Certification: CompTIA Security+
Exam: SY0-801
Version: Security+ V8
Reading time: 5 minutes
Official source: CompTIA Security+ V8

CompTIA Security+ SY0-801 is the V8 version of the Security+ certification exam. It measures whether you can apply foundational cybersecurity knowledge across threats, architecture, security operations, identity, incident response, risk, compliance, and modern technologies such as artificial intelligence.

As of October 2026, CompTIA lists Security+ V8 as expected to launch on or around November 17, 2026. If you are preparing specifically for SY0-801, use the V8 objectives. Security+ material written for SY0-701 overlaps heavily with V8, but it does not cover the exact same blueprint.

The exam at a glance

Exam detailSecurity+ SY0-801
CertificationCompTIA Security+
Exam codeSY0-801
VersionV8
Expected launchOn or around November 17, 2026
Maximum questions90
Time limit90 minutes
Question typesMultiple-choice and performance-based questions
Passing score750 on a scale of 100–900
Language listed for V8English
Number of domains5
Number of numbered objectives27

The official Security+ V8 page is here:

https://www.comptia.org/en-us/certifications/security/v8/

Check that page before scheduling the exam. CompTIA controls the exam dates, objectives, requirements, and any changes made before or after launch.

What Security+ is testing

Security+ is not an exam about one security product or one job.

You are expected to understand how the major parts of an enterprise security program fit together.

That includes questions such as:

  • How should access to a system be controlled?
  • What does suspicious activity look like in a log?
  • Which security control is appropriate for a particular threat?
  • How should an organization protect sensitive data?
  • What happens when a vulnerability is discovered?
  • How should an incident be investigated and contained?
  • How do backups, failover, and disaster recovery differ?
  • What risks are introduced by cloud services, third parties, mobile devices, and AI?
  • How do policies, audits, risk management, and compliance affect technical security?

That is why simply memorizing acronyms is not enough.

If a question mentions RPO, for example, you need to know that it measures the acceptable amount of data loss in time, how it differs from RTO, and how both values affect a recovery design.

If the question mentions SAML, you need to understand what role it plays in federated authentication and how that differs from technologies such as LDAP and OAuth.

If the question gives you several authentication failures across many user accounts, you may need to recognize password spraying from the pattern rather than from the words "password spraying."

That distinction—recognizing and applying a concept rather than merely recalling its definition—is important throughout SY0-801.

The five SY0-801 domains

The exam is divided into five domains.

DomainWeight
1.0 General Security Concepts16%
2.0 Threats, Vulnerabilities, and Attacks24%
3.0 Security Architecture19%
4.0 Security Operations27%
5.0 Security Program Management and Oversight14%

These percentages tell you approximately how much of the scored exam is associated with each domain.

1.0 General Security Concepts — 16%

This is the foundation.

You need to understand core security principles, security controls, change management, and cryptography.

This includes concepts such as defense in depth, the CIA triad, AAA, Zero Trust, least privilege, certificates, PKI, encryption, hashing, and digital signatures.

2.0 Threats, Vulnerabilities, and Attacks — 24%

This domain focuses on what can go wrong.

You will study threat actors, attack vectors, vulnerabilities, malware, network attacks, application attacks, credential attacks, indicators of compromise, and AI-related threats.

SY0-801 specifically includes security issues involving technologies such as large language models, prompt injection, poisoning, hallucinations, jailbreaking, and other AI risks.

3.0 Security Architecture — 19%

Security Architecture is about designing environments so they are harder to compromise and easier to recover.

It includes cloud and on-premises architectures, segmentation, Zero Trust, secure communications, data protection, redundancy, load balancing, clustering, backups, disaster recovery, business continuity, RTO, RPO, MTTR, and MTBF.

4.0 Security Operations — 27%

This is the largest domain.

It covers the controls and processes used to operate security every day: firewalls, IDS/IPS, WAFs, EDR, XDR, DLP, NAC, vulnerability management, SIEM, IAM, security monitoring, automation, incident response, digital forensics, and investigations.

Expect this domain to require more than definitions. Many of the objectives begin with "Given a scenario", which means you need to know how to choose or apply the correct technology or process.

5.0 Security Program Management and Oversight — 14%

This domain covers the management side of cybersecurity.

You need to understand governance, policies, standards, procedures, risk management, third-party risk, compliance, privacy, audits, penetration testing, security-awareness programs, and quantitative risk calculations.

Pay attention to the verbs in the objectives

CompTIA tells you something about the expected depth of knowledge through the wording of each objective.

Explain

You need to understand the subject well enough to describe how it works and why it matters.

Compare and contrast

You need to know the differences and similarities between technologies or approaches.

Knowing two separate definitions is not enough.

Summarize

You need to understand the important characteristics and relationships of the subject.

Given a scenario

This is the most important wording to notice.

CompTIA can describe a situation and expect you to determine the correct response.

For example:

A company wants to allow administrators elevated permissions only while they are performing an approved maintenance task.

You should be able to recognize that this points toward just-in-time privileged access, even if the question never gives you that term directly.

Performance-based questions

Security+ includes performance-based questions, usually called PBQs.

A PBQ asks you to work through a practical scenario rather than simply select one answer from a normal multiple-choice question.

You might need to interpret:

  • firewall rules;
  • network diagrams;
  • access-control information;
  • security alerts;
  • logs;
  • vulnerability results;
  • authentication events;
  • or system configurations.

A PBQ is testing whether you can use what you know.

Suppose you are shown:

10:02  Login failed: jsmith
10:02  Login failed: bwilliams
10:03  Login failed: adavis
10:03  Login failed: mgarcia
10:04  Login failed: rthomas

If the same password is being attempted across those accounts, you should recognize the pattern as possible password spraying.

The exam does not need to ask:

What is password spraying?

It can show you password spraying and ask what is happening.

That is the level at which you should prepare.

How to know whether you are ready

Do not judge readiness by how familiar the objective list looks.

For every topic in the SY0-801 objectives, ask yourself three questions:

Can I explain what it is without looking it up?

Can I explain how it differs from similar technologies or concepts?

Could I recognize when it should be used—or when it is being attacked—inside a scenario?

If the answer to any of those is no, that topic is not finished.

The remaining five parts of this Tech Little Brawta Security+ series follow the CompTIA blueprint domain by domain:

  1. General Security Concepts
  2. Threats, Vulnerabilities, and Attacks
  3. Security Architecture
  4. Security Operations
  5. Security Program Management and Oversight

Each part teaches the concepts underneath the objectives rather than simply listing them.

By the end of the series, you should be able to work through the official SY0-801 objectives and know exactly what you understand, what you do not understand, and what you still need to review before sitting the exam.

Official CompTIA source

CompTIA Security+ V8

https://www.comptia.org/en-us/certifications/security/v8/