Introduction and Certification Overview
CompTIA Security+ is the most widely held entry-to-intermediate level cybersecurity certification in the world. Administered by CompTIA (Computing Technology Industry Association), Security+ validates the baseline security skills and knowledge required to perform core security functions and pursue a career in IT security. It is vendor-neutral, meaning it covers security concepts, principles, and practices applicable across technologies, platforms, and environments rather than being tied to any specific vendor’s products.
Now in its seventh major version — SY0-701, released November 2023 — Security+ has evolved alongside the security profession to reflect the current threat landscape, including cloud security, hybrid environments, automation, zero trust architecture, and the expanded attack surface created by IoT, operational technology, and remote workforce adoption. The certification is trusted by more than 700,000 IT professionals globally and is recognized by the US Department of Defense as meeting DoD 8570/8140 requirements for Information Assurance Technical (IAT) Level II positions.
Security+ occupies a critical position in the certification ecosystem: it is the natural next step for IT generalists seeking to specialize in security (after CompTIA A+ and Network+), and it is the recognized baseline security credential for professionals beginning security-focused career paths. It provides the conceptual vocabulary, technical knowledge, and practical skills that serve as a foundation for advanced certifications including CASP+, CySA+, CISSP, and CEH. For many employers — particularly in the US government and defense sectors — Security+ is a minimum hire requirement for IT security roles.
Certification at a Glance
| Item | Detail |
|---|---|
| Full Name | CompTIA Security+ (SY0-701) |
| Issuing Body | CompTIA — Computing Technology Industry Association |
| Current Version | SY0-701 (released November 2023; replaces SY0-601) |
| Exam Format | Maximum 90 questions; combination of multiple-choice and performance-based questions (PBQs) |
| Exam Duration | 90 minutes |
| Passing Score | 750 on a scale of 100–900 |
| Number of Domains | 5 domains |
| Prerequisites | No mandatory prerequisites; CompTIA recommends Network+ and 2 years of IT experience with a security focus, but these are advisory only |
| Validity Period | 3 years; renewal through Continuing Education (CE) or retake |
| CE Credits Required | 50 Continuing Education (CE) units over 3 years for renewal |
| DoD Approval | Approved under DoD 8570/8140 for IAT Level II, CSSP Analyst, CSSP Infrastructure Support, IASAE Level I |
| Vendor Neutrality | Fully vendor-neutral; no vendor-specific tools, platforms, or proprietary technologies tested |
| Exam Delivery | Pearson VUE testing centers (in-person) or Pearson VUE online proctored |
| Exam Cost | USD $392 (standard); discounts available through academic institutions, training bundles, and voucher programs |
| Languages Available | English, Japanese, Portuguese, Simplified Chinese, German |
| CompTIA Pathway Position | Entry-to-intermediate; follows Network+; precedes CySA+, PenTest+, and CASP+ |
| Global Recognition | Recognized in 147+ countries; referenced in US DoD directives, Federal Agency security frameworks, and enterprise hiring standards |
History and Evolution of CompTIA Security+
CompTIA Security+ has a history spanning more than two decades, during which it has been updated seven times to reflect the rapidly evolving security threat landscape, technology environment, and professional skill requirements. Each version has retained the foundational security principles that made the certification valuable while updating technical content to reflect current threats, tools, and practices.
| Version | Year Released | Key Changes & Focus Areas |
|---|---|---|
| SY0-101 (v1) | 2002 | First edition; foundational security concepts — network security, cryptography, access control, authentication; established the vendor-neutral security baseline credential model |
| SY0-201 (v2) | 2008 | Expanded network infrastructure security; added application, data, and host security; updated threat and vulnerability coverage; wireless network security expanded |
| SY0-301 (v3) | 2011 | Major restructuring; added compliance and operational security; expanded cryptography; introduced risk management concepts; updated to reflect evolving threat landscape |
| SY0-401 (v4) | 2014 | Shifted emphasis toward risk management and policy; expanded mobile device security; cloud computing security introduced; updated malware and application security coverage |
| SY0-501 (v5) | 2017 | Updated threat intelligence coverage; expanded identity and access management; cloud and virtualization security deepened; incident response and forensics expanded; 6-domain structure |
| SY0-601 (v6) | 2020 | Significant restructuring to 5 domains; expanded cloud hybrid environment coverage; risk management deepened; secure protocols and implementation updated; operational security and governance integrated |
| SY0-701 (v7) | November 2023 | Current version; enhanced AI and automation threats; expanded zero trust and SASE coverage; updated cloud-native security; expanded IoT and OT threats; Governance, Risk & Compliance domain made more explicit; updated PBQ format with new scenario types |
What Changed: SY0-601 to SY0-701
The SY0-701 update represents a significant content refresh from its predecessor. Candidates preparing from SY0-601 materials will find that while the domain structure is similar, the specific content emphasis has shifted substantially. Key changes include:
- Expanded AI and Automation CoverageThe SY0-701 explicitly covers AI-driven threats (AI-powered phishing, automated vulnerability discovery), AI-enabled defensive tools (AI-powered SIEM, automated incident response), and the security considerations of AI systems themselves
- Zero Trust Architecture DeepenedZero Trust is now a primary architectural concept tested throughout multiple domains, not a peripheral topic; candidates must understand zero trust principles, components, and implementation approaches
- Cloud-Native and Hybrid EmphasisCloud security is integrated throughout all five domains; hybrid environment security (on-premises plus cloud) is a primary operational context throughout the exam
- Governance, Risk and Compliance Domain ExpandedThe fifth domain (GRC) has been significantly expanded with more emphasis on regulatory frameworks, third-party risk, data privacy regulations, and security policy frameworks
- Updated Threat LandscapeNew attack techniques including living-off-the-land (LotL) attacks, supply chain attacks, and AI-assisted social engineering are explicitly included; IoT and OT threats expanded
- Revised PBQ FormatPerformance-based questions include new scenario types reflecting cloud and hybrid environments; drag-and-drop and ordering updated questions to reflect current security workflows
Exam Structure, Format, and Performance-Based Questions
The Security+ exam is structured to test both conceptual knowledge and practical application through a combination of traditional multiple-choice questions and performance-based questions (PBQs). This dual format reflects CompTIA’s objective to certify professionals who can not only recall security concepts but also apply them to realistic scenarios — addressing the criticism that purely knowledge-based exams do not validate practical competency.
Exam Format Details
| Item | Detail |
|---|---|
| Maximum Questions | 90 questions (combination of multiple-choice and PBQs) |
| Time Limit | 90 minutes (60 seconds per question at maximum; PBQs typically require more time |
| Passing Score | 750 on a scale of 100–900 (approximately 83% scaled score; not a direct percentage of correct answers) |
| Scaled Scoring | The 100–900 scale is a psychometric transformation that accounts for question difficulty variation between exam forms; the raw number of correct answers required varies slightly between forms |
| Question Ordering | PBQs typically appear at the beginning of the exam; multiple-choice questions follow. Candidates can flag and return to questions but cannot return to the PBQ section after leaving it (in most delivery modes) |
| Exam Delivery | Pearson VUE testing centers(in-person, supervised); Pearson VUE online proctored (from home or office, with webcam monitoring) |
| Retake Policy | No mandatory waiting period for first retake; subsequent retakes require a 14-day waiting period; no maximum retake limit; full exam fee applies to each retake |
| Score Reporting | Immediate pass/fail result at the testing center; detailed performance report by domain available through the Pearson VUE portal |
| Exam Language | English (primary); Japanese, Portuguese, Simplified Chinese, and German available at select centers |
Performance-Based Questions (PBQs)
Performance-based questions are the distinguishing feature of Security+ compared to purely multiple-choice examinations. PBQs present scenarios in interactive, simulated environments where candidates must perform actual security tasks rather than select an answer from a list. They test applied knowledge and problem-solving capability that multiple-choice questions cannot assess.
| Item | Detail |
|---|---|
| PBQ Types | Drag-and-drop (matching items to categories, placing steps in correct sequence); fill-in-the-blank (typing a specific command, port number, or term); simulation (interacting with a simulated firewall, IDS, or network tool interface); ordering (arranging process steps in the correct sequence); hotspot (clicking the correct element in a network diagram or interface screenshot) |
| Typical PBQ Topics | Firewall rule configuration (identifying correct ACL rules for a given policy); network troubleshooting (reading packet captures or network diagrams); cryptography application (selecting appropriate algorithm for a given requirement); incident response steps (ordering the phases of an IR lifecycle); access control configuration (selecting correct permission settings for a scenario); log analysis (identifying attack evidence in a log excerpt) |
| Time Allocation | PBQs appear at the start of the exam; they are typically more time-consuming than multiple-choice questions. Candidates who spend excessive time on a difficult PBQ risk running short of time for the remaining questions. CompTIA recommends spending no more than 5–7 minutes per PBQ before flagging and moving on. |
| Scoring | PBQs may be partially scored — candidates who get some elements of a multi-part PBQ correct may receive partial credit. This makes it worthwhile to attempt every PBQ rather than leaving them blank, even when unsure of the complete answer. |
| Cannot Skip | Unlike multiple-choice questions, PBQs presented at the beginning of the exam cannot be skipped and revisited. Candidates must complete or flag each PBQ before advancing. This makes time management strategy for PBQs particularly important. |
The 5 Security+ SY0-701 Exam Domains — Complete Reference
The SY0-701 examination is organized across five domains that collectively cover the full scope of foundational and intermediate information security practice. CompTIA publishes the official exam objectives document (available free from the CompTIA website) which specifies every sub-topic and sub-subtopic within each domain. The objectives document is the authoritative guide to exam content and should be the primary study roadmap for every candidate.
