Control jobs
- Prevent stop it
- Deter discourage it
- Detect find it
- Correct repair it
- Compensate substitute
- Direct require it
Study guide · Flashcards & memory notes
40 recall cards for the facts Security+ (SY0-701) keeps asking you to separate: controls and cryptography, attacks, architecture and operations, and risk.
How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.
Choose a deck, flip each card, and mark what you already know.
You marked every card in this deck as known. Shuffle and run through it again, or choose another deck.
Select a question to reveal its answer.
Controls, CIA, zero trust, and cryptography.
Who can read the data. Publishing a lab result breaks confidentiality even if the file is unchanged.
That data was not changed without permission. An edited invoice that still opens is an integrity failure.
That people can use the data when they need it. Ransomware that blocks access is an availability failure.
It stops the action before it succeeds. A firewall drop is preventive. A camera recording is detective.
A substitute when the preferred control cannot be used. A VPN plus a device certificate can stand in for MFA on a legacy app.
The Policy Enforcement Point. The Policy Engine decides. The Policy Administrator carries the decision out.
A TPM is a chip on the motherboard. An HSM is a dedicated key device. Both hold keys in hardware.
A hash is one-way. Encryption can be reversed with the key.
So identical passwords produce different hashes and a precomputed table fails.
Who sent it, and that it did not change. It uses the sender's private key. A shared symmetric key cannot show which party signed.
Actors, social engineering, malware, and vulnerabilities.
An insider misuses access they already have. Shadow IT is a system the organization did not approve.
Phishing by text message. Vishing is a voice call.
On its own, without a user opening a host file. A virus needs a host.
Malware that looks useful so someone will install it.
Spraying tries a few passwords on many accounts. Brute force tries many passwords on one account.
SQL injection changes a database query. XSS runs a script in the browser.
A flaw that is exploited before the vendor has a patch.
The resource changes after the permission check and before it is used.
A site the targets already visit, compromised so their browsers are infected.
It hides processes and files. Ransomware demands payment. A logic bomb waits for a condition.
Sites, devices, email, and vulnerability handling.
Hot is fastest, then warm, then cold. Cold is space more than equipment.
The maximum acceptable downtime. RPO is how much data you can lose.
When people must be able to leave, such as a door during a fire. Sensitive data should fail closed.
HTTP requests, such as form fields and URLs. A layer 4 filter does not understand the application.
No network path to other systems.
A network segment that faces untrusted traffic, with internal systems behind it.
CVE names the flaw. CVSS scores its severity.
A false negative misses a real flaw. A false positive is an alert on something harmless.
SPF lists senders, DKIM signs the message, and DMARC sets the failure policy.
It collects logs from many systems and correlates them into alerts.
Access, incidents, and risk decisions.
SAML carries a sign-in assertion. OAuth issues an authorization token.
MAC uses system labels, DAC lets the owner decide, and RBAC uses roles.
Something you know, have, or are, and somewhere you are.
Elevated access that expires. It replaces a standing admin right.
Preparation, detection, analysis, then containment. Eradication, recovery, and lessons learned come after.
Asset value times exposure factor.
SLE times the annualized rate of occurrence.
Avoid stops the activity. Transfer shifts the impact, often to insurance.
The controller decides why data is processed. The processor follows those instructions.
The tester is given internal knowledge, such as diagrams or credentials. An unknown environment withholds that knowledge.
Groupings that make the highest-yield Security+ facts easier to recall.
Smishing is a text. Vishing is a call. Typosquatting is a lookalike name. A watering hole is a site people already trust.
SPF lists the senders. DKIM signs the body. DMARC tells receivers what to do when those checks fail.
SLE = value × exposure factor. ALE = SLE × how often per year. Compare a control's yearly cost with ALE.
Prepare, detect, analyze, contain, eradicate, recover, learn. Isolate a spreading host before you restore files.
Hot, then warm, then cold. RTO is downtime. RPO is data loss. Fail open for a fire door. Fail closed for payroll.
Test what you have learned with a timed practice exam.
Exam format, the 750 passing score, five domain weights, and a study plan.
Reference notes for controls, threats, architecture, operations, and program management.
40 recall cards in four decks, plus memory notes for attacks, identity, and risk math.
200 original questions with custom exams, explanations, and an unofficial score on the 100-900 scale.
Useful companions while you study.
Generate strong random passwords with custom length, characters, symbols, and security options.
Encode text and files to Base64 or decode Base64 data with UTF-8 support.
Calculate trigonometric functions, logarithms, powers, roots, factorials, and advanced expressions.
Calculate elapsed time, add or subtract hours and minutes, and convert time to decimal hours.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. CompTIA and Security+ are trademarks of CompTIA, Inc. NodnWebTools is not affiliated with, endorsed by, or sponsored by CompTIA.