Domain Weighting and an 8-12 Week Study Plan

Key Takeaways

  • SY0-701 domain weights are 12%, 22%, 18%, 28%, and 20% across the five official domains.
  • Security Operations is the largest domain at 28%, so monitoring, hardening, incident response, and vulnerability management need sustained practice.
  • An 8-week plan works for candidates with stronger networking and operations experience; a 12-week plan gives more time for fundamentals and PBQs.
  • Study time should follow both domain weight and personal weakness, not domain weight alone.
  • Practice should become more scenario-heavy in the final third of the plan.
Last updated: April 2026

Official SY0-701 Domain Weighting

DomainNameExam weight
1.0General Security Concepts12%
2.0Threats, Vulnerabilities, and Mitigations22%
3.0Security Architecture18%
4.0Security Operations28%
5.0Security Program Management and Oversight20%

The weighting tells you where points are likely concentrated, but it does not mean the smaller domains are optional. Domain 1 terms appear inside incident, architecture, identity, and risk questions. Weak vocabulary makes high-weight scenario questions harder.

8-Week Study Plan

Use this pace if you already understand basic networking, operating systems, cloud terminology, and IT operations.

WeekPrimary focusOutput
1Domain 1 foundations: CIA, controls, identity terms, cryptography basicsOne-page concept map and control classification drills
2Domain 2 threats: malware, social engineering, application and cloud weaknessesThreat indicator notebook
3Domain 2 mitigations and vulnerability managementRemediation priority drills
4Domain 3 architecture: segmentation, resilience, secure design, data protectionNetwork and cloud design comparison table
5Domain 4 operations: logging, monitoring, hardening, IAM operationsLog interpretation practice set
6Domain 4 incident response, automation, endpoint and network operationsIncident timeline exercises
7Domain 5 governance, risk, compliance, third parties, privacyRisk register and audit evidence drills
8Mixed review, PBQs, timed sets, missed-question repairTwo timed mixed practice sessions and final weak-area list

12-Week Study Plan

Use this pace if Security+ is your first security exam or if networking and command-line operations are still new.

WeeksPrimary focusWhat to slow down and practice
1-2Domain 1 foundationsTerms, control categories, IAM vocabulary, basic cryptography
3-4Domain 2 threats and mitigationsAttack clues, vulnerability scan findings, patch and segmentation choices
5-6Domain 3 architectureSecure network, cloud, identity, resilience, and data designs
7-9Domain 4 operationsLogs, alerts, hardening, incident response, account management
10Domain 5 governance and riskPolicies, risk response, compliance evidence, vendor oversight
11Mixed scenario reviewCompare close answer choices and repair weak domains
12Timed readinessPBQ practice, pacing, sleep schedule, formula-free review

Time Allocation by Weight

If you have 60 total study hours, start with this split and adjust after diagnostics.

DomainWeightApproximate hours
General Security Concepts12%7
Threats, Vulnerabilities, and Mitigations22%13
Security Architecture18%11
Security Operations28%17
Security Program Management and Oversight20%12

Scenario: Adjusting the Plan

A candidate scores well on definitions but misses log questions, vulnerability remediation order, and business impact questions. That candidate should not reread the glossary for another week. A better plan is:

WeaknessAdjustment
Log questionsDaily short sets using authentication, firewall, endpoint, and web server events
Remediation orderPractice "exploitability, exposure, asset value, compensating controls" ranking
Business impactAdd change management, BIA, RTO, RPO, downtime, and exception workflow review

The goal is not to finish pages. The goal is to reduce repeatable mistakes.

Test Your Knowledge

Which SY0-701 domain has the highest official exam weight?

A
B
C
D
Test Your Knowledge

A candidate has 12 weeks and limited networking experience. Which study approach is most appropriate?

A
B
C
D
Test Your KnowledgeMatching

Match each SY0-701 domain to its official weight.

Match each item on the left with the correct item on the right

1
General Security Concepts
2
Threats, Vulnerabilities, and Mitigations
3
Security Architecture
4
Security Operations
5
Security Program Management and Oversight