← All certifications
CompTIA
CompTIA Security+
Certloom is an independent study platform. Not affiliated with, endorsed by, or sponsored by any certification vendor. All trademarks are the property of their respective owners.
Sign in to set your exam date and start a study plan.
SY0-701Current version
- Questions
- 90
- Time limit
- 90 min
- Score to pass
- 750
Domains
- 1.0
General Security Concepts- 1.1Compare security control categories (technical, managerial, operational, physical) and control types (preventive, deterrent, detective, corrective, compensating, directive).
- 1.2Explain core security concepts including confidentiality, integrity, availability, non-repudiation, authentication, authorization, accounting, and zero trust principles.
- 1.3Apply cryptographic building blocks: symmetric and asymmetric use cases, hashing, salting, digital signatures, certificates, and key management.
12% - 2.0
Threats, Vulnerabilities, and Mitigations- 2.1Differentiate threat actor types by motivation, resources, and level of sophistication.
- 2.2Identify common threat vectors and attack surfaces across message-based, file-based, network, and human channels.
- 2.3Analyze vulnerability classes affecting applications, operating systems, hardware, virtualized workloads, cloud services, and the supply chain.
- 2.4Recognize indicators of malicious activity from observable system and network behavior.
22% - 3.0
Security Architecture- 3.1Compare architecture models including on-premises, cloud, hybrid, serverless, microservices, IoT, and ICS/SCADA, along with their security tradeoffs.
- 3.2Apply secure design principles to enterprise infrastructure: segmentation, device placement, failure modes, and selection of secure protocols.
- 3.3Select data protection controls based on data classification, data state, and sovereignty requirements.
18% - 4.0
Security Operations- 4.1Apply secure baselines and hardening measures to endpoints, servers, mobile devices, and network equipment.
- 4.2Execute the vulnerability management lifecycle: identification, analysis, prioritization, remediation, validation, and reporting.
- 4.3Interpret alerting and monitoring data drawn from logs, telemetry, and security tooling.
- 4.4Implement identity and access management: provisioning, authentication factors, authorization models, and privileged access control.
- 4.5Execute incident response phases and select appropriate investigative data sources.
28% - 5.0
Security Program Management and Oversight- 5.1Summarize governance structures and the relationship between policies, standards, procedures, and guidelines.
- 5.2Apply the risk management process: identification, assessment, analysis, response selection, and ongoing monitoring.
- 5.3Evaluate third-party and supply-chain risk through assessment, contractual agreements, and continuous monitoring.
20%