Skip to main content
← Blog·8 min read·June 22, 2026 · updated June 24, 2026

Security+ is live on Revy's Tech Journey

CompTIA Security+ (SY0-701) is the entry-level cybersecurity certification employers ask for by name, and as of today it is live on Revy's Tech Journey. 28 lessons across 5 domains, 500 Q-bank questions, 1,141 Adventure scenes, 18 SOC simulator tickets, 24 performance-based questions, and 800 flashcards. Six of six study surfaces live on day one, a free first Practice Exam attempt, and a Mastery Index with evidence quality on your dashboard.

N
IT Service Center Manager, former CTE teacher, founder of Revtek

Why Security+ matters right now

Security+ is the cert employers list when they post a junior security analyst, SOC analyst, or security engineer role and do not want to filter out career-changers. It is vendor-neutral, it covers the breadth of the field, and it is the cert the federal government and its contractors point to most often.

On the demand side: the Bureau of Labor Statistics projects employment of information security analysts to grow 29 percent from 2024 to 2034, against 3 percent projected for all occupations combined. On pay, BLS reports a median annual wage of $124,910 for the occupation in May 2024. Read that as the occupation, not the credential. BLS does not publish wages by certification, so nobody can honestly quote you a Security+ holder's salary band, and an entry-level help desk to SOC move will start well under a national median.

On the gatekeeping side: DoD Manual 8140.03 took effect February 15, 2023 and cancelled the old 8570.01-M workforce manual outright. The IAT and IAM level labels came from 8570 and do not appear in the replacement, so a job posting saying "IAT Level II" is using retired language. Under 8140, a position is coded to a work role in the DoD Cyberspace Workforce Framework at a basic, intermediate, or advanced proficiency, and a certification is one of three ways to meet the foundational qualification, alongside education and training. Security+ appears on the qualification matrix for a long list of foundational cyber-IT and cyber-defense work roles, which is why recruiters still ask for it first. Check the matrix for the specific work role code in the posting rather than trusting the label.

Put the two together and Security+ is one of the highest-leverage single exams a career-changer can sit. The exam voucher runs $439 as of this writing. It opens doors that A+ alone does not.

What is live in RTJ Security+ today

The six study surfaces we ship for A+ and Net+ are live for Security+ on day one, with no "coming soon" placeholder on the track. Volume differs by track, and the Sim mode format differs too: Security+ Sim tickets are multiple-choice governance and incident-response scenarios, while Net+ has hands-on consoles. The breakdown:

  • 28 lessons across the five SY0-701 domains. General Security Concepts, Threats and Vulnerabilities, Security Architecture, Security Operations, and Security Program Management and Oversight. Each lesson maps to one or more specific objectives in the CompTIA blueprint.
  • 500 Q-bank questions with explanations grounded in NIST, MITRE ATT&CK, CIS, and OWASP source material. Items carry an objective ID and a source citation. Written against the SY0-701 objectives, not carried over from the prior exam version.
  • 1,141 Adventure scenes across the same 28 lessons. SOC-flavored helpdesk-to-incident-response scenarios with branching choices, NIST and MITRE citations on the decision points, and the same five archetype taxonomy as A+ and Net+. The section below walks through what the Security+ campaign puts you inside.
  • 18 SOC simulator tickets in the dedicated Sim mode. Triage real-feeling alerts, decide what to escalate, and live with the consequences when you guess.
  • 24 performance-based questions. RTJ practices five authored patterns: drag-target, image hotspot, ordered list, validated input, and log picker. CompTIA does not publish a fixed PBQ count, position, or format taxonomy.
  • 800 flashcards for recall drills on the high-volume vocabulary the exam loves to test. CIA triad, frameworks, attack types, indicators of compromise.

Pricing is the same as the rest of the platform. Free tier gets you a meaningful taste of every surface. Pro unlocks unlimited attempts, the full Q-bank, the full Adventure Mode, and the full Sim queue across all three cert tracks.

The trinity: A+ then Net+ then Security+

We deliberately built A+, Network+, and Security+ in that order. They are the three certs CompTIA itself stacks into its core technician path, and they are the three certs employers most often list together when they want a candidate with broad foundations rather than narrow specialty.

A+ teaches you the physical world. Laptops, printers, mobile devices, operating systems, troubleshooting methodology. It is the cert that tells an employer you can sit at a service desk and not panic when the user hands you a broken machine.

Net+ teaches you what connects those machines. Ethernet, IP, routing, switching, DNS, firewalls at the packet level. It is the cert that tells an employer you can read a network diagram, troubleshoot a connectivity problem above Layer 1, and understand what a router actually does.

Security+ teaches you who is attacking that network and how. It assumes you already know the building (A+) and the plumbing (Net+). When the lesson talks about a VLAN hopping attack, the platform assumes you know what a VLAN is. When it talks about a misconfigured DNS resolver enabling cache poisoning, it assumes you know what DNS does in the first place. Security+ is the cap on the technical-foundation stack. After it, the next moves are specialty: cloud, pentest, GRC, or vendor-specific paths.

