The format, passing score, and five published domains of CompTIA Security+ SY0-701, plus the distinctions worth learning before you book.
Exam: SY0-701Up to 90 questions · 90 minutesReviewed October 2026
Exam version notice: This overview follows CompTIA Security+ exam objectives version 6.0 for SY0-701, reviewed in October 2026. CompTIA calls that version Security+ V7. The exam allows a maximum of 90 questions in 90 minutes, and CompTIA publishes a passing score of 750 on a scale of 100 to 900. CompTIA has said Security+ V8 is expected on or around November 17, 2026. Items tagged Extra are useful context the SY0-701 objective list does not name. Confirm the exam code, fee, and objectives with CompTIA before you register.
What Security+ covers
CompTIA Security+ is the vendor-neutral certification for people who assess a security posture, monitor hybrid environments, and respond to incidents. SY0-701 checks whether you can name a control, tell attacks apart, place a security device, operate identity and monitoring tools, and explain governance and risk. It is not a senior architect exam, and it does not ask you to configure a specific vendor's console from memory.
Who it is for
Administrators who already touch accounts, networks, and servers
People moving into a security analyst or security engineer role
Candidates who want a shared vocabulary before a vendor security exam
What the exam verifies
Which control stops, detects, or repairs an action
How common attacks arrive and which mitigation fits
How identity, logging, and recovery decisions are made
Exam format
Figures below come from the SY0-701 objectives version 6.0 and CompTIA's Security+ pages reviewed in October 2026.
CompTIA Security+ SY0-701 exam facts. Confirm the fee and testing policy with CompTIA before you book.
Specification
SY0-701 (Security+ V7)
Level
Foundational security. No prior certification is required. CompTIA recommends two years of IT administration with a security focus.
Length of test
90 minutes.
Question types
Multiple choice and performance-based questions. The stem says how many answers to choose.
Number of questions
Maximum of 90.
Passing score
750 on a scale of 100 to 900. CompTIA does not publish the raw-score conversion.
Objectives
Version 6.0. Five domains. Example lists in the objectives are not exhaustive.
Exam price
Confirm the current voucher price with CompTIA. Regional pricing changes.
Validity
Three years from the pass date. Confirm renewal options with CompTIA.
Later version
Security+ V8 is expected on or around November 17, 2026. V7 remains the SY0-701 exam described here.
Published domains
CompTIA publishes these weights. The 200 practice questions use the same share.
1. General Security Concepts12%
2. Threats, Vulnerabilities, and Mitigations22%
3. Security Architecture18%
4. Security Operations28%
5. Security Program Management and Oversight20%
Domain 112%
General security concepts
Controls, the CIA triad, zero trust, change management, and cryptography.
Control categories and control types
CIA, AAA, and zero trust planes
Change approval, backout, and maintenance windows
Keys, hashing, certificates, and obfuscation
Domain 222%
Threats, vulnerabilities, and mitigations
Who attacks, how they get in, and what you do about it.
Actors and motivations
Message, human, and supply-chain vectors
Application, cloud, and mobile vulnerabilities
Indicators and hardening
Domain 318%
Security architecture
Where controls sit, and how the environment survives a failure.
Cloud, isolation, and infrastructure as code
Firewalls, VPN, and failure modes
Data states and classifications
Sites, backups, and power
Domain 428%
Security operations
The largest domain. Day-to-day security work.
Baselines, hardening, and mobile models
Vulnerability management and monitoring
Identity, federation, and privileged access
Incident response and evidence
Domain 520%
Security program management
Governance, risk math, vendors, compliance, and awareness.
Policies, standards, and procedures
SLE, ALE, appetite, and treatment
Agreements and third-party assessment
Audits, privacy, and phishing exercises
Ideas to recognize
Learn the unmarked rows first. The same map is in the core notes and flashcards.
High-yield Security+ distinctions. Extra rows are useful context the SY0-701 objective list does not name.
Pair
How to separate them
Preventive and detective
Preventive stops the action. Detective finds it. Corrective repairs it. Deterrent discourages it.
Policy Engine and PEP
The engine decides. The Policy Enforcement Point allows or blocks the request.
Hash and encryption
A hash is one-way. Encryption is reversible with the right key.
Smishing and vishing
Smishing is a text. Vishing is a voice call.
Worm and virus
A worm spreads on its own. A virus needs a host.
CVE and CVSS
CVE names the flaw. CVSS scores it.
SPF, DKIM, and DMARC
SPF lists senders. DKIM signs the message. DMARC says what to do when they fail.
SAML and OAuth
SAML carries a sign-in assertion. OAuth issues an authorization token.
RTO and RPO
RTO is downtime. RPO is how much data you can lose.
OpenID Connect Extra
Often used with OAuth for sign-in. The SY0-701 bullets name OAuth and SAML, not OpenID Connect.
How Security+ questions are written
Most items are multiple choice. Some ask you to choose two or three answers, and the stem says so. Performance-based items ask you to match a term to a job or put a process in order. Read FIRST, NEXT, and BEST as ordering words: the right control at the wrong time is still wrong.
One fact. Name the control, attack, or formula.
A short scene. Match the symptom to the actor, vulnerability, or log you would open.
A decision. Isolate before you investigate. Back out a failed change before you redraw the diagram. Fail closed for data, and fail open when people must leave a burning room.
CompTIA says the example lists in the objectives are not exhaustive. A question can use a technology that fits an objective even when the PDF did not print that product name. Do not expect vendor console screenshots.
How to plan your Security+ study
A practical sequence if attacks, logs, and risk formulas still blur together.
01
Separate controls
Say whether a control is technical, managerial, operational, or physical, and whether it prevents, detects, corrects, deters, compensates, or directs. Then place CIA and zero trust on one sentence each.
02
Name the attack by its path
Text, voice, lookalike domain, trusted website, self-spreading malware, and a query that changed. Say the mitigation that stops that path.
03
Place the device
Inline versus tap. Fail open versus fail closed. Hot, warm, and cold. RTO versus RPO. A screened subnet versus the internal database network.
04
Operate identity and response
SAML, OAuth, and the access models. Then say the incident order out loud: prepare, detect, analyze, contain, eradicate, recover, and learn.
05
Do the risk math
SLE is asset value times exposure factor. ALE is SLE times the annualized rate. Then pick avoid, mitigate, transfer, or accept, and name the agreement that fits the vendor.
06
Drill, then sit a timed exam
Use the four flashcard decks until you can answer before the card flips. Then take original questions and return to any domain under 75 percent. Use 90 minutes as the pace of the live exam. Treat the 100 to 900 estimate as a personal trend, not a prediction.
The NodnWebTools Security+ study path
The overview, core notes, flashcards, and practice exams are all published.
200 original questions with custom exams, explanations, and an unofficial score on the 100-900 scale.
Frequently asked questions
How long is the Security+ SY0-701 exam?
CompTIA allows a maximum of 90 questions and 90 minutes. Questions are multiple choice and performance-based. Confirm the current details with CompTIA before you book.
What score do I need to pass Security+?
CompTIA publishes a passing score of 750 on a scale of 100 to 900 for SY0-701. This site converts a practice percentage linearly onto that scale and labels the result unofficial, because CompTIA does not publish the real conversion.
Which Security+ version is current?
This page follows exam objectives version 6.0 for SY0-701, which CompTIA calls Security+ V7. CompTIA has said Security+ V8 is expected on or around November 17, 2026. Confirm which exam code you will sit before you study or buy a voucher.
Does Security+ expire?
Yes. CompTIA certifications are valid for three years from the date you pass. Renewal options change, so confirm the current policy with CompTIA.
Are there prerequisites for Security+?
No prior certification is required. CompTIA recommends at least two years of experience in IT administration with a security focus, plus hands-on experience with technical information security.
Does this page include real CompTIA exam questions?
No. The practice questions on this site are original. They are not CompTIA exam items, and a practice score does not predict a result.
NodnWebTools provides general informational, educational, and convenience resources. Calculations, conversions, estimates, and learning materials may contain errors or become outdated. Financial, tax, medical, legal, and travel information is not professional advice. Verify important results and current requirements with qualified professionals or authoritative sources. Protect sensitive files and personal information, review each tool’s privacy limitations, and use only content you are authorized to process. You are responsible for how you use and share results. Study resources are independent and do not guarantee exam success or imply certification-provider endorsement. CompTIA and Security+ are trademarks of CompTIA, Inc. NodnWebTools is not affiliated with, endorsed by, or sponsored by CompTIA.