Exampractice
IT & Networking

CompTIA Security+ Exam Topics Explained

Every SY0-701 domain explained — what each CompTIA Security+ exam topic actually tests, typical question themes, and how to map them to your revision.

Liam Anderson · 10 min read
Diagram showing the five CompTIA Security+ SY0-701 exam domains as layers of one secured building

Ask most candidates what Security+ covers and they will say "a bit of everything in security" — which is true, and useless for planning revision. In reality, every question on SY0-701 belongs to one of exactly five domains: General Security Concepts; Threats, Vulnerabilities and Mitigations; Security Architecture; Security Operations; and Security Program Management and Oversight. Encryption fundamentals, incident response, compliance frameworks — each has a fixed home in that structure, and knowing which home is which changes how you study. Below, each domain gets the same treatment: what it genuinely asks of you, the question themes candidates report most often, and how much weight it deserves in your timetable.

A quick versioning note before anything else, because studying the wrong syllabus is the most expensive mistake available. SY0-701 went live in November 2023 and, as of August 2026, is the only Security+ exam you can book; CompTIA has signalled that a successor is expected but has announced no replacement, so the five domains below are the ones you will face. CompTIA, the vendor behind the certification, gives the full exam objectives away as a free download on comptia.org — that document is the definitive syllabus, and this article is your guided tour of it.

The five SY0-701 domains at a glance

Before the detail, here is the shape of the exam. Each domain is a themed slice of the objectives; CompTIA publishes an exact percentage weighting for every domain in the official objectives document, so download that PDF from comptia.org and note the current figures before you build a revision timetable.

DomainWhat it is really about
1. General Security ConceptsThe vocabulary and building blocks everything else depends on
2. Threats, Vulnerabilities and MitigationsWho attacks, how they get in, and what stops them
3. Security ArchitectureDesigning systems and networks so they are defensible
4. Security OperationsRunning security day to day — monitoring, hardening, responding
5. Security Program Management and OversightGovernance, risk, compliance and the business side of security

A useful mental model: domains 1 and 2 give you the language and the adversary, domains 3 and 4 are the technical job, and domain 5 is the organisational wrapper. Questions rarely announce which domain they come from, and plenty blend two — a question about a compromised server can test threat identification, operational response and reporting obligations in one scenario.

Domain 1: General Security Concepts

This domain is the foundation course. Expect it to test whether you can define and correctly apply the core ideas of the profession: the confidentiality, integrity and availability triad; authentication, authorisation and accounting; control categories (technical, managerial, operational, physical) and control types (preventive, detective, corrective, deterrent, compensating); zero trust thinking; and the essentials of cryptography — symmetric versus asymmetric encryption, hashing, digital signatures, certificates and public key infrastructure.

Typical question themes here are definitional but rarely trivial. Rather than "define hashing", you are more likely to see a short scenario — a company wants to prove a file has not been altered in transit — and be asked which concept or control fits. The trap is that several answer options will be real security controls; only one matches the precise goal in the stem.

Why it matters for your revision: weakness in Domain 1 leaks into every other domain. If you are shaky on the difference between a preventive and a compensating control, you will misread questions in architecture and operations too. Nail this domain early — it is the cheapest accuracy gain on the whole exam.

Themes candidates underestimate

Change management and its security implications sit in this domain, and they surprise people who expected pure technology. So does physical security. Questions about bollards, access badges and sensor types feel out of place to candidates who revised only network topics, but they are squarely on the syllabus.

Domain 2: Threats, Vulnerabilities and Mitigations

Domain 2 is the adversary's-eye view. It covers threat actors and their motivations (nation states, organised crime, insiders, hacktivists), attack surfaces and vectors, social engineering, malware families, application and network attacks, and the mitigation techniques that blunt each one.

The characteristic question style is classification under ambiguity. A scenario describes suspicious behaviour — an email that urges a wire transfer, a process quietly encrypting files, traffic beaconing to an unknown host — and you must name the attack, the actor type most likely behind it, or the single best mitigation. Distractors are engineered to be adjacent: phishing versus whaling versus business email compromise, or virus versus worm versus trojan. The difference between options is usually one detail in the stem, so slow reading pays.

