The official Security+ SY0-701 acronym list has 200+ entries. You don’t need all 200. You need about 60 — the ones that actually appear on the exam in 80% of questions.

Here they are, ranked by exam frequency and grouped by domain. Came from the IG reel? Scroll to the list and start drilling.

Tier 1 — Memorize cold (the 30 that appear in every exam)

These show up in 60+% of questions. If you can’t recall any of these in under 5 seconds — both directions — keep studying.

AcronymExpansionDomainWhat it does
MFAMulti-Factor AuthenticationIdentitySomething you know + have + are
SSOSingle Sign-OnIdentityOne login → many apps
RBACRole-Based Access ControlIdentityPermissions tied to job role
ABACAttribute-Based Access ControlIdentityPermissions tied to attributes (location, time, etc.)
LDAPLightweight Directory Access ProtocolIdentityDirectory lookups (Active Directory uses it)
SAMLSecurity Assertion Markup LanguageIdentitySSO via XML between identity providers
OAuthOpen AuthorizationIdentityDelegated authorization for apps
MACMandatory Access ControlIdentityOS-enforced labels (Bell-LaPadula, Biba)
DACDiscretionary Access ControlIdentityOwner sets permissions
AESAdvanced Encryption StandardCryptoSymmetric encryption (256-bit standard)
RSARivest-Shamir-AdlemanCryptoAsymmetric encryption + signatures
PKIPublic Key InfrastructureCryptoThe whole certificate trust chain
CACertificate AuthorityCryptoIssues digital certificates
CRLCertificate Revocation ListCryptoList of revoked certificates
OCSPOnline Certificate Status ProtocolCryptoReal-time cert revocation check
TLSTransport Layer SecurityCryptoThe modern replacement for SSL
HMACHash-based Message Authentication CodeCryptoHash + secret key = integrity proof
VPNVirtual Private NetworkNetworkEncrypted tunnel
IPSIntrusion Prevention SystemNetworkDetects AND blocks attacks
IDSIntrusion Detection SystemNetworkDetects attacks, alerts only
DLPData Loss PreventionNetworkStops sensitive data exfiltration
WAFWeb Application FirewallNetworkLayer-7 firewall for web apps
NACNetwork Access ControlNetworkPosture-check devices before LAN access
SIEMSecurity Information and Event ManagementOperationsLog aggregation + correlation
SOARSecurity Orchestration, Automation, ResponseOperationsAutomated incident workflows
EDREndpoint Detection and ResponseOperationsModern endpoint security
XDRExtended Detection and ResponseOperationsEDR + network + cloud telemetry
APTAdvanced Persistent ThreatThreatsNation-state or organized criminal actor
DDoSDistributed Denial of ServiceThreatsOverwhelm a service with traffic
CVECommon Vulnerabilities and ExposuresThreatsThe canonical vulnerability ID system

Tier 2 — Recognize on sight (another 30 you should know)

These appear in 15–30% of questions. You should recognize them, even if recall is slower.

AcronymExpansionNotes
PIIPersonally Identifiable InformationWhat HIPAA/PCI/GDPR all care about
PHIProtected Health InformationHIPAA-specific
PCI-DSSPayment Card Industry Data Security StandardCredit card data protection
HIPAAHealth Insurance Portability and Accountability ActUS healthcare regulation
GDPRGeneral Data Protection RegulationEU privacy regulation
SOCSecurity Operations Center / System and Organization ControlsTwo meanings — context matters
SOC 2Service Organization Control 2SaaS security audit framework
NISTNational Institute of Standards and TechnologyPublishes US security standards
ISO 27001International Org for Standardization 27001International security management standard
CIAConfidentiality, Integrity, AvailabilityThe security triad
AAAAuthentication, Authorization, AccountingThe access-control triad
MITMMan-in-the-MiddleInterception attack
XSSCross-Site ScriptingInjecting JS into a vulnerable site
SQLiSQL InjectionInjecting SQL into a vulnerable input
CSRFCross-Site Request ForgeryTrick a logged-in user into an action
RCERemote Code ExecutionRun code on a target system
DKIMDomainKeys Identified MailEmail authentication via signing
SPFSender Policy FrameworkEmail anti-spoofing
DMARCDomain-based Message Authentication, Reporting, and ConformanceEmail policy combining SPF + DKIM
MDMMobile Device ManagementManaging phones/tablets at scale
BYODBring Your Own DeviceLetting personal devices on corp network
CASBCloud Access Security BrokerVisibility/control for cloud apps
ZTNAZero Trust Network AccessModern replacement for VPN
SASESecure Access Service EdgeCloud-delivered security + networking
IAMIdentity and Access ManagementThe whole identity discipline
PAMPrivileged Access ManagementSpecial vault for admin accounts
HSMHardware Security ModuleTamper-resistant key storage
TPMTrusted Platform ModuleChip on the motherboard that stores keys
UEFIUnified Extensible Firmware InterfaceModern BIOS replacement
SBOMSoftware Bill of MaterialsInventory of components in a software product

The pairs that get confused most

The single biggest source of acronym-question mistakes is the paired terms. Drill these specifically — practice “when do you use X vs Y” for each pair:

PairThe distinction
DLP vs DRMDLP stops data from leaving the org. DRM controls how a recipient uses data after they get it.
IDS vs IPSIDS detects + alerts. IPS detects + blocks. IPS is inline; IDS is passive.
SSO vs MFASSO reduces the number of logins. MFA strengthens each login. They’re complementary, not competitors.
RBAC vs ABACRBAC = permissions per role (admin, user, auditor). ABAC = permissions per attribute (location, time, device posture).
EDR vs XDREDR sees just endpoints. XDR correlates endpoints + network + cloud.
SIEM vs SOARSIEM collects + correlates logs. SOAR automates the response.
AAA vs CIAAAA = access control (Authentication, Authorization, Accounting). CIA = security goals (Confidentiality, Integrity, Availability).
CRL vs OCSPCRL is a downloadable list. OCSP is a real-time query. OCSP is the modern approach; CRL is the fallback.
SPF vs DKIM vs DMARCSPF says “this IP is allowed to send for this domain.” DKIM signs the message. DMARC says what to do when SPF/DKIM fail.

The 10-minute daily drill

Two weeks to lock in 60 acronyms:

  1. Day 1–3: Tier 1 only. Both directions: acronym → expansion, expansion → acronym.
  2. Day 4–6: Tier 1 + Tier 2.
  3. Day 7–10: Tier 1 + 2 + the paired-confusion drill.
  4. Day 11–14: Full mixed deck, timed. 60 acronyms in under 5 minutes.

By day 14, the categories trigger the meanings automatically and you’re spotting acronym questions on sight during the exam.

Practice as flashcards (free)

🛡️ Studying for CompTIA Security+?

Practice with free flashcards, crypto-decoder drills, and exam-style scenarios at secplus.it-learn.io — aligned to the current SY0-701 objectives. Free with a quick signup.

The flashcard deck on secplus.it-learn.io is keyed off this exact list — same 60 acronyms, same grouping, same paired-confusion drill. Drill 10 minutes a day for two weeks and the acronym questions on SY0-701 become reflex.

🎯 Studying for any IT cert?

All the free cert-study tools — Network+, Security+, CCIE Security, CHFI, ECIH — live at study.it-learn.io. Flashcards, quizzes, calculators, mnemonics. Free with a quick signup.