🇬🇧 CompTIA A+ / Network+ / Security+ · flashcards

CompTIA A+ / Network+ / Security+ CompTIA Security+: Architecture, Operations & Governance (SY0-701) Flashcards

75 question-and-answer cards covering CompTIA Security+: Architecture, Operations & Governance (SY0-701) as it is examined in CompTIA A+ / Network+ / Security+. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

75Cards in deck
24Free preview
15Syllabus topics
~207Chars per answer
FreePrice

24 sample cards from the CompTIA Security+: Architecture, Operations & Governance (SY0-701) deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is Infrastructure as Code (IaC) and one security benefit?

    Defining and provisioning infrastructure through machine-readable configuration files rather than manual setup. Security benefit: consistent, repeatable, version-controlled, hardened deployments that reduce configuration drift and human error.

  2. Differentiate a policy, standard, procedure, and guideline in governance.

    Policy: high-level statement of intent/rules. Standard: mandatory specific requirements supporting a policy. Procedure: step-by-step instructions to achieve a task. Guideline: recommended, non-mandatory best-practice advice.

  3. What is the difference between governance and management in security?

    Governance sets direction, defines policy, assigns accountability and oversees risk to align security with business objectives. Management executes and operates within that framework day-to-day.

  4. What is an Acceptable Use Policy (AUP)?

    A policy defining the permitted and prohibited uses of an organisation's IT systems and data by users, setting expectations and the consequences of misuse.

  5. Name common governance committee/structure types and a regulatory consideration.

    Boards, committees, and government entities (centralised vs decentralised structures). They provide oversight, set policy, and must consider applicable laws/regulations (e.g. UK GDPR, sector regulators) when establishing security direction.

  6. What are the four main risk response strategies?

    Accept (tolerate the risk), Avoid (stop the risky activity), Transfer/Share (e.g. insurance, outsourcing), and Mitigate/Reduce (apply controls to lower the risk).

  7. Give the formula for Single Loss Expectancy (SLE).

    $$\text{SLE} = \text{Asset Value (AV)} \times \text{Exposure Factor (EF)}$$ where EF is the percentage of asset value lost in a single incident.

  8. Give the formula for Annualized Loss Expectancy (ALE).

    $$\text{ALE} = \text{SLE} \times \text{ARO}$$ where ARO is the Annualized Rate of Occurrence (expected number of incidents per year).

  9. Differentiate quantitative and qualitative risk assessment.

    Quantitative assigns numeric/monetary values (e.g. SLE, ALE) for objective cost-benefit analysis. Qualitative uses subjective ratings (e.g. high/medium/low) based on judgement when precise figures aren't available.

  10. What is the difference between inherent risk, residual risk, and risk appetite?

    Inherent risk is the risk before any controls. Residual risk is the risk remaining after controls are applied. Risk appetite is the amount/type of risk an organisation is willing to accept in pursuit of its objectives.

  11. What is a Business Impact Analysis (BIA) and what key metrics does it produce?

    A process that identifies critical functions and the impact of their disruption. It produces metrics such as RTO, RPO, MTD (Maximum Tolerable Downtime), and the resources needed to recover.

  12. What is the purpose of a risk register?

    A central document that records identified risks, their likelihood and impact, owners, current controls, risk responses and status — used to track and manage risk over time.

  13. In third-party/vendor risk, distinguish an SLA, MOU/MOA, BPA, and MSA.

    SLA: service-level agreement defining performance/uptime guarantees. MOU/MOA: memorandum of understanding/agreement, an informal/formal statement of intent. BPA: business partners agreement governing a partnership. MSA: master service agreement setting overarching contract terms.

  14. What is the purpose of due diligence and due care in third-party risk management?

    Due diligence is the investigation/assessment of a vendor's security and viability before engagement. Due care is the ongoing reasonable effort and monitoring to ensure the vendor maintains required security throughout the relationship.

  15. What is a supply chain attack and how is it mitigated in vendor risk?

    An attack that compromises an organisation by targeting a trusted third-party supplier, vendor or software component. Mitigations include vendor assessments, audits, monitoring, contractual security requirements and validating software integrity.

  16. What is the difference between an RFP, RFQ, and RFI in vendor selection?

    RFI (Request for Information): gather general info about capabilities. RFP (Request for Proposal): solicit detailed proposed solutions. RFQ (Request for Quotation): obtain specific pricing for defined requirements.

  17. What is the difference between a right-to-audit clause and vendor attestation?

    A right-to-audit clause contractually permits the organisation to directly inspect/audit the vendor's controls. Vendor attestation is a self-reported or independently certified assurance (e.g. a SOC 2 report) provided by the vendor instead of a direct audit.

  18. What is UK GDPR and what does it govern?

    The UK's retained version of the EU General Data Protection Regulation, governing the processing of personal data of individuals in the UK — covering lawful basis, data subject rights, breach notification, and accountability.

  19. Which UK body regulates data protection, and what is the GDPR breach notification deadline?

    The Information Commissioner's Office (ICO). Notifiable personal-data breaches must be reported to the ICO without undue delay and within 72 hours of becoming aware where feasible.

  20. What is the UK Data Protection Act 2018 and how does it relate to UK GDPR?

    The DPA 2018 is the UK law that sits alongside and supplements UK GDPR, implementing and tailoring data-protection rules (including law-enforcement and intelligence processing) within UK law.

  21. What is the difference between a regulation, a standard, and a framework in compliance?

    A regulation is legally mandated (e.g. UK GDPR). A standard is a defined requirement set, sometimes contractually required (e.g. PCI DSS, ISO 27001). A framework is a structured guidance model for organising security practices (e.g. NIST CSF).

  22. What are common consequences of non-compliance?

    Fines/sanctions, loss of business or licence, reputational damage, contractual penalties, increased scrutiny/audits, and potential legal liability for the organisation and its officers.

  23. Differentiate a SOC 2 Type I and Type II report.

    SOC 2 Type I assesses whether controls are suitably designed at a single point in time. Type II assesses both the design and the operating effectiveness of those controls over a period (typically 3-12 months).

  24. What is PCI DSS and to whom does it apply?

    The Payment Card Industry Data Security Standard — a contractual standard that applies to any organisation that stores, processes or transmits cardholder/payment card data, mandating controls to protect that data.

What this deck covers

The CompTIA Security+: Architecture, Operations & Governance (SY0-701) deck follows the CompTIA A+ / Network+ / Security+ CompTIA Security+: Architecture, Operations & Governance (SY0-701) syllabus — 4 chapters and 15 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 18.8 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 207 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

CompTIA Security+: Architecture, Operations & Governance (SY0-701) flashcards FAQ

How many CompTIA Security+: Architecture, Operations & Governance (SY0-701) flashcards are in this CompTIA A+ / Network+ / Security+ deck?

75 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CompTIA A+ / Network+ / Security+ flashcards free?

Yes. The preview here is free to read with no signup, and the full 75-card deck is free inside the Examius app.

What do the CompTIA Security+: Architecture, Operations & Governance (SY0-701) cards cover?

They follow the CompTIA A+ / Network+ / Security+ CompTIA Security+: Architecture, Operations & Governance (SY0-701) syllabus — 4 chapters and 15 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.