Each domain carries a published percentage weight indicating its proportional representation in the exam question pool. These weights should guide study time allocation — higher-weighted domains warrant more preparation time — but all domains must be studied thoroughly as weaknesses in any domain will affect the scaled score.
1.0 12% of Exam |
General Security Concepts Establishes the foundational vocabulary, principles, and conceptual framework underpinning all security practice. Sub-topics include: security controls (technical, managerial, operational, physical; preventive, detective, corrective, deterrent, compensating, directive), fundamental security concepts (CIA Triad — Confidentiality, Integrity, Availability; non-repudiation, authentication, authorization, accounting; zero trust principles — never trust always verify, least privilege, micro segmentation), change management security implications (approval process, impact assessment, testing, backout planning, legacy systems), basic cryptography concepts (symmetric vs. asymmetric encryption, hashing, digital signatures, key exchange, PKI fundamentals, common use cases for cryptographic protocols), and authentication concepts (password-based authentication, multi-factor authentication factors — Type 1/2/3, passwordless authentication, SSO concepts). This domain provides the conceptual vocabulary used throughout the entire exam and in professional security practice. |
2.0 22% of Exam |
Threats, Vulnerabilities, and Mitigations The largest domain; covers the threat landscape, attack techniques, vulnerability types, and defensive countermeasures. Sub-topics include: threat actors and motivations (nation-state, organized crime, hacktivists, insiders, script kiddies — each with distinct capabilities, resources, and objectives), attack surfaces (on-premises, cloud, remote work, supply chain, IoT/OT), social engineering techniques (phishing, vishing, smishing, spear-phishing, whaling, BEC, pretexting, baiting, piggybacking, watering hole attacks), malware types (ransomware, Trojans, worms, spyware, adware, rootkits, backdoors, keyloggers, logic bombs, fileless malware), application attacks (SQL injection, XSS, buffer overflow, race conditions, directory traversal, privilege escalation, request forgery — CSRF and SSRF), network-based attacks (DoS/DDoS — volumetric, protocol, application layer; on-path/MITM; DNS attacks; VLAN hopping; replay attacks; ARP poisoning), indicators of malicious activity (network anomalies, host-based anomalies, application anomalies), and mitigation techniques for each attack category. This domain requires understanding both how attacks work and what controls defend against them. |
3.0 18% of Exam |
Security Architecture Covers secure design principles for infrastructure, cloud, network, and application environments. Sub-topics include: security implications of different architectures (cloud — IaaS, PaaS, SaaS, shared responsibility model; hybrid cloud; on-premises; serverless; microservices; network infrastructure — physical vs. logical segmentation, software-defined networking; IoT; industrial control systems/SCADA/OT; embedded systems; RTOS), infrastructure considerations (device placement, security zones, attack surface minimization, connectivity technologies — cellular, VPN, SD-WAN, SASE), network security design (network segmentation, DMZ, jump server, proxy server, IDS/IPS placement, load balancers, web application firewalls, firewall types — stateless, stateful, NGFW, UTM), secure network protocols (DNS security, HTTPS, SFTP, SRTP, SNMPv3, IPSec, TLS/DTLS, SSH, LDAPS), data protection (data at rest, in transit, in use; encryption approaches; tokenization; data masking; rights management), resiliency and recovery (high availability, geographic dispersal, RAID levels, replication, backup strategies — 3-2-1 rule, RTO/RPO, DR site types — hot/warm/cold), and zero trust implementation components (policy engine, policy administrator, policy enforcement point). Architecture questions require applying design principles to specific scenarios — not just defining terms. |
4.0 28% of Exam |
Security Operations The largest domain by weight; covers the day-to-day operational security activities that maintain organizational security posture. Sub-topics include: identity and access management operations (user lifecycle management — provisioning, deprovisioning, role-based access, privilege management; MFA enforcement; PAM; federation and SSO technologies — SAML, OAuth 2.0, OpenID Connect, RADIUS, TACACS+, Kerberos; directory services — LDAP, Active Directory), security alerting and monitoring (SIEM — log aggregation, correlation, alerting; SOAR — automated response playbooks; EDR/XDR; network traffic analysis; threat intelligence feeds — STIX/TAXII, IoC types), automation and orchestration in security (benefits of automation, playbook development, API-based security integrations, security script basics), vulnerability management (scan types — credentialed vs. non-credentialed, internal vs. external; CVSS scoring and prioritization; remediation workflows; patch management; penetration testing integration), incident response (NIST IR lifecycle — Preparation, Detection, Analysis, Containment, Eradication, Recovery, Post-Incident Activity; incident classification; digital forensics — order of volatility, chain of custody, evidence preservation; e-discovery), endpoint security operations (antivirus/anti-malware, EDR, application control, disk encryption, patch management, host-based IDS/IPS), hardening techniques (default credential removal, disabling unnecessary services and ports, patch management, encryption at rest, secure baseline configurations — CIS Benchmarks, STIG), cloud security operations (cloud security posture management — CSPM, secrets management, serverless security, container security — image scanning, runtime security), and network security operations (firewall management, IDS/IPS tuning, network segmentation maintenance, wireless security operations — 802.1X, EAP types). This domain rewards candidates with practical operational experience the most. |
5.0 20% of Exam |
Security Program Management and Oversight Covers the governance, risk management, compliance, and program management activities that direct and oversee the security function. Sub-topics include: elements of effective security governance (security policies — acceptable use, data handling, password policies, BYOD, clean desk, social media; policy frameworks and standards — NIST CSF, ISO 27001, SOC 2, CIS Controls; security program structure and ownership), risk management (risk assessment types — qualitative and quantitative; risk treatment options — accept, avoid, transfer, mitigate; business impact analysis; risk register; risk tolerance and appetite), third-party risk management (vendor assessment, supply chain risk, right-to-audit clauses, SLA security requirements, questionnaire frameworks), data classification and privacy (data classification tiers — public, internal, confidential, restricted; data subject rights; privacy regulations — GDPR, CCPA, HIPAA; data retention and destruction), compliance frameworks and legal considerations (regulatory drivers — PCI DSS, HIPAA, GDPR, SOX; compliance monitoring; audit and assessment types — internal, external, compliance, penetration test; security reporting and KPIs), security awareness and training (phishing simulation programs, security culture, role-based training, new hire orientation, metrics for awareness effectiveness), and automation and AI in governance (automated compliance monitoring, AI-assisted risk assessment, governance tools). The GRC domain tests the understanding of security management as a business function — not just technical operations. |
Domain Weights and Study Priority
| Domain | Exam Weight | Study Priority Notes |
|---|---|---|
| 1.0: General Security Concepts | 12% | Smallest domain; do not underestimate — foundational vocabulary tested throughout the entire exam; all other domains assume Domain 1 concepts; cryptography sub-topics require dedicated study time |
| 2.0: Threats, Vulnerabilities & Mitigations | 22% | Second highest weight; largest content breadth; requires memorizing attack types, malware categories, social engineering techniques, and specific countermeasures; attack scenario questions are most common on exam |
| 3.0: Security Architecture | 18% | Network design, cloud architecture, and secure protocol selection; diagram-based PBQs often draw from this domain; hybrid cloud and zero trust architecture are particularly high-frequency topics |
| 4.0: Security Operations | 28% | Highest weight; most operationally broad; identity/access management, incident response, vulnerability management, and hardening are all high-frequency; candidates with operational security experience have a natural advantage |
| 5.0: Security Program Management & Oversight | 20% | Often underestimated; GRC frameworks, risk quantification, privacy regulations (GDPR, CCPA, HIPAA), and third-party risk management require dedicated study; many candidates find this the least familiar domain |
Key Concepts and Technical Areas in Depth
Certain conceptual areas are tested with particularly high frequency across Security+ exam domains. The following sections provide deeper coverage of the highest-priority technical areas — those that appear most consistently in Security+ exam questions and which candidates most commonly struggle with.
