Security+ Glossary: The 40 Terms You Must Know
A plain-English glossary of the 40 most tested Security+ SY0-701 terms - from ALE, APT and DLP to WAF and zero trust - grouped by domain.
Security+ glossary · 10 min read · updated 2026-09-05
Security+ is a vocabulary exam as much as a security exam. These forty terms cover the acronyms and concepts the SY0-701 leans on most heavily, in plain English.
Concepts and risk (Domains 1 and 5)
CIA triad - confidentiality, integrity, availability: the three goals every control ultimately serves. Zero trust - no implicit trust from network location; verify identity, device and context continuously. ALE, SLE and ARO - annualized loss expectancy = single loss expectancy x annual rate of occurrence, the exam's only real math. Due care vs due diligence - doing what a prudent organisation should versus demonstrating that it was done.
Policy - a mandatory high-level statement. Standard - the mandatory technical detail. Guideline - advisory. Baseline - the minimum acceptable configuration. Gap analysis - comparing your current state to a target framework and listing the deltas.
Threats and mitigations (Domain 2)
APT - advanced persistent threat, a well-resourced attacker that stays hidden long-term. Ransomware - data encryption plus extortion. Phishing, spear phishing and whaling - mass, targeted and executive-focused deceptive email. Tailgating - physical social engineering through a door. LOLBins - legitimate binaries like PowerShell or certutil abused by attackers.
EDR - endpoint detection and response, behavioural endpoint monitoring with response actions. DLP - data loss prevention, stopping sensitive data from leaving. MFA - multiple authentication factors (something you know, have, are). SIEM - centralised log correlation and alerting. SOAR - automated response playbooks across tools. WAF - web application firewall filtering HTTP attacks like SQLi and XSS.
Architecture and operations (Domains 3 and 4)
ZTNA - zero trust network access, per-application remote access replacing the trusted VPN. Microsegmentation - granular east-west traffic control. TPM - trusted platform module, a hardware root of trust for keys and boot integrity. HSM - dedicated hardware for cryptographic operations. Tokenization vs masking - replacing sensitive data with a token versus hiding part of it in display.
Order of volatility - the forensic sequence in which evidence disappears, RAM before disk, disk before archive. Chain of custody - the documented trail of evidence handling. RTO and RPO - how fast you must recover versus how much data you may lose. BIA - business impact analysis, the study that produces those numbers.
Frequently asked questions
- How many terms should I memorise for Security+?
- The official list runs to hundreds, but roughly 40-60 core terms appear again and again in scenarios. Learn each as a definition in your own words plus one example, rather than as an acronym expansion.
- Do I need to know port numbers and protocols for Security+?
- Yes - a compact set is tested: 22 SSH, 25 and 587 SMTP, 53 DNS, 80 and 443 HTTP(S), 110 and 143 mail retrieval, 389 and 636 LDAP(LDAPS), 445 SMB, 3389 RDP, plus ICMP. Know what each protocol does and which are secure versus legacy.
- Where can I drill Security+ vocabulary with explanations?
- The PassYour Security+ track includes 225 exam-style questions with explanations mapped to the five domains plus lesson flashcards, and the free online quiz covers the most common terms to get you started.
Keep reading for Security+
PassYour is an independent study aid and is not affiliated with, endorsed by or sponsored by ISC2, CompTIA or Microsoft.
