CompTIA Security+
Security+ is the certificate that appears in more entry-level security job adverts than any other, and it satisfies a great many procurement and government screening lists besides.
Ninety minutes, 750 to pass, and an announced retirement date for the English edition.
According to CompTIA, this exam version (SY0-701) can be booked until 11 June 2027.
Exam facts
- Exam code
- SY0-701
- Level
- Associate
- Field
- Cybersecurity
- Duration
- 90 minutes
- Questions
- maximum of 90 (multiple choice and performance-based items)
- Passing score
- 750 on a scale of 100 to 900
- Languages
- English, Japanese, Portuguese, Spanish, Thai
- Price
- 439 USD (read 8 September 2026)
- Validity
- 3 years, renewable
- Exam delivery
- Pearson VUE (test centre or online proctored)
- Last exam day of this version
- 11 June 2027
Prerequisites: No formal prerequisites. CompTIA recommends Network+ and two years in a security or systems administrator role.
Renewal: Continuing Education: 50 CEUs within three years, or pass the current Security+ exam
Source: exam page at CompTIA · Price: CompTIA list price since the June 2026 price round (partner price list, read 2026-09-08); CompTIA shows your local price in its purchase widget
How to prepare
1. A practice test in the exam format
MeasureUp sells a practice test for SY0-701 with questions in the exam format, an explanation for every answer and a timed mode; the price shows in your currency on the shop page. Affiliate link.
Practice test for SY0-701 at MeasureUp (opens in a new tab)Book the exam
Delivered by Pearson VUE (test centre or online proctored). Schedule with CompTIA (opens in a new tab)
Affiliate disclosure: the practice-test link above is affiliate links — buying through them may earn us a commission at no extra cost to you. The vendor's learning path and booking links carry no commission.
- Breadth over depth throughout. Cryptography, identity, network defence, governance, risk and incident response each get a share and none gets a deep one.
- Performance-based items alongside multiple choice, and they carry weight.
- Scenario framing rather than definitions: the stem describes an event and asks for your response.
- Governance and risk appear more than candidates expect, and technical people under-prepare that section reliably.
- Two years of experience is recommended, not required, and plenty of people pass without it.
Bought for the filter, kept for the vocabulary
Security+ appears in more entry-level security adverts than any other certificate and satisfies a long list of procurement and government screening requirements. That recognition is what you are paying for, and everybody involved knows it. What you keep afterwards is a shared vocabulary across the whole field, wide enough that a help-desk analyst and a compliance officer can read the same incident report and mean the same things by it. The syllabus is not deep anywhere, and that is a design choice rather than a flaw: it is the certificate that lets you find out which corner of security you want to go deep in.
Ninety minutes, up to 90 questions, one number to remember
| What | SY0-701 |
|---|---|
| Time | 90 minutes |
| Questions | Up to 90, multiple choice and performance-based |
| Pass mark | 750 on a scale of 100 to 900 |
| Languages | English, Japanese, Portuguese, Spanish, Thai |
| English edition retires | 11 June 2027 |
| Renewal | Three years, 50 continuing-education credits or a resit |
Ninety minutes for up to 90 questions sounds like a minute each, and the performance-based items break that arithmetic. A simulation can absorb five minutes on its own, so the sensible order is to answer the multiple-choice items at pace, flag anything uncertain, and give the simulations the time that is left rather than the time they demand on first encounter. The paper stops when the scoring engine decides: the question count is a ceiling, not a promise.
The ladder underneath and above
CompTIA recommends Network+ and two years in a security or systems administration role before this exam. The order matters more than the years. Candidates who stall on this syllabus are almost always missing the networking layer beneath it rather than the security content itself, because half the scenarios describe traffic, segmentation or a device that somebody reached when they should not have. Above it sits the analyst certificate for operations work and the penetration testing certificate for offensive work, and passing either renews this one. Holding this one, in turn, refreshes A+ and Network+ automatically, and that is the case for climbing rather than collecting.
The English edition retires on 11 June 2027
Other language editions follow later. That is a long runway rather than an emergency, and it matters in one specific way: preparation material written for the current version stays useful for a considerable time, and anything you buy close to the date should be checked against whichever version you will actually sit. A pass does not become invalid when the version changes.
What a question looks like
Written by us in the exam's style. It is not a real question from any question bank, and we do not publish those.
An organisation discovers that a departing employee retained access to a shared mailbox for three weeks after leaving. No data appears to have been taken. Beyond removing the access, what control most directly prevents a recurrence?
Every option is a real control and several would help. The question asks which one addresses the cause rather than the incident, and the cause is a process that failed rather than a technology that was missing. Candidates who read security as a technical subject choose a technical control; the exam wants the joining-and-leaving process.
