SY0-701Free Study Guide

CompTIA Security+ SY0-701The Complete Beginner's Guide

Complete Security+ SY0-701 study guide — 212 chapters covering all 5 exam domains with real-world examples, exam traps, and practice questions.

212 chapters
~88 hours total read
Free — no signup required

How to use this guide

This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.

① Read a chapter② Answer practice questions③ Review missed answers④ Repeat
Study Chapters

212 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.

Start Chapter 1
Practice Questions

Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.

Go to practice test
Glossary

Every SY0-701term defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.

Browse glossary
Exam Overview

Exam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.

View exam guide

General Security Concepts (12%)

26 chapters

Domain overview
1

Security Controls

Objective 1.1 · General Security Concepts

25m
2

Cryptography Fundamentals

Objective 1.4 · General Security Concepts

25m
3

PKI and Digital Certificates

Objective 1.4 · General Security Concepts

25m
4

Hashing Algorithms

Objective 1.4 · General Security Concepts

25m
5

Symmetric vs Asymmetric Encryption

Objective 1.4 · General Security Concepts

25m
6

Authentication Methods

Objective 1.2 · General Security Concepts

25m
7

Multi-Factor Authentication (MFA)

Objective 1.2 · General Security Concepts

25m
8

Zero Trust Architecture

Objective 1.2 · General Security Concepts

25m
48

Access Control Models (DAC, MAC, RBAC)

Objective 1.1 · General Security Concepts

25m
49

CIA Triad — Confidentiality, Integrity, Availability

Objective 1.1 · General Security Concepts

25m
50

Non-Repudiation and Digital Signatures

Objective 1.1 · General Security Concepts

25m
51

Kerberos Authentication Protocol

Objective 1.2 · General Security Concepts

25m
52

LDAP, RADIUS, and TACACS+ for Auth

Objective 1.2 · General Security Concepts

25m
53

Biometric Authentication Types

Objective 1.2 · General Security Concepts

25m
54

SSO, SAML, and OAuth 2.0

Objective 1.2 · General Security Concepts

25m
55

Cryptographic Key Management

Objective 1.4 · General Security Concepts

25m
56

Certificate Lifecycle Management

Objective 1.4 · General Security Concepts

25m
57

CRL and OCSP — Certificate Revocation

Objective 1.4 · General Security Concepts

25m
58

Hardware Security Modules (HSM)

Objective 1.4 · General Security Concepts

25m
59

Secure Network Protocols (HTTPS, SFTP, SRTP)

Objective 1.4 · General Security Concepts

25m
60

Obfuscation and Steganography

Objective 1.4 · General Security Concepts

25m
61

Deception Technologies and Honeypots

Objective 1.1 · General Security Concepts

25m
62

Security Gap Analysis

Objective 1.1 · General Security Concepts

25m
63

Change Management in Security

Objective 1.1 · General Security Concepts

25m
64

Security Baselines and Benchmarks

Objective 1.1 · General Security Concepts

25m
65

Open vs Closed Security Systems

Objective 1.1 · General Security Concepts

25m

Threats, Vulnerabilities & Mitigations (22%)

49 chapters

Domain overview
9

Malware Types and Characteristics

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
10

Social Engineering Attacks

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
11

Phishing, Vishing, and Smishing

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
12

Application Attacks: SQL Injection, XSS

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
13

Network-Based Attacks

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
14

DoS and DDoS Attacks

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
15

Vulnerability Scanning and Assessment

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
16

Threat Intelligence and Indicators of Compromise

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
17

Password Attacks

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
18

Insider Threats

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
19

Ransomware Attacks

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
66

Advanced Persistent Threats (APT)

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
67

Supply Chain Attacks

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
68

Zero-Day Vulnerabilities

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
69

Business Email Compromise (BEC)

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
70

Credential Stuffing Attacks

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
71

Man-in-the-Middle Attacks

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
72

Session Hijacking and Fixation

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
73

Replay Attacks and Prevention

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
74

Pass-the-Hash and Pass-the-Ticket

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
75

Lateral Movement Techniques

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
76

Privilege Escalation Attacks

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
77

Rootkits and Bootkits

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
78

Fileless Malware Attacks

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
79

Cryptojacking and Resource Abuse

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
80

Botnets and Command-and-Control (C2)

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
81

Watering Hole Attacks

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
82

ICS and SCADA Security Threats

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
83

IoT Security Vulnerabilities

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
84

Wireless Network Attacks (Evil Twin, WPS)

