CompTIA Security+ — All Questions
Own the complete CompTIA Security+ (SY0-701) guide — PDF + EPUB, $14.99 →
← Back to practice49 questions
Which document outlines acceptable and prohibited uses of an organization's IT systems by employees?
- a.Memorandum of understanding
- b.Acceptable use policy✓
- c.Business impact analysis
- d.Service level agreement
An acceptable use policy (AUP) defines how employees may and may not use company systems and data. It sets expectations and provides grounds for enforcement. Users typically acknowledge it as a condition of access.
Which risk response involves purchasing insurance to shift financial impact to a third party?
- a.Risk acceptance
- b.Risk transference✓
- c.Risk mitigation
- d.Risk avoidance
Risk transference shifts the financial consequences of a risk to another party, commonly through insurance or contracts. The risk still exists, but its impact is borne elsewhere. It is chosen when handling the risk directly is impractical or costly.
Choosing to take no action and knowingly bear a low-level risk is called:
- a.Risk acceptance✓
- b.Risk transference
- c.Risk avoidance
- d.Risk mitigation
Risk acceptance is a conscious decision to tolerate a risk, usually when the cost of controls exceeds the potential loss. It should be formally documented and approved. Acceptance is appropriate for low-impact or low-likelihood risks.
Eliminating a risky activity entirely so the risk no longer applies is known as:
- a.Risk mitigation
- b.Risk avoidance✓
- c.Risk acceptance
- d.Risk transference
Risk avoidance removes the risk by discontinuing the activity that causes it. For example, not deploying a feature that would expose sensitive data. It fully eliminates that risk but may sacrifice a business opportunity.
Which regulation governs the protection of personal data for individuals in the European Union?
- a.SOX
- b.PCI DSS
- c.HIPAA
- d.GDPR✓
The General Data Protection Regulation (GDPR) sets strict requirements for handling the personal data of EU residents. It mandates consent, breach notification, and data subject rights. Non-compliance can result in substantial fines.
Which standard governs the secure handling of payment card data?
- a.HIPAA
- b.PCI DSS✓
- c.FERPA
- d.GDPR
The Payment Card Industry Data Security Standard (PCI DSS) defines controls for organizations that store, process, or transmit cardholder data. It is a contractual requirement rather than a law. Compliance reduces the risk of payment data breaches.
Which US regulation protects the privacy and security of health information?
- a.GDPR
- b.PCI DSS
- c.HIPAA✓
- d.GLBA
The Health Insurance Portability and Accountability Act (HIPAA) sets requirements for safeguarding protected health information. It applies to healthcare providers, plans, and their business associates. Violations can lead to significant penalties.
A calculation of expected yearly loss from a risk, found by multiplying single loss expectancy by annual rate of occurrence, is the:
- a.Annualized loss expectancy✓
- b.Risk appetite
- c.Exposure factor
- d.Residual risk
Annualized loss expectancy (ALE) estimates the expected yearly cost of a risk by multiplying single loss expectancy (SLE) by the annualized rate of occurrence (ARO). It supports cost-benefit decisions about controls. Spending more than the ALE on mitigation is usually not justified.
Which assessment identifies the critical processes and the impact of their disruption to guide continuity planning?
- a.Business impact analysis✓
- b.Vulnerability scan
- c.Gap analysis
- d.Penetration test
A business impact analysis (BIA) identifies critical business functions and quantifies the effect of their disruption over time. It informs RTO and RPO targets and prioritizes recovery. It is a foundation of business continuity planning.
Which agreement defines the measurable service levels a provider must meet, such as uptime guarantees?
- a.Service level agreement✓
- b.BPA
- c.NDA
- d.MOU
A service level agreement (SLA) specifies measurable commitments like availability and response times, with consequences for missing them. It sets clear expectations between provider and customer. Monitoring against the SLA holds the provider accountable.
Which legal agreement prohibits parties from disclosing confidential information they receive?
- a.SLA
- b.AUP
- c.Non-disclosure agreement✓
- d.MOU
A non-disclosure agreement (NDA) legally binds parties to keep shared confidential information secret. It is common when sharing sensitive data with vendors, partners, or employees. Breaching it can result in legal liability.
