CompTIA Security+ Exam Objectives: A Practical Domain

CompTIA Security+ remains one of the most widely recognized entry-to-mid-level cybersecurity certifications, frequently serving as a baseline requirement for DoD 8570 compliance and private-sector security roles. Understanding the current exam objectives is essential not just for passing the exam, but for evaluating whether this certification maps to the practical skills your team needs. This article breaks down each objective domain, its relative weight, and the operational relevance of the topics covered [4].

Exam Format and Structural Overview

The CompTIA Security+ exam (SY0-701) consists of a maximum of 90 questions, including multiple-choice and performance-based items. Candidates have 90 minutes to complete it, with a passing score of 750 on a scale of 100–900. The exam is structured around five objective domains, each carrying a specific percentage weight that reflects its importance in the overall assessment [4]. Performance-based questions require candidates to perform tasks in a simulated environment—such as configuring a firewall rule, identifying an incident from log data, or implementing an access control policy. These practical components are what distinguish Security+ from purely knowledge-check certifications and are a primary reason hiring managers value it as a signal of hands-on capability [3].

The table below summarizes the five domains and their approximate weightings on the current exam:

DomainApproximate Weight
General Security Concepts12%
Threats, Vulnerabilities, and Mitigations22%
Security Architecture18%
Security Operations28%
Security Program Management and Oversight20%

Domain 1: General Security Concepts (12%)

This domain establishes the foundational vocabulary and principles that underpin the rest of the exam. It covers the CIA triad, non-repudiation, and the types of security controls—preventive, detective, corrective, deterrent, and compensating. Candidates are expected to understand fundamental cryptography concepts such as symmetric versus asymmetric encryption, hashing, and digital signatures at a conceptual level, with deeper application deferred to later domains [4].

Authentication and authorization mechanisms form a significant portion of this section. Expect questions on multi-factor authentication (MFA), single sign-on (SSO), federated identity, and the differences between access control models—discretionary (DAC), mandatory (MAC), role-based (RBAC), and attribute-based (ABAC). The exam also tests foundational zero-trust concepts, including the principle of never trusting by default and continuously verifying. Security managers reviewing this domain should note that it aligns closely with the baseline knowledge expected of any SOC analyst or junior security engineer [5].

Additionally, this domain touches on basic security posture concepts like defense-in-depth, security through obscurity (and why it fails), and the importance of least privilege. While the weighting is the lowest of all domains, these concepts are recursively tested within the context of other sections, making mastery here a prerequisite for performing well overall.

Domain 2: Threats, Vulnerabilities, and Mitigations (22%)

At 22%, this is the second-heaviest domain and arguably the most operationally relevant for day-to-day security work. It requires candidates to identify and categorize threat actors—ranging from nation-state APTs and organized crime groups to insider threats and hacktivists—as well as understand their typical tactics, techniques, and procedures (TTPs). Attack vectors covered include social engineering (phishing, vishing, smishing, pretexting), physical attacks, and supply-chain compromises [3].

Vulnerability management is a core competency tested here. Candidates must understand the lifecycle of vulnerability identification, assessment, remediation, and reporting. This includes knowledge of common scanning tools, the role of CVSS scoring, and the difference between unpatched systems, misconfigurations, and zero-day vulnerabilities. The exam expects familiarity with common software and hardware vulnerabilities such as buffer overflows, race conditions, improper error handling, and insecure deserialization.

Mitigation techniques round out this domain. Candidates should be prepared to select appropriate countermeasures for given threat scenarios—for example, implementing network segmentation to limit lateral movement, applying endpoint detection and response (EDR) to address malware, or deploying email filtering to reduce phishing success rates. This domain maps directly to the threat-informed defense skills that security teams need to operationalize, making it a strong indicator of whether a candidate can contribute meaningfully to vulnerability management programs [5].

Domain 3: Security Architecture (18%)

Security Architecture focuses on how security controls are designed and integrated into enterprise infrastructure. A major emphasis in the current objectives is zero-trust architecture—candidates must understand how to apply zero-trust principles across network, application, and identity layers, including micro-segmentation, software-defined perimeters, and continuous verification mechanisms [5].

Enterprise security architecture concepts are tested extensively: defense-in-depth strategies, secure system design, and the security implications of cloud service models (IaaS, PaaS, SaaS) and deployment models (public, private, hybrid, community). Candidates need to understand shared responsibility models and how security obligations shift depending on the cloud model chosen. Cryptographic implementation is also covered here—expect questions on selecting appropriate algorithms for specific use cases, managing PKI infrastructure, understanding certificate lifecycle management, and deploying TLS correctly.

Network architecture security is another key area. This includes securing wired and wireless networks, implementing firewalls and next-generation firewalls, using VPNs (site-to-site and remote access), and understanding the security functions of load balancers, reverse proxies, and web application firewalls. For security managers, this domain reflects the skills needed to evaluate architectural decisions and ensure that security is embedded into infrastructure design rather than bolted on after deployment [4].

Domain 4: Security Operations (28%)

At 28%, Security Operations is the single largest domain and the one most directly tied to the daily responsibilities of SOC analysts, incident responders, and security administrators. The exam tests the full incident response lifecycle: preparation, identification, containment, eradication, recovery, and lessons learned. Candidates must be able to distinguish between incidents and events, understand triage prioritization, and know when to escalate [4].

Monitoring and detection are heavily weighted. Expect questions on SIEM configuration and use cases, log aggregation, alert fatigue management, and the role of threat intelligence feeds—both tactical (indicators of compromise) and strategic (threat actor profiles). The exam also covers automation and orchestration concepts, including SOAR platforms and how they accelerate response workflows. Understanding the MITRE ATT&CK framework and how it maps to detection rules and response playbooks is increasingly important.

This domain also addresses foundational security operations tasks: patch management, vulnerability scanning schedules, change management processes, and backup and recovery procedures. Candidates should understand the difference between full, incremental, and differential backups, and the security considerations for backup storage (encryption, off-site retention, immutability). For certification candidates targeting SOC roles, this domain represents the highest-yield study area—performance-based questions here often simulate real incident analysis tasks [3].

Domain 5: Security Program Management and Oversight (20%)

The final domain shifts focus from technical execution to governance, risk, and compliance (GRC). It covers risk management methodologies—qualitative versus quantitative risk assessment, risk matrices, and the calculation of single-loss expectancy (SLE), annualized loss expectancy (ALE), and annualized rate of occurrence (ARO). Candidates must understand how to translate technical risk into business terms that executives can act on [4].

Compliance and regulatory frameworks are tested at a conceptual level. The exam does not require deep knowledge of any single regulation but expects familiarity with the purpose and scope of frameworks such as NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, and SOC 2. Candidates should understand the difference between policies, standards, procedures, and guidelines, and know how to map controls to regulatory requirements.

Security awareness training, vendor risk management, third-party assessments, and business continuity planning (BCP) and disaster recovery (DR) also fall under this domain. Candidates need to understand recovery time objectives (RTO), recovery point objectives (RPO), mean time to restore (MTTR), and how to design DR strategies that align with organizational tolerance for downtime. For security managers, this domain validates a candidate’s readiness to participate in governance conversations and support audit and compliance activities—skills that are often underdeveloped in purely technical staff [3].

Practical Study Strategy by Domain Weight

Given the unequal domain weightings, an efficient study plan should allocate preparation time proportionally. The following ordered list provides a recommended study sequence based on both weight and foundational dependency:

  1. General Security Concepts (12%) — Study first. These are the building blocks referenced throughout every other domain. Weakness here compounds errors elsewhere.
  2. Threats, Vulnerabilities, and Mitigations (22%) — Tackle second. Build on the foundational concepts to understand adversarial tactics and how controls counter them.
  3. Security Architecture (18%) — Study third. Apply threat knowledge to infrastructure design, understanding where and how controls are positioned.
  4. Security Operations (28%) — Prioritize heavily. This is the highest-weight domain and the most likely source of performance-based questions. Dedicate significant lab time here.
  5. Security Program Management (20%) — Study last. GRC concepts are more conceptual and can be reinforced efficiently through practice questions and framework mapping exercises.

Candidates should supplement objective-level study with hands-on labs—particularly for Domain 4. Tools such as pfSense for firewall configuration, Wireshark for traffic analysis, and open-source SIEM platforms like Wazuh provide practical experience that directly supports performance-based question success [5].

FAQ

How often do the CompTIA Security+ exam objectives change?

CompTIA typically updates its exam objectives every three years. The current SY0-701 objectives replaced the SY0-601 version. Candidates should always verify the exact exam code on their registration to ensure they are studying the correct objectives.

Is prior IT experience required before attempting Security+?

CompTIA recommends two years of experience in IT administration with a security focus, as well as Network+ or equivalent knowledge. However, the exam is achievable without formal experience if candidates invest sufficient time in hands-on labs and structured study.

How does Security+ compare to other entry-level certifications like CySA+ or SSCP?

Security+ is broader and more foundational, covering GRC, architecture, operations, and threats at a conceptual level. CySA+ focuses more narrowly on security operations, incident response, and threat detection. SSCP is more technically deep but narrower in scope. Security+ is generally recommended as the first certification in the CompTIA cybersecurity pathway.

Are performance-based questions scored differently from multiple-choice?

CompTIA does not disclose its exact scoring algorithm, but performance-based questions contribute to the overall score and can effectively function as gatekeepers—a strong performance on PBQs significantly increases the probability of passing.

Sources

Scroll to Top