Cryptography: Algorithms, Protocols, and Applications
| Item | Detail |
|---|---|
| Symmetric Encryption | Same key encrypts and decrypts; fast; suitable for bulk data encryption; key exchange is the primary challenge. Algorithms: AES (Advanced Encryption Standard — 128, 192, 256-bit keys; current standard; modes include ECB, CBC, CTR, GCM), DES (56-bit; deprecated — too weak), 3DES (triple DES; 168-bit effective; deprecated by NIST 2023), Blowfish/Twofish (less common alternatives), RC4 (stream cipher; deprecated — used in WEP; broken). |
| Asymmetric Encryption | Public/private key pair; public key encrypts, private key decrypts; solves key distribution; computationally expensive. Algorithms: RSA (Rivest–Shamir–Adleman; 2048-bit minimum; used for key exchange and digital signatures), ECC (Elliptic Curve Cryptography; equivalent security with smaller keys; used in ECDH and ECDSA; preferred for constrained environments), Diffie-Hellman (DH/ECDH; key exchange only — not encryption; enables Perfect Forward Secrecy in TLS). |
| Hashing | One-way function; fixed-length output; collision resistant; cannot be reversed. Uses: password storage, data integrity, digital signatures. Algorithms: MD5 (128-bit output; deprecated — collision attacks; still seen in legacy systems), SHA-1 (160-bit; deprecated — collision attacks demonstrated), SHA-256 / SHA-2 family (current standard; 256, 384, 512-bit variants), SHA-3 (alternative construction; resistant to SHA-2 weaknesses), bcrypt/scrypt/Argon2 (password-specific; intentionally slow with salt; recommended for credential storage). |
| Digital Signatures | Sender signs message hash with private key; recipient verifies with sender’s public key; provides authentication, integrity, non-repudiation. Standard: RSA-PSS or ECDSA; used in code signing, S/MIME email, PDF signing, TLS certificate validation, and software update authentication. |
| PKI Components | Certificate Authority (CA) — trusted entity that signs certificates; Root CA (offline; signs intermediate CAs); Intermediate CA (online; signs end-entity certificates); Certificate (X.509 format; contains: subject, issuer, public key, validity period, serial number, signature); Certificate Revocation List (CRL) and OCSP (Online Certificate Status Protocol) for revocation checking; Certificate Signing Request (CSR); trust chain / chain of trust. Know the difference between self-signed and CA-signed certificates. |
| TLS/SSL | Transport Layer Security (TLS) secures network communications — HTTPS, email (SMTPS, IMAPS), and application traffic. TLS 1.3 is current standard; TLS 1.0 and 1.1 deprecated; SSL (all versions) deprecated. TLS handshake: establishes cipher suite, authenticates server (and optionally client), negotiates session keys using asymmetric cryptography, then switches to symmetric encryption for bulk data transfer. Perfect Forward Secrecy (PFS): ephemeral key exchange means past sessions cannot be decrypted if long-term keys are later compromised. |
| Common Use Cases for Cryptographic Algorithms | HTTPS/TLS: RSA or ECDH for key exchange + AES for data; SSH: ECDH + AES; VPN (IPSec): DH for key exchange + AES for data + HMAC for integrity; Email (S/MIME): RSA + AES + SHA; PGP/GPG: RSA or ECC + AES + SHA; Password storage: bcrypt/Argon2 with salt; Code signing: RSA or ECDSA; Disk encryption (BitLocker/FileVault/LUKS): AES-256. |
| Steganography | Hiding data within another file (image, audio, video) without visible detection; different from encryption — the existence of the message is hidden, not just the content. Used by attackers for data exfiltration (hiding stolen data in innocuous files) and for covert communication. Detection: steganalysis tools; unusual file size increases; statistical analysis of pixel values. |
Network Protocols, Ports, and Security Relevance
Security+ heavily tests knowledge of specific protocols, their default ports, whether they transmit data in plaintext or encrypted form, and their secure alternatives. Candidates must memorize the following:
| Protocol | Port(s) | Security Notes |
|---|---|---|
| HTTP | 80 TCP | Plaintext web traffic; always replace with HTTPS (443); susceptible to MitM, sniffing, session hijacking |
| HTTPS | 443 TCP | HTTP encrypted with TLS; current standard for all web traffic; HSTS enforces HTTPS-only |
| FTP | 20/21 TCP | Plaintext file transfer; credentials transmitted in clear-text; replace with SFTP (22) or FTPS (990) |
| SFTP | 22 TCP | Secure file transfer over SSH; fully encrypted; preferred alternative to FTP |
| SSH | 22 TCP | Encrypted remote shell; replaces Telnet; used for remote administration, tunnelling |
| Telnet | 23 TCP | Plaintext remote shell; completely deprecated; credentials and all traffic in plaintext |
| SMTP | 25 TCP | Mail transfer; plaintext by default; port 587 (STARTTLS) or 465 (SMTPS) for encrypted email submission |
| DNS | 53 UDP/TCP | Domain resolution; plaintext by default; DNSSEC adds integrity; DoH (443) and DoT (853) add encryption |
| DHCP | 67/68 UDP | IP address assignment; no authentication — vulnerable to rogue DHCP servers; DHCP snooping mitigates |
| TFTP | 69 UDP | Trivial FTP; no authentication; plaintext; used for firmware updates; restrict to isolated networks |
| HTTP Alt / Squid | 8080 TCP | Web proxy port; commonly used for HTTP proxy and web caching |
| POP3 | 110 TCP | Mail retrieval; plaintext; deprecated — use POP3S (995) with TLS |
| POP3S | 995 TCP | POP3 encrypted with TLS |
| IMAP | 143 TCP | Mail retrieval with server-side storage; plaintext; use IMAPS (993) with TLS |
| IMAPS | 993 TCP | IMAP encrypted with TLS |
| SMTPS | 465 TCP | SMTP encrypted with TLS for email submission |
| LDAP | 389 TCP | Directory queries; plaintext; replace with LDAPS (636) for encrypted directory traffic |
| LDAPS | 636 TCP | LDAP encrypted with TLS |
| SMB | 445 TCP | Windows file sharing; historically vulnerable (EternalBlue/WannaCry); restrict to internal networks |
| RDP | 3389 TCP | Remote Desktop Protocol; frequently targeted; use NLA, strong credentials, MFA; restrict to VPN |
| SNMP v1/v2 | 161/162 UDP | Network management; community strings transmitted in plaintext; use SNMPv3 with authentication and encryption |
| SNMPv3 | 161/162 UDP | SNMP with authentication and encryption; preferred for all network management |
| NTP | 123 UDP | Time synchronization; monlist attacks possible; NTPsec and authentication mitigate |
| Syslog | 514 UDP | Log forwarding; plaintext UDP; use TLS syslog (6514) for secure log transmission |
| BGP | 179 TCP | Internet routing; BGP hijacking attacks; RPKI adds route origin validation |
| RIP | 520 UDP | Legacy routing protocol; unauthenticated; replaced by OSPF/BGP in modern networks |
Identity and Access Management: Protocols and Concepts
| Item | Detail |
|---|---|
| Authentication vs. Authorization vs. Accounting | Authentication: verifying identity (who are you?); Authorization: determining what access is permitted (what can you do?); Accounting: tracking what was done (what did you do?). Together: AAA. Implemented by RADIUS and TACACS+ in network access control scenarios. |
| Multi-Factor Authentication (MFA) | Combining two or more independent authentication factors: Type 1 (something you know — password, PIN, passphrase), Type 2 (something you have — hardware token, smart card, authenticator app OTP, phone), Type 3 (something you are — biometric: fingerprint, retina, voice, gait). 2FA uses exactly two factors. MFA uses two or more. Two-step verification (e.g., password + SMS code from the same account) is not true MFA. Phishing-resistant MFA: FIDO2/WebAuthn hardware keys (YubiKey, Google Titan) — cryptographically bound to the site origin. |
| Access Control Models | Discretionary Access Control (DAC): resource owners control access; flexible but hard to manage at scale; default UNIX/Windows file system model. Mandatory Access Control (MAC): OS enforces access based on labels/classifications; subjects cannot override; used in government/military systems (SELinux). Role-Based Access Control (RBAC): permissions assigned to roles; users assigned to roles; standard enterprise model. Attribute-Based Access Control (ABAC): access decisions based on multiple attributes — user, resource, environment; most flexible and granular. Rule-Based Access Control: access decisions based on rules in an ACL; commonly used in firewall rule sets. |
| Federation and SSO | Single Sign-On (SSO): authenticate once, access multiple applications without re-authenticating. SAML 2.0 (Security Assertion Markup Language): XML-based federation protocol; used for enterprise SSO and web SSO; supports browser-based authentication; IdP (Identity Provider) issues assertions consumed by SP (Service Provider). OAuth 2.0: authorization framework (not authentication); delegates access without sharing credentials; used by ‘Sign in with Google/Facebook’; defines access scopes. OpenID Connect (OIDC): authentication layer built on OAuth 2.0; adds ID token for user identity; used with OAuth for complete authentication + authorization. Kerberos: ticket-based authentication for Windows/AD environments; TGT (Ticket Granting Ticket) from KDC; used for network service authentication in enterprise. RADIUS: centralized authentication for network access (VPN, Wi-Fi); used with 802.1X; encrypts password only. TACACS+: Cisco-developed; encrypts entire payload; separates authentication, authorization, and accounting; preferred for device administration. |
| Privileged Access Management (PAM) | Controls for managing privileged accounts (domain administrators, root accounts, service accounts): password vaulting (credentials stored and rotated automatically; never known to users), session recording (all privileged sessions recorded for audit), just-in-time (JIT) access (privileges granted for specific tasks, specific duration; revoked automatically), and privileged account monitoring (alerts on anomalous privileged activity). Key PAM products: CyberArk, BeyondTrust, Delinea, HashiCorp Vault. |
| Zero Trust Identity Principles | Never trust, always verify: no implicit trust based on network location or previous authentication. Every access request verified against identity, device health, location, and risk signals. Continuous authorization: trust is re-evaluated during active sessions, not only at login. Least privilege: minimum permissions granted for the specific task. Microsegmentation: network access limited to specific resources required; no broad network trust. |
Threat Actors and Attack Techniques
| Item | Detail |
|---|---|
| Threat Actor Types | Nation-state actors: government-sponsored; APT methodology; sophisticated tools; espionage, sabotage, IP theft objectives; well-resourced and patient. Organized criminal groups: financially motivated; ransomware, fraud, credential theft; professional operations. Hacktivists: ideologically motivated; DDoS, defacement, data disclosure. Insider threats: current/former employees; malicious (theft, sabotage) or unintentional (misconfiguration, phishing susceptibility). Script kiddies: low skill; using existing tools without deep understanding; opportunistic. Competitor: corporate espionage; targeted IP theft. Shadow IT: employees deploying unauthorized technology; unintentional security risk. |
| Phishing Attack Variants | Phishing: mass-distribution email impersonating legitimate senders to harvest credentials or deliver malware. Spear-phishing: targeted phishing with personalized content based on research. Whaling: spear-phishing targeting senior executives (CEO, CFO). Vishing: voice phishing via phone calls — impersonating IT support, government agencies, banks. Smishing: SMS-based phishing — malicious links via text message. Business Email Compromise (BEC): impersonating executives or vendors to authorize wire transfers or redirect payments. Pharming: redirecting users to fake websites via DNS manipulation — without clicking a phishing link. Pretexting: creating a fabricated scenario to manipulate targets (impersonating IT support, HR, auditors). |
