Security Plus Exam Objectives 601: What Actually Gets Tested and How to Study It
The CompTIA Security+ SY0-601 exam broke down into five domains with pretty specific weightings. If you are just now looking at it, the biggest domain by far is Implementation of Security Protocols and Technologies at 26 percent. That means roughly a quarter of the exam is about making things work, not just defining them. The other domains spread across General Security Concepts at 15 percent, Threats Vulnerabilities and Mitigations at 22 percent, Operations and Incident Response at 20 percent, and Governance Risk and Compliance at 17 percent. Getting these weights right changes how you should spend your study time, and most people study in the wrong order. You can download the official objectives PDF directly from the CompTIA website. Search for SY0-601 objectives or go to comptia.org and look under Certifications then Security+. It is a single PDF file, usually around 30 to 40 pages, listing every topic CompTIA says could appear on the exam. That document is your blueprint. Everything else is interpretation. I recommend downloading it and printing it so you can physically check things off as you study. Digital copies are fine too, but the act of marking something off on paper actually sticks better than clicking a checkbox on a screen. Here is what most people skip when they first look at the objectives. They skim the domain titles and go straight to flashcards. Do not do that. Look at the sub-objectives under each domain heading. Those bullet points are the actual questions they can ask you. A line that says "identify the purpose of protocols" means they can show you a scenario with TLS, SSH, SNMPv3, SFTP, and LDAP and ask which one is being used and why. The answer choices will all be real protocols. You have to know the difference between them, not just their names.
General Security Concepts
This domain sounds small at 15 percent, but it contains the foundation everything else builds on. CIA triad comes up constantly, but the exam will rarely ask you to define confidentiality, integrity, and availability. It will give you a scenario and ask which principle is being violated or protected. For example, if a ransomware attack encrypts files and makes them inaccessible, that is availability. If someone tampers with a software update but the signature is still valid because the key was compromised, that is integrity. If a database is accessed by the wrong person, that is confidentiality. Easy to understand, easy to mess up under exam pressure. Authentication, authorization, and accounting, commonly called AAA, is another area people think they know but do not actually understand well enough for the exam. RADIUS combines authentication and authorization but does accounting. TACACS+ separates all three. If you see a question asking about granular command-level authorization on network devices, TACACS+ is usually the answer. Kerberos uses tickets and involves a Key Distribution Center. If the scenario mentions a ticket-granting ticket or mutual authentication between client and server, think Kerberos. Pretty much every large enterprise Windows environment uses Kerberos by default, so you will encounter that concept a lot in real life too, not just on the exam. Cryptography is heavily tested here and it is also where most people lose points. You need to know the difference between symmetric and asymmetric encryption cold. AES is symmetric and fast, used for bulk data encryption. RSA is asymmetric and slower, used for key exchange and digital signatures. ECC is the smaller-key alternative to RSA that gives similar security with less computational overhead. Hashing is not encryption. MD5 and SHA-1 are broken and you should never use them. SHA-256 and SHA-3 are the standards. HMAC adds a secret key to a hash for message authentication. Digital signatures combine hashing and asymmetric encryption to provide non-repudiation, which means the sender cannot deny they sent the message. That is a specific legal and compliance concept that shows up in scenarios about audit trails.
PKI is another big one. You need to understand what a Certificate Authority does, what an intermediate CA is, and how certificate revocation works. CRL stands for Certificate Revocation List and it is published periodically by the CA. OCSP is the Online Certificate Status Protocol and it checks revocation status in real time. Both have trade-offs. CRLs can get large and slow to distribute. OCSP requires contacting the responder online, which raises privacy concerns because the responder knows which certificate you are checking. OCSP stapling fixes some of that by having the web server attach a time-stamped response from the CA. You should know why stapling exists and what problem it solves.
