You’ll notice several SY0-401 differences in Compliance and Operational Security compared to the SY0-301 exam. The weighting of this domain is the same at 18%. You can expect to see as many as 18 questions on Compliance and Operational Security. While many of the topics from the SY0-301 exam are in the 401 objectives, you’ll find that many have been reorganized and some have been expanded. A significant addition is an objective related to integrating systems and data with third parties.
This post is a part of a series showing all the SYO-401 differences compared to the SY0-301 exam. Here are links to all the pages in the series:
- SY0-401 Differences in Domains
- SY0-401 Differences in Network Security
- SY0-401 Differences in Compliance and Operational Security
- SY0-401 Differences in Threats and Vulnerabilities
- SY0-401 Differences in Application, Data and Host Security
- SY0-401 Differences in Access Control and Identity Management
- SY0-401 Differences in Cryptography
- SY0-401 Differences in Acronyms
SY0-301 Available Until December 31, 2014
Remember, you can still take the SY0-301 exam up until December 31, 2014.
Hiring managers rarely care what version of Security+ you have. They only want to know you are Security+ certified. Unless you want to be on the bleeding edge of this certification, you don’t need to pursue the 401 version.
At this writing, there is a limited amount of material available for the 401 version. However, there is plenty of study material available for the 301 version. Many people tell me they take and pass the Security+ exam within 30 days after getting this book: CompTIA Security+: Get Certified Get Ahead: SY0-301 Study Guide. Even if it takes you a little longer, you’ll still have plenty of time to get the certification before December 31, 2014.
CompTIA Security+: Get Certified Get Ahead: SY0-401 Study Guide is now available.
SY0-401 Differences in Risk Related Concepts
This objective has a minor change in the wording expecting you to focus on the importance of risk related concepts.
SY0-301 | SY0-401 |
Explain risk related concepts | Explain the importance of risk related concepts. |
CompTIA has added some new items in this objective, though they were either in other areas of the SY0-301 objectives, or implied by existing objectives. For example, False negatives is a new bullet but it was implied with the existing False positives in the previous version.
Under Risk calculations, SLE and ARO are new bullets but they were in the acronym list and you needed to understand them in order to calculate the ALE.
MTTR and MTBF are also added here, but they were in the same objective in the previous exam. The difference is that they were spelled out as Mean time to restore and mean time between failures.
Last, Recovery time objective and recovery point objective is added in this objective, but it was in a different objective in this section in the previous exam. The only completely new item is MTTF.
Master Security+ Performance Based Questions Video
SY0-401 Differences in Third Party Issues
This objective is completely new and doesn’t match an objective in the previous exam.
SY0-301 | SY0-401 |
Summarize the security implications of integrating systems and data with third parties. |
It includes the following objectives:
- On-boarding/off-boarding business partners
- Social media networks and/or applications
- Interoperability agreements
- SLA
- BPA
- MOU
- ISA
- Privacy considerations
- Risk awareness
- Unauthorized data sharing
- Data ownership
- Data backups
- Follow security policy and procedures
- Review agreement requirements to verify compliance and performance standards
While some of the topics were implied or covered in the previous version, you’ll need to understand them within the context of third parties in the 401 exam.
SY0-401 Differences in Risk Mitigation
The wording of this objective is worded slightly different but the meaning is primarily the same.
SY0-301 | SY0-401 |
Carry out appropriate risk mitigation strategies | Given a scenario, implement appropriate risk mitigation strategies. |
One item, Implement security controls based on risk, was removed from this objective. However, security controls are included in several objectives. Another item was slightly modified:
- 301: Implement policies and procedures to prevent data loss or theft
- 401: Enforce policies and procedures to prevent data loss or theft
Last the following bullets were added here, though DLP was included in the previous version:
- Enforce technology controls
- Data Loss Prevention (DLP)
SY0-401 Differences in Basic Forensic Procedures
Incident response was a single objective in the previous version but CompTIA separated it into two objectives in the current version. The first objective addresses forensic procedures. The wording of the first objective is slightly modified but execute and implement mean basically the same thing.
SY0-301 | SY0-401 |
Execute appropriate incident response procedures | Given a scenario, implement basic forensic procedures. |
Several items were moved into the next objective. However, one new item that is important to recognize is Big Data analysis.
SY0-401 Differences in Incident Response
The wording of the following objective was modified giving it less emphasis on incident response.
SY0-301 | SY0-401 |
Execute appropriate incident response procedures | Summarize common incident response procedures. |
While some of the items in this objective were in the previous objective, it’s worth listing them all due. I’ve highlighted the ones that are new.
- Summarize common incident response procedures.
- Preparation
- Incident identification
- Escalation and notification
- Mitigation steps
- Lessons learned
- Reporting
- Recovery/reconstitution procedures
- First responder
- Incident isolation
- Quarantine
- Device removal
- Data breach
- Damage and loss control
SY0-401 Differences in Awareness and Training
Here’s one of the few objectives that has the same wording.
SY0-301 | SY0-401 |
Explain the importance of security related awareness and training | Explain the importance of security related awareness and training. |
However, it does have the following new topics within it:
- Role-based training
- Follow up and gather training metrics to validate compliance and security posture
While Information classification was in the previous version, CompTIA added the following classification labels in the new version.
- High
- Medium
- Low
- Confidential
- Private
- Public
Also, Threat awareness was slightly modified to New threats and new security trends/alerts.
SY0-401 Differences in Physical Security and Environmental Controls
This objective combined topics from several other objectives in the previous exam. Instead of only including environmental controls, it also includes objectives related to Physical security and Control types.
SY0-301 | SY0-401 |
Explain the impact and proper use of environmental controls | Compare and contrast physical security and environmental controls. |
The Environmental controls bullet includes all of the original topics. However, the Video monitoring bullet was removed. Physical security is the next major topic in this section. It includes many topics from other objectives in the previous exam but adds the following new topics:
- Proper lighting
- Signs
- Guards
- Barricades
- Biometrics
- Protected distribution (cabling)
- Alarms
- Motion detection
Last, CompTIA chose to spell out the types of controls in the Control types topic.
- Deterrent
- Preventive
- Detective
- Compensating
- Technical
- Administrative
SY0-401 Differences in Risk Management Best Practices
This objective includes three topics: Business continuity concepts, Fault tolerance, and Disaster recovery concepts. It combines topics from two other objectives in the previous exam.
SY0-301 | SY0-401 |
Compare and contrast aspects of business continuity Execute disaster recovery plans and procedures | Summarize risk management best practices. |
The Business continuity concepts objective includes several familiar topics, but also adds the following new items:
- Identification of critical systems and components
- Risk assessment
- High availability
- Redundancy
- Tabletop exercises
The Fault tolerance bullet includes the same topics from the redundancy and fault tolerance bullet in the previous exam. Last, the Disaster recovery concepts objective includes many of the same objectives from the Execute disaster recovery plans and procedures objective. The single change is that backups are reworded as:
- Backup plans/policies
SY0-401 Differences in Confidentiality, Integrity, and Availability
The last objective in this domain was significantly reworded with several additions. It’s worth noting that confidentiality, integrity and availability are so integral to IT security that these topics were implied in the previous exam. However, CompTIA clearly spelled out what they’re expecting you to know.
SY0-301 | SY0-401 |
Exemplify the concepts of confidentiality, integrity and availability (CIA) | Given a scenario, select the appropriate control to meet the goals of security. |
The following bullets were added in this objective:
- Confidentiality
- Encryption
- Access controls
- Steganography
- Integrity
- Hashing
- Digital signatures
- Certificates
- Non-repudiation
- Availability
- Redundancy
- Fault tolerance
- Patching
- Safety
- Fencing
- Lighting
- Locks
- CCTV
- Escape plans
- Drills
- Escape routes
- Testing controls
SY0-401 Differences in Compliance and Operational Security Summary
This domain is weighted the same at 18% but it includes many changes. Most of the changes are just reorganization of the topics, but there are some new topics, such as integrating systems and data with third parties.