| Malware Categories | Ransomware: encrypts files and demands payment for decryption keys; often combined with data exfiltration for double extortion; RaaS (Ransomware-as-a-Service) model. Trojan: malicious software disguised as legitimate software; does not self-replicate; creates backdoors. Worm: self-replicating malware that spreads across networks without user interaction; exploits vulnerabilities. Virus: attaches to legitimate programs; requires user action to spread; file infectors, macro viruses. Rootkit: conceals itself and other malware within the OS or firmware; difficult to detect and remove; operates at kernel level. Spyware/Keylogger: silently monitors and exfiltrates user activity, credentials, or keystrokes. Backdoor: covert persistent access mechanism installed by malware or attackers. Fileless malware: executes in memory without writing to disk; uses legitimate tools (PowerShell, WMI); evades file-based antivirus. Logic bomb: dormant malicious code activated by a specific trigger (date, event, condition). Adware: displays unwanted advertisements; often bundled with free software; may track browsing. |
| Network Attacks | DoS (Denial of Service): single source; resource exhaustion or disruption. DDoS (Distributed DoS): multiple coordinated sources (botnet); volumetric (bandwidth flooding — UDP flood, DNS amplification, NTP amplification), protocol (SYN flood, Ping of Death, Smurf), application layer (HTTP flood, Slowloris). On-path attack (MitM): intercepting and potentially modifying traffic between two parties; ARP poisoning, evil twin Wi-Fi, SSL stripping. Replay attack: capturing and re-transmitting valid authentication tokens or transactions; prevented by nonces and timestamps. DNS attacks: DNS poisoning/spoofing (redirecting legitimate domains to malicious IPs), DNS hijacking (modifying DNS records), DNS amplification (DDoS reflection). VLAN hopping: switch spoofing or double tagging to access VLANs beyond authorized scope. MAC flooding: overwhelming a switch’s MAC address table to cause it to broadcast all traffic (fail-open mode, enabling sniffing). |
| Application Attacks | SQL Injection (SQLi): inserting malicious SQL code into input fields; reads, modifies, or deletes database data; prevented by parameterized queries and input validation. Cross-Site Scripting (XSS): injecting malicious scripts into web pages viewed by other users; stored (persisted in database), reflected (in URL parameters), DOM-based; prevented by output encoding. Cross-Site Request Forgery (CSRF): tricking authenticated users into executing unintended actions on a web application; prevented by CSRF tokens and SameSite cookie attribute. Server-Side Request Forgery (SSRF): causing the server to make requests to internal resources on behalf of the attacker; cloud metadata service exploitation. Buffer overflow: writing beyond allocated memory buffer; can cause crashes or arbitrary code execution; prevented by input validation, ASLR, DEP/NX, stack canaries. Directory traversal: using path traversal sequences (../../) to access files outside the web root; prevented by input sanitization and file access controls. Privilege escalation: exploiting vulnerabilities or misconfigurations to gain higher-level access than authorized. |
Security Tools and Technologies
Security+ tests knowledge of a wide range of security tools and technologies — both in terms of their function and their appropriate application to specific security problems. Candidates must understand which tool addresses which security need, how to interpret tool outputs in scenario questions, and the strengths and limitations of each tool category.
Detection and Monitoring Tools
| Item | Detail |
|---|---|
| SIEM (Security Information & Event Management) | Aggregates and correlates log data from across the environment — endpoints, network devices, servers, cloud services, identity systems — and applies rules and analytics to generate security alerts. Provides central visibility, compliance reporting, and historical investigation capability. Key products: Microsoft Sentinel, Splunk, IBM QRadar, LogRhythm, Elastic SIEM. Security+ candidates must understand log sources, correlation rule concepts, and how to interpret SIEM alerts. |
| IDS / IPS | Intrusion Detection System (IDS): monitors network traffic or host activity for attack signatures or anomalies; generates alerts but does not block. Intrusion Prevention System (IPS): actively blocks detected threats in addition to alerting. Signature-based: matches known attack patterns; fast but cannot detect novel attacks. Anomaly-based (behavioral): establishes baseline, flags deviations; detects novel attacks but higher false positive rate. Network-based (NIDS/NIPS): monitors network traffic. Host-based (HIDS/HIPS): monitors activity on individual endpoints. False positive (legitimate activity flagged as malicious) and false negative (malicious activity not detected) are key IDS concepts. |
| EDR / XDR | Endpoint Detection and Response (EDR): continuous endpoint monitoring, behavioral threat detection, investigation tools, and response capability (process kill, isolation). Examples: CrowdStrike Falcon, Microsoft Defender for Endpoint, SentinelOne, Carbon Black. Extended Detection and Response (XDR): correlates telemetry from endpoints, networks, email, identity, and cloud into unified detection and response platform; reduces siloed alert context. |
| Vulnerability Scanners | Automated tools that identify known vulnerabilities (CVEs), misconfigurations, and missing patches. Credentialed scans (with authentication) provide deeper visibility — patch status, software versions, service configuration; unauthenticated scans show only what is visible from the network. Key tools: Nessus, OpenVAS/Greenbone, Qualys, Nexpose, Rapid7. CVSS score output — understand 0–10 severity scale, base vs. environmental vs. temporal scores. |
| SOAR (Security Orchestration, Automation & Response) | Automates repetitive SOC workflows through playbooks: alert enrichment, threat intelligence lookup, indicator blocking, ticket creation, analyst notification. Reduces manual workload and mean time to respond. Works alongside SIEM — SIEM generates alerts; SOAR automates the response workflow. Examples: Splunk SOAR (Phantom), Palo Alto XSOAR, Microsoft Sentinel playbooks, ServiceNow SecOps. |
| Threat Intelligence Platforms | Aggregate, normalize, and operationalize threat intelligence from commercial feeds, open-source (VirusTotal, AlienVault OTX, MISP), and government sources (CISA, ISAC feeds). Produce IoCs (Indicators of Compromise — IP addresses, domain names, file hashes, email addresses) that are distributed to blocking controls. STIX (Structured Threat Information Expression) and TAXII (Trusted Automated eXchange of Intelligence Information) are the standard formats and transport protocols for threat intelligence sharing. |
Network Security Technologies
| Item | Detail |
|---|---|
| Firewall Types | Packet filter (stateless): inspects individual packets against ACL rules; no session awareness; fast but limited. Stateful inspection: tracks connection state; understands TCP handshake; more intelligent than packet filter. Next-Generation Firewall (NGFW): application-layer inspection, user-identity awareness, SSL/TLS inspection, integrated IPS, threat intelligence feeds; most capable. Unified Threat Management (UTM): NGFW plus additional security services (antivirus, web filtering, email security) in a single appliance; common in SMB environments. Web Application Firewall (WAF): inspects HTTP/S traffic; protects web applications against OWASP Top 10 attacks (SQLi, XSS, CSRF); deployed in front of web applications. |
| Network Access Control (NAC) | Enforces security policy compliance for devices before granting network access: checking patch status, antivirus presence, OS version, certificates. IEEE 802.1X: port-based NAC; authenticates devices/users via RADIUS before granting switch or Wi-Fi access; uses EAP (Extensible Authentication Protocol) methods — EAP-TLS (certificate-based; strongest), PEAP (username/password protected by TLS tunnel), EAP-TTLS. Quarantine VLAN: non-compliant devices placed in isolated VLAN with access only to remediation resources. |
| VPN Technologies | Site-to-site VPN: connects two networks permanently; replaces dedicated WAN circuits; uses IPSec or TLS. Remote access VPN: individual user connects to corporate network from remote location; full tunnel (all traffic through VPN) vs. split tunnel (only corporate traffic through VPN; internet traffic goes direct). SSL/TLS VPN: browser-based or thin-client; operates over HTTPS port 443; easier to deploy through firewalls. IPSec VPN: tunnel mode (entire packet encrypted; used for site-to-site) vs. transport mode (payload only encrypted; used for host-to-host). Always-on VPN: automatically connects when device leaves corporate network. ZTNA (Zero Trust Network Access): replaces VPN with application-specific access based on continuous identity and device verification. |
| Wireless Security | WEP (Wired Equivalent Privacy): 64/128-bit RC4 encryption; completely broken — never use. WPA (Wi-Fi Protected Access): TKIP encryption; deprecated. WPA2-Personal: AES-CCMP encryption; passphrase-based; vulnerable to offline dictionary attacks on captured 4-way handshake. WPA2-Enterprise: 802.1X authentication; each user has unique credentials; much stronger than personal mode. WPA3-Personal: SAE (Simultaneous Authentication of Equals) replaces PSK; resistant to offline dictionary attacks; forward secrecy. WPA3-Enterprise: 192-bit security mode. Evil twin attack: rogue AP with same SSID as legitimate AP; captures credentials or traffic. De-authentication attack: forces clients to reconnect; enables handshake capture. Captive portals: redirect unauthenticated clients to authentication page; common in guest Wi-Fi. |
| DNS Security | DNSSEC: cryptographic signing of DNS records; verifies record integrity and authenticity; prevents DNS cache poisoning. DNS over HTTPS (DoH): encrypts DNS queries within HTTPS (port 443); prevents ISP eavesdropping and DNS manipulation; implemented in modern browsers. DNS over TLS (DoT): encrypts DNS queries over TLS (port 853); more explicit separation from web traffic than DoH. DNS sink holing: redirecting malicious domain resolution to a controlled IP — prevents malware C2 communication; used in enterprise security and law enforcement. Split-horizon DNS: different DNS responses for internal vs. external queries — prevents internal naming disclosure. |
| Load Balancers and Proxies | Load balancer distributes traffic across multiple servers for availability and performance; also provides a security layer — hides individual server addresses; can perform SSL termination and provide some WAF functionality. Forward proxy: client-side proxy; intercepts outbound client requests; enables URL filtering, content inspection, SSL inspection, and anonymous browsing. Reverse proxy: server-side proxy; intercepts inbound requests to servers; hides server infrastructure; provides load balancing, SSL termination, and WAF protection. Transparent proxy: intercepts traffic without client configuration (no proxy settings required); used for content filtering and monitoring. |
Incident Response and Digital Forensics
Incident response and digital forensics are among the most heavily tested operational topics on the Security+ exam. Candidates must understand the lifecycle of incident response, specific forensic techniques and principles, and the legal and procedural considerations that govern how digital evidence is collected, preserved, and analyzed.
