SY0-701
CompTIA Security+ SY0-701
The most widely required entry-level security credential, and the DoD 8140 IAT Level II baseline. No experience prerequisite.
- Questions
- max 90
- Time
- 90 min
- Pass
- 750/900
- Reading
- ~11 hrs
General Security Concepts
12% of exam- 1.1Compare and contrast various types of security controls18m
Sort controls by category (technical, managerial, operational, physical) and by type (preventive, deterrent, detective, corrective, compensating, directive).
- 1.2Summarize fundamental security concepts24m
CIA triad, non-repudiation, AAA, gap analysis, and zero trust's control and data planes.
- 1.3Explain the importance of change management processes and the impact to security16m
Approval chains, maintenance windows, backout plans, and why undocumented change is a security problem.
- 1.4Explain the importance of using appropriate cryptographic solutions32m
PKI, symmetric vs asymmetric, key exchange, hashing, salting, digital signatures, certificates, and blockchain.
Threats, Vulnerabilities, and Mitigations
22% of exam- 2.1Compare and contrast common threat actors and motivations16m
Nation-state, unskilled attacker, hacktivist, insider threat, organized crime, shadow IT — and what each actually wants.
- 2.2Explain common threat vectors and attack surfaces22m
Message-based, image-based, file-based, removable device, supply chain, and human vectors including phishing and pretexting.
- 2.3Explain various types of vulnerabilities26m
Application, OS, web, hardware, cloud, virtualization, supply chain, cryptographic, and zero-day vulnerabilities.
- 2.4Given a scenario, analyze indicators of malicious activity34m
Recognize malware, network, application, and physical attacks from their observable indicators. Heavy PBQ territory.
- 2.5Explain the purpose of mitigation techniques used to secure the enterprise22m
Segmentation, access control, isolation, patching, encryption, monitoring, hardening, and least privilege.
Security Architecture
18% of exam- 3.1Compare and contrast security implications of different architecture models28m
Cloud, IaC, serverless, microservices, on-prem, virtualization, IoT, ICS/SCADA, and embedded systems.
- 3.2Given a scenario, apply security principles to secure enterprise infrastructure26m
Device placement, security zones, failure modes, and selecting the right control for the traffic you need to govern.
- 3.3Compare and contrast concepts and strategies to protect data22m
Data classification, states, sovereignty, and methods: encryption, hashing, masking, tokenization, obfuscation.
- 3.4Explain the importance of resilience and recovery in security architecture20m
High availability, site considerations, testing, backups, and power. RPO and RTO in plain terms.
Security Operations
28% of exam- 4.1Given a scenario, apply common security techniques to computing resources26m
Secure baselines, hardening targets, wireless security settings, and mobile deployment models.
- 4.2Explain the security implications of proper hardware, software, and data asset management16m
Acquisition, assignment, monitoring, and disposal — including sanitization, destruction, and certification.
- 4.3Explain various activities associated with vulnerability management28m
Discovery, analysis, prioritization with CVSS and CVE, remediation, validation, and reporting.
- 4.4Explain security alerting and monitoring concepts and tools26m
SIEM, SNMP, NetFlow, antivirus, DLP, SCAP, and the monitoring lifecycle from alert to tuning.
- 4.5Given a scenario, modify enterprise capabilities to enhance security30m
Firewalls, IDS/IPS, web filtering, DNS filtering, email security, EDR/XDR, and secure protocol selection.
- 4.6Given a scenario, implement and maintain identity and access management30m
Provisioning, federation, SSO, LDAP, OAuth, SAML, MFA factors, password policy, and privileged access management.
- 4.7Explain the importance of automation and orchestration related to secure operations16m
Use cases for scripting and SOAR, plus the real costs: complexity, single points of failure, technical debt.
- 4.8Explain appropriate incident response activities24m
The IR lifecycle in order, training, testing, root cause analysis, threat hunting, and digital forensics.
- 4.9Given a scenario, use data sources to support an investigation26m
Reading firewall, application, endpoint, OS, IDS/IPS and network logs, plus packet captures and vulnerability scans.
Security Program Management and Oversight
20% of exam- 5.1Summarize elements of effective security governance20m
Guidelines, policies, standards, procedures, governance structures, and roles like owner, custodian, processor.
- 5.2Explain elements of the risk management process26m
Risk identification, assessment types, analysis, register, appetite, response strategies, and business impact analysis.
- 5.3Explain the processes associated with third-party risk assessment and management18m
Vendor assessment, due diligence, questionnaires, and agreement types: SLA, MOU, MSA, NDA, BPA, SOW.
- 5.4Summarize elements of effective security compliance18m
Reporting, monitoring, consequences of non-compliance, and privacy regimes including data subject rights.
- 5.5Explain types and purposes of audits and assessments16m
Internal and external audits, attestation, and penetration testing types: known, partial, and unknown environment.
- 5.6Given a scenario, implement security awareness practices16m
Phishing recognition and reporting, anomalous behaviour, user guidance, and measuring whether training worked.