Not sure where to start?
Take the 24-question diagnostic
About 8 minutes, untimed. Every domain gets a band and you get a study-first list; misses go straight into your flashcard reviews.
Timed mock exam
Take a full-length CompTIA Security+ practice test
Questions weighted across every domain, on the clock — with a per-domain score breakdown when you finish.
Exam domains
Each category's percentage is its approximate weight on the CompTIA Security+ exam. The bars track your mastery — terms you've marked “I know this” or recalled from flashcards.
Exam Domains
100%The five SY0-701 domains, in objective order. Percentages reflect each domain's approximate weight on the exam.
- Security Operations24 terms
Domain 4 — day-to-day operations: monitoring, IAM, vulnerability management, incident response, and digital forensics.
- Security Operations Essentials · 11 terms
- Incident Response and IAM · 13 terms
- Threats, Vulnerabilities, and Mitigations24 terms
Domain 2 — attack types, malware families, vulnerabilities, and the mitigations and controls that stop them.
- Malware and Social Engineering · 12 terms
- Attacks and Exploits · 12 terms
- Security Program Management and Oversight24 terms
Domain 5 — risk management, governance, compliance frameworks, third-party risk, and security awareness.
- Governance and Policy · 12 terms
- Risk and Third-Party Management · 12 terms
- Security Architecture24 terms
Domain 3 — designing secure networks, cloud, virtualization, and resilience: segmentation, zero-trust, redundancy, backup.
- Cloud and Resilience · 12 terms
- Network Security Architecture · 12 terms
- General Security Concepts24 terms
Domain 1 — the foundational vocabulary of security: the CIA triad, AAA, cryptographic primitives, IAM, and zero-trust.
- Core Security Concepts · 12 terms
- Cryptography and Principles · 12 terms