Security+ SY0-701 · Domain 4
Domain 4: Security Operations
Why This Domain Matters
Domain 4 is the single largest slice of the SY0-701 exam — bigger than Domain 1 and Domain 3 combined — and it's also the one most closely aligned with day-to-day IT/security-operations work.
Baselines and hardening, alerting and monitoring, identity and access management — these are the daily reality of running an endpoint/identity security stack, and the exam mostly asks you to relabel that work in CompTIA's vocabulary, then fill in the adjacent pieces day-to-day tickets don't force you to touch (vulnerability scoring math, formal incident-response phase names, digital forensics chain of custody).
Target 90%+ on this domain — 28% of the final score rides on it. The one trap: don't let familiarity breed sloppiness. The exam tests the precise CompTIA term for things practitioners do casually and messily on the job — know the vocabulary as rigorously as the click-path.
Objective-by-Objective Breakdown
4.1 Common Security Techniques for Computing Resources
Secure baselines are established (a documented target configuration), deployed (rolled out to the fleet), and maintained (drift is detected and corrected over time) — a lifecycle, not a one-off event.
Hardening applies across a long list of targets: mobile devices, workstations, switches, routers, cloud infrastructure, servers, ICS/SCADA, embedded systems, RTOS, and IoT devices — each with a different practical ceiling on how hard it can be hardened (an IoT sensor or an ICS controller often can't run an agent or take frequent patches at all).
Wireless installation considerations — site surveys (physically measuring signal coverage and interference before deployment) and heat maps (the visual output of that survey, showing signal strength across a floor plan) — are RF planning tasks that happen before a network exists.
Mobile solutions cover MDM (the management platform itself) and three deployment models — BYOD, COPE, CYOD, detailed in Confusables — plus connection methods: cellular, Wi-Fi, Bluetooth, each with a different exposure profile.
Wireless security settings are WPA3 (the current encryption standard, replacing WPA2), AAA/RADIUS (centralized authentication for network access), and the cryptographic and authentication protocols riding on top (e.g., EAP variants).
Application security covers input validation (rejecting malformed/malicious input before it's processed — the root cause CompTIA blames for injection attacks in Domain 2), secure cookies (flags like Secure and HttpOnly that limit how a session cookie can be transmitted or accessed), static code analysis (scanning source code for flaws without executing it), and code signing (a cryptographic signature proving code came from a trusted publisher and wasn't tampered with).
Sandboxing isolates untrusted code/files in a contained environment to observe behavior without risking the host. Monitoring closes the loop — baselines and hardening are worthless without ongoing visibility that they're still in effect.
4.2 Asset Management
Asset management runs a lifecycle:
- acquisition/procurement: bringing the asset in
- assignment/accounting: recording who owns it and how it's classified
- monitoring/asset tracking: inventory — knowing what you have — and enumeration — actively listing/discovering it
- disposal/decommissioning at end of life: sanitization, destruction, certification that it was done, and data retention obligations that might outlive the device itself
4.3 Vulnerability Management
Identification methods: vulnerability scans (automated checks against known-vulnerability databases), application security testing split into static (source code, not running) and dynamic (the running application, black-box) analysis, package monitoring (watching dependencies for known-vulnerable versions), threat feeds (OSINT — open-source intelligence; proprietary/third-party feeds; information-sharing organizations, e.g., an ISAO; and dark web monitoring), penetration testing, responsible disclosure programs including bug bounties, and system/process audits.
Analysis then has to confirm a finding is real (false positive vs. false negative — see Confusables), prioritize it, and score it: CVE identifies which vulnerability it is; CVSS scores how severe it is (see Confusables).
Vulnerability classification, exposure factor (the percentage of an asset's value that would be lost if the risk materialized), environmental variables (context specific to your environment that can raise or lower a CVSS base score), industry/organizational impact, and risk tolerance all feed the prioritization call.
Response and remediation options are patching, insurance (transferring residual risk), segmentation, compensating controls (an alternative safeguard when the primary control can't be applied), and exceptions/exemptions (formally accepted, documented deviations).
Validation closes the loop: rescanning, audit, verification that remediation actually worked — then reporting.
