How to study for CompTIA Security+ SY0-701
How to study for CompTIA Security+ SY0-701: what is recall and what is scenario judgment, the few calculations, the common traps, and a week-by-week plan.
Security+ is wide rather than deep. The SY0-701 objectives cover five domains, from cryptography to incident response to governance, and most of it is unfamiliar vocabulary on first contact: dozens of acronyms, attack names and control types. The exam then asks you to apply that vocabulary in short scenarios, plus a few performance-based questions where you do a task instead of picking an answer.
That shape points to a study method: build the vocabulary with fast, spaced recall, then spend most of your practice time on choosing between close neighbors in a scenario. This guide covers how to do both, using the structure of the free CompTIA Security+ course.
Know what you are walking into
The SY0-701 exam has a maximum of 90 questions in 90 minutes, a mix of multiple-choice and performance-based questions (PBQs), with a passing score of 750 on a scale of 100 to 900. The five domains are weighted:
| Domain | Weight |
|---|---|
| General Security Concepts | 12% |
| Threats, Vulnerabilities and Mitigations | 22% |
| Security Architecture | 18% |
| Security Operations | 28% |
| Security Program Management and Oversight | 20% |
Security Operations and program management (governance, risk and compliance) together are nearly half of the exam. The five SY0-701 domains, explained goes through what each one covers.
One timing note: CompTIA lists SY0-701 as retiring June 11, 2027 for the English exam, and a newer version is expected around November 17, 2026 with objectives not yet finalized when the course was built. Check which version your exam date books you into.
Recall vs application
Roughly, the material splits into two kinds.
Pure recall. Acronyms (RTO, RPO, MTBF, SLE, ALE), port numbers, the steps of the incident response lifecycle, the CIA triad, control categories and types. These are flashcard material and should become instant. Security+ ports and protocols to memorize groups the ports by job, which is easier than a flat list.
Scenario judgment. Which control fits, which attack is happening, which metric answers the question, which backup type the job describes. These items give you a short story and four plausible answers, so the skill is telling neighbors apart. Practice by writing one sentence that separates each pair:
- IDS vs IPS. An IDS watches a copy of traffic and alerts. An IPS sits inline and can block.
- RTO vs RPO vs MTD. RPO is how much data you can afford to lose, measured in time. RTO is how fast you must recover. MTD is the outer limit the RTO has to fit inside, so a documented RTO must be less than the MTD.
- Incremental vs differential. An incremental copies what changed since the last backup of any type and clears the archive bit. A differential copies everything since the last full and does not clear it.
- Qualitative vs quantitative risk. Qualitative uses low, medium and high ratings; quantitative puts dollar figures on risk.
If you can say these from memory, a large share of the scenario items stop being guesses.
The math is small but predictable
Security+ is not a math exam, but a few calculations reliably appear. All of them are in the course as worked cards.
Annualized loss expectancy. SLE = asset value x exposure factor, and ALE = SLE x ARO. A $500,000 data center with an exposure factor of 0.10 and an ARO of 0.2 (once every 5 years) has an SLE of $50,000 and an ALE of $10,000 per year. The follow-up question is whether a control is worth buying: a cooling fault with an ALE of $25,000 per year, cut in half by an $8,000-per-year control, saves $12,500 and nets $4,500 per year, so it is worth it.
Availability. A server that ran 8,760 hours and failed 4 times has an MTBF of 2,190 hours. If those failures took 20 hours to fix in total, MTTR is 5 hours, and availability = MTBF / (MTBF + MTTR) = 2,190 / 2,195, about 99.77%.
Restore chains. With a full backup on Sunday and incrementals Monday through Friday, a Saturday failure needs 6 restores in order. With differentials instead, it needs 2: Sunday's full plus Friday's differential.
Subnetting. Usable hosts = 2^(32 - n) - 2. A /27 gives 30 usable hosts; a subnet that needs 100 hosts needs a /25 (126 usable). The subnet and CIDR calculator shows the network, broadcast and host range for any address, which is useful for checking your own work.
Where people lose points
- Governance feels like reading, so it gets skimmed. In the course, Unit 15 (Governance, Risk and Compliance) is the largest unit at 11 chapters and 244 cards, because the domain weight is high. Policies vs standards vs procedures, risk responses, agreement types and frameworks are exactly the close-neighbor material that scenario questions test.
- Similar attack names. The phishing family, injection vs XSS vs CSRF, and the password attacks blur together unless you drill the distinguishing feature of each.
- Picking a correct answer instead of the best one. Several options are often true statements. The question asks for the one that fits the scenario.
- PBQs eating the clock. CompTIA does not publish an official time budget for PBQs. General test-taking advice is to read the full task first, and if one PBQ is stalling you, flag it and come back, because one slow item can take time from the multiple-choice questions. PBQs still count, so do not abandon them.
A week-by-week plan
CompTIA suggests about 30 to 40 hours of study for Security+. That fits a four-to-six-week plan with daily sessions. The course runs in 16 units, 79 chapters and 1,308 cards, in an order where each unit builds on the last:
| Weeks | Units | Focus |
|---|---|---|
| 1 | 1-3 | Foundations, cryptography, networking |
| 2 | 4-7 | Threat actors, social engineering and malware, attacks, vulnerabilities |
| 3 | 8-11 | Network architecture, infrastructure and cloud, data protection, identity and access |
| 4 | 12-14 | Security operations, incident response, resilience |
| 5 | 15-16 | Governance, risk and compliance; exam format and PBQs |
| 6 | All | Mixed review and timed practice |
Three habits make the schedule work:
- Learn new cards early each day, then do your reviews. Spaced review of week 1 during week 4 is what keeps cryptography from fading by exam day. What spaced repetition actually does explains the mechanism, and the study schedule generator turns an exam date and topic list into a daily plan.
- Quiz, do not reread. Answering a scenario card from memory does more than reading the explanation again; see the testing effect.
- Mix domains in the final weeks. The real exam does not group questions by domain. Interleaving vs blocking explains why mixed practice helps you recognize which concept a question is about.
If you are new to IT
Security+ has no hard prerequisites. CompTIA recommends Network+ and about two years of security or systems administration experience as background, not as a requirement. Security+ vs Network+ vs A+ helps you decide whether to start somewhere else.
A first programming course also helps more than people expect. Injection attacks, buffer overflows and race conditions are much easier to picture once you have seen how code handles input and memory. What's in intro computer science maps a Python-based CS1 course, and how to study for intro computer science covers the tracing practice that also trains you to read a script in a PBQ. Encodr's free intro college course flashcards list the full set.
When you are ready, open the Security+ SY0-701 flashcards and start with Unit 1.
Encodr turns this into a habit: study anything in a feed, and it schedules the rest.
Get started free