Decide what is failing before you decide what fixes it.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>comptia</category>
      <category>learning</category>
    </item>
    <item>
      <title>A honeypot is not there to stop anybody, and that is the whole point on Security+</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Fri, 31 Jul 2026 10:20:57 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/a-honeypot-is-not-there-to-stop-anybody-and-that-is-the-whole-point-on-security-4m1f</link>
      <guid>https://dev.to/tiltedlunar123/a-honeypot-is-not-there-to-stop-anybody-and-that-is-the-whole-point-on-security-4m1f</guid>
      <description>&lt;p&gt;Deception and disruption technology sits in objective 1.2, and the vocabulary is genuinely small. Four terms. Most people memorize all four in about ten minutes and then still miss the question, because these stems are aimed somewhere else. They want the job the thing is doing.&lt;/p&gt;

&lt;h2&gt;
  
  
  The four terms sort themselves by size
&lt;/h2&gt;

&lt;p&gt;So what is being faked here?&lt;/p&gt;

&lt;p&gt;A honeytoken is a fake piece of data. A credential nobody was ever issued. An email address no human uses. A customer record with no customer behind it.&lt;/p&gt;

&lt;p&gt;Move up a rung and a honeyfile is a fake file. The stock example is something named passwords.txt, sitting in a share where it looks worth opening.&lt;/p&gt;

&lt;p&gt;A honeypot is a fake system, a server that looks like part of your environment without being part of it.&lt;/p&gt;

&lt;p&gt;Biggest of the four, a honeynet is a fake network. Several honeypots plus the supporting cast. Workstations and routers and a firewall, enough of an environment that it holds up when somebody starts poking around in it.&lt;/p&gt;

&lt;p&gt;Token, file, system, network. Exam stems almost always describe the fake thing directly, so most of these questions come down to matching that description to the right rung on the ladder.&lt;/p&gt;

&lt;h2&gt;
  
  
  The pair that actually gets missed
&lt;/h2&gt;

&lt;p&gt;Honeyfile and honeytoken are worth slowing down on. Both are bait and both are small, so the answer choices lean on them hard.&lt;/p&gt;

&lt;p&gt;A honeyfile is an alarm. It sits inside your environment, and the whole value is that nobody has a legitimate reason to open it. Somebody opens it and you have a detection. You have it early, too.&lt;/p&gt;

&lt;p&gt;The honeytoken works as a tracer instead. Its value shows up after the data has left you. You seed a fake credential or a fake record, and when it surfaces somewhere it should not be, in a dump or inside another company's system, you know which copy walked out and usually where it walked out of.&lt;/p&gt;

&lt;p&gt;So what is the scenario actually asking for? An alarm inside the building, or a way to follow something that already left. That single split resolves most of them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why the family works at all
&lt;/h2&gt;

&lt;p&gt;Here is the part CompTIA cares about, and the part people skip on their way to memorizing four words.&lt;/p&gt;

&lt;p&gt;Detection normally has a false positive problem. A rule that alerts on failed logins also alerts on the guy who forgot his password after vacation. Every real detection you write has to be tuned against normal behavior, and tuning is exactly where real alerts get buried.&lt;/p&gt;

&lt;p&gt;A honeypot has no normal behavior to tune against. Nobody has a business reason to authenticate to a server that serves nothing, or to open a file that no process ever references. Legitimate use is zero. Interaction is the signal, full stop.&lt;/p&gt;

&lt;p&gt;That is why the deception answer wins when a stem describes a team buried in alerts and asks what would give them a high-confidence indicator.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it is not
&lt;/h2&gt;

&lt;p&gt;Nothing in this family prevents anything, and this is where the trap answers live. When the stem asks how to stop the intrusion, or how to keep somebody off the file server, every deception option in the list is wrong no matter how good it sounds.&lt;/p&gt;

&lt;p&gt;What deception does is detect, and buy time. A scanner that burns its whole run enumerating an environment you invented is not spending that run on the real one. That is the disruption half of the objective title, though detection is what you actually deploy it for.&lt;/p&gt;

&lt;h2&gt;
  
  
  Reading the stem
&lt;/h2&gt;

&lt;p&gt;Two questions, in this order.&lt;/p&gt;

&lt;p&gt;What is the fake thing? Is it data? A file? A system, or a whole environment? That picks your term.&lt;/p&gt;

&lt;p&gt;Do you want an alarm or a tracer? That splits honeyfile from honeytoken when both are sitting in the options.&lt;/p&gt;

&lt;p&gt;There is a third habit worth building, and it carries well past this objective. When you see a control in an answer choice, ask what it produces. A honeypot produces an alert with almost no noise attached. A honeytoken produces attribution later. A firewall produces a block. Once you are reading controls by what comes out of them, four technically-true answers stop looking so similar, which is most of what this exam is.&lt;/p&gt;

&lt;p&gt;I write practice questions for this objective over at &lt;a href="https://secplusmastery.com" rel="noopener noreferrer"&gt;SecPlus Mastery&lt;/a&gt;, and the deception ones are some of the easiest questions to write badly. It is very tempting to put a honeypot next to three controls nobody would ever pick. The real exam does not do that. It gives you four things a real company genuinely does, and the deception option is right or wrong depending on one word in the stem, usually detect or prevent.&lt;/p&gt;

&lt;p&gt;If you have not measured where you stand on Domain 1 yet, the &lt;a href="https://secplusmastery.com/diagnostic" rel="noopener noreferrer"&gt;free diagnostic&lt;/a&gt; breaks your result out by objective, which tells you more than a single percentage when you are deciding what to study next.&lt;/p&gt;

&lt;p&gt;One last thing about honeypots specifically. Anything you deploy has to be isolated from the real environment. A decoy that shares credentials or sits flat on the production network hands an attacker a foothold, which is worth remembering on the exam for the same reason it is worth remembering on the job.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>comptia</category>
      <category>learning</category>
    </item>
    <item>
      <title>If your tool deletes 20,000 things, the interesting code is not the deleting</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Fri, 31 Jul 2026 01:01:27 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/if-your-tool-deletes-20000-things-the-interesting-code-is-not-the-deleting-kgl</link>
      <guid>https://dev.to/tiltedlunar123/if-your-tool-deletes-20000-things-the-interesting-code-is-not-the-deleting-kgl</guid>
      <description>&lt;p&gt;The first version of my Gmail cleanup extension was about forty lines. Find the messages matching a query, then delete them one at a time. It demoed beautifully on a test account with a couple hundred messages in it.&lt;/p&gt;

&lt;p&gt;Then I pointed it at a real inbox with nineteen thousand old promotions in it, and learned that the deleting was never the hard part.&lt;/p&gt;

&lt;h2&gt;
  
  
  A cleanup run is a batch job wearing a button
&lt;/h2&gt;

&lt;p&gt;That reframe fixed most of my design problems. One click on the front, but behind it sits a job that runs for minutes against data somebody actually cares about in an environment that can vanish at any moment for reasons having nothing to do with your code. Tabs get closed. Laptops sleep. Wi-Fi drops.&lt;/p&gt;

&lt;p&gt;So where does your progress live? If the answer is a variable in that tab, all of it dies with the tab. The user is left holding a partly-cleaned mailbox with no idea how far it got, and no way to find out. Which is a genuinely bad afternoon when the thing being partly-processed is their mail.&lt;/p&gt;

