CompTIA Security+ study plan by domain
Security+ is a common first step into cybersecurity and a requirement for many government and contractor roles. This prompt has your todo.is agent plan the five SY0-701 domains by weight, turn the long acronym list into daily flashcards, and add performance-based question practice that matches what the exam asks.
The prompt
- Make me a CompTIA Security+ study plan for exam [EXAM CODE] on [EXAM DATE]. I can study [WEEKLY HOURS] hours a week and my background is [BACKGROUND]. Plan the weeks by the five domains and their weights from the official exam objectives, with extra time on Security Operations. Send me 15 acronyms a day from the objectives with a one-line meaning, as a CSV I can import into Anki. Add performance-based question practice (firewall rules, log analysis, matching attacks to controls), a practice exam in the last two weeks and a review day after it. Give me an Excel plan and remind me each weekday at [TIME] on Telegram.
What to change
- [EXAM CODE]: Usually "SY0-701". Check the CompTIA site in case a newer version is out.
- [EXAM DATE]: E.g. "May 9".
- [WEEKLY HOURS]: E.g. "8".
- [BACKGROUND]: E.g. "have A+ and work help desk" or "career changer, no IT job".
- [TIME]: E.g. "12:30" for a lunchtime set.
Example result
- CompTIA Security+ (SY0-701): 7 weeks
- Exam: May 9 · 8 h a week · Has A+, works help desk
- Exam basics
- • Up to 90 questions in 90 minutes, multiple choice and performance-based questions
- • Scored 100 to 900, passing score 750
- • Five domains (check the current objectives):
- • General Security Concepts, 12%
- • Threats, Vulnerabilities and Mitigations, 22%
- • Security Architecture, 18%
- • Security Operations, 28%
- • Security Program Management and Oversight, 20%
- Week 1: general concepts
- • CIA triad, AAA, zero trust (control plane and data plane), change management, PKI and certificates, hashing vs encryption
- Week 2: threats
- • Phishing types, malware (ransomware, trojans, rootkits), password attacks, application attacks (SQL injection, XSS, buffer overflow), indicators of compromise
- Week 3: architecture
- • Cloud models and shared responsibility, network segmentation, firewalls (stateful, WAF), VPN types, secure protocols (SSH, HTTPS, SFTP), high availability and backups
- Weeks 4 and 5: security operations
- • Hardening, MDM, wireless security (WPA3, 802.1X), IAM and MFA, SIEM and log review, vulnerability scans, incident response steps (prepare, detect, analyse, contain, eradicate, recover, lessons learned), digital forensics basics
- Week 6: program management
- • Governance, policies, risk analysis (SLE, ARO, ALE), third-party risk, compliance, audits, security awareness
- Week 7: practice
- • Full practice exam on Monday, review Tuesday
- • PBQ drills daily, light acronym review, rest the day before
- PBQ drill sample
- A log shows 400 failed logins from one IP to many usernames in 2 minutes. Identify the attack (password spraying), the control (account lockout policy plus MFA) and where to block it (firewall or IPS rule on that IP).
- Formula to know
- • ALE = SLE × ARO. A $20,000 loss that happens once every 4 years: 20,000 × 0.25 = $5,000 a year.
How to do it with todo.is
- Check your exam code and date, then fill in the prompt.
- Send it to your agent in todo.is or on Telegram.
- You get an Excel plan and an acronym CSV, and a short reminder every weekday.
- After the practice exam, send your score by domain and your agent rebuilds the last week around it.
Tips for a better result
- Learn the acronyms early and a little each day. Questions assume you know them without thinking.
- For "best" or "first" questions, choose the answer that fits the incident response order.
- Read each PBQ carefully, then flag it and come back if it is long. Do not let one PBQ eat 15 minutes.
- If your job requires DoD 8140 compliance, check which exam version your employer needs.
CompTIA Security+ study plan: FAQ
- How long should I study for Security+? With A+ or IT experience, 4 to 8 weeks is common. Without it, plan for 2 to 3 months.
- Is Security+ hard? It is broad rather than deep. The hardest parts for most people are the acronyms and the performance-based questions.
- Do I need A+ first? No, it is not required, but CompTIA recommends some networking and security experience first.
- Can my agent explain practice questions? Yes. Paste the question and your answer, and it explains the right choice and why the others are wrong.
JavaScript is required to use the todo.is app.