CompTIA Security+ Practice Test of the Day 082125

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 5.3 (Explain the processes associated with third-party risk assessment and management) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 082125
10 questions • Single best answer
Question 1
Before signing a contract with a new payroll processing vendor, the security team reviews the vendor's SOC 2 Type II report, most recent external penetration test results, and security awareness training records. What third-party risk management activity is this?
    Question 2
    A cloud services agreement specifies that the provider guarantees 99.95% monthly uptime, maximum 4-hour response time for critical support tickets, and financial credits if service levels are not met. What type of agreement is this?
      Question 3
      A company requires a third-party software developer to sign an agreement before receiving proprietary source code, preventing the developer from disclosing or using the code outside the project scope. What type of agreement is this?
        Question 4
        A contract between a company and its managed security service provider includes a clause granting the company the right to inspect the MSSP's facilities, review security policies, examine audit logs, and verify compliance with contractual requirements at any time. What contractual provision is this?
          Question 5
          Two government agencies establish a cooperative framework to share cybersecurity threat intelligence. They document their mutual intentions, data sharing responsibilities, and expected behaviors in a non-binding agreement without creating legally enforceable obligations. What type of agreement is this?
            Question 6
            Before a penetration testing firm begins an engagement, they and the client document acceptable testing methods, systems excluded from testing, emergency contacts, and criteria for stopping the test. What document governs the conduct of the engagement?
              Question 7
              A managed service provider and its enterprise client sign a comprehensive agreement establishing general legal terms, liability limitations, payment terms, and dispute resolution procedures. Individual service engagements are then governed by separate work orders referencing this agreement. What agreement type provides the overarching framework?
                Question 8
                Before onboarding any new vendor, an organization sends a standardized form asking about the vendor's data protection practices, incident response capabilities, employee security training, and third-party audit history. What third-party risk management activity is this?
                  Question 9
                  A security team periodically reviews all active vendor relationships, checking for recent security incidents at vendor sites, changes in their financial stability, new regulatory violations, and updates to their security certifications. What ongoing vendor management activity does this represent?
                    Question 10
                    A security team discovers that a key software vendor also provides identical services to two direct competitors. They raise concerns that the vendor's dual relationship may affect how the vendor prioritizes patches, shares information, or manages incidents for each client. What vendor selection concern is this?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top