Courseiva
SY0-701Exam Domain

Security Operations (28%)SY0-701 Study Guide

64 chapters
~1593 min total
Free — no signup required

Quick Answer

Security Operations tests your ability to detect, respond to, and recover from real-world security incidents. On the SY0-701 exam it covers incident response (NIST SP 800-61), vulnerability management, SIEM log analysis, data protection, and change management. It is worth 28% of your score — the highest-weighted domain.

Security Operations is the single largest domain on the SY0-701 exam at 28% — and the one most grounded in real-world analyst work.

This domain covers what a security team does every day: detecting threats through SIEM and IDS/IPS, running the incident response playbook, scanning and patching vulnerabilities, protecting data, and keeping change management locked down.

Exam questions are almost entirely scenario-based. You will be handed a situation — ransomware hits a file server, a SIEM alert fires at 2am, a critical CVE drops for a system you own — and asked what to do next, in what order, and with which tool.

The NIST SP 800-61 incident response lifecycle (Preparation → Detection and Analysis → Containment → Eradication and Recovery → Post-Incident Activity) appears on nearly every exam version. Treat it as a required memorisation.

What the exam tests

  • Incident response lifecycle — Preparation, Detection & Analysis, Containment, Eradication & Recovery, Post-Incident Activity (NIST SP 800-61). Know the exact order cold.
  • Vulnerability management — scan types, CVSS severity scoring, patch prioritisation, and the critical difference between a vulnerability scan and a penetration test.
  • Security monitoring — SIEM log correlation, IDS vs IPS placement and behaviour, alert triage, and separating true positives from false positives.
  • Identity and access management operations — enforcing MFA, detecting privilege escalation, account lockout policies, and least-privilege principles.
  • Data protection — encryption at rest vs in transit, DLP tool placement, data classification schemes, and secure data disposal methods.
  • Disaster recovery and business continuity — RTO vs RPO definitions, full/incremental/differential backup strategies, and failover testing.

Common exam traps

  • Containment comes before Eradication in incident response — reversing these two phases is the most common mistake on this domain.
  • A vulnerability scan identifies weaknesses; a penetration test actively exploits them. The exam expects you to know which is appropriate and when.
  • RTO is how fast you restore service; RPO is how much data loss you can tolerate. Mixing these up costs marks on scenario questions.
  • Not every SIEM alert is a real threat — the exam tests alert triage. Recognising false positives is a distinct skill from detecting real incidents.
  • IDS alerts and logs; IPS blocks. Placement also differs — IDS can be passive/out-of-band, IPS must be inline. Confusing them is a guaranteed wrong answer.

Security Operations (28%) Chapters

28

Identity and Access Management

Objective 4.6 · Security Operations

25m
29

Privileged Access Management

Objective 4.6 · Security Operations

25m
30

Incident Response Process

Objective 4.8 · Security Operations

25m
31

Log Monitoring and SIEM

Objective 4.9 · Security Operations

18m
32

Endpoint Detection and Response (EDR)

Objective 4.5 · Security Operations

25m
33

System and OS Hardening

Objective 4.1 · Security Operations

25m
34

Patch and Vulnerability Management

Objective 4.1 · Security Operations

25m
35

Digital Forensics Basics

Objective 4.8 · Security Operations

25m
36

Wireless Security Protocols

Objective 4.4 · Security Operations

25m
37

Email Security (SPF, DKIM, DMARC)

Objective 4.4 · Security Operations

25m
38

Mobile Device Security

Objective 4.5 · Security Operations

25m
39

Physical Security Controls

Objective 4.1 · Security Operations

25m
134

User Provisioning and De-provisioning

Objective 4.6 · Security Operations

25m
135

Account Lifecycle Management

Objective 4.6 · Security Operations

25m
136

Directory Services — Active Directory

Objective 4.6 · Security Operations

25m
137

Federated Identity Management

Objective 4.6 · Security Operations

25m
138

Behavioral Analytics in Security

Objective 4.9 · Security Operations

25m
139

UEBA — User and Entity Behavior Analytics

Objective 4.9 · Security Operations

25m
140

Alert Triage and Investigation

Objective 4.8 · Security Operations

25m
141

False Positive Management and Tuning

Objective 4.9 · Security Operations

25m
142

XDR — Extended Detection and Response

Objective 4.9 · Security Operations

25m
143

SOAR — Security Orchestration Automation

Objective 4.9 · Security Operations

25m
144

Chain of Custody in Digital Forensics

Objective 4.8 · Security Operations

25m
145

Memory Forensics Techniques

Objective 4.8 · Security Operations

25m
146

Disk Forensics and Imaging

Objective 4.8 · Security Operations

25m
147

Network Forensics and Packet Analysis

Objective 4.8 · Security Operations

25m
148

Windows Event Log Analysis

Objective 4.9 · Security Operations

25m
149

Linux Syslog and Journal Analysis

Objective 4.9 · Security Operations

25m
150

Indicators of Compromise vs Attack (IOC/IOA)

Objective 4.9 · Security Operations

25m
151

Threat Sharing — MISP, STIX, TAXII

Objective 4.9 · Security Operations

25m
152

Vulnerability Management Lifecycle

Objective 4.1 · Security Operations

25m
153

Vulnerability Remediation Prioritization

Objective 4.1 · Security Operations

25m
154

Application Whitelisting and Control

Objective 4.1 · Security Operations

25m
155

Hardening Windows Systems

Objective 4.1 · Security Operations

25m
156

Hardening Linux Systems

Objective 4.1 · Security Operations

25m
157

Hardening Network Devices

Objective 4.1 · Security Operations

25m
158

Mobile Device Management (MDM/MAM)

Objective 4.5 · Security Operations

25m
159

Container Hardening Best Practices

Objective 4.1 · Security Operations

25m
160

Cloud Workload Protection

Objective 4.5 · Security Operations

25m
161

DNS Filtering and Sinkholing

Objective 4.4 · Security Operations

25m
162

Web Proxy Security Controls

Objective 4.4 · Security Operations

25m
163

Email Security — DMARC, Advanced Threats

Objective 4.4 · Security Operations

25m
164

Data Exfiltration Detection

Objective 4.9 · Security Operations

25m
165

File Integrity Monitoring (FIM)

Objective 4.9 · Security Operations

25m
166

Network Access Control (NAC)

Objective 4.4 · Security Operations

25m
167

Incident Containment Strategies

Objective 4.8 · Security Operations

25m
168

Incident Eradication and Recovery

Objective 4.8 · Security Operations

25m
169

Post-Incident Review and Lessons Learned

Objective 4.8 · Security Operations

25m
170

Threat Modeling — STRIDE and PASTA

Objective 4.1 · Security Operations

25m
171

Red Team vs Blue Team Operations

Objective 4.1 · Security Operations

25m
172

Purple Team Operations

Objective 4.1 · Security Operations

25m
173

Bug Bounty Programs

Objective 4.1 · Security Operations

25m
174

Secure Coding Practices (OWASP)

Objective 4.2 · Security Operations

25m
175

Security Code Review

Objective 4.2 · Security Operations

25m
176

DevSecOps — Security in DevOps Pipelines

Objective 4.2 · Security Operations

25m
177

Cryptographic Operations in SOC

Objective 4.7 · Security Operations

25m
178

Key Escrow and Recovery

Objective 4.7 · Security Operations

25m
179

Certificate Pinning and Transparency

Objective 4.7 · Security Operations

25m
180

DNSSEC and DNS Security

Objective 4.4 · Security Operations

25m
181

Endpoint Privilege Management

Objective 4.5 · Security Operations

25m
182

OT/IT Convergence Security

Objective 4.5 · Security Operations

25m
183

Embedded System and Firmware Security

Objective 4.5 · Security Operations

25m
184

SOC Tool Stack Overview

Objective 4.9 · Security Operations

25m
185

Security Metrics and KPIs

Objective 4.9 · Security Operations

25m

Other SY0-701 Domains

Test your Security Operations (28%) knowledge

Free SY0-701 practice questions with full explanations. Test what you learn chapter by chapter.

SY0-701 Practice Questions