SY0-801 — CompTIA Security+ V8 Study Plan

A practical 7-day, 14-day, 30-day, and 60/90-day study plan for CompTIA Security+ V8 (SY0-801) candidates.

Study Plan orientation

This Study Plan is for candidates preparing for the real CompTIA Security+ V8 (SY0-801) exam from CompTIA. It is designed to turn your remaining study time into a practical schedule: diagnostic practice, objective-by-objective review, scenario drills, missed-question repair, timed mocks, and final-week consolidation.

Use the official CompTIA exam objectives as your source of truth. The planning buckets below are for organizing your preparation, not a replacement for the official objective list.

Which plan should you use?

Time remainingBest fitMain goalMock exam timingWhat to avoid
7 daysYou already studied and need final reviewClose weak areas and improve exam timing1 timed mock early or midweek, then targeted reviewStarting large new courses
14 daysYou know some material but have gapsFocused coverage plus two rounds of timed practiceDiagnostic on Day 1, mocks around Days 7 and 13Passive reading without question review
30 daysBalanced preparationCover all major objective areas and build recallWeekly timed practice, full mock near the endSaving practice questions until the final week
60 daysFull preparation at moderate paceLearn, drill, lab, and review with repetitionDiagnostic early, mocks in final thirdMoving on before missed questions are repaired
90 daysFull preparation at lighter paceBuild strong fundamentals and long-term retentionDiagnostic early, periodic section quizzes, final mocksOver-studying familiar topics while avoiding weak ones

Core preparation buckets for SY0-801

Use these buckets to organize your calendar. Map each one back to the official CompTIA Security+ V8 (SY0-801) objectives as you study.

BucketWhat to practiceExample review tasks
Threats, attacks, and vulnerabilitiesAttack types, threat actors, malware, social engineering, vulnerability conceptsIdentify likely attack from scenario wording; match vulnerability to mitigation
Secure architecture and designNetwork segmentation, secure cloud concepts, resilience, zero trust ideas, hardeningChoose controls for a business scenario; compare compensating controls
Identity, access, and authenticationIAM, MFA, authorization, account lifecycle, privileged accessDecide least-privilege access; compare authentication and authorization controls
Cryptography and data protectionEncryption uses, hashing, certificates, PKI concepts, data statesPick correct protection for data at rest, in transit, or in use
Network, endpoint, and application securityFirewalls, secure protocols, endpoint controls, application security basicsInterpret rule intent; choose secure protocol or endpoint mitigation
Security operations and monitoringLogging, SIEM concepts, alert triage, vulnerability management, change controlRead short log excerpts; decide next operational step
Incident response and forensics basicsPreparation, detection, containment, eradication, recovery, lessons learnedChoose FIRST or BEST response in an incident scenario
Governance, risk, and compliancePolicies, risk terms, security awareness, third-party risk, business continuityMap control to risk; distinguish policy, standard, procedure, and guideline

Daily practice rhythm

Use one of these rhythms based on your available time. A shorter, consistent block is better than occasional unfocused cramming.

Available timeDaily structureBest use
30 minutes10 min flash review, 15 min questions, 5 min error logMaintenance day or final-week refresh
60 minutes15 min concept review, 30 min questions, 15 min missed-question repairStandard weekday session
90 minutes25 min objective review, 40 min mixed questions, 25 min explanations and notesMain study block
2 hours30 min review, 45 min domain drill, 30 min scenario/PBQ-style practice, 15 min error logWeekend or accelerated prep
3+ hoursTwo 90-minute blocks with a break; one learning block and one practice blockFull prep day or mock review day

The daily loop

  1. Start with retrieval. Before reading, write or say what you remember about the topic.
  2. Review one narrow objective area. Keep the scope small enough to finish.
  3. Answer practice questions. Include scenario wording such as BEST, FIRST, MOST likely, and LEAST.
  4. Review every miss and every lucky guess. Do not only check the correct answer.
  5. Update your weak-area list. Keep it short and actionable.
  6. End with a 5-minute recap. Record what you will review tomorrow.

Diagnostic-first practice

Take a diagnostic before building the rest of your schedule. The purpose is not to predict your official result; it is to locate weak areas.

Diagnostic stepActionOutput
1. Take a mixed quizUse a broad set of SY0-801-style questions across objectivesBaseline strengths and weaknesses
2. Mark confidenceLabel each answer: sure, unsure, guessedSeparates knowledge gaps from test-taking issues
3. Categorize missesUse the missed-question method belowRepair list
4. Pick top 3 weak areasChoose only the highest-impact gaps firstStudy priorities for the next 3-5 days
5. Retest narrowlyDrill only those weak areasEvidence that the gap is closing

Missed-question review method

Missed-question review is where most score improvement happens. Treat each miss as a defect to repair.

Log columnWhat to write
DateWhen you missed it
TopicExample: IAM, incident response, cryptography, cloud security
Question typeDefinition, scenario, log interpretation, control selection, PBQ-style
Why I missed itKnowledge gap, misread wording, confused terms, rushed, changed correct answer
Correct ruleOne sentence explaining the concept
Wrong-answer trapWhy the tempting wrong option was wrong
Recheck date24 hours later, then 3-7 days later

Common Security+ miss patterns

Miss patternFix
Confusing similar controlsBuild comparison cards: preventive vs detective, technical vs administrative, compensating vs corrective
Missing the word FIRST or BESTUnderline the action word before reading answer choices
Choosing the strongest technical control when the scenario asks for business fitIdentify constraints: cost, risk, compliance, availability, least privilege
Memorizing acronyms without use casesAdd one real use case and one distractor for each acronym
Weak incident response orderPractice short incident timelines and decide the next step
Weak log or alert interpretationReview small samples of authentication, firewall, endpoint, and web events

Hands-on and scenario review

Security+ is not only vocabulary. Schedule hands-on concept review so terms connect to real operational decisions.

AreaPractical review activity
IAMTrace a user lifecycle: onboarding, role change, privileged access, offboarding
MFA and authenticationCompare phishing-resistant, possession-based, knowledge-based, and biometric factors
Network securitySketch a segmented network and place firewalls, IDS/IPS, VPN, jump hosts, and management access
Cloud securityMap shared responsibility, IAM, encryption, logging, network controls, and governance decisions
Vulnerability managementWalk through discovery, prioritization, remediation, exception handling, and verification
Incident responseCreate a one-page playbook for malware, compromised credentials, and data exposure
Logging and monitoringPractice identifying source, destination, user, event type, severity, and likely next step
Cryptography and PKIDiagram certificate issuance, trust, revocation concepts, hashing, and encryption use cases
Governance and riskMatch policies, standards, procedures, risk register items, and awareness training examples

Timed mock exam strategy

Do not use full timed mocks too early if you have not reviewed the objectives. Do use them early enough to fix weaknesses.

StagePractice typePurpose
Start of planUntimed diagnostic or mixed quizFind weak areas
Middle of planTimed section setsBuild pace within topic areas
Final thirdFull timed mockPractice endurance, pacing, and scenario reading
Final weekLimited timed practice plus reviewConfirm readiness without exhausting yourself
Final 24 hoursLight recall onlyKeep confidence and reduce mistakes

How to review a timed mock

Review passWhat to do
Pass 1: TimingIdentify sections where you rushed, stalled, or over-reviewed
Pass 2: MissesAdd every miss to the error log
Pass 3: GuessesReview correct answers you guessed; they are still weak areas
Pass 4: Objective mappingMap misses back to official objectives
Pass 5: RetestDrill weak objectives within 24-48 hours

7-day final review plan

Use this if your exam is one week away. The goal is not to relearn everything. The goal is to stabilize recall, repair weak areas, and avoid avoidable mistakes.

DayFocusStudy actionsPractice actions
1Diagnostic and triageTake a mixed diagnostic; map misses to objectivesBuild top 5 weak-area list
2Threats and vulnerabilitiesReview attacks, malware, social engineering, vulnerability concepts40-60 targeted questions
3Architecture, IAM, and secure designReview segmentation, zero trust concepts, access control, cloud security basicsScenario drills and control-selection questions
4Security operations and incident responseReview logs, monitoring, alert triage, containment, recoveryTimed section set; incident-response questions
5Crypto, data protection, and governanceReview PKI concepts, encryption use cases, risk, policies, compliance languageMixed quiz; repair misses
6Timed mock and remediationTake one timed mock or large timed setSpend more time reviewing than testing
7Light final reviewAcronyms, weak notes, process order, common trapsNo heavy new material; rest and logistics

7-day rules

  • Stop adding large new resources after Day 5.
  • Do not take a full mock late on Day 7.
  • Review your missed-question log every day.
  • Prioritize weak high-frequency concepts over obscure details.
  • Practice reading the full question stem before looking at answers.
  • Prepare exam-day logistics the day before, not the morning of the exam.

14-day focused plan

Use this if you have two weeks and need a structured, high-yield review.

DayFocusTasks
1DiagnosticMixed diagnostic; create error log; rank weak buckets
2Threat landscapeAttacks, threat actors, social engineering, malware, indicators
3Vulnerabilities and remediationVulnerability lifecycle, patching, scanning concepts, compensating controls
4Network and infrastructure securitySegmentation, firewalls, IDS/IPS, secure protocols, remote access
5IAM and authenticationAccount lifecycle, MFA, authorization, privileged access, federation concepts
6Cryptography and data securityEncryption use cases, hashing, PKI, certificates, data classification
7Timed mock 1Full timed practice or large timed set; deep review
8Mock repair dayRe-study top weak areas from mock; retest narrowly
9Cloud, virtualization, mobile, and endpoint securityShared responsibility, hardening, endpoint protection, secure configuration
10Security operationsMonitoring, logging, SIEM concepts, vulnerability management, change control
11Incident response and forensics basicsResponse phases, evidence handling concepts, communication, lessons learned
12Governance, risk, and compliancePolicies, risk treatment, third-party risk, awareness, continuity concepts
13Timed mock 2Timed practice; focus on pacing and question discipline
14Final consolidationMissed-question log, acronyms, weak diagrams, light review only

14-day daily targets

ActivityTarget
Objective review1-2 focused areas per day
Practice questions40-80 per day, depending on schedule
Missed-question repairSame day, before moving on
Acronym review10-15 minutes daily
Scenario practiceAt least every other day
RestProtect sleep in the final 3 nights

30-day balanced plan

Use this if you want a realistic month-long schedule with enough time for learning, practice, and correction.

Weekly structure

WeekGoalMain study focusPractice focus
1Build baseline and cover fundamentalsThreats, vulnerabilities, security principles, core controlsDiagnostic plus targeted quizzes
2Secure architecture and implementationNetwork security, IAM, cloud, endpoint, application securityScenario drills and control selection
3Operations, incident response, and riskLogging, monitoring, vulnerability management, IR, governanceTimed section sets
4Final integrationWeak areas, mixed review, exam pacingFull timed mock and final remediation

30-day calendar

Day rangeFocusActions
Days 1-2Diagnostic and setupTake diagnostic; organize official objectives; start error log
Days 3-5Threats and attacksReview attack types, malware, social engineering, indicators; drill questions
Days 6-7Vulnerabilities and remediationReview vulnerability management, scanning concepts, patching, compensating controls
Days 8-10Network and architectureSegmentation, secure protocols, remote access, resilience, secure design
Days 11-13IAM and authenticationLeast privilege, MFA, account lifecycle, privileged access, federation concepts
Day 14Weekly reviewTimed section set; repair weak areas
Days 15-17Cloud, endpoint, and application securityShared responsibility, hardening, secure configurations, application concepts
Days 18-20Cryptography and data protectionEncryption, hashing, PKI, certificates, data classification and handling
Day 21Timed practiceLarge timed mixed set; deep review
Days 22-24Security operationsLogging, monitoring, alert triage, SIEM concepts, vulnerability operations
Days 25-26Incident responseResponse phases, containment choices, recovery, lessons learned
Day 27Governance and riskPolicies, standards, risk terms, third-party risk, awareness, continuity
Day 28Full timed mockSimulate exam conditions as closely as your practice platform allows
Day 29Mock repairRe-study only missed and guessed topics; retest weak areas
Day 30Final reviewAcronyms, error log, process order, light mixed practice

30-day pacing rule

By the end of each week, produce a short evidence list:

EvidenceExample
Objectives reviewed“IAM account lifecycle, MFA, least privilege”
Weak areas repaired“Stopped confusing hashing and encryption use cases”
Remaining risks“Need more incident response FIRST-step practice”
Next week’s priority“Timed scenario questions under pressure”

60/90-day full preparation path

Use this if you are starting earlier or want stronger fundamentals. The 60-day version moves faster; the 90-day version adds more review, lab-style reinforcement, and spaced repetition.

Phase plan

Phase60-day timing90-day timingGoalOutput
1. Setup and diagnosticDays 1-3Week 1Understand baseline and gather materialsDiagnostic report and objective checklist
2. FoundationsDays 4-14Weeks 2-3Build core security vocabulary and conceptsNotes, acronyms, first error log
3. Technical controlsDays 15-30Weeks 4-6Learn networks, IAM, cloud, endpoint, crypto, data protectionDiagrams and scenario drill results
4. Operations and responseDays 31-42Weeks 7-9Practice monitoring, vulnerability management, IR, and governancePlaybooks and timed section sets
5. IntegrationDays 43-52Weeks 10-11Mix domains and improve decision-makingMixed practice and weak-area ranking
6. Final readinessDays 53-60Weeks 12-13Timed mocks, repair, final reviewReadiness checklist and final error-log review

60-day weekly schedule

WeekFocusPractice
1Diagnostic, exam objectives, study systemMixed diagnostic; create error log
2Threats, attacks, vulnerabilitiesTargeted quizzes; compare similar attacks
3Secure architecture and network controlsScenario drills; draw secure network layouts
4IAM, authentication, authorizationLeast-privilege and access lifecycle questions
5Cloud, endpoint, mobile, and application securityControl-selection questions; hardening review
6Cryptography and data protectionUse-case drills for encryption, hashing, PKI, data states
7Security operations and monitoringLog interpretation; vulnerability management workflow
8Incident response, governance, and riskIR order questions; risk and policy comparison
9Mixed timed practiceFull mock or large timed sets; repair misses
Final daysWeak-area sprintError log, acronyms, final readiness checks

90-day weekly schedule

WeekFocusPractice
1Setup, objectives, diagnosticBaseline quiz and study calendar
2Security principles and threat overviewShort daily quizzes
3Attacks, vulnerabilities, and remediationScenario drills and comparison notes
4Network security and secure protocolsDiagramming and control placement
5Secure architecture, resilience, and cloud conceptsArchitecture scenario questions
6IAM, authentication, authorizationLeast-privilege and account lifecycle drills
7Endpoint, mobile, and application securityHardening and secure configuration review
8Cryptography, PKI, and data protectionUse-case and terminology drills
9Security operations and monitoringLogs, alerts, SIEM concepts, vulnerability workflow
10Incident response and forensics conceptsTimeline and FIRST-step practice
11Governance, risk, compliance, and continuityPolicy/risk matching exercises
12Mixed timed practice and mock reviewFull timed mock or large timed sets
13Final weak-area sprintError log, retesting, light final review

Weekly review checklist

At the end of each week, answer these questions honestly.

QuestionIf the answer is no
Did I review every missed question?Schedule a repair block before new material
Can I explain why the wrong answers were wrong?Re-read explanations and make comparison notes
Did I practice scenarios, not just definitions?Add BEST/FIRST/MOST likely question sets
Did I touch weak areas more than comfortable areas?Rebalance the next week
Did I use the official objectives as a checklist?Map your notes and misses back to objectives
Did I do at least one timed set?Add timing practice before the next full mock

Final-week rules

RuleWhy it matters
Stop adding major new resources 3-5 days before the examNew material can create anxiety without improving readiness
Review misses before reviewing highlightsMisses show actual risk
Use short timed sets, not endless full mocksYou need accuracy and stamina, not exhaustion
Keep an acronym sheetSecurity+ wording often depends on recognizing abbreviations quickly
Practice question disciplineRead the last sentence, identify BEST/FIRST/LEAST, then evaluate answers
Sleep and logistics are part of prepFatigue causes misreads and second-guessing

Exam-readiness checks

You are closer to ready when most of these are true:

  • You can map your remaining weak areas to specific official SY0-801 objectives.
  • Your practice results are stable across mixed question sets, not only familiar topic quizzes.
  • You can explain missed questions without rereading the full lesson.
  • You can handle scenario questions that ask for the BEST, FIRST, MOST likely, or LEAST appropriate answer.
  • You can compare similar controls and choose based on business constraints.
  • You can read simple security events, logs, alerts, or diagrams and decide the likely next step.
  • You have reviewed all guessed answers from your timed mocks.
  • You are no longer discovering large new topic areas in the final few days.
  • You have a short final-review list, not a full course to redo.

What to do next

Pick the plan that matches your remaining time, take a diagnostic or mixed practice set, and build your first weak-area list. Then follow the daily loop: review one focused objective area, answer SY0-801-style practice questions, repair every miss, and retest weak topics until they improve.

Browse Certification Practice Tests by Exam Family