SY0-701Security+

What's on the Security+ exam

Security+ validates baseline cybersecurity skills: security concepts and cryptography, the threat landscape, secure architecture, day-to-day security operations, and program governance.

5 domains  ·  28objectives  ·  in official exam order

1.0 General Security Concepts

12% of the exam
  • 1.1Security control categories and types
  • 1.2Core security concepts: CIA, AAA, zero trust, and more
  • 1.3Why change management matters to security
  • 1.4Cryptography in practice: encryption, PKI, and certificates

2.0 Threats, Vulnerabilities, and Mitigations

22% of the exam
  • 2.1Threat actors and what motivates them
  • 2.2Threat vectors and attack surfaces
  • 2.3Vulnerability types across platforms
  • 2.4Reading the signs of an attack in progress
  • 2.5Mitigation techniques that shrink enterprise risk

3.0 Security Architecture

18% of the exam
  • 3.1Security trade-offs across architecture models
  • 3.2Securing enterprise infrastructure by design
  • 3.3Data protection strategies and controls
  • 3.4Resilience and recovery built into the architecture

4.0 Security Operations

28% of the exam
  • 4.1Hardening and securing computing resources
  • 4.2Asset management's role in security
  • 4.3The vulnerability management lifecycle
  • 4.4Security alerting and monitoring: concepts and tooling
  • 4.5Tuning enterprise tools to improve security
  • 4.6Identity and access management, implemented and maintained
  • 4.7Automation and orchestration in security operations
  • 4.8Incident response, from detection to lessons learned
  • 4.9Using logs and data sources in investigations

5.0 Security Program Management and Oversight

20% of the exam
  • 5.1The elements of effective security governance
  • 5.2The risk management process
  • 5.3Assessing and managing third-party risk
  • 5.4Security compliance essentials
  • 5.5Audits, assessments, and penetration test types
  • 5.6Building security awareness programs

This is our plain-English overview of what the exam covers, in the blueprint's order. The official objectives document — with every sub-objective — is published by CompTIA.

Get the official objectives at CompTIA.org ↗

Study every one of these topics here

ExamWizardz turns this list into a guided plan — practice tests, hands-on labs and PBQs, flashcards, and articles mapped to the Security+ exam.

CompTIA®, A+®, Network+®, and Security+® are registered trademarks of CompTIA, Inc. ExamWizardz is not affiliated with, endorsed by, or sponsored by CompTIA. This overview is ExamWizardz's own summary of publicly documented exam scope.