πŸ‡ΊπŸ‡Έ CompTIA Security+ Β· flashcards

CompTIA Security+ Security Operations Flashcards

68 question-and-answer cards covering Security Operations as it is examined in CompTIA Security+. 24 of them are printed below, taken from across the deck β€” no signup, no paywall on the preview.

68Cards in deck
24Free preview
28Syllabus topics
~213Chars per answer
FreePrice

24 sample cards from the Security Operations deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What are the four stages of the identity/account provisioning lifecycle?

    Provisioning (create the account/identity), Permission assignment (grant appropriate access), Periodic review/attestation (verify access is still appropriate), and De-provisioning (disable/remove access when no longer needed).

  2. Compare DAC, MAC, RBAC, and ABAC access control models.

    DAC: owner sets permissions (discretionary). MAC: system enforces access via labels/clearances (mandatory, non-overridable). RBAC: access based on job role. ABAC: access based on attributes/policies (user, resource, environment conditions).

  3. What is the principle of least privilege and how does it differ from rule-based access control?

    Least privilege grants users only the minimum access needed for their job. Rule-based access control applies global if/then rules (e.g., time-of-day or ACL conditions) to all users regardless of role.

  4. What are the three authentication factor categories, and which are combined for true MFA?

    Something you know (password/PIN), something you have (token/phone), and something you are (biometric). True MFA requires factors from at least two different categories β€” two passwords is not MFA.

  5. What is the difference between TOTP and HOTP?

    HOTP (HMAC-based One-Time Password) generates a code from a counter that increments per use. TOTP (Time-based One-Time Password) generates a code from the current time, so it expires after a short window (e.g., 30 seconds).

  6. What are key password policy concepts: length, complexity, reuse, expiration, and age?

    Length = minimum characters (most impactful). Complexity = mix of character types. Reuse = prevents using previous passwords. Expiration = forces periodic change. Age = minimum time before a password can be changed again.

  7. What is password spraying, and how does account lockout defend against it?

    Password spraying tries a few common passwords across many accounts to avoid lockouts. Account lockout (after N failed attempts) limits guesses per account, mitigating brute-force and spraying attacks.

  8. What is a password manager and what is passwordless authentication?

    A password manager is a vault that securely stores and generates strong, unique passwords. Passwordless authentication removes passwords entirely, using factors like biometrics, hardware security keys (FIDO2/WebAuthn), or magic links.

  9. What is PAM (Privileged Access Management) and what is just-in-time permission?

    PAM secures, controls, and monitors accounts with elevated privileges. Just-in-time (JIT) permission grants elevated access only for a limited time when needed, then revokes it, minimizing standing privilege.

  10. What is a password vault and ephemeral credential in PAM?

    A password vault securely stores and rotates privileged account credentials, brokering access without revealing the password. Ephemeral credentials are temporary, single-use credentials issued for one session that expire automatically.

  11. What are the main benefits of automation and orchestration in security operations?

    Efficiency/time savings, enforcing baselines, standard infrastructure configurations, scaling securely, employee retention, reaction time, and acting as a workforce multiplier β€” all with consistent, repeatable execution.

  12. What is the difference between automation and orchestration?

    Automation makes a single task run without manual effort. Orchestration coordinates multiple automated tasks and tools into a unified end-to-end workflow (e.g., a SOAR playbook executing many steps across systems).

  13. What is SOAR and how does it relate to a playbook?

    SOAR (Security Orchestration, Automation, and Response) integrates tools to automate incident response. A playbook is the defined, ordered set of automated/manual steps SOAR executes to handle a specific type of incident.

  14. What are the considerations/risks when using automation and orchestration?

    Complexity, cost, single point of failure, technical debt, and ongoing supportability. Poorly designed automation can propagate errors quickly across many systems.

  15. List the phases of the incident response process (NIST/CompTIA model).

    Preparation, Detection, Analysis, Containment, Eradication, Recovery, and Lessons Learned (post-incident activity).

  16. What is the difference between containment, eradication, and recovery?

    Containment limits the spread/damage of an incident (isolate affected systems). Eradication removes the threat (malware, accounts, vulnerabilities). Recovery restores systems to normal operation and validates they are clean.

  17. What is the difference between a tabletop exercise and a simulation in incident response?

    A tabletop exercise is a discussion-based walkthrough of a scenario by the response team (low cost, no live systems). A simulation actively executes a scenario (e.g., a simulated phishing attack) to test real responses and tooling.

  18. What are root cause analysis and threat hunting in incident response activities?

    Root cause analysis identifies the underlying reason an incident occurred to prevent recurrence. Threat hunting is proactively searching networks/systems for hidden threats that evaded existing detection controls.

  19. What is the order of volatility in digital forensics?

    Collect evidence from most to least volatile: CPU registers/cache β†’ RAM (memory) β†’ network/routing/ARP cache β†’ temporary files/swap β†’ disk/storage β†’ remote logging/archived media. Most volatile data must be captured first.

  20. What is chain of custody and why is it critical in forensics?

    Chain of custody is the documented, unbroken record of who collected, handled, transferred, and stored evidence, with times and reasons. It ensures evidence integrity and admissibility in legal proceedings.

  21. What is legal hold and e-discovery in digital forensics?

    Legal hold (preservation) is the requirement to retain potentially relevant data once litigation is anticipated. E-discovery is the process of identifying, collecting, and producing electronically stored information for legal proceedings.

  22. Why is data acquisition order and hashing important when imaging evidence?

    Forensic imaging captures a bit-for-bit copy of media, and a cryptographic hash (e.g., SHA-256) of the original and the image proves the copy is identical and unaltered, preserving evidence integrity.

  23. What investigation data sources are used during an incident, and what does each provide?

    Dashboards (summarized view), automated reports, vulnerability scans, packet captures, firewall/IDS/IPS logs, application/OS/endpoint/network logs, metadata, and vulnerability scan output β€” each provides evidence of activity for analysis.

  24. What is the difference between a firewall log and an IPS/IDS log as data sources?

    A firewall log records allowed/denied connections based on rules (who connected where). An IDS/IPS log records detected/blocked attack signatures or anomalies (what malicious activity was attempted), giving threat context.

What this deck covers

The Security Operations deck follows the CompTIA Security+ Security Operations syllabus β€” 6 chapters and 28 topics β€” so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 11.3 cards per chapter.

Answers are written to be recallable, not just readable β€” averaging about 213 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Security Operations flashcards FAQ

How many Security Operations flashcards are in this CompTIA Security+ deck?

68 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these CompTIA Security+ flashcards free?

Yes. The preview here is free to read with no signup, and the full 68-card deck is free inside the Examius app.

What do the Security Operations cards cover?

They follow the CompTIA Security+ Security Operations syllabus β€” 6 chapters and 28 topics β€” so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.