About the Exam

CompTIA Security+ SY0-701 is CompTIA's Security+ certification exam for IT professionals moving into baseline cybersecurity roles. It covers security controls, threats and vulnerability mitigation, security architecture, security operations, and security program management; the exam uses up to 90 multiple-choice and performance-based questions over 90 minutes, and CompTIA recommends about 2 years of security-focused IT administration experience. Passing shows you can assess an enterprise security posture, secure hybrid environments, and respond to security events and incidents.

Exam Topics

  • General Security Concepts12%
  • Threats, Vulnerabilities, and Mitigations22%
  • Security Architecture18%
  • Security Operations28%
  • Security Program Management and Oversight20%

How to Use This Practice Exam

  1. Browse — Read each question, select your answer, and reveal the explanation.
  2. Exam Mode — Simulate real exam conditions with a timed session and score report.
  3. Learn Mode — Spaced repetition schedules questions you struggle with for long-term retention.

Download the Full Exam PDF

Get every question and answer in a clean, printable PDF built for offline study. Purchase once, keep permanent access, and re-download the latest version anytime.

Last updated July 8, 2026 at 6:09 PM

Topic filter
Retired questions
Question sort
Questions per page

QuestionQ1

Security Architecture

To which of the following security categories does an EDR solution fall?

Explanation

An EDR solution is a technology-based endpoint security control that provides threat detection, investigation, and response capabilities on devices. It belongs to the technical security category.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ2

General Security Concepts

Which of the following covers individual rights, including the right to be informed, the right of access, and the right to be forgotten?

Explanation

The General Data Protection Regulation (GDPR) grants data subjects rights to information about personal-data processing, access to their personal data, and erasure of personal data in applicable circumstances.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ3

General Security Concepts

Which of the following explains the difference between encryption and hashing?

Explanation

Encryption converts plaintext into ciphertext so authorized parties can recover the original data with the appropriate key. Hashing computes a one-way fixed-length digest (often used as a checksum or for integrity verification) and does not recover the original input.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ4

Threats, Vulnerabilities, and Mitigations

Which risk management strategy should an enterprise implement first when a legacy application is critical to business operations and preventive controls have not yet been put in place?

Explanation

Risk mitigation reduces either the likelihood or impact of a risk through controls. Implementing the missing preventive controls is therefore the appropriate initial response for a business-critical legacy application.

Community Discussion

No comments yet. Be the first to start the discussion!

QuestionQ5

Security Program Management and Oversight

A security officer is implementing a security awareness program by placing security-themed posters throughout the building and assigning online user training. Which of the following would the security officer be most likely to implement?

Explanation

A phishing campaign, particularly a simulated one, is a common security awareness measure that reinforces user training and evaluates whether users can identify phishing and other social-engineering attempts.

Community Discussion

No comments yet. Be the first to start the discussion!
Know a question that should be here? Contribute to this exam
Back home