Vulnerability topics also live here: misconfigurations, unpatched software, zero-days, supply-chain weaknesses and the lifecycle from discovery to remediation. Expect indicator-style questions too — given a set of symptoms, identify the likely compromise.

For revision, build comparison notes rather than flat lists. A table of social-engineering techniques with the one distinguishing feature of each will earn more marks than re-reading definitions ten times, because the exam tests discrimination between neighbours, not recall in isolation.

Domain 3: Security Architecture

Architecture questions ask a different kind of question: not "what is this?" but "how would you build this securely?" The domain spans secure network design (segmentation, zones, firewall and proxy placement, VPNs), cloud and virtualisation models and their security trade-offs, infrastructure as code, embedded and IoT considerations, resilience and recovery (backups, redundancy, site strategies), and data protection — classifying data and securing it at rest, in transit and in use.

Typical question themes include placement decisions (where in a network diagram a sensor or firewall belongs), model selection (which cloud responsibility falls to you versus the provider), and resilience trade-offs (which backup or site strategy meets a stated recovery objective at the lowest cost). This is also fertile ground for performance-based questions, where you might arrange components in a network diagram rather than pick from four options.

Candidates from helpdesk backgrounds often find this the most abstract domain, because few juniors get to design networks. The fix is not more reading but more diagrams: sketch a small business network, then redraw it segmented, then add remote access, and narrate why each control sits where it does. If a network refresher would help before you go deep here, the CompTIA Network+ certification guide covers the underlying networking layer that Security+ quietly assumes.

Domain 4: Security Operations

Domain 4 is the largest slice of working security life: applying secure baselines and hardening systems; managing assets, patches and vulnerabilities; monitoring, logging and alerting; identity and access management in practice (provisioning, least privilege, multifactor authentication, single sign-on); automation; and incident response from detection through containment, eradication, recovery and lessons learned. Digital forensics basics — evidence handling, chain of custody — appear here too.

Question themes are procedural and sequential. Expect "what should the analyst do FIRST" and "what is the NEXT step" stems, where every option is a legitimate action and the mark depends on ordering. Incident response phases are a favourite: memorise the sequence, but also understand what distinguishes containment from eradication in a concrete case, because scenarios test the boundary, not the list.

Log-reading questions are common and worth deliberate practice. You may be shown firewall entries, authentication logs or alert output and asked what happened or what to do about it. If you have never stared at raw logs, spend time with samples until the format stops being noise. Free sample questions on the SY0-701 Security+ exam page include operations-style scenarios you can use to test whether you can read a situation, not just recite a process.

Because operations content is broad, it punishes shallow coverage. When candidates fail Security+, self-reports frequently point at scenario-heavy operational questions — the style of question is examined in depth in how hard the Security+ exam really is, which stays out of scope here.

Domain 5: Security Program Management and Oversight

The final domain zooms out from technology to the organisation. It covers security governance (policies, standards, procedures, guidelines), risk management (assessment, analysis, registers, appetite and tolerance), third-party and supply-chain risk, compliance and privacy obligations, audits and assessments, penetration-testing concepts from a programme perspective, and security awareness training.

The question style shifts noticeably: fewer packets, more paperwork. Typical themes include matching a document type to a purpose (is this a policy or a standard?), interpreting risk calculations conceptually, choosing the right response to a stated risk (accept, transfer, avoid, mitigate), and identifying what belongs in vendor agreements.

Technical candidates habitually deprioritise this domain and regret it. The vocabulary is precise and the distractors exploit sloppiness — risk appetite versus risk tolerance, audit versus assessment, policy versus procedure. The material is not hard; it is simply unfamiliar to people who have never sat in a governance meeting. A few focused evenings of flashcard work typically move accuracy here faster than in any technical domain. If the governance side of security appeals to you more than the technical side, the ISO/IEC 27002-based EXIN Information Security Foundation exam shows what a dedicated management-track qualification looks like.

