CompTIA Security+ Study Guide 2026
CompTIA Security+ (SY0-701) is the most widely recognised entry-level cybersecurity certification globally. It is a base...
CompTIA Security+ (SY0-701) is the most widely recognised entry-level cybersecurity certification globally. It is a baseline requirement for many government and defence roles and is respected across all industries. Tour guide covers all five domains with the concepts most likely to appear on the exam.
Domain 1: General Security Concepts (12%)
- Security controls: technical, managerial, operational, physical
- Control categories: preventive, detective, corrective, deterrent, compensating
- Cryptography basics: symmetric vs asymmetric, hashing
- PKI: CAs, certificates, digital signatures
- Authentication: MFA, biometrics, tokens
Domain 2: Threats, Vulnerabilities and Mitigations (22%)
- Malware types: virus, worm, Trojan, ransomware, rootkit, spyware, adware
- Attack types: phishing, vishing, smishing, social engineering, MitM, DoS/DDoS
- Application attacks: SQL injection, XSS, CSRF, buffer overflow
- Threat intelligence: IOCs, threat hunting
- Vulnerability scanning vs penetration testing
Domain 3: Security Architecture (18%)
- Network segmentation: DMZ, VLANs, microsegmentation
- Zero trust architecture
- Cloud security: shared responsibility, CASB
- Firewalls, IDS, IPS
- VPN types: site-to-site, remote access, split tunnelling
Domain 4: Security Operations (28%)
Largest domain. Focus on:
- IAM: RBAC, ABAC, least privilege, separation of duties
- Incident response: preparation, detection, containment, eradication, recovery, lessons learned
- Digital forensics: chain of custody, order of volatility
- SIEM: log aggregation, correlation, alerting
- Endpoint security: EDR, DLP, application control
Domain 5: Security Program Management (20%)
- Risk management: risk assessment, risk register, qualitative vs quantitative
- Governance: policies, standards, procedures, guidelines
- Compliance frameworks: NIST, ISO 27001, HIPAA, PCI DSS, GDPR
- Data privacy: PII, PHI, data classification, retention policies
Key Acronyms to Know
- AAA: Authentication, Authorisation, Accounting
- CIA: Confidentiality, Integrity, Availability
- OILRIG: Oxidation Is Loss, Reduction Is Gain (also used in chemistry)
- RBAC: Role-Based Access Control
- SIEM: Security Information and Event Management
- MFA: Multi-Factor Authentication
- PKI: Public Key Infrastructure
Domain breakdown and what to prioritise
CompTIA Security+ SY0-701 has six domains: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), Security Program Management and Oversight (20%). Security Operations is the largest domain โ it covers incident response, digital forensics, vulnerability management, identity and access management, and endpoint security. If you have limited time, start here.
The terminology challenge
Security+ is terminology-heavy. You will encounter dozens of acronyms โ SIEM, SOAR, EDR, XDR, PKI, MFA, RADIUS, TACACS+, IPsec, TLS, SSH โ and the exam tests whether you know what each one does and in which scenario to apply it. The most effective way to learn security terminology is through active recall with flashcards, not passive reading of a textbook. Dragonfly's Security+ flashcard set covers the 100 most frequently tested terms.
Pay particular attention to the distinction between similar-sounding tools and concepts: IDS vs IPS (detection vs prevention), vulnerability scan vs penetration test (passive vs active), symmetric vs asymmetric encryption (speed vs key management), authentication vs authorisation (who you are vs what you can do). These distinctions appear in scenario questions repeatedly.
Performance-based questions
Security+ includes performance-based questions (PBQs) at the start of the exam that require you to complete a task โ configure a firewall rule, analyse a network diagram, match access controls to scenarios. These cannot be skipped easily and take longer than standard multiple choice. Mark them and return if you get stuck โ spending 20 minutes on one PBQ can cost you time on 10 easier questions.
Cryptography: what you need to know
Security+ cryptography questions test concept, not mathematics. You need to know: symmetric encryption (single shared key, fast, examples: AES, 3DES, DES) vs asymmetric encryption (public/private key pair, slower, examples: RSA, ECC, Diffie-Hellman); hashing (one-way, produces a fixed-length digest, not encryption โ SHA-256, MD5); and digital signatures (asymmetric encryption applied to a hash, provides authentication and non-repudiation). PKI (Public Key Infrastructure) combines asymmetric encryption and digital certificates to provide scalable trusted communication.
The most exam-relevant concepts are: which algorithm is appropriate for which use case, what makes a hash collision significant, what the role of a Certificate Authority is, and how TLS uses both symmetric and asymmetric encryption in a single handshake (asymmetric to exchange keys, then symmetric for the session).
Incident response and digital forensics
The Security+ exam includes substantial content on incident response procedures and digital forensics. The incident response lifecycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) is directly testable. Know each phase, what activities happen in it, and who is responsible. Digital forensics concepts include the order of volatility (capture the most volatile evidence first โ RAM before disk before network), chain of custody (maintain integrity of evidence), legal holds, and the difference between a forensic image and a copy.
Security+ in the South African job market
CompTIA Security+ is recognised by South African employers across banking (Standard Bank, FNB, Absa, Nedbank, Capitec), insurance (Discovery, Old Mutual, Sanlam), government departments, and IT managed service providers. It is also a prerequisite for many remote cybersecurity analyst roles with international employers, which is increasingly relevant for South African candidates seeking USD or GBP-denominated salaries. The certification is DoD 8570 compliant โ relevant for candidates working with US government contractors or defence-sector organisations operating in South Africa.
Practice Security+ Questions
Free original CompTIA Security+ practice questions with explanations.
Start Security+ Practice