NIST Incident Response Lifecycle (SP 800-61)
| Item | Detail |
|---|---|
| Phase 1: Preparation | Establishing IR capability before incidents occur: developing and testing IR plans and playbooks, training the IR team, deploying detection tooling (SIEM, EDR), establishing communication procedures, identifying key contacts (legal, communications, executive escalation), and preparing evidence collection tools. Preparation is the highest-leverage investment — everything that makes response faster and more effective happens here. |
| Phase 2: Detection and Analysis | Identifying that a security incident has occurred and characterizing its scope, impact, and severity: analyzing alerts from security tools, reviewing logs, correlating events across multiple data sources, establishing the timeline of the incident, identifying affected systems and data, and classifying the incident by type and severity. Indicators of Compromise (IoCs) — specific technical artifacts indicating compromise — are identified and documented during this phase. |
| Phase 3: Containment | Limiting the spread and impact of the incident while preserving evidence: short-term containment (isolating affected systems from the network, blocking malicious IPs, disabling compromised accounts), evidence preservation (forensic imaging of affected systems before remediation), and long-term containment (implementing more sustainable controls while full remediation is prepared — enhanced monitoring, network segmentation adjustments, temporary access restrictions). |
| Phase 4: Eradication | Removing the root cause of the incident from the environment: eliminating malware, removing unauthorized accounts and persistence mechanisms, closing exploited vulnerabilities (patching, configuration correction), and validating that all attacker footholds have been removed. Incomplete eradication leads to re-compromise — thorough investigation of persistence mechanisms is essential before declaring eradication complete. |
| Phase 5: Recovery | Restoring affected systems and services to normal operation: rebuilding from clean backups or known-good images, validating system integrity before bringing systems back online, restoring data from backup, conducting post-restoration testing to confirm normal operation, and implementing enhanced monitoring for signs of re-compromise during the initial recovery period. |
| Phase 6: Post-Incident Activity (Lessons Learned) | Structured review of the incident to improve future capability: documenting the complete incident timeline, identifying what detection or prevention controls failed, determining what controls could have caught the incident earlier, identifying process improvements, and updating playbooks, policies, and controls based on findings. Lessons learned meetings should include all stakeholders and result in a written report with tracked remediation actions. |
Digital Forensics Principles
| Item | Detail |
|---|---|
| Order of Volatility | The sequence in which digital evidence should be collected — most volatile (most easily lost) first: CPU registers and cache, RAM/system memory, active network connections and processes, running processes, temporary file system data, disk (hard drive/SSD), remote logging and monitoring data, physical configuration and network topology, archival media. Collecting memory before disk is critical — active malware processes, encryption keys, network connections, and user activity are only in RAM. |
| Chain of Custody | The documented record of who collected, handled, transferred, and accessed evidence from the point of collection through to court presentation. Every transfer of evidence must be documented and signed. Purpose: demonstrates that evidence has not been tampered with; required for evidence to be admissible in legal proceedings. Chain of custody documentation includes: who collected it, when and where, how it was packaged and sealed, every person who accessed it subsequently, and storage conditions. |
| Evidence Integrity | Forensic copies of digital evidence must be bit-for-bit identical to the original. Hash verification (MD5 or SHA-256 of the original and the forensic copy) proves the copy is identical and that evidence has not been modified. Write blockers prevent inadvertent modification of evidence during imaging. FTK Imager, dd, and similar tools create forensic images with hash verification. |
| Legal Hold | A directive to preserve all potentially relevant data when litigation or investigation is reasonably anticipated. Suspends normal data retention and deletion policies for covered data. Failure to implement legal hold when required can result in spoliation of evidence — destruction of evidence after a duty to preserve arose — which can result in serious legal consequences. |
| Data Acquisition Types | Static acquisition: imaging a powered-off drive; most straightforward; complete bit-for-bit copy. Live acquisition: imaging a running system while powered on; necessary to capture volatile data (RAM, active connections); risk of evidence modification during collection. Logical acquisition: copies files and directories rather than raw sectors; faster but misses deleted files and slack space. Remote acquisition: imaging over a network; used when physical access is not possible. |
| Anti-Forensics Techniques (Attacker Perspective) | Attackers use anti-forensics to frustrate investigation: log clearing and timestamp manipulation, secure file deletion (overwriting files to prevent recovery), encryption of malicious files, fileless malware (no disk artifacts), steganography (hiding data in innocuous files), and covert communication channels. Understanding these techniques helps forensic investigators know where to look and what to expect. |
Governance, Risk, Compliance, and Privacy
Domain 5 (Security Program Management and Oversight) is frequently underestimated by candidates with strong technical backgrounds. Its content covers the governance and business dimensions of security — policy frameworks, risk management methodology, regulatory compliance, and privacy law — that are tested as heavily as technical topics in Domain 4. Candidates who skip or skim this domain consistently underperform.
Key Security Frameworks
| Item | Detail |
|---|---|
| NIST Cybersecurity Framework (CSF) 2.0 | Voluntary US framework for managing cybersecurity risk across six functions: Govern (security governance and risk management strategy — new in CSF 2.0), Identify (asset management, risk assessment), Protect (access control, security awareness, data security, resilience), Detect (continuous monitoring, anomaly detection), Respond (incident response, communications), Recover (recovery planning, improvement). Widely adopted as a risk management reference across all sectors globally. |
| NIST SP 800-53 | Comprehensive security and privacy control catalog for US federal information systems; provides controls across 20 control families; used as the basis for federal system authorization (ATO process under RMF). Mapped to CSF for organizations using both frameworks. |
| ISO/IEC 27001 | International standard for Information Security Management Systems (ISMS); certifiable against by third-party auditors; Plan-Do-Check-Act cycle; Annex A provides a control reference of 93 controls in 4 themes. Most widely recognized international security management standard; particularly important for European and multinational organizations. |
| CIS Controls (v8) | Center for Internet Security Controls; 18 control groups with 153 safeguards prioritized by security impact and implementation feasibility; Implementation Group 1 (IG1 — 56 safeguards) represents the minimum viable security for all organizations regardless of size. Highly practical and actionable; maps to NIST CSF and ISO 27001. |
| SOC 2 | AICPA audit standard for service organizations; evaluates controls relevant to Trust Services Criteria (TSC): Security (required), Availability, Processing Integrity, Confidentiality, Privacy (optional). Type I: controls designed correctly at a point in time. Type II: controls operated effectively over an audit period (typically 6–12 months). Critical for SaaS providers and cloud services vendors in B2B relationships. |
| PCI DSS (Payment Card Industry Data Security Standard) | Mandatory for organizations that store, process, or transmit cardholder data; 12 requirements across network security, access control, encryption, monitoring, and vulnerability management; quarterly vulnerability scanning and annual penetration testing required; QSA (Qualified Security Assessor) performs formal assessments for Levels 1 and 2 merchants. |
Risk Management Concepts
| Item | Detail |
|---|---|
| Risk Assessment: Qualitative vs. Quantitative | Qualitative: uses relative scales (High/Medium/Low; 1–5 ratings) for likelihood and impact; faster, accessible, subjective. Quantitative: uses financial values — Asset Value (AV), Exposure Factor (EF), Single Loss Expectancy (SLE = AV × EF), Annualized Rate of Occurrence (ARO), Annualized Loss Expectancy (ALE = SLE × ARO), and safeguard value (ALE before – ALE after – annual safeguard cost). Security+ candidates must be able to calculate SLE and ALE from given values. |
| Risk Treatment Options | Risk Mitigation (Accept + Reduce): implementing controls to reduce likelihood or impact — most common response for significant risks. Risk Transfer: shifting financial risk to a third party — cyber insurance, contractual indemnification. Risk Avoidance: discontinuing the risk-creating activity — cessation of a business process or service. Risk Acceptance: formally acknowledging and accepting the residual risk — documented, time-bounded, with executive sign-off; appropriate only when treatment cost exceeds expected loss. |