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
85

Bluetooth Attacks (Bluejacking, Bluesnarfing)

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
86

Physical Security Attacks

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
87

Typosquatting and Domain Hijacking

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
88

Deepfakes and AI-Powered Attacks

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
89

Threat Actor Types and Motivations

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
90

Threat Hunting Methodology

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
91

Penetration Testing Types (Black/White/Grey Box)

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
92

Buffer Overflow Vulnerabilities

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
93

XML Injection and XXE Attacks

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
94

Injection Attacks Overview

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
95

Insecure Deserialization Attacks

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
96

Race Condition Vulnerabilities

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
97

Spyware and Adware

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
98

RFID and NFC Security Attacks

Objective 2.3 · Threats Vulnerabilities Mitigations

25m
99

Shoulder Surfing and Dumpster Diving

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
100

Tailgating and Piggybacking

Objective 2.2 · Threats Vulnerabilities Mitigations

25m
101

Drive-By Downloads

Objective 2.4 · Threats Vulnerabilities Mitigations

25m
102

CVEs, CVSS Scoring, and NVD

Objective 2.1 · Threats Vulnerabilities Mitigations

25m
103

Exploit Kits and Automated Attacks

Objective 2.4 · Threats Vulnerabilities Mitigations

25m

Security Architecture (18%)

38 chapters

Domain overview
20

Network Segmentation and Isolation

Objective 3.1 · Security Architecture

25m
21

Firewall Types and Deployment

Objective 3.1 · Security Architecture

25m
22

IDS vs IPS

Objective 3.1 · Security Architecture

25m
23

VPN Types and Protocols

Objective 3.3 · Security Architecture

25m
24

Cloud Security Fundamentals

Objective 3.6 · Security Architecture

25m
25

Virtualization and Container Security

Objective 3.6 · Security Architecture

25m
26

Secure Network Design Principles

Objective 3.1 · Security Architecture

25m
27

Data Protection and Encryption at Rest

Objective 3.5 · Security Architecture

25m
104

DMZ Architecture and Design

Objective 3.1 · Security Architecture

25m
105

Proxy Servers and Forward/Reverse Proxies

Objective 3.1 · Security Architecture

25m
106

Web Application Firewall (WAF)

Objective 3.1 · Security Architecture

25m
107

Unified Threat Management (UTM)

Objective 3.1 · Security Architecture

25m
108

Cloud Access Security Broker (CASB)

Objective 3.6 · Security Architecture

25m
109

SASE — Secure Access Service Edge

Objective 3.6 · Security Architecture

25m
110

Microsegmentation in Cloud and SDN

Objective 3.1 · Security Architecture

25m
111

Air-Gapped Networks

Objective 3.1 · Security Architecture

25m
112

Bastion Hosts and Jump Servers

Objective 3.1 · Security Architecture

25m
113

Cloud-Native Security Architecture

Objective 3.6 · Security Architecture

25m
114

Container and Kubernetes Security

Objective 3.6 · Security Architecture

25m
115

Serverless Security Considerations

Objective 3.6 · Security Architecture

25m
116

Infrastructure as Code Security

Objective 3.6 · Security Architecture

25m
117

API Security — OAuth, JWT, Rate Limiting

Objective 3.1 · Security Architecture

25m
118

Data Loss Prevention (DLP)

Objective 3.5 · Security Architecture

25m
119

Digital Rights Management (DRM)

Objective 3.5 · Security Architecture

25m
120

Secure Backup and Recovery Architecture

Objective 3.5 · Security Architecture

25m
121

Redundancy and Resilience Strategies

Objective 3.4 · Security Architecture

25m
122

High Availability Clustering

Objective 3.4 · Security Architecture

25m
123

Geographic Redundancy and Replication

Objective 3.4 · Security Architecture

25m
124

Disaster Recovery Tiers (RTO and RPO)

Objective 3.4 · Security Architecture

25m
125

Third-Party Risk in Architecture

Objective 3.2 · Security Architecture

25m
126

Secure Baseline Configurations

Objective 3.2 · Security Architecture

25m
127

NAT and Firewall Rule Design

Objective 3.1 · Security Architecture

25m
128

Load Balancer Security Considerations

Objective 3.1 · Security Architecture

25m
129

Software-Defined Networking Security

Objective 3.1 · Security Architecture

25m
130

Cloud IAM and Identity Architecture

Objective 3.6 · Security Architecture

25m
131

Secure Software Design Principles

Objective 3.2 · Security Architecture

25m
132

Supply Chain Risk Architecture

Objective 3.2 · Security Architecture

25m
133

Honeynet Deployment and Design

Objective 3.1 · Security Architecture

25m

Security Operations (28%)

