EVIDENCE · NOT SCORES
SIGN IN
← ALL CERTIFICATIONS

COMPTIA

CompTIA Security+ — a plan built from evidence

Work the exam blueprint one mission at a time. Leave a record of what you can do — not a number that guesses at it.

SECURITY+EXAM SY0-701BLUEPRINT SY0-701

BUILD MY CERTIFICATION PATH

WHERE YOU ARE COMING FROM

Coming in from another field

You do not need a security job to start. Begin with the blueprint, then work the hands-on missions in the order your evidence says to. You finish with a record you can walk into an interview and talk through.

Already working in IT

You know a lot of this. The plan starts from what the coach sees you do. Your time goes to the domains where your evidence is thin — not to a course that re-teaches your day job.

Teaching or mentoring others

Every domain maps to the concepts underneath it, and each learner keeps their own evidence map. Use it to see where a cohort is thin before the exam window, not after.

WHY THIS PATH
  • The exam blueprint is the map. Every mission traces to a published domain and objective, so you always know why you are doing the thing you are doing.
  • Evidence is observed, not self-reported. Four states, and each one points back to work you did in a lab, a terminal, or a conversation.
  • Add or move your exam date anytime. The plan adjusts. Your progress is never lost.
EXAM BLUEPRINT

The published domains and objectives for SY0-701. Your missions come from these objectives, and your progress is recorded against them.

  • 12%

    1.0

    General Security Concepts

    • 1.1Security control categories and functions
    • 1.2Fundamental security concepts
    • 1.3Security impacts of change management
    • 1.4Appropriate cryptographic solutions
  • 22%

    2.0

    Threats, Vulnerabilities, and Mitigations

    • 2.1Threat actor attributes and motivations
    • 2.2Threat vectors and attack surfaces
    • 2.3Vulnerability types
    • 2.4Indicators of malicious activity
    • 2.5Enterprise mitigation techniques
  • 18%

    3.0

    Security Architecture

    • 3.1Security implications of architecture models
    • 3.2Security principles for enterprise infrastructure
    • 3.3Data protection concepts and strategies
    • 3.4Resilience and recovery architecture
  • 28%

    4.0

    Security Operations

    • 4.1Security techniques for computing resources
    • 4.2Hardware software and data asset management
    • 4.3Vulnerability management activities
    • 4.4Security alerting and monitoring
    • 4.5Enterprise security capability changes
    • 4.6Identity and access management
    • 4.7Security automation and orchestration
    • 4.8Incident response activities
    • 4.9Investigation data sources
  • 20%

    5.0

    Security Program Management and Oversight

    • 5.1Effective security governance
    • 5.2Risk management process
    • 5.3Third-party risk management
    • 5.4Effective security compliance
    • 5.5Audits and security assessments
    • 5.6Security awareness practices