SY0-701
The current exam code for the CompTIA Security+ certification.
Getting Started: How the Exam Works
Free knowledge base
Everything from the course in one searchable place: 289 entries. Use it to review before a practice test or look up a word you forgot.
289 results
The current exam code for the CompTIA Security+ certification.
Getting Started: How the Exam Works
Performance-Based Question; interactive, hands-on simulation questions on the exam.
Getting Started: How the Exam Works
A statistical adjustment of raw scores to ensure consistent difficulty across different exam versions.
Getting Started: How the Exam Works
The global testing provider for CompTIA certification exams.
Getting Started: How the Exam Works
An official document outlining all topics covered on a CompTIA exam.
Getting Started: How the Exam Works
A question type where you select one best answer from several options.
Getting Started: How the Exam Works
To remember the scoring: 'Seven-Fifty to Certify' (750 for passing).
Getting Started: How the Exam Works
Memorize the passing score (750 on a scale of 100-900) and the maximum number of questions (90) and time limit (90 minutes). These are frequently tested facts.
Getting Started: How the Exam Works
Not checking the exam version: Always ensure your study materials are for SY0-701.
Getting Started: How the Exam Works
Neglecting PBQs: These are critical; practice them, don't just focus on multiple choice.
Getting Started: How the Exam Works
Poor time management: Rushing or spending too long on a single question can lead to not finishing.
Getting Started: How the Exam Works
Percentage of questions from a specific topic area on the exam.
Getting Started: How the Exam Works
Engaging with material through practice, explanation, and application.
Getting Started: How the Exam Works
Hands-on simulation questions on the exam.
Getting Started: How the Exam Works
Strategically allocating time during the exam to answer all questions.
Getting Started: How the Exam Works
Removing incorrect answer choices to increase chances of guessing correctly.
Getting Started: How the Exam Works
To remember the top three weighted domains: 'A.O.T.' - Architecture (24%), Operations (26%), Threats (22%). Think of a giant 'Attack On Titan' to remember these big ones!
Getting Started: How the Exam Works
The CompTIA Security+ SY0-701 exam consists of a maximum of 90 questions, to be completed within 90 minutes. You must score 750 out of 900 to pass. Remember these precise numbers.
Getting Started: How the Exam Works
Only memorizing definitions without understanding their practical application.
Getting Started: How the Exam Works
Ignoring domains with lower weightings, as these can still contribute to a failing score.
Getting Started: How the Exam Works
Not practicing time management, leading to rushing or not finishing the exam.
Getting Started: How the Exam Works
Ensuring data is accessed only by authorized individuals.
General Security Concepts
Maintaining accuracy and trustworthiness of data.
General Security Concepts
Ensuring authorized users can access systems when needed.
General Security Concepts
Security measures implemented through hardware or software.
General Security Concepts
Policies, procedures, and guidelines for security.
General Security Concepts
Measures to protect physical assets from unauthorized access.
General Security Concepts
Controls designed to stop an incident from occurring.
General Security Concepts
Controls designed to identify incidents after they occur.
General Security Concepts
Remember the CIA Triad with 'CIA': Confidentiality, Integrity, Availability. Think of a spy agency protecting secrets!
General Security Concepts
The exam often presents scenarios and asks you to identify the best control type or category that addresses a specific security concern. Pay close attention to keywords like 'prevent,' 'detect,' 'restore,' or 'discourage.'
General Security Concepts
Confusing the purpose of detective and preventative controls. Preventative stops, detective identifies.
General Security Concepts
Underestimating the importance of administrative controls; policies are just as crucial as technology.
General Security Concepts
Forgetting that a single control can often support multiple aspects of the CIA Triad.
General Security Concepts
Verifying the identity of a user or device.
General Security Concepts
Determining what an authenticated entity can do.
General Security Concepts
Tracking and logging user activities for security.
General Security Concepts
Security model: never trust, always verify every access request.
General Security Concepts
Dividing networks into small, isolated segments.
General Security Concepts
Measures protecting physical assets from threats.
General Security Concepts
Multi-factor authentication; using two or more verification methods.
General Security Concepts
A small room with two doors, only one of which can be open at a time.
General Security Concepts
Remember AAA with 'Are you who you say you are? Are you allowed to do that? And did you do it?'
