Security+
CompTIA Security+ (SY0-701)
This track is built to help you think like a security practitioner — the way CompTIA expects on the Security+ exam. Not memorization. Not buzzword matching. Applied knowledge across threats, architecture, operations, and governance.
Exam Details
| Detail | Security+ (SY0-701) |
|---|---|
| Format | Up to 90 questions (multiple-choice and performance-based) |
| Time | 90 minutes |
| US Exam Voucher (verify current price) | $439 USD |
| Passing Score | 750 out of 900 |
| Experience | Recommended, not required: CompTIA Network+ plus 2 years in a security or systems administrator role |
| Renewal | 50 CEUs over 3 years; $150 total CE fee when renewing through CEUs |
Source and Scope Note
Track scope checked August 24, 2026. The reference was CompTIA’s current Security+ V7 exam objectives, exam series SY0-701, launched November 7, 2023. CompTIA’s page does not currently provide an exact retirement date for this exam series.
This note records the objectives used for the track; it does not mean CompTIA reviewed or endorsed the lessons. The practice material is original and does not reproduce live exam items. Report a content issue.
What You’ll Learn
- Build a core security foundation beyond memorizing terms and acronyms
- Understand how CompTIA frames questions — applied knowledge, not rote recall
- Work through threat analysis, architecture, and operations scenarios
- Use reading, practice, and domain evidence to choose what to review next
Domain 1 — General Security Concepts (12%)
Security controls, CIA triad, AAA, zero trust, change management, and cryptographic solutions.
Section A — Security Foundations
- 1 Security Control Categories and Types Free Free Preview
- 2 The CIA Triad and Fundamental Security Concepts Full Access
- 3 Authentication, Authorization, and Accounting (AAA) Full Access
- ✓ Section A Review: Security Foundations Full Access
Section B — Zero Trust and Cryptography
- 4 Zero Trust Architecture Full Access
- 5 Change Management and Security Impact Full Access
- 6 Cryptographic Concepts and Methods Full Access
- 7 Public Key Infrastructure (PKI) Full Access
- ✓ Section B Review: Zero Trust and Cryptography Full Access
Domain 1 Review
- ★ Capstone Review: GENERAL SECURITY CONCEPTS Full Access
Domain 2 — Threats, Vulnerabilities, and Mitigations (22%)
Threat actors, attack surfaces, social engineering, vulnerability categories, malware, attacks, and mitigation techniques.
Section A — Threat Landscape
- 8 Threat Actor Types and Motivations Free Free Preview
- 9 Threat Vectors and Attack Surfaces Full Access
- 10 Social Engineering Techniques Full Access
- ✓ Section A Review: Threat Landscape Full Access
Section B — Vulnerability Categories
- 11 Application and Software Vulnerabilities Full Access
- 12 Operating System and Hardware Vulnerabilities Full Access
- 13 Cloud and Virtualization Vulnerabilities Full Access
- 14 Web-Based and Mobile Device Vulnerabilities Full Access
- ✓ Section B Review: Vulnerability Categories Full Access
Section C — Malicious Activity and Mitigations
- 15 Malware Types and Indicators of Compromise Full Access
- 16 Network and Application Attacks Full Access
- 17 Cryptographic and Password Attacks Full Access
- 18 Mitigation Techniques and Controls Full Access
- ✓ Section C Review: Malicious Activity and Mitigations Full Access
Domain 2 Review
- ★ Capstone Review: THREATS, VULNERABILITIES, AND MITIGATIONS Full Access
Domain 3 — Security Architecture (18%)
Cloud models, virtualization, IoT/ICS, infrastructure as code, design principles, data protection, and resilience.
Section A — Architecture Models
- 19 Cloud and Hybrid Security Models Free Free Preview
- 20 Virtualization, Containerization, and Serverless Full Access
- 21 IoT, ICS/SCADA, and Embedded Systems Full Access
- 22 Infrastructure as Code and Automation Full Access
- ✓ Section A Review: Architecture Models Full Access
Section B — Data Protection and Resilience
- 23 Security Architecture Design Principles Full Access
- 24 Data Protection, Classification, and Privacy Full Access
- 25 High Availability and Site Resilience Full Access
- 26 Backup Strategies and Disaster Recovery Full Access
- ✓ Section B Review: Data Protection and Resilience Full Access
Domain 3 Review
- ★ Capstone Review: SECURITY ARCHITECTURE Full Access
Domain 4 — Security Operations (28%)
Secure baselines, hardening, wireless, asset management, vulnerability management, monitoring, defense tools, identity, and incident response.
Section A — Secure Computing
- 27 Secure Baselines and Hardening Free Free Preview
- 28 Wireless and Mobile Device Security Full Access
- 29 Asset Management and Configuration Control Full Access
- 30 Vulnerability Management Lifecycle Full Access
- ✓ Section A Review: Secure Computing Full Access
Section B — Monitoring and Defense
- 31 Security Monitoring and Log Analysis Full Access
- 32 Firewalls, IDS/IPS, and Network Security Tools Full Access
- 33 Endpoint Detection, Response, and DLP Full Access
- ✓ Section B Review: Monitoring and Defense Full Access
Section C — Identity and Response
- 34 Identity and Access Management Full Access
- 35 Authentication Methods and MFA Full Access
- 36 Automation and Orchestration Full Access
- 37 Incident Response and Digital Forensics Full Access
- ✓ Section C Review: Identity and Response Full Access
Domain 4 Review
- ★ Capstone Review: SECURITY OPERATIONS Full Access
Domain 5 — Security Program Management and Oversight (20%)
Governance, policies, risk management, third-party risk, compliance, audits, and security awareness programs.
Section A — Governance and Risk
- 38 Security Governance and Policy Frameworks Free Free Preview
- 39 Risk Identification and Assessment Full Access
- 40 Risk Analysis and Treatment Strategies Full Access
- 41 Third-Party and Supply Chain Risk Full Access
- ✓ Section A Review: Governance and Risk Full Access
Section B — Compliance and Awareness
- 42 Regulatory Compliance and Privacy Full Access
- 43 Audits, Assessments, and Penetration Testing Full Access
- 44 Security Awareness and Training Programs Full Access
- ✓ Section B Review: Compliance and Awareness Full Access
Domain 5 Review
- ★ Capstone Review: SECURITY PROGRAM MANAGEMENT AND OVERSIGHT Full Access
Career Benefits
- Common next roles include security analyst, SOC analyst, and security-focused systems administrator
- Listed as a qualification option for certain DoD 8140 work roles; verify the current matrix for a specific position
- Vendor-neutral baseline security certification recognized globally
- May be requested or valued for security analyst, systems administration, and SOC roles
How It Compares
Security+ is a foundational, vendor-neutral certification covering broad security concepts. CySA+ V4 (CS0-004) is a more focused analyst certification covering security operations, vulnerability management, incident response and management, and reporting and communication. CompTIA does not require Security+ before CySA+, although Security+ followed by CySA+ can be a practical progression from broad fundamentals to analyst work.
CISSP and CISM target experienced professionals with broader or management-centered responsibilities. Choose the next credential by comparing its outline and experience guidance with the work you perform or want to perform. See the full comparison →
Head-to-head comparisons: Security+ vs CySA+ · Security+ vs CISM · Security+ vs CISSP · Security+ vs CRISC