Free CompTIA Security+ (SY0-701) practice test

The CompTIA Security+ (SY0-701) is the standard entry-level security certification: it covers core security concepts, threats and mitigations, security architecture, day-to-day operations, and governance. This site gives you 433 original practice questions and 16 performance-based questions for it, free and without an account.

Practice two ways: adaptive drills that repeat your weak topics more often and explain every answer, or a full 90-minute exam simulation with 60 questions plus 4 PBQs, scored on the real 100 to 900 scale. The PBQ lab simulates the exam's hands-on formats: hardening configuration panels, incident-response ordering, and clickable network diagrams. Every topic links to the matching free Professor Messer video.

What SY0-701 covers

SY0-701 domainExam weightQuestions here
General Security Concepts12%about 52
Threats, Vulnerabilities & Mitigations22%about 95
Security Architecture18%about 78
Security Operations28%about 121
Program Management & Oversight20%about 87

Real exam facts: up to 90 questions, 90 minutes, passing score 750 on the 100 to 900 scale. CompTIA recommends Network+ and about two years of security-focused IT administration.

Practice questions from this bank

Sample question 1 · SY0-701 · General Security Concepts

An organization documents a formal security policy that dictates how employees must classify and handle sensitive data. Under the CompTIA control categories, this policy is an example of which category?

  1. ATechnical
  2. BPhysical
  3. CManagerial
  4. DOperational
Show answer and explanation

C. Managerial

Managerial controls (also called administrative controls) are the policies, procedures, and guidelines that govern how security is designed and enforced. A written data-handling policy is documentation rather than a technology or a human-performed task, so it is managerial. Operational controls are the ones carried out by people, such as security awareness training.

Topic: Security Controls

Sample question 2 · SY0-701 · Threats, Vulnerabilities & Mitigations

Which threat actor is typically the best funded and most technically sophisticated, usually conducting long-term espionage against government and critical-infrastructure targets?

  1. AHacktivist
  2. BInsider threat
  3. CNation-state actor
  4. DUnskilled attacker
Show answer and explanation

C. Nation-state actor

Nation-state actors, often called advanced persistent threats (APTs), have the deepest funding and highest sophistication, and their goal is usually long-term espionage or strategic disruption. Hacktivists are ideologically driven but far less resourced, and an unskilled attacker relies on tools written by others.

Topic: Threat Actors

Sample question 3 · SY0-701 · Security Architecture

Which practice defines virtual networks, servers, and firewall rules in version-controlled template files so that environments can be provisioned the same way every time?

  1. AInfrastructure as code
  2. BServerless computing
  3. CContinuous integration
  4. DVertical scaling
Show answer and explanation

A. Infrastructure as code

Infrastructure as code (IaC) describes networks, servers, and security rules in machine-readable template files kept in version control, so environments are built consistently and changes can be peer-reviewed. Continuous integration automates building and testing application code, not the provisioning of infrastructure.

Topic: Cloud Infrastructures

Sample question 4 · SY0-701 · Security Operations

During configuration management, a security team documents the minimum acceptable security settings that every new server build must meet before it goes into production. What is this documented standard called?

  1. AA security baseline
  2. BA change advisory board
  3. CA recovery point objective
  4. DA memorandum of understanding
Show answer and explanation

A. A security baseline

A secure baseline is the documented set of minimum security settings a system must meet; it is established, deployed to systems, and then maintained as threats change. A change advisory board reviews proposed changes, and a recovery point objective is a backup metric, not a configuration standard.

Topic: Secure Baselines

Sample question 5 · SY0-701 · Program Management & Oversight

Which policy document defines the permitted and prohibited uses of company-owned devices, email, and internet access, and is typically signed by users during onboarding?

  1. AAcceptable use policy
  2. BIncident response policy
  3. CChange management policy
  4. DDisaster recovery policy
Show answer and explanation

A. Acceptable use policy

The acceptable use policy (AUP) states how employees may and may not use organizational systems, and it is commonly signed during onboarding. Incident response, change management, and disaster recovery policies govern operational processes rather than everyday user conduct.

Topic: Security Policies

Sample question 6 · SY0-701 · General Security Concepts

As part of change management, a team prepares documented steps to restore systems to their previous state if a deployment causes unexpected problems. What is this documentation called?

  1. AImpact analysis
  2. BMaintenance window
  3. CStandard operating procedure
  4. DBackout plan
Show answer and explanation

D. Backout plan

A backout plan (also called a rollback plan) defines how to reverse a change and return to the last known-good state if something goes wrong. Impact analysis is performed beforehand to predict effects, not to undo a change that has already failed.

Topic: Change Management

Sample question 7 · SY0-701 · Threats, Vulnerabilities & Mitigations

What defines a zero-day vulnerability?

  1. AA flaw that affects only systems older than one year
  2. BA flaw that requires physical access to exploit
  3. CA flaw exploited before the vendor has released a fix
  4. DA flaw that has been patched but not yet deployed
Show answer and explanation

C. A flaw exploited before the vendor has released a fix

A zero-day vulnerability is one that is unknown to the vendor or has no available patch, so defenders have had zero days to prepare when it is first exploited. The choice describing a flaw that has been patched but not yet deployed is a patch-deployment gap, not a zero-day.

Topic: Zero-day Vulnerabilities

Sample question 8 · SY0-701 · Security Architecture

An intrusion prevention system detects threats only by comparing traffic against a database of previously catalogued attack indicators. What is the main limitation of this detection method?

  1. AIt relies on a learned network baseline that must be trained first
  2. BIt flags any deviation from normal behavior as an attack
  3. CIt cannot detect a brand-new attack that has no matching entry yet
  4. DIt requires the appliance to run in passive monitoring mode
Show answer and explanation

C. It cannot detect a brand-new attack that has no matching entry yet

Signature-based detection compares traffic to a database of known indicators, so a zero-day attack with no matching entry slips through until a signature is written. Anomaly-based detection, which learns a baseline and flags deviations, is the technique better suited to catching novel attacks.

Topic: Intrusion Prevention

Common questions

How many questions are on the Security+ exam?

The SY0-701 exam has a maximum of 90 questions in 90 minutes, mixing multiple choice with performance-based questions. The passing score is 750 on a 100 to 900 scale.

Do I need Network+ before Security+?

No, but CompTIA recommends Network+ plus about two years of IT administration with a security focus. Security+ leans on networking fundamentals, so comfort with ports, protocols, and topologies helps a lot.

What does SY0-701 cover?

Five domains: General Security Concepts (12%), Threats, Vulnerabilities & Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management & Oversight (20%). Our drills track your accuracy in each domain separately.

Is this actually free?

Yes. Every question, every PBQ, and the full exam simulator are free with no account. Every topic links to the matching video in Professor Messer's free SY0-701 course.

More free practice tests

Back to all cert900 exams