Security+ acronyms quiz
The Security+ SY0-701 exam leans hard on acronyms. This endless drill covers all 307 on CompTIA's list, both directions — expand the acronym, or name it from its meaning. Answer with the number keys. No signup, no limit.
The full Security+ acronym list
| Acronym | Expansion | Category |
|---|---|---|
| AAA | Authentication, Authorization, and Accounting | Identity & Access |
| ABAC | Attribute-Based Access Control | Identity & Access |
| ACL | Access Control List | Identity & Access |
| AES | Advanced Encryption Standard | Cryptography |
| AH | Authentication Header | Network |
| AI | Artificial Intelligence | General |
| AIS | Automated Indicator Sharing | Threats & Attacks |
| ALE | Annualized Loss Expectancy | Governance & Risk |
| AP | Access Point | Wireless |
| API | Application Programming Interface | General |
| APT | Advanced Persistent Threat | Threats & Attacks |
| ARO | Annualized Rate of Occurrence | Governance & Risk |
| ARP | Address Resolution Protocol | Network |
| ASLR | Address Space Layout Randomization | Security Operations |
| ATT&CK | Adversarial Tactics, Techniques, and Common Knowledge | Threats & Attacks |
| AUP | Acceptable Use Policy | Governance & Risk |
| AV | Antivirus | Security Operations |
| BASH | Bourne Again Shell | Security Operations |
| BCP | Business Continuity Planning | Governance & Risk |
| BGP | Border Gateway Protocol | Network |
| BIA | Business Impact Analysis | Governance & Risk |
| BIOS | Basic Input/Output System | Hardware & Endpoint |
| BPA | Business Partners Agreement | Governance & Risk |
| BPDU | Bridge Protocol Data Unit | Network |
| BYOD | Bring Your Own Device | Mobile |
| CA | Certificate Authority | Cryptography |
| CAPTCHA | Completely Automated Public Turing Test to Tell Computers and Humans Apart | Identity & Access |
| CAR | Corrective Action Report | Security Operations |
| CASB | Cloud Access Security Broker | Cloud & Virtualization |
| CBC | Cipher Block Chaining | Cryptography |
| CCMP | Counter Mode/CBC-MAC Protocol | Wireless |
| CCTV | Closed-Circuit Television | Physical Security |
| CERT | Computer Emergency Response Team | Security Operations |
| CFB | Cipher Feedback | Cryptography |
| CHAP | Challenge Handshake Authentication Protocol | Identity & Access |
| CIA | Confidentiality, Integrity, and Availability | General |
| CIO | Chief Information Officer | Governance & Risk |
| CIRT | Computer Incident Response Team | Security Operations |
| CMS | Content Management System | General |
| COOP | Continuity of Operations Planning | Governance & Risk |
| COPE | Corporate-Owned, Personally Enabled | Mobile |
| CP | Contingency Planning | Governance & Risk |
| CRC | Cyclic Redundancy Check | Network |
| CRL | Certificate Revocation List | Cryptography |
| CSO | Chief Security Officer | Governance & Risk |
| CSP | Cloud Service Provider | Cloud & Virtualization |
| CSR | Certificate Signing Request | Cryptography |
| CSRF | Cross-Site Request Forgery | Threats & Attacks |
| CSU | Channel Service Unit | Network |
| CTM | Counter Mode | Cryptography |
| CTO | Chief Technology Officer | Governance & Risk |
| CVE | Common Vulnerabilities and Exposures | Threats & Attacks |
| CVSS | Common Vulnerability Scoring System | Threats & Attacks |
| CYOD | Choose Your Own Device | Mobile |
| DAC | Discretionary Access Control | Identity & Access |
| DBA | Database Administrator | General |
| DDoS | Distributed Denial-of-Service | Threats & Attacks |
| DEP | Data Execution Prevention | Security Operations |
| DES | Data Encryption Standard | Cryptography |
| DHCP | Dynamic Host Configuration Protocol | Network |
