What is CompTIA Security+? The Complete Beginner's Guide

CompTIA Security+ là gì? Toàn tập cho người mới bắt đầu

If you're looking for your first security certification, you'll almost certainly come across this name. Security+ appears in almost every cybersecurity learning roadmap and is also frequently found in job postings in Vietnam.

This article explains what it is, what the exam is like, and, more importantly: whether you truly need it.

What is Security+ certification?

CompTIA Security+ is a foundational security certification issued by CompTIA — a non-profit organization in the US, not affiliated with any specific technology vendor. This point is important: it's a vendor-neutral certification, meaning it doesn't teach you about a particular vendor's products but rather teaches principles applicable in any environment.

The current version is SY0-701, released in November 2023.

The certification is valid for 3 years from the date of passing the exam, after which it can be renewed through CompTIA's Continuing Education (CE) program.

What does the exam consist of?

Category Information
Exam Code SY0-701
Number of Questions Maximum 90 questions
Duration 90 minutes
Question Types Multiple-choice + performance-based questions (PBQs)
Passing Score 750 on a scale of 100–900
Format In-person at a Pearson VUE testing center or online at home
Language English (and some other languages, Vietnamese not available)

A point to note: the 100–900 score range is not a percentage scale. Achieving 750 does not mean you answered 83% of the questions correctly. This is a scaled score, calculated based on the difficulty of the exam questions you received.

Five domains and their weight

This is your roadmap to allocate study time. Don't study all five parts equally — the weightings vary quite a bit.

Domain Weight Main Content
1. General Security Concepts 12% Foundational concepts: CIA triad, control types, zero trust, basic cryptography
2. Threats, Vulnerabilities & Mitigations 22% Attack types, threat actors, vulnerabilities, mitigation strategies
3. Security Architecture 18% Infrastructure architecture, cloud, data protection, resilience
4. Security Operations 28% Daily operations: monitoring, vulnerability management, incident response, IAM
5. Security Program Management & Oversight 20% Governance, risk, compliance, vendor management, awareness training

Security Operations accounts for 28% — the largest portion. Combined with Threats at 22%, these two parts make up half of the exam. If you have limited time, this is where you should focus your efforts.

Domain 5 is often overlooked by technical learners because it leans towards governance and policy, with nothing "hands-on." But it accounts for 20% — ignoring it can lead to losing points quickly.

Exam prerequisites

There are no mandatory prerequisites. Anyone can register for the exam; no prior degrees or certifications are required.

CompTIA recommends (but does not require): having Network+ and about 2 years of IT experience in a security-related role.

In reality, in Vietnam, most successful candidates fall into one of three groups:

  • Currently working as a system or network administrator, looking to transition into security
  • Fourth-year IT students, studying to boost their resume competitiveness
  • Working in a SOC at Tier 1, needing a certification to advance to the next tier

If you have never touched computer networks, TCP/IP, or operating systems at an administrative level, you can still take the exam — but your study time will be significantly longer, and it's advisable to supplement your network fundamentals first.

Why is Security+ mentioned so often?

It's included in the US Department of Defense's DoD 8140/8570 standard. While this might seem distant to the Vietnamese market, the impact is very real: FDI enterprises, companies outsourcing for US clients, and organizations adopting international standards all use this list as a reference when writing job descriptions.

It's the most frequently mentioned security certification in job postings. Not because it's the hardest, but because it's the common denominator — recruiters use it as a first filter.

It covers a broad range rather than deep specialization. You won't become a pentesting expert or a forensics expert after Security+. But you will understand the overall picture, enough to communicate with industry professionals and know which direction you want to pursue next.

Quick comparison with other certifications

Certification Level Focus When it's suitable
Security+ Foundational Broad, theoretical + situational First security certification
CEH Intermediate Attacks, tools Want to pursue an offensive path, or required by employer
CySA+ Intermediate Analysis, defense, SOC Already working in SOC, want to advance to a higher tier
PenTest+ Intermediate Full lifecycle penetration testing Want to do pentesting with reporting skills

The most common order: Security+ first, then branch out depending on career direction.

Who should and who should not study it yet?

You should study it if:

  • You are currently in IT and want to transition to security in the next 6–12 months
  • Your resume is being filtered out, and you need a recognized credential
  • Your company requires the certification for the position you're aiming for
  • You want a systematic foundation instead of fragmented learning from YouTube

You should not rush into it yet if:

  • You lack basic network and operating system fundamentals — studying Network+ or supplementing your knowledge first will be more effective
  • You've worked in security for several years and need a certification for career advancement — consider CySA+ or a higher-level certification directly
  • You're only studying because others are, without a clear career goal

The last point is more important than people might think. Security+ is an investment of both money and several hundred hours. If you don't know what you want to do with it yet, spend a week researching job roles before investing your money.

How long does it take to study?

Almost entirely dependent on your existing foundation:

  • Already a sysadmin/network professional for 2+ years: 6–8 weeks, about 1–2 hours per day
  • Has basic IT knowledge, not yet in security: 10–12 weeks
  • Completely new: 4–6 months, should supplement network knowledge concurrently

These figures assume you study consistently. Cramming on weekends is often less effective for content with many technical terms like Security+.

Next steps

If you decide to pursue it, here are three things you should do in order:

  1. Download the official SY0-701 objectives from the CompTIA website. This is the exact list of what the exam asks — it's free and the most important document you'll have.
  2. Self-assess how much of it you already know.
  3. Choose a study method that fits your time and background.


See also: New Security+ version coming soon: should you take SY0-701 now or wait? · 90-day self-study roadmap for Security+ · Cost of taking the Security+ exam in Vietnam


Note for publisher: Number of questions, duration, scoring scale, and domain weightings are based on SY0-701 objectives. Cross-reference with the official CompTIA website before publishing, and update when a new version is released.