Click Study Flashcards above to open the flashcard hub — hundreds of Security+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official SY0-701 domains, so you study exactly what the exam tests.[2]
Pair them with our free practice test and study guide. Want extra insurance for exam day? Capital Prep’s CompTIA Security+ premium study materials come with a CompTIA Security+ exam pass guarantee: your money back if you don’t pass, plus up to $439 toward your retake fee — and Career Employer students get a special discount.
CompTIA Security+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.
Security+ Flashcard Study Modes
Flip mode lets you read a front, think, then check the back at your own pace. Match turns the deck into a timed pairing game against the clock. Type shows a definition and asks you to spell the term back, so a card like EDR has to come from memory. Quiz builds multiple choice questions from the same 325 cards.

Why Flashcards Work for Security+
Security Operations carries the heaviest weight on the exam at 28 percent, and it is the largest slice of the deck with 72 cards. The terms here cover monitoring, endpoint defense, identity, and email hardening, so you get acronyms such as MDM and XDR alongside detection and integrity cards like FIM, plus SSO and SPF for access and mail authentication.
Threats, Vulnerabilities & Mitigations is worth 22 percent and holds 70 cards. Expect malware families and attack techniques stated plainly, from Worm and Rootkit to social engineering entries like Vishing, along with remediation-style prompts such as XSS fix that ask what actually stops the attack rather than what it is called.
Security Program Management & Oversight accounts for 20 percent of the exam and 59 cards. This is governance, risk math, and agreements. Risk quantification cards like SLE, ARO, and ALE sit next to contract vocabulary such as MSA and BPA, with SDLC covering how security fits into development process oversight.
Security Architecture is 18 percent with 56 cards on network and system design. You work through boundary and inspection devices including DMZ, WAF, IDS, and IPS, protective controls such as DLP, and resilience or platform terms like UPS and IoT that show up in design and placement questions.
General Security Concepts is weighted at 12 percent but still brings 68 cards, mostly cryptography and trust infrastructure. Symmetric and asymmetric algorithms such as AES, RSA, and ECC appear beside hashing with MD5, certificate lifecycle terms including CSR and CRL, and hardware trust with TPM.
Security+ is dense with terminology — attack types, malware families, cryptography, network appliances, access-control models, and GRC acronyms.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
Security+ Flashcards by Domain
The cards are organized by the five official SY0-701 domains. Drill the highest-weighted ones first — Security Operations and Threats, Vulnerabilities & Mitigations make up half the exam:[2]
| Domain | Exam weight |
|---|---|
| Security Operations | 28% |
| Threats, Vulnerabilities & Mitigations | 22% |
| Security Program Management & Oversight | 20% |
| Security Architecture | 18% |
| General Security Concepts | 12% |
How to Get the Most Out of These Flashcards
- Start where the weight is. Security Operations is 28 percent of the exam and 72 cards, so run that domain in Flip first and do not move on until the backs feel predictable.
- Type-drill the acronyms you confuse. Cards like XDR and EDR, or SPF inside the mail cluster, reward exact recall, and typing exposes the ones you only half know.
- Use Match for malware and device families. Pairing Worm, Trojan, and Botnet against their definitions under time pressure builds the fast sorting the Threats, Vulnerabilities & Mitigations questions expect.
- Switch to the practice test after Quiz stabilizes. Once Quiz stops surprising you across all five domains, move to scenario questions and use the study guide to fill whatever the results expose.
- Rotate domains, do not binge one. With 325 cards, run one domain plus a short Match round on a weaker domain each session, and revisit Security Program Management & Oversight risk math often.
Security+ Flashcards FAQ
Hundreds of free Security+ flashcards, organized across all five SY0-701 domains — General Security Concepts, Threats/Vulnerabilities/Mitigations, Security Architecture, Security Operations, and Security Program Management & Oversight. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. Security+ is heavy on terminology (ports, protocols, attack types, crypto, frameworks), which is exactly what flashcards drill best.
All five SY0-701 domains: General Security Concepts (CIA triad, controls, Zero Trust, cryptography), Threats/Vulnerabilities/Mitigations (attacks, malware, social engineering), Security Architecture (cloud, infrastructure, data protection, resilience), Security Operations (hardening, monitoring, IAM, incident response), and Security Program Management (governance, risk, compliance).
Lead with the highest-weighted domains — Security Operations (28%) and Threats, Vulnerabilities & Mitigations (22%) — then drill Program Management, Architecture, and General Concepts. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to CompTIA's current SY0-701 exam objectives, covering all five scored domains in their official proportions, including the newer Zero Trust and Security Operations emphasis.
CompTIA Security+ flashcard bank
All 325 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
General Security Concepts (68)
- CIA triad
Show answerHide answer
Confidentiality, Integrity, Availability — the three core goals of information security.
- Confidentiality
Show answerHide answer
Ensuring only authorized people can read data; enforced by encryption and access control.
