CompTIA Security+ (SY0-701): What the Exam Actually Covers, Costs, and Requires
Official details for CompTIA Security+ Practice Test (SY0-701) – Official Certification Exam Information Guide as published by the certification body.
What This Exam Actually Certifies
Security+ checks whether you can do the day-to-day work of a junior security practitioner: spot a threat, harden a system, respond to an incident, and explain why you did what you did in terms a compliance officer would accept. It doesn't certify deep specialization in any one area. That's by design. CompTIA built SY0-701 as a broad floor, not a ceiling, covering everything from cryptographic basics to third party risk management well enough that you can function on a security team without needing hand holding on the fundamentals.
The current version, SY0-701, replaced SY0-601 in November 2023 and leaned harder into cloud security, zero trust architecture, and IoT than its predecessor did. If you're studying from material written before late 2023, you're looking at the wrong blueprint.
Who This Exam Is For
If you already hold Network+ and have spent a year or two doing IT support, systems administration, or help desk work with some security responsibility mixed in, Security+ is the natural next step. It's also the exam most US federal contracting roles point to when they need a baseline cybersecurity credential under DoD 8140.
It's a weaker fit if you're brand new to IT with no networking or systems background at all. You can technically sit the exam with zero experience since CompTIA doesn't enforce prerequisites, but the material assumes you already know what a subnet is and what a Windows Group Policy object does. Candidates who skip Network+ and jump straight to Security+ tend to spend extra weeks backfilling networking concepts they didn't realize they needed.
Exam Format and What Test Day Feels Like
You get 90 minutes for up to 90 questions, a pace that gives you roughly a minute per item with no built in cushion. The exam is a fixed, linear form, meaning the questions don't adapt to how you're doing, and you can move backward and forward through the whole thing freely.
A handful of those 90 questions are performance based questions (PBQs), interactive simulations where you configure a firewall rule, match an attack to its category, or drag network components into a secure topology. These typically appear early in the exam and tend to eat more time than a single multiple choice item, since there's no partial credit shortcut. A common strategy candidates use is flagging every PBQ, clearing the multiple choice questions first, then returning to the simulations with whatever time is left. Whether that works for you depends on how you handle pressure, but it's worth deciding your approach before you sit down, not during the exam.
The Five Domains and Their Weight
CompTIA's own exam outline breaks Security+ into five domains, and the weighting tells you where to spend your study hours.
Domain | Weight |
|---|---|
General Security Concepts | 12% |
Threats, Vulnerabilities, and Mitigations | 22% |
Security Architecture | 18% |
Security Operations | 28% |
Security Program Management and Oversight | 20% |
Security Operations carries the most weight by a clear margin. That domain covers vulnerability management, identity and access management, incident response, and the alerting tools you'd actually use in a SOC, so it rewards candidates who've touched real security tooling, not just flashcards. Threats, Vulnerabilities, and Mitigations comes next, covering the threat actor types, attack vectors, and malware categories that show up constantly in scenario questions.
What This Actually Costs
The CompTIA Security+ exam voucher lists at $425 USD through the CompTIA Store. Every attempt requires a full voucher; there's no discounted retake fee unless you buy a retake assurance add-on ahead of time or purchase a bundle that includes one. Academic pricing runs well below list for eligible students, and CompTIA's authorized training partners routinely resell vouchers at a discount, so the list price is a ceiling rather than a fixed cost.
Budget beyond the voucher for study materials if you go that route, whether that's CompTIA's own CertMaster products or third party courses. Candidates who pass on the first attempt spend far less overall than those who need a second voucher, so treating prep time as the real cost control lever tends to pay off more than hunting for a cheaper voucher.
Prerequisites and Eligibility
There's no enforced prerequisite. CompTIA recommends Network+ and two years of hands-on experience in a security or systems administration role, but you can register and sit the exam without either. Recommended isn't required, and plenty of career changers pass without meeting that bar exactly, though they typically compensate with heavier self-study on networking fundamentals.
Scoring and What Passing Requires
You need 750 out of a possible 900 to pass. CompTIA uses a compensatory scoring model, meaning there's a single overall cutoff and no requirement to clear each domain individually. Doing exceptionally well in Security Operations can offset a weaker showing in General Security Concepts, so you don't need to be equally strong everywhere, just strong enough on average. You'll get a provisional pass or fail result the moment you submit the exam.
Renewal and Continuing Education
Security+ certifications carry a three year validity period from your certification date. To keep it active, you renew through CompTIA's Continuing Education (CE) program by earning CEUs, which can come from a mix of relevant work experience, further training, teaching, or other CompTIA-approved activities, rather than retaking the exam cold. If you let the certification lapse without renewing, you'll need to sit the current version of the exam again to reclaim it.
How Security+ Compares to SSCP
The closest vendor-neutral alternative most candidates weigh against Security+ is (ISC)²'s SSCP (Systems Security Certified Practitioner). The two aren't quite interchangeable. SSCP requires a minimum of one year of relevant work experience across its seven domains, or you can pass the exam first and become an Associate of ISC2 while you accumulate that experience within two years. Security+ has no such requirement.
SSCP also moved to computerized adaptive testing in October 2025, running somewhere between 100 and 125 questions depending on how the adaptive engine assesses you, compared to Security+'s fixed 90 question format. In practice, employers tend to treat Security+ as the more common entry point and SSCP as a step for people already doing hands-on security work who want a credential that reflects that experience. If you're choosing between them with no security experience yet, Security+ is usually the more accessible starting point.
Realistic Preparation Timeline
Candidates with some IT background and Network+ already in hand typically need six to eight weeks of consistent study, covering roughly ten to fifteen hours a week. That's enough time to work through each domain once, then spend the final one to two weeks on timed practice exams and PBQ simulations specifically, since the simulation format trips up more people than the multiple choice content does.
Candidates starting with no networking background should plan closer to ten to twelve weeks, with the first few weeks spent shoring up fundamentals that Network+ would normally have covered. Compressing this timeline under pressure to hit a job application deadline is one of the more common reasons people fail on the first attempt and need to buy a second voucher.
Frequently Asked Questions
Same exams as Featured on home
CompTIA
CompTIA Security+
Explore exam
Oracle Cloud
Oracle Cloud Infrastructure Foundations Associate
Explore exam
Amazon Web Services (AWS)
AWS Certified Solutions Architect – Associate
Explore exam
Servicenow
ServiceNow Certified Application Developer
Explore exam
PeopleCert
PRINCE2 Foundation
Explore exam
Information Systems Audit and Control Association (ISACA)
Certified in Risk and Information Systems Control (CRISC)
Explore exam
Google Cloud
Google Cloud Professional Cloud Architect
Explore exam
EC‑Council
Certified Ethical Hacker(CEH)
Explore exam