The residual risk that remains after all controls have been applied should be:
- a.Eliminated completely
- b.Accepted by management✓
- c.Transferred automatically
- d.Ignored entirely
Residual risk is what remains after mitigations are in place, and it cannot usually be reduced to zero. Senior management should formally acknowledge and accept it. This ensures leadership is aware of and owns the remaining exposure.
Which framework provides a widely used structure for managing cybersecurity risk through functions like Identify, Protect, Detect, Respond, and Recover?
- a.NIST Cybersecurity Framework✓
- b.MITRE ATT&CK
- c.PCI DSS
- d.OWASP Top Ten
The NIST Cybersecurity Framework organizes security activities into core functions: Identify, Protect, Detect, Respond, and Recover. It offers a flexible, risk-based approach adaptable to any organization. It helps align security programs with business goals.
Regular training that teaches employees to recognize phishing and follow security policies is called:
- a.Change management
- b.Security awareness training✓
- c.Penetration testing
- d.Vulnerability management
Security awareness training educates users to recognize threats like phishing and to follow safe practices. Because people are a common attack vector, this reduces human-related risk. Ongoing and simulated exercises reinforce the behavior over time.
An asset worth $200,000 would lose 25% of its value in a particular incident. What is the single loss expectancy?
- a.$150,000, representing the residual value of the asset remaining after the incident occurs
- b.$50,000✓
- c.$25,000, calculated by applying an unrelated fixed percentage to the total asset value
- d.$200,000, representing the asset's entire replacement value regardless of the actual loss
Single loss expectancy equals asset value multiplied by the exposure factor, here $200,000 times 0.25, which is $50,000. It estimates the loss from one occurrence of the risk. SLE feeds into the annualized loss expectancy calculation.
If a single loss expectancy is $10,000 and the event is expected to occur twice per year, what is the annualized loss expectancy?
- a.$10,000, which simply repeats the single loss expectancy without factoring in the frequency
- b.$12,000, produced by adding an arbitrary surcharge on top of the single loss expectancy
- c.$5,000, found by dividing the single loss expectancy by the annualized rate of occurrence
- d.$20,000✓
Annualized loss expectancy equals single loss expectancy times the annualized rate of occurrence, here $10,000 times 2, which is $20,000. It expresses expected yearly loss to justify control spending. Spending more than the ALE on mitigation is generally not cost-effective.
A board formally states the broad amount and type of risk the organization is willing to pursue to meet its objectives. Which term describes this statement?
- a.Residual risk
- b.Annualized loss expectancy, which quantifies the expected yearly cost of a specific risk
- c.Risk appetite✓
- d.Risk tolerance
Risk appetite is the overall level and type of risk an organization is willing to accept in pursuit of its goals, set at the strategic level. Risk tolerance is the acceptable deviation for a specific risk. Appetite guides how aggressively the organization operates.
Which document catalogs identified risks along with their likelihood, impact, owner, and mitigation status so they can be tracked over time?
- a.A non-disclosure agreement that legally binds parties to keep shared information secret
- b.An acceptable use policy that defines permitted and prohibited use of company systems
- c.A risk register✓
- d.A service level agreement that defines the measurable performance a vendor must meet
A risk register is the central record of identified risks, capturing likelihood, impact, ownership, and treatment status. It supports ongoing tracking and reporting to leadership. Keeping it current is essential to risk governance.
An organization integrates automated tools that constantly evaluate its risk posture as conditions change, rather than assessing only once a year. Which assessment type is this?
- a.An ad hoc assessment triggered irregularly whenever someone happens to request one
- b.A recurring annual assessment scheduled on a fixed once-per-year calendar cadence
- c.A continuous assessment✓
- d.A one-time assessment performed only at the launch of a single specific project effort
A continuous risk assessment constantly monitors the environment so emerging risks are identified in near real time. It contrasts with point-in-time approaches like annual or ad hoc assessments. Continuous insight supports faster, better-informed decisions.
After identifying a phishing risk, a company deploys email filtering and trains staff to reduce the likelihood and impact. Which risk management strategy is this?
- a.Risk avoidance, in which the risky activity is discontinued so the risk no longer applies
- b.Risk mitigation✓
- c.Risk acceptance, in which the organization knowingly tolerates the risk without any action
- d.Risk transference, in which the financial impact is shifted to an insurer or third party
Risk mitigation applies controls to reduce a risk's likelihood or impact, such as filtering and awareness training against phishing. The risk is lowered but not eliminated. It is the most common strategy for risks the business must live with.
A legacy system cannot meet the encryption standard, so leadership formally documents and approves a temporary deviation with compensating controls. What is this called?
- a.A residual risk calculation quantifying what remains after all the controls are applied
- b.A policy exception with a documented exemption✓
- c.A business impact analysis identifying critical processes and their disruption effects
- d.A service level agreement defining measurable performance commitments from a vendor
A policy exception (exemption) formally authorizes a documented deviation from a standard, usually time-limited and paired with compensating controls. It keeps deviations visible and accountable rather than hidden. Regular review ensures exceptions do not become permanent gaps.
A one-page document states, at a high level, that the organization is committed to protecting the confidentiality of customer data. Which governance artifact is this?
- a.A procedure, which gives the exact step-by-step instructions to accomplish a specific task
- b.A guideline, which offers optional, recommended but non-mandatory best practices to follow
- c.A policy✓
- d.A standard, which specifies mandatory technical requirements such as minimum key lengths
A policy is a high-level statement of management intent and direction, such as a commitment to protect customer data. Standards specify mandatory requirements, procedures give step-by-step instructions, and guidelines are advisory. Together they form the governance hierarchy.
Before modifying a production firewall, an organization requires the change to be requested, reviewed, approved, tested, and documented with a rollback plan. Which process governs this?
- a.Change management✓
- b.A business impact analysis that ranks processes by the effect of their disruption over time
- c.Incident response, which is the process followed only after a security event is detected
- d.Penetration testing, which authorizes simulated attacks to evaluate the real defenses
Change management controls how modifications are proposed, reviewed, approved, tested, and documented, including rollback plans. It reduces the risk of outages and security gaps from unmanaged changes. Backout plans allow safe recovery if a change fails.
Under GDPR, a company decides why and how personal data is processed, while a vendor merely processes that data on the company's instructions. What is the company's role?
- a.The supervisory authority, which is the regulator enforcing the data protection law
- b.The data subject, who is the individual that the personal data actually describes here
- c.The data processor, which only acts on documented instructions given by another party
- d.The data controller✓
Under GDPR, the data controller determines the purposes and means of processing personal data, bearing primary accountability. The processor acts on the controller's instructions. Distinguishing the roles clarifies legal responsibilities and liability.
A customer in the EU formally requests that a company erase all personal data it holds about them. Which GDPR right is being exercised?
- a.The right to erasure, also known as the right to be forgotten✓
- b.The right to rectification, which lets a person correct inaccurate personal data held
- c.The right of access, which lets a person obtain a copy of the data held about them
- d.The right to portability, which lets a person receive their data in a reusable format
The right to erasure, or right to be forgotten, lets individuals request deletion of their personal data under certain conditions. Organizations must have processes to honor valid requests. It is one of several data subject rights GDPR grants.
A retailer wants to shrink the systems subject to payment card security requirements. Which approach most directly reduces PCI DSS scope?
- a.Increasing the frequency of general security awareness training for all staff members
- b.Encrypting all employee laptops that never store or process any cardholder data at all
- c.Purchasing cyber-insurance to transfer the financial impact of a potential data breach
- d.Segmenting the cardholder data environment and tokenizing stored card numbers✓
Segmenting the cardholder data environment and replacing stored card numbers with tokens removes systems from PCI DSS scope, since fewer components touch actual card data. This lowers compliance cost and risk. Scope reduction is a core PCI DSS strategy.
A hospital must implement administrative, physical, and technical safeguards to protect patient health information. Which regulation imposes these categories of safeguards?
- a.GDPR, which governs the personal data of individuals located within the European Union
- b.HIPAA✓
- c.PCI DSS, which governs the protection of payment card data for merchants and processors
- d.SOX, which governs the accuracy and integrity of public companies' financial reporting
HIPAA's Security Rule requires administrative, physical, and technical safeguards to protect electronic protected health information. It applies to covered entities and their business associates. Violations can bring significant civil and criminal penalties.
Which US law was enacted primarily to ensure the accuracy and integrity of public companies' financial reporting and internal controls?
- a.GLBA, which governs how financial institutions protect consumers' nonpublic information
- b.The Sarbanes-Oxley Act✓
- c.GDPR, which regulates the processing of personal data belonging to European Union residents
- d.HIPAA, which sets requirements for safeguarding individuals' protected health information
The Sarbanes-Oxley Act (SOX) mandates controls and executive accountability over financial reporting for public companies. IT controls supporting the integrity of financial data fall in its scope. It arose from major corporate accounting scandals.
