Free CompTIA Security+ (SY0-701) practice test

Every question below is original, written against the SY0-701 exam objectives, and comes with a full explanation — no braindumps, no recycled question banks. CertBench holds 800+ Security+ questions across all five domains, weighted the way the real exam weights them.

Try the samples, then take the free 25-question diagnostic to get a readiness score that tells you exactly which domains need work.

What the exam covers

1.0General Security Concepts12% of exam
2.0Threats, Vulnerabilities, and Mitigations22% of exam
3.0Security Architecture18% of exam
4.0Security Operations28% of exam
5.0Security Program Management and Oversight20% of exam

Sample questions

Pick an answer to see instant grading and the explanation — the same experience as the full bank of 842 questions.

1.An organization implements a system in which employees attempting to access the corporate VPN are evaluated against the following conditions before access is granted: their device must have a current antivirus signature file, the operating system must not have critical patches outstanding for more than 72 hours, and the connection must originate from a recognized country. Employees whose devices fail any condition are redirected to a remediation portal rather than granted VPN access. Which access control concept does this system implement?

2.A company uses OpenID Connect (OIDC) to allow users to log in to its application using their Google account. Which IAM function does OIDC provide in this scenario?

3.An organisation enforces a policy that each user account must only have the minimum permissions necessary to perform the user's assigned job duties and nothing more. Which principle does this policy implement?

4.A security engineer is hardening a Linux web server. They configure the web server process to run under a dedicated service account that has read access to web content directories, write access to log directories, and no other filesystem permissions. The account cannot execute system binaries outside the web server application, cannot access other users' home directories, and has no sudo privileges. If the web server process is compromised, the attacker operates within the constraints of this account. Which security principle does this configuration most directly implement, and what is its defensive value in a compromise scenario?

5.A security analyst is reviewing an embedded RTOS device used in a medical infusion pump. The device has no user interface and communicates only via a proprietary protocol over a local network. Which security control is MOST feasible to implement on this device?

6.An attacker sends an email with a PDF attachment that exploits a vulnerability in the PDF reader to execute malicious code. Which threat vector does this represent?

7.A penetration tester is given only the organization's company name and public-facing IP ranges before beginning the assessment. What type of environment is this?

8.Which attribute most distinguishes a nation-state threat actor from organized crime?

9.An organisation has a new SIEM deployment and initially receives 10,000 alerts per day, nearly all false positives. Which strategy BEST addresses this problem over time?

10.Which data sanitization method is MOST appropriate when a company needs to reassign an internal hard drive to a different employee for continued use?

Practice by exam objective

Drill a specific objective — each page has its own set of questions with explanations.

3.1Compare and contrast security implications of different architecture models1.1Compare and contrast various types of security controls2.1Compare and contrast common threat actors and motivations5.1Summarize elements of effective security governance4.1Given a scenario, apply common security techniques to computing resources3.2Given a scenario, apply security principles to secure enterprise infrastructure4.2Explain the security implications of proper hardware, software, and data asset management1.2Summarize fundamental security concepts5.2Explain elements of the risk management process2.2Explain common threat vectors and attack surfaces2.3Explain various types of vulnerabilities1.3Explain the importance of change management processes and the impact to security3.3Compare and contrast concepts and strategies to protect data5.3Explain the processes associated with third-party risk assessment and management4.3Explain various activities associated with vulnerability management5.4Summarize elements of effective security compliance3.4Explain the importance of resilience and recovery in security architecture4.4Explain security alerting and monitoring concepts and tools2.4Given a scenario, analyze indicators of malicious activity1.4Explain the importance of using appropriate cryptographic solutions4.5Given a scenario, modify enterprise capabilities to enhance security5.5Explain types and purposes of audits and assessments2.5Explain the purpose of mitigation techniques used to secure the enterprise4.6Given a scenario, implement and maintain identity and access management5.6Given a scenario, implement security awareness practices4.7Explain the importance of automation and orchestration related to secure operations4.8Explain appropriate incident response activities4.9Given a scenario, use data sources to support an investigation

Find out if you'd pass today

Take the free 25-question diagnostic and get a readiness score with a domain-by-domain breakdown — then a daily study plan built from your actual weak spots.

Take the free diagnostic

Not ready to sign up? Try the 3-minute readiness check — no account needed.

Frequently asked questions

How many questions are on the Security+ exam?

The SY0-701 exam has a maximum of 90 questions — a mix of multiple-choice and performance-based questions (PBQs) — in 90 minutes. Most candidates see fewer than 90 because PBQs count for more.

What score do I need to pass Security+?

You need 750 on a scale of 100–900. CompTIA doesn't publish a percentage, but 750/900 is commonly treated as roughly 83%, so aim to score consistently above that on practice exams before booking.

Are these real Security+ exam questions?

No — using leaked exam content (braindumps) violates CompTIA's policies and can void your certification. CertBench questions are original items written to cover the same SY0-701 objectives at exam-level difficulty, each with an explanation of why the right answer is right.

How should I use practice tests to prepare?

Take a diagnostic first to find your weak domains, drill those domains until they turn green, and use spaced repetition on every question you miss. Save full-length timed exams for the final two weeks. CertBench automates that sequence into a daily plan.