Plain-language Security+ study guides: compare similar concepts, work through calculations and practise the decisions behind SY0-701 questions.
To work out ALE, SLE, ARO, RTO, RPO, MTTR, and MTBF questions, first separate money, recovery targets and observed times. SLE = asset value × exposure factor; ALE = SLE × ARO. RTO is the target recovery time, RPO the acceptable data-loss window, MTTR average repair or recovery time, and MTBF average operating time between failures.
Exam guideThe difference between authentication, authorization, and accounting is the question each answers: authentication checks who you are, authorization decides what you may do, and accounting records your activity. Remember AAA as identity, permission and record. A successful login doesn’t automatically grant access to every file or action.
Exam guideFirewalls, VPNs, proxies, WAFs, and network segmentation work together by controlling different parts of a connection: firewalls enforce traffic rules, VPNs protect a tunnel, proxies mediate requests, WAFs inspect web requests, and segmentation restricts movement between zones. Use them in layers, with each control matched to the traffic and risk it can handle.
Exam guideThe difference between hashing, encryption, and encoding is what each does to data: hashing creates a one-way digest for comparison, encryption protects data with a key, and encoding changes its format so another system can read it. Choose hashing to check integrity, encryption for confidentiality, and encoding for compatibility.
Exam guideTo remember the differences between IDS, IPS, SIEM, SOAR, and EDR, attach a job to each: IDS detects suspicious activity, IPS can block it, SIEM connects events from logs, SOAR runs response workflows, and EDR investigates and responds on endpoints. In a scenario, look for the action and the place it happens.
Exam guideFor Security+ performance-based questions, expect to apply security knowledge in a task rather than only choose a letter. Approach each PBQ by reading the goal, checking the constraints, examining the supplied evidence and making the smallest correct changes. Practise explaining your decisions, managing time and checking that every requested part is complete.
Exam guideCommon attacks differ by how they reach a victim or use credentials: phishing uses deceptive messages, smishing uses texts, and vishing uses voice calls. Password spraying tries a few passwords across many accounts; credential stuffing reuses stolen login pairs; brute-force guessing systematically tries candidates. Identify the delivery channel and the login pattern separately.
Exam guideFor Security+, memorise common service ports together with their purpose and transport: SSH 22, DNS 53, DHCP 67/68, HTTP 80, HTTPS 443, SMTP 25, SMB 445, LDAP 389 and RDP 3389 are a useful starting set. Then learn secure alternatives, monitoring and VPN ports. This is a study shortlist, not a guaranteed exam-only list.
Exam guideThe difference between vulnerability scanning, penetration testing, threat hunting, and risk assessment is their aim: scanning finds potential weaknesses, penetration testing tries authorised attacks to validate exposure, threat hunting looks for hidden malicious activity, and risk assessment weighs likelihood and business impact. Choose the activity that answers the organisation’s actual question.
Exam guideThe difference between symmetric and asymmetric encryption is the keys: symmetric encryption uses the same secret key to encrypt and decrypt, while asymmetric encryption uses a related public and private key pair. Use symmetric encryption for bulk data; use public-key methods for tasks such as secure key establishment, signatures and some encryption workflows.
Concept lessons, explained practice, a firewall exercise and a daily study route across the five SY0-701 domains.