CompTIA Security+ Certification

Certification guide

CompTIA Security+ is the most widely held entry point into a cybersecurity career — a vendor-neutral certification that tells employers you can assess an organization’s security posture, recommend and implement controls, monitor hybrid cloud and on-premises environments, and operate with an awareness of the laws and policies that govern the work. It appears in more early-career security job listings than any comparable credential and satisfies U.S. DoD 8140 requirements for a long list of defense work roles.

The current exam version is SY0-701, released by CompTIA in November 2023. CompTIA typically refreshes the exam on a roughly three-year cycle, with a successor (SY0-801) expected to begin rolling out in late 2026 and SY0-701 remaining available for a transition period after that — check CompTIA’s official Security+ page for retirement dates before scheduling your test.

Exam code SY0-701 Up to 90 questions 90 minutes Passing score 750 / 900 Multiple-choice + performance-based

What the exam covers

CompTIA publishes official exam objectives that organize SY0-701 into five domains, each with a defined share of the exam. The domain names and weightings below are cited from those official objectives; the descriptions of what each one means in practice are our own.

Domain 1 · 12% of the exam

General Security Concepts

The vocabulary and mental models everything else builds on: categories of security controls, the CIA triad and non-repudiation, Zero Trust principles, change management’s role in security, and foundational cryptography concepts from key management to hashing. Small in weight, but these ideas reappear inside questions across every other domain.

Domain 2 · 22% of the exam

Threats, Vulnerabilities, and Mitigations

Know your adversary. This domain tests whether you can recognize threat actors and their motivations, spot attack techniques from phishing and business email compromise to injection attacks, malware families, and password attacks, understand common vulnerability classes, and pick the mitigation that actually addresses a given scenario.

Domain 3 · 18% of the exam

Security Architecture

How to build environments that are defensible by design: comparing cloud, hybrid, virtualized, and industrial-control architectures; network design elements like segmentation, screened subnets, and secure remote access; protecting data across its states and jurisdictions; and the resilience patterns — clustering, backups, recovery sites — that keep a business running through failure.

Domain 4 · 28% of the exam

Security Operations

The largest domain, and the day job: hardening and baselining systems, securing wireless and mobile fleets, vulnerability management and alerting, identity and access management from SSO to just-in-time privilege, automation, and the incident response lifecycle through forensics fundamentals. Expect scenario questions that read like tickets from a real SOC queue.

Domain 5 · 20% of the exam

Security Program Management and Oversight

The governance layer: policies and standards, risk management from registers to quantitative analysis, third-party and vendor risk, compliance and privacy obligations, audits and penetration-test concepts, and building a security-awareness program. This is where technical practitioners often lose easy points — and where a well-drilled candidate quietly banks them.

How our practice exam prepares you

Our Security+ mock is built to the same blueprint: up to 90 questions in a 90-minute timed sitting, with the question mix weighted to the five domains in the same proportions as the official objectives. Every question is tagged to its domain, the order shuffles on every attempt, and each question comes with a full explanation covering why the right answer is right and why each distractor is wrong — because the explanation you read after a miss is where the real studying happens. Retake it as often as you like; your score history tracks your progress on your results page.

CompTIA Security+ (SY0-701) — Practice Exam

Randomized full-length SY0-701 practice exam drawn from a large, blueprint-weighted bank. Every attempt is a fresh 90-question stratified draw matching the official domain blueprint (General Security…

90 questions 90 min pass 83%
Subscribe to start

Trademark and content notice. CompTIA® and Security+® are registered trademarks of CompTIA, Inc. The SY0-701 exam objectives, including the domain titles and weightings referenced above, are the copyrighted property of CompTIA, Inc., and are cited here for identification and educational reference only. Candidates should download the complete, official exam objectives directly from CompTIA at comptia.org.

Certifym.net is an independent study resource operated by Certifym Exam Services, LLC. We are not affiliated with, endorsed by, or sponsored by CompTIA, Inc. All practice questions, answers, and explanations on this site are original works created by Certifym; they are not actual CompTIA exam questions and are not derived from any live exam content. Use of this site does not guarantee a passing score on any certification exam. Exam details (question counts, duration, scoring, and version timelines) are subject to change by CompTIA — always verify current details on CompTIA’s official website.

Frequently Asked Questions

How many questions are on the Security+ exam?

Up to 90 questions on the current SY0-701 version, delivered as a mix of multiple-choice items and performance-based questions (PBQs). The PBQs are interactive scenarios u2014 configuring firewall rules, analyzing log output, matching controls to threats u2014 and they typically appear at the start of the exam.

What is the Security+ passing score?

750 out of 900 on CompTIA's scaled scoring system, which works out to roughly 83 percent. This is not a straight raw score u2014 performance-based questions are weighted more heavily than standard multiple-choice items, so the exact number of questions you need correct varies by form.

How much does the Security+ exam cost?

$425 USD for a single voucher through CompTIA as of 2026. Authorized training partners and the CompTIA Academic Store often sell the same voucher for less, and vouchers are typically valid for 11 to 12 months after purchase. Verify the current price at comptia.org before you book through Pearson VUE.

How long is the Security+ exam?

90 minutes to complete up to 90 questions u2014 an average of one minute per item. The performance-based questions consume time disproportionately, so most candidates leave the PBQs flagged for review, work through the multiple-choice items first, then return to finish the PBQs.

What are the 5 Security+ (SY0-701) domains and their weights?

General Security Concepts (12 percent), Threats, Vulnerabilities, and Mitigations (22 percent), Security Architecture (18 percent), Security Operations (28 percent), and Security Program Management and Oversight (20 percent). Security Operations is the single largest domain and deserves the most study time.

Do I need experience to take the Security+ exam?

No formal experience is required to sit the exam. CompTIA recommends CompTIA Network+ and about two years of hands-on experience in a security or systems administrator role, but neither is enforced at registration. You can register and test whenever you feel ready.

What are performance-based questions on the Security+ exam?

Performance-based questions (PBQs) are interactive simulations that ask you to complete a real task u2014 configuring an access control list, matching log entries to attack types, drag-and-drop firewall rule ordering, and similar exercises. Expect around three to five PBQs on the SY0-701 exam, and expect them to be time-consuming.

How do I maintain the Security+ certification after I pass?

Security+ is valid for three years. Renew by earning 50 Continuing Education Units (CEUs) over the three-year cycle, passing the newest version of the exam, or earning a higher-level CompTIA certification such as CySA+ or CASP+. There is also a CE program fee (currently around $50 per year or $150 for the full three-year cycle).

How many practice questions does Certifym provide for Security+?

900 unique Security+ practice questions across 10 full-length exam sets, plus industry-vertical variants (healthcare, financial services, federal, manufacturing, SaaS, and more), all mapped to the current SY0-701 domain weights with detailed explanations for every answer choice.