SY0-701 · Associate

CompTIA Security+

Build the security judgment to recognise threats, choose controls and respond with purpose.

Start Free

Your free account includes a full SY0-701 practice exam.

ExamNova practice

Your first session

Questions
90
Time limit
90 min
Coverage
5 domains

Practise, review your answers and see where to focus next.

Preview a question

Is SY0-701 your next step?

For learners developing a broad cybersecurity foundation. Security+ spans technical controls and operational decisions alongside risk, governance and communication.

Recognise threats and exposure

Connect attack behaviour and vulnerabilities to the risks they create and the controls that reduce them.

Design and operate securely

Work through identity, architecture, data protection, monitoring and incident response scenarios.

Make risk-informed decisions

Distinguish governance, compliance and risk-management activities by their practical purpose.

Official certification guide ↗

What you’ll study

Explore the domains and topics in your ExamNova study path.

General Security Concepts12% practice balance

Explore General Security Concepts

Compare and Contrast Various Types of Security Controls

  • Compensating and Corrective
  • Preventive
  • Directive and Detective
  • Deterrent
  • Control Categories Overview

Summarize Fundamental Security Concepts

  • Access Control and Authentication Methods
  • Authorization and CIA Triad
  • Confidential Computing and Defense in Depth
  • Least Privilege, Separation of Duties, and Non-Repudiation
  • Privacy by Design and Zero Trust

Explain the Importance of Change Management Processes and the Impact to Security

  • Change Approval and Impact Analysis
  • Backout Plan
  • Operational Procedures and Maintenance
  • Allow/Deny Lists and Dependencies
  • Version Control

Explain the Importance of Using Appropriate Cryptographic Solutions

  • Asymmetric and Symmetric Encryption
  • Transport Layer Security and Digital Signatures
  • Hashing Techniques and HSM Usage
  • Public Key Infrastructure and Key Management
  • Salting Techniques and TPM
  • Tokenization and Disk Encryption Methods
Threats, Vulnerabilities, and Mitigations22% practice balance

Explore Threats, Vulnerabilities, and Mitigations

Compare and Contrast Common Threat Actors and Motivations

  • Hacktivist and Internal Threats
  • External Threat Actors and Motivations
  • Nation-State Threats and Organized Crime
  • Resources and Capabilities of Threat Actors
  • Unskilled Attackers and Shadow IT

Explain Common Threat Vectors and Attack Surfaces

  • Social Engineering Attack Techniques
  • Business Email Compromise and Phishing
  • Spear Phishing and Whaling
  • Smishing and Vishing
  • Human-Centric Security Strategies

Explain Various Types of Vulnerabilities

  • API Authorization, Authentication, and SSRF Vulnerabilities
  • Client-Side XSS and Injection Vulnerabilities
  • Cloud Storage and Database Exposures
  • IoT Botnets and Edge Device Risk
  • Vulnerability Scanning and Penetration Testing
  • Serverless, Container, and Supply Chain Vulnerabilities

Given a Scenario, Analyze Indicators of Malicious Activity

  • APT, Fileless, and Evasive Malware Indicators
  • Ransomware Kill Chain and Extortion Indicators
  • Supply Chain, DDoS, and DNS Attack Indicators
  • IDS and IPs Response Indicators
  • MITM and Protocol Exploit Indicators
  • Scanning and Reconnaissance Indicators

Explain the Purpose of Mitigation Techniques Used to Secure the Enterprise

  • Access Control and Application Allow Listing
  • System Hardening and Patch Management
  • Network Segmentation and Configuration Enforcement
  • Data Protection Mechanisms
  • Continuous Monitoring Practices
Security Architecture18% practice balance

Explore Security Architecture

Compare and Contrast Security Implications of Different Architecture Models

  • Shared Responsibility Model
  • Cloud-Native Security Posture Management Tools
  • Multi-Cloud and Hybrid Cloud Security
  • Container Security in Orchestration Environments
  • Identity and Access Management Frameworks

Given a Scenario, Apply Security Principles to Secure Enterprise Infrastructure

  • Secure Software Development Practices
  • Endpoint Management, BYOD, and Device Posture
  • Endpoint Threat Prevention, Detection, and Response
  • Network Security and Access Control
  • SASE and Distributed Access Security
  • WAF Tuning and DevSecOps Application Controls
  • Network Segmentation and Zero Trust Principles

Compare and Contrast Concepts and Strategies to Protect Data

  • Data Loss Prevention Strategies
  • Data Masking and Anonymization Techniques
  • Data Residency and Sovereignty
  • Encryption Mechanisms Overview
  • Privacy Enhancing Technologies
  • Compliance and Data Protection Regulations

Explain the Importance of Resilience and Recovery in Security Architecture

  • Business Continuity and Disaster Recovery Planning
  • Recovery Objectives and Crisis Communication
  • Incident Response and Cyber Insurance
  • Resilience Frameworks and Training
  • Testing Resilience through Simulations
Security Operations28% practice balance

Explore Security Operations

Given a Scenario, Apply Common Security Techniques to Computing Resources

  • Application Hardening Techniques
  • Mobile Security Strategies
  • Establishing Secure Baselines
  • Wireless Network Protection
  • Configuration Management Practices

Explain the Security Implications of Proper Hardware, Software, and Data Asset Management

  • Asset Acquisition and Accounting Practices
  • Data Classification and Retention Policies
  • Asset Disposal and Inventory Management
  • Ownership Responsibilities and Data Sanitization
  • Asset Monitoring and Tracking Techniques

Explain Various Activities Associated with Vulnerability Management

  • Vulnerability Scanners and Continuous Monitoring
  • Automated Patch and Configuration Management
  • Vulnerability Prioritization and Risk Scoring
  • Attack Surface Management
  • Attack Surface Management and Exposure Discovery
  • Threat-Informed Vulnerability Prioritization and NAC Isolation

Explain Security Alerting and Monitoring Concepts and Tools

  • Centralized Logging and Analysis Techniques
  • User Behavior Analytics in Security Monitoring
  • Endpoint and Network Detection Tools
  • Security Information and Event Management
  • Automation in Security Monitoring

Given a Scenario, Modify Enterprise Capabilities to Enhance Security

  • CTI Planning and Lifecycle Basics
  • Operationalizing IOCs and TTPs
  • TIPs, Feeds, and STIX/TAXII
  • Threat Hunting and OSINT
  • MITRE ATT&CK Mapping

Given a Scenario, Implement and Maintain Identity and Access Management

  • ABAC and RBAC
  • Least Privilege
  • Authentication Methods and Security
  • Identity Federation and Single Sign-On
  • Privileged Access Management Practices

Explain the Importance of Automation and Orchestration Related to Secure Operations

  • Automation in Security Operations
  • Orchestration in Secure Environments
  • SOAR and Operational Efficiency
  • Managing Technical Debt in Security
  • Implementing Guardrails for Security Automation

Explain Appropriate Incident Response Activities

  • Incident Response Phases and Frameworks
  • Communication and Reporting in Incidents
  • Legal Considerations in Incident Response
  • Roles of Security Operations Center
  • Integrating SOAR in Incident Response
  • Threat Hunting in Incident Response

Given a Scenario, Use Data Sources to Support an Investigation

  • Digital Forensics Tools and Malware Analysis
  • Memory Forensics and Live System Analysis
  • Chain of Custody and Evidence Handling
  • Legal and Ethical Considerations in Digital Forensics
  • Types of Forensics and Their Applications
Security Program Management and Oversight20% practice balance

Explore Security Program Management and Oversight

Summarize Elements of Effective Security Governance

  • Security Governance Frameworks
  • Performance Measurement in Security
  • Legal Requirements and Data Classification
  • Stakeholder and Regulatory Reporting
  • Security Policies and Risk-Based Auditing
  • Continuous Compliance Monitoring and Automation
  • Threat Modeling and STRIDE Risk Analysis
  • Security Metrics, KPIs, and KRIs

Explain Elements of the Risk Management Process

  • Business Impact Analysis and Quantitative Vs. Qualitative Risk
  • Continuous Risk Assessment and Monitoring
  • Risk Management Frameworks
  • Governance and Compliance in Risk Management
  • Disaster Recovery and Resiliency Planning

Explain the Processes Associated with Third-Party Risk Assessment and Management

  • Third-Party Risk Assessment Processes
  • Vendor Due Diligence and Onboarding Reviews
  • Contract Clauses, Fourth-Party Risk, and Continuous Monitoring
  • Service Level Agreements in Security
  • Fourth-Party Risk Management
  • Supply Chain Cybersecurity Risks

Summarize Elements of Effective Security Compliance

  • Audit Trails, Logging, and Continuous Auditing
  • Internal and External Security Audits
  • Security Policy Development
  • Understanding Compliance Regulations
  • Impact Assessments for Compliance

Explain Types and Purposes of Audits and Assessments

  • SOC 2 and Compliance Audits
  • Internal Audit and External Audit
  • Assessment Methodologies and Approaches
  • Penetration Testing and Variants
  • Compliance and Audit Processes

Given a Scenario, Implement Security Awareness Practices

  • Gamified Training Design and Engagement
  • Training Metrics, Simulations, and Role-Specific Skills
  • Phishing Awareness and Simulation
  • Role-Based Security Education
  • Secure Development Practices Training
  • Platforms for Security Awareness Training

Percentages show ExamNova’s practice balance. Consult the official guide for the vendor’s current exam outline.

Try focused practice

Explore a topic with sample questions and explanations.

Try a question before you start.

Read the scenario. Consider your answer, then reveal the reasoning.

Pay attention to the role and stage of an incident in each scenario. The next appropriate action depends on both.

An insurance firm is deploying a new actuarial modeling system that processes large amounts of policyholder data. Using NIST RMF and a GRC platform, which initial phase focuses on establishing the security context by defining system boundaries, categorizing information, and determining impact levels?

  • Monitor
  • Assess
  • Prepare
  • Authorize
Show answer and explanations

Monitor — Monitor tracks security controls, changes, and risk posture after authorization. It maintains the security posture but does not establish the initial system context, boundaries, or information categorization.

Assess — Assess is used to determine whether controls are implemented correctly and operating as intended. It occurs after earlier RMF steps establish the system context and categorize the information.

Prepare — Prepare is the foundational RMF phase. It sets the risk management context, defines roles and system boundaries, categorizes the system and information it processes, and determines impact levels. GRC inventory and classification features support these activities.

Authorize — Authorize is the decision to grant or deny authorization to operate based on the implemented and assessed controls and residual risk. It comes after the system has been prepared, not before.

A clearer way to prepare.

One place to practise, understand your results and plan the next session.

Practise with purpose

Start with your free exam. Explore Exam, Endless and Custom practice modes as you build your study routine.

Understand the answer

Review the reasoning behind your answers and return to the decisions that need another look.

Find your next focus

Use domain-level performance and readiness to see strengths, gaps and areas you have yet to assess.

Put it into practice.

Explore hands-on tasks connected to SY0-701. These are real Labs from the catalogue.

Make SY0-701 your next step.

Create your free account. Start practising.

Start Free