Credential type: certification examination · verified on the issuer's site September 19, 2026 issuer page
Scheduled retirement
SY0-701 retires on June 11, 2027
CompTIA prints a retirement date for Security+ SY0-701 on the certification page: 'Retirement: English - June 11, 2027; Japanese, Portuguese, Spanish, and Thai - August 13, 2027' (exam version V7, launched November 7, 2023). No successor exam code is named on the page.
No direct replacement is named in the reviewed official sources.
What This Exam Validates
The CompTIA Security+ certification exam validates standard technical skills across five core security domains to help professionals build practical expertise for daily infrastructure protection and risk response duties. The thorough assessment evaluates your understanding of general security concepts, threats and mitigations, security architecture, security operations, and security program management for modern enterprise environments.
Who Should Take This Exam
IT professionals, security administrators, and network engineers with hands-on technical experience preparing for a career in cybersecurity should take this exam. Candidates benefit from a background in administrative computing and infrastructure support.
Skills You Should Be Ready to Demonstrate
- Security controls
- Threat actors and motivations
- Architecture models
- Computing resources
- Security governance
How to Prepare Before Retirement
Review official exam objectives across all specified domains by utilizing study materials from CompTIA. Practice applying security principles to enterprise environments, and check with CompTIA for further updates to the certification path. Focus your study time heavily on operational controls, asset management, and structured risk management methodologies to ensure thorough preparation for test day.
Domain Study Guidance
General security concepts: Study Guidance
Covers basic security concepts, including the implementation of standard security controls, the management of organizational change, and the understanding of fundamental principles required for securing modern network environments and systems against potential failures.
- Security controls
- Fundamental concepts
- Change management
Threats, vulnerabilities, and mitigations: Study Guidance
Focuses extensively on identifying various threat actors, distinct threat vectors, expanding attack surfaces, and a wide assortment of different types of vulnerabilities that affect modern computing systems and organizational networks today.
- Threat actors and motivations
- Threat vectors and attack surfaces
- Vulnerabilities
Security architecture: Study Guidance
Explores complex architecture models, enterprise infrastructure configurations, and advanced data protection methods designed to secure information assets across distributed corporate networks and cloud environments effectively during daily operations.
- Architecture models
- Enterprise infrastructure
- Data protection
Security operations: Study Guidance
Addresses computing resources management, asset tracking practices, and detailed vulnerability management procedures required to maintain operational stability and rapid incident response readiness within enterprise technology structures across all networks.
- Computing resources
- Asset management
- Vulnerability management
Security program management and oversight: Study Guidance
Deals directly with security governance structures, structured risk management frameworks, compliance requirements, and specific third-party risk considerations necessary for maintaining organizational security posture and oversight across all connected business units.
- Security governance
- Risk management
- Third-party risk
Exam-Day Guidance
Manage your time carefully across the 90 questions within the strict 90-minute limit. Answer straightforward multiple-choice items first, leaving sufficient time for complex performance-based questions.
Frequently asked questions
How many questions are on the exam?
The exam consists of a total of exactly 90 questions, which include multiple-choice items with single or multiple selections as well as performance-based tasks administered during the testing session.
What is the passing score?
The required passing score is 750 on a scale of 100-900. Candidates must meet or exceed this specific target to successfully earn the official certification from CompTIA.
How long is the exam?
Candidates are given a total duration of 90 minutes to complete the linear exam format without extra scheduled breaks during the testing session at the authorized testing center.
What is the cost of the exam?
The official exam price is set at $404.0 USD. Vouchers can be purchased directly through CompTIA or through authorized training partners globally for scheduling your test appointment.
Sources and Verification
Verified 2026-08-30
How this page was made
This informational page was carefully compiled using official exam documentation, precise domain weight breakdowns, and published objectives directly sourced from CompTIA publications.
Exam Domains
1.0 General security concepts
12%
- 1.1Security controls
comparing technical, preventive, managerial, deterrent, operational, detective, physical, corrective, compensating, and directive controls.
- 1.2Fundamental concepts
summarizing confidentiality, integrity, and availability (CIA); non-repudiation; authentication, authorization, and accounting (AAA); zero trust; and deception/disruption technology.
- 1.3Change management
explaining business processes, technical implications, documentation, and version control.
- 1.4Cryptographic solutions
using public key infrastructure (PKI), encryption, obfuscation, hashing, digital signatures, and blockchain.
2.0 Threats, vulnerabilities, and mitigations
22%
- 2.1Threat actors and motivations
comparing nation-states, unskilled attackers, hacktivists, insider threats, organized crime, shadow IT, and motivations like data exfiltration, espionage, and financial gain.
- 2.2Threat vectors and attack surfaces
explaining message-based, unsecure networks, social engineering, file-based, voice call, supply chain, and vulnerable software vectors.
- 2.3Vulnerabilities
explaining application, hardware, mobile device, virtualization, operating system (OS)-based, cloud-specific, web-based, and supply chain vulnerabilities.
- 2.4Malicious activity
analyzing malware attacks, password attacks, application attacks, physical attacks, network attacks, and cryptographic attacks.
- 2.5Mitigation techniques
using segmentation, access control, configuration enforcement, hardening, isolation, and patching.
3.0 Security architecture
18%
- 3.1Architecture models
comparing on-premises, cloud, virtualization, Internet of Things (IoT), industrial control systems (ICS), and infrastructure as code (IaC).
- 3.2Enterprise infrastructure
applying security principles to infrastructure considerations, control selection, and secure communication/access.
- 3.3Data protection
comparing data types, securing methods, general considerations, and classifications.
- 3.4Resilience and recovery
explaining high availability, site considerations, testing, power, platform diversity, backups, and continuity of operations
4.0 Security operations
28%
- 4.1Computing resources
applying secure baselines, mobile solutions, hardening, wireless security, application security, sandboxing, and monitoring.
- 4.2Asset management
explaining acquisition, disposal, assignment, and monitoring/tracking of hardware, software, and data assets.
- 4.3Vulnerability management
identifying, analyzing, remediating, validating, and reporting vulnerabilities.
- 4.4Alerting and monitoring
explaining monitoring tools and computing resource activities.
- 4.5Enterprise security
modifying firewalls, IDS/IPS, DNS filtering, DLP (data loss prevention), NAC (network access control), and EDR/XDR (endpoint/extended detection and response).
- 4.6Identity and access management
implementing provisioning, SSO (single sign-on), MFA (multifactor authentication), and privileged access tools.
- 4.7Automation and orchestration
explaining automation use cases, scripting benefits, and considerations.
- 4.8Incident response
implementing processes, training, testing, root cause analysis, threat hunting, and digital forensics.
- 4.9Data sources
using log data and other sources to support investigations.
5.0 Security program management and oversight
20%
- 5.1Security governance
summarizing guidelines, policies, standards, procedures, external considerations, monitoring, governance structures, and roles/responsibilities.
- 5.2Risk management
explaining risk identification, assessment, analysis, register, tolerance, appetite, strategies, reporting, and business impact analysis (BIA).
- 5.3Third-party risk
managing vendor assessment, selection, agreements, monitoring, questionnaires, and rules of engagement.
- 5.4Security compliance
summarizing compliance reporting, consequences of non-compliance, monitoring, and privacy.
- 5.5Audits and assessments
explaining attestation, internal/external audits, and penetration testing.
- 5.6Security awareness
implementing phishing training, anomalous behavior recognition, user guidance, reporting, and monitoring.
Exam Details
Question TypesMultiple Choice (single), Multiple Choice (multiple), Performance-Based
FormatLinear
Online ProctoringAvailable
ID RequirementsTwo forms of ID are required. Primary ID must be government-issued, include candidate's name, photo, and signature (e.g. passport, driver's license). Secondary ID must include candidate's name and signature or name and photo.
RenewalRequired -- Earn CE credits through CompTIA CE program (training, conferences, publishing, teaching, higher certs) or retake the current exam version before expiry.
PrerequisitesCompTIA Network+; two years of experience working in a security/ systems administrator job role
Retake PolicyNo waiting period required before first retake. After the second failed attempt, candidates must wait 14 calendar days before any subsequent attempt. No limit on total attempts.
LanguagesEnglish, Japanese, Portuguese, Simplified Chinese