Free CompTIA Security+ Exam Flashcards

Memorize 50 essential terms and definitions for the CompTIA Security+ Certification (SY0-701). See the term, recall the definition, then flip to check yourself.

50 Flashcards
10 Topics
100% Free
TermClick to flip

Phishing

Tap to reveal definition
Card 1 of 50Threats & Attacks

Filter by Topic

Jump to Card

About These CompTIA Security+ Flashcards

These 50 flashcards are designed to help you memorize key terms and definitions for the CompTIA Security+ Certification (SY0-701). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.

Topics Covered

Threats & Attacks8 cards
Cryptography6 cards
Identity & Access6 cards
Network Security6 cards
Security Operations6 cards
Governance5 cards
Architecture5 cards
Endpoint Security4 cards
Physical Security2 cards
Wireless Security2 cards

Complete Flashcard Reference

Review every term in this set. Open any term to reveal its definition.

Phishing

Social engineering attack using fraudulent emails/messages to trick users into revealing credentials or installing malware. Variants: Spear phishing (targeted), Whaling (executives), Vishing (voice), Smishing (SMS). Defense: user training, email filtering.

Ransomware

Malware that encrypts victim's data and demands payment for decryption key. Spreads via phishing, RDP, vulnerabilities. Prevention: backups (3-2-1 rule), patching, user training, endpoint protection. Never guarantee recovery if paid.

SQL Injection

Attack inserting malicious SQL code through user input to manipulate databases. Can extract, modify, or delete data. Prevention: parameterized queries, input validation, least privilege database accounts, WAF.

Cross-Site Scripting (XSS)

Injecting malicious scripts into web pages viewed by other users. Types: Stored (persistent), Reflected (non-persistent), DOM-based. Steals cookies, sessions, credentials. Prevention: input validation, output encoding, CSP.

Man-in-the-Middle (MITM)

Attacker secretly intercepts and possibly alters communication between two parties. Can capture credentials, inject malware. Prevention: encryption (HTTPS, VPN), certificate validation, HSTS.

DDoS (Distributed Denial of Service)

Overwhelming target with traffic from multiple sources to disrupt service. Types: volumetric (bandwidth), protocol (SYN flood), application layer (HTTP flood). Mitigation: CDN, rate limiting, DDoS protection services.

Zero-Day

Attack exploiting unknown vulnerability before patch is available. Extremely dangerous—no signature for detection. Mitigation: defense in depth, behavior-based detection, least privilege, network segmentation.

Password Attacks

Brute force: try all combinations. Dictionary: try common words/passwords. Rainbow table: precomputed hash lookup. Password spraying: few passwords against many accounts. Prevention: strong passwords, MFA, account lockout, salted hashes.

Symmetric Encryption

Same key for encryption and decryption. Fast, efficient for large data. Algorithms: AES (preferred, 128/256-bit), 3DES (legacy), Blowfish. Challenge: secure key distribution. Used for: data at rest, VPNs, disk encryption.

Asymmetric Encryption

Public/private key pair. Public encrypts, private decrypts (or vice versa for signing). Slower than symmetric. Algorithms: RSA, ECC, Diffie-Hellman. Used for: key exchange, digital signatures, PKI.

Hashing

One-way function producing fixed-length digest. Cannot reverse to original data. Used for: integrity verification, password storage. Algorithms: SHA-256 (recommended), SHA-3, MD5/SHA-1 (deprecated). Collisions are a concern.

Digital Signature

Proves authenticity and integrity. Process: hash message, encrypt hash with private key. Recipient decrypts with public key, compares hashes. Provides: authentication, integrity, non-repudiation.

PKI (Public Key Infrastructure)

Framework for managing digital certificates and keys. Components: CA (Certificate Authority), RA (Registration Authority), certificates, CRL/OCSP (revocation). Enables secure communication and authentication.

TLS (Transport Layer Security)

Protocol securing network communications. Replaces SSL. Provides: encryption, integrity, authentication. Uses: asymmetric for key exchange, symmetric for data. TLS 1.2/1.3 current standards. Basis for HTTPS.

Authentication Factors

Something you know (password, PIN). Something you have (token, smart card, phone). Something you are (biometrics). Somewhere you are (location). Something you do (behavior). MFA combines multiple factors.

Single Sign-On (SSO)

One authentication grants access to multiple systems. Improves user experience, reduces password fatigue. Protocols: SAML, OAuth, OpenID Connect. Risk: compromised credentials affect all systems.

LDAP (Lightweight Directory Access Protocol)

Protocol for accessing directory services. Stores user/computer info. Active Directory uses LDAP. Port 389 (unencrypted), 636 (LDAPS). Used for centralized authentication and authorization.

Access Control Models

DAC (Discretionary): Owner controls access. MAC (Mandatory): Labels/clearances, strict hierarchy. RBAC (Role-Based): Access by job role. ABAC (Attribute-Based): Multiple attributes determine access.

Least Privilege

Users and systems get minimum permissions needed for their function. Reduces attack surface and damage from compromise. Regularly review and revoke unnecessary access. Core security principle.

Federation

Trust relationship between organizations allowing users to access resources across domains. Uses: SAML, OAuth. Example: using Google account to log into third-party site. Enables B2B and cloud access.

Firewall Types

Packet filtering: examines headers (Layer 3-4). Stateful: tracks connection state. Application/proxy: inspects content (Layer 7). NGFW: combines features + IPS, DPI, application awareness. WAF: protects web apps.

IDS vs IPS

IDS (Intrusion Detection): monitors and alerts on suspicious activity, passive. IPS (Intrusion Prevention): monitors and blocks attacks, inline/active. Detection methods: signature-based, anomaly-based, heuristic.

VPN (Virtual Private Network)

Encrypted tunnel over public network. Types: Site-to-site (between networks), Remote access (individual users). Protocols: IPsec (network layer), SSL/TLS VPN (transport layer), WireGuard. Provides confidentiality and integrity.

Network Segmentation

Dividing network into smaller zones with controlled access between them. Limits lateral movement if breached. Implementations: VLANs, subnets, firewalls, microsegmentation. Zero trust assumes breach.

DMZ (Demilitarized Zone)

Network segment between internal network and internet. Hosts public-facing services (web, email, DNS). Protected by firewalls on both sides. Compromised DMZ server can't directly access internal network.

NAC (Network Access Control)

Controls device access to network based on compliance. Checks: antivirus status, patches, configuration. Non-compliant devices quarantined or remediated. 802.1X for port-based authentication.

SIEM (Security Information and Event Management)

Centralized log collection, correlation, and analysis. Provides real-time alerts, dashboards, forensics. Aggregates logs from firewalls, servers, endpoints. Key for incident detection and compliance.

Vulnerability Scanning

Automated discovery of security weaknesses. Types: credentialed (authenticated, more thorough), non-credentialed. Scan regularly, prioritize by severity (CVSS). Tools: Nessus, Qualys, OpenVAS. Different from penetration testing.

Penetration Testing

Authorized simulated attack to find vulnerabilities. Types: black box (no info), white box (full info), gray box (partial). Steps: recon, scanning, exploitation, post-exploitation, reporting. Get written authorization.

Incident Response Steps

1) Preparation (plans, tools, training). 2) Identification (detect, verify). 3) Containment (limit damage). 4) Eradication (remove threat). 5) Recovery (restore systems). 6) Lessons learned (improve). Document everything.

Chain of Custody

Documentation tracking who handled evidence, when, and what was done. Essential for legal proceedings. Includes: date/time, handler name, action taken, storage location. Maintain integrity of evidence.

Business Continuity vs Disaster Recovery

BC: keeping business running during disruption (alternate sites, processes). DR: restoring IT systems after disaster. RPO: acceptable data loss. RTO: acceptable downtime. Both require planning and testing.

Risk Assessment

Identifying and evaluating risks. Formula: Risk = Threat × Vulnerability × Impact. Qualitative: high/medium/low ratings. Quantitative: dollar values (ALE = ARO × SLE). Informs security investments.

Risk Responses

Avoid: eliminate risk by removing activity. Mitigate: reduce likelihood or impact with controls. Transfer: shift risk to third party (insurance, contracts). Accept: acknowledge and document risk. No response = negligence.

Security Frameworks

NIST: comprehensive US government framework. CIS Controls: prioritized security actions. ISO 27001: international standard, certifiable. COBIT: IT governance. Use frameworks to structure security programs.

Regulations

HIPAA: healthcare data. PCI DSS: payment cards. GDPR: EU personal data. SOX: financial reporting. FERPA: student records. Non-compliance can result in fines, legal action, reputation damage.

Data Classification

Categorizing data by sensitivity. Government: Top Secret, Secret, Confidential, Unclassified. Corporate: Confidential, Private, Sensitive, Public. Determines handling, storage, access controls required.

Defense in Depth

Multiple layers of security controls. If one fails, others provide protection. Layers: physical, network, host, application, data. No single point of failure. Assume each layer may be bypassed.

Zero Trust

Security model assuming no implicit trust. 'Never trust, always verify.' Verify identity, device health, context for every access request. Microsegmentation, least privilege, continuous validation.

Cloud Security

Shared responsibility model: cloud provider secures infrastructure, customer secures data/config. Concerns: data sovereignty, multi-tenancy, API security. Tools: CASB, CSPM. Encrypt data, manage access carefully.

Virtualization Security

Concerns: VM escape (breaking out to hypervisor), VM sprawl (unmanaged VMs), resource contention. Controls: patch hypervisors, isolate networks, secure VM templates, monitor activity.

Secure Coding Practices

Input validation, output encoding, parameterized queries, error handling (no sensitive info in errors), secure authentication, encryption of sensitive data, principle of least privilege. OWASP Top 10 as guide.

EDR (Endpoint Detection and Response)

Advanced endpoint security with continuous monitoring, threat detection, and response capabilities. Records endpoint activity, uses behavioral analysis, enables investigation and remediation. Beyond traditional AV.

DLP (Data Loss Prevention)

Prevents unauthorized data transfer. Types: network (monitor traffic), endpoint (control USB, email), cloud (SaaS visibility). Identifies sensitive data via patterns, keywords, classification. Can block, alert, encrypt.

Host-Based Firewall

Firewall running on individual computer. Controls inbound/outbound traffic per application. Windows Defender Firewall, iptables (Linux). Defense in depth—protects even on internal network.

Hardening

Reducing attack surface. Disable unnecessary services/ports, remove unused software, apply patches, strong configurations, disable default accounts. Use security benchmarks (CIS). Regular audits.

Physical Security Controls

Deterrent: signs, guards. Preventive: locks, mantraps, fencing. Detective: cameras, motion sensors, alarms. Compensating: backup controls when primary fails. Layer physical and logical security.

Environmental Controls

HVAC: temperature/humidity control for equipment. Fire suppression: FM-200, CO2, water (sprinklers). UPS: battery backup for short outages. Generator: extended power outages. Monitor and maintain.

Wireless Security Protocols

WEP: deprecated, easily cracked (IV weakness). WPA: TKIP, improved but vulnerable. WPA2: AES-CCMP, current minimum standard. WPA3: SAE (resistant to offline attacks), required for WiFi 6 certification.

Wireless Attacks

Evil twin: rogue AP mimicking legitimate. Deauthentication: forcing clients to reconnect (capture handshake). WPS attack: brute force PIN. Jamming: disrupting signal. Defense: strong encryption, disable WPS, monitor for rogues.

Frequently Asked Questions

What is the CompTIA Security+ passing score?

The CompTIA Security+ passing score is 750 on a 100-900 scale. Because CompTIA uses scaled scoring and performance-based questions, do not treat this as a simple raw percentage. Use practice results by domain to decide what to review next.

How hard is the CompTIA Security+ exam?

CompTIA Security+ (SY0-701) is moderately challenging because it mixes security vocabulary with applied scenarios. The exam includes up to 90 multiple-choice and performance-based questions in 90 minutes. Prior networking knowledge helps, but candidates still need practice with logs, access control, vulnerability prioritization, incident response, and governance scenarios.

How long should I study for Security+?

Most candidates should plan 90-150 hours, depending on networking background and hands-on security experience. CompTIA recommends Network+ knowledge and two years in a security or systems administrator role, but there are no formal prerequisites. Spend extra time on Security Operations and Threats/Vulnerabilities because they make up half the exam.

Is CompTIA Security+ worth it for government jobs?

Yes. CompTIA lists Security+ for multiple DoD 8140 work roles, including cyber defense analyst, incident responder, vulnerability analyst, security control assessor, system administrator, network specialist, systems planner, IT project manager, information security manager, and secure software assessor.

Which Security+ domains should I prioritize?

Prioritize Security Operations (28%) and Threats, Vulnerabilities, and Mitigations (22%) first because together they make up half the exam. Then cover Security Program Management and Oversight (20%), Security Architecture (18%), and General Security Concepts (12%). Use missed questions to rebalance your final review.

What is the Security+ retake policy and exam cost?

The standard U.S. Security+ exam voucher price is $425. If you fail, you can retake immediately with no waiting period for your second attempt. For a third attempt or subsequent retakes, you must wait at least 14 calendar days. There's no limit on retake attempts, but you pay the full voucher price each time. The certification is valid for 3 years and can be renewed through continuing education units (CEUs).

Same family resources

Explore More CompTIA Certifications

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.