Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on subdomain 5.6 (Given a scenario, implement security awareness practices.) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

CompTIA Security+ Practice Test of the Day 260226
10 questions • Single best answer
Question 1
Your organization recently experienced multiple credential-harvesting attempts targeting remote employees. A security administrator at a mid-sized company is tasked with improving user awareness to reduce successful phishing attacks. Leadership wants measurable improvement and proof that employees understand how to recognize and report phishing attempts. The administrator decides to implement a formal security awareness initiative. Which of the following actions would BEST support this objective?
    Question 2
    An analyst in a SOC observes that several employees have recently connected unauthorized USB drives to corporate laptops in a hybrid work environment. While no malware was detected, leadership is concerned about insider threats and unintentional data exfiltration. The security team wants to strengthen awareness without immediately implementing strict technical enforcement controls. Which of the following is the MOST appropriate security awareness action?
      Question 3
      Your company has expanded to support a fully remote workforce across multiple geographic regions. A security administrator notices an increase in risky behavior, including employees discussing sensitive projects over unsecured public Wi-Fi and failing to use company VPN services. Management requests a proactive awareness strategy tailored to hybrid and remote environments. Which of the following should the administrator implement FIRST?
        Question 4
        An organization recently implemented a formal process for employees to report suspicious emails. However, the SOC notices that many users still forward phishing emails to colleagues instead of reporting them through the official mechanism. Leadership wants to reinforce correct reporting behavior while improving monitoring effectiveness. Which of the following actions would BEST address this issue?
          Question 5
          A security administrator at a mid-sized company is developing a new security awareness program after a recent insider threat incident involving unauthorized sharing of confidential design documents. The investigation determined that the employee did not act maliciously but failed to understand data handling expectations. Leadership wants to reduce unintentional insider threats through improved awareness. Which of the following should the administrator implement to BEST address this issue?
            Question 6
            An analyst in a SOC notices a pattern of employees clicking on urgent “invoice correction” emails that create a sense of panic and time pressure. After analysis, the messages are confirmed as social engineering attempts leveraging emotional manipulation. The security team wants to strengthen users’ ability to identify these tactics. Which of the following training enhancements would be MOST effective?
              Question 7
              Your company operates in a regulated industry and must demonstrate ongoing security awareness training. During an audit, it is discovered that training was conducted once during onboarding but never reinforced. Several employees were unaware of recent policy updates regarding hybrid work security expectations. Which of the following would BEST demonstrate compliance while improving overall awareness?
                Question 8
                An organization has introduced a formal suspicious message reporting channel, but employees hesitate to report potential phishing emails because they fear disciplinary action if they are wrong. Leadership wants to increase early reporting to reduce dwell time of threats. Which of the following is the BEST approach?
                  Question 9
                  A security administrator at a mid-sized company is reviewing the results of a recent phishing simulation campaign. The results show that while most employees did not click the malicious link, many failed to report the email through the official reporting channel. Leadership wants to improve early detection of real threats and reinforce proper reporting behavior. Which of the following actions would BEST improve the effectiveness of the awareness program?
                    Question 10
                    An analyst in a SOC observes anomalous behavior involving an employee accessing sensitive HR records outside normal business hours from an unfamiliar geographic location. Initial investigation reveals the employee was unaware that accessing such records remotely without VPN usage violated operational security guidelines. Leadership wants to reduce similar risky and unexpected behavior. Which of the following awareness measures would BEST address this issue?

                      Take more CompTIA Security+ practice tests

                      Leave a Reply

                      Your email address will not be published. Required fields are marked *