TB.

Security+ SY0-701 · Domain 1

Domain 1: General Security Concepts

Why This Domain Matters

Domain 1 is 12% of the SY0-701 exam by weight, but it supplies the vocabulary every other domain depends on — you cannot reason about Domain 2 (threats) or Domain 4 (operations) without control categories, zero trust terminology, and cryptographic primitives already fluent.

It is also the domain closest to day-to-day security-operations tooling in practice: identity-based access control is zero trust in production, and endpoint-detection alerts are how honeytokens and change-control violations surface in real environments.

Objective-by-Objective Breakdown

1.1 Security Controls

Controls are described along two independent dimensions, and the exam tests both separately.

Categories (who/what implements the control):

  • Technical: enforced by systems, e.g. a firewall rule
  • Managerial: governance/policy, e.g. a risk assessment procedure
  • Operational: people executing day-to-day processes, e.g. security awareness training
  • Physical: tangible barriers, e.g. a fence

Types (what the control does):

  • Preventive: stops the event, e.g. an ACL blocking traffic
  • Deterrent: discourages attempt, e.g. warning signage
  • Detective: identifies after the fact, e.g. an IDS alert
  • Corrective: restores after impact, e.g. restoring from backup
  • Compensating: substitute when the primary control isn't feasible, e.g. manual transaction review when automated fraud detection is down
  • Directive: mandates a behaviour, e.g. an acceptable use policy

A single real control usually has one category and one type. Example: a Conditional Access policy blocking non-compliant devices is technical + preventive. A firewall rule blocking traffic is the same combination.

1.2 Fundamental Concepts

The CIA triad — the three core security goals every control serves

Zero trust: control plane decides, data plane enforces — nothing implicitly trusted

CIA triad:

  • confidentiality: only authorised parties read data
  • integrity: data isn't altered undetected
  • availability: data/systems are accessible when needed

Non-repudiation: proof an action occurred and cannot be denied by its actor, achieved through digital signatures and tamper-evident logging (not the same as authentication; see Confusables).

AAA:

  • Authentication: proving identity: for people, password/biometric/token combinations; for systems, certificates and mutual authentication
  • Authorisation: what an authenticated identity may do, modelled via RBAC, DAC, MAC, or ABAC
  • Accounting: logging what was done

Gap analysis: comparing your current control set against a required baseline or standard to find deficiencies. This is literally what an ISO 27001 or Essential Eight readiness assessment does.

Zero trust splits into two planes.

Control plane (decides):

  • adaptive identity: risk-based, continuously re-evaluated identity signals
  • threat scope reduction: minimising blast radius via segmentation
  • policy-driven access control: rules engine making grant/deny decisions
  • executed by the Policy Engine (evaluates policy against signals) and Policy Administrator (issues the decision)

Data plane (enforces):

  • implicit trust zones: network segments still requiring their own verification
  • subject/system: the requester
  • the Policy Enforcement Point: the gate that actually allows or blocks the connection

Map this directly to your daily tools: Conditional Access's decision logic is the Policy Engine/Administrator; the actual sign-in block at the application is the Policy Enforcement Point.

Physical security:

  • bollards: vehicle-ramming prevention
  • access control vestibule: mantrap, one person through at a time
  • fencing
  • video surveillance
  • security guards
  • access badges
  • lighting
  • sensors: infrared, pressure, microwave, ultrasonic; all motion/intrusion detection, differing in what they sense

Deception & disruption:

  • honeypot
  • honeynet
  • honeyfile
  • honeytoken: see the comparison table below

1.3 Change Management

The exam separates the business process from the technical implications. Business process: a request goes through approval, with clear ownership and identified stakeholders; an impact analysis assesses risk/blast radius; test results validate the change works; a backout plan defines how to revert if it fails; a maintenance window schedules low-impact timing; a standard operating procedure (SOP) documents the repeatable steps.

Technical implications of the change itself:

  • updates to allow/deny lists
  • restricted activities during the window
  • expected downtime
  • service or application restarts
  • compatibility with legacy applications
  • dependency mapping

Underpinning all of it: documentation and version control, so every change is traceable and reversible.

1.4 Cryptographic Solutions

PKI relies on public/private key pairs; key escrow lets a trusted third party hold a recoverable copy of private keys under governance (a legitimate control, not inherently a backdoor).

Encryption levels run from broad to narrow:

  • full-disk: BitLocker via Intune, backed by the device's TPM
  • partition
  • volume
  • file
  • database
  • record

Choose the narrowest level that meets the requirement: encrypting one sensitive file doesn't require encrypting the whole database.

Symmetric encryption uses one shared key: fast, used for bulk data. The standard example is AES with 128-, 192-, or 256-bit keys.

Asymmetric uses a public/private key pair:

  • slower
  • used for key exchange
  • digital signatures
  • certificates: RSA, ECC

Key exchange protocols let two parties agree a symmetric key over an insecure channel; Diffie-Hellman is the classic example (ECDHE in modern TLS).

Hardware tools:

  • TPM: soldered chip, single-device root of trust, stores BitLocker keys, verifies boot integrity
  • HSM: dedicated appliance managing keys at scale for many systems
  • key management system: software/service coordinating key lifecycle
  • secure enclave: isolated, hardware-protected execution region within a processor

Obfuscation:

  • steganography: hiding data inside other data, e.g. an image
  • tokenization: substituting a non-mathematically-derived token for sensitive data
  • data masking: obscuring parts of a value, e.g. showing only the last four digits

Hashing produces a one-way, fixed-length digest for integrity checking; salting adds unique random data before hashing to defeat rainbow-table attacks; key stretching (e.g. PBKDF2, bcrypt) deliberately slows down hashing of weak inputs like passwords to resist brute force.

Digital signatures hash a message and encrypt the hash with the sender's private key, providing integrity, authenticity, and non-repudiation together.

Blockchain / open public ledger: a distributed, append-only record verified by consensus rather than a central authority, providing integrity without a single trusted party.

Certificates: issued by a Certificate Authority (CA), anchored at a root of trust; a Certificate Signing Request (CSR) bundles a public key and identity details for the CA to sign; certificates may be self-signed (no external CA, common internally) or third-party (publicly trusted); a wildcard certificate covers a domain and its first-level subdomains; revocation is checked via a CRL (periodic list) or OCSP (real-time query).

Confusables — Don't Mix These Up

Control categories vs. control types

TermWhat it isKey differentiatorExam tell
Technical / Managerial / Operational / PhysicalThe four categories (who/what implements the control)Answers "where does this control live?"Stem asks "which category"
Preventive / Deterrent / Detective / Corrective / Compensating / DirectiveThe six types (what the control does in time)Answers "what does this control do?"Stem asks "which type" or describes a timing (before/during/after)

Hashing vs. Encryption vs. Encoding vs. Obfuscation

TermWhat it isKey differentiatorExam tell
HashingOne-way fixed-length digestCannot be reversed; used for integrity"Verify the file wasn't altered"
EncryptionReversible transform requiring a keyConfidentiality; key required to reverse"Protect data so only the key holder can read it"
EncodingReversible transform for compatibility (e.g. Base64)No key needed to reverse; not securityDistractor claiming Base64 "encrypts" data
ObfuscationMakes data/logic harder to interpret (masking, steganography)Not cryptographically strong; hides rather than secures"Hide" or "disguise" without a security guarantee

Symmetric vs. Asymmetric

TermWhat it isKey differentiatorExam tell
SymmetricOne shared secret key (AES)Fast; used for bulk data encryption"Encrypt large volumes of data efficiently"
AsymmetricPublic/private key pair (RSA, ECC)Slower; used for key exchange, signatures, certificates"Establish trust" or "exchange a key securely"

CRL vs. OCSP

TermWhat it isKey differentiatorExam tell
CRLPeriodically published list of revoked cert serial numbersClient downloads/checks the whole list; can lag"Check against a published list"
OCSPReal-time request/response for one certificate's statusImmediate, per-certificate check (OCSP stapling avoids exposing browsing to the responder)"Real-time" or "during the TLS handshake"

Honeypot vs. Honeynet vs. Honeyfile vs. Honeytoken

TermWhat it isKey differentiatorExam tell
HoneypotA single decoy systemOne machine, studies attacker behaviour"Decoy server"
HoneynetA network of honeypotsSimulates a whole environment"Decoy network/segment"
HoneyfileA decoy fileWhole file is the lure"Fake file named passwords.xlsx"
HoneytokenA decoy data element (credential, DB row, API key)Smallest unit; not necessarily a file"Fake value/record that alerts when used"

TPM vs. HSM vs. Secure Enclave

TermWhat it isKey differentiatorExam tell
TPMChip soldered to one device's motherboardSingle-device root of trust (e.g. BitLocker keys)"Built into the laptop/PC"
HSMDedicated hardware applianceEnterprise-scale, serves many systems (e.g. a CA)"Manages keys for the organisation"
Secure enclaveIsolated region within a processorHardware-isolated execution inside the CPU package"Isolated area of the chip," mobile/device context

Exam Traps

  • Corrective vs. compensating: corrective fixes damage after an incident; compensating substitutes for a control that can't be deployed at all. Don't pick "corrective" just because a stem mentions "after."
  • Category vs. type mixed in one stem: read carefully whether the question wants the category (technical/managerial/operational/physical) or the type (preventive/detective/etc.); both are often true of the same control.
  • Authentication vs. non-repudiation: authentication proves identity now; non-repudiation proves an action happened and can't be denied later. A login prompt is not non-repudiation.
  • Encoding presented as "encryption": Base64 and similar are common wrong-answer bait, no key, trivially reversible.
  • CRL vs. OCSP timing: "real-time" or "during the handshake" always points to OCSP, never CRL.
  • Zero trust is "never trust, always verify", not "trust but verify" (the latter is a classic wrong-answer trap).
  • Honeytoken need not be a file: don't default to "honeyfile" whenever the scenario mentions fake data; check whether it's a whole file or a smaller embedded value.
  • Key escrow ≠ backdoor: when properly governed, it's a legitimate recovery mechanism, not automatically a security weakness: read the scenario for controls, not just the concept name.

Acronym Table

AcronymExpansionOne-line meaning
CIAConfidentiality, Integrity, AvailabilityThe three core security goals
AAAAuthentication, Authorization, AccountingIdentity verification, permission, and logging
RBACRole-Based Access ControlAccess tied to a user's assigned role
DACDiscretionary Access ControlResource owner decides access
MACMandatory Access ControlSystem-enforced labels/classifications control access
ABACAttribute-Based Access ControlAccess decided by attributes (user, resource, environment)
PAPolicy AdministratorZero trust component that issues the access decision
PEPolicy EngineZero trust component that evaluates policy against signals
PEPPolicy Enforcement PointZero trust component that enforces the grant/deny decision
PKIPublic Key InfrastructureFramework for issuing/managing public-key certificates
CACertificate AuthorityIssues and signs digital certificates
CRLCertificate Revocation ListPublished list of revoked certificates
OCSPOnline Certificate Status ProtocolReal-time certificate revocation check
CSRCertificate Signing RequestRequest submitted to a CA to obtain a signed certificate
TPMTrusted Platform ModuleChip-based hardware root of trust on a device
HSMHardware Security ModuleDedicated appliance for enterprise key management
KMSKey Management SystemCoordinates cryptographic key lifecycle
FDEFull-Disk EncryptionEncrypts an entire storage drive
SOPStandard Operating ProcedureDocumented repeatable process steps
MFAMulti-Factor AuthenticationAuthentication using two or more factor types

Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.

Interactive drills

Flashcards

Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.

Due today: 20

Flipped: 0/20

Quiz

10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.

Score: 0/10

Q1EasyA company installs security cameras and posts security guards at its main entrance. Which control category best describes both measures?

Q2EasyWhich cryptographic tool is a dedicated chip soldered onto a laptop's motherboard, used to store full-disk encryption keys and verify boot integrity?

Q3EasyAn organisation wants to confirm a downloaded file hasn't been altered in transit, without needing to reverse any transformation. Which technique should be used?

Q4MediumA security analyst configures a Conditional Access policy that requires a compliant, hybrid-joined device before granting access to a sensitive SaaS application, and re-evaluates the decision continuously as conditions change. This best exemplifies which zero trust concept?

Q5MediumWhich technology allows a browser to check whether a specific certificate has been revoked in real time as part of the TLS handshake, without downloading an entire revocation list?

Q6MediumBefore patching a production database server, a change advisory board reviews the plan, and the change record documents who approved the request, the affected stakeholders, and the steps to revert if patching fails. What are the documented revert instructions called?

Q7MediumA penetration tester places a fake row labelled "admintemppassword" inside a live production database, configured to trigger an alert whenever that specific value is queried or copied. Which deception technique is this?

Q8HardA legal aid organisation stores case files on a shared drive that already has full-disk encryption enabled. It now needs an additional layer of protection so that even users with general OS-level access to the drive cannot open specific highly sensitive case documents without an extra decryption step. Which encryption level should be added on top of the existing full-disk encryption?

Q9Hard, PBQ — orderingArrange the following steps for obtaining a publicly trusted TLS certificate for a new website in the correct order:

Q10Medium, PBQ — log interpretationA SOC analyst reviews an access log: