0Pricing
Cloud & IT Cert Prep · Lesson

SY0-701 Exam Domains and Weighting

Review the five exam domains — General Security Concepts, Threats/Vulnerabilities, Security Architecture, Security Operations, Governance — and their percentage weights.

SY0-701 Exam Domains and Weighting is a free Cloud & IT Cert Prep lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Cloud & IT Cert Prep learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

CompTIA Security+ SY0-701 Overview

The CompTIA Security+ SY0-701 exam was released in November 2023, replacing SY0-601. It consists of a maximum of 90 questions, with a mix of multiple-choice and performance-based questions (PBQs). You have 90 minutes to complete the exam. The passing score is 750 on a scale of 100-900. The exam covers five domains, each with a specific weighting that reflects how many questions fall within that domain. Understanding the domain structure helps you prioritize your study time based on how heavily each area is tested.

Domain 1: General Security Concepts (12%)

Domain 1: General Security Concepts accounts for approximately 12% of the exam — about 11 questions. This domain covers foundational security principles that underpin everything else: the CIA triad (Confidentiality, Integrity, Availability), authentication and authorization concepts, cryptographic foundations (symmetric/asymmetric encryption, hashing, PKI), the difference between security control types (technical, managerial, operational) and categories (preventive, detective, corrective, deterrent, compensating). Questions in this domain test your understanding of why security controls exist and the theoretical framework for organizing them.

Domain 2: Threats, Vulnerabilities, and Mitigations (22%)

Domain 2: Threats, Vulnerabilities, and Mitigations is the largest single domain at 22% of the exam — approximately 20 questions. This domain covers threat actors (script kiddies through nation-states), attack types (malware, phishing, social engineering, network attacks, application attacks), indicators of compromise, vulnerability management (scanning, CVSS scoring, patching prioritization), and the specific mitigations that address each threat. Expect scenario-based questions where you must identify which attack type is occurring or which mitigation is most appropriate for a given situation.

Domain 3: Security Architecture (18%)

Domain 3: Security Architecture covers 18% of the exam — approximately 16 questions. This domain addresses how security controls are designed and deployed: network segmentation, firewalls, VPNs, IDS/IPS, zero trust architecture, cloud security models (shared responsibility, IaaS/PaaS/SaaS), virtualization security, secure infrastructure design, and resilience concepts (redundancy, high availability, geographic dispersal). Questions often present network diagrams or architecture descriptions and ask you to identify security gaps or recommend the appropriate control to add. Knowing when to use each control type is critical here.

Domain 4: Security Operations (28%)

Domain 4: Security Operations is the heaviest weighted domain at 28% of the exam — approximately 25 questions. This domain covers day-to-day security work: identity and access management, endpoint security (antivirus, EDR, MDM, hardening), network security monitoring, incident response lifecycle (preparation through lessons learned), digital forensics (evidence acquisition, chain of custody, forensic artifacts), vulnerability assessment, and log analysis. Domain 4 reflects the operational skills security professionals use daily and includes many scenario-based questions testing how you would respond to specific security events.

Domain 5: Security Program Management (20%)

Domain 5: Security Program Management and Oversight covers 20% of the exam — approximately 18 questions. This domain covers the governance, risk, and compliance (GRC) side of security: risk management (identification, analysis, treatment), data privacy regulations (GDPR, HIPAA, PCI-DSS, CCPA), security frameworks (NIST RMF, ISO 27001, CIS Controls), data classification schemes, business continuity and disaster recovery planning, third-party risk management (vendor assessments, supply chain security), and security audits. Domain 5 questions often present a business scenario and ask you to identify the appropriate governance response or compliance requirement.

Domain Weight Summary Table

For quick reference: Domain 1: General Security Concepts — 12% (foundational principles, CIA, cryptography, control types); Domain 2: Threats, Vulnerabilities, Mitigations — 22% (attack types, malware, social engineering, vulnerability management); Domain 3: Security Architecture — 18% (network design, cloud, zero trust, resilience); Domain 4: Security Operations — 28% (IAM, endpoints, IR, forensics, monitoring — the heaviest domain); Domain 5: Security Program Management — 20% (risk management, compliance, frameworks, BCP/DRP). Domains 4 and 2 together account for exactly 50% of the exam.

How SY0-701 Differs from SY0-601

The SY0-701 version introduced several notable changes from the previous SY0-601 exam: cloud and hybrid security content was significantly expanded, reflecting the industry shift to cloud-first architectures; zero trust architecture was added as a core concept; operational technology (OT/ICS) security was given dedicated coverage; the governance domain was restructured to Domain 5 with greater emphasis on data privacy regulations; and automation in security operations (SOAR, scripting for security) was added. The five-domain structure replaced the previous six-domain structure of SY0-601, consolidating some topics.

Performance-Based Questions Overview

Performance-Based Questions (PBQs) are simulation-style questions that require you to interact with a virtual environment or drag-and-drop interface to complete a task. Common PBQ types: firewall rule configuration — given a scenario, add or modify rules in a simulated firewall interface; network diagram analysis — identify security gaps in a network diagram and place appropriate controls; log analysis — analyze provided log excerpts and identify the attack type; order-of-operations — drag steps into correct sequence (e.g., incident response phases); and matching — pair security concepts with their definitions or use cases. PBQs typically appear at the beginning of the exam.

High-Priority Study Areas by Domain

Within each domain, certain topics appear more frequently based on exam blueprints and candidate reports: Domain 1 — cipher comparison tables, symmetric vs asymmetric use cases, PKI components; Domain 2 — malware type behaviors, phishing variants (spear/whaling/vishing), CVSS scoring, MITRE ATT&CK; Domain 3 — network segmentation (DMZ, VLANs), cloud shared responsibility, IDS vs IPS vs firewall comparison; Domain 4 — incident response lifecycle phases and their activities, SIEM/EDR roles, forensic order of volatility, access control models (RBAC/MAC/DAC); Domain 5 — risk calculation (SLE, ARO, ALE), GDPR key requirements, BCP vs DRP distinction.

Acronyms, Registration, and Prep Timeline

Security+ is notorious for testing acronyms — build a flashcard deck for: authentication protocols (RADIUS, TACACS+, SAML, OAuth, OIDC); cryptographic algorithms (RSA, ECC, AES, SHA-256, HMAC); network protocol secure replacements (Telnet/SSH, FTP/SFTP, HTTP/HTTPS, LDAP/LDAPS); attack types (DoS, MITM, ARP spoofing, XSS, CSRF); and compliance acronyms (NIST, GDPR, HIPAA, PCI-DSS, SOC 2). The exam uses acronyms without spelling them out — knowing them cold is essential.

The exam is delivered at Pearson VUE centers or online-proctored. Cost is approximately $404 USD. A typical study plan: 40-60 hours over 4-8 weeks — study guide, practice exams, video courses, and hands-on labs. CompTIA recommends 2+ years of IT experience with a security focus.

Quick Check

Test your understanding of CompTIA Security+ (SY0-701) concepts from this lesson.

Lesson Recap

In this lesson you learned: SY0-701 has five domains with Domain 4 (Security Operations, 28%) and Domain 2 (Threats, 22%) carrying the most weight — together comprising 50% of the exam, performance-based questions appear at the start and test hands-on skills like firewall configuration, log analysis, and network diagram interpretation, and the exam shifted from SY0-601 to add greater emphasis on cloud security, zero trust, OT/ICS, and data privacy. Next up we focus on strategies for tackling performance-based questions effectively.

Frequently asked questions

Is the “SY0-701 Exam Domains and Weighting” lesson free?

Yes — the full text of “SY0-701 Exam Domains and Weighting” is free to read here on the web, and the Cloud & IT Cert Prep course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Cloud & IT Cert Prep course, upgrade to CoddyKit PRO.

What will I learn in “SY0-701 Exam Domains and Weighting”?

Review the five exam domains — General Security Concepts, Threats/Vulnerabilities, Security Architecture, Security Operations, Governance — and their percentage weights. You practise Cloud & IT Cert Prep with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Cloud & IT Cert Prep?

No prior experience is required. Cloud & IT Cert Prep on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “SY0-701 Exam Domains and Weighting” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Cloud & IT Cert Prep lesson?

Yes. Every Cloud & IT Cert Prep lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. SY0-701 Exam Domains and Weighting
  2. Performance-Based Questions (PBQs) Strategy
  3. High-Frequency Exam Topics Review
  4. Time Management and Elimination Strategies
← Back to Cloud & IT Cert Prep