Exampractice
IT & Networking

CompTIA Security+ Certification Guide

What CompTIA Security+ is, the SY0-701 exam format and cost, who the certification suits, and a practical five-step route to earning and keeping it.

Liam Anderson · 9 min read
Trailhead signpost with a shield-marked gate representing CompTIA Security+ as the entry point to cybersecurity careers

CompTIA Security+ is the most established entry point into professional cybersecurity certification: a single vendor-neutral exam, currently version SY0-701, that validates the baseline security skills employers expect of a first security hire. There are no enforced prerequisites, the exam runs to a maximum of 90 questions in 90 minutes, and as of June 2026 the US retail price listed by CompTIA's authorised resellers is $439. This guide covers the whole journey — what the certification is, exactly what the exam looks like, who it suits, how to prepare, and what happens after you pass.

A note on versions before anything else, because it is the question most 2026 candidates ask first: SY0-701 has been the live exam since November 2023 and is the only version you can book as of August 2026. CompTIA's page lists an estimated retirement "in 2026" without a fixed date, and while a successor is widely expected, none has been officially announced. If you are ready to study now, study for SY0-701 — a pass keeps your certification valid for three years regardless of which exam version you sat.

What is CompTIA Security+?

CompTIA Security+ is a certification awarded by CompTIA, the vendor-neutral IT industry body behind A+ and Network+, and earned by passing one exam — currently SY0-701. It sits at the early-career level of the security field: above CompTIA's general IT certifications, below analyst- and architect-level credentials such as CySA+ and SecurityX (formerly CASP+).

Because it is vendor-neutral, Security+ certifies transferable security fundamentals rather than any one product — the thinking, terminology and core practices that apply whether your employer runs Microsoft, Cisco or an in-house stack. That neutrality is a large part of its market position: job adverts for junior security analysts, systems administrators with security duties and SOC (security operations centre) trainees regularly name it, and it is widely used in meeting US Department of Defense workforce requirements under the DoD 8140 programme, which makes it close to a default for security-adjacent roles around US government and defence contracting. (Whether all that recognition justifies the fee for your situation is a separate question, argued properly in is Security+ worth it in 2026.)

SY0-701 exam essentials

FactDetail (as of August 2026)
Exam codeSY0-701 (live since November 2023)
QuestionsMaximum 90 — many candidates see fewer, as unscored seeded questions vary
Time90 minutes
Question typesMultiple-choice (single and multiple response) plus performance-based questions
Passing score750 on a 100–900 scale
CostUS retail $439 per attempt, as listed by CompTIA's authorised resellers in June 2026; varies by country, with authorised-reseller vouchers typically cheaper
PrerequisitesNone enforced; CompTIA recommends Network+ plus two years in a security or systems administrator role
DeliveryPearson VUE test centres or OnVUE online proctoring from home
Validity3 years, renewable through CompTIA's Continuing Education programme

Three details in that table deserve emphasis. The 750 pass mark is a scaled score, not a percentage — do not read it as 83 per cent. The recommended experience is genuinely a recommendation: plenty of candidates pass without Network+ or two years in post, though the networking assumed by the exam then has to come from somewhere. And the fee buys one attempt; CompTIA sells a voucher-plus-retake bundle if you want insurance, and prices differ by region, so confirm the current figure for your country on comptia.org before budgeting.

What the exam covers

SY0-701 organises its objectives into five domains: General Security Concepts; Threats, Vulnerabilities and Mitigations; Security Architecture; Security Operations; and Security Program Management and Oversight. Together they span the vocabulary of the field, how attacks work and how they are blunted, secure design, day-to-day defensive operations, and the governance layer of risk and compliance. The full objectives document — including each domain's exact percentage weighting — is a free download from comptia.org, and a domain-by-domain walkthrough of what each one actually asks is in the dedicated Security+ exam topics breakdown, so this guide will not duplicate it.

What matters at the guide level is the exam's character: it is scenario-driven. Most questions wrap a workplace situation around the knowledge being tested and ask what a security professional should do first, next or best. The performance-based questions push further, simulating small tasks. This shapes preparation more than any content list does — reading alone prepares you for perhaps half the exam's style, which is why the preparation route below leans on doing.

Who should take Security+ — and who should wait

Security+ earns its keep for some readers and wastes months for others. A quick decision framework:

Take it now if:

  • You work in IT support, systems administration or networking and want to move toward security. This is the certification's centre of gravity — a helpdesk analyst with two years of tickets behind them, comfortable with networking basics and itching to move to a SOC role, is almost the model candidate.
  • You are targeting roles connected to US federal government or defence contracting, where DoD 8140-related requirements make a qualifying certification close to mandatory.
  • You already do security tasks without the title — managing access, hardening servers, handling phishing reports — and need a credential that makes the experience legible to employers.

Wait, or choose differently, if:

  • You are brand new to IT with no networking foundation. The exam assumes you understand how networks operate; going in without that means learning two subjects at once. Building the foundation first — and whether that means Network+ or jumping straight in — is exactly the question settled in Security+ vs Network+, and if you are even earlier in your journey, the overview of which CompTIA certification to start with sorts the whole portfolio by background.
  • You already work as a security analyst with several years' experience. Security+ may be beneath your level; the analyst-tier CySA+ is likely the better target, and the ordering question is covered in the Security+ vs CySA+ comparison.
  • You want a product-specific operations role in one ecosystem, where a vendor credential such as Microsoft's SC-200 may speak more directly to the job description than a neutral baseline.

