Security+ SY0-701: Domains, Format, and Study Order

A certification candidate reviews Security+ study notes next to a laptop showing exam objectives

The CompTIA Security+ SY0-701 exam is the current version of the most widely recognized entry-level security certification, and knowing its exact structure is the fastest way to stop wasting study time. The exam has five domains weighted between 12% and 28%, a maximum of 90 questions in 90 minutes, and a passing score of 750 on a 100-900 scale. CompTIA Security+ SY0-701 launched on November 7, 2023, and CompTIA lists retirement as usually three years after launch, estimated in 2026, so candidates starting preparation now should plan deliberately rather than assume the version will stay open indefinitely.

This guide breaks down the domain weights, the question format, the recommended background, and a study order matched to how the exam distributes its points. The same weighted-domain method works for other multi-domain vendor exams, including the CompTIA A+ 220-1201 Core 1 domains and study guide and the CCNA 200-301 domain breakdown.

Exam format and scoring

SY0-701 is exam version V7 of Security+. It presents a maximum of 90 questions, mixing multiple-choice items with performance-based questions that ask you to configure or troubleshoot in a simulated environment. You get 90 minutes total, which averages out to a minute per question, and the performance-based items typically consume more than that, so pacing on multiple choice matters. The passing score is 750 on a scale from 100 to 900, which works out to roughly 80 percent, a higher bar than the CompTIA baseline of 700 seen on A+ and Network+.

The exam is available in English, Japanese, Portuguese, Spanish, and Thai. CompTIA lists it as mapping to a broad set of DoD 8140 work roles, including cyber defense analyst, incident responder, vulnerability analyst, and system administrator, which is why the credential carries weight in government and contractor hiring pipelines.

Domain weights by percentage

The five domains are not equally weighted, and study hours should reflect that. The table below shows the official weighting from the exam objectives summary:

DomainWeightCore focus
General security concepts12%Security controls, CIA triad, zero trust, cryptography basics, change management
Threats, vulnerabilities, and mitigations22%Threat actors, attack vectors, malware analysis, mitigation techniques
Security architecture18%Cloud, virtualization, IoT, ICS, data protection, resilience and recovery
Security operations28%Hardening, asset and vulnerability management, IAM, incident response, forensics
Security program management and oversight20%Governance, risk management, third-party risk, compliance, audits, awareness training

Security operations carries the heaviest weighting at 28%, followed by threats, vulnerabilities, and mitigations at 22%. Together those two domains account for half of the exam, so a study plan that treats all five domains as equal will underinvest in exactly the areas that decide pass or fail.

Recommended background

CompTIA recommends Network+ certification plus two years of hands-on experience in a security or systems administrator role before attempting Security+, and that recommendation is worth taking seriously even though nothing technically blocks a newer candidate from booking the exam. The trade-off is straightforward: with the recommended background, the architecture and operations domains feel like structured review, and you can spend most of your hours on gaps. Without it, expect a longer runway, because the performance-based questions assume comfort with real firewall, logging, and access-control configurations rather than memorized definitions.

How to sequence your study

A weighted study order beats a linear one. Work through this sequence:

  1. Start with general security concepts at 12% as a fast pass. This domain is vocabulary-dense but light, and it supplies the terminology every other domain reuses.
  2. Move to threats, vulnerabilities, and mitigations at 22%. Learn threat actor types, attack vectors, and malware categories by pairing each with its mitigation, because exam items frequently ask for the pairing, not the definition.
  3. Take on security operations, the 28% domain, in two blocks: operations tooling (hardening, EDR/XDR, NAC, DLP, monitoring) and then the response lifecycle (incident response, root cause analysis, threat hunting, digital forensics). Give this domain the largest share of your calendar.
  4. Study security program management and oversight at 20% as its own block. Governance, risk registers, third-party assessment, and audit terminology are easy to confuse and easy to score once separated.
  5. Finish with security architecture at 18%, integrating what you already learned, since cloud, virtualization, and resilience topics connect back to controls and operations.

Two full weeks before the exam date, shift entirely to timed practice sets that mirror the 90-question, 90-minute format so pacing becomes automatic.

Scheduling and test day

CompTIA exams are delivered through Pearson VUE, and its online testing option runs 24/7 under remote proctoring that applies the same monitoring conditions as a test center, so you choose between a home session and a test-center seat based on your connection quality and workspace privacy rather than exam availability. Book through CompTIA Central after checking the current retirement schedule for SY0-701, and leave enough calendar room for one retake if the first attempt falls short of 750.

Readiness checklist

  • You can name all five domains and their weights from memory.
  • You have scored 750 or higher on a full-length timed practice exam twice.
  • You can walk through an incident response sequence and a vulnerability management lifecycle end to end.
  • You can compare control types and cryptography use cases without notes.
  • You have verified your exam delivery choice and confirmed the booking date leaves buffer time.

Sources

Scroll to Top