CompTIA Security+

CompTIA

Complete guide to passing the CompTIA Security+ exam on your first attempt.

MediumVery High Search Volume
Key Information at a Glance
Cost

$392

Pass Rate

~70%

Validity

3 years

Region

Global

Provider

CompTIA

Salary Impact

$65k-$95k

Are you ready for CompTIA Security+?

Loading quiz...

Complete Overview

CompTIA Security+ is a single-exam, vendor-neutral cybersecurity certification aimed at people moving into core security functions, and the current version is V7 under exam code SY0-701. CompTIA sells the voucher through its own store rather than publishing a fixed global list price on a static page, and the price differs by region, so the store is the only reliable place to check what you will pay before booking. The exam launched on 7 November 2023 and CompTIA estimates retirement in 2026, in line with its usual pattern of retiring a version about three years after launch. CompTIA has published draft Security+ V8 objectives on its Exam Objectives Under Development page, and SY0-701 remains the live exam listed on the Security+ certification page.

The exam runs 90 minutes with a maximum of 90 questions, mixing multiple choice with performance-based questions delivered in a simulated interface. The passing score is 750 on a scale of 100 to 900, the highest cut score of the three foundational CompTIA credentials, above Network+ at 720 and A+ Core 2 at 700. CompTIA recommends holding Network+ plus two years of experience in a security or systems administrator job role, though no prerequisite is checked at booking. The exam is offered in English, Japanese, Portuguese, Spanish and Thai.

Five domains carry published weights summing to 100 percent: security operations at 28 percent, threats vulnerabilities and mitigations at 22 percent, security program management and oversight at 20 percent, security architecture at 18 percent and general security concepts at 12 percent. That distribution is the most useful planning fact on the exam. Operations plus threats account for half the questions, and governance, risk and compliance content in security program management is worth more than architecture, which surprises candidates who arrive expecting a purely technical paper.

CompTIA does not publish a pass rate for Security+ or for any of its certifications. Its Exam Development policy states that CompTIA exams are criterion-referenced against a cut score rather than norm-referenced, that exam content, results data and analyses are classified as highly confidential, and that it is CompTIA policy not to disclose pass rates to any external third party. Security+ is accredited by the ANSI National Accreditation Board under ISO 17024, and CompTIA estimates 5,000 subject matter expert hours go into developing a single exam.

Security+ is valid for three years and enrols automatically in CompTIA's Continuing Education programme. Renewal takes 50 continuing education units across the cycle plus a total CE fee of $150, which is the heaviest CEU requirement of the three foundational credentials, against 30 for Network+ and 20 for A+. Passing Security+ renews an existing Network+ and A+ without additional CE fees, because CompTIA renews lower certifications when a higher one is earned.

CompTIA maps Security+ to a long list of DoD 8140 work roles including cyber defense analyst, incident responder, vulnerability analyst, security control assessor, system administrator, network specialist, systems planner, IT project manager, information security manager and secure software assessor. The US Bureau of Labor Statistics puts the median annual wage for information security analysts at $124,910 in May 2024 and projects the occupation to grow 29 percent between 2024 and 2034, adding 52,100 jobs, which is far above the 3 percent average across all occupations.

Why Get CompTIA Security+ Certified?

Five published domains with weights summing to 100 percent give a precise study allocation: security operations 28 percent, threats and mitigations 22 percent, program management 20 percent, architecture 18 percent and general concepts 12 percent.

CompTIA maps Security+ to more DoD 8140 work roles than any other foundational credential in its range, naming cyber defense analyst, incident responder, vulnerability analyst, security control assessor, system administrator, network specialist, systems planner, IT project manager, information security manager and secure software assessor.

Passing Security+ renews both Network+ and A+ automatically without paying their CE fees, saving 30 plus 20 CEUs and $225 in fees across a renewal cycle.

The credential is accredited by the ANSI National Accreditation Board under ISO 17024, one of eight CompTIA certifications the vendor lists as holding that accreditation.

The US Bureau of Labor Statistics projects 29 percent growth in information security analyst roles between 2024 and 2034, adding 52,100 positions, against a 3 percent average across all occupations.

The BLS median annual wage for information security analysts was $124,910 in May 2024, more than double the $60,340 median for computer user support specialists that A+ targets.

One 90-minute exam completes the certification, against the two separate exams and 180 minutes A+ requires, so the whole credential closes in a single sitting.

Exam Format & Structure

Duration

90 minutes. CompTIA structures its exams as a single session with no scheduled breaks, at test centres and through OnVUE alike.

Questions

A maximum of 90 questions. CompTIA publishes a ceiling rather than a fixed count and does not disclose how many questions are required to pass or how many a candidate answered incorrectly.

Passing Score

750 on a scale of 100 to 900. CompTIA sets passing scores by statistical analysis and states they are subject to change.

Question Types

  • Multiple choice, single response
  • Multiple choice, multiple response
  • Performance-based questions delivered in a simulated interface

Delivery Method

Computer-based at a Pearson VUE test centre, or online through Pearson VUE OnVUE remote proctoring. CompTIA offers online testing for all its certifications except in China, Cuba, Iran, North Korea, South Korea, Slovenia, Sudan and Syria. Test centre candidates are photographed before testing and cannot sit the exam if they decline; OnVUE candidates are webcam-recorded throughout the session.

How scoring works

Score scale

100 to 900 scaled, as published on CompTIA's Security+ certification page.

