CompTIA Security+ Domains 4 & 5

COMPTIA · Security+ (SY0-701)

By Mr Sparkles

Log in to rate

operations, governance

Certification Summary

CompTIA Security+ SY0-701 is the standard hurdle for systems administrators and junior security analysts tasked with maintaining basic infrastructure defenses. People sit this exam because their leads view it as a prerequisite for getting access to production environments, often using it to satisfy a checkbox for compliance audits or government contracts.

The exam leans on scenario based questions that force you to prioritize mitigation steps during a simulated breach. Security Operations at 28 percent, Threats, Vulnerabilities, and Mitigations at 22 percent, and Security Program Management and Oversight at 20 percent carry the weight of the assessment. You will also see questions on Security Architecture and General Security Concepts that require you to identify specific cryptographic implementations and the standard access control models defined in the CompTIA framework.

Study

Card 1 of 108

Log in to mark cards as mastered and track progress.

The Imposter Hunt

The Imposter Hunt (Unlocked!)

Prove your knowledge to unlock this challenge.

Test your knowledge and spot the fake definitions.

0% / 75% mastery
0%

Mastery

0 of 108 cards mastered

All cards (108)

Scroll to review fronts and backs

Card 1

Front

SOAR

Back

Security Orchestration Automation and Response. Playbooks that automate enrichment and response steps.

Card 2

Front

EDR

Back

Endpoint Detection and Response. Watches endpoint behavior and can isolate a host.

Card 3

Front

XDR

Back

Extended Detection and Response. Correlates signals across endpoint, network, email, cloud, and more.

Card 4

Front

UEBA

Back

User and Entity Behavior Analytics. Spots weird activity relative to a normal baseline.

Card 5

Front

FIM

Back

File Integrity Monitoring. Alerts when critical files change unexpectedly.

Card 6

Front

MDM

Back

Mobile Device Management. Enforce lock screens, encryption, wipe, and app controls on phones and tablets.

Card 7

Front

BYOD

Back

Bring Your Own Device. Personal device used for work. Needs containers or strong separation.

Card 8

Front

COPE

Back

Corporate Owned Personally Enabled. Company owns the device, employee can still use it personally under policy.

Card 9

Front

Hardening

Back

Reduce attack surface. Patch, disable unused services, kill default accounts, enforce baselines.

Card 10

Front

Secure baseline

Back

Approved minimum config for a system type. Drift detection finds unauthorized changes.

Card 11

Front

Allow list

Back

Only approved apps or traffic are permitted. Deny by default.

Card 12

Front

Patch management

Back

Find, test, deploy, and verify updates that close known vulnerabilities.

Card 13

Front

Credentialed scan

Back

Vuln scan that logs in. Sees patch level and local config better than an outside scan.

Card 14

Front

Non credentialed scan

Back

Outside view of exposed services. Good for what an attacker can see without a login.

Card 15

Front

Vulnerability scan

Back

Automated check for known weaknesses. Does not fully exploit them like a pen test.

Card 16

Front

Penetration test

Back

Authorized attempt to exploit weaknesses and prove real impact. Needs written permission.

Card 17

Front

Red team

Back

Adversary simulation that tests detection and response, not just whether a hole exists.

Card 18

Front

Blue team

Back

Defenders who monitor, detect, and respond.

Card 19

Front

Purple team

Back

Red and blue work together to improve controls and detections faster.

Card 20

Front

IR preparation

Back

Before an incident: plans, contacts, tools, logging, and training.

Card 21

Front

IR identification

Back

Confirm something is an incident, scope it, and assign severity.

Card 22

Front

IR containment

Back

Stop the bleeding. Isolate hosts, disable accounts, block IOCs.

Card 23

Front

IR eradication

Back

Remove the cause. Wipe malware, close the hole, reset credentials.

Card 24

Front

IR recovery

Back

Bring systems back carefully and watch for reinfection.

Card 25

Front

Lessons learned

Back

After action review. Update playbooks and controls so the next event goes better.

Card 26

Front

Chain of custody

Back

Document who handled evidence, when, and why. Breaks in the chain wreck court use.

