he Five Security+ (SY0-701) Exam Domains, Explained



The Five Security+ (SY0-701) Exam Domains, Explained

CompTIA Security+ (SY0-701) is built from five weighted domains, and the weights are the first thing to understand, because they tell you where your study hours pay off. This page walks through each domain, what it tests, and how to allocate your time. For the wider view of the exam, see the full Security+ (SY0-701) guide.

The weights at a glance

  • General Security Concepts — 12 percent
  • Threats, Vulnerabilities, and Mitigations — 22 percent
  • Security Architecture — 18 percent
  • Security Operations — 28 percent
  • Security Program Management and Oversight — 20 percent

Security Operations and Threats together are half the exam. If you are short on time, those two are where to concentrate. But do not skip the smallest domain: General Security Concepts underpins questions everywhere else.

General Security Concepts (12 percent)

The foundation. This domain covers control types (technical, managerial, operational, physical), the CIA triad, the basics of cryptography including PKI and encryption, change management, and physical security elements. It is the smallest domain by weight and often rated the easiest, but every concept here shows up inside questions across the other four domains. Candidates who skip it because it looks basic tend to lose points they did not expect to lose. Learn it early and it makes everything after it easier.

Threats, Vulnerabilities, and Mitigations (22 percent)

The second-largest domain. This is the attacker's side of the exam: malware types, social engineering, common attack techniques, the vulnerabilities they exploit, and the mitigations that stop them. It rewards recognizing patterns, matching an attack to the right defense, and reasoning about indicators rather than memorizing definitions. Solid coverage here also makes the Operations domain easier, since detection and response build on understanding the threats.

Security Architecture (18 percent)

This domain is about secure design: network segmentation, secure protocols, cloud and hybrid architecture, resilience, and zero trust as a design principle rather than a buzzword. Many candidates rate it the trickiest of the five because it asks you to reason about design tradeoffs, not recall facts. Expect scenario questions where more than one answer looks defensible and the best one depends on the architecture described.

Security Operations (28 percent)

The largest domain, and the one that most often decides a pass or fail. It covers the day-to-day work of security: monitoring and logging, incident response, vulnerability management, identity and access operations, and automation. It also carries the most performance-based questions, which appear near the start of the exam. Because it is both the heaviest and the most hands-on, this domain deserves the most study time and the most lab practice. Reading about incident response is not the same as working through a scenario, and this domain tests the difference.

Security Program Management and Oversight (20 percent)

A full fifth of the exam sits here, and it surprises candidates who expect Security+ to be purely technical. This domain covers risk management, governance, compliance, policies, and oversight, the organizational side of security. Give it real attention. It is straightforward to study but easy to underweight, and twenty percent is too much to leave to chance.

Turning the weights into a plan

Match your hours to the weights: most time on Security Operations and Threats, a solid block on Program Management and Architecture, and efficient review cycles on General Security Concepts. Pair the reading with hands-on lab work for the Operations domain in particular. For a week-by-week schedule that applies this allocation, see how to study for Security+, and match your materials to the current exam with CertMaster Study, CertMaster Labs, and CertMaster Practice.