CompTIA Security+ Domains 1- 3
COMPTIA · Security+ (SY0-701)
concepts, threats, architecture
Certification Summary
CompTIA Security+ SY0-701 is the standard hurdle for systems administrators and junior security analysts tasked with maintaining basic infrastructure defenses. People sit this exam because their leads view it as a prerequisite for getting access to production environments, often using it to satisfy a checkbox for compliance audits or government contracts.
The exam leans on scenario based questions that force you to prioritize mitigation steps during a simulated breach. Security Operations at 28 percent, Threats, Vulnerabilities, and Mitigations at 22 percent, and Security Program Management and Oversight at 20 percent carry the weight of the assessment. You will also see questions on Security Architecture and General Security Concepts that require you to identify specific cryptographic implementations and the standard access control models defined in the CompTIA framework.
You have mastered every card in this deck.
Pass complete.
Log in to mark cards as mastered and track progress.
The Imposter Hunt
The Imposter Hunt (Unlocked!)
Prove your knowledge to unlock this challenge.
Test your knowledge and spot the fake definitions.
Log in and master this deck to unlock.
All cards (109)
Scroll to review fronts and backs
Card 1
Front
Confidentiality
Back
Keep data away from people who should not see it. Encryption, access controls, and classification all serve this.
Card 2
Front
Integrity
Back
Data stays accurate and unaltered except by authorized changes. Hashes, signatures, and FIM help prove it.
Card 3
Front
Availability
Back
Systems and data are usable when needed. Think redundancy, backups, patching, and DDoS defenses.
Card 4
Front
Non repudiation
Back
You cannot credibly deny you did something. Digital signatures and solid audit logs are the usual proof.
Card 5
Front
AAA
Back
Authentication, Authorization, Accounting. Prove who you are, what you can do, and keep a record of it.
Card 6
Front
Authentication
Back
Proving identity. Password, cert, token, biometric, or a mix.
Card 7
Front
Authorization
Back
Deciding what an authenticated identity is allowed to do.
Card 8
Front
Least privilege
Back
Give only the access needed for the job. Nothing extra "just in case."
Card 9
Front
Separation of duties
Back
Split critical tasks so one person cannot complete a risky action alone.
Card 10
Front
Defense in depth
Back
Layer controls so one failure does not sink you. Firewall plus EDR plus MFA plus logging, etc.
Card 11
Front
Zero Trust
Back
Never trust by default. Continuously verify user, device, and context no matter where the request comes from.
Card 12
Front
Managerial controls
Back
Policies, standards, risk decisions, awareness programs. People and paperwork side of security.
Card 13
Front
Technical controls
Back
Stuff systems enforce: MFA, ACLs, encryption, EDR, DLP, IDS/IPS.
Card 14
Front
Operational controls
Back
Day to day processes: change management, incident response drills, vulnerability management.
Card 15
Front
Physical controls
Back
Locks, badges, guards, cameras, mantraps, bollards. Tangible protection of facilities and gear.
Card 16
Front
Preventive control
Back
Stops an incident before it happens. Firewall rule, MFA, allow list.
Card 17
Front
Detective control
Back
Finds something that already happened or is happening. SIEM alert, IDS, CCTV review.
Card 18
Front
Corrective control
Back
Fixes after the fact. Restore from backup, patch, reimage.
Card 19
Front
Deterrent control
Back
Discourages an attacker. Warning banner, visible cameras, guards.
Card 20
Front
Compensating control
Back
Alternate control when the preferred one is not feasible. Extra monitoring when MFA cannot be added.
Card 21
Front
Symmetric encryption
Back
Same shared key encrypts and decrypts. Fast for bulk data. AES is the modern default.
Card 22
Front
Asymmetric encryption
Back
Public and private key pair. Great for key exchange, signatures, and identity. RSA and ECC are common.
Card 23
Front
AES
Back
Advanced Encryption Standard. Symmetric block cipher. AES 256 is what you will hear most on the exam.
Card 24
Front
Hashing
Back
One way function that outputs a fixed digest. Used for integrity and password storage. SHA 256 is common.
Card 25
Front
Salting
Back
Random data mixed with a password before hashing so identical passwords do not share the same hash.
Card 26
Front
Key stretching
Back
Run a password hash many times (PBKDF2, bcrypt, scrypt) so offline guessing gets expensive.
Card 27
Front
Digital signature
Back
Hash of data signed with the sender private key. Proves integrity and who signed it.
