CompTIA Security+ Practice Test of the Day 260331

Welcome to today’s CompTIA Security+ practice test!

This practice test uses our new UI!

Today’s practice test is based on Subdomain 4.9 (Given a scenario, use data sources to support an investigation) from the CompTIA Security+ SY0-701 objectives.

This beginner-level practice test is inspired by the CompTIA Security+ (SY0-701) exam and is designed to help you reinforce key cybersecurity concepts on a daily basis.

These questions are not official exam questions, nor are they brain dumps, but they reflect topics and scenarios relevant to the Security+ certification. Use them to test your knowledge, identify areas for improvement, and build daily cybersecurity habits.

Note: CompTIA and Security+ are registered trademarks of CompTIA. This content is not affiliated with or endorsed by CompTIA.

To choose CompTIA Security+ practice tests based on specific domains/subdomains, click that link.

Recommended read: Ultimate CompTIA Security+ Study Guide (2026)

CompTIA Security+ Practice Test of the Day 260331
10 questions • Single best answer
Question 1
A security analyst reviews logs showing that the perimeter firewall allowed inbound TCP connections on port 3389 from an external IP at 2:00 AM — connections that should never occur. Which log data source provides this information?
    Question 2
    A forensic investigator searches Windows Event Logs for process creation events, service installations, and privilege escalation activity on a compromised workstation. Which log data source is being analyzed?
      Question 3
      An analyst investigating a web application breach queries logs showing every HTTP request — including URIs, parameters, user agents, response codes, and timestamps — to identify the SQL injection payload used. Which log source provides this data?
        Question 4
        A SOC analyst queries network flow records from the core switches to identify all systems that communicated with a suspected compromised host over the past 72 hours — mapping the potential lateral movement paths. Which data source is being used?
          Question 5
          A security engineer captures all network traffic on a segment for a 10-minute window during a suspected data exfiltration event — preserving the complete payload content for forensic analysis. Which data source does this describe?
            Question 6
            A vulnerability management platform automatically scans all assets weekly and produces reports ranking vulnerabilities by CVSS score — showing which systems are missing critical patches. Which security data source does this describe?
              Question 7
              A SIEM platform aggregates data from multiple security tools and presents a unified dashboard showing open incidents, critical alerts, endpoint compliance status, and threat trends — giving the SOC team a consolidated operational view. Which data source concept does this represent?
                Question 8
                An IDS generates an alert when it detects a pattern matching a known buffer overflow exploit attempt in network traffic. Which log data source produced this alert?
                  Question 9
                  During a breach investigation, a forensic analyst examines file system timestamps, registry modification records, prefetch files, and event log entries on a workstation — building a timeline of attacker activity. Which log data category is being primarily analyzed?
                    Question 10
                    A threat intelligence analyst correlates data from vulnerability scans, firewall logs, IDS alerts, and endpoint telemetry — identifying that a specific CVE was exploited after the IDS missed the attempt but the endpoint log shows process injection. Which analytical approach does combining these sources represent?
                      Cybersecurity Acronyms Desk Mat

                      Tired of Googling acronyms while practicing/studying?
                      Keep them all under your keyboard.

                      📋 GET_THE_DESK_MAT

                      Take more CompTIA Security+ practice tests

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top