CompTIA Security+ sample questions with answers
20 free CompTIA Security+ sample questions (10 per exam) across the exam's domains, each with its answer and an explanation. No account needed.
SY0-801 sample questions
CompTIA Security+ (SY0-801), CompTIA.
Question 1
Domain: General Security Concepts
A certificate authority has revoked a certificate. Which protocol lets a client check the status of that single certificate in real time without downloading a complete revocation list?
- CRL
- CSR
- OCSP
- LDAP
Show the answer
Answer: C. OCSP
OCSP (RFC 6960) allows a client to query a responder for the status of a specific certificate. A CRL also conveys revocation, but the client must download and parse the full list published by the CA, which is what the question rules out.
Checked against: https://www.rfc-editor.org/rfc/rfc6960
Question 2
Domain: General Security Concepts
A company mounts signs at its data center entrance stating that the area is under continuous video surveillance and that intruders will be prosecuted. What type of control are the signs themselves?
- Detective
- Deterrent
- Corrective
- Compensating
Show the answer
Answer: B. Deterrent
The signs aim to discourage an attacker from trying in the first place, which is the definition of a deterrent control. They are not detective: the cameras may record events, but a sign on its own identifies nothing that has happened.
Checked against: https://csrc.nist.gov/glossary/term/security_control
Question 3
Domain: Threats, Vulnerabilities, and Attacks
Which system provides a standard identifier, such as CVE-2026-1234, for a publicly known vulnerability?
- CVSS
- CVE
- SCAP
- CWE
Show the answer
Answer: B. CVE
Common Vulnerabilities and Exposures assigns identifiers to publicly disclosed vulnerabilities. CVSS scores severity, and CWE names weakness types rather than specific flaws.
Checked against: https://www.cve.org/About/Overview
Question 4
Domain: Threats, Vulnerabilities, and Attacks
An employee receives a phone call from someone claiming to be from the IT help desk, who says the employee's account is locked and asks for the one-time code just sent to their phone.
Which social engineering technique is being used?
- Smishing
- Tailgating
- Watering hole
- Vishing
Show the answer
Answer: D. Vishing
Vishing is voice-based phishing, where the attacker uses a phone call and a pretext, here the help desk and a locked account, to obtain credentials or codes. Smishing is tempting because an SMS code is involved, but the social engineering itself is delivered by voice call, not by text message.
Checked against: https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks
Question 5
Domain: Security Architecture
A Windows service on several servers needs a domain account whose password rotates automatically and that no person ever signs in with.
Which account type should be used?
- A shared domain admin account
- A group Managed Service Account
- A local administrator account
- An emergency access account
Show the answer
Answer: B. A group Managed Service Account
A gMSA is a domain service account whose password the domain manages and rotates automatically, and no person signs in with it.
Question 6
Domain: Security Architecture
Which architecture model runs application code in short-lived functions where the cloud provider manages the underlying servers and operating system?
- Serverless
- Microservices on dedicated hosts
- Virtual desktop infrastructure
- On-premises clustering
Show the answer
Answer: A. Serverless
In serverless computing the provider manages the servers, runtime and scaling, and the customer supplies function code and configuration. Microservices are a way of structuring an application into small services, but they may still run on servers or containers that the customer manages.
Checked against: https://docs.aws.amazon.com/lambda/latest/dg/welcome.html
Question 7
Domain: Security Operations
A monitoring platform learns typical sign-in volumes for each hour and department, then alerts on deviations instead of using a fixed threshold.
Which AI capability is this?
- Agentic AI
- Chatbot
- AI-augmented baselines
- Predictive analysis
Show the answer
Answer: C. AI-augmented baselines
Learning what normal looks like and flagging deviations replaces static thresholds with AI-augmented baselines. Predictive analysis forecasts future events instead.
Checked against: https://lecbyo.files.cmp.optimizely.com/download/77f3bd3223ac11f180820e495f189928
Question 8
Domain: Security Operations
Solid-state drives that held confidential data are being retired and will not be reused. The organization wants the highest assurance that the data cannot be recovered with laboratory techniques.
Which disposal method is most appropriate?
- Performing a single-pass overwrite with zeros across the whole drive using a disk utility
- Deleting the partitions and reformatting
- Degaussing the drives
- Physically destroying the drives by shredding or disintegration
Show the answer
Answer: D. Physically destroying the drives by shredding or disintegration
Physical destruction corresponds to the Destroy category of NIST SP 800-88 and gives the highest assurance when the media will not be reused. Degaussing is tempting because it works on magnetic media, but it is ineffective on flash-based SSDs, which do not store data magnetically.
Checked against: https://csrc.nist.gov/pubs/sp/800/88/r2/final
Question 9
Domain: Security Operations
A cloud team configures its pipeline so that any infrastructure template that creates a storage bucket without encryption or with public access fails automatically and cannot be deployed.
Which automation use case does this represent?
- Guard rails
- Ticket creation
- Escalation
- User provisioning
Show the answer
Answer: A. Guard rails
Guard rails are automated checks that prevent insecure configurations from being deployed while still letting teams work quickly. Ticket creation is a distractor: it records issues for follow-up but does not stop the insecure deployment.
Checked against: https://csrc.nist.gov/pubs/sp/800/204/d/final
Question 10
Domain: Security Program Management and Oversight
Which model describes an intrusion by its adversary, capability, infrastructure and victim?
- Cyber Kill Chain
- MITRE ATT&CK
- Diamond Model of Intrusion Analysis
- CVSS
Show the answer
Answer: C. Diamond Model of Intrusion Analysis
The Diamond Model links those four features of every intrusion event. The kill chain orders attack stages, and ATT&CK catalogues tactics and techniques.
Checked against: https://attack.mitre.org/
SY0-701 sample questions
CompTIA Security+ (SY0-701), CompTIA.
Question 1
Domain: General Security Concepts
In a zero trust architecture, which component makes the decision to grant, deny or revoke a subject's access to a resource, based on policy and inputs such as threat intelligence?
- Policy enforcement point
- Implicit trust zone
- Policy engine
- Data plane
Show the answer
Answer: C. Policy engine
NIST SP 800-207 describes the policy engine as the component that makes and logs the access decision, which the policy administrator then acts upon. The policy enforcement point is the tempting choice, but it only enables, monitors and terminates the connection according to the decision it receives.
Checked against: https://csrc.nist.gov/pubs/sp/800/207/final
Question 2
Domain: Threats, Vulnerabilities, and Mitigations
Which statement best describes the risk of running hardware that has reached end-of-life?
- The vendor no longer supplies security updates, so newly found vulnerabilities stay unpatched
- The hardware automatically stops functioning on the end-of-life date and can no longer be powered on
- End-of-life hardware cannot be connected to modern networks
- End-of-life status means the device has a known backdoor
Show the answer
Answer: A. The vendor no longer supplies security updates, so newly found vulnerabilities stay unpatched
Once a product is end-of-life, the vendor typically stops releasing firmware and security fixes, so any new vulnerabilities remain exploitable. The hardware usually keeps working normally, which is exactly why such devices often remain in service and become a risk.
Checked against: https://www.cisa.gov/securebydesign
Question 3
Domain: Threats, Vulnerabilities, and Mitigations
An application checks that a file is safe and then opens it, but an attacker swaps the file in the brief interval between the check and the use. What type of vulnerability is this?
- Race condition (time-of-check to time-of-use)
- Buffer overflow
- SQL injection
- Memory leak
Show the answer
Answer: A. Race condition (time-of-check to time-of-use)
A TOCTOU race condition occurs when the state of a resource changes between the time it is checked and the time it is used. A buffer overflow is tempting as another classic application flaw, but it involves writing beyond allocated memory, not a timing window.
Checked against: https://cwe.mitre.org/data/definitions/367.html
Question 4
Domain: Security Architecture
A company's unreleased product formula gives it a competitive advantage and is protected by keeping it confidential rather than by patent. Which data type is this?
- Regulated data
- Public data
- Legal information
- Trade secret
Show the answer
Answer: D. Trade secret
A trade secret is valuable business information that derives its value from being kept secret, such as a formula or process. Regulated data is tempting because it is also sensitive, but that term refers to data such as health or payment data whose handling is governed by law or regulation.
