Hardening, critical files and processes
Hardening removes what a system does not need (services, default accounts, open ports) and fixes a baseline such as a CIS Benchmark. For an analyst the baseline matters twice: it shrinks the attack surface, and it gives you something to compare against. Know the places attackers edit: scheduled tasks, services and the hosts file on Windows; /etc/passwd, /etc/shadow, cron and SSH authorized_keys on Linux. Know normal process lineage too: svchost.exe under C:\Windows\System32 is expected, while the same name in a user's Temp folder is a lead.
Cloud, virtualization, containers and APIs
Cloud telemetry comes in two layers. The control plane records who created, changed or deleted resources; the workload layer records what the virtual machine, function or container did. Containers add a lifecycle problem: one image runs as many short-lived instances, so logs have to be shipped off the instance while it runs. APIs are both attack surface and data source, since a gateway can log the caller, the key used and the request rate.
Endpoints and mobile devices
Endpoint and mobile management covers enrollment, configuration profiles, compliance status and remote lock or wipe. Exam options often pair it with endpoint detection and response (EDR): management pushes settings, while EDR records process, file and network events and can isolate a host. The differences between EDR, XDR and SIEM are laid out in SIEM vs SOAR vs EDR.
Identity and access
Authentication proves who someone is; authorization decides what they may do. Privileged access management (PAM) vaults administrator credentials and issues them only for a task. Secrets management does the same for machine credentials (API keys, tokens, database passwords) so they stop living in scripts and code repositories. MFA, single sign-on and federation through SAML or OAuth/OpenID Connect are the methods to recognize.
Encryption and data protection
Match each control to the state of the data: TLS in transit, disk or database encryption at rest, data loss prevention (DLP) watching data in motion. Key handling decides the real protection, because whoever can export a key can read everything it protects.