Training course
This is a free, self-paced reading course for CompTIA Security+ (SY0-701), the most widely held entry point into a cybersecurity career, and the credential that tells an employer you can assess a security posture, recommend and implement controls, monitor hybrid cloud and on-premises environments, and work inside the laws and policies that govern the field. It also satisfies U.S. DoD 8140 requirements for a long list of defense work roles. Read it straight through, in order, before you start drilling practice questions, so that a missed item becomes a gap you can name rather than a definition you half-recognize.
The course is organized as one module per official exam domain, in the order CompTIA publishes them, and each module carries the domain’s published weight. Security+ is lopsided in a way that catches people out, and following the weighting fixes it. Security Operations alone is 28% of the exam, and Security Program Management and Oversight is another 20%, governance material that technical candidates tend to skim and then lose easy points on. General Security Concepts is only 12%, but its vocabulary turns up inside questions in every other domain, which is why it comes first here.
What the course covers
General Security Concepts
Module 1 · 12%The vocabulary and mental models everything else builds on: categories of security controls, the CIA triad and non-repudiation, Zero Trust principles, the role change management plays in security, and foundational cryptography from key management through hashing. Small in weight, large in reach, these ideas reappear inside questions across every other domain.
Threats, Vulnerabilities, and Mitigations
Module 2 · 22%Know your adversary. Threat actors and their motivations; attack techniques from phishing and business email compromise through injection attacks, malware families, and password attacks; the common vulnerability classes; and how to choose the mitigation that actually addresses the scenario in front of you rather than the one that sounds strongest.
Security Architecture
Module 3 · 18%Building environments that are defensible by design: comparing cloud, hybrid, virtualized, and industrial-control architectures; network design elements including segmentation, screened subnets, and secure remote access; protecting data across its states and jurisdictions; and the resilience patterns (clustering, backups, recovery sites) that keep a business running through failure.
Security Operations
Module 4 · 28%The largest domain, and the day job: hardening and baselining systems, securing wireless and mobile fleets, vulnerability management and alerting, identity and access management from SSO through just-in-time privilege, automation, and the incident response lifecycle including forensics fundamentals. Expect scenario questions that read like tickets from a real SOC queue.
Security Program Management and Oversight
Module 5 · 20%The governance layer: policies and standards, risk management from registers through quantitative analysis, third-party and vendor risk, compliance and privacy obligations, audits and penetration-test concepts, and building a security-awareness program. This is where technical practitioners most often lose points they could have banked.
How to use it
Read a module, then test that domain immediately rather than waiting until you have covered everything. The free Security+ sample questions are the quickest way to check whether a module landed, and the full-length blueprint-weighted mock sits on the SY0-701 certification guide alongside the exam logistics, question count, timing, and the 750 / 900 scaled cut score. Reading the course itself requires a free Certifym account.
Be honest about module 5. Governance reads like the least interesting fifth of the syllabus and is the one candidates postpone, but at 20% it is worth more than Security Architecture and nearly twice General Security Concepts, and it is the easiest domain to score well in because the answers are definitional rather than situational. Read it early rather than last. Elsewhere, work scenarios rather than definitions: SY0-701 mixes performance-based questions that drop you into a simulated task with multiple-choice items that describe an incident and ask what you do next, and neither rewards recall on its own.
CompTIA Security+ (SY0-701) Training
Module 1: General Security Concepts 12% of exam
The foundational vocabulary the exam builds on: control categories and types, the CIA triad, non-repudiation and AAA, Zero Trust, physical security, and change management.
- 1.1 What Security+ Is 4 min Free preview
- 1.2 Security Control Categories and Types 4 min π
- 1.3 CIA Triad, Non-repudiation, and AAA 4 min π
- 1.4 Zero Trust 4 min π
- 1.5 Physical Security Controls 4 min π
- 1.6 Change Management in Security Context 4 min π
Module 2: Threats, Vulnerabilities, and Mitigations 22% of exam
The threats the exam expects you to recognize by name, the vulnerabilities they exploit at each layer of the stack, and the mitigation techniques applied across scenarios.
- 2.1 Threat Actors and Motivations 4 min π
- 2.2 Threat Vectors and Attack Surfaces 4 min π
- 2.3 Application Vulnerabilities 4 min π
- 2.4 OS, Firmware, and Hardware Vulnerabilities 4 min π
- 2.5 Web-Based and API Vulnerabilities 4 min π
- 2.6 Malware Attacks 4 min π
- 2.7 Network Attacks 4 min π
- 2.8 Password Attacks and Application Attacks 4 min π
- 2.9 Cryptographic and Supply Chain Vulnerabilities 4 min π
- 2.10 Indicators of Compromise 4 min π
- 2.11 Mitigation Techniques 4 min π
Module 3: Security Architecture 18% of exam
The architectural building blocks: deployment models, network infrastructure, enterprise security appliances, data protection, resilience, and applied cryptography including PKI, TLS, IPsec, and SSH.
- 3.1 Architecture Models 4 min π
- 3.2 Network Infrastructure Concepts 4 min π
- 3.3 Enterprise Infrastructure Security 4 min π
- 3.4 Data Protection 4 min π
- 3.5 Resilience and Recovery in Architecture 4 min π
- 3.6 Cryptographic Solutions 4 min π
- 3.7 Public Key Infrastructure (PKI) 4 min π
- 3.8 Encryption Applications: TLS, IPsec, SSH 4 min π
- 3.9 Certificate Management 4 min π
Module 4: Security Operations 28% of exam
The largest domain: hardening, asset management, vulnerability management, security monitoring, IAM, automation, incident response, forensics, application security, email and endpoint protection, backup and recovery, and awareness.
- 4.1 Secure Baselines and Hardening 4 min π
- 4.2 Hardware, Software, and Data Asset Management 4 min π
- 4.3 Vulnerability Management 4 min π
- 4.4 Security Monitoring 4 min π
- 4.5 Firewall Configuration and Network Access 4 min π
- 4.6 Identification, Authentication, and Authorization 4 min π
- 4.7 IAM Implementation 4 min π
- 4.8 Automation and Orchestration 4 min π
- 4.9 Incident Response 4 min π
- 4.10 Digital Forensics and Data Sources 4 min π
- 4.11 Application Security in Operations 4 min π
- 4.12 Email Security and Endpoint Protection 4 min π
- 4.13 Backup and Recovery Operations 4 min π
- 4.14 Awareness and Training Programs 4 min π
Module 5: Security Program Management and Oversight 20% of exam
The program-management side of security: governance, policies and procedures, roles and responsibilities, risk management, third-party risk, compliance, audits, privacy, and awareness at program scale.
- 5.1 Security Governance 4 min π
- 5.2 Policies, Standards, and Procedures 4 min π
- 5.3 Roles and Responsibilities 4 min π
- 5.4 Risk Management Concepts 4 min π
- 5.5 Risk Assessment and Analysis 4 min π
- 5.6 Third-Party Risk Management 4 min π
- 5.7 Compliance and Regulations 4 min π
- 5.8 Audits and Assessments 4 min π
- 5.9 Data Privacy 4 min π
- 5.10 Awareness, Training, and Reporting 4 min π
Frequently asked questions about the Security+ training course
Is the Security+ training course free?
Yes. The course costs nothing to read; it is behind a free Certifym account, with no payment and no card. It is funded by the same practice-exam catalog it sits alongside.
How is the course structured?
One module per official SY0-701 exam domain, in CompTIA’s published order, with each module weighted to the domain’s published percentage: 12%, 22%, 18%, 28%, and 20%. Within each module the material is broken into short lessons, followed by key terms and further reading.
Does this replace CompTIA’s official training?
No. CompTIA publishes the authoritative SY0-701 exam objectives along with its own CertMaster courseware, and those are the reference of record. This course is an independent study companion, written to be read quickly and to slot alongside practice questions.
Do I need Network+ before starting?
There is no enforced prerequisite, but Security+ quietly assumes networking fluency, the Security Architecture module in particular expects you to already understand segmentation, subnets, and remote access. Network+ is the usual step before it. If your networking is shaky, work through the Network+ course first rather than trying to learn both at once.
What should I do after finishing the course?
Move to blueprint-weighted practice questions and keep going until you are clearing the bar consistently across all five domains rather than riding a strong Security Operations score. After the exam, CySA+ is the analyst-level credential further along the same path.
Is the course current, and what about SY0-801?
The course is built against SY0-701, released by CompTIA in November 2023 and still the current exam. CompTIA refreshes Security+ on a roughly three-year cycle, and a successor, SY0-801, is expected to begin rolling out in late 2026, with SY0-701 remaining available for a transition period after that. Check CompTIA’s official Security+ page for retirement dates before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by CompTIA, Inc. CompTIA® and Security+® are registered trademarks of CompTIA, Inc. Use of these marks is solely to identify the certification for which these study materials are intended. The SY0-701 exam objectives, including the domain titles and weightings referenced above, are the property of CompTIA, Inc.; candidates should download the complete, official objectives directly from CompTIA at comptia.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual CompTIA training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and renewal policies are set by CompTIA and may change; always verify current details on the CompTIA site before scheduling your exam.
