πŸ”’ CompTIA Security+ Roadmap

Your complete guide to earning the CompTIA Security+ (SY0-701) certification β€” the industry's leading entry-level cybersecurity credential, covering threat management, cryptography, identity management, and security operations.

πŸ“… 3–4 Months Study
πŸ“ 90 Questions Β· 90 Min
πŸ† Score: 750 / 900
πŸ’Ό DoD 8570.01-M Baseline
🌍 Globally Recognized
🎯 Entry-to-Mid Level | Cybersecurity Analyst / Security+

What is CompTIA Security+?

CompTIA Security+ (SY0-701) is the most widely adopted vendor-neutral cybersecurity certification globally. It validates the core knowledge required of any cybersecurity role and provides a springboard into intermediate-level cybersecurity jobs. It is required by the U.S. Department of Defense for IT positions under DoD 8570.01-M/DoD-M 8140, covering roles such as Information Assurance Technician (IAT) Level II. The 2023 SY0-701 update emphasizes today's critical topics: generative AI threats, hybrid/cloud security, zero trust architecture, and automation in security operations.

πŸ“‹ Recommended Prerequisites

πŸ—ΊοΈ Certification Pathway

CompTIA A+
β†’
CompTIA Network+
β†’
CompTIA Security+
β†’
CySA+ / PenTest+
β†’
CASP+ / CISSP
Exam Blueprint
SY0-701 Domain Breakdown (5 Domains)
Know what's on the exam before you study
Domain 1: General Security Concepts 12%
  • Security controls (technical, operational, managerial, physical) by category and type
  • Cryptography: symmetric, asymmetric, hashing, digital signatures, PKI, certificates
  • Authentication factors and access control models (MAC, DAC, RBAC, ABAC)
  • Zero Trust architecture and identity concepts
Domain 2: Threats, Vulnerabilities & Mitigations 22%
  • Threat actors: nation-state, insider, hacktivist, script kiddie, organized crime
  • Social engineering: phishing, spear phishing, vishing, smishing, pretexting, baiting
  • Malware types: ransomware, worm, Trojan, rootkit, spyware, botnet, fileless/LotL
  • Application vulnerabilities: SQLi, XSS, CSRF, buffer overflow, IDOR, race condition
  • MITRE ATT&CK framework, threat intelligence, CVSS scoring, vulnerability scanning
Domain 3: Security Architecture 18%
  • Network segmentation: VLANs, DMZ, micro-segmentation, air gaps
  • Cloud security: shared responsibility model, SaaS/PaaS/IaaS, CASB, CSPM
  • Firewalls: stateless, stateful, NGFW, WAF; IDS vs IPS
  • Secure network protocols: TLS 1.3, IPSec, SSH, HTTPS, SFTP, DNSSEC
  • Wireless security: WPA2/WPA3, 802.1X, EAP variants, rogue AP detection
Domain 4: Security Operations 28%
  • Endpoint protection: AV, EDR, XDR, application allow-listing, host hardening
  • SIEM & SOAR: log aggregation, correlation rules, automated response playbooks
  • Incident response: NIST phases (Prepare β†’ Detect β†’ Contain β†’ Eradicate β†’ Recover β†’ Post-Incident)
  • Digital forensics: order of volatility, chain of custody, write-blockers, imaging
  • Identity & access management: PAM, MFA, SSO, SAML, OAuth, RADIUS, LDAP
  • Vulnerability management: scanning frequency, CVSS prioritization, patching SLAs
Domain 5: Security Program Management & Oversight 20%
  • Risk management: risk types, quantitative analysis (SLE, ALE, ARO), risk responses
  • Compliance frameworks: NIST CSF, ISO 27001, PCI DSS, HIPAA, GDPR, SOC 2
  • Security policies: policy vs standard vs procedure vs guideline; data classification
  • Third-party and supply chain risk; vendor assessment, right-to-audit clauses
  • Awareness training: phishing simulations, acceptable use policies
  • Privacy concepts: DPA, PII, PHI, data sovereignty, masking, tokenization
Phase 1 Β· Weeks 1–3
Foundations β€” Networking & Security Basics
3 weeks Β· Build the essential knowledge base

Security+ builds heavily on networking knowledge. Start here even if you're coming from Network+, as we frame everything through a security lens.

