CHEAT SHEET · SECURITY+

Security+ Cheat Sheet.
The night-before summary, built like the exam.

Weighted to the current exam outline·15-minute scan
By Vincent Ruan, EA, CFP®Published July 21, 2026
Drill weak spots →

Exam Logistics at a Glance

DetailValue
Exam codeSY0-701
Length of test90 minutes
Question countMaximum of 90 questions
Question typesMultiple-choice and performance-based questions (PBQs)
Passing score750 on a scale of 100-900
Content domains5 domains
DeliveryPearson VUE test center or OnVUE online proctoring (24/7)
LanguagesEnglish, Japanese, Portuguese, Spanish, Thai
Recommended experience2 years in IT administration with a security focus
Certification validityExam usually retired 3 years after launch
Renewal50 CEUs

Content Domains (Quick List)

  • 1.0 General Security Concepts — 12% of the exam
  • 2.0 Threats, Vulnerabilities, and Mitigations — 22% of the exam (the heaviest domain besides Security Operations)
  • 3.0 Security Architecture — 18% of the exam
  • 4.0 Security Operations — 28% of the exam (the single largest domain — prioritize study time here)
  • 5.0 Security Program Management and Oversight — 20% of the exam

Study-Time Allocation Tip

Since Domain 4 (28%) and Domain 2 (22%) together make up half the exam, weight your practice-question time toward operational security controls and threat/vulnerability analysis before polishing governance and architecture topics.

Key Terms and Concepts to Memorize

Domain 1 — General Security Concepts

  • CIA triad: confidentiality, integrity, availability — the foundation every other concept maps back to
  • Non-repudiation, AAA (authentication, authorization, accounting) framework
  • Physical vs. logical vs. administrative controls, and control types (preventive, detective, corrective, deterrent, compensating)
  • Zero Trust principles: never trust, always verify; control plane vs. data plane

Domain 2 — Threats, Vulnerabilities, Mitigations

  • Threat actor types: nation-state, hacktivist, insider, organized crime, unskilled attacker
  • Social engineering vectors: phishing, vishing, smishing, pretexting, business email compromise
  • Vulnerability classes: zero-day, misconfiguration, supply chain, cryptographic weaknesses
  • Malware families: ransomware, worms, trojans, rootkits, spyware, logic bombs
  • Mitigation techniques: segmentation, patching, least privilege, encryption, monitoring

Domain 3 — Security Architecture

  • Cloud vs. on-prem vs. hybrid architecture trade-offs, IaC (infrastructure as code)
  • Network segmentation: VLANs, screened subnets (DMZ), microsegmentation, zero trust architecture
  • Resilience concepts: redundancy, high availability, RTO/RPO, backup types (full, incremental, differential)
  • Data protection: encryption at rest/in transit/in use, tokenization, masking, data classification

Domain 4 — Security Operations

  • Hardening techniques: baselines, patch management, disabling unnecessary services/ports
  • Identity and access management: SSO, federation, MFA factors, conditional access, privileged access management
  • Incident response lifecycle: preparation, detection, analysis, containment, eradication, recovery, lessons learned
  • Log sources and SIEM/SOAR concepts, digital forensics basics (chain of custody, order of volatility)
  • Vulnerability management workflow: scanning, prioritization (CVSS), remediation, validation

Domain 5 — Security Program Management and Oversight

  • Governance elements: policies, standards, procedures, guidelines
  • Risk management: risk register, risk appetite/tolerance, qualitative vs. quantitative risk analysis (ALE, SLE, ARO)
  • Third-party/vendor risk management, compliance frameworks, and audits
  • Security awareness training and the role of a security champion program

Common Gotchas and Traps

  • Questions often present two technically correct answers — pick the most secure or least disruptive option per the scenario, not just any valid control.
  • Performance-based questions (PBQs) typically appear early in the exam and can consume disproportionate time — do not let them derail your pacing for the remaining multiple-choice items.
  • Do not confuse similar-sounding acronyms: IPS vs. IDS, SIEM vs. SOAR, RTO vs. RPO, MTBF vs. MTTR.
  • Many distractors describe a real security concept that is simply the wrong fit for the scenario's stated goal (e.g., confidentiality control offered when the question asks about availability).
  • Watch for questions that test order of operations, especially in incident response and forensics (order of volatility, chain of custody).
  • Zero Trust and least privilege appear across multiple domains — expect them to resurface in architecture, operations, and governance contexts, not just one section.

