Security+ Exam Objectives (SY0-701): All Five Domains, Weighted
This is the full SY0-701 objectives list with CompTIA's official weights, plus the part a plain copy of the objectives leaves out: what each one actually asks of you, and where the marks concentrate. The headline to act on is that Security Operations alone is 28% of the exam - more than twice Domain 1 - and together with Threats it accounts for half your score.
See your score broken down by these exact domains
The objectives tell you what is testable. A full-length practice exam tells you which parts of it you cannot do yet. The first one is free - explanation and Exam Tip on every item, plus a personalized Exam Coach that names the weak domains in priority order. Create an account on the next screen and the code applies itself.
SECPLUS-EXAM-FULL
Start the free exam
Already have an account? Log in to start · Prefer a 5-question taster? Try the short version.
On this page
Where the marks are
Two things follow from that shape, and most study plans get both wrong:
- Domain 4 deserves roughly a third of your time. It has nine sub-objectives, the most of any domain, and covers hardening, vulnerability management, monitoring and alerting, identity and access management, automation, incident response and investigation. People under-study it because "operations" sounds vague. It is where the exam lives.
- Domain 5 is not filler. Governance, risk, third-party management, compliance and audits are 20% - more than Security Architecture. Technical candidates routinely skim it and lose a fifth of the exam. It is also the most learnable, because it is definitions and processes rather than judgement.
How to read the objectives
CompTIA prefixes each sub-objective with a phrase that tells you the depth expected, and it is the single most useful signal on the page:
- "Given a scenario…" - you will have to apply it to a situation, and these are the sub-objectives most likely to appear as a performance-based question. There are seven of them in SY0-701. Treat every one as high priority.
- "Explain…" / "Summarize…" - understanding and recall. Solid reading is enough.
- "Compare and contrast…" - you need the boundaries between similar things, which is where distractors are built. Expect questions whose four options are all real terms from the same family.
The five domains, objective by objective
1.0 General Security Concepts4 sub-objectives. The vocabulary the other four domains assume.
- 1.1Compare and contrast various types of security controlsCategories: technical, managerial, operational, physical. Types: preventive, deterrent, detective, corrective, compensating, directive. Expect questions that give you a control and ask for both its category and its type - they are independent axes, and mixing them up is the classic Domain 1 loss.
- 1.2Summarize fundamental security conceptsCIA triad, non-repudiation, AAA for people and systems, authorization models, gap analysis, zero trust (control plane and data plane, policy engine, policy administrator, policy enforcement point), physical security, and deception technology - honeypots, honeynets, honeyfiles, honeytokens.
- 1.3Explain the importance of change management and its security impactApproval process, ownership, stakeholders, impact analysis, test results, backout plan, maintenance window, standard operating procedure; technical implications such as allow and deny lists, restricted activities, downtime, restarts, legacy applications and dependencies; documentation and version control. Dry, and reliably tested.
- 1.4Explain the importance of using appropriate cryptographic solutionsPKI and key management, symmetric and asymmetric encryption, key exchange and key length, encryption levels from full-disk to record, TPM and HSM, secure enclave, obfuscation (steganography, tokenization, data masking), hashing and salting, digital signatures, key stretching, blockchain, and certificates - CA, CRL, OCSP, self-signed, wildcard, CSR. Cryptography and PKI guide.
2.0 Threats, Vulnerabilities, and Mitigations5 sub-objectives. The most memorable domain, and the one with the most terminology.
- 2.1Compare and contrast common threat actors and motivationsNation-state, unskilled attacker, hacktivist, insider threat, organised crime, shadow IT; attributes such as internal versus external, resources and funding, level of sophistication; motivations from data exfiltration and espionage to service disruption, blackmail, ethical, revenge, war.
- 2.2Explain common threat vectors and attack surfacesMessage-based (email, SMS, instant messaging), image and file based, voice call, removable device, vulnerable software, unsupported systems, unsecure networks, open service ports, default credentials, supply chain, and the human vectors - phishing, vishing, smishing, misinformation, impersonation, business email compromise, pretexting, watering hole, brand impersonation, typosquatting.
- 2.3Explain various types of vulnerabilitiesApplication (memory injection, buffer overflow, race conditions including TOC/TOU, malicious update), operating system, web (SQL injection, XSS), hardware (firmware, end-of-life, legacy), virtualization (VM escape, resource reuse), cloud, supply chain, cryptographic, misconfiguration, mobile (side loading, jailbreaking) and zero-day.
- 2.4Given a scenario, analyze indicators of malicious activityMalware types, physical and network attacks, application attacks, cryptographic attacks, password attacks, and the indicators themselves - account lockout, impossible travel, resource consumption, out-of-cycle logging, missing logs, published documents. High-value: this is scenario-based and often a PBQ. Attack types guide.
- 2.5Explain the purpose of mitigation techniques used to secure the enterpriseSegmentation, access control (ACLs and permissions), application allow lists, isolation, patching, encryption, monitoring, least privilege, configuration enforcement, decommissioning, and hardening targets from encryption and endpoint protection to host-based firewalls, HIPS, disabling ports and protocols, default password changes and removal of unnecessary software.
3.0 Security Architecture4 sub-objectives. Design decisions and their trade-offs.
- 3.1Compare and contrast security implications of different architecture modelsCloud responsibility models, infrastructure as code, serverless, microservices, network infrastructure choices (physical isolation and air gap, logical segmentation, SDN), on-premises, centralised versus decentralised, containerisation, virtualization, IoT, ICS and SCADA, RTOS, embedded systems, and the considerations that separate them - availability, resilience, cost, responsiveness, scalability, ease of deployment, patch availability, power and compute.
- 3.2Given a scenario, apply security principles to secure enterprise infrastructureDevice placement, security zones, attack surface, connectivity, failure modes (fail-open versus fail-closed), device attributes (active versus passive, inline versus tap or monitor), network appliances, port security with 802.1X and EAP, firewall types, and secure communication including VPN, remote access, tunnelling with TLS and IPsec, SD-WAN and SASE. A frequent PBQ source - expect to place devices on a diagram.
- 3.3Compare and contrast concepts and strategies to protect dataData types and classifications (regulated, trade secret, intellectual property, legal, financial, human and non-human readable; sensitive, confidential, public, restricted, private, critical), states of data (at rest, in transit, in use), data sovereignty and geolocation, and the methods - geographic restrictions, encryption, hashing, masking, tokenization, obfuscation, segmentation, permission restrictions.
- 3.4Explain the importance of resilience and recovery in security architectureHigh availability and load balancing versus clustering, site considerations (hot, cold, warm, geographic dispersion), platform diversity, multi-cloud, continuity of operations, capacity planning for people, technology and infrastructure, testing (tabletop exercises, failover, simulation, parallel processing), backups including snapshots, replication, journaling and encryption, and power resilience with generators and UPS.
4.0 Security Operations9 sub-objectives - the most of any domain, and the largest weight. Study this one hardest.
- 4.1Given a scenario, apply common security techniques to computing resourcesSecure baselines (establish, deploy, maintain), hardening targets from mobile devices and workstations to switches, routers, servers, ICS/SCADA, embedded and IoT; wireless devices including installation and site surveys, heat maps; mobile deployment models (BYOD, COPE, CYOD), connection methods, wireless security settings (WPA3, AAA/RADIUS, cryptographic protocols, authentication protocols), and application security - input validation, secure cookies, static analysis, code signing, sandboxing, monitoring.
- 4.2Explain the security implications of proper hardware, software and data asset managementAcquisition and procurement, assignment and ownership, classification, monitoring and asset tracking including inventory and enumeration, and disposal and decommissioning - sanitization, destruction, certification, data retention.
- 4.3Explain various activities associated with vulnerability managementIdentification methods (vulnerability scan, application security testing, threat feeds, OSINT, dark web, penetration testing, responsible disclosure, bug bounty, system/process audit), analysis (confirmation, false positives and negatives, prioritize, CVSS, CVE, vulnerability classification, exposure factor, environmental variables, industry impact, risk tolerance), response and remediation, and validation and reporting.
- 4.4Explain security alerting and monitoring concepts and toolsMonitoring computing resources - systems, applications, infrastructure; activities including log aggregation, alerting, scanning, reporting, archiving, alert response, validation, quarantine and alert tuning; and the tools - SCAP, benchmarks, agents versus agentless, SIEM, antivirus, DLP, SNMP traps, NetFlow, vulnerability scanners. A real log-analysis PBQ, walked through.
- 4.5Given a scenario, modify enterprise capabilities to enhance securityFirewall rules and access lists, IDS/IPS trends and signatures, web filtering (agent-based, centralised proxy, URL scanning, content categorisation, block rules, reputation), operating system security including group policy and SELinux, secure protocols and port selection, DNS filtering, email security (DMARC, DKIM, SPF, gateways), file integrity monitoring, DLP, network access control, EDR and XDR, and user behaviour analytics.
- 4.6Given a scenario, implement and maintain identity and access managementProvisioning and de-provisioning, permission assignments, identity proofing, federation, SSO with LDAP, OAuth and SAML, interoperability, attestation, access controls (mandatory, discretionary, role-based, rule-based, attribute-based, time-of-day, least privilege), multifactor authentication with its factors and implementations, and password concepts including policies, managers and passwordless. High-yield and PBQ-prone.
- 4.7Explain the importance of automation and orchestration related to secure operationsUse cases such as user and resource provisioning, guard rails, security groups, ticket creation and escalation, enabling and disabling services, continuous integration and testing, and API integration; plus the benefits and the other side - complexity, cost, single point of failure, technical debt, ongoing supportability.
- 4.8Explain appropriate incident response activitiesThe process - preparation, detection, analysis, containment, eradication, recovery, lessons learned - plus training, testing through tabletop exercises and simulations, root cause analysis, threat hunting, and digital forensics including legal hold, chain of custody, acquisition, reporting, preservation and e-discovery. Learn the phase order cold; questions frequently hinge on which phase an action belongs to.
- 4.9Given a scenario, use data sources to support an investigationLog data - firewall, application, endpoint, OS-specific security logs, IPS/IDS, network, metadata - and other sources such as vulnerability scans, automated reports, dashboards and packet captures. In practice this means reading log excerpts and drawing a conclusion, which is exactly what the PBQs ask.
5.0 Security Program Management and Oversight6 sub-objectives. The domain technical candidates skim - and it is a fifth of the exam.
- 5.1Summarize elements of effective security governanceGuidelines, policies (AUP, information security, business continuity, disaster recovery, incident response, SDLC, change management), standards (password, access control, physical security, encryption), procedures (change management, onboarding and offboarding, playbooks), external considerations (regulatory, legal, industry, local/regional/national/global), monitoring and revision, governance structures (boards, committees, government entities, centralised versus decentralised) and roles - owners, controllers, processors, custodians, stewards.
- 5.2Explain elements of the risk management processRisk identification and assessment (ad hoc, recurring, one-time, continuous), risk analysis (qualitative, quantitative, SLE, ALE, ARO), risk register with key risk indicators, owners and thresholds, risk tolerance and appetite (expansionary, conservative, neutral), risk response - transfer, accept with exemption or exception, avoid, mitigate - plus reporting and business impact analysis with RTO, RPO, MTTR and MTBF. Learn the formulas; they are free marks.
- 5.3Explain the processes associated with third-party risk assessment and managementVendor assessment (penetration testing, right-to-audit clause, evidence of internal audits, independent assessments, supply chain analysis), vendor selection through due diligence and conflict-of-interest checks, agreement types - SLA, MOA, MOU, MSA, WO/SOW, NDA, BPA - and vendor monitoring, questionnaires and rules of engagement.
- 5.4Summarize elements of effective security complianceCompliance reporting (internal and external), consequences of non-compliance - fines, sanctions, reputational damage, loss of licence, contractual impacts - compliance monitoring through due diligence and care, attestation and acknowledgement, internal and external monitoring, automation, and privacy: legal implications at every jurisdictional level, data subject, controller versus processor, ownership, retention and the right to be forgotten.
- 5.5Explain types and purposes of audits and assessmentsAttestation; internal audits including compliance, audit committee and self-assessments; external audits including regulatory, examinations, assessment and independent third-party audit; and penetration testing - physical, offensive, defensive, integrated, known, partially known and unknown environment, plus reconnaissance types.
- 5.6Given a scenario, implement security awareness practicesPhishing campaigns and recognising attempts, anomalous behaviour recognition (risky, unexpected, unintentional), user guidance and training across policies, situational awareness, insider threat, password management, removable media, social engineering, operational security and hybrid or remote work; plus reporting and monitoring, initial and recurring, development and execution.
Turn the objectives into a priority list
A checklist tells you everything matters. One full-length attempt tells you which three sub-objectives are actually costing you marks. Free, no credit card, with a personalized Exam Coach that reads the whole attempt and names what to revisit first.
SECPLUS-EXAM-FULL
Redeem the code
Already have an account? Log in to redeem
What to study first
Weights tell you what the exam values, not what to learn first, because some domains are load-bearing for others. A sequence that works:
- Domain 1, despite being smallest. Control categories and types, CIA, AAA and zero trust are the vocabulary the other four domains use without explaining. Twelve percent of marks, and a prerequisite for the other 88.
- Domain 4, because it is where the marks are. Nine sub-objectives at 28%. Give it roughly a third of your total study time, and start with identity and access management (4.6) and incident response (4.8), which are the most reliably tested.
- Domain 2, which is mostly terminology. Attack types, threat actors and indicators are high-volume recall, so this is where flashcards genuinely help. Security+ flashcards, and the acronym list - CompTIA publishes 322 of them.
- Domain 5, deliberately and early enough. One fifth of the exam, almost pure definitions and processes, and the highest marks-per-hour of anything here. Learn the risk formulas (SLE, ALE, ARO) and the agreement types (MOU, MSA, SOW, BPA) properly.
- Domain 3 last. Architecture rewards understanding you will partly have absorbed from 4 and 5 by this point.
- Then the PBQs. Every "given a scenario" sub-objective is a candidate, and PBQs cost time as well as marks. How PBQs are marked and how to attack them.
Frequently asked questions
What are the Security+ SY0-701 domains and their weights?
Five domains: General Security Concepts 12%, Threats, Vulnerabilities and Mitigations 22%, Security Architecture 18%, Security Operations 28%, and Security Program Management and Oversight 20%. Security Operations is the largest by some distance, and with Threats it accounts for half the exam.
How many questions are on the Security+ exam?
A maximum of 90 questions in 90 minutes, mixing multiple choice with performance-based questions. The pass mark is 750 on a 100 to 900 scale. That is not simply 83 percent - the exam is scaled, so questions are not all worth the same and you cannot convert the pass mark into a number of correct answers.
Which domain should I study first?
Domain 1, even though it is the smallest. It defines the vocabulary - control categories and types, CIA, AAA, zero trust components - that the other four domains assume you already have. Then go straight to Domain 4 at 28%, because that is where the marks concentrate, and do not leave Domain 5 to the last week: it is 20% of the exam and the easiest 20% to learn.
Are the objectives the same as the syllabus or blueprint?
Yes. CompTIA publishes the document as "exam objectives"; candidates and training providers say syllabus or blueprint. All three refer to the same numbered list of domains and sub-objectives, and it is the authoritative statement of what the exam can test. Download the current PDF from CompTIA's Security+ certification page.
How are performance-based questions weighted?
CompTIA does not publish PBQ weighting. What is known: they usually appear early, they are worth more than a single multiple-choice item, and they consume time out of proportion to their number. The practical strategy is to flag and skip any PBQ that stalls you, clear the multiple-choice questions, and come back with whatever time is left - candidates fail on the clock more often than on the content.
Do I need to memorise all 322 acronyms?
Not as a list. CompTIA publishes them in an appendix to the objectives as a scope statement - it means any of them can appear without being spelled out. The efficient approach is to learn them grouped by what they do rather than alphabetically, so an unfamiliar one can be placed by context. The acronyms, grouped by function.