CompTIA Security+ (SY0-801) — the full course
This course teaches SY0-801, the Security+ exam that launches on or around 17 November 2026. If you are booked on SY0-701, which can be taken until 11 June 2027, use our SY0-701 course instead.
Every lesson and every lab is free to read, mapped one-to-one to CompTIA’s published exam objectives.
Jump to a domain: 1. General Security Concepts · 2. Threats, Vulnerabilities, and Attacks · 3. Security Architecture · 4. Security Operations · 5. Security Program Management and Oversight
What the exam weighs
| Domain | Share of the exam | Lessons here |
|---|---|---|
| 1. General Security Concepts | 16% | 7 |
| 2. Threats, Vulnerabilities, and Attacks | 24% | 11 |
| 3. Security Architecture | 19% | 9 |
| 4. Security Operations | 27% | 13 |
| 5. Security Program Management and Oversight | 14% | 6 |
The curriculum
1. General Security Concepts 16% of the exam
-
02 Defence in depth: CIA, AAA and non-repudiation, stated precisely enough to be useful objective 1.1 part single
-
05 PKI and certificates, and the key management that decides whether any of it works objective 1.3 part single
-
06 Encryption: algorithms, key length, key exchange, and where to apply it objective 1.3 part single
2. Threats, Vulnerabilities, and Attacks 24% of the exam
-
01 Characterising threats and vulnerabilities: intelligence, scoring and what to fix first objective 2.1 part single
-
03 Threat vectors: messages, attachments, networks, remote access and the supply chain objective 2.3 part single
-
04 Threat vectors: browsers, endpoints, people, IoT and OT, physical access and radio objective 2.3 part single
-
06 Attack surfaces: systems, credentials, devices, identity providers and exposed data objective 2.4 part single
-
07 Social engineering: phishing in all its forms, impersonation and deepfakes objective 2.5 part single
3. Security Architecture 19% of the exam
-
02 Operational technology, air gaps, segmentation and infrastructure as code objective 3.1 part single
-
04 Secure communication and access: VPNs, tunnels, SSE and out-of-band management objective 3.2 part single
4. Security Operations 27% of the exam
-
02 Mobile device management, application security, sandboxing and deception objective 4.1 part single
-
03 Firewalls, intrusion detection and prevention, and choosing the network control objective 4.1 part single
-
11 The incident response process, and the preparation that decides the outcome objective 4.7 part single
-
12 Threat hunting, digital forensics, root cause and the post-incident report objective 4.7 part single
5. Security Program Management and Oversight 14% of the exam
-
01 Policies, standards, procedures, plans and guidelines, and the difference between them objective 5.1 part single
-
03 Third-party risk: selecting a vendor, the agreement, and monitoring after the ink dries objective 5.3 part single
Supplementary not examined — background reading
18 of the 47 lessons have an audio episode so far, and each plays in the lesson itself — there is nothing extra to sign up for.
The episodes are also a podcast: listen on Spotify.