CompTIA Security+ SY0-701 Exam Objectives Notes

CompTIA Security+ Certification Exam Objectives \n\n## Overview \n- Certification Exam Name: CompTIA Security+ \n- Exam Number: SY0-701 V7 \n- Copyright: © 2023 CompTIA, Inc. All rights reserved. \n\n--- \n## About the Exam \n- The CompTIA Security+ certification exam verifies the candidate's: \n - Knowledge and skills necessary to assess the security posture of an enterprise environment. \n - Ability to recommend and implement appropriate security solutions. \n - Capacity to monitor and secure hybrid environments, which include: \n - Cloud \n - Mobile \n - Internet of Things (IoT) \n - Awareness of applicable regulations and policies, inclusive of governance, risk, and compliance principles. \n - Skills in identifying, analyzing, and responding to security events and incidents. \n\n## Exam Accreditation \n- The CompTIA Security+ exam is accredited by ANSI, in compliance with ISO 17024. \n- Undergoes regular reviews and updates of exam objectives. \n\n## Exam Development \n- CompTIA exams are developed through workshops with subject matter experts and industry-wide surveys to assess the requisite skills and knowledge for IT professionals. \n\n## Authorized Study Materials Policy \n- CompTIA does not authorize any third-party training sites (sometimes referred to as “brain dumps”). \n- Using unauthorized materials can lead to revoked certifications and suspension from future testing. \n- Candidates are advised to review the CompTIA Certification Exam Policies before starting exam preparation. \n- For clarity regarding unauthorized studies, contact CompTIA at examsecurity@comptia.org. \n\n--- \n## TEST DETAILS \n- Required Exam: SY0-701 \n- Number of Questions: Maximum of 90 \n- Types of Questions: \n - Multiple-choice \n - Performance-based \n- Length of Test: 90 minutes \n- Recommended Experience: \n - Minimum of 2 years in IT administration focusing on security. \n - Hands-on experience with technical information security and broad security concept knowledge. \n\n## Exam Objectives (Domains) \n| DOMAIN | PERCENTAGE OF EXAMINATION | \n|---------|---------------------------| \n| 1.0 General Security Concepts | 12% | \n| 2.0 Threats, Vulnerabilities, and Mitigations | 22% | \n| 3.0 Security Architecture | 18% | \n| 4.0 Security Operations | 28% | \n| 5.0 Security Program Management and Oversight | 20% | \n| Total | 100% | \n\n--- \n## 1.0 General Security Concepts \n### 1.1 Security Controls \n- Compare and Contrast Types of Security Controls: \n - Categories: \n - Technical \n - Managerial \n - Operational \n - Physical \n - Control Types: \n - Preventive \n - Deterrent \n - Detective \n - Corrective \n - Compensating \n - Directive

\n### 1.2 Fundamental Security Concepts  \n- **Confidentiality, Integrity, and Availability (CIA)**  \n- **Non-repudiation**: Assurance of being able to prove the authenticity of an action or transaction.  \n- **Authentication, Authorization, and Accounting (AAA)**:  \n  - Authenticating people and systems.  \n  - Understanding different authorization models.  \n- **Gap analysis**: A method to compare the actual performance or outcomes with the desired or potential performance or outcomes.  \n- **Zero Trust Model**:  \n  - Consists of control planes and data planes:  \n    - **Control Plane**:  \n      - Adaptive identity  \n      - Threat scope reduction  \n      - Policy-driven access  \n      - Policy Administrator  \n      - Policy Engine  \n    - **Data Plane**:  \n      - Implicit trust zones  \n      - Subject/System interactions  \n      - Policy Enforcement Points  \n- **Physical Security**:  \n  - Examples:  \n    - Bollards  \n    - Access control vestibule  \n    - Fencing  \n    - Video surveillance  \n    - Security guard presence  \n    - Access badges  \n    - Lighting and sensor systems: infrared, pressure, microwave, ultrasonic  \n- **Deception and disruption technologies**:  \n  - Honeypot, Honeynet, Honeyfile, Honeytoken  \n\n### 1.3 Change Management Processes  \n- **Importance and Security Impact**:  \n  - Business process factors that affect security operations:  \n    - Approval processes  \n    - Data ownership  \n    - Stakeholder involvement  \n    - Impact analysis  \n    - Test results  \n    - Backout plans  \n    - Maintenance windows  \n    - Standard operating procedures (SOPs)  \n  - **Technical Implications**:  \n    - Allow lists/deny lists  \n    - Restricted activities/downtime  \n    - Service and application restarts  \n    - Legacy applications/dependencies  \n  - **Documentation**:  \n    - Updating diagrams and policies/procedures  \n  - **Version Control**:  \n    - Importance for maintaining document integrity and management.  \n\n### 1.4 Cryptographic Solutions  \n- **Importance of Appropriate Cryptographic Solutions**:  \n  - **Public Key Infrastructure (PKI)**: Critical components include public keys, private keys, key escrow.  \n  - **Encryption Levels**:  \n    - Full-disk  \n    - Partition  \n    - File  \n    - Volume  \n    - Database  \n    - Record  \n    - Transport/communication  \n    - Types: Asymmetric, Symmetric  \n  - **Key Exchange & Algorithms**:  \n  - **Key Length Considerations**: Critical for security strength.  \n- **Tools for Cryptography**:  \n  - Trusted Platform Module (TPM)  \n  - Hardware Security Module (HSM)  \n  - Key Management Systems  \n  - Secure Enclaves  \n- **Obfuscation Techniques**:  \n  - Steganography, tokenization, data masking  \n- **Hashing, Salting, and Digital Signatures**: Critical for data integrity verification.  \n- **Key Stretching and Blockchain**: Techniques for enhancing security.  \n- **Certificates and Authorities**:  \n  - Role of Certificate Authorities (CA) and Certificate Revocation Lists (CRLs)  \n  - Online Certificate Status Protocol (OCSP)  \n  - Self-signed certificates versus third-party certificates.  \n\n### 1.5 Common Threat Actors and Vectors  \n- **Types of Threat Actors**:  \n  - Nation-state  \n  - Unskilled attacker  \n  - Hacktivist  \n  - Insider threats  \n  - Organized crime groups  \n  - Shadow IT  \n- **Attributes of Actors**:  \n  - Internal versus external actors  \n  - Resource availability and funding  \n  - Sophistication and capability levels  \n- **Motivations of Threat Actors**:  \n  - Data exfiltration and espionage  \n  - Disruption and blackmail  \n  - Financial gain  \n  - Philosophical/political beliefs, revenge, chaos, or war  \n\n### 1.6 Threat Vectors and Attack Surfaces  \n- **Common Threat Vectors**:  \n  - Email messages, SMS, instant messaging (IM)  \n  - Image-based, file-based, voice calls  \n  - Removable devices and vulnerable software  \n- **Specific Vectors**:  \n  - Unsupported systems and unsecure networks (wired, wireless, Bluetooth)  \n  - Exploited open service ports and default credentials  \n  - Supply chain vulnerabilities involving:  \n    - Managed Service Providers (MSPs)  \n    - Vendors  \n    - Suppliers  \n- **Human Vectors/Social Engineering Techniques**:  \n  - Phishing, vishing, smishing  \n  - Misinformation and impersonation strategies  \n  - Business email compromises, pretexting, watering hole attacks, brand impersonation, typosquatting  \n\n---  \n## 2.0 Threats, Vulnerabilities, and Mitigations  \n### 2.1 Types of Vulnerabilities  \n- **Application Vulnerabilities**:  \n  - Memory injection, buffer overflow, race conditions  \n    - Time-of-check (TOC), time-of-use (TOU)  \n  - Malicious updates  \n- **Operating System Vulnerabilities**: Issues inherent with OS designs.  \n- **Web-based Vulnerabilities**:  \n  - Structured Query Language injection (SQLi)  \n  - Cross-site scripting (XSS)  \n- **Hardware Vulnerabilities**:  \n  - Issues such as outdated firmware, end-of-life systems, legacy hardware.  \n- **Virtualization Vulnerabilities**:  \n  - Virtual machine (VM) escape, resource reuse vulnerabilities  \n- **Cloud-based Vulnerabilities**: Specific to cloud service implementations.  \n- **Supply Chain Vulnerabilities**:  \n  - Resulting from third-party service, hardware, and software providers.  \n- **Cryptographic Vulnerabilities**:  \n  - Inherent weaknesses in cryptographic implementations.  \n- **Misconfiguration Vulnerabilities**:  \n  - Resulting from improper settings.  \n- **Mobile Device Vulnerabilities**:  \n - Side loading, jailbreaking risks  \n- **Zero-Day Vulnerabilities**: A type of attack that exploits previously unknown vulnerabilities.  \n\n### 2.2 Analyzing Malicious Activity Indicators  \n- **Indicators of Malware Attacks**:  \n  - Ransomware, Trojans, worms, spyware, bloatware, viruses, keyloggers, logic bombs, rootkits.  \n- **Physical Attack Indicators**:  \n  - Physical breaches indicating brute force and environmental triggers.  \n- **Network Attack Indicators**:  \n  - Distributed Denial-of-Service (DDoS) including amplified and reflected attacks.  \n  - Domain Name System (DNS) attacks, wireless, on-path, credential replay attacks, malicious code insertion.  \n- **Application Attack Indicators**:  \n  - Injection attacks, buffer overflow incidents, replay and privilege escalation attempts, forgery, directory traversal incidents.  \n- **Cryptographic Attack Indicators**:  \n  - Downgrade, collision, or birthday attacks.  \n- **Password Attack Indicators**:  \n  - Password spraying and brute force attempts observed.  \n- **General Indicators of Compromise**:  \n  - Account lockouts, concurrent session usage anomalies, blocked content attempts, impossible travel incidents, resource consumption spikes, missing logs.  \n\n### 2.3 Mitigation Techniques to Secure the Enterprise  \n- **Segmentation and Access Control**:  \n  - Implementation of Access Control Lists (ACLs) and defined permissions.  \n- **Application Allowlist and Isolation**: Techniques to reduce risk.  \n- **Patching Management and Encryption**: Regular updates and strong encryption practices.  \n- **Monitoring and Least Privilege**:  \n  - Strict role-based and attribute-based access management.  \n- **Configuration Enforcement**: Ensure compliance with security policies.  \n- **Decommissioning Procedures**: Proper protocols for retiring outdated hardware and software.  \n- **Hardening Techniques**:  \n  - Include encryption, endpoint protection installation, firewalls, intrusion prevention systems, disabling unnecessary ports/protocols, and changing default passwords.  \n\n### 2.4 Security Architecture Implications  \n- **Security Considerations in Architecture Models**:  \n  - Cloud models (responsibility matrix, hybrid considerations)  \n  - Infrastructure as Code (IaC), Serverless, Microservices considerations.  \n- **Networking Considerations**:  \n  - Strategies involving physical isolation (air-gapped networks, logical segmentation, software-defined networking).  \n- **Real-time operating systems (RTOS)** and  Industrial Control Systems (ICS)/Supervisory Control and Data Acquisition (SCADA) security considerations.  \n- **Architecture Deliverables**:  \n  - Availability, resilience, cost, responsiveness, scalability, risk transference, and recovery considerations (e.g. patch availability).  \n\n### 2.5 Applying Security Principles  \n- **Infrastructure Security Principles**:  \n  - Device placement, security zoning, attack surface management, connectivity assessments, and identification of failure modes (fail-open versus fail-closed).  \n- **Device and Network Configuration**:  \n  - Consideration of device attributes (active vs passive) and network appliances’ security roles.  \n  - Implementation measures such as port security (802.1X, EAP).  \n  - Firewalls and their types: Web Application Firewall (WAF), Unified Threat Management (UTM), Next-Generation Firewall (NGFW), Layer 4 and Layer 7 firewalls.  \n\n---  \n## 3.0 Security Architecture  \n### 3.1 Database Protection Strategies  \n- **Data Types**:  \n  - Regulated, trade secrets, intellectual property, financial information, personal data.  \n- **Data Classifications**:  \n  - Sensitive, confidential, public, restricted, private, critical.  \n- **Data States**:  \n  - Data at rest, data in transit, data in use.  \n- **General Data Considerations**:  \n  - Data sovereignty, geolocation aspects and how they apply to secure operations.  \n\n### 3.2 Methods to Secure Data  \n- **Secure Data Methods**:  \n  - Geographic restrictions, encryption (as per requirements), hashing methods, masking, tokenization, obfuscation practices, segmentation and permission restrictions.  \n\n### 3.3 Importance of Resilience and Recovery (Architecture)  \n- **High Availability Techniques**:  \n  - Load balancing strategies versus clustering advantages.  \n- **Site Considerations for Data Recovery**:  \n  - Hot, cold, and warm site advantages, based on geographic dispersion.  \n- **Diversity of Platforms**:  \n  - Employment of multi-cloud systems.  \n- **Operational Continuity Measures**:  \n  - Capacity planning for resources and infrastructure.  \n- **Testing and Backup Measures**:  \n  - Methods of testing resilience, including tabletop exercises, failed recovery tests, and practices around backups (onsite/offsite, frequency, encryption).  \n\n### 3.4 Security Techniques Applied to Computing Resources  \n- **Secure Baselines**:  \n  - Establishing, deploying, and maintaining baselines for various devices including mobile devices, workstations, routers, and servers.  \n- **Wireless Security Settings**:  \n  - Wi-Fi Protected Access 3 (WPA3), RADIUS, cryptographic and authentication protocols to be used.  \n- **Application Security Measures**:  \n  - Input validation methods, use of secure cookies, static code analysis, sandboxing, and monitoring practices.  \n\n---  \n## 4.0 Security Operations  \n### 4.1 Vulnerability Management Activities  \n- **Identification Methods**:  \n  - Utilizing vulnerability scans, application security methods, penetration testing, and threat feeds to gather relevant data.  \n- **Analysis Techniques**:  \n  - Understanding false positives/negatives, prioritization techniques (CVSS), and classification of vulnerabilities.  \n- **Response and Remediation Practices**:  \n  - Implementing patch management, segmentation strategies, and compensating controls.  \n- **Validation of Remediation Techniques**:  \n  - Rescanning, auditing, and verification methods.  \n- **Reporting Frameworks**:  \n  - Structured reporting methods for communicating vulnerabilities and remediation results.  \n\n### 4.2 Security Alerting and Monitoring Concepts  \n- **Monitoring Computing Resources**:  \n  - Identification of the resource scope (systems, applications, infrastructure).  \n- **Activities of Security Operations**:  \n  - Includes logs aggregation, alert tuning, reporting methodologies, and remediation activities across resource sets (quarantines, validations).  \n- **Use of Tools**:  \n  - Security Content Automation Protocol (SCAP), vulnerability scanners, SIEM, and data loss prevention tools.  \n\n### 4.3 Adjusting Capabilities for Enhanced Security  \n- **Firewall Configuration Techniques**:  \n  - Rules setup, access list management, and processing access by ports/protocols.  \n- **Intrusion Detection and Prevention Systems (IDS/IPS)**:  \n  - Analysis of trends, signature configurations.  \n- **Web Filtering Strategies**:  \n  - Techniques employed include agent-based, centralized proxy analyses, URL scanning, and content categorization rules.  \n- **OS Security Parameters**:  \n  - Employing Group Policy, SELinux implementations.  \n- **Secure Communication Protocols**:  \n  - Implementations of VPNs, secure tunneling methods such as TLS and IPSec.  \n\n### 4.4 Identity and Access Management (IAM)  \n- **User Account Management**:  \n  - Processes for provisioning and de-provisioning user accounts, permission assignments, and security implications.  \n- **Federation and Single Sign-On (SSO)**:  \n  - Techniques involving LDAP, OAuth, and SAML.  \n- **Access Control Systems**:  \n  - Understanding mandatory vs discretionary vs role-based vs rule-based access controls.  \n- **Implementation of Multifactor Authentication**:  \n  - Use of biometrics and authentication tokens, understanding the factors of authentication.  \n- **Password Management Best Practices**:  \n  - Addressing length, complexity, reuse, and expiration cycles.  \n\n---  \n## 5.0 Security Program Management and Oversight  \n### 5.1 Third-Party Risk Assessment and Management  \n- **Vendor Assessment Methods**:  \n  - Penetration testing, right-to-audit clauses, independent assessments, and analysis of supply chains.  \n- **Selection Criteria for Vendors**:  \n  - Due diligence methodologies, monitoring processes, and conflict of interest scrutiny.  \n- **Types of Agreements**:  \n  - Service-level agreements (SLA), Memorandum of Agreement (MOA), Memorandum of Understanding (MOU), Non-Disclosure Agreements (NDA).  \n\n### 5.2 Effective Security Compliance Elements  \n- **Compliance Reporting**:  \n  - Understanding internal and external reporting structures.  \n- **Consequences of Non-Compliance**:  \n  - Financial penalties, reputation loss, and operational interruptions.  \n- **Regulatory Considerations**:  \n  - Different frameworks (local, regional, industry-specific) affecting compliance.  \n\n### 5.3 Audit and Assessment Types  \n- **Understanding Audits**:  \n  - Internal (self-assessments) and external audit roles including compliance and regulatory examinations.  \n- **Penetration Testing Strategies**:  \n  - Various testing environments (physical, known/unknown environments, reconnaissance).  \n\n### 5.4 Security Awareness Practices  \n- **Implementing Effective Awareness Programs**:  \n  - Phishing campaigns, guidance on recognizing malicious behavior, managing anomalous behavior, and operational security training.  \n- **Monitoring and Reporting Mechanisms**:  \n  - Initial and continued monitoring for compliance with security practices and policies.  \n\n### 5.5 Governance Structure Elements  \n- **Security Guidelines and Policies**:  \n  - Acceptable use policies, information security policies, incident response manuals.  \n- **Establishing Standards and Procedures**:  \n  - Maintenance for password policies, physical security guidelines, encryption procedures.  \n- **Roles and Responsibilities Distribution**:  \n  - Including data ownership, custodianship, processing, and control functions.  \n

--- \n## Acronym List \n- Alphabetical listing of commonly used acronyms relevant to Security+, including: \n - 2FA (Two-factor Authentication) \n - AAA (Authentication, Authorization, Accounting) \n - ACL (Access Control List) \n - AES (Advanced Encryption Standard) \n - DDoS (Distributed Denial of Service) \n - IPSec (Internet Protocol Security) \n - PKI (Public Key Infrastructure) \n - RTO (Recovery Time Objective) \n - RPO (Recovery Point Objective) \n - SIEM (Security Information and Event Management) \n
--- \n## Equipment and Tools for Security+ \n### Recommended Equipment \n- Tablets, Laptops, Web servers, Firewalls, Routers, Switches. \n### Spare Parts/Hardware Recommendations \n- NICs, Power Supplies, UPS systems. \n### Recommended Software Tools \n- Vulnerability scanners, SIEM tools, Pen testing software, Packet capture software. \n### Other Tools \n- Access to cloud environments, network diagrams and simulations.