The V8 draft is not a renumbering. It renames Domain 2, redistributes the weights, and introduces roughly twenty terms absent from SY0-701 material — passkeys, quishing, BIMI, living-off-the-land tooling, canary accounts, secrets scanning, alert tuning, break-glass access, agentic AI, ransomware negotiation and behavioural risk scoring among them.
Every exam revision produces the same two claims: that nothing much changed, and that everything changed. Both are wrong here, and the way to settle it is not to argue about the structure but to read the vocabulary.
Structure moves modestly between SY0-701 and the V8 draft. One domain is renamed, the weights shift, and twenty-eight objectives become twenty-seven. If that were all, a lightly edited V7 book would cover the exam.
It is not all. The draft's 849 sub-points contain roughly twenty terms that a 2023-era guide has no reason to mention, because in 2023 several of them did not exist as exam concepts. Those terms are the difference between a book written for this exam and a book reissued for it — and they are what this guide lists, objective by objective.
Domain 2 is renamed: "Threats, Vulnerabilities, and Mitigations" in V7 becomes "Threats, Vulnerabilities, and Attacks" in the V8 draft. The other four keep their names — General Security Concepts, Security Architecture, Security Operations, and Security Program Management and Oversight.
The weights redistribute across those five domains, and the objective count drops from twenty-eight to twenty-seven, spread three, six, four, eight and six.
What did not move deserves saying, because secondhand commentary frequently gets it wrong: threat actors are still in 2.1 and architecture still opens at 3.1. No large topic jumped domains between versions.
The draft distributes the exam as follows. Security Operations remains the heaviest domain by some distance, and Threats gains ground on the previous version.
| Domain | V8 draft weight | Objectives |
|---|---|---|
| 1.0 General Security Concepts | 16% | 3 |
| 2.0 Threats, Vulnerabilities, and Attacks | 24% | 6 |
| 3.0 Security Architecture | 19% | 4 |
| 4.0 Security Operations | 27% | 8 |
| 5.0 Security Program Management and Oversight | 14% | 6 |
This is the useful part. Each of these appears in the V8 draft and in no SY0-701 material, because most of them entered mainstream security practice after the previous exam was written. If your study guide does not teach them, it was not written for this exam.
Authentication is where the change is most visible. Passkeys and passwordless authentication arrive in the identity and access objectives, and they bring their own exam-relevant nuance rather than being a synonym for multi-factor. Break-glass emergency access, just-in-time privilege elevation, time-of-day access models and monitoring for compromised credentials sit alongside them.
Social engineering picks up two delivery routes that did not exist in the older material: quishing — phishing delivered through a QR code — and RCS as a message vector. Email authentication gains BIMI, taught alongside DMARC, SPF and DKIM rather than instead of them.
Operations gains the vocabulary of a working SOC rather than a textbook one: alert tuning, secrets scanning, canary accounts, endpoint posture and compliance checking, and living-off-the-land tooling as an attacker technique rather than a footnote.
The objective numbers matter more than the terms themselves, because they tell you which chapter of any guide should be teaching them — and let you check a book's index against the exam it claims to cover.
| Term | Objective | Why it is new |
|---|---|---|
| Passkeys, passwordless | 4.5 | Syncable authenticators changed the authentication model after SY0-701 was written |
| Quishing (QR-code phishing) | 2.5 | A delivery route that became mainstream after the previous exam |
| RCS as a message vector | 2.3 | Rich messaging replaced SMS as an attack surface |
| Living-off-the-land tools | 2.3 | Named as a technique rather than left implicit |
| BIMI (with DMARC, SPF, DKIM) | 4.1 | Email authentication gained a fourth component |
| Canary accounts, secrets scanning | 4.1 | Detection practice that moved from mature SOCs into the syllabus |
| Alert tuning | 4.4 | Recognises that alert volume, not alert absence, is the operational problem |
| Break-glass access, JIT elevation | 4.5 | Privilege management shifted from standing access to time-bounded access |
| Agentic AI, AI-augmented baselines | 4.6 | AI enters operations as scope, not as a mention |
| Ransomware negotiation | 4.7 | An incident-response step with no equivalent in the NIST sequence |
| Behavioural risk scoring | 5.6 | Human risk measured rather than asserted |
| Backup immutability | 3.4 | Ransomware changed what a backup has to survive |
Artificial intelligence stops being a mention and becomes scope. The draft puts large language model risk into the threat objectives and puts agentic AI, chatbots, predictive analytics and AI-augmented baselines into security operations. A guide that gives AI a sidebar has not covered this; a guide that gives it chapters has.
And Domain 5 asks for arithmetic rather than definitions. Single loss expectancy, annualised rate of occurrence and annualised loss expectancy are listed explicitly under business-level considerations. SLE is asset value multiplied by exposure factor; ALE is SLE multiplied by ARO. Expect to compute a figure and then decide what it means, not to recognise a definition.
There is a third change worth naming even though it is not vocabulary: incident response gains negotiation with ransomware operators as a step, alongside notification of stakeholders, customers and law enforcement. Candidates who learned the four-phase NIST cycle will find the exam's own sequence differs, and the exam's sequence is the one being tested.
The draft marks the number of questions and the exam duration as to be determined. We will not print figures CompTIA has not published, and any source giving you "90 questions in 90 minutes" for SY0-801 has copied them from V7.
The passing score is published and does carry across: 750 on a scale of 100 to 900. So do the question types — multiple-choice and performance-based.
Everything above is drawn from a draft. CompTIA revises drafts, and the version number displayed on the download page has not always matched the version declared inside the file. Download the current objectives before you schedule and check them against whatever you are studying from.
It is a poor substitute. The new vocabulary is not a glossary appended to old material — passkeys change how the authentication objectives are taught, and the AI objectives change what security operations covers. The terms are the visible symptom, not the whole change.
Twenty-seven objectives across the five domains, distributed three, six, four, eight and six, breaking down into 849 individual sub-points in the draft. SY0-701 had twenty-eight objectives.
Not substantially. Threat actors remain in 2.1 and architecture still opens at 3.1. Claims that whole topics jumped domains between the versions do not hold up against the two objective lists.
CompTIA publishes weights at the domain level, not per topic, so we will not invent a percentage. What is certain from the draft: AI risk appears in the threat objectives and AI-assisted operations appear in Domain 4, which carries the largest weight of the five.
No. They are draft objectives published for review, and CompTIA revises them. When Security+ V8 disappears from the exams-under-development page, the final version exists — verify against it before you schedule.
Rules change. Where a figure or a procedure can move, the issuing agency’s current published instructions win over anything here.