Baseline cybersecurity certification: threats, architecture, operations, governance and risk (DoD 8140).
Set by CompTIA
Free to start · 41 lessons · 3 mock exams · about 39 h of study
You’ll sign in or create a free account first.
CompTIA Security+ is one of the most widely held entry-to-intermediate cybersecurity certifications. Security administrators, SOC analysts, systems and network administrators and career changers take it to prove they can secure networks, identities, endpoints and cloud workloads, respond to incidents, and work within governance, risk and compliance rules. It meets DoD 8140 requirements for many U.S. government roles and appears in job ads worldwide.
The exam is one 90-minute session of up to 90 questions: scenario multiple choice plus performance-based questions (PBQs), which are simulations where you configure, match or analyse. Two versions exist during the changeover. SY0-701 (V7) is live now, and its English version retires on 11 June 2027. SY0-801 (V8) launches on 17 November 2026 in English and adds AI and LLM threats. Both versions pass at 750 on a 100–900 scale. A top result of 850+ shows you read scenarios the way the item writers intend and choose the best answer, not just a plausible one.
Courselo maps both official objective documents onto 41 focused lessons across the five domains, with each version-specific point labelled. Topic banks drill the traps written into CompTIA distractors, PBQ-style data items train log, rule-table and diagram analysis, and full mocks timed like the real exam (one per version) show which domain is costing you points.
Format
1 h 30 min in total · 1 section · 2 versions
Live since 7 November 2023. The English exam retires 11 June 2027; Japanese, Portuguese, Spanish and Thai retire 13 August 2027. Domain weights: 12 / 22 / 18 / 28 / 20. Five domains, 28 objectives (1.1–1.4, 2.1–2.5, 3.1–3.4, 4.1–4.9, 5.1–5.6).
One continuous 90-minute section of up to 90 questions following the SY0-701 objectives: General Security Concepts 12%, Threats, Vulnerabilities, and Mitigations 22%, Security Architecture 18%, Security Operations 28%, Security Program Management and Oversight 20%. Performance-based questions usually come first. You can flag, skip and return; there is no penalty for wrong answers.
Scoring
100–900 · pass 750
Elite
About 96% correct. You beat the hardest best-answer items and the multi-step PBQs.
Syllabus
6 units · 41 topics · about 39 h of lessons and core practice
≈ 3%1 h 10 min
The vocabulary every other domain builds on: CIA, non-repudiation, AAA, defense in depth, least privilege and gap analysis, plus the Zero Trust model with its control-plane and data-plane components (V7 1.2, V8 1.1 and 3.2).
Your course
AI-generated · reviewedParts of this course are generated from the official specification the first time they’re needed, then checked and kept.
Lessons
41
One for every syllabus topic, generated from the official specification and checked
Practice questions
Adaptive
Generated for each topic as you practise, checked before you see them, each with an explanation
Mock exams
3
Questions
If you can be ready before about May 2027, SY0-701 is a safe choice. It is fully supported, study material for it is mature, and the English exam stays available until 11 June 2027. SY0-801 launches on 17 November 2026 in English only and adds AI/LLM threats and some newer terms. Pick it if you will test after launch and want the version that stays current until about 2029. Both versions earn the same Security+ certification, last 3 years, pass at 750 and have the same format. Roughly three-quarters of the content is shared, so studying with Courselo keeps both options open.
CompTIA does not publish a raw cut score. Your answers are converted to a scaled score from 100 to 900, and 750 passes. Performance-based questions can carry more weight than multiple-choice items, so no fixed percentage applies. Courselo’s conservative estimate is about 81% correct for 750. Aim for 86%+ (about 800) on a full mock before you book, and .
Set a target and a test date. You’ll take a diagnostic, see a predicted score with its range, and get a plan for every week until the exam.
Question types
SY0-701 only content includes the Zero Trust control-plane/data-plane vocabulary, blockchain/open public ledger, key stretching, SASE and SD-WAN, containerization, attribute-based access control, risk appetite types (expansionary, conservative, neutral), amplified/reflected DDoS, birthday/collision attacks and VM escape.
Delivery. Computer-based via Pearson VUE: at a test centre or online proctored (OnVUE). SY0-701 is offered in English, Japanese, Portuguese, Spanish and Thai. SY0-801 launches in English only on 17 November 2026. The SY0-701 English exam retires on 11 June 2027 and its other languages on 13 August 2027.
Security+ is a single computer-based session of up to 90 questions in 90 minutes. The exact number varies by exam form because performance-based questions take longer to answer. Most candidates see about 75–90 items. There are three item styles:
You can skip, flag and return to any question, including PBQs, until time runs out. No calculator is provided; the arithmetic that appears (such as ALE = SLE × ARO) is simple enough to do on the note board. CompTIA may include unscored trial items that are not identified.
The score is a scaled score from 100 to 900, and 750 passes on both SY0-701 and SY0-801. The domain weightings differ by version:
| Domain | SY0-701 | SY0-801 |
|---|---|---|
| 1 General Security Concepts | 12% | 16% |
| 2 Threats, Vulnerabilities, and Mitigations (V8: and Attacks) | 22% | 24% |
| 3 Security Architecture | 18% | 19% |
| 4 Security Operations | 28% | 27% |
| 5 Security Program Management and Oversight | 20% | 14% |
880
Top marks
The Courselo target: about 91–92% correct on full mocks, with every domain above 85% and PBQ-style items fully correct.
850
Safe pass
Buffer against a harder form or a slow PBQ. Book the exam once you reach this on a full mock for your version.
800
Pass
The official pass mark on both SY0-701 and SY0-801. About 81% correct on a Courselo full mock.
750
How CompTIA scores Security+. Your answers are converted by a statistical algorithm into a scaled score from 100 to 900, and 750 passes on both SY0-701 and SY0-801. CompTIA does not publish how many questions you must get right. Items are not all worth the same: performance-based questions can be worth more than one multiple-choice item, and candidates widely believe that partial credit is possible on multi-part PBQs, although CompTIA does not confirm this. Unscored trial items may be included without being identified. Scoring is compensatory, so a strong domain can make up for a weak one. There is no negative marking. The score report appears as soon as you finish. It shows your scaled score and lists the objectives linked to the questions you missed, not the questions themselves.
How Courselo estimates your score. The Courselo curve is a deliberately conservative estimate. About 81% correct maps to 750, 86% to about 795, 92% to about 850 and 96% to about 880. Every question in a Courselo mock counts once. A multiple-response item earns credit only when your selection matches every correct option. A PBQ-style item set is scored item by item, so a partly correct simulation earns partial credit, as it may on the real exam.
What the targets mean. A mock score of 750 means you would pass a typical form with no margin. Aim for 800+ on the full mock for your version before you book. For top marks, keep going until you reach 850+. At that level no domain is below about 85%, and you consistently pick the best control, the first step or the most likely attack when two options are both technically true.
| Band | From |
|---|---|
| PassMeets the CompTIA standard; Security+ certification awarded (valid 3 years). | 750+ |
| FailBelow 750. The first retake can be booked immediately; a 14-day wait applies before the third and later attempts. | 100+ |
≈ 2.5%45 min
Classifying any control by category (technical, managerial, operational, physical) and by function (preventive, deterrent, detective, corrective, compensating, directive). It is tested in multiple choice and in matching PBQs (V7 1.1, V8 1.1).
≈ 1.5%40 min
Perimeter and facility controls, sensors and access control vestibules, and the physical attacks they counter: tailgating, badge cloning, skimming, forced entry and environmental attacks (V7 1.2 and 2.4; V8 2.3 physical-based vectors and 2.5 physical attacks).
≈ 2%45 min
How change management processes protect security: approvals, impact analysis, backout plans, maintenance windows, technical implications of changes and keeping documentation current (V7 1.3, V8 1.2).
≈ 3%1 h 20 min
Symmetric and asymmetric encryption, key exchange, algorithms and key lengths, encryption levels from full-disk to record, hashing and salting, digital signatures, obfuscation and hardware crypto tools such as TPM, HSM, KMS and secure enclaves (V7 1.4, V8 1.3).
≈ 2%1 h
Public key infrastructure and the certificate life cycle: CAs, root of trust, CSRs, revocation with CRL and OCSP, key escrow, and choosing between self-signed, third-party and wildcard certificates (V7 1.4, V8 1.3).
About 5 h 40 min of study, lessons and core practice
≈ 2.5%45 min
Who attacks and why. Covers nation-state, unskilled, hacktivist, insider, organized crime, competitor and terrorist actors, their resources and sophistication, and their motivations (V7 2.1, V8 2.2).
≈ 2.5%55 min
The routes attackers use: message-based, image- and file-based, browser, network and remote access, endpoint and living-off-the-land, supply chain, removable media, IoT/OT and signal-based vectors, and how to shrink the attack surface (V7 2.2, V8 2.3).
≈ 3%50 min
Recognising phishing and its variants, pretexting, impersonation, business email compromise, watering holes, typosquatting and deepfakes from scenario clues, and choosing the control that stops each (V7 2.2 and 2.4, V8 2.3 and 2.5).
≈ 3%1 h 15 min
Memory injection, buffer overflows, race conditions, injection, cross-site scripting, request forgery, directory traversal, replay and privilege escalation, recognised from code, URLs and logs, with the secure-coding fix for each (V7 2.3 and 2.4, V8 2.4 and 2.5).
≈ 3%1 h 5 min
Vulnerabilities beyond application code: unpatched, legacy and end-of-life systems, firmware, VM escape and resource reuse, cloud misconfiguration, mobile sideloading and jailbreaking, zero-days, stale credentials, rogue devices and shadow IT (V7 2.3, V8 2.4).
≈ 3.5%1 h 10 min
Distinguishing malware by behaviour and analysing indicators of malicious activity (hashes, processes, artifacts, account lockouts, impossible travel, missing logs) to decide what happened and what to do first (V7 2.4, V8 2.5).
≈ 3.5%1 h 10 min
Analysing DDoS, DNS, on-path, spoofing, sniffing and wireless attacks, downgrade and collision attacks, and password spraying, brute force, enumeration, replay and MFA bypass from traffic and authentication evidence (V7 2.4, V8 2.5).
≈ 2%55 min
Security+ V8 (from ~2026-11-17) only
The new SY0-801 objective 2.6, plus the LLM attack surface from 2.4. Covers model manipulation, poisoning, prompt injection, jailbreaking, evasion, data loss, privacy, hallucinations, bias, explainability, ethics, session hijacking and code execution in AI-enabled systems.
About 8 h 5 min of study, lessons and core practice
≈ 3%1 h 5 min
Security implications of cloud service and deployment models, the shared responsibility matrix, infrastructure as code, serverless, microservices, containers and virtualization, and the technical and business considerations that decide between them (V7 3.1, V8 3.1).
≈ 2.5%50 min
Air-gapped and segmented networks, software-defined networking, centralized and decentralized designs, and the special constraints of ICS/SCADA, operational technology, RTOS, embedded and IoT systems that often cannot be patched (V7 3.1, V8 3.1).
≈ 3.5%1 h 15 min
Applying security principles to network design: device placement, security zones, failure modes, inline vs tap devices, jump servers, proxies, IDS/IPS, load balancers, 802.1X port security and firewall types (V7 3.2, V8 3.2).
≈ 2.5%1 h
VPNs and tunneling (TLS, IPsec), SD-WAN and SASE (V7) and Security Service Edge (V8), secure administrative access and file transfer, Zero Trust access decisions, and the service and privileged identities behind them (V7 3.2, V8 3.2).
