Security+7 min read

How to study for the Security+ exam

Most Security+ advice tells you what to learn. Almost none of it tells you how much of each thing, which is the part the exam has already published. Here is a method built backwards from the exam itself.

What you are actually walking into#

Imagine being handed a 90-question quiz and a kitchen timer set to 90 minutes. That is the whole shape of it. One minute per question, with no slack built in anywhere.

CompTIA publishes the format, so none of this has to be a surprise on the day:

  • A maximum of 90 questions, mixing multiple choice with performance-based questions, which are the small interactive tasks where you drag, match or configure something rather than pick a letter.
  • 90 minutes total.
  • A passing score of 750, on a scale that runs from 100 to 900.
  • CompTIA recommends Network+ first, plus about two years in a security or systems administrator role. That is a recommendation, not a gate. Plenty of people sit it earlier.

The number that matters most in that list is the one people misread, so it gets its own section.

Why 750 is not 83 percent#

Here is the trap. You see "750 out of 900" and your brain does the division: 83 percent. Then you panic, because 83 percent feels enormous.

It is not a percentage. It is a scaled score, which means the raw number of questions you got right is run through a conversion before it becomes the number you see. The scale starts at 100, not at 0. Somebody who answers nothing correctly does not score 0, they score 100.

Two consequences follow, and both change how you should study:

  • You cannot compute your own percentage needed. CompTIA does not publish the raw-to-scaled conversion, and it varies between exam forms so that a slightly harder set of questions is not a harder exam.
  • Questions are not all worth the same. Performance-based questions generally carry more weight than a single multiple-choice item, which is why leaving them blank hurts more than it looks like it should.
The honest version

Nobody outside CompTIA can tell you "you need to get N questions right". Aim to be comfortably competent across every domain rather than to clear a specific number, because the specific number is not knowable.

Study by weight, not by chapter order#

Think of the exam as a pie that has already been sliced, with the sizes printed on the box. Most study plans ignore the sizes and work through a textbook front to back, which means spending equal time on a 12 percent slice and a 28 percent slice.

These are the published weights for SY0-701:

DomainWeightHours in a 40-hour plan
1.0 General Security Concepts12%4.8
2.0 Threats, Vulnerabilities and Mitigations22%8.8
3.0 Security Architecture18%7.2
4.0 Security Operations28%11.2
5.0 Security Program Management and Oversight20%8.0

Security Operations is the largest domain on the exam, and it is the one self-taught candidates most often underprepare, because it is the least glamorous. It is logging, monitoring, incident response, vulnerability management and hardening. It is more than twice the size of General Security Concepts, which is where most people spend their first two weeks because that is where the textbook starts.

Domain 5 catches people out for a different reason. It is governance, risk and compliance: policies, audits, vendor agreements, risk registers. There is very little to do and a lot to recognise, so it rewards flashcards far more than lab time, and it is a fifth of the exam.

How to handle the performance-based questions#

Performance-based questions usually appear first, and they are the single most common way people lose the exam on time rather than on knowledge. You open the exam, hit a drag-and-drop firewall ruleset, spend eleven minutes on it, and now 79 questions are waiting behind a clock that has lost an eighth of its total.

The fix is mechanical:

  1. Flag and skip every performance-based question on first contact. Do not read it properly. Mark it, move on.
  2. Clear all the multiple choice first. These are roughly a minute each and you will bank time on the easy ones.
  3. Come back with the remaining time and spend it deliberately. If 25 minutes are left and four tasks are flagged, that is six minutes each, and you now know it.

A partly completed performance-based question is usually worth partial credit, so putting something reasonable in every field beats leaving one perfect and one blank.

What "best" means in a Security+ question#

Security+ questions very often ask for the best or most likely answer, and they are built so that two or three options are genuinely true statements. This is the thing that makes people feel they are being tricked. They are not. The question is testing whether you can rank correct answers.

Three habits do most of the work:

  • Read the last sentence first. The scenario often contains a paragraph of detail that does not change the answer. The actual question is usually one line at the end, and knowing it changes what you look for in the paragraph.
  • Find the role. "You are the security analyst" and "you are the compliance officer" lead to different best answers from the identical scenario. The exam tells you whose job you are doing.
  • Prefer the control that addresses the stated problem, not the strongest control available. If the scenario describes an employee reusing passwords, multifactor authentication is a better answer than full disk encryption, even though encryption is a stronger control in the abstract. It does not address what the scenario said.

A four-week plan that fits around a job#

This assumes roughly ten hours a week. Stretch it to eight weeks at five hours if that is more honest about your life. The proportions are what matter, not the calendar.

WeekFocusWhat "done" looks like
1Domain 1 and Domain 2 vocabularyYou can define every term in the objectives list without looking, even if you cannot yet apply it.
2Domain 4, the largest oneYou can walk the incident response phases in order and say what a SIEM does in one sentence.
3Domain 3 and Domain 5You can sketch a segmented network, and you can compute a single loss expectancy without notes.
4Timed practice onlyFull 90-minute sets. You are no longer learning content, you are learning pace.

Week 4 is the one people cut when they run short, and it is the one that most directly changes the outcome. Knowing the material and finishing in time are two separate skills, and only one of them can be practised in the last week.

One sentence to carry into the exam

Answer the question that was asked, in the role you were given: the best answer is the one that fixes the stated problem, not the strongest control on the page.

Test yourself in the free Kestrel Exams app

Topic-selectable practice — offline, no ads, no account.

Practice this topic →

Frequently asked questions#

How long does it take to study for Security+?

Commonly somewhere between six and twelve weeks at roughly eight to ten hours a week, and much less if you already work in IT. The honest answer is that it depends far more on your existing exposure to networks and systems administration than on any study plan, which is why CompTIA recommends Network+ and about two years of experience first.

Is 750 out of 900 the same as 83 percent?

No. It is a scaled score on a range that starts at 100, not a percentage of questions answered correctly. CompTIA does not publish the conversion from raw score to scaled score, and it varies between exam forms, so you cannot work out how many questions you need to get right.

What is the hardest Security+ domain?

Security Operations is the largest at 28 percent and the one most often underprepared, because it covers routine work like logging, monitoring and vulnerability management rather than memorable attacks. Security Program Management and Oversight is a close second for difficulty, since 20 percent of the exam is governance and risk material that is hard to make concrete.

Should I answer the performance-based questions first?

No. Flag and skip them, clear the multiple choice, then return with the time you have left and divide it deliberately between the flagged tasks. They usually appear first and they are the most common reason people run out of time on an exam they knew well enough to pass.

Do I need Network+ before Security+?

It is recommended by CompTIA but not required, and there is no prerequisite enforced when you book. If you cannot comfortably explain what a subnet, a VLAN and a default gateway are, the networking content inside Security+ will cost you more time than taking Network+ first would have.

Suggest a change

Something here not clear? A topic you wish we covered? Tell us. We read every message, and a request is the fastest way to get a guide written — several of these exist because somebody asked.