General Security Concepts
The exam often presents scenarios where you need to apply AAA concepts. For Zero Trust, focus on its core principle of 'never trust, always verify' and how it differs from traditional perimeter-based security. For physical security, memorize common control types and their purpose.
General Security Concepts
Confusing authorization with authentication; authentication is about identity, authorization is about permissions.
General Security Concepts
Believing Zero Trust means 'no access'; it means 'no implicit trust' and access is granted only after verification.
General Security Concepts
Underestimating the importance of physical security; a data breach can start with someone walking into the server room.
General Security Concepts
Methods to mislead attackers, gather intelligence, and waste their resources.
General Security Concepts
A decoy system designed to attract and trap attackers to observe their actions.
General Security Concepts
A network of multiple honeypots to simulate a more complex target environment.
General Security Concepts
A fake piece of data used to detect unauthorized access when it is touched.
General Security Concepts
Redirects malicious DNS requests to a controlled server to neutralize threats.
General Security Concepts
Unused IP address space monitored for traffic to detect suspicious activity.
General Security Concepts
Formal process to control and track modifications to IT systems, minimizing risks.
General Security Concepts
A formal proposal detailing a modification to an IT system or service.
General Security Concepts
Deception: HHH D-D. Honeypot, Honeynet, Honeytoken, DNS Sinkhole, Darknet – they all DECEIVE!
General Security Concepts
Memorize the core purpose of each deception technique (honeypot, honeytoken, DNS sinkhole, darknet) and the key steps in a change management process. The exam often asks for the 'why' behind these concepts.
General Security Concepts
Confusing honeypots with production systems; honeypots are intentionally vulnerable decoys.
General Security Concepts
Skipping steps in change management, leading to undocumented changes and potential outages.
General Security Concepts
Believing deception techniques are a primary defense; they are intelligence-gathering and delaying tools, not preventative firewalls.
General Security Concepts
System for managing digital certificates and public keys.
General Security Concepts
Trusted entity that issues and manages digital certificates.
General Security Concepts
Uses a single, shared secret key for encryption and decryption.
General Security Concepts
Uses a public/private key pair for encryption and decryption.
General Security Concepts
One-way function to create a fixed-size digest for integrity.
General Security Concepts
Key that can be shared, used to encrypt or verify signatures.
General Security Concepts
Secret key, used to decrypt or create digital signatures.
General Security Concepts
Electronic document binding a public key to an identity.
General Security Concepts
Remember 'HASH' for Integrity: H-as-fixed-size, A-lways-unique, S-ingle-direction, H-ard-to-reverse.
General Security Concepts
Memorize the core properties of hashing: fixed output size, unique output for unique input, and irreversibility. Also, know the key difference between symmetric (speed, shared key) and asymmetric (key exchange, public/private pair) encryption.
General Security Concepts
Confusing hashing with encryption; hashing is one-way for integrity, encryption is two-way for confidentiality.
General Security Concepts
Believing that a hash can be reversed to reveal the original data.
General Security Concepts
Underestimating the importance of secure key management in any cryptographic system.
General Security Concepts
Individual or group posing a risk to systems/data.
Threats, Vulnerabilities, and Mitigations
The reason behind a threat actor's attack.
Threats, Vulnerabilities, and Mitigations
Method or path used to gain unauthorized access.
Threats, Vulnerabilities, and Mitigations
Inexperienced attacker using pre-made tools.
Threats, Vulnerabilities, and Mitigations
Attacker motivated by political or social causes.
Threats, Vulnerabilities, and Mitigations
Government-sponsored group with significant resources.
Threats, Vulnerabilities, and Mitigations
Threat from within an organization, malicious or negligent.
Threats, Vulnerabilities, and Mitigations
Advanced Persistent Threat; sophisticated, long-term attack.
Threats, Vulnerabilities, and Mitigations
To remember the main motivations: FEAR - Financial, Espionage, Activism, Revenge/Disruption.
Threats, Vulnerabilities, and Mitigations
The exam often asks you to distinguish between different threat actor types based on their motivations and resources. Look for keywords like 'financial gain' (organized crime), 'political agenda' (hacktivist), 'pre-made tools' (script kiddie), or 'state-sponsored' (nation-state actor). Memorize the characteristics of each type.
Threats, Vulnerabilities, and Mitigations
Confusing the motivation with the actor type (e.g., 'financial gain' is a motivation, not an actor type).
