CompTIA Security+ sample questions with answers

20 free CompTIA Security+ sample questions (10 per exam) across the exam's domains, each with its answer and an explanation. No account needed.

SY0-801 sample questions

CompTIA Security+ (SY0-801), CompTIA.

  1. Question 1

    Domain: General Security Concepts

    A certificate authority has revoked a certificate. Which protocol lets a client check the status of that single certificate in real time without downloading a complete revocation list?

    1. CRL
    2. CSR
    3. OCSP
    4. LDAP
    Show the answer

    Answer: C. OCSP

    OCSP (RFC 6960) allows a client to query a responder for the status of a specific certificate. A CRL also conveys revocation, but the client must download and parse the full list published by the CA, which is what the question rules out.

    Checked against: https://www.rfc-editor.org/rfc/rfc6960

  2. Question 2

    Domain: General Security Concepts

    A company mounts signs at its data center entrance stating that the area is under continuous video surveillance and that intruders will be prosecuted. What type of control are the signs themselves?

    1. Detective
    2. Deterrent
    3. Corrective
    4. Compensating
    Show the answer

    Answer: B. Deterrent

    The signs aim to discourage an attacker from trying in the first place, which is the definition of a deterrent control. They are not detective: the cameras may record events, but a sign on its own identifies nothing that has happened.

    Checked against: https://csrc.nist.gov/glossary/term/security_control

  3. Question 3

    Domain: Threats, Vulnerabilities, and Attacks

    Which system provides a standard identifier, such as CVE-2026-1234, for a publicly known vulnerability?

    1. CVSS
    2. CVE
    3. SCAP
    4. CWE
    Show the answer

    Answer: B. CVE

    Common Vulnerabilities and Exposures assigns identifiers to publicly disclosed vulnerabilities. CVSS scores severity, and CWE names weakness types rather than specific flaws.

    Checked against: https://www.cve.org/About/Overview

  4. Question 4

    Domain: Threats, Vulnerabilities, and Attacks

    An employee receives a phone call from someone claiming to be from the IT help desk, who says the employee's account is locked and asks for the one-time code just sent to their phone.

    Which social engineering technique is being used?

    1. Smishing
    2. Tailgating
    3. Watering hole
    4. Vishing
    Show the answer

    Answer: D. Vishing

    Vishing is voice-based phishing, where the attacker uses a phone call and a pretext, here the help desk and a locked account, to obtain credentials or codes. Smishing is tempting because an SMS code is involved, but the social engineering itself is delivered by voice call, not by text message.

    Checked against: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks

  5. Question 5

    Domain: Security Architecture

    A Windows service on several servers needs a domain account whose password rotates automatically and that no person ever signs in with.

    Which account type should be used?

    1. A shared domain admin account
    2. A group Managed Service Account
    3. A local administrator account
    4. An emergency access account
    Show the answer

    Answer: B. A group Managed Service Account

    A gMSA is a domain service account whose password the domain manages and rotates automatically, and no person signs in with it.

    Checked against: https://learn.microsoft.com/en-us/windows-server/identity/ad-ds/manage/group-managed-service-accounts/group-managed-service-accounts/group-managed-service-accounts-overview

  6. Question 6

    Domain: Security Architecture

    Which architecture model runs application code in short-lived functions where the cloud provider manages the underlying servers and operating system?

    1. Serverless
    2. Microservices on dedicated hosts
    3. Virtual desktop infrastructure
    4. On-premises clustering
    Show the answer

    Answer: A. Serverless

    In serverless computing the provider manages the servers, runtime and scaling, and the customer supplies function code and configuration. Microservices are a way of structuring an application into small services, but they may still run on servers or containers that the customer manages.

    Checked against: https://docs.aws.amazon.com/lambda/latest/dg/welcome.html

  7. Question 7

    Domain: Security Operations

    A monitoring platform learns typical sign-in volumes for each hour and department, then alerts on deviations instead of using a fixed threshold.

    Which AI capability is this?

    1. Agentic AI
    2. Chatbot
    3. AI-augmented baselines
    4. Predictive analysis
    Show the answer

    Answer: C. AI-augmented baselines

    Learning what normal looks like and flagging deviations replaces static thresholds with AI-augmented baselines. Predictive analysis forecasts future events instead.

    Checked against: https://lecbyo.files.cmp.optimizely.com/download/77f3bd3223ac11f180820e495f189928

  8. Question 8

    Domain: Security Operations

    Solid-state drives that held confidential data are being retired and will not be reused. The organization wants the highest assurance that the data cannot be recovered with laboratory techniques.

    Which disposal method is most appropriate?

    1. Performing a single-pass overwrite with zeros across the whole drive using a disk utility
    2. Deleting the partitions and reformatting
    3. Degaussing the drives
    4. Physically destroying the drives by shredding or disintegration
    Show the answer

    Answer: D. Physically destroying the drives by shredding or disintegration

    Physical destruction corresponds to the Destroy category of NIST SP 800-88 and gives the highest assurance when the media will not be reused. Degaussing is tempting because it works on magnetic media, but it is ineffective on flash-based SSDs, which do not store data magnetically.

    Checked against: https://csrc.nist.gov/pubs/sp/800/88/r2/final

  9. Question 9

    Domain: Security Operations

    A cloud team configures its pipeline so that any infrastructure template that creates a storage bucket without encryption or with public access fails automatically and cannot be deployed.

    Which automation use case does this represent?

    1. Guard rails
    2. Ticket creation
    3. Escalation
    4. User provisioning
    Show the answer

    Answer: A. Guard rails

    Guard rails are automated checks that prevent insecure configurations from being deployed while still letting teams work quickly. Ticket creation is a distractor: it records issues for follow-up but does not stop the insecure deployment.

    Checked against: https://csrc.nist.gov/pubs/sp/800/204/d/final

  10. Question 10

    Domain: Security Program Management and Oversight

    Which model describes an intrusion by its adversary, capability, infrastructure and victim?

    1. Cyber Kill Chain
    2. MITRE ATT&CK
    3. Diamond Model of Intrusion Analysis
    4. CVSS
    Show the answer

    Answer: C. Diamond Model of Intrusion Analysis

    The Diamond Model links those four features of every intrusion event. The kill chain orders attack stages, and ATT&CK catalogues tactics and techniques.

    Checked against: https://attack.mitre.org/

SY0-701 sample questions

CompTIA Security+ (SY0-701), CompTIA.

  1. Question 1

    Domain: General Security Concepts

    In a zero trust architecture, which component makes the decision to grant, deny or revoke a subject's access to a resource, based on policy and inputs such as threat intelligence?

    1. Policy enforcement point
    2. Implicit trust zone
    3. Policy engine
    4. Data plane
    Show the answer

    Answer: C. Policy engine

    NIST SP 800-207 describes the policy engine as the component that makes and logs the access decision, which the policy administrator then acts upon. The policy enforcement point is the tempting choice, but it only enables, monitors and terminates the connection according to the decision it receives.

    Checked against: https://csrc.nist.gov/pubs/sp/800/207/final

  2. Question 2

    Domain: Threats, Vulnerabilities, and Mitigations

    Which statement best describes the risk of running hardware that has reached end-of-life?

    1. The vendor no longer supplies security updates, so newly found vulnerabilities stay unpatched
    2. The hardware automatically stops functioning on the end-of-life date and can no longer be powered on
    3. End-of-life hardware cannot be connected to modern networks
    4. End-of-life status means the device has a known backdoor
    Show the answer

    Answer: A. The vendor no longer supplies security updates, so newly found vulnerabilities stay unpatched

    Once a product is end-of-life, the vendor typically stops releasing firmware and security fixes, so any new vulnerabilities remain exploitable. The hardware usually keeps working normally, which is exactly why such devices often remain in service and become a risk.

    Checked against: https://www.cisa.gov/securebydesign

  3. Question 3

    Domain: Threats, Vulnerabilities, and Mitigations

    An application checks that a file is safe and then opens it, but an attacker swaps the file in the brief interval between the check and the use. What type of vulnerability is this?

    1. Race condition (time-of-check to time-of-use)
    2. Buffer overflow
    3. SQL injection
    4. Memory leak
    Show the answer

    Answer: A. Race condition (time-of-check to time-of-use)

    A TOCTOU race condition occurs when the state of a resource changes between the time it is checked and the time it is used. A buffer overflow is tempting as another classic application flaw, but it involves writing beyond allocated memory, not a timing window.

    Checked against: https://cwe.mitre.org/data/definitions/367.html

  4. Question 4

    Domain: Security Architecture

    A company's unreleased product formula gives it a competitive advantage and is protected by keeping it confidential rather than by patent. Which data type is this?

    1. Regulated data
    2. Public data
    3. Legal information
    4. Trade secret
    Show the answer

    Answer: D. Trade secret

    A trade secret is valuable business information that derives its value from being kept secret, such as a formula or process. Regulated data is tempting because it is also sensitive, but that term refers to data such as health or payment data whose handling is governed by law or regulation.

