Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 26 pages
Exam (elaborations)

CompTIA Security+ (SY0-701) Certification Exam Complete Exam Guide: Domains, Concepts, and Practice Questions with Answers & Rationales

Document preview thumbnail
Preview 3 out of 26 pages

CompTIA Security+ (SY0-701) Certification Exam Complete Exam Guide: Domains, Concepts, and Practice Questions with Answers & Rationales

Content preview

CompTIA Security+ (SY0-701) Certification Exam Complete
Exam Guide: Domains, Concepts, and Practice Questions
with Answers & Rationales


QUESTIONS START ON PAGE 3

🎯 Exam Domains (5 Domains)
The Security+ SY0-701 exam is organized into five domains that cover essential
cybersecurity concepts:
Domain Percentage Description
1. General Security ~20% CIA Triad, control types,
Concepts frameworks, Zero Trust, AAA
2. Threats, Vulnerabilities & ~25% Threat actors, malware, social
Mitigations engineering, attack types
3. Security Architecture ~20% Defense-in-depth, network
segmentation, cloud security
4. Security Operations ~20% Logging, SIEM, incident
response, monitoring
5. Security Program ~15% Policies, GRC, BCP/DR,
Management & Oversight awareness training
📚 Core Security Concepts
The CIA Triad
The CIA Triad is the foundational model for information security:
Principle Definition Key Controls
Confidentiality Ensuring data is not Encryption, access
accessed by unauthorized control, data masking
individuals

, Integrity Ensuring data remains Hashing, checksums,
accurate and unaltered digital signatures
Availability Ensuring authorized users Redundancy, fault
can access data when tolerance, disaster
needed recovery
Additional Core Principles
Non-repudiation ensures a person or entity cannot deny having performed a particular
action. Methods include digital signatures, audit logs, and time-stamping.
AAA Framework (Authentication, Authorization, Accounting):
 Authentication: Verifying identity (passwords, biometrics, MFA)
 Authorization: Determining access levels (RBAC, ABAC, MAC)
 Accounting: Tracking user actions via logging and monitoring
Security Control Categories
Controls are classified by type (how they are implemented):
Control Purpose Examples
Type
Technical Use technology to Firewalls, encryption, antivirus, ACLs
enforce security
Managerial Oversee security Risk assessments, policy development,
program awareness training
Operational Day-to-day security User training, configuration
activities management, monitoring
Physical Protect physical assets Locks, security guards, surveillance
cameras
Controls are also categorized by function:
Function Purpose Examples
Preventive Stop incidents before Firewalls, encryption, access
they occur control

, Deterrent Discourage security Warning signs, visible
violations cameras
Detective Identify active or past IDS, audit logs, file integrity
incidents checkers
Corrective Mitigate impact after Antivirus removal, patch
detection management, system restore
Compensating Alternative when primary MFA as biometric substitute,
control unavailable manual log review
Directive Guide behavior via rules Security policies, employee
handbooks
Zero Trust Model
Zero Trust operates on "never trust, always verify" – no user or device is automatically
trusted, whether inside or outside the network. Key components include continuous
verification, granular access control (least privilege), and micro-segmentation (dividing the
network into smaller zones).
Domain 1: General Security Concepts (Questions 1–20)
1. Which of the following ensures that data is not accessed by unauthorized
individuals?
a) Integrity
b) Confidentiality
c) Availability
d) Non-repudiation
Explanation: Confidentiality ensures data is not accessed by unauthorized individuals,
processes, or systems. It is achieved through encryption, access controls, and data
masking.
2. A company wants to ensure that a user cannot deny having submitted a financial
transaction. Which principle is being enforced?
a) Integrity
b) Confidentiality
c) Availability
d) Non-repudiation

Document information

Uploaded on
May 8, 2026
Number of pages
26
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$35.00

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
171
Followers
6
Items
2134
Last sold
2 days ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions