CompTIA Security+ Study Guide (SY0-701)
Welcome to the complete, open study curriculum for the CompTIA Security+ (SY0-701) examination. Organized across 5 official domains and 20 modular lessons, each section breaks down enterprise cybersecurity, threat intelligence, security architecture, incident response, and governance with explicit exam trap callouts, technical summaries, and interactive knowledge checkpoints.
Curriculum Roadmap
General Security Concepts & Cryptography
Core cybersecurity tenets including CIA triad, non-repudiation, Zero Trust architecture, security control taxonomies, and cryptographic algorithms.
Threats, Vulnerabilities, and Mitigations
Analysis of threat actors, social engineering vectors, malware strains, web application exploits (OWASP Top 10), and defensive mitigation strategies.
Security Architecture & Network Defense
Secure enterprise topologies, cloud models, perimeter security appliances, data protection (DLP/tokenization), and high-availability resilience.
Security Operations & Incident Response
System baseline hardening, IAM/PAM governance, SIEM/SOAR monitoring, vulnerability management, digital forensics, and incident response execution.
Security Program Management & Governance
Enterprise cybersecurity frameworks (NIST CSF 2.0, ISO 27001), regulatory compliance, quantitative risk math (SLE/ALE), vendor oversight, and personnel security.