Threats, Vulnerabilities, and Mitigations
Underestimating the danger of insider threats, assuming all threats are external.
Threats, Vulnerabilities, and Mitigations
Not recognizing that a single attack can involve multiple attack vectors.
Threats, Vulnerabilities, and Mitigations
Writing data beyond a buffer's allocated memory, overwriting adjacent data.
Threats, Vulnerabilities, and Mitigations
A numeric value exceeding its data type's max, causing wrap-around.
Threats, Vulnerabilities, and Mitigations
Inserting malicious SQL into input fields to manipulate database queries.
Threats, Vulnerabilities, and Mitigations
Injecting malicious client-side scripts into web pages viewed by others.
Threats, Vulnerabilities, and Mitigations
SQL queries where parameters are separated from the SQL code, preventing injection.
Threats, Vulnerabilities, and Mitigations
Converting special characters in user input to prevent them from being executed.
Threats, Vulnerabilities, and Mitigations
A security standard that helps prevent XSS by specifying allowed content sources.
Threats, Vulnerabilities, and Mitigations
A system-level memory protection feature that marks memory areas as non-executable.
Threats, Vulnerabilities, and Mitigations
Think of 'SQLi' as 'SQL-Lie' – the attacker lies to the database with false input. 'XSS' is like 'Cross-Site Sneaking' – scripts sneak onto other users' browsers.
Threats, Vulnerabilities, and Mitigations
The exam often presents scenarios where an attacker manipulates input fields. Keywords like 'unexpected database errors,' 'pop-up scripts,' or 'application crashes after long input' are strong indicators of these vulnerabilities. Memorize the primary mitigation for each: parameterized queries for SQLi, input validation/output encoding for XSS, and bounds checking/memory-safe languages for overflows.
Threats, Vulnerabilities, and Mitigations
Confusing server-side (SQLi) with client-side (XSS) injection attacks.
Threats, Vulnerabilities, and Mitigations
Believing that simply filtering out 'bad' keywords is sufficient to prevent SQLi or XSS.
Threats, Vulnerabilities, and Mitigations
Forgetting that integer overflows can also lead to serious security flaws, not just buffer overflows.
Threats, Vulnerabilities, and Mitigations
Malicious software designed to harm or gain unauthorized access.
Threats, Vulnerabilities, and Mitigations
Manipulating people to divulge info or perform actions.
Threats, Vulnerabilities, and Mitigations
Fraudulent messages to trick victims into revealing data.
Threats, Vulnerabilities, and Mitigations
Malware that encrypts data and demands payment for release.
Threats, Vulnerabilities, and Mitigations
Evidence an attack is currently in progress.
Threats, Vulnerabilities, and Mitigations
Evidence a security breach has already occurred.
Threats, Vulnerabilities, and Mitigations
Malware designed to hide its presence and maintain access.
Threats, Vulnerabilities, and Mitigations
To remember types of social engineering: 'P.S. W.I.S.H. D.S.' for Phishing, Spear phishing, Whaling, Impersonation, Smishing, Vishing, Dumpster diving, Shoulder surfing.
Threats, Vulnerabilities, and Mitigations
The exam often tests your ability to differentiate between various malware types and social engineering tactics. Pay close attention to the specific characteristics and delivery methods of each. For example, knowing that a worm self-replicates while a virus requires user execution is a key distinction. Also, be ready to identify common IoAs and IoCs.
Threats, Vulnerabilities, and Mitigations
Confusing the specific mechanisms of different malware types (e.g., how a virus spreads vs. a worm).
Threats, Vulnerabilities, and Mitigations
Underestimating the effectiveness of social engineering; attackers exploit human nature, not just technical flaws.
Threats, Vulnerabilities, and Mitigations
Failing to distinguish between an Indicator of Attack (IoA) and an Indicator of Compromise (IoC) – one is about active threat, the other about past breach.
Threats, Vulnerabilities, and Mitigations
Actions to reduce the likelihood or impact of a threat.
Threats, Vulnerabilities, and Mitigations
Securing a system by reducing its attack surface and vulnerabilities.
Threats, Vulnerabilities, and Mitigations
The sum of all possible points where an unauthorized user can try to enter or extract data from an environment.
Threats, Vulnerabilities, and Mitigations
A security measure that stops an incident from occurring.
