Security+ SY0-701 Cheat Sheet: Ports, Crypto, Auth
A Security+ SY0-701 cheat sheet covering common ports and protocols, cryptography, authentication (SAML, OAuth, RADIUS) and attack types.
By CompCertQuiz Editorial · Published · Last reviewed · 9 min read
This Security+ SY0-701 cheat sheet collects the facts that the exam most often expects you to recall: common ports and protocols, cryptography, authentication and identity protocols, and attack types. Use it as a review aid after you have studied the concepts, not as a replacement for understanding them.
Version note: this article covers SY0-701. CompTIA has announced a successor, Security+ V8 (exam code SY0-801), with a launch planned for November 2026. Check the CompTIA Security+ V8 page for current dates and objectives before you schedule, and book the version that matches the objectives you studied.
Common ports and protocols
Port questions usually appear as short recall items or inside PBQs such as firewall rule tasks. Prefer secure protocols whenever a question asks which to use.
| Port | Protocol | Notes |
|---|---|---|
| 20/21 | FTP | Cleartext file transfer; 21 control, 20 data (active mode) |
| 22 | SSH / SCP / SFTP | Encrypted remote administration and file transfer |
| 23 | Telnet | Cleartext remote access; replace with SSH |
| 25 | SMTP | Server-to-server email |
| 53 | DNS | UDP for queries, TCP for zone transfers and large responses |
| 67/68 | DHCP | UDP; server 67, client 68 |
| 69 | TFTP | UDP; no authentication |
| 80 | HTTP | Cleartext web |
| 88 | Kerberos | Ticket-based authentication |
| 110 | POP3 | Cleartext email retrieval (995 for POP3S) |
| 123 | NTP | Time synchronization (UDP) |
| 143 | IMAP | Cleartext email access (993 for IMAPS) |
| 161/162 | SNMP | Device management; 162 for traps. Use SNMPv3 for security |
| 389 | LDAP | Directory access, cleartext (636 for LDAPS) |
| 443 | HTTPS | HTTP over TLS |
| 445 | SMB | Windows file sharing |
| 514 | Syslog | Log forwarding (UDP by default) |
| 587 | SMTP submission | Client mail submission, typically with STARTTLS (465 is SMTP over implicit TLS) |
| 1433 | Microsoft SQL Server | Database |
| 1812/1813 | RADIUS | Authentication/authorization and accounting (UDP) |
| 3389 | RDP | Remote Desktop; restrict and protect with VPN or gateway |
| 49 | TACACS+ | TCP; separates authentication, authorization and accounting |
Memory trick: the secure version of a protocol almost always replaces a cleartext one with TLS or SSH: Telnet becomes SSH, HTTP becomes HTTPS, LDAP becomes LDAPS, and POP3 and IMAP become POP3S and IMAPS.
Cryptography essentials
Symmetric versus asymmetric
| Symmetric | Asymmetric | |
|---|---|---|
| Keys | One shared secret key | Public and private key pair |
| Speed | Fast; good for bulk data | Slower; used for key exchange, signatures |
| Examples | AES (128/192/256-bit keys), ChaCha20; 3DES and DES are legacy | RSA, ECC, Diffie-Hellman (key agreement) |
| Main challenge | Securely distributing the key | Computational cost; managing certificates |
AES is the standard symmetric algorithm, specified in NIST FIPS 197. In practice, protocols such as TLS use asymmetric cryptography to authenticate and agree on a key, then use symmetric encryption for the actual data. This is called a hybrid approach.
Who uses which key
- Confidentiality: encrypt with the recipient's public key; only their private key decrypts.
- Digital signature: sign with your own private key; anyone verifies with your public key. This provides integrity, authentication and non-repudiation.
Hashing
- A hash is one-way and produces a fixed-length digest; it provides integrity, not confidentiality.
- SHA-256 and SHA-3 are current choices. MD5 and SHA-1 are considered weak because of collision attacks.
- Salting adds unique random data to each password before hashing, defeating precomputed rainbow tables.
- Key stretching (PBKDF2, bcrypt) makes each password guess deliberately slow.
- HMAC combines a hash with a secret key to verify both integrity and authenticity.
PKI and certificates
- A certificate authority (CA) issues certificates that bind a public key to an identity; the root CA is the trust anchor.
- A certificate signing request (CSR) is how you ask a CA to issue a certificate for your key.
- Revocation is checked with a CRL (a published list) or OCSP (a real-time status query).
- A wildcard certificate covers all first-level subdomains of one domain; a self-signed certificate is not trusted by default.
- Hardware that protects keys: a TPM is a chip on a device, an HSM is a dedicated appliance or card for key storage and operations.
Related protocols
- TLS 1.3 is the current TLS version (RFC 8446); SSL and early TLS versions are deprecated.
- IPsec secures IP traffic using ESP (encryption and integrity) and AH (integrity only), in transport or tunnel mode.
- WPA3 uses SAE to replace the pre-shared-key handshake of WPA2-Personal.
- Data obfuscation: masking hides parts of data, tokenization replaces data with a token, steganography hides data inside other files.
Authentication and identity
Factors
Something you know (password, PIN), something you have (token, smart card, authenticator app), something you are (biometrics), and somewhere you are (location). Multifactor authentication requires two or more different factors; a password plus a security question is still one factor.
SSO and federation protocols
| Protocol | Purpose | Key details |
|---|---|---|
| SAML | Federated authentication (SSO) | XML assertions passed from an identity provider (IdP) to a service provider (SP); common for enterprise web SSO |
| OAuth 2.0 | Authorization (delegated access) | Issues access tokens so an app can act on a user’s behalf without their password (RFC 6749) |
| OpenID Connect | Authentication layer on OAuth 2.0 | Returns an ID token describing who the user is |
| Kerberos | Ticket-based authentication | Uses a KDC and tickets; sensitive to clock skew |
| LDAP | Directory service protocol | Query and authenticate against directories; use LDAPS |
See RFC 6749 for the OAuth 2.0 framework. The classic trap is calling OAuth an authentication protocol: it authorizes access, and OpenID Connect adds authentication on top.
RADIUS versus TACACS+
| RADIUS | TACACS+ | |
|---|---|---|
| Transport | UDP (1812/1813) | TCP (49) |
| AAA | Combines authentication and authorization | Separates authentication, authorization and accounting |
| Encryption | Encrypts only the password in the packet | Encrypts the entire payload |
| Typical use | Network access: Wi-Fi, VPN, 802.1X | Administrative access to network devices |
See RFC 2865 (RADIUS) and RFC 8907 (TACACS+).
Access control models
- MAC (mandatory): labels and clearances set by policy; users cannot change them.
- DAC (discretionary): the resource owner decides who gets access.
- RBAC: permissions follow job roles.
- ABAC: decisions use attributes of user, resource and environment.
- Rule-based: system-enforced rules such as time-of-day or IP restrictions.
Common attack types
| Attack | How to recognize it |
|---|---|
| Phishing / spear phishing | Deceptive email; spear phishing targets a specific person or group |
| Vishing / smishing | Voice call / text message social engineering |
| Business email compromise | Impersonating an executive or vendor to authorize payments |
| SQL injection | Malicious SQL in input; mitigate with parameterized queries and input validation |
| Cross-site scripting (XSS) | Script injected into a page that runs in other users’ browsers; mitigate with output encoding |
| CSRF | Tricks an authenticated user’s browser into sending an unwanted request |
| Buffer overflow | Input exceeds memory allocation, corrupting adjacent memory |
| Directory traversal | Sequences like ../ to reach files outside the web root |
| On-path (formerly man-in-the-middle) | Attacker intercepts or alters traffic between two parties |
| Replay | Captured valid data is re-sent; mitigate with nonces and timestamps |
| DDoS | Many sources overwhelm availability; amplification and reflection abuse third-party servers |
| DNS poisoning | False records injected into a resolver cache |
| Password spraying | A few common passwords tried across many accounts |
| Brute force / credential stuffing | Many guesses on one account / reused leaked credentials |
| Ransomware | Encrypts data and demands payment; backups and segmentation limit impact |
| Rootkit | Hides malware at OS or firmware level |
| Logic bomb | Malicious code that triggers on a condition or date |
| Birthday / collision | Finding two inputs with the same hash |
| Downgrade | Forcing a connection to use a weaker protocol or cipher |
For web application flaws, the OWASP Top 10 is the best companion reference.
Frequently asked questions
What is the difference between RADIUS and TACACS+?
RADIUS uses UDP, combines authentication and authorization, and encrypts only the password; it is typical for network access such as Wi-Fi and VPN. TACACS+ uses TCP port 49, separates authentication, authorization and accounting, and encrypts the whole payload; it is typical for administering network devices.
What is the difference between SAML and OAuth?
SAML is an XML-based standard for federated authentication and single sign-on. OAuth 2.0 is an authorization framework that lets an application obtain limited access to a resource on a user's behalf. OpenID Connect builds authentication on top of OAuth 2.0.
Which key signs a message and which verifies it?
The sender signs with their private key and the recipient verifies with the sender's public key. Encryption for confidentiality is the reverse: the sender encrypts with the recipient's public key.
Which ports should I memorize for Security+?
Prioritize 22 (SSH), 25 (SMTP), 53 (DNS), 80 (HTTP), 443 (HTTPS), 389 and 636 (LDAP and LDAPS), 3389 (RDP), 161 and 162 (SNMP), 1812 and 1813 (RADIUS), 49 (TACACS+), and the secure email ports 993 and 995.
Test your recall with the free SY0-701 practice questions, and see the common exam traps for the mix-ups that cost points.
CompCertQuiz is an independent practice-exam site and is not affiliated with, endorsed by, or sponsored by CompTIA. Our practice questions are original material written for exam preparation. CompTIA and its certification names are trademarks of CompTIA, Inc. Always confirm exam details on comptia.org.