CompTIA Security+ SY0-701 Exam Objectives
The CompTIA Security+ SY0-701 exam covers 28 objectives across five domains. Here is the full list, with each domain’s exam weight and a link to free practice questions for it. Use it as a checklist: study every objective, then test yourself. Free, no account.
Last updated August 2026
The five domains by exam weight
Domain 4, Security Operations, is the largest at 28%, so give it the most study time. Each domain links to free practice questions.
| Domain | Name | Objectives | Weight |
|---|---|---|---|
| 1 | General Security Concepts | 4 | 12% |
| 2 | Threats, Vulnerabilities, and Mitigations | 5 | 22% |
| 3 | Security Architecture | 4 | 18% |
| 4 | Security Operations | 9 | 28% |
| 5 | Security Program Management and Oversight | 6 | 20% |
Domain 1: General Security Concepts
12% of the exam- 1.1Compare and contrast various types of security controls
- 1.2Summarize fundamental security concepts
- 1.3Explain the importance of change management processes
- 1.4Explain the importance of using appropriate cryptographic solutions
Domain 2: Threats, Vulnerabilities, and Mitigations
22% of the exam- 2.1Compare and contrast common threat actors and motivations
- 2.2Explain common threat vectors and attack surfaces
- 2.3Explain various types of vulnerabilities
- 2.4Given a scenario, analyze indicators of malicious activity
- 2.5Explain the purpose of mitigation techniques used to secure the enterprise
Domain 3: Security Architecture
18% of the exam- 3.1Compare and contrast security implications of different architecture models
- 3.2Given a scenario, apply security principles to secure enterprise infrastructure
- 3.3Compare and contrast concepts and strategies to protect data
- 3.4Explain the importance of resilience and recovery in security architecture
Domain 4: Security Operations
28% of the exam- 4.1Given a scenario, apply common security techniques to computing resources
- 4.2Explain the security implications of proper hardware, software, and data asset management
- 4.3Explain various activities associated with vulnerability management
- 4.4Explain security alerting and monitoring concepts and tools
- 4.5Given a scenario, modify enterprise capabilities to enhance security
- 4.6Given a scenario, implement and maintain identity and access management
- 4.7Explain the importance of automation and orchestration related to secure operations
- 4.8Explain appropriate incident response activities
- 4.9Given a scenario, use data sources to support an investigation
Domain 5: Security Program Management and Oversight
20% of the exam- 5.1Summarize elements of effective security governance
- 5.2Explain elements of the risk management process
- 5.3Explain the processes associated with third-party risk assessment and management
- 5.4Summarize elements of effective security compliance
- 5.5Explain types of audits and assessments
- 5.6Given a scenario, implement security awareness practices
Security+ objectives FAQ
How many objectives are on the Security+ exam?
The CompTIA Security+ SY0-701 exam has 28 objectives across five domains: Domain 1 has 4, Domain 2 has 5, Domain 3 has 4, Domain 4 has 9, and Domain 5 has 6.
What are the five Security+ domains and their exam weights?
Domain 1 General Security Concepts (12%), Domain 2 Threats, Vulnerabilities, and Mitigations (22%), Domain 3 Security Architecture (18%), Domain 4 Security Operations (28%), and Domain 5 Security Program Management and Oversight (20%).
Which Security+ domain is the largest?
Domain 4, Security Operations, at 28% of the exam. It also has the most objectives, nine. Domain 2, Threats, Vulnerabilities, and Mitigations, is next at 22%.
Are these the current Security+ objectives?
Yes. These are the objectives for the current SY0-701 version of the exam, which CompTIA released in November 2023. It is the version you sit today.
Where can I download the official Security+ objectives?
CompTIA publishes the full objectives PDF on its website. This page summarizes the same five domains and 28 objectives and links free practice questions for each, so you can study the structure and test yourself in one place.
Cover every objective, then prove it
SecPlus Mastery turns this list into a guided path: a lesson for every objective, then over 1,000 practice questions, timed mock exams, and spaced review across all five domains. Domain 1 is free.
Keep studying: exam guide, practice test, and the 30-day study plan.
Prefer to watch an objective explained before you read it? Every domain has video lessons.
Objectives follow the CompTIA Security+ SY0-701 exam. CompTIA and Security+ are trademarks of CompTIA, used here for identification only. SecPlus Mastery is an independent study resource and is not affiliated with or endorsed by CompTIA.