CompTIA Security+ Practice Test of the Day 260320

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.4 (Explain security alerting and monitoring concepts and tools.) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260320
10 questions • Single best answer
Question 1
A security operations team needs to collect and normalize event data from firewalls, servers, and endpoints into a central platform that correlates events and generates alerts. Which monitoring tool BEST meets this requirement?
    Question 2
    After a SIEM generates hundreds of low-priority alerts daily, analysts stop investigating them. An audit reveals the rules are triggering on normal activity. Which monitoring activity should the team perform to address this?
      Question 3
      A SOC analyst identifies a host generating unusual outbound traffic. The SIEM automatically isolates the endpoint from the network while the investigation continues. Which monitoring response activity does this represent?
        Question 4
        A security team uses an automated tool to measure system configurations against CIS Benchmarks and NIST standards — generating compliance scores and identifying deviations from accepted security baselines. Which monitoring framework does this describe?
          Question 5
          A network engineer configures a core router to send interface state changes, high CPU alerts, and authentication failure notifications to the monitoring platform. Which protocol is the router using to send these event notifications?
            Question 6
            A security engineer deploys software on each monitored endpoint that continuously streams system telemetry, process activity, and file changes to the centralized monitoring platform. Which deployment approach does this represent?
              Question 7
              A compliance officer needs to retain six months of firewall, authentication, and application logs for regulatory audit purposes — even after the data is no longer needed for active monitoring. Which monitoring activity addresses this requirement?
                Question 8
                A security analyst reviews a weekly dashboard showing patch compliance rates, endpoint antivirus health, and open vulnerability counts by severity. Which monitoring activity does this represent?
                  Question 9
                  A network team exports per-flow records from their core switches — capturing source and destination IPs, port numbers, protocol, and byte counts for every network conversation. Which monitoring data source is being collected?
                    Question 10
                    An endpoint security platform automatically detects and removes malware discovered on a workstation before it can spread to other systems. Which monitoring tool category provides this combined detection and automated response capability?
                      Next step: Hands-on

                      Theory tested. Now put it into practice.

                      The exam checks what you know, but employers check what you can do.

                      HTB Academy’s guided labs cover the same ground hands-on, with you at the keyboard.

                      Build hands-on skills →

                      This is an affiliate link. If you sign up, The Cybersecurity Trail earns a commission at no cost to you.

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top