CompTIA Certification

Security+

CompTIA Security+ (SY0-701)

CompTIA | 5 domains · 61 lessons and reviews | Free Preview

This track is built to help you think like a security practitioner — the way CompTIA expects on the Security+ exam. Not memorization. Not buzzword matching. Applied knowledge across threats, architecture, operations, and governance.

Exam Details

Security+ exam details
Detail Security+ (SY0-701)
Format Up to 90 questions (multiple-choice and performance-based)
Time 90 minutes
US Exam Voucher (verify current price) $439 USD
Passing Score 750 out of 900
Experience Recommended, not required: CompTIA Network+ plus 2 years in a security or systems administrator role
Renewal 50 CEUs over 3 years; $150 total CE fee when renewing through CEUs

Source and Scope Note

Track scope checked August 24, 2026. The reference was CompTIA’s current Security+ V7 exam objectives, exam series SY0-701, launched November 7, 2023. CompTIA’s page does not currently provide an exact retirement date for this exam series.

This note records the objectives used for the track; it does not mean CompTIA reviewed or endorsed the lessons. The practice material is original and does not reproduce live exam items. Report a content issue.

What You’ll Learn

  • Build a core security foundation beyond memorizing terms and acronyms
  • Understand how CompTIA frames questions — applied knowledge, not rote recall
  • Work through threat analysis, architecture, and operations scenarios
  • Use reading, practice, and domain evidence to choose what to review next
Start a Free Lesson →
Domain 1 — General Security Concepts (12%)

Security controls, CIA triad, AAA, zero trust, change management, and cryptographic solutions.

Section A — Security Foundations

  1. 1 Security Control Categories and Types Free Free Preview
  2. 2 The CIA Triad and Fundamental Security Concepts Full Access
  3. 3 Authentication, Authorization, and Accounting (AAA) Full Access
  4. Section A Review: Security Foundations Full Access

Section B — Zero Trust and Cryptography

  1. 4 Zero Trust Architecture Full Access
  2. 5 Change Management and Security Impact Full Access
  3. 6 Cryptographic Concepts and Methods Full Access
  4. 7 Public Key Infrastructure (PKI) Full Access
  5. Section B Review: Zero Trust and Cryptography Full Access

Domain 1 Review

  1. Capstone Review: GENERAL SECURITY CONCEPTS Full Access
Domain 2 — Threats, Vulnerabilities, and Mitigations (22%)

Threat actors, attack surfaces, social engineering, vulnerability categories, malware, attacks, and mitigation techniques.

Section A — Threat Landscape

  1. 8 Threat Actor Types and Motivations Free Free Preview
  2. 9 Threat Vectors and Attack Surfaces Full Access
  3. 10 Social Engineering Techniques Full Access
  4. Section A Review: Threat Landscape Full Access

Section B — Vulnerability Categories

  1. 11 Application and Software Vulnerabilities Full Access
  2. 12 Operating System and Hardware Vulnerabilities Full Access
  3. 13 Cloud and Virtualization Vulnerabilities Full Access
  4. 14 Web-Based and Mobile Device Vulnerabilities Full Access
  5. Section B Review: Vulnerability Categories Full Access

Section C — Malicious Activity and Mitigations

  1. 15 Malware Types and Indicators of Compromise Full Access
  2. 16 Network and Application Attacks Full Access
  3. 17 Cryptographic and Password Attacks Full Access
  4. 18 Mitigation Techniques and Controls Full Access
  5. Section C Review: Malicious Activity and Mitigations Full Access

Domain 2 Review

  1. Capstone Review: THREATS, VULNERABILITIES, AND MITIGATIONS Full Access
Domain 3 — Security Architecture (18%)

Cloud models, virtualization, IoT/ICS, infrastructure as code, design principles, data protection, and resilience.

Section A — Architecture Models

  1. 19 Cloud and Hybrid Security Models Free Free Preview
  2. 20 Virtualization, Containerization, and Serverless Full Access
  3. 21 IoT, ICS/SCADA, and Embedded Systems Full Access
  4. 22 Infrastructure as Code and Automation Full Access
  5. Section A Review: Architecture Models Full Access

Section B — Data Protection and Resilience

  1. 23 Security Architecture Design Principles Full Access
  2. 24 Data Protection, Classification, and Privacy Full Access
  3. 25 High Availability and Site Resilience Full Access
  4. 26 Backup Strategies and Disaster Recovery Full Access
  5. Section B Review: Data Protection and Resilience Full Access

Domain 3 Review

  1. Capstone Review: SECURITY ARCHITECTURE Full Access
Domain 4 — Security Operations (28%)

Secure baselines, hardening, wireless, asset management, vulnerability management, monitoring, defense tools, identity, and incident response.

Section A — Secure Computing

  1. 27 Secure Baselines and Hardening Free Free Preview
  2. 28 Wireless and Mobile Device Security Full Access
  3. 29 Asset Management and Configuration Control Full Access
  4. 30 Vulnerability Management Lifecycle Full Access
  5. Section A Review: Secure Computing Full Access

Section B — Monitoring and Defense

  1. 31 Security Monitoring and Log Analysis Full Access
  2. 32 Firewalls, IDS/IPS, and Network Security Tools Full Access
  3. 33 Endpoint Detection, Response, and DLP Full Access
  4. Section B Review: Monitoring and Defense Full Access

Section C — Identity and Response

  1. 34 Identity and Access Management Full Access
  2. 35 Authentication Methods and MFA Full Access
  3. 36 Automation and Orchestration Full Access
  4. 37 Incident Response and Digital Forensics Full Access
  5. Section C Review: Identity and Response Full Access

Domain 4 Review

  1. Capstone Review: SECURITY OPERATIONS Full Access
Domain 5 — Security Program Management and Oversight (20%)

Governance, policies, risk management, third-party risk, compliance, audits, and security awareness programs.

Section A — Governance and Risk

  1. 38 Security Governance and Policy Frameworks Free Free Preview
  2. 39 Risk Identification and Assessment Full Access
  3. 40 Risk Analysis and Treatment Strategies Full Access
  4. 41 Third-Party and Supply Chain Risk Full Access
  5. Section A Review: Governance and Risk Full Access

Section B — Compliance and Awareness

  1. 42 Regulatory Compliance and Privacy Full Access
  2. 43 Audits, Assessments, and Penetration Testing Full Access
  3. 44 Security Awareness and Training Programs Full Access
  4. Section B Review: Compliance and Awareness Full Access

Domain 5 Review

  1. Capstone Review: SECURITY PROGRAM MANAGEMENT AND OVERSIGHT Full Access

Career Benefits

  • Common next roles include security analyst, SOC analyst, and security-focused systems administrator
  • Listed as a qualification option for certain DoD 8140 work roles; verify the current matrix for a specific position
  • Vendor-neutral baseline security certification recognized globally
  • May be requested or valued for security analyst, systems administration, and SOC roles

How It Compares

Security+ is a foundational, vendor-neutral certification covering broad security concepts. CySA+ V4 (CS0-004) is a more focused analyst certification covering security operations, vulnerability management, incident response and management, and reporting and communication. CompTIA does not require Security+ before CySA+, although Security+ followed by CySA+ can be a practical progression from broad fundamentals to analyst work.

CISSP and CISM target experienced professionals with broader or management-centered responsibilities. Choose the next credential by comparing its outline and experience guidance with the work you perform or want to perform. See the full comparison →

Head-to-head comparisons: Security+ vs CySA+ · Security+ vs CISM · Security+ vs CISSP · Security+ vs CRISC