SY0-701 · General Security Concepts · Updated July 26, 2026
CompTIA Security+ (SY0-701) Study Guide: Format, Domains, Cost, and How to Pass
CompTIA Security+ (SY0-701) is the industry’s most widely held entry-level cybersecurity certification: a single 90-minute exam of up to 90 questions covering security concepts, threats, architecture, operations, and program management. It’s designed for people moving into security roles — help desk technicians, junior sysadmins, career changers, and anyone who needs a DoD 8140-recognized baseline credential. There are no formal prerequisites, though CompTIA recommends Network+ knowledge and about two years of security-focused IT experience. Passing requires a scaled score of 750 on a 100–900 scale, and most well-prepared candidates get there in four to eight weeks of structured, practice-driven study.
What the Security+ exam looks like
Before you build a study plan, you need an accurate picture of what you’re walking into. Here are the verified facts for SY0-701:
- Question count: up to 90 questions. Most candidates see fewer — somewhere in the 70s or 80s is common — because performance-based questions count more heavily toward the total.
- Question types: multiple-choice (single answer and multiple response) plus performance-based questions (PBQs). PBQs are interactive scenarios — you might drag attack names onto descriptions, configure a firewall rule set, or match controls to requirements in a simulated environment.
- Time limit: 90 minutes total. That includes the PBQs, which is why time management matters so much (more on that below).
- Scoring: scaled from 100 to 900, with 750 required to pass.
- Cost: the exam voucher is $439 USD at US pricing. Retakes cost the same, so a failed attempt is an expensive lesson — budget for one serious attempt, not two casual ones.
- Prerequisites: none. You can register and sit the exam tomorrow if you want. CompTIA recommends Network+ certification and roughly two years of IT administration with a security focus, but plenty of candidates pass without either.
- Certification lifespan: three years from your pass date, renewable through CompTIA’s Continuing Education (CE) program — earning CEUs through training, higher-level certifications, or work activities — rather than retaking the exam.
The single most important thing to internalize about this exam: it is a reading comprehension and discrimination test as much as a knowledge test. Most questions present a scenario and ask for the “BEST” or “MOST likely” answer among several technically plausible options. Knowing definitions isn’t enough; you have to recognize which concept a scenario is describing and which control fits the constraint the question sets up.
The five SY0-701 domains
SY0-701 organizes its objectives into five domains. The weights tell you where the questions come from — and where your study hours should go.
| # | Domain | Weight |
|---|---|---|
| 1 | General Security Concepts | 12% |
| 2 | Threats, Vulnerabilities, and Mitigations | 22% |
| 3 | Security Architecture | 18% |
| 4 | Security Operations | 28% |
| 5 | Security Program Management and Oversight | 20% |
Domain 1: General Security Concepts (12%) is the vocabulary layer everything else builds on: the CIA triad (confidentiality, integrity, availability), control categories (technical, managerial, operational, physical) and control types (preventive, detective, corrective, deterrent, compensating, directive), zero trust, physical security, and change management. It’s the smallest domain by weight, but its concepts appear inside questions from every other domain, so weak fundamentals here cost you points everywhere.
Domain 2: Threats, Vulnerabilities, and Mitigations (22%) covers the adversary’s side of the board: threat actor types and motivations, attack surfaces and vectors, social engineering, malware families, application and network attacks, and the mitigations that counter each. Expect scenario questions that describe an attack in progress and ask you to name it — or name the control that would have stopped it. This is the domain where precise discrimination between similar-sounding attacks (phishing vs. smishing vs. vishing, DNS poisoning vs. domain hijacking) pays off.
Domain 3: Security Architecture (18%) is about designing secure environments: cloud and on-premises architecture models, infrastructure considerations (network appliances, port security, firewall types), secure communications (VPNs, TLS, SD-WAN), data protection strategies, and resilience — backups, redundancy, high availability, and recovery sites. Questions here often hand you business requirements and ask which architecture or placement decision satisfies them.
Domain 4: Security Operations (28%) is the heavyweight — more than a quarter of the exam. It covers the day-to-day work of security: hardening and baselines, asset and vulnerability management, monitoring and alerting tools, identity and access management, automation, incident response, and using logs and data sources to support investigations. If you’re short on time, this is the domain you cannot afford to under-study. It’s also the most PBQ-friendly territory: log analysis, firewall rules, and tool output interpretation all live here.
Domain 5: Security Program Management and Oversight (20%) covers governance, risk, and compliance (GRC): policies and standards, risk management processes (risk register, assessment types, risk appetite), third-party risk, compliance and audit concepts, and security awareness training. Candidates from technical backgrounds routinely underestimate this domain and get hurt by it — a fifth of the exam is essentially “the business side of security,” and the terminology (SLA vs. MOU vs. MSA, qualitative vs. quantitative risk) is exact and testable.
