Study plan
Match Your Prep to SY0-701
Domain weights and a suggested study order. Unlock the full library with 30-day access ($19.99) in the pricing section above.
Match your prep to how CompTIA weights Security+ SY0-701
The live SY0-701 exam (objectives version 5.0) certifies that you can assess enterprise security posture,
monitor hybrid environments, operate with governance and compliance awareness, and respond to security
events. CompTIA publishes five domains; official guidance puts the heaviest weight on
Security Operations (28%), followed by Threats, Vulnerabilities, and Mitigations
(22%) and Security Program Management and Oversight (20%).
Domain weights below come from the CompTIA Security+ SY0-701 exam objectives document. Use them to budget study
hours, not as a guarantee of how many questions you will see on a specific attempt. The exam allows up to
90 questions in 90 minutes (multiple-choice and performance-based).
| Domain |
Weight |
What to study |
| 1.0 General Security Concepts |
12% |
Security control categories and types, CIA and AAA, zero trust, physical security, cryptography and PKI basics, change management |
| 2.0 Threats, Vulnerabilities, and Mitigations |
22% |
Threat actors and motivations, attack vectors and surfaces, vulnerability types, malware and network attacks, mitigation and hardening |
| 3.0 Security Architecture |
18% |
Cloud and hybrid architecture, identity and access, secure network design, encryption, PKI, secure software and supply chain |
| 4.0 Security Operations |
28% |
Asset and vulnerability management, monitoring and alerting, incident response and forensics, automation, SIEM, and log analysis |
| 5.0 Security Program Management and Oversight |
20% |
Governance, risk and compliance, policies and awareness, third-party risk, disaster recovery, privacy, and audit |
What to focus on first: threats and vulnerabilities (domain 2) and general security concepts (domain 1)
build the language for everything else. Add security architecture (domain 3), then operations (domain 4), the largest
slice on the exam, and program management (domain 5) for governance, risk, and compliance scenarios.
Suggested Study Order
- General security concepts (controls, CIA, AAA, cryptography basics)
- Threats, vulnerabilities, and mitigations
- Security architecture (identity, cloud, network design)
- Security operations (monitoring, IR, automation)
- Security program management and oversight
Under time pressure, leaning hardest into Security Operations and
Threats, Vulnerabilities, and Mitigations before you polish lighter domains mirrors where CompTIA
weights the blueprint. The timed simulation on this site rehearses that mixed multiple-choice and
performance-based pressure across all five domains in one 90-minute session.
Source: CompTIA Security+ SY0-701 Certification Exam Objectives, version 5.0
(PDF).
No recurring membership. One-time 30-day access ($19.99 list) includes the full library and timed simulation.
No additional software is required. Everything runs in your browser.