THE DEV BENCH
🛡️

CompTIA Security+ · SY0-701

One workspace for passing Security+ (SY0-701) — the foundational cybersecurity cert. Domain-weighted decks, a high-yield acronym drill, a full practice exam, a study routine, and free-first resources.

Study SY0-701 now.It's the only version testable in mid-2026. A successor (SY0-801) is announced for ~Nov 2026 but isn't live yet, and a credential earned on SY0-701 stays valid for 3 years. Security+ is knowledge-based, so this path has no hands-on lab — the exam's few performance-based questions (PBQs) are simulated as scenario questions in the practice exam.

Deep work · Security+total
or log

Certification roadmap

sequence
A+ / Network+CompTIA foundationsOptional first

Optional prerequisites

Not required, but Network+ networking basics make Security+ easier. Skip if you already have ~2 years of IT/security experience (CompTIA's recommended background).

SY0-701CompTIA Security+The goal

Intermediate · max 90 questions (MCQ + PBQs) · 90 min · 750/900 to pass · valid 3 yrs

The target of this workspace. Current version SY0-701 (Exam Objectives v5.0). A successor (SY0-801) is announced for ~Nov 2026 but is NOT live — study SY0-701 now; it's the only version testable in mid-2026.

CySA+ / SecurityXNext stepsAfter Security+

Advanced

Natural progressions: CySA+ (analyst/blue-team) or SecurityX (formerly CASP+). Earning a higher CompTIA cert also renews Security+.

Exam domains — weight your study by these

official weights
DomainWeightWhat it covers
1.0 General Security Concepts12%Control types & categories, CIA/AAA, Zero Trust, physical security, change management, cryptography & PKI.
2.0 Threats, Vulnerabilities & Mitigations22%Threat actors, attack vectors & social engineering, vulnerability types, malware & attack indicators, mitigations.
3.0 Security Architecture18%Cloud & architecture models, securing infrastructure, data protection & classification, resilience & recovery (RTO/RPO).
4.0 Security Operations28%Hardening, asset & vulnerability management, monitoring (SIEM), IAM & MFA, automation, incident response, investigation.
5.0 Security Program Management & Oversight20%Governance, risk management (SLE/ARO/ALE), third-party risk, compliance, audits & pentesting, security awareness.

Security Operations (28%) + Threats (22%) = half the exam — the decks are sized to match.

Flashcard decks — the recall layer

6 decks · 193 cards
D1 · General Security Concepts25 cards — control types/categories, CIA, AAA, Zero Trust, physical security, change management, and the crypto/PKI fundamentals the whole exam builds on. Start here.

Domains 2–5 + Acronyms

Practice exams

live · 3 full-length + 1 quick pool

Sit A, B and C in that order — they are three separate question sets, not one pool reshuffled. Each is 90 questions in 90 minutes, weighted to the official blueprint (D1 11 · D2 20 · D3 16 · D4 25 · D5 18) and scored against 83%, the real 750-of-900 bar. Because no question is shared between them, a score that climbs from A to C is genuine learning rather than remembering. Take the first one cold and timed — the score barely matters, the per-objective breakdown is the point.

Tick Calibrate mode on the start screen. It scores how confident you were against whether you were actually right, which surfaces what you are confidently wrong about — the most dangerous category, because you will never think to revise it.