Checked against: https://www.uspto.gov/ip-policy/trade-secret-policy
Question 5
Domain: Security Architecture
A firewall protecting a hospital's patient monitoring network loses power to its inspection module. Management decides that monitoring traffic must keep flowing even if inspection is unavailable.
Which failure mode has management chosen?
- Fail-open
- Fail-closed
- Fail-secure
- Fail-over to passive mode
Show the answer
Answer: A. Fail-open
Fail-open lets traffic continue to pass when the security device fails, prioritizing availability over security. Fail-closed (also called fail-secure) is the opposite: it blocks traffic when the device fails, which would interrupt patient monitoring.
Checked against: https://csrc.nist.gov/glossary/term/fail_safe
Question 6
Domain: Security Operations
During an audit, the security team finds servers on the network that do not appear in the asset inventory and have no assigned owner.
What is the main security risk of these unknown assets?
- They increase software licensing costs and complicate annual vendor license true-up audits
- They slow down the network
- They are unlikely to be patched, monitored or protected by security controls
- They violate the data retention policy
Show the answer
Answer: C. They are unlikely to be patched, monitored or protected by security controls
Assets that are not inventoried or owned are usually missed by patching, monitoring and vulnerability management, creating unmanaged attack surface. Licensing cost is a real concern for asset management, but it is not the primary security risk.
Checked against: https://www.cisecurity.org/controls/inventory-and-control-of-enterprise-assets
Question 7
Domain: Security Operations
A network team wants to know which internal hosts talk to which external IP addresses, how many bytes are transferred and for how long, without storing full packet payloads.
Which data source best meets the requirement?
- Full packet capture
- SNMP traps
- Antivirus logs
- NetFlow or IPFIX flow records
Show the answer
Answer: D. NetFlow or IPFIX flow records
Flow records summarize conversations by source, destination, ports, byte counts and duration without payloads, which suits large-scale traffic analysis. Full packet capture is tempting because it contains everything, but storing payloads is exactly what the team wants to avoid.
Checked against: https://www.rfc-editor.org/rfc/rfc7011
Question 8
Domain: Security Operations
Two vulnerabilities have the same CVSS base score of 8.1. One affects an internet-facing payment server; the other affects an isolated lab machine with no sensitive data.
Which approach should drive the remediation order?
- Fix them in the order the scanner listed them
- Adjust priority using environmental factors such as exposure and asset criticality
- Fix the lab machine first because it is easier
- Treat them identically, because matching base scores mean matching organizational risk
Show the answer
Answer: B. Adjust priority using environmental factors such as exposure and asset criticality
CVSS base scores describe the vulnerability itself, while environmental factors such as exposure and business criticality determine actual risk to the organization. Treating them identically is tempting because the scores match, but it ignores that the payment server is far more exposed and valuable.
Checked against: https://www.first.org/cvss/v4-0/specification-document
Question 9
Domain: Security Program Management and Oversight
During reconnaissance, a tester gathers employee names from the company's website, searches public DNS records and reviews job postings, without sending any traffic to the target's systems beyond normal public browsing.
What type of reconnaissance is this?
- Active reconnaissance
- Passive reconnaissance
- Vulnerability scanning
- Offensive testing
Show the answer
Answer: B. Passive reconnaissance
Passive reconnaissance collects information from public sources without directly probing the target's systems, making it hard to detect. Active reconnaissance is the tempting distractor, but it involves directly interacting with the target, for example port scanning.
Checked against: https://csrc.nist.gov/pubs/sp/800/115/final
Question 10
Domain: Security Program Management and Oversight
A SaaS provider's customers want independent assurance about its controls, so it hires a CPA firm to evaluate how well its controls operated over a 12-month period and issue a report.
What type of assessment is this?
- Internal self-assessment
- Regulatory examination
- Independent third-party audit
- Partially known penetration test
Show the answer
Answer: C. Independent third-party audit
An independent third-party audit, such as a SOC 2 Type II engagement, provides external attestation about controls over a period. A regulatory examination is tempting because it is also external, but it is carried out by a regulator exercising legal authority, not a firm hired by the company.
Checked against: https://www.aicpa-cima.com/topic/audit-assurance/audit-and-assurance-greater-than-soc-2
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
CompTIA Security+ course and practice exam: SY0-801: the exam guide, with the format, cost, pass mark and domains from the vendor.