CompTIA logo

CompTIA Security+ (SY0-701) study guide

4 min read · Updated July 18, 2026 · AI-assisted, editorially reviewed

SY0-701Intermediate

How to use this guide

Study time should follow the official weightings — the domain percentages below are where your marks actually come from. Work each domain in order, then use practice-exam scores per domain to decide where to double back.

The fastest feedback loop: read one domain’s focus areas, take a practice run, review every explanation for the questions you missed, and only then move on. Explanations teach the concept — skipping them is the most common way to plateau.

1. General Security Concepts

12% of the exam

Know these cold:

  • Security controls by type (preventive, detective, corrective, compensating) and category
  • Zero trust: control plane vs data plane, policy engines and enforcement points
  • Change management and its security impact
  • Cryptographic concepts: PKI, key exchange, hashing, certificates

2. Threats, Vulnerabilities, and Mitigations

22% of the exam

Know these cold:

  • Threat actors and motivations; attack surfaces and vectors
  • Social engineering: phishing, BEC, impersonation, urgency tactics
  • Malware types and indicators; injection, traversal and memory attacks
  • Supply chain risk and mitigation techniques (segmentation, hardening, patching)

3. Security Architecture

18% of the exam

Know these cold:

  • Cloud, hybrid, IoT/OT and virtualization security implications
  • Segmentation, screened subnets, jump servers and zero-trust conduits
  • Data protection: encryption states, masking, tokenization, DLP placement
  • Resilience: backups (offline/immutable), HA, failover design

4. Security Operations

28% of the exam

Know these cold:

  • Incident response lifecycle — containment before eradication, evidence handling
  • Detection: SIEM correlation, impossible travel, log analysis
  • Vulnerability management: scanning, triage, false positives, remediation SLAs
  • Identity operations: MFA methods and fatigue attacks, access reviews, email authentication (SPF/DKIM/DMARC)

5. Security Program Management and Oversight

20% of the exam

Know these cold:

  • Risk: register, appetite, ALE/SLE/ARO, responses (transfer, accept, mitigate, avoid)
  • Governance documents: policy vs standard vs procedure vs guideline
  • Third-party risk: SOC 2 review, vendor assessment, right-to-audit
  • Awareness programs, tabletop exercises, RTO/RPO and continuity metrics

Common mistakes

  • Studying domains evenly when the weightings are 12/22/18/28/20 — Security Operations alone is more than a quarter of the exam.
  • Memorising port numbers and acronyms but skipping scenario judgment; SY0-701 leans hard on "what should you do NEXT" questions.
  • Ignoring the governance domain (20%) because it feels non-technical — risk math (ALE = SLE × ARO), document types and third-party assessment are reliable marks.
  • Leaving performance-based questions to burn time at the start — flag them, finish the multiple choice, then return.
  • Confusing similar controls under pressure: compensating vs corrective, masking vs tokenization, SPF vs DKIM vs DMARC. Drill the contrasts, not the definitions.

Exam-day tips

  • PBQs come first: if one takes more than ~3 minutes, flag it and move on — the multiple choice behind it is faster scoring.
  • Budget one minute per question; the 90-minute clock is comfortable only if you don't stall.
  • Answer from the scenario's constraints, not your own workplace habits — the exam rewards the best answer among the four given.
  • Eliminate the two clearly-wrong options first; most items come down to a judgment call between two plausible ones.
  • Watch for scope words in the stem (FIRST, BEST, MOST likely) — they change which answer is correct.
  • You get a pencil-board or digital scratch area: dump the risk formulas onto it in the first minute.

How to know you’re ready

One good practice score can be luck. The signal that holds up: consistently at or above the real pass mark (750 on a 100–900 scale (≈ 83%)) across multiple full-length sets, with no single domain dragging far below the rest. Kwizza tracks your per-domain readiness automatically as you practice.

Free, full-length, weighted to the official blueprint — every answer explained.

Start the Security+ practice exam →

Written against CompTIA’s officially published exam objectives; last reviewed July 18, 2026. AI-assisted and editorially reviewed — see how our exams are made.

Kwizza is an independent study tool and is not affiliated with, endorsed by, or sponsored by CompTIA. CompTIA names, logos and certification marks are the property of their respective owners and are used here only to identify the exam described. Practice questions are original, written against the publicly published exam objectives — no real exam content is reproduced.