The Best Study Material for this roadmap is the 92-Day Security+ CertMaster Learn & Lab Account
Most study plans fail not because of incorrect content, but because they are written for people with 4 hours of free time every day. Working professionals don't have 4 hours.
The roadmap below assumes you have 1.5 hours on weekdays and 4 hours on weekends — about 15 hours a week. A total of nearly 180 hours over 90 days, enough for someone with a basic IT background.
Before you start: two mandatory tasks
1. Schedule your exam now.
It sounds counterintuitive, but without an exam date, the plan will drift. Schedule it 90–100 days from today. You can postpone if needed, but you must have a real date on the calendar.
2. Download the SY0-701 objectives from the CompTIA website.
It's free. This is the exact list of what will be asked on the exam. Print it out, and mark off each item as you study it. By the end, this list will be your map of the areas you still need to review.
Self-assess your starting point
Honestly answer these four questions:
- Can you explain how TCP/IP, subnets, DNS, and DHCP work?
- Have you configured firewalls, VPNs, or permissions on Windows Server / Linux?
- Can you distinguish between symmetric and asymmetric encryption?
- Have you worked in an environment with security processes (logging, backup, access control)?
3 or more "yes" answers: The 90-day roadmap below is suitable. 1–2 answers: Add 3–4 weeks for the networking fundamentals at the beginning. No answers: You should learn basic networking knowledge first, don't jump straight into Security+.
Overarching principles
Domain weighting determines time allocation. Security Operations accounts for 28%, Threats 22% — these two parts make up half of the exam. The roadmap below dedicates the most weeks to them.
Alternate between theory and labs, do not separate them. Read a chapter and then do the corresponding lab in the same week. If you leave labs until the end, you'll forget all the initial theory.
The last three weeks are only for practice tests, no new knowledge. If by week 10 you are still learning new content, the roadmap has slipped — address this by postponing the exam, not by cutting the practice test phase.
Phase 1 — Weeks 1 to 3: Foundations
Content: Full Domain 1 (General Security Concepts, 12%), plus the beginning of Domain 3 (Security Architecture).
This is the terminology phase. You will encounter a series of new concepts: the CIA triad, types of controls (preventive/detective/corrective, technical/managerial/operational), zero trust, PKI, various types of digital certificates.
Weekly tasks:
- Read/watch 2–3 theory chapters
- Make flashcards for terminology — this part requires memorization, there's no other way
- Do labs on encryption and digital certificates
Common trap: skimming over the "types of controls" section because it seems boring. The exam asks many questions like "what type of control is this?", and these are the easiest points to earn.
Phase 2 — Weeks 4 to 6: Threats and vulnerabilities
Content: Domain 2 (Threats, Vulnerabilities & Mitigations, 22%).
This section is the most interesting and also has the most details to remember: types of malware, network attack techniques, application attacks, social engineering, types of threat actors and their motivations.
Tasks:
- Create a table comparing similar types of attacks (this is where the exam often tries to trick you: phishing vs vishing vs smishing vs whaling; DDoS vs DoS vs amplification)
- Do vulnerability scanning labs and interpret the results
- Start doing practice questions by domain, don't wait until the end
Week 6 checkpoint: Take a practice test for domains 1 and 2. If below 70%, spend an additional 3–4 days reinforcing before moving on.
Phase 3 — Weeks 7 to 9: Security operations
Content: Domain 4 (Security Operations, 28%) — the largest part of the exam.
Monitoring and logging, vulnerability management, incident response, identity and access management (IAM), automation, endpoint security.
Three weeks for one domain may sound like a lot, but this is 28% of the exam and also the most job-relevant section. Studying this thoroughly has value beyond the exam.
Tasks:
- Do labs on IAM, permissions, multi-factor authentication
- Read real logs — even if it's just Windows Event Viewer logs on your machine
- Master the steps in the incident response process in order
Phase 4 — Weeks 10 to 11: Architecture and governance
Content: The remainder of Domain 3 (18%) and all of Domain 5 (Security Program Management, 20%).
Domain 5 is the part that technical learners often find most tedious: risk management, compliance, vendor management, policies, awareness training. Nothing to "play with," just management concepts.
But it accounts for 20% of the exam. Skipping this domain means voluntarily losing one-fifth of the points. The most effective way to learn: relate it to your current company — does the company have a password policy, an onboarding process, who approves access? Connecting concepts to real-world examples will help you remember them better than rote memorization.
Phase 5 — Weeks 12 to 13: Practice tests
No new content. This phase involves only three things:
1. Take full-length practice exams, timed for 90 minutes. At least 3 times, spaced several days apart.
2. After each exam, analyze incorrect answers by domain. Don't just look at the correct answer — understand why you chose incorrectly. Three common reasons: lack of knowledge, skimming the question, or confusing two similar concepts. Each reason requires a different approach.
3. Practice PBQs separately. Performance-based questions (PBQs) consume the most time in the exam room. Get familiar with them beforehand to avoid panic.
Safety threshold: consistently scoring over 85% on practice exams. If below 80%, you should reschedule the exam — failing costs more than rescheduling.
Last three days
- Day -3: Review all terminology flashcards, no new practice tests
- Day -2: Re-read the compiled list of incorrect answers, check equipment if taking the exam online
- Day -1: Rest. Do not study. Get enough sleep. Cramming on the last day does more harm than good.
If you fall behind schedule
This happens to most working professionals, and it doesn't mean your plan is ruined. Three ways to handle it, in order of priority:
1. Reschedule the exam for 3–4 weeks later. Much cheaper than failing. 2. Cut down on labs, keep theory and practice tests. Labs are important for career but account for fewer points on the exam. 3. Never cut the practice test phase. This is the part that turns knowledge into scores.
The only thing you should not do: keep the original exam date and hope for luck.
See also: What is CompTIA Security+? · What are PBQs in the Security+ exam? · How to register for the Security+ exam