Overview

Domain 4 is the largest domain on the SY0-701 exam at 28%, covering the day-to-day operational activities that keep an organization secure. This includes identity management, monitoring, incident response, vulnerability management, and security tooling. Expect the most questions from this domain.

Exam Weight

28% — approximately 25-26 questions out of 90.

Topics

TopicNoteKey Focus
Identity Managementidentity-managementProvisioning, deprovisioning, directory services
Single Sign-OnssoSAML, OAuth, OIDC, federation
Multi-Factor AuthenticationmfaFactor types, push notifications, TOTP, FIDO2
FederationfederationCross-organization trust, SAML assertions
Privileged Access Managementprivileged-access-managementPAM, just-in-time access, credential vaulting
Endpoint Securityendpoint-securityAntivirus, HIDS, application control, boot integrity
EDR/XDRedr-xdrEndpoint/extended detection and response
SIEMsiemLog aggregation, correlation, alerting, dashboards
SOARsoarSecurity orchestration, automation, playbooks
Vulnerability Managementvulnerability-managementScanning, CVE, CVSS, remediation prioritization
Penetration Testingpenetration-testingRules of engagement, methodologies, reporting
Incident Responseincident-responsePhases, containment, eradication, lessons learned
Digital Forensicsdigital-forensicsChain of custody, imaging, volatility order
Threat Huntingthreat-huntingProactive search, hypothesis-driven, IOC analysis
Threat Intelligencethreat-intelligenceOSINT, STIX/TAXII, TTP, threat feeds
Log Managementlog-managementSyslog, centralized logging, retention, NTP
Network Monitoringnetwork-monitoringNetFlow, packet capture, SNMP, baseline
Email Securityemail-securitySPF, DKIM, DMARC, gateway filtering
Automation & Scriptingautomation-and-scriptingPython, PowerShell, Bash, API integration
HardeninghardeningBenchmarks, CIS, STIG, removing unnecessary services

Cross-Domain Connections