CompTIA Security+ study guide
Security+ is the most common entry point into cybersecurity. It validates the baseline skills needed for roles like security analyst, SOC analyst, and systems administrator, and it meets U.S. DoD 8140 requirements for many positions.
Exam details change. Always confirm the current exam version, objectives, length, and passing score on the certification body's official website before you schedule.
Eligibility
There are no formal prerequisites. Anyone can register. CompTIA recommends Network+ and about two years of IT administration experience with a security focus, but neither is required.
Exam format & cost
| Current exam | SY0-701 |
|---|---|
| Length | Up to 90 questions, 90 minutes, multiple choice plus performance-based questions |
| Passing score | 750 on a 100–900 scale |
| Exam fee | About $425–$439 (US). CompTIA reportedly raised prices in mid-2026. |
| Validity | 3 years from your exam date |
| Renewal | 50 continuing education units (CEUs) plus an annual CE fee (about $50/year), or earn a qualifying higher certification |
| Recognition | Meets U.S. DoD 8140 requirements for many roles |
Version change ahead: several training providers report that the next version, SY0-801, is expected in late 2026 and that SY0-701 will retire around mid-2027. As of October 2026 these dates aren't consistently confirmed, so check CompTIA's Security+ page. A certification earned on either version is valid for the full three years.
Performance-based questions (PBQs) are hands-on simulations, such as configuring a firewall rule or matching attacks to mitigations.
The five domains
| Domain | Weight |
|---|---|
| 1.0 General Security Concepts | 12% |
| 2.0 Threats, Vulnerabilities, and Mitigations | 22% |
| 3.0 Security Architecture | 18% |
| 4.0 Security Operations | 28% |
| 5.0 Security Program Management and Oversight | 20% |
Handling performance-based questions
PBQs usually appear at the start of the exam and can eat up your time. Many test-takers flag them, answer all the multiple-choice questions first, and then come back with the remaining time. Partial credit is generally possible, so attempt every part.
High-yield topics
- Social engineering variants: phishing, smishing, vishing, whaling, pretexting, and watering hole attacks.
- Malware types and their indicators: ransomware, trojans, worms, rootkits, and logic bombs.
- Application attacks: injection, XSS, CSRF, buffer overflow, and race conditions.
- Cryptography basics: hashing vs. encryption, salting, PKI, certificates, and OCSP vs. CRL.
- The incident response process and the order of volatility.
- Common ports and secure protocol replacements (SSH, SFTP, LDAPS, HTTPS, SNMPv3).
- Cloud shared responsibility and zero trust concepts.
Six-week plan
- Weeks 1–2: Domains 1 and 2. Learn the vocabulary, because Security+ is very terminology-heavy.
- Weeks 3–4: Domains 3 and 4. Security Operations is the biggest domain, so give it extra time.
- Week 5: Domain 5 (governance, risk, compliance, and third-party risk).
- Week 6: Timed mixed sessions daily. Aim for a consistent 85%+ in practice before booking.
Ready to test yourself on Security+?
Start Security+ practice