CompTIA Security+ SY0-701 Exam Objectives Notes
CompTIA Security+ Certification Exam Objectives \n\n## Overview \n- Certification Exam Name: CompTIA Security+ \n- Exam Number: SY0-701 V7 \n- Copyright: © 2023 CompTIA, Inc. All rights reserved. \n\n--- \n## About the Exam \n- The CompTIA Security+ certification exam verifies the candidate's: \n - Knowledge and skills necessary to assess the security posture of an enterprise environment. \n - Ability to recommend and implement appropriate security solutions. \n - Capacity to monitor and secure hybrid environments, which include: \n - Cloud \n - Mobile \n - Internet of Things (IoT) \n - Awareness of applicable regulations and policies, inclusive of governance, risk, and compliance principles. \n - Skills in identifying, analyzing, and responding to security events and incidents. \n\n## Exam Accreditation \n- The CompTIA Security+ exam is accredited by ANSI, in compliance with ISO 17024. \n- Undergoes regular reviews and updates of exam objectives. \n\n## Exam Development \n- CompTIA exams are developed through workshops with subject matter experts and industry-wide surveys to assess the requisite skills and knowledge for IT professionals. \n\n## Authorized Study Materials Policy \n- CompTIA does not authorize any third-party training sites (sometimes referred to as “brain dumps”). \n- Using unauthorized materials can lead to revoked certifications and suspension from future testing. \n- Candidates are advised to review the CompTIA Certification Exam Policies before starting exam preparation. \n- For clarity regarding unauthorized studies, contact CompTIA at examsecurity@comptia.org. \n\n--- \n## TEST DETAILS \n- Required Exam: SY0-701 \n- Number of Questions: Maximum of 90 \n- Types of Questions: \n - Multiple-choice \n - Performance-based \n- Length of Test: 90 minutes \n- Recommended Experience: \n - Minimum of 2 years in IT administration focusing on security. \n - Hands-on experience with technical information security and broad security concept knowledge. \n\n## Exam Objectives (Domains) \n| DOMAIN | PERCENTAGE OF EXAMINATION | \n|---------|---------------------------| \n| 1.0 General Security Concepts | 12% | \n| 2.0 Threats, Vulnerabilities, and Mitigations | 22% | \n| 3.0 Security Architecture | 18% | \n| 4.0 Security Operations | 28% | \n| 5.0 Security Program Management and Oversight | 20% | \n| Total | 100% | \n\n--- \n## 1.0 General Security Concepts \n### 1.1 Security Controls \n- Compare and Contrast Types of Security Controls: \n - Categories: \n - Technical \n - Managerial \n - Operational \n - Physical \n - Control Types: \n - Preventive \n - Deterrent \n - Detective \n - Corrective \n - Compensating \n - Directive
\n### 1.2 Fundamental Security Concepts \n- **Confidentiality, Integrity, and Availability (CIA)** \n- **Non-repudiation**: Assurance of being able to prove the authenticity of an action or transaction. \n- **Authentication, Authorization, and Accounting (AAA)**: \n - Authenticating people and systems. \n - Understanding different authorization models. \n- **Gap analysis**: A method to compare the actual performance or outcomes with the desired or potential performance or outcomes. \n- **Zero Trust Model**: \n - Consists of control planes and data planes: \n - **Control Plane**: \n - Adaptive identity \n - Threat scope reduction \n - Policy-driven access \n - Policy Administrator \n - Policy Engine \n - **Data Plane**: \n - Implicit trust zones \n - Subject/System interactions \n - Policy Enforcement Points \n- **Physical Security**: \n - Examples: \n - Bollards \n - Access control vestibule \n - Fencing \n - Video surveillance \n - Security guard presence \n - Access badges \n - Lighting and sensor systems: infrared, pressure, microwave, ultrasonic \n- **Deception and disruption technologies**: \n - Honeypot, Honeynet, Honeyfile, Honeytoken \n\n### 1.3 Change Management Processes \n- **Importance and Security Impact**: \n - Business process factors that affect security operations: \n - Approval processes \n - Data ownership \n - Stakeholder involvement \n - Impact analysis \n - Test results \n - Backout plans \n - Maintenance windows \n - Standard operating procedures (SOPs) \n - **Technical Implications**: \n - Allow lists/deny lists \n - Restricted activities/downtime \n - Service and application restarts \n - Legacy applications/dependencies \n - **Documentation**: \n - Updating diagrams and policies/procedures \n - **Version Control**: \n - Importance for maintaining document integrity and management. \n\n### 1.4 Cryptographic Solutions \n- **Importance of Appropriate Cryptographic Solutions**: \n - **Public Key Infrastructure (PKI)**: Critical components include public keys, private keys, key escrow. \n - **Encryption Levels**: \n - Full-disk \n - Partition \n - File \n - Volume \n - Database \n - Record \n - Transport/communication \n - Types: Asymmetric, Symmetric \n - **Key Exchange & Algorithms**: \n - **Key Length Considerations**: Critical for security strength. \n- **Tools for Cryptography**: \n - Trusted Platform Module (TPM) \n - Hardware Security Module (HSM) \n - Key Management Systems \n - Secure Enclaves \n- **Obfuscation Techniques**: \n - Steganography, tokenization, data masking \n- **Hashing, Salting, and Digital Signatures**: Critical for data integrity verification. \n- **Key Stretching and Blockchain**: Techniques for enhancing security. \n- **Certificates and Authorities**: \n - Role of Certificate Authorities (CA) and Certificate Revocation Lists (CRLs) \n - Online Certificate Status Protocol (OCSP) \n - Self-signed certificates versus third-party certificates. \n\n### 1.5 Common Threat Actors and Vectors \n- **Types of Threat Actors**: \n - Nation-state \n - Unskilled attacker \n - Hacktivist \n - Insider threats \n - Organized crime groups \n - Shadow IT \n- **Attributes of Actors**: \n - Internal versus external actors \n - Resource availability and funding \n - Sophistication and capability levels \n- **Motivations of Threat Actors**: \n - Data exfiltration and espionage \n - Disruption and blackmail \n - Financial gain \n - Philosophical/political beliefs, revenge, chaos, or war \n\n### 1.6 Threat Vectors and Attack Surfaces \n- **Common Threat Vectors**: \n - Email messages, SMS, instant messaging (IM) \n - Image-based, file-based, voice calls \n - Removable devices and vulnerable software \n- **Specific Vectors**: \n - Unsupported systems and unsecure networks (wired, wireless, Bluetooth) \n - Exploited open service ports and default credentials \n - Supply chain vulnerabilities involving: \n - Managed Service Providers (MSPs) \n - Vendors \n - Suppliers \n- **Human Vectors/Social Engineering Techniques**: \n - Phishing, vishing, smishing \n - Misinformation and impersonation strategies \n - Business email compromises, pretexting, watering hole attacks, brand impersonation, typosquatting \n\n--- \n## 2.0 Threats, Vulnerabilities, and Mitigations \n### 2.1 Types of Vulnerabilities \n- **Application Vulnerabilities**: \n - Memory injection, buffer overflow, race conditions \n - Time-of-check (TOC), time-of-use (TOU) \n - Malicious updates \n- **Operating System Vulnerabilities**: Issues inherent with OS designs. \n- **Web-based Vulnerabilities**: \n - Structured Query Language injection (SQLi) \n - Cross-site scripting (XSS) \n- **Hardware Vulnerabilities**: \n - Issues such as outdated firmware, end-of-life systems, legacy hardware. \n- **Virtualization Vulnerabilities**: \n - Virtual machine (VM) escape, resource reuse vulnerabilities \n- **Cloud-based Vulnerabilities**: Specific to cloud service implementations. \n- **Supply Chain Vulnerabilities**: \n - Resulting from third-party service, hardware, and software providers. \n- **Cryptographic Vulnerabilities**: \n - Inherent weaknesses in cryptographic implementations. \n- **Misconfiguration Vulnerabilities**: \n - Resulting from improper settings. \n- **Mobile Device Vulnerabilities**: \n - Side loading, jailbreaking risks \n- **Zero-Day Vulnerabilities**: A type of attack that exploits previously unknown vulnerabilities. \n\n### 2.2 Analyzing Malicious Activity Indicators \n- **Indicators of Malware Attacks**: \n - Ransomware, Trojans, worms, spyware, bloatware, viruses, keyloggers, logic bombs, rootkits. \n- **Physical Attack Indicators**: \n - Physical breaches indicating brute force and environmental triggers. \n- **Network Attack Indicators**: \n - Distributed Denial-of-Service (DDoS) including amplified and reflected attacks. \n - Domain Name System (DNS) attacks, wireless, on-path, credential replay attacks, malicious code insertion. \n- **Application Attack Indicators**: \n - Injection attacks, buffer overflow incidents, replay and privilege escalation attempts, forgery, directory traversal incidents. \n- **Cryptographic Attack Indicators**: \n - Downgrade, collision, or birthday attacks. \n- **Password Attack Indicators**: \n - Password spraying and brute force attempts observed. \n- **General Indicators of Compromise**: \n - Account lockouts, concurrent session usage anomalies, blocked content attempts, impossible travel incidents, resource consumption spikes, missing logs. \n\n### 2.3 Mitigation Techniques to Secure the Enterprise \n- **Segmentation and Access Control**: \n - Implementation of Access Control Lists (ACLs) and defined permissions. \n- **Application