Quick Answer
General Security Concepts covers the foundational principles of cybersecurity, including the CIA triad, risk management, security controls, and threat types, which are tested through scenario-based questions on the SY0-701 exam.
General Security Concepts is the foundational domain of the CompTIA Security+ SY0-701 exam, covering the core principles that underpin all of cybersecurity. In plain English, this domain teaches you the 'why' behind security—why we need confidentiality, integrity, and availability (the CIA triad), how to manage risk, and what controls (like firewalls, encryption, or policies) actually do. It’s like learning the rules of the road before driving: you’ll understand threats, vulnerabilities, and the mindset to protect data and systems.
This domain is critical for real-world IT, security, and cloud work because every security decision—from configuring a cloud bucket to responding to a breach—starts with these concepts. For example, when you set up AWS S3 permissions, you’re applying the principle of least privilege. When you patch a server, you’re reducing risk. Understanding these fundamentals helps you communicate with stakeholders, justify security spending, and avoid common mistakes that lead to data leaks. Employers expect you to think like a security professional, not just a technician.
On the SY0-701 exam, this domain tests your ability to define and apply security concepts across scenarios. You’ll be asked to identify which control (deterrent, preventive, detective, corrective, compensating, directive) fits a given situation—like a security guard (deterrent) vs. an IDS (detective). You’ll also need to understand risk management terms (likelihood, impact, RPO, RTO), types of threats (malware, social engineering, supply chain), and the difference between vulnerability and threat. Expect multiple-choice questions that give a short scenario and ask for the best control or concept.
To study this domain effectively, focus on memorizing the definitions and then applying them to practice questions. Start with the CIA triad and non-repudiation. Then learn the control types by creating mnemonics (e.g., 'Prevent, Detect, Correct'). Use flashcards for terms like 'vulnerability' vs. 'threat' vs. 'risk'. Finally, practice with scenario-based questions from CompTIA’s official study materials or a reputable test bank. Don’t just read—quiz yourself daily. This domain is 12% of the exam, so you need to master it, but it’s also the easiest to score high on if you practice.
What the exam tests
Common exam traps
Security Controls
Objective 1.1 · General Security Concepts
Cryptography Fundamentals
Objective 1.4 · General Security Concepts
PKI and Digital Certificates
Objective 1.4 · General Security Concepts
Hashing Algorithms
Objective 1.4 · General Security Concepts
Symmetric vs Asymmetric Encryption
Objective 1.4 · General Security Concepts
Authentication Methods
Objective 1.2 · General Security Concepts
Multi-Factor Authentication (MFA)
Objective 1.2 · General Security Concepts
Zero Trust Architecture
Objective 1.2 · General Security Concepts
Access Control Models (DAC, MAC, RBAC)
Objective 1.1 · General Security Concepts
CIA Triad — Confidentiality, Integrity, Availability
Objective 1.1 · General Security Concepts
Non-Repudiation and Digital Signatures
Objective 1.1 · General Security Concepts
Kerberos Authentication Protocol
Objective 1.2 · General Security Concepts
LDAP, RADIUS, and TACACS+ for Auth
Objective 1.2 · General Security Concepts
Biometric Authentication Types
Objective 1.2 · General Security Concepts
SSO, SAML, and OAuth 2.0
Objective 1.2 · General Security Concepts
Cryptographic Key Management
Objective 1.4 · General Security Concepts
Certificate Lifecycle Management
Objective 1.4 · General Security Concepts
CRL and OCSP — Certificate Revocation
Objective 1.4 · General Security Concepts
Hardware Security Modules (HSM)
Objective 1.4 · General Security Concepts
Secure Network Protocols (HTTPS, SFTP, SRTP)
Objective 1.4 · General Security Concepts
Obfuscation and Steganography
Objective 1.4 · General Security Concepts
Deception Technologies and Honeypots
Objective 1.1 · General Security Concepts
Security Gap Analysis
Objective 1.1 · General Security Concepts
Change Management in Security
Objective 1.1 · General Security Concepts
Security Baselines and Benchmarks
Objective 1.1 · General Security Concepts
Open vs Closed Security Systems
Objective 1.1 · General Security Concepts
Free SY0-701 practice questions with full explanations. Test what you learn chapter by chapter.
SY0-701 Practice Questions