| Threat Modeling | Structured process for identifying potential security threats to a system or application during design: STRIDE model (Spoofing identity, Tampering with data, Repudiation, Information disclosure, Denial of service, Elevation of privilege); PASTA (Process for Attack Simulation and Threat Analysis); attack trees. Goal: identify and address threats at design time when remediation cost is lowest. |
| Business Impact Analysis (BIA) | Identifies critical business functions, their dependencies on IT systems, and the financial and operational impact of disrupting them at various time points. Outputs: Maximum Tolerable Downtime (MTD) / Maximum Tolerable Period of Disruption (MTPD), Recovery Time Objective (RTO — how quickly systems must be restored), Recovery Point Objective (RPO — maximum acceptable data loss measured in time), Mean Time to Recovery (MTTR), Mean Time Between Failures (MTBF). These metrics drive DR architecture and backup strategy decisions. |
| Security Policy Types | Acceptable Use Policy (AUP): defines permissible and prohibited uses of organizational technology assets. Data Handling Policy: specifies how data must be classified, stored, transmitted, retained, and destroyed by classification level. Password Policy: minimum length, complexity, history, expiration, and lockout requirements. BYOD (Bring Your Own Device) Policy: conditions under which personal devices may access corporate resources; MDM/MAM requirements. Clean Desk Policy: requirements for securing sensitive materials when workstations are unattended. Social Media Policy: guidance on organizational information disclosure on public platforms. Incident Response Policy: defines what constitutes an incident, reporting requirements, and response authority. |
Privacy Regulations Tested on Security+
| Item | Detail |
|---|---|
| GDPR (General Data Protection Regulation) | EU regulation governing personal data of EU residents; applies to any organization processing EU resident data regardless of location. Key provisions: lawful basis for processing, data minimization, purpose limitation, data subject rights (access, rectification, erasure, portability, restriction, objection), data breach notification within 72 hours, Data Protection Officer (DPO) requirement for certain organizations, Data Protection Impact Assessment (DPIA) for high-risk processing, transfer restrictions for data leaving the EU/EEA. Fines: up to 4% of global annual turnover or €20 million. |
| CCPA / CPRA (California Consumer Privacy Act / Privacy Rights Act) | US state law (California) provides consumer data rights: right to know what data is collected, right to delete personal information, right to opt-out of data sale, right to non-discrimination for exercising rights. CPRA (2023) added: right to correct inaccurate information, right to limit use of sensitive personal information, and created the California Privacy Protection Agency. Often considered the US equivalent of GDPR for California residents. |
| HIPAA (Health Insurance Portability and Accountability Act) | US federal law protecting health information (PHI — Protected Health Information). Security Rule: administrative, physical, and technical safeguards for electronic PHI (ePHI). Privacy Rule: limitations on use and disclosure of PHI. Breach Notification Rule: notification to affected individuals, HHS, and media (for large breaches) within 60 days. Business Associate Agreements (BAA) required for all vendors with PHI access. Minimum necessary standard: only the minimum PHI necessary for the purpose should be used or disclosed. |
| SOX (Sarbanes-Oxley Act) | US federal law for publicly traded companies; Section 302 requires CEO/CFO certification of financial report accuracy; Section 404 requires internal controls over financial reporting assessment; Section 802 protects whistleblowers; implications for IT: access controls on financial systems, audit logging of all financial system access, change management controls, data integrity requirements for financial records. SOX compliance is enforced by the SEC and PCAOB. |
| Data Classification | Most organizations implement a 4-tier scheme: Public (no restrictions; openly available), Internal/Private (non-sensitive internal information; standard access controls), Confidential (sensitive business information; restricted access, encryption required), Restricted/Highly Confidential (most sensitive — PII, PHI, financial data, trade secrets; strict access controls, enhanced encryption, audit logging). Government classification: Unclassified, Controlled Unclassified Information (CUI), Confidential, Secret, Top Secret. |
Security+ Compared with Comparable Certifications
Security+ occupies the entry-to-intermediate tier of the cybersecurity certification landscape. Understanding its positioning relative to both foundational certifications (that precede it) and advanced certifications (that follow it) helps candidates plan their certification journey and helps employers understand the level of expertise the credential represents.
| Certification | Issuing Body | Level & Focus | Best Suited For |
|---|---|---|---|
| CompTIA Security+ | CompTIA | Entry-to-intermediate; vendor-neutral broad security baseline; DoD 8570 IAT Level II; no prerequisites required; 3-year renewal | IT professionals seeking first security credential; DoD/government IT workers; professionals moving from Network+ to security specialization; anyone needing DoD 8570 IAT II compliance |
| CompTIA Network+ | CompTIA | Foundational networking; recommended prerequisite for Security+; no security-specific content but network knowledge is essential for security | IT generalists building toward Security+; those without a strong networking foundation who need to understand routing, switching, protocols before tackling security |
| CompTIA CySA+ | CompTIA | Intermediate; security analytics and operations; threat detection, SIEM, vulnerability management, incident response; DoD 8570 CSSP Analyst | Security analysts, SOC Tier 1-2 professionals; those who have Security+ and want to deepen analytics and operations knowledge; natural next step after Security+ |
| CompTIA PenTest+ | CompTIA | Intermediate; penetration testing; vulnerability assessment, exploit execution, reporting; DoD 8570 CSSP Analyst | Security professionals focused on offensive security and penetration testing; complements Security+ with hands-on attack skills |
| CompTIA CASP+ | CompTIA | Advanced; enterprise security architecture; no exam score pass/fail — mastery demonstrated; DoD 8570 IASAE Level I and II | Senior security practitioners; enterprise security architects; those with 10+ years who want advanced technical (not management) credentials |
| CISSP | ISC2 | Advanced; management-oriented broad security; 8 domains; 5-year experience required; gold standard for senior security | Experienced professionals (5+ years) targeting CISO, security director, architect, and senior management roles; significant step up from Security+ in depth and experience requirements |
| CEH | EC-Council | Intermediate; ethical hacking / penetration testing; 20 domains covering attack lifecycle; DoD 8570 IAT Level II | Penetration testers, red teamers, offensive security professionals; complements Security+ with attack-focused methodology and tooling |
| GISF / GSEC | GIAC/SANS | Entry/Intermediate; SANS-curriculum aligned; GSEC is significantly more technical than Security+; expensive | Professionals completing SANS SEC courses; those wanting GIAC brand recognition; GSEC is considerably harder and more expensive than Security+ |
CompTIA Certification Pathway
| Item | Detail |
|---|---|
| IT Fundamentals (ITF+) | Entry point for non-IT professionals; covers basic IT concepts; not a career credential — a starting point for those with no IT background |
| A+ | Foundational IT support certification; hardware, operating systems, troubleshooting; recommended first professional certification for IT career entry |
| Network+ | Foundational networking; TCP/IP, network architecture, protocols, troubleshooting; recommended prerequisite for Security+ |
| Security+ | Baseline security credential; recommended after Network+ and 2 years IT experience; subject of this document |
| CySA+ / PenTest+ | Intermediate specializations following Security+: CySA+ for security analysis/operations; PenTest+ for penetration testing and vulnerability assessment |
| Cloud+ | Intermediate cloud technology certification; complements Security+ for cloud-focused roles |
| CASP+ (CompTIA Advanced Security Practitioner) | Advanced enterprise security; for senior practitioners; no associate/professional tier — directly follows Security+ and specializations at the advanced level |
| Linux+ | Intermediate Linux administration; complements Security+ for roles requiring Linux proficiency (most security roles benefit from Linux skills) |
Study Strategy and Exam Preparation
Security+ is an accessible but substantive certification that rewards structured preparation. Candidates with IT background and some security exposure typically require 2–3 months of dedicated preparation; those new to security or without networking foundation may need 4–6 months. The dual format (multiple-choice + PBQs) requires both conceptual study and hands-on practice — neither alone is sufficient.
