SecuritySeptember 30, 202625 min read

Security+ SY0-701 Acronyms & Glossary: 55 Terms (2026)

55 Security+ terms defined in plain English, each with how SY0-701 questions phrase it and the rival term it gets confused with, plus 84 acronyms to scan before exam day.

  • 55Terms defined
  • 84 listedAcronyms
  • SY0-701Exam
  • Up to 90Questions
  • 750 / 900Pass mark
Security+ SY0-701 acronyms and glossary study sheet

How to use this glossary

Security+ is a vocabulary exam wearing a scenario costume. Most SY0-701 questions describe a situation in two or three sentences and ask you to name the control, attack or process it describes, and the four answer choices are usually close relatives: SIEM and SOAR, IDS and IPS, RTO and RPO. If you only know what an acronym stands for, those questions become coin flips. This glossary defines each term, then tells you the cue in the question that points to it and the rival it gets confused with.

Version note: as of September 2026, SY0-701 is still the current Security+ exam. CompTIA says Security+ V8 (SY0-801) is expected to launch on or around November 17, 2026, and the English SY0-701 exam is scheduled to retire on June 11, 2027, so both versions will overlap for several months. A Security+ certification earned on SY0-701 stays valid for three years either way. Confirm dates on CompTIA's site before booking.

Every term below is tagged with the exam domain it belongs to. This is where the vocabulary load sits across the SY0-701 blueprint:

  • CoreGeneral Security Concepts12%9 terms
  • ThreatThreats, Vulnerabilities, and Mitigations22%11 terms
  • ArchSecurity Architecture18%7 terms
  • OpsSecurity Operations28%18 terms
  • GRCSecurity Program Management and Oversight20%10 terms

Each card has three layers: a plain-English definition, an On the exam line describing how questions use the term, and — where one exists — the term it is most often confused with. Click that link to jump straight to the rival definition.

The A–Z glossary

ABACAttribute-Based Access ControlOps

An access model that grants or denies each request by evaluating attributes of the user, the resource, the action and the environment, such as department, data label, device health, location or time of day.

On the examConditions are the cue: 'only from a managed device', 'only during business hours', 'only if the file is tagged Internal'. Several contextual conditions together point to ABAC, not RBAC.

ALEAnnualized Loss ExpectancyGRC

The expected yearly cost of one specific risk, calculated as single loss expectancy multiplied by the annualized rate of occurrence. It lets you compare what a control costs against the loss it prevents.

On the examExpect arithmetic: SLE x ARO = ALE. A $20,000 loss expected once every four years gives an ARO of 0.25 and an ALE of $5,000. Controls costing more rarely make sense.

Don’t confuse with SLE

AROAnnualized Rate of OccurrenceGRC

How many times per year a given threat is expected to happen. Once a year is 1.0, once every ten years is 0.1, and several times a year is a number above 1.

On the examThe trap is converting frequency into a decimal. 'Once every five years' is 0.2, not 5. Questions often hide the ARO inside the scenario and then ask you for the ALE.

BECBusiness Email CompromiseThreat

A fraud in which an attacker impersonates or takes over an executive, supplier or partner mailbox to trick staff into wiring money, changing bank details or sending sensitive data. Often no malware is involved at all.

On the examScenario: 'the CFO emailed an urgent request to pay a new vendor account'. That is BEC, and the best mitigations are out-of-band verification and payment approval procedures, not antivirus.

BIABusiness Impact AnalysisGRC

A process that identifies critical business functions, the systems they depend on and the impact of losing them over time. Its outputs include recovery objectives such as RTO and RPO and the order in which to restore systems.

On the examIf a question asks which activity sets recovery priorities or produces RTO and RPO values, the answer is the BIA, not the risk register and not the disaster recovery plan itself.

Chain of CustodyOps

A documented record of every person who collected, handled, transferred or stored a piece of evidence, with times and purpose. It shows the evidence was not tampered with and keeps it usable in legal proceedings.

On the examShows up in digital forensics questions. If evidence may go to court or is handed between teams, the missing step is documenting chain of custody, usually alongside hashing the forensic image.

CIA TriadConfidentiality, Integrity, AvailabilityCore

The three core goals of information security: confidentiality keeps data away from unauthorized people, integrity keeps it accurate and unaltered, and availability keeps systems and data usable when they are needed.

On the examMany questions ask which goal a control supports. Encryption maps to confidentiality, hashing to integrity, and redundancy, backups or load balancing to availability. Map the control to the goal first.

Compensating ControlCore

An alternative safeguard used when the primary or required control cannot be applied, giving comparable protection by other means. Example: isolating a legacy system that cannot be patched on its own network segment.

On the examCue phrases: 'cannot be patched', 'vendor no longer supports it', 'the requirement cannot be met'. The answer is a compensating control such as segmentation, not a corrective or deterrent control.

CVECommon Vulnerabilities and ExposuresOps

A public catalog that gives each disclosed vulnerability a unique identifier, such as CVE-2024-12345, so vendors, scanners and analysts all refer to the same flaw by the same name.

On the examCVE names the flaw; it does not rate it. When a question asks how a scan finding is matched to a known, publicly disclosed vulnerability, the answer is the CVE identifier.

CVSSCommon Vulnerability Scoring SystemOps

A standard method for rating vulnerability severity from 0.0 to 10.0 using factors such as attack vector, attack complexity, privileges required and impact. Teams use the score to decide what to fix first.

On the examQuestions about prioritizing which scan findings to remediate first point to CVSS, weighed with exposure and asset criticality. A base score of 9.0 or higher is rated Critical.

Don’t confuse with CVE

Data ControllerGRC

The organization that decides why and how personal data is collected and processed. It carries primary legal accountability for privacy compliance, even when another company handles the data on its behalf.

On the examScenario: a company hires a cloud payroll firm. The company is the controller and the payroll firm is the processor. Accountability for lawful use of the data stays with the controller.

Don’t confuse with Data Processor

Data MaskingArch

Hiding part or all of a data value by replacing characters with placeholders, such as showing only the last four digits of a card number. The masked view does not reveal the original value.

On the examCue: a help desk agent or developer needs to see the record but not the full sensitive value. Masking fits screens and test data; tokenization fits systems that must later use the real value.

Data ProcessorGRC

An organization that handles personal data on behalf of a data controller and only under the controller's instructions, such as a cloud provider, payroll service or email marketing platform.

On the examLook for 'on behalf of' or 'under contract'. The processor must follow the controller's instructions and does not decide the purpose of processing, so it is rarely the accountable party.

DLPData Loss PreventionOps

Tools and policies that find sensitive data, such as card numbers or health records, in motion, at rest or in use, and block, quarantine or alert when it is about to leave approved locations.

On the examScenario: an employee emails a spreadsheet of Social Security numbers to a personal account or copies it to USB. The control that stops this is DLP, not a firewall or an IPS.

DMARCDomain-based Message Authentication, Reporting, and ConformanceOps

An email policy published in DNS that tells receiving servers what to do with messages that fail SPF or DKIM checks, such as quarantine or reject, and where to send reports about spoofing attempts.

On the examWhen the goal is stopping spoofed email that uses your domain and getting reports about it, DMARC is the answer. It builds on SPF and DKIM rather than replacing either one.

EDREndpoint Detection and ResponseOps

Agent-based software on laptops, servers and workstations that records process, file and network activity, detects suspicious behavior and lets responders isolate the host or stop processes remotely.

On the examIf the scenario is about detecting fileless malware or odd behavior on a host and isolating that machine, choose EDR. Signature-based antivirus is the usual weaker distractor.

Don’t confuse with XDR

EncryptionCore

A reversible transformation of readable data into ciphertext using an algorithm and a key. Symmetric encryption uses one shared key; asymmetric encryption uses a mathematically linked public and private key pair.

On the examReversibility is the tell: if authorized parties must read the data again, it is encryption. Symmetric (AES) is fast for bulk data; asymmetric (RSA, ECC) solves key exchange and enables signatures.

Don’t confuse with Hashing

HashingCore

A one-way function that turns input of any size into a fixed-length digest. The same input always produces the same hash, and even a one-character change produces a completely different result.

On the examHashing proves integrity and protects stored passwords; it cannot be reversed, so it is not encryption. Watch for SHA-256 versus AES distractors and salting as the defense against rainbow tables.

Don’t confuse with Encryption

HSMHardware Security ModuleCore

A dedicated, tamper-resistant hardware appliance or card that generates, stores and uses cryptographic keys at scale, so that private keys never leave the device in readable form.

On the examEnterprise scale is the cue: a certificate authority, a payment system or many servers that need central key protection. Protecting a single laptop's boot and disk keys points to TPM instead.

Don’t confuse with TPM

IaCInfrastructure as CodeArch

Defining servers, networks and cloud resources in version-controlled configuration files or templates, so environments are deployed automatically and identically every time instead of being built by hand.

On the examCue: consistent, repeatable deployments and no configuration drift. The security upside is that templates can be reviewed and scanned before deployment; the downside is that one flawed template repeats everywhere.

IDSIntrusion Detection SystemOps

A sensor that monitors network or host activity for signatures or anomalies that indicate an attack and raises alerts. It watches a copy of the traffic and does not block anything by itself.

On the examPassive monitoring, 'alert only', or a SPAN port or network tap connection all mean IDS. If the question requires stopping malicious traffic in real time, IDS is the wrong answer.

Don’t confuse with IPS

IPSIntrusion Prevention SystemOps

A device placed inline in the traffic path that inspects packets for attack signatures or anomalies and drops, blocks or resets malicious connections as they happen.

On the examInline placement and 'automatically block' point to IPS. Know the trade-off: a false positive on an IPS blocks legitimate traffic, while a false positive on an IDS only creates noise.

Don’t confuse with IDS

MFAMultifactor AuthenticationOps

Authentication that requires two or more different factor types: something you know, something you have, something you are, and sometimes somewhere you are. Two passwords are still a single factor type.

On the examClassic trap: a password plus a security question is one factor type, so it is not MFA. A password plus an authenticator app or fingerprint is. MFA fatigue (push bombing) appears as a weakness.

Non-repudiationCore

Assurance that someone cannot credibly deny having sent a message or performed an action, because evidence, usually a digital signature made with their private key, ties the act to them.

On the examAsked which property a digital signature adds beyond integrity, the answer is non-repudiation. Symmetric encryption cannot provide it, because both parties hold the same shared key.

OAuthOpen AuthorizationOps

An authorization framework that lets an application get limited, token-based access to a user's resources on another service without ever receiving the user's password, such as an app reading your calendar.

On the examKeywords: delegated access, 'allow this app to', access token, without sharing credentials. OAuth handles authorization; OpenID Connect is layered on top when authentication is needed.

Don’t confuse with SAML

On-path AttackThreat

An attack where the adversary sits between two communicating parties to intercept, read or alter traffic, for example through ARP poisoning, a rogue access point or DNS manipulation. Formerly called man-in-the-middle.

On the examSY0-701 uses 'on-path' rather than man-in-the-middle. Cue: traffic silently relayed through an attacker device. TLS with proper certificate validation and 802.1X are typical mitigations.

Don’t confuse with Replay Attack

PKIPublic Key InfrastructureCore

The combination of certificate authorities, digital certificates, registration processes and revocation services that binds public keys to identities, so people and systems can trust encryption and signatures.

On the examKnow the parts: root and intermediate CAs, the CSR, key escrow, and CRL or OCSP for revocation. A common question asks which component confirms whether a certificate has been revoked.

Race ConditionThreat

A flaw where the outcome depends on the timing of events, letting an attacker act in the gap between a check and a use. Time-of-check to time-of-use (TOCTOU) is the classic example.

On the examCue: two processes touching the same resource at once, or a value that changes after it was validated. TOCTOU is the term to recognize; locking and atomic operations are the fix.

RBACRole-Based Access ControlOps

An access model where permissions are assigned to job roles, such as nurse or payroll clerk, and users gain access by being placed in a role. Moving a user to a new role changes their permissions.

On the examCue: access based on job function, or fast onboarding by department. If extra conditions such as location, time of day or device posture appear, the answer shifts to ABAC.

Don’t confuse with ABAC

Replay AttackThreat

Capturing valid authentication data or a legitimate transaction and sending it again later to gain access or repeat the action, without needing to decrypt or understand what was captured.

On the examLook for a captured session token or hash being reused. Timestamps, nonces, session expiration and one-time tokens defeat replays; encrypting the traffic alone does not.

Risk AppetiteGRC

The overall amount and type of risk an organization is willing to pursue or accept to reach its goals. SY0-701 describes appetite as expansionary, conservative or neutral.

On the examBroad, strategic wording such as 'leadership will accept moderate risk to grow quickly' signals risk appetite. Know the three categories named in the objectives: expansionary, conservative and neutral.

Don’t confuse with Risk Tolerance

Risk ToleranceGRC

The acceptable variation around a specific risk or objective, usually expressed as a measurable threshold, such as maximum hours of downtime or dollar loss, before action must be taken.

On the examNumbers and thresholds point to tolerance: 'no more than four hours of outage per quarter'. Appetite is the broad stance; tolerance is the measurable limit for one specific risk.

Don’t confuse with Risk Appetite

RPORecovery Point ObjectiveGRC

The maximum amount of data loss an organization can accept, measured as time back to the last usable copy. An RPO of one hour means backups or replication must happen at least hourly.

On the examData loss equals RPO. If the question is about backup frequency or how much data can be lost, choose RPO. It drives backup schedules, not how fast systems come back.

Don’t confuse with RTO

RTORecovery Time ObjectiveGRC

The maximum acceptable time to restore a system or process after a disruption before the business impact becomes unacceptable. It drives choices such as hot, warm or cold recovery sites.

On the examDowntime equals RTO. If a system must be running again within two hours, that is the RTO. Very short RTOs justify hot sites, clustering and other high-availability designs.

Don’t confuse with RPO

SAMLSecurity Assertion Markup LanguageOps

An XML-based standard that lets an identity provider pass signed authentication assertions to a service provider, enabling web single sign-on across organizations and cloud applications.

On the examKeywords: federation, identity provider, single sign-on into a SaaS application, XML assertion. SAML authenticates users for SSO; OAuth authorizes applications to access resources.

Don’t confuse with OAuth

SASESecure Access Service EdgeArch

A cloud-delivered model that combines networking with security services such as secure web gateway, CASB, firewall as a service and zero trust network access, applied close to users wherever they connect.

On the examCue: remote and branch users need the same security policy delivered from the cloud instead of backhauling traffic to headquarters. SD-WAN handles routing; SASE adds the security stack.

Don’t confuse with SD-WAN

SCADASupervisory Control and Data AcquisitionArch

Systems that monitor and control industrial processes across distributed sites, such as power grids, pipelines and water treatment. SCADA is a type of industrial control system (ICS) and is often hard to patch.

On the examCue: critical infrastructure or legacy controllers that cannot be patched or run agents. The expected answer is network segmentation or isolation, not frequent updates or endpoint software.

SD-WANSoftware-Defined Wide Area NetworkArch

A virtual WAN architecture that centrally manages and routes traffic across several connection types, such as MPLS, broadband and LTE, choosing the best path for each application.

On the examPure connectivity cue: cheaper links between branch offices with central management. SD-WAN on its own is not a security stack; if cloud-delivered security services are required, look for SASE.

SIEMSecurity Information and Event ManagementOps

A platform that collects logs from across the environment, normalizes and correlates the events, raises alerts, and supports dashboards, log retention and investigations.

On the examCue: aggregating and correlating logs from many sources to spot an attack or build one timeline of events. If the scenario needs automatic response actions, look at SOAR instead.

Don’t confuse with SOAR

SLESingle Loss ExpectancyGRC

The expected monetary loss from one occurrence of a risk, calculated as asset value multiplied by exposure factor, which is the percentage of the asset's value lost in that event.

On the examFormula: SLE = AV x EF. A $100,000 server with a 40% exposure factor gives an SLE of $40,000. Multiply the SLE by the ARO to get the ALE.

SmishingSMS phishingThreat

Phishing delivered by SMS or another text messaging channel, usually a short urgent message with a link or callback number, such as a fake parcel delivery notice or bank alert.

On the examThe channel decides the name: text message is smishing, voice call is vishing, email is phishing. Questions describe the channel and expect you to pick the matching term.

Don’t confuse with Vishing

SOARSecurity Orchestration, Automation, and ResponseOps

A platform that connects security tools and runs automated playbooks, such as enriching an alert, disabling an account or isolating a host, to make incident response faster and more consistent.

On the examCue words: playbook, runbook, automate repetitive tasks, reduce analyst workload or response time. SIEM detects and correlates; SOAR orchestrates and takes action.

Don’t confuse with SIEM

SPFSender Policy FrameworkOps

A DNS TXT record that lists which mail servers are allowed to send email for a domain, so receiving servers can reject or flag messages that come from unauthorized sources.

On the examCue: verifying which servers may send mail for the domain. SPF checks the sending server, DKIM checks the message signature, and DMARC sets the policy and reporting.

Don’t confuse with DMARC

SQLiSQL InjectionThreat

An attack that inserts crafted SQL statements into an input field or URL parameter so the application's database runs them, exposing, changing or deleting data it should protect.

On the examLook for payloads like ' OR 1=1 -- in logs. The fixes are parameterized queries and input validation. If the payload is a script tag instead, the answer is XSS.

Don’t confuse with XSS

Supply Chain AttackThreat

Compromising an organization through a trusted third party, such as a software vendor's update, a managed service provider or a hardware component, instead of attacking the target directly.

On the examCue: malware arrived in a legitimate, signed vendor update or through an MSP's remote access. Mitigations include vendor assessments, a software bill of materials and monitoring third-party access.

Tabletop ExerciseOps

A discussion-based session where team members talk through a simulated incident scenario step by step to test plans, roles and communication, without touching production systems.

On the examCue: low cost, talk-through, no systems affected. Contrast it with a simulation or a failover test, which exercises real or mock systems and costs more time and money.

TokenizationArch

Replacing sensitive data, such as a card number, with a random token that has no mathematical relationship to the original. The real value is stored separately in a secured token vault.

On the examCue: payment processing or shrinking PCI DSS scope, where an authorized system must still retrieve the real value. Tokens are looked up in the vault, never decrypted.

Don’t confuse with Data Masking

TPMTrusted Platform ModuleCore

A chip on a computer's motherboard that securely stores keys, measures the boot process and supports features such as full disk encryption and device attestation for that one machine.

On the examCue: a single laptop or server needs boot integrity measurements or disk encryption keys bound to its hardware, as with BitLocker. Central key management for many systems points to HSM.

VishingVoice phishingThreat

Phishing carried out by phone call or voicemail, sometimes with spoofed caller ID or an AI-cloned voice, to pressure the victim into revealing credentials or taking an action.

On the examA caller posing as IT support who asks for a password reset code is vishing. Expect it combined with pretexting, where the caller has a believable backstory ready.

WAFWeb Application FirewallArch

A firewall that inspects HTTP and HTTPS traffic to and from a web application at layer 7 and blocks attacks such as SQL injection and cross-site scripting based on rules.

On the examWhen the protected asset is a web application and the attacks are SQLi or XSS, pick the WAF over a network firewall or a general-purpose IPS.

Don’t confuse with IPS

Watering Hole AttackThreat

Compromising a website that a targeted group is known to visit, such as an industry forum or supplier portal, so that members of that group are infected when they browse it.

On the examCue: the attacker reaches a specific group indirectly through a site they already trust. If victims land on a look-alike domain after a typo instead, the answer is typosquatting.

XDRExtended Detection and ResponseOps

A detection and response platform that correlates telemetry from endpoints, network, email, identity and cloud into unified incidents, extending the EDR idea beyond individual hosts.

On the examCue: correlating detections across several security layers rather than endpoints alone. If the scope is one host and its processes, plain EDR is the better fit.

XSSCross-Site ScriptingThreat

An attack that injects malicious script into a trusted web page so it runs in other users' browsers, where it can steal session cookies or perform actions as the victim.

On the examA <script> payload in a comment field or URL points to XSS. The victim is the browser user, not the database. Fixes are input validation, output encoding and a WAF.

Zero TrustCore

A security model that grants no implicit trust based on network location. Every access request is authenticated, authorized and continuously evaluated using identity, device posture and context.

On the examKnow the planes: the control plane (policy engine, policy administrator) decides and the data plane (policy enforcement point) enforces. Cue: 'never trust, always verify' and removing implicit trust zones.

Zero-dayThreat

A vulnerability that the vendor does not yet know about or has not yet patched, so defenders have had zero days to fix it. Exploits for it slip past signature-based detection.

On the examCue: no patch and no signature exists yet. The best answers are behavior-based detection, EDR, segmentation and least privilege, not 'apply the latest patch'.

Terms the exam loves to confuse

These six pairs account for a large share of wrong answers on SY0-701, because the two terms sit side by side in the objectives and often appear together as answer choices.

IDSA passive sensor that watches a copy of network or host traffic and raises an alert when it sees attack signatures or anomalies.

IPSAn inline device in the traffic path that inspects packets and actively drops or blocks malicious connections as they happen.

The tellAsk whether the traffic must be stopped. Alert only, or a SPAN or tap connection, means IDS; inline and automatic blocking means IPS.

SIEMCollects, normalizes and correlates logs from many sources to detect attacks, raise alerts and support investigation and retention.

SOARRuns automated playbooks across connected security tools to enrich alerts and take response actions such as disabling accounts or isolating hosts.

The tellCorrelating and alerting is SIEM. Words like playbook, automate, orchestrate or cut analyst response time point to SOAR.

RTOThe maximum acceptable downtime: how quickly a system or process must be restored after a disruption.

RPOThe maximum acceptable data loss: how far back in time the last usable backup or replica can be.

The tellTime until the system is running again is RTO. Amount of data you can afford to lose, or backup frequency, is RPO.

Risk AppetiteThe broad, strategic amount of risk leadership is willing to take on, described as expansionary, conservative or neutral.

Risk ToleranceThe specific, measurable threshold of acceptable variation for a particular risk, such as maximum downtime or financial loss.

The tellA general stance set by leadership is appetite. A concrete number or limit attached to one risk is tolerance.

SAMLAn XML standard where an identity provider sends signed assertions to a service provider so users can sign in once across web applications.

OAuthA framework that issues access tokens so an application can reach a user's resources on another service without seeing the password.

The tellUsers signing in through a federated identity provider is SAML. An app being granted permission to act on your data is OAuth.

HashingA one-way function producing a fixed-length digest; it cannot be reversed and is used to verify integrity and store passwords.

EncryptionA reversible transformation using a key, so authorized parties can decrypt the ciphertext back into the original readable data.

The tellIf anyone ever needs the original data back, it is encryption. If you only need to verify it has not changed, it is hashing.

Acronym quick-scan

CompTIA prints a full acronym list, several hundred entries long, at the end of the SY0-701 exam objectives. The 84 below are the ones most tightly tied to objective bullet points, so scan these first.

  • AAAAuthentication, Authorization, and Accounting
  • AESAdvanced Encryption Standard
  • ALEAnnualized Loss Expectancy
  • APTAdvanced Persistent Threat
  • AROAnnualized Rate of Occurrence
  • AVAsset Value
  • BECBusiness Email Compromise
  • BIABusiness Impact Analysis
  • BPABusiness Partners Agreement
  • CACertificate Authority
  • CASBCloud Access Security Broker
  • CRLCertificate Revocation List
  • CSRCertificate Signing Request
  • CVECommon Vulnerabilities and Exposures
  • CVSSCommon Vulnerability Scoring System
  • DDoSDistributed Denial of Service
  • DKIMDomainKeys Identified Mail
  • DLPData Loss Prevention
  • DMARCDomain-based Message Authentication, Reporting, and Conformance
  • DNSSECDomain Name System Security Extensions
  • ECCElliptic Curve Cryptography
  • EDREndpoint Detection and Response
  • EFExposure Factor
  • FDEFull Disk Encryption
  • FIMFile Integrity Monitoring
  • GDPRGeneral Data Protection Regulation
  • HIDSHost-based Intrusion Detection System
  • HSMHardware Security Module
  • IaaSInfrastructure as a Service
  • IaCInfrastructure as Code
  • ICSIndustrial Control System
  • IDSIntrusion Detection System
  • IoCIndicator of Compromise
  • IoTInternet of Things
  • IPSIntrusion Prevention System
  • IPSecInternet Protocol Security
  • LDAPLightweight Directory Access Protocol
  • MDMMobile Device Management
  • MFAMultifactor Authentication
  • MOAMemorandum of Agreement
  • MOUMemorandum of Understanding
  • MSAMaster Service Agreement
  • MSPManaged Service Provider
  • MTBFMean Time Between Failures
  • MTTRMean Time to Repair
  • NACNetwork Access Control
  • NDANon-disclosure Agreement
  • NGFWNext-generation Firewall
  • OCSPOnline Certificate Status Protocol
  • OSINTOpen-source Intelligence
  • PAMPrivileged Access Management
  • PBKDF2Password-based Key Derivation Function 2
  • PCI DSSPayment Card Industry Data Security Standard
  • PKIPublic Key Infrastructure
  • RADIUSRemote Authentication Dial-in User Service
  • RBACRole-based Access Control
  • RPORecovery Point Objective
  • RTORecovery Time Objective
  • RTOSReal-time Operating System
  • SaaSSoftware as a Service
  • SAMLSecurity Assertion Markup Language
  • SASESecure Access Service Edge
  • SBOMSoftware Bill of Materials
  • SCADASupervisory Control and Data Acquisition
  • SCAPSecurity Content Automation Protocol
  • SD-WANSoftware-defined Wide Area Network
  • SDNSoftware-defined Networking
  • SIEMSecurity Information and Event Management
  • SLAService-level Agreement
  • SLESingle Loss Expectancy
  • SOARSecurity Orchestration, Automation, and Response
  • SOWStatement of Work
  • SPFSender Policy Framework
  • SQLiSQL Injection
  • SSOSingle Sign-on
  • TACACS+Terminal Access Controller Access-Control System Plus
  • TOTPTime-based One-time Password
  • TPMTrusted Platform Module
  • VPNVirtual Private Network
  • WAFWeb Application Firewall
  • WPA3Wi-Fi Protected Access 3
  • XDRExtended Detection and Response
  • XSSCross-site Scripting
  • ZTNAZero Trust Network Access

How to make the terms stick

Reading this list once will not stick; these three steps turn it into points on SY0-701.

  1. Study by domain weightSecurity Operations is 28% of the exam and Threats is 22%, so learn the SIEM, EDR, IAM, email security and attack terms first. General Security Concepts is only 12%, but its crypto vocabulary feeds questions in every other domain.
  2. Learn terms in rival pairsNever study IDS without IPS, RTO without RPO, or SAML without OAuth. For each pair, write the single cue word that separates them, then cover the definitions and test yourself on the cue alone until it is automatic.
  3. Rewrite scenarios, not flashcardsFor every term, write a two-sentence scenario the way CompTIA phrases it, then name the term without looking. Do the risk formulas (SLE, ARO, ALE) with real numbers until the decimal conversion is instant.

Knowing the word is not the same as answering the question

Knowing a definition is not the same as spotting it inside a scenario. Timed practice questions make you choose SIEM over SOAR or RPO over RTO under exam pressure, which is where points are won.

App StoreGoogle PlayFree practice testSecurity+ exam page

FAQ

How many acronyms are on the Security+ SY0-701 exam?

CompTIA publishes a full acronym list, several hundred entries long, at the end of the SY0-701 exam objectives document. Not every acronym appears on every exam form, and CompTIA does not publish how many are tested. Expect questions to use acronyms without expanding them, so you should recognize the core security tools, protocols, attacks and risk metrics on sight, starting with the 84 in the quick-scan above.

Do I need to memorize every Security+ acronym?

No. Memorizing expansions alone is low value, because questions test what a term does, not what its letters stand for. Focus on acronyms that name tools, protocols, attacks and risk metrics, and learn them in confused pairs such as IDS and IPS or RTO and RPO. Obscure hardware and legacy protocol acronyms rarely decide a question, so recognize them but do not drill them.

Is SY0-701 still the current Security+ exam in 2026?

Yes. As of September 2026, SY0-701 is the live Security+ exam. CompTIA says Security+ V8 (SY0-801) is expected on or around November 17, 2026, and the English SY0-701 exam is scheduled to retire on June 11, 2027. If you are already studying for SY0-701, you can finish and test on it; the certification is valid for three years whichever version you pass.

What Security+ terms are most often confused?

The classic confusions are IDS versus IPS, SIEM versus SOAR, RTO versus RPO, risk appetite versus risk tolerance, SAML versus OAuth, and hashing versus encryption. Others that cost points are tokenization versus data masking, RBAC versus ABAC, EDR versus XDR and SPF versus DMARC. In each case one scenario keyword decides the answer, so learn that keyword rather than the full definition.

Sources

Scope and domain names on this page come from CompTIA’s published exam objectives; definitions are ours, written for exam prep:

Checked September 30, 2026. Exam objectives are revised on the vendor’s schedule — if a term here is not in the current objectives, the objectives win.