90 questions, 90 minutes, 27 objectives: the Security+ exam in plain English
The Security+ exam has up to 90 questions in 90 minutes, mixing multiple-choice and performance-based questions. You pass with a scaled score of 750 on a scale of 100 to 900. V8 (SY0-801) covers five domains and 27 objectives, weighted 16, 24, 19, 27 and 14 per cent. Security Operations is the largest domain in both V7 and V8.
Up to 90 questions in 90 minutes sounds like a minute each. It is not, because the performance-based questions take longer, and they often arrive first. Candidates who study every topic evenly meet those tasks cold, in Security Operations, the heaviest domain. Here is the whole exam on one map.
How is the Security+ exam structured?
| Item | Detail |
|---|---|
| Questions | Up to 90 |
| Time | 90 minutes |
| Question types | Multiple choice and performance-based |
| Passing score | 750 on a scale of 100 to 900 |
| Delivery | Pearson VUE test centre or online with OnVUE |
| Versions | Same format for V7 (SY0-701) and V8 (SY0-801) |
Two details in that table shape how you prepare.
The score is scaled. A result of 750 is a point on CompTIA's 100 to 900 scale, not a percentage of questions answered correctly. Ignore any "percentage needed to pass" you read online, and judge your readiness another way.
The format does not change between versions. CompTIA expects V8 on or around 17 November 2026, and English V7 retires on 11 June 2027. What differs is the content, and that is set by five domains.
What do the five domains cover?
CompTIA groups everything the exam tests into five domains. They carry unequal weight, and your study hours should follow the weights of the version you sit.
| Domain | V8 weight | V8 objectives | V7 weight |
|---|---|---|---|
| 1 · General Security Concepts | 16% | 3 | 12% |
| 2 · Threats, Vulnerabilities and Attacks | 24% | 6 | 22% |
| 3 · Security Architecture | 19% | 4 | 18% |
| 4 · Security Operations | 27% | 8 | 28% |
| 5 · Security Program Management and Oversight | 14% | 6 | 20% |
V7 calls Domain 2 Threats, Vulnerabilities and Mitigations, and spreads its content over 28 objectives rather than 27. If you are weighing the two versions, what changed with Security+ SY0-801 covers every move.
Security Operations carries more than a quarter of the exam in both versions. In V8, Operations and Threats together make up just over half. Domain 5 is the smallest in V8, but at 14 per cent it is still too large to skip.
The 27 V8 objectives in plain English
Titles follow CompTIA's SY0-801 list, shortened slightly. The second column says what each asks of you.
Domain 1 · General Security Concepts (16 per cent)
| Objective | In practice |
|---|---|
| 1.1 Explain security concepts and controls | Types of controls, confidentiality, integrity and availability, zero trust |
| 1.2 Demonstrate the impact of change management on security | Approvals, testing, rollback and documentation |
| 1.3 Explain appropriate cryptographic solutions | Encryption, hashing, certificates and keys, and when to use each |
Domain 2 · Threats, Vulnerabilities and Attacks (24 per cent)
| Objective | In practice |
|---|---|
| 2.1 Explain characteristics of threats and vulnerabilities | How threats and weaknesses combine into risk |
| 2.2 Describe threat actors and motivations | Criminals, nation states, insiders and hacktivists |
| 2.3 Describe threat vectors and sources | Email, messaging, removable media, supply chain |
| 2.4 Explain vulnerabilities and attack surfaces | Weaknesses in applications, systems, cloud and people |
| 2.5 Analyse indicators of malicious activity | Signs of malware, password attacks and network attacks |
| 2.6 Summarise threats and vulnerabilities of AI usage | Risks from using and attacking AI tools |
Domain 3 · Security Architecture (19 per cent)
| Objective | In practice |
|---|---|
| 3.1 Compare security implications of architecture models | On-premises, cloud, hybrid and virtualised designs |
| 3.2 Manage the architecture to protect the infrastructure | Firewalls, segmentation and secure access |
| 3.3 Summarise strategies to protect data | Data types, classification, states and protection methods |
| 3.4 Explain resilience and recovery | Backups, redundancy, high availability, recovery testing |
Domain 4 · Security Operations (27 per cent)
| Objective | In practice |
|---|---|
| 4.1 Apply mitigating controls | Harden systems, devices and applications |
| 4.2 Explain asset management | Track, assign and dispose of assets safely |
| 4.3 Perform vulnerability management tasks | Scan, prioritise, fix and confirm |
| 4.4 Explain security alerting and monitoring | Logs, SIEM, alerts and tuning |
| 4.5 Apply identity and access management | Multifactor sign-in, single sign-on, least privilege |
| 4.6 Apply automation and orchestration | Scripts and tools, including AI-assisted work |
| 4.7 Summarise incident response activities | Prepare, detect, contain, recover and learn |
| 4.8 Use data, artifacts and sources in an investigation | Reconstruct events from logs, alerts and evidence |
Domain 5 · Security Program Management and Oversight (14 per cent)
| Objective | In practice |
|---|---|
| 5.1 Explain governance, risk and compliance artifacts | Policies, standards, procedures and guidelines |
| 5.2 Explain risk management processes | Identify, assess, treat and monitor risk |
| 5.3 Explain third-party risk assessment and management | Vendor assessment, contracts and monitoring |
| 5.4 Summarise effective security compliance | Reporting, monitoring, consequences of non-compliance |
| 5.5 Explain audit and assessment activities | Internal and external audits, penetration tests |
| 5.6 Apply security awareness concepts | Phishing campaigns, training and reporting culture |
Notice the verbs. "Apply", "perform" and "use" mean you must do something, and most of those objectives sit in Security Operations. That is where reading alone falls shortest.
Which question formats will you see?
| Format | What you do |
|---|---|
| Multiple choice, one answer | Choose the single best answer |
| Multiple choice, several answers | Choose every correct answer the question asks for |
| Performance-based | Solve a task in a simulated environment, such as ordering rules, matching items or reading a log |
CompTIA names these formats for both versions. On a several-answer question, read the stem for how many answers it wants before you look at the options.
How should you handle performance-based questions?
They often appear early and take longer than anything else. Many candidates flag them, answer the multiple-choice questions first and return with the time left. Rehearse that order in every timed practice exam, so it is a habit on the day rather than a decision.
Reading alone does not prepare you for them. Practise in a lab or a simulator. A small home lab is enough: two virtual machines, a free firewall and a log viewer. Use it to harden a system, read logs and spot a simulated attack.
Aim the lab at your weakest objectives. One candidate rated himself 2 out of 5 on 4.4, monitoring, and 4.8, investigations. He gave both extra lab time, and both turned up in his performance-based questions.
How do the weights turn into hours and readiness?
Split your study hours in proportion to the weights, then move hours towards the objectives you rated lowest. For an 80-hour V8 plan, the book's starting split looks like this.
| V8 domain | Hours | Study first |
|---|---|---|
| Security Operations | 22 | Monitoring, identity and access, investigations |
| Threats, Vulnerabilities and Attacks | 19 | Indicators of malicious activity, attack surfaces |
| Security Architecture | 15 | Infrastructure security, resilience |
| General Security Concepts | 13 | Controls, cryptography |
| Security Program Management and Oversight | 11 | Risk management, third-party risk |
Readiness is a pattern, not a single score. Look for consistent results across two or three full practice exams, with no domain far behind the others. You should also feel confident with performance-based tasks.
One high practice result tells you little. Stable results on material for your exam code tell you far more.
What to do with this map
Go back to the objective tables and rate yourself from 1 to 5 on all 27. Your five lowest scores become the first targets in your plan. Then size the whole effort with how many hours to study for Security+, which turns the weights into weeks.
When you want to test yourself, the Security+ practice questions work through ten new scenarios across the domains.
Every figure here was checked against CompTIA's documents in October 2026. Chapter 5 of the book gives you the same map with each V8 objective set beside its closest V7 match, ready to rate. Appendix G adds 16 practice questions mapped to domain and objective. The map shows where the marks are. Your ratings show where to start.
- Rate yourself from 1 to 5 on each of the 27 objectives below and circle your five lowest.
- Download the exam objectives for your version from comptia.org and check the version number and domain weights.
- In your next timed practice set, flag every performance-based question, finish the multiple choice and then return.
- Set up a two-machine home lab and use it to read one log this week.
Questions readers ask
Does Security+ test any one vendor's products?
Is the exam formally recognised?
What happens if I do not pass first time?
Can I sit the exam online?
- CompTIA Security+ page
- SY0-801 exam objectives
- SY0-701 exam objectives
- CompTIA Certification Retake Policy
This guide is independent and is not endorsed by CompTIA. Facts change: confirm them on the official page before you act.