
CompTIA Security+ SY0-701 Study Guide & Exam Tips
CompTIA Security+ (SY0-701) tests five security domains, weighted from 12% to 28%, with up to 90 multiple-choice and performance-based questions in 90 minutes. You need a scaled score of 750 out of 900 to pass. This guide walks through what’s actually inside each domain, how to study it differently from the others, and whether SY0-701 is still the version you should be preparing for right now.
If you want a week-by-week study calendar, a performance-based question (PBQ) pacing strategy, and the mistakes that sink most first-time candidates, our companion guide — How to Pass the CompTIA Security+ Exam on Your First Attempt — covers that ground in detail. Use this article as the domain-by-domain reference to study alongside it.
SY0-701 at a Glance
| Detail | Current information |
| Exam code | SY0-701 (CompTIA labels it internally as “V7”) |
| Question format | Multiple-choice and performance-based questions |
| Number of questions | Up to 90 |
| Time limit | 90 minutes |
| Passing score | 750, on a scale of 100–900 |
| Certification validity | 3 years, renewable through continuing education |
| Delivery | Pearson VUE test center or online proctored |
| Recommended background | CompTIA Network+ and roughly 2 years in a security or systems administration role — recommended, not required |
| Exam voucher cost | Rose to $439 USD in the US after CompTIA’s June 2026 price update. Pricing varies by region and changes over time, so confirm the current figure before you buy. |
Security+ also maps to a range of cyber work roles under the Department of Defense’s DoD 8140 workforce framework — the newer name for what many federal and contractor job postings still describe as “DoD 8570 compliant.”
Is SY0-701 Still the Right Exam to Study For?
Yes — with one thing worth knowing before you commit to a timeline. CompTIA’s own Security+ certification page lists an estimated retirement window of 2026 for SY0-701, three years after its November 2023 launch. As of this writing, CompTIA has not published a public announcement naming a successor exam, a confirmed retirement date, or new pricing.
That said, training providers and members of the CompTIA Instructors Network have discussed a next-generation exam — widely referred to informally as SY0-801, though CompTIA has not confirmed that code — with a possible preview release around October 2026 and broader availability in late 2026 or early 2027, reportedly built around new objectives covering AI-related threats. Treat this as industry reporting, not a confirmed CompTIA release.
In practice, this shouldn’t change your plans. SY0-701 is the only exam you can currently book; its study materials are mature, and whichever version you eventually sit, your certification stays valid for three years from your test date. If you’re on track to be exam-ready within the next few months, there’s little reason to wait on an update that hasn’t been officially announced. Before you lock in a study timeline, it’s still worth checking CompTIA’s Security+ certification page directly for the current status.
The Five SY0-701 Domains, Explained
Study time should follow domain weight, not an even split across all five. Here’s what’s actually inside each one and how to approach it differently.
Domain 1: General Security Concepts — 12%
This domain covers categories of security controls (technical, managerial, operational, and physical, applied as preventive, detective, corrective, deterrent, compensating, or directive), core principles like the CIA triad, non-repudiation, authentication/authorization/accounting (AAA), zero trust, and deception technology such as honeypots. It also covers the basics of change management for security-relevant changes and the building blocks of cryptography — PKI, encryption, hashing, digital signatures, and obfuscation.
How to study it: Treat this domain as the vocabulary and framework layer that resurfaces throughout the other four. Don’t stop at memorizing definitions — practice identifying which control type or cryptographic approach fits a given scenario. Knowing that a firewall rule and a SIEM alert solve different kinds of problems (preventive vs. detective) matters more than reciting the CIA triad.
Domain 2: Threats, Vulnerabilities, and Mitigations — 22%
This domain covers threat actor types and motivations, common attack vectors and attack surfaces (social engineering, supply chain, network-based, message-based), categories of vulnerabilities (application, cloud, mobile, OS, hardware), recognizing malicious activity (malware, password attacks, application attacks, network and physical attacks), and mitigation techniques like segmentation, hardening, and patching.
How to study it: This is one of the two heaviest-weighted domains, so build recognition skills, not just recall. Practice matching a described scenario — say, a spike in outbound traffic at 2 a.m. — to the correct threat category, rather than only memorizing a list of attack names.
Domain 3: Security Architecture — 18%
This domain covers architecture models (cloud, on-premises, virtualization, IoT, industrial control systems, infrastructure as code), applying security principles to enterprise infrastructure, data protection and classification, and resilience and recovery concepts like high availability, backups, and continuity planning.
How to study it: Expect “best next step” scenario questions here rather than pure recall. Focus on trade-offs — why a team might choose a hybrid cloud model for one workload and full on-premises for another — rather than just labeling architecture diagrams.
Domain 4: Security Operations — 28%
The largest domain. It covers hardening and securing computing resources, asset management, the vulnerability management lifecycle, monitoring and alerting, core security tooling (firewalls, IDS/IPS, DLP, NAC, EDR/XDR), identity and access management (SSO, MFA, provisioning), automation and orchestration, and incident response and digital forensics.
How to study it: Performance-based questions concentrate most heavily here, so pair reading with actual practice. Work through log excerpts, firewall rule sets, and the correct order of incident-response steps — containment before eradication, eradication before recovery — instead of only reading about them.
Domain 5: Security Program Management and Oversight — 20%
This domain covers security governance and policy, risk management (identification, assessment, risk register, risk appetite and tolerance), third-party and vendor risk, compliance and privacy obligations, audits and assessments (including types of penetration testing), and security-awareness topics like phishing recognition.
How to study it: This domain rewards understanding process and sequence — why a vendor risk assessment happens before a contract is signed, for instance — more than memorizing terminology. Practice sequencing questions specifically.
Where to spend your limited time: Domains 2 and 4 together account for exactly half the exam. If your study time is tight, prioritize these two before rounding out the rest. How to Pass the CompTIA Security+ Exam on Your First Attempt has a full week-by-week plan built around this weighting.
Multiple-Choice vs. Performance-Based Questions
SY0-701 mixes standard multiple-choice questions with performance-based questions (PBQs) — interactive tasks like configuring a firewall rule, matching controls to a scenario, or reading a log to identify what happened. PBQs typically appear early in the exam and carry more weight in scoring than a single multiple-choice item.
If PBQs are new to you, budget separate, deliberate practice time for them. Reading about how to configure an access control list and actually doing it under time pressure are different skills, and they’re graded differently. How to Pass the CompTIA Security+ Exam on Your First Attempt covers a specific PBQ pacing strategy if you want tactics for exam day itself.
Do You Need Network+ First?
CompTIA recommends Network+ and about two years of security or systems administration experience before attempting Security+ — but neither is a hard prerequisite, and plenty of candidates pass without them. If you’re earlier in your IT path and unsure where to start, [Internal Link: CompTIA A+ vs Network+ 2026 – Which IT Cert to Start With → /blog/comptia/comptia-a-plus-vs-network-plus-2026] and [Internal Link: CompTIA Network+ N10-009 Study Guide – Pass Your Exam → /blog/comptia/comptia-network-plus-n10-009-exam-blueprint] can help you decide whether to build that foundation first or head straight into Security+ prep.
Study Resources Worth Using
Depth of practice matters more than the number of resources you collect. A short, well-used list beats a long, half-used one:
- CompTIA’s official exam objectives document. Free and the only complete list of what can appear on the exam. Download it first and use it as your checklist.
- A full video course covering all five domains. Professor Messer’s free SY0-701 course is the most widely used option in this category. Whichever you pick, confirm it’s built for SY0-701 specifically and not the retired SY0-601.
- Domain-specific practice questions with explanations, so you understand why a wrong answer is wrong, not just that it was wrong.
- A timed, full-length practice exam that includes PBQs, taken close to your test date to confirm readiness rather than to learn new material for the first time.
Cost, Vouchers, and Booking Your Exam
The SY0-701 voucher price rose in June 2026, along with the rest of CompTIA’s exam lineup. Buying through a discounted, verified voucher—rather than paying CompTIA’s list price directly—is one of the most straightforward ways to reduce that cost. Get your CompTIA Security+ (SY0-701) exam voucher has current pricing and what’s included, and CompTIA Exam Voucher 2026: Save Up to $110 walks through how to vet a voucher seller before buying from anyone.
Once you’re certified, Security+ stays valid for three years. Many candidates use it as a springboard to a more specialized certification — CompTIA Security+ vs CySA+ – Best Cybersecurity Cert 2026, if you’re weighing what comes next, or our CompTIA Exam Vouchers collection — which already stocks CySA+ and PenTest+ — if you already know your next exam.
For a broader look at why Security+ specifically is worth the investment, see Why CompTIA Security+ in 2026 Is a Career Game-Changer, and for how it fits alongside CompTIA’s other certifications, see Top 5 CompTIA Certifications to Boost Your IT Career in 2026.
Frequently Asked Questions
Is the CompTIA Security+ SY0-701 exam hard?
It’s a meaningful step up from A+ or Network+ because it tests applied judgment across five domains rather than straightforward recall, and because the performance-based questions require hands-on skill, not just knowledge. Candidates with some IT background who study systematically generally find it achievable.
How long does it take to prepare for SY0-701?
Most candidates with some IT experience spend several weeks to a few months, depending on background and hours available per week. Let domain weight guide how you split that time rather than following a flat schedule.
Do I need CompTIA Network+ before Security+?
No. CompTIA recommends Network+ and about two years of security or systems administration experience, but neither is required to register for the exam.
Is SY0-701 being replaced by a new exam?
Not officially, as of this writing. CompTIA’s own materials list an estimated 2026 retirement window, and industry reports point to a next-generation exam in development, but CompTIA has not confirmed a public announcement, exam code, or retirement date. Check CompTIA’s certification page for the current status before finalizing your study timeline.
What’s the difference between a multiple-choice question and a PBQ?
Multiple-choice questions ask you to select an answer; performance-based questions ask you to complete a simulated task, like configuring a setting or analyzing a log. PBQs carry more weight than a standard multiple-choice item.
Can I save money on the exam with a voucher?
Yes. A verified exam voucher covers the exam fee at a lower price than paying CompTIA directly. Get your CompTIA Security+ (SY0-701) exam voucher at current pricing.


