CompTIA Security+ (SY0-701) exam objectives
CompTIA publishes 5 exam domains with official weightings. The weight tells you where your marks come from — study time should roughly follow it.
SY0-701Intermediate
1. General Security Concepts
12%- Security controls by type (preventive, detective, corrective, compensating) and category
- Zero trust: control plane vs data plane, policy engines and enforcement points
- Change management and its security impact
- Cryptographic concepts: PKI, key exchange, hashing, certificates
2. Threats, Vulnerabilities, and Mitigations
22%- Threat actors and motivations; attack surfaces and vectors
- Social engineering: phishing, BEC, impersonation, urgency tactics
- Malware types and indicators; injection, traversal and memory attacks
- Supply chain risk and mitigation techniques (segmentation, hardening, patching)
3. Security Architecture
18%- Cloud, hybrid, IoT/OT and virtualization security implications
- Segmentation, screened subnets, jump servers and zero-trust conduits
- Data protection: encryption states, masking, tokenization, DLP placement
- Resilience: backups (offline/immutable), HA, failover design
4. Security Operations
28%- Incident response lifecycle — containment before eradication, evidence handling
- Detection: SIEM correlation, impossible travel, log analysis
- Vulnerability management: scanning, triage, false positives, remediation SLAs
- Identity operations: MFA methods and fatigue attacks, access reviews, email authentication (SPF/DKIM/DMARC)
5. Security Program Management and Oversight
20%- Risk: register, appetite, ALE/SLE/ARO, responses (transfer, accept, mitigate, avoid)
- Governance documents: policy vs standard vs procedure vs guideline
- Third-party risk: SOC 2 review, vendor assessment, right-to-audit
- Awareness programs, tabletop exercises, RTO/RPO and continuity metrics
Our practice exam distributes its questions across these exact domains at these weightings — so your score per domain tells you precisely where you stand.
Practice these objectives free →