← All Practice Quizzes

CompTIA Security+ (SY0-701) Practice Quiz — 20 Free Sample Questions

CompTIA Security+ (SY0-701) is the most widely recognized entry-level cybersecurity certification and a DoD 8570 baseline requirement for many federal IT roles. The SY0-701 exam has up to 90 questions in 90 minutes, with a passing score of 750 out of 900. What trips up most candidates isn't the definitions — it's the scenario questions that require you to choose between controls, identify attack types from symptoms, or pick the correct incident response action given a specific situation. This Security+ practice quiz covers 20 questions drawn from the five SY0-701 domains: General Security Concepts, Threats, Vulnerabilities and Mitigations, Security Architecture, Security Operations, and Security Program Management. Use it to identify whether your knowledge gaps are in cryptography, access control, threat actors, network security, or compliance.

What this CompTIA Security+ (SY0-701) quiz helps you figure out

Use this Security+ quiz to see whether your next study block should focus on threat recognition, controls, or performance-based reasoning. It is designed to catch weak areas before they turn into broad domain misses.

Security+ candidates often know the definitions but still miss scenario questions. A diagnostic helps you find whether architecture, response, identity, or secure operations is the real weak domain.

Study path

This page works best as a three-step loop: quiz, focused review, then targeted follow-up in the coach and guide cluster.

Scenario judgment

Test whether you can choose the best next action, not just recall terms.

Tool familiarity

Measure whether you actually understand the platforms or workflows being tested.

Domain balance

See which major exam domain deserves your next study block.

Topic-specific study sequence

1

Baseline your readiness

Take the quiz before studying so you know which domain needs attention first.

2

Review by workflow

Cluster misses by process, tool, or scenario type.

3

Turn misses into a plan

Use the coach and guide cluster to reinforce the same concepts from different angles.

How to read your score

0-9 correct

You are still in the learn-the-framework stage. Focus on the core blueprint first.

10-15 correct

You have useful coverage, but one or two domains are still holding the score down.

16-20 correct

You are close to readiness. Study the misses as decision-making patterns, not isolated facts.

Question styles you will see on this page

Sample angle 1

An attacker sends a deceptive email to a company's finance department appearing to be from the CEO, requesting an urgent wire transfer. This attack is best classified as:

Business Email Compromise (BEC) is a form of spear phishing that targets specific individuals — typically in finance — using spoofed executive identities to authorize fraudulent transfers. Vishing uses voice calls; smishing uses SMS; a watering hole attack compromises websites frequented by the target organization. BEC is one of the costliest social engineering attacks by financial impact.

Sample angle 2

Which encryption type uses the same key to both encrypt and decrypt data, making it faster but requiring secure key exchange?

Symmetric encryption (e.g., AES) uses a single shared key for both encryption and decryption. It is computationally fast and suitable for bulk data encryption, but the key must be securely shared between parties. Asymmetric encryption uses a key pair (public/private) and solves the key distribution problem but is much slower, so it is typically used only to exchange symmetric keys.

Sample angle 3

A company implements multi-factor authentication requiring something you know, something you have, and something you are. 'Something you are' refers to:

The three MFA factors are: something you know (password, PIN), something you have (hardware token, smart card, authenticator app), and something you are (biometric: fingerprint, facial recognition, iris scan). Requiring multiple factors significantly reduces account compromise risk even when a password is stolen.

Question 1 of 200 correct so far

An attacker sends a deceptive email to a company's finance department appearing to be from the CEO, requesting an urgent wire transfer. This attack is best classified as:

About the CompTIA Security+ (SY0-701) and what to do after this result

CompTIA Security+ SY0-701 is the current version of the certification, launched in November 2023. It covers five domains with the following approximate weightings: General Security Concepts (12%), Threats, Vulnerabilities, and Mitigations (22%), Security Architecture (18%), Security Operations (28%), and Security Program Management and Oversight (20%). The exam has up to 90 questions — multiple choice and performance-based — with a 90-minute time limit and a passing score of 750 on a 100-900 scale. Performance-based questions (PBQs) simulate real environments and typically appear at the start of the exam. Security+ is recognized by the U.S. Department of Defense under Directive 8570 as a baseline certification for IAT Level II and IAM Level I positions. Key topic clusters include symmetric vs asymmetric cryptography, PKI and certificate management, network segmentation and zero trust architecture, identity and access management (MFA, SSO, PAM), threat intelligence (TTPs, IOCs, threat actors), vulnerability management lifecycle, SIEM and SOAR, incident response phases, business continuity and disaster recovery (BCP/DRP), and governance frameworks (NIST, ISO 27001, SOC 2). CompTIA recommends two years of IT experience with a security focus before attempting the exam.

Next best steps

Frequently Asked Questions

What is the passing score for Security+ SY0-701?

750 on a scaled score of 100-900. The exam has up to 90 questions (multiple choice and performance-based) with a 90-minute time limit. Performance-based questions appear early in the exam and test practical skills in simulated environments.

Is Security+ required for federal government IT jobs?

Yes. CompTIA Security+ satisfies the DoD 8570 baseline requirement for Information Assurance Technical (IAT) Level II and Information Assurance Management (IAM) Level I positions. Many federal contractors also require it for cleared IT roles.

What is the difference between SY0-601 and SY0-701?

SY0-701 (released November 2023) updated the domain structure from six domains to five and increased emphasis on cloud security, zero trust architecture, automation/orchestration (SOAR), and current threat actor TTPs. SY0-601 retired in July 2024. Candidates should study SY0-701 materials exclusively.