🇺🇸 CompTIA Security+ · flashcards
CompTIA Security+ Security Architecture Flashcards
60 question-and-answer cards covering Security Architecture as it is examined in CompTIA Security+. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.
24 sample cards from the Security Architecture deck
Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.
What is the difference between IPSec transport mode and tunnel mode?
Transport mode encrypts only the packet payload (host-to-host). Tunnel mode encrypts the entire original packet and adds a new header (gateway-to-gateway/site-to-site VPN).
What are the four common data classifications in business/government?
Common examples: Public, Private/Internal, Confidential, and Restricted/Critical (government often uses Unclassified, Confidential, Secret, Top Secret).
Distinguish data at rest, data in transit, and data in use.
At rest: stored data (disk/db). In transit: data moving across a network. In use: data being actively processed in memory/CPU. Each requires different protection (encryption, TLS, memory protection).
What is the difference between PII and PHI?
PII (Personally Identifiable Information) is data that can identify an individual (name, SSN). PHI (Protected Health Information) is health-related data tied to an individual, protected under HIPAA.
What is data sovereignty?
The principle that data is subject to the laws and regulations of the country in which it is physically stored or collected, affecting where data may legally reside and be processed.
What is tokenization as a method to secure data?
Replacing sensitive data with a non-sensitive surrogate (token) that has no exploitable value; the mapping is stored securely in a separate token vault, reducing exposure of real data.
Compare masking and encryption for protecting data.
Masking obscures data by replacing it with realistic but fake values (often irreversible, for display/testing). Encryption reversibly transforms data using a key so authorized parties can recover the original.
What is a Hardware Security Module (HSM)?
A dedicated, tamper-resistant hardware device that securely generates, stores, and manages cryptographic keys and performs crypto operations.
What is Data Loss Prevention (DLP)?
A set of tools and processes that detect and prevent unauthorized access, use, or exfiltration of sensitive data across endpoints, networks, and storage.
What does high availability (HA) aim to achieve, and how is it measured?
It ensures systems remain operational with minimal downtime, typically measured in 'nines' of uptime (e.g., 99.999% = 'five nines' ≈ 5 minutes of downtime per year).
Compare a hot site, warm site, and cold site.
Hot site: fully equipped and running, near-instant failover (highest cost). Warm site: partially equipped, needs some setup/data restore (moderate). Cold site: space/power only, longest recovery time (lowest cost).
What is geographic dispersion (geo-redundancy) in site planning?
Distributing systems/data across separate physical locations so a localized disaster (fire, flood, power loss) at one site doesn't take down operations.
What is platform diversity and what risk does it mitigate?
Using different vendors, operating systems, or technologies so a single vulnerability or exploit cannot compromise the entire environment, reducing systemic/monoculture risk.
What is a multi-cloud strategy and one benefit it provides?
Using services from multiple cloud providers; benefits include avoiding vendor lock-in, increasing resilience, and meeting diverse compliance or performance needs.
What is capacity planning, and what three areas does Security+ emphasize?
Ensuring sufficient resources to meet demand and recovery needs; key areas are People (staffing), Technology (compute/storage/bandwidth), and Infrastructure (facilities/power).
Compare RTO and RPO.
RTO (Recovery Time Objective) is the maximum acceptable time to restore a system after an outage. RPO (Recovery Point Objective) is the maximum acceptable amount of data loss measured in time (how far back the last good backup must be).
Compare a full, incremental, and differential backup.
Full: copies all data. Incremental: copies only data changed since the last backup (any type) — fast backup, slower restore. Differential: copies data changed since the last full backup — slower backup, faster restore.
What is the 3-2-1 backup rule?
Keep 3 copies of data, on 2 different types of media, with 1 copy stored offsite, to protect against device failure, site disaster, and ransomware.
Compare tabletop exercises and failover/parallel testing for continuity plans.
Tabletop exercises are discussion-based walkthroughs of the plan (low cost, no disruption). Failover/parallel testing actually activates backup systems to validate real recovery, providing stronger assurance but more risk/cost.
What is the role of a UPS in power resilience?
An Uninterruptible Power Supply provides immediate, short-term battery power during an outage to prevent abrupt shutdown and bridge the gap until generators start or power returns.
Compare a UPS and a generator for power resilience.
A UPS gives instant but short-duration battery power for graceful shutdown/bridging; a generator provides longer-term power for extended outages but takes time to start, so the two are used together.
What is a Power Distribution Unit (PDU) in a data center?
A device that distributes electrical power to racks/equipment, often with monitoring, surge protection, and the ability to manage redundant power feeds.
What is dual power supply / redundant power in HA design?
Equipping critical devices with two independent power supplies fed from separate sources/PDUs so the device keeps running if one supply or feed fails.
What is a containerized architecture and a key security consideration?
Packaging applications with their dependencies into isolated containers sharing a host OS kernel; key concerns include kernel-level isolation weaknesses, insecure images, and securing the orchestration layer (e.g., Kubernetes).
What this deck covers
The Security Architecture deck follows the CompTIA Security+ Security Architecture syllabus — 4 chapters and 21 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 15.0 cards per chapter.
Answers are written to be recallable, not just readable — averaging about 182 characters, which is long enough to carry the reasoning and short enough to say out loud.
A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.
Security Architecture flashcards FAQ
How many Security Architecture flashcards are in this CompTIA Security+ deck?
60 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.
Are these CompTIA Security+ flashcards free?
Yes. The preview here is free to read with no signup, and the full 60-card deck is free inside the Examius app.
What do the Security Architecture cards cover?
They follow the CompTIA Security+ Security Architecture syllabus — 4 chapters and 21 topics — so the questions track what is actually examinable.
How should I use these flashcards?
Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.