Get the Full Details

Threats Vulnerabilities and Mitigations
At 22 percent this is the second largest domain, and it is where the exam gets practical. You will see attacks described in narrative form rather than as simple definitions. A man-in-the-middle attack might be described as someone intercepting communication between two parties and relaying it, possibly modifying it. You need to recognize the pattern, not just the term. ARP poisoning, DNS poisoning, and SSL stripping are all MITM variants that show up individually and as answer choices. Social engineering is heavily weighted and it is not just about recognizing phishing. The exam will describe scenarios involving pretexting, baiting, tailgating, and quid pro quo. Pretexting involves creating a fabricated scenario to manipulate someone. Baiting offers something tempting, like a free USB drive left in a parking lot. Tailgating is physically following someone into a restricted area. Quid pro quo is offering help or a service in exchange for information. These distinctions matter because the answer choices will include all of them, and you have to pick the one that matches the scenario exactly. Vulnerability scanning and management is a practical area that connects directly to real work. Tools like Nessus, OpenVAS, and Qualys are commonly referenced. The exam cares more about the process than the tool names though. You need to understand the difference between authenticated and unauthenticated scans, credentialed scans give more detail because they log into the system, and passive scans monitor traffic without sending packets, which makes them harder to detect but slower to produce results. The vulnerability management lifecycle involves identification, prioritization based on risk, remediation, and verification. Prioritization is usually done using CVSS scores, which you should know how to read. A CVSS score of 9.0 or above is critical and should be addressed first, but business context can shift that priority.
I remember dealing with a situation at work where a vulnerability scanner flagged a server with a high CVSS score for an outdated library, but the vulnerable function was not exposed through any network service. The scanner did not know about the application architecture. We had to manually verify the attack vector before spending time on remediation. CompTIA expects you to know this distinction too. A high vulnerability score does not automatically mean immediate action. You assess exposure and exploitability, not just the score.
Implementation of Security Protocols and Technologies
This is the largest domain at 26 percent and it covers a lot of ground. Network hardening is fundamental. You need to know how to configure firewalls, implement network segmentation with VLANs and DMZs, and apply principle of least privilege to network services. Default ports matter. SSH is 22, HTTPS is 443, RDP is 3389, SNMP is 161 and 162. Knowing the default ports helps you identify what services are running when you see them in a scenario. Firewall rules should deny by default and allow only what is necessary. Any rule that says allow all is a red flag. Wireless security is another practical area. WPA3 is the current standard and it uses SAE for authentication instead of the pre-shared key handshake that WPA2 uses. WPA3 makes brute force attacks harder by using Simultaneous Authentication of Equals. WPA2 with TKIP is deprecated and should not be used. CCMP is the encryption protocol for WPA2 and WPA3. AES-CCMP is the correct answer for modern wireless encryption. If you see WEP or TKIP in a scenario, the answer is usually that it is insecure and should be replaced. VPN technologies come up regularly. IPsec operates at layer 3 and can protect all traffic between two networks. SSL/TLS VPNs operate at layer 7 and provide application-level access. Tunnel mode IPsec encrypts the entire original packet including the header, while transport mode only encrypts the payload. This distinction matters for exam questions about gateway-to-gateway VPNs versus host-to-gateway setups. IKE Phase 1 establishes the ISAKMP SA and negotiates the encryption and authentication method. IKE Phase 2 establishes the IPsec SA and negotiates the transform set for the actual data tunnel.

Email security is frequently tested. SPF, DKIM, and DMARC are the three main protocols. SPF tells receiving servers which IP addresses are allowed to send mail for a domain. DKIM adds a cryptographic signature to outgoing messages so the receiver can verify the sender has not tampered with them. DMARC ties SPF and DKIM together and tells receivers what to do with messages that fail authentication. SPF alone is not sufficient because it does not prevent header forging. You need all three working together for proper email security, and DMARC is what makes the system enforceable. Secure protocols for specific use cases is another area that trips people up. SNMPv3 adds authentication and encryption to what was previously an unsecured protocol. FTPS adds SSL/TLS to FTP. SFTP uses SSH for file transfer. SCP also uses SSH. LDAPS is LDAP over SSL on port 636. SMTPS is SMTP over SSL on port 465. These distinctions are subtle but the exam loves them. You should be able to look at a port number and a protocol name and immediately know if it is secure or not.
