← CertOwl Blog

Security+

Security+ acronyms: what to learn and what to skip

By SunTzu, founder of CertOwl Published 4 min read

Quick answer

CompTIA publishes an acronym appendix in the SY0-701 exam objectives with over 300 entries, and its own wording asks for a working knowledge of them rather than recall of the expansions. The same document warns that its example lists are not exhaustive, so the appendix is a floor and not a boundary. The efficient approach is to learn what each acronym does and when you would choose it, grouped by domain, rather than reciting letters.

Source acronym appendix in the SY0-701 exam objectivesSize over 300 entriesCompTIA wording working knowledge, lists not exhaustiveWhat the exam tests use in context, not expansionBest method grouped drilling with spaced repetition

Halfway through the exam a question arrives with three acronyms in a single line. You know two of them cold. The third you have definitely seen, probably on a flashcard, and now it sits there while the clock runs. That moment is what sends people searching for the acronym list in the first place, and it is also the reason a list on its own rarely fixes the problem.

What CompTIA actually publishes

The SY0-701 exam objectives document ends with an appendix of acronyms, and it is long. Counts circulating online vary between roughly 320 and 330 depending on who did the counting, so treat any exact figure with mild suspicion, but it comfortably clears 300 entries.

Two lines in that document matter more than the list itself. CompTIA asks candidates to attain a working knowledge of the listed acronyms, which is a different instruction from memorise these expansions. And the objectives state plainly that the example lists are not exhaustive, and that other technologies or processes may appear on the exam without being named in the document.

So the appendix is a floor rather than a fence. Learning every entry does not guarantee you meet nothing unfamiliar, and reciting expansions does not equal the working knowledge being asked for.

Why the flashcard approach stalls

Most people start by drilling expansions: SAML equals Security Assertion Markup Language, done. Then a scenario question asks which authentication approach fits a federation between two organisations, and the expansion is no help at all. You needed to know what SAML is for.

Exam questions live at the level of use. Given a situation, what would you deploy, and why that rather than the near neighbour. Expansions are the label on the box, and the exam asks what is inside.

There is also a volume problem. Three hundred entries drilled as raw pairs is weeks of work with poor retention, and much of that effort lands on acronyms that appear rarely. Effort spread evenly across an uneven list is effort wasted.

Where the marks actually sit

Group them by domain and the picture sharpens. The clusters that repay attention are the ones the exam leans on repeatedly.

Cryptography and certificates carry heavy weight: the differences between AES, RSA, ECC, TLS, PKI, CA, CSR, CRL and OCSP come up in scenarios constantly, because certificate handling is a daily task in the job the exam models. Identity and access is the next cluster: MFA, SSO, SAML, OAuth, LDAP, RBAC, ABAC, PAM. Network defence follows: IDS and IPS, WAF, DLP, NAC, VPN, DMZ, SIEM, SOAR.

Governance and risk fills out the rest and tends to be the group people underprepare: RTO, RPO, MTTR, MTBF, SLA, MOU, BIA, GDPR. These are the acronyms most likely to appear in the wordy questions where the answer hinges on knowing that one metric measures downtime tolerance and the other measures data loss tolerance.

If it helps to have the definitions somewhere searchable while you study, we keep a free glossary of security terms that covers these in plain language.

A method that holds

Work in groups of eight to ten related acronyms rather than alphabetically. Related terms reinforce each other, and alphabetical order puts unrelated things side by side for no reason.

For each one, answer three questions instead of one: what does it stand for, what does it do, and when would you pick it over the obvious alternative. That third question is where exam marks live, and it is the one flashcards skip.

Then space the repetition. Fifteen minutes daily beats a weekend marathon, and it fits alongside the wider study timeline we set out in how long to study for Security+.

Finally, meet them in questions rather than in isolation. An acronym you have only seen on a card is a stranger under time pressure; one you have met inside three scenarios is furniture. That difference is worth more than another hundred entries memorised, and it feeds directly into how the exam is actually scored, which we explained in the Security+ passing score.

Test yourself: 3 quick questions

How does HTTPS defend against an on-path (MITM) attack?

An on-path (MITM) attacker inserts themselves between two parties and intercepts/alters the traffic. HTTPS encrypts the traffic (even if intercepted, it cannot be read) and the certificate proves the server's identity (preventing a fake server). That is why universal HTTPS is so important.

What is a side-channel attack?

A side-channel attack does not attack the algorithm directly but measures indirect traces of its execution: how long an operation takes, power consumption, electromagnetic radiation, sound. From these leaks the key can be reconstructed. Defense: constant-time implementations, shielding.

Why is log aggregation (collecting logs in one place) important and what is its prerequisite?

Logs are scattered across hundreds of devices, and an attack leaves traces in multiple places - only once combined in one place (log aggregation) do they give a picture and enable correlation and search. The prerequisite is synchronized time (NTP): without accurately synchronized clocks the logs can't be ordered correctly, so the sequence of events is wrong.

Score: · Hundreds more with explanations, free in the app: Get CertOwl on the App Store

Frequently asked questions

Do I need to memorise the whole acronym list?

No. You need working knowledge of the common ones and recognition of the rest. Time spent on the heavily tested clusters returns far more than even coverage of all 300 plus.

Will acronyms outside the list appear on the exam?

CompTIA states its example lists are not exhaustive, so yes, that is possible. This is a reason to understand concepts rather than to memorise harder.

Is knowing the expansion ever enough?

Occasionally, for a straight definition question. Most questions describe a situation and ask what fits, and for those you need to know the function, not the letters.

CertOwl drills Security+ acronyms the way the exam uses them: grouped by domain, inside scenario questions with every option explained, and returning through spaced repetition until they stop slipping. The A+ and Network+ tracks are completely free.

Get CertOwl on the App Store

Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations

More CompTIA guides