Iβm running the CompTIA Security+ SY0-701 objectives one domain per week starting September 21, and sitting the exam in the week of October 26. This post sets out the goal, the intent behind it, and the scope of each week.
The goal
Become a security focused RTE and program manager. Concretely, that means three things by the first week of November.
Hold the certification. Security+ appears as required or strongly preferred on program and delivery roles, including ones where the work is planning rather than engineering, and itβs the credential that clears that line.
Speak the language security teams plan in. Control categories, risk registers, accreditation vocabulary, identity and access models. Enough to read a security requirement and price it in schedule terms.
Have five published pieces. Show the connection between security constraints and delivery outcomes, written while the material is fresh rather than reconstructed later.
The intent
Security and compliance are the binding constraint on more and more delivery work, and schedules slip in the space between the two groups who have to cooperate on it. The people who understand the controls usually donβt run a train. The people who run trains usually canβt plan around an accreditation boundary.
Most of what separates those two groups is vocabulary. I want to hear a security lead describe a control requirement in a planning session and know roughly what it costs in sequencing and time, enough to push back on an estimate and hold the date. Writing the implementation is someone elseβs job.
Thatβs the version of the role Iβm building toward: an RTE who runs trains where security is the constraint that governs the plan, and treats it as a planning input like any other dependency.
Scope by domain
The exam is a maximum of 90 questions in 90 minutes, multiple choice and performance based. The five domains carry different weight, and each one still gets a full week here, so the lighter domains finish early and the heavy ones donβt get crammed into a Thursday.
Domain 1
Week 1, September 21 to 27: General Security Concepts, 12 percent of the exam. Control categories and control types, the CIA triad, non-repudiation, AAA, gap analysis, zero trust across the control plane and data plane, physical security, and deception technology. Objective 1.3 is change management and its security impact, which maps onto program work more directly than anything else in the domain. Objective 1.4 runs cryptographic solutions from PKI through certificates.
Domain 2
Week 2, September 28 to October 4: Threats, Vulnerabilities, and Mitigations, 22 percent. Threat actors and their motivations, threat vectors and attack surfaces, the vulnerability catalogue across application, OS, web, hardware, virtualization, cloud, and supply chain, indicators of malicious activity, and the mitigation techniques used to secure an enterprise.
Domain 3
Week 3, October 5 to 11: Security Architecture, 18 percent. Architecture models and their security implications, securing enterprise infrastructure, data protection strategies, and resilience and recovery. Architecture choices show up as delivery constraints more plainly here than anywhere else on the exam.
Domain 4
Week 4, October 12 to 18: Security Operations, 28 percent. The biggest domain and the widest, nine objectives covering secure baselines and hardening, asset management, vulnerability management, alerting and monitoring, enterprise capability changes, identity and access management, automation and orchestration, incident response, and investigative data sources.
Domain 5
Week 5, October 19 to 25: Security Program Management and Oversight, 20 percent. Governance, the risk management process, third party risk, compliance, audits and assessments, and security awareness practices. The exam vocabulary and the program vocabulary already overlap in this one, so it should be the easiest week of the five.
The exam itself is the week of 26 October.
Practice and checkpoints
Reading the objectives and answering against them under a clock are different skills, so the testing runs alongside the study weeks instead of piling up at the end.
The seat gets booked in Week 1. Scheduling first fixes the end date before thereβs any room to slip it.
Week 3 closes with a timed sectional covering the first three domains, 90 minutes, and I want 80 percent per domain before moving on. Misses go into a flashcard deck, rebuilt from the misses only.
Week 4 is performance based question drills. PBQs punish people who only read: firewall rule ordering, ACL construction, log correlation to identify an attack type from raw entries, and control mapping across the four categories. Under four minutes per question, and anything scoring under 90 percent gets repeated after a 48 hour gap.
Week 5 is four full length timed exams, 90 questions in 90 minutes with no reference material, on Monday, Wednesday, Friday, and Saturday, run under testing center conditions. The gate for sitting the real exam is 85 percent or better on two consecutive attempts. A scoring log tracks the trend, and average time per question catches pacing problems early.
Publishing alongside
One post per week, drawn from whichever domain Iβm in that week. Each one takes an idea from the material and works out what it means for someone sequencing delivery rather than implementing controls: change management as a control category, vulnerability severity as a backlog input, architecture models as sequencing constraints, identity and access work inside a value stream, audit cadence against planning cadence. A closing post follows the exam.
Writing it weekly keeps me honest about what Iβve actually retained. If I can restate it for a reader in my own terms, I have it.
Full Roadmap
Security+ roadmap
Study
Exam
Publish
Select a bar for detail.
Week 1 β General Security Concepts
Domain 1, 12 percent of the exam. Objectives 1.1 through 1.4.
- 1.1 compare and contrast security control categories and types: technical, managerial, operational, and physical, against preventive, deterrent, detective, corrective, compensating, and directive
- 1.2 fundamental concepts: CIA, non-repudiation, AAA, gap analysis, zero trust control plane and data plane, physical security, and deception technology
- 1.3 change management processes and their security impact: approval, ownership, impact analysis, backout plans, maintenance windows, and version control
- 1.4 cryptographic solutions: PKI, encryption levels, TPM and HSM, obfuscation, hashing, salting, digital signatures, key stretching, and the certificate objectives
Schedule SY0-701 Exam
Book the seat in week 1 so the rest of the plan has a fixed end date.
- Reserve a morning seat at a San Antonio Pearson VUE testing center for the week of October 26
- Confirm identification requirements and testing center policies
- Block the two days prior for final review only
Post 1 β Change Management Is the Security Control
Drawn from objectives 1.1 and 1.3. Control categories and the approval process as program vocabulary.
- 400 to 600 words on why change management sits in a security exam at all, using the 1.3 objective list
- Map approval process, impact analysis, backout plan, and maintenance window onto how a release train already runs
- Use the four control categories and six control types as the framing device rather than a glossary
Week 2 β Threats, Vulnerabilities, and Mitigations
Domain 2, 22 percent of the exam. Objectives 2.1 through 2.5.
- 2.1 threat actors and motivations, and actor attributes of origin, funding, and sophistication
- 2.2 threat vectors and attack surfaces: message, image, file, voice, removable device, unsecure networks, supply chain, and the human and social engineering vectors
- 2.3 vulnerability types across application, OS, web, hardware, virtualization, cloud, supply chain, cryptographic, misconfiguration, mobile, and zero-day
- 2.4 indicators of malicious activity: malware, physical, network, application, cryptographic, and password attacks, plus the indicators list
- 2.5 mitigation techniques: segmentation, access control, allow lists, isolation, patching, encryption, monitoring, least privilege, configuration enforcement, decommissioning, and hardening
Post 2 β Vulnerability Management as a Backlog Problem
Drawn from objectives 2.3 and 2.5. How severity and remediation deadlines get sequenced against feature work.
- 400 to 600 words on severity-driven prioritization colliding with PI planning and committed objectives
- Cover the 2.5 mitigation techniques as the menu a team actually negotiates from
Week 3 β Security Architecture
Domain 3, 18 percent of the exam. Objectives 3.1 through 3.4.
- 3.1 architecture models: cloud responsibility matrix, IaC, serverless, microservices, network infrastructure, on-premises, containerization, ICS and SCADA, RTOS, embedded systems, and high availability, with the considerations list
- 3.2 securing enterprise infrastructure: device placement, security zones, failure modes, network appliances, port security, firewall types, and secure communication including VPN, tunneling, SD-WAN, and SASE
- 3.3 data protection: data types, classifications, data states, sovereignty, and the geographic restriction, encryption, masking, tokenization, and permission restriction methods
- 3.4 resilience and recovery: load balancing versus clustering, hot, warm, and cold sites, platform diversity, capacity planning, testing, backups, and power
- Verify the drafted resilience plan against the RTO, RPO, MTTR, and MTBF definitions as the objectives state them
Domain 1 to 3 Checkpoint Exam
Timed sectional exam limited to the first three domains, taken after Week 3.
- 90 minute timed run restricted to General Security Concepts, Threats, and Architecture
- Target threshold of 80 percent per domain before advancing
- Rebuild flashcard deck from missed items only
Post 3 β Architecture Decisions as Delivery Constraints
Drawn from objectives 3.1 and 3.2. Architecture model tradeoffs read as sequencing constraints.
- 400 to 600 words tying the 3.1 considerations list to delivery sequencing
- Anchor on a toolchain migration into a secured on-prem environment, covering application, security posture, and access model
- Treat security zones and device placement as decisions that set what can be delivered in parallel
Week 4 β Security Operations
Domain 4, 28 percent of the exam and the largest domain. Objectives 4.1 through 4.9.
- 4.1 secure baselines and hardening targets across servers, workstations, cloud infrastructure, ICS and SCADA, embedded systems, and IoT, plus wireless and mobile solutions and application security
- 4.2 asset management across acquisition, assignment, monitoring, and disposal including sanitization, destruction, certification, and data retention
- 4.3 vulnerability management: identification methods, CVSS and CVE, prioritization, response and remediation, validation, and reporting
- 4.4 alerting and monitoring: log aggregation, alert tuning, SCAP, SIEM, DLP, NetFlow, and SNMP traps
- 4.5 enterprise capabilities: firewall rules, IDS and IPS, web filtering, DNS filtering, DMARC, DKIM, SPF, NAC, EDR and XDR
- 4.6 identity and access management: provisioning, federation, SSO via LDAP, OAuth, and SAML, the access control models, multifactor factors and implementations, password concepts, and PAM
- 4.7 automation and orchestration use cases, benefits, and considerations
- 4.8 incident response from preparation through lessons learned, plus root cause analysis, threat hunting, and digital forensics
- 4.9 log data and investigation data sources
Performance Based Question Drills
Focused simulation work on the interactive question formats that open the real exam.
- Practice firewall rule ordering and ACL construction simulations
- Work log correlation exercises identifying attack type from raw entries
- Complete drag and drop control mapping across the four control categories
- Time each PBQ set to under four minutes per question
- Repeat any drill scored below 90 percent after a 48 hour gap
Post 4 β ICAM Inside a Value Stream
Drawn from objective 4.6.
- 400 to 600 words on running ICAM teams inside a value stream without losing PI predictability
- Name policy enforcement point, policy decision point, and policy administration point in NIST 800-207 terms
- Connect identity governance implementation work to the access control models in objective 4.6
Week 5 β Security Program Management and Oversight
Domain 5, 20 percent of the exam. Objectives 5.1 through 5.6.
- 5.1 governance: guidelines, policies, standards, procedures, external considerations, governance structures, and the owner, controller, processor, and custodian roles
- 5.2 risk management: risk identification and assessment types, qualitative versus quantitative analysis, SLE, ALE, and ARO, the risk register, risk appetite, the transfer, accept, avoid, and mitigate strategies, and business impact analysis
- 5.3 third party risk: vendor assessment, right-to-audit clauses, supply chain analysis, and the SLA, MOA, MOU, MSA, WO and SOW, NDA, and BPA agreement types
- 5.4 compliance: reporting, consequences of non-compliance, compliance monitoring, and privacy including data subject, controller versus processor, and right to be forgotten
- 5.5 audits and assessments: attestation, internal and external audits, and the penetration testing types and reconnaissance modes
- 5.6 security awareness practices including phishing campaigns and anomalous behavior recognition
- Build a risk register with likelihood, impact, risk appetite, and treatment decisions
- Drill the SLE, ARO, and ALE formulas until the arithmetic is automatic
Full Length Practice Exam Series
Four full length timed exams under real testing conditions to confirm readiness and pacing.
- Run each exam at 90 minutes with 90 questions and no reference material, on Monday, Wednesday, Friday, and Saturday
- Maintain a scoring log to confirm an upward trend across attempts
- Require 85 percent or better on two consecutive attempts before sitting the real exam
- Simulate testing center conditions with a cleared desk and no interruptions
- Record average time per question to identify pacing risk
Post 5 β Audit Cadence Versus PI Cadence
Drawn from domain 5. Where governance and audit timelines collide with program increment planning.
- 400 to 600 words on risk registers, risk owners, and key risk indicators as program artifacts rather than security artifacts
- Cover what a right-to-audit clause and a vendor questionnaire actually cost a delivery schedule
- Written so the mechanism is the point and the specific compliance regime is only the example
CompTIA Security+ SY0-701 Exam
The certification attempt itself. Maximum of 90 questions, 90 minutes, multiple-choice and performance-based.
- Arrive 30 minutes early with two forms of identification
- Clear performance based questions first, then flag and return as time allows
- Reserve the final 10 minutes for flagged question review
- Re-apply to postings previously skipped for lacking the certification
- Log the three year continuing education renewal date
Post 6 β What an RTE Takes From Security+
Closing post of the cycle, written after the exam result.
- 400 to 600 words on what the certification gives a program role that it does not give an engineer
- Link the five prior posts so the series reads as one body of work
- Frame the credential as a contractual gate cleared, not as the claim itself