Exampractice
IT & Networking

Security+ Study Schedule for Beginners

A realistic week-by-week Security+ study schedule for people with little IT background, from networking groundwork to a final review week before SY0-701.

Liam Anderson · 7 min read
Ten-week calendar with colour-coded study blocks leading to a circled Security+ exam date

Picture a retail supervisor who has decided to move into IT security. She has no networking background, evenings and weekends to study, and one question: how do I organise the next couple of months so I actually sit the CompTIA Security+ exam instead of endlessly "preparing" for it? This article is the timetable she needs — a ten-week schedule (an eight-week core plan plus two optional foundation weeks) built for people starting with little or no IT experience.

One honesty note before the calendar. CompTIA publishes no official study-hours figure for Security+ (SY0-701), and anyone quoting an exact number is guessing. What CompTIA does say is that the exam has no enforced prerequisites but is recommended for people with CompTIA Network+ and around two years in a security or systems administrator role. If that is not you, you are not disqualified — you simply need a schedule that builds the missing groundwork first, which is exactly what the plan below does.

Before week 1: three setup tasks

  1. Download the official SY0-701 exam objectives free from comptia.org. Every week below is anchored to its five domains: General Security Concepts; Threats, Vulnerabilities and Mitigations; Security Architecture; Security Operations; and Security Program Management and Oversight. For a plain-English walkthrough of what each domain means, read our Security+ exam objectives breakdown first.
  2. Choose one primary study resource (a book or video course written for SY0-701) and stick with it. Beginners lose more time switching resources than they lose to any single imperfect one.
  3. Fix your weekly study budget in your diary. The plan assumes roughly five to eight hours a week — for example, three weekday evening sessions of about an hour plus a longer weekend block. If you can only manage less, stretch the plan rather than skipping weeks; consistency beats intensity.

If you are still deciding whether Security+ is even the right first exam for you, that question has its own guide — see which CompTIA certification to start with — and this schedule will still be here when you have decided.

Weeks 1–2 (optional): IT and networking foundations

Skip these two weeks only if you can already explain what an IP address, a port, a server and a firewall are without looking anything up. Security+ constantly assumes this vocabulary, and beginners who skip straight to domain study end up relearning it mid-plan at double the cost.

  • Week 1 — how computers and networks talk. IP addressing at a conceptual level, common protocols and ports, what switches, routers and firewalls do, and the difference between a client, a server and a cloud service.
  • Week 2 — the security lens. Confidentiality, integrity and availability; what authentication and authorisation mean; what an attack surface is. End the week by re-skimming the objectives document — noticeably more of it should now make sense.

You do not need the full CompTIA Network+ certification before Security+ — CompTIA's recommendation is guidance, not a rule — but if these two weeks feel genuinely enjoyable rather than remedial, the Network+ certification guide is worth a look for later.

Weeks 3–7: one domain per week

The heart of the plan: five domains, five weeks, in an order chosen so each week feeds the next. Work through your primary resource's chapters for that domain, then close every week the same way — write a one-page summary from memory, and answer a set of practice questions restricted to that domain, logging your score.

  • Week 3 — General Security Concepts. Control types and categories, core principles, cryptography basics, zero trust vocabulary. This is the exam's shared language; over-invest here and every later week gets cheaper.
  • Week 4 — Threats, Vulnerabilities and Mitigations. Threat actors, attack types and their tell-tale indicators. Beginner tactic: build a two-column table as you go — attack on the left, its standard mitigation on the right. It becomes your single best revision asset.
  • Week 5 — Security Architecture. Cloud versus on-premises, segmentation, data protection, resilience. This is the hardest week for career-changers because it assumes infrastructure intuition; slow down, draw diagrams, and accept that two passes through the material is normal.
  • Week 6 — Security Operations. Hardening, identity and access management, monitoring, incident response. Learn the incident response stages as a story you can retell, not a list you recite — "what happens next?" questions are a Security+ staple.
  • Week 7 — Security Program Management and Oversight. Governance, risk management, third-party risk, compliance and awareness. It reads like paperwork; treat it as free marks, because its questions reward precise definitions more than deep technical skill.

