comptia-security-plus

CompTIA Security+

Security

Practice scenario-based questions covering all five SY0-701 exam domains to build the hands-on knowledge needed for securing networks, applications, and devices. Prepare to pass the most widely recognized entry-level cyber-security certification.

Sign up free — practice 5 questions on this cert without a card.

CybersecurityCompTIA ProfessionalNetwork Security90 min exam90 questions750/900 to pass~$425 USD

Difficulty

Moderate

Avg study time

60-120h

6-12 weeks typical

Pass rate

~60-70%

First attempt

Market demand

Very High

Most popular entry-level security certification

Exam Domain Breakdown

General Security Concepts12%
Threats, Vulnerabilities, and Mitigations22%
Security Architecture18%
Security Operations28%
Security Program Management and Oversight20%

Difficulty by Topic

Security concepts & CIA triad
Confidentiality, integrity, availability, AAA, non-repudiation, zero trust, defense in depth
Threat actors & attack types
Nation-state, hacktivists, insider threats, phishing, social engineering, malware types, supply chain attacks
Vulnerability management
Vulnerability scanning, CVEs, CVSS scoring, penetration testing, responsible disclosure, patch management
Cryptography & PKI
Symmetric vs asymmetric, hashing, digital signatures, certificates, CAs, key management, TLS/SSL, certificate pinning
Network security
Firewalls, IDS/IPS, NAC, VPN, network segmentation, port security, SIEM, DLP, proxy servers
Identity & access management
MFA, SSO, LDAP, OAuth, SAML, RBAC, PAM, federation, passwordless authentication, biometrics
Security architecture & design
Cloud security models, microservices, containerization, serverless, IaC, secure baselines, hardening, embedded systems
Incident response & forensics
IR lifecycle, containment, eradication, recovery, chain of custody, order of volatility, log analysis, playbooks
Governance, risk & compliance
Frameworks (NIST, ISO 27001), risk assessment, BIA, policies, regulations (GDPR, HIPAA, PCI DSS), auditing
Performance-based questions (PBQs)
Hands-on simulations: configuring firewalls, analyzing logs, matching attack types, network diagrams, drag-and-drop

Exam Tips

1

Security+ uses both multiple-choice and performance-based questions (PBQs). PBQs appear first and simulate real-world tasks like configuring firewalls or analyzing logs. Skip them initially if stuck — flag and return after completing the multiple-choice questions.

2

Security Operations is the largest domain at 28%. Focus heavily on SIEM, log analysis, incident response procedures, and security monitoring. Know the difference between IDS and IPS, and when to use each.

3

Cryptography is the hardest topic for most candidates. Know symmetric (AES, DES) vs asymmetric (RSA, ECC), hashing algorithms (SHA-256, MD5), digital signatures, and the full PKI certificate lifecycle.

4

The exam loves scenario-based questions. When you see 'which is the BEST approach' or 'MOST effective control,' eliminate answers that are technically valid but don't fit the specific scenario described.

5

Know the threat actor categories and their motivations: nation-state (espionage, disruption), organized crime (financial gain), hacktivists (ideology), insider threats (access), and script kiddies (notoriety).

6

Identity and access management is heavily tested. Understand MFA factors (something you know/have/are), the difference between authentication and authorization, and protocols like SAML, OAuth, and LDAP.

7

Governance and compliance questions require knowing frameworks by name: NIST CSF for cybersecurity, NIST 800-53 for controls, ISO 27001 for ISMS, PCI DSS for payment data, HIPAA for healthcare, GDPR for EU privacy.

8

You get 90 minutes for up to 90 questions — time is tight. Spend no more than 1 minute per multiple-choice question on your first pass. Budget 15-20 minutes at the end for PBQs and flagged questions.

Study Resources

Who It's Best Suited For

IT professionals entering cybersecurity

Help desk, network admin, and sysadmin professionals looking to transition into security analyst, SOC analyst, or security engineer roles.

Military and government IT staff

Security+ meets DoD 8570/8140 requirements for IAT Level II positions, making it mandatory for many government and defense contractor roles.

Recent graduates in IT or cybersecurity

Graduates with a degree in IT, computer science, or cybersecurity who want an industry-recognized credential to land their first security role.

Career changers with Network+ or equivalent

IT professionals with networking fundamentals who want to build on that foundation with security expertise and a vendor-neutral certification.

Security-aware developers and cloud engineers

Developers and cloud professionals who want to formalize their security knowledge and understand secure architecture, compliance, and risk management.

Certification Path

A+
Network+
Security+
CySA+ / PenTest+
CASP+