CompTIA Security+ (SY0-701) study guide
4 min read · Updated July 18, 2026 · AI-assisted, editorially reviewed
How to use this guide
Study time should follow the official weightings — the domain percentages below are where your marks actually come from. Work each domain in order, then use practice-exam scores per domain to decide where to double back.
The fastest feedback loop: read one domain’s focus areas, take a practice run, review every explanation for the questions you missed, and only then move on. Explanations teach the concept — skipping them is the most common way to plateau.
1. General Security Concepts
12% of the examKnow these cold:
- Security controls by type (preventive, detective, corrective, compensating) and category
- Zero trust: control plane vs data plane, policy engines and enforcement points
- Change management and its security impact
- Cryptographic concepts: PKI, key exchange, hashing, certificates
2. Threats, Vulnerabilities, and Mitigations
22% of the examKnow these cold:
- Threat actors and motivations; attack surfaces and vectors
- Social engineering: phishing, BEC, impersonation, urgency tactics
- Malware types and indicators; injection, traversal and memory attacks
- Supply chain risk and mitigation techniques (segmentation, hardening, patching)
3. Security Architecture
18% of the examKnow these cold:
- Cloud, hybrid, IoT/OT and virtualization security implications
- Segmentation, screened subnets, jump servers and zero-trust conduits
- Data protection: encryption states, masking, tokenization, DLP placement
- Resilience: backups (offline/immutable), HA, failover design
4. Security Operations
28% of the examKnow these cold:
- Incident response lifecycle — containment before eradication, evidence handling
- Detection: SIEM correlation, impossible travel, log analysis
- Vulnerability management: scanning, triage, false positives, remediation SLAs
- Identity operations: MFA methods and fatigue attacks, access reviews, email authentication (SPF/DKIM/DMARC)
5. Security Program Management and Oversight
20% of the examKnow these cold:
- Risk: register, appetite, ALE/SLE/ARO, responses (transfer, accept, mitigate, avoid)
- Governance documents: policy vs standard vs procedure vs guideline
- Third-party risk: SOC 2 review, vendor assessment, right-to-audit
- Awareness programs, tabletop exercises, RTO/RPO and continuity metrics
Common mistakes
- Studying domains evenly when the weightings are 12/22/18/28/20 — Security Operations alone is more than a quarter of the exam.
- Memorising port numbers and acronyms but skipping scenario judgment; SY0-701 leans hard on "what should you do NEXT" questions.
- Ignoring the governance domain (20%) because it feels non-technical — risk math (ALE = SLE × ARO), document types and third-party assessment are reliable marks.
- Leaving performance-based questions to burn time at the start — flag them, finish the multiple choice, then return.
- Confusing similar controls under pressure: compensating vs corrective, masking vs tokenization, SPF vs DKIM vs DMARC. Drill the contrasts, not the definitions.
Exam-day tips
- PBQs come first: if one takes more than ~3 minutes, flag it and move on — the multiple choice behind it is faster scoring.
- Budget one minute per question; the 90-minute clock is comfortable only if you don't stall.
- Answer from the scenario's constraints, not your own workplace habits — the exam rewards the best answer among the four given.
- Eliminate the two clearly-wrong options first; most items come down to a judgment call between two plausible ones.
- Watch for scope words in the stem (FIRST, BEST, MOST likely) — they change which answer is correct.
- You get a pencil-board or digital scratch area: dump the risk formulas onto it in the first minute.
How to know you’re ready
One good practice score can be luck. The signal that holds up: consistently at or above the real pass mark (750 on a 100–900 scale (≈ 83%)) across multiple full-length sets, with no single domain dragging far below the rest. Kwizza tracks your per-domain readiness automatically as you practice.
Free, full-length, weighted to the official blueprint — every answer explained.
Start the Security+ practice exam →