Practice Exam A — full lengthstart here · diagnostic90 questions, 90 minutes, blueprint-weighted. Sit this first, cold, with nothing looked up. Its per-objective results tell you which of the 28 objectives to spend your remaining days on.Practice Exam B — full lengthdistinct set · more scenario-drivenA completely different 90 questions, leaning harder on applied scenarios. Sit it after you have worked your weak objectives from A.Practice Exam C — full length, hardestfinal readiness checkOver-weights the BEST/FIRST/MOST-likely discrimination questions and the near-miss pairs the real exam loves — RTO vs RPO, CVE vs CVSS, spraying vs stuffing, DAC vs MAC vs RBAC vs ABAC. Pass this at 83% and you are genuinely ready.Practice Exam D — full length, applieddistinct set · situationalA situation, then what are you looking at or what do you do next. Reaches corners the earlier sets touch once — OAuth versus OIDC, DMARC alignment, single loss expectancy arithmetic, zero trust policy enforcement points, legal hold.Practice Exam E — full length, precisiondistinct set · compare and contrastBuilt almost entirely from the near-miss pairs that decide borderline passes: TACACS+ versus RADIUS, hashing versus encryption, end-of-life versus end-of-support, residency versus sovereignty, event versus alert versus incident.Practice Exam F — full length, exam-realistic styleclosest to the real thing · sit this lastRebuilt to match CompTIA's actual house style after a measured comparison found the earlier sets too clean. Every item opens with a situation, every item asks BEST / MOST LIKELY / FIRST, distractors are deliberately defensible so several turn on picking the better of two reasonable actions, and eight embed dense PBQ-style data in the stem. Stems average roughly twice the length of the earlier sets.PBQ drill — 6 performance-based scenariosdo this before exam dayFirewall ACLs, log analysis, IAM, PKI, incident response and segmentation — 30 decision steps with worked explanations. The real exam OPENS with 3-6 of these and weights them heavily; this is the one thing you should not walk in having never practised.PBQ drill 2 — 6 further scenariosnew scenarios · no overlap with drill 1Thirty more decision steps across six entirely different scenarios: vulnerability scan triage, SPF/DKIM/DMARC email authentication, wireless deployment, insecure protocol replacement, forensic order of volatility, and cloud security posture. Sitting drill 1 twice trains recognition; this trains the skill.Quick drill pool — 45 questionsshorter · rotating drawA 45-question draw from a rotating pool. Useful for a short session between the full-length sits, not a substitute for one.

Professor Messer's free course — mapped to all 28 objectives

free · 121 videos · 15h 11m

Do not watch this end to end unless you have weeks. Use it as a lookup table. When a practice exam flags an objective — say 4.6 Identity & access management — open that objective below and watch its 4 videos (31 min), rather than scrubbing a 15-hour course for the ten minutes you actually need.

Entirely free. Links go to Professor Messer's own site; the per-objective grouping and runtimes below are read directly from his published course index.

1.0 General Security Concepts 12% of the exam · 18 videos · 151 min

1.1 Security controls (1 · 12 min)

1.3 Change management (2 · 22 min)

2.0 Threats, Vulnerabilities & Mitigations 22% of the exam · 38 videos · 252 min
3.0 Security Architecture 18% of the exam · 18 videos · 152 min

3.2 Securing enterprise infrastructure (6 · 45 min)

3.3 Protecting data (3 · 26 min)

3.4 Resilience & recovery (5 · 35 min)

4.0 Security Operations 28% of the exam · 29 videos · 247 min

4.2 Asset management (1 · 9 min)

4.4 Alerting & monitoring (2 · 25 min)

4.5 Enhancing enterprise capabilities (7 · 54 min)

4.6 Identity & access management (4 · 31 min)

4.7 Automation & orchestration (1 · 8 min)

4.8 Incident response (3 · 26 min)

4.9 Data sources for investigation (1 · 14 min)

5.0 Security Program Management & Oversight 20% of the exam · 17 videos · 100 min

5.3 Third-party risk (2 · 17 min)

5.4 Security compliance (2 · 13 min)

5.5 Audits & assessments (2 · 8 min)

5.6 Security awareness (2 · 11 min)

PBQs and the limits of this path

honest

Security+ is a knowledge-based exam — there is no product to break-fix, so this path is decks and exams rather than a lab. For genuinely hands-on security reps, the CKA and Linux/Docker labs elsewhere on The Dev Bench build adjacent skills.

On performance-based questions, be clear about what the PBQ drill is and is not. The real exam presents an interactive simulation — drag-and-drop, a firewall configuration screen, a terminal. This engine is multiple choice, so the drill does not reproduce that interface. What it does reproduce is the part that actually decides the outcome: reading a dense scenario — a rule table, raw log lines, a permissions matrix — and reasoning to a defensible answer under time pressure. The interface is the easy half to pick up on the day; the reasoning is not.

Exam-day tactics for PBQs: they come first, before any multiple choice, and they are weighted more heavily than a single MCQ. Read every instruction before touching anything. If one looks overwhelming, flag it and move on — clear the multiple choice, then return with what time remains. Pearson VUE gives you flag-for-review, an item-review screen at the end, highlight and strikethrough on the question text, and a digital whiteboard. Knowing those exist beforehand is one less thing consuming your attention at 8:30 in the morning.

Skill map — where to practice each thing

the workspace
SkillPractice withStatus
Per-domain concept recallThe five domain decks (weighted to the blueprint)ready
Acronym fluency (319 on the official list)High-yield deck (83, with context) + complete list deck (237)ready
Full-length timed exam enduranceExams A, B and C — 90 questions in 90 min, three distinct setsready
Per-objective weak-area targetingExam results tag to one of the 28 objectives, then jump to that objective's videosready
Confidence calibrationCalibrate mode on any practice exam — finds what you are confidently wrong aboutready
Performance-based questions (PBQs)PBQ drill — 6 scenarios, 30 decision steps (reasoning, not the real drag-and-drop interface)ready
Full video courseProfessor Messer's free SY0-701 course, mapped per objective belowexternal

The final six days before a booked exam

if the date is set

With the date already booked, more study material is the wrong investment — testing yourself beats re-reading it, by a wide margin. So this week is diagnosis and targeted repair, not coverage.

Day 1Exam A, cold and timed. Nothing else.

Sit the full 90 in 90 minutes with Calibrate mode on, look nothing up, and do not pause. The score is not the point — the per-objective breakdown is, and it is only honest if you don't help yourself. Then read the explanation for every single miss, including the ones you guessed right.

Day 2Attack the weak objectives Exam A named.

For each weak objective, watch its videos above (usually 10-40 minutes, not hours), then drill that domain's deck. Interleave — rotate between two or three objectives rather than blocking one all day; mixing is harder in the moment and retains far better. Start the high-yield acronym deck in short bursts.

Day 3PBQ drill, then Exam B.

Work all six PBQ scenarios first — this is the format most likely to rattle you on the day. Then sit Exam B, timed. Compare per-objective against A: the gap is your actual progress, since the two share no questions.

Day 4Second pass on whatever is still weak.

By now the same one or two objectives have probably been flagged twice. Those get the time. Keep the acronym deck ticking daily — spacing across days is what makes it stick, and one long cram session on the last day is close to worthless.

Day 5Exam C — the honest readiness check.

Hardest of the three, and the one weighted toward BEST/FIRST discrimination. Pass it at 83% under the timer and you are ready. Miss it and you still have a day, and you will know exactly where to spend it.

Day 6Deliberately light. No new material.

Re-read the explanations you got wrong, skim the acronym decks, and stop early. Cramming the night before trades memory consolidation for anxiety, and you are sitting this in the morning — sleep is doing more for your score at this point than another hour of questions.

A study routine

if the exam is further out
  1. 1.Watch a section of Professor Messer's free SY0-701 course, then drill that domain's deck — recall out loud before revealing. ~20 min/day.
  2. 2.Drill the Acronyms deck daily in short bursts — it's the highest-leverage spaced-repetition target for this exam.
  3. 3.Once two domains feel solid, sit the practice exam; review every miss and watch the per-domain weak-area breakdown.
  4. 4.Weight your time to the heavy domains: Security Operations (28%) and Threats (22%) are half the exam.
  5. 5.Before booking, aim for ≥85% on the practice exam across several attempts under the timer.

Curated resources — free-first

verified July 2026

Everything you need to pass is free (Professor Messer + the official objectives). Paid options are labeled. Every link checked live (July 2026); prices shift, so treat costs as “as seen.”

Start your reps