Recommended Preparation Timeline
| Phase | Duration | Activities |
|---|---|---|
| Foundation Assessment | 1 week | Download the official CompTIA SY0-701 Exam Objectives document (free from CompTIA.org) — this is the authoritative exam blueprint. Take a free diagnostic practice test to identify current knowledge baseline. Identify knowledge gaps by domain. Assess hands-on tool familiarity (Wireshark, firewall configuration, basic Linux command line). |
| Domain Study | 6–10 weeks | Work through each domain systematically using the exam objectives as your guide. Use your chosen study guide alongside the objectives document. Take notes by domain, particularly on: protocol names and port numbers, cryptographic algorithms and their use cases, attack types and their mitigations, and acronyms. Complete 20–30 practice questions after each major section. |
| Lab Practice (Parallel) | 4–8 weeks (parallel with domain study) | Hands-on practice for PBQ topics: set up packet capture practice in Wireshark (analyze HTTP vs. HTTPS, identify scanning patterns); practice firewall rule configuration (pfSense or cloud security group); practice log analysis in a free SIEM tool; complete scenario-based exercises on TryHackMe (Security+ learning path); set up Kali Linux for basic tool familiarity (Nmap scanning, basic Metasploit concepts without exploitation). |
| Practice Exam Intensive | 2–3 weeks | Complete full-length (90-question) practice exams under timed conditions (90 minutes). Target 80%+ on practice exams before scheduling the real exam (Security+ scaled at 750/900 ≈ 83%). Analyze every incorrect answer — understand why the correct answer is correct. Review weak domains with focused re-study. Complete at least 3–5 full-length timed practice exams total. |
| Final Week Review | 1 week | No new material; consolidation only. Review acronym and port number lists. Review cryptographic algorithm decision tables. Review IR lifecycle phases and forensic principles. Verify test center logistics. Get adequate sleep before exam day — fatigue significantly impacts performance on scenario-based questions. |
Recommended Study Resources
| Item | Detail |
|---|---|
| CompTIA SY0-701 Official Exam Objectives | Free from CompTIA.org; the authoritative blueprint for the exam; every sub-topic listed in the objectives has appeared or will appear on the exam; read it thoroughly before studying and use it to verify coverage of all topics |
| CompTIA Security+ Study Guide (Mike Chapple & David Seidl) | Official CompTIA-endorsed study guide; comprehensive coverage of all domains; practice questions after each chapter; widely considered the gold standard reference for Security+ |
| CompTIA Security+ Get Certified Get Ahead (Darril Gibson / Mike Chapple) | A long-standing and highly regarded study guide known for its clear explanations, extensive practice questions, and exam-focused writing style; some candidates prefer this over the official guide |
| Professor Messer’s Security+ Course (Free) | Completely free, high-quality video course by Professor Messer specifically aligned to the Security+ exam objectives; available on YouTube and ProfessorMesser.com; supplementary course notes and practice exams also available (paid); widely recommended as a supplement to a primary study guide |
| Jason Dion’s Security+ Practice Exams (Udemy) | High-quality, exam-representative practice questions with detailed explanations; available on Udemy (frequently discounted); widely regarded as the best third-party practice exam resource for Security+ |
| TryHackMe (Security+ Learning Path) | Hands-on interactive platform with guided rooms covering Security+ domain topics in practical scenarios; essential for PBQ preparation; free and paid tiers; particularly valuable for candidates without hands-on security lab experience |
| CompTIA CertMaster Practice | Official CompTIA practice exam and adaptive learning tool; provides exam-representative questions with explanations; progress tracking by domain; available as a standalone purchase or bundled with study guide |
| Wireshark (Free) | Essential free tool for network traffic analysis practice; install and capture live traffic; open .pcap practice files from online resources; practice identifying protocols, analyzing HTTP vs. HTTPS, spotting scanning patterns and anomalies |
| Anki Flashcards (Free) | Spaced repetition flashcard application; create cards for port numbers, cryptographic algorithms, protocol comparisons, acronyms, and attack types; daily flashcard review over several weeks is the most efficient memorization strategy for Security + large vocabulary |
DoD 8570/8140 Compliance and Government Recognition
The US Department of Defense’s DoD Directive 8570.01-M (and its successor DoD Instruction 8140.03) establishes mandatory cybersecurity certification requirements for all military and civilian personnel, and contractors, who perform Information Assurance (IA) functions on DoD networks. Security+ is the most commonly held DoD 8570 certification and is the primary compliance pathway for IAT Level II — the most widely required baseline in the DoD contractor community.
Security+ in DoD 8570/8140 Roles
| Workforce Category | Level | Security+ Satisfies? |
|---|---|---|
| Information Assurance Technical (IAT) | Level I | No — IAT Level I satisfied by A+, CCNA-Security, Network+, SSCP, or Systems Security Certified Practitioner |
| Information Assurance Technical (IAT) | Level II | YES — Security+ is the primary certification for IAT Level II; also satisfied by CCNA Security, CySA+, GICSP, GSEC, SSCP |
| Information Assurance Technical (IAT) | Level III | No — IAT Level III requires CASP+, CISA, GCIH, GCED, CISSP, or CISSP-ISSAP/ISSEP/ISSMP |
| Information Assurance Management (IAM) | Level I | Yes — Security+ satisfies IAM Level I alongside CAP, GSLC, CISM, CISSP |
| Information Assurance System Architecture & Engineering (IASAE) | Level I | Yes — Security+ satisfies IASAE Level I (alone or with other certs in the category) |
| CSSP (Cyber Security Service Provider) Analyst | Primary | Yes — Security+ is approved for CSSP Analyst alongside CySA+, CEH, CFR, GCIH, GCIA |
| CSSP Infrastructure Support | Primary | Yes — Security+ is approved for CSSP Infrastructure Support |
Career Pathways, Roles, and Salary Ranges
Security+ is most valuable for professionals at the early-to-mid career stage in information security — those transitioning from general IT into security, those in entry-level security roles seeking to advance, and those in non-security IT roles who need to demonstrate security competency. It is also the mandatory baseline for a wide range of government and contractor positions, making it essential for public sector IT careers.
Roles That Value or Require Security+
| Item | Detail |
|---|---|
| Security Analyst (SOC Tier 1) | Entry-level SOC position; monitoring security alerts, triaging events, escalating incidents; Security+ is frequently listed as required or preferred; provides the vocabulary and conceptual foundation for understanding SIEM alerts, IDS/IPS signatures, and network anomalies |
| IT Security Specialist / Administrator | Mid-level role implementing and maintaining security controls: firewall management, endpoint security, patch management, access control, security monitoring; Security+ validates the broad knowledge set required for this generalist security role |
| Network Security Engineer | Design and implementation of network security infrastructure: firewall rules, IDS/IPS configuration, VPN management, wireless security, network segmentation; Security+ combined with Network+ provides the foundation; CCNA Security or CySA+ often follows |
| System Administrator (Security Focus) | System administrators with security responsibilities: hardening systems, managing access controls, implementing encryption, patch management, log review; Security+ is commonly listed in sysadmin job postings where security responsibilities are significant |
| Cloud Security Analyst | Entry-to-mid security roles in cloud environments: cloud security posture review, IAM configuration, cloud logging and monitoring, compliance checks; Security+ SY0-701’s expanded cloud content makes it more relevant for cloud roles than previous versions; CompTIA Cloud+ or AWS/Azure security certifications often follow |
| Penetration Tester (Junior) | Entry-level offensive security roles; vulnerability assessment, basic exploitation, report writing; Security+ provides the conceptual foundation but PenTest+ or CEH is typically required for dedicated pen test roles; Security+ can serve as the stepping stone |
| DoD / Government IT Security | All IAT Level II positions within DoD agencies and contractors require Security+ or equivalent; this represents a very large employment market for Security+ holders including the US military branches, NSA, DHS, and thousands of government contractors |
| Help Desk / IT Support (Security-Aware) | Help desk professionals with security awareness responsibilities: identifying and escalating suspicious activity, enforcing security policies, supporting security tool users; Security+ adds significant value in help desk roles that interface with security operations |
| Compliance / Risk Analyst (Junior) | Entry-level GRC roles: assisting with compliance assessments, maintaining risk registers, supporting audit activities; Security+ Domain 5’s GRC content directly prepares candidates for these roles; CRISC or CISA often follows for dedicated GRC careers |
Salary Impact and Market Value
Security+ consistently ranks among the top IT certifications associated with meaningful salary premiums. The following figures represent approximate ranges for US-based professionals in roles where Security+ is a primary or contributing qualification (2024–2025 data; significant variation by location, clearance status, organization size, and total experience):
| Role | Experience Level | Approximate US Salary Range |
|---|---|---|
| SOC Analyst Tier 1 | 0–2 years, Security+ | $50,000 – $75,000 |
| SOC Analyst Tier 2 | 2–5 years, Security+ + CySA+ | $70,000 – $100,000 |
| IT Security Specialist | 2–5 years, Security+ | $65,000 – $95,000 |
| Network Security Engineer | 3–6 years, Security+ + CCNA | $80,000 – $115,000 |
| System Administrator (Security Focus) | 3–6 years, Security+ | $70,000 – $100,000 |
| Cloud Security Analyst | 3–5 years, Security+ + Cloud cert | $80,000 – $120,000 |
| Junior Penetration Tester | 2–4 years, Security+ + PenTest+/CEH | $70,000 – $100,000 |
| DoD Contractor (Cleared, IAT II) | 2–5 years, Security+ + clearance | $85,000 – $130,000 (clearance premium) |
Continuing Education and Certification Renewal
CompTIA Security+ is valid for three years from the date of certification. The CompTIA Continuing Education (CE) program allows certification holders to renew without retaking the exam by accumulating 50 CE units within the 3-year certification period and paying the renewal fee. This requirement ensures that Security+ holders maintain current knowledge in a rapidly evolving field.