≈ 3%1 h 10 min
Classifying data, protecting it at rest, in transit and in use, choosing between encryption, hashing, masking, tokenization and obfuscation, and the roles, handling rules, life cycle and sovereignty issues that govern it (V7 3.3, V8 3.3).
≈ 2%50 min
Load balancing, clustering and autoscaling, hot, warm and cold sites, geographic dispersion, platform diversity, multicloud, capacity planning, continuity of operations and power resilience (V7 3.4, V8 3.4).
≈ 2%50 min
Designing backups (frequency, onsite/offsite, encryption, snapshots, replication, journaling, immutability), testing recovery with tabletop, failover, simulation and parallel processing, and applying RTO, RPO, MTTR and MTBF (V7 3.4 and 5.2, V8 3.4).
About 7 h of study, lessons and core practice
≈ 2.5%1 h
The enterprise mitigation toolkit: segmentation, access control, allow lists, isolation, patching, configuration enforcement, decommissioning, secure baselines, hardening each target type, deception technology and sandboxing (V7 2.5 and 4.1, V8 4.1).
≈ 1.5%45 min
Planning and securing wireless networks (site surveys, heat maps, WPA3, RADIUS, EAP) and managing mobile devices with MDM across BYOD, COPE and CYOD deployment models (V7 4.1, V8 4.1 and 2.4).
≈ 2.5%1 h 5 min
Writing and ordering firewall rules and ACLs, choosing between network, host and wireless IDS/IPS and their detection methods, and enforcing network access control with 802.1X, captive portals and posture checks (V7 4.5, V8 4.1).
≈ 1.5%50 min
Web and content filtering, DNS filtering, email authentication (SPF, DKIM, DMARC, BIMI) and gateways, and choosing secure protocols and ports in place of insecure ones (V7 4.5, V8 4.1).
≈ 2%55 min
Antivirus, EDR and XDR, user behaviour analytics, file integrity monitoring and DLP on endpoints, OS hardening with Group Policy and SELinux, and application security controls from input validation to code signing and secrets scanning (V7 4.1 and 4.5, V8 4.1).
≈ 1.5%40 min
The asset life cycle and its security implications: procurement, assignment and ownership, inventory and enumeration, and disposal with sanitization, destruction and certification (V7 4.2, V8 4.2).
≈ 3%1 h 10 min
The full vulnerability management cycle: identification (scans, code analysis, pen tests, threat feeds, CSPM), analysis and prioritization with CVSS and CVE, response, validation and reporting, plus bug bounties and responsible disclosure (V7 4.3, V8 2.1 and 4.3).
≈ 2%55 min
Monitoring systems, applications and infrastructure with SIEM, SCAP and benchmarks, agents and agentless tools, NetFlow, SNMP, syslog and packet analysis, and tuning alerts so the right event gets action first (V7 4.4, V8 4.4).
≈ 2%50 min
The identity life cycle (proofing, provisioning, deprovisioning, access review), SSO and federation with SAML, OAuth and LDAP, account types and attestation (V7 4.6, V8 4.5).
≈ 2.5%1 h
Access control models (MAC, DAC, RBAC, rule-based, ABAC, time-based, just-in-time), MFA factors and implementations, password policy, passkeys and passwordless login, and privileged access management (V7 4.6, V8 4.5).
≈ 1.5%40 min
Where scripting and orchestration improve security (provisioning, guard rails, ticketing, CI/CD), their benefits and risks, and AI capabilities in security operations (V7 4.7, V8 4.6).
≈ 2.5%1 h
The incident response life cycle in order, preparation with playbooks and exercises, choosing the right next step, root cause analysis, threat hunting, and notification and negotiation in V8 (V7 4.8, V8 4.7).
