- SY0-801 Domain 1, General Security Concepts (16%). Objectives 1.1 and 1.2.
- Explain defense in depth, including confidentiality, integrity, and availability (CIA), authentication, authorization, and accounting (AAA), non-repudiation, Zero Trust principles, and least privilege.
- Compare control categories (technical, managerial, physical, and operational) and control types (preventive, deterring, corrective, detective, compensating, and directive).
- Demonstrate how change management affects security, including change advisory board approval, ownership, impact analysis, test results, backout planning, maintenance windows, documentation, and version control.
CompTIA Security+ V8 (SY0-801) Certification Training Course
Get ready for the next version of Security+. CompTIA expects Security+ V8 (SY0-801) to launch on or around November 17, 2026. This course covers the five SY0-801 domains and helps you decide whether to test on SY0-701 or SY0-801.
Prepare for the newest version of Security+ and choose the right exam for your test date.
The CompTIA Security+ V8 (SY0-801) Certification Training Course with Accumentum prepares you for the newest version of CompTIA Security+. CompTIA expects SY0-801 to launch on or around November 17, 2026, and lists English as the exam language. The current exam, SY0-701, stays available in English until June 11, 2027.
CompTIA says V8 offers expanded coverage of areas such as AI-related risks, security operations, and modern environments. The SY0-801 objectives add objective 2.6, Summarize threats and vulnerabilities associated with artificial intelligence (AI) usage, and they place more weight on general security concepts and on threats, vulnerabilities, and attacks than SY0-701 does.
The course follows CompTIA’s five SY0-801 domains: General Security Concepts (16%), Threats, Vulnerabilities, and Attacks (24%), Security Architecture (19%), Security Operations (27%), and Security Program Management and Oversight (14%). Each module maps to one domain, so you can see where your study time goes.
If you are already studying for SY0-701, the transition section and FAQs below explain which exam to take based on your test date. Accumentum’s SY0-701 course page stays available at the current Security+ training page for candidates who plan to test before SY0-701 retires.
Build SY0-801 exam readiness and core cybersecurity skills.
Apply core security concepts
Explain security concepts and controls, including Zero Trust principles, demonstrate how change management affects security, and explain cryptographic solutions such as PKI, certificates, encryption, and hashing.
Recognize threats, including AI risks
Describe threat actors and threat vectors, explain vulnerabilities and attack surfaces, analyze indicators of malicious activity, and summarize threats and vulnerabilities associated with AI usage.
Secure architecture and operations
Compare architecture models across cloud, OT, and on-premises environments, manage the security architecture including Zero Trust architecture, apply mitigating controls, manage identity and access, and use alerting, monitoring, and automation.
Respond, recover, and govern
Summarize incident response, use data and artifacts to support investigations, explain resilience and recovery, and apply governance, risk, third-party risk, compliance, audit, and awareness concepts.
Who Should Attend
- IT professionals who want a vendor-neutral cybersecurity certification and plan to test on or after the SY0-801 launch.
- Systems administrators, network administrators, and help desk staff moving into security roles.
- Security analysts and junior security engineers who want current coverage of AI-related threats, Zero Trust, and cloud, hybrid, and OT environments.
- SY0-701 candidates whose test date falls after SY0-701 retires, or who prefer to study the newer objectives.
Prerequisites
- There are no Accumentum enrollment prerequisites for this course.
- CompTIA lists recommended experience for SY0-801 as a security administrator with two years of hands-on experience.
- Comfort with networking, operating systems, and basic security terms will help you keep pace with the domain material.
- Plan your exam date before you start. Candidates testing before November 17, 2026 can only take SY0-701, so they should use Accumentum’s SY0-701 course instead.
The Security+ V8 training course covers all five SY0-801 domains.
Ten modules follow CompTIA’s published SY0-801 domains and objectives, including objective 2.6 on threats and vulnerabilities associated with AI usage.
Security Concepts, Controls, and Change Management
Cryptographic Solutions
Threats, Threat Actors, and Threat Vectors
Vulnerabilities, Attack Surfaces, and Malicious Activity
Threats and Vulnerabilities in AI Usage
Architecture Models and Infrastructure Security
Data Protection, Resilience, and Recovery
Mitigating Controls, Assets, and Vulnerability Management
Identity, Automation, Incident Response, and Investigations
Security Program Management and Oversight
- SY0-801 Domain 1, General Security Concepts (16%). Objective 1.3.
- Explain public key infrastructure (PKI), including public keys, private keys, and key escrow.
- Describe certificates, including certificate authorities, certificate revocation lists, OCSP, self-signed and third-party certificates, root of trust, certificate signing requests, and wildcard certificates.
- Compare symmetric and asymmetric encryption, encryption levels from full disk to database and record, transport encryption, key exchange, algorithms, and key length.
- Explain digital signatures, salting, obfuscation, and hashing algorithms.
- SY0-801 Domain 2, Threats, Vulnerabilities, and Attacks (24%). Objectives 2.1 to 2.3.
- Explain characteristics of threats and vulnerabilities, including threat feeds, likelihood, impact, CVSS scoring, prioritization, and CVE.
- Describe threat actors such as organized crime, unskilled attackers, hacktivists, insiders, competitors, and state-sponsored actors, along with their motivations and attributes.
- Describe threat vectors and sources, including message, image, attachment, browser, network, remote access, endpoint, supply chain, human, IoT, OT, physical, and signal-based vectors.
- SY0-801 Domain 2, Threats, Vulnerabilities, and Attacks (24%). Objectives 2.4 and 2.5.
- Explain types of vulnerabilities and attack surfaces, such as unsupported and unpatched systems, race conditions, hardcoded secrets, zero-day vulnerabilities, shadow IT, misconfiguration, and large language models.
- Analyze indicators of malicious activity across malware, physical, network, social engineering, application, and credential attacks.
- Recognize indicators of compromise such as hashes, IP addresses, malicious processes, log manipulation, impossible travel, and concurrent sessions.
- SY0-801 Domain 2, Threats, Vulnerabilities, and Attacks (24%). Objective 2.6, which does not appear in the SY0-701 objective list on CompTIA’s V7 page.
- Summarize AI threats such as model manipulation, poisoning, prompt injection, jailbreaking, evasion, session hijacking, and code execution.
- Explain data loss, privacy, bias, explainability, hallucinations, and ethical considerations in AI usage.
- SY0-801 Domain 3, Security Architecture (19%). Objectives 3.1 and 3.2.
- Compare the security implications of architecture models, including cloud (serverless, multicloud, deployment models, and infrastructure as code), OT, on-premises infrastructure, air-gapped networks, microservices, and segmentation.
- Weigh technical and business considerations such as availability, resilience, data sovereignty, data classification, cost, and risk.
- Manage the security architecture with device placement, security zones, Zero Trust architecture, secure communication and access (VPN, tunneling, and Security Service Edge), and identity management.
- SY0-801 Domain 3, Security Architecture (19%). Objectives 3.3 and 3.4.
- Summarize data types, data states (data at rest, data in use, and data in transit), and data classifications.
- Explain methods used to secure data, such as masking, hashing, tokenization, encryption, and deidentification, along with data protection roles and the data management life cycle.
- Explain resilience and recovery, including hot, warm, and cold sites, redundancy, backups and restoration testing, failover testing, disaster recovery, business continuity, and recovery metrics such as RTO and RPO.
- SY0-801 Domain 4, Security Operations (27%). Objectives 4.1 to 4.4.
- Apply mitigating controls such as segmentation, hardening, deception technology, intrusion detection and prevention, firewalls, endpoint detection and response, network access control, and email security (DMARC, SPF, and DKIM).
- Explain the security implications of the asset management life cycle, from planning and acquisition to monitoring and disposal.
- Perform vulnerability management tasks: identification, prioritization, remediation, verification, and reporting.
- Explain alerting and monitoring concepts and tools, including log aggregation, alert tuning, SIEM, NetFlow, syslog, SCAP, and dashboards.
- SY0-801 Domain 4, Security Operations (27%). Objectives 4.5 to 4.8.
