CompTIA Security+ Domains 4 & 5
COMPTIA · Security+ (SY0-701)
operations, governance
Certification Summary
CompTIA Security+ SY0-701 is the standard hurdle for systems administrators and junior security analysts tasked with maintaining basic infrastructure defenses. People sit this exam because their leads view it as a prerequisite for getting access to production environments, often using it to satisfy a checkbox for compliance audits or government contracts.
The exam leans on scenario based questions that force you to prioritize mitigation steps during a simulated breach. Security Operations at 28 percent, Threats, Vulnerabilities, and Mitigations at 22 percent, and Security Program Management and Oversight at 20 percent carry the weight of the assessment. You will also see questions on Security Architecture and General Security Concepts that require you to identify specific cryptographic implementations and the standard access control models defined in the CompTIA framework.
You have mastered every card in this deck.
Pass complete.
Log in to mark cards as mastered and track progress.
The Imposter Hunt
The Imposter Hunt (Unlocked!)
Prove your knowledge to unlock this challenge.
Test your knowledge and spot the fake definitions.
Log in and master this deck to unlock.
All cards (108)
Scroll to review fronts and backs
Card 1
Front
SOAR
Back
Security Orchestration Automation and Response. Playbooks that automate enrichment and response steps.
Card 2
Front
EDR
Back
Endpoint Detection and Response. Watches endpoint behavior and can isolate a host.
Card 3
Front
XDR
Back
Extended Detection and Response. Correlates signals across endpoint, network, email, cloud, and more.
Card 4
Front
UEBA
Back
User and Entity Behavior Analytics. Spots weird activity relative to a normal baseline.
Card 5
Front
FIM
Back
File Integrity Monitoring. Alerts when critical files change unexpectedly.
Card 6
Front
MDM
Back
Mobile Device Management. Enforce lock screens, encryption, wipe, and app controls on phones and tablets.
Card 7
Front
BYOD
Back
Bring Your Own Device. Personal device used for work. Needs containers or strong separation.
Card 8
Front
COPE
Back
Corporate Owned Personally Enabled. Company owns the device, employee can still use it personally under policy.
Card 9
Front
Hardening
Back
Reduce attack surface. Patch, disable unused services, kill default accounts, enforce baselines.
Card 10
Front
Secure baseline
Back
Approved minimum config for a system type. Drift detection finds unauthorized changes.
Card 11
Front
Allow list
Back
Only approved apps or traffic are permitted. Deny by default.
Card 12
Front
Patch management
Back
Find, test, deploy, and verify updates that close known vulnerabilities.
Card 13
Front
Credentialed scan
Back
Vuln scan that logs in. Sees patch level and local config better than an outside scan.
Card 14
Front
Non credentialed scan
Back
Outside view of exposed services. Good for what an attacker can see without a login.
Card 15
Front
Vulnerability scan
Back
Automated check for known weaknesses. Does not fully exploit them like a pen test.
Card 16
Front
Penetration test
Back
Authorized attempt to exploit weaknesses and prove real impact. Needs written permission.
Card 17
Front
Red team
Back
Adversary simulation that tests detection and response, not just whether a hole exists.
Card 18
Front
Blue team
Back
Defenders who monitor, detect, and respond.
Card 19
Front
Purple team
Back
Red and blue work together to improve controls and detections faster.
Card 20
Front
IR preparation
Back
Before an incident: plans, contacts, tools, logging, and training.
Card 21
Front
IR identification
Back
Confirm something is an incident, scope it, and assign severity.
Card 22
Front
IR containment
Back
Stop the bleeding. Isolate hosts, disable accounts, block IOCs.
Card 23
Front
IR eradication
Back
Remove the cause. Wipe malware, close the hole, reset credentials.
Card 24
Front
IR recovery
Back
Bring systems back carefully and watch for reinfection.
Card 25
Front
Lessons learned
Back
After action review. Update playbooks and controls so the next event goes better.
Card 26
Front
Chain of custody
Back
Document who handled evidence, when, and why. Breaks in the chain wreck court use.