4.4 Security Alerting and Monitoring
Monitoring spans systems, applications, and infrastructure.
The activities are log aggregation (pulling logs into one place), alerting, scanning, reporting, archiving (retaining logs for later use — investigations, compliance), and alert response/remediation, which includes quarantine (isolating a flagged item) and alert tuning (adjusting thresholds/rules to cut false positives without missing real threats).
The tool list is dense:
- SCAP: Security Content Automation Protocol — a NIST standard for expressing vulnerability/configuration checks in a standardized, automatable format
- benchmarks: e.g., CIS benchmarks — hardening standards a baseline can be measured against
- agent-based vs. agentless monitoring
- SIEM
- antivirus
- DLP
- SNMP traps: alerts pushed from network devices when a monitored condition is hit
- NetFlow: network traffic flow metadata, not full packet capture
- vulnerability scanners
4.5 Enterprise Capabilities to Enhance Security
Firewalls run on rules/access lists filtering by ports/protocols, and can carve out screened subnets (the modern name for a DMZ). IDS/IPS detection relies on signatures (known-pattern matching) with an eye on trends (behavioral/anomaly detection catching what signatures miss).
Web filters can be agent-based (client-side) or run through a centralized proxy, and act via URL scanning, content categorization, block rules, and reputation scoring.
OS security includes Group Policy (the on-premises, Active Directory-joined policy mechanism) and SELinux (a Linux mandatory access control implementation).
Secure protocol implementation means picking the right protocol, port, and transport method for the job — this is where Domain 3's TLS/IPsec knowledge gets applied operationally. DNS filtering blocks resolution to known-malicious domains before a connection is even attempted.
Email security rests on DMARC, DKIM, and SPF (see Confusables) plus a security gateway inspecting mail in transit. File integrity monitoring (FIM) watches critical files/configs for unauthorized change. DLP stops sensitive data leaving where it shouldn't. NAC gates network access based on device/identity posture.
EDR/XDR and user behavior analytics round out detection and response (see Confusables for EDR vs. XDR vs. antivirus).
4.6 Identity and Access Management
Provisioning/de-provisioning creates and removes accounts across their lifecycle. Permission assignments carry implications — over-provisioning is its own risk, independent of whether an account is ever misused. Identity proofing verifies a person really is who they claim before a credential is ever issued.
Federation lets identity trust extend across organizational boundaries; SSO is the user-facing result, implemented via LDAP (directory lookup/bind, not itself an SSO protocol), OAuth (a delegated-authorization framework, token-based), and SAML (an XML-based assertion standard built for browser-based enterprise SSO) — see Confusables for how these three actually differ despite all appearing under the same SSO heading.
Interoperability is systems working together across those federated/SSO boundaries. Attestation proves a device's health state (e.g., TPM/Secure Boot integrity) before it's trusted, which is a different concept from identity proofing (which is about a person).
Access controls:
- MAC: labels set centrally, user can't override — think classified environments
- DAC: the resource owner decides
- RBAC: permissions tied to job role
- rule-based: if-then logic, e.g., firewall rules
- ABAC: attributes — user, resource, environment — evaluated dynamically
- time-of-day restrictions
- least privilege as the guiding principle underneath all of them
MFA implementations include biometrics, hard/soft authentication tokens, and security keys, built from the four factor categories: something you know, have, are, and somewhere you are (location).
Password concepts cover length, complexity, reuse, expiration, and age as best practices, alongside password managers and the passwordless trend replacing all of it.
PAM tools provide just-in-time permissions (elevated access granted only for a defined window), password vaulting (credentials stored/rotated centrally rather than known by a human), and ephemeral credentials (short-lived, auto-expiring).
4.7 Automation and Orchestration
Use cases:
- user and resource provisioning
- guardrails: automated policy enforcement preventing risky configurations
- security groups
- automatic ticket creation and escalation
- enabling/disabling services or access programmatically
- continuous integration and testing
- integrations via APIs
The benefits CompTIA wants you to recite:
- efficiency/time savings
- enforcing baselines consistently
- standard infrastructure configurations
- scaling securely: security keeps pace with growth instead of lagging it
- employee retention: less repetitive manual toil
- faster reaction time
- acting as a workforce multiplier
The other side of the ledger: added complexity, cost, the risk of a single point of failure if the automation itself breaks or is compromised, technical debt (quick automations that become hard to maintain), and ongoing supportability.
