CompTIA Security+ Practice Test of the Day 070825

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 3.2 (Given a scenario, apply security principles to secure enterprise infrastructure) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 070825
10 questions • Single best answer
Question 1
A firewall inspects each packet individually based on source/destination IP and port, but does not track connection state or understand protocol context. A packet claiming to be part of an established connection is allowed through even though no connection was initiated. Which firewall type is described?
    Question 2
    An organization's firewall tracks the state of all active connections and maintains a connection table. Return traffic for established sessions is automatically permitted without requiring explicit inbound rules. Which firewall type is described?
      Question 3
      An organization deploys a firewall capable of identifying and controlling traffic by application — blocking Tor regardless of port, allowing Slack but limiting its bandwidth, and enforcing policies based on user identity rather than IP address. Which firewall type is described?
        Question 4
        A security architect places a bastion host in a highly secured DMZ that administrators must connect to before accessing any internal production servers. All privileged management access flows through this single, heavily audited system. Which network appliance is described?
          Question 5
          An intrusion prevention system is deployed inline between the internet edge router and the internal network. All traffic passes through it, and the system can drop malicious packets in real time before they reach internal systems. Which device attribute does this describe?
            Question 6
            A network switch port is configured to require devices to authenticate using EAP over 802.1X before being granted network access. Devices that fail authentication are placed in a restricted VLAN with no access to internal resources. Which security principle does this implement?
              Question 7
              A web application firewall is placed in front of a company's customer-facing web application. It inspects all HTTP/HTTPS requests and responses, blocking SQL injection attempts, XSS payloads, and other OWASP Top 10 attack patterns before they reach the application server. Which firewall type is described?
                Question 8
                A security architect configures a firewall to fail-closed. During a hardware failure, all network traffic — including legitimate business traffic — is blocked until the firewall is restored. Which security design decision does this represent?
                  Question 9
                  Remote employees connect to the corporate network through an encrypted tunnel that authenticates their devices, encrypts all traffic between the device and the corporate gateway, and routes internal traffic through the corporate network. Which secure communication method is described?
                    Question 10
                    A proxy server is deployed between employees and the internet. When a user requests a web page, the proxy retrieves it on their behalf and returns it to the user. The server also caches frequently accessed content and filters requests against a blocklist. Which proxy deployment is described?
                      Next step: Hands-on

                      Theory tested. Now put it into practice.

                      The exam checks what you know, but employers check what you can do.

                      HTB Academy’s guided labs cover the same ground hands-on, with you at the keyboard.

                      Build hands-on skills →

                      This is an affiliate link. If you sign up, The Cybersecurity Trail earns a commission at no cost to you.

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top