Study Guide

Security+ SY0-701 Study Guide: 5 Domains Explained

A domain-by-domain Security+ SY0-701 study guide: the five domains, their exam weights, and what to focus on in each one.

By CompCertQuiz Editorial · Published · Last reviewed · 9 min read

CompTIA Security+ SY0-701 is a vendor-neutral exam built around five domains. The fastest way to study is to let the domain weights decide how your hours are split, then go deep on the topics CompTIA lists in its official objectives. This guide walks through each domain, shows what the exam tends to test, and gives concrete things to practice.

Version note: this article covers SY0-701. CompTIA has announced a successor, Security+ V8 (exam code SY0-801), with a launch planned for November 2026. Check the CompTIA Security+ V8 page for current dates and objectives before you schedule, and book the version that matches the objectives you studied.

The five SY0-701 domains and their weights

These are the domain percentages published in the SY0-701 exam objectives on comptia.org:

DomainNameWeight
1General Security Concepts12%
2Threats, Vulnerabilities, and Mitigations22%
3Security Architecture18%
4Security Operations28%
5Security Program Management and Oversight20%

Domains 2 and 4 together account for 50% of the exam. A sensible rule is to split your study time roughly in proportion to those weights, then add extra hours to whichever domain your practice scores show is weakest.

Domain 1: General Security Concepts (12%)

This is the smallest domain, but its vocabulary shows up in every other domain, so learn it first.

What to study

  • Control categories and types. Categories are technical, managerial, operational and physical. Types are preventive, deterrent, detective, corrective, compensating and directive. Expect scenario questions that ask you to classify a control on both axes.
  • Core concepts. The CIA triad (confidentiality, integrity, availability), non-repudiation, and AAA (authentication, authorization, accounting). Zero trust, including the control plane and data plane, policy engine, policy administrator and policy enforcement point.
  • Physical security and deception. Bollards, access control vestibules, fencing, sensors, and deception tools such as honeypots, honeynets, honeyfiles and honeytokens.
  • Change management. Approval, impact analysis, test results, backout plan, maintenance window and standard operating procedures.
  • Cryptographic solutions. Symmetric versus asymmetric encryption, hashing, salting, key stretching, digital signatures, PKI and certificates, TPM and HSM, tokenization, masking and steganography.

Practice tip: build a one-page table of control types with a real example of each (for instance, a security camera is a detective, physical control; a firewall rule is a preventive, technical control; a warning banner is a deterrent). Drill it until classification is automatic.

Domain 2: Threats, Vulnerabilities, and Mitigations (22%)

This domain is about recognizing what is happening in a scenario and picking the right response.

What to study

  • Threat actors and motivations. Nation-state, unskilled attacker, hacktivist, insider threat, organized crime, and shadow IT, with motivations such as financial gain, espionage, service disruption and ethical or political belief.
  • Threat vectors and attack surfaces. Phishing, vishing, smishing, business email compromise, pretexting, watering hole, typosquatting, removable media, unsecure networks, open service ports, default credentials and supply chain.
  • Vulnerability types. SQL injection, cross-site scripting, buffer overflow, race conditions (TOC/TOU), VM escape, sideloading, jailbreaking, misconfiguration, end-of-life software and zero-day vulnerabilities. The OWASP Top 10 is a good companion for the web-application items.
  • Indicators of malicious activity. Malware (ransomware, trojan, worm, rootkit, keylogger, logic bomb), network attacks (DDoS, on-path, DNS attacks, credential replay), password attacks (spraying, brute force) and application attacks (injection, directory traversal, privilege escalation).
  • Mitigation techniques. Segmentation, patching, least privilege, application allow lists, isolation, encryption, monitoring, configuration enforcement and hardening.

Practice tip: for each attack, learn the one detail that distinguishes it from look-alikes. Password spraying tries one or a few common passwords across many accounts; brute force tries many passwords against one account. A watering hole compromises a site the victims visit; phishing goes to the victim directly.

Domain 3: Security Architecture (18%)

What to study

  • Architecture models. Cloud (shared responsibility, hybrid, multi-cloud), infrastructure as code, serverless, microservices, containerization, virtualization, software-defined networking, air-gapped networks, IoT, ICS/SCADA, embedded systems and RTOS.
  • Securing enterprise infrastructure. Device placement, security zones, screened subnets, fail-open versus fail-closed, inline versus tap/monitor, jump servers, proxies, IDS/IPS, load balancers, 802.1X port security, firewall types (WAF, UTM, NGFW), VPN, IPsec, TLS, SD-WAN and SASE.
  • Data protection. Data types and classifications, data states (at rest, in transit, in use), data sovereignty, and protection methods such as encryption, masking, tokenization and segmentation.
  • Resilience and recovery. High availability, load balancing versus clustering, hot/warm/cold sites, backups and snapshots, replication, UPS and generators, and testing methods such as tabletop exercises and failover tests.

Practice tip: draw a simple network (internet, firewall, screened subnet with web server, internal LAN) and place every appliance on it. Many PBQs ask you to do exactly this.

Domain 4: Security Operations (28%)

The largest domain is about how security work is actually done day to day. Budget the most time here.

What to study

  • Secure baselines and hardening. Establish, deploy and maintain baselines; mobile device management; wireless security settings (including WPA3); application security and sandboxing.
  • Asset management. Acquisition, tracking, and disposal including sanitization, destruction and certification of destruction.
  • Vulnerability management. Scanning, static and dynamic analysis, penetration testing, bug bounty, CVE and CVSS, false positives versus false negatives, remediation, compensating controls and rescanning to validate fixes.
  • Monitoring and tooling. SIEM, log aggregation, alert tuning, NetFlow, SNMP traps, DLP, EDR/XDR, NAC, DNS filtering, and email security with SPF, DKIM and DMARC.
  • Identity and access management. Provisioning and deprovisioning, federation, SSO, SAML, OAuth, LDAP, access control models (MAC, DAC, RBAC, rule-based, ABAC), multifactor authentication, password concepts, and privileged access management.
  • Automation and incident response. The incident response process (preparation, detection, analysis, containment, eradication, recovery, lessons learned), root cause analysis, threat hunting and digital forensics (legal hold, chain of custody, preservation, e-discovery). NIST SP 800-61 is the standard reference for incident handling.
  • Investigation data sources. Firewall, application, endpoint, OS and network logs, packet captures, vulnerability scan output and dashboards.

Practice tip: memorize the incident response order and then practice mapping scenarios to a phase. If a question describes isolating an infected host, that is containment, not eradication.

Domain 5: Security Program Management and Oversight (20%)

What to study

  • Governance. Policies, standards and procedures; the difference between them; data roles (owner, controller, processor, custodian or steward); governance structures and external considerations such as regulatory and legal requirements.
  • Risk management. Qualitative versus quantitative analysis; SLE, ARO and ALE (SLE multiplied by ARO equals ALE); risk register, appetite and tolerance; strategies (accept, avoid, transfer, mitigate); and business impact analysis metrics RTO, RPO, MTTR and MTBF.
  • Third-party risk. Vendor assessment and due diligence, right to audit, and agreement types such as SLA, MOA, MOU, MSA, SOW, NDA and BPA.
  • Compliance and privacy. Reporting, consequences of non-compliance, attestation, data subjects, controllers and processors, retention and the right to be forgotten.
  • Audits, assessments and awareness. Internal and external audits, penetration testing environments (known, partially known, unknown), and security awareness programs including phishing simulations.

Practice tip: this domain is vocabulary-heavy and rewards precision. Make flashcards for paired terms that are easy to mix up (policy versus standard, controller versus processor, MOU versus SLA).

A simple way to allocate study time

  1. Read the full objectives list once so nothing in the exam is a surprise.
  2. Study Domain 1 first, then work through 2, 3, 4 and 5 using your preferred book or video course.
  3. Take a practice set after each domain and write down every miss with a one-line reason.
  4. In the last phase, mix domains in timed sets. Try the free SY0-701 practice questions to see what scenario-style questions feel like.

Frequently asked questions

How many domains are on the Security+ SY0-701 exam?

Five: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management and Oversight (20%).

Which SY0-701 domain is the biggest?

Security Operations at 28%. It covers monitoring, vulnerability management, identity and access management, automation and incident response, so it deserves the largest share of your study hours.

Do I need to memorize every acronym in the objectives?

CompTIA publishes an acronym list with the objectives, and you should be able to expand and explain the ones that appear in the objective bullets. Understanding what each does matters more than reciting the expansion, because questions are usually scenario based.

Is Security+ SY0-701 still the right exam to study for?

SY0-701 is the current version at the time of writing, and CompTIA has announced SY0-801 for a November 2026 launch. If you plan to test soon, SY0-701 is appropriate; if your exam date is after the new version launches, confirm on comptia.org which objectives apply.

Ready to test yourself? Start with the Security+ SY0-701 overview or jump straight into free practice. When you are ready to plan your weeks, follow our 30-day Security+ study plan, review the common Security+ exam traps, and check the Security+ exam cost before you book.

CompCertQuiz is an independent practice-exam site and is not affiliated with, endorsed by, or sponsored by CompTIA. Our practice questions are original material written for exam preparation. CompTIA and its certification names are trademarks of CompTIA, Inc. Always confirm exam details on comptia.org.

More from the blog