4.8 Incident Response Activities
The incident response lifecycle — a cycle, not a one-way list
The IR process, in order:
- preparation: before anything happens — plans, tools, training in place
- detection
- analysis
- containment
- eradication
- recovery
- lessons learned: see Confusables for the containment/eradication/recovery distinction specifically
Training and testing (tabletop exercises — discussion-based, no systems touched; and simulations — a more realistic, interactive mock scenario) build and validate the plan without waiting for a real incident. Root cause analysis asks why the incident was possible, not just what happened.
Threat hunting is proactive — searching for compromise indicators before an alert ever fires, rather than waiting for one.
Digital forensics runs alongside IR when evidence needs to hold up:
- legal hold: a legal obligation to preserve relevant data, suspending normal deletion
- chain of custody: an unbroken, documented record of who handled evidence and when
- acquisition: capturing evidence, typically via a forensically sound image
- reporting
- preservation
- e-discovery: identifying and producing electronically stored information for legal proceedings
4.9 Data Sources to Support an Investigation
Log data spans firewall logs, application logs, endpoint logs, OS-specific security logs, IPS/IDS logs, network logs, and metadata (data about the data — timestamps, headers, file properties — often as revealing as content).
Beyond logs, an investigation draws on vulnerability scans, automated reports, dashboards, and packet captures (full payload capture, richer but heavier than NetFlow's metadata-only view).
Confusables — Don't Mix These Up
BYOD vs. COPE vs. CYOD
| Term | Who owns the device | Personal use allowed | Corporate control |
|---|---|---|---|
| BYOD (Bring Your Own Device) | Employee | Yes — it's their device | Lowest — limited to what the user allows via enrollment |
| COPE (Corporate-Owned, Personally Enabled) | Organization | Yes, alongside work use | High — fully managed corporate device |
| CYOD (Choose Your Own Device) | Organization | Typically limited/none | High — user picks hardware from an approved list, managed like any corporate device |
False Positive vs. False Negative
| Term | What happened | Practical risk |
|---|---|---|
| False positive | A benign event was flagged as malicious | Alert fatigue, wasted investigation time |
| False negative | An actual malicious event was NOT flagged | The worse outcome — a real threat goes undetected |
CVE vs. CVSS
| Term | What it is | Answers |
|---|---|---|
| CVE (Common Vulnerabilities and Exposures) | A standardized identifier/dictionary entry for one specific known vulnerability | "Which vulnerability is this?" |
| CVSS (Common Vulnerability Scoring System) | A numeric severity score (with environmental/temporal adjustments) for a vulnerability | "How severe is it?" |
SPF vs. DKIM vs. DMARC
| Term | What it verifies | Mechanism | Exam tell |
|---|---|---|---|
| SPF | Was this email sent from an IP authorized to send for this domain? | DNS TXT record listing authorized sending servers | "The receiving server checked the sender's IP against a published list" |
| DKIM | Was this message's content unaltered and genuinely from this domain? | Cryptographic signature in the header, verified against a public key in DNS | "A digital signature confirmed the message wasn't tampered with" |
| DMARC | What should happen if SPF and/or DKIM fail, and who gets told? | Policy (none/quarantine/reject) plus reporting, built on SPF/DKIM alignment | "Failed messages were quarantined and a report was sent to the domain owner" |
LDAP vs. OAuth vs. SAML
| Term | Primary purpose | Typical use |
|---|---|---|
| LDAP | Directory lookup/bind protocol | Querying/authenticating against a directory (e.g., AD) — often internal, not itself a web SSO mechanism |
| OAuth | Delegated authorization framework | Issuing a scoped token so an app can act on a user's behalf, without handing over the password |
| SAML | XML-based authentication/authorization assertion standard | Browser-based enterprise SSO between an identity provider and a service provider |
EDR vs. XDR vs. Antivirus
| Term | Scope | Behavior |
|---|---|---|
| Antivirus | Single endpoint | Signature/heuristic-based malware detection and prevention |
| EDR | Single endpoint, but continuous | Ongoing behavioral monitoring, investigation, and response actions (isolate, kill process) beyond simple AV |
| XDR | Across multiple domains | Correlates signals across endpoint, email, identity, and cloud apps — a superset of EDR's telemetry scope |
