Every Exam PrepFREE EXAM PREP
Ask AI
STUDY GUIDE · COMPTIA SECURITY+

CompTIA Security+ (SY0-701) Study Guide

Verified against the CompTIA exam objectives 6 sections
Written by Every Exam Prep Editorial TeamSource and review policyPublished July 18, 2026
Questions
90
Time limit
1h 30m
Passing score
750 (on a scale of 100-900)
Governing body
CompTIA

CompTIA Security+ is a foundational, vendor-neutral certification that validates the core skills needed to secure networks, systems, and data in a modern IT environment. The current version of the exam, SY0-701, covers the baseline knowledge that employers expect from anyone working in a cybersecurity-adjacent role, from configuring secure network architectures to responding to incidents and understanding governance requirements.

The certification is aimed at IT professionals who already have some hands-on experience and want to formalize their security knowledge, as well as career changers looking to break into cybersecurity for the first time. It is commonly pursued by help desk technicians, systems administrators, network administrators, and junior security analysts who want to move into dedicated security positions such as SOC analyst, security administrator, or security engineer.

Why It Matters for Your Career

  • It is widely recognized across both private industry and government, and it satisfies DoD 8570/8140 baseline requirements for many federal and contractor security roles.
  • It signals to employers that a candidate understands practical security concepts rather than just theory, since the exam includes performance-based questions that simulate real tasks.
  • It often serves as a prerequisite or stepping stone toward more advanced certifications, giving candidates a structured entry point into the broader cybersecurity certification track.

For many professionals, Security+ is the certification that unlocks the first true security-focused job title on a resume, making it one of the most commonly requested entry-level cybersecurity credentials in job postings.

Understanding the exam's structure helps you plan your study timeline and know what to expect on test day. Security+ (SY0-701) is a single exam with a defined set of logistics set by CompTIA and delivered through its official testing partner.

Format Details

  • The exam contains a maximum of 90 questions, combining multiple-choice items with performance-based questions that require you to complete simulated tasks.
  • You are given 90 minutes to complete the exam, so pacing matters, especially around the performance-based items, which tend to take longer than multiple-choice questions.
  • Scoring uses a scale of 100 to 900, and the passing score is 750.
  • The exam is offered in several languages, including English, Japanese, Portuguese, Spanish, and Thai, making it accessible to a global candidate pool.

Delivery and Scheduling

Pearson VUE is the official testing provider that schedules CompTIA exams. Candidates can choose to test in person at a Pearson VUE test center or take the exam remotely through the OnVUE online proctoring platform, which is available 24/7 for added flexibility. Before sitting for the exam, CompTIA recommends candidates have CompTIA Network+ under their belt along with around two years of experience in a security or systems administrator role, though these are recommendations rather than strict enrollment requirements.

Once earned, the certification does not last indefinitely. CompTIA certifications are generally retired a few years after launch, and Security+ can be kept active afterward through a formal continuing education process rather than by retaking the exam from scratch.

The Security+ exam measures five content domains, each weighted differently to reflect its importance in day-to-day security work. Knowing these weightings helps you allocate study time proportionally rather than spreading effort evenly across topics that carry unequal weight on exam day.

Domain 1.0: General Security Concepts

Domain 1.0 accounts for 12% of the examination. It covers foundational terminology and concepts such as security controls, the CIA triad, authentication and authorization models, cryptographic basics, and change management processes that underpin every other domain.

Domain 2.0: Threats, Vulnerabilities, and Mitigations

Domain 2.0 accounts for 22% of the examination, making it one of the two heaviest domains. It focuses on identifying threat actors, attack vectors, malware types, vulnerabilities, and the appropriate mitigation techniques used to reduce organizational risk.

Domain 3.0: Security Architecture

Domain 3.0 accounts for 18% of the examination. This domain deals with designing and implementing secure infrastructure, including network segmentation, cloud and hybrid environment considerations, and data protection strategies.

