If you're looking for your first security certification, you'll almost certainly come across this name. Security+ appears in almost every cybersecurity learning roadmap and is also frequently found in job postings in Vietnam.
This article explains what it is, what the exam is like, and, more importantly: whether you truly need it.
What is Security+ certification?
CompTIA Security+ is a foundational security certification issued by CompTIA — a non-profit organization in the US, not affiliated with any specific technology vendor. This point is important: it's a vendor-neutral certification, meaning it doesn't teach you about a particular vendor's products but rather teaches principles applicable in any environment.
The current version is SY0-701, released in November 2023.
The certification is valid for 3 years from the date of passing the exam, after which it can be renewed through CompTIA's Continuing Education (CE) program.
What does the exam consist of?
| Category | Information |
|---|---|
| Exam Code | SY0-701 |
| Number of Questions | Maximum 90 questions |
| Duration | 90 minutes |
| Question Types | Multiple-choice + performance-based questions (PBQs) |
| Passing Score | 750 on a scale of 100–900 |
| Format | In-person at a Pearson VUE testing center or online at home |
| Language | English (and some other languages, Vietnamese not available) |
A point to note: the 100–900 score range is not a percentage scale. Achieving 750 does not mean you answered 83% of the questions correctly. This is a scaled score, calculated based on the difficulty of the exam questions you received.
Five domains and their weight
This is your roadmap to allocate study time. Don't study all five parts equally — the weightings vary quite a bit.
| Domain | Weight | Main Content |
|---|---|---|
| 1. General Security Concepts | 12% | Foundational concepts: CIA triad, control types, zero trust, basic cryptography |
| 2. Threats, Vulnerabilities & Mitigations | 22% | Attack types, threat actors, vulnerabilities, mitigation strategies |
| 3. Security Architecture | 18% | Infrastructure architecture, cloud, data protection, resilience |
| 4. Security Operations | 28% | Daily operations: monitoring, vulnerability management, incident response, IAM |
| 5. Security Program Management & Oversight | 20% | Governance, risk, compliance, vendor management, awareness training |
Security Operations accounts for 28% — the largest portion. Combined with Threats at 22%, these two parts make up half of the exam. If you have limited time, this is where you should focus your efforts.
Domain 5 is often overlooked by technical learners because it leans towards governance and policy, with nothing "hands-on." But it accounts for 20% — ignoring it can lead to losing points quickly.
Exam prerequisites
There are no mandatory prerequisites. Anyone can register for the exam; no prior degrees or certifications are required.
CompTIA recommends (but does not require): having Network+ and about 2 years of IT experience in a security-related role.
In reality, in Vietnam, most successful candidates fall into one of three groups:
- Currently working as a system or network administrator, looking to transition into security
- Fourth-year IT students, studying to boost their resume competitiveness
- Working in a SOC at Tier 1, needing a certification to advance to the next tier
If you have never touched computer networks, TCP/IP, or operating systems at an administrative level, you can still take the exam — but your study time will be significantly longer, and it's advisable to supplement your network fundamentals first.
Why is Security+ mentioned so often?
It's included in the US Department of Defense's DoD 8140/8570 standard. While this might seem distant to the Vietnamese market, the impact is very real: FDI enterprises, companies outsourcing for US clients, and organizations adopting international standards all use this list as a reference when writing job descriptions.
It's the most frequently mentioned security certification in job postings. Not because it's the hardest, but because it's the common denominator — recruiters use it as a first filter.
It covers a broad range rather than deep specialization. You won't become a pentesting expert or a forensics expert after Security+. But you will understand the overall picture, enough to communicate with industry professionals and know which direction you want to pursue next.
Quick comparison with other certifications
| Certification | Level | Focus | When it's suitable |
|---|---|---|---|
| Security+ | Foundational | Broad, theoretical + situational | First security certification |
| CEH | Intermediate | Attacks, tools | Want to pursue an offensive path, or required by employer |
| CySA+ | Intermediate | Analysis, defense, SOC | Already working in SOC, want to advance to a higher tier |
| PenTest+ | Intermediate | Full lifecycle penetration testing | Want to do pentesting with reporting skills |
The most common order: Security+ first, then branch out depending on career direction.
Who should and who should not study it yet?
You should study it if:
- You are currently in IT and want to transition to security in the next 6–12 months
- Your resume is being filtered out, and you need a recognized credential
- Your company requires the certification for the position you're aiming for
- You want a systematic foundation instead of fragmented learning from YouTube
You should not rush into it yet if:
- You lack basic network and operating system fundamentals — studying Network+ or supplementing your knowledge first will be more effective
- You've worked in security for several years and need a certification for career advancement — consider CySA+ or a higher-level certification directly
- You're only studying because others are, without a clear career goal
The last point is more important than people might think. Security+ is an investment of both money and several hundred hours. If you don't know what you want to do with it yet, spend a week researching job roles before investing your money.
How long does it take to study?
Almost entirely dependent on your existing foundation:
- Already a sysadmin/network professional for 2+ years: 6–8 weeks, about 1–2 hours per day
- Has basic IT knowledge, not yet in security: 10–12 weeks
- Completely new: 4–6 months, should supplement network knowledge concurrently
These figures assume you study consistently. Cramming on weekends is often less effective for content with many technical terms like Security+.
Next steps
If you decide to pursue it, here are three things you should do in order:
- Download the official SY0-701 objectives from the CompTIA website. This is the exact list of what the exam asks — it's free and the most important document you'll have.
- Self-assess how much of it you already know.
- Choose a study method that fits your time and background.
See also: New Security+ version coming soon: should you take SY0-701 now or wait? · 90-day self-study roadmap for Security+ · Cost of taking the Security+ exam in Vietnam
Note for publisher: Number of questions, duration, scoring scale, and domain weightings are based on SY0-701 objectives. Cross-reference with the official CompTIA website before publishing, and update when a new version is released.