Study guide · Core notes

Security+ Core Notes for SY0-701

Reference notes for controls, attacks, architecture, day-to-day operations, and the risk decisions Security+ keeps asking you to separate.

Exam: SY0-701Objectives version 6.0Reviewed October 2026

How to read these notes: Items tagged Extra sit outside the SY0-701 objective bullets, such as OpenID Connect. Learn the unmarked items first. New to the exam? Start with the overview for the format and the five domains. These notes follow objectives version 6.0.

General security concepts

Domain 1 is 12 percent of the exam. Name the control before you name the product.

Control types on SY0-701. Categories are technical, managerial, operational, and physical.
TypeWhat it doesExample
PreventiveStops the actionA firewall rule that drops the packet
DeterrentDiscourages the attemptA sign that says the lobby is recorded
DetectiveFinds the actionThe camera recording itself, or a SIEM alert
CorrectiveRepairs the damageRestoring clean files after malware removal
CompensatingSubstitutes when the preferred control cannot be usedVPN and a device certificate because an old app cannot do MFA
DirectiveTells people what they must doA password standard

CIA and AAA

Confidentiality limits who can read data. Integrity detects unauthorized change. Availability means the data is there when it is needed. Non-repudiation proves who sent or did something. AAA is authentication (who you are), authorization (what you may do), and accounting (what you did).

Zero trust

The control plane decides: adaptive identity, threat scope reduction, and policy-driven access. The Policy Engine decides, and the Policy Administrator carries the decision out. The data plane enforces it. The Policy Enforcement Point allows or blocks the request. Being on the office LAN is not an implicit trust zone.

Change management

Identify owners and stakeholders, analyze impact, record test results, and get approval before the maintenance window. The backout plan is how you return to the last working state. Afterward, update diagrams, policies, and version control. Allow lists and deny lists may need a matching change, and a service restart can take dependents down with it.

Cryptography

Symmetric encryption is fast for bulk data and uses a shared key. Asymmetric encryption uses a public and private key and is how you exchange a key or make a signature. A hash is one-way. A salt makes identical passwords hash differently. Key stretching slows password hashing. A digital signature is a hash protected with the sender's private key. A TPM is a motherboard chip. An HSM is a dedicated key device. Key escrow keeps a recovery copy. OCSP checks one certificate now. A CRL is a list that can be stale. Tokenization, masking, and steganography hide or replace data. They are not encryption.

Threats, vulnerabilities, and mitigations

Domain 2 is 22 percent. Separate the actor, the path, and the fix.

Actors and the motivation that usually fits. Attributes also include internal or external, funding, and skill.
ActorUsual clue
Nation-stateFunding and skill, often espionage or strategic disruption
Organized crimeFinancial gain
HacktivistA political or philosophical cause
InsiderSomeone who already has access and misuses it
Shadow ITA system the organization did not approve
Unskilled attackerLimited skill, often ready-made tools

Paths in

Smishing is SMS. Vishing is voice. Phishing is usually email. Business email compromise impersonates a trusted person to move money. Pretexting is a made-up story. Typosquatting is a lookalike domain. A watering hole is a site the target already visits. Removable media, default passwords, open ports, and a compromised supplier or MSP are vectors too.

Malware and attacks

A worm spreads on its own. A virus needs a host. A Trojan looks legitimate. A logic bomb waits for a condition. A rootkit hides. Ransomware extorts. Spyware collects. A keylogger records keys. Password spraying tries a few passwords on many accounts. Brute force tries many passwords on one account. SQL injection changes a query. Cross-site scripting runs in the browser. A buffer overflow writes past a memory boundary. A downgrade forces a weaker protocol. A birthday attack seeks a hash collision.

Indicators and fixes

Impossible travel, concurrent sessions, missing logs, and a spike in resource use are clues. Segment networks, patch, encrypt, monitor, enforce least privilege, and decommission what you no longer need. Hardening changes the default password, closes unused ports, and adds a host firewall and endpoint protection. An allow list blocks unapproved programs.

Security architecture

Domain 3 is 18 percent. Say where the control sits, and what happens when it fails.

Recovery and failure choices. RTO is downtime. RPO is data loss.
TermMeaning
Hot siteReady to run, with current data
Warm sitePartial equipment or data, slower than hot
Cold siteSpace and power, little ready equipment
Fail-openTraffic or a door continues when the control fails. Use it for life safety.
Fail-closedAccess stops when the control fails. Use it for sensitive data.
UPSShort power so a generator can start

Placement

An IPS inline can block. A tap only copies traffic. A jump server is the admin door into a private network. A screened subnet faces the internet. The database stays behind it. 802.1X with EAP authenticates a switch port. A WAF understands HTTP. A VPN is the remote encrypted tunnel. SD-WAN steers across circuits. SASE delivers security from the cloud edge. An air gap has no network path.

Data and resilience

Data is at rest, in transit, or in use. Sovereignty means the law of the place where the data sits. Load balancing shares work. Clustering keeps a service alive when a node dies. Geographic dispersion and a second cloud survive a regional outage. A responsibility matrix says who patches the host and who patches the guest. Infrastructure as code builds that environment from files. Industrial and real-time systems often cannot take a casual patch.

Security operations

Domain 4 is 28 percent, the largest share. This is the daily work.

Identity and email controls that are easy to swap on a hurried read.
ControlJob
SPFLists which servers may send mail for the domain
DKIMSigns the message so a change is visible
DMARCSays what to do when SPF or DKIM fails, and asks for reports
SAMLCarries a sign-in assertion for federation
OAuthIssues a scoped authorization token. It is not a password.
LDAPLooks up a directory
OpenID Connect ExtraA common sign-in layer on OAuth. The SY0-701 bullets name OAuth and SAML.

Access and mobile devices

BYOD is user-owned. COPE is company-owned and personally enabled. CYOD is a choice from an approved list. COBO, on the acronym list, is corporate-owned and business only. MDM can wipe company data. WPA3 is the wireless protection the objectives name. NAC checks a device before it joins. MAC uses system labels. DAC lets the owner decide. RBAC uses roles. ABAC uses attributes such as department, sensitivity, and time. Just-in-time rights expire. A vault plus ephemeral credentials replaces a shared admin password. Factors are something you know, have, are, or somewhere you are.

Vulnerabilities and monitoring

CVE names a flaw. CVSS scores it. A false positive alerts on nothing. A false negative misses a real flaw, which is worse. Rescan after you patch. A SIEM correlates logs. EDR watches the endpoint. XDR reaches across more telemetry. Tune noisy alerts. Quarantine a host that is encrypting shares. File integrity monitoring reports a binary that changed outside a patch window. Static analysis reads code. Dynamic analysis runs it. A sandbox isolates unknown software.

Incidents and evidence

The order is preparation, detection, analysis, containment, eradication, recovery, and lessons learned. Isolate a spreading host before a long write-up. A legal hold stops deletion. A chain of custody records every person who handles the image. Useful sources include firewall, endpoint, and application logs, plus a packet capture. Automation can provision accounts from HR, and a bad HR record will be applied just as fast.

Security program management and oversight

Domain 5 is 20 percent. Policies, dollars, vendors, and proof.

Risk math. Compare a control's yearly cost with ALE, not with a single dramatic loss, unless a law requires the control anyway.
TermMeaning
Exposure factorPercent of the asset lost in one event
SLEAsset value times exposure factor. One event.
AROHow many times a year you expect the event
ALESLE times ARO. The yearly figure.
MTBFAverage time between failures
MTTRAverage time to repair or recover

Governance

A policy mandates. A standard gives the required specification, such as password length. A procedure or playbook is the steps. A guideline only advises. The owner is accountable. The controller decides why personal data is processed. The processor acts on the controller's instructions. The custodian takes day-to-day care. The data subject is the person the record describes.

Treatment, vendors, and tests

Avoid stops the activity. Mitigate reduces it. Transfer shifts the impact, often with insurance. Accept keeps it, sometimes as a time-bounded exception. Expansionary appetite takes more risk. Conservative appetite takes less. An SLA measures service. An NDA protects secrets. An MOU states intent. A statement of work defines one job. A right-to-audit clause lets you test the vendor. A known environment gives the tester internal knowledge. An unknown environment does not. Passive reconnaissance does not touch the target. Phishing exercises need a first report and a later measurement.

Frequently asked questions

Are these notes the official CompTIA objectives?

No. They are an original summary of the public SY0-701 objectives, version 6.0. Confirm the current PDF with CompTIA before you book.

What does the Extra tag mean?

Extra marks a useful idea the SY0-701 objective bullets do not name, such as OpenID Connect. Learn the unmarked items first.

Which incident steps does SY0-701 list?

Preparation, detection, analysis, containment, eradication, recovery, and lessons learned. Contain before you restore.

Continue the Security+ study path

Use the flashcards to check whether you can recall these distinctions.

Security+ hub →
Available

Overview

Exam format, the 750 passing score, five domain weights, and a study plan.

Available · You are here

Core Notes

Reference notes for controls, threats, architecture, operations, and program management.

Available

Practice Exams

200 original questions with custom exams, explanations, and an unofficial score on the 100-900 scale.

Related Tools

Useful companions while you study.

All study topics →