Card 28
Front
PKI
Back
Public Key Infrastructure. Policies, CAs, and certificates that bind public keys to identities.
Card 29
Front
Certificate Authority
Back
Trusted issuer of digital certificates. Root CA is the trust anchor.
Card 30
Front
CSR
Back
Certificate Signing Request. You send your public key and identity info to a CA to get a cert.
Card 31
Front
CRL
Back
Certificate Revocation List. Published list of certs that were revoked early.
Card 32
Front
OCSP
Back
Online Certificate Status Protocol. Live check of whether a cert is still valid.
Card 33
Front
TPM
Back
Trusted Platform Module. Hardware chip on a device that stores keys and supports secure boot and disk crypto.
Card 34
Front
HSM
Back
Hardware Security Module. Dedicated appliance for generating and guarding enterprise crypto keys.
Card 35
Front
Tokenization
Back
Replace sensitive values with tokens that map back through a vault. Common in payment systems.
Card 36
Front
Threat actor
Back
Anyone or anything that can exploit a vulnerability. Nation states, criminals, insiders, hacktivists, script kiddies.
Card 37
Front
APT
Back
Advanced Persistent Threat. Usually nation state level. Quiet, long dwell, targeted.
Card 38
Front
Hacktivist
Back
Attacks for a cause. Defacements, leaks, and DDoS are typical.
Card 39
Front
Insider threat
Back
Risk from someone with legitimate access. Can be malicious or just careless.
Card 40
Front
Shadow IT
Back
Systems or SaaS people use without IT approval. Convenience first, visibility last.
Card 41
Front
Organized crime
Back
Profit driven groups. Ransomware, fraud, credential theft.
Card 42
Front
Virus
Back
Malware that attaches to a host file and needs that file to run.
Card 43
Front
Worm
Back
Self spreading malware that moves across networks without a user opening a file each time.
Card 44
Front
Trojan
Back
Looks useful or legit, but carries a malicious payload.
Card 45
Front
Ransomware
Back
Encrypts or locks data and demands payment. Immutable backups and least privilege matter a lot.
Card 46
Front
Rootkit
Back
Hides malicious activity deep in the OS. Reimaging is often safer than "cleaning."
Card 47
Front
Logic bomb
Back
Malware that waits for a time or condition before firing.
Card 48
Front
Fileless malware
Back
Lives in memory and abuses trusted tools. Behavior based EDR helps more than simple signatures.
Card 49
Front
Phishing
Back
Broad fraudulent messages, usually email, tricking people into clicking or giving up secrets.
Card 50
Front
Spear phishing
Back
Targeted phishing aimed at a specific person or group.
Card 51
Front
Whaling
Back
Phishing aimed at executives or other high value targets.
Card 52
Front
Vishing
Back
Voice phishing over phone or voicemail.
Card 53
Front
Smishing
Back
Phishing over SMS.
Card 54
Front
BEC
Back
Business Email Compromise. Impersonates a trusted party to push money or data transfers.
Card 55
Front
Pretexting
Back
Builds a fake story to get the victim to cooperate.
Card 56
Front
Tailgating
Back
Following an authorized person into a secure area without badging in.
Card 57
Front
Watering hole
Back
Compromise a site your targets already trust, then wait for them to visit.
Card 58
Front
SQL injection
Back
Malicious input changes a database query. Parameterized queries are the fix.
Card 59
Front
XSS
Back
Cross site scripting. Attacker script runs in another user browser. Encode output and use CSP.
Card 60
Front
SSRF
Back
Server is tricked into calling an attacker chosen URL. Cloud metadata endpoints are a classic target.
Card 61
Front
Privilege escalation
Back
Move from a lower privilege account or process to a higher one.
Card 62
Front
On path attack
Back
Attacker sits between two parties and can read or alter traffic. Old name was MITM.
Card 63
Front
Evil twin
Back
Rogue access point that mimics a real SSID to lure clients.
Card 64
Front
Rogue AP
Back
Unauthorized wireless access point plugged into your network.
Card 65
Front
DDoS
Back
Flood a service from many sources until legit users cannot get through.
Card 66
Front
Password spraying
Back
Try a few common passwords across many accounts to dodge lockouts.
Card 67
Front
Zero day
Back
Vulnerability with no vendor patch yet. Defense in depth matters because you cannot just "update."
Card 68
Front
Supply chain attack
Back
Hit a vendor or update channel so you can reach many downstream customers.