Threats, Vulnerabilities, and Mitigations
A security measure that identifies an incident after it has occurred.
Threats, Vulnerabilities, and Mitigations
A documented set of security configurations applied to systems.
Threats, Vulnerabilities, and Mitigations
Dividing a computer network into smaller, isolated sub-networks.
Threats, Vulnerabilities, and Mitigations
To remember hardening steps: 'D.U.M.P.S.': Disable unnecessary, Update patches, Modify defaults, Protect access, Segment networks.
Threats, Vulnerabilities, and Mitigations
The exam often asks about the difference between preventative and detective controls. Memorize examples for each category. Keywords like 'stop,' 'prevent,' 'block' indicate preventative, while 'detect,' 'monitor,' 'alert' indicate detective.
Threats, Vulnerabilities, and Mitigations
Forgetting to update firmware or drivers during patch management, leaving critical vulnerabilities.
Threats, Vulnerabilities, and Mitigations
Assuming default security settings are adequate for production environments.
Threats, Vulnerabilities, and Mitigations
Overlooking the human element and not providing security awareness training for users.
Threats, Vulnerabilities, and Mitigations
Divides cloud security duties between provider and customer.
Security Architecture
Managing infrastructure through code, not manual processes.
Security Architecture
Executing code without managing underlying servers.
Security Architecture
Application built as small, independent, communicating services.
Security Architecture
Infrastructure as a Service; customer manages OS, apps, data.
Security Architecture
Platform as a Service; provider manages OS, middleware.
Security Architecture
Software as a Service; provider manages almost everything.
Security Architecture
For Shared Responsibility: 'I' (IaaS) Manage Most, 'P' (PaaS) Manage Some, 'S' (SaaS) Manage Seldom.
Security Architecture
Memorize the key distinctions of the Shared Responsibility Model for IaaS, PaaS, and SaaS. The exam often presents scenarios asking who is responsible for a specific security control.
Security Architecture
Assuming the cloud provider handles all security, neglecting customer responsibilities.
Security Architecture
Granting overly broad permissions to serverless functions or microservices.
Security Architecture
Not treating IaC templates with the same security rigor as application code.
Security Architecture
Connects different networks and forwards data packets.
Security Architecture
Connects devices within a single network segment.
Security Architecture
Monitors and controls network traffic based on rules.
Security Architecture
Logically segments network devices regardless of physical location.
Security Architecture
Isolated network segment for public-facing services.
Security Architecture
Highly granular segmentation, often down to individual workloads.
Security Architecture
To remember the benefits of segmentation: 'Limit Attacks, Isolate Breaches, Control Access!'
Security Architecture
The exam expects you to know the purpose and benefits of network segmentation (e.g., reducing attack surface, limiting lateral movement). Be familiar with common network devices like firewalls, routers, and switches, and how they contribute to security. Understand DMZs and VLANs as key segmentation techniques.
Security Architecture
Confusing a router's function with a switch's function; routers connect networks, switches connect devices within a network.
Security Architecture
Believing that simply having a firewall is enough; internal segmentation is crucial even if the perimeter is strong.
Security Architecture
Overlooking the security implications of unmanaged or poorly configured network devices.
Security Architecture
Data stored on persistent storage media.
Security Architecture
Data moving across a network or between systems.
Security Architecture
Data actively being used by a computer system.
Security Architecture
Categorizing data based on sensitivity and business impact.
Security Architecture
General Data Protection Regulation, EU privacy law.
Security Architecture
California Consumer Privacy Act, US privacy law.
Security Architecture
Collecting only necessary personal data.
Security Architecture
Integrating privacy into system design from the start.
Security Architecture
Remember 'R.I.P.' for the data states: Rest, In Transit, Process. Then think 'E.S.S.' for their protection: Encryption, Secure Protocols, Secure Enclaves.
Security Architecture
Memorize the three data states (at rest, in transit, in process) and their primary protection methods (encryption, secure protocols, secure enclaves/DLP). The exam often tests your ability to match the state to the appropriate control.
Security Architecture
Forgetting to protect data in all three states; focusing only on data at rest.
Security Architecture
Failing to classify data, leading to either over-securing or under-securing information.
Security Architecture
Ignoring privacy regulations, which can result in severe legal and financial consequences.
Security Architecture
Ability to absorb and recover from disruptions.
Security Architecture
Duplication of components to prevent single points of failure.
Security Architecture
Ensuring systems are operational for a very high percentage of time.
Security Architecture
System continues operating without interruption despite component failures.
Security Architecture
Plan for restoring IT systems after a major incident.
Security Architecture
Plan for maintaining essential business functions during disruptions.
Security Architecture
Maximum acceptable downtime for a system or application.
Security Architecture
Maximum acceptable amount of data loss, measured in time.
Security Architecture
RPO is 'Point' of data, RTO is 'Time' to get back Online. Think P for Point, T for Time.
Security Architecture
The exam often tests your understanding of RTO and RPO. Remember: RTO is about TIME to recover, RPO is about DATA you can LOSE.
Security Architecture
Confusing RTO with RPO: RTO is about time to restore, RPO is about data loss.
Security Architecture
Underestimating the importance of testing DR/BC plans; untested plans often fail.
Security Architecture
Failing to involve business stakeholders in BC planning, leading to IT-centric plans that don't meet business needs.
Security Architecture
Process of securing a system by reducing its attack surface and vulnerabilities.
Security Operations
Granting users only the minimum access necessary to perform their job functions.
Security Operations
A set of minimum security configurations and best practices for a system or application.
Security Operations
Systematic process of tracking and managing an organization's assets throughout their lifecycle.
Security Operations
Maintaining the consistency of a system's performance, functional, and physical attributes.
Security Operations
Checking user-supplied data to ensure it conforms to expected formats and types, preventing attacks.
Security Operations
To remember hardening steps: 'DAPPER' - Disable unnecessary, Apply patches, Passwords strong, Permissions least, Eliminate defaults, Review regularly.
Security Operations
The exam often tests your understanding of hardening steps for various system types (OS, applications, network devices). Memorize common techniques like disabling unnecessary services, applying patches, and implementing least privilege. For asset management, focus on why it's important for security (e.g., 'you can't protect what you don't know about').
Security Operations
Forgetting to harden systems after initial deployment, leaving default configurations vulnerable.
Security Operations
Neglecting to regularly update asset inventories, leading to 'ghost' assets or unknown devices.
Security Operations
Applying patches without testing, which can cause system instability or downtime.
Security Operations
Continuous process to identify, assess, and mitigate security weaknesses.
Security Operations
Automated process to identify known security weaknesses.
Security Operations
Scan with authorized login access for deeper system analysis.
Security Operations
Scan without login access, simulating an external attacker.
Security Operations
Static Application Security Testing; analyzes source code for flaws.
Security Operations
Dynamic Application Security Testing; tests running applications for flaws.
Security Operations
Directly fixing a vulnerability, e.g., applying a patch.
Security Operations
To remember the Vulnerability Management Lifecycle: 'D-S-A-P-R-V' – 'Detect, Scan, Assess, Prioritize, Remediate, Verify.'
Security Operations
The exam often asks about the different types of vulnerability scans (credentialed vs. non-credentialed, network vs. host vs. application) and their use cases. Memorize the phases of the vulnerability management lifecycle and common tools like Nessus and Nmap.
Security Operations
Confusing vulnerability scanning with penetration testing; scanning identifies known flaws, pen testing exploits them.
Security Operations
Neglecting to perform credentialed scans, leading to an incomplete view of internal vulnerabilities.
Security Operations
Failing to follow up on identified vulnerabilities, leaving them unaddressed and systems exposed.
Security Operations
Security Information and Event Management; centralizes log data for analysis.
Security Operations
Intrusion Detection System; monitors network for malicious activity, alerts.
Security Operations
Intrusion Prevention System; monitors network for malicious activity, blocks.
Security Operations
Data Loss Prevention; prevents sensitive data from leaving the organization.
Security Operations
User and Entity Behavior Analytics; detects anomalous user behavior.
Security Operations
Security Orchestration, Automation, and Response; automates security tasks.
Security Operations
Reviewing system records to identify security incidents or issues.
Security Operations
Linking disparate events to identify patterns or complex attacks.
Security Operations
To remember the key enterprise tools, think: 'SIEM's ID-PS DLP's UEBA SOARs.' (SIEM, IDS, IPS, DLP, UEBA, SOAR)
Security Operations
The exam often tests your understanding of the *purpose* and *function* of each tool. Don't just memorize acronyms; know what problem each tool solves and how it contributes to overall security. Pay close attention to the distinction between IDS (detects) and IPS (detects and prevents).
Security Operations
Confusing IDS (detection only) with IPS (detection and prevention).
Security Operations
Underestimating the importance of proper log configuration and retention.
Security Operations
Believing a single security tool can provide complete protection without integration.
Security Operations
Tracking user activities and resource usage.
Security Operations
Role-Based Access Control; permissions based on user roles.
Security Operations
Discretionary Access Control; resource owner sets permissions.
Security Operations
Mandatory Access Control; system-enforced security labels.
Security Operations
Single Sign-On; one login for multiple applications.
Security Operations
Remember 'AAA' for Identity Management: Authenticate (Who are you?), Authorize (What can you do?), Account (What did you do?).
Security Operations
The exam frequently asks about the differences between authentication, authorization, and accounting. Memorize the 'AAA' acronym and what each A stands for. Also, be ready to identify examples of the three authentication factors: something you know, something you have, and something you are.
Security Operations
Confusing authentication (who you are) with authorization (what you can do).
Security Operations
Underestimating the importance of MFA; it's a critical security control.
Security Operations
Believing that simply having an IAM system guarantees security without proper configuration and policy enforcement.
Security Operations
Documented procedures for handling security incidents.
Security Operations
Documentation of evidence handling to prove integrity.
Security Operations
Process of collecting and analyzing digital evidence.
Security Operations
Computer Security Incident Response Team.
Security Operations
Limiting the scope and impact of an incident.
Security Operations
Removing the root cause of an incident.
Security Operations
Restoring systems to normal operation.
Security Operations
PREPARE for DETECTED incidents, CONTAIN them, ERADICATE the threat, RECOVER, then POST-mortem.
Security Operations
The CompTIA Security+ exam heavily emphasizes the incident response lifecycle. Memorize the NIST phases (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity) and recognize keywords associated with each phase.
Security Operations
Skipping phases of the incident response lifecycle, especially post-incident review.
Security Operations
Failing to maintain a proper chain of custody during digital forensics, invalidating evidence.
Security Operations
Not testing incident response plans regularly, leading to ineffective responses during actual incidents.
Security Operations
Aligning IT strategy with business strategy to achieve organizational goals.
Security Program Management and Oversight
Framework for enterprise IT governance and management, focusing on control objectives.
Security Program Management and Oversight
Framework for IT service management, covering service lifecycle stages.
Security Program Management and Oversight
International standard for Information Security Management Systems (ISMS).
Security Program Management and Oversight
Process of identifying, assessing, and controlling threats to an organization.
Security Program Management and Oversight
Eliminating the activity that creates the risk.
Security Program Management and Oversight
Shifting risk to another party, often via insurance or outsourcing.
Security Program Management and Oversight
Reducing the likelihood or impact of a risk through controls.
Security Program Management and Oversight
Decision to take no action against a risk, often due to cost or low impact.
Security Program Management and Oversight
To remember the risk strategies: A.T.M.A. (Avoid, Transfer, Mitigate, Accept). Think of an 'ATM' as a place where you manage your financial risks!
Security Program Management and Oversight
The exam often asks about the purpose of specific frameworks. Remember COBIT for IT governance, ITIL for IT service management, and ISO/IEC 27001 for information security management systems.
Security Program Management and Oversight
Confusing governance frameworks with compliance regulations; frameworks are guides, regulations are mandates.
Security Program Management and Oversight
Not understanding that risk acceptance is a deliberate, informed decision, not just ignoring a risk.
Security Program Management and Oversight
Believing risk can be completely eliminated; it can only be managed and reduced.
Security Program Management and Oversight
Assigns monetary values to risk components for financial assessment.
Security Program Management and Oversight
The total monetary worth of a specific asset.
Security Program Management and Oversight
Percentage of asset value lost if a specific threat occurs.
Security Program Management and Oversight
Monetary loss expected from one occurrence of a threat event (AV x EF).
Security Program Management and Oversight
Estimated frequency of a threat event occurring within one year.
Security Program Management and Oversight
Total expected financial loss from a threat over a one-year period (SLE x ARO).
Security Program Management and Oversight
SLEepy AROma makes you ALErt! SLE = AV x EF, ARO is the frequency, ALE = SLE x ARO.