- Integrity
Show answerHide answer
Ensuring data is accurate and unaltered; enforced by hashing and digital signatures.
- Availability
Show answerHide answer
Ensuring authorized users can access data when needed; enforced by redundancy and backups.
- Non-repudiation
Show answerHide answer
Assurance that someone cannot deny an action they performed; provided by digital signatures and logging.
- AAA
Show answerHide answer
Authentication (prove identity), Authorization (grant rights), and Accounting (log activity).
- Authentication
Show answerHide answer
Verifying that a subject is who it claims to be (e.g., with a password, token, or biometric).
- Authorization
Show answerHide answer
Granting an authenticated subject the rights to access specific resources.
- Accounting (auditing)
Show answerHide answer
Recording what authenticated subjects do, for tracking and forensics.
- Authentication vs. authorization
Show answerHide answer
Authentication proves WHO you are; authorization decides WHAT you may access.
- Technical control
Show answerHide answer
A safeguard implemented by technology — firewall, encryption, MFA, antivirus.
- Managerial control
Show answerHide answer
An administrative safeguard — policies, risk assessments, security planning.
- Operational control
Show answerHide answer
A safeguard carried out by people — awareness training, guard duty, config management.
- Physical control
Show answerHide answer
A tangible safeguard — locks, fences, badges, cameras, bollards.
- Preventive control
Show answerHide answer
A control that stops an incident before it happens (e.g., a firewall rule or a lock).
- Deterrent control
Show answerHide answer
A control that discourages an attacker (e.g., a warning sign or lighting).
- Detective control
Show answerHide answer
A control that identifies an incident during or after it (e.g., an IDS or log review).
- Corrective control
Show answerHide answer
A control that fixes or limits damage after an event (e.g., restoring a backup).
- Compensating control
Show answerHide answer
An alternative control used when the primary control isn't feasible.
- Directive control
Show answerHide answer
A control that directs behavior, such as a policy or procedure.
- Zero Trust
Show answerHide answer
A model that removes implicit trust and verifies every request — 'never trust, always verify.'
- Control plane (Zero Trust)
Show answerHide answer
The 'brain' that makes access decisions: the Policy Engine and Policy Administrator.
- Data plane (Zero Trust)
Show answerHide answer
The part that enforces decisions on each request via the Policy Enforcement Point (PEP).
- Policy Engine (PE)
Show answerHide answer
The Zero Trust component that decides to grant or deny access based on policy and context.
- Policy Enforcement Point (PEP)
Show answerHide answer
The Zero Trust component that allows or blocks each actual request to a resource.
- Adaptive identity
Show answerHide answer
Adjusting authentication requirements based on context and risk (a Zero Trust concept).
- Implicit trust zone
Show answerHide answer
An area where access is trusted by default — what Zero Trust seeks to eliminate.
- Honeypot
Show answerHide answer
A decoy system that lures attackers away from real assets and records their behavior.
- Honeynet
Show answerHide answer
A network of honeypots that mimics a real environment to study attackers.
- Honeyfile
Show answerHide answer
A bait file (e.g., 'passwords.xlsx') that triggers an alert when accessed.
- Honeytoken
Show answerHide answer
Fake data (a credential, record, or API key) that signals compromise when used.
- Symmetric encryption
Show answerHide answer
Encryption using one shared secret key to both encrypt and decrypt; fast (e.g., AES).
- Asymmetric encryption
Show answerHide answer
Encryption using a public/private key pair; one key encrypts, the other decrypts (e.g., RSA, ECC).
- AES
Show answerHide answer
Advanced Encryption Standard — the dominant symmetric block cipher (128/192/256-bit keys).
- RSA
Show answerHide answer
A widely used asymmetric algorithm for key exchange and digital signatures.
- ECC
Show answerHide answer
Elliptic Curve Cryptography — asymmetric crypto giving strong security with smaller keys.
- Diffie-Hellman
Show answerHide answer
A key-exchange method that lets two parties derive a shared secret over an insecure channel.
- Hashing
Show answerHide answer
A one-way function producing a fixed-length digest; used for integrity, not reversible.
- SHA-256
Show answerHide answer
A secure hashing algorithm producing a 256-bit digest, used for integrity verification.
- MD5
Show answerHide answer
An obsolete hash function, broken by collisions — should not be used for security.
- Salting
Show answerHide answer
Adding unique random data to a password before hashing so identical passwords differ.
- Key stretching
Show answerHide answer
Repeatedly hashing a password (e.g., bcrypt, PBKDF2, Argon2) to slow brute-force attacks.
- Digital signature
Show answerHide answer
A message hash encrypted with the signer's private key; proves integrity and authenticity.
- Public key — when to use
Show answerHide answer
Encrypt FOR someone with their public key; verify a signature with the signer's public key.
- Private key — when to use
Show answerHide answer
Decrypt what was sent to you; SIGN messages with your own private key.