You can absolutely take Security+ first. People do it. But the people who learn the field deeply and stay employable across role changes tend to walk the stack in order.

Try Security+ free before you commit

The first Practice Exam attempt on every track is free, and it is the full-length exam, not a cut-down taste. One attempt, no credit card, no pop-up after the score. For Security+ that is 5 performance-based questions plus 85 multiple-choice items, 90 minutes on the clock, full timing pressure, and a scored attempt that adds evidence to your Mastery Index.

The result breaks the attempt down by domain. It shows where the RTJ questions landed, where they did not, and which objectives the missed items mapped to. The dashboard keeps the Mastery Index next to its evidence-quality label so a high number never hides thin practice.

That is the deal across the board. We do not believe in selling you a tier before you have felt the product work for you.

What Security+ Adventure Mode puts you inside

Adventure Mode is the surface that gets the most "I did not know studying could feel like this" feedback on A+ and Net+. For Security+ the framing shifts from the helpdesk to the SOC, and the scenarios get sharper. A few of the situations you will sit inside today:

  • A junior SOC analyst sees a Splunk alert at 2 in the morning. Authentication-failure spike from a country the company does not operate in. Decide whether to escalate, block the source, or wait for context. The choice changes the next scene.
  • A junior tech finds an unlabeled USB drive in the lobby. Plug it into an air-gapped analysis box? Hand it to security? Leave it where it was? The scene assumes you have read the AUP and rewards reading the policy first.
  • A phishing email reaches the CFO's inbox claiming to be from the CEO and asking for a same-day wire transfer. Walk through the indicators, decide which control should have caught it, and write the after-action note.
  • A vendor pushes a software update that turns out to ship with a backdoor. Supply-chain attack live in your environment. Decide how to scope the blast radius and what to do first while the incident is still hot.

Every scenario uses the same archetype taxonomy we lock for the whole platform. The hand-waver who underreports symptoms. The self-diagnoser who tells you the fix before you ask. The prepared user who hands you logs. The deadline-panic user who needs it fixed five minutes ago. The reluctant user who does not want to be on the phone. Reading the person on the other end of the ticket is part of the skill, and the Adventure scenes make you practice it.

Where to go from here

If you already have an RTJ account, the Security+ track is sitting in your dashboard right now. Open it, take the Practice Exam, and inspect the scored attempt plus its effect on your evidence. The whole loop takes 35 minutes.

If you do not have an account yet, sign up on the free tier and run the same loop. No card required. The Security+ track page walks through the full objective map if you want to see the syllabus before you start.

If you are mapping a longer path, the A+ track and Net+ track pages cover the rest of the trinity in the same depth.

Questions about your specific path? Email the team. We reply personally, usually within a day.

Sources

  1. CompTIA. CompTIA Security+ certification overview (SY0-701). Domain weights, objective list, exam format, and scoring referenced throughout the post.
  2. U.S. Department of Defense. DoD Cyber Workforce Framework (DCWF) and the 8140 qualification matrix. Source for the work-role qualification model, the February 15, 2023 effective date of DoD Manual 8140.03, and its cancellation of DoD 8570.01-M. Look up the specific work role code before trusting a job posting's cert list.
  3. U.S. Bureau of Labor Statistics. Occupational Outlook Handbook: Information Security Analysts. Source for the 29 percent projected employment growth (2024 to 2034) and the $124,910 median annual wage (May 2024). BLS reports by occupation. It publishes no wage series for certification holders, so any "Security+ salary" figure you see elsewhere is somebody's survey, not federal data.

About the authors

Nicholas Miller
Founder and Lead Author

IT Service Center Manager and former CTE / IT teacher. Owner of Revtek IT Solutions in Chicago's south suburbs. Writes everything that ships under his name and reviews every line of Revy-assisted drafting before publish.

LinkedIn ↗
R
Revy
Study buddy · AI co-author

Revy helps draft and structure these posts. Every piece is reviewed, edited, and fact-checked by Nick before publish. We disclose this here because it is the right thing to do. See the AI Policy for the full stance.

Who writes this, and who checks it

Nicholas Miller
IT Service Center Manager · former high school CTE and IT teacher · founder of Revtek IT Solutions

Nick writes and edits these posts. AI helps with research, outlines, and first drafts. Nick reviews the draft before it goes live, and he is the only reviewer, so this is one person checking his own work. That catches a lot and it misses some.

When a post turns out to be wrong, the fix and the date it happened go on the corrections log, in public, including the ones nobody outside noticed. We do not use confidential, recalled, or leaked exam content. These posts are written from CompTIA's published objectives and authoritative technical sources. The AI policy has the longer version.

LinkedIn ↗