Cram Sheet · Exam Eve

Security+ SY0-701: Exam Eve Cram Sheet

Exam Fri, Jul 31, 2026 @ 11:30 AM · every flagged weak spot & missed point, one line each.

Domain 1 — General Security Concepts

Domain 2 — Threats, Vulnerabilities, Mitigations

Domain 3 — Security Architecture

CVSS Quick Reference

Ports: Most-Tested (Domain 4)

PortServicePortServicePortService
20/21FTP69TFTP445SMB
22SSH/SFTP/SCP80HTTP1433MS SQL
23Telnet88Kerberos3306MySQL
25SMTP110POP33389RDP
53DNS119NNTP5060/1SIP
67/68DHCP123NTP8080HTTP alt/proxy
135RPC137–139NetBIOS465/587SMTPS
143IMAP161/162SNMP514Syslog
389LDAP443HTTPS636LDAPS
993IMAPS995POP3S

Nmap Flags: Most-Tested (Domain 4.1)

FlagWhat it does
-sSTCP SYN scan, “stealth”/half-open, never completes the handshake, less likely to be logged
-sTTCP connect scan, full three-way handshake, noisier, used when SYN scan isn't available
-sUUDP scan, slower and less reliable than TCP scans
-sVService/version detection, identifies what's running on open ports
-OOS detection, fingerprints the target OS
-snPing scan, host discovery only, no port scan
-PnSkip host discovery, treats all hosts as up and scans anyway
-pPort spec, e.g. -p 1-1000, -p- for all 65535
-AAggressive scan, bundles OS detection + version detection + scripts + traceroute
-T0T5Timing template, paranoid to insane, lower is slower/stealthier

Domain 4 — Security Operations

Domain 5 — Security Program Management

Governance Frameworks

PBQ Traps & Exam Strategy

Security+ SY0-701: Exam Eve Cram Sheet — you know this. Sleep well.