&lt;p&gt;So progress has to be written down as it happens, not held in memory and saved at the end. That one change drags a lot of other decisions with it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Every step has to be safe to run twice
&lt;/h2&gt;

&lt;p&gt;Once progress is durable you can resume, and resuming means steps get repeated. A crash lands somewhere in the middle of a batch. You cannot always tell whether the last call actually went through, though.&lt;/p&gt;

&lt;p&gt;So deleting something that is already deleted has to be a quiet no-op rather than an error that halts the whole run, and the same goes for a message the user happened to move by hand while the job was still going. The run should shrug and continue.&lt;/p&gt;

&lt;p&gt;Nothing clever there. It is just the thing you skip when you are writing the forty-line version.&lt;/p&gt;

&lt;h2&gt;
  
  
  The preview has to be the real code
&lt;/h2&gt;

&lt;p&gt;Dry-Run mode was originally going to be its own little function that counted matches. That was a mistake and I caught it early, thankfully.&lt;/p&gt;

&lt;p&gt;If the preview has its own copy of the matching logic, the preview lies. Not always. Eventually, and specifically on the edge cases where you most needed the truth. A preview is only worth something if it is the exact same selection code, with the destructive call switched off at the end.&lt;/p&gt;

&lt;p&gt;That is also why the extension ships three modes rather than one. Dry-Run shows what a rule would take and touches nothing. Review lets you approve first. Live just runs. Same path through the code, three different endings.&lt;/p&gt;

&lt;h2&gt;
  
  
  Write the log for the user, not for yourself
&lt;/h2&gt;

&lt;p&gt;"Deleted 12,431 messages" is a developer's log line. It tells the person who wrote the code that the loop finished.&lt;/p&gt;

&lt;p&gt;For the actual human at 11pm it answers nothing they care about. What did that rule match, and can I take it back? So the recovery log keeps the last twenty runs and the restore is one click. Building that took longer than the deletion feature did, and it is the part I would keep if I could only keep one.&lt;/p&gt;

&lt;h2&gt;
  
  
  Default to leaving things alone
&lt;/h2&gt;

&lt;p&gt;The last one is less about engineering and more about nerve. What should happen to a message the rules are unsure about? Nothing at all.&lt;/p&gt;

&lt;p&gt;Starred, important, and unread mail gets skipped automatically, because those are the three signals people already use to mean "this one matters" without ever thinking of it as a protect list. A whitelist covers the senders that rule cannot guess.&lt;/p&gt;

&lt;p&gt;The general version: when a tool operates in bulk on data it did not create, the correct default is timid. Users can always widen the net. They cannot always undo.&lt;/p&gt;

&lt;p&gt;None of this made the extension faster. It is honestly a little slower than the naive version, and it asks more questions along the way. What all that caution buys is the nerve to press the button in the first place, which turns out to be the feature people were missing.&lt;/p&gt;

&lt;p&gt;The extension is &lt;a href="https://chromewebstore.google.com/detail/bmcfpljakkpcbinhgiahncpcbhmihgpc" rel="noopener noreferrer"&gt;Bulk Delete Gmail Emails - Gmail One-Click Cleaner&lt;/a&gt; if you want to look at how it ended up.&lt;/p&gt;

</description>
      <category>productivity</category>
      <category>chrome</category>
      <category>webdev</category>
      <category>email</category>
    </item>
    <item>
      <title>A revoked certificate is still a perfectly valid certificate until somebody goes and checks</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Fri, 31 Jul 2026 00:53:03 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/a-revoked-certificate-is-still-a-perfectly-valid-certificate-until-somebody-goes-and-checks-1og2</link>
      <guid>https://dev.to/tiltedlunar123/a-revoked-certificate-is-still-a-perfectly-valid-certificate-until-somebody-goes-and-checks-1og2</guid>
      <description>&lt;p&gt;Say a company finds out on a Tuesday that the private key behind one of its TLS certificates has been sitting in a public repo for a month. They rotate the key, get a new certificate issued, and revoke the old one. Reasonable response.&lt;/p&gt;

&lt;p&gt;Now look at the old certificate. The dates on it are still good through next March. The CA signature verifies fine. Nothing about the name has changed either, so every field a client can check on its own passes. The certificate does not know it was revoked, and it never will.&lt;/p&gt;

&lt;p&gt;That gap is the reason a whole revocation system has to exist, and it is the part of PKI that SY0-701 keeps poking at.&lt;/p&gt;

&lt;h2&gt;
  
  
  Expired and revoked fail in completely different ways
&lt;/h2&gt;

&lt;p&gt;An expired certificate is easy. The client has a clock and the certificate has a notAfter date, so the comparison happens in memory in a microsecond. Nobody has to be online for that. Nobody has to be asked.&lt;/p&gt;

&lt;p&gt;Revocation has none of it. Where does the revocation decision actually live? At the CA, not in the certificate. So a client that wants to know has to go get that information from somewhere else. And if it cannot reach that somewhere else, it has to decide what to do about not knowing.&lt;/p&gt;

&lt;p&gt;Hold onto that last sentence. It decides more exam questions than the acronyms do.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three mechanisms, one question underneath
&lt;/h2&gt;

&lt;p&gt;All three answer the same question: is this certificate still good? What separates them is who does the legwork, and when.&lt;/p&gt;

&lt;h3&gt;
  
  
  CRL, where you download the whole list
&lt;/h3&gt;

&lt;p&gt;A certificate revocation list is a signed file the CA publishes with the serial numbers it has revoked. Your client downloads it and caches it, then checks whether the serial in front of it shows up on that list.&lt;/p&gt;

&lt;p&gt;It works, and it has two costs. The list gets big at a CA of any real size; that is just volume. The other cost is staleness. A CRL is only as fresh as the last time it was published, so there is a window where a certificate is revoked in reality and still missing from the copy your client happens to be holding.&lt;/p&gt;

&lt;h3&gt;
  
  
  OCSP, where you ask about one certificate
&lt;/h3&gt;

&lt;p&gt;The Online Certificate Status Protocol swaps the download for a question. The client sends the serial number of the one certificate it cares about to an OCSP responder, and gets a status back: good, revoked, or (when the responder has no record of that serial) unknown.&lt;/p&gt;

&lt;p&gt;Smaller and fresher, and it introduces two new problems in the process. Every new connection now waits on a round trip to a third party before anything loads. And the CA is now receiving a running list of the sites you visit, because you asked about them one at a time.&lt;/p&gt;

&lt;h3&gt;
  
  
  Stapling, where the server asks first
&lt;/h3&gt;

&lt;p&gt;Stapling flips who does the asking. The web server queries the OCSP responder on its own schedule, gets back a status response that the CA has timestamped and signed, and hands that response to every client during the TLS handshake.&lt;/p&gt;

&lt;p&gt;So the client gets a fresh signed answer without ever contacting the CA. The latency is gone, and so is the privacy leak. A slow responder also stops being every visitor's problem.&lt;/p&gt;

&lt;p&gt;So could a compromised server just staple a "good" response for a certificate that was actually revoked? It cannot. The CA signed that response, and the response carries a timestamp. The server has no way to forge either one. All it is doing is carrying somebody else's sealed note.&lt;/p&gt;

&lt;h2&gt;
  
  
  Soft-fail, which is where the scenario questions actually live
&lt;/h2&gt;

&lt;p&gt;Here is the part that gets skipped, and it is the part that separates memorizing three acronyms from understanding the control.&lt;/p&gt;

&lt;p&gt;So what happens when a browser cannot reach the CRL distribution point or the OCSP responder at all? In most cases it does not stop. It notes the failure and goes on to the site. That behavior is called soft-fail. It exists because the alternative, hard-fail, means the internet breaks for you every time some CA has a bad afternoon.&lt;/p&gt;

&lt;p&gt;The consequence is uncomfortable. An attacker who is positioned to present you a stolen certificate is very often positioned to block your revocation check too, and a blocked check reads as "could not determine" rather than "do not trust." The check that was supposed to save you is the one that quietly gives up.&lt;/p&gt;

&lt;p&gt;Stapling helps here in a way that is worth understanding. The status arrives inside the handshake you were already having, so there is no separate connection sitting out there for somebody to interfere with.&lt;/p&gt;

&lt;h2&gt;
  
  
  Reading these questions on the exam
&lt;/h2&gt;

&lt;p&gt;A few things fall out of all of this that are worth carrying in with you.&lt;/p&gt;

&lt;p&gt;When a scenario says a certificate was compromised and asks what to do about it, revocation is the answer and waiting for expiry is not. Certificates get issued for a year or more at a time, and "it runs out eventually" has never been an incident response.&lt;/p&gt;

&lt;p&gt;If the complaint is handshake latency, or privacy (the CA quietly learns what you browse), or a responder outage dragging sites down with it, the answer is stapling. Those are OCSP's costs, and stapling is the fix CompTIA wants you to name.&lt;/p&gt;

&lt;p&gt;A large environment fighting with a revocation file that will not stop growing? That one is a CRL question.&lt;/p&gt;

&lt;p&gt;And when an answer choice tells you revocation checking will reliably stop a stolen certificate from being used, be a little suspicious of it. It stops that certificate when the check completes and the client honors what came back.&lt;/p&gt;

&lt;p&gt;One drilling habit that costs nothing: on any certificate question, before you read the options, ask who has to do work in that scenario, and whether that work lands on the client or on the server or back at the CA. Then read the choices. They tend to sort themselves out, because these mechanisms put the work in three different places.&lt;/p&gt;

&lt;p&gt;If you want to find out whether this material is genuinely solid for you rather than just familiar, the free diagnostic at &lt;a href="https://secplusmastery.com/diagnostic" rel="noopener noreferrer"&gt;https://secplusmastery.com/diagnostic&lt;/a&gt; is a decent gut check, and the lessons and question bank are at &lt;a href="https://secplusmastery.com" rel="noopener noreferrer"&gt;https://secplusmastery.com&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>comptia</category>
      <category>learning</category>
    </item>
    <item>
      <title>The Security+ trap in identity questions is the employee who changed jobs, not the one who left</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Thu, 30 Jul 2026 09:37:41 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/the-security-trap-in-identity-questions-is-the-employee-who-changed-jobs-not-the-one-who-left-19l6</link>
      <guid>https://dev.to/tiltedlunar123/the-security-trap-in-identity-questions-is-the-employee-who-changed-jobs-not-the-one-who-left-19l6</guid>
      <description>&lt;p&gt;Objective 4.6 looks like a vocabulary list. Provisioning and deprovisioning. Permission assignments. Identity proofing. Attestation. Then a pile of privileged access management tools at the end.&lt;/p&gt;

&lt;p&gt;So people study it as terms to recognize. Then the exam hands you a scenario about somebody who moved departments, and the vocabulary does not help. Every option on the screen is a real control that a real company really uses.&lt;/p&gt;

&lt;p&gt;Here is the shift that makes this domain easier: identity questions are rarely asking who should have access. They are asking how long somebody keeps access after the reason for it went away.&lt;/p&gt;

&lt;h2&gt;
  
  
  The middle of the lifecycle is where the questions live
&lt;/h2&gt;

&lt;p&gt;The account lifecycle has three parts, and only one usually gets studied properly.&lt;/p&gt;

&lt;p&gt;Provisioning is the beginning. Somebody proves who they are, an account gets created, permissions get assigned. Least privilege belongs here.&lt;/p&gt;

&lt;p&gt;Deprovisioning is the end. Somebody leaves and the access goes away.&lt;/p&gt;

&lt;p&gt;The middle is everything else, and the middle is where the exam sets its traps. People change roles. They cover for a coworker for two weeks. Somebody joins a project, gets added to a share, and the project ends. Nobody remembers.&lt;/p&gt;

&lt;h2&gt;
  
  
  Leaving triggers a process. Moving does not.
&lt;/h2&gt;

&lt;p&gt;When an employee resigns, a process starts. HR knows. The manager knows. Somewhere a ticket gets filed that says disable this account. It gets filed because a departure is obviously an access event.&lt;/p&gt;

&lt;p&gt;A transfer from finance over to marketing plays out differently. The person needs the marketing tools, so a ticket goes in to add that access. Nobody files the other ticket. Those old finance permissions just stay where they are, attached to a real person who still logs in every morning.&lt;/p&gt;

&lt;p&gt;That accumulation has a name on the exam: permission creep, sometimes written as privilege creep. The stem describes it without ever naming it. Transferred six months ago, still approving invoices for the old department.&lt;/p&gt;

&lt;p&gt;Read that kind of stem slowly, because the answer that feels obvious is usually the wrong one. Why?&lt;/p&gt;

&lt;h2&gt;
  
  
  Least privilege is not the fix for creep
&lt;/h2&gt;

&lt;p&gt;There is a very good reason least privilege trips people up here. It sits right in the answer list and it feels correct.&lt;/p&gt;

&lt;p&gt;Least privilege was what you were supposed to do at account creation, but that timing is exactly why it cannot be the cleanup. It describes what permissions should look like at the moment they get assigned. It does not go find the ones that already drifted.&lt;/p&gt;

&lt;p&gt;What finds those is a review. Somebody with authority looks at who has access to what, then confirms each entry or strips it. CompTIA files this under attestation: a formal confirmation that access or identity information is still appropriate. Also called an access review, or a recertification.&lt;/p&gt;

&lt;p&gt;So the split is this. Least privilege is a design rule applied when access is granted. Attestation is a recurring check on access that already exists. A stem describing a mess that piled up wants the second one.&lt;/p&gt;

&lt;h2&gt;
  
  
  The offboarding question has its own trap
&lt;/h2&gt;

&lt;p&gt;Deprovisioning seems simple until the choices offer you both delete the account and disable the account. Which one?&lt;/p&gt;

&lt;p&gt;Disable it. Deleting can take things with it that you still need: any route into that person's encrypted files and mailbox, plus the audit trail showing which account did what. Investigations tend to happen after somebody leaves. Fairly often they happen because somebody left.&lt;/p&gt;

&lt;p&gt;Disabling kills the login immediately, which is the actual security requirement. Deletion happens later, once retention and legal sign off.&lt;/p&gt;

&lt;h2&gt;
  
  
  PAM asks the same question about administrators
&lt;/h2&gt;

&lt;p&gt;The back half of 4.6 exists in order to solve one problem: standing privilege. An administrator holding admin rights all day is holding them during all the hours they are not doing anything administrative. Phish that account on a Tuesday afternoon and the attacker inherits everything it carries.&lt;/p&gt;

&lt;p&gt;Three tools. Three different complaints.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Password vaulting&lt;/strong&gt; stores privileged credentials centrally. Nobody memorizes the domain admin password anymore. You check it out, the vault records that you did, and the password rotates afterward. Reach for this when a stem complains about a shared admin password six people know, or when the logs cannot say which human was behind an action.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Ephemeral credentials&lt;/strong&gt; have a short life built in. They expire on their own instead of waiting for somebody to remember to revoke them. Is the stem worried about credentials staying valid long after the work finished? That is the shape it is describing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Just-in-time permissions&lt;/strong&gt; go after standing privilege directly. The account carries no elevated rights during normal work. An admin task comes up, elevation gets requested and approved for a defined window, and then it drops off when the window closes.&lt;/p&gt;

&lt;p&gt;A real PAM product does all three, so they blur on the job. On the exam they stay separable, but only because the stem tells you which complaint it is making.&lt;/p&gt;

&lt;h2&gt;
  
  
  The question to ask on any 4.6 scenario
&lt;/h2&gt;

&lt;p&gt;How long does this person hold this permission, and what takes it away?&lt;/p&gt;

&lt;p&gt;Provisioning decides what they get on day one. Attestation catches what they should have lost in the middle. Deprovisioning ends it. Elevation that expires shrinks the window to one task, and vaulting means they never personally hold the credential at all, which is the part people find genuinely strange the first time they watch a real rollout and realize the administrators themselves no longer know the password.&lt;/p&gt;

&lt;p&gt;The fact that these work as exam questions comes down to the wrong answers. None are fake. You are being asked which real control fixes the failure in front of you, and that is a different skill from remembering definitions.&lt;/p&gt;

&lt;p&gt;Want to know whether this domain is a weak spot for you? The free diagnostic at &lt;a href="https://secplusmastery.com/diagnostic" rel="noopener noreferrer"&gt;secplusmastery.com/diagnostic&lt;/a&gt; is scored by objective, so it will show you where 4.6 sits next to everything else. The full identity and access material, with scenario-style practice questions, lives at &lt;a href="https://secplusmastery.com" rel="noopener noreferrer"&gt;secplusmastery.com&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>comptia</category>
      <category>learning</category>
    </item>
    <item>
      <title>Your inbox does not need another cleanup weekend. It needs a retention policy.</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Wed, 29 Jul 2026 09:49:20 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/your-inbox-does-not-need-another-cleanup-weekend-it-needs-a-retention-policy-5e36</link>
      <guid>https://dev.to/tiltedlunar123/your-inbox-does-not-need-another-cleanup-weekend-it-needs-a-retention-policy-5e36</guid>
      <description>&lt;p&gt;Every few months the same thing used to happen. Storage warning. A Saturday burned on deleting email. One glorious week of a clean mailbox, then the slow refill until the warning came back. I ran that loop three or four times before it occurred to me that the cleanup was never the hard part.&lt;/p&gt;

&lt;p&gt;The missing piece was a rule.&lt;/p&gt;

&lt;h2&gt;
  
  
  Companies solved this decades ago
&lt;/h2&gt;

&lt;p&gt;Any organization past a certain size runs a retention schedule. This class of record is kept seven years, that one for a year, this other one ninety days, and something deletes them on that schedule without a human weighing in each time. Nobody does it because deleting things is fun! They do it because keeping everything forever costs money and creates liability.&lt;/p&gt;

&lt;p&gt;A personal mailbox has both of those problems in miniature. Almost nobody writes the rule down.&lt;/p&gt;

&lt;h2&gt;
  
  
  What a personal retention rule looks like
&lt;/h2&gt;

&lt;p&gt;Pick a number per category while nothing is on fire. Mine ended up like this:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Promotions and marketing: 30 days. Did a sale fail to move me in a month? Then it never will.&lt;/li&gt;
&lt;li&gt;Social and app notifications: 30 days; most are stale before I even open them.&lt;/li&gt;
&lt;li&gt;Newsletters: 90 days.&lt;/li&gt;
&lt;li&gt;Receipts, orders, tax and anything from an actual human: keep.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That last line matters more than the rest put together, and it is the reason the whole exercise works. The deletions are aimed at categories that were disposable on arrival, so nothing in the rule requires courage.&lt;/p&gt;

&lt;p&gt;So why does cleanup swallow an entire weekend? Because of the alternative: deciding whether one particular email is safe to delete while you are staring down forty thousand of them. You are not slow because there is a lot of mail. You are slow because you are making the same judgment call thousands of times.&lt;/p&gt;

&lt;h2&gt;
  
  
  The gap in Gmail's native tooling
&lt;/h2&gt;

&lt;p&gt;Gmail filters will happily delete mail for you. Set the criteria, tick "Delete it," and matching messages land in Trash on arrival.&lt;/p&gt;

&lt;p&gt;Notice the limit, though. Filters run at arrival time. A filter can throw something away the moment it shows up, but it cannot say "keep this for thirty days, then get rid of it." There is no built-in retention window for a regular Gmail account, which is a shame, because a retention window is precisely what a rule like the one above describes. You do want the receipt from that store... for a month, not until 2034.&lt;/p&gt;

&lt;p&gt;So the native toolkit splits into two halves that do not quite meet; filters handle mail you never wanted at all. Search operators like &lt;code&gt;category:promotions older_than:30d&lt;/code&gt; handle the aging pile, but only when you remember to run them, which puts a human back in the loop and lands you right back on the treadmill.&lt;/p&gt;

&lt;p&gt;One more thing worth knowing before automating anything: deleted mail sits in Trash for 30 days and keeps counting against your quota the entire time. Retention rules that ignore Trash appear to do nothing for a month.&lt;/p&gt;

&lt;h2&gt;
  
  
  Closing the loop
&lt;/h2&gt;

&lt;p&gt;What actually broke the cycle for me was scheduling the thing rather than remembering it. I build a Chrome extension called &lt;a href="https://chromewebstore.google.com/detail/bulk-delete-gmail-emails/bmcfpljakkpcbinhgiahncpcbhmihgpc" rel="noopener noreferrer"&gt;Gmail One-Click Cleaner&lt;/a&gt; partly because I wanted this for myself: it runs cleanups on a schedule you set, daily or weekly or monthly, against rule sets you configure. It also keeps a global whitelist so specific senders or domains are never touched no matter what a rule says.&lt;/p&gt;

&lt;p&gt;If you would rather not install anything, the honest alternative is a recurring calendar reminder and a saved set of search queries. That genuinely works. It just puts you back in the loop every single month.&lt;/p&gt;

&lt;p&gt;Either way, the part that matters is the rule rather than the tool. Write down what each category is worth in days. Decide once which senders are permanently off limits. Then hand the enforcing to something that is not your memory, because the reason the mailbox filled up again was never that you lacked a delete button.&lt;/p&gt;

</description>
      <category>productivity</category>
      <category>gmail</category>
      <category>email</category>
      <category>automation</category>
    </item>
    <item>
      <title>Masking hides data from a person. Tokenization hides it from your database.</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Wed, 29 Jul 2026 09:40:41 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/masking-hides-data-from-a-person-tokenization-hides-it-from-your-database-55c9</link>
      <guid>https://dev.to/tiltedlunar123/masking-hides-data-from-a-person-tokenization-hides-it-from-your-database-55c9</guid>
      <description>&lt;p&gt;A Security+ scenario hands you a payment application and asks how to protect the stored card numbers. Four choices come with it: encryption and tokenization, masking and obfuscation. All four hide data. Three of them are still wrong.&lt;/p&gt;

&lt;p&gt;Objective 3.3 lists those as separate methods to secure data, and most people study them as a vocabulary list: four words, four one-line definitions, done. Then the exam hands you a scenario where every definition fits, and the real question turns out to be one the flashcards never asked. After this control is applied, can the original value come back, and who holds the thing that brings it back? Sitting underneath both of those is a third question: who was it hidden from to begin with?&lt;/p&gt;

&lt;p&gt;Sort by those and the pile comes apart fast.&lt;/p&gt;

&lt;h2&gt;
  
  
  Encryption keeps a mathematical link to the original
&lt;/h2&gt;

&lt;p&gt;Encryption turns plaintext into ciphertext, and two properties describe what you get. Confusion means the ciphertext looks nothing like what you started with; diffusion means that changing a single character of the plaintext changes the output dramatically.&lt;/p&gt;

&lt;p&gt;What matters more for sorting exam answers is the part underneath. The ciphertext is derived from the plaintext, so the original is mathematically in there, and handing someone the key brings the real value back in full every time. That is not a weakness in the control; it is the entire reason anybody picked it, because your application needs that card number eventually.&lt;/p&gt;

&lt;p&gt;Encryption is the answer when data has to survive a stolen drive or an intercepted session and the business still needs the real value later. Reversible on purpose.&lt;/p&gt;

&lt;h2&gt;
  
  
  Tokenization deliberately breaks that link
&lt;/h2&gt;

&lt;p&gt;Tokenization replaces sensitive data with a completely different set of data. It is not hashing, and it is not encryption either. Nothing gets transformed. One set of characters simply stands in for another, and that distinction is the whole reason tokenization sits on the objectives list as its own bullet instead of as a flavor of encryption.&lt;/p&gt;

&lt;p&gt;No math connects the token to the card number. You cannot crack a token, because there is nothing inside it to crack. The only route back is a lookup at the token service that issued it.&lt;/p&gt;

&lt;p&gt;Follow a mobile payment through and the win becomes obvious. You register the card once with a token service, and your phone stores the token rather than the card itself. From then on the register only ever sees that token: the merchant's payment server checks it against the token service and gets back a yes or a no. The card number was never in the merchant's environment at all. Breach the merchant and you get tokens.&lt;/p&gt;

&lt;p&gt;Memorize that fork. Encryption protects a value you are still holding; tokenization means you stopped holding it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Masking is about the person looking at the screen
&lt;/h2&gt;

&lt;p&gt;Masking makes data harder to read, and everybody recognizes the version printed on a receipt (asterisks, then the last four digits). Underneath, the implementation varies. Sometimes part of the value is encrypted. Sometimes the characters are shuffled out of order, or swapped for completely different information.&lt;/p&gt;

&lt;p&gt;Which is why implementation is the wrong thing to fixate on here. Masking is defined by the outcome at the point of display: somebody legitimately needs to work with this record, and that somebody does not need to see all of it.&lt;/p&gt;

&lt;p&gt;A support agent confirming they pulled up the right account needs four digits. Someone testing a report against production-shaped data needs realistic rows, not real people. In both cases the person is authorized to be in the record and is going to stay in it all day, so the control cannot be about keeping them out; it is about shrinking how much of the record they carry around while they work.&lt;/p&gt;

&lt;p&gt;Notice what masking never claims, though. It says nothing about whether the real number is still sitting in the database. Usually it is.&lt;/p&gt;

&lt;h2&gt;
  
  
  Obfuscation is the category, not the control
&lt;/h2&gt;

&lt;p&gt;Obfuscation means making something much harder to understand without making it genuinely impossible. Hiding a file inside an image with steganography? Obfuscation. Running an XOR cipher over source code? Also obfuscation. So is masking, technically.&lt;/p&gt;

&lt;p&gt;Which is what makes it the distractor when it turns up in a list beside tokenization and masking: a scenario specific enough to name a card number and a payment processor is asking which control you would actually deploy, not which family of techniques that control belongs to, and picking the family is the answer of somebody who recognized all four words without ever pinning down the difference between them. Obfuscation earns the pick when the stem describes hiding data inside something else, or making code difficult to follow rather than unreadable.&lt;/p&gt;

&lt;h2&gt;
  
  
  Running a 3.3 scenario in one pass
&lt;/h2&gt;

&lt;p&gt;Three questions, in this order.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Who was this hidden from?&lt;/strong&gt; An outside attacker holding the storage or the wire points at encryption. A legitimate insider who belongs in that record points at masking. Nobody in particular, but you want the value out of your environment entirely, points at tokenization.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Can the original come back, and how?&lt;/strong&gt; With a key, encryption. Through a lookup at a separate service, tokenization. Whatever masking hid is generally still sitting right behind it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What is the stem actually protecting against?&lt;/strong&gt; Scope is the tell for tokenization. A stem built around "the application must not store the primary account number" is not encryption phrased differently; it is telling you the value should never be in there in the first place.&lt;/p&gt;

&lt;p&gt;One habit is worth building on top of all that. When two answers survive, ask which one leaves the sensitive value in your possession. Encryption does. Tokenization does not. A surprising number of 3.3 questions come down to that single fork, and they stop being vocabulary questions the moment you start reading them that way.&lt;/p&gt;

&lt;p&gt;Reading this and sorting it under a clock are different skills, and only one of them shows up on exam day. The free diagnostic at &lt;a href="https://secplusmastery.com/diagnostic" rel="noopener noreferrer"&gt;secplusmastery.com/diagnostic&lt;/a&gt; will show you where Domain 3 sits against your other weak spots, and the lessons and practice bank are at &lt;a href="https://secplusmastery.com" rel="noopener noreferrer"&gt;secplusmastery.com&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>comptia</category>
      <category>learning</category>
    </item>
    <item>
      <title>On Security+, a vulnerability is not closed until someone proves it</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Tue, 28 Jul 2026 09:22:56 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/on-security-a-vulnerability-is-not-closed-until-someone-proves-it-2di</link>
      <guid>https://dev.to/tiltedlunar123/on-security-a-vulnerability-is-not-closed-until-someone-proves-it-2di</guid>
      <description>&lt;p&gt;Objective 4.3 asks you to explain the activities associated with vulnerability management, and almost all the study time goes to the front of that list. Scanning, then arguing with what the scanner said. After that the material trails off somewhere around the word "patch," and the exam does not.&lt;/p&gt;

&lt;p&gt;The back half of that objective hands out points, because it is the part that looks like a real ticket queue instead of tool output. Here is the sort I use when a question drops a scan finding in front of me.&lt;/p&gt;

&lt;h2&gt;
  
  
  CVE names the broken thing. CWE names the mistake.
&lt;/h2&gt;

&lt;p&gt;Study notes swap these two constantly. They answer different questions.&lt;/p&gt;

&lt;p&gt;MITRE defines a vulnerability as "a specific instance of one or more weaknesses in a specific product that can be exploited." That is what a CVE identifies: one flaw in one product, with a number you can hand to a vendor.&lt;/p&gt;

&lt;p&gt;A weakness is broader. MITRE calls it a condition in a component that "could contribute to the introduction of vulnerabilities," and that is a CWE. It names the category of error, and one CWE entry usually sits underneath hundreds of CVE records.&lt;/p&gt;

&lt;p&gt;Made concrete? Building a SQL statement out of unchecked user input is a class of mistake, and it has a CWE. The specific version of the specific product where somebody actually did that is the instance, and it gets a CVE.&lt;/p&gt;

&lt;p&gt;CVSS is neither of those. It is the severity score (0 to 10) hung on the instance. FIRST publishes the specification, and the spec is honest about what its number leaves out. A base score "reflects the severity of a vulnerability according to its intrinsic characteristics which are constant over time." Constant over time, and identical for every organization on earth, which is exactly why the same document tells you to supplement it with environmental scoring for your own deployment.&lt;/p&gt;

&lt;p&gt;So when a stem asks what identifies the flaw found on that host, you want the CVE. Where did the "critical" rating come from? CVSS. What kind of coding error produced the whole family of them? CWE.&lt;/p&gt;

&lt;h2&gt;
  
  
  "We can't patch it" does not end the question
&lt;/h2&gt;

&lt;p&gt;Patching is the default and it is correct most of the time. Questions get interesting when the stem quietly takes that option away. A medical device that loses its certification if you touch the firmware. A controller that cannot be rebooted while the line is running. A vendor that went out of business in 2019.&lt;/p&gt;

&lt;p&gt;The 4.3 vocabulary for that situation is worth learning as a menu:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Compensating controls.&lt;/strong&gt; Disable the vulnerable service, or put an ACL or a firewall policy in front of it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Segmentation.&lt;/strong&gt; Move the thing somewhere the rest of the network cannot reach.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Insurance.&lt;/strong&gt; Shift the financial damage rather than the flaw.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Exception or exemption.&lt;/strong&gt; A review committee looks at the risk and formally decides this one does not get patched.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That last item is the one people refuse to pick, because choosing it feels like admitting defeat. It is a legitimate outcome. An exception somebody reviewed and wrote down is vulnerability management working as designed; an unpatched system nobody ever decided about is the failure. Those two situations look identical from the outside until you go looking for the paperwork.&lt;/p&gt;

&lt;h2&gt;
  
  
  Validation is what separates the last two answers
&lt;/h2&gt;

&lt;p&gt;Watch for this shape. The stem describes a fix being applied, then asks what happens next. Two choices look responsible: close the ticket and notify the requester, or rescan the host.&lt;/p&gt;

&lt;p&gt;Rescanning wins, and the reason is worth internalizing. Your deployment tool reporting "success" is a claim made by the same machine you are asking about. Validation of remediation means independent confirmation, which in practice is a rescan plus an audit of a sample of systems, checking that the patch installed where the console says it did. Anyone who has watched a patch report disagree with reality knows why CompTIA bothers testing this.&lt;/p&gt;

&lt;p&gt;If one option verifies and another documents, verification comes first.&lt;/p&gt;

&lt;h2&gt;
  
  
  Reporting is doing work
&lt;/h2&gt;

&lt;p&gt;The final activity in the objective is reporting: which systems took the patch, and what has shown up since the last cycle. Paperwork, right? Ask what happens without it. That exception granted for one quarter turns permanent, because the only thing that would have surfaced it again is a report nobody runs. Findings age out of everyone's memory except the attacker's.&lt;/p&gt;

&lt;h2&gt;
  
  
  Drilling it
&lt;/h2&gt;

&lt;p&gt;Run any vulnerability scenario through four questions, in this order:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Is the finding real?&lt;/li&gt;
&lt;li&gt;How bad is it here, in this environment, rather than in the abstract?&lt;/li&gt;
&lt;li&gt;What is the response, and if it is not a patch, which alternative and who signed off?&lt;/li&gt;
&lt;li&gt;What proves it worked?&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Answer sets for this objective tend to include one option from each of those four steps. Figuring out which step the stem stopped at will usually knock out three choices before you have read any of them closely.&lt;/p&gt;

&lt;p&gt;I write practice questions for this objective over at &lt;a href="https://secplusmastery.com" rel="noopener noreferrer"&gt;secplusmastery.com&lt;/a&gt;, and if you want to know which domains are quietly costing you points before you build a study plan, there is a free diagnostic at &lt;a href="https://secplusmastery.com/diagnostic" rel="noopener noreferrer"&gt;secplusmastery.com/diagnostic&lt;/a&gt;.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>comptia</category>
      <category>learning</category>
    </item>
    <item>
      <title>Cleaning Gmail is the easy half. Stopping it from refilling is the other one</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Mon, 27 Jul 2026 09:28:43 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/cleaning-gmail-is-the-easy-half-stopping-it-from-refilling-is-the-other-one-40em</link>
      <guid>https://dev.to/tiltedlunar123/cleaning-gmail-is-the-easy-half-stopping-it-from-refilling-is-the-other-one-40em</guid>
      <description>&lt;p&gt;Clearing out Gmail on a Sunday feels great. Storage bar back in the green. Inbox down to something you can actually look at. Six weeks later you are back where you started, though.&lt;/p&gt;

&lt;p&gt;That is not a discipline problem. Deleting is a one-time action pointed at a continuous inflow, and until you do something about the inflow, the pile rebuilds at exactly the rate it built the first time.&lt;/p&gt;

&lt;p&gt;Gmail ships the tool for the second half. Most people never take it past "apply a label," though.&lt;/p&gt;

&lt;h2&gt;
  
  
  Filters are rules, not folders
&lt;/h2&gt;

&lt;p&gt;A Gmail filter can archive or delete a message outright (it can also star it, or forward it somewhere else). You hang the action off any search you can write.&lt;/p&gt;

&lt;p&gt;So: anything you can find, you can automate. The workflow is the cleanup workflow you already know, aimed at the future instead of the past.&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Type the search into the Gmail search bar and run it.&lt;/li&gt;
&lt;li&gt;Read the results. Do not skip this. The filter will do the same thing to mail you have not seen yet.&lt;/li&gt;
&lt;li&gt;Open the search options and click Create filter.&lt;/li&gt;
&lt;li&gt;Pick the action.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Four filters that carry most of the weight
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;The sender that never stops.&lt;/strong&gt; &lt;code&gt;from:noreply@somecompany.com&lt;/code&gt;, set to delete. Order updates from a store you used once in 2019. Notifications from an app you abandoned. If you would never open one, it does not need to land in your inbox first so you can ignore it there.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The marketing tail.&lt;/strong&gt; &lt;code&gt;category:promotions older_than:1m&lt;/code&gt;. Delete on arrival is aggressive here, so if you are the sort of person who occasionally wants the coupon, archive it instead and let search dig it out on the rare day you need it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Robot mail you only care about live.&lt;/strong&gt; Build notifications and monitoring that already resolved itself. Something like &lt;code&gt;from:ci@example.com subject:passed&lt;/code&gt;, deleted on arrival; the failures still reach you. Worth five minutes for anyone whose inbox runs 80 percent machine-generated.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Newsletters you actually read.&lt;/strong&gt; Do not delete these. Archive them on arrival and apply a label, so you read them in one sitting when you feel like it instead of eight interruptions across a workday.&lt;/p&gt;

&lt;h2&gt;
  
  
  Filters do not touch the backlog
&lt;/h2&gt;

&lt;p&gt;This is the part that surprises people, so it is worth being blunt about. A filter runs on mail as it arrives. Google's documentation says it outright for forwarding: create a filter to forward messages and only new messages are affected.&lt;/p&gt;

&lt;p&gt;Which means order matters! Clear the backlog first, then set the filters so it does not come back. Do it the other way around and the filters hum along on new mail while your existing 40,000 promotional messages sit exactly where they were.&lt;/p&gt;

&lt;p&gt;The backlog is the tedious half. Searching and selecting in the Gmail web interface only gets you a screen of results at a time. The link that selects every conversation matching the search is easy to miss, too, and that one link is the difference between a cleanup and an afternoon. A few thousand messages? Fine. Eighty thousand is an evening you are not getting back.&lt;/p&gt;

&lt;p&gt;That is the gap my extension fills. Gmail One-Click Cleaner does the bulk pass, deleting by age or size or category. Everything it removes goes to Trash rather than being erased. Starred, important and unread mail gets skipped automatically, and Review and Dry-Run modes let you see what a rule would hit before you let it touch anything. Free for the core cleanup, and it lives on the &lt;a href="https://chromewebstore.google.com/detail/bmcfpljakkpcbinhgiahncpcbhmihgpc" rel="noopener noreferrer"&gt;Chrome Web Store&lt;/a&gt;. Full disclosure, I built it.&lt;/p&gt;

&lt;p&gt;Whichever way you clear the backlog, set the filters afterward. Deleting is a chore that comes back; a filter is a chore you do once.&lt;/p&gt;

&lt;h2&gt;
  
  
  One last thing about the storage bar
&lt;/h2&gt;

&lt;p&gt;Deleting does not free space on its own. Mail sits in Trash for 30 days before Gmail removes it for good, and it counts against your quota that entire time, which is why a big cleanup so often looks like it accomplished nothing. Cleared a lot and the bar did not move? Empty the Trash. Look again.&lt;/p&gt;

</description>
      <category>productivity</category>
      <category>gmail</category>
      <category>email</category>
      <category>webdev</category>
    </item>
    <item>
      <title>The Security+ questions about phishing campaigns are not about attackers</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Mon, 27 Jul 2026 09:21:28 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/the-security-questions-about-phishing-campaigns-are-not-about-attackers-56</link>
      <guid>https://dev.to/tiltedlunar123/the-security-questions-about-phishing-campaigns-are-not-about-attackers-56</guid>
      <description>&lt;p&gt;Domain 5.6 is the part of Security+ that people skim. It reads like an HR slide deck: awareness training and phishing simulations. Nothing to configure or subnet. Free points, right?&lt;/p&gt;

&lt;p&gt;Then the exam hands you a scenario, and it turns out these questions have exactly one correct action buried in them, same as everything else on the test.&lt;/p&gt;

&lt;p&gt;Here is what actually gets asked.&lt;/p&gt;

&lt;h2&gt;
  
  
  A phishing campaign is something you run, not something that happens to you
&lt;/h2&gt;

&lt;p&gt;The word itself is the trap. Outside the exam, a phishing campaign means a wave of attacks aimed at a company. On Security+ it means the reverse: your own security team sends fake phishing mail to your own users to find out who bites.&lt;/p&gt;

&lt;p&gt;The mechanics show up in the stems. The campaign is automated, and it reports opens and clicks (plus anything else a user does with the message) back to a central console. Whoever clicks gets training assigned to them, often immediately.&lt;/p&gt;

&lt;p&gt;So when a stem says the security team sent messages to employees and tracked who clicked, nothing bad has happened yet. That is not an incident, and containment is the wrong pick. You are being asked about the awareness program.&lt;/p&gt;

&lt;h2&gt;
  
  
  Recognizing a phish is a checklist, and the exam uses the same checklist
&lt;/h2&gt;

&lt;p&gt;Spelling and grammar mistakes, in the message and inside the link. A domain name close to a real one without being it. An attachment that has no business being attached. A request for login credentials.&lt;/p&gt;

&lt;p&gt;The other half of that objective is what to do next, and that is where people lose the point. Every organization is supposed to have a well known process for reporting a suspected phishing email up to the security team, and users are supposed to know what that process is before they need it. If the stem describes an employee who just received something suspicious, report it through that process. Not delete it. Not forward it around the department as a warning, which only spreads the thing further.&lt;/p&gt;

&lt;p&gt;Filtering catches most of it. Users exist in this model to catch what the filter missed, which is why the reporting path counts as a control and not just as good manners.&lt;/p&gt;

&lt;h2&gt;
  
  
  Anomalous behavior comes in three flavors and the exam wants the label
&lt;/h2&gt;

&lt;p&gt;This is the piece most likely to show up as a sorting question. Three buckets.&lt;/p&gt;

&lt;p&gt;Risky behavior means the user did something dangerous on purpose. Modifying files they had no reason to touch, or moving company data somewhere it does not belong. They knew better.&lt;/p&gt;

&lt;p&gt;Unexpected behavior means the activity does not match the pattern: a login from a country where nobody works, or a jump in outbound transfers at an hour when the office is empty.&lt;/p&gt;

&lt;p&gt;Unintentional behavior is an honest mistake. A typo. A setting somebody got wrong and never noticed.&lt;/p&gt;

&lt;p&gt;The tell is intent plus pattern. Deliberate but dangerous lands in risky. Out of character lands in unexpected. Why does the label matter? Two of those call for training and one might call for HR, so the sorting decides the response.&lt;/p&gt;

&lt;h2&gt;
  
  
  Reporting and monitoring splits into an initial half and a recurring half
&lt;/h2&gt;

&lt;p&gt;Initial reporting is the baseline. Measure before you change anything, so later numbers have something to sit next to.&lt;/p&gt;

&lt;p&gt;Recurring is the part that matters. Monitoring runs continuously and produces metrics like phishing click rates and multifactor authentication use. Password manager adoption too. Those numbers are how anyone knows whether the program did anything at all, and they are also how you find the users who keep needing the same lesson taught to them a fourth time.&lt;/p&gt;

&lt;p&gt;Asked how you know the awareness program is working? That is recurring monitoring. Asked what you do at the very start? Initial.&lt;/p&gt;

&lt;h2&gt;
  
  
  Development and execution are two separate words on purpose
&lt;/h2&gt;

&lt;p&gt;Development is building the thing. Materials and a schedule, tailored to job function and to whatever regulation your industry lives under.&lt;/p&gt;

&lt;p&gt;Execution is delivery. Then the numbers that show what changed.&lt;/p&gt;

&lt;p&gt;CompTIA splits them because real programs split them, and because a stem can hand you a program that was developed carefully and executed badly. Those two situations do not have the same fix.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this is worth an hour
&lt;/h2&gt;

&lt;p&gt;Domain 5 carries 20 percent of the exam. Biggest single slice of the five. Security awareness is a small corner of it, but the material is short and the vocabulary is fixed, with almost no technical depth to fall into. An hour here beats a fourth pass through cryptography.&lt;/p&gt;

&lt;p&gt;What does not work is memorizing the objective list, since the exam never asks you to recite it. It asks what one specific person should do next. If you want to find out whether you can make that call under exam conditions, the free diagnostic at &lt;a href="https://secplusmastery.com/diagnostic" rel="noopener noreferrer"&gt;https://secplusmastery.com/diagnostic&lt;/a&gt; is a quick read on where the gaps sit, and the full bank at &lt;a href="https://secplusmastery.com" rel="noopener noreferrer"&gt;https://secplusmastery.com&lt;/a&gt; works Domain 5 the way the exam does, in scenarios instead of definitions.&lt;/p&gt;

&lt;p&gt;One question to carry into every 5.6 item: is this stem about preventing, detecting, responding, or measuring? Four answer choices, and they tend to contain one of each.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>comptia</category>
      <category>learning</category>
    </item>
    <item>
      <title>Risk appetite and risk tolerance are two different numbers on Security+</title>
      <dc:creator>TiltedLunar123</dc:creator>
      <pubDate>Sun, 26 Jul 2026 08:56:15 +0000</pubDate>
      <link>https://dev.to/tiltedlunar123/risk-appetite-and-risk-tolerance-are-two-different-numbers-on-security-55cj</link>
      <guid>https://dev.to/tiltedlunar123/risk-appetite-and-risk-tolerance-are-two-different-numbers-on-security-55cj</guid>
      <description>&lt;p&gt;Domain 5 hands out points to anyone who slows down and reads the stem carefully, and risk management is where that pays off most. The questions rarely ask you to define a term. They describe a company doing something, then ask what the company just demonstrated, or who should have been watching, or which number should have triggered a phone call.&lt;/p&gt;

&lt;p&gt;Two words carry most of that weight. People use them as synonyms in normal conversation. CompTIA does not.&lt;/p&gt;

&lt;h2&gt;
  
  
  Appetite is the plan. Tolerance is how far past the plan you can drift
&lt;/h2&gt;

&lt;p&gt;Risk appetite is the amount of risk an organization is willing to take on deliberately, before anything has gone wrong. A posture, set at the top (by the board, not by the SOC) and written down somewhere.&lt;/p&gt;

&lt;p&gt;The exam gives it three flavors:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Expansionary: growth first, accept more risk to move faster. A startup racing a competitor to launch.&lt;/li&gt;
&lt;li&gt;Conservative: protect what already exists and take on as little as possible. Hospitals and banks, anyone sitting on regulated data.&lt;/li&gt;
&lt;li&gt;Neutral: the middle, and the safe pick when a stem hands you no signal either way.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Tolerance is a different measurement. It is the variance the organization can live with once reality starts pushing on that plan, and it usually runs wider than the appetite. Appetite says we intend to operate here. Tolerance says we can survive drifting out to there before somebody has to act.&lt;/p&gt;

&lt;p&gt;Scenario tell: is the stem describing a decision made in advance, or how far something slipped before anyone escalated? First one is appetite. Second is tolerance.&lt;/p&gt;

&lt;h2&gt;
  
  
  The risk register is a document, and three of its columns get tested
&lt;/h2&gt;

&lt;p&gt;A risk register is the running list of risks tied to a project or an organization, with what each risk is and what is being done about it. It gets updated constantly. Management reads it to decide where money goes.&lt;/p&gt;

&lt;p&gt;Three fields show up in questions far more than the rest.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Risk owner.&lt;/strong&gt; A named person, accountable for that one risk. Not "the security team." Not "IT." Who exactly? The trap is assuming the owner is whoever does the technical work. Ownership usually sits with the person who owns the business function taking the risk, since they are the one who can accept it or fund the fix.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Key risk indicator.&lt;/strong&gt; A metric that warns you a risk is moving the wrong direction while there is still time to do something. That last part is the whole trick. A KRI is early. If the stem describes the outage already in progress or the data already gone, you are past the indicator and into the incident. Failed login attempts climbing week over week is a KRI. The account takeover is not.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Risk threshold.&lt;/strong&gt; The line. Cross it and the response stops being optional. A KRI without a threshold is a chart nobody acts on.&lt;/p&gt;

&lt;h2&gt;
  
  
  Qualitative or quantitative depends on what the stem needs
&lt;/h2&gt;

&lt;p&gt;Qualitative analysis sorts risks into categories. High, medium, low. Red, yellow and green squares on a grid. Fast and subjective. Good enough to triage a hundred risks in an afternoon.&lt;/p&gt;

&lt;p&gt;Quantitative analysis produces a specific dollar value, built from what the asset is worth, how much of that value a single event destroys, and how often the event happens in a year.&lt;/p&gt;

&lt;p&gt;So which one? Not whichever sounds more rigorous. Pick based on what the scenario needs to accomplish. Somebody justifying a forty thousand dollar purchase to a CFO needs a number. Somebody ordering next quarter's backlog needs a ranking. Real programs run both, qualitative to triage everything and quantitative on the handful that have to be defended with math.&lt;/p&gt;

&lt;h2&gt;
  
  
  Assessment cadence is a question by itself
&lt;/h2&gt;

&lt;p&gt;The exam separates assessments by when they happen, and the vocabulary is cheap points.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;One-time: a single event drove it. An acquisition, a new platform.&lt;/li&gt;
&lt;li&gt;Ad hoc: for this purpose only, usually because something just happened.&lt;/li&gt;
&lt;li&gt;Recurring: on a schedule. When a stem mentions a regulation, start here. PCI DSS expects an annual risk assessment from organizations handling cardholder data.&lt;/li&gt;
&lt;li&gt;Continuous: always running.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  What to do with this on exam day
&lt;/h2&gt;

&lt;p&gt;Two questions before you read the answers.&lt;/p&gt;

&lt;p&gt;Is this about the plan or the drift away from it? Plan means appetite. Drift means tolerance, or the threshold that sits inside it.&lt;/p&gt;

&lt;p&gt;Then: is it asking who decides? That is the risk owner. Who watches? The key risk indicator. What number forces somebody to act? The threshold.&lt;/p&gt;

&lt;p&gt;The rest is reps against reworded stems, which is the part nobody enjoys. I built the practice bank at &lt;a href="https://secplusmastery.com" rel="noopener noreferrer"&gt;secplusmastery.com&lt;/a&gt; around that problem, and the &lt;a href="https://secplusmastery.com/diagnostic" rel="noopener noreferrer"&gt;free diagnostic&lt;/a&gt; will tell you whether Domain 5 is actually costing you points or whether the leak is somewhere else.&lt;/p&gt;

&lt;p&gt;Governance questions feel like paperwork, and they are also the cheapest points on the test, because nothing here asks you to recall a port number or trace a packet. Who owns it. How far it can slip. When somebody has to pick up the phone.&lt;/p&gt;

</description>
      <category>security</category>
      <category>cybersecurity</category>
      <category>comptia</category>
      <category>learning</category>
    </item>
  </channel>
</rss>
