← Back to blog
Study science

The five CompTIA Security+ SY0-701 domains, explained

What each of the five SY0-701 domains covers, how much of the exam it is worth, and how to split your study time across them.

CompTIA Security+ exam SY0-701 is organized into five domains, and the weights are not even. Knowing which domains carry the most questions tells you where your hours should go. The format, per CompTIA's Security+ page: up to 90 questions, multiple choice and performance-based, in 90 minutes, with a passing score of 750 on a scale of 100 to 900.

The five domains and their weights

DomainShare of the exam
1.0 General Security Concepts12%
2.0 Threats, Vulnerabilities and Mitigations22%
3.0 Security Architecture18%
4.0 Security Operations28%
5.0 Security Program Management and Oversight20%

These come from CompTIA's own comparison of the SY0-601 and SY0-701 versions. SY0-701 has 28 objectives, down from 35, and CompTIA says about 20% of the objectives were updated to reflect trends such as zero trust, IoT, operational technology, cloud and hybrid environments.

What each domain is about

General Security Concepts (12%). The vocabulary everything else rests on: security controls and how they are categorized, the ideas behind zero trust, and the basics of cryptography. It is the smallest domain, but weak foundations here make every later domain harder.

Threats, Vulnerabilities and Mitigations (22%). Who attacks, how, and what reduces the risk: threat actors and their motivations, attack types, and the mitigations and hardening steps that answer them.

Security Architecture (18%). How secure systems are designed: network design, cloud and virtualized environments, data protection and resilience. Networking basics matter here, which is one reason CompTIA recommends Network+ first. The subnet and CIDR calculator is good practice for the addressing side.

Security Operations (28%). The biggest domain and the day-to-day work: monitoring, vulnerability management, identity and access management, incident response and automation. If you only had one domain to over-study, this is it.

Security Program Management and Oversight (20%). Governance, risk management, third-party risk, compliance and audit. It reads less technical, and many candidates under-prepare for it because of that.

How to use the weights

Split study time roughly in line with the percentages, then shift extra hours to whichever domain your practice questions show you are weakest in. Two traps: skipping the 12% domain because it looks basic, and skipping the 20% domain because it looks like paperwork.

CompTIA has also said a newer version of Security+ is expected around November 17, 2026, and lists SY0-701 as retiring June 11, 2027 for English. Check the objectives for the version you are booked to sit.

Where this goes next

An Encodr Security+ course is in the works. See the Security+ coming-soon page for the exam facts, or browse all exam prep courses. Related reading: ports and protocols to memorize and Security+ vs Network+ vs A+.

Free tool

Subnet and CIDR Calculator

Get the mask, network and broadcast address, host range and usable hosts for any IPv4 address and prefix.

Try it →

Encodr turns this into a habit: study anything in a feed, and it schedules the rest.

Get started free

Related posts