CompTIA Security+ (SY0-701) Study Plan¶
6-Week Comprehensive Study Schedule¶
Week 1: General Security Concepts¶
Day 1-2: Core Security Principles¶
- CIA triad - confidentiality, integrity, availability
- AAA framework - authentication, authorization, accounting
- Non-repudiation and accountability
- Gap analysis and security assessments
- Review Notes:
01-security-concepts.md
Day 3-4: Security Frameworks and Models¶
- Zero trust architecture and principles
- Defense in depth and layered security
- Threat actors - nation-state, organized crime, insiders, hacktivists
- Attack surface management
- Review Notes:
01-security-concepts.md
Day 5-6: Cryptography Fundamentals¶
- Symmetric encryption - AES, 3DES
- Asymmetric encryption - RSA, ECC, Diffie-Hellman
- Hashing - SHA-256, MD5, bcrypt
- PKI components - CA, RA, certificates, CRL, OCSP
- Digital signatures and certificates
- Review Notes:
01-security-concepts.md
Day 7: Week 1 Review¶
- Practice questions on security concepts (target: 65%+)
- Review CIA triad applications
- Create cryptography comparison chart
Week 2: Threats, Vulnerabilities, and Mitigations¶
Day 8-9: Malware and Attack Types¶
- Malware types - ransomware, trojans, worms, rootkits, fileless
- Social engineering - phishing, vishing, smishing, pretexting
- Network attacks - MITM, DDoS, DNS poisoning, replay
- Application attacks - SQL injection, XSS, CSRF, buffer overflow
- Review Notes:
02-threats-vulnerabilities.md
Day 10-11: Vulnerability Types and Indicators¶
- Software vulnerabilities - zero-day, unpatched, misconfigurations
- Hardware vulnerabilities - firmware, side-channel attacks
- Supply chain vulnerabilities
- Indicators of compromise (IoCs) and indicators of attack (IoAs)
- Review Notes:
02-threats-vulnerabilities.md
Day 12-13: MITRE ATT&CK and Mitigation Techniques¶
- MITRE ATT&CK framework tactics and techniques
- Cyber kill chain stages
- Mitigation strategies for common attacks
- Hardening techniques and security baselines
- Review Notes:
02-threats-vulnerabilities.md
Day 14: Week 2 Review¶
- Practice questions on threats and vulnerabilities (target: 65%+)
- Review malware comparison chart
- Practice matching attacks to defenses
Week 3: Security Architecture¶
Day 15-16: Network Security¶
- Firewalls - packet filtering, stateful, NGFW, WAF
- IDS/IPS - signature-based, anomaly-based, inline vs passive
- Network access control (NAC)
- Proxy servers and reverse proxies
- Network segmentation and micro-segmentation
- Review Notes:
03-security-architecture.md
Day 17-18: Cryptographic Implementation¶
- TLS/SSL protocol details and versions
- IPsec - transport mode, tunnel mode
- SSH, SFTP, FTPS
- Certificate management and lifecycle
- Key management and key escrow
- Review Notes:
03-security-architecture.md
Day 19-20: Cloud and Infrastructure Security¶
- Cloud security models - shared responsibility
- CASB, SASE, ZTNA
- Secure network design patterns
- Resilience and recovery - HA, DR, backups
- Secure protocols vs insecure counterparts
- Review Notes:
03-security-architecture.md
Day 21: Week 3 Review¶
- Practice questions on security architecture (target: 70%+)
- Review secure vs insecure protocol pairs
- Practice network security device selection
Week 4: Security Operations¶
Day 22-23: Monitoring and Detection¶
- SIEM concepts and log management
- Security monitoring tools and techniques
- Alert triage and investigation
- Threat intelligence and threat hunting
- Vulnerability scanning and assessment
- Review Notes:
04-security-operations.md
Day 24-25: Incident Response and Forensics¶
- IR lifecycle - preparation, detection, containment, recovery, post-incident
- Digital forensics - evidence handling, chain of custody
- Order of volatility and forensic imaging
- Legal hold and e-discovery
- Tabletop exercises and incident simulations
- Review Notes:
04-security-operations.md