Operations and Incident Response
Operations and incident response covers 20 percent and it is where theory meets practice. Defense in depth is the concept of layering security controls so that if one fails, others still provide protection. This is not just a buzzword on the exam. You will see questions asking you to identify which layer of defense a specific control belongs to. Physical controls like badges and cameras are one layer. Network controls like firewalls and IDS are another. Host controls like antivirus and HIDS are a third. Application controls like input validation and WAFs are yet another. Each layer addresses different attack vectors. Monitoring and detection tools are extensively covered. SIEM platforms aggregate logs from multiple sources and correlate events to detect patterns. IDS detects suspicious activity. IPS actively blocks it. NIDS monitors network traffic. NIPS sits in-line and can block traffic. HIDS runs on individual hosts and monitors system calls and file integrity. Log analysis is a practical skill the exam tests through scenarios where you are given log entries and asked to identify the attack or the anomaly. Timestamps, source IPs, user agents, and error codes are the key data points to look for. The incident response process follows a specific sequence that CompTIA expects you to know. Preparation comes first, then identification, containment, eradication, recovery, and lessons learned. This is NIST SP 800-61 based. A common mistake is thinking containment comes before identification. You cannot properly contain an incident if you do not know what you are containing. The phases must follow that order, even though in practice they sometimes overlap. Lessons learned is the final phase and it is often skipped in real organizations, which is why incidents keep happening in the same way. The exam will not let you skip it.
Data handling and protection is part of this domain too. Classification labels like public, internal, confidential, and restricted should be applied to data and controls should match the classification level. Encryption at rest and encryption in transit are separate requirements. Key management is critical and often overlooked. If you encrypt data but cannot securely store or rotate the keys, the encryption provides no real protection. Hardware security modules are used for enterprise key storage. I ran into a case where a team had implemented full disk encryption on their servers but the drive recovery keys were stored in the same unencrypted file share as the server configuration files. During a breach scenario, the attacker could have easily accessed both. The encryption existed in name only because the keys were not separated from the encrypted data by a meaningful control boundary. CompTIA expects you to recognize this kind of flaw in exam scenarios and understand that key management is not a secondary concern. Backup strategies involve full, incremental, and differential backups. Full backups copy everything and take the longest. Incremental backups copy only changes since the last backup of any type and restore requires the last full backup plus all incrementals in sequence. Differential backups copy changes since the last full backup and restore requires only the last full and the latest differential. The RTO and RPO concepts tie into this. Recovery Time Objective is how long you can afford to be down. Recovery Point Objective is how much data loss you can tolerate. A lower RPO requires more frequent backups.

Governance Risk and Compliance
This domain at 17 percent deals with policy, risk, and regulatory requirements. Risk assessment methods include qualitative and quantitative approaches. Qualitative assessments use scales like high, medium, and low based on expert judgment. Quantitative assessments assign dollar values to risks and calculate Annualized Loss Expectancy by multiplying Single Loss Expectancy by the Annualized Rate of Occurrence. ALE is a formula you should memorize because it appears directly on the exam. Risk treatment options are accept, mitigate, transfer, or avoid. Accept means you acknowledge the risk and do nothing. Mitigate means you implement controls to reduce it. Transfer means you shift it, usually through insurance or outsourcing. Avoid means you eliminate the activity that creates the risk. The exam will present a scenario and ask which risk treatment is most appropriate. The answer depends on the cost-benefit analysis. If a control costs more than the potential loss, accepting the risk may be the rational choice. Frameworks and standards are tested but not as deeply as you might think. NIST CSF has five functions: identify, protect, detect, respond, and recover. ISO 27001 is the international standard for information security management systems. NIST 800-53 provides detailed control families. COBIT focuses on IT governance. SOX applies to publicly traded companies and covers financial reporting controls. HIPAA covers health information. PCI DSS covers payment card data. GDPR covers European Union personal data. You need to know which framework applies to which regulation and what the basic requirements are.