Containment vs. Eradication vs. Recovery
| Term | Goal | Exam tell |
|---|---|---|
| Containment | Stop the incident from spreading | "The affected host was isolated from the network" |
| Eradication | Remove the root cause from the environment | "The malware was deleted and the exploited vulnerability was patched" |
| Recovery | Restore normal operation and confirm it's clean | "Systems were restored from backup and monitored for recurrence before returning to production" |
Sanitization vs. Destruction
| Term | What happens to the data | What happens to the media | Reusable afterward? |
|---|---|---|---|
| Sanitization | Removed so it cannot be recovered | Media itself is preserved | Yes |
| Destruction | Removed along with the media | Media is physically destroyed (shredded, pulverized, incinerated) | No |
Exam Traps
- BYOD/COPE/CYOD is about ownership + personal-use rights, not just "who manages it." COPE and CYOD both end up fully corporate-managed — the differentiator between them is how the device was selected/sourced, not the management outcome.
- CVE names it, CVSS scores it. A stem that gives you a numeric severity score is asking about CVSS even if it never says the word; a stem asking "which specific flaw" is CVE.
- A false negative is worse than a false positive, even though false positives feel more annoying day-to-day — don't let annoyance bias which one the exam treats as the bigger risk.
- SPF checks the sending IP, DKIM checks message integrity/signature, DMARC is the policy + reporting layer on top of both. A stem about "what to do when authentication fails" is DMARC, not SPF or DKIM individually.
- LDAP is not an SSO protocol by itself — it's a directory access protocol. The exam lists it under SSO because directories often sit behind SSO, but don't pick LDAP for a stem describing browser-based federation between an IdP and a web app; that's SAML (or OAuth/OIDC).
- EDR vs. XDR is a scope question, not a "better vs. worse" question. If the stem describes correlation across endpoint, email, and identity signals, that's XDR; if it's endpoint-only behavioral monitoring and response, that's EDR.
- Containment ≠ eradication. Isolating a host (containment) does not remove the malware or close the vulnerability (eradication) — a stem describing only isolation hasn't described eradication yet, no matter how final it sounds.
- Sanitization can leave the media intact; destruction cannot. If a stem says the drive was later reissued to someone else, that's sanitization, not destruction — destruction never leaves reusable media.
- Conditional Access is not the same thing as classic NAC. Conditional Access gates access based on identity/device signals at the application/cloud layer; 802.1X-style NAC gates access at the network port itself. A stem about a switch port refusing to forward traffic until 802.1X authentication succeeds is NAC, not Conditional Access.
Acronym Table
| Acronym | Expansion | One-line meaning |
|---|---|---|
| MDM | Mobile Device Management | Platform for enrolling, configuring, and managing mobile/endpoint devices |
| BYOD | Bring Your Own Device | Employee-owned device enrolled for work use |
| COPE | Corporate-Owned, Personally Enabled | Org-owned device that also permits personal use |
| CYOD | Choose Your Own Device | User selects from an approved list; device is corporate-owned/managed |
| WPA3 | Wi-Fi Protected Access 3 | Current wireless encryption/security standard |
| AAA | Authentication, Authorization, Accounting | Framework for controlling and logging access |
| RADIUS | Remote Authentication Dial-In User Service | Centralized AAA protocol, commonly for network/Wi-Fi access |
| EAP | Extensible Authentication Protocol | Authentication framework used within 802.1X |
| ICS | Industrial Control System | Systems managing physical industrial processes |
| SCADA | Supervisory Control and Data Acquisition | A type of ICS for monitoring/controlling distributed processes |
| RTOS | Real-Time Operating System | OS guaranteeing processing within a fixed time constraint |
| IoT | Internet of Things | Network-connected, often resource-constrained devices |
| SAST | Static Application Security Testing | Analyzes source code without executing it |
| DAST | Dynamic Application Security Testing | Tests a running application from the outside |
| OSINT | Open-Source Intelligence | Threat/security intel gathered from publicly available sources |
| ISAO | Information Sharing and Analysis Organization | Group facilitating threat-intel sharing between organizations |
| CVE | Common Vulnerabilities and Exposures | Standardized identifier for a specific known vulnerability |
| CVSS | Common Vulnerability Scoring System | Numeric severity score for a vulnerability |
| SCAP | Security Content Automation Protocol | NIST standard for automating vulnerability/configuration checks |
| SIEM | Security Information and Event Management | Aggregates, correlates, and alerts on log data at scale |
| DLP | Data Loss Prevention | Detects/blocks sensitive data leaving where it shouldn't |
| SNMP | Simple Network Management Protocol | Protocol for monitoring/managing network devices; traps push alert conditions |
| NAC | Network Access Control | Gates network access based on device/identity posture |
| EDR | Endpoint Detection and Response | Continuous endpoint monitoring plus investigation/response actions |
| XDR | Extended Detection and Response | Correlates detection/response signals across multiple domains |
| UBA | User Behavior Analytics | Detects anomalies in user activity patterns |
| DMARC | Domain-based Message Authentication, Reporting & Conformance | Policy + reporting layer built on SPF/DKIM alignment |
| DKIM | DomainKeys Identified Mail | Cryptographic signature verifying message integrity/origin |
| SPF | Sender Policy Framework | DNS record listing servers authorized to send for a domain |
| FIM | File Integrity Monitoring | Detects unauthorized changes to critical files/configs |
| SELinux | Security-Enhanced Linux | Linux mandatory access control implementation |
| LDAP | Lightweight Directory Access Protocol | Protocol for querying/binding against a directory service |
| SSO | Single Sign-On | One authentication grants access across multiple systems |
| SAML | Security Assertion Markup Language | XML-based standard for exchanging auth assertions (SSO/federation) |
| OAuth | (not an acronym — open standard) | Delegated authorization framework using scoped tokens |
| MFA | Multifactor Authentication | Requires two or more independent proof factors |
| PAM | Privileged Access Management | Tools/practices controlling and limiting privileged account use |
| PIM | Privileged Identity Management | Microsoft Entra's just-in-time privileged role activation feature |
| JIT | Just-in-Time (permissions) | Elevated access granted only for a defined, limited window |
| RCA | Root Cause Analysis | Determining the underlying reason an incident was possible |
Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.
Interactive drills
Flashcards
Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.
Due today: 20
Flipped: 0/20
Quiz
10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.
Score: 0/10
Q1EasyA vulnerability scan report lists a standardized identifier for a specific flaw alongside a severity score of 9.8 out of 10. Which two SY0-701 concepts are being described, in that order?
Q2EasyWhich mobile deployment model has the organization provide a list of approved devices, requiring the employee to select and use one of those specific devices, which then remains corporate-owned and managed?
Q3EasyAn alert fires flagging a legitimate scheduled backup job as ransomware-like behavior, but investigation finds no malicious activity occurred. What is this called?
Q4MediumA vendor security suite shows a single incident that automatically pulls together an endpoint alert, a phishing email flagged by the mail gateway, and a risky sign-in from the identity provider — all correlated out of the box as one incident by that suite. Which capability is this?
Q5MediumA receiving mail server checks whether the connecting IP address is listed among a domain's authorized senders, as published in a DNS record. Which mechanism performed this check?
Q6MediumA switch port refuses to forward any traffic from a newly connected laptop until the laptop completes 802.1X authentication. Which control is this?
Q7MediumAn organization decommissions old hard drives by shredding them into fragments so that no data or component of the drive can ever be recovered or reused. Which asset disposal concept is this?
Q8MediumAn administrator requests elevated access to a production system for a specific task. The system automatically grants the elevated role for a two-hour window and automatically revokes it afterward with no manual step. Which PAM capability is this?
Q9Hard, PBQ — incident response phase orderingthe organization's SOC responds to an incident with the following events, listed out of order:
Q10Hard, PBQ — matching email security records to what they verifyFor each statement, identify which mechanism it describes: