The 30-day Security+ plan: weighted by what the exam scores
Four weeks, five domains, three practice-exam checkpoints. Built for the version you will sit, SY0-701 or the new SY0-801.

Where the points are
SY0-701 domain weights
SY0-801 (V8) domain weights
The plan
- 1-3
Diagnostic and core concepts
Take a diagnostic practice exam cold to find your weak domain, then learn the CIA triad, AAA, zero trust, change management and the basics of cryptography and PKI.
- 4-10
Threats, attacks and vulnerabilities
Social engineering, malware, application and network attacks, indicators of compromise, and the mitigations for each. On SY0-801, add AI-driven threats and attacks on large language models.
- 11-16
Security architecture
Cloud and on-premises models, segmentation, secure network design, data protection, resilience, backups and recovery. Checkpoint 1: a full timed exam on day 16.
- 17-24
Security operations
The heaviest domain: hardening, identity and access, monitoring, logs and SIEM, vulnerability management, incident response steps and digital forensics basics. Practice reading logs daily.
- 25-27
Program management and risk
Governance, policies, risk math (SLE, ALE, ARO), third-party risk, audits and compliance. Checkpoint 2: a full timed exam on day 27.
- 28-30
Final checkpoint and review
One last unseen timed exam. Review every wrong answer and every option explanation. Book the exam when you are at 80% or higher.
5 free Security+ practice questions
One from each domain. These are extra questions, not taken from the courses.
A retailer reviews stock-room badge logs once a month and has found several after-hours entries weeks after they happened. Management now wants a control that stops unauthorized entry at the moment it is attempted. Which control type should be ADDED?
- Correct. A preventive control, such as a locked door tied to role-based badge rights, blocks the entry when it is attempted.
- The retailer already has a detective control in the monthly log review. Another one would still find entries only after they happen.
- Corrective controls restore or repair after an incident. They would not stop the after-hours entry itself.
- A deterrent, such as a warning sign, may discourage some people, but it does not physically or logically stop a determined person.
An organization already uses app-based push MFA, yet it keeps losing accounts to phishing kits that relay the real sign-in page and capture the session. Which control would MOST effectively stop this technique?
- The kit captures whatever password the user types, so complexity rules make no difference.
- Training helps but a convincing proxy of the real page still fools users; it is not the most effective technical fix.
- Correct. The authenticator checks the site origin cryptographically, so a relay on a different domain never receives a valid assertion.
- SMS codes can be typed into the proxy page and relayed just like push approvals, so they do not stop the relay.
A development team deploys a web application to a PaaS offering. A scan finds a vulnerable open source library bundled inside the application package. Who is responsible for fixing it?
- The provider patches the runtime it supplies, not third-party libraries the customer bundles with its own code.
- OS patching is the provider's job in PaaS, but the flaw is in the application package, not the OS.
- Tenant isolation does not fix vulnerable code. An exploitable library is still exposed through the application.
- Correct. The library ships inside the customer's application package, so updating it is the customer's responsibility.
A water utility needs to protect a set of programmable logic controllers. The vendor states the controllers cannot run endpoint agents and firmware can only be updated during a scheduled annual outage. Which approach BEST reduces risk right now?
- The vendor already stated the controllers cannot run agents, so this is not an option here.
- Updating during production risks an outage of a critical process, which ICS operators must avoid.
- Giving controllers internet access expands exposure and bypasses change control.
- Correct. Segmentation limits who can reach the controllers without touching the fragile devices themselves.
At 2 a.m. an engineer applies an emergency firewall change to block an active attack, without waiting for the weekly change advisory board meeting. According to sound change management practice, what should happen NEXT?
- Correct. Emergency changes are allowed to bypass normal scheduling, but they must still be documented and reviewed after the fact.
- Rolling back would reopen the active attack; emergency processes exist to avoid exactly that.
- No change is exempt from review; skipping it leaves undocumented changes that break baselines and audits.
- The engineer followed a legitimate emergency path, so discipline is not appropriate when it is documented.
Practice exams for your checkpoints
Security+ SY0-801 Exam Prep
540 V8 questions, 6 timed exams.
See the course on Udemy →
FAQ
Can I pass Security+ in 30 days?
Many candidates with some IT background do, studying 1.5 to 2 hours a day. With no IT background, plan for 6 to 10 weeks.
What score should I get on practice exams before booking?
Aim for 80% or higher on full timed practice exams you have not seen before, across all five domains.
Should I follow this plan for SY0-701 or SY0-801?
Both. The five domains are the same; only the weights change. Use the weight table for your version to decide where extra time goes.
How do I prepare for PBQs?
Practice reading exhibits: logs, firewall rules, network diagrams and incident timelines. Speed at reading exhibits matters more than memorizing facts.
More guides: AIF-C01 study guide · RAG vs fine-tuning · Bedrock vs SageMaker AI · AI Practitioner vs Cloud Practitioner · all guides