64 chapters

Domain overview
28

Identity and Access Management

Objective 4.6 · Security Operations

25m
29

Privileged Access Management

Objective 4.6 · Security Operations

25m
30

Incident Response Process

Objective 4.8 · Security Operations

25m
31

Log Monitoring and SIEM

Objective 4.9 · Security Operations

18m
32

Endpoint Detection and Response (EDR)

Objective 4.5 · Security Operations

25m
33

System and OS Hardening

Objective 4.1 · Security Operations

25m
34

Patch and Vulnerability Management

Objective 4.1 · Security Operations

25m
35

Digital Forensics Basics

Objective 4.8 · Security Operations

25m
36

Wireless Security Protocols

Objective 4.4 · Security Operations

25m
37

Email Security (SPF, DKIM, DMARC)

Objective 4.4 · Security Operations

25m
38

Mobile Device Security

Objective 4.5 · Security Operations

25m
39

Physical Security Controls

Objective 4.1 · Security Operations

25m
134

User Provisioning and De-provisioning

Objective 4.6 · Security Operations

25m
135

Account Lifecycle Management

Objective 4.6 · Security Operations

25m
136

Directory Services — Active Directory

Objective 4.6 · Security Operations

25m
137

Federated Identity Management

Objective 4.6 · Security Operations

25m
138

Behavioral Analytics in Security

Objective 4.9 · Security Operations

25m
139

UEBA — User and Entity Behavior Analytics

Objective 4.9 · Security Operations

25m
140

Alert Triage and Investigation

Objective 4.8 · Security Operations

25m
141

False Positive Management and Tuning

Objective 4.9 · Security Operations

25m
142

XDR — Extended Detection and Response

Objective 4.9 · Security Operations

25m
143

SOAR — Security Orchestration Automation

Objective 4.9 · Security Operations

25m
144

Chain of Custody in Digital Forensics

Objective 4.8 · Security Operations

25m
145

Memory Forensics Techniques

Objective 4.8 · Security Operations

25m
146

Disk Forensics and Imaging

Objective 4.8 · Security Operations

25m
147

Network Forensics and Packet Analysis

Objective 4.8 · Security Operations

25m
148

Windows Event Log Analysis

Objective 4.9 · Security Operations

25m
149

Linux Syslog and Journal Analysis

Objective 4.9 · Security Operations

25m
150

Indicators of Compromise vs Attack (IOC/IOA)

Objective 4.9 · Security Operations

25m
151

Threat Sharing — MISP, STIX, TAXII

Objective 4.9 · Security Operations

25m
152

Vulnerability Management Lifecycle

Objective 4.1 · Security Operations

25m
153

Vulnerability Remediation Prioritization

Objective 4.1 · Security Operations

25m
154

Application Whitelisting and Control

Objective 4.1 · Security Operations

25m
155

Hardening Windows Systems

Objective 4.1 · Security Operations

25m
156

Hardening Linux Systems

Objective 4.1 · Security Operations

25m
157

Hardening Network Devices

Objective 4.1 · Security Operations

25m
158

Mobile Device Management (MDM/MAM)

Objective 4.5 · Security Operations

25m
159

Container Hardening Best Practices

Objective 4.1 · Security Operations

25m
160

Cloud Workload Protection

Objective 4.5 · Security Operations

25m
161

DNS Filtering and Sinkholing

Objective 4.4 · Security Operations

25m
162

Web Proxy Security Controls

Objective 4.4 · Security Operations

25m
163

Email Security — DMARC, Advanced Threats

Objective 4.4 · Security Operations

25m
164

Data Exfiltration Detection

Objective 4.9 · Security Operations

25m
165

File Integrity Monitoring (FIM)

Objective 4.9 · Security Operations

25m
166

Network Access Control (NAC)

Objective 4.4 · Security Operations

25m
167

Incident Containment Strategies

Objective 4.8 · Security Operations

25m
168

Incident Eradication and Recovery

Objective 4.8 · Security Operations

25m
169

Post-Incident Review and Lessons Learned

Objective 4.8 · Security Operations

25m
170

Threat Modeling — STRIDE and PASTA

Objective 4.1 · Security Operations

25m
171

Red Team vs Blue Team Operations

Objective 4.1 · Security Operations

25m
172

Purple Team Operations

Objective 4.1 · Security Operations

25m
173

Bug Bounty Programs

Objective 4.1 · Security Operations

25m
174

Secure Coding Practices (OWASP)

