Career Employer

Your FREE Security+ Flashcards 2026 – 300+ Cards

Realistic, Security+ exam-style flashcards across all 5 SY0-701 domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer CompTIA Security+”

By

Click Study Flashcards above to open the flashcard hub — hundreds of Security+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official SY0-701 domains, so you study exactly what the exam tests.[2]

Pair them with our free practice test and study guide. Want extra insurance for exam day? Capital Prep’s CompTIA Security+ premium study materials come with a CompTIA Security+ exam pass guarantee: your money back if you don’t pass, plus up to $439 toward your retake fee — and Career Employer students get a special discount.

CompTIA Security+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.

Security+ Flashcard Study Modes

Flip mode lets you read a front, think, then check the back at your own pace. Match turns the deck into a timed pairing game against the clock. Type shows a definition and asks you to spell the term back, so a card like EDR has to come from memory. Quiz builds multiple choice questions from the same 325 cards.

Free CompTIA Security+ flashcards from Career Employer — active recall for the SY0-701 exam

Why Flashcards Work for Security+

Security Operations carries the heaviest weight on the exam at 28 percent, and it is the largest slice of the deck with 72 cards. The terms here cover monitoring, endpoint defense, identity, and email hardening, so you get acronyms such as MDM and XDR alongside detection and integrity cards like FIM, plus SSO and SPF for access and mail authentication.

Threats, Vulnerabilities & Mitigations is worth 22 percent and holds 70 cards. Expect malware families and attack techniques stated plainly, from Worm and Rootkit to social engineering entries like Vishing, along with remediation-style prompts such as XSS fix that ask what actually stops the attack rather than what it is called.

Security Program Management & Oversight accounts for 20 percent of the exam and 59 cards. This is governance, risk math, and agreements. Risk quantification cards like SLE, ARO, and ALE sit next to contract vocabulary such as MSA and BPA, with SDLC covering how security fits into development process oversight.

Security Architecture is 18 percent with 56 cards on network and system design. You work through boundary and inspection devices including DMZ, WAF, IDS, and IPS, protective controls such as DLP, and resilience or platform terms like UPS and IoT that show up in design and placement questions.

General Security Concepts is weighted at 12 percent but still brings 68 cards, mostly cryptography and trust infrastructure. Symmetric and asymmetric algorithms such as AES, RSA, and ECC appear beside hashing with MD5, certificate lifecycle terms including CSR and CRL, and hardware trust with TPM.

Security+ is dense with terminology — attack types, malware families, cryptography, network appliances, access-control models, and GRC acronyms.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

Security+ Flashcards by Domain

The cards are organized by the five official SY0-701 domains. Drill the highest-weighted ones first — Security Operations and Threats, Vulnerabilities & Mitigations make up half the exam:[2]

Security+ flashcards by domain and weight
DomainExam weight
Security Operations28%
Threats, Vulnerabilities & Mitigations22%
Security Program Management & Oversight20%
Security Architecture18%
General Security Concepts12%

How to Get the Most Out of These Flashcards

  • Start where the weight is. Security Operations is 28 percent of the exam and 72 cards, so run that domain in Flip first and do not move on until the backs feel predictable.
  • Type-drill the acronyms you confuse. Cards like XDR and EDR, or SPF inside the mail cluster, reward exact recall, and typing exposes the ones you only half know.
  • Use Match for malware and device families. Pairing Worm, Trojan, and Botnet against their definitions under time pressure builds the fast sorting the Threats, Vulnerabilities & Mitigations questions expect.
  • Switch to the practice test after Quiz stabilizes. Once Quiz stops surprising you across all five domains, move to scenario questions and use the study guide to fill whatever the results expose.
  • Rotate domains, do not binge one. With 325 cards, run one domain plus a short Match round on a weaker domain each session, and revisit Security Program Management & Oversight risk math often.

Security+ Flashcards FAQ

Hundreds of free Security+ flashcards, organized across all five SY0-701 domains — General Security Concepts, Threats/Vulnerabilities/Mitigations, Security Architecture, Security Operations, and Security Program Management & Oversight. They're free with no account required.

CompTIA Security+ flashcard bank

All 325 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

General Security Concepts (68)

CIA triad
Show answer

Confidentiality, Integrity, Availability — the three core goals of information security.

Confidentiality
Show answer

Ensuring only authorized people can read data; enforced by encryption and access control.

