Skip to content

CompTIA · SY0-701 · Intermediate

CompTIA Security+ (SY0-701) study guide

4 min read · Updated July 18, 2026 · AI-assisted, editorially reviewed

How to use this guide

Give each domain study time in proportion to its official weighting. The percentages below are where your marks actually come from. Work through the domains in order, then let your per-domain practice scores show you what to go back to.

The fastest way to improve: read one domain’s focus areas, take a practice run, then read the explanation for every question you missed before moving on. The explanations are where the learning happens. Skipping them is the most common reason people stop improving.

1. General Security Concepts

12% of the exam

What to focus on:

  • Security controls by type (preventive, detective, corrective, compensating) and category
  • Zero trust: control plane vs data plane, policy engines and enforcement points
  • Change management and its security impact
  • Cryptographic concepts: PKI, key exchange, hashing, certificates

2. Threats, Vulnerabilities, and Mitigations

22% of the exam

What to focus on:

  • Threat actors and motivations; attack surfaces and vectors
  • Social engineering: phishing, BEC, impersonation, urgency tactics
  • Malware types and indicators; injection, traversal and memory attacks
  • Supply chain risk and mitigation techniques (segmentation, hardening, patching)

3. Security Architecture

18% of the exam

What to focus on:

  • Cloud, hybrid, IoT/OT and virtualization security implications
  • Segmentation, screened subnets, jump servers and zero-trust conduits
  • Data protection: encryption states, masking, tokenization, DLP placement
  • Resilience: backups (offline/immutable), HA, failover design

4. Security Operations

28% of the exam

What to focus on:

  • Incident response lifecycle: containment before eradication, evidence handling
  • Detection: SIEM correlation, impossible travel, log analysis
  • Vulnerability management: scanning, triage, false positives, remediation SLAs
  • Identity operations: MFA methods and fatigue attacks, access reviews, email authentication (SPF/DKIM/DMARC)

5. Security Program Management and Oversight

20% of the exam

What to focus on:

  • Risk: register, appetite, ALE/SLE/ARO, responses (transfer, accept, mitigate, avoid)
  • Governance documents: policy vs standard vs procedure vs guideline
  • Third-party risk: SOC 2 review, vendor assessment, right-to-audit
  • Awareness programs, tabletop exercises, RTO/RPO and continuity metrics

Common mistakes

  • Studying all five domains evenly. The weightings are 12/22/18/28/20, and Security Operations alone is more than a quarter of the exam.
  • Memorising ports and acronyms but skipping scenario judgment. SY0-701 is full of "what should you do NEXT" questions.
  • Skipping governance because it feels non-technical. It is 20% of the exam, and risk math (ALE = SLE x ARO), document types and third-party assessment are easy marks.
  • Grinding on the performance-based questions first. Flag them, finish the multiple choice, then come back.
  • Confusing similar controls under pressure: compensating vs corrective, masking vs tokenization, SPF vs DKIM vs DMARC. Drill the contrasts, not the definitions.

Exam-day tips

  • Flag any PBQ that runs past about 3 minutes. They come first, and the multiple choice behind them scores faster.
  • Budget one minute per question. The 90-minute clock is comfortable only if you never stall.
  • Answer from the scenario's constraints, not your own workplace habits. You are picking the best of the four options given.
  • Eliminate the two clearly wrong options first. Most items come down to a judgment call between the remaining two.
  • Watch the scope words in the stem. FIRST, BEST and MOST likely change which answer is correct.
  • Dump the risk formulas onto your scratch area in the first minute. You get a pencil board or a digital equivalent.

How to know you’re ready

One good practice score can be luck. What counts is scoring at or above the real pass mark (750 on a 100 to 900 scale) across several full-length sets in a row, with no single domain trailing far behind the others. Kwizza tracks your per-domain readiness automatically as you practice.

Free, full-length, and weighted to the official blueprint. Every answer is explained.

Start the Security+ practice exam →

Written against CompTIA’s officially published exam objectives; last reviewed July 18, 2026. AI-assisted and editorially reviewed. See how our exams are made.

Kwizza is an independent study tool and is not affiliated with, endorsed by, or sponsored by CompTIA. CompTIA names, logos and certification marks are the property of their respective owners and are used here only to identify the exam described. Practice questions are original, written against the publicly published exam objectives. No real exam content is reproduced.