Common Security+ Exam Traps and How to Avoid Them
The Security+ SY0-701 traps that cost points: CIA vs AAA, preventive vs detective controls, RTO vs RPO, MTTR vs MTBF, and how to eliminate wrong answers.
By CompCertQuiz Editorial · Published · Last reviewed · 9 min read
Many missed Security+ questions are not caused by missing knowledge. They come from mixing up two terms that sound alike or from reading a question too quickly. This article covers the SY0-701 mix-ups that come up most often, with a one-line rule for each, and then a method for eliminating wrong answers when you are unsure.
Version note: this article covers SY0-701. CompTIA has announced a successor, Security+ V8 (exam code SY0-801), with a launch planned for November 2026. Check the CompTIA Security+ V8 page for current dates and objectives before you schedule, and book the version that matches the objectives you studied.
Trap 1: CIA versus AAA
The CIA triad describes what you are protecting; AAA describes how access is controlled and tracked. They are different frameworks, and exam writers like to blur them.
| Term | Question it answers | Example |
|---|---|---|
| Confidentiality | Can only the right people see it? | Encrypting a laptop drive |
| Integrity | Has it been altered? | Hashing a file, digital signature |
| Availability | Can authorized users reach it when needed? | Redundant servers, UPS |
| Authentication | Who are you? | Password plus authenticator app |
| Authorization | What are you allowed to do? | Role grants read-only access |
| Accounting | What did you do? | Logging and auditing activity |
- Encryption is confidentiality; hashing is integrity. A hash cannot be reversed to reveal the data, and a changed hash shows the data changed.
- Non-repudiation is separate from the triad: a sender cannot credibly deny an action. Digital signatures provide it because only the signer holds the private key.
- Identification is not authentication. Stating a username identifies; proving it with a credential authenticates.
- Authentication is not authorization. Logging in successfully does not mean you may open every file. OAuth is an authorization framework; OpenID Connect adds authentication.
Trap 2: preventive versus detective (and the other control types)
Security+ classifies controls by category (technical, managerial, operational, physical) and by type (preventive, deterrent, detective, corrective, compensating, directive). Questions usually ask for the type.
| Type | Purpose | Example |
|---|---|---|
| Preventive | Stop an event from happening | Firewall rule, MFA, locked door, IPS blocking traffic |
| Deterrent | Discourage an attempt | Warning sign, visible camera, banner |
| Detective | Identify an event during or after | IDS alert, log review, motion sensor |
| Corrective | Limit damage and restore after an event | Restoring from backup, isolating and cleaning a host |
| Compensating | Substitute when the primary control is not feasible | Segmenting a legacy system that cannot be patched |
| Directive | Instruct behavior | Policy, procedure, acceptable use policy |
Rules of thumb:IDS detects and IPS prevents, because an IPS sits inline and can block. A camera that records is detective; a camera used mainly to scare off intruders is deterrent. If the question stresses "an alternative because the standard control cannot be used," the answer is compensating. If the scenario is after the event and about repair, think corrective.
Trap 3: RTO, RPO, MTTR and MTBF
These business impact analysis terms are easy to scramble under pressure. Tie each to its unit and its question.
| Term | Meaning | Think |
|---|---|---|
| RTO (recovery time objective) | Maximum acceptable time to restore a service after disruption | How long can we be down? |
| RPO (recovery point objective) | Maximum acceptable amount of data loss, measured as time back from the failure | How much data can we lose? |
| MTTR (mean time to repair or restore) | Average time to fix a failed component or service | How long do repairs usually take? |
| MTBF (mean time between failures) | Average operating time between failures of a repairable system | How reliable is it? |
Worked example: backups run every four hours, and a failure happens just before the next backup. You could lose up to four hours of data, so the achievable RPO is about four hours. If the business says it can only tolerate 15 minutes of data loss, backups alone do not meet the RPO and you need replication or journaling. RTO is separate: if the service must be back in one hour, a cold site that takes days to build does not meet the RTO, while a hot site might.
Also remember the related risk formulas: SLE = asset value x exposure factor and ALE = SLE x ARO, where ARO is the annualized rate of occurrence.
Trap 4: IDS versus IPS, and fail-open versus fail-closed
- An IDS monitors and alerts (often on a tap or SPAN port); an IPS is inline and can block.
- Fail-closed blocks traffic when the device fails, favoring security; fail-open allows traffic, favoring availability. A safety system such as a door lock for emergency exit is a classic example where life safety demands fail-open behavior.
- A false positive is an alert for something that is not a problem; a false negative is a real problem that was missed. False negatives are usually the more dangerous.
Trap 5: look-alike attacks and terms
- Virus versus worm: a virus needs a host file or user action; a worm spreads on its own across networks.
- Password spraying versus brute force: spraying uses a few passwords across many accounts, which avoids lockouts; brute force hammers one account.
- Phishing, spear phishing, whaling: broad, targeted, and aimed at senior executives.
- Vulnerability scan versus penetration test: a scan identifies potential weaknesses; a penetration test attempts to exploit them to show real impact.
- Sanitization versus destruction: sanitization removes data so media can be reused; destruction physically ruins the media.
- Policy versus standard versus procedure: policy states intent, standard sets mandatory specifics, procedure lists the steps.
- Data controller versus processor: the controller decides why and how personal data is processed; the processor handles it on the controller's behalf.
- Risk appetite versus tolerance: appetite is the broad amount of risk an organization is willing to pursue; tolerance is the acceptable deviation around specific objectives.
- Risk transfer: insurance or contractual shifting of the financial impact, not elimination of the risk.
Trap 6: incident response order
The phases are preparation, detection, analysis, containment, eradication, recovery and lessons learned, consistent with NIST SP 800-61. When a question asks what to do first after confirming an active compromise, the answer is generally to contain it, not to wipe systems or begin a full investigation; preserving evidence and chain of custody still matter if forensics are needed.
A method for eliminating wrong answers
- Read the last sentence first. Find what is being asked: the best, most cost-effective, first, or most likely answer. Then read the scenario for clues.
- Underline the constraint.Words such as "without interrupting users," "legacy system," or "limited budget" often rule out otherwise correct options.
- Classify the problem before looking at the options. Decide whether it is an attack type, a control type, a crypto choice or a risk strategy, then check the options against that.
- Eliminate by category mismatch. If the question asks for a detective control, remove any option that is clearly preventive. If it is about integrity, remove options that only provide confidentiality.
- Beware extremes. Options that say always, never, or require something disproportionate to the problem (replacing the entire network to fix one misconfiguration) are rarely right.
- Prefer the least privilege and defense-in-depth answer when two options both work, and prefer secure protocols over cleartext ones.
- Choose between the last two with the wording. Re-read the question and ask which option addresses exactly the stated problem, not a related one.
Time-saver: if you cannot narrow past two options in about a minute, pick your best answer, flag it, and move on. You can return after the rest of the exam.
Turn traps into practice
When you miss a practice question, note which trap caught you: a term mix-up, a missed constraint, or rushing. Over a few sets, patterns appear and the fix becomes obvious. Try the free SY0-701 practice questions and keep the cheat sheet nearby for ports, crypto and authentication reminders. If you are still planning your study time, the 30-day Security+ study plan builds trap review into each week.
Frequently asked questions
What is the difference between RTO and RPO?
RTO is how long a service can be down before the impact is unacceptable. RPO is how much data, measured in time, the organization can afford to lose. A four-hour backup interval implies an RPO of up to four hours.
What is the difference between MTTR and MTBF?
MTTR is the average time it takes to repair or restore something after it fails. MTBF is the average time a system operates between failures, so it measures reliability.
What is the difference between a preventive and a detective control?
A preventive control stops an event from occurring, such as a firewall rule or multifactor authentication. A detective control identifies that an event is occurring or has occurred, such as an IDS alert or a log review.
What is the difference between authentication and authorization?
Authentication verifies who you are. Authorization determines what an authenticated identity is allowed to do. Accounting records what it did.
How do I eliminate wrong answers on Security+?
Identify what the question asks, classify the concept, and remove options from the wrong category or that ignore a stated constraint. Then choose between the remaining options by which one addresses exactly the problem described.
CompCertQuiz is an independent practice-exam site and is not affiliated with, endorsed by, or sponsored by CompTIA. Our practice questions are original material written for exam preparation. CompTIA and its certification names are trademarks of CompTIA, Inc. Always confirm exam details on comptia.org.