Entry-level cybersecurity study guide
Aligned to the official CompTIA Security+ SY0-701 exam objectives
601 practice questions
140 flashcards
Completely free

CompTIA Security+ Exam Prep

Practice general security concepts, threats, vulnerabilities, architecture, operations, governance, risk, and compliance with 601 original SY0-701-aligned questions.

601 original questions
SY0-701 weighted
Controls + operations

Most popular

Start with free practice questions

Jump into a mixed set drawn from 601 free practice questions.

Free Practice Questions

Exam structure

Know the split before you start drilling

General Security Concepts

12%

12 scored + 0 pretest

Threats, Vulnerabilities, and Mitigations

22%

22 scored + 0 pretest

Security Architecture

18%

18 scored + 0 pretest

Security Operations

28%

28 scored + 0 pretest

Security Program Management and Oversight

20%

20 scored + 0 pretest

Current exam code

SY0-701

CompTIA's official objectives list Security+ exam number SY0-701.

Official exam size

Max 90 questions

CompTIA lists a maximum of 90 multiple-choice and performance-based questions.

Testing time

90 minutes

The official objectives list 90 minutes for the Security+ exam.

Largest domain

Operations 28%

Security Operations is the largest SY0-701 domain.

Weighted mock

100 questions

The site mock preserves the SY0-701 domain mix: 12/22/18/28/20.

Practice bank

601 questions

The bank expands the public objectives into original drills and explanations.

Start here

How to study for Security+

Use this sequence for the cleanest Security+ pass.

1

1. Anchor the control language

CIA, AAA, nonrepudiation, control types, crypto, and Zero Trust make every later domain easier to reason through.

2

2. Connect threats to mitigations

For every attack or vulnerability, practice naming the exposed path and the control that directly reduces it.

3

3. Finish with operations and governance

Monitoring, IAM, incident response, risk, compliance, and third-party oversight are high-yield because they drive daily security decisions.

About the exam

Security+ Exam structure

CompTIA Security+ SY0-701 prep with 601 original practice questions, objective-weighted mocks, cybersecurity flashcards, and topic recovery.

Issuer and path

CompTIA Security+ Exam Prep is administered through CompTIA. Check official resources before booking, retesting, or relying on a stale requirement.

General Security Concepts

12%

12 scored + 0 pretest

Security controls, core principles, change management, cryptography, public key infrastructure, Zero Trust, deception, and physical security.

Threats, Vulnerabilities, and Mitigations

22%

22 scored + 0 pretest

Threat actors, attack vectors, social engineering, malware, application attacks, vulnerabilities, indicators of compromise, and hardening controls.

Security Architecture

18%

18 scored + 0 pretest

Enterprise architecture, cloud and virtualization models, secure design principles, resilience, data protection, segmentation, and recovery design.

Security Operations

28%

28 scored + 0 pretest

Secure baselines, vulnerability management, monitoring, identity and access, automation, incident response, endpoint, network, cloud, and log investigations.

Security Program Management and Oversight

20%

20 scored + 0 pretest

Governance, risk, compliance, third-party risk, policies, audits, awareness, business continuity, resilience planning, and legal considerations.

Before you schedule

Confirm the current exam code, voucher rules, Pearson VUE appointment, ID requirements, testing format, retake policy, and whether you need extra time for performance-based questions.

Official Outline Coverage Map

Coverage is mapped to official outline item counts so content depth can be checked without hard-coding a single exam.

Official outline
TopicOfficial outline itemsYour questionsYour flashcardsConfidence
Security Controls and Core Security Fundamentals63610
Priority
Cryptography, Zero Trust and Change Management63610
Strong
Threat Actors, Attack Vectors and Social Engineering74410
Priority
Vulnerabilities and Malicious Activity Indicators84410
Priority
Mitigation and Hardening Techniques74410
Strong
Architecture Models and Secure Design63610
Priority
Enterprise Infrastructure and Data Protection63610
Strong
Resilience, Recovery and Secure Architecture63610
Priority
Secure Baselines and Asset Management74210
Strong
Vulnerability Management, Monitoring and Alerting74210
Priority
Identity, Access, Automation and Incident Response74210
Priority
Logs, Endpoint, Network and Cloud Investigation74210
Strong
Governance, Risk, Compliance and Third-Party Oversight106110
Priority
Policies, Awareness, Audits and Continuity Planning106010
Strong

How to use this guide

How to study for Security+

Treat each item as a control-selection problem: identify the asset, threat, vulnerability, control objective, operational context, and risk tradeoff.