Score needed to pass

750. CompTIA states that passing scores are set using statistical analysis and are subject to change.

When results arrive

The score appears on screen immediately after the exam. Test centre candidates receive a printed score report carrying their photograph; online candidates find the report in their Pearson VUE account within 24 hours. The exam record appears in the CompTIA certification account within five business days, and passing triggers a CompTIA Certmetrics email. The report names the exam objectives attached to questions answered incorrectly, but not the questions or the count.

How the scale is built

CompTIA describes calculating a scaled score with a mathematical algorithm from what would otherwise be a percentage score, with the cut score set by statistical analysis. The model is criterion-referenced: your score is compared to an established standard for minimal competency in the job role, never to other candidates, so there is no curve and no norm-referencing. Scoring is compensatory across the five domains, because a weak domain can be offset by a strong one and CompTIA publishes no per-domain minimum. CompTIA does not disclose the number of questions required to pass, the number answered incorrectly, or the raw-to-scale conversion, and it publishes no negative-marking rule for Security+.

Pacing and time budget

90 questions in 90 minutes gives you 1 minute exactly, since the exam allows a maximum of 90 questions in 90 minutes. Performance-based questions consume several minutes each, and Security+ scenario stems read long, so the average has to be beaten on the definition questions. per question.

5

Every performance-based question located and flagged, none attempted yet, and 3 to 5 definition questions cleared to build momentum

25

About 30 multiple-choice questions, running ahead of the one-minute average to bank time for the simulations and the long scenario stems

50

About 60 questions, with every remaining unflagged item being one you can settle in under 45 seconds

65

All multiple-choice and multiple-response questions answered, leaving only flagged performance-based items and flagged scenario questions

85

All performance-based questions attempted and every flagged item revisited, with 5 minutes reserved for a final sweep for unanswered questions

  • Security+ stems are long. A scenario that supplies a compliance constraint, a budget and a technical detail can take 90 seconds to read alone, so the definition questions must be cleared in 30 seconds to fund them.
  • The 28 minutes CompTIA allows for the Candidate Agreement review sit outside the 90-minute exam clock, so reading it does not eat into your time.
  • Performance-based questions are simulations and cannot be resolved by elimination. Banking the multiple choice first turns them from a time risk into a bonus.
  • Security operations is 28 percent of the exam, so roughly one question in four comes from hardening, vulnerability management, monitoring, identity, automation or incident response. Expect these to cluster and pace accordingly.
  • The exam is a single continuous session with no scheduled breaks, so plan hydration and food before check-in rather than mid-exam.
  • Under OnVUE all working goes on the built-in digital whiteboard. Use it to write out the control classification grid in the first minute, which is legitimate scratch work and stops the categories blurring under pressure.

Where the marks are

Security operations

28%

The largest domain by six points. Covers secure baselines and hardening, asset management, the vulnerability management cycle, monitoring tools, firewalls and EDR, identity and access management, automation, incident response and digital forensics.

Threats, vulnerabilities, and mitigations

22%

Recognition-driven. Questions describe an incident and expect you to name the actor, the vector or the attack, then pick the mitigation from segmentation, access control, configuration enforcement, hardening, isolation or patching.

Security program management and oversight

20%

Governance hierarchy, the risk vocabulary from appetite to register, third-party vendor lifecycle, compliance reporting, attestation and audits, and security awareness. Definition-heavy, which makes it the cheapest domain to secure.

Security architecture

18%

Design questions that supply a constraint: on-premises against cloud, virtualization, IoT, ICS and infrastructure as code, plus data classification, high availability, site selection, backups and continuity of operations.

General security concepts

12%

The smallest domain but the vocabulary the other four reuse: ten control categories, the CIA triad, non-repudiation, AAA, zero trust, deception technology, change management and cryptographic solutions including PKI.

Incident response and digital forensics

Inside the 28 percent security operations domain; CompTIA does not publish a sub-weight

Named in the objectives as processes, training, testing, root cause analysis, threat hunting and digital forensics. Ordering questions ask which phase a scenario describes or which comes next, so the sequence must be exact.

Cryptographic solutions

Inside the 12 percent general security concepts domain; CompTIA does not publish a sub-weight

Public key infrastructure, encryption, obfuscation, hashing, digital signatures and blockchain. Cryptographic attacks appear separately inside the 22 percent threats domain, so the material is examined from two directions.

Risk management

Inside the 20 percent security program management domain; CompTIA does not publish a sub-weight

Risk identification, assessment, analysis, register, tolerance, appetite, treatment strategies, reporting and business impact analysis. Questions often hinge on distinguishing tolerance from appetite, or transfer from mitigation.

The numbers

750 on a scale of 100 to 900

Passing score

Source: CompTIA, Security+ certification exam details

Launched 7 November 2023, retirement estimated 2026

Launch date and estimated retirement, exam series SY0-701 (V7)

Source: CompTIA, Security+ certification exam details

90 minutes, maximum of 90 questions

Exam length and question ceiling

Source: CompTIA, Security+ certification exam details

50 continuing education units plus a $150 total CE fee

Renewal requirement over the three-year cycle

Source: CompTIA, Earn Continuing Education Units (CEUs) and Continuing Education Renewal Fees

$124,910 per year, or $60.05 per hour

Median annual wage, information security analysts, May 2024

Source: US Bureau of Labor Statistics, Occupational Outlook Handbook, Information Security Analysts

29 percent, adding 52,100 jobs from a 2024 base of 182,800

Projected employment growth, information security analysts, 2024 to 2034

Source: US Bureau of Labor Statistics, Employment Projections program

If you fail

Wait before retaking

No waiting period between the first and second attempt. Before a third attempt, and before any subsequent attempt, CompTIA requires at least 14 calendar days from the date of the last attempt. Client-proctored exams follow the same rule, and CompTIA states these requirements cannot be waived under any circumstances.