| Item | Detail |
|---|---|
| Total CE Units Required | 50 CE units over the 3-year certification period |
| Annual Renewal Fee | USD $50 per year (billed annually or as a single USD $150 payment for the 3-year cycle) |
| CE Submission Platform | CompTIA CE portal (https://ce.comptia.org); CE units submitted with supporting evidence for each activity |
| Retake Option | Candidates who prefer not to pursue CE renewal may retake the current exam before the certification expires; a passing score on the current exam renews the certification for another 3 years |
| Higher-Level Certification Renewal | Candidates who earn a higher-level CompTIA certification within the 3-year period automatically renew Security+; e.g., earning CySA+ or CASP+ renews Security+ as part of the same renewal action |
CE-Eligible Activities
| Activity | CE Units | Notes |
|---|---|---|
| Completing higher-level CompTIA exams (CySA+, PenTest+, CASP+, Cloud+) | Renews Security+ automatically | Earning any higher-level CompTIA cert automatically renews Security+ |
| Completing other vendor certifications (CISSP, CEH, CCNA Security, etc.) | Up to 20 CE units per certification | Other security certifications earn CE units; maximum varies by cert level |
| Attending security conferences (RSA, DEF CON, Black Hat, CompTIA events) | 1 CE unit per contact hour | Must document attendance; retain agendas or certificates of attendance |
| Completing security training courses (SANS, Cybrary, Coursera, LinkedIn Learning) | 1 CE unit per hour | Must be security-related content; retain certificates of completion |
| CompTIA CertMaster CE (Online self-paced course) | Varies by course; designed to cover full 50 CE requirement | CompTIA’s dedicated CE renewal course; covers all 50 CE units in one purchase |
| Webinars and virtual training (CompTIA and approved partners) | 1 CE unit per hour | CompTIA regularly offers free CE-eligible webinars for members |
| Publishing security articles, blog posts, or research | Up to 5 CE units per publication | Must be substantial, security-relevant content publicly available |
Exam Tips, Strategy, and Common Pitfalls
Knowledge Exam Tips
| Item | Detail |
|---|---|
| Read Questions Completely Before Looking at Answers | Security+ scenario questions often hinge on a single key word: ‘MOST likely’, ‘BEST mitigates’, ‘FIRST action’, ‘LEAST intrusive’. Identify the key qualifier before reading options. Misidentifying the question’s focus is the most common source of incorrect answers on scenario questions. |
| Eliminate Obviously Wrong Answers First | Most questions have two plausible answers and two clearly incorrect ones. Eliminating the clearly wrong options first often leaves a much more manageable choice between the remaining two. Never leave a question blank — there is no penalty for guessing. |
| Memorize Port Numbers and Protocol Pairings | A consistent category of Security+ questions presents a scenario and asks which port or protocol is being used or should be used. Create and regularly review a complete port number reference card. Particularly important: know plaintext vs. encrypted protocol pairs (HTTP/HTTPS, FTP/SFTP, Telnet/SSH, POP3/POP3S, IMAP/IMAPS, LDAP/LDAPS). |
| Know Cryptographic Algorithm Appropriate Use Cases | Questions frequently describe a requirement (fast, bulk encryption for database; key exchange with forward secrecy; password storage; signing software packages) and ask which algorithm or protocol satisfies it. Memorize the decision table: symmetric for bulk, asymmetric for key exchange and signatures, hashing for integrity, bcrypt/Argon2 for passwords, TLS for transport. |
| Understand Attack-to-Mitigation Pairings | Security+ tests both how attacks work and what defends against them — often in the same question. For each attack type (SQL injection, XSS, phishing, DoS, ARP poisoning), know the primary technical countermeasure. Common pairings: SQL injection → parameterized queries; XSS → output encoding; phishing → email authentication (SPF/DKIM/DMARC) + user training; ARP poisoning → dynamic ARP inspection; DoS → rate limiting + CDN. |
| Allocate PBQ Time Strategically | PBQs appear at the start of the exam. Spend a maximum of 5–7 minutes per PBQ before flagging and moving on. Many multiple-choice questions are faster to answer — completing them builds a time buffer for returning to flagged PBQs. Never let a single difficult PBQ consume more than 10 minutes. |
| Use Process of Elimination on Unfamiliar PBQs | If a PBQ scenario is unfamiliar, apply what you know: eliminate options that are clearly wrong, identify options that partially satisfy the scenario, and select the best available answer. Partial credit is available for PBQs — attempting an incomplete answer is better than leaving a PBQ blank. |
| Watch for ‘Except’ and Negative Questions | Some questions are phrased as ‘Which of the following is NOT…?’ or ‘All of the following EXCEPT…’ These require identifying the incorrect or inappropriate item rather than the correct one. Read these questions especially carefully — it is easy to misread the negative and select an answer that would be correct for a positive question. |
Common Preparation Pitfalls
| Item | Detail |
|---|---|
| Neglecting Domain 5 (GRC) | Candidates with technical backgrounds frequently allocate insufficient study time to Domain 5, treating it as ‘common sense’ content. The GRC domain is specifically designed to test knowledge of frameworks, risk calculation methodology, privacy law specifics (GDPR 72-hour notification, HIPAA 60-day notification), and compliance assessment types — none of which is intuitive without study. |
| Skipping Lab Practice | Candidates who prepare exclusively from books consistently struggle with PBQs. Even basic hands-on experience — reading a Wireshark packet capture, configuring a simple firewall rule, interpreting a vulnerability scan output — dramatically improves PBQ performance. At minimum, complete 10–15 hours of hands-on practice on TryHackMe or a local lab environment. |
| Memorizing Without Understanding | Security+ has a large vocabulary of technical terms, acronyms, and protocol names. Candidates who memorize definitions without understanding the underlying concept fail on application questions where the term appears in an unfamiliar context. Study definitions alongside the ‘why’, why does this protocol exist, what problem does it solve, what are its limitations? |
| Using Outdated Study Materials | Materials written for SY0-601 are significantly different from SY0-701, particularly in cloud security, zero trust, AI/automation, and GRC content. Using outdated materials risks studying content that no longer appears on the exam while missing new content that does. Verify that all materials are explicitly aligned to SY0-701. |
| Scheduling the Exam Too Early | Many candidates schedule their exam date based on target dates rather than actual readiness. The most reliable readiness indicator is consistently scoring 80%+ on full-length practice exams under timed conditions. Do not schedule the exam until practice exam performance demonstrates genuine readiness. |
| Ignoring Acronyms | Security+ uses a very large number of acronyms — many of which are tested in questions where the acronym appears without expansion. Create a comprehensive acronym reference from the exam objectives and study it regularly. CompTIA provides an acronym list as part of the exam objectives document. |
Conclusion
CompTIA Security+ SY0-701 represents the essential baseline credential for the cybersecurity profession — a comprehensive, vendor-neutral certification that validates the knowledge and practical skills required to begin and advance an information security career.
The certification’s five-domain structure — General Security Concepts, Threats and Vulnerabilities, Security Architecture, Security Operations, and Security Program Management — reflects the full scope of modern security practice. Security+ does not make a security expert; it establishes the conceptual foundation, technical vocabulary, and operational awareness that make subsequent learning, experience, and specialization far more productive. Professionals who earn Security+ and then invest in hands-on experience and advanced certifications (CySA+, PenTest+, CISSP, CEH) consistently advance faster than those who pursue advanced credentials without this foundational grounding.
The SY0-701 update’s emphasis on cloud-native security, zero trust architecture, AI-driven threats, and an expanded governance and compliance framework reflects the contemporary security landscape with unusual accuracy. Candidates who prepare thoroughly for SY0-701 are not merely preparing for an exam — they are building the security knowledge model that serves their professional practice in the current threat environment.
For organizations hiring entry-to-mid security talent, Security+ provides a reliable baseline signal. It is not a guarantee of operational competency — the practical exam component cannot fully substitute for real-world experience — but it does confirm that a candidate has invested in systematic security education and has demonstrated knowledge across the breadth of security domains that effective security practice requires. Combined with a rigorous hiring process that assesses practical skills through technical interviews and scenario exercises, Security+ certification is a valuable and reliable hiring filter.
Security+ Quick Reference Glossary
| Item | Detail |
|---|---|
| AAA | Authentication, Authorization, and Accounting — the three components of access control; implemented by RADIUS and TACACS+. |
| ALE | Annualized Loss Expectancy — expected annual financial loss from a risk: ALE = SLE × ARO. |
| ARO | Annualized Rate of Occurrence — expected frequency of a threat event per year. |
| BIA | Business Impact Analysis — assessment of the operational and financial impact of disrupting critical business functions. |
| BYOD | Bring Your Own Device — policy governing personal device use for business purposes. |
| CAT | Computerized Adaptive Testing — not used in Security+ (fixed-form exam); contrast with CISSP which uses CAT. |
| CIA Triad | Confidentiality, Integrity, Availability — the foundational model of information security objectives. |
| CSPM | Cloud Security Posture Management — tools that assess and enforce security best practices in cloud environments. |
| CVSS | Common Vulnerability Scoring System — standardized 0–10 severity scoring for vulnerabilities. |
| DoD 8570 | US Department of Defense directive mandating cybersecurity certification for IA roles; Security+ satisfies IAT Level II. |
| EDR | Endpoint Detection and Response — continuous endpoint monitoring and threat detection/response capability. |
| FPR / TPR | False Positive Rate / True Positive Rate — key metrics for evaluating IDS/IPS detection accuracy. |
| IoC | Indicator of Compromise — technical artifacts (IP, hash, domain, email) indicating a system has been compromised. |
| MFA | Multi-Factor Authentication — authentication, requiring two or more independent factors (Type 1/2/3). |
| MTTR / MTBF | Mean Time to Recovery / Mean Time Between Failures — availability and reliability metrics. |
| NAC | Network Access Control — enforces device security compliance before granting network access; uses 802.1X. |
| PBQ | Performance-Based Question — hands-on scenario question in Security+ exam; tests applied skills. |
| RBAC | Role-Based Access Control — permissions assigned to roles; users assigned to roles; standard enterprise model. |
| RPO / RTO | Recovery Point Objective (maximum data loss) / Recovery Time Objective (maximum downtime) — DR design metrics. |
| SIEM | Security Information and Event Management — centralized log aggregation, correlation, and alerting platform. |
| SOAR | Security Orchestration, Automation and Response — automated security workflow execution. |
| SLE | Single Loss Expectancy — expected financial loss from a single threat occurrence: SLE = AV × EF. |
| ZTNA | Zero Trust Network Access — replaces VPN with application-specific access based on continuous verification. |