Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Last-minute review

Security+ Cram Sheet: Last-Minute Review

This sheet is for the final two days before your Security+ (SY0-701) exam. It focuses on recalling specific details like port numbers and some formulas, plus sequences that need to be in the correct order, as well as pairs of terms that sound similar but have different functions. It won't cover any topics you might have missed. What it can do is help prevent losing points on facts you already know but might mix up when the 90-minute clock is running.

Last updated September 2026

The exam at a glance

Questions
Up to 90
Time
90 minutes
Passing score
750 on a 100 to 900 scale
PBQs
Usually first

Ports: the secure swaps

You'll likely see at least one question asking for the secure replacement of a cleartext protocol or asking which service runs on a given port number. Know these swaps cold. The complete list of ports appears on the ports cheat sheet.

Cleartext protocols and their secure replacements, with ports
Instead ofPortUsePort
HTTP80HTTPS443
FTP20/21SFTP or FTPS22 or 989/990
Telnet23SSH22
SMTP25SMTPS or submission465 or 587
POP3110POP3S995
IMAP143IMAPS993
LDAP389LDAPS636
DNS53DoH or DoT443 or 853
SNMP v1/v2c161/162SNMPv3161/162
Syslog514Syslog over TLS6514
TFTP69SFTP or SCP22
PPTP1723IPsec IKEv2500 and 4500
VNC5900RDP or SSH tunnel3389 or 22
WinRM over HTTP5985WinRM over HTTPS5986
SIP5060SIP over TLS5061

Risk formulas and recovery numbers

Domain 5 nearly always includes a quantitative risk question. Learn to follow this sequence: first, multiply asset value by exposure factor to find single loss expectancy; then, multiply that figure by the annual rate of occurrence to get the annualized loss expectancy, the number you compare against control costs.

Risk formulas and recovery metrics with what each one means
TermWhat it means
Single loss expectancy (SLE)SLE = AV x EFThe loss from one event. The exposure factor shows how much value an asset could lose; for example, 0.4 means a 40 percent loss.
Annualized loss expectancy (ALE)ALE = SLE x AROThe expected annual loss. An ARO of 0.5 suggests that an event happens roughly every two years.
Recovery time objective (RTO)How long a system can stay down before it's no longer tolerable. This is the time needed to get the system running again.
Recovery point objective (RPO)How much data you can afford to lose, counted backward from when the failure happens. It determines how frequently backups are required.
MTTRMean time to repair, which is the average duration to fix a broken component.
MTBFMean time between failures, indicating how long a repairable part usually operates before it breaks down; higher numbers are better.

Two orders to know

Two orders come up as "what do you do next" questions. Get the sequence wrong and every answer choice starts to look reasonable.

Incident response

  1. Preparation
  2. Detection
  3. Analysis
  4. Containment
  5. Eradication
  6. Recovery
  7. Lessons learned

The order of containment and eradication matters. You first limit the damage and then remove the cause afterward. Updating the playbook comes later, as part of lessons learned.

Order of volatility

  1. CPU registers and cache
  2. RAM
  3. Network state
  4. Disk
  5. Backups and archives

Collect volatile evidence first because it disappears once the machine loses power or reboots. Hash any collected data and ensure an unbroken chain of custody from start to finish.

Pairs people mix up

The wrong answers on Security+ often closely resemble the correct ones, coming from a similar family but serving a slightly different purpose. These are the pairs that cause the most confusion for test-takers.

  • Control category vs control type

    Category tells you who or what enforces the control (technical, managerial, operational, or physical), and type describes what the control aims to do, such as prevent, deter, detect, correct, compensate, or direct. Each control falls into one category but can fit more than one type.

  • Incremental backup vs differential backup

    Incremental backups only record changes since the last backup of any kind, making each backup swift; however, a restore needs the last full backup plus every incremental since then. Differential backups capture what has changed since the last full backup, meaning you need just the most recent full and differential for a recovery.

  • RTO vs RPO

    RTO, the Recovery Time Objective, is the time needed to get back online, while RPO, the Recovery Point Objective, is how much data, measured back in time, you can afford to lose.

    Full comparison: RTO vs RPO
  • IDS vs IPS

    An IDS (Intrusion Detection System) monitors a copy of the traffic and sends alerts; an IPS (Intrusion Prevention System) sits inline and can block threats. If the question mentions stopping an attack, it's looking for the IPS.

    Full comparison: IDS vs IPS
  • Hashing vs encryption

    Hashing verifies data integrity through one-way functions, while encryption protects confidentiality but requires the right key to reverse.

    Full comparison: Hashing vs encryption
  • Symmetric vs asymmetric encryption

    Symmetric uses one shared key and is speedy for handling large amounts of data, like AES does. Asymmetric requires a pair of keys and moves slower, used for exchanging keys and creating digital signatures, as RSA and ECC do.

    Full comparison: Symmetric vs asymmetric encryption
  • Signing vs encrypting for someone

    You sign something with your private key, and anyone can verify it using your public key. To encrypt a message for someone else, you use their public key; only they can unlock it with their private key.

  • Authentication vs authorization

    Authentication verifies your identity. Authorization grants permissions once the identity is confirmed.

    Full comparison: Authentication vs authorization
  • Vulnerability scan vs penetration test

    A vulnerability scan finds weaknesses and reports them without exploiting them. A penetration test aims to exploit these under agreed rules to show potential attacker capabilities.

    Full comparison: Vulnerability scan vs penetration test
  • False positive vs false negative

    A false positive alerts on harmless activity, while a false negative misses a real attack and is more dangerous.

Lists to recognize

These are often presented as "which of the following is an example of" questions, so be sure to know which items fit each list.

Authentication factors

  • Something you know
  • Something you have
  • Something you are
  • Somewhere you are

Risk treatment

  • Transfer
  • Accept (exemption or exception)
  • Avoid
  • Mitigate

Access control models

  • Mandatory
  • Discretionary
  • Role-based
  • Rule-based
  • Attribute-based

Penetration test environments

  • Known
  • Partially known
  • Unknown

Data roles

  • Owner
  • Controller
  • Processor
  • Custodian or steward

How to use this sheet in the last 48 hours

  1. Quiz yourself from itCover the right-hand column and say the answer out loud before looking. Mark every mistake. Rereading the sheet seems like progress, but recalling the answer from memory is what helps on test day.
  2. Drill the missesFor each error, do a brief practice set on that topic so you understand it in context, not just by definition.
  3. Try one PBQIf you've never done a performance-based question, look at one now. They usually come first on the exam, and meeting the format for the first time on exam day wastes time you need later.
  4. Stop the night beforeChoose a stop time and stick to it. Make sure both IDs match the name on registration and that you know your check-in time, then get some rest.

Security+ cram sheet FAQ

  • What should I review the night before the Security+ exam?
    Review facts prone to confusion, like port numbers and their secure replacements, risk formulas, incident response order, the order of volatility, and control categories versus types. Don't begin a new topic you haven't studied. There's not enough time for it to stick and it cuts into sleep.
  • Can you pass Security+ by cramming?
    Not from nothing. The exam has up to 90 questions in 90 minutes, with many scenario questions that require understanding over rote memorization. Cramming helps just at the end for recalling facts on this sheet after you've worked through all five domains.
  • What are the most commonly confused Security+ topics?
    The ones people struggle with most are control categories versus control types and incremental versus differential backups. RTO and RPO get mixed up a lot too, as do IDS and IPS. Each pair is listed above with differences noted in a few lines.
  • How do I know I am ready to take Security+?
    Take a full timed practice test and analyze the results by domain. If you score well across every domain, not just on average, you're close. But if one domain scores much lower than others, spend your remaining time there instead of rereading this sheet, or move the appointment. You can push a test center booking back up to 24 hours ahead, and an online one right up to its start time.

Spend the last two days on your weak spots

SecPlus Mastery tracks your progress on each of the 28 SY0-701 objectives, so the final two days go to the areas where you're still weak. The timed mock exam mirrors the actual exam setup, with Domain 1 available without charge.

New accounts get 50% off both plans for 7 days: the 90-Day Pass is $19.50 instead of $39.

Aligned to the CompTIA Security+ SY0-701 objectives. Last reviewed September 2026. CompTIA and Security+ are trademarks of CompTIA, used here for identification only. SecPlus Mastery is an independent study resource and is not affiliated with or endorsed by CompTIA.