How to prepare: a five-step route

There is no official CompTIA figure for study hours, and any source that promises one is inventing it — your timeline depends on how much of the recommended experience you actually have. What can be prescribed is sequence:

  1. Download the SY0-701 objectives and read them twice. The free PDF on comptia.org is the contract for the exam. Mark every objective you could not explain to a colleague; that marked-up document is your personal syllabus, and it prevents the classic error of studying what your chosen book emphasises rather than what CompTIA tests.
  2. Work through one primary study resource, aligned to SY0-701. One current, version-correct course or book covered thoroughly beats three covered partially. Check the version: materials for the retired SY0-601 still circulate and the syllabus changed.
  3. Add hands-on practice for everything operational. Scenario and performance-based questions reward candidates who have actually looked at logs, configured a firewall rule in a lab, or walked through an incident-response exercise. Free tools and home labs are enough; the point is converting read knowledge into applied knowledge.
  4. Test yourself early and let the results steer. An initial diagnostic set of questions shows where you genuinely stand across the five domains — the free Security+ SY0-701 sample questions are a no-cost place to start, and the full method for turning practice scores into decisions is laid out in the Security+ practice test strategy guide.
  5. Finish with timed, full-length simulation. In the last stretch, sit complete 90-minute practice exams under honest conditions to train pacing and stamina, then book when your results are consistently comfortable on questions you have never seen before.

If you want this sequence expanded into an actual calendar with weekly milestones, the week-by-week Security+ study plan does precisely that. And if what you really want to know is how hard the exam feels and why people fail it, that has its own dedicated answer in how hard is the Security+ exam — the short version is that it is passable with honest preparation and punishing without it.

Booking, exam day and retakes

Security+ is delivered through Pearson VUE. You have two options: a test centre appointment, or OnVUE online proctoring, which lets you sit the exam from home under webcam supervision with a locked-down machine and a clear desk. Both deliver the identical exam; choose the environment where you concentrate better, and if you choose home, run the system test well before exam day.

If the attempt goes wrong, CompTIA's retake policy is more forgiving than most: there is no waiting period between a first and second attempt, a 14-calendar-day wait applies from the third attempt onwards, and each attempt requires a full-price voucher unless you purchased a retake bundle up front. Budget-conscious candidates should also know that vouchers from CompTIA's authorised resellers are legitimate and routinely cheaper than retail — "authorised" is the word that matters.

After the pass: keeping Security+ current

Security+ is valid for three years from your pass date. Renewal runs through CompTIA's Continuing Education (CE) programme, and you have four routes: upload 50 continuing education units (CEUs) earned through training, work activities and community contributions; complete CompTIA's CertMaster CE course for Security+; pass the current version of the exam again; or earn a higher-level CompTIA certification, which renews Security+ automatically.

That last route is the one career-minded holders should notice, because CompTIA's renewal model is stackable: renewing a higher certification renews the ones beneath it, and you pay CE fees only for your highest cert. If you expect to pursue CySA+ or another advanced credential within three years anyway, your Security+ renewal effectively takes care of itself. If you renew via CEU upload instead, CompTIA's fee schedule as of August 2026 places Security+ in the $150-per-three-year-cycle tier, paid by the expiration date. Where the certification leads over those three years and beyond — typical next roles and the credential ladder above it — is mapped in the Security+ career path guide.

Frequently asked questions

Should I wait for the next version of the exam instead of taking SY0-701?

No — as of August 2026, SY0-701 is the only live version and CompTIA has not officially announced a successor or launch date. Your certification is valid for three years from whenever you pass, regardless of exam version, so waiting mostly means arriving later with the same credential.

Do I need to pass A+ or Network+ first?

No. CompTIA enforces no prerequisites on Security+; A+ and Network+ are recommendations. The practical question is whether you have the networking knowledge the exam assumes — if you do, from work or self-study, skipping the earlier certifications is common and legitimate.

Can I take the exam from home?

Yes. Pearson VUE's OnVUE service delivers Security+ online with remote proctoring. You need a webcam, a stable connection, a private room and a cleared desk, and you must complete identity and workspace checks before the exam starts.

What does the 750 passing score actually mean?

Scores are scaled between 100 and 900 based on question difficulty, so 750 is not 83 per cent and CompTIA does not publish a simple correct-answers conversion. Aim to be comfortably strong across all five domains rather than reverse-engineering a minimum.

Where Security+ fits in your plan

Security+ works best understood as a gateway rather than a destination: one exam, three years of currency, and a recognised baseline that moves you from "interested in security" to "employable in security" in the eyes of many hiring processes. If the profile in this guide matches you — some IT grounding, security ambitions, need for a credential that travels across employers and sectors — the route is clear: download the SY0-701 objectives, build the five-step preparation above, benchmark honestly with practice questions, and book through Pearson VUE when the numbers say ready.

The wider CompTIA security track continues past it — CySA+ for analysts, PenTest+ for offensive roles, SecurityX at the advanced end — and every exam page in the CompTIA exams hub shows what each next step looks like when you get there. For now, one well-prepared pass is the whole job.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like