CompTIA Security+ (SY0-701) Practice Test
This exam retires on Friday, June 11, 2027.
CompTIA has not announced a direct replacement.
Build your confidence for CompTIA Security+ (SY0-701). Practice the concepts, understand the answers, and strengthen your knowledge one question at a time.
Try a sample questionExam overview and details
CompTIA Security+ SY0-701 assesses five domains: security fundamentals (12%); threats, vulnerabilities and mitigation (22%); secure architecture (18%); security operations (28%); and security programme management and oversight (20%). Cryptography and PKI are included within the objectives, not a separate sixth domain. Use this independent practice bank to review security decisions and investigate knowledge gaps against the official SY0-701 objectives.
Sample Questions
Choose an answer and explore the explanation to see how practice works.
A company wants to ensure that the software it develops will not be tampered with after the final version is completed. Which of the following should the company most likely use?
A SaaS company wants to be able to compute statistics on customer billing data without ever decrypting it. Which encryption technique BEST fits this design goal?
A facilities manager is upgrading the power design of a small data center. The objective is to keep IT loads online for at least 15 minutes during a utility outage so that diesel generators can start and stabilize before any equipment loses power. Which device BEST meets the requirement?
A logistics company learns that a software update from a small open-source library used by its inventory system was tampered with by an attacker who compromised the maintainer's CI/CD pipeline. The malicious update was installed on hundreds of customers before it was discovered. Which attack vector category BEST describes this incident?
An identity team is implementing multifactor authentication. The first factor is a password (something you know). For the second factor, the team selects a hardware security key that the user must physically tap. Which factor category does the hardware key represent?
Career Opportunities & Salary
Exam insights and study advice
For a scenario question, identify the asset, threat, constraint and requested action before choosing a control. Distinguish prevention, detection and recovery instead of selecting the strongest-sounding product. For a missed question, explain why the closest distractor is wrong and check the relevant objective and source. Include practical incident and configuration exercises in your preparation.
Recommended
These are the backgrounds the certifying body suggests. Check the vendor's own page for anything it formally requires.
Your Path Forward
What this exam covers
Use the published domain weights to plan your study. Practice results do not predict your certification exam score.
01Security operations
Addresses computing resources management, asset tracking practices, and detailed vulnerability management procedures required to maintain operational stability and rapid incident response readiness within enterprise technology structures across all networks.
Topics
- Computing resources
- Asset management
- Vulnerability management
- Alerting and monitoring
- Enterprise security
- Identity and access management
- Automation and orchestration
- Incident response
- Data sources
Learning objectives
- Computing resources: applying secure baselines, mobile solutions, hardening, wireless security, application security, sandboxing, and monitoring
- Asset management: explaining acquisition, disposal, assignment, and monitoring/tracking of hardware, software, and data assets
- Vulnerability management: identifying, analyzing, remediating, validating, and reporting vulnerabilities
- Alerting and monitoring: explaining monitoring tools and computing resource activities
- Enterprise security: modifying firewalls, IDS/IPS, DNS filtering, DLP (data loss prevention), NAC (network access control), and EDR/XDR (endpoint/extended detection and response)
- Identity and access management: implementing provisioning, SSO (single sign-on), MFA (multifactor authentication), and privileged access tools
- Automation and orchestration: explaining automation use cases, scripting benefits, and considerations
- Incident response: implementing processes, training, testing, root cause analysis, threat hunting, and digital forensics
- Data sources: using log data and other sources to support investigations
02Threats, vulnerabilities, and mitigations
Focuses extensively on identifying various threat actors, distinct threat vectors, expanding attack surfaces, and a wide assortment of different types of vulnerabilities that affect modern computing systems and organizational networks today.
Topics
- Threat actors and motivations
- Threat vectors and attack surfaces
- Vulnerabilities
- Malicious activity
- Mitigation techniques
Learning objectives
- Threat actors and motivations: comparing nation-states, unskilled attackers, hacktivists, insider threats, organized crime, shadow IT, and motivations like data exfiltration, espionage, and financial gain
- Threat vectors and attack surfaces: explaining message-based, unsecure networks, social engineering, file-based, voice call, supply chain, and vulnerable software vectors
- Vulnerabilities: explaining application, hardware, mobile device, virtualization, operating system (OS)-based, cloud-specific, web-based, and supply chain vulnerabilities
- Malicious activity: analyzing malware attacks, password attacks, application attacks, physical attacks, network attacks, and cryptographic attacks
- Mitigation techniques: using segmentation, access control, configuration enforcement, hardening, isolation, and patching
03Security program management and oversight
Deals directly with security governance structures, structured risk management frameworks, compliance requirements, and specific third-party risk considerations necessary for maintaining organizational security posture and oversight across all connected business units.
Topics
- Security governance
- Risk management
- Third-party risk
- Security compliance
- Audits and assessments
- Security awareness
Learning objectives
- Security governance: summarizing guidelines, policies, standards, procedures, external considerations, monitoring, governance structures, and roles/responsibilities
- Risk management: explaining risk identification, assessment, analysis, register, tolerance, appetite, strategies, reporting, and business impact analysis (BIA)
- Third-party risk: managing vendor assessment, selection, agreements, monitoring, questionnaires, and rules of engagement
- Security compliance: summarizing compliance reporting, consequences of non-compliance, monitoring, and privacy
- Audits and assessments: explaining attestation, internal/external audits, and penetration testing
- Security awareness: implementing phishing training, anomalous behavior recognition, user guidance, reporting, and monitoring
04Security architecture
Explores complex architecture models, enterprise infrastructure configurations, and advanced data protection methods designed to secure information assets across distributed corporate networks and cloud environments effectively during daily operations.
Topics
- Architecture models
- Enterprise infrastructure
- Data protection
- Resilience and recovery
Learning objectives
- Architecture models: comparing on-premises, cloud, virtualization, Internet of Things (IoT), industrial control systems (ICS), and infrastructure as code (IaC)
- Enterprise infrastructure: applying security principles to infrastructure considerations, control selection, and secure communication/access
- Data protection: comparing data types, securing methods, general considerations, and classifications
- Resilience and recovery: explaining high availability, site considerations, testing, power, platform diversity, backups, and continuity of operations
05General security concepts
Covers basic security concepts, including the implementation of standard security controls, the management of organizational change, and the understanding of fundamental principles required for securing modern network environments and systems against potential failures.
Topics
- Security controls
- Fundamental concepts
- Change management
- Cryptographic solutions
Learning objectives
- Security controls: comparing technical, preventive, managerial, deterrent, operational, detective, physical, corrective, compensating, and directive controls
- Fundamental concepts: summarizing confidentiality, integrity, and availability (CIA); non-repudiation; authentication, authorization, and accounting (AAA); zero trust; and deception/disruption technology
- Change management: explaining business processes, technical implications, documentation, and version control
- Cryptographic solutions: using public key infrastructure (PKI), encryption, obfuscation, hashing, digital signatures, and blockchain