    Checked against: https://www.uspto.gov/ip-policy/trade-secret-policy

  5. Question 5

    Domain: Security Architecture

    A firewall protecting a hospital's patient monitoring network loses power to its inspection module. Management decides that monitoring traffic must keep flowing even if inspection is unavailable.

    Which failure mode has management chosen?

    1. Fail-open
    2. Fail-closed
    3. Fail-secure
    4. Fail-over to passive mode
    Show the answer

    Answer: A. Fail-open

    Fail-open lets traffic continue to pass when the security device fails, prioritizing availability over security. Fail-closed (also called fail-secure) is the opposite: it blocks traffic when the device fails, which would interrupt patient monitoring.

    Checked against: https://csrc.nist.gov/glossary/term/fail_safe

  6. Question 6

    Domain: Security Operations

    During an audit, the security team finds servers on the network that do not appear in the asset inventory and have no assigned owner.

    What is the main security risk of these unknown assets?

    1. They increase software licensing costs and complicate annual vendor license true-up audits
    2. They slow down the network
    3. They are unlikely to be patched, monitored or protected by security controls
    4. They violate the data retention policy
    Show the answer

    Answer: C. They are unlikely to be patched, monitored or protected by security controls

    Assets that are not inventoried or owned are usually missed by patching, monitoring and vulnerability management, creating unmanaged attack surface. Licensing cost is a real concern for asset management, but it is not the primary security risk.

    Checked against: https://www.cisecurity.org/controls/inventory-and-control-of-enterprise-assets

  7. Question 7

    Domain: Security Operations

    A network team wants to know which internal hosts talk to which external IP addresses, how many bytes are transferred and for how long, without storing full packet payloads.

    Which data source best meets the requirement?

    1. Full packet capture
    2. SNMP traps
    3. Antivirus logs
    4. NetFlow or IPFIX flow records
    Show the answer

    Answer: D. NetFlow or IPFIX flow records

    Flow records summarize conversations by source, destination, ports, byte counts and duration without payloads, which suits large-scale traffic analysis. Full packet capture is tempting because it contains everything, but storing payloads is exactly what the team wants to avoid.

    Checked against: https://www.rfc-editor.org/rfc/rfc7011

  8. Question 8

    Domain: Security Operations

    Two vulnerabilities have the same CVSS base score of 8.1. One affects an internet-facing payment server; the other affects an isolated lab machine with no sensitive data.

    Which approach should drive the remediation order?

    1. Fix them in the order the scanner listed them
    2. Adjust priority using environmental factors such as exposure and asset criticality
    3. Fix the lab machine first because it is easier
    4. Treat them identically, because matching base scores mean matching organizational risk
    Show the answer

    Answer: B. Adjust priority using environmental factors such as exposure and asset criticality

    CVSS base scores describe the vulnerability itself, while environmental factors such as exposure and business criticality determine actual risk to the organization. Treating them identically is tempting because the scores match, but it ignores that the payment server is far more exposed and valuable.

    Checked against: https://www.first.org/cvss/v4-0/specification-document

  9. Question 9

    Domain: Security Program Management and Oversight

    During reconnaissance, a tester gathers employee names from the company's website, searches public DNS records and reviews job postings, without sending any traffic to the target's systems beyond normal public browsing.

    What type of reconnaissance is this?

    1. Active reconnaissance
    2. Passive reconnaissance
    3. Vulnerability scanning
    4. Offensive testing
    Show the answer

    Answer: B. Passive reconnaissance

    Passive reconnaissance collects information from public sources without directly probing the target's systems, making it hard to detect. Active reconnaissance is the tempting distractor, but it involves directly interacting with the target, for example port scanning.

    Checked against: https://csrc.nist.gov/pubs/sp/800/115/final

  10. Question 10

    Domain: Security Program Management and Oversight

    A SaaS provider's customers want independent assurance about its controls, so it hires a CPA firm to evaluate how well its controls operated over a 12-month period and issue a report.

    What type of assessment is this?

    1. Internal self-assessment
    2. Regulatory examination
    3. Independent third-party audit
    4. Partially known penetration test
    Show the answer

    Answer: C. Independent third-party audit

    An independent third-party audit, such as a SOC 2 Type II engagement, provides external attestation about controls over a period. A regulatory examination is tempting because it is also external, but it is carried out by a regulator exercising legal authority, not a firm hired by the company.

    Checked against: https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2

More practice

A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.

CompTIA Security+ course and practice exam: SY0-801: the exam guide, with the format, cost, pass mark and domains from the vendor.