CompTIA Security+ in 60 Days: A Day-by-Day Study Plan
A structured 60-day schedule for SY0-701 covering all five domains, with weekly milestones, hands-on exercises, practice-test checkpoints, and the acronyms and ports worth memorizing.
Before Day 1
The exam: SY0-701, up to 90 questions in 90 minutes, including performance-based items, scored 100 to 900 with a 750 pass mark. That is roughly 83 percent on a scaled score, so aim for 85 percent or better on practice tests.
The five domains and their weights:
1. General Security Concepts, 12 percent
2. Threats, Vulnerabilities and Mitigations, 22 percent
3. Security Architecture, 18 percent
4. Security Operations, 28 percent
5. Security Program Management and Oversight, 20 percent
Notice that Security Operations is the largest domain. Weight your effort accordingly, and do not spend half your time on cryptography because it feels hardest.
Time commitment: this plan assumes 1.5 to 2 hours on weekdays and 3 to 4 hours on weekend days, roughly 90 to 110 hours total. Book the exam now, dated 60 days out. A booked date is the single most effective study aid there is.
Days 1 to 10: General Security Concepts and Foundations
Days 1 to 2. The CIA triad, non-repudiation, authentication versus authorization versus accounting. Control categories (technical, managerial, operational, physical) and control types (preventive, deterrent, detective, corrective, compensating, directive). Expect several questions that simply ask you to classify a control.
Days 3 to 4. Zero trust: control plane and data plane, policy engine, policy administrator, policy enforcement point. Read the CISA maturity model summary. This is heavily represented in SY0-701.
Days 5 to 6. Cryptography concepts: symmetric versus asymmetric, key exchange, hashing, salting, digital signatures, certificates and the PKI hierarchy, and what a CSR is. Focus on purpose and use case rather than internal mathematics.
Days 7 to 8. Change management and the security implications of change. Often skipped, reliably tested.
Days 9 to 10. Deception technologies (honeypots, honeytokens), physical security, and a first review pass. Checkpoint: take a Domain 1 quiz and aim for 80 percent.
Days 11 to 24: Threats, Vulnerabilities and Mitigations
This is the second-largest domain and the most fun to study.
Days 11 to 13. Threat actors and motivations: nation state, unskilled attacker, hacktivist, insider threat, organized crime, shadow IT. Attributes: resources, sophistication, internal versus external.
Days 14 to 16. Attack vectors and social engineering: phishing, vishing, smishing, pretexting, business email compromise, watering hole, typosquatting, brand impersonation. Know the vocabulary precisely, because questions hinge on the exact term.
Days 17 to 19. Vulnerability types: memory injection, buffer overflow, race conditions (including TOCTOU), malicious updates, virtualization escape, cloud misconfiguration, supply chain, and the mobile and zero-day categories.
Days 20 to 22. Malware and indicators: ransomware, trojan, worm, rootkit, logic bomb, keylogger. Then network attacks: on-path, DDoS, DNS poisoning, ARP poisoning, credential replay, and password attacks (spraying versus brute force).
Days 23 to 24. Mitigation techniques: segmentation, isolation, patching, encryption, hardening, least privilege, allowlisting, configuration enforcement, decommissioning. Checkpoint: Domain 2 quiz, target 80 percent.
Days 25 to 36: Security Architecture
Days 25 to 27. Architecture models: cloud responsibility matrix, infrastructure as code, serverless, microservices, on-premises versus centralized versus decentralized, virtualization, containerization, IoT, ICS and SCADA, embedded systems, and real-time operating systems. Know the trade-offs each model implies.
Days 28 to 30. Secure infrastructure: device placement, security zones, attack surface, failure modes (fail open versus fail closed), active versus passive inline appliances, and the difference between a screened subnet, a jump server, a proxy, and a load balancer.
Days 31 to 33. Data protection: data types and classifications, data at rest, in transit and in use, tokenization, masking, obfuscation, hashing, and geographic and sovereignty considerations.
Days 34 to 36. Resilience: high availability, load balancing versus clustering, site considerations (hot, warm, cold, geographic dispersion), platform diversity, backups, continuity of operations, capacity planning, and testing (tabletop, simulation, parallel processing, failover). Checkpoint: Domain 3 quiz, target 80 percent.
Days 37 to 50: Security Operations, the Biggest Domain
Give this domain the most time. It is 28 percent of the exam.
Days 37 to 38. Secure baselines, hardening targets, wireless security (WPA3, SAE), mobile deployment models (BYOD, COPE, CYOD), and mobile connection methods.
Days 39 to 40. Asset management: acquisition, assignment and ownership, classification, monitoring, and the disposal stack (sanitization, destruction, certification, data retention).
Days 41 to 42. Vulnerability management end to end: discovery methods, static and dynamic analysis, penetration testing, responsible disclosure, bug bounty, CVSS and CVE, CISA KEV, false positives and negatives, prioritization, compensating controls, and validation and reporting.
Days 43 to 45. Monitoring and alerting: SIEM, SNMP traps, NetFlow, log aggregation, antivirus, DLP, SCAP, benchmarks, agent versus agentless, alert tuning, quarantine.
Days 46 to 47. Enterprise capabilities: firewall types and rules, IDS and IPS, web filtering, DNS filtering, email security (DMARC, DKIM, SPF, gateways), EDR and XDR, and the concept of a user behaviour analytics tool.
Days 48 to 49. Identity and access management: provisioning and deprovisioning, SSO, LDAP, OAuth, SAML, federation, interoperability, attestation, access control models (RBAC, ABAC, MAC, DAC, rule-based), MFA factors, password concepts and password managers, and passwordless approaches.
Day 50. Automation and orchestration, plus incident response: the lifecycle, root cause analysis, threat hunting, and digital forensics (legal hold, chain of custody, acquisition, preservation, e-discovery). Checkpoint: Domain 4 quiz, target 85 percent.
Days 51 to 56: Security Program Management and Oversight
Days 51 to 52. Governance: policy types (AUP, information security, business continuity, disaster recovery, incident response, SDLC, change management), standards, procedures, guidelines, governance structures, and roles (owner, controller, processor, custodian, steward).
Days 53 to 54. Risk management: identification, assessment types (ad hoc, recurring, one-time, continuous), analysis (qualitative and quantitative), and the quantitative formulas. Memorize SLE, ARO, and ALE, and be able to compute ALE = SLE x ARO. Then risk register, tolerance and appetite, and the four responses (accept, avoid, transfer, mitigate).
Days 55 to 56. Third-party risk: vendor assessment, penetration testing and audits of suppliers, right-to-audit clauses, and the agreement types (SLA, MOU, MOA, MSA, SOW, NDA, BPA). Then compliance, privacy, and the audit and assessment section, plus security awareness training. Checkpoint: Domain 5 quiz, target 80 percent.
Days 57 to 60: Final Preparation
Day 57. Full-length timed practice exam under real conditions. Score it, then list every missed question by domain.
Day 58. Review only the misses. Do not study new material. Practise performance-based questions specifically, because they consume disproportionate time.
Day 59. Second full-length timed exam. You want 85 percent or better. Memorization sweep: common ports (20/21, 22, 23, 25, 53, 67/68, 69, 80, 110, 123, 143, 161/162, 389, 443, 445, 465/587, 636, 993, 995, 1433, 1521, 3306, 3389), the risk formulas, and the agreement acronyms.
Day 60. Light review of your notes only. Confirm your test centre or proctoring setup, sleep properly, and stop studying by early evening.
Exam-Day Tactics
Do the performance-based questions last. Flag and skip them on the first pass, bank the multiple-choice marks, then return with the remaining time.
Watch for "BEST" and "MOST likely." Several options will be defensible; one is best.
Do not leave anything blank. There is no penalty for guessing.
Trust your first instinct unless you find a concrete reason to change it.
Practise Deliberately, Not Passively
Re-reading notes creates false confidence. Answering questions and reading the explanation for every miss is what actually moves your score. CyberCertPrep's Security+ bank covers all five SY0-701 domains with detailed explanations, timed full-length simulations, and weak-domain analytics, so each checkpoint in this plan tells you precisely where to spend the next week.
Sources & References
Daniel Agrici
CEH, Security+, PenTest+
Daniel is the founder of CyberCertPrep. With a background in penetration testing and security consulting, he has passed 8 cybersecurity certifications and writes about exam strategies and career development.
Ready to start practicing?
72+ certifications. 126,000+ questions. 20 free per cert.