Security Plus Training Course

Training course

This is a free, self-paced reading course for CompTIA Security+ (SY0-701), the most widely held entry point into a cybersecurity career, and the credential that tells an employer you can assess a security posture, recommend and implement controls, monitor hybrid cloud and on-premises environments, and work inside the laws and policies that govern the field. It also satisfies U.S. DoD 8140 requirements for a long list of defense work roles. Read it straight through, in order, before you start drilling practice questions, so that a missed item becomes a gap you can name rather than a definition you half-recognize.

The course is organized as one module per official exam domain, in the order CompTIA publishes them, and each module carries the domain’s published weight. Security+ is lopsided in a way that catches people out, and following the weighting fixes it. Security Operations alone is 28% of the exam, and Security Program Management and Oversight is another 20%, governance material that technical candidates tend to skim and then lose easy points on. General Security Concepts is only 12%, but its vocabulary turns up inside questions in every other domain, which is why it comes first here.

SY0-701 Foundational level 5 modules Domain-weighted Self-paced Free account

What the course covers

General Security Concepts

Module 1 · 12%

The vocabulary and mental models everything else builds on: categories of security controls, the CIA triad and non-repudiation, Zero Trust principles, the role change management plays in security, and foundational cryptography from key management through hashing. Small in weight, large in reach, these ideas reappear inside questions across every other domain.

Threats, Vulnerabilities, and Mitigations

Module 2 · 22%

Know your adversary. Threat actors and their motivations; attack techniques from phishing and business email compromise through injection attacks, malware families, and password attacks; the common vulnerability classes; and how to choose the mitigation that actually addresses the scenario in front of you rather than the one that sounds strongest.

Security Architecture

Module 3 · 18%

Building environments that are defensible by design: comparing cloud, hybrid, virtualized, and industrial-control architectures; network design elements including segmentation, screened subnets, and secure remote access; protecting data across its states and jurisdictions; and the resilience patterns (clustering, backups, recovery sites) that keep a business running through failure.

Security Operations

Module 4 · 28%

The largest domain, and the day job: hardening and baselining systems, securing wireless and mobile fleets, vulnerability management and alerting, identity and access management from SSO through just-in-time privilege, automation, and the incident response lifecycle including forensics fundamentals. Expect scenario questions that read like tickets from a real SOC queue.

Security Program Management and Oversight

Module 5 · 20%

The governance layer: policies and standards, risk management from registers through quantitative analysis, third-party and vendor risk, compliance and privacy obligations, audits and penetration-test concepts, and building a security-awareness program. This is where technical practitioners most often lose points they could have banked.

How to use it

Read a module, then test that domain immediately rather than waiting until you have covered everything. The free Security+ sample questions are the quickest way to check whether a module landed, and the full-length blueprint-weighted mock sits on the SY0-701 certification guide alongside the exam logistics, question count, timing, and the 750 / 900 scaled cut score. Reading the course itself requires a free Certifym account.

Be honest about module 5. Governance reads like the least interesting fifth of the syllabus and is the one candidates postpone, but at 20% it is worth more than Security Architecture and nearly twice General Security Concepts, and it is the easiest domain to score well in because the answers are definitional rather than situational. Read it early rather than last. Elsewhere, work scenarios rather than definitions: SY0-701 mixes performance-based questions that drop you into a simulated task with multiple-choice items that describe an incident and ask what you do next, and neither rewards recall on its own.

CompTIA Security+ (SY0-701) Training

Module 1: General Security Concepts 12% of exam

The foundational vocabulary the exam builds on: control categories and types, the CIA triad, non-repudiation and AAA, Zero Trust, physical security, and change management.

  • 1.1 What Security+ Is 4 min Free preview
  • 1.2 Security Control Categories and Types 4 min πŸ”’
  • 1.3 CIA Triad, Non-repudiation, and AAA 4 min πŸ”’
  • 1.4 Zero Trust 4 min πŸ”’
  • 1.5 Physical Security Controls 4 min πŸ”’
  • 1.6 Change Management in Security Context 4 min πŸ”’

Module 2: Threats, Vulnerabilities, and Mitigations 22% of exam

The threats the exam expects you to recognize by name, the vulnerabilities they exploit at each layer of the stack, and the mitigation techniques applied across scenarios.

  • 2.1 Threat Actors and Motivations 4 min πŸ”’
  • 2.2 Threat Vectors and Attack Surfaces 4 min πŸ”’
  • 2.3 Application Vulnerabilities 4 min πŸ”’
  • 2.4 OS, Firmware, and Hardware Vulnerabilities 4 min πŸ”’
  • 2.5 Web-Based and API Vulnerabilities 4 min πŸ”’
  • 2.6 Malware Attacks 4 min πŸ”’
  • 2.7 Network Attacks 4 min πŸ”’
  • 2.8 Password Attacks and Application Attacks 4 min πŸ”’
  • 2.9 Cryptographic and Supply Chain Vulnerabilities 4 min πŸ”’
  • 2.10 Indicators of Compromise 4 min πŸ”’
  • 2.11 Mitigation Techniques 4 min πŸ”’

Module 3: Security Architecture 18% of exam

The architectural building blocks: deployment models, network infrastructure, enterprise security appliances, data protection, resilience, and applied cryptography including PKI, TLS, IPsec, and SSH.

