TB.

Security+ SY0-701 · Domain 4

Domain 4: Security Operations

Why This Domain Matters

Domain 4 is the single largest slice of the SY0-701 exam — bigger than Domain 1 and Domain 3 combined — and it's also the one most closely aligned with day-to-day IT/security-operations work.

Baselines and hardening, alerting and monitoring, identity and access management — these are the daily reality of running an endpoint/identity security stack, and the exam mostly asks you to relabel that work in CompTIA's vocabulary, then fill in the adjacent pieces day-to-day tickets don't force you to touch (vulnerability scoring math, formal incident-response phase names, digital forensics chain of custody).

Target 90%+ on this domain — 28% of the final score rides on it. The one trap: don't let familiarity breed sloppiness. The exam tests the precise CompTIA term for things practitioners do casually and messily on the job — know the vocabulary as rigorously as the click-path.

Objective-by-Objective Breakdown

4.1 Common Security Techniques for Computing Resources

Secure baselines are established (a documented target configuration), deployed (rolled out to the fleet), and maintained (drift is detected and corrected over time) — a lifecycle, not a one-off event.

Hardening applies across a long list of targets: mobile devices, workstations, switches, routers, cloud infrastructure, servers, ICS/SCADA, embedded systems, RTOS, and IoT devices — each with a different practical ceiling on how hard it can be hardened (an IoT sensor or an ICS controller often can't run an agent or take frequent patches at all).

Wireless installation considerations — site surveys (physically measuring signal coverage and interference before deployment) and heat maps (the visual output of that survey, showing signal strength across a floor plan) — are RF planning tasks that happen before a network exists.

Mobile solutions cover MDM (the management platform itself) and three deployment models — BYOD, COPE, CYOD, detailed in Confusables — plus connection methods: cellular, Wi-Fi, Bluetooth, each with a different exposure profile.

Wireless security settings are WPA3 (the current encryption standard, replacing WPA2), AAA/RADIUS (centralized authentication for network access), and the cryptographic and authentication protocols riding on top (e.g., EAP variants).

Application security covers input validation (rejecting malformed/malicious input before it's processed — the root cause CompTIA blames for injection attacks in Domain 2), secure cookies (flags like Secure and HttpOnly that limit how a session cookie can be transmitted or accessed), static code analysis (scanning source code for flaws without executing it), and code signing (a cryptographic signature proving code came from a trusted publisher and wasn't tampered with).

Sandboxing isolates untrusted code/files in a contained environment to observe behavior without risking the host. Monitoring closes the loop — baselines and hardening are worthless without ongoing visibility that they're still in effect.

4.2 Asset Management

Asset management runs a lifecycle:

  • acquisition/procurement: bringing the asset in
  • assignment/accounting: recording who owns it and how it's classified
  • monitoring/asset tracking: inventory — knowing what you have — and enumeration — actively listing/discovering it
  • disposal/decommissioning at end of life: sanitization, destruction, certification that it was done, and data retention obligations that might outlive the device itself

4.3 Vulnerability Management

Identification methods: vulnerability scans (automated checks against known-vulnerability databases), application security testing split into static (source code, not running) and dynamic (the running application, black-box) analysis, package monitoring (watching dependencies for known-vulnerable versions), threat feeds (OSINT — open-source intelligence; proprietary/third-party feeds; information-sharing organizations, e.g., an ISAO; and dark web monitoring), penetration testing, responsible disclosure programs including bug bounties, and system/process audits.

Analysis then has to confirm a finding is real (false positive vs. false negative — see Confusables), prioritize it, and score it: CVE identifies which vulnerability it is; CVSS scores how severe it is (see Confusables).

Vulnerability classification, exposure factor (the percentage of an asset's value that would be lost if the risk materialized), environmental variables (context specific to your environment that can raise or lower a CVSS base score), industry/organizational impact, and risk tolerance all feed the prioritization call.

Response and remediation options are patching, insurance (transferring residual risk), segmentation, compensating controls (an alternative safeguard when the primary control can't be applied), and exceptions/exemptions (formally accepted, documented deviations).