Core Concepts to Master

OSI model from a security perspective
TCP/IP protocols (TCP, UDP, ICMP, ARP)
Port numbers: 21 FTP, 22 SSH, 25 SMTP, 53 DNS, 80 HTTP, 443 HTTPS, 3389 RDP
Subnetting & CIDR notation
DNS, DHCP, NAT concepts
CIA Triad deep dive
Authentication vs Authorization vs Accounting (AAA)
Encryption: symmetric (AES) vs asymmetric (RSA)
Hashing: MD5, SHA-256, salting
PKI, digital certificates, CAs
Basic Linux command line
Windows Active Directory basics

πŸ“š Study Resources

  • Professor Messer's CompTIA Security+ SY0-701 Course (free on YouTube & professormesser.com)
  • CompTIA Security+ Study Guide by Mike Chapple & David Seidl (Sybex) β€” 8th Edition for SY0-701
  • CompTIA Security+ All-in-One Exam Guide by Wm. Arthur Conklin & Greg White
  • CompTIA Security+ Exam Objectives (SY0-701) β€” free PDF at comptia.org
  • Jason Dion's Security+ course on Udemy (highly rated, scenario-based)

Week 1–3 Strategy

  • Download the official SY0-701 exam objectives and use as your study checklist
  • Create a vocabulary list: learn every acronym (AAA, AES, IPSEC, CVSS, MTTR, RTO, RPO, etc.)
  • Watch Professor Messer's free videos β€” excellent for visual learners
  • Don't memorize port numbers by rote β€” understand WHY each protocol uses that port
Phase 2 Β· Weeks 4–7
Deep Dive β€” Threats, Architecture & Operations
4 weeks Β· Master the bulk of exam content

This phase covers the highest-weight domains. Spend extra time on Domain 4 (Security Operations, 28%) and Domain 2 (Threats, 22%).

Threat & Attack Knowledge

All social engineering types with real examples
Malware family characteristics (ransomware, RAT, rootkit, worm)
OWASP Top 10 vulnerabilities with code examples
SQL injection β€” manual & tool-based identification
XSS (reflected, stored, DOM-based)
CSRF prevention (tokens, SameSite)
Buffer overflow and memory protections (ASLR, DEP)
Fileless malware / LotL techniques (PowerShell, WMI)
APT kill chain (7 phases)
CVSS scoring: base, temporal, environmental
MITRE ATT&CK tactics & techniques
DDoS types: volumetric, protocol, application layer

Security Architecture

Firewall types & stateful inspection
IDS vs IPS, signature vs anomaly detection
Network segmentation: VLAN, DMZ, micro-segmentation
VPN types: IPSec (transport/tunnel), SSL VPN, split tunneling
TLS 1.3 handshake & certificate validation
WPA2 vs WPA3, KRACK vulnerability
Zero Trust principles (verify explicitly, least privilege, assume breach)
SASE (Secure Access Service Edge), SD-WAN
Cloud shared responsibility model
CASB, CSPM, SWG cloud security controls

Security Operations

SIEM: log sources, correlation rules, dashboards
SOAR playbooks and automation
Incident response phases (NIST SP 800-61r2)
Digital forensics: order of volatility
Chain of custody and write-blockers
EDR behavioral detection vs signature AV
Vulnerability scanning tools (Nessus, OpenVAS)
Patch management and hardening baselines
Identity management: PAM, MFA/2FA, SSO, federation
RADIUS, TACACS+, LDAP, SAML, OAuth 2.0, OIDC

πŸ“š Additional Resources

  • TryHackMe.com β€” Pre-Security & SOC Level 1 learning paths (hands-on, browser-based)
  • Hack The Box Academy β€” Security Fundamentals track
  • Mike Meyers' Security+ course on Total Seminars / Udemy
  • NIST SP 800-61r2 (Incident Response Guide) β€” free at NIST.gov
  • OWASP Web Security Testing Guide (WSTG) β€” free at owasp.org
Phase 3 Β· Weeks 8–10
Hands-On Labs β€” Build & Defend
3 weeks Β· Practical skills that cement theory

Security+ includes performance-based questions (PBQs) that test practical skills. Building a home lab is the best way to prepare and also builds your portfolio.

πŸ”¬ Home Lab Setup (Budget: $0–50/month)

Lab 1: Virtualized Security Lab (VirtualBox + Kali Linux)

Set up VirtualBox with Kali Linux VM (attacker) and a vulnerable target (Metasploitable2 or DVWA). Practice reconnaissance with nmap, exploitation with Metasploit (ethical, air-gapped lab only), and web application testing with Burp Suite Community Edition. Learn basic Wireshark packet capture: capture HTTP login, identify plaintext credentials, understand why HTTPS matters.

Lab 2: Windows Active Directory & Hardening

Spin up a Windows Server VM (evaluation license β€” free), configure Active Directory Domain Services, create users/groups, apply Group Policy Objects (GPOs) for password complexity, account lockout, and AppLocker. Configure Windows Firewall rules and Windows Defender. Audit event logs (Event ID 4624 logon success, 4625 logon failure, 4688 process creation).

Lab 3: Linux Hardening & Vulnerability Scanning

Harden an Ubuntu/CentOS server: disable unnecessary services, configure UFW firewall, set up fail2ban for SSH brute-force protection, configure auditd for logging. Run OpenVAS vulnerability scanner against your Metasploitable target. Interpret CVSS scores from scan results and prioritize remediation.

Lab 4: Cryptography Workshop

Use OpenSSL to generate RSA key pairs, create self-signed certificates, practice TLS inspection with Wireshark. Hash files with sha256sum and verify integrity. Experiment with GPG for asymmetric encryption and digital signatures. Set up a simple PKI with an intermediate CA. This directly maps to Domain 1 exam objectives.

Lab 5: SIEM Simulation with Splunk Free

Install Splunk Free (500MB/day β€” no cost), ingest Windows Event Logs and Apache web server logs. Create searches for failed logon attempts, suspicious process execution, and web attack indicators. Build a simple dashboard. Understand log sources and how SIEM correlation rules work β€” this directly prepares for Domain 4 PBQs.

🌐 Online Practice Environments (No Local Setup)

  • TryHackMe β€” Blue team & SOC training rooms (browser-based, guided)
  • Hack The Box (HTB) Academy β€” free tier with structured learning paths
  • CyberDefenders.org β€” Blue team DFIR challenges, CTF-style, free
  • OWASP WebGoat + WebWolf β€” intentionally vulnerable web app, Docker-based
  • PicoCTF β€” beginner-friendly CTF competitions covering security basics
Phase 4 Β· Weeks 11–12
Practice Exams & Weak Area Targeting
2 weeks Β· Simulate exam conditions

Two weeks of focused practice exam drilling. Track wrong answers by domain and create targeted review sessions. Aim for 85%+ on practice exams before sitting the real exam.

Practice Exam Strategy

Take timed, full-length 90-question practice exams
Focus 30 min/day on flashcard review (our 60-card deck)
For every wrong answer: read the explanation, find it in your textbook, re-test the next day
Practice performance-based questions (PBQs) β€” drag & drop, matching, diagram-based
Review scenario-based questions: identify the BEST answer, not just a correct answer
Track domain scores: if any domain <80%, spend 3 extra days on it

πŸ“š Practice Exam Resources

  • Jason Dion's Practice Exams on Udemy β€” 6 full exams, SY0-701 aligned, highly rated
  • Professor Messer's Practice Exams (3 exams at professormesser.com, $9.99)
  • Boson Ex-Sim for Security+ (most difficult, closest to real exam difficulty)
  • CompTIA CertMaster Practice β€” official, expensive but authoritative
  • This platform's Security+ quiz bank β€” 50 original questions, mixed types
  • ExamCompass.com β€” free Security+ practice tests

Exam-Day Answering Strategy

  • PBQs appear at the start β€” don't spend more than 4 minutes on one PBQ; mark and return
  • 'BEST' answer questions: eliminate 2 wrong answers first, then compare the 2 remaining carefully
  • Scenario questions: identify what the SPECIFIC problem is, then select the control that addresses it directly
  • When in doubt between preventive vs detective: Security+ often prefers preventive controls
  • Read ALL answer choices before selecting β€” CompTIA loves plausible distractors
  • If it mentions 'which is the FIRST step': think Incident Response phases (Preparation first, then Detection)

Seven Most-Tested Topics (Spend Extra Time)

1. Authentication types and differences (MFA, SSO, SAML, OAuth)
2. Cryptography comparisons (symmetric vs asymmetric, when to use each)
3. Incident response phases and order
4. Access control models (MAC, DAC, RBAC, ABAC β€” know the differences)
5. Network security devices and their layer of the OSI model
6. Risk calculation (ALE = SLE Γ— ARO, ROSI)
7. Vulnerability vs threat vs risk definitions
Phase 5 Β· Post-Certification
Career Launch & Continuing Education
Ongoing Β· Maintain and grow your career

Entry-Level Job Roles (Security+ qualifies you for)

SOC Analyst (Tier 1)
$55K–$80K
IT Security Analyst
$60K–$90K
Cybersecurity Analyst
$65K–$95K
Information Security Specialist
$60K–$85K
Jr. Penetration Tester
$65K–$90K
Compliance Analyst
$55K–$80K

Next Certifications to Pursue

CySA+ β€” Threat detection and response, blue team focus
PenTest+ β€” Authorized penetration testing techniques
CASP+ β€” Advanced security architecture (no MCQ, PBQ only)
CEH β€” Ethical hacking (EC-Council), red team focus
CISSP β€” Management-level, 5+ years experience required
Cloud certs β€” AWS Security Specialty, Azure Security Engineer

Continuing Education & Renewal

  • Security+ is valid for 3 years and requires 50 CEUs (Continuing Education Units) to renew (OR pass a higher-level exam)
  • CEUs earned from: training, conference attendance, writing articles, teaching, webinars
  • Follow: SANS Internet Storm Center (isc.sans.edu), Krebs on Security, The Hacker News (daily threat intel)
  • Build your home lab continuously β€” join CTF competitions: Hack The Box, PicoCTF, National Cyber League
  • Engage with the community: r/CompTIA, r/cybersecurity, local DC (DEF CON) groups

Ready to Earn Your Security+?

Start with our original practice questions and flashcards β€” 50 scenario-based questions covering all 5 SY0-701 domains, designed to prepare you for real exam complexity without exam dumps.