| DHE | Diffie-Hellman Ephemeral | Cryptography |
| DKIM | DomainKeys Identified Mail | Network |
| DLL | Dynamic-Link Library | Security Operations |
| DLP | Data Loss Prevention | Security Operations |
| DMARC | Domain-based Message Authentication Reporting and Conformance | Network |
| DNAT | Destination Network Address Translation | Network |
| DNS | Domain Name System | Network |
| DoS | Denial-of-Service | Threats & Attacks |
| DPO | Data Protection Officer | Governance & Risk |
| DRP | Disaster Recovery Plan | Governance & Risk |
| DSA | Digital Signature Algorithm | Cryptography |
| EAP | Extensible Authentication Protocol | Identity & Access |
| ECB | Electronic Codebook | Cryptography |
| ECC | Elliptic Curve Cryptography | Cryptography |
| ECDHE | Elliptic Curve Diffie-Hellman Ephemeral | Cryptography |
| ECDSA | Elliptic Curve Digital Signature Algorithm | Cryptography |
| EDR | Endpoint Detection and Response | Security Operations |
| EFS | Encrypting File System | Cryptography |
| ERP | Enterprise Resource Planning | General |
| ESN | Electronic Serial Number | Mobile |
| ESP | Encapsulating Security Payload | Network |
| FACL | File System Access Control List | Identity & Access |
| FDE | Full Disk Encryption | Cryptography |
| FIM | File Integrity Monitoring | Security Operations |
| FPGA | Field Programmable Gate Array | Hardware & Endpoint |
| FRR | False Rejection Rate | Identity & Access |
| FTP | File Transfer Protocol | Network |
| FTPS | File Transfer Protocol Secure | Network |
| GCM | Galois/Counter Mode | Cryptography |
| GDPR | General Data Protection Regulation | Governance & Risk |
| GPG | GNU Privacy Guard | Cryptography |
| GPO | Group Policy Object | Security Operations |
| GPS | Global Positioning System | Mobile |
| GPU | Graphics Processing Unit | Hardware & Endpoint |
| GRE | Generic Routing Encapsulation | Network |
| HA | High Availability | Security Operations |
| HDD | Hard Disk Drive | Hardware & Endpoint |
| HIDS | Host-based Intrusion Detection System | Security Operations |
| HIPS | Host-based Intrusion Prevention System | Security Operations |
| HMAC | Hash-based Message Authentication Code | Cryptography |
| HOTP | HMAC-based One-Time Password | Identity & Access |
| HSM | Hardware Security Module | Cryptography |
| HTML | Hypertext Markup Language | General |
| HTTP | Hypertext Transfer Protocol | Network |
| HTTPS | Hypertext Transfer Protocol Secure | Network |
| HVAC | Heating, Ventilation, and Air Conditioning | Physical Security |
| IaaS | Infrastructure as a Service | Cloud & Virtualization |
| IaC | Infrastructure as Code | Cloud & Virtualization |
| IAM | Identity and Access Management | Identity & Access |
| ICMP | Internet Control Message Protocol | Network |
| ICS | Industrial Control Systems | Security Operations |
| IDF | Intermediate Distribution Frame | Physical Security |
| IDS | Intrusion Detection System | Security Operations |
| IdP | Identity Provider | Identity & Access |
| IEEE | Institute of Electrical and Electronics Engineers | General |
| IKE | Internet Key Exchange | Network |
| IM | Instant Messaging | General |
| IMAP | Internet Message Access Protocol | Network |
| IoC | Indicators of Compromise | Threats & Attacks |
| IoT | Internet of Things | Security Operations |
| IP | Internet Protocol | Network |
| IPS | Intrusion Prevention System | Security Operations |
| IPSec | Internet Protocol Security | Network |
| IR | Incident Response | Security Operations |
| IRC | Internet Relay Chat | Threats & Attacks |
| IRP | Incident Response Plan | Security Operations |
| ISO | International Organization for Standardization | Governance & Risk |
| ISP | Internet Service Provider | Network |
| ISSO | Information Systems Security Officer | Governance & Risk |
| IV | Initialization Vector | Cryptography |
| KDC | Key Distribution Center | Identity & Access |
| KEK | Key Encryption Key | Cryptography |
| L2TP | Layer 2 Tunneling Protocol | Network |
| LAN | Local Area Network | Network |
| LDAP | Lightweight Directory Access Protocol | Identity & Access |
| LEAP | Lightweight Extensible Authentication Protocol | Wireless |
| MaaS | Monitoring as a Service | Cloud & Virtualization |
| MAC | Mandatory Access Control | Identity & Access |
| MAM | Mobile Application Management | Mobile |
| MAN | Metropolitan Area Network | Network |
| MBR | Master Boot Record | Hardware & Endpoint |
| MD5 | Message Digest 5 | Cryptography |
| MDF | Main Distribution Frame | Physical Security |
| MDM | Mobile Device Management | Mobile |
| MFA | Multifactor Authentication | Identity & Access |
| MFD | Multifunction Device | Hardware & Endpoint |
| MFP | Multifunction Printer | Hardware & Endpoint |
| ML | Machine Learning | General |
| MMS | Multimedia Message Service | Mobile |
| MOA | Memorandum of Agreement | Governance & Risk |
| MOU | Memorandum of Understanding | Governance & Risk |
| MPLS | Multiprotocol Label Switching | Network |
| MSA | Master Service Agreement | Governance & Risk |
| MSCHAP | Microsoft Challenge Handshake Authentication Protocol | Identity & Access |
| MSP | Managed Service Provider | Security Operations |
| MSSP | Managed Security Service Provider | Security Operations |
| MTBF | Mean Time Between Failures | Governance & Risk |
| MTTF | Mean Time to Failure | Governance & Risk |
| MTTR | Mean Time to Repair | Governance & Risk |
| MTU | Maximum Transmission Unit | Network |
| NAC | Network Access Control | Network |
| NAT | Network Address Translation | Network |
| NDA | Non-Disclosure Agreement | Governance & Risk |
| NFC | Near Field Communication | Mobile |
| NGFW | Next-Generation Firewall | Network |
| NIDS | Network-based Intrusion Detection System | Security Operations |
| NIPS | Network-based Intrusion Prevention System | Security Operations |
| NIST | National Institute of Standards and Technology | Governance & Risk |
| NTFS | New Technology File System | Hardware & Endpoint |
| NTLM | New Technology LAN Manager | Identity & Access |
| NTP | Network Time Protocol | Network |
| OAuth | Open Authorization | Identity & Access |
| OCSP | Online Certificate Status Protocol | Cryptography |
| OID | Object Identifier | Cryptography |
| OS | Operating System | Hardware & Endpoint |
| OSINT | Open-Source Intelligence | Threats & Attacks |
| OSPF | Open Shortest Path First | Network |
| OT | Operational Technology | Security Operations |
| OTA | Over-the-Air | Mobile |
| OVAL | Open Vulnerability and Assessment Language | Threats & Attacks |
| P2P | Peer-to-Peer | Network |
| PaaS | Platform as a Service | Cloud & Virtualization |
| PAC | Proxy Auto Configuration | Network |
| PAM | Privileged Access Management | Identity & Access |
| PAP | Password Authentication Protocol | Identity & Access |
| PAT | Port Address Translation | Network |
| PBKDF2 | Password-Based Key Derivation Function 2 | Cryptography |
| PCAP | Packet Capture | Security Operations |
| PCI DSS | Payment Card Industry Data Security Standard | Governance & Risk |
| PDU | Power Distribution Unit | Physical Security |
| PEAP | Protected Extensible Authentication Protocol | Wireless |
| PED | Personal Electronic Device | Mobile |
| PEM | Privacy Enhanced Mail | Cryptography |
| PFS | Perfect Forward Secrecy | Cryptography |