- Hybrid encryption
Show answerHide answer
Use asymmetric crypto to exchange a fast symmetric session key, then symmetric for the data (TLS).
- PKI
Show answerHide answer
Public Key Infrastructure — the CAs, policies, and keys that issue and manage digital certificates.
- Certificate Authority (CA)
Show answerHide answer
A trusted entity that issues and signs digital certificates.
- Root CA
Show answerHide answer
The top, self-signed CA in a trust chain; usually kept offline for protection.
- Intermediate CA
Show answerHide answer
A CA signed by the root that issues end-entity certificates to protect the root key.
- Digital certificate (X.509)
Show answerHide answer
A file binding a public key to a verified identity, signed by a CA.
- CSR
Show answerHide answer
Certificate Signing Request — a request sent to a CA to issue a certificate for a public key.
- CRL
Show answerHide answer
Certificate Revocation List — a published list of certificates the CA has revoked.
- OCSP
Show answerHide answer
Online Certificate Status Protocol — a real-time query to check if a certificate is revoked.
- Certificate pinning
Show answerHide answer
Associating a host with its expected certificate/key to resist fraudulent certs.
- Wildcard certificate
Show answerHide answer
A certificate that secures a domain and all its subdomains (e.g., *.example.com).
- TPM
Show answerHide answer
Trusted Platform Module — a hardware chip that securely stores keys and supports disk encryption.
- HSM
Show answerHide answer
Hardware Security Module — a tamper-resistant device for generating and storing keys.
- Secure enclave
Show answerHide answer
An isolated hardware region that protects data and keys even from the host OS.
- Key escrow
Show answerHide answer
Storing a copy of keys with a trusted third party so data can be recovered if a key is lost.
- Steganography
Show answerHide answer
Hiding data inside other data (e.g., within an image) so its existence is concealed.
- Obfuscation
Show answerHide answer
Making data or code hard to understand to slow analysis (not true encryption).
- Blockchain
Show answerHide answer
A distributed, append-only ledger secured by hashing and consensus.
- Tokenization (crypto)
Show answerHide answer
Replacing sensitive data with a non-sensitive token mapped to the real value stored securely.
- Cipher suite
Show answerHide answer
The set of algorithms (key exchange, encryption, hashing) negotiated for a TLS session.
- Perfect forward secrecy
Show answerHide answer
Using ephemeral keys so a compromised long-term key can't decrypt past sessions.
- Change management
Show answerHide answer
A structured process to approve, document, test, and roll back changes safely.
- Gap analysis
Show answerHide answer
Comparing the current security posture to a desired state to find what's missing.
Threats, Vulnerabilities & Mitigations (70)
- Phishing
Show answerHide answer
A fraudulent message (usually email) that tricks the victim into revealing credentials or running malware.
- Vishing
Show answerHide answer
Voice phishing — a social-engineering attack carried out over a phone call.
- Smishing
Show answerHide answer
SMS phishing — a social-engineering attack delivered by text message.
- Spear phishing
Show answerHide answer
A phishing attack targeted at a specific individual using personalized details.
- Whaling
Show answerHide answer
A phishing attack that specifically targets high-value executives.
- Business email compromise (BEC)
Show answerHide answer
Impersonating a trusted executive or vendor to authorize fraudulent payments.
- Pretexting
Show answerHide answer
Inventing a believable scenario or pretext to manipulate a victim into cooperating.
- Pharming
Show answerHide answer
Redirecting users from a legitimate site to a fake one, often via poisoned DNS.
- Watering hole attack
Show answerHide answer
Compromising a website the target group is known to visit, to infect them.
- Typosquatting
Show answerHide answer
Registering misspelled domains to catch users who mistype a URL.
- Impersonation
Show answerHide answer
Pretending to be someone trusted to gain access or information.
- Tailgating
Show answerHide answer
Following an authorized person through a secure door without credentials.
- Dumpster diving
Show answerHide answer
Searching discarded materials for sensitive information.
- Shoulder surfing
Show answerHide answer
Observing someone's screen or keypad to steal credentials or data.
- Disinformation/misinformation
Show answerHide answer
Spreading false content to manipulate beliefs or actions.
- Threat actor
Show answerHide answer
An individual or group that carries out an attack.
- Nation-state actor
Show answerHide answer
A government-sponsored, highly resourced threat actor; usually motivated by espionage.
- Advanced persistent threat (APT)
Show answerHide answer
A skilled, well-resourced adversary that maintains long-term stealthy access.
- Organized crime
Show answerHide answer
A profit-driven, well-funded threat actor group.
- Hacktivist
Show answerHide answer
An attacker motivated by a political or social cause.
- Insider threat
Show answerHide answer
A current/former employee or partner who misuses authorized access.
- Unskilled attacker
Show answerHide answer
A 'script kiddie' who uses others' tools without deep expertise.
- Shadow IT
Show answerHide answer
Hardware, software, or services used without IT/security approval.
