1.0 General Security Concepts — 12%
This domain establishes the language used everywhere else: categories and functions of controls, fundamental security principles, zero-trust ideas, change management, and core cryptographic concepts. It is smaller by weight, but weakness here makes later questions harder because architecture, operations, and governance assume you can distinguish preventive from detective controls, confidentiality from integrity, authentication from authorization, and hashing from encryption.
Study priority: build contrast tables for concepts that look similar, then practice choosing the property a scenario actually requires. For cryptography, connect certificates, digital signatures, hashing, key use, encryption, and non-repudiation to the problem they solve instead of memorizing isolated definitions.
2.0 Threats, Vulnerabilities, and Mitigations — 22%
This domain follows the path from threat to weakness to observable behavior to mitigation. Learn how social engineering, malware, application flaws, misconfiguration, exposed services, supply-chain weaknesses, and identity abuse create risk. Then pair them with controls that reduce likelihood, limit exploitation, detect activity, or reduce impact. A threat name without an attack path is fragile knowledge.
Study priority: for each threat family, record the precondition, likely evidence, immediate defensive action, and longer-term mitigation. When two controls are both valid, ask which one addresses the stated root cause or current stage rather than which one sounds more sophisticated.
3.0 Security Architecture — 18%
Architecture questions connect trust boundaries, segmentation, resilience, cloud responsibility, data protection, availability, embedded environments, and secure design. The exam often rewards designs that reduce blast radius, establish identity close to the resource, protect sensitive data throughout its lifecycle, and avoid unnecessary single dependencies. Architecture is where many individual controls become a defensible system.
Study priority: draw small diagrams. Mark users, workloads, data, trust zones, control points, dependencies, and failure paths. Then ask what happens if one component is compromised or unavailable. That habit makes segmentation, high availability, cloud models, secure protocols, data protection, and recovery choices easier to reason about.
4.0 Security Operations — 28%
Security Operations is the largest domain and the day-to-day execution layer: secure baselines, hardening, identity operations, vulnerability management, monitoring, endpoint controls, automation, backups, incident response, evidence, and recovery. Many questions are sequences rather than definitions. You need to recognize what has already happened and choose the next defensible action without skipping required validation or damaging evidence.
Study priority: practice workflows. For a vulnerability, move from discovery to validation, prioritization, ownership, remediation, verification, and exception handling. For an incident, move from preparation and detection through analysis, containment, eradication, recovery, and lessons learned while preserving the information required for investigation and follow-up.
5.0 Security Program Management and Oversight — 20%
This domain covers the management system around the controls: governance, policy, risk, third-party relationships, compliance, audits, awareness, data roles, and continuous oversight. Technical learners sometimes under-study it because the material feels less hands-on, but the exam can distinguish between implementing a control and proving that an organization assigned ownership, accepted residual risk, documented an exception, or established evidence for review.
Study priority: attach an owner, evidence artifact, review trigger, and escalation path to each governance concept. Know the difference between policy and procedure, risk identification and risk treatment, due diligence and ongoing monitoring, compliance obligations and security best practice, and awareness activity versus measurable behavior change.