Security+ glossary
Plain-language definitions of key CompTIA Security+ (SY0-701) terms, organized by exam domain. New terms are added regularly.
Core concepts
Cryptography
Symmetric encryption
Asymmetric encryption
Hashing
Salt
Hash-based message authentication code (HMAC)
Digital signature
Diffie-Hellman key exchange
Digital certificate
Trusted platform module (TPM)
Hardware security module (HSM)
Secure enclave
Key escrow
Online certificate status protocol (OCSP)
Certificate pinning
Downgrade attack
Threat actors and vectors
Insider threat
Advanced persistent threat (APT)
Threat actor attributes
Threat actor motivation
Double extortion ransomware
Social engineering
Phishing
Watering hole attack
Watering hole
Typosquatting (registering similar domains)
Business email compromise (BEC)
Smishing (SMS phishing)
Pretexting (fabricated scenario)
Malware and malicious activity
Virus and worm
Trojan horse and Remote Access Trojan (RAT)
Rootkit
Ransomware
Logic bomb
Denial-of-Service and Distributed Denial-of-Service (DoS/DDoS)
On-path / MITM attack and evil twin
Indicator of compromise (IoC)
Pass-the-hash
Golden ticket
Command and control (C2)
Beaconing (periodic check-in)
Defense techniques
Architecture and infrastructure
Enterprise infrastructure
Demilitarized zone / screened subnet (DMZ)
Jump server / bastion host
Intrusion detection system / intrusion prevention system (IDS/IPS)
Firewall
Next-generation firewall (NGFW)
Web application firewall (WAF)
802.1X port-based network access control
Virtual private network / IPsec (VPN)
Secure access service edge (SASE)
EAP-TLS (EAP - Transport Layer Security)
WPA3-SAE (simultaneous authentication of equals)
Security objectives and controls
Enterprise security capabilities
Sender Policy Framework (SPF)
DomainKeys Identified Mail (DKIM)
Domain-based Message Authentication, Reporting and Conformance (DMARC)
Endpoint Detection and Response / Extended Detection and Response (EDR/XDR)
User and Entity Behavior Analytics (UEBA)
Network Access Control (NAC)
File Integrity Monitoring (FIM)
DNS Security Extensions (DNSSEC)
Cloud access security broker (CASB)
Data protection
Hardening and asset security
Risk management
Vulnerability management
Monitoring and alerting
Automation and incident response
Identity and access management (IAM)
Security governance
Compliance and third-party risk
Resilience and recovery
Audits, assessments and awareness
Get CertOwl on the App Store
Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations