Study guide · Exam overview

CompTIA Security+: what SY0-701 expects

The format, passing score, and five published domains of CompTIA Security+ SY0-701, plus the distinctions worth learning before you book.

Exam: SY0-701Up to 90 questions · 90 minutesReviewed October 2026

Exam version notice: This overview follows CompTIA Security+ exam objectives version 6.0 for SY0-701, reviewed in October 2026. CompTIA calls that version Security+ V7. The exam allows a maximum of 90 questions in 90 minutes, and CompTIA publishes a passing score of 750 on a scale of 100 to 900. CompTIA has said Security+ V8 is expected on or around November 17, 2026. Items tagged Extra are useful context the SY0-701 objective list does not name. Confirm the exam code, fee, and objectives with CompTIA before you register.

What Security+ covers

CompTIA Security+ is the vendor-neutral certification for people who assess a security posture, monitor hybrid environments, and respond to incidents. SY0-701 checks whether you can name a control, tell attacks apart, place a security device, operate identity and monitoring tools, and explain governance and risk. It is not a senior architect exam, and it does not ask you to configure a specific vendor's console from memory.

Who it is for

  • Administrators who already touch accounts, networks, and servers
  • People moving into a security analyst or security engineer role
  • Candidates who want a shared vocabulary before a vendor security exam

What the exam verifies

  • Which control stops, detects, or repairs an action
  • How common attacks arrive and which mitigation fits
  • How identity, logging, and recovery decisions are made

Exam format

Figures below come from the SY0-701 objectives version 6.0 and CompTIA's Security+ pages reviewed in October 2026.

CompTIA Security+ SY0-701 exam facts. Confirm the fee and testing policy with CompTIA before you book.
SpecificationSY0-701 (Security+ V7)
LevelFoundational security. No prior certification is required. CompTIA recommends two years of IT administration with a security focus.
Length of test90 minutes.
Question typesMultiple choice and performance-based questions. The stem says how many answers to choose.
Number of questionsMaximum of 90.
Passing score750 on a scale of 100 to 900. CompTIA does not publish the raw-score conversion.
ObjectivesVersion 6.0. Five domains. Example lists in the objectives are not exhaustive.
Exam priceConfirm the current voucher price with CompTIA. Regional pricing changes.
ValidityThree years from the pass date. Confirm renewal options with CompTIA.
Later versionSecurity+ V8 is expected on or around November 17, 2026. V7 remains the SY0-701 exam described here.

Published domains

CompTIA publishes these weights. The 200 practice questions use the same share.

  • 1. General Security Concepts12%
  • 2. Threats, Vulnerabilities, and Mitigations22%
  • 3. Security Architecture18%
  • 4. Security Operations28%
  • 5. Security Program Management and Oversight20%
Domain 112%

General security concepts

Controls, the CIA triad, zero trust, change management, and cryptography.

  • Control categories and control types
  • CIA, AAA, and zero trust planes
  • Change approval, backout, and maintenance windows
  • Keys, hashing, certificates, and obfuscation
Domain 222%

Threats, vulnerabilities, and mitigations

Who attacks, how they get in, and what you do about it.

  • Actors and motivations
  • Message, human, and supply-chain vectors
  • Application, cloud, and mobile vulnerabilities
  • Indicators and hardening
Domain 318%

Security architecture

Where controls sit, and how the environment survives a failure.

  • Cloud, isolation, and infrastructure as code
  • Firewalls, VPN, and failure modes
  • Data states and classifications
  • Sites, backups, and power
Domain 428%

Security operations

The largest domain. Day-to-day security work.

  • Baselines, hardening, and mobile models
  • Vulnerability management and monitoring
  • Identity, federation, and privileged access
  • Incident response and evidence
Domain 520%

Security program management

Governance, risk math, vendors, compliance, and awareness.

  • Policies, standards, and procedures
  • SLE, ALE, appetite, and treatment
  • Agreements and third-party assessment
  • Audits, privacy, and phishing exercises

Ideas to recognize

Learn the unmarked rows first. The same map is in the core notes and flashcards.

High-yield Security+ distinctions. Extra rows are useful context the SY0-701 objective list does not name.
PairHow to separate them
Preventive and detectivePreventive stops the action. Detective finds it. Corrective repairs it. Deterrent discourages it.
Policy Engine and PEPThe engine decides. The Policy Enforcement Point allows or blocks the request.
Hash and encryptionA hash is one-way. Encryption is reversible with the right key.
Smishing and vishingSmishing is a text. Vishing is a voice call.
Worm and virusA worm spreads on its own. A virus needs a host.
CVE and CVSSCVE names the flaw. CVSS scores it.
SPF, DKIM, and DMARCSPF lists senders. DKIM signs the message. DMARC says what to do when they fail.
SAML and OAuthSAML carries a sign-in assertion. OAuth issues an authorization token.
RTO and RPORTO is downtime. RPO is how much data you can lose.
OpenID Connect ExtraOften used with OAuth for sign-in. The SY0-701 bullets name OAuth and SAML, not OpenID Connect.

How Security+ questions are written

Most items are multiple choice. Some ask you to choose two or three answers, and the stem says so. Performance-based items ask you to match a term to a job or put a process in order. Read FIRST, NEXT, and BEST as ordering words: the right control at the wrong time is still wrong.

CompTIA says the example lists in the objectives are not exhaustive. A question can use a technology that fits an objective even when the PDF did not print that product name. Do not expect vendor console screenshots.

How to plan your Security+ study

A practical sequence if attacks, logs, and risk formulas still blur together.

01

Separate controls

Say whether a control is technical, managerial, operational, or physical, and whether it prevents, detects, corrects, deters, compensates, or directs. Then place CIA and zero trust on one sentence each.

02

Name the attack by its path

Text, voice, lookalike domain, trusted website, self-spreading malware, and a query that changed. Say the mitigation that stops that path.

03

Place the device

Inline versus tap. Fail open versus fail closed. Hot, warm, and cold. RTO versus RPO. A screened subnet versus the internal database network.

04

Operate identity and response

SAML, OAuth, and the access models. Then say the incident order out loud: prepare, detect, analyze, contain, eradicate, recover, and learn.

05

Do the risk math

SLE is asset value times exposure factor. ALE is SLE times the annualized rate. Then pick avoid, mitigate, transfer, or accept, and name the agreement that fits the vendor.

06

Drill, then sit a timed exam

Use the four flashcard decks until you can answer before the card flips. Then take original questions and return to any domain under 75 percent. Use 90 minutes as the pace of the live exam. Treat the 100 to 900 estimate as a personal trend, not a prediction.

The NodnWebTools Security+ study path

The overview, core notes, flashcards, and practice exams are all published.

Security+ hub →
Available · You are here

Overview

Exam format, the 750 passing score, five domain weights, and a study plan.

Available

Core Notes

Reference notes for controls, threats, architecture, operations, and program management.

Available

Practice Exams

200 original questions with custom exams, explanations, and an unofficial score on the 100-900 scale.

Frequently asked questions

How long is the Security+ SY0-701 exam?

CompTIA allows a maximum of 90 questions and 90 minutes. Questions are multiple choice and performance-based. Confirm the current details with CompTIA before you book.

What score do I need to pass Security+?

CompTIA publishes a passing score of 750 on a scale of 100 to 900 for SY0-701. This site converts a practice percentage linearly onto that scale and labels the result unofficial, because CompTIA does not publish the real conversion.

Which Security+ version is current?

This page follows exam objectives version 6.0 for SY0-701, which CompTIA calls Security+ V7. CompTIA has said Security+ V8 is expected on or around November 17, 2026. Confirm which exam code you will sit before you study or buy a voucher.

Does Security+ expire?

Yes. CompTIA certifications are valid for three years from the date you pass. Renewal options change, so confirm the current policy with CompTIA.

Are there prerequisites for Security+?

No prior certification is required. CompTIA recommends at least two years of experience in IT administration with a security focus, plus hands-on experience with technical information security.

Does this page include real CompTIA exam questions?

No. The practice questions on this site are original. They are not CompTIA exam items, and a practice score does not predict a result.

Related Tools

Useful companions while you study.

All study topics →