← Back to blog
Study science

How to study for CompTIA Security+ SY0-701

How to study for CompTIA Security+ SY0-701: what is recall and what is scenario judgment, the few calculations, the common traps, and a week-by-week plan.

Security+ is wide rather than deep. The SY0-701 objectives cover five domains, from cryptography to incident response to governance, and most of it is unfamiliar vocabulary on first contact: dozens of acronyms, attack names and control types. The exam then asks you to apply that vocabulary in short scenarios, plus a few performance-based questions where you do a task instead of picking an answer.

That shape points to a study method: build the vocabulary with fast, spaced recall, then spend most of your practice time on choosing between close neighbors in a scenario. This guide covers how to do both, using the structure of the free CompTIA Security+ course.

Know what you are walking into

The SY0-701 exam has a maximum of 90 questions in 90 minutes, a mix of multiple-choice and performance-based questions (PBQs), with a passing score of 750 on a scale of 100 to 900. The five domains are weighted:

DomainWeight
General Security Concepts12%
Threats, Vulnerabilities and Mitigations22%
Security Architecture18%
Security Operations28%
Security Program Management and Oversight20%

Security Operations and program management (governance, risk and compliance) together are nearly half of the exam. The five SY0-701 domains, explained goes through what each one covers.

One timing note: CompTIA lists SY0-701 as retiring June 11, 2027 for the English exam, and a newer version is expected around November 17, 2026 with objectives not yet finalized when the course was built. Check which version your exam date books you into.

Recall vs application

Roughly, the material splits into two kinds.

Pure recall. Acronyms (RTO, RPO, MTBF, SLE, ALE), port numbers, the steps of the incident response lifecycle, the CIA triad, control categories and types. These are flashcard material and should become instant. Security+ ports and protocols to memorize groups the ports by job, which is easier than a flat list.

Scenario judgment. Which control fits, which attack is happening, which metric answers the question, which backup type the job describes. These items give you a short story and four plausible answers, so the skill is telling neighbors apart. Practice by writing one sentence that separates each pair:

If you can say these from memory, a large share of the scenario items stop being guesses.

The math is small but predictable

Security+ is not a math exam, but a few calculations reliably appear. All of them are in the course as worked cards.

Annualized loss expectancy. SLE = asset value x exposure factor, and ALE = SLE x ARO. A $500,000 data center with an exposure factor of 0.10 and an ARO of 0.2 (once every 5 years) has an SLE of $50,000 and an ALE of $10,000 per year. The follow-up question is whether a control is worth buying: a cooling fault with an ALE of $25,000 per year, cut in half by an $8,000-per-year control, saves $12,500 and nets $4,500 per year, so it is worth it.

Availability. A server that ran 8,760 hours and failed 4 times has an MTBF of 2,190 hours. If those failures took 20 hours to fix in total, MTTR is 5 hours, and availability = MTBF / (MTBF + MTTR) = 2,190 / 2,195, about 99.77%.

Restore chains. With a full backup on Sunday and incrementals Monday through Friday, a Saturday failure needs 6 restores in order. With differentials instead, it needs 2: Sunday's full plus Friday's differential.

Subnetting. Usable hosts = 2^(32 - n) - 2. A /27 gives 30 usable hosts; a subnet that needs 100 hosts needs a /25 (126 usable). The subnet and CIDR calculator shows the network, broadcast and host range for any address, which is useful for checking your own work.

Where people lose points

A week-by-week plan

CompTIA suggests about 30 to 40 hours of study for Security+. That fits a four-to-six-week plan with daily sessions. The course runs in 16 units, 79 chapters and 1,308 cards, in an order where each unit builds on the last:

WeeksUnitsFocus
11-3Foundations, cryptography, networking
24-7Threat actors, social engineering and malware, attacks, vulnerabilities
38-11Network architecture, infrastructure and cloud, data protection, identity and access
412-14Security operations, incident response, resilience
515-16Governance, risk and compliance; exam format and PBQs
6AllMixed review and timed practice

Three habits make the schedule work:

  1. Learn new cards early each day, then do your reviews. Spaced review of week 1 during week 4 is what keeps cryptography from fading by exam day. What spaced repetition actually does explains the mechanism, and the study schedule generator turns an exam date and topic list into a daily plan.
  2. Quiz, do not reread. Answering a scenario card from memory does more than reading the explanation again; see the testing effect.
  3. Mix domains in the final weeks. The real exam does not group questions by domain. Interleaving vs blocking explains why mixed practice helps you recognize which concept a question is about.

If you are new to IT

Security+ has no hard prerequisites. CompTIA recommends Network+ and about two years of security or systems administration experience as background, not as a requirement. Security+ vs Network+ vs A+ helps you decide whether to start somewhere else.

A first programming course also helps more than people expect. Injection attacks, buffer overflows and race conditions are much easier to picture once you have seen how code handles input and memory. What's in intro computer science maps a Python-based CS1 course, and how to study for intro computer science covers the tracing practice that also trains you to read a script in a PBQ. Encodr's free intro college course flashcards list the full set.

When you are ready, open the Security+ SY0-701 flashcards and start with Unit 1.

Encodr turns this into a habit: study anything in a feed, and it schedules the rest.

Get started free

Related posts