Step2Study
IT & TechnologySY0-701100% Free

CompTIA Security+ (SY0-701)

Practice bank
256 Qs
Real exam
90 Qs
Time limit
90 min
Passing
750 on a 100–900 scale (~83%)

Exam blueprint

General Security Concepts
12%
Threats, Vulnerabilities, and Mitigations
22%
Security Architecture
18%
Security Operations
28%
Security Program Management and Oversight
20%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 90 min · pass 83% · 256 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Part of a learning path

Study with friends

Challenge a friend to beat your score.

CompTIA Security+ (SY0-701) practice test questions

Sample questions from the 256-question bank, with answers and explanations.

All questions
  1. 1. A SIEM correlation rule triggers an alert when a single source IP generates 10 or more failed authentication attempts against the same user account within any 5-minute sliding window. The following failed login events are logged for user "jsmith" from one IP address: 3 attempts at 09:00, 4 attempts at 09:01, 2 attempts at 09:03, and 3 attempts at 09:05. Did the correlation rule trigger, and why?

    Security Operations

    • A. Yes, because the very first 3 attempts at 09:00 alone exceeded the threshold
    • B. No, because only 3 attempts occurred at 09:05, which is below the threshold
    • C. No, because a correlation rule requires attempts from multiple source IP addresses
    • D. Yes, because 12 failed attempts occurred within the 09:00–09:05 five-minute window, exceeding the threshold
    Show answer

    D. Yes, because 12 failed attempts occurred within the 09:00–09:05 five-minute window, exceeding the threshold

    Summing attempts within the 5-minute window from 09:00 to 09:05 gives 3+4+2+3 = 12 failed attempts, which meets and exceeds the threshold of 10, so the rule triggers. Evaluating only the last timestamp in isolation (option B) or the first timestamp alone (option C) ignores the sliding window aggregation the correlation rule is designed to perform.

  2. 2. A digital forensics examiner creates a bit-for-bit image of a seized hard drive and calculates a SHA-256 hash of both the original and the image. What is the PRIMARY purpose of this hashing step in maintaining chain of custody?

    Security Operations

    • A. To compress the image file for easier storage and transport
    • B. To encrypt the evidence so unauthorized parties cannot view it
    • C. To speed up the indexing process during keyword searches
    • D. To prove the forensic image is an exact, unaltered copy of the original evidence
    Show answer

    D. To prove the forensic image is an exact, unaltered copy of the original evidence

    Hashing the original drive and its forensic image produces a unique digital fingerprint; matching hash values prove the copy is identical and unaltered, which is essential for maintaining evidence integrity and admissibility in legal proceedings as part of chain of custody.

  3. 3. A company wants to determine which business processes are most critical to resume first after a disruption, along with the maximum acceptable downtime for each. Which activity should the company perform?

    Security Program Management and Oversight

    • A. Penetration test
    • B. Business Impact Analysis (BIA)
    • C. Vulnerability assessment
    • D. Tabletop exercise
    Show answer

    B. Business Impact Analysis (BIA)

    A Business Impact Analysis (BIA) identifies critical business functions, their dependencies, and metrics such as Recovery Time Objective (RTO) and Maximum Tolerable Downtime (MTD), enabling prioritization of recovery efforts.

  4. 4. A user who is authenticated to an online banking portal unknowingly visits a malicious website that contains a hidden form auto-submitting a funds transfer request to the bank's server using the user's active session cookie. Which attack does this describe?

    Threats, Vulnerabilities, and Mitigations

    • A. Cross-site request forgery
    • B. Session replay attack
    • C. SQL injection
    • D. Cross-site scripting
    Show answer

    A. Cross-site request forgery

    Cross-site request forgery (CSRF) tricks an authenticated user's browser into submitting an unwanted, state-changing request to a trusted site using the victim's existing session, without the victim's knowledge. Because the browser automatically includes the session cookie, the bank server processes the forged request as legitimate.

  5. 5. In a zero trust architecture, a user's request to access a financial application is evaluated by policy logic and then a decision must actually be carried out on the network, such as opening or blocking a session. Which component performs this enforcement action?

    General Security Concepts

    • A. Policy Enforcement Point
    • B. Policy Decision Point
    • C. Policy Administrator
    • D. Trust Broker
    Show answer

    A. Policy Enforcement Point

    The Policy Enforcement Point (PEP) sits inline between the subject and resource and carries out the decision made by the Policy Decision Point, such as granting or denying access.