Card 27
Front
Order of volatility
Back
Collect the most fleeting evidence first: CPU/cache, RAM, network state, then disk, then backups.
Card 28
Front
Write blocker
Back
Hardware or software that lets you read a drive without changing it.
Card 29
Front
Forensic image
Back
Bit for bit copy of media used for analysis while preserving the original.
Card 30
Front
Legal hold
Back
Stop deleting or altering records that may be needed for an investigation or lawsuit.
Card 31
Front
Hash verification
Back
Hash evidence before and after imaging to prove nothing changed.
Card 32
Front
RBAC
Back
Role Based Access Control. Permissions follow job roles.
Card 33
Front
ABAC
Back
Attribute Based Access Control. Decisions use attributes like department, device health, or location.
Card 34
Front
MAC
Back
Mandatory Access Control. System enforced labels. Users cannot casually override them.
Card 35
Front
DAC
Back
Discretionary Access Control. Resource owners decide who gets access. Flexible but messy.
Card 36
Front
PAM
Back
Privileged Access Management. Vaults, session recording, and just in time admin rights.
Card 37
Front
JIT access
Back
Just in time privilege. Temporary elevation instead of permanent admin.
Card 38
Front
SSO
Back
Single Sign On. One login unlocks many apps.
Card 39
Front
Federation
Back
Trust another identity provider for authentication.
Card 40
Front
SAML
Back
XML based federation protocol common for enterprise web SSO.
Card 41
Front
OAuth 2.0
Back
Delegated authorization. Lets an app act with limited access without sharing the user password.
Card 42
Front
OIDC
Back
OpenID Connect. Identity layer on top of OAuth 2.0. This is the login piece.
Card 43
Front
Kerberos
Back
Ticket based network authentication. Core of many Windows domains.
Card 44
Front
RADIUS
Back
Central AAA for VPN, WiFi, and network devices.
Card 45
Front
TACACS+
Back
Device admin AAA that cleanly separates authentication, authorization, and accounting.
Card 46
Front
LDAP
Back
Directory access protocol. Query users and groups. Prefer LDAPS in production.
Card 47
Front
MFA
Back
Multifactor Authentication. Combine factors like something you know, have, and are.
Card 48
Front
FIDO2
Back
Phishing resistant passwordless auth using public key crypto. Often with WebAuthn.
Card 49
Front
Deprovisioning
Back
Remove accounts and access when someone leaves or changes roles. Automate this if you can.
Card 50
Front
SPF
Back
Sender Policy Framework. Lists which servers may send mail for a domain.
Card 51
Front
DKIM
Back
DomainKeys Identified Mail. Cryptographic signature on outbound email.
Card 52
Front
DMARC
Back
Policy and reporting that builds on SPF and DKIM alignment. Helps stop spoofing.
Card 53
Front
Secure email gateway
Back
Filters spam, malware, and phishing before mail hits the inbox.
Card 54
Front
Sandboxing
Back
Detonate a file or URL in an isolated environment before trusting it.
Card 55
Front
Secure Boot
Back
Firmware verifies bootloader signatures so unsigned boot malware has a harder time.
Card 56
Front
Full disk encryption
Back
Encrypt the whole volume so a stolen laptop does not spill plaintext files.
Card 57
Front
Host firewall
Back
Filters traffic on the individual endpoint.
Card 58
Front
Application allow listing
Back
Only approved binaries can run. Strong ransomware control when done well.
Card 59
Front
Impossible travel
Back
Same account appears in distant places too quickly to be real. Strong identity risk signal.
Card 60
Front
Playbook
Back
Repeatable response steps for a known incident type.
Card 61
Front
Policy
Back
High level management statement of intent. What must be true.
Card 62
Front
Standard
Back
Mandatory specific requirement that supports a policy.
Card 63
Front
Procedure
Back
Step by step instructions for how to do something.
Card 64
Front
Baseline
Back
Minimum secure configuration for a system class.
Card 65
Front
Risk
Back
Chance that a threat exploits a vulnerability and causes impact.
Card 66
Front
Threat
Back
Potential cause of harm. Who or what could hurt you.
Card 67
Front
Vulnerability
Back
Weakness that can be exploited.
