CompTIA Security+ Practice Test of the Day 073125

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.8 (Explain appropriate incident response activities) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 073125
10 questions • Single best answer
Question 1
A threat hunter at a financial services company reviews historical endpoint telemetry and network flow data looking for attacker techniques consistent with APT group TTPs, even though no alerts have fired. She is trying to find activity that may have evaded automated detection. Which incident response activity is this?
    Question 2
    An incident responder determines that an attacker entered the environment through a phishing email that delivered a macro-enabled document, which then downloaded a remote access tool. After full eradication, the team documents this sequence in a report to help prevent recurrence. Which incident response phase does the report support?
      Question 3
      An incident response team confirms that ransomware has encrypted files on 12 servers in one subnet. They immediately reconfigure firewall rules to block all traffic from that subnet to the rest of the network and disable the affected servers' Active Directory accounts. Which incident response phase are they performing?
        Question 4
        After a breach, forensic investigators must collect disk images and memory captures from compromised servers. The lead investigator documents every person who handled the evidence, the timestamps of each transfer, and the storage location at each step. Which forensic principle does this documentation support?
          Question 5
          A legal team is notified that the company is being sued. They immediately instruct IT to preserve all emails, documents, and logs related to the project in dispute and to suspend any automatic deletion policies that would have removed those records. Which action is the legal team initiating?
            Question 6
            A newly formed incident response team participates in a quarterly exercise where a facilitator describes an evolving scenario over several hours. Team members make response decisions, discuss tool usage, and identify gaps in their playbooks, but no actual systems are touched. Which type of testing is this?
              Question 7
              A forensic analyst receives a hard drive from an affected server. Before doing anything else, she creates a bit-for-bit image of the drive and stores the original in a write-protected evidence bag. All subsequent analysis is performed on the image. Which forensic principle is she applying?
                Question 8
                After an incident is fully resolved, the security team schedules a structured meeting where all responders review what happened, discuss what worked and what did not, and update playbooks and detection rules based on the experience. Which incident response phase does this represent?
                  Question 9
                  A court orders a company to produce all internal messages related to a product liability claim. The legal team works with IT to search email archives, collaboration tools, and file shares for relevant records and compile them for production. Which digital forensics process does this describe?
                    Question 10
                    A CISO mandates that all incident responders complete annual hands-on training where they work through realistic breach scenarios using actual tools in a lab environment to practice detection, containment, and eradication steps. Which incident response preparedness activity does this represent?
                      Cybersecurity Acronyms Desk Mat

                      Tired of Googling acronyms while practicing/studying?
                      Keep them all under your keyboard.

                      📋 GET_THE_DESK_MAT

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top