← All guides

A 14-Week CompTIA Security+ (SY0-701) Study Plan That Fits a Real Schedule

In short

Most people need about 100 hours to pass the CompTIA Security+ (SY0-701) exam. Spread over 14 weeks, that's roughly 7 hours a week — one weekday hour most nights plus a longer weekend session. The plan below follows the five exam domains in order of weight, so your time lands where the questions are.

How long you actually need

The SY0-701 exam is a maximum of 90 questions in 90 minutes, and you pass at 750 on a 100–900 scale — a fixed cutoff that's the same for every candidate. About 100 hours of focused prep is the realistic target for someone with a bit of IT background.

Those hours aren't split evenly, because the domains aren't weighted evenly. Match your study time to the exam's own weighting:

  • Security Operations — 28% · ~28 hours. The largest domain, 15 objectives. This is where performance-based questions live (reading firewall logs, SIEM alerts, incident response steps).
  • Threats, Vulnerabilities, and Mitigations — 22% · ~22 hours. Nine objectives on threat actors, attack types, and malware indicators.
  • Security Program Management and Oversight — 20% · ~20 hours. Risk management, audits, third-party risk, compliance.
  • Security Architecture — 18% · ~18 hours. Cloud, on-prem, and hybrid designs; high availability; backups and recovery.
  • General Security Concepts — 12% · ~12 hours. The foundations: control types, the CIA and AAA concepts, zero trust and gap analysis, and PKI.

Study Security Operations like it's worth 28% of your grade, because it is.

Week by week

Here's the 14 weeks mapped to the domains. Each block ends when you can pass a topic quiz on it, then you move on.

CompTIA Security+ (SY0-701) 14-week study plan, in study order: General Security Concepts (12h) → Threats, Vulnerabilities, and Mitigations (22h) → Security Architecture (18h) → Security Operations (28h) → Security Program Management and Oversight (20h).
CompTIA Security+ (SY0-701) 14-week study plan, in study order: General Security Concepts (12h) → Threats, Vulnerabilities, and Mitigations (22h) → Security Architecture (18h) → Security Operations (28h) → Security Program Management and Oversight (20h).

Weeks 1–2 — General Security Concepts (12 hours). Start with the vocabulary everything else builds on. Learn the four control types
work through the CIA and AAA models
finish with PKI, certificates, and change management. Don't rush this; a shaky grasp here costs you points across all five domains.

Weeks 3–5 — Threats, Vulnerabilities, and Mitigations (22 hours). Nine objectives, so give it three weeks. Build flashcards for threat actors and their motivations
map each attack type (social engineering, network, cryptographic) to its indicators →
learn the enterprise mitigation for each. The exam loves "given this indicator, name the attack" questions.

Weeks 6–7 — Security Architecture (18 hours). Study the diagrams: how cloud, serverless, on-prem, and hybrid networks get secured. Nail high availability, network segmentation, and the difference between hot, warm, and cold recovery sites — these are reliable question sources.

Weeks 8–11 — Security Operations (28 hours). Four full weeks on the biggest domain. Work through secure baselines and hardening →
IAM and privileged access →
the incident response lifecycle →
reading real log snippets from firewalls and SIEM tools. Practice actual performance-based questions here; reading about logs isn't the same as interpreting one under time pressure.

Weeks 12–13 — Security Program Management and Oversight (20 hours). The governance domain. Learn the risk management process end to end, qualitative versus quantitative analysis, third-party vendor risk, and the audit and compliance terminology. It's dry, but it's a fifth of the exam.

Week 14 — Full review and timed practice. No new material. Sit full-length timed practice tests, review every wrong answer back to its objective, and re-drill your weakest domain. You want to be finishing 90 questions with time to spare.

If you have less time (or more)

Compressing to ~8 weeks: double your weekly hours to 12–14 and lean on the weighting. Give full attention to Security Operations, Threats, and Program Management — the three domains that together are 70% of the exam — and move faster through the 12% and 18% domains. Skipping the low-weight domains entirely is a mistake; every domain appears.

Stretching to 20+ weeks: if you're new to IT, add a slower first month on General Security Concepts and Architecture before touching the heavier domains, and keep hands-on labs running the whole time. CompTIA recommends about two years of security-focused IT experience — extra weeks are how you make up for less.

Either way, keep the ratio: your hours per domain should track the exam's percentages, and the final week stays review-only.

Common questions

How many questions are on the SY0-701 exam? A maximum of 90, mixing standard multiple-choice with hands-on performance-based questions.

What is the passing score for Security+? 750 on a 100–900 scale. CompTIA sets it as a fixed cutoff, identical for every candidate.

How much time do I get? 90 minutes for the whole exam — about a minute per question, which is why timed practice matters.

How much does the exam cost? The registration fee is $425.

What topics are covered? Five domains: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management and Oversight (20%).

How long should I study? Around 100 hours for most candidates. Only Ever breaks every domain into 15-minute topics, so you can fit consistent prep around a full schedule instead of hunting for a free afternoon.


Ready to test where you stand? Try the free practice questions for Security+ — full explanations included, no paywall.