Explore / Careers & Certification
CompTIA Security+ (SY0-701) Exam Prep

Work through every bullet of CompTIA's Security+ SY0-701 objectives from first principles, in proportion to the five domain weights, with scenario-based checks, performance-based question reasoning practice and a timed 90-question mock. This is independent study material, not affiliated with or endo
Expert · 64 levels · 2 free · Created Oct 2026 · Professionally curated by levelupwith.com
What's inside
- Level 1: Exam Orientation: SY0-701 Facts and Question FormatsFree
[Orientation – all domains] Learn how the CompTIA Security+ (SY0-701) exam is structured — at most 90 questions in 90 minutes, pass mark 750 on a 100-900 scale, multiple-choice and performance-based questions, five weighted domains, English exam retiring 11 June 2027 — and how this independent course (not affiliated with CompTIA, with no promise of a pass) maps to objectives version 5.0. - Level 2: Security Control Categories and Control TypesFree
[1.0 General Security Concepts – 1.1] Compare and contrast the four control categories (Technical, Managerial, Operational, Physical) and the six control types (Preventive, Deterrent, Detective, Corrective, Compensating, Directive). - Level 3: CIA, Non-repudiation, AAA and Gap Analysis
[1.0 General Security Concepts – 1.2] Summarize Confidentiality, Integrity, and Availability (CIA), non-repudiation, Authentication, Authorization, and Accounting (AAA) — authenticating people, authenticating systems, authorization models — and gap analysis. - Level 4: Zero Trust: Control Plane and Data Plane
[1.0 General Security Concepts – 1.2] Explain Zero Trust from first principles: the Control Plane (adaptive identity, threat scope reduction, policy-driven access control, Policy Administrator, Policy Engine) and the Data Plane (implicit trust zones, subject/system, Policy Enforcement Point). - Level 5: Physical Security and Deception Technology
[1.0 General Security Concepts – 1.2] Summarize physical security (bollards, access control vestibule, fencing, video surveillance, security guard, access badge, lighting, and infrared, pressure, microwave and ultrasonic sensors) and deception and disruption technology (honeypot, honeynet, honeyfile, honeytoken). - Level 6: Change Management and Its Security Impact
[1.0 General Security Concepts – 1.3] Explain change management: business processes (approval process, ownership, stakeholders, impact analysis, test results, backout plan, maintenance window, standard operating procedure), technical implications (allow lists/deny lists, restricted activities, downtime, service restart, application restart, legacy applications, dependencies), documentation (updating diagrams, policies/procedures) and version control. - Level 7: Encryption, Key Exchange and Cryptographic Tools
[1.0 General Security Concepts – 1.4] Explain encryption from first principles: symmetric vs. asymmetric, public key and private key, key exchange, algorithms and key length, transport/communication encryption, encryption levels (full-disk, partition, file, volume, database, record), and the tools Trusted Platform Module (TPM), hardware security module (HSM), key management system and secure enclave. - Level 8: Hashing, Signatures, Obfuscation, PKI and Certificates
[1.0 General Security Concepts – 1.4] Explain hashing, salting, key stretching, digital signatures, obfuscation (steganography, tokenization, data masking), blockchain and the open public ledger, and public key infrastructure (PKI): key escrow, certificate authorities, certificate revocation lists (CRLs), Online Certificate Status Protocol (OCSP), self-signed and third-party certificates, root of trust, certificate signing request (CSR) generation and wildcard certificates. - Level 9: Threat Actors, Attributes and Motivations
[2.0 Threats, Vulnerabilities, and Mitigations – 2.1] Compare and contrast threat actors (nation-state, unskilled attacker, hacktivist, insider threat, organized crime, shadow IT), their attributes (internal/external, resources/funding, level of sophistication/capability) and motivations (data exfiltration, espionage, service disruption, blackmail, financial gain, philosophical/political beliefs, ethical, revenge, disruption/chaos, war). - Level 10: Threat Vectors and Attack Surfaces
[2.0 Threats, Vulnerabilities, and Mitigations – 2.2] Explain the technical threat vectors and attack surfaces: message-based (email, Short Message Service (SMS), instant messaging (IM)), image-based, file-based, voice call, removable device, vulnerable software (client-based vs. agentless), unsupported systems and applications, unsecure networks (wireless, wired, Bluetooth), open service ports, default credentials, and supply chain (managed service providers (MSPs), vendors, suppliers). - Level 11: Human Vectors and Social Engineering
[2.0 Threats, Vulnerabilities, and Mitigations – 2.2] Explain human vectors/social engineering: phishing, vishing, smishing, misinformation/disinformation, impersonation, business email compromise, pretexting, watering hole, brand impersonation and typosquatting. - Level 12: Application, OS-based and Web-based Vulnerabilities
[2.0 Threats, Vulnerabilities, and Mitigations – 2.3] Explain software vulnerability types: application (memory injection, buffer overflow, race conditions with time-of-check (TOC) and time-of-use (TOU), malicious update), operating system (OS)-based, and web-based (Structured Query Language injection (SQLi), cross-site scripting (XSS)). - Level 13: Hardware, Virtualization, Cloud and Other Vulnerabilities
[2.0 Threats, Vulnerabilities, and Mitigations – 2.3] Explain the remaining vulnerability types: hardware (firmware, end-of-life, legacy), virtualization (virtual machine (VM) escape, resource reuse), cloud-specific, supply chain (service provider, hardware provider, software provider), cryptographic, misconfiguration, mobile device (side loading, jailbreaking) and zero-day. - Level 14: Indicators of Malware Attacks
[2.0 Threats, Vulnerabilities, and Mitigations – 2.4] Given a scenario, analyze indicators of malware attacks: ransomware, Trojan, worm, spyware, bloatware, virus, keylogger, logic bomb and rootkit. - Level 15: Indicators of Physical and Network Attacks
[2.0 Threats, Vulnerabilities, and Mitigations – 2.4] Given a scenario, analyze physical attacks (brute force, radio frequency identification (RFID) cloning, environmental) and network attacks (distributed denial-of-service (DDoS) amplified and reflected, Domain Name System (DNS) attacks, wireless, on-path, credential replay, malicious code). - Level 16: Indicators of Application Attacks
[2.0 Threats, Vulnerabilities, and Mitigations – 2.4] Given a scenario, analyze application attacks: injection, buffer overflow, replay, privilege escalation, forgery and directory traversal. - Level 17: Cryptographic and Password Attacks
[2.0 Threats, Vulnerabilities, and Mitigations – 2.4] Given a scenario, analyze cryptographic attacks (downgrade, collision, birthday) and password attacks (spraying, brute force). - Level 18: Reading Indicators of Malicious Activity
[2.0 Threats, Vulnerabilities, and Mitigations – 2.4] Given a scenario, interpret the listed indicators: account lockout, concurrent session usage, blocked content, impossible travel, resource consumption, resource inaccessibility, out-of-cycle logging, published/documented and missing logs. - Level 19: Enterprise Mitigation Techniques
[2.0 Threats, Vulnerabilities, and Mitigations – 2.5] Explain the purpose of mitigation techniques used to secure the enterprise: segmentation, access control (access control list (ACL), permissions), application allow list, isolation, patching, encryption, monitoring, least privilege, configuration enforcement and decommissioning. - Level 20: Hardening Techniques
[2.0 Threats, Vulnerabilities, and Mitigations – 2.5] Explain hardening techniques: encryption, installation of endpoint protection, host-based firewall, host-based intrusion prevention system (HIPS), disabling ports/protocols, default password changes and removal of unnecessary software. - Level 21: Cloud, On-Premises and the Responsibility Matrix
[Security Architecture] Objective 3.1: compares the security implications of cloud, on-premises, and centralized vs. decentralized architecture models, explaining the cloud responsibility matrix, hybrid considerations and third-party vendors from first principles. - Level 22: Virtualization, Containers, IaC, Serverless and SDN
[Security Architecture] Objective 3.1: explains virtualization, containerization, microservices, serverless, infrastructure as code (IaC) and network infrastructure choices: physical isolation (air-gapped), logical segmentation and software-defined networking (SDN). - Level 23: IoT, ICS/SCADA, RTOS, Embedded Systems and Trade-offs
[Security Architecture] Objective 3.1: covers Internet of Things (IoT), industrial control systems (ICS)/supervisory control and data acquisition (SCADA), real-time operating system (RTOS), embedded systems and high availability, then weighs every listed consideration from availability and cost to inability to patch, power and compute. - Level 24: Zones, Device Placement and Failure Modes
[Security Architecture] Objective 3.2: applies the infrastructure considerations of device placement, security zones, attack surface, connectivity, failure modes (fail-open, fail-closed) and device attributes (active vs. passive, inline vs. tap/monitor). - Level 25: Network Appliances, Port Security and Firewall Types
