The 5 Security+ SY0-701 Domains Explained
What each Security+ SY0-701 domain covers, its exam weight and the topics candidates most often get wrong.
Security+ domains · 6 min read · updated 2026-09-04
Security+ SY0-701 measures five domains with very different weights. Knowing where the exam concentrates its points tells you where to spend your weeks.
General Security Concepts (12%) and Threats (22%)
Concepts sets the vocabulary: CIA triad, zero trust, cryptography fundamentals, change management and risk terminology. Threats, vulnerabilities and mitigations then tests attack types, malware, vulnerability scanning and which control stops which attack.
The classic mistake is memorising attack names without their mitigations - the exam asks you to pick the control, not the definition.
Security Architecture (18%) and Security Operations (28%)
Architecture spans on-premises and cloud models, virtualization, enterprise network design and data protection strategies. Operations is the heaviest domain: asset hardening, baselines, identity and access, detection, log analysis and incident response basics.
Operations is where scenario questions concentrate - expect log snippets, indicator analysis and questions about the correct sequence of response steps.
Security Program Management (20%)
Governance and compliance, policy hierarchy, risk management math (ALE, SLE, ARO), third-party risk and security awareness programs. This domain is deceptively textual - the exam uses close wording to test whether you can tell appetite from tolerance or policy from standard.
Write the definitions in your own words and compare them side by side; rote reading rarely survives the distractors.
Frequently asked questions
- What are the five Security+ SY0-701 domains?
- General Security Concepts (12%), Threats, Vulnerabilities and Mitigations (22%), Security Architecture (18%), Security Operations (28%) and Security Program Management (20%).
- Is SY0-701 the latest Security+ version?
- Yes - SY0-701 replaced SY0-601 as the current version. Make sure any study material, practice questions or voucher you buy explicitly says SY0-701.
- Which Security+ domain should I study first?
- Start with General Security Concepts because everything else reuses its vocabulary, then move to Threats and Mitigations - at 22% it is one of the two heaviest domains alongside Security Operations at 28%.
Keep reading for Security+
PassYour is an independent study aid and is not affiliated with, endorsed by or sponsored by ISC2, CompTIA or Microsoft.
