Security+ · Learn
41 lessons in 6 units, about 38 h 50 min of reading and core practice. Each lesson ends with a quick check.
Specification
Unit 1
SY0-701 objectives 1.1–1.4 and SY0-801 objectives 1.1–1.3. Covers security control categories and types, fundamental concepts (CIA, AAA, non-repudiation, defense in depth, least privilege, Zero Trust), physical security, change management, cryptography and PKI. V8 merges controls and concepts into one objective and moves deception technology to Domain 4.
6 lessons · 5 h 40 min of study · ≈14% of the test
Unit 2
SY0-701 objectives 2.1–2.5 and SY0-801 objectives 2.1–2.6. Covers threat actors and motivations, threat vectors and attack surfaces, social engineering, application, system and cloud vulnerabilities, and analysing indicators of malware, network, credential and physical attacks. V8 adds AI/LLM threats (2.6) and moves CVSS/CVE into this domain. The V7 mitigation techniques objective (2.5) is taught under Domain 4, where V8 places it.
8 lessons · 8 h 5 min of study · ≈23% of the test
Unit 3
SY0-701 and SY0-801 objectives 3.1–3.4. Covers the security implications of cloud, virtualized, on-premises, OT/IoT and embedded architectures, securing enterprise infrastructure and remote access, protecting data, and resilience and recovery. V8 adds SSE, gMSAs, data roles and the data life cycle, and moves recovery metrics (RTO, RPO, MTTR, MTBF) here from Domain 5.
7 lessons · 7 h of study · ≈19% of the test
Unit 4
SY0-701 objectives 4.1–4.9 and SY0-801 objectives 4.1–4.8, the most heavily weighted domain. Covers mitigation and hardening, wireless and mobile security, firewalls, IDS/IPS and NAC, web, DNS and email security, endpoint and application security, asset and vulnerability management, monitoring, identity and access management, automation, incident response and investigations. This domain is the richest source of performance-based questions.
13 lessons · 11 h 50 min of study · ≈27% of the test
Unit 5
SY0-701 and SY0-801 objectives 5.1–5.6. Covers governance documents and structures, risk management and quantitative risk analysis, third-party risk, compliance and privacy, audits, assessments and penetration testing, and security awareness. The domain is lighter in V8, which moves recovery metrics to Domain 3 and adds attack frameworks and awareness metrics.
6 lessons · 5 h 15 min of study · ≈16% of the test
Unit 6
The practical skills that PBQs assess across all domains: rule tables, log analysis, matching and placement, and ordering procedures, plus the time management that stops PBQs from costing multiple-choice points.
1 lesson · 1 h of study · ≈1% of the test
Start here
Domain 1: general security concepts (V7 12% · V8 16%) · Lesson 1 of 6
The vocabulary every other domain builds on: CIA, non-repudiation, AAA, defense in depth, least privilege and gap analysis, plus the Zero Trust model with its control-plane and data-plane components (V7 1.2, V8 1.1 and 3.2).
1 h 10 min of study≈3% of the test
Start the first lessonSign in to keep your place and see your mastery on every topic.
Every lesson is free to read. With an account, finished lessons are ticked off, quick checks feed your mastery, and flashcards come back for review.
Strategy, scoring and test day, beyond the syllabus.
Learn, then practise
Each lesson ends with three quick questions. For more, practice adapts to the topics you’re weakest on.
Open practice