[Security Architecture] Objective 3.2: teaches the network appliances (jump server, proxy server, intrusion prevention system (IPS)/intrusion detection system (IDS), load balancer, sensors), port security with 802.1X and Extensible Authentication Protocol (EAP), and the firewall types: web application firewall (WAF), unified threat management (UTM), next-generation firewall (NGFW) and Layer 4/Layer 7. - Level 26: VPN, TLS, IPSec, SD-WAN, SASE and Control Selection
[Security Architecture] Objective 3.2: covers secure communication/access, including virtual private network (VPN), remote access, tunneling with Transport Layer Security (TLS) and Internet protocol security (IPSec), software-defined wide area network (SD-WAN) and secure access service edge (SASE), and practises the selection of effective controls. - Level 27: Data Types and Classifications
[Security Architecture] Objective 3.3: defines the data types (regulated, trade secret, intellectual property, legal information, financial information, human- and non-human-readable) and the data classifications (sensitive, confidential, public, restricted, private, critical). - Level 28: Data States, Sovereignty and Protection Methods
[Security Architecture] Objective 3.3: explains the data states (data at rest, data in transit, data in use), data sovereignty and geolocation, and the methods to secure data: geographic restrictions, encryption, hashing, masking, tokenization, obfuscation, segmentation and permission restrictions. - Level 29: High Availability, Sites and Continuity Planning
[Security Architecture] Objective 3.4: teaches resilience through high availability (load balancing vs. clustering), site considerations (hot, cold, warm, geographic dispersion), platform diversity, multi-cloud systems, continuity of operations and capacity planning for people, technology and infrastructure. - Level 30: Resilience Testing, Backups and Power
[Security Architecture] Objective 3.4: covers recovery through testing (tabletop exercises, fail over, simulation, parallel processing), backups (onsite/offsite, frequency, encryption, snapshots, recovery, replication, journaling) and power (generators, uninterruptible power supply (UPS)). - Level 31: Secure Baselines and Hardening Targets
[Security Operations] Objective 4.1: applies secure baselines (establish, deploy, maintain) and hardening across the listed targets: mobile devices, workstations, switches, routers, cloud infrastructure, servers, ICS/SCADA, embedded systems, RTOS and IoT devices. - Level 32: Wireless Installation and Security Settings
[Security Operations] Objective 4.1: covers wireless devices and their installation considerations (site surveys, heat maps) and wireless security settings: Wi-Fi Protected Access 3 (WPA3), AAA/Remote Authentication Dial-In User Service (RADIUS), cryptographic protocols and authentication protocols. - Level 33: Mobile Solutions: MDM and Deployment Models
[Security Operations] Objective 4.1: teaches mobile solutions, including mobile device management (MDM), the deployment models bring your own device (BYOD), corporate-owned, personally enabled (COPE) and choose your own device (CYOD), and the connection methods cellular, Wi-Fi and Bluetooth. - Level 34: Application Security, Sandboxing and Monitoring
[Security Operations] Objective 4.1: covers application security techniques (input validation, secure cookies, static code analysis, code signing) together with sandboxing and monitoring as applied to computing resources. - Level 35: Asset Management from Acquisition to Disposal
[Security Operations] Objective 4.2: explains the security implications of hardware, software and data asset management: the acquisition/procurement process, assignment/accounting (ownership, classification), monitoring/asset tracking (inventory, enumeration) and disposal/decommissioning (sanitization, destruction, certification, data retention). - Level 36: Finding Vulnerabilities: Identification Methods
[Security Operations] Objective 4.3: teaches the vulnerability identification methods: vulnerability scan, application security (static analysis, dynamic analysis, package monitoring), threat feeds (open-source intelligence (OSINT), proprietary/third-party, information-sharing organization, dark web), penetration testing, responsible disclosure program and bug bounty program, and system/process audit. - Level 37: Vulnerability Analysis, Remediation and Reporting
[Security Operations] Objective 4.3: covers vulnerability analysis (confirmation of false positives and false negatives, prioritization, Common Vulnerability Scoring System (CVSS), Common Vulnerabilities and Exposures (CVE), vulnerability classification, exposure factor, environmental variables, industry/organizational impact, risk tolerance), response and remediation (patching, insurance, segmentation, compensating controls, exceptions and exemptions), validation of remediation (rescanning, audit, verification) and reporting. - Level 38: Security Alerting and Monitoring Tools
