Security+ Practice Questions with Explanations
These original Security+ questions test control selection and security judgment across the SY0-701 domains.
- Each explanation identifies the best response and why the distractors are weaker.
- Use them as learning exercises, not a prediction of your official score: CompTIA's 750 passing score is scaled, and a short practice set cannot reproduce the exam's content mix or scoring.
On this page9 sections
- Question 1: suspicious authentication
- Question 2: prioritize a vulnerability
- Question 3: protect data at rest
- Question 4: contain a compromised endpoint
- Question 5: supplier access
- Question 6: recover safely after ransomware
- Question 7: policy and standard
- Question 8: choose the right control
- How to use these questions
The questions below are independently written study exercises based on current Security+ subject areas. They do not reproduce CompTIA exam questions or claim to match a live performance-based interface. Read each prompt, choose an answer before looking at the explanation, and identify the clue that determines the best action. The goal is to practice transferable reasoning.
Question 1: suspicious authentication
An employee reports repeated multifactor prompts they did not initiate. Authentication logs show a successful login shortly afterward from an unfamiliar location. What is the best immediate response?
- Temporarily disable the account or restrict access, revoke active sessions, and preserve the authentication records for investigation.
- Delete the account and all associated logs so the attacker cannot use them.
- Ignore the event because the login included the correct password.
- Rebuild all company endpoints before confirming any device was affected.
Answer: A. The repeated prompts and unfamiliar successful login provide evidence of possible credential compromise. Restricting access and revoking sessions reduce immediate risk, while preserved logs support investigation and scope determination. Deleting records destroys evidence. A valid password does not prove the legitimate user performed the login. Rebuilding every endpoint is disproportionate without evidence of endpoint compromise.
The decision principle is to contain credible risk while keeping the investigation possible. A longer-term response may include password reset, authentication review, endpoint checks, and user coaching, but the question asks for the immediate response.
Question 2: prioritize a vulnerability
A scan reports two findings. Finding A has a critical severity label on an isolated test server with no sensitive data. Finding B is rated high on a public customer portal that stores personal information and has a known exploit path. Which should the security team prioritize first?
- Finding A, because the word critical always outranks every other factor.
- Finding B, after validating exposure and available mitigations, because public reachability and sensitive data increase its risk context.
- Neither, because a scan result should never drive remediation.
- Finding A, because test systems cannot be isolated from production risks.
Answer: B. Severity labels help triage but do not replace context. A public-facing service with sensitive data and an exploitable path may present greater immediate exposure than an isolated test host. The team should confirm the finding, assess business impact, choose a safe remediation or temporary restriction, and verify the result. The label alone is not a complete risk decision.
A is tempting because it treats the scanner's label as an absolute order. C overcorrects: scanner findings need validation and context, not automatic dismissal. D invents a fact about the test network. The useful analysis considers exposure, exploitability, asset importance, and compensating controls.
Question 3: protect data at rest
A laptop containing confidential records is frequently used offsite. The organization wants to reduce the chance that a lost or stolen device exposes its stored data. Which control most directly addresses this risk?
- Full-disk encryption with protected keys and an appropriate authentication control.
- A network intrusion detection sensor at the office gateway.
- A longer password expiration interval for the user's email account.
- A public status page that lists planned system maintenance.
Answer: A. Full-disk encryption directly reduces exposure of data stored on a lost device, provided keys and authentication are protected. The gateway sensor may detect some network activity but does not protect a powered-off device's stored data. Email password policy and a status page do not address the stated physical-loss scenario.
The limitation matters: encryption does not prevent an authorized logged-in user from disclosing data, and it does not replace access control, backup, or device management. The best answer directly addresses the stated risk while recognizing that no single control covers every threat.
Question 4: contain a compromised endpoint
An endpoint detection alert shows a workstation making repeated connections to a suspected command-and-control address. The user is still working, and the device may contain evidence needed to determine scope. What is the best next step?
- Isolate the workstation from the network using the approved response process, preserve relevant telemetry, and begin scoping the event.
- Wipe the device immediately without recording its state.
- Disable all network monitoring because the alert could be a false positive.
- Allow the workstation to remain connected until the next scheduled patch window.
Answer: A. Isolation can prevent additional communication while preserving records for analysis. The analyst should follow the organization's incident process, validate the alert, and determine the affected scope. Wiping without preserving evidence may erase useful information. Turning off monitoring removes visibility. Waiting until a patch window leaves a suspected active compromise connected.
The scenario does not establish that every response detail is identical across organizations. The best choice balances immediate containment with evidence preservation and authorized procedure. Eradication and recovery decisions follow when the cause and scope are better understood.
Question 5: supplier access
A support supplier asks for a shared administrator account that remains enabled between service calls. The supplier needs to troubleshoot one application. Which design best reduces risk while enabling the work?
