Free sampler

Try 12 free CompTIA Security+ practice questions

Real exam-style questions taken word for word from the CompTIA Security+ study guide. Three are below, with the full answer explanation. Enter your email and the full 12-question PDF is yours.

Unlock the full sampler
CompTIA Security+ cover
12 questions in the PDF Taken verbatim from the book One email, no spam, unsubscribe any time

Three questions to try right now

Work each one before you open the answer. These are the same style and depth as the CompTIA Security+ (SY0-701) exam expects.

Question 1. A security engineer is hardening a new Linux server. The engineer disables unused services, closes unnecessary ports, sets a minimum password length policy, and installs a host-based firewall. This set of actions is BEST described as

  • A. establishing a secure baseline.
  • B. application allow listing.
  • C. network segmentation.
  • D. configuration drift remediation.
Show the answer

Answer: A. The set of security configurations applied to a new system (disabling services, closing ports, setting policies, and installing a host-based firewall) constitutes establishing a secure baseline for that system.

Question 2. A hospital's compliance officer discovers that a business associate transmitted unencrypted patient records via email, potentially violating federal health privacy law. Which consequence of non-compliance is MOST immediately at risk?

  • A. Reputational damage only
  • B. Loss of license
  • C. Regulatory fines and sanctions
  • D. Contractual impacts only
Show the answer

Answer: C. Regulatory fines and sanctions are the most immediate consequences of transmitting unencrypted PHI in violation of federal health privacy law, in addition to reputational damage and potential contractual impacts.

Question 3. An auditor reviews access control configurations and user privilege assignments to verify compliance with the organization's least-privilege policy without exploiting any vulnerabilities. This is BEST described as which type of assessment activity?

  • A. Offensive penetration testing
  • B. Internal compliance audit
  • C. Vulnerability scanning
  • D. Red team exercise
Show the answer

Answer: B. Reviewing access control configurations and verifying compliance with policy without attempting exploitation is an internal compliance audit activity, not offensive testing.

Unlock the full 12-question sampler

All 12 come with the same written explanations the book uses, covering why the right answer is right. We email you the PDF, nothing else.

One email with the PDF. Unsubscribe any time.

What you get

The sampler is free. Here is exactly what lands in your inbox.

The 12-question PDF

Print it or work it on screen, then score yourself against the answer key.

Questions from the real book

Nothing is written for marketing. Every question is lifted from the study guide itself.

A one-time discount

A few days later we send one email with a code for the full study guide. That is the entire sequence.

CompTIA Security+ cover

The full CompTIA Security+ study guide

The complete guide covers the CompTIA Security+ (SY0-701) exam objective by objective in plain English, with the full practice question bank behind these samples.

From $20.99

See the study guide   All CompTIA guides