  6. 6. A security team wants to automatically isolate an infected endpoint from the network, disable the compromised user account, and open a ticket whenever the EDR platform detects ransomware behavior, all without analyst intervention. Which capability BEST supports this requirement?

    Security Operations

    • A. A SOAR playbook that orchestrates predefined automated response actions
    • B. A manual runbook printed for the on-call analyst
    • C. A vulnerability scanner scheduled to run weekly
    • D. A configuration management database (CMDB) update script
    Show answer

    A. A SOAR playbook that orchestrates predefined automated response actions

    Security Orchestration, Automation, and Response (SOAR) platforms use playbooks to automatically execute a sequence of response actions across multiple tools when specific triggers occur, enabling fast, consistent incident response without manual steps.

  7. 7. A SOC analyst configures a monitoring platform to build a baseline of typical login times, data access volume, and file transfer patterns for each employee. When a user account suddenly downloads ten times its normal data volume at 3 a.m. from an unusual location, the platform generates a high-risk alert even though no signature-based rule was triggered. Which technology enables this capability?

    Security Operations

    • A. Data loss prevention (DLP)
    • B. Endpoint detection and response (EDR)
    • C. User and entity behavior analytics (UEBA)
    • D. Security orchestration, automation, and response (SOAR)
    Show answer

    C. User and entity behavior analytics (UEBA)

    UEBA uses machine learning to establish behavioral baselines for users and entities, then flags statistically anomalous activity (like unusual volume, time, or location) even without a matching signature. DLP focuses on content inspection to block sensitive data leaving the network, EDR focuses on endpoint process/telemetry analysis, and SOAR automates response actions rather than detecting behavioral anomalies.

  8. 8. A development team wants to prevent SQL injection attacks against a customer-facing web application without altering the application's business logic. Which of the following is the MOST effective mitigation to implement in the application's database access layer?

    Threats, Vulnerabilities, and Mitigations

    • A. Enforcing complex password policies for database accounts
    • B. Using parameterized queries (prepared statements)
    • C. Implementing rate limiting on the login page
    • D. Encrypting all data at rest in the database
    Show answer

    B. Using parameterized queries (prepared statements)

    Parameterized queries (prepared statements) separate SQL code from user-supplied data, ensuring input is always treated as data and never executed as part of the SQL command. This directly addresses the root cause of SQL injection, unlike password policies, encryption at rest, or rate limiting, which do not prevent malicious input from being interpreted as code.

  9. 9. A malware analyst receives a suspicious executable and needs to examine its embedded strings, imported library functions, and file header structure without ever executing the code, in order to minimize risk to the analysis environment. Which technique should the analyst use?

    Security Operations

    • A. Network traffic capture during execution
    • B. Static analysis
    • C. Dynamic sandboxing
    • D. Behavioral analysis in a live environment
    Show answer

    B. Static analysis

    Static analysis examines a file's code, strings, headers, and imports without running it, making it the safest way to gather initial indicators before deciding whether further dynamic testing in an isolated sandbox is warranted.

  10. 10. An organization's internal audit team reviews financial controls each quarter, while an outside CPA firm independently reviews the same controls annually and issues a report to the board and external stakeholders. What is the primary advantage of the external audit compared to the internal audit?

    Security Program Management and Oversight

    • A. It provides independent, unbiased assurance to external stakeholders
    • B. It replaces the need for any internal control monitoring
    • C. It is performed more frequently and catches issues faster
    • D. It has full access to make changes to the controls being tested
    Show answer

    A. It provides independent, unbiased assurance to external stakeholders

    External audits are conducted by independent third parties with no organizational bias, providing credible, objective assurance to external stakeholders such as investors, regulators, or customers. Internal audits, while valuable for continuous self-monitoring, lack this independence.

  11. 11. A financial services firm requires that all customer data transmitted between its mobile app and backend API servers cannot be read even if intercepted on public Wi-Fi networks. Which control category directly addresses this requirement?

    Security Architecture

    • A. Data at rest encryption
    • B. Data in use encryption
    • C. Data in transit encryption
    • D. Data masking
    Show answer

    C. Data in transit encryption

    Protecting data as it moves across a network, such as between a mobile app and API servers, is the definition of data-in-transit encryption, typically implemented via TLS.