Weightings for each domain are printed in the official objectives document — check them there, and if a heavily weighted domain produced your worst end-of-week score, earmark it now for extra attention in week 9.

Week 8: connect the domains

Real exam questions rarely stay inside one domain, so week 8 is integration week:

  1. Reread your five one-page summaries in a single sitting.
  2. Revisit your two hardest topics from your week-end logs and go one level deeper on each.
  3. Do mixed-domain question sets for the first time — no domain filter — and note which domains your wrong answers cluster in.
  4. Book your exam if you have not already. A date roughly two weeks out converts vague intention into a deadline, and CompTIA exams can be scheduled through Pearson VUE at a test centre or online. As of June 2026, US retail pricing listed by CompTIA's authorized resellers is $439, with authorized voucher resellers somewhat cheaper — prices vary by country, so confirm on comptia.org.

Week 9: full-length practice and repair

This week revolves around timed, full-length practice: 90 questions in 90 minutes, simulating the real exam's mix of multiple-choice and performance-based questions. ExamPractice's SY0-701 Security+ practice questions include free samples, with fuller question sets and a timed simulation mode for subscribers. Take one full test early in the week, spend two or three sessions repairing the weakest domains it exposes, then take a second full test at the weekend to confirm the repair worked.

Two rules for this week. First, review every wrong answer until you can explain why the right option is right — moving your score by understanding, not by memorising questions. Second, do not spiral into infinite testing; two full-length tests with genuine review beat five taken back to back. The deeper method — how to score, review and act on practice tests, including PBQ practice — is covered in our dedicated Security+ practice test strategy guide.

Week 10: taper and sit the exam

Ease off. Light revision of your summary pages and your attack-versus-mitigation table, a final pass over acronyms, and plenty of sleep beat any last-minute cramming. Sort your logistics early in the week — ID, check-in steps, and the differences between test-centre and online proctoring are all in the Security+ exam day checklist. Then sit the exam. You need 750 on a scaled range of 100–900 to pass; a scaled score is not a percentage, so do not try to convert it into "questions I can afford to miss".

If the result goes the wrong way, it is a setback, not a verdict — CompTIA allows an immediate second attempt with no waiting period, and the Security+ retake strategy guide covers turning a score report into a focused second run.

Adjusting the schedule to your life

  • Faster (six to eight weeks total): you work in IT already, or the foundation weeks bored you. Skip weeks 1–2 and compress weeks 3 and 7 into one week each if their end-of-week scores are strong.
  • Slower (twelve to sixteen weeks): your weekly hours are limited or week 5 hit hard. Give Security Architecture and Security Operations two weeks each, and keep everything else in sequence. A longer plan you finish beats a shorter plan you abandon.
  • Restarting after a stall: do not start over from week 1. Re-run the previous week's question set to find your real current level, and resume from there.

Common beginner scheduling mistakes

  • All input, no output. Watching videos for six weeks and answering questions only at the end. The weekly question sets in this plan are not optional extras; they are the mechanism that makes reading stick.
  • Perfecting week 3 forever. Cryptography rabbit holes claim many beginners. Reach "can explain and distinguish", then move — week 8 and week 9 exist to deepen weak spots.
  • No booked exam date. Open-ended plans drift. Booking in week 8 gives the final fortnight real stakes.
  • Ignoring the objectives document. Your course is an interpretation of the objectives, not a replacement for them. Tick objectives off as you go so gaps are visible before week 9, not during the exam.

Your first study session starts tonight

A schedule only works once a session happens, so make the first one trivially small: tonight, download the SY0-701 objectives, read the Domain 1 section, and put your week-by-week plan into your calendar. In ten weeks — or eight, or sixteen, depending on the version you chose — the retail supervisor from the opening paragraph walks out of a Pearson VUE test centre with a pass. There is no reason that cannot be you.

Exam facts in this guide were checked against official certification-provider pages on . Fees, exam codes and policies change — confirm on the provider’s own site before you book.

Put it into practice

Test what you have just read

Reading about an exam only takes you so far. Work through practice questions for your certification and find the gaps before exam day does.

You may also like