Night-Before Checklist

  • Confirm your Pearson VUE appointment details and, if testing remotely, verify your OnVUE system check and ID requirements in advance.
  • Do a final pass on the domain you're weakest in — but don't cram new material; focus on reinforcing what you already know.
  • Review the CIA triad, AAA framework, incident response steps, and risk formulas (ALE = SLE × ARO) one last time — these anchor many scenario questions.
  • Skim your list of confusable acronym pairs (IDS/IPS, RTO/RPO, MTBF/MTTR, SSO/federation) to avoid last-minute mix-ups.
  • Get sufficient sleep — the exam is only 90 minutes but performance-based questions demand sustained focus early on.
  • Prepare your government-issued photo ID and, for online testing, ensure a quiet, clear workspace that meets OnVUE proctoring requirements.
  • Plan your pacing: with up to 90 questions in 90 minutes, budget roughly a minute per question and flag-and-return on anything that stalls you.

Frequently asked questions

How many questions are on the CompTIA Security+ (SY0-701) exam, and how long do I get?

The SY0-701 exam contains a maximum of 90 questions, and you're given 90 minutes to complete it. Questions come in two formats: multiple-choice and performance-based (PBQs), where you complete hands-on, simulation-style tasks. Because you could face up to 90 items in 90 minutes, budget roughly one minute per question — but flag the more time-consuming performance-based questions and consider tackling them after you've locked in the faster multiple-choice points.

What score do I need to pass, and does CompTIA publish pass rates?

You need a scaled score of 750 to pass, on a scale of 100 to 900. CompTIA does not publish exam pass rates, because exam questions and passing scores are subject to change without notice — so ignore any "official pass rate" figure you see quoted elsewhere. Note that the 100–900 scale is not a simple percentage, so 750 does not translate to a fixed number of questions correct; focus on mastering the objectives rather than chasing a raw percentage.

What experience should I have before taking Security+, and are there prerequisites?

There are no mandatory prerequisites, but CompTIA recommends a minimum of 2 years of experience in IT administration with a focus on security. CompTIA also recommends holding CompTIA Network+ and having two years of experience in a security or systems administrator job role before attempting Security+. If you don't have the full two years of hands-on experience yet, the recommendations signal the exam assumes practical familiarity with networking and security operations — so lean heavily on labs and performance-based practice to close that gap.

How can I take the exam, and how do I keep the certification current after I pass?

CompTIA exams are delivered through Pearson VUE, and you can test either in person at a Pearson VUE test center or online via the OnVUE remote proctoring platform, which is available 24/7. After you pass, you renew CompTIA Security+ by earning 50 Continuing Education Units (CEUs) — through training, higher education, industry activities, and completing additional certifications — so you don't have to retake the exam. Because online OnVUE proctoring runs 24/7, it's the more flexible option if you can meet the workspace and equipment requirements, and starting to log CEU-eligible activities early makes the 50-CEU renewal far easier to hit.

Sources

  1. 1.CompTIA Security+ (SY0-701) Certification Exam Objectives (Version 5.0)CompTIA (accessed Jul 18, 2026)
  2. 2.CompTIA Security+ Certification PageCompTIA (accessed Jul 18, 2026)
  3. 3.Schedule Your CompTIA ExamCompTIA (accessed Jul 18, 2026)
  4. 4.Renewing CompTIA Security+ with Multiple ActivitiesCompTIA (accessed Jul 18, 2026)
  5. 5.CompTIA — Pearson VUEPearson VUE (accessed Jul 18, 2026)