Security+ Cram Sheet: Last-Minute Review
This sheet is for the final two days before your Security+ (SY0-701) exam. It focuses on recalling specific details like port numbers and some formulas, plus sequences that need to be in the correct order, as well as pairs of terms that sound similar but have different functions. It won't cover any topics you might have missed. What it can do is help prevent losing points on facts you already know but might mix up when the 90-minute clock is running.
Last updated September 2026
The exam at a glance
- Questions
- Up to 90
- Time
- 90 minutes
- Passing score
- 750 on a 100 to 900 scale
- PBQs
- Usually first
Ports: the secure swaps
You'll likely see at least one question asking for the secure replacement of a cleartext protocol or asking which service runs on a given port number. Know these swaps cold. The complete list of ports appears on the ports cheat sheet.
| Instead of | Port | Use | Port |
|---|---|---|---|
| HTTP | 80 | HTTPS | 443 |
| FTP | 20/21 | SFTP or FTPS | 22 or 989/990 |
| Telnet | 23 | SSH | 22 |
| SMTP | 25 | SMTPS or submission | 465 or 587 |
| POP3 | 110 | POP3S | 995 |
| IMAP | 143 | IMAPS | 993 |
| LDAP | 389 | LDAPS | 636 |
| DNS | 53 | DoH or DoT | 443 or 853 |
| SNMP v1/v2c | 161/162 | SNMPv3 | 161/162 |
| Syslog | 514 | Syslog over TLS | 6514 |
| TFTP | 69 | SFTP or SCP | 22 |
| PPTP | 1723 | IPsec IKEv2 | 500 and 4500 |
| VNC | 5900 | RDP or SSH tunnel | 3389 or 22 |
| WinRM over HTTP | 5985 | WinRM over HTTPS | 5986 |
| SIP | 5060 | SIP over TLS | 5061 |
Risk formulas and recovery numbers
Domain 5 nearly always includes a quantitative risk question. Learn to follow this sequence: first, multiply asset value by exposure factor to find single loss expectancy; then, multiply that figure by the annual rate of occurrence to get the annualized loss expectancy, the number you compare against control costs.
| Term | What it means |
|---|---|
| Single loss expectancy (SLE)SLE = AV x EF | The loss from one event. The exposure factor shows how much value an asset could lose; for example, 0.4 means a 40 percent loss. |
| Annualized loss expectancy (ALE)ALE = SLE x ARO | The expected annual loss. An ARO of 0.5 suggests that an event happens roughly every two years. |
| Recovery time objective (RTO) | How long a system can stay down before it's no longer tolerable. This is the time needed to get the system running again. |
| Recovery point objective (RPO) | How much data you can afford to lose, counted backward from when the failure happens. It determines how frequently backups are required. |
| MTTR | Mean time to repair, which is the average duration to fix a broken component. |
| MTBF | Mean time between failures, indicating how long a repairable part usually operates before it breaks down; higher numbers are better. |
Two orders to know
Two orders come up as "what do you do next" questions. Get the sequence wrong and every answer choice starts to look reasonable.
Incident response
- Preparation
- Detection
- Analysis
- Containment
- Eradication
- Recovery
- Lessons learned
The order of containment and eradication matters. You first limit the damage and then remove the cause afterward. Updating the playbook comes later, as part of lessons learned.
Order of volatility
- CPU registers and cache
- RAM
- Network state
- Disk
- Backups and archives
Collect volatile evidence first because it disappears once the machine loses power or reboots. Hash any collected data and ensure an unbroken chain of custody from start to finish.
Pairs people mix up
The wrong answers on Security+ often closely resemble the correct ones, coming from a similar family but serving a slightly different purpose. These are the pairs that cause the most confusion for test-takers.
Control category vs control type
Category tells you who or what enforces the control (technical, managerial, operational, or physical), and type describes what the control aims to do, such as prevent, deter, detect, correct, compensate, or direct. Each control falls into one category but can fit more than one type.
Incremental backup vs differential backup
Incremental backups only record changes since the last backup of any kind, making each backup swift; however, a restore needs the last full backup plus every incremental since then. Differential backups capture what has changed since the last full backup, meaning you need just the most recent full and differential for a recovery.
RTO vs RPO
RTO, the Recovery Time Objective, is the time needed to get back online, while RPO, the Recovery Point Objective, is how much data, measured back in time, you can afford to lose.
Full comparison: RTO vs RPOIDS vs IPS
An IDS (Intrusion Detection System) monitors a copy of the traffic and sends alerts; an IPS (Intrusion Prevention System) sits inline and can block threats. If the question mentions stopping an attack, it's looking for the IPS.
Full comparison: IDS vs IPSHashing vs encryption
Hashing verifies data integrity through one-way functions, while encryption protects confidentiality but requires the right key to reverse.
Full comparison: Hashing vs encryptionSymmetric vs asymmetric encryption
Symmetric uses one shared key and is speedy for handling large amounts of data, like AES does. Asymmetric requires a pair of keys and moves slower, used for exchanging keys and creating digital signatures, as RSA and ECC do.
Full comparison: Symmetric vs asymmetric encryptionSigning vs encrypting for someone
You sign something with your private key, and anyone can verify it using your public key. To encrypt a message for someone else, you use their public key; only they can unlock it with their private key.
Authentication vs authorization
Authentication verifies your identity. Authorization grants permissions once the identity is confirmed.
Full comparison: Authentication vs authorizationVulnerability scan vs penetration test
A vulnerability scan finds weaknesses and reports them without exploiting them. A penetration test aims to exploit these under agreed rules to show potential attacker capabilities.
Full comparison: Vulnerability scan vs penetration testFalse positive vs false negative
A false positive alerts on harmless activity, while a false negative misses a real attack and is more dangerous.
Lists to recognize
These are often presented as "which of the following is an example of" questions, so be sure to know which items fit each list.
Authentication factors
- Something you know
- Something you have
- Something you are
- Somewhere you are
Risk treatment
- Transfer
- Accept (exemption or exception)
- Avoid
- Mitigate
Access control models
- Mandatory
- Discretionary
- Role-based
- Rule-based
- Attribute-based
Penetration test environments
- Known
- Partially known
- Unknown
Data roles
- Owner
- Controller
- Processor
- Custodian or steward
How to use this sheet in the last 48 hours
- Quiz yourself from itCover the right-hand column and say the answer out loud before looking. Mark every mistake. Rereading the sheet seems like progress, but recalling the answer from memory is what helps on test day.
- Drill the missesFor each error, do a brief practice set on that topic so you understand it in context, not just by definition.
- Try one PBQIf you've never done a performance-based question, look at one now. They usually come first on the exam, and meeting the format for the first time on exam day wastes time you need later.
- Stop the night beforeChoose a stop time and stick to it. Make sure both IDs match the name on registration and that you know your check-in time, then get some rest.
Security+ cram sheet FAQ
What should I review the night before the Security+ exam?
Review facts prone to confusion, like port numbers and their secure replacements, risk formulas, incident response order, the order of volatility, and control categories versus types. Don't begin a new topic you haven't studied. There's not enough time for it to stick and it cuts into sleep.Can you pass Security+ by cramming?
Not from nothing. The exam has up to 90 questions in 90 minutes, with many scenario questions that require understanding over rote memorization. Cramming helps just at the end for recalling facts on this sheet after you've worked through all five domains.What are the most commonly confused Security+ topics?
The ones people struggle with most are control categories versus control types and incremental versus differential backups. RTO and RPO get mixed up a lot too, as do IDS and IPS. Each pair is listed above with differences noted in a few lines.How do I know I am ready to take Security+?
Take a full timed practice test and analyze the results by domain. If you score well across every domain, not just on average, you're close. But if one domain scores much lower than others, spend your remaining time there instead of rereading this sheet, or move the appointment. You can push a test center booking back up to 24 hours ahead, and an online one right up to its start time.
Keep reading
Spend the last two days on your weak spots
SecPlus Mastery tracks your progress on each of the 28 SY0-701 objectives, so the final two days go to the areas where you're still weak. The timed mock exam mirrors the actual exam setup, with Domain 1 available without charge.
New accounts get 50% off both plans for 7 days: the 90-Day Pass is $19.50 instead of $39.
Aligned to the CompTIA Security+ SY0-701 objectives. Last reviewed September 2026. CompTIA and Security+ are trademarks of CompTIA, used here for identification only. SecPlus Mastery is an independent study resource and is not affiliated with or endorsed by CompTIA.