PrepForCerts

Published by PrepForCerts · Editorial responsibility and sources

CompTIA Security+ Exam Objectives & Domains (2026)

Quick Answer

The current Security+ exam is organized into five domains covering general security concepts, threats, vulnerabilities and mitigations, security architecture, security operations, and security program management and oversight. Operations and threats carry the most scored questions. Every "given a scenario" bullet will appear as an applied question, and performance-based questions draw from the technical domains. Download the current objectives PDF from CompTIA and use it as your checklist.

Domains
5
Question Format
Multiple Choice + PBQ
Heaviest Domains
Operations & Threats
Typical Study Time
2-4 Months
On this page

Security+ is the certification where reading the objectives carefully has the highest payoff, because the exam is deliberately written to test judgment rather than recall. The blueprint tells you this openly: high-weight bullets are phrased as "given a scenario, implement" or "given a scenario, analyze," which means you will be asked what you would do, not what something is called. This guide walks through all five Security+ domains in 2026, unpacks what each is actually assessing, explains how the weighting should shape your schedule, and shows how to work the objectives list into a system that surfaces gaps before the exam does. Pair it with the official objectives PDF, which is free and published by CompTIA.

The Five Security+ Domains

The domains progress from vocabulary to threats to design to daily operations to governance. That is roughly the order a real security practitioner encounters them, and it is a sensible study order too.

General Security Concepts

The vocabulary and control taxonomy layer: security control categories and types, fundamental concepts including the CIA triad, non-repudiation, authentication, authorization and accounting, zero trust, physical security, deception technologies, change management processes and their security implications, and cryptographic fundamentals such as public key infrastructure, encryption levels, key exchange, digital signatures, certificates, hashing and salting. Cryptography here is conceptual — you need to know which primitive solves which problem, not the mathematics.

Threats, Vulnerabilities and Mitigations

Threat actors and their motivations, attack surfaces and threat vectors, vulnerability types across applications, operating systems, hardware, cloud, supply chain and cryptographic implementations, indicators of malicious activity, and the mitigation techniques used to secure an enterprise. This domain generates a large share of scenario questions: you are shown symptoms and asked to identify the attack, or shown an attack and asked for the appropriate mitigation. Learn the indicators, not just the attack names.

Security Architecture

Designing for security: architecture models including cloud, infrastructure as code, serverless, microservices, network segmentation and virtualization, secure infrastructure principles such as device placement, failure modes, and control selection, data protection concepts covering classification, states, sovereignty and methods including encryption, masking and tokenization, and resilience and recovery design including high availability, redundancy, testing and backup strategies. Expect to choose the right control for a described environment.

Security Operations

Typically the heaviest domain. Applying security techniques to computing resources, hardening targets, wireless and mobile security, asset management, vulnerability management from identification through remediation and validation, security alerting and monitoring, modifying enterprise capabilities such as firewalls, IDS/IPS, web filtering and DLP, identity and access management including provisioning, permissions, multifactor authentication and privileged access, automation and scripting for security operations, incident response processes and digital forensics fundamentals, and using data sources for investigation. This is where most performance-based questions live.

Security Program Management and Oversight

The governance layer: security governance elements including policies, standards, procedures and guidelines, risk management processes covering identification, assessment, analysis, register, appetite and treatment, third-party risk and vendor assessment, compliance and reporting obligations, audits and assessments including penetration testing types, and security awareness practices. Non-technical candidates often find this domain the easiest points on the exam; deeply technical candidates often underestimate it and lose points there.

Weighting: Where Your Hours Should Actually Go

The objectives PDF lists a percentage for each domain, and on Security+ the distribution is meaningfully uneven. Security operations carries the largest share, threats and vulnerabilities is next, and the remaining three split the rest with general concepts typically the smallest.

The practical implication is that operations deserves the most study time and the most practice questions — and conveniently, it is also where performance-based questions concentrate, so time invested there pays twice.

But there is a subtlety unique to Security+. The general security concepts domain is small by weight yet functions as the vocabulary layer for every other domain. A candidate who is shaky on control categories or cryptographic primitives will misread questions in operations and architecture, because the answer options use that vocabulary. So concepts should be studied first and thoroughly even though it will not, by itself, generate many questions.

