Course · $400 Free reference Certifications

Security+ acronyms, decoded

The high-frequency acronyms CompTIA Security+ expects you to recognize instantly — grouped by theme, with a one-line meaning each.

Advertisement · 728×90

Core security concepts

AcronymMeaning
CIAConfidentiality, Integrity, Availability — the security triad
AAAAuthentication, Authorization, Accounting
MFAMulti-Factor Authentication
SSOSingle Sign-On
RBACRole-Based Access Control
PoLPPrinciple of Least Privilege

Cryptography & PKI

AcronymMeaning
PKIPublic Key Infrastructure
CACertificate Authority
TLSTransport Layer Security (replaces SSL)
HSMHardware Security Module
MACMessage Authentication Code (also Mandatory Access Control)

Defenses & monitoring

AcronymMeaning
IDS / IPSIntrusion Detection / Prevention System
SIEMSecurity Information and Event Management
DLPData Loss Prevention
WAFWeb Application Firewall
EDREndpoint Detection and Response
SOCSecurity Operations Center

Threats & attacks

AcronymMeaning
MITMMan-in-the-Middle attack
DDoSDistributed Denial of Service
XSSCross-Site Scripting
CSRFCross-Site Request Forgery
RCERemote Code Execution
APTAdvanced Persistent Threat

Test yourself

4 quick questions — tap an answer to check it instantly. Nothing is sent anywhere.

1. CIA in security stands for…

Answer: B. The CIA triad = Confidentiality, Integrity, Availability.

2. AAA stands for…

Answer: A. AAA = Authentication, Authorization, Accounting.

3. A SIEM is used to…

Answer: B. SIEM = Security Information and Event Management — log aggregation and analysis.

4. Which can block an attack inline, not just alert?

Answer: B. An IPS can block inline; an IDS only detects and alerts.

Sources

  1. CompTIA Network+ / Security+ exam objectives.
  2. Relevant RFCs and vendor documentation.

Reference summary only.