Skip to content

Portal | Level: L1: Foundations | Topics: CompTIA Security+ (SY0-701) | Domain: Security

CompTIA Security+ SY0-701 Certification Prep

All Security+ study material lives here, in one place. Use this as the entry point — the five domain pages hold the practice questions, and the tables below are the fast-reference material worth memorizing before exam day.

Scope and source note

This is an original Security+ SY0-701 study question bank. It was built from the current SY0-701 objective structure and publicly available study references, then rewritten into new questions. It intentionally avoids copied exam dumps or copyrighted practice-exam text.

Primary fact-check sources reviewed:

  • CompTIA Security+ SY0-701 Certification Exam Objectives, Exam Number SY0-701 V7.
  • Professor Messer SY0-701 course index and public pop-quiz format examples.
  • Pearson/Exam Cram SY0-701 sample chapter objective map.
  • Public GitHub/community study-guide repositories for topic coverage only.
  • NIST Cybersecurity Framework 2.0.
  • NIST SP 800-61 incident-response guidance.
  • NIST SP 800-63B digital identity guidance.
  • OWASP Top 10 2021 application-security categories.

Exam shape

Item Security+ SY0-701
Max questions Up to 90
Time 90 minutes
Score scale 100-900
Passing score 750
Question styles Multiple choice and performance-based

Domain weights

Domain Weight Practice questions
1.0 General Security Concepts 12% Q001-Q018, Q124-Q142 (37 total)
2.0 Threats, Vulnerabilities, and Mitigations 22% Q019-Q051, Q143-Q172 (63 total)
3.0 Security Architecture 18% Q052-Q078, Q173-Q197 (52 total)
4.0 Security Operations 28% Q079-Q120, Q198-Q201 (46 total)
5.0 Security Program Management and Oversight 20% Q121-Q123 (in progress)

201 questions total. Numbering has a gap by design — questions were added in two batches; the second batch continues the sequence at Q124 rather than renumbering the first batch and breaking existing links.


High-yield memory tables

Control categories

Control Purpose Example
Preventive Stop an event before it occurs Firewall deny rule, MFA, locked door
Detective Identify that something occurred IDS alert, log review, motion sensor
Corrective Restore or fix after an event Patch, restore from backup, reimage host
Deterrent Discourage action Warning banner, security guard, camera sign
Directive Tell users what to do Policy, sign, procedure, standard
Compensating Alternative when primary control is not feasible Extra monitoring when legacy app cannot use MFA

Common ports

Protocol Port Notes
FTP 20/21 Insecure file transfer
SSH/SFTP/SCP 22 Secure remote shell/file transfer
Telnet 23 Insecure remote shell
SMTP 25 Mail transfer
DNS 53 UDP commonly, TCP for zone transfers/large replies
DHCP 67/68 Address assignment
HTTP 80 Insecure web
Kerberos 88 Ticket-based authentication
POP3 110 Mail retrieval
NTP 123 Time sync
IMAP 143 Mail retrieval
SNMP 161/162 Monitoring/traps
LDAP 389 Directory access
HTTPS 443 TLS-protected web
SMB/CIFS 445 Windows file sharing
LDAPS 636 LDAP over TLS
RDP 3389 Windows remote desktop
Syslog 514 Often UDP, can be secured separately

Crypto distinctions

Concept Use
Hashing Integrity; one-way digest
Salting Defends against precomputed password hash tables
Symmetric encryption Fast encryption with one shared secret key
Asymmetric encryption Public/private key pair; key exchange, signatures
Digital signature Integrity, authentication, non-repudiation
Certificate Binds public key to subject identity
HSM Hardware protection for cryptographic keys
Perfect forward secrecy Past sessions remain protected even if long-term key is later compromised

Authentication factors

Factor Example
Something you know Password, PIN
Something you have Smart card, hardware token, phone authenticator app
Something you are Fingerprint, face, iris
Somewhere you are Location-based conditional access
Something you do Behavioral pattern, typing cadence

Identity tokens

Item Main purpose Common mistake
SAML assertion Federated enterprise identity claim Trusting unsigned or wrong signed XML element
OAuth access token API authorization to resources/scopes Treating it as proof of user authentication
OIDC ID token Authentication claims about user/session Failing to validate issuer/audience/signature/expiry
Refresh token Get new access tokens Storing it in unsafe browser-accessible locations

API authorization failures

Failure Symptom Fix pattern
BOLA / IDOR Change object ID and see another user's object Server-side object ownership/permission check on every object access
BFLA Normal user calls admin-only function Enforce role/scope permissions on every function/API route
Excessive data exposure API returns more fields than UI shows Server-side response filtering and schema review
Unrestricted resource use Expensive calls cause cost/DoS Rate limits, quotas, authentication, bounded queries

Cloud-native controls

Control Best use Caveat
CSPM Find risky cloud configuration Does not protect runtime by itself
CWPP Protect workloads at runtime Needs tuning and coverage
Admission policy Prevent unsafe Kubernetes objects Only works for API-created/updated resources
NetworkPolicy Limit pod traffic Requires enforcing CNI plugin
Image signing Verify artifact source/integrity Needs policy enforcement, not just signatures sitting around
Secrets manager Centralize/audit/rotate secrets Still must solve secret-zero/workload identity

Known content-quality note

Across all 201 questions, the correct answer is disproportionately "A": 186 A / 11 B / 4 C / 0 D (93% A). This wasn't caught before the first publish. It's a real weakness for practice purposes — a test-taker could learn "guess A" instead of the material. Not fixed here (reshuffling correct-answer position across 200 questions without breaking the Q/A correspondence needs care), but flagged so it isn't mistaken for a reliable practice signal. If you want this fixed, say so and it can be done as a dedicated pass.


Bank in progress — Domain 5 is partial as of 2026-07-10 (Q121-123 only) and will be extended.