CompTIA · free study guide

CompTIA Security+ study guide

CompTIA Security+

Free CompTIA Security+ study guide and exam blueprint. 90 questions in 90 minutes. Written from CompTIA's SY0-701 objectives v5.0, last checked 20 July 2026. Domain weightings, glossary, and practice questions with worked explanations.

Written from CompTIA's SY0-701 objectives v5.0. Last checked against that document on 20 July 2026.
90 questions 90 minutes 5 domains
Orientation

The current version.

The most expensive mistake in Security+ prep is studying the wrong version. Candidates fail not because they studied too little but because they studied SY0-601, retired in July 2024. Everything here is built to the current exam, SY0-701, objectives version 5.0.

Is SY0-701 still current?
Yes. As of July 2026, SY0-701 is the only active version. A successor, SY0-801, has been floated by training providers for late 2026, but CompTIA has not confirmed it, and no official objectives exist. When 801 does launch, 701 stays available for roughly six more months, and any Security+ you earn on 701 is valid for three years regardless. Ignore third-party pages claiming an "April 2026 objectives refresh": CompTIA's own objectives document is still version 5.0, unchanged since 2023.

What you are walking into

A maximum of 90 questions in 90 minutes, so roughly one minute each. Two question types: standard multiple-choice, and performance-based questions (PBQs) that put you in a simulated environment to do a task, configure a firewall rule, match attacks to indicators, order incident-response steps. PBQs usually come first and are worth more, so a common tactic is to flag them and return after clearing the faster multiple-choice.

Scoring is scaled from 100 to 900, and you need 750 to pass. CompTIA does not publish this as a percentage, so ignore anyone who tells you "you need 83%." The scaled score weights harder questions more.

CompTIA recommends about two years of IT administration experience with a security focus, but there is no formal prerequisite. Anyone can sit it.

The nature of the exam

Security+ is dense with terminology, and much of it tests distinctions: which category a control falls in, which attack matches an indicator, symmetric versus asymmetric, MAC versus DAC versus RBAC. The objectives are long lists of specific technologies, and the exam expects you to recognize and separate them. This is not a conceptual essay exam; it is recognition and applied recall at speed. The acronym list alone runs to hundreds of entries, and the exam assumes you know them.

The order that works

Your study plan

Exam Objectives

What the exam is made of.

Five domains, published weights. Security Operations dominates at more than a quarter of the exam, and the two operational domains together are half of it.

12%General Concepts22%Threats18%Architecture28%Operations20%Program Mgmt
Five domains · 28 objectives max 90 questions

Security Operations is 28%, the single largest domain, and Threats, Vulnerabilities, and Mitigations is 22%. Together they are half the exam. General Security Concepts, despite being the foundation everyone starts with, is the smallest at 12%. Study time should follow the weights, not the chapter order of a textbook.

The five domains

DomainWeightWhat it covers
1.0 General Security Concepts12%Control categories and types, CIA and AAA, zero trust, physical security, change management, cryptographic solutions. Four objectives.
2.0 Threats, Vulnerabilities, and Mitigations22%Threat actors and motivations, threat vectors, vulnerability types, indicators of malicious activity, mitigation techniques. Five objectives.
3.0 Security Architecture18%Architecture models, securing infrastructure, protecting data, resilience and recovery. Four objectives.
4.0 Security Operations28%Hardening, asset management, vulnerability management, monitoring, enterprise security capabilities, identity and access management, automation, incident response, investigation. Nine objectives.
5.0 Security Program Management and Oversight20%Governance, risk management, third-party risk, compliance, audits and assessments, security awareness. Six objectives.

The format

QuestionsMaximum of 90.
Time90 minutes. About one minute per question.
TypesMultiple-choice and performance-based (PBQ) simulations.
Pass mark750 on a scaled 100-900 range. No published percentage.
ExperienceAbout two years in IT with a security focus recommended, but not required.
DeliveryPearson VUE test center or online proctored.
ValidityThree years; renew with continuing education units (CEUs).
What this practice tool reproduces, and what it cannot
The mock matches the blueprint weighting, the 90-question length, and the 90-minute clock, and it reproduces multiple-choice items. It cannot reproduce performance-based questions, which need a simulated environment to configure or drag-and-match. Expect several PBQs on the real exam; the knowledge they test, control types, attack indicators, incident-response order, is covered here in multiple-choice form.

