StudyToCert

All certifications / Security+ / Cheat sheet

Security+ SY0-701 cheat sheet

Every exam tip and key term from the free Security+ lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: General security concepts (12%)

Exam tips

Key terms

Technical control
A control enforced by hardware, software or firmware, such as a firewall, encryption or MFA.
Managerial control
A control that directs or governs security, such as a policy, risk assessment or vendor assessment; also called administrative.
Operational control
A control carried out by people in daily work, such as guards, backup procedures or delivering training.
Physical control
A control that protects tangible spaces and objects, such as fences, locks, bollards and cameras.
Control category
How a control is implemented and by whom; separate from control type, which describes what it does.
Defense in depth
Layering several different controls so that the failure of one does not expose the asset.
Preventive control
Stops an incident before it happens, such as a firewall rule, lock or MFA.
Deterrent control
Discourages an attacker from trying, such as a warning sign, visible camera or login banner.
Detective control
Identifies or records an incident, such as an IDS, SIEM alert, audit or log review.
Corrective control
Limits damage and restores normal operation after an incident, such as restoring backups or reimaging.
Compensating control
An alternative control used when the primary control cannot be implemented, addressing the same risk.
Directive control
Instructs people on required behavior, such as a policy, procedure or acceptable use agreement.
Confidentiality
Ensuring only authorized parties can access information.
Integrity
Ensuring information is accurate and unchanged except by authorized processes.
Availability
Ensuring systems and data are accessible to authorized users when needed.
Authentication
Proving a claimed identity, for example with a password, token, certificate or biometric.
Authorization
Determining what an authenticated subject is allowed to do.
Accounting
Recording user activity so it can be reviewed, audited or billed.
Non-repudiation
Assurance that someone cannot deny an action, typically provided by digital signatures.
Zero trust
A security model that removes implicit trust based on network location and verifies every access request.
Control plane
The part of a zero trust architecture that manages policy and makes access decisions.
Data plane
The part of a zero trust architecture where traffic flows and access decisions are enforced.
Policy engine
The control plane component that evaluates a request against policy and decides to grant, deny or revoke.
Policy administrator
The control plane component that carries out the engine's decision by establishing or ending sessions.
Policy enforcement point (PEP)
The data plane component between subject and resource that allows, monitors or terminates connections.
Adaptive identity
Adjusting authentication requirements based on risk signals such as location, device and behavior.
Implicit trust zone
The area behind a PEP where traffic is trusted after passing the check; kept as small as possible.
Bollard
A short, sturdy post that blocks vehicles from reaching entrances or buildings.
Access control vestibule
A small room with two interlocking doors that allows one person through at a time; also called a mantrap.
Tailgating
Following an authorized person through a secured entrance without their knowledge; piggybacking is with their consent.
Honeypot
A decoy system with no legitimate use, designed to attract attackers and detect their activity.
Honeynet
A network of honeypots that simulates a real environment to observe attacker behavior.
Honeytoken
Fake data, such as a bogus account, record or credential, that triggers an alert when used or accessed.
DNS sinkhole
A DNS server configuration that returns a controlled address for known-malicious domains to disrupt and detect malware.
Change management
The formal process for requesting, approving, testing, implementing and documenting changes.
Change advisory board (CAB)
The group that reviews and approves or rejects significant changes.
Impact analysis
An assessment of what a change could affect, how badly and how likely, before it is approved.
Backout plan
Documented steps to return a system to its previous state if a change fails.
Maintenance window
A pre-agreed time when changes are allowed because business impact is lowest.
Stakeholder
Anyone affected by a change who should be consulted or informed.
Version control
Tracking changes to code or configuration over time so they can be reviewed and reverted.
Symmetric encryption
Encryption that uses the same secret key to encrypt and decrypt; fast and suited to bulk data.
Asymmetric encryption
Encryption that uses a public/private key pair; slower but solves key distribution and enables signatures.
AES
Advanced Encryption Standard, the current standard symmetric block cipher with 128-, 192- or 256-bit keys.
ECC
Elliptic curve cryptography, an asymmetric approach offering strong security with smaller keys.
Diffie-Hellman
A key agreement method that lets two parties derive a shared secret over an untrusted network.
Session key
A temporary symmetric key used to encrypt one communication session.
Perfect forward secrecy
Use of ephemeral keys so that compromise of a long-term key does not expose past sessions.
Hash
A fixed-length, one-way output of a hash function used to verify integrity.
Collision
Two different inputs that produce the same hash, which breaks a hash function's security.
Salt
A random, per-user value added to a password before hashing to make each hash unique.
Rainbow table
A precomputed table of hashes and matching passwords used to reverse unsalted hashes quickly.
Key stretching
Repeating or strengthening a hash so each guess is slow, using algorithms like PBKDF2, bcrypt or Argon2.
HMAC
A hash-based message authentication code that combines a hash with a secret key for integrity and authenticity.
Pepper
A secret value added to passwords before hashing that is stored separately from the password database.
Full disk encryption (FDE)
Encrypting an entire drive, including the OS, so data is unreadable without the key when the device is off.
Self-encrypting drive (SED)
A drive that performs full disk encryption in its own hardware.
Volume encryption
Encrypting a specific partition or logical volume rather than the whole disk.
File-level encryption
Encrypting individual files or folders, often tied to specific users.
Transparent data encryption (TDE)
Database encryption of data and log files at rest, decrypted automatically for authorized queries.
Record-level encryption
Encrypting individual records or fields, such as card numbers, within a database.
Obfuscation
Making data difficult to understand or recognize, with or without encryption.
Steganography
Hiding data inside another file or medium so its existence is concealed.
Tokenization
Replacing a sensitive value with a random token that can only be mapped back through a secure vault.
Token vault
The protected system that stores the mapping between tokens and original sensitive values.
Data masking
Hiding part or all of a data value, such as showing only the last four digits of a card.
Static masking
Permanently replacing sensitive values in a copy of data, often for testing.
Dynamic masking
Hiding data at display time based on the viewer's role while stored data stays unchanged.
Public key
The shareable half of a key pair, used to encrypt data for the owner or verify the owner's signatures.
Private key
The secret half of a key pair, used to decrypt data sent to the owner or create digital signatures.
Key pair
A mathematically linked public and private key used in asymmetric cryptography.
Key escrow
Storing a copy of a key with a trusted party or system so it can be recovered when needed.
Key rotation
Replacing keys periodically or after suspected compromise to limit exposure.
Dual control
Requiring two or more authorized people to perform a sensitive action, such as recovering an escrowed key.
Public key infrastructure (PKI)
The CAs, certificates, policies and processes used to manage and trust public keys.
Certificate authority (CA)
A trusted entity that validates identities and signs digital certificates.
Certificate signing request (CSR)
A request containing a public key and identity details, sent to a CA to obtain a certificate.
Root of trust
The trusted anchor, usually a root CA certificate preinstalled in the trust store, from which trust chains are built.
Intermediate CA
A CA signed by the root that issues end-entity certificates, keeping the root offline.
Self-signed certificate
A certificate signed with its own private key rather than by a trusted CA.
Wildcard certificate
A certificate for all first-level subdomains of a domain, such as *.example.com.
Subject Alternative Name (SAN)
A certificate field listing multiple specific host names or domains the certificate is valid for.
Revocation
Invalidating a certificate before its expiration date, for example after key compromise.
Certificate revocation list (CRL)
A CA-signed list of revoked certificate serial numbers published periodically.
CRL distribution point
A field in a certificate that tells clients where to download the CRL.
OCSP
Online Certificate Status Protocol, which returns the real-time status of a single certificate.
OCSP responder
The CA server that answers OCSP requests with signed good, revoked or unknown responses.
OCSP stapling
The server attaches a recent CA-signed OCSP response to its certificate during the TLS handshake.
Soft fail
A client behavior that accepts a certificate when revocation status cannot be checked.
Digital signature
A value created with a private key over a message's hash, proving integrity, origin and non-repudiation.
Message digest
The fixed-length hash of a message that is actually signed.
Signing
Using the signer's private key to create a signature over a digest.
Verification
Using the signer's public key to check a signature against a freshly computed hash.
Code signing
Digitally signing software so users can verify its publisher and that it was not modified.
ECDSA
Elliptic Curve Digital Signature Algorithm, a common signature algorithm using elliptic curve keys.
Trusted Platform Module (TPM)
A chip on a device's motherboard that securely stores keys and boot measurements for that device.
Measured boot
Recording hashes of boot components so their integrity can be checked or attested.
Hardware security module (HSM)
A tamper-resistant appliance or service that generates, stores and uses keys for many systems.
Secure enclave
An isolated, protected processor environment that keeps secrets and code separate from the main OS.
Key management system (KMS)
Software and processes that manage keys through their lifecycle, including rotation and auditing.
Remote attestation
A device proving its boot and configuration state to a remote server, typically using its TPM.
Non-exportable key
A key that can be used inside secure hardware but never extracted from it.
OSI model
A seven-layer conceptual model describing how network communication is divided into functions.
Encapsulation
Wrapping data from a higher layer with each lower layer's header as it moves down the stack.
Layer 2 (Data Link)
The layer that moves frames between devices on the same local network using MAC addresses.
Layer 3 (Network)
The layer that routes packets between networks using IP addresses.
Layer 4 (Transport)
The layer that provides end-to-end delivery using TCP or UDP and port numbers.
Layer 7 (Application)
The layer where user-facing protocols such as HTTP, DNS and SMTP operate.
SYN flood
A Layer 4 denial-of-service attack that exhausts a server with half-open TCP connections.
Telnet
A cleartext remote terminal protocol on TCP 23, replaced by SSH.
SSH
Secure Shell, an encrypted remote access and tunneling protocol on TCP 22.
SFTP
SSH File Transfer Protocol, which transfers files over an encrypted SSH connection.
FTPS
FTP secured with TLS, a different protocol from SFTP.
LDAPS
LDAP over TLS, typically on TCP 636, protecting directory queries and binds.
SNMPv3
The version of SNMP that adds authentication, integrity and encryption with per-user credentials.
HSTS
HTTP Strict Transport Security, which tells browsers to use only HTTPS for a site.
Port
A number that identifies a specific service or application on a host.
Port 22
SSH, SFTP and SCP for encrypted remote access and file transfer.
Port 25
SMTP, used to deliver email between mail servers.
Port 53
DNS, using UDP for most queries and TCP for zone transfers and large responses.
Ports 389 and 636
LDAP (cleartext or StartTLS) and LDAPS (LDAP over TLS) respectively.
Port 3389
Remote Desktop Protocol for graphical remote access to Windows systems.
Port 443
HTTPS, web traffic protected by TLS.
ARP poisoning
Sending forged ARP replies to associate the attacker's MAC address with another host's IP, enabling on-path attacks.
DNS poisoning
Inserting false records into a DNS resolver's cache so users are redirected to malicious addresses.
Rogue DHCP server
An unauthorized DHCP server that hands out incorrect settings such as a malicious gateway or DNS server.
DHCP starvation
Exhausting a DHCP server's address pool with requests from fake MAC addresses.
DHCP snooping
A switch feature that allows DHCP server responses only on trusted ports.
Dynamic ARP inspection
A switch feature that drops ARP messages that do not match trusted IP-to-MAC bindings.
DNSSEC
DNS Security Extensions, which digitally sign DNS records so resolvers can verify their authenticity and integrity.

Domain 2: Threats, vulnerabilities & mitigations (22%)

Exam tips

Key terms

Threat actor
The individual or group responsible for a threat or attack.
Nation-state actor
A government-sponsored group with high resources and sophistication, often conducting espionage or sabotage.
Advanced persistent threat (APT)
A long-term, stealthy campaign by a skilled, well-resourced actor that maintains access to a target.
Organized crime
Financially motivated criminal groups running operations such as ransomware and fraud.
Hacktivist
An actor who attacks to promote a political or social cause, often through defacement, DDoS or leaks.
Unskilled attacker
An attacker who relies on tools and exploits created by others; formerly called a script kiddie.
Insider threat
A risk from someone with legitimate access, whether malicious or accidental.
Shadow IT
Technology used within an organization without approval from IT or security.
Espionage
Covertly gathering secret or sensitive information for a government or competitor.
Data exfiltration
Unauthorized transfer of data out of an organization's environment.
Financial gain
Attacking for money, through ransomware, fraud, theft or selling data.
Blackmail (extortion)
Threatening to release data or continue harm unless the victim pays or complies.
Double extortion
Ransomware that both encrypts data and threatens to publish stolen copies.
Service disruption
Attacking to make systems or services unavailable.
Cryptojacking
Secretly using a victim's computing resources to mine cryptocurrency.
Threat vector
The path or method an attacker uses to reach a target; also called an attack vector.
Attack surface
The total set of points where an attacker could try to enter or extract data.
Smishing
Phishing delivered by SMS text message.
Vishing
Phishing conducted over voice calls.
Baiting
Leaving infected media or offering something tempting so a victim introduces malware themselves.
Supply chain attack
Compromising a target through a trusted supplier, vendor, software update or service provider.
Unsupported system
A system past end of life that no longer receives security updates.
Default credentials
Factory-set usernames and passwords that attackers know and try first.
Phishing
Fraudulent messages, usually email, that trick recipients into revealing information or running malware.
Spear phishing
Phishing targeted at a specific person or group using tailored details.
Whaling
Spear phishing aimed at senior executives.
Pretexting
Creating an invented but believable scenario to justify a request for information or access.
Business email compromise (BEC)
Using a compromised or spoofed business email account to trick staff into sending money or data.
Watering hole attack
Compromising a website the target group commonly visits in order to infect its visitors.
Typosquatting
Registering misspelled versions of real domains to catch typos or make phishing look legitimate.
Out-of-band verification
Confirming a request through a separate, trusted channel such as a known phone number.
OWASP Top 10
A regularly updated list of the most critical web application security risk categories.
Broken access control
Failures that let users act outside their intended permissions, such as viewing others' records.
Insecure direct object reference
Accessing an object by changing an identifier because the server does not check authorization.
Injection
Sending untrusted input to an interpreter so it is executed as part of a command or query.
Security misconfiguration
Insecure defaults, unnecessary features, verbose errors or open storage that weaken an application.
Software and data integrity failure
Trusting code, updates or data without verifying their integrity, such as unsigned updates or insecure deserialization.
Server-side request forgery (SSRF)
Tricking a server into making requests to destinations the attacker chooses, often internal systems.
SQL injection
Inserting SQL syntax into input that an application places into a database query, changing the query's meaning.
Parameterized query
A query with fixed structure where user input is passed separately as data; also called a prepared statement.
Reflected XSS
Script supplied in a request that the server immediately includes in its response to that victim.
Stored XSS
Script saved by the application and served to every user who views the affected content.
Output encoding
Converting special characters so browsers display untrusted data as text rather than executing it.
CSRF
Cross-site request forgery, which makes a logged-in user's browser send an unwanted request to a trusted site.
Anti-CSRF token
A random value tied to the session that must accompany state-changing requests, which attackers cannot guess.
Buffer overflow
Writing more data to a buffer than it can hold, overwriting adjacent memory.
Race condition
A flaw where the result depends on the timing of events that an attacker can influence.
TOCTOU
Time-of-check to time-of-use, a race condition where a resource changes between being checked and being used.
Memory injection
Placing and running malicious code inside the memory of a legitimate running process.
DLL injection
Forcing a running process to load a malicious dynamic link library.
ASLR
Address space layout randomization, which randomizes memory locations to make exploitation harder.
DEP
Data execution prevention, which marks data regions of memory as non-executable.
Threat modeling
A structured process for identifying and prioritizing threats to a system and planning mitigations.
Data flow diagram
A diagram showing how data moves between users, processes and stores, used as the basis for a threat model.
Trust boundary
A point where data moves between areas with different levels of trust.
STRIDE
A threat categorization: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
Attack tree
A diagram breaking an attacker's goal into the alternative ways it could be achieved.
MITRE ATT&CK
A public knowledge base of real-world adversary tactics and techniques.
Cyber Kill Chain
A model of intrusion stages from reconnaissance to actions on objectives.
Ransomware
Malware that encrypts data or systems and demands payment for recovery, often also stealing data.
Trojan
Malware disguised as legitimate software that the user installs willingly.
Worm
Self-replicating malware that spreads across networks without user action.
Rootkit
Malware that hides deep in the OS or firmware to conceal itself and maintain privileged access.
Logic bomb
Malicious code that triggers when a specific condition, such as a date or event, occurs.
Keylogger
Software or hardware that records keystrokes to capture sensitive input.
Fileless malware
Malware that runs in memory and abuses legitimate tools, leaving little or nothing on disk.
Spyware
Malware that secretly monitors and collects information about a user.
Brute force attack
Trying many possible passwords against an account until one works.
Dictionary attack
A guessing attack using lists of common words and known passwords.
Password spraying
Trying a few common passwords against many accounts to avoid lockout.
Credential stuffing
Using username and password pairs stolen from one breach to log in to other services.
Offline attack
Cracking stolen password hashes on the attacker's own hardware, where no lockout applies.
Account lockout
Disabling an account temporarily after a set number of failed login attempts.
Passwordless authentication
Logging in without a shared password, for example with passkeys or FIDO2 security keys.
Downgrade attack
Forcing parties to negotiate a weaker protocol version or cipher than both support.
SSL stripping
Rewriting HTTPS connections or links to plain HTTP so traffic is not encrypted.
Collision
Two different inputs that produce the same hash value.
Birthday attack
Exploiting probability to find hash collisions in roughly the square root of the possible hash values.
Collision resistance
The property that it is infeasible to find two inputs with the same hash.
HSTS
HTTP Strict Transport Security, a header that tells browsers to use only HTTPS for a site.
Indicator
An observable clue that suggests malicious activity may be occurring.
Impossible travel
Logins from locations too far apart to reach in the time between them.
Concurrent session usage
The same account active in multiple places at once when that is not normal.
Resource consumption
Unusual CPU, memory, disk or network use that may signal malware or exfiltration.
Missing logs
Gaps or deletions in logging, often caused by attackers covering their tracks.
Out-of-cycle logging
Activity recorded at unusual times for the user or system.
Indicator of compromise (IoC)
A specific artifact, such as a hash, IP address or domain, linked to known malicious activity.
Segmentation
Dividing a network into zones and controlling traffic between them to limit an attacker's reach.
VLAN
A virtual LAN that logically separates traffic on shared switch hardware.
Screened subnet
A zone between the internet and the internal network for public-facing servers; formerly called a DMZ.
Microsegmentation
Fine-grained segmentation that applies policy to individual workloads or applications.
Lateral movement
An attacker moving from one compromised system to others within a network.
Air gap
Physical isolation of a system or network from all other networks.
Isolation
Separating a system so it cannot communicate, used for high-risk systems or during incident response.
Least privilege
Granting only the minimum access needed to perform a task, for only as long as needed.
Access control list (ACL)
An ordered list of rules on a resource specifying which subjects are allowed or denied which access.
Implicit deny
The default rule that blocks anything not explicitly permitted.
Privilege creep
The gradual accumulation of unnecessary access as users change roles.
Access review
A periodic check where owners confirm that each user's access is still required.
Need to know
Restricting access to information to those who require it for a specific task.
Separation of duties
Splitting a sensitive process among several people so no one can complete it alone.
Application allow listing
Permitting only approved software to run and blocking everything else by default.
Deny listing
Blocking specific known-bad software while allowing everything else.
Hash rule
An allow list rule that approves a file by its exact cryptographic hash.
Publisher rule
An allow list rule that approves software signed by a trusted vendor's certificate.
Path rule
An allow list rule that approves programs in a specific folder location.
Audit mode
Running an allow list policy that logs would-be blocks without enforcing them.
Living off the land
Attackers using legitimate built-in tools to avoid detection and bypass controls.
Patch management
The process of identifying, testing, deploying and verifying software updates.
Virtual patching
Blocking exploitation of a vulnerability with a network control, such as an IPS or WAF rule, until a real patch is applied.
End of life
The point after which a vendor stops providing updates for a product.
Encryption at rest
Encrypting stored data on disks, databases or backups.
Encryption in transit
Encrypting data as it moves across networks, for example with TLS or a VPN.
SIEM
Security information and event management, which collects, correlates and alerts on logs from many sources.
Asset inventory
An accurate list of hardware and software, needed to know what to patch and monitor.
Hardening
Reducing a system's attack surface by removing unneeded components and securing its configuration.
Secure baseline
A documented, approved secure configuration applied consistently to systems.
CIS Benchmarks
Consensus-based secure configuration guides published by the Center for Internet Security.
Configuration drift
Gradual deviation of a system's settings from its approved baseline.
Host-based firewall
Firewall software on an individual system that controls its inbound and outbound traffic.