- Create named, scoped accounts with time-limited access, approve the work, log activity, and review access after the support task.
- Provide the shared administrator password permanently because the supplier is contractually obligated to protect it.
- Disable audit logging to avoid exposing supplier activity.
- Give the supplier access to every production system so troubleshooting is not delayed.
Answer: A. Named, least-privilege, time-limited access supports accountability and limits exposure. Logging and review provide evidence of what happened and whether access should end. A contract is important but does not make permanent broad access safe. Disabling logs removes visibility, and broad production access exceeds the stated need.
This question crosses security operations and program oversight. The organization should define supplier responsibilities, approval, and monitoring. Access convenience is a legitimate concern, but it should be addressed with a workable scoped process instead of an uncontrolled shared credential.
Question 6: recover safely after ransomware
A team has isolated affected systems after a ransomware event. A backup is available, but the team has not determined whether the backup contains the same compromised configuration or whether the attacker still has access. What is the best next step before restoring production?
- Validate the backup and recovery environment, remove or contain the persistence path, and restore through a controlled process.
- Restore immediately to maximize availability, then investigate any new alert later.
- Delete all backups because ransomware may have affected one copy.
- Pay the attacker before checking whether clean recovery material exists.
Answer: A. A safe recovery requires confidence that the backup and destination are usable and that the attacker cannot simply reinfect restored systems. The team should verify integrity, address persistence, and follow a controlled restoration plan. Immediate restoration may reintroduce the compromise. Deleting all backups removes recovery options. Payment is not a substitute for assessing clean recovery.
Availability matters, but speed without validation can extend the incident. Good recovery planning includes protected backups, tested restoration, access controls, and decisions about business priorities. This scenario tests the difference between having a backup and having a trusted recovery capability.
Question 7: policy and standard
An organization wants every employee account to use multifactor authentication. Which document should state the mandatory organizational requirement, while a more detailed technical document defines accepted authentication methods?
- The policy states the mandatory requirement; a standard defines the approved technical methods.
- A procedure states the business objective; the policy lists every click in the sign-in interface.
- A guideline creates a mandatory control, while a standard is optional advice.
- A log file replaces written requirements because it records sign-ins.
Answer: A. A policy expresses an organizational requirement. A standard translates it into specific, measurable rules such as the approved methods. Procedures provide repeatable steps for carrying out a task, while guidelines recommend practices. Logs can show events but do not replace governance documents.
The distinction is useful when testing a control. A policy says what must happen, a standard defines acceptable implementation, and a procedure helps staff perform it consistently. An audit can compare actual account configuration and evidence with those requirements.
Question 8: choose the right control
A company learns that employees sometimes send sensitive files to personal email accounts. It wants to detect and reduce inappropriate outbound transfers while keeping approved business sharing possible. Which is the best first program of work?
- Classify sensitive data, define acceptable sharing rules, deploy a proportionate outbound monitoring or prevention control, and review alerts with an exception process.
- Block all internet access for every employee permanently.
- Encrypt the company's public website and assume the file-transfer issue is resolved.
- Remove the data classification labels so users are not confused.
Answer: A. The organization needs to understand what data is sensitive, set a clear rule, apply a control that can detect or prevent the relevant transfer, and handle legitimate exceptions. Blocking all internet access may harm business functions and does not establish a sustainable policy. Website encryption is unrelated to outbound file handling. Removing labels weakens understanding.
A strong answer accounts for security and operational use. Monitoring without a defined policy can produce noisy alerts; prevention without an exception path may disrupt work. The program should measure whether the control reduces inappropriate transfers and adjust based on evidence.
How to use these questions
Score your first attempt, but spend more time on explanations than the total. For every miss, note the domain, the clue, and the reasoning error. For a correct answer, check whether you can explain why the alternatives are weaker. If you guessed, count the item as a learning need even though the answer was right.
After reviewing, wait a day and summarize the underlying concepts without looking at the answer key. Then create a new scenario with changed facts. For instance, change an internal system to an internet-facing one or change a user account to a supplier account. If your decision changes for a defensible reason, you are applying the concept rather than memorizing the letter.
These eight questions are only a short sample. They do not cover every task in the official objectives and cannot estimate your passing probability. CompTIA publishes a passing score of 750 on a 100 to 900 scale; it is not a direct raw percentage. Use a broader set of objective-aligned practice and focused study before relying on a readiness judgment.
Common questions
Are these real Security+ exam questions?
No. They are original study scenarios and do not reproduce protected exam content.
Do these questions predict my score?
No. They cover selected concepts and do not reproduce the full exam or scoring.
How should I review a wrong answer?
Identify the missed clue, objective, and reasoning error, then practice the same skill in a new scenario.
Is 83% on practice enough to pass?
No raw-percentage conversion is established. CompTIA's published threshold is a scaled 750 on a 100 to 900 scale.