What this exam is not

Domain 1 12% · 4 objectives

General security concepts.

The smallest domain at 12%, but the foundation the other four build on. It defines the vocabulary, control categories, the CIA triad, zero trust, and cryptography, that every other domain assumes you already know.

1.1 Security controls

Controls are classified two ways at once, and the exam tests both axes.

By category (what kind)By type (what it does)
Technical (implemented in tech: firewalls, encryption)Preventive (stops it: a lock, a firewall rule)
Managerial (policies, procedures, risk assessments)Deterrent (discourages: a warning sign, a guard)
Operational (run by people: guards, training, awareness)Detective (finds it: logs, IDS, cameras)
Physical (real-world: fences, bollards, locks)Corrective (fixes it after: backups, patching)
 Compensating (an alternative when the primary is not possible)
 Directive (instructs: an acceptable use policy)

A camera is physical by category and can be both deterrent (visible, discourages) and detective (records, finds). The exam loves questions that ask you to place a control on both axes.

1.2 Fundamental concepts

1.3 Change management

1.4 Cryptographic solutions

Domain 2 22% · 5 objectives

Threats, vulnerabilities, and mitigations.

The second-largest domain at 22%. This is the attacker's half of the exam: who attacks, how they get in, what weaknesses they exploit, how you spot them, and how you stop them. Much of it is matching, actor to motivation, attack to indicator.

2.1 Threat actors and motivations

2.2 Threat vectors and attack surfaces

2.3 Vulnerability types

2.4 Indicators of malicious activity

This objective is heavy on matching an attack to what you would observe. Know the malware family, the attack, and the tell-tale indicator.

2.5 Mitigation techniques

Domain 3 18% · 4 objectives

Security architecture.

18% of the exam. How you design and structure systems securely: the trade-offs of different architectures, how you secure infrastructure, how you protect data in its various states, and how you build in resilience so you can recover.

3.1 Architecture models

3.2 Securing infrastructure

3.3 Protecting data

3.4 Resilience and recovery

Domain 4 28% · 9 objectives

Security operations.

The largest domain, more than a quarter of the exam, with nine objectives. This is security as a running practice: hardening systems, managing assets and vulnerabilities, monitoring, controlling identity and access, automating, and responding to incidents. If your study time is limited, it starts here.

4.1 Secure computing techniques

4.3 Vulnerability management

4.4 Alerting and monitoring

4.5-4.6 Enterprise capabilities and identity

4.7 Automation and orchestration

4.8 Incident response

Learn this sequence cold; the exam tests the order.

StepWhat happens
1. PreparationBuild the plan, tools, and training before anything happens.
2. DetectionIdentify that an incident is occurring.
3. AnalysisDetermine scope, impact, and what is affected.
4. ContainmentStop the spread; limit the damage.
5. EradicationRemove the cause: malware, the attacker's access.
6. RecoveryRestore systems to normal operation.
7. Lessons learnedReview to improve for next time.

4.9 Investigation data

Where to spend your time
This domain is 28% of the exam. Within it, the highest-yield items are the access control models (MAC/DAC/RBAC), the incident response order, the email authentication trio (SPF/DKIM/DMARC), and the role of the SIEM. They are heavily tested and quick to confuse.
Domain 5 20% · 6 objectives

Security program management and oversight.

20% of the exam, and the most managerial. This is security as governance: the policies and structures that run a program, the formal process of managing risk, overseeing vendors, meeting compliance obligations, running audits, and training people. Much of it is definitions and process.

5.1 Governance

5.2 Risk management

This objective carries the exam's quantitative risk formulas. Learn them; they are among the few calculations Security+ asks.

TermMeaning
SLE (Single Loss Expectancy)Cost of one occurrence = Asset Value x Exposure Factor.
ARO (Annualized Rate of Occurrence)How many times per year it is expected to happen.
ALE (Annualized Loss Expectancy)Expected yearly cost = SLE x ARO.

5.3 Third-party risk

5.4-5.5 Compliance and audits

5.6 Security awareness

Reference

Glossary.

High-yield terms as SY0-701 uses them, weighted toward the distinctions the exam tests and the acronyms it assumes you know.

AAA
Authentication (who you are), Authorization (what you may do), Accounting (what you did). Applies to people and systems.
ALE
Annualized Loss Expectancy = SLE x ARO. The expected yearly cost of a risk.
ARO
Annualized Rate of Occurrence. How many times per year an event is expected.
CIA triad
Confidentiality, Integrity, Availability. The three goals security exists to protect.
Chain of custody
Documented handling of evidence proving it was not tampered with, so it is admissible.
Compensating control
An alternative control used when the primary one is not feasible.
CVE
Common Vulnerabilities and Exposures: the public catalog of known vulnerabilities.
CVSS
Common Vulnerability Scoring System: a 0-10 severity score used to prioritize.
DAC
Discretionary Access Control: the data owner decides who gets access.
DMARC / DKIM / SPF
The three email-authentication mechanisms. SPF authorizes sending servers, DKIM signs messages, DMARC ties them together and sets policy.
Impossible travel
Logins from two locations too far apart to travel between in the elapsed time; an indicator of compromise.
MAC
Mandatory Access Control: the system enforces access by classification labels; the most rigid model.
MFA
Multifactor authentication: combining different factor types (know, have, are, somewhere). Two passwords is not MFA.
Non-repudiation
The inability to deny an action. Provided by digital signatures.
On-path attack
An attacker positioned between two parties, intercepting or altering traffic. Formerly "man-in-the-middle."
PKI
Public Key Infrastructure: certificate authorities, public/private keys, and revocation (CRL, OCSP) that make asymmetric cryptography trustworthy.
RBAC
Role-Based Access Control: permissions assigned to roles, and users to roles.
RPO
Recovery Point Objective: the maximum acceptable data loss, measured in time.
RTO
Recovery Time Objective: the maximum acceptable time to restore a system.
SIEM
Security Information and Event Management: aggregates and correlates logs into alerts; the hub of a SOC.
SLE
Single Loss Expectancy = Asset Value x Exposure Factor. The cost of one occurrence.
SOAR
Security Orchestration, Automation, and Response: automating security workflows to multiply a team.
Symmetric vs asymmetric
Symmetric uses one shared key (fast, hard to exchange); asymmetric uses a public/private pair (solves exchange, slower).
TPM vs HSM
TPM is a crypto chip on the motherboard of one device; an HSM is dedicated hardware for managing keys at scale.
Zero Trust
Never trust, always verify. Access is decided per request via a control plane and enforced at a data-plane policy enforcement point.
Zero-day
A vulnerability with no available patch, unknown to the vendor or newly disclosed.
Common questions

CompTIA Security+ exam questions, answered

How many questions are on the CompTIA Security+ exam?

The CompTIA Security+ exam has 90 questions and lasts 90 minutes. CompTIA uses a scaled score rather than a published percentage, so there is no fixed pass mark to quote.

What is on the CompTIA Security+ exam?

The exam covers 5 domains: General Concepts (12%), Threats (22%), Architecture (18%), Operations (28%), Program Mgmt (20%). These weightings come from CompTIA's SY0-701 objectives v5.0.

Is this CompTIA Security+ material current?

Yes. This guide was written from CompTIA's own published outline, SY0-701 objectives v5.0, and last checked against that document on 20 July 2026. That date is shown on every page so you can judge for yourself rather than take our word for it.

Are there free CompTIA Security+ practice questions?

Yes. Sample questions with full worked explanations are free and need no account. The complete question bank and the full-length 90-question timed mock are paid.

Practise it

The guide above is free. The question bank and the full-length timed mock are the paid part.

Open Security+ →
Other exams:
PMP · CAPM · PMI-ACP · PSM I · PRINCE2 · ITIL · ISTQB CTFL · CC · Network+ · CISSP · AWS CCP

Cutscores is independent and is not affiliated with, authorised by, endorsed by or sponsored by CompTIA or any certification body. Security+ and all certification names and marks are the property of their respective owners, and are used here only to describe which exam this material prepares you for. We do not reproduce live exam content.