CompTIA Security+ · SY0-701
One workspace for passing Security+ (SY0-701) — the foundational cybersecurity cert. Domain-weighted decks, a high-yield acronym drill, a full practice exam, a study routine, and free-first resources.
Study SY0-701 now.It's the only version testable in mid-2026. A successor (SY0-801) is announced for ~Nov 2026 but isn't live yet, and a credential earned on SY0-701 stays valid for 3 years. Security+ is knowledge-based, so this path has no hands-on lab — the exam's few performance-based questions (PBQs) are simulated as scenario questions in the practice exam.
Certification roadmap
sequenceOptional prerequisites
Not required, but Network+ networking basics make Security+ easier. Skip if you already have ~2 years of IT/security experience (CompTIA's recommended background).
Intermediate · max 90 questions (MCQ + PBQs) · 90 min · 750/900 to pass · valid 3 yrs
The target of this workspace. Current version SY0-701 (Exam Objectives v5.0). A successor (SY0-801) is announced for ~Nov 2026 but is NOT live — study SY0-701 now; it's the only version testable in mid-2026.
Advanced
Natural progressions: CySA+ (analyst/blue-team) or SecurityX (formerly CASP+). Earning a higher CompTIA cert also renews Security+.
Exam domains — weight your study by these
official weights| Domain | Weight | What it covers |
|---|---|---|
| 1.0 General Security Concepts | 12% | Control types & categories, CIA/AAA, Zero Trust, physical security, change management, cryptography & PKI. |
| 2.0 Threats, Vulnerabilities & Mitigations | 22% | Threat actors, attack vectors & social engineering, vulnerability types, malware & attack indicators, mitigations. |
| 3.0 Security Architecture | 18% | Cloud & architecture models, securing infrastructure, data protection & classification, resilience & recovery (RTO/RPO). |
| 4.0 Security Operations | 28% | Hardening, asset & vulnerability management, monitoring (SIEM), IAM & MFA, automation, incident response, investigation. |
| 5.0 Security Program Management & Oversight | 20% | Governance, risk management (SLE/ARO/ALE), third-party risk, compliance, audits & pentesting, security awareness. |
Security Operations (28%) + Threats (22%) = half the exam — the decks are sized to match.
Flashcard decks — the recall layer
6 decks · 193 cardsDomains 2–5 + Acronyms
Practice exams
live · 3 full-length + 1 quick poolSit A, B and C in that order — they are three separate question sets, not one pool reshuffled. Each is 90 questions in 90 minutes, weighted to the official blueprint (D1 11 · D2 20 · D3 16 · D4 25 · D5 18) and scored against 83%, the real 750-of-900 bar. Because no question is shared between them, a score that climbs from A to C is genuine learning rather than remembering. Take the first one cold and timed — the score barely matters, the per-objective breakdown is the point.
Tick Calibrate mode on the start screen. It scores how confident you were against whether you were actually right, which surfaces what you are confidently wrong about — the most dangerous category, because you will never think to revise it.
Professor Messer's free course — mapped to all 28 objectives
free · 121 videos · 15h 11mDo not watch this end to end unless you have weeks. Use it as a lookup table. When a practice exam flags an objective — say 4.6 Identity & access management — open that objective below and watch its 4 videos (31 min), rather than scrubbing a 15-hour course for the ten minutes you actually need.
Entirely free. Links go to Professor Messer's own site; the per-objective grouping and runtimes below are read directly from his published course index.
1.0 General Security Concepts — 12% of the exam · 18 videos · 151 min
1.1 Security controls (1 · 12 min)
- Security Controls11:48
1.2 Fundamental security concepts (7 · 52 min)
1.3 Change management (2 · 22 min)
1.4 Cryptographic solutions (8 · 65 min)
2.0 Threats, Vulnerabilities & Mitigations — 22% of the exam · 38 videos · 252 min
2.1 Threat actors & motivations (1 · 10 min)
- Threat Actors10:23
2.2 Threat vectors & attack surfaces (5 · 37 min)
2.3 Types of vulnerabilities (14 · 74 min)
- Memory Injections2:39
- Buffer Overflows3:37
- Race Conditions4:58
- Malicious Updates5:45
- Operating System Vulnerabilities4:09
- SQL Injection5:09
- Cross-site Scripting8:34
- Hardware Vulnerabilities6:27
- Virtualization Vulnerabilities5:29
- Cloud-specific Vulnerabilities4:06
- Supply Chain Vulnerabilities9:12
- Misconfiguration Vulnerabilities7:09
- Mobile Device Vulnerabilities3:23
- Zero-day Vulnerabilities3:02
2.4 Indicators of malicious activity (15 · 105 min)
- An Overview of Malware6:06
- Viruses and Worms5:54
- Spyware and Bloatware4:21
- Other Malware Types7:32
- Physical Attacks4:04
- Denial of Service6:07
- DNS Attacks8:57
- Wireless Attacks7:55
- On-path Attacks5:30
- Replay Attacks5:45
- Malicious Code3:40
- Application Attacks11:48
- Cryptographic Attacks9:31
- Password Attacks7:15
- Indicators of Compromise10:59
2.5 Mitigation techniques (3 · 25 min)
3.0 Security Architecture — 18% of the exam · 18 videos · 152 min
3.1 Architecture model implications (4 · 45 min)
3.2 Securing enterprise infrastructure (6 · 45 min)
3.3 Protecting data (3 · 26 min)
3.4 Resilience & recovery (5 · 35 min)
- Resiliency9:42
- Capacity Planning3:53
- Recovery Testing5:18
- Backups12:16
- Power Resiliency4:02
4.0 Security Operations — 28% of the exam · 29 videos · 247 min
4.1 Securing computing resources (5 · 43 min)
4.2 Asset management (1 · 9 min)
- Asset Management8:37
4.3 Vulnerability management (5 · 38 min)
4.4 Alerting & monitoring (2 · 25 min)
- Security Monitoring10:27
- Security Tools14:06
4.5 Enhancing enterprise capabilities (7 · 54 min)
- Firewalls11:31
- Web Filtering10:00
- Operating System Security3:22
- Secure Protocols4:47
- Email Security7:05
- Monitoring Data7:25
- Endpoint Security9:25
4.6 Identity & access management (4 · 31 min)
4.7 Automation & orchestration (1 · 8 min)
4.8 Incident response (3 · 26 min)
4.9 Data sources for investigation (1 · 14 min)
- Log Data13:41
5.0 Security Program Management & Oversight — 20% of the exam · 17 videos · 100 min
5.1 Security governance (5 · 31 min)
5.2 Risk management (4 · 19 min)
5.3 Third-party risk (2 · 17 min)
5.4 Security compliance (2 · 13 min)
- Compliance8:06
- Privacy5:21
5.5 Audits & assessments (2 · 8 min)
5.6 Security awareness (2 · 11 min)
- Security Awareness6:45
- User Training4:31
PBQs and the limits of this path
honestSecurity+ is a knowledge-based exam — there is no product to break-fix, so this path is decks and exams rather than a lab. For genuinely hands-on security reps, the CKA and Linux/Docker labs elsewhere on The Dev Bench build adjacent skills.