Card 27

Front

Order of volatility

Back

Collect the most fleeting evidence first: CPU/cache, RAM, network state, then disk, then backups.

Card 28

Front

Write blocker

Back

Hardware or software that lets you read a drive without changing it.

Card 29

Front

Forensic image

Back

Bit for bit copy of media used for analysis while preserving the original.

Card 30

Front

Legal hold

Back

Stop deleting or altering records that may be needed for an investigation or lawsuit.

Card 31

Front

Hash verification

Back

Hash evidence before and after imaging to prove nothing changed.

Card 32

Front

RBAC

Back

Role Based Access Control. Permissions follow job roles.

Card 33

Front

ABAC

Back

Attribute Based Access Control. Decisions use attributes like department, device health, or location.

Card 34

Front

MAC

Back

Mandatory Access Control. System enforced labels. Users cannot casually override them.

Card 35

Front

DAC

Back

Discretionary Access Control. Resource owners decide who gets access. Flexible but messy.

Card 36

Front

PAM

Back

Privileged Access Management. Vaults, session recording, and just in time admin rights.

Card 37

Front

JIT access

Back

Just in time privilege. Temporary elevation instead of permanent admin.

Card 38

Front

SSO

Back

Single Sign On. One login unlocks many apps.

Card 39

Front

Federation

Back

Trust another identity provider for authentication.

Card 40

Front

SAML

Back

XML based federation protocol common for enterprise web SSO.

Card 41

Front

OAuth 2.0

Back

Delegated authorization. Lets an app act with limited access without sharing the user password.

Card 42

Front

OIDC

Back

OpenID Connect. Identity layer on top of OAuth 2.0. This is the login piece.

Card 43

Front

Kerberos

Back

Ticket based network authentication. Core of many Windows domains.

Card 44

Front

RADIUS

Back

Central AAA for VPN, WiFi, and network devices.

Card 45

Front

TACACS+

Back

Device admin AAA that cleanly separates authentication, authorization, and accounting.

Card 46

Front

LDAP

Back

Directory access protocol. Query users and groups. Prefer LDAPS in production.

Card 47

Front

MFA

Back

Multifactor Authentication. Combine factors like something you know, have, and are.

Card 48

Front

FIDO2

Back

Phishing resistant passwordless auth using public key crypto. Often with WebAuthn.

Card 49

Front

Deprovisioning

Back

Remove accounts and access when someone leaves or changes roles. Automate this if you can.

Card 50

Front

SPF

Back

Sender Policy Framework. Lists which servers may send mail for a domain.

Card 51

Front

DKIM

Back

DomainKeys Identified Mail. Cryptographic signature on outbound email.

Card 52

Front

DMARC

Back

Policy and reporting that builds on SPF and DKIM alignment. Helps stop spoofing.

Card 53

Front

Secure email gateway

Back

Filters spam, malware, and phishing before mail hits the inbox.

Card 54

Front

Sandboxing

Back

Detonate a file or URL in an isolated environment before trusting it.

Card 55

Front

Secure Boot

Back

Firmware verifies bootloader signatures so unsigned boot malware has a harder time.

Card 56

Front

Full disk encryption

Back

Encrypt the whole volume so a stolen laptop does not spill plaintext files.

Card 57

Front

Host firewall

Back

Filters traffic on the individual endpoint.

Card 58

Front

Application allow listing

Back

Only approved binaries can run. Strong ransomware control when done well.

Card 59

Front

Impossible travel

Back

Same account appears in distant places too quickly to be real. Strong identity risk signal.

Card 60

Front

Playbook

Back

Repeatable response steps for a known incident type.

Card 61

Front

Policy

Back

High level management statement of intent. What must be true.

Card 62

Front

Standard

Back

Mandatory specific requirement that supports a policy.

Card 63

Front

Procedure

Back

Step by step instructions for how to do something.

Card 64

Front

Baseline

Back

Minimum secure configuration for a system class.

Card 65

Front

Risk

Back

Chance that a threat exploits a vulnerability and causes impact.

Card 66

Front

Threat

Back

Potential cause of harm. Who or what could hurt you.