Attempt limit

CompTIA publishes no cap on attempts, provided the 14-day interval is observed from the third attempt onward. Beta examinations may be taken only once. A candidate who has already passed and certified cannot retake the same exam code without prior consent from CompTIA and must wait until CompTIA releases the next Security+ exam series.

Retake fee

The full exam price for every attempt. CompTIA states that candidates must pay the exam price each time they attempt the exam and that it does not offer any free re-tests or discounts on retakes. The two exceptions are a Retake Assurance voucher bought inside a CompTIA bundle, which activates only after you take and do not pass the exam, and a free retake where CompTIA classifies a score as indeterminate because of unexplained statistical discrepancies.

A voucher is consumed by the attempt whether you pass or fail, and vouchers expire 12 months after issue with no extensions. Rescheduling a test centre appointment inside 24 hours, or failing to appear, forfeits the fee; online proctored appointments can be rescheduled or cancelled up until the scheduled start time. Violating the retake policy invalidates the test and can trigger a suspension of at least six calendar months, and CompTIA states repeat violators are permanently banned. The score report names the objectives attached to your missed questions, which is the most useful input for planning a second attempt. Candidates who want a result reviewed can request a manual rescore through the CompTIA Help Center, where an Exam Services staff member compares the responses to the official answer key, though CompTIA will not release questions, answers or scoring keys.

Exam Domains & Topics

Security operations
28%

The largest domain by a wide margin. Everything that happens in a running security function: hardening, vulnerability management, monitoring, identity and access, automation and incident response.

Key Topics to Master:

  • Applying secure baselines, mobile solutions, hardening, wireless security, application security, sandboxing and monitoring to computing resources
  • Asset management across acquisition, disposal, assignment and monitoring of hardware, software and data
  • Vulnerability management: identification, analysis, remediation, validation and reporting
  • Alerting and monitoring tools and the activities they cover
  • Enterprise security: modifying firewalls, IDS and IPS, DNS filtering, data loss prevention, network access control and endpoint or extended detection and response
  • Identity and access management: provisioning, single sign-on, multifactor authentication and privileged access tools
  • Automation and orchestration use cases, scripting benefits and considerations
  • Incident response processes, training, testing, root cause analysis, threat hunting and digital forensics
  • Using log data and other sources to support investigations
Threats, vulnerabilities, and mitigations
22%

Who attacks, how they get in, what is weak, and what you do about it. The second largest domain and the most recognition-driven.

Key Topics to Master:

  • Threat actors: nation-states, unskilled attackers, hacktivists, insider threats, organized crime and shadow IT
  • Motivations including data exfiltration, espionage and financial gain
  • Threat vectors and attack surfaces: message-based, unsecure networks, social engineering, file-based, voice call, supply chain and vulnerable software
  • Vulnerabilities across application, hardware, mobile device, virtualization, operating system, cloud-specific, web-based and supply chain
  • Analysing malware, password, application, physical, network and cryptographic attacks
  • Mitigation techniques: segmentation, access control, configuration enforcement, hardening, isolation and patching
Security program management and oversight
20%

Governance, risk, third-party management, compliance, audits and awareness. The domain most technically minded candidates underestimate, and it is worth more than architecture.

Key Topics to Master:

  • Security governance: guidelines, policies, standards, procedures, external considerations, monitoring, governance structures and roles and responsibilities
  • Risk management: identification, assessment, analysis, register, tolerance, appetite, strategies, reporting and business impact analysis
  • Third-party risk: vendor assessment, selection, agreements, monitoring, questionnaires and rules of engagement
  • Security compliance: reporting, consequences of non-compliance, monitoring and privacy
  • Audits and assessments: attestation, internal and external audits, and penetration testing
  • Security awareness: phishing training, anomalous behaviour recognition, user guidance, reporting and monitoring
Security architecture
18%

Designing the environment: deployment models, infrastructure considerations, data protection and resilience.

Key Topics to Master:

  • Architecture models: on-premises, cloud, virtualization, Internet of Things, industrial control systems and infrastructure as code
  • Enterprise infrastructure: applying security principles to infrastructure considerations and control selection
  • Secure communication and access design
  • Data protection: data types, securing methods, general considerations and classifications
  • Resilience and recovery: high availability, site considerations, testing and power
  • Platform diversity, backups and continuity of operations
General security concepts
12%

The smallest domain and the vocabulary layer the other four assume. Control types, the fundamentals, change management and cryptographic solutions.

Key Topics to Master:

  • Comparing technical, preventive, managerial, deterrent, operational, detective, physical, corrective, compensating and directive controls
  • Confidentiality, integrity and availability, plus non-repudiation
  • Authentication, authorization and accounting
  • Zero trust, and deception and disruption technology
  • Change management: business processes, technical implications, documentation and version control
  • Cryptographic solutions: public key infrastructure, encryption, obfuscation, hashing, digital signatures and blockchain

Recommended Study Plan

Week 1: Scope, vocabulary and control types
9 to 11 hours
  • 1Download the official SY0-701 exam objectives from CompTIA and print the five domain weights, since operations at 28 percent and threats at 22 percent carry half the exam between them
  • 2Confirm every resource you buy names SY0-701, because SY0-601 material predates the November 2023 restructure and the domain list changed
  • 3Learn the ten control categories in the objectives and be able to classify any given control as technical, managerial, operational or physical, and as preventive, deterrent, detective, corrective, compensating or directive
  • 4Learn confidentiality, integrity, availability, non-repudiation, and authentication, authorization and accounting as precise definitions rather than slogans
  • 5Watch Professor Messer's free SY0-701 general security concepts modules and take notes against numbered objectives
  • 6Sit a 20-question concepts quiz and log every miss against an objective number
Week 2: Cryptography and change management
10 to 12 hours
  • 1Learn public key infrastructure end to end: certificate authorities, certificate signing requests, revocation and the chain of trust
  • 2Compare symmetric and asymmetric encryption and know which is used where in a real protocol exchange
  • 3Learn hashing, salting and digital signatures, and be able to state which property each one provides
  • 4Cover obfuscation techniques including tokenization, data masking and steganography
  • 5Learn the change management topics in the objectives: business processes, technical implications, documentation and version control
  • 6Generate a self-signed certificate and inspect it, so the fields stop being abstract
Week 3: Threat actors, vectors and attack surfaces
10 to 12 hours
  • 1Learn each threat actor type in the objectives and the resources, sophistication and motivation profile that distinguishes it
  • 2Learn the motivation list including data exfiltration, espionage and financial gain, and match motivations to actors
  • 3Cover threat vectors: message-based, unsecure networks, social engineering, file-based, voice call, supply chain and vulnerable software
  • 4Build a one-page social engineering table with the countermeasure for each technique
  • 5Practise scenario questions that describe an incident and ask which actor type it indicates
  • 6Sit a 25-question threat actor drill
Week 4: Vulnerabilities and attacks
11 to 13 hours
  • 1Cover vulnerabilities by category: application, hardware, mobile device, virtualization, operating system, cloud-specific, web-based and supply chain
  • 2Learn malware types and the specific behaviour each one produces on a host
  • 3Learn password attacks, application attacks, physical attacks, network attacks and cryptographic attacks as named items
  • 4Practise distinguishing similar attacks under pressure, for example on-path from replay, and injection from cross-site scripting
  • 5Learn the mitigation list: segmentation, access control, configuration enforcement, hardening, isolation and patching
  • 6Sit a 30-question threats and mitigations drill and log every confusion pair
Week 5: Security architecture, part one
10 to 12 hours
  • 1Compare on-premises, cloud, virtualization, IoT, industrial control systems and infrastructure as code as architecture models, with the security trade-off of each
  • 2Learn enterprise infrastructure considerations and control selection criteria
  • 3Cover secure communication and access design including VPN and remote access patterns
  • 4Learn data types, data classifications and the securing methods that apply to each
  • 5Practise choosing a control given a stated business constraint, which is how architecture questions are usually framed
  • 6Sit a 20-question architecture drill
Week 6: Resilience and recovery
10 to 12 hours
  • 1Learn high availability patterns and site considerations including hot, warm and cold sites
  • 2Cover testing types for continuity plans and know what each one proves
  • 3Learn power resilience: uninterruptible power supplies, generators and dual supply
  • 4Cover platform diversity and why monoculture is a resilience risk
  • 5Learn backup types, retention and restoration order, and continuity of operations planning
  • 6Sit a mid-course full-length practice exam of 90 questions in 90 minutes and record the domain breakdown
Week 7: Security operations, part one: hardening and vulnerability management
11 to 13 hours
  • 1Learn secure baselines, hardening targets, wireless security, application security and sandboxing
  • 2Cover asset management across acquisition, assignment, monitoring and disposal, including secure disposal methods
  • 3Learn the vulnerability management cycle in order: identification, analysis, remediation, validation and reporting
  • 4Cover vulnerability scoring and prioritisation, and the difference between a false positive and a false negative in a report
  • 5Run a vulnerability scanner against a lab host and read the output rather than the summary
  • 6Sit a 30-question operations drill covering hardening and vulnerability management
Week 8: Security operations, part two: monitoring, enterprise controls and identity
11 to 13 hours
  • 1Learn alerting and monitoring tools and the resource activities they cover
  • 2Cover firewalls, IDS and IPS, DNS filtering, data loss prevention, network access control and endpoint or extended detection and response, and know which one stops which attack
  • 3Learn identity and access management: provisioning, deprovisioning, single sign-on, multifactor authentication and privileged access management
  • 4Learn the four authentication factor categories and place every named method into one
  • 5Cover automation and orchestration use cases, scripting benefits and the considerations against them
  • 6Sit a 30-question drill on enterprise controls and identity
Week 9: Security operations, part three: incident response and forensics
12 to 14 hours
  • 1Learn the incident response process as an ordered sequence, since ordering questions are common
  • 2Cover training, testing, root cause analysis and threat hunting as separate named activities
  • 3Learn digital forensics concepts including chain of custody, order of volatility, legal hold and acquisition
  • 4Practise reading log data and identifying which source answers a given investigative question
  • 5Work through five end-to-end incident scenarios, naming the phase at each step
  • 6Remember operations is 28 percent of the exam, so this is where an extra week pays best
Week 10: Security program management: governance and risk
10 to 12 hours
  • 1Learn the governance hierarchy: guidelines, policies, standards and procedures, and know which sits above which
  • 2Cover governance structures, roles and responsibilities, and external considerations
  • 3Learn the risk vocabulary precisely: identification, assessment, analysis, register, tolerance, appetite and reporting
  • 4Learn the four risk treatment strategies and be able to name the one a scenario describes
  • 5Cover business impact analysis and the metrics it produces
  • 6Sit a 25-question governance and risk drill; this domain is 20 percent of the exam and is pure definition work
Week 11: Third-party risk, compliance, audits and awareness
10 to 12 hours
  • 1Learn the vendor lifecycle: assessment, selection, agreements, monitoring, questionnaires and rules of engagement
  • 2Learn the named agreement types and what each one commits the parties to
  • 3Cover compliance reporting, consequences of non-compliance, compliance monitoring and privacy
  • 4Learn attestation, internal audits, external audits and penetration testing as distinct assurance activities
  • 5Cover security awareness: phishing training, anomalous behaviour recognition, user guidance, reporting and monitoring
  • 6Sit a 25-question third-party and compliance drill
Week 12: Performance-based questions and weak-domain repair
12 to 14 hours
  • 1Practise performance-based questions in CompTIA CertMaster Labs or an equivalent browser-based lab
  • 2Rehearse a full 90-minute run flagging every simulation, clearing the multiple choice, then returning
  • 3Rank the five domains by practice score and give the bottom two the rest of the week
  • 4Rework every question missed since week 6 against its numbered objective
  • 5Re-drill the control classification table and the incident response sequence, both of which decay fastest
  • 6Buy the voucher only now, since a CompTIA voucher is valid for 12 months from issue and cannot be extended
Week 13: Full-length rehearsals against the 750 cut score
10 to 12 hours
  • 1Sit two full-length practice exams on separate days, targeting a stable margin above 750, which is higher than Network+ at 720 and A+ Core 2 at 700
  • 2Rebuild the control types table, the threat actor table and the risk vocabulary from memory in under ten minutes each
  • 3Practise acronym expansion under speed, since the objectives are dense with them and the exam does not gloss them
  • 4Rehearse the OnVUE or test centre process end to end so exam day holds no surprises
  • 5Confirm your two forms of ID meet the CompTIA Candidate ID Policy and that the names match your registration exactly
  • 6If testing online, run the Pearson VUE system test on the exact device and network you will use
Week 14: Sit the exam and set up renewal
6 to 8 hours
  • 1Allow 28 minutes for the Candidate Agreement review that CompTIA requires before the exam begins
  • 2Check in about 30 minutes ahead if testing through OnVUE, as CompTIA recommends
  • 3Sit SY0-701 and read the on-screen score before closing the session
  • 4Expect the score report in your Pearson VUE account within 24 hours and the exam record in your CompTIA certification account within five business days
  • 5If you passed and hold Network+ or A+, note that Security+ has just renewed both without their CE fees
  • 6Set a reminder three years out for the 50 continuing education units and $150 CE fee, or plan CySA+, PenTest+ or SecurityX instead, each of which renews Security+ for free

Ready to pass CompTIA Security+?

Get 500+ practice questions, video walkthroughs, and a pass guarantee.

94% pass rate on first attempt
$196$98

Best Study Resources

CompTIA Security+ SY0-701 exam objectives

Official objectives

The definitive scope document from CompTIA, listing every examinable item under a numbered objective along with the five domain percentages and a full acronym list. CompTIA's score report reports your misses against these same objective numbers, which makes the report directly actionable.

Free

Professor Messer's free Security+ SY0-701 training course

Video course

A complete free video course mapped to the current objective list, published at professormesser.com alongside monthly live study groups. The course structure follows the numbered objectives, so progress can be tracked against the official document.

Free

CompTIA CertMaster Learn plus Labs for Security+

Official courseware

CompTIA's most complete Security+ learning product, combining instructional content, video, interactives, simulated and live virtual machine labs, assessments and practice tests. CompTIA estimates 30 to 60 hours for Learn plus Labs together.

Paid, sold in the CompTIA Store

CompTIA CertMaster Learn for Security+

Official courseware

Instructional content, video, interactives, simulated labs, assessments and practice tests, aimed at candidates building foundational knowledge with no prior job role experience. CompTIA estimates 25 to 40 hours.

Paid, sold in the CompTIA Store

CompTIA CertMaster Labs for Security+

Virtual labs

A live virtual lab environment with guided tasks and real-world scenarios. CompTIA estimates 15 to 25 hours. This is the closest sanctioned rehearsal for the performance-based questions on the exam.

Paid, sold in the CompTIA Store

CompTIA CertMaster Practice for Security+

Practice exams

Timed practice exams, objective quizzes and objective-level mastery scores, aimed at confirming readiness and closing gaps before booking. CompTIA estimates 10 to 20 hours.

Paid, sold in the CompTIA Store

Security+ Complete Bundle with Retake

Bundle

CompTIA pairs CertMaster Learn, Labs and Practice with a voucher plus Retake Assurance. Because CompTIA charges the full exam price for every attempt and offers no retake discounts, a bundled retake voucher is the only sanctioned way to cut the cost of a second attempt. Practice and Exam and Learn and Exam bundles are also sold.

Paid, sold in the CompTIA Store

CompTIA Security+ self-study guide and practice questions

Book and sample questions

CompTIA sells an official self-study guide it describes as providing 100 percent coverage of the objectives and content examples on the syllabus, and publishes free downloadable practice question sets. The vendor states plainly that these practice questions are not questions from the live exam and that the real exam includes additional question types.

Paid book, free question sets

NIST Cybersecurity Framework and NIST SP 800-61

Reference standard

The objectives name governance frameworks, risk management and incident response processes without prescribing a single source. The NIST publications give the vocabulary those objectives assume, particularly for the 20 percent security program management domain and the incident response items inside security operations.

Free

Pearson VUE OnVUE system test

Exam-day tool

Run this on the same device and network you will use on exam day. Pearson VUE warns that failing to meet the minimum requirements on exam day can result in immediate exam cancellation and forfeiture of the exam fee, so it is preparation rather than an optional check.

Free

Common Mistakes to Avoid

Studying SY0-601 material for the SY0-701 exam

SY0-701 launched on 7 November 2023 and restructured the domain list to five domains: security operations 28 percent, threats vulnerabilities and mitigations 22 percent, security program management and oversight 20 percent, security architecture 18 percent and general security concepts 12 percent. Check the exam code on every book, course and practice set.

Treating security program management as optional because it is not technical

Governance, risk, third-party management, compliance, audits and awareness make up 20 percent of the exam, more than security architecture at 18 percent. It is definition-heavy and therefore the cheapest domain to secure, and the most expensive to skip on a paper with a 750 cut score.

Underestimating the 750 cut score

Security+ passes at 750 on the 100 to 900 scale, above Network+ at 720, A+ Core 2 at 700 and A+ Core 1 at 675. Practice performance that would comfortably clear Network+ can fall short here, so calibrate against 750 specifically rather than against a generic passing band.

Learning attack names without learning the distinguishing detail

The threats domain is 22 percent and questions routinely offer two plausible attacks. Build explicit confusion pairs, for example on-path against replay, phishing against pretexting, and injection against cross-site scripting, and write the one sentence that separates each pair.

Skipping the control classification exercise

General security concepts is only 12 percent, but the objectives ask you to compare technical, preventive, managerial, deterrent, operational, detective, physical, corrective, compensating and directive controls. Questions from other domains reuse this classification, so a single control can be asked about in two ways.

Never touching a performance-based question before exam day

Performance-based questions are a published question type on SY0-701 and place you in a simulated interface rather than in front of four options. Rehearse them in CertMaster Labs or an equivalent, and practise scratch work on a digital whiteboard, because OnVUE permits nothing else.

Chasing a published pass rate to gauge difficulty

CompTIA states as policy that it does not disclose pass rates to any external third party, because its exams are criterion-referenced against a cut score rather than norm-referenced and a single data point invites misinterpretation. Calibrate against your own domain scores on full-length practice exams.

Booking a third attempt too soon after a second failure

CompTIA requires no wait between the first and second attempt, but at least 14 calendar days must pass before a third attempt and before every subsequent attempt. A test taken in violation is invalidated, and the candidate may be suspended; CompTIA states repeat violators are permanently banned.

Buying the voucher at the start of a long study plan

A CompTIA voucher is valid for 12 months from the date it is received, and CompTIA states the expiration date cannot be extended under any circumstances. On a 14-week plan bought on day one, a single delay can burn the voucher entirely.

Waiting for SY0-801 instead of sitting the live exam

CompTIA has published draft V8 objectives on its Exam Objectives Under Development page, but that page states drafts reflect proposed content, may contain errors and are revised repeatedly before launch. SY0-701 is the exam CompTIA currently lists as live, and a voucher can be used for any version of the certification exam as long as it is used before it expires.

Exam Day Tips

  • 1

    Allow for the Candidate Agreement before the clock starts. Pearson VUE states the candidate is given 28 minutes to review it, separate from the 90 minutes of exam time.

  • 2

    Bring two original, unexpired IDs. The primary must be government-issued with your name and a recent recognisable photo; the secondary needs at least name and signature or name and a recognisable photo. Both must carry the exact first and last name you registered with.

  • 3

    At a test centre, expect to be photographed before testing. CompTIA states that candidates who decline the photograph will not be allowed to take the exam, and the photo appears on the printed score report.

  • 4

    If testing online, check in about 30 minutes before your appointment as CompTIA recommends, then expect a room scan, photographs of your workspace, and continuous webcam recording for the whole session.

  • 5

    Clear the desk completely for OnVUE. No books, no paper, no pen, pencil or marker, no erasable whiteboard, no second monitor, and no phone within reach once the exam begins. Use the built-in digital whiteboard for any working out.

  • 6

    Plan for no breaks. CompTIA structures its exams as a single continuous session with no scheduled breaks, whether at a test centre or online.

  • 7

    Flag performance-based questions and come back to them. With a maximum of 90 questions in 90 minutes, every minute spent on a simulation is a multiple-choice question left unanswered.

  • 8

    Count the required answers on multiple-response questions, since selecting the wrong number of options loses a question you actually knew.

  • 9

    Read scenario stems for the constraint before reading the options. Security+ questions frequently supply a business or compliance constraint that eliminates two technically correct answers.

  • 10

    If English is not your first language and you are testing in a non-English-speaking country where no localised version exists, the ESL accommodation adds 30 minutes and Pearson VUE grants it automatically at registration in eligible countries. It is unavailable in English-speaking countries because every CompTIA exam is offered in English.

  • 11

    Read the on-screen score before closing the session. The report also lands in your Pearson VUE account within 24 hours and in your CompTIA certification account within five business days.

Career Paths & Salary Ranges

Information security analyst

The occupation Security+ maps to most directly. BLS counted 182,800 of these jobs in 2024 and projects 29 percent growth to 2034, adding 52,100 positions. CompTIA lists cyber defense analyst and vulnerability analyst among the DoD 8140 work roles for Security+.

US median $124,910, or $60.05 per hour (BLS, May 2024)

Security analyst in the information sector

The highest-paying industry for security analysts, ahead of management of companies at $127,840, finance and insurance at $126,970, computer systems design at $126,690 and consulting at $120,050. Computer systems design employs the largest share at 22 percent.

US median $136,390 for information security analysts in the information industry (BLS, May 2024)

Security-focused systems administrator

CompTIA names system administrator and network specialist among the DoD 8140 work roles Security+ satisfies. BLS counted 331,500 of these jobs in 2024, projects a 4 percent decline to 2034, and still expects about 14,300 openings a year as workers leave the occupation.

