CompTIA Security+ Exam Objectives
SY0-701
The CompTIA Security+ SY0-701 exam is organized into five domains that measure practical cybersecurity knowledge across technical and administrative responsibilities.
General Security Concepts (12%) covers the foundations. Expect questions on security controls, core principles like confidentiality, integrity, and availability, and essential ideas such as authentication, authorization, non-repudiation, and basic cryptographic purpose. This domain sets the baseline for everything else on the exam.
Threats, Vulnerabilities, and Mitigations (22%) focuses on identifying and responding to common security risks. You will need to understand malware types, social engineering, application attacks, vulnerability management, hardening, and how organizations reduce exposure through layered defenses and secure practices.
Security Architecture (18%) tests your ability to recognize secure design decisions. This includes network segmentation, secure protocols, cloud and hybrid considerations, identity and access management, resilience, and architecture choices that support stronger protection across systems and applications.
Security Operations (28%) is the largest domain and emphasizes day-to-day defensive work. Topics include monitoring, logging, alerting, incident response, digital forensics concepts, disaster recovery, data protection, and operational security controls used to maintain secure environments.
Security Program Management and Oversight (20%) covers governance and organizational security practices. Expect content on risk management, security policies, compliance, awareness training, third-party risk, audits, and oversight processes that help align cybersecurity with business needs.
Together, these domains reflect the broad, job-relevant scope of Security+ and explain why SY0-701 is valued for roles like Security Analyst, Security Administrator, and Security Engineer.
Exam Overview
Exam Domains
All Exam Objectives
5 domains covering 100% of the exam
General Security Concepts
12% of exam~11 questions
Threats, Vulnerabilities, and Mitigations
22% of exam~20 questions
Security Architecture
18% of exam~16 questions
Security Operations
28% of exam~25 questions
Security Program Management and Oversight
20% of exam~18 questions
Strategy
Study Strategy by Domain Weight
Prioritize your study time based on exam weightings
Security Operations
Allocate approximately 22 hours of study time
Threats, Vulnerabilities, and Mitigations
Allocate approximately 18 hours of study time
Security Program Management and Oversight
Allocate approximately 16 hours of study time
Security Architecture
Allocate approximately 14 hours of study time
General Security Concepts
Allocate approximately 10 hours of study time
More Resources