Home Blog About
Practice Tests
๐Ÿ“ Matric Mathematics โš—๏ธ Physical Sciences ๐ŸŒฟ Life Sciences ๐Ÿš— K53 Learners Licence โ˜๏ธ AWS Cloud Practitioner ๐Ÿ”’ CompTIA Security+ ๐Ÿฅ NCLEX Nursing ๐ŸŒ General Knowledge ๐Ÿง  IQ & Logic ๐Ÿงฌ Psychology
Privacy Policy Disclaimer
Practice Free
IT Certifications

CompTIA Security+ Study Guide 2026

Complete SY0-701 study guide covering all five domains with key concepts, acronyms, and strategies to pass first time.

📅 May 2026🕑 5 min read📄 ~761 words
๐Ÿ”’
Security+

CompTIA Security+ Study Guide 2026

CompTIA Security+ (SY0-701) is the most widely recognised entry-level cybersecurity certification globally. It is a base...

CompTIA Security+ (SY0-701) is the most widely recognised entry-level cybersecurity certification globally. It is a baseline requirement for many government and defence roles and is respected across all industries. Tour guide covers all five domains with the concepts most likely to appear on the exam.

Domain 1: General Security Concepts (12%)

Domain 2: Threats, Vulnerabilities and Mitigations (22%)

High-yield concepts: Know the differences between malware types, the CIA Triad, and the Shared Responsibility Model cold. These appear in multiple questions.

Domain 3: Security Architecture (18%)

Domain 4: Security Operations (28%)

Largest domain. Focus on:

Domain 5: Security Program Management (20%)

Key Acronyms to Know

Domain breakdown and what to prioritise

CompTIA Security+ SY0-701 has six domains: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), Security Program Management and Oversight (20%). Security Operations is the largest domain โ€” it covers incident response, digital forensics, vulnerability management, identity and access management, and endpoint security. If you have limited time, start here.

The terminology challenge

Security+ is terminology-heavy. You will encounter dozens of acronyms โ€” SIEM, SOAR, EDR, XDR, PKI, MFA, RADIUS, TACACS+, IPsec, TLS, SSH โ€” and the exam tests whether you know what each one does and in which scenario to apply it. The most effective way to learn security terminology is through active recall with flashcards, not passive reading of a textbook. Dragonfly's Security+ flashcard set covers the 100 most frequently tested terms.

Pay particular attention to the distinction between similar-sounding tools and concepts: IDS vs IPS (detection vs prevention), vulnerability scan vs penetration test (passive vs active), symmetric vs asymmetric encryption (speed vs key management), authentication vs authorisation (who you are vs what you can do). These distinctions appear in scenario questions repeatedly.

Performance-based questions

Security+ includes performance-based questions (PBQs) at the start of the exam that require you to complete a task โ€” configure a firewall rule, analyse a network diagram, match access controls to scenarios. These cannot be skipped easily and take longer than standard multiple choice. Mark them and return if you get stuck โ€” spending 20 minutes on one PBQ can cost you time on 10 easier questions.

Cryptography: what you need to know

Security+ cryptography questions test concept, not mathematics. You need to know: symmetric encryption (single shared key, fast, examples: AES, 3DES, DES) vs asymmetric encryption (public/private key pair, slower, examples: RSA, ECC, Diffie-Hellman); hashing (one-way, produces a fixed-length digest, not encryption โ€” SHA-256, MD5); and digital signatures (asymmetric encryption applied to a hash, provides authentication and non-repudiation). PKI (Public Key Infrastructure) combines asymmetric encryption and digital certificates to provide scalable trusted communication.

The most exam-relevant concepts are: which algorithm is appropriate for which use case, what makes a hash collision significant, what the role of a Certificate Authority is, and how TLS uses both symmetric and asymmetric encryption in a single handshake (asymmetric to exchange keys, then symmetric for the session).

Incident response and digital forensics

The Security+ exam includes substantial content on incident response procedures and digital forensics. The incident response lifecycle (Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned) is directly testable. Know each phase, what activities happen in it, and who is responsible. Digital forensics concepts include the order of volatility (capture the most volatile evidence first โ€” RAM before disk before network), chain of custody (maintain integrity of evidence), legal holds, and the difference between a forensic image and a copy.

Security+ in the South African job market

CompTIA Security+ is recognised by South African employers across banking (Standard Bank, FNB, Absa, Nedbank, Capitec), insurance (Discovery, Old Mutual, Sanlam), government departments, and IT managed service providers. It is also a prerequisite for many remote cybersecurity analyst roles with international employers, which is increasingly relevant for South African candidates seeking USD or GBP-denominated salaries. The certification is DoD 8570 compliant โ€” relevant for candidates working with US government contractors or defence-sector organisations operating in South Africa.

Practice Security+ Questions

Free original CompTIA Security+ practice questions with explanations.

Start Security+ Practice
DE
Dragonfly Exam Papers
Content Team ยท South Africa

Our content team has spent years reviewing South African exam papers, IT certification blueprints, and university past papers. Every question is written with one goal: to make the why behind each answer as clear as the answer itself.

Frequently Asked Questions

What domains are in CompTIA Security+ SY0-701?
Six domains: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management and Oversight (20%). Security Operations is the largest domain โ€” focus significant preparation time here.
Is CompTIA Security+ recognised in South Africa?
Yes โ€” widely recognised by South African employers in banking, insurance, government, and IT services. It is also DoD 8570 approved for US government contractor roles, relevant for candidates targeting international opportunities or remote work.
How long does Security+ preparation take?
8 to 12 weeks with some IT background; 12 to 16 weeks without. Security+ is terminology-heavy โ€” build vocabulary through flashcards alongside scenario-based questions. Performance-based questions (PBQs) at the start of the exam require hands-on configuration skills, so include lab practice in your preparation.

๐Ÿ“š Further Reading & Official Sources