≈ 2%1 h
Forensic principles (legal hold, chain of custody, order of volatility, preservation, e-discovery) and choosing and correlating the log and data sources that answer an investigation question (V7 4.8 and 4.9, V8 4.7 and 4.8).
About 11 h 50 min of study, lessons and core practice
≈ 3%55 min
The governance document hierarchy (guidelines, policies, standards, procedures), key policies, external considerations, governance structures and roles for systems and data (V7 5.1, V8 5.1).
≈ 3.5%1 h 10 min
The risk management process from identification to reporting: qualitative and quantitative analysis (SLE, ALE, ARO, EF), risk registers, appetite and tolerance, treatment strategies and business impact analysis (V7 5.2, V8 5.2).
≈ 2.5%45 min
Selecting, contracting and monitoring vendors: due diligence, right-to-audit, questionnaires, agreement types (SLA, MOU, MOA, MSA, SOW, NDA, BPA) and rules of engagement (V7 5.3, V8 5.3).
≈ 2.5%50 min
Compliance reporting and monitoring, consequences of non-compliance, privacy obligations (data subject rights, controller vs processor, retention, right to be forgotten) and legal compliance such as legal holds (V7 5.4, V8 5.4).
≈ 2.5%55 min
Internal and external audits and attestation, penetration test types and environments, passive vs active reconnaissance, assessment scoping, and in V8 the attack frameworks used to structure findings (V7 5.5, V8 5.5).
≈ 2%40 min
Running phishing campaigns, recognising anomalous behaviour, delivering user training on the right topics, and measuring whether the program works (V7 5.6, V8 5.6).
About 5 h 15 min of study, lessons and core practice
≈ 1%1 h
How to work the 3–5 simulations that open most Security+ forms. Covers completing firewall rule tables, analysing logs, matching attacks to controls, placing devices on diagrams and ordering procedures, all under time pressure.
About 1 h of study, lessons and core practice
1 diagnostic · 2 full-length, timed and scored like the real test
Strategy guides
7
Pacing, section strategy and test-day guides
Free to start
Every lesson and guide is free, with 40 practice questions a day and the diagnostic. Pro removes the limits.
Compare plansPBQs are interactive tasks such as completing a firewall rule table, matching attacks to controls, placing devices on a diagram or analysing logs. Most forms have 3–5, usually at the start. They take longer than multiple-choice items, so many top scorers skip them at first, answer all the multiple choice, and then return with the time left, which is typically 25–35 minutes. You can flag and return to any question. Candidates widely report that PBQs can earn partial credit, so always submit your best attempt.
There is no penalty for wrong answers, and unanswered questions are simply marked wrong, so answer everything. You can flag any item and return to it before time runs out. Multiple-response items tell you how many to pick (“Choose two.”). Pick exactly that many.
There are no formal prerequisites. CompTIA recommends about two years of hands-on security or systems administration experience, and Network+ is recommended for V7. With networking basics, most candidates need 6–8 weeks at 8–10 hours a week. Complete beginners should plan 10–12 weeks and learn TCP/IP, ports and subnetting basics first. Hands-on practice with firewalls, logs, Active Directory/Group Policy and a SIEM makes PBQs much faster.
Yes. You can test at a Pearson VUE test centre or through OnVUE online proctoring with a webcam, a clean room and a stable connection. If you fail, there is no waiting period before your second attempt. A 14-day wait applies before the third and any later attempt, and each attempt needs a new voucher. Your score report lists the objectives you missed. Run the Courselo diagnostic again, work through those topics, and score 800+ on the full mock before rebooking.
The certification is valid for 3 years. Renew it by earning 50 continuing education units (CEUs) through CompTIA’s CE program, or by passing a higher-level CompTIA certification such as CySA+, PenTest+ or SecurityX. Security+ is approved for many roles under the U.S. Department of Defense 8140 workforce framework (the successor to 8570). Check the current DoD Cyber Workforce Qualification Matrix for your specific work role.