Allowlist and Isolation**: Techniques to reduce risk. \n- **Patching Management and Encryption**: Regular updates and strong encryption practices. \n- **Monitoring and Least Privilege**: \n - Strict role-based and attribute-based access management. \n- **Configuration Enforcement**: Ensure compliance with security policies. \n- **Decommissioning Procedures**: Proper protocols for retiring outdated hardware and software. \n- **Hardening Techniques**: \n - Include encryption, endpoint protection installation, firewalls, intrusion prevention systems, disabling unnecessary ports/protocols, and changing default passwords. \n\n### 2.4 Security Architecture Implications \n- **Security Considerations in Architecture Models**: \n - Cloud models (responsibility matrix, hybrid considerations) \n - Infrastructure as Code (IaC), Serverless, Microservices considerations. \n- **Networking Considerations**: \n - Strategies involving physical isolation (air-gapped networks, logical segmentation, software-defined networking). \n- **Real-time operating systems (RTOS)** and Industrial Control Systems (ICS)/Supervisory Control and Data Acquisition (SCADA) security considerations. \n- **Architecture Deliverables**: \n - Availability, resilience, cost, responsiveness, scalability, risk transference, and recovery considerations (e.g. patch availability). \n\n### 2.5 Applying Security Principles \n- **Infrastructure Security Principles**: \n - Device placement, security zoning, attack surface management, connectivity assessments, and identification of failure modes (fail-open versus fail-closed). \n- **Device and Network Configuration**: \n - Consideration of device attributes (active vs passive) and network appliances’ security roles. \n - Implementation measures such as port security (802.1X, EAP). \n - Firewalls and their types: Web Application Firewall (WAF), Unified Threat Management (UTM), Next-Generation Firewall (NGFW), Layer 4 and Layer 7 firewalls. \n\n--- \n## 3.0 Security Architecture \n### 3.1 Database Protection Strategies \n- **Data Types**: \n - Regulated, trade secrets, intellectual property, financial information, personal data. \n- **Data Classifications**: \n - Sensitive, confidential, public, restricted, private, critical. \n- **Data States**: \n - Data at rest, data in transit, data in use. \n- **General Data Considerations**: \n - Data sovereignty, geolocation aspects and how they apply to secure operations. \n\n### 3.2 Methods to Secure Data \n- **Secure Data Methods**: \n - Geographic restrictions, encryption (as per requirements), hashing methods, masking, tokenization, obfuscation practices, segmentation and permission restrictions. \n\n### 3.3 Importance of Resilience and Recovery (Architecture) \n- **High Availability Techniques**: \n - Load balancing strategies versus clustering advantages. \n- **Site Considerations for Data Recovery**: \n - Hot, cold, and warm site advantages, based on geographic dispersion. \n- **Diversity of Platforms**: \n - Employment of multi-cloud systems. \n- **Operational Continuity Measures**: \n - Capacity planning for resources and infrastructure. \n- **Testing and Backup Measures**: \n - Methods of testing resilience, including tabletop exercises, failed recovery tests, and practices around backups (onsite/offsite, frequency, encryption). \n\n### 3.4 Security Techniques Applied to Computing Resources \n- **Secure Baselines**: \n - Establishing, deploying, and maintaining baselines for various devices including mobile devices, workstations, routers, and servers. \n- **Wireless Security Settings**: \n - Wi-Fi Protected Access 3 (WPA3), RADIUS, cryptographic and authentication protocols to be used. \n- **Application Security Measures**: \n - Input validation methods, use of secure cookies, static code analysis, sandboxing, and monitoring practices. \n\n--- \n## 4.0 Security Operations \n### 4.1 Vulnerability Management Activities \n- **Identification Methods**: \n - Utilizing vulnerability scans, application security methods, penetration testing, and threat feeds to gather relevant data. \n- **Analysis Techniques**: \n - Understanding false positives/negatives, prioritization techniques (CVSS), and classification of vulnerabilities. \n- **Response and Remediation Practices**: \n - Implementing patch management, segmentation strategies, and compensating controls. \n- **Validation of Remediation Techniques**: \n - Rescanning, auditing, and verification methods. \n- **Reporting Frameworks**: \n - Structured reporting methods for communicating vulnerabilities and remediation results. \n\n### 4.2 Security Alerting and Monitoring Concepts \n- **Monitoring Computing Resources**: \n - Identification