Cybersecurity
Break into security — CompTIA Security+ (SY0-701) domain-weighted decks, an acronym drill, and a full-length practice exam.
Flashcard decks
8 decks · 508 cards · in study orderSecurity+ domains
6 decks · 193 cards2Security+ SY0-701 · D1 — General Security Concepts (12%)Domain 1: security control categories & types, the CIA triad and fundamental concepts, AAA, zero trust, physical security, change management, and cryptographic solutions (PKI, encryption, hashing, certificates).253Security+ SY0-701 · D2 — Threats, Vulnerabilities & Mitigations (22%)Domain 2: threat actors & motivations, threat vectors & attack surfaces, vulnerability types, indicators of malicious activity (malware & attacks), and mitigation techniques.204Security+ SY0-701 · D3 — Security Architecture (18%)Domain 3: security implications of architecture models (cloud, IaC, serverless, IoT, SCADA/ICS), securing enterprise infrastructure, data protection, and resilience & recovery.205Security+ SY0-701 · D4 — Security Operations (28%)Domain 4 (the largest): securing computing resources, asset management, vulnerability management, alerting & monitoring, enhancing security capabilities, identity & access management (IAM), automation, incident response, and investigation data sources.266Security+ SY0-701 · D5 — Program Management & Oversight (20%)Domain 5: security governance, the risk management process, third-party/vendor risk, compliance, audits & assessments (incl. penetration testing), and security awareness.197Security+ SY0-701 · Acronyms (high-yield)The SY0-701 exam is acronym-heavy — the official objectives PDF ships a ~280-300 acronym list to master. This deck drills a curated high-yield selection; the full list is in the CompTIA objectives PDF (see resources).83
Legacy cert decks — being merged
1 deck · 78 cardsPractice exams
9 setsSecurity+ PracticeDraws 45 questions per attempt from a domain-weighted pool, pass at 83% (mirrors the real 750-on-100..900 scale). Scenario + recall MCQs across all 5 domains, with a missed-question review, explanations, and a per-domain weak-area breakdown. Progress saves in your browser — no login. Note: the real exam also has ~3-6 performance-based questions (PBQs), simulated here as scenario MCQs.Practice Exam AA FULL-LENGTH 90-question exam in 90 minutes, weighted exactly to the official SY0-701 blueprint (D1 11 · D2 20 · D3 16 · D4 25 · D5 18). Pass mark 83%, mirroring the real 750-on-a-100..900 scale. Every question carries an objective-level topic tag (e.g. "4.6 IAM"), so the weak-area breakdown points at one of the 28 numbered objectives rather than a whole domain. Sit it once, cold and timed, and treat the result as a diagnostic — not a score. Exams B and C are separate question sets so improvement across attempts is real rather than recognition.Practice Exam BA FULL-LENGTH 90-question exam in 90 minutes, weighted to the official SY0-701 blueprint (D1 11 · D2 20 · D3 16 · D4 25 · D5 18). Pass mark 83%, mirroring the real 750-on-a-100..900 scale. A completely DISTINCT question set from Exam A — no shared questions — so a score improvement from A to B is real learning rather than remembering. Leans slightly more scenario-driven. Objective-level topic tags drive the weak-area breakdown.Practice Exam CA FULL-LENGTH 90-question exam in 90 minutes, weighted to the official SY0-701 blueprint (D1 11 · D2 20 · D3 16 · D4 25 · D5 18). Pass mark 83%. The HARDEST of the three and a completely distinct question set from A and B — it deliberately over-weights the BEST/FIRST/MOST-likely discrimination questions and the near-miss pairs the real exam loves (RTO vs RPO, CVE vs CVSS, spraying vs stuffing, DAC vs MAC vs RBAC vs ABAC). Sit this last as your final readiness check: pass C at 83% and you are genuinely ready.Practice Exam DA FULL-LENGTH 90-question exam in 90 minutes, weighted to the official SY0-701 blueprint (D1 11 · D2 20 · D3 16 · D4 25 · D5 18). Pass mark 83%. A completely distinct question set from A, B and C. D is the APPLIED set: most items put you in front of a situation — a log line, a configuration, a design decision — and ask what you are looking at or what you do next. It also deliberately covers the corners the earlier sets touch only once, including OAuth versus OpenID Connect, DMARC alignment, SLE arithmetic, policy enforcement points, subprocessor risk and legal hold.PBQ DrillThe real exam OPENS with 3-6 performance-based questions, they are weighted more heavily than a single multiple-choice item, and they are where most people burn time and confidence. This drill works six PBQ scenarios — firewall ACLs, log analysis, IAM and least privilege, PKI and certificates, incident response sequencing, and network segmentation — each broken into decision steps with a worked explanation. Being straight with you: the engine is multiple-choice, so this is not the real drag-and-drop interface. What it reproduces is the part that actually decides the outcome — reading a dense scenario and reasoning to a defensible answer. On the day, flag the PBQs, do the multiple choice first, and come back to them with your remaining time.Practice Exam EA FULL-LENGTH 90-question exam in 90 minutes, weighted to the official SY0-701 blueprint (D1 11 · D2 20 · D3 16 · D4 25 · D5 18). Pass mark 83%. A completely distinct question set from A, B, C and D. E is the PRECISION set, built around the compare-and-contrast pairs that decide borderline passes — TACACS+ versus RADIUS, hashing versus encryption, end-of-life versus end-of-support, residency versus sovereignty, automation versus orchestration, event versus alert versus incident, design versus operating effectiveness — plus the protocol and port detail the earlier sets sample only lightly.Practice Exam FA FULL-LENGTH 90-question exam in 90 minutes, weighted to the official SY0-701 blueprint (D1 11 · D2 20 · D3 16 · D4 25 · D5 18). Pass mark 83%. A completely distinct question set from A-E, rebuilt to match CompTIA's actual house style: every item opens with a situation rather than a definition, nearly all ask BEST / MOST LIKELY / FIRST, distractors are deliberately defensible so several items turn on choosing the better of two reasonable actions, and eight items embed dense performance-based data such as log excerpts and rule tables inside the stem. Sit this after A-E — it is the closest of the six to exam day.PBQ Drill 2Thirty decision steps across SIX performance-based scenarios that do not appear in the first PBQ drill: vulnerability scan triage, email authentication with SPF/DKIM/DMARC, wireless deployment, insecure-protocol replacement, digital forensics order of volatility, and cloud security posture. Each item is self-contained because the runner shuffles the draw. The real exam opens with 3-6 PBQs and weights them well above a single multiple-choice item.