Which of the following is a direct consequence an organization may face for failing to meet a mandatory regulatory requirement?
- a.A guaranteed increase in customer trust regardless of the underlying nature of the violation
- b.Regulatory fines and potential loss of operating license✓
- c.The removal of any obligation to notify affected individuals about a reported data breach
- d.An automatic and permanent immunity from all future audits and regulatory examinations
Non-compliance can lead to fines, sanctions, loss of license, contractual penalties, and reputational damage. These consequences make compliance a business priority, not just a legal formality. The specific penalties depend on the regulation and severity.
An organization hires an independent accredited firm to formally examine and attest to its security controls for customers. Which type of assessment is this?
- a.An internal self-assessment performed by the organization's own staff for its own internal use
- b.A tabletop exercise walking a team through a hypothetical incident scenario verbally as a group
- c.A vulnerability scan that enumerates known weaknesses without exploiting any of them at all
- d.An external independent third-party audit✓
An external audit by an independent third party provides objective assurance and attestation that others, such as customers or regulators, can trust. Internal audits and self-assessments are valuable but lack that independence. Independence strengthens credibility of the findings.
After examining a service provider's controls, an independent auditor issues a formal signed statement about their effectiveness for the reporting period. This formal statement is called:
- a.An attestation✓
- b.A memorandum of understanding expressing the non-binding intentions of two separate parties
- c.A statement of work detailing the specific deliverables and tasks of a defined engagement
- d.A business impact analysis identifying critical functions and the effect of their disruption
Attestation is an auditor's formal declaration about the state or effectiveness of controls, such as in a SOC 2 report. It gives third parties confidence without their needing to audit directly. It is a common form of external assurance.
Two independent companies form a partnership and sign a document defining how they will share profits, responsibilities, and liabilities in the venture. Which agreement is this?
- a.A non-disclosure agreement legally binding the parties to protect the shared confidential data
- b.A service level agreement specifying measurable performance targets such as guaranteed uptime
- c.A memorandum of understanding expressing only a non-binding intention to cooperate together
- d.A business partnership agreement✓
A business partnership agreement (BPA) defines the terms between partners, including responsibilities, profit sharing, and liabilities. It differs from an SLA, which sets performance metrics, and an NDA, which protects confidentiality. Choosing the right agreement clarifies obligations.
A company wants contractual authority to inspect a critical vendor's security controls at any time during the relationship. Which provision should be included in the contract?
- a.A non-disclosure clause preventing either party from revealing shared confidential information
- b.A data retention clause specifying how long records must be kept before final disposal
- c.A right-to-audit clause✓
- d.A service level agreement clause specifying only the vendor's guaranteed monthly uptime percentage
A right-to-audit clause grants the customer contractual authority to assess the vendor's controls, providing ongoing assurance. Without it, the customer may have no leverage to verify security. It is a key element of third-party risk management.
Before onboarding a new software supplier, a company reviews the supplier's security questionnaire, financial stability, and history of breaches. This process is best described as:
- a.A tabletop exercise rehearsing the company's response to a hypothetical security incident
- b.A penetration test actively exploiting the supplier's externally facing internet systems
- c.A business impact analysis ranking the company's own internal processes by criticality
- d.Vendor due diligence✓
Vendor due diligence evaluates a prospective third party's security, financial health, and track record before engagement. It informs whether the vendor's risk is acceptable. Ongoing monitoring continues the assessment throughout the relationship.
A policy specifies that customer transaction records are kept for exactly seven years and then securely destroyed. Which governance concept does this implement?
- a.A data retention policy✓
- b.A right-to-audit clause granting authority to inspect a third party's security controls
- c.Data masking, which hides selected characters of a value while showing the remainder
- d.Data classification, which labels information by its sensitivity to guide proper handling
A data retention policy defines how long different data types are kept and when they are disposed of, balancing legal, business, and privacy needs. Keeping data too long increases risk and liability. Secure destruction at end of retention completes the lifecycle.
Which governance structure is typically responsible for setting overall risk direction and holding management accountable for the security program?
