Skip to main content
CompTIA Security+ · SY0-701

Security+ that teaches judgment, not just terminology.

The vendor-neutral cybersecurity credential. Threats and attack types, identity and access, security architecture, operations and incident response. Our Sim shifts you to a SOC environment with social engineering attempts and incident scenarios.

Format
One exam
Questions
Up to 90
Time
90 min
Pass score
750/900
Exam objectives

What CompTIA Security+ actually covers.

Pulled directly from the official CompTIA exam objectives. Every line maps to our content.

1.0

General Security Concepts

12% of exam
  • Security control categories (technical, managerial, operational, physical)
  • Fundamental concepts (CIA triad, AAA)
  • Change management and PKI
  • Cryptographic solutions and key management
2.0

Threats, Vulnerabilities, Mitigations

22% of exam
  • Threat actors and motivations
  • Common attack types (phishing, vishing, malware, supply chain)
  • Vulnerability types and management
  • Mitigation techniques and segmentation
3.0

Security Architecture

18% of exam
  • Architecture models (cloud, hybrid, IaC, SDN, MSP, on-prem)
  • Enterprise infrastructure security principles
  • Data protection (classification, encryption at rest/in transit)
  • Resilience and recovery
4.0

Security Operations

28% of exam
  • Computing resource security (hardening, configuration)
  • Asset management lifecycle
  • Vulnerability management workflow
  • Security operations (logging, alerting, monitoring)
  • Identity and access management (auth, SSO, MFA, federation)
  • Automation and orchestration
  • Incident response phases
  • Investigations and digital forensics
5.0

Security Program Management

20% of exam
  • Effective security governance
  • Risk management process
  • Third-party risk and SLAs
  • Compliance and audit
  • Security awareness practices
Study timeline

How long it takes.

Honest estimates. The platform tracks your progress so you can see when you are ready, not just when the calendar says you should be.

Hours/weekWeeks to readySuited for
5 hours16-20 weeksWorking in IT, evening study
10 hours8-12 weeksNet+ holders moving into security
20+ hours5-7 weeksDedicated SOC pivot
Sample question

From the quiz pool.

Domain 2.0 Threats and Mitigations

A caller identifying as the company CEO calls the help desk claiming to be locked out of email before an important board meeting. They cannot recite their employee ID and want a password reset right away. The CEO's actual account shows an active session from the HQ office. What is the most appropriate response?

AReset the password and email it to the caller
BAsk the caller to email IT from the CEO's address to confirm
CRefuse the reset and escalate to security as a potential vishing attemptAnswer
DReset the password and require MFA verification
Why

The real CEO is already signed in from HQ. The unverified caller is using authority and urgency, classic vishing tells. The right move is to refuse the reset, document the call, and escalate to security to investigate. Any other choice could leak credentials to an attacker.

Questions.

Do I need Network+ before Security+?+

Recommended. Security+ assumes you understand subnetting, common ports, and basic networking. Net+ first makes Security+ noticeably easier.

How does the SOC Sim differ from the help desk Sim in A+?+

Same tools, different emphasis. Sec+ Sim leans heavy into identity verification, MFA push patterns, suspicious logins, social engineering attempts. Around 15-20 percent of tickets are bad-faith because that is the core of the cert.

Is the exam more scenario-based than memorization?+

Yes. Security+ SY0-701 is heavily scenario-driven. The Adventure mode and Sim are built around that style of question.

Does Security+ have performance-based questions?+

Yes, similar to A+. CompTIA includes PBQs that simulate small configuration tasks. Our Sim mode is the closest equivalent at scale.

Start CompTIA Security+ free. Move when ready.

Full free tier from day one. No credit card.