Home › Study Guides › SY0-701 Exam Objectives: Full Domain Breakdown
What the current Security+ exam actually tests, domain by domain, and how the weighting should shape your study time.
SY0-701 is the exam code for the current version of CompTIA Security+. If you are comparing study materials you will see this code everywhere, on practice tests, textbooks and video courses, because CompTIA revises the exam periodically and materials written for an older version such as SY0-601 do not map cleanly onto the current one.
One framing point before the objectives themselves. Exam codes are a snapshot, not a permanent label. CompTIA has retired and replaced the Security+ code several times over the certification's history, typically every few years, as the threats and the required skills change. The domain structure and skill categories tend to evolve gradually between versions, so most of what follows stays useful even after the next version replaces SY0-701. If you are reading this after a new code has been announced, confirm the current version on CompTIA's Security+ certification page before you buy study materials or schedule your exam. The underlying study approach barely changes.
SY0-701 organises its content into five domains, each carrying a different weight in the overall exam. CompTIA publishes the official weighting breakdown on its certification page, and it is worth checking that page directly rather than relying on secondhand percentages, since weighting can shift slightly between exam updates. The five below are listed roughly in the order CompTIA presents them, though nothing about the exam requires you to study them in that order.
General Security Concepts covers the vocabulary and principles that everything else builds on: control types, meaning technical, managerial, operational and physical; the CIA triad of confidentiality, integrity and availability; authentication and authorisation concepts; zero trust principles; and cryptographic basics. If you are weak here, every other domain gets harder, because this is the shared language the rest of the exam assumes you know.
Threats, Vulnerabilities and Mitigations is the domain most people associate with hacking content: threat actor types such as nation-state, hacktivist, insider threat and organised crime, plus attack vectors, malware categories, social engineering techniques and vulnerability types. It also covers mitigation techniques, meaning the what-do-you-do-about-it half rather than just identification. This domain carries heavy memorisation requirements, since there are dozens of named attack types and threat actor categories to keep straight.
Security Architecture covers how to design environments securely: network segmentation, cloud security models and the considerations specific to infrastructure, platform and software as a service, zero trust architecture, on-premises against cloud against hybrid infrastructure decisions, and secure system design principles like defence in depth. It is more conceptual and scenario-driven than pure recall.
Security Operations is typically the highest-weighted domain on the exam, and it covers the day-to-day work of a security practitioner: hardening techniques, security monitoring and alerting, incident response procedures, digital forensics basics, vulnerability management, and identity and access management operations. Because it carries the most weight, it deserves proportionally more of your study time than a simple divide-by-five approach would give it. It is also where the most performance-based questions cluster, since what you actually do when something happens is easier to test through a scenario than through a multiple-choice definition.
Security Program Management and Oversight covers governance: risk management frameworks, compliance and regulatory considerations, third-party and vendor risk, security awareness training, and the various agreement types that show up in vendor and partnership contexts. It is less technical and more about process and organisational structure, which trips up candidates who are strong technically but have not spent time in a governance-adjacent role. If you have never had to negotiate a vendor contract or sit through a compliance audit, expect this domain to feel unfamiliar in a way the more hands-on domains do not. Memorising the agreement-type distinctions specifically, meaning what a non-disclosure agreement covers as against a memorandum of understanding, tends to be the highest-leverage use of study time here.
Across all five domains, SY0-701 mixes traditional multiple-choice questions with performance-based questions that can draw from anywhere in the syllabus. One might ask you to match attack types to appropriate mitigations, configure a firewall rule set, or sequence the steps of an incident response process correctly. These test application rather than recall, which means reading about a concept is not enough; you need to have worked through scenario-style practice before exam day.
On structuring your study, do not take the domains in isolation and hope they connect on exam day. A lot of the content deliberately overlaps, since a given attack type shows up under Threats, Vulnerabilities and Mitigations but also informs decisions in Security Architecture and Security Operations. A week-by-week plan that revisits earlier domains while introducing new ones tends to outperform a strictly linear read-through. And given how much of this exam is dense, specific terminology, covering attack names, control categories, port numbers and protocol acronyms, flashcard-based review is a natural fit. Rather than rereading definitions passively, active recall forces you to retrieve the term from memory, which is a much stronger predictor of exam-day performance. CoStudy's SY0-701 decks follow this exact five-domain structure, and the first ten questions of every deck are free with no signup, which is enough to see how the objectives translate into actual recall practice before you commit to a full study plan.
A few questions come up repeatedly. SY0-701 replaced SY0-601 as the current version, and CompTIA typically runs a transition window where both are available before the older one retires, so check its official announcements for exact retirement dates if you are deciding which version to study for mid-transition. Your certification does not expire when a new code is released: once you pass any version of Security+ it stands on its own, and renewal requirements through continuing education units or retesting are separate from version transitions. The five domains are not equally weighted, and Security Operations typically carries the largest share. Difficulty comparisons across versions are subjective, but SY0-701 shifted more content toward operational and governance topics than earlier versions did, so candidates coming from a purely technical background sometimes find the governance domain less familiar territory. CompTIA publishes an official exam objectives document for each version from its certification page, and you should download it directly rather than relying solely on secondhand summaries, since it is the authoritative source for exactly what is testable and also where you will find the current code if you are reading this after SY0-701 has been replaced. Finally, Security+ uses a scaled score rather than a raw percentage, with the passing threshold and the format details published by CompTIA, which means how many questions can I miss is not a fixed number, because a mix of easier and harder questions shifts the maths on any given attempt.
Read this in the CoStudy app →