Objective 4.2 · Security Operations

25m
175

Security Code Review

Objective 4.2 · Security Operations

25m
176

DevSecOps — Security in DevOps Pipelines

Objective 4.2 · Security Operations

25m
177

Cryptographic Operations in SOC

Objective 4.7 · Security Operations

25m
178

Key Escrow and Recovery

Objective 4.7 · Security Operations

25m
179

Certificate Pinning and Transparency

Objective 4.7 · Security Operations

25m
180

DNSSEC and DNS Security

Objective 4.4 · Security Operations

25m
181

Endpoint Privilege Management

Objective 4.5 · Security Operations

25m
182

OT/IT Convergence Security

Objective 4.5 · Security Operations

25m
183

Embedded System and Firmware Security

Objective 4.5 · Security Operations

25m
184

SOC Tool Stack Overview

Objective 4.9 · Security Operations

25m
185

Security Metrics and KPIs

Objective 4.9 · Security Operations

25m

Security Program Management & Oversight (20%)

35 chapters

Domain overview
40

Risk Management Concepts

Objective 5.2 · Security Program Management

25m
41

Risk Assessment and Analysis

Objective 5.2 · Security Program Management

25m
42

Compliance and Regulatory Frameworks

Objective 5.4 · Security Program Management

18m
43

GDPR, HIPAA, and PCI-DSS

Objective 5.4 · Security Program Management

25m
44

Security Policies and Procedures

Objective 5.1 · Security Program Management

25m
45

Security Awareness Training

Objective 5.6 · Security Program Management

25m
46

Business Continuity and Disaster Recovery

Objective 5.3 · Security Program Management

25m
47

Data Classification and Privacy

Objective 5.5 · Security Program Management

25m
186

Quantitative vs Qualitative Risk Analysis

Objective 5.2 · Security Program Management

25m
187

Risk Register Management

Objective 5.2 · Security Program Management

25m
188

Risk Treatment — Accept, Avoid, Transfer, Mitigate

Objective 5.2 · Security Program Management

25m
189

Third-Party Risk Assessment

Objective 5.4 · Security Program Management

25m
190

Vendor Due Diligence in Security

Objective 5.4 · Security Program Management

25m
191

Contractual Security Requirements

Objective 5.4 · Security Program Management

25m
192

Privacy by Design Principles

Objective 5.5 · Security Program Management

25m
193

Data Subject Rights under Privacy Law

Objective 5.5 · Security Program Management

25m
194

Data Retention and Destruction Policies

Objective 5.5 · Security Program Management

25m
195

Data Breach Notification Requirements

Objective 5.5 · Security Program Management

25m
196

Legal Holds and e-Discovery

Objective 5.5 · Security Program Management

25m
197

Information Security Governance

Objective 5.1 · Security Program Management

25m
198

NIST CSF and Security Frameworks

Objective 5.1 · Security Program Management

25m
199

ISO 27001 and ISMS Overview

Objective 5.1 · Security Program Management

25m
200

SOC 2 and FedRAMP Compliance

Objective 5.4 · Security Program Management

25m
201

Phishing Simulations and Awareness

Objective 5.6 · Security Program Management

25m
202

Tabletop Exercises and Simulations

Objective 5.3 · Security Program Management

25m
203

Business Impact Analysis (BIA)

Objective 5.3 · Security Program Management

25m
204

Business Continuity Testing

Objective 5.3 · Security Program Management

25m
205

Executive Security Reporting and Dashboards

Objective 5.1 · Security Program Management

25m
206

Insider Threat Program Management

Objective 5.6 · Security Program Management

25m
207

Security Budget and ROI Justification

Objective 5.1 · Security Program Management

25m
208

Regulatory Investigations and Enforcement

Objective 5.4 · Security Program Management

25m
209

Security SLAs and MSSPs

Objective 5.4 · Security Program Management

25m
210

System Certification and Accreditation

Objective 5.1 · Security Program Management

25m
211

NIST Risk Management Framework (RMF)

Objective 5.2 · Security Program Management

25m
212

Security Automation in Programs

Objective 5.1 · Security Program Management

25m

Ready to test your knowledge?

Free SY0-701 practice questions with full explanations. Test what you learn chapter by chapter.

SY0-701 Practice Questions