What it costs to get and to keep
| Item | Amount | Note |
|---|---|---|
| Exam fee | 439 USD | partner price list after CompTIA's June 2026 price round; CompTIA shows the figure only inside its purchase widget, by country (read 8 September 2026) |
| Renewal every three years | not published | 50 continuing-education credits, or passing the current Security+ exam again. A higher CompTIA certificate renews it automatically (read 12 September 2026) |
| What it renews for you | not published | holding this refreshes A+ and Network+ beneath it, which is the practical argument for climbing rather than collecting at the same level (read 12 September 2026) |
How much preparation, from where you are
- You administer systems and have handled an incident
- The technical material will be familiar. The work is governance, risk and the formal vocabulary for things you already do informally, which is the section experienced people skip and lose marks on.
- You hold Network+ and are moving toward security
- The intended path, and the shortest one. Much of the network defence material builds directly on what you already did, and the new ground is cryptography and process.
- You are changing career into security
- Do the networking first, whatever the order of the certificates suggests. Candidates who stall in this syllabus are almost always missing the layer underneath rather than the security content itself.
What passing this does not prove
- Whether you could run an investigation, which is the analyst exam's territory.
- Any specific toolchain, which is why it travels and why it feels abstract.
- Whether you would notice the incident in the first place.
- The organisational politics of saying no, which is most of a security job.
Against the alternatives
- SC-900 — Microsoft Certified: Security, Compliance, and Identity Fundamentals
- Microsoft's security fundamentals paper is cheaper, shorter and considerably thinner. Take that one to name products, this one to be taken seriously as an entry candidate.
- CS0-004 — CompTIA CySA+
- The analyst certificate above this, and the natural next step for anyone heading into a security operations seat rather than a generalist one.
- CISSP — Certified Information Systems Security Professional (CISSP)
- Not an alternative. The other is a management qualification gated on documented experience, while this is the way in. Years apart in what they claim about a candidate.
SY0-701 — quick answers
Is it worth the fee?
For entry into security, yes, with less argument than almost any other credential covered here. It is named by hiring filters and by screening lists in ways that no competing entry certificate matches, and that recognition is what you are buying. The knowledge is broad rather than deep, and everybody involved knows it.
Should I wait for the next version?
No. The English edition runs until June 2027, your pass survives the changeover, and studying against a published syllabus beats waiting for an unpublished one. Only check the version if you are booking close to the date.
Do I need two years of experience?
It is recommended and not required, and many people pass without it. What experience actually buys is recognising the scenarios, because the questions describe situations rather than defining terms. Without it, budget more time and use a lab.
What does it renew?
Holding it refreshes A+ and Network+ automatically inside CompTIA's system. That is worth planning around: climbing the ladder keeps everything beneath current, whereas collecting certificates at the same level means feeding several renewal cycles at once.
How do I manage the clock with the simulations?
Answer the multiple-choice items first at a steady pace and flag the ones you are unsure of, then return to the performance-based items with whatever remains. A simulation met cold at the start of the paper can eat a tenth of your time on its own, and the multiple-choice marks it displaces are easier to collect.
What comes next
- CompTIA · N10-009CompTIA Network+
- CompTIA · CS0-004CompTIA CySA+
- CompTIA · PT0-003CompTIA PenTest+
- Microsoft · SC-900Microsoft Certified: Security, Compliance, and Identity Fundamentals
- CompTIA · 220-1201 + 220-1202CompTIA A+
- CompTIA · XK0-006CompTIA Linux+
- ISC2 · CISSPCertified Information Systems Security Professional (CISSP)
- ISACA · CISACertified Information Systems Auditor (CISA)
- EC-Council · 312-50Certified Ethical Hacker (CEH)
Concepts this exam draws on
Glossary entries with the reason each one matters for SY0-701.
- SSL/TLS
Cryptography and PKI: certificates, ciphers and where TLS fails.
- Encryption
Cryptographic concepts and their use are a general-security-concepts objective.
- Hashing
Hashing, salting and password storage appear in the same objective group.
- PKI
Certificates and PKI are examined at the entry level.
- Authentication
Authentication factors and their weaknesses.
- MFA
Named, ranked and recommended throughout the identity objectives.
- Firewall
Firewall types and placement in the architecture domain.
- VPN
Secure remote access in the architecture domain.
- Phishing
The threats domain starts with social engineering.
- Ransomware
Malware types and the attack chain behind an extortion incident.
- Zero Trust
The architecture domain now names the model explicitly.
- Incident Response
Incident response process is a security-operations objective.
- Security Risk Assessment
Risk management vocabulary in the governance domain.
Last reviewed 12 September 2026 · Getting Digital
