CompTIA Security+ Practice Test of the Day 260325

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.8 (Explain appropriate incident response activities) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260325
10 questions • Single best answer
Question 1
An incident response team establishes communication trees, defines escalation procedures, and pre-positions forensic tools before any incidents occur. Which incident response phase does this represent?
    Question 2
    A SOC analyst notices an unusual outbound data transfer pattern and escalates it to the incident response team. The team confirms that an endpoint is communicating with a known malicious IP. Which incident response phase does this represent?
      Question 3
      After confirming ransomware on several workstations, the incident response team immediately isolates the affected machines from the network — blocking lateral movement while preserving forensic evidence. Which incident response phase does this represent?
        Question 4
        After isolating compromised systems, the incident response team removes the malware, patches the exploited vulnerability, resets all affected credentials, and closes the attacker's persistent backdoor. Which incident response phase does this represent?
          Question 5
          After eradicating malware from affected servers, the incident response team rebuilds clean images, restores data from verified backups, validates system integrity, and returns the servers to production. Which incident response phase does this represent?
            Question 6
            After resolving a phishing-triggered data breach, the incident response team meets to document what happened, evaluate the effectiveness of their response, and identify specific improvements to detection and containment procedures. Which phase does this describe?
              Question 7
              An incident response team gathers in a conference room to walk through a simulated ransomware attack scenario — discussing decisions, roles, and communication without actually executing any technical actions. Which IR testing method does this describe?
                Question 8
                An incident responder places a legal hold on all email, documents, and logs related to a suspected data breach — notifying custodians that relevant data must not be altered or deleted pending investigation. Which digital forensics concept does this represent?
                  Question 9
                  A forensic investigator creates a bit-for-bit image of a compromised server's hard drive using a write blocker — hashing the original and the image to verify they are identical — before conducting any analysis. Which forensic process does this describe?
                    Question 10
                    An incident responder proactively searches through endpoint telemetry, network logs, and memory artifacts for indicators of attacker presence — without waiting for automated alerts to fire. Which IR activity does this describe?
                      Next step: Hands-on

                      Theory tested. Now put it into practice.

                      The exam checks what you know, but employers check what you can do.

                      HTB Academy’s guided labs cover the same ground hands-on, with you at the keyboard.

                      Build hands-on skills →

                      This is an affiliate link. If you sign up, The Cybersecurity Trail earns a commission at no cost to you.

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top