CompTIA Security+ SY0-701: A Practical Study Roadmap
How to structure Security+ SY0-701 prep around the five domains, PBQs, and high-yield habits—without drowning in acronyms.
You open a practice exam on a Tuesday night. Question 14 asks whether a SIEM alert about impossible travel should trigger containment or eradication first. Question 31 wants the best compensating control when legacy equipment cannot run MFA. Question 47 is a drag-and-drop firewall rule PBQ. You realize you studied flashcards alphabetically—AES, ABAC, AUP—but never built a map from scenario → domain → control type → next step. That gap is exactly what SY0-701 is designed to expose.
This post is a study roadmap, not a promise that reading alone passes the exam. It shows how to weight your time against the five domains, when to start PBQ practice, how to tell the difference between "I recognize the term" and "I can decide under pressure," and what to do with the score report whether you pass or need to go back.
What SY0-701 actually measures
CompTIA positions Security+ SY0-701 for people who can assess security posture, operate in hybrid environments, apply basic GRC thinking, and participate in incident response. The exam runs roughly 90 questions in 90 minutes, mixing standard multiple-choice with performance-based questions (PBQs). The passing score is 750 on a 900-point scale.
The critical detail most candidates miss is domain weighting. Your calendar should reflect it:
| Domain | Weight | Why it matters for your schedule |
|---|---|---|
| 1.0 General Security Concepts | 12% | Foundational vocabulary—short on points, long on reuse |
| 2.0 Threats, Vulnerabilities, and Mitigations | 22% | Second-largest slice; scenario-heavy |
| 3.0 Security Architecture | 18% | Cloud, segmentation, resilience—diagram thinking |
| 4.0 Security Operations | 28% | Largest domain—IAM, monitoring, IR, vuln mgmt |
| 5.0 Security Program Management and Oversight | 20% | Risk, policy, third-party, awareness |
Domain 4 at 28% means that if you spend equal weeks on CIA triads and SIEM tuning, you under-invested in operations by a wide margin. Domain 1 is only 12%, but every other domain assumes you know preventive versus detective controls, hashing versus encryption, and basic IAM terms. Skipping Domain 1 creates friction everywhere else because its vocabulary is the grammar every later scenario speaks.
How this series covers the blueprint
Each post in this series maps to a domain or cross-cutting theme. Use this table to locate the deep-dive chapter you need rather than reading the series linearly.
| Post | Slug | Domain / Focus |
|---|---|---|
| 02 | security-controls-cia-aaa | Domain 1 — Controls, CIA, AAA, Zero Trust vocabulary |
| 03 | cryptography-pki-for-security-plus | Domain 1 — Cryptography, PKI, key custody |
| 04 | threat-actors-vectors-social-engineering | Domain 2 — Actors, attack vectors, social engineering |
| 05 | vulnerabilities-iocs-mitigations | Domain 2 — Vulnerability classes, IoCs, mitigation mapping |
| 06 | zero-trust-and-secure-architecture | Domain 3 — Cloud, segmentation, secure design |
| 07 | data-protection-and-enterprise-resilience | Domain 3 — Encryption scope, backups, continuity |
| 08 | iam-monitoring-and-hardening | Domain 4 — IAM lifecycle, SIEM, endpoint controls |
| 09 | incident-response-vulnerability-management | Domain 4 — IR phases, vuln scanning, forensics basics |
| 10 | governance-risk-compliance-awareness | Domain 5 — Risk, policy, third-party, GRC |
| 11 | security-plus-acronyms-that-matter | Cross-domain — Acronym decision patterns |
| 12 | security-plus-exam-day-and-pbqs | Exam strategy — PBQ mechanics, time management |
Use the roadmap post for scheduling; use those chapters for depth. They are not a substitute for objectives-aligned practice questions—CompTIA's published objectives remain the scope contract.
Building a 7-week plan that respects the weights
Assume you can invest 10–12 hours per week and you already have networking basics at the Network+ level. The table below shows primary focus, a secondary touch to sustain earlier material, and one concrete output per week that tells you whether you understood something or merely read it.
| Week | Primary focus | Secondary touch | Measurable output |
|---|---|---|---|
| 1 | Domain 1: controls, CIA/AAA, crypto vocabulary | Skim full objective list | Classify 20 controls by category and type |
| 2 | Domain 2: actors, vectors, vulnerability classes | Domain 1 review quiz | Write actor + vector + mitigation for 10 scenarios |
| 3 | Domain 3: architecture, cloud, resilience | Start PBQs—firewall or ACL style | Draw one hybrid network with trust zones labeled |
| 4 | Domain 4 part 1: IAM, MFA, PAM, SSO | PBQ drill | Explain why SSO ≠ authorization without notes |
| 5 | Domain 4 part 2: SIEM, EDR, IR lifecycle | Timed 25-question set | Walk detection through recovery aloud |
| 6 | Domain 5: risk, policy, audits, vendor risk | Weak-domain repair | Draft a qualitative risk matrix example |
| 7 | Full mixed practice + PBQs | Exam-day logistics | Two timed half-exams, scored and reviewed |
If you already work in a SOC, invert weeks five and six with week one: front-load GRC and architecture gaps instead of re-reading syslog formats you see daily.
PBQs: time budget and the flag-and-return discipline
PBQs simulate real tasks—ordering IR steps, configuring access rules, reading logs, placing controls on a network diagram. Candidates who train only on multiple-choice question banks often panic when a PBQ appears because the time economics are different: a drag-and-drop or simulation item can consume five to eight minutes without feeling like it. In a 90-minute exam where the average pace is roughly a minute per question, two or three heavy PBQs can erase the comfortable buffer most candidates assume they have.
Start PBQ practice no later than week three. Early PBQs build mechanical confidence—drag-and-drop, matching, rule ordering—so the interface is familiar before exam day. In weeks five through seven, mix PBQs into the same timed session as multiple-choice so you experience the fatigue pattern rather than treating each question type as a separate rehearsal that never competes for the same clock.
On exam day, read the entire PBQ prompt before interacting with it. Partial credit exists on some interactive items; completing three-quarters of a task correctly beats leaving it blank after spending four minutes in confusion and walking away. If you reach a PBQ that looks genuinely unfamiliar, flag it and return. The interface supports this, and a fresh look after clearing a run of straightforward multiple-choice questions sometimes unlocks the reasoning that first-contact stress blocked. The weaker strategy is planting yourself on one difficult interactive item for ten minutes while your time margin evaporates. A flagged PBQ with a best-effort answer costs you far less than an abandoned block of standard questions you would have answered correctly on a calmer pass.
Study judgment—three scenarios where weak and strong diverge
Two weeks before the exam, Domain 5 scores 45% on practice sets. The weak move is opening the Domain 5 textbook chapter, reading forty pages, and calling it covered. Reading without forcing retrieval produces a feeling of familiarity but not actual recall under timed conditions. The strong move is identifying the three or four objective phrases where your miss rate is highest—risk calculation methods, third-party assessment types, policy hierarchy—and running 20-question focused sets with immediate answer review. Forty-five minutes of targeted retrieval practice outperforms two hours of re-reading material you already encountered in week six.
Question 31 asks the best compensating control when legacy equipment cannot run an agent-based EDR. The weak answer reaches for the most technically sophisticated option on the list: deploy a SIEM correlation rule. The strong answer reads the constraint first. The equipment cannot run an agent, so all agent-dependent controls are disqualified before you evaluate them. Network isolation plus a dedicated jump host with strict authentication and logging is a legitimate compensating control when the preferred control is impossible to implement. The exam signals this with words like "cannot," "legacy," or "unsupported platform." Candidates who miss this pattern tend to answer the question they wished were asked rather than the one on the screen.
After a second exam attempt, you score 763 but Domain 3 shows a low performance band. Passing is passing, and 763 clears the 750 threshold. But the score report's objective-area breakdown is a diagnostic, not a receipt. A low Domain 3 band tells you that cloud architecture and segmentation questions were your floor—not a reason to retake, but a direct pointer to the professional development that certification prep compressed into two weeks of survey-level study. Many practitioners find that narrow margins on architecture domains predict exactly the friction they feel six months later when a job requires real cloud segmentation decisions. Reading the score report as a learning signal rather than a verdict is how certification prep pays forward into practice.
The retake loop—if you need one
If you do not pass, the score report hands you the repair list. Every domain band that shows below target is a chapter you covered but did not convert to decision quality. The mistake to avoid is re-reading the same material in the same way and expecting a different result on the same timeline.