Card 69
Front
IoC
Back
Indicator of Compromise. Evidence that something bad may have happened. Odd traffic, new admin accounts, disabled AV.
Card 70
Front
IaaS
Back
Infrastructure as a Service. You manage OS, apps, and data. Provider owns the hardware layer.
Card 71
Front
PaaS
Back
Platform as a Service. Provider runs more of the stack. You still own apps, data, and access.
Card 72
Front
SaaS
Back
Software as a Service. Provider runs the app. You still own identities, data, and config choices.
Card 73
Front
Shared responsibility
Back
Cloud security split. Provider secures the cloud. You secure what you put in it and how you configure it.
Card 74
Front
Firewall
Back
Filters traffic by rules. NGFW adds app awareness and deeper inspection.
Card 75
Front
WAF
Back
Web Application Firewall. Focused on HTTP attacks like SQLi and XSS.
Card 76
Front
IDS
Back
Intrusion Detection System. Alerts on suspicious activity. Does not block by itself.
Card 77
Front
IPS
Back
Intrusion Prevention System. Inline and can block bad traffic.
Card 78
Front
DMZ
Back
Segment for public facing services so the internet does not talk straight into the internal LAN.
Card 79
Front
VLAN
Back
Logical network segment. Needs routing and firewall policy to actually enforce security.
Card 80
Front
Microsegmentation
Back
Fine grained isolation between workloads, common in virtual and cloud environments.
Card 81
Front
NAC
Back
Network Access Control. Check user or device before granting network access. Often with 802.1X.
Card 82
Front
802.1X
Back
Port based network access control. Supplicant, authenticator, and authentication server.
Card 83
Front
VPN
Back
Encrypted tunnel over an untrusted network. Can be remote access or site to site.
Card 84
Front
IPsec
Back
Network layer VPN suite. Common for site to site tunnels.
Card 85
Front
ZTNA
Back
Zero Trust Network Access. Grants app specific access instead of dumping someone on the whole LAN.
Card 86
Front
Jump host
Back
Hardened admin entry point. Funnel privileged access through one monitored box.
Card 87
Front
CASB
Back
Cloud Access Security Broker. Visibility and control for SaaS use and shadow IT.
Card 88
Front
CSPM
Back
Cloud Security Posture Management. Finds risky cloud configs like public buckets.
Card 89
Front
Fail closed
Back
On failure, deny access or shut down. Safer default for many security devices.
Card 90
Front
RTO
Back
Recovery Time Objective. How long a system can be down before the business is in real trouble.
Card 91
Front
RPO
Back
Recovery Point Objective. How much data loss you can tolerate, measured in time.
Card 92
Front
Hot site
Back
Near ready disaster recovery site with systems and recent data. Fast and expensive.
Card 93
Front
Warm site
Back
Partially ready DR site. Hardware may be there, but data and config still need work.
Card 94
Front
Cold site
Back
Facility with power and space. You bring everything else. Cheap and slow.
Card 95
Front
Full backup
Back
Copy everything selected. Slowest backup, simplest restore.
Card 96
Front
Incremental backup
Back
Only changes since the last backup of any type. Fast backup, more pieces to restore.
Card 97
Front
Data at rest
Back
Stored data on disk, database, or object storage. Encrypt and control access.
Card 98
Front
Data in transit
Back
Data moving across a network. Protect with TLS or VPN.
Card 99
Front
Data in use
Back
Data actively processed in memory or by an app. Access control and secure enclaves matter here.
Card 100
Front
DLP
Back
Data Loss Prevention. Detect or block sensitive data from leaving in email, USB, cloud, etc.
Card 101
Front
Port 22
Back
SSH. Secure remote shell and SFTP. Preferred over Telnet.
Card 102
Front
Port 23
Back
Telnet. Cleartext remote shell. Replace with SSH.
Card 103
Front
Port 80
Back
HTTP. Unencrypted web. Prefer HTTPS on 443.
Card 104
Front
Port 443
Back
HTTPS. Web and APIs over TLS.
Card 105
Front
Port 636
Back
LDAPS. LDAP wrapped in TLS.
Card 106
Front
Port 3389
Back
RDP. Encrypted but high risk if exposed. Restrict, MFA, jump hosts.
Card 107
Front
Port 445
Back
SMB. Windows file sharing. A favorite lateral movement target.
Card 108
Front
Port 53
Back
DNS. Name resolution. Watch it for malware callback patterns too.
Card 109
Front
Port 88
Back
Kerberos. Ticket based auth in Windows domains.