CompTIA Security+ guideStart here
Security+ SY0-701 Exam Objectives Explained
The five SY0-701 domains, what each one asks you to do, and why a percentage is not a guaranteed number of questions.
Short answer
SY0-701 has five domains: General Security Concepts 12%, Threats, Vulnerabilities, and Mitigations 22%, Security Architecture 18%, Security Operations 28%, and Security Program Management and Oversight 20%. Those percentages describe the blueprint. They do not guarantee a question count on your form. Read CompTIA’s objectives PDF for the official wording, and use this page to decide how to practice.
A percentage is not a question count
CompTIA publishes domain weights for SY0-701 and also says the exam has a maximum of 90 questions. If you multiply 28% by 90 you get a figure that looks like a quota. It is not. Forms vary, performance-based questions take more time than one multiple-choice item, and CompTIA does not promise that your sitting will contain 90 scored items in those exact ratios. Study the weight as a priority, not as a tally.
The next version, SY0-801, publishes different weights. Do not mix them into this checklist. Details are in the version guide.
What each domain is asking
General Security Concepts, 12%. You should be able to say what a control does (prevent, detect, correct, deter, compensate) and what confidentiality, integrity, and availability each protect. Cryptography in this domain includes knowing that hashing, encryption, and signatures are not the same tool. The controls guide separates category from function. The cryptography guide separates the mechanisms. The weight is the smallest. The ideas show up inside the other domains, so skipping it to “save time” usually costs you later.
Threats, Vulnerabilities, and Mitigations, 22%. The skill is a distinction. A criminal group is an actor. A phishing email is a vector. An unpatched service is a vulnerability. The exploit is what someone does with that weakness. The mitigation has to match the path. A longer password policy does not segment an infected host. Practice that matching in the threats guide.
Security Architecture, 18%. This domain is about where a control lives. A perimeter firewall, a web application firewall, and full-disk encryption answer different failures. Resilience shows up as recovery point and recovery time, which are not synonyms. The recovery metrics guide puts both on one timeline. Zero trust’s control plane and data plane are in the zero trust guide. Cloud, on-premises, and remote access change the picture. A control that is right in one design can be noise in another.
Security Operations, 28%. This is the largest published weight. It covers monitoring, vulnerability handling, identity, firewall and detection tools, and incident work. The practical skill is reading evidence: a log line, an alert, a new privileged account. The log guide uses synthetic examples so you can practice that read without anyone’s real incident.
Security Program Management and Oversight, 20%. Governance, risk, third parties, compliance, and audits. You should be able to tell a policy from a procedure, an acceptance decision from a mitigation, and an audit from a penetration test. Risk formulas have units. Single loss expectancy is one event. Annualized loss expectancy multiplies that event by how often you expect it.
How to use the official PDF
Download the objectives from CompTIA. After you practice a domain, mark the bullets you still cannot explain with an example of your own. A highlighted PDF is not the same as being able to choose a control.
Work an original item in the free Security+ set when you want to test one of those distinctions. Twenty questions cannot reproduce the blueprint, and they are not a mini form of the exam.
Trust the source
Official sources
Exam policies can change. Use these primary sources for the most current details.