[Security Operations] Objective 4.4: explains monitoring of computing resources (systems, applications, infrastructure), the activities (log aggregation, alerting, scanning, reporting, archiving, alert response and remediation/validation with quarantine and alert tuning) and the tools: Security Content Automation Protocol (SCAP), benchmarks, agents/agentless, security information and event management (SIEM), antivirus, data loss prevention (DLP), Simple Network Management Protocol (SNMP) traps, NetFlow and vulnerability scanners. - Level 39: Firewall Rules, IDS/IPS, Web Filters and OS Security
[Security Operations] Objective 4.5: modifies enterprise capabilities to enhance security through the firewall (rules, access lists, ports/protocols, screened subnets), IDS/IPS (trends, signatures), web filter (agent-based, centralized proxy, Uniform Resource Locator (URL) scanning, content categorization, block rules, reputation) and operating system security (Group Policy, Security-Enhanced Linux (SELinux)). - Level 40: Secure Protocols, Ports, DNS Filtering and Email
[Security Operations] Objective 4.5: teaches implementation of secure protocols (protocol selection, port selection, transport method) with the secure protocols and their ports, DNS filtering, and email security: Domain-based Message Authentication Reporting and Conformance (DMARC), DomainKeys Identified Mail (DKIM), Sender Policy Framework (SPF) and gateway. - Level 41: Identity Lifecycle, Federation and Single Sign-On
[4.0 Security Operations] Serves objective 4.6 (implement and maintain identity and access management): provisioning/de-provisioning user accounts, permission assignments and implications, identity proofing, federation, single sign-on (SSO) with Lightweight Directory Access Protocol (LDAP), Open Authorization (OAuth) and Security Assertions Markup Language (SAML), interoperability and attestation. - Level 42: Access Controls, MFA, Passwords and Privileged Access
[4.0 Security Operations] Serves objective 4.6: access controls (mandatory, discretionary, role-based, rule-based, attribute-based, time-of-day restrictions, least privilege), multifactor authentication (MFA) implementations and factors, password concepts, and privileged access management (PAM) tools. - Level 43: Automation and Orchestration for Secure Operations
[4.0 Security Operations] Serves objective 4.7 (explain the importance of automation and orchestration related to secure operations): use cases of automation and scripting, benefits and other considerations. - Level 44: The Incident Response Process
[4.0 Security Operations] Serves objective 4.8 (given a scenario, implement appropriate incident response activities): the process of preparation, detection, analysis, containment, eradication, recovery and lessons learned, plus training, testing (tabletop exercise, simulation), root cause analysis and threat hunting. - Level 45: Digital Forensics and Evidence Handling
[4.0 Security Operations] Serves objective 4.8: digital forensics activities of legal hold, chain of custody, acquisition, reporting, preservation and e-discovery. - Level 46: Logs and Data Sources for Investigations
[4.0 Security Operations] Serves objective 4.9 (given a scenario, use data sources to support an investigation): log data (firewall logs, application logs, endpoint logs, OS-specific security logs, IPS/IDS logs, network logs, metadata) and data sources (vulnerability scans, automated reports, dashboards, packet captures). - Level 47: Governance: Policies, Standards, Procedures, Guidelines
[5.0 Security Program Management and Oversight] Serves objective 5.1 (summarize elements of effective security governance): guidelines, policies, standards and procedures, with every named example. - Level 48: Governance Structures, External Factors and Data Roles
[5.0 Security Program Management and Oversight] Serves objective 5.1: external considerations, monitoring and revision, types of governance structures, and roles and responsibilities for systems and data. - Level 49: Risk Identification, Assessment and Analysis
[5.0 Security Program Management and Oversight] Serves objective 5.2 (explain elements of the risk management process): risk identification, risk assessment (ad hoc, recurring, one-time, continuous) and risk analysis, both qualitative and quantitative. - Level 50: Risk Registers, Appetite, Strategies and BIA
[5.0 Security Program Management and Oversight] Serves objective 5.2: the risk register (key risk indicators, risk owners, risk threshold), risk tolerance, risk appetite, risk management strategies, risk reporting and business impact analysis (BIA). - Level 51: Third-Party Risk: Assessing and Monitoring Vendors
[5.0 Security Program Management and Oversight] Serves objective 5.3 (explain the processes associated with third-party risk assessment and management): vendor assessment, vendor selection, vendor monitoring, questionnaires and rules of engagement. - Level 52: Third-Party Agreement Types
[5.0 Security Program Management and Oversight] Serves objective 5.3: agreement types, namely service-level agreement (SLA), memorandum of agreement (MOA), memorandum of understanding (MOU), master service agreement (MSA), work order (WO)/statement of work (SOW), non-disclosure agreement (NDA) and business partners agreement (BPA). - Level 53: Compliance Reporting, Monitoring and Consequences
[5.0 Security Program Management and Oversight] Serves objective 5.4 (summarize elements of effective security compliance): compliance reporting, consequences of non-compliance and compliance monitoring. - Level 54: Privacy: Data Subjects, Roles and Retention
[5.0 Security Program Management and Oversight] Serves objective 5.4: privacy, covering legal implications (local/regional, national, global), data subject, controller vs. processor, ownership, data inventory and retention, and right to be forgotten. - Level 55: Audits, Assessments and Attestation
[5.0 Security Program Management and Oversight] Serves objective 5.5 (explain types and purposes of audits and assessments): attestation, internal audits and assessments (compliance, audit committee, self-assessments) and external ones (regulatory, examinations, assessment, independent third-party audit). - Level 56: Penetration Testing Types and Reconnaissance
[5.0 Security Program Management and Oversight] Serves objective 5.5: penetration testing that is physical, offensive, defensive or integrated, in a known environment, partially known environment or unknown environment, with passive and active reconnaissance. - Level 57: Security Awareness Practices
[5.0 Security Program Management and Oversight] Serves objective 5.6 (given a scenario, implement security awareness practices): phishing, anomalous behavior recognition, user guidance and training, reporting and monitoring, development and execution. - Level 58: Exam Craft: PBQ and Best-Answer Reasoning Workshop
[All five domains: 1.0 General Security Concepts, 2.0 Threats, Vulnerabilities, and Mitigations, 3.0 Security Architecture, 4.0 Security Operations, 5.0 Security Program Management and Oversight] An exam-craft workshop that practises the reasoning for performance-based questions and scenario "best answer" multiple choice using original practice items written for this course, which are not real exam questions, with no pass promised. - Level 59: Acronym Review: Cryptography, Keys and Certificates
[Acronym list: cryptography] Reviews the cryptography acronyms on CompTIA's SY0-701 acronym list that earlier levels did not spell out, so the learner recognises each one in a question. - Level 60: Acronym Review: Authentication and Secure Protocols
[Acronym list: authentication and protocols] Reviews the authentication, remote access and protocol acronyms on CompTIA's SY0-701 acronym list that earlier levels did not spell out, with which are legacy and which are current. - Level 61: Acronym Review: Networks and Infrastructure
[Acronym list: networks] Reviews the network and infrastructure acronyms on CompTIA's SY0-701 acronym list that earlier levels did not spell out, with the security point the exam attaches to each. - Level 62: Acronym Review: Hosts, Hardware and Software
[Acronym list: hosts and software] Reviews the host, hardware, device and software acronyms on CompTIA's SY0-701 acronym list that earlier levels did not spell out, with the security point the exam attaches to each. - Level 63: Acronym Review: Roles, Plans and Threat Intelligence
[Acronym list: roles, plans and threat intelligence] Reviews the role, planning, development and threat intelligence acronyms on CompTIA's SY0-701 acronym list that earlier levels did not spell out, and teaches user behavior analytics from objective 4.5. - Level 64: Timed Mock Exam: 90 Questions in 90 Minutes Timed mock
[All five domains, weighted 12% / 22% / 18% / 28% / 20%] The timed mock exam of 90 original practice questions in 90 minutes with an 83% pass mark, testing all SY0-701 objectives in proportion to the domain weightings; it is independent of CompTIA, does not contain real exam questions, and does not guarantee a pass.
Access
The first 2 levels are free with a free account. Every level, the podcast edition and the AI tutor come with All Access at £4.99/month or any Creator plan — see pricing.