US median $96,800 for network and computer systems administrators (BLS, May 2024)

Network support with a security remit

The common entry point for candidates who hold Network+ and add Security+ before moving into a dedicated security team. BLS counted 152,700 of these jobs in 2024 and projects 2 percent growth to 2034.

US median $73,340 for computer network support specialists (BLS, May 2024)

Computer network architect

Designing and implementing data communication networks including LANs, WANs and intranets, with security architecture as a core responsibility. BLS lists a bachelor's degree as the typical entry-level education, so this route pairs Security+ with a degree rather than replacing one.

US median $130,390 (BLS, May 2024)

Computer and information systems manager

The furthest destination on this track, planning, coordinating and directing computer-related activities. CompTIA names information security manager and IT project manager among the DoD 8140 work roles Security+ satisfies, and BLS lists a bachelor's degree as typical entry-level education.

US median $171,200 (BLS, May 2024)

Prerequisites & Requirements

  • There are no enforced prerequisites. CompTIA does not require any prior certification, degree or work history to register for SY0-701.
  • CompTIA recommends holding CompTIA Network+ before attempting Security+.
  • CompTIA also recommends two years of experience working in a security or systems administrator job role.
  • A valid exam voucher is required for each attempt, and CompTIA states that candidates must pay the exam price each time they attempt the exam.
  • Two original, valid, unexpired forms of identification are required, with the first and last name matching the registration exactly.
  • Candidates must register using an address in the country where they reside at the time of testing and must test in that same country, unless CompTIA approves an exception in advance by email to its exam security team.
  • OnVUE candidates must use a personal computer and a personal internet or local network connection, running Windows 10 or macOS 14 or higher, with a single display and no virtual machine.
  • Candidates under 18 taking an online exam may present a valid student ID, and a guardian must present a valid ID and give verbal consent during check-in. From 23 June 2026, all minors need parental consent recorded in CompTIA Central before registering.
  • For DoD roles, CompTIA notes that certifications earned after 31 December 2010 are valid for three years and are automatically enrolled in the CompTIA CE Program, and that DoD compliance requirements also apply to government contractors.

Frequently Asked Questions

What is the passing score for Security+?

750 on a scale of 100 to 900. CompTIA sets passing scores through statistical analysis and states they are subject to change. It is the highest cut score of the three foundational CompTIA credentials, above Network+ at 720, A+ Core 2 at 700 and A+ Core 1 at 675.

How many questions are on the exam and how long is it?

A maximum of 90 questions in 90 minutes, mixing multiple choice with performance-based questions. CompTIA publishes a ceiling rather than a fixed count, and does not disclose how many questions are required to pass or how many a candidate answered incorrectly.

Which exam version is current, and is SY0-801 out?

SY0-701 (V7) is the exam CompTIA currently lists on its Security+ certification page, launched on 7 November 2023 with retirement estimated in 2026. CompTIA has published draft Security+ V8 objectives on its Exam Objectives Under Development page, and that page states drafts reflect proposed content, may contain typographical errors or unclear wording, and are revised repeatedly before launch.

What is the Security+ pass rate?

CompTIA does not publish one. Its Exam Development policy states that it is CompTIA policy not to disclose pass rates to any external third party, that its exam content, results data and analyses are classified as highly confidential, and that its exams are criterion-referenced against a cut score rather than norm-referenced. Any percentage quoted elsewhere did not come from CompTIA.

How much does Security+ cost?

CompTIA sells the voucher through its own store and does not publish a single fixed list price on a static page, and prices vary by region and market. Check the CompTIA Store for your country. For comparison, the only retail figure CompTIA has published on its blog is $253 USD per exam for the A+ 220-1101 and 220-1102 series as of 1 February 2024.

Are there ways to reduce the fee?

Yes, and CompTIA publishes them. Actively registered students at four-year institutions in the United States, and some two-year institutions, can get 35 to 55 percent off all products in the CompTIA Store after verifying through SheerID, and no other discount can be stacked on a verified student discount. CompTIA also lists bundles, employer reimbursement, government-sponsored and nonprofit training programmes, eligible 529 plan funds for certain nondegree training and certification exams, and limited-time flash sales.

How long is an exam voucher valid?

Twelve months from the date you received it. CompTIA states the expiration date cannot be extended under any circumstances and that you must register and sit the exam before it expires. A purchased voucher can be used for any version of that certification exam as long as it is used before expiry, which matters if V8 launches while your voucher is live.

What happens if I fail?

You receive a score report listing the exam objectives attached to the questions you answered incorrectly, though not the questions themselves or how many you missed. You then buy another voucher and rebook. CompTIA states that candidates must pay the exam price each time they attempt the exam and that it offers no free re-tests or discounts on retakes.

How long must I wait before retaking?

Nothing between the first and second attempt. Before a third attempt, and before every subsequent attempt, you must wait at least 14 calendar days from the date of your last attempt. CompTIA states these requirements cannot be waived, that a test in violation of the retake policy is invalidated, and that repeat violators are permanently banned from the certification programme.

Can I retake Security+ after passing it?

Not with the same exam code without prior consent from CompTIA. Once you have passed and certified, you must wait for a new exam series before attempting to recertify by examination. For client-proctored exams the wait is 12 calendar months after a first-attempt pass, unless CompTIA has updated the objectives and released a new exam series code.

Does Security+ expire, and how do I renew it?

It is valid for three years from the date you earn it and enrols automatically in CompTIA's Continuing Education programme. Renewing by continuing education takes 50 CEUs across the three-year cycle plus a total CE fee of $150, payable by the expiration date. That is the heaviest CEU load of the three foundational credentials, against 30 for Network+ and 20 for A+. CompTIA sets four tests for a valid CEU: the activity must be an approved CE activity type, at least 50 percent of its content must relate to one or more exam objectives for the certification being renewed, you must hold the required documentation, and it must fall inside your three-year cycle. Submitted CEUs are accepted automatically, with audits performed randomly.

Can I renew Security+ without paying the CE fee?

Yes, by earning a higher-level CompTIA certification. The hierarchy runs SecurityX, then CySA+ and PenTest+, then Security+, then Network+, then A+. Earning CySA+, PenTest+ or SecurityX renews Security+ without additional CE fees, and renewing Security+ in turn renews Network+ and A+. CompTIA notes that CE fees are not waived where the higher certification does not fully renew the lower one.

Does passing Security+ renew my Network+ and A+?

Yes. CompTIA places Security+ above Network+ and A+ in its certification hierarchy, and renewing a higher-level certification automatically renews the lower ones without additional CE fees. That saves 30 Network+ CEUs and $150, plus 20 A+ CEUs and $75, for that cycle.

What identification do I need on exam day?

Two original, valid, unexpired IDs with the first and last name matching your registration exactly on both. The primary must be government-issued with a recent recognisable photo, such as a passport, driving licence or national identity card. The secondary needs at least name and signature or name and a recognisable photo. IDs must be issued by the country you are testing in, unless you present an international travel passport plus a secondary ID. US military-issued IDs are accepted at a physical test centre, including spouse and dependant IDs, but CompTIA states they cannot be used for identity verification with OnVUE under any circumstance, because certain IDs must not by law be photocopied, digitised or captured on camera.

What are the rules for online proctored testing?

You need Windows 10 or macOS 14 or higher, a working webcam, microphone and speaker with no headphones, exactly one display, and at least 6 Mbps download and 2 Mbps upload on a personal connection. Virtual machines, beta operating systems, phones, tablets, watches, smart glasses, second monitors, VPNs, corporate networks and shared or public networks are prohibited. You must be alone in a walled room with a closed door and pass a room scan. CompTIA also prohibits reusing a laptop or workstation already used by another testing candidate.

Can I use a calculator or any reference material?

No. CompTIA's Candidate Agreement prohibits possession in the testing area of books, notes, paper, documents, writing materials, phones, handheld computers, laptops, smart glasses, watches and other electronic devices. Nothing is supplied as an in-exam reference. The agreement also expressly prohibits using any artificial intelligence software, program or application during the examination, or using AI to generate or recreate the exam.

What accommodations are available?

Accommodation requests are handled through Pearson VUE rather than CompTIA directly, and CompTIA states it is committed to complying with applicable laws for individuals with disabilities. ADA accommodations may be available for online proctored exams case by case, and time accommodations online can be handled by closing the browser to stop the clock and resuming within the allotted window. The English as a Second Language accommodation adds 30 minutes for English-delivered exams in non-English-speaking countries where no localised version exists, granted automatically at registration in eligible countries.

How does the score scale work?

CompTIA reports a scaled score on a 100 to 900 range, produced by a mathematical algorithm from what would otherwise be a percentage score, with the cut score set by statistical analysis. CompTIA does not disclose the number of questions required to pass or the number answered incorrectly, which is why 750 does not translate into a fixed percentage of correct answers.

When do results arrive?

Your score appears on screen immediately after you complete the exam. At a test centre the score report is printed and carries your photograph. Online, the report is available in your Pearson VUE account within 24 hours. Your exam information appears in your CompTIA certification account within five business days, and passing triggers a congratulatory email from CompTIA Certmetrics with instructions for accessing your record.

How does Security+ compare with Network+?

Both run 90 minutes with a maximum of 90 questions, but Security+ needs 750 against Network+ at 720. Network+ has five domains of networking with security at 14 percent; Security+ has five domains that are entirely security. CompTIA lists Network+ plus two years of security or systems administration experience as the recommended background for Security+. Renewal is heavier at 50 CEUs against 30, though the $150 CE fee is the same.

Success Stories

Security+ opened doors I didn't know existed. Within 2 months of certification, I landed my dream job in a SOC. Professor Messer's free videos combined with hands-on TryHackMe labs were my winning combination.

Jennifer Martinez

SOC Analyst at CrowdStrike

Score: 812/900

Coming from help desk, I needed something to prove my security knowledge. Security+ did exactly that. The investment in study materials paid back 10x with my salary increase.

David Okonkwo

Information Security Analyst at Bank of America

Score: 789/900

For my government role, Security+ was mandatory. I'm glad it was - the knowledge directly applies to my daily work protecting critical infrastructure.

Amanda Foster

DoD Cybersecurity Specialist

Score: 835/900

Is this the right exam for your situation?

Is Security+ enough to get hired with no experience?

Necessary for many defence and government roles, and sufficient for none on its own.

Government jobs that no longer require a degree, and how they really screen you

Named in DoD Directive 8140, which makes it an eligibility gate rather than a signal.

50% OFF

Pass CompTIA Security+, Guaranteed

94% pass rate on first attempt

500+ Real QuestionsUpdated weekly
Video Walkthroughs20+ hours
Pass or Full RefundGuaranteed
Lifetime AccessFree updates
SAVE $98
$98
$19650% OFF

One-time • Lifetime access

Secure Instant
4.9/5 (2,847 reviews)
30-Day Guarantee, Pass or get 100% refund