Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on subdomain 3.3 (Compare and contrast concepts and strategies to protect data.) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Security+ 021326
10 questions • Single best answer
Question 1
A security administrator at a mid-sized healthcare company is reviewing how patient medical records containing PII and PHI are stored in a cloud-hosted database. The organization wants to ensure that even if physical storage media are stolen from the cloud provider’s data center, the data remains unreadable. Which of the following controls BEST addresses this requirement?
    Question 2
    An analyst in a SOC observes that a multinational organization stores European customer data in a U.S.-based cloud region, and auditors have raised concerns about legal jurisdiction and privacy compliance. Which concept is MOST relevant to this issue?
      Question 3
      Your organization processes credit card transactions and wants to reduce the scope of systems subject to PCI DSS audits. The security team proposes replacing stored credit card numbers with non-sensitive reference values while maintaining transaction functionality. Which method BEST supports this objective?
        Question 4
        A security administrator is designing a system that processes proprietary trade secrets in memory before writing results to disk. The administrator wants to focus specifically on protecting the data while it is actively being processed by applications. Which data state is being addressed?
          Question 5
          A company wants to ensure that only employees in the finance department can access payroll data classified as confidential, with access restricted based on job function. Which control BEST meets this requirement?
            Question 6
            An organization classifies its research data as critical intellectual property and wants to prevent unauthorized copying between network zones. Which strategy BEST reduces this risk?
              Question 7
              A global organization must restrict access to sensitive engineering documents so they can only be accessed from specific countries due to export control regulations. Which control BEST satisfies this requirement?
                Question 8
                Your company wants to share sanitized datasets with a third-party analytics vendor while preserving realistic structure and formatting but removing real customer identities. Which technique BEST meets this requirement?
                  Question 9
                  An enterprise is evaluating whether to use hashing or encryption for protecting stored passwords in an internal application and wants to ensure passwords cannot be reversed. Which solution BEST meets this goal?
                    Question 10
                    A security architect is reviewing strategies to protect financial data stored in multiple cloud providers and wants to ensure confidentiality even if one provider is compromised. Which approach BEST protects the data itself regardless of provider security?

                      Take more CompTIA Security+ practice tests

                      Leave a Reply

                      Your email address will not be published. Required fields are marked *