Free 30-Day Security+ Study Plan (SY0-701)
A focused 30-day plan to prepare for the CompTIA Security+ SY0-701 exam (up to 90 questions, 90 minutes, 750 of 900 to pass). Each day covers a defined topic, with built-in review and practice days. Adjust the pace to your schedule, but keep the order: it follows the five domains by exam weight.
Last updated August 2026
Week 1: Foundations and Domain 1 (General Security Concepts)
- Day 1: OrientationLearn the exam format (up to 90 questions, 90 minutes, 750 of 900 to pass, including performance-based questions) and the five domains and their weights. Skim the acronyms glossary and the ports cheat sheet.
- Day 2: Security controlsStudy control categories (technical, managerial, operational, physical) and control types (preventive, deterrent, detective, corrective, compensating, directive).
- Day 3: Core conceptsReview the CIA triad, non-repudiation, AAA, Zero Trust, physical security, and deception techniques such as honeypots.
- Day 4: CryptographyStudy symmetric vs asymmetric encryption, hashing, digital signatures, PKI, and certificates. Use the cryptography cheat sheet.
- Day 5: Change management and reviewReview change management processes, then take the Domain 1 practice questions and note weak spots.
- Day 6: Threats beginStart Domain 2: threat actors and their motivations, plus threat vectors and attack surfaces.
- Day 7: Week 1 reviewLight day. Re-quiz Domain 1, build flashcards for anything shaky, and rest.
Week 2: Threats and Architecture (Domains 2 and 3)
- Day 8: VulnerabilitiesStudy vulnerability types: application, operating system, web, hardware, cloud, supply chain, and misconfiguration.
- Day 9: Malicious activityLearn malware types and social engineering techniques. Use the common attacks cheat sheet.
- Day 10: MitigationsStudy mitigation techniques: segmentation, hardening, least privilege, patching, and isolation. Take the Domain 2 practice questions.
- Day 11: Architecture modelsStart Domain 3: cloud, serverless, microservices, virtualization, infrastructure as code, and Zero Trust models.
- Day 12: Secure infrastructureStudy firewalls, IDS and IPS, and ports and protocols. Use the ports cheat sheet and the IDS vs IPS guide.
- Day 13: Data and resilienceReview data classification, DLP, encryption states, backups, RAID, and high availability.
- Day 14: Week 2 reviewTake the full 30-question practice test and record which domains are weakest.
Week 3: Security Operations (Domain 4, the largest domain)
- Day 15: Secure resourcesStudy secure baselines, hardening, mobile device security, and endpoint protection such as EDR.
- Day 16: Asset and vulnerability managementReview asset inventory and disposal, vulnerability scanning, CVSS scoring, and remediation.
- Day 17: Monitoring and alertingStudy SIEM, SNMP, NetFlow, log aggregation, and alerting concepts.
- Day 18: Enterprise capabilitiesReview firewall rules, web and DNS filtering, email security, NAC, and DLP.
- Day 19: Identity and accessStudy IAM, provisioning, SSO, MFA, federation, and PAM. Use the MAC vs DAC vs RBAC and authentication vs authorization guides.
- Day 20: Automation and incident responseReview SOAR, the incident response phases, digital forensics, and log data sources.
- Day 21: Domain 4 reviewTake the Domain 4 practice questions and review every item you miss.
Week 4: Program Management and final prep (Domain 5 plus review)
- Day 22: GovernanceStart Domain 5: policies, standards, procedures, guidelines, and roles and responsibilities.
- Day 23: Risk managementStudy risk assessment, SLE, ARO, and ALE, the risk register, and the four risk responses: accept, avoid, transfer, mitigate.
- Day 24: Third-party riskReview vendor assessment, due diligence, and agreements such as SLA, MOU, NDA, and BPA.
- Day 25: Compliance and privacyStudy key regulations (HIPAA, GDPR, PCI DSS), data roles, and privacy concepts.
- Day 26: Audits and awarenessReview internal and external audits, penetration testing, attestation, and security awareness training. Take the Domain 5 practice questions.
- Day 27: Full reviewTake the full practice test again and concentrate on your weakest domains.
- Day 28: Targeted reviewRedo the per-domain practice for your two weakest domains and re-read the ports, cryptography, attacks, and acronyms cheat sheets.
- Day 29: Light review and logisticsSkim all cheat sheets and flashcards. Confirm your exam appointment, ID, and testing rules. Do not cram new material.
- Day 30: Exam dayDo a brief warm-up with the cheat sheets, arrive early, read each question carefully, flag and return to hard ones, and manage your time. You are ready.
Free resources used in this plan
Follow the plan without the guesswork
SecPlus Mastery turns this plan into a guided path: lessons for every objective, over 1,000 practice questions, timed mock exams, and spaced review that tells you what to study next and when you are ready.
New accounts get 30% off both plans for 7 days: the 90-Day Pass is $27.30 instead of $39.
Security+ study plan FAQ
Is 30 days enough to study for Security+?
For many people with some IT background, a focused 30 days is enough. If you are newer to IT, give yourself six to eight weeks and spread each topic over more days.How many hours a day should I study?
Plan for about one to two hours on study days, with lighter review days. Consistency matters more than occasional marathon sessions.Is this study plan free?
Yes. The full plan and the printable PDF checklist are free, and every resource it links to is free as well.What order should I study the domains in?
This plan follows the domains in order and by exam weight, spending the most time on Domain 4, Security Operations, which is the largest domain.
Thirty days is tight, so use what makes a topic stick fastest: video lessons for the concepts that will not land off the page, and mnemonics for the lists you just have to memorise.
Aligned to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.