A legacy controller cannot be patched because the vendor no longer exists. The team places it on an isolated VLAN with strict access rules. What is the VLAN acting as?
Security+ exam objectives
The exam covers five domains. CompTIA publishes the objectives for each version; they are the official scope of what can be tested.
| Questions | Up to 90, multiple choice and performance-based |
|---|---|
| Time | 90 minutes |
| Passing score | 750 on a scale of 100 to 900 |
The five domains on SY0-801
| Domain | Weight | Covers |
|---|---|---|
| 1. General Security Concepts | 16% | Controls, change management, cryptography |
| 2. Threats, Vulnerabilities, and Attacks | 24% | Actors, vectors, vulnerabilities, indicators, AI threats |
| 3. Security Architecture | 19% | Cloud and network design, data protection, resilience |
| 4. Security Operations | 27% | Mitigations, identity, monitoring, incident response |
| 5. Security Program Management and Oversight | 14% | Governance, risk, vendors, compliance, audits |
Where to start
Start where the marks are: Security Operations is the largest domain. Then cover threats and attacks, because their scenarios appear across every domain.
Try 3 questions
Logs show one failed login for each of 400 different accounts, all using the password "Autumn2026!", from one IP address over an hour. What attack is this?
Employees sign in once to the company identity provider and then reach a cloud HR app without another password. The identity provider sends the app a signed XML assertion. What protocol is this?
Next step
Questions people ask
Where are the official objectives?
On comptia.org, on each version's exam page. They are free to download.
Does the course follow the objectives?
Yes. Every lesson and question is tagged with the SY0-801 objective it practices.