CompTIA Security+ Practice Test of the Day 071425

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 2.2 (Explain common threat vectors and attack surfaces) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 071425
10 questions • Single best answer
Question 1
An employee receives an email appearing to come from the company's IT helpdesk, asking her to click a link and verify her credentials before her account is locked. The link leads to a spoofed login page that captures her username and password. Which threat vector is described?
    Question 2
    A user receives a text message appearing to be from their bank, warning of suspicious account activity and asking them to click a link to verify their identity. The link leads to a fake banking site that steals login credentials. Which attack vector is described?
      Question 3
      An attacker calls an employee, poses as a Microsoft support technician, and claims the employee's computer is sending error reports. The caller convinces the employee to install remote access software, giving the attacker control of the machine. Which attack vector is described?
        Question 4
        An attacker compromises the email account of a company's CFO and uses it to send a message to the accounts payable team, directing them to wire $250,000 to a new vendor account. The payment is made before anyone realizes the CFO's account was hijacked. Which attack is described?
          Question 5
          Security researchers discover that a managed service provider's remote monitoring software was compromised. The attacker used the MSP's trusted access to push malicious updates to thousands of client organizations simultaneously. Which threat vector does this represent?
            Question 6
            An attacker leaves several USB drives labeled 'Q3 Salary Data' in a company's parking lot. A curious employee picks one up and plugs it into their workstation. The drive automatically executes malware that establishes a reverse shell. Which threat vector is being exploited?
              Question 7
              An attacker identifies that employees of a target company frequently visit a niche industry forum. The attacker compromises the forum's website and injects malware that silently infects visitors' browsers. Employees who visit the forum have their credentials stolen. Which attack technique is described?
                Question 8
                A penetration tester gains access to a company's network by using the username 'admin' and password 'admin' on an internet-facing router that was installed the previous month. Which attack surface vulnerability did the tester exploit?
                  Question 9
                  An attacker registers the domain 'micros0ft-support.com' — substituting the letter 'o' with a zero — and uses it to host a fake support portal that harvests credentials from employees who mistype the URL. Which attack technique is described?
                    Question 10
                    A hospital's radiology department still runs Windows XP on machines connected to MRI equipment because the vendor does not support newer operating systems. A security assessment identifies these machines as a significant attack surface. Which vulnerability category BEST describes this risk?
                      Cybersecurity Acronyms Desk Mat

                      Tired of Googling acronyms while practicing/studying?
                      Keep them all under your keyboard.

                      📋 GET_THE_DESK_MAT

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top