Skip to main content

Security+ SY0-701

Free Security+ Practice Test (SY0-701)

3 free Security Plus (SY0-701) practice exams to start — no signup required. 1,808 total questions across 75 exams with Campaign Pass.

1,808 questions|75 exams|5 domains
Start Free Practice Test

No signup needed — start immediately

Sign up free to unlock the RPG campaign — battle 210 enemies, collect loot, level up your character. Enter the campaign

12 free Security+ practice questions

  1. General Security Concepts

    Question 1. Before approving a Saturday patch to a credit union's core ledger database, the change advisory board asks the DBA how the team will return the ledger to its last known-good state if the patch fails halfway. Which change management element answers this question?

    1. AA documented maintenance window
    2. BStakeholder sign-off from the finance department
    3. CA backout plan
    4. DAn updated application dependency diagram
    Show the answer

    Correct answer: C. A backout plan

    A backout plan defines the steps to reverse a change and restore the prior working state if the change fails. A maintenance window only sets when the work happens; it says nothing about how to recover.

  2. Threats, Vulnerabilities, and Mitigations

    Question 2. An anonymous collective knocks an oil pipeline operator's public website offline and replaces the homepage with a climate protest banner. No ransom or payment demand is ever made. Which threat actor type and motivation BEST fits this activity?

    1. AHacktivist motivated by philosophical or political beliefs
    2. BOrganized crime motivated by financial gain
    3. CNation-state actor motivated by espionage
    4. DInsider threat motivated by revenge
    Show the answer

    Correct answer: A. Hacktivist motivated by philosophical or political beliefs

    Defacement plus disruption carrying a political message, with no money demanded, is classic hacktivism. Organized crime would normally monetize the attack, for example through extortion or ransom.

  3. Security Architecture

    Question 3. A chain of 40 bakeries is dropping its MPLS circuits that haul all traffic back to head office. Each shop and every remote worker should go straight to SaaS apps, with web filtering, CASB, and zero trust access enforced by a single cloud provider. Which architecture BEST fits?

    1. AA screened subnet at headquarters
    2. BA full mesh of site-to-site IPsec VPN tunnels
    3. CAn on-premises next-generation firewall cluster
    4. DSecure access service edge (SASE)
    Show the answer

    Correct answer: D. Secure access service edge (SASE)

    SASE converges networking and security services such as SWG, CASB, and ZTNA into a cloud-delivered edge that users and sites connect to directly. A site-to-site VPN mesh or an on-premises firewall cluster does not deliver those services to remote workers as one cloud platform.

  4. Security Operations

    Question 4. EDR telemetry shows a finance workstation sending regular beacons to a domain listed in a command-and-control threat feed. Leadership wants the threat stopped but also wants volatile evidence kept for forensics. What should the analyst do NEXT?

    1. AReimage the workstation from the standard gold image
    2. BMove the host to a quarantine VLAN and leave it powered on
    3. CPower off the workstation to halt the malware
    4. DDelete the suspicious scheduled task and keep monitoring
    Show the answer

    Correct answer: B. Move the host to a quarantine VLAN and leave it powered on

    Network isolation contains the threat while keeping RAM contents such as processes and connections available for memory capture. Powering off stops the beaconing but destroys that volatile evidence.

  5. Security Program Management and Oversight

    Question 5. A hospital is finalizing a contract with a cloud dictation vendor. Its CISO insists that the hospital, or an outside assessor acting for it, may inspect the vendor's safeguards at any point during the contract term. Which provision BEST supports this?

    1. AA service-level agreement with an uptime target
    2. BA right-to-audit clause
    3. CA mutual non-disclosure agreement
    4. DA memorandum of understanding
    Show the answer

    Correct answer: B. A right-to-audit clause

    A right-to-audit clause gives the customer contractual permission to assess the vendor's controls directly or through a third party. An SLA defines performance commitments such as availability, not inspection rights.

  6. General Security Concepts

    Question 6. A cloud engineer plants a fake API access key in a configuration file on an internal share. The key grants no permissions, and any attempt to use it immediately raises a high-priority alert in the SIEM. Which deception technique has the engineer deployed?

    1. AHoneypot
    2. BDNS sinkhole
    3. CHoneynet
    4. DHoneytoken
    Show the answer

    Correct answer: D. Honeytoken

    A honeytoken is a fake piece of data, such as a credential or key, whose use signals that an intruder has found and tried it. A honeypot is an entire decoy system rather than a single planted data item.

  7. Threats, Vulnerabilities, and Mitigations

    Question 7. A WAF alert shows one external IP requesting /invoices/print?template=../../../../windows/win.ini against a company's billing portal, followed by several similar requests with extra ../ sequences. Which attack is MOST likely being attempted?

    1. ADirectory traversal
    2. BServer-side request forgery
    3. CCross-site scripting
    4. DLDAP injection
    Show the answer

    Correct answer: A. Directory traversal

    Repeated ../ sequences try to escape the web root and read arbitrary files on the server, which is directory traversal. SSRF would instead supply a URL to make the server send a request to another system.

  8. Security Architecture

    Question 8. An online ticketing company decides its order database must be recoverable to within a few seconds of any outage, because nightly backups would lose a full day of sales. Which approach BEST meets this requirement?

    1. AWeekly full backups with daily differential backups
    2. BA cold site restored from offsite tape
    3. CContinuous replication to a secondary site
    4. DVolume snapshots taken each night at midnight
    Show the answer

    Correct answer: C. Continuous replication to a secondary site

    Continuous replication copies each change to the secondary site almost immediately, so only seconds of data are at risk. Nightly snapshots and daily differentials still leave up to a day of data unprotected.

  9. Security Operations

    Question 9. Fake invoices that appear to come from a company's accounts-payable address keep reaching partners. The company already publishes an SPF record and signs outbound mail with DKIM. What should the mail administrator add so receiving servers reject messages that fail those checks?

    1. AS/MIME certificates for the finance team
    2. BEnforced TLS for SMTP connections
    3. CA secure email gateway attachment sandbox
    4. DA DMARC record with a reject policy
    Show the answer

    Correct answer: D. A DMARC record with a reject policy

    DMARC tells receiving servers what to do when a message fails SPF and DKIM alignment, and a p=reject policy has them refuse it. S/MIME signs and encrypts individual messages but does not stop outsiders from spoofing the domain to other recipients.

  10. Security Program Management and Oversight

    Question 10. A warehouse's inventory server and its data are valued at $200,000. Analysts estimate that a flood would destroy 25 percent of that value and expect such a flood once every two years. What is the annualized loss expectancy (ALE)?

    1. A$25,000
    2. B$50,000
    3. C$100,000
    4. D$12,500
    Show the answer

    Correct answer: A. $25,000

    SLE = $200,000 x 0.25 = $50,000, and ARO = 0.5 (once every two years), so ALE = $50,000 x 0.5 = $25,000. $50,000 is the single loss expectancy, not the annual figure.

  11. Threats, Vulnerabilities, and Mitigations

    Question 11. A hospital's imaging scanner is driven by a PC whose vendor contract voids support if any software, including patches, is added. A scan shows several critical CVEs on that PC. Which mitigation BEST lowers the exposure without breaching the contract?

    1. AApply the missing patches during the next maintenance window
    2. BInstall a host-based antivirus agent on the PC
    3. CIsolate the PC on a dedicated VLAN that only the imaging archive can reach
    4. DAccept the risk and record it in the risk register
    Show the answer

    Correct answer: C. Isolate the PC on a dedicated VLAN that only the imaging archive can reach

    Segmentation is a compensating control: it shrinks who can reach the vulnerable PC without changing any software on it. Patching or adding an agent would breach the vendor contract, and accepting the risk leaves the exposure unchanged.

  12. Security Operations

    Question 12. An access review finds that 14 engineers hold permanent domain admin rights, although they need elevated access only during approved maintenance windows. Which change BEST enforces least privilege while still letting them do their work?

    1. AKeep the admin group but require password rotation every 30 days
    2. BGrant just-in-time elevation through a privileged access management tool
    3. CFederate their logins with SAML-based single sign-on
    4. DMove the engineers into a separate role with the same permanent rights
    Show the answer

    Correct answer: B. Grant just-in-time elevation through a privileged access management tool

    Just-in-time elevation through PAM grants admin rights only for an approved window and then revokes them, which removes standing privilege. Password rotation leaves the permanent admin rights in place.

Start the full free Security+ practice exam

3 free practice exams · 1,808 questions in the Security+ bank

SY0-701 Domain Breakdown

12%General Security Concepts
~69 questions
22%Threats, Vulnerabilities & Mitigations
~127 questions
18%Security Architecture
~104 questions
28%Security Operations
~161 questions
20%Security Program Management & Oversight
~114 questions

How It Works

Step 1

Start a Free Practice Test

Pick a Security+ exam topic and jump into 25 real-format SY0-701 questions. No signup, no paywall.

Step 2

Get Premium AI Deep Dives

Campaign Pass adds AI deep dives with mnemonics. Missed questions auto-generate spaced repetition flashcards.

Step 3

Unlock Battles & Leaderboards

Sign up free to enter the RPG campaign — battle enemies tied to each domain, collect loot, and compete on weekly leaderboards.

Why Prepare with SecuSpark?

Real Exam Format

Single choice, multiple choice, and drag-and-drop questions mirror the actual SY0-701 exam experience.

Premium AI Deep Dives

Get instant explanations with memory mnemonics when you answer incorrectly — learn from mistakes, not just scores.

All 5 Domains Covered

1,808 questions weighted to match real exam distribution across all five SY0-701 domains.

Start Free, No Tricks

No credit card required for the free tier. 3 exams per cert are included. Campaign Pass unlocks all exams, RPG battles, and premium AI study tools.

Security+ Practice Test FAQ

Is this Security+ practice test really free?

Yes — 3 practice exams (75 questions) are completely free. No credit card, no signup wall. Pick a free exam and start immediately. Campaign Pass unlocks all 75 exams and 1,808 questions.

Is "Security Plus" the same as Security+?

Yes. Security Plus, Sec+ and Security+ all mean the CompTIA Security+ certification, currently exam code SY0-701. Every practice test on this page is for that exam, whichever spelling you searched.

What is the Security+ SY0-701 pass rate?

CompTIA doesn't publish official pass rates. Community surveys put it around 70-80% for well-prepared candidates. You need 750 out of 900 to pass.

How does the scoring work?

Each practice exam scores you out of 100%. The real SY0-701 exam uses a scale of 100-900 with a passing score of 750. Our practice exams give you immediate feedback so you know exactly where you stand.

Are performance-based questions (PBQs) included?

Our questions cover the same concepts as PBQs — network diagrams, log analysis, security configs — in multiple-choice format. Solid prep for the real PBQs on exam day.

How many questions should I practice before taking the real exam?

Most successful candidates practice 300-500+ questions and aim for consistent scores above 85% before scheduling the real exam. With 1,808 questions available, you can cover every domain multiple times.

Which Security+ domains are covered?

All five SY0-701 domains: General Security Concepts (12%), Threats & Vulnerabilities (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management (20%).

Start Your Security+ Practice Test Now

3 free exams to start. 1,808 total questions with Campaign Pass. No signup required.

Start Free Practice Test