Integrity
Show answer

Ensuring data is accurate and unaltered; enforced by hashing and digital signatures.

Availability
Show answer

Ensuring authorized users can access data when needed; enforced by redundancy and backups.

Non-repudiation
Show answer

Assurance that someone cannot deny an action they performed; provided by digital signatures and logging.

AAA
Show answer

Authentication (prove identity), Authorization (grant rights), and Accounting (log activity).

Authentication
Show answer

Verifying that a subject is who it claims to be (e.g., with a password, token, or biometric).

Authorization
Show answer

Granting an authenticated subject the rights to access specific resources.

Accounting (auditing)
Show answer

Recording what authenticated subjects do, for tracking and forensics.

Authentication vs. authorization
Show answer

Authentication proves WHO you are; authorization decides WHAT you may access.

Technical control
Show answer

A safeguard implemented by technology — firewall, encryption, MFA, antivirus.

Managerial control
Show answer

An administrative safeguard — policies, risk assessments, security planning.

Operational control
Show answer

A safeguard carried out by people — awareness training, guard duty, config management.

Physical control
Show answer

A tangible safeguard — locks, fences, badges, cameras, bollards.

Preventive control
Show answer

A control that stops an incident before it happens (e.g., a firewall rule or a lock).

Deterrent control
Show answer

A control that discourages an attacker (e.g., a warning sign or lighting).

Detective control
Show answer

A control that identifies an incident during or after it (e.g., an IDS or log review).

Corrective control
Show answer

A control that fixes or limits damage after an event (e.g., restoring a backup).

Compensating control
Show answer

An alternative control used when the primary control isn't feasible.

Directive control
Show answer

A control that directs behavior, such as a policy or procedure.

Zero Trust
Show answer

A model that removes implicit trust and verifies every request — 'never trust, always verify.'

Control plane (Zero Trust)
Show answer

The 'brain' that makes access decisions: the Policy Engine and Policy Administrator.

Data plane (Zero Trust)
Show answer

The part that enforces decisions on each request via the Policy Enforcement Point (PEP).

Policy Engine (PE)
Show answer

The Zero Trust component that decides to grant or deny access based on policy and context.

Policy Enforcement Point (PEP)
Show answer

The Zero Trust component that allows or blocks each actual request to a resource.

Adaptive identity
Show answer

Adjusting authentication requirements based on context and risk (a Zero Trust concept).

Implicit trust zone
Show answer

An area where access is trusted by default — what Zero Trust seeks to eliminate.

Honeypot
Show answer

A decoy system that lures attackers away from real assets and records their behavior.

Honeynet
Show answer

A network of honeypots that mimics a real environment to study attackers.

Honeyfile
Show answer

A bait file (e.g., 'passwords.xlsx') that triggers an alert when accessed.

Honeytoken
Show answer

Fake data (a credential, record, or API key) that signals compromise when used.

Symmetric encryption
Show answer

Encryption using one shared secret key to both encrypt and decrypt; fast (e.g., AES).

Asymmetric encryption
Show answer

Encryption using a public/private key pair; one key encrypts, the other decrypts (e.g., RSA, ECC).

AES
Show answer

Advanced Encryption Standard — the dominant symmetric block cipher (128/192/256-bit keys).

RSA
Show answer

A widely used asymmetric algorithm for key exchange and digital signatures.

ECC
Show answer

Elliptic Curve Cryptography — asymmetric crypto giving strong security with smaller keys.

Diffie-Hellman
Show answer

A key-exchange method that lets two parties derive a shared secret over an insecure channel.

Hashing
Show answer

A one-way function producing a fixed-length digest; used for integrity, not reversible.

SHA-256
Show answer

A secure hashing algorithm producing a 256-bit digest, used for integrity verification.

MD5
Show answer

An obsolete hash function, broken by collisions — should not be used for security.

Salting
Show answer

Adding unique random data to a password before hashing so identical passwords differ.

Key stretching
Show answer

Repeatedly hashing a password (e.g., bcrypt, PBKDF2, Argon2) to slow brute-force attacks.

Digital signature
Show answer

A message hash encrypted with the signer's private key; proves integrity and authenticity.

Public key — when to use
Show answer

Encrypt FOR someone with their public key; verify a signature with the signer's public key.

Private key — when to use
Show answer

Decrypt what was sent to you; SIGN messages with your own private key.

Hybrid encryption
Show answer

Use asymmetric crypto to exchange a fast symmetric session key, then symmetric for the data (TLS).

PKI
Show answer

Public Key Infrastructure — the CAs, policies, and keys that issue and manage digital certificates.

Certificate Authority (CA)
Show answer

A trusted entity that issues and signs digital certificates.

Root CA
Show answer

The top, self-signed CA in a trust chain; usually kept offline for protection.

Intermediate CA
Show answer

A CA signed by the root that issues end-entity certificates to protect the root key.

Digital certificate (X.509)
Show answer

A file binding a public key to a verified identity, signed by a CA.

CSR
Show answer

Certificate Signing Request — a request sent to a CA to issue a certificate for a public key.

CRL
Show answer

Certificate Revocation List — a published list of certificates the CA has revoked.

OCSP
Show answer

Online Certificate Status Protocol — a real-time query to check if a certificate is revoked.

Certificate pinning
Show answer

Associating a host with its expected certificate/key to resist fraudulent certs.

Wildcard certificate
Show answer

A certificate that secures a domain and all its subdomains (e.g., *.example.com).

TPM
Show answer

Trusted Platform Module — a hardware chip that securely stores keys and supports disk encryption.

HSM
Show answer

Hardware Security Module — a tamper-resistant device for generating and storing keys.

Secure enclave
Show answer

An isolated hardware region that protects data and keys even from the host OS.

Key escrow
Show answer

Storing a copy of keys with a trusted third party so data can be recovered if a key is lost.

Steganography
Show answer

Hiding data inside other data (e.g., within an image) so its existence is concealed.

Obfuscation
Show answer

Making data or code hard to understand to slow analysis (not true encryption).

Blockchain
Show answer

A distributed, append-only ledger secured by hashing and consensus.

Tokenization (crypto)
Show answer

Replacing sensitive data with a non-sensitive token mapped to the real value stored securely.

Cipher suite
Show answer

The set of algorithms (key exchange, encryption, hashing) negotiated for a TLS session.

Perfect forward secrecy
Show answer

Using ephemeral keys so a compromised long-term key can't decrypt past sessions.

Change management
Show answer

A structured process to approve, document, test, and roll back changes safely.

Gap analysis
Show answer

Comparing the current security posture to a desired state to find what's missing.

Threats, Vulnerabilities & Mitigations (70)

Phishing
Show answer

A fraudulent message (usually email) that tricks the victim into revealing credentials or running malware.

Vishing
Show answer

Voice phishing — a social-engineering attack carried out over a phone call.

Smishing
Show answer

SMS phishing — a social-engineering attack delivered by text message.

Spear phishing
Show answer

A phishing attack targeted at a specific individual using personalized details.

Whaling
Show answer

A phishing attack that specifically targets high-value executives.

Business email compromise (BEC)
Show answer

Impersonating a trusted executive or vendor to authorize fraudulent payments.

Pretexting
Show answer

Inventing a believable scenario or pretext to manipulate a victim into cooperating.

Pharming
Show answer

Redirecting users from a legitimate site to a fake one, often via poisoned DNS.

Watering hole attack
Show answer

Compromising a website the target group is known to visit, to infect them.

Typosquatting
Show answer

Registering misspelled domains to catch users who mistype a URL.

Impersonation
Show answer

Pretending to be someone trusted to gain access or information.

Tailgating
Show answer

Following an authorized person through a secure door without credentials.

Dumpster diving
Show answer

Searching discarded materials for sensitive information.

Shoulder surfing
Show answer

Observing someone's screen or keypad to steal credentials or data.

Disinformation/misinformation
Show answer

Spreading false content to manipulate beliefs or actions.

Threat actor
Show answer

An individual or group that carries out an attack.

Nation-state actor
Show answer

A government-sponsored, highly resourced threat actor; usually motivated by espionage.

Advanced persistent threat (APT)
Show answer

A skilled, well-resourced adversary that maintains long-term stealthy access.

Organized crime
Show answer

A profit-driven, well-funded threat actor group.

Hacktivist
Show answer

An attacker motivated by a political or social cause.

Insider threat
Show answer

A current/former employee or partner who misuses authorized access.

Unskilled attacker
Show answer

A 'script kiddie' who uses others' tools without deep expertise.

Shadow IT
Show answer

Hardware, software, or services used without IT/security approval.

Threat vector
Show answer

The path or means an attacker uses to gain access (email, USB, supply chain).

Attack surface
Show answer

The total set of points where an attacker could try to enter or extract data.

Supply chain attack
Show answer

Compromising a trusted vendor, MSP, or software update to reach the target.

Malware
Show answer

Malicious software — ransomware, trojans, worms, viruses, spyware, rootkits, keyloggers.

Ransomware
Show answer

Malware that encrypts data and demands payment for the decryption key.

Double extortion
Show answer

Ransomware that also steals data and threatens to leak it if unpaid.

Trojan
Show answer

Malware disguised as legitimate software that hides a malicious payload.

Worm
Show answer

Self-replicating malware that spreads across networks without user action.

Virus
Show answer

Malware that attaches to a host file and spreads when that file is executed.

Spyware
Show answer

Malware that secretly gathers information about a user or system.

Keylogger
Show answer

Malware or hardware that records keystrokes to steal credentials.

Rootkit
Show answer

Malware that hides at a privileged level (often the kernel) to maintain stealthy access.

Logic bomb
Show answer

Malicious code that executes when a specific condition or time is met.

Bloatware
Show answer

Unwanted pre-installed software that expands the attack surface.

Fileless malware
Show answer

Malware that runs in memory using legitimate tools, leaving little on disk.

Botnet
Show answer

A network of compromised devices controlled by an attacker (often for DDoS).

Buffer overflow
Show answer

Writing more data than a buffer holds, overwriting adjacent memory to run code.

Race condition (TOCTOU)
Show answer

A timing flaw between time-of-check and time-of-use that can be exploited.

Memory injection
Show answer

Inserting malicious code into a running process's memory space.

SQL injection
Show answer

Inserting malicious SQL into input so the database runs unintended commands.

SQL injection fix
Show answer

Use parameterized queries (prepared statements) plus input validation.

Cross-site scripting (XSS)
Show answer

Injecting script into a trusted site that runs in another user's browser.

XSS fix
Show answer

Output encoding, input validation, and a Content Security Policy (CSP).

Cross-site request forgery (CSRF)
Show answer

Tricking a logged-in user's browser into sending an unwanted authenticated request.

Zero-day
Show answer

A vulnerability unknown to the vendor with no patch available yet.

Misconfiguration
Show answer

An insecure default or setting; a leading cause of breaches.

Default credentials
Show answer

Factory usernames/passwords left unchanged — an easy attacker entry point.

VM escape
Show answer

Breaking out of a virtual machine to access the hypervisor or host.

On-path attack
Show answer

An attacker secretly relays or alters traffic between two parties (formerly MITM).

Replay attack
Show answer

Capturing and re-sending valid data (e.g., a session token) to impersonate a user.

DNS poisoning
Show answer

Corrupting DNS records to redirect users to malicious sites.

ARP poisoning
Show answer

Sending forged ARP messages to associate the attacker's MAC with another IP.

DDoS attack
Show answer

Overwhelming a target with traffic from many sources to deny service.

Amplification attack
Show answer

Using a service to multiply traffic volume toward a victim (a DDoS technique).

Privilege escalation
Show answer

Gaining higher rights than granted — vertical (to admin) or horizontal (to a peer).

Password spraying
Show answer

Trying a few common passwords against many accounts to avoid lockouts.

Brute-force attack
Show answer

Systematically trying many passwords or keys until one works.

Dictionary attack
Show answer

Trying passwords from a list of likely words.

Rainbow table
Show answer

A precomputed table of hashes used to crack unsalted password hashes.

Indicator of compromise (IoC)
Show answer

An artifact (IP, hash, behavior) suggesting a system was breached.

Mitigation: segmentation
Show answer

Dividing a network into zones to limit how far an attacker can move.

Mitigation: least privilege
Show answer

Granting only the minimum access needed to limit the blast radius.

Mitigation: patching
Show answer

Applying updates to fix known vulnerabilities.

Mitigation: hardening
Show answer

Removing unneeded services/accounts and applying secure baselines.

Application allow list
Show answer

Permitting only approved software to run (stronger than block-listing).

Sandboxing
Show answer

Running untrusted code in an isolated environment to contain harm.

Defense in depth
Show answer

Layering multiple independent controls so one failure isn't a breach.

Security Architecture (56)

Shared responsibility model
Show answer

Cloud split: provider secures the infrastructure; customer secures data, identity, and config.

Security OF vs. IN the cloud
Show answer

Provider = security OF the cloud (infrastructure); customer = security IN the cloud (data/config).

IaaS
Show answer

Infrastructure as a Service — customer manages OS, apps, and data (most responsibility).

PaaS
Show answer

Platform as a Service — provider manages the platform; customer manages apps and data.

SaaS
Show answer

Software as a Service — provider manages almost everything; customer manages data and access.

Virtualization
Show answer

Running multiple guest operating systems on one physical host via a hypervisor.

Hypervisor
Show answer

Software that creates and runs virtual machines (Type 1 bare-metal or Type 2 hosted).

Containerization
Show answer

Packaging an app with its dependencies in an isolated container sharing the host kernel.

Serverless
Show answer

Running code as functions without managing servers; the provider scales it.

Microservices
Show answer

Building an app as small, independently deployable services.

Infrastructure as Code (IaC)
Show answer

Provisioning infrastructure from version-controlled machine-readable files.

Software-defined networking (SDN)
Show answer

Centrally programming network behavior via software, separate from hardware.

IoT
Show answer

Internet of Things — networked everyday devices, often with weak built-in security.

ICS/SCADA
Show answer

Industrial control systems that run physical processes; hard to patch, need segmentation.

Embedded system
Show answer

A purpose-built computer inside a device, often with limited update ability.

Security zone
Show answer

A network segment grouped by trust level to control traffic between areas.

DMZ
Show answer

A perimeter network segment that hosts public-facing services, isolated from the internal LAN.

Firewall
Show answer

A device that filters network traffic based on rules to enforce a security boundary.

Next-generation firewall (NGFW)
Show answer

A firewall adding application awareness, deep inspection, and threat intel.

WAF
Show answer

Web Application Firewall — protects web apps from layer-7 attacks like injection and XSS.

UTM
Show answer

Unified Threat Management — one appliance combining firewall, IPS, AV, filtering, and more.

IDS
Show answer

Intrusion Detection System — detects and alerts on suspicious traffic (passive).

IPS
Show answer

Intrusion Prevention System — detects and blocks suspicious traffic inline (active).

IDS vs. IPS
Show answer

IDS only detects/alerts (passive); IPS sits inline and can block (active).

Proxy server
Show answer

An intermediary that mediates and can filter client requests to other servers.

Jump server
Show answer

A hardened pivot host used to administer systems in a secure zone.

Load balancer
Show answer

Distributes traffic across multiple servers for availability and scale.

Fail-open vs. fail-closed
Show answer

Fail-open allows traffic on failure (availability); fail-closed blocks it (security).

Active vs. passive (sensor)
Show answer

Active devices sit inline and can act; passive devices observe via a tap or span port.

802.1X
Show answer

A port-based network access control standard that authenticates devices before granting access.

Port security
Show answer

Limiting which devices (by MAC) can connect to a switch port.

Data at rest
Show answer

Data stored on disk, database, or backup; protected with encryption and access control.

Data in transit
Show answer

Data moving across a network; protected with TLS or VPN encryption.

Data in use
Show answer

Data actively processed in memory; protected by techniques like secure enclaves.

Data classification
Show answer

Labeling data by sensitivity (public, sensitive, confidential, critical) to set controls.

Data masking
Show answer

Hiding part of a data value (e.g., showing only the last four digits).

Tokenization
Show answer

Replacing sensitive data with a non-sensitive token; the real value is stored securely.

DLP
Show answer

Data Loss Prevention — detects and blocks unauthorized movement of sensitive data.

Data sovereignty
Show answer

The principle that data is subject to the laws of the country where it resides.

High availability (HA)
Show answer

Designing systems to stay operational with minimal downtime via redundancy.

Clustering
Show answer

Linking servers so they act as one resilient unit, with failover.

Load balancing vs. clustering
Show answer

Load balancing spreads traffic; clustering provides coordinated failover/redundancy.

Hot site
Show answer

A fully equipped alternate site ready for near-instant failover (most expensive).

Warm site
Show answer

A partially equipped recovery site needing some setup before use.

Cold site
Show answer

A recovery site with space and power only; longest to bring online (cheapest).

Geographic dispersion
Show answer

Placing redundant systems in different locations to survive regional disasters.

RAID
Show answer

Redundant Array of Independent Disks — combines drives for redundancy and/or performance.

UPS
Show answer

Uninterruptible Power Supply — battery backup that keeps systems up during short outages.

3-2-1 backup rule
Show answer

Keep 3 copies of data, on 2 media types, with 1 copy offsite.

RTO
Show answer

Recovery Time Objective — the maximum acceptable time to restore a system.

RPO
Show answer

Recovery Point Objective — the maximum acceptable data loss, measured back to the last backup.

RTO vs. RPO
Show answer

RTO = how fast you recover (downtime); RPO = how much data you can lose.

MTBF
Show answer

Mean Time Between Failures — average time a system runs before failing.

MTTR
Show answer

Mean Time To Repair — average time to restore a failed system.

Snapshot
Show answer

A point-in-time copy of a system or volume for quick recovery.

Journaling
Show answer

Logging changes so a system can be restored to a consistent state after a crash.

Security Operations (72)

Hardening
Show answer

Reducing attack surface by removing unneeded services/accounts and applying secure baselines.

Secure baseline
Show answer

A standard, approved secure configuration applied to systems.

MDM
Show answer

Mobile Device Management — centrally enforces policies and security on mobile devices.

BYOD
Show answer

Bring Your Own Device — employees use personal devices for work (higher risk).

COPE
Show answer

Corporate-Owned, Personally Enabled — company device usable for personal tasks.

WPA3
Show answer

The current secure Wi-Fi protocol; uses SAE to resist offline password cracking.

SAE
Show answer

Simultaneous Authentication of Equals — WPA3's secure key-exchange handshake.

Sanitization
Show answer

Securely erasing or destroying media so data can't be recovered before disposal.

Asset inventory
Show answer

A maintained list of hardware/software assets, essential to securing them.

Vulnerability scan
Show answer

An automated check that identifies known weaknesses in systems.

Penetration test
Show answer

An authorized simulated attack that actually exploits weaknesses to prove risk.

Vuln scan vs. pen test
Show answer

A scan only identifies weaknesses; a pen test exploits them.

CVE
Show answer

Common Vulnerabilities and Exposures — a public catalog of unique vulnerability IDs.

CVSS
Show answer

Common Vulnerability Scoring System — a 0–10 severity score for a vulnerability.

False positive
Show answer

A reported vulnerability/alert that isn't actually a real issue.

False negative
Show answer

A real vulnerability or attack that the tool failed to detect (dangerous).

Responsible disclosure
Show answer

Reporting a vulnerability privately to the vendor before public release.

Bug bounty
Show answer

A program that pays outside researchers for responsibly reported vulnerabilities.

Remediation
Show answer

Fixing a vulnerability by patching, reconfiguring, or applying a compensating control.

Rescanning/validation
Show answer

Re-scanning after remediation to confirm the fix actually worked.

SIEM
Show answer

Security Information and Event Management — aggregates and correlates logs to detect threats.

Log aggregation
Show answer

Centralizing logs from many sources for correlation and analysis.

Alert tuning
Show answer

Adjusting detection rules to cut false positives and reduce alert fatigue.

SNMP
Show answer

Simple Network Management Protocol — monitors and manages network devices.

NetFlow
Show answer

A protocol that records IP traffic flow data for monitoring and analysis.

SOAR
Show answer

Security Orchestration, Automation, and Response — automates response via playbooks.

EDR
Show answer

Endpoint Detection and Response — monitors endpoints to detect and respond to threats.

XDR
Show answer

Extended Detection and Response — correlates detection across endpoints, network, and cloud.

FIM
Show answer

File Integrity Monitoring — alerts when critical files change unexpectedly.

Antivirus/anti-malware
Show answer

Software that detects and removes malicious code on endpoints.

Web filtering
Show answer

Blocking access to malicious or disallowed websites.

DNS filtering
Show answer

Blocking resolution of known-malicious domains.

SPF
Show answer

Sender Policy Framework — lists which mail servers may send for a domain.

DKIM
Show answer

DomainKeys Identified Mail — cryptographically signs email to prove it wasn't altered.

DMARC
Show answer

Ties SPF and DKIM together and tells receivers how to handle failures (anti-spoofing).

SPF/DKIM/DMARC
Show answer

The email-authentication trio that fights spoofing and phishing.

Identity and access management (IAM)
Show answer

Policies and tools that manage identities and control access.

Provisioning/deprovisioning
Show answer

Creating accounts on hire and promptly removing them on departure.

Identity proofing
Show answer

Verifying a person's real-world identity before issuing credentials.

SSO
Show answer

Single Sign-On — one authentication grants access to multiple systems.

Federation
Show answer

Trusting identities from another domain to access resources (e.g., SAML, OIDC).

SAML
Show answer

Security Assertion Markup Language — an XML standard for federated SSO.

OAuth
Show answer

An authorization framework that lets apps access resources without sharing passwords.

OpenID Connect (OIDC)
Show answer

An authentication layer built on OAuth 2.0 for verifying identity.

LDAP
Show answer

Lightweight Directory Access Protocol — queries and manages directory information.

Kerberos
Show answer

A ticket-based network authentication protocol using a trusted Key Distribution Center.

MFA
Show answer

Multi-factor authentication — two or more factors from different categories.

Something you know
Show answer

An MFA knowledge factor — a password or PIN.

Something you have
Show answer

An MFA possession factor — a token, phone, or smart card.

Something you are
Show answer

An MFA inherence factor — a biometric like a fingerprint or face.

Why two passwords isn't MFA
Show answer

Both are the same category (knowledge); MFA needs DIFFERENT factor types.

TOTP
Show answer

Time-based One-Time Password — a short-lived code from an authenticator app.

RBAC
Show answer

Role-Based Access Control — permissions follow the user's role.

MAC (access)
Show answer

Mandatory Access Control — the system enforces labels/clearances (high security).

DAC
Show answer

Discretionary Access Control — the resource owner decides who gets access.

ABAC
Show answer

Attribute-Based Access Control — access decided by attributes and context.

Least privilege
Show answer

Granting only the minimum access needed to do a job.

Separation of duties
Show answer

Splitting a sensitive task so no single person controls the whole process.

PAM
Show answer

Privileged Access Management — controls, vaults, and audits admin accounts.

Just-in-time access
Show answer

Granting elevated rights only for the moment they're needed, then revoking.

Incident response lifecycle
Show answer

Preparation; detection & analysis; containment, eradication & recovery; post-incident.

IR: first action (live)
Show answer

Containment — isolate affected systems to stop the spread before eradicating.

Eradication
Show answer

Removing the threat and any persistence from affected systems.

Recovery (IR)
Show answer

Restoring systems from known-good, tested backups and monitoring for reinfection.

Post-incident activity
Show answer

Lessons learned and root cause analysis that feed back into preparation.

Tabletop exercise
Show answer

A discussion-based walkthrough of an incident scenario to test the plan.

Threat hunting
Show answer

Proactively searching for hidden threats that evaded automated detection.

Digital forensics
Show answer

Collecting and analyzing evidence in a sound, documented way.

Chain of custody
Show answer

Documentation of who handled evidence, when, and how — to keep it admissible.

Legal hold
Show answer

A directive to preserve relevant data when litigation/investigation is anticipated.

Order of volatility
Show answer

Collecting the most volatile evidence (RAM) before the least (disk, archives).

e-Discovery
Show answer

Identifying and producing electronic evidence for legal proceedings.

Security Program Management & Oversight (59)

Governance
Show answer

The policies, standards, procedures, and oversight that direct a security program.

Policy
Show answer

A high-level statement of management's security intent and rules.

Standard
Show answer

A specific mandatory requirement that supports a policy (e.g., password length).

Procedure
Show answer

A step-by-step instruction for performing a task securely.

Guideline
Show answer

A recommended, non-mandatory best practice.

Acceptable Use Policy (AUP)
Show answer

Defines acceptable use of organizational systems and data.

Change management policy
Show answer

Requires approval, testing, documentation, and rollback for changes.

SDLC
Show answer

Software Development Life Cycle — the structured process for building software securely.

Data owner
Show answer

The person accountable for a data set and for setting its classification.

Data controller
Show answer

The party that determines why and how personal data is processed.

Data processor
Show answer

The party that processes personal data on the controller's behalf.

Data custodian/steward
Show answer

The role that implements controls and maintains data quality day-to-day.

Risk management
Show answer

Identifying, assessing, and treating risk to keep it within appetite.

Qualitative risk analysis
Show answer

Rating risk by likelihood and impact (low/medium/high), no dollar values.

