CompTIA Security+ guideStart here

CompTIA Security+ SY0-701 Study Guide

Start Security+ from the live SY0-701 blueprint: five domains, a first diagnostic, and a week you can actually finish.

Short answer

Study the live exam, SY0-701, not the announced next version. Learn the five domains by what you must be able to decide, spend more time on Security Operations (28%) and Threats, Vulnerabilities, and Mitigations (22%), and use a short mixed set to find the domain you cannot explain yet. CompTIA recommends Network+ and two years in a security or systems role. That is not a prerequisite.

Start from the exam you can book

The exam you can book today is CompTIA Security+ V7, series SY0-701. CompTIA lists a maximum of 90 questions, multiple-choice and performance-based items, 90 minutes, and a passing score of 750 on a scale of 100 to 900. Security+ V8, series SY0-801, is published as a later version. Do not study its draft weights until it is the exam you intend to sit. The version difference is in SY0-701 and the next exam.

CompTIA recommends Network+ and two years of work in a security or systems administrator role. The objectives PDF describes two years of IT administration with a security focus. You can register without those. If networks are still unfamiliar, budget time for protocols and identity before you grind acronyms. Whether to earn Network+ first is a separate decision in do you need Network+ before Security+.

What the five weights are for

DomainWeight on SY0-701What to practice
General Security Concepts12%Controls, CIA, and the difference between hashing and encryption. The cryptography guide keeps those jobs apart
Threats, Vulnerabilities, and Mitigations22%Actor, vector, vulnerability, and the control that fits
Security Architecture18%Where a control sits, and RPO versus RTO. The recovery metrics guide uses one clock
Security Operations28%Logs, identity, and what you do first. The next action after a confirmed incident is the incident response guide
Security Program Management and Oversight20%Policy versus procedure, and a risk decision with units

A weight is a share of the blueprint. It is not a promise that 28% of 90 will be operations items on your form. The objectives guide walks through that limit.

A first diagnostic you can do today

  1. Write one sentence for each domain without looking.
  2. Answer a short mixed set and mark the domain of every miss.
  3. Circle the miss that was a vocabulary gap and the miss that was a bad control choice. Those are different study jobs.
  4. Put the weaker of the two largest domains first tomorrow.

Practice a Security+ scenario in Passy when you want another original item. The free set is multiple choice. It will not look like a performance-based question, and the percentage is not a 750.

One illustrative week

This is a shape, not a prescription. It assumes about 45 minutes on five days for someone who already knows what a firewall is.

DayBlock
1Operations: one synthetic log, then say what you would check next
2Threats: four scenarios, each with actor, vulnerability, and mitigation
3Architecture: one control-placement choice and one RPO/RTO contrast
4Program management: one policy/procedure pair and one risk response
5Mixed review of the misses, plus a short pass over General Security Concepts

If the minutes are shorter, keep day 1 and day 2 and drop the rest. A plan that fits the calendar is in the study outline. CompTIA’s own FAQ has suggested 30 to 40 hours of study. That is a general suggestion from CompTIA, not a personal deadline.

What this page will not do

It will not reprint the objectives. Download those from CompTIA and use them as a checklist after you can explain a domain out loud. It will not tell you that a Passy score predicts the scaled result.

Trust the source

Official sources

Exam policies can change. Use these primary sources for the most current details.