1/16
CompTIA Security+ (SY0-701): General Security Concepts Literacy (Beginner Level) About this Skill Benchmark The General Security Concepts Literacy (Beginner Level) benchmark measures your understanding of the foundational elements of cybersecurity. You will be evaluated on your knowledge of the core principles that guide security practices, such as confidentiality, integrity, and availability (the CIA triad), and the types of security controls used to protect assets. A learner who scores high on this benchmark demonstrates literacy in many areas of this domain and understands the essential principles and policies that form the bedrock of information security, including the identification of security goals. Topics covered: Provide an overview of the CIA Triad which includes confidentiality, integrity, and availability Define non-repudiation Compare authentication, authorization, and accounting Outline how to authenticate people Outline how to authenticate systems Compare authorization models Compare control categories like technical, managerial, operational, and physical Compare control types including preventive, deterrent, detective, corrective, compensating, and directive Outline the use of gap analysis in the context of security Provide an overview of the Zero Trust control plane including adaptive identity, threat scope reduction, policy-driven access control, and Policy Administrator Provide an overview of the Zero Trust data plane which includes implicit trust zones, subject/system, and Policy Enforcement Points Compare deception technologies such as honeypots, honeynets, honeyfiles, and honeytokens Define preventative physical security controls like bollards, access control vestibule, access badges/cards, fencing, gates, mantraps, and security guards Outline detective physical security controls like video surveillance, lighting, and infrared, pressure, microwave, and ultrasonic sensors Outline change management business processes including approval, ownership, stakeholders, impact analysis, test results, backout plan, maintenance window, and standard operating procedures Define change management technical implications like allow lists, deny lists, restricted activities, downtime, service restart, application restart, legacy applications, and dependencies Understand the importance of comprehensive documentation and version control View less Why take a Skill Benchmark? Determine your skill level in a particular area โ you canโt fail Get personalized recommendations targeted to improving your skills Skip the material you already know Help your company gauge where to target its resources Challenge yourself to learn new skills and improve your score What to expect: Mostly multiple choice, but some matching and ranking questions Immediate results and learning recommendations Your scores not visible to other learners
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Which security goal controls an attacker's ability to get unauthorized access to data or information from an application or system?
Instruction:ย Choose the option that best answers the question.ย
Non-repudiation
Integrity
Confidentiality
Availability
Confidentiality
Which security control enforces the inability of a subject to deny that they participated in a digital transaction, agreement, contract, or communication such as an email?
Instruction:ย Choose the option that best answers the question.ย
Integrity
Availability
Non-repudiation
Confidentiality
Non-repudiation
What is the process of granting an authenticated entity permission to access a resource or perform a specific function?
Instruction:ย Choose the option that best answers the question.ย
Availability
Authorization
Authentication
Accounting
Authorization
Which of these are common ways to authenticate people?
Instruction:ย Choose all options that best answer the question.ย
A network interface MAC address
An X.509 device certificate
A QR or other code they present on a device
A smart card token or fob that they possess
A biometric attribute
A password, PIN, or passphrase they know
A QR or other code they present on a device
A smart card token or fob that they possess
A biometric attribute
A password, PIN, or passphrase they know
What is one way to enable authentication of non-traditional network endpoints such as smart card readers, HVAC systems, medical equipment, and IP-enabled door locks?
Instruction:ย Choose the option that best answers the question.ย
Protected access files
Packet mode
Repudiation
Endpoint fingerprinting
Endpoint fingerprinting
What is a strict mathematical model where access to resources is determined by the system based on predefined security labels and rules?
Instruction:ย Choose the option that best answers the question.ย
DAC
MAC
ABAC
RBAC
MAC
Which category of controls supports ongoing maintenance, due care, and continual improvement such as conducting tested patch management?
Instruction:ย Choose the option that best answers the question.ย
Technical
Physical
Managerial
Operational
Operational
Which type of security control is made up of mandatory policies and regulations that are in place to maintain consistency and compliance?
Instruction:ย Choose the option that best answers the question.ย
Preventative
Deterrent
Corrective
Directive
Directive
What is a comprehensive appraisal that helps organizations determine the difference between the current state of their information security to specific industry requirements guidance and best practices?
Instruction:ย Choose the option that best answers the question.ย
External audit
Security controls assessment
Vulnerability assessment
Gap analysis
Gap analysis
What is the term for an evolving set of cybersecurity initiatives that move defenses from static, network-based perimeters to focus on users, assets, and resources?
Instruction:ย Choose the option that best answers the question.ย
Zero trust
Trust but verify
Transitive trust
Zero-day malware
Zero trust
What is defined by explicit trust zones, such as data centers, DMZs, and the public Internet?
Instruction:ย Choose the option that best answers the question.ย
Zero Trust data plane
Zero Trust service plane
Zero Trust control plane
Zero Trust management plane
Zero Trust data plane
What is a system (e.g., a web server) or resource that is designed to be attractive to potential attackers and intruders?
Instruction:ย Choose the option that best answers the question.ย
Honey file
Honeynet
Honeypot
Honey token
Honeypot
Which are preventative physical security controls?
Instruction:ย Choose all options that best answer the question.ย
IDS
Signage
Fences
Mantraps
Gates
Bollards
Signage
Fences
Mantraps
Gates
Bollards
Which lightning systems are designed for reserve or on-hold use or to supplement permanent systems?
Instruction:ย Choose the option that best answers the question.ย
Continuous lighting
Moveable lighting hardware
Emergency lighting
Stand-by lighting
Stand-by lighting
What is the methodical approach to handling the transition or modification of an organization's goals, processes, or technologies?
Instruction:ย Choose the option that best answers the question.ย
Change management
Configuration management
Problem management
Incident management
Change management
Which initiative consists of planned and unplanned downtime (e.g., an outage) and must be considered with technical change management when making modifications or performing migrations?
Instruction:ย Choose the option that best answers the question.ย
Availability
Resiliency
Capacity
Durability
Availability
What is a set of data, tools, utilities, and processes used to support configuration management?
Instruction:ย Choose the option that best answers the question.ย
CMS
CMDB
ITSM
CSP
CMS