Vendor-neutral certification covering core cybersecurity skills and best practices.
Who it's for
Entry-level IT professionals looking to build a foundation in cybersecurity, or move into a dedicated security role — CompTIA markets Security+ as the baseline credential employers look for before trusting someone with security responsibilities.
What's covered
- General security concepts — 12%
- Threats, vulnerabilities, and mitigations — 22%
- Security architecture — 18%
- Security operations — 28%
- Security program management and oversight — 20%
What to expect
Beyond standard multiple-choice, expect performance-based questions (PBQs) that drop you into a simulated environment — configuring a firewall rule, matching an attack type to a log excerpt — designed to test applied skill, not just terminology recall.
How to prepare
CompTIA's own prep stack is extensive: CertMaster Learn (self-paced e-learning), CertMaster Practice (adaptive practice questions), CertMaster Labs (hands-on simulated environments), official study guides, and the published exam objectives PDF that maps 1:1 to the content domains above — most candidates with some IT background report several weeks of focused study.
Certification details
- Certifying body: CompTIA.
- Eligibility: No mandatory prerequisites; CompTIA recommends Network+ certification plus two years of security/systems administration experience.
- Exam format: Up to 90 questions (multiple-choice and performance-based), 90-minute time limit. Passing score is 750 on a 100–900 scale.
- Content outline: General Security Concepts (12%), Threats/Vulnerabilities/Mitigations (22%), Security Architecture (18%), Security Operations (28%), Security Program Management & Oversight (20%).
- Note: CompTIA does not publish an official pass rate.
- Recertification: Certification is valid for 3 years; renew via 50 continuing education units (CertMaster CE, a higher-level exam, or qualifying CEU activities).