- a.External attackers, whose activity indirectly shapes the organization's technical controls
- b.Individual end users, who each independently define the organization's security strategy
- c.The board of directors and executive governance committee✓
- d.The help desk team, which handles day-to-day user support tickets and password resets
Boards and executive committees provide governance oversight, setting risk appetite and holding management accountable for the security program. Governance is a leadership responsibility, not solely a technical one. Clear structures ensure security aligns with business objectives.
A client provides testers with no prior information about the target environment, requiring them to discover everything as a real outside attacker would. Which engagement type is this?
- a.A partially known (gray-box) test, in which testers are given some limited internal information
- b.A tabletop exercise, in which participants only discuss a scenario without touching any systems
- c.An unknown environment (black-box) test✓
- d.A known environment (white-box) test, in which testers receive full internal documentation
An unknown environment, or black-box, penetration test gives the testers no internal knowledge, simulating an external attacker's perspective. Known (white-box) tests share full information, and partially known (gray-box) tests share some. The choice shapes realism and efficiency.
During continuity planning, a team determines that a payroll system must be restored within four hours and can lose at most one hour of data. Which two metrics are these?
- a.Recovery time objective and recovery point objective✓
- b.Single loss expectancy and annualized rate of occurrence, both used in quantitative analysis
- c.Risk appetite and risk tolerance, both describing how much risk the organization will accept
- d.Mean time between failures and mean time to repair, both describing hardware reliability
The recovery time objective (RTO) is the maximum acceptable time to restore a service, and the recovery point objective (RPO) is the maximum tolerable data loss. Here RTO is four hours and RPO is one hour. Both come from the business impact analysis.
Who is ultimately accountable for classifying a dataset and deciding who may access it, even though IT staff physically maintain the storage?
- a.The end user, who consumes the data but has no authority over its classification level
- b.The data custodian, who implements and maintains the controls but does not set the policy
- c.The data processor, who handles the data only on documented instructions from other parties
- d.The data owner✓
The data owner is accountable for a dataset, including its classification and access decisions, even when custodians handle day-to-day storage and protection. Ownership assigns responsibility for the data's proper handling. Custodians and stewards execute the owner's decisions.
Many privacy laws require that when personal data is breached, affected individuals and regulators must be informed within a defined timeframe. What is this obligation called?
- a.A breach notification requirement✓
- b.A memorandum of understanding stating the non-binding intentions of two cooperating parties
- c.A right-to-audit clause granting authority to inspect a partner's internal security controls
- d.A service level agreement defining the measurable performance a provider is required to meet
Breach notification requirements obligate organizations to inform affected individuals and often regulators within set deadlines after a data breach. Laws like GDPR and various state statutes impose these duties. Timely notification is both a legal and trust obligation.
A team rates risks as high, medium, or low based on expert judgment of likelihood and impact rather than precise dollar figures. Which analysis approach is this?
- a.Qualitative analysis✓
- b.A business impact analysis, which identifies critical functions and their disruption effects
- c.Quantitative analysis, which assigns specific monetary values such as SLE and ALE to risks
- d.A penetration test, which actively attempts to exploit the weaknesses in the environment
Qualitative risk analysis uses descriptive ratings like high, medium, and low based on judgment when precise figures are unavailable. It is faster and more subjective than quantitative analysis. Many programs combine both for a fuller picture.
When an employee leaves, the organization follows a checklist to disable accounts, revoke access, and collect equipment. Which governance element defines these steps?
- a.A standard specifying mandatory technical parameters such as the minimum password length
- b.A guideline offering optional, recommended best practices that staff may choose to follow
- c.A high-level policy stating only the organization's general commitment to protecting security
- d.An offboarding procedure✓
An offboarding procedure gives the step-by-step actions for securely separating an employee, such as disabling accounts and recovering assets. Procedures translate policy into concrete, repeatable steps. Prompt offboarding prevents lingering access from becoming a threat.
Before a penetration test begins, both parties sign a document defining the scope, permitted techniques, timing, and systems that are off-limits. What is this document?
- a.A service level agreement that specifies the measurable performance the tester must meet
- b.A business impact analysis that identifies critical processes and their disruption effects
- c.A non-disclosure agreement that solely governs the confidentiality of the shared information
- d.The rules of engagement✓
Rules of engagement define the scope, boundaries, permitted methods, and timing of a penetration test, protecting both parties. They prevent misunderstandings and unintended damage. Clear authorization also keeps the testing legal.
An organization takes reasonable, ongoing steps a prudent entity would take to protect its assets and meet its obligations. Which concept describes this ongoing reasonable action?
- a.Risk acceptance
- b.Separation of duties, which splits a sensitive task among several people to deter any fraud
- c.Due diligence
- d.Due care✓
Due care is the ongoing exercise of reasonable precautions a prudent organization would take, while due diligence is the investigation and research that informs decisions. Both are used to demonstrate responsible governance. Together they help defend against negligence claims.
The security team periodically compiles key risks, their status, and trends into a summary for executives to support decision-making. This activity is called:
- a.Penetration testing, which authorizes simulated attacks to validate the technical defenses
- b.Risk reporting✓
- c.Data masking, which hides portions of sensitive fields displayed within an application interface
- d.Change management, which controls how modifications to systems are approved and then tracked
Risk reporting communicates the current risk landscape, status, and trends to stakeholders such as executives and the board. It enables informed, risk-based decisions and resource allocation. Effective reporting is clear, timely, and tied to business impact.
A bank must protect customers' nonpublic personal financial information and explain its information-sharing practices. Which US law imposes these requirements?
- a.HIPAA, which specifically governs the protection of individuals' protected health information
- b.GDPR, which governs the processing of the personal data of European Union member residents
- c.The Gramm-Leach-Bliley Act✓
- d.PCI DSS, which is a contractual standard governing the handling of payment card data records
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customers' nonpublic personal information and disclose their information-sharing practices. It includes a Safeguards Rule for security controls. It applies specifically to financial services firms.
Why should security policies include a defined schedule for periodic review and revision?
- a.So they stay aligned with evolving threats, technology, regulations, and business needs✓
- b.Because review permanently eliminates all residual risk associated with the policy's subject
- c.Because policies that are reviewed can never afterward be challenged in any court of law
- d.So that employees are no longer required to acknowledge or follow them once they are reviewed
Policies must be reviewed and revised on a schedule so they remain effective as threats, technology, laws, and the business change. Stale policies create gaps and compliance issues. Governance includes ownership and a defined revision cadence.
When selecting a firm to perform an independent security audit, why should the auditor have no financial stake in the outcome?
- a.Because regulators require every external auditor to also sell remediation products to clients
- b.To avoid a conflict of interest that could compromise the audit's objectivity✓
- c.Because a financial stake would make the audit finish faster and cost the client much less
- d.Because auditors with a financial stake are legally required to work at no cost to the client
An auditor with a financial stake in the outcome has a conflict of interest that can bias findings and undermine trust in the results. Independence is essential to a credible, objective assessment. Vendor selection should screen for such conflicts.
To reduce manual effort and errors, an organization implements tools that continuously collect evidence and generate compliance status reports automatically. Which benefit does this automation primarily provide?
- a.It eliminates any need for human oversight of the compliance program from that point going forward
- b.More consistent, timely, and accurate monitoring of compliance status✓
- c.It provides a guarantee that the organization can never experience any future data breach at all
- d.It permanently removes the organization from the scope of every applicable regulation it faces
Automating compliance evidence collection and reporting improves consistency, timeliness, and accuracy while reducing manual burden. It supports continuous rather than point-in-time compliance visibility. Human oversight is still required to interpret and act on results.
How hard is the exam?
CompTIA Security+ (currently exam SY0-701) is up to 90 questions — multiple-choice plus performance-based — in 90 minutes, with a passing score of 750 on a 100-900 scale, a higher bar than A+. The voucher is about $404. Information security analysts earn a median of about $124,910/year (BLS, May 2024) — one of the best-paid entry-level certifications.
- Recommended study hours
- 100-160 hours for most; more if networking fundamentals are new to you.
- Pass rate
- We read CompTIA's own published material in September 2026 and there is no pass rate in it. By stated policy: “it is CompTIA’s policy to not disclose pass rates to any external third party.” The Security+ page publishes the cut score, 750 on a 100-900 scale, and nothing about how many reach it.Source: CompTIA — Exam Development (test policies), on disclosure of pass rates
- Where to focus first
- Security Operations (28%) is the largest domain, followed by Threats, Vulnerabilities & Mitigations (22%) — together half the exam.
Fees and salaries are approximate and change over time. The pass rate above is quoted from the source linked beside it, for the period that source covers — where we have not checked a source, we say so and give no number.