CompTIA Security+ exam objectives
The published blueprint is the contract: the exam can only test what is on this list. Domains carry their official weightings, and objectives with a practice page link straight to questions written for that objective.
Titles and weightings from the official objectives. CompTIA exam page ↗
General Security Concepts
12% of exam1.1 1.1 Compare and contrast various types of security controls
- 1.2 1.2 Summarize fundamental security conceptsPractice
- 1.3 1.3 Explain the importance of change management processes and the impact to securityPractice
- 1.4 1.4 Explain the importance of using appropriate cryptographic solutionsPractice
Threats, Vulnerabilities, and Mitigations
22% of exam- 2.1 2.1 Compare and contrast common threat actors and motivationsPractice
- 2.2 2.2 Explain common threat vectors and attack surfacesPractice
- 2.3 2.3 Explain various types of vulnerabilitiesPractice
- 2.4 2.4 Given a scenario, analyze indicators of malicious activityPractice
- 2.5 2.5 Explain the purpose of mitigation techniques used to secure the enterprisePractice
Security Architecture
18% of exam- 3.1 3.1 Compare and contrast security implications of different architecture modelsPractice
- 3.2 3.2 Given a scenario, apply security principles to secure enterprise infrastructurePractice
- 3.3 3.3 Compare and contrast concepts and strategies to protect dataPractice
- 3.4 3.4 Explain the importance of resilience and recovery in security architecturePractice
Security Operations
28% of exam- 4.1 4.1 Given a scenario, apply common security techniques to computing resourcesPractice
- 4.2 4.2 Explain the security implications of proper hardware, software, and data asset managementPractice
- 4.3 4.3 Explain various activities associated with vulnerability managementPractice
4.4 4.4 Explain security alerting and monitoring concepts and tools
4.5 4.5 Given a scenario, modify enterprise capabilities to enhance security
- 4.6 4.6 Given a scenario, implement and maintain identity and access managementPractice
- 4.7 4.7 Explain the importance of automation and orchestration related to secure operationsPractice
- 4.8 4.8 Explain appropriate incident response activitiesPractice
- 4.9 4.9 Given a scenario, use data sources to support an investigationPractice
Security Program Management and Oversight
20% of exam- 5.1 5.1 Summarize elements of effective security governancePractice
- 5.2 5.2 Explain elements of the risk management processPractice
- 5.3 5.3 Explain the processes associated with third-party risk assessment and managementPractice
- 5.4 5.4 Summarize elements of effective security compliancePractice
- 5.5 5.5 Explain types and purposes of audits and assessmentsPractice
- 5.6 5.6 Given a scenario, implement security awareness practicesPractice
Objectives marked Practice open a page of original questions written for that objective, each with a full explanation cited to CompTIA documentation.
Keep reading
Security+ practice questions
Free sample questions with the full explanation on every answer.
Free Security+ practice test
Ten real questions, playable now. No account, no card.
Security+ passing score
The exact cut score, what kind of number it is, and the retake terms.
How hard is Security+?
An honest difficulty read from the format, the clock and the weights.
What Security+ costs
The voucher price, the retake, and what renewal costs across the cycle.
Security+ guide
Who it is for, study plans by experience level, and whether it is worth it.
Common Ports & Protocols
A printable reference table, free.
Security+ vs CISSP
Side by side on cost, difficulty, and which one to take first.