CompTIA Security+ SY0-701 Reference – Secure In Security
SECURE IN SECURITY — CompTIA Security+ SY0-701 Reference Contact / About / Policy
Security+
CompTIA Security+ SY0-701 · Comprehensive Certification Reference
INTRODUCTION & CERTIFICATION OVERVIEW

Introduction and Certification Overview

CompTIA Security+ is the most widely held entry-to-intermediate level cybersecurity certification in the world. Administered by CompTIA (Computing Technology Industry Association), Security+ validates the baseline security skills and knowledge required to perform core security functions and pursue a career in IT security. It is vendor-neutral, meaning it covers security concepts, principles, and practices applicable across technologies, platforms, and environments rather than being tied to any specific vendor’s products.

Now in its seventh major version — SY0-701, released November 2023 — Security+ has evolved alongside the security profession to reflect the current threat landscape, including cloud security, hybrid environments, automation, zero trust architecture, and the expanded attack surface created by IoT, operational technology, and remote workforce adoption. The certification is trusted by more than 700,000 IT professionals globally and is recognized by the US Department of Defense as meeting DoD 8570/8140 requirements for Information Assurance Technical (IAT) Level II positions.

Security+ occupies a critical position in the certification ecosystem: it is the natural next step for IT generalists seeking to specialize in security (after CompTIA A+ and Network+), and it is the recognized baseline security credential for professionals beginning security-focused career paths. It provides the conceptual vocabulary, technical knowledge, and practical skills that serve as a foundation for advanced certifications including CASP+, CySA+, CISSP, and CEH. For many employers — particularly in the US government and defense sectors — Security+ is a minimum hire requirement for IT security roles.

Key Context
According to CompTIA’s own data, Security+ is the most popular and widely recognized entry-level cybersecurity certification globally, with over 700,000 certifications issued. It is cited in more entry-to-mid-level cybersecurity job postings than any other single certification, and it is the only certification mandated by the US DoD for contractors and civilian employees in IAT Level II information assurance roles under DoD 8570.01-M.

Certification at a Glance

Item Detail
Full Name CompTIA Security+ (SY0-701)
Issuing Body CompTIA — Computing Technology Industry Association
Current Version SY0-701 (released November 2023; replaces SY0-601)
Exam Format Maximum 90 questions; combination of multiple-choice and performance-based questions (PBQs)
Exam Duration 90 minutes
Passing Score 750 on a scale of 100–900
Number of Domains 5 domains
Prerequisites No mandatory prerequisites; CompTIA recommends Network+ and 2 years of IT experience with a security focus, but these are advisory only
Validity Period 3 years; renewal through Continuing Education (CE) or retake
CE Credits Required 50 Continuing Education (CE) units over 3 years for renewal
DoD Approval Approved under DoD 8570/8140 for IAT Level II, CSSP Analyst, CSSP Infrastructure Support, IASAE Level I
Vendor Neutrality Fully vendor-neutral; no vendor-specific tools, platforms, or proprietary technologies tested
Exam Delivery Pearson VUE testing centers (in-person) or Pearson VUE online proctored
Exam Cost USD $392 (standard); discounts available through academic institutions, training bundles, and voucher programs
Languages Available English, Japanese, Portuguese, Simplified Chinese, German
CompTIA Pathway Position Entry-to-intermediate; follows Network+; precedes CySA+, PenTest+, and CASP+
Global Recognition Recognized in 147+ countries; referenced in US DoD directives, Federal Agency security frameworks, and enterprise hiring standards
HISTORY & EVOLUTION OF SECURITY+

History and Evolution of CompTIA Security+

CompTIA Security+ has a history spanning more than two decades, during which it has been updated seven times to reflect the rapidly evolving security threat landscape, technology environment, and professional skill requirements. Each version has retained the foundational security principles that made the certification valuable while updating technical content to reflect current threats, tools, and practices.

Version Year Released Key Changes & Focus Areas
SY0-101 (v1) 2002 First edition; foundational security concepts — network security, cryptography, access control, authentication; established the vendor-neutral security baseline credential model
SY0-201 (v2) 2008 Expanded network infrastructure security; added application, data, and host security; updated threat and vulnerability coverage; wireless network security expanded
SY0-301 (v3) 2011 Major restructuring; added compliance and operational security; expanded cryptography; introduced risk management concepts; updated to reflect evolving threat landscape
SY0-401 (v4) 2014 Shifted emphasis toward risk management and policy; expanded mobile device security; cloud computing security introduced; updated malware and application security coverage
SY0-501 (v5) 2017 Updated threat intelligence coverage; expanded identity and access management; cloud and virtualization security deepened; incident response and forensics expanded; 6-domain structure
SY0-601 (v6) 2020 Significant restructuring to 5 domains; expanded cloud hybrid environment coverage; risk management deepened; secure protocols and implementation updated; operational security and governance integrated
SY0-701 (v7) November 2023 Current version; enhanced AI and automation threats; expanded zero trust and SASE coverage; updated cloud-native security; expanded IoT and OT threats; Governance, Risk & Compliance domain made more explicit; updated PBQ format with new scenario types

What Changed: SY0-601 to SY0-701

The SY0-701 update represents a significant content refresh from its predecessor. Candidates preparing from SY0-601 materials will find that while the domain structure is similar, the specific content emphasis has shifted substantially. Key changes include:

  • Expanded AI and Automation CoverageThe SY0-701 explicitly covers AI-driven threats (AI-powered phishing, automated vulnerability discovery), AI-enabled defensive tools (AI-powered SIEM, automated incident response), and the security considerations of AI systems themselves
  • Zero Trust Architecture DeepenedZero Trust is now a primary architectural concept tested throughout multiple domains, not a peripheral topic; candidates must understand zero trust principles, components, and implementation approaches
  • Cloud-Native and Hybrid EmphasisCloud security is integrated throughout all five domains; hybrid environment security (on-premises plus cloud) is a primary operational context throughout the exam
  • Governance, Risk and Compliance Domain ExpandedThe fifth domain (GRC) has been significantly expanded with more emphasis on regulatory frameworks, third-party risk, data privacy regulations, and security policy frameworks
  • Updated Threat LandscapeNew attack techniques including living-off-the-land (LotL) attacks, supply chain attacks, and AI-assisted social engineering are explicitly included; IoT and OT threats expanded
  • Revised PBQ FormatPerformance-based questions include new scenario types reflecting cloud and hybrid environments; drag-and-drop and ordering updated questions to reflect current security workflows
EXAM STRUCTURE, FORMAT & PERFORMANCE-BASED QUESTIONS

Exam Structure, Format, and Performance-Based Questions

The Security+ exam is structured to test both conceptual knowledge and practical application through a combination of traditional multiple-choice questions and performance-based questions (PBQs). This dual format reflects CompTIA’s objective to certify professionals who can not only recall security concepts but also apply them to realistic scenarios — addressing the criticism that purely knowledge-based exams do not validate practical competency.

Exam Format Details

Item Detail
Maximum Questions 90 questions (combination of multiple-choice and PBQs)
Time Limit 90 minutes (60 seconds per question at maximum; PBQs typically require more time
Passing Score 750 on a scale of 100–900 (approximately 83% scaled score; not a direct percentage of correct answers)
Scaled Scoring The 100–900 scale is a psychometric transformation that accounts for question difficulty variation between exam forms; the raw number of correct answers required varies slightly between forms
Question Ordering PBQs typically appear at the beginning of the exam; multiple-choice questions follow. Candidates can flag and return to questions but cannot return to the PBQ section after leaving it (in most delivery modes)
Exam Delivery Pearson VUE testing centers(in-person, supervised); Pearson VUE online proctored (from home or office, with webcam monitoring)
Retake Policy No mandatory waiting period for first retake; subsequent retakes require a 14-day waiting period; no maximum retake limit; full exam fee applies to each retake
Score Reporting Immediate pass/fail result at the testing center; detailed performance report by domain available through the Pearson VUE portal
Exam Language English (primary); Japanese, Portuguese, Simplified Chinese, and German available at select centers

Performance-Based Questions (PBQs)

Performance-based questions are the distinguishing feature of Security+ compared to purely multiple-choice examinations. PBQs present scenarios in interactive, simulated environments where candidates must perform actual security tasks rather than select an answer from a list. They test applied knowledge and problem-solving capability that multiple-choice questions cannot assess.

Item Detail
PBQ Types Drag-and-drop (matching items to categories, placing steps in correct sequence); fill-in-the-blank (typing a specific command, port number, or term); simulation (interacting with a simulated firewall, IDS, or network tool interface); ordering (arranging process steps in the correct sequence); hotspot (clicking the correct element in a network diagram or interface screenshot)
Typical PBQ Topics Firewall rule configuration (identifying correct ACL rules for a given policy); network troubleshooting (reading packet captures or network diagrams); cryptography application (selecting appropriate algorithm for a given requirement); incident response steps (ordering the phases of an IR lifecycle); access control configuration (selecting correct permission settings for a scenario); log analysis (identifying attack evidence in a log excerpt)
Time Allocation PBQs appear at the start of the exam; they are typically more time-consuming than multiple-choice questions. Candidates who spend excessive time on a difficult PBQ risk running short of time for the remaining questions. CompTIA recommends spending no more than 5–7 minutes per PBQ before flagging and moving on.
Scoring PBQs may be partially scored — candidates who get some elements of a multi-part PBQ correct may receive partial credit. This makes it worthwhile to attempt every PBQ rather than leaving them blank, even when unsure of the complete answer.
Cannot Skip Unlike multiple-choice questions, PBQs presented at the beginning of the exam cannot be skipped and revisited. Candidates must complete or flag each PBQ before advancing. This makes time management strategy for PBQs particularly important.
Tip
The most effective PBQ preparation strategy is hands-on practice rather than reading about PBQ topics. Set up a home lab using free tools: practice firewall rule configuration in pfSense, analyze packet captures in Wireshark, practice log analysis with the ELK stack or Splunk free tier, and complete scenario-based exercises on platforms like TryHackMe. The goal is to be able to recognize correct configurations and identify security issues in realistic simulated environments — not just recall definitions.
THE 5 SECURITY+ EXAM DOMAINS — COMPLETE REFERENCE

The 5 Security+ SY0-701 Exam Domains — Complete Reference

The SY0-701 examination is organized across five domains that collectively cover the full scope of foundational and intermediate information security practice. CompTIA publishes the official exam objectives document (available free from the CompTIA website) which specifies every sub-topic and sub-subtopic within each domain. The objectives document is the authoritative guide to exam content and should be the primary study roadmap for every candidate.

Each domain carries a published percentage weight indicating its proportional representation in the exam question pool. These weights should guide study time allocation — higher-weighted domains warrant more preparation time — but all domains must be studied thoroughly as weaknesses in any domain will affect the scaled score.

1.0

12% of Exam

General Security Concepts

Establishes the foundational vocabulary, principles, and conceptual framework underpinning all security practice. Sub-topics include: security controls (technical, managerial, operational, physical; preventive, detective, corrective, deterrent, compensating, directive), fundamental security concepts (CIA Triad — Confidentiality, Integrity, Availability; non-repudiation, authentication, authorization, accounting; zero trust principles — never trust always verify, least privilege, micro segmentation), change management security implications (approval process, impact assessment, testing, backout planning, legacy systems), basic cryptography concepts (symmetric vs. asymmetric encryption, hashing, digital signatures, key exchange, PKI fundamentals, common use cases for cryptographic protocols), and authentication concepts (password-based authentication, multi-factor authentication factors — Type 1/2/3, passwordless authentication, SSO concepts). This domain provides the conceptual vocabulary used throughout the entire exam and in professional security practice.

2.0

22% of Exam

Threats, Vulnerabilities, and Mitigations

The largest domain; covers the threat landscape, attack techniques, vulnerability types, and defensive countermeasures. Sub-topics include: threat actors and motivations (nation-state, organized crime, hacktivists, insiders, script kiddies — each with distinct capabilities, resources, and objectives), attack surfaces (on-premises, cloud, remote work, supply chain, IoT/OT), social engineering techniques (phishing, vishing, smishing, spear-phishing, whaling, BEC, pretexting, baiting, piggybacking, watering hole attacks), malware types (ransomware, Trojans, worms, spyware, adware, rootkits, backdoors, keyloggers, logic bombs, fileless malware), application attacks (SQL injection, XSS, buffer overflow, race conditions, directory traversal, privilege escalation, request forgery — CSRF and SSRF), network-based attacks (DoS/DDoS — volumetric, protocol, application layer; on-path/MITM; DNS attacks; VLAN hopping; replay attacks; ARP poisoning), indicators of malicious activity (network anomalies, host-based anomalies, application anomalies), and mitigation techniques for each attack category. This domain requires understanding both how attacks work and what controls defend against them.

3.0

18% of Exam

Security Architecture

Covers secure design principles for infrastructure, cloud, network, and application environments. Sub-topics include: security implications of different architectures (cloud — IaaS, PaaS, SaaS, shared responsibility model; hybrid cloud; on-premises; serverless; microservices; network infrastructure — physical vs. logical segmentation, software-defined networking; IoT; industrial control systems/SCADA/OT; embedded systems; RTOS), infrastructure considerations (device placement, security zones, attack surface minimization, connectivity technologies — cellular, VPN, SD-WAN, SASE), network security design (network segmentation, DMZ, jump server, proxy server, IDS/IPS placement, load balancers, web application firewalls, firewall types — stateless, stateful, NGFW, UTM), secure network protocols (DNS security, HTTPS, SFTP, SRTP, SNMPv3, IPSec, TLS/DTLS, SSH, LDAPS), data protection (data at rest, in transit, in use; encryption approaches; tokenization; data masking; rights management), resiliency and recovery (high availability, geographic dispersal, RAID levels, replication, backup strategies — 3-2-1 rule, RTO/RPO, DR site types — hot/warm/cold), and zero trust implementation components (policy engine, policy administrator, policy enforcement point). Architecture questions require applying design principles to specific scenarios — not just defining terms.

4.0

28% of Exam

Security Operations

The largest domain by weight; covers the day-to-day operational security activities that maintain organizational security posture. Sub-topics include: identity and access management operations (user lifecycle management — provisioning, deprovisioning, role-based access, privilege management; MFA enforcement; PAM; federation and SSO technologies — SAML, OAuth 2.0, OpenID Connect, RADIUS, TACACS+, Kerberos; directory services — LDAP, Active Directory), security alerting and monitoring (SIEM — log aggregation, correlation, alerting; SOAR — automated response playbooks; EDR/XDR; network traffic analysis; threat intelligence feeds — STIX/TAXII, IoC types), automation and orchestration in security (benefits of automation, playbook development, API-based security integrations, security script basics), vulnerability management (scan types — credentialed vs. non-credentialed, internal vs. external; CVSS scoring and prioritization; remediation workflows; patch management; penetration testing integration), incident response (NIST IR lifecycle — Preparation, Detection, Analysis, Containment, Eradication, Recovery, Post-Incident Activity; incident classification; digital forensics — order of volatility, chain of custody, evidence preservation; e-discovery), endpoint security operations (antivirus/anti-malware, EDR, application control, disk encryption, patch management, host-based IDS/IPS), hardening techniques (default credential removal, disabling unnecessary services and ports, patch management, encryption at rest, secure baseline configurations — CIS Benchmarks, STIG), cloud security operations (cloud security posture management — CSPM, secrets management, serverless security, container security — image scanning, runtime security), and network security operations (firewall management, IDS/IPS tuning, network segmentation maintenance, wireless security operations — 802.1X, EAP types). This domain rewards candidates with practical operational experience the most.

5.0

20% of Exam

Security Program Management and Oversight

Covers the governance, risk management, compliance, and program management activities that direct and oversee the security function. Sub-topics include: elements of effective security governance (security policies — acceptable use, data handling, password policies, BYOD, clean desk, social media; policy frameworks and standards — NIST CSF, ISO 27001, SOC 2, CIS Controls; security program structure and ownership), risk management (risk assessment types — qualitative and quantitative; risk treatment options — accept, avoid, transfer, mitigate; business impact analysis; risk register; risk tolerance and appetite), third-party risk management (vendor assessment, supply chain risk, right-to-audit clauses, SLA security requirements, questionnaire frameworks), data classification and privacy (data classification tiers — public, internal, confidential, restricted; data subject rights; privacy regulations — GDPR, CCPA, HIPAA; data retention and destruction), compliance frameworks and legal considerations (regulatory drivers — PCI DSS, HIPAA, GDPR, SOX; compliance monitoring; audit and assessment types — internal, external, compliance, penetration test; security reporting and KPIs), security awareness and training (phishing simulation programs, security culture, role-based training, new hire orientation, metrics for awareness effectiveness), and automation and AI in governance (automated compliance monitoring, AI-assisted risk assessment, governance tools). The GRC domain tests the understanding of security management as a business function — not just technical operations.

DOMAIN WEIGHTS & STUDY PRIORITY

Domain Weights and Study Priority

Domain Exam Weight Study Priority Notes
1.0: General Security Concepts 12% Smallest domain; do not underestimate — foundational vocabulary tested throughout the entire exam; all other domains assume Domain 1 concepts; cryptography sub-topics require dedicated study time
2.0: Threats, Vulnerabilities & Mitigations 22% Second highest weight; largest content breadth; requires memorizing attack types, malware categories, social engineering techniques, and specific countermeasures; attack scenario questions are most common on exam
3.0: Security Architecture 18% Network design, cloud architecture, and secure protocol selection; diagram-based PBQs often draw from this domain; hybrid cloud and zero trust architecture are particularly high-frequency topics
4.0: Security Operations 28% Highest weight; most operationally broad; identity/access management, incident response, vulnerability management, and hardening are all high-frequency; candidates with operational security experience have a natural advantage
5.0: Security Program Management & Oversight 20% Often underestimated; GRC frameworks, risk quantification, privacy regulations (GDPR, CCPA, HIPAA), and third-party risk management require dedicated study; many candidates find this the least familiar domain
KEY CONCEPTS & TECHNICAL AREAS IN DEPTH

Key Concepts and Technical Areas in Depth

Certain conceptual areas are tested with particularly high frequency across Security+ exam domains. The following sections provide deeper coverage of the highest-priority technical areas — those that appear most consistently in Security+ exam questions and which candidates most commonly struggle with.

Cryptography: Algorithms, Protocols, and Applications

Item Detail
Symmetric Encryption Same key encrypts and decrypts; fast; suitable for bulk data encryption; key exchange is the primary challenge. Algorithms: AES (Advanced Encryption Standard — 128, 192, 256-bit keys; current standard; modes include ECB, CBC, CTR, GCM), DES (56-bit; deprecated — too weak), 3DES (triple DES; 168-bit effective; deprecated by NIST 2023), Blowfish/Twofish (less common alternatives), RC4 (stream cipher; deprecated — used in WEP; broken).
Asymmetric Encryption Public/private key pair; public key encrypts, private key decrypts; solves key distribution; computationally expensive. Algorithms: RSA (Rivest–Shamir–Adleman; 2048-bit minimum; used for key exchange and digital signatures), ECC (Elliptic Curve Cryptography; equivalent security with smaller keys; used in ECDH and ECDSA; preferred for constrained environments), Diffie-Hellman (DH/ECDH; key exchange only — not encryption; enables Perfect Forward Secrecy in TLS).
Hashing One-way function; fixed-length output; collision resistant; cannot be reversed. Uses: password storage, data integrity, digital signatures. Algorithms: MD5 (128-bit output; deprecated — collision attacks; still seen in legacy systems), SHA-1 (160-bit; deprecated — collision attacks demonstrated), SHA-256 / SHA-2 family (current standard; 256, 384, 512-bit variants), SHA-3 (alternative construction; resistant to SHA-2 weaknesses), bcrypt/scrypt/Argon2 (password-specific; intentionally slow with salt; recommended for credential storage).
Digital Signatures Sender signs message hash with private key; recipient verifies with sender’s public key; provides authentication, integrity, non-repudiation. Standard: RSA-PSS or ECDSA; used in code signing, S/MIME email, PDF signing, TLS certificate validation, and software update authentication.
PKI Components Certificate Authority (CA) — trusted entity that signs certificates; Root CA (offline; signs intermediate CAs); Intermediate CA (online; signs end-entity certificates); Certificate (X.509 format; contains: subject, issuer, public key, validity period, serial number, signature); Certificate Revocation List (CRL) and OCSP (Online Certificate Status Protocol) for revocation checking; Certificate Signing Request (CSR); trust chain / chain of trust. Know the difference between self-signed and CA-signed certificates.
TLS/SSL Transport Layer Security (TLS) secures network communications — HTTPS, email (SMTPS, IMAPS), and application traffic. TLS 1.3 is current standard; TLS 1.0 and 1.1 deprecated; SSL (all versions) deprecated. TLS handshake: establishes cipher suite, authenticates server (and optionally client), negotiates session keys using asymmetric cryptography, then switches to symmetric encryption for bulk data transfer. Perfect Forward Secrecy (PFS): ephemeral key exchange means past sessions cannot be decrypted if long-term keys are later compromised.
Common Use Cases for Cryptographic Algorithms HTTPS/TLS: RSA or ECDH for key exchange + AES for data; SSH: ECDH + AES; VPN (IPSec): DH for key exchange + AES for data + HMAC for integrity; Email (S/MIME): RSA + AES + SHA; PGP/GPG: RSA or ECC + AES + SHA; Password storage: bcrypt/Argon2 with salt; Code signing: RSA or ECDSA; Disk encryption (BitLocker/FileVault/LUKS): AES-256.
Steganography Hiding data within another file (image, audio, video) without visible detection; different from encryption — the existence of the message is hidden, not just the content. Used by attackers for data exfiltration (hiding stolen data in innocuous files) and for covert communication. Detection: steganalysis tools; unusual file size increases; statistical analysis of pixel values.

Network Protocols, Ports, and Security Relevance

Security+ heavily tests knowledge of specific protocols, their default ports, whether they transmit data in plaintext or encrypted form, and their secure alternatives. Candidates must memorize the following:

Protocol Port(s) Security Notes
HTTP 80 TCP Plaintext web traffic; always replace with HTTPS (443); susceptible to MitM, sniffing, session hijacking
HTTPS 443 TCP HTTP encrypted with TLS; current standard for all web traffic; HSTS enforces HTTPS-only
FTP 20/21 TCP Plaintext file transfer; credentials transmitted in clear-text; replace with SFTP (22) or FTPS (990)
SFTP 22 TCP Secure file transfer over SSH; fully encrypted; preferred alternative to FTP
SSH 22 TCP Encrypted remote shell; replaces Telnet; used for remote administration, tunnelling
Telnet 23 TCP Plaintext remote shell; completely deprecated; credentials and all traffic in plaintext
SMTP 25 TCP Mail transfer; plaintext by default; port 587 (STARTTLS) or 465 (SMTPS) for encrypted email submission
DNS 53 UDP/TCP Domain resolution; plaintext by default; DNSSEC adds integrity; DoH (443) and DoT (853) add encryption
DHCP 67/68 UDP IP address assignment; no authentication — vulnerable to rogue DHCP servers; DHCP snooping mitigates
TFTP 69 UDP Trivial FTP; no authentication; plaintext; used for firmware updates; restrict to isolated networks
HTTP Alt / Squid 8080 TCP Web proxy port; commonly used for HTTP proxy and web caching
POP3 110 TCP Mail retrieval; plaintext; deprecated — use POP3S (995) with TLS
POP3S 995 TCP POP3 encrypted with TLS
IMAP 143 TCP Mail retrieval with server-side storage; plaintext; use IMAPS (993) with TLS
IMAPS 993 TCP IMAP encrypted with TLS
SMTPS 465 TCP SMTP encrypted with TLS for email submission
LDAP 389 TCP Directory queries; plaintext; replace with LDAPS (636) for encrypted directory traffic
LDAPS 636 TCP LDAP encrypted with TLS
SMB 445 TCP Windows file sharing; historically vulnerable (EternalBlue/WannaCry); restrict to internal networks
RDP 3389 TCP Remote Desktop Protocol; frequently targeted; use NLA, strong credentials, MFA; restrict to VPN
SNMP v1/v2 161/162 UDP Network management; community strings transmitted in plaintext; use SNMPv3 with authentication and encryption
SNMPv3 161/162 UDP SNMP with authentication and encryption; preferred for all network management
NTP 123 UDP Time synchronization; monlist attacks possible; NTPsec and authentication mitigate
Syslog 514 UDP Log forwarding; plaintext UDP; use TLS syslog (6514) for secure log transmission
BGP 179 TCP Internet routing; BGP hijacking attacks; RPKI adds route origin validation
RIP 520 UDP Legacy routing protocol; unauthenticated; replaced by OSPF/BGP in modern networks

Identity and Access Management: Protocols and Concepts

Item Detail
Authentication vs. Authorization vs. Accounting Authentication: verifying identity (who are you?); Authorization: determining what access is permitted (what can you do?); Accounting: tracking what was done (what did you do?). Together: AAA. Implemented by RADIUS and TACACS+ in network access control scenarios.
Multi-Factor Authentication (MFA) Combining two or more independent authentication factors: Type 1 (something you know — password, PIN, passphrase), Type 2 (something you have — hardware token, smart card, authenticator app OTP, phone), Type 3 (something you are — biometric: fingerprint, retina, voice, gait). 2FA uses exactly two factors. MFA uses two or more. Two-step verification (e.g., password + SMS code from the same account) is not true MFA. Phishing-resistant MFA: FIDO2/WebAuthn hardware keys (YubiKey, Google Titan) — cryptographically bound to the site origin.
Access Control Models Discretionary Access Control (DAC): resource owners control access; flexible but hard to manage at scale; default UNIX/Windows file system model. Mandatory Access Control (MAC): OS enforces access based on labels/classifications; subjects cannot override; used in government/military systems (SELinux). Role-Based Access Control (RBAC): permissions assigned to roles; users assigned to roles; standard enterprise model. Attribute-Based Access Control (ABAC): access decisions based on multiple attributes — user, resource, environment; most flexible and granular. Rule-Based Access Control: access decisions based on rules in an ACL; commonly used in firewall rule sets.
Federation and SSO Single Sign-On (SSO): authenticate once, access multiple applications without re-authenticating. SAML 2.0 (Security Assertion Markup Language): XML-based federation protocol; used for enterprise SSO and web SSO; supports browser-based authentication; IdP (Identity Provider) issues assertions consumed by SP (Service Provider). OAuth 2.0: authorization framework (not authentication); delegates access without sharing credentials; used by ‘Sign in with Google/Facebook’; defines access scopes. OpenID Connect (OIDC): authentication layer built on OAuth 2.0; adds ID token for user identity; used with OAuth for complete authentication + authorization. Kerberos: ticket-based authentication for Windows/AD environments; TGT (Ticket Granting Ticket) from KDC; used for network service authentication in enterprise. RADIUS: centralized authentication for network access (VPN, Wi-Fi); used with 802.1X; encrypts password only. TACACS+: Cisco-developed; encrypts entire payload; separates authentication, authorization, and accounting; preferred for device administration.
Privileged Access Management (PAM) Controls for managing privileged accounts (domain administrators, root accounts, service accounts): password vaulting (credentials stored and rotated automatically; never known to users), session recording (all privileged sessions recorded for audit), just-in-time (JIT) access (privileges granted for specific tasks, specific duration; revoked automatically), and privileged account monitoring (alerts on anomalous privileged activity). Key PAM products: CyberArk, BeyondTrust, Delinea, HashiCorp Vault.
Zero Trust Identity Principles Never trust, always verify: no implicit trust based on network location or previous authentication. Every access request verified against identity, device health, location, and risk signals. Continuous authorization: trust is re-evaluated during active sessions, not only at login. Least privilege: minimum permissions granted for the specific task. Microsegmentation: network access limited to specific resources required; no broad network trust.

Threat Actors and Attack Techniques

Item Detail
Threat Actor Types Nation-state actors: government-sponsored; APT methodology; sophisticated tools; espionage, sabotage, IP theft objectives; well-resourced and patient. Organized criminal groups: financially motivated; ransomware, fraud, credential theft; professional operations. Hacktivists: ideologically motivated; DDoS, defacement, data disclosure. Insider threats: current/former employees; malicious (theft, sabotage) or unintentional (misconfiguration, phishing susceptibility). Script kiddies: low skill; using existing tools without deep understanding; opportunistic. Competitor: corporate espionage; targeted IP theft. Shadow IT: employees deploying unauthorized technology; unintentional security risk.
Phishing Attack Variants Phishing: mass-distribution email impersonating legitimate senders to harvest credentials or deliver malware. Spear-phishing: targeted phishing with personalized content based on research. Whaling: spear-phishing targeting senior executives (CEO, CFO). Vishing: voice phishing via phone calls — impersonating IT support, government agencies, banks. Smishing: SMS-based phishing — malicious links via text message. Business Email Compromise (BEC): impersonating executives or vendors to authorize wire transfers or redirect payments. Pharming: redirecting users to fake websites via DNS manipulation — without clicking a phishing link. Pretexting: creating a fabricated scenario to manipulate targets (impersonating IT support, HR, auditors).
Malware Categories Ransomware: encrypts files and demands payment for decryption keys; often combined with data exfiltration for double extortion; RaaS (Ransomware-as-a-Service) model. Trojan: malicious software disguised as legitimate software; does not self-replicate; creates backdoors. Worm: self-replicating malware that spreads across networks without user interaction; exploits vulnerabilities. Virus: attaches to legitimate programs; requires user action to spread; file infectors, macro viruses. Rootkit: conceals itself and other malware within the OS or firmware; difficult to detect and remove; operates at kernel level. Spyware/Keylogger: silently monitors and exfiltrates user activity, credentials, or keystrokes. Backdoor: covert persistent access mechanism installed by malware or attackers. Fileless malware: executes in memory without writing to disk; uses legitimate tools (PowerShell, WMI); evades file-based antivirus. Logic bomb: dormant malicious code activated by a specific trigger (date, event, condition). Adware: displays unwanted advertisements; often bundled with free software; may track browsing.
Network Attacks DoS (Denial of Service): single source; resource exhaustion or disruption. DDoS (Distributed DoS): multiple coordinated sources (botnet); volumetric (bandwidth flooding — UDP flood, DNS amplification, NTP amplification), protocol (SYN flood, Ping of Death, Smurf), application layer (HTTP flood, Slowloris). On-path attack (MitM): intercepting and potentially modifying traffic between two parties; ARP poisoning, evil twin Wi-Fi, SSL stripping. Replay attack: capturing and re-transmitting valid authentication tokens or transactions; prevented by nonces and timestamps. DNS attacks: DNS poisoning/spoofing (redirecting legitimate domains to malicious IPs), DNS hijacking (modifying DNS records), DNS amplification (DDoS reflection). VLAN hopping: switch spoofing or double tagging to access VLANs beyond authorized scope. MAC flooding: overwhelming a switch’s MAC address table to cause it to broadcast all traffic (fail-open mode, enabling sniffing).
Application Attacks SQL Injection (SQLi): inserting malicious SQL code into input fields; reads, modifies, or deletes database data; prevented by parameterized queries and input validation. Cross-Site Scripting (XSS): injecting malicious scripts into web pages viewed by other users; stored (persisted in database), reflected (in URL parameters), DOM-based; prevented by output encoding. Cross-Site Request Forgery (CSRF): tricking authenticated users into executing unintended actions on a web application; prevented by CSRF tokens and SameSite cookie attribute. Server-Side Request Forgery (SSRF): causing the server to make requests to internal resources on behalf of the attacker; cloud metadata service exploitation. Buffer overflow: writing beyond allocated memory buffer; can cause crashes or arbitrary code execution; prevented by input validation, ASLR, DEP/NX, stack canaries. Directory traversal: using path traversal sequences (../../) to access files outside the web root; prevented by input sanitization and file access controls. Privilege escalation: exploiting vulnerabilities or misconfigurations to gain higher-level access than authorized.
SECURITY TOOLS & TECHNOLOGIES

Security Tools and Technologies

Security+ tests knowledge of a wide range of security tools and technologies — both in terms of their function and their appropriate application to specific security problems. Candidates must understand which tool addresses which security need, how to interpret tool outputs in scenario questions, and the strengths and limitations of each tool category.

Detection and Monitoring Tools

Item Detail
SIEM (Security Information & Event Management) Aggregates and correlates log data from across the environment — endpoints, network devices, servers, cloud services, identity systems — and applies rules and analytics to generate security alerts. Provides central visibility, compliance reporting, and historical investigation capability. Key products: Microsoft Sentinel, Splunk, IBM QRadar, LogRhythm, Elastic SIEM. Security+ candidates must understand log sources, correlation rule concepts, and how to interpret SIEM alerts.
IDS / IPS Intrusion Detection System (IDS): monitors network traffic or host activity for attack signatures or anomalies; generates alerts but does not block. Intrusion Prevention System (IPS): actively blocks detected threats in addition to alerting. Signature-based: matches known attack patterns; fast but cannot detect novel attacks. Anomaly-based (behavioral): establishes baseline, flags deviations; detects novel attacks but higher false positive rate. Network-based (NIDS/NIPS): monitors network traffic. Host-based (HIDS/HIPS): monitors activity on individual endpoints. False positive (legitimate activity flagged as malicious) and false negative (malicious activity not detected) are key IDS concepts.
EDR / XDR Endpoint Detection and Response (EDR): continuous endpoint monitoring, behavioral threat detection, investigation tools, and response capability (process kill, isolation). Examples: CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black. Extended Detection and Response (XDR): correlates telemetry from endpoints, networks, email, identity, and cloud into unified detection and response platform; reduces siloed alert context.
Vulnerability Scanners Automated tools that identify known vulnerabilities (CVEs), misconfigurations, and missing patches. Credentialed scans (with authentication) provide deeper visibility — patch status, software versions, service configuration; unauthenticated scans show only what is visible from the network. Key tools: Nessus, OpenVAS/Greenbone, Qualys, Nexpose, Rapid7. CVSS score output — understand 0–10 severity scale, base vs. environmental vs. temporal scores.
SOAR (Security Orchestration, Automation & Response) Automates repetitive SOC workflows through playbooks: alert enrichment, threat intelligence lookup, indicator blocking, ticket creation, analyst notification. Reduces manual workload and mean time to respond. Works alongside SIEM — SIEM generates alerts; SOAR automates the response workflow. Examples: Splunk SOAR (Phantom), Palo Alto XSOAR, Microsoft Sentinel playbooks, ServiceNow SecOps.
Threat Intelligence Platforms Aggregate, normalize, and operationalize threat intelligence from commercial feeds, open-source (VirusTotal, AlienVault OTX, MISP), and government sources (CISA, ISAC feeds). Produce IoCs (Indicators of Compromise — IP addresses, domain names, file hashes, email addresses) that are distributed to blocking controls. STIX (Structured Threat Information Expression) and TAXII (Trusted Automated eXchange of Intelligence Information) are the standard formats and transport protocols for threat intelligence sharing.

Network Security Technologies

Item Detail
Firewall Types Packet filter (stateless): inspects individual packets against ACL rules; no session awareness; fast but limited. Stateful inspection: tracks connection state; understands TCP handshake; more intelligent than packet filter. Next-Generation Firewall (NGFW): application-layer inspection, user-identity awareness, SSL/TLS inspection, integrated IPS, threat intelligence feeds; most capable. Unified Threat Management (UTM): NGFW plus additional security services (antivirus, web filtering, email security) in a single appliance; common in SMB environments. Web Application Firewall (WAF): inspects HTTP/S traffic; protects web applications against OWASP Top 10 attacks (SQLi, XSS, CSRF); deployed in front of web applications.
Network Access Control (NAC) Enforces security policy compliance for devices before granting network access: checking patch status, antivirus presence, OS version, certificates. IEEE 802.1X: port-based NAC; authenticates devices/users via RADIUS before granting switch or Wi-Fi access; uses EAP (Extensible Authentication Protocol) methods — EAP-TLS (certificate-based; strongest), PEAP (username/password protected by TLS tunnel), EAP-TTLS. Quarantine VLAN: non-compliant devices placed in isolated VLAN with access only to remediation resources.
VPN Technologies Site-to-site VPN: connects two networks permanently; replaces dedicated WAN circuits; uses IPSec or TLS. Remote access VPN: individual user connects to corporate network from remote location; full tunnel (all traffic through VPN) vs. split tunnel (only corporate traffic through VPN; internet traffic goes direct). SSL/TLS VPN: browser-based or thin-client; operates over HTTPS port 443; easier to deploy through firewalls. IPSec VPN: tunnel mode (entire packet encrypted; used for site-to-site) vs. transport mode (payload only encrypted; used for host-to-host). Always-on VPN: automatically connects when device leaves corporate network. ZTNA (Zero Trust Network Access): replaces VPN with application-specific access based on continuous identity and device verification.
Wireless Security WEP (Wired Equivalent Privacy): 64/128-bit RC4 encryption; completely broken — never use. WPA (Wi-Fi Protected Access): TKIP encryption; deprecated. WPA2-Personal: AES-CCMP encryption; passphrase-based; vulnerable to offline dictionary attacks on captured 4-way handshake. WPA2-Enterprise: 802.1X authentication; each user has unique credentials; much stronger than personal mode. WPA3-Personal: SAE (Simultaneous Authentication of Equals) replaces PSK; resistant to offline dictionary attacks; forward secrecy. WPA3-Enterprise: 192-bit security mode. Evil twin attack: rogue AP with same SSID as legitimate AP; captures credentials or traffic. De-authentication attack: forces clients to reconnect; enables handshake capture. Captive portals: redirect unauthenticated clients to authentication page; common in guest Wi-Fi.
DNS Security DNSSEC: cryptographic signing of DNS records; verifies record integrity and authenticity; prevents DNS cache poisoning. DNS over HTTPS (DoH): encrypts DNS queries within HTTPS (port 443); prevents ISP eavesdropping and DNS manipulation; implemented in modern browsers. DNS over TLS (DoT): encrypts DNS queries over TLS (port 853); more explicit separation from web traffic than DoH. DNS sink holing: redirecting malicious domain resolution to a controlled IP — prevents malware C2 communication; used in enterprise security and law enforcement. Split-horizon DNS: different DNS responses for internal vs. external queries — prevents internal naming disclosure.
Load Balancers and Proxies Load balancer distributes traffic across multiple servers for availability and performance; also provides a security layer — hides individual server addresses; can perform SSL termination and provide some WAF functionality. Forward proxy: client-side proxy; intercepts outbound client requests; enables URL filtering, content inspection, SSL inspection, and anonymous browsing. Reverse proxy: server-side proxy; intercepts inbound requests to servers; hides server infrastructure; provides load balancing, SSL termination, and WAF protection. Transparent proxy: intercepts traffic without client configuration (no proxy settings required); used for content filtering and monitoring.
INCIDENT RESPONSE & DIGITAL FORENSICS

Incident Response and Digital Forensics

Incident response and digital forensics are among the most heavily tested operational topics on the Security+ exam. Candidates must understand the lifecycle of incident response, specific forensic techniques and principles, and the legal and procedural considerations that govern how digital evidence is collected, preserved, and analyzed.

NIST Incident Response Lifecycle (SP 800-61)

Item Detail
Phase 1: Preparation Establishing IR capability before incidents occur: developing and testing IR plans and playbooks, training the IR team, deploying detection tooling (SIEM, EDR), establishing communication procedures, identifying key contacts (legal, communications, executive escalation), and preparing evidence collection tools. Preparation is the highest-leverage investment — everything that makes response faster and more effective happens here.
Phase 2: Detection and Analysis Identifying that a security incident has occurred and characterizing its scope, impact, and severity: analyzing alerts from security tools, reviewing logs, correlating events across multiple data sources, establishing the timeline of the incident, identifying affected systems and data, and classifying the incident by type and severity. Indicators of Compromise (IoCs) — specific technical artifacts indicating compromise — are identified and documented during this phase.
Phase 3: Containment Limiting the spread and impact of the incident while preserving evidence: short-term containment (isolating affected systems from the network, blocking malicious IPs, disabling compromised accounts), evidence preservation (forensic imaging of affected systems before remediation), and long-term containment (implementing more sustainable controls while full remediation is prepared — enhanced monitoring, network segmentation adjustments, temporary access restrictions).
Phase 4: Eradication Removing the root cause of the incident from the environment: eliminating malware, removing unauthorized accounts and persistence mechanisms, closing exploited vulnerabilities (patching, configuration correction), and validating that all attacker footholds have been removed. Incomplete eradication leads to re-compromise — thorough investigation of persistence mechanisms is essential before declaring eradication complete.
Phase 5: Recovery Restoring affected systems and services to normal operation: rebuilding from clean backups or known-good images, validating system integrity before bringing systems back online, restoring data from backup, conducting post-restoration testing to confirm normal operation, and implementing enhanced monitoring for signs of re-compromise during the initial recovery period.
Phase 6: Post-Incident Activity (Lessons Learned) Structured review of the incident to improve future capability: documenting the complete incident timeline, identifying what detection or prevention controls failed, determining what controls could have caught the incident earlier, identifying process improvements, and updating playbooks, policies, and controls based on findings. Lessons learned meetings should include all stakeholders and result in a written report with tracked remediation actions.

Digital Forensics Principles

Item Detail
Order of Volatility The sequence in which digital evidence should be collected — most volatile (most easily lost) first: CPU registers and cache, RAM/system memory, active network connections and processes, running processes, temporary file system data, disk (hard drive/SSD), remote logging and monitoring data, physical configuration and network topology, archival media. Collecting memory before disk is critical — active malware processes, encryption keys, network connections, and user activity are only in RAM.
Chain of Custody The documented record of who collected, handled, transferred, and accessed evidence from the point of collection through to court presentation. Every transfer of evidence must be documented and signed. Purpose: demonstrates that evidence has not been tampered with; required for evidence to be admissible in legal proceedings. Chain of custody documentation includes: who collected it, when and where, how it was packaged and sealed, every person who accessed it subsequently, and storage conditions.
Evidence Integrity Forensic copies of digital evidence must be bit-for-bit identical to the original. Hash verification (MD5 or SHA-256 of the original and the forensic copy) proves the copy is identical and that evidence has not been modified. Write blockers prevent inadvertent modification of evidence during imaging. FTK Imager, dd, and similar tools create forensic images with hash verification.
Legal Hold A directive to preserve all potentially relevant data when litigation or investigation is reasonably anticipated. Suspends normal data retention and deletion policies for covered data. Failure to implement legal hold when required can result in spoliation of evidence — destruction of evidence after a duty to preserve arose — which can result in serious legal consequences.
Data Acquisition Types Static acquisition: imaging a powered-off drive; most straightforward; complete bit-for-bit copy. Live acquisition: imaging a running system while powered on; necessary to capture volatile data (RAM, active connections); risk of evidence modification during collection. Logical acquisition: copies files and directories rather than raw sectors; faster but misses deleted files and slack space. Remote acquisition: imaging over a network; used when physical access is not possible.
Anti-Forensics Techniques (Attacker Perspective) Attackers use anti-forensics to frustrate investigation: log clearing and timestamp manipulation, secure file deletion (overwriting files to prevent recovery), encryption of malicious files, fileless malware (no disk artifacts), steganography (hiding data in innocuous files), and covert communication channels. Understanding these techniques helps forensic investigators know where to look and what to expect.
GOVERNANCE, RISK, COMPLIANCE & PRIVACY

Governance, Risk, Compliance, and Privacy

Domain 5 (Security Program Management and Oversight) is frequently underestimated by candidates with strong technical backgrounds. Its content covers the governance and business dimensions of security — policy frameworks, risk management methodology, regulatory compliance, and privacy law — that are tested as heavily as technical topics in Domain 4. Candidates who skip or skim this domain consistently underperform.

Key Security Frameworks

Item Detail
NIST Cybersecurity Framework (CSF) 2.0 Voluntary US framework for managing cybersecurity risk across six functions: Govern (security governance and risk management strategy — new in CSF 2.0), Identify (asset management, risk assessment), Protect (access control, security awareness, data security, resilience), Detect (continuous monitoring, anomaly detection), Respond (incident response, communications), Recover (recovery planning, improvement). Widely adopted as a risk management reference across all sectors globally.
NIST SP 800-53 Comprehensive security and privacy control catalog for US federal information systems; provides controls across 20 control families; used as the basis for federal system authorization (ATO process under RMF). Mapped to CSF for organizations using both frameworks.
ISO/IEC 27001 International standard for Information Security Management Systems (ISMS); certifiable against by third-party auditors; Plan-Do-Check-Act cycle; Annex A provides a control reference of 93 controls in 4 themes. Most widely recognized international security management standard; particularly important for European and multinational organizations.
CIS Controls (v8) Center for Internet Security Controls; 18 control groups with 153 safeguards prioritized by security impact and implementation feasibility; Implementation Group 1 (IG1 — 56 safeguards) represents the minimum viable security for all organizations regardless of size. Highly practical and actionable; maps to NIST CSF and ISO 27001.
SOC 2 AICPA audit standard for service organizations; evaluates controls relevant to Trust Services Criteria (TSC): Security (required), Availability, Processing Integrity, Confidentiality, Privacy (optional). Type I: controls designed correctly at a point in time. Type II: controls operated effectively over an audit period (typically 6–12 months). Critical for SaaS providers and cloud services vendors in B2B relationships.
PCI DSS (Payment Card Industry Data Security Standard) Mandatory for organizations that store, process, or transmit cardholder data; 12 requirements across network security, access control, encryption, monitoring, and vulnerability management; quarterly vulnerability scanning and annual penetration testing required; QSA (Qualified Security Assessor) performs formal assessments for Levels 1 and 2 merchants.

Risk Management Concepts

Item Detail
Risk Assessment: Qualitative vs. Quantitative Qualitative: uses relative scales (High/Medium/Low; 1–5 ratings) for likelihood and impact; faster, accessible, subjective. Quantitative: uses financial values — Asset Value (AV), Exposure Factor (EF), Single Loss Expectancy (SLE = AV × EF), Annualized Rate of Occurrence (ARO), Annualized Loss Expectancy (ALE = SLE × ARO), and safeguard value (ALE before – ALE after – annual safeguard cost). Security+ candidates must be able to calculate SLE and ALE from given values.
Risk Treatment Options Risk Mitigation (Accept + Reduce): implementing controls to reduce likelihood or impact — most common response for significant risks. Risk Transfer: shifting financial risk to a third party — cyber insurance, contractual indemnification. Risk Avoidance: discontinuing the risk-creating activity — cessation of a business process or service. Risk Acceptance: formally acknowledging and accepting the residual risk — documented, time-bounded, with executive sign-off; appropriate only when treatment cost exceeds expected loss.
Threat Modeling Structured process for identifying potential security threats to a system or application during design: STRIDE model (Spoofing identity, Tampering with data, Repudiation, Information disclosure, Denial of service, Elevation of privilege); PASTA (Process for Attack Simulation and Threat Analysis); attack trees. Goal: identify and address threats at design time when remediation cost is lowest.
Business Impact Analysis (BIA) Identifies critical business functions, their dependencies on IT systems, and the financial and operational impact of disrupting them at various time points. Outputs: Maximum Tolerable Downtime (MTD) / Maximum Tolerable Period of Disruption (MTPD), Recovery Time Objective (RTO — how quickly systems must be restored), Recovery Point Objective (RPO — maximum acceptable data loss measured in time), Mean Time to Recovery (MTTR), Mean Time Between Failures (MTBF). These metrics drive DR architecture and backup strategy decisions.
Security Policy Types Acceptable Use Policy (AUP): defines permissible and prohibited uses of organizational technology assets. Data Handling Policy: specifies how data must be classified, stored, transmitted, retained, and destroyed by classification level. Password Policy: minimum length, complexity, history, expiration, and lockout requirements. BYOD (Bring Your Own Device) Policy: conditions under which personal devices may access corporate resources; MDM/MAM requirements. Clean Desk Policy: requirements for securing sensitive materials when workstations are unattended. Social Media Policy: guidance on organizational information disclosure on public platforms. Incident Response Policy: defines what constitutes an incident, reporting requirements, and response authority.

Privacy Regulations Tested on Security+

Item Detail
GDPR (General Data Protection Regulation) EU regulation governing personal data of EU residents; applies to any organization processing EU resident data regardless of location. Key provisions: lawful basis for processing, data minimization, purpose limitation, data subject rights (access, rectification, erasure, portability, restriction, objection), data breach notification within 72 hours, Data Protection Officer (DPO) requirement for certain organizations, Data Protection Impact Assessment (DPIA) for high-risk processing, transfer restrictions for data leaving the EU/EEA. Fines: up to 4% of global annual turnover or €20 million.
CCPA / CPRA (California Consumer Privacy Act / Privacy Rights Act) US state law (California) provides consumer data rights: right to know what data is collected, right to delete personal information, right to opt-out of data sale, right to non-discrimination for exercising rights. CPRA (2023) added: right to correct inaccurate information, right to limit use of sensitive personal information, and created the California Privacy Protection Agency. Often considered the US equivalent of GDPR for California residents.
HIPAA (Health Insurance Portability and Accountability Act) US federal law protecting health information (PHI — Protected Health Information). Security Rule: administrative, physical, and technical safeguards for electronic PHI (ePHI). Privacy Rule: limitations on use and disclosure of PHI. Breach Notification Rule: notification to affected individuals, HHS, and media (for large breaches) within 60 days. Business Associate Agreements (BAA) required for all vendors with PHI access. Minimum necessary standard: only the minimum PHI necessary for the purpose should be used or disclosed.
SOX (Sarbanes-Oxley Act) US federal law for publicly traded companies; Section 302 requires CEO/CFO certification of financial report accuracy; Section 404 requires internal controls over financial reporting assessment; Section 802 protects whistleblowers; implications for IT: access controls on financial systems, audit logging of all financial system access, change management controls, data integrity requirements for financial records. SOX compliance is enforced by the SEC and PCAOB.
Data Classification Most organizations implement a 4-tier scheme: Public (no restrictions; openly available), Internal/Private (non-sensitive internal information; standard access controls), Confidential (sensitive business information; restricted access, encryption required), Restricted/Highly Confidential (most sensitive — PII, PHI, financial data, trade secrets; strict access controls, enhanced encryption, audit logging). Government classification: Unclassified, Controlled Unclassified Information (CUI), Confidential, Secret, Top Secret.
SECURITY+ VS. COMPARABLE CERTIFICATIONS

Security+ Compared with Comparable Certifications

Security+ occupies the entry-to-intermediate tier of the cybersecurity certification landscape. Understanding its positioning relative to both foundational certifications (that precede it) and advanced certifications (that follow it) helps candidates plan their certification journey and helps employers understand the level of expertise the credential represents.

Certification Issuing Body Level & Focus Best Suited For
CompTIA Security+ CompTIA Entry-to-intermediate; vendor-neutral broad security baseline; DoD 8570 IAT Level II; no prerequisites required; 3-year renewal IT professionals seeking first security credential; DoD/government IT workers; professionals moving from Network+ to security specialization; anyone needing DoD 8570 IAT II compliance
CompTIA Network+ CompTIA Foundational networking; recommended prerequisite for Security+; no security-specific content but network knowledge is essential for security IT generalists building toward Security+; those without a strong networking foundation who need to understand routing, switching, protocols before tackling security
CompTIA CySA+ CompTIA Intermediate; security analytics and operations; threat detection, SIEM, vulnerability management, incident response; DoD 8570 CSSP Analyst Security analysts, SOC Tier 1-2 professionals; those who have Security+ and want to deepen analytics and operations knowledge; natural next step after Security+
CompTIA PenTest+ CompTIA Intermediate; penetration testing; vulnerability assessment, exploit execution, reporting; DoD 8570 CSSP Analyst Security professionals focused on offensive security and penetration testing; complements Security+ with hands-on attack skills
CompTIA CASP+ CompTIA Advanced; enterprise security architecture; no exam score pass/fail — mastery demonstrated; DoD 8570 IASAE Level I and II Senior security practitioners; enterprise security architects; those with 10+ years who want advanced technical (not management) credentials
CISSP ISC2 Advanced; management-oriented broad security; 8 domains; 5-year experience required; gold standard for senior security Experienced professionals (5+ years) targeting CISO, security director, architect, and senior management roles; significant step up from Security+ in depth and experience requirements
CEH EC-Council Intermediate; ethical hacking / penetration testing; 20 domains covering attack lifecycle; DoD 8570 IAT Level II Penetration testers, red teamers, offensive security professionals; complements Security+ with attack-focused methodology and tooling
GISF / GSEC GIAC/SANS Entry/Intermediate; SANS-curriculum aligned; GSEC is significantly more technical than Security+; expensive Professionals completing SANS SEC courses; those wanting GIAC brand recognition; GSEC is considerably harder and more expensive than Security+

CompTIA Certification Pathway

Item Detail
IT Fundamentals (ITF+) Entry point for non-IT professionals; covers basic IT concepts; not a career credential — a starting point for those with no IT background
A+ Foundational IT support certification; hardware, operating systems, troubleshooting; recommended first professional certification for IT career entry
Network+ Foundational networking; TCP/IP, network architecture, protocols, troubleshooting; recommended prerequisite for Security+
Security+ Baseline security credential; recommended after Network+ and 2 years IT experience; subject of this document
CySA+ / PenTest+ Intermediate specializations following Security+: CySA+ for security analysis/operations; PenTest+ for penetration testing and vulnerability assessment
Cloud+ Intermediate cloud technology certification; complements Security+ for cloud-focused roles
CASP+ (CompTIA Advanced Security Practitioner) Advanced enterprise security; for senior practitioners; no associate/professional tier — directly follows Security+ and specializations at the advanced level
Linux+ Intermediate Linux administration; complements Security+ for roles requiring Linux proficiency (most security roles benefit from Linux skills)
STUDY STRATEGY & EXAM PREPARATION

Study Strategy and Exam Preparation

Security+ is an accessible but substantive certification that rewards structured preparation. Candidates with IT background and some security exposure typically require 2–3 months of dedicated preparation; those new to security or without networking foundation may need 4–6 months. The dual format (multiple-choice + PBQs) requires both conceptual study and hands-on practice — neither alone is sufficient.

Recommended Preparation Timeline

Phase Duration Activities
Foundation Assessment 1 week Download the official CompTIA SY0-701 Exam Objectives document (free from CompTIA.org) — this is the authoritative exam blueprint. Take a free diagnostic practice test to identify current knowledge baseline. Identify knowledge gaps by domain. Assess hands-on tool familiarity (Wireshark, firewall configuration, basic Linux command line).
Domain Study 6–10 weeks Work through each domain systematically using the exam objectives as your guide. Use your chosen study guide alongside the objectives document. Take notes by domain, particularly on: protocol names and port numbers, cryptographic algorithms and their use cases, attack types and their mitigations, and acronyms. Complete 20–30 practice questions after each major section.
Lab Practice (Parallel) 4–8 weeks (parallel with domain study) Hands-on practice for PBQ topics: set up packet capture practice in Wireshark (analyze HTTP vs. HTTPS, identify scanning patterns); practice firewall rule configuration (pfSense or cloud security group); practice log analysis in a free SIEM tool; complete scenario-based exercises on TryHackMe (Security+ learning path); set up Kali Linux for basic tool familiarity (Nmap scanning, basic Metasploit concepts without exploitation).
Practice Exam Intensive 2–3 weeks Complete full-length (90-question) practice exams under timed conditions (90 minutes). Target 80%+ on practice exams before scheduling the real exam (Security+ scaled at 750/900 ≈ 83%). Analyze every incorrect answer — understand why the correct answer is correct. Review weak domains with focused re-study. Complete at least 3–5 full-length timed practice exams total.
Final Week Review 1 week No new material; consolidation only. Review acronym and port number lists. Review cryptographic algorithm decision tables. Review IR lifecycle phases and forensic principles. Verify test center logistics. Get adequate sleep before exam day — fatigue significantly impacts performance on scenario-based questions.

Recommended Study Resources

Item Detail
CompTIA SY0-701 Official Exam Objectives Free from CompTIA.org; the authoritative blueprint for the exam; every sub-topic listed in the objectives has appeared or will appear on the exam; read it thoroughly before studying and use it to verify coverage of all topics
CompTIA Security+ Study Guide (Mike Chapple & David Seidl) Official CompTIA-endorsed study guide; comprehensive coverage of all domains; practice questions after each chapter; widely considered the gold standard reference for Security+
CompTIA Security+ Get Certified Get Ahead (Darril Gibson / Mike Chapple) A long-standing and highly regarded study guide known for its clear explanations, extensive practice questions, and exam-focused writing style; some candidates prefer this over the official guide
Professor Messer’s Security+ Course (Free) Completely free, high-quality video course by Professor Messer specifically aligned to the Security+ exam objectives; available on YouTube and ProfessorMesser.com; supplementary course notes and practice exams also available (paid); widely recommended as a supplement to a primary study guide
Jason Dion’s Security+ Practice Exams (Udemy) High-quality, exam-representative practice questions with detailed explanations; available on Udemy (frequently discounted); widely regarded as the best third-party practice exam resource for Security+
TryHackMe (Security+ Learning Path) Hands-on interactive platform with guided rooms covering Security+ domain topics in practical scenarios; essential for PBQ preparation; free and paid tiers; particularly valuable for candidates without hands-on security lab experience
CompTIA CertMaster Practice Official CompTIA practice exam and adaptive learning tool; provides exam-representative questions with explanations; progress tracking by domain; available as a standalone purchase or bundled with study guide
Wireshark (Free) Essential free tool for network traffic analysis practice; install and capture live traffic; open .pcap practice files from online resources; practice identifying protocols, analyzing HTTP vs. HTTPS, spotting scanning patterns and anomalies
Anki Flashcards (Free) Spaced repetition flashcard application; create cards for port numbers, cryptographic algorithms, protocol comparisons, acronyms, and attack types; daily flashcard review over several weeks is the most efficient memorization strategy for Security + large vocabulary
Tip
The CompTIA SY0-701 Exam Objectives document is free, authoritative, and underutilized. Most candidates skim it once and rely entirely on their study guide. The objectives document lists every specific sub-topic and sub-subtopic — when in doubt about whether a topic will appear on the exam, check the objectives. If a topic is in the objectives, prepare for it. If your study guide covers a topic not in the objectives, it is lower priority. Making the objectives document your study roadmap alongside a comprehensive guide is the most efficient preparation approach.
DOD 8570/8140 COMPLIANCE & GOVERNMENT RECOGNITION

DoD 8570/8140 Compliance and Government Recognition

The US Department of Defense’s DoD Directive 8570.01-M (and its successor DoD Instruction 8140.03) establishes mandatory cybersecurity certification requirements for all military and civilian personnel, and contractors, who perform Information Assurance (IA) functions on DoD networks. Security+ is the most commonly held DoD 8570 certification and is the primary compliance pathway for IAT Level II — the most widely required baseline in the DoD contractor community.

Security+ in DoD 8570/8140 Roles

Workforce Category Level Security+ Satisfies?
Information Assurance Technical (IAT) Level I No — IAT Level I satisfied by A+, CCNA-Security, Network+, SSCP, or Systems Security Certified Practitioner
Information Assurance Technical (IAT) Level II YES — Security+ is the primary certification for IAT Level II; also satisfied by CCNA Security, CySA+, GICSP, GSEC, SSCP
Information Assurance Technical (IAT) Level III No — IAT Level III requires CASP+, CISA, GCIH, GCED, CISSP, or CISSP-ISSAP/ISSEP/ISSMP
Information Assurance Management (IAM) Level I Yes — Security+ satisfies IAM Level I alongside CAP, GSLC, CISM, CISSP
Information Assurance System Architecture & Engineering (IASAE) Level I Yes — Security+ satisfies IASAE Level I (alone or with other certs in the category)
CSSP (Cyber Security Service Provider) Analyst Primary Yes — Security+ is approved for CSSP Analyst alongside CySA+, CEH, CFR, GCIH, GCIA
CSSP Infrastructure Support Primary Yes — Security+ is approved for CSSP Infrastructure Support
Key Concept
DoD 8570 IAT Level II compliance is required for a very large percentage of DoD contractor cybersecurity roles. Companies including Booz Allen Hamilton, Lockheed Martin, Raytheon, Leidos, SAIC, ManTech, and thousands of smaller defense contractors require Security+ as a hire condition for security-related positions. The combination of Security+ (IAT Level II) and an active or eligible-for-clearance background is the most common starting profile for DoD contractor cybersecurity careers. Many contractors reimburse exam fees and study materials for employees pursuing Security+.
CAREER PATHWAYS, ROLES & SALARY RANGES

Career Pathways, Roles, and Salary Ranges

Security+ is most valuable for professionals at the early-to-mid career stage in information security — those transitioning from general IT into security, those in entry-level security roles seeking to advance, and those in non-security IT roles who need to demonstrate security competency. It is also the mandatory baseline for a wide range of government and contractor positions, making it essential for public sector IT careers.

Roles That Value or Require Security+

Item Detail
Security Analyst (SOC Tier 1) Entry-level SOC position; monitoring security alerts, triaging events, escalating incidents; Security+ is frequently listed as required or preferred; provides the vocabulary and conceptual foundation for understanding SIEM alerts, IDS/IPS signatures, and network anomalies
IT Security Specialist / Administrator Mid-level role implementing and maintaining security controls: firewall management, endpoint security, patch management, access control, security monitoring; Security+ validates the broad knowledge set required for this generalist security role
Network Security Engineer Design and implementation of network security infrastructure: firewall rules, IDS/IPS configuration, VPN management, wireless security, network segmentation; Security+ combined with Network+ provides the foundation; CCNA Security or CySA+ often follows
System Administrator (Security Focus) System administrators with security responsibilities: hardening systems, managing access controls, implementing encryption, patch management, log review; Security+ is commonly listed in sysadmin job postings where security responsibilities are significant
Cloud Security Analyst Entry-to-mid security roles in cloud environments: cloud security posture review, IAM configuration, cloud logging and monitoring, compliance checks; Security+ SY0-701’s expanded cloud content makes it more relevant for cloud roles than previous versions; CompTIA Cloud+ or AWS/Azure security certifications often follow
Penetration Tester (Junior) Entry-level offensive security roles; vulnerability assessment, basic exploitation, report writing; Security+ provides the conceptual foundation but PenTest+ or CEH is typically required for dedicated pen test roles; Security+ can serve as the stepping stone
DoD / Government IT Security All IAT Level II positions within DoD agencies and contractors require Security+ or equivalent; this represents a very large employment market for Security+ holders including the US military branches, NSA, DHS, and thousands of government contractors
Help Desk / IT Support (Security-Aware) Help desk professionals with security awareness responsibilities: identifying and escalating suspicious activity, enforcing security policies, supporting security tool users; Security+ adds significant value in help desk roles that interface with security operations
Compliance / Risk Analyst (Junior) Entry-level GRC roles: assisting with compliance assessments, maintaining risk registers, supporting audit activities; Security+ Domain 5’s GRC content directly prepares candidates for these roles; CRISC or CISA often follows for dedicated GRC careers

Salary Impact and Market Value

Security+ consistently ranks among the top IT certifications associated with meaningful salary premiums. The following figures represent approximate ranges for US-based professionals in roles where Security+ is a primary or contributing qualification (2024–2025 data; significant variation by location, clearance status, organization size, and total experience):

Role Experience Level Approximate US Salary Range
SOC Analyst Tier 1 0–2 years, Security+ $50,000 – $75,000
SOC Analyst Tier 2 2–5 years, Security+ + CySA+ $70,000 – $100,000
IT Security Specialist 2–5 years, Security+ $65,000 – $95,000
Network Security Engineer 3–6 years, Security+ + CCNA $80,000 – $115,000
System Administrator (Security Focus) 3–6 years, Security+ $70,000 – $100,000
Cloud Security Analyst 3–5 years, Security+ + Cloud cert $80,000 – $120,000
Junior Penetration Tester 2–4 years, Security+ + PenTest+/CEH $70,000 – $100,000
DoD Contractor (Cleared, IAT II) 2–5 years, Security+ + clearance $85,000 – $130,000 (clearance premium)
CONTINUING EDUCATION (CE) & CERTIFICATION RENEWAL

Continuing Education and Certification Renewal

CompTIA Security+ is valid for three years from the date of certification. The CompTIA Continuing Education (CE) program allows certification holders to renew without retaking the exam by accumulating 50 CE units within the 3-year certification period and paying the renewal fee. This requirement ensures that Security+ holders maintain current knowledge in a rapidly evolving field.

Item Detail
Total CE Units Required 50 CE units over the 3-year certification period
Annual Renewal Fee USD $50 per year (billed annually or as a single USD $150 payment for the 3-year cycle)
CE Submission Platform CompTIA CE portal (https://ce.comptia.org); CE units submitted with supporting evidence for each activity
Retake Option Candidates who prefer not to pursue CE renewal may retake the current exam before the certification expires; a passing score on the current exam renews the certification for another 3 years
Higher-Level Certification Renewal Candidates who earn a higher-level CompTIA certification within the 3-year period automatically renew Security+; e.g., earning CySA+ or CASP+ renews Security+ as part of the same renewal action

CE-Eligible Activities

Activity CE Units Notes
Completing higher-level CompTIA exams (CySA+, PenTest+, CASP+, Cloud+) Renews Security+ automatically Earning any higher-level CompTIA cert automatically renews Security+
Completing other vendor certifications (CISSP, CEH, CCNA Security, etc.) Up to 20 CE units per certification Other security certifications earn CE units; maximum varies by cert level
Attending security conferences (RSA, DEF CON, Black Hat, CompTIA events) 1 CE unit per contact hour Must document attendance; retain agendas or certificates of attendance
Completing security training courses (SANS, Cybrary, Coursera, LinkedIn Learning) 1 CE unit per hour Must be security-related content; retain certificates of completion
CompTIA CertMaster CE (Online self-paced course) Varies by course; designed to cover full 50 CE requirement CompTIA’s dedicated CE renewal course; covers all 50 CE units in one purchase
Webinars and virtual training (CompTIA and approved partners) 1 CE unit per hour CompTIA regularly offers free CE-eligible webinars for members
Publishing security articles, blog posts, or research Up to 5 CE units per publication Must be substantial, security-relevant content publicly available
EXAM TIPS, STRATEGY & COMMON PITFALLS

Exam Tips, Strategy, and Common Pitfalls

Knowledge Exam Tips

Item Detail
Read Questions Completely Before Looking at Answers Security+ scenario questions often hinge on a single key word: ‘MOST likely’, ‘BEST mitigates’, ‘FIRST action’, ‘LEAST intrusive’. Identify the key qualifier before reading options. Misidentifying the question’s focus is the most common source of incorrect answers on scenario questions.
Eliminate Obviously Wrong Answers First Most questions have two plausible answers and two clearly incorrect ones. Eliminating the clearly wrong options first often leaves a much more manageable choice between the remaining two. Never leave a question blank — there is no penalty for guessing.
Memorize Port Numbers and Protocol Pairings A consistent category of Security+ questions presents a scenario and asks which port or protocol is being used or should be used. Create and regularly review a complete port number reference card. Particularly important: know plaintext vs. encrypted protocol pairs (HTTP/HTTPS, FTP/SFTP, Telnet/SSH, POP3/POP3S, IMAP/IMAPS, LDAP/LDAPS).
Know Cryptographic Algorithm Appropriate Use Cases Questions frequently describe a requirement (fast, bulk encryption for database; key exchange with forward secrecy; password storage; signing software packages) and ask which algorithm or protocol satisfies it. Memorize the decision table: symmetric for bulk, asymmetric for key exchange and signatures, hashing for integrity, bcrypt/Argon2 for passwords, TLS for transport.
Understand Attack-to-Mitigation Pairings Security+ tests both how attacks work and what defends against them — often in the same question. For each attack type (SQL injection, XSS, phishing, DoS, ARP poisoning), know the primary technical countermeasure. Common pairings: SQL injection → parameterized queries; XSS → output encoding; phishing → email authentication (SPF/DKIM/DMARC) + user training; ARP poisoning → dynamic ARP inspection; DoS → rate limiting + CDN.
Allocate PBQ Time Strategically PBQs appear at the start of the exam. Spend a maximum of 5–7 minutes per PBQ before flagging and moving on. Many multiple-choice questions are faster to answer — completing them builds a time buffer for returning to flagged PBQs. Never let a single difficult PBQ consume more than 10 minutes.
Use Process of Elimination on Unfamiliar PBQs If a PBQ scenario is unfamiliar, apply what you know: eliminate options that are clearly wrong, identify options that partially satisfy the scenario, and select the best available answer. Partial credit is available for PBQs — attempting an incomplete answer is better than leaving a PBQ blank.
Watch for ‘Except’ and Negative Questions Some questions are phrased as ‘Which of the following is NOT…?’ or ‘All of the following EXCEPT…’ These require identifying the incorrect or inappropriate item rather than the correct one. Read these questions especially carefully — it is easy to misread the negative and select an answer that would be correct for a positive question.

Common Preparation Pitfalls

Item Detail
Neglecting Domain 5 (GRC) Candidates with technical backgrounds frequently allocate insufficient study time to Domain 5, treating it as ‘common sense’ content. The GRC domain is specifically designed to test knowledge of frameworks, risk calculation methodology, privacy law specifics (GDPR 72-hour notification, HIPAA 60-day notification), and compliance assessment types — none of which is intuitive without study.
Skipping Lab Practice Candidates who prepare exclusively from books consistently struggle with PBQs. Even basic hands-on experience — reading a Wireshark packet capture, configuring a simple firewall rule, interpreting a vulnerability scan output — dramatically improves PBQ performance. At minimum, complete 10–15 hours of hands-on practice on TryHackMe or a local lab environment.
Memorizing Without Understanding Security+ has a large vocabulary of technical terms, acronyms, and protocol names. Candidates who memorize definitions without understanding the underlying concept fail on application questions where the term appears in an unfamiliar context. Study definitions alongside the ‘why’, why does this protocol exist, what problem does it solve, what are its limitations?
Using Outdated Study Materials Materials written for SY0-601 are significantly different from SY0-701, particularly in cloud security, zero trust, AI/automation, and GRC content. Using outdated materials risks studying content that no longer appears on the exam while missing new content that does. Verify that all materials are explicitly aligned to SY0-701.
Scheduling the Exam Too Early Many candidates schedule their exam date based on target dates rather than actual readiness. The most reliable readiness indicator is consistently scoring 80%+ on full-length practice exams under timed conditions. Do not schedule the exam until practice exam performance demonstrates genuine readiness.
Ignoring Acronyms Security+ uses a very large number of acronyms — many of which are tested in questions where the acronym appears without expansion. Create a comprehensive acronym reference from the exam objectives and study it regularly. CompTIA provides an acronym list as part of the exam objectives document.
CONCLUSION

Conclusion

CompTIA Security+ SY0-701 represents the essential baseline credential for the cybersecurity profession — a comprehensive, vendor-neutral certification that validates the knowledge and practical skills required to begin and advance an information security career.

The certification’s five-domain structure — General Security Concepts, Threats and Vulnerabilities, Security Architecture, Security Operations, and Security Program Management — reflects the full scope of modern security practice. Security+ does not make a security expert; it establishes the conceptual foundation, technical vocabulary, and operational awareness that make subsequent learning, experience, and specialization far more productive. Professionals who earn Security+ and then invest in hands-on experience and advanced certifications (CySA+, PenTest+, CISSP, CEH) consistently advance faster than those who pursue advanced credentials without this foundational grounding.

The SY0-701 update’s emphasis on cloud-native security, zero trust architecture, AI-driven threats, and an expanded governance and compliance framework reflects the contemporary security landscape with unusual accuracy. Candidates who prepare thoroughly for SY0-701 are not merely preparing for an exam — they are building the security knowledge model that serves their professional practice in the current threat environment.

For organizations hiring entry-to-mid security talent, Security+ provides a reliable baseline signal. It is not a guarantee of operational competency — the practical exam component cannot fully substitute for real-world experience — but it does confirm that a candidate has invested in systematic security education and has demonstrated knowledge across the breadth of security domains that effective security practice requires. Combined with a rigorous hiring process that assesses practical skills through technical interviews and scenario exercises, Security+ certification is a valuable and reliable hiring filter.

Final Note
Security+ is not the destination, it is the departure point for a security career. The most valuable investment after earning Security+ is the practical experience that the certification’s content comes to life through. Seek roles that expose you to real security operations: SOC analysis, vulnerability management, incident response, and security tool administration. Every hour spent operating real security tools in real environments compounds the value of the Security+ knowledge base into genuine security competency.

Security+ Quick Reference Glossary

Item Detail
AAA Authentication, Authorization, and Accounting — the three components of access control; implemented by RADIUS and TACACS+.
ALE Annualized Loss Expectancy — expected annual financial loss from a risk: ALE = SLE × ARO.
ARO Annualized Rate of Occurrence — expected frequency of a threat event per year.
BIA Business Impact Analysis — assessment of the operational and financial impact of disrupting critical business functions.
BYOD Bring Your Own Device — policy governing personal device use for business purposes.
CAT Computerized Adaptive Testing — not used in Security+ (fixed-form exam); contrast with CISSP which uses CAT.
CIA Triad Confidentiality, Integrity, Availability — the foundational model of information security objectives.
CSPM Cloud Security Posture Management — tools that assess and enforce security best practices in cloud environments.
CVSS Common Vulnerability Scoring System — standardized 0–10 severity scoring for vulnerabilities.
DoD 8570 US Department of Defense directive mandating cybersecurity certification for IA roles; Security+ satisfies IAT Level II.
EDR Endpoint Detection and Response — continuous endpoint monitoring and threat detection/response capability.
FPR / TPR False Positive Rate / True Positive Rate — key metrics for evaluating IDS/IPS detection accuracy.
IoC Indicator of Compromise — technical artifacts (IP, hash, domain, email) indicating a system has been compromised.
MFA Multi-Factor Authentication — authentication, requiring two or more independent factors (Type 1/2/3).
MTTR / MTBF Mean Time to Recovery / Mean Time Between Failures — availability and reliability metrics.
NAC Network Access Control — enforces device security compliance before granting network access; uses 802.1X.
PBQ Performance-Based Question — hands-on scenario question in Security+ exam; tests applied skills.
RBAC Role-Based Access Control — permissions assigned to roles; users assigned to roles; standard enterprise model.
RPO / RTO Recovery Point Objective (maximum data loss) / Recovery Time Objective (maximum downtime) — DR design metrics.
SIEM Security Information and Event Management — centralized log aggregation, correlation, and alerting platform.
SOAR Security Orchestration, Automation and Response — automated security workflow execution.
SLE Single Loss Expectancy — expected financial loss from a single threat occurrence: SLE = AV × EF.
ZTNA Zero Trust Network Access — replaces VPN with application-specific access based on continuous verification.