CompTIA Security+ SY0-701 — Complete Study Guide
Practice as you learn. Every concept maps to real exam questions with verified answers in the CompTIA exam hub, or drill the full exam with timed practice on ExamRoll.io.
This guide covers each SY0-701 domain in depth. Pick a domain to go deep, or work through them in order.
The domains
- Governance, Risk Management & Compliance — Governance, Risk Management, and Compliance — collectively abbreviated GRC — is the connective tissue that binds technical security controls to
- Identity & Access Management — Identity and Access Management (IAM) is the discipline of ensuring that the right subjects — users, services, and devices — obtain the right access
- Threats, Attacks & Vulnerabilities — The modern threat landscape is defined by adversaries who blend technical exploitation with human manipulation, chain low-severity weaknesses into
- Network Security & Architecture — Network security architecture is the discipline of arranging devices, controls, and traffic flows so that malicious activity is contained, monitored,
- Security Operations, Monitoring & Detection — Modern security operations depend on the ability to observe, correlate, and act on signals emerging from every corner of the enterprise — endpoints,
- Incident Response, Forensics & Assessment — Security incidents are inevitable. The discipline of incident response converts a chaotic, damaging event into a structured, documented process that
- Application & Web Security — Modern applications sit at the intersection of business logic, sensitive data, and untrusted user input. Because web and mobile front ends are
- Cloud, Virtualization & Container Security — Modern enterprises rarely operate in a single, self-contained data center. Workloads span public cloud providers, private virtualization clusters,
- Data Security, Privacy & Cryptography — Data is the ultimate target of most attacks, and cryptography is the primary technical mechanism for protecting it in transit, at rest, and in use.
- Business Continuity & Disaster Recovery — Business continuity (BC) and disaster recovery (DR) form the operational backbone of organizational resilience. Where security controls attempt to
- Endpoint, Mobile & Physical Security — The security of information systems ultimately depends on the security of the physical and endpoint devices that store and process data. A perfectly
- Vulnerability Management & Patch Management — Vulnerability management is the continuous process of identifying, classifying, remediating, and verifying security weaknesses across an
Ready to practice?
- Browse every question with verified answers → — free, with explanations.
- Start timed practice tests on ExamRoll.io → — the full question bank, in 20+ languages.
Pass the whole exam — not just this question
You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.
Pass your exam →