Prepia
All posts

IT & Cybersecurity · 7 min read

Security+ SY0-701: what actually changed, domain by domain

CompTIA cut a domain, rebalanced the weights, and quietly rewrote what “threats” means. Here’s the delta that matters for your prep.

SY0-701 isn't a cosmetic refresh. CompTIA collapsed six domains into five, moved a quarter of the exam's weight into operations, and rewrote the threat landscape around how attacks actually arrive in 2026 — supply chain, identity, and cloud misconfiguration rather than parking-lot USB drops.

If you built your prep around a 601-era course, most of it still applies. But “mostly” is where points die. Here's the delta, domain by domain, and what to do about it.

The new shape of the exam

The 601's six domains are gone. The 701 tests five, and the weights tell you where CompTIA thinks the job went: Security Operations is now the single biggest slice of the exam, and governance grew from an afterthought into a fifth of your score.

SY0-701 domains and weights
DomainWhat moved
1. General Security Concepts (12%)New umbrella for fundamentals: CIA, zero trust, change management, cryptography basics. Mostly relocated 601 material, tested at a gentler depth.
2. Threats, Vulnerabilities & Mitigations (22%)Slimmer than the 601's 24% attack domain. Fewer named malware species to memorize; more on threat actors, supply chain, and mitigation choice.
3. Security Architecture (18%)Absorbed most of the old Implementation domain. Cloud, hybrid, and IaC scenarios replaced a chunk of the on-prem appliance trivia.
4. Security Operations (28%)The big winner — up from 16%. Monitoring, hardening, identity lifecycle, incident response, and log-reading scenarios dominate the exam.
5. Program Management & Oversight (20%)Governance, risk, compliance, and third-party risk, expanded from 14% and asked more concretely than the old GRC word salad.

What “threats” means now

The 601 wanted taxonomy: which attack is this, pick the label. The 701 wants judgment: given this actor and this environment, which mitigation actually helps? You'll see fewer questions naming obscure malware families and more pairing a scenario with the least-bad control.

  • Zero trust moved from buzzword to testable model — know the control plane vs. data plane split and where policy decisions happen.
  • Supply chain and third-party compromise show up in both Domain 2 and Domain 5; expect vendor-risk questions wearing a technical costume.
  • Deprecated-but-listed tech (WEP, unsalted MD5) appears mostly as the wrong answer. Recognizing legacy is now the skill, not configuring it.

What this means for your prep

Rebalance your hours to match the weights. Two of every five practice sessions should be operations-flavored: reading logs, ordering incident-response steps, picking hardening moves. If your question bank still splits evenly across six old domains, it's training you for the wrong exam.

One thing didn't change: performance-based questions still front-load the exam and still eat clock. Flag them, clear the multiple choice, come back. The 701 rewards the same calm it always did — it just asks you to be calm about different things.