Skip to content
CompTIA Security+ and PenTest+

CompTIA Security+ SY0-701 study guide: objectives, plan and resources

Security+ SY0-701 study guide: all five domains and their objectives, a study plan, PBQ practice, honest resources, and whether to take SY0-701 or SY0-801.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 9 min read

The fastest way to pass Security+ SY0-701 is to study directly from CompTIA’s official exam objectives, weight your time by the domain percentages, and practise performance-based questions (PBQs) from the first week rather than the last. Security Operations is the biggest domain at 28%, so it deserves the most hours.

There is one timing decision to make first, because CompTIA is replacing this exam. Below: which version to sit, what is on SY0-701, how to study each domain, the resources worth your time, and how to plan the weeks.

SY0-701 or SY0-801: which Security+ should you take?

SY0-701 launched in November 2023 and is still available. CompTIA’s Security+ page says the new version, Security+ V8, is expected to launch on or around 17 November 2026, and its V8 page lists the exam code as SY0-801. CompTIA has said V8 expands coverage of areas such as AI-related risks, security operations and modern environments. Older versions are retired some time after a new one launches, so check CompTIA’s Security+ page for SY0-701’s retirement date before you plan.

Both versions lead to the same certification. Here is how to choose:

Your situation Sensible choice
You are already studying and can sit the exam in the next few months SY0-701. Materials are mature and plentiful. Finish what you started.
You are starting from scratch now and need several months Either works. SY0-701 has more study material today; SY0-801 will be current for longer.
You will not be ready for many months Probably SY0-801. Check SY0-701’s retirement date on CompTIA’s Security+ page first, so you do not prepare for an exam that retires before you sit it.
You have already bought a voucher Check which exam version it covers and its expiry date, and confirm with CompTIA before you plan.

Launch and retirement dates can move, so check CompTIA’s official pages before you book. The rest of this guide covers SY0-701.

What is on the Security+ SY0-701 exam?

The facts from CompTIA’s exam page:

  • Exam code: SY0-701
  • Questions: up to 90, a mix of multiple-choice and performance-based
  • Time: 90 minutes
  • Passing score: 750 on a scale of 100–900
  • Recommended experience: CompTIA Network+ and, in CompTIA’s words, “a minimum of 2 years of experience in IT administration with a focus on security” (recommended, not required)
  • Price: varies by country; check CompTIA’s exam page for the current price where you live

The five SY0-701 domains and their objectives

Download the official exam objectives PDF from CompTIA’s site. It is free and it is the real syllabus; every good course and book is built on it. The structure:

Domain Weight Objectives
1.0 General Security Concepts 12% 1.1 security controls · 1.2 fundamental security concepts · 1.3 change management · 1.4 cryptographic solutions
2.0 Threats, Vulnerabilities & Mitigations 22% 2.1 threat actors and motivations · 2.2 threat vectors and attack surfaces · 2.3 types of vulnerabilities · 2.4 indicators of malicious activity · 2.5 mitigation techniques
3.0 Security Architecture 18% 3.1 architecture models · 3.2 securing enterprise infrastructure · 3.3 protecting data · 3.4 resilience and recovery
4.0 Security Operations 28% 4.1 securing computing resources · 4.2 asset management · 4.3 vulnerability management · 4.4 alerting and monitoring · 4.5 enhancing enterprise capabilities · 4.6 identity and access management · 4.7 automation and orchestration · 4.8 incident response · 4.9 data sources for investigations
5.0 Security Program Management & Oversight 20% 5.1 security governance · 5.2 risk management · 5.3 third-party risk · 5.4 security compliance · 5.5 audits and assessments · 5.6 security awareness

Notice the verbs in the full objectives: compare and contrast, explain, summarise, and, given a scenario, apply, analyse or implement. The “given a scenario” objectives are where PBQs and the harder multiple-choice questions come from. Flag them in your copy of the objectives and give them extra practice.

How to study each domain

Domain 1: General Security Concepts (12%)

Small domain, but everything else builds on it. Know control categories (technical, managerial, operational, physical) and control types (preventive, deterrent, detective, corrective, compensating, directive) well enough to classify an example instantly. Learn the CIA triad, non-repudiation, AAA, zero trust concepts, and the role of change management.

For cryptography, understand why rather than memorising lists. Hashing is a good example to try yourself on any Mac or Linux terminal:

$ echo -n “Transfer N50,000 to account 0123456789” | shasum -a 256
e0434bf12fcd035910d3b834b7d28415148b82ae34f1e02eafb956e31ac8414f  -
$ echo -n “Transfer N500,000 to account 0123456789” | shasum -a 256
4cebb378e739e5fa14ec55c1d364445cb7f668379c1147c90e6b2eabc505e024  -

One extra zero changes the entire hash. That is integrity, demonstrated in two commands, and it is the kind of understanding that answers scenario questions you have never seen before. (On Linux, sha256sum does the same job.)

Domain 2: Threats, Vulnerabilities & Mitigations (22%)

Learn threat actor types and motivations, then the attack surface: email, messaging, removable media, supply chain, unsecured networks, social engineering. For vulnerabilities, cover application issues (injection, buffer overflow, race conditions), web, OS, cloud, mobile and misconfiguration.

Objective 2.4 asks you to analyse indicators of malicious activity. Practise reading evidence, not just definitions. For example, what does this lab log excerpt suggest?

Oct 10 02:14:07 web01 sshd[3112]: Failed password for root from 203.0.113.45 port 51122 ssh2
Oct 10 02:14:08 web01 sshd[3114]: Failed password for root from 203.0.113.45 port 51130 ssh2
Oct 10 02:14:09 web01 sshd[3116]: Failed password for root from 203.0.113.45 port 51138 ssh2

Repeated failures, one account, one source, one second apart: a brute-force attempt. The mitigations from 2.5 follow naturally: disable direct root login, use key-based authentication, apply account lockout or rate limiting, and alert on the pattern.