of the resource scope (systems, applications, infrastructure). \n- **Activities of Security Operations**: \n - Includes logs aggregation, alert tuning, reporting methodologies, and remediation activities across resource sets (quarantines, validations). \n- **Use of Tools**: \n - Security Content Automation Protocol (SCAP), vulnerability scanners, SIEM, and data loss prevention tools. \n\n### 4.3 Adjusting Capabilities for Enhanced Security \n- **Firewall Configuration Techniques**: \n - Rules setup, access list management, and processing access by ports/protocols. \n- **Intrusion Detection and Prevention Systems (IDS/IPS)**: \n - Analysis of trends, signature configurations. \n- **Web Filtering Strategies**: \n - Techniques employed include agent-based, centralized proxy analyses, URL scanning, and content categorization rules. \n- **OS Security Parameters**: \n - Employing Group Policy, SELinux implementations. \n- **Secure Communication Protocols**: \n - Implementations of VPNs, secure tunneling methods such as TLS and IPSec. \n\n### 4.4 Identity and Access Management (IAM) \n- **User Account Management**: \n - Processes for provisioning and de-provisioning user accounts, permission assignments, and security implications. \n- **Federation and Single Sign-On (SSO)**: \n - Techniques involving LDAP, OAuth, and SAML. \n- **Access Control Systems**: \n - Understanding mandatory vs discretionary vs role-based vs rule-based access controls. \n- **Implementation of Multifactor Authentication**: \n - Use of biometrics and authentication tokens, understanding the factors of authentication. \n- **Password Management Best Practices**: \n - Addressing length, complexity, reuse, and expiration cycles. \n\n--- \n## 5.0 Security Program Management and Oversight \n### 5.1 Third-Party Risk Assessment and Management \n- **Vendor Assessment Methods**: \n - Penetration testing, right-to-audit clauses, independent assessments, and analysis of supply chains. \n- **Selection Criteria for Vendors**: \n - Due diligence methodologies, monitoring processes, and conflict of interest scrutiny. \n- **Types of Agreements**: \n - Service-level agreements (SLA), Memorandum of Agreement (MOA), Memorandum of Understanding (MOU), Non-Disclosure Agreements (NDA). \n\n### 5.2 Effective Security Compliance Elements \n- **Compliance Reporting**: \n - Understanding internal and external reporting structures. \n- **Consequences of Non-Compliance**: \n - Financial penalties, reputation loss, and operational interruptions. \n- **Regulatory Considerations**: \n - Different frameworks (local, regional, industry-specific) affecting compliance. \n\n### 5.3 Audit and Assessment Types \n- **Understanding Audits**: \n - Internal (self-assessments) and external audit roles including compliance and regulatory examinations. \n- **Penetration Testing Strategies**: \n - Various testing environments (physical, known/unknown environments, reconnaissance). \n\n### 5.4 Security Awareness Practices \n- **Implementing Effective Awareness Programs**: \n - Phishing campaigns, guidance on recognizing malicious behavior, managing anomalous behavior, and operational security training. \n- **Monitoring and Reporting Mechanisms**: \n - Initial and continued monitoring for compliance with security practices and policies. \n\n### 5.5 Governance Structure Elements \n- **Security Guidelines and Policies**: \n - Acceptable use policies, information security policies, incident response manuals. \n- **Establishing Standards and Procedures**: \n - Maintenance for password policies, physical security guidelines, encryption procedures. \n- **Roles and Responsibilities Distribution**: \n - Including data ownership, custodianship, processing, and control functions. \n
--- \n## Acronym List \n- Alphabetical listing of commonly used acronyms relevant to Security+, including: \n - 2FA (Two-factor Authentication) \n - AAA (Authentication, Authorization, Accounting) \n - ACL (Access Control List) \n - AES (Advanced Encryption Standard) \n - DDoS (Distributed Denial of Service) \n - IPSec (Internet Protocol Security) \n - PKI (Public Key Infrastructure) \n - RTO (Recovery Time Objective) \n - RPO (Recovery Point Objective) \n - SIEM (Security Information and Event Management) \n
--- \n## Equipment and Tools for Security+ \n### Recommended Equipment \n- Tablets, Laptops, Web servers, Firewalls, Routers, Switches. \n### Spare Parts/Hardware Recommendations \n- NICs, Power Supplies, UPS systems. \n### Recommended Software Tools \n- Vulnerability scanners, SIEM tools, Pen testing software, Packet capture software. \n### Other Tools \n- Access to cloud environments, network diagrams and simulations.