CompTIA Security+ Practice Test of the Day 080225

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.9 (Given a scenario, use data sources to support an investigation) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 080225
10 questions • Single best answer
Question 1
An analyst investigating a suspected data exfiltration incident needs to determine which internal hosts communicated with an external IP address flagged by threat intelligence over the past 72 hours. No full packet captures are available. Which data source would BEST provide the source IPs, destination IPs, ports, and connection timestamps needed?
    Question 2
    A forensic investigator examining a suspected insider threat case reviews email headers and document properties to determine when files were created, by whom, and on which system, without opening the file contents themselves. Which data source is she using?
      Question 3
      During an investigation into a web application attack, a security analyst replays the raw network traffic captured at the time of the incident. She is able to see the exact HTTP requests sent by the attacker, including the malicious payload embedded in a POST request. Which data source made this possible?
        Question 4
        A SOC analyst investigating a compromised Windows workstation reviews the Security event log and finds event ID 4624 (successful logon) and event ID 4648 (logon using explicit credentials) from a service account at 3:17 AM on a weekend. No legitimate activity is expected at that time. Which data source did the analyst use?
          Question 5
          An analyst investigating a web server compromise pulls the access log from the server and finds a series of requests from a single IP address containing directory traversal strings and attempts to access configuration files. Which log type provided this evidence?
            Question 6
            A security team uses an automated platform that runs daily checks across all endpoints and produces a formatted summary showing which systems have unpatched vulnerabilities, sorted by severity and asset group. An analyst reviews this output each morning to prioritize remediation work. Which data source is the analyst using?
              Question 7
              A CISO wants a single view showing real-time counts of open critical vulnerabilities, average time to patch by team, number of active incidents, and endpoint compliance percentage, all updating live as data changes. Which data source format BEST meets this need?
                Question 8
                An analyst investigating a malware infection on an endpoint reviews a log showing which processes were launched, which parent process spawned them, registry keys modified, and files created or deleted during the infection timeframe. Which data source is this?
                  Question 9
                  An IDS generates an alert on a suspicious outbound connection from an internal server. The analyst checks a related data source and confirms the connection was explicitly permitted by a firewall rule that should have been removed after a project ended six months ago. Which data source helped confirm the permissive rule?
                    Question 10
                    A security team is asked to provide evidence supporting a claim that an internal system was not communicating with a known malicious IP address during a specific two-hour window last Tuesday. Which combination of data sources would BEST support or refute this claim?
                      Cybersecurity Acronyms Desk Mat

                      Tired of Googling acronyms while practicing/studying?
                      Keep them all under your keyboard.

                      📋 GET_THE_DESK_MAT

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top