Domain 3: Security architecture (18%)

Exam tips

Key terms

IaaS
Infrastructure as a Service, providing virtual machines, storage and networks; the customer manages the OS and above.
PaaS
Platform as a Service, providing a managed platform where the customer deploys code and manages data and access.
SaaS
Software as a Service, a complete application run by the provider; the customer manages data, users and settings.
Shared responsibility model
The division of security duties between cloud provider and customer, varying by service model.
Multitenancy
Multiple customers sharing the same underlying cloud infrastructure while logically separated.
Hybrid cloud
A combination of on-premises or private infrastructure with public cloud services.
CASB
Cloud access security broker, which provides visibility and policy enforcement for cloud and SaaS use.
Infrastructure as code (IaC)
Defining and deploying infrastructure through machine-readable templates rather than manual setup.
Serverless
Running event-triggered functions without managing servers; the provider handles the underlying platform.
Microservices
An architecture that splits an application into small, independent services communicating over APIs.
Container
A lightweight package of an application and its dependencies that shares the host operating system kernel.
Container image
The template from which containers are created, which should be scanned and trusted.
Orchestration
Automated deployment, scaling and management of containers, for example with Kubernetes.
Immutable infrastructure
Replacing components with new versions rather than modifying them in place.
Hypervisor
Software that creates and manages virtual machines and keeps them isolated from each other.
Type 1 hypervisor
A bare-metal hypervisor that runs directly on hardware.
Type 2 hypervisor
A hosted hypervisor that runs as an application on a normal operating system.
VM escape
An attack in which code breaks out of a virtual machine to reach the hypervisor, host or other VMs.
VM sprawl
Uncontrolled growth of virtual machines that are unmanaged, unpatched or forgotten.
Resource reuse
The risk that data remains in memory or storage reassigned from one VM or tenant to another.
Snapshot
A saved state of a VM at a point in time, which may contain sensitive data and old vulnerabilities.
Industrial control system (ICS)
Systems that monitor and control physical industrial processes.
SCADA
Supervisory control and data acquisition, an ICS type that manages geographically distributed processes.
PLC
Programmable logic controller, a rugged computer that controls machinery in industrial settings.
IoT
Internet of Things, network-connected everyday devices such as cameras, sensors and smart appliances.
Embedded system
A computer built into another device to perform a dedicated function.
RTOS
Real-time operating system, designed to respond to events within strict, predictable time limits.
Data diode
A device that allows network traffic to flow in only one direction.
On-premises
Infrastructure owned and operated by the organization in its own facilities.
Vendor lock-in
Dependence on one provider's services that makes switching costly or difficult.
Data sovereignty
The principle that data is subject to the laws of the country where it is stored.
Scalability
The ability to increase or decrease capacity to match demand.
Capital expenditure (CapEx)
Up-front spending on assets such as servers, typical of on-premises infrastructure.
Operating expenditure (OpEx)
Ongoing pay-as-you-go spending, typical of cloud services.
Stateless packet filter
A firewall that evaluates each packet independently against address, protocol and port rules.
Stateful firewall
A firewall that tracks connection state and allows return traffic for established connections.
Layer 7 firewall
A firewall that understands and filters based on application protocols and content.
Next-generation firewall (NGFW)
A firewall combining stateful inspection, application awareness, user identity and integrated IPS.
Web application firewall (WAF)
A firewall that inspects HTTP/HTTPS traffic to protect web applications from attacks like SQL injection.
Unified threat management (UTM)
An all-in-one appliance combining firewall, IPS, antivirus, filtering and VPN functions.
TLS inspection
Decrypting and re-encrypting TLS traffic so a security device can inspect its contents.
IDS
Intrusion detection system, which monitors and alerts on suspicious activity without blocking it.
IPS
Intrusion prevention system, which sits inline and can block malicious traffic automatically.
Inline
Deployed directly in the traffic path so traffic must pass through the device.
Network tap
A hardware device that copies all traffic on a network link to a monitoring tool.
SPAN port
A switch port configured to mirror traffic from other ports to a monitoring device.
Signature-based detection
Detecting attacks by matching known patterns.
Anomaly-based detection
Detecting attacks by spotting deviations from a learned baseline of normal behavior.
False negative
A real attack that the system fails to detect.
Fail-open
A failure mode where a device allows traffic or access when it fails, favoring availability.
Fail-closed
A failure mode where a device blocks traffic or access when it fails, favoring security.
Fail-safe (physical)
A lock that unlocks on power loss so people can exit safely.
Fail-secure (physical)
A lock that stays locked on power loss to protect assets.
Bypass module
Hardware that passes traffic around an inline device if it fails, a fail-open design.
High availability pair
Two redundant devices where one takes over if the other fails.
802.1X
An IEEE standard for port-based network access control using EAP and usually RADIUS.
Supplicant
The device or software requesting network access in 802.1X.
Authenticator
The switch or access point that enforces 802.1X by controlling the port.
Authentication server
The server, usually RADIUS, that checks credentials and approves or denies access.
EAP-TLS
An EAP method using certificates on both client and server for mutual authentication.
Network access control (NAC)
Checking identity and device posture before granting network access and enforcing policy.
Port security
A switch feature that restricts which and how many MAC addresses can use a port.
Dissolvable agent
A temporary NAC agent that checks a device's posture and then removes itself.
Site-to-site VPN
An encrypted tunnel connecting two networks, typically between gateways.
Split tunnel
A VPN setup where only corporate traffic uses the tunnel and other traffic goes directly to the internet.
IPsec tunnel mode
IPsec mode that encrypts the entire original packet and adds a new header, used between gateways.
ESP
Encapsulating Security Payload, the IPsec protocol that provides encryption plus integrity and authentication.
SD-WAN
Software-defined WAN, which manages and routes traffic across multiple links using policy.
SASE
Secure access service edge, which combines SD-WAN style networking with cloud-delivered security services.
Jump server
A hardened host that administrators connect through to reach sensitive systems.
Reverse proxy
A server that receives inbound requests on behalf of back-end servers.
Data classification
Labeling data by sensitivity and value so appropriate controls can be applied.
PII
Personally identifiable information that can identify an individual.
PHI
Protected health information, health data linked to an individual.
Regulated data
Data governed by laws or industry standards, such as card data or health records.
Trade secret
Confidential business information that provides a competitive advantage.
Data owner
The senior person accountable for data who decides its classification and access.
Data custodian
The role, often IT, that implements and maintains the controls the owner requires.
Data at rest
Data stored on disks, databases, backups or other media.
Data in transit
Data moving across a network; also called data in motion.
Data in use
Data being actively processed in memory or displayed.
Transport encryption
Protecting data in transit with protocols such as TLS, IPsec or SSH.
Confidential computing
Using hardware trusted execution environments to protect data while it is processed.
Memory scraping
Malware that reads sensitive data from a system's memory while it is in use.
Encryption
Reversible transformation of data using a key so only authorized holders can read it.
Hashing
One-way transformation producing a fixed-length value, used for integrity checks and password storage.
Data masking
Hiding part or all of a sensitive value from view.
Tokenization
Replacing sensitive data with a random token mapped back only through a secure vault.
Data loss prevention (DLP)
Tools and policies that detect and stop sensitive data from leaving authorized locations.
Endpoint DLP
DLP running on devices to control actions such as USB copying, printing and uploads.
Geographic restriction
Limiting where data may be stored or accessed from, for example by country.
High availability
Designing systems to keep running with minimal downtime through redundancy and failover.
Single point of failure
A component whose failure stops the whole system.
Active-passive cluster
A cluster where a standby node takes over if the active node fails.
Active-active cluster
A cluster where all nodes handle workload simultaneously.
Load balancer
A device or service that distributes requests across multiple servers and checks their health.
RAID 5
Disk striping with distributed parity across three or more disks, surviving one disk failure.
RAID 6
Disk striping with double parity, surviving two simultaneous disk failures.
UPS
Uninterruptible power supply, providing short-term battery power during outages.
RPO
Recovery point objective, the maximum acceptable data loss measured in time.
RTO
Recovery time objective, the maximum acceptable time to restore a service.
MTBF
Mean time between failures, the average time a component operates before failing.
Incremental backup
A backup of data changed since the last backup of any type.
Differential backup
A backup of data changed since the last full backup.
Hot site
A fully equipped, up-to-date recovery site ready to take over quickly.
Cold site
A recovery site with space and power but little or no equipment.
Immutable backup
A backup that cannot be modified or deleted for a defined retention period.

Domain 4: Security operations (28%)

Exam tips

Key terms

Secure baseline
An approved secure configuration that systems of a given type must meet, established, deployed and maintained.
MDM
Mobile device management, software that enforces policies and can lock or wipe mobile devices.
BYOD
Bring your own device, where employees use personal devices for work.
COPE
Corporate-owned, personally enabled: company devices that allow personal use.
CYOD
Choose your own device: employees select from a list of approved company-managed devices.
Containerization
Separating work apps and data from personal content on a device.
Jailbreaking/rooting
Removing OS restrictions on iOS (jailbreaking) or Android (rooting), bypassing built-in security.
WPA3
The current Wi-Fi security standard, using SAE for personal mode and stronger enterprise options.
SAE
Simultaneous Authentication of Equals, the WPA3 handshake that resists offline password cracking.
Pre-shared key (PSK)
A shared passphrase used in WPA2-Personal, vulnerable to offline cracking after handshake capture.
RADIUS
A centralized authentication, authorization and accounting protocol used for enterprise Wi-Fi and network access.
EAP
Extensible Authentication Protocol, a framework for authentication methods used with 802.1X.
EAP-TLS
An EAP method with certificate-based mutual authentication.
Evil twin
A malicious access point impersonating a legitimate network name to intercept users.
Captive portal
A web page that users must interact with before gaining network access.
Asset management
Tracking hardware, software and data through their lifecycle with owners and inventory records.
Enumeration
Discovering and listing assets, for example through network scans or agents.
Sanitization
Removing data from media so it cannot be recovered, allowing reuse.
Cryptographic erase
Sanitizing an encrypted drive by securely destroying its encryption key.
Degaussing
Erasing magnetic media with a strong magnetic field.
Destruction
Physically destroying media by shredding, pulverizing or incineration.
Certificate of destruction
Documented proof from a disposal provider that specific assets were destroyed or sanitized.
Vulnerability scan
An automated check of systems for known weaknesses such as missing patches or misconfigurations.
Credentialed scan
A scan that logs in to systems for deeper, more accurate results.
Non-credentialed scan
A scan without login access, showing what an outsider can see.
False positive
A reported vulnerability that does not actually exist.
False negative
A real vulnerability that a scan fails to report.
CVE
Common Vulnerabilities and Exposures, unique public identifiers for known vulnerabilities.
CVSS
Common Vulnerability Scoring System, a 0.0 to 10.0 severity rating for vulnerabilities.
Penetration test
An authorized simulated attack that exploits weaknesses to show real-world impact.
Rules of engagement
The written agreement defining scope, methods, timing and limits of a test.
Known environment
A test where testers receive full information about the target; formerly white box.
Unknown environment
A test where testers start with little or no information; formerly black box.
Passive reconnaissance
Gathering information without directly interacting with target systems, such as OSINT.
Active reconnaissance
Gathering information by directly probing target systems, such as port scanning.
Pivoting
Using a compromised system as a stepping stone to reach other systems.
OSINT
Open-source intelligence gathered from publicly available sources.
SIEM
Security information and event management, which aggregates, normalizes, correlates and alerts on log data.
Correlation
Linking related events from different sources to identify patterns such as an attack.
Log aggregation
Collecting logs from many systems into a central location.
Alert fatigue
Analysts becoming desensitized to alerts because of excessive false positives.
SCAP
Security Content Automation Protocol, NIST standards for automated, consistent security checks.
NetFlow
A protocol that records metadata about network flows, such as addresses, ports and byte counts.
Syslog
A standard protocol for sending log messages to a central collector.
SPF
Sender Policy Framework, a DNS record listing servers authorized to send email for a domain.
DKIM
DomainKeys Identified Mail, which signs email with a private key and publishes the public key in DNS.
DMARC
A DNS policy that checks SPF/DKIM alignment with the From domain, sets handling and requests reports.
Alignment
The DMARC requirement that the visible From domain matches the domain authenticated by SPF or DKIM.
DMARC policy
The action receivers take on failing mail: none, quarantine or reject.
Secure email gateway
A system that filters inbound and outbound email for spam, malware and phishing.
S/MIME
A standard for signing and encrypting individual email messages with certificates.
EDR
Endpoint detection and response, agents that record endpoint activity and enable detection, investigation and response.
XDR
Extended detection and response, correlating telemetry across endpoints, network, email, identity and cloud.
DLP
Data loss prevention, tools that identify sensitive data and control where it can go.
UEBA
User and entity behavior analytics, which baselines normal behavior and flags deviations.
Telemetry
Detailed activity data collected from systems for analysis.
Host isolation
Cutting an endpoint off from the network, except the security console, to contain a threat.
Behavioral baseline
A model of normal activity against which anomalies are measured.
Provisioning
Creating accounts and granting access when a user joins or changes role.
Deprovisioning
Removing or disabling access when it is no longer needed.
Single sign-on (SSO)
Authenticating once to access multiple applications.
Identity provider (IdP)
The system that authenticates users and issues assertions or tokens to applications.
SAML
An XML-based standard for sending signed authentication assertions from an IdP to a service provider.
OAuth 2.0
An authorization framework that grants applications limited access to resources using tokens.
OpenID Connect
An authentication layer on OAuth 2.0 that provides an ID token identifying the user.
LDAP
A protocol for querying and modifying directory services such as Active Directory.
Multifactor authentication (MFA)
Authentication requiring two or more factors from different categories.
Something you have
A possession factor such as a phone app, hardware key or smart card.
Something you are
A biometric factor such as fingerprint, face or iris.
MFA fatigue
An attack that floods a user with push prompts until they approve one.
FIDO2/passkeys
Phishing-resistant authentication using public key cryptography bound to the real site.
Privileged access management (PAM)
Tools and processes that vault, control, monitor and audit privileged accounts.
Just-in-time access
Granting elevated privileges only when needed and removing them automatically after a set time.
Crossover error rate (CER)
The point where a biometric system's false acceptance and false rejection rates are equal.
Incident response plan
A documented approach defining roles, procedures and communications for handling incidents.
Playbook
Step-by-step procedures for responding to a specific type of incident.
Detection
Identifying that a potential security incident may be occurring.
Containment
Limiting the scope and spread of an incident, such as isolating systems or disabling accounts.
Eradication
Removing the cause of an incident, such as malware, attacker accounts and exploited vulnerabilities.
Recovery
Restoring systems and operations to normal and monitoring for recurrence.
Lessons learned
The post-incident review that identifies improvements to prevent or better handle future incidents.
Root cause analysis
Identifying the underlying reason an incident was possible.
Tabletop exercise
A discussion-based walkthrough of a scenario to test a plan without touching systems.
Inject
A new development introduced during an exercise to test participants' responses.
Walkthrough
A step-by-step review of plan procedures to confirm they are complete and understood.
Simulation
An exercise that recreates realistic conditions, such as a phishing campaign or simulated attack.
Parallel processing test
Running recovery systems alongside production to confirm they work without interrupting operations.
Failover test
Actually switching operations to backup systems or sites to prove recovery works.
After-action review
The post-exercise discussion that records lessons and assigns improvements.
Order of volatility
Collecting evidence from the most short-lived sources first, such as memory before disk.
Chain of custody
Documented record of every person who handled evidence, when and why.
Legal hold
An instruction to preserve relevant data when litigation or investigation is expected, overriding normal deletion.
Acquisition
Collecting evidence, typically by creating forensic copies of media or memory.
Write blocker
A device or tool that prevents any changes to original evidence during acquisition.
Forensic image
A bit-by-bit copy of storage, including deleted files and unallocated space.
E-discovery
Identifying, collecting and producing electronic information for legal proceedings.
Automation
Using scripts and tools to perform tasks without manual effort.
Orchestration
Coordinating multiple tools and automated tasks into a workflow.
SOAR
Security orchestration, automation and response platforms that integrate tools and run response playbooks.
Runbook
A detailed step-by-step procedure for a specific operational or technical task.
Guard rail
An automated control that prevents insecure configurations or actions.
Technical debt
The future cost of maintaining quick or poorly designed solutions such as unmanaged scripts.
Firewall log
A record of allowed and denied network connections with addresses, ports and actions.
Application log
Events recorded by applications, such as requests, errors, logins and transactions.
Endpoint log
Activity recorded on a device, such as processes, file changes and registry edits.
OS security log
Operating system records of logins, privilege use and account or policy changes.
Metadata
Data about data, such as email headers or file timestamps.
Packet capture
A recording of full network packets, including content where not encrypted.
DNS log
Records of domain name lookups, useful for spotting malicious domains.

Domain 5: Program management & oversight (20%)

Exam tips

Key terms

Policy
A high-level, mandatory statement of management's intent and direction.
Standard
A mandatory, specific requirement that supports a policy, such as a minimum key length.
Procedure
Detailed step-by-step instructions for performing a task consistently.
Guideline
Recommended, non-mandatory advice or best practice.
Acceptable use policy (AUP)
A policy defining permitted and prohibited use of organizational systems and data.
Governance
The structures, roles and processes by which an organization directs and oversees security.
Policy exception
A formally approved, documented deviation from a policy or standard, usually with compensating controls.
Risk register
A central record of risks with owners, ratings, controls, treatments and status.
Risk appetite
The amount and type of risk an organization is willing to pursue or accept overall.
Risk tolerance
The acceptable variation in risk around the appetite for specific risks or objectives.
Single loss expectancy (SLE)
The expected cost of one occurrence: asset value times exposure factor.
Annualized rate of occurrence (ARO)
The expected number of occurrences per year.
Annualized loss expectancy (ALE)
The expected yearly loss: SLE times ARO.
Exposure factor (EF)
The percentage of an asset's value lost in a single incident.
Residual risk
The risk that remains after controls are applied.
Risk treatment
The decision on how to respond to an identified risk.
Mitigate
Reduce a risk's likelihood or impact by applying controls.
Transfer
Shift the financial impact of a risk to another party, such as an insurer.
Avoid
Eliminate a risk by not performing the risky activity.
Accept
Formally acknowledge a risk and take no further action, usually because treatment costs more than the potential loss.
Risk exception
A formally approved, time-limited deviation from a policy or standard, often with compensating controls.
Cyber insurance
Insurance that covers financial losses from cyber incidents, a common form of risk transfer.
Service level agreement (SLA)
A contract defining measurable service levels, such as uptime and response times, and penalties for missing them.
Memorandum of understanding (MOU)
A usually non-binding document recording shared intent between parties.
Master service agreement (MSA)
A contract setting general terms for an ongoing relationship and future work.
Statement of work (SOW)
A document defining specific tasks, deliverables, timeline and cost for a project.
Non-disclosure agreement (NDA)
A legal agreement to keep shared information confidential.
Right-to-audit clause
A contract term allowing the customer or its auditor to assess the vendor's controls.
Vendor due diligence
Assessing a supplier's security, financial and legal standing before and during a relationship.
Compliance
Meeting the requirements of applicable laws, regulations, contracts and standards.
Data controller
The organization that decides why and how personal data is processed and is primarily accountable.
Data processor
An organization that processes personal data on the controller's behalf and instructions.
Data subject
The individual whom personal data describes.
Right to be forgotten
A data subject's right in some jurisdictions to have their personal data erased.
Attestation
A formal statement that controls meet specified criteria, such as a SOC 2 report.
External audit
An independent third-party examination of an organization's controls or compliance.
Due care
Acting responsibly to meet security and legal obligations.
Security awareness training
Education that helps people recognize threats, follow policy and report issues.
Phishing simulation
A harmless fake phishing campaign used to measure and improve staff responses.
Reporting rate
The percentage of recipients who report a phishing email, simulated or real.
Role-based training
Training tailored to the risks of specific roles, such as finance, developers or executives.
Just-in-time training
A short lesson delivered at the moment a user makes a mistake.
Anomalous behavior recognition
Training people to notice risky, unexpected or unintentional behavior that may indicate a threat.
Click rate
The percentage of recipients who click a link in a phishing simulation.
Study Security+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Security+ study plan