Security+ SY0-701 · Domain 1
Domain 1: General Security Concepts
Why This Domain Matters
Domain 1 is 12% of the SY0-701 exam by weight, but it supplies the vocabulary every other domain depends on — you cannot reason about Domain 2 (threats) or Domain 4 (operations) without control categories, zero trust terminology, and cryptographic primitives already fluent.
It is also the domain closest to day-to-day security-operations tooling in practice: identity-based access control is zero trust in production, and endpoint-detection alerts are how honeytokens and change-control violations surface in real environments.
Objective-by-Objective Breakdown
1.1 Security Controls
Controls are described along two independent dimensions, and the exam tests both separately.
Categories (who/what implements the control):
- Technical: enforced by systems, e.g. a firewall rule
- Managerial: governance/policy, e.g. a risk assessment procedure
- Operational: people executing day-to-day processes, e.g. security awareness training
- Physical: tangible barriers, e.g. a fence
Types (what the control does):
- Preventive: stops the event, e.g. an ACL blocking traffic
- Deterrent: discourages attempt, e.g. warning signage
- Detective: identifies after the fact, e.g. an IDS alert
- Corrective: restores after impact, e.g. restoring from backup
- Compensating: substitute when the primary control isn't feasible, e.g. manual transaction review when automated fraud detection is down
- Directive: mandates a behaviour, e.g. an acceptable use policy
A single real control usually has one category and one type. Example: a Conditional Access policy blocking non-compliant devices is technical + preventive. A firewall rule blocking traffic is the same combination.
1.2 Fundamental Concepts
The CIA triad — the three core security goals every control serves
Zero trust: control plane decides, data plane enforces — nothing implicitly trusted
CIA triad:
- confidentiality: only authorised parties read data
- integrity: data isn't altered undetected
- availability: data/systems are accessible when needed
Non-repudiation: proof an action occurred and cannot be denied by its actor, achieved through digital signatures and tamper-evident logging (not the same as authentication; see Confusables).
AAA:
- Authentication: proving identity: for people, password/biometric/token combinations; for systems, certificates and mutual authentication
- Authorisation: what an authenticated identity may do, modelled via RBAC, DAC, MAC, or ABAC
- Accounting: logging what was done
Gap analysis: comparing your current control set against a required baseline or standard to find deficiencies. This is literally what an ISO 27001 or Essential Eight readiness assessment does.
Zero trust splits into two planes.
Control plane (decides):
- adaptive identity: risk-based, continuously re-evaluated identity signals
- threat scope reduction: minimising blast radius via segmentation
- policy-driven access control: rules engine making grant/deny decisions
- executed by the Policy Engine (evaluates policy against signals) and Policy Administrator (issues the decision)
Data plane (enforces):
- implicit trust zones: network segments still requiring their own verification
- subject/system: the requester
- the Policy Enforcement Point: the gate that actually allows or blocks the connection
Map this directly to your daily tools: Conditional Access's decision logic is the Policy Engine/Administrator; the actual sign-in block at the application is the Policy Enforcement Point.
Physical security:
- bollards: vehicle-ramming prevention
- access control vestibule: mantrap, one person through at a time
- fencing
- video surveillance
- security guards
- access badges
- lighting
- sensors: infrared, pressure, microwave, ultrasonic; all motion/intrusion detection, differing in what they sense
Deception & disruption:
- honeypot
- honeynet
- honeyfile
- honeytoken: see the comparison table below
1.3 Change Management
The exam separates the business process from the technical implications. Business process: a request goes through approval, with clear ownership and identified stakeholders; an impact analysis assesses risk/blast radius; test results validate the change works; a backout plan defines how to revert if it fails; a maintenance window schedules low-impact timing; a standard operating procedure (SOP) documents the repeatable steps.
Technical implications of the change itself:
- updates to allow/deny lists
- restricted activities during the window
- expected downtime
- service or application restarts
- compatibility with legacy applications
- dependency mapping
Underpinning all of it: documentation and version control, so every change is traceable and reversible.
1.4 Cryptographic Solutions
PKI relies on public/private key pairs; key escrow lets a trusted third party hold a recoverable copy of private keys under governance (a legitimate control, not inherently a backdoor).
Encryption levels run from broad to narrow:
- full-disk: BitLocker via Intune, backed by the device's TPM
- partition
- volume
- file
- database
- record
Choose the narrowest level that meets the requirement: encrypting one sensitive file doesn't require encrypting the whole database.
