Skip to content
CompTIA Security+ Practice iconSY0-701 · Security+ study app

CompTIA Security+ Practice:
SY0-701 study app

Know what to study.
Know why it works.

Learn the concept, practise the decision and return to what needs work. A daily study route across all five Security+ domains.

See how you’ll study
Download on the App StoreGet it on Google Play

iPhone and Android release planned. Store links coming soon.

Layered metallic shield with a lime security boundary and red threat signal
BUILD YOUR SECURITY KNOWLEDGE
Actual Today screen showing a recommended lesson followed by practiceYour next step, ready.
1,284original practice questions
28concept lessons
5SY0-701 domains
Learn → applyexplanations and practical work
A clear next step

How will I study with the app?

Start with a short assessment, then follow a lesson, practise the topic and review what you missed. Your recent answers help choose the next focus.

01LearnBuild the concept
02PractiseApply the decision
03ReviewReturn to the gaps
01

Learn the decision

A principle, a worked example and a quick check before you practise.

Concept lesson explaining the difference between policy, standard and procedure
02

Explain every answer

See why your choice works, why another option falls short and what to remember.

Practice question with an explanation about password and PIN authentication factors
03

Put controls to work

Allow the required connections and block the risky paths in the firewall exercise.

Interactive firewall exercise showing a network diagram and allow or deny choices

Actual app screens with sample study data. Select a screen to view it in full.

See where to focus

What does my progress show?

See the decisions you’ve studied, where your answers are stronger and what still needs attention. Domain views help you choose the next topic.

  • Coverage you can interpret

    Track distinct decisions, so repeated question variants don’t inflate topic coverage.

  • A route that changes with you

    Recent misses and due reviews guide your next session.

  • Review at the right time

    Return to due questions, saved items and topics that need another look.

Practice estimates guide your study. They aren’t official exam scores or a guarantee of passing.

Domain progress screen with a radar chart and separate views for coverage and accuracy
Coverage ≠ accuracySee what you’ve studied and how well you can apply it.
SY0-701 coverage

Which Security+ topics does it cover?

The study route covers the five published SY0-701 domains. The percentages here are official exam weights, rather than your score or progress.

Up to 90questions
90 minutesexam time

The exam combines multiple-choice and performance-based questions.

Read the official SY0-701 objectives ↗
  1. 01

    General Security Concepts

    Controls, identity and cryptography

    12%exam weight
  2. 02

    Threats, Vulnerabilities, and Mitigations

    Attack patterns, weaknesses and defences

    22%exam weight
  3. 03

    Security Architecture

    Networks, data and secure designs

    18%exam weight
  4. 04

    Security Operations

    Monitoring, access and incident response

    28%exam weight
  5. 05

    Security Program Management and Oversight

    Policies, risk and business decisions

    20%exam weight
Start learning here

What do you want to understand next?

Ten free guides with direct answers, worked examples and reasoning checks. Pick the distinction you keep mixing up.

01

What’s the difference between hashing, encryption, and encoding?

The difference between hashing, encryption, and encoding is what each does to data: hashing creates a one-way digest for comparison, encryption protects data with a key, and encoding changes its format so another system can read it. Choose hashing to check integrity, encryption for confidentiality, and encoding for compatibility.

02

What’s the difference between symmetric and asymmetric encryption, and when would I use each?

The difference between symmetric and asymmetric encryption is the keys: symmetric encryption uses the same secret key to encrypt and decrypt, while asymmetric encryption uses a related public and private key pair. Use symmetric encryption for bulk data; use public-key methods for tasks such as secure key establishment, signatures and some encryption workflows.

03

How do I remember the differences between IDS, IPS, SIEM, SOAR, and EDR?

To remember the differences between IDS, IPS, SIEM, SOAR, and EDR, attach a job to each: IDS detects suspicious activity, IPS can block it, SIEM connects events from logs, SOAR runs response workflows, and EDR investigates and responds on endpoints. In a scenario, look for the action and the place it happens.

04

What’s the difference between authentication, authorization, and accounting?

The difference between authentication, authorization, and accounting is the question each answers: authentication checks who you are, authorization decides what you may do, and accounting records your activity. Remember AAA as identity, permission and record. A successful login doesn’t automatically grant access to every file or action.

05

How do common attacks like phishing, smishing, vishing, password spraying, credential stuffing, and brute force differ?

Common attacks differ by how they reach a victim or use credentials: phishing uses deceptive messages, smishing uses texts, and vishing uses voice calls. Password spraying tries a few passwords across many accounts; credential stuffing reuses stolen login pairs; brute-force guessing systematically tries candidates. Identify the delivery channel and the login pattern separately.

06

What ports and protocols do I actually need to memorise for Security+?

For Security+, memorise common service ports together with their purpose and transport: SSH 22, DNS 53, DHCP 67/68, HTTP 80, HTTPS 443, SMTP 25, SMB 445, LDAP 389 and RDP 3389 are a useful starting set. Then learn secure alternatives, monitoring and VPN ports. This is a study shortlist, not a guaranteed exam-only list.

07

How do firewalls, VPNs, proxies, WAFs, and network segmentation work together?

Firewalls, VPNs, proxies, WAFs, and network segmentation work together by controlling different parts of a connection: firewalls enforce traffic rules, VPNs protect a tunnel, proxies mediate requests, WAFs inspect web requests, and segmentation restricts movement between zones. Use them in layers, with each control matched to the traffic and risk it can handle.

08

What’s the difference between vulnerability scanning, penetration testing, threat hunting, and risk assessment?

The difference between vulnerability scanning, penetration testing, threat hunting, and risk assessment is their aim: scanning finds potential weaknesses, penetration testing tries authorised attacks to validate exposure, threat hunting looks for hidden malicious activity, and risk assessment weighs likelihood and business impact. Choose the activity that answers the organisation’s actual question.

09

How do I work out ALE, SLE, ARO, RTO, RPO, MTTR, and MTBF questions?

To work out ALE, SLE, ARO, RTO, RPO, MTTR, and MTBF questions, first separate money, recovery targets and observed times. SLE = asset value × exposure factor; ALE = SLE × ARO. RTO is the target recovery time, RPO the acceptable data-loss window, MTTR average repair or recovery time, and MTBF average operating time between failures.

10

What should I expect from Security+ performance-based questions, and how should I approach them?

For Security+ performance-based questions, expect to apply security knowledge in a task rather than only choose a letter. Approach each PBQ by reading the goal, checking the constraints, examining the supplied evidence and making the smallest correct changes. Practise explaining your decisions, managing time and checking that every requested part is complete.

Browse all Security+ study guides →
Before you choose

What else should I know?

Is this an official CompTIA app?

CompTIA Security+ Practice is an independent study app from Cyber Phoenix LTD. CompTIA and Security+ are trademarks of CompTIA. The app isn’t affiliated with or endorsed by CompTIA.

Does the app explain incorrect answers?

Yes. Practice includes explanations for the correct choice and the alternatives, plus hints when you need help. Concept lessons explain the principle before practice.

Does it include practical exercises?

Yes. The firewall exercise asks you to allow required connections and deny risky paths. It helps you apply network controls; it doesn’t reproduce a live exam question.

Can I download it now?

The iPhone and Android release is planned. Verified App Store and Google Play listing links will appear here when available.

CompTIA Security+ Practice iconCompTIA Security+ Practice

Your next study session
starts with a clear task.

iPhone and Android release planned. While you wait, work through the free study guides above.

Download on the App StoreGet it on Google Play
Choose a free study guide ↑