The approach that works is diagnostic sorting. Review your incorrect answers and classify each one as a knowledge gap (the concept was never learned), a misread (you knew the material but rushed the stem), or a trap (a distractor exploited a fuzzy distinction between neighboring concepts). Only knowledge gaps need new content. Misreads need stem-reading discipline—slow down on scenario questions, identify the verb: "best prevents," "first step," "most likely." Trap patterns need explicit documentation: write out the distractor you chose and the correct answer side-by-side, then articulate in one sentence why the exam preferred the other option.
CompTIA enforces a waiting period before a retake. That interval is not time for the material to rest—it is time to run focused practice on the exact objective bands that scored low, ideally with a mix of fresh question sources you have not already memorized. Candidates who pass on a retake generally do not re-read the book cover to cover; they drill the specific decisions they could not make under timed pressure until those decisions become automatic.
Common exam traps across the blueprint
| Trap | What the exam wants | What candidates pick instead |
|---|---|---|
| "Best" vs "first" in IR | Containment before eradication when spread is still active | Jump to wipe and rebuild |
| Similar-sounding controls | Match purpose—prevent/detect/correct | Match buzzword familiarity |
| Crypto goal | Encryption for confidentiality; hashing for integrity | "Encrypt passwords" (should be salted hashes) |
| Zero Trust | Continuous verification, microsegmentation, no implicit LAN trust | "Install a firewall" alone |
| Risk terms | Threat exploits vulnerability; risk weighs likelihood and impact | Use the three terms interchangeably |
| Compensating control | Acceptable alternative when the primary control is impossible | Extra control added because you felt like it |
| "Temporary" privilege | Time-bound least privilege via PAM with approval and audit | "We'll clean it up after the incident" |
Another pattern worth memorizing: "best" and "first" are not synonyms. A question asking what you should do first during an active incident usually wants containment even if eradication would be the best long-term answer. A question asking best prevents recurrence usually wants root-cause elimination, not a compensating control. The verb in the question stem is the instruction; the answer choices are evaluated against it, not against your general preference for certain security tools.
What ready feels like
You are approaching readiness when you can place a scenario in the correct domain and control type in under 20 seconds, define vulnerability, threat, and risk without circular definitions, narrate an incident from detection through lessons learned with correct phase verbs, and choose among TPM, HSM, hashing, salting, and digital signatures for a stated goal without second-guessing yourself. Readiness is not "I finished all the videos." It is stable performance on mixed, timed sets near passing range with reviewed weak areas trending upward over successive sessions.
Carry one mental habit into the exam room: when a question feels ambiguous, identify what property is at stake—confidentiality, integrity, availability, non-repudiation—and what action the stem is asking for—prevent, detect, correct, respond. Most distractors collapse when you apply those two filters before reading the answer choices.
Exam traps summary
| Trap | Reality check |
|---|---|
| Equal time across domains | Domain 4 at 28% deserves 28% of your calendar, not 20% |
| Finishing all videos = ready | Stable performance on timed mixed sets is the signal; video completion is not |
| PBQs are just longer questions | They consume 5–8 minutes each; budget them explicitly or they steal your margin |
| "Compensating" means "extra" | Compensating controls substitute when the primary cannot be implemented |
| Score report is pass/fail only | The objective-band breakdown is a professional development roadmap |
| Re-reading fixes a retake | Diagnostic sorting by miss type—knowledge, misread, trap—outperforms re-reading |
| "Best" and "first" are interchangeable | The verb in the stem is the instruction; read it carefully every time |
Closing frame
Domain weights are a study budget. PBQs are a skill with a time cost, not a surprise. Weak/strong distinctions separate instinct from judgment, and judgment is what 90 minutes at 90 questions tests. Build the schedule around the weights, start PBQs early enough to make them comfortable, and treat the score report—whether from a practice exam or the real thing—as a diagnostic rather than a verdict.
The exam is designed to reward practitioners who can reason under pressure, not practitioners who memorized the most acronyms in the right font. Build the map from scenario to domain to control type to next step, and question 14 about impossible travel becomes a classification exercise rather than a guess.
Companion reading: the Exam Day Strategy and PBQs post for specific PBQ mechanics and timing technique, and the IAM, Monitoring, and Hardening post for the decision patterns inside the largest domain.