The whole first domain of CompTIA Security+ (SY0-701), taught on video and free to watch. No account, no payment. Each lesson names the exact trap CompTIA uses to test the objective, so you recognize it on exam day.
The two axes every control has: category (who enforces it) and type (what it does).
Watch on YouTube (opens in a new tab)CIA triad, AAA, Zero Trust, physical security, and deception tech.
Watch on YouTube (opens in a new tab)Approvals, impact analysis, backout plans, and the technical implications.
Watch on YouTube (opens in a new tab)PKI, encryption, hashing, salting, digital signatures, key exchange, and tools.
Watch on YouTube (opens in a new tab)Prefer to read? Every objective also has a written lesson, practice questions, and a hands-on lab.
Start Domain 1 freeDomain 1 is free for everyone. A SecPlus Mastery plan unlocks all 27 video lessons across Domains 2 to 5, plus the written lessons, labs, and over 1,000 practice questions. Open a domain to see what is inside.
17 min
18 min
19 min
17 min
20 min
20 min
15 min
17 min
16 minUnlock every video lesson with a one-time plan, yours to keep.
Extra videos outside the main course: study tips, tool walkthroughs, and exam-day advice, posted as they are made. Free for everyone, no account needed.
About 95 percent of the web is already encrypted, so the coffee shop hacker a VPN ad warns you about mostly cannot see what you type. What a VPN actually does, when it genuinely helps, and the watcher you would be paying to trust.
Watch on YouTube (opens in a new tab)A stranger called the help desk, said the right words, and walked out with the keys to a company worth billions. No malware, no firewall broken. The six levers of influence behind the 2023 casino breaches, and how you stop a con that targets the person, not the technology.
Watch on YouTube (opens in a new tab)A ransomware gang with a human resources team, an employee of the month, and payday on the 15th, straight from a real leaked chat log. How ransomware as a service became a billion-dollar industry, and the one thing finally breaking it: customers who stop paying.
Watch on YouTube (opens in a new tab)One tap on Approve at 3 a.m. was all it took to breach Uber, and your MFA probably has the same weakness. How push bombing wears people down, why not every kind of MFA is equal, and the one login a phishing site cannot touch.
Watch on YouTube (opens in a new tab)The real dark web is quieter and more fragile than the movies show. Follow one identity-for-sale listing from add to cart to the FBI seizure banner, and see why a place built for anonymity keeps losing to law enforcement. It maps straight to Security+ objective 2.1.
Watch on YouTube (opens in a new tab)An email from your CEO says wire 250,000 dollars today and keep it quiet. He never sent it. How a stranger puts your boss's name at the top of your inbox, why the checks meant to catch it often fail, and the boring habit that does.
Watch on YouTube (opens in a new tab)A stranger calls already knowing your name, your street, and the last four of your card, and you never handed him any of it. We follow one real breached record from the company that lost it to the scam call it becomes, and the free move that breaks the chain.
Watch on YouTube (opens in a new tab)A fish tank robbed a casino. Equifax lost 147 million people. A whole country ran out of gas over one password. Six of the biggest hacks ever, ranked by how small the way in was, with the same boring mistake sitting under every one.
Watch on YouTube (opens in a new tab)Her password was strong and her 2-step was on, and someone on another continent was still reading her email. How a stolen session cookie lets an attacker skip the password and the code entirely, shown live, plus the two free settings that shut it down.
Watch on YouTube (opens in a new tab)A remote developer passed four video interviews, a background check, and reference checks, then loaded malware onto the company laptop 25 minutes after it arrived. The North Korean fake IT worker scheme, the real FBI photo of a laptop farm, and the hiring checks that catch it.
Watch on YouTube (opens in a new tab)The phone never left the nightstand, but by sunrise the bank was logging in from another city. A SIM swap steals your phone number itself, and in 2024 one stranger used it to hijack the U.S. SEC and move the price of Bitcoin. Why text message codes are the weak link, and the two minute fix.
Watch on YouTube (opens in a new tab)Your baby monitor could be helping knock a website offline while the family sleeps, with no break in and no ransom note. How attackers sweep the internet for the factory passwords nobody changed, herd cheap cameras into a botnet, and the two minute fix that pulls yours back out.
Watch on YouTube (opens in a new tab)A cracked app or game cheat can hide an infostealer that copies your saved passwords, autofill cards, and login sessions in seconds. No password guess, no 2FA prompt, and the one habit that shuts it down.
Watch on YouTube (opens in a new tab)One reply to a wrong number text turns into weeks of friendly chat and a fake investment app showing money that was never there. This is pig butchering, and the three tells that stop it before you wire a cent.
Watch on YouTube (opens in a new tab)An employee joined a routine video call with his boss and coworkers, approved one transfer, and the company lost about 25 million dollars. Every other face was a deepfake, and the simple verification habit that would have caught it.
Watch on YouTube (opens in a new tab)A few seconds of audio is enough to clone a voice you trust, then call your family at 2 a.m. begging for money. How voice-cloning scams really work, and the one family safe word that stops them.
Watch on YouTube (opens in a new tab)A fake 'I am not a robot' check quietly drops a command onto your clipboard, then walks you into pasting it and pressing Enter yourself. This is ClickFix, why your antivirus stays quiet, and the rule that stops it.
Watch on YouTube (opens in a new tab)A sticker slapped over a real QR code can take your card details in under a minute, with no email and no link to click. How quishing works, why your phone alone will not save you, and the two-second check that does.
Watch on YouTube (opens in a new tab)Identity theft rarely starts with a hack. It is your own data, leaked in breaches and sold cheap, and the free credit freeze that shuts the whole scheme down.
Watch on YouTube (opens in a new tab)A Flipper Zero, a rubber ducky, a booby-trapped USB cable. The cheap gadgets that walk through the doors you left unlocked, and the habits that close them.
Watch on YouTube (opens in a new tab)HTTPS quietly killed password sniffing. The real danger is the evil twin that becomes the network and feeds you fake pages, and what actually protects you.
Watch on YouTube (opens in a new tab)How attackers turn a stolen hash back into your password, and why length beats complexity for surviving a crack.
Watch on YouTube (opens in a new tab)A real breach traced from the first phishing email to ransomware, and the single habit that breaks the chain.
Watch on YouTube (opens in a new tab)Domain 1 is free, on video and in writing. A SecPlus Mastery plan unlocks Domains 2 to 5, over 1,000 practice questions, timed mock exams, and spaced review across the whole exam, and the new video lessons land for members first.
One-time payment · no subscription · yours to keep
CompTIA and Security+ are trademarks of CompTIA, used here for identification only. SecPlus Mastery is an independent study resource and is not affiliated with or endorsed by CompTIA.