Security Program Management and Oversight
The exam often presents scenarios where you need to calculate SLE, ARO, or ALE. Remember the formulas: SLE = AV * EF, and ALE = SLE * ARO. Look for keywords like 'asset value,' 'percentage lost,' 'occurs annually,' or 'expected frequency.'
Security Program Management and Oversight
Confusing Exposure Factor (EF) with the actual monetary loss; EF is a percentage.
Security Program Management and Oversight
Incorrectly calculating ARO, especially when events occur less frequently than once a year (e.g., once every 5 years is ARO 0.2, not 5).
Security Program Management and Oversight
Forgetting to convert the Exposure Factor percentage into a decimal before multiplying (e.g., 50% is 0.5).
Security Program Management and Oversight
Risk from external vendors, partners, or service providers.
Security Program Management and Oversight
Third-Party Risk Management; structured process for vendor risk.
Security Program Management and Oversight
Research and investigation before entering a contract.
Security Program Management and Oversight
Auditor's report on a service organization's controls.
Security Program Management and Oversight
Risk associated with vendors in the product/service delivery chain.
Security Program Management and Oversight
Contract defining service and security expectations.
Security Program Management and Oversight
Remember 'VENDORS' for key Third-Party Risk areas: Vulnerabilities, External access, Non-compliance, Data handling, Operational impact, Reputation, Security controls.
Security Program Management and Oversight
The exam often tests your understanding of what constitutes a third party and the types of reports used to assess their security, such as SOC 2 Type 2. Memorize that SOC 2 reports focus on security, availability, processing integrity, confidentiality, and privacy.
Security Program Management and Oversight
Assuming a third party's security is 'good enough' without verification. Always verify through audits or reports.
Security Program Management and Oversight
Not including specific security clauses and audit rights in contracts with third parties.
Security Program Management and Oversight
Failing to continuously monitor third-party performance and security posture after initial onboarding.
Security Program Management and Oversight
Simulated cyberattack to exploit vulnerabilities and assess risk.
Security Program Management and Oversight
Pen test with no prior knowledge of the target system.
Security Program Management and Oversight
Pen test with full knowledge of the target system.
Security Program Management and Oversight
Pen test with limited, partial knowledge of the target.
Security Program Management and Oversight
Gathering information about a target before an attack.
Security Program Management and Oversight
Leveraging a vulnerability to gain unauthorized access.
Security Program Management and Oversight
Examining source code for security flaws.
Security Program Management and Oversight
To remember the pen test phases: 'P-S-G-M-A-R' (Planning, Scanning, Gaining, Maintaining, Analysis, Reporting).
Security Program Management and Oversight
The exam often tests your ability to distinguish between vulnerability scanning and penetration testing. Remember that scanning IDENTIFIES, while pen testing EXPLOITS. Also, know the different 'box' types (black, white, gray) and what level of information they imply for the tester.
Security Program Management and Oversight
Confusing vulnerability scanning with penetration testing; scanning finds, pen testing exploits.
Security Program Management and Oversight
Not clearly defining the scope and rules of engagement before a penetration test, leading to legal or operational issues.
Security Program Management and Oversight
Failing to remediate vulnerabilities found during assessments, making the entire exercise pointless.
Security Program Management and Oversight
General understanding of threats and policies.
Security Program Management and Oversight
Developing specific skills for job functions.
Security Program Management and Oversight
In-depth, formal learning for professionals.
Security Program Management and Oversight
Testing employees' ability to identify phishing.
Security Program Management and Oversight
Employees acting as a defense against threats.
Security Program Management and Oversight
Applying game-design elements to learning.
Security Program Management and Oversight
To remember the difference: A.T.E. - **A**wareness (broad), **T**raining (skills), **E**ducation (deep).
Security Program Management and Oversight
The exam often asks about the *purpose* and *components* of security awareness programs. Look for keywords like 'reduce human error,' 'foster security culture,' or 'compliance requirements.' Remember the distinction between awareness, training, and education.
Security Program Management and Oversight
Treating security awareness as a one-time event rather than a continuous process.
Security Program Management and Oversight
Using generic, irrelevant content that doesn't resonate with employees' daily tasks.
Security Program Management and Oversight
Focusing solely on technical controls and neglecting the human element of security.
Security Program Management and Oversight