Study guide · Flashcards & memory notes

Security+ Flashcards & Memory Notes

40 recall cards for the facts Security+ (SY0-701) keeps asking you to separate: controls and cryptography, attacks, architecture and operations, and risk.

Exam: SY0-7014 decks · 40 cardsNo sign-up required

How to use these cards: Say the answer out loud before you flip the card, and mark it honestly. Revisit the cards you missed tomorrow rather than rereading them right away. Progress is kept only while this page is open. For the full explanations behind each card, see the core notes.

Study mode

Choose a deck, flip each card, and mark what you already know.

All flashcards

Select a question to reveal its answer.

Deck 1 · Foundations

Controls, CIA, zero trust, and cryptography.

10 cards
1.1What does confidentiality protect?

Who can read the data. Publishing a lab result breaks confidentiality even if the file is unchanged.

1.2What does integrity protect?

That data was not changed without permission. An edited invoice that still opens is an integrity failure.

1.3What does availability protect?

That people can use the data when they need it. Ransomware that blocks access is an availability failure.

1.4What does a preventive control do?

It stops the action before it succeeds. A firewall drop is preventive. A camera recording is detective.

1.5What is a compensating control?

A substitute when the preferred control cannot be used. A VPN plus a device certificate can stand in for MFA on a legacy app.

1.6Which zero trust component blocks or allows the request?

The Policy Enforcement Point. The Policy Engine decides. The Policy Administrator carries the decision out.

1.7How do a TPM and an HSM differ?

A TPM is a chip on the motherboard. An HSM is a dedicated key device. Both hold keys in hardware.

1.8How does a hash differ from encryption?

A hash is one-way. Encryption can be reversed with the key.

1.9Why salt a password hash?

So identical passwords produce different hashes and a precomputed table fails.

1.10What does a digital signature prove?

Who sent it, and that it did not change. It uses the sender's private key. A shared symmetric key cannot show which party signed.

Deck 2 · Threats

Actors, social engineering, malware, and vulnerabilities.

10 cards
2.1How does an insider differ from shadow IT?

An insider misuses access they already have. Shadow IT is a system the organization did not approve.

2.2What is smishing?

Phishing by text message. Vishing is a voice call.

2.3How does a worm spread?

On its own, without a user opening a host file. A virus needs a host.

2.4What is a Trojan?

Malware that looks useful so someone will install it.

2.5How does password spraying differ from brute force?

Spraying tries a few passwords on many accounts. Brute force tries many passwords on one account.

2.6How do SQL injection and cross-site scripting differ?

SQL injection changes a database query. XSS runs a script in the browser.

2.7What is a zero-day?

A flaw that is exploited before the vendor has a patch.

2.8What is a time-of-check to time-of-use race?

The resource changes after the permission check and before it is used.

2.9What is a watering hole?

A site the targets already visit, compromised so their browsers are infected.

2.10What does a rootkit do?

It hides processes and files. Ransomware demands payment. A logic bomb waits for a condition.

Deck 3 · Architecture and operations

Sites, devices, email, and vulnerability handling.

10 cards
3.1Order hot, warm, and cold sites by speed.

Hot is fastest, then warm, then cold. Cold is space more than equipment.

3.2What is RTO?

The maximum acceptable downtime. RPO is how much data you can lose.

3.3When should a control fail open?

When people must be able to leave, such as a door during a fire. Sensitive data should fail closed.

3.4What does a web application firewall inspect?

HTTP requests, such as form fields and URLs. A layer 4 filter does not understand the application.

3.5What is an air gap?

No network path to other systems.

3.6What is a screened subnet?

A network segment that faces untrusted traffic, with internal systems behind it.

3.7How do CVE and CVSS differ?

CVE names the flaw. CVSS scores its severity.

3.8Which is worse, a false positive or a false negative?

A false negative misses a real flaw. A false positive is an alert on something harmless.

3.9What do SPF, DKIM, and DMARC each do?

SPF lists senders, DKIM signs the message, and DMARC sets the failure policy.

3.10What does a SIEM do?

It collects logs from many systems and correlates them into alerts.

Deck 4 · Identity, response, and governance

Access, incidents, and risk decisions.

10 cards
4.1How do SAML and OAuth differ?

SAML carries a sign-in assertion. OAuth issues an authorization token.

4.2How do MAC, DAC, and RBAC differ?

MAC uses system labels, DAC lets the owner decide, and RBAC uses roles.

4.3Name the four authentication factors on SY0-701.

Something you know, have, or are, and somewhere you are.

4.4What is just-in-time permission?

Elevated access that expires. It replaces a standing admin right.

4.5What is the incident order through containment?

Preparation, detection, analysis, then containment. Eradication, recovery, and lessons learned come after.

4.6What is the single loss expectancy formula?

Asset value times exposure factor.

4.7What is the annualized loss expectancy formula?

SLE times the annualized rate of occurrence.

4.8How do avoid and transfer differ?

Avoid stops the activity. Transfer shifts the impact, often to insurance.

4.9How do a controller and a processor differ?

The controller decides why data is processed. The processor follows those instructions.

4.10What is a known test environment?

The tester is given internal knowledge, such as diagrams or credentials. An unknown environment withholds that knowledge.

Memory notes

Groupings that make the highest-yield Security+ facts easier to recall.

Control jobs

  • Prevent stop it
  • Deter discourage it
  • Detect find it
  • Correct repair it
  • Compensate substitute
  • Direct require it

Message paths

Smishing is a text. Vishing is a call. Typosquatting is a lookalike name. A watering hole is a site people already trust.

Mail authentication

SPF lists the senders. DKIM signs the body. DMARC tells receivers what to do when those checks fail.

Risk dollars

SLE = value × exposure factor. ALE = SLE × how often per year. Compare a control's yearly cost with ALE.

Incident order

Prepare, detect, analyze, contain, eradicate, recover, learn. Isolate a spreading host before you restore files.

Sites and time

Hot, then warm, then cold. RTO is downtime. RPO is data loss. Fail open for a fire door. Fail closed for payroll.

Continue the Security+ study path

Test what you have learned with a timed practice exam.

Security+ hub →
Available

Overview

Exam format, the 750 passing score, five domain weights, and a study plan.

Available

Core Notes

Reference notes for controls, threats, architecture, operations, and program management.

Available · You are here

Flashcards & Memory Notes

40 recall cards in four decks, plus memory notes for attacks, identity, and risk math.

Available

Practice Exams

200 original questions with custom exams, explanations, and an unofficial score on the 100-900 scale.

Related Tools

Useful companions while you study.

All study topics →