CompTIA Security+ guideStart here
CompTIA Security+ SY0-701 Study Guide
Start Security+ from the live SY0-701 blueprint: five domains, a first diagnostic, and a week you can actually finish.
Short answer
Study the live exam, SY0-701, not the announced next version. Learn the five domains by what you must be able to decide, spend more time on Security Operations (28%) and Threats, Vulnerabilities, and Mitigations (22%), and use a short mixed set to find the domain you cannot explain yet. CompTIA recommends Network+ and two years in a security or systems role. That is not a prerequisite.
Start from the exam you can book
The exam you can book today is CompTIA Security+ V7, series SY0-701. CompTIA lists a maximum of 90 questions, multiple-choice and performance-based items, 90 minutes, and a passing score of 750 on a scale of 100 to 900. Security+ V8, series SY0-801, is published as a later version. Do not study its draft weights until it is the exam you intend to sit. The version difference is in SY0-701 and the next exam.
CompTIA recommends Network+ and two years of work in a security or systems administrator role. The objectives PDF describes two years of IT administration with a security focus. You can register without those. If networks are still unfamiliar, budget time for protocols and identity before you grind acronyms. Whether to earn Network+ first is a separate decision in do you need Network+ before Security+.
What the five weights are for
| Domain | Weight on SY0-701 | What to practice |
|---|---|---|
| General Security Concepts | 12% | Controls, CIA, and the difference between hashing and encryption. The cryptography guide keeps those jobs apart |
| Threats, Vulnerabilities, and Mitigations | 22% | Actor, vector, vulnerability, and the control that fits |
| Security Architecture | 18% | Where a control sits, and RPO versus RTO. The recovery metrics guide uses one clock |
| Security Operations | 28% | Logs, identity, and what you do first. The next action after a confirmed incident is the incident response guide |
| Security Program Management and Oversight | 20% | Policy versus procedure, and a risk decision with units |
A weight is a share of the blueprint. It is not a promise that 28% of 90 will be operations items on your form. The objectives guide walks through that limit.
A first diagnostic you can do today
- Write one sentence for each domain without looking.
- Answer a short mixed set and mark the domain of every miss.
- Circle the miss that was a vocabulary gap and the miss that was a bad control choice. Those are different study jobs.
- Put the weaker of the two largest domains first tomorrow.
Practice a Security+ scenario in Passy when you want another original item. The free set is multiple choice. It will not look like a performance-based question, and the percentage is not a 750.
One illustrative week
This is a shape, not a prescription. It assumes about 45 minutes on five days for someone who already knows what a firewall is.
| Day | Block |
|---|---|
| 1 | Operations: one synthetic log, then say what you would check next |
| 2 | Threats: four scenarios, each with actor, vulnerability, and mitigation |
| 3 | Architecture: one control-placement choice and one RPO/RTO contrast |
| 4 | Program management: one policy/procedure pair and one risk response |
| 5 | Mixed review of the misses, plus a short pass over General Security Concepts |
If the minutes are shorter, keep day 1 and day 2 and drop the rest. A plan that fits the calendar is in the study outline. CompTIA’s own FAQ has suggested 30 to 40 hours of study. That is a general suggestion from CompTIA, not a personal deadline.
What this page will not do
It will not reprint the objectives. Download those from CompTIA and use them as a checklist after you can explain a domain out loud. It will not tell you that a Passy score predicts the scaled result.
Trust the source
Official sources
Exam policies can change. Use these primary sources for the most current details.