Every one of these walks through an incident that actually happened, names the technique behind it, and ends on the control that stops it. Each is filed under the SY0-701 objective it maps to, so you can watch the ones that match whatever you are studying this week. Free, no account needed.
Looking for the structured course instead? Domain 1 is taught in full on video, free, and every objective in Domains 2 to 5 has a lesson for members.
17 case studies
A leaked internal chat log shows a ransomware crew running payroll, onboarding, and a support desk. How affiliates rent the tooling, where the money splits, and why falling payment rates are squeezing the whole model.
Watch on YouTube (opens in a new tab)One identity listing followed from a marketplace cart to a seizure banner. What actually changes hands down there, how the markets are structured, and why a network built for anonymity keeps losing to law enforcement.
Watch on YouTube (opens in a new tab)One leaked customer record traced from the company that lost it to the caller who reads your own address back to you. How breach data gets aggregated and resold, and where the chain can be broken.
Watch on YouTube (opens in a new tab)A remote hire cleared four video interviews and a background check, then loaded malware onto the company laptop 25 minutes after it arrived. How the North Korean IT worker scheme is staffed, and which hiring controls catch it.
Watch on YouTube (opens in a new tab)An attacker phoned support, cleared identity verification with details anyone could look up, and walked away with a password reset. The influence techniques behind the 2023 casino intrusions, and the verification steps that break them.
Watch on YouTube (opens in a new tab)A wire request that reads like it came from the CEO usually never touched his mailbox. How display-name spoofing and lookalike domains slip past a reader, where SPF, DKIM, and DMARC stop short, and the out-of-band check that catches the rest.
Watch on YouTube (opens in a new tab)A network-connected fish tank. An unpatched web framework. One reused password. Six well-known breaches ranked by how small the initial entry point was, with the same failure sitting under all of them.
Watch on YouTube (opens in a new tab)A wrong-number text becomes weeks of friendly conversation and an investment app showing balances that never existed. The structure of the con, and the three tells that surface before any money moves.
Watch on YouTube (opens in a new tab)An employee joined a routine call with his CFO and colleagues, approved one transfer, and the company lost about 25 million dollars. Every other participant was synthetic. What the fraud needs to work, and the verification habit that ends it.
Watch on YouTube (opens in a new tab)A few seconds of public audio is enough to clone a voice, and then the call comes in at 2 a.m. from someone you trust. How the tooling works now, and why an agreed family code word beats caller ID.
Watch on YouTube (opens in a new tab)A fake bot check copies a command onto the clipboard and coaches the visitor into pasting it into the Run box. Endpoint tooling stays quiet because the user is the one executing, which is exactly the point.
Watch on YouTube (opens in a new tab)A sticker over a real QR code routes a payment to an attacker page, with no email to inspect and no link text to hover. Why the phone alone will not save you, and the check that takes two seconds.
Watch on YouTube (opens in a new tab)A Flipper Zero, a keystroke-injecting USB stick, a charging cable with a radio inside. What each cheap device really does, which doors it walks through, and the physical controls that close them.
Watch on YouTube (opens in a new tab)A valid session token is proof that someone already logged in, so an attacker holding one never meets the password prompt or the code. How the theft happens, shown live, plus the two settings that shorten the window.
Watch on YouTube (opens in a new tab)A cracked app or game cheat runs code that copies saved passwords, autofill card data, and live session cookies in a single pass. No password guessing and no MFA prompt, because the credentials were already on the machine.
Watch on YouTube (opens in a new tab)HTTPS ended casual password sniffing, so the live risk is the rogue access point that becomes the network and serves its own pages. How an evil twin gets set up, and what genuinely protects a client on it.
Watch on YouTube (opens in a new tab)How a stolen hash becomes a password again through wordlists, mangling rules, and brute force. Then the part the exam tests: why length beats symbol substitution for surviving that process.
Watch on YouTube (opens in a new tab)2 case studies
Roughly 95 percent of the web is already encrypted in transit, which removes most of the threat a VPN ad describes. What the tunnel actually hides, where it still earns its keep, and who you hand your traffic to instead.
Watch on YouTube (opens in a new tab)Identity theft usually starts with data that leaked somewhere else and was resold cheap, not with a fresh hack of you. What sits inside one record, what a thief does with it, and the free freeze that shuts the scheme down.
Watch on YouTube (opens in a new tab)4 case studies
Attackers sweep the internet for factory passwords nobody changed, then herd the devices into a botnet the owner never notices. How the scan works, and the baseline hardening that pulls a device back out of the pool.
Watch on YouTube (opens in a new tab)Repeated push prompts at 3 a.m. wore one contractor down until he tapped Approve. Why push approval is the softest MFA factor, and what number matching and phishing-resistant factors change.
Watch on YouTube (opens in a new tab)Porting a number away from its owner hands over every code sent to it, which is how one attacker hijacked a U.S. SEC account in 2024. What a carrier checks before a port, and the account lock that raises the bar.
Watch on YouTube (opens in a new tab)One real intrusion traced from the opening phishing email through credential theft, lateral movement, and encryption on day 34. Where the timeline left gaps a defender could have used.
Watch on YouTube (opens in a new tab)Case studies show you what an attack looks like. The exam asks you to pick the control that stops it. SecPlus Mastery teaches every objective, then drills you on it with over 1,000 practice questions, timed mock exams, and spaced review.
One-time payment · no subscription · yours to keep
CompTIA and Security+ are trademarks of CompTIA, used here for identification only. SecPlus Mastery is an independent study resource and is not affiliated with or endorsed by CompTIA.