dc dotCreds
CompTIA Security+

Security+ Practice Test

Start today's 10-question Security+ set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 221 Verified Questions

Questions updated at Jul 18, 2026, 1:30 PM CDT

Go Pro - One Time Unlock

Unlock the full SY0-701 bank

221 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank on web and iPhone

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 Security+ questions

Use this Security+ practice test to review CompTIA Security+ SY0-701. Questions rotate daily and each explanation links to the source used to validate the answer.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

221 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective 2.1 Threats, vulnerabilities, and mitigations

An attacker discovers a previously unknown vulnerability in a software application that could be exploited to gain unauthorized access. What type of attack is this?

Concept tested:
Question 2 of 10
Objective 1.2 General security concepts

A company's data is compromised, and unauthorized changes have been made to a critical document. Which CIA principle is most directly affected?

Concept tested:
Question 3 of 10
Objective 3.2 Security architecture

Which of the following best describes how network segmentation enhances security?

Concept tested:
Question 4 of 10
Objective 5.2 Security program management and oversight

A security consultant is conducting a risk assessment for a company. They calculate the monetary loss that is expected each time a server goes offline due to power failure, taking into account the cost of lost sales and recovery labor. Which metric does this represent?

Concept tested:
Question 5 of 10
Objective 4.8 Security operations

Which term describes organized actions taken to detect, analyze, contain, eradicate, and recover from a cybersecurity incident?

Concept tested:
Question 6 of 10
Objective 1.3 General security concepts

A high-tech manufacturing competitor attempts to gain access to a firm's proprietary battery design files. The attacker targets the firm's employees with highly customized spear-phishing emails aimed at stealing intellectual property for financial advantage in their own market. Which type of threat actor does this describe?

Concept tested:
Question 7 of 10
Objective 3.3 Security architecture

An IT administrator is tasked with classifying Personally Identifiable Information (PII) to ensure appropriate security controls are applied. Which classification level represents the highest level of sensitivity and requires the most stringent security measures?

Concept tested:
Question 8 of 10
Objective 5.1 Security program management and oversight

A hospital uses an application where access permissions are granted based on the user's role (e.g., Doctors can read/write patient charts, Nurses can read charts and write notes, and Billing clerks can only view billing information). Which access control model is in use?

Concept tested:
Question 9 of 10
Objective 4.7 Security operations

What is a key advantage of automation in security operations regarding cost and governance?

Concept tested:
Question 10 of 10
Objective 2.2 Threats, vulnerabilities, and mitigations

A hospital's computers suddenly display a message stating that all medical databases have been encrypted and will remain inaccessible until a payment is made in cryptocurrency. Which type of malware has infected the hospital network?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 211 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
SY0-701 Pro $4.99 one-time

Unlock all 221 Security+ questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question SY0-701 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

CompTIA Core Trio Bundle $9.99 one-time

Unlock the full entry-level CompTIA stack with A+, Network+, and Security+ in one purchase, with available 50-question PDFs included.

What’s includedA+ Core 1, A+ Core 2, Network+, Security+, Available 50-question PDFs
Cybersecurity Access Bundle $6.99/month

Security, defensive analysis, and network security practice in one monthly unlock.

What’s includedSecurity+, CySA+, Certified Ethical Hacker, CCNA

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full SY0-701 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

221 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 211 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily SY0-701 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Official exam resources

Use these official CompTIA resources alongside the daily practice set. They cover the provider's own exam page, study guide, or prep material.

Need adjacent CompTIA practice pages too? CompTIA practice hub.

Source-backed answer review

The free daily Security+ set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 An attacker discovers a previously unknown vulnerability in a software application that could be exploited to gain unauthorized access. What type of attack is this?

Answer choices

  1. A. SQL Injection
  2. B. Zero-Day Exploit
  3. C. Phishing
  4. D. Man-in-the-Middle

Correct answer

Zero-Day Exploit

a Zero-Day Exploit occurs when an attacker uses a newly discovered vulnerability before the developers can release a patch. This matters because understanding zero-day exploits is crucial for identifying and mitigating security risks before they are widely known.

Wrong-answer review

  • A. SQL Injection: SQL Injection is not correct in this case because the scenario requires Zero-Day Exploit since a Zero-Day Exploit occurs when an attacker uses a newly discovered vulnerability before the developers can release a patch.
  • C. Phishing: Phishing is not correct in this case because the scenario requires Zero-Day Exploit since a Zero-Day Exploit occurs when an attacker uses a newly discovered vulnerability before the developers can release a patch.
  • D. Man-in-the-Middle: Man-in-the-Middle is not correct in this case because the scenario requires Zero-Day Exploit since a Zero-Day Exploit occurs when an attacker uses a newly discovered vulnerability before the developers can release a patch.