The governance domain is the inverse. It is largely self-contained and can be studied late without penalty, and it rewards focused reading rather than practice repetition.

Performance-Based Questions and the Objectives

Performance-based questions appear at the start of the Security+ exam and draw from the technical domains — most often operations, architecture, and threats. They ask you to do something: analyze log output and identify the attack, configure a firewall rule set, match indicators to attack types, or place controls in a network diagram.

You can predict which objectives will produce them. Any bullet phrased as "given a scenario, implement" or "given a scenario, analyze" that involves a tool, a configuration, or an artifact is a plausible PBQ source. Log analysis, firewall and access control configuration, and attack-indicator matching are perennial.

Preparing for them requires a different activity than multiple choice. Read real log samples until the shapes of common attacks are familiar — repeated failed authentications, unusual outbound volume, requests with encoded payloads. Practise reading a rule set top to bottom and predicting what traffic it permits. None of that emerges from flashcards.

One tactical note for exam day: PBQs are time expensive. Many successful candidates flag them, complete the multiple-choice section first, then return with the remaining time budgeted. Getting stuck on the first PBQ and losing twenty minutes is a common and entirely avoidable way to fail.

Turning the Objectives Into a Working Study System

Download the current objectives PDF from CompTIA and confirm it matches the exam version you are booked for. Copy every sub-bullet into a tracker with a confidence rating. There are a lot of bullets — that is the point. Seeing the full scope early prevents the mid-study realization that three domains are untouched.

Study in domain order: concepts, threats, architecture, operations, governance. After each domain, run practice questions restricted to that domain and map every miss back to the specific bullet. Do not move on while a domain is producing repeated misses in the same area — that is an uncovered bullet, not bad luck.

Once all five domains are covered, switch entirely to mixed full-length timed practice. The purpose changes at this stage: you are no longer learning content, you are training question interpretation and time management. Aim for consistent scores in the mid-eighties across at least two independent question sources before booking, since a single source can flatter you through familiarity.

In the final week, do a full read of the objectives list and write a one-sentence explanation for every bullet you hesitate on. That list, and only that list, is your last-week study plan.

Expert Insight

Security+ is scored to reward the candidate who thinks like a defender with a budget. When a question offers a technically perfect control and a proportionate one, the proportionate answer is usually keyed — because the objectives repeatedly frame control selection as a risk decision rather than a maximum-security decision. Candidates who internalize that framing gain several points across the exam without learning any new content.

Study Tips

Common Mistakes

Frequently Asked Questions

How many domains are on the Security+ exam?

Five: general security concepts, threats vulnerabilities and mitigations, security architecture, security operations, and security program management and oversight. Exact weightings are published in the current objectives PDF.

Which Security+ domain is weighted the heaviest?

Security operations typically carries the largest share of scored questions, with threats, vulnerabilities and mitigations next. Those two together account for a substantial portion of the exam and deserve the most practice time.

Do I need to know cryptography math for Security+?

No. Security+ tests cryptography conceptually — which primitive solves which problem, how certificates and key exchange work at a high level, and where hashing and salting apply. You will not be asked to perform calculations.

Which objectives produce performance-based questions?

PBQs draw mainly from the technical domains: log analysis and incident response in operations, control placement in architecture, and attack-indicator matching in threats. Any "given a scenario, implement or analyze" bullet involving a tool or artifact is a candidate.

How often do the Security+ objectives change?

CompTIA revises Security+ periodically, updating the domain structure and content to reflect current practice. Always download the objectives matching the exam version your voucher applies to.

Can I skip the governance domain if I am technical?

No, and it would be an expensive shortcut. Governance, risk and compliance content is straightforward reading with a meaningful share of scored questions — it is among the highest points-per-hour material on the exam.

How long does it take to cover all the objectives?

Two to four months is typical for candidates with some IT background studying consistently. Coverage is not the bar though — you should be able to explain every bullet without notes and score consistently in the mid-eighties on mixed practice before booking.

Drill every Security+ domain free

Adaptive Security+ questions with instant explanations, weak-domain tracking, and scenario practice built around the official objectives.

Start Free Security+ Practice

Ready to Start Your Certification Journey?

Practice with real exam-style questions and track your progress.

Start Free Security+ Practice