If you already know basic networking and can give the exam 15 or more focused hours a week, the 6-week plan below is realistic. If you’re newer to IT, or you have a job and a family and can give it 6 to 8 hours a week, take the 12-week plan. Both cover the same SY0-701 objectives; the longer one simply gives each domain more room and more practice.
Pick one honestly, then pick a target date now and work backwards; book it once your first full mock (week 5 or week 10) is in a range you’re comfortable with. A booked date tends to turn a plan into a deadline.
Before you start: three things to settle
Which exam version are you sitting?
This plan is built on SY0-701, the current version. CompTIA says the next version, Security+ V8 (SY0-801), is expected to launch on or around 17 November 2026. SY0-701 stays available for a while after that; check CompTIA’s Security+ page for its retirement date before you book.
If you start now, SY0-701 is a sensible choice because study material for it is mature; just confirm it’s still offered on your exam date. If you choose SY0-801, download its objectives from the V8 page and adjust the weights below; the weekly structure still works.
What the exam looks like
SY0-701 has up to 90 questions in 90 minutes, a mix of multiple-choice and performance-based questions (PBQs), with a passing score of 750 on a 100–900 scale. The five domains and their weights are:
| Domain | Weight |
|---|---|
| 1.0 General Security Concepts | 12% |
| 2.0 Threats, Vulnerabilities & Mitigations | 22% |
| 3.0 Security Architecture | 18% |
| 4.0 Security Operations | 28% |
| 5.0 Security Program Management & Oversight | 20% |
Security Operations alone is more than a quarter of the exam, and Domains 2 and 4 together are half of it. Your plan should reflect that, and both versions below do.
Your core materials
Keep it lean. Four things are enough:
- The official exam objectives PDF from CompTIA’s site. This is your checklist. Every line in it is fair game, and nothing outside it is.
- One main course, either a video series or a book. Pick one and finish it rather than sampling five.
- One bank of practice questions from a reputable publisher, used for learning, not memorising.
- A small lab: a Linux virtual machine and a free packet-capture tool are enough to make Domains 2 and 4 concrete. Our home lab guide walks through a free setup.
Avoid “dumps”, meaning collections of leaked or recalled live exam questions. They break CompTIA’s candidate agreement, can cost you the certification, and leave you unable to answer the interview questions that follow.
How to study each week
Both plans use the same weekly rhythm. It’s built around active recall, because rereading notes feels productive and isn’t.
- Learn (about 50% of your time): watch or read the material for that week’s objectives.
- Make (about 20%): turn each objective into your own one-line answer or a flashcard. If you can’t write it in one line, you don’t understand it yet.
- Do (about 15%): one hands-on task tied to the week’s content.
- Test (about 15%): practice questions on that week’s domain, then review every wrong answer and every lucky guess.
Keep an error log, a simple spreadsheet with three columns: the question topic, why you got it wrong, and the objective number. By week four it becomes the most valuable study document you own, because it shows your real weak spots rather than the ones you assume.
The 6-week Security+ study plan (about 15–18 hours a week)
This plan suits people with some IT background: help desk, networking, system administration, or a completed Network+.
| Week | Focus | Hands-on task | Checkpoint |
|---|---|---|---|
| 1 | Domain 1: security controls, CIA, AAA, zero trust, change management, cryptography and PKI | Generate a key pair and a self-signed certificate with OpenSSL; read the certificate fields | 30 Domain 1 questions; aim for 75%+ |
| 2 | Domain 2: threat actors, attack vectors, vulnerability types, indicators of malicious activity, mitigations | Capture your own lab traffic in Wireshark and identify DNS, HTTP and a TCP handshake | 40 Domain 2 questions |
| 3 | Domain 3: cloud and on-premises architecture, network infrastructure, data protection, resilience and recovery | Draw a segmented network for a fictional company (DMZ, internal, management) | 30 Domain 3 questions |
| 4 | Domain 4, first half: hardening, asset management, vulnerability management, monitoring, identity and access management | Run a basic Nmap scan against your own lab VM and read the results | 40 Domain 4 questions |
| 5 | Domain 4, second half (automation, incident response, investigation data sources) and Domain 5 (governance, risk, third parties, compliance, audits, awareness) | Write a one-page incident response note for a fictional phishing incident | 40 mixed questions; first full-length practice exam at the weekend |
| 6 | Error log, PBQ practice, two more full-length exams, light review | Redo every PBQ-style task you got wrong | Confirm your booked date, or book it now if your week 5 mock was in a range you’re comfortable with |
Week 6 rule: no new material after Wednesday. The last three days are for your error log, sleep and one final timed exam.
A note on the “aim for 75%+” targets: they’re sensible personal benchmarks, not CompTIA figures. Practice question banks vary in difficulty, so watch the trend in your own scores rather than chasing a single number.
The 12-week Security+ study plan (about 6–8 hours a week)
This plan suits beginners and working adults. It front-loads foundations, because Security+ assumes you know what a subnet, a port and a protocol are.
| Week | Focus | Hands-on task |
|---|---|---|
| 1 | Foundations: the OSI model, IP addressing, common ports and protocols | Run ip a (Linux) or ipconfig (Windows) and explain every line of output |
| 2 | Domain 1, part 1: control categories and types, CIA, AAA, zero trust, physical security, deception technologies | Sort 20 example controls into technical, managerial, operational and physical |
| 3 | Domain 1, part 2: change management, cryptography, hashing, PKI and certificates | Hash a file with sha256sum, change one character, hash it again |
| 4 | Domain 2, part 1: threat actors and motivations, threat vectors, social engineering | Analyse a phishing email in your own inbox’s “show original” view; note the headers |
| 5 | Domain 2, part 2: vulnerability types, indicators of malicious activity, mitigation techniques | Match ten attack descriptions to their indicators |
| 6 | Domain 3, part 1: architecture models, cloud, infrastructure as code, network security design | Sketch a segmented network for a fictional company |
| 7 | Domain 3, part 2: data types and classification, data protection, resilience, backups and recovery | Write a backup plan using the 3-2-1 approach for a fictional small business |
| 8 | Domain 4, part 1: hardening, asset management, vulnerability management | Scan your own lab VM with Nmap; list open services and decide which to disable |
| 9 | Domain 4, part 2: monitoring, logging, email and endpoint security, IAM | Read a Linux auth log and find failed logins |
| 10 | Domain 4, part 3: automation, incident response, investigation data sources | Write an incident timeline for a fictional phishing case; sit your first full-length practice exam at the weekend |
| 11 | Domain 5: governance, risk management, third-party risk, compliance, audits, security awareness | Fill in a five-row risk register for a fictional fintech |
| 12 | Full mocks, PBQ practice, error log review | Two timed full-length exams; review every miss |
In weeks 1 to 11, end each week with 20 to 30 questions on that week’s content. From week 6, add one mixed 30-question set every fortnight so earlier domains don’t fade.
Hands-on tasks, done properly
The tasks in the tables are small on purpose. Here are two of them in full so you know what “done” looks like.
Hashing (week 3 of the 12-week plan):
$ echo “transfer 5000 to account 0123” > note.txt
$ sha256sum note.txt
698c85092afea6f23a06eca5f299ed1d31a8ed0fda7ada56352d7264926561f8 note.txt
$ echo “transfer 9000 to account 0123” > note.txt
$ sha256sum note.txt
20e25da4a084b4a07d6795dc291b01d5dcee02491fdae84aebbb9bdc7c3b3ee3 note.txt
Run it yourself and you’ll get exactly the same two hashes, because SHA-256 is deterministic. Yet changing one character changed the whole hash. That is integrity, one leg of CIA, and it’s what file integrity monitoring relies on.
Failed logins (week 9):
$ sudo grep “Failed password” /var/log/auth.log | tail -3
Oct 10 09:14:02 lab-ubuntu sshd[2211]: Failed password for invalid user admin from 192.168.56.20 port 51544 ssh2
Oct 10 09:14:05 lab-ubuntu sshd[2213]: Failed password for invalid user admin from 192.168.56.20 port 51546 ssh2
Oct 10 09:14:09 lab-ubuntu sshd[2215]: Failed password for root from 192.168.56.20 port 51550 ssh2
Ask yourself the exam’s questions: what’s the indicator, what’s the likely attack, and what’s the mitigation? (Repeated failures from one host suggest password guessing; mitigations include account lockout, MFA, disabling root login over SSH, and restricting SSH by source address.) On newer distributions that log to the journal instead, journalctl -u ssh shows the same events.
Only run scans and tests against machines you own or have written permission to test.
Performance-based questions
PBQs are short simulations: configure a firewall rule, match attacks to indicators, place controls on a network diagram. They tend to appear at the start of the exam and can eat time. A common approach is to flag a long PBQ, answer the multiple-choice questions, then come back; just be sure to leave enough time to return.
Practise them deliberately from the halfway point of either plan. Our guide to Security+ SY0-701 PBQs covers the common formats and how to practise each.
What forum advice gets right, and wrong
Search “security+ study plan reddit” and you’ll find plenty of threads. The advice that holds up:
- Use the objectives as your checklist. It’s the most repeated advice from people who passed.
- One course, one question bank. Switching resources every week is a form of procrastination.
- Do timed full-length practice before the real thing. Ninety minutes goes faster than you expect.
The advice to treat with care:
- “I passed in a week.” Possible for someone with years of IT experience. Not a plan for a beginner.
- “Just memorise the acronyms.” You need them, but the exam asks scenario questions. Knowing what SIEM stands for won’t tell you which log source answers the question.
- Shared “real exam questions”. These are dumps. Skip them.
Booking the exam
Pick a target date now; book it once your first full mock (week 5 or week 10) is in a range you’re comfortable with. You can sit it online with a remote proctor or at a test centre. Check CompTIA’s Security+ page for the current price, as it changes and differs by region. If you’re booking from Nigeria, our guide on how to book a CompTIA exam from Nigeria covers payment and test-centre options.
Not sure Security+ is the right first exam? Read Security+ vs Network+ before you commit. For deeper notes on every objective and resource, see the CompTIA Security+ SY0-701 study guide.