Every Security+ objective on one page. Rate yourself 1 to 5.Study what's low.
All 28published SY0-701 objectives, 1.1 through 5.6, with a checkbox and a confidence rating for each. Fill it in honestly and you'll have a study plan in about nine minutes, one built from your actual gaps instead of someone else's course order.
Most people study Security+ in the order the material is presented to them. That's the wrong order. It's the author's order, not yours.
CompTIA publishes exactly what's on the exam: 28objectives across five domains. There is no mystery about scope. The only real question is which of those you can explain out loud to another human, and which you'd have to look up.
Be honest. “I've heard of it” is a 2, not a 4. The checklist is worthless if you're generous with yourself. The exam won't be.
Redo it every two weeks.Same sheet, different pen color. Watching 2s become 4s is the only progress signal in certification study that isn't self-delusion, and it's what keeps people going through week five.
CompTIA Security+ SY0-701 Objective Confidence Checklist
Name: ____________ · Started: ______ · Exam date: ______ · Round: ☐ 1st ☐ 2nd ☐ 3rd
- 1
- Never seen it.
- 2
- I recognize the term. I couldn't explain it.
- 3
- I can define it. I'd struggle with a scenario question.
- 4
- I can explain it and apply it to a scenario.
- 5
- I could teach it to someone else without notes.
☐ = covered in study. The rating is separate. Covering it and knowing it are not the same thing, which is the entire point of this sheet. Passing score 750/900 · 90 questions in 90 minutes · $439, no free retake.
Domain 1.0: General Security Concepts · 12% of the exam
Domain total: ___ / 20
| ☐ | Obj | Objective | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|---|---|
| ☐ | 1.1 | Compare and contrast various types of security controls. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 1.2 | Summarize fundamental security concepts. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 1.3 | Explain the importance of change management processes and the impact to security. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 1.4 | Explain the importance of using appropriate cryptographic solutions. | ○ | ○ | ○ | ○ | ○ |
Domain 2.0: Threats, Vulnerabilities, and Mitigations · 22% of the exam
Domain total: ___ / 25
| ☐ | Obj | Objective | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|---|---|
| ☐ | 2.1 | Compare and contrast common threat actors and motivations. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 2.2 | Explain common threat vectors and attack surfaces. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 2.3 | Explain various types of vulnerabilities. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 2.4 | Given a scenario, analyze indicators of malicious activity. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 2.5 | Explain the purpose of mitigation techniques used to secure the enterprise. | ○ | ○ | ○ | ○ | ○ |
Domain 3.0: Security Architecture · 18% of the exam
Domain total: ___ / 20
| ☐ | Obj | Objective | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|---|---|
| ☐ | 3.1 | Compare and contrast security implications of different architecture models. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 3.2 | Given a scenario, apply security principles to secure enterprise infrastructure. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 3.3 | Compare and contrast concepts and strategies to protect data. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 3.4 | Explain the importance of resilience and recovery in security architecture. | ○ | ○ | ○ | ○ | ○ |
Domain 4.0: Security Operations · 28% of the exam
Domain total: ___ / 45
| ☐ | Obj | Objective | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|---|---|
| ☐ | 4.1 | Given a scenario, apply common security techniques to computing resources. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 4.2 | Explain the security implications of proper hardware, software, and data asset management. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 4.3 | Explain various activities associated with vulnerability management. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 4.4 | Explain security alerting and monitoring concepts and tools. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 4.5 | Given a scenario, modify enterprise capabilities to enhance security. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 4.6 | Given a scenario, implement and maintain identity and access management. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 4.7 | Explain the importance of automation and orchestration related to secure operations. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 4.8 | Explain appropriate incident response activities. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 4.9 | Given a scenario, use data sources to support an investigation. | ○ | ○ | ○ | ○ | ○ |
Domain 5.0: Security Program Management and Oversight · 20% of the exam
Domain total: ___ / 30
| ☐ | Obj | Objective | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|---|---|
| ☐ | 5.1 | Summarize elements of effective security governance. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 5.2 | Explain elements of the risk management process. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 5.3 | Explain the processes associated with third-party risk assessment and management. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 5.4 | Summarize elements of effective security compliance. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 5.5 | Explain types and purposes of audits and assessments. | ○ | ○ | ○ | ○ | ○ |
| ☐ | 5.6 | Given a scenario, implement security awareness practices. | ○ | ○ | ○ | ○ | ○ |
Print this page (Ctrl/Cmd + P) for a paper copy. The surrounding page furniture is stripped automatically.
Also free: the complete Domain 1 guide, all 82 pages →