← All guides

A 14-Week CompTIA Security+ (SY0-701) Study Plan That Fits a Real Schedule

In short

Most people need about 100 hours to pass the CompTIA Security+ (SY0-701) exam. Spread over 14 weeks, that's roughly 7 hours a week — one weekday hour most nights plus a longer weekend session. The plan below follows the five exam domains in order of weight, so your time lands where the questions are.

How long you actually need

The SY0-701 exam is a maximum of 90 questions in 90 minutes, and you pass at 750 on a 100–900 scale — a fixed cutoff that's the same for every candidate. About 100 hours of focused prep is the realistic target for someone with a bit of IT background.

Those hours aren't split evenly, because the domains aren't weighted evenly. Match your study time to the exam's own weighting:

  • Security Operations — 28% · ~28 hours. The largest domain, 15 objectives. This is where performance-based questions live (reading firewall logs, SIEM alerts, incident response steps).
  • Threats, Vulnerabilities, and Mitigations — 22% · ~22 hours. Nine objectives on threat actors, attack types, and malware indicators.
  • Security Program Management and Oversight — 20% · ~20 hours. Risk management, audits, third-party risk, compliance.
  • Security Architecture — 18% · ~18 hours. Cloud, on-prem, and hybrid designs; high availability; backups and recovery.
  • General Security Concepts — 12% · ~12 hours. The foundations: control types, the CIA and AAA concepts, zero trust and gap analysis, and PKI.

Study Security Operations like it's worth 28% of your grade, because it is.

Week by week

Here's the 14 weeks mapped to the domains. Each block ends when you can pass a topic quiz on it, then you move on.

CompTIA Security+ (SY0-701) 14-week study plan, in study order: General Security Concepts (12h) → Threats, Vulnerabilities, and Mitigations (22h) → Security Architecture (18h) → Security Operations (28h) → Security Program Management and Oversight (20h).
CompTIA Security+ (SY0-701) 14-week study plan, in study order: General Security Concepts (12h) → Threats, Vulnerabilities, and Mitigations (22h) → Security Architecture (18h) → Security Operations (28h) → Security Program Management and Oversight (20h).

Weeks 1–2 — General Security Concepts (12 hours). Start with the vocabulary everything else builds on. Learn the four control types → work through the CIA and AAA models → finish with PKI, certificates, and change management. Don't rush this; a shaky grasp here costs you points across all five domains.

Weeks 3–5 — Threats, Vulnerabilities, and Mitigations (22 hours). Nine objectives, so give it three weeks. Build flashcards for threat actors and their motivations → map each attack type (social engineering, network, cryptographic) to its indicators → learn the enterprise mitigation for each. The exam loves "given this indicator, name the attack" questions.

Weeks 6–7 — Security Architecture (18 hours). Study the diagrams: how cloud, serverless, on-prem, and hybrid networks get secured. Nail high availability, network segmentation, and the difference between hot, warm, and cold recovery sites — these are reliable question sources.

Weeks 8–11 — Security Operations (28 hours). Four full weeks on the biggest domain. Work through secure baselines and hardening → IAM and privileged access → the incident response lifecycle → reading real log snippets from firewalls and SIEM tools. Practice actual performance-based questions here; reading about logs isn't the same as interpreting one under time pressure.

Weeks 12–13 — Security Program Management and Oversight (20 hours). The governance domain. Learn the risk management process end to end, qualitative versus quantitative analysis, third-party vendor risk, and the audit and compliance terminology. It's dry, but it's a fifth of the exam.

Week 14 — Full review and timed practice. No new material. Sit full-length timed practice tests, review every wrong answer back to its objective, and re-drill your weakest domain. You want to be finishing 90 questions with time to spare.

If you have less time (or more)

Compressing to ~8 weeks: double your weekly hours to 12–14 and lean on the weighting. Give full attention to Security Operations, Threats, and Program Management — the three domains that together are 70% of the exam — and move faster through the 12% and 18% domains. Skipping the low-weight domains entirely is a mistake; every domain appears.

Stretching to 20+ weeks: if you're new to IT, add a slower first month on General Security Concepts and Architecture before touching the heavier domains, and keep hands-on labs running the whole time. CompTIA recommends about two years of security-focused IT experience — extra weeks are how you make up for less.

Either way, keep the ratio: your hours per domain should track the exam's percentages, and the final week stays review-only.

Common questions

How many questions are on the SY0-701 exam? A maximum of 90, mixing standard multiple-choice with hands-on performance-based questions.

What is the passing score for Security+? 750 on a 100–900 scale. CompTIA sets it as a fixed cutoff, identical for every candidate.

How much time do I get? 90 minutes for the whole exam — about a minute per question, which is why timed practice matters.

How much does the exam cost? The registration fee is $425.

What topics are covered? Five domains: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management and Oversight (20%).

How long should I study? Around 100 hours for most candidates. Only Ever breaks every domain into 15-minute topics, so you can fit consistent prep around a full schedule instead of hunting for a free afternoon.


Ready to test where you stand? Try the free practice questions for Security+ — full explanations included, no paywall.