Overview

Domain 1 covers the foundational security concepts that underpin all other domains. It accounts for 12% of the SY0-701 exam and focuses on core security principles, identity and access management frameworks, and the threat landscape. While it is the smallest domain by weight, the concepts here are referenced throughout every other domain.

Exam Weight

12% — approximately 10-11 questions out of 90.

Topics

TopicNoteKey Focus
Security Fundamentalssecurity-conceptsCIA, least privilege, separation of duties
CIA Triadcia-triadConfidentiality, Integrity, Availability
AAA Frameworkaaa-frameworkRADIUS, TACACS+, Kerberos
AuthenticationauthenticationFactors, biometrics, passwordless
AuthorizationauthorizationOAuth, implicit deny, permissions
Access Control Modelsaccess-control-modelsDAC, MAC, RBAC, ABAC
Zero Trustzero-trustControl/data plane, policy engine
Defense in Depthdefense-in-depthLayered security, control types
Threat Actorsthreat-actorsAPT, insider, hacktivists, organized crime
Attack Vectorsattack-vectorsSupply chain, message-based, removable device
Social Engineeringsocial-engineeringPhishing, pretexting, tailgating
Physical Securityphysical-securityMantraps, bollards, surveillance
Deception Technologiesdeception-technologiesHoneypots, DNS sinkholes, honeytokens
Change Managementchange-managementCAB, rollback plans, maintenance windows

Cross-Domain Connections

Domain 1 concepts appear throughout the exam in applied contexts: