Skip to content
CompTIA Security+ and PenTest+

Security+ study plan: a 6-week and a 12-week version

A Security+ study plan for SY0-701 in two versions, 6 weeks and 12 weeks, mapped to the exam domains, with weekly tasks, practice checkpoints and lab work.

LearnCyber editorial team, reviewed by Hackrowd Technology’s penetration testers · · 9 min read

If you already know basic networking and can give the exam 15 or more focused hours a week, the 6-week plan below is realistic. If you’re newer to IT, or you have a job and a family and can give it 6 to 8 hours a week, take the 12-week plan. Both cover the same SY0-701 objectives; the longer one simply gives each domain more room and more practice.

Pick one honestly, then pick a target date now and work backwards; book it once your first full mock (week 5 or week 10) is in a range you’re comfortable with. A booked date tends to turn a plan into a deadline.

Before you start: three things to settle

Which exam version are you sitting?

This plan is built on SY0-701, the current version. CompTIA says the next version, Security+ V8 (SY0-801), is expected to launch on or around 17 November 2026. SY0-701 stays available for a while after that; check CompTIA’s Security+ page for its retirement date before you book.

If you start now, SY0-701 is a sensible choice because study material for it is mature; just confirm it’s still offered on your exam date. If you choose SY0-801, download its objectives from the V8 page and adjust the weights below; the weekly structure still works.

What the exam looks like

SY0-701 has up to 90 questions in 90 minutes, a mix of multiple-choice and performance-based questions (PBQs), with a passing score of 750 on a 100–900 scale. The five domains and their weights are:

Domain Weight
1.0 General Security Concepts 12%
2.0 Threats, Vulnerabilities & Mitigations 22%
3.0 Security Architecture 18%
4.0 Security Operations 28%
5.0 Security Program Management & Oversight 20%

Security Operations alone is more than a quarter of the exam, and Domains 2 and 4 together are half of it. Your plan should reflect that, and both versions below do.

Your core materials

Keep it lean. Four things are enough:

  1. The official exam objectives PDF from CompTIA’s site. This is your checklist. Every line in it is fair game, and nothing outside it is.
  2. One main course, either a video series or a book. Pick one and finish it rather than sampling five.
  3. One bank of practice questions from a reputable publisher, used for learning, not memorising.
  4. A small lab: a Linux virtual machine and a free packet-capture tool are enough to make Domains 2 and 4 concrete. Our home lab guide walks through a free setup.

Avoid “dumps”, meaning collections of leaked or recalled live exam questions. They break CompTIA’s candidate agreement, can cost you the certification, and leave you unable to answer the interview questions that follow.

How to study each week

Both plans use the same weekly rhythm. It’s built around active recall, because rereading notes feels productive and isn’t.

  • Learn (about 50% of your time): watch or read the material for that week’s objectives.
  • Make (about 20%): turn each objective into your own one-line answer or a flashcard. If you can’t write it in one line, you don’t understand it yet.
  • Do (about 15%): one hands-on task tied to the week’s content.
  • Test (about 15%): practice questions on that week’s domain, then review every wrong answer and every lucky guess.

Keep an error log, a simple spreadsheet with three columns: the question topic, why you got it wrong, and the objective number. By week four it becomes the most valuable study document you own, because it shows your real weak spots rather than the ones you assume.

The 6-week Security+ study plan (about 15–18 hours a week)

This plan suits people with some IT background: help desk, networking, system administration, or a completed Network+.

Week Focus Hands-on task Checkpoint
1 Domain 1: security controls, CIA, AAA, zero trust, change management, cryptography and PKI Generate a key pair and a self-signed certificate with OpenSSL; read the certificate fields 30 Domain 1 questions; aim for 75%+
2 Domain 2: threat actors, attack vectors, vulnerability types, indicators of malicious activity, mitigations Capture your own lab traffic in Wireshark and identify DNS, HTTP and a TCP handshake 40 Domain 2 questions
3 Domain 3: cloud and on-premises architecture, network infrastructure, data protection, resilience and recovery Draw a segmented network for a fictional company (DMZ, internal, management) 30 Domain 3 questions
4 Domain 4, first half: hardening, asset management, vulnerability management, monitoring, identity and access management Run a basic Nmap scan against your own lab VM and read the results 40 Domain 4 questions
5 Domain 4, second half (automation, incident response, investigation data sources) and Domain 5 (governance, risk, third parties, compliance, audits, awareness) Write a one-page incident response note for a fictional phishing incident 40 mixed questions; first full-length practice exam at the weekend
6 Error log, PBQ practice, two more full-length exams, light review Redo every PBQ-style task you got wrong Confirm your booked date, or book it now if your week 5 mock was in a range you’re comfortable with

Week 6 rule: no new material after Wednesday. The last three days are for your error log, sleep and one final timed exam.

A note on the “aim for 75%+” targets: they’re sensible personal benchmarks, not CompTIA figures. Practice question banks vary in difficulty, so watch the trend in your own scores rather than chasing a single number.

The 12-week Security+ study plan (about 6–8 hours a week)

This plan suits beginners and working adults. It front-loads foundations, because Security+ assumes you know what a subnet, a port and a protocol are.

Week Focus Hands-on task
1 Foundations: the OSI model, IP addressing, common ports and protocols Run ip a (Linux) or ipconfig (Windows) and explain every line of output
2 Domain 1, part 1: control categories and types, CIA, AAA, zero trust, physical security, deception technologies Sort 20 example controls into technical, managerial, operational and physical
3 Domain 1, part 2: change management, cryptography, hashing, PKI and certificates Hash a file with sha256sum, change one character, hash it again
4 Domain 2, part 1: threat actors and motivations, threat vectors, social engineering Analyse a phishing email in your own inbox’s “show original” view; note the headers
5 Domain 2, part 2: vulnerability types, indicators of malicious activity, mitigation techniques Match ten attack descriptions to their indicators
6 Domain 3, part 1: architecture models, cloud, infrastructure as code, network security design Sketch a segmented network for a fictional company
7 Domain 3, part 2: data types and classification, data protection, resilience, backups and recovery Write a backup plan using the 3-2-1 approach for a fictional small business
8 Domain 4, part 1: hardening, asset management, vulnerability management Scan your own lab VM with Nmap; list open services and decide which to disable
9 Domain 4, part 2: monitoring, logging, email and endpoint security, IAM Read a Linux auth log and find failed logins
10 Domain 4, part 3: automation, incident response, investigation data sources Write an incident timeline for a fictional phishing case; sit your first full-length practice exam at the weekend
11 Domain 5: governance, risk management, third-party risk, compliance, audits, security awareness Fill in a five-row risk register for a fictional fintech
12 Full mocks, PBQ practice, error log review Two timed full-length exams; review every miss

In weeks 1 to 11, end each week with 20 to 30 questions on that week’s content. From week 6, add one mixed 30-question set every fortnight so earlier domains don’t fade.

Hands-on tasks, done properly

The tasks in the tables are small on purpose. Here are two of them in full so you know what “done” looks like.

Hashing (week 3 of the 12-week plan):

$ echo “transfer 5000 to account 0123” > note.txt
$ sha256sum note.txt
698c85092afea6f23a06eca5f299ed1d31a8ed0fda7ada56352d7264926561f8  note.txt
$ echo “transfer 9000 to account 0123” > note.txt
$ sha256sum note.txt
20e25da4a084b4a07d6795dc291b01d5dcee02491fdae84aebbb9bdc7c3b3ee3  note.txt

Run it yourself and you’ll get exactly the same two hashes, because SHA-256 is deterministic. Yet changing one character changed the whole hash. That is integrity, one leg of CIA, and it’s what file integrity monitoring relies on.

Failed logins (week 9):

$ sudo grep “Failed password” /var/log/auth.log | tail -3
Oct 10 09:14:02 lab-ubuntu sshd[2211]: Failed password for invalid user admin from 192.168.56.20 port 51544 ssh2
Oct 10 09:14:05 lab-ubuntu sshd[2213]: Failed password for invalid user admin from 192.168.56.20 port 51546 ssh2
Oct 10 09:14:09 lab-ubuntu sshd[2215]: Failed password for root from 192.168.56.20 port 51550 ssh2

Ask yourself the exam’s questions: what’s the indicator, what’s the likely attack, and what’s the mitigation? (Repeated failures from one host suggest password guessing; mitigations include account lockout, MFA, disabling root login over SSH, and restricting SSH by source address.) On newer distributions that log to the journal instead, journalctl -u ssh shows the same events.

Only run scans and tests against machines you own or have written permission to test.

Performance-based questions

PBQs are short simulations: configure a firewall rule, match attacks to indicators, place controls on a network diagram. They tend to appear at the start of the exam and can eat time. A common approach is to flag a long PBQ, answer the multiple-choice questions, then come back; just be sure to leave enough time to return.

Practise them deliberately from the halfway point of either plan. Our guide to Security+ SY0-701 PBQs covers the common formats and how to practise each.

What forum advice gets right, and wrong

Search “security+ study plan reddit” and you’ll find plenty of threads. The advice that holds up:

  • Use the objectives as your checklist. It’s the most repeated advice from people who passed.
  • One course, one question bank. Switching resources every week is a form of procrastination.
  • Do timed full-length practice before the real thing. Ninety minutes goes faster than you expect.

The advice to treat with care:

  • “I passed in a week.” Possible for someone with years of IT experience. Not a plan for a beginner.
  • “Just memorise the acronyms.” You need them, but the exam asks scenario questions. Knowing what SIEM stands for won’t tell you which log source answers the question.
  • Shared “real exam questions”. These are dumps. Skip them.

Booking the exam

Pick a target date now; book it once your first full mock (week 5 or week 10) is in a range you’re comfortable with. You can sit it online with a remote proctor or at a test centre. Check CompTIA’s Security+ page for the current price, as it changes and differs by region. If you’re booking from Nigeria, our guide on how to book a CompTIA exam from Nigeria covers payment and test-centre options.

Not sure Security+ is the right first exam? Read Security+ vs Network+ before you commit. For deeper notes on every objective and resource, see the CompTIA Security+ SY0-701 study guide.

Questions

How many hours does it take to study for Security+?

It depends on your background. The two plans here add up to roughly 70 to 110 hours in total, but treat that as a planning figure, not a rule. Someone with no IT experience may need more, especially for networking foundations.

Can I pass Security+ with no IT experience?

Yes, people do, but expect to spend extra time on networking basics first. The 12-week plan builds that in during week 1; add another week or two if subnets and ports are completely new to you.

Should I wait for SY0-801?

Not necessarily. SY0-701 remains available after V8 launches (check CompTIA's Security+ page for the retirement date), and both lead to the same Security+ certification. Choose the version whose study material you can get hold of and finish.

How do I know I'm ready?

You're consistently comfortable on full-length timed practice exams, your error log has stopped growing, and you can explain each objective in one line without notes.