TCL Portal

CompTIA Security+ Exam Domains Explained: The Full SY0-701 Breakdown

By: Sekiko Jo Published:
  • #Security+
  • #CompTIA
  • #Exam Domains
  • #Security Certification
  • #CISSP

Part of our CompTIA Security+ Hub 2026 series.

When people ask me what’s actually on the Security+ exam, they usually already have a vague sense that it’s “network security stuff.” That’s not wrong, but it undersells how much the current version — SY0-701 — has shifted toward operational judgment rather than pure terminology recall. If you’re prepping from an older study guide built around SY0-601, the domain structure has changed enough that it’s worth re-reading before you build a study plan.

This is a domain-by-domain breakdown: what each one actually tests, why the weighting is what it is, and where candidates consistently lose points.

Security+ Exam Domain Breakdown

CompTIA’s official exam objectives for SY0-701 define five domains (CompTIA Security+ certification page):

DomainWeight
1. General Security Concepts12%
2. Threats, Vulnerabilities, and Mitigations22%
3. Security Architecture18%
4. Security Operations28%
5. Security Program Management and Oversight20%

1. General Security Concepts (12%) is the foundation domain — security controls (technical, managerial, operational, physical), the CIA triad, non-repudiation, zero trust concepts, and the basic vocabulary the rest of the exam assumes you already have. It’s the smallest domain by weight, but candidates who rush it tend to misread scenario questions later because they blur terms like “compensating control” and “detective control.”

2. Threats, Vulnerabilities, and Mitigations (22%) covers threat actors and their motivations, attack surfaces, types of vulnerabilities (application, cloud, supply chain), and the mitigation techniques that pair with each. This domain rewards pattern-matching — knowing which mitigation goes with which threat type — more than memorizing attack names.

3. Security Architecture (18%) is about designing secure systems: cloud vs. on-premise security implications, infrastructure hardening, data protection strategies, and resilience/recovery design. This domain has grown in emphasis compared to older Security+ versions, reflecting how much day-to-day security work now happens in cloud and hybrid environments rather than in a single on-prem network.

4. Security Operations (28%) is the largest domain and the one most likely to include performance-based questions — the simulation-style items where you configure a setting or interpret a log rather than pick from four answers. It covers hardening techniques, incident response, digital forensics basics, and security monitoring (SIEM, alerting, vulnerability management). This is the domain where hands-on lab time pays off more than flashcards do.

5. Security Program Management and Oversight (20%) covers governance, risk management, third-party risk, compliance, and security awareness training. It’s the domain that most resembles “management thinking” rather than technical configuration, and it’s also the domain that overlaps most with what CISSP tests at a much deeper level (see below).

Which Domains Are Hardest for Candidates

In my experience mentoring people through this exam, Domain 4 (Security Operations) is where the most candidates get surprised — not because the material is conceptually hard, but because it’s tested through scenarios and simulations rather than definition recall. You can read about incident response phases for weeks and still freeze on a performance-based item that asks you to actually triage a log excerpt.

Domain 5 (Security Program Management and Oversight) is the second common stumbling block, for a different reason: candidates coming from a purely technical background (sysadmins, help desk, network techs) often haven’t been exposed to formal risk management vocabulary — risk appetite, risk tolerance, qualitative vs. quantitative risk assessment — and it reads like a foreign language on first pass.

Domain 2 (Threats, Vulnerabilities, and Mitigations) trips people up in a quieter way: there are a lot of similarly-named attack types and mitigations, and the exam likes to test whether you can match the right mitigation to a specific scenario rather than just recognize a term.

How Domains Map to Real Job Tasks

The domain weights aren’t arbitrary — they roughly mirror how time actually gets spent in an entry-to-mid-level security or IT role:

That last point matters for career planning, not just exam prep: a Security+ holder who’s comfortable talking through Domain 5 material is already exercising a muscle that becomes central at the CCSP and CISSP level.

A practical way to think about it, if you’re currently studying: don’t treat the five domains as five separate study blocks to be checked off in isolation. Build a study plan that spends time proportional to weight — roughly twice as long on Security Operations as on General Security Concepts — but layer in a second pass where you deliberately connect domains to each other. A phishing scenario question, for example, might touch Domain 2 (the threat and mitigation), Domain 4 (how your SOC would detect and respond to it), and Domain 5 (whether your security awareness training program should have prevented it in the first place). Exam writers build cross-domain scenarios on purpose, and candidates who studied domains as silos are the ones who get thrown by them.

What Changed From SY0-601 to SY0-701

If you’re studying from older material, it’s worth knowing explicitly what shifted. SY0-601 had a similar five-domain structure but different weighting and emphasis — the current SY0-701 version reduced the total number of objectives from 35 to 28 while keeping five domains, and shifted more weight toward operational and architecture content that reflects how much security work now happens in cloud-native and hybrid environments rather than a single flat corporate network. If your study guide, practice test bank, or course was built for SY0-601, double-check it’s been updated — vendors sometimes leave old material live even after CompTIA retires the exam version, and it’s an easy way to waste study hours on outdated weighting.

A Note on Studying for the Weight, Not Just the Topic List

One mistake I see often: candidates read the objectives document, see five domains, and assume equal study time makes sense because there are “five things to learn.” The weighting exists precisely because that assumption is wrong. Security Operations at 28% deserves roughly seven times the study attention General Security Concepts at 12% gets on a strict proportional basis — and while I wouldn’t follow that ratio with mathematical precision, treating all five domains as equally important is a common and avoidable way to underperform on exam day. If you only have time to build hands-on lab familiarity with one domain before the exam, make it Security Operations; it’s both the heaviest-weighted and the one most likely to test you through simulation rather than multiple choice.

How This Compares to CCSP/CISSP Domain Structure

Security+, CCSP, and CISSP all test overlapping subject matter — access control, risk, incident response, architecture — but they carve it up differently because they’re built for different points in a career.

CISSP splits security knowledge into eight domains (full breakdown here), each weighted between 10% and 16%, and every domain assumes you’re accountable for a security program, not just executing tasks within one. Security and Risk Management alone is 16% of CISSP — roughly the same relative emphasis Security+ gives its entire “Program Management and Oversight” domain, except CISSP goes several levels deeper into governance, legal, and business-continuity judgment.

CCSP takes a narrower slice — cloud security specifically — and organizes it into six domains covering cloud architecture, data security, platform and infrastructure security, application security, operations, and legal/risk/compliance. Its domain structure assumes you already have the general security fluency Security+ builds, and it drills into cloud-specific decisions Security+ only touches at a surface level in its Security Architecture domain.

The practical takeaway: Security+‘s five domains are meant to be absorbed by someone with roughly two years of IT experience and no prior security-specific credential. CISSP and CCSP’s domain structures assume you already have that baseline and are being tested on judgment under real accountability — which is also why both require years of documented work experience that Security+ does not.

If you’re trying to figure out which of the three to pursue next, and in what order, the full three-way comparison walks through prerequisites, difficulty, and a recommended sequence by career stage.

Building a Study Schedule Around the Weights

Once the domain weights are clear, the next question people ask is how to actually allocate study time against them. There’s no single correct formula, but a reasonable starting point is to roughly mirror the exam’s own weighting while adding a modest floor for the lightest domain so it doesn’t get neglected entirely.

A candidate studying for 8 weeks at a sustainable pace might allocate something like: one week on General Security Concepts (enough to lock in vocabulary, since everything else depends on it), two weeks on Threats, Vulnerabilities, and Mitigations, one and a half weeks on Security Architecture, two and a half weeks on Security Operations (including dedicated lab time, not just reading), and one week on Security Program Management and Oversight — with the final days reserved for full-length practice exams that mix all five domains together rather than testing them in isolation.

The practice-exam step matters more than it might seem. Domain-isolated practice questions teach you to recognize a domain’s “flavor,” but the real exam deliberately writes scenarios that don’t announce which domain they’re testing. If your practice routine never forces you to identify the domain from context, the real exam will be your first time doing that under time pressure — which is a bad place to encounter it for the first time.

Where This Fits in a Broader Certification Path

Security+ is often the first formal security certification someone earns, but it’s rarely meant to be the last. If you’re mapping out what comes after — and specifically whether the next step should be a cloud-focused credential like CCSP or a broader governance-oriented one like CISSP — the domain structure covered here is a useful reference point. Every domain in Security+ has a deeper, more specialized counterpart in one or both of those credentials: General Security Concepts and Security Program Management foreshadow CISSP’s Security and Risk Management domain, while Security Architecture foreshadows both CCSP’s cloud architecture domain and CISSP’s Security Architecture and Engineering domain, just tested at a level that assumes years of applied judgment rather than foundational familiarity.

Sources

FAQ

How many domains does the Security+ exam have?

The current SY0-701 version has five domains: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management and Oversight (20%).

Which Security+ domain has the most questions?

Security Operations, at 28% of the exam. It's the largest domain by weight and includes many of the performance-based questions, which is why candidates who only study flashcards tend to underperform there.

Is Security+ domain structure similar to CISSP?

They cover overlapping ground — access control, cryptography, risk, operations — but CISSP splits that ground into eight domains aimed at governance-level judgment across a full security program, while Security+ compresses it into five domains aimed at hands-on, entry-to-mid-level competency. Security+ assumes you're doing the work; CISSP assumes you're accountable for the program.

About the authors