Security+

Security+ exam objectives

The exam covers five domains. CompTIA publishes the objectives for each version; they are the official scope of what can be tested.

QuestionsUp to 90, multiple choice and performance-based
Time90 minutes
Passing score750 on a scale of 100 to 900

The five domains on SY0-801

DomainWeightCovers
1. General Security Concepts16%Controls, change management, cryptography
2. Threats, Vulnerabilities, and Attacks24%Actors, vectors, vulnerabilities, indicators, AI threats
3. Security Architecture19%Cloud and network design, data protection, resilience
4. Security Operations27%Mitigations, identity, monitoring, incident response
5. Security Program Management and Oversight14%Governance, risk, vendors, compliance, audits

Where to start

Start where the marks are: Security Operations is the largest domain. Then cover threats and attacks, because their scenarios appear across every domain.

Try 3 questions

Question 1Objective 1.1

A legacy controller cannot be patched because the vendor no longer exists. The team places it on an isolated VLAN with strict access rules. What is the VLAN acting as?

Question 2Objective 2.5

Logs show one failed login for each of 400 different accounts, all using the password "Autumn2026!", from one IP address over an hour. What attack is this?

Question 3Objective 4.5

Employees sign in once to the company identity provider and then reach a cloud HR app without another password. The identity provider sends the app a signed XML assertion. What protocol is this?

Next step

CompTIA's Security+ V8 exam page

Questions people ask

Where are the official objectives?

On comptia.org, on each version's exam page. They are free to download.

Does the course follow the objectives?

Yes. Every lesson and question is tagged with the SY0-801 objective it practices.