Recently I passed the CompTIA Security+ SY0-701 Certification exam. Here is a rough organization of my study path so you guys can follow it too! This post is mainly an overview of the main concepts covered on the exam.
Overview of Main Concepts
- Intro to security Principles
- NIST Cybersecurity Framework 2.0
- CIA Triad
- Threat, Vulnerability, and Risk
- Non-Reputation
- Authentication, Authorization, and Accounting (AAA)
- Zero Trust Architecture
Official Exam Breakdown
- General security concepts (12%)
- Threats, vulnerabilities, and mitigations (22%)
- Security architecture (18%)
- Security operations (28%)
- Security program management and oversight (20%)
Click the links in the official exam breakdown to dive deeper into concepts, I have compiled topics I needed a refresher on while studying.
Performance Based Questions (PBQ)
Performance based questions can manifest as simulations in a preset environment or a simulation. I was not aware of PBQ’s before taking the exam, so I was a bit surprised when tasked with solving real world problems in simulations. However, studying the concepts seemed to prepare me well. Below are a few resources to prepare for PBQ.
Performance-Based Questions Overview| CompTIA IT Certifications
CompTIA Security+ Performance Based Questions for 2025
CompTIA Security+ SY0-701 PBQ Simulator

Leave a Reply