CompTIA Security+ Master Guide 2026
CompTIA Security+ tests baseline security skills across five areas: security concepts, threats and mitigations, architecture, operations, and program oversight.
- The current SY0-701 objectives describe a 90-minute exam with up to 90 multiple-choice and performance-based questions.
- There is no formal work-experience prerequisite listed in the saved official objective source; practical familiarity helps, but it is a preparation advantage rather than an entry gate.
On this page13 sections
- What the exam covers
- Format and time
- Eligibility and readiness
- How to study the five domains
- Original sample question
- A practical study sequence
- How to judge readiness
- Reason from the risk to the control
- Connect common terms to decisions
- Use the blueprint to allocate effort
- Make practice review count
- What Security+ can and cannot show
- Fees, results, and maintenance
Security+ is a vendor-neutral baseline cybersecurity certification from CompTIA. It is designed to assess whether a candidate can recognize common security risks, choose sensible controls, support secure operations, and contribute to a security program. It does not certify a person for a regulated occupation or prove mastery of every specialty. Think of it as evidence of broad foundational knowledge, then assess practical skill and role fit separately.
What the exam covers
The current SY0-701 objectives organize the exam into five weighted domains. The percentages show relative emphasis in the blueprint, not a guarantee of the exact number of questions in each category. Performance-based questions can combine multiple skills, so an operational scenario may involve architecture, risk, and incident response at once.
| Domain | Weight | What you need to do |
|---|---|---|
| General Security Concepts | 12% | Explain control types, security principles, cryptographic ideas, and the purpose of common controls. |
| Threats, Vulnerabilities, and Mitigations | 22% | Recognize threat actors and attack patterns, interpret indicators, assess vulnerabilities, and choose proportionate mitigations. |
| Security Architecture | 18% | Select secure designs for networks, cloud, applications, and systems; understand resilience, segmentation, and data handling. |
| Security Operations | 28% | Apply operational controls for identity, monitoring, vulnerability management, incident response, and recovery. |
| Security Program Management and Oversight | 20% | Understand governance, policy, risk, third-party oversight, awareness, audits, and compliance concepts. |
Security Operations has the largest published weight, but studying only that domain would be a mistake. The remaining four together account for most of the blueprint. A candidate should know enough governance to understand why a control exists, enough architecture to place it correctly, and enough operations to test whether it is working.
Format and time
The official objective PDF states a maximum of 90 questions and a 90-minute appointment. It lists multiple-choice and performance-based questions. That establishes the broad question families, not a fixed count of each, a precise live interface, or an exact allocation by domain. Do not assume that every task can be solved by recalling a term. Security work often requires choosing a sequence, prioritizing an action, interpreting a log, or matching a control to a risk.
At the maximum question count, 90 minutes averages one minute per item. Some questions will take seconds; a scenario with several details may take longer. Read the task verb carefully: identify, implement, investigate, contain, or recover point to different stages of work. Before choosing a control, identify the asset, the exposure, the objective, and the constraints. If a question describes a suspected compromise, containment and evidence preservation may both matter, but the requested goal determines which action comes first.
Eligibility and readiness
The saved official objectives describe recommended experience, including roughly two years of IT administration with a security focus and hands-on technical security experience. This is preparation guidance, not a registration prerequisite. The objective source does not establish a degree requirement or require another certification before taking the exam. A newcomer can study the material, but should budget time to learn networking, operating systems, identity, and basic risk concepts before relying on timed practice.
Separate three questions. Eligibility asks whether the testing process permits you to book and sit. Readiness asks whether you can reason through the objectives under timed conditions. Certification status asks whether you passed and fulfilled any steps required by CompTIA to hold the credential. A recommendation about experience should not be mistaken for a barrier to registration, and passing an exam should not be confused with proof of job performance.
How to study the five domains
Start with assets, threats, and controls
Security decisions begin with context. Identify what must be protected, who may affect it, how an attack could occur, and what outcome the organization needs. A control is useful when it reduces a relevant risk at a reasonable cost. For example, multifactor authentication can reduce account takeover risk, but it does not prevent a vulnerable public service from being exploited. A firewall rule can restrict network paths, but it cannot decide whether an employee should have access to sensitive records. The exam rewards choosing a control that addresses the described cause rather than naming a familiar technology.
Learn threat patterns through their evidence
For each common attack type, learn its preconditions, observable evidence, likely impact, and practical mitigation. Phishing relies on persuading a person to act; credential stuffing reuses known username and password pairs; ransomware may encrypt data and disrupt operations; a denial-of-service attack targets availability. Connect each pattern to logs and controls. Repeated failed logins across many accounts suggest a different investigation from a single user reporting a suspicious attachment. Avoid memorizing isolated labels without understanding what an analyst would see.
Build architectural intuition
Architecture questions ask where controls belong and how design limits blast radius. Segmentation can constrain lateral movement. A secure cloud design still needs identity, logging, configuration management, backup, and data-protection choices. Encryption protects confidentiality in transit or at rest, but key ownership, access, rotation, and recovery remain operational concerns. High availability reduces outage risk, while backups support restoration after data loss; neither is a substitute for the other.
Treat operations as a lifecycle
Operational security is more than monitoring. A mature cycle identifies assets, establishes baselines, detects deviations, triages alerts, contains incidents, removes causes, recovers service, and learns from the event. Vulnerability management similarly requires inventory, prioritization, remediation, and verification. A scanner finding is not automatically the most urgent issue: exploitability, exposure, asset importance, and compensating controls affect priority. Record decisions so teams can explain why a risk was accepted, mitigated, or deferred.
Connect governance to daily work
Policies state expectations; standards make them specific; procedures explain repeatable steps; guidelines offer recommendations. Risk owners make decisions about business exposure, while security teams advise and operate controls. Third-party oversight asks what data and access a supplier receives, how the supplier protects it, and what happens when the relationship ends. Compliance asks whether applicable requirements are met; it does not automatically prove that the organization is secure.
Original sample question
A monitoring system reports that a user account has authenticated from two distant locations within a short period. The user confirms they did not travel and does not recognize one login. Which action best reduces immediate risk while preserving a sound investigation?
- Disable or temporarily lock the account, revoke active sessions, and preserve the authentication records for investigation.
- Delete the account and all of its logs so the attacker cannot reuse them.
- Ignore the alert because valid credentials were presented.
- Rebuild every workstation before determining whether the account was compromised.
Answer: A. The account may be compromised even though authentication succeeded. Restricting access and revoking sessions addresses immediate exposure; retaining logs supports investigation and helps determine scope. Deleting evidence destroys useful records, while valid credentials do not establish that the legitimate user performed the login. Rebuilding all endpoints is broad and unsupported before evidence identifies endpoint compromise.
A practical study sequence
Begin by reading the objective list and marking each task as familiar, partly understood, or new. Use the weights to plan time, then let diagnostic results adjust the plan. A four-week schedule can work for someone with relevant experience and steady study hours; a beginner may need a longer foundation phase. Calendar length alone does not predict readiness. The key is repeated retrieval and scenario application, not passive hours with videos.
- Week 1: map the objectives, refresh networking and security fundamentals, and create a glossary in your own words. Practice explaining why controls work.
- Week 2: focus on threats, vulnerabilities, and architecture. For each scenario, identify the likely attack path, impact, and control that breaks the path.
- Week 3: study operations and incident response. Work through alert triage, identity decisions, vulnerability prioritization, backup recovery, and evidence handling.
- Week 4: cover governance and oversight, then revisit weak areas with mixed questions. Review every wrong answer by explaining why the best choice fits the objective and why each distractor fails.
Keep a decision log. For every missed question, record the cue you overlooked, the concept involved, and the next step you would take in a real environment. If you missed a question because you chose eradication before containment, write a short incident timeline. If you missed a risk question, distinguish likelihood, impact, control effectiveness, and ownership. This turns mistakes into reusable reasoning rather than a list of answers to memorize.
How to judge readiness
Readiness means more than recognizing vocabulary. You should be able to explain the objective, select an action in an unfamiliar but bounded situation, and defend your choice against plausible alternatives. Practice under timed conditions after learning, not before you understand the material. A score on a third-party quiz is a diagnostic for that quiz; it is not an official prediction unless the provider has validated such a relationship, and no such relationship is established in the saved official source.
Use a three-part check. First, can you explain the major concepts without looking at notes? Second, can you apply them to different contexts, such as a small business, a cloud service, or a regulated data set? Third, can you make a decision when two options sound reasonable by identifying the question's actual objective and constraints? If one domain remains weak, spend targeted time there and then retest with fresh scenarios.
Reason from the risk to the control
A reliable way to solve security scenarios is to reason in order. Name the asset and the security property at risk. Identify the threat or failure path. Choose a control that interrupts that path. Then decide how to verify the control and what operational side effect it may create. This method prevents answers that sound technical but do not solve the stated problem. If the concern is unauthorized disclosure, availability measures alone are insufficient. If the concern is an outage, stronger encryption may have little direct effect.
Consider a file share containing payroll data. An employee needs access for a defined task, while a contractor should not see the records. A sensible design separates identity proof from authorization, grants the employee only the needed group access, reviews the contractor's account lifecycle, and records access events. Encryption can protect stored or transmitted data, but it does not correct excessive permissions. Logging can support detection, but it does not itself prevent a disclosure. A strong answer understands the control's boundary.
This reasoning also helps with tradeoffs. A control can reduce risk while adding cost, delay, or complexity. Multifactor authentication may add a step to sign-in, but can materially reduce the value of a stolen password. A strict network restriction may reduce exposure but break a legitimate workflow. A good security process evaluates impact, documents an exception, assigns an owner, and sets a review date rather than silently weakening the control forever.
Connect common terms to decisions
| Concept | Practical question | Common reasoning error |
|---|---|---|
| Least privilege | What access does this task actually require, and when should it end? | Giving broad permanent rights because they are convenient. |
| Defense in depth | Which independent layers reduce the chance or impact of compromise? | Assuming one control makes the system secure. |
| Segmentation | Which paths should be possible between systems? | Treating internal network location as proof of trust. |
| Cryptographic key management | Who can use or recover the key, and how is access controlled? | Assuming encrypted data is safe regardless of key exposure. |
| Risk acceptance | Who owns the decision and when will it be reviewed? | Confusing an undocumented exception with a control. |
| Incident evidence | What records help establish scope and sequence? | Erasing logs or rebuilding systems before preserving needed evidence. |
The point is not to memorize a universal first action for every incident. The best action depends on the objective, severity, and stage. For suspected data exfiltration, containing access and preserving relevant evidence matter. For a service outage, recovery priorities may dominate after safety and evidence requirements are addressed. Read the scenario for the requested outcome and choose the narrowest effective action that does not destroy information needed for the next step.
Use the blueprint to allocate effort
A domain percentage is a planning signal, not a promise about exact question counts. If you have ten study sessions, assigning one session to each domain is a simple starting point, but the 28% Operations domain deserves more practice time than its 12% general-concepts share. A reasonable adjustment is to devote three sessions to operations, two each to threats and program oversight, and the remaining sessions to architecture and general concepts, then change that plan based on diagnostics. Do not leave any domain untouched because it has a smaller weight.
Within a domain, weight alone is still not enough. A learner who works in endpoint administration may need more time on governance or cloud architecture. A software developer may know application risks but need incident response and identity lifecycle. Keep a simple tracker with each objective, your confidence, and one piece of evidence that you can apply it. Evidence might be a correct explanation, a lab observation, or a scenario decision with a complete rationale.
A useful weekly rhythm alternates learning and retrieval. Spend one session learning a concept, another explaining it from memory, and another applying it in a different setting. For example, study access control, then explain how a user gets permissions in a small office, then analyze an employee moving teams in a cloud service. The change in context exposes whether you understand the principle or only remember one example.
Make practice review count
After answering a question, review the reasoning even when you chose correctly. You may have guessed or relied on a cue that will not transfer. Write one sentence for why the best answer fits, then identify why each tempting alternative is weaker. If the item asks what to do first, alternatives may all be reasonable later actions. Mark the stage of work: prevention, detection, analysis, containment, eradication, recovery, or lessons learned.
Avoid memorizing leaked or recalled exam questions. CompTIA prohibits unauthorized third-party training materials such as brain dumps. Besides the policy risk, recalled items do not build the ability to interpret a new scenario. Use legitimate materials and original practice that teaches the concepts. A question bank is useful when explanations teach why a control fits the problem; a large question count alone does not demonstrate quality.
For performance-based work, practice with safe labs or written tasks that ask you to interpret artifacts, order actions, map controls, or configure a permitted environment. Do not claim that a home lab reproduces the exam interface unless the training provider can substantiate it. Practice the underlying skills: read the prompt, identify required output, avoid changing unrelated settings, and verify that the result addresses the stated need.
What Security+ can and cannot show
A passing result demonstrates a baseline across a broad security outline. It can support an early-career application, help structure learning, or provide a common vocabulary for security work. It does not establish years of experience, authorize penetration testing, replace role-specific training, or guarantee employment. Employers may require practical experience, background checks, other credentials, or skills that are outside this exam. Describe the credential accurately and pair it with projects or work examples that show what you can do.
Security work also includes judgment and communication. A technically correct control can fail if it is not usable, maintained, or accepted by the people who must operate it. When explaining a recommendation, state the risk, the expected benefit, the operational cost, and how success will be checked. This habit helps with exam scenarios and with real security conversations.
Fees, results, and maintenance
CompTIA lists a U.S./North America standard Security+ voucher at US$439 and a Voucher Plus Retake Assurance product at US$579. The passing score is 750 on a 100 to 900 scale, which is not a raw percentage-correct requirement. English SY0-701 is scheduled to retire June 11, 2027. CompTIA lists 50 CEUs over three years and a US$150 total CE fee to maintain Security+ through continuing education. These are scoped U.S./North America product prices and current maintenance terms; regional checkout can differ. The next version, SY0-701 V8, is expected to launch around November 17, 2026, so candidates should match their materials to the version they book.
A retake is allowed with no waiting period between the first and second attempts; wait at least 14 calendar days before a third or later attempt. A full exam fee applies to each attempt unless a purchased retake-assurance product covers it under its terms. The standard U.S./North America voucher is listed at US$439, and the assurance package at US$579; neither price includes study resources or travel.
Common questions
How many questions are on Security+?
The official SY0-701 objective document gives a maximum of 90 questions, not a guaranteed fixed count.
How long is the exam?
The official objective document specifies 90 minutes.
Is work experience required?
The saved objective source describes recommended experience, not a registration prerequisite.
What domains should I prioritize?
Security Operations has the largest weight at 28%, followed by Threats, Vulnerabilities, and Mitigations at 22%; all five domains matter.