On performance-based questions, be clear about what the PBQ drill is and is not. The real exam presents an interactive simulation — drag-and-drop, a firewall configuration screen, a terminal. This engine is multiple choice, so the drill does not reproduce that interface. What it does reproduce is the part that actually decides the outcome: reading a dense scenario — a rule table, raw log lines, a permissions matrix — and reasoning to a defensible answer under time pressure. The interface is the easy half to pick up on the day; the reasoning is not.
Exam-day tactics for PBQs: they come first, before any multiple choice, and they are weighted more heavily than a single MCQ. Read every instruction before touching anything. If one looks overwhelming, flag it and move on — clear the multiple choice, then return with what time remains. Pearson VUE gives you flag-for-review, an item-review screen at the end, highlight and strikethrough on the question text, and a digital whiteboard. Knowing those exist beforehand is one less thing consuming your attention at 8:30 in the morning.
Skill map — where to practice each thing
the workspace| Skill | Practice with | Status |
|---|---|---|
| Per-domain concept recall | The five domain decks (weighted to the blueprint) | ready |
| Acronym fluency (319 on the official list) | High-yield deck (83, with context) + complete list deck (237) | ready |
| Full-length timed exam endurance | Exams A, B and C — 90 questions in 90 min, three distinct sets | ready |
| Per-objective weak-area targeting | Exam results tag to one of the 28 objectives, then jump to that objective's videos | ready |
| Confidence calibration | Calibrate mode on any practice exam — finds what you are confidently wrong about | ready |
| Performance-based questions (PBQs) | PBQ drill — 6 scenarios, 30 decision steps (reasoning, not the real drag-and-drop interface) | ready |
| Full video course | Professor Messer's free SY0-701 course, mapped per objective below | external |
The final six days before a booked exam
if the date is setWith the date already booked, more study material is the wrong investment — testing yourself beats re-reading it, by a wide margin. So this week is diagnosis and targeted repair, not coverage.
Day 1Exam A, cold and timed. Nothing else.
Sit the full 90 in 90 minutes with Calibrate mode on, look nothing up, and do not pause. The score is not the point — the per-objective breakdown is, and it is only honest if you don't help yourself. Then read the explanation for every single miss, including the ones you guessed right.
Day 2Attack the weak objectives Exam A named.
For each weak objective, watch its videos above (usually 10-40 minutes, not hours), then drill that domain's deck. Interleave — rotate between two or three objectives rather than blocking one all day; mixing is harder in the moment and retains far better. Start the high-yield acronym deck in short bursts.
Day 3PBQ drill, then Exam B.
Work all six PBQ scenarios first — this is the format most likely to rattle you on the day. Then sit Exam B, timed. Compare per-objective against A: the gap is your actual progress, since the two share no questions.
Day 4Second pass on whatever is still weak.
By now the same one or two objectives have probably been flagged twice. Those get the time. Keep the acronym deck ticking daily — spacing across days is what makes it stick, and one long cram session on the last day is close to worthless.
Day 5Exam C — the honest readiness check.
Hardest of the three, and the one weighted toward BEST/FIRST discrimination. Pass it at 83% under the timer and you are ready. Miss it and you still have a day, and you will know exactly where to spend it.
Day 6Deliberately light. No new material.
Re-read the explanations you got wrong, skim the acronym decks, and stop early. Cramming the night before trades memory consolidation for anxiety, and you are sitting this in the morning — sleep is doing more for your score at this point than another hour of questions.
A study routine
if the exam is further out- 1.Watch a section of Professor Messer's free SY0-701 course, then drill that domain's deck — recall out loud before revealing. ~20 min/day.
- 2.Drill the Acronyms deck daily in short bursts — it's the highest-leverage spaced-repetition target for this exam.
- 3.Once two domains feel solid, sit the practice exam; review every miss and watch the per-domain weak-area breakdown.
- 4.Weight your time to the heavy domains: Security Operations (28%) and Threats (22%) are half the exam.
- 5.Before booking, aim for ≥85% on the practice exam across several attempts under the timer.
Curated resources — free-first
verified July 2026Everything you need to pass is free (Professor Messer + the official objectives). Paid options are labeled. Every link checked live (July 2026); prices shift, so treat costs as “as seen.”