Cyber Questline

SY0-701 Available

CompTIA Security+ quest path

Security concepts, identity, architecture, operations, threats, and incident response practice.

275Original questions
85%Practice target
90%Comfort target
SY0-701Exam objectives

Knowledge map

Practice by objective

Search this track

Reviewed 2026-09-08. Topic labels summarize the linked study material; objective numbers identify the exam scope.

1.0 General Security Concepts4 objectives33 questions
Objective 1.1

Control Function And Zero Trust Decisions; Risk Management

Practice 5 items
Objective 1.2

Risk Management; Control Function And Zero Trust Decisions; Identity and Account Management; Securing The Basic LAN

Practice 9 items
Objective 1.3

Securing Individual Systems; Business Security Impact; Cryptographic Lifecycle And Change Evidence

Practice 4 items
Objective 1.4

Foundations of Cryptography; Cryptographic Lifecycle And Change Evidence; Data Stewardship And Sanitization; Secure Protocols and Applications

Practice 15 items
2.0 Threats, Vulnerabilities, and Mitigations5 objectives60 questions
Objective 2.1

Risk Management

Practice 4 items
Objective 2.2

Securing Individual Systems; Securing Dedicated and Mobile Systems; Secure Protocols and Applications; Application And Email Validation; Testing Infrastructure; Threat Evidence And Bounded Conclusions

Practice 8 items
Objective 2.3

Cryptographic Lifecycle And Change Evidence; Foundations of Cryptography; Threat Evidence And Bounded Conclusions; Securing Virtual and Cloud Environments; Securing Dedicated and Mobile Systems; Application And Email Validation

Practice 16 items
Objective 2.4

Physical Security; Phishing Resistant Authentication And Recovery; Threat Evidence And Bounded Conclusions; Securing Individual Systems; Securing The Basic LAN; Securing Wireless LANs; Securing Virtual and Cloud Environments; Secure Protocols and Applications

Practice 25 items
Objective 2.5

Physical Security; Phishing Resistant Authentication And Recovery; Tools of the Trade; Protocol And Port Awareness; Containment And Control Tradeoffs

Practice 7 items
3.0 Security Architecture4 objectives50 questions
Objective 3.1

Securing The Basic LAN; Securing Virtual and Cloud Environments; Architecture Failure Domains And Data Protection

Practice 9 items
Objective 3.2

Physical Security; Securing The Basic LAN; Containment And Control Tradeoffs; Securing Wireless LANs; Secure Protocols and Applications; Architecture Failure Domains And Data Protection

Practice 23 items
Objective 3.3

Data Stewardship And Sanitization; Tools of the Trade; Securing Individual Systems; Securing Dedicated and Mobile Systems; Architecture Failure Domains And Data Protection

Practice 7 items
Objective 3.4

Physical Security; Securing Individual Systems; Securing The Basic LAN; Architecture Failure Domains And Data Protection; Securing Virtual and Cloud Environments; Recovery Objectives And Immutable Copy Limits

Practice 11 items
4.0 Security Operations9 objectives77 questions
Objective 4.1

Foundations of Cryptography; Server Hardening Basics; Protocol And Port Awareness; Tools of the Trade; Securing Individual Systems; Wireless Identity And Platform Limits; Securing Wireless LANs; Securing Dedicated and Mobile Systems; Application And Email Validation

Practice 16 items
Objective 4.2

Data Stewardship And Sanitization; Securing Virtual and Cloud Environments; Securing Dedicated and Mobile Systems

Practice 3 items
Objective 4.3

Securing Virtual and Cloud Environments; Securing Dedicated and Mobile Systems; Application And Email Validation; Testing Infrastructure; Vulnerability Evidence And Prioritization

Practice 11 items
Objective 4.4

Risk Management; Cryptographic Lifecycle And Change Evidence; Physical Security; Tools of the Trade; Evidence Correlation And Time Normalization; Vulnerability Evidence And Prioritization; Containment And Control Tradeoffs; Securing The Basic LAN

Practice 12 items
Objective 4.5

Application And Email Validation; Secure Protocols and Applications

Practice 3 items
Objective 4.6

Identity and Account Management; Federation And Token Validation; Authentication Sessions And Revocation; Securing Dedicated and Mobile Systems; Phishing Resistant Authentication And Recovery

Practice 12 items
Objective 4.7

Tools of the Trade; Business Security Impact; Automation Guardrails And Validation

Practice 3 items
Objective 4.8

Containment And Control Tradeoffs; Securing Virtual and Cloud Environments; Dealing with Incidents; Awareness Outcomes And Response Improvement

Practice 10 items
Objective 4.9

Physical Security; Evidence Correlation And Time Normalization; Awareness Outcomes And Response Improvement

Practice 7 items
5.0 Security Program Management and Oversight6 objectives55 questions
Objective 5.1

Data Stewardship And Sanitization; Risk Management; Authentication Sessions And Revocation; Identity and Account Management; Phishing Resistant Authentication And Recovery; Risk And Governance Terms; Securing The Basic LAN; Securing Wireless LANs; Governance Assurance And Privacy Evidence; Business Security Impact; Awareness Outcomes And Response Improvement; Dealing with Incidents

Practice 16 items
Objective 5.2

Risk Management; Cryptographic Lifecycle And Change Evidence; Business Security Impact; Recovery Objectives And Immutable Copy Limits; Risk Calculations And Metric Denominators

Practice 16 items
Objective 5.3

Secure Protocols and Applications; Governance Assurance And Privacy Evidence; Dealing with Incidents

Practice 7 items
Objective 5.4

Risk Management; Securing Dedicated and Mobile Systems; Governance Assurance And Privacy Evidence; Awareness Outcomes And Response Improvement

Practice 6 items
Objective 5.5

Securing Individual Systems; Governance Assurance And Privacy Evidence; Testing Infrastructure

Practice 7 items
Objective 5.6

Securing Wireless LANs; Awareness Outcomes And Response Improvement

Practice 3 items