Card 67

Front

Vulnerability

Back

Weakness that can be exploited.

Card 68

Front

Inherent risk

Back

Risk before you apply controls.

Card 69

Front

Residual risk

Back

Risk left after controls. Someone still owns that leftover.

Card 70

Front

Risk appetite

Back

How much risk leadership is willing to live with.

Card 71

Front

Risk register

Back

Living list of risks, owners, ratings, and treatment status.

Card 72

Front

Avoid risk

Back

Stop doing the risky activity altogether.

Card 73

Front

Mitigate risk

Back

Reduce likelihood or impact with controls.

Card 74

Front

Transfer risk

Back

Shift impact through insurance or contracts.

Card 75

Front

Accept risk

Back

Knowingly keep the residual risk with an owner sign off.

Card 76

Front

SLE

Back

Single Loss Expectancy. Asset value times exposure factor for one incident.

Card 77

Front

ARO

Back

Annualized Rate of Occurrence. How often you expect the incident per year.

Card 78

Front

ALE

Back

Annualized Loss Expectancy. SLE times ARO. Useful for comparing control cost to loss.

Card 79

Front

BIA

Back

Business Impact Analysis. Identifies critical processes and what downtime actually costs.

Card 80

Front

BCP

Back

Business Continuity Plan. Keep the business running through disruption.

Card 81

Front

DRP

Back

Disaster Recovery Plan. Restore IT systems after a disaster.

Card 82

Front

COOP

Back

Continuity of Operations. Keep essential functions going under stress.

Card 83

Front

Due diligence

Back

Research and assessment before you trust a vendor or decision.

Card 84

Front

Due care

Back

Ongoing responsible action after you already know the risks.

Card 85

Front

SLA

Back

Service Level Agreement. Contracted uptime or support expectations.

Card 86

Front

NDA

Back

Nondisclosure Agreement. Contractual secrecy obligations.

Card 87

Front

Right to audit

Back

Contract language letting you assess a vendor security posture.

Card 88

Front

DPA

Back

Data Processing Agreement. Spells out how a vendor may handle personal data.

Card 89

Front

Vendor offboarding

Back

End access, return or destroy data, and close accounts when a vendor relationship ends.

Card 90

Front

SBOM

Back

Software Bill of Materials. Inventory of components in software so you can track inherited risk.

Card 91

Front

PCI DSS

Back

Payment Card Industry Data Security Standard. Rules for handling cardholder data.

Card 92

Front

GDPR

Back

EU privacy regulation for personal data. Consent, rights, and breach notice expectations matter.

Card 93

Front

HIPAA

Back

US health data privacy and security rules for protected health information.

Card 94

Front

NIST

Back

US standards body. Cybersecurity Framework and many SP 800 docs show up on exams.

Card 95

Front

ISO 27001

Back

International standard for an information security management system.

Card 96

Front

SOC 2

Back

Independent report on a service org controls, often used in vendor reviews.

Card 97

Front

Data retention

Back

How long you keep data. Over retention increases breach blast radius.

Card 98

Front

Data sovereignty

Back

Laws of the country where data lives can control how that data may be handled.

Card 99

Front

Awareness training

Back

Teach people how phishing, reporting, and policy look in real life. Humans are a control.

Card 100

Front

Change management

Back

Controlled process for changes: request, approve, test, backout plan, maintenance window.

Card 101

Front

Backout plan

Back

How you reverse a failed change and restore the prior working state.

Card 102

Front

Maintenance window

Back

Scheduled time for disruptive changes with stakeholders warned.

Card 103

Front

Audit

Back

Independent or internal check that controls exist and work as claimed.

Card 104

Front

Evidence

Back

Artifacts that prove a control operated: logs, tickets, screenshots, configs.

Card 105

Front

Incident

Back

A security event that threatens confidentiality, integrity, or availability and needs response.

Card 106

Front

Breach notification

Back

Legal or contractual duty to tell affected parties or regulators after certain incidents.

Card 107

Front

Third party risk

Back

Risk introduced by vendors, partners, and supply chain dependencies.

Card 108

Front

Acceptable use policy

Back

Rules for how employees may use company systems and data.