CompTIA A+ Certification Guide for Beginners
·10 min read
What CompTIA A+ covers, how the 220-1201 and 220-1202 exams work, and a step-by-step plan to earn the certification as a complete beginner.
Continue readingA domain-by-domain breakdown of the SY0-701 Security+ exam objectives — what each of the five domains actually tests and how to read the official list.

The CompTIA Security+ exam (SY0-701) tests five domains: General Security Concepts; Threats, Vulnerabilities and Mitigations; Security Architecture; Security Operations; and Security Program Management and Oversight. You face a maximum of 90 questions in 90 minutes, mixing multiple-choice with performance-based questions, and you need a scaled score of 750 on a 100–900 scale to pass. This article explains what each domain actually asks of you — not just what the official objectives list says, but what the wording means in practice.
CompTIA publishes the full exam objectives document as a free download on comptia.org, and it should be the first thing you read before buying any course or book. Each domain's official weighting — the percentage of the exam it contributes — is printed in that document, so download the current SY0-701 version and check the percentages there rather than relying on second-hand summaries. As of August 2026, SY0-701 (live since November 2023) is the only current version of the exam; CompTIA lists an estimated retirement "in 2026" without a fixed date, and a successor is expected but unannounced. Study against SY0-701 objectives until CompTIA says otherwise.
The objectives document is not a syllabus in the school sense. It is a hierarchical list: five domains at the top, each broken into numbered objectives, each objective followed by a long list of example topics, technologies and acronyms. Two things trip up first-time readers.
First, the verbs matter. An objective that begins "compare and contrast" is asking you to distinguish between similar things (types of controls, categories of threat actor), while "explain" objectives test understanding of why something works, and "given a scenario" objectives are the ones most likely to surface as situational questions — including performance-based questions (PBQs), where you interact with a simulated environment rather than picking A, B, C or D.
Second, the bulleted example lists under each objective are illustrative, not exhaustive contracts. CompTIA notes that its bullet lists show examples of what could appear; you are being tested on the objective, not on memorising the bullets. Treat the bullets as a vocabulary checklist and the objective sentence as the actual skill.
With that reading method in place, here is what each domain really covers.
This domain is the foundation layer — the shared vocabulary the rest of the exam assumes. It covers the categories and types of security controls (technical, managerial, operational, physical; preventive, detective, corrective and so on), core principles such as confidentiality, integrity and availability, zero trust concepts, and the building blocks of cryptography.
What actually matters here:
If you are new to security, this domain rewards being studied first, because the other four domains reuse its terminology constantly.
This is the "know your enemy" domain. It covers threat actors and their motivations, common attack vectors and surfaces, types of vulnerabilities, indicators of malicious activity, and the mitigation techniques that blunt each attack.
The practical skill being tested is recognition. Questions describe a symptom — odd outbound traffic, a user reporting a convincing invoice email, an application crashing on long input — and ask you to name the attack or pick the mitigation. To prepare well:
Architecture is where the exam asks how you would build things securely rather than how you would recognise an attack. It spans the security implications of different architecture models — cloud, on-premises, virtualisation, containers, industrial control systems and embedded devices — plus securing enterprise infrastructure, protecting data, and designing for resilience and recovery.
Candidates without infrastructure experience find this the most abstract domain, so anchor it in concrete comparisons:
If terms like subnetting or hypervisors are entirely new to you, a short detour into networking fundamentals pays off; CompTIA itself recommends Network+-level knowledge and around two years in a security or systems administrator role before Security+, although there are no enforced prerequisites. Readers starting from zero should build extra time into their plan — the Security+ study schedule for beginners shows how to sequence that.
Operations is the day-job domain: applying security to computing resources, monitoring, vulnerability management, responding to incidents and using the tooling of a working security team. In practice it covers hardening baselines, mobile and wireless security, identity and access management, automation, incident response processes and using logs and other data sources to support investigations.
Three preparation notes:
The final domain covers governance, risk and compliance: security policies and standards, risk management processes, third-party risk, compliance monitoring, audits and assessments, and security awareness practices. It is the least technical domain and the one technical candidates most often under-prepare, precisely because it feels like paperwork.
Do not make that mistake. The objective wording here leans on precise definitions — risk appetite versus risk tolerance, qualitative versus quantitative risk analysis, types of agreements with vendors — and precision is easy to test with multiple choice. Learn the risk formulas and terms exactly as the objectives phrase them, and be able to walk through a risk register entry: identify the risk, assess likelihood and impact, choose a treatment (accept, transfer, avoid, mitigate).
The objectives document describes content, but reading it alongside the exam format reveals how content becomes questions. The exam allows a maximum of 90 questions in 90 minutes — note "maximum": CompTIA seeds unscored questions, so candidates often see fewer than 90. Questions are multiple-choice (single and multiple response) plus performance-based items, and scoring is scaled from 100 to 900 with 750 to pass. A scaled score is not a percentage — you cannot translate 750 into "83% correct".
PBQs typically front-load the exam and simulate tasks: configuring a rule set, matching attacks to descriptions, ordering steps. They draw disproportionately on "given a scenario" objectives, which is why this article keeps flagging them. How to pace and practise PBQs is its own topic — the Security+ practice test strategy guide covers timing and review methods, and the Security+ exam day checklist covers handling them under real exam conditions.
Knowing the boundaries saves study time:
A practical five-step method:
Yes. SY0-701 reorganised the exam into the five domains described above; SY0-601 retired on 31 July 2024. Study materials written for SY0-601 will cover much overlapping ground but will not match the current domain structure, so check that anything you buy states SY0-701 on the cover.
You should be able to expand and place every acronym, because answer options frequently use them unexpanded. The objectives document includes an acronym list at the back — turn it into flashcards early so decoding acronyms never costs you exam time.
No. As of August 2026 CompTIA lists SY0-701 as the current exam with no officially announced successor or fixed retirement date. Certification remains valid for three years from your pass date regardless of which exam version you sat, so passing the live version now loses you nothing.
US retail is $439 as listed by CompTIA's authorized resellers in June 2026, with lower prices (roughly $365–394) through authorized voucher resellers; fees vary by country, so confirm current pricing on comptia.org before booking.
The objectives document tells you what to learn; it deliberately says nothing about how or in what order. Once you have mapped the five domains against your own starting knowledge, your next moves are sequencing that material into weeks — covered in the beginner-friendly Security+ study schedule — and validating progress with domain-scored practice, covered in the practice test strategy guide. For the wider context of format, cost and whether Security+ suits your career stage, the full CompTIA Security+ certification guide is the place to start. Read the objectives first, though — twenty minutes with the official document will make every other resource you touch easier to judge.
Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.
Put it into practice
Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.
·10 min read
What CompTIA A+ covers, how the 220-1201 and 220-1202 exams work, and a step-by-step plan to earn the certification as a complete beginner.
Continue reading·10 min read
What CompTIA Network+ covers, how the N10-009 exam works, who should take it and a practical preparation plan — everything in one guide.
Continue reading·9 min read
What CompTIA Security+ is, the SY0-701 exam format and cost, who the certification suits, and a practical five-step route to earning and keeping it.
Continue reading