General Security Concepts: what Security+ tests and how to prepare
The vocabulary domain. It defines the control types, security principles and change-management ideas the other four domains assume you already know, which is why weak scores here tend to drag everything else down.
What this domain covers
The list below follows the published exam objectives for SY0-701. Depth matters more than breadth here: the exam asks you to apply these ideas to a scenario, not to recite them.
- Control categories — technical, managerial, operational, physical — and control types such as preventive, detective, corrective and compensating.
- The CIA triad, non-repudiation, authentication, authorisation and accounting, and gap analysis.
- Zero trust as a model: control plane and data plane, policy engine, policy administrator and policy enforcement point.
- Physical security measures and deception technology such as honeypots and honeytokens.
- Change management as a security process, and the cryptographic building blocks: PKI, encryption levels, key exchange, hashing, digital signatures and certificates.
Where candidates lose marks
- Confusing control category with control type. A question asks for both, and a firewall can be technical and preventive at once — the exam expects you to keep the two axes separate.
- Treating compensating controls as a synonym for "backup plan". A compensating control exists because the primary control is not feasible, and the exam tests that distinction directly.
- Reciting the zero trust components without knowing which one makes the decision and which one enforces it.
Study this domain first even though it looks like the easiest. Every scenario in Security Operations and Security Architecture is built on this vocabulary, and candidates who skim it here pay for it repeatedly later.
Find out if this domain is your weak one
20 free Security+ questions, no card required. Readiness is reported per domain, so you can see whether General Security Concepts is where your revision should go.