- Apply identity and access management concepts, including provisioning, federation, single sign-on, account types, MFA, access control models, and password concepts such as passkeys and passwordless.
- Apply automation and orchestration to secure operations, including automation use cases, guardrails, AI capabilities such as agentic tools and chatbots, and CI/CD workflows.
- Summarize incident response activities: preparation, identification, investigation, containment, eradication and recovery, notification, and post-incident lessons learned and root cause analysis.
- Use log and trace data, data sources, system images, and log-parsing techniques to support a security investigation.
- SY0-801 Domain 5, Security Program Management and Oversight (14%). Objectives 5.1 to 5.6.
- Explain governance, risk, and compliance artifacts: guidelines, standards, procedures, plans, and policies.
- Explain risk management processes, including risk identification, assessment, analysis, the risk register, risk treatment, and business impact analysis.
- Explain third-party risk assessment and management, from vendor selection and agreement types to vendor monitoring and rules of engagement.
- Summarize security compliance, explain audit and assessment activities including penetration testing, and apply security awareness concepts.
Designed for Security+ V8 preparation and a clear move from SY0-701.
Instructor-Led Sessions
Live virtual sessions that walk through each SY0-801 domain and objective with examples from cloud, hybrid, OT, and on-premises environments.
Hands-On Practice
Exercises on controls, cryptography, log and alert review, identity, vulnerability management, and incident response.
Transition Guidance
Clear advice on choosing SY0-701 or SY0-801 based on your test date, and on what changed between the two versions.
Exam Readiness Review
Domain review and practice with multiple choice and performance-based question styles before you schedule.
SY0-701 to SY0-801: exam details and transition.
Security+ SY0-801 Exam Readiness
Accumentum’s Security+ V8 course prepares you for all five SY0-801 domains and helps you pick SY0-701 or SY0-801 based on your test date.

CompTIA expects Security+ V8, exam code SY0-801, to launch on or around November 17, 2026. CompTIA lists English as the exam language. The current version, Security+ V7 (SY0-701), retires in English on June 11, 2027. Japanese, Portuguese, Spanish, and Thai versions of SY0-701 retire on August 13, 2027.
Which exam to take depends on your test date. Before November 17, 2026, SY0-701 is the only option. From November 17, 2026 through June 11, 2027, both versions are available in English, so take the one that matches the objectives you studied. After June 11, 2027, English candidates take SY0-801.
SY0-801 has a maximum of 90 questions, a mix of multiple choice and performance-based items, with a 90 minute time limit and a passing score of 750 on a scale of 100 to 900. That format is the same as SY0-701. CompTIA recommends two years of hands-on experience as a security administrator and lists SY0-801 as ISO 17024 accredited through ANAB.
The domain weights change between versions. General Security Concepts moves from 12% to 16%. Threats, Vulnerabilities, and Mitigations (22%) becomes Threats, Vulnerabilities, and Attacks (24%) and adds objective 2.6 on threats and vulnerabilities associated with AI usage. Security Architecture moves from 18% to 19%, Security Operations from 28% to 27%, and Security Program Management and Oversight from 20% to 14%.
Accumentum is an independent training provider. CompTIA sets and changes exam rules, dates, fees, and policies, so confirm current details on comptia.org before you schedule.
When SY0-801 launches, when SY0-701 retires, which exam to take, what changed between versions, and how Accumentum’s course fits your plan.
Enroll in the CompTIA Security+ V8 Certification Training Course with Accumentum.
Enroll in Accumentum’s CompTIA Security+ V8 (SY0-801) Certification Training Course if you plan to take Security+ on or after November 17, 2026.
You will work through all five SY0-801 domains with an instructor, including objective 2.6 on threats and vulnerabilities associated with AI usage, and practice multiple choice and performance-based question styles before you schedule.
If you plan to test before SY0-701 retires, Accumentum’s SY0-701 course may be the better fit. For course dates and help choosing, visit the registration page or contact Accumentum.
Get ready for Security+ V8 with Accumentum.
Prepare for CompTIA Security+ SY0-801 while you build the security skills every IT and cybersecurity role depends on.