1. Identify the asset and data state

Decide what must be protected, where it lives, and whether confidentiality, integrity, or availability is primary.

2. Name the threat and weakness

Separate actor, vector, vulnerability, exploit, indicator, and business impact.

3. Pick the direct control

Choose the preventive, detective, corrective, compensating, or governance control that reduces the actual risk.

4. Verify operation and oversight

Look for logging, monitoring, testing, documentation, ownership, and review so the control stays effective.

Security Controls and Core Security Fundamentals
Concepts

Security Controls and Core Security Fundamentals

Security+ questions often begin with the purpose of a control, the CIA triad, nonrepudiation, authentication, authorization, and accountability.

Key rules

Rule 1

Security controls are selected by function and purpose, including preventive, detective, corrective, deterrent, compensating, and directive controls.

Exam cue: Name the control objective before naming a product.

Rule 2

The CIA triad frames confidentiality, integrity, and availability tradeoffs in almost every security design.

Exam cue: Separate confidentiality, integrity, and availability.

Rule 3

AAA and nonrepudiation connect identities, permissions, logs, and evidence to defensible security operations.

Exam cue: Tie accountability to identity, logging, and evidence.

Common traps

Choosing a detective control when prevention is required.

Prevention: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Treating authentication and authorization as the same step.

Prevention: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Ignoring availability when a control blocks legitimate operations.

Prevention: Avoid answers that trust location alone, skip evidence, ignore business impact, or choose a tool that does not address the described risk.

Memory anchors

Preventive Control

A preventive control blocks or reduces the chance of an unwanted event before it happens.

Detective Control

A detective control identifies events, anomalies, or violations after or while they occur.

Corrective Control

A corrective control restores a system or process after an incident or error.

Deterrent Control

A deterrent control discourages a threat actor by increasing perceived risk or effort.

CIA Triad

Confidentiality protects data exposure, integrity protects correctness, and availability protects access when needed.

Authentication

Authentication verifies that an identity claim belongs to the entity presenting it.

Authorization

Authorization decides what an authenticated identity is allowed to access or perform.

Accounting

Accounting records activity so actions can be reviewed, attributed, and audited.

Nonrepudiation

Nonrepudiation provides evidence that a party cannot credibly deny an action.

Least Privilege

Least privilege grants only the access needed for the approved task and no more.

Next best moves

Quick check-up

Use a short quiz to confirm the rule pattern is actually sticking.

Check-up Questions

1-2 question checkpoint

A company configures its email gateway to reject executable attachments before they reach user inboxes. Which control type is this?

Security staff review badge logs each morning to identify attempts to enter a restricted laboratory overnight. Which control type best describes the log review?

Answer all questions to submit.

Next step personalized recommendations

Open another topic next

Official resources

Verify the details with the official sources

Use these links for eligibility, scheduling, handbook rules, and issuer updates. Our guide helps you study; official sources tell you what the testing partner currently requires.

FAQ

Common Security+ questions

Is this the official Security+ exam?

No. These are original practice questions aligned to CompTIA's public SY0-701 objectives. They are not copied from secure exam material.

Which Security+ version is this page aligned to?

This page is aligned to Security+ SY0-701, the exam code listed in CompTIA's current official objectives.

Does Security+ include performance-based questions?

Yes. CompTIA lists multiple-choice and performance-based questions. This bank focuses on scenario-based objective mastery for practice mode and mock mode.

What should I study first?

Start with security controls, CIA, IAM, common threats, and vulnerability management. Those concepts repeat across architecture, operations, and governance.

How should I use the 601 questions?

Use topic drills for weak objectives, section drills for the five SY0-701 domains, then 100-question weighted mocks to practice time and domain balance.

What is Pass Harbor?

Completely free exam prep for 317 U.S. exams.

  • Practice questions
  • Flashcards
  • Study guides
  • Mock exams
  • No registration
  • No paywall
  • Start instantly
No more expensive exam prep. Quality study tools should be accessible to everyone.