Security+ acronyms quiz

The Security+ SY0-701 exam leans hard on acronyms. This endless drill covers all 307 on CompTIA's list, both directions — expand the acronym, or name it from its meaning. Answer with the number keys. No signup, no limit.

Loading the drill…

The full Security+ acronym list

AcronymExpansion
AAAAuthentication, Authorization, and Accounting
ABACAttribute-Based Access Control
ACLAccess Control List
AESAdvanced Encryption Standard
AHAuthentication Header
AIArtificial Intelligence
AISAutomated Indicator Sharing
ALEAnnualized Loss Expectancy
APAccess Point
APIApplication Programming Interface
APTAdvanced Persistent Threat
AROAnnualized Rate of Occurrence
ARPAddress Resolution Protocol
ASLRAddress Space Layout Randomization
ATT&CKAdversarial Tactics, Techniques, and Common Knowledge
AUPAcceptable Use Policy
AVAntivirus
BASHBourne Again Shell
BCPBusiness Continuity Planning
BGPBorder Gateway Protocol
BIABusiness Impact Analysis
BIOSBasic Input/Output System
BPABusiness Partners Agreement
BPDUBridge Protocol Data Unit
BYODBring Your Own Device
CACertificate Authority
CAPTCHACompletely Automated Public Turing Test to Tell Computers and Humans Apart
CARCorrective Action Report
CASBCloud Access Security Broker
CBCCipher Block Chaining
CCMPCounter Mode/CBC-MAC Protocol
CCTVClosed-Circuit Television
CERTComputer Emergency Response Team
CFBCipher Feedback
CHAPChallenge Handshake Authentication Protocol
CIAConfidentiality, Integrity, and Availability
CIOChief Information Officer
CIRTComputer Incident Response Team
CMSContent Management System
COOPContinuity of Operations Planning
COPECorporate-Owned, Personally Enabled
CPContingency Planning
CRCCyclic Redundancy Check
CRLCertificate Revocation List
CSOChief Security Officer
CSPCloud Service Provider
CSRCertificate Signing Request
CSRFCross-Site Request Forgery
CSUChannel Service Unit
CTMCounter Mode
CTOChief Technology Officer
CVECommon Vulnerabilities and Exposures
CVSSCommon Vulnerability Scoring System
CYODChoose Your Own Device
DACDiscretionary Access Control
DBADatabase Administrator
DDoSDistributed Denial-of-Service
DEPData Execution Prevention
DESData Encryption Standard
DHCPDynamic Host Configuration Protocol
DHEDiffie-Hellman Ephemeral
DKIMDomainKeys Identified Mail
DLLDynamic-Link Library
DLPData Loss Prevention
DMARCDomain-based Message Authentication Reporting and Conformance
DNATDestination Network Address Translation
DNSDomain Name System
DoSDenial-of-Service
DPOData Protection Officer
DRPDisaster Recovery Plan
DSADigital Signature Algorithm
EAPExtensible Authentication Protocol
ECBElectronic Codebook
ECCElliptic Curve Cryptography
ECDHEElliptic Curve Diffie-Hellman Ephemeral
ECDSAElliptic Curve Digital Signature Algorithm
EDREndpoint Detection and Response
EFSEncrypting File System
ERPEnterprise Resource Planning
ESNElectronic Serial Number
ESPEncapsulating Security Payload
FACLFile System Access Control List
FDEFull Disk Encryption
FIMFile Integrity Monitoring
FPGAField Programmable Gate Array
FRRFalse Rejection Rate
FTPFile Transfer Protocol
FTPSFile Transfer Protocol Secure
GCMGalois/Counter Mode
GDPRGeneral Data Protection Regulation
GPGGNU Privacy Guard
GPOGroup Policy Object
GPSGlobal Positioning System
GPUGraphics Processing Unit
GREGeneric Routing Encapsulation
HAHigh Availability
HDDHard Disk Drive
HIDSHost-based Intrusion Detection System
HIPSHost-based Intrusion Prevention System
HMACHash-based Message Authentication Code
HOTPHMAC-based One-Time Password
HSMHardware Security Module
HTMLHypertext Markup Language
HTTPHypertext Transfer Protocol
HTTPSHypertext Transfer Protocol Secure
HVACHeating, Ventilation, and Air Conditioning
IaaSInfrastructure as a Service
IaCInfrastructure as Code
IAMIdentity and Access Management
ICMPInternet Control Message Protocol
ICSIndustrial Control Systems
IDFIntermediate Distribution Frame
IDSIntrusion Detection System
IdPIdentity Provider
IEEEInstitute of Electrical and Electronics Engineers
IKEInternet Key Exchange
IMInstant Messaging
IMAPInternet Message Access Protocol
IoCIndicators of Compromise
IoTInternet of Things
IPInternet Protocol
IPSIntrusion Prevention System
IPSecInternet Protocol Security
IRIncident Response
IRCInternet Relay Chat
IRPIncident Response Plan
ISOInternational Organization for Standardization
ISPInternet Service Provider
ISSOInformation Systems Security Officer
IVInitialization Vector
KDCKey Distribution Center
KEKKey Encryption Key
L2TPLayer 2 Tunneling Protocol
LANLocal Area Network
LDAPLightweight Directory Access Protocol
LEAPLightweight Extensible Authentication Protocol
MaaSMonitoring as a Service
MACMandatory Access Control
MAMMobile Application Management
MANMetropolitan Area Network
MBRMaster Boot Record
MD5Message Digest 5
MDFMain Distribution Frame
MDMMobile Device Management
MFAMultifactor Authentication
MFDMultifunction Device
MFPMultifunction Printer
MLMachine Learning
MMSMultimedia Message Service
MOAMemorandum of Agreement
MOUMemorandum of Understanding
MPLSMultiprotocol Label Switching
MSAMaster Service Agreement
MSCHAPMicrosoft Challenge Handshake Authentication Protocol
MSPManaged Service Provider
MSSPManaged Security Service Provider
MTBFMean Time Between Failures
MTTFMean Time to Failure
MTTRMean Time to Repair
MTUMaximum Transmission Unit
NACNetwork Access Control
NATNetwork Address Translation
NDANon-Disclosure Agreement
NFCNear Field Communication
NGFWNext-Generation Firewall
NIDSNetwork-based Intrusion Detection System
NIPSNetwork-based Intrusion Prevention System
NISTNational Institute of Standards and Technology
NTFSNew Technology File System
NTLMNew Technology LAN Manager
NTPNetwork Time Protocol
OAuthOpen Authorization
OCSPOnline Certificate Status Protocol
OIDObject Identifier
OSOperating System
OSINTOpen-Source Intelligence
OSPFOpen Shortest Path First
OTOperational Technology
OTAOver-the-Air
OVALOpen Vulnerability and Assessment Language
P2PPeer-to-Peer
PaaSPlatform as a Service
PACProxy Auto Configuration
PAMPrivileged Access Management
PAPPassword Authentication Protocol
PATPort Address Translation
PBKDF2Password-Based Key Derivation Function 2
PCAPPacket Capture
PCI DSSPayment Card Industry Data Security Standard
PDUPower Distribution Unit
PEAPProtected Extensible Authentication Protocol
PEDPersonal Electronic Device
PEMPrivacy Enhanced Mail
PFSPerfect Forward Secrecy
PGPPretty Good Privacy
PHIProtected Health Information
PIIPersonally Identifiable Information
PIVPersonal Identity Verification
PKCSPublic Key Cryptography Standards
PKIPublic Key Infrastructure
POPPost Office Protocol
POTSPlain Old Telephone Service
PPPPoint-to-Point Protocol
PPTPPoint-to-Point Tunneling Protocol
PSKPre-Shared Key
PTZPan-Tilt-Zoom
PUPPotentially Unwanted Program
RARegistration Authority
RADIUSRemote Authentication Dial-in User Service
RAIDRedundant Array of Inexpensive Disks
RASRemote Access Server
RATRemote Access Trojan
RBACRole-Based Access Control
RC4Rivest Cipher 4
RDPRemote Desktop Protocol
RFIDRadio Frequency Identification
RIPEMDRACE Integrity Primitives Evaluation Message Digest
ROIReturn on Investment
RPORecovery Point Objective
RSARivest, Shamir, Adleman
RTBHRemotely Triggered Black Hole
RTORecovery Time Objective
RTOSReal-Time Operating System
RTPReal-Time Transport Protocol
S/MIMESecure/Multipurpose Internet Mail Extensions
SaaSSoftware as a Service
SAESimultaneous Authentication of Equals
SAMLSecurity Assertion Markup Language
