RSS Amplifier

Ford's Notes Newsletter · May 11, 2026

'Break Glass' as an Authentication Technique added to the CompTIA Security+ Exam Objectives

0
Sign in to vote or save

Brian Ford · Ford's Notes Newsletter

I’ve been researching the updated objectives for the upcoming (November 2026) release of the CompTIA Security+ exam. My take is that CompTIA is steadily improving its certifications, moving away from candidates having to memorize facts and instead focusing on how security can, and often is, implemented and where it potentially breaks down. An example of this is adding ‘Glass Break’ or emergency access authentication to the exam objectives.

Emergency access (often called “break-glass” accounts) is not a single authentication technique itself, but rather a privileged access management strategy that uses specific, high-assurance authentication methods to bypass standard, potentially failed, authentication systems during a crisis. It involves creating accounts that are pre-configured to be exempt from standard policies (such as Multi-Factor Authentication (MFA) or single sign-on) that might be disabled during a system outage.

While bypassing standard methods, they use strong, separate credentials, such as dedicated FIDO2 security keys or specialized, non-expiring passwords. Another emergency access technique is to use pre-generated codes for when a network is down, and admins can’t access authentication servers.

These techniques are not for regular use, but rather for emergencies when administrators are locked out. They must be highly monitored, and their use is carefully audited. When I encounter an organization that has implemented some form of privileged access, I view it as a sign of a mature security organization. I believe including this as a topic in the SY0-801 exam will add it to many more security professionals’ toolkits.

No posts

Read the original on fordsnotes.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.