CompTIA Security+ (SY0-701) Resources — Official Docs, Frameworks, Tools & Labs

A curated, blueprint-aligned list for SY0-701: official CompTIA pages, security frameworks (NIST/ISO/CIS), OWASP & MITRE, cloud/shared-responsibility guides, crypto/PKI references, incident response/forensics, and vetted open-source tools and lab ideas.

Use this page as your launchpad. Pair it with the Syllabus, Cheatsheet, and Practice.


CompTIA official


Core frameworks & references (GRC)


Threats, testing & intel


Identity & access (IAM)


Crypto, TLS & PKI


Cloud & container security


Operations, IR & forensics


Email, web & DNS protections


Tools you should recognize (open-source or free tiers)


Safe hands-on labs (free or low-cost)

  • Blue-team mini-SOC: 2–3 VMs (Linux + Windows) with a syslog stack (ELK) and sample logs; practice detection → triage → IR decisions.
  • Web app & WAF practice: Run OWASP Juice Shop in a container; test input validation and see WAF rule effects (in a lab only).
  • TLS/PKI drill: Generate a test CA, issue a leaf cert, enable OCSP stapling on a lab web server, and validate in a browser/openssl s_client.
  • IAM/SSO walkthrough: Configure a simple SAML/OIDC integration using a free developer IdP and a demo app; practice MFA and role/attribute mappings.
  • Cloud posture sandbox: Create a trial project; practice least-privilege roles, storage encryption, and scanning for misconfigurations.

Always follow laws, ROE, and ethics. Keep testing in isolated labs only.


Study funnel (pair these with your plan)

  • Syllabus: domain-by-domain objectives → Open
  • Cheatsheet: high-yield contrasts & pickers → Open
  • Practice: timed drills & full mocks → Start
  • Overview: format, pacing, and 3–5 week plan → Read