CompTIA Security+ guideHigh-value skills
Security+ Acronyms: How to Learn Them Without Memorizing Blindly
Learn Security+ acronyms by the job they do. These pairs are in the SY0-701 objectives. None of them is guaranteed to appear on your form.
Short answer
Learn the job before the expansion. On SY0-701, IDS alerts and IPS can block, SIEM collects events and SOAR helps orchestrate a response, RPO is data loss and RTO is downtime, SAML and OAuth are different access standards, and EDR watches an endpoint while XDR looks across more sources. The objectives glossary uses RBAC for both role-based and rule-based access control. Nothing here is a promise that the acronym will be on your form.
Function first
The SY0-701 objectives include a long acronym list. Reprinting it does not tell you which term to choose when two of them both sound like “security software.” Use the list as a spell-check after you can explain the pair. An acronym’s presence in the glossary is not a promise it will show up on your form.
Pairs that get swapped
| Pair | How to tell them apart | A context cue in a stem |
|---|---|---|
| IDS and IPS | An intrusion detection system raises an alert from a copy of traffic. An intrusion prevention system sits in the path and can block. | “Tap” or “copy” leans IDS. “Inline” and “dropped the packet” leans IPS. |
| SIEM and SOAR | A SIEM collects and correlates security events. SOAR, security orchestration, automation, and response, is about coordinating the follow-up. The objectives also discuss automation and orchestration as their own topic. | A dashboard of logons is SIEM work. A playbook that opens a ticket and disables an account is orchestration. |
| RTO and RPO | Recovery time objective is how long you can be down. Recovery point objective is how much data, in time, you can afford to lose. | “Back online in two hours” is RTO. “Lose at most 15 minutes of orders” is RPO. |
| SAML and OAuth | Both appear under single sign-on in the objectives. SAML is a way to pass an authentication assertion. OAuth is an authorization framework for delegated access. They are not two names for a password. | “Prove who the user is to another site” is closer to SAML. “Let this app act with a limited grant” is closer to OAuth. |
| EDR and XDR | Endpoint detection and response watches the host: processes, files, and local activity. Extended detection and response is the broader correlation across more than one kind of source. | A suspicious process on a laptop is an EDR question. A story that combines endpoint and network detections is where XDR is the broader idea. |
| Two meanings of RBAC | The objectives glossary expands RBAC as role-based access control and, on the next line, as rule-based access control. The body lists both “role-based” and “rule-based.” | A job title granting folder access is role-based. A condition such as time of day or a firewall-style rule is rule-based. Read the stem. Do not expand the letters and stop. |
OpenID Connect is a real standard on top of OAuth. The SY0-701 objectives PDF does not name it. The same objectives do list attribute-based access control next to mandatory, discretionary, role-based, and rule-based. The identity guide is where those decisions get a scenario. Recovery time and recovery point get a worked timeline in the recovery metrics guide.
A way to practice without a deck of 200 cards
- Cover the expansion. Read a one-line scenario and say which side of the pair fits.
- If you miss, write the cue you ignored (“inline,” “15 minutes of data,” “job title”).
- Only then look up the letters.
Use a Security+ scenario that turns on one of these pairs. Getting the letters right and picking the wrong control is still a miss. The free set will not quiz you on the entire glossary.
Trust the source
Official sources
Exam policies can change. Use these primary sources for the most current details.