Day 26-27: Identity and Access Management¶
- Authentication methods - passwords, MFA, biometrics, certificates
- SSO and federation - SAML, OAuth, OIDC
- Access control models - RBAC, ABAC, MAC, DAC
- Privileged access management
- Account lifecycle management
- Penetration testing concepts and methodologies
- Review Notes:
04-security-operations.md
Day 28: Week 4 Review¶
- Practice questions on security operations (target: 70%+)
- Review IR lifecycle steps
- Practice evidence handling scenarios
Week 5: Security Program Management¶
Day 29-30: Risk Management¶
- Risk identification, assessment, and analysis
- Qualitative vs quantitative risk analysis
- Risk response strategies - mitigate, accept, transfer, avoid
- Risk register and risk appetite
- Business impact analysis (BIA)
- Review Notes:
05-governance-compliance.md
Day 31-32: Governance and Policies¶
- Security policies, standards, procedures, guidelines
- Acceptable use, data handling, incident response policies
- Change management and its security impact
- Data governance and classification
- Third-party risk management and vendor assessment
- Review Notes:
05-governance-compliance.md
Day 33-34: Compliance and Frameworks¶
- NIST CSF and RMF
- ISO 27001 and CIS Controls
- Regulations - GDPR, HIPAA, PCI-DSS, SOX
- Audits and assessments - internal, external, regulatory
- Security awareness training programs
- Review Notes:
05-governance-compliance.md
Day 35: Week 5 Review¶
- Practice questions on governance (target: 75%+)
- Review framework comparisons
- Practice risk calculation scenarios
Week 6: Review and Exam Preparation¶
Day 36-37: Full Practice Exams¶
- Complete full-length practice exam 1
- Review all incorrect answers thoroughly
- Identify weak areas and knowledge gaps
- Target score: 80%+
Day 38-39: Weak Area Deep Dive¶
- Review notes for identified weak domains
- Additional practice questions on weak areas
- Re-study key concepts and acronyms
- Complete full-length practice exam 2
Day 40-41: Performance-Based Question Practice¶
- Practice scenario-based questions
- Practice log analysis and network diagram questions
- Review common PBQ formats and techniques
- Time management under test pressure
Day 42: Final Review and Exam Day Prep¶
- Review fact sheet and quick reference
- Skim through all study notes
- Review acronym list
- Prepare exam logistics and get rest
Daily Study Routine (2-3 hours/day)¶
Recommended Schedule¶
- 30 minutes: Read study notes and review concepts
- 45 minutes: Deep dive into specific topics with documentation
- 45 minutes: Practice questions and scenario analysis
- 15 minutes: Review incorrect answers and note weak areas
Practice Exam Strategy¶
Target Scores by Week¶
- Week 2: 60%+ on domain-specific practice
- Week 3: 65%+ on domain-specific practice
- Week 4: 70%+ on mixed practice exams
- Week 5: 75%+ on mixed practice exams
- Week 6: 80%+ consistently on full practice exams
Study Resources¶
Free Resources¶
- π Professor Messer Security+ SY0-701 - Free video course
- π MITRE ATT&CK Framework - Adversary tactics reference
- π NIST Publications - Security guidelines and standards
- π OWASP Top 10 - Web application security risks
Paid Resources¶
- π CertMaster Learn for Security+ - Official training
- π CertMaster Practice for Security+ - Official practice
- Jason Dion Security+ SY0-701 (Udemy) - Video course and practice exams
- CompTIA Security+ Study Guide (SY0-701) - Sybex book
Final Exam Checklist¶
Content Preparation¶
- All five domain notes reviewed
- Fact sheet key facts memorized
- Port numbers for common services memorized
- Acronyms reviewed
- Common scenarios practiced
Exam Day Strategy¶
- Time management: ~1 minute per question
- Skip PBQs initially, return after MCQs
- Read questions carefully for keywords
- Eliminate wrong answers first
- Flag uncertain questions and return later
- Reserve 15 minutes for review