SANSubject Alternative Name
SASESecure Access Service Edge
SCADASupervisory Control and Data Acquisition
SCAPSecurity Content Automation Protocol
SCEPSimple Certificate Enrollment Protocol
SD-WANSoftware-Defined Wide Area Network
SDKSoftware Development Kit
SDLCSoftware Development Life Cycle
SDNSoftware-Defined Networking
SEDSelf-Encrypting Drive
SEHStructured Exception Handling
SFTPSecure File Transfer Protocol
SHASecure Hash Algorithm
SIEMSecurity Information and Event Management
SIMSubscriber Identity Module
SLAService Level Agreement
SLESingle Loss Expectancy
SMSShort Message Service
SMTPSimple Mail Transfer Protocol
SMTPSSimple Mail Transfer Protocol Secure
SNMPSimple Network Management Protocol
SOAPSimple Object Access Protocol
SOARSecurity Orchestration, Automation, and Response
SoCSystem on Chip
SOCSecurity Operations Center
SOWStatement of Work
SPFSender Policy Framework
SPIMSpam over Instant Messaging
SQLStructured Query Language
SQLiSQL Injection
SRTPSecure Real-Time Transport Protocol
SSDSolid State Drive
SSHSecure Shell
SSLSecure Sockets Layer
SSOSingle Sign-On
STIXStructured Threat Information eXpression
STPSpanning Tree Protocol
SWGSecure Web Gateway
TACACS+Terminal Access Controller Access Control System Plus
TAXIITrusted Automated eXchange of Indicator Information
TCP/IPTransmission Control Protocol/Internet Protocol
TGTTicket Granting Ticket
TKIPTemporal Key Integrity Protocol
TLSTransport Layer Security
TOTPTime-based One-Time Password
TPMTrusted Platform Module
TTPTactics, Techniques, and Procedures
UATUser Acceptance Testing
UAVUnmanned Aerial Vehicle
UDPUser Datagram Protocol
UEFIUnified Extensible Firmware Interface
UEMUnified Endpoint Management
UPSUninterruptible Power Supply
URIUniform Resource Identifier
URLUniform Resource Locator
USBUniversal Serial Bus
USB OTGUSB On-the-Go
UTMUnified Threat Management
VBAVisual Basic for Applications
VDIVirtual Desktop Infrastructure
VLANVirtual Local Area Network
VLSMVariable-Length Subnet Masking
VMVirtual Machine
VoIPVoice over Internet Protocol
VPCVirtual Private Cloud
VPNVirtual Private Network
VTCVideo Teleconferencing
WAFWeb Application Firewall
WAPWireless Access Point
WEPWired Equivalent Privacy
WIDSWireless Intrusion Detection System
WIPSWireless Intrusion Prevention System
WPAWi-Fi Protected Access
WPSWi-Fi Protected Setup
WTLSWireless Transport Layer Security
XDRExtended Detection and Response
XMLExtensible Markup Language
XORExclusive OR
XSSCross-Site Scripting

Acronyms are the easy part

The rest of the exam is scenarios and PBQs. Take the free 25-question diagnostic to see how ready you actually are — and get a daily plan for everything else.

Take the free diagnostic

Frequently asked questions

How many acronyms are on the Security+ SY0-701 exam?

CompTIA's official objectives list around 307 acronyms — from the everyday (CIA, AAA, MFA, PKI) to the obscure (SASE, TAXII, OVAL). This quiz drills the full set in both directions: expand the acronym, and name the acronym from its meaning.

What's the best way to memorize Security+ acronyms?

Short, frequent drills beat one long cram. Do 15–20 here every day and let spaced repetition surface the ones you keep missing right before you'd forget them. Focus on the high-frequency families — access control (DAC/MAC/RBAC/ABAC), the AAA protocols (RADIUS/TACACS+), and the detection stack (IDS/IPS/EDR/XDR/SIEM/SOAR).

Do I need to know every acronym for the exam?

You won't be asked to define all of them, but the exam uses acronyms constantly in both questions and answer choices — recognizing them cold saves time and prevents avoidable mistakes. The high-frequency ones (CIA, PKI, MFA, EDR, SIEM, SOAR, IAM) show up everywhere.