Card 68
Front
Inherent risk
Back
Risk before you apply controls.
Card 69
Front
Residual risk
Back
Risk left after controls. Someone still owns that leftover.
Card 70
Front
Risk appetite
Back
How much risk leadership is willing to live with.
Card 71
Front
Risk register
Back
Living list of risks, owners, ratings, and treatment status.
Card 72
Front
Avoid risk
Back
Stop doing the risky activity altogether.
Card 73
Front
Mitigate risk
Back
Reduce likelihood or impact with controls.
Card 74
Front
Transfer risk
Back
Shift impact through insurance or contracts.
Card 75
Front
Accept risk
Back
Knowingly keep the residual risk with an owner sign off.
Card 76
Front
SLE
Back
Single Loss Expectancy. Asset value times exposure factor for one incident.
Card 77
Front
ARO
Back
Annualized Rate of Occurrence. How often you expect the incident per year.
Card 78
Front
ALE
Back
Annualized Loss Expectancy. SLE times ARO. Useful for comparing control cost to loss.
Card 79
Front
BIA
Back
Business Impact Analysis. Identifies critical processes and what downtime actually costs.
Card 80
Front
BCP
Back
Business Continuity Plan. Keep the business running through disruption.
Card 81
Front
DRP
Back
Disaster Recovery Plan. Restore IT systems after a disaster.
Card 82
Front
COOP
Back
Continuity of Operations. Keep essential functions going under stress.
Card 83
Front
Due diligence
Back
Research and assessment before you trust a vendor or decision.
Card 84
Front
Due care
Back
Ongoing responsible action after you already know the risks.
Card 85
Front
SLA
Back
Service Level Agreement. Contracted uptime or support expectations.
Card 86
Front
NDA
Back
Nondisclosure Agreement. Contractual secrecy obligations.
Card 87
Front
Right to audit
Back
Contract language letting you assess a vendor security posture.
Card 88
Front
DPA
Back
Data Processing Agreement. Spells out how a vendor may handle personal data.
Card 89
Front
Vendor offboarding
Back
End access, return or destroy data, and close accounts when a vendor relationship ends.
Card 90
Front
SBOM
Back
Software Bill of Materials. Inventory of components in software so you can track inherited risk.
Card 91
Front
PCI DSS
Back
Payment Card Industry Data Security Standard. Rules for handling cardholder data.
Card 92
Front
GDPR
Back
EU privacy regulation for personal data. Consent, rights, and breach notice expectations matter.
Card 93
Front
HIPAA
Back
US health data privacy and security rules for protected health information.
Card 94
Front
NIST
Back
US standards body. Cybersecurity Framework and many SP 800 docs show up on exams.
Card 95
Front
ISO 27001
Back
International standard for an information security management system.
Card 96
Front
SOC 2
Back
Independent report on a service org controls, often used in vendor reviews.
Card 97
Front
Data retention
Back
How long you keep data. Over retention increases breach blast radius.
Card 98
Front
Data sovereignty
Back
Laws of the country where data lives can control how that data may be handled.
Card 99
Front
Awareness training
Back
Teach people how phishing, reporting, and policy look in real life. Humans are a control.
Card 100
Front
Change management
Back
Controlled process for changes: request, approve, test, backout plan, maintenance window.
Card 101
Front
Backout plan
Back
How you reverse a failed change and restore the prior working state.
Card 102
Front
Maintenance window
Back
Scheduled time for disruptive changes with stakeholders warned.
Card 103
Front
Audit
Back
Independent or internal check that controls exist and work as claimed.
Card 104
Front
Evidence
Back
Artifacts that prove a control operated: logs, tickets, screenshots, configs.
Card 105
Front
Incident
Back
A security event that threatens confidentiality, integrity, or availability and needs response.
Card 106
Front
Breach notification
Back
Legal or contractual duty to tell affected parties or regulators after certain incidents.
Card 107
Front
Third party risk
Back
Risk introduced by vendors, partners, and supply chain dependencies.
Card 108
Front
Acceptable use policy
Back
Rules for how employees may use company systems and data.