Reference notes for controls, attacks, architecture, day-to-day operations, and the risk decisions Security+ keeps asking you to separate.
Exam: SY0-701Objectives version 6.0Reviewed October 2026
How to read these notes: Items tagged Extra sit outside the SY0-701 objective bullets, such as OpenID Connect. Learn the unmarked items first. New to the exam? Start with the overview for the format and the five domains. These notes follow objectives version 6.0.
General security concepts
Domain 1 is 12 percent of the exam. Name the control before you name the product.
Control types on SY0-701. Categories are technical, managerial, operational, and physical.
Type
What it does
Example
Preventive
Stops the action
A firewall rule that drops the packet
Deterrent
Discourages the attempt
A sign that says the lobby is recorded
Detective
Finds the action
The camera recording itself, or a SIEM alert
Corrective
Repairs the damage
Restoring clean files after malware removal
Compensating
Substitutes when the preferred control cannot be used
VPN and a device certificate because an old app cannot do MFA
Directive
Tells people what they must do
A password standard
CIA and AAA
Confidentiality limits who can read data. Integrity detects unauthorized change. Availability means the data is there when it is needed. Non-repudiation proves who sent or did something. AAA is authentication (who you are), authorization (what you may do), and accounting (what you did).
Zero trust
The control plane decides: adaptive identity, threat scope reduction, and policy-driven access. The Policy Engine decides, and the Policy Administrator carries the decision out. The data plane enforces it. The Policy Enforcement Point allows or blocks the request. Being on the office LAN is not an implicit trust zone.
Change management
Identify owners and stakeholders, analyze impact, record test results, and get approval before the maintenance window. The backout plan is how you return to the last working state. Afterward, update diagrams, policies, and version control. Allow lists and deny lists may need a matching change, and a service restart can take dependents down with it.
Cryptography
Symmetric encryption is fast for bulk data and uses a shared key. Asymmetric encryption uses a public and private key and is how you exchange a key or make a signature. A hash is one-way. A salt makes identical passwords hash differently. Key stretching slows password hashing. A digital signature is a hash protected with the sender's private key. A TPM is a motherboard chip. An HSM is a dedicated key device. Key escrow keeps a recovery copy. OCSP checks one certificate now. A CRL is a list that can be stale. Tokenization, masking, and steganography hide or replace data. They are not encryption.
Threats, vulnerabilities, and mitigations
Domain 2 is 22 percent. Separate the actor, the path, and the fix.
Actors and the motivation that usually fits. Attributes also include internal or external, funding, and skill.
Actor
Usual clue
Nation-state
Funding and skill, often espionage or strategic disruption
Organized crime
Financial gain
Hacktivist
A political or philosophical cause
Insider
Someone who already has access and misuses it
Shadow IT
A system the organization did not approve
Unskilled attacker
Limited skill, often ready-made tools
Paths in
Smishing is SMS. Vishing is voice. Phishing is usually email. Business email compromise impersonates a trusted person to move money. Pretexting is a made-up story. Typosquatting is a lookalike domain. A watering hole is a site the target already visits. Removable media, default passwords, open ports, and a compromised supplier or MSP are vectors too.
Malware and attacks
A worm spreads on its own. A virus needs a host. A Trojan looks legitimate. A logic bomb waits for a condition. A rootkit hides. Ransomware extorts. Spyware collects. A keylogger records keys. Password spraying tries a few passwords on many accounts. Brute force tries many passwords on one account. SQL injection changes a query. Cross-site scripting runs in the browser. A buffer overflow writes past a memory boundary. A downgrade forces a weaker protocol. A birthday attack seeks a hash collision.
Indicators and fixes
Impossible travel, concurrent sessions, missing logs, and a spike in resource use are clues. Segment networks, patch, encrypt, monitor, enforce least privilege, and decommission what you no longer need. Hardening changes the default password, closes unused ports, and adds a host firewall and endpoint protection. An allow list blocks unapproved programs.
Security architecture
Domain 3 is 18 percent. Say where the control sits, and what happens when it fails.
Recovery and failure choices. RTO is downtime. RPO is data loss.
Term
Meaning
Hot site
Ready to run, with current data
Warm site
Partial equipment or data, slower than hot
Cold site
Space and power, little ready equipment
Fail-open
Traffic or a door continues when the control fails. Use it for life safety.
Fail-closed
Access stops when the control fails. Use it for sensitive data.
UPS
Short power so a generator can start
Placement
An IPS inline can block. A tap only copies traffic. A jump server is the admin door into a private network. A screened subnet faces the internet. The database stays behind it. 802.1X with EAP authenticates a switch port. A WAF understands HTTP. A VPN is the remote encrypted tunnel. SD-WAN steers across circuits. SASE delivers security from the cloud edge. An air gap has no network path.
Data and resilience
Data is at rest, in transit, or in use. Sovereignty means the law of the place where the data sits. Load balancing shares work. Clustering keeps a service alive when a node dies. Geographic dispersion and a second cloud survive a regional outage. A responsibility matrix says who patches the host and who patches the guest. Infrastructure as code builds that environment from files. Industrial and real-time systems often cannot take a casual patch.
Security operations
Domain 4 is 28 percent, the largest share. This is the daily work.
Identity and email controls that are easy to swap on a hurried read.
Control
Job
SPF
Lists which servers may send mail for the domain
DKIM
Signs the message so a change is visible
DMARC
Says what to do when SPF or DKIM fails, and asks for reports
SAML
Carries a sign-in assertion for federation
OAuth
Issues a scoped authorization token. It is not a password.
LDAP
Looks up a directory
OpenID Connect Extra
A common sign-in layer on OAuth. The SY0-701 bullets name OAuth and SAML.
Access and mobile devices
BYOD is user-owned. COPE is company-owned and personally enabled. CYOD is a choice from an approved list. COBO, on the acronym list, is corporate-owned and business only. MDM can wipe company data. WPA3 is the wireless protection the objectives name. NAC checks a device before it joins. MAC uses system labels. DAC lets the owner decide. RBAC uses roles. ABAC uses attributes such as department, sensitivity, and time. Just-in-time rights expire. A vault plus ephemeral credentials replaces a shared admin password. Factors are something you know, have, are, or somewhere you are.
Vulnerabilities and monitoring
CVE names a flaw. CVSS scores it. A false positive alerts on nothing. A false negative misses a real flaw, which is worse. Rescan after you patch. A SIEM correlates logs. EDR watches the endpoint. XDR reaches across more telemetry. Tune noisy alerts. Quarantine a host that is encrypting shares. File integrity monitoring reports a binary that changed outside a patch window. Static analysis reads code. Dynamic analysis runs it. A sandbox isolates unknown software.
Incidents and evidence
The order is preparation, detection, analysis, containment, eradication, recovery, and lessons learned. Isolate a spreading host before a long write-up. A legal hold stops deletion. A chain of custody records every person who handles the image. Useful sources include firewall, endpoint, and application logs, plus a packet capture. Automation can provision accounts from HR, and a bad HR record will be applied just as fast.
Security program management and oversight
Domain 5 is 20 percent. Policies, dollars, vendors, and proof.
Risk math. Compare a control's yearly cost with ALE, not with a single dramatic loss, unless a law requires the control anyway.
Term
Meaning
Exposure factor
Percent of the asset lost in one event
SLE
Asset value times exposure factor. One event.
ARO
How many times a year you expect the event
ALE
SLE times ARO. The yearly figure.
MTBF
Average time between failures
MTTR
Average time to repair or recover
Governance
A policy mandates. A standard gives the required specification, such as password length. A procedure or playbook is the steps. A guideline only advises. The owner is accountable. The controller decides why personal data is processed. The processor acts on the controller's instructions. The custodian takes day-to-day care. The data subject is the person the record describes.
Treatment, vendors, and tests
Avoid stops the activity. Mitigate reduces it. Transfer shifts the impact, often with insurance. Accept keeps it, sometimes as a time-bounded exception. Expansionary appetite takes more risk. Conservative appetite takes less. An SLA measures service. An NDA protects secrets. An MOU states intent. A statement of work defines one job. A right-to-audit clause lets you test the vendor. A known environment gives the tester internal knowledge. An unknown environment does not. Passive reconnaissance does not touch the target. Phishing exercises need a first report and a later measurement.
Frequently asked questions
Are these notes the official CompTIA objectives?
No. They are an original summary of the public SY0-701 objectives, version 6.0. Confirm the current PDF with CompTIA before you book.
What does the Extra tag mean?
Extra marks a useful idea the SY0-701 objective bullets do not name, such as OpenID Connect. Learn the unmarked items first.
Which incident steps does SY0-701 list?
Preparation, detection, analysis, containment, eradication, recovery, and lessons learned. Contain before you restore.
Continue the Security+ study path
Use the flashcards to check whether you can recall these distinctions.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. CompTIA and Security+ are trademarks of CompTIA, Inc. NodnWebTools is not affiliated with, endorsed by, or sponsored by CompTIA.