Domain 4.0: Security Operations

Domain 4.0 accounts for 28% of the examination, making it the single largest domain. It covers hands-on operational tasks such as incident response, security monitoring, hardening techniques, identity and access management, and applying appropriate security tools.

Domain 5.0: Security Program Management and Oversight

Domain 5.0 accounts for 20% of the examination. It addresses governance, risk management, compliance, third-party risk, audits, and the policies that guide an organization's overall security posture.

Because Security Operations and Threats, Vulnerabilities, and Mitigations together make up half the exam, candidates typically benefit from spending a disproportionate share of study time on practical, scenario-based material from those two domains.

Most candidates who already have some IT background can prepare for Security+ in about six to eight weeks of consistent study, though the right pace depends on your starting knowledge and how much time you can dedicate each week. Because the exam rewards applied understanding over memorization, a plan that mixes reading, active recall, and hands-on practice tends to outperform passive review alone.

Weeks 1-2: Build the Foundation

Start with Domain 1.0 concepts, since terminology and core models here underpin every later topic. Learn the CIA triad, control types, and basic cryptography, and get comfortable with the vocabulary before moving into more complex material.

Weeks 3-4: Go Deep on the Heaviest Domains

Shift focus to Domains 2.0 and 4.0, since together they represent half the exam's content. Study threat actors, attack techniques, and mitigations, then move into operational tasks like incident response and monitoring. Use scenario-based practice questions here rather than pure flashcard review, since these domains lean heavily on performance-based question formats.

Weeks 5-6: Architecture and Governance

Cover Domain 3.0 (security architecture) and Domain 5.0 (program management and oversight). These domains tend to reward understanding how policies, audits, and architectural decisions connect back to the concepts learned earlier.

Final Week: Review and Simulate

  • Take full-length practice exams under timed conditions to build stamina for the 90-minute window.
  • Review a glossary of key terms daily to reinforce vocabulary recall.
  • Revisit weak domains identified from practice exam results rather than re-studying everything equally.
  • Practice performance-based question formats specifically, since they differ from standard multiple-choice review.

Adjust this timeline shorter if you already have strong hands-on security experience, or longer if you are coming from outside IT and need extra time with foundational networking and systems concepts.

Careful preparation can be undermined by avoidable mistakes on test day or by common misunderstandings about how the exam is scored. Keeping the following in mind can help you perform closer to your actual ability level.

Before the Exam

  • Confirm your testing method in advance, whether that is an in-person Pearson VUE test center or the OnVUE remote proctoring option, and check technical requirements ahead of time if testing online.
  • Get familiar with the format of performance-based questions beforehand, since they are unlike typical multiple-choice items and can eat up disproportionate time if you have not practiced them.
  • Review the exam's language options if English is not your first language, since Security+ is offered in several languages.

During the Exam

  • Budget your time deliberately across the 90-minute window; if a performance-based question is taking too long, flag it and move on rather than losing time you need for the remaining questions.
  • Answer every question, since skipped items count against you the same as wrong answers.
  • Watch for distractor answers that sound technically correct but do not match the specific scenario described in the question.

Common Mistakes to Avoid

  • Relying solely on memorized definitions instead of understanding how concepts apply in real scenarios, which is where performance-based questions catch unprepared candidates.
  • Underestimating Domain 4.0 material, since Security Operations carries the heaviest weighting and covers dense, practical content.
  • Skipping timed practice exams, which leaves candidates unprepared for the pacing pressure of the 90-minute limit.
  • Assuming a passing score requires answering nearly everything correctly, when in fact the scaled scoring system means the passing threshold is calibrated differently than a simple percentage.

Walking in with a clear plan for time management and a realistic sense of which domains carry the most weight goes a long way toward reducing exam-day stress.

Preparing for Security+ does not require expensive materials alone. A combination of free, targeted resources can reinforce the same concepts covered in official study guides, especially when used consistently alongside a structured study plan.

Practice Questions

Working through practice questions modeled on the exam's multiple-choice and performance-based formats helps you get comfortable with how CompTIA phrases scenarios and distractor answers. Repeated exposure to realistic question styles builds the pattern recognition needed to work through unfamiliar scenarios quickly on exam day.

Flashcards

Flashcards are especially useful for the dense vocabulary and acronym-heavy material found throughout the five domains, from control types in Domain 1.0 to attack techniques in Domain 2.0. Short, frequent review sessions using flashcards support the kind of spaced repetition that helps terminology stick before test day.

Glossary

A glossary of key security terms is a fast way to clarify definitions on the fly while studying, rather than pausing your session to search elsewhere. Since Security+ leans heavily on precise terminology, keeping a glossary on hand can prevent small misunderstandings from compounding into larger gaps in later domains.

Used together, practice questions, flashcards, and a glossary give candidates a low-cost way to reinforce official study materials, check readiness before scheduling the exam, and identify which of the five domains still need additional review.

CompTIA Security+ flashcards

30 cards on the highest-yield terms and rules. Grading uses spaced repetition and saves in this browser.

Card 1 of 300 mastered
Say the answer out loud before flipping.
Browse all 30 cards
  1. What are the three pillars of the CIA triad?

    Confidentiality, Integrity, and Availability. Confidentiality restricts data access to authorized parties, integrity ensures data has not been altered improperly, and availability ensures systems and data are accessible when needed.

  2. What does the AAA framework stand for in security operations?

    Authentication, Authorization, and Accounting. Authentication verifies identity, authorization determines what an authenticated identity is permitted to do, and accounting logs what actions were actually taken.

  3. What is the difference between authentication and authorization?

    Authentication proves who a user is (identity verification), while authorization determines what an authenticated user is allowed to access or do.

  4. What is non-repudiation?

    A security property ensuring a party cannot deny having performed an action, typically enforced through digital signatures and audit logs that tie an action to a specific identity.

  5. What is the difference between symmetric and asymmetric encryption?

    Symmetric encryption uses a single shared key for both encryption and decryption, making it fast but requiring secure key distribution. Asymmetric encryption uses a mathematically linked public/private key pair, solving key distribution but at a higher computational cost.

  6. What is a zero-day vulnerability?

    A previously unknown software flaw that has no available patch, exploited by attackers before the vendor becomes aware and can issue a fix.

  7. What distinguishes a vulnerability from a threat and a risk?

    A vulnerability is a weakness that can be exploited, a threat is a potential danger that could exploit that weakness, and risk is the likelihood and impact of a threat successfully exploiting a vulnerability.

  8. What is social engineering?

    The use of psychological manipulation to trick people into divulging confidential information, granting access, or performing actions that compromise security, rather than exploiting technical flaws.

  9. What is the difference between phishing, vishing, and smishing?

    Phishing is social engineering conducted via email, vishing is conducted via voice/phone calls, and smishing is conducted via SMS text messages.

  10. What is the purpose of defense in depth?

    A layered security strategy that uses multiple, overlapping controls (technical, administrative, and physical) so that if one control fails, others still protect the asset.

  11. What is the principle of least privilege?

    Users, processes, and systems should be granted only the minimum access rights necessary to perform their required functions, reducing the potential impact of a compromised account.

  12. What is a DDoS attack?

    A distributed denial-of-service attack in which multiple compromised systems (often a botnet) flood a target with traffic or requests, overwhelming it and denying service to legitimate users.

  13. What is the difference between a virus, a worm, and a trojan?

    A virus requires a host file and user action to spread, a worm self-propagates across networks without user interaction, and a trojan disguises itself as legitimate software to trick users into installing it.

  14. What is ransomware?

    Malware that encrypts a victim's files or locks them out of a system, then demands payment (typically cryptocurrency) in exchange for restoring access.

  15. What is multifactor authentication (MFA)?

    An authentication method requiring two or more independent verification factors from different categories: something you know (password), something you have (token), and something you are (biometric).

  16. What is the purpose of a firewall?

    A network security device or software that monitors and controls incoming and outgoing traffic based on predetermined security rules, forming a barrier between trusted and untrusted networks.

  17. What is the difference between an IDS and an IPS?

    An intrusion detection system (IDS) monitors traffic and alerts on suspicious activity but does not act on it, while an intrusion prevention system (IPS) sits inline and can actively block or stop detected threats.

  18. What is a VPN and what does it provide?

    A virtual private network creates an encrypted tunnel over a public network, providing confidentiality and integrity for data in transit between endpoints.

  19. What is the purpose of network segmentation?

    Dividing a network into smaller isolated zones to limit the lateral movement of attackers, contain breaches, and enforce access controls between segments.

  20. What is a security control's classification as preventive, detective, or corrective?

    Preventive controls stop an incident before it occurs (e.g., firewalls), detective controls identify an incident as or after it occurs (e.g., IDS, logging), and corrective controls restore systems and reduce impact after an incident (e.g., backups, patching).

  21. What is the difference between qualitative and quantitative risk analysis?

    Qualitative risk analysis uses subjective ratings (high/medium/low) to prioritize risks, while quantitative risk analysis assigns numeric/monetary values, such as calculating Annualized Loss Expectancy, to measure risk impact.

  22. What is Single Loss Expectancy (SLE) and how is it calculated?

    SLE is the monetary loss expected from a single occurrence of a risk event, calculated as Asset Value multiplied by the Exposure Factor (the percentage of asset value lost).

  23. What is Annualized Loss Expectancy (ALE)?

    The expected yearly monetary loss from a risk, calculated as Single Loss Expectancy (SLE) multiplied by the Annualized Rate of Occurrence (ARO).

  24. What are the four common risk response strategies?

    Accept (take no action and absorb the risk), avoid (eliminate the activity causing the risk), mitigate (reduce likelihood or impact with controls), and transfer (shift risk to a third party, such as through insurance).

  25. What is the difference between RTO and RPO in business continuity planning?

    Recovery Time Objective (RTO) is the maximum acceptable time to restore a system after a disruption, while Recovery Point Objective (RPO) is the maximum acceptable amount of data loss measured in time since the last backup.

  26. What is the purpose of a Business Impact Analysis (BIA)?

    A process that identifies critical business functions and quantifies the operational and financial impact of their disruption, informing recovery priorities and continuity planning.

  27. What is the chain of custody in digital forensics?

    A documented, unbroken record of who collected, handled, transferred, and stored evidence, ensuring the evidence remains admissible and untampered from collection through legal proceedings.

  28. What is the difference between symmetric key algorithms like AES and asymmetric algorithms like RSA?

    AES is a symmetric algorithm that uses the same secret key for encryption and decryption and is efficient for bulk data, while RSA is an asymmetric algorithm using a public/private key pair, commonly used for key exchange and digital signatures.

  29. What is a digital certificate used for in a PKI?

    A digital certificate binds a public key to a verified identity, issued and signed by a trusted Certificate Authority (CA), enabling parties to trust that a public key belongs to the claimed owner.

  30. What is the purpose of hashing in security?

    Hashing produces a fixed-length, one-way digest of data used to verify integrity; any change to the original data produces a different hash, but the original data cannot be derived from the hash.

CompTIA Security+ glossary

24 terms the CompTIA Security+ tests, defined in plain English.

Advanced Persistent Threat (APT)
A sophisticated, often state-sponsored threat actor that gains and maintains unauthorized, long-term access to a network to conduct stealthy, targeted operations such as espionage or data theft.
Attack Surface
The total sum of all points where an unauthorized user could attempt to enter or extract data from a system, including software, hardware, and human vectors.
Botnet
A network of compromised, internet-connected devices controlled remotely by an attacker, commonly used to launch distributed denial-of-service attacks or spam campaigns.
Business Continuity Plan (BCP)
A documented strategy outlining how an organization will continue critical operations during and after a disruptive event.
Certificate Authority (CA)
A trusted entity that issues and digitally signs digital certificates, vouching for the authenticity of the public key and identity contained within them.
CIA Triad
The foundational security model comprising Confidentiality, Integrity, and Availability, used to evaluate and design protections for information systems.
Cross-Site Scripting (XSS)
A web application vulnerability where an attacker injects malicious scripts into trusted web pages, which then execute in the browsers of unsuspecting users.
Data Classification
The process of categorizing data based on its sensitivity and criticality (e.g., public, internal, confidential, restricted) to apply appropriate handling and protection controls.
Data Loss Prevention (DLP)
A set of tools and policies designed to detect and prevent sensitive data from being exfiltrated, leaked, or improperly accessed outside authorized boundaries.
Federation
A trust relationship between separate organizations or identity providers that allows users to authenticate once and access resources across multiple systems or domains.
Incident Response Plan
A documented set of procedures for detecting, containing, eradicating, and recovering from security incidents, typically following phases such as preparation, identification, containment, eradication, recovery, and lessons learned.
Penetration Testing
An authorized, simulated cyberattack against a system performed to identify exploitable vulnerabilities before real attackers can find and use them.
Privilege Escalation
A technique in which an attacker gains higher-level access than originally granted, either vertically (obtaining admin rights) or horizontally (accessing other accounts at the same privilege level).
Public Key Infrastructure (PKI)
The framework of policies, roles, hardware, and software used to create, manage, distribute, and revoke digital certificates that bind public keys to identities.
Role-Based Access Control (RBAC)
An access control model that assigns permissions to users based on their organizational role rather than individually, simplifying administration and enforcing least privilege.
Security Information and Event Management (SIEM)
A platform that aggregates, correlates, and analyzes log and event data from across an organization's systems in real time to detect and support response to security incidents.
Security Orchestration, Automation, and Response (SOAR)
A set of tools and processes that automate incident response workflows, integrating with security tools to execute predefined playbooks and reduce manual response time.
Segmentation
The practice of dividing a network or system into isolated zones or subnets to limit the scope of a compromise and enforce controlled access between areas.
Single Sign-On (SSO)
An authentication mechanism that allows a user to log in once and gain access to multiple independent systems or applications without re-authenticating for each.
SQL Injection
An attack technique that inserts malicious SQL statements into input fields to manipulate a database, potentially exposing, altering, or deleting data.
Threat Actor
An individual or group responsible for carrying out a cyberattack, such as a nation-state, hacktivist, insider, or organized crime group, each with different motivations and capabilities.
Threat Intelligence
Evidence-based knowledge about existing or emerging threats, including indicators of compromise and adversary tactics, used to inform proactive defensive decisions.
Vulnerability Scanning
An automated process of identifying known security weaknesses in systems, applications, or networks by comparing them against databases of known vulnerabilities.
Zero Trust
A security model that assumes no user or device is inherently trusted, requiring continuous verification of identity and context before granting access to resources, regardless of network location.

Sources

  1. 1.CompTIA Security+ (SY0-701) Certification Exam Objectives (Version 5.0)CompTIA (accessed Jul 18, 2026)
  2. 2.CompTIA Security+ Certification PageCompTIA (accessed Jul 18, 2026)
  3. 3.CompTIA — Pearson VUEPearson VUE (accessed Jul 18, 2026)
  4. 4.Schedule Your CompTIA ExamCompTIA (accessed Jul 18, 2026)
  5. 5.Renewing CompTIA Security+ with Multiple ActivitiesCompTIA (accessed Jul 18, 2026)

Official sources

Primary documents used to verify the exam details shown on this page.

Last verified against the CompTIA exam objectives: