CoStudy

HomeStudy Guides › Security+ Practice Test: Sample Questions and Answers

Security+ Practice Test: Sample Questions and Answers

Five worked questions, one per SY0-701 domain, with the distractors explained rather than just marked wrong.

Published 2026-08-26 · certifications · exam prep · CoStudy

Only two things separate a useful Security+ practice test from a waste of time: mirroring the actual question style, and explaining the wrong answers instead of just marking them wrong. Most free practice tests online skip the second part, which means you learn what you got wrong without learning why, and you will make the same mistake again on a different phrasing of the same concept.

This matters more for Security+ than for a lot of certifications, because it is not a pure knowledge-recall exam. A meaningful portion of the test is performance-based questions, where you are given a scenario such as a network diagram or a set of logs and asked to configure something or identify the correct sequence of actions. You cannot cram your way through one of those the way you can memorise a definition. The only way to get comfortable with them is repetition under realistic conditions, which is exactly what a good practice test should simulate. What follows are sample questions spanning the five domains tested on the current SY0-701 exam, each with a full explanation of the correct answer and why the distractors are wrong. Use them as a diagnostic rather than a substitute for full-length timed practice.

From General Security Concepts: a company implements a policy requiring two different types of authentication factors before granting access to a system, and you are asked what this is called, with the options being single sign-on, multifactor authentication, role-based access control and federation. The answer is multifactor authentication, which requires two or more distinct factor categories, meaning something you know such as a password, something you have such as a token or phone, or something you are such as a biometric. Single sign-on is about using one credential across multiple systems rather than about factor count. Role-based access control governs what a user can do once authenticated, not how they authenticate. Federation allows identity to be trusted across organisational boundaries, which is related but separate.

From Threats, Vulnerabilities and Mitigations: an attacker sends an email that appears to come from the company's chief financial officer, instructing the finance team to wire funds to a new account, and the options are whaling, business email compromise, vishing and typosquatting. The answer is business email compromise, which specifically describes attacks that impersonate a trusted internal figure, often an executive, to manipulate financial or sensitive actions. Whaling is the related concept where the target is a high-value individual, whereas here the executive's identity is being spoofed rather than targeted, which is exactly the discrimination the question is testing. Vishing is voice-based phishing, which does not apply to an email attack. Typosquatting involves registering deceptively similar domain names, which is not described here.

From Security Architecture: which cloud deployment model gives an organisation the most control over the underlying infrastructure while still avoiding physical hardware ownership, with the options being software, platform, infrastructure and desktop as a service. The answer is infrastructure as a service, which gives the customer control over operating systems, storage and networking configuration on top of vendor-managed physical hardware, the most control of the standard models without owning equipment. Platform as a service abstracts away the operating system and infrastructure layer, leaving you to manage only applications and data. Software as a service abstracts nearly everything, delivering a finished application. Desktop as a service is a narrower delivery model for virtual desktops rather than general infrastructure.

From Security Operations: during an incident response process, which phase involves determining the root cause and removing the threat actor's access from the environment, with the options being preparation, containment, eradication and lessons learned. The answer is eradication, the phase focused on removing the root cause, meaning malware, unauthorised accounts and backdoors, after the threat has been contained. Containment comes first and focuses on limiting spread rather than removal. Preparation happens before an incident occurs, building the tools and playbooks you will need. Lessons learned happens after recovery, reviewing what happened and what to improve.

And from Security Program Management and Oversight: a company requires third-party vendors to sign an agreement defining confidentiality obligations before sharing sensitive data, and you are asked what that document is called, with the options being a service level agreement, a non-disclosure agreement, a memorandum of understanding and a business partnership agreement. The answer is the non-disclosure agreement, which specifically governs confidentiality obligations. A service level agreement defines performance expectations such as uptime, not confidentiality. A memorandum of understanding is a non-binding statement of intent between parties. A business partnership agreement governs the broader terms of a partnership rather than confidentiality specifically. This cluster of four agreement types is worth over-preparing, because the exam reuses them as distractors for each other constantly.

On using practice tests effectively, do not just take one long test and call it done. The highest-value approach is to run smaller, timed sets by domain, review every explanation including the ones you got right, since understanding why something is correct catches gaps you did not know you had, and then repeat the domains where you are weakest closer to your exam date. Flashcard-style review pairs well with this: use flashcards to drill the underlying facts such as ports, attack types and control categories, then use practice questions to test whether you can apply them under scenario pressure. CoStudy's Security+ practice questions follow the same format as the samples above, with full explanations rather than just correct and incorrect markers, organised by domain so you can target weak spots directly. The first ten questions of every deck are free with no signup, so you can see how your recall holds up before deciding whether to open the full bank.

A few questions come up repeatedly. CompTIA states the exam contains a maximum of ninety questions combining multiple-choice and performance-based types, to be completed within a time limit it sets, and you should check its official exam details page for the current allotment since these details can be revised between version updates. Performance-based questions are not harder so much as different, testing application rather than recall, and most candidates find them more time-consuming even when the underlying concept is one they know well, which is why practising that specific style matters rather than only multiple choice. You should always guess on questions you do not know, because CompTIA does not subtract points for wrong answers, so an educated guess is always better than a blank. The quality of free online practice tests varies widely, so look for ones that explain answers rather than just scoring you, and be sceptical of question banks recycling questions CompTIA has previously flagged as compromised, since those get retired from the live pool. And on readiness, there is no official crossover number, but a common rule of thumb is consistently scoring comfortably above the passing threshold of 750 out of 900 across multiple full-length practice tests, not just on your best attempt.

Read this in the CoStudy app →

Keep reading

Practise this exam

All study guides · Browse question banks · Editorial policy