Escrito por estudiantes que aprobaron Inmediatamente disponible después del pago Leer en línea o como PDF ¿Documento equivocado? Cámbialo gratis 4,6 TrustPilot
logo-home
Document preview thumbnail
Vista previa 3 fuera de 26 páginas
Examen

CompTIA Security+ SY0-701 Exam Cheat Sheet 2026/2027 | Complete Questions & Verified Answers

Document preview thumbnail
Vista previa 3 fuera de 26 páginas

Prepare for the CompTIA Security+ SY0-701 certification exam with comprehensive questions and answers covering cybersecurity concepts, threats, architecture, security operations, risk management, and governance.

Vista previa del contenido

Comptia Security + Exam




Breach A breach is the penetration of system defenses, achieved through information
gathered by reconnaissance to penetrate the system defenses and gain
unauthorized access.


Escalate Privileges Escalating privileges is one of the primary objectives of an attacker and can be
achieved by configuring additional (escalated) rights to do more than just
breaching the system.


Create a Backdoor Creating a backdoor is an alternative method of accessing an application or
operating system for troubleshooting. Hackers often create backdoors to
exploit a system without being detected.


Stage Staging a computer involves preparing it to perform additional tasks in the
attack, such as installing software designed to attack other systems. This is an
optional step.


Exploit An exploitation takes advantage of known vulnerabilities in software and
systems. Types of exploitation include:
Stealing information
Denying services
Crashing systems
Modifying/Altering information


Layering Layering involves implementing multiple security strategies to protect the same
asset. Defense in depth or security in depth is the premise that no single layer is
completely effective in securing the assets. The most secure system/network
has many layers of security and eliminates single points of failure.


Principle of Least Privilege The principle of least privilege states that users or groups are given only the
access they need to do their job and nothing more. When assigning privileges,
be aware that it is often easier to give a user more access when they need it
than to take away privileges that have already been granted.


Variety Defensive layers should have variety and be diverse; implementing multiple
layers of the exact same defense does not provide adequate strength against
attacks.


Randomness Randomness in security is the constant change in personal habits and
passwords to prevent anticipated events and exploitation.

, Comptia Security + Exam
Simplicity Security measures should provide protection, but not be so complex that you
do not understand and use them.


Sophisticated Attacks Sophisticated attacks are complex, making them difficult to detect and thwart.
Sophisticated attacks:
Use common internet tools and protocols, making it difficult to distinguish an
attack from legitimate traffic.
Vary their behavior, making the same attack appear differently each time.


Proliferation of Attack Software A wide variety of attack tools are available on the internet, allowing anyone
with a moderate level of technical knowledge to download the tools and run
an attack.


Attack Scale and Velocity The scale and velocity of an attack can grow to millions of computers in a
matter of minutes or days due to its ability to proliferate on the internet.
Because modern attacks are not limited to user interactions, such as using a
floppy disk, to spread an attack from machine to machine, the attacks often
affect very large numbers of computers in a relatively short amount of time.


Confidentiality Ensures that data is not disclosed to unintended persons. This is provided
through encryption, which converts the data into a form that makes it less likely
to be usable by an unintended recipient.


Integrity ensures that data is not modified or tampered with. This is provided through
hashing.


Availability which ensures the uptime of the system so that data is available when needed


Non-repudiation provides validation of a message's origin. For example, if a user sends a digitally
signed email, they cannot claim later that the email was not sent. Non-
repudiation is enforced by digital signatures.


CIA of Security refers to confidentiality, integrity, and availability. These are often identified as
the three main goals of security.




Physical security which includes all hardware and software necessary to secure data, such as
firewalls and antivirus software.


Users and administrators which are the people who use the software and the people who manage the
software, respectively.


Policies which are the rules an organization implements to protect information.

, Comptia Security + Exam
Risk management is the process of identifying security issues and deciding which
countermeasures to take in reducing risk to an acceptable level. The main
objective is to reduce the risk for an organization to a level that is deemed
acceptable by senior management.


asset something that has value to the person or organization, such as sensitive
information in a database.


threat an entity that can cause the loss of an asset or any potential danger to the
confidentiality, integrity, or availability of information or systems, such as a data
breach that results in a database being stolen.


threat agent (sometimes known as an attacker) is an entity that can carry out a threat, such
as a disgruntled employee who copies a database to a thumb drive and sells it
to a competitor.


vulnerability is a weakness that allows a threat to be carried out, such as a USB port that is
enabled on the server hosting the database or a server room door that is
frequently left ajar. USB devices pose the greatest threat to the confidentiality
of data in most secure organizations. There are so many devices that can
support file storage that stealing data has become easy, and preventing it is
difficult.


exploit a procedure or product that takes advantage of a vulnerability to carry out a
threat, such as when a disgruntled employee waits for the server room door to
be left ajar, copies the database to a thumb drive, and then sells it.




Script kiddies who download and run attacks available on the internet, but generally are not
technically savvy enough to create their own attacking code or script.


Cybercriminals who usually seek to exploit security vulnerabilities for some kind of financial
reward or revenge.


Cyber terrorists who generally use the Internet to carry out terrorist activities, such as
disrupting network-dependent institutions.


Internal threats authorized individuals that exploit their inherent privileges to carry out an
attack. This category includes employees (both current and former), janitors,
security guards, and even customers.


External threats any individuals or groups that attacks a network from the outside and seeks to
gain unauthorized access to data.


Persistent threats threats seek to gain access to a network and remain there undetected. With this
type of threat, the attacker will go to great lengths to hide their tracks and
presence in the network.

Información del documento

Subido en
19 de agosto de 2026
Número de páginas
26
Escrito en
2026/2027
Tipo
Examen
Contiene
Preguntas y respuestas
$10.99

¿Documento equivocado? Cámbialo gratis Dentro de los 14 días posteriores a la compra y antes de descargarlo, puedes elegir otro documento. Puedes gastar el importe de nuevo.
Escrito por estudiantes que aprobaron
Inmediatamente disponible después del pago
Leer en línea o como PDF

Seller avatar
Nexasdocsales
5.0
(2)
Vendido
2
Seguidores
1
Artículos
682
Última venta
1 mes hace



Por qué los estudiantes eligen Stuvia

Creado por compañeros estudiantes, verificado por reseñas

Calidad en la que puedes confiar: escrito por estudiantes que aprobaron y evaluado por otros que han usado estos resúmenes.

¿No estás satisfecho? Elige otro documento

¡No te preocupes! Puedes elegir directamente otro documento que se ajuste mejor a lo que buscas.

Paga como quieras, empieza a estudiar al instante

Sin suscripción, sin compromisos. Paga como estés acostumbrado con tarjeta de crédito y descarga tu documento PDF inmediatamente.

Student with book image

“Comprado, descargado y aprobado. Así de fácil puede ser.”

Alisha Student

Preguntas frecuentes