Validation closes the loop: rescanning, audit, verification that remediation actually worked — then reporting.

4.4 Security Alerting and Monitoring

Monitoring spans systems, applications, and infrastructure.

The activities are log aggregation (pulling logs into one place), alerting, scanning, reporting, archiving (retaining logs for later use — investigations, compliance), and alert response/remediation, which includes quarantine (isolating a flagged item) and alert tuning (adjusting thresholds/rules to cut false positives without missing real threats).

The tool list is dense:

  • SCAP: Security Content Automation Protocol — a NIST standard for expressing vulnerability/configuration checks in a standardized, automatable format
  • benchmarks: e.g., CIS benchmarks — hardening standards a baseline can be measured against
  • agent-based vs. agentless monitoring
  • SIEM
  • antivirus
  • DLP
  • SNMP traps: alerts pushed from network devices when a monitored condition is hit
  • NetFlow: network traffic flow metadata, not full packet capture
  • vulnerability scanners

4.5 Enterprise Capabilities to Enhance Security

Firewalls run on rules/access lists filtering by ports/protocols, and can carve out screened subnets (the modern name for a DMZ). IDS/IPS detection relies on signatures (known-pattern matching) with an eye on trends (behavioral/anomaly detection catching what signatures miss).

Web filters can be agent-based (client-side) or run through a centralized proxy, and act via URL scanning, content categorization, block rules, and reputation scoring.

OS security includes Group Policy (the on-premises, Active Directory-joined policy mechanism) and SELinux (a Linux mandatory access control implementation).

Secure protocol implementation means picking the right protocol, port, and transport method for the job — this is where Domain 3's TLS/IPsec knowledge gets applied operationally. DNS filtering blocks resolution to known-malicious domains before a connection is even attempted.

Email security rests on DMARC, DKIM, and SPF (see Confusables) plus a security gateway inspecting mail in transit. File integrity monitoring (FIM) watches critical files/configs for unauthorized change. DLP stops sensitive data leaving where it shouldn't. NAC gates network access based on device/identity posture.

EDR/XDR and user behavior analytics round out detection and response (see Confusables for EDR vs. XDR vs. antivirus).

4.6 Identity and Access Management

Provisioning/de-provisioning creates and removes accounts across their lifecycle. Permission assignments carry implications — over-provisioning is its own risk, independent of whether an account is ever misused. Identity proofing verifies a person really is who they claim before a credential is ever issued.

Federation lets identity trust extend across organizational boundaries; SSO is the user-facing result, implemented via LDAP (directory lookup/bind, not itself an SSO protocol), OAuth (a delegated-authorization framework, token-based), and SAML (an XML-based assertion standard built for browser-based enterprise SSO) — see Confusables for how these three actually differ despite all appearing under the same SSO heading.

Interoperability is systems working together across those federated/SSO boundaries. Attestation proves a device's health state (e.g., TPM/Secure Boot integrity) before it's trusted, which is a different concept from identity proofing (which is about a person).

Access controls:

  • MAC: labels set centrally, user can't override — think classified environments
  • DAC: the resource owner decides
  • RBAC: permissions tied to job role
  • rule-based: if-then logic, e.g., firewall rules
  • ABAC: attributes — user, resource, environment — evaluated dynamically
  • time-of-day restrictions
  • least privilege as the guiding principle underneath all of them

MFA implementations include biometrics, hard/soft authentication tokens, and security keys, built from the four factor categories: something you know, have, are, and somewhere you are (location).

Password concepts cover length, complexity, reuse, expiration, and age as best practices, alongside password managers and the passwordless trend replacing all of it.

PAM tools provide just-in-time permissions (elevated access granted only for a defined window), password vaulting (credentials stored/rotated centrally rather than known by a human), and ephemeral credentials (short-lived, auto-expiring).

4.7 Automation and Orchestration

Use cases:

  • user and resource provisioning
  • guardrails: automated policy enforcement preventing risky configurations
  • security groups
  • automatic ticket creation and escalation
  • enabling/disabling services or access programmatically
  • continuous integration and testing
  • integrations via APIs

The benefits CompTIA wants you to recite:

  • efficiency/time savings
  • enforcing baselines consistently
  • standard infrastructure configurations
  • scaling securely: security keeps pace with growth instead of lagging it
  • employee retention: less repetitive manual toil
  • faster reaction time
  • acting as a workforce multiplier

The other side of the ledger: added complexity, cost, the risk of a single point of failure if the automation itself breaks or is compromised, technical debt (quick automations that become hard to maintain), and ongoing supportability.

4.8 Incident Response Activities

The incident response lifecycle — a cycle, not a one-way list

The IR process, in order:

  • preparation: before anything happens — plans, tools, training in place
  • detection
  • analysis
  • containment
  • eradication
  • recovery
  • lessons learned: see Confusables for the containment/eradication/recovery distinction specifically

Training and testing (tabletop exercises — discussion-based, no systems touched; and simulations — a more realistic, interactive mock scenario) build and validate the plan without waiting for a real incident. Root cause analysis asks why the incident was possible, not just what happened.

Threat hunting is proactive — searching for compromise indicators before an alert ever fires, rather than waiting for one.

Digital forensics runs alongside IR when evidence needs to hold up:

  • legal hold: a legal obligation to preserve relevant data, suspending normal deletion
  • chain of custody: an unbroken, documented record of who handled evidence and when
  • acquisition: capturing evidence, typically via a forensically sound image
  • reporting
  • preservation
  • e-discovery: identifying and producing electronically stored information for legal proceedings

4.9 Data Sources to Support an Investigation

Log data spans firewall logs, application logs, endpoint logs, OS-specific security logs, IPS/IDS logs, network logs, and metadata (data about the data — timestamps, headers, file properties — often as revealing as content).

Beyond logs, an investigation draws on vulnerability scans, automated reports, dashboards, and packet captures (full payload capture, richer but heavier than NetFlow's metadata-only view).

Confusables — Don't Mix These Up

BYOD vs. COPE vs. CYOD

TermWho owns the devicePersonal use allowedCorporate control
BYOD (Bring Your Own Device)EmployeeYes — it's their deviceLowest — limited to what the user allows via enrollment
COPE (Corporate-Owned, Personally Enabled)OrganizationYes, alongside work useHigh — fully managed corporate device
CYOD (Choose Your Own Device)OrganizationTypically limited/noneHigh — user picks hardware from an approved list, managed like any corporate device

False Positive vs. False Negative

TermWhat happenedPractical risk
False positiveA benign event was flagged as maliciousAlert fatigue, wasted investigation time
False negativeAn actual malicious event was NOT flaggedThe worse outcome — a real threat goes undetected

CVE vs. CVSS

TermWhat it isAnswers
CVE (Common Vulnerabilities and Exposures)A standardized identifier/dictionary entry for one specific known vulnerability"Which vulnerability is this?"
CVSS (Common Vulnerability Scoring System)A numeric severity score (with environmental/temporal adjustments) for a vulnerability"How severe is it?"

SPF vs. DKIM vs. DMARC

TermWhat it verifiesMechanismExam tell
SPFWas this email sent from an IP authorized to send for this domain?DNS TXT record listing authorized sending servers"The receiving server checked the sender's IP against a published list"
DKIMWas this message's content unaltered and genuinely from this domain?Cryptographic signature in the header, verified against a public key in DNS"A digital signature confirmed the message wasn't tampered with"
DMARCWhat should happen if SPF and/or DKIM fail, and who gets told?Policy (none/quarantine/reject) plus reporting, built on SPF/DKIM alignment"Failed messages were quarantined and a report was sent to the domain owner"

LDAP vs. OAuth vs. SAML

TermPrimary purposeTypical use
LDAPDirectory lookup/bind protocolQuerying/authenticating against a directory (e.g., AD) — often internal, not itself a web SSO mechanism
OAuthDelegated authorization frameworkIssuing a scoped token so an app can act on a user's behalf, without handing over the password
SAMLXML-based authentication/authorization assertion standardBrowser-based enterprise SSO between an identity provider and a service provider

EDR vs. XDR vs. Antivirus

TermScopeBehavior
AntivirusSingle endpointSignature/heuristic-based malware detection and prevention
EDRSingle endpoint, but continuousOngoing behavioral monitoring, investigation, and response actions (isolate, kill process) beyond simple AV
XDRAcross multiple domainsCorrelates signals across endpoint, email, identity, and cloud apps — a superset of EDR's telemetry scope

Containment vs. Eradication vs. Recovery

TermGoalExam tell
ContainmentStop the incident from spreading"The affected host was isolated from the network"
EradicationRemove the root cause from the environment"The malware was deleted and the exploited vulnerability was patched"
RecoveryRestore normal operation and confirm it's clean"Systems were restored from backup and monitored for recurrence before returning to production"

Sanitization vs. Destruction

TermWhat happens to the dataWhat happens to the mediaReusable afterward?
SanitizationRemoved so it cannot be recoveredMedia itself is preservedYes
DestructionRemoved along with the mediaMedia is physically destroyed (shredded, pulverized, incinerated)No

Exam Traps

  • BYOD/COPE/CYOD is about ownership + personal-use rights, not just "who manages it." COPE and CYOD both end up fully corporate-managed — the differentiator between them is how the device was selected/sourced, not the management outcome.
  • CVE names it, CVSS scores it. A stem that gives you a numeric severity score is asking about CVSS even if it never says the word; a stem asking "which specific flaw" is CVE.
  • A false negative is worse than a false positive, even though false positives feel more annoying day-to-day — don't let annoyance bias which one the exam treats as the bigger risk.
  • SPF checks the sending IP, DKIM checks message integrity/signature, DMARC is the policy + reporting layer on top of both. A stem about "what to do when authentication fails" is DMARC, not SPF or DKIM individually.
  • LDAP is not an SSO protocol by itself — it's a directory access protocol. The exam lists it under SSO because directories often sit behind SSO, but don't pick LDAP for a stem describing browser-based federation between an IdP and a web app; that's SAML (or OAuth/OIDC).
  • EDR vs. XDR is a scope question, not a "better vs. worse" question. If the stem describes correlation across endpoint, email, and identity signals, that's XDR; if it's endpoint-only behavioral monitoring and response, that's EDR.
  • Containment ≠ eradication. Isolating a host (containment) does not remove the malware or close the vulnerability (eradication) — a stem describing only isolation hasn't described eradication yet, no matter how final it sounds.
  • Sanitization can leave the media intact; destruction cannot. If a stem says the drive was later reissued to someone else, that's sanitization, not destruction — destruction never leaves reusable media.
  • Conditional Access is not the same thing as classic NAC. Conditional Access gates access based on identity/device signals at the application/cloud layer; 802.1X-style NAC gates access at the network port itself. A stem about a switch port refusing to forward traffic until 802.1X authentication succeeds is NAC, not Conditional Access.