  12. 12. A vulnerability management team supports thousands of laptops that frequently connect from home networks, hotel Wi-Fi, and coffee shops, rarely joining the corporate network directly. The team needs continuous, up-to-date vulnerability data regardless of the laptops' network location. Which scanning approach best meets this need?

    Security Operations

    • A. Non-credentialed port scanning
    • B. Agent-based scanning
    • C. Unauthenticated network-based scanning
    • D. Passive network scanning
    Show answer

    B. Agent-based scanning

    Agent-based scanning installs lightweight software on each endpoint that reports vulnerability data over the internet regardless of network location, making it ideal for remote or intermittently connected devices. Network-based and passive scans require the device to be reachable on a monitored network segment.

  13. 13. A company wants to ensure that only corporate laptops with up-to-date antivirus signatures and the latest OS patches are permitted to join the internal network, while non-compliant devices are automatically placed into a quarantine VLAN. Which technology should be implemented?

    Security Operations

    • A. Data loss prevention (DLP)
    • B. Web application firewall (WAF)
    • C. Virtual private network (VPN)
    • D. Network access control (NAC)
    Show answer

    D. Network access control (NAC)

    NAC evaluates device posture (patch level, AV status) before granting network access and can dynamically quarantine non-compliant devices to a restricted VLAN. VPN provides secure remote connectivity, DLP prevents sensitive data exfiltration, and a WAF protects web applications—none perform posture-based network admission control.

  14. 14. During an incident response, a security team discovers that a compromised Linux server's kernel-level components have been modified to hide malicious processes and network connections from standard system utilities. Which type of malware is most likely responsible?

    Threats, Vulnerabilities, and Mitigations

    • A. Worm
    • B. Logic bomb
    • C. Adware
    • D. Rootkit
    Show answer

    D. Rootkit

    A rootkit modifies the operating system at a low level, often the kernel, to conceal malicious processes, files, and connections from detection tools. This gives attackers persistent, stealthy access to the compromised system.

  15. 15. After restoring services from a widespread outage caused by a misconfigured firewall rule, the incident response team wants to determine the underlying reason the misconfiguration was deployed without review. Which activity should the team perform?

    Security Operations

    • A. CVSS rescoring
    • B. Root cause analysis
    • C. Chain of custody documentation
    • D. Order of volatility assessment
    Show answer

    B. Root cause analysis

    Root cause analysis systematically investigates why an incident occurred, tracing back to the underlying process failure, such as a bypassed change management review, so preventive measures can be implemented.

  16. 16. A compliance team requires immediate alerts whenever critical operating system files, such as boot configuration files or system binaries, are modified without an approved change ticket. Which control should be implemented to meet this requirement?

    Security Operations

    • A. Data loss prevention (DLP)
    • B. File integrity monitoring (FIM)
    • C. User and entity behavior analytics (UEBA)
    • D. Network access control (NAC)
    Show answer

    B. File integrity monitoring (FIM)

    FIM tools calculate and store cryptographic hashes of critical files and alert when a file's hash changes, indicating unauthorized modification. DLP focuses on data exfiltration, NAC controls network admission, and UEBA focuses on behavioral anomalies rather than file content changes.

  17. 17. An e-commerce platform designs its web tier for high availability using an N+1 redundancy model. Each server can handle 250 concurrent sessions, and the platform must support a peak load of 1,000 concurrent sessions. How many servers should be deployed?

    Security Architecture

    • A. 5
    • B. 8
    • C. 4
    • D. 6
    Show answer

    A. 5

    N is calculated as the load divided by per-server capacity: 1,000 / 250 = 4 servers needed to handle peak load. N+1 redundancy adds one additional server for failover, resulting in 4 + 1 = 5 total servers.

  18. 18. A security team runs a tool nightly that compares each server's current configuration settings against the organization's approved secure image and generates an alert whenever a setting no longer matches the standard. What is this process called?

    Security Operations

    • A. Penetration testing
    • B. Vulnerability scanning
    • C. Attack surface mapping
    • D. Configuration compliance scanning
    Show answer

    D. Configuration compliance scanning

    Configuration compliance scanning checks systems against an established secure baseline and flags deviations, helping maintain consistent hardening over time. Vulnerability scanning looks for known weaknesses/CVEs, penetration testing simulates attacks, and attack surface mapping identifies exposed entry points—none of these specifically compare configs to a baseline.