Extra learning features

Why candidates miss this

SQL Injection attacks involve manipulating database queries, but the scenario explicitly describes a previously *unknown* vulnerability. The assumption that all attacks involve database interaction, or that an attacker would necessarily target a database, overlooks the broader category of exploits targeting application logic and code flaws; zero-day exploits can manifest in many ways beyond database manipulation. Likely wrong answer: SQL Injection Review focus: OWASP SQL Injection Prevention Cheat Sheet

Objective/domain: Threats, vulnerabilities, and mitigations

Source: Avoiding Social Engineering and Phishing Attacks | CISA

Question 2 A company's data is compromised, and unauthorized changes have been made to a critical document. Which CIA principle is most directly affected?

Answer choices

  1. A. Availability
  2. B. Integrity
  3. C. Authentication
  4. D. Confidentiality

Correct answer

Integrity

Objective/domain: General security concepts

Source: integrity - Glossary | CSRC

Question 3 Which of the following best describes how network segmentation enhances security?

Answer choices

  1. A. It eliminates the need for firewalls and other security measures.
  2. B. It decreases network performance due to increased complexity.
  3. C. It limits the spread of a breach to specific segments, reducing overall impact.
  4. D. It increases the attack surface by creating more entry points.

Correct answer

It limits the spread of a breach to specific segments, reducing overall impact.

Objective/domain: Security architecture

Source: Zero Trust Maturity Model | CISA

Question 4 A security consultant is conducting a risk assessment for a company. They calculate the monetary loss that is expected each time a server goes offline due to power failure, taking into account the cost of lost sales and recovery labor. Which metric does this represent?

Answer choices

  1. A. Single Loss Expectancy (SLE)
  2. B. Annualized Rate of Occurrence (ARO)
  3. C. Annualized Loss Expectancy (ALE)
  4. D. Asset Value (AV)

Correct answer

Single Loss Expectancy (SLE)

Objective/domain: Security program management and oversight

Source: CompTIA Security+ Official Study Guide

Question 5 Which term describes organized actions taken to detect, analyze, contain, eradicate, and recover from a cybersecurity incident?

Answer choices

  1. A. Incident response
  2. B. Vendor onboarding
  3. C. Change freeze
  4. D. Data minimization

Correct answer

Incident response

Objective/domain: Security operations

Source: incident response - NIST CSRC Glossary

Question 6 A high-tech manufacturing competitor attempts to gain access to a firm's proprietary battery design files. The attacker targets the firm's employees with highly customized spear-phishing emails aimed at stealing intellectual property for financial advantage in their own market. Which type of threat actor does this describe?

Answer choices

  1. A. Nation-state actor
  2. B. Hacktivist
  3. C. Competitor/Corporate spy
  4. D. Insider threat

Correct answer

Competitor/Corporate spy

Objective/domain: General security concepts

Source: CompTIA Security+ SY0-701 Objectives

Question 7 An IT administrator is tasked with classifying Personally Identifiable Information (PII) to ensure appropriate security controls are applied. Which classification level represents the highest level of sensitivity and requires the most stringent security measures?

Answer choices

  1. A. Confidential data that requires strict access controls and encryption.
  2. B. Data that can be shared freely without any restrictions.
  3. C. Information that is only relevant to specific departments within an organization.
  4. D. Publicly available data that does not require protection.

Correct answer

Confidential data that requires strict access controls and encryption.

Objective/domain: Security architecture

Source: Guide to Protecting the Confidentiality of PII (NIST SP 800-122)

Question 8 A hospital uses an application where access permissions are granted based on the user's role (e.g., Doctors can read/write patient charts, Nurses can read charts and write notes, and Billing clerks can only view billing information). Which access control model is in use?

Answer choices

  1. A. Discretionary Access Control (DAC)
  2. B. Role-Based Access Control (RBAC)
  3. C. Mandatory Access Control (MAC)
  4. D. Attribute-Based Access Control (ABAC)

Correct answer

Role-Based Access Control (RBAC)

Objective/domain: Security program management and oversight

Source: CompTIA Security+ SY0-701 Objectives

Question 9 What is a key advantage of automation in security operations regarding cost and governance?

Answer choices

  1. A. It increases the speed of system deployment without additional resources
  2. B. It enhances the physical security infrastructure
  3. C. It automates compliance checks, reducing manual errors and saving time
  4. D. It reduces the need for human oversight, thereby lowering costs

Correct answer

It automates compliance checks, reducing manual errors and saving time

Objective/domain: Security operations

Source: What is SOAR? | IBM

Question 10 A hospital's computers suddenly display a message stating that all medical databases have been encrypted and will remain inaccessible until a payment is made in cryptocurrency. Which type of malware has infected the hospital network?

Answer choices

  1. A. Rootkit
  2. B. Ransomware
  3. C. Trojan horse
  4. D. Spyware

Correct answer

Ransomware

Objective/domain: Threats, vulnerabilities, and mitigations

Source: CompTIA Security+ SY0-701 Objectives

Where to go after the daily web set

How are Security+ questions generated?

dotCreds builds Security+ practice questions from public exam objectives and CompTIA exam objectives and source-backed references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start Security+ practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.