Quantitative risk analysis
Show answer

Assigning dollar values to risk using SLE, ARO, and ALE.

Exposure factor (EF)
Show answer

The percentage of an asset's value lost in a single event.

SLE
Show answer

Single Loss Expectancy = asset value × exposure factor.

ARO
Show answer

Annualized Rate of Occurrence — expected number of events per year.

ALE
Show answer

Annualized Loss Expectancy = SLE × ARO.

ALE example
Show answer

A $20,000 SLE happening twice a year (ARO 2) gives an ALE of $40,000.

Risk register
Show answer

A documented list of risks with owner, likelihood, impact, and treatment.

Risk appetite
Show answer

The amount and type of risk an organization is willing to accept.

Risk tolerance
Show answer

The acceptable variation around the risk appetite for a specific objective.

Key Risk Indicator (KRI)
Show answer

A metric that signals rising risk exposure.

Risk mitigation
Show answer

Reducing a risk's likelihood or impact with controls.

Risk transference
Show answer

Shifting risk to another party, e.g., buying cyber insurance.

Risk avoidance
Show answer

Eliminating a risk by stopping the risky activity entirely.

Risk acceptance
Show answer

Acknowledging a risk and taking no action because it's within appetite.

Four risk responses
Show answer

Mitigate, transfer, avoid, accept.

Inherent vs. residual risk
Show answer

Inherent = risk before controls; residual = risk remaining after controls.

Business impact analysis (BIA)
Show answer

Identifies critical functions and sets recovery objectives (RTO/RPO).

SLA
Show answer

Service Level Agreement — defines guaranteed service levels and metrics with a provider.

MOU/MOA
Show answer

Memorandum of Understanding/Agreement — outlines intentions between parties.

MSA
Show answer

Master Service Agreement — overarching terms governing ongoing work.

SOW/WO
Show answer

Statement of Work / Work Order — the specific deliverables and tasks.

NDA
Show answer

Non-Disclosure Agreement — a confidentiality obligation between parties.

BPA
Show answer

Business Partners Agreement — terms governing a partnership.

Due diligence
Show answer

Investigating risks before entering an agreement or activity.

Due care
Show answer

Taking reasonable, ongoing steps to protect assets (the 'prudent person' standard).

Right-to-audit clause
Show answer

A contract term allowing a customer to audit a vendor's security.

Vendor/third-party risk
Show answer

Risk introduced by suppliers, MSPs, and partners with access.

Supply chain analysis
Show answer

Assessing the security of vendors and the components they provide.

Compliance
Show answer

Meeting legal, regulatory, and contractual security requirements.

Consequences of non-compliance
Show answer

Fines, sanctions, reputational damage, and possible loss of license.

Attestation
Show answer

A formal statement confirming the state of controls (often by an auditor).

Privacy: right to be forgotten
Show answer

An individual's right to request deletion of their personal data.

Data retention
Show answer

Policy defining how long data is kept and when it's securely destroyed.

Internal vs. external audit
Show answer

Internal audits are run by the organization; external by independent third parties.

Regulatory audit
Show answer

An assessment required by a law or regulator (e.g., PCI DSS, HIPAA).

Known environment (white-box)
Show answer

A pen test where the tester has full knowledge of the target.

Partially known (gray-box)
Show answer

A pen test where the tester has limited information.

Unknown environment (black-box)
Show answer

A pen test with no prior information — simulates an outsider.

Passive reconnaissance
Show answer

Gathering info without directly touching the target (e.g., OSINT).

Active reconnaissance
Show answer

Directly probing the target (e.g., scanning), which can be detected.

Security awareness training
Show answer

Ongoing education that teaches users to recognize and report threats.

Phishing campaign (internal)
Show answer

A simulated phishing test used to measure and improve user awareness.

Anomalous behavior recognition
Show answer

Training users to spot and report unusual activity.

Onboarding/offboarding
Show answer

Procedures for granting access on hire and revoking it on departure.

Playbook
Show answer

A documented set of steps for responding to a specific type of incident.

References

  1. 1.CompTIA. “CompTIA Security+ (SY0-701) Certification.” comptia.org. ↑
  2. 2.CompTIA. “Security+ (SY0-701) Exam Objectives.” comptia.org. ↑
  3. 3.National Institute of Standards and Technology. “Cybersecurity Framework (CSF) 2.0.” nist.gov. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.