Acronym Table

AcronymExpansionOne-line meaning
MDMMobile Device ManagementPlatform for enrolling, configuring, and managing mobile/endpoint devices
BYODBring Your Own DeviceEmployee-owned device enrolled for work use
COPECorporate-Owned, Personally EnabledOrg-owned device that also permits personal use
CYODChoose Your Own DeviceUser selects from an approved list; device is corporate-owned/managed
WPA3Wi-Fi Protected Access 3Current wireless encryption/security standard
AAAAuthentication, Authorization, AccountingFramework for controlling and logging access
RADIUSRemote Authentication Dial-In User ServiceCentralized AAA protocol, commonly for network/Wi-Fi access
EAPExtensible Authentication ProtocolAuthentication framework used within 802.1X
ICSIndustrial Control SystemSystems managing physical industrial processes
SCADASupervisory Control and Data AcquisitionA type of ICS for monitoring/controlling distributed processes
RTOSReal-Time Operating SystemOS guaranteeing processing within a fixed time constraint
IoTInternet of ThingsNetwork-connected, often resource-constrained devices
SASTStatic Application Security TestingAnalyzes source code without executing it
DASTDynamic Application Security TestingTests a running application from the outside
OSINTOpen-Source IntelligenceThreat/security intel gathered from publicly available sources
ISAOInformation Sharing and Analysis OrganizationGroup facilitating threat-intel sharing between organizations
CVECommon Vulnerabilities and ExposuresStandardized identifier for a specific known vulnerability
CVSSCommon Vulnerability Scoring SystemNumeric severity score for a vulnerability
SCAPSecurity Content Automation ProtocolNIST standard for automating vulnerability/configuration checks
SIEMSecurity Information and Event ManagementAggregates, correlates, and alerts on log data at scale
DLPData Loss PreventionDetects/blocks sensitive data leaving where it shouldn't
SNMPSimple Network Management ProtocolProtocol for monitoring/managing network devices; traps push alert conditions
NACNetwork Access ControlGates network access based on device/identity posture
EDREndpoint Detection and ResponseContinuous endpoint monitoring plus investigation/response actions
XDRExtended Detection and ResponseCorrelates detection/response signals across multiple domains
UBAUser Behavior AnalyticsDetects anomalies in user activity patterns
DMARCDomain-based Message Authentication, Reporting & ConformancePolicy + reporting layer built on SPF/DKIM alignment
DKIMDomainKeys Identified MailCryptographic signature verifying message integrity/origin
SPFSender Policy FrameworkDNS record listing servers authorized to send for a domain
FIMFile Integrity MonitoringDetects unauthorized changes to critical files/configs
SELinuxSecurity-Enhanced LinuxLinux mandatory access control implementation
LDAPLightweight Directory Access ProtocolProtocol for querying/binding against a directory service
SSOSingle Sign-OnOne authentication grants access across multiple systems
SAMLSecurity Assertion Markup LanguageXML-based standard for exchanging auth assertions (SSO/federation)
OAuth(not an acronym — open standard)Delegated authorization framework using scoped tokens
MFAMultifactor AuthenticationRequires two or more independent proof factors
PAMPrivileged Access ManagementTools/practices controlling and limiting privileged account use
PIMPrivileged Identity ManagementMicrosoft Entra's just-in-time privileged role activation feature
JITJust-in-Time (permissions)Elevated access granted only for a defined, limited window
RCARoot Cause AnalysisDetermining the underlying reason an incident was possible

Drills: 20 flashcards + 10 exam-realistic questions, at the end of this page.

Interactive drills

Flashcards

Click a card to flip it, then rate how well you knew it — cards you rate lower come back sooner. 20 cards from real study drills, scheduled with spaced repetition.

Due today: 20

Flipped: 0/20

Quiz

10 exam-style questions, easy to hard. Pick an option to see whether you're right, and why.

Score: 0/10

Q1EasyA vulnerability scan report lists a standardized identifier for a specific flaw alongside a severity score of 9.8 out of 10. Which two SY0-701 concepts are being described, in that order?

Q2EasyWhich mobile deployment model has the organization provide a list of approved devices, requiring the employee to select and use one of those specific devices, which then remains corporate-owned and managed?

Q3EasyAn alert fires flagging a legitimate scheduled backup job as ransomware-like behavior, but investigation finds no malicious activity occurred. What is this called?

Q4MediumA vendor security suite shows a single incident that automatically pulls together an endpoint alert, a phishing email flagged by the mail gateway, and a risky sign-in from the identity provider — all correlated out of the box as one incident by that suite. Which capability is this?

Q5MediumA receiving mail server checks whether the connecting IP address is listed among a domain's authorized senders, as published in a DNS record. Which mechanism performed this check?

Q6MediumA switch port refuses to forward any traffic from a newly connected laptop until the laptop completes 802.1X authentication. Which control is this?

Q7MediumAn organization decommissions old hard drives by shredding them into fragments so that no data or component of the drive can ever be recovered or reused. Which asset disposal concept is this?

Q8MediumAn administrator requests elevated access to a production system for a specific task. The system automatically grants the elevated role for a two-hour window and automatically revokes it afterward with no manual step. Which PAM capability is this?

Q9Hard, PBQ — incident response phase orderingthe organization's SOC responds to an incident with the following events, listed out of order:

Q10Hard, PBQ — matching email security records to what they verifyFor each statement, identify which mechanism it describes: