CompTIA Security+ 6-Week Study Plan (SY0-701)
The CompTIA Security+ (SY0-701) examination features up to 90 scored scenario questions and performance-based questions (PBQs), with a 90-minute time limit and a 750/900 scaled passing score (~83.3%). Follow this structured 6-week roadmap to allocate your study hours, pace your test session at 1.00 minute per multiple-choice question, and execute the essential Pearson VUE first-5-minute dry-erase dump sheet.
6-Week Structured Study Schedule
Week 1: Domain 1.0 — General Security Concepts & Cryptography
Study CIA triad, control taxonomies (managerial, operational, technical), functional types (preventative, detective, corrective), symmetric vs asymmetric ciphers, hashing, and PKI certificate architectures.
Week 2: Domain 2.0 — Threats, Vulnerabilities, and Mitigations
Analyze threat actors, attack vectors, social engineering, OWASP Top 10 vulnerabilities, supply chain risks, and malware indicators.
Week 3: Domain 3.0 — Security Architecture & Cloud
Master Zero Trust architecture (ZTA), secure network design (microsegmentation, SASE, CASB), cloud security shared responsibility models, and resilient infrastructure.
Week 4: Domain 4.0 — Security Operations & Incident Response
Dive into SIEM log aggregation, SOAR automated playbooks, vulnerability scanning, digital forensics acquisition, and baseline hardening.
Week 5: Domain 5.0 — Governance, Risk, and Compliance
Review NIST CSF, ISO 27001, privacy regulations (GDPR, HIPAA), third-party vendor assessments, BIA disaster recovery, and data classification.
Week 6: Full-Length Practice Exams & Distractor Autopsies
Run multiple full 90-question timed mock simulations, review wrong answers with distractor autopsies, and memorize the first-5-minute Pearson VUE dump sheet.
Pearson VUE First-5-Minute Dry-Erase Dump Sheet
As soon as your test timer begins at Pearson VUE, write down these core reference triggers on your provided dry-erase scratch booklet:
- Technical = Machine logic (ACL, cipher)
- Managerial = Policy & governance (AUP)
- Operational = Human procedure (Patrols)
- Kerberos: UDP/TCP 88
- TACACS+: TCP 49 | RADIUS: 1812/1813
- LDAPS: TCP 636 | SNMPv3: UDP 161/162
- 1. Preparation → 2. Detection/Analysis
- 3. Containment → 4. Eradication
- 5. Recovery → 6. Lessons Learned