CompTIA Security+ Exam Objectives (SY0-701): The Full Domain Breakdown
The complete SY0-701 exam objectives, broken down by domain and weight. See exactly what each of the five Security+ domains covers and how to budget your study time.
If you are studying for CompTIA Security+ and only have the exam code, start here. The SY0-701 exam is built from a published list of objectives, grouped into five domains, and each domain carries a fixed percentage of the exam. That weighting is the single most useful thing you can know before you open a single study video, because it tells you where your hours actually belong. Get it wrong and you will over-study the domain that opens every course and run out of time before the two that carry the most marks.
This is the full SY0-701 objectives breakdown: every domain, its exact weight, what it actually tests, and how to turn all of it into a study plan instead of a wall of bullet points. It is written to the current version, SY0-701, not the retired SY0-601 blueprint that a surprising number of pages still list as if it were live.
Quick takeaways
- SY0-701 is the current Security+ exam. Any page still listing "Attacks, Threats, and Vulnerabilities" as domain 1 is describing the retired SY0-601 version. Do not study from it.
- There are five domains, and they are weighted: Security Operations alone is 28 percent of the exam, and the top two domains together are half of it.
- The exam is a maximum of 90 questions in 90 minutes, a mix of multiple-choice and performance-based questions (PBQs), passing at 750 on a 100-to-900 scale, per CompTIA.
- Read the domain weights as a study-hour budget, not a table of contents. Spend your time in proportion to the marks.
- PrepClubs' Security+ track maps every practice question to the exact SY0-701 objective it tests, so a wrong answer points you straight back to the domain and objective to review.
- PrepClubs is independent prep material and is not affiliated with or endorsed by CompTIA.
What the SY0-701 objectives are (and where "V7" fits in)
CompTIA publishes a document called the exam objectives (sometimes labeled the exam blueprint) for every version of Security+. It lists every domain, every objective inside that domain, and the acronyms and technologies you are expected to recognize. For the current exam, that document is the SY0-701 objectives.
You may see CompTIA refer to this as "Security+ V7." That is marketing versioning for the same exam. V7 and SY0-701 are the same thing. There is no separate "V7 code" to hunt for, and nothing extra to study because of the label. When a source names SY0-701, it is describing the exam you will sit.
Here is the format at a glance, per CompTIA's own exam page:
| Attribute | SY0-701 |
|---|---|
| Number of questions | Maximum of 90 |
| Time limit | 90 minutes |
| Question types | Multiple-choice and performance-based (PBQs) |
| Passing score | 750 (on a scale of 100 to 900) |
| Recommended experience | Network+ and about 2 years in a security or systems administration role |
| Number of domains | 5 |
The five SY0-701 domains and their exact weights
This is the table the whole exam hangs on. CompTIA assigns each domain a percentage of the total exam, and those percentages do not change between candidates.
| SY0-701 domain | Exam weight |
|---|---|
| 1.0 General Security Concepts | 12% |
| 2.0 Threats, Vulnerabilities, and Mitigations | 22% |
| 3.0 Security Architecture | 18% |
| 4.0 Security Operations | 28% |
| 5.0 Security Program Management and Oversight | 20% |
Two things jump out. Domain 4.0, Security Operations, is the largest at 28 percent, which is more than double the smallest. And the two biggest domains, Security Operations and Threats, Vulnerabilities, and Mitigations, add up to 50 percent of the exam between them. If you learn nothing else before you plan your studying, learn that.

Domain by domain: what each one actually tests
The domain names are broad. Here is what sits under each one, so you know what you are actually being asked.
1.0 General Security Concepts (12%)
The foundations. Security controls (technical, managerial, operational, physical), the CIA triad, authentication and authorization concepts, zero trust, physical security, and the basics of cryptography (encryption, hashing, digital certificates, PKI). This domain is smaller than people expect given how much every course front-loads it. It is 12 percent, not 30.
2.0 Threats, Vulnerabilities, and Mitigations (22%)
The attack side. Threat actors and their motivations, attack surfaces and vectors (phishing, malware, social engineering), the specific vulnerabilities of applications, hardware, and cloud, indicators of malicious activity, and the mitigation techniques that counter them. This is the second-heaviest domain and the one most people find genuinely interesting.
3.0 Security Architecture (18%)
Designing secure systems. Architecture models (cloud, on-premises, hybrid, IoT, ICS/SCADA), the security implications of each, secure data protection (classification, encryption at rest and in transit, DLP), and resilience and recovery (backups, high availability). If you think in systems, this domain rewards you.
4.0 Security Operations (28%)
The biggest domain, and the day-job of a security analyst. Applying security to hosts, mobile, and cloud, hardening, vulnerability management, security monitoring and alerting (SIEM, log data), identity and access management in practice, automation, incident response, and digital forensics basics. More than a quarter of your exam lives here. Treat it accordingly.
5.0 Security Program Management and Oversight (20%)
The governance layer. Security governance, risk management (assessment, analysis, and the risk register), third-party and vendor risk, compliance, audits and assessments, and security awareness practices. This domain is where technical candidates lose easy marks because it is less hands-on and more about policy, process, and business judgment.
How to turn the weights into a study plan
The objectives list is not a study plan on its own. It becomes one the moment you overlay the weights on your available hours. Here is a simple way to do it.
Say you have 20 hours of focused study left. Split them in proportion to the domain weights:
| Domain | Weight | Study hours (of 20) |
|---|---|---|
| 4.0 Security Operations | 28% | About 5.5 |
| 2.0 Threats, Vulnerabilities, Mitigations | 22% | About 4.5 |
| 5.0 Security Program Management | 20% | About 4 |
| 3.0 Security Architecture | 18% | About 3.5 |
| 1.0 General Security Concepts | 12% | About 2.5 |
Most people do the exact opposite of this table. They pour early enthusiasm into domain 1.0 because it comes first in every course, then hit test day underprepared on the two heaviest domains at the back. Working the weights on purpose is the cheapest edge you can give yourself.
Then, within each domain, let practice questions tell you which specific objectives are weak. When you miss a question, do not just note the right answer. Map it to the exact objective it came from, learn the surrounding concept, and re-test with a fresh question later. A bank that labels every question by its SY0-701 objective turns that loop from guesswork into a checklist.
SY0-601 versus SY0-701: what changed
If you find an older guide, it may describe the retired SY0-601 exam, which had different domain names. This matters because the blueprints are genuinely different, and studying the old one wastes time.
| SY0-601 (retired) domains | SY0-701 (current) domains |
|---|---|
| Attacks, Threats, and Vulnerabilities | General Security Concepts |
| Architecture and Design | Threats, Vulnerabilities, and Mitigations |
| Implementation | Security Architecture |
| Operations and Incident Response | Security Operations |
| Governance, Risk, and Compliance | Security Program Management and Oversight |
The SY0-701 refresh consolidated and re-sequenced the material, added more on modern topics like zero trust and automation, and rebalanced the weights. The practical rule: if a resource lists "Attacks, Threats, and Vulnerabilities" as domain 1, it is the old exam. Close it and find current material.
FAQ
How many domains are on the Security+ SY0-701 exam?
Five: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management and Oversight (20%), per CompTIA.
Which Security+ domain is the most important?
By exam weight, Security Operations at 28 percent, followed by Threats, Vulnerabilities, and Mitigations at 22 percent. Those two are half the exam, so they deserve the most study time.
Are the SY0-601 objectives still valid?
No. SY0-601 is the retired version with different domain names and weightings. Study only the SY0-701 objectives. If a page lists "Attacks, Threats, and Vulnerabilities" as a domain, it is describing the old exam.
Where can I get the official Security+ objectives?
CompTIA publishes the SY0-701 exam objectives document on its own certification site. It is the authoritative source for domain weights and the full objective list, and it is worth downloading before you start.
Do I need to memorize every objective?
You need to recognize and apply the concepts behind them, not recite the list. The exam is scenario-based, so understanding why a control fits a situation matters more than memorizing that it exists. Practice questions tied to each objective are the fastest way to find the gaps.
How is the exam scored against these domains?
CompTIA does not publish a per-domain or per-question point breakdown, and the 750 passing mark is a scaled score, not a raw percentage. The domain weights tell you where the questions cluster, which is why you weight your studying to match.
Related on PrepClubs
- Security+ practice test (SY0-701): how to use a full-length bank as a diagnostic against these domains.
- How many questions are on the Security+ exam: the format and scoring in full.
- Security+ performance-based questions: what PBQs are and how to practice them.
- How to study for Security+ in 30 days: an objective-weighted plan built on this exact table.
Study the objectives that actually carry the marks
Knowing the five SY0-701 domains is step one. Studying them in proportion to their weight, and drilling the specific objectives you keep missing, is what gets you to 750. That is how PrepClubs' Security+ track is built: every practice question is mapped to the exact SY0-701 objective it tests, so a wrong answer sends you straight to the domain and concept to review, not back to a generic video. You start with a free 25-question diagnostic to see which domains are weak, then unlock 10 full-length practice tests (900 original SY0-701 questions), each with a written rationale, for a one-time $69. It is a one-time payment with 30 days of access, not a subscription. If you prepare with PrepClubs and do not pass your real test, we extend your access at no extra cost. No fine print, no satisfaction-guarantee hedge. You get more time with the material, free. PrepClubs has helped more than 1,600 students prepare for cognitive and certification assessments. Start with the free Security+ diagnostic.
FAQ