Symmetric encryption uses one shared key: fast, used for bulk data. The standard example is AES with 128-, 192-, or 256-bit keys.
Asymmetric uses a public/private key pair:
- slower
- used for key exchange
- digital signatures
- certificates: RSA, ECC
Key exchange protocols let two parties agree a symmetric key over an insecure channel; Diffie-Hellman is the classic example (ECDHE in modern TLS).
Hardware tools:
- TPM: soldered chip, single-device root of trust, stores BitLocker keys, verifies boot integrity
- HSM: dedicated appliance managing keys at scale for many systems
- key management system: software/service coordinating key lifecycle
- secure enclave: isolated, hardware-protected execution region within a processor
Obfuscation:
- steganography: hiding data inside other data, e.g. an image
- tokenization: substituting a non-mathematically-derived token for sensitive data
- data masking: obscuring parts of a value, e.g. showing only the last four digits
Hashing produces a one-way, fixed-length digest for integrity checking; salting adds unique random data before hashing to defeat rainbow-table attacks; key stretching (e.g. PBKDF2, bcrypt) deliberately slows down hashing of weak inputs like passwords to resist brute force.
Digital signatures hash a message and encrypt the hash with the sender's private key, providing integrity, authenticity, and non-repudiation together.
Blockchain / open public ledger: a distributed, append-only record verified by consensus rather than a central authority, providing integrity without a single trusted party.
Certificates: issued by a Certificate Authority (CA), anchored at a root of trust; a Certificate Signing Request (CSR) bundles a public key and identity details for the CA to sign; certificates may be self-signed (no external CA, common internally) or third-party (publicly trusted); a wildcard certificate covers a domain and its first-level subdomains; revocation is checked via a CRL (periodic list) or OCSP (real-time query).
Confusables — Don't Mix These Up
Control categories vs. control types
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Technical / Managerial / Operational / Physical | The four categories (who/what implements the control) | Answers "where does this control live?" | Stem asks "which category" |
| Preventive / Deterrent / Detective / Corrective / Compensating / Directive | The six types (what the control does in time) | Answers "what does this control do?" | Stem asks "which type" or describes a timing (before/during/after) |
Hashing vs. Encryption vs. Encoding vs. Obfuscation
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Hashing | One-way fixed-length digest | Cannot be reversed; used for integrity | "Verify the file wasn't altered" |
| Encryption | Reversible transform requiring a key | Confidentiality; key required to reverse | "Protect data so only the key holder can read it" |
| Encoding | Reversible transform for compatibility (e.g. Base64) | No key needed to reverse; not security | Distractor claiming Base64 "encrypts" data |
| Obfuscation | Makes data/logic harder to interpret (masking, steganography) | Not cryptographically strong; hides rather than secures | "Hide" or "disguise" without a security guarantee |
Symmetric vs. Asymmetric
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Symmetric | One shared secret key (AES) | Fast; used for bulk data encryption | "Encrypt large volumes of data efficiently" |
| Asymmetric | Public/private key pair (RSA, ECC) | Slower; used for key exchange, signatures, certificates | "Establish trust" or "exchange a key securely" |
CRL vs. OCSP
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| CRL | Periodically published list of revoked cert serial numbers | Client downloads/checks the whole list; can lag | "Check against a published list" |
| OCSP | Real-time request/response for one certificate's status | Immediate, per-certificate check (OCSP stapling avoids exposing browsing to the responder) | "Real-time" or "during the TLS handshake" |
Honeypot vs. Honeynet vs. Honeyfile vs. Honeytoken
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| Honeypot | A single decoy system | One machine, studies attacker behaviour | "Decoy server" |
| Honeynet | A network of honeypots | Simulates a whole environment | "Decoy network/segment" |
| Honeyfile | A decoy file | Whole file is the lure | "Fake file named passwords.xlsx" |
| Honeytoken | A decoy data element (credential, DB row, API key) | Smallest unit; not necessarily a file | "Fake value/record that alerts when used" |
TPM vs. HSM vs. Secure Enclave
| Term | What it is | Key differentiator | Exam tell |
|---|---|---|---|
| TPM | Chip soldered to one device's motherboard | Single-device root of trust (e.g. BitLocker keys) | "Built into the laptop/PC" |
| HSM | Dedicated hardware appliance | Enterprise-scale, serves many systems (e.g. a CA) | "Manages keys for the organisation" |
| Secure enclave | Isolated region within a processor | Hardware-isolated execution inside the CPU package | "Isolated area of the chip," mobile/device context |
Exam Traps
- Corrective vs. compensating: corrective fixes damage after an incident; compensating substitutes for a control that can't be deployed at all. Don't pick "corrective" just because a stem mentions "after."
- Category vs. type mixed in one stem: read carefully whether the question wants the category (technical/managerial/operational/physical) or the type (preventive/detective/etc.); both are often true of the same control.
- Authentication vs. non-repudiation: authentication proves identity now; non-repudiation proves an action happened and can't be denied later. A login prompt is not non-repudiation.
- Encoding presented as "encryption": Base64 and similar are common wrong-answer bait, no key, trivially reversible.
- CRL vs. OCSP timing: "real-time" or "during the handshake" always points to OCSP, never CRL.
- Zero trust is "never trust, always verify", not "trust but verify" (the latter is a classic wrong-answer trap).
- Honeytoken need not be a file: don't default to "honeyfile" whenever the scenario mentions fake data; check whether it's a whole file or a smaller embedded value.
- Key escrow ≠ backdoor: when properly governed, it's a legitimate recovery mechanism, not automatically a security weakness: read the scenario for controls, not just the concept name.
Acronym Table
| Acronym | Expansion | One-line meaning |
|---|---|---|
| CIA | Confidentiality, Integrity, Availability | The three core security goals |
| AAA | Authentication, Authorization, Accounting | Identity verification, permission, and logging |
| RBAC | Role-Based Access Control | Access tied to a user's assigned role |
| DAC | Discretionary Access Control | Resource owner decides access |
| MAC | Mandatory Access Control | System-enforced labels/classifications control access |
| ABAC | Attribute-Based Access Control | Access decided by attributes (user, resource, environment) |
| PA | Policy Administrator | Zero trust component that issues the access decision |
| PE | Policy Engine | Zero trust component that evaluates policy against signals |
| PEP | Policy Enforcement Point | Zero trust component that enforces the grant/deny decision |
| PKI | Public Key Infrastructure | Framework for issuing/managing public-key certificates |
| CA | Certificate Authority | Issues and signs digital certificates |
| CRL | Certificate Revocation List | Published list of revoked certificates |
| OCSP | Online Certificate Status Protocol | Real-time certificate revocation check |
| CSR | Certificate Signing Request | Request submitted to a CA to obtain a signed certificate |
| TPM | Trusted Platform Module | Chip-based hardware root of trust on a device |
| HSM | Hardware Security Module | Dedicated appliance for enterprise key management |
| KMS | Key Management System | Coordinates cryptographic key lifecycle |
| FDE | Full-Disk Encryption | Encrypts an entire storage drive |
| SOP | Standard Operating Procedure | Documented repeatable process steps |
| MFA | Multi-Factor Authentication | Authentication using two or more factor types |
Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.
Interactive drills
Flashcards
Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.
Due today: 20
Flipped: 0/20
Quiz
10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.
Score: 0/10
Q1EasyA company installs security cameras and posts security guards at its main entrance. Which control category best describes both measures?
Q2EasyWhich cryptographic tool is a dedicated chip soldered onto a laptop's motherboard, used to store full-disk encryption keys and verify boot integrity?
Q3EasyAn organisation wants to confirm a downloaded file hasn't been altered in transit, without needing to reverse any transformation. Which technique should be used?
Q4MediumA security analyst configures a Conditional Access policy that requires a compliant, hybrid-joined device before granting access to a sensitive SaaS application, and re-evaluates the decision continuously as conditions change. This best exemplifies which zero trust concept?
Q5MediumWhich technology allows a browser to check whether a specific certificate has been revoked in real time as part of the TLS handshake, without downloading an entire revocation list?
Q6MediumBefore patching a production database server, a change advisory board reviews the plan, and the change record documents who approved the request, the affected stakeholders, and the steps to revert if patching fails. What are the documented revert instructions called?
Q7MediumA penetration tester places a fake row labelled "admintemppassword" inside a live production database, configured to trigger an alert whenever that specific value is queried or copied. Which deception technique is this?
Q8HardA legal aid organisation stores case files on a shared drive that already has full-disk encryption enabled. It now needs an additional layer of protection so that even users with general OS-level access to the drive cannot open specific highly sensitive case documents without an extra decryption step. Which encryption level should be added on top of the existing full-disk encryption?
Q9Hard, PBQ — orderingArrange the following steps for obtaining a publicly trusted TLS certificate for a new website in the correct order:
Q10Medium, PBQ — log interpretationA SOC analyst reviews an access log: