Start free →
Study guide · Security+

CompTIA Security+ Practice Exam (SY0-701)

270 practice questions mapped to the SY0-701 blueprint — with full explanations for every answer. Free to start.

Start practicing now — free

20 free questions per session · Full explanations · No credit card

Try Security+ questions →

About the Security+ SY0-701 exam

CompTIA Security+ (SY0-701) is the industry's leading entry-level cybersecurity certification. It's DoD-approved, globally recognized, and required or preferred for a wide range of security roles. The SY0-701 version launched in November 2023 with a heavier emphasis on current threats, cloud security, and automation.

The exam allows up to 90 questions, 90-minute time limit, passing score of 750 (scale 100–900). Questions include multiple choice and performance-based items.

SY0-701 exam domains

12%
General Security Concepts
22%
Threats, Vulnerabilities & Mitigations
18%
Security Architecture
28%
Security Operations
20%
Security Program Management & Oversight

Sample Security+ practice questions

A security analyst discovers that an attacker has been using a technique where malicious code is injected into a legitimate process's memory space, allowing the attacker to evade detection. Which technique is being described?
A. SQL injection
B. Cross-site scripting (XSS)
C. Process injection ✓
D. Directory traversal
Process injection is a technique where attackers inject code into a legitimate running process to evade security tools and persist in memory without dropping files to disk. SQL injection and XSS target web applications. Directory traversal exploits path handling.
Which of the following best describes the principle of least privilege?
A. Users should change their passwords frequently
B. Users and systems should only have the minimum access rights needed to perform their function ✓
C. All data should be encrypted at rest and in transit
D. Security patches should be applied within 30 days
Least privilege limits the access rights for users, accounts, and processes to only what is strictly required for their legitimate purpose. This limits the damage that can result from accidents, errors, or unauthorized use.
A company wants to implement multi-factor authentication (MFA) that uses something the user has. Which of the following meets this requirement?
A. Password
B. Fingerprint scan
C. Hardware token ✓
D. Security questions
MFA factors: something you know (password, PIN), something you have (hardware token, smart card, phone), something you are (biometrics). A hardware token is a physical device the user possesses.

How to prepare for Security+

Start with the objectives, not a textbook

Download the official CompTIA SY0-701 exam objectives PDF and use it as your study map. Work through each objective, testing yourself on each one before moving to the next.

Understand, don't memorize

Security+ tests your ability to apply concepts, not recite definitions. Many candidates fail because they memorize terms but can't apply them in scenario-based questions. Focus on understanding why — why is MFA better than a password alone? Why is network segmentation effective against lateral movement?

Know your attack types cold

Domain 2 (Threats, Vulnerabilities & Mitigations) is 22% of the exam. You'll need to recognize phishing, spear phishing, vishing, smishing, whaling, MitM, replay attacks, SQL injection, buffer overflow, and more.

270 Security+ questions with full explanations

Free to start · Pro unlocks all questions + timed exam mode

Start practicing →

More certification practice on aprencert