- Threat vector
Show answerHide answer
The path or means an attacker uses to gain access (email, USB, supply chain).
- Attack surface
Show answerHide answer
The total set of points where an attacker could try to enter or extract data.
- Supply chain attack
Show answerHide answer
Compromising a trusted vendor, MSP, or software update to reach the target.
- Malware
Show answerHide answer
Malicious software — ransomware, trojans, worms, viruses, spyware, rootkits, keyloggers.
- Ransomware
Show answerHide answer
Malware that encrypts data and demands payment for the decryption key.
- Double extortion
Show answerHide answer
Ransomware that also steals data and threatens to leak it if unpaid.
- Trojan
Show answerHide answer
Malware disguised as legitimate software that hides a malicious payload.
- Worm
Show answerHide answer
Self-replicating malware that spreads across networks without user action.
- Virus
Show answerHide answer
Malware that attaches to a host file and spreads when that file is executed.
- Spyware
Show answerHide answer
Malware that secretly gathers information about a user or system.
- Keylogger
Show answerHide answer
Malware or hardware that records keystrokes to steal credentials.
- Rootkit
Show answerHide answer
Malware that hides at a privileged level (often the kernel) to maintain stealthy access.
- Logic bomb
Show answerHide answer
Malicious code that executes when a specific condition or time is met.
- Bloatware
Show answerHide answer
Unwanted pre-installed software that expands the attack surface.
- Fileless malware
Show answerHide answer
Malware that runs in memory using legitimate tools, leaving little on disk.
- Botnet
Show answerHide answer
A network of compromised devices controlled by an attacker (often for DDoS).
- Buffer overflow
Show answerHide answer
Writing more data than a buffer holds, overwriting adjacent memory to run code.
- Race condition (TOCTOU)
Show answerHide answer
A timing flaw between time-of-check and time-of-use that can be exploited.
- Memory injection
Show answerHide answer
Inserting malicious code into a running process's memory space.
- SQL injection
Show answerHide answer
Inserting malicious SQL into input so the database runs unintended commands.
- SQL injection fix
Show answerHide answer
Use parameterized queries (prepared statements) plus input validation.
- Cross-site scripting (XSS)
Show answerHide answer
Injecting script into a trusted site that runs in another user's browser.
- XSS fix
Show answerHide answer
Output encoding, input validation, and a Content Security Policy (CSP).
- Cross-site request forgery (CSRF)
Show answerHide answer
Tricking a logged-in user's browser into sending an unwanted authenticated request.
- Zero-day
Show answerHide answer
A vulnerability unknown to the vendor with no patch available yet.
- Misconfiguration
Show answerHide answer
An insecure default or setting; a leading cause of breaches.
- Default credentials
Show answerHide answer
Factory usernames/passwords left unchanged — an easy attacker entry point.
- VM escape
Show answerHide answer
Breaking out of a virtual machine to access the hypervisor or host.
- On-path attack
Show answerHide answer
An attacker secretly relays or alters traffic between two parties (formerly MITM).
- Replay attack
Show answerHide answer
Capturing and re-sending valid data (e.g., a session token) to impersonate a user.
- DNS poisoning
Show answerHide answer
Corrupting DNS records to redirect users to malicious sites.
- ARP poisoning
Show answerHide answer
Sending forged ARP messages to associate the attacker's MAC with another IP.
- DDoS attack
Show answerHide answer
Overwhelming a target with traffic from many sources to deny service.
- Amplification attack
Show answerHide answer
Using a service to multiply traffic volume toward a victim (a DDoS technique).
- Privilege escalation
Show answerHide answer
Gaining higher rights than granted — vertical (to admin) or horizontal (to a peer).
- Password spraying
Show answerHide answer
Trying a few common passwords against many accounts to avoid lockouts.
- Brute-force attack
Show answerHide answer
Systematically trying many passwords or keys until one works.
- Dictionary attack
Show answerHide answer
Trying passwords from a list of likely words.
- Rainbow table
Show answerHide answer
A precomputed table of hashes used to crack unsalted password hashes.
- Indicator of compromise (IoC)
Show answerHide answer
An artifact (IP, hash, behavior) suggesting a system was breached.
- Mitigation: segmentation
Show answerHide answer
Dividing a network into zones to limit how far an attacker can move.
- Mitigation: least privilege
Show answerHide answer
Granting only the minimum access needed to limit the blast radius.
- Mitigation: patching
Show answerHide answer
Applying updates to fix known vulnerabilities.
- Mitigation: hardening
Show answerHide answer
Removing unneeded services/accounts and applying secure baselines.
- Application allow list
Show answerHide answer
Permitting only approved software to run (stronger than block-listing).
- Sandboxing
Show answerHide answer
Running untrusted code in an isolated environment to contain harm.
- Defense in depth
Show answerHide answer
Layering multiple independent controls so one failure isn't a breach.
Security Architecture (56)
- Shared responsibility model
Show answerHide answer
Cloud split: provider secures the infrastructure; customer secures data, identity, and config.
- Security OF vs. IN the cloud
Show answerHide answer
Provider = security OF the cloud (infrastructure); customer = security IN the cloud (data/config).
- IaaS
Show answerHide answer
Infrastructure as a Service — customer manages OS, apps, and data (most responsibility).
- PaaS
Show answerHide answer
Platform as a Service — provider manages the platform; customer manages apps and data.
- SaaS
Show answerHide answer
Software as a Service — provider manages almost everything; customer manages data and access.
- Virtualization
Show answerHide answer
Running multiple guest operating systems on one physical host via a hypervisor.
- Hypervisor
Show answerHide answer
Software that creates and runs virtual machines (Type 1 bare-metal or Type 2 hosted).
- Containerization
Show answerHide answer
Packaging an app with its dependencies in an isolated container sharing the host kernel.
- Serverless
Show answerHide answer
Running code as functions without managing servers; the provider scales it.
- Microservices
Show answerHide answer
Building an app as small, independently deployable services.
- Infrastructure as Code (IaC)
Show answerHide answer
Provisioning infrastructure from version-controlled machine-readable files.
- Software-defined networking (SDN)
Show answerHide answer
Centrally programming network behavior via software, separate from hardware.
- IoT
Show answerHide answer
Internet of Things — networked everyday devices, often with weak built-in security.
- ICS/SCADA
Show answerHide answer
Industrial control systems that run physical processes; hard to patch, need segmentation.
- Embedded system
Show answerHide answer
A purpose-built computer inside a device, often with limited update ability.
- Security zone
Show answerHide answer
A network segment grouped by trust level to control traffic between areas.
- DMZ
Show answerHide answer
A perimeter network segment that hosts public-facing services, isolated from the internal LAN.
- Firewall
Show answerHide answer
A device that filters network traffic based on rules to enforce a security boundary.
- Next-generation firewall (NGFW)
Show answerHide answer
A firewall adding application awareness, deep inspection, and threat intel.
- WAF
Show answerHide answer
Web Application Firewall — protects web apps from layer-7 attacks like injection and XSS.
- UTM
Show answerHide answer
Unified Threat Management — one appliance combining firewall, IPS, AV, filtering, and more.
- IDS
Show answerHide answer
Intrusion Detection System — detects and alerts on suspicious traffic (passive).
- IPS
Show answerHide answer
Intrusion Prevention System — detects and blocks suspicious traffic inline (active).
- IDS vs. IPS
Show answerHide answer
IDS only detects/alerts (passive); IPS sits inline and can block (active).
- Proxy server
Show answerHide answer
An intermediary that mediates and can filter client requests to other servers.
- Jump server
Show answerHide answer
A hardened pivot host used to administer systems in a secure zone.
- Load balancer
Show answerHide answer
Distributes traffic across multiple servers for availability and scale.
- Fail-open vs. fail-closed
Show answerHide answer
Fail-open allows traffic on failure (availability); fail-closed blocks it (security).
- Active vs. passive (sensor)
Show answerHide answer
Active devices sit inline and can act; passive devices observe via a tap or span port.
- 802.1X
Show answerHide answer
A port-based network access control standard that authenticates devices before granting access.
- Port security
Show answerHide answer
Limiting which devices (by MAC) can connect to a switch port.
- Data at rest
Show answerHide answer
Data stored on disk, database, or backup; protected with encryption and access control.
- Data in transit
Show answerHide answer
Data moving across a network; protected with TLS or VPN encryption.
- Data in use
Show answerHide answer
Data actively processed in memory; protected by techniques like secure enclaves.
- Data classification
Show answerHide answer
Labeling data by sensitivity (public, sensitive, confidential, critical) to set controls.
- Data masking
Show answerHide answer
Hiding part of a data value (e.g., showing only the last four digits).
- Tokenization
Show answerHide answer
Replacing sensitive data with a non-sensitive token; the real value is stored securely.
- DLP
Show answerHide answer
Data Loss Prevention — detects and blocks unauthorized movement of sensitive data.
- Data sovereignty
Show answerHide answer
The principle that data is subject to the laws of the country where it resides.
- High availability (HA)
Show answerHide answer
Designing systems to stay operational with minimal downtime via redundancy.
- Clustering
Show answerHide answer
Linking servers so they act as one resilient unit, with failover.
- Load balancing vs. clustering
Show answerHide answer
Load balancing spreads traffic; clustering provides coordinated failover/redundancy.
- Hot site
Show answerHide answer
A fully equipped alternate site ready for near-instant failover (most expensive).
- Warm site
Show answerHide answer
A partially equipped recovery site needing some setup before use.
- Cold site
Show answerHide answer
A recovery site with space and power only; longest to bring online (cheapest).
- Geographic dispersion
Show answerHide answer
Placing redundant systems in different locations to survive regional disasters.
- RAID
Show answerHide answer
Redundant Array of Independent Disks — combines drives for redundancy and/or performance.
- UPS
Show answerHide answer
Uninterruptible Power Supply — battery backup that keeps systems up during short outages.
- 3-2-1 backup rule
Show answerHide answer
Keep 3 copies of data, on 2 media types, with 1 copy offsite.
- RTO
Show answerHide answer
Recovery Time Objective — the maximum acceptable time to restore a system.
- RPO
Show answerHide answer
Recovery Point Objective — the maximum acceptable data loss, measured back to the last backup.
- RTO vs. RPO
Show answerHide answer
RTO = how fast you recover (downtime); RPO = how much data you can lose.
- MTBF
Show answerHide answer
Mean Time Between Failures — average time a system runs before failing.
- MTTR
Show answerHide answer
Mean Time To Repair — average time to restore a failed system.
- Snapshot
Show answerHide answer
A point-in-time copy of a system or volume for quick recovery.
- Journaling
Show answerHide answer
Logging changes so a system can be restored to a consistent state after a crash.
Security Operations (72)
- Hardening
Show answerHide answer
Reducing attack surface by removing unneeded services/accounts and applying secure baselines.
- Secure baseline
Show answerHide answer
A standard, approved secure configuration applied to systems.
- MDM
Show answerHide answer
Mobile Device Management — centrally enforces policies and security on mobile devices.
- BYOD
Show answerHide answer
Bring Your Own Device — employees use personal devices for work (higher risk).
- COPE
Show answerHide answer
Corporate-Owned, Personally Enabled — company device usable for personal tasks.
- WPA3
Show answerHide answer
The current secure Wi-Fi protocol; uses SAE to resist offline password cracking.
- SAE
Show answerHide answer
Simultaneous Authentication of Equals — WPA3's secure key-exchange handshake.
- Sanitization
Show answerHide answer
Securely erasing or destroying media so data can't be recovered before disposal.
- Asset inventory
Show answerHide answer
A maintained list of hardware/software assets, essential to securing them.
- Vulnerability scan
Show answerHide answer
An automated check that identifies known weaknesses in systems.
- Penetration test
Show answerHide answer
An authorized simulated attack that actually exploits weaknesses to prove risk.
- Vuln scan vs. pen test
Show answerHide answer
A scan only identifies weaknesses; a pen test exploits them.
- CVE
Show answerHide answer
Common Vulnerabilities and Exposures — a public catalog of unique vulnerability IDs.
- CVSS
Show answerHide answer
Common Vulnerability Scoring System — a 0–10 severity score for a vulnerability.
- False positive
Show answerHide answer
A reported vulnerability/alert that isn't actually a real issue.
- False negative
Show answerHide answer
A real vulnerability or attack that the tool failed to detect (dangerous).
- Responsible disclosure
Show answerHide answer
Reporting a vulnerability privately to the vendor before public release.
- Bug bounty
Show answerHide answer
A program that pays outside researchers for responsibly reported vulnerabilities.
- Remediation
Show answerHide answer
Fixing a vulnerability by patching, reconfiguring, or applying a compensating control.
- Rescanning/validation
Show answerHide answer
Re-scanning after remediation to confirm the fix actually worked.
- SIEM
Show answerHide answer
Security Information and Event Management — aggregates and correlates logs to detect threats.
- Log aggregation
Show answerHide answer
Centralizing logs from many sources for correlation and analysis.
- Alert tuning
Show answerHide answer
Adjusting detection rules to cut false positives and reduce alert fatigue.
- SNMP
Show answerHide answer
Simple Network Management Protocol — monitors and manages network devices.
- NetFlow
Show answerHide answer
A protocol that records IP traffic flow data for monitoring and analysis.
- SOAR
Show answerHide answer
Security Orchestration, Automation, and Response — automates response via playbooks.
- EDR
Show answerHide answer
Endpoint Detection and Response — monitors endpoints to detect and respond to threats.
- XDR
Show answerHide answer
Extended Detection and Response — correlates detection across endpoints, network, and cloud.
- FIM
Show answerHide answer
File Integrity Monitoring — alerts when critical files change unexpectedly.
- Antivirus/anti-malware
Show answerHide answer
Software that detects and removes malicious code on endpoints.
- Web filtering
Show answerHide answer
Blocking access to malicious or disallowed websites.
- DNS filtering
Show answerHide answer
Blocking resolution of known-malicious domains.
- SPF
Show answerHide answer
Sender Policy Framework — lists which mail servers may send for a domain.
- DKIM
Show answerHide answer
DomainKeys Identified Mail — cryptographically signs email to prove it wasn't altered.
- DMARC
Show answerHide answer
Ties SPF and DKIM together and tells receivers how to handle failures (anti-spoofing).
- SPF/DKIM/DMARC
Show answerHide answer
The email-authentication trio that fights spoofing and phishing.
- Identity and access management (IAM)
Show answerHide answer
Policies and tools that manage identities and control access.
- Provisioning/deprovisioning
Show answerHide answer
Creating accounts on hire and promptly removing them on departure.
- Identity proofing
Show answerHide answer
Verifying a person's real-world identity before issuing credentials.
- SSO
Show answerHide answer
Single Sign-On — one authentication grants access to multiple systems.
- Federation
Show answerHide answer
Trusting identities from another domain to access resources (e.g., SAML, OIDC).
- SAML
Show answerHide answer
Security Assertion Markup Language — an XML standard for federated SSO.
- OAuth
Show answerHide answer
An authorization framework that lets apps access resources without sharing passwords.
- OpenID Connect (OIDC)
Show answerHide answer
An authentication layer built on OAuth 2.0 for verifying identity.
- LDAP
Show answerHide answer
Lightweight Directory Access Protocol — queries and manages directory information.
- Kerberos
Show answerHide answer
A ticket-based network authentication protocol using a trusted Key Distribution Center.
- MFA
Show answerHide answer
Multi-factor authentication — two or more factors from different categories.
- Something you know
Show answerHide answer
An MFA knowledge factor — a password or PIN.
- Something you have
Show answerHide answer
An MFA possession factor — a token, phone, or smart card.
- Something you are
Show answerHide answer
An MFA inherence factor — a biometric like a fingerprint or face.
- Why two passwords isn't MFA
Show answerHide answer
Both are the same category (knowledge); MFA needs DIFFERENT factor types.
- TOTP
Show answerHide answer
Time-based One-Time Password — a short-lived code from an authenticator app.
- RBAC
Show answerHide answer
Role-Based Access Control — permissions follow the user's role.
- MAC (access)
Show answerHide answer
Mandatory Access Control — the system enforces labels/clearances (high security).
- DAC
Show answerHide answer
Discretionary Access Control — the resource owner decides who gets access.
- ABAC
Show answerHide answer
Attribute-Based Access Control — access decided by attributes and context.
- Least privilege
Show answerHide answer
Granting only the minimum access needed to do a job.
- Separation of duties
Show answerHide answer
Splitting a sensitive task so no single person controls the whole process.
- PAM
Show answerHide answer
Privileged Access Management — controls, vaults, and audits admin accounts.
- Just-in-time access
Show answerHide answer
Granting elevated rights only for the moment they're needed, then revoking.
- Incident response lifecycle
Show answerHide answer
Preparation; detection & analysis; containment, eradication & recovery; post-incident.
- IR: first action (live)
Show answerHide answer
Containment — isolate affected systems to stop the spread before eradicating.
- Eradication
Show answerHide answer
Removing the threat and any persistence from affected systems.
- Recovery (IR)
Show answerHide answer
Restoring systems from known-good, tested backups and monitoring for reinfection.
- Post-incident activity
Show answerHide answer
Lessons learned and root cause analysis that feed back into preparation.
- Tabletop exercise
Show answerHide answer
A discussion-based walkthrough of an incident scenario to test the plan.
- Threat hunting
Show answerHide answer
Proactively searching for hidden threats that evaded automated detection.
- Digital forensics
Show answerHide answer
Collecting and analyzing evidence in a sound, documented way.
- Chain of custody
Show answerHide answer
Documentation of who handled evidence, when, and how — to keep it admissible.
- Legal hold
Show answerHide answer
A directive to preserve relevant data when litigation/investigation is anticipated.
- Order of volatility
Show answerHide answer
Collecting the most volatile evidence (RAM) before the least (disk, archives).
- e-Discovery
Show answerHide answer
Identifying and producing electronic evidence for legal proceedings.
Security Program Management & Oversight (59)
- Governance
Show answerHide answer
The policies, standards, procedures, and oversight that direct a security program.
- Policy
Show answerHide answer
A high-level statement of management's security intent and rules.
- Standard
Show answerHide answer
A specific mandatory requirement that supports a policy (e.g., password length).
- Procedure
Show answerHide answer
A step-by-step instruction for performing a task securely.
- Guideline
Show answerHide answer
A recommended, non-mandatory best practice.
- Acceptable Use Policy (AUP)
Show answerHide answer
Defines acceptable use of organizational systems and data.
- Change management policy
Show answerHide answer
Requires approval, testing, documentation, and rollback for changes.
- SDLC
Show answerHide answer
Software Development Life Cycle — the structured process for building software securely.
- Data owner
Show answerHide answer
The person accountable for a data set and for setting its classification.
- Data controller
Show answerHide answer
The party that determines why and how personal data is processed.
- Data processor
Show answerHide answer
The party that processes personal data on the controller's behalf.
- Data custodian/steward
Show answerHide answer
The role that implements controls and maintains data quality day-to-day.
- Risk management
Show answerHide answer
Identifying, assessing, and treating risk to keep it within appetite.
- Qualitative risk analysis
Show answerHide answer
Rating risk by likelihood and impact (low/medium/high), no dollar values.
- Quantitative risk analysis
Show answerHide answer
Assigning dollar values to risk using SLE, ARO, and ALE.
- Exposure factor (EF)
Show answerHide answer
The percentage of an asset's value lost in a single event.
- SLE
Show answerHide answer
Single Loss Expectancy = asset value × exposure factor.
- ARO
Show answerHide answer
Annualized Rate of Occurrence — expected number of events per year.
- ALE
Show answerHide answer
Annualized Loss Expectancy = SLE × ARO.
- ALE example
Show answerHide answer
A $20,000 SLE happening twice a year (ARO 2) gives an ALE of $40,000.
- Risk register
Show answerHide answer
A documented list of risks with owner, likelihood, impact, and treatment.
- Risk appetite
Show answerHide answer
The amount and type of risk an organization is willing to accept.
- Risk tolerance
Show answerHide answer
The acceptable variation around the risk appetite for a specific objective.
- Key Risk Indicator (KRI)
Show answerHide answer
A metric that signals rising risk exposure.
- Risk mitigation
Show answerHide answer
Reducing a risk's likelihood or impact with controls.
- Risk transference
Show answerHide answer
Shifting risk to another party, e.g., buying cyber insurance.
- Risk avoidance
Show answerHide answer
Eliminating a risk by stopping the risky activity entirely.
- Risk acceptance
Show answerHide answer
Acknowledging a risk and taking no action because it's within appetite.
- Four risk responses
Show answerHide answer
Mitigate, transfer, avoid, accept.
- Inherent vs. residual risk
Show answerHide answer
Inherent = risk before controls; residual = risk remaining after controls.
- Business impact analysis (BIA)
Show answerHide answer
Identifies critical functions and sets recovery objectives (RTO/RPO).
- SLA
Show answerHide answer
Service Level Agreement — defines guaranteed service levels and metrics with a provider.
- MOU/MOA
Show answerHide answer
Memorandum of Understanding/Agreement — outlines intentions between parties.
- MSA
Show answerHide answer
Master Service Agreement — overarching terms governing ongoing work.
- SOW/WO
Show answerHide answer
Statement of Work / Work Order — the specific deliverables and tasks.
- NDA
Show answerHide answer
Non-Disclosure Agreement — a confidentiality obligation between parties.
- BPA
Show answerHide answer
Business Partners Agreement — terms governing a partnership.
- Due diligence
Show answerHide answer
Investigating risks before entering an agreement or activity.
- Due care
Show answerHide answer
Taking reasonable, ongoing steps to protect assets (the 'prudent person' standard).
- Right-to-audit clause
Show answerHide answer
A contract term allowing a customer to audit a vendor's security.
- Vendor/third-party risk
Show answerHide answer
Risk introduced by suppliers, MSPs, and partners with access.
- Supply chain analysis
Show answerHide answer
Assessing the security of vendors and the components they provide.
- Compliance
Show answerHide answer
Meeting legal, regulatory, and contractual security requirements.
- Consequences of non-compliance
Show answerHide answer
Fines, sanctions, reputational damage, and possible loss of license.
- Attestation
Show answerHide answer
A formal statement confirming the state of controls (often by an auditor).
- Privacy: right to be forgotten
Show answerHide answer
An individual's right to request deletion of their personal data.
- Data retention
Show answerHide answer
Policy defining how long data is kept and when it's securely destroyed.
- Internal vs. external audit
Show answerHide answer
Internal audits are run by the organization; external by independent third parties.
- Regulatory audit
Show answerHide answer
An assessment required by a law or regulator (e.g., PCI DSS, HIPAA).
- Known environment (white-box)
Show answerHide answer
A pen test where the tester has full knowledge of the target.
- Partially known (gray-box)
Show answerHide answer
A pen test where the tester has limited information.
- Unknown environment (black-box)
Show answerHide answer
A pen test with no prior information — simulates an outsider.
- Passive reconnaissance
Show answerHide answer
Gathering info without directly touching the target (e.g., OSINT).
- Active reconnaissance
Show answerHide answer
Directly probing the target (e.g., scanning), which can be detected.
- Security awareness training
Show answerHide answer
Ongoing education that teaches users to recognize and report threats.
- Phishing campaign (internal)
Show answerHide answer
A simulated phishing test used to measure and improve user awareness.
- Anomalous behavior recognition
Show answerHide answer
Training users to spot and report unusual activity.
- Onboarding/offboarding
Show answerHide answer
Procedures for granting access on hire and revoking it on departure.
- Playbook
Show answerHide answer
A documented set of steps for responding to a specific type of incident.
References
- 1.CompTIA. “CompTIA Security+ (SY0-701) Certification.” comptia.org. ↑
- 2.CompTIA. “Security+ (SY0-701) Exam Objectives.” comptia.org. ↑
- 3.National Institute of Standards and Technology. “Cybersecurity Framework (CSF) 2.0.” nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