A study plan that works
The single biggest predictor of passing is not hours logged watching videos — it’s the number of realistic practice questions you’ve answered and reviewed. The plan below is built around that fact. It runs four to eight weeks depending on your background; someone with hands-on IT experience can compress it, and a career changer should stretch it.
Week 1: Diagnose before you study. Take a full-length practice test cold, before you’ve studied anything. This feels backwards and the score will sting — that’s fine. The point isn’t the score; it’s the domain-by-domain breakdown. You’ll discover you already know more than you think in some areas (usually networking-adjacent topics) and less than you think in others (usually GRC). Write down your per-domain percentages. This is your map for the next several weeks, and it stops you from spending ten hours re-learning things you already know.
Weeks 2–4: Study your weak domains, in weight order. Attack the intersection of “low diagnostic score” and “high exam weight” first — for most people that means Domain 4 (Security Operations) and Domain 2 (Threats). Study actively, not passively: for every topic, work practice questions on that topic the same day you study it, and read the explanations for every question — including the ones you got right, because confirming your reasoning matters as much as fixing your errors.
As you work through the objectives, go deep on the topics the exam loves to test as discriminations:
- Detection and prevention technology: understand the difference between an IDS and an IPS, why signature-based detection misses novel attacks while behavioral analysis catches them, and how sensor placement changes what a tool can do.
- Network access control: 802.1X port-based authentication and its accommodations for devices that can’t authenticate is a recurring scenario pattern.
- Wireless security: know WPA3 and SAE cold, including what SAE fixes about WPA2’s four-way handshake, and the real risks of public Wi-Fi like evil twins and rogue access points.
- Attack identification: be able to recognize privilege escalation (vertical vs. horizontal), DNS poisoning and hijacking, and keyloggers from a two-sentence scenario description.
- Compliance mechanics: for Domain 5, understand how PCI DSS assessments work and why organizations move toward continuous compliance monitoring instead of point-in-time audits.
Weeks 4–6: Drill by domain, then mixed. Once you’ve covered your weak areas, shift the ratio from studying to drilling. Run domain-specific question sets until you’re consistently scoring 85%+ in each domain, then switch to mixed sets that pull from all five — because the real exam won’t tell you which domain a question comes from, and part of the skill is recognizing what’s being asked. Keep an error log: every missed question gets a one-line note about why you missed it (didn’t know the concept, misread the question, fell for a distractor). Patterns in that log tell you exactly what to fix.
Weeks 6–7: Simulate under time. Take at least two or three full-length, 90-question, 90-minute timed practice exams under real conditions — no pausing, no looking things up, PBQ-style questions included if your practice platform has them. You’re training two things: pacing (about a minute per question, with a buffer for PBQs) and stamina (question 80 should get the same attention as question 8). If you’re scoring consistently in the mid-80s on fresh, full-length practice exams, you’re ready.
Final week: Review missed questions, not everything. Resist the urge to re-read the whole objective list. Go back through your error log and your most recent missed questions. Re-drill acronyms — the exam is dense with them, and a forgotten expansion can sink an otherwise easy question. Skim your weakest domain one more time. Then stop studying the night before; cramming past that point trades away the alertness the PBQs demand.
Two scheduling notes. First, book your exam date before you feel ready — around week 2 or 3. A real date on the calendar converts “someday” studying into deadline studying, and you can reschedule with Pearson VUE if you genuinely need to. Second, study in shorter daily sessions rather than weekend marathons; five 45-minute sessions beat one four-hour slog for retention, every time.
How the exam is scored (and what 750 really means)
Security+ uses scaled scoring, and it’s worth understanding honestly, because myths about it cause bad test-day decisions.
Your scaled score of 100–900 is not a percentage. CompTIA converts your raw performance into the scaled range using a process that accounts for question difficulty across different exam forms — two candidates can answer a different mix of questions and still be scored equivalently. That means 750 does not equal “83.3% correct.” Nobody outside CompTIA can tell you the exact raw percentage that maps to 750, and it can differ between exam forms. Aiming for “mid-80s on realistic practice exams” is the practical proxy that works.
Three scoring facts should directly change how you take the test:
- There is no penalty for wrong answers — an unanswered question and a wrong answer cost you exactly the same. Never, under any circumstances, leave a question blank. If time is expiring, guess on everything remaining. A blind guess on a four-option question is worth 25% of a point on average; a blank is worth zero.
- PBQs are typically front-loaded — they usually appear at the start of the exam, before the multiple-choice section. A PBQ can eat five or more minutes, and staring at a hard one while the clock runs is how well-prepared candidates fail. The standard, effective strategy: give each PBQ a fair attempt, and if one is consuming you, flag it, skip it, and return after finishing the multiple-choice questions. The exam interface lets you flag and revisit questions, so use it.
- Partial credit exists on PBQs. Do as much of each PBQ as you can even if you can’t complete it perfectly — placing six of eight items correctly is worth more than abandoning it.
One more expectation-setter: some questions on your exam may be unscored experimental items that CompTIA is evaluating for future use. You can’t identify them, so don’t try — but it does mean a question that seems bizarrely hard or out of scope may not count against you. Answer it and move on without letting it rattle you.
Common mistakes that fail first-timers
The failure patterns on Security+ are remarkably consistent. Avoid these six:
1. Memorizing dumps instead of learning concepts. Braindumps — leaked real exam questions — are both a violation of CompTIA’s exam policies (grounds for certification revocation) and a genuinely bad strategy. SY0-701 questions are scenario-based and the pool rotates; memorized answers collapse the moment a scenario is reworded. Legitimate practice questions teach you the reasoning; dumps teach you letter positions.
2. Ignoring PBQs until exam day. If the first interactive, multi-part question you ever attempt is on the real exam, the format shock alone will cost you ten minutes and a spike of panic. Practice PBQ-style questions during prep so the format is boring by test day.
3. Passive studying — watching and reading without answering. Video courses and books feel productive, but recognition is not recall. Candidates who “studied for three months” and failed almost always mean three months of consumption with minimal practice testing. The research on retrieval practice is unambiguous: answering questions and reviewing explanations is where learning actually happens. Practice questions are not the final step of studying; they are studying.
4. Never simulating time pressure. Untimed practice in a quiet room with coffee is a different sport from 90 questions in 90 minutes. If your first timed full-length experience is the real thing, expect to leave questions on the table. At least two full timed simulations before exam day is the minimum.
5. Being weak on acronyms. Security+ is an alphabet soup: EAP-TLS, SCAP, SOAR, SASE, RTO, RPO, MTTR, MOU, AUP, and a few hundred more. Questions frequently use acronyms without expansion, and distractor answers are often acronyms one letter apart. Build a deliberate acronym review — flashcards work well here — into your final two weeks.
6. Under-studying Domain 5 because it’s “not technical.” GRC content is 20% of the exam — as much as any domain except Security Operations. Technical candidates skim it, assume common sense will carry them, and then face five precise questions in a row distinguishing risk transference from risk avoidance and an SOW from an MSA. Common sense does not carry you; the terminology does.
Exam-day logistics
You take Security+ through Pearson VUE, either in person at a testing center or online proctored from home or office.
Testing center: arrive at least 15 minutes early. You’ll need to present valid identification that meets Pearson VUE’s requirements — check the exact ID policy for your country when you register, and make sure the name on your registration matches your ID. Personal items — phone, watch, notes, even your own pen — go in a locker. You’ll get an erasable board or equivalent for scratch work.
Online proctored: you’ll need a computer with a webcam and microphone, a reliable internet connection, and a private room with a cleared desk. Run Pearson VUE’s system test on the actual machine and network you’ll use, well before exam day. At check-in you’ll photograph your ID and your workspace, and a proctor monitors you throughout — no one may enter the room, and you can’t leave it during the exam. If your home environment can’t guarantee 90+ uninterrupted minutes of solitude, book a testing center instead; a proctor revoking your session over an interruption is a miserable (and avoidable) way to lose $439.
Either way, your pass/fail result appears at completion — you walk out (or log off) knowing. The score report shows your scaled score and, if you didn’t pass, the domains where you were weak, which becomes the study map for a retake. Your official certificate follows through CompTIA’s certification account afterward.
One tactical note: the exam may end with a short survey before your result appears. Budget your 90 minutes for the questions only — the survey doesn’t eat exam time, but seeing extra screens when you expect a result can be momentarily alarming. It’s normal.
Quick reference
- Exam code: SY0-701 (current Security+ version)
- Questions: up to 90 — multiple-choice plus performance-based questions (PBQs)
- Time: 90 minutes
- Scoring: 100–900 scaled; 750 to pass; unanswered questions score the same as wrong ones, so answer everything
- Cost: $439 USD per voucher (US pricing); retakes cost the same
- Prerequisites: none required; Network+ plus ~2 years of security-focused IT experience recommended
- Validity: 3 years, renewable via CompTIA’s Continuing Education (CE) program without retesting
- Domain weights: Security Operations 28% > Threats/Vulnerabilities/Mitigations 22% > Program Management 20% > Security Architecture 18% > General Security Concepts 12%
- Delivery: Pearson VUE testing centers or online proctored; valid ID required; results at completion
- Readiness signal: consistent mid-80s scores on fresh, full-length, timed practice exams
- PBQ strategy: attempt each, flag and skip any time sink, finish the multiple-choice, then return — partial credit counts