Security+
SY0-701

Security+ SY0-701 Exam Domains

The CompTIA Security+ certification (SY0-701) covers 5 exam domains with 183 testable concepts. This breakdown shows each Security+ domain weight, objectives, and key topics to help you focus your study time effectively.

Domains

5 areas

Concepts

183 total

Heaviest Domain

Security Operations (28%)

Pass Rate

99% when concept mastery is above 95%Check my mastery

Domain 1Domain 2Domain 3Domain 4 (28%)Domain 5
1.0

General Security Concepts

12% of exam28 conceptsFoundation

Foundational security principles including the CIA triad, security controls, cryptographic concepts, and authentication methods. This domain establishes the core vocabulary and frameworks used throughout the exam.

CIA TriadZero TrustSecurity ControlsAAA FrameworkGap AnalysisCryptographic Concepts

Exam objectives:

  • 1.1 Compare and contrast various types of security controls
  • 1.2 Summarize fundamental security concepts
  • 1.3 Explain the importance of change management processes
  • +1 more objectives

Study tip: Start here. These concepts appear throughout all other domains.

2.0

Threats, Vulnerabilities, and Mitigations

22% of exam45 conceptsIntermediate

The largest technical domain covering threat actors, attack vectors, vulnerability types, and mitigation strategies. Expect scenario-based questions requiring you to identify attacks and recommend countermeasures.

Threat ActorsSocial EngineeringMalware TypesApplication AttacksNetwork AttacksIndicator Analysis

Exam objectives:

  • 2.1 Compare and contrast common threat actors and motivations
  • 2.2 Explain common threat vectors and attack surfaces
  • 2.3 Explain various types of vulnerabilities
  • +2 more objectives

Study tip: Focus on recognizing attack patterns and matching them to mitigations.

3.0

Security Architecture

18% of exam38 conceptsIntermediate

Infrastructure security including network design, cloud environments, secure protocols, and resilience strategies. Tests your ability to architect secure solutions across on-premises and cloud environments.

Cloud SecurityNetwork SegmentationSecure ProtocolsData ProtectionHigh AvailabilityBackup Strategies

Exam objectives:

  • 3.1 Compare and contrast security implications of different architecture models
  • 3.2 Given a scenario, apply security principles to secure enterprise infrastructure
  • 3.3 Compare and contrast concepts and strategies to protect data
  • +1 more objectives

Study tip: Understand both on-prem and cloud architectures. Know when to use each approach.

4.0

Security Operations

28% of exam48 conceptsAdvanced

The highest-weighted domain covering day-to-day security tasks: monitoring, incident response, vulnerability management, and security tooling. Heavy emphasis on practical, operational scenarios.

SIEM & SOARIncident ResponseVulnerability ScanningIdentity ManagementEndpoint SecurityDigital Forensics

Exam objectives:

  • 4.1 Given a scenario, apply common security techniques to computing resources
  • 4.2 Explain the security implications of proper hardware, software, and data asset management
  • 4.3 Explain various activities associated with vulnerability management
  • +6 more objectives

Study tip: This is 28% of the exam. Practice PBQs heavily for this domain.

5.0

Security Program Management and Oversight

20% of exam24 conceptsFoundation

Governance, risk management, compliance, and security awareness. Covers frameworks, policies, third-party risk, and audit processes. Less technical but requires understanding organizational security.

Risk AssessmentCompliance FrameworksSecurity PoliciesThird-Party RiskSecurity AwarenessAudit Types

Exam objectives:

  • 5.1 Summarize elements of effective security governance
  • 5.2 Explain elements of the risk management process
  • 5.3 Explain the processes associated with third-party risk assessment and management
  • +3 more objectives

Study tip: Memorize key frameworks (NIST, ISO 27001) and their purposes.

Recommended Study Order

If you're new to security:

  1. 1.Domain 1 — Build your foundation
  2. 2.Domain 5 — Understand governance context
  3. 3.Domain 3 — Learn architecture concepts
  4. 4.Domain 2 — Study threats and mitigations
  5. 5.Domain 4 — Apply everything operationally

If you have IT experience:

  1. 1.Domain 4 — Highest weight, most practical
  2. 2.Domain 2 — Critical for scenario questions
  3. 3.Domain 3 — Architecture decisions
  4. 4.Domain 5 — Governance & compliance
  5. 5.Domain 1 — Review fundamentals last

Ready to start studying?

Take our free readiness assessment to identify which domains need the most attention.

99% of students who reach 95% concept mastery pass