How the topics turn into actual exam questions

Knowing the syllabus is half the picture; the delivery format shapes how the topics feel on the day. SY0-701 presents a maximum of 90 questions in 90 minutes — most candidates see fewer than 90, because CompTIA seeds unscored trial questions in varying numbers. Scoring is scaled from 100 to 900 with a pass mark of 750; that is a scaled score, not 83 per cent, so do not translate practice percentages directly.

Two question types carry the five domains:

  1. Multiple-choice questions, single and multiple response. The multiple-response items tell you how many options to pick. Across all domains, the house style is scenario-first: a short situation, then a question asking for the best, first or most likely answer.
  2. Performance-based questions (PBQs), interactive items that typically appear at the start of the exam. They ask you to do something — order steps, match attacks to mitigations, configure a simulated component — and they draw disproportionately on domains 2, 3 and 4, where doing rather than knowing can be simulated.

The tactical side — how to pace PBQs, when to flag and return, and how to drill them before the day — belongs to its own playbook, covered in the Security+ practice test strategy guide, so this article leaves it at one line: never let an early PBQ eat ten minutes you will want later.

Reading the official objectives like an examiner

The objectives PDF from comptia.org is more useful than most candidates realise, because its verbs are a difficulty map. Objectives that begin "compare and contrast" or "explain" are asking for conceptual discrimination — flashcard and comparison-table territory. Objectives that begin "given a scenario" are telling you, explicitly, that this topic will arrive wrapped in a situation and may power a PBQ — these need applied practice, not re-reading.

Work through the document once with a highlighter in two colours: one for "given a scenario" objectives, one for everything else. The scenario list becomes your hands-on practice agenda; the rest becomes your recall agenda. Also read the acronym list at the back — the exam uses acronyms freely, and losing marks because SASE or SCAP did not ring a bell is entirely avoidable.

One more examiner's habit: the bullet lists under each objective are inclusion lists, not decoration. If "24. capacity planning" appears as a sub-bullet, it can be a question. When a practice question surprises you, trace it back to its bullet — you will almost always find it sitting in plain sight.

Common mistakes when mapping the topics to revision

  • Revising domains in order and running out of steam. Candidates start at Domain 1, polish it endlessly, and reach governance topics exhausted with a week left. Sequence by weakness instead: take a diagnostic early and spend your best hours on your worst domain.
  • Treating domain names as fences. The exam blends domains inside single questions. Revise topics, check understanding across boundaries — can you follow one scenario from attack (Domain 2) through response (Domain 4) to reporting (Domain 5)?
  • Ignoring the weightings. The official objectives state each domain's percentage; two candidates with identical knowledge can score differently because one allocated time in proportion to the weightings and the other split time evenly. Check the current figures in the PDF and let them set your ratios.
  • Memorising port numbers and acronyms first. They matter, but they are the garnish. The exam's centre of gravity is judgement in scenarios; rote lists alone have never passed it.
  • Studying the wrong version. Materials for the retired SY0-601 still circulate. SY0-701 restructured the syllabus into the five domains above — verify that every resource you use names SY0-701.

Turning the domain map into a study sequence

Here is a prioritisation that suits most candidates coming from a year or two of general IT: secure Domain 1 first, because everything else compounds on it; then take a diagnostic set of questions across all five domains to find your true weak spots rather than your assumed ones; then give domains 2, 3 and 4 the bulk of your remaining technical study time — with your personal weakest of the three getting the most; and hold Domain 5 for concentrated vocabulary work in the final stretch, when flashcard-friendly material benefits from freshness. Re-test after each block and let the results, not the table of contents, dictate where you go next.

How many weeks that takes depends on your starting point, and turning this sequence into a calendar is a separate job — the week-by-week Security+ study plan exists precisely for that. And when you want the full picture beyond the syllabus — cost, booking, renewal, whether the certification suits your situation — the CompTIA Security+ certification guide is the companion piece to this topic breakdown.

Whatever order you choose, keep returning to mixed-domain question sets as you go. The exam will not sort its questions by chapter, and neither should your final preparation.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like