Welcome to Xavier's Institute for Security Excellence โ where mutant powers map to CompTIA Security+ SY0-701 domains. From Professor X's governance to Wolverine's penetration testing, all five domains are covered.
All five SY0-701 domains โ click to expand.
Objectives: 1.1 ยท 1.2 ยท 1.3 ยท 1.4
Objectives: 2.1 ยท 2.2 ยท 2.3 ยท 2.4 ยท 2.5
Objectives: 3.1 ยท 3.2 ยท 3.3 ยท 3.4
Objectives: 4.1โ4.9
Objectives: 5.1โ5.6
One mnemonic per domain. Click a domain โ others close automatically.
Security Controls ยท Types of controls ยท Open Public Ledger ยท Root of Trust ยท MFA
๐งช Quick Check:
Malware types ยท Attack vectors ยท Gap exploitation ยท Nation-state threats ยท Escalation of privilege ยท Threat actors ยท OSINT
๐งช Quick Check:
Xero Trust Architecture ยท Air-gap isolation ยท Virtualization ยท Infrastructure as Code ยท Encryption ยท Resilience & HA
๐งช Quick Check:
Chain of custody ยท Your IR plan ยท Continuous monitoring ยท Log analysis/SIEM ยท Orchestration (SOAR) ยท Pen testing ยท SSO/IAM
๐งช Quick Check:
Risk management ยท Oversight & governance ยท GDPR/HIPAA/PCI compliance ยท User awareness training ยท External audits
๐งช Quick Check:
Every X-Men '97 character represents a real security role.
X-Men '97 scenarios mapped to Security+ exam concepts.
The concepts most likely to appear on your SY0-701 exam.
SLE = Asset Value x Exposure Factor. $10M mansion x 40% EF = $4M SLE. ALE = SLE x ARO. Sentinels attack twice/year (ARO=2): ALE = $8M/year. ARO of 0.25 = once every 4 years. Know these formulas cold โ quantitative risk questions appear often.
Something you know: Xavier's mental password. Something you have: Cyclops's visor (hardware token). Something you are: Jean Grey's biometric brainwave scan. Somewhere you are: geolocation to X-Mansion. True MFA requires 2+ DIFFERENT factor types โ two passwords = single-factor.
Policy = high-level intent (mandatory). Standard = mandatory rules (specific requirements). Procedure = step-by-step how-to (mandatory). Guideline = recommended best practices (optional). Only policies, standards, and procedures are mandatory.
Asymmetric (PKI): Public key encrypts, private key decrypts. Slow but good for key exchange and digital signatures. Symmetric: Same key encrypts and decrypts. Fast โ great for bulk data encryption. In practice: asymmetric exchanges the symmetric key, then symmetric does the heavy lifting.
Preparation โ Detection โ Analysis โ Containment โ Eradication โ Recovery โ Lessons Learned. Xavier PREPARES. Cerebro DETECTS. Beast ANALYZES. Cyclops CONTAINS. Storm ERADICATES. Wolverine's healing = RECOVERY. Xavier writes LESSONS LEARNED.
Domain 4.8 โ The complete IR process with X-Men at each phase.
Domain 4.4 โ Security alerting, monitoring tools, and indicators of compromise.
SIEM aggregates logs from all sources, correlates events, and fires alerts. Like Cerebro detecting every mutant worldwide and flagging anomalies in real-time. Requires tuning to reduce false positives.
Threat feeds (OSINT, ISACs, dark web) provide intelligence about emerging threats before they hit. Jean proactively reads threat actors' minds โ exactly like threat intel feeds inform defenses before an attack.
Regular vulnerability scanning (CVE tracking, CVSS scoring) identifies weaknesses before attackers exploit them. Beast methodically catalogs every weakness and prioritizes fixes by impact score.
Account lockouts, impossible travel (NY and Tokyo in 1 hour), resource spikes, out-of-cycle logging, and missing logs all indicate compromise. These are Domain 2.4 exam targets โ know them all.
๐งช Detection Quick Check
Security governance roles โ Domain 5.1 exam targets.
๐งช Roles Quick Check
Internal and external reporting timelines โ these numbers appear on the exam.
Immediate: Alert SOC/CISO on detection. Ongoing: Status updates at defined intervals during active incidents. Post-incident: Full lessons-learned report within defined SLA (typically 72hโ30 days). Xavier gets a report after every mission.
GDPR: 72 hours to supervisory authority. HIPAA: 60 days (500+ individuals = HHS + media). PCI DSS: Immediately to card brands. SEC: 4 business days for material breaches. Know the timelines โ they appear on the exam.
Legal Hold: Preserve all relevant data when litigation is anticipated. Chain of Custody: Document every person who handles evidence. Order of Volatility: RAM first, then swap, then disk, then remote logs.
๐งช Reporting Quick Check
After the X-Men win โ lessons learned, metrics, and training updates.
Xavier gathers every X-Man for post-mission debrief. Document: timeline, detection, response actions, what worked, what failed, root cause, recommended changes. Conduct within 72 hours while details are fresh. This report drives playbook updates and defensive improvements.
MTTD โ Mean Time to Detect. MTTR โ Mean Time to Respond/Recover. MTBF โ Mean Time Between Failures. RTO โ Recovery Time Objective. RPO โ Recovery Point Objective. Track metrics across incidents to measure team improvement.
Every incident reveals training gaps. Update security awareness training, revise phishing simulation campaigns, conduct new tabletop exercises for similar scenarios. The Sentinel attack changed X-Man training protocols permanently โ turn pain into preparedness.
Guide the X-Men through a full IR lifecycle. Wrong answers say "Try again!" โ answer correctly to advance.
Cerebro is screaming. Dozens of Sentinel signatures converging on Genosha. Beast confirms: NOT a false positive โ attack is real. What is the FIRST correct action?
Sentinels have breached Genosha and are actively attacking. Cyclops must CONTAIN damage before it spreads to Xavier's School. What is the correct containment strategy?
Sentinels contained but their C2 signal is still active. Storm must eradicate the SOURCE. What defines proper eradication?
Sentinels gone. Recovery complete. Xavier assembles every X-Man. What MUST happen in Lessons Learned?
You guided the X-Men through all four IR phases:
Everything you need to pass the SY0-701.
65 cards covering all five exam domains. Progress saves automatically. โจ๏ธ Space=flip ยท 1=Again ยท 2=Got It ยท 3=Easy ยท S=Skip
65 cards ยท All 5 domains ยท Leitner spaced repetition
Loading...
Click or press Space to revealAll caught up! Switch to All Cards to keep drilling.
One question per domain area. Personalized missed-topic feedback. Retake resets cleanly โ no page reload needed.