CredenTrek
Independent roadmaps for accredited credentialsEdition 2026.2 · Register verified 9 October 2026
Library / Security+ / Guide 04 of 8
Security+ · Exam format and domains

90 questions, 90 minutes, 27 objectives: the Security+ exam in plain English

By Mustafa K. Al-Dori · Checked against official documents on 9 October 2026 · 6 min read

The short answer

The Security+ exam has up to 90 questions in 90 minutes, mixing multiple-choice and performance-based questions. You pass with a scaled score of 750 on a scale of 100 to 900. V8 (SY0-801) covers five domains and 27 objectives, weighted 16, 24, 19, 27 and 14 per cent. Security Operations is the largest domain in both V7 and V8.

Up to 90 questions in 90 minutes sounds like a minute each. It is not, because the performance-based questions take longer, and they often arrive first. Candidates who study every topic evenly meet those tasks cold, in Security Operations, the heaviest domain. Here is the whole exam on one map.

How is the Security+ exam structured?

Item Detail
Questions Up to 90
Time 90 minutes
Question types Multiple choice and performance-based
Passing score 750 on a scale of 100 to 900
Delivery Pearson VUE test centre or online with OnVUE
Versions Same format for V7 (SY0-701) and V8 (SY0-801)

Two details in that table shape how you prepare.

The score is scaled. A result of 750 is a point on CompTIA's 100 to 900 scale, not a percentage of questions answered correctly. Ignore any "percentage needed to pass" you read online, and judge your readiness another way.

The format does not change between versions. CompTIA expects V8 on or around 17 November 2026, and English V7 retires on 11 June 2027. What differs is the content, and that is set by five domains.

What do the five domains cover?

CompTIA groups everything the exam tests into five domains. They carry unequal weight, and your study hours should follow the weights of the version you sit.

Domain V8 weight V8 objectives V7 weight
1 · General Security Concepts 16% 3 12%
2 · Threats, Vulnerabilities and Attacks 24% 6 22%
3 · Security Architecture 19% 4 18%
4 · Security Operations 27% 8 28%
5 · Security Program Management and Oversight 14% 6 20%

V7 calls Domain 2 Threats, Vulnerabilities and Mitigations, and spreads its content over 28 objectives rather than 27. If you are weighing the two versions, what changed with Security+ SY0-801 covers every move.

Security Operations carries more than a quarter of the exam in both versions. In V8, Operations and Threats together make up just over half. Domain 5 is the smallest in V8, but at 14 per cent it is still too large to skip.

The 27 V8 objectives in plain English

Titles follow CompTIA's SY0-801 list, shortened slightly. The second column says what each asks of you.

Domain 1 · General Security Concepts (16 per cent)

Objective In practice
1.1 Explain security concepts and controls Types of controls, confidentiality, integrity and availability, zero trust
1.2 Demonstrate the impact of change management on security Approvals, testing, rollback and documentation
1.3 Explain appropriate cryptographic solutions Encryption, hashing, certificates and keys, and when to use each

Domain 2 · Threats, Vulnerabilities and Attacks (24 per cent)

Objective In practice
2.1 Explain characteristics of threats and vulnerabilities How threats and weaknesses combine into risk
2.2 Describe threat actors and motivations Criminals, nation states, insiders and hacktivists
2.3 Describe threat vectors and sources Email, messaging, removable media, supply chain
2.4 Explain vulnerabilities and attack surfaces Weaknesses in applications, systems, cloud and people
2.5 Analyse indicators of malicious activity Signs of malware, password attacks and network attacks
2.6 Summarise threats and vulnerabilities of AI usage Risks from using and attacking AI tools

Domain 3 · Security Architecture (19 per cent)

Objective In practice
3.1 Compare security implications of architecture models On-premises, cloud, hybrid and virtualised designs
3.2 Manage the architecture to protect the infrastructure Firewalls, segmentation and secure access
3.3 Summarise strategies to protect data Data types, classification, states and protection methods
3.4 Explain resilience and recovery Backups, redundancy, high availability, recovery testing

Domain 4 · Security Operations (27 per cent)

Objective In practice
4.1 Apply mitigating controls Harden systems, devices and applications
4.2 Explain asset management Track, assign and dispose of assets safely
4.3 Perform vulnerability management tasks Scan, prioritise, fix and confirm
4.4 Explain security alerting and monitoring Logs, SIEM, alerts and tuning
4.5 Apply identity and access management Multifactor sign-in, single sign-on, least privilege
4.6 Apply automation and orchestration Scripts and tools, including AI-assisted work
4.7 Summarise incident response activities Prepare, detect, contain, recover and learn
4.8 Use data, artifacts and sources in an investigation Reconstruct events from logs, alerts and evidence

Domain 5 · Security Program Management and Oversight (14 per cent)

Objective In practice
5.1 Explain governance, risk and compliance artifacts Policies, standards, procedures and guidelines
5.2 Explain risk management processes Identify, assess, treat and monitor risk
5.3 Explain third-party risk assessment and management Vendor assessment, contracts and monitoring
5.4 Summarise effective security compliance Reporting, monitoring, consequences of non-compliance
5.5 Explain audit and assessment activities Internal and external audits, penetration tests
5.6 Apply security awareness concepts Phishing campaigns, training and reporting culture

Notice the verbs. "Apply", "perform" and "use" mean you must do something, and most of those objectives sit in Security Operations. That is where reading alone falls shortest.

Which question formats will you see?

Format What you do
Multiple choice, one answer Choose the single best answer
Multiple choice, several answers Choose every correct answer the question asks for
Performance-based Solve a task in a simulated environment, such as ordering rules, matching items or reading a log

CompTIA names these formats for both versions. On a several-answer question, read the stem for how many answers it wants before you look at the options.

How should you handle performance-based questions?

They often appear early and take longer than anything else. Many candidates flag them, answer the multiple-choice questions first and return with the time left. Rehearse that order in every timed practice exam, so it is a habit on the day rather than a decision.

Reading alone does not prepare you for them. Practise in a lab or a simulator. A small home lab is enough: two virtual machines, a free firewall and a log viewer. Use it to harden a system, read logs and spot a simulated attack.

Aim the lab at your weakest objectives. One candidate rated himself 2 out of 5 on 4.4, monitoring, and 4.8, investigations. He gave both extra lab time, and both turned up in his performance-based questions.

How do the weights turn into hours and readiness?

Split your study hours in proportion to the weights, then move hours towards the objectives you rated lowest. For an 80-hour V8 plan, the book's starting split looks like this.

V8 domain Hours Study first
Security Operations 22 Monitoring, identity and access, investigations
Threats, Vulnerabilities and Attacks 19 Indicators of malicious activity, attack surfaces
Security Architecture 15 Infrastructure security, resilience
General Security Concepts 13 Controls, cryptography
Security Program Management and Oversight 11 Risk management, third-party risk

Readiness is a pattern, not a single score. Look for consistent results across two or three full practice exams, with no domain far behind the others. You should also feel confident with performance-based tasks.

One high practice result tells you little. Stable results on material for your exam code tell you far more.

What to do with this map

Go back to the objective tables and rate yourself from 1 to 5 on all 27. Your five lowest scores become the first targets in your plan. Then size the whole effort with how many hours to study for Security+, which turns the weights into weeks.

When you want to test yourself, the Security+ practice questions work through ten new scenarios across the domains.

Every figure here was checked against CompTIA's documents in October 2026. Chapter 5 of the book gives you the same map with each V8 objective set beside its closest V7 match, ready to rate. Appendix G adds 16 practice questions mapped to domain and objective. The map shows where the marks are. Your ratings show where to start.

Your next step
  1. Rate yourself from 1 to 5 on each of the 27 objectives below and circle your five lowest.
  2. Download the exam objectives for your version from comptia.org and check the version number and domain weights.
  3. In your next timed practice set, flag every performance-based question, finish the multiple choice and then return.
  4. Set up a two-machine home lab and use it to read one log this week.

Questions readers ask

Does Security+ test any one vendor's products?
No. Security+ is vendor-neutral, so it is not tied to one company's tools and the knowledge travels across employers. Interviewers may still test the tools they use, so pair the credential with hands-on practice on at least one platform you are likely to meet at work.
Is the exam formally recognised?
CompTIA describes the exam as accredited to the ISO 17024 standard through ANAB. It also maps Security+ to US Department of Defense 8140 work roles, such as incident responder and vulnerability analyst, which is why government suppliers often name it in job advertisements.
What happens if I do not pass first time?
There is no waiting period before a second attempt. Before a third or later attempt, you must wait at least 14 calendar days from your last one. Every attempt is paid at the full exam price, and CompTIA offers no free retakes or retake discounts.
Can I sit the exam online?
Yes, through Pearson VUE's OnVUE service, if it is offered in your country. CompTIA states it is not available in some countries, including South Korea and Slovenia. You need a private, enclosed room, a clear desk, a webcam and a passed system test, and proctors speak English only.
Sources

This guide is independent and is not endorsed by CompTIA. Facts change: confirm them on the official page before you act.