CompTIA Security+ is the certification most people use to prove they can do cyber security work rather than just talk about it. It is vendor-neutral, it has no formal prerequisites, and it appears in UK job adverts for SOC analyst, security administrator and junior security engineer roles more often than almost anything else at entry level. It is also a step up from the CompTIA exams below it — not because the content is exotic, but because a third of it asks you to do something rather than pick an answer. This guide covers the current exam, the five domains, the performance-based questions, and how to prepare.
The short answer
The current Security+ exam is SY0-701. You get up to 90 questions in 90 minutes, a mix of multiple choice and performance-based simulations, and you need 750 on a scale of 100–900 to pass. There are no formal prerequisites, though CompTIA recommends Network+ and around two years of hands-on security or systems administration experience first.
- Exam code SY0-701 (Security+ V7)
- Questions maximum 90 — multiple choice plus performance-based
- Time 90 minutes
- Pass score 750 on a 100–900 scale
- Prerequisites none formally; Network+ and ~2 years' experience recommended
- Launched November 2023
- Certification validity three years, renewable through CompTIA's continuing education programme
The five domains
The weightings matter, because they are uneven enough to change how you should allocate revision time.
| Domain | Weight |
|---|---|
| 1.0 General Security Concepts | 12% |
| 2.0 Threats, Vulnerabilities and Mitigations | 22% |
| 3.0 Security Architecture | 18% |
| 4.0 Security Operations | 28% |
| 5.0 Security Program Management and Oversight | 20% |
1.0 General Security Concepts (12%)
The smallest domain and the conceptual foundation. Security controls by category (technical, managerial, operational, physical) and by type (preventive, deterrent, detective, corrective, compensating, directive) — a classic exam trick is to give you a control and ask for both classifications. Then the CIA triad, non-repudiation, AAA, zero trust, defence in depth, and the cryptographic building blocks: symmetric versus asymmetric, hashing, digital signatures, PKI, certificates.
2.0 Threats, Vulnerabilities and Mitigations (22%)
Threat actors and their motivations, attack surfaces and vectors, the full catalogue of attack types (injection, XSS, on-path, replay, privilege escalation, supply chain, social engineering), indicators of compromise, and the mitigation techniques you apply. This domain is heavy on recognition — a scenario describes symptoms and you name the attack.
3.0 Security Architecture (18%)
Securing infrastructure: cloud, on-premises, hybrid, virtualisation, IoT, ICS/SCADA and embedded systems. Network segmentation, secure protocols, firewalls and their placement. Data classification, data states and protection methods. Resilience and recovery — high availability, backups, site considerations, and testing your recovery plan rather than assuming it works.
4.0 Security Operations (28%)
The biggest domain, and the one closest to a real security job. Hardening, secure baselines, asset management, vulnerability management (scanning, analysis, remediation, validation, reporting), monitoring and alerting, SIEM, identity and access management, automation, incident response, and digital forensics. If you only have time to be genuinely strong in one domain, make it this one.
5.0 Security Program Management and Oversight (20%)
The governance half: security policies and standards, risk management (identification, assessment, analysis, register, appetite, tolerance), third-party and vendor risk, compliance, audits and assessments, and security awareness. Candidates from a technical background routinely under-prepare this domain and it is a fifth of the paper.
Find your weakest domain before exam day
PassNova's Security+ bank has 300 exam-style questions mapped to all five SY0-701 domains, each with a clear explanation. The first 15 are free — no account needed.
Performance-based questions
PBQs are what makes Security+ harder than a straight multiple-choice exam, and they are what catches out people who prepared with flashcards alone.
A PBQ puts you in a simulated interface or gives you a task to complete: configure firewall rules, match attack types to log entries, place security controls into a network diagram, analyse output and identify the compromise. There is no option list to reason backwards from. You either know how the thing works or you do not.
Three practical points:
- PBQs come first. They are typically front-loaded, which is exactly when it is most tempting to sink twenty minutes into one. Do not. Flag anything that resists you after a few minutes, clear the multiple-choice questions, then come back with the remaining time.
- Partial credit generally applies. An incomplete PBQ attempt is worth more than a blank one — always leave something.
- Read logs and outputs slowly. Most PBQ errors are misread evidence rather than missing knowledge. The answer is usually visible in the output if you stop skimming.
Is SY0-701 about to be replaced?
CompTIA typically refreshes Security+ on a roughly three-year cycle, and SY0-701 launched in November 2023 — so a successor version is widely expected. As things stand, CompTIA has not published a retirement date for SY0-701, and every specific date circulating online is a third-party estimate rather than an announcement.
What that means practically: if you are ready now, sit SY0-701 now. CompTIA normally runs an overlap of several months after a new version becomes generally available, and a certification earned under the current code does not become less valid when the next one appears. Waiting for a version that has no confirmed date is the worse plan. Check the official CompTIA Security+ page for the current exam code and any announcement before you book.
Where Security+ sits in the CompTIA path
CompTIA's certifications stack, and Security+ sits at the point where general IT becomes security-specific.
- A+ — the IT support foundation: hardware, operating systems, basic networking, troubleshooting. The starting point if you are new to IT entirely.
- Network+ — networking fundamentals. Recommended before Security+ because a lot of Security+ assumes you already understand subnets, ports, protocols and routing.
- Security+ — the cyber security baseline. This one.
- CySA+ — the defensive next step: threat detection, analysis and response, aimed at SOC analyst work.
- PenTest+ — the offensive next step: penetration testing and vulnerability assessment.
- Cloud+ — cloud infrastructure, if your work is heading that way.
Beyond CompTIA, the usual progression is towards CISSP for security leadership (which requires five years of paid experience) or CISM for security management. CEH is the common alternative to PenTest+ on the offensive side. None of those are sensible before Security+.
Six timed mocks and a downloadable study guide
The full 300-question Security+ bank, an AI study tutor and a PDF study guide come with PassNova Premium — £4.99/month, 7-day free trial.
How to prepare
1. Weight your study to the domains. Security Operations is 28% and General Security Concepts is 12%. Those are not equal and your revision timetable should not treat them as such.
2. Do not skip the governance domain. Domain 5 is 20% of the paper — risk registers, appetite versus tolerance, third-party assessments, compliance. Technical candidates find it dry and skim it, then lose a fifth of the exam. Learning the vocabulary precisely is most of the work.
3. Practise PBQs deliberately. Read real log output. Work through firewall rule sets. If you have no lab access, even reading and explaining sample outputs out loud builds the habit of extracting evidence rather than pattern-matching.
4. Learn acronyms in context. Security+ is acronym-dense, and the exam will use the acronym without expanding it. But learning that "SAML" stands for something is worthless; learning that it carries authentication assertions between an identity provider and a service provider is the mark.
5. Sit full 90-minute mocks. Ninety questions in ninety minutes is one minute each, with PBQs eating far more than that. Pacing is a genuine skill on this exam and it only comes from full-length practice.
Frequently asked questions
How many questions are on the Security+ exam?
A maximum of 90, in 90 minutes, mixing multiple-choice and performance-based questions. Not every sitting reaches 90.
What is the Security+ pass mark?
750 on a scale of 100 to 900. That is a scaled score, not a percentage — it does not mean you need 83% of the questions right.
Do I need Network+ before Security+?
Not formally. CompTIA recommends it, and the recommendation is sound: Security+ assumes working knowledge of ports, protocols, subnetting and routing. If networking is genuinely new to you, Network+ first will make Security+ considerably easier.
How long does Security+ take to study for?
With relevant IT experience, most candidates take somewhere between six and ten weeks of consistent part-time study. From a standing start with no IT background it takes longer — and A+ and Network+ first is usually the faster overall route.
Does Security+ expire?
The certification is valid for three years and can be renewed through CompTIA's continuing education programme — by earning CE units, or by passing a higher-level CompTIA certification. Check CompTIA's current renewal terms, as the details change.
Is Security+ worth it in the UK?
It is one of the most frequently named certifications in UK entry-level cyber security job adverts, and it is vendor-neutral, so it is not tied to one employer's stack. It will not by itself get you a security job without any experience — but it is the credential most often used to filter applications, so not having it is a real disadvantage.
The bottom line
Security+ is a broad, practical exam that rewards understanding over memorisation, and the performance-based questions are the part that decides most results. Weight your revision towards Security Operations, refuse to skip the governance domain, practise reading real output, and sit full-length timed mocks until the clock is a non-issue.
Practise with PassNova's Security+ questions — 300 items mapped to the five SY0-701 domains, six timed mocks, and an explanation on every answer. The first 15 questions are free to try without an account.