  • 3.1 Architecture Models 4 min πŸ”’
  • 3.2 Network Infrastructure Concepts 4 min πŸ”’
  • 3.3 Enterprise Infrastructure Security 4 min πŸ”’
  • 3.4 Data Protection 4 min πŸ”’
  • 3.5 Resilience and Recovery in Architecture 4 min πŸ”’
  • 3.6 Cryptographic Solutions 4 min πŸ”’
  • 3.7 Public Key Infrastructure (PKI) 4 min πŸ”’
  • 3.8 Encryption Applications: TLS, IPsec, SSH 4 min πŸ”’
  • 3.9 Certificate Management 4 min πŸ”’

Module 4: Security Operations 28% of exam

The largest domain: hardening, asset management, vulnerability management, security monitoring, IAM, automation, incident response, forensics, application security, email and endpoint protection, backup and recovery, and awareness.

  • 4.1 Secure Baselines and Hardening 4 min πŸ”’
  • 4.2 Hardware, Software, and Data Asset Management 4 min πŸ”’
  • 4.3 Vulnerability Management 4 min πŸ”’
  • 4.4 Security Monitoring 4 min πŸ”’
  • 4.5 Firewall Configuration and Network Access 4 min πŸ”’
  • 4.6 Identification, Authentication, and Authorization 4 min πŸ”’
  • 4.7 IAM Implementation 4 min πŸ”’
  • 4.8 Automation and Orchestration 4 min πŸ”’
  • 4.9 Incident Response 4 min πŸ”’
  • 4.10 Digital Forensics and Data Sources 4 min πŸ”’
  • 4.11 Application Security in Operations 4 min πŸ”’
  • 4.12 Email Security and Endpoint Protection 4 min πŸ”’
  • 4.13 Backup and Recovery Operations 4 min πŸ”’
  • 4.14 Awareness and Training Programs 4 min πŸ”’

Module 5: Security Program Management and Oversight 20% of exam

The program-management side of security: governance, policies and procedures, roles and responsibilities, risk management, third-party risk, compliance, audits, privacy, and awareness at program scale.

  • 5.1 Security Governance 4 min πŸ”’
  • 5.2 Policies, Standards, and Procedures 4 min πŸ”’
  • 5.3 Roles and Responsibilities 4 min πŸ”’
  • 5.4 Risk Management Concepts 4 min πŸ”’
  • 5.5 Risk Assessment and Analysis 4 min πŸ”’
  • 5.6 Third-Party Risk Management 4 min πŸ”’
  • 5.7 Compliance and Regulations 4 min πŸ”’
  • 5.8 Audits and Assessments 4 min πŸ”’
  • 5.9 Data Privacy 4 min πŸ”’
  • 5.10 Awareness, Training, and Reporting 4 min πŸ”’

Frequently asked questions about the Security+ training course

Is the Security+ training course free?

Yes. The course costs nothing to read; it is behind a free Certifym account, with no payment and no card. It is funded by the same practice-exam catalog it sits alongside.

How is the course structured?

One module per official SY0-701 exam domain, in CompTIA’s published order, with each module weighted to the domain’s published percentage: 12%, 22%, 18%, 28%, and 20%. Within each module the material is broken into short lessons, followed by key terms and further reading.

Does this replace CompTIA’s official training?

No. CompTIA publishes the authoritative SY0-701 exam objectives along with its own CertMaster courseware, and those are the reference of record. This course is an independent study companion, written to be read quickly and to slot alongside practice questions.

Do I need Network+ before starting?

There is no enforced prerequisite, but Security+ quietly assumes networking fluency, the Security Architecture module in particular expects you to already understand segmentation, subnets, and remote access. Network+ is the usual step before it. If your networking is shaky, work through the Network+ course first rather than trying to learn both at once.

What should I do after finishing the course?

Move to blueprint-weighted practice questions and keep going until you are clearing the bar consistently across all five domains rather than riding a strong Security Operations score. After the exam, CySA+ is the analyst-level credential further along the same path.

Is the course current, and what about SY0-801?

The course is built against SY0-701, released by CompTIA in November 2023 and still the current exam. CompTIA refreshes Security+ on a roughly three-year cycle, and a successor, SY0-801, is expected to begin rolling out in late 2026, with SY0-701 remaining available for a transition period after that. Check CompTIA’s official Security+ page for retirement dates before you schedule.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by CompTIA, Inc. CompTIA® and Security+® are registered trademarks of CompTIA, Inc. Use of these marks is solely to identify the certification for which these study materials are intended. The SY0-701 exam objectives, including the domain titles and weightings referenced above, are the property of CompTIA, Inc.; candidates should download the complete, official objectives directly from CompTIA at comptia.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual CompTIA training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and renewal policies are set by CompTIA and may change; always verify current details on the CompTIA site before scheduling your exam.