Show Menu
Cheatography

CompTIA Security+ (SY0-701) Acronyms & Key Terms Cheat Sheet (DRAFT) by

The must-know acronyms and key terms for CompTIA Security+ (SY0-701) — one-page rapid review.

This is a draft cheat sheet. It is a work in progress and is not finished yet.

Core Security Concepts

CIA triad
Confid­ent­iality, Integrity, Availa­bility: the three pillars of security
AAA
Authen­tic­ation, Author­iza­tion, Accoun­ting: who you are, what you can do, what is logged
Zero Trust
Never trust, always verify: verify every user and device explicitly
Least privilege
Users get only the minimum access needed for their job
Defense in depth
Layered controls so one failure does not breach everything

Threats & Attacks

APT
Advanced Persistent Threat: long-term targeted intrusion, often nation­-state
DDoS
Distri­buted Denial of Service: traffic flood from many sources
MITM
Man-in­-th­e-M­iddle: attacker intercepts traffic between two parties
SQLi
SQL Injection: malicious SQL via unsani­tized input
XSS
Cross-Site Scripting: malicious script injected into web pages
XSRF/CSRF
Cross-Site Request Forgery: forged requests using a victim's session
Phishing / Whaling / Vishing
Email / execut­ive­-ta­rgeted / voice-call social engine­ering
Ransomware
Malware that encrypts data and demands payment

Crypto­graphy & PKI

AES
Advanced Encryption Standard: symmetric cipher (128/1­92/­256­-bit)
RSA
Asymmetric cipher used for key exchange and digital signatures
PKI
Public Key Infras­tru­cture: CAs, certif­icates, trust chains
CA
Certif­icate Authority: issues and signs digital certif­icates
CRL / OCSP
Certif­icate Revocation List / online check for revoked certs
Hashing (SHA-256)
One-way integrity check; hashing is not encryption
Digital signature
Proves authen­ticity, integrity, and non-re­pud­iation
TLS
Encrypts data in transit (HTTPS); SSL is deprecated

Network Security

IDS / IPS
Intrusion Detection / Prevention System: detect vs detect­-an­d-block
HIDS / NIDS
Host-based vs networ­k-based IDS
SIEM
Security Inform­ation and Event Manage­ment: centra­lized log analysis
SOAR
Security Orches­tra­tion, Automation and Response
WAF
Web Applic­ation Firewall: filters HTTP attacks like SQLi and XSS
NAC
Network Access Control: enforces device compliance before joining
DMZ
Demili­tarized Zone: buffer network between public and private
VPN / IPsec
Encrypted tunnel; IPsec suite for secure IP commun­ica­tions
VLAN
Virtual LAN: segments broadcast domains logically
SPF / DKIM / DMARC
Email authen­tic­ation trio against spoofing

Identity & Access

MFA
Multi-­Factor Authen­tic­ation: two or more proof categories
SSO
Single Sign-On: one login for many apps
SAML / OAuth / OpenID
Federation and delegated author­ization standards
RADIUS / TACACS+
AAA protocols (TACACS+ encrypts the full payload)
RBAC / ABAC
Role-Based / Attrib­ute­-Based Access Control
Kerberos
Ticket­-based auth, port 88; default in Active Directory
LDAP
Directory access protocol, port 389 (LDAPS 636)

Operations & Governance

BIA
Business Impact Analysis: identifies critical processes and recovery priorities
RTO / RPO
Recovery Time Objective / Recovery Point Objective
SLA
Service Level Agreement: uptime and perfor­mance contract
Hardening
Disabling unnece­ssary services and ports to reduce attack surface
Patching
Applying fixes; one of the highes­t-ROI controls
Backups (3-2-1)
3 copies, 2 media types, 1 offsite
Incident response
Prepar­ation, Detection, Contai­nment, Eradic­ation, Recovery, Lessons learned

More from ByteBar

Exam-r­eady? Get the Security+ (SY0-701) Study Guide — $5 at byteba­rhq.com
Free IT study resources and practice questions at byteba­rhq.com