Policies and procedures are the documents that translate requirements into action. An acceptable use policy defines how employees may use company resources. A privacy policy defines how personal data is collected and used. A segregation of duties policy ensures no single person has enough access to commit and conceal fraud. Change management procedures control how modifications are requested, approved, tested, and deployed. The exam will test your ability to identify which policy addresses a given scenario. Business continuity and disaster recovery are related but distinct. BCP keeps the business running during a disruption. DRP restores IT systems after a disaster. A BIA, or Business Impact Analysis, identifies critical business functions and the resources they depend on. It determines maximum tolerable downtime and prioritizes recovery efforts. The BIA feeds into both the BCP and DRP. Without a BIA, you are making recovery decisions based on guesswork rather than business requirements.
How to actually study for this exam
The objectives document is necessary but not sufficient. You need practice questions that mimic the exam style, which means scenario-based questions rather than simple definition recall. Performance-based questions require hands-on familiarity with concepts like firewall rule configuration, log analysis, and network topology design. If you can, set up a home lab with a firewall appliance, a VPN router, and a few virtual machines. Configuring things yourself makes the performance-based questions much less intimidating. When you study, work through each domain in order of weight. Start with Implementation and Threats since they make up nearly half the exam. Then move to Operations and Governance. General Security Concepts last because it is the smallest domain and the concepts reinforce what you have already studied. Reviewing PKI and cryptography after studying the other domains makes more sense because you will understand why those concepts matter in context. Do not rely solely on video courses. You need to read the objectives document itself and understand every bullet point. If a bullet point mentions a term you have never heard, look it up. CompTIA includes specific terminology that may not appear in your study materials. Terms like SANS, MITRE ATT&CK, and STIX/TAXII are examples. They appear as answer choices even if the objectives do not dedicate a separate bullet to them.

The exam itself is computer-based and adaptive in the sense that the question pool varies by test center and date. You get 90 minutes for up to 90 questions. Some of those questions are performance-based and require you to interact with a simulated environment. PBQs usually appear early in the exam, so you do not want to waste time on easy questions and then run out of time for the harder ones. Budget your minutes carefully. If a question is taking more than a minute, mark it and move on. You can come back to it. One thing I noticed from reviewing actual exam content across multiple attempts is that CompTIA tends to recycle scenario patterns. Firewall configuration questions always involve allowing legitimate traffic while blocking everything else. Incident response questions always include a distractor that seems reasonable but violates the proper sequence. Risk calculation questions always give you enough information to compute ALE but some of the numbers are irrelevant. Learning to identify relevant information quickly saves significant time during the exam. If you are transitioning from SY0-501 to SY0-601, the biggest changes involve cloud security, container security, and IoT/OT security. These topics received more emphasis in SY0-601 than in the previous version. Container security basics like image scanning, immutable infrastructure, and runtime protection are fair game. IoT and OT security questions focus on the unique constraints of these environments, such as limited processing power, long lifecycle, and safety-critical operations.
The SY0-601 exam was retired in 2024 and replaced by SY0-701, but the core concepts remain relevant. If you are studying SY0-601 objectives specifically, perhaps for a course or because your organization still references that version, the material I covered above reflects what that exam actually tested. The fundamental security concepts do not change significantly between versions. What changes is the emphasis and the inclusion of newer topics like zero trust architecture and supply chain security, which became more prominent in later versions. Download the official objectives PDF from CompTIA and use it as your checklist. Work through each domain systematically. Practice with scenario-based questions, not just flashcards. Understand the why behind each concept, not just the definition. If you can explain why a particular control is appropriate for a given scenario, you are ready for the exam.