  19. 19. An organization wants administrators to check out credentials from a centralized vault for a limited session, with all password rotations and usage automatically logged for audit purposes, rather than administrators memorizing static passwords. Which solution best meets this requirement?

    Security Operations

    • A. Single sign-on (SSO)
    • B. Network access control (NAC)
    • C. Role-based access control (RBAC)
    • D. Privileged access management (PAM) solution
    Show answer

    D. Privileged access management (PAM) solution

    A PAM solution centrally vaults, rotates, and audits privileged credentials, issuing temporary checkout access instead of allowing administrators to know static passwords. SSO reduces authentication prompts across applications but doesn't manage privileged credential vaulting, RBAC assigns permissions by job role, and NAC governs network admission.

  20. 20. A security architect is redesigning network access controls under a zero trust model. Instead of relying on a flat internal network where any authenticated device can reach any server, the architect wants to isolate each application workload so that lateral movement between systems requires explicit policy approval for every connection. Which approach BEST achieves this goal?

    Security Operations

    • A. Enabling port security on all access-layer switches
    • B. Deploying a single perimeter firewall at the network edge
    • C. Implementing microsegmentation with policy enforcement between workloads
    • D. Requiring VPN access for all remote employees
    Show answer

    C. Implementing microsegmentation with policy enforcement between workloads

    Microsegmentation divides the network into granular zones, often down to the individual workload level, and enforces explicit policy for every connection, directly aligning with zero trust's principle of never trusting implicit lateral access.

  21. 21. A penetration tester crafts the following input for a corporate directory search field: *)(uid=*))(|(uid=*. After submission, the application returns all user records instead of just the intended search result. Which type of injection attack does this represent?

    Threats, Vulnerabilities, and Mitigations

    • A. SQL injection
    • B. LDAP injection
    • C. Command injection
    • D. XML injection
    Show answer

    B. LDAP injection

    LDAP injection manipulates LDAP query filters using special characters such as parentheses, asterisks, and pipe symbols to alter the logic of directory service queries, often bypassing filters to return unauthorized data. The crafted string uses LDAP filter syntax (uid=*, parentheses, and the OR operator |) to exploit an improperly sanitized directory search.

  22. 22. A financial company requires that the employee who initiates a wire transfer request cannot also be the employee who approves and releases the transfer. Which security principle does this control enforce?

    Security Operations

    • A. Least privilege
    • B. Separation of duties
    • C. Mandatory vacation
    • D. Job rotation
    Show answer

    B. Separation of duties

    Separation of duties splits a critical task among multiple people so no single individual can complete a sensitive process alone, reducing fraud and error risk.

  23. 23. An analyst plots each identified risk on a chart using descriptive labels such as 'High,' 'Medium,' and 'Low' for both likelihood and impact, rather than assigning specific dollar values. Which risk assessment approach is being used?

    Security Program Management and Oversight

    • A. Single loss expectancy calculation
    • B. Annualized loss expectancy calculation
    • C. Qualitative analysis
    • D. Quantitative analysis
    Show answer

    C. Qualitative analysis

    Qualitative risk analysis uses subjective, descriptive categories like High/Medium/Low instead of precise numerical or monetary values to rank risks.

  24. 24. An organization is implementing an asset management program for its IT equipment. Which practice would BEST help the organization track hardware throughout its entire lifecycle, from procurement to disposal?

    Security Operations

    • A. Conducting an inventory audit only when a device is reported lost
    • B. Allowing employees to label their own equipment informally
    • C. Assigning a unique asset tag and recording it in a centralized inventory database
    • D. Storing asset information in individual spreadsheets on each technician's laptop
    Show answer

    C. Assigning a unique asset tag and recording it in a centralized inventory database

    A centralized inventory database with unique asset tags provides consistent tracking of ownership, location, status, and lifecycle stage for every device, supporting accountability and disposal procedures.

  25. 25. A network administrator is redesigning a corporate office network. Guest Wi-Fi users, employee workstations, and VoIP phones must all be logically separated so that a compromise on one group cannot directly reach the others, while sharing the same physical switches. Which technology BEST accomplishes this?

    Security Architecture

    • A. Network address translation
    • B. VLANs with inter-VLAN access control lists
    • C. Port security based on MAC address
    • D. A single flat subnet with a host-based firewall on each device
    Show answer

    B. VLANs with inter-VLAN access control lists

    VLANs logically segment traffic on shared physical switches, and applying ACLs between VLANs enforces which groups can communicate, limiting lateral movement between guest, employee, and VoIP segments.

CompTIA Security+ (SY0-701) flashcards

Tap a card to flip it. 212 flashcards in the full deck.

  • SIEM Correlation Rule Thresholds

    Flip card

    A rule that aggregates related events (e.g., failed logins) over a defined time window and triggers an alert once a cumulative threshold is met, rather than evaluating single events in isolation.

    • Uses sliding time windows to sum related events
    • Reduces noise compared to alerting on every single event
    • Threshold tuning balances detection speed vs false positives
    Study this card →
  • Hashing for Evidence Integrity

    Flip card

    Cryptographic hashing (e.g., SHA-256) creates a unique digest of forensic evidence used to verify that a copy is identical to the original and has not been altered.

    • Matching hash values confirm image integrity
    • Part of maintaining chain of custody documentation
    • Common algorithms: SHA-256, MD5 (legacy)
    Study this card →
  • Business Impact Analysis (BIA)

    Flip card

    A process that identifies and evaluates the potential effects of disruptions to critical business operations, establishing priorities like RTO and MTD.

    • Outputs include Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
    • Forms the foundation for business continuity and disaster recovery planning
    • Focuses on business processes, not technical vulnerabilities
    Study this card →
  • Cross-Site Request Forgery (CSRF)

    Flip card

    An attack that forces an authenticated user's browser to send unwanted requests to a web application in which the user is currently logged in.

    • Exploits trust a site has in the user's browser
    • Mitigated with anti-CSRF tokens and SameSite cookies
    • Requires the victim to be actively authenticated
    Study this card →
  • Policy Enforcement Point (PEP)

    Flip card

    The zero trust component that enforces the access decision by allowing, denying, or terminating a connection between subject and resource.

    • Works together with the Policy Decision Point (PDP)
    • Sits inline in the data path
    • Defined in NIST SP 800-207 zero trust architecture
    Study this card →
  • SOAR Playbook

    Flip card

    A predefined, automated workflow within a Security Orchestration, Automation, and Response platform that executes multiple response actions in sequence when triggered by an alert.

    • Orchestrates actions across multiple security tools
    • Reduces mean time to respond (MTTR)
    • Can isolate hosts, disable accounts, create tickets automatically
    Study this card →
  • User and Entity Behavior Analytics (UEBA)

    Flip card

    A security analytics approach that establishes baselines of normal user/entity behavior and detects anomalies that may indicate compromise or insider threats.

    • Uses machine learning/statistical modeling
    • Detects anomalies without relying on known signatures
    • Often integrated into SIEM platforms
    Study this card →
  • Parameterized Queries

    Flip card

    A secure coding technique that uses precompiled SQL statements with placeholders for user input, preventing the input from being interpreted as executable SQL code.

    • Also called prepared statements
    • Separates SQL logic from data
    • Primary defense against SQL injection, along with input validation and stored procedures
    Study this card →
  • Static Malware Analysis

    Flip card

    Examining a malware sample's code, strings, headers, and structure without executing it, to safely gather indicators of behavior and intent.

    • No code execution required
    • Includes string extraction, disassembly, and header inspection
    • Safer but less revealing than dynamic analysis
    Study this card →
  • Internal vs. External Audit

    Flip card

    Internal audits are performed by an organization's own staff for continuous self-assessment, while external audits are performed by independent third parties to provide unbiased assurance to outside stakeholders.

    • Internal audits are typically more frequent and operational in focus
    • External audits provide independence and credibility to regulators/investors
    • Both are components of a mature governance and oversight program
    Study this card →
  • Data in Transit

    Flip card

    Data actively moving across a network, protected primarily through encryption protocols like TLS or IPsec VPNs.

    • TLS 1.2/1.3 commonly used for transit protection
    • Prevents eavesdropping/man-in-the-middle attacks
    • One of three data states: rest, transit, use
    Study this card →
  • Agent-Based Vulnerability Scanning

    Flip card

    A scanning method where software agents are installed on endpoints to collect vulnerability data locally and report it to a central console, independent of network location.

    • Ideal for remote/roaming devices
    • Provides continuous local visibility
    • Requires agent deployment and maintenance overhead
    Study this card →
  • Network Access Control (NAC)

    Flip card

    A security solution that checks device compliance (patches, AV, configuration) before allowing network access, quarantining non-compliant devices.

    • Enforces posture assessment at connection time
    • Can use 802.1X for authentication
    • Non-compliant devices routed to remediation VLAN
    Study this card →
  • Rootkit

    Flip card

    Malware that gains and maintains privileged access to a system while hiding its presence, often by modifying the OS kernel or core utilities.

    • Operates at kernel or firmware level for stealth
    • Difficult to detect with standard OS tools
    • Often requires specialized detection or full OS reinstall to remove
    Study this card →
  • Root Cause Analysis

    Flip card

    A structured investigation technique used after an incident to identify the fundamental underlying cause, not just the symptoms, to prevent recurrence.

    • Often performed during the lessons-learned phase of incident response
    • Techniques include the '5 Whys' and fishbone diagrams
    • Leads to corrective actions like updated change management controls
    Study this card →
  • File Integrity Monitoring (FIM)

    Flip card

    A security control that monitors and alerts on unauthorized changes to critical system or configuration files by comparing current file hashes to a known-good baseline.

    • Uses cryptographic hashing to detect changes
    • Commonly monitors OS binaries, config files, and logs
    • Helps detect rootkits, tampering, and unauthorized changes
    Study this card →
  • N+1 Redundancy

    Flip card

    A fault-tolerance design where one extra unit of capacity (N+1) is provisioned beyond the minimum required (N) to handle a component failure without service disruption.

    • N = required capacity units to meet load
    • N+1 adds exactly one spare unit
    • Contrasts with 2N (full duplicate) redundancy
    Study this card →
  • Configuration Compliance Scanning

    Flip card

    Automated comparison of a system's current settings against an approved secure baseline to detect unauthorized drift.

    • Detects configuration drift over time
    • Complements vulnerability scanning
    • Often tied to hardening standards like CIS benchmarks
    Study this card →
  • Privileged Access Management (PAM)

    Flip card

    A solution that centrally stores, rotates, and audits privileged account credentials, granting temporary checkout access instead of persistent knowledge of passwords.

    • Automatically rotates privileged passwords
    • Logs all checkout and usage sessions
    • Reduces standing privileged credential exposure
    Study this card →
  • Microsegmentation

    Flip card

    A zero trust network security technique that divides a network into small, isolated segments—often per workload—requiring explicit policy approval for any communication between them.

    • Core zero trust principle: never trust, always verify, even internally
    • Reduces blast radius by limiting lateral movement
    • Often implemented via software-defined networking or host-based firewalls
    Study this card →
  • LDAP Injection

    Flip card

    An attack that manipulates LDAP (Lightweight Directory Access Protocol) query filters by injecting special characters to alter search logic and bypass access controls.

    • Exploits parentheses, asterisks, and boolean operators in filters
    • Can bypass authentication or dump directory data
    • Mitigated by input sanitization and parameterized LDAP queries
    Study this card →
  • Separation of Duties

    Flip card

    A control that divides critical tasks among multiple people so no single individual can complete a sensitive process alone.

    • Prevents fraud and error by requiring collusion for abuse
    • Common in financial approvals and change management
    • Different from least privilege, which limits access scope
    Study this card →
  • Qualitative Risk Analysis

    Flip card

    A risk assessment method that uses descriptive, subjective categories (e.g., High/Medium/Low) rather than numeric values to rank likelihood and impact.

    • Faster and less resource-intensive than quantitative analysis
    • Relies on expert judgment and relative rankings
    • Often combined with quantitative methods for a hybrid semi-quantitative approach
    Study this card →
  • Asset Management

    Flip card

    The process of tracking and managing organizational assets throughout their lifecycle, including acquisition, use, maintenance, and disposal.

    • Unique asset tags/IDs enable tracking
    • Centralized inventory improves accountability
    • Lifecycle includes procurement to decommissioning
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.