← All certifications

CompTIA · SY0-701 · 2023-11 objectives

CompTIA Security+

200
questions
8
practice tests
1
free test
750 / 900
to pass the real exam

Try 5 questions

Real questions from the Security+ bank, one per domain. No account, no card needed! Just choose an answer and see the why.

1 / 5OBJ 1.1

A fence, a locked door, and a security guard are all examples of which category of security control?

Practice tests

Timed and scored like the real thing. Answers stay on the server until you submit, then every question is explained in review.

Exam objectives

What SY0-701 covers, and how much of the exam each domain accounts for. Percentages are the share of scored questions in the 2023-11 objectives.

1.0General Security Concepts

12%
  • 1.1Compare and contrast various types of security controls (categories: technical, managerial, operational, physical; types: preventive, deterrent, detective, corrective, compensating, directive).
  • 1.2Summarize fundamental security concepts (CIA, non-repudiation, AAA, Zero Trust planes/components, physical security, deception and disruption technologies).
  • 1.3Explain the importance of change management processes and the impact to security (approval, ownership, impact analysis, backout plan, maintenance window, SOPs, version control).
  • 1.4Explain the importance of using appropriate cryptographic solutions (PKI, symmetric/asymmetric, hashing, salting, digital signatures, key stretching, TPM/HSM, obfuscation, certificates).

2.0Threats, Vulnerabilities, and Mitigations

22%
  • 2.1Compare and contrast common threat actors and motivations (nation-state, unskilled, hacktivist, insider, organized crime, shadow IT; attributes and motivations).
  • 2.2Explain common threat vectors and attack surfaces (message/file/voice, removable media, unsecure networks, default credentials, supply chain, social engineering).
  • 2.3Explain various types of vulnerabilities (application, OS, web, hardware, virtualization, cloud, cryptographic, misconfiguration, mobile, zero-day).
  • 2.4Given a scenario, analyze indicators of malicious activity (malware types, network/application/cryptographic/password attacks, and their indicators).
  • 2.5Explain the purpose of mitigation techniques used to secure the enterprise (segmentation, access control, allow listing, patching, least privilege, hardening, decommissioning).

3.0Security Architecture

18%
  • 3.1Compare and contrast security implications of different architecture models (cloud, IaC, serverless, microservices, SDN, containerization, IoT, ICS/SCADA, embedded, HA).
  • 3.2Given a scenario, apply security principles to secure enterprise infrastructure (device placement, security zones, fail modes, appliances, port security, firewall types, secure access).
  • 3.3Compare and contrast concepts and strategies to protect data (data types/classifications, data states, sovereignty, encryption, masking, tokenization, segmentation).
  • 3.4Explain the importance of resilience and recovery in security architecture (HA, sites, diversity, capacity planning, testing, backups, power).

4.0Security Operations

28%
  • 4.1Given a scenario, apply common security techniques to computing resources (secure baselines, hardening, wireless/mobile security, application security, sandboxing, monitoring).
  • 4.2Explain the security implications of proper hardware, software, and data asset management (acquisition, assignment, inventory, disposal/sanitization, retention).
  • 4.3Explain various activities associated with vulnerability management (scanning, SAST/DAST, threat feeds, pentesting, CVSS/CVE, remediation, validation, reporting).
  • 4.4Explain security alerting and monitoring concepts and tools (log aggregation, SIEM, DLP, SNMP, NetFlow, SCAP, agents, alert tuning).
  • 4.5Given a scenario, modify enterprise capabilities to enhance security (firewalls, IDS/IPS, web/DNS filtering, email security DMARC/DKIM/SPF, FIM, NAC, EDR/XDR, Group Policy/SELinux).
  • 4.6Given a scenario, implement and maintain identity and access management (provisioning, federation, SSO, access control models, MFA, PAM, password concepts, passwordless).
  • 4.7Explain the importance of automation and orchestration related to secure operations (use cases, benefits, and considerations such as complexity and technical debt).
  • 4.8Explain appropriate incident response activities (IR process, training, testing, root cause analysis, threat hunting, digital forensics).
  • 4.9Given a scenario, use data sources to support an investigation (log data, packet captures, dashboards, automated reports, metadata).

5.0Security Program Management and Oversight

20%
  • 5.1Summarize elements of effective security governance (policies, standards, procedures, external considerations, governance structures, roles and responsibilities).
  • 5.2Explain elements of the risk management process (identification, assessment, quantitative/qualitative analysis SLE/ALE/ARO, risk register, appetite/tolerance, strategies, BIA).
  • 5.3Explain the processes associated with third-party risk assessment and management (vendor assessment/selection, agreement types, monitoring, rules of engagement).
  • 5.4Summarize elements of effective security compliance (reporting, consequences of non-compliance, monitoring, privacy considerations).
  • 5.5Explain types and purposes of audits and assessments (attestation, internal/external audits, penetration testing types and reconnaissance).
  • 5.6Given a scenario, implement security awareness practices (phishing campaigns, anomalous behavior recognition, user training, reporting and monitoring).

Summarized from CompTIA Security+’s published exam objectives. Always check the vendor’s current objectives before your exam.