Cheat Sheet

Security+ SY0-701 Cheat Sheet: Ports, Crypto, Auth

A Security+ SY0-701 cheat sheet covering common ports and protocols, cryptography, authentication (SAML, OAuth, RADIUS) and attack types.

By CompCertQuiz Editorial · Published · Last reviewed · 9 min read

This Security+ SY0-701 cheat sheet collects the facts that the exam most often expects you to recall: common ports and protocols, cryptography, authentication and identity protocols, and attack types. Use it as a review aid after you have studied the concepts, not as a replacement for understanding them.

Version note: this article covers SY0-701. CompTIA has announced a successor, Security+ V8 (exam code SY0-801), with a launch planned for November 2026. Check the CompTIA Security+ V8 page for current dates and objectives before you schedule, and book the version that matches the objectives you studied.

Common ports and protocols

Port questions usually appear as short recall items or inside PBQs such as firewall rule tasks. Prefer secure protocols whenever a question asks which to use.

PortProtocolNotes
20/21FTPCleartext file transfer; 21 control, 20 data (active mode)
22SSH / SCP / SFTPEncrypted remote administration and file transfer
23TelnetCleartext remote access; replace with SSH
25SMTPServer-to-server email
53DNSUDP for queries, TCP for zone transfers and large responses
67/68DHCPUDP; server 67, client 68
69TFTPUDP; no authentication
80HTTPCleartext web
88KerberosTicket-based authentication
110POP3Cleartext email retrieval (995 for POP3S)
123NTPTime synchronization (UDP)
143IMAPCleartext email access (993 for IMAPS)
161/162SNMPDevice management; 162 for traps. Use SNMPv3 for security
389LDAPDirectory access, cleartext (636 for LDAPS)
443HTTPSHTTP over TLS
445SMBWindows file sharing
514SyslogLog forwarding (UDP by default)
587SMTP submissionClient mail submission, typically with STARTTLS (465 is SMTP over implicit TLS)
1433Microsoft SQL ServerDatabase
1812/1813RADIUSAuthentication/authorization and accounting (UDP)
3389RDPRemote Desktop; restrict and protect with VPN or gateway
49TACACS+TCP; separates authentication, authorization and accounting

Memory trick: the secure version of a protocol almost always replaces a cleartext one with TLS or SSH: Telnet becomes SSH, HTTP becomes HTTPS, LDAP becomes LDAPS, and POP3 and IMAP become POP3S and IMAPS.

Cryptography essentials

Symmetric versus asymmetric

SymmetricAsymmetric
KeysOne shared secret keyPublic and private key pair
SpeedFast; good for bulk dataSlower; used for key exchange, signatures
ExamplesAES (128/192/256-bit keys), ChaCha20; 3DES and DES are legacyRSA, ECC, Diffie-Hellman (key agreement)
Main challengeSecurely distributing the keyComputational cost; managing certificates

AES is the standard symmetric algorithm, specified in NIST FIPS 197. In practice, protocols such as TLS use asymmetric cryptography to authenticate and agree on a key, then use symmetric encryption for the actual data. This is called a hybrid approach.

Who uses which key

  • Confidentiality: encrypt with the recipient's public key; only their private key decrypts.
  • Digital signature: sign with your own private key; anyone verifies with your public key. This provides integrity, authentication and non-repudiation.

Hashing

  • A hash is one-way and produces a fixed-length digest; it provides integrity, not confidentiality.
  • SHA-256 and SHA-3 are current choices. MD5 and SHA-1 are considered weak because of collision attacks.
  • Salting adds unique random data to each password before hashing, defeating precomputed rainbow tables.
  • Key stretching (PBKDF2, bcrypt) makes each password guess deliberately slow.
  • HMAC combines a hash with a secret key to verify both integrity and authenticity.

PKI and certificates

  • A certificate authority (CA) issues certificates that bind a public key to an identity; the root CA is the trust anchor.
  • A certificate signing request (CSR) is how you ask a CA to issue a certificate for your key.
  • Revocation is checked with a CRL (a published list) or OCSP (a real-time status query).
  • A wildcard certificate covers all first-level subdomains of one domain; a self-signed certificate is not trusted by default.
  • Hardware that protects keys: a TPM is a chip on a device, an HSM is a dedicated appliance or card for key storage and operations.

Related protocols

  • TLS 1.3 is the current TLS version (RFC 8446); SSL and early TLS versions are deprecated.
  • IPsec secures IP traffic using ESP (encryption and integrity) and AH (integrity only), in transport or tunnel mode.
  • WPA3 uses SAE to replace the pre-shared-key handshake of WPA2-Personal.
  • Data obfuscation: masking hides parts of data, tokenization replaces data with a token, steganography hides data inside other files.

Authentication and identity

Factors

Something you know (password, PIN), something you have (token, smart card, authenticator app), something you are (biometrics), and somewhere you are (location). Multifactor authentication requires two or more different factors; a password plus a security question is still one factor.

SSO and federation protocols

ProtocolPurposeKey details
SAMLFederated authentication (SSO)XML assertions passed from an identity provider (IdP) to a service provider (SP); common for enterprise web SSO
OAuth 2.0Authorization (delegated access)Issues access tokens so an app can act on a user’s behalf without their password (RFC 6749)
OpenID ConnectAuthentication layer on OAuth 2.0Returns an ID token describing who the user is
KerberosTicket-based authenticationUses a KDC and tickets; sensitive to clock skew
LDAPDirectory service protocolQuery and authenticate against directories; use LDAPS

See RFC 6749 for the OAuth 2.0 framework. The classic trap is calling OAuth an authentication protocol: it authorizes access, and OpenID Connect adds authentication on top.

RADIUS versus TACACS+

RADIUSTACACS+
TransportUDP (1812/1813)TCP (49)
AAACombines authentication and authorizationSeparates authentication, authorization and accounting
EncryptionEncrypts only the password in the packetEncrypts the entire payload
Typical useNetwork access: Wi-Fi, VPN, 802.1XAdministrative access to network devices

See RFC 2865 (RADIUS) and RFC 8907 (TACACS+).

Access control models

  • MAC (mandatory): labels and clearances set by policy; users cannot change them.
  • DAC (discretionary): the resource owner decides who gets access.
  • RBAC: permissions follow job roles.
  • ABAC: decisions use attributes of user, resource and environment.
  • Rule-based: system-enforced rules such as time-of-day or IP restrictions.

Common attack types

AttackHow to recognize it
Phishing / spear phishingDeceptive email; spear phishing targets a specific person or group
Vishing / smishingVoice call / text message social engineering
Business email compromiseImpersonating an executive or vendor to authorize payments
SQL injectionMalicious SQL in input; mitigate with parameterized queries and input validation
Cross-site scripting (XSS)Script injected into a page that runs in other users’ browsers; mitigate with output encoding
CSRFTricks an authenticated user’s browser into sending an unwanted request
Buffer overflowInput exceeds memory allocation, corrupting adjacent memory
Directory traversalSequences like ../ to reach files outside the web root
On-path (formerly man-in-the-middle)Attacker intercepts or alters traffic between two parties
ReplayCaptured valid data is re-sent; mitigate with nonces and timestamps
DDoSMany sources overwhelm availability; amplification and reflection abuse third-party servers
DNS poisoningFalse records injected into a resolver cache
Password sprayingA few common passwords tried across many accounts
Brute force / credential stuffingMany guesses on one account / reused leaked credentials
RansomwareEncrypts data and demands payment; backups and segmentation limit impact
RootkitHides malware at OS or firmware level
Logic bombMalicious code that triggers on a condition or date
Birthday / collisionFinding two inputs with the same hash
DowngradeForcing a connection to use a weaker protocol or cipher

For web application flaws, the OWASP Top 10 is the best companion reference.

Frequently asked questions

What is the difference between RADIUS and TACACS+?

RADIUS uses UDP, combines authentication and authorization, and encrypts only the password; it is typical for network access such as Wi-Fi and VPN. TACACS+ uses TCP port 49, separates authentication, authorization and accounting, and encrypts the whole payload; it is typical for administering network devices.

What is the difference between SAML and OAuth?

SAML is an XML-based standard for federated authentication and single sign-on. OAuth 2.0 is an authorization framework that lets an application obtain limited access to a resource on a user's behalf. OpenID Connect builds authentication on top of OAuth 2.0.

Which key signs a message and which verifies it?

The sender signs with their private key and the recipient verifies with the sender's public key. Encryption for confidentiality is the reverse: the sender encrypts with the recipient's public key.

Which ports should I memorize for Security+?

Prioritize 22 (SSH), 25 (SMTP), 53 (DNS), 80 (HTTP), 443 (HTTPS), 389 and 636 (LDAP and LDAPS), 3389 (RDP), 161 and 162 (SNMP), 1812 and 1813 (RADIUS), 49 (TACACS+), and the secure email ports 993 and 995.

Test your recall with the free SY0-701 practice questions, and see the common exam traps for the mix-ups that cost points.

CompCertQuiz is an independent practice-exam site and is not affiliated with, endorsed by, or sponsored by CompTIA. Our practice questions are original material written for exam preparation. CompTIA and its certification names are trademarks of CompTIA, Inc. Always confirm exam details on comptia.org.

More from the blog