CompTIA · SY0-701

SY0-701 Exam: Complete CompTIA Security+ Guide

CompTIA Security+ badge

Current SY0-701 Security+ exam guide covering the 90-minute format, 750 passing score, five domains, performance-based questions, and prep.

Last verified September 6, 2026

SY0-701 exam at a glance

DetailInformation
Exam nameCompTIA Security+
Exam codeSY0-701
Certification earnedCompTIA Security+
CostSee the regional CompTIA store; voucher pricing varies
Duration90 min
QuestionsMaximum of 90 questions
Passing score750 / 900
FormatMultiple choice and performance-based questions
DeliveryTest center or online proctored
PrerequisitesNone required
Validity3 years
RenewalEarn 50 CEUs, use an eligible renewal activity, or retake as permitted

Facts last verified September 6, 2026

Domain breakdown

DomainWeight
General Security Concepts
Apply security controls, Zero Trust, cryptography, change management, and enterprise security concepts.
12%
Threats, Vulnerabilities, and Mitigations
Recognize threat actors, attack surfaces, vulnerabilities, indicators, analysis methods, and mitigations.
22%
Security Architecture
Compare architecture models, secure infrastructure and data, and design for resilience and recovery.
18%
Security Operations
Harden systems, manage assets and vulnerabilities, monitor activity, secure identity, and respond to incidents.
28%
Security Program Management and Oversight
Apply governance, risk, third-party, compliance, audit, awareness, and security program practices.
20%
Total100%

Who should take the SY0-701 exam?

Security+ is for early-career cybersecurity practitioners and IT professionals who need a broad, vendor-neutral security foundation. Common roles include security specialist, help desk or systems administrator with security duties, junior security analyst, and network administrator.

CompTIA recommends Network+ knowledge and roughly two years in a security or systems administrator role. Those are recommendations, not prerequisites. You should already understand IP networking, operating systems, accounts, basic cloud concepts, and troubleshooting so study time can focus on security decisions.

The credential covers enterprise security across on-premises, cloud, mobile, and operational contexts. It is not a penetration-testing certification and does not make someone a senior security engineer. Its value is a shared baseline for controls, threats, architecture, operations, and governance.

Skills measured on Security+ SY0-701

The official SY0-701 objectives are the authoritative checklist. Download the current revision and mark every objective. Examples in the document are not exhaustive, so understand the concept behind each named technology.

General Security Concepts (12%)

Compare technical, managerial, operational, and physical controls and preventive, deterrent, detective, corrective, compensating, and directive functions. A control can belong to a category and serve a function; learn to describe both without treating the terms as interchangeable.

Security principles include confidentiality, integrity, availability, non-repudiation, authentication, authorization, accounting, least privilege, and Zero Trust. Understand control and data planes, policy decision and enforcement points, adaptive identity, implicit trust reduction, and deception technologies at an applied level.

Cryptography coverage includes encryption, hashing, salting, digital signatures, certificates, PKI, keys, and suitable use cases. Change management examines approval, impact, testing, backout, documentation, version control, and ownership because uncontrolled change is a security risk.

Threats, Vulnerabilities, and Mitigations (22%)

Identify threat actors by motivation, capability, resources, access, and intent. Attack surfaces include people, endpoints, servers, applications, supply chains, cloud services, wireless systems, mobile devices, physical access, and third parties. Social engineering exploits trust and process, not only software bugs.

Recognize indicators and behavior for malware, password attacks, network attacks, application attacks, cryptographic attacks, and physical threats. Do not stop at naming an attack; connect the indicator to likely scope, evidence, containment, and mitigation.

Vulnerability management involves discovery, validation, prioritization, remediation, exception, and verification. Consider exploitability, exposure, asset value, business context, and compensating controls rather than ranking every issue by CVSS alone.

Mitigations include segmentation, hardening, patching, least privilege, access control, isolation, monitoring, encryption, filtering, and user education. Choose a control that addresses the stated attack path with acceptable operational impact.

Security Architecture (18%)

Compare cloud, virtualization, containers, serverless, microservices, infrastructure as code, hybrid, and legacy architectures. Understand shared responsibility, isolation, attack surface, availability, and management implications. Secure design begins with requirements and data flows, not a product list.

Infrastructure security covers zones, segmentation, secure protocols, wireless, network appliances, endpoint and mobile patterns, embedded and industrial systems, and physical controls. Apply Zero Trust and least privilege while preserving required connectivity.

Data protection depends on state—at rest, in transit, or in use—plus classification, sovereignty, residency, retention, minimization, masking, tokenization, encryption, and key management. Resilience includes redundancy, backups, replication, geographic diversity, capacity, recovery sites, power, and tested restoration.

Security Operations (28%)

This largest domain turns design into daily practice. Harden endpoints, mobile devices, wireless, cloud resources, applications, and networks. Use secure baselines, patching, configuration controls, host firewalls, endpoint protection, application allowlisting, and least functionality.

Asset management covers acquisition through disposal. Know inventories, ownership, classification, acceptable use, monitoring, data sanitization, and destruction. Vulnerability operations include scans, penetration-test results, threat intelligence, prioritization, remediation, rescanning, and reporting.

Security monitoring draws from firewall, application, endpoint, identity, network, DNS, email, cloud, and physical logs. Understand SIEM, SOAR, DLP, IDS/IPS, EDR/XDR, file-integrity monitoring, and common analysis commands. Correlate evidence and time sources before drawing conclusions.

Identity operations include provisioning, federation, SSO, MFA, passwordless authentication, privileged access, access reviews, and account lifecycle. Automation improves consistency but needs authorization, logging, testing, and a safe failure mode.

Incident response follows preparation, detection, analysis, containment, eradication, recovery, and lessons learned. Preserve evidence with correct chain of custody and understand basic forensic acquisition, legal hold, reporting, and communication needs.

Security Program Management and Oversight (20%)

Governance defines policies, standards, procedures, guidelines, roles, responsibilities, and oversight. Risk work identifies assets, threats, vulnerabilities, likelihood, impact, appetite, tolerance, and treatment options: mitigate, transfer, accept, or avoid.

Third-party risk begins before purchase and continues through due diligence, contracts, monitoring, incident obligations, data handling, and offboarding. Agreements such as SLAs, MOUs, NDAs, and business partner agreements serve different purposes.

Compliance and privacy requirements vary by industry and jurisdiction. Know the purpose of audits, assessments, evidence, findings, remediation, and reporting without treating Security+ as legal qualification. Security awareness programs should address behavior and measure outcomes, not only record annual attendance.

How to prepare for SY0-701

Use the objectives as a literal tracker. For every bullet, be able to define it, recognize a scenario, choose a relevant control, and name an important limitation. Prioritize Security Operations because it carries 28%, but mix domains so governance and architecture constraints appear in technical work.

Build a safe home lab with virtual machines, sample logs, account policies, a vulnerability scanner, firewall rules, certificates, backups, and a SIEM or log-analysis tool. Practice Linux and Windows commands listed in the objectives. Never scan systems you do not own or have permission to test.

Train for performance-based questions. Given a diagram, logs, command output, or control list, practice configuring or arranging the solution under time pressure. Reserve time to review flagged items.

Security+ practice questions

Use mixed scenario questions that require the best or first action. Identify whether the item asks for prevention, detection, response, recovery, governance, or evidence. Read every qualifier; several choices may be generally good security practices but only one fits the immediate objective.

Avoid brain dumps. CompTIA explicitly rejects unauthorized exam content, and using it can lead to revocation or suspension. Objective-aligned practice and labs build reusable security judgment.

SY0-701 compared with other CompTIA exams

Network+ builds the networking foundation that Security+ assumes. CySA+ goes deeper into defensive analysis and incident response, while PenTest+ focuses on authorized offensive assessment. Security+ is the broad baseline between general IT and specialized cybersecurity work.

Career value of Security+

Security+ is widely used as an early-career screening credential because it is vendor neutral and covers technical and governance fundamentals. It can support junior analyst, administrator, and security specialist applications, especially when a role explicitly lists it.

Pair it with evidence: harden a lab, analyze an incident dataset, document a risk assessment, or write a recovery runbook. Practical work demonstrates that you can turn vocabulary into decisions.

Exam-day notes

  • The exam allows up to 90 questions in 90 minutes.
  • Expect multiple-choice and performance-based questions.
  • The passing score is 750 on a 100–900 scale.
  • Voucher prices vary by country, taxes, discounts, and bundle; confirm the CompTIA store checkout.
  • Online and Pearson VUE test-center delivery are available subject to regional options.

SY0-701 FAQ

Is the SY0-701 Security+ exam hard?

Security+ is an early-career certification, but it covers a broad operational baseline and includes performance-based items. Candidates need to apply controls and interpret scenarios, not only define security terms.

How many questions are on SY0-701?

CompTIA lists a maximum of 90 questions. The exam can include multiple-choice and performance-based questions, so the exact mix and count can vary.

What score do you need to pass Security+ SY0-701?

You need 750 on CompTIA's 100–900 scale. That scaled result should not be interpreted as a simple percentage of questions correct.

Are there prerequisites for Security+?

There are no mandatory certifications or courses. CompTIA recommends Network+ knowledge and about two years in a security or systems administrator role, but candidates can take SY0-701 without them.

How long is CompTIA Security+ valid?

Security+ is valid for three years. You can renew through CompTIA's continuing education program by earning 50 CEUs and meeting current requirements, completing an eligible single activity, or recertifying through an accepted exam path.

Prep resources

ResourceTypeProvider
CompTIA Security+ certification page official Official guideCompTIA
Official SY0-701 exam objectives official Official guideCompTIA
Official Security+ training options official CourseCompTIA
CompTIA continuing education program official Official guideCompTIA

← More CompTIA exams