Track
Security+
Security+ tests whether you can name the right control, threat, or process for a situation. These notes follow the public SY0-701 domain names and paraphrase the ideas. Confirm current domain weights against CompTIA's outline before you sit. Drill questions stay with your coach.
0 done · 0 in progress · 30 not started
Family
Notes
Progress
Showing 30 of 30
General concepts
Controls, security goals, zero trust, and the cryptographic ideas other domains lean on.
- General security conceptsReadyNot startedDomain overview. The exam's first domain is the vocabulary every other domain borrows, especially controls and security goals.14 min
- Security controlsReadyNot startedA control is a safeguard. The exam sorts them by what they do and by how they are built.16 min
- CIA and the foundation termsReadyNot startedConfidentiality, integrity, and availability are the goals. AAA, non-repudiation, and a few neighbors are how the exam names the mechanisms.15 min
- Zero trustReadyNot startedZero trust means every request is authenticated and authorized in context. The network location is not a proof.13 min
- Cryptography basicsReadyNot startedPick the primitive that matches the goal. Encryption hides, hashes fingerprint, signatures tie a fingerprint to a key.18 min
- Change managementOutlineNot startedOutline only. Change management is the controlled path from a request to a recorded result.8 min
- PKI and certificatesOutlineNot startedOutline only. PKI is the system that lets strangers trust a public key. The crypto note stops just short of it.8 min
Threats and mitigations
Who attacks, how they get in, which weaknesses matter, and which controls answer them.
- Threats, vulnerabilities, and mitigationsReadyNot startedDomain overview. Separate the actor, the weakness, the event, and the control that answers it.14 min
- Threat actorsReadyNot startedActors differ by skill, funding, access, and motive. The exam wants the best-fitting label, not a true-crime story.14 min
- Threat vectors and attack surfacesReadyNot startedA vector is the path in. The attack surface is the set of paths you actually exposed.14 min
- Vulnerability typesReadyNot startedGroup weaknesses by what failed. The web families on the BSCP track are examples, not extra vocabulary.16 min
- Indicators of malicious activityReadyNot startedAn indicator is evidence something is wrong. Learn the signal, not a hunt procedure.13 min
- Mitigation techniquesReadyNot startedMitigations are the controls you pair with a weakness. Learn the pairing, including when the answer is to remove the feature.15 min
Architecture
How networks, data, and recovery are designed so a single failure is not the whole story.
- Security architectureReadyNot startedDomain overview. Architecture is where you put the boundaries, the data, and the spare parts before an incident.13 min
- Enterprise infrastructureReadyNot startedPlace the control where the decision should happen. Know the difference between a boundary, a directory, and a tunnel.16 min
- Data protectionReadyNot startedProtect data by knowing what it is, where it is, and which state it is in. Classification comes before the product.14 min
- Resilience and recoveryReadyNot startedResilience is surviving failure. Learn RTO, RPO, sites, and backups as design numbers, not as a restore tutorial.15 min
Operations
Identity, monitoring, vulnerabilities, and incidents — the work of running security day to day.
- Security operationsReadyNot startedDomain overview. Operations is the largest published slice of SY0-701. It is the work of running identity, visibility, patches, and response.13 min
- Identity and access managementReadyNot startedIAM is the lifecycle of identities and the checks on each request. Least privilege and joiner-mover-leaver are the exam's favorite shapes.16 min
- Monitoring and loggingReadyNot startedMonitoring is collection plus a decision. Logs that nobody can trust or retrieve are not a detective control.14 min
- Vulnerability managementReadyNot startedVulnerability management is the loop of find, prioritize, fix, and confirm. A scanner is only the find step.14 min
- Incident responseReadyNot startedIncident response is an ordered process. Containment beats curiosity, and evidence has a chain of custody.15 min
- Asset managementOutlineNot startedOutline only. You cannot protect, patch, or retire what you have not inventoried.8 min
- Automation and orchestrationOutlineNot startedOutline only. Automation repeats a check. Orchestration coordinates steps across systems. Both can spread a mistake quickly.8 min
Program management
Governance, risk, suppliers, and the oversight that decides what 'good enough' means.
- Security program managementReadyNot startedDomain overview. This domain is who decides, which risks are accepted, and how outsiders and auditors fit.12 min
- Governance and complianceReadyNot startedGovernance is internal direction. Compliance is meeting a stated requirement. Policies, standards, and procedures sit at different altitudes.14 min
- Risk managementReadyNot startedRisk is likelihood and impact. The responses are avoid, mitigate, transfer, and accept. Residual risk remains after you choose.16 min
- Third-party riskReadyNot startedVendors enlarge the surface and the trust boundary. Agreements and reviews are how the program stays honest about that.13 min
- Security awarenessOutlineNot startedOutline only. Awareness is a recurring control aimed at human vectors, not a single annual video.8 min
- Audits and assessmentsOutlineNot startedOutline only. An audit checks against a criterion. An assessment is a broader look. Neither is a pentest by default.8 min