Two learners seen from behind working at code screens

FREESELF-PACEDCOMPTIA

CompTIA Security+ Study Hub

Cybersecurity fundamentals across five domains — threats, architecture, implementation, operations, and governance. Full 90-question timed exam, 150+ flashcards, per-domain objective drills, 12-week plan.

Exam Domains

The 5 domains on the SY0-701 exam, with their weight on the test. Each has its own objectives page, flashcard deck, and drill in the hub.

D1 · General Security Concepts

Exam weight 12%

Security controls and categories, the CIA triad, zero trust, physical security, change management, and cryptographic solutions such as PKI, encryption, hashing, and certificates.

D2 · Threats, Vulnerabilities & Mitigations

Exam weight 22%

Threat actors and motivations, attack surfaces and vectors, vulnerability types, indicators of malicious activity, and the mitigation techniques that counter them.

D3 · Security Architecture

Exam weight 18%

Architecture models including cloud, on-premises, and hybrid, secure enterprise infrastructure, data protection strategies, and resilience and recovery design.

D4 · Security Operations

Exam weight 28%

Securing computing resources, asset and vulnerability management, monitoring, identity and access management, automation, incident response, and using data sources in investigations.

D5 · Security Program Management

Exam weight 20%

Security governance, risk management, third-party risk, compliance, audits and assessments, and security awareness practices.

What's Inside This Hub

Everything is free and built from the official exam outline.

Domain Breakdowns

Every SY0-701 domain decomposed into objectives with weights, key terms, and exam-day focus areas.

178 Flashcards

Flip, tag as known or review, shuffle, and track progress. Your session survives a refresh.

90-Question Practice Exam

Timed, with a question navigator, flags, auto-save resume, and per-question explanations with a domain breakdown of your score.

Objective Drills

Per-domain timed drills to isolate weak domains, plus an AI-generated targeted drill for members.

12-Week Study Plan

Checkable weekly milestones, daily hour targets, and a final-week sprint. Copy-to-clipboard export.

Cheat Sheet & Resources

Printable one-page reference for the final week, plus vetted books, courses, labs, and practice-exam vendors.

Sample Flashcards

Five of the 178 cards in the hub. Tap a card to see the answer.

CIA Triad

Confidentiality, Integrity, Availability — the foundational model for information security. Plus authenticity and non-repudiation in expanded models.

Confidentiality

Ensuring information is accessible only to those authorized to have access. Enforced via encryption, access controls, and need-to-know.

Phishing

Email-based social engineering using deceptive messages to trick recipients into revealing credentials, clicking malicious links, or downloading malware.

Spear Phishing

Targeted phishing aimed at a specific individual or organization, using personalized info to increase credibility and success rate.

IaaS

Infrastructure as a Service — cloud model where the provider supplies VMs, storage, and networking; the customer manages the OS and everything above.

Sample Practice Questions

Two of the 90 questions in the timed practice exam. Every question has an explanation like these.

An organization wants to ensure that a former employee cannot deny sending a particular email after their termination. Which security principle is most directly addressed?

A) Confidentiality B) Integrity C) Non-repudiation D) Availability Correct answer: C. Non-repudiation provides assurance that a party cannot deny the validity of an action they performed. Digital signatures and detailed logging are the primary mechanisms.

An attacker registers the domain 'paypa1.com' (with a numeral 1) hoping users will mistype the legitimate domain. What attack is this?

A) DNS poisoning B) Pharming C) Typosquatting D) Watering hole attack Correct answer: C. Typosquatting (also called URL hijacking) registers domains that look similar to legitimate ones to capture mistyped traffic. DNS poisoning corrupts resolver caches, pharming redirects via compromised DNS or hosts file, and watering hole attacks compromise sites the target group already visits.

How to Use This Hub

The path most learners follow. Move at your own pace.

  1. Domains

    Read the domain breakdowns and note the exam weights.

  2. Flashcards

    Work each deck until every card is tagged known.

  3. Practice

    Take the timed exam, review explanations, then drill weak domains.

  4. Final Week

    Follow the sprint in the study plan and print the cheat sheet.

CompTIA Security+ FAQ

Is this hub free?

Yes. VetTech Learning Hub is free with no paywall. A free account is optional and unlocks the AI exam tutor, which runs on your own AI provider key.

Can I get instructor support?

Yes. Ask about veteran cohorts, which pair the study hub with instructor-led sessions, labs, mentoring, and career support.

Are exam fees included?

Exam fees are set by the credential vendor and paid to their testing provider. We prepare you and help you schedule.

Start CompTIA Security+ Today

Open the free study hub now, or talk with us about cohorts, mentoring, and career support.