| PGP | Pretty Good Privacy | Cryptography |
| PHI | Protected Health Information | Governance & Risk |
| PII | Personally Identifiable Information | Governance & Risk |
| PIV | Personal Identity Verification | Identity & Access |
| PKCS | Public Key Cryptography Standards | Cryptography |
| PKI | Public Key Infrastructure | Cryptography |
| POP | Post Office Protocol | Network |
| POTS | Plain Old Telephone Service | Network |
| PPP | Point-to-Point Protocol | Network |
| PPTP | Point-to-Point Tunneling Protocol | Network |
| PSK | Pre-Shared Key | Wireless |
| PTZ | Pan-Tilt-Zoom | Physical Security |
| PUP | Potentially Unwanted Program | Threats & Attacks |
| RA | Registration Authority | Cryptography |
| RADIUS | Remote Authentication Dial-in User Service | Identity & Access |
| RAID | Redundant Array of Inexpensive Disks | Hardware & Endpoint |
| RAS | Remote Access Server | Network |
| RAT | Remote Access Trojan | Threats & Attacks |
| RBAC | Role-Based Access Control | Identity & Access |
| RC4 | Rivest Cipher 4 | Cryptography |
| RDP | Remote Desktop Protocol | Network |
| RFID | Radio Frequency Identification | Physical Security |
| RIPEMD | RACE Integrity Primitives Evaluation Message Digest | Cryptography |
| ROI | Return on Investment | Governance & Risk |
| RPO | Recovery Point Objective | Governance & Risk |
| RSA | Rivest, Shamir, Adleman | Cryptography |
| RTBH | Remotely Triggered Black Hole | Network |
| RTO | Recovery Time Objective | Governance & Risk |
| RTOS | Real-Time Operating System | Hardware & Endpoint |
| RTP | Real-Time Transport Protocol | Network |
| S/MIME | Secure/Multipurpose Internet Mail Extensions | Cryptography |
| SaaS | Software as a Service | Cloud & Virtualization |
| SAE | Simultaneous Authentication of Equals | Wireless |
| SAML | Security Assertion Markup Language | Identity & Access |
| SAN | Subject Alternative Name | Cryptography |
| SASE | Secure Access Service Edge | Cloud & Virtualization |
| SCADA | Supervisory Control and Data Acquisition | Security Operations |
| SCAP | Security Content Automation Protocol | Security Operations |
| SCEP | Simple Certificate Enrollment Protocol | Cryptography |
| SD-WAN | Software-Defined Wide Area Network | Network |
| SDK | Software Development Kit | General |
| SDLC | Software Development Life Cycle | General |
| SDN | Software-Defined Networking | Network |
| SED | Self-Encrypting Drive | Cryptography |
| SEH | Structured Exception Handling | Security Operations |
| SFTP | Secure File Transfer Protocol | Network |
| SHA | Secure Hash Algorithm | Cryptography |
| SIEM | Security Information and Event Management | Security Operations |
| SIM | Subscriber Identity Module | Mobile |
| SLA | Service Level Agreement | Governance & Risk |
| SLE | Single Loss Expectancy | Governance & Risk |
| SMS | Short Message Service | Mobile |
| SMTP | Simple Mail Transfer Protocol | Network |
| SMTPS | Simple Mail Transfer Protocol Secure | Network |
| SNMP | Simple Network Management Protocol | Network |
| SOAP | Simple Object Access Protocol | General |
| SOAR | Security Orchestration, Automation, and Response | Security Operations |
| SoC | System on Chip | Hardware & Endpoint |
| SOC | Security Operations Center | Security Operations |
| SOW | Statement of Work | Governance & Risk |
| SPF | Sender Policy Framework | Network |
| SPIM | Spam over Instant Messaging | Threats & Attacks |
| SQL | Structured Query Language | General |
| SQLi | SQL Injection | Threats & Attacks |
| SRTP | Secure Real-Time Transport Protocol | Network |
| SSD | Solid State Drive | Hardware & Endpoint |
| SSH | Secure Shell | Network |
| SSL | Secure Sockets Layer | Cryptography |
| SSO | Single Sign-On | Identity & Access |
| STIX | Structured Threat Information eXpression | Threats & Attacks |
| STP | Spanning Tree Protocol | Network |
| SWG | Secure Web Gateway | Network |
| TACACS+ | Terminal Access Controller Access Control System Plus | Identity & Access |
| TAXII | Trusted Automated eXchange of Indicator Information | Threats & Attacks |
| TCP/IP | Transmission Control Protocol/Internet Protocol | Network |
| TGT | Ticket Granting Ticket | Identity & Access |
| TKIP | Temporal Key Integrity Protocol | Wireless |
| TLS | Transport Layer Security | Cryptography |
| TOTP | Time-based One-Time Password | Identity & Access |
| TPM | Trusted Platform Module | Cryptography |
| TTP | Tactics, Techniques, and Procedures | Threats & Attacks |
| UAT | User Acceptance Testing | General |
| UAV | Unmanned Aerial Vehicle | Physical Security |
| UDP | User Datagram Protocol | Network |
| UEFI | Unified Extensible Firmware Interface | Hardware & Endpoint |
| UEM | Unified Endpoint Management | Mobile |
| UPS | Uninterruptible Power Supply | Physical Security |
| URI | Uniform Resource Identifier | General |
| URL | Uniform Resource Locator | General |
| USB | Universal Serial Bus | Hardware & Endpoint |
| USB OTG | USB On-the-Go | Hardware & Endpoint |
| UTM | Unified Threat Management | Network |
| VBA | Visual Basic for Applications | Security Operations |
| VDI | Virtual Desktop Infrastructure | Cloud & Virtualization |
| VLAN | Virtual Local Area Network | Network |
| VLSM | Variable-Length Subnet Masking | Network |
| VM | Virtual Machine | Cloud & Virtualization |
| VoIP | Voice over Internet Protocol | Network |
| VPC | Virtual Private Cloud | Cloud & Virtualization |
| VPN | Virtual Private Network | Network |
| VTC | Video Teleconferencing | General |
| WAF | Web Application Firewall | Network |
| WAP | Wireless Access Point | Wireless |
| WEP | Wired Equivalent Privacy | Wireless |
| WIDS | Wireless Intrusion Detection System | Wireless |
| WIPS | Wireless Intrusion Prevention System | Wireless |
| WPA | Wi-Fi Protected Access | Wireless |
| WPS | Wi-Fi Protected Setup | Wireless |
| WTLS | Wireless Transport Layer Security | Wireless |
| XDR | Extended Detection and Response | Security Operations |
| XML | Extensible Markup Language | General |
| XOR | Exclusive OR | Cryptography |
| XSS | Cross-Site Scripting | Threats & Attacks |
Acronyms are the easy part
The rest of the exam is scenarios and PBQs. Take the free 25-question diagnostic to see how ready you actually are — and get a daily plan for everything else.
Take the free diagnosticFrequently asked questions
How many acronyms are on the Security+ SY0-701 exam?
CompTIA's official objectives list around 307 acronyms — from the everyday (CIA, AAA, MFA, PKI) to the obscure (SASE, TAXII, OVAL). This quiz drills the full set in both directions: expand the acronym, and name the acronym from its meaning.
What's the best way to memorize Security+ acronyms?
Short, frequent drills beat one long cram. Do 15–20 here every day and let spaced repetition surface the ones you keep missing right before you'd forget them. Focus on the high-frequency families — access control (DAC/MAC/RBAC/ABAC), the AAA protocols (RADIUS/TACACS+), and the detection stack (IDS/IPS/EDR/XDR/SIEM/SOAR).
Do I need to know every acronym for the exam?
You won't be asked to define all of them, but the exam uses acronyms constantly in both questions and answer choices — recognizing them cold saves time and prevents avoidable mistakes. The high-frequency ones (CIA, PKI, MFA, EDR, SIEM, SOAR, IAM) show up everywhere.