certslothcertsloth
← SY0-701 overview

Security+ / STUDY TOOLS

SY0-701 quick review

This guide targets V7/SY0-701. CompTIA lists V8 for around 17 November 2026 and English V7 retirement on 11 June 2027; match notes and practice to the version you book.

Reviewed 10 October 2026 against the linked published scope. Domains: security concepts 12%, threats 22%, architecture 18%, operations 28%, program oversight 20%. Includes performance-based questions.

Memory hook: Identify the asset, threat and business impact; choose a control and prove it works.

Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.

Security concepts and attacks

  • CIA: confidentiality prevents inappropriate disclosure; integrity protects against unauthorized alteration; availability preserves usable access. Authentication proves identity, authorization grants actions, accounting records activity. Nonrepudiation supports attribution.
  • Administrative/managerial, operational, technical and physical describe control forms. Preventive, detective, corrective, deterrent, compensating and directive describe their purpose. One safeguard can serve several purposes.
  • Zero trust requires explicit verification, least privilege and continuing evaluation; it does not mean no one can access anything. A control plane makes policy decisions; enforcement points apply them to traffic or requests.
  • Social engineering targets people; phishing uses deceptive messages, smishing texts, vishing calls. Password spraying tries a few passwords across many accounts; credential stuffing reuses stolen pairs; brute force tries many guesses.
  • SQL injection changes a database query: use parameterized queries. XSS runs attacker code in a victim's browser: use contextual output encoding and suitable sanitization. CSRF abuses an authenticated browser's trust: use anti-CSRF tokens and appropriate origin/request checks. SSRF makes a server fetch unintended resources: validate allowed destinations and restrict outbound/internal access.
  • Distinguish exploitability from consequence: a vulnerability is a weakness, a threat may exploit it, and risk combines likelihood with impact. Patch, mitigate or accept through an authorized owner; scan again to verify.

Architecture, identity and cryptography

  • Segment trust zones, reduce exposed services and separate management from user access. Defense in depth combines independent controls. IaaS/PaaS/SaaS change operational duties; data, identity and permitted use remain customer concerns.
  • Symmetric encryption uses a shared key; asymmetric uses a key pair. Hashing detects changes; HMAC adds shared-secret authentication; a digital signature uses the signer's private key and is verified with its public key. A signature does not hide the message.
  • PKI certificates bind identities to public keys. Check trust chain, name, validity and revocation. Encryption at rest needs protected keys; TLS protects the connection, not compromised endpoints. Tokenization substitutes a reference; masking obscures display.
  • MFA requires different factor categories. Two passwords are still one category. Federation delegates authentication; SSO reduces repeated sign-ins. RBAC follows roles; ABAC evaluates attributes; PAM constrains and records privileged activity.
  • RPO = tolerable lost time of data; RTO = recovery time target. Replication improves availability but can copy corruption. Offline/immutable recovery copies and tested restores address different risks.

Operations and oversight

  • Secure baselines, asset inventories, change control and patching prevent unmanaged drift. EDR investigates endpoint behavior; SIEM correlates events; SOAR orchestrates response. Tune alerts against evidence, not alert count alone.
  • Prepare response; detect/analyze; contain; eradicate; restore; learn. Preserve evidence, hashes, timestamps and custody records under authority. Safety and active harm can demand urgent action before a full forensic collection.
  • BIA identifies critical processes and dependencies. Risk owners choose avoid, mitigate, transfer or accept. Policies state intent; standards mandate details; procedures give steps; guidelines recommend.
  • SLE = asset value × exposure factor; ALE = SLE × annual occurrence rate. Quantitative estimates depend on assumptions. Residual risk remains after controls; inherent risk precedes them.
  • Assess suppliers before and during use; contracts, audit reports and insurance do not remove accountability. Minimize collected data, classify it, set retention and dispose securely. Legal obligations depend on jurisdiction and data type.

Exam traps

  • A compliance certificate is evidence with a scope and period, not proof of zero risk.
  • A backup job succeeding is weaker evidence than a verified restore.
  • Choose the first, best or most cost-effective action the scenario actually asks for; investigate evidence before buying a product.

Final active recall

1. A hash matches. Does that prove who created the file?

No. An ordinary hash supports integrity comparison, not identity. A trusted signature can support origin authentication.

2. One password plus a PIN is MFA?

No. Both are knowledge factors.

3. A restore loses 20 minutes of data and takes two hours. Which objectives are relevant?

RPO evaluates the data-loss window; RTO evaluates recovery duration.

4. A critical vulnerability is found on an isolated low-value system. Patch it before all other findings?

Prioritize using exposure, exploitability, asset criticality and business impact; severity alone is insufficient.

5. Who accepts residual business risk?

The authorized business risk owner, informed by the security assessment and treatment options.

Sources and further practice

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Security Principles and Controls

Memory hook: Protect the right property with the right kind of control.

Must remember

Confidentiality prevents unauthorized disclosure; integrity protects against unauthorized alteration; availability keeps a service usable. Authenticity establishes that something is genuine. Non-repudiation supplies evidence of origin or action, subject to trustworthy keys, identities and records.

Authentication establishes an identity, authorization decides permitted actions and accounting records activity. Identify which stage failed: a valid login with excessive database privileges is an authorization problem.

Classification Examples
Technical Firewall, encryption, access-control software.
Managerial Policy, risk assessment, oversight.
Operational Human-run procedures, training, guard processes.
Physical Locks, barriers, cameras, environmental protection.
Preventive / detective / corrective Block / discover / repair.
Deterrent / directive / compensating Discourage / instruct / supply an alternative protection.

One control can have several classifications. A camera detects; a visible camera may also deter. A compensating control addresses the original control's intent when the normal implementation is not feasible; it does not simply mean a cheaper control.

Zero trust evaluates access using identity, device state, resource sensitivity and context rather than trusting network location. A policy engine decides, a policy administrator arranges the session and an enforcement point permits or blocks it. Least privilege and segmentation reduce blast radius; continuous evaluation handles changing conditions.

Honeypots, honeynets, honeyfiles and honeytokens are deception tools. Access to a decoy can be a high-value detection signal, but a decoy needs containment and monitoring.

Choose under exam pressure

Requirement Choice and reason
Prevent disclosure Access control and encryption appropriate to the data path.
Find unauthorized changes Integrity checks, signatures and audit evidence.
Legacy system cannot implement a mandated control Evaluate an approved compensating control against the same risk.

Traps

  • Encryption alone does not make a service available.
  • Zero trust is an architecture and decision process, not one appliance.

Practise this topic

02 · Threats, Attacks and Indicators

Memory hook: Actor explains intent; evidence identifies the technique.

Must remember

Actors differ in funding, access and motivation: nation-state espionage, organized financial crime, hacktivism, malicious or careless insiders and opportunistic attackers. Shadow IT is unapproved technology that creates unmanaged exposure; it is not necessarily malicious.

Phishing targets messages; spear phishing targets a person/group; whaling targets senior staff. Smishing uses text messages and vishing voice calls. Pretexting invents a credible story, business email compromise abuses trusted payment workflows, and tailgating exploits physical access. Verify unusual requests through an independent channel, especially when voice or video could be synthesized.

Indicator Likely technique / useful response
Many passwords against one account Brute force; rate limits and monitoring.
One common password across many users Password spraying; MFA and password hygiene.
Known breached username/password pairs Credential stuffing; revoke/resecure reused credentials.
Browser executes untrusted page content XSS; contextual output encoding and safe frameworks.
Query structure changes through input Injection; parameterized queries and validation.
Server fetches attacker-chosen internal URL SSRF; destination controls and restricted credentials.
Local IP maps to an unexpected MAC Possible ARP spoofing; inspect trusted bindings and switching controls.

Ransomware denies access or extorts using stolen data; a worm self-propagates; a Trojan disguises malicious behavior; rootkits hide privileged persistence; spyware captures information. Fileless activity can use legitimate interpreters and memory rather than a conspicuous executable.

Race conditions exploit timing (including time-of-check/time-of-use); buffer overflows corrupt memory; insecure direct object references expose missing object-level authorization. Supply-chain compromise can enter through dependencies, build systems or updates. Downgrade attacks seek weaker protocols; replay reuses captured valid messages without breaking the cipher.

Treat a single indicator as a hypothesis. Correlate identity, endpoint, network and application evidence before concluding cause.

Choose under exam pressure

Requirement Choice and reason
Suspicious urgent transfer request Independently verify with established contacts.
Database query injection Use parameterized queries; a WAF is supplementary.
Large distributed traffic flood Use upstream capacity and DDoS protections as well as local controls.

Traps

  • A strong password does not prevent phishing of a live session.
  • A vulnerability is a weakness; an exploit is a method of using it.

Practise this topic

03 · Cryptography, Certificates and Keys

Memory hook: Encrypt for secrecy; sign for origin; hash for comparison.

Must remember

Symmetric encryption uses a shared secret and is efficient for bulk data. Asymmetric cryptography uses a key pair for operations such as signatures or key establishment. TLS combines authenticated negotiation with efficient symmetric protection; it does not encrypt with a certificate as though the certificate were a secret key.

Hashing produces a digest without a decryption operation. Password storage needs a suitable salted password-hashing/key-derivation function with work cost; a fast unsalted hash is unsuitable. A salt is unique nonsecret input preventing identical passwords from sharing the same stored result. An HMAC uses a secret key to authenticate a message; a plain hash alone does not prove origin.

Digital signatures use a private signing key and public verification key. Encryption for a recipient and signing as a sender are different operations. PKI binds public keys to identities through certificates and trusted issuers. Validate chain, hostname/SAN, dates, intended use and revocation information such as CRLs/OCSP. A CSR requests issuance; a CA signs the certificate.

Key management includes generation, distribution, storage, access, rotation, revocation, backup and destruction. HSMs protect key operations; TPMs support device-bound measurements and key protection. Losing an encryption key without recovery can make intact backups unusable.

Tokenization replaces sensitive values with references, often using a protected mapping service. Masking obscures displayed data. Steganography hides the existence of a message; encryption hides meaning. Blockchain links records using cryptography and consensus but does not guarantee that input data was true.

Protect data in transit, at rest and in use with controls suited to each state. Cryptographic erase depends on effective key destruction and the absence of surviving usable key copies.

Choose under exam pressure

Requirement Choice and reason
Protect bulk stored data Symmetric encryption with controlled keys.
Verify a publisher A valid digital signature and trusted identity/key binding.
Reduce exposure in test datasets Approved masking, tokenization or synthetic data.

Traps

  • Base64 is encoding, not encryption.
  • A valid certificate does not prove the business behind a site is honest.

Practise this topic

04 · Secure Architecture and Network Defences

Memory hook: Reduce exposure; separate trust; inspect the right layer.

Must remember

Security responsibility changes across IaaS, PaaS and SaaS. Customers retain responsibilities for their data, identities and configuration even when infrastructure is managed. Virtual machines share a hypervisor; containers normally share the host kernel. Isolation, patching and image provenance remain important.

Segment systems by sensitivity and function: user networks, guests, servers, management, IoT and operational technology. A screened subnet/DMZ hosts externally reachable services while restricting movement inward. Air gaps and logical isolation differ; removable media and maintenance paths can still introduce risk. Industrial systems prioritize safety and availability, so patching may require controlled maintenance and compensating safeguards.

Control Deciding role
Stateful firewall / ACL Permit or deny network flows at the relevant enforcement point.
WAF Inspect web application requests; supplement secure application code.
IDS / IPS Detect / potentially block suspicious traffic.
Proxy / secure web gateway Mediate outbound web access and policy.
NAC Assess/authorize device network admission.
VPN Protect a tunnel; endpoint compromise remains possible.
DLP Discover and restrict sensitive-data movement.
EDR / XDR Endpoint detection/response / correlation across broader sources.

Choose fail-open versus fail-closed behavior according to safety and availability requirements. A load balancer improves distribution/availability; it is not a substitute for authentication. Secure management interfaces separately from application traffic, prefer encrypted protocols and restrict administrative access.

Wireless protection includes WPA3 or appropriate enterprise authentication, secure onboarding, guest isolation and removal of legacy protocols. An evil twin imitates a legitimate network; validate the authentication server certificate in enterprise Wi-Fi rather than accepting any certificate prompt.

IaC makes configuration repeatable but also makes a bad template repeatable. Review plans, scan configurations, protect state and control deployment credentials.

Choose under exam pressure

Requirement Choice and reason
Block common web-request attacks WAF plus application-layer fixes.
Untrusted guest devices Separate network and restricted routing/access.
Legacy industrial controller cannot be patched now Approved segmentation, monitoring and maintenance planning.

Traps

  • A VPN does not make the endpoint trustworthy.
  • Containers are not equivalent to separate hardware trust boundaries.

Practise this topic

05 · Hardening and Vulnerability Management

Memory hook: Inventory, prioritize, fix, verify.

Must remember

You cannot secure unknown assets. Maintain ownership, location, purpose, classification, versions and support status. Apply secure baselines: remove unused software/services, disable default accounts, restrict administration, patch, configure logging and enforce appropriate endpoint protection.

Mobile management can enforce encryption, screen lock, application policy and remote wipe. BYOD raises ownership/privacy boundaries; choose whole-device management versus application/container controls deliberately. Rooted/jailbroken devices weaken assumptions. Wireless, browser, email and document settings can expose different attack surfaces.

Vulnerability scanning identifies potential weaknesses; penetration testing attempts to demonstrate exploitability within authorization and rules of engagement. Credentialed scans can inspect more internal configuration. SAST examines code without running the application; DAST tests running behavior; software composition analysis identifies dependencies and known component issues.

Prioritize using exploitability, exposure, asset value, business impact and active exploitation, not severity alone. CVE identifies a known vulnerability; CVSS scores technical severity; threat intelligence adds context. A low-scoring flaw on a critical exposed identity system can deserve urgent action.

Remediation may mean patching, reconfiguration, removing a component or applying an approved compensating control. Exceptions need owners, expiration and risk acceptance. Test compatibility, maintain a rollback plan, deploy in controlled stages and rescan to verify the issue is resolved. Suppressing an alert is not remediation.

False positive: a reported issue that is not actually present. False negative: an existing issue missed by the test. Confirm with evidence before tuning detection. Sandboxing isolates suspicious code for analysis; a safe analysis environment should not have production access or usable production credentials.

Choose under exam pressure

Requirement Choice and reason
Find missing updates at scale Authenticated scanning with appropriate permissions.
Prove a finding’s impact Authorized validation or penetration testing within scope.
Cannot immediately patch Time-bound approved mitigation and tracked risk.

Traps

  • CVSS alone is not business risk.
  • An uncredentialed scan may miss issues visible from inside the system.

Practise this topic

06 · Identity, Authentication and Privileged Access

Memory hook: Who are you, what may you do, and for how long?

Must remember

Factors are something you know, have or are. Two passwords are not MFA. Hardware-backed phishing-resistant authentication reduces risks that a phishable one-time code does not fully address. Biometrics need fallback and privacy controls; false acceptance and false rejection trade off against each other.

SSO reduces repeated sign-ins; federation lets one identity provider assert identity to another service. SAML carries assertions commonly used in enterprise federation. OAuth delegates authorization; OpenID Connect adds an identity layer. Kerberos uses tickets and depends on appropriate time synchronization. LDAP is a directory-access protocol, not encryption by itself.

RBAC grants access through roles; ABAC evaluates attributes and context; discretionary access lets owners delegate; mandatory access enforces centrally controlled labels. Least privilege restricts permissions; separation of duties prevents one person completing a sensitive workflow alone. Need-to-know narrows access even among sufficiently cleared users.

Provisioning must cover joiners, movers and leavers. Reconcile access after role changes and promptly revoke accounts, sessions, keys and tokens when required. Periodic access reviews find accumulated privilege and dormant accounts. Service accounts need ownership, scoped permissions and credential lifecycle controls too.

PAM manages privileged access with vaulting, approval, session recording and just-in-time elevation. Just-enough access narrows the permitted actions. A break-glass account needs controlled storage, monitoring and periodic tests; it should not become a daily shared login.

RADIUS commonly centralizes network access authentication; TACACS+ is often used for network-device administration with separable AAA functions. Certificates and device posture can supplement user identity. An authenticated user can still be compromised or unauthorized for the requested object.

Choose under exam pressure

Requirement Choice and reason
Temporary production administration Approved just-in-time privilege with logging.
Access depends on classification and device state Attribute/context-based policy.
A user changes department Reconcile old and new permissions, not only add the new role.

Traps

  • SSO without careful controls can concentrate compromise risk.
  • Authentication success does not establish authorization for every resource.

Practise this topic

07 · Incident Response and Evidence

Memory hook: Contain harm while preserving what explains it.

Must remember

Preparation establishes contacts, authority, playbooks, logging, tools and exercises. Detection and analysis distinguish an event from an incident and establish scope. Containment limits damage; eradication removes the cause/persistence; recovery restores trustworthy service; lessons learned improve the system. These activities can overlap and repeat.

Use the scenario's authority and safety requirements. Isolate a compromised endpoint when appropriate, but do not automatically power it off: volatile evidence may matter. Human safety and urgent containment can outweigh evidence collection when the situation requires it. Engage legal, privacy and communications owners for reporting obligations and external statements.

Chain of custody records who collected, handled, transferred and stored evidence. Integrity hashes help demonstrate that a copy has not changed; they do not independently establish who collected it or whether collection was lawful. Preserve originals and work on validated copies where practical.

Volatile sources include running processes, memory and active network connections; disks and archived logs are generally less volatile. Collection order depends on the system and investigative purpose. Record synchronized timestamps, time zones, commands and methods. A legal hold suspends normal deletion for relevant material.

Threat hunting starts with a hypothesis and seeks evidence beyond existing alerts. Root-cause analysis asks why the incident was possible, not only which host was infected. Tabletop exercises test decisions and communication; simulations and technical exercises test execution.

Backups used for recovery must be known good, accessible and protected from the same compromise. Rebuilding without revoking stolen credentials or closing the original entry point invites recurrence.

Choose under exam pressure

Requirement Choice and reason
Suspected compromise with ongoing exfiltration Authorized containment plus scoped evidence preservation.
Evidence may be needed in proceedings Document custody and collection integrity.
Validate response coordination Tabletop exercise with owners and decision points.

Traps

  • Reimaging first can destroy the explanation of a broader breach.
  • An incident is not closed merely because alerts stop.

Practise this topic

08 · Monitoring, Automation and Investigation

Memory hook: Correlate signals; constrain automated actions.

Must remember

Collect evidence from identity providers, endpoints, applications, DNS, proxies, firewalls, databases and cloud control planes. Normalize timestamps and retain enough context to connect a user, device, request and resource. Central collection improves correlation but needs access control, integrity protection and retention limits.

SIEM aggregates and correlates security events. SOAR orchestrates response workflows and integrations. EDR supplies endpoint evidence and response; XDR combines multiple detection domains. A dashboard without useful detections or responders is not an effective control.

Data source What it answers
Authentication log Who attempted access, from where, with which outcome?
DNS log Which names did a host request?
Flow record Which endpoints communicated, when and how much?
Packet capture What protocol details/content are visible at this point?
Application audit Which business action or object was affected?
Endpoint telemetry Which process, parent, file or persistence mechanism was involved?

Encrypted traffic can still reveal timing, volume and endpoints while hiding application content. Packet capture location and collection permissions matter. Baselines distinguish ordinary patterns from meaningful deviations; tune rules with feedback instead of disabling noisy detection broadly.

Automation can enrich indicators, create tickets, quarantine endpoints, revoke sessions or enforce configurations. Give automation minimal permissions, bounded targets, tested rollback and human approval for actions with substantial impact. Protect integration credentials and validate untrusted input before passing it to scripts.

Track mean time to detect/respond, coverage, false positives and repeat incidents with clear definitions. A falling alert count can mean better security, broken collection or weaker rules; investigate the reason.

Choose under exam pressure

Requirement Choice and reason
Connect login and endpoint evidence Correlate sources in a SIEM with consistent identifiers/time.
Repeat a well-defined response safely A tested SOAR playbook with scoped credentials.
Need packet-level protocol behavior Capture at an authorized point; consider encryption and privacy.

Traps

  • Logs can contain credentials or personal data.
  • Automating a flawed decision makes the mistake faster and broader.

Practise this topic

09 · Governance, Risk and Assurance

Memory hook: Business owns risk; controls reduce it; evidence checks it.

Must remember

Policy states management intent; standards set mandatory requirements; procedures describe steps; guidelines advise. Assign data/system owners and accountable decision makers. Security should enable business objectives within legal and risk constraints.

Threats can exploit vulnerabilities and cause impact. Inherent risk exists before controls; residual risk remains afterward. Appetite is the broad willingness to take risk; tolerance defines acceptable variation/bounds. Treat risk by avoiding, mitigating, transferring/sharing or formally accepting it. Insurance transfers some financial consequences, not accountability or every impact.

Quantitative example: an asset worth $100,000 with 20% expected loss per event has SLE = $20,000. At 0.5 events/year, ALE = $10,000/year. Estimates are uncertain; qualitative matrices express relative likelihood/impact without pretending to precise currency.

Change control records purpose, impact, dependencies, approvals, testing, maintenance window, rollback and validation. Emergency changes still need defined authority and retrospective documentation. Version control supports traceability; it does not approve a change by itself.

Supplier assessment covers security evidence, subcontractors, data location, access, continuity, breach notification and exit/deletion terms. SLAs define service commitments; NDAs protect shared confidential information; rules of engagement constrain testing. Review suppliers throughout the relationship.

Audits compare evidence against criteria; assessments evaluate controls; attestation is a formal assertion/report; penetration tests validate selected attack paths. Compliance is a baseline tied to scope, not proof of complete security. Awareness programs need role-specific training, usable reporting channels and measured outcomes, not only annual attendance.

Choose under exam pressure

Requirement Choice and reason
Control costs more than justified risk reduction Escalate a documented business risk decision.
Supplier stores sensitive customer data Assess contractual, technical and lifecycle controls.
Audit finds missing evidence Correct the evidence/control process, not merely the report wording.

Traps

  • A technical administrator does not unilaterally accept business risk.
  • A supplier certification applies to its stated scope and period.

Practise this topic

10 · Data Lifecycle, Privacy and Recovery

Memory hook: Know the owner, keep only what you need, test restoration.

Must remember

Classify data by business impact and obligations, then label and protect it consistently. Owners decide use/classification; custodians implement handling. Controllers determine processing purposes while processors act under applicable instructions; exact legal duties depend on jurisdiction and contract.

The lifecycle runs through collection/creation, use, sharing, storage, retention and disposal. Minimize collection, restrict purpose and access, discover misplaced sensitive data and track copies. Data residency describes where data is stored; sovereignty/jurisdiction concerns which laws may apply. Encryption does not automatically resolve every cross-border obligation.

Choose disposal by medium and sensitivity: clear, purge or physically destroy using an approved sanitization method. A quick format or ordinary file deletion may leave recoverable data. Track disposal and verify sanitization; retain evidence when required. Legal holds can override routine deletion.

RPO measures tolerable lost data in time; RTO measures target restoration time. A business impact analysis prioritizes services and dependencies. High availability handles component failures; backups recover prior data; disaster recovery restores technology; business continuity sustains critical business operations.

Full backups simplify restoration but copy more data. Incremental backups copy changes since the preceding backup and may require a chain; differential backups copy changes since the full backup. Offline/isolated or suitably immutable copies resist attacks on live systems. Replication can also replicate corruption and deletion.

Hot, warm and cold recovery sites trade readiness for cost. Test restoration, application consistency, key availability, access, DNS and dependent services. Redundant power, UPS/generators, geographic diversity and people/process continuity address different failure modes.

Choose under exam pressure

Requirement Choice and reason
Recover yesterday’s deleted records A tested point-in-time/backup capability, not only replication.
Minimal data loss after disaster A replication/backup frequency consistent with the RPO.
Retire sensitive storage Approved sanitization with verification and records.

Traps

  • Replication is not a substitute for independent recovery history.
  • A backup without usable decryption keys may be worthless.

Practise this topic

Search across every published topic.