CompTIA Security+ Study Library
SY0-701
23 free articles on the concepts the SY0-701 exam tests, grouped by exam domain. Each one backs real questions in our practice exam.
General Security Concepts
Security Architecture
- 802.1X Port-Based Network Access Control, Explained How IEEE 802.1X authenticates devices before granting network access: supplicant, authenticator, RADIUS roles, EAP, MAB, and SY0-701 exam patterns.
- EAP-TLS: Certificate-Based Wi-Fi and Network Authentication EAP-TLS uses digital certificates on both client and server for passwordless mutual authentication. Learn how it works and how SY0-701 tests it.
- Host-Based Intrusion Prevention (HIPS): Blocking Threats on the Endpoint How a host-based intrusion prevention system (HIPS) blocks malicious activity on the endpoint in real time, and how it differs from HIDS and EDR.
- IDS vs IPS: The Difference and When to Use Each IDS detects and alerts; IPS sits inline and blocks. Learn how each works, how an IPS differs from a firewall, and how SY0-701 tests the distinction.
- Inline vs Passive Security Devices: Deployment, Fail-Open, and Fail-Closed What inline deployment means, how it differs from passive monitoring, and why fail-open vs fail-closed decides availability when a device dies.
- MAC Address Filtering: Why It's a Weak Security Control MAC filtering is easily defeated because hardware addresses are visible in every frame and trivially spoofed. Here's why, and what SY0-701 expects.
- WPA3 and SAE: How Modern Wi-Fi Stops Offline Dictionary Attacks WPA3's SAE handshake ends offline dictionary attacks on Wi-Fi passphrases. See how it beats WPA2's four-way handshake and how SY0-701 tests it.
Security Operations
- False Positives and False Negatives in IDS/IPS Alerting How false positives and false negatives occur in IDS/IPS alerting, why inline blocking raises the stakes, and how to tune and verify alerts.
- Network Sensors and Monitoring Architecture What a network sensor does in security monitoring: where sensors sit, how they capture traffic, and how IDS and IPS sensor logs differ.
- Signature-Based Detection: How It Works and Where It Fails Signature-based detection matches traffic to known attack patterns — fast and precise, but blind to zero-days. See how SY0-701 tests the gap.
- SPAN Ports vs Network Taps: Passive Traffic Monitoring Explained How SPAN port mirroring and network taps feed monitoring tools, why taps win on high-throughput links, and what passive really means on SY0-701.
Security Program Management and Oversight
- Continuous Compliance: Staying Secure Between Audits Due care vs due diligence, internal and external compliance monitoring, and the data classification levels that drive it — explained for SY0-701.
- Juice Jacking: The Risk of Public USB Charging Juice jacking abuses public USB ports to steal data or install malware while your phone charges. Here's how it works and the safest ways to charge.
- PCI DSS Assessments: QSA Audits vs Self-Assessment Questionnaires How PCI DSS compliance is actually validated: QSA on-site audits vs Self-Assessment Questionnaires, who needs which, and how SY0-701 tests it.
- Public Wi-Fi Risks: What Actually Happens on an Open Network Open Wi-Fi sends your traffic in cleartext, exposing you to sniffing, evil twins, and on-path attacks. Learn the real risks and what a VPN fixes.
- Reducing PCI DSS Scope with Segmentation and Tokenization Why network segmentation is the go-to answer for shrinking PCI DSS audit scope, how tokenization and P2PE help, and what SY0-701 asks about it.
- Security Awareness for Remote and Hybrid Work What remote work security best practices belong in awareness training — home Wi-Fi hardening, VPN habits, device security, and hybrid-work policy.
Threats, Vulnerabilities, and Mitigations
- DNS Cache Poisoning and Domain Hijacking, Explained DNS cache poisoning corrupts resolver answers; domain hijacking steals the domain itself. Learn how each attack works and how SY0-701 tests them.
- Keyloggers: How Keystroke-Logging Malware Works A keylogger records every keystroke to steal passwords and card numbers. See how software and hardware keyloggers work and what actually stops them.
- Privilege Escalation: Vertical, Horizontal, and How Attackers Get There Vertical privilege escalation gains higher rights; horizontal reaches a peer's data. Learn how each works, real techniques, and how SY0-701 tests them.
- The Birthday Attack: Hash Collisions and Probability A birthday attack finds two inputs sharing a hash far faster than brute force, thanks to probability. Learn why, the math, and how SY0-701 tests it.
- Wireless, Wired, and Bluetooth Attack Surfaces Compared Compare wireless, wired, and Bluetooth attack surfaces for Security+ SY0-701 — what risks they share, what's unique, and how each is secured.
Reading is step one — practicing is what passes the exam.
1,300 original SY0-701 questions, every answer explained, $69 once — no subscription.