Domain 3: Security Architecture (18%)

Compare architecture models: on-premises, cloud (IaaS, PaaS, SaaS and the shared responsibility model), containers, serverless, IoT, ICS/SCADA. Know network infrastructure concepts such as segmentation, DMZs, firewalls by type, VPNs, and secure access. For data protection, learn data states (at rest, in transit, in use), classifications and methods such as encryption, tokenisation, masking and hashing. For resilience, cover backups, high availability, site types (hot, warm, cold), and testing of recovery plans.

A useful exercise: sketch a small fictional company’s network on paper and mark where you would put each control. If you cannot place it, you do not understand it yet.

Domain 4: Security Operations (28%)

The largest domain and the most practical. Spend real time on:

  • Identity and access management (4.6): provisioning and deprovisioning, SSO, federation, MFA methods, password policies, privileged access management. The NIST digital identity guidelines (SP 800-63B) are the standard reference behind much of this.
  • Vulnerability management (4.3): scanning, prioritisation, CVSS and CVE, remediation, validation and reporting. Read the CVSS overview from FIRST so scores mean something to you.
  • Alerting and monitoring (4.4): SIEM, log aggregation, alert tuning, and the tools that feed them.
  • Incident response (4.8): the process from preparation through detection, analysis, containment, eradication, recovery and lessons learned.
  • Data sources (4.9): which log or artefact answers which question (firewall logs, application logs, endpoint logs, packet captures, metadata).

If you can, install a free SIEM or log tool in a home lab and send it logs from one Linux and one Windows VM. An afternoon with real logs makes this domain far easier.

Domain 5: Security Program Management & Oversight (20%)

Beginners with a technical bent often underestimate this domain. It covers governance (policies, standards, procedures, roles), the risk management process (identification, assessment, analysis, registers, appetite and tolerance, BIA terms such as RTO and RPO), third-party risk, compliance, audits and assessments (including penetration testing types), and security awareness. If you come from audit, banking or legal work, this is where you have an advantage.

How to practise performance-based questions

PBQs are short simulations: dragging controls onto a network diagram, matching attacks to indicators, configuring firewall rules, or picking the right steps from a log. They often appear at the start of the exam.

  • Practise with them from week one, not just in the final week.
  • If a PBQ is taking too long, flag it and come back; the multiple-choice questions may be quicker marks.
  • Read every word of the scenario. PBQs reward careful reading more than speed.

Our dedicated guide covers Security+ SY0-701 PBQs and how to practise them.

A study plan you can follow

The right length depends on your background. As a starting point:

If you... Plan for
Already work in IT and know networking A compressed plan of around six weeks
Are new to IT or still shaky on networking Around twelve weeks, or take Network+ first

Whatever the length, the shape is the same:

  1. Phase 1, learn: one primary course or book, mapped against the objectives. Take short notes in your own words.
  2. Phase 2, apply: labs, PBQ practice and scenario questions, domain by domain, weighted towards Domains 4, 2 and 5.
  3. Phase 3, test and fix: timed practice exams from reputable providers, then return to the objectives you got wrong. Do not just retake the same test until you remember the answers.

We lay out week-by-week versions in our 6-week and 12-week Security+ study plan. If you are unsure whether to start with Network+ instead, read Security+ vs Network+.

Which Security+ resources are worth using?

  • CompTIA’s official exam objectives (free). The non-negotiable checklist.
  • CompTIA’s own training products, such as its CertMaster range, if your budget allows.
  • One main video course and one main book. Choose reputable, current SY0-701 material and finish it, rather than sampling ten.
  • Reputable practice exams that explain why each answer is right or wrong.
  • Hands-on labs, in a home lab or a structured course.
  • Free primary sources for depth: NIST CSF 2.0, the OWASP Top 10 and the NIST identity guidelines above.

What to avoid: exam dumps, meaning collections of real or “recalled” exam questions. Using them breaches CompTIA’s candidate agreement and can lead to your certification being revoked, and they leave you unable to do the work the certification describes. We explain the risks in why exam dumps can cost you your certification.

Booking and exam day

CompTIA exams are delivered by Pearson VUE, either at a test centre or online with remote proctoring. For the online option, test your computer and room setup in advance and read the rules on what is allowed on your desk. Bring the required identification to a test centre and arrive early.

During the exam, flag hard questions and keep moving, budget your time around the PBQs, and use any remaining minutes to review flagged items.

After you pass

You will hold a certification, not just a course certificate, and the difference matters to employers. Our guide to certificate vs certification explains what employers actually check. CompTIA certifications must be renewed through CompTIA’s continuing education programme; see the official Security+ pages for the current rules.

Then decide what comes next: the best cybersecurity certifications for beginners suggests an order, whether you head towards a SOC role, penetration testing or GRC.

Questions

How hard is Security+ SY0-701?

It is broad rather than deep. Most people find the volume of topics, and the scenario-style questions, harder than any single concept. Solid networking knowledge makes it noticeably easier.

Can I pass Security+ with no experience?

Many people do, although CompTIA recommends Network+ and some IT experience. Without experience, give yourself more time and plenty of hands-on practice.

Should I wait for SY0-801?

Only if you will not be ready before SY0-701 retires, or you simply prefer the newer material. If you are already well into SY0-701 preparation, finishing it is usually the better choice.

How many questions are on the SY0-701 exam?

Up to 90, with 90 minutes to answer them and a passing score of 750 on a 100–900 scale.

Is Security+ enough to get a job?

On its own, rarely. It helps your CV get through screening; employers also want to see practical skills, projects and the ability to explain your thinking.