StudyToCert

All certifications / Security+ / Lessons

CompTIA Security+ SY0-701 · Domain 1: General security concepts

Secure vs insecure protocols: SSH/Telnet, SFTP/FTP, LDAPS/LDAP, HTTPS/HTTP, SNMPv3

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Many of the internet's oldest protocols were designed for trusted networks and send everything, including usernames and passwords, in cleartext. Anyone who can capture the traffic, for example on shared Wi-Fi or after an ARP poisoning attack, can read it. Security+ expects you to know each insecure protocol, its secure replacement, and the ports they use. The secure versions add three things through encryption and authentication: confidentiality (eavesdroppers cannot read the traffic), integrity (changes in transit are detected) and server, and sometimes client, authentication (you know you reached the real system). Knowing the pairs